Compare commits

..

8 Commits

Author SHA1 Message Date
Constantin Graf
c1abe73241 Updated Laravel to v13 2026-09-23 15:12:55 +02:00
Constantin Graf
0ef944a896 Add check for premium to telemetry and update lookup 2026-09-22 17:05:35 +02:00
Constantin Graf
2072223f19 Add basic e2e tests for admin panel 2026-09-22 17:05:35 +02:00
Constantin Graf
9ea774c1ac Address review feedback on composer updates
- Default INERTIA_SSR_ENABLED to false to match .env.example, .env.ci and
  .env.production, so existing setups keep the previous behaviour.
- Stop tracking the published Filament assets under /public/fonts/filament and
  add them to .gitignore, as recommended by the Filament docs. They are
  regenerated by filament:assets via the filament:upgrade post-autoload-dump
  hook. /public/css and /public/js are already ignored.
- Drop the now dead theme.css filter from the Vite asset list in app.blade.php,
  since the custom Filament theme was removed along with viteTheme().
2026-09-22 17:05:35 +02:00
Constantin Graf
d1f7e206f2 Add psysh to gitignore 2026-09-22 17:05:35 +02:00
Constantin Graf
5f23ce98d7 Add additional tests for filament 2026-09-22 17:05:35 +02:00
Constantin Graf
400df23035 Add github action to prevent non-tag refs in manifest.json 2026-09-22 17:05:35 +02:00
Constantin Graf
981bad5414 Updated compose dependencies 2026-09-22 17:05:35 +02:00
15 changed files with 244 additions and 142 deletions

View File

@@ -103,8 +103,6 @@ jobs:
{
echo "invoicing_repository=$(jq -r '.Invoicing.repository' extensions/manifest.json)"
echo "invoicing_ref=$(jq -r '.Invoicing.ref' extensions/manifest.json)"
echo "auditing_repository=$(jq -r '.Auditing.repository' extensions/manifest.json)"
echo "auditing_ref=$(jq -r '.Auditing.ref' extensions/manifest.json)"
} >> "$GITHUB_OUTPUT"
- name: "Checkout invoicing extension"
@@ -121,26 +119,9 @@ jobs:
- name: "Install npm dependencies in invoicing extension"
run: cd extensions/Invoicing && npm ci
- name: "Checkout auditing extension"
uses: actions/checkout@v7
with:
repository: ${{ steps.extension-manifest.outputs.auditing_repository }}
ref: ${{ steps.extension-manifest.outputs.auditing_ref }}
path: extensions/Auditing
ssh-key: ${{ secrets.SSH_PRIVATE_KEY_AUDITING_EXTENSION }}
- name: "Install composer dependencies in auditing extension"
run: cd extensions/Auditing && composer install --no-dev --no-ansi --no-interaction --prefer-dist --ignore-platform-reqs --classmap-authoritative
- name: "Install npm dependencies in auditing extension"
run: cd extensions/Auditing && npm ci
- name: "Activate invoicing extension"
run: php artisan module:enable Invoicing
- name: "Activate auditing extension"
run: php artisan module:enable Auditing
- name: "Install npm dependencies"
run: npm ci

