Compare commits

...

10 Commits

Author SHA1 Message Date
Gregor Vostrak
eb7233dfba anchor cross-day calendar e2e tests to Wednesday and Thursday
The tests used today and tomorrow (or yesterday) and skipped when those fell outside the visible week. The Saturday skips were also wrong for the Monday week start e2e users get, so the tests failed whenever CI ran on a Sunday. Using Wednesday and Thursday of the current week keeps both days visible whichever day the suite runs, so the day-of-week skips are gone.
2026-09-28 17:18:40 +02:00
Gregor Vostrak
398a81798b move project task count into its own sortable column
Also removes the ring around the project color dot, shrinks it slightly and tightens its spacing to the name.
2026-09-28 17:18:40 +02:00
Gregor Vostrak
d54296e66a fix live timer restarting while duration input is paused 2026-09-16 15:34:16 +02:00
Gregor Vostrak
95ddbf9ead fix placeholder users being resolved by authentication flows 2026-09-16 15:25:08 +02:00
Constantin Graf
70646a0dd4 Add additional validation for import, Enhanced ZIP extraction in importer 2026-09-16 15:02:54 +02:00
Gregor Vostrak
5b12c09747 bump invoicing extension to v0.0.6 for pagination ui package change 2026-09-07 17:13:20 +02:00
Gregor Vostrak
24023353f2 bump ui package version 2026-09-07 16:40:55 +02:00
Gregor Vostrak
720d20c10e move pagination component to ui package 2026-09-07 16:40:55 +02:00
Gregor Vostrak
82ea9af8b5 fix radix dialog focus restore behaviour 2026-09-04 14:55:09 +02:00
Gregor Vostrak
169d522da0 fix activity graph border color 2026-09-03 17:15:19 +02:00
41 changed files with 1207 additions and 303 deletions

View File

@@ -0,0 +1,37 @@
<?php
declare(strict_types=1);
namespace App\Auth;
use Illuminate\Auth\EloquentUserProvider;
use Illuminate\Database\Eloquent\Builder;
use Illuminate\Database\Eloquent\Model;
/**
* User provider that only resolves non-placeholder users.
*
* Placeholder users are created by imports and when members are removed from an
* organization. They can share an email address with a real user, so resolving a user by
* email can return a placeholder instead of the real account. The login flow filters them
* out explicitly, but the password broker and the guard credential checks (for example the
* password confirmation) resolve users through the configured user provider.
*
* Registered as the "eloquent" provider driver in the AuthServiceProvider, so it replaces the
* built-in one for every provider in config/auth.php.
*/
class ActiveUserProvider extends EloquentUserProvider
{
/**
* @param Model|null $model
* @return Builder<Model>
*/
#[\Override]
protected function newModelQuery($model = null): Builder
{
$query = parent::newModelQuery($model);
$query->getQuery()->where('is_placeholder', '=', false);
return $query;
}
}

View File

@@ -24,6 +24,7 @@ class ImportRequest extends BaseFormRequest
'data' => [ 'data' => [
'required', 'required',
'string', 'string',
'max:'.config('import.max_data_size'),
], ],
]; ];
} }

View File

@@ -38,7 +38,10 @@ use OwenIt\Auditing\Contracts\Auditable as AuditableContract;
* @property string|null $pending_email * @property string|null $pending_email
* @property Carbon|null $email_verified_at * @property Carbon|null $email_verified_at
* @property string|null $password * @property string|null $password
* @property string|null $remember_token
* @property string|null $two_factor_secret * @property string|null $two_factor_secret
* @property string|null $two_factor_recovery_codes
* @property Carbon|null $two_factor_confirmed_at
* @property string $timezone * @property string $timezone
* @property bool $is_placeholder * @property bool $is_placeholder
* @property Weekday $week_start * @property Weekday $week_start
@@ -150,7 +153,9 @@ class User extends Authenticatable implements AuditableContract, FilamentUser, M
public function canAccessPanel(Panel $panel): bool public function canAccessPanel(Panel $panel): bool
{ {
return in_array($this->email, config('auth.super_admins', []), true) && $this->hasVerifiedEmail(); return $this->is_placeholder === false
&& in_array($this->email, config('auth.super_admins', []), true)
&& $this->hasVerifiedEmail();
} }
public function isMemberOfOrganization(Organization $organization): bool public function isMemberOfOrganization(Organization $organization): bool

View File

@@ -4,11 +4,14 @@ declare(strict_types=1);
namespace App\Providers; namespace App\Providers;
use App\Auth\ActiveUserProvider;
use App\Models\Passport\AuthCode; use App\Models\Passport\AuthCode;
use App\Models\Passport\Client; use App\Models\Passport\Client;
use App\Models\Passport\RefreshToken; use App\Models\Passport\RefreshToken;
use App\Models\Passport\Token; use App\Models\Passport\Token;
use Illuminate\Contracts\Foundation\Application;
use Illuminate\Foundation\Support\Providers\AuthServiceProvider as ServiceProvider; use Illuminate\Foundation\Support\Providers\AuthServiceProvider as ServiceProvider;
use Illuminate\Support\Facades\Auth;
use Laravel\Passport\Passport; use Laravel\Passport\Passport;
class AuthServiceProvider extends ServiceProvider class AuthServiceProvider extends ServiceProvider
@@ -26,6 +29,13 @@ class AuthServiceProvider extends ServiceProvider
*/ */
public function boot(): void public function boot(): void
{ {
// Replaces the built-in eloquent user provider, so that no authentication flow can
// resolve a placeholder user. The driver name is kept, because Passport recognizes
// only providers that are configured with the driver "eloquent".
Auth::provider('eloquent', function (Application $app, array $config): ActiveUserProvider {
return new ActiveUserProvider($app->make('hash'), $config['model']);
});
// define scopes for passport tokens // define scopes for passport tokens
Passport::tokensCan([ Passport::tokensCan([
'create' => 'Create resources', 'create' => 'Create resources',

View File

@@ -9,11 +9,8 @@ use App\Service\Import\Importers\ImporterContract;
use App\Service\Import\Importers\ImporterProvider; use App\Service\Import\Importers\ImporterProvider;
use App\Service\Import\Importers\ImportException; use App\Service\Import\Importers\ImportException;
use App\Service\Import\Importers\ReportDto; use App\Service\Import\Importers\ReportDto;
use Illuminate\Support\Carbon;
use Illuminate\Support\Facades\Cache; use Illuminate\Support\Facades\Cache;
use Illuminate\Support\Facades\DB; use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Storage;
use Illuminate\Support\Str;
class ImportService class ImportService
{ {
@@ -25,8 +22,6 @@ class ImportService
/** @var ImporterContract $importer */ /** @var ImporterContract $importer */
$importer = app(ImporterProvider::class)->getImporter($importerType); $importer = app(ImporterProvider::class)->getImporter($importerType);
$importer->init($organization); $importer->init($organization);
Storage::disk(config('filesystems.default'))
->put('import/'.Carbon::now()->toDateString().'-'.$organization->getKey().'-'.Str::uuid(), $data);
$lock = Cache::lock('import:'.$organization->getKey(), config('octane.max_execution_time', 60) + 1); $lock = Cache::lock('import:'.$organization->getKey(), config('octane.max_execution_time', 60) + 1);

View File

@@ -16,7 +16,6 @@ use Illuminate\Support\Str;
use League\Csv\Reader; use League\Csv\Reader;
use Override; use Override;
use Spatie\TemporaryDirectory\TemporaryDirectory; use Spatie\TemporaryDirectory\TemporaryDirectory;
use ZipArchive;
class SolidtimeImporter extends DefaultImporter class SolidtimeImporter extends DefaultImporter
{ {
@@ -34,16 +33,10 @@ class SolidtimeImporter extends DefaultImporter
$temporaryDirectoryZip = null; $temporaryDirectoryZip = null;
$temporaryDirectory = null; $temporaryDirectory = null;
try { try {
$zip = new ZipArchive;
$temporaryDirectoryZip = TemporaryDirectory::make(); $temporaryDirectoryZip = TemporaryDirectory::make();
file_put_contents($temporaryDirectoryZip->path('import.zip'), $data); file_put_contents($temporaryDirectoryZip->path('import.zip'), $data);
$res = $zip->open($temporaryDirectoryZip->path('import.zip'), ZipArchive::RDONLY);
if ($res !== true) {
throw new ImportException('Invalid ZIP, error code: '.$res);
}
$temporaryDirectory = TemporaryDirectory::make(); $temporaryDirectory = TemporaryDirectory::make();
$zip->extractTo($temporaryDirectory->path()); app(ZipImportHelper::class)->extract($temporaryDirectoryZip->path('import.zip'), $temporaryDirectory->path());
$zip->close();
if (! file_exists($temporaryDirectory->path('meta.json'))) { if (! file_exists($temporaryDirectory->path('meta.json'))) {
throw new ImportException('File "meta.json" missing in ZIP'); throw new ImportException('File "meta.json" missing in ZIP');

View File

@@ -13,7 +13,6 @@ use Illuminate\Support\Str;
use Override; use Override;
use Spatie\TemporaryDirectory\TemporaryDirectory; use Spatie\TemporaryDirectory\TemporaryDirectory;
use ValueError; use ValueError;
use ZipArchive;
class TogglDataImporter extends DefaultImporter class TogglDataImporter extends DefaultImporter
{ {
@@ -26,16 +25,10 @@ class TogglDataImporter extends DefaultImporter
$temporaryDirectoryZip = null; $temporaryDirectoryZip = null;
$temporaryDirectory = null; $temporaryDirectory = null;
try { try {
$zip = new ZipArchive;
$temporaryDirectoryZip = TemporaryDirectory::make(); $temporaryDirectoryZip = TemporaryDirectory::make();
file_put_contents($temporaryDirectoryZip->path('import.zip'), $data); file_put_contents($temporaryDirectoryZip->path('import.zip'), $data);
$res = $zip->open($temporaryDirectoryZip->path('import.zip'), ZipArchive::RDONLY);
if ($res !== true) {
throw new ImportException('Invalid ZIP, error code: '.$res);
}
$temporaryDirectory = TemporaryDirectory::make(); $temporaryDirectory = TemporaryDirectory::make();
$zip->extractTo($temporaryDirectory->path()); app(ZipImportHelper::class)->extract($temporaryDirectoryZip->path('import.zip'), $temporaryDirectory->path());
$zip->close();
if (! file_exists($temporaryDirectory->path('clients.json'))) { if (! file_exists($temporaryDirectory->path('clients.json'))) {
throw new ImportException('File "clients.json" missing in ZIP'); throw new ImportException('File "clients.json" missing in ZIP');
} }

