feat(10.1-01): run registered widget actions through a cabana-owned route

- pact: AdminClientAssets, AdminAction, AdminActionInput, AdminActionResult,
  HasAdminActions and AdminPartialData contracts
- fields.yaml type: widget with widget, action and fill keys; boot checks the
  plugin tag prefix, the registered action and writable scalar fill fields
- POST .../widgets/{field} behind requireAjax, controller and action
  permissions, scoped non-locking record read and a server-side fill filter
- typed OpenAPI operation, inventories and an acme conformance case
This commit is contained in:
Jakub Zych
2026-09-28 23:35:00 +02:00
parent 9b98d8409f
commit f9281949a6
19 changed files with 876 additions and 10 deletions

View File

@@ -66,9 +66,10 @@ func TestPhase10CSRF(t *testing.T) {
}
})
}
// refresh, logout, settings put, create, bulk-delete, update, delete, link, unlink
if unsafe != 9 {
t.Fatalf("walked %d state-changing routes, want 9: %v", unsafe, router.order)
// refresh, logout, settings put, create, bulk-delete, widget action,
// update, delete, link, unlink
if unsafe != 10 {
t.Fatalf("walked %d state-changing routes, want 10: %v", unsafe, router.order)
}
loginHandler := router.handlers[login]