mirror of
https://github.com/solidtime-io/solidtime.git
synced 2026-08-08 16:22:16 +01:00
Compare commits
4 Commits
v0.15.1
...
feature/e2
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
785c8b939f | ||
|
|
b2fa07b38b | ||
|
|
5b053bc2c1 | ||
|
|
b775aaf1df |
2
.env.ci
2
.env.ci
@@ -60,7 +60,7 @@ AUDITING_ENABLED=true
|
|||||||
TELESCOPE_ENABLED=false
|
TELESCOPE_ENABLED=false
|
||||||
|
|
||||||
# Services
|
# Services
|
||||||
GOTENBERG_URL=http://localhost:3000
|
GOTENBERG_URL=http://0.0.0.0:3000
|
||||||
|
|
||||||
# Octane
|
# Octane
|
||||||
OCTANE_SERVER=frankenphp
|
OCTANE_SERVER=frankenphp
|
||||||
|
|||||||
@@ -77,9 +77,6 @@ TELESCOPE_ENABLED=false
|
|||||||
# Services
|
# Services
|
||||||
GOTENBERG_URL=http://gotenberg:3000
|
GOTENBERG_URL=http://gotenberg:3000
|
||||||
|
|
||||||
# Octane
|
|
||||||
OCTANE_SERVER=frankenphp
|
|
||||||
|
|
||||||
# Local setup
|
# Local setup
|
||||||
NGINX_HOST_NAME=solidtime.test
|
NGINX_HOST_NAME=solidtime.test
|
||||||
NETWORK_NAME=reverse-proxy-docker-traefik_routing
|
NETWORK_NAME=reverse-proxy-docker-traefik_routing
|
||||||
|
|||||||
30
.github/workflows/build-onpremise.yml
vendored
30
.github/workflows/build-onpremise.yml
vendored
@@ -35,7 +35,7 @@ jobs:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: "Check out code"
|
- name: "Check out code"
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0 # Required for WyriHaximus/github-action-get-previous-tag
|
fetch-depth: 0 # Required for WyriHaximus/github-action-get-previous-tag
|
||||||
|
|
||||||
@@ -46,9 +46,9 @@ jobs:
|
|||||||
- name: "Get Previous tag (normal push)"
|
- name: "Get Previous tag (normal push)"
|
||||||
id: previoustag
|
id: previoustag
|
||||||
if: ${{ !startsWith(github.ref, 'refs/tags/v') }}
|
if: ${{ !startsWith(github.ref, 'refs/tags/v') }}
|
||||||
uses: "WyriHaximus/github-action-get-previous-tag@v2"
|
uses: "WyriHaximus/github-action-get-previous-tag@v1"
|
||||||
with:
|
with:
|
||||||
pattern: "v*[0-9].*[0-9].*[0-9]"
|
prefix: "v"
|
||||||
|
|
||||||
- name: "Get version"
|
- name: "Get version"
|
||||||
id: release-version
|
id: release-version
|
||||||
@@ -91,12 +91,12 @@ jobs:
|
|||||||
if: steps.cache-vendor.outputs.cache-hit != 'true' # Skip if cache hit
|
if: steps.cache-vendor.outputs.cache-hit != 'true' # Skip if cache hit
|
||||||
|
|
||||||
- name: "Use Node.js"
|
- name: "Use Node.js"
|
||||||
uses: actions/setup-node@v6
|
uses: actions/setup-node@v4
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
|
|
||||||
- name: "Checkout invoicing extension"
|
- name: "Checkout invoicing extension"
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
repository: solidtime-io/extension-invoicing
|
repository: solidtime-io/extension-invoicing
|
||||||
path: extensions/Invoicing
|
path: extensions/Invoicing
|
||||||
@@ -124,27 +124,27 @@ jobs:
|
|||||||
|
|
||||||
- name: "Docker meta"
|
- name: "Docker meta"
|
||||||
id: "meta"
|
id: "meta"
|
||||||
uses: docker/metadata-action@v6
|
uses: docker/metadata-action@v5
|
||||||
with:
|
with:
|
||||||
images: |
|
images: |
|
||||||
${{ env.DOCKER_REPO }}
|
${{ env.DOCKER_REPO }}
|
||||||
|
|
||||||
- name: "Login to solidtime OnPremise Registry"
|
- name: "Login to solidtime OnPremise Registry"
|
||||||
uses: docker/login-action@v4
|
uses: docker/login-action@v3
|
||||||
with:
|
with:
|
||||||
registry: registry.on-premise.solidtime.io
|
registry: registry.on-premise.solidtime.io
|
||||||
username: ${{ secrets.ONPREMISE_USERNAME }}
|
username: ${{ secrets.ONPREMISE_USERNAME }}
|
||||||
password: ${{ secrets.ONPREMISE_TOKEN }}
|
password: ${{ secrets.ONPREMISE_TOKEN }}
|
||||||
|
|
||||||
- name: "Set up QEMU"
|
- name: "Set up QEMU"
|
||||||
uses: docker/setup-qemu-action@v4
|
uses: docker/setup-qemu-action@v3
|
||||||
|
|
||||||
- name: "Set up Docker Buildx"
|
- name: "Set up Docker Buildx"
|
||||||
uses: docker/setup-buildx-action@v4
|
uses: docker/setup-buildx-action@v3
|
||||||
|
|
||||||
- name: "Build and push by digest"
|
- name: "Build and push by digest"
|
||||||
id: build
|
id: build
|
||||||
uses: docker/build-push-action@v7
|
uses: docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: .
|
context: .
|
||||||
file: docker/prod/Dockerfile
|
file: docker/prod/Dockerfile
|
||||||
@@ -163,7 +163,7 @@ jobs:
|
|||||||
touch "${{ runner.temp }}/digests/${digest#sha256:}"
|
touch "${{ runner.temp }}/digests/${digest#sha256:}"
|
||||||
|
|
||||||
- name: "Upload digest"
|
- name: "Upload digest"
|
||||||
uses: actions/upload-artifact@v7
|
uses: actions/upload-artifact@v4
|
||||||
with:
|
with:
|
||||||
name: digests-${{ env.PLATFORM_PAIR }}
|
name: digests-${{ env.PLATFORM_PAIR }}
|
||||||
path: ${{ runner.temp }}/digests/*
|
path: ${{ runner.temp }}/digests/*
|
||||||
@@ -177,25 +177,25 @@ jobs:
|
|||||||
- build
|
- build
|
||||||
steps:
|
steps:
|
||||||
- name: "Download digests"
|
- name: "Download digests"
|
||||||
uses: actions/download-artifact@v8
|
uses: actions/download-artifact@v4
|
||||||
with:
|
with:
|
||||||
path: ${{ runner.temp }}/digests
|
path: ${{ runner.temp }}/digests
|
||||||
pattern: digests-*
|
pattern: digests-*
|
||||||
merge-multiple: true
|
merge-multiple: true
|
||||||
|
|
||||||
- name: "Login to solidtime OnPremise Registry"
|
- name: "Login to solidtime OnPremise Registry"
|
||||||
uses: docker/login-action@v4
|
uses: docker/login-action@v3
|
||||||
with:
|
with:
|
||||||
registry: registry.on-premise.solidtime.io
|
registry: registry.on-premise.solidtime.io
|
||||||
username: ${{ secrets.ONPREMISE_USERNAME }}
|
username: ${{ secrets.ONPREMISE_USERNAME }}
|
||||||
password: ${{ secrets.ONPREMISE_TOKEN }}
|
password: ${{ secrets.ONPREMISE_TOKEN }}
|
||||||
|
|
||||||
- name: "Set up Docker Buildx"
|
- name: "Set up Docker Buildx"
|
||||||
uses: docker/setup-buildx-action@v4
|
uses: docker/setup-buildx-action@v3
|
||||||
|
|
||||||
- name: "Docker meta"
|
- name: "Docker meta"
|
||||||
id: meta
|
id: meta
|
||||||
uses: docker/metadata-action@v6
|
uses: docker/metadata-action@v5
|
||||||
with:
|
with:
|
||||||
images: |
|
images: |
|
||||||
${{ env.DOCKER_REPO }}
|
${{ env.DOCKER_REPO }}
|
||||||
|
|||||||
24
.github/workflows/build-private.yml
vendored
24
.github/workflows/build-private.yml
vendored
@@ -22,7 +22,7 @@ jobs:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: "Check out code"
|
- name: "Check out code"
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0 # Required for WyriHaximus/github-action-get-previous-tag
|
fetch-depth: 0 # Required for WyriHaximus/github-action-get-previous-tag
|
||||||
|
|
||||||
@@ -33,9 +33,9 @@ jobs:
|
|||||||
- name: "Get Previous tag (normal push)"
|
- name: "Get Previous tag (normal push)"
|
||||||
id: previoustag
|
id: previoustag
|
||||||
if: ${{ !startsWith(github.ref, 'refs/tags/v') }}
|
if: ${{ !startsWith(github.ref, 'refs/tags/v') }}
|
||||||
uses: "WyriHaximus/github-action-get-previous-tag@v2"
|
uses: "WyriHaximus/github-action-get-previous-tag@v1"
|
||||||
with:
|
with:
|
||||||
pattern: "v*[0-9].*[0-9].*[0-9]"
|
prefix: "v"
|
||||||
|
|
||||||
- name: "Get version"
|
- name: "Get version"
|
||||||
id: version
|
id: version
|
||||||
@@ -68,12 +68,12 @@ jobs:
|
|||||||
run: cat .env
|
run: cat .env
|
||||||
|
|
||||||
- name: "Use Node.js"
|
- name: "Use Node.js"
|
||||||
uses: actions/setup-node@v6
|
uses: actions/setup-node@v4
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
|
|
||||||
- name: "Checkout billing extension"
|
- name: "Checkout billing extension"
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
repository: solidtime-io/extension-billing
|
repository: solidtime-io/extension-billing
|
||||||
path: extensions/Billing
|
path: extensions/Billing
|
||||||
@@ -93,7 +93,7 @@ jobs:
|
|||||||
run: cd extensions/Billing && npm ci
|
run: cd extensions/Billing && npm ci
|
||||||
|
|
||||||
- name: "Checkout services extension"
|
- name: "Checkout services extension"
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
repository: solidtime-io/extension-services
|
repository: solidtime-io/extension-services
|
||||||
path: extensions/Services
|
path: extensions/Services
|
||||||
@@ -111,7 +111,7 @@ jobs:
|
|||||||
run: cd extensions/Services && npm ci
|
run: cd extensions/Services && npm ci
|
||||||
|
|
||||||
- name: "Checkout invoicing extension"
|
- name: "Checkout invoicing extension"
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
repository: solidtime-io/extension-invoicing
|
repository: solidtime-io/extension-invoicing
|
||||||
path: extensions/Invoicing
|
path: extensions/Invoicing
|
||||||
@@ -160,7 +160,7 @@ jobs:
|
|||||||
SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }}
|
SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }}
|
||||||
|
|
||||||
- name: "Login to GitHub Container Registry"
|
- name: "Login to GitHub Container Registry"
|
||||||
uses: docker/login-action@v4
|
uses: docker/login-action@v3
|
||||||
with:
|
with:
|
||||||
registry: rg.fr-par.scw.cloud/solidtime
|
registry: rg.fr-par.scw.cloud/solidtime
|
||||||
username: nologin
|
username: nologin
|
||||||
@@ -168,7 +168,7 @@ jobs:
|
|||||||
|
|
||||||
- name: "Docker meta"
|
- name: "Docker meta"
|
||||||
id: "meta"
|
id: "meta"
|
||||||
uses: docker/metadata-action@v6
|
uses: docker/metadata-action@v5
|
||||||
with:
|
with:
|
||||||
images: rg.fr-par.scw.cloud/solidtime/solidtime
|
images: rg.fr-par.scw.cloud/solidtime/solidtime
|
||||||
tags: |
|
tags: |
|
||||||
@@ -179,13 +179,13 @@ jobs:
|
|||||||
type=sha,format=long
|
type=sha,format=long
|
||||||
|
|
||||||
- name: "Set up QEMU"
|
- name: "Set up QEMU"
|
||||||
uses: docker/setup-qemu-action@v4
|
uses: docker/setup-qemu-action@v3
|
||||||
|
|
||||||
- name: "Set up Docker Buildx"
|
- name: "Set up Docker Buildx"
|
||||||
uses: docker/setup-buildx-action@v4
|
uses: docker/setup-buildx-action@v3
|
||||||
|
|
||||||
- name: "Build and push"
|
- name: "Build and push"
|
||||||
uses: docker/build-push-action@v7
|
uses: docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: .
|
context: .
|
||||||
build-args: |
|
build-args: |
|
||||||
|
|||||||
32
.github/workflows/build-public.yml
vendored
32
.github/workflows/build-public.yml
vendored
@@ -36,7 +36,7 @@ jobs:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: "Check out code"
|
- name: "Check out code"
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0 # Required for WyriHaximus/github-action-get-previous-tag
|
fetch-depth: 0 # Required for WyriHaximus/github-action-get-previous-tag
|
||||||
|
|
||||||
@@ -47,9 +47,9 @@ jobs:
|
|||||||
- name: "Get Previous tag (normal push)"
|
- name: "Get Previous tag (normal push)"
|
||||||
id: previoustag
|
id: previoustag
|
||||||
if: ${{ !startsWith(github.ref, 'refs/tags/v') }}
|
if: ${{ !startsWith(github.ref, 'refs/tags/v') }}
|
||||||
uses: "WyriHaximus/github-action-get-previous-tag@v2"
|
uses: "WyriHaximus/github-action-get-previous-tag@v1"
|
||||||
with:
|
with:
|
||||||
pattern: "v*[0-9].*[0-9].*[0-9]"
|
prefix: "v"
|
||||||
|
|
||||||
- name: "Get version"
|
- name: "Get version"
|
||||||
id: release-version
|
id: release-version
|
||||||
@@ -92,7 +92,7 @@ jobs:
|
|||||||
if: steps.cache-vendor.outputs.cache-hit != 'true' # Skip if cache hit
|
if: steps.cache-vendor.outputs.cache-hit != 'true' # Skip if cache hit
|
||||||
|
|
||||||
- name: "Use Node.js"
|
- name: "Use Node.js"
|
||||||
uses: actions/setup-node@v6
|
uses: actions/setup-node@v4
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
|
|
||||||
@@ -109,34 +109,34 @@ jobs:
|
|||||||
|
|
||||||
- name: "Docker meta"
|
- name: "Docker meta"
|
||||||
id: "meta"
|
id: "meta"
|
||||||
uses: docker/metadata-action@v6
|
uses: docker/metadata-action@v5
|
||||||
with:
|
with:
|
||||||
images: |
|
images: |
|
||||||
${{ env.DOCKERHUB_REPO }}
|
${{ env.DOCKERHUB_REPO }}
|
||||||
${{ env.GHCR_REPO }}
|
${{ env.GHCR_REPO }}
|
||||||
|
|
||||||
- name: "Login to Docker Hub Container Registry"
|
- name: "Login to Docker Hub Container Registry"
|
||||||
uses: docker/login-action@v4
|
uses: docker/login-action@v3
|
||||||
with:
|
with:
|
||||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||||
|
|
||||||
- name: "Login to GitHub Container Registry"
|
- name: "Login to GitHub Container Registry"
|
||||||
uses: docker/login-action@v4
|
uses: docker/login-action@v3
|
||||||
with:
|
with:
|
||||||
registry: ghcr.io
|
registry: ghcr.io
|
||||||
username: ${{ github.actor }}
|
username: ${{ github.actor }}
|
||||||
password: ${{ secrets.GITHUB_TOKEN }}
|
password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
|
||||||
- name: "Set up QEMU"
|
- name: "Set up QEMU"
|
||||||
uses: docker/setup-qemu-action@v4
|
uses: docker/setup-qemu-action@v3
|
||||||
|
|
||||||
- name: "Set up Docker Buildx"
|
- name: "Set up Docker Buildx"
|
||||||
uses: docker/setup-buildx-action@v4
|
uses: docker/setup-buildx-action@v3
|
||||||
|
|
||||||
- name: "Build and push by digest"
|
- name: "Build and push by digest"
|
||||||
id: build
|
id: build
|
||||||
uses: docker/build-push-action@v7
|
uses: docker/build-push-action@v6
|
||||||
with:
|
with:
|
||||||
context: .
