feat: add wildcard token support for allowed extensions and access token CLI commands

Introduce WILDCARD_TOKENS set in attachments.py to treat "*", ".*", "*.*" as wildcards that fall back to ALLOWED_UPLOAD_TYPES. Add cmd_token_issue and cmd_token_list CLI commands for issuing and listing DevPlace access tokens. Register access_tokens table in SOFT_DELETE_TABLES and initialize its columns and indexes in init_db. Replace Form() with Depends(json_or_form(...)) in admin backup, container, notification, settings, and user routers to support both JSON and form data.
This commit is contained in:
2026-06-17 17:10:52 +00:00
parent 217210e02f
commit 9598a1b867
45 changed files with 436 additions and 284 deletions
@@ -29,7 +29,7 @@ Set with the `mode` attribute:
| `allowed-types` | (none) | Comma list of permitted extensions, e.g. `.jpg,.png`. |
| `max-size` | `10` | Maximum size per file, in MB. |
| `max-files` | `10` | Maximum number of files. |
| `hide-chips` | off | Suppress the per-file name chips and keep only the `(N)` count badge on the button. |
| `show-chips` | off | Show the per-file name chips. Off by default, so only the `(N)` count badge appears on the button and no file name is ever shown. |
| `endpoint` | `/uploads/upload` | Upload URL (attachment / direct). |
| `name` | `attachment_uids` | Hidden field name for collected UIDs (attachment mode). |
| `field-name` | `file` | File field name in upload requests / native field mode. |