View File

@@ -0,0 +1,129 @@
<?php
declare(strict_types=1);
namespace App\Service\Import\Importers;
use ZipArchive;
/**
* Extracts uploaded ZIP archives with limits on file count, total uncompressed
* size and entry paths, so a small malicious archive can not fill the disk
* (decompression bomb) or write outside the target directory (zip slip).
*/
class ZipImportHelper
{
private const int CHUNK_SIZE = 1024 * 1024;
/**
* @throws ImportException
*/
public function extract(string $zipPath, string $targetPath): void
{
$zip = new ZipArchive;
$res = $zip->open($zipPath, ZipArchive::RDONLY);
if ($res !== true) {
throw new ImportException('Invalid ZIP, error code: '.$res);
}
try {
$maxFiles = (int) config('import.zip_max_files');
$maxUncompressedSize = (int) config('import.zip_max_uncompressed_size');
if ($zip->numFiles > $maxFiles) {
throw new ImportException('ZIP contains too many files, maximum is '.$maxFiles);
}
// Check the sizes declared in the archive before writing anything to disk
$declaredSize = 0;
for ($index = 0; $index < $zip->numFiles; $index++) {
$stat = $zip->statIndex($index);
if ($stat === false) {
throw new ImportException('Invalid ZIP entry');
}
$this->validateEntryName($stat['name']);
$declaredSize += $stat['size'];
if ($declaredSize > $maxUncompressedSize) {
throw new ImportException('ZIP uncompressed size exceeds the maximum of '.$maxUncompressedSize.' bytes');
}
}
// The declared sizes can be forged, so the written bytes are counted as well
$writtenSize = 0;
for ($index = 0; $index < $zip->numFiles; $index++) {
$stat = $zip->statIndex($index);
if ($stat === false) {
throw new ImportException('Invalid ZIP entry');
}
$name = $stat['name'];
$entryPath = $targetPath.DIRECTORY_SEPARATOR.$name;
if (str_ends_with($name, '/')) {
$this->ensureDirectoryExists($entryPath);
continue;
}
$this->ensureDirectoryExists(dirname($entryPath));
$stream = $zip->getStreamIndex($index);
if ($stream === false) {
throw new ImportException('ZIP entry "'.$name.'" can not be read');
}
$target = fopen($entryPath, 'wb');
if ($target === false) {
fclose($stream);
throw new ImportException('ZIP entry "'.$name.'" can not be extracted');
}
try {
while (! feof($stream)) {
$chunk = fread($stream, self::CHUNK_SIZE);
if ($chunk === false) {
throw new ImportException('ZIP entry "'.$name.'" can not be read');
}
$writtenSize += strlen($chunk);
if ($writtenSize > $maxUncompressedSize) {
throw new ImportException('ZIP uncompressed size exceeds the maximum of '.$maxUncompressedSize.' bytes');
}
fwrite($target, $chunk);
}
} finally {
fclose($target);
fclose($stream);
}
}
} finally {
$zip->close();
}
}
/**
* @throws ImportException
*/
private function validateEntryName(string $name): void
{
if ($name === '' || str_contains($name, "\0") || str_contains($name, '\\') || str_starts_with($name, '/')) {
throw new ImportException('ZIP contains an invalid file path: "'.$name.'"');
}
if (preg_match('/^[a-zA-Z]:/', $name) === 1) {
throw new ImportException('ZIP contains an invalid file path: "'.$name.'"');
}
foreach (explode('/', rtrim($name, '/')) as $segment) {
if ($segment === '' || $segment === '..') {
throw new ImportException('ZIP contains an invalid file path: "'.$name.'"');
}
}
}
/**
* @throws ImportException
*/
private function ensureDirectoryExists(string $path): void
{
if (is_dir($path)) {
return;
}
if (! mkdir($path, 0700, true) && ! is_dir($path)) {
throw new ImportException('Directory "'.$path.'" can not be created');
}
}
}

View File

@@ -218,7 +218,16 @@ class MemberService
$placeholderUser = $user->replicate(); $placeholderUser = $user->replicate();
$placeholderUser->is_placeholder = true; $placeholderUser->is_placeholder = true;
$placeholderUser->current_team_id = $member->organization_id; // Reset authentication relevant properties on the placeholder user
$placeholderUser->password = null;
$placeholderUser->remember_token = null;
$placeholderUser->two_factor_secret = null;
$placeholderUser->two_factor_recovery_codes = null;
$placeholderUser->two_factor_confirmed_at = null;
$placeholderUser->email_verified_at = null;
$placeholderUser->pending_email = null;
$placeholderUser->current_team_id = null;
$placeholderUser->profile_photo_path = null;
$placeholderUser->save(); $placeholderUser->save();
$member->user()->associate($placeholderUser); $member->user()->associate($placeholderUser);

34
config/import.php Normal file
View File

@@ -0,0 +1,34 @@
<?php
declare(strict_types=1);
return [
/*
|--------------------------------------------------------------------------
| Import payload limit
|--------------------------------------------------------------------------
|
| Maximum length of the base64 encoded "data" field of an import request in
| bytes. Requests with a larger payload are rejected with a validation error.
|
*/
'max_data_size' => (int) (env('IMPORT_MAX_DATA_SIZE') ?: 50 * 1024 * 1024),
/*
|--------------------------------------------------------------------------
| ZIP extraction limits
|--------------------------------------------------------------------------
|
| Limits applied to ZIP based importers before and during extraction to
| protect the instance against decompression bombs. The uncompressed size
| is the sum of all files in the archive in bytes.
|
*/
'zip_max_files' => (int) (env('IMPORT_ZIP_MAX_FILES') ?: 100),
'zip_max_uncompressed_size' => (int) (env('IMPORT_ZIP_MAX_UNCOMPRESSED_SIZE') ?: 500 * 1024 * 1024),
];

View File

@@ -0,0 +1,53 @@
<?php
declare(strict_types=1);
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Query\Builder;
use Illuminate\Support\Facades\DB;
return new class extends Migration
{
/**
* Placeholder users used to be created as a full copy of the user they were made from,
* which included the credentials and the account state of that user. A placeholder is a
* stand-in for a person in one organization, not an account, and the row shares the email
* address with the real account, so these values are removed from the placeholders that
* already exist. The organization a placeholder belongs to is recorded on its member row.
*/
public function up(): void
{
DB::table('users')
->where('is_placeholder', '=', true)
->where(function (Builder $builder): void {
$builder->whereNotNull('password')
->orWhereNotNull('remember_token')
->orWhereNotNull('two_factor_secret')
->orWhereNotNull('two_factor_recovery_codes')
->orWhereNotNull('two_factor_confirmed_at')
->orWhereNotNull('email_verified_at')
->orWhereNotNull('pending_email')
->orWhereNotNull('current_team_id')
->orWhereNotNull('profile_photo_path');
})
->update([
'password' => null,
'remember_token' => null,
'two_factor_secret' => null,
'two_factor_recovery_codes' => null,
'two_factor_confirmed_at' => null,
'email_verified_at' => null,
'pending_email' => null,
'current_team_id' => null,
'profile_photo_path' => null,
]);
}
/**
* Reverse the migrations.
*/
public function down(): void
{
//
}
};

