Problem/Motivation

A generation writes the classes of the endpoints, their permissions, and the endpoints and structures of the model - and stops short of the one thing that makes an endpoint answer: the REST resource configuration. A generated endpoint is a registered plugin that nothing has switched on, so it has no route and does not appear in the OpenAPI description. A site that generates its API finds nothing to call until somebody enables forty resources by hand.

The other direction is worse, because it fails later and elsewhere. When the model changes and an endpoint leaves the plan, the generation removes its class and its permission, but a resource configuration that was switched on for it stays, naming a plugin that is gone, and the roles that were granted its permission keep a permission that no module provides. The cache rebuild survives the first since the configuration of a missing plugin is loaded disabled, but the configuration export carries it for ever, and a role holding an unknown permission cannot be saved: the next edit of that role, or the next configuration import, fails. The order matters as much: a class removed while its configuration is still enabled is exactly the broken router this module already had to guard against once.

Proposed resolution

  • A generation that adds an endpoint writes its REST resource configuration as well - the methods its kind answers, the formats and the authentication of this site - owned by the generator the way the endpoints and structures of the model are: a configuration a person changed is left as it is and named.
  • An endpoint that leaves the plan is retired in one order and in one place: its configuration disabled, its permission revoked from every role that holds it, the configuration removed, and only then its class and permission. Each step is reported.
  • Retiring is a breaking change, so it waits in the change queue like any other; a generation run with the explicit option retires what it removes. A frozen or overridden endpoint is never retired silently.
  • A resource configuration this site wrote for a generated endpoint by hand, or changed, is not deleted: it is disabled and named, and the person decides.
  • Coverage that generates an endpoint, enables it, grants its permission to a role, regenerates from a model without it, and asserts that the caches rebuild, the route is gone (404, not 500), the role can be saved, the configuration export no longer names the endpoint, and the configuration can be imported on a fresh site.

Remaining tasks

Everything.

Issue fork myrest-3624015

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

sergeydruua created an issue. See original summary.

  • sergeydruua committed 83f6f5b5 on 1.0.x
    Issue #3624015: Switch the REST resources of generated endpoints on and...
sergeydruua’s picture

Status: Active » Fixed

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

sergeydruua’s picture

Status: Fixed » Closed (fixed)