test(12.2-05): prove relation child and protected file scoping through the router
- acme.deferred fixture plugin over testdata/deferred (test-only), two controllers, recording Form and Relation hooks, two admins - TestRelationChildScope*: every child route answers 404 for another parent, a hidden parent and another admin's pending child, changes nothing; undeclared toolbar buttons 403 before SQL; pivot whitelist - TestProtectedFile*: foreign, pending and public files 404; only jpeg, png, gif and webp inline; nosniff, no-store and sandbox CSP everywhere
This commit is contained in:
36
modules/cabana/testdata/deferred/controllers/gadgets/config_relation.yaml
vendored
Normal file
36
modules/cabana/testdata/deferred/controllers/gadgets/config_relation.yaml
vendored
Normal file
@@ -0,0 +1,36 @@
|
||||
# A belongsToMany relation with a manage form and a pivot form, and a
|
||||
# deferrable hasMany relation (nullable gadget_id) whose manage form lives
|
||||
# in the plugin's models directory ($/ path) and carries a fileupload and a
|
||||
# datepicker field. Both declare every toolbar button.
|
||||
members:
|
||||
label: Members
|
||||
view:
|
||||
list:
|
||||
columns:
|
||||
email:
|
||||
label: Email
|
||||
toolbarButtons: create|update|delete|link|unlink
|
||||
showSearch: true
|
||||
manage:
|
||||
form: $/acme/deferred/models/member/fields.yaml
|
||||
list:
|
||||
columns:
|
||||
email:
|
||||
label: Email
|
||||
showSearch: true
|
||||
pivot:
|
||||
form: $/acme/deferred/models/member/pivot_fields.yaml
|
||||
parts:
|
||||
label: Parts
|
||||
view:
|
||||
list:
|
||||
columns:
|
||||
label:
|
||||
label: Label
|
||||
toolbarButtons: create|update|delete|link|unlink
|
||||
manage:
|
||||
form: $/acme/deferred/models/part/fields.yaml
|
||||
list:
|
||||
columns:
|
||||
label:
|
||||
label: Label
|
||||
Reference in New Issue
Block a user