mirror of
https://github.com/solidtime-io/solidtime.git
synced 2026-10-08 05:43:18 +01:00
Compare commits
84 Commits
feature/vo
...
feature/fi
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
7a83d96b79 | ||
|
|
c23f09fb2d | ||
|
|
a0262addb7 | ||
|
|
b4911ebddd | ||
|
|
3ade20887b | ||
|
|
4943a38ffe | ||
|
|
12e355ff26 | ||
|
|
01b60c0f6a | ||
|
|
927da7dce9 | ||
|
|
c89fa87b0f | ||
|
|
02cf600f43 | ||
|
|
98a460725f | ||
|
|
95645ddd91 | ||
|
|
1de985b577 | ||
|
|
d54296e66a | ||
|
|
95ddbf9ead | ||
|
|
70646a0dd4 | ||
|
|
5b12c09747 | ||
|
|
24023353f2 | ||
|
|
720d20c10e | ||
|
|
82ea9af8b5 | ||
|
|
169d522da0 | ||
|
|
45c7377802 | ||
|
|
8e57275cef | ||
|
|
efc6b55628 | ||
|
|
c12789376d | ||
|
|
4795812b60 | ||
|
|
0e00979ab8 | ||
|
|
f1426fcb5e | ||
|
|
23f512d4a4 | ||
|
|
637475e669 | ||
|
|
3ec2abb309 | ||
|
|
3e36b1cc01 | ||
|
|
7831bc697e | ||
|
|
602a8daa1f | ||
|
|
38b448a729 | ||
|
|
e6f071f87f | ||
|
|
693a1fa7e0 | ||
|
|
77f14b696e | ||
|
|
593372bae5 | ||
|
|
db9ca51fc4 | ||
|
|
28aba7b27a | ||
|
|
453d5ed066 | ||
|
|
ed3ba0135b | ||
|
|
fb7d945c50 | ||
|
|
9958e1c09c | ||
|
|
f00d48f1c3 | ||
|
|
7edbfd5d76 | ||
|
|
1edb940557 | ||
|
|
c9330e6cb8 | ||
|
|
0e9f652d84 | ||
|
|
d29f5706ce | ||
|
|
b2849ec04a | ||
|
|
bd69cf478c | ||
|
|
5197135d00 | ||
|
|
b09b8649b8 | ||
|
|
99fafdb8d6 | ||
|
|
b02e49c7e0 | ||
|
|
8609635d74 | ||
|
|
5a07f798b3 | ||
|
|
3af69830ee | ||
|
|
a050153bcd | ||
|
|
9d9731c7ce | ||
|
|
dfe3206614 | ||
|
|
97fd882878 | ||
|
|
111e12df12 | ||
|
|
de13c07855 | ||
|
|
29a2e994cd | ||
|
|
f6d886b218 | ||
|
|
80d98b30a1 | ||
|
|
32f2f1431b | ||
|
|
8f6d584ee9 | ||
|
|
1905cbf40c | ||
|
|
c8f668238e | ||
|
|
bf11bacdee | ||
|
|
f3c6a0b8ae | ||
|
|
619c602571 | ||
|
|
600daf44d9 | ||
|
|
a1d6c92806 | ||
|
|
ce1bd6a435 | ||
|
|
79d85227c2 | ||
|
|
885abf3333 | ||
|
|
c0c8fee6be | ||
|
|
cbcd1e51f6 |
@@ -5,7 +5,8 @@ APP_KEY=base64:UNQNf1SXeASNkWux01Rj8EnHYx8FO0kAxWNDwktclkk=
|
||||
APP_DEBUG=true
|
||||
APP_URL=https://solidtime.test
|
||||
APP_FORCE_HTTPS=false
|
||||
APP_ENABLE_REGISTRATION=true
|
||||
# Supported values: on, off, invite-only (true/false are supported for backwards compatibility)
|
||||
APP_ENABLE_REGISTRATION=on
|
||||
SUPER_ADMINS=admin@example.com
|
||||
PAGINATION_PER_PAGE_DEFAULT=500
|
||||
|
||||
|
||||
12
.github/VOUCHED.td
vendored
12
.github/VOUCHED.td
vendored
@@ -14,10 +14,14 @@
|
||||
# Seeded 2026-07-25 from the authors of every merged pull request.
|
||||
|
||||
agross
|
||||
akolenda
|
||||
bufferhead-code
|
||||
candideu
|
||||
KasparRosin
|
||||
kasparrosin
|
||||
korridor
|
||||
Onatcer
|
||||
ShrootBuck
|
||||
smileBeda
|
||||
nikbucher tasks table sorting
|
||||
onatcer
|
||||
shrootbuck
|
||||
smilebeda
|
||||
thespyder
|
||||
utlark
|
||||
|
||||
4
.github/workflows/build-onpremise.yml
vendored
4
.github/workflows/build-onpremise.yml
vendored
@@ -141,7 +141,7 @@ jobs:
|
||||
${{ env.DOCKER_REPO }}
|
||||
|
||||
- name: "Login to solidtime OnPremise Registry"
|
||||
uses: docker/login-action@v4
|
||||
uses: docker/login-action@v4.6.0
|
||||
with:
|
||||
registry: registry.on-premise.solidtime.io
|
||||
username: ${{ secrets.ONPREMISE_USERNAME }}
|
||||
@@ -195,7 +195,7 @@ jobs:
|
||||
merge-multiple: true
|
||||
|
||||
- name: "Login to solidtime OnPremise Registry"
|
||||
uses: docker/login-action@v4
|
||||
uses: docker/login-action@v4.6.0
|
||||
with:
|
||||
registry: registry.on-premise.solidtime.io
|
||||
username: ${{ secrets.ONPREMISE_USERNAME }}
|
||||
|
||||
4
.github/workflows/build-private.yml
vendored
4
.github/workflows/build-private.yml
vendored
@@ -97,7 +97,7 @@ jobs:
|
||||
- name: "Install dependencies in billing extension"
|
||||
uses: php-actions/composer@v6
|
||||
env:
|
||||
COMPOSER_AUTH: '{"http-basic": {"spark.laravel.com": {"username": "gregor@vostrak.at", "password": "${{ secrets.LARAVEL_SPARK_API_KEY }}"}}}'
|
||||
COMPOSER_AUTH: '{"http-basic": {"spark.laravel.com": {"username": "${{ secrets.LARAVEL_SPARK_USERNAME }}", "password": "${{ secrets.LARAVEL_SPARK_API_KEY }}"}}}'
|
||||
with:
|
||||
working_dir: "extensions/Billing"
|
||||
command: install
|
||||
@@ -177,7 +177,7 @@ jobs:
|
||||
SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }}
|
||||
|
||||
- name: "Login to GitHub Container Registry"
|
||||
uses: docker/login-action@v4
|
||||
uses: docker/login-action@v4.6.0
|
||||
with:
|
||||
registry: rg.fr-par.scw.cloud/solidtime
|
||||
username: nologin
|
||||
|
||||
8
.github/workflows/build-public.yml
vendored
8
.github/workflows/build-public.yml
vendored
@@ -117,13 +117,13 @@ jobs:
|
||||
${{ env.GHCR_REPO }}
|
||||
|
||||
- name: "Login to Docker Hub Container Registry"
|
||||
uses: docker/login-action@v4
|
||||
uses: docker/login-action@v4.6.0
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||
|
||||
- name: "Login to GitHub Container Registry"
|
||||
uses: docker/login-action@v4
|
||||
uses: docker/login-action@v4.6.0
|
||||
with:
|
||||
registry: ghcr.io
|
||||
username: ${{ github.actor }}
|
||||
@@ -177,13 +177,13 @@ jobs:
|
||||
merge-multiple: true
|
||||
|
||||
- name: "Login to Docker Hub"
|
||||
uses: docker/login-action@v4
|
||||
uses: docker/login-action@v4.6.0
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||
|
||||
- name: "Login to GHCR"
|
||||
uses: docker/login-action@v4
|
||||
uses: docker/login-action@v4.6.0
|
||||
with:
|
||||
registry: ghcr.io
|
||||
username: ${{ github.actor }}
|
||||
|
||||
136
.github/workflows/phpunit-extensions.yml
vendored
Normal file
136
.github/workflows/phpunit-extensions.yml
vendored
Normal file
@@ -0,0 +1,136 @@
|
||||
name: PHPUnit Tests - Extensions
|
||||
on: push
|
||||
permissions:
|
||||
contents: read
|
||||
jobs:
|
||||
phpunit-extensions:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 15
|
||||
strategy:
|
||||
matrix:
|
||||
postgres_version: [ 15, 16, 17 ]
|
||||
|
||||
services:
|
||||
pgsql_test:
|
||||
image: postgres:${{ matrix.postgres_version }}
|
||||
env:
|
||||
PGPASSWORD: 'root'
|
||||
POSTGRES_DB: 'laravel'
|
||||
POSTGRES_USER: 'root'
|
||||
POSTGRES_PASSWORD: 'root'
|
||||
ports:
|
||||
- 5432:5432
|
||||
options: >-
|
||||
--health-cmd pg_isready
|
||||
--health-interval 10s
|
||||
--health-timeout 5s
|
||||
--health-retries 5
|
||||
gotenberg:
|
||||
image: gotenberg/gotenberg:8
|
||||
ports:
|
||||
- 3000:3000
|
||||
options: >-
|
||||
--health-cmd "curl --silent --fail http://localhost:3000/health"
|
||||
--health-interval 10s
|
||||
--health-timeout 5s
|
||||
--health-retries 5
|
||||
steps:
|
||||
- name: "Checkout code"
|
||||
uses: actions/checkout@v7
|
||||
|
||||
- name: "Setup PHP"
|
||||
uses: shivammathur/setup-php@v2
|
||||
with:
|
||||
php-version: '8.3'
|
||||
extensions: dom, curl, libxml, mbstring, zip, pcntl, pdo, sqlite, pdo_sqlite, bcmath, soap, intl, gd, exif, iconv
|
||||
coverage: pcov
|
||||
|
||||
- uses: actions/setup-node@v7
|
||||
with:
|
||||
node-version: '20.x'
|
||||
|
||||
- name: "Read extension manifest"
|
||||
id: extension-manifest
|
||||
run: |
|
||||
{
|
||||
echo "billing_repository=$(jq -r '.Billing.repository' extensions/manifest.json)"
|
||||
echo "billing_ref=$(jq -r '.Billing.ref' extensions/manifest.json)"
|
||||
echo "services_repository=$(jq -r '.Services.repository' extensions/manifest.json)"
|
||||
echo "services_ref=$(jq -r '.Services.ref' extensions/manifest.json)"
|
||||
echo "invoicing_repository=$(jq -r '.Invoicing.repository' extensions/manifest.json)"
|
||||
echo "invoicing_ref=$(jq -r '.Invoicing.ref' extensions/manifest.json)"
|
||||
} >> "$GITHUB_OUTPUT"
|
||||
|
||||
- name: "Checkout billing extension"
|
||||
uses: actions/checkout@v7
|
||||
with:
|
||||
repository: ${{ steps.extension-manifest.outputs.billing_repository }}
|
||||
ref: ${{ steps.extension-manifest.outputs.billing_ref }}
|
||||
path: extensions/Billing
|
||||
ssh-key: ${{ secrets.SSH_PRIVATE_KEY_BILLING_EXTENSION }}
|
||||
|
||||
- name: "Install composer dependencies in billing extension"
|
||||
working-directory: extensions/Billing
|
||||
env:
|
||||
COMPOSER_AUTH: '{"http-basic": {"spark.laravel.com": {"username": "contact@solidtime.io", "password": "${{ secrets.LARAVEL_SPARK_API_KEY }}"}}}'
|
||||
run: composer install -n --prefer-dist --ignore-platform-reqs
|
||||
|
||||
- name: "Install npm dependencies in billing extension"
|
||||
run: cd extensions/Billing && npm ci
|
||||
|
||||
- name: "Checkout services extension"
|
||||
uses: actions/checkout@v7
|
||||
with:
|
||||
repository: ${{ steps.extension-manifest.outputs.services_repository }}
|
||||
ref: ${{ steps.extension-manifest.outputs.services_ref }}
|
||||
path: extensions/Services
|
||||
ssh-key: ${{ secrets.SSH_PRIVATE_KEY_SERVICES_EXTENSION }}
|
||||
|
||||
- name: "Install composer dependencies in services extension"
|
||||
working-directory: extensions/Services
|
||||
run: composer install -n --prefer-dist --ignore-platform-reqs
|
||||
|
||||
- name: "Install npm dependencies in services extension"
|
||||
run: cd extensions/Services && npm ci
|
||||
|
||||
- name: "Checkout invoicing extension"
|
||||
uses: actions/checkout@v7
|
||||
with:
|
||||
repository: ${{ steps.extension-manifest.outputs.invoicing_repository }}
|
||||
ref: ${{ steps.extension-manifest.outputs.invoicing_ref }}
|
||||
path: extensions/Invoicing
|
||||
ssh-key: ${{ secrets.SSH_PRIVATE_KEY_INVOICING_EXTENSION }}
|
||||
|
||||
- name: "Install composer dependencies in invoicing extension"
|
||||
working-directory: extensions/Invoicing
|
||||
run: composer install -n --prefer-dist --ignore-platform-reqs
|
||||
|
||||
- name: "Install npm dependencies in invoicing extension"
|
||||
run: cd extensions/Invoicing && npm ci
|
||||
|
||||
- name: "Run composer install"
|
||||
run: composer install -n --prefer-dist --ignore-platform-reqs
|
||||
|
||||
- name: "Activate billing extension"
|
||||
run: php artisan module:enable Billing
|
||||
|
||||
- name: "Activate services extension"
|
||||
run: php artisan module:enable Services
|
||||
|
||||
- name: "Activate invoicing extension"
|
||||
run: php artisan module:enable Invoicing
|
||||
|
||||
- name: "Install dependencies"
|
||||
run: npm ci
|
||||
|
||||
- name: "Build Frontend"
|
||||
run: npm run build
|
||||
|
||||
- name: "Prepare Laravel Application"
|
||||
run: |
|
||||
cp .env.ci .env
|
||||
php artisan key:generate
|
||||
php artisan passport:keys
|
||||
|
||||
- name: "Run PHPUnit"
|
||||
run: php artisan test extensions/Billing/tests extensions/Services/tests extensions/Invoicing/tests --stop-on-failure
|
||||
2
.github/workflows/phpunit.yml
vendored
2
.github/workflows/phpunit.yml
vendored
@@ -68,7 +68,7 @@ jobs:
|
||||
run: php artisan test --stop-on-failure --coverage-text --coverage-clover=coverage.xml
|
||||
|
||||
- name: "Upload coverage reports to Codecov"
|
||||
uses: codecov/codecov-action@v7.0.0
|
||||
uses: codecov/codecov-action@v7.1.1
|
||||
with:
|
||||
token: ${{ secrets.CODECOV_TOKEN }}
|
||||
slug: solidtime-io/solidtime
|
||||
|
||||
@@ -4,9 +4,11 @@ declare(strict_types=1);
|
||||
|
||||
namespace App\Actions\Fortify;
|
||||
|
||||
use App\Enums\RegistrationMode;
|
||||
use App\Enums\Weekday;
|
||||
use App\Events\NewsletterRegistered;
|
||||
use App\Models\User;
|
||||
use App\Service\InvitationService;
|
||||
use App\Service\IpLookup\IpLookupServiceContract;
|
||||
use App\Service\TimezoneService;
|
||||
use App\Service\UserService;
|
||||
@@ -31,13 +33,14 @@ class CreateNewUser implements CreatesNewUsers
|
||||
*/
|
||||
public function create(array $input): User
|
||||
{
|
||||
if (! config('app.enable_registration')) {
|
||||
$registrationMode = RegistrationMode::fromConfig(config('app.enable_registration'));
|
||||
if ($registrationMode === RegistrationMode::Off) {
|
||||
throw ValidationException::withMessages([
|
||||
'email' => [__('Registration is disabled.')],
|
||||
]);
|
||||
}
|
||||
|
||||
Validator::make($input, [
|
||||
$validated = Validator::make($input, [
|
||||
'name' => [
|
||||
'required',
|
||||
'string',
|
||||
@@ -60,6 +63,20 @@ class CreateNewUser implements CreatesNewUsers
|
||||
],
|
||||
])->validate();
|
||||
|
||||
if ($registrationMode === RegistrationMode::InviteOnly) {
|
||||
$invitationService = app(InvitationService::class);
|
||||
$email = (string) $validated['email'];
|
||||
if (! $invitationService->hasAcceptedInvitationForEmail($email)) {
|
||||
$message = $invitationService->hasPendingInvitationForEmail($email)
|
||||
? __('Please accept the organization invitation sent to your email address before registering.')
|
||||
: __('Registration is only available to invited users.');
|
||||
|
||||
throw ValidationException::withMessages([
|
||||
'email' => [$message],
|
||||
]);
|
||||
}
|
||||
}
|
||||
|
||||
$timezone = null;
|
||||
if (array_key_exists('timezone', $input) && is_string($input['timezone'])) {
|
||||
if (app(TimezoneService::class)->isValid($input['timezone'])) {
|
||||
|
||||
37
app/Auth/ActiveUserProvider.php
Normal file
37
app/Auth/ActiveUserProvider.php
Normal file
@@ -0,0 +1,37 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Auth;
|
||||
|
||||
use Illuminate\Auth\EloquentUserProvider;
|
||||
use Illuminate\Database\Eloquent\Builder;
|
||||
use Illuminate\Database\Eloquent\Model;
|
||||
|
||||
/**
|
||||
* User provider that only resolves non-placeholder users.
|
||||
*
|
||||
* Placeholder users are created by imports and when members are removed from an
|
||||
* organization. They can share an email address with a real user, so resolving a user by
|
||||
* email can return a placeholder instead of the real account. The login flow filters them
|
||||
* out explicitly, but the password broker and the guard credential checks (for example the
|
||||
* password confirmation) resolve users through the configured user provider.
|
||||
*
|
||||
* Registered as the "eloquent" provider driver in the AuthServiceProvider, so it replaces the
|
||||
* built-in one for every provider in config/auth.php.