View File

@@ -53,6 +53,47 @@ function todayAt(hour: number, minute: number = 0): string {
return d.toISOString().replace(/\.\d{3}Z$/, 'Z'); return d.toISOString().replace(/\.\d{3}Z$/, 'Z');
} }
// Cross-day tests anchor to Wednesday and Thursday of the current week instead of today and
// tomorrow. E2E users start the week on Monday, so both days are always in the visible week,
// whichever day the suite runs on.
function wednesdayAt(hour: number, minute: number = 0): Date {
const now = new Date();
const daysSinceMonday = (now.getDay() + 6) % 7;
return new Date(
now.getFullYear(),
now.getMonth(),
now.getDate() - daysSinceMonday + 2,
hour,
minute,
0,
0
);
}
function thursdayAt(hour: number, minute: number = 0): Date {
const d = wednesdayAt(hour, minute);
d.setDate(d.getDate() + 1);
return d;
}
function toApiTimestamp(date: Date): string {
return date.toISOString().replace(/\.\d{3}Z$/, 'Z');
}
// Local calendar date (YYYY-MM-DD), matching FullCalendar's data-date attributes
function toDateStr(date: Date): string {
const month = String(date.getMonth() + 1).padStart(2, '0');
const day = String(date.getDate()).padStart(2, '0');
return `${date.getFullYear()}-${month}-${day}`;
}
async function columnHeaderCenterX(page: Page, date: Date): Promise<number> {
const header = page.locator(`.fc-col-header-cell[data-date="${toDateStr(date)}"]`);
await expect(header).toBeVisible();
const box = await header.boundingBox();
return box!.x + box!.width / 2;
}
/** /**
* These tests verify that changing the project on a time entry via the calendar * These tests verify that changing the project on a time entry via the calendar
* updates the billable status to match the new project's is_billable setting. * updates the billable status to match the new project's is_billable setting.
@@ -962,14 +1003,9 @@ test.describe('Drag-to-Move Events', () => {
page, page,
ctx, ctx,
}) => { }) => {
const now = new Date(); // Create entry: Thursday 00:30 → Thursday 01:30 (1 hour, near midnight)
const dayOfWeek = now.getDay(); const start = toApiTimestamp(thursdayAt(0, 30));
// Need today to have a previous day visible in the week view (skip Sunday with Monday week start) const end = toApiTimestamp(thursdayAt(1, 30));
test.skip(dayOfWeek === 1, 'Skipping on Monday — previous day not visible in week view');
// Create entry: today 00:30 → today 01:30 (1 hour, near midnight)
const start = todayAt(0, 30);
const end = todayAt(1, 30);
await createTimeEntryWithTimestampsViaApi(ctx, { await createTimeEntryWithTimestampsViaApi(ctx, {
description: 'Drag up past midnight test', description: 'Drag up past midnight test',
start, start,
@@ -978,11 +1014,10 @@ test.describe('Drag-to-Move Events', () => {
await goToCalendar(page); await goToCalendar(page);
await scrollCalendarToTime(page, '00:00:00'); await scrollCalendarToTime(page, '00:00:00');
const todayStr = new Date(now.getFullYear(), now.getMonth(), now.getDate()) const thursdayCol = page.locator(
.toISOString() `.fc-timegrid-col[data-date="${toDateStr(thursdayAt(0))}"]`
.split('T')[0]; );
const todayCol = page.locator(`.fc-timegrid-col[data-date="${todayStr}"]`); const event = thursdayCol
const event = todayCol
.locator('.fc-event') .locator('.fc-event')
.filter({ hasText: 'Drag up past midnight test' }); .filter({ hasText: 'Drag up past midnight test' });
await expect(event).toBeVisible({ timeout: 10000 }); await expect(event).toBeVisible({ timeout: 10000 });
@@ -1018,10 +1053,7 @@ test.describe('Drag-to-Move Events', () => {
expect(newDurationMs).toBe(3600000); expect(newDurationMs).toBe(3600000);
// The event should have moved to the previous day // The event should have moved to the previous day
const yesterdayStr = new Date(now.getFullYear(), now.getMonth(), now.getDate() - 1) expect(toDateStr(newStart)).toBe(toDateStr(wednesdayAt(0)));
.toISOString()
.split('T')[0];
expect(newStart.toISOString().split('T')[0]).toBe(yesterdayStr);
}); });
}); });
@@ -1261,8 +1293,8 @@ test.describe('Resize Events', () => {
}); });
test('resize bottom edge across day boundary changes end date', async ({ page, ctx }) => { test('resize bottom edge across day boundary changes end date', async ({ page, ctx }) => {
const start = todayAt(10); const start = toApiTimestamp(wednesdayAt(10));
const end = todayAt(11); const end = toApiTimestamp(wednesdayAt(11));
await createTimeEntryWithTimestampsViaApi(ctx, { await createTimeEntryWithTimestampsViaApi(ctx, {
description: 'Cross resize end test', description: 'Cross resize end test',
start, start,
@@ -1271,26 +1303,8 @@ test.describe('Resize Events', () => {
await goToCalendar(page); await goToCalendar(page);
await scrollCalendarToTime(page, '09:00:00'); await scrollCalendarToTime(page, '09:00:00');
// Find a column AFTER today (for end resize, end must be > start) // Resize into Thursday's column (for end resize, end must be > start)
const headers = page.locator('.fc-col-header-cell'); const targetX = await columnHeaderCenterX(page, thursdayAt(0));
const headerCount = await headers.count();
let targetX: number | undefined;
let todayIndex = -1;
for (let i = 0; i < headerCount; i++) {
const header = headers.nth(i);
const isToday = await header.evaluate((el) => el.classList.contains('fc-day-today'));
if (isToday) {
todayIndex = i;
break;
}
}
// Pick first column after today, or skip if today is last
for (let i = todayIndex + 1; i < headerCount; i++) {
const box = await headers.nth(i).boundingBox();
targetX = box!.x + box!.width / 2;
break;
}
test.skip(targetX === undefined, 'No column after today to resize to');
const event = page const event = page
.locator('.fc-event') .locator('.fc-event')
@@ -1318,7 +1332,7 @@ test.describe('Resize Events', () => {
// First drag down vertically to engage resize (like test 3.1) // First drag down vertically to engage resize (like test 3.1)
await page.mouse.move(centerX, bottomY + slotHeight * 4, { steps: 15 }); await page.mouse.move(centerX, bottomY + slotHeight * 4, { steps: 15 });
// Then move horizontally to a later day column // Then move horizontally to a later day column
await page.mouse.move(targetX!, bottomY + slotHeight * 4, { steps: 10 }); await page.mouse.move(targetX, bottomY + slotHeight * 4, { steps: 10 });
await page.mouse.up(); await page.mouse.up();
})(), })(),
]); ]);
@@ -1340,8 +1354,8 @@ test.describe('Resize Events', () => {
page, page,
ctx, ctx,
}) => { }) => {
const start = todayAt(10); const start = toApiTimestamp(wednesdayAt(10));
const end = todayAt(14); const end = toApiTimestamp(wednesdayAt(14));
await createTimeEntryWithTimestampsViaApi(ctx, { await createTimeEntryWithTimestampsViaApi(ctx, {
description: 'Cross resize end test', description: 'Cross resize end test',
start, start,
@@ -1350,30 +1364,8 @@ test.describe('Resize Events', () => {
await goToCalendar(page); await goToCalendar(page);
await scrollCalendarToTime(page, '09:00:00'); await scrollCalendarToTime(page, '09:00:00');
// Find a non-today column header that is AFTER today (later day needed for end-edge resize) // Resize into Thursday's column (later day needed for end-edge resize)
const headers = page.locator('.fc-col-header-cell'); const targetX = await columnHeaderCenterX(page, thursdayAt(0));
const headerCount = await headers.count();
let targetX: number | undefined;
let foundToday = false;
for (let i = 0; i < headerCount; i++) {
const header = headers.nth(i);
const isToday = await header.evaluate((el) => el.classList.contains('fc-day-today'));
if (isToday) {
foundToday = true;
continue;
}
if (foundToday) {
const box = await header.boundingBox();
targetX = box!.x + box!.width / 2;
break;
}
}
// If today is the last column, use the one before today instead won't work for end resize,
// so skip this test in that edge case
if (targetX === undefined) {
test.skip();
return;
}
const event = page const event = page
.locator('.fc-event') .locator('.fc-event')
@@ -1398,7 +1390,7 @@ test.describe('Resize Events', () => {
await page.waitForTimeout(100); await page.waitForTimeout(100);
await page.mouse.down(); await page.mouse.down();
// Move to a different day column at same Y position // Move to a different day column at same Y position
await page.mouse.move(targetX!, bottomY - 3, { steps: 15 }); await page.mouse.move(targetX, bottomY - 3, { steps: 15 });
await page.mouse.up(); await page.mouse.up();
})(), })(),
]); ]);
@@ -1464,22 +1456,9 @@ test.describe('Resize Events', () => {
}); });
test('multi-day event end resize on last day works correctly', async ({ page, ctx }) => { test('multi-day event end resize on last day works correctly', async ({ page, ctx }) => {
// Create entry spanning today evening → tomorrow morning // Create entry spanning Wednesday evening → Thursday morning
const start = todayAt(20); const start = toApiTimestamp(wednesdayAt(20));
const tomorrow = new Date(); const end = toApiTimestamp(thursdayAt(10));
tomorrow.setDate(tomorrow.getDate() + 1);
const tomorrowStr = `${tomorrow.getFullYear()}-${String(tomorrow.getMonth() + 1).padStart(2, '0')}-${String(tomorrow.getDate()).padStart(2, '0')}`;
const end = new Date(
tomorrow.getFullYear(),
tomorrow.getMonth(),
tomorrow.getDate(),
10,
0,
0,
0
)
.toISOString()
.replace(/\.\d{3}Z$/, 'Z');
await createTimeEntryWithTimestampsViaApi(ctx, { await createTimeEntryWithTimestampsViaApi(ctx, {
description: 'Multi-day end resize', description: 'Multi-day end resize',
@@ -1488,14 +1467,14 @@ test.describe('Resize Events', () => {
}); });
await goToCalendar(page); await goToCalendar(page);
// Check if tomorrow column is visible const thursdayCol = page.locator(
const tomorrowCol = page.locator(`.fc-timegrid-col[data-date="${tomorrowStr}"]`); `.fc-timegrid-col[data-date="${toDateStr(thursdayAt(0))}"]`
test.skip((await tomorrowCol.count()) === 0, 'Tomorrow not visible in current view'); );
await scrollCalendarToTime(page, '09:00:00'); await scrollCalendarToTime(page, '09:00:00');
// Find the event segment on tomorrow's column // Find the event segment on Thursday's column
const event = tomorrowCol const event = thursdayCol
.locator('.fc-event') .locator('.fc-event')
.filter({ hasText: 'Multi-day end resize' }) .filter({ hasText: 'Multi-day end resize' })
.first(); .first();
@@ -1541,22 +1520,9 @@ test.describe('Resize Events', () => {
page, page,
ctx, ctx,
}) => { }) => {
// Create entry spanning today → tomorrow // Create entry spanning Wednesday → Thursday
const start = todayAt(10); const start = toApiTimestamp(wednesdayAt(10));
const tomorrow = new Date(); const end = toApiTimestamp(thursdayAt(14));
tomorrow.setDate(tomorrow.getDate() + 1);
const tomorrowStr = `${tomorrow.getFullYear()}-${String(tomorrow.getMonth() + 1).padStart(2, '0')}-${String(tomorrow.getDate()).padStart(2, '0')}`;
const end = new Date(
tomorrow.getFullYear(),
tomorrow.getMonth(),
tomorrow.getDate(),
14,
0,
0,
0
)
.toISOString()
.replace(/\.\d{3}Z$/, 'Z');
await createTimeEntryWithTimestampsViaApi(ctx, { await createTimeEntryWithTimestampsViaApi(ctx, {
description: 'Backward end resize multi', description: 'Backward end resize multi',
@@ -1565,29 +1531,16 @@ test.describe('Resize Events', () => {
}); });
await goToCalendar(page); await goToCalendar(page);
// Check if tomorrow column is visible const thursdayCol = page.locator(
const tomorrowCol = page.locator(`.fc-timegrid-col[data-date="${tomorrowStr}"]`); `.fc-timegrid-col[data-date="${toDateStr(thursdayAt(0))}"]`
test.skip((await tomorrowCol.count()) === 0, 'Tomorrow not visible in current view'); );
await scrollCalendarToTime(page, '12:00:00'); await scrollCalendarToTime(page, '12:00:00');
// Find today's column header to get its X center const wednesdayX = await columnHeaderCenterX(page, wednesdayAt(0));
const headers = page.locator('.fc-col-header-cell');
const headerCount = await headers.count();
let todayX: number | undefined;
for (let i = 0; i < headerCount; i++) {
const header = headers.nth(i);
const isToday = await header.evaluate((el) => el.classList.contains('fc-day-today'));
if (isToday) {
const box = await header.boundingBox();
todayX = box!.x + box!.width / 2;
break;
}
}
test.skip(todayX === undefined, 'Could not find today column header');
// Find event segment on tomorrow's column and resize end backward to today // Find event segment on Thursday's column and resize end backward to Wednesday
const event = tomorrowCol const event = thursdayCol
.locator('.fc-event') .locator('.fc-event')
.filter({ hasText: 'Backward end resize multi' }) .filter({ hasText: 'Backward end resize multi' })
.first(); .first();
@@ -1609,9 +1562,9 @@ test.describe('Resize Events', () => {
await page.mouse.move(centerX, bottomY - 3); await page.mouse.move(centerX, bottomY - 3);
await page.waitForTimeout(100); await page.waitForTimeout(100);
await page.mouse.down(); await page.mouse.down();
// Drag down a bit first, then move to today's column at a Y after the start // Drag down a bit first, then move to Wednesday's column at a Y after the start
await page.mouse.move(centerX, bottomY + slotHeight, { steps: 5 }); await page.mouse.move(centerX, bottomY + slotHeight, { steps: 5 });
await page.mouse.move(todayX!, bottomY + slotHeight, { steps: 10 }); await page.mouse.move(wednesdayX, bottomY + slotHeight, { steps: 10 });
await page.mouse.up(); await page.mouse.up();
})(), })(),
]); ]);
@@ -1627,8 +1580,8 @@ test.describe('Resize Events', () => {
}); });
test('resize end to earlier column prevents end before start', async ({ page, ctx }) => { test('resize end to earlier column prevents end before start', async ({ page, ctx }) => {
const start = todayAt(10); const start = toApiTimestamp(thursdayAt(10));
const end = todayAt(14); const end = toApiTimestamp(thursdayAt(14));
await createTimeEntryWithTimestampsViaApi(ctx, { await createTimeEntryWithTimestampsViaApi(ctx, {
description: 'End before start test', description: 'End before start test',
