Drupal Version
10.1.7
Domain module version
2.0.0-beta1
Expected Behavior
Receive a warning when trying to delete domain fields from content types.
Actual Behavior
For content types that don't have domain fields strange access issue appear after running node_access_rebuild() on different domains.
Steps to reproduce
- Create two domains, e.g domain1 and domain2
- Create a role with access to edit article node types (the permission from drupal core)
- Remove both domain fields form the article content type. This I what I figured I should do if I want a content type be available on all domains.
- Login with the admin user on domain1 and create an article node
- Rebuild access permission on admin/reports/status/rebuild on domain1
- Create a user with only that newly created role and login on domain2
- Try to edit the article and receive an access denied
- Login with the admin on domain2 and rebuild access permissions
- Try again to edit the article with the non-admin user successfully.
Restoring the two domain fields on the article content type and then rebuilding access on the default domain solves the issue.
Rebuilding access permissions on a non-default domain still gives access denied errors for users that have permissions to perform the operations, it happens for viewing nodes too so I think there some bug here as one has to be careful to edit nodes and rebuild access from the default domain.
My point here is that I made the mistake of removing the domain access-related fields from content types when that lead to many hard-to-debug errors so I feel we should display a warning when a user attempts to delete the domain fields from a content type.
| Comment | File | Size | Author |
|---|---|---|---|
| #14 | Capture d’écran 2025-12-05 à 09.38.13.png | 66.51 KB | mably |
| #5 | Capture d’écran 2025-09-21 à 19.51.01.png | 40.39 KB | mably |
Issue fork domain-3408521
Show commands
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #2
mably commentedAny suggestions welcome.
Might be related to this issue: #3047514: Logic flaw in grants?
Comment #3
mably commentedUnless new, valuable information is provided, this issue will be closed in 3 months.
Comment #5
mably commentedLooks like you are not supposed to remove the Domain affiliation fields:
Pushed a small MR that improves handling of content types that do not have the domain access fields.
Could probably be merged as it only adds new grants to users with "all domains" permissions or affiliations, so the performance impact should be very limited.
Comment #6
mably commentedComment #10
mably commentedComment #11
mably commentedThis feature should be made optional trough a new configuration option.
Comment #12
mably commentedComment #13
mably commentedNew configuration option added to enable this feature:
Feedback welcome.
Comment #14
mably commentedComment #16
mably commented