feat(12.2-03): add parent-scoped child show, update, delete and pivot routes

- loadChild finds a child with one query carrying the parent predicate; a foreign child is 404
- GET/PUT .../records/{child} and POST .../delete (all or nothing) per relation kind
- hasMany link adopts NULL-key rows and unlink clears the key; pending created children are never candidates
- link accepts pivot values for one id through the pivot.form whitelist; GET/PUT .../pivot/{child}
- Link and Unlink share linkRelated/unlinkRelated for the deferred commit
This commit is contained in:
Jakub Zych
2026-10-02 18:44:34 +02:00
parent 48a5b8045a
commit afb05b6ee4
13 changed files with 2327 additions and 90 deletions

View File

@@ -68,9 +68,10 @@ func TestPhase10CSRF(t *testing.T) {
}
// refresh, logout, settings put, create, bulk-delete, widget action,
// toolbar action, update, delete, link, unlink, file upload, file
// reorder, file caption, file remove, relation child create
if unsafe != 16 {
t.Fatalf("walked %d state-changing routes, want 16: %v", unsafe, router.order)
// reorder, file caption, file remove, relation child create, update
// and delete, pivot update
if unsafe != 19 {
t.Fatalf("walked %d state-changing routes, want 19: %v", unsafe, router.order)
}
loginHandler := router.handlers[login]