feat(12.2-02): add file removal, caption, reorder and protected downloads

- DELETE, PUT and POST reorder under .../{id}/files/{field}, each scoped by one parent query (404 for a foreign file)
- protected download and thumb routes: is_public=false only, nosniff, private no-store, sandbox CSP, inline only for jpeg/png/gif/webp
- the save applies deferred removals, replaces attachOne files and rechecks maxFiles and required
- blobs of deleted files are removed after commit
- swagger2openapi emits binary content for file responses
- admin OpenAPI, TS types, conformance, README and attachments docs
This commit is contained in:
Jakub Zych
2026-10-02 18:11:56 +02:00
parent 044e0450ef
commit e54fd257ee
17 changed files with 2237 additions and 82 deletions

View File

@@ -67,9 +67,10 @@ func TestPhase10CSRF(t *testing.T) {
})
}
// refresh, logout, settings put, create, bulk-delete, widget action,
// toolbar action, update, delete, link, unlink, file upload
if unsafe != 12 {
t.Fatalf("walked %d state-changing routes, want 12: %v", unsafe, router.order)
// toolbar action, update, delete, link, unlink, file upload, file
// reorder, file caption, file remove
if unsafe != 15 {
t.Fatalf("walked %d state-changing routes, want 15: %v", unsafe, router.order)
}
loginHandler := router.handlers[login]