Talking Drupal

Talking Drupal Hosts

Talking Drupal is a weekly chat about web design and development by a group of people with one thing in common: We Love Drupal. With hosts John Picozzi, Nic Laflin, and Martin Anderson-Clutz

  1. 4d ago ·  Video

    Talking Drupal #570 - Laravel & Marketing PHP

    Today we are talking about Laravel, Marketing, and The PHP Foundation with guest Matt Stauffer. We'll also cover Formdazzle as our module of the week. For show notes visit: https://www.talkingDrupal.com/570 Topics What Is Laravel Writing Laravel Books AI and Technical Writing Laravel Versus CMS Drupal as Framework Integrating Laravel and CMS Laravel and Symfony Marketing Modern PHP Laravel Community Marketing Jigsaw and Onramp Drupal Marketing Lessons Onboarding Focus in Laravel Laravel BDFL Changes Onboarding And Docs Drupal Framework Perception What PHP Foundation Does Marketing PHP Vs Laravel AI Answers And Positioning Cross Ecosystem Collaboration Resources Jigsaw Onramp Native php Alpine Tailwind Vue Laravel herd php.new Blog post on how to contribute to php Laracon talk Kent C. Dodds The Last Software Engineer (how in the AI era, we need to all become Product Engineers) Guests Matt Stauffer - mattstauffer.com Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi Amber Matz - tugboatqa.com [amber himes matz](https://www.drupal.org/u/amber himes matz) MOTW Correspondent Bernardo Martinez - bernardm28 Brief description: This week's module is Formdazzle, a developer tool that makes theming Drupal forms easier. Drupal's Form API is a powerful abstraction, but when you want to target one specific field, label, button, or form wrapper, the default Twig template suggestions can be limited. The module works by taking information Drupal already knows about the form, like the form ID, element type, and element name, and using that to generate more targeted Twig template suggestions. For example, in a Drupal View with exposed filters, you may want to style the Reset button differently from the Submit button. By default, Drupal renders both buttons through the same input–submit.html.twig template, which makes it difficult to customize them independently. This module lets you assign different templates to individual form buttons—such as Submit, Reset, or Filter—based on their action, type, and other properties. This module has no configuration. Just enable the module and it starts working and look at the twig debug comments including extra template suggestions. Module name/project name: formdazzle Brief history How old: created in 13 September 2019 by johnalbin Versions available: ^10.1 ^11 ^12 Maintainership Actively maintained Last release was 1 September 2026, currently the module has two maintainers Stephen Mustgrave and John Albin. The module includes both test and security coverage. Usage stats: 3,956 according to drupal.org Module features and usage There's no configuration. Just enable the module and it starts working, including with Views exposed forms and Webform. Formdazzle automatically adds more specific theme suggestions based on the form ID, element type, and element name.

  2. Sep 10

    Talking Drupal #569 - Site Templates

    On today's show we are talking about Site Templates, What they do, and How you can use them with guests Tim Lehnen & Adam Globus-Hoenich. We'll also cover Haven as our module of the week. For show notes visit: https://www.talkingDrupal.com/569 Topics MOTW: Haven What Site Templates Are Canvas Components Included Promoting Templates Beyond Drupal Templates vs Distributions Who Benefits from Templates Template Types and Adoption Where to Find Templates Featured vs Installer List Free vs Paid Templates Recipes vs Templates Distributions and Themes Empowering Site Builders Exporting a Template Designing for Users Releases Without Upgrades Best Practices and AI How to Contribute Resources Webinar: Drupal Canvas and Agentic Content Management: What Enterprise Teams Need to Know Drupal Site Templates Tim's book - Fog & Fireflies Guests Tim Lehnen - @TimLehnen hestenet Adam Globus-Hoenich - @PhenaProxima phenaproxima Hosts Nic Laflin - nLighteneddevelopment.com nicxvan Stephen Cross - SecondSginalMedia.com [stephencross]](https://www.drupal.org/u/stephencross) Amber Matz - tugboatqa.com [amber himes matz](https://www.drupal.org/u/amber himes matz) Module of the Week Correspondent Martin Anderson-Clutz - mandclu.com mandclu Haven - Site Template - Designed for non-profit sites, this template features a bright, warm design that can be adapted for many use cases. It comes pre-confifgured with blog, projects and people profiles, as well as newsletter signup, donation add-ons and more.

