security headers, notifications, GDPR consent, masked fields

This commit is contained in:
2026-08-21 19:03:14 +02:00
parent 81fa409513
commit 05b3dc8cb1
37 changed files with 569 additions and 14 deletions
+82
View File
@@ -0,0 +1,82 @@
/**
* Fields for the Notifications global — localized user-facing texts for action
* results (form submission outcomes, and future contexts). Every text is
* localized: true so each language has its own value. Empty fields fall back to
* built-in English defaults (see modules/notifications/defaults).
*
* Grouped per context. `form` holds the outcomes of submitForm; more groups
* (e.g. `newsletter`, `system`) can be added the same way without touching
* consumers — getNotificationTexts resolves whatever exists, falling back
* per field.
*/ export const notificationsFields = [
{
name: 'form',
type: 'group',
admin: {
description: 'Messages shown after a form is submitted. Leave a field empty to use the built-in default.'
},
fields: [
{
name: 'success',
type: 'text',
admin: {
placeholder: 'Thank you — your message has been sent.'
},
localized: true
},
{
name: 'error',
type: 'text',
admin: {
placeholder: 'Something went wrong. Please try again later.'
},
localized: true
},
{
name: 'rateLimited',
type: 'text',
admin: {
placeholder: 'Too many attempts. Please wait a moment and try again.'
},
localized: true
},
{
name: 'turnstile',
type: 'text',
admin: {
placeholder: 'Captcha verification failed. Please try again.'
},
localized: true
},
{
name: 'validation',
type: 'text',
admin: {
description: 'Shown on a validation error. Use {field} to insert the offending field name.',
placeholder: 'Please check the {field} field and try again.'
},
localized: true
},
{
name: 'consent',
type: 'text',
admin: {
description: 'Shown when the GDPR consent checkbox is left unchecked.',
placeholder: 'Please accept the privacy policy to continue.'
},
localized: true
},
{
name: 'notFound',
type: 'text',
admin: {
placeholder: 'This form is no longer available.'
},
localized: true
}
],
label: 'Form messages'
}
];
//# sourceMappingURL=fields.js.map
+1
View File
@@ -0,0 +1 @@
{"version":3,"sources":["../../../src/globals/Notifications/fields.ts"],"sourcesContent":["import type { Field } from 'payload'\n\n/**\n * Fields for the Notifications global — localized user-facing texts for action\n * results (form submission outcomes, and future contexts). Every text is\n * localized: true so each language has its own value. Empty fields fall back to\n * built-in English defaults (see modules/notifications/defaults).\n *\n * Grouped per context. `form` holds the outcomes of submitForm; more groups\n * (e.g. `newsletter`, `system`) can be added the same way without touching\n * consumers — getNotificationTexts resolves whatever exists, falling back\n * per field.\n */\nexport const notificationsFields: Field[] = [\n {\n name: 'form',\n type: 'group',\n admin: {\n description:\n 'Messages shown after a form is submitted. Leave a field empty to use the built-in default.',\n },\n fields: [\n {\n name: 'success',\n type: 'text',\n admin: { placeholder: 'Thank you — your message has been sent.' },\n localized: true,\n },\n {\n name: 'error',\n type: 'text',\n admin: { placeholder: 'Something went wrong. Please try again later.' },\n localized: true,\n },\n {\n name: 'rateLimited',\n type: 'text',\n admin: { placeholder: 'Too many attempts. Please wait a moment and try again.' },\n localized: true,\n },\n {\n name: 'turnstile',\n type: 'text',\n admin: { placeholder: 'Captcha verification failed. Please try again.' },\n localized: true,\n },\n {\n name: 'validation',\n type: 'text',\n admin: {\n description:\n 'Shown on a validation error. Use {field} to insert the offending field name.',\n placeholder: 'Please check the {field} field and try again.',\n },\n localized: true,\n },\n {\n name: 'consent',\n type: 'text',\n admin: {\n description: 'Shown when the GDPR consent checkbox is left unchecked.',\n placeholder: 'Please accept the privacy policy to continue.',\n },\n localized: true,\n },\n {\n name: 'notFound',\n type: 'text',\n admin: { placeholder: 'This form is no longer available.' },\n localized: true,\n },\n ],\n label: 'Form messages',\n },\n]\n"],"names":["notificationsFields","name","type","admin","description","fields","placeholder","localized","label"],"mappings":"AAEA;;;;;;;;;;CAUC,GACD,OAAO,MAAMA,sBAA+B;IAC1C;QACEC,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aACE;QACJ;QACAC,QAAQ;YACN;gBACEJ,MAAM;gBACNC,MAAM;gBACNC,OAAO;oBAAEG,aAAa;gBAA0C;gBAChEC,WAAW;YACb;YACA;gBACEN,MAAM;gBACNC,MAAM;gBACNC,OAAO;oBAAEG,aAAa;gBAAgD;gBACtEC,WAAW;YACb;YACA;gBACEN,MAAM;gBACNC,MAAM;gBACNC,OAAO;oBAAEG,aAAa;gBAAyD;gBAC/EC,WAAW;YACb;YACA;gBACEN,MAAM;gBACNC,MAAM;gBACNC,OAAO;oBAAEG,aAAa;gBAAiD;gBACvEC,WAAW;YACb;YACA;gBACEN,MAAM;gBACNC,MAAM;gBACNC,OAAO;oBACLC,aACE;oBACFE,aAAa;gBACf;gBACAC,WAAW;YACb;YACA;gBACEN,MAAM;gBACNC,MAAM;gBACNC,OAAO;oBACLC,aAAa;oBACbE,aAAa;gBACf;gBACAC,WAAW;YACb;YACA;gBACEN,MAAM;gBACNC,MAAM;gBACNC,OAAO;oBAAEG,aAAa;gBAAoC;gBAC1DC,WAAW;YACb;SACD;QACDC,OAAO;IACT;CACD,CAAA"}
+17
View File
@@ -0,0 +1,17 @@
import { notificationsFields } from './fields.js';
/**
* Builds the Notifications global — localized action-result texts. Readable by
* any authenticated panel user; server-side helpers read it with overrideAccess
* so the frontend can resolve texts without a session.
*/ export function buildNotifications() {
return {
slug: 'notifications',
label: 'Notifications',
access: {
read: ()=>true
},
fields: notificationsFields
};
}
//# sourceMappingURL=index.js.map
+1
View File
@@ -0,0 +1 @@
{"version":3,"sources":["../../../src/globals/Notifications/index.ts"],"sourcesContent":["import type { GlobalConfig } from 'payload'\nimport { notificationsFields } from './fields.js'\n\n/**\n * Builds the Notifications global — localized action-result texts. Readable by\n * any authenticated panel user; server-side helpers read it with overrideAccess\n * so the frontend can resolve texts without a session.\n */\nexport function buildNotifications(): GlobalConfig {\n return {\n slug: 'notifications',\n label: 'Notifications',\n access: {\n read: () => true, // texts are public-facing (shown to end users)\n },\n fields: notificationsFields,\n }\n}\n"],"names":["notificationsFields","buildNotifications","slug","label","access","read","fields"],"mappings":"AACA,SAASA,mBAAmB,QAAQ,cAAa;AAEjD;;;;CAIC,GACD,OAAO,SAASC;IACd,OAAO;QACLC,MAAM;QACNC,OAAO;QACPC,QAAQ;YACNC,MAAM,IAAM;QACd;QACAC,QAAQN;IACV;AACF"}