Drupal 12 Proposal Would Let Editors Reference Unpublished Nodes They Can View

Granular Access Without Broader Bypass Permissions
Drupal 12 graphic about a mismatch between viewing access and reference access. An editor can see a content item but cannot select it as a reference. The graphic shows one visible content card and a separate reference list connected by a blocked path and an alternate allowed path. Text reads "DISCOVER DRUPAL". "When Viewing Access and Reference Access Don’t Match". "A Drupal 12 proposal revisits a workflow limitation first reported during Drupal 8".

Core contributors are reviewing a Drupal 12 proposal that would let node reference fields include unpublished nodes an editor already has permission to view. The work is tracked in Drupal core issue #2845144, opened on 20 January 2017. A draft change record published on 2 September 2026 identifies the change for the 12.0.x branch and Drupal 12.0.0, while the issue remains in Needs review.

The current behaviour can interrupt staged or moderated publishing workflows. An editor may be permitted to view an unpublished node but still be unable to find or save it through a standard node reference field. The original issue documented the limitation during Drupal 8 and also raised the access-control risk of exposing unpublished nodes to users who were not authorised to see them.

The proposed implementation adds a field setting labelled “Include unpublished nodes the user has access to view.” It is disabled by default, so existing reference fields retain their current behaviour unless the option is enabled. The setting is implemented in NodeSelection and applies specifically to node references rather than all publishable entity types.

When enabled, the selection follows the user's existing unpublished-content permissions. Users with “View own unpublished content” can reference their own unpublished nodes, while those with “View any unpublished content” can reference unpublished nodes regardless of author. Users with neither permission continue to receive published nodes only through this selection path, while “Bypass content access control” remains a separate broader permission.

The current implementation does not extend the same behaviour to media or other publishable entity types. Follow-up issue #3110677 tracks related work that could broaden the approach. Issue discussion has also treated identification of unpublished items in autocomplete results as separate follow-up work rather than a requirement for the current proposal.

Recent issue activity also warns sites using patch #109 that users with neither unpublished-view permission can reference unpublished nodes because the patch lacks the required publication-status filter. The current merge request corrects that condition and adds test coverage, according to the 2 September update. Until the merge request is accepted and the issue status changes, the behaviour remains proposed rather than an available Drupal 12 core feature.

Disclosure: This content is produced with the assistance of AI.

Note: The vision of this web portal is to help promote news and stories around the Drupal community and promote and celebrate the people and organizations in the community. We strive to create and distribute our content based on these content policy. If you see any omission/variation on this please reach out to us at #thedroptimes channel on Drupal Slack and we will try to address the issue as best we can.

Upcoming Events

Latest Opportunities