Skip to content

Afform: Gate admin PriceFieldValues on Forms - #36434

Open
rbaugh wants to merge 2 commits into
civicrm:masterfrom
rbaugh:afform-visibility-pricefieldvalues
Open

Afform: Gate admin PriceFieldValues on Forms#36434
rbaugh wants to merge 2 commits into
civicrm:masterfrom
rbaugh:afform-visibility-pricefieldvalues

Conversation

@rbaugh

@rbaugh rbaugh commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

Overview

PriceFieldValue has a property that specifies if the value should be public or admin. This is a core setting and the public/admin are defined by default. In QuickForm, these values are hidden on forms when the user does not have edit contribution permission. On Afform, these values are being leaked to the form regardless of the user's permissions.

Before

All PriceFieldValues are shown for a PriceField.

After

PriceFieldValues are limited to the user based on their permission.

Technical Details

In PR #35572 we introduced the ability to use af-if statements for each option, for option based fields. This PR leverages that work and injects an af-if condition on PriceFieldValues that have the visibility_id:name = 'admin'. It then uses the civi.afform.prefill and civi.api.respond to populate a property (has_all_price_options) on each entity, in which a PriceField can be added. The property is only added if the current user has the edit contribution permission. The af-if logic then looks for the property from the prefill/response to determine if it should show the value to the user.

While this does still expose the PriceFieldValue to the af-entity rendered to the browser, it is at least preventing the select option/radio/checkbox from being rendered if the user doesn't have the correct permission. If for some reason it is exposed or some user can force a submission with the value selected, the submission will enforce the validity of the value in use for the user.

Currently this is also an issue with the base OptionValue, but that is more complex in that we don't know what permission should be applied to each. The basic OptionValue records typically don't even have this field set as the core add/edit screen doesn't even expose the field to the UI. Normally this is only set through something that extends the OptionValue, like PriceFieldValue, or via some API/code generation in which it would be set. We likely need to look at patching those as well, but currently nothing in core is preventing these on any QuickForm either.

cc: @mattwire @colemanw

@civibot

civibot Bot commented Aug 7, 2026

Copy link
Copy Markdown

🤖 Thank you for contributing to CiviCRM! ❤️ We will need to test and review this PR. 👷

Introduction for new contributors...
  • If this is your first PR, an admin will greenlight automated testing with the command ok to test or add to whitelist.
  • A series of tests will automatically run. You can see the results at the bottom of this page (if there are any problems, it will include a link to see what went wrong).
  • A demo site will be built where anyone can try out a version of CiviCRM that includes your changes.
  • If this process needs to be repeated, an admin will issue the command test this please to rerun tests and build a new demo site.
  • Before this PR can be merged, it needs to be reviewed. Please keep in mind that reviewers are volunteers, and their response time can vary from a few hours to a few weeks depending on their availability and their knowledge of this particular part of CiviCRM.
  • A great way to speed up this process is to "trade reviews" with someone - find an open PR that you feel able to review, and leave a comment like "I'm reviewing this now, could you please review mine?" (include a link to yours). You don't have to wait for a response to get started (and you don't have to stop at one!) the more you review, the faster this process goes for everyone 😄
  • To ensure that you are credited properly in the final release notes, please add yourself to contributor-key.yml
  • For more information about contributing, see CONTRIBUTING.md.
PR commands & links...
  • /rebase <branch-name> will rebase your branch and change the base of the PR.
  • /squash will combine all commits (keeping only the first commit messsage).
  • /port <branch-name> will create a copy of this PR against a different branch.
  • /lintroll will automatically fix linting errors, amending commits as needed.
  • retest this please will rerun the tests and rebuild the demo site.
  • 📖 Review standards
  • 🗒️ Review template (brief or verbose)

➡️ Online demo of this PR 🔗

@civibot civibot Bot added the master label Aug 7, 2026
@rbaugh
rbaugh force-pushed the afform-visibility-pricefieldvalues branch from c23f2b4 to 61cf026 Compare August 7, 2026 16:02
@rbaugh
rbaugh force-pushed the afform-visibility-pricefieldvalues branch from 61cf026 to f73d30b Compare August 7, 2026 16:37
@rbaugh

rbaugh commented Aug 7, 2026

Copy link
Copy Markdown
Contributor Author

retest this please

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant