mirror of
https://github.com/solidtime-io/solidtime.git
synced 2026-08-18 13:12:16 +01:00
Compare commits
109 Commits
v0.11.0
...
4432174439
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
4432174439 | ||
|
|
ccb16118a9 | ||
|
|
dad686d107 | ||
|
|
414b5d3294 | ||
|
|
e9217df338 | ||
|
|
96a0c21b5e | ||
|
|
8e7c8a1e1b | ||
|
|
6299e242a9 | ||
|
|
c573d31ef9 | ||
|
|
00ffabe108 | ||
|
|
5b756be058 | ||
|
|
dc70eb7130 | ||
|
|
c2a8eac65f | ||
|
|
28ecfc63a3 | ||
|
|
433a6f3770 | ||
|
|
0ba20fd24c | ||
|
|
3267acb161 | ||
|
|
7d9ecd9526 | ||
|
|
3a17f80f99 | ||
|
|
e29ea2ea42 | ||
|
|
fb6e4639ce | ||
|
|
69bc41988a | ||
|
|
f7663b1c8b | ||
|
|
793bd11dcf | ||
|
|
77a62afd69 | ||
|
|
b73aa543fd | ||
|
|
2d6f9e514f | ||
|
|
f8e668790b | ||
|
|
77a5e979c6 | ||
|
|
353a579850 | ||
|
|
bd44a2b376 | ||
|
|
277dbaf6eb | ||
|
|
1cf33ddb3f | ||
|
|
84cd0d572d | ||
|
|
f37b86f377 | ||
|
|
1e7364fc4b | ||
|
|
8cbc9838c9 | ||
|
|
71c8992e31 | ||
|
|
53d91b65d6 | ||
|
|
0c88a10eb5 | ||
|
|
dd7b23958a | ||
|
|
1eb066f5aa | ||
|
|
b1287c6a0a | ||
|
|
815abb5980 | ||
|
|
e2f859be27 | ||
|
|
3d26fcaefe | ||
|
|
1e73a90f9d | ||
|
|
0f8f906e5c | ||
|
|
797fddf638 | ||
|
|
d07294ae7c | ||
|
|
1f49940805 | ||
|
|
6be6a48e0d | ||
|
|
b94a04dca0 | ||
|
|
bd3b8f265f | ||
|
|
c19a0f9acc | ||
|
|
5c6d84dc38 | ||
|
|
5c67709746 | ||
|
|
a2b0828c54 | ||
|
|
b94872b07b | ||
|
|
12bbbf64e9 | ||
|
|
c07ac4b0e4 | ||
|
|
a58566d002 | ||
|
|
57ed6036e6 | ||
|
|
ef7569b63b | ||
|
|
19c789b78e | ||
|
|
49548037b3 | ||
|
|
97df779d1e | ||
|
|
a1d5563fc4 | ||
|
|
c94ca804f8 | ||
|
|
189682cfaf | ||
|
|
8d16503541 | ||
|
|
e43ce477b8 | ||
|
|
5646aedb25 | ||
|
|
2b46e568e0 | ||
|
|
89a4a1962a | ||
|
|
c581ad8854 | ||
|
|
bce6cb9395 | ||
|
|
1cdae98ed9 | ||
|
|
02f6436fd0 | ||
|
|
452acca942 | ||
|
|
192c8c3b88 | ||
|
|
6218ffceb5 | ||
|
|
ba32be0543 | ||
|
|
bd817db06f | ||
|
|
97f4bce676 | ||
|
|
6962b668fb | ||
|
|
be8091296c | ||
|
|
84c4750c9b | ||
|
|
f582adab0d | ||
|
|
c60cff04ce | ||
|
|
cae41e4b4f | ||
|
|
8973be9dab | ||
|
|
2a0b8d31e6 | ||
|
|
d2f3fe411a | ||
|
|
f880f9f730 | ||
|
|
556bbedeca | ||
|
|
eed638d0aa | ||
|
|
864f41bda6 | ||
|
|
26524c5f40 | ||
|
|
cf98fabe0a | ||
|
|
88c0c334e9 | ||
|
|
0fc325363d | ||
|
|
1afc16573a | ||
|
|
147514a606 | ||
|
|
435522b502 | ||
|
|
f1d001e03e | ||
|
|
7f145cf1c2 | ||
|
|
b579ed1075 | ||
|
|
ed2b7476ae |
2
.env.ci
2
.env.ci
@@ -60,7 +60,7 @@ AUDITING_ENABLED=true
|
|||||||
TELESCOPE_ENABLED=false
|
TELESCOPE_ENABLED=false
|
||||||
|
|
||||||
# Services
|
# Services
|
||||||
GOTENBERG_URL=http://0.0.0.0:3000
|
GOTENBERG_URL=http://localhost:3000
|
||||||
|
|
||||||
# Octane
|
# Octane
|
||||||
OCTANE_SERVER=frankenphp
|
OCTANE_SERVER=frankenphp
|
||||||
|
|||||||
@@ -77,6 +77,9 @@ TELESCOPE_ENABLED=false
|
|||||||
# Services
|
# Services
|
||||||
GOTENBERG_URL=http://gotenberg:3000
|
GOTENBERG_URL=http://gotenberg:3000
|
||||||
|
|
||||||
|
# Octane
|
||||||
|
OCTANE_SERVER=frankenphp
|
||||||
|
|
||||||
# Local setup
|
# Local setup
|
||||||
NGINX_HOST_NAME=solidtime.test
|
NGINX_HOST_NAME=solidtime.test
|
||||||
NETWORK_NAME=reverse-proxy-docker-traefik_routing
|
NETWORK_NAME=reverse-proxy-docker-traefik_routing
|
||||||
|
|||||||
4
.github/workflows/build-onpremise.yml
vendored
4
.github/workflows/build-onpremise.yml
vendored
@@ -91,7 +91,7 @@ jobs:
|
|||||||
if: steps.cache-vendor.outputs.cache-hit != 'true' # Skip if cache hit
|
if: steps.cache-vendor.outputs.cache-hit != 'true' # Skip if cache hit
|
||||||
|
|
||||||
- name: "Use Node.js"
|
- name: "Use Node.js"
|
||||||
uses: actions/setup-node@v4
|
uses: actions/setup-node@v6
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
|
|
||||||
@@ -177,7 +177,7 @@ jobs:
|
|||||||
- build
|
- build
|
||||||
steps:
|
steps:
|
||||||
- name: "Download digests"
|
- name: "Download digests"
|
||||||
uses: actions/download-artifact@v4
|
uses: actions/download-artifact@v6
|
||||||
with:
|
with:
|
||||||
path: ${{ runner.temp }}/digests
|
path: ${{ runner.temp }}/digests
|
||||||
pattern: digests-*
|
pattern: digests-*
|
||||||
|
|||||||
10
.github/workflows/build-private.yml
vendored
10
.github/workflows/build-private.yml
vendored
@@ -22,7 +22,7 @@ jobs:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: "Check out code"
|
- name: "Check out code"
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v5
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0 # Required for WyriHaximus/github-action-get-previous-tag
|
fetch-depth: 0 # Required for WyriHaximus/github-action-get-previous-tag
|
||||||
|
|
||||||
@@ -68,12 +68,12 @@ jobs:
|
|||||||
run: cat .env
|
run: cat .env
|
||||||
|
|
||||||
- name: "Use Node.js"
|
- name: "Use Node.js"
|
||||||
uses: actions/setup-node@v4
|
uses: actions/setup-node@v6
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
|
|
||||||
- name: "Checkout billing extension"
|
- name: "Checkout billing extension"
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v5
|
||||||
with:
|
with:
|
||||||
repository: solidtime-io/extension-billing
|
repository: solidtime-io/extension-billing
|
||||||
path: extensions/Billing
|
path: extensions/Billing
|
||||||
@@ -93,7 +93,7 @@ jobs:
|
|||||||
run: cd extensions/Billing && npm ci
|
run: cd extensions/Billing && npm ci
|
||||||
|
|
||||||
- name: "Checkout services extension"
|
- name: "Checkout services extension"
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v5
|
||||||
with:
|
with:
|
||||||
repository: solidtime-io/extension-services
|
repository: solidtime-io/extension-services
|
||||||
path: extensions/Services
|
path: extensions/Services
|
||||||
@@ -111,7 +111,7 @@ jobs:
|
|||||||
run: cd extensions/Services && npm ci
|
run: cd extensions/Services && npm ci
|
||||||
|
|
||||||
- name: "Checkout invoicing extension"
|
- name: "Checkout invoicing extension"
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v5
|
||||||
with:
|
with:
|
||||||
repository: solidtime-io/extension-invoicing
|
repository: solidtime-io/extension-invoicing
|
||||||
path: extensions/Invoicing
|
path: extensions/Invoicing
|
||||||
|
|||||||
6
.github/workflows/build-public.yml
vendored
6
.github/workflows/build-public.yml
vendored
@@ -36,7 +36,7 @@ jobs:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: "Check out code"
|
- name: "Check out code"
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v5
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0 # Required for WyriHaximus/github-action-get-previous-tag
|
fetch-depth: 0 # Required for WyriHaximus/github-action-get-previous-tag
|
||||||
|
|
||||||
@@ -92,7 +92,7 @@ jobs:
|
|||||||
if: steps.cache-vendor.outputs.cache-hit != 'true' # Skip if cache hit
|
if: steps.cache-vendor.outputs.cache-hit != 'true' # Skip if cache hit
|
||||||
|
|
||||||
- name: "Use Node.js"
|
- name: "Use Node.js"
|
||||||
uses: actions/setup-node@v4
|
uses: actions/setup-node@v6
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
|
|
||||||
@@ -169,7 +169,7 @@ jobs:
|
|||||||
- build
|
- build
|
||||||
steps:
|
steps:
|
||||||
- name: "Download digests"
|
- name: "Download digests"
|
||||||
uses: actions/download-artifact@v4
|
uses: actions/download-artifact@v6
|
||||||
with:
|
with:
|
||||||
path: ${{ runner.temp }}/digests
|
path: ${{ runner.temp }}/digests
|
||||||
pattern: digests-*
|
pattern: digests-*
|
||||||
|
|||||||
2
.github/workflows/generate-api-docs.yml
vendored
2
.github/workflows/generate-api-docs.yml
vendored
@@ -29,7 +29,7 @@ jobs:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v5
|
||||||
|
|
||||||
- name: "Setup PHP"
|
- name: "Setup PHP"
|
||||||
uses: shivammathur/setup-php@v2
|
uses: shivammathur/setup-php@v2
|
||||||
|
|||||||
4
.github/workflows/npm-build.yml
vendored
4
.github/workflows/npm-build.yml
vendored
@@ -11,7 +11,7 @@ jobs:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v5
|
||||||
|
|
||||||
- name: "Setup PHP (for Ziggy)"
|
- name: "Setup PHP (for Ziggy)"
|
||||||
uses: shivammathur/setup-php@v2
|
uses: shivammathur/setup-php@v2
|
||||||
@@ -24,7 +24,7 @@ jobs:
|
|||||||
run: composer install -n --prefer-dist
|
run: composer install -n --prefer-dist
|
||||||
|
|
||||||
- name: "Use Node.js"
|
- name: "Use Node.js"
|
||||||
uses: actions/setup-node@v4
|
uses: actions/setup-node@v6
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
|
|
||||||
|
|||||||
4
.github/workflows/npm-format-check.yml
vendored
4
.github/workflows/npm-format-check.yml
vendored
@@ -9,10 +9,10 @@ jobs:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v5
|
||||||
|
|
||||||
- name: "Use Node.js"
|
- name: "Use Node.js"
|
||||||
uses: actions/setup-node@v4
|
uses: actions/setup-node@v6
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
|
|
||||||
|
|||||||
4
.github/workflows/npm-lint.yml
vendored
4
.github/workflows/npm-lint.yml
vendored
@@ -11,10 +11,10 @@ jobs:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v5
|
||||||
|
|
||||||
- name: "Use Node.js"
|
- name: "Use Node.js"
|
||||||
uses: actions/setup-node@v4
|
uses: actions/setup-node@v6
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
|
|
||||||
|
|||||||
4
.github/workflows/npm-publish-api.yml
vendored
4
.github/workflows/npm-publish-api.yml
vendored
@@ -11,11 +11,11 @@ jobs:
|
|||||||
id-token: write
|
id-token: write
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v5
|
||||||
# Setup .npmrc file to publish to npm
|
# Setup .npmrc file to publish to npm
|
||||||
- name: Install root project dependencies
|
- name: Install root project dependencies
|
||||||
run: npm ci
|
run: npm ci
|
||||||
- uses: actions/setup-node@v4
|
- uses: actions/setup-node@v6
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
registry-url: 'https://registry.npmjs.org'
|
registry-url: 'https://registry.npmjs.org'
|
||||||
|
|||||||
4
.github/workflows/npm-publish-ui.yml
vendored
4
.github/workflows/npm-publish-ui.yml
vendored
@@ -11,9 +11,9 @@ jobs:
|
|||||||
id-token: write
|
id-token: write
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v5
|
||||||
# Setup .npmrc file to publish to npm
|
# Setup .npmrc file to publish to npm
|
||||||
- uses: actions/setup-node@v4
|
- uses: actions/setup-node@v6
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
registry-url: 'https://registry.npmjs.org'
|
registry-url: 'https://registry.npmjs.org'
|
||||||
|
|||||||
4
.github/workflows/npm-typecheck.yml
vendored
4
.github/workflows/npm-typecheck.yml
vendored
@@ -10,7 +10,7 @@ jobs:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v5
|
||||||
|
|
||||||
- name: "Setup PHP (for Ziggy)"
|
- name: "Setup PHP (for Ziggy)"
|
||||||
uses: shivammathur/setup-php@v2
|
uses: shivammathur/setup-php@v2
|
||||||
@@ -23,7 +23,7 @@ jobs:
|
|||||||
run: composer install -n --prefer-dist
|
run: composer install -n --prefer-dist
|
||||||
|
|
||||||
- name: "Use Node.js"
|
- name: "Use Node.js"
|
||||||
uses: actions/setup-node@v4
|
uses: actions/setup-node@v6
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
|
|
||||||
|
|||||||
2
.github/workflows/phpstan.yml
vendored
2
.github/workflows/phpstan.yml
vendored
@@ -9,7 +9,7 @@ jobs:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v5
|
||||||
|
|
||||||
- name: "Setup PHP"
|
- name: "Setup PHP"
|
||||||
uses: shivammathur/setup-php@v2
|
uses: shivammathur/setup-php@v2
|
||||||
|
|||||||
6
.github/workflows/phpunit.yml
vendored
6
.github/workflows/phpunit.yml
vendored
@@ -36,7 +36,7 @@ jobs:
|
|||||||
--health-retries 5
|
--health-retries 5
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v5
|
||||||
|
|
||||||
- name: "Setup PHP"
|
- name: "Setup PHP"
|
||||||
uses: shivammathur/setup-php@v2
|
uses: shivammathur/setup-php@v2
|
||||||
@@ -48,7 +48,7 @@ jobs:
|
|||||||
- name: "Run composer install"
|
- name: "Run composer install"
|
||||||
run: composer install -n --prefer-dist
|
run: composer install -n --prefer-dist
|
||||||
|
|
||||||
- uses: actions/setup-node@v4
|
- uses: actions/setup-node@v6
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
|
|
||||||
@@ -68,7 +68,7 @@ jobs:
|
|||||||
run: php artisan test --stop-on-failure --coverage-text --coverage-clover=coverage.xml
|
run: php artisan test --stop-on-failure --coverage-text --coverage-clover=coverage.xml
|
||||||
|
|
||||||
- name: "Upload coverage reports to Codecov"
|
- name: "Upload coverage reports to Codecov"
|
||||||
uses: codecov/codecov-action@v5.4.3
|
uses: codecov/codecov-action@v5.5.1
|
||||||
with:
|
with:
|
||||||
token: ${{ secrets.CODECOV_TOKEN }}
|
token: ${{ secrets.CODECOV_TOKEN }}
|
||||||
slug: solidtime-io/solidtime
|
slug: solidtime-io/solidtime
|
||||||
|
|||||||
4
.github/workflows/pint.yml
vendored
4
.github/workflows/pint.yml
vendored
@@ -9,9 +9,9 @@ jobs:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v5
|
||||||
|
|
||||||
- name: "Check code style"
|
- name: "Check code style"
|
||||||
uses: aglipanci/laravel-pint-action@2.5
|
uses: aglipanci/laravel-pint-action@2.6
|
||||||
with:
|
with:
|
||||||
configPath: "pint.json"
|
configPath: "pint.json"
|
||||||
|
|||||||
4
.github/workflows/playwright.yml
vendored
4
.github/workflows/playwright.yml
vendored
@@ -35,10 +35,10 @@ jobs:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v5
|
||||||
|
|
||||||
- name: "Setup node"
|
- name: "Setup node"
|
||||||
uses: actions/setup-node@v4
|
uses: actions/setup-node@v6
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
|
|
||||||
|
|||||||
1
.gitignore
vendored
1
.gitignore
vendored
@@ -42,3 +42,4 @@ yarn-error.log
|
|||||||
/data
|
/data
|
||||||
/config/caddy
|
/config/caddy
|
||||||
/config/composer
|
/config/composer
|
||||||
|
/AGENTS.md
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
# solidtime - The modern Open-Source Time Tracker
|
# solidtime - The modern Open-Source TimeTracker
|
||||||
|
|
||||||
[](https://github.com/solidtime-io/solidtime/blob/main/LICENSE.md)
|
[](https://github.com/solidtime-io/solidtime/blob/main/LICENSE.md)
|
||||||
[](https://codecov.io/gh/solidtime-io/solidtime)
|
[](https://codecov.io/gh/solidtime-io/solidtime)
|
||||||
@@ -37,6 +37,8 @@ If you have a **feature request**, please [**create a discussion**](https://gith
|
|||||||
|
|
||||||
Please open an issue or start a discussion and wait for approval before submitting a pull request. This does not apply to tiny fixes or changes however, please keep in mind that we might not merge PRs for various reasons.
|
Please open an issue or start a discussion and wait for approval before submitting a pull request. This does not apply to tiny fixes or changes however, please keep in mind that we might not merge PRs for various reasons.
|
||||||
|
|
||||||
|
**If you submit an AI slop pull request (especially without following the proper procedure), you will be banned from future contributions to solidtime.**
|
||||||
|
|
||||||
Please read the [CONTRIBUTING.md](./CONTRIBUTING.md) before sumbitting a Pull Request.
|
Please read the [CONTRIBUTING.md](./CONTRIBUTING.md) before sumbitting a Pull Request.
|
||||||
|
|
||||||
We do accept contributions in the [documentation repository](https://github.com/solidtime-io/docs) f.e. to add new self-hosting guides.
|
We do accept contributions in the [documentation repository](https://github.com/solidtime-io/docs) f.e. to add new self-hosting guides.
|
||||||
|
|||||||
15
SECURITY.md
15
SECURITY.md
@@ -3,3 +3,18 @@
|
|||||||
## Reporting a Vulnerability
|
## Reporting a Vulnerability
|
||||||
|
|
||||||
If you discover a security vulnerability regarding this project, please e-mail me to [security@solidtime.io](mailto:security@solidtime.io)!
|
If you discover a security vulnerability regarding this project, please e-mail me to [security@solidtime.io](mailto:security@solidtime.io)!
|
||||||
|
|
||||||
|
## Out of scope
|
||||||
|
|
||||||
|
|
||||||
|
Reports we typically won't issue an advisory for:
|
||||||
|
|
||||||
|
* Theoretical findings without a working PoC
|
||||||
|
* Raw scanner output without manual validation
|
||||||
|
* Missing/weak security headers in isolation (CSP, X-Frame-Options, HSTS, etc.)
|
||||||
|
* SPF/DKIM/DMARC on non-mail-sending domains; missing DNSSEC/CAA; TLS cipher preferences
|
||||||
|
* Self-XSS; CSRF on non-state-changing endpoints (logout, theme)
|
||||||
|
* CSV / spreadsheet formula injection in exports — treated as a spreadsheet-application issue
|
||||||
|
* Org owners or admins acting destructively within their own organization
|
||||||
|
* Anything requiring direct DB, shell, or filesystem access on a self-hosted instance
|
||||||
|
* Missing OAuth Scope enforcement (this is not implemented yet, but AI scanners flag it which is why it is included in this list until we actually support it)
|
||||||
|
|||||||
@@ -5,9 +5,12 @@ declare(strict_types=1);
|
|||||||
namespace App\Actions\Fortify;
|
namespace App\Actions\Fortify;
|
||||||
|
|
||||||
use App\Enums\Weekday;
|
use App\Enums\Weekday;
|
||||||
|
use App\Mail\VerifyUpdatedEmailMail;
|
||||||
use App\Models\User;
|
use App\Models\User;
|
||||||
use Illuminate\Database\Eloquent\Builder;
|
use Illuminate\Database\Eloquent\Builder;
|
||||||
|
use Illuminate\Support\Facades\Mail;
|
||||||
use Illuminate\Support\Facades\Validator;
|
use Illuminate\Support\Facades\Validator;
|
||||||
|
use Illuminate\Support\Str;
|
||||||
use Illuminate\Validation\Rule;
|
use Illuminate\Validation\Rule;
|
||||||
use Illuminate\Validation\ValidationException;
|
use Illuminate\Validation\ValidationException;
|
||||||
use Korridor\LaravelModelValidationRules\Rules\UniqueEloquent;
|
use Korridor\LaravelModelValidationRules\Rules\UniqueEloquent;
|
||||||
@@ -24,6 +27,10 @@ class UpdateUserProfileInformation implements UpdatesUserProfileInformation
|
|||||||
*/
|
*/
|
||||||
public function update(User $user, array $input): void
|
public function update(User $user, array $input): void
|
||||||
{
|
{
|
||||||
|
if (isset($input['email']) && is_string($input['email'])) {
|
||||||
|
$input['email'] = Str::lower($input['email']);
|
||||||
|
}
|
||||||
|
|
||||||
Validator::make($input, [
|
Validator::make($input, [
|
||||||
'name' => [
|
'name' => [
|
||||||
'required',
|
'required',
|
||||||
@@ -58,16 +65,17 @@ class UpdateUserProfileInformation implements UpdatesUserProfileInformation
|
|||||||
$user->updateProfilePhoto($input['photo']);
|
$user->updateProfilePhoto($input['photo']);
|
||||||
}
|
}
|
||||||
|
|
||||||
if ($input['email'] !== $user->email) {
|
$email = Str::lower((string) $input['email']);
|
||||||
|
|
||||||
|
if ($email !== Str::lower($user->email)) {
|
||||||
$user->forceFill([
|
$user->forceFill([
|
||||||
'name' => $input['name'],
|
'name' => $input['name'],
|
||||||
'email' => $input['email'],
|
'pending_email' => $email,
|
||||||
'email_verified_at' => null,
|
|
||||||
'timezone' => $input['timezone'],
|
'timezone' => $input['timezone'],
|
||||||
'week_start' => $input['week_start'],
|
'week_start' => $input['week_start'],
|
||||||
])->save();
|
])->save();
|
||||||
|
|
||||||
$user->sendEmailVerificationNotification();
|
Mail::to($email)->send(new VerifyUpdatedEmailMail($user, $email));
|
||||||
} else {
|
} else {
|
||||||
$user->forceFill([
|
$user->forceFill([
|
||||||
'name' => $input['name'],
|
'name' => $input['name'],
|
||||||
|
|||||||
@@ -4,18 +4,9 @@ declare(strict_types=1);
|
|||||||
|
|
||||||
namespace App\Actions\Jetstream;
|
namespace App\Actions\Jetstream;
|
||||||
|
|
||||||
use App\Enums\Role;
|
use App\Exceptions\MovedToApiException;
|
||||||
use App\Models\Organization;
|
use App\Models\Organization;
|
||||||
use App\Models\User;
|
use App\Models\User;
|
||||||
use App\Service\MemberService;
|
|
||||||
use Closure;
|
|
||||||
use Illuminate\Contracts\Validation\ValidationRule;
|
|
||||||
use Illuminate\Database\Eloquent\Builder;
|
|
||||||
use Illuminate\Support\Facades\Gate;
|
|
||||||
use Illuminate\Support\Facades\Validator;
|
|
||||||
use Illuminate\Validation\Rule;
|
|
||||||
use Illuminate\Validation\Rules\In;
|
|
||||||
use Korridor\LaravelModelValidationRules\Rules\ExistsEloquent;
|
|
||||||
use Laravel\Jetstream\Contracts\AddsTeamMembers;
|
use Laravel\Jetstream\Contracts\AddsTeamMembers;
|
||||||
|
|
||||||
class AddOrganizationMember implements AddsTeamMembers
|
class AddOrganizationMember implements AddsTeamMembers
|
||||||
@@ -25,70 +16,6 @@ class AddOrganizationMember implements AddsTeamMembers
|
|||||||
*/
|
*/
|
||||||
public function add(User $owner, Organization $organization, string $email, ?string $role = null): void
|
public function add(User $owner, Organization $organization, string $email, ?string $role = null): void
|
||||||
{
|
{
|
||||||
Gate::forUser($owner)->authorize('addTeamMember', $organization); // TODO: refactor after owner refactoring
|
throw new MovedToApiException;
|
||||||
|
|
||||||
$this->validate($organization, $email, $role);
|
|
||||||
|
|
||||||
$newOrganizationMember = User::query()
|
|
||||||
->where('email', $email)
|
|
||||||
->where('is_placeholder', '=', false)
|
|
||||||
->firstOrFail();
|
|
||||||
|
|
||||||
app(MemberService::class)->addMember($newOrganizationMember, $organization, Role::from($role));
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Validate the add member operation.
