Problem/Motivation

It's right there in black-and-white, my friends: https://git.drupalcode.org/project/drupal/-/blob/main/core/lib/Drupal/Co...

If we're in the middle of a site installation, a recipe's installed config is not validated. This means you can sneak bad config into a site via a recipe that is out of date (or, worst-case scenario, actively malicious).

Proposed resolution

We need to validate config when installing from a recipe.

We can't really do it whilst applying the recipe, because config is shifting around us. But we could maybe do it a separate, specific step of a recipe-based installation.

Comments

phenaproxima created an issue. See original summary.

phenaproxima’s picture