enhancement
major
minor
major
minor
Affects 8.0.0-alpha8 (tl-layout-view). Found while building a sales application whose desk must not be reachable without login.
Any view file can be rendered top-level
ViewServlet.resolveViewPath takes whatever follows the window segment of the URL and, if it ends in .view.xml, loads /WEB-INF/views/<remainder> as the root of the browser tab. There is no list of views that may be entered this way. ViewConfig only knows default-view (app.view.xml).
So every view file the application or the framework ships is an entry point, although almost all of them are fragments: the framework's own login.view.xml, user-menu.view.xml, change-password.view.xml, otp.view.xml, mfa-enroll.view.xml, the admin/ tree, and every application dialog or pane that is meant to be reached through a <view-ref> or an <open-dialog>. Requesting /view/<window>/ida/pipeline.view.xml renders that pane outside the app shell, without the sidebar, the notices area, the input channels the enclosing view binds, and outside whatever the root view puts in front of it.
Requested: only views registered as entry points of the application may be loaded top-level. An application may declare several entry points (e.g. a public landing page next to the desk), but it must list them explicitly.
Lösung
- ViewConfig gets an entry-points list of view files (paths relative to /WEB-INF/views/, keyed by the path so that the configuration files of several modules merge). The default view (default-view) is an entry point implicitly.
- The ViewServlet resolves a .view.xml URL only against this list. A request naming a view that is not registered is answered with 404 Not Found: the URL is not part of the application's surface. A redirect to the default view would not be an alternative, because there is no way back to the requested view afterwards.
- The framework's own fragments (login.view.xml, user-menu.view.xml, the admin/ tree, the self-service dialogs, …) are not registered. An application that wants, say, the settings view as a bookmarkable entry registers it.
Example (<app>.config.xml): {{{#!xml <config config:interface="com.top_logic.layout.view.ViewConfig"> <entry-points> <entry-point view="landing.view.xml"/> </entry-points> </config> }}}
Not part of this ticket: gating entry points for anonymous sessions. Each top-level view is responsible for handling the anonymous case itself (e.g. a <switch> on currentUser() that shows the login instead of the desk); the framework does not redirect anonymous requests elsewhere.