Overview
Encountering an issue when trying to publish changes: "The current user is not allowed to update the field 'changed'."
Although logged in as an Admin and the article was created by the same user, still unable to publish the changes. This issue is only with node and not with xb_page.
Request payload :
{ "node:1:en": { "entity_type": "node", "entity_id": "1", "data_hash": "a73b1168aa056125", "langcode": "en", "owner": { "name": "admin", "avatar": null, "uri": "/user/1", "id": 1 }, "label": "Article", "updated": 1752566801 } }
Response :
[ { "detail": "The current user is not allowed to update the field 'changed'.", "source": { "pointer": "entity_form_fields.changed" }, "meta": { "entity_type": "node", "entity_id": "1", "label": "Article", "api_auto_save_key": "node:1:en" } } ]
Console error :
{ "status": "422", "errors": { "errors": [ { "detail": "The current user is not allowed to update the field 'changed'.", "source": { "pointer": "entity_form_fields.changed" }, "meta": { "entity_type": "node", "entity_id": "1", "label": "Article", "api_auto_save_key": "node:1:en" } } ] }, "message": "The current user is not allowed to update the field 'changed'." }
Likely cause
ui/src/components/review/UnpublishedChanges.tsx sends changed: Math.floor(new Date().getTime() / 1000) and \Drupal\experience_builder\ClientDataToEntityConverter::setEntityFields will throw an access violation of that is equal to server request time. For details see https://git.drupalcode.org/project/experience_builder/-/merge_requests/1...
Proposed resolution
Since \Drupal\Core\Entity\ContentEntityForm::updateChangedTime set the changed time for almost all content entities the client changed will almost always have no affect on the actually value set for changed. Even if updateChangedTime it would be very likely that changed would somehow be set in the form submission process.
For that reason for entities that implement EntityChangedInterface we should in this ignore the value that is sent by the client and just let the form logic take care of setting changed
User interface changes
| Comment | File | Size | Author |
|---|---|---|---|
| #16 | xb_revision_debug.zip | 3.4 KB | tedbow |
| Screen Recording 2025-07-15 at 1.42.44 PM.mov | 20.54 MB | mayur-sose |
Issue fork experience_builder-3536040
Show commands
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #2
tedbow@mayur-sose This is random error correct? Or does this happen on all nodes all the time?
Comment #3
tedbowAlso does it happen for others with less permissions but who are still able to publish
Comment #4
larowlanI have seen this regularly in e2e tests - example - https://git.drupalcode.org/project/experience_builder/-/jobs/5966903#L4919
It appears to be random - as doesn't occur on re-test - but that might indicate its a race/timing issue - and being related to 'changed' that feels likely as some time passing may be the trigger.
Comment #5
larowlanSeeing this again in CI today https://git.drupalcode.org/project/experience_builder/-/jobs/5979572#L1351
Comment #6
isholgueras commentedAfter debugging a bit, I think it's because of this piece of code in
ClientDataToEntityConverterhttps://git.drupalcode.org/issue/experience_builder-3536247/-/blob/35362...
There is a case when the
$form_updated_changed_fieldvalue is not TRUE so is set to the original field, and the opposite. I still working on how to reproduce it reliably.Comment #7
wim leersAFAICT
\Drupal\Core\Entity\EntityChangedTrait::setChangedTime()is only called by tests, except for in one main spot and 3 spots in total:\Drupal\Core\Entity\ContentEntityForm::updateChangedTime()(which is what we're hitting)\Drupal\Core\Entity\Form\RevisionRevertForm::prepareRevision()\Drupal\Core\Action\Plugin\Action\SaveAction::execute()Related: shouldn't we remove all our explicit checks for
'changed'the field NAME and switch it over to checking'changed'the field TYPE? 😅Comment #8
isholgueras commentedComment #9
tedbowOne thing I noticed in 0.x is that it does not seem that change time is ever updated
With node or page
If you look at the entity revisions list and the time is the same for all revisions
Comment #12
bnjmnmI tested a theory in the branch
3536040-ensure-unique-changedand it may have fixed it. I can't be 100% sure as I've only run it ~10 times so far and there's only one e2e running to make things faster, but it has yet to fail.Although I couldn't reproduce locally, I ran logs on
UnpublishedChanges.tsxand the manually createdchangedvalue was sometimes only 1 different from the existing one. This had me wondering if there are instances where, the value set could be identical to the prior one - if that were the case then$form_updated_changed_field = $changed_timestamp_int !== ((int) $entity_form_fields['changed']);might be FALSE and an unworthychangeddoes not get the desiredcontinue;treatment.Comment #13
tedbow#9 is probably unrelated. opened another issue #3537709: Revision created timestamp not updated when editing in XB
Comment #15
tedbow@bnjmnm thanks for the investigation.
I originally wrote the logic around "changed" I think I made it overly complex to cover edge cases that probably won't happen
I think basically 2) is very unlikely to happen so1) is not needed. Even if 1 was needed 3) means there would probably other implications to consider
So made an MR to ignore "changed" from the client. https://git.drupalcode.org/issue/experience_builder-3536040/-/tree/35360...
Comment #16
tedbowHere is little debug module to get around the problem in #3537709: Revision created timestamp not updated when editing in XB so you can see when testing the changed time is actually still updated
Comment #17
tedbowI think issue summary needs to be updated. I can do that tomorrow but until then this is where I think it stands
I detailed in the problem and why @bnjmnm's MR could still result in random fails in test in comments here https://git.drupalcode.org/project/experience_builder/-/merge_requests/1...
I do think now the proper solution is ignore the "
changed" value from the client because was always being ignore except to determine if access was going to be checked. That is done in my MR https://git.drupalcode.org/project/experience_builder/-/merge_requests/1351. I have explained the reasoning of why I think it is ok in #15It would be possible to write a test by mocking the request time, through a new class like
\Drupal\update_test\Datetime\TestTime::getRequestTimeand have the client send in the same timestamp. This should result in access error in 0.x but not in https://git.drupalcode.org/project/experience_builder/-/merge_requests/1351Comment #18
tedbowUpdated the summary based on this MR https://git.drupalcode.org/project/experience_builder/-/merge_requests/1351
It doesn't require any front-end changes but it would probably be good idea for the front-end to also stop sending
changedbut it could be in follow-upComment #19
isholgueras commentedAfter reviewing both MR, I think I feel mor comfortable with MR 1351 (ignoring
changed). https://git.drupalcode.org/project/experience_builder/-/merge_requests/1351.Agree, but I think you're covering it well by ignoring
changed.Comment #20
f.mazeikis commentedAfter reviewing and testing, I agree with @isholgueras that for time being MR1351 seems like a better solution.
Comment #23
wim leershttps://git.drupalcode.org/project/experience_builder/-/merge_requests/1... is … 🤪😄
Glad to see this one done :) Closed https://git.drupalcode.org/project/experience_builder/-/merge_requests/1350.
Comment #24
mayur-sose commentedVerified below scenarios :
Create a new Article node.
Edit the Article.
Attempt to publish changes.
As Admin, edit the Article.
Attempt to publish changes.
No "changed" field error; operation completes successfully.
Edit xb_page.
Publish changes.
Create and edit an Article node.
Publish.
View "changed" field value/time before and after.