|
context: .
|
||||||
file: docker/prod/Dockerfile
|
file: docker/prod/Dockerfile
|
||||||
@@ -155,7 +155,7 @@ jobs:
|
|||||||
touch "${{ runner.temp }}/digests/${digest#sha256:}"
|
touch "${{ runner.temp }}/digests/${digest#sha256:}"
|
||||||
|
|
||||||
- name: "Upload digest"
|
- name: "Upload digest"
|
||||||
uses: actions/upload-artifact@v7
|
uses: actions/upload-artifact@v4
|
||||||
with:
|
with:
|
||||||
name: digests-${{ env.PLATFORM_PAIR }}
|
name: digests-${{ env.PLATFORM_PAIR }}
|
||||||
path: ${{ runner.temp }}/digests/*
|
path: ${{ runner.temp }}/digests/*
|
||||||
@@ -169,31 +169,31 @@ jobs:
|
|||||||
- build
|
- build
|
||||||
steps:
|
steps:
|
||||||
- name: "Download digests"
|
- name: "Download digests"
|
||||||
uses: actions/download-artifact@v8
|
uses: actions/download-artifact@v4
|
||||||
with:
|
with:
|
||||||
path: ${{ runner.temp }}/digests
|
path: ${{ runner.temp }}/digests
|
||||||
pattern: digests-*
|
pattern: digests-*
|
||||||
merge-multiple: true
|
merge-multiple: true
|
||||||
|
|
||||||
- name: "Login to Docker Hub"
|
- name: "Login to Docker Hub"
|
||||||
uses: docker/login-action@v4
|
uses: docker/login-action@v3
|
||||||
with:
|
with:
|
||||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||||
|
|
||||||
- name: "Login to GHCR"
|
- name: "Login to GHCR"
|
||||||
uses: docker/login-action@v4
|
uses: docker/login-action@v3
|
||||||
with:
|
with:
|
||||||
registry: ghcr.io
|
registry: ghcr.io
|
||||||
username: ${{ github.actor }}
|
username: ${{ github.actor }}
|
||||||
password: ${{ secrets.GITHUB_TOKEN }}
|
password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
|
||||||
- name: "Set up Docker Buildx"
|
- name: "Set up Docker Buildx"
|
||||||
uses: docker/setup-buildx-action@v4
|
uses: docker/setup-buildx-action@v3
|
||||||
|
|
||||||
- name: "Docker meta"
|
- name: "Docker meta"
|
||||||
id: meta
|
id: meta
|
||||||
uses: docker/metadata-action@v6
|
uses: docker/metadata-action@v5
|
||||||
with:
|
with:
|
||||||
images: |
|
images: |
|
||||||
${{ env.DOCKERHUB_REPO }}
|
${{ env.DOCKERHUB_REPO }}
|
||||||
|
|||||||
4
.github/workflows/generate-api-docs.yml
vendored
4
.github/workflows/generate-api-docs.yml
vendored
@@ -29,7 +29,7 @@ jobs:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: "Setup PHP"
|
- name: "Setup PHP"
|
||||||
uses: shivammathur/setup-php@v2
|
uses: shivammathur/setup-php@v2
|
||||||
@@ -52,7 +52,7 @@ jobs:
|
|||||||
run: php artisan scramble:export --path=build/api-docs.json
|
run: php artisan scramble:export --path=build/api-docs.json
|
||||||
|
|
||||||
- name: "Upload API docs to GitHub"
|
- name: "Upload API docs to GitHub"
|
||||||
uses: actions/upload-artifact@v7
|
uses: actions/upload-artifact@v4
|
||||||
with:
|
with:
|
||||||
name: api-docs.json
|
name: api-docs.json
|
||||||
path: build/api-docs.json
|
path: build/api-docs.json
|
||||||
|
|||||||
4
.github/workflows/npm-build.yml
vendored
4
.github/workflows/npm-build.yml
vendored
@@ -11,7 +11,7 @@ jobs:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: "Setup PHP (for Ziggy)"
|
- name: "Setup PHP (for Ziggy)"
|
||||||
uses: shivammathur/setup-php@v2
|
uses: shivammathur/setup-php@v2
|
||||||
@@ -24,7 +24,7 @@ jobs:
|
|||||||
run: composer install -n --prefer-dist
|
run: composer install -n --prefer-dist
|
||||||
|
|
||||||
- name: "Use Node.js"
|
- name: "Use Node.js"
|
||||||
uses: actions/setup-node@v6
|
uses: actions/setup-node@v4
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
|
|
||||||
|
|||||||
4
.github/workflows/npm-format-check.yml
vendored
4
.github/workflows/npm-format-check.yml
vendored
@@ -9,10 +9,10 @@ jobs:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: "Use Node.js"
|
- name: "Use Node.js"
|
||||||
uses: actions/setup-node@v6
|
uses: actions/setup-node@v4
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
|
|
||||||
|
|||||||
4
.github/workflows/npm-lint.yml
vendored
4
.github/workflows/npm-lint.yml
vendored
@@ -11,10 +11,10 @@ jobs:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: "Use Node.js"
|
- name: "Use Node.js"
|
||||||
uses: actions/setup-node@v6
|
uses: actions/setup-node@v4
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
|
|
||||||
|
|||||||
4
.github/workflows/npm-publish-api.yml
vendored
4
.github/workflows/npm-publish-api.yml
vendored
@@ -11,11 +11,11 @@ jobs:
|
|||||||
id-token: write
|
id-token: write
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v4
|
||||||
# Setup .npmrc file to publish to npm
|
# Setup .npmrc file to publish to npm
|
||||||
- name: Install root project dependencies
|
- name: Install root project dependencies
|
||||||
run: npm ci
|
run: npm ci
|
||||||
- uses: actions/setup-node@v6
|
- uses: actions/setup-node@v4
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
registry-url: 'https://registry.npmjs.org'
|
registry-url: 'https://registry.npmjs.org'
|
||||||
|
|||||||
4
.github/workflows/npm-publish-ui.yml
vendored
4
.github/workflows/npm-publish-ui.yml
vendored
@@ -11,9 +11,9 @@ jobs:
|
|||||||
id-token: write
|
id-token: write
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v4
|
||||||
# Setup .npmrc file to publish to npm
|
# Setup .npmrc file to publish to npm
|
||||||
- uses: actions/setup-node@v6
|
- uses: actions/setup-node@v4
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
registry-url: 'https://registry.npmjs.org'
|
registry-url: 'https://registry.npmjs.org'
|
||||||
|
|||||||
27
.github/workflows/npm-test-unit.yml
vendored
27
.github/workflows/npm-test-unit.yml
vendored
@@ -1,27 +0,0 @@
|
|||||||
name: NPM Test Unit
|
|
||||||
|
|
||||||
on: [push]
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
build:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
timeout-minutes: 10
|
|
||||||
env:
|
|
||||||
TZ: UTC
|
|
||||||
|
|
||||||
steps:
|
|
||||||
- name: "Checkout code"
|
|
||||||
uses: actions/checkout@v6
|
|
||||||
|
|
||||||
- name: "Use Node.js"
|
|
||||||
uses: actions/setup-node@v6
|
|
||||||
with:
|
|
||||||
node-version: '20.x'
|
|
||||||
|
|
||||||
- name: "Install npm dependencies"
|
|
||||||
run: npm ci
|
|
||||||
|
|
||||||
- name: "Run vitest"
|
|
||||||
run: npm run test:unit
|
|
||||||
4
.github/workflows/npm-typecheck.yml
vendored
4
.github/workflows/npm-typecheck.yml
vendored
@@ -10,7 +10,7 @@ jobs:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: "Setup PHP (for Ziggy)"
|
- name: "Setup PHP (for Ziggy)"
|
||||||
uses: shivammathur/setup-php@v2
|
uses: shivammathur/setup-php@v2
|
||||||
@@ -23,7 +23,7 @@ jobs:
|
|||||||
run: composer install -n --prefer-dist
|
run: composer install -n --prefer-dist
|
||||||
|
|
||||||
- name: "Use Node.js"
|
- name: "Use Node.js"
|
||||||
uses: actions/setup-node@v6
|
uses: actions/setup-node@v4
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
|
|
||||||
|
|||||||
2
.github/workflows/phpstan.yml
vendored
2
.github/workflows/phpstan.yml
vendored
@@ -9,7 +9,7 @@ jobs:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: "Setup PHP"
|
- name: "Setup PHP"
|
||||||
uses: shivammathur/setup-php@v2
|
uses: shivammathur/setup-php@v2
|
||||||
|
|||||||
6
.github/workflows/phpunit.yml
vendored
6
.github/workflows/phpunit.yml
vendored
@@ -36,7 +36,7 @@ jobs:
|
|||||||
--health-retries 5
|
--health-retries 5
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: "Setup PHP"
|
- name: "Setup PHP"
|
||||||
uses: shivammathur/setup-php@v2
|
uses: shivammathur/setup-php@v2
|
||||||
@@ -48,7 +48,7 @@ jobs:
|
|||||||
- name: "Run composer install"
|
- name: "Run composer install"
|
||||||
run: composer install -n --prefer-dist
|
run: composer install -n --prefer-dist
|
||||||
|
|
||||||
- uses: actions/setup-node@v6
|
- uses: actions/setup-node@v4
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
|
|
||||||
@@ -68,7 +68,7 @@ jobs:
|
|||||||
run: php artisan test --stop-on-failure --coverage-text --coverage-clover=coverage.xml
|
run: php artisan test --stop-on-failure --coverage-text --coverage-clover=coverage.xml
|
||||||
|
|
||||||
- name: "Upload coverage reports to Codecov"
|
- name: "Upload coverage reports to Codecov"
|
||||||
uses: codecov/codecov-action@v7.0.0
|
uses: codecov/codecov-action@v5.4.3
|
||||||
with:
|
with:
|
||||||
token: ${{ secrets.CODECOV_TOKEN }}
|
token: ${{ secrets.CODECOV_TOKEN }}
|
||||||
slug: solidtime-io/solidtime
|
slug: solidtime-io/solidtime
|
||||||
|
|||||||
4
.github/workflows/pint.yml
vendored
4
.github/workflows/pint.yml
vendored
@@ -9,9 +9,9 @@ jobs:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: "Check code style"
|
- name: "Check code style"
|
||||||
uses: aglipanci/laravel-pint-action@2.6
|
uses: aglipanci/laravel-pint-action@2.5
|
||||||
with:
|
with:
|
||||||
configPath: "pint.json"
|
configPath: "pint.json"
|
||||||
|
|||||||
14
.github/workflows/playwright.yml
vendored
14
.github/workflows/playwright.yml
vendored
@@ -35,10 +35,10 @@ jobs:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: "Setup node"
|
- name: "Setup node"
|
||||||
uses: actions/setup-node@v6
|
uses: actions/setup-node@v4
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
|
|
||||||
@@ -86,7 +86,7 @@ jobs:
|
|||||||
MAILPIT_BASE_URL: 'http://localhost:8025'
|
MAILPIT_BASE_URL: 'http://localhost:8025'
|
||||||
|
|
||||||
- name: "Upload blob report"
|
- name: "Upload blob report"
|
||||||
uses: actions/upload-artifact@v7
|
uses: actions/upload-artifact@v4
|
||||||
if: always()
|
if: always()
|
||||||
with:
|
with:
|
||||||
name: blob-report-${{ matrix.shardIndex }}
|
name: blob-report-${{ matrix.shardIndex }}
|
||||||
@@ -99,10 +99,10 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: "Checkout code"
|
||||||
uses: actions/checkout@v6
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: "Setup node"
|
- name: "Setup node"
|
||||||
uses: actions/setup-node@v6
|
uses: actions/setup-node@v4
|
||||||
with:
|
with:
|
||||||
node-version: '20.x'
|
node-version: '20.x'
|
||||||
|
|
||||||
@@ -110,7 +110,7 @@ jobs:
|
|||||||
run: npm ci
|
run: npm ci
|
||||||
|
|
||||||
- name: "Download blob reports"
|
- name: "Download blob reports"
|
||||||
uses: actions/download-artifact@v8
|
uses: actions/download-artifact@v4
|
||||||
with:
|
with:
|
||||||
path: all-blob-reports
|
path: all-blob-reports
|
||||||
pattern: blob-report-*
|
pattern: blob-report-*
|
||||||
@@ -120,7 +120,7 @@ jobs:
|
|||||||
run: npx playwright merge-reports --reporter html ./all-blob-reports
|
run: npx playwright merge-reports --reporter html ./all-blob-reports
|
||||||
|
|
||||||
- name: "Upload merged HTML report"
|
- name: "Upload merged HTML report"
|
||||||
uses: actions/upload-artifact@v7
|
uses: actions/upload-artifact@v4
|
||||||
with:
|
with:
|
||||||
name: playwright-report
|
name: playwright-report
|
||||||
path: playwright-report/
|
path: playwright-report/
|
||||||
|
|||||||
1
.gitignore
vendored
1
.gitignore
vendored
@@ -42,4 +42,3 @@ yarn-error.log
|
|||||||
/data
|
/data
|
||||||
/config/caddy
|
/config/caddy
|
||||||
/config/composer
|
/config/composer
|
||||||
/AGENTS.md
|
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
# solidtime - The modern Open-Source TimeTracker
|
# solidtime - The modern Open-Source Time Tracker
|
||||||
|
|
||||||
[](https://github.com/solidtime-io/solidtime/blob/main/LICENSE.md)
|
[](https://github.com/solidtime-io/solidtime/blob/main/LICENSE.md)
|
||||||
[](https://codecov.io/gh/solidtime-io/solidtime)
|
[](https://codecov.io/gh/solidtime-io/solidtime)
|
||||||
|
|||||||
15
SECURITY.md
15
SECURITY.md
@@ -3,18 +3,3 @@
|
|||||||
## Reporting a Vulnerability
|
## Reporting a Vulnerability
|
||||||
|
|
||||||
If you discover a security vulnerability regarding this project, please e-mail me to [security@solidtime.io](mailto:security@solidtime.io)!
|
If you discover a security vulnerability regarding this project, please e-mail me to [security@solidtime.io](mailto:security@solidtime.io)!
