pkg/actionprovides type-safe server functions that can be called directly from your components without manually configuring HTTP route handlers, serializers, or API endpoints.
Dual-Mode Progressive Enhancement
- Modern Browsers (WASM active):Executes an asynchronous RPC call over
fetch()without refreshing or redirecting the browser page. - Zero-JS / Degraded Clients:Submits via a standard HTML form POST with automatic redirection and error flash messages, ensuring 100% accessible operation without client-side scripts.
Server Action Example
app/feedback/page.gox
package feedback
import (
"context"
"fmt"
"github.com/misbakhul29/goks/pkg/action"
"github.com/misbakhul29/goks/pkg/component"
"github.com/misbakhul29/goks/pkg/html"
)
type FeedbackInput struct {
Comment string `form:"comment" json:"comment"`
}
var SubmitFeedback = action.Define("submitFeedback", func(ctx context.Context, input FeedbackInput) error {
fmt.Printf("Received feedback: %s\n", input.Comment)
return nil
})
type Page struct {
component.ComponentBase
}
func (p *Page) Render() *component.Node {
return html.Form(html.Input().Attr("name", "_csrf").Attr("type", "hidden").Attr("value", action.GetCSRFToken()), html.Label("Your Feedback").Class("block text-sm font-medium text-slate-300"), html.Textarea().Class("w-full p-3 rounded-lg bg-slate-900 border border-slate-700").Attr("name", "comment"), html.Button("Send Feedback").Class("px-5 py-2.5 rounded-lg bg-cyan-500 text-slate-950 font-bold").Attr("type", "submit")).Attr("action", SubmitFeedback.URL()).Class("space-y-4 max-w-md").Attr("method", "POST")
}Security by Default
Every Server Action is guarded by cryptographic CSRF tokens, strict origin verification, and request payload size limits. Any action invoked without a valid token is rejected with an HTTP 403 Forbidden status.