  3. Sep 3

    Talking Drupal #568 - Off The Cuff #12

    Today we are talking about Drupal Performance, Rapid Development, and Drupal Canvas Maturity with our hosts. We'll also cover Microsoft 365 FullCalendar as our module of the week. For show notes visit: https://www.talkingDrupal.com/568 Topics Deprecating Module Theme Files Migrating Hooks to Classes Why This Change Matters Drupal Performance Gains Performance Audits and Lighthouse Automating Checks and Spreadsheet Rant AI Spreadsheet Cautionary Tale Privacy Concerns with AI Freelancer Pressure Rapid Change Reality Canvas Release Risks Community Support Needed AI For Documentation Canvas Production Readiness Canvas Architecture Debate AI For Voting Research LLM Bias And Sources Resources Rebrickable Webpagetest Lighthouse Tugboat Drupal canvas Guests Martin Anderson-Clutz - mandclu.com mandclu Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi Amber Matz - tugboatqa.com [amber himes matz](https://www.drupal.org/u/amber himes matz) MOTW Correspondent Martin Anderson-Clutz - mandclu.com mandclu Brief description: Have you ever wanted your users' own Outlook calendars to show up right alongside your Drupal content in a calendar view? There's a module for that. Module name/project name: Microsoft 365 FullCalendar Brief history How old: created just last month, August 19 2026, by fabianderijk of Finalist Versions available: 1.0.0, which works with Drupal 11 Maintainership Brand new — the first and only release is from last month, and the whole commit history is basically launch day Security coverage: brand new, so not yet Test coverage: yes, both unit tests and kernel tests Documentation: a genuinely thorough README — it walks through privacy, the config guard rails, and three different ways to customize event output Open issues: none yet, it's less than two weeks old Usage stats: Too new for a site count Module features and usage With this installed, it adds the signed-in user's Microsoft 365, or Outlook, calendar as an extra event source on a FullCalendar view — so their personal appointments sit right next to the Drupal content the view already renders It leans on the Microsoft 365 Connector module and its SSO submodule, plus the FullCalendar module. Each user must have signed in through Microsoft 365 SSO: anyone who hasn't just sees no events, which is a clean fallback It uses lazy loading, so it only fetches events in the date range the calendar is currently showing, not your whole calendar Privacy is baked in: anything marked private or confidential in Outlook is masked, so it shows up as just "Busy", with no title, location, or meeting link, unless the site builder deliberately turns masking off The response itself is per-user and marked private, no-store, so it never lands in a shared or CDN cache There's a clever server-side cache too: it stores the raw Graph response before masking, so a single fetch can serve several displays that each have different masking settings You get guard rails you can tune with Drush or an admin form: max events, max date range, cache lifetime, and a separate, shorter failure cache That failure cache is a nice touch — if there's no active Microsoft session, or Graph errors out, it caches the empty result briefly so a broken connection doesn't get re-polled on every single calendar click Under the hood it calls Graph's calendarView endpoint rather than /me/events, which means recurring meetings get expanded into their individual occurrences — exactly what a calendar grid needs Every event carries CSS classes for its status — busy, free, tentative, out-of-office, working elsewhere, cancelled — so you can style them however you want And if CSS isn't enough, there's a server-side alter hook and a JavaScript pre-build event for fully custom rendering. Nice detail: the hook is explicitly guarded so you can't use it to put back a title or location that masking just stripped out Clearly this will be more useful for edge cases, for example an intranet, but I think this is a really interesting example of the power of Drupal as an integration layer, or as some like to put it, the "glass" through which a user can interact with multiple systems