|
||||||
|
|
||||||
## Out of scope
|
|
||||||
|
|
||||||
|
|
||||||
Reports we typically won't issue an advisory for:
|
|
||||||
|
|
||||||
* Theoretical findings without a working PoC
|
|
||||||
* Raw scanner output without manual validation
|
|
||||||
* Missing/weak security headers in isolation (CSP, X-Frame-Options, HSTS, etc.)
|
|
||||||
* SPF/DKIM/DMARC on non-mail-sending domains; missing DNSSEC/CAA; TLS cipher preferences
|
|
||||||
* Self-XSS; CSRF on non-state-changing endpoints (logout, theme)
|
|
||||||
* CSV / spreadsheet formula injection in exports — treated as a spreadsheet-application issue
|
|
||||||
* Org owners or admins acting destructively within their own organization
|
|
||||||
* Anything requiring direct DB, shell, or filesystem access on a self-hosted instance
|
|
||||||
* Missing OAuth Scope enforcement (this is not implemented yet, but AI scanners flag it which is why it is included in this list until we actually support it)
|
|
||||||
|
|||||||
@@ -16,6 +16,7 @@ use Illuminate\Support\Facades\Validator;
|
|||||||
use Illuminate\Validation\ValidationException;
|
use Illuminate\Validation\ValidationException;
|
||||||
use Korridor\LaravelModelValidationRules\Rules\UniqueEloquent;
|
use Korridor\LaravelModelValidationRules\Rules\UniqueEloquent;
|
||||||
use Laravel\Fortify\Contracts\CreatesNewUsers;
|
use Laravel\Fortify\Contracts\CreatesNewUsers;
|
||||||
|
use Laravel\Jetstream\Jetstream;
|
||||||
use Log;
|
use Log;
|
||||||
|
|
||||||
class CreateNewUser implements CreatesNewUsers
|
class CreateNewUser implements CreatesNewUsers
|
||||||
@@ -54,7 +55,7 @@ class CreateNewUser implements CreatesNewUsers
|
|||||||
}),
|
}),
|
||||||
],
|
],
|
||||||
'password' => $this->passwordRules(),
|
'password' => $this->passwordRules(),
|
||||||
'terms' => ['accepted', 'required'],
|
'terms' => Jetstream::hasTermsAndPrivacyPolicyFeature() ? ['accepted', 'required'] : '',
|
||||||
'newsletter_consent' => [
|
'newsletter_consent' => [
|
||||||
'boolean',
|
'boolean',
|
||||||
],
|
],
|
||||||
|
|||||||
@@ -4,9 +4,13 @@ declare(strict_types=1);
|
|||||||
|
|
||||||
namespace App\Actions\Fortify;
|
namespace App\Actions\Fortify;
|
||||||
|
|
||||||
use App\Exceptions\MovedToApiException;
|
use App\Enums\Weekday;
|
||||||
use App\Models\User;
|
use App\Models\User;
|
||||||
|
use Illuminate\Database\Eloquent\Builder;
|
||||||
|
use Illuminate\Support\Facades\Validator;
|
||||||
|
use Illuminate\Validation\Rule;
|
||||||
use Illuminate\Validation\ValidationException;
|
use Illuminate\Validation\ValidationException;
|
||||||
|
use Korridor\LaravelModelValidationRules\Rules\UniqueEloquent;
|
||||||
use Laravel\Fortify\Contracts\UpdatesUserProfileInformation;
|
use Laravel\Fortify\Contracts\UpdatesUserProfileInformation;
|
||||||
|
|
||||||
class UpdateUserProfileInformation implements UpdatesUserProfileInformation
|
class UpdateUserProfileInformation implements UpdatesUserProfileInformation
|
||||||
@@ -20,6 +24,56 @@ class UpdateUserProfileInformation implements UpdatesUserProfileInformation
|
|||||||
*/
|
*/
|
||||||
public function update(User $user, array $input): void
|
public function update(User $user, array $input): void
|
||||||
{
|
{
|
||||||
throw new MovedToApiException;
|
Validator::make($input, [
|
||||||
|
'name' => [
|
||||||
|
'required',
|
||||||
|
'string',
|
||||||
|
'max:255',
|
||||||
|
],
|
||||||
|
'email' => [
|
||||||
|
'required',
|
||||||
|
'email',
|
||||||
|
'max:255',
|
||||||
|
UniqueEloquent::make(User::class, 'email')->ignore($user->id)->query(function (Builder $query) {
|
||||||
|
/** @var Builder<User> $query */
|
||||||
|
return $query->where('is_placeholder', '=', false);
|
||||||
|
}),
|
||||||
|
],
|
||||||
|
'photo' => [
|
||||||
|
'nullable',
|
||||||
|
'mimes:jpg,jpeg,png',
|
||||||
|
'max:1024',
|
||||||
|
],
|
||||||
|
'timezone' => [
|
||||||
|
'required',
|
||||||
|
'timezone:all',
|
||||||
|
],
|
||||||
|
'week_start' => [
|
||||||
|
'required',
|
||||||
|
Rule::enum(Weekday::class),
|
||||||
|
],
|
||||||
|
])->validateWithBag('updateProfileInformation');
|
||||||
|
|
||||||
|
if (isset($input['photo'])) {
|
||||||
|
$user->updateProfilePhoto($input['photo']);
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($input['email'] !== $user->email) {
|
||||||
|
$user->forceFill([
|
||||||
|
'name' => $input['name'],
|
||||||
|
'email' => $input['email'],
|
||||||
|
'email_verified_at' => null,
|
||||||
|
'timezone' => $input['timezone'],
|
||||||
|
'week_start' => $input['week_start'],
|
||||||
|
])->save();
|
||||||
|
|
||||||
|
$user->sendEmailVerificationNotification();
|
||||||
|
} else {
|
||||||
|
$user->forceFill([
|
||||||
|
'name' => $input['name'],
|
||||||
|
'timezone' => $input['timezone'],
|
||||||
|
'week_start' => $input['week_start'],
|
||||||
|
])->save();
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
94
app/Actions/Jetstream/AddOrganizationMember.php
Normal file
94
app/Actions/Jetstream/AddOrganizationMember.php
Normal file
@@ -0,0 +1,94 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Actions\Jetstream;
|
||||||
|
|
||||||
|
use App\Enums\Role;
|
||||||
|
use App\Models\Organization;
|
||||||
|
use App\Models\User;
|
||||||
|
use App\Service\MemberService;
|
||||||
|
use Closure;
|
||||||
|
use Illuminate\Contracts\Validation\ValidationRule;
|
||||||
|
use Illuminate\Database\Eloquent\Builder;
|
||||||
|
use Illuminate\Support\Facades\Gate;
|
||||||
|
use Illuminate\Support\Facades\Validator;
|
||||||
|
use Illuminate\Validation\Rule;
|
||||||
|
use Illuminate\Validation\Rules\In;
|
||||||
|
use Korridor\LaravelModelValidationRules\Rules\ExistsEloquent;
|
||||||
|
use Laravel\Jetstream\Contracts\AddsTeamMembers;
|
||||||
|
|
||||||
|
class AddOrganizationMember implements AddsTeamMembers
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* Add a new team member to the given team.
|
||||||
|
*/
|
||||||
|
public function add(User $owner, Organization $organization, string $email, ?string $role = null): void
|
||||||
|
{
|
||||||
|
Gate::forUser($owner)->authorize('addTeamMember', $organization); // TODO: refactor after owner refactoring
|
||||||
|
|
||||||
|
$this->validate($organization, $email, $role);
|
||||||
|
|
||||||
|
$newOrganizationMember = User::query()
|
||||||
|
->where('email', $email)
|
||||||
|
->where('is_placeholder', '=', false)
|
||||||
|
->firstOrFail();
|
||||||
|
|
||||||
|
app(MemberService::class)->addMember($newOrganizationMember, $organization, Role::from($role));
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Validate the add member operation.
|
||||||
|
*/
|
||||||
|
protected function validate(Organization $organization, string $email, ?string $role): void
|
||||||
|
{
|
||||||
|
Validator::make([
|
||||||
|
'email' => $email,
|
||||||
|
'role' => $role,
|
||||||
|
], $this->rules())->after(
|
||||||
|
$this->ensureUserIsNotAlreadyOnTeam($organization, $email)
|
||||||
|
)->validateWithBag('addTeamMember');
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Get the validation rules for adding a team member.
|
||||||
|
*
|
||||||
|
* @return array<string, array<ValidationRule|Rule|string|In>>
|
||||||
|
*/
|
||||||
|
protected function rules(): array
|
||||||
|
{
|
||||||
|
return [
|
||||||
|
'email' => [
|
||||||
|
'required',
|
||||||
|
'email',
|
||||||
|
ExistsEloquent::make(User::class, 'email', function (Builder $builder) {
|
||||||
|
/** @var Builder<User> $builder */
|
||||||
|
return $builder->where('is_placeholder', '=', false);
|
||||||
|
})->withMessage(__('We were unable to find a registered user with this email address.')),
|
||||||
|
],
|
||||||
|
'role' => [
|
||||||
|
'required',
|
||||||
|
'string',
|
||||||
|
Rule::in([
|
||||||
|
Role::Admin->value,
|
||||||
|
Role::Manager->value,
|
||||||
|
Role::Employee->value,
|
||||||
|
]),
|
||||||
|
],
|
||||||
|
];
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Ensure that the user is not already on the team.
|
||||||
|
*/
|
||||||
|
protected function ensureUserIsNotAlreadyOnTeam(Organization $team, string $email): Closure
|
||||||
|
{
|
||||||
|
return function ($validator) use ($team, $email): void {
|
||||||
|
$validator->errors()->addIf(
|
||||||
|
$team->hasRealUserWithEmail($email),
|
||||||
|
'email',
|
||||||
|
__('This user already belongs to the team.')
|
||||||
|
);
|
||||||
|
};
|
||||||
|
}
|
||||||
|
}
|
||||||
59
app/Actions/Jetstream/CreateOrganization.php
Normal file
59
app/Actions/Jetstream/CreateOrganization.php
Normal file
@@ -0,0 +1,59 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Actions\Jetstream;
|
||||||
|
|
||||||
|
use App\Events\AfterCreateOrganization;
|
||||||
|
use App\Models\Organization;
|
||||||
|
use App\Models\User;
|
||||||
|
use App\Service\IpLookup\IpLookupServiceContract;
|
||||||
|
use App\Service\OrganizationService;
|
||||||
|
use Illuminate\Auth\Access\AuthorizationException;
|
||||||
|
use Illuminate\Support\Facades\Gate;
|
||||||
|
use Illuminate\Support\Facades\Validator;
|
||||||
|
use Illuminate\Validation\ValidationException;
|
||||||
|
use Laravel\Jetstream\Contracts\CreatesTeams;
|
||||||
|
use Laravel\Jetstream\Jetstream;
|
||||||
|
|
||||||
|
class CreateOrganization implements CreatesTeams
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* Validate and create a new team for the given user.
|
||||||
|
*
|
||||||
|
* @param array<string, string> $input
|
||||||
|
*
|
||||||
|
* @throws AuthorizationException
|
||||||
|
* @throws ValidationException
|
||||||
|
*/
|
||||||
|
public function create(User $user, array $input): Organization
|
||||||
|
{
|
||||||
|
Gate::forUser($user)->authorize('create', Jetstream::newTeamModel());
|
||||||
|
|
||||||
|
Validator::make($input, [
|
||||||
|
'name' => ['required', 'string', 'max:255'],
|
||||||
|
])->validateWithBag('createTeam');
|
||||||
|
|
||||||
|
$ipLookupResponse = app(IpLookupServiceContract::class)->lookup(request()->ip());
|
||||||
|
|
||||||
|
$currency = null;
|
||||||
|
if ($ipLookupResponse !== null) {
|
||||||
|
$currency = $ipLookupResponse->currency;
|
||||||
|
}
|
||||||
|
|
||||||
|
$organization = app(OrganizationService::class)->createOrganization(
|
||||||
|
$input['name'],
|
||||||
|
$user,
|
||||||
|
false,
|
||||||
|
$currency
|
||||||
|
);
|
||||||
|
|
||||||
|
$user->switchTeam($organization);
|
||||||
|
|
||||||
|
// Note: The refresh is necessary for currently unknown reasons. Do not remove it.
|
||||||
|
$organization = $organization->refresh();
|
||||||
|
AfterCreateOrganization::dispatch($organization);
|
||||||
|
|
||||||
|
return $organization;
|
||||||
|
}
|
||||||
|
}
|
||||||
21
app/Actions/Jetstream/DeleteOrganization.php
Normal file
21
app/Actions/Jetstream/DeleteOrganization.php
Normal file
@@ -0,0 +1,21 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Actions\Jetstream;
|
||||||
|
|
||||||
|
use App\Models\Organization;
|
||||||
|
use App\Service\DeletionService;
|
||||||
|
use Laravel\Jetstream\Contracts\DeletesTeams;
|
||||||
|
|
||||||
|
class DeleteOrganization implements DeletesTeams
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* Delete the given team.
|
||||||
|
*/
|
||||||
|
public function delete(Organization $organization): void
|
||||||
|
{
|
||||||
|
/** @see ValidateOrganizationDeletion */
|
||||||
|
app(DeletionService::class)->deleteOrganization($organization);
|
||||||
|
}
|
||||||
|
}
|
||||||
30
app/Actions/Jetstream/DeleteUser.php
Normal file
30
app/Actions/Jetstream/DeleteUser.php
Normal file
@@ -0,0 +1,30 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Actions\Jetstream;
|
||||||
|
|
||||||
|
use App\Exceptions\Api\ApiException;
|
||||||
|
use App\Models\User;
|
||||||
|
use App\Service\DeletionService;
|
||||||
|
use Illuminate\Validation\ValidationException;
|
||||||
|
use Laravel\Jetstream\Contracts\DeletesUsers;
|
||||||
|
|
||||||
|
class DeleteUser implements DeletesUsers
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* Delete the given user.
|
||||||
|
*
|
||||||
|
* @throws ValidationException
|
||||||
|
*/
|
||||||
|
public function delete(User $user): void
|
||||||
|
{
|
||||||
|
try {
|
||||||
|
app(DeletionService::class)->deleteUser($user);
|
||||||
|
} catch (ApiException $exception) {
|
||||||
|
throw ValidationException::withMessages([
|
||||||
|
'password' => $exception->getTranslatedMessage(),
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
24
app/Actions/Jetstream/InviteOrganizationMember.php
Normal file
24
app/Actions/Jetstream/InviteOrganizationMember.php
Normal file
@@ -0,0 +1,24 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Actions\Jetstream;
|
||||||
|
|
||||||
|
use App\Exceptions\MovedToApiException;
|
||||||
|
use App\Models\Organization;
|
||||||
|
use App\Models\User;
|
||||||
|
use Exception;
|
||||||
|
use Laravel\Jetstream\Contracts\InvitesTeamMembers;
|
||||||
|
|
||||||
|
class InviteOrganizationMember implements InvitesTeamMembers
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* Invite a new team member to the given team.
