Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: Views Bootstrap 5.5.4 — Minor update available for module views_bootstrap (5.5.4). Release: Rightup theme 1.0.3 — Minor update available for theme vartheme_bs5_rightup (1.0.3). Release: CommentOn 1.0.6 — Minor update available for module commenton (1.0.6). Release: ChatGPT Ads 1.0.3 — Minor update available for module chatgpt_ads (1.0.3). Release: Opensolr Search 5.1.3 — Minor update available for module opensolr_search (5.1.3). Release: ServiceM8 Webform Integration 1.2.1 — Minor update available for module servicem8_webform (1.2.1). Release: PostfixAdmin 1.0.0 — Initial release available for module postfix_admin (1.0.0)! Release: ip_analyser 1.0.3 — Minor update available for module ip_analyser (1.0.3). Module Revived: Swagger-PHP OpenAPI 3 documentation generator 1.0.0 — Module swagger_php updated after 10 months of inactivity (1.0.0). Security Coverage: Microsoft Azure AI — Module ai_provider_azure now has official Drupal security advisory coverage.

This module is intended for site administrators. The module allows site administrators to block certain module from being installed, based on a blacklist set on settings.php file.

Who is this for?

Drupal 8 comes with the powerful Configuration Management (CM) system and modules like config_split and readonlymode can helps the sites administrators to control the modules that are being installed and configured through the environments. But sometimes, only basing your administration on CM could be not enough, since the users could have access to the config files and hooks like `hook_update` to enable certain non-desired modules programmatically.

The idea behind of this module is to provides more one additional security layer allowing you to define and control a blacklist of modules that you don't want to get installed at your environment(s).

Usage and configuration

This module does not offer an administrative form, instead, its configuration must be made directly in the settings.php file through the variable $settings['module_blacklist'] to define the list of modules that you want to block the installation.

settings.php:

$settings['module_blacklist'] = [
  'devel',
  'simpletest',
  'migrate_drupal_ui',
];

Why use settings.php instead of an admin form to save the blacklist?
The purpose of the settings.php file is to be specific to environments, read-only and protected from users, so keep the list on there is more secure than configs, where could be replaced. $settings variables are read-only/Immutable.

Once the list is defined, any attempt to enable the listed modules will throw an
exception and the process will terminate.

Also, the module alters the core admin form that list the available modules at
/admin/modules disabling the checkboxes and adding a warning message to the
blacklisted modules.

Drush bypass

By design, any kind of attempt to enable the blacklisted modules will throw an exception and kill the process, even using Drush. If you want to allow Drush to enable modules (drush pm-enable <module>), add this settings to your settings.php:
$settings['module_blacklist_drush'] = TRUE;

TODO

- Implement tests

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
1
Tracked since
Mar 2023
Latest release
3 years ago
Releases (12 mo)
0
Maintenance
Dormant

Releases

Version Type Core Release date
8.x-1.0-alpha4 Pre-release Mar 28, 2023