fix(10.1): WR-05 drop widgets the admin may not run from the form schema
formSchema now filters type: widget fields by the action's permissions, the same D-12 filtering listSchema applies to toolbarActions, so an admin without the action permission no longer gets a button that always answers 403, and the action name is not revealed. The filtered fields are a new slice, so the cached schema is never modified.
This commit is contained in:
@@ -519,6 +519,21 @@ func (s *service) formSchema(w http.ResponseWriter, r *http.Request) {
|
||||
WriteError(w, http.StatusInternalServerError, "error", msgServerError)
|
||||
return
|
||||
}
|
||||
// Like toolbarActions in the list schema (D-12), a widget whose
|
||||
// action this admin may not run is not offered. A new slice: the
|
||||
// localized view must never share its backing array with the cache.
|
||||
principal, _ := bouncer.User(r.Context())
|
||||
kept := make([]FormField, 0, len(view.Fields))
|
||||
for _, field := range view.Fields {
|
||||
if field.Type == "widget" {
|
||||
action, ok := cc.Actions[field.Action]
|
||||
if !ok || !Allows(principal, action.Permissions) {
|
||||
continue
|
||||
}
|
||||
}
|
||||
kept = append(kept, field)
|
||||
}
|
||||
view.Fields = kept
|
||||
view.Assets = s.controllerAssets(cc)
|
||||
meta := map[string]any{}
|
||||
if view.Meta.Locale != "" {
|
||||
|
||||
Reference in New Issue
Block a user