Issue #3618619: Pre-release audit since alpha13: 164 strings never translated, configuration nothing could validate, tables a screen reader could not name, a doc describing a design that was replaced, and domain_extras still forced onto Drupal 12

Full pre-release audit of 1.x since 1.0.0-alpha13, plus the domain_extras update. Every linter was green at the audited commit, so none of this was visible to tooling.

Security. No defects. All 88 entity queries declare accessCheck; the interaction capability token signs instance, optional token and expiry into one HMAC and compares with hash_equals(); the three open routes are token-gated in the controller behind no_cache and Referrer-Policy: no-referrer; no unserialize, no interpolated SQL, no |raw; the one concatenated XPath rejects non-NCNames first. What was missing was validation: the three settings objects are now FullyValidatable, so a value the engine cannot act on is refused at save instead of failing later in a queue worker. The shipped defaults validate clean.

Translations, the largest finding. The French was presented as complete and was not: 164 strings had no translation at all, almost all config schema and info labels, which is exactly what the Config Translation and Views UIs show. All 164 are translated, using the vocabulary already in the shipped files (jeton, nœud, échéance, délai d'expiration, issue, affectation, conservation). Five placeholder-only strings (@name, @state, @node (#@id), @node: @outcome, @label (@variables)) are deliberately left alone. Nothing was stale: all 97 entries potx does not extract are still live strings, so none were pruned. Separately, the two model editors disagreed on their own vocabulary, orchestra_cm saying "Jonction (entrante)" where orchestra_modeler said "Jointure (entrant)"; both now use the former, which is also the one that agrees in gender.

Accessibility. Four data tables rendered with no caption (task inbox, delegations, pending operations, workflow versions), so a screen reader announced them unnamed. The delegations table names which of its three tabs it is showing. The alpha13 aria-disabled fix is intact and no state is conveyed by color alone.

Documentation. docs/timers.md explained the payment backstop by what a workflow "used to" draw; documentation describes the design that exists. docs/metrics.md is regenerated.

Performance. Nothing to fix. The delegations listing and the task inbox both batch-preload the accounts their rows name, and every remaining in-loop entity load is a config entity from the static cache.

domain_extras published a 4.x branch declaring ^11.4 || ^12, so it comes off the lenient allow list and the requirement admits it, as domain did in [#3618602].

Two things deliberately not changed. The DrupalPractice warning on orchestra_views.routing.yml is a false positive: the route is a read-only menu overview rendered by core's own SystemController::systemAdminMenuBlockPage, and core gates its identical routes on the same access administration pages. And an existing site whose active config predates a settings key has to gain it before it validates; the shipped defaults are complete, and the reinstall path this alpha series uses covers it.

Verification. PHPStan level 3 clean, phpcs clean (Drupal and DrupalPractice), msgfmt --check clean on all 34 .po files with no run-together entries, potx re-run confirming only the five deliberate keeps remain, and the affected kernel classes green locally.

Merge request reports

Loading
Loading