drupal / pixienote
A private personal information hub for contacts, bookmarks, notes, schedules, and service links.
Package info
git.drupalcode.org/project/pixienote.git
Type:drupal-recipe
pkg:composer/drupal/pixienote
Requires
- drupal/accessible_menu: ^1.0
- drupal/aggregator: ^2.2
- drupal/bootstrap_cloud: 7.1.7
- drupal/calendar_view: ^2.1
- drupal/copyright_footer: ^3.4
- drupal/core: ^11.4
- drupal/node_view_permissions: ^2.0
- drupal/printable: ^3.1
- twig/twig: >=3.29 <3.30
Requires (Dev)
None
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-09-30 06:58:53 UTC
README
PixieNote is a Drupal Recipe for a private personal information hub. It adds contacts, bookmarks, notes, schedules, service links, RSS news, a note-photo grid, tags, list views, search, browser printing, and the Bootstrap Cloud Pixie Dark presentation.
The Recipe contains configuration, public RSS feed definitions, and the
footer layout settings. It does not include imported feed items, sample
content, user accounts, email addresses, credentials, private keys, uploaded
files, or identifiers copied from the production site.
The Recipe navigation omits Bootstrap Cloud's default logo. Add your own
branding after installation if desired. The front page is the i News Top view
at /top; the included public feeds appear after their first refresh.
English, Japanese, Simplified Chinese, and Thai are available as interface
languages with URL prefixes (/en, /ja, /zh-hans, /th). The Recipe
enables Drupal's translation tools, but does not ship translated personal
content or guarantee complete contributed-module interface translations.
Requirements
- Drupal 11.4 or later
- PHP supported by the installed Drupal release
- Composer
- Drush 13 or later for the required node-access rebuild
- A fresh site installed with the Minimal profile
- A private-file directory configured outside the public web root before uploading contact or note images
Install
Run these commands from the root of an installed Drupal project. Drupal's
recommended project template from 11.2 onward already places Recipe packages
in recipes/. If your Composer project does not have that installer path,
configure it before requiring PixieNote:
composer config allow-plugins.drupal/core-recipe-unpack true
composer require drupal/core-recipe-unpack composer/installers:^2.3
composer config --merge --json extra.installer-paths '{"recipes/{$name}":["type:drupal-recipe"]}'
The Recipe application below assumes recipes/pixienote/recipe.yml exists
after Composer finishes. If it does not, check the installer path instead of
applying a different copy of the Recipe.
Before applying the Recipe, create a private-file directory in the Composer
project root, outside web/, and make it writable by the PHP web-server
user. In web/sites/default/settings.php, set the following path (adjust it
if your project uses a different web root):
$settings['file_private_path'] = dirname($app_root) . '/private';
On the standard recommended-project layout, create that directory with
mkdir -p private from the Composer project root. Do not put private files
in web/sites/default/files or commit them to version control.
Before running the commands below, replace any placeholder site email address
in Drupal's Basic site settings with a deliverable address that you control.
The setup-contact script uses that address as the recipient of the public
Contact form; it does not ship or print an email address. It refuses to create
the form if the address is invalid. If a feedback form already exists, the
script validates but does not replace its recipient. Changing the site's
email later does not update the form; edit its recipient separately in
Drupal's Contact forms administration screen.
composer require drupal/pixienote 'drush/drush:^13' --with-all-dependencies
cd web
../vendor/bin/drush recipe ../recipes/pixienote
../vendor/bin/drush php:script setup-contact --script-path=../recipes/pixienote/scripts
../vendor/bin/drush php:eval '\Drupal\node_view_permissions\NodeAccessRebuildHelper::rebuild();'
../vendor/bin/drush cr
../vendor/bin/drush cron
Do not create private records or open the site to other users before the
node-access rebuild finishes successfully. The Node View Permissions
module marks access grants for rebuilding during installation, but Drupal's
original public default grant may still be present until that rebuild. A
cache rebuild alone is not sufficient. Then create an authenticated user.
PixieNote intentionally ships no accounts or personal content. Ordinary
authenticated users can create contacts, bookmarks, notes, and schedules.
The main navigation + link opens /node/add. The i Services link list remains
available at /m and follows the source site's administrator-managed
permissions; use an administrator account to add service links. The standard
administration-menu Add content link remains available separately.