|
||||
*/
|
||||
class ActiveUserProvider extends EloquentUserProvider
|
||||
{
|
||||
/**
|
||||
* @param Model|null $model
|
||||
* @return Builder<Model>
|
||||
*/
|
||||
#[\Override]
|
||||
protected function newModelQuery($model = null): Builder
|
||||
{
|
||||
$query = parent::newModelQuery($model);
|
||||
$query->getQuery()->where('is_placeholder', '=', false);
|
||||
|
||||
return $query;
|
||||
}
|
||||
}
|
||||
@@ -51,7 +51,8 @@ class TimeEntrySendStillRunningMailsCommand extends Command
|
||||
])
|
||||
->whereHas('user', function (Builder $query): void {
|
||||
/** @var Builder<User> $query */
|
||||
$query->where('is_placeholder', '=', false);
|
||||
$query->where('is_placeholder', '=', false)
|
||||
->where('send_time_entry_still_running_email', '=', true);
|
||||
})
|
||||
->orderBy('created_at', 'asc')
|
||||
->chunk(500, function (Collection $timeEntries) use ($dryRun, &$sentMails): void {
|
||||
|
||||
29
app/Enums/RegistrationMode.php
Normal file
29
app/Enums/RegistrationMode.php
Normal file
@@ -0,0 +1,29 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Enums;
|
||||
|
||||
enum RegistrationMode: string
|
||||
{
|
||||
case On = 'on';
|
||||
case InviteOnly = 'invite-only';
|
||||
case Off = 'off';
|
||||
|
||||
public static function fromConfig(mixed $value): self
|
||||
{
|
||||
if ($value === true) {
|
||||
return self::On;
|
||||
}
|
||||
|
||||
if ($value === false || $value === null) {
|
||||
return self::Off;
|
||||
}
|
||||
|
||||
return match (strtolower(trim((string) $value))) {
|
||||
'1', 'on', 'true' => self::On,
|
||||
'invite-only' => self::InviteOnly,
|
||||
default => self::Off,
|
||||
};
|
||||
}
|
||||
}
|
||||
@@ -21,6 +21,7 @@ enum TimeEntryAggregationType: string
|
||||
case Billable = 'billable';
|
||||
case Description = 'description';
|
||||
case Tag = 'tag';
|
||||
case Type = 'type';
|
||||
|
||||
public static function fromInterval(TimeEntryAggregationTypeInterval $timeEntryAggregationTypeInterval): TimeEntryAggregationType
|
||||
{
|
||||
|
||||
15
app/Enums/TimeEntryType.php
Normal file
15
app/Enums/TimeEntryType.php
Normal file
@@ -0,0 +1,15 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Enums;
|
||||
|
||||
use Datomatic\LaravelEnumHelper\LaravelEnumHelper;
|
||||
|
||||
enum TimeEntryType: string
|
||||
{
|
||||
use LaravelEnumHelper;
|
||||
|
||||
case Work = 'work';
|
||||
case Break = 'break';
|
||||
}
|
||||
@@ -60,7 +60,6 @@ abstract class ApiException extends Exception
|
||||
*/
|
||||
public function report(): bool
|
||||
{
|
||||
// TODO: temporary activated
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,4 +7,9 @@ namespace App\Exceptions\Api;
|
||||
class CanNotDeleteUserWhoIsOwnerOfOrganizationWithMultipleMembers extends ApiException
|
||||
{
|
||||
public const string KEY = 'can_not_delete_user_who_is_owner_of_organization_with_multiple_members';
|
||||
|
||||
public function report(): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,4 +7,9 @@ namespace App\Exceptions\Api;
|
||||
class CanNotRemoveOwnerFromOrganization extends ApiException
|
||||
{
|
||||
public const string KEY = 'can_not_remove_owner_from_organization';
|
||||
|
||||
public function report(): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,4 +7,9 @@ namespace App\Exceptions\Api;
|
||||
class ChangingRoleOfPlaceholderIsNotAllowed extends ApiException
|
||||
{
|
||||
public const string KEY = 'changing_role_of_placeholder_is_not_allowed';
|
||||
|
||||
public function report(): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,4 +7,9 @@ namespace App\Exceptions\Api;
|
||||
class ChangingRoleToPlaceholderIsNotAllowed extends ApiException
|
||||
{
|
||||
public const string KEY = 'changing_role_to_placeholder_is_not_allowed';
|
||||
|
||||
public function report(): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -19,6 +19,16 @@ class EntityStillInUseApiException extends ApiException
|
||||
|
||||
public const string KEY = 'entity_still_in_use';
|
||||
|
||||
/**
|
||||
* Report the exception.
|
||||
*
|
||||
* @return bool true means the exception handler will not report it again
|
||||
*/
|
||||
public function report(): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the translated message for the exception.
|
||||
*/
|
||||
|
||||
@@ -7,4 +7,9 @@ namespace App\Exceptions\Api;
|
||||
class FeatureIsNotAvailableInFreePlanApiException extends ApiException
|
||||
{
|
||||
public const string KEY = 'feature_is_not_available_in_free_plan';
|
||||
|
||||
public function report(): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,4 +7,9 @@ namespace App\Exceptions\Api;
|
||||
class InactiveUserCanNotBeUsedApiException extends ApiException
|
||||
{
|
||||
public const string KEY = 'inactive_user_can_not_be_used';
|
||||
|
||||
public function report(): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,4 +7,9 @@ namespace App\Exceptions\Api;
|
||||
class InvitationForTheEmailAlreadyExistsApiException extends ApiException
|
||||
{
|
||||
public const string KEY = 'invitation_for_the_email_already_exists';
|
||||
|
||||
public function report(): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,4 +7,9 @@ namespace App\Exceptions\Api;
|
||||
class OnlyOwnerCanChangeOwnership extends ApiException
|
||||
{
|
||||
public const string KEY = 'only_owner_can_change_ownership';
|
||||
|
||||
public function report(): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,4 +7,9 @@ namespace App\Exceptions\Api;
|
||||
class OnlyPlaceholdersCanBeMergedIntoAnotherMember extends ApiException
|
||||
{
|
||||
public const string KEY = 'only_placeholders_can_be_merged_into_another_member';
|
||||
|
||||
public function report(): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,4 +7,9 @@ namespace App\Exceptions\Api;
|
||||
class OrganizationHasNoSubscriptionButMultipleMembersException extends ApiException
|
||||
{
|
||||
public const string KEY = 'organization_has_no_subscription_but_multiple_members';
|
||||
|
||||
public function report(): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,4 +7,9 @@ namespace App\Exceptions\Api;
|
||||
class OrganizationNeedsAtLeastOneOwner extends ApiException
|
||||
{
|
||||
public const string KEY = 'organization_needs_at_least_one_owner';
|
||||
|
||||
public function report(): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,4 +7,9 @@ namespace App\Exceptions\Api;
|
||||
class OverlappingTimeEntryApiException extends ApiException
|
||||
{
|
||||
public const string KEY = 'overlapping_time_entry';
|
||||
|
||||
public function report(): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,4 +7,9 @@ namespace App\Exceptions\Api;
|
||||
class ThisPlaceholderCanNotBeInvitedUseTheMergeToolInsteadException extends ApiException
|
||||
{
|
||||
public const string KEY = 'this_placeholder_can_not_be_invited_use_the_merge_tool_instead_api_exception';
|
||||
|
||||
public function report(): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,4 +7,9 @@ namespace App\Exceptions\Api;
|
||||
class TimeEntryCanNotBeRestartedApiException extends ApiException
|
||||
{
|
||||
public const string KEY = 'time_entry_can_not_be_restarted';
|
||||
|
||||
public function report(): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,4 +7,14 @@ namespace App\Exceptions\Api;
|
||||
class TimeEntryStillRunningApiException extends ApiException
|
||||
{
|
||||
public const string KEY = 'time_entry_still_running';
|
||||
|
||||
/**
|
||||
* Report the exception.
|
||||
*
|
||||
* @return bool true means the exception handler will not report it again
|
||||
*/
|
||||
public function report(): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,4 +7,9 @@ namespace App\Exceptions\Api;
|
||||
class UserIsAlreadyMemberOfOrganizationApiException extends ApiException
|
||||
{
|
||||
public const string KEY = 'user_is_already_member_of_organization';
|
||||
|
||||
public function report(): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,4 +7,9 @@ namespace App\Exceptions\Api;
|
||||
class UserIsAlreadyMemberOfProjectApiException extends ApiException
|
||||
{
|
||||
public const string KEY = 'user_is_already_member_of_project';
|
||||
|
||||
public function report(): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,4 +7,9 @@ namespace App\Exceptions\Api;
|
||||
class UserNotPlaceholderApiException extends ApiException
|
||||
{
|
||||
public const string KEY = 'user_not_placeholder';
|
||||
|
||||
public function report(): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,4 +7,9 @@ namespace App\Exceptions\Api;
|
||||
class UserResendEmailVerificationNoPendingEmailApiException extends ApiException
|
||||
{
|
||||
public const string KEY = 'user_resend_email_verification_no_pending_email';
|
||||
|
||||
public function report(): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -6,7 +6,11 @@ namespace App\Exceptions;
|
||||
|
||||
use Illuminate\Foundation\Exceptions\Handler as ExceptionHandler;
|
||||
use Illuminate\Http\RedirectResponse;
|
||||
use Illuminate\Http\Request;
|
||||
use League\OAuth2\Server\Exception\OAuthServerException;
|
||||
use Symfony\Component\HttpFoundation\Exception\SuspiciousOperationException;
|
||||
use Symfony\Component\HttpFoundation\Response;
|
||||
use Symfony\Component\HttpKernel\Exception\BadRequestHttpException;
|
||||
use Throwable;
|
||||
|
||||
class Handler extends ExceptionHandler
|
||||
@@ -30,6 +34,33 @@ class Handler extends ExceptionHandler
|
||||
$this->reportable(function (Throwable $e): void {
|
||||
//
|
||||
});
|
||||
|
||||
$this->dontReportWhen(fn (Throwable $e): bool => $e instanceof OAuthServerException
|
||||
&& $e->getErrorType() === 'access_denied'
|
||||
&& $e->getHttpStatusCode() === 401);
|
||||
|
||||
// A request on an untrusted host (see App\Http\Middleware\TrustHosts)
|
||||
// otherwise renders as a bare "Bad request." 400. Show a message that
|
||||
// says how to fix it instead. The framework has already converted the
|
||||
// SuspiciousOperationException into a BadRequestHttpException by the time
|
||||
// renderables run, so we match that and inspect the original.
|
||||
$this->renderable(function (BadRequestHttpException $e, Request $request): ?Response {
|
||||
$previous = $e->getPrevious();
|
||||
|
||||
if (! $previous instanceof SuspiciousOperationException
|
||||
|| ! str_starts_with($previous->getMessage(), 'Untrusted Host')) {
|
||||
return null; // any other bad request keeps the default response
|
||||
}
|
||||
|
||||
$message = 'This hostname is not configured for this instance. '
|
||||
.'Set APP_URL, or add the host to TRUSTED_HOSTS.';
|
||||
|
||||
if ($request->expectsJson()) {
|
||||
return response()->json(['message' => $message], 400);
|
||||
}
|
||||
|
||||
return response()->view('errors.untrusted-host', ['message' => $message], 400);
|
||||
});
|
||||
}
|
||||
|
||||
public function render($request, Throwable $e): Response|RedirectResponse
|
||||
|
||||
@@ -28,7 +28,9 @@ class ExportController extends Controller
|
||||
|
||||
$filepath = $exportService->export($organization);
|
||||
$downloadUrl = Storage::disk(config('filesystems.private'))
|
||||
->temporaryUrl($filepath, Carbon::now()->addMinutes(10));
|
||||
->temporaryUrl($filepath, Carbon::now()->addMinutes(10), [
|
||||
'ResponseContentDisposition' => 'attachment; filename="'.basename($filepath).'"',
|
||||
]);
|
||||
|
||||
return new JsonResponse([
|
||||
'success' => true,
|
||||
|
||||
@@ -78,6 +78,9 @@ class OrganizationController extends Controller
|
||||
if ($request->getPreventOverlappingTimeEntries() !== null) {
|
||||
$organization->prevent_overlapping_time_entries = $request->getPreventOverlappingTimeEntries();
|
||||
}
|
||||
if ($request->getBreaksEnabled() !== null) {
|
||||
$organization->breaks_enabled = $request->getBreaksEnabled();
|
||||
}
|
||||
$hasBillableRate = $request->has('billable_rate');
|
||||
if ($hasBillableRate) {
|
||||
$oldBillableRate = $organization->billable_rate;
|
||||
|
||||
@@ -57,6 +57,7 @@ class ReportController extends Controller
|
||||
$filter->addEnd($properties->end);
|
||||
$filter->addActive($properties->active);
|
||||
$filter->addBillable($properties->billable);
|
||||
$filter->addType($properties->timeEntryType);
|
||||
$filter->addMemberIdsFilter($properties->memberIds?->toArray());
|
||||
$filter->addProjectIdsFilter($properties->projectIds?->toArray());
|
||||
$filter->addTagIdsFilter($properties->tagIds?->toArray(), $properties->tagMatchType);
|
||||
|
||||
@@ -112,6 +112,7 @@ class ReportController extends Controller
|
||||
$properties->timezone = $timezone;
|
||||
$properties->roundingType = $request->getPropertyRoundingType();
|
||||
$properties->roundingMinutes = $request->getPropertyRoundingMinutes();
|
||||
$properties->timeEntryType = $request->getPropertyTimeEntryType();
|
||||
$report->properties = $properties;
|
||||
if ($isPublic) {
|
||||
$report->share_secret = $reportService->generateSecret();
|
||||
|
||||
@@ -6,6 +6,7 @@ namespace App\Http\Controllers\Api\V1;
|
||||
|
||||
use App\Enums\ExportFormat;
|
||||
use App\Enums\Role;
|
||||
use App\Enums\TimeEntryType;
|
||||
use App\Exceptions\Api\FeatureIsNotAvailableInFreePlanApiException;
|
||||
use App\Exceptions\Api\OverlappingTimeEntryApiException;
|
||||
use App\Exceptions\Api\PdfRendererIsNotConfiguredException;
|
||||
@@ -209,6 +210,7 @@ class TimeEntryController extends Controller
|
||||
$filter->addTaskIdsFilter($request->input('task_ids'));
|
||||
$filter->addClientIdsFilter($request->input('client_ids'));
|
||||
$filter->addBillableFilter($request->input('billable'));
|
||||
$filter->addTypeFilter($request->input('type'));
|
||||
|
||||
return $filter->get();
|
||||
}
|
||||
@@ -334,7 +336,9 @@ class TimeEntryController extends Controller
|
||||
|
||||
return response()->json([
|
||||
'download_url' => Storage::disk(config('filesystems.private'))
|
||||
->temporaryUrl($path, now()->addMinutes(5)),
|
||||
->temporaryUrl($path, now()->addMinutes(5), [
|
||||
'ResponseContentDisposition' => 'attachment; filename="'.$filename.'"',
|
||||
]),
|
||||
]);
|
||||
}
|
||||
|
||||
@@ -533,7 +537,7 @@ class TimeEntryController extends Controller
|
||||
->putFileAs($folderPath, new File($tempFolder->path($filenameTemp)), $filename);
|
||||
} else {
|
||||
Excel::store(
|
||||
new TimeEntriesReportExport($aggregatedData, $format, $currency, $group, $subGroup, $showBillableRate),
|
||||
new TimeEntriesReportExport($aggregatedData, $format, $currency, $group, $subGroup, $showBillableRate, $localizationService),
|
||||
$path,
|
||||
config('filesystems.private'),
|
||||
$format->getExportPackageType(),
|
||||
@@ -545,7 +549,9 @@ class TimeEntryController extends Controller
|
||||
|
||||
return response()->json([
|
||||
'download_url' => Storage::disk(config('filesystems.private'))
|
||||
->temporaryUrl($path, now()->addMinutes(5)),
|
||||
->temporaryUrl($path, now()->addMinutes(5), [
|
||||
'ResponseContentDisposition' => 'attachment; filename="'.$filename.'"',
|
||||
]),
|
||||
]);
|
||||
}
|
||||
|
||||
@@ -568,6 +574,7 @@ class TimeEntryController extends Controller
|
||||
$filter->addTaskIdsFilter($request->input('task_ids'));
|
||||
$filter->addClientIdsFilter($request->input('client_ids'));
|
||||
$filter->addBillableFilter($request->input('billable'));
|
||||
$filter->addTypeFilter($request->input('type'));
|
||||
|
||||
return $filter->get();
|
||||
}
|
||||
@@ -759,6 +766,19 @@ class TimeEntryController extends Controller
|
||||
continue;
|
||||
|
||||
}
|
||||
// Changing time entries to Break entries is only allowed when breaks are enabled in the org settings
|
||||
$resultingType = isset($changes['type']) ? TimeEntryType::from($changes['type']) : $timeEntry->type;
|
||||
if ($resultingType === TimeEntryType::Break && $timeEntry->type !== TimeEntryType::Break && ! $organization->breaks_enabled) {
|
||||
$error->push($id);
|
||||
|
||||
continue;
|
||||
}
|
||||
// Break entries can not be billable, have tags or belong to a project/task (see TimeEntry::booted)
|
||||
if ($resultingType === TimeEntryType::Break && ($project !== null || $task !== null || $request->boolean('changes.billable') || count($changes['tags'] ?? []) > 0)) {
|
||||
$error->push($id);
|
||||
|
||||
continue;
|
||||
}
|
||||
$oldProject = $timeEntry->project;
|
||||
$oldTask = $timeEntry->task;
|
||||
|
||||
|
||||
@@ -124,6 +124,10 @@ class UserController extends Controller
|
||||
$user->week_start = $request->getWeekStart();
|
||||
}
|
||||
|
||||
if ($request->getSendTimeEntryStillRunningEmail() !== null) {
|
||||
$user->send_time_entry_still_running_email = $request->getSendTimeEntryStillRunningEmail();
|
||||
}
|
||||
|
||||
$user->save();
|
||||
|
||||
if ($emailToVerify !== null) {
|
||||
|
||||
@@ -36,6 +36,7 @@ class OrganizationInvitationController extends Controller
|
||||
}
|
||||
|
||||
return redirect(route('register'))
|
||||
->with('registration_email', $email)
|
||||
->with('bannerText', __('Please create an account to finish joining the :organization organization.', [
|
||||
'organization' => $organization->name,
|
||||
]))
|
||||
|
||||
@@ -15,6 +15,7 @@ use App\Http\Middleware\PreventRequestsDuringMaintenance;
|
||||
use App\Http\Middleware\RedirectIfAuthenticated;
|
||||
use App\Http\Middleware\ShareInertiaData;
|
||||
use App\Http\Middleware\TrimStrings;
|
||||
use App\Http\Middleware\TrustHosts;
|
||||
use App\Http\Middleware\TrustProxies;
|
||||
use App\Http\Middleware\ValidateSignature;
|
||||
use App\Http\Middleware\VerifyCsrfToken;
|
||||
@@ -47,6 +48,7 @@ class Kernel extends HttpKernel
|
||||
*/
|
||||
protected $middleware = [
|
||||
ForceHttps::class,
|
||||
TrustHosts::class,
|
||||
TrustProxies::class,
|
||||
HandleCors::class,
|
||||
PreventRequestsDuringMaintenance::class,
|
||||
|
||||
56
app/Http/Middleware/TrustHosts.php
Normal file
56
app/Http/Middleware/TrustHosts.php
Normal file
@@ -0,0 +1,56 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Http\Middleware;
|
||||
|
||||
use Illuminate\Http\Middleware\TrustHosts as BaseTrustHosts;
|
||||
use Illuminate\Http\Request;
|
||||
use Illuminate\Http\Response;
|
||||
|
||||
/**
|
||||
* Rejects requests whose Host is not trusted, preventing Host-header poisoning of
|
||||
* generated URLs (password reset, SSO callback, invitations). Trusted = the
|
||||
* APP_URL host and its subdomains, plus TRUSTED_HOSTS (for multi-host access such
|
||||
* as a Tailscale name). Health-check endpoints are exempt (probed by IP).
