Full pre-release audit of 1.x since 1.0.0-alpha13, over 645 PHP files, 31 submodules, 34 documentation pages and 34 translation files. Every linter is green at the audited commit (PHPStan at level 3, phpcs with Drupal and DrupalPractice, cspell, composer validate), so as with the alpha13 audit none of the findings below were visible to tooling.

Security: no defects, one gap now closed

The parts that carry the risk hold up. All 88 entity queries declare accessCheck explicitly. The interaction capability token, which is the whole anonymous-access surface, signs instance, optional token and expiry into one HMAC keyed by the private key and the hash salt, compares with hash_equals(), and validates every component with ctype_digit. The three routes with _access: TRUE are gated on that token in the controller and carry Referrer-Policy: no-referrer and no_cache. There is no unserialize, no interpolated SQL and no |raw in a template; the one concatenated XPath rejects anything that is not an NCName first, and both Markup::create() calls escape or run Xss::filterAdmin() first. Every permission carries restrict access: true except the three that are deliberately user-facing.

The gap was that nothing validated the configuration: not one of the six config types declared FullyValidatable, so a value the engine cannot act on saved without complaint and failed later, at runtime, in a queue worker. All six now do, the three settings objects and the three config entities, and turning it on immediately found two defects nothing else had.

  • A node's config key was required by the schema, but a start, end or gateway node runs no task and carries no task settings. 81 violations across every workflow on the site, all of them the schema's fault. Its sibling keys (split, join, assignments, status) were already declared optional; this one was missed.
  • example_content_review shipped without execution_mode, alone among the fifteen shipped workflows. The accessor falls back to 'default', which is exactly why nothing caught it.

Verified both directions afterwards: 23 shipped config files and 29 active config objects validate with no violations. The shipped-file check supplies the uuid a config entity gains at install, because an install file that omits one is correct; without that it reports 21 violations that are an artifact of the check rather than of the config.

Translations: 164 strings never translated

Measured in both directions, with the right tool for each. potx extracted 1431 strings from 577 files (a run that finds none is a crashed run, so the count matters), and a plain substring search over the tree answered the other direction.

  • 164 strings had no French at all, almost all of them config schema and info file labels, which is what the Config Translation and Views UIs show. They are translated, using the vocabulary already established in the shipped files (jeton, nœud, échéance, délai d'expiration, issue, affectation, conservation).
  • Five placeholder-only strings are deliberately left alone: @name, @state, @node (#@id), @node: @outcome and @label (@variables) carry no words, so a French msgstr identical to the msgid would add nothing and an empty one correctly falls back.
  • Nothing is stale: all 97 entries potx does not extract are still live strings in the tree, so none may be pruned. A further 71 apparently-missing strings are logger messages, correctly absent from a .po file.
  • The two model editors disagreed on their own vocabulary: orchestra_cm said "Jonction (entrante)" and "Division (sortante)" where orchestra_modeler said "Jointure (entrant)" and "Division (sortant)", so the same two labels read differently depending on which editor was open, and the modeler pair did not agree in gender either. Both now use the orchestra_cm wording.

Accessibility

Four data tables rendered with no #caption: the task inbox, the delegations listing, the pending operations table and the workflow version list. A screen reader announced those as unlabeled tables, and the delegations one now names which of its three tabs it is showing. What was already right stays right: the inert payment control keeps the role that makes its aria-disabled mean anything, and the status and lifecycle markers both carry a text label, so no state is conveyed by color alone.

Documentation

docs/timers.md explained the payment backstop by saying such a workflow "used to draw a release step on an outgoing edge". Documentation describes the design that exists, not the one that was replaced before any release. docs/metrics.md is regenerated from the current tree.

Performance: nothing to fix

Checked for the usual shapes and found none surviving. The delegations listing and the task inbox both batch-preload the accounts their rows name, and every remaining entity load inside a loop is a config entity served from the static cache.

Also in scope

domain_extras published a 4.x branch on 2026-08-22 declaring ^11.4 || ^12, so it no longer has to be forced onto Drupal 12 by the lenient plugin on the next-major lane. Widening the development requirement and dropping the entry is the same move domain itself got in #3618602: Declare Drupal 12 compatibility, so a dependent's next-major lane resolves instead of failing on orchestra's core pin.

Deliberately not changed

The DrupalPractice warning on orchestra_views.routing.yml is a false positive: the route is a read-only menu overview rendered by core's own SystemController::systemAdminMenuBlockPage, and core gates its identical routes on the same "access administration pages". It stays as it is.

AI-Generated: Yes (Claude Code was used to run this audit, to draft this summary and to write the fixes. I reviewed them, and the findings are each backed by a measurement quoted above.)

Issue fork orchestra-3618619

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

mably created an issue. See original summary.

mably’s picture

Title: Pre-release audit since alpha13: 163 strings never translated, configuration nothing can validate, tables a screen reader cannot name, a doc describing a design that was replaced, and domain_extras still forced onto Drupal 12 » Pre-release audit since alpha13: 164 strings never translated, configuration nothing could validate, a node key the schema wrongly required, tables a screen reader could not name, and domain_extras still forced onto Drupal 12
Issue summary: View changes

  • mably committed dce054f7 on 1.x
    task: #3618619 Pre-release audit since alpha13: 164 strings never...
mably’s picture

Status: Active » Fixed

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.