start, start,
@@ -1637,25 +1590,8 @@ test.describe('Resize Events', () => {
await goToCalendar(page); await goToCalendar(page);
await scrollCalendarToTime(page, '09:00:00'); await scrollCalendarToTime(page, '09:00:00');
// Find a column BEFORE today // Target Wednesday's column, the day before the entry
const headers = page.locator('.fc-col-header-cell'); const targetX = await columnHeaderCenterX(page, wednesdayAt(0));
const headerCount = await headers.count();
let targetX: number | undefined;
let todayIndex = -1;
for (let i = 0; i < headerCount; i++) {
const header = headers.nth(i);
const isToday = await header.evaluate((el) => el.classList.contains('fc-day-today'));
if (isToday) {
todayIndex = i;
break;
}
}
for (let i = todayIndex - 1; i >= 0; i--) {
const box = await headers.nth(i).boundingBox();
targetX = box!.x + box!.width / 2;
break;
}
test.skip(targetX === undefined, 'No column before today to test');
const event = page const event = page
.locator('.fc-event') .locator('.fc-event')
@@ -1683,7 +1619,7 @@ test.describe('Resize Events', () => {
await page.waitForTimeout(100); await page.waitForTimeout(100);
await page.mouse.down(); await page.mouse.down();
// Move to earlier column at a Y position near the top of the grid (before start time) // Move to earlier column at a Y position near the top of the grid (before start time)
await page.mouse.move(targetX!, eventBox!.y - slotHeight * 4, { steps: 15 }); await page.mouse.move(targetX, eventBox!.y - slotHeight * 4, { steps: 15 });
await page.mouse.up(); await page.mouse.up();
// Wait for any potential API call // Wait for any potential API call
@@ -1732,30 +1668,21 @@ test.describe('Click-Drag Selection to Create', () => {
test('drag-to-create spanning two days opens create modal with correct cross-day times', async ({ test('drag-to-create spanning two days opens create modal with correct cross-day times', async ({
page, page,
}) => { }) => {
const now = new Date();
const dayOfWeek = now.getDay();
// Need today and tomorrow both visible (skip Saturday with Monday week start)
test.skip(dayOfWeek === 6, 'Skipping on Saturday — tomorrow not visible in week view');
await goToCalendar(page); await goToCalendar(page);
await expect(page.locator('.fc')).toBeVisible(); await expect(page.locator('.fc')).toBeVisible();
// Use mid-day times so both start and end slots are visible in the viewport // Use mid-day times so both start and end slots are visible in the viewport
await scrollCalendarToTime(page, '10:00:00'); await scrollCalendarToTime(page, '10:00:00');
// Find today's and tomorrow's columns // Find Wednesday's and Thursday's columns
const todayStr = new Date(now.getFullYear(), now.getMonth(), now.getDate()) const wednesdayStr = toDateStr(wednesdayAt(0));
.toISOString() const thursdayStr = toDateStr(thursdayAt(0));
.split('T')[0];
const tomorrowStr = new Date(now.getFullYear(), now.getMonth(), now.getDate() + 1)
.toISOString()
.split('T')[0];
const todayCol = page.locator(`.fc-timegrid-col[data-date="${todayStr}"]`); const wednesdayCol = page.locator(`.fc-timegrid-col[data-date="${wednesdayStr}"]`);
const tomorrowCol = page.locator(`.fc-timegrid-col[data-date="${tomorrowStr}"]`); const thursdayCol = page.locator(`.fc-timegrid-col[data-date="${thursdayStr}"]`);
await expect(todayCol).toBeVisible(); await expect(wednesdayCol).toBeVisible();
await expect(tomorrowCol).toBeVisible(); await expect(thursdayCol).toBeVisible();
// Find the 11:00 slot (start) and 13:00 slot (end on tomorrow) // Find the 11:00 slot (start) and 13:00 slot (end on Thursday)
const startSlot = page.locator('.fc-timegrid-slot-lane[data-time="11:00:00"]').first(); const startSlot = page.locator('.fc-timegrid-slot-lane[data-time="11:00:00"]').first();
const endSlot = page.locator('.fc-timegrid-slot-lane[data-time="13:00:00"]').first(); const endSlot = page.locator('.fc-timegrid-slot-lane[data-time="13:00:00"]').first();
await expect(startSlot).toBeVisible(); await expect(startSlot).toBeVisible();
@@ -1763,18 +1690,18 @@ test.describe('Click-Drag Selection to Create', () => {
const startSlotBox = await startSlot.boundingBox(); const startSlotBox = await startSlot.boundingBox();
const endSlotBox = await endSlot.boundingBox(); const endSlotBox = await endSlot.boundingBox();
const todayColBox = await todayCol.boundingBox(); const wednesdayColBox = await wednesdayCol.boundingBox();
const tomorrowColBox = await tomorrowCol.boundingBox(); const thursdayColBox = await thursdayCol.boundingBox();
// Start drag at 11:00 on today's column // Start drag at 11:00 on Wednesday's column
const startX = todayColBox!.x + todayColBox!.width / 2; const startX = wednesdayColBox!.x + wednesdayColBox!.width / 2;
const startY = startSlotBox!.y + 2; const startY = startSlotBox!.y + 2;
// End drag at 13:00 on tomorrow's column // End drag at 13:00 on Thursday's column
const endX = tomorrowColBox!.x + tomorrowColBox!.width / 2; const endX = thursdayColBox!.x + thursdayColBox!.width / 2;
const endY = endSlotBox!.y + 2; const endY = endSlotBox!.y + 2;
// Drag from today to tomorrow — move down first, then across // Drag from Wednesday to Thursday, moving down first, then across
const slotHeight = await getSlotHeight(page); const slotHeight = await getSlotHeight(page);
await page.mouse.move(startX, startY); await page.mouse.move(startX, startY);
await page.mouse.down(); await page.mouse.down();
@@ -1792,9 +1719,9 @@ test.describe('Click-Drag Selection to Create', () => {
await expect(dialog.getByText('Start')).toBeVisible(); await expect(dialog.getByText('Start')).toBeVisible();
await expect(dialog.getByText('End')).toBeVisible(); await expect(dialog.getByText('End')).toBeVisible();
// Start date should be today, end date should be tomorrow // Start date should be Wednesday, end date should be Thursday
await expect(dialog.getByText(todayStr)).toBeVisible(); await expect(dialog.getByText(wednesdayStr)).toBeVisible();
await expect(dialog.getByText(tomorrowStr)).toBeVisible(); await expect(dialog.getByText(thursdayStr)).toBeVisible();
}); });
}); });
@@ -1876,17 +1803,9 @@ test.describe('Timezone & Localization', () => {
test.describe('Multi-Day Events', () => { test.describe('Multi-Day Events', () => {
test('event spanning 2 days renders and is visible', async ({ page, ctx }) => { test('event spanning 2 days renders and is visible', async ({ page, ctx }) => {
// Create entry that spans from today 22:00 to tomorrow 02:00 // Create entry that spans from Wednesday 22:00 to Thursday 02:00
const now = new Date(); const start = toApiTimestamp(wednesdayAt(22));
const dayOfWeek = now.getDay(); const end = toApiTimestamp(thursdayAt(2));
// If today is Saturday (6), the entry would span to next week and may not be visible
test.skip(dayOfWeek === 6, 'Skipping on Saturday — multi-day would span to next week');
const startDate = new Date(now.getFullYear(), now.getMonth(), now.getDate(), 22, 0, 0);
const endDate = new Date(now.getFullYear(), now.getMonth(), now.getDate() + 1, 2, 0, 0);
const start = startDate.toISOString().replace(/\.\d{3}Z$/, 'Z');
const end = endDate.toISOString().replace(/\.\d{3}Z$/, 'Z');
await createTimeEntryWithTimestampsViaApi(ctx, { await createTimeEntryWithTimestampsViaApi(ctx, {
description: 'Multi day entry', description: 'Multi day entry',
@@ -1901,14 +1820,8 @@ test.describe('Multi-Day Events', () => {
}); });
test('multi-day event can be edited via click', async ({ page, ctx }) => { test('multi-day event can be edited via click', async ({ page, ctx }) => {
const now = new Date(); const start = toApiTimestamp(wednesdayAt(22));
test.skip(now.getDay() === 6, 'Skip on Saturday'); const end = toApiTimestamp(thursdayAt(2));
const startDate = new Date(now.getFullYear(), now.getMonth(), now.getDate(), 22, 0, 0);
const endDate = new Date(now.getFullYear(), now.getMonth(), now.getDate() + 1, 2, 0, 0);
const start = startDate.toISOString().replace(/\.\d{3}Z$/, 'Z');
const end = endDate.toISOString().replace(/\.\d{3}Z$/, 'Z');
await createTimeEntryWithTimestampsViaApi(ctx, { await createTimeEntryWithTimestampsViaApi(ctx, {
description: 'Multi day edit test', description: 'Multi day edit test',
@@ -1927,14 +1840,8 @@ test.describe('Multi-Day Events', () => {
}); });
test('multi-day event context menu works', async ({ page, ctx }) => { test('multi-day event context menu works', async ({ page, ctx }) => {
const now = new Date(); const start = toApiTimestamp(wednesdayAt(22));
test.skip(now.getDay() === 6, 'Skip on Saturday'); const end = toApiTimestamp(thursdayAt(2));
const startDate = new Date(now.getFullYear(), now.getMonth(), now.getDate(), 22, 0, 0);
const endDate = new Date(now.getFullYear(), now.getMonth(), now.getDate() + 1, 2, 0, 0);
const start = startDate.toISOString().replace(/\.\d{3}Z$/, 'Z');
const end = endDate.toISOString().replace(/\.\d{3}Z$/, 'Z');
await createTimeEntryWithTimestampsViaApi(ctx, { await createTimeEntryWithTimestampsViaApi(ctx, {
description: 'Multi day ctx test', description: 'Multi day ctx test',
@@ -1954,16 +1861,11 @@ test.describe('Multi-Day Events', () => {
page, page,
ctx, ctx,
}) => { }) => {
const now = new Date(); // Create entry: Wednesday 22:00 → Thursday 02:00 (4 hours, spanning 2 days)
const dayOfWeek = now.getDay(); const startDate = wednesdayAt(22);
// Need today and tomorrow both visible (skip Saturday) const endDate = thursdayAt(2);
test.skip(dayOfWeek === 6, 'Skipping on Saturday — multi-day would span to next week'); const start = toApiTimestamp(startDate);
const end = toApiTimestamp(endDate);
// Create entry: today 22:00 → tomorrow 02:00 (4 hours, spanning 2 days)
const startDate = new Date(now.getFullYear(), now.getMonth(), now.getDate(), 22, 0, 0);
const endDate = new Date(now.getFullYear(), now.getMonth(), now.getDate() + 1, 2, 0, 0);
const start = startDate.toISOString().replace(/\.\d{3}Z$/, 'Z');
const end = endDate.toISOString().replace(/\.\d{3}Z$/, 'Z');
await createTimeEntryWithTimestampsViaApi(ctx, { await createTimeEntryWithTimestampsViaApi(ctx, {
description: 'Multi day drag test', description: 'Multi day drag test',
@@ -1973,12 +1875,9 @@ test.describe('Multi-Day Events', () => {
await goToCalendar(page); await goToCalendar(page);
await scrollCalendarToTime(page, '00:00:00'); await scrollCalendarToTime(page, '00:00:00');
// Find the clipped segment on tomorrow's column (00:00-02:00) // Find the clipped segment on Thursday's column (00:00-02:00)
const tomorrowStr = new Date(now.getFullYear(), now.getMonth(), now.getDate() + 1) const thursdayCol = page.locator(`.fc-timegrid-col[data-date="${toDateStr(endDate)}"]`);
.toISOString() const event = thursdayCol.locator('.fc-event').filter({ hasText: 'Multi day drag test' });
.split('T')[0];
const tomorrowCol = page.locator(`.fc-timegrid-col[data-date="${tomorrowStr}"]`);
const event = tomorrowCol.locator('.fc-event').filter({ hasText: 'Multi day drag test' });
await expect(event).toBeVisible({ timeout: 10000 }); await expect(event).toBeVisible({ timeout: 10000 });
const eventBox = await event.boundingBox(); const eventBox = await event.boundingBox();
@@ -2013,27 +1912,19 @@ test.describe('Multi-Day Events', () => {
// Duration must be preserved (4 hours) // Duration must be preserved (4 hours)
expect(Math.abs(newDurationMs - origDurationMs)).toBeLessThan(60000); expect(Math.abs(newDurationMs - origDurationMs)).toBeLessThan(60000);
// The start should still be on today (not jumped to tomorrow) // The start should still be on Wednesday (not jumped to Thursday)
const todayStr = new Date(now.getFullYear(), now.getMonth(), now.getDate()) expect(toDateStr(newStart)).toBe(toDateStr(startDate));
.toISOString()
.split('T')[0];
expect(newStart.toISOString().split('T')[0]).toBe(todayStr);
}); });
test('dragging clipped segment of multi-day event upward shifts event earlier', async ({ test('dragging clipped segment of multi-day event upward shifts event earlier', async ({
page, page,
ctx, ctx,
}) => { }) => {
const now = new Date(); // Create entry: Wednesday 22:00 → Thursday 02:00 (4 hours, spanning 2 days)
const dayOfWeek = now.getDay(); const startDate = wednesdayAt(22);
// Need today and tomorrow both visible (skip Saturday) const endDate = thursdayAt(2);
test.skip(dayOfWeek === 6, 'Skipping on Saturday — multi-day would span to next week'); const start = toApiTimestamp(startDate);
const end = toApiTimestamp(endDate);
// Create entry: today 22:00 → tomorrow 02:00 (4 hours, spanning 2 days)
const startDate = new Date(now.getFullYear(), now.getMonth(), now.getDate(), 22, 0, 0);
const endDate = new Date(now.getFullYear(), now.getMonth(), now.getDate() + 1, 2, 0, 0);
const start = startDate.toISOString().replace(/\.\d{3}Z$/, 'Z');
const end = endDate.toISOString().replace(/\.\d{3}Z$/, 'Z');
await createTimeEntryWithTimestampsViaApi(ctx, { await createTimeEntryWithTimestampsViaApi(ctx, {
description: 'Multi day drag up test', description: 'Multi day drag up test',
@@ -2043,12 +1934,9 @@ test.describe('Multi-Day Events', () => {
await goToCalendar(page); await goToCalendar(page);
await scrollCalendarToTime(page, '00:00:00'); await scrollCalendarToTime(page, '00:00:00');
// Find the clipped segment on tomorrow's column (00:00-02:00) // Find the clipped segment on Thursday's column (00:00-02:00)
const tomorrowStr = new Date(now.getFullYear(), now.getMonth(), now.getDate() + 1) const thursdayCol = page.locator(`.fc-timegrid-col[data-date="${toDateStr(endDate)}"]`);
.toISOString() const event = thursdayCol
.split('T')[0];
const tomorrowCol = page.locator(`.fc-timegrid-col[data-date="${tomorrowStr}"]`);
const event = tomorrowCol
.locator('.fc-event') .locator('.fc-event')
.filter({ hasText: 'Multi day drag up test' }); .filter({ hasText: 'Multi day drag up test' });
await expect(event).toBeVisible({ timeout: 10000 }); await expect(event).toBeVisible({ timeout: 10000 });

