fix(09): WR-04 apply a form field's required flag only in the contexts that can supply it

This commit is contained in:
Jakub Zych
2026-10-01 21:05:33 +02:00
parent f2ab93f291
commit b8084080cb
2 changed files with 35 additions and 3 deletions

View File

@@ -335,7 +335,7 @@ func (s CRUDService) save(ctx context.Context, cc *CompiledController, id any, i
return &CapabilityError{ControllerID: controllerID(cc)}
}
}
rules := mergedRules(cc, target)
rules := mergedRules(cc, target, op)
msgs, err := lagoon.Validate(ctx, tx, target, rules, valuesForRules(target, rules), nil)
if err != nil {
return &CapabilityError{ControllerID: controllerID(cc)}
@@ -689,7 +689,10 @@ func fillAllowed(cc *CompiledController, model any, op string) []string {
return out
}
func mergedRules(cc *CompiledController, model any) map[string]string {
// mergedRules combines the model's rules with the form's `required` flags. A
// field whose `context` hides it on op cannot be supplied there, so its form
// level `required` does not apply to that operation.
func mergedRules(cc *CompiledController, model any, op string) map[string]string {
out := map[string]string{}
if rules, ok := model.(hasRules); ok && rules != nil {
for key, rule := range rules.Rules() {
@@ -702,7 +705,7 @@ func mergedRules(cc *CompiledController, model any) map[string]string {
for _, field := range cc.Form.Fields {
// Relation fields are not writable columns. required stays on the
// schema for the client, but it cannot be checked by Fill.
if field.Required && scalarFormField(field.Type) {
if field.Required && scalarFormField(field.Type) && contextAllows(cc, field.Name, op) {
out[field.Name] = mergeRequired(out[field.Name])
}
}