|
|
||||||
*/
|
|
||||||
protected function validate(Organization $organization, string $email, ?string $role): void
|
|
||||||
{
|
|
||||||
Validator::make([
|
|
||||||
'email' => $email,
|
|
||||||
'role' => $role,
|
|
||||||
], $this->rules())->after(
|
|
||||||
$this->ensureUserIsNotAlreadyOnTeam($organization, $email)
|
|
||||||
)->validateWithBag('addTeamMember');
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Get the validation rules for adding a team member.
|
|
||||||
*
|
|
||||||
* @return array<string, array<ValidationRule|Rule|string|In>>
|
|
||||||
*/
|
|
||||||
protected function rules(): array
|
|
||||||
{
|
|
||||||
return [
|
|
||||||
'email' => [
|
|
||||||
'required',
|
|
||||||
'email',
|
|
||||||
ExistsEloquent::make(User::class, 'email', function (Builder $builder) {
|
|
||||||
/** @var Builder<User> $builder */
|
|
||||||
return $builder->where('is_placeholder', '=', false);
|
|
||||||
})->withMessage(__('We were unable to find a registered user with this email address.')),
|
|
||||||
],
|
|
||||||
'role' => [
|
|
||||||
'required',
|
|
||||||
'string',
|
|
||||||
Rule::in([
|
|
||||||
Role::Admin->value,
|
|
||||||
Role::Manager->value,
|
|
||||||
Role::Employee->value,
|
|
||||||
]),
|
|
||||||
],
|
|
||||||
];
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Ensure that the user is not already on the team.
|
|
||||||
*/
|
|
||||||
protected function ensureUserIsNotAlreadyOnTeam(Organization $team, string $email): Closure
|
|
||||||
{
|
|
||||||
return function ($validator) use ($team, $email): void {
|
|
||||||
$validator->errors()->addIf(
|
|
||||||
$team->hasRealUserWithEmail($email),
|
|
||||||
'email',
|
|
||||||
__('This user already belongs to the team.')
|
|
||||||
);
|
|
||||||
};
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -25,6 +25,8 @@ class CreateOrganization implements CreatesTeams
|
|||||||
*
|
*
|
||||||
* @throws AuthorizationException
|
* @throws AuthorizationException
|
||||||
* @throws ValidationException
|
* @throws ValidationException
|
||||||
|
*
|
||||||
|
* @deprecated Use REST endpoint instead
|
||||||
*/
|
*/
|
||||||
public function create(User $user, array $input): Organization
|
public function create(User $user, array $input): Organization
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -12,6 +12,8 @@ class DeleteOrganization implements DeletesTeams
|
|||||||
{
|
{
|
||||||
/**
|
/**
|
||||||
* Delete the given team.
|
* Delete the given team.
|
||||||
|
*
|
||||||
|
* @deprecated Use REST endpoint instead
|
||||||
*/
|
*/
|
||||||
public function delete(Organization $organization): void
|
public function delete(Organization $organization): void
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -16,6 +16,8 @@ class DeleteUser implements DeletesUsers
|
|||||||
* Delete the given user.
|
* Delete the given user.
|
||||||
*
|
*
|
||||||
* @throws ValidationException
|
* @throws ValidationException
|
||||||
|
*
|
||||||
|
* @deprecated Use REST endpoint instead
|
||||||
*/
|
*/
|
||||||
public function delete(User $user): void
|
public function delete(User $user): void
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -18,6 +18,8 @@ class ValidateOrganizationDeletion
|
|||||||
* @param Organization $organization Organization to be deleted
|
* @param Organization $organization Organization to be deleted
|
||||||
*
|
*
|
||||||
* @throws AuthorizationException
|
* @throws AuthorizationException
|
||||||
|
*
|
||||||
|
* @deprecated Use REST endpoint instead
|
||||||
*/
|
*/
|
||||||
public function validate(User $user, Organization $organization): void
|
public function validate(User $user, Organization $organization): void
|
||||||
{
|
{
|
||||||
|
|||||||
28
app/Events/MemberAdded.php
Normal file
28
app/Events/MemberAdded.php
Normal file
@@ -0,0 +1,28 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Events;
|
||||||
|
|
||||||
|
use App\Models\Member;
|
||||||
|
use App\Models\Organization;
|
||||||
|
use App\Models\User;
|
||||||
|
use Illuminate\Foundation\Events\Dispatchable;
|
||||||
|
|
||||||
|
class MemberAdded
|
||||||
|
{
|
||||||
|
use Dispatchable;
|
||||||
|
|
||||||
|
public Member $member;
|
||||||
|
|
||||||
|
public Organization $organization;
|
||||||
|
|
||||||
|
public User $user;
|
||||||
|
|
||||||
|
public function __construct(Member $member, Organization $organization, User $user)
|
||||||
|
{
|
||||||
|
$this->member = $member;
|
||||||
|
$this->organization = $organization;
|
||||||
|
$this->user = $user;
|
||||||
|
}
|
||||||
|
}
|
||||||
28
app/Events/MemberAdding.php
Normal file
28
app/Events/MemberAdding.php
Normal file
@@ -0,0 +1,28 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Events;
|
||||||
|
|
||||||
|
use App\Enums\Role;
|
||||||
|
use App\Models\Organization;
|
||||||
|
use App\Models\User;
|
||||||
|
use Illuminate\Foundation\Events\Dispatchable;
|
||||||
|
|
||||||
|
class MemberAdding
|
||||||
|
{
|
||||||
|
use Dispatchable;
|
||||||
|
|
||||||
|
public User $user;
|
||||||
|
|
||||||
|
public Organization $organization;
|
||||||
|
|
||||||
|
public Role $role;
|
||||||
|
|
||||||
|
public function __construct(User $user, Organization $organization, Role $role)
|
||||||
|
{
|
||||||
|
$this->user = $user;
|
||||||
|
$this->organization = $organization;
|
||||||
|
$this->role = $role;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Exceptions\Api;
|
||||||
|
|
||||||
|
class UserResendEmailVerificationNoPendingEmailApiException extends ApiException
|
||||||
|
{
|
||||||
|
public const string KEY = 'user_resend_email_verification_no_pending_email';
|
||||||
|
}
|
||||||
@@ -50,7 +50,7 @@ class FailedJobResource extends Resource
|
|||||||
TextInput::make('queue')->disabled(),
|
TextInput::make('queue')->disabled(),
|
||||||
|
|
||||||
// make text a little bit smaller because often a complete Stack Trace is shown:
|
// make text a little bit smaller because often a complete Stack Trace is shown:
|
||||||
TextArea::make('exception')->disabled()->columnSpan(4)->extraInputAttributes(['style' => 'font-size: 80%;']),
|
Textarea::make('exception')->disabled()->columnSpan(4)->extraInputAttributes(['style' => 'font-size: 80%;']),
|
||||||
PrettyJsonField::make('payload')->disabled()->columnSpan(4),
|
PrettyJsonField::make('payload')->disabled()->columnSpan(4),
|
||||||
])->columns(4);
|
])->columns(4);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -39,7 +39,7 @@ class OrganizationInvitationResource extends Resource
|
|||||||
->required(),
|
->required(),
|
||||||
Select::make('role')
|
Select::make('role')
|
||||||
->options(Role::class),
|
->options(Role::class),
|
||||||
Forms\Components\Select::make('organization_id')
|
Select::make('organization_id')
|
||||||
->label('Organization')
|
->label('Organization')
|
||||||
->relationship(name: 'organization', titleAttribute: 'name')
|
->relationship(name: 'organization', titleAttribute: 'name')
|
||||||
->searchable(['name'])
|
->searchable(['name'])
|
||||||
|
|||||||
@@ -55,7 +55,7 @@ class OrganizationResource extends Resource
|
|||||||
->label('Is personal?')
|
->label('Is personal?')
|
||||||
->hiddenOn(['create'])
|
->hiddenOn(['create'])
|
||||||
->required(),
|
->required(),
|
||||||
Forms\Components\Select::make('user_id')
|
Select::make('user_id')
|
||||||
->label('Owner')
|
->label('Owner')
|
||||||
->relationship(name: 'owner', titleAttribute: 'email')
|
->relationship(name: 'owner', titleAttribute: 'email')
|
||||||
->searchable(['name', 'email'])
|
->searchable(['name', 'email'])
|
||||||
@@ -76,7 +76,7 @@ class OrganizationResource extends Resource
|
|||||||
Select::make('time_format')
|
Select::make('time_format')
|
||||||
->options(TimeFormat::toSelectArray())
|
->options(TimeFormat::toSelectArray())
|
||||||
->required(),
|
->required(),
|
||||||
Forms\Components\Select::make('currency')
|
Select::make('currency')
|
||||||
->label('Currency')
|
->label('Currency')
|
||||||
->options(function (): array {
|
->options(function (): array {
|
||||||
$currencies = ISOCurrencyProvider::getInstance()->getAvailableCurrencies();
|
$currencies = ISOCurrencyProvider::getInstance()->getAvailableCurrencies();
|
||||||
@@ -114,22 +114,22 @@ class OrganizationResource extends Resource
|
|||||||
{
|
{
|
||||||
return $table
|
return $table
|
||||||
->columns([
|
->columns([
|
||||||
Tables\Columns\TextColumn::make('name')
|
TextColumn::make('name')
|
||||||
->searchable()
|
->searchable()
|
||||||
->sortable(),
|
->sortable(),
|
||||||
Tables\Columns\IconColumn::make('personal_team')
|
Tables\Columns\IconColumn::make('personal_team')
|
||||||
->boolean()
|
->boolean()
|
||||||
->label('Is personal?')
|
->label('Is personal?')
|
||||||
->sortable(),
|
->sortable(),
|
||||||
Tables\Columns\TextColumn::make('owner.email')
|
TextColumn::make('owner.email')
|
||||||
->sortable(),
|
->sortable(),
|
||||||
Tables\Columns\TextColumn::make('currency'),
|
TextColumn::make('currency'),
|
||||||
TextColumn::make('billable_rate')
|
TextColumn::make('billable_rate')
|
||||||
->money(fn (Organization $resource) => $resource->currency, divideBy: 100),
|
->money(fn (Organization $resource) => $resource->currency, divideBy: 100),
|
||||||
Tables\Columns\TextColumn::make('created_at')
|
TextColumn::make('created_at')
|
||||||
->dateTime()
|
->dateTime()
|
||||||
->sortable(),
|
->sortable(),
|
||||||
Tables\Columns\TextColumn::make('updated_at')
|
TextColumn::make('updated_at')
|
||||||
->dateTime()
|
->dateTime()
|
||||||
->sortable()
|
->sortable()
|
||||||
->toggleable(isToggledHiddenByDefault: true),
|
->toggleable(isToggledHiddenByDefault: true),
|
||||||
@@ -223,7 +223,7 @@ class OrganizationResource extends Resource
|
|||||||
|
|
||||||
return $select;
|
return $select;
|
||||||
}),
|
}),
|
||||||
Forms\Components\Select::make('timezone')
|
Select::make('timezone')
|
||||||
->label('Timezone')
|
->label('Timezone')
|
||||||
->options(fn (): array => app(TimezoneService::class)->getSelectOptions())
|
->options(fn (): array => app(TimezoneService::class)->getSelectOptions())
|
||||||
->searchable()
|
->searchable()
|
||||||
|
|||||||
@@ -49,13 +49,13 @@ class UsersRelationManager extends RelationManager
|
|||||||
return $table
|
return $table
|
||||||
->recordTitleAttribute('name')
|
->recordTitleAttribute('name')
|
||||||
->columns([
|
->columns([
|
||||||
Tables\Columns\TextColumn::make('name'),
|
TextColumn::make('name'),
|
||||||
Tables\Columns\TextColumn::make('role'),
|
TextColumn::make('role'),
|
||||||
TextColumn::make('billable_rate')
|
TextColumn::make('billable_rate')
|
||||||
->money($organization->currency, divideBy: 100),
|
->money($organization->currency, divideBy: 100),
|
||||||
])
|
])
|
||||||
->headerActions([
|
->headerActions([
|
||||||
Tables\Actions\AttachAction::make()
|
AttachAction::make()
|
||||||
->recordTitle(fn (User $record): string => "{$record->name} ({$record->email})")
|
->recordTitle(fn (User $record): string => "{$record->name} ({$record->email})")
|
||||||
->form(fn (AttachAction $action): array => [
|
->form(fn (AttachAction $action): array => [
|
||||||
$action->getRecordSelect(),
|
$action->getRecordSelect(),
|
||||||
|
|||||||
@@ -63,11 +63,11 @@ class ReportResource extends Resource
|
|||||||
return $record->getRawOriginal('properties');
|
return $record->getRawOriginal('properties');
|
||||||
})
|
})
|
||||||
->disabled(),
|
->disabled(),
|
||||||
Forms\Components\DateTimePicker::make('created_at')
|
DateTimePicker::make('created_at')
|
||||||
->label('Created At')
|
->label('Created At')
|
||||||
->hiddenOn(['create'])
|
->hiddenOn(['create'])
|
||||||
->disabled(),
|
->disabled(),
|
||||||
Forms\Components\DateTimePicker::make('updated_at')
|
DateTimePicker::make('updated_at')
|
||||||
->label('Updated At')
|
->label('Updated At')
|
||||||
->hiddenOn(['create'])
|
->hiddenOn(['create'])
|
||||||
->disabled(),
|
->disabled(),
|
||||||
@@ -78,10 +78,10 @@ class ReportResource extends Resource
|
|||||||
{
|
{
|
||||||
return $table
|
return $table
|
||||||
->columns([
|
->columns([
|
||||||
Tables\Columns\TextColumn::make('name')
|
TextColumn::make('name')
|
||||||
->searchable()
|
->searchable()
|
||||||
->sortable(),
|
->sortable(),
|
||||||
Tables\Columns\TextColumn::make('description')
|
TextColumn::make('description')
|
||||||
->searchable()
|
->searchable()
|
||||||
->sortable(),
|
->sortable(),
|
||||||
ToggleColumn::make('is_public')
|
ToggleColumn::make('is_public')
|
||||||
@@ -90,10 +90,10 @@ class ReportResource extends Resource
|
|||||||
TextColumn::make('organization.name')
|
TextColumn::make('organization.name')
|
||||||
->searchable()
|
->searchable()
|
||||||
->sortable(),
|
->sortable(),
|
||||||
Tables\Columns\TextColumn::make('created_at')
|
TextColumn::make('created_at')
|
||||||
->dateTime()
|
->dateTime()
|
||||||
->sortable(),
|
->sortable(),
|
||||||
Tables\Columns\TextColumn::make('updated_at')
|
TextColumn::make('updated_at')
|
||||||
->dateTime()
|
->dateTime()
|
||||||
->sortable()
|
->sortable()
|
||||||
->toggleable(isToggledHiddenByDefault: true),
|
->toggleable(isToggledHiddenByDefault: true),
|
||||||
|
|||||||
@@ -93,11 +93,11 @@ class TimeEntryResource extends Resource
|
|||||||
($record->end?->toDateTimeString('minute') ?? '...').')';
|
($record->end?->toDateTimeString('minute') ?? '...').')';
|
||||||
})
|
})
|
||||||
->label('Time'),
|
->label('Time'),
|
||||||
Tables\Columns\TextColumn::make('organization.name')
|
TextColumn::make('organization.name')
|
||||||
->sortable(),
|
->sortable(),
|
||||||
Tables\Columns\TextColumn::make('created_at')
|
TextColumn::make('created_at')
|
||||||
->sortable(),
|
->sortable(),
|
||||||
Tables\Columns\TextColumn::make('updated_at')
|
TextColumn::make('updated_at')
|
||||||
->sortable(),
|
->sortable(),
|
||||||
])
|
])
|
||||||
->filters([
|
->filters([
|
||||||
|
|||||||
@@ -47,17 +47,17 @@ class UserResource extends Resource
|
|||||||
return $form
|
return $form
|
||||||
->columns(1)
|
->columns(1)
|
||||||
->schema([
|
->schema([
|
||||||
Forms\Components\TextInput::make('id')
|
TextInput::make('id')
|
||||||
->label('ID')
|
->label('ID')
|
||||||
->disabled()
|
->disabled()
|
||||||
->visibleOn(['update', 'show'])
|
->visibleOn(['update', 'show'])
|
||||||
->readOnly()
|
->readOnly()
|
||||||
->maxLength(255),
|
->maxLength(255),
|
||||||
Forms\Components\TextInput::make('name')
|
TextInput::make('name')
|
||||||
->label('Name')
|
->label('Name')
|
||||||
->required()
|
->required()
|
||||||
->maxLength(255),
|
->maxLength(255),
|
||||||
Forms\Components\TextInput::make('email')
|
TextInput::make('email')
|
||||||
->label('Email')
|
->label('Email')
|
||||||
->required()
|
->required()
|
||||||
->rules($record?->is_placeholder ? [] : [
|
->rules($record?->is_placeholder ? [] : [
|
||||||
|
|||||||
@@ -20,7 +20,7 @@ class ApiTokenController extends Controller
|
|||||||
/**
|
/**
|
||||||
* List all api token of the currently authenticated user
|
* List all api token of the currently authenticated user
|
||||||
*
|
*
|
||||||
* This endpoint is independent of organization.
|
* This endpoint is independent of the organization.
|
||||||
*
|
*
|
||||||
* @operationId getApiTokens
|
* @operationId getApiTokens
|
||||||
*
|
*
|
||||||
@@ -35,6 +35,7 @@ class ApiTokenController extends Controller
|
|||||||
/** @var Builder<Client> $query */
|
/** @var Builder<Client> $query */
|
||||||
$query->whereJsonContains('grant_types', 'personal_access');
|
$query->whereJsonContains('grant_types', 'personal_access');
|
||||||
})
|
})
|
||||||
|
->orderBy('created_at', 'desc')
|
||||||
->get();
|
->get();
|
||||||
|
|
||||||
return new ApiTokenCollection($tokens);
|
return new ApiTokenCollection($tokens);
|
||||||
|
|||||||
@@ -41,6 +41,7 @@ class InvitationController extends Controller
|
|||||||
$this->checkPermission($organization, 'invitations:view');
|
$this->checkPermission($organization, 'invitations:view');
|
||||||
|
|
||||||
$invitations = $organization->teamInvitations()
|
$invitations = $organization->teamInvitations()
|
||||||
|
->orderBy('created_at', 'desc')
|
||||||
->paginate(config('app.pagination_per_page_default'));
|
->paginate(config('app.pagination_per_page_default'));
|
||||||
|
|
||||||
return InvitationCollection::make($invitations);
|
return InvitationCollection::make($invitations);
|
||||||
|
|||||||
@@ -60,6 +60,7 @@ class MemberController extends Controller
|
|||||||
$members = Member::query()
|
$members = Member::query()
|
||||||
->whereBelongsTo($organization, 'organization')
|
->whereBelongsTo($organization, 'organization')
|
||||||
->with(['user'])
|
->with(['user'])
|
||||||
|
->orderBy('created_at', 'desc')
|
||||||
->paginate(config('app.pagination_per_page_default'));
|
->paginate(config('app.pagination_per_page_default'));
|
||||||
|
|
||||||
return MemberCollection::make($members);
|
return MemberCollection::make($members);
|
||||||
|
|||||||
@@ -5,11 +5,17 @@ declare(strict_types=1);
|
|||||||
namespace App\Http\Controllers\Api\V1;
|
namespace App\Http\Controllers\Api\V1;
|
||||||
|
|
||||||
use App\Enums\Role;
|
use App\Enums\Role;
|
||||||
|
use App\Events\AfterCreateOrganization;
|
||||||
|
use App\Http\Requests\V1\Organization\OrganizationStoreRequest;
|
||||||
use App\Http\Requests\V1\Organization\OrganizationUpdateRequest;
|
use App\Http\Requests\V1\Organization\OrganizationUpdateRequest;
|
||||||
use App\Http\Resources\V1\Organization\OrganizationResource;
|
use App\Http\Resources\V1\Organization\OrganizationResource;
|
||||||
use App\Models\Organization;
|
use App\Models\Organization;
|
||||||
use App\Service\BillableRateService;
|
use App\Service\BillableRateService;
|
||||||
|
use App\Service\DeletionService;
|
||||||
|
use App\Service\IpLookup\IpLookupServiceContract;
|
||||||
|
use App\Service\OrganizationService;
|
||||||
use Illuminate\Auth\Access\AuthorizationException;
|
use Illuminate\Auth\Access\AuthorizationException;
|
||||||
|
use Illuminate\Http\JsonResponse;
|
||||||
|
|
||||||
class OrganizationController extends Controller
|
class OrganizationController extends Controller
|
||||||
{
|
{
|
||||||
@@ -80,4 +86,48 @@ class OrganizationController extends Controller
|
|||||||
|
|
||||||
return new OrganizationResource($organization, true);
|
return new OrganizationResource($organization, true);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Create organization
|
||||||
|
*
|
||||||
|
* @operationId createOrganization
|
||||||
|
*/
|
||||||
|
public function store(OrganizationStoreRequest $request, OrganizationService $organizationService): OrganizationResource
|
||||||
|
{
|
||||||
|
$user = $this->user();
|
||||||
|
$ipLookupResponse = app(IpLookupServiceContract::class)->lookup($request->ip());
|
||||||
|
|
||||||
|
$currency = $ipLookupResponse?->currency;
|
||||||
|
|
||||||
|
$organization = $organizationService->createOrganization(
|
||||||
|
$request->getName(),
|
||||||
|
$user,
|
||||||
|
false,
|
||||||
|
$currency
|
||||||
|
);
|
||||||
|
|
||||||
|
$user->switchTeam($organization);
|
||||||
|
|
||||||
|
// Note: The refresh is necessary for currently unknown reasons. Do not remove it.
|
||||||
|
$organization = $organization->refresh();
|
||||||
|
AfterCreateOrganization::dispatch($organization);
|
||||||
|
|
||||||
|
return new OrganizationResource($organization, true);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Delete organization
|
||||||
|
*
|
||||||
|
* @operationId deleteOrganization
|
||||||
|
*
|
||||||
|
* @throws AuthorizationException
|
||||||
|
*/
|
||||||
|
public function destroy(Organization $organization, DeletionService $deletionService): JsonResponse
|
||||||
|
{
|
||||||
|
$this->checkPermission($organization, 'organizations:delete');
|
||||||
|
|
||||||
|
$deletionService->deleteOrganization($organization);
|
||||||
|
|
||||||
|
return response()->json(null, 204);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -60,7 +60,9 @@ class ProjectController extends Controller
|
|||||||
$projectsQuery->whereNull('archived_at');
|
$projectsQuery->whereNull('archived_at');
|
||||||
}
|
}
|
||||||
|
|
||||||
$projects = $projectsQuery->paginate(config('app.pagination_per_page_default'));
|
$projects = $projectsQuery
|
||||||
|
->orderBy('created_at', 'desc')
|
||||||
|
->paginate(config('app.pagination_per_page_default'));
|
||||||
|
|
||||||
$showBillableRate = $this->member($organization)->role !== Role::Employee->value || $organization->employees_can_see_billable_rates;
|
$showBillableRate = $this->member($organization)->role !== Role::Employee->value || $organization->employees_can_see_billable_rates;
|
||||||
|
|
||||||
@@ -76,7 +78,7 @@ class ProjectController extends Controller
|
|||||||
*/
|
*/
|
||||||
public function show(Organization $organization, Project $project): JsonResource
|
public function show(Organization $organization, Project $project): JsonResource
|
||||||
{
|
{
|
||||||
$this->checkPermission($organization, 'projects:view', $project);
|
$this->checkPermission($organization, 'projects:view:all', $project);
|
||||||
|
|
||||||
// Note: There is currently no need to check if a user is a member of the project,
|
// Note: There is currently no need to check if a user is a member of the project,
|
||||||
// since this is only relevant for users with the role "employee" and they can not access this endpoint.
|
// since this is only relevant for users with the role "employee" and they can not access this endpoint.
