Compare commits

..

10 Commits

Author SHA1 Message Date
Gregor Vostrak
194fa6cf49 Remove task from time entry when project changes without a new task
PUT /time-entries/{id} accepted a new project_id while keeping a task from
the previous project, leaving the entry with a task that belongs to a
different project. The bulk endpoint already handled a project switch but
kept the task when the project was removed.

Both endpoints now remove the task whenever project_id is changed without
task_id and the current task does not belong to the new project.
2026-10-02 18:17:05 +02:00
Constantin Graf
349623d537 Reverted “Updated UUID generation” 2026-09-24 13:31:26 +02:00
Constantin Graf
a9d016d773 Added deletion of refresh tokens in DeletionService 2026-09-24 13:31:26 +02:00
Constantin Graf
2ebbbceefb Updated billing extension 2026-09-24 13:31:26 +02:00
Gregor Vostrak
e85058aefd add 1password ignore attributes for time tracker component inputs 2026-09-24 13:28:48 +02:00
Constantin Graf
a86c18ad2d Prevent non-primary mouse buttons from resizing events 2026-09-24 11:55:32 +02:00
dependabot[bot]
f683c03ff9 Bump the minor-updates group across 1 directory with 5 updates
Bumps the minor-updates group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [laravel/fortify](https://github.com/laravel/fortify) | `1.39.0` | `1.40.0` |
| [laravel/framework](https://github.com/laravel/framework) | `13.32.0` | `13.33.0` |
| [laravel/octane](https://github.com/laravel/octane) | `2.19.1` | `2.20.0` |
| [laravel/sail](https://github.com/laravel/sail) | `1.67.0` | `1.68.0` |
| [laravel/telescope](https://github.com/laravel/telescope) | `5.24.0` | `5.25.0` |



Updates `laravel/fortify` from 1.39.0 to 1.40.0
- [Release notes](https://github.com/laravel/fortify/releases)
- [Changelog](https://github.com/laravel/fortify/blob/1.x/CHANGELOG.md)
- [Commits](https://github.com/laravel/fortify/compare/v1.39.0...v1.40.0)

Updates `laravel/framework` from 13.32.0 to 13.33.0
- [Release notes](https://github.com/laravel/framework/releases)
- [Changelog](https://github.com/laravel/framework/blob/13.x/CHANGELOG.md)
- [Commits](https://github.com/laravel/framework/compare/v13.32.0...v13.33.0)

Updates `laravel/octane` from 2.19.1 to 2.20.0
- [Release notes](https://github.com/laravel/octane/releases)
- [Changelog](https://github.com/laravel/octane/blob/2.x/CHANGELOG.md)
- [Commits](https://github.com/laravel/octane/compare/v2.19.1...v2.20.0)

Updates `laravel/sail` from 1.67.0 to 1.68.0
- [Release notes](https://github.com/laravel/sail/releases)
- [Changelog](https://github.com/laravel/sail/blob/1.x/CHANGELOG.md)
- [Commits](https://github.com/laravel/sail/compare/v1.67.0...v1.68.0)

Updates `laravel/telescope` from 5.24.0 to 5.25.0
- [Release notes](https://github.com/laravel/telescope/releases)
- [Changelog](https://github.com/laravel/telescope/blob/5.x/CHANGELOG.md)
- [Commits](https://github.com/laravel/telescope/compare/v5.24.0...v5.25.0)

---
updated-dependencies:
- dependency-name: laravel/fortify
  dependency-version: 1.40.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-updates
- dependency-name: laravel/framework
  dependency-version: 13.33.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-updates
- dependency-name: laravel/octane
  dependency-version: 2.20.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-updates
- dependency-name: laravel/sail
  dependency-version: 1.68.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-updates
- dependency-name: laravel/telescope
  dependency-version: 5.25.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-24 11:35:35 +02:00
Constantin Graf
fa0bbc8cfd Add permission config to npm-format-check GitHub action 2026-09-24 11:31:38 +02:00
Constantin Graf
fff3502e53 Updated UUID generation 2026-09-24 11:31:38 +02:00
Constantin Graf
e801c4311c Add new extension auditing 2026-09-24 11:31:38 +02:00
10 changed files with 229 additions and 42 deletions

