- backend.uri prefix (default /backend) mounts the admin API at {prefix}/api/v1
and the embedded SPA shell at {prefix} with an api/ JSON 404 fallback
- cookie transport: an X-Requested-With login sets the HttpOnly summer_admin
cookie and returns no token; the backend guard reads the cookie after Bearer
- CSRF wrapper refuses cookie-only POST/PUT/DELETE without X-Requested-With
- boardwalk package embeds boardwalk/dist, rewrites index.html once per prefix
and sets cache and security headers
- framework admin OpenAPI pipeline (swag, swagger2openapi, openapi-typescript)
with prefix-relative paths and typed envelopes for the tracer routes
- admin/ Vite SPA: login, plugin rail, section panel and read-only list
through the openapi-fetch client typed by the generated schema
56 lines
1.1 KiB
JSON
56 lines
1.1 KiB
JSON
{
|
|
"data": [
|
|
{
|
|
"code": "demo",
|
|
"label": "Demo",
|
|
"icon": "disc-3",
|
|
"order": 100,
|
|
"controller": "acme.demo.widgets",
|
|
"sideMenu": [
|
|
{
|
|
"code": "widgets",
|
|
"label": "Widgets",
|
|
"icon": "tags",
|
|
"order": 0,
|
|
"controller": "acme.demo.widgets",
|
|
"sideMenu": []
|
|
},
|
|
{
|
|
"code": "gadgets",
|
|
"label": "Gadgets",
|
|
"icon": "icon-archive",
|
|
"order": 0,
|
|
"controller": "acme.demo.gadgets",
|
|
"sideMenu": []
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"code": "tools",
|
|
"label": "Tools",
|
|
"icon": "unknown-icon-name",
|
|
"order": 300,
|
|
"controller": "acme.tools.hammers",
|
|
"sideMenu": [
|
|
{
|
|
"code": "hammers",
|
|
"label": "Hammers",
|
|
"icon": "puzzle",
|
|
"order": 0,
|
|
"controller": "acme.tools.hammers",
|
|
"sideMenu": []
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"code": "hidden",
|
|
"label": "Hidden",
|
|
"icon": "users",
|
|
"order": 200,
|
|
"controller": "acme.hidden.items",
|
|
"sideMenu": []
|
|
}
|
|
],
|
|
"meta": { "locale": "en" }
|
|
}
|