Closed (fixed)
Project:
Experience Builder
Version:
0.x-dev
Component:
Internal HTTP API
Priority:
Major
Category:
Task
Assigned:
Unassigned
Issue tags:
Reporter:
Created:
12 Jun 2025 at 20:30 UTC
Updated:
21 Jul 2025 at 14:59 UTC
Jump to comment: Most recent
Comments
Comment #2
penyaskitoPost-poned on #3529836: Enable starting with an empty XB UI (so without first having to create an entity with a component tree)
Comment #3
wim leers🤔 Shouldn't this be the other way around, i.e. this before #3529836? Because of:
Devil's advocate: why this permission? Only for #3529836? It's not one of the permissions @lauriii prescribed?
Comment #4
penyaskitoI doubted to be honest. But without #3529836 this will be hard to write tests for, while #3529836 can still use 'access administration pages' as we are doing now.
Why a new permission? Because we could use "Create Pages (for Page content entities)", but we might have XB enabled for other content entities and a user might not have permission to create pages but to edit e.g. articles. And I'm assuming here that the XB UI will be able to create any enabled XB content type from blank.
An alternative is another route access check that checks if I have permissions for any XB-enabled content.
Comment #5
penyaskitoThis will be probably the solution we will go for, so changed the title + IS
Comment #7
wim leersI think we have an alternative solution for #4 over at #3529836-7: Enable starting with an empty XB UI (so without first having to create an entity with a component tree) 😊
I'm pretty sure @lauriii specifically wanted to AVOID this kind of permission.
So then this is the generalization of #3529836-7: Enable starting with an empty XB UI (so without first having to create an entity with a component tree), for much later!
Comment #8
wim leers@penyaskito's work at #3529895: Provide the client with `create` operation access information similar to #3516657 inspired me and made me realize a connection: the
\Drupal\Core\Entity\EntityFieldManagerInterface::getFieldMapByFieldType()-based logic he wrote for\Drupal\experience_builder\Controller\ExperienceBuilderController::getContentEntityCreateOperations()is what #3529836: Enable starting with an empty XB UI (so without first having to create an entity with a component tree) needs as the long-term solution, rather than the pragmatic interim linked in #7.Combine the pattern of #3529895 with the logic in
ComponentTreeEditAccessCheck(from #3516432: Update all XB routes to respect content entity update/field edit access of edited XB field), and I think we have a solution!Comment #10
wim leersResponse for
/xb/api/v0/config/componentwhen accessing as not just the anonymous user, but also an authenticated user that for example can only edit Media entities, but not Pages nor article nodes:Comment #11
penyaskito@Wim at #8: This is exactly what I was envisioning in #3452581-54: [META] XB Permissions!!!
Comment #12
wim leersHah! 😄 Great minds … 🥸
Comment #14
penyaskitoComment #15
penyaskitoComment #16
wim leersComment #17
wim leersNote that while reviewing #3522488: Follow-up for #3518292: `ApiContentControllers::list()`: search should exclude entity query matches for entities with auto-save data, I noticed this MR should also update
Because
makes no sense — it was a useful interim step, but what this issue is doing is more appropriate :)
Comment #18
wim leersComment #19
wim leersDiscussed with @effulgentsia and @penyaskito — @effulgentsia agrees this should be beta-blocking.
Comment #20
penyaskitoComment #21
penyaskitoAssuming the last failure is a cypress random failure, which I'm retrying, this should be ready for review.
Comment #22
wim leersMaybe I'm missing something, but these changes don't quite make sense to me? 😅
Comment #23
wim leersNeeds reroll after #3492722: Update XB to require Drupal 11.2 🙏
Comment #24
isholgueras commentedworking on the reroll
Comment #25
isholgueras commentedReroll done.
Comment #26
wim leers@penyaskito is working to address https://git.drupalcode.org/project/experience_builder/-/merge_requests/1... 👍
Comment #27
penyaskitoFixed logic.
There is one cypress test that requires the permission to pass, but I can't reproduce locally (but test fails locally too).
Comment #28
larowlanLooks good to me, found one minor nit and self-addressed it.
Comment #29
wim leersJust triaged #3533461 and found it to be blocked on this: #3533461-5: Only users with "edit" operation access to code components can see previews with auto-saved code components.
Comment #30
wim leersFound only one problem: half a dozen remaining occurrences of the
access administration pagespermission. Refactored them all away. Was trivial thanks to the infrastructure (and examples!) in this MR 😊👍Echo'ing @larowlan's RTBC — this is so long overdue, and feels great to finally get XB to this point! 😊 Thanks, @penyaskito!
Comment #31
wim leersGot
navigation.cy.jsto green — it had previously implicitly (and inappropriately) been relying on theaccess administration pagespermission, simply to use/admin/configas the "last visited URL" for the "Exit XB" functionality.Merging at last… 🚢🥳
Comment #33
wim leers