dvPageMiddlewareKeysUnavailableReason top-level constant
Why the remaining keys cannot be page middleware, and where each belongs.
Every one names a place to put the thing the developer wanted. A refusal that only says no leaves them with a working build and no feature, which is barely better than the silence this replaced.
Implementation
const Map<String, String> dvPageMiddlewareKeysUnavailableReason =
<String, String>{
'policy': 'Nothing in the middleware list says which policy, so this key '
'cannot decide anything. Declare it where the name goes: '
'@DVPage(policy: DVPolicies.yourPolicy), which the router enforces '
'before the page builds.',
'tenant': 'A tenant is resolved from the request that reaches the server, '
'and activating a route sends none. Declare it on the '
'@DVBackendFunction the page calls.',
'cors': 'CORS is a rule about who may call the server, answered on every '
'response including the preflight, which never reaches a route at '
'all. Configure it under dartvel.server.cors.',
'csrf': 'A CSRF token is checked where the state-changing request is '
'received. The generated backend already validates one on every such '
'request; a page has none to check.',
'rateLimit': 'A limit the caller enforces on itself is not a limit -- the '
'page and the visitor are the same machine, and anyone who wants past '
'it can call the API directly. Declare it on the @DVBackendFunction '
'the page calls.',
'rateLimitCheckout': 'Nothing implements this in any scope. It is not a '
'preset of rateLimit; there is no code behind the name. Use '
'DVMiddlewares.rateLimit on the @DVBackendFunction you meant to '
'limit.',
'requestLogging': 'This writes one line per request the server handles, '
'and a route activation is not one. Declare it on the '
'@DVBackendFunction.',
'tracing': 'The tracer spans a server request from arrival to response. A '
'route activation has neither end. Declare it on the '
'@DVBackendFunction.',
'securityHeaders': 'Headers go on an HTTP response, and activating a route '
'produces none -- the document carrying this page was sent long '
'before. Declare it on the @DVBackendFunction.',
'csp': 'A Content-Security-Policy reaches the browser as a header on the '
'document, and it is applied before any route exists. A route cannot '
'change the policy the page it is inside was loaded under. Set '
'dartvel.security.csp and declare DVMiddlewares.csp where the '
'document is served.',
'bodyLimit': 'A page never reads a request body, so there is nothing here '
'to cap. The limit belongs where the body is read: '
'@DVBackendFunction with DVMiddlewares.bodyLimit.',
'uploadLimit': 'A page never reads an upload, so there is nothing here to '
'cap. The limit belongs where the body is read: @DVBackendFunction '
'with DVMiddlewares.uploadLimit.',
'compression': 'Compression is negotiated between the server and the '
'browser when a response is sent. Configure it under '
'dartvel.server.compression, where false turns it off.',
'locale': 'The application has one locale at a time and I18n.load sets it. '
'Negotiating a different one per route would leave the page in one '
'language and the shell already rendered around it in another.',
'idempotency': 'An idempotency key belongs to a request that changes '
'something, and opening a page changes nothing. Declare it on the '
'@DVBackendFunction that writes.',
'cacheTags': 'Nothing implements this in any scope. Cache invalidation '
'lives on DV.Cache: set(key, value, tags: ...) and delete(DVCacheTag(...)).',
'featureFlags': 'Nothing in the middleware list says which flag. If the '
'flag decides who may open the page, that is @DVPage(policy: ...); if '
'it decides what a call returns, declare the key on the '
'@DVBackendFunction.',
};