View File

@@ -84,8 +84,6 @@ jobs:
echo "services_ref=$(jq -r '.Services.ref' extensions/manifest.json)"
echo "invoicing_repository=$(jq -r '.Invoicing.repository' extensions/manifest.json)"
echo "invoicing_ref=$(jq -r '.Invoicing.ref' extensions/manifest.json)"
echo "auditing_repository=$(jq -r '.Auditing.repository' extensions/manifest.json)"
echo "auditing_ref=$(jq -r '.Auditing.ref' extensions/manifest.json)"
} >> "$GITHUB_OUTPUT"
- name: "Checkout billing extension"
@@ -147,25 +145,6 @@ jobs:
- name: "Install npm dependencies in invoicing extension"
run: cd extensions/Invoicing && npm ci
- name: "Checkout auditing extension"
uses: actions/checkout@v7
with:
repository: ${{ steps.extension-manifest.outputs.auditing_repository }}
ref: ${{ steps.extension-manifest.outputs.auditing_ref }}
path: extensions/Auditing
ssh-key: ${{ secrets.SSH_PRIVATE_KEY_AUDITING_EXTENSION }}
- name: "Install composer dependencies in auditing extension"
uses: php-actions/composer@v6
with:
working_dir: "extensions/Auditing"
command: install
only_args: --no-dev --no-ansi --no-interaction --prefer-dist --ignore-platform-reqs --classmap-authoritative
php_version: 8.3
- name: "Install npm dependencies in auditing extension"
run: cd extensions/Auditing && npm ci
- name: "Setup PHP with PECL extension"
uses: shivammathur/setup-php@v2
with:
@@ -189,9 +168,6 @@ jobs:
- name: "Activate invoicing extension"
run: php artisan module:enable Invoicing
- name: "Activate auditing extension"
run: php artisan module:enable Auditing
- name: "Install npm dependencies"
run: npm ci

View File

@@ -1,8 +1,6 @@
name: NPM Format Check
on: [push]
permissions:
contents: read
jobs:
format-check:

View File

@@ -0,0 +1,99 @@
<?php
declare(strict_types=1);
namespace App\Filament\Resources;
use App\Filament\Resources\AuditResource\Pages\CreateAudit;
use App\Filament\Resources\AuditResource\Pages\ListAudits;
use App\Filament\Resources\AuditResource\Pages\ViewAudit;
use App\Models\Audit;
use Filament\Actions\ViewAction;
use Filament\Forms\Components\Textarea;
use Filament\Forms\Components\TextInput;
use Filament\Resources\Resource;
use Filament\Schemas\Schema;
use Filament\Tables\Columns\IconColumn;
use Filament\Tables\Columns\TextColumn;
use Filament\Tables\Table;
use Illuminate\Support\Str;
use Novadaemon\FilamentPrettyJson\Form\PrettyJsonField;
class AuditResource extends Resource
{
protected static ?string $model = Audit::class;
protected static string|\BackedEnum|null $navigationIcon = 'heroicon-o-archive-box';
protected static string|\UnitEnum|null $navigationGroup = 'System';
public static function form(Schema $schema): Schema
{
return $schema
->components([
TextInput::make('user_type')
->maxLength(255),
TextInput::make('user_id'),
TextInput::make('event')
->required()
->maxLength(255),
TextInput::make('auditable_type')
->required()
->maxLength(255),
TextInput::make('auditable_id')
->required(),
PrettyJsonField::make('old_values'),
PrettyJsonField::make('new_values'),
Textarea::make('url'),
TextInput::make('ip_address'),
TextInput::make('user_agent')
->maxLength(1023),
TextInput::make('tags')
->maxLength(255),
]);
}
public static function table(Table $table): Table
{
return $table
->columns([
TextColumn::make('user.name'),
TextColumn::make('event'),
TextColumn::make('auditable_type'),
TextColumn::make('auditable_id'),
IconColumn::make('was_command')
->getStateUsing(fn (Audit $record) => Str::startsWith($record->url, 'artisan '))
->boolean(),
TextColumn::make('created_at')
->sortable()
->dateTime(),
TextColumn::make('updated_at')
->sortable()
->dateTime(),
])
->filters([
//
])
->recordActions([
ViewAction::make(),
])
->toolbarActions([
])
->defaultSort('created_at', 'desc');
}
public static function getRelations(): array
{
return [
];
}
public static function getPages(): array
{
return [
'index' => ListAudits::route('/'),
'create' => CreateAudit::route('/create'),
'view' => ViewAudit::route('/{record}'),
];
}
}

View File

@@ -0,0 +1,13 @@
<?php
declare(strict_types=1);
namespace App\Filament\Resources\AuditResource\Pages;
use App\Filament\Resources\AuditResource;
use Filament\Resources\Pages\CreateRecord;
class CreateAudit extends CreateRecord
{
protected static string $resource = AuditResource::class;
}

