feat(10.1-01): serve controller JS/CSS and run registered toolbar actions

- boardwalk exports ContentType and SetSecurityHeaders
- pact.AdminClientAssets files are read and hashed at boot and served by exact
  key under {prefix}/assets/{vendor}/{plugin}/ with nosniff, CSP, CORP,
  no-cache and an ETag; a miss falls through to the SPA
- list and form schemas carry assets URLs with a ?v= hash
- toolbar.buttons resolves create, delete and registered actions after decode;
  toolbarActions is permission-filtered per admin
- POST .../toolbar/{action} behind requireAjax and action permissions
This commit is contained in:
Jakub Zych
2026-09-28 23:41:17 +02:00
parent f9281949a6
commit 8b1cb244de
23 changed files with 772 additions and 64 deletions

View File

@@ -67,9 +67,9 @@ func TestPhase10CSRF(t *testing.T) {
})
}
// refresh, logout, settings put, create, bulk-delete, widget action,
// update, delete, link, unlink
if unsafe != 10 {
t.Fatalf("walked %d state-changing routes, want 10: %v", unsafe, router.order)
// toolbar action, update, delete, link, unlink
if unsafe != 11 {
t.Fatalf("walked %d state-changing routes, want 11: %v", unsafe, router.order)
}
loginHandler := router.handlers[login]