View File

@@ -679,6 +679,10 @@ class TimeEntryController extends Controller
$timeEntry->member()->associate($newMember);
$timeEntry->user()->associate($newMember->user);
}
// If project is changed, but task is not, we remove the old task from the time entry
if ($request->has('project_id') && ! $request->has('task_id') && $oldTask !== null && $oldTask->project_id !== $project?->getKey()) {
$timeEntry->task()->disassociate();
}
$timeEntry->description = $request->input('description', $timeEntry->description) ?? '';
$timeEntry->setComputedAttributeValue('billable_rate');
$timeEntry->save();
@@ -790,7 +794,7 @@ class TimeEntryController extends Controller
$timeEntry->user_id = $newMember->user_id;
}
// If project is changed, but task is not, we remove the old task from the time entry
if ($oldProject !== null && $project !== null && $oldProject->isNot($project) && $task === null) {
if ($request->has('changes.project_id') && ! $request->has('changes.task_id') && $oldTask !== null && $oldTask->project_id !== $project?->getKey()) {
$timeEntry->task()->disassociate();
}
if ($overwriteClient) {

View File

@@ -11,6 +11,7 @@ use App\Models\Client;
use App\Models\Member;
use App\Models\Organization;
use App\Models\OrganizationInvitation;
use App\Models\Passport\RefreshToken;
use App\Models\Project;
use App\Models\ProjectMember;
use App\Models\Report;
@@ -169,6 +170,10 @@ class DeletionService
}
}
// Refresh tokens are not linked to the user directly, so they need to be deleted via their access tokens.
// Otherwise a still-valid refresh token could be used to issue a new access token for a deleted user,
// which fails with a foreign key violation on oauth_access_tokens.user_id.
RefreshToken::query()->whereIn('access_token_id', $user->accessTokens()->pluck('id'))->delete();
$user->accessTokens()->delete();
$user->authCodes()->delete();