|
||||
*/
|
||||
class TrustHosts extends BaseTrustHosts
|
||||
{
|
||||
/**
|
||||
* @return array<int, string|null>
|
||||
*/
|
||||
public function hosts(): array
|
||||
{
|
||||
/** @var array<int, string> $configured */
|
||||
$configured = config('app.trusted_hosts', []);
|
||||
|
||||
$extra = array_map(function (string $host): string {
|
||||
$host = trim($host);
|
||||
|
||||
// "*.example.com" matches any subdomain, not the apex.
|
||||
if (str_starts_with($host, '*.')) {
|
||||
return '^.+\.'.preg_quote(substr($host, 2), '#').'$';
|
||||
}
|
||||
|
||||
return '^'.preg_quote($host, '#').'$';
|
||||
}, $configured);
|
||||
|
||||
return array_merge([$this->allSubdomainsOfApplicationUrl()], $extra);
|
||||
}
|
||||
|
||||
/**
|
||||
* @param \Closure(Request): Response $next
|
||||
*/
|
||||
public function handle(Request $request, $next)
|
||||
{
|
||||
// Exempt health checks (probed by IP). Also reset the trusted hosts,
|
||||
// since Octane leaks the static state across requests.
|
||||
if ($request->is('health-check/*')) {
|
||||
Request::setTrustedHosts([]);
|
||||
|
||||
return $next($request);
|
||||
}
|
||||
|
||||
return parent::handle($request, $next);
|
||||
}
|
||||
}
|
||||
@@ -24,6 +24,7 @@ class ImportRequest extends BaseFormRequest
|
||||
'data' => [
|
||||
'required',
|
||||
'string',
|
||||
'max:'.config('import.max_data_size'),
|
||||
],
|
||||
];
|
||||
}
|
||||
|
||||
@@ -51,6 +51,9 @@ class OrganizationUpdateRequest extends BaseFormRequest
|
||||
'prevent_overlapping_time_entries' => [
|
||||
'boolean',
|
||||
],
|
||||
'breaks_enabled' => [
|
||||
'boolean',
|
||||
],
|
||||
'number_format' => [
|
||||
Rule::enum(NumberFormat::class),
|
||||
],
|
||||
@@ -125,4 +128,9 @@ class OrganizationUpdateRequest extends BaseFormRequest
|
||||
{
|
||||
return $this->has('prevent_overlapping_time_entries') ? $this->boolean('prevent_overlapping_time_entries') : null;
|
||||
}
|
||||
|
||||
public function getBreaksEnabled(): ?bool
|
||||
{
|
||||
return $this->has('breaks_enabled') ? $this->boolean('breaks_enabled') : null;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -8,6 +8,7 @@ use App\Enums\TagMatchType;
|
||||
use App\Enums\TimeEntryAggregationType;
|
||||
use App\Enums\TimeEntryAggregationTypeInterval;
|
||||
use App\Enums\TimeEntryRoundingType;
|
||||
use App\Enums\TimeEntryType;
|
||||
use App\Enums\Weekday;
|
||||
use App\Http\Requests\V1\BaseFormRequest;
|
||||
use App\Models\Organization;
|
||||
@@ -177,6 +178,12 @@ class ReportStoreRequest extends BaseFormRequest
|
||||
'numeric',
|
||||
'integer',
|
||||
],
|
||||
// Filter by time entry type
|
||||
'properties.time_entry_type' => [
|
||||
'nullable',
|
||||
'string',
|
||||
Rule::enum(TimeEntryType::class),
|
||||
],
|
||||
];
|
||||
}
|
||||
|
||||
@@ -240,6 +247,15 @@ class ReportStoreRequest extends BaseFormRequest
|
||||
return null;
|
||||
}
|
||||
|
||||
public function getPropertyTimeEntryType(): ?TimeEntryType
|
||||
{
|
||||
if (! $this->has('properties.time_entry_type') || $this->input('properties.time_entry_type') === null) {
|
||||
return null;
|
||||
}
|
||||
|
||||
return TimeEntryType::from($this->input('properties.time_entry_type'));
|
||||
}
|
||||
|
||||
public function getPropertyGroup(): TimeEntryAggregationType
|
||||
{
|
||||
return TimeEntryAggregationType::from($this->input('properties.group'));
|
||||
|
||||
@@ -9,6 +9,7 @@ use App\Enums\TagMatchType;
|
||||
use App\Enums\TimeEntryAggregationType;
|
||||
use App\Enums\TimeEntryAggregationTypeInterval;
|
||||
use App\Enums\TimeEntryRoundingType;
|
||||
use App\Enums\TimeEntryType;
|
||||
use App\Http\Requests\V1\BaseFormRequest;
|
||||
use App\Models\Client;
|
||||
use App\Models\Member;
|
||||
@@ -183,6 +184,11 @@ class TimeEntryAggregateExportRequest extends BaseFormRequest
|
||||
'string',
|
||||
'in:true,false',
|
||||
],
|
||||
// Filter by time entry type
|
||||
'type' => [
|
||||
'string',
|
||||
Rule::enum(TimeEntryType::class),
|
||||
],
|
||||
'fill_gaps_in_time_groups' => [
|
||||
'string',
|
||||
'in:true,false',
|
||||
|
||||
@@ -7,6 +7,7 @@ namespace App\Http\Requests\V1\TimeEntry;
|
||||
use App\Enums\TagMatchType;
|
||||
use App\Enums\TimeEntryAggregationType;
|
||||
use App\Enums\TimeEntryRoundingType;
|
||||
use App\Enums\TimeEntryType;
|
||||
use App\Http\Requests\V1\BaseFormRequest;
|
||||
use App\Models\Client;
|
||||
use App\Models\Member;
|
||||
@@ -169,6 +170,11 @@ class TimeEntryAggregateRequest extends BaseFormRequest
|
||||
'string',
|
||||
'in:true,false',
|
||||
],
|
||||
// Filter by time entry type
|
||||
'type' => [
|
||||
'string',
|
||||
Rule::enum(TimeEntryType::class),
|
||||
],
|
||||
'fill_gaps_in_time_groups' => [
|
||||
'string',
|
||||
'in:true,false',
|
||||
|
||||
@@ -7,6 +7,7 @@ namespace App\Http\Requests\V1\TimeEntry;
|
||||
use App\Enums\ExportFormat;
|
||||
use App\Enums\TagMatchType;
|
||||
use App\Enums\TimeEntryRoundingType;
|
||||
use App\Enums\TimeEntryType;
|
||||
use App\Models\Client;
|
||||
use App\Models\Member;
|
||||
use App\Models\Organization;
|
||||
@@ -155,6 +156,11 @@ class TimeEntryIndexExportRequest extends TimeEntryIndexRequest
|
||||
'string',
|
||||
'in:true,false',
|
||||
],
|
||||
// Filter by time entry type
|
||||
'type' => [
|
||||
'string',
|
||||
Rule::enum(TimeEntryType::class),
|
||||
],
|
||||
// Limit the number of returned time entries (default: 150)
|
||||
'limit' => [
|
||||
'integer',
|
||||
|
||||
@@ -6,6 +6,7 @@ namespace App\Http\Requests\V1\TimeEntry;
|
||||
|
||||
use App\Enums\TagMatchType;
|
||||
use App\Enums\TimeEntryRoundingType;
|
||||
use App\Enums\TimeEntryType;
|
||||
use App\Http\Requests\V1\BaseFormRequest;
|
||||
use App\Models\Client;
|
||||
use App\Models\Member;
|
||||
@@ -148,6 +149,11 @@ class TimeEntryIndexRequest extends BaseFormRequest
|
||||
'string',
|
||||
'in:true,false',
|
||||
],
|
||||
// Filter by time entry type
|
||||
'type' => [
|
||||
'string',
|
||||
Rule::enum(TimeEntryType::class),
|
||||
],
|
||||
// Limit the number of returned time entries (default: 150)
|
||||
'limit' => [
|
||||
'integer',
|
||||
|
||||
@@ -4,6 +4,7 @@ declare(strict_types=1);
|
||||
|
||||
namespace App\Http\Requests\V1\TimeEntry;
|
||||
|
||||
use App\Enums\TimeEntryType;
|
||||
use App\Http\Requests\V1\BaseFormRequest;
|
||||
use App\Models\Member;
|
||||
use App\Models\Organization;
|
||||
@@ -14,6 +15,7 @@ use App\Service\PermissionStore;
|
||||
use Illuminate\Contracts\Validation\ValidationRule;
|
||||
use Illuminate\Database\Eloquent\Builder;
|
||||
use Illuminate\Support\Facades\Auth;
|
||||
use Illuminate\Validation\Rule;
|
||||
use Korridor\LaravelModelValidationRules\Rules\ExistsEloquent;
|
||||
|
||||
/**
|
||||
@@ -24,7 +26,7 @@ class TimeEntryStoreRequest extends BaseFormRequest
|
||||
/**
|
||||
* Get the validation rules that apply to the request.
|
||||
*
|
||||
* @return array<string, array<string|ValidationRule>>
|
||||
* @return array<string, array<string|\Closure|ValidationRule|\Illuminate\Contracts\Validation\Rule>>
|
||||
*/
|
||||
public function rules(): array
|
||||
{
|
||||
@@ -42,6 +44,7 @@ class TimeEntryStoreRequest extends BaseFormRequest
|
||||
'nullable',
|
||||
'string',
|
||||
'required_with:task_id',
|
||||
'prohibited_if:type,break',
|
||||
ExistsEloquent::make(Project::class, null, function (Builder $builder): Builder {
|
||||
/** @var Builder<Project> $builder */
|
||||
$builder = $builder->whereBelongsTo($this->organization, 'organization');
|
||||
@@ -60,6 +63,7 @@ class TimeEntryStoreRequest extends BaseFormRequest
|
||||
'task_id' => [
|
||||
'nullable',
|
||||
'string',
|
||||
'prohibited_if:type,break',
|
||||
ExistsEloquent::make(Task::class, null, function (Builder $builder): Builder {
|
||||
/** @var Builder<Task> $builder */
|
||||
return $builder->whereBelongsTo($this->organization, 'organization');
|
||||
@@ -85,6 +89,16 @@ class TimeEntryStoreRequest extends BaseFormRequest
|
||||
'billable' => [
|
||||
'required',
|
||||
'boolean',
|
||||
'declined_if:type,break',
|
||||
],
|
||||
// Type of the time entry (work time or a break)
|
||||
'type' => [
|
||||
Rule::enum(TimeEntryType::class),
|
||||
function (string $attribute, mixed $value, \Closure $fail): void {
|
||||
if ($value === TimeEntryType::Break->value && ! $this->organization->breaks_enabled) {
|
||||
$fail('Breaks are disabled for this organization.');
|
||||
}
|
||||
},
|
||||
],
|
||||
// Description of time entry
|
||||
'description' => [
|
||||
@@ -96,6 +110,7 @@ class TimeEntryStoreRequest extends BaseFormRequest
|
||||
'tags' => [
|
||||
'nullable',
|
||||
'array',
|
||||
'prohibited_if:type,break',
|
||||
],
|
||||
'tags.*' => [
|
||||
ExistsEloquent::make(Tag::class, null, function (Builder $builder): Builder {
|
||||
|
||||
@@ -4,6 +4,7 @@ declare(strict_types=1);
|
||||
|
||||
namespace App\Http\Requests\V1\TimeEntry;
|
||||
|
||||
use App\Enums\TimeEntryType;
|
||||
use App\Http\Requests\V1\BaseFormRequest;
|
||||
use App\Models\Member;
|
||||
use App\Models\Organization;
|
||||
@@ -14,6 +15,7 @@ use App\Service\PermissionStore;
|
||||
use Illuminate\Contracts\Validation\ValidationRule;
|
||||
use Illuminate\Database\Eloquent\Builder;
|
||||
use Illuminate\Support\Facades\Auth;
|
||||
use Illuminate\Validation\Rule;
|
||||
use Korridor\LaravelModelValidationRules\Rules\ExistsEloquent;
|
||||
|
||||
/**
|
||||
@@ -24,7 +26,7 @@ class TimeEntryUpdateMultipleRequest extends BaseFormRequest
|
||||
/**
|
||||
* Get the validation rules that apply to the request.
|
||||
*
|
||||
* @return array<string, array<string|ValidationRule>>
|
||||
* @return array<string, array<string|ValidationRule|\Illuminate\Contracts\Validation\Rule>>
|
||||
*/
|
||||
public function rules(): array
|
||||
{
|
||||
@@ -54,6 +56,7 @@ class TimeEntryUpdateMultipleRequest extends BaseFormRequest
|
||||
'nullable',
|
||||
'string',
|
||||
'required_with:task_id',
|
||||
'prohibited_if:changes.type,break',
|
||||
ExistsEloquent::make(Project::class, null, function (Builder $builder): Builder {
|
||||
/** @var Builder<Project> $builder */
|
||||
$builder = $builder->whereBelongsTo($this->organization, 'organization');
|
||||
@@ -72,6 +75,7 @@ class TimeEntryUpdateMultipleRequest extends BaseFormRequest
|
||||
'changes.task_id' => [
|
||||
'nullable',
|
||||
'string',
|
||||
'prohibited_if:changes.type,break',
|
||||
ExistsEloquent::make(Task::class, null, function (Builder $builder): Builder {
|
||||
/** @var Builder<Task> $builder */
|
||||
return $builder->whereBelongsTo($this->organization, 'organization');
|
||||
@@ -84,7 +88,13 @@ class TimeEntryUpdateMultipleRequest extends BaseFormRequest
|
||||
],
|
||||
// Whether time entry is billable
|
||||
'changes.billable' => [
|
||||
'sometimes',
|
||||
'boolean',
|
||||
'declined_if:changes.type,break',
|
||||
],
|
||||
// Type of the time entry (work time or a break)
|
||||
'changes.type' => [
|
||||
Rule::enum(TimeEntryType::class),
|
||||
],
|
||||
// Description of time entry
|
||||
'changes.description' => [
|
||||
@@ -96,6 +106,7 @@ class TimeEntryUpdateMultipleRequest extends BaseFormRequest
|
||||
'changes.tags' => [
|
||||
'nullable',
|
||||
'array',
|
||||
'prohibited_if:changes.type,break',
|
||||
],
|
||||
'changes.tags.*' => [
|
||||
'string',
|
||||
|
||||
@@ -4,16 +4,21 @@ declare(strict_types=1);
|
||||
|
||||
namespace App\Http\Requests\V1\TimeEntry;
|
||||
|
||||
use App\Enums\TimeEntryType;
|
||||
use App\Http\Requests\V1\BaseFormRequest;
|
||||
use App\Models\Member;
|
||||
use App\Models\Organization;
|
||||
use App\Models\Project;
|
||||
use App\Models\Tag;
|
||||
use App\Models\Task;
|
||||
use App\Models\TimeEntry;
|
||||
use App\Service\PermissionStore;
|
||||
use Illuminate\Contracts\Validation\ValidationRule;
|
||||
use Illuminate\Database\Eloquent\Builder;
|
||||
use Illuminate\Support\Facades\Auth;
|
||||
use Illuminate\Validation\ConditionalRules;
|
||||
use Illuminate\Validation\Rule;
|
||||
use Illuminate\Validation\Rules\ProhibitedIf;
|
||||
use Korridor\LaravelModelValidationRules\Rules\ExistsEloquent;
|
||||
|
||||
/**
|
||||
@@ -24,10 +29,19 @@ class TimeEntryUpdateRequest extends BaseFormRequest
|
||||
/**
|
||||
* Get the validation rules that apply to the request.
|
||||
*
|
||||
* @return array<string, array<string|ValidationRule>>
|
||||
* @return array<string, array<string|\Closure|ValidationRule|\Illuminate\Contracts\Validation\Rule|ProhibitedIf|ConditionalRules>>
|
||||
*/
|
||||
public function rules(): array
|
||||
{
|
||||
// Break restrictions need to apply based on the type the entry will have after the
|
||||
// update, not only when the payload itself contains type=break.
|
||||
$timeEntry = $this->route('timeEntry');
|
||||
$timeEntry = $timeEntry instanceof TimeEntry ? $timeEntry : null;
|
||||
$resultingType = $this->has('type')
|
||||
? TimeEntryType::tryFrom((string) $this->input('type'))
|
||||
: $timeEntry?->type;
|
||||
$isBreak = $resultingType === TimeEntryType::Break;
|
||||
|
||||
return [
|
||||
// ID of the organization member that the time entry should belong to
|
||||
'member_id' => [
|
||||
@@ -42,6 +56,7 @@ class TimeEntryUpdateRequest extends BaseFormRequest
|
||||
'nullable',
|
||||
'string',
|
||||
'required_with:task_id',
|
||||
Rule::prohibitedIf($isBreak),
|
||||
ExistsEloquent::make(Project::class, null, function (Builder $builder): Builder {
|
||||
/** @var Builder<Project> $builder */
|
||||
$builder = $builder->whereBelongsTo($this->organization, 'organization');
|
||||
@@ -60,6 +75,7 @@ class TimeEntryUpdateRequest extends BaseFormRequest
|
||||
'task_id' => [
|
||||
'nullable',
|
||||
'string',
|
||||
Rule::prohibitedIf($isBreak),
|
||||
ExistsEloquent::make(Task::class, null, function (Builder $builder): Builder {
|
||||
/** @var Builder<Task> $builder */
|
||||
return $builder->whereBelongsTo($this->organization, 'organization');
|
||||
@@ -82,7 +98,22 @@ class TimeEntryUpdateRequest extends BaseFormRequest
|
||||
],
|
||||
// Whether time entry is billable
|
||||
'billable' => [
|
||||
'sometimes',
|
||||
'boolean',
|
||||
Rule::when($isBreak, ['declined']),
|
||||
],
|
||||
// Type of the time entry (work time or a break)
|
||||
'type' => [
|
||||
Rule::enum(TimeEntryType::class),
|
||||
function (string $attribute, mixed $value, \Closure $fail) use ($timeEntry): void {
|
||||
// While breaks are disabled, entries that already are breaks may stay
|
||||
// breaks, but converting a work entry to a break is not allowed.