|
||||||
|
*
|
||||||
|
* @throws Exception
|
||||||
|
*/
|
||||||
|
public function invite(User $user, Organization $organization, string $email, ?string $role = null): void
|
||||||
|
{
|
||||||
|
throw new MovedToApiException;
|
||||||
|
}
|
||||||
|
}
|
||||||
24
app/Actions/Jetstream/RemoveOrganizationMember.php
Normal file
24
app/Actions/Jetstream/RemoveOrganizationMember.php
Normal file
@@ -0,0 +1,24 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Actions\Jetstream;
|
||||||
|
|
||||||
|
use App\Exceptions\MovedToApiException;
|
||||||
|
use App\Models\Organization;
|
||||||
|
use App\Models\User;
|
||||||
|
use Exception;
|
||||||
|
use Laravel\Jetstream\Contracts\RemovesTeamMembers;
|
||||||
|
|
||||||
|
class RemoveOrganizationMember implements RemovesTeamMembers
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* Remove the team member from the given team.
|
||||||
|
*
|
||||||
|
* @throws Exception
|
||||||
|
*/
|
||||||
|
public function remove(User $user, Organization $organization, User $teamMember): void
|
||||||
|
{
|
||||||
|
throw new MovedToApiException;
|
||||||
|
}
|
||||||
|
}
|
||||||
25
app/Actions/Jetstream/UpdateMemberRole.php
Normal file
25
app/Actions/Jetstream/UpdateMemberRole.php
Normal file
@@ -0,0 +1,25 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Actions\Jetstream;
|
||||||
|
|
||||||
|
use App\Enums\Role;
|
||||||
|
use App\Exceptions\MovedToApiException;
|
||||||
|
use App\Models\Member;
|
||||||
|
use App\Models\Organization;
|
||||||
|
use App\Models\User;
|
||||||
|
use Exception;
|
||||||
|
|
||||||
|
class UpdateMemberRole
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* Update the role for the given team member.
|
||||||
|
*
|
||||||
|
* @throws Exception
|
||||||
|
*/
|
||||||
|
public function update(User $actingUser, Organization $organization, string $userId, string $role): void
|
||||||
|
{
|
||||||
|
throw new MovedToApiException;
|
||||||
|
}
|
||||||
|
}
|
||||||
48
app/Actions/Jetstream/UpdateOrganization.php
Normal file
48
app/Actions/Jetstream/UpdateOrganization.php
Normal file
@@ -0,0 +1,48 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Actions\Jetstream;
|
||||||
|
|
||||||
|
use App\Models\Organization;
|
||||||
|
use App\Models\User;
|
||||||
|
use App\Rules\CurrencyRule;
|
||||||
|
use Illuminate\Auth\Access\AuthorizationException;
|
||||||
|
use Illuminate\Support\Facades\Gate;
|
||||||
|
use Illuminate\Support\Facades\Validator;
|
||||||
|
use Illuminate\Validation\ValidationException;
|
||||||
|
use Laravel\Jetstream\Contracts\UpdatesTeamNames;
|
||||||
|
|
||||||
|
class UpdateOrganization implements UpdatesTeamNames
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* Validate and update the given team's name.
|
||||||
|
*
|
||||||
|
* @param array<string, string> $input
|
||||||
|
*
|
||||||
|
* @throws AuthorizationException
|
||||||
|
* @throws ValidationException
|
||||||
|
*/
|
||||||
|
public function update(User $user, Organization $organization, array $input): void
|
||||||
|
{
|
||||||
|
Gate::forUser($user)->authorize('update', $organization);
|
||||||
|
|
||||||
|
Validator::make($input, [
|
||||||
|
'name' => [
|
||||||
|
'required',
|
||||||
|
'string',
|
||||||
|
'max:255',
|
||||||
|
],
|
||||||
|
'currency' => [
|
||||||
|
'required',
|
||||||
|
'string',
|
||||||
|
new CurrencyRule,
|
||||||
|
],
|
||||||
|
])->validateWithBag('updateTeamName');
|
||||||
|
|
||||||
|
$organization->forceFill([
|
||||||
|
'name' => $input['name'],
|
||||||
|
'currency' => $input['currency'],
|
||||||
|
])->save();
|
||||||
|
}
|
||||||
|
}
|
||||||
28
app/Actions/Jetstream/ValidateOrganizationDeletion.php
Normal file
28
app/Actions/Jetstream/ValidateOrganizationDeletion.php
Normal file
@@ -0,0 +1,28 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Actions\Jetstream;
|
||||||
|
|
||||||
|
use App\Models\Organization;
|
||||||
|
use App\Models\User;
|
||||||
|
use App\Service\PermissionStore;
|
||||||
|
use Illuminate\Auth\Access\AuthorizationException;
|
||||||
|
|
||||||
|
class ValidateOrganizationDeletion
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* Validate that the team can be deleted by the given user.
|
||||||
|
*
|
||||||
|
* @param User $user Authenticated user
|
||||||
|
* @param Organization $organization Organization to be deleted
|
||||||
|
*
|
||||||
|
* @throws AuthorizationException
|
||||||
|
*/
|
||||||
|
public function validate(User $user, Organization $organization): void
|
||||||
|
{
|
||||||
|
if (! app(PermissionStore::class)->userHas($organization, $user, 'organizations:delete')) {
|
||||||
|
throw new AuthorizationException;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -69,7 +69,7 @@ class UserCreateCommand extends Command
|
|||||||
);
|
);
|
||||||
});
|
});
|
||||||
/** @var Organization|null $organization */
|
/** @var Organization|null $organization */
|
||||||
$organization = $user->ownedOrganizations->first();
|
$organization = $user->ownedTeams->first();
|
||||||
if ($organization === null) {
|
if ($organization === null) {
|
||||||
throw new LogicException('User does not have an organization');
|
throw new LogicException('User does not have an organization');
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -4,12 +4,8 @@ declare(strict_types=1);
|
|||||||
|
|
||||||
namespace App\Enums;
|
namespace App\Enums;
|
||||||
|
|
||||||
use Datomatic\LaravelEnumHelper\LaravelEnumHelper;
|
|
||||||
|
|
||||||
enum Role: string
|
enum Role: string
|
||||||
{
|
{
|
||||||
use LaravelEnumHelper;
|
|
||||||
|
|
||||||
case Owner = 'owner';
|
case Owner = 'owner';
|
||||||
case Admin = 'admin';
|
case Admin = 'admin';
|
||||||
case Manager = 'manager';
|
case Manager = 'manager';
|
||||||
|
|||||||
@@ -1,31 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace App\Events;
|
|
||||||
|
|
||||||
use App\Models\Member;
|
|
||||||
use App\Models\Organization;
|
|
||||||
use App\Models\User;
|
|
||||||
use Illuminate\Foundation\Events\Dispatchable;
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Replaces legacy TeamMemberAdded event.
|
|
||||||
*/
|
|
||||||
class MemberAdded
|
|
||||||
{
|
|
||||||
use Dispatchable;
|
|
||||||
|
|
||||||
public Member $member;
|
|
||||||
|
|
||||||
public Organization $organization;
|
|
||||||
|
|
||||||
public User $user;
|
|
||||||
|
|
||||||
public function __construct(Member $member, Organization $organization, User $user)
|
|
||||||
{
|
|
||||||
$this->member = $member;
|
|
||||||
$this->organization = $organization;
|
|
||||||
$this->user = $user;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,31 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace App\Events;
|
|
||||||
|
|
||||||
use App\Enums\Role;
|
|
||||||
use App\Models\Organization;
|
|
||||||
use App\Models\User;
|
|
||||||
use Illuminate\Foundation\Events\Dispatchable;
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Replaces legacy AddingTeamMember event.
|
|
||||||
*/
|
|
||||||
class MemberAdding
|
|
||||||
{
|
|
||||||
use Dispatchable;
|
|
||||||
|
|
||||||
public User $user;
|
|
||||||
|
|
||||||
public Organization $organization;
|
|
||||||
|
|
||||||
public Role $role;
|
|
||||||
|
|
||||||
public function __construct(User $user, Organization $organization, Role $role)
|
|
||||||
{
|
|
||||||
$this->user = $user;
|
|
||||||
$this->organization = $organization;
|
|
||||||
$this->role = $role;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,38 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace App\Events;
|
|
||||||
|
|
||||||
use App\Enums\Role;
|
|
||||||
use App\Models\Organization;
|
|
||||||
use App\Models\User;
|
|
||||||
use Illuminate\Foundation\Events\Dispatchable;
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Replaces legacy InvitingTeamMember event.
|
|
||||||
*/
|
|
||||||
class OrganizationInvitationAdding
|
|
||||||
{
|
|
||||||
use Dispatchable;
|
|
||||||
|
|
||||||
public Organization $organization;
|
|
||||||
|
|
||||||
public string $email;
|
|
||||||
|
|
||||||
public Role $role;
|
|
||||||
|
|
||||||
public User $inviter;
|
|
||||||
|
|
||||||
public function __construct(
|
|
||||||
Organization $organization,
|
|
||||||
string $email,
|
|
||||||
Role $role,
|
|
||||||
User $inviter
|
|
||||||
) {
|
|
||||||
$this->role = $role;
|
|
||||||
$this->email = $email;
|
|
||||||
$this->organization = $organization;
|
|
||||||
$this->inviter = $inviter;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace App\Exceptions\Api;
|
|
||||||
|
|
||||||
class UserResendEmailVerificationNoPendingEmailApiException extends ApiException
|
|
||||||
{
|
|
||||||
public const string KEY = 'user_resend_email_verification_no_pending_email';
|
|
||||||
}
|
|
||||||
@@ -50,7 +50,7 @@ class FailedJobResource extends Resource
|
|||||||
TextInput::make('queue')->disabled(),
|
TextInput::make('queue')->disabled(),
|
||||||
|
|
||||||
// make text a little bit smaller because often a complete Stack Trace is shown:
|
// make text a little bit smaller because often a complete Stack Trace is shown:
|
||||||
Textarea::make('exception')->disabled()->columnSpan(4)->extraInputAttributes(['style' => 'font-size: 80%;']),
|
TextArea::make('exception')->disabled()->columnSpan(4)->extraInputAttributes(['style' => 'font-size: 80%;']),
|
||||||
PrettyJsonField::make('payload')->disabled()->columnSpan(4),
|
PrettyJsonField::make('payload')->disabled()->columnSpan(4),
|
||||||
])->columns(4);
|
])->columns(4);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -39,7 +39,7 @@ class OrganizationInvitationResource extends Resource
|
|||||||
->required(),
|
->required(),
|
||||||
Select::make('role')
|
Select::make('role')
|
||||||
->options(Role::class),
|
->options(Role::class),
|
||||||
Select::make('organization_id')
|
Forms\Components\Select::make('organization_id')
|
||||||
->label('Organization')
|
->label('Organization')
|
||||||
->relationship(name: 'organization', titleAttribute: 'name')
|
->relationship(name: 'organization', titleAttribute: 'name')
|
||||||
->searchable(['name'])
|
->searchable(['name'])
|
||||||
|
|||||||
@@ -55,7 +55,7 @@ class OrganizationResource extends Resource
|
|||||||
->label('Is personal?')
|
->label('Is personal?')
|
||||||
->hiddenOn(['create'])
|
->hiddenOn(['create'])
|
||||||
->required(),
|
->required(),
|
||||||
Select::make('user_id')
|
Forms\Components\Select::make('user_id')
|
||||||
->label('Owner')
|
->label('Owner')
|
||||||
->relationship(name: 'owner', titleAttribute: 'email')
|
->relationship(name: 'owner', titleAttribute: 'email')
|
||||||
->searchable(['name', 'email'])
|
->searchable(['name', 'email'])
|
||||||
@@ -76,7 +76,7 @@ class OrganizationResource extends Resource
|
|||||||
Select::make('time_format')
|
Select::make('time_format')
|
||||||
->options(TimeFormat::toSelectArray())
|
->options(TimeFormat::toSelectArray())
|
||||||
->required(),
|
->required(),
|
||||||
Select::make('currency')
|
Forms\Components\Select::make('currency')
|
||||||
->label('Currency')
|
->label('Currency')
|
||||||
->options(function (): array {
|
->options(function (): array {
|
||||||
$currencies = ISOCurrencyProvider::getInstance()->getAvailableCurrencies();
|
$currencies = ISOCurrencyProvider::getInstance()->getAvailableCurrencies();
|
||||||
@@ -114,22 +114,22 @@ class OrganizationResource extends Resource
|
|||||||
{
|
{
|
||||||
return $table
|
return $table
|
||||||
->columns([
|
->columns([
|
||||||
TextColumn::make('name')
|
Tables\Columns\TextColumn::make('name')
|
||||||
->searchable()
|
->searchable()
|
||||||
->sortable(),
|
->sortable(),
|
||||||
Tables\Columns\IconColumn::make('personal_team')
|
Tables\Columns\IconColumn::make('personal_team')
|
||||||
->boolean()
|
->boolean()
|
||||||
->label('Is personal?')
|
->label('Is personal?')
