Install

Works with Drupal: ^10.3 || ^11

Using Composer to manage Drupal site dependencies

Alternative installation files

Download tar.gz 17.5 KB
MD5: dc69731a5641e6ce87283d1aee172d68
SHA-1: f655a0d7f9e8149dc3a17b9f120e19d99b0dc6e5
SHA-256: d8f7e62b40a1109d6e11de7b801400b61c0c6286a11a7f577016f4e73b56a1b4
Download zip 26.02 KB
MD5: cf44e70c94502cf59c50ec3e08d71fe1
SHA-1: be7269138ebc78a7bf819ac19be21763a68af2bd
SHA-256: b25bac94ab023ae58dfb371d512f59d0b4ff78477673ab084d5f3bbb8fe1de25

Release notes

The first stable release. It lands five contributor merge requests that had been open since 2021, 2022 and 2024, adds the module's first test coverage, and rebuilds the flag and unflag endpoints on top of JSON:API Resources.

What this module is for

Core JSON:API already exposes flagging entities, so creating and deleting flaggings needs no contrib module. What core cannot do is return flag state as part of the flagged entity. This module adds computed fields so a client fetching an article receives that state in the same response, instead of one filtered request per flag.

Endpoints

POST   /jsonapi/flag/{flag}/{entity_id}    201, the created flagging as a resource object
DELETE /jsonapi/flag/{flag}/{entity_id}    204

{flag} accepts a flag machine name or a uuid. {entity_id} accepts an id or a uuid. Both routes accept every authentication provider enabled on the site, the same set core JSON:API accepts.

Before the endpoints will answer

Core sets jsonapi.settings.read_only to TRUE by default, which makes both endpoints return 405. Turning it off is a site wide decision affecting every JSON:API write, not only this module's, so weigh it rather than flipping it. The README explains this in full.

The flaggable must be viewable

Both endpoints now answer 404 when the requesting account cannot view the entity being flagged. This is stricter than the unreleased patch that circulated in 2024, and it bites in places worth knowing: a flag targeting user breaks for accounts without access user profiles, and anonymous flagging breaks wherever anonymous lacks access content.

Created by: introfini
Created on: 28 Aug 2026 at 09:44 UTC
Last updated: 28 Aug 2026 at 09:44 UTC
Bug fixes
New features

Other releases