79
composer.lock generated
View File

@@ -429,23 +429,24 @@
},
{
"name": "brick/math",
"version": "0.19.1",
"version": "1.0.0",
"source": {
"type": "git",
"url": "https://github.com/brick/math.git",
"reference": "a89bc96a7cf3d7b59e725afe57ccb95eb03cf6ce"
"reference": "2effe05d2177c451b86c6a073196a4034c02f211"
},
"dist": {
"type": "zip",
"url": "https://api.github.com/repos/brick/math/zipball/a89bc96a7cf3d7b59e725afe57ccb95eb03cf6ce",
"reference": "a89bc96a7cf3d7b59e725afe57ccb95eb03cf6ce",
"url": "https://api.github.com/repos/brick/math/zipball/2effe05d2177c451b86c6a073196a4034c02f211",
"reference": "2effe05d2177c451b86c6a073196a4034c02f211",
"shasum": ""
},
"require": {
"php": "^8.2"
},
"require-dev": {
"phpstan/phpstan": "2.1.22",
"phpstan/phpstan": "2.2.13",
"phpstan/phpstan-phpunit": "2.0.18",
"phpunit/phpunit": "^11.5"
},
"type": "library",
@@ -476,7 +477,7 @@
],
"support": {
"issues": "https://github.com/brick/math/issues",
"source": "https://github.com/brick/math/tree/0.19.1"
"source": "https://github.com/brick/math/tree/1.0.0"
},
"funding": [
{
@@ -484,7 +485,7 @@
"type": "github"
}
],
"time": "2026-08-08T23:03:16+00:00"
"time": "2026-09-12T10:28:18+00:00"
},
{
"name": "brick/money",
@@ -4218,16 +4219,16 @@
},
{
"name": "laravel/fortify",
"version": "v1.39.0",
"version": "v1.40.0",
"source": {
"type": "git",
"url": "https://github.com/laravel/fortify.git",
"reference": "b1fc50707bbe007fd92165d8b7d460ab549b355a"
"reference": "fe0fce8814660317df0684f2c7be3b573def67d3"
},
"dist": {
"type": "zip",
"url": "https://api.github.com/repos/laravel/fortify/zipball/b1fc50707bbe007fd92165d8b7d460ab549b355a",
"reference": "b1fc50707bbe007fd92165d8b7d460ab549b355a",
"url": "https://api.github.com/repos/laravel/fortify/zipball/fe0fce8814660317df0684f2c7be3b573def67d3",
"reference": "fe0fce8814660317df0684f2c7be3b573def67d3",
"shasum": ""
},
"require": {
@@ -4278,24 +4279,24 @@
"issues": "https://github.com/laravel/fortify/issues",
"source": "https://github.com/laravel/fortify"
},
"time": "2026-08-23T07:46:41+00:00"
"time": "2026-09-10T11:52:08+00:00"
},
{
"name": "laravel/framework",
"version": "v13.32.0",
"version": "v13.33.0",
"source": {
"type": "git",
"url": "https://github.com/laravel/framework.git",
"reference": "cdd8b33c246719acdd118c705ce8c7ab5ef48a96"
"reference": "91188a17ceaa3dbace6e8a5f7abd0d042e466359"
},
"dist": {
"type": "zip",
"url": "https://api.github.com/repos/laravel/framework/zipball/cdd8b33c246719acdd118c705ce8c7ab5ef48a96",
"reference": "cdd8b33c246719acdd118c705ce8c7ab5ef48a96",
"url": "https://api.github.com/repos/laravel/framework/zipball/91188a17ceaa3dbace6e8a5f7abd0d042e466359",
"reference": "91188a17ceaa3dbace6e8a5f7abd0d042e466359",
"shasum": ""
},
"require": {
"brick/math": "^0.14.2 || ^0.15 || ^0.16 || ^0.17 || ^0.18 || ^0.19",
"brick/math": "^0.14.2 || ^0.15 || ^0.16 || ^0.17 || ^0.18 || ^0.19 || ^0.20 || ^1.0",
"composer-runtime-api": "^2.2",
"doctrine/inflector": "^2.0.5",
"dragonmantank/cron-expression": "^3.4",
@@ -4509,20 +4510,20 @@
"issues": "https://github.com/laravel/framework/issues",
"source": "https://github.com/laravel/framework"
},
"time": "2026-09-15T14:55:30+00:00"
"time": "2026-09-22T14:12:33+00:00"
},
{
"name": "laravel/octane",
"version": "v2.19.1",
"version": "v2.20.0",
"source": {
"type": "git",
"url": "https://github.com/laravel/octane.git",
"reference": "68a2516a0318baba0de0e4648f61e335c5e69dca"
"reference": "df4c38dcddc5f51e36e7f1d788841130c4fb8f45"