|
||||||
->sortable(),
|
->sortable(),
|
||||||
TextColumn::make('owner.email')
|
Tables\Columns\TextColumn::make('owner.email')
|
||||||
->sortable(),
|
->sortable(),
|
||||||
TextColumn::make('currency'),
|
Tables\Columns\TextColumn::make('currency'),
|
||||||
TextColumn::make('billable_rate')
|
TextColumn::make('billable_rate')
|
||||||
->money(fn (Organization $resource) => $resource->currency, divideBy: 100),
|
->money(fn (Organization $resource) => $resource->currency, divideBy: 100),
|
||||||
TextColumn::make('created_at')
|
Tables\Columns\TextColumn::make('created_at')
|
||||||
->dateTime()
|
->dateTime()
|
||||||
->sortable(),
|
->sortable(),
|
||||||
TextColumn::make('updated_at')
|
Tables\Columns\TextColumn::make('updated_at')
|
||||||
->dateTime()
|
->dateTime()
|
||||||
->sortable()
|
->sortable()
|
||||||
->toggleable(isToggledHiddenByDefault: true),
|
->toggleable(isToggledHiddenByDefault: true),
|
||||||
@@ -223,7 +223,7 @@ class OrganizationResource extends Resource
|
|||||||
|
|
||||||
return $select;
|
return $select;
|
||||||
}),
|
}),
|
||||||
Select::make('timezone')
|
Forms\Components\Select::make('timezone')
|
||||||
->label('Timezone')
|
->label('Timezone')
|
||||||
->options(fn (): array => app(TimezoneService::class)->getSelectOptions())
|
->options(fn (): array => app(TimezoneService::class)->getSelectOptions())
|
||||||
->searchable()
|
->searchable()
|
||||||
|
|||||||
@@ -21,7 +21,7 @@ use Illuminate\Validation\Rule;
|
|||||||
|
|
||||||
class InvitationsRelationManager extends RelationManager
|
class InvitationsRelationManager extends RelationManager
|
||||||
{
|
{
|
||||||
protected static string $relationship = 'organizationInvitations';
|
protected static string $relationship = 'teamInvitations';
|
||||||
|
|
||||||
protected static ?string $title = 'Invitations';
|
protected static ?string $title = 'Invitations';
|
||||||
|
|
||||||
@@ -64,7 +64,7 @@ class InvitationsRelationManager extends RelationManager
|
|||||||
$ownerRecord = $this->getOwnerRecord();
|
$ownerRecord = $this->getOwnerRecord();
|
||||||
|
|
||||||
return app(InvitationService::class)
|
return app(InvitationService::class)
|
||||||
->inviteUser($ownerRecord, $data['email'], Role::from($data['role']), auth()->user());
|
->inviteUser($ownerRecord, $data['email'], Role::from($data['role']));
|
||||||
}),
|
}),
|
||||||
])
|
])
|
||||||
->actions([
|
->actions([
|
||||||
|
|||||||
@@ -49,13 +49,13 @@ class UsersRelationManager extends RelationManager
|
|||||||
return $table
|
return $table
|
||||||
->recordTitleAttribute('name')
|
->recordTitleAttribute('name')
|
||||||
->columns([
|
->columns([
|
||||||
TextColumn::make('name'),
|
Tables\Columns\TextColumn::make('name'),
|
||||||
TextColumn::make('role'),
|
Tables\Columns\TextColumn::make('role'),
|
||||||
TextColumn::make('billable_rate')
|
TextColumn::make('billable_rate')
|
||||||
->money($organization->currency, divideBy: 100),
|
->money($organization->currency, divideBy: 100),
|
||||||
])
|
])
|
||||||
->headerActions([
|
->headerActions([
|
||||||
AttachAction::make()
|
Tables\Actions\AttachAction::make()
|
||||||
->recordTitle(fn (User $record): string => "{$record->name} ({$record->email})")
|
->recordTitle(fn (User $record): string => "{$record->name} ({$record->email})")
|
||||||
->form(fn (AttachAction $action): array => [
|
->form(fn (AttachAction $action): array => [
|
||||||
$action->getRecordSelect(),
|
$action->getRecordSelect(),
|
||||||
|
|||||||
@@ -63,11 +63,11 @@ class ReportResource extends Resource
|
|||||||
return $record->getRawOriginal('properties');
|
return $record->getRawOriginal('properties');
|
||||||
})
|
})
|
||||||
->disabled(),
|
->disabled(),
|
||||||
DateTimePicker::make('created_at')
|
Forms\Components\DateTimePicker::make('created_at')
|
||||||
->label('Created At')
|
->label('Created At')
|
||||||
->hiddenOn(['create'])
|
->hiddenOn(['create'])
|
||||||
->disabled(),
|
->disabled(),
|
||||||
DateTimePicker::make('updated_at')
|
Forms\Components\DateTimePicker::make('updated_at')
|
||||||
->label('Updated At')
|
->label('Updated At')
|
||||||
->hiddenOn(['create'])
|
->hiddenOn(['create'])
|
||||||
->disabled(),
|
->disabled(),
|
||||||
@@ -78,10 +78,10 @@ class ReportResource extends Resource
|
|||||||
{
|
{
|
||||||
return $table
|
return $table
|
||||||
->columns([
|
->columns([
|
||||||
TextColumn::make('name')
|
Tables\Columns\TextColumn::make('name')
|
||||||
->searchable()
|
->searchable()
|
||||||
->sortable(),
|
->sortable(),
|
||||||
TextColumn::make('description')
|
Tables\Columns\TextColumn::make('description')
|
||||||
->searchable()
|
->searchable()
|
||||||
->sortable(),
|
->sortable(),
|
||||||
ToggleColumn::make('is_public')
|
ToggleColumn::make('is_public')
|
||||||
@@ -90,10 +90,10 @@ class ReportResource extends Resource
|
|||||||
TextColumn::make('organization.name')
|
TextColumn::make('organization.name')
|
||||||
->searchable()
|
->searchable()
|
||||||
->sortable(),
|
->sortable(),
|
||||||
TextColumn::make('created_at')
|
Tables\Columns\TextColumn::make('created_at')
|
||||||
->dateTime()
|
->dateTime()
|
||||||
->sortable(),
|
->sortable(),
|
||||||
TextColumn::make('updated_at')
|
Tables\Columns\TextColumn::make('updated_at')
|
||||||
->dateTime()
|
->dateTime()
|
||||||
->sortable()
|
->sortable()
|
||||||
->toggleable(isToggledHiddenByDefault: true),
|
->toggleable(isToggledHiddenByDefault: true),
|
||||||
|
|||||||
@@ -93,11 +93,11 @@ class TimeEntryResource extends Resource
|
|||||||
($record->end?->toDateTimeString('minute') ?? '...').')';
|
($record->end?->toDateTimeString('minute') ?? '...').')';
|
||||||
})
|
})
|
||||||
->label('Time'),
|
->label('Time'),
|
||||||
TextColumn::make('organization.name')
|
Tables\Columns\TextColumn::make('organization.name')
|
||||||
->sortable(),
|
->sortable(),
|
||||||
TextColumn::make('created_at')
|
Tables\Columns\TextColumn::make('created_at')
|
||||||
->sortable(),
|
->sortable(),
|
||||||
TextColumn::make('updated_at')
|
Tables\Columns\TextColumn::make('updated_at')
|
||||||
->sortable(),
|
->sortable(),
|
||||||
])
|
])
|
||||||
->filters([
|
->filters([
|
||||||
|
|||||||
@@ -12,7 +12,6 @@ use App\Filament\Resources\UserResource\RelationManagers\OwnedOrganizationsRelat
|
|||||||
use App\Models\User;
|
use App\Models\User;
|
||||||
use App\Service\DeletionService;
|
use App\Service\DeletionService;
|
||||||
use App\Service\TimezoneService;
|
use App\Service\TimezoneService;
|
||||||
use App\Service\UserService;
|
|
||||||
use Brick\Money\ISOCurrencyProvider;
|
use Brick\Money\ISOCurrencyProvider;
|
||||||
use Exception;
|
use Exception;
|
||||||
use Filament\Forms;
|
use Filament\Forms;
|
||||||
@@ -48,17 +47,17 @@ class UserResource extends Resource
|
|||||||
return $form
|
return $form
|
||||||
->columns(1)
|
->columns(1)
|
||||||
->schema([
|
->schema([
|
||||||
TextInput::make('id')
|
Forms\Components\TextInput::make('id')
|
||||||
->label('ID')
|
->label('ID')
|
||||||
->disabled()
|
->disabled()
|
||||||
->visibleOn(['update', 'show'])
|
->visibleOn(['update', 'show'])
|
||||||
->readOnly()
|
->readOnly()
|
||||||
->maxLength(255),
|
->maxLength(255),
|
||||||
TextInput::make('name')
|
Forms\Components\TextInput::make('name')
|
||||||
->label('Name')
|
->label('Name')
|
||||||
->required()
|
->required()
|
||||||
->maxLength(255),
|
->maxLength(255),
|
||||||
TextInput::make('email')
|
Forms\Components\TextInput::make('email')
|
||||||
->label('Email')
|
->label('Email')
|
||||||
->required()
|
->required()
|
||||||
->rules($record?->is_placeholder ? [] : [
|
->rules($record?->is_placeholder ? [] : [
|
||||||
@@ -180,7 +179,7 @@ class UserResource extends Resource
|
|||||||
])
|
])
|
||||||
->actions([
|
->actions([
|
||||||
Impersonate::make()->before(function (User $record): void {
|
Impersonate::make()->before(function (User $record): void {
|
||||||
if ($record->currentOrganization === null) {
|
if ($record->currentTeam === null) {
|
||||||
$organization = $record->organizations()->where('personal_team', '=', true)->first();
|
$organization = $record->organizations()->where('personal_team', '=', true)->first();
|
||||||
if ($organization === null) {
|
if ($organization === null) {
|
||||||
$organization = $record->organizations()->first();
|
$organization = $record->organizations()->first();
|
||||||
@@ -188,7 +187,8 @@ class UserResource extends Resource
|
|||||||
if ($organization === null) {
|
if ($organization === null) {
|
||||||
throw new Exception('User has no organization');
|
throw new Exception('User has no organization');
|
||||||
}
|
}
|
||||||
app(UserService::class)->switchCurrentOrganization($record, $organization);
|
$record->currentTeam()->associate($organization);
|
||||||
|
$record->save();
|
||||||
}
|
}
|
||||||
}),
|
}),
|
||||||
Tables\Actions\EditAction::make(),
|
Tables\Actions\EditAction::make(),
|
||||||
|
|||||||
@@ -16,7 +16,7 @@ class OwnedOrganizationsRelationManager extends RelationManager
|
|||||||
{
|
{
|
||||||
protected static ?string $title = 'Owned Organizations';
|
protected static ?string $title = 'Owned Organizations';
|
||||||
|
|
||||||
protected static string $relationship = 'ownedOrganizations';
|
protected static string $relationship = 'ownedTeams';
|
||||||
|
|
||||||
public function form(Form $form): Form
|
public function form(Form $form): Form
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -20,7 +20,7 @@ class ApiTokenController extends Controller
|
|||||||
/**
|
/**
|
||||||
* List all api token of the currently authenticated user
|
* List all api token of the currently authenticated user
|
||||||
*
|
*
|
||||||
* This endpoint is independent of the organization.
|
* This endpoint is independent of organization.
|
||||||
*
|
*
|
||||||
* @operationId getApiTokens
|
* @operationId getApiTokens
|
||||||
*
|
*
|
||||||
|
|||||||
@@ -40,7 +40,7 @@ class InvitationController extends Controller
|
|||||||
{
|
{
|
||||||
$this->checkPermission($organization, 'invitations:view');
|
$this->checkPermission($organization, 'invitations:view');
|
||||||
|
|
||||||
$invitations = $organization->organizationInvitations()
|
$invitations = $organization->teamInvitations()
|
||||||
->orderBy('created_at', 'desc')
|
->orderBy('created_at', 'desc')
|
||||||
->paginate(config('app.pagination_per_page_default'));
|
->paginate(config('app.pagination_per_page_default'));
|
||||||
|
|
||||||
@@ -63,7 +63,7 @@ class InvitationController extends Controller
|
|||||||
$email = $request->getEmail();
|
$email = $request->getEmail();
|
||||||
$role = $request->getRole();
|
$role = $request->getRole();
|
||||||
|
|
||||||
$invitationService->inviteUser($organization, $email, $role, $this->user());
|
$invitationService->inviteUser($organization, $email, $role);
|
||||||
|
|
||||||
return response()->json(null, 204);
|
return response()->json(null, 204);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -192,7 +192,7 @@ class MemberController extends Controller
|
|||||||
throw new ThisPlaceholderCanNotBeInvitedUseTheMergeToolInsteadException;
|
throw new ThisPlaceholderCanNotBeInvitedUseTheMergeToolInsteadException;
|
||||||
}
|
}
|
||||||
|
|
||||||
$invitationService->inviteUser($organization, $user->email, Role::Employee, $this->user());
|
$invitationService->inviteUser($organization, $user->email, Role::Employee);
|
||||||
|
|
||||||
return response()->json(null, 204);
|
return response()->json(null, 204);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -5,19 +5,11 @@ declare(strict_types=1);
|
|||||||
namespace App\Http\Controllers\Api\V1;
|
namespace App\Http\Controllers\Api\V1;
|
||||||
|
|
||||||
use App\Enums\Role;
|
use App\Enums\Role;
|
||||||
use App\Events\AfterCreateOrganization;
|
|
||||||
use App\Http\Requests\V1\Organization\OrganizationDestroyRequest;
|
|
||||||
use App\Http\Requests\V1\Organization\OrganizationStoreRequest;
|
|
||||||
use App\Http\Requests\V1\Organization\OrganizationUpdateRequest;
|
use App\Http\Requests\V1\Organization\OrganizationUpdateRequest;
|
||||||
use App\Http\Resources\V1\Organization\OrganizationResource;
|
use App\Http\Resources\V1\Organization\OrganizationResource;
|
||||||
use App\Models\Organization;
|
use App\Models\Organization;
|
||||||
use App\Service\BillableRateService;
|
use App\Service\BillableRateService;
|
||||||
use App\Service\DeletionService;
|
|
||||||
use App\Service\IpLookup\IpLookupServiceContract;
|
|
||||||
use App\Service\OrganizationService;
|
|
||||||
use App\Service\UserService;
|
|
||||||
use Illuminate\Auth\Access\AuthorizationException;
|
use Illuminate\Auth\Access\AuthorizationException;
|
||||||
use Illuminate\Http\JsonResponse;
|
|
||||||
|
|
||||||
class OrganizationController extends Controller
|
class OrganizationController extends Controller
|
||||||
{
|
{
|
||||||
@@ -51,9 +43,6 @@ class OrganizationController extends Controller
|
|||||||
if ($request->getName() !== null) {
|
if ($request->getName() !== null) {
|
||||||
$organization->name = $request->getName();
|
$organization->name = $request->getName();
|
||||||
}
|
}
|
||||||
if ($request->getCurrency() !== null) {
|
|
||||||
$organization->currency = $request->getCurrency();
|
|
||||||
}
|
|
||||||
if ($request->getEmployeesCanSeeBillableRates() !== null) {
|
if ($request->getEmployeesCanSeeBillableRates() !== null) {
|
||||||
$organization->employees_can_see_billable_rates = $request->getEmployeesCanSeeBillableRates();
|
$organization->employees_can_see_billable_rates = $request->getEmployeesCanSeeBillableRates();
|
||||||
}
|
}
|
||||||
@@ -91,46 +80,4 @@ class OrganizationController extends Controller
|
|||||||
|
|
||||||
return new OrganizationResource($organization, true);
|
return new OrganizationResource($organization, true);
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
|
||||||
* Create organization
|
|
||||||
*
|
|
||||||
* @operationId createOrganization
|
|
||||||
*/
|
|
||||||
public function store(OrganizationStoreRequest $request, OrganizationService $organizationService): OrganizationResource
|
|
||||||
{
|
|
||||||
$user = $this->user();
|
|
||||||
$ipLookupResponse = app(IpLookupServiceContract::class)->lookup($request->ip());
|
|
||||||
|
|
||||||
$currency = $ipLookupResponse?->currency;
|
|
||||||
|
|
||||||
$organization = $organizationService->createOrganization(
|
|
||||||
$request->getName(),
|
|
||||||
$user,
|
|
||||||
false,
|
|
||||||
$currency
|
|
||||||
);
|
|
||||||
|
|
||||||
app(UserService::class)->switchCurrentOrganization($user, $organization);
|
|
||||||
|
|
||||||
AfterCreateOrganization::dispatch($organization);
|
|
||||||
|
|
||||||
return new OrganizationResource($organization, true);
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Delete organization
|
|
||||||
*
|
|
||||||
* @operationId deleteOrganization
|
|
||||||
*
|
|
||||||
* @throws AuthorizationException
|
|
||||||
*/
|
|
||||||
public function destroy(Organization $organization, OrganizationDestroyRequest $request, DeletionService $deletionService): JsonResponse
|
|
||||||
{
|
|
||||||
$this->checkPermission($organization, 'organizations:delete');
|
|
||||||
|
|
||||||
$deletionService->deleteOrganization($organization);
|
|
||||||
|
|
||||||
return response()->json(null, 204);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -78,7 +78,7 @@ class ProjectController extends Controller
|
|||||||
*/
|
*/
|
||||||
public function show(Organization $organization, Project $project): JsonResource
|
public function show(Organization $organization, Project $project): JsonResource
|
||||||
{
|
{
|
||||||
$this->checkPermission($organization, 'projects:view:all', $project);
|
$this->checkPermission($organization, 'projects:view', $project);
|
||||||
|
|
||||||
// Note: There is currently no need to check if a user is a member of the project,
|
// Note: There is currently no need to check if a user is a member of the project,
|
||||||
// since this is only relevant for users with the role "employee" and they can not access this endpoint.
