Only build the package management forms for visitors who can use them - #1837
Merged
Conversation
viewPackageAction built and createView()'d the add-maintainer, remove-maintainer, transfer and delete forms for every visitor, including anonymous ones. The template already renders each of them behind the matching voter grant, so for the overwhelming majority of the 4.5M package page views per APM period all four were discarded unrendered. createView() is not free either: RemoveMaintainerRequestType uses an EntityType, so materialising its choice list runs a real query against the package's maintainers. Gating on the same grants the template uses makes the rendered output identical while dropping four form builds and one query from almost every package page view.
stof
approved these changes
Sep 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
viewPackageActionbuilt andcreateView()'d the add-maintainer, remove-maintainer, transfer and delete forms for every visitor, including anonymous ones. The template already renders each of them behind the matching voter grant (view_package.html.twig:103,173,191,211), so for the overwhelming majority of the ~4.5M package page views per APM period all four were discarded unrendered.createView()is not free either:RemoveMaintainerRequestTypeuses anEntityType, so materialising its choice list runs a real query against the package's maintainers (UserRepository::getPackageMaintainersQueryBuilder).Gating on the same grants the template uses keeps the rendered output identical while dropping four form builds and one query from almost every package page view.
Verification
composer phpstanclean, full suite green. The existingtestCreateMaintainer/testRemoveMaintainer/testTransferPackagetests already cover the granted side end-to-end (they crawl the page and submit the forms); the new test covers the other half — that an anonymous visitor gets none of the four, and a maintainer still gets all four.