feat(10-01): serve the embedded admin SPA at backend.uri with cookie login

- backend.uri prefix (default /backend) mounts the admin API at {prefix}/api/v1
  and the embedded SPA shell at {prefix} with an api/ JSON 404 fallback
- cookie transport: an X-Requested-With login sets the HttpOnly summer_admin
  cookie and returns no token; the backend guard reads the cookie after Bearer
- CSRF wrapper refuses cookie-only POST/PUT/DELETE without X-Requested-With
- boardwalk package embeds boardwalk/dist, rewrites index.html once per prefix
  and sets cache and security headers
- framework admin OpenAPI pipeline (swag, swagger2openapi, openapi-typescript)
  with prefix-relative paths and typed envelopes for the tracer routes
- admin/ Vite SPA: login, plugin rail, section panel and read-only list
  through the openapi-fetch client typed by the generated schema
This commit is contained in:
Jakub Zych
2026-09-27 15:21:48 +02:00
parent 8c3e131111
commit 5f9353841b
79 changed files with 10745 additions and 147 deletions

View File

@@ -104,10 +104,10 @@ func TestCRUDRecordRoutes(t *testing.T) {
cap := &captureRouter{}
(&service{}).mount(cap)
for _, want := range []string{
"POST /_admin/api/v1/{vendor}/{plugin}/{controller}",
"GET /_admin/api/v1/{vendor}/{plugin}/{controller}/{id}",
"PUT /_admin/api/v1/{vendor}/{plugin}/{controller}/{id}",
"DELETE /_admin/api/v1/{vendor}/{plugin}/{controller}/{id}",
"POST " + adminAPI("/{vendor}/{plugin}/{controller}"),
"GET " + adminAPI("/{vendor}/{plugin}/{controller}/{id}"),
"PUT " + adminAPI("/{vendor}/{plugin}/{controller}/{id}"),
"DELETE " + adminAPI("/{vendor}/{plugin}/{controller}/{id}"),
} {
mw, ok := cap.middleware[want]
if !ok {