|
||||||
|
|||||||
@@ -6,6 +6,7 @@ namespace App\Http\Controllers\Api\V1;
|
|||||||
|
|
||||||
use App\Exceptions\Api\InactiveUserCanNotBeUsedApiException;
|
use App\Exceptions\Api\InactiveUserCanNotBeUsedApiException;
|
||||||
use App\Exceptions\Api\UserIsAlreadyMemberOfProjectApiException;
|
use App\Exceptions\Api\UserIsAlreadyMemberOfProjectApiException;
|
||||||
|
use App\Http\Requests\V1\ProjectMember\ProjectMemberIndexRequest;
|
||||||
use App\Http\Requests\V1\ProjectMember\ProjectMemberStoreRequest;
|
use App\Http\Requests\V1\ProjectMember\ProjectMemberStoreRequest;
|
||||||
use App\Http\Requests\V1\ProjectMember\ProjectMemberUpdateRequest;
|
use App\Http\Requests\V1\ProjectMember\ProjectMemberUpdateRequest;
|
||||||
use App\Http\Resources\V1\ProjectMember\ProjectMemberCollection;
|
use App\Http\Resources\V1\ProjectMember\ProjectMemberCollection;
|
||||||
@@ -41,12 +42,13 @@ class ProjectMemberController extends Controller
|
|||||||
*
|
*
|
||||||
* @operationId getProjectMembers
|
* @operationId getProjectMembers
|
||||||
*/
|
*/
|
||||||
public function index(Organization $organization, Project $project): ProjectMemberCollection
|
public function index(Organization $organization, Project $project, ProjectMemberIndexRequest $request): ProjectMemberCollection
|
||||||
{
|
{
|
||||||
$this->checkPermission($organization, 'project-members:view', $project);
|
$this->checkPermission($organization, 'project-members:view', $project);
|
||||||
|
|
||||||
$projectMembers = ProjectMember::query()
|
$projectMembers = ProjectMember::query()
|
||||||
->whereBelongsTo($project, 'project')
|
->whereBelongsTo($project, 'project')
|
||||||
|
->orderBy('created_at', 'desc')
|
||||||
->paginate(config('app.pagination_per_page_default'));
|
->paginate(config('app.pagination_per_page_default'));
|
||||||
|
|
||||||
return new ProjectMemberCollection($projectMembers);
|
return new ProjectMemberCollection($projectMembers);
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ declare(strict_types=1);
|
|||||||
namespace App\Http\Controllers\Api\V1;
|
namespace App\Http\Controllers\Api\V1;
|
||||||
|
|
||||||
use App\Enums\Weekday;
|
use App\Enums\Weekday;
|
||||||
|
use App\Http\Requests\V1\Report\ReportIndexRequest;
|
||||||
use App\Http\Requests\V1\Report\ReportStoreRequest;
|
use App\Http\Requests\V1\Report\ReportStoreRequest;
|
||||||
use App\Http\Requests\V1\Report\ReportUpdateRequest;
|
use App\Http\Requests\V1\Report\ReportUpdateRequest;
|
||||||
use App\Http\Resources\V1\Report\DetailedReportResource;
|
use App\Http\Resources\V1\Report\DetailedReportResource;
|
||||||
@@ -40,7 +41,7 @@ class ReportController extends Controller
|
|||||||
*
|
*
|
||||||
* @operationId getReports
|
* @operationId getReports
|
||||||
*/
|
*/
|
||||||
public function index(Organization $organization): ReportCollection
|
public function index(Organization $organization, ReportIndexRequest $request): ReportCollection
|
||||||
{
|
{
|
||||||
$this->checkPermission($organization, 'reports:view');
|
$this->checkPermission($organization, 'reports:view');
|
||||||
|
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ declare(strict_types=1);
|
|||||||
namespace App\Http\Controllers\Api\V1;
|
namespace App\Http\Controllers\Api\V1;
|
||||||
|
|
||||||
use App\Exceptions\Api\EntityStillInUseApiException;
|
use App\Exceptions\Api\EntityStillInUseApiException;
|
||||||
|
use App\Http\Requests\V1\Tag\TagIndexRequest;
|
||||||
use App\Http\Requests\V1\Tag\TagStoreRequest;
|
use App\Http\Requests\V1\Tag\TagStoreRequest;
|
||||||
use App\Http\Requests\V1\Tag\TagUpdateRequest;
|
use App\Http\Requests\V1\Tag\TagUpdateRequest;
|
||||||
use App\Http\Resources\V1\Tag\TagCollection;
|
use App\Http\Resources\V1\Tag\TagCollection;
|
||||||
@@ -34,7 +35,7 @@ class TagController extends Controller
|
|||||||
*
|
*
|
||||||
* @throws AuthorizationException
|
* @throws AuthorizationException
|
||||||
*/
|
*/
|
||||||
public function index(Organization $organization): TagCollection
|
public function index(Organization $organization, TagIndexRequest $request): TagCollection
|
||||||
{
|
{
|
||||||
$this->checkPermission($organization, 'tags:view');
|
$this->checkPermission($organization, 'tags:view');
|
||||||
|
|
||||||
|
|||||||
@@ -82,7 +82,9 @@ class TaskController extends Controller
|
|||||||
$query->whereNull('done_at');
|
$query->whereNull('done_at');
|
||||||
}
|
}
|
||||||
|
|
||||||
$tasks = $query->paginate(config('app.pagination_per_page_default'));
|
$tasks = $query
|
||||||
|
->orderBy('created_at', 'desc')
|
||||||
|
->paginate(config('app.pagination_per_page_default'));
|
||||||
|
|
||||||
return new TaskCollection($tasks);
|
return new TaskCollection($tasks);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -53,12 +53,13 @@ use Illuminate\Support\Facades\Blade;
|
|||||||
use Illuminate\Support\Facades\DB;
|
use Illuminate\Support\Facades\DB;
|
||||||
use Illuminate\Support\Facades\Log;
|
use Illuminate\Support\Facades\Log;
|
||||||
use Illuminate\Support\Facades\Storage;
|
use Illuminate\Support\Facades\Storage;
|
||||||
|
use Illuminate\Support\Str;
|
||||||
use Maatwebsite\Excel\Facades\Excel;
|
use Maatwebsite\Excel\Facades\Excel;
|
||||||
use Spatie\TemporaryDirectory\TemporaryDirectory;
|
use Spatie\TemporaryDirectory\TemporaryDirectory;
|
||||||
|
|
||||||
class TimeEntryController extends Controller
|
class TimeEntryController extends Controller
|
||||||
{
|
{
|
||||||
private function assertNoOverlap(Organization $organization, Member $member, \Illuminate\Support\Carbon $start, ?\Illuminate\Support\Carbon $end, ?TimeEntry $exclude = null): void
|
private function assertNoOverlap(Organization $organization, Member $member, Carbon $start, ?Carbon $end, ?TimeEntry $exclude = null): void
|
||||||
{
|
{
|
||||||
if (! $organization->prevent_overlapping_time_entries) {
|
if (! $organization->prevent_overlapping_time_entries) {
|
||||||
return;
|
return;
|
||||||
@@ -246,7 +247,7 @@ class TimeEntryController extends Controller
|
|||||||
'user',
|
'user',
|
||||||
'tagsRelation',
|
'tagsRelation',
|
||||||
]);
|
]);
|
||||||
$filename = 'time-entries-export-'.now()->format('Y-m-d_H-i-s').'.'.$format->getFileExtension();
|
$filename = 'time-entries-export-'.now()->format('Y-m-d_H-i-s').'-'.Str::uuid().'.'.$format->getFileExtension();
|
||||||
$folderPath = 'exports';
|
$folderPath = 'exports';
|
||||||
$path = $folderPath.'/'.$filename;
|
$path = $folderPath.'/'.$filename;
|
||||||
$localizationService = LocalizationService::forOrganization($organization);
|
$localizationService = LocalizationService::forOrganization($organization);
|
||||||
@@ -469,7 +470,7 @@ class TimeEntryController extends Controller
|
|||||||
$timezone = app(TimezoneService::class)->getTimezoneFromUser($this->user());
|
$timezone = app(TimezoneService::class)->getTimezoneFromUser($this->user());
|
||||||
$localizationService = LocalizationService::forOrganization($organization);
|
$localizationService = LocalizationService::forOrganization($organization);
|
||||||
|
|
||||||
$filename = 'time-entries-report-'.now()->format('Y-m-d_H-i-s').'.'.$format->getFileExtension();
|
$filename = 'time-entries-report-'.now()->format('Y-m-d_H-i-s').'-'.Str::uuid().'.'.$format->getFileExtension();
|
||||||
$folderPath = 'exports';
|
$folderPath = 'exports';
|
||||||
$path = $folderPath.'/'.$filename;
|
$path = $folderPath.'/'.$filename;
|
||||||
|
|
||||||
@@ -628,9 +629,9 @@ class TimeEntryController extends Controller
|
|||||||
/** @var Member|null $member */
|
/** @var Member|null $member */
|
||||||
$member = $request->has('member_id') ? Member::query()->findOrFail($request->input('member_id')) : null;
|
$member = $request->has('member_id') ? Member::query()->findOrFail($request->input('member_id')) : null;
|
||||||
if ($timeEntry->member->user_id === Auth::id() && ($member === null || $member->user_id === Auth::id())) {
|
if ($timeEntry->member->user_id === Auth::id() && ($member === null || $member->user_id === Auth::id())) {
|
||||||
$this->checkPermission($organization, 'time-entries:update:own');
|
$this->checkPermission($organization, 'time-entries:update:own', $timeEntry);
|
||||||
} else {
|
} else {
|
||||||
$this->checkPermission($organization, 'time-entries:update:all');
|
$this->checkPermission($organization, 'time-entries:update:all', $timeEntry);
|
||||||
}
|
}
|
||||||
|
|
||||||
if ($timeEntry->end !== null && $request->has('end') && $request->input('end') === null) {
|
if ($timeEntry->end !== null && $request->has('end') && $request->input('end') === null) {
|
||||||
|
|||||||
@@ -4,15 +4,26 @@ declare(strict_types=1);
|
|||||||
|
|
||||||
namespace App\Http\Controllers\Api\V1;
|
namespace App\Http\Controllers\Api\V1;
|
||||||
|
|
||||||
|
use App\Exceptions\Api\CanNotDeleteUserWhoIsOwnerOfOrganizationWithMultipleMembers;
|
||||||
|
use App\Exceptions\Api\UserResendEmailVerificationNoPendingEmailApiException;
|
||||||
|
use App\Http\Requests\V1\User\UserUpdateRequest;
|
||||||
use App\Http\Resources\V1\User\UserResource;
|
use App\Http\Resources\V1\User\UserResource;
|
||||||
|
use App\Mail\VerifyUpdatedEmailMail;
|
||||||
|
use App\Models\User;
|
||||||
|
use App\Service\DeletionService;
|
||||||
|
use App\Support\Base64File;
|
||||||
use Illuminate\Auth\Access\AuthorizationException;
|
use Illuminate\Auth\Access\AuthorizationException;
|
||||||
|
use Illuminate\Http\JsonResponse;
|
||||||
|
use Illuminate\Support\Facades\Mail;
|
||||||
|
use Illuminate\Support\Facades\Storage;
|
||||||
|
use Illuminate\Support\Str;
|
||||||
|
|
||||||
class UserController extends Controller
|
class UserController extends Controller
|
||||||
{
|
{
|
||||||
/**
|
/**
|
||||||
* Get the current user
|
* Get the current user
|
||||||
*
|
*
|
||||||
* This endpoint is independent of organization.
|
* This endpoint is independent of the organization.
|
||||||
*
|
*
|
||||||
* @operationId getMe
|
* @operationId getMe
|
||||||
*
|
*
|
||||||
@@ -24,4 +35,119 @@ class UserController extends Controller
|
|||||||
|
|
||||||
return new UserResource($user);
|
return new UserResource($user);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Update the current user
|
||||||
|
*
|
||||||
|
* This endpoint is independent of the organization.
|
||||||
|
*
|
||||||
|
* @operationId updateUser
|
||||||
|
*/
|
||||||
|
public function update(User $user, UserUpdateRequest $request): UserResource
|
||||||
|
{
|
||||||
|
if ($user->getKey() !== $this->user()->getKey()) {
|
||||||
|
throw new AuthorizationException;
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($request->hasPhotoKey()) {
|
||||||
|
$photoDisk = (string) config('jetstream.profile_photo_disk', 'public');
|
||||||
|
$previousPhotoPath = $user->profile_photo_path;
|
||||||
|
$newPhoto = $request->getPhoto();
|
||||||
|
|
||||||
|
if ($newPhoto === null) {
|
||||||
|
$user->profile_photo_path = null;
|
||||||
|
} else {
|
||||||
|
$decoded = Base64File::decode($newPhoto);
|
||||||
|
assert($decoded !== null);
|
||||||
|
$extension = Base64File::extension($decoded['mime_type']);
|
||||||
|
assert($extension !== null);
|
||||||
|
|
||||||
|
$photoPath = 'profile-photos/'.Str::uuid().'.'.$extension;
|
||||||
|
Storage::disk($photoDisk)->put($photoPath, $decoded['data'], 'public');
|
||||||
|
$user->profile_photo_path = $photoPath;
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($previousPhotoPath !== null) {
|
||||||
|
Storage::disk($photoDisk)->delete($previousPhotoPath);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
$emailToVerify = null;
|
||||||
|
$email = $request->getEmail();
|
||||||
|
if ($email !== null && $email !== Str::lower($user->email)) {
|
||||||
|
$emailToVerify = $email;
|
||||||
|
$user->pending_email = $email;
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($request->getName() !== null) {
|
||||||
|
$user->name = $request->getName();
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($request->getTimezone() !== null) {
|
||||||
|
$user->timezone = $request->getTimezone();
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($request->getWeekStart() !== null) {
|
||||||
|
$user->week_start = $request->getWeekStart();
|
||||||
|
}
|
||||||
|
|
||||||
|
$user->save();
|
||||||
|
|
||||||
|
if ($emailToVerify !== null) {
|
||||||
|
Mail::to($emailToVerify)->send(new VerifyUpdatedEmailMail($user, $emailToVerify));
|
||||||
|
}
|
||||||
|
|
||||||
|
return new UserResource($user);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Resend the pending email update verification email.
|
||||||
|
*
|
||||||
|
* This endpoint is independent of the organization.
|
||||||
|
*
|
||||||
|
* @operationId resendUserEmailVerification
|
||||||
|
*
|
||||||
|
* @throws AuthorizationException Thrown when the authenticated user does not match the user whose email is pending verification.
|
||||||
|
* @throws UserResendEmailVerificationNoPendingEmailApiException Thrown when the user does not have a pending email to verify.
|
||||||
|
*/
|
||||||
|
public function resendEmailVerification(User $user): JsonResponse
|
||||||
|
{
|
||||||
|
if ($user->getKey() !== $this->user()->getKey()) {
|
||||||
|
throw new AuthorizationException;
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($user->pending_email === null) {
|
||||||
|
throw new UserResendEmailVerificationNoPendingEmailApiException;
|
||||||
|
}
|
||||||
|
|
||||||
|
Mail::to($user->pending_email)
|
||||||
|
->queue(new VerifyUpdatedEmailMail($user, $user->pending_email));
|
||||||
|
|
||||||
|
return response()->json(null, 204);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Handles the deletion of a user.
|
||||||
|
*
|
||||||
|
* This endpoint is independent of the organization.
|
||||||
|
*
|
||||||
|
* @operationId deleteUser
|
||||||
|
*
|
||||||
|
* @param User $user The user instance to be deleted.
|
||||||
|
* @param DeletionService $deletionService The service responsible for performing the user deletion.
|
||||||
|
* @return JsonResponse A JSON response with a 204 No Content status upon successful deletion.
|
||||||
|
*
|
||||||
|
* @throws AuthorizationException Thrown when the authenticated user does not match the user to be deleted.
|
||||||
|
* @throws CanNotDeleteUserWhoIsOwnerOfOrganizationWithMultipleMembers Thrown when the user to be deleted is the owner of an organization with multiple members.
|
||||||
|
*/
|
||||||
|
public function destroy(User $user, DeletionService $deletionService): JsonResponse
|
||||||
|
{
|
||||||
|
if ($user->getKey() !== $this->user()->getKey()) {
|
||||||
|
throw new AuthorizationException;
|
||||||
|
}
|
||||||
|
|
||||||
|
$deletionService->deleteUser($user);
|
||||||
|
|
||||||
|
return response()->json(null, 204);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -14,7 +14,7 @@ class UserMembershipController extends Controller
|
|||||||
/**
|
/**
|
||||||
* Get the memberships of the current user
|
* Get the memberships of the current user
|
||||||
*
|
*
|
||||||
* This endpoint is independent of organization.
|
* This endpoint is independent of the organization.
|
||||||
*
|
*
|
||||||
* @operationId getMyMemberships
|
* @operationId getMyMemberships
|
||||||
*
|
*
|
||||||
|
|||||||
@@ -17,7 +17,7 @@ class UserTimeEntryController extends Controller
|
|||||||
/**
|
/**
|
||||||
* Get the active time entry of the current user
|
* Get the active time entry of the current user
|
||||||
*
|
*
|
||||||
* This endpoint is independent of organization.
|
* This endpoint is independent of the organization.
|
||||||
*
|
*
|
||||||
* @operationId getMyActiveTimeEntry
|
* @operationId getMyActiveTimeEntry
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -4,30 +4,13 @@ declare(strict_types=1);
|
|||||||
|
|
||||||
namespace App\Http\Controllers\Web;
|
namespace App\Http\Controllers\Web;
|
||||||
|
|
||||||
use App\Enums\Role;
|
|
||||||
use App\Service\DashboardService;
|
|
||||||
use App\Service\PermissionStore;
|
|
||||||
use Illuminate\Auth\Access\AuthorizationException;
|
|
||||||
use Inertia\Inertia;
|
use Inertia\Inertia;
|
||||||
use Inertia\Response;
|
use Inertia\Response;
|
||||||
|
|
||||||
class DashboardController extends Controller
|
class DashboardController extends Controller
|
||||||
{
|
{
|
||||||
/**
|
public function dashboard(): Response
|
||||||
* @throws AuthorizationException
|
|
||||||
*/
|
|
||||||
public function dashboard(DashboardService $dashboardService, PermissionStore $permissionStore): Response
|
|
||||||
{
|
{
|
||||||
$user = $this->user();
|
|
||||||
$organization = $this->currentOrganization();
|
|
||||||
|
|
||||||
$latestTeamActivity = null;
|
|
||||||
if ($permissionStore->has($organization, 'time-entries:view:all')) {
|
|
||||||
$latestTeamActivity = $dashboardService->latestTeamActivity($organization);
|
|
||||||
}
|
|
||||||
|
|
||||||
$showBillableRate = $this->member($organization)->role !== Role::Employee->value || $organization->employees_can_see_billable_rates;
|
|
||||||
|
|
||||||
return Inertia::render('Dashboard');
|
return Inertia::render('Dashboard');
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,75 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Http\Controllers\Web;
|
||||||
|
|
||||||
|
use App\Enums\Role;
|
||||||
|
use App\Models\OrganizationInvitation;
|
||||||
|
use App\Models\User;
|
||||||
|
use App\Service\MemberService;
|
||||||
|
use Illuminate\Http\RedirectResponse;
|
||||||
|
use Illuminate\Support\Facades\Auth;
|
||||||
|
use RuntimeException;
|
||||||
|
|
||||||
|
class OrganizationInvitationController extends Controller
|
||||||
|
{
|
||||||
|
public function accept(OrganizationInvitation $invitation, MemberService $memberService): RedirectResponse
|
||||||
|
{
|
||||||
|
$email = strtolower($invitation->email);
|
||||||
|
$role = Role::tryFrom($invitation->role);
|
||||||
|
if ($role === null || $role === Role::Owner || $role === Role::Placeholder) {
|
||||||
|
throw new RuntimeException('Invalid role');
|
||||||
|
}
|
||||||
|
|
||||||
|
$organization = $invitation->organization;
|
||||||
|
$invitee = User::query()
|
||||||
|
->where('email', $email)
|
||||||
|
->where('is_placeholder', '=', false)
|
||||||
|
->first();
|
||||||
|
|
||||||
|
// No account yet — finish on registration.
|
||||||
|
if ($invitee === null) {
|
||||||
|
if ($invitation->accepted_at === null) {
|
||||||
|
$invitation->accepted_at = now();
|
||||||
|
$invitation->save();
|
||||||
|
}
|
||||||
|
|
||||||
|
return redirect(route('register'))
|
||||||
|
->with('bannerText', __('Please create an account to finish joining the :organization organization.', [
|
||||||
|
'organization' => $organization->name,
|
||||||
|
]))
|
||||||
|
->with('bannerStyle', 'info');
|
||||||
|
}
|
||||||
|
|
||||||
|
$alreadyMember = $memberService->isEmailAlreadyMember($organization, $email);
|
||||||
|
if (! $alreadyMember) {
|
||||||
|
$memberService->addMember($invitee, $organization, $role);
|
||||||
|
$invitation->delete();
|
||||||
|
}
|
||||||
|
|
||||||
|
// Logged out — banner on /login.
|
||||||
|
if (! Auth::check()) {
|
||||||
|
return redirect(route('login'))
|
||||||
|
->with('bannerText', __('Great! You have accepted the invitation to join the :organization organization. Please log in to access it.', [
|
||||||
|
'organization' => $organization->name,
|
||||||
|
]))
|
||||||
|
->with('bannerStyle', 'success');
|
||||||
|
}
|
||||||
|
|
||||||
|
// Logged in — banner on /dashboard.
|
||||||
|
if ($alreadyMember) {
|
||||||
|
return redirect(route('dashboard'))
|
||||||
|
->with('bannerText', __('You are already a member of the :organization organization.', [
|
||||||
|
'organization' => $organization->name,
|
||||||
|
]))
|
||||||
|
->with('bannerStyle', 'danger');
|
||||||
|
}
|
||||||
|
|
||||||
|
return redirect(route('dashboard'))
|
||||||
|
->with('bannerText', __('Great! You have accepted the invitation to join the :organization organization.', [
|
||||||
|
'organization' => $organization->name,
|
||||||
|
]))
|
||||||
|
->with('bannerStyle', 'success');
|
||||||
|
}
|
||||||
|
}
|
||||||
53
app/Http/Controllers/Web/UserController.php
Normal file
53
app/Http/Controllers/Web/UserController.php
Normal file
@@ -0,0 +1,53 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Http\Controllers\Web;
|
||||||
|
|
||||||
|
use App\Models\User;
|
||||||
|
use Illuminate\Http\RedirectResponse;
|
||||||
|
use Illuminate\Http\Request;
|
||||||
|
use Illuminate\Support\Carbon;
|
||||||
|
use Illuminate\Support\Str;
|
||||||
|
|
||||||
|
class UserController extends Controller
|
||||||
|
{
|
||||||
|
public function verifyEmailChange(Request $request, User $user): RedirectResponse
|
||||||
|
{
|
||||||
|
if ($request->user()?->getAuthIdentifier() !== $user->getKey()) {
|
||||||
|
abort(403);
|
||||||
|
}
|
||||||
|
|
||||||
|
$email = $request->query('email');
|
||||||
|
if (! is_string($email)) {
|
||||||
|
abort(403);
|
||||||
|
}
|
||||||
|
|
||||||
|
$email = Str::lower($email);
|
||||||
|
|
||||||
|
if ($user->pending_email !== $email) {
|
||||||
|
abort(403);
|
||||||
|
}
|
||||||
|
|
||||||
|
$emailAlreadyInUse = User::query()
|
||||||
|
->where('email', '=', $email)
|
||||||
|
->where('is_placeholder', '=', false)
|
||||||
|
->whereKeyNot($user->getKey())
|
||||||
|
->exists();
|
||||||
|
|
||||||
|
if ($emailAlreadyInUse) {
|
||||||
|
return redirect(route('dashboard'))
|
||||||
|
->with('bannerStyle', 'danger')
|
||||||
|
->with('bannerText', __('The email address is already in use.'));
|
||||||
|
}
|
||||||
|
|
||||||
|
$user->email = $email;
|
||||||
|
$user->pending_email = null;
|
||||||
|
$user->email_verified_at = Carbon::now();
|
||||||
|
$user->save();
|
||||||
|
|
||||||
|
return redirect(route('dashboard'))
|
||||||
|
->with('bannerStyle', 'success')
|
||||||
|
->with('bannerText', __('Your email address has been updated successfully.'));
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -4,9 +4,37 @@ declare(strict_types=1);
|
|||||||
|
|
||||||
namespace App\Http;
|
namespace App\Http;
|
||||||
|
|
||||||
|
use App\Http\Middleware\Authenticate;
|
||||||
use App\Http\Middleware\CheckOrganizationBlocked;
|
use App\Http\Middleware\CheckOrganizationBlocked;
|
||||||
|
use App\Http\Middleware\EncryptCookies;
|
||||||
|
use App\Http\Middleware\EnsureEmailIsVerified;
|
||||||
|
use App\Http\Middleware\ForceHttps;
|
||||||
use App\Http\Middleware\ForceJsonResponse;
|
use App\Http\Middleware\ForceJsonResponse;
|
||||||
|
use App\Http\Middleware\HandleInertiaRequests;
|
||||||
|
use App\Http\Middleware\PreventRequestsDuringMaintenance;
|
||||||
|
use App\Http\Middleware\RedirectIfAuthenticated;
|
||||||
|
use App\Http\Middleware\ShareInertiaData;
|
||||||
|
use App\Http\Middleware\TrimStrings;
|
||||||
|
use App\Http\Middleware\TrustProxies;
|
||||||
|
use App\Http\Middleware\ValidateSignature;
|
||||||
|
use App\Http\Middleware\VerifyCsrfToken;
|
||||||
|
use Illuminate\Auth\Middleware\AuthenticateWithBasicAuth;
|
||||||
|
use Illuminate\Auth\Middleware\Authorize;
|
||||||
|
use Illuminate\Auth\Middleware\RequirePassword;
|
||||||
|
use Illuminate\Cookie\Middleware\AddQueuedCookiesToResponse;
|
||||||
use Illuminate\Foundation\Http\Kernel as HttpKernel;
|
use Illuminate\Foundation\Http\Kernel as HttpKernel;
|
||||||
|
use Illuminate\Foundation\Http\Middleware\ConvertEmptyStringsToNull;
|
||||||
|
use Illuminate\Foundation\Http\Middleware\HandlePrecognitiveRequests;
|
||||||
|
use Illuminate\Foundation\Http\Middleware\ValidatePostSize;
|
||||||
|
use Illuminate\Http\Middleware\AddLinkHeadersForPreloadedAssets;
|
||||||
|
use Illuminate\Http\Middleware\HandleCors;
|
||||||
|
use Illuminate\Http\Middleware\SetCacheHeaders;
|
||||||
|
use Illuminate\Routing\Middleware\SubstituteBindings;
|
||||||
|
use Illuminate\Routing\Middleware\ThrottleRequests;
|
||||||
|
use Illuminate\Session\Middleware\AuthenticateSession;
|
||||||
|
use Illuminate\Session\Middleware\StartSession;
|
||||||
|
use Illuminate\View\Middleware\ShareErrorsFromSession;
|
||||||
|
use Laravel\Passport\Http\Middleware\CreateFreshApiToken;
|
||||||
|
|
||||||
class Kernel extends HttpKernel
|
class Kernel extends HttpKernel
|
||||||
{
|
{
|
||||||
@@ -18,13 +46,13 @@ class Kernel extends HttpKernel
|
|||||||
* @var array<int, class-string|string>
|
* @var array<int, class-string|string>
|
||||||
*/
|
*/
|
||||||
protected $middleware = [
|
protected $middleware = [
|
||||||
\App\Http\Middleware\ForceHttps::class,
|
ForceHttps::class,
|
||||||
\App\Http\Middleware\TrustProxies::class,
|
TrustProxies::class,
|
||||||
\Illuminate\Http\Middleware\HandleCors::class,
|
HandleCors::class,
|
||||||
\App\Http\Middleware\PreventRequestsDuringMaintenance::class,
|
PreventRequestsDuringMaintenance::class,
|
||||||
\Illuminate\Foundation\Http\Middleware\ValidatePostSize::class,
|
ValidatePostSize::class,
|
||||||
\App\Http\Middleware\TrimStrings::class,
|
TrimStrings::class,
|
||||||
\Illuminate\Foundation\Http\Middleware\ConvertEmptyStringsToNull::class,
|
ConvertEmptyStringsToNull::class,
|
||||||
];
|
];
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -34,21 +62,21 @@ class Kernel extends HttpKernel
|
|||||||
*/
|
*/
|
||||||
protected $middlewareGroups = [
|
protected $middlewareGroups = [
|
||||||
'web' => [
|
'web' => [
|
||||||
\App\Http\Middleware\EncryptCookies::class,
|
EncryptCookies::class,
|
||||||
\Illuminate\Cookie\Middleware\AddQueuedCookiesToResponse::class,
|
AddQueuedCookiesToResponse::class,
|
||||||
\Illuminate\Session\Middleware\StartSession::class,
|
StartSession::class,
|
||||||
\Illuminate\View\Middleware\ShareErrorsFromSession::class,
|
ShareErrorsFromSession::class,
|
||||||
\App\Http\Middleware\VerifyCsrfToken::class,
|
VerifyCsrfToken::class,
|
||||||
\Illuminate\Routing\Middleware\SubstituteBindings::class,
|
SubstituteBindings::class,
|
||||||
\App\Http\Middleware\HandleInertiaRequests::class,
|
HandleInertiaRequests::class,
|
||||||
\App\Http\Middleware\ShareInertiaData::class,
|
ShareInertiaData::class,
|
||||||
\Illuminate\Http\Middleware\AddLinkHeadersForPreloadedAssets::class,
|
AddLinkHeadersForPreloadedAssets::class,
|
||||||
\Laravel\Passport\Http\Middleware\CreateFreshApiToken::class,
|
CreateFreshApiToken::class,
|
||||||
],
|
],
|
||||||
|
|
||||||
'api' => [
|
'api' => [
|
||||||
\Illuminate\Routing\Middleware\ThrottleRequests::class.':api',
|
ThrottleRequests::class.':api',
|
||||||
\Illuminate\Routing\Middleware\SubstituteBindings::class,
|
SubstituteBindings::class,
|
||||||
ForceJsonResponse::class,
|
ForceJsonResponse::class,
|
||||||
],
|
],
|
||||||
|
|
||||||
@@ -64,17 +92,17 @@ class Kernel extends HttpKernel
|
|||||||
* @var array<string, class-string|string>
|
* @var array<string, class-string|string>
|
||||||
*/
|
*/
|
||||||
protected $middlewareAliases = [
|
protected $middlewareAliases = [
|
||||||
'auth' => \App\Http\Middleware\Authenticate::class,
|
'auth' => Authenticate::class,
|
||||||
'auth.basic' => \Illuminate\Auth\Middleware\AuthenticateWithBasicAuth::class,
|
'auth.basic' => AuthenticateWithBasicAuth::class,
|
||||||
'auth.session' => \Illuminate\Session\Middleware\AuthenticateSession::class,
|
'auth.session' => AuthenticateSession::class,
|
||||||
'cache.headers' => \Illuminate\Http\Middleware\SetCacheHeaders::class,
|
'cache.headers' => SetCacheHeaders::class,
|
||||||
'can' => \Illuminate\Auth\Middleware\Authorize::class,
|
'can' => Authorize::class,
|
||||||
'guest' => \App\Http\Middleware\RedirectIfAuthenticated::class,
|
'guest' => RedirectIfAuthenticated::class,
|
||||||
'password.confirm' => \Illuminate\Auth\Middleware\RequirePassword::class,
|
'password.confirm' => RequirePassword::class,
|
||||||
'precognitive' => \Illuminate\Foundation\Http\Middleware\HandlePrecognitiveRequests::class,
|
'precognitive' => HandlePrecognitiveRequests::class,
|
||||||
'signed' => \App\Http\Middleware\ValidateSignature::class,
|
'signed' => ValidateSignature::class,
|
||||||
'throttle' => \Illuminate\Routing\Middleware\ThrottleRequests::class,
|
'throttle' => ThrottleRequests::class,
|
||||||
'verified' => \App\Http\Middleware\EnsureEmailIsVerified::class,
|
'verified' => EnsureEmailIsVerified::class,
|
||||||
'check-organization-blocked' => CheckOrganizationBlocked::class,
|
'check-organization-blocked' => CheckOrganizationBlocked::class,
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -14,7 +14,7 @@ class ForceHttps
|
|||||||
/**
|
/**
|
||||||
* Handle an incoming request.
