feat(10.1-01): run registered widget actions through a cabana-owned route

- pact: AdminClientAssets, AdminAction, AdminActionInput, AdminActionResult,
  HasAdminActions and AdminPartialData contracts
- fields.yaml type: widget with widget, action and fill keys; boot checks the
  plugin tag prefix, the registered action and writable scalar fill fields
- POST .../widgets/{field} behind requireAjax, controller and action
  permissions, scoped non-locking record read and a server-side fill filter
- typed OpenAPI operation, inventories and an acme conformance case
This commit is contained in:
Jakub Zych
2026-09-28 23:35:00 +02:00
parent 9b98d8409f
commit f9281949a6
19 changed files with 876 additions and 10 deletions

View File

@@ -1,6 +1,34 @@
{
"components": {
"schemas": {
"cabana.AdminActionRequest": {
"properties": {
"record_id": {
"type": "integer"
},
"values": {
"additionalProperties": {},
"type": "object"
}
},
"type": "object"
},
"cabana.AdminActionResult": {
"properties": {
"fill": {
"additionalProperties": {},
"type": "object"
},
"message": {
"type": "string"
}
},
"required": [
"fill",
"message"
],
"type": "object"
},
"cabana.AdminIDsRequest": {
"properties": {
"ids": {
@@ -196,6 +224,21 @@
],
"type": "object"
},
"cabana.Envelope-cabana_AdminActionResult": {
"properties": {
"data": {
"$ref": "#/components/schemas/cabana.AdminActionResult"
},
"meta": {
"$ref": "#/components/schemas/cabana.SuccessMeta"
}
},
"required": [
"data",
"meta"
],
"type": "object"
},
"cabana.Envelope-cabana_AdminLoginData": {
"properties": {
"data": {
@@ -394,6 +437,14 @@
},
"cabana.FormField": {
"properties": {
"action": {
"description": "Action names the controller action the widget runs (pact.HasAdminActions).",
"type": "string"
},
"actionLabel": {
"description": "ActionLabel is the action's Label, localized per request.",
"type": "string"
},
"attributes": {
"additionalProperties": {
"$ref": "#/components/schemas/cabana.jsonScalar"
@@ -412,6 +463,13 @@
"emptyOption": {
"type": "string"
},
"fill": {
"description": "Fill lists the fields of the same form the action writes back (D-07).",
"items": {
"type": "string"
},
"type": "array"
},
"label": {
"type": "string"
},
@@ -450,6 +508,10 @@
},
"type": {
"type": "string"
},
"widget": {
"description": "Widget is the custom-element tag of a `type: widget` field (D-06).",
"type": "string"
}
},
"required": [
@@ -2668,6 +2730,121 @@
]
}
},
"/{vendor}/{plugin}/{controller}/widgets/{field}": {
"post": {
"description": "Runs the controller action a `type: widget` field declares. The record is loaded through the controller's form scope (404 when out of scope); only the field's fill keys with scalar values reach the action and the response.",
"parameters": [
{
"description": "Vendor",
"in": "path",
"name": "vendor",
"required": true,
"schema": {
"type": "string"
}
},
{
"description": "Plugin",
"in": "path",
"name": "plugin",
"required": true,
"schema": {
"type": "string"
}
},
{
"description": "Controller",
"in": "path",
"name": "controller",
"required": true,
"schema": {
"type": "string"
}
},
{
"description": "Widget field name",
"in": "path",
"name": "field",
"required": true,
"schema": {
"type": "string"
}
}
],
"requestBody": {
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/cabana.AdminActionRequest"
}
}
},
"description": "Record id and fill snapshot",
"required": true
},
"responses": {
"200": {
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/cabana.Envelope-cabana_AdminActionResult"
}
}
},
"description": "OK"
},
"401": {
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/cabana.ErrorEnvelope"
}
}
},
"description": "Unauthorized"
},
"403": {
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/cabana.ErrorEnvelope"
}
}
},
"description": "Forbidden"
},
"404": {
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/cabana.ErrorEnvelope"
}
}
},
"description": "Not Found"
},
"422": {
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/cabana.ErrorEnvelope"
}
}
},
"description": "Unprocessable Entity"
}
},
"security": [
{
"BackendBearer": []
}
],
"summary": "Run a widget action",
"tags": [
"admin"
]
}
},
"/{vendor}/{plugin}/{controller}/{id}": {
"delete": {
"parameters": [