feat(10.1-01): serve controller JS/CSS and run registered toolbar actions
- boardwalk exports ContentType and SetSecurityHeaders
- pact.AdminClientAssets files are read and hashed at boot and served by exact
key under {prefix}/assets/{vendor}/{plugin}/ with nosniff, CSP, CORP,
no-cache and an ETag; a miss falls through to the SPA
- list and form schemas carry assets URLs with a ?v= hash
- toolbar.buttons resolves create, delete and registered actions after decode;
toolbarActions is permission-filtered per admin
- POST .../toolbar/{action} behind requireAjax and action permissions
This commit is contained in:
@@ -273,13 +273,13 @@ func TestContentTypesAndCaching(t *testing.T) {
|
||||
if index.Header().Get("Cache-Control") != "no-store" || !strings.HasPrefix(index.Header().Get("Content-Type"), "text/html") {
|
||||
t.Fatalf("index headers = %v", index.Header())
|
||||
}
|
||||
if got := contentType("x.svg"); got != "image/svg+xml" {
|
||||
if got := ContentType("x.svg"); got != "image/svg+xml" {
|
||||
t.Fatalf("svg type %q", got)
|
||||
}
|
||||
if got := contentType("x.json"); got != "application/json" {
|
||||
if got := ContentType("x.json"); got != "application/json" {
|
||||
t.Fatalf("json type %q", got)
|
||||
}
|
||||
if got := contentType("x.unknown-ext"); got != "application/octet-stream" {
|
||||
if got := ContentType("x.unknown-ext"); got != "application/octet-stream" {
|
||||
t.Fatalf("unknown type %q", got)
|
||||
}
|
||||
}
|
||||
@@ -432,7 +432,7 @@ func TestPhase10BoardwalkServing(t *testing.T) {
|
||||
if cc := get(mapped, testPrefix+"/robots.txt").Header().Get("Cache-Control"); cc != "no-cache" {
|
||||
t.Fatalf("non-asset file Cache-Control=%q, want no-cache", cc)
|
||||
}
|
||||
if got := contentType("UPPER.JS"); got != "text/javascript; charset=utf-8" {
|
||||
if got := ContentType("UPPER.JS"); got != "text/javascript; charset=utf-8" {
|
||||
t.Fatalf("extension case: %q", got)
|
||||
}
|
||||
})
|
||||
|
||||
Reference in New Issue
Block a user