View File

@@ -9,6 +9,6 @@
}, },
"Invoicing": { "Invoicing": {
"repository": "solidtime-io/extension-invoicing", "repository": "solidtime-io/extension-invoicing",
"ref": "v0.0.5" "ref": "v0.0.6"
} }
} }

2
package-lock.json generated
View File

@@ -8564,7 +8564,7 @@
}, },
"resources/js/packages/ui": { "resources/js/packages/ui": {
"name": "@solidtime/ui", "name": "@solidtime/ui",
"version": "0.0.22", "version": "0.0.23",
"license": "AGPL-3.0", "license": "AGPL-3.0",
"devDependencies": { "devDependencies": {
"@types/chroma-js": "^3.1.2", "@types/chroma-js": "^3.1.2",

View File

@@ -7,7 +7,7 @@ import { type Client } from '@/packages/api/src';
import ClientTableRow from '@/Components/Common/Client/ClientTableRow.vue'; import ClientTableRow from '@/Components/Common/Client/ClientTableRow.vue';
import ClientCreateModal from '@/Components/Common/Client/ClientCreateModal.vue'; import ClientCreateModal from '@/Components/Common/Client/ClientCreateModal.vue';
import ClientTableHeading from '@/Components/Common/Client/ClientTableHeading.vue'; import ClientTableHeading from '@/Components/Common/Client/ClientTableHeading.vue';
import Pagination from '@/Components/Common/Pagination.vue'; import Pagination from '@/packages/ui/src/Pagination.vue';
import { canCreateClients } from '@/utils/permissions'; import { canCreateClients } from '@/utils/permissions';
import { useProjectsQuery } from '@/utils/useProjectsQuery'; import { useProjectsQuery } from '@/utils/useProjectsQuery';
import { import {

View File

@@ -6,17 +6,25 @@ import { computed, ref, watch } from 'vue';
import ProjectCreateModal from '@/packages/ui/src/Project/ProjectCreateModal.vue'; import ProjectCreateModal from '@/packages/ui/src/Project/ProjectCreateModal.vue';
import ProjectTableHeading from '@/Components/Common/Project/ProjectTableHeading.vue'; import ProjectTableHeading from '@/Components/Common/Project/ProjectTableHeading.vue';
import ProjectTableRow from '@/Components/Common/Project/ProjectTableRow.vue'; import ProjectTableRow from '@/Components/Common/Project/ProjectTableRow.vue';
import Pagination from '@/Components/Common/Pagination.vue'; import Pagination from '@/packages/ui/src/Pagination.vue';
import LoadingSpinner from '@/packages/ui/src/LoadingSpinner.vue'; import LoadingSpinner from '@/packages/ui/src/LoadingSpinner.vue';
export type SortColumn = export type SortColumn =
'name' | 'client_name' | 'spent_time' | 'progress' | 'billable_rate' | 'status' | 'visibility'; | 'name'
| 'tasks'
| 'client_name'
| 'spent_time'
| 'progress'
| 'billable_rate'
| 'status'
| 'visibility';
export type { SortDirection } from '@/utils/useSortableTable'; export type { SortDirection } from '@/utils/useSortableTable';
import { canCreateProjects } from '@/utils/permissions'; import { canCreateProjects } from '@/utils/permissions';
import type { CreateProjectBody, Project, Client, CreateClientBody } from '@/packages/api/src'; import type { CreateProjectBody, Project, Client, CreateClientBody } from '@/packages/api/src';
import { useProjectsStore } from '@/utils/useProjects'; import { useProjectsStore } from '@/utils/useProjects';
import { useClientsStore } from '@/utils/useClients'; import { useClientsStore } from '@/utils/useClients';
import { useClientsQuery } from '@/utils/useClientsQuery'; import { useClientsQuery } from '@/utils/useClientsQuery';
import { useTasksQuery } from '@/utils/useTasksQuery';
import { getOrganizationCurrencyString } from '@/utils/money'; import { getOrganizationCurrencyString } from '@/utils/money';
import { isAllowedToPerformPremiumAction } from '@/utils/billing'; import { isAllowedToPerformPremiumAction } from '@/utils/billing';
import { useOrganizationQuery } from '@/utils/useOrganizationQuery'; import { useOrganizationQuery } from '@/utils/useOrganizationQuery';
@@ -56,6 +64,16 @@ const clientNameMap = computed(() => {
return map; return map;
}); });
const { tasks } = useTasksQuery();
const taskCountMap = computed(() => {
const map = new Map<string, number>();
tasks.value.forEach((task) => {
map.set(task.project_id, (map.get(task.project_id) ?? 0) + 1);
});
return map;
});
// Define column accessors for sorting. // Define column accessors for sorting.
// Numeric columns use sortDescFirst so that the first click (chevron down) sorts highest-first, // Numeric columns use sortDescFirst so that the first click (chevron down) sorts highest-first,
// while text columns default to ascending (A-Z) on first click (chevron down). // while text columns default to ascending (A-Z) on first click (chevron down).
@@ -64,6 +82,11 @@ const columns = computed<SortableColumnDef<Project, SortColumn>[]>(() => [
id: 'name', id: 'name',
accessorFn: (row: Project) => row.name.toLowerCase(), accessorFn: (row: Project) => row.name.toLowerCase(),
}, },
{
id: 'tasks',
sortDescFirst: true,
accessorFn: (row: Project) => taskCountMap.value.get(row.id) ?? 0,
},
{ {
id: 'client_name', id: 'client_name',
accessorFn: (row: Project) => { accessorFn: (row: Project) => {
@@ -161,7 +184,7 @@ async function createClient(client: CreateClientBody): Promise<Client | undefine
} }
const gridTemplate = computed(() => { const gridTemplate = computed(() => {
return `grid-template-columns: minmax(300px, 1fr) minmax(150px, auto) minmax(140px, auto) minmax(130px, auto) ${props.showBillableRate ? 'minmax(130px, auto)' : ''} minmax(120px, auto) minmax(120px, auto) 80px;`; return `grid-template-columns: minmax(300px, 1fr) minmax(100px, auto) minmax(150px, auto) minmax(140px, auto) minmax(130px, auto) ${props.showBillableRate ? 'minmax(130px, auto)' : ''} minmax(120px, auto) minmax(120px, auto) 80px;`;
}); });
</script> </script>

View File

@@ -36,6 +36,9 @@ function handleSort(column: SortColumn) {
@sort="handleSort"> @sort="handleSort">
Name Name
</SortableTableHeaderCell> </SortableTableHeaderCell>
<SortableTableHeaderCell column="tasks" v-bind="sortState" @sort="handleSort">
Tasks
</SortableTableHeaderCell>
<SortableTableHeaderCell column="client_name" v-bind="sortState" @sort="handleSort"> <SortableTableHeaderCell column="client_name" v-bind="sortState" @sort="handleSort">
Client Client
</SortableTableHeaderCell> </SortableTableHeaderCell>

View File

@@ -88,17 +88,19 @@ const showEditProjectModal = ref(false);
<ContextMenuTrigger as-child> <ContextMenuTrigger as-child>
<TableRow :href="route('projects.show', { project: project.id })"> <TableRow :href="route('projects.show', { project: project.id })">
<div <div
class="whitespace-nowrap min-w-0 flex items-center space-x-5 py-4 pr-3 text-sm font-medium text-text-primary pl-2 sm:pl-4 lg:pl-6"> class="whitespace-nowrap min-w-0 flex items-center space-x-3 py-4 pr-3 text-sm font-medium text-text-primary pl-2 sm:pl-4 lg:pl-6">
<div <div
:style="{ :style="{ backgroundColor: project.color }"
backgroundColor: project.color, class="w-2.5 h-2.5 ml-1 rounded-full"></div>
boxShadow: `var(--tw-ring-inset) 0 0 0 calc(4px + var(--tw-ring-offset-width)) ${project.color}30`,
}"
class="w-3 h-3 ml-1 rounded-full"></div>
<span class="overflow-ellipsis overflow-hidden"> <span class="overflow-ellipsis overflow-hidden">
{{ project.name }} {{ project.name }}
</span> </span>
<span class="text-text-secondary"> {{ projectTasksCount }} Tasks </span> </div>
<div class="whitespace-nowrap px-3 py-4 text-sm text-text-primary">
<span v-if="projectTasksCount">
{{ projectTasksCount }} {{ projectTasksCount === 1 ? 'Task' : 'Tasks' }}
</span>
<span v-else class="text-text-tertiary">--</span>
</div> </div>
<div class="whitespace-nowrap min-w-0 px-3 py-4 text-sm text-text-primary"> <div class="whitespace-nowrap min-w-0 px-3 py-4 text-sm text-text-primary">
<div v-if="project.client_id" class="overflow-ellipsis overflow-hidden"> <div v-if="project.client_id" class="overflow-ellipsis overflow-hidden">

View File

@@ -63,7 +63,7 @@ const max = computed(() => {
}); });
const backgroundColor = useCssVariable('--theme-color-card-background'); const backgroundColor = useCssVariable('--theme-color-card-background');
const borderColor = useCssVariable('--color-border'); const borderColor = useCssVariable('--color-border-secondary');
const labelColor = useCssVariable('--color-text-secondary'); const labelColor = useCssVariable('--color-text-secondary');
const chartColorRaw = useCssVariable('--theme-color-chart'); const chartColorRaw = useCssVariable('--theme-color-chart');

View File

@@ -9,7 +9,7 @@ import {
ArrowDownTrayIcon, ArrowDownTrayIcon,
LockClosedIcon, LockClosedIcon,
} from '@heroicons/vue/20/solid'; } from '@heroicons/vue/20/solid';
import Pagination from '@/Components/Common/Pagination.vue'; import Pagination from '@/packages/ui/src/Pagination.vue';
import { import {
DropdownMenu, DropdownMenu,
DropdownMenuContent, DropdownMenuContent,

View File

@@ -1,6 +1,6 @@
{ {
"name": "@solidtime/ui", "name": "@solidtime/ui",
"version": "0.0.22", "version": "0.0.23",
"description": "Package containing the solidtime ui components", "description": "Package containing the solidtime ui components",
"main": "./dist/solidtime-ui-lib.umd.cjs", "main": "./dist/solidtime-ui-lib.umd.cjs",
"module": "./dist/solidtime-ui-lib.js", "module": "./dist/solidtime-ui-lib.js",

View File

@@ -11,6 +11,7 @@ import {
CommandShortcut, CommandShortcut,
} from '../command'; } from '../command';
import { cn } from '../utils/cn'; import { cn } from '../utils/cn';
import { useDialogFocusRestore } from '../utils/useDialogFocusRestore';
import type { import type {
CommandPaletteCommand, CommandPaletteCommand,
CommandPaletteGroup, CommandPaletteGroup,
@@ -36,6 +37,8 @@ const emit = defineEmits<{
select: [command: CommandPaletteCommand | EntitySearchResult]; select: [command: CommandPaletteCommand | EntitySearchResult];
}>(); }>();
const { onOpenAutoFocus, onCloseAutoFocus } = useDialogFocusRestore();
// Non-empty groups for rendering // Non-empty groups for rendering
const nonEmptyGroups = computed(() => props.groups.filter((g) => g.commands.length > 0)); const nonEmptyGroups = computed(() => props.groups.filter((g) => g.commands.length > 0));
@@ -71,7 +74,9 @@ watch(open, (isOpen) => {
) )
"> ">
<DialogContent <DialogContent
class="pointer-events-auto bg-default-background w-full max-w-lg border border-border-tertiary shadow-lg sm:rounded-lg outline-none overflow-hidden p-0 data-[state=open]:animate-in data-[state=closed]:animate-out data-[state=closed]:fade-out-0 data-[state=open]:fade-in-0 data-[state=closed]:zoom-out-95 data-[state=open]:zoom-in-95"> class="pointer-events-auto bg-default-background w-full max-w-lg border border-border-tertiary shadow-lg sm:rounded-lg outline-none overflow-hidden p-0 data-[state=open]:animate-in data-[state=closed]:animate-out data-[state=closed]:fade-out-0 data-[state=open]:fade-in-0 data-[state=closed]:zoom-out-95 data-[state=open]:zoom-in-95"
@open-auto-focus="onOpenAutoFocus"
@close-auto-focus="onCloseAutoFocus">
<CommandRoot <CommandRoot
v-model:search-term="searchTerm" v-model:search-term="searchTerm"
class="[&_[cmdk-group-heading]]:px-2 [&_[cmdk-group-heading]]:font-medium [&_[cmdk-group-heading]]:text-muted-foreground [&_[cmdk-group]:not([hidden])_~[cmdk-group]]:pt-0 [&_[cmdk-group]]:px-2 [&_[cmdk-input-wrapper]_svg]:h-5 [&_[cmdk-input-wrapper]_svg]:w-5 [&_[cmdk-input]]:h-12 [&_[cmdk-item]]:px-2 [&_[cmdk-item]]:py-3 [&_[cmdk-item]_svg]:h-5 [&_[cmdk-item]_svg]:w-5"> class="[&_[cmdk-group-heading]]:px-2 [&_[cmdk-group-heading]]:font-medium [&_[cmdk-group-heading]]:text-muted-foreground [&_[cmdk-group]:not([hidden])_~[cmdk-group]]:pt-0 [&_[cmdk-group]]:px-2 [&_[cmdk-input-wrapper]_svg]:h-5 [&_[cmdk-input-wrapper]_svg]:w-5 [&_[cmdk-input]]:h-12 [&_[cmdk-item]]:px-2 [&_[cmdk-item]]:py-3 [&_[cmdk-item]_svg]:h-5 [&_[cmdk-item]_svg]:w-5">

View File

@@ -16,8 +16,8 @@ import {
ChevronRightIcon, ChevronRightIcon,
EllipsisHorizontalIcon, EllipsisHorizontalIcon,
} from '@heroicons/vue/20/solid'; } from '@heroicons/vue/20/solid';
import { buttonVariants } from '@/packages/ui/src'; import { buttonVariants } from './Buttons/index';
import { cn } from '@/lib/utils'; import { cn } from './utils/cn';
import { computed, watch } from 'vue'; import { computed, watch } from 'vue';
const page = defineModel<number>('page', { default: 1 }); const page = defineModel<number>('page', { default: 1 });

View File

@@ -1,5 +1,6 @@
<script setup lang="ts"> <script setup lang="ts">
import { cn } from '../utils/cn'; import { cn } from '../utils/cn';
import { useDialogFocusRestore } from '../utils/useDialogFocusRestore';
import { import {
DialogContent, DialogContent,
type DialogContentEmits, type DialogContentEmits,
@@ -20,6 +21,10 @@ const delegatedProps = computed(() => {
}); });
const forwarded = useForwardPropsEmits(delegatedProps, emits); const forwarded = useForwardPropsEmits(delegatedProps, emits);
// Forwarded consumer listeners run first, so a consumer can still take over
// by calling preventDefault() on close-auto-focus.
const { onOpenAutoFocus, onCloseAutoFocus } = useDialogFocusRestore();
</script> </script>
<template> <template>
@@ -36,7 +41,9 @@ const forwarded = useForwardPropsEmits(delegatedProps, emits);
'my-3 md:my-14 xl:my-24 bg-default-background grid w-full max-w-lg border border-border-tertiary shadow-lg duration-200 rounded-lg outline-none data-[state=open]:animate-in data-[state=closed]:animate-out data-[state=closed]:fade-out-0 data-[state=open]:fade-in-0 data-[state=closed]:zoom-out-95 data-[state=open]:zoom-in-95', 'my-3 md:my-14 xl:my-24 bg-default-background grid w-full max-w-lg border border-border-tertiary shadow-lg duration-200 rounded-lg outline-none data-[state=open]:animate-in data-[state=closed]:animate-out data-[state=closed]:fade-out-0 data-[state=open]:fade-in-0 data-[state=closed]:zoom-out-95 data-[state=open]:zoom-in-95',
props.class props.class
) )
"> "
@open-auto-focus="onOpenAutoFocus"
@close-auto-focus="onCloseAutoFocus">
<slot /> <slot />
</DialogContent> </DialogContent>
</div> </div>

View File

@@ -1,5 +1,6 @@
<script setup lang="ts"> <script setup lang="ts">
import { cn } from '../utils/cn'; import { cn } from '../utils/cn';
import { useDialogFocusRestore } from '../utils/useDialogFocusRestore';
import { X } from '@lucide/vue'; import { X } from '@lucide/vue';
import { import {
DialogClose, DialogClose,
@@ -22,6 +23,10 @@ const delegatedProps = computed(() => {
}); });
const forwarded = useForwardPropsEmits(delegatedProps, emits); const forwarded = useForwardPropsEmits(delegatedProps, emits);
// Forwarded consumer listeners run first, so a consumer can still take over
// by calling preventDefault() on close-auto-focus.
const { onOpenAutoFocus, onCloseAutoFocus } = useDialogFocusRestore();
</script> </script>
<template> <template>
@@ -36,6 +41,8 @@ const forwarded = useForwardPropsEmits(delegatedProps, emits);
) )
" "
v-bind="forwarded" v-bind="forwarded"
@open-auto-focus="onOpenAutoFocus"
@close-auto-focus="onCloseAutoFocus"
@pointer-down-outside=" @pointer-down-outside="
(event) => { (event) => {
const originalEvent = event.detail.originalEvent; const originalEvent = event.detail.originalEvent;

View File

@@ -32,6 +32,7 @@ import InputLabel from './Input/InputLabel.vue';
import TextInput from './Input/TextInput.vue'; import TextInput from './Input/TextInput.vue';
import LoadingSpinner from './LoadingSpinner.vue'; import LoadingSpinner from './LoadingSpinner.vue';
import Modal from './Modal.vue'; import Modal from './Modal.vue';
import Pagination from './Pagination.vue';
import ProjectBadge from './Project/ProjectBadge.vue'; import ProjectBadge from './Project/ProjectBadge.vue';
import TimeEntryCreateModal from './TimeEntry/TimeEntryCreateModal.vue'; import TimeEntryCreateModal from './TimeEntry/TimeEntryCreateModal.vue';
import TimeEntryEditModal from './TimeEntry/TimeEntryEditModal.vue'; import TimeEntryEditModal from './TimeEntry/TimeEntryEditModal.vue';
@@ -257,6 +258,7 @@ export {
NumberFieldDecrement, NumberFieldDecrement,
NumberFieldIncrement, NumberFieldIncrement,
NumberFieldInput, NumberFieldInput,
Pagination,
Popover, Popover,
PopoverAnchor, PopoverAnchor,
PopoverContent, PopoverContent,

View File

@@ -0,0 +1,87 @@
import { describe, expect, it, vi } from 'vitest';
import { useDialogFocusRestore } from './useDialogFocusRestore';
function closeEvent() {
return new CustomEvent('focusScope.autoFocusOnUnmount', { cancelable: true });
}
describe('useDialogFocusRestore', () => {
it('restores focus to the element focused when the dialog opened', () => {
vi.useFakeTimers();
const button = document.createElement('button');
document.body.appendChild(button);
button.focus();
const { onOpenAutoFocus, onCloseAutoFocus } = useDialogFocusRestore();
onOpenAutoFocus();
button.blur();
const event = closeEvent();
onCloseAutoFocus(event);
expect(event.defaultPrevented).toBe(true);
vi.runAllTimers();
expect(document.activeElement).toBe(button);
button.remove();
vi.useRealTimers();
});
it('focuses nothing when the dialog was opened with nothing focused', () => {
vi.useFakeTimers();
const stale = document.createElement('button');
document.body.appendChild(stale);
const { onOpenAutoFocus, onCloseAutoFocus } = useDialogFocusRestore();
// First open from the button, then close
stale.focus();
onOpenAutoFocus();
onCloseAutoFocus(closeEvent());
vi.runAllTimers();
stale.blur();
// Second open from the body must not refocus the stale button
onOpenAutoFocus();
const event = closeEvent();
onCloseAutoFocus(event);
expect(event.defaultPrevented).toBe(true);
vi.runAllTimers();
expect(document.activeElement).toBe(document.body);
stale.remove();
vi.useRealTimers();
});
it('does not restore focus to an element that was removed', () => {
vi.useFakeTimers();
const button = document.createElement('button');
document.body.appendChild(button);
button.focus();
const { onOpenAutoFocus, onCloseAutoFocus } = useDialogFocusRestore();
onOpenAutoFocus();
button.remove();
onCloseAutoFocus(closeEvent());
vi.runAllTimers();
expect(document.activeElement).toBe(document.body);
vi.useRealTimers();
});
it('leaves control to a consumer that already prevented the event', () => {
vi.useFakeTimers();
const button = document.createElement('button');
document.body.appendChild(button);
button.focus();
const { onOpenAutoFocus, onCloseAutoFocus } = useDialogFocusRestore();
onOpenAutoFocus();
button.blur();
const event = closeEvent();
event.preventDefault();
onCloseAutoFocus(event);
vi.runAllTimers();
expect(document.activeElement).toBe(document.body);
button.remove();
vi.useRealTimers();
});
});

View File

@@ -0,0 +1,41 @@
/**
* Restores focus to the element that was focused when a dialog opened.
*
* reka-ui remembers the active element at content mount as the dialog's
* "trigger" (only when it is not the body) and refocuses it on every close,
* but it never clears that value. A dialog opened while nothing is focused
* (e.g. the command palette via Cmd+K from the body) therefore refocuses
* whatever triggered a *previous* open. Bind these handlers to
* `DialogContent`'s `open-auto-focus` / `close-auto-focus` events to restore
* exactly the previously focused element, or nothing.
*
* A consumer handler that already called `preventDefault()` on
* `close-auto-focus` keeps control; this composable then does nothing.
*/
export function useDialogFocusRestore() {
let previouslyFocused: HTMLElement | null = null;
function onOpenAutoFocus() {
const active = document.activeElement;
previouslyFocused =
active instanceof HTMLElement && active !== document.body ? active : null;
}
function onCloseAutoFocus(event: Event) {
const target = previouslyFocused;
previouslyFocused = null;
if (event.defaultPrevented) {
return;
}
// Prevents both FocusScope's default restore and reka-ui's trigger refocus
event.preventDefault();
// Same tick reka-ui uses, so the dialog content is fully gone first
setTimeout(() => {
if (target?.isConnected) {
target.focus({ preventScroll: true });
}
}, 0);
}
return { onOpenAutoFocus, onCloseAutoFocus };
}

View File

@@ -1,5 +1,5 @@
import { defineStore } from 'pinia'; import { defineStore } from 'pinia';
import { computed, ref } from 'vue'; import { computed, ref, watch } from 'vue';
import { api } from '@/packages/api/src'; import { api } from '@/packages/api/src';
import type { TimeEntry } from '@/packages/api/src'; import type { TimeEntry } from '@/packages/api/src';
import dayjs, { Dayjs } from 'dayjs'; import dayjs, { Dayjs } from 'dayjs';
@@ -57,7 +57,6 @@ export const useCurrentTimeEntryStore = defineStore('currentTimeEntry', () => {
const currentTimeEntry = ref<TimeEntry>({ ...emptyTimeEntry }); const currentTimeEntry = ref<TimeEntry>({ ...emptyTimeEntry });
const { handleApiRequestNotifications } = useNotificationsStore(); const { handleApiRequestNotifications } = useNotificationsStore();
const queryClient = useQueryClient(); const queryClient = useQueryClient();
useLocalStorage('solidtime/current-time-entry', currentTimeEntry, { useLocalStorage('solidtime/current-time-entry', currentTimeEntry, {
deep: true, deep: true,
}); });
@@ -89,23 +88,12 @@ export const useCurrentTimeEntryStore = defineStore('currentTimeEntry', () => {
try { try {
const timeEntriesResponse = await api.getMyActiveTimeEntry({}); const timeEntriesResponse = await api.getMyActiveTimeEntry({});
if (timeEntriesResponse?.data) { if (timeEntriesResponse?.data) {
if (timeEntriesResponse.data) { currentTimeEntry.value = timeEntriesResponse.data;
currentTimeEntry.value = timeEntriesResponse.data; } else if (currentTimeEntry.value.id !== '') {
if ( // No active time entry on server
currentTimeEntry.value.start !== '' && // Only reset if we had a previously started timer (has an ID)
currentTimeEntry.value.end === null // Don't reset if user is preparing a new time entry (no ID yet)
) { currentTimeEntry.value = { ...emptyTimeEntry };
startLiveTimer();
}
} else {
// No active time entry on server
// Only reset if we had a previously started timer (has an ID)
// Don't reset if user is preparing a new time entry (no ID yet)
if (currentTimeEntry.value.id !== '') {
currentTimeEntry.value = { ...emptyTimeEntry };
stopLiveTimer();
}
}
} }
} catch { } catch {
// API error (e.g., 404 when no active time entry) // API error (e.g., 404 when no active time entry)
@@ -113,7 +101,6 @@ export const useCurrentTimeEntryStore = defineStore('currentTimeEntry', () => {
// Don't reset if user is preparing a new time entry (no ID yet) // Don't reset if user is preparing a new time entry (no ID yet)
if (currentTimeEntry.value.id !== '') { if (currentTimeEntry.value.id !== '') {
currentTimeEntry.value = { ...emptyTimeEntry }; currentTimeEntry.value = { ...emptyTimeEntry };
stopLiveTimer();
} }
} }
} else { } else {
@@ -294,6 +281,18 @@ export const useCurrentTimeEntryStore = defineStore('currentTimeEntry', () => {
return isActive.value && currentTimeEntry.value.type === 'break'; return isActive.value && currentTimeEntry.value.type === 'break';
}); });
watch(
isActive,
(active) => {
if (active) {
startLiveTimer();
} else {
stopLiveTimer();
}
},
{ immediate: true }
);
async function setActiveState(newState: boolean) { async function setActiveState(newState: boolean) {
if (newState) { if (newState) {
startLiveTimer(); startLiveTimer();

