feat(12.1-01): cabana.ForbiddenError answers a refused write with 403

- hooks and bulk, record, toolbar and widget actions may return it
- 403 forbidden with the localized message and field details; the write's
  transaction is rolled back; other errors stay the opaque 500
- form shows a refused save as a persistent banner and keeps the values;
  a refused delete is a toast
- smoke tests, OpenAPI notes, dist, README, docs
This commit is contained in:
Jakub Zych
2026-10-04 23:53:34 +02:00
parent 61d5fc72ad
commit 71073bc8a2
23 changed files with 486 additions and 48 deletions

View File

@@ -140,6 +140,11 @@ func (c actController) AdminActions() []pact.AdminAction {
return pact.AdminActionResult{}, &cabana.ValidationError{Details: map[string]any{"name": []string{"Name is taken."}}}
case "boom":
return pact.AdminActionResult{}, errors.New("upstream said hunter2")
case "refused":
return pact.AdminActionResult{}, &cabana.ForbiddenError{
Message: "acme.demo::lang.gadgets.looked_up",
Details: map[string]any{"name": []string{"acme.demo::lang.gadgets.name"}},
}
case "nested":
return pact.AdminActionResult{Fill: map[string]any{"name": []string{"a"}, "active": false}}, nil
case "encoded":