feat(10.1-01): render header and form partials into an allowlisted node tree

- fields.yaml type: partial with a bare path name and config_list.yaml
  headerPartial resolve to {ConfigDir}/_{name}.htm, parsed at boot; the
  controller must implement pact.AdminPartialData
- html/template render against a curated view model, then x/net/html
  ParseFragment and a tag, attribute and URL allowlist with 64 KiB, 2000-node
  and depth-32 caps; the model type and trusted template types are refused
- GET .../partials/{name} with optional ?id= loaded through the form scope
- golang.org/x/net becomes a direct requirement (D-18), no new module
This commit is contained in:
Jakub Zych
2026-09-28 23:52:50 +02:00
parent 8b1cb244de
commit 771d2ccce0
16 changed files with 850 additions and 18 deletions

View File

@@ -82,6 +82,11 @@ type CompiledController struct {
// in declared order.
scripts []*pluginAsset
styles []*pluginAsset
// partials are the parsed controller partials (headerPartial and every
// `type: partial` path) keyed by name; formPartials are the names form
// fields declare, the only ones a request may render with a record id.
partials map[string]*compiledPartial
formPartials map[string]bool
}
// Registry is the immutable controller map keyed by controller ID.