Drupal Planet

Stuart Clark (Deciphered): Druxt Auth 0.5.0; two ways to sign in without leaving your site

Every Druxt site I have built signs people in by sending them somewhere else to do it: out to Drupal's login page, on to a consent screen, and eventually back. With Druxt Auth 0.5.0 the username and password can now be handled entirely in the frontend instead, either through the authorization code grant or through the password grant.

If you have not used it, Druxt Auth wires Nuxt's auth module to Simple OAuth on the Drupal side. It targets Nuxt 2 today, because @nuxtjs/auth-next does.

The first is the authorization code grant, which now takes credentials directly. Druxt Auth signs the visitor in through Drupal's JSON login route first, so the authorize step finds a session waiting and returns a code without rendering anything:

Continue reading →

Drupal Starshot blog: Drupal CMS 2.2: Multilingual, out of the box

Drupal CMS 2.2.0 is out, and this release is all about multilingual. Setting up a site to publish in multiple languages has always been possible in Drupal, but it was not easy. With 2.2, we've tackled the biggest pain points from the installer through to translating your Canvas pages.

Finding your language in the installer

The first thing you'll notice is the language selector in the installer. Instead of scrolling through a long select list, you can now start typing and search for your language.

It's a small change, but makes for a much better first impression.

Recipe config is now translated

Previously, if you installed Drupal CMS in another language, any configuration provided by recipes (such as content types, fields, views, even the dashboard) would still show up in English. 

Recipes can include translatable configuration and that is now translated along with the rest of the site.

The multilingual recipe

Adding a second language to a Drupal site involves a lot of steps: installing the right modules, configuring language detection, enabling translation for each content type and field, and making sure you haven't missed anything along the way. Most people figure this out through trial and error (and a fair amount of searching).

The new multilingual recipe takes care of most of this for you:

  • Installs the required modules and applies the basic language settings
  • Provides a multilingual setup checklist to guide you through the remaining steps
  • Modifies the content translation settings page to make it more intuitive, including a 'Recommended setup' option that enables translation for the entities most commonly translated (node types, Canvas pages, menu links and taxonomy terms).

Translating Canvas pages

Canvas now fully supports translation and we're using Canvas Translate to provide the translation management within the canvas editor. You can translate any component on a page, and use the Canvas preview to see how the translated version will look before you publish it.

Using the bundled Canvas Translate AI module, you can also get AI-generated translations with one click: either for all components, or individually.

New multilingual demo

Drupal core has long shipped with the Umami multilingual demo, which has community contributed, cooked and photographed recipes. Umami will not be included in Drupal 12 anymore and it was in need of a design rethink and retooling with our new easy to use page building capabilities. This resulted in the new Dashi demo, which brings the same multilingual content to a customizable setup with Canvas page and content templates.

Try it out

Try it out by installing Drupal CMS 2.2.0!

  1. Install DDEV
  2. Run the following commands:
mkdir my-drupal-site && cd my-drupal-site ddev config --project-type=drupal11 --docroot=web ddev composer create-project drupal/cms ddev launchFile attachments:  Screenshot 2026-09-23 at 10.38.37 am.png Screenshot 2026-09-23 at 11.38.36 am.png Screenshot 2026-09-23 at 11.38.22 am.png content-translation.gif

Drupal Association blog: Meet The Drupal Association Team At DrupalCon Rotterdam 2026

DrupalCon Rotterdam 2026 is almost here. The Drupal Association staff and board are heading to the Netherlands next week, and we'd love to see you there!

Photo Credits: Ryan Witcombe

Here's where you'll find us during DrupalCon Rotterdam 2026:

Drupal.org Engineering Panel

Join the DA engineering team for an open and honest look at the current state and future of Drupal.org (the platform the entire community relies on every day). From nearly 10,000 projects migrated to GitLab, plans to support a brand new Drupal.org marketing site, and initiative support for Drupal CMS + Canvas and the AI Initiative, there's a lot to cover. The session closes with an open Q&A, so bring your questions

Day & Date: Wednesday, September 30, 2026

Time: 11:40 to 12:25 CEST

Location: Goudriaan Room I&II

Marketing Panel

Building on the momentum of the Drupal AI initiative, the Drupal Association is growing coordinated advocacy and marketing efforts in new areas, opening the door for more people to get involved and make a visible contribution.

Join the panel to understand how the initiative is taking shape, why they’re gaining traction, and what makes them different. The panelists will discuss how marketing in Drupal is becoming one of the most accessible and high-impact ways to contribute, where individuals and organizations  alike can raise their profile, earn recognition, and help shape Drupal’s future.