View File

@@ -0,0 +1,18 @@
<?php
declare(strict_types=1);
namespace App\Filament\Resources\AuditResource\Pages;
use App\Filament\Resources\AuditResource;
use Filament\Resources\Pages\ListRecords;
class ListAudits extends ListRecords
{
protected static string $resource = AuditResource::class;
protected function getHeaderActions(): array
{
return [];
}
}

View File

@@ -0,0 +1,13 @@
<?php
declare(strict_types=1);
namespace App\Filament\Resources\AuditResource\Pages;
use App\Filament\Resources\AuditResource;
use Filament\Resources\Pages\ViewRecord;
class ViewAudit extends ViewRecord
{
protected static string $resource = AuditResource::class;
}

View File

@@ -11,7 +11,6 @@ use App\Models\Client;
use App\Models\Member;
use App\Models\Organization;
use App\Models\OrganizationInvitation;
use App\Models\Passport\RefreshToken;
use App\Models\Project;
use App\Models\ProjectMember;
use App\Models\Report;
@@ -170,10 +169,6 @@ class DeletionService
}
}
// Refresh tokens are not linked to the user directly, so they need to be deleted via their access tokens.
// Otherwise a still-valid refresh token could be used to issue a new access token for a deleted user,
// which fails with a foreign key violation on oauth_access_tokens.user_id.
RefreshToken::query()->whereIn('access_token_id', $user->accessTokens()->pluck('id'))->delete();
$user->accessTokens()->delete();
$user->authCodes()->delete();

View File

@@ -229,6 +229,7 @@ class ClockifyTimeEntriesImporter extends DefaultImporter
'Project',
'Description',
'User',
'Group',
'Email',
'Tags',
'Start Date',

79
composer.lock generated
View File

@@ -429,24 +429,23 @@
},
{
"name": "brick/math",
"version": "1.0.0",
"version": "0.19.1",
"source": {
"type": "git",
"url": "https://github.com/brick/math.git",
"reference": "2effe05d2177c451b86c6a073196a4034c02f211"
"reference": "a89bc96a7cf3d7b59e725afe57ccb95eb03cf6ce"
},
"dist": {
"type": "zip",
"url": "https://api.github.com/repos/brick/math/zipball/2effe05d2177c451b86c6a073196a4034c02f211",
"reference": "2effe05d2177c451b86c6a073196a4034c02f211",
"url": "https://api.github.com/repos/brick/math/zipball/a89bc96a7cf3d7b59e725afe57ccb95eb03cf6ce",
"reference": "a89bc96a7cf3d7b59e725afe57ccb95eb03cf6ce",
"shasum": ""
},
"require": {
"php": "^8.2"
},
"require-dev": {
"phpstan/phpstan": "2.2.13",
"phpstan/phpstan-phpunit": "2.0.18",
"phpstan/phpstan": "2.1.22",
"phpunit/phpunit": "^11.5"
},
"type": "library",
@@ -477,7 +476,7 @@
],
"support": {
"issues": "https://github.com/brick/math/issues",
"source": "https://github.com/brick/math/tree/1.0.0"
"source": "https://github.com/brick/math/tree/0.19.1"
},
"funding": [
{
@@ -485,7 +484,7 @@
"type": "github"
}
],
"time": "2026-09-12T10:28:18+00:00"
"time": "2026-08-08T23:03:16+00:00"
},
{
"name": "brick/money",
@@ -4219,16 +4218,16 @@
},
{
"name": "laravel/fortify",
"version": "v1.40.0",
"version": "v1.39.0",
"source": {
"type": "git",
"url": "https://github.com/laravel/fortify.git",
"reference": "fe0fce8814660317df0684f2c7be3b573def67d3"
"reference": "b1fc50707bbe007fd92165d8b7d460ab549b355a"
},
"dist": {
"type": "zip",
"url": "https://api.github.com/repos/laravel/fortify/zipball/fe0fce8814660317df0684f2c7be3b573def67d3",
"reference": "fe0fce8814660317df0684f2c7be3b573def67d3",
"url": "https://api.github.com/repos/laravel/fortify/zipball/b1fc50707bbe007fd92165d8b7d460ab549b355a",
"reference": "b1fc50707bbe007fd92165d8b7d460ab549b355a",
"shasum": ""
},
"require": {
@@ -4279,24 +4278,24 @@
"issues": "https://github.com/laravel/fortify/issues",
"source": "https://github.com/laravel/fortify"
},
"time": "2026-09-10T11:52:08+00:00"
"time": "2026-08-23T07:46:41+00:00"
},
{
"name": "laravel/framework",
"version": "v13.33.0",
"version": "v13.32.0",
"source": {
"type": "git",
"url": "https://github.com/laravel/framework.git",
"reference": "91188a17ceaa3dbace6e8a5f7abd0d042e466359"
"reference": "cdd8b33c246719acdd118c705ce8c7ab5ef48a96"
},
"dist": {
"type": "zip",
"url": "https://api.github.com/repos/laravel/framework/zipball/91188a17ceaa3dbace6e8a5f7abd0d042e466359",
"reference": "91188a17ceaa3dbace6e8a5f7abd0d042e466359",
"url": "https://api.github.com/repos/laravel/framework/zipball/cdd8b33c246719acdd118c705ce8c7ab5ef48a96",
"reference": "cdd8b33c246719acdd118c705ce8c7ab5ef48a96",
"shasum": ""
},
"require": {
"brick/math": "^0.14.2 || ^0.15 || ^0.16 || ^0.17 || ^0.18 || ^0.19 || ^0.20 || ^1.0",
"brick/math": "^0.14.2 || ^0.15 || ^0.16 || ^0.17 || ^0.18 || ^0.19",
"composer-runtime-api": "^2.2",
"doctrine/inflector": "^2.0.5",
"dragonmantank/cron-expression": "^3.4",
@@ -4510,20 +4509,20 @@
"issues": "https://github.com/laravel/framework/issues",
"source": "https://github.com/laravel/framework"
},
"time": "2026-09-22T14:12:33+00:00"
"time": "2026-09-15T14:55:30+00:00"
},
{
"name": "laravel/octane",
"version": "v2.20.0",
"version": "v2.19.1",
"source": {
"type": "git",
"url": "https://github.com/laravel/octane.git",
"reference": "df4c38dcddc5f51e36e7f1d788841130c4fb8f45"
"reference": "68a2516a0318baba0de0e4648f61e335c5e69dca"