|
// since this is only relevant for users with the role "employee" and they can not access this endpoint.
|
||||||
|
|||||||
@@ -53,13 +53,12 @@ use Illuminate\Support\Facades\Blade;
|
|||||||
use Illuminate\Support\Facades\DB;
|
use Illuminate\Support\Facades\DB;
|
||||||
use Illuminate\Support\Facades\Log;
|
use Illuminate\Support\Facades\Log;
|
||||||
use Illuminate\Support\Facades\Storage;
|
use Illuminate\Support\Facades\Storage;
|
||||||
use Illuminate\Support\Str;
|
|
||||||
use Maatwebsite\Excel\Facades\Excel;
|
use Maatwebsite\Excel\Facades\Excel;
|
||||||
use Spatie\TemporaryDirectory\TemporaryDirectory;
|
use Spatie\TemporaryDirectory\TemporaryDirectory;
|
||||||
|
|
||||||
class TimeEntryController extends Controller
|
class TimeEntryController extends Controller
|
||||||
{
|
{
|
||||||
private function assertNoOverlap(Organization $organization, Member $member, Carbon $start, ?Carbon $end, ?TimeEntry $exclude = null): void
|
private function assertNoOverlap(Organization $organization, Member $member, \Illuminate\Support\Carbon $start, ?\Illuminate\Support\Carbon $end, ?TimeEntry $exclude = null): void
|
||||||
{
|
{
|
||||||
if (! $organization->prevent_overlapping_time_entries) {
|
if (! $organization->prevent_overlapping_time_entries) {
|
||||||
return;
|
return;
|
||||||
@@ -247,7 +246,7 @@ class TimeEntryController extends Controller
|
|||||||
'user',
|
'user',
|
||||||
'tagsRelation',
|
'tagsRelation',
|
||||||
]);
|
]);
|
||||||
$filename = 'time-entries-export-'.now()->format('Y-m-d_H-i-s').'-'.Str::uuid().'.'.$format->getFileExtension();
|
$filename = 'time-entries-export-'.now()->format('Y-m-d_H-i-s').'.'.$format->getFileExtension();
|
||||||
$folderPath = 'exports';
|
$folderPath = 'exports';
|
||||||
$path = $folderPath.'/'.$filename;
|
$path = $folderPath.'/'.$filename;
|
||||||
$localizationService = LocalizationService::forOrganization($organization);
|
$localizationService = LocalizationService::forOrganization($organization);
|
||||||
@@ -470,7 +469,7 @@ class TimeEntryController extends Controller
|
|||||||
$timezone = app(TimezoneService::class)->getTimezoneFromUser($this->user());
|
$timezone = app(TimezoneService::class)->getTimezoneFromUser($this->user());
|
||||||
$localizationService = LocalizationService::forOrganization($organization);
|
$localizationService = LocalizationService::forOrganization($organization);
|
||||||
|
|
||||||
$filename = 'time-entries-report-'.now()->format('Y-m-d_H-i-s').'-'.Str::uuid().'.'.$format->getFileExtension();
|
$filename = 'time-entries-report-'.now()->format('Y-m-d_H-i-s').'.'.$format->getFileExtension();
|
||||||
$folderPath = 'exports';
|
$folderPath = 'exports';
|
||||||
$path = $folderPath.'/'.$filename;
|
$path = $folderPath.'/'.$filename;
|
||||||
|
|
||||||
@@ -629,9 +628,9 @@ class TimeEntryController extends Controller
|
|||||||
/** @var Member|null $member */
|
/** @var Member|null $member */
|
||||||
$member = $request->has('member_id') ? Member::query()->findOrFail($request->input('member_id')) : null;
|
$member = $request->has('member_id') ? Member::query()->findOrFail($request->input('member_id')) : null;
|
||||||
if ($timeEntry->member->user_id === Auth::id() && ($member === null || $member->user_id === Auth::id())) {
|
if ($timeEntry->member->user_id === Auth::id() && ($member === null || $member->user_id === Auth::id())) {
|
||||||
$this->checkPermission($organization, 'time-entries:update:own', $timeEntry);
|
$this->checkPermission($organization, 'time-entries:update:own');
|
||||||
} else {
|
} else {
|
||||||
$this->checkPermission($organization, 'time-entries:update:all', $timeEntry);
|
$this->checkPermission($organization, 'time-entries:update:all');
|
||||||
}
|
}
|
||||||
|
|
||||||
if ($timeEntry->end !== null && $request->has('end') && $request->input('end') === null) {
|
if ($timeEntry->end !== null && $request->has('end') && $request->input('end') === null) {
|
||||||
|
|||||||
@@ -1,33 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace App\Http\Controllers\Api\V1;
|
|
||||||
|
|
||||||
use App\Service\TimezoneService;
|
|
||||||
use Illuminate\Http\JsonResponse;
|
|
||||||
|
|
||||||
class TimeZoneController extends Controller
|
|
||||||
{
|
|
||||||
/**
|
|
||||||
* Get all timezones
|
|
||||||
*
|
|
||||||
* @response object{key: string}[]
|
|
||||||
*
|
|
||||||
* @operationId getTimezones
|
|
||||||
*/
|
|
||||||
public function index(): JsonResponse
|
|
||||||
{
|
|
||||||
$timezones = app(TimezoneService::class)->getTimezones();
|
|
||||||
|
|
||||||
$response = [];
|
|
||||||
|
|
||||||
foreach ($timezones as $timezone) {
|
|
||||||
$response[] = (object) [
|
|
||||||
'key' => $timezone,
|
|
||||||
];
|
|
||||||
}
|
|
||||||
|
|
||||||
return response()->json($response);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -4,30 +4,15 @@ declare(strict_types=1);
|
|||||||
|
|
||||||
namespace App\Http\Controllers\Api\V1;
|
namespace App\Http\Controllers\Api\V1;
|
||||||
|
|
||||||
use App\Exceptions\Api\CanNotDeleteUserWhoIsOwnerOfOrganizationWithMultipleMembers;
|
|
||||||
use App\Exceptions\Api\UserResendEmailVerificationNoPendingEmailApiException;
|
|
||||||
use App\Http\Requests\V1\User\UserDestroyRequest;
|
|
||||||
use App\Http\Requests\V1\User\UserUpdateCurrentOrganizationRequest;
|
|
||||||
use App\Http\Requests\V1\User\UserUpdateRequest;
|
|
||||||
use App\Http\Resources\V1\User\UserResource;
|
use App\Http\Resources\V1\User\UserResource;
|
||||||
use App\Mail\VerifyUpdatedEmailMail;
|
|
||||||
use App\Models\Organization;
|
|
||||||
use App\Models\User;
|
|
||||||
use App\Service\DeletionService;
|
|
||||||
use App\Service\UserService;
|
|
||||||
use App\Support\Base64File;
|
|
||||||
use Illuminate\Auth\Access\AuthorizationException;
|
use Illuminate\Auth\Access\AuthorizationException;
|
||||||
use Illuminate\Http\JsonResponse;
|
|
||||||
use Illuminate\Support\Facades\Mail;
|
|
||||||
use Illuminate\Support\Facades\Storage;
|
|
||||||
use Illuminate\Support\Str;
|
|
||||||
|
|
||||||
class UserController extends Controller
|
class UserController extends Controller
|
||||||
{
|
{
|
||||||
/**
|
/**
|
||||||
* Get the current user
|
* Get the current user
|
||||||
*
|
*
|
||||||
* This endpoint is independent of the organization.
|
* This endpoint is independent of organization.
|
||||||
*
|
*
|
||||||
* @operationId getMe
|
* @operationId getMe
|
||||||
*
|
*
|
||||||
@@ -39,169 +24,4 @@ class UserController extends Controller
|
|||||||
|
|
||||||
return new UserResource($user);
|
return new UserResource($user);
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
|
||||||
* Update the current organization of the current user
|
|
||||||
*
|
|
||||||
* Switches the organization that the user is currently working in. The user
|
|
||||||
* must be a member of the given organization. This endpoint is independent of
|
|
||||||
* the organization.
|
|
||||||
*
|
|
||||||
* @operationId updateMyCurrentOrganization
|
|
||||||
*
|
|
||||||
* @throws AuthorizationException
|
|
||||||
*/
|
|
||||||
public function updateMyCurrentOrganization(UserUpdateCurrentOrganizationRequest $request, UserService $userService): UserResource
|
|
||||||
{
|
|
||||||
$user = $this->user();
|
|
||||||
|
|
||||||
/** @var Organization|null $organization */
|
|
||||||
$organization = $user->organizations()
|
|
||||||
->whereKey($request->getOrganizationId())
|
|
||||||
->first();
|
|
||||||
|
|
||||||
if ($organization === null) {
|
|
||||||
throw new AuthorizationException;
|
|
||||||
}
|
|
||||||
|
|
||||||
$userService->switchCurrentOrganization($user, $organization);
|
|
||||||
|
|
||||||
return new UserResource($user->refresh());
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Update the current user
|
|
||||||
*
|
|
||||||
* This endpoint is independent of the organization.
|
|
||||||
*
|
|
||||||
* @operationId updateUser
|
|
||||||
*/
|
|
||||||
public function update(User $user, UserUpdateRequest $request): UserResource
|
|
||||||
{
|
|
||||||
if ($user->getKey() !== $this->user()->getKey()) {
|
|
||||||
throw new AuthorizationException;
|
|
||||||
}
|
|
||||||
|
|
||||||
if ($request->hasPhotoKey()) {
|
|
||||||
$photoDisk = (string) config('filesystems.public');
|
|
||||||
$previousPhotoPath = $user->profile_photo_path;
|
|
||||||
$newPhoto = $request->getPhoto();
|
|
||||||
|
|
||||||
if ($newPhoto === null) {
|
|
||||||
$user->profile_photo_path = null;
|
|
||||||
} else {
|
|
||||||
$decoded = Base64File::decode($newPhoto);
|
|
||||||
assert($decoded !== null);
|
|
||||||
$extension = Base64File::extension($decoded['mime_type']);
|
|
||||||
assert($extension !== null);
|
|
||||||
|
|
||||||
$photoPath = 'profile-photos/'.Str::uuid().'.'.$extension;
|
|
||||||
Storage::disk($photoDisk)->put($photoPath, $decoded['data'], 'public');
|
|
||||||
$user->profile_photo_path = $photoPath;
|
|
||||||
}
|
|
||||||
|
|
||||||
if ($previousPhotoPath !== null) {
|
|
||||||
Storage::disk($photoDisk)->delete($previousPhotoPath);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
$emailToVerify = null;
|
|
||||||
$email = $request->getEmail();
|
|
||||||
if ($email !== null && $email !== Str::lower($user->email)) {
|
|
||||||
$emailToVerify = $email;
|
|
||||||
$user->pending_email = $email;
|
|
||||||
}
|
|
||||||
|
|
||||||
if ($request->getName() !== null) {
|
|
||||||
$user->name = $request->getName();
|
|
||||||
}
|
|
||||||
|
|
||||||
if ($request->getTimezone() !== null) {
|
|
||||||
$user->timezone = $request->getTimezone();
|
|
||||||
}
|
|
||||||
|
|
||||||
if ($request->getWeekStart() !== null) {
|
|
||||||
$user->week_start = $request->getWeekStart();
|
|
||||||
}
|
|
||||||
|
|
||||||
$user->save();
|
|
||||||
|
|
||||||
if ($emailToVerify !== null) {
|
|
||||||
Mail::to($emailToVerify)->send(new VerifyUpdatedEmailMail($user, $emailToVerify));
|
|
||||||
}
|
|
||||||
|
|
||||||
return new UserResource($user);
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Reset the pending email for a user.
|
|
||||||
*
|
|
||||||
* This endpoint is independent of the organization.
|
|
||||||
*
|
|
||||||
* @operationId resetUserPendingEmail
|
|
||||||
*
|
|
||||||
* @throws AuthorizationException Thrown when the authenticated user does not match the user whose email is pending verification.
|
|
||||||
*/
|
|
||||||
public function resetPendingEmail(User $user): JsonResponse
|
|
||||||
{
|
|
||||||
if ($user->getKey() !== $this->user()->getKey()) {
|
|
||||||
throw new AuthorizationException;
|
|
||||||
}
|
|
||||||
|
|
||||||
$user->pending_email = null;
|
|
||||||
$user->save();
|
|
||||||
|
|
||||||
return response()->json(null, 204);
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Resend the pending email update verification email.
|
|
||||||
*
|
|
||||||
* This endpoint is independent of the organization.
|
|
||||||
*
|
|
||||||
* @operationId resendUserEmailVerification
|
|
||||||
*
|
|
||||||
* @throws AuthorizationException Thrown when the authenticated user does not match the user whose email is pending verification.
|
|
||||||
* @throws UserResendEmailVerificationNoPendingEmailApiException Thrown when the user does not have a pending email to verify.
|
|
||||||
*/
|
|
||||||
public function resendEmailVerification(User $user): JsonResponse
|
|
||||||
{
|
|
||||||
if ($user->getKey() !== $this->user()->getKey()) {
|
|
||||||
throw new AuthorizationException;
|
|
||||||
}
|
|
||||||
|
|
||||||
if ($user->pending_email === null) {
|
|
||||||
throw new UserResendEmailVerificationNoPendingEmailApiException;
|
|
||||||
}
|
|
||||||
|
|
||||||
Mail::to($user->pending_email)
|
|
||||||
->queue(new VerifyUpdatedEmailMail($user, $user->pending_email));
|
|
||||||
|
|
||||||
return response()->json(null, 204);
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Handles the deletion of a user.
|
|
||||||
*
|
|
||||||
* This endpoint is independent of the organization.
|
|
||||||
*
|
|
||||||
* @operationId deleteUser
|
|
||||||
*
|
|
||||||
* @param User $user The user instance to be deleted.
|
|
||||||
* @param DeletionService $deletionService The service responsible for performing the user deletion.
|
|
||||||
* @return JsonResponse A JSON response with a 204 No Content status upon successful deletion.
|
|
||||||
*
|
|
||||||
* @throws AuthorizationException Thrown when the authenticated user does not match the user to be deleted.
|
|
||||||
* @throws CanNotDeleteUserWhoIsOwnerOfOrganizationWithMultipleMembers Thrown when the user to be deleted is the owner of an organization with multiple members.
|
|
||||||
*/
|
|
||||||
public function destroy(User $user, UserDestroyRequest $request, DeletionService $deletionService): JsonResponse
|
|
||||||
{
|
|
||||||
if ($user->getKey() !== $this->user()->getKey()) {
|
|
||||||
throw new AuthorizationException;
|
|
||||||
}
|
|
||||||
|
|
||||||
$deletionService->deleteUser($user);
|
|
||||||
|
|
||||||
return response()->json(null, 204);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -14,7 +14,7 @@ class UserMembershipController extends Controller
|
|||||||
/**
|
/**
|
||||||
* Get the memberships of the current user
|
* Get the memberships of the current user
|
||||||
*
|
*
|
||||||
* This endpoint is independent of the organization.
|
* This endpoint is independent of organization.