},
"dist": {
"type": "zip",
"url": "https://api.github.com/repos/laravel/octane/zipball/68a2516a0318baba0de0e4648f61e335c5e69dca",
"reference": "68a2516a0318baba0de0e4648f61e335c5e69dca",
"url": "https://api.github.com/repos/laravel/octane/zipball/df4c38dcddc5f51e36e7f1d788841130c4fb8f45",
"reference": "df4c38dcddc5f51e36e7f1d788841130c4fb8f45",
"shasum": ""
},
"require": {
@@ -4598,7 +4599,7 @@
"issues": "https://github.com/laravel/octane/issues",
"source": "https://github.com/laravel/octane"
},
"time": "2026-08-13T13:58:52+00:00"
"time": "2026-08-23T17:25:20+00:00"
},
{
"name": "laravel/passkeys",
@@ -4804,16 +4805,16 @@
},
{
"name": "laravel/serializable-closure",
"version": "v2.0.16",
"version": "v2.1.0",
"source": {
"type": "git",
"url": "https://github.com/laravel/serializable-closure.git",
"reference": "7cfc24e4fa2cca045fb8dd2a797a2b2b13b655ed"
"reference": "2d5869a838bbcf37e0d8b0568fc41914e81374b5"
},
"dist": {
"type": "zip",
"url": "https://api.github.com/repos/laravel/serializable-closure/zipball/7cfc24e4fa2cca045fb8dd2a797a2b2b13b655ed",
"reference": "7cfc24e4fa2cca045fb8dd2a797a2b2b13b655ed",
"url": "https://api.github.com/repos/laravel/serializable-closure/zipball/2d5869a838bbcf37e0d8b0568fc41914e81374b5",
"reference": "2d5869a838bbcf37e0d8b0568fc41914e81374b5",
"shasum": ""
},
"require": {
@@ -4861,7 +4862,7 @@
"issues": "https://github.com/laravel/serializable-closure/issues",
"source": "https://github.com/laravel/serializable-closure"
},
"time": "2026-08-18T20:28:54+00:00"
"time": "2026-09-22T14:32:34+00:00"
},
{
"name": "laravel/tinker",
@@ -15337,16 +15338,16 @@
},
{
"name": "laravel/sail",
"version": "v1.67.0",
"version": "v1.68.0",
"source": {
"type": "git",
"url": "https://github.com/laravel/sail.git",
"reference": "639e03ac12cf23def171770bcab05758045b2642"
"reference": "2bc304083d515065b03944e425e62cb3c526c33e"
},
"dist": {
"type": "zip",
"url": "https://api.github.com/repos/laravel/sail/zipball/639e03ac12cf23def171770bcab05758045b2642",
"reference": "639e03ac12cf23def171770bcab05758045b2642",
"url": "https://api.github.com/repos/laravel/sail/zipball/2bc304083d515065b03944e425e62cb3c526c33e",
"reference": "2bc304083d515065b03944e425e62cb3c526c33e",
"shasum": ""
},
"require": {
@@ -15396,7 +15397,7 @@
"issues": "https://github.com/laravel/sail/issues",
"source": "https://github.com/laravel/sail"
},
"time": "2026-08-12T13:55:56+00:00"
"time": "2026-09-18T14:34:46+00:00"
},
{
"name": "laravel/sentinel",
@@ -15456,16 +15457,16 @@
},
{
"name": "laravel/telescope",
"version": "v5.24.0",
"version": "v5.25.0",
"source": {
"type": "git",
"url": "https://github.com/laravel/telescope.git",
"reference": "50cbcf4553ddfd8d4bd456b04f97dfed923007d9"
"reference": "65fe6724f8688de01dfa74b28a0edc191bc3caa8"
},
"dist": {
"type": "zip",
"url": "https://api.github.com/repos/laravel/telescope/zipball/50cbcf4553ddfd8d4bd456b04f97dfed923007d9",
"reference": "50cbcf4553ddfd8d4bd456b04f97dfed923007d9",
"url": "https://api.github.com/repos/laravel/telescope/zipball/65fe6724f8688de01dfa74b28a0edc191bc3caa8",
"reference": "65fe6724f8688de01dfa74b28a0edc191bc3caa8",
"shasum": ""
},
"require": {
@@ -15518,9 +15519,9 @@
"monitoring"
],
"support": {
"source": "https://github.com/laravel/telescope/tree/v5.24.0"
"source": "https://github.com/laravel/telescope/tree/v5.25.0"
},
"time": "2026-09-08T16:15:16+00:00"
"time": "2026-09-09T14:16:19+00:00"
},
{
"name": "mockery/mockery",

