Prevent saving config entities when configuration overrides are applied
Problem/MotivationThe underlying config system strictly separates between loading with overrides and loading an editable config that can be saved.The config entities doesn't do that. It supports...
View ArticleDrupal DateTime have no render to json_encode
Problem/MotivationDateTimePlus doesn't implement \JsonSerializable, so json_encode(new DateTimePlus()) just returns an empty object.There are different reasons why it would be interesting to add this...
View ArticleAdd dblog-specific permissions to control access to dblog routes
Problem/MotivationWhile creating reports for some of the users on one of the sites I'm currently working on, I realized that they should be reachable from the Reports menu, not the Content menu, which...
View ArticleDeprecate table names from entity definitions
Updated: Comment #0@plach came up with this idea, so kudos go to him.Problem/MotivationThe names of the entity tables for entity types are exposed in the entity type annotation even though, they really...
View ArticleImageUrlFormatter HTML-escapes ampersands in image style URLs when a second...
Problem/MotivationThe "URL to image" formatter (ImageUrlFormatter) returns the URL as a plain string in #markup. Renderer::ensureMarkupIsSafe() passes any non-MarkupInterface#markup through...
View ArticleDrupal Usability Meeting 2026-10-02
This meeting takes place every Friday at 14:00 UTC (currently 7:00am PT, 10:00am ET). See Time.is to see what that is in your timezone.The meetings are held using Zoom, and a link is posted in the #ux...
View ArticleIndicate in form error messages when error is sidebar
Problem/MotivationThe usability team recommends adding some indicators to form validation error messages in the top status message area when the invalid field is in the advanced sidebar. The reason is...
View ArticleThe field name is not displayed in LinkWidget error messages
Problem/MotivationThe LinkWidget validation callback error messages do not include the field name. If an entity form has multiple Link fields, then it may be difficult to tell which instance had the...
View ArticleDrupal Usability Meeting 2026-10-09
This meeting takes place every Friday at 14:00 UTC (currently 7:00am PT, 10:00am ET). See Time.is to see what that is in your timezone.The meetings are held using Zoom, and a link is posted in the #ux...
View ArticleIdentify code that needs deprecation and removal for custom file extension...
Problem/Motivation.theme, .module, and soon .profile file extensions have been deprecated. There is a lot of code supporting these, we should identify what code can be dropped once we remove...
View ArticleRemove obsolete, empty and hidden Navigation Top Bar module
Problem/Motivationcore/modules/navigation/modules/navigation_top_bar is an obsolete empty module with just an info file. It used to be a feature flag module for the top bar in navigation. Not needed...
View ArticleRemove search module coverage from robots.txt
Problem/MotivationWhile writing Drupal 12 release notes it came up that robots.txt still contains coverage for the removed search module. This should also be removed.Steps to reproduceProposed...
View ArticleAllow recipe to add multiple buttons to CKEditor toolbar
Problem/MotivationWhen using `addItemToToolbar` currently you can only add a single toolbar item to CKEditor within one recipe. We need something like `addItemsToToolbar` that would accept an array of...
View ArticleRemove the Search module
Problem/MotivationRemaining tasksPostponed on #3595089: Remove the Olivero theme and may need a rebase when that is committed.The change record for this issue should include a link to recommendations...
View ArticleAdministrator cannot access to temporary files without usage that are owned...
Problem/MotivationAdministrator cannot access to temporary files without usage that are owned by other usersSteps to reproduce1. Create a image field in content type. 2. Create a node and upload a...
View ArticlePotential race condition in container rebuilds
Problem/MotivationIn #3592577: Ensure that hook attributes are never parsed from a stale opcache we added an opcache_invalidate() call during hook parsing to ensure that hooks can never be parsed from...
View Articlehook_field_*_third_party_settings_form() is called for every field on the...
Problem/MotivationThe hook_field_formatter_third_party_settings_form() and hook_field_widget_third_party_settings_form() hooks are invoked for every field on the Manage Display page, even though none...
View ArticleDisallow dangerous filenames e.g. command injection characters
Problem/MotivationFollowing discussion with the Drupal Security Team, it was agreed that this could be handled in a public "security improvements" issue.At present Drupal's file API allows filenames to...
View ArticleAllow override of page cache response policies, specifically NoServerError
Problem/MotivationWe have designed our own public API that can result in very long DB queries.We get a lot of hammering from bots and AI agents, which means we end up with a lot of those long DB...
View Article