|
||||
if ($value === TimeEntryType::Break->value
|
||||
&& ! $this->organization->breaks_enabled
|
||||
&& $timeEntry?->type !== TimeEntryType::Break) {
|
||||
$fail('Breaks are disabled for this organization.');
|
||||
}
|
||||
},
|
||||
],
|
||||
// Description of time entry
|
||||
'description' => [
|
||||
@@ -94,6 +125,7 @@ class TimeEntryUpdateRequest extends BaseFormRequest
|
||||
'tags' => [
|
||||
'nullable',
|
||||
'array',
|
||||
Rule::prohibitedIf($isBreak),
|
||||
],
|
||||
'tags.*' => [
|
||||
'string',
|
||||
|
||||
@@ -58,6 +58,9 @@ class UserUpdateRequest extends BaseFormRequest
|
||||
'week_start' => [
|
||||
Rule::enum(Weekday::class),
|
||||
],
|
||||
'send_time_entry_still_running_email' => [
|
||||
'boolean',
|
||||
],
|
||||
];
|
||||
}
|
||||
|
||||
@@ -81,6 +84,13 @@ class UserUpdateRequest extends BaseFormRequest
|
||||
return $this->has('week_start') ? Weekday::from($this->input('week_start')) : null;
|
||||
}
|
||||
|
||||
public function getSendTimeEntryStillRunningEmail(): ?bool
|
||||
{
|
||||
return $this->has('send_time_entry_still_running_email')
|
||||
? $this->boolean('send_time_entry_still_running_email')
|
||||
: null;
|
||||
}
|
||||
|
||||
public function hasPhotoKey(): bool
|
||||
{
|
||||
return $this->has('photo');
|
||||
|
||||
@@ -57,6 +57,8 @@ class OrganizationResource extends BaseResource
|
||||
'employees_can_manage_tasks' => $this->resource->employees_can_manage_tasks,
|
||||
/** @var bool $prevent_overlapping_time_entries Prevent creating overlapping time entries (only new entries) */
|
||||
'prevent_overlapping_time_entries' => $this->resource->prevent_overlapping_time_entries,
|
||||
/** @var bool $breaks_enabled Whether members of the organization can track breaks */
|
||||
'breaks_enabled' => $this->resource->breaks_enabled,
|
||||
/** @var string $currency Currency code (ISO 4217) */
|
||||
'currency' => $this->resource->currency,
|
||||
/** @var string $currency_symbol Currency symbol */
|
||||
|
||||
@@ -50,6 +50,8 @@ class DetailedReportResource extends BaseResource
|
||||
'member_ids' => $this->resource->properties->memberIds?->toArray(),
|
||||
/** @var bool|null $billable Filter by billable status */
|
||||
'billable' => $this->resource->properties->billable,
|
||||
/** @var string|null $time_entry_type Filter by time entry type */
|
||||
'time_entry_type' => $this->resource->properties->timeEntryType?->value,
|
||||
/** @var array<string>|null $client_ids Filter by client IDs, client IDs are OR combined */
|
||||
'client_ids' => $this->resource->properties->clientIds?->toArray(),
|
||||
/** @var array<string>|null $project_ids Filter by project IDs, project IDs are OR combined */
|
||||
|
||||
@@ -47,6 +47,8 @@ class TimeEntryResource extends BaseResource
|
||||
'tags' => $this->resource->tags ?? [],
|
||||
/** @var bool $billable Whether time entry is billable */
|
||||
'billable' => $this->resource->billable,
|
||||
/** @var string $type Type of the time entry (`work` time or a `break`) */
|
||||
'type' => $this->resource->type->value,
|
||||
];
|
||||
}
|
||||
}
|
||||
|
||||
@@ -36,6 +36,8 @@ class UserResource extends BaseResource
|
||||
'timezone' => $this->resource->timezone,
|
||||
/** @var Weekday $week_start Starting day of the week */
|
||||
'week_start' => $this->resource->week_start->value,
|
||||
/** @var bool $send_time_entry_still_running_email Whether to email the user when a time entry has been running for more than 8 hours */
|
||||
'send_time_entry_still_running_email' => $this->resource->send_time_entry_still_running_email,
|
||||
];
|
||||
}
|
||||
}
|
||||
|
||||
@@ -34,6 +34,7 @@ use OwenIt\Auditing\Contracts\Auditable as AuditableContract;
|
||||
* @property bool $employees_can_see_billable_rates
|
||||
* @property bool $employees_can_manage_tasks
|
||||
* @property bool $prevent_overlapping_time_entries
|
||||
* @property bool $breaks_enabled
|
||||
* @property User $owner
|
||||
* @property Carbon|null $created_at
|
||||
* @property Carbon|null $updated_at
|
||||
@@ -70,6 +71,7 @@ class Organization extends Model implements AuditableContract
|
||||
'employees_can_see_billable_rates' => 'boolean',
|
||||
'employees_can_manage_tasks' => 'boolean',
|
||||
'prevent_overlapping_time_entries' => 'boolean',
|
||||
'breaks_enabled' => 'boolean',
|
||||
'number_format' => NumberFormat::class,
|
||||
'currency_format' => CurrencyFormat::class,
|
||||
'date_format' => DateFormat::class,
|
||||
|
||||
@@ -4,6 +4,7 @@ declare(strict_types=1);
|
||||
|
||||
namespace App\Models;
|
||||
|
||||
use App\Enums\TimeEntryType;
|
||||
use App\Models\Concerns\CustomAuditable;
|
||||
use App\Models\Concerns\HasUuids;
|
||||
use App\Service\BillableRateService;
|
||||
@@ -28,6 +29,7 @@ use Staudenmeir\EloquentJsonRelations\Relations\BelongsToJson;
|
||||
* @property Carbon|null $end
|
||||
* @property int|null $billable_rate Billable rate per hour in cents
|
||||
* @property bool $billable
|
||||
* @property TimeEntryType $type
|
||||
* @property array<string> $tags
|
||||
* @property string $user_id
|
||||
* @property string $member_id
|
||||
@@ -71,12 +73,20 @@ class TimeEntry extends Model implements AuditableContract
|
||||
'start' => 'datetime',
|
||||
'end' => 'datetime',
|
||||
'billable' => 'bool',
|
||||
'type' => TimeEntryType::class,
|
||||
'tags' => 'array',
|
||||
'billable_rate' => 'int',
|
||||
'is_imported' => 'bool',
|
||||
'still_active_email_sent_at' => 'datetime',
|
||||
];
|
||||
|
||||
/**
|
||||
* @var array<string, string>
|
||||
*/
|
||||
protected $attributes = [
|
||||
'type' => 'work',
|
||||
];
|
||||
|
||||
public const array SELECT_COLUMNS = [
|
||||
'id',
|
||||
'description',
|
||||
@@ -84,6 +94,7 @@ class TimeEntry extends Model implements AuditableContract
|
||||
'end',
|
||||
'billable_rate',
|
||||
'billable',
|
||||
'type',
|
||||
'user_id',
|
||||
'organization_id',
|
||||
'project_id',
|
||||
@@ -117,6 +128,21 @@ class TimeEntry extends Model implements AuditableContract
|
||||
'billable_rate',
|
||||
];
|
||||
|
||||
protected static function booted(): void
|
||||
{
|
||||
// Break entries can never be billable, have tags or belong to a project/task.
|
||||
static::saving(function (TimeEntry $timeEntry): void {
|
||||
if ($timeEntry->type === TimeEntryType::Break) {
|
||||
$timeEntry->billable = false;
|
||||
$timeEntry->billable_rate = null;
|
||||
$timeEntry->project_id = null;
|
||||
$timeEntry->task_id = null;
|
||||
$timeEntry->client_id = null;
|
||||
$timeEntry->tags = [];
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
public function getBillableRateComputed(): ?int
|
||||
{
|
||||
return app(BillableRateService::class)->getBillableRateForTimeEntry($this);
|
||||
@@ -173,6 +199,16 @@ class TimeEntry extends Model implements AuditableContract
|
||||
$builder->whereJsonContains('tags', $tag->getKey());
|
||||
}
|
||||
|
||||
/**
|
||||
* Only work entries — breaks do not count toward tracked/billable time.
|
||||
*
|
||||
* @param Builder<TimeEntry> $builder
|
||||
*/
|
||||
public function scopeWorkTime(Builder $builder): void
|
||||
{
|
||||
$builder->where('type', '=', TimeEntryType::Work);
|
||||
}
|
||||
|
||||
/**
|
||||
* @return BelongsTo<User, $this>
|
||||
*/
|
||||
|
||||
@@ -38,10 +38,14 @@ use OwenIt\Auditing\Contracts\Auditable as AuditableContract;
|
||||
* @property string|null $pending_email
|
||||
* @property Carbon|null $email_verified_at
|
||||
* @property string|null $password
|
||||
* @property string|null $remember_token
|
||||
* @property string|null $two_factor_secret
|
||||
* @property string|null $two_factor_recovery_codes
|
||||
* @property Carbon|null $two_factor_confirmed_at
|
||||
* @property string $timezone
|
||||
* @property bool $is_placeholder
|
||||
* @property Weekday $week_start
|
||||
* @property bool $send_time_entry_still_running_email
|
||||
* @property string|null $profile_photo_path
|
||||
* @property-read Organization|null $currentOrganization
|
||||
* @property-read string $profile_photo_url
|
||||
@@ -108,6 +112,7 @@ class User extends Authenticatable implements AuditableContract, FilamentUser, M
|
||||
'is_admin' => 'boolean',
|
||||
'is_placeholder' => 'boolean',
|
||||
'week_start' => Weekday::class,
|
||||
'send_time_entry_still_running_email' => 'boolean',
|
||||
];
|
||||
|
||||
/**
|
||||
@@ -117,6 +122,7 @@ class User extends Authenticatable implements AuditableContract, FilamentUser, M
|
||||
*/
|
||||
protected $attributes = [
|
||||
'week_start' => Weekday::Monday,
|
||||
'send_time_entry_still_running_email' => true,
|
||||
];
|
||||
|
||||
/**
|
||||
@@ -147,7 +153,9 @@ class User extends Authenticatable implements AuditableContract, FilamentUser, M
|
||||
|
||||
public function canAccessPanel(Panel $panel): bool
|
||||
{
|
||||
return in_array($this->email, config('auth.super_admins', []), true) && $this->hasVerifiedEmail();
|
||||
return $this->is_placeholder === false
|
||||
&& in_array($this->email, config('auth.super_admins', []), true)
|
||||
&& $this->hasVerifiedEmail();
|
||||
}
|
||||
|
||||
public function isMemberOfOrganization(Organization $organization): bool
|
||||
|
||||
@@ -20,6 +20,7 @@ use App\Service\BillingContract;
|
||||
use App\Service\IpLookup\IpLookupServiceContract;
|
||||
use App\Service\IpLookup\NoIpLookupService;
|
||||
use App\Service\PermissionStore;
|
||||
use DateTimeInterface;
|
||||
use Dedoc\Scramble\Scramble;
|
||||
use Dedoc\Scramble\Support\Generator\OpenApi;
|
||||
use Dedoc\Scramble\Support\Generator\SecurityScheme;
|
||||
@@ -29,8 +30,13 @@ use Filament\Tables\Table;
|
||||
use Illuminate\Database\Eloquent\Model;
|
||||
use Illuminate\Database\Eloquent\Relations\Relation;
|
||||
use Illuminate\Foundation\Application;
|
||||
use Illuminate\Http\Request;
|
||||
use Illuminate\Support\Facades\Route;
|
||||
use Illuminate\Support\Facades\Storage;
|
||||
use Illuminate\Support\Facades\URL;
|
||||
use Illuminate\Support\ServiceProvider;
|
||||
use Illuminate\Support\Str;
|
||||
use Symfony\Component\HttpFoundation\StreamedResponse;
|
||||
|
||||
class AppServiceProvider extends ServiceProvider
|
||||
{
|
||||
@@ -98,6 +104,27 @@ class AppServiceProvider extends ServiceProvider
|
||||
$this->app->bind(IpLookupServiceContract::class, NoIpLookupService::class);
|
||||
$this->app->bind(BillingContract::class);
|
||||
|
||||
// Storage
|
||||
// The local driver ignores the ResponseContentDisposition option of temporaryUrl,
|
||||
// so mirror it through the signed query parameters of the storage route.
|
||||
$privateDisk = config('filesystems.private');
|
||||
if (config('filesystems.disks.'.$privateDisk.'.driver') === 'local') {
|
||||
$disk = Storage::disk($privateDisk);
|
||||
$disk->serveUsing(function (Request $request, string $path, array $headers) use ($disk): StreamedResponse {
|
||||
return $disk->response($path, null, $headers, $request->query('disposition', 'inline'));
|
||||
});
|
||||
$disk->buildTemporaryUrlsUsing(function (string $path, DateTimeInterface $expiration, array $options) use ($privateDisk): string {
|
||||
$parameters = array_filter([
|
||||
'path' => $path,
|
||||
'disposition' => isset($options['ResponseContentDisposition'])
|
||||
? Str::before($options['ResponseContentDisposition'], ';')
|
||||
: null,
|
||||
]);
|
||||
|
||||
return url(URL::temporarySignedRoute('storage.'.$privateDisk, $expiration, $parameters, absolute: false));
|
||||
});
|
||||
}
|
||||
|
||||
// Routing
|
||||
Route::model('member', Member::class);
|
||||
Route::model('invitation', OrganizationInvitation::class);
|
||||
|
||||
@@ -4,11 +4,14 @@ declare(strict_types=1);
|
||||
|
||||
namespace App\Providers;
|
||||
|
||||
use App\Auth\ActiveUserProvider;
|
||||
use App\Models\Passport\AuthCode;
|
||||
use App\Models\Passport\Client;
|
||||
use App\Models\Passport\RefreshToken;
|
||||
use App\Models\Passport\Token;
|
||||
use Illuminate\Contracts\Foundation\Application;
|
||||
use Illuminate\Foundation\Support\Providers\AuthServiceProvider as ServiceProvider;
|
||||
use Illuminate\Support\Facades\Auth;
|
||||
use Laravel\Passport\Passport;
|
||||
|
||||
class AuthServiceProvider extends ServiceProvider
|
||||
@@ -26,6 +29,13 @@ class AuthServiceProvider extends ServiceProvider
|
||||
*/
|
||||
public function boot(): void
|
||||
{
|
||||
// Replaces the built-in eloquent user provider, so that no authentication flow can
|
||||
// resolve a placeholder user. The driver name is kept, because Passport recognizes
|
||||
// only providers that are configured with the driver "eloquent".
|
||||
Auth::provider('eloquent', function (Application $app, array $config): ActiveUserProvider {
|
||||
return new ActiveUserProvider($app->make('hash'), $config['model']);
|
||||
});
|
||||
|
||||
// define scopes for passport tokens
|
||||
Passport::tokensCan([
|
||||
'create' => 'Create resources',
|
||||
|
||||
@@ -45,6 +45,7 @@ class FortifyServiceProvider extends ServiceProvider
|
||||
|
||||
Fortify::registerView(function () {
|
||||
return Inertia::render('Auth/Register', [
|
||||
'email' => session('registration_email', ''),
|
||||
'terms_url' => config('auth.terms_url'),
|
||||
'privacy_policy_url' => config('auth.privacy_policy_url'),
|
||||
'newsletter_consent' => config('auth.newsletter_consent'),
|
||||
|
||||
@@ -33,8 +33,8 @@ class RouteServiceProvider extends ServiceProvider
|
||||
}
|
||||
|
||||
return $request->user()
|
||||
? Limit::perMinute(200)->by($request->user()->id)
|
||||
: Limit::perMinute(60)->by($request->ip());
|
||||
? Limit::perMinute(config('app.api_rate_limit_authenticated_per_minute'))->by($request->user()->id)
|
||||
: Limit::perMinute(config('app.api_rate_limit_guest_per_minute'))->by($request->ip());
|
||||
});
|
||||
|
||||
$this->routes(function (): void {
|
||||
|
||||
@@ -4,6 +4,7 @@ declare(strict_types=1);
|
||||
|
||||
namespace App\Service;
|
||||
|
||||
use App\Enums\TimeEntryType;
|
||||
use App\Enums\Weekday;
|
||||
use App\Models\Organization;
|
||||
use App\Models\Project;
|
||||
@@ -154,6 +155,7 @@ class DashboardService
|
||||
->select(DB::raw('DATE('.$dateWithTimeZone.') as date, round(sum(extract(epoch from (coalesce("end", now()) - start)))) as aggregate'))
|
||||
->where('user_id', '=', $user->getKey())
|
||||
->where('organization_id', '=', $organization->getKey())
|
||||
->workTime()
|
||||
->groupBy(DB::raw('DATE('.$dateWithTimeZone.')'))
|
||||
->orderBy('date');
|
||||
|
||||
@@ -195,6 +197,7 @@ class DashboardService
|
||||
->select(DB::raw('DATE('.$dateWithTimeZone.') as date, round(sum(extract(epoch from (coalesce("end", now()) - start)))) as aggregate'))
|
||||
->where('user_id', '=', $user->getKey())
|
||||
->where('organization_id', '=', $organization->getKey())
|
||||
->workTime()
|
||||
->groupBy(DB::raw('DATE('.$dateWithTimeZone.')'))
|
||||
->orderBy('date');
|
||||
|
||||
@@ -222,7 +225,8 @@ class DashboardService
|
||||
$query = TimeEntry::query()
|
||||
->select(DB::raw('round(sum(extract(epoch from (coalesce("end", now()) - start)))) as aggregate'))
|
||||
->where('user_id', '=', $user->getKey())
|
||||
->where('organization_id', '=', $organization->getKey());
|
||||
->where('organization_id', '=', $organization->getKey())
|
||||
->workTime();
|
||||
|
||||
$query = $this->constrainDateByPossibleDates($query, $possibleDays, $timezone);
|
||||
/** @var Collection<int, object{aggregate: int}> $resultDb */
|
||||
@@ -290,6 +294,7 @@ class DashboardService
|
||||
->select(DB::raw('project_id, round(sum(extract(epoch from (coalesce("end", now()) - start)))) as aggregate'))
|
||||
->where('user_id', '=', $user->getKey())
|
||||
->where('organization_id', '=', $organization->getKey())
|
||||
->workTime()
|
||||
->groupBy('project_id');
|
||||
|
||||
$query = $this->constrainDateByCurrentWeek($query, $timezone, $user->week_start);
|
||||
@@ -433,7 +438,8 @@ class DashboardService
|
||||
JOIN time_entries ON time_entries.start < time_ranges."end"
|
||||
AND coalesce(time_entries."end", :now::timestamp) > time_ranges.start
|
||||
WHERE time_entries.user_id = :user_id and
|
||||
time_entries.organization_id = :organization_id
|
||||
time_entries.organization_id = :organization_id and
|
||||
time_entries.type = :work_type
|
||||
GROUP BY time_ranges.start
|
||||
ORDER BY time_ranges.start
|
||||
', [
|
||||
@@ -442,6 +448,7 @@ class DashboardService
|
||||
'user_id' => $user->getKey(),
|
||||
'organization_id' => $organization->getKey(),
|
||||
'now' => Carbon::now()->toDateTimeString(),
|
||||
'work_type' => TimeEntryType::Work->value,
|
||||
]))->pluck('aggregate', 'start');
|
||||
|
||||
$response = [];
|
||||
|
||||
@@ -8,6 +8,7 @@ use App\Enums\TagMatchType;
|
||||
use App\Enums\TimeEntryAggregationType;
|
||||
use App\Enums\TimeEntryAggregationTypeInterval;
|
||||
use App\Enums\TimeEntryRoundingType;
|
||||
use App\Enums\TimeEntryType;
|
||||
use App\Enums\Weekday;
|
||||
use App\Service\TimeEntryFilter;
|
||||
use Illuminate\Contracts\Database\Eloquent\Castable;
|
||||
@@ -68,6 +69,8 @@ class ReportPropertiesDto implements Castable
|
||||
|
||||
public ?int $roundingMinutes = null;
|
||||
|
||||
public ?TimeEntryType $timeEntryType = null;
|
||||
|
||||
/**
|
||||
* Get the caster class to use when casting from / to this cast target.