Day & Date: Tuesday, September 29, 2026

Time: 16:40 to 17:25 CEST

Location: Goudriaan Room I&II

Drupal Association Public Board Meeting

The DA Public Board Meeting is open to all DrupalCon attendees and is your opportunity to hear directly from the Drupal Association board. Come with your questions, your feedback, and your ideas. This is your chance to engage with the people shaping the future of the Drupal Association.

Day & Date: Tuesday, September 29, 2026

Time: 14:25 – 15:10 CEST

Location: Rotterdam Room I&II

Drupal Association Partner Lunch

An exclusive afternoon gathering for agency leaders and partners to connect with Dries and DA leadership over a seated lunch. A unique opportunity to share strategies, discuss the Drupal business ecosystem, and build meaningful relationships with peers from around the world.

Tickets are required, register here.

Day & Date: Tuesday, September 29, 2026

Time: 12:00 – 13:30 CEST

Location: Postillion Hotel & Convention Centre WTC Rotterdam

Drupal Business Dinner

Cap off Wednesday evening with the Drupal Business Dinner, an intimate gathering of Drupal agency executives for a seated 3-course dinner, a presentation, and meaningful conversations in a beautiful Rotterdam venue.

Tickets are required, register here.

Day & Date: Wednesday, September 30, 2026

Time: 19:00 – 22:30 CEST

Location: De Harmonie, Rotterdam

Photo credits: Matthew Saunders

Whether you're joining us for a session, an exclusive event, or just stopping by our booth to say hello, the Drupal Association team can't wait to connect with you.

The last few days are left to secure your ticket to DrupalCon Rotterdam 2026, if you already haven’t. See You in Rotterdam!

Drupal AI Initiative: Introducing our official Drupal AI Initiative training program: AI Inside Drupal Essentials

As we see our goals for Drupal AI innovation under responsible human guidance flourishing at such a remarkable pace, we recognize a growing community need for practical, responsible ways to learn it. We’re excited to announce, as part of our efforts to fill that need, AI Inside Drupal Essentials (AIDE,) developed and presented by DrupalEasy, as the official training program of the Drupal AI Initiative. 

We’ve partnered with Drupal expert developer and highly respected trainer Mike Anello (ultimike) to ensure the program supports our mission to drive responsible AI innovation and build on Drupal’s position as the leading open-source content management system for AI integration. Mike and the team at DrupalEasy have the commitment and experience to create, maintain and present the curriculum with our standard for ethical, powerful, and accessible AI in the open-source world.

AIDE

AIDE is designed to help you move forward quickly and confidently with a solid foundation in how to conscientiously take advantage of Drupal AI benefits. The 2-week, 18-hour curriculum is presented on a timetable designed to integrate well into work schedules; meeting live, online for 3 hours every other day. The first session kicks off on November 9, 2026 and runs through November 20th. Additional sessions will be announced in the coming weeks.

In addition to DrupalEasy’s signature lively, online classes; each class session is recorded and becomes part of the video library that participants have lifetime access to. Other resources included as part of the course is a dedicated Slack channel and more than 100 pages of technical guides and implementation tools. The cost to register is $600.

Learn risk mitigation & human oversight

Mike Anello, who has meticulously developed hundreds of hours of Drupal curriculum and trained Drupal developers for more than 20 years, has created another stellar program that leads you, hands-on, through admin-facing responsible AI techniques that prioritize workflows that keep a human in the loop to review AI-generated suggestions before they are saved to the database. From class to class, you'll move from secure foundations to advanced agentic workflows and high-performance retrieval augmented generation (RAG) search, with intensive hands-on examples you can apply to your own Drupal projects right away.

Course content

The course covers four areas:

  • AI Foundations: Establish a baseline for secure LLM integration. Configure the AI Automators and Field Widget Actions modules to see how AI output can be reviewed before it's saved.
  • AI Agents: Implement agentic workflows and swarm orchestration agents, and deploy tool-calling capabilities that let AI interact directly with Drupal's Tool API.
  • RAG Search: Build retrieval augmented generation systems using vector databases, and learn semantic chunking and representation strategies that maximize search accuracy.
  • Local AI & Privacy: Deploy local models via Ollama for maximum privacy and cost-efficiency, and use the AI Metering module for automatic local fallback when commercial API quotas are reached.

Our goal, with AIDE and our other learning resources including webinars, workshops, events and the Drupal AI Demo is to make sure everyone who works with Drupal AI can do it safely and effectively.  

Learn more about AI Inside Drupal Essentials training , or ask about the course or AIDE team pricing.