  4. Aug 27

    Talking Drupal #567 - Common Vulnerabilities & Exposures

    Today we are talking about Security, Vulnerabilities, and how to avoid exposure with guest Dave Welch. We'll also cover Security Scanner as our module of the week. For show notes visit: https://www.talkingDrupal.com/567 Topics What Are CVEs CVE Lifecycle and Disclosure AI Era Security Challenges What CVE Program Excludes Patch Fast Reality Global Security Signals CVE Timing Judgment KEV Flags Explained CVE Updates Link Rot Who Decides CVE Sneaky Patch Dangers ADP Program Fixes Small Team Triage Vulnerability Tsunami AI Autonomous Security Future Legal Pressure Budgets Resources Psalm PHP Static Analysis Tool SARIF format PHP ecosystem Council of roots How AI Broke Open Source Security: End-of-Life Software Is the Most Exposed CVE podcast Vulncon PSIRT Guests David Welch - github: dwelch2344 dwelch2344 Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi JD Flynn - dorficus MOTW Correspondent Martin Anderson-Clutz - mandclu.com mandclu Brief description: Have you ever wanted a fast way to catch the security mistakes that slip into custom Drupal code — especially the code your AI assistant just wrote — before it ships? There's a module for that. Module name/project name: Security Scanner Brief history How old: created in July 2026 by Mayank Gupta (mayankguptadotcom) of Acquia Versions available: 1.0.0, which works with Drupal 10.3 and 11 Maintainership Actively maintained — created and shipped its first stable this summer, with steady development right through late July Security coverage Test coverage — and it's strong: unit and kernel tests, including a regression corpus built from real Drupal core advisories Documentation? In-depth README with a full check table and CI recipes, plus a CHANGELOG Number of open issues: 1 issue, not a bug Usage stats: 2 sites (it's brand new) Module features and usage Provide a Drush command, has no UI — you point drush security:scan at a module or any path, it reads the code statically, and prints a prioritized, OWASP-mapped list of things to review It's built for the age of AI-written code — the checks target the classes AI assistants keep reintroducing: routes with no access check, #markup and |raw XSS, missing CSRF tokens, unserialize() on untrusted data, hardcoded secrets Then there's an optional deep pass: with the Psalm static analysis scanning engine installed, it'll trace untrusted input across functions and files to catch cross-function issues. And it's honest about state — the report always says whether that deep pass ran, was skipped, or failed, so a failure never gets mistaken for a clean scan One nice detail under the hood: a tokenizer-backed "code map" that knows whether a match is real code, a comment, or a string — so it won't flag the word "unserialize" sitting in a doc comment. That kills the single biggest source of false positives The checks are regression-tested against real Drupal advisories (Drupalgeddon, Drupalgeddon2, the 2019 unserialize bug, etc) so a pattern that caused an actual CVE can't quietly come back in your custom code Output comes in three flavors: a readable table, JSON for CI and AI agents, and SARIF — which means findings show up as annotations right on your GitHub or GitLab merge-request diff instead of buried in a job log For adopting it on an existing codebase there's a baseline file — you fingerprint the findings you've reviewed, with a required reason on each, and they stop failing the build but never go invisible; every run still counts them It exits non-zero on error-level findings, so it drops straight into CI or a pre-commit hook And it's extensible — checks are Drupal plugins with a #[SecurityCheck] attribute, so any module can add its own or alter the ones that ship Big caveat, and the module says this itself: a finding means "review this," not "this is broken." Static analysis has false positives, and a clean scan doesn't prove the code is secure — access-control logic especially still needs human review I first heard about this module over beverages at Drupalcamp Asheville, so I know that this module was largely vibe-coded, after having an AI agent ingest every single Drupal security team CVE. So I like to think of this module as security pattern recognition tool, but of course it does even more