|
||||||
*
|
*
|
||||||
* @operationId getMyMemberships
|
* @operationId getMyMemberships
|
||||||
*
|
*
|
||||||
|
|||||||
@@ -17,7 +17,7 @@ class UserTimeEntryController extends Controller
|
|||||||
/**
|
/**
|
||||||
* Get the active time entry of the current user
|
* Get the active time entry of the current user
|
||||||
*
|
*
|
||||||
* This endpoint is independent of the organization.
|
* This endpoint is independent of organization.
|
||||||
*
|
*
|
||||||
* @operationId getMyActiveTimeEntry
|
* @operationId getMyActiveTimeEntry
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -59,7 +59,7 @@ class Controller extends BaseController
|
|||||||
protected function currentOrganization(): Organization
|
protected function currentOrganization(): Organization
|
||||||
{
|
{
|
||||||
$user = $this->user();
|
$user = $this->user();
|
||||||
$organization = $user->currentOrganization;
|
$organization = $user->currentTeam;
|
||||||
if ($organization === null) {
|
if ($organization === null) {
|
||||||
$organization = $user->organizations()->first();
|
$organization = $user->organizations()->first();
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -4,21 +4,4 @@ declare(strict_types=1);
|
|||||||
|
|
||||||
namespace App\Http\Controllers\Web;
|
namespace App\Http\Controllers\Web;
|
||||||
|
|
||||||
use App\Models\Organization;
|
abstract class Controller extends \App\Http\Controllers\Controller {}
|
||||||
use App\Service\PermissionStore;
|
|
||||||
use Illuminate\Auth\Access\AuthorizationException;
|
|
||||||
|
|
||||||
abstract class Controller extends \App\Http\Controllers\Controller
|
|
||||||
{
|
|
||||||
public function __construct(
|
|
||||||
protected PermissionStore $permissionStore,
|
|
||||||
) {}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* @throws AuthorizationException
|
|
||||||
*/
|
|
||||||
protected function hasPermission(Organization $organization, string $permission): bool
|
|
||||||
{
|
|
||||||
return $this->permissionStore->has($organization, $permission);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -4,13 +4,30 @@ declare(strict_types=1);
|
|||||||
|
|
||||||
namespace App\Http\Controllers\Web;
|
namespace App\Http\Controllers\Web;
|
||||||
|
|
||||||
|
use App\Enums\Role;
|
||||||
|
use App\Service\DashboardService;
|
||||||
|
use App\Service\PermissionStore;
|
||||||
|
use Illuminate\Auth\Access\AuthorizationException;
|
||||||
use Inertia\Inertia;
|
use Inertia\Inertia;
|
||||||
use Inertia\Response;
|
use Inertia\Response;
|
||||||
|
|
||||||
class DashboardController extends Controller
|
class DashboardController extends Controller
|
||||||
{
|
{
|
||||||
public function dashboard(): Response
|
/**
|
||||||
|
* @throws AuthorizationException
|
||||||
|
*/
|
||||||
|
public function dashboard(DashboardService $dashboardService, PermissionStore $permissionStore): Response
|
||||||
{
|
{
|
||||||
|
$user = $this->user();
|
||||||
|
$organization = $this->currentOrganization();
|
||||||
|
|
||||||
|
$latestTeamActivity = null;
|
||||||
|
if ($permissionStore->has($organization, 'time-entries:view:all')) {
|
||||||
|
$latestTeamActivity = $dashboardService->latestTeamActivity($organization);
|
||||||
|
}
|
||||||
|
|
||||||
|
$showBillableRate = $this->member($organization)->role !== Role::Employee->value || $organization->employees_can_see_billable_rates;
|
||||||
|
|
||||||
return Inertia::render('Dashboard');
|
return Inertia::render('Dashboard');
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,63 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace App\Http\Controllers\Web;
|
|
||||||
|
|
||||||
use App\Models\Organization;
|
|
||||||
use Brick\Money\Currency;
|
|
||||||
use Brick\Money\ISOCurrencyProvider;
|
|
||||||
use Illuminate\Http\RedirectResponse;
|
|
||||||
use Illuminate\Http\Request;
|
|
||||||
use Illuminate\Support\Str;
|
|
||||||
use Inertia\Inertia;
|
|
||||||
use Inertia\Response;
|
|
||||||
|
|
||||||
class OrganizationController extends Controller
|
|
||||||
{
|
|
||||||
/**
|
|
||||||
* Show the team creation screen.
|
|
||||||
*/
|
|
||||||
public function create(Request $request): Response
|
|
||||||
{
|
|
||||||
return Inertia::render('Teams/Create');
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Show the organizatio details screen.
|
|
||||||
*
|
|
||||||
* @param string $organizationId The organization ID
|
|
||||||
*/
|
|
||||||
public function show(string $organizationId): Response|RedirectResponse
|
|
||||||
{
|
|
||||||
$organization = Str::isUuid($organizationId) ? Organization::find($organizationId) : null;
|
|
||||||
if ($organization === null) {
|
|
||||||
return redirect()->route('dashboard');
|
|
||||||
}
|
|
||||||
if (! $this->hasPermission($organization, 'organizations:view')) {
|
|
||||||
return redirect()->route('dashboard');
|
|
||||||
}
|
|
||||||
|
|
||||||
$owner = $organization->owner;
|
|
||||||
|
|
||||||
return Inertia::render('Teams/Show', [
|
|
||||||
'team' => [
|
|
||||||
'id' => $organization->getKey(),
|
|
||||||
'name' => $organization->name,
|
|
||||||
'currency' => $organization->currency,
|
|
||||||
'owner' => [
|
|
||||||
'id' => $owner->getKey(),
|
|
||||||
'name' => $owner->name,
|
|
||||||
'profile_photo_url' => $owner->profile_photo_url,
|
|
||||||
],
|
|
||||||
],
|
|
||||||
'currencies' => array_map(function (Currency $currency): string {
|
|
||||||
return $currency->getName();
|
|
||||||
}, ISOCurrencyProvider::getInstance()->getAvailableCurrencies()),
|
|
||||||
'permissions' => [
|
|
||||||
'canDeleteTeam' => $this->hasPermission($organization, 'organizations:delete'),
|
|
||||||
'canUpdateTeam' => $this->hasPermission($organization, 'organizations:update'),
|
|
||||||
],
|
|
||||||
]);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,75 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace App\Http\Controllers\Web;
|
|
||||||
|
|
||||||
use App\Enums\Role;
|
|
||||||
use App\Models\OrganizationInvitation;
|
|
||||||
use App\Models\User;
|
|
||||||
use App\Service\MemberService;
|
|
||||||
use Illuminate\Http\RedirectResponse;
|
|
||||||
use Illuminate\Support\Facades\Auth;
|
|
||||||
use RuntimeException;
|
|
||||||
|
|
||||||
class OrganizationInvitationController extends Controller
|
|
||||||
{
|
|
||||||
public function accept(OrganizationInvitation $invitation, MemberService $memberService): RedirectResponse
|
|
||||||
{
|
|
||||||
$email = strtolower($invitation->email);
|
|
||||||
$role = Role::tryFrom($invitation->role);
|
|
||||||
if ($role === null || $role === Role::Owner || $role === Role::Placeholder) {
|
|
||||||
throw new RuntimeException('Invalid role');
|
|
||||||
}
|
|
||||||
|
|
||||||
$organization = $invitation->organization;
|
|
||||||
$invitee = User::query()
|
|
||||||
->where('email', $email)
|
|
||||||
->where('is_placeholder', '=', false)
|
|
||||||
->first();
|
|
||||||
|
|
||||||
// No account yet — finish on registration.
|
|
||||||
if ($invitee === null) {
|
|
||||||
if ($invitation->accepted_at === null) {
|
|
||||||
$invitation->accepted_at = now();
|
|
||||||
$invitation->save();
|
|
||||||
}
|
|
||||||
|
|
||||||
return redirect(route('register'))
|
|
||||||
->with('bannerText', __('Please create an account to finish joining the :organization organization.', [
|
|
||||||
'organization' => $organization->name,
|
|
||||||
]))
|
|
||||||
->with('bannerStyle', 'info');
|
|
||||||
}
|
|
||||||
|
|
||||||
$alreadyMember = $memberService->isEmailAlreadyMember($organization, $email);
|
|
||||||
if (! $alreadyMember) {
|
|
||||||
$memberService->addMember($invitee, $organization, $role);
|
|
||||||
$invitation->delete();
|
|
||||||
}
|
|
||||||
|
|
||||||
// Logged out — banner on /login.
|
|
||||||
if (! Auth::check()) {
|
|
||||||
return redirect(route('login'))
|
|
||||||
->with('bannerText', __('Great! You have accepted the invitation to join the :organization organization. Please log in to access it.', [
|
|
||||||
'organization' => $organization->name,
|
|
||||||
]))
|
|
||||||
->with('bannerStyle', 'success');
|
|
||||||
}
|
|
||||||
|
|
||||||
// Logged in — banner on /dashboard.
|
|
||||||
if ($alreadyMember) {
|
|
||||||
return redirect(route('dashboard'))
|
|
||||||
->with('bannerText', __('You are already a member of the :organization organization.', [
|
|
||||||
'organization' => $organization->name,
|
|
||||||
]))
|
|
||||||
->with('bannerStyle', 'danger');
|
|
||||||
}
|
|
||||||
|
|
||||||
return redirect(route('dashboard'))
|
|
||||||
->with('bannerText', __('Great! You have accepted the invitation to join the :organization organization.', [
|
|
||||||
'organization' => $organization->name,
|
|
||||||
]))
|
|
||||||
->with('bannerStyle', 'success');
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,54 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace App\Http\Controllers\Web;
|
|
||||||
|
|
||||||
use Illuminate\Contracts\Auth\StatefulGuard;
|
|
||||||
use Illuminate\Http\RedirectResponse;
|
|
||||||
use Illuminate\Http\Request;
|
|
||||||
use Illuminate\Routing\Controller;
|
|
||||||
use Illuminate\Support\Facades\DB;
|
|
||||||
use Illuminate\Validation\ValidationException;
|
|
||||||
use Laravel\Fortify\Actions\ConfirmPassword;
|
|
||||||
|
|
||||||
class OtherBrowserSessionsController extends Controller
|
|
||||||
{
|
|
||||||
/**
|
|
||||||
* Log the user out of their other browser sessions across all devices.
|
|
||||||
*/
|
|
||||||
public function destroy(Request $request, StatefulGuard $guard): RedirectResponse
|
|
||||||
{
|
|
||||||
$password = (string) $request->string('password');
|
|
||||||
|
|
||||||
$confirmed = app(ConfirmPassword::class)($guard, $request->user(), $password);
|
|
||||||
|
|
||||||
if (! $confirmed) {
|
|
||||||
throw ValidationException::withMessages([
|
|
||||||
'password' => __('The password is incorrect.'),
|
|
||||||
]);
|
|
||||||
}
|
|
||||||
|
|
||||||
$guard->logoutOtherDevices($password);
|
|
||||||
|
|
||||||
$this->deleteOtherSessionRecords($request);
|
|
||||||
|
|
||||||
return back(303);
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Delete the other browser session records from storage.
|
|
||||||
*/
|
|
||||||
protected function deleteOtherSessionRecords(Request $request): void
|
|
||||||
{
|
|
||||||
if (config('session.driver') !== 'database') {
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
DB::connection(config('session.connection'))
|
|
||||||
->table(config('session.table', 'sessions'))
|
|
||||||
->where('user_id', $request->user()->getAuthIdentifier())
|
|
||||||
->where('id', '!=', $request->session()->getId())
|
|
||||||
->delete();
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,53 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace App\Http\Controllers\Web;
|
|
||||||
|
|
||||||
use App\Models\User;
|
|
||||||
use Illuminate\Http\RedirectResponse;
|
|
||||||
use Illuminate\Http\Request;
|
|
||||||
use Illuminate\Support\Carbon;
|
|
||||||
use Illuminate\Support\Str;
|
|
||||||
|
|
||||||
class UserController extends Controller
|
|
||||||
{
|
|
||||||
public function verifyEmailChange(Request $request, User $user): RedirectResponse
|
|
||||||
{
|
|
||||||
if ($request->user()?->getAuthIdentifier() !== $user->getKey()) {
|
|
||||||
abort(403);
|
|
||||||
}
|
|
||||||
|
|
||||||
$email = $request->query('email');
|
|
||||||
if (! is_string($email)) {
|
|
||||||
abort(403);
|
|
||||||
}
|
|
||||||
|
|
||||||
$email = Str::lower($email);
|
|
||||||
|
|
||||||
if ($user->pending_email !== $email) {
|
|
||||||
abort(403);
|
|
||||||
}
|
|
||||||
|
|
||||||
$emailAlreadyInUse = User::query()
|
|
||||||
->where('email', '=', $email)
|
|
||||||
->where('is_placeholder', '=', false)
|
|
||||||
->whereKeyNot($user->getKey())
|
|
||||||
->exists();
|
|
||||||
|
|
||||||
if ($emailAlreadyInUse) {
|
|
||||||
return redirect(route('dashboard'))
|
|
||||||
->with('bannerStyle', 'danger')
|
|
||||||
->with('bannerText', __('The email address is already in use.'));
|
|
||||||
}
|
|
||||||
|
|
||||||
$user->email = $email;
|
|
||||||
$user->pending_email = null;
|
|
||||||
$user->email_verified_at = Carbon::now();
|
|
||||||
$user->save();
|
|
||||||
|
|
||||||
return redirect(route('dashboard'))
|
|
||||||
->with('bannerStyle', 'success')
|
|
||||||
->with('bannerText', __('Your email address has been updated successfully.'));
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,142 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace App\Http\Controllers\Web;
|
|
||||||
|
|
||||||
use App\Enums\Weekday;
|
|
||||||
use App\Service\Dto\UserAgentDto;
|
|
||||||
use App\Service\TimezoneService;
|
|
||||||
use Illuminate\Http\Request;
|
|
||||||
use Illuminate\Routing\Controller;
|
|
||||||
use Illuminate\Support\Carbon;
|
|
||||||
use Illuminate\Support\Facades\Auth;
|
|
||||||
use Illuminate\Support\Facades\DB;
|
|
||||||
use Inertia\Inertia;
|
|
||||||
use Inertia\Response;
|
|
||||||
use Laravel\Fortify\Actions\DisableTwoFactorAuthentication;
|
|
||||||
use Laravel\Fortify\Features;
|
|
||||||
|
|
||||||
class UserProfileController extends Controller
|
|
||||||
{
|
|
||||||
/**
|
|
||||||
* Validate the two-factor authentication state for the request.
|
|
||||||
*/
|
|
||||||
protected function validateTwoFactorAuthenticationState(Request $request): void
|
|
||||||
{
|
|
||||||
if (! Features::optionEnabled(Features::twoFactorAuthentication(), 'confirm')) {
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
$currentTime = time();
|
|
||||||
|
|
||||||
// Notate totally disabled state in session...
|
|
||||||
if ($this->twoFactorAuthenticationDisabled($request)) {
|
|
||||||
$request->session()->put('two_factor_empty_at', $currentTime);
|
|
||||||
}
|
|
||||||
|
|
||||||
// If was previously totally disabled this session but is now confirming, notate time...