|
||||
*
|
||||
@@ -129,6 +132,12 @@ class ReportPropertiesDto implements Castable
|
||||
$dto->roundingType = isset($data->roundingType) ? TimeEntryRoundingType::from($data->roundingType) : null;
|
||||
// Note: roundingMinutes was added later so it is possible that the value is missing in persisted reports in the DB
|
||||
$dto->roundingMinutes = isset($data->roundingMinutes) ? (int) $data->roundingMinutes : null;
|
||||
// Note: timeEntryType was added later, reports persisted before that are missing the value and default to "work"
|
||||
if (property_exists($data, 'timeEntryType')) {
|
||||
$dto->timeEntryType = $data->timeEntryType !== null ? TimeEntryType::from($data->timeEntryType) : null;
|
||||
} else {
|
||||
$dto->timeEntryType = TimeEntryType::Work;
|
||||
}
|
||||
|
||||
return $dto;
|
||||
}
|
||||
@@ -157,6 +166,7 @@ class ReportPropertiesDto implements Castable
|
||||
'timezone' => $value->timezone,
|
||||
'roundingType' => $value->roundingType?->value,
|
||||
'roundingMinutes' => $value->roundingMinutes,
|
||||
'timeEntryType' => $value->timeEntryType?->value,
|
||||
];
|
||||
|
||||
$jsonString = json_encode($data);
|
||||
|
||||
@@ -107,6 +107,7 @@ class ExportService
|
||||
'end',
|
||||
'billable_rate',
|
||||
'billable',
|
||||
'type',
|
||||
'member_id',
|
||||
'user_id',
|
||||
'organization_id',
|
||||
@@ -131,6 +132,7 @@ class ExportService
|
||||
$timeEntry->end?->toIso8601ZuluString() ?? '',
|
||||
$timeEntry->billable_rate ?? '',
|
||||
$timeEntry->billable ? 'true' : 'false',
|
||||
$timeEntry->type->value,
|
||||
$timeEntry->member_id,
|
||||
$timeEntry->user_id,
|
||||
$timeEntry->organization_id,
|
||||
|
||||
@@ -9,11 +9,8 @@ use App\Service\Import\Importers\ImporterContract;
|
||||
use App\Service\Import\Importers\ImporterProvider;
|
||||
use App\Service\Import\Importers\ImportException;
|
||||
use App\Service\Import\Importers\ReportDto;
|
||||
use Illuminate\Support\Carbon;
|
||||
use Illuminate\Support\Facades\Cache;
|
||||
use Illuminate\Support\Facades\DB;
|
||||
use Illuminate\Support\Facades\Storage;
|
||||
use Illuminate\Support\Str;
|
||||
|
||||
class ImportService
|
||||
{
|
||||
@@ -25,8 +22,6 @@ class ImportService
|
||||
/** @var ImporterContract $importer */
|
||||
$importer = app(ImporterProvider::class)->getImporter($importerType);
|
||||
$importer->init($organization);
|
||||
Storage::disk(config('filesystems.default'))
|
||||
->put('import/'.Carbon::now()->toDateString().'-'.$organization->getKey().'-'.Str::uuid(), $data);
|
||||
|
||||
$lock = Cache::lock('import:'.$organization->getKey(), config('octane.max_execution_time', 60) + 1);
|
||||
|
||||
|
||||
@@ -44,7 +44,7 @@ class ClockifyProjectsImporter extends DefaultImporter
|
||||
'organization_id' => $this->organization->id,
|
||||
], [
|
||||
'color' => $this->colorService->getRandomColor(),
|
||||
'is_billable' => $record['Billability'] === 'Yes',
|
||||
'is_billable' => ($record['Billability'] ?? '') === 'Yes',
|
||||
'billable_rate' => $billableRateKey !== null && $record[$billableRateKey] !== '' ? (int) (((float) $record[$billableRateKey]) * 100) : null,
|
||||
'estimated_time' => isset($record['Estimated (h)']) && is_numeric($record['Estimated (h)']) ? (int) ($record['Estimated (h)'] * 3600) : null,
|
||||
'archived_at' => $record['Status'] === 'Archived' ? Carbon::now() : null,
|
||||
@@ -54,6 +54,7 @@ class ClockifyProjectsImporter extends DefaultImporter
|
||||
if ($tasksKey !== null && $record[$tasksKey] !== '') {
|
||||
$tasks = explode(', ', $record[$tasksKey]);
|
||||
foreach ($tasks as $task) {
|
||||
$this->checkTaskNameLength($task);
|
||||
$this->taskImportHelper->getKey([
|
||||
'name' => $task,
|
||||
'project_id' => $projectId,
|
||||
@@ -83,7 +84,6 @@ class ClockifyProjectsImporter extends DefaultImporter
|
||||
'Project',
|
||||
'Status',
|
||||
'Visibility',
|
||||
'Billability',
|
||||
];
|
||||
foreach ($requiredFields as $requiredField) {
|
||||
if (! in_array($requiredField, $header, true)) {
|
||||
|
||||
@@ -5,6 +5,7 @@ declare(strict_types=1);
|
||||
namespace App\Service\Import\Importers;
|
||||
|
||||
use App\Enums\Role;
|
||||
use App\Enums\TimeEntryType;
|
||||
use App\Jobs\RecalculateSpentTimeForProject;
|
||||
use App\Jobs\RecalculateSpentTimeForTask;
|
||||
use App\Models\TimeEntry;
|
||||
@@ -71,8 +72,12 @@ class ClockifyTimeEntriesImporter extends DefaultImporter
|
||||
'role' => Role::Placeholder->value,
|
||||
]);
|
||||
$member = $this->memberImportHelper->getModelById($memberId);
|
||||
// Clockify allows a project/task/client/tags/billable on breaks, but those are
|
||||
// meaningless for non-work time. Detect breaks up front and skip creating any of
|
||||
// that so a break can't spawn an orphan project/tag or inflate the import counts.
|
||||
$isBreak = isset($record['Type']) && strtolower($record['Type']) === 'break';
|
||||
$clientId = null;
|
||||
if (($record['Client'] ?? '') !== '') {
|
||||
if (! $isBreak && ($record['Client'] ?? '') !== '') {
|
||||
$clientId = $this->clientImportHelper->getKey([
|
||||
'name' => $record['Client'],
|
||||
'organization_id' => $this->organization->id,
|
||||
@@ -81,7 +86,7 @@ class ClockifyTimeEntriesImporter extends DefaultImporter
|
||||
$projectId = null;
|
||||
$project = null;
|
||||
$projectMember = null;
|
||||
if ($record['Project'] !== '') {
|
||||
if (! $isBreak && $record['Project'] !== '') {
|
||||
$projectId = $this->projectImportHelper->getKey([
|
||||
'name' => $record['Project'],
|
||||
'client_id' => $clientId,
|
||||
@@ -97,7 +102,8 @@ class ClockifyTimeEntriesImporter extends DefaultImporter
|
||||
]);
|
||||
}
|
||||
$taskId = null;
|
||||
if ($taskKey !== null && $record[$taskKey] !== '') {
|
||||
if (! $isBreak && $taskKey !== null && $record[$taskKey] !== '') {
|
||||
$this->checkTaskNameLength($record[$taskKey]);
|
||||
$taskId = $this->taskImportHelper->getKey([
|
||||
'name' => $record[$taskKey],
|
||||
'project_id' => $projectId,
|
||||
@@ -123,7 +129,12 @@ class ClockifyTimeEntriesImporter extends DefaultImporter
|
||||
}
|
||||
$timeEntry->billable = $record['Billable'] === 'Yes';
|
||||
}
|
||||
$timeEntry->tags = $this->getTags($record['Tags']);
|
||||
if ($isBreak) {
|
||||
// Breaks can not be billable or belong to a project/task (already skipped above)
|
||||
$timeEntry->type = TimeEntryType::Break;
|
||||
$timeEntry->billable = false;
|
||||
}
|
||||
$timeEntry->tags = $isBreak ? [] : $this->getTags($record['Tags']);
|
||||
$timeEntry->is_imported = true;
|
||||
|
||||
// Start
|
||||
@@ -217,7 +228,6 @@ class ClockifyTimeEntriesImporter extends DefaultImporter
|
||||
'Project',
|
||||
'Description',
|
||||
'User',
|
||||
'Group',
|
||||
'Email',
|
||||
'Tags',
|
||||
'Start Date',
|
||||
|
||||
@@ -21,6 +21,8 @@ use Illuminate\Database\Eloquent\Builder;
|
||||
|
||||
abstract class DefaultImporter implements ImporterContract
|
||||
{
|
||||
protected const TASK_NAME_MAX_LENGTH = 500;
|
||||
|
||||
protected Organization $organization;
|
||||
|
||||
/**
|
||||
@@ -181,6 +183,16 @@ abstract class DefaultImporter implements ImporterContract
|
||||
$this->billableRateService = app(BillableRateService::class);
|
||||
}
|
||||
|
||||
/**
|
||||
* @throws ImportException
|
||||
*/
|
||||
protected function checkTaskNameLength(string $taskName): void
|
||||
{
|
||||
if (strlen($taskName) > self::TASK_NAME_MAX_LENGTH) {
|
||||
throw new ImportException('Task name ("'.$taskName.'") is too long, maximum length is '.self::TASK_NAME_MAX_LENGTH.' characters');
|
||||
}
|
||||
}
|
||||
|
||||
#[\Override]
|
||||
public function getReport(): ReportDto
|
||||
{
|
||||
|
||||
@@ -113,6 +113,7 @@ class GenericTimeEntriesImporter extends DefaultImporter
|
||||
}
|
||||
$taskId = null;
|
||||
if ($record['task'] !== '') {
|
||||
$this->checkTaskNameLength($record['task']);
|
||||
$taskId = $this->taskImportHelper->getKey([
|
||||
'name' => $record['task'],
|
||||
'project_id' => $projectId,
|
||||
|
||||
@@ -92,6 +92,7 @@ class HarvestTimeEntriesImporter extends DefaultImporter
|
||||
}
|
||||
$taskId = null;
|
||||
if ($record['Task'] !== '') {
|
||||
$this->checkTaskNameLength($record['Task']);
|
||||
$taskId = $this->taskImportHelper->getKey([
|
||||
'name' => $record['Task'],
|
||||
'project_id' => $projectId,
|
||||
|
||||
@@ -5,6 +5,7 @@ declare(strict_types=1);
|
||||
namespace App\Service\Import\Importers;
|
||||
|
||||
use App\Enums\Role;
|
||||
use App\Enums\TimeEntryType;
|
||||
use App\Jobs\RecalculateSpentTimeForProject;
|
||||
use App\Jobs\RecalculateSpentTimeForTask;
|
||||
use App\Models\TimeEntry;
|
||||
@@ -15,7 +16,6 @@ use Illuminate\Support\Str;
|
||||
use League\Csv\Reader;
|
||||
use Override;
|
||||
use Spatie\TemporaryDirectory\TemporaryDirectory;
|
||||
use ZipArchive;
|
||||
|
||||
class SolidtimeImporter extends DefaultImporter
|
||||
{
|
||||
@@ -33,16 +33,10 @@ class SolidtimeImporter extends DefaultImporter
|
||||
$temporaryDirectoryZip = null;
|
||||
$temporaryDirectory = null;
|
||||
try {
|
||||
$zip = new ZipArchive;
|
||||
$temporaryDirectoryZip = TemporaryDirectory::make();
|
||||
file_put_contents($temporaryDirectoryZip->path('import.zip'), $data);
|
||||
$res = $zip->open($temporaryDirectoryZip->path('import.zip'), ZipArchive::RDONLY);
|
||||
if ($res !== true) {
|
||||
throw new ImportException('Invalid ZIP, error code: '.$res);
|
||||
}
|
||||
$temporaryDirectory = TemporaryDirectory::make();
|
||||
$zip->extractTo($temporaryDirectory->path());
|
||||
$zip->close();
|
||||
app(ZipImportHelper::class)->extract($temporaryDirectoryZip->path('import.zip'), $temporaryDirectory->path());
|
||||
|
||||
if (! file_exists($temporaryDirectory->path('meta.json'))) {
|
||||
throw new ImportException('File "meta.json" missing in ZIP');
|
||||
@@ -205,6 +199,7 @@ class SolidtimeImporter extends DefaultImporter
|
||||
if ($projectId === null) {
|
||||
throw new Exception('Project does not exist');
|
||||
}
|
||||
$this->checkTaskNameLength($task['name']);
|
||||
$this->taskImportHelper->getKey([
|
||||
'name' => $task['name'],
|
||||
'project_id' => $projectId,
|
||||
@@ -255,6 +250,14 @@ class SolidtimeImporter extends DefaultImporter
|
||||
throw new ImportException('Invalid billable value');
|
||||
}
|
||||
$timeEntry->billable = $timeEntryRow['billable'] === 'true';
|
||||
// The type column does not exist in old exports
|
||||
if (($timeEntryRow['type'] ?? '') !== '') {
|
||||
$type = TimeEntryType::tryFrom($timeEntryRow['type']);
|
||||
if ($type === null) {
|
||||
throw new ImportException('Invalid type value');
|
||||
}
|
||||
$timeEntry->type = $type;
|
||||
}
|
||||
$timeEntry->tags = $this->getTags($timeEntryRow['tags']);
|
||||
$timeEntry->is_imported = true;
|
||||
|
||||
|
||||
@@ -13,7 +13,6 @@ use Illuminate\Support\Str;
|
||||
use Override;
|
||||
use Spatie\TemporaryDirectory\TemporaryDirectory;
|
||||
use ValueError;
|
||||
use ZipArchive;
|
||||
|
||||
class TogglDataImporter extends DefaultImporter
|
||||
{
|
||||
@@ -26,16 +25,10 @@ class TogglDataImporter extends DefaultImporter
|
||||
$temporaryDirectoryZip = null;
|
||||
$temporaryDirectory = null;
|
||||
try {
|
||||
$zip = new ZipArchive;
|
||||
$temporaryDirectoryZip = TemporaryDirectory::make();
|
||||
file_put_contents($temporaryDirectoryZip->path('import.zip'), $data);
|
||||
$res = $zip->open($temporaryDirectoryZip->path('import.zip'), ZipArchive::RDONLY);
|
||||
if ($res !== true) {
|
||||
throw new ImportException('Invalid ZIP, error code: '.$res);
|
||||
}
|
||||
$temporaryDirectory = TemporaryDirectory::make();
|
||||
$zip->extractTo($temporaryDirectory->path());
|
||||
$zip->close();
|
||||
app(ZipImportHelper::class)->extract($temporaryDirectoryZip->path('import.zip'), $temporaryDirectory->path());
|
||||
if (! file_exists($temporaryDirectory->path('clients.json'))) {
|
||||
throw new ImportException('File "clients.json" missing in ZIP');
|
||||
}
|
||||
@@ -160,9 +153,16 @@ class TogglDataImporter extends DefaultImporter
|
||||
}
|
||||
foreach ($projectMembers as $projectMember) {
|
||||
$userId = $this->userImportHelper->getKeyByExternalIdentifier((string) $projectMember->user_id);
|
||||
if ($userId === null) {
|
||||
throw new Exception('User does not exist');
|
||||
}
|
||||
$memberId = $this->memberImportHelper->getKeyByExternalIdentifier($userId);
|
||||
if ($memberId === null) {
|
||||
throw new Exception('Member does not exist');
|
||||
}
|
||||
$this->projectMemberImportHelper->getKey([
|
||||
'project_id' => $projectId,
|
||||
'member_id' => $this->memberImportHelper->getKeyByExternalIdentifier($userId),
|
||||
'member_id' => $memberId,
|
||||
], [
|
||||
'user_id' => $userId,
|
||||
'billable_rate' => $projectMember->rate !== null ? (int) ($projectMember->rate * 100) : null,
|
||||
@@ -189,6 +189,7 @@ class TogglDataImporter extends DefaultImporter
|
||||
if ($projectId === null) {
|
||||
throw new Exception('Project does not exist');
|
||||
}
|
||||
$this->checkTaskNameLength($task->name);
|
||||
$this->taskImportHelper->getKey([
|
||||
'name' => $task->name,
|
||||
'project_id' => $projectId,
|
||||
|
||||
@@ -97,6 +97,7 @@ class TogglTimeEntriesImporter extends DefaultImporter
|
||||
}
|
||||
$taskId = null;
|
||||
if ($record['Task'] !== '') {
|
||||
$this->checkTaskNameLength($record['Task']);
|
||||
$taskId = $this->taskImportHelper->getKey([
|
||||
'name' => $record['Task'],
|
||||
'project_id' => $projectId,
|
||||
|
||||
129
app/Service/Import/Importers/ZipImportHelper.php
Normal file
129
app/Service/Import/Importers/ZipImportHelper.php
Normal file
@@ -0,0 +1,129 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Service\Import\Importers;
|
||||
|
||||
use ZipArchive;
|
||||
|
||||
/**
|
||||
* Extracts uploaded ZIP archives with limits on file count, total uncompressed
|
||||
* size and entry paths, so a small malicious archive can not fill the disk
|
||||
* (decompression bomb) or write outside the target directory (zip slip).