|
* Handle an incoming request.
|
||||||
*
|
*
|
||||||
* @param \Closure(\Illuminate\Http\Request): (\Symfony\Component\HttpFoundation\Response) $next
|
* @param Closure(Request): (Response) $next
|
||||||
*/
|
*/
|
||||||
public function handle(Request $request, Closure $next, string ...$guards): Response
|
public function handle(Request $request, Closure $next, string ...$guards): Response
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -13,7 +13,7 @@ class ForceJsonResponse
|
|||||||
/**
|
/**
|
||||||
* Handle an incoming request.
|
* Handle an incoming request.
|
||||||
*
|
*
|
||||||
* @param \Closure(\Illuminate\Http\Request): (\Symfony\Component\HttpFoundation\Response) $next
|
* @param Closure(Request): (Response) $next
|
||||||
*/
|
*/
|
||||||
public function handle(Request $request, Closure $next, string ...$guards): Response
|
public function handle(Request $request, Closure $next, string ...$guards): Response
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -60,6 +60,8 @@ class HandleInertiaRequests extends Middleware
|
|||||||
] : null,
|
] : null,
|
||||||
'flash' => [
|
'flash' => [
|
||||||
'message' => fn () => $request->session()->get('message'),
|
'message' => fn () => $request->session()->get('message'),
|
||||||
|
'bannerText' => fn () => $request->session()->get('bannerText'),
|
||||||
|
'bannerStyle' => fn () => $request->session()->get('bannerStyle'),
|
||||||
],
|
],
|
||||||
]);
|
]);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -15,7 +15,7 @@ class RedirectIfAuthenticated
|
|||||||
/**
|
/**
|
||||||
* Handle an incoming request.
|
* Handle an incoming request.
|
||||||
*
|
*
|
||||||
* @param \Closure(\Illuminate\Http\Request): (\Symfony\Component\HttpFoundation\Response) $next
|
* @param Closure(Request): (Response) $next
|
||||||
*/
|
*/
|
||||||
public function handle(Request $request, Closure $next, string ...$guards): Response
|
public function handle(Request $request, Closure $next, string ...$guards): Response
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -39,7 +39,6 @@ class ShareInertiaData
|
|||||||
'canUpdatePassword' => Features::enabled(Features::updatePasswords()),
|
'canUpdatePassword' => Features::enabled(Features::updatePasswords()),
|
||||||
'canUpdateProfileInformation' => Features::canUpdateProfileInformation(),
|
'canUpdateProfileInformation' => Features::canUpdateProfileInformation(),
|
||||||
'hasEmailVerification' => Features::enabled(Features::emailVerification()),
|
'hasEmailVerification' => Features::enabled(Features::emailVerification()),
|
||||||
'flash' => $request->session()->get('flash', []),
|
|
||||||
'hasAccountDeletionFeatures' => Jetstream::hasAccountDeletionFeatures(),
|
'hasAccountDeletionFeatures' => Jetstream::hasAccountDeletionFeatures(),
|
||||||
'hasApiFeatures' => Jetstream::hasApiFeatures(),
|
'hasApiFeatures' => Jetstream::hasApiFeatures(),
|
||||||
'hasTeamFeatures' => Jetstream::hasTeamFeatures(),
|
'hasTeamFeatures' => Jetstream::hasTeamFeatures(),
|
||||||
|
|||||||
@@ -21,6 +21,11 @@ class InvitationIndexRequest extends BaseFormRequest
|
|||||||
public function rules(): array
|
public function rules(): array
|
||||||
{
|
{
|
||||||
return [
|
return [
|
||||||
|
'page' => [
|
||||||
|
'integer',
|
||||||
|
'min:1',
|
||||||
|
'max:2147483647',
|
||||||
|
],
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -21,6 +21,11 @@ class MemberIndexRequest extends BaseFormRequest
|
|||||||
public function rules(): array
|
public function rules(): array
|
||||||
{
|
{
|
||||||
return [
|
return [
|
||||||
|
'page' => [
|
||||||
|
'integer',
|
||||||
|
'min:1',
|
||||||
|
'max:2147483647',
|
||||||
|
],
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -7,6 +7,7 @@ namespace App\Http\Requests\V1\Member;
|
|||||||
use App\Http\Requests\V1\BaseFormRequest;
|
use App\Http\Requests\V1\BaseFormRequest;
|
||||||
use App\Models\Member;
|
use App\Models\Member;
|
||||||
use App\Models\Organization;
|
use App\Models\Organization;
|
||||||
|
use Illuminate\Contracts\Validation\Rule;
|
||||||
use Illuminate\Contracts\Validation\ValidationRule;
|
use Illuminate\Contracts\Validation\ValidationRule;
|
||||||
use Illuminate\Database\Eloquent\Builder;
|
use Illuminate\Database\Eloquent\Builder;
|
||||||
use Korridor\LaravelModelValidationRules\Rules\ExistsEloquent;
|
use Korridor\LaravelModelValidationRules\Rules\ExistsEloquent;
|
||||||
@@ -19,7 +20,7 @@ class MemberMergeIntoRequest extends BaseFormRequest
|
|||||||
/**
|
/**
|
||||||
* Get the validation rules that apply to the request.
|
* Get the validation rules that apply to the request.
|
||||||
*
|
*
|
||||||
* @return array<string, array<string|ValidationRule|\Illuminate\Contracts\Validation\Rule>>
|
* @return array<string, array<string|ValidationRule|Rule>>
|
||||||
*/
|
*/
|
||||||
public function rules(): array
|
public function rules(): array
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -0,0 +1,36 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Http\Requests\V1\Organization;
|
||||||
|
|
||||||
|
use App\Http\Requests\V1\BaseFormRequest;
|
||||||
|
use App\Models\Organization;
|
||||||
|
use Illuminate\Contracts\Validation\Rule;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @property Organization $organization Organization from model binding
|
||||||
|
*/
|
||||||
|
class OrganizationStoreRequest extends BaseFormRequest
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* Get the validation rules that apply to the request.
|
||||||
|
*
|
||||||
|
* @return array<string, array<string|Rule>>
|
||||||
|
*/
|
||||||
|
public function rules(): array
|
||||||
|
{
|
||||||
|
return [
|
||||||
|
'name' => [
|
||||||
|
'required',
|
||||||
|
'string',
|
||||||
|
'max:255',
|
||||||
|
],
|
||||||
|
];
|
||||||
|
}
|
||||||
|
|
||||||
|
public function getName(): string
|
||||||
|
{
|
||||||
|
return (string) $this->input('name');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Http\Requests\V1\ProjectMember;
|
||||||
|
|
||||||
|
use App\Http\Requests\V1\BaseFormRequest;
|
||||||
|
use Illuminate\Contracts\Validation\ValidationRule;
|
||||||
|
|
||||||
|
class ProjectMemberIndexRequest extends BaseFormRequest
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* Get the validation rules that apply to the request.
|
||||||
|
*
|
||||||
|
* @return array<string, array<string|ValidationRule>>
|
||||||
|
*/
|
||||||
|
public function rules(): array
|
||||||
|
{
|
||||||
|
return [
|
||||||
|
'page' => [
|
||||||
|
'integer',
|
||||||
|
'min:1',
|
||||||
|
'max:2147483647',
|
||||||
|
],
|
||||||
|
];
|
||||||
|
}
|
||||||
|
}
|
||||||
27
app/Http/Requests/V1/Report/ReportIndexRequest.php
Normal file
27
app/Http/Requests/V1/Report/ReportIndexRequest.php
Normal file
@@ -0,0 +1,27 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Http\Requests\V1\Report;
|
||||||
|
|
||||||
|
use App\Http\Requests\V1\BaseFormRequest;
|
||||||
|
use Illuminate\Contracts\Validation\ValidationRule;
|
||||||
|
|
||||||
|
class ReportIndexRequest extends BaseFormRequest
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* Get the validation rules that apply to the request.
|
||||||
|
*
|
||||||
|
* @return array<string, array<string|ValidationRule>>
|
||||||
|
*/
|
||||||
|
public function rules(): array
|
||||||
|
{
|
||||||
|
return [
|
||||||
|
'page' => [
|
||||||
|
'integer',
|
||||||
|
'min:1',
|
||||||
|
'max:2147483647',
|
||||||
|
],
|
||||||
|
];
|
||||||
|
}
|
||||||
|
}
|
||||||
27
app/Http/Requests/V1/Tag/TagIndexRequest.php
Normal file
27
app/Http/Requests/V1/Tag/TagIndexRequest.php
Normal file
@@ -0,0 +1,27 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Http\Requests\V1\Tag;
|
||||||
|
|
||||||
|
use App\Http\Requests\V1\BaseFormRequest;
|
||||||
|
use Illuminate\Contracts\Validation\ValidationRule;
|
||||||
|
|
||||||
|
class TagIndexRequest extends BaseFormRequest
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* Get the validation rules that apply to the request.
|
||||||
|
*
|
||||||
|
* @return array<string, array<string|ValidationRule>>
|
||||||
|
*/
|
||||||
|
public function rules(): array
|
||||||
|
{
|
||||||
|
return [
|
||||||
|
'page' => [
|
||||||
|
'integer',
|
||||||
|
'min:1',
|
||||||
|
'max:2147483647',
|
||||||
|
],
|
||||||
|
];
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -26,6 +26,11 @@ class TaskIndexRequest extends BaseFormRequest
|
|||||||
public function rules(): array
|
public function rules(): array
|
||||||
{
|
{
|
||||||
return [
|
return [
|
||||||
|
'page' => [
|
||||||
|
'integer',
|
||||||
|
'min:1',
|
||||||
|
'max:2147483647',
|
||||||
|
],
|
||||||
'project_id' => [
|
'project_id' => [
|
||||||
ExistsEloquent::make(Project::class, null, function (Builder $builder): Builder {
|
ExistsEloquent::make(Project::class, null, function (Builder $builder): Builder {
|
||||||
/** @var Builder<Project> $builder */
|
/** @var Builder<Project> $builder */
|
||||||
|
|||||||
95
app/Http/Requests/V1/User/UserUpdateRequest.php
Normal file
95
app/Http/Requests/V1/User/UserUpdateRequest.php
Normal file
@@ -0,0 +1,95 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Http\Requests\V1\User;
|
||||||
|
|
||||||
|
use App\Enums\Weekday;
|
||||||
|
use App\Http\Requests\V1\BaseFormRequest;
|
||||||
|
use App\Models\User;
|
||||||
|
use App\Rules\Base64ImageRule;
|
||||||
|
use Illuminate\Contracts\Validation\ValidationRule;
|
||||||
|
use Illuminate\Database\Eloquent\Builder;
|
||||||
|
use Illuminate\Support\Str;
|
||||||
|
use Illuminate\Validation\Rule;
|
||||||
|
use Korridor\LaravelModelValidationRules\Rules\UniqueEloquent;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @property User $user User from model binding
|
||||||
|
*/
|
||||||
|
class UserUpdateRequest extends BaseFormRequest
|
||||||
|
{
|
||||||
|
protected function prepareForValidation(): void
|
||||||
|
{
|
||||||
|
if ($this->has('email') && is_string($this->input('email'))) {
|
||||||
|
$this->merge([
|
||||||
|
'email' => Str::lower((string) $this->input('email')),
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Get the validation rules that apply to the request.
|
||||||
|
*
|
||||||
|
* @return array<string, array<string|\Illuminate\Contracts\Validation\Rule|ValidationRule>>
|
||||||
|
*/
|
||||||
|
public function rules(): array
|
||||||
|
{
|
||||||
|
return [
|
||||||
|
'name' => [
|
||||||
|
'string',
|
||||||
|
'max:255',
|
||||||
|
],
|
||||||
|
'email' => [
|
||||||
|
'email',
|
||||||
|
'max:255',
|
||||||
|
UniqueEloquent::make(User::class, 'email')->ignore($this->user->id)->query(function (Builder $query) {
|
||||||
|
/** @var Builder<User> $query */
|
||||||
|
return $query->where('is_placeholder', '=', false);
|
||||||
|
}),
|
||||||
|
],
|
||||||
|
'photo' => [
|
||||||
|
'nullable',
|
||||||
|
new Base64ImageRule,
|
||||||
|
],
|
||||||
|
'timezone' => [
|
||||||
|
'timezone:all',
|
||||||
|
],
|
||||||
|
'week_start' => [
|
||||||
|
Rule::enum(Weekday::class),
|
||||||
|
],
|
||||||
|
];
|
||||||
|
}
|
||||||
|
|
||||||
|
public function getName(): ?string
|
||||||
|
{
|
||||||
|
return $this->has('name') ? (string) $this->input('name') : null;
|
||||||
|
}
|
||||||
|
|
||||||
|
public function getEmail(): ?string
|
||||||
|
{
|
||||||
|
return $this->has('email') ? Str::lower((string) $this->input('email')) : null;
|
||||||
|
}
|
||||||
|
|
||||||
|
public function getTimezone(): ?string
|
||||||
|
{
|
||||||
|
return $this->has('timezone') ? (string) $this->input('timezone') : null;
|
||||||
|
}
|
||||||
|
|
||||||
|
public function getWeekStart(): ?Weekday
|
||||||
|
{
|
||||||
|
return $this->has('week_start') ? Weekday::from($this->input('week_start')) : null;
|
||||||
|
}
|
||||||
|
|
||||||
|
public function hasPhotoKey(): bool
|
||||||
|
{
|
||||||
|
return $this->has('photo');
|
||||||
|
}
|
||||||
|
|
||||||
|
public function getPhoto(): ?string
|
||||||
|
{
|
||||||
|
$value = $this->input('photo');
|
||||||
|
|
||||||
|
return is_string($value) ? $value : null;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -4,9 +4,10 @@ declare(strict_types=1);
|
|||||||
|
|
||||||
namespace App\Http\Resources\V1\Client;
|
namespace App\Http\Resources\V1\Client;
|
||||||
|
|
||||||
|
use App\Http\Resources\PaginatedResourceCollection;
|
||||||
use Illuminate\Http\Resources\Json\ResourceCollection;
|
use Illuminate\Http\Resources\Json\ResourceCollection;
|
||||||
|
|
||||||
class ClientCollection extends ResourceCollection
|
class ClientCollection extends ResourceCollection implements PaginatedResourceCollection
|
||||||
{
|
{
|
||||||
/**
|
/**
|
||||||
* The resource that this resource collects.
|
* The resource that this resource collects.
|
||||||
|
|||||||
@@ -4,9 +4,10 @@ declare(strict_types=1);
|
|||||||
|
|
||||||
namespace App\Http\Resources\V1\Tag;
|
namespace App\Http\Resources\V1\Tag;
|
||||||
|
|
||||||
|
use App\Http\Resources\PaginatedResourceCollection;
|
||||||
use Illuminate\Http\Resources\Json\ResourceCollection;
|
use Illuminate\Http\Resources\Json\ResourceCollection;
|
||||||
|
|
||||||
class TagCollection extends ResourceCollection
|
class TagCollection extends ResourceCollection implements PaginatedResourceCollection
|
||||||
{
|
{
|
||||||
/**
|
/**
|
||||||
* The resource that this resource collects.
|
* The resource that this resource collects.
|
||||||
|
|||||||
@@ -28,6 +28,8 @@ class UserResource extends BaseResource
|
|||||||
'name' => $this->resource->name,
|
'name' => $this->resource->name,
|
||||||
/** @var string $email Email of user */
|
/** @var string $email Email of user */
|
||||||
'email' => $this->resource->email,
|
'email' => $this->resource->email,
|
||||||
|
/** @var string|null $pending_email Email address awaiting verification (set when the user has requested an email change but not yet verified the new address) */
|
||||||
|
'pending_email' => $this->resource->pending_email,
|
||||||
/** @var string $profile_photo_url Profile photo URL */
|
/** @var string $profile_photo_url Profile photo URL */
|
||||||
'profile_photo_url' => $this->resource->profile_photo_url,
|
'profile_photo_url' => $this->resource->profile_photo_url,
|
||||||
/** @var string $timezone Timezone (f.e. Europe/Berlin or America/New_York) */
|
/** @var string $timezone Timezone (f.e. Europe/Berlin or America/New_York) */
|
||||||
|
|||||||
@@ -1,43 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace App\Listeners;
|
|
||||||
|
|
||||||
use App\Models\Member;
|
|
||||||
use App\Models\User;
|
|
||||||
use App\Service\MemberService;
|
|
||||||
use Illuminate\Database\Eloquent\Builder;
|
|
||||||
use Laravel\Jetstream\Events\TeamMemberAdded;
|
|
||||||
|
|
||||||
class RemovePlaceholder
|
|
||||||
{
|
|
||||||
/**
|
|
||||||
* Handle the event.
|
|
||||||
*/
|
|
||||||
public function handle(TeamMemberAdded $event): void
|
|
||||||
{
|
|
||||||
$memberService = app(MemberService::class);
|
|
||||||
$member = Member::query()
|
|
||||||
->whereBelongsTo($event->team, 'organization')
|
|
||||||
->whereBelongsTo($event->user, 'user')
|
|
||||||
->firstOrFail();
|
|
||||||
$placeholders = Member::query()
|
|
||||||
->whereHas('user', function (Builder $query) use ($event): void {
|
|
||||||
/** @var Builder<User> $query */
|
|
||||||
$query->where('is_placeholder', '=', true)
|
|
||||||
->where('email', '=', $event->user->email);
|
|
||||||
})
|
|
||||||
->whereBelongsTo($event->team, 'organization')
|
|
||||||
->with(['user'])
|
|
||||||
->get();
|
|
||||||
|
|
||||||
foreach ($placeholders as $placeholder) {
|
|
||||||
/** @var Member $placeholder */
|
|
||||||
$placeholderUser = $placeholder->user;
|
|
||||||
$memberService->assignOrganizationEntitiesToDifferentMember($event->team, $placeholder, $member);
|
|
||||||
$placeholder->delete();
|
|
||||||
$placeholderUser->delete();
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -8,6 +8,7 @@ use App\Models\OrganizationInvitation;
|
|||||||
use Illuminate\Bus\Queueable;
|
use Illuminate\Bus\Queueable;
|
||||||
use Illuminate\Mail\Mailable;
|
use Illuminate\Mail\Mailable;
|
||||||
use Illuminate\Queue\SerializesModels;
|
use Illuminate\Queue\SerializesModels;
|
||||||
|
use Illuminate\Support\Carbon;
|
||||||
use Illuminate\Support\Facades\URL;
|
use Illuminate\Support\Facades\URL;
|
||||||
|
|
||||||
class OrganizationInvitationMail extends Mailable
|
class OrganizationInvitationMail extends Mailable
|
||||||
@@ -32,9 +33,12 @@ class OrganizationInvitationMail extends Mailable
|
|||||||
public function build(): self
|
public function build(): self
|
||||||
{
|
{
|
||||||
return $this->markdown('emails.organization-invitation', [
|
return $this->markdown('emails.organization-invitation', [
|
||||||
'acceptUrl' => URL::signedRoute('team-invitations.accept', [
|
'acceptUrl' => URL::to(URL::signedRoute(
|
||||||
'invitation' => $this->invitation,
|
'organization-invitations.accept',
|
||||||
]),
|
['invitation' => $this->invitation->getKey()],
|
||||||
|
Carbon::now()->addDays(90),
|
||||||
|
false
|
||||||
|
)),
|
||||||
])->subject(__('Organization Invitation'));
|
])->subject(__('Organization Invitation'));
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
48
app/Mail/VerifyUpdatedEmailMail.php
Normal file
48
app/Mail/VerifyUpdatedEmailMail.php
Normal file
@@ -0,0 +1,48 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Mail;
|
||||||
|
|
||||||
|
use App\Models\User;
|
||||||
|
use Illuminate\Bus\Queueable;
|
||||||
|
use Illuminate\Mail\Mailable;
|
||||||
|
use Illuminate\Queue\SerializesModels;
|
||||||
|
use Illuminate\Support\Carbon;
|
||||||
|
use Illuminate\Support\Facades\URL;
|
||||||
|
use Illuminate\Support\Str;
|
||||||
|
|
||||||
|
class VerifyUpdatedEmailMail extends Mailable
|
||||||
|
{
|
||||||
|
use Queueable, SerializesModels;
|
||||||
|
|
||||||
|
public User $user;
|
||||||
|
|
||||||
|
public string $email;
|
||||||
|
|
||||||
|
public function __construct(User $user, string $email)
|
||||||
|
{
|
||||||
|
$this->user = $user;
|
||||||
|
$this->email = Str::lower($email);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Build the message.