View File

@@ -6,6 +6,7 @@ namespace Tests\Feature;
use App\Models\User; use App\Models\User;
use Illuminate\Foundation\Testing\RefreshDatabase; use Illuminate\Foundation\Testing\RefreshDatabase;
use Illuminate\Support\Facades\Hash;
use Tests\TestCase; use Tests\TestCase;
class PasswordConfirmationTest extends TestCase class PasswordConfirmationTest extends TestCase
@@ -43,4 +44,43 @@ class PasswordConfirmationTest extends TestCase
$response->assertSessionHasErrors(); $response->assertSessionHasErrors();
} }
public function test_password_can_be_confirmed_if_a_placeholder_user_with_the_same_email_exists(): void
{
// Arrange
// Placeholders created by an import have no password at all. The placeholder is created
// first so that it would be returned by an unordered lookup by email.
$email = 'shared@example.com';
User::factory()->placeholder()->create(['email' => $email, 'password' => null]);
$user = User::factory()->create(['email' => $email, 'password' => Hash::make('secret-password')]);
// Act
$response = $this->actingAs($user)->post('/user/confirm-password', [
'password' => 'secret-password',
]);
// Assert
$response->assertRedirect();
$response->assertSessionHasNoErrors();
$this->assertTrue($this->app['session']->has('auth.password_confirmed_at'));
}
public function test_password_confirmation_ignores_the_password_of_a_placeholder_user_with_the_same_email(): void
{
// Arrange
// Placeholders created by removing a member copy the password hash as of the removal,
// so the placeholder holds a password that the real user has since replaced.
$email = 'shared@example.com';
User::factory()->placeholder()->create(['email' => $email, 'password' => Hash::make('outdated-password')]);
$user = User::factory()->create(['email' => $email, 'password' => Hash::make('current-password')]);
// Act
$response = $this->actingAs($user)->post('/user/confirm-password', [
'password' => 'outdated-password',
]);
// Assert
$response->assertSessionHasErrors();
$this->assertFalse($this->app['session']->has('auth.password_confirmed_at'));
}
} }

View File

@@ -7,6 +7,7 @@ namespace Tests\Feature;
use App\Models\User; use App\Models\User;
use Illuminate\Auth\Notifications\ResetPassword; use Illuminate\Auth\Notifications\ResetPassword;
use Illuminate\Foundation\Testing\RefreshDatabase; use Illuminate\Foundation\Testing\RefreshDatabase;
use Illuminate\Support\Facades\Hash;
use Illuminate\Support\Facades\Notification; use Illuminate\Support\Facades\Notification;
use Laravel\Fortify\Features; use Laravel\Fortify\Features;
use Tests\TestCase; use Tests\TestCase;
@@ -93,4 +94,62 @@ class PasswordResetTest extends TestCase
return true; return true;
}); });
} }
public function test_password_reset_targets_the_real_user_when_a_placeholder_user_with_the_same_email_exists(): void
{
Notification::fake();
// The placeholder is created first so that it would be returned by an unordered lookup by email
$email = 'shared@example.com';
$placeholder = User::factory()->placeholder()->create(['email' => $email]);
$user = User::factory()->create(['email' => $email]);
$placeholderPasswordBefore = $placeholder->password;
$response = $this->post('/forgot-password', [
'email' => $email,
]);
$response->assertSessionHasNoErrors();
Notification::assertNotSentTo($placeholder, ResetPassword::class);
Notification::assertSentTo($user, ResetPassword::class, function (ResetPassword $notification) use ($email) {
$response = $this->post('/reset-password', [
'token' => $notification->token,
'email' => $email,
'password' => 'new-password-123',
'password_confirmation' => 'new-password-123',
]);
$response->assertSessionHasNoErrors();
return true;
});
$placeholder->refresh();
$user->refresh();
$this->assertSame($placeholderPasswordBefore, $placeholder->password);
$this->assertTrue(Hash::check('new-password-123', $user->password));
$response = $this->post('/login', [
'email' => $email,
'password' => 'new-password-123',
]);
$response->assertSessionHasNoErrors();
$this->assertAuthenticatedAs($user);
}
public function test_password_reset_link_is_not_sent_if_only_a_placeholder_user_with_the_email_exists(): void
{
Notification::fake();
$placeholder = User::factory()->placeholder()->create();
$response = $this->post('/forgot-password', [
'email' => $placeholder->email,
]);
$response->assertSessionHasErrors('email');
Notification::assertNothingSent();
}
} }

View File

@@ -0,0 +1,90 @@
<?php
declare(strict_types=1);
namespace Tests\Unit\Auth;
use App\Auth\ActiveUserProvider;
use App\Models\User;
use Illuminate\Support\Facades\Auth;
use PHPUnit\Framework\Attributes\CoversClass;
use Tests\TestCaseWithDatabase;
#[CoversClass(ActiveUserProvider::class)]
class ActiveUserProviderTest extends TestCaseWithDatabase
{
public function test_password_broker_uses_the_active_user_provider(): void
{
// Act
$brokerProvider = Auth::createUserProvider(config('auth.passwords.users.provider'));
// Assert
$this->assertInstanceOf(ActiveUserProvider::class, $brokerProvider);
}
public function test_api_guard_uses_the_active_user_provider(): void
{
// Act
$guardProvider = Auth::createUserProvider(config('auth.guards.api.provider'));
// Assert
$this->assertInstanceOf(ActiveUserProvider::class, $guardProvider);
}
public function test_web_guard_uses_the_active_user_provider(): void
{
// Act
$guardProvider = Auth::createUserProvider(config('auth.guards.web.provider'));
// Assert
$this->assertInstanceOf(ActiveUserProvider::class, $guardProvider);
}
public function test_retrieve_by_credentials_ignores_placeholder_users_with_the_same_email(): void
{
// Arrange
$email = 'shared@example.com';
$placeholder = User::factory()->placeholder()->create(['email' => $email]);
$user = User::factory()->create(['email' => $email]);
$provider = Auth::createUserProvider('users');
// Act
$result = $provider->retrieveByCredentials(['email' => $email]);
// Assert
$this->assertInstanceOf(User::class, $result);
$this->assertTrue($user->is($result));
$this->assertFalse($placeholder->is($result));
}
public function test_retrieve_by_credentials_returns_null_if_only_a_placeholder_user_exists(): void
{
// Arrange
$email = 'placeholder-only@example.com';
User::factory()->placeholder()->create(['email' => $email]);
$provider = Auth::createUserProvider('users');
// Act
$result = $provider->retrieveByCredentials(['email' => $email]);
// Assert
$this->assertNull($result);
}
public function test_retrieve_by_id_returns_null_for_placeholder_users(): void
{
// Arrange
$placeholder = User::factory()->placeholder()->create();
$user = User::factory()->create();
$provider = Auth::createUserProvider('users');
// Act
$placeholderResult = $provider->retrieveById($placeholder->getKey());
$userResult = $provider->retrieveById($user->getKey());
// Assert
$this->assertNull($placeholderResult);
$this->assertInstanceOf(User::class, $userResult);
$this->assertTrue($user->is($userResult));
}
}

View File

@@ -97,6 +97,29 @@ class ImportEndpointTest extends ApiEndpointTestAbstract
]); ]);
} }
public function test_import_fails_if_data_exceeds_maximum_size(): void
{
// Arrange
config(['import.max_data_size' => 16]);
$user = $this->createUserWithPermission([
'import',
]);
$this->mock(ImportService::class, function (MockInterface $mock): void {
$mock->shouldNotReceive('import');
});
Passport::actingAs($user->user);
// Act
$response = $this->postJson(route('api.v1.import.import', ['organization' => $user->organization->getKey()]), [
'type' => 'toggl_time_entries',
'data' => base64_encode(str_repeat('a', 15)),
]);
// Assert
$response->assertStatus(422);
$response->assertJsonValidationErrors(['data']);
}
public function test_import_return_error_message_if_import_fails(): void public function test_import_return_error_message_if_import_fails(): void
{ {
// Arrange // Arrange

View File

@@ -105,6 +105,9 @@ class OrganizationInvitationEndpointTest extends EndpointTestAbstract
$this->assertDatabaseMissing(OrganizationInvitation::class, [ $this->assertDatabaseMissing(OrganizationInvitation::class, [
'id' => $invitation->getKey(), 'id' => $invitation->getKey(),
]); ]);
// Joining sets the organization as the current one for the user, independently of the
// placeholders that were merged into them
$this->assertSame($user->organization->getKey(), $user2->user->fresh()->current_team_id);
} }
public function test_accepting_invitation_while_logged_out_redirects_to_login(): void public function test_accepting_invitation_while_logged_out_redirects_to_login(): void

View File

@@ -53,6 +53,23 @@ class UserModelTest extends ModelTestAbstract
$this->assertTrue($canAccess); $this->assertTrue($canAccess);
} }
public function test_placeholder_user_with_a_super_admin_email_can_not_access_admin_panel(): void
{
// Arrange
Config::set('auth.super_admins', ['some@email.test', 'other@email.test']);
$user = User::factory()->placeholder()->create([
'email' => 'some@email.test',
]);
$panelProvider = new AdminPanelProvider(app());
$mainPanel = $panelProvider->panel(Panel::make());
// Act
$canAccess = $user->canAccessPanel($mainPanel);
// Assert
$this->assertFalse($canAccess);
}
public function test_scope_belongs_to_organization_returns_only_users_of_organization_including_owners(): void public function test_scope_belongs_to_organization_returns_only_users_of_organization_including_owners(): void
{ {
// Arrange // Arrange

View File

@@ -412,10 +412,11 @@ class DeletionServiceTest extends TestCaseWithDatabase
$this->assertDatabaseHas(Organization::class, [ $this->assertDatabaseHas(Organization::class, [
'id' => $organizationOfA->getKey(), 'id' => $organizationOfA->getKey(),
]); ]);
// The placeholder user should exist with current_team_id set to the org where they are a placeholder // The placeholder user should exist and must not reference the deleted organization,
// which is what caused the foreign key violation in #989
$placeholderUser = User::query()->where('is_placeholder', true)->first(); $placeholderUser = User::query()->where('is_placeholder', true)->first();
$this->assertNotNull($placeholderUser); $this->assertNotNull($placeholderUser);
$this->assertSame($organizationOfA->getKey(), $placeholderUser->current_team_id); $this->assertNull($placeholderUser->current_team_id);
$this->assertDatabaseHas(Member::class, [ $this->assertDatabaseHas(Member::class, [
'id' => $memberBInOrgA->getKey(), 'id' => $memberBInOrgA->getKey(),
'user_id' => $placeholderUser->getKey(), 'user_id' => $placeholderUser->getKey(),

View File

@@ -41,6 +41,7 @@ class ImportServiceTest extends TestCase
$this->assertSame(1, $report->usersCreated); $this->assertSame(1, $report->usersCreated);
$this->assertSame(2, $report->projectsCreated); $this->assertSame(2, $report->projectsCreated);
$this->assertSame(1, $report->clientsCreated); $this->assertSame(1, $report->clientsCreated);
Storage::disk(config('filesystems.default'))->assertDirectoryEmpty('import');
} }
public function test_import_releases_lock_if_an_exception_happens_during_the_import(): void public function test_import_releases_lock_if_an_exception_happens_during_the_import(): void