View File

@@ -1,7 +1,7 @@
{
"Billing": {
"repository": "solidtime-io/extension-billing",
"ref": "v0.0.7"
"ref": "v0.0.8"
},
"Services": {
"repository": "solidtime-io/extension-services",

View File

@@ -111,6 +111,8 @@ export function useEventResize(params: {
edge: 'start' | 'end',
dayStr: string
) {
if (e.button !== 0) return;
e.preventDefault();
e.stopPropagation();

View File

@@ -168,6 +168,10 @@ defineExpose({ submit, focusAfterStart });
data-testid="time_entry_description"
class="w-full rounded-l-lg py-4 sm:py-2.5 px-3.5 border-b border-b-card-background-separator @2xl:px-4 text-base text-text-primary bg-transparent border-none placeholder-text-secondary focus:ring-0 transition"
type="text"
autocomplete="off"
data-1p-ignore
data-lpignore="true"
data-form-type="other"
@keydown.enter="submit"
@keydown.esc="showDropdown = false"
@blur="updateTimeEntryDescription" />

View File

@@ -170,6 +170,10 @@ function closeAndFocusInput() {
: 'text-text-primary bg-card-background border-border-secondary border border-none'
"
type="text"
autocomplete="off"
data-1p-ignore
data-lpignore="true"
data-form-type="other"
@focusin="openModalOnTab"
@click="openModalOnClick"
@keydown.exact.tab="focusNextElement"

View File

@@ -19,7 +19,7 @@ export const useNotificationsStore = defineStore('notifications', () => {
const showActionBlockedModal = ref(false);
function addNotification(type: NotificationType, title: string, message?: string) {
const uuid = crypto.randomUUID();
const uuid = Math.random().toString(36).substring(7);
notifications.value.push({ title, message, type, uuid });
setTimeout(() => {

View File

@@ -2780,6 +2780,90 @@ class TimeEntryEndpointTest extends ApiEndpointTestAbstract
});
}
public function test_update_endpoint_removes_task_if_project_is_changed_without_setting_a_new_task(): void
{
// Arrange
$data = $this->createUserWithPermission([
'time-entries:update:own',
'projects:view:all',
]);
$project1 = Project::factory()->forOrganization($data->organization)->create();
$project2 = Project::factory()->forOrganization($data->organization)->create();
$task1 = Task::factory()->forProject($project1)->forOrganization($data->organization)->create();
$timeEntry = TimeEntry::factory()->forOrganization($data->organization)->forProject($project1)->forTask($task1)->forMember($data->member)->create();
Passport::actingAs($data->user);
// Act
$response = $this->putJson(route('api.v1.time-entries.update', [$data->organization->getKey(), $timeEntry->getKey()]), [
'project_id' => $project2->getKey(),
]);
// Assert
$response->assertValid();
$this->assertResponseCode($response, 200);
$response->assertJsonPath('data.project_id', $project2->getKey());
$response->assertJsonPath('data.task_id', null);
$this->assertDatabaseHas(TimeEntry::class, [
'id' => $timeEntry->getKey(),
'project_id' => $project2->getKey(),
'task_id' => null,
]);
}
public function test_update_endpoint_removes_task_if_project_is_removed_without_removing_the_task(): void
{
// Arrange
$data = $this->createUserWithPermission([
'time-entries:update:own',
'projects:view:all',
]);
$project = Project::factory()->forOrganization($data->organization)->create();
$task = Task::factory()->forProject($project)->forOrganization($data->organization)->create();
$timeEntry = TimeEntry::factory()->forOrganization($data->organization)->forProject($project)->forTask($task)->forMember($data->member)->create();
Passport::actingAs($data->user);
// Act
$response = $this->putJson(route('api.v1.time-entries.update', [$data->organization->getKey(), $timeEntry->getKey()]), [
'project_id' => null,
]);
// Assert
$response->assertValid();
$this->assertResponseCode($response, 200);
$this->assertDatabaseHas(TimeEntry::class, [
'id' => $timeEntry->getKey(),
'project_id' => null,
'task_id' => null,
]);
}
public function test_update_endpoint_keeps_task_if_project_is_set_to_the_project_of_the_task(): void
{
// Arrange
$data = $this->createUserWithPermission([
'time-entries:update:own',
'projects:view:all',
]);
$project = Project::factory()->forOrganization($data->organization)->create();
$task = Task::factory()->forProject($project)->forOrganization($data->organization)->create();
$timeEntry = TimeEntry::factory()->forOrganization($data->organization)->forProject($project)->forTask($task)->forMember($data->member)->create();
Passport::actingAs($data->user);
// Act
$response = $this->putJson(route('api.v1.time-entries.update', [$data->organization->getKey(), $timeEntry->getKey()]), [
'project_id' => $project->getKey(),
]);
// Assert
$response->assertValid();
$this->assertResponseCode($response, 200);
$this->assertDatabaseHas(TimeEntry::class, [
'id' => $timeEntry->getKey(),
'project_id' => $project->getKey(),
'task_id' => $task->getKey(),
]);
}
public function test_update_endpoint_fails_if_employee_tries_to_update_time_entry_to_private_project_without_access(): void
{
// Arrange
@@ -3807,6 +3891,44 @@ class TimeEntryEndpointTest extends ApiEndpointTestAbstract
]);
}
public function test_update_multiple_removes_task_from_time_entries_if_project_is_removed_without_removing_the_task(): void
{
// Arrange
$data = $this->createUserWithPermission([
'time-entries:update:own',
'projects:view:all',
]);
$project = Project::factory()->forOrganization($data->organization)->create();
$task = Task::factory()->forProject($project)->forOrganization($data->organization)->create();
$timeEntry = TimeEntry::factory()->forOrganization($data->organization)->forProject($project)->forTask($task)->forMember($data->member)->create();
Passport::actingAs($data->user);
// Act
$response = $this->patchJson(route('api.v1.time-entries.update-multiple', [$data->organization->getKey()]), [
'ids' => [
$timeEntry->getKey(),
],
'changes' => [
'project_id' => null,
],
]);
// Assert
$response->assertValid();
$this->assertResponseCode($response, 200);
$response->assertExactJson([
'success' => [
$timeEntry->getKey(),
],
'error' => [],
]);
$this->assertDatabaseHas(TimeEntry::class, [
'id' => $timeEntry->getKey(),
'project_id' => null,
'task_id' => null,
]);
}
public function test_update_multiple_updates_own_time_entries_and_fails_for_time_entries_of_other_users_and_and_other_organizations_with_own_time_entries_permission(): void
{
// Arrange