  5. Aug 20

    Talking Drupal #566 - DrupalEasy: Responsible Drupal AI

    Today we are talking about Drupal, AI, and learning to use it responsibly with guest Mike Anello. We'll also cover Entity Mesh as our module of the week. For show notes visit: https://www.talkingDrupal.com/566 Topics Course overview Fast moving modules Inside vs outside AI No code approach Keeping curriculum current Essentials vs add ons Chat Claude Code setup Inside vs Outside AI Rules and Provider Calls Guardrails in Drupal UI Model QA and Testing Local Models and Costs Token Budgets and Logging Course Use Cases Overview RAG and Vector Basics Class Schedule and Pricing AI Predictions and Wrap Resources New DrupalEasy class: Responsible Drupal AI Basics Training at orlando amazee ai Jrockowitz losing my skill AI module ecosystem AI browser provider (LLM in Google Chrome) amazee.ai Private AI Provider Derecho Guests Mike Anello - drupaleasy.com ultimike Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi JD Flynn - dorficus MOTW Correspondent Martin Anderson-Clutz - mandclu.com mandclu Brief description: Have you ever wanted a way to analyze and visualize the ways in which the content on your Drupal site is interlinked? There's a module for that. Module name/project name: Entity Mesh Brief history How old: created in Jan 2025 by Jorge Tutor (gedur) of Metadrop Versions available: 2.1.0 and 2.0.3, both of which work with Drupal 11 Maintainership Actively maintained, latest release last month, and a commit just yesterday Security coverage Test coverage Documentation? Project page is pretty descriptive Number of open issues: 13 open issues, 4 of which are bugs, but 2 of those were marked fixed in the past week Usage stats: 437 sites Module features and usage With Entity Mesh installed, the module will analyze the rendered output of your nodes using a chosen account, looking for links to other content That means it will find not just links in entity relationship fields, but also links within formatted text, menus, and more The results can be visualized in a D3.js 3D visualization, displayed as a table, or exported as a CSV The report also exposes a set of Views-style filters, to help you narrow down to the specific set of information you want to understand Entity Mesh analyzes the DOM of your rendered nodes, looking for links, iframes, and images. Internal paths are further analyzed and categorized, for example based on whether the specified path redirects, is broken, points to something that is access-denied, and so on From a marketing perspective, that allows you to understand the paths available to navigate from a source page to a target page, the content linked to or from a specific page, and will also augment the content deletion confirmation form to advise the user of any existing links to the content being deleted There are obvious SEO advantages to being able to find redirect chain, broken or access denied links, and there are GDPR compliance implications for being able to identify iframes that might load third-party cookies The project page also mentions that this module could be very useful to run after a content migration, for QA The actual analysis of your site content be triggered by drush, an admin form, or by cron, and you can set limits on the size of the batch to run, because of the weight it puts on your site by rendering every node it analyzes The current versions Entity Mesh also depend on the Entity Registry and Entity Render Context modules, that have essentially the same maintainers, so if there's only part of Entity Mesh that you really need, you could also give those a look Back in episode #321 we covered Entity Usage, and there are some definite similarities, but also some differences. While they both provide reporting on content relationships, Entity Usage does so by examining structured field values at save time. So, the information gathered is different, and collects data that can be displayed in views or custom code.

  6. Aug 13

    Talking Drupal #565 - That Geerling Guy

    Today we are talking about Open Source sustainability, becoming your own content creation machine, and how drupal influenced some of that with guest Jeff Geerling. We'll also cover AI Metering as our module of the week. For show notes visit: https://www.talkingDrupal.com/565 Topics Jeff's Timekeeping Icebreaker Jeff's Drupal Origin Story From Drupal to Hardware Tinkering Staying Motivated on YouTube What Conferences Are Really About DrupalCon Memories and Community Why Jeff Moved to Hugo PSA Tornado Warning Detour Keeping Up with Drupal CMS PHP Perception Shift Fast Drupal Setup COVID Streaming Boom Picking Video Projects Decommissioning Builds YouTube Algorithm Risk Vintage Time Server Creator Starter Tips Supporting Maintainers Books and Crohns Local Control Trends AI Workflow Boundaries Timing Obsession Kind Drupal Culture Guests Jeff Geerling - jeffgeerling.com geerlingguy Hosts Nic Laflin - nLighteneddevelopment.com nicxvan Mike Anello - drupaleasy.com ultimike JD Flynn - dorficus MOTW Correspondent Mike Anello - drupaleasy.com ultimike Brief description: AI Metering module - helps keep track of your users' AI token usage on the site. Includes cost estimation, token limits, and local LLM fallback options. Module name/project name: AI Metering Brief history How old: created in June 1 2026 by Jérôme Tchania (codeitwisely) Versions available: 1.0.1 Maintainership Actively maintained - yes Co-maintained by Carlos Ospina (camoa) Security coverage - yes Test coverage - yes Documentation - yes Number of open issues: 9 open issues, 4 of which are bugs against the current branch Usage stats: Sites: 78 Module features and usage Obtains token costs for all modules from LiteLLM Can be configured to send email when the token limit is being approached. Per user and per role reports. LLM fallback to Ollama