DDEV Blog: DDEV September 2026: v1.25.4 Ships, Hobobiker Rides Again, Pressable Goes Official

DDEV v1.25.4 Is Out

DDEV v1.25.4 landed on September 2 with 142 PRs from the community. The theme is doing less by hand:

  • Database seeding — a new project can start from a seed snapshot instead of an import step.
  • ddev start --reset-database — throw away a project's database and start clean without ddev delete -O.
  • Global Dockerfiles and env files — image and environment customizations applied to every project at once, instead of per-project.
  • MySQL 9.7 LTS, plus MODX Revolution and Maho project types.
  • Linux packages moved to Cloudsmith at packages.ddev.com (Gemfury keeps working).

Read the full release post for details.

Snapshots, Explained (with Screencast)

The snapshot work in v1.25.4 got its own post: DDEV Snapshots: Checkpoints, Restores, and Seeded Databases. It covers basic snapshot use, checkpointing during a migration, uncompressed snapshots, snapshots embedded in the project, and seeding a new project from a snapshot — with a screencast↗ walking through old and new behavior.

The older DDEV Database Management post has been updated to match.

Hobobiker Rides Again: A Three-Part Live Series on Drupal 6 → Drupal 11 with Claude

The Drupal AI Learners Club↗ — the initiative led by Amber Matz and Angie Byron that meets regularly for show-and-tell on AI tools and workflows — has scheduled a three-part live series with Randy Fay joining Amber and Angie as host, migrating hobobiker.com — a Drupal 6 site with years of content — two different ways.

After Jamie Abrahams migrated a site live and checked the result with evals in One Command, One Migration: AI Best Practices in Action↗, Randy tried the approach on his own very old site. The results made one thing clear: Claude does its best work with a guided plan, a clear view of the source and destination, and success criteria it has to prove it has met. So the series takes hobobiker.com on two journeys — one ending in static HTML, the other in Drupal 11 — and checks both against the same test suite.

These are working sessions, not polished demos. Bring your questions, suggestions, and opinions; the peanut gallery is part of the show.

All three are on the club's Luma calendar↗, and recaps of past sessions are collected in the session list on drupal.org↗.

  • October 16, 2026 at 9:30 AM US Pacific / 12:30 PM US Eastern / 18:30 CEST — Part 1: Road Test: Having Claude Write the Tests Before the Trip
    Before any migration starts, we need a way to know whether it worked. Randy works with Claude to explore the Drupal 6 site and design automated tests covering content and design: pages, paths, images, menus, and how things look. The goal is a test suite that doesn't depend on any particular destination, so the same tests can run against a static archive and a Drupal 11 rebuild. Along the way: how to push Claude past "looks good to me" toward a complete verification plan, and how a sandboxed environment like coder.ddev.com smooths out the process.
    RSVP↗

  • October 23, 2026 at 9:30 AM US Pacific / 12:30 PM US Eastern / 18:30 CEST — Part 2: The Last Ride: Sending a Drupal Site into Retirement
    Not every old Drupal site needs an upgrade; some just need a dignified retirement. Randy has archived plenty of legacy sites as static HTML, and this time Claude does the work — given a proven strategy (Lullabot's "Sending a Drupal Site into Retirement"), clear success criteria, and the tests from Part 1. Can it turn hobobiker.com into a static site that holds up, in an hour, in a way everyone watching can follow? A practical use case for anyone with an aging site that still has content worth keeping.
    RSVP↗

  • October 30, 2026 at 9:30 AM US Pacific / 12:30 PM US Eastern / 17:30 CET — Part 3: The Long Haul: Planning and Running a Drupal 6 to Drupal 11 Migration
    This is the hard one. Drupal 6 to Drupal 11 skips many major versions and hits most of the snags that come with them. Instead of turning Claude loose, we prepare it the way you'd onboard a new team member: first it explores the D6 source database and files, then it learns what the D11 destination offers, then it writes a migration plan before touching any code. Randy follows that plan live, with plenty of input from the peanut gallery, stopping at sensible checkpoints and picking up in later sessions if needed. The finish line is the same test suite from Road Test, now running against a working Drupal 11 site.
    RSVP↗

Pressable Ships an Official DDEV Add-On

Pressable↗ released an official, open-source DDEV add-on for syncing WordPress sites between their hosting and a local DDEV environment.

