Problem/Motivation
This module removes a resource from the plugin definitions in three cases: the optional module it declares is not installed (myrest_requires_module), the convention role it needs is not filled in (myrest_requires_role), and the bundle it serves does not exist. Removing it is the right answer - an endpoint that cannot work should not be registered, documented, or something a site has to know to switch off.
It is only safe while nobody has enabled that resource. Once a site has a rest_resource_config entity for it, removing the definition does not remove the endpoint: it breaks the router. ResourceRoutes::getRoutesForResourceConfig() calls $rest_resource_config->getResourcePlugin() with no guard, so a configuration entity naming a definition that is no longer there throws PluginNotFoundException out of the route rebuild. The whole site then fails to rebuild its caches - not the endpoint, the site.
Measured while working on the form submission base class: dropping one resource whose configuration was enabled made drush cr exit with an error, and the route it left behind answered 500 rather than 404.
The three existing cases reach it the same way. A site that has the endpoints enabled and then uninstalls the optional module, empties the counter role, or removes the bundle gets a broken cache rebuild instead of an endpoint that quietly went away.
Proposed resolution
- Decide what a removed definition means for a configuration entity that names it, and do that in one place rather than per case: either disable the configuration alongside the definition, or leave the definition and refuse at the endpoint.
- Whichever is chosen, an enabled configuration entity naming a missing plugin must not be able to break the route rebuild.
- Coverage that enables a resource, removes the reason it was registered, and asserts that the caches still rebuild and that the endpoint answers 404 rather than 500.
Remaining tasks
Everything.
Issue fork myrest-3622945
Show commands
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #4
sergeydruua commentedComment #6
sergeydruua commented