|
||||
*/
|
||||
class ZipImportHelper
|
||||
{
|
||||
private const int CHUNK_SIZE = 1024 * 1024;
|
||||
|
||||
/**
|
||||
* @throws ImportException
|
||||
*/
|
||||
public function extract(string $zipPath, string $targetPath): void
|
||||
{
|
||||
$zip = new ZipArchive;
|
||||
$res = $zip->open($zipPath, ZipArchive::RDONLY);
|
||||
if ($res !== true) {
|
||||
throw new ImportException('Invalid ZIP, error code: '.$res);
|
||||
}
|
||||
|
||||
try {
|
||||
$maxFiles = (int) config('import.zip_max_files');
|
||||
$maxUncompressedSize = (int) config('import.zip_max_uncompressed_size');
|
||||
|
||||
if ($zip->numFiles > $maxFiles) {
|
||||
throw new ImportException('ZIP contains too many files, maximum is '.$maxFiles);
|
||||
}
|
||||
|
||||
// Check the sizes declared in the archive before writing anything to disk
|
||||
$declaredSize = 0;
|
||||
for ($index = 0; $index < $zip->numFiles; $index++) {
|
||||
$stat = $zip->statIndex($index);
|
||||
if ($stat === false) {
|
||||
throw new ImportException('Invalid ZIP entry');
|
||||
}
|
||||
$this->validateEntryName($stat['name']);
|
||||
$declaredSize += $stat['size'];
|
||||
if ($declaredSize > $maxUncompressedSize) {
|
||||
throw new ImportException('ZIP uncompressed size exceeds the maximum of '.$maxUncompressedSize.' bytes');
|
||||
}
|
||||
}
|
||||
|
||||
// The declared sizes can be forged, so the written bytes are counted as well
|
||||
$writtenSize = 0;
|
||||
for ($index = 0; $index < $zip->numFiles; $index++) {
|
||||
$stat = $zip->statIndex($index);
|
||||
if ($stat === false) {
|
||||
throw new ImportException('Invalid ZIP entry');
|
||||
}
|
||||
$name = $stat['name'];
|
||||
$entryPath = $targetPath.DIRECTORY_SEPARATOR.$name;
|
||||
|
||||
if (str_ends_with($name, '/')) {
|
||||
$this->ensureDirectoryExists($entryPath);
|
||||
|
||||
continue;
|
||||
}
|
||||
$this->ensureDirectoryExists(dirname($entryPath));
|
||||
|
||||
$stream = $zip->getStreamIndex($index);
|
||||
if ($stream === false) {
|
||||
throw new ImportException('ZIP entry "'.$name.'" can not be read');
|
||||
}
|
||||
$target = fopen($entryPath, 'wb');
|
||||
if ($target === false) {
|
||||
fclose($stream);
|
||||
throw new ImportException('ZIP entry "'.$name.'" can not be extracted');
|
||||
}
|
||||
try {
|
||||
while (! feof($stream)) {
|
||||
$chunk = fread($stream, self::CHUNK_SIZE);
|
||||
if ($chunk === false) {
|
||||
throw new ImportException('ZIP entry "'.$name.'" can not be read');
|
||||
}
|
||||
$writtenSize += strlen($chunk);
|
||||
if ($writtenSize > $maxUncompressedSize) {
|
||||
throw new ImportException('ZIP uncompressed size exceeds the maximum of '.$maxUncompressedSize.' bytes');
|
||||
}
|
||||
fwrite($target, $chunk);
|
||||
}
|
||||
} finally {
|
||||
fclose($target);
|
||||
fclose($stream);
|
||||
}
|
||||
}
|
||||
} finally {
|
||||
$zip->close();
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* @throws ImportException
|
||||
*/
|
||||
private function validateEntryName(string $name): void
|
||||
{
|
||||
if ($name === '' || str_contains($name, "\0") || str_contains($name, '\\') || str_starts_with($name, '/')) {
|
||||
throw new ImportException('ZIP contains an invalid file path: "'.$name.'"');
|
||||
}
|
||||
if (preg_match('/^[a-zA-Z]:/', $name) === 1) {
|
||||
throw new ImportException('ZIP contains an invalid file path: "'.$name.'"');
|
||||
}
|
||||
foreach (explode('/', rtrim($name, '/')) as $segment) {
|
||||
if ($segment === '' || $segment === '..') {
|
||||
throw new ImportException('ZIP contains an invalid file path: "'.$name.'"');
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* @throws ImportException
|
||||
*/
|
||||
private function ensureDirectoryExists(string $path): void
|
||||
{
|
||||
if (is_dir($path)) {
|
||||
return;
|
||||
}
|
||||
if (! mkdir($path, 0700, true) && ! is_dir($path)) {
|
||||
throw new ImportException('Directory "'.$path.'" can not be created');
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -18,11 +18,31 @@ use Illuminate\Support\Facades\Mail;
|
||||
|
||||
class InvitationService
|
||||
{
|
||||
public function hasAcceptedInvitationForEmail(string $email): bool
|
||||
{
|
||||
return OrganizationInvitation::query()
|
||||
->whereRaw('lower(email) = ?', [strtolower($email)])
|
||||
->whereNotNull('accepted_at')
|
||||
->exists();
|
||||
}
|
||||
|
||||
public function hasPendingInvitationForEmail(string $email): bool
|
||||
{
|
||||
return OrganizationInvitation::query()
|
||||
->whereRaw('lower(email) = ?', [strtolower($email)])
|
||||
->whereNull('accepted_at')
|
||||
->exists();
|
||||
}
|
||||
|
||||
/**
|
||||
* @throws UserIsAlreadyMemberOfOrganizationApiException|InvitationForTheEmailAlreadyExistsApiException
|
||||
*/
|
||||
public function inviteUser(Organization $organization, string $email, Role $role, User $inviter): OrganizationInvitation
|
||||
{
|
||||
// Normalize the email so it matches how user emails are stored (see UserService::createUser),
|
||||
// otherwise a mixed-case invite silently fails to link on registration.
|
||||
$email = strtolower($email);
|
||||
|
||||
if (app(MemberService::class)->isEmailAlreadyMember($organization, $email)) {
|
||||
throw new UserIsAlreadyMemberOfOrganizationApiException;
|
||||
}
|
||||
@@ -55,7 +75,7 @@ class InvitationService
|
||||
$organizations = new Collection;
|
||||
|
||||
$invitations = OrganizationInvitation::query()
|
||||
->where('email', $user->email)
|
||||
->whereRaw('lower(email) = ?', [strtolower($user->email)])
|
||||
->whereNotNull('accepted_at')
|
||||
->get();
|
||||
|
||||
|
||||
@@ -8,12 +8,14 @@ use App\Enums\CurrencyFormat;
|
||||
use App\Enums\DateFormat;
|
||||
use App\Enums\IntervalFormat;
|
||||
use App\Enums\NumberFormat;
|
||||
use App\Enums\TimeEntryAggregationType;
|
||||
use App\Enums\TimeFormat;
|
||||
use App\Models\Organization;
|
||||
use Brick\Math\BigDecimal;
|
||||
use Brick\Money\Money;
|
||||
use Carbon\CarbonInterface;
|
||||
use Carbon\CarbonInterval;
|
||||
use Illuminate\Support\Carbon;
|
||||
|
||||
class LocalizationService
|
||||
{
|
||||
@@ -152,6 +154,38 @@ class LocalizationService
|
||||
return $date->format($this->dateFormat->toCarbonFormat());
|
||||
}
|
||||
|
||||
/**
|
||||
* Time group types have no server-side descriptor; their keys are ISO dates and are
|
||||
* formatted here instead. A Week key is the first day of that week, so it renders as the
|
||||
* range it covers. A Year key is already a bare year, so it is returned unchanged - it must
|
||||
* not be parsed, Carbon reads a four digit string as a time of day.
|
||||
*/
|
||||
public function formatTimeGroupKey(?string $key, TimeEntryAggregationType $groupType): ?string
|
||||
{
|
||||
if ($key === null) {
|
||||
return null;
|
||||
}
|
||||
|
||||
if ($groupType === TimeEntryAggregationType::Day) {
|
||||
return $this->formatDate(Carbon::parse($key));
|
||||
}
|
||||
|
||||
if ($groupType === TimeEntryAggregationType::Week) {
|
||||
$weekStart = Carbon::parse($key);
|
||||
|
||||
return $this->formatDate($weekStart).' - '.$this->formatDate($weekStart->copy()->addDays(6));
|
||||
}
|
||||
|
||||
if ($groupType === TimeEntryAggregationType::Month) {
|
||||
// Note: the leading "!" resets all fields the format does not name. Without it the
|
||||
// day of the month is taken from today, and a day that the parsed month does not
|
||||
// have overflows the date into the next month.
|
||||
return Carbon::createFromFormat('!Y-m', $key)->format('F Y');
|
||||
}
|
||||
|
||||
return $key;
|
||||
}
|
||||
|
||||
public function setDateFormat(DateFormat $dateFormat): void
|
||||
{
|
||||
$this->dateFormat = $dateFormat;
|
||||
|
||||
@@ -218,7 +218,16 @@ class MemberService
|
||||
|
||||
$placeholderUser = $user->replicate();
|
||||
$placeholderUser->is_placeholder = true;
|
||||
$placeholderUser->current_team_id = $member->organization_id;
|
||||
// Reset authentication relevant properties on the placeholder user
|
||||
$placeholderUser->password = null;
|
||||
$placeholderUser->remember_token = null;
|
||||
$placeholderUser->two_factor_secret = null;
|
||||
$placeholderUser->two_factor_recovery_codes = null;
|
||||
$placeholderUser->two_factor_confirmed_at = null;
|
||||
$placeholderUser->email_verified_at = null;
|
||||
$placeholderUser->pending_email = null;
|
||||
$placeholderUser->current_team_id = null;
|
||||
$placeholderUser->profile_photo_path = null;
|
||||
$placeholderUser->save();
|
||||
|
||||
$member->user()->associate($placeholderUser);
|
||||
|
||||
@@ -80,6 +80,10 @@ class PermissionStore
|
||||
'invoices:update',
|
||||
'invoices:download',
|
||||
'invoices:delete',
|
||||
'invoice-recipients:view',
|
||||
'invoice-recipients:create',
|
||||
'invoice-recipients:update',
|
||||
'invoice-recipients:delete',
|
||||
'invoice-settings:view',
|
||||
'invoice-settings:update',
|
||||
],
|
||||
@@ -147,6 +151,10 @@ class PermissionStore
|
||||
'invoices:update',
|
||||
'invoices:download',
|
||||
'invoices:delete',
|
||||
'invoice-recipients:view',
|
||||
'invoice-recipients:create',
|
||||
'invoice-recipients:update',
|
||||
'invoice-recipients:delete',
|
||||
'invoice-settings:view',
|
||||
'invoice-settings:update',
|
||||
],
|
||||
@@ -203,6 +211,10 @@ class PermissionStore
|
||||
'invoices:update',
|
||||
'invoices:download',
|
||||
'invoices:delete',
|
||||
'invoice-recipients:view',
|
||||
'invoice-recipients:create',
|
||||
'invoice-recipients:update',
|
||||
'invoice-recipients:delete',
|
||||
'invoice-settings:view',
|
||||
'invoice-settings:update',
|
||||
],
|
||||
|
||||
@@ -4,6 +4,7 @@ declare(strict_types=1);
|
||||
|
||||
namespace App\Service\ReportExport;
|
||||
|
||||
use App\Enums\TimeEntryType;
|
||||
use App\Models\TimeEntry;
|
||||
use App\Service\IntervalService;
|
||||
use Illuminate\Database\Eloquent\Builder;
|
||||
@@ -25,6 +26,7 @@ class TimeEntriesDetailedCsvExport extends CsvExport
|
||||
'Duration',
|
||||
'Duration (decimal)',
|
||||
'Billable',
|
||||
'Break',
|
||||
'Tags',
|
||||
];
|
||||
|
||||
@@ -58,6 +60,7 @@ class TimeEntriesDetailedCsvExport extends CsvExport
|
||||
'Duration' => $duration !== null ? $interval->format($model->getDuration()) : null,
|
||||
'Duration (decimal)' => $duration?->totalHours,
|
||||
'Billable' => $model->billable ? 'Yes' : 'No',
|
||||
'Break' => $model->type === TimeEntryType::Break ? 'Yes' : 'No',
|
||||
'Tags' => $model->tagsRelation->pluck('name')->implode(', '),
|
||||
];
|
||||
}
|
||||
|
||||
@@ -5,6 +5,7 @@ declare(strict_types=1);
|
||||
namespace App\Service\ReportExport;
|
||||
|
||||
use App\Enums\ExportFormat;
|
||||
use App\Enums\TimeEntryType;
|
||||
use App\Models\TimeEntry;
|
||||
use App\Service\LocalizationService;
|
||||
use Illuminate\Database\Eloquent\Builder;
|
||||
@@ -106,6 +107,7 @@ class TimeEntriesDetailedExport implements FromQuery, ShouldAutoSize, WithColumn
|
||||
'Duration',
|
||||
'Duration (decimal)',
|
||||
'Billable',
|
||||
'Break',
|
||||
'Tags',
|
||||
];
|
||||
}
|
||||
@@ -130,6 +132,7 @@ class TimeEntriesDetailedExport implements FromQuery, ShouldAutoSize, WithColumn
|
||||
$duration !== null ? $this->localizationService->formatInterval($duration) : null,
|
||||
$duration?->totalHours,
|
||||
$model->billable ? 'Yes' : 'No',
|
||||
$model->type === TimeEntryType::Break ? 'Yes' : 'No',
|
||||
$model->tagsRelation->pluck('name')->implode(', '),
|
||||
];
|
||||
} elseif ($this->exportFormat === ExportFormat::ODS) {
|
||||
@@ -144,6 +147,7 @@ class TimeEntriesDetailedExport implements FromQuery, ShouldAutoSize, WithColumn
|
||||
$duration !== null ? $this->localizationService->formatInterval($duration) : null,
|
||||
$duration?->totalHours,
|
||||
$model->billable ? 'Yes' : 'No',
|
||||
$model->type === TimeEntryType::Break ? 'Yes' : 'No',
|
||||
$model->tagsRelation->pluck('name')->implode(', '),
|
||||
];
|
||||
} else {
|
||||
|
||||
@@ -6,6 +6,7 @@ namespace App\Service\ReportExport;
|
||||
|
||||
use App\Enums\ExportFormat;
|
||||
use App\Enums\TimeEntryAggregationType;
|
||||
use App\Service\LocalizationService;
|
||||
use Illuminate\View\View;
|
||||
use Maatwebsite\Excel\Concerns\Exportable;
|
||||
use Maatwebsite\Excel\Concerns\FromView;
|
||||
@@ -48,6 +49,8 @@ class TimeEntriesReportExport implements FromView, ShouldAutoSize, WithCustomCsv
|
||||
|
||||
private bool $showBillableRate;
|
||||
|
||||
private LocalizationService $localization;
|
||||
|
||||
/**
|
||||
* @param array{
|
||||
* grouped_type: string|null,
|
||||
@@ -68,7 +71,7 @@ class TimeEntriesReportExport implements FromView, ShouldAutoSize, WithCustomCsv
|
||||
* cost: int|null
|
||||
* } $data
|
||||
*/
|
||||
public function __construct(array $data, ExportFormat $exportFormat, string $currency, TimeEntryAggregationType $group, TimeEntryAggregationType $subGroup, bool $showBillableRate)
|
||||
public function __construct(array $data, ExportFormat $exportFormat, string $currency, TimeEntryAggregationType $group, TimeEntryAggregationType $subGroup, bool $showBillableRate, LocalizationService $localization)
|
||||
{
|
||||
$this->data = $data;
|
||||
$this->exportFormat = $exportFormat;
|
||||
@@ -76,6 +79,7 @@ class TimeEntriesReportExport implements FromView, ShouldAutoSize, WithCustomCsv
|
||||
$this->group = $group;
|
||||
$this->subGroup = $subGroup;
|
||||
$this->showBillableRate = $showBillableRate;
|
||||
$this->localization = $localization;
|
||||
}
|
||||
|
||||
public function view(): View
|
||||
@@ -87,6 +91,7 @@ class TimeEntriesReportExport implements FromView, ShouldAutoSize, WithCustomCsv
|
||||
'subGroup' => $this->subGroup,
|
||||
'exportFormat' => $this->exportFormat,
|
||||
'showBillableRate' => $this->showBillableRate,
|
||||
'localization' => $this->localization,
|
||||
]);
|
||||
}
|
||||
|
||||
|
||||
@@ -353,6 +353,13 @@ class TimeEntryAggregationService
|
||||
'color' => null,
|
||||
];
|
||||
}
|
||||
} elseif ($type === TimeEntryAggregationType::Type) {
|
||||
foreach ($keys as $key) {
|
||||
$descriptorMap[$key] = [
|
||||
'description' => $key === 'break' ? 'Break' : 'Work time',
|
||||
'color' => null,
|
||||
];
|
||||
}
|
||||
} elseif ($type === TimeEntryAggregationType::Tag) {
|
||||
$tags = Tag::query()
|
||||
->whereIn('id', $keys)
|
||||
@@ -504,6 +511,8 @@ class TimeEntryAggregationService
|
||||
return 'client_id';
|
||||
} elseif ($group === TimeEntryAggregationType::Billable) {
|
||||
return 'billable';
|
||||
} elseif ($group === TimeEntryAggregationType::Type) {
|
||||
return 'type';
|
||||
} elseif ($group === TimeEntryAggregationType::Description) {
|
||||
return 'description';
|
||||
} elseif ($group === TimeEntryAggregationType::Tag) {
|
||||
|
||||
@@ -5,6 +5,7 @@ declare(strict_types=1);
|
||||
namespace App\Service;
|
||||
|
||||
use App\Enums\TagMatchType;
|
||||
use App\Enums\TimeEntryType;
|
||||
use App\Models\Member;
|
||||
use App\Models\TimeEntry;
|
||||
use Illuminate\Database\Eloquent\Builder;
|
||||
@@ -144,6 +145,32 @@ class TimeEntryFilter
|
||||
return $this;
|
||||
}
|
||||
|
||||
public function addTypeFilter(?string $type): self
|
||||
{
|
||||
if ($type === null) {
|
||||
return $this;
|
||||
}
|
||||
$typeEnum = TimeEntryType::tryFrom($type);
|
||||
if ($typeEnum === null) {
|
||||
Log::warning('Invalid type filter value', ['value' => $type]);
|
||||
|
||||
return $this;
|
||||
}
|
||||
$this->addType($typeEnum);
|
||||
|
||||
return $this;
|
||||
}
|
||||
|
||||
public function addType(?TimeEntryType $type): self
|
||||
{
|
||||
if ($type === null) {
|
||||
return $this;
|
||||
}
|
||||
$this->builder->where('type', '=', $type->value);
|
||||
|
||||
return $this;
|
||||
}
|
||||
|
||||
/**
|
||||
* @param array<string>|null $clientIds
|
||||
*/
|
||||
|
||||
@@ -75,11 +75,32 @@ return [
|
||||
|
||||
'url' => env('APP_URL', 'http://localhost'),
|
||||
|
||||
/*
|
||||
|--------------------------------------------------------------------------
|
||||
| Trusted Hosts
|
||||
|--------------------------------------------------------------------------
|
||||
|
|
||||
| Additional hostnames (besides the APP_URL host and its subdomains) that
|
||||
| the application is allowed to respond on. This is needed for multi-host
|
||||
| setups, e.g. reaching the instance over both a public domain and a
|
||||
| Tailscale name. A request arriving on any host that is neither APP_URL
|
||||
| (nor a subdomain of it) nor listed here is rejected, which prevents
|
||||
| Host-header poisoning of password reset and other out-of-band links.
|
||||
|
|
||||
| See App\Http\Middleware\TrustHosts.
|
||||
|
|
||||
*/
|
||||
|
||||
'trusted_hosts' => array_values(array_filter(array_map(
|
||||
'trim',
|
||||
explode(',', (string) env('TRUSTED_HOSTS', ''))
|
||||
))),
|
||||
|
||||
'asset_url' => env('ASSET_URL'),
|
||||
|
||||
'force_https' => (bool) env('APP_FORCE_HTTPS', false),
|
||||
|
||||
'enable_registration' => (bool) env('APP_ENABLE_REGISTRATION', false),
|
||||
'enable_registration' => env('APP_ENABLE_REGISTRATION', 'off'),
|
||||
|
||||
'local_email_verification' => (bool) env('APP_LOCAL_EMAIL_VERIFICATION', false),
|
||||
|
||||
@@ -137,6 +158,21 @@ return [
|
||||
|
||||
'pagination_per_page_default' => (int) env('PAGINATION_PER_PAGE_DEFAULT', 15),
|
||||
|
||||
/*
|
||||
|--------------------------------------------------------------------------
|
||||
| API Rate Limiting
|
||||
|--------------------------------------------------------------------------
|
||||
|
|
||||
| The number of API requests allowed per minute, counted per user for
|
||||
| authenticated requests and per IP address for guest requests. These
|
||||
| limits are only enforced when the application runs in production.