  7. Aug 6

    Talking Drupal #564 - Approachable Open Source

    Today we are talking about Maintaining NodeJS, Patternlab, Writing Books, and Open Source with guest Brian Muenzenmeyer. We'll also cover AI Webform Generator as our module of the week. For show notes visit: https://www.talkingDrupal.com/564 Topics Brian Open Source Origins Pattern Lab Node Journey Maintaining and Moving On Writing Approachable Open Source Who the Book Is For Beyond Code Contributions All Things Open Book Signing Choosing Conferences to Attend Pitching Open Source at Work Misconceptions and Starting Small Avoiding Maintainer Burnout Handling AI Noise and Low Effort PRs DCO and Licensing Basics Better Communication and Reviews Node and Drupal Lessons Optimism for Open Source Future Resources Brian Muenzenmeyer https://brianmuenzenmeyer.com https://approachableopensource.com/ https://bsky.app/profile/brianmuenzenmeyer.com https://www.linkedin.com/in/brian-muenzenmeyer-91a77554/ https://www.renderatl.com/schedule upcoming https://nodeconf.eu/program upcoming spectrum of engagement https://approachableopensource.com/blog/2025-open-source-pace-layers/ change in contention https://brianmuenzenmeyer.com/posts/2018-i-maintainer/ burnout https://approachableopensource.com/read/the_spectrum_of_engagement/ https://approachableopensource.com/read/the_four_files_of_any_open_source_project/ LICENSE Hodag Cryptid https://en.wikipedia.org/wiki/Hodag https://www.rhinelanderchamber.com/about-the-hodag/ You should write a book All contributors spec Talk at all things apart DCO Developer Certificate of Origin Open source law policy and practice Sustain OSS Guests Brian Muenzenmeyer - brianmuenzenmeyer.com Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi Bernardo Martinez - bernardm28 JD Flynn - dorficus MOTW Correspondent Jacob Rockowitz - jrockowitz.com jrockowitz Brief description: AI Webform Generator enables site builders to create a Drupal Webform, or update an existing one, from plain-English instructions. It sends the request through the site's configured Drupal AI provider, validates the returned Webform definition, and saves the resulting form. Review the generated change before using the form. Module name/project name: AI Webform Generator (ai_webform_generator) Brief history Created on 2 July 2026 by chaitanyadessai (Chaitanya R Dessai). The current stable release is 1.0.2, released on 3 July 2026, and supports Drupal ^10 || ^11. Maintainership Appears actively maintained: Drupal.org lists an update on 24 July 2026. Maintainers: zeeshan_khan and chaitanyadessai. (Specbee) Security coverage: Yes. Stable releases are covered by Drupal's security advisory policy. Test coverage: Yes. Version 1.0.2 includes unit, kernel, and functional tests for prompt building, JSON validation, settings, route access, Webform building, and optional CAPTCHA elements. Documentation: Yes. The project page and module README cover requirements, configuration, usage, security considerations, and supported field types. Issues: 1 open issue, with 0 open bug reports (7 issues total). Usage stats: 1 site reports using this module. Module features and usage Creates complete Webforms and updates existing Webforms in place from natural-language prompts. Supports common Webform elements, including text, email, telephone, number, date, select, checkbox, radio, range, password, hidden, and managed-file elements. Validates the AI response before applying the Webform definition. Uses the existing Drupal AI provider configuration; API keys are not stored in this module's configuration. Provides configurable model, temperature, output-token, and per-user request limits to balance output quality and provider spend. Requires trusted users with both the generator permission and ordinary Webform edit access when changing an existing form. AI-Generate Notes, Review, and Recipe (used for testing) https://github.com/jrockowitz/drupal_playground/tree/main/recipes/drupal_playground_webform_ai AI-Generated Assessment Technical: The module separates AI generation, prompt building, JSON validation, and Webform construction into Drupal services. It uses the site's configured Drupal AI provider, validates a limited allowlist of Webform element types before saving, and exposes model, temperature, output-token, and per-user request-limit settings. Access and error handling: Generation requires its own permission, and updating an existing Webform also requires normal Webform update access. A per-user flood limit constrains provider spend; failures are logged, with detailed upstream errors shown only to generator administrators. Code quality: Version 1.0.2 uses strict types and separates form, service, validation, and persistence responsibilities. It includes unit, kernel, and functional coverage for core behavior. This assessment is a code review of the released module, not a security audit. Implementation: The module creates new Webforms and updates supported fields of existing Webforms in place, but saves the generated definition immediately without a preview, diff, or approval screen. Usefulness: The module is useful for quickly drafting straightforward Webforms and iterating on common field changes when a site builder reviews the result. Complex, highly customized, or regulated forms need especially careful manual review before publication. How to use it: Configure a chat-capable provider, select an existing Webform or choose to create one, describe the fields and validation in plain English, submit the request, and then review the saved Webform. For example, create a disposable contact Webform and ask the generator to add a required telephone field while preserving the existing fields. AI-generated source code: The module's runtime use of AI and its code style cannot establish whether its source was AI-generated or AI-assisted. Its public project metadata does not make an authorship claim, so this is unknown. Possible improvements: Add a preview/diff and explicit approval before saving; broaden support for advanced Webform structures and handlers; add optional, privacy-conscious prompt and response audit logs; and expand regression coverage for complex Webform updates. Next steps for adopters: Restrict generation to trusted roles, begin with a low request limit, test representative prompts outside production, and review every generated field, validation rule, confirmation message, and permission before publishing.

