- backend.uri prefix (default /backend) mounts the admin API at {prefix}/api/v1
and the embedded SPA shell at {prefix} with an api/ JSON 404 fallback
- cookie transport: an X-Requested-With login sets the HttpOnly summer_admin
cookie and returns no token; the backend guard reads the cookie after Bearer
- CSRF wrapper refuses cookie-only POST/PUT/DELETE without X-Requested-With
- boardwalk package embeds boardwalk/dist, rewrites index.html once per prefix
and sets cache and security headers
- framework admin OpenAPI pipeline (swag, swagger2openapi, openapi-typescript)
with prefix-relative paths and typed envelopes for the tracer routes
- admin/ Vite SPA: login, plugin rail, section panel and read-only list
through the openapi-fetch client typed by the generated schema
8 lines
241 B
JSON
8 lines
241 B
JSON
{
|
|
"data": [
|
|
{ "id": 1, "name": "Blue widget", "code": "W-01", "tags": ["small", "round"] },
|
|
{ "id": 2, "name": "Green widget", "code": "W-02", "tags": [] }
|
|
],
|
|
"meta": { "page": 1, "per_page": 20, "total": 2, "last_page": 1 }
|
|
}
|