|
||||||
|
*/
|
||||||
|
public function build(): self
|
||||||
|
{
|
||||||
|
$verificationUrl = URL::temporarySignedRoute(
|
||||||
|
'users.verify-email-change',
|
||||||
|
Carbon::now()->addMinutes((int) config('auth.verification.expire', 60)),
|
||||||
|
[
|
||||||
|
'user' => $this->user->getKey(),
|
||||||
|
'email' => $this->email,
|
||||||
|
],
|
||||||
|
false
|
||||||
|
);
|
||||||
|
|
||||||
|
return $this->markdown('emails.verify-updated-email', [
|
||||||
|
'verificationUrl' => URL::to($verificationUrl),
|
||||||
|
])->subject(__('Verify Email Address'));
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -24,6 +24,7 @@ use Illuminate\Support\Str;
|
|||||||
use Laravel\Jetstream\Events\TeamCreated;
|
use Laravel\Jetstream\Events\TeamCreated;
|
||||||
use Laravel\Jetstream\Events\TeamDeleted;
|
use Laravel\Jetstream\Events\TeamDeleted;
|
||||||
use Laravel\Jetstream\Events\TeamUpdated;
|
use Laravel\Jetstream\Events\TeamUpdated;
|
||||||
|
use Laravel\Jetstream\Team;
|
||||||
use Laravel\Jetstream\Team as JetstreamTeam;
|
use Laravel\Jetstream\Team as JetstreamTeam;
|
||||||
use OwenIt\Auditing\Contracts\Auditable as AuditableContract;
|
use OwenIt\Auditing\Contracts\Auditable as AuditableContract;
|
||||||
|
|
||||||
@@ -36,6 +37,7 @@ use OwenIt\Auditing\Contracts\Auditable as AuditableContract;
|
|||||||
* @property string $user_id
|
* @property string $user_id
|
||||||
* @property bool $employees_can_see_billable_rates
|
* @property bool $employees_can_see_billable_rates
|
||||||
* @property bool $employees_can_manage_tasks
|
* @property bool $employees_can_manage_tasks
|
||||||
|
* @property bool $prevent_overlapping_time_entries
|
||||||
* @property User $owner
|
* @property User $owner
|
||||||
* @property Carbon|null $created_at
|
* @property Carbon|null $created_at
|
||||||
* @property Carbon|null $updated_at
|
* @property Carbon|null $updated_at
|
||||||
@@ -176,7 +178,7 @@ class Organization extends JetstreamTeam implements AuditableContract
|
|||||||
*
|
*
|
||||||
* @param array<string> $columns
|
* @param array<string> $columns
|
||||||
*/
|
*/
|
||||||
public function findOrFail(string $id, array $columns = ['*']): \Laravel\Jetstream\Team
|
public function findOrFail(string $id, array $columns = ['*']): Team
|
||||||
{
|
{
|
||||||
if (! Str::isUuid($id)) {
|
if (! Str::isUuid($id)) {
|
||||||
throw (new ModelNotFoundException)->setModel(
|
throw (new ModelNotFoundException)->setModel(
|
||||||
|
|||||||
@@ -18,6 +18,7 @@ use OwenIt\Auditing\Contracts\Auditable as AuditableContract;
|
|||||||
* @property string $email
|
* @property string $email
|
||||||
* @property string $role
|
* @property string $role
|
||||||
* @property string $organization_id
|
* @property string $organization_id
|
||||||
|
* @property Carbon|null $accepted_at
|
||||||
* @property Carbon|null $updated_at
|
* @property Carbon|null $updated_at
|
||||||
* @property Carbon|null $created_at
|
* @property Carbon|null $created_at
|
||||||
* @property-read Organization $organization
|
* @property-read Organization $organization
|
||||||
@@ -41,14 +42,16 @@ class OrganizationInvitation extends JetstreamTeamInvitation implements Auditabl
|
|||||||
protected $table = 'organization_invitations';
|
protected $table = 'organization_invitations';
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* The attributes that are mass assignable.
|
* Get the attributes that should be cast.
|
||||||
*
|
*
|
||||||
* @var array<int, string>
|
* @return array<string, string>
|
||||||
*/
|
*/
|
||||||
protected $fillable = [
|
public function casts(): array
|
||||||
'email',
|
{
|
||||||
'role',
|
return [
|
||||||
];
|
'accepted_at' => 'datetime',
|
||||||
|
];
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get the organization that the invitation belongs to.
|
* Get the organization that the invitation belongs to.
|
||||||
|
|||||||
@@ -36,6 +36,7 @@ use OwenIt\Auditing\Contracts\Auditable as AuditableContract;
|
|||||||
* @property string $id
|
* @property string $id
|
||||||
* @property string $name
|
* @property string $name
|
||||||
* @property string $email
|
* @property string $email
|
||||||
|
* @property string|null $pending_email
|
||||||
* @property Carbon|null $email_verified_at
|
* @property Carbon|null $email_verified_at
|
||||||
* @property string|null $password
|
* @property string|null $password
|
||||||
* @property string|null $two_factor_secret
|
* @property string|null $two_factor_secret
|
||||||
@@ -105,6 +106,7 @@ class User extends Authenticatable implements AuditableContract, FilamentUser, M
|
|||||||
protected $casts = [
|
protected $casts = [
|
||||||
'name' => 'string',
|
'name' => 'string',
|
||||||
'email' => 'string',
|
'email' => 'string',
|
||||||
|
'pending_email' => 'string',
|
||||||
'email_verified_at' => 'datetime',
|
'email_verified_at' => 'datetime',
|
||||||
'is_admin' => 'boolean',
|
'is_admin' => 'boolean',
|
||||||
'is_placeholder' => 'boolean',
|
'is_placeholder' => 'boolean',
|
||||||
|
|||||||
@@ -6,6 +6,7 @@ namespace App\Policies;
|
|||||||
|
|
||||||
use App\Models\Organization;
|
use App\Models\Organization;
|
||||||
use App\Models\User;
|
use App\Models\User;
|
||||||
|
use App\Service\PermissionStore;
|
||||||
use Filament\Facades\Filament;
|
use Filament\Facades\Filament;
|
||||||
use Illuminate\Auth\Access\HandlesAuthorization;
|
use Illuminate\Auth\Access\HandlesAuthorization;
|
||||||
|
|
||||||
@@ -58,19 +59,7 @@ class OrganizationPolicy
|
|||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
|
|
||||||
return $user->ownsTeam($organization);
|
return app(PermissionStore::class)->userHas($organization, $user, 'organizations:update');
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Determine whether the user can add team members.
|
|
||||||
*/
|
|
||||||
public function addTeamMember(User $user, Organization $organization): bool
|
|
||||||
{
|
|
||||||
if (Filament::isServing()) {
|
|
||||||
return true;
|
|
||||||
}
|
|
||||||
|
|
||||||
return true;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -4,11 +4,9 @@ declare(strict_types=1);
|
|||||||
|
|
||||||
namespace App\Providers;
|
namespace App\Providers;
|
||||||
|
|
||||||
use App\Listeners\RemovePlaceholder;
|
|
||||||
use Illuminate\Auth\Events\Registered;
|
use Illuminate\Auth\Events\Registered;
|
||||||
use Illuminate\Auth\Listeners\SendEmailVerificationNotification;
|
use Illuminate\Auth\Listeners\SendEmailVerificationNotification;
|
||||||
use Illuminate\Foundation\Support\Providers\EventServiceProvider as ServiceProvider;
|
use Illuminate\Foundation\Support\Providers\EventServiceProvider as ServiceProvider;
|
||||||
use Laravel\Jetstream\Events\TeamMemberAdded;
|
|
||||||
|
|
||||||
class EventServiceProvider extends ServiceProvider
|
class EventServiceProvider extends ServiceProvider
|
||||||
{
|
{
|
||||||
@@ -21,9 +19,6 @@ class EventServiceProvider extends ServiceProvider
|
|||||||
Registered::class => [
|
Registered::class => [
|
||||||
SendEmailVerificationNotification::class,
|
SendEmailVerificationNotification::class,
|
||||||
],
|
],
|
||||||
TeamMemberAdded::class => [
|
|
||||||
RemovePlaceholder::class,
|
|
||||||
],
|
|
||||||
];
|
];
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -17,6 +17,7 @@ use Illuminate\Support\Facades\Hash;
|
|||||||
use Illuminate\Support\Facades\RateLimiter;
|
use Illuminate\Support\Facades\RateLimiter;
|
||||||
use Illuminate\Support\ServiceProvider;
|
use Illuminate\Support\ServiceProvider;
|
||||||
use Illuminate\Support\Str;
|
use Illuminate\Support\Str;
|
||||||
|
use Inertia\Inertia;
|
||||||
use Laravel\Fortify\Contracts\TwoFactorLoginResponse;
|
use Laravel\Fortify\Contracts\TwoFactorLoginResponse;
|
||||||
use Laravel\Fortify\Fortify;
|
use Laravel\Fortify\Fortify;
|
||||||
use Laravel\Fortify\Http\Responses\LoginResponse;
|
use Laravel\Fortify\Http\Responses\LoginResponse;
|
||||||
@@ -41,6 +42,14 @@ class FortifyServiceProvider extends ServiceProvider
|
|||||||
Fortify::updateUserPasswordsUsing(UpdateUserPassword::class);
|
Fortify::updateUserPasswordsUsing(UpdateUserPassword::class);
|
||||||
Fortify::resetUserPasswordsUsing(ResetUserPassword::class);
|
Fortify::resetUserPasswordsUsing(ResetUserPassword::class);
|
||||||
|
|
||||||
|
Fortify::registerView(function () {
|
||||||
|
return Inertia::render('Auth/Register', [
|
||||||
|
'terms_url' => config('auth.terms_url'),
|
||||||
|
'privacy_policy_url' => config('auth.privacy_policy_url'),
|
||||||
|
'newsletter_consent' => config('auth.newsletter_consent'),
|
||||||
|
]);
|
||||||
|
});
|
||||||
|
|
||||||
Fortify::authenticateUsing(function (Request $request): ?User {
|
Fortify::authenticateUsing(function (Request $request): ?User {
|
||||||
/** @var User|null $user */
|
/** @var User|null $user */
|
||||||
$user = User::query()
|
$user = User::query()
|
||||||
|
|||||||
@@ -13,20 +13,18 @@ use App\Actions\Jetstream\RemoveOrganizationMember;
|
|||||||
use App\Actions\Jetstream\UpdateMemberRole;
|
use App\Actions\Jetstream\UpdateMemberRole;
|
||||||
use App\Actions\Jetstream\UpdateOrganization;
|
use App\Actions\Jetstream\UpdateOrganization;
|
||||||
use App\Actions\Jetstream\ValidateOrganizationDeletion;
|
use App\Actions\Jetstream\ValidateOrganizationDeletion;
|
||||||
use App\Enums\Role;
|
|
||||||
use App\Enums\Weekday;
|
use App\Enums\Weekday;
|
||||||
use App\Models\Member;
|
use App\Models\Member;
|
||||||
use App\Models\Organization;
|
use App\Models\Organization;
|
||||||
use App\Models\OrganizationInvitation;
|
use App\Models\OrganizationInvitation;
|
||||||
use App\Models\User;
|
use App\Models\User;
|
||||||
|
use App\Service\PermissionStore;
|
||||||
use App\Service\TimezoneService;
|
use App\Service\TimezoneService;
|
||||||
use Brick\Money\Currency;
|
use Brick\Money\Currency;
|
||||||
use Brick\Money\ISOCurrencyProvider;
|
use Brick\Money\ISOCurrencyProvider;
|
||||||
use Illuminate\Http\Request;
|
use Illuminate\Http\Request;
|
||||||
use Illuminate\Support\Facades\Gate;
|
use Illuminate\Support\Facades\Gate;
|
||||||
use Illuminate\Support\ServiceProvider;
|
use Illuminate\Support\ServiceProvider;
|
||||||
use Inertia\Inertia;
|
|
||||||
use Laravel\Fortify\Fortify;
|
|
||||||
use Laravel\Jetstream\Actions\UpdateTeamMemberRole;
|
use Laravel\Jetstream\Actions\UpdateTeamMemberRole;
|
||||||
use Laravel\Jetstream\Actions\ValidateTeamDeletion;
|
use Laravel\Jetstream\Actions\ValidateTeamDeletion;
|
||||||
use Laravel\Jetstream\Jetstream;
|
use Laravel\Jetstream\Jetstream;
|
||||||
@@ -60,13 +58,6 @@ class JetstreamServiceProvider extends ServiceProvider
|
|||||||
Jetstream::useTeamInvitationModel(OrganizationInvitation::class);
|
Jetstream::useTeamInvitationModel(OrganizationInvitation::class);
|
||||||
app()->singleton(UpdateTeamMemberRole::class, UpdateMemberRole::class);
|
app()->singleton(UpdateTeamMemberRole::class, UpdateMemberRole::class);
|
||||||
app()->singleton(ValidateTeamDeletion::class, ValidateOrganizationDeletion::class);
|
app()->singleton(ValidateTeamDeletion::class, ValidateOrganizationDeletion::class);
|
||||||
Fortify::registerView(function () {
|
|
||||||
return Inertia::render('Auth/Register', [
|
|
||||||
'terms_url' => config('auth.terms_url'),
|
|
||||||
'privacy_policy_url' => config('auth.privacy_policy_url'),
|
|
||||||
'newsletter_consent' => config('auth.newsletter_consent'),
|
|
||||||
]);
|
|
||||||
});
|
|
||||||
Gate::define('removeTeamMember', function (User $user, Organization $team) {
|
Gate::define('removeTeamMember', function (User $user, Organization $team) {
|
||||||
return false;
|
return false;
|
||||||
});
|
});
|
||||||
@@ -79,205 +70,10 @@ class JetstreamServiceProvider extends ServiceProvider
|
|||||||
{
|
{
|
||||||
Jetstream::defaultApiTokenPermissions([]);
|
Jetstream::defaultApiTokenPermissions([]);
|
||||||
|
|
||||||
Jetstream::role(Role::Owner->value, 'Owner', [
|
foreach (PermissionStore::roleDefinitions() as $role => $definition) {
|
||||||
'charts:view:own',
|
Jetstream::role($role, $definition['name'], $definition['permissions'])
|
||||||
'charts:view:all',
|
->description($definition['description']);
|
||||||
'projects:view',
|
}
|
||||||
'projects:view:all',
|
|
||||||
'projects:create',
|
|
||||||
'projects:update',
|
|
||||||
'projects:delete',
|
|
||||||
'project-members:view',
|
|
||||||
'project-members:create',
|
|
||||||
'project-members:update',
|
|
||||||
'project-members:delete',
|
|
||||||
'tasks:view',
|
|
||||||
'tasks:view:all',
|
|
||||||
'tasks:create',
|
|
||||||
'tasks:create:all',
|
|
||||||
'tasks:update',
|
|
||||||
'tasks:update:all',
|
|
||||||
'tasks:delete',
|
|
||||||
'tasks:delete:all',
|
|
||||||
'time-entries:view:all',
|
|
||||||
'time-entries:create:all',
|
|
||||||
'time-entries:update:all',
|
|
||||||
'time-entries:delete:all',
|
|
||||||
'time-entries:view:own',
|
|
||||||
'time-entries:create:own',
|
|
||||||
'time-entries:update:own',
|
|
||||||
'time-entries:delete:own',
|
|
||||||
'tags:view',
|
|
||||||
'tags:create',
|
|
||||||
'tags:update',
|
|
||||||
'tags:delete',
|
|
||||||
'clients:view',
|
|
||||||
'clients:view:all',
|
|
||||||
'clients:create',
|
|
||||||
'clients:update',
|
|
||||||
'clients:delete',
|
|
||||||
'organizations:view',
|
|
||||||
'organizations:update',
|
|
||||||
'organizations:delete',
|
|
||||||
'import',
|
|
||||||
'export',
|
|
||||||
'invitations:view',
|
|
||||||
'invitations:create',
|
|
||||||
'invitations:resend',
|
|
||||||
'invitations:remove',
|
|
||||||
'members:view',
|
|
||||||
'members:invite-placeholder',
|
|
||||||
'members:change-ownership',
|
|
||||||
'members:make-placeholder',
|
|
||||||
'members:merge-into',
|
|
||||||
'members:update',
|
|
||||||
'members:delete',
|
|
||||||
'billing',
|
|
||||||
'reports:view',
|
|
||||||
'reports:create',
|
|
||||||
'reports:update',
|
|
||||||
'reports:delete',
|
|
||||||
'invoices:view',
|
|
||||||
'invoices:create',
|
|
||||||
'invoices:update',
|
|
||||||
'invoices:download',
|
|
||||||
'invoices:delete',
|
|
||||||
'invoice-settings:view',
|
|
||||||
'invoice-settings:update',
|
|
||||||
])->description('Owner users can perform any action. There is only one owner per organization.');
|
|
||||||
|
|
||||||
Jetstream::role(Role::Admin->value, 'Administrator', [
|
|
||||||
'charts:view:own',
|
|
||||||
'charts:view:all',
|
|
||||||
'projects:view',
|
|
||||||
'projects:view:all',
|
|
||||||
'projects:create',
|
|
||||||
'projects:update',
|
|
||||||
'projects:delete',
|
|
||||||
'project-members:view',
|
|
||||||
'project-members:create',
|
|
||||||
'project-members:update',
|
|
||||||
'project-members:delete',
|
|
||||||
'tasks:view',
|
|
||||||
'tasks:view:all',
|
|
||||||
'tasks:create',
|
|
||||||
'tasks:create:all',
|
|
||||||
'tasks:update',
|
|
||||||
'tasks:update:all',
|
|
||||||
'tasks:delete',
|
|
||||||
'tasks:delete:all',
|
|
||||||
'time-entries:view:all',
|
|
||||||
'time-entries:create:all',
|
|
||||||
'time-entries:update:all',
|
|
||||||
'time-entries:delete:all',
|
|
||||||
'time-entries:view:own',
|
|
||||||
'time-entries:create:own',
|
|
||||||
'time-entries:update:own',
|
|
||||||
'time-entries:delete:own',
|
|
||||||
'tags:view',
|
|
||||||
'tags:create',
|
|
||||||
'tags:update',
|
|
||||||
'tags:delete',
|
|
||||||
'clients:view',
|
|
||||||
'clients:view:all',
|
|
||||||
'clients:create',
|
|
||||||
'clients:update',
|
|
||||||
'clients:delete',
|
|
||||||
'organizations:view',
|
|
||||||
'organizations:update',
|
|
||||||
'import',
|
|
||||||
'export',
|
|
||||||
'invitations:view',
|
|
||||||
'invitations:create',
|
|
||||||
'invitations:resend',
|
|
||||||
'invitations:remove',
|
|
||||||
'members:view',
|
|
||||||
'members:invite-placeholder',
|
|
||||||
'members:make-placeholder',
|
|
||||||
'members:merge-into',
|
|
||||||
'members:delete',
|
|
||||||
'members:update',
|
|
||||||
'reports:view',
|
|
||||||
'reports:create',
|
|
||||||
'reports:update',
|
|
||||||
'reports:delete',
|
|
||||||
'invoices:view',
|
|
||||||
'invoices:create',
|
|
||||||
'invoices:update',
|
|
||||||
'invoices:download',
|
|
||||||
'invoices:delete',
|
|
||||||
'invoice-settings:view',
|
|
||||||
'invoice-settings:update',
|
|
||||||
])->description('Administrator users can perform any action, except accessing the billing dashboard.');
|
|
||||||
|
|
||||||
Jetstream::role(Role::Manager->value, 'Manager', [
|
|
||||||
'charts:view:own',
|
|
||||||
'charts:view:all',
|
|
||||||
'projects:view',
|
|
||||||
'projects:view:all',
|
|
||||||
'projects:create',
|
|
||||||
'projects:update',
|
|
||||||
'projects:delete',
|
|
||||||
'project-members:view',
|
|
||||||
'project-members:create',
|
|
||||||
'project-members:update',
|
|
||||||
'project-members:delete',
|
|
||||||
'tasks:view',
|
|
||||||
'tasks:view:all',
|
|
||||||
'tasks:create',
|
|
||||||
'tasks:create:all',
|
|
||||||
'tasks:update',
|
|
||||||
'tasks:update:all',
|
|
||||||
'tasks:delete',
|
|
||||||
'tasks:delete:all',
|
|
||||||
'time-entries:view:all',
|
|
||||||
'time-entries:create:all',
|
|
||||||
'time-entries:update:all',
|
|
||||||
'time-entries:delete:all',
|
|
||||||
'time-entries:view:own',
|
|
||||||
'time-entries:create:own',
|
|
||||||
'time-entries:update:own',
|
|
||||||
'time-entries:delete:own',
|
|
||||||
'tags:view',
|
|
||||||
'tags:create',
|
|
||||||
'tags:update',
|
|
||||||
'tags:delete',
|
|
||||||
'clients:view',
|
|
||||||
'clients:view:all',
|
|
||||||
'clients:create',
|
|
||||||
'clients:update',
|
|
||||||
'clients:delete',
|
|
||||||
'organizations:view',
|
|
||||||
'invitations:view',
|
|
||||||
'members:view',
|
|
||||||
'reports:view',
|
|
||||||
'reports:create',
|
|
||||||
'reports:update',
|
|
||||||
'reports:delete',
|
|
||||||
'invoices:view',
|
|
||||||
'invoices:create',
|
|
||||||
'invoices:update',
|
|
||||||
'invoices:download',
|
|
||||||
'invoices:delete',
|
|
||||||
'invoice-settings:view',
|
|
||||||
'invoice-settings:update',
|
|
||||||
])->description('Managers have full access to all projects, time entries, ect. but cannot manage the organization (add/remove member, edit the organization, ect.).');
|
|
||||||
|
|
||||||
Jetstream::role(Role::Employee->value, 'Employee', [
|
|
||||||
'charts:view:own',
|
|
||||||
'projects:view',
|
|
||||||
'tags:view',
|
|
||||||
'tasks:view',
|
|
||||||
'clients:view',
|
|
||||||
'time-entries:view:own',
|
|
||||||
'time-entries:create:own',
|
|
||||||
'time-entries:update:own',
|
|
||||||
'time-entries:delete:own',
|
|
||||||
'organizations:view',
|
|
||||||
])->description('Employees have the ability to read, create, and update their own time entries, they can see the projects that they are members of and the clients they are assigned to.');
|
|
||||||
|
|
||||||
Jetstream::role(Role::Placeholder->value, 'Placeholder', [
|
|
||||||
])->description('Placeholders are used for importing data. They cannot log in and have no permissions.');
|
|
||||||
|
|
||||||
Jetstream::inertia()
|
Jetstream::inertia()
|
||||||
->whenRendering(
|
->whenRendering(
|
||||||
@@ -304,28 +100,8 @@ class JetstreamServiceProvider extends ServiceProvider
|
|||||||
'owner' => [
|
'owner' => [
|
||||||
'id' => $owner->getKey(),
|
'id' => $owner->getKey(),
|
||||||
'name' => $owner->name,
|
'name' => $owner->name,
|
||||||
'email' => $owner->email,
|
|
||||||
'profile_photo_url' => $owner->profile_photo_url,
|
'profile_photo_url' => $owner->profile_photo_url,
|
||||||
],
|
],
|
||||||
'users' => $teamModel->users->map(function (User $user): array {
|
|
||||||
return [
|
|
||||||
'id' => $user->getKey(),
|
|
||||||
'name' => $user->name,
|
|
||||||
'email' => $user->email,
|
|
||||||
'profile_photo_url' => $user->profile_photo_url,
|
|
||||||
'membership' => [
|
|
||||||
'id' => $user->membership->id,
|
|
||||||
'role' => $user->membership->role,
|
|
||||||
],
|
|
||||||
];
|
|
||||||
}),
|
|
||||||
'team_invitations' => $teamModel->teamInvitations->map(function (OrganizationInvitation $invitation): array {
|
|
||||||
return [
|
|
||||||
'id' => $invitation->getKey(),
|
|
||||||
'email' => $invitation->email,
|
|
||||||
'role' => $invitation->role,
|
|
||||||
];
|
|
||||||
}),
|
|
||||||
],
|
],
|
||||||
'currencies' => array_map(function (Currency $currency): string {
|
'currencies' => array_map(function (Currency $currency): string {
|
||||||
return $currency->getName();
|
return $currency->getName();
|
||||||
|
|||||||
45
app/Rules/Base64ImageRule.php
Normal file
45
app/Rules/Base64ImageRule.php
Normal file
@@ -0,0 +1,45 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Rules;
|
||||||
|
|
||||||
|
use App\Support\Base64File;
|
||||||
|
use Closure;
|
||||||
|
use Illuminate\Contracts\Validation\ValidationRule;
|
||||||
|
use Illuminate\Translation\PotentiallyTranslatedString;
|
||||||
|
|
||||||
|
class Base64ImageRule implements ValidationRule
|
||||||
|
{
|
||||||
|
private const array ALLOWED_MIME_TYPES = [
|
||||||
|
'image/jpeg',
|
||||||
|
'image/png',
|
||||||
|
];
|
||||||
|
|
||||||
|
private const int MAX_BYTES = 1024 * 1024;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Run the validation rule.