|
||||
|
|
||||
*/
|
||||
|
||||
'api_rate_limit_authenticated_per_minute' => (int) (env('API_RATE_LIMIT_AUTH_PER_MINUTE') ?: 200),
|
||||
|
||||
'api_rate_limit_guest_per_minute' => (int) (env('API_RATE_LIMIT_GUEST_PER_MINUTE') ?: 60),
|
||||
|
||||
/*
|
||||
|--------------------------------------------------------------------------
|
||||
| Encryption Key
|
||||
|
||||
34
config/import.php
Normal file
34
config/import.php
Normal file
@@ -0,0 +1,34 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
return [
|
||||
|
||||
/*
|
||||
|--------------------------------------------------------------------------
|
||||
| Import payload limit
|
||||
|--------------------------------------------------------------------------
|
||||
|
|
||||
| Maximum length of the base64 encoded "data" field of an import request in
|
||||
| bytes. Requests with a larger payload are rejected with a validation error.
|
||||
|
|
||||
*/
|
||||
|
||||
'max_data_size' => (int) (env('IMPORT_MAX_DATA_SIZE') ?: 50 * 1024 * 1024),
|
||||
|
||||
/*
|
||||
|--------------------------------------------------------------------------
|
||||
| ZIP extraction limits
|
||||
|--------------------------------------------------------------------------
|
||||
|
|
||||
| Limits applied to ZIP based importers before and during extraction to
|
||||
| protect the instance against decompression bombs. The uncompressed size
|
||||
| is the sum of all files in the archive in bytes.
|
||||
|
|
||||
*/
|
||||
|
||||
'zip_max_files' => (int) (env('IMPORT_ZIP_MAX_FILES') ?: 100),
|
||||
|
||||
'zip_max_uncompressed_size' => (int) (env('IMPORT_ZIP_MAX_UNCOMPRESSED_SIZE') ?: 500 * 1024 * 1024),
|
||||
|
||||
];
|
||||
@@ -33,6 +33,7 @@ class OrganizationFactory extends Factory
|
||||
'user_id' => User::factory(),
|
||||
'personal_team' => true,
|
||||
'employees_can_see_billable_rates' => false,
|
||||
'breaks_enabled' => false,
|
||||
'number_format' => $this->faker->randomElement(NumberFormat::values()),
|
||||
'currency_format' => $this->faker->randomElement(CurrencyFormat::values()),
|
||||
'date_format' => $this->faker->randomElement(DateFormat::values()),
|
||||
@@ -55,6 +56,13 @@ class OrganizationFactory extends Factory
|
||||
]);
|
||||
}
|
||||
|
||||
public function withBreaksEnabled(): self
|
||||
{
|
||||
return $this->state(fn (array $attributes) => [
|
||||
'breaks_enabled' => true,
|
||||
]);
|
||||
}
|
||||
|
||||
public function withOwner(?User $owner = null): self
|
||||
{
|
||||
return $this->state(fn (array $attributes) => [
|
||||
|
||||
@@ -4,6 +4,7 @@ declare(strict_types=1);
|
||||
|
||||
namespace Database\Factories;
|
||||
|
||||
use App\Enums\TimeEntryType;
|
||||
use App\Models\Member;
|
||||
use App\Models\Organization;
|
||||
use App\Models\Project;
|
||||
@@ -33,6 +34,7 @@ class TimeEntryFactory extends Factory
|
||||
'start' => $start,
|
||||
'end' => $this->faker->dateTimeBetween($start, 'now'),
|
||||
'billable' => $this->faker->boolean(),
|
||||
'type' => TimeEntryType::Work,
|
||||
'is_imported' => false,
|
||||
'tags' => [],
|
||||
'user_id' => User::factory(),
|
||||
@@ -44,6 +46,18 @@ class TimeEntryFactory extends Factory
|
||||
];
|
||||
}
|
||||
|
||||
public function isBreak(): self
|
||||
{
|
||||
return $this->state(function (array $attributes): array {
|
||||
return [
|
||||
'type' => TimeEntryType::Break,
|
||||
'billable' => false,
|
||||
'project_id' => null,
|
||||
'task_id' => null,
|
||||
];
|
||||
});
|
||||
}
|
||||
|
||||
public function notBillable(): self
|
||||
{
|
||||
return $this->state(function (array $attributes): array {
|
||||
|
||||
@@ -0,0 +1,24 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
use Illuminate\Database\Migrations\Migration;
|
||||
use Illuminate\Database\Schema\Blueprint;
|
||||
use Illuminate\Support\Facades\Schema;
|
||||
|
||||
return new class extends Migration
|
||||
{
|
||||
public function up(): void
|
||||
{
|
||||
Schema::table('time_entries', function (Blueprint $table): void {
|
||||
$table->string('type')->default('work');
|
||||
});
|
||||
}
|
||||
|
||||
public function down(): void
|
||||
{
|
||||
Schema::table('time_entries', function (Blueprint $table): void {
|
||||
$table->dropColumn('type');
|
||||
});
|
||||
}
|
||||
};
|
||||
@@ -0,0 +1,24 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
use Illuminate\Database\Migrations\Migration;
|
||||
use Illuminate\Database\Schema\Blueprint;
|
||||
use Illuminate\Support\Facades\Schema;
|
||||
|
||||
return new class extends Migration
|
||||
{
|
||||
public function up(): void
|
||||
{
|
||||
Schema::table('organizations', function (Blueprint $table): void {
|
||||
$table->boolean('breaks_enabled')->default(false)->after('prevent_overlapping_time_entries');
|
||||
});
|
||||
}
|
||||
|
||||
public function down(): void
|
||||
{
|
||||
Schema::table('organizations', function (Blueprint $table): void {
|
||||
$table->dropColumn('breaks_enabled');
|
||||
});
|
||||
}
|
||||
};
|
||||
@@ -0,0 +1,230 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
use Illuminate\Database\Migrations\Migration;
|
||||
use Illuminate\Support\Facades\DB;
|
||||
use Illuminate\Support\Facades\Log;
|
||||
|
||||
use function Laravel\Prompts\info as consoleInfo;
|
||||
|
||||
return new class extends Migration
|
||||
{
|
||||
/**
|
||||
* PostgreSQL cannot build or drop an index concurrently inside a transaction.
|
||||
* Keeping this migration non-transactional prevents long write locks in production.
|
||||
*
|
||||
* @var bool
|
||||
*/
|
||||
public $withinTransaction = false;
|
||||
|
||||
/**
|
||||
* Run the migrations.
|
||||
*/
|
||||
public function up(): void
|
||||
{
|
||||
// Tenant-scoped client pagination ordered by newest first; also covers the organization FK.
|
||||
$this->runIndexOperation('create', 'clients_organization_created_id_index', 'CREATE INDEX CONCURRENTLY clients_organization_created_id_index ON clients (organization_id, created_at DESC, id)');
|
||||
|
||||
// Tenant-scoped project pagination ordered by newest first; also covers the organization FK.
|
||||
$this->runIndexOperation('create', 'projects_organization_created_id_index', 'CREATE INDEX CONCURRENTLY projects_organization_created_id_index ON projects (organization_id, created_at DESC, id)');
|
||||
// Speeds client relationship loads and the FK check when a client is deleted or its ID changes.
|
||||
$this->runIndexOperation('create', 'projects_client_id_index', 'CREATE INDEX CONCURRENTLY projects_client_id_index ON projects (client_id)');
|
||||
|
||||
// Tenant-scoped task pagination ordered by newest first; also covers the organization FK.
|
||||
$this->runIndexOperation('create', 'tasks_organization_created_id_index', 'CREATE INDEX CONCURRENTLY tasks_organization_created_id_index ON tasks (organization_id, created_at DESC, id)');
|
||||
// Speeds project task lists and the FK check when a project is deleted or its ID changes.
|
||||
$this->runIndexOperation('create', 'tasks_project_id_index', 'CREATE INDEX CONCURRENTLY tasks_project_id_index ON tasks (project_id)');
|
||||
|
||||
// Tenant-scoped tag pagination ordered by newest first; also covers the organization FK.
|
||||
$this->runIndexOperation('create', 'tags_organization_created_id_index', 'CREATE INDEX CONCURRENTLY tags_organization_created_id_index ON tags (organization_id, created_at DESC, id)');
|
||||
|
||||
// Tenant-scoped report pagination ordered by newest first; also covers the organization FK.
|
||||
$this->runIndexOperation('create', 'reports_organization_created_id_index', 'CREATE INDEX CONCURRENTLY reports_organization_created_id_index ON reports (organization_id, created_at DESC, id)');
|
||||
|
||||
// Tenant-scoped member pagination; the existing (organization_id, user_id) unique index remains for membership lookup.
|
||||
$this->runIndexOperation('create', 'members_organization_created_id_index', 'CREATE INDEX CONCURRENTLY members_organization_created_id_index ON members (organization_id, created_at DESC, id)');
|
||||
// Supports reverse user-to-membership lookups and the FK check when a user is deleted or its ID changes.
|
||||
$this->runIndexOperation('create', 'members_user_id_index', 'CREATE INDEX CONCURRENTLY members_user_id_index ON members (user_id)');
|
||||
|
||||
// The existing (project_id, user_id) unique index covers project_id, but member_id and legacy user_id need reverse indexes.
|
||||
$this->runIndexOperation('create', 'project_members_member_id_index', 'CREATE INDEX CONCURRENTLY project_members_member_id_index ON project_members (member_id)');
|
||||
$this->runIndexOperation('create', 'project_members_user_id_index', 'CREATE INDEX CONCURRENTLY project_members_user_id_index ON project_members (user_id)');
|
||||
|
||||
// Supports organization deletion/current-team cleanup and the FK check on users.current_team_id.
|
||||
$this->runIndexOperation('create', 'users_current_team_id_index', 'CREATE INDEX CONCURRENTLY users_current_team_id_index ON users (current_team_id)');
|
||||
|
||||
// Filament loads the newest audits first; this avoids scanning and sorting the large append-only audit table.
|
||||
$this->runIndexOperation('create', 'audits_created_at_index', 'CREATE INDEX CONCURRENTLY audits_created_at_index ON audits (created_at DESC)');
|
||||
|
||||
// Main tenant time-entry range/pagination path, including its start DESC, id ordering; also covers the organization FK.
|
||||
$this->runIndexOperation('create', 'time_entries_organization_start_id_index', 'CREATE INDEX CONCURRENTLY time_entries_organization_start_id_index ON time_entries (organization_id, start DESC, id)');
|
||||
// Filament lists time entries globally by creation time, so the tenant-prefixed index cannot provide this ordering.
|
||||
$this->runIndexOperation('create', 'time_entries_created_at_index', 'CREATE INDEX CONCURRENTLY time_entries_created_at_index ON time_entries (created_at DESC)');
|
||||
// Dashboard history is consistently filtered by user and organization, then bounded by start; user first also covers its FK.
|
||||
$this->runIndexOperation('create', 'time_entries_user_organization_start_index', 'CREATE INDEX CONCURRENTLY time_entries_user_organization_start_index ON time_entries (user_id, organization_id, start)');
|
||||
// Member timelines, overlap checks, and billable-rate updates start with member_id; also covers its FK.
|
||||
$this->runIndexOperation('create', 'time_entries_member_start_index', 'CREATE INDEX CONCURRENTLY time_entries_member_start_index ON time_entries (member_id, start)');
|
||||
// These relationship/filter indexes also prevent full scans for FK checks when parent rows change or are deleted.
|
||||
$this->runIndexOperation('create', 'time_entries_project_id_index', 'CREATE INDEX CONCURRENTLY time_entries_project_id_index ON time_entries (project_id)');
|
||||
$this->runIndexOperation('create', 'time_entries_task_id_index', 'CREATE INDEX CONCURRENTLY time_entries_task_id_index ON time_entries (task_id)');
|
||||
$this->runIndexOperation('create', 'time_entries_client_id_index', 'CREATE INDEX CONCURRENTLY time_entries_client_id_index ON time_entries (client_id)');
|
||||
// Active-timer checks touch only open entries, so a partial index stays small while serving the hot member_id lookup.
|
||||
$this->runIndexOperation('create', 'time_entries_active_member_index', 'CREATE INDEX CONCURRENTLY time_entries_active_member_index ON time_entries (member_id) WHERE "end" IS NULL');
|
||||
// whereJsonContains(tags, tag_id) compiles to JSONB containment, which is supported by a GIN index.
|
||||
$this->runIndexOperation('create', 'time_entries_tags_gin_index', 'CREATE INDEX CONCURRENTLY time_entries_tags_gin_index ON time_entries USING GIN (tags)');
|
||||
|
||||
// Passport already indexes user_id; these indexes cover the other FK used during OAuth client deletion/update.
|
||||
$this->runIndexOperation('create', 'oauth_access_tokens_client_id_index', 'CREATE INDEX CONCURRENTLY oauth_access_tokens_client_id_index ON oauth_access_tokens (client_id)');
|
||||
$this->runIndexOperation('create', 'oauth_auth_codes_client_id_index', 'CREATE INDEX CONCURRENTLY oauth_auth_codes_client_id_index ON oauth_auth_codes (client_id)');
|
||||
|
||||
// owner_id is already the leading column of oauth_clients_owner_id_owner_type_index.
|
||||
$this->runIndexOperation('drop', 'oauth_clients_user_id_index', 'DROP INDEX CONCURRENTLY oauth_clients_user_id_index');
|
||||
// Public report lookup starts with the unique share_secret index; no query filters only by this boolean.
|
||||
$this->runIndexOperation('drop', 'reports_is_public_index', 'DROP INDEX CONCURRENTLY reports_is_public_index');
|
||||
}
|
||||
|
||||
/**
|
||||
* Reverse the migrations.
|
||||
*/
|
||||
public function down(): void
|
||||
{
|
||||
$indexes = [
|
||||
'clients_organization_created_id_index',
|
||||
'projects_organization_created_id_index',
|
||||
'projects_client_id_index',
|
||||
'tasks_organization_created_id_index',
|
||||
'tasks_project_id_index',
|
||||
'tags_organization_created_id_index',
|
||||
'reports_organization_created_id_index',
|
||||
'members_organization_created_id_index',
|
||||
'members_user_id_index',
|
||||
'project_members_member_id_index',
|
||||
'project_members_user_id_index',
|
||||
'users_current_team_id_index',
|
||||
'audits_created_at_index',
|
||||
'time_entries_organization_start_id_index',
|
||||
'time_entries_created_at_index',
|
||||
'time_entries_user_organization_start_index',
|
||||
'time_entries_member_start_index',
|
||||
'time_entries_project_id_index',
|
||||
'time_entries_task_id_index',
|
||||
'time_entries_client_id_index',
|
||||
'time_entries_active_member_index',
|
||||
'time_entries_tags_gin_index',
|
||||
'oauth_access_tokens_client_id_index',
|
||||
'oauth_auth_codes_client_id_index',
|
||||
];
|
||||
|
||||
$concurrently = DB::transactionLevel() === 0 ? ' CONCURRENTLY' : '';
|
||||
foreach ($indexes as $index) {
|
||||
$this->runIndexOperation('drop', $index, 'DROP INDEX'.$concurrently.' IF EXISTS '.$index);
|
||||
}
|
||||
|
||||
$this->runIndexOperation('create', 'oauth_clients_user_id_index', 'CREATE INDEX'.$concurrently.' oauth_clients_user_id_index ON oauth_clients (owner_id)');
|
||||
$this->runIndexOperation('create', 'reports_is_public_index', 'CREATE INDEX'.$concurrently.' reports_is_public_index ON reports (is_public)');
|
||||
}
|
||||
|
||||
private function runIndexOperation(string $operation, string $index, string $statement): void
|
||||
{
|
||||
$indexState = $this->indexState($index);
|
||||
|
||||
if ($operation === 'create' && $indexState === ['valid' => true, 'ready' => true]) {
|
||||
$this->writeProgress(sprintf('Skipping index [%s] because it already exists and is valid', $index));
|
||||
|
||||
return;
|
||||
}
|
||||
|
||||
if ($operation === 'drop' && $indexState === null) {
|
||||
$this->writeProgress(sprintf('Skipping index [%s] because it does not exist', $index));
|
||||
|
||||
return;
|
||||
}
|
||||
|
||||
if ($operation === 'create' && $indexState !== null) {
|
||||
$this->writeProgress(sprintf(
|
||||
'Index [%s] exists but is incomplete (valid=%s, ready=%s); dropping it before rebuilding',
|
||||
$index,
|
||||
$indexState['valid'] ? 'true' : 'false',
|
||||
$indexState['ready'] ? 'true' : 'false',
|
||||
));
|
||||
$this->executeIndexStatement(
|
||||
'drop incomplete',
|
||||
$index,
|
||||
(DB::transactionLevel() === 0 ? 'DROP INDEX CONCURRENTLY ' : 'DROP INDEX ').$this->quoteIdentifier($index),
|
||||
);
|
||||
}
|
||||
|
||||
$this->executeIndexStatement($operation, $index, $statement);
|
||||
}
|
||||
|
||||
private function executeIndexStatement(string $operation, string $index, string $statement): void
|
||||
{
|
||||
$startedAt = microtime(true);
|
||||
$this->writeProgress(sprintf('Starting to %s index [%s]', $operation, $index));
|
||||
|
||||
try {
|
||||
DB::statement($statement);
|
||||
} catch (Throwable $exception) {
|
||||
$this->writeProgress(sprintf(
|
||||
'Failed to %s index [%s] after %.2f seconds: %s',
|
||||
$operation,
|
||||
$index,
|
||||
microtime(true) - $startedAt,
|
||||
$exception->getMessage(),
|
||||
));
|
||||
|
||||
throw $exception;
|
||||
}
|
||||
|
||||
$this->writeProgress(sprintf(
|
||||
'Finished %s index [%s] in %.2f seconds',
|
||||
$operation === 'create' ? 'creating' : 'dropping',
|
||||
$index,
|
||||
microtime(true) - $startedAt,
|
||||
));
|
||||
}
|
||||
|
||||
/**
|
||||
* @return array{valid: bool, ready: bool}|null
|
||||
*/
|
||||
private function indexState(string $index): ?array
|
||||
{
|
||||
$state = DB::selectOne(
|
||||
<<<'SQL'
|
||||
SELECT pg_index.indisvalid::int AS valid, pg_index.indisready::int AS ready
|
||||
FROM pg_index
|
||||
JOIN pg_class ON pg_class.oid = pg_index.indexrelid
|
||||
JOIN pg_namespace ON pg_namespace.oid = pg_class.relnamespace
|
||||
WHERE pg_namespace.nspname = current_schema()
|
||||
AND pg_class.relname = ?