},
"dist": {
"type": "zip",
"url": "https://api.github.com/repos/laravel/octane/zipball/df4c38dcddc5f51e36e7f1d788841130c4fb8f45",
"reference": "df4c38dcddc5f51e36e7f1d788841130c4fb8f45",
"url": "https://api.github.com/repos/laravel/octane/zipball/68a2516a0318baba0de0e4648f61e335c5e69dca",
"reference": "68a2516a0318baba0de0e4648f61e335c5e69dca",
"shasum": ""
},
"require": {
@@ -4599,7 +4598,7 @@
"issues": "https://github.com/laravel/octane/issues",
"source": "https://github.com/laravel/octane"
},
"time": "2026-08-23T17:25:20+00:00"
"time": "2026-08-13T13:58:52+00:00"
},
{
"name": "laravel/passkeys",
@@ -4805,16 +4804,16 @@
},
{
"name": "laravel/serializable-closure",
"version": "v2.1.0",
"version": "v2.0.16",
"source": {
"type": "git",
"url": "https://github.com/laravel/serializable-closure.git",
"reference": "2d5869a838bbcf37e0d8b0568fc41914e81374b5"
"reference": "7cfc24e4fa2cca045fb8dd2a797a2b2b13b655ed"
},
"dist": {
"type": "zip",
"url": "https://api.github.com/repos/laravel/serializable-closure/zipball/2d5869a838bbcf37e0d8b0568fc41914e81374b5",
"reference": "2d5869a838bbcf37e0d8b0568fc41914e81374b5",
"url": "https://api.github.com/repos/laravel/serializable-closure/zipball/7cfc24e4fa2cca045fb8dd2a797a2b2b13b655ed",
"reference": "7cfc24e4fa2cca045fb8dd2a797a2b2b13b655ed",
"shasum": ""
},
"require": {
@@ -4862,7 +4861,7 @@
"issues": "https://github.com/laravel/serializable-closure/issues",
"source": "https://github.com/laravel/serializable-closure"
},
"time": "2026-09-22T14:32:34+00:00"
"time": "2026-08-18T20:28:54+00:00"
},
{
"name": "laravel/tinker",
@@ -15338,16 +15337,16 @@
},
{
"name": "laravel/sail",
"version": "v1.68.0",
"version": "v1.67.0",
"source": {
"type": "git",
"url": "https://github.com/laravel/sail.git",
"reference": "2bc304083d515065b03944e425e62cb3c526c33e"
"reference": "639e03ac12cf23def171770bcab05758045b2642"
},
"dist": {
"type": "zip",
"url": "https://api.github.com/repos/laravel/sail/zipball/2bc304083d515065b03944e425e62cb3c526c33e",
"reference": "2bc304083d515065b03944e425e62cb3c526c33e",
"url": "https://api.github.com/repos/laravel/sail/zipball/639e03ac12cf23def171770bcab05758045b2642",
"reference": "639e03ac12cf23def171770bcab05758045b2642",
"shasum": ""
},
"require": {
@@ -15397,7 +15396,7 @@
"issues": "https://github.com/laravel/sail/issues",
"source": "https://github.com/laravel/sail"
},
"time": "2026-09-18T14:34:46+00:00"
"time": "2026-08-12T13:55:56+00:00"
},
{
"name": "laravel/sentinel",
@@ -15457,16 +15456,16 @@
},
{
"name": "laravel/telescope",
"version": "v5.25.0",
"version": "v5.24.0",
"source": {
"type": "git",
"url": "https://github.com/laravel/telescope.git",
"reference": "65fe6724f8688de01dfa74b28a0edc191bc3caa8"
"reference": "50cbcf4553ddfd8d4bd456b04f97dfed923007d9"
},
"dist": {
"type": "zip",
"url": "https://api.github.com/repos/laravel/telescope/zipball/65fe6724f8688de01dfa74b28a0edc191bc3caa8",
"reference": "65fe6724f8688de01dfa74b28a0edc191bc3caa8",
"url": "https://api.github.com/repos/laravel/telescope/zipball/50cbcf4553ddfd8d4bd456b04f97dfed923007d9",
"reference": "50cbcf4553ddfd8d4bd456b04f97dfed923007d9",
"shasum": ""
},
"require": {
@@ -15519,9 +15518,9 @@
"monitoring"
],
"support": {
"source": "https://github.com/laravel/telescope/tree/v5.25.0"
"source": "https://github.com/laravel/telescope/tree/v5.24.0"
},
"time": "2026-09-09T14:16:19+00:00"
"time": "2026-09-08T16:15:16+00:00"
},
{
"name": "mockery/mockery",

