feat(10.1-01): render header and form partials into an allowlisted node tree
- fields.yaml type: partial with a bare path name and config_list.yaml
headerPartial resolve to {ConfigDir}/_{name}.htm, parsed at boot; the
controller must implement pact.AdminPartialData
- html/template render against a curated view model, then x/net/html
ParseFragment and a tag, attribute and URL allowlist with 64 KiB, 2000-node
and depth-32 caps; the model type and trusted template types are refused
- GET .../partials/{name} with optional ?id= loaded through the form scope
- golang.org/x/net becomes a direct requirement (D-18), no new module
This commit is contained in:
@@ -224,13 +224,15 @@ func TestFormSchemaRejects(t *testing.T) {
|
||||
name: "partial",
|
||||
config: formConfig,
|
||||
fields: "fields:\n editors:\n type: partial\n tab: Editors\n span: full\n",
|
||||
want: []string{"acme.demo", "acme.demo.widgets", "models/widget/fields.yaml", "partial"},
|
||||
// A partial now needs a path naming its template.
|
||||
want: []string{"acme.demo", "acme.demo.widgets", "models/widget/fields.yaml", "partial", "path"},
|
||||
},
|
||||
{
|
||||
name: "partial path",
|
||||
config: formConfig,
|
||||
fields: "fields:\n editors:\n type: partial\n path: $/golem15/acme/controllers/collections/_editors.htm\n",
|
||||
want: []string{"acme.demo", "acme.demo.widgets", "models/widget/fields.yaml", "path"},
|
||||
// Winter's $/ and ~/ paths are refused: only a bare partial name.
|
||||
want: []string{"acme.demo", "acme.demo.widgets", "models/widget/fields.yaml", "partial", "path", "not supported"},
|
||||
},
|
||||
{
|
||||
name: "missing fields",
|
||||
@@ -277,7 +279,7 @@ func TestFormSchemaRejects(t *testing.T) {
|
||||
plugin: &formPlugin{fsys: fsys},
|
||||
ctl: schemaController{model: "Widget"},
|
||||
}})
|
||||
if err == nil || !strings.Contains(err.Error(), "partial") {
|
||||
if err == nil || !strings.Contains(err.Error(), "partial") || !strings.Contains(err.Error(), "path") {
|
||||
t.Fatalf("activation err = %v", err)
|
||||
}
|
||||
})
|
||||
|
||||
Reference in New Issue
Block a user