  8. Aug 3

    TD Cafe #020 - AI & Development Teams

    How should development teams adopt AI without sacrificing code quality or collaboration? In this Talking Drupal Cafe, Stephen Cross is joined by Mike Miles and Jim Birch to discuss practical strategies for integrating AI into Drupal development teams. They explore AI coding assistants, team policies, code review, agent workflows, governance, and real-world lessons from using tools like Claude Code and GitHub Copilot in production environments. For show notes visit: https://www.talkingDrupal.com/cafe020 Topics Why AI Matters Now Team Introductions From Experiments to Workflows Standards and Guardrails Skills and Automation Examples Taming Verbose AI Code Adoption and Tool Choices Governance and Training Measuring Productivity Gains Keeping Up Without FOMO AI for Editors and Site Features Red Teaming and AI Security Jim Birch Jim Birch is Director of Engineering and AI Practice Lead at Kanopi Studios, where he leads engineering teams and oversees the company's responsible adoption of AI. Jim is also a Drupal CMS committer, and Recipes Initiative Coordinator, and is a Google Cloud Certified Generative AI Leader. Michael Miles Mike Miles is a technical leader and speaker with more than 20 years of experience in web engineering, open-source development, and digital platform delivery. As the Director of Web Development at MIT Sloan, he leads the team responsible for the development, maintenance, and growth of the school's public digital properties. Mike regularly speaks at technical conferences on topics including modern web development, Drupal, technical leadership, testing, delivery practices, and practical AI adoption. He is also one of the organizers of New England Drupal Camp. Stephen Cross Stephen Cross has been a Drupal developer for over 20 years and founded Talking Drupal in 2013. As founder of Second Signal Media, he combines his passion for open source and media production to share conversations that help the Drupal community learn and grow. Guests Michael Miles - mikemiles86 Jim Birch - thejimbirch Stephen Cross - stephencross Resources Courses https://anthropic.skilljar.com/ https://academy.openai.com/pages/courses Skills https://kanopi.github.io/cms-cultivator/ https://kanopi.github.io/delivery-record/

4.9
out of 5
28 Ratings

About

Talking Drupal is a weekly chat about web design and development by a group of people with one thing in common: We Love Drupal. With hosts John Picozzi, Nic Laflin, and Martin Anderson-Clutz

You Might Also Like