Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: MCP Sentinel 2.29.0 — Minor update available for module mcp_sentinel (2.29.0). Release: Audit Chain 1.10.9 — Minor update available for module audit_chain (1.10.9). Release: Menu Autopilot 1.4.7 — Minor update available for module menu_autopilot (1.4.7). Release: FileGate 1.11.3 — Minor update available for module file_gate (1.11.3). Release: Download Tracker 1.0.7 — Minor update available for module download_tracker (1.0.7). Release: Directory2Block Slideshow 1.0.8 — Minor update available for module directory2block_slideshow (1.0.8). Release: Mautic Audiences 1.1.5 — Minor update available for module mautic_audiences (1.1.5). Release: Rightup theme 1.0.3 — Minor update available for theme vartheme_bs5_rightup (1.0.3). Module Revived: Swagger-PHP OpenAPI 3 documentation generator 1.0.0 — Module swagger_php updated after 10 months of inactivity (1.0.0). Security Coverage: Microsoft Azure AI — Module ai_provider_azure now has official Drupal security advisory coverage.

This is a utility module that adds the ability to specify actions that should be taken
on your route when an HttpException occurs on it. A common example would be, when an
access check fails and an AccessDeniedException is returned.

Obviously you can write your own EventSubscriber to handle your case, but I think for
common/straightforward actions (i.e. redirecting the user on an access denied response),
declaring it alongside the route is clearer.

Example - CSRF tokens

One example is if you want to add a CSRF Token to your route, but you'd rather the user
was redirected if this validation fails, rather than being left on an Access Denied page.

Your my_module.routing.yml may look like this:

    my_module.listing_route:
      path: '/my/listing/path'
      defaults:
        _controller: '\Drupal\my_module\Controller\CoolController::listThings'
      methods: [ GET ]

    my_module.action_route:
      path: '/my/listing/path/take_action'
      defaults:
        _controller: '\Drupal\my_module\Controller\CoolController::takeAction'
      methods: [ GET ]
      options:
        on_exception:
         - on:
             - name: '.*AccessDeniedHttpException$'
               message: '.*csrf_token.*'
           then:
             - log: 'Oh noes, this should not happen but it did.'
             - redirect: my_module.listing_route
        requirements:
          _csrf_token: 'TRUE'

Or you could redirect all exceptions regardless of what they are:

    my_module.action_route:
      path: '/my/listing/path/take_action'
      defaults:
        _controller: '\Drupal\my_module\Controller\CoolController::takeAction'
      methods: [ GET ]
      options:
        on_exception:
          - then:
              - redirect: my_module.listing_route

Rules

For an on_exception rule to match at least one of its 'on' conditions must match all
of its conditions.

More than one rule can be specified for the same route. The first rule that matches
will have all of its actions executed.

Todo

If others find this helpful, we should probably refactor this module to use proper
Condition and Action Plugins rather than all the switch statements.

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
2
Tracked since
May 2023
Latest release
2 years ago
Releases (12 mo)
0
Maintenance
Slowing

Releases

Version Type Core Release date
1.0.0-beta4 Pre-release Apr 16, 2024
1.0.0-beta3 Pre-release May 26, 2023