View File

@@ -42,6 +42,31 @@ class SolidtimeImporterTest extends ImporterTestAbstract
$this->fail(); $this->fail();
} }
public function test_import_throws_exception_if_zip_exceeds_uncompressed_size_limit(): void
{
// Arrange
config(['import.zip_max_uncompressed_size' => 10]);
$zipPath = $this->createTestZip('solidtime_import_test_1');
$timezone = 'Europe/Vienna';
$organization = Organization::factory()->create();
$importer = new SolidtimeImporter;
$importer->init($organization);
$data = file_get_contents($zipPath);
// Act
try {
$importer->importData($data, $timezone);
} catch (Exception $e) {
// Assert
$this->assertInstanceOf(ImportException::class, $e);
$this->assertSame('ZIP uncompressed size exceeds the maximum of 10 bytes', $e->getMessage());
$this->assertSame(0, $importer->getReport()->timeEntriesCreated);
return;
}
$this->fail();
}
public function test_import_of_test_file_succeeds(): void public function test_import_of_test_file_succeeds(): void
{ {
// Arrange // Arrange

View File

@@ -39,6 +39,31 @@ class TogglDataImporterTest extends ImporterTestAbstract
$this->fail(); $this->fail();
} }
public function test_import_throws_exception_if_zip_contains_too_many_files(): void
{
// Arrange
config(['import.zip_max_files' => 1]);
$zipPath = $this->createTestZip('toggl_data_import_test_1');
$timezone = 'Europe/Vienna';
$organization = Organization::factory()->create();
$importer = new TogglDataImporter;
$importer->init($organization);
$data = file_get_contents($zipPath);
// Act
try {
$importer->importData($data, $timezone);
} catch (Exception $e) {
// Assert
$this->assertInstanceOf(ImportException::class, $e);
$this->assertSame('ZIP contains too many files, maximum is 1', $e->getMessage());
$this->assertSame(0, $importer->getReport()->projectsCreated);
return;
}
$this->fail();
}
public function test_import_of_test_file_succeeds(): void public function test_import_of_test_file_succeeds(): void
{ {
// Arrange // Arrange

View File

@@ -0,0 +1,254 @@
<?php
declare(strict_types=1);
namespace Tests\Unit\Service\Import\Importers;
use App\Service\Import\Importers\ImportException;
use App\Service\Import\Importers\ZipImportHelper;
use PHPUnit\Framework\Attributes\CoversClass;
use Spatie\TemporaryDirectory\TemporaryDirectory;
use Tests\TestCase;
use ZipArchive;
#[CoversClass(ZipImportHelper::class)]
class ZipImportHelperTest extends TestCase
{
private TemporaryDirectory $sourceDirectory;
private TemporaryDirectory $targetDirectory;
protected function setUp(): void
{
parent::setUp();
$this->sourceDirectory = TemporaryDirectory::make();
$this->targetDirectory = TemporaryDirectory::make();
}
protected function tearDown(): void
{
$this->sourceDirectory->delete();
$this->targetDirectory->delete();
parent::tearDown();
}
/**
* @param array<string, string> $files
*/
private function createZip(array $files): string
{
$zipPath = $this->sourceDirectory->path('test.zip');
$zip = new ZipArchive;
$zip->open($zipPath, ZipArchive::CREATE);
foreach ($files as $name => $content) {
$zip->addFromString($name, $content);
}
$zip->close();
return $zipPath;
}
private function assertNothingExtracted(): void
{
$this->assertSame([], array_values(array_diff(scandir($this->targetDirectory->path()), ['.', '..'])));
}
public function test_extract_extracts_files_and_nested_directories(): void
{
// Arrange
$zipPath = $this->createZip([
'meta.json' => '{"version":"1.0"}',
'nested/dir/file.csv' => 'a,b',
]);
// Act
app(ZipImportHelper::class)->extract($zipPath, $this->targetDirectory->path());
// Assert
$this->assertSame('{"version":"1.0"}', file_get_contents($this->targetDirectory->path('meta.json')));
$this->assertSame('a,b', file_get_contents($this->targetDirectory->path('nested/dir/file.csv')));
}
public function test_extract_throws_exception_if_file_is_not_a_zip(): void
{
// Arrange
$path = $this->sourceDirectory->path('not-a-zip.txt');
file_put_contents($path, 'not a zip');
// Act
try {
app(ZipImportHelper::class)->extract($path, $this->targetDirectory->path());
} catch (ImportException $e) {
// Assert
$this->assertSame('Invalid ZIP, error code: 19', $e->getMessage());
$this->assertNothingExtracted();
return;
}
$this->fail();
}
public function test_extract_throws_exception_if_zip_contains_too_many_files(): void
{
// Arrange
config(['import.zip_max_files' => 2]);
$zipPath = $this->createZip([
'a.txt' => 'a',
'b.txt' => 'b',
'c.txt' => 'c',
]);
// Act
try {
app(ZipImportHelper::class)->extract($zipPath, $this->targetDirectory->path());
} catch (ImportException $e) {
// Assert
$this->assertSame('ZIP contains too many files, maximum is 2', $e->getMessage());
$this->assertNothingExtracted();
return;
}
$this->fail();
}
public function test_extract_throws_exception_before_writing_if_declared_uncompressed_size_exceeds_limit(): void
{
// Arrange
config(['import.zip_max_uncompressed_size' => 100]);
$zipPath = $this->createZip([
'a.txt' => str_repeat('a', 60),
'b.txt' => str_repeat('b', 60),
]);
// Act
try {
app(ZipImportHelper::class)->extract($zipPath, $this->targetDirectory->path());
} catch (ImportException $e) {
// Assert
$this->assertSame('ZIP uncompressed size exceeds the maximum of 100 bytes', $e->getMessage());
$this->assertNothingExtracted();
return;
}
$this->fail();
}
public function test_extract_throws_exception_if_actual_uncompressed_size_exceeds_limit_despite_forged_headers(): void
{
// Arrange
config(['import.zip_max_uncompressed_size' => 1000]);
$zipPath = $this->createZip([
'bomb.bin' => str_repeat("\0", 100000),
]);
// Forge the uncompressed size in the local file header (offset 22) and central directory header (offset 24)
$content = file_get_contents($zipPath);
$forgedSize = pack('V', 10);
$localHeaderOffset = strpos($content, "PK\x03\x04");
$centralHeaderOffset = strpos($content, "PK\x01\x02");
$this->assertNotFalse($localHeaderOffset);
$this->assertNotFalse($centralHeaderOffset);
$content = substr_replace($content, $forgedSize, $localHeaderOffset + 22, 4);
$content = substr_replace($content, $forgedSize, $centralHeaderOffset + 24, 4);
file_put_contents($zipPath, $content);
$zip = new ZipArchive;
$this->assertTrue($zip->open($zipPath, ZipArchive::RDONLY));
$this->assertSame(10, $zip->statIndex(0)['size']);
$zip->close();
// Act
try {
app(ZipImportHelper::class)->extract($zipPath, $this->targetDirectory->path());
} catch (ImportException $e) {
// Assert
$this->assertSame('ZIP uncompressed size exceeds the maximum of 1000 bytes', $e->getMessage());
$extracted = $this->targetDirectory->path('bomb.bin');
if (file_exists($extracted)) {
$this->assertLessThanOrEqual(1000, filesize($extracted));
}
return;
}
$this->fail();
}
public function test_extract_throws_exception_if_zip_contains_path_traversal(): void
{
// Arrange
$zipPath = $this->createZip([
'../evil.txt' => 'evil',
]);
// Act
try {
app(ZipImportHelper::class)->extract($zipPath, $this->targetDirectory->path());
} catch (ImportException $e) {
// Assert
$this->assertSame('ZIP contains an invalid file path: "../evil.txt"', $e->getMessage());
$this->assertFileDoesNotExist(dirname($this->targetDirectory->path()).'/evil.txt');
$this->assertNothingExtracted();
return;
}
$this->fail();
}
public function test_extract_throws_exception_if_zip_contains_nested_path_traversal(): void
{
// Arrange
$zipPath = $this->createZip([
'sub/../../evil.txt' => 'evil',
]);
// Act
try {
app(ZipImportHelper::class)->extract($zipPath, $this->targetDirectory->path());
} catch (ImportException $e) {
// Assert
$this->assertSame('ZIP contains an invalid file path: "sub/../../evil.txt"', $e->getMessage());
$this->assertNothingExtracted();
return;
}
$this->fail();
}
public function test_extract_throws_exception_if_zip_contains_absolute_path(): void
{
// Arrange
$zipPath = $this->createZip([
'/tmp/evil.txt' => 'evil',
]);
// Act
try {
app(ZipImportHelper::class)->extract($zipPath, $this->targetDirectory->path());
} catch (ImportException $e) {
// Assert
$this->assertSame('ZIP contains an invalid file path: "/tmp/evil.txt"', $e->getMessage());
$this->assertNothingExtracted();
return;
}
$this->fail();
}
public function test_extract_throws_exception_if_zip_contains_backslash_path(): void
{
// Arrange
$zipPath = $this->createZip([
'..\\evil.txt' => 'evil',
]);
// Act
try {
app(ZipImportHelper::class)->extract($zipPath, $this->targetDirectory->path());
} catch (ImportException $e) {
// Assert
$this->assertSame('ZIP contains an invalid file path: "..\\evil.txt"', $e->getMessage());
$this->assertNothingExtracted();
return;
}
$this->fail();
}
}

View File

@@ -13,6 +13,7 @@ use App\Models\TimeEntry;
use App\Models\User; use App\Models\User;
use App\Service\MemberService; use App\Service\MemberService;
use App\Service\UserService; use App\Service\UserService;
use Illuminate\Support\Facades\Hash;
use InvalidArgumentException; use InvalidArgumentException;
use PHPUnit\Framework\Attributes\CoversClass; use PHPUnit\Framework\Attributes\CoversClass;
use Tests\TestCaseWithDatabase; use Tests\TestCaseWithDatabase;
@@ -64,6 +65,48 @@ class MemberServiceTest extends TestCaseWithDatabase
$this->assertSame(Role::Admin->value, $oldOwnerMember->refresh()->role); $this->assertSame(Role::Admin->value, $oldOwnerMember->refresh()->role);
} }
public function test_make_member_to_placeholder_does_not_copy_the_credentials_and_account_state_of_the_user(): void
{
// Arrange
$user = User::factory()->create([
'password' => Hash::make('secret-password'),
'remember_token' => 'remember-me-token',
'two_factor_secret' => 'two-factor-secret',
'two_factor_recovery_codes' => 'two-factor-recovery-codes',
'two_factor_confirmed_at' => '2026-09-16 10:00:00',
'email_verified_at' => '2026-09-16 09:00:00',
'pending_email' => 'pending@example.com',
'profile_photo_path' => 'profile-photos/photo.png',
]);
$organization = Organization::factory()->create();
$member = Member::factory()->forOrganization($organization)->forUser($user)->role(Role::Employee)->create();
// Act
$this->memberService->makeMemberToPlaceholder($member);
// Assert
$member->refresh();
$placeholderUser = $member->user;
$this->assertTrue($placeholderUser->is_placeholder);
$this->assertSame($user->email, $placeholderUser->email);
$this->assertNull($placeholderUser->password);
$this->assertNull($placeholderUser->remember_token);
$this->assertNull($placeholderUser->two_factor_secret);
$this->assertNull($placeholderUser->two_factor_recovery_codes);
$this->assertNull($placeholderUser->two_factor_confirmed_at);
$this->assertNull($placeholderUser->email_verified_at);
$this->assertNull($placeholderUser->pending_email);
$this->assertNull($placeholderUser->current_team_id);
$this->assertNull($placeholderUser->profile_photo_path);
// the user the placeholder was created from keeps their own credentials and state
$user->refresh();
$this->assertTrue(Hash::check('secret-password', (string) $user->password));
$this->assertSame('two-factor-secret', $user->two_factor_secret);
$this->assertNotNull($user->email_verified_at);
$this->assertSame('pending@example.com', $user->pending_email);
$this->assertSame('profile-photos/photo.png', $user->profile_photo_path);
}
public function test_make_member_to_placeholder_creates_new_user_based_on_member_and_changes_member_to_placeholder(): void public function test_make_member_to_placeholder_creates_new_user_based_on_member_and_changes_member_to_placeholder(): void
{ {
// Arrange // Arrange