|
||||||
|
*
|
||||||
|
* @param Closure(string): PotentiallyTranslatedString $fail
|
||||||
|
*/
|
||||||
|
public function validate(string $attribute, mixed $value, Closure $fail): void
|
||||||
|
{
|
||||||
|
if (! is_string($value)) {
|
||||||
|
$fail(__('validation.string'));
|
||||||
|
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
$file = Base64File::decode($value);
|
||||||
|
if ($file === null || ! in_array($file['mime_type'], self::ALLOWED_MIME_TYPES, true)) {
|
||||||
|
$fail(__('validation.mimes', ['values' => 'jpg, png']));
|
||||||
|
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (strlen($file['data']) > self::MAX_BYTES) {
|
||||||
|
$fail(__('validation.max.file', ['max' => (string) (self::MAX_BYTES / 1024)]));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -8,9 +8,11 @@ use App\Enums\Role;
|
|||||||
use App\Exceptions\Api\InvitationForTheEmailAlreadyExistsApiException;
|
use App\Exceptions\Api\InvitationForTheEmailAlreadyExistsApiException;
|
||||||
use App\Exceptions\Api\UserIsAlreadyMemberOfOrganizationApiException;
|
use App\Exceptions\Api\UserIsAlreadyMemberOfOrganizationApiException;
|
||||||
use App\Mail\OrganizationInvitationMail;
|
use App\Mail\OrganizationInvitationMail;
|
||||||
use App\Models\Member;
|
|
||||||
use App\Models\Organization;
|
use App\Models\Organization;
|
||||||
use App\Models\OrganizationInvitation;
|
use App\Models\OrganizationInvitation;
|
||||||
|
use App\Models\User;
|
||||||
|
use Illuminate\Support\Collection;
|
||||||
|
use Illuminate\Support\Facades\Log;
|
||||||
use Illuminate\Support\Facades\Mail;
|
use Illuminate\Support\Facades\Mail;
|
||||||
use Laravel\Jetstream\Events\InvitingTeamMember;
|
use Laravel\Jetstream\Events\InvitingTeamMember;
|
||||||
|
|
||||||
@@ -21,11 +23,7 @@ class InvitationService
|
|||||||
*/
|
*/
|
||||||
public function inviteUser(Organization $organization, string $email, Role $role): OrganizationInvitation
|
public function inviteUser(Organization $organization, string $email, Role $role): OrganizationInvitation
|
||||||
{
|
{
|
||||||
if (Member::query()
|
if (app(MemberService::class)->isEmailAlreadyMember($organization, $email)) {
|
||||||
->whereBelongsTo($organization, 'organization')
|
|
||||||
->whereRelation('user', 'email', '=', $email)
|
|
||||||
->where('role', '!=', Role::Placeholder->value)
|
|
||||||
->exists()) {
|
|
||||||
throw new UserIsAlreadyMemberOfOrganizationApiException;
|
throw new UserIsAlreadyMemberOfOrganizationApiException;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -48,4 +46,37 @@ class InvitationService
|
|||||||
|
|
||||||
return $invitation;
|
return $invitation;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return Collection<int, Organization>
|
||||||
|
*/
|
||||||
|
public function processAcceptedInvitations(User $user): Collection
|
||||||
|
{
|
||||||
|
$organizations = new Collection;
|
||||||
|
|
||||||
|
$invitations = OrganizationInvitation::query()
|
||||||
|
->where('email', $user->email)
|
||||||
|
->whereNotNull('accepted_at')
|
||||||
|
->get();
|
||||||
|
|
||||||
|
foreach ($invitations as $invitation) {
|
||||||
|
$organization = $invitation->organization;
|
||||||
|
$role = Role::tryFrom($invitation->role);
|
||||||
|
if ($role === null) {
|
||||||
|
Log::error('Invalid role in invitation', [
|
||||||
|
'invitation' => $invitation->getKey(),
|
||||||
|
'role' => $invitation->role,
|
||||||
|
]);
|
||||||
|
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
app(MemberService::class)->addMember($user, $organization, $role);
|
||||||
|
|
||||||
|
$invitation->delete();
|
||||||
|
|
||||||
|
$organizations->push($organization);
|
||||||
|
}
|
||||||
|
|
||||||
|
return $organizations;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -96,6 +96,30 @@ class LocalizationService
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Format a duration for reporting contexts (PDF reports, places that display duration
|
||||||
|
* directly next to cost). Promotes the verbose `Hh Mm` format to the compact `HH:MM:SS`
|
||||||
|
* so totals stay narrow and reconcile with cost, which is always computed to the second.
|
||||||
|
*/
|
||||||
|
public function formatIntervalForReporting(CarbonInterval $interval): string
|
||||||
|
{
|
||||||
|
$promoted = [
|
||||||
|
IntervalFormat::HoursMinutes,
|
||||||
|
IntervalFormat::HoursMinutesColonSeparated,
|
||||||
|
];
|
||||||
|
if (! in_array($this->intervalFormat, $promoted, true)) {
|
||||||
|
return $this->formatInterval($interval);
|
||||||
|
}
|
||||||
|
|
||||||
|
$previous = $this->intervalFormat;
|
||||||
|
$this->intervalFormat = IntervalFormat::HoursMinutesSecondsColonSeparated;
|
||||||
|
try {
|
||||||
|
return $this->formatInterval($interval);
|
||||||
|
} finally {
|
||||||
|
$this->intervalFormat = $previous;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
public function formatCurrency(Money $money): string
|
public function formatCurrency(Money $money): string
|
||||||
{
|
{
|
||||||
$currencyService = app(CurrencyService::class);
|
$currencyService = app(CurrencyService::class);
|
||||||
|
|||||||
@@ -5,6 +5,8 @@ declare(strict_types=1);
|
|||||||
namespace App\Service;
|
namespace App\Service;
|
||||||
|
|
||||||
use App\Enums\Role;
|
use App\Enums\Role;
|
||||||
|
use App\Events\MemberAdded;
|
||||||
|
use App\Events\MemberAdding;
|
||||||
use App\Events\MemberRemoved;
|
use App\Events\MemberRemoved;
|
||||||
use App\Exceptions\Api\CanNotRemoveOwnerFromOrganization;
|
use App\Exceptions\Api\CanNotRemoveOwnerFromOrganization;
|
||||||
use App\Exceptions\Api\ChangingRoleOfPlaceholderIsNotAllowed;
|
use App\Exceptions\Api\ChangingRoleOfPlaceholderIsNotAllowed;
|
||||||
@@ -36,7 +38,8 @@ class MemberService
|
|||||||
public function addMember(User $user, Organization $organization, Role $role, bool $asSuperAdmin = false): Member
|
public function addMember(User $user, Organization $organization, Role $role, bool $asSuperAdmin = false): Member
|
||||||
{
|
{
|
||||||
if (! $asSuperAdmin) {
|
if (! $asSuperAdmin) {
|
||||||
AddingTeamMember::dispatch($organization, $user);
|
MemberAdding::dispatch($user, $organization, $role);
|
||||||
|
AddingTeamMember::dispatch($organization, $user); // Legacy event
|
||||||
}
|
}
|
||||||
|
|
||||||
$member = new Member;
|
$member = new Member;
|
||||||
@@ -49,14 +52,37 @@ class MemberService
|
|||||||
$user->currentOrganization()->associate($organization);
|
$user->currentOrganization()->associate($organization);
|
||||||
$user->save();
|
$user->save();
|
||||||
});
|
});
|
||||||
|
$this->mergePlaceholderMembersIntoExistingMember($member, $organization, $user);
|
||||||
|
|
||||||
if (! $asSuperAdmin) {
|
if (! $asSuperAdmin) {
|
||||||
TeamMemberAdded::dispatch($organization, $user);
|
MemberAdded::dispatch($member, $organization, $user);
|
||||||
|
TeamMemberAdded::dispatch($organization, $user); // Legacy event
|
||||||
}
|
}
|
||||||
|
|
||||||
return $member;
|
return $member;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
private function mergePlaceholderMembersIntoExistingMember(Member $member, Organization $organization, User $user): void
|
||||||
|
{
|
||||||
|
$placeholders = Member::query()
|
||||||
|
->whereHas('user', function (Builder $query) use ($user): void {
|
||||||
|
/** @var Builder<User> $query */
|
||||||
|
$query->where('is_placeholder', '=', true)
|
||||||
|
->where('email', '=', $user->email);
|
||||||
|
})
|
||||||
|
->whereBelongsTo($organization, 'organization')
|
||||||
|
->with(['user'])
|
||||||
|
->get();
|
||||||
|
|
||||||
|
foreach ($placeholders as $placeholder) {
|
||||||
|
/** @var Member $placeholder */
|
||||||
|
$placeholderUser = $placeholder->user;
|
||||||
|
$this->assignOrganizationEntitiesToDifferentMember($organization, $placeholder, $member);
|
||||||
|
$placeholder->delete();
|
||||||
|
$placeholderUser->delete();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @throws CanNotRemoveOwnerFromOrganization
|
* @throws CanNotRemoveOwnerFromOrganization
|
||||||
* @throws EntityStillInUseApiException
|
* @throws EntityStillInUseApiException
|
||||||
@@ -209,4 +235,13 @@ class MemberService
|
|||||||
$this->userService->makeSureUserHasCurrentOrganization($user);
|
$this->userService->makeSureUserHasCurrentOrganization($user);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public function isEmailAlreadyMember(Organization $organization, string $email): bool
|
||||||
|
{
|
||||||
|
return Member::query()
|
||||||
|
->whereBelongsTo($organization, 'organization')
|
||||||
|
->whereRelation('user', 'email', '=', $email)
|
||||||
|
->where('role', '!=', Role::Placeholder->value)
|
||||||
|
->exists();
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -4,14 +4,238 @@ declare(strict_types=1);
|
|||||||
|
|
||||||
namespace App\Service;
|
namespace App\Service;
|
||||||
|
|
||||||
|
use App\Enums\Role;
|
||||||
use App\Models\Organization;
|
use App\Models\Organization;
|
||||||
use App\Models\User;
|
use App\Models\User;
|
||||||
use Illuminate\Support\Facades\Auth;
|
use Illuminate\Support\Facades\Auth;
|
||||||
use Laravel\Jetstream\Jetstream;
|
|
||||||
use Laravel\Jetstream\Role;
|
|
||||||
|
|
||||||
class PermissionStore
|
class PermissionStore
|
||||||
{
|
{
|
||||||
|
/**
|
||||||
|
* @var array<string, array{name: string, permissions: array<string>, description: string}>
|
||||||
|
*/
|
||||||
|
private const array ROLE_DEFINITIONS = [
|
||||||
|
'owner' => [
|
||||||
|
'name' => 'Owner',
|
||||||
|
'permissions' => [
|
||||||
|
'charts:view:own',
|
||||||
|
'charts:view:all',
|
||||||
|
'projects:view',
|
||||||
|
'projects:view:all',
|
||||||
|
'projects:create',
|
||||||
|
'projects:update',
|
||||||
|
'projects:delete',
|
||||||
|
'project-members:view',
|
||||||
|
'project-members:create',
|
||||||
|
'project-members:update',
|
||||||
|
'project-members:delete',
|
||||||
|
'tasks:view',
|
||||||
|
'tasks:view:all',
|
||||||
|
'tasks:create',
|
||||||
|
'tasks:create:all',
|
||||||
|
'tasks:update',
|
||||||
|
'tasks:update:all',
|
||||||
|
'tasks:delete',
|
||||||
|
'tasks:delete:all',
|
||||||
|
'time-entries:view:all',
|
||||||
|
'time-entries:create:all',
|
||||||
|
'time-entries:update:all',
|
||||||
|
'time-entries:delete:all',
|
||||||
|
'time-entries:view:own',
|
||||||
|
'time-entries:create:own',
|
||||||
|
'time-entries:update:own',
|
||||||
|
'time-entries:delete:own',
|
||||||
|
'tags:view',
|
||||||
|
'tags:create',
|
||||||
|
'tags:update',
|
||||||
|
'tags:delete',
|
||||||
|
'clients:view',
|
||||||
|
'clients:view:all',
|
||||||
|
'clients:create',
|
||||||
|
'clients:update',
|
||||||
|
'clients:delete',
|
||||||
|
'organizations:view',
|
||||||
|
'organizations:update',
|
||||||
|
'organizations:delete',
|
||||||
|
'import',
|
||||||
|
'export',
|
||||||
|
'invitations:view',
|
||||||
|
'invitations:create',
|
||||||
|
'invitations:resend',
|
||||||
|
'invitations:remove',
|
||||||
|
'members:view',
|
||||||
|
'members:invite-placeholder',
|
||||||
|
'members:change-ownership',
|
||||||
|
'members:make-placeholder',
|
||||||
|
'members:merge-into',
|
||||||
|
'members:update',
|
||||||
|
'members:delete',
|
||||||
|
'billing',
|
||||||
|
'reports:view',
|
||||||
|
'reports:create',
|
||||||
|
'reports:update',
|
||||||
|
'reports:delete',
|
||||||
|
'invoices:view',
|
||||||
|
'invoices:create',
|
||||||
|
'invoices:update',
|
||||||
|
'invoices:download',
|
||||||
|
'invoices:delete',
|
||||||
|
'invoice-settings:view',
|
||||||
|
'invoice-settings:update',
|
||||||
|
],
|
||||||
|
'description' => 'Owner users can perform any action. There is only one owner per organization.',
|
||||||
|
],
|
||||||
|
'admin' => [
|
||||||
|
'name' => 'Administrator',
|
||||||
|
'permissions' => [
|
||||||
|
'charts:view:own',
|
||||||
|
'charts:view:all',
|
||||||
|
'projects:view',
|
||||||
|
'projects:view:all',
|
||||||
|
'projects:create',
|
||||||
|
'projects:update',
|
||||||
|
'projects:delete',
|
||||||
|
'project-members:view',
|
||||||
|
'project-members:create',
|
||||||
|
'project-members:update',
|
||||||
|
'project-members:delete',
|
||||||
|
'tasks:view',
|
||||||
|
'tasks:view:all',
|
||||||
|
'tasks:create',
|
||||||
|
'tasks:create:all',
|
||||||
|
'tasks:update',
|
||||||
|
'tasks:update:all',
|
||||||
|
'tasks:delete',
|
||||||
|
'tasks:delete:all',
|
||||||
|
'time-entries:view:all',
|
||||||
|
'time-entries:create:all',
|
||||||
|
'time-entries:update:all',
|
||||||
|
'time-entries:delete:all',
|
||||||
|
'time-entries:view:own',
|
||||||
|
'time-entries:create:own',
|
||||||
|
'time-entries:update:own',
|
||||||
|
'time-entries:delete:own',
|
||||||
|
'tags:view',
|
||||||
|
'tags:create',
|
||||||
|
'tags:update',
|
||||||
|
'tags:delete',
|
||||||
|
'clients:view',
|
||||||
|
'clients:view:all',
|
||||||
|
'clients:create',
|
||||||
|
'clients:update',
|
||||||
|
'clients:delete',
|
||||||
|
'organizations:view',
|
||||||
|
'organizations:update',
|
||||||
|
'import',
|
||||||
|
'export',
|
||||||
|
'invitations:view',
|
||||||
|
'invitations:create',
|
||||||
|
'invitations:resend',
|
||||||
|
'invitations:remove',
|
||||||
|
'members:view',
|
||||||
|
'members:invite-placeholder',
|
||||||
|
'members:make-placeholder',
|
||||||
|
'members:merge-into',
|
||||||
|
'members:delete',
|
||||||
|
'members:update',
|
||||||
|
'reports:view',
|
||||||
|
'reports:create',
|
||||||
|
'reports:update',
|
||||||
|
'reports:delete',
|
||||||
|
'invoices:view',
|
||||||
|
'invoices:create',
|
||||||
|
'invoices:update',
|
||||||
|
'invoices:download',
|
||||||
|
'invoices:delete',
|
||||||
|
'invoice-settings:view',
|
||||||
|
'invoice-settings:update',
|
||||||
|
],
|
||||||
|
'description' => 'Administrator users can perform any action, except accessing the billing dashboard.',
|
||||||
|
],
|
||||||
|
'manager' => [
|
||||||
|
'name' => 'Manager',
|
||||||
|
'permissions' => [
|
||||||
|
'charts:view:own',
|
||||||
|
'charts:view:all',
|
||||||
|
'projects:view',
|
||||||
|
'projects:view:all',
|
||||||
|
'projects:create',
|
||||||
|
'projects:update',
|
||||||
|
'projects:delete',
|
||||||
|
'project-members:view',
|
||||||
|
'project-members:create',
|
||||||
|
'project-members:update',
|
||||||
|
'project-members:delete',
|
||||||
|
'tasks:view',
|
||||||
|
'tasks:view:all',
|
||||||
|
'tasks:create',
|
||||||
|
'tasks:create:all',
|
||||||
|
'tasks:update',
|
||||||
|
'tasks:update:all',
|
||||||
|
'tasks:delete',
|
||||||
|
'tasks:delete:all',
|
||||||
|
'time-entries:view:all',
|
||||||
|
'time-entries:create:all',
|
||||||
|
'time-entries:update:all',
|
||||||
|
'time-entries:delete:all',
|
||||||
|
'time-entries:view:own',
|
||||||
|
'time-entries:create:own',
|
||||||
|
'time-entries:update:own',
|
||||||
|
'time-entries:delete:own',
|
||||||
|
'tags:view',
|
||||||
|
'tags:create',
|
||||||
|
'tags:update',
|
||||||
|
'tags:delete',
|
||||||
|
'clients:view',
|
||||||
|
'clients:view:all',
|
||||||
|
'clients:create',
|
||||||
|
'clients:update',
|
||||||
|
'clients:delete',
|
||||||
|
'organizations:view',
|
||||||
|
'invitations:view',
|
||||||
|
'members:view',
|
||||||
|
'reports:view',
|
||||||
|
'reports:create',
|
||||||
|
'reports:update',
|
||||||
|
'reports:delete',
|
||||||
|
'invoices:view',
|
||||||
|
'invoices:create',
|
||||||
|
'invoices:update',
|
||||||
|
'invoices:download',
|
||||||
|
'invoices:delete',
|
||||||
|
'invoice-settings:view',
|
||||||
|
'invoice-settings:update',
|
||||||
|
],
|
||||||
|
'description' => 'Managers have full access to all projects, time entries, ect. but cannot manage the organization (add/remove member, edit the organization, ect.).',
|
||||||
|
],
|
||||||
|
'employee' => [
|
||||||
|
'name' => 'Employee',
|
||||||
|
'permissions' => [
|
||||||
|
'charts:view:own',
|
||||||
|
'projects:view',
|
||||||
|
'tags:view',
|
||||||
|
'tasks:view',
|
||||||
|
'clients:view',
|
||||||
|
'time-entries:view:own',
|
||||||
|
'time-entries:create:own',
|
||||||
|
'time-entries:update:own',
|
||||||
|
'time-entries:delete:own',
|
||||||
|
'organizations:view',
|
||||||
|
],
|
||||||
|
'description' => 'Employees have the ability to read, create, and update their own time entries, they can see the projects that they are members of and the clients they are assigned to.',
|
||||||
|
],
|
||||||
|
'placeholder' => [
|
||||||
|
'name' => 'Placeholder',
|
||||||
|
'permissions' => [],
|
||||||
|
'description' => 'Placeholders are used for importing data. They cannot log in and have no permissions.',
|
||||||
|
],
|
||||||
|
];
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var array<string, array<string>>
|
||||||
|
*/
|
||||||
|
private static array $customRolePermissions = [];
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @var array<string, array<string>>
|
* @var array<string, array<string>>
|
||||||
*/
|
*/
|
||||||
@@ -22,6 +246,37 @@ class PermissionStore
|
|||||||
$this->permissionCache = [];
|
$this->permissionCache = [];
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return array<string, array{name: string, permissions: array<string>, description: string}>
|
||||||
|
*/
|
||||||
|
public static function roleDefinitions(): array
|
||||||
|
{
|
||||||
|
return self::ROLE_DEFINITIONS;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param array<string> $permissions
|
||||||
|
*/
|
||||||
|
public static function registerCustomRole(string $role, array $permissions): void
|
||||||
|
{
|
||||||
|
self::$customRolePermissions[$role] = $permissions;
|
||||||
|
}
|
||||||
|
|
||||||
|
public static function resetCustomRoles(): void
|
||||||
|
{
|
||||||
|
self::$customRolePermissions = [];
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return array<string>
|
||||||
|
*/
|
||||||
|
public static function permissionsForRole(string $role): array
|
||||||
|
{
|
||||||
|
return self::$customRolePermissions[$role]
|
||||||
|
?? self::ROLE_DEFINITIONS[$role]['permissions']
|
||||||
|
?? [];
|
||||||
|
}
|
||||||
|
|
||||||
public function has(Organization $organization, string $permission): bool
|
public function has(Organization $organization, string $permission): bool
|
||||||
{
|
{
|
||||||
/** @var User|null $user */
|
/** @var User|null $user */
|
||||||
@@ -68,14 +323,11 @@ class PermissionStore
|
|||||||
return [];
|
return [];
|
||||||
}
|
}
|
||||||
|
|
||||||
/** @var Role|null $roleObj */
|
$permissions = self::permissionsForRole($role);
|
||||||
$roleObj = Jetstream::findRole($role);
|
|
||||||
|
|
||||||
$permissions = $roleObj->permissions ?? [];
|
|
||||||
|
|
||||||
// If the organization allows employees to manage tasks and the user is an employee,
|
// If the organization allows employees to manage tasks and the user is an employee,
|
||||||
// add the task management permissions for accessible projects
|
// add the task management permissions for accessible projects
|
||||||
if ($role === \App\Enums\Role::Employee->value && $organization->employees_can_manage_tasks) {
|
if ($role === Role::Employee->value && $organization->employees_can_manage_tasks) {
|
||||||
$permissions = array_merge($permissions, [
|
$permissions = array_merge($permissions, [
|
||||||
'tasks:create',
|
'tasks:create',
|
||||||
'tasks:update',
|
'tasks:update',
|
||||||
|
|||||||
@@ -10,6 +10,9 @@ use Illuminate\Database\Eloquent\Model;
|
|||||||
use Illuminate\Http\File;
|
use Illuminate\Http\File;
|
||||||
use Illuminate\Support\Carbon;
|
use Illuminate\Support\Carbon;
|
||||||
use Illuminate\Support\Facades\Storage;
|
use Illuminate\Support\Facades\Storage;
|
||||||
|
use League\Csv\CannotInsertRecord;
|
||||||
|
use League\Csv\Exception;
|
||||||
|
use League\Csv\UnavailableStream;
|
||||||
use League\Csv\Writer;
|
use League\Csv\Writer;
|
||||||
use Spatie\TemporaryDirectory\TemporaryDirectory;
|
use Spatie\TemporaryDirectory\TemporaryDirectory;
|
||||||
|
|
||||||
@@ -58,9 +61,9 @@ abstract class CsvExport
|
|||||||
abstract public function mapRow(Model $model): array;
|
abstract public function mapRow(Model $model): array;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @throws \League\Csv\CannotInsertRecord
|
* @throws CannotInsertRecord
|
||||||
* @throws \League\Csv\Exception
|
* @throws Exception
|
||||||
* @throws \League\Csv\UnavailableStream
|
* @throws UnavailableStream
|
||||||
*/
|
*/
|
||||||
public function export(): void
|
public function export(): void
|
||||||
{
|
{
|
||||||
@@ -72,6 +75,7 @@ abstract class CsvExport
|
|||||||
$writer->insertOne(static::HEADER);
|
$writer->insertOne(static::HEADER);
|
||||||
|
|
||||||
$this->builder->chunk($this->chunk, function (Collection $models) use ($writer): void {
|
$this->builder->chunk($this->chunk, function (Collection $models) use ($writer): void {
|
||||||
|
/** @var T $model */
|
||||||
foreach ($models as $model) {
|
foreach ($models as $model) {
|
||||||
$data = $this->mapRow($model);
|
$data = $this->mapRow($model);
|
||||||
$row = $this->convertRow($data);
|
$row = $this->convertRow($data);
|
||||||
|
|||||||
@@ -38,7 +38,7 @@ class UserService
|
|||||||
): User {
|
): User {
|
||||||
$user = new User;
|
$user = new User;
|
||||||
$user->name = $name;
|
$user->name = $name;
|
||||||
$user->email = $email;
|
$user->email = strtolower($email);
|
||||||
$user->password = Hash::make($password);
|
$user->password = Hash::make($password);
|
||||||
$user->timezone = $timezone;
|
$user->timezone = $timezone;
|
||||||
$user->week_start = $weekStart;
|
$user->week_start = $weekStart;
|
||||||
@@ -47,19 +47,22 @@ class UserService
|
|||||||
}
|
}
|
||||||
$user->save();
|
$user->save();
|
||||||
|
|
||||||
$organization = app(OrganizationService::class)->createOrganization(
|
$organizations = app(InvitationService::class)->processAcceptedInvitations($user);
|
||||||
$this->getOrganizationNameForUserName($user->name),
|
|
||||||
$user,
|
|
||||||
true,
|
|
||||||
$currency,
|
|
||||||
$numberFormat,
|
|
||||||
$currencyFormat,
|
|
||||||
$dateFormat,
|
|
||||||
$intervalFormat,
|
|
||||||
$timeFormat,
|
|
||||||
);
|
|
||||||
|
|
||||||
$user->ownedTeams()->save($organization);
|
if ($organizations->isEmpty()) {
|
||||||
|
$organization = app(OrganizationService::class)->createOrganization(
|
||||||
|
$this->getOrganizationNameForUserName($user->name),
|
||||||
|
$user,
|
||||||
|
true,
|
||||||
|
$currency,
|
||||||
|
$numberFormat,
|
||||||
|
$currencyFormat,
|
||||||
|
$dateFormat,
|
||||||
|
$intervalFormat,
|
||||||
|
$timeFormat,
|
||||||
|
);
|
||||||
|
$user->ownedTeams()->save($organization);
|
||||||
|
}
|
||||||
|
|
||||||
return $user;
|
return $user;
|
||||||
}
|
}
|
||||||
|
|||||||
45
app/Support/Base64File.php
Normal file
45
app/Support/Base64File.php
Normal file
@@ -0,0 +1,45 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Support;
|
||||||
|
|
||||||
|
use Symfony\Component\Mime\MimeTypes;
|
||||||
|
|
||||||
|
class Base64File
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @return array{data: string, mime_type: string}|null
|
||||||
|
*/
|
||||||
|
public static function decode(string $value): ?array
|
||||||
|
{
|
||||||
|
if (str_contains($value, ',')) {
|
||||||
|
[, $value] = explode(',', $value, 2);
|
||||||
|
}
|
||||||
|
|
||||||
|
$value = preg_replace('/\s+/', '', $value);
|
||||||
|
if ($value === null || $value === '') {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
$decoded = base64_decode($value, true);
|
||||||
|
if ($decoded === false) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
$mimeType = (new \finfo(FILEINFO_MIME_TYPE))->buffer($decoded);
|
||||||
|
if ($mimeType === false) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
return [
|
||||||
|
'data' => $decoded,
|
||||||
|
'mime_type' => $mimeType,
|
||||||
|
];
|
||||||
|
}
|
||||||
|
|
||||||
|
public static function extension(string $mimeType): ?string
|
||||||
|
{
|
||||||
|
return MimeTypes::getDefault()->getExtensions($mimeType)[0] ?? null;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -1,6 +1,10 @@
|
|||||||
<?php
|
<?php
|
||||||
|
|
||||||
declare(strict_types=1);
|
declare(strict_types=1);
|
||||||
|
use App\Exceptions\Handler;
|
||||||
|
use App\Http\Kernel;
|
||||||
|
use Illuminate\Contracts\Debug\ExceptionHandler;
|
||||||
|
use Illuminate\Foundation\Application;
|
||||||
|
|
||||||
/*
|
/*
|
||||||
|--------------------------------------------------------------------------
|
|--------------------------------------------------------------------------
|
||||||
@@ -13,7 +17,7 @@ declare(strict_types=1);
|
|||||||
|
|
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
$app = new Illuminate\Foundation\Application(
|
$app = new Application(
|
||||||
$_ENV['APP_BASE_PATH'] ?? dirname(__DIR__)
|
$_ENV['APP_BASE_PATH'] ?? dirname(__DIR__)
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -30,7 +34,7 @@ $app = new Illuminate\Foundation\Application(
|
|||||||
|
|
||||||
$app->singleton(
|
$app->singleton(
|
||||||
Illuminate\Contracts\Http\Kernel::class,
|
Illuminate\Contracts\Http\Kernel::class,
|
||||||
App\Http\Kernel::class
|
Kernel::class
|
||||||
);
|
);
|
||||||
|
|
||||||
$app->singleton(
|
$app->singleton(
|
||||||
@@ -39,8 +43,8 @@ $app->singleton(
|
|||||||
);
|
);
|
||||||
|
|
||||||
$app->singleton(
|
$app->singleton(
|
||||||
Illuminate\Contracts\Debug\ExceptionHandler::class,
|
ExceptionHandler::class,
|
||||||
App\Exceptions\Handler::class
|
Handler::class
|
||||||
);
|
);
|
||||||
|
|
||||||
/*
|
/*
|
||||||
|
|||||||
4585
composer.lock
generated
4585
composer.lock
generated
File diff suppressed because it is too large
Load Diff
@@ -7,6 +7,13 @@ use App\Enums\DateFormat;
|
|||||||
use App\Enums\IntervalFormat;
|
use App\Enums\IntervalFormat;
|
||||||
use App\Enums\NumberFormat;
|
use App\Enums\NumberFormat;
|
||||||
use App\Enums\TimeFormat;
|
use App\Enums\TimeFormat;
|
||||||
|
use App\Providers\AppServiceProvider;
|
||||||
|
use App\Providers\AuthServiceProvider;
|
||||||
|
use App\Providers\EventServiceProvider;
|
||||||
|
use App\Providers\Filament\AdminPanelProvider;
|
||||||
|
use App\Providers\FortifyServiceProvider;
|
||||||
|
use App\Providers\JetstreamServiceProvider;
|
||||||
|
use App\Providers\RouteServiceProvider;
|
||||||
use Illuminate\Support\Facades\Facade;
|
use Illuminate\Support\Facades\Facade;
|
||||||
use Illuminate\Support\ServiceProvider;
|
use Illuminate\Support\ServiceProvider;
|
||||||
use Nwidart\Modules\LaravelModulesServiceProvider;
|
use Nwidart\Modules\LaravelModulesServiceProvider;
|
||||||
@@ -190,13 +197,13 @@ return [
|
|||||||
/*
|
/*
|
||||||
* Application Service Providers...