View File

@@ -10,6 +10,9 @@ use App\Exceptions\Api\CanNotDeleteUserWhoIsOwnerOfOrganizationWithMultipleMembe
use App\Models\Client;
use App\Models\Member;
use App\Models\Organization;
use App\Models\Passport\Client as PassportClient;
use App\Models\Passport\RefreshToken;
use App\Models\Passport\Token;
use App\Models\Project;
use App\Models\ProjectMember;
use App\Models\Report;
@@ -23,6 +26,7 @@ use Illuminate\Support\Collection;
use Illuminate\Support\Facades\Event;
use Illuminate\Support\Facades\Log;
use Illuminate\Support\Facades\Storage;
use Illuminate\Support\Str;
use PHPUnit\Framework\Attributes\CoversClass;
use Tests\TestCaseWithDatabase;
use TiMacDonald\Log\LogEntry;
@@ -424,4 +428,45 @@ class DeletionServiceTest extends TestCaseWithDatabase
'role' => Role::Placeholder->value,
]);
}
public function test_delete_user_deletes_access_tokens_and_their_refresh_tokens_but_does_not_delete_tokens_of_other_users(): void
{
// Arrange
$user = User::factory()->create();
$otherUser = User::factory()->create();
$passportClient = PassportClient::factory()->create();
$userToken = Token::factory()->forUser($user)->forClient($passportClient)->create();
$userRefreshToken = RefreshToken::query()->create([
'id' => Str::random(100),
'access_token_id' => $userToken->getKey(),
'revoked' => false,
'expires_at' => now()->addDays(30),
]);
$otherUserToken = Token::factory()->forUser($otherUser)->forClient($passportClient)->create();
$otherUserRefreshToken = RefreshToken::query()->create([
'id' => Str::random(100),
'access_token_id' => $otherUserToken->getKey(),
'revoked' => false,
'expires_at' => now()->addDays(30),
]);
// Act
$this->deletionService->deleteUser($user);
// Assert
$this->assertDatabaseMissing(Token::class, [
'id' => $userToken->getKey(),
]);
$this->assertDatabaseMissing(RefreshToken::class, [
'id' => $userRefreshToken->getKey(),
]);
$this->assertDatabaseHas(Token::class, [
'id' => $otherUserToken->getKey(),
]);
$this->assertDatabaseHas(RefreshToken::class, [
'id' => $otherUserRefreshToken->getKey(),
]);
}
}