View File

@@ -19,6 +19,7 @@ const resourcePages = [
{ path: '/admin/project-members', heading: 'Project Members' },
{ path: '/admin/tokens', heading: 'Tokens' },
{ path: '/admin/failed-jobs', heading: 'Failed Jobs' },
{ path: '/admin/audits', heading: 'Audits' },
];
test.describe('Admin Panel Access', () => {

View File

@@ -1,7 +1,7 @@
{
"Billing": {
"repository": "solidtime-io/extension-billing",
"ref": "v0.0.8"
"ref": "v0.0.7"
},
"Services": {
"repository": "solidtime-io/extension-services",
@@ -10,9 +10,5 @@
"Invoicing": {
"repository": "solidtime-io/extension-invoicing",
"ref": "v0.0.7"
},
"Auditing": {
"repository": "solidtime-io/extension-auditing",
"ref": "v0.0.2"
}
}

View File

@@ -111,8 +111,6 @@ export function useEventResize(params: {
edge: 'start' | 'end',
dayStr: string
) {
if (e.button !== 0) return;
e.preventDefault();
e.stopPropagation();

View File

@@ -0,0 +1,59 @@
<?php
declare(strict_types=1);
namespace Tests\Unit\Filament\Resources;
use App\Filament\Resources\AuditResource;
use App\Models\Audit;
use App\Models\TimeEntry;
use App\Models\User;
use Illuminate\Support\Facades\Config;
use Illuminate\Support\Facades\DB;
use Livewire\Livewire;
use PHPUnit\Framework\Attributes\UsesClass;
use Tests\Unit\Filament\FilamentTestCase;
#[UsesClass(AuditResource::class)]
class AuditResourceTest extends FilamentTestCase
{
protected function setUp(): void
{
parent::setUp();
Config::set('auth.super_admins', ['admin@example.com']);
$user = User::factory()->withPersonalOrganization()->create([
'email' => 'admin@example.com',
]);
$this->actingAs($user);
}
public function test_can_list_audits(): void
{
// Arrange
$user = $this->createUserWithPermission();
$timeEntry = TimeEntry::factory()->forMember($user->member)->create();
DB::table((new Audit)->getTable())->delete();
$audits = Audit::factory()->auditFor($timeEntry)->auditUser($user->user)->createMany(5);
// Act
$response = Livewire::test(AuditResource\Pages\ListAudits::class);
// Assert
$response->assertSuccessful();
$response->assertCanSeeTableRecords($audits);
}
public function test_can_see_view_page_of_audit(): void
{
// Arrange
DB::table((new Audit)->getTable())->delete();
$audit = Audit::factory()->create();
// Act
$response = Livewire::test(AuditResource\Pages\ViewAudit::class, ['record' => $audit->getKey()]);
// Assert
$response->assertSuccessful();
}
}

View File

@@ -10,9 +10,6 @@ use App\Exceptions\Api\CanNotDeleteUserWhoIsOwnerOfOrganizationWithMultipleMembe
use App\Models\Client;
use App\Models\Member;
use App\Models\Organization;
use App\Models\Passport\Client as PassportClient;
use App\Models\Passport\RefreshToken;
use App\Models\Passport\Token;
use App\Models\Project;
use App\Models\ProjectMember;
use App\Models\Report;
@@ -26,7 +23,6 @@ use Illuminate\Support\Collection;
use Illuminate\Support\Facades\Event;
use Illuminate\Support\Facades\Log;
use Illuminate\Support\Facades\Storage;
use Illuminate\Support\Str;
use PHPUnit\Framework\Attributes\CoversClass;
use Tests\TestCaseWithDatabase;
use TiMacDonald\Log\LogEntry;
@@ -428,45 +424,4 @@ class DeletionServiceTest extends TestCaseWithDatabase
'role' => Role::Placeholder->value,
]);
}
public function test_delete_user_deletes_access_tokens_and_their_refresh_tokens_but_does_not_delete_tokens_of_other_users(): void
{
// Arrange
$user = User::factory()->create();
$otherUser = User::factory()->create();
$passportClient = PassportClient::factory()->create();
$userToken = Token::factory()->forUser($user)->forClient($passportClient)->create();
$userRefreshToken = RefreshToken::query()->create([
'id' => Str::random(100),
'access_token_id' => $userToken->getKey(),
'revoked' => false,
'expires_at' => now()->addDays(30),
]);
$otherUserToken = Token::factory()->forUser($otherUser)->forClient($passportClient)->create();
$otherUserRefreshToken = RefreshToken::query()->create([
'id' => Str::random(100),
'access_token_id' => $otherUserToken->getKey(),
'revoked' => false,
'expires_at' => now()->addDays(30),
]);
// Act
$this->deletionService->deleteUser($user);
// Assert
$this->assertDatabaseMissing(Token::class, [
'id' => $userToken->getKey(),
]);
$this->assertDatabaseMissing(RefreshToken::class, [
'id' => $userRefreshToken->getKey(),
]);
$this->assertDatabaseHas(Token::class, [
'id' => $otherUserToken->getKey(),
]);
$this->assertDatabaseHas(RefreshToken::class, [
'id' => $otherUserRefreshToken->getKey(),
]);
}
}