fix(10.1): WR-06 honour the widget field's context on the action route

widgetAction derives the form from the request (create without record_id,
update with one) and answers 404 when the field's context hides the
widget on that form, reusing contextAllows as the save path does. An
update-only action can no longer run with a nil record through a direct
POST.
This commit is contained in:
Jakub Zych
2026-09-29 10:00:08 +02:00
parent 7b72bf4be4
commit 719ed719b4
3 changed files with 80 additions and 1 deletions

View File

@@ -40,6 +40,17 @@ func (s *service) widgetAction(w http.ResponseWriter, r *http.Request) {
writeCRUDError(w, err)
return
}
// The field's context applies here as on save: without record_id
// the request comes from the create form, with one from the update
// form. A widget its context hides on that form does not exist.
op := "create"
if in.RecordID != nil {
op = "update"
}
if !contextAllows(cc, field.Name, op) {
WriteError(w, http.StatusNotFound, "not_found", msgNotFound)
return
}
input := pact.AdminActionInput{Field: field.Name, Values: onlyFillScalars(field.Fill, in.Values)}
if in.RecordID != nil {
db, err := s.db()