DataTable replaces the 20-line Table scaffold entirely: columns, sorting, filtering, pagination, selection, bulk actions, comparison layout, sticky first column, custom HTML cells, and a remote source driven by a `request` output rather than a function prop (props travel as HTML attributes, so a function arrives as its own source text). Toaster replaces the hand-rolled status div: tone icons, actions, hover pause/resume and a progress bar. Overlays audit -- Modal and Drawer declared aria-modal="true" but nothing ever moved focus into the panel, so the @keydown handler on their root never ran and closeOnEscape did nothing. Focus, focus restore, a Tab trap and a body scroll lock now live in the reactive runtime, shared by both. ContextMenu placed pointer menus by subtracting a guessed 340x420 from the viewport, which pushed every menu that was not that size away from the pointer; it now positions at the pointer and lets the anchored clamp pull it back once it can be measured. The reactive runtime size budget moves 150k -> 175k to cover anchored overlays, dialog behaviour, the toaster and the DataTable client half. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
27 lines
1.1 KiB
TypeScript
27 lines
1.1 KiB
TypeScript
// API route: POST /api/invite. Validates the body with the SAME schema the
|
|
// modal's invite form uses in the browser, so a request that bypasses the
|
|
// client (curl, a replayed fetch, a stale page) is held to identical rules.
|
|
//
|
|
// There is no mail provider wired up in the example, so a successful parse
|
|
// just echoes the invite back. The point being demonstrated is the shared
|
|
// schema and the client/server round trip, not delivery.
|
|
import { verifyCsrf, type Context } from "@wrnexus/core";
|
|
import { parseBody } from "@wrnexus/validation";
|
|
import invite from "../schemas/invite.ts";
|
|
|
|
export async function POST(ctx: Context): Promise<Response> {
|
|
if (!verifyCsrf(ctx)) return new Response("Invalid CSRF token", { status: 403 });
|
|
|
|
const result = await parseBody(invite, ctx.req);
|
|
if (!result.ok) return result.response; // 400 { ok:false, errors } — rendered per field
|
|
|
|
const { email, message } = result.value as { email: string; message?: string };
|
|
|
|
return Response.json({
|
|
ok: true,
|
|
email,
|
|
message: message ?? "",
|
|
sentAt: new Date().toISOString(),
|
|
});
|
|
}
|