fix(09): WR-03 refuse writes that the compiled list and form do not declare

This commit is contained in:
Jakub Zych
2026-10-01 21:04:31 +02:00
parent 28aa073de0
commit f2ab93f291
8 changed files with 127 additions and 5 deletions

View File

@@ -221,4 +221,4 @@ Scope reads and writes with `pact.ListExtendQuery` and `pact.FormExtendQuery` ra
## Toolbar actions
`toolbar.buttons` in `config_list.yaml` lists the built-in `create` and `delete` and any action the controller registers through `pact.HasAdminActions`. See [Partials and widgets](partials-and-widgets.md) for actions and the rest of the extension points.
`toolbar.buttons` in `config_list.yaml` lists the built-in `create` and `delete` and any action the controller registers through `pact.HasAdminActions`. The declarations are enforced by the server, not only shown by the SPA. `POST /{controller}` needs a `config_form.yaml` and `create` in `toolbar.buttons`; `PUT` and `DELETE /{controller}/{id}` need a form (the form screen carries the delete button, as in WinterCMS); `POST /{controller}/bulk-delete` needs `delete` in `toolbar.buttons`, which in turn needs `showCheckboxes: true`. A write the controller does not declare answers 403 `forbidden`. See [Partials and widgets](partials-and-widgets.md) for actions and the rest of the extension points.