feat(10.1-01): serve controller JS/CSS and run registered toolbar actions
- boardwalk exports ContentType and SetSecurityHeaders
- pact.AdminClientAssets files are read and hashed at boot and served by exact
key under {prefix}/assets/{vendor}/{plugin}/ with nosniff, CSP, CORP,
no-cache and an ETag; a miss falls through to the SPA
- list and form schemas carry assets URLs with a ?v= hash
- toolbar.buttons resolves create, delete and registered actions after decode;
toolbarActions is permission-filtered per admin
- POST .../toolbar/{action} behind requireAjax and action permissions
This commit is contained in:
@@ -77,6 +77,11 @@ type CompiledController struct {
|
||||
// the single namespace that toolbar.buttons names and widget action: keys
|
||||
// resolve through. create and delete are reserved built-in names.
|
||||
Actions map[string]pact.AdminAction
|
||||
|
||||
// scripts and styles are the controller's declared plugin JS and CSS,
|
||||
// in declared order.
|
||||
scripts []*pluginAsset
|
||||
styles []*pluginAsset
|
||||
}
|
||||
|
||||
// Registry is the immutable controller map keyed by controller ID.
|
||||
@@ -86,6 +91,9 @@ type Registry struct {
|
||||
roleGrants map[string]map[string]bool
|
||||
navigation []pact.NavigationItem
|
||||
settings map[string]*CompiledSetting
|
||||
// assets are every controller's declared plugin files keyed by URL tail
|
||||
// (vendor/plugin/<path after assets/>); the asset route serves only these.
|
||||
assets map[string]*pluginAsset
|
||||
}
|
||||
|
||||
// Get returns the compiled controller for a D-09 id (vendor.plugin.controller).
|
||||
|
||||
Reference in New Issue
Block a user