feat(10.1-01): run registered widget actions through a cabana-owned route
- pact: AdminClientAssets, AdminAction, AdminActionInput, AdminActionResult,
HasAdminActions and AdminPartialData contracts
- fields.yaml type: widget with widget, action and fill keys; boot checks the
plugin tag prefix, the registered action and writable scalar fill fields
- POST .../widgets/{field} behind requireAjax, controller and action
permissions, scoped non-locking record read and a server-side fill filter
- typed OpenAPI operation, inventories and an acme conformance case
This commit is contained in:
@@ -92,6 +92,9 @@ func compileRegistry(items []controllerRef) (*Registry, error) {
|
||||
if err := BindWritableFields(compiled); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if err := compileExtension(item.plugin.ID(), compiled, assets.AdminFS()); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
byID[id] = compiled
|
||||
}
|
||||
return &Registry{byID: byID}, nil
|
||||
@@ -179,6 +182,11 @@ func compileContributions(reg *Registry, plugins []party.Plugin) error {
|
||||
return err
|
||||
}
|
||||
}
|
||||
for name, action := range controller.Actions {
|
||||
if err := reg.validatePermissions("action "+id+"."+name, action.Permissions); err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
}
|
||||
for _, item := range reg.navigation {
|
||||
if err := reg.validateNavigation(item); err != nil {
|
||||
|
||||
Reference in New Issue
Block a user