The Recipe includes a small set of public RSS feed definitions for English,
Japanese, Simplified Chinese, and Thai. Feed items are not included and are
fetched only when Drupal's Aggregator refreshes the feeds. Anonymous visitors
can read the i News lists; the other personal-service views remain protected.
The final drush cron command above performs the initial feed refresh so i News
is populated immediately after installation. It requires outbound access to
the included public feed URLs.
Re-applying the Recipe to an existing PixieNote installation is supported,
but existing configuration entities are not automatically overwritten.
Configuration actions do run again: they restore the Pixie Dark theme,
accessible-menu and print settings, clear anonymous permissions, and grant
the Recipe's authenticated permissions. They also keep the i Services View at
/m, remove its legacy main-menu entry, restore the standard administration
Add content link, and keep the separate main-menu + entry pointed at
/node/add. Review those actions before re-applying to a customized site.
Apply later configuration changes through Drupal's normal configuration
management workflow. Re-application is not a content migration or a
replacement for a site backup.
Updating
Back up the database, private files, and active configuration first. On a
standard Drupal 11 project, core-recipe-unpack moves the Recipe's package
dependencies into the site's composer.json and removes drupal/pixienote
as a direct requirement. Therefore composer update drupal/pixienote is not
an update path. Review the desired release and the site's root dependency
constraints, then fetch that Recipe release again. For the 1.x series, update
the Bootstrap Cloud and Twig root constraints at the same time. The installer
may have unpacked the old exact theme constraint into the site's root
composer.json; updating PixieNote alone could select an older Recipe release.
Confirm that the existing feedback Contact form still has the intended
recipient; rerunning setup-contact preserves it rather than syncing it to
the current site email address. Then run:
composer require 'drupal/pixienote:^1.0' 'drupal/bootstrap_cloud:7.1.7' 'twig/twig:>=3.29 <3.30' --with-all-dependencies
cd web
../vendor/bin/drush recipe ../recipes/pixienote
../vendor/bin/drush php:script setup-contact --script-path=../recipes/pixienote/scripts
../vendor/bin/drush php:eval '\Drupal\node_view_permissions\NodeAccessRebuildHelper::rebuild();'
../vendor/bin/drush cr
Recipe releases have no automatic update path. Existing configuration entities, including Views and blocks, retain local edits when a Recipe is re-applied, while configuration actions run again and can replace theme or permission customizations. Compare local configuration with the updated Recipe and import reviewed changes through your site's configuration management. Do not blindly replace the active configuration on a site with private data.
What is installed
| Content type | Purpose | List path |
|---|---|---|
| i Address | Contacts | /a |
| i Bookmark | Bookmarks | /b |
| i Note | Notes | /n |
| i Scheduler | Month and week calendars | /calendar |
| i Services | Administrator-managed service links | /m |
The i News feed list is at /f, with its Top page at /top and a recent-news
block on /m. The i Pics grid at /n/p shows images attached to the current
user's i Note records. These are Views, not extra content types. RSS feeds
and imported items are shared site content; they are not user-isolated.
A new contact's birthday is empty until entered; the source site's "today"
default is intentionally not carried over to avoid a misleading age.
Included RSS sample sources
| Language | Sources |
|---|---|
| English | BBC News |
| Japanese | asahi.com, Yahoo! ニュース, 毎日新聞, 日本経済新聞 |
| Simplified Chinese | 法广中文新闻, 央视国内新闻, 央视国际新闻, CCTV-新闻, CCTV-1, CCTV-2, CCTV-4 |
| Thai | Sanook! |
The feed URLs are public examples and can be edited or removed after
installation. The Recipe does not copy or publish any fetched feed items.
The six reference-site CCTV feeds returned HTTP 403 during the 2026-09-26
fresh-install check. The additional RFI Chinese news feed populated
the Simplified Chinese news list in that check. Public feed availability can
change; replace any source that becomes inaccessible.
The reference site's CNN Top Stories URL returned only April 2023 items in
the same check, so the Recipe uses BBC News for the English list instead.
The legacy CNN URL is http://rss.cnn.com/rss/cnn_topstories.rss; add it
manually only if its published items become current again.