  • What it does — ddev pull pressable and ddev push pressable sync the database and uploads over SSH and WP-CLI, with no API tokens or plugins required. --skip-db and --skip-files let you move one or the other, and Pressable limits pushes to non-production staging sites, with confirmation prompts, as a safeguard.
  • Install — ddev add-on get pressable/ddev-pressable
  • Links: changelog entry↗ • source on GitHub↗

There's also a French write-up from KingLand looking at how Pressable combines the DDEV add-on with MCP-driven AI for agency WordPress maintenance, including the case for keeping humans on the sensitive operations: Pressable : l'hébergement WordPress dopé par DDEV et l'IA↗ (French).

Community Projects

ddev-branchery: a URL, PHP version, and database per branch — Benjamin Kott's add-on gives each Git branch its own worktree beside the main checkout, with its own web address, PHP runtime, and isolated database, while the main project keeps running. Documentation↗

ddev-tailnet-proxy: DDEV projects on your tailnet — Titouan Mathis built a proxy that discovers running DDEV projects on a remote development server, assigns them stable ports, and serves them under the server's Tailscale hostname — no per-project configuration. Read the note↗

TYPO3 Quickstarter 0.7.0 — The CLI that scaffolds local TYPO3 environments on DDEV added support for legacy TYPO3 9 and 10 on PHP 7.4, so older extensions can be worked on before modernizing, plus a built-in phpMyAdmin that auto-logs in. Release notes↗

Knecht Cloud, hands-on — Matthias Andrasch walks through installing Knecht Cloud on a Hetzner VPS: project setup, AI-driven workflows, a browser terminal, and online previews, in a tool built for DDEV projects on TYPO3, Drupal, and Craft CMS. Read part 1↗

Talks and Tutorials from Around the Web
  • DDEV & shopware-cli for Shopware 6 → Benny Poensgen's slides from Shopware Open-Stage on September 17, 2026, on pairing DDEV with shopware-cli. View the deck↗ — see also his Shopware on DDEV post, and his October 21 training session below.
  • Mailpit with DDEV for Drupal 11 email testing (Spanish) → Jesús Daza covers DDEV's built-in Mailpit integration and an SMTP-based setup, how to reach the UI, and how to confirm mail is being delivered during development. Read on solucionex.com↗
  • A DDEV-based local development workflow → Michael K. Laweh on what DDEV gives a consultant working across Laravel, Yii, and WordPress projects: consistency across projects and teams, fast project setup, and framework-agnostic tooling. Read on klytron.com↗
DDEV Live Training

Sessions are open to everybody.

Zoom Join Info:
Link: Join Zoom Meeting
Passcode: 12345

Governance
  • The next DDEV advisory group meeting, open to everybody, is November 4, 2026 at 8:00 AM US Mountain / 10:00 AM US Eastern / 16:00 CET. Add to Google Calendar • See the agenda. We love to hear from our community!
Sponsorship Update

We so appreciate all of you supporting the project!

August 2026: ~$10,038/month (83.7% of goal)

September 2026: ~$10,099/month (84.2% of goal)

If DDEV has helped your team, consider sponsoring. → Become a sponsor↗

Contact us to discuss sponsorship options that work for your organization.

Stay in the Loop—Follow Us and Join the Conversation

Compiled and edited with assistance from Claude Code.

Talking Drupal: Talking Drupal #571 - GovHub

Today we are talking about GovHub, Drupal in Government, and Why Governments Love Drupal with guest Jasmyne Epps. We'll also cover Convivial Gov Site Template as our module of the week.

For show notes visit: https://www.talkingDrupal.com/571

Topics
  • GovHub Origins and Goals
  • Feature Requests and Governance
  • Why Government Chooses Drupal
  • Team Structure and Release Cadence
  • Accessibility and Compliance Strategy
  • Hosting Model and Multisite
  • Structured Content and Microcontent
  • Syndication and Emergency Alerts
  • Orchard Design System Explained
  • Training and Onboarding Editors
  • Gov Talks Conference
  • Logo Specs and Releases
  • Ticket Prioritization PRICE
  • QA Workflow with Tugboat
  • Handling Traffic Spikes
  • Drupal 11 Performance Talk
  • Drupal 11 Upgrade Gotchas
  • Getting Users Excited
  • Translation Strategy Limits
  • Why Government Loves Drupal
Resources Guests

Jasmyne Epps - jasmyneepps.com jasmyneepps

Hosts

Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi Amber Matz - tugboatqa.com [amber himes matz](https://www.drupal.org/u/amber himes matz)

