Problem/Motivation

On a content entity page, the Navigation top bar shows the "More actions" (three dots) toggle even when the current user has access to none of that page's local tasks. The toggle opens a dropdown with nothing in it, so it reads as a broken control.

Empty array was handled in #3538236: Empty top bar actions dropdown

Steps to reproduce

  1. Install a site with the Navigation module enabled.
  2. Create a role with access navigation and access content, and nothing that grants access to a node's local tasks — no edit, no delete, no revisions, no layout. Assign it to a user.
  3. As that user, view any node.
  4. The three dots "More actions" toggle is in the top bar. Open it: the dropdown is empty.

screenshot for the issue

It is easiest to see on an entity whose local tasks all sit behind one administrative permission. On an Entityqueue subqueue page, for example, every page action belongs to administer entityqueue, so any editor who can reach the queue but not administer it gets the toggle with an empty menu.

Proposed resolution

Filter the local tasks by #access in NavigationRenderer::getLocalTasks(), where the array is built, rather than leaving it to render time.

The access result of each excluded task is added to the top bar's cacheability first, so the toggle appears again for a user who does have access, and the result still varies correctly by permissions.

Doing it here rather than in the template also fixes the second half: with no accessible page actions, hasLocalTasks() is now false, so ::removeLocalTasks() leaves the regular tabs block alone instead of hiding it in favour of a top bar that shows nothing.

Remaining tasks

User interface changes

  • The top bar "More actions" toggle is no longer shown to a user who has access to none of the page's local tasks. It is unchanged for everyone else.

API changes

Data model changes

Release notes snippet

CommentFileSizeAuthor
#8 top-bar-page-actions-toggle.png18.18 KBrajab natshah

Issue fork drupal-3622837

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

rajab natshah created an issue. See original summary.

rajab natshah’s picture

Issue summary: View changes
rajab natshah’s picture

Status: Active » Needs review
smustgrave’s picture

IS and MR is too much like AI and should be written by a human please

smustgrave’s picture

Version: 11.x-dev » main
Status: Needs review » Needs work

Issue needs to be against main so needs work for that but really should be updated by a human

rajab natshah’s picture

You are right Stephen,
My AI Agent did that.
working on the

  • Reviewed by human
  • Code review by maintainers
rajab natshah’s picture

Issue summary: View changes
StatusFileSize
new18.18 KB
rajab natshah’s picture

Issue summary: View changes