The calendar opens at /calendar; /calendar/month is the reference site's
monthly alias, linked from a Calendar menu in the header only on calendar
pages. The weekly calendar is available at /calendar/week. Day and year
views at /calendar/day and /calendar/year are chronological lists rather than
calendar grids; both default to the current date or year and accept a date
argument in the URL. The schedule list remains at /calendar/list. The configuration
also installs an empty Tags vocabulary, tag lists,
search, a responsive Pixie Dark theme, an accessible menu, and a printable
browser view. Tags are optional at first because no example terms are
installed. The accessible menu loads its pinned JavaScript build from
jsDelivr; an offline installation needs a separately hosted copy. Bootstrap
Cloud is pinned to 7.1.7 so the tested Pixie Dark presentation does not
drift when a new theme release appears. The selected HiraMaruPro-W4 font is
not bundled with Bootstrap Cloud or this Recipe. Browsers without that font
use the theme's fallback stack, so exact typography depends on fonts
installed on each visitor's device.
Twig is temporarily constrained to 3.29.x: 3.30.0 produces a template
TypeError and HTTP 500 responses in the fresh Drupal 11.4.7 Recipe test
environment. The constraint is unpacked into the site's root Composer
requirements. Remove it only after an upstream fix is verified against the
full Recipe suite.
The footer uses the stable 3.4 series of the Copyright Footer module. Its
organization name, organization URL, origin year, version, and version URL
start empty. After applying the Recipe, set your own values in the Copyright
Footer block configuration; no publisher identity is installed as a site
default. Bootstrap Cloud 7.1.7 centers the copyright/Contact row, restores
the mobile navigation icon contrast, and fixes dark editor/form text colors.
The public Contact link appears beside the copyright text in a centered row.
The documented setup step creates the required Contact form from the
installing site's own mail setting.
Privacy defaults
PixieNote grants authenticated users permissions for their own personal
records and uses Node View Permissions for bundle-level view access. Review
role permissions before allowing multiple unrelated users onto one site.
Images use Drupal's private file scheme; configure file_private_path in
settings.php before enabling uploads.
Keep self-registration disabled, as in a fresh Minimal install. Taxonomy
terms are a shared vocabulary, so this Recipe is intended for a personal
site or a trusted group, not as a fully isolated multi-tenant service.
Aggregator feed sources and their items are also shared with authenticated
users; add only sources appropriate for that audience.
Verification
On a fresh test site, assert that the node-access rebuild flag is clear,
there is no nid = 0 default grant in node_access, and anonymous and
other authenticated users cannot read another owner's private record or
download its private image or thumbnail. The included functional and
privacy-audit tests exercise those conditions.
ReapplicationTest applies the Recipe to a populated, customized test site.
It verifies preservation of a note, its tag and private image (including the
file bytes), an edited RSS source, a Views title, a block weight, and the site
name. It checks that existing entity IDs are unchanged, documented theme and
permission actions run again, and the retained note and image remain readable
only by their owner. This tests reapplication of the same Recipe, not an
upgrade between different releases or a substitute for a backup/restore test.
To run this focused check in the Drupal test checkout, with its test server
running and the usual SIMPLETEST_* and browser-output variables configured:
vendor/bin/phpunit -c web/core/phpunit.xml.dist recipes/pixienote/tests/src/Functional/ReapplicationTest.php
If you use a PHP-enabled Drupal test checkout, run phpcs with the Drupal
and DrupalPractice standards and run the tests in tests/. Current
versions of several dependencies, including Calendar View and Printable,
emit Drupal 11 deprecation notices. PHP 8.4 additionally reports nullable
parameter deprecations in Calendar View. These are upstream compatibility
warnings, not passing evidence for future Drupal versions; do not suppress
test failures while reviewing them.
Scope
The Recipe reproduces the reusable structure and principal behavior of the source service. Production-only branding, analytics, advertising, mail settings, API credentials, content, and the site-specific print-link layout overlay are intentionally excluded. The production calendar uses a beta Calendar module with month, week, day, and year views. This Recipe recreates its month and week grids with the supported stable Calendar View module. Day and year views use Drupal core Views as chronological lists instead of grids, so the layout and navigation are not pixel-identical. PDF export relies on the browser's Print dialog; Printable's save-PDF feature is disabled.