|
* Application Service Providers...
|
||||||
*/
|
*/
|
||||||
App\Providers\AppServiceProvider::class,
|
AppServiceProvider::class,
|
||||||
App\Providers\AuthServiceProvider::class,
|
AuthServiceProvider::class,
|
||||||
App\Providers\EventServiceProvider::class,
|
EventServiceProvider::class,
|
||||||
App\Providers\Filament\AdminPanelProvider::class,
|
AdminPanelProvider::class,
|
||||||
App\Providers\RouteServiceProvider::class,
|
RouteServiceProvider::class,
|
||||||
App\Providers\FortifyServiceProvider::class,
|
FortifyServiceProvider::class,
|
||||||
App\Providers\JetstreamServiceProvider::class,
|
JetstreamServiceProvider::class,
|
||||||
// Warning: Do not add TelescopeServiceProvider here since it is already conditionally registered in AppServiceProvider
|
// Warning: Do not add TelescopeServiceProvider here since it is already conditionally registered in AppServiceProvider
|
||||||
LaravelModulesServiceProvider::class,
|
LaravelModulesServiceProvider::class,
|
||||||
])->toArray(),
|
])->toArray(),
|
||||||
|
|||||||
@@ -1,6 +1,11 @@
|
|||||||
<?php
|
<?php
|
||||||
|
|
||||||
declare(strict_types=1);
|
declare(strict_types=1);
|
||||||
|
use App\Extensions\Auditing\Resolvers\CustomIpAddressResolver;
|
||||||
|
use OwenIt\Auditing\Models\Audit;
|
||||||
|
use OwenIt\Auditing\Resolvers\UrlResolver;
|
||||||
|
use OwenIt\Auditing\Resolvers\UserAgentResolver;
|
||||||
|
use OwenIt\Auditing\Resolvers\UserResolver;
|
||||||
|
|
||||||
return [
|
return [
|
||||||
|
|
||||||
@@ -15,7 +20,7 @@ return [
|
|||||||
|
|
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
'implementation' => OwenIt\Auditing\Models\Audit::class,
|
'implementation' => Audit::class,
|
||||||
|
|
||||||
/*
|
/*
|
||||||
|--------------------------------------------------------------------------
|
|--------------------------------------------------------------------------
|
||||||
@@ -32,7 +37,7 @@ return [
|
|||||||
'web',
|
'web',
|
||||||
'api',
|
'api',
|
||||||
],
|
],
|
||||||
'resolver' => OwenIt\Auditing\Resolvers\UserResolver::class,
|
'resolver' => UserResolver::class,
|
||||||
],
|
],
|
||||||
|
|
||||||
/*
|
/*
|
||||||
@@ -44,9 +49,9 @@ return [
|
|||||||
|
|
|
|
||||||
*/
|
*/
|
||||||
'resolvers' => [
|
'resolvers' => [
|
||||||
'ip_address' => App\Extensions\Auditing\Resolvers\CustomIpAddressResolver::class,
|
'ip_address' => CustomIpAddressResolver::class,
|
||||||
'user_agent' => OwenIt\Auditing\Resolvers\UserAgentResolver::class,
|
'user_agent' => UserAgentResolver::class,
|
||||||
'url' => OwenIt\Auditing\Resolvers\UrlResolver::class,
|
'url' => UrlResolver::class,
|
||||||
],
|
],
|
||||||
|
|
||||||
/*
|
/*
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
<?php
|
<?php
|
||||||
|
|
||||||
declare(strict_types=1);
|
declare(strict_types=1);
|
||||||
|
use App\Models\User;
|
||||||
|
|
||||||
return [
|
return [
|
||||||
|
|
||||||
@@ -69,7 +70,7 @@ return [
|
|||||||
'providers' => [
|
'providers' => [
|
||||||
'users' => [
|
'users' => [
|
||||||
'driver' => 'eloquent',
|
'driver' => 'eloquent',
|
||||||
'model' => App\Models\User::class,
|
'model' => User::class,
|
||||||
],
|
],
|
||||||
|
|
||||||
],
|
],
|
||||||
|
|||||||
@@ -2,6 +2,7 @@
|
|||||||
|
|
||||||
declare(strict_types=1);
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
use Maatwebsite\Excel\DefaultValueBinder;
|
||||||
use Maatwebsite\Excel\Excel;
|
use Maatwebsite\Excel\Excel;
|
||||||
use PhpOffice\PhpSpreadsheet\Reader\Csv;
|
use PhpOffice\PhpSpreadsheet\Reader\Csv;
|
||||||
|
|
||||||
@@ -226,7 +227,7 @@ return [
|
|||||||
|
|
|
|
||||||
*/
|
*/
|
||||||
'value_binder' => [
|
'value_binder' => [
|
||||||
'default' => Maatwebsite\Excel\DefaultValueBinder::class,
|
'default' => DefaultValueBinder::class,
|
||||||
],
|
],
|
||||||
|
|
||||||
'cache' => [
|
'cache' => [
|
||||||
|
|||||||
@@ -25,9 +25,24 @@ class OrganizationInvitationFactory extends Factory
|
|||||||
'email' => $this->faker->unique()->safeEmail(),
|
'email' => $this->faker->unique()->safeEmail(),
|
||||||
'role' => Role::Employee->value,
|
'role' => Role::Employee->value,
|
||||||
'organization_id' => Organization::factory(),
|
'organization_id' => Organization::factory(),
|
||||||
|
'accepted_at' => null,
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public function role(Role $role): self
|
||||||
|
{
|
||||||
|
return $this->state(fn (array $attributes) => [
|
||||||
|
'role' => $role->value,
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function accepted(): self
|
||||||
|
{
|
||||||
|
return $this->state(fn (array $attributes): array => [
|
||||||
|
'accepted_at' => $this->faker->dateTime(),
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
|
||||||
public function forOrganization(Organization $organization): self
|
public function forOrganization(Organization $organization): self
|
||||||
{
|
{
|
||||||
return $this->state(fn (array $attributes) => [
|
return $this->state(fn (array $attributes) => [
|
||||||
|
|||||||
@@ -9,6 +9,7 @@ use App\Enums\Weekday;
|
|||||||
use App\Models\Organization;
|
use App\Models\Organization;
|
||||||
use App\Models\User;
|
use App\Models\User;
|
||||||
use Illuminate\Database\Eloquent\Factories\Factory;
|
use Illuminate\Database\Eloquent\Factories\Factory;
|
||||||
|
use Illuminate\Http\FileHelpers;
|
||||||
use Illuminate\Support\Facades\Storage;
|
use Illuminate\Support\Facades\Storage;
|
||||||
use Illuminate\Support\Str;
|
use Illuminate\Support\Str;
|
||||||
|
|
||||||
@@ -27,6 +28,7 @@ class UserFactory extends Factory
|
|||||||
return [
|
return [
|
||||||
'name' => $this->faker->name(),
|
'name' => $this->faker->name(),
|
||||||
'email' => $this->faker->unique()->safeEmail(),
|
'email' => $this->faker->unique()->safeEmail(),
|
||||||
|
'pending_email' => null,
|
||||||
'email_verified_at' => now(),
|
'email_verified_at' => now(),
|
||||||
'password' => '$2y$10$92IXUNpkjO0rOQ5byMi.Ye4oKoEa3Ro9llC/.og/at2.uheWG/igi', // password
|
'password' => '$2y$10$92IXUNpkjO0rOQ5byMi.Ye4oKoEa3Ro9llC/.og/at2.uheWG/igi', // password
|
||||||
'two_factor_secret' => null,
|
'two_factor_secret' => null,
|
||||||
@@ -90,7 +92,7 @@ class UserFactory extends Factory
|
|||||||
public function withProfilePicture(): static
|
public function withProfilePicture(): static
|
||||||
{
|
{
|
||||||
$profilePhoto = $this->faker->image(null, 500, 500);
|
$profilePhoto = $this->faker->image(null, 500, 500);
|
||||||
/** @see \Illuminate\Http\FileHelpers::hashName */
|
/** @see FileHelpers::hashName */
|
||||||
$path = 'profile-photos/'.Str::random(40).'.png';
|
$path = 'profile-photos/'.Str::random(40).'.png';
|
||||||
Storage::disk(config('jetstream.profile_photo_disk', 'public'))->put($path, $profilePhoto);
|
Storage::disk(config('jetstream.profile_photo_disk', 'public'))->put($path, $profilePhoto);
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,30 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* Run the migrations.
|
||||||
|
*/
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('organization_invitations', function (Blueprint $table): void {
|
||||||
|
$table->timestamp('accepted_at')->nullable()->after('email');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Reverse the migrations.
|
||||||
|
*/
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('organization_invitations', function (Blueprint $table): void {
|
||||||
|
$table->dropColumn('accepted_at');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* Run the migrations.
|
||||||
|
*/
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('users', function (Blueprint $table): void {
|
||||||
|
$table->string('pending_email')->nullable()->after('email');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Reverse the migrations.
|
||||||
|
*/
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('users', function (Blueprint $table): void {
|
||||||
|
$table->dropColumn('pending_email');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,64 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* Run the migrations.
|
||||||
|
*
|
||||||
|
* @throws RuntimeException
|
||||||
|
*/
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
$duplicateEmails = DB::table('users')
|
||||||
|
->selectRaw('LOWER(email) as normalized_email')
|
||||||
|
->selectRaw('COUNT(*) as user_count')
|
||||||
|
->selectRaw("STRING_AGG(id::text || ' <' || email || '>', ', ' ORDER BY email) as users")
|
||||||
|
->where('is_placeholder', false)
|
||||||
|
->groupByRaw('LOWER(email)')
|
||||||
|
->havingRaw('COUNT(*) > 1')
|
||||||
|
->orderBy('normalized_email')
|
||||||
|
->get();
|
||||||
|
|
||||||
|
if ($duplicateEmails->isNotEmpty()) {
|
||||||
|
$duplicateEmailMessage = $duplicateEmails
|
||||||
|
->take(20)
|
||||||
|
->map(fn (stdClass $duplicateEmail): string => sprintf(
|
||||||
|
'%s (%d users: %s)',
|
||||||
|
$duplicateEmail->normalized_email,
|
||||||
|
$duplicateEmail->user_count,
|
||||||
|
$duplicateEmail->users,
|
||||||
|
))
|
||||||
|
->implode('; ');
|
||||||
|
|
||||||
|
$remainingDuplicateCount = $duplicateEmails->count() - 20;
|
||||||
|
$remainingDuplicateMessage = $remainingDuplicateCount > 0
|
||||||
|
? sprintf('; and %d more duplicate normalized emails', $remainingDuplicateCount)
|
||||||
|
: '';
|
||||||
|
|
||||||
|
throw new RuntimeException(
|
||||||
|
'Cannot lowercase users.email because doing so would create duplicate non-placeholder user emails and violate the unique index on users.email for non-placeholder users. Resolve these case-insensitive duplicates first: '.
|
||||||
|
$duplicateEmailMessage.
|
||||||
|
$remainingDuplicateMessage
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
DB::table('users')
|
||||||
|
->whereRaw('email <> LOWER(email)')
|
||||||
|
->update([
|
||||||
|
'email' => DB::raw('LOWER(email)'),
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Reverse the migrations.
|
||||||
|
*/
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
//
|
||||||
|
}
|
||||||
|
};
|
||||||
689
e2e/calendar-settings.spec.ts
Normal file
689
e2e/calendar-settings.spec.ts
Normal file
@@ -0,0 +1,689 @@
|
|||||||
|
import type { Page } from '@playwright/test';
|
||||||
|
import { expect } from '@playwright/test';
|
||||||
|
import { PLAYWRIGHT_BASE_URL } from '../playwright/config';
|
||||||
|
import { test } from '../playwright/fixtures';
|
||||||
|
import { createBareTimeEntryViaApi, createTimeEntryWithTimestampsViaApi } from './utils/api';
|
||||||
|
|
||||||
|
async function goToCalendar(page: Page) {
|
||||||
|
await page.goto(PLAYWRIGHT_BASE_URL + '/calendar');
|
||||||
|
await expect(page.locator('.fc')).toBeVisible({ timeout: 10000 });
|
||||||
|
}
|
||||||
|
|
||||||
|
async function openSettingsPopover(page: Page) {
|
||||||
|
await page.getByRole('button', { name: 'Calendar settings' }).click();
|
||||||
|
await expect(page.getByText('Calendar Settings')).toBeVisible();
|
||||||
|
}
|
||||||
|
|
||||||
|
async function clearCalendarSettings(page: Page) {
|
||||||
|
await page.evaluate(() => localStorage.removeItem('solidtime:calendar-settings'));
|
||||||
|
}
|
||||||
|
|
||||||
|
function getCalendarTitle(page: Page) {
|
||||||
|
return page.getByTestId('calendar-title');
|
||||||
|
}
|
||||||
|
|
||||||
|
async function scrollCalendarToTime(page: Page, time: string) {
|
||||||
|
await page.evaluate((t) => {
|
||||||
|
const slot = document.querySelector(`.fc-timegrid-slot-lane[data-time="${t}"]`);
|
||||||
|
if (slot) slot.scrollIntoView({ block: 'start' });
|
||||||
|
}, time);
|
||||||
|
await page.waitForTimeout(300);
|
||||||
|
}
|
||||||
|
|
||||||
|
async function getSlotHeight(page: Page): Promise<number> {
|
||||||
|
return await page.evaluate(() => {
|
||||||
|
const slots = Array.from(document.querySelectorAll('.fc-timegrid-slot-lane'));
|
||||||
|
for (let i = 0; i < slots.length; i++) {
|
||||||
|
const h = slots[i].getBoundingClientRect().height;
|
||||||
|
if (h > 0) return h;
|
||||||
|
}
|
||||||
|
return 20;
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
test.describe('Calendar Settings', () => {
|
||||||
|
test.beforeEach(async ({ page }) => {
|
||||||
|
await clearCalendarSettings(page);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('settings popover shows all fields with correct defaults', async ({ page }) => {
|
||||||
|
await goToCalendar(page);
|
||||||
|
await openSettingsPopover(page);
|
||||||
|
|
||||||
|
await expect(page.getByLabel('Snap Interval')).toContainText('15 min');
|
||||||
|
await expect(page.getByLabel('Start Time')).toContainText('12:00 AM');
|
||||||
|
await expect(page.getByLabel('End Time')).toContainText('12:00 AM (next)');
|
||||||
|
await expect(page.getByLabel('Grid Scale')).toContainText('15 min');
|
||||||
|
});
|
||||||
|
|
||||||
|
test('snap interval can be changed and persists across reload', async ({ page }) => {
|
||||||
|
await goToCalendar(page);
|
||||||
|
await openSettingsPopover(page);
|
||||||
|
|
||||||
|
// Change snap interval to 30 min
|
||||||
|
await page.getByLabel('Snap Interval').click();
|
||||||
|
await page.getByRole('option', { name: '30 min' }).click();
|
||||||
|
|
||||||
|
// Close the popover by pressing Escape
|
||||||
|
await page.keyboard.press('Escape');
|
||||||
|
|
||||||
|
// Verify localStorage was updated
|
||||||
|
const stored = await page.evaluate(() =>
|
||||||
|
JSON.parse(localStorage.getItem('solidtime:calendar-settings') || '{}')
|
||||||
|
);
|
||||||
|
expect(stored.snapMinutes).toBe(30);
|
||||||
|
|
||||||
|
// Reload and verify persistence
|
||||||
|
await page.reload();
|
||||||
|
await expect(page.locator('.fc')).toBeVisible();
|
||||||
|
await openSettingsPopover(page);
|
||||||
|
await expect(page.getByLabel('Snap Interval')).toContainText('30 min');
|
||||||
|
});
|
||||||
|
|
||||||
|
test('start time change is applied to calendar and rejects invalid values', async ({
|
||||||
|
page,
|
||||||
|
}) => {
|
||||||
|
await goToCalendar(page);
|
||||||
|
|
||||||
|
// Verify 7 AM slot exists with default start (00:00)
|
||||||
|
await expect(page.locator('.fc-timegrid-slot[data-time="07:00:00"]')).not.toHaveCount(0);
|
||||||
|
|
||||||
|
await openSettingsPopover(page);
|
||||||
|
|
||||||
|
// Set end time to 6 PM first
|
||||||
|
await page.getByLabel('End Time').click();
|
||||||
|
await page.getByRole('option', { name: '6:00 PM' }).click();
|
||||||
|
|
||||||
|
// Change start time to 8 AM (valid)
|
||||||
|
await page.getByLabel('Start Time').click();
|
||||||
|
await page.getByRole('option', { name: '8:00 AM' }).click();
|
||||||
|
|
||||||
|
// Try to set start time to 6 PM (invalid: equals end time) — should be rejected
|
||||||
|
await page.getByLabel('Start Time').click();
|
||||||
|
await page.getByRole('option', { name: '6:00 PM' }).click();
|
||||||
|
|
||||||
|
// Should be rejected — start time stays at 8 AM
|
||||||
|
await expect(page.getByLabel('Start Time')).toContainText('8:00 AM');
|
||||||
|
|
||||||
|
// Close the popover
|
||||||
|
await page.keyboard.press('Escape');
|
||||||
|
|
||||||
|
// Calendar should no longer show hours before 8 AM
|
||||||
|
await expect(page.locator('.fc-timegrid-slot[data-time="07:00:00"]')).toHaveCount(0);
|
||||||
|
await expect(page.locator('.fc-timegrid-slot[data-time="08:00:00"]')).not.toHaveCount(0);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('end time change is applied to calendar and rejects invalid values', async ({ page }) => {
|
||||||
|
await goToCalendar(page);
|
||||||
|
|
||||||
|
// Verify 19:00 slot exists with default end (24:00)
|
||||||
|
await expect(page.locator('.fc-timegrid-slot[data-time="19:00:00"]')).not.toHaveCount(0);
|
||||||
|
|
||||||
|
await openSettingsPopover(page);
|
||||||
|
|
||||||
|
// Set start time to 8 AM first
|
||||||
|
await page.getByLabel('Start Time').click();
|
||||||
|
await page.getByRole('option', { name: '8:00 AM' }).click();
|
||||||
|
|
||||||
|
// Change end time to 6 PM (valid)
|
||||||
|
await page.getByLabel('End Time').click();
|
||||||
|
await page.getByRole('option', { name: '6:00 PM' }).click();
|
||||||
|
|
||||||
|
// Try to set end time to 8 AM (invalid: equals start time) — should be rejected
|
||||||
|
await page.getByLabel('End Time').click();
|
||||||
|
await page.getByRole('option', { name: '8:00 AM' }).click();
|
||||||
|
|
||||||
|
// Should be rejected — end time stays at 6 PM
|
||||||
|
await expect(page.getByLabel('End Time')).toContainText('6:00 PM');
|
||||||
|
|
||||||
|
// Close the popover
|
||||||
|
await page.keyboard.press('Escape');
|
||||||
|
|
||||||
|
// Calendar should no longer show hours at or after 6 PM
|
||||||
|
await expect(page.locator('.fc-timegrid-slot[data-time="18:00:00"]')).toHaveCount(0);
|
||||||
|
await expect(page.locator('.fc-timegrid-slot[data-time="17:00:00"]')).not.toHaveCount(0);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('grid scale affects number of calendar slots', async ({ page }) => {
|
||||||
|
await goToCalendar(page);
|
||||||
|
|
||||||
|
// Count slots with default 15-min scale
|
||||||
|
const defaultSlotCount = await page.locator('.fc-timegrid-slot').count();
|
||||||
|
|
||||||
|
// Change to 30 min scale (should halve the slots)
|
||||||
|
await openSettingsPopover(page);
|
||||||
|
await page.getByLabel('Grid Scale').click();
|
||||||
|
await page.getByRole('option', { name: '30 min' }).click();
|
||||||
|
await page.keyboard.press('Escape');
|
||||||
|
|
||||||
|
// Wait for FullCalendar to re-render with new slot count
|
||||||
|
await expect(async () => {
|
||||||
|
const count = await page.locator('.fc-timegrid-slot').count();
|
||||||
|
expect(count).toBeLessThan(defaultSlotCount);
|
||||||
|
}).toPass({ timeout: 5000 });
|
||||||
|
|
||||||
|
const largerSlotCount = await page.locator('.fc-timegrid-slot').count();
|
||||||
|
|
||||||
|
// Navigate away and back to get a clean calendar mount
|
||||||
|
await page.goto(PLAYWRIGHT_BASE_URL + '/time');
|
||||||
|
await goToCalendar(page);
|
||||||
|
|
||||||
|
// Change to 5 min scale (many more slots)
|
||||||
|
await openSettingsPopover(page);
|
||||||
|
await page.getByLabel('Grid Scale').click();
|
||||||
|
await page.getByRole('option', { name: '5 min', exact: true }).click();
|
||||||
|
await page.keyboard.press('Escape');
|
||||||
|
|
||||||
|
// Wait for FullCalendar to re-render with new slot count
|
||||||
|
await expect(async () => {
|
||||||
|
const count = await page.locator('.fc-timegrid-slot').count();
|
||||||
|
expect(count).toBeGreaterThan(largerSlotCount);
|
||||||
|
}).toPass({ timeout: 5000 });
|
||||||
|
});
|
||||||
|
|
||||||
|
test('all settings persist across navigation', async ({ page }) => {
|
||||||
|
await goToCalendar(page);
|
||||||
|
await openSettingsPopover(page);
|
||||||
|
|
||||||
|
// Change every setting
|
||||||
|
await page.getByLabel('Snap Interval').click();
|
||||||
|
await page.getByRole('option', { name: '5 min', exact: true }).click();
|
||||||
|
await page.getByLabel('Start Time').click();
|
||||||
|
await page.getByRole('option', { name: '6:00 AM' }).click();
|
||||||
|
await page.getByLabel('End Time').click();
|
||||||
|
await page.getByRole('option', { name: '10:00 PM' }).click();
|
||||||
|
await page.getByLabel('Grid Scale').click();
|
||||||
|
await page.getByRole('option', { name: '30 min' }).click();
|
||||||
|
|
||||||
|
// Close the popover
|
||||||
|
await page.keyboard.press('Escape');
|
||||||
|
|
||||||
|
// Navigate away and back
|
||||||
|
await page.goto(PLAYWRIGHT_BASE_URL + '/time');
|
||||||
|
await goToCalendar(page);
|
||||||
|
|
||||||
|
// Verify all settings persisted
|
||||||
|
await openSettingsPopover(page);
|
||||||
|
await expect(page.getByLabel('Snap Interval')).toContainText('5 min');
|
||||||
|
await expect(page.getByLabel('Start Time')).toContainText('6:00 AM');
|
||||||
|
await expect(page.getByLabel('End Time')).toContainText('10:00 PM');
|
||||||
|
await expect(page.getByLabel('Grid Scale')).toContainText('30 min');
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
test.describe('Calendar Toolbar', () => {
|
||||||
|
test('prev and next buttons navigate the calendar', async ({ page }) => {
|
||||||
|
await goToCalendar(page);
|
||||||
|
|
||||||
|
// Use column headers to detect navigation (title only shows month which may not change)
|
||||||
|
const getHeaderTexts = async () => {
|
||||||
|
const headers = page.locator('.fc-col-header-cell');
|
||||||
|
return headers.allTextContents();
|
||||||
|
};
|
||||||
|
|
||||||
|
const initialHeaders = await getHeaderTexts();
|
||||||
|
|
||||||
|
// Click next
|
||||||
|
await page.getByRole('button', { name: 'Next', exact: true }).click();
|
||||||
|
await expect(page.locator('.fc')).toBeVisible();
|
||||||
|
|
||||||
|
const nextHeaders = await getHeaderTexts();
|
||||||
|
expect(nextHeaders).not.toEqual(initialHeaders);
|
||||||
