fix(10.1): WR-06 honour the widget field's context on the action route
widgetAction derives the form from the request (create without record_id, update with one) and answers 404 when the field's context hides the widget on that form, reusing contextAllows as the save path does. An update-only action can no longer run with a nil record through a direct POST.
This commit is contained in:
@@ -40,6 +40,17 @@ func (s *service) widgetAction(w http.ResponseWriter, r *http.Request) {
|
||||
writeCRUDError(w, err)
|
||||
return
|
||||
}
|
||||
// The field's context applies here as on save: without record_id
|
||||
// the request comes from the create form, with one from the update
|
||||
// form. A widget its context hides on that form does not exist.
|
||||
op := "create"
|
||||
if in.RecordID != nil {
|
||||
op = "update"
|
||||
}
|
||||
if !contextAllows(cc, field.Name, op) {
|
||||
WriteError(w, http.StatusNotFound, "not_found", msgNotFound)
|
||||
return
|
||||
}
|
||||
input := pact.AdminActionInput{Field: field.Name, Values: onlyFillScalars(field.Fill, in.Values)}
|
||||
if in.RecordID != nil {
|
||||
db, err := s.db()
|
||||
|
||||
Reference in New Issue
Block a user