|
||||
SQL,
|
||||
[$index],
|
||||
);
|
||||
|
||||
if ($state === null) {
|
||||
return null;
|
||||
}
|
||||
|
||||
return [
|
||||
'valid' => (bool) $state->valid,
|
||||
'ready' => (bool) $state->ready,
|
||||
];
|
||||
}
|
||||
|
||||
private function quoteIdentifier(string $identifier): string
|
||||
{
|
||||
return DB::connection()->getQueryGrammar()->wrap($identifier);
|
||||
}
|
||||
|
||||
private function writeProgress(string $message): void
|
||||
{
|
||||
if (app()->runningUnitTests()) {
|
||||
return;
|
||||
}
|
||||
|
||||
$message = sprintf('[%s] %s', date(DATE_ATOM), $message);
|
||||
Log::info($message);
|
||||
consoleInfo($message);
|
||||
}
|
||||
};
|
||||
@@ -0,0 +1,24 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
use Illuminate\Database\Migrations\Migration;
|
||||
use Illuminate\Database\Schema\Blueprint;
|
||||
use Illuminate\Support\Facades\Schema;
|
||||
|
||||
return new class extends Migration
|
||||
{
|
||||
public function up(): void
|
||||
{
|
||||
Schema::table('users', function (Blueprint $table): void {
|
||||
$table->boolean('send_time_entry_still_running_email')->default(true)->after('week_start');
|
||||
});
|
||||
}
|
||||
|
||||
public function down(): void
|
||||
{
|
||||
Schema::table('users', function (Blueprint $table): void {
|
||||
$table->dropColumn('send_time_entry_still_running_email');
|
||||
});
|
||||
}
|
||||
};
|
||||
@@ -0,0 +1,53 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
use Illuminate\Database\Migrations\Migration;
|
||||
use Illuminate\Database\Query\Builder;
|
||||
use Illuminate\Support\Facades\DB;
|
||||
|
||||
return new class extends Migration
|
||||
{
|
||||
/**
|
||||
* Placeholder users used to be created as a full copy of the user they were made from,
|
||||
* which included the credentials and the account state of that user. A placeholder is a
|
||||
* stand-in for a person in one organization, not an account, and the row shares the email
|
||||
* address with the real account, so these values are removed from the placeholders that
|
||||
* already exist. The organization a placeholder belongs to is recorded on its member row.
|
||||
*/
|
||||
public function up(): void
|
||||
{
|
||||
DB::table('users')
|
||||
->where('is_placeholder', '=', true)
|
||||
->where(function (Builder $builder): void {
|
||||
$builder->whereNotNull('password')
|
||||
->orWhereNotNull('remember_token')
|
||||
->orWhereNotNull('two_factor_secret')
|
||||
->orWhereNotNull('two_factor_recovery_codes')
|
||||
->orWhereNotNull('two_factor_confirmed_at')
|
||||
->orWhereNotNull('email_verified_at')
|
||||
->orWhereNotNull('pending_email')
|
||||
->orWhereNotNull('current_team_id')
|
||||
->orWhereNotNull('profile_photo_path');
|
||||
})
|
||||
->update([
|
||||
'password' => null,
|
||||
'remember_token' => null,
|
||||
'two_factor_secret' => null,
|
||||
'two_factor_recovery_codes' => null,
|
||||
'two_factor_confirmed_at' => null,
|
||||
'email_verified_at' => null,
|
||||
'pending_email' => null,
|
||||
'current_team_id' => null,
|
||||
'profile_photo_path' => null,
|
||||
]);
|
||||
}
|
||||
|
||||
/**
|
||||
* Reverse the migrations.
|
||||
*/
|
||||
public function down(): void
|
||||
{
|
||||
//
|
||||
}
|
||||
};
|
||||
@@ -1,7 +1,6 @@
|
||||
ARG PHP_VERSION=8.3
|
||||
ARG FRANKENPHP_VERSION=1.8
|
||||
ARG FRANKENPHP_VERSION=1.11
|
||||
ARG COMPOSER_VERSION=2.8
|
||||
ARG BUN_VERSION="latest"
|
||||
ARG APP_ENV
|
||||
ARG DOCKER_FILES_BASE_PATH="docker/prod/"
|
||||
|
||||
@@ -16,13 +15,13 @@ RUN CGO_ENABLED=1 \
|
||||
XCADDY_GO_BUILD_FLAGS="-ldflags='-w -s' -tags=nobadger,nomysql,nopgx" \
|
||||
CGO_CFLAGS=$(php-config --includes) \
|
||||
CGO_LDFLAGS="$(php-config --ldflags) $(php-config --libs)" \
|
||||
xcaddy build v2.10.0 \
|
||||
xcaddy build \
|
||||
--output /usr/local/bin/frankenphp \
|
||||
--with github.com/dunglas/frankenphp=./ \
|
||||
--with github.com/dunglas/frankenphp/caddy=./caddy/ \
|
||||
--with github.com/dunglas/caddy-cbrotli
|
||||
|
||||
FROM dunglas/frankenphp:${FRANKENPHP_VERSION}-php${PHP_VERSION} AS base
|
||||
FROM dunglas/frankenphp:${FRANKENPHP_VERSION}-php${PHP_VERSION}
|
||||
|
||||
COPY --from=upstream /usr/local/bin/frankenphp /usr/local/bin/frankenphp
|
||||
|
||||
@@ -32,26 +31,28 @@ LABEL org.opencontainers.image.description="solidtime is a modern open source ti
|
||||
LABEL org.opencontainers.image.source="https://github.com/solidtime-io/solidtime"
|
||||
LABEL org.opencontainers.image.licenses="AGPL"
|
||||
|
||||
ARG WWWUSER=1000
|
||||
ARG WWWGROUP=1000
|
||||
ARG USER_ID=1000
|
||||
ARG GROUP_ID=1000
|
||||
ARG TZ=UTC
|
||||
ARG APP_DIR=/var/www/html
|
||||
ARG APP_ENV
|
||||
ARG APP_HOST
|
||||
ARG DOCKER_FILES_BASE_PATH
|
||||
|
||||
ENV DEBIAN_FRONTEND=noninteractive \
|
||||
TERM=xterm-color \
|
||||
OCTANE_SERVER=frankenphp \
|
||||
TZ=${TZ} \
|
||||
USER=octane \
|
||||
ROOT=${APP_DIR} \
|
||||
APP_ENV=${APP_ENV} \
|
||||
LANG=C.UTF-8 \
|
||||
USER=laravel \
|
||||
ROOT=/var/www/html \
|
||||
APP_ENV=production \
|
||||
COMPOSER_ALLOW_SUPERUSER=1 \
|
||||
COMPOSER_FUND=0 \
|
||||
COMPOSER_MAX_PARALLEL_HTTP=24 \
|
||||
XDG_CONFIG_HOME=${APP_DIR}/.config \
|
||||
XDG_DATA_HOME=${APP_DIR}/.data \
|
||||
SERVER_NAME=${APP_HOST}
|
||||
COMPOSER_MAX_PARALLEL_HTTP=48 \
|
||||
WITH_HORIZON=false \
|
||||
WITH_SCHEDULER=false \
|
||||
WITH_REVERB=false \
|
||||
WITH_SSR=false
|
||||
|
||||
ENV XDG_CONFIG_HOME=${ROOT}/.config XDG_DATA_HOME=${ROOT}/.data
|
||||
|
||||
WORKDIR ${ROOT}
|
||||
|
||||
@@ -60,6 +61,9 @@ SHELL ["/bin/bash", "-eou", "pipefail", "-c"]
|
||||
RUN ln -snf /usr/share/zoneinfo/${TZ} /etc/localtime \
|
||||
&& echo ${TZ} > /etc/timezone
|
||||
|
||||
RUN echo "Acquire::http::No-Cache true;" >> /etc/apt/apt.conf.d/99custom && \
|
||||
echo "Acquire::BrokenProxy true;" >> /etc/apt/apt.conf.d/99custom
|
||||
|
||||
RUN apt-get update; \
|
||||
apt-get upgrade -yqq; \
|
||||
apt-get install -yqq --no-install-recommends --show-progress \
|
||||
@@ -68,40 +72,36 @@ RUN apt-get update; \
|
||||
wget \
|
||||
vim \
|
||||
git \
|
||||
unzip \
|
||||
ncdu \
|
||||
procps \
|
||||
unzip \
|
||||
ca-certificates \
|
||||
supervisor \
|
||||
libsodium-dev \
|
||||
libbrotli-dev \
|
||||
# Install PHP extensions (included with dunglas/frankenphp)
|
||||
# && curl -fsSL https://bun.sh/install | BUN_INSTALL=/usr bash \
|
||||
&& install-php-extensions \
|
||||
apcu \
|
||||
bz2 \
|
||||
pcntl \
|
||||
mbstring \
|
||||
bcmath \
|
||||
sockets \
|
||||
pgsql \
|
||||
pdo_pgsql \
|
||||
opcache \
|
||||
exif \
|
||||
pdo_mysql \
|
||||
zip \
|
||||
uv \
|
||||
vips \
|
||||
intl \
|
||||
gd \
|
||||
redis \
|
||||
rdkafka \
|
||||
memcached \
|
||||
igbinary \
|
||||
ffi \
|
||||
ldap \
|
||||
&& apt-get -y autoremove \
|
||||
&& apt-get clean \
|
||||
&& docker-php-source delete \
|
||||
&& rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* \
|
||||
&& rm /var/log/lastlog /var/log/faillog
|
||||
&& rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* /var/log/lastlog /var/log/faillog
|
||||
|
||||
RUN arch="$(uname -m)" \
|
||||
&& case "$arch" in \
|
||||
@@ -111,106 +111,64 @@ RUN arch="$(uname -m)" \
|
||||
x86) _cronic_fname='supercronic-linux-386' ;; \
|
||||
*) echo >&2 "error: unsupported architecture: $arch"; exit 1 ;; \
|
||||
esac \
|
||||
&& wget -q "https://github.com/aptible/supercronic/releases/download/v0.2.29/${_cronic_fname}" \
|
||||
&& wget -q "https://github.com/aptible/supercronic/releases/download/v0.2.38/${_cronic_fname}" \
|
||||
-O /usr/bin/supercronic \
|
||||
&& chmod +x /usr/bin/supercronic \
|
||||
&& mkdir -p /etc/supercronic \
|
||||
&& echo "*/1 * * * * php ${ROOT}/artisan schedule:run --no-interaction" > /etc/supercronic/laravel
|
||||
|
||||
RUN userdel --remove --force www-data \
|
||||
&& groupadd --force -g ${WWWGROUP} ${USER} \
|
||||
&& useradd -ms /bin/bash --no-log-init --no-user-group -g ${WWWGROUP} -u ${WWWUSER} ${USER} \
|
||||
&& setcap -r /usr/local/bin/frankenphp
|
||||
|
||||
RUN chown -R ${USER}:${USER} ${ROOT} /var/{log,run} \
|
||||
&& chmod -R a+rw ${ROOT} /var/{log,run}
|
||||
&& groupadd --force -g ${GROUP_ID} ${USER} \
|
||||
&& useradd -ms /bin/bash --no-log-init --no-user-group -g ${GROUP_ID} -u ${USER_ID} ${USER}
|
||||
|
||||
RUN cp ${PHP_INI_DIR}/php.ini-production ${PHP_INI_DIR}/php.ini
|
||||
|
||||
USER ${USER}
|
||||
COPY --link --from=vendor /usr/bin/composer /usr/bin/composer
|
||||
COPY --link ${DOCKER_FILES_BASE_PATH}deployment/supervisord.conf /etc/
|
||||
COPY --link ${DOCKER_FILES_BASE_PATH}deployment/octane/FrankenPHP/supervisord.frankenphp.conf /etc/supervisor/conf.d/
|
||||
COPY --link ${DOCKER_FILES_BASE_PATH}deployment/supervisord.*.conf /etc/supervisor/conf.d/
|
||||
COPY --link ${DOCKER_FILES_BASE_PATH}deployment/start-container /usr/local/bin/start-container
|
||||
COPY --link ${DOCKER_FILES_BASE_PATH}deployment/healthcheck /usr/local/bin/healthcheck
|
||||
COPY --link ${DOCKER_FILES_BASE_PATH}deployment/php.ini ${PHP_INI_DIR}/conf.d/99-php.ini
|
||||
#COPY --link composer.* ./
|
||||
|
||||
COPY --link --chown=${WWWUSER}:${WWWUSER} --from=vendor /usr/bin/composer /usr/bin/composer
|
||||
|
||||
COPY --link --chown=${WWWUSER}:${WWWUSER} ${DOCKER_FILES_BASE_PATH}deployment/supervisord.conf /etc/
|
||||
COPY --link --chown=${WWWUSER}:${WWWUSER} ${DOCKER_FILES_BASE_PATH}deployment/octane/FrankenPHP/supervisord.frankenphp.conf /etc/supervisor/conf.d/
|
||||
COPY --link --chown=${WWWUSER}:${WWWUSER} ${DOCKER_FILES_BASE_PATH}deployment/supervisord.*.conf /etc/supervisor/conf.d/
|
||||
COPY --link --chown=${WWWUSER}:${WWWUSER} ${DOCKER_FILES_BASE_PATH}deployment/start-container /usr/local/bin/start-container
|
||||
COPY --link --chown=${WWWUSER}:${WWWUSER} ${DOCKER_FILES_BASE_PATH}deployment/healthcheck /usr/local/bin/healthcheck
|
||||
COPY --link --chown=${WWWUSER}:${WWWUSER} ${DOCKER_FILES_BASE_PATH}deployment/php.ini ${PHP_INI_DIR}/conf.d/99-octane.ini
|
||||
|
||||
RUN chmod +x /usr/local/bin/start-container /usr/local/bin/healthcheck
|
||||
|
||||
###########################################
|
||||
|
||||
#FROM base AS common
|
||||
#
|
||||
#USER ${USER}
|
||||
#
|
||||
#COPY --link --chown=${WWWUSER}:${WWWUSER} . .
|
||||
#
|
||||
#RUN composer install \
|
||||
# --no-dev \
|
||||
# --no-interaction \
|
||||
# --no-autoloader \
|
||||
# --no-ansi \
|
||||
# --no-scripts \
|
||||
# --no-progress \
|
||||
# --audit
|
||||
|
||||
###########################################
|
||||
# Build frontend assets with Bun
|
||||
###########################################
|
||||
|
||||
#FROM oven/bun:${BUN_VERSION} AS build
|
||||
#
|
||||
#ARG APP_ENV
|
||||
#
|
||||
#ENV ROOT=/var/www/html \
|
||||
# APP_ENV=${APP_ENV} \
|
||||
# NODE_ENV=${APP_ENV:-production}
|
||||
#
|
||||
#WORKDIR ${ROOT}
|
||||
#
|
||||
#COPY --link package.json bun.lock* ./
|
||||
#
|
||||
|
||||
#RUN bun install --frozen-lockfile
|
||||
#
|
||||
#COPY --link . .
|
||||
#COPY --link --from=common ${ROOT}/vendor vendor
|
||||
#
|
||||
#RUN bun run build
|
||||
|
||||
###########################################
|
||||
|
||||
#FROM common AS runner
|
||||
|
||||
USER ${USER}
|
||||
|
||||
ENV WITH_HORIZON=false \
|
||||
WITH_SCHEDULER=false \
|
||||
WITH_REVERB=false
|
||||
|
||||
COPY --link --chown=${WWWUSER}:${WWWUSER} . ./
|
||||
|
||||
RUN test -z "$(find . -name .git -print -quit)"
|
||||
#COPY --link --chown=${WWWUSER}:${WWWUSER} --from=build ${ROOT}/public public
|
||||
COPY --link . .
|
||||
|
||||
RUN mkdir -p \
|
||||
storage/framework/{sessions,views,cache,testing} \
|
||||
storage/logs \
|
||||
bootstrap/cache && chmod -R a+rw storage
|
||||
bootstrap/cache \
|
||||
&& chmod +x /usr/local/bin/start-container /usr/local/bin/healthcheck
|
||||
|
||||
#RUN composer install \
|
||||
# --classmap-authoritative \
|
||||
# --no-interaction \
|
||||
# --no-ansi \
|
||||
# --no-dev \
|
||||
# && composer clear-cache
|
||||
RUN composer dump-autoload \
|
||||
--optimize \
|
||||
--apcu \
|
||||
--no-dev
|
||||
|
||||
RUN cat .env
|
||||
#RUN php artisan env
|
||||
#RUN bun run build
|
||||
|
||||
RUN chown -R ${USER_ID}:${GROUP_ID} ${ROOT} \
|
||||
&& find / -perm /6000 -type f -exec chmod a-s {} + 2>/dev/null || true
|
||||
|
||||
USER ${USER}
|
||||
|
||||
EXPOSE 8000
|
||||
#EXPOSE 2019
|
||||
#EXPOSE 8080
|
||||
|
||||
ENTRYPOINT ["start-container"]
|
||||
|
||||
#HEALTHCHECK --start-period=5s --interval=2s --timeout=5s --retries=8 CMD healthcheck || exit 1
|
||||
#HEALTHCHECK --start-period=30s --interval=10s --timeout=3s --retries=3 CMD healthcheck || exit 1
|
||||
|
||||
@@ -22,6 +22,13 @@ elif [ "${container_mode}" = "reverb" ]; then
|
||||
echo "Healthcheck failed."
|
||||
exit 1
|
||||
fi
|
||||
elif [ "${container_mode}" = "ssr" ]; then
|
||||
if [ "$(supervisorctl status inertia-ssr-server:inertia-ssr-server_0 | awk '{print tolower($2)}')" = "running" ]; then
|
||||
exit 0
|
||||
else
|
||||
echo "Healthcheck failed."
|
||||
exit 1
|
||||
fi
|
||||
elif [ "${container_mode}" = "worker" ]; then
|
||||
if [ "$(supervisorctl status worker:worker_0 | awk '{print tolower($2)}')" = "running" ]; then
|
||||
exit 0
|
||||
|
||||
@@ -3,6 +3,14 @@
|
||||
|
||||
admin {$CADDY_SERVER_ADMIN_HOST}:{$CADDY_SERVER_ADMIN_PORT}
|
||||
|
||||
log {
|
||||
level {$CADDY_SERVER_LOG_LEVEL:WARN}
|
||||
}
|
||||
|
||||
auto_https off
|
||||
|
||||
skip_install_trust
|
||||
|
||||
frankenphp {
|
||||
worker "{$APP_PUBLIC_PATH}/frankenphp-worker.php" {$CADDY_SERVER_WORKER_COUNT}
|
||||
}
|
||||
@@ -20,7 +28,7 @@
|
||||
|
||||
{$CADDY_SERVER_SERVER_NAME} {
|
||||
log {
|
||||
level WARN
|
||||
level {$CADDY_SERVER_LOG_LEVEL:WARN}
|
||||
|
||||
format filter {
|
||||
wrap {$CADDY_SERVER_LOGGER}
|
||||
@@ -60,7 +68,6 @@
|
||||
error @rejected 401
|
||||
|
||||
php_server {
|
||||
index frankenphp-worker.php
|
||||
try_files {path} frankenphp-worker.php
|
||||
resolve_root_symlink
|
||||
}
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user