MOTW Correspondent

Martin Anderson-Clutz - mandclu.com mandclu

  • Brief description:
    • Have you ever wanted to stand up a polished, accessible government website in Drupal (with components, content types, SEO, and cookie consent all wired up) without writing any code? There's a site template for that.
  • Module name/project name:
  • Brief history
    • Created in March 2026 by Morpht, the shop behind the Convivial family — with Ivan Zugec leading the maintainer team.
    • Versions available: 1.3.3, which works with Drupal 11
  • Maintainership
    • Actively maintained: release just last week, on September 16th
    • Security coverage
    • Test coverage: functional tests for install and validation, plus a kernel requirements test.
    • Documentation there's a full handbook over at docs.morpht.com, and a live demo at gov.convivial.io
    • Open issues: none?
  • Site template features and usage
    • Like the Haven site template we talked about a couple of weeks ago, Convivial Gov gives you a curated stack plus demo content, and in this case hands you a robust, ready-to-customize government site.
    • Because it's built on Drupal CMS, you get all the latest Drupal tooling: Canvas for visual page building, Single Directory Components, and Recipes.
    • The front end is Morpht's Morphos theme, built on Tailwind and DaisyUI, so you get dark mode, multiple colour palettes, and a big library of editor-friendly components out of the box. It's worth mentioning that using the Morphos theme on a production site requires a paid license
    • The provided components are sorted into six buckets: container, content, child, element, background, and behavior. They include fun ones like scroll reveal and a colour palette switching behavior
    • The content model is broad. You get seven content types: Page, Section, Article, Publication, Resource, Topic, and Audience. And, they come with a stack of teaser and card view modes to display them.
    • The whole point is no-code: a site builder can compose sophisticated pages in Canvas without ever touching a template.
    • One thing to watch: the default timezone is Australia/Sydney out of the box
    • It's also worth comparing Convivial Gov to another site template called Local. Both dropped in March 2026, both are Canvas-based Drupal CMS site templates for the public sector, and both lean on ECA for automation — so there's real common ground. The difference is scope and mechanism. Local, from Annertech, is narrowly purpose-built for local councils and community-service directories: it ships a specific service information architecture — Service and Service Landing content types — with ECA wired so section pages stay in sync when service pages get published or updated, taking its cues from the gov.uk design system. Convivial Gov goes the other way — it's design-system-led and general-purpose, a broad component library and content model meant for any government, agency, or marketing site rather than one particular workflow.

Centarro: Drupal Commerce vs. Shopify

Shopify is the fastest way to launch a simple online store. It handles hosting, security, and checkout beautifully. For straightforward DTC brands, it's hard to beat. But the more your business strays from a simple product catalog (B2B workflows, multi-brand storefronts, complex product configurations, deep ERP integration, content-driven commerce, full SEO control) the more you end up fighting the platform, stacking paid apps, and working around limitations that shouldn't exist.

And there’s a deeper issue. Shopify is a merchant services company first and an ecommerce platform second. When 68% of GMV (Gross Merchandise Value) flows through Shopify Payments and the Shop app mediates your post-purchase relationship, you have to ask yourself: do you really own your customer relationship at all?

Drupal Commerce is an open source ecommerce framework that gives you complete ownership of your code, data model, customer relationships, and roadmap. No per-transaction platform fees. No forced migrations. No artificial product limits. No locked-down URLs. No platform inserting itself between you and your buyers. It's built for businesses that need the platform to adapt to them—not the other way around.

Read more

Jacob Rockowitz: Vibing Drupal: Using AI to hammer at the Webform module's security issues

I came up with the title for this blog post while working on 20+ Webform security issues, because there were moments when I used Codex to hammer out a particularly complex issue. I couldn't help but find it ironic to use something as advanced as AI to hammer at a problem or challenge.

Some security issues were so complex to reproduce that I had to push Codex to replicate the problem, and it occasionally generated sloppy code. Still, even with Codex generating AI-slop, it helped me understand the root causes and solutions for security issues that had lingered for years.

Before I go any further, let's step back and talk about the challenge of maintaining the Webform module and addressing security issues.

Maintaining the Webform module

The bulk of the Webform module was created a decade ago, when I had more time and motivation to make a sizable contribution to Drupal. Drupal contributors and their contributions come in all shapes and sizes. The current codebase is stable and extendable, with "extendable" as the keyword, because people and AIs can alter and create Webform features and behaviors as needed using contributed modules or custom code. It is ironic that all the example webforms included in the Webform module, intended to help humans, have proven incredibly useful for AIs in understanding and extending webforms.

Though I am willing to say the code is stable, the fact that a webform is generally public and accepts input leaves the Webform module open to security issues. In other words, malicious actors, including AI, will target webforms to exploit XSS vulnerabilities or expose data.

Securing the Webform module

It is worth recognizing and praising Drupal's security team for...Read More

Pages