Problem/Motivation
On a content entity page, the Navigation top bar shows the "More actions" (three dots) toggle even when the current user has access to none of that page's local tasks. The toggle opens a dropdown with nothing in it, so it reads as a broken control.
Empty array was handled in #3538236: Empty top bar actions dropdown
Steps to reproduce
- Install a site with the Navigation module enabled.
- Create a role with access navigation and access content, and nothing that grants access to a node's local tasks — no edit, no delete, no revisions, no layout. Assign it to a user.
- As that user, view any node.
- The three dots "More actions" toggle is in the top bar. Open it: the dropdown is empty.

It is easiest to see on an entity whose local tasks all sit behind one administrative permission. On an Entityqueue subqueue page, for example, every page action belongs to administer entityqueue, so any editor who can reach the queue but not administer it gets the toggle with an empty menu.
Proposed resolution
Filter the local tasks by #access in NavigationRenderer::getLocalTasks(), where the array is built, rather than leaving it to render time.
The access result of each excluded task is added to the top bar's cacheability first, so the toggle appears again for a user who does have access, and the result still varies correctly by permissions.
Doing it here rather than in the template also fixes the second half: with no accessible page actions, hasLocalTasks() is now false, so ::removeLocalTasks() leaves the regular tabs block alone instead of hiding it in favour of a top bar that shows nothing.
Remaining tasks
User interface changes
- The top bar "More actions" toggle is no longer shown to a user who has access to none of the page's local tasks. It is unchanged for everyone else.
API changes
Data model changes
Release notes snippet
| Comment | File | Size | Author |
|---|---|---|---|
| #8 | top-bar-page-actions-toggle.png | 18.18 KB | rajab natshah |
Issue fork drupal-3622837
Show commands
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #3
rajab natshahComment #4
rajab natshahComment #5
smustgrave commentedIS and MR is too much like AI and should be written by a human please
Comment #6
smustgrave commentedIssue needs to be against main so needs work for that but really should be updated by a human
Comment #7
rajab natshahYou are right Stephen,
My AI Agent did that.
working on the
Comment #8
rajab natshahComment #9
rajab natshah