|
|
||||||
|
// Click prev — should go back to original
|
||||||
|
await page.getByRole('button', { name: 'Previous', exact: true }).click();
|
||||||
|
await expect(page.locator('.fc')).toBeVisible();
|
||||||
|
|
||||||
|
const backHeaders = await getHeaderTexts();
|
||||||
|
expect(backHeaders).toEqual(initialHeaders);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('today button returns to current week', async ({ page }) => {
|
||||||
|
await goToCalendar(page);
|
||||||
|
|
||||||
|
// Use column headers to detect navigation (title only shows month which may not change)
|
||||||
|
const getHeaderTexts = async () => {
|
||||||
|
const headers = page.locator('.fc-col-header-cell');
|
||||||
|
return headers.allTextContents();
|
||||||
|
};
|
||||||
|
|
||||||
|
const initialHeaders = await getHeaderTexts();
|
||||||
|
|
||||||
|
// Navigate away
|
||||||
|
await page.getByRole('button', { name: 'Next', exact: true }).click();
|
||||||
|
await page.getByRole('button', { name: 'Next', exact: true }).click();
|
||||||
|
|
||||||
|
const awayHeaders = await getHeaderTexts();
|
||||||
|
expect(awayHeaders).not.toEqual(initialHeaders);
|
||||||
|
|
||||||
|
// Click today
|
||||||
|
await page.getByRole('button', { name: 'today', exact: true }).click();
|
||||||
|
await expect(page.locator('.fc')).toBeVisible();
|
||||||
|
|
||||||
|
const todayHeaders = await getHeaderTexts();
|
||||||
|
expect(todayHeaders).toEqual(initialHeaders);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('view switcher toggles between week and day views', async ({ page }) => {
|
||||||
|
await goToCalendar(page);
|
||||||
|
|
||||||
|
// Default should be week view — verify multiple day columns exist
|
||||||
|
await expect(page.locator('.fc-col-header-cell')).not.toHaveCount(1);
|
||||||
|
|
||||||
|
// Switch to day view
|
||||||
|
await page.getByRole('tab', { name: 'day', exact: true }).click();
|
||||||
|
await expect(page.locator('.fc')).toBeVisible();
|
||||||
|
|
||||||
|
// Day view should show exactly 1 day column
|
||||||
|
await expect(page.locator('.fc-col-header-cell')).toHaveCount(1);
|
||||||
|
|
||||||
|
// Switch back to week view
|
||||||
|
await page.getByRole('tab', { name: 'week', exact: true }).click();
|
||||||
|
await expect(page.locator('.fc')).toBeVisible();
|
||||||
|
|
||||||
|
// Week view should show multiple day columns again
|
||||||
|
await expect(page.locator('.fc-col-header-cell')).not.toHaveCount(1);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
test.describe('Visual Snapping', () => {
|
||||||
|
test.beforeEach(async ({ page }) => {
|
||||||
|
await clearCalendarSettings(page);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('snap interval of 1 minute allows fine-grained positioning', async ({ page, ctx }) => {
|
||||||
|
await goToCalendar(page);
|
||||||
|
await openSettingsPopover(page);
|
||||||
|
|
||||||
|
// Set snap interval to 1 min
|
||||||
|
await page.getByLabel('Snap Interval').click();
|
||||||
|
await page.getByRole('option', { name: '1 min' }).click();
|
||||||
|
await page.keyboard.press('Escape');
|
||||||
|
|
||||||
|
// Create a 1h time entry
|
||||||
|
await createBareTimeEntryViaApi(ctx, 'Snap 1min test', '1h');
|
||||||
|
await goToCalendar(page);
|
||||||
|
|
||||||
|
// Scroll the calendar so the 14:00 target area is visible
|
||||||
|
await scrollCalendarToTime(page, '13:00:00');
|
||||||
|
|
||||||
|
const event = page.locator('.fc-event').first();
|
||||||
|
await expect(event).toBeVisible();
|
||||||
|
|
||||||
|
// Get target slot at a non-15-min boundary time
|
||||||
|
const targetSlot = page.locator('.fc-timegrid-slot-lane[data-time="14:00:00"]').first();
|
||||||
|
const targetBox = await targetSlot.boundingBox();
|
||||||
|
expect(targetBox).not.toBeNull();
|
||||||
|
|
||||||
|
// Drag event to a position offset from the 15-min boundary
|
||||||
|
const putResponsePromise = page.waitForResponse(
|
||||||
|
(resp) => resp.url().includes('/time-entries/') && resp.request().method() === 'PUT'
|
||||||
|
);
|
||||||
|
|
||||||
|
await event.hover();
|
||||||
|
await page.mouse.down();
|
||||||
|
await page.mouse.move(targetBox!.x + targetBox!.width / 2, targetBox!.y + 5, { steps: 10 });
|
||||||
|
await page.mouse.up();
|
||||||
|
|
||||||
|
const putResponse = await putResponsePromise;
|
||||||
|
expect(putResponse.status()).toBe(200);
|
||||||
|
|
||||||
|
const body = await putResponse.json();
|
||||||
|
const startDate = new Date(body.data.start);
|
||||||
|
const minutes = startDate.getMinutes();
|
||||||
|
|
||||||
|
// With 1-min snap, any minute value is valid (0-59)
|
||||||
|
expect(minutes).toBeGreaterThanOrEqual(0);
|
||||||
|
expect(minutes).toBeLessThanOrEqual(59);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('snap interval of 60 minutes creates hour-aligned entries', async ({ page, ctx }) => {
|
||||||
|
await goToCalendar(page);
|
||||||
|
await openSettingsPopover(page);
|
||||||
|
|
||||||
|
// Set snap interval to 60 min
|
||||||
|
await page.getByLabel('Snap Interval').click();
|
||||||
|
await page.getByRole('option', { name: '1 hour' }).click();
|
||||||
|
await page.keyboard.press('Escape');
|
||||||
|
|
||||||
|
// Create a 1h time entry
|
||||||
|
await createBareTimeEntryViaApi(ctx, 'Snap 60min test', '1h');
|
||||||
|
await goToCalendar(page);
|
||||||
|
|
||||||
|
// Scroll the calendar so the 14:00 target area is visible
|
||||||
|
await scrollCalendarToTime(page, '13:00:00');
|
||||||
|
|
||||||
|
const event = page.locator('.fc-event').first();
|
||||||
|
await expect(event).toBeVisible();
|
||||||
|
|
||||||
|
// Get target slot
|
||||||
|
const targetSlot = page.locator('.fc-timegrid-slot-lane[data-time="14:00:00"]').first();
|
||||||
|
const targetBox = await targetSlot.boundingBox();
|
||||||
|
expect(targetBox).not.toBeNull();
|
||||||
|
|
||||||
|
// Drag event
|
||||||
|
const putResponsePromise = page.waitForResponse(
|
||||||
|
(resp) => resp.url().includes('/time-entries/') && resp.request().method() === 'PUT'
|
||||||
|
);
|
||||||
|
|
||||||
|
await event.hover();
|
||||||
|
await page.mouse.down();
|
||||||
|
await page.mouse.move(targetBox!.x + targetBox!.width / 2, targetBox!.y + 5, { steps: 10 });
|
||||||
|
await page.mouse.up();
|
||||||
|
|
||||||
|
const putResponse = await putResponsePromise;
|
||||||
|
expect(putResponse.status()).toBe(200);
|
||||||
|
|
||||||
|
const body = await putResponse.json();
|
||||||
|
const startDate = new Date(body.data.start);
|
||||||
|
const minutes = startDate.getMinutes();
|
||||||
|
|
||||||
|
// With 60-min snap, minutes should be 0 (on the hour)
|
||||||
|
expect(minutes).toBe(0);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('changing snap interval mid-session affects next drag', async ({ page, ctx }) => {
|
||||||
|
// Create a 1h time entry
|
||||||
|
await createBareTimeEntryViaApi(ctx, 'Snap change test', '1h');
|
||||||
|
await goToCalendar(page);
|
||||||
|
|
||||||
|
// Set snap to 15 min
|
||||||
|
await openSettingsPopover(page);
|
||||||
|
await page.getByLabel('Snap Interval').click();
|
||||||
|
await page.getByRole('option', { name: '15 min' }).click();
|
||||||
|
await page.keyboard.press('Escape');
|
||||||
|
|
||||||
|
// Scroll the calendar so the 14:00 target area is visible
|
||||||
|
await scrollCalendarToTime(page, '13:00:00');
|
||||||
|
|
||||||
|
const event = page.locator('.fc-event').first();
|
||||||
|
await expect(event).toBeVisible();
|
||||||
|
|
||||||
|
// Drag event to 14:00 area
|
||||||
|
const targetSlot14 = page.locator('.fc-timegrid-slot-lane[data-time="14:00:00"]').first();
|
||||||
|
const targetBox14 = await targetSlot14.boundingBox();
|
||||||
|
expect(targetBox14).not.toBeNull();
|
||||||
|
|
||||||
|
const putResponsePromise1 = page.waitForResponse(
|
||||||
|
(resp) => resp.url().includes('/time-entries/') && resp.request().method() === 'PUT'
|
||||||
|
);
|
||||||
|
|
||||||
|
await event.hover();
|
||||||
|
await page.mouse.down();
|
||||||
|
await page.mouse.move(targetBox14!.x + targetBox14!.width / 2, targetBox14!.y + 5, {
|
||||||
|
steps: 10,
|
||||||
|
});
|
||||||
|
await page.mouse.up();
|
||||||
|
|
||||||
|
const putResponse1 = await putResponsePromise1;
|
||||||
|
expect(putResponse1.status()).toBe(200);
|
||||||
|
|
||||||
|
const body1 = await putResponse1.json();
|
||||||
|
const startDate1 = new Date(body1.data.start);
|
||||||
|
expect(startDate1.getMinutes() % 15).toBe(0);
|
||||||
|
|
||||||
|
// Wait for query re-fetch/re-renders to fully settle after drag
|
||||||
|
await page.waitForTimeout(1500);
|
||||||
|
|
||||||
|
// Change snap to 30 min
|
||||||
|
// Use Escape first to ensure no stale popover is open, then re-open
|
||||||
|
await page.keyboard.press('Escape');
|
||||||
|
await page.waitForTimeout(300);
|
||||||
|
await openSettingsPopover(page);
|
||||||
|
await page.waitForTimeout(300);
|
||||||
|
await page.getByLabel('Snap Interval').click({ force: true });
|
||||||
|
await page.getByRole('option', { name: '30 min' }).click();
|
||||||
|
await page.keyboard.press('Escape');
|
||||||
|
|
||||||
|
// Scroll the calendar so the 10:00 target area is visible
|
||||||
|
await scrollCalendarToTime(page, '09:00:00');
|
||||||
|
|
||||||
|
// Drag event to 10:00 area
|
||||||
|
const targetSlot10 = page.locator('.fc-timegrid-slot-lane[data-time="10:00:00"]').first();
|
||||||
|
const targetBox10 = await targetSlot10.boundingBox();
|
||||||
|
expect(targetBox10).not.toBeNull();
|
||||||
|
|
||||||
|
const putResponsePromise2 = page.waitForResponse(
|
||||||
|
(resp) => resp.url().includes('/time-entries/') && resp.request().method() === 'PUT'
|
||||||
|
);
|
||||||
|
|
||||||
|
await event.hover();
|
||||||
|
await page.mouse.down();
|
||||||
|
await page.mouse.move(targetBox10!.x + targetBox10!.width / 2, targetBox10!.y + 5, {
|
||||||
|
steps: 10,
|
||||||
|
});
|
||||||
|
await page.mouse.up();
|
||||||
|
|
||||||
|
const putResponse2 = await putResponsePromise2;
|
||||||
|
expect(putResponse2.status()).toBe(200);
|
||||||
|
|
||||||
|
const body2 = await putResponse2.json();
|
||||||
|
const startDate2 = new Date(body2.data.start);
|
||||||
|
expect(startDate2.getMinutes() % 30).toBe(0);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('snap with different grid scale (slot != snap)', async ({ page, ctx }) => {
|
||||||
|
await goToCalendar(page);
|
||||||
|
await openSettingsPopover(page);
|
||||||
|
|
||||||
|
// Set grid scale to 30 min, snap to 5 min
|
||||||
|
await page.getByLabel('Grid Scale').click();
|
||||||
|
await page.getByRole('option', { name: '30 min' }).click();
|
||||||
|
await page.getByLabel('Snap Interval').click();
|
||||||
|
await page.getByRole('option', { name: '5 min', exact: true }).click();
|
||||||
|
await page.keyboard.press('Escape');
|
||||||
|
|
||||||
|
// Wait for re-render with 30-min grid
|
||||||
|
await expect(async () => {
|
||||||
|
const slotCount = await page.locator('.fc-timegrid-slot-lane').count();
|
||||||
|
// 24 hours * 2 slots/hour = 48 slots for 30-min grid
|
||||||
|
expect(slotCount).toBeLessThanOrEqual(48);
|
||||||
|
}).toPass({ timeout: 5000 });
|
||||||
|
|
||||||
|
// Verify grid is 30-min (fewer slots than default 15-min)
|
||||||
|
const slotCount = await page.locator('.fc-timegrid-slot-lane').count();
|
||||||
|
// Default 15-min grid has 96 slots; 30-min grid should have 48
|
||||||
|
expect(slotCount).toBeLessThanOrEqual(48);
|
||||||
|
|
||||||
|
// Create a 1h time entry and go to calendar
|
||||||
|
await createBareTimeEntryViaApi(ctx, 'Grid snap test', '1h');
|
||||||
|
await goToCalendar(page);
|
||||||
|
|
||||||
|
// Re-apply settings since goToCalendar navigates
|
||||||
|
await openSettingsPopover(page);
|
||||||
|
await page.getByLabel('Grid Scale').click();
|
||||||
|
await page.getByRole('option', { name: '30 min' }).click();
|
||||||
|
await page.getByLabel('Snap Interval').click();
|
||||||
|
await page.getByRole('option', { name: '5 min', exact: true }).click();
|
||||||
|
await page.keyboard.press('Escape');
|
||||||
|
|
||||||
|
// Scroll so both the event (9:00) and target (14:00) are in viewport
|
||||||
|
await scrollCalendarToTime(page, '08:00:00');
|
||||||
|
|
||||||
|
const event = page.locator('.fc-event').first();
|
||||||
|
await expect(event).toBeVisible();
|
||||||
|
|
||||||
|
// Capture target coordinates after scroll is settled
|
||||||
|
const targetSlot = page.locator('.fc-timegrid-slot-lane[data-time="14:00:00"]').first();
|
||||||
|
const targetBox = await targetSlot.boundingBox();
|
||||||
|
expect(targetBox).not.toBeNull();
|
||||||
|
|
||||||
|
const putResponsePromise = page.waitForResponse(
|
||||||
|
(resp) => resp.url().includes('/time-entries/') && resp.request().method() === 'PUT'
|
||||||
|
);
|
||||||
|
|
||||||
|
await event.hover();
|
||||||
|
await page.mouse.down();
|
||||||
|
await page.mouse.move(targetBox!.x + targetBox!.width / 2, targetBox!.y + 5, { steps: 10 });
|
||||||
|
await page.mouse.up();
|
||||||
|
|
||||||
|
const putResponse = await putResponsePromise;
|
||||||
|
expect(putResponse.status()).toBe(200);
|
||||||
|
|
||||||
|
const body = await putResponse.json();
|
||||||
|
const startDate = new Date(body.data.start);
|
||||||
|
// Snap is 5 min, so minutes should be divisible by 5
|
||||||
|
expect(startDate.getMinutes() % 5).toBe(0);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
test.describe('Calendar Settings Effects', () => {
|
||||||
|
test.beforeEach(async ({ page }) => {
|
||||||
|
await clearCalendarSettings(page);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('start/end time hides slots outside visible range', async ({ page, ctx }) => {
|
||||||
|
// Create a time entry at 6 AM today
|
||||||
|
const now = new Date();
|
||||||
|
const start = new Date(now.getFullYear(), now.getMonth(), now.getDate(), 6, 0, 0);
|
||||||
|
const end = new Date(start.getTime() + 3600 * 1000); // 7 AM
|
||||||
|
await createTimeEntryWithTimestampsViaApi(ctx, {
|
||||||
|
description: 'Early morning entry',
|
||||||
|
start: start.toISOString().replace(/\.\d{3}Z$/, 'Z'),
|
||||||
|
end: end.toISOString().replace(/\.\d{3}Z$/, 'Z'),
|
||||||
|
});
|
||||||
|
|
||||||
|
await goToCalendar(page);
|
||||||
|
|
||||||
|
// Verify 6 AM slot is visible with default settings
|
||||||
|
await expect(page.locator('.fc-timegrid-slot[data-time="06:00:00"]')).not.toHaveCount(0);
|
||||||
|
|
||||||
|
// Set start time to 8 AM
|
||||||
|
await openSettingsPopover(page);
|
||||||
|
await page.getByLabel('Start Time').click();
|
||||||
|
await page.getByRole('option', { name: '8:00 AM' }).click();
|
||||||
|
await page.keyboard.press('Escape');
|
||||||
|
|
||||||
|
// 6 AM slot should be hidden
|
||||||
|
await expect(page.locator('.fc-timegrid-slot[data-time="06:00:00"]')).toHaveCount(0);
|
||||||
|
|
||||||
|
// 8 AM slot should be visible
|
||||||
|
await expect(page.locator('.fc-timegrid-slot[data-time="08:00:00"]')).not.toHaveCount(0);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('grid scale affects event visual height proportionally', async ({ page, ctx }) => {
|
||||||
|
// Create a 1h time entry
|
||||||
|
await createBareTimeEntryViaApi(ctx, 'Height test', '1h');
|
||||||
|
await goToCalendar(page);
|
||||||
|
|
||||||
|
const event = page.locator('.fc-event').first();
|
||||||
|
await expect(event).toBeVisible();
|
||||||
|
await event.scrollIntoViewIfNeeded();
|
||||||
|
|
||||||
|
// Get event height with default 15-min grid scale
|
||||||
|
const box15 = await event.boundingBox();
|
||||||
|
expect(box15).not.toBeNull();
|
||||||
|
const height15 = box15!.height;
|
||||||
|
|
||||||
|
// Change grid scale to 60 min
|
||||||
|
await openSettingsPopover(page);
|
||||||
|
await page.getByLabel('Grid Scale').click();
|
||||||
|
await page.getByRole('option', { name: '1 hour' }).click();
|
||||||
|
await page.keyboard.press('Escape');
|
||||||
|
|
||||||
|
// Wait for re-render and scroll event into view
|
||||||
|
await event.scrollIntoViewIfNeeded();
|
||||||
|
await expect(async () => {
|
||||||
|
const box = await event.boundingBox();
|
||||||
|
expect(box).not.toBeNull();
|
||||||
|
expect(box!.height).not.toBe(height15);
|
||||||
|
}).toPass({ timeout: 5000 });
|
||||||
|
|
||||||
|
const box60 = await event.boundingBox();
|
||||||
|
expect(box60).not.toBeNull();
|
||||||
|
const height60 = box60!.height;
|
||||||
|
|
||||||
|
// Event should appear smaller with larger grid scale
|
||||||
|
expect(height15).toBeGreaterThan(height60);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('snap interval affects drag granularity', async ({ page, ctx }) => {
|
||||||
|
await goToCalendar(page);
|
||||||
|
await openSettingsPopover(page);
|
||||||
|
|
||||||
|
// Set snap to 30 min
|
||||||
|
await page.getByLabel('Snap Interval').click();
|
||||||
|
await page.getByRole('option', { name: '30 min' }).click();
|
||||||
|
await page.keyboard.press('Escape');
|
||||||
|
|
||||||
|
// Create a 1h time entry
|
||||||
|
await createBareTimeEntryViaApi(ctx, 'Drag granularity test', '1h');
|
||||||
|
await goToCalendar(page);
|
||||||
|
|
||||||
|
// Scroll the calendar so the 14:00 target area is visible
|
||||||
|
await scrollCalendarToTime(page, '13:00:00');
|
||||||
|
|
||||||
|
const event = page.locator('.fc-event').first();
|
||||||
|
await expect(event).toBeVisible();
|
||||||
|
|
||||||
|
// Get target slot
|
||||||
|
const targetSlot = page.locator('.fc-timegrid-slot-lane[data-time="14:00:00"]').first();
|
||||||
|
const targetBox = await targetSlot.boundingBox();
|
||||||
|
expect(targetBox).not.toBeNull();
|
||||||
|
|
||||||
|
// Drag event
|
||||||
|
const putResponsePromise = page.waitForResponse(
|
||||||
|
(resp) => resp.url().includes('/time-entries/') && resp.request().method() === 'PUT'
|
||||||
|
);
|
||||||
|
|
||||||
|
await event.hover();
|
||||||
|
await page.mouse.down();
|
||||||
|
await page.mouse.move(targetBox!.x + targetBox!.width / 2, targetBox!.y + 5, { steps: 10 });
|
||||||
|
await page.mouse.up();
|
||||||
|
|
||||||
|
const putResponse = await putResponsePromise;
|
||||||
|
expect(putResponse.status()).toBe(200);
|
||||||
|
|
||||||
|
const body = await putResponse.json();
|
||||||
|
const startDate = new Date(body.data.start);
|
||||||
|
const minutes = startDate.getMinutes();
|
||||||
|
|
||||||
|
// With 30-min snap, minutes should be 0 or 30
|
||||||
|
expect(minutes % 30).toBe(0);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('settings apply immediately without page reload', async ({ page }) => {
|
||||||
|
await goToCalendar(page);
|
||||||
|
|
||||||
|
// Count slots with default grid scale (15 min)
|
||||||
|
const defaultSlotCount = await page.locator('.fc-timegrid-slot').count();
|
||||||
|
|
||||||
|
// Change grid scale to 30 min
|
||||||
|
await openSettingsPopover(page);
|
||||||
|
await page.getByLabel('Grid Scale').click();
|
||||||
|
await page.getByRole('option', { name: '30 min' }).click();
|
||||||
|
await page.keyboard.press('Escape');
|
||||||
|
|
||||||
|
// Verify slot count changed without navigation
|
||||||
|
await expect(async () => {
|
||||||
|
const count = await page.locator('.fc-timegrid-slot').count();
|
||||||
|
expect(count).toBeLessThan(defaultSlotCount);
|
||||||
|
}).toPass({ timeout: 5000 });
|
||||||
|
|
||||||
|
// Wait for FullCalendar to fully stabilize after re-render
|
||||||
|
await page.waitForTimeout(2000);
|
||||||
|
await expect(page.locator('.fc')).toBeVisible();
|
||||||
|
|
||||||
|
// Change start time to 8 AM
|
||||||
|
// FullCalendar re-render from grid scale change can make popover elements unstable.
|
||||||
|
// Retry the open+click sequence if it fails.
|
||||||
|
await expect(async () => {
|
||||||
|
await page.keyboard.press('Escape');
|
||||||
|
await page.waitForTimeout(300);
|
||||||
|
await page.getByRole('button', { name: 'Calendar settings' }).click();
|
||||||
|
await expect(page.getByText('Calendar Settings')).toBeVisible();
|
||||||
|
const startTimeBtn = page.getByLabel('Start Time');
|
||||||
|
await expect(startTimeBtn).toBeVisible();
|
||||||
|
await startTimeBtn.click({ timeout: 3000 });
|
||||||
|
}).toPass({ timeout: 10000 });
|
||||||
|
|
||||||
|
await page.getByRole('option', { name: '8:00 AM' }).click();
|
||||||
|
await page.keyboard.press('Escape');
|
||||||
|
|
||||||
|
// Verify 7 AM slot is hidden without reload
|
||||||
|
await expect(async () => {
|
||||||
|
const count = await page.locator('.fc-timegrid-slot[data-time="07:00:00"]').count();
|
||||||
|
expect(count).toBe(0);
|
||||||
|
}).toPass({ timeout: 5000 });
|
||||||
|
});
|
||||||
|
});
|
||||||
2566
e2e/calendar.spec.ts
2566
e2e/calendar.spec.ts
File diff suppressed because it is too large
Load Diff
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user