|
|
||||||
if ($this->hasJustBegunConfirmingTwoFactorAuthentication($request)) {
|
|
||||||
$request->session()->put('two_factor_confirming_at', $currentTime);
|
|
||||||
}
|
|
||||||
|
|
||||||
// If the profile is reloaded and is not confirmed but was previously in confirming state, disable...
|
|
||||||
if ($this->neverFinishedConfirmingTwoFactorAuthentication($request, $currentTime)) {
|
|
||||||
app(DisableTwoFactorAuthentication::class)(Auth::user());
|
|
||||||
|
|
||||||
$request->session()->put('two_factor_empty_at', $currentTime);
|
|
||||||
$request->session()->remove('two_factor_confirming_at');
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Determine if two-factor authentication is totally disabled.
|
|
||||||
*
|
|
||||||
* @return bool
|
|
||||||
*/
|
|
||||||
protected function twoFactorAuthenticationDisabled(Request $request)
|
|
||||||
{
|
|
||||||
return is_null($request->user()->two_factor_secret) &&
|
|
||||||
is_null($request->user()->two_factor_confirmed_at);
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Determine if two-factor authentication is just now being confirmed within the last request cycle.
|
|
||||||
*
|
|
||||||
* @return bool
|
|
||||||
*/
|
|
||||||
protected function hasJustBegunConfirmingTwoFactorAuthentication(Request $request)
|
|
||||||
{
|
|
||||||
return ! is_null($request->user()->two_factor_secret) &&
|
|
||||||
is_null($request->user()->two_factor_confirmed_at) &&
|
|
||||||
$request->session()->has('two_factor_empty_at') &&
|
|
||||||
is_null($request->session()->get('two_factor_confirming_at'));
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Determine if two-factor authentication was never totally confirmed once confirmation started.
|
|
||||||
*
|
|
||||||
* @return bool
|
|
||||||
*/
|
|
||||||
protected function neverFinishedConfirmingTwoFactorAuthentication(Request $request, int $currentTime)
|
|
||||||
{
|
|
||||||
return ! array_key_exists('code', $request->session()->getOldInput()) &&
|
|
||||||
is_null($request->user()->two_factor_confirmed_at) &&
|
|
||||||
$request->session()->get('two_factor_confirming_at', 0) !== $currentTime;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Show the general profile settings screen.
|
|
||||||
*/
|
|
||||||
public function show(Request $request): Response
|
|
||||||
{
|
|
||||||
$this->validateTwoFactorAuthenticationState($request);
|
|
||||||
|
|
||||||
return Inertia::render('Profile/Show', [
|
|
||||||
'timezones' => app(TimezoneService::class)->getSelectOptions(),
|
|
||||||
'weekdays' => Weekday::toSelectArray(),
|
|
||||||
'confirmsTwoFactorAuthentication' => Features::optionEnabled(Features::twoFactorAuthentication(), 'confirm'),
|
|
||||||
'sessions' => $this->sessions($request),
|
|
||||||
]);
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Get the current sessions.
|
|
||||||
*
|
|
||||||
* @return array<int, object{agent: array{is_desktop: bool, platform: string|null, browser: string|null}, ip_address: string, is_current_device: bool, last_active: string}&\stdClass>
|
|
||||||
*/
|
|
||||||
public function sessions(Request $request): array
|
|
||||||
{
|
|
||||||
if (config('session.driver') !== 'database') {
|
|
||||||
return [];
|
|
||||||
}
|
|
||||||
|
|
||||||
return collect(
|
|
||||||
DB::connection(config('session.connection'))->table(config('session.table', 'sessions'))
|
|
||||||
->where('user_id', $request->user()->getAuthIdentifier())
|
|
||||||
->orderBy('last_activity', 'desc')
|
|
||||||
->get()
|
|
||||||
)->map(function (object $session) use ($request): object {
|
|
||||||
$agent = $this->createAgent(is_string($session->user_agent) ? $session->user_agent : '');
|
|
||||||
|
|
||||||
return (object) [
|
|
||||||
'agent' => [
|
|
||||||
'is_desktop' => $agent->isDesktop(),
|
|
||||||
'platform' => $agent->platform(),
|
|
||||||
'browser' => $agent->browser(),
|
|
||||||
],
|
|
||||||
'ip_address' => is_string($session->ip_address) ? $session->ip_address : '',
|
|
||||||
'is_current_device' => $session->id === $request->session()->getId(),
|
|
||||||
'last_active' => Carbon::createFromTimestamp($session->last_activity)->diffForHumans(),
|
|
||||||
];
|
|
||||||
})->all();
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Create a new agent instance from the given session.
|
|
||||||
*/
|
|
||||||
protected function createAgent(string $userAgent): UserAgentDto
|
|
||||||
{
|
|
||||||
return tap(new UserAgentDto, fn ($agent) => $agent->setUserAgent($userAgent));
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -4,37 +4,9 @@ declare(strict_types=1);
|
|||||||
|
|
||||||
namespace App\Http;
|
namespace App\Http;
|
||||||
|
|
||||||
use App\Http\Middleware\Authenticate;
|
|
||||||
use App\Http\Middleware\CheckOrganizationBlocked;
|
use App\Http\Middleware\CheckOrganizationBlocked;
|
||||||
use App\Http\Middleware\EncryptCookies;
|
|
||||||
use App\Http\Middleware\EnsureEmailIsVerified;
|
|
||||||
use App\Http\Middleware\ForceHttps;
|
|
||||||
use App\Http\Middleware\ForceJsonResponse;
|
use App\Http\Middleware\ForceJsonResponse;
|
||||||
use App\Http\Middleware\HandleInertiaRequests;
|
|
||||||
use App\Http\Middleware\PreventRequestsDuringMaintenance;
|
|
||||||
use App\Http\Middleware\RedirectIfAuthenticated;
|
|
||||||
use App\Http\Middleware\ShareInertiaData;
|
|
||||||
use App\Http\Middleware\TrimStrings;
|
|
||||||
use App\Http\Middleware\TrustProxies;
|
|
||||||
use App\Http\Middleware\ValidateSignature;
|
|
||||||
use App\Http\Middleware\VerifyCsrfToken;
|
|
||||||
use Illuminate\Auth\Middleware\AuthenticateWithBasicAuth;
|
|
||||||
use Illuminate\Auth\Middleware\Authorize;
|
|
||||||
use Illuminate\Auth\Middleware\RequirePassword;
|
|
||||||
use Illuminate\Cookie\Middleware\AddQueuedCookiesToResponse;
|
|
||||||
use Illuminate\Foundation\Http\Kernel as HttpKernel;
|
use Illuminate\Foundation\Http\Kernel as HttpKernel;
|
||||||
use Illuminate\Foundation\Http\Middleware\ConvertEmptyStringsToNull;
|
|
||||||
use Illuminate\Foundation\Http\Middleware\HandlePrecognitiveRequests;
|
|
||||||
use Illuminate\Foundation\Http\Middleware\ValidatePostSize;
|
|
||||||
use Illuminate\Http\Middleware\AddLinkHeadersForPreloadedAssets;
|
|
||||||
use Illuminate\Http\Middleware\HandleCors;
|
|
||||||
use Illuminate\Http\Middleware\SetCacheHeaders;
|
|
||||||
use Illuminate\Routing\Middleware\SubstituteBindings;
|
|
||||||
use Illuminate\Routing\Middleware\ThrottleRequests;
|
|
||||||
use Illuminate\Session\Middleware\AuthenticateSession;
|
|
||||||
use Illuminate\Session\Middleware\StartSession;
|
|
||||||
use Illuminate\View\Middleware\ShareErrorsFromSession;
|
|
||||||
use Laravel\Passport\Http\Middleware\CreateFreshApiToken;
|
|
||||||
|
|
||||||
class Kernel extends HttpKernel
|
class Kernel extends HttpKernel
|
||||||
{
|
{
|
||||||
@@ -46,13 +18,13 @@ class Kernel extends HttpKernel
|
|||||||
* @var array<int, class-string|string>
|
* @var array<int, class-string|string>
|
||||||
*/
|
*/
|
||||||
protected $middleware = [
|
protected $middleware = [
|
||||||
ForceHttps::class,
|
\App\Http\Middleware\ForceHttps::class,
|
||||||
TrustProxies::class,
|
\App\Http\Middleware\TrustProxies::class,
|
||||||
HandleCors::class,
|
\Illuminate\Http\Middleware\HandleCors::class,
|
||||||
PreventRequestsDuringMaintenance::class,
|
\App\Http\Middleware\PreventRequestsDuringMaintenance::class,
|
||||||
ValidatePostSize::class,
|
\Illuminate\Foundation\Http\Middleware\ValidatePostSize::class,
|
||||||
TrimStrings::class,
|
\App\Http\Middleware\TrimStrings::class,
|
||||||
ConvertEmptyStringsToNull::class,
|
\Illuminate\Foundation\Http\Middleware\ConvertEmptyStringsToNull::class,
|
||||||
];
|
];
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -62,21 +34,21 @@ class Kernel extends HttpKernel
|
|||||||
*/
|
*/
|
||||||
protected $middlewareGroups = [
|
protected $middlewareGroups = [
|
||||||
'web' => [
|
'web' => [
|
||||||
EncryptCookies::class,
|
\App\Http\Middleware\EncryptCookies::class,
|
||||||
AddQueuedCookiesToResponse::class,
|
\Illuminate\Cookie\Middleware\AddQueuedCookiesToResponse::class,
|
||||||
StartSession::class,
|
\Illuminate\Session\Middleware\StartSession::class,
|
||||||
ShareErrorsFromSession::class,
|
\Illuminate\View\Middleware\ShareErrorsFromSession::class,
|
||||||
VerifyCsrfToken::class,
|
\App\Http\Middleware\VerifyCsrfToken::class,
|
||||||
SubstituteBindings::class,
|
\Illuminate\Routing\Middleware\SubstituteBindings::class,
|
||||||
HandleInertiaRequests::class,
|
\App\Http\Middleware\HandleInertiaRequests::class,
|
||||||
ShareInertiaData::class,
|
\App\Http\Middleware\ShareInertiaData::class,
|
||||||
AddLinkHeadersForPreloadedAssets::class,
|
\Illuminate\Http\Middleware\AddLinkHeadersForPreloadedAssets::class,
|
||||||
CreateFreshApiToken::class,
|
\Laravel\Passport\Http\Middleware\CreateFreshApiToken::class,
|
||||||
],
|
],
|
||||||
|
|
||||||
'api' => [
|
'api' => [
|
||||||
ThrottleRequests::class.':api',
|
\Illuminate\Routing\Middleware\ThrottleRequests::class.':api',
|
||||||
SubstituteBindings::class,
|
\Illuminate\Routing\Middleware\SubstituteBindings::class,
|
||||||
ForceJsonResponse::class,
|
ForceJsonResponse::class,
|
||||||
],
|
],
|
||||||
|
|
||||||
@@ -92,17 +64,17 @@ class Kernel extends HttpKernel
|
|||||||
* @var array<string, class-string|string>
|
* @var array<string, class-string|string>
|
||||||
*/
|
*/
|
||||||
protected $middlewareAliases = [
|
protected $middlewareAliases = [
|
||||||
'auth' => Authenticate::class,
|
'auth' => \App\Http\Middleware\Authenticate::class,
|
||||||
'auth.basic' => AuthenticateWithBasicAuth::class,
|
'auth.basic' => \Illuminate\Auth\Middleware\AuthenticateWithBasicAuth::class,
|
||||||
'auth.session' => AuthenticateSession::class,
|
'auth.session' => \Illuminate\Session\Middleware\AuthenticateSession::class,
|
||||||
'cache.headers' => SetCacheHeaders::class,
|
'cache.headers' => \Illuminate\Http\Middleware\SetCacheHeaders::class,
|
||||||
'can' => Authorize::class,
|
'can' => \Illuminate\Auth\Middleware\Authorize::class,
|
||||||
'guest' => RedirectIfAuthenticated::class,
|
'guest' => \App\Http\Middleware\RedirectIfAuthenticated::class,
|
||||||
'password.confirm' => RequirePassword::class,
|
'password.confirm' => \Illuminate\Auth\Middleware\RequirePassword::class,
|
||||||
'precognitive' => HandlePrecognitiveRequests::class,
|
'precognitive' => \Illuminate\Foundation\Http\Middleware\HandlePrecognitiveRequests::class,
|
||||||
'signed' => ValidateSignature::class,
|
'signed' => \App\Http\Middleware\ValidateSignature::class,
|
||||||
'throttle' => ThrottleRequests::class,
|
'throttle' => \Illuminate\Routing\Middleware\ThrottleRequests::class,
|
||||||
'verified' => EnsureEmailIsVerified::class,
|
'verified' => \App\Http\Middleware\EnsureEmailIsVerified::class,
|
||||||
'check-organization-blocked' => CheckOrganizationBlocked::class,
|
'check-organization-blocked' => CheckOrganizationBlocked::class,
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -17,7 +17,7 @@ class EnsureEmailIsVerified
|
|||||||
*/
|
*/
|
||||||
public function handle(Request $request, Closure $next, ?string $redirectToRoute = null): Response
|
public function handle(Request $request, Closure $next, ?string $redirectToRoute = null): Response
|
||||||
{
|
{
|
||||||
if (! app()->isLocal() || config('app.local_email_verification')) {
|
if (! app()->isLocal()) {
|
||||||
if ($request->user() === null ||
|
if ($request->user() === null ||
|
||||||
(! $request->user()->hasVerifiedEmail())) {
|
(! $request->user()->hasVerifiedEmail())) {
|
||||||
return $request->expectsJson()
|
return $request->expectsJson()
|
||||||
|
|||||||
@@ -14,7 +14,7 @@ class ForceHttps
|
|||||||
/**
|
/**
|
||||||
* Handle an incoming request.
|
* Handle an incoming request.
|
||||||
*
|
*
|
||||||
* @param Closure(Request): (Response) $next
|
* @param \Closure(\Illuminate\Http\Request): (\Symfony\Component\HttpFoundation\Response) $next
|
||||||
*/
|
*/
|
||||||
public function handle(Request $request, Closure $next, string ...$guards): Response
|
public function handle(Request $request, Closure $next, string ...$guards): Response
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -13,7 +13,7 @@ class ForceJsonResponse
|
|||||||
/**
|
/**
|
||||||
* Handle an incoming request.
|
* Handle an incoming request.
|
||||||
*
|
*
|
||||||
* @param Closure(Request): (Response) $next
|
* @param \Closure(\Illuminate\Http\Request): (\Symfony\Component\HttpFoundation\Response) $next
|
||||||
*/
|
*/
|
||||||
public function handle(Request $request, Closure $next, string ...$guards): Response
|
public function handle(Request $request, Closure $next, string ...$guards): Response
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -46,7 +46,7 @@ class HandleInertiaRequests extends Middleware
|
|||||||
/** @var BillingContract $billing */
|
/** @var BillingContract $billing */
|
||||||
$billing = app(BillingContract::class);
|
$billing = app(BillingContract::class);
|
||||||
|
|
||||||
$currentOrganization = $request->user()?->currentOrganization;
|
$currentOrganization = $request->user()?->currentTeam;
|
||||||
|
|
||||||
return array_merge(parent::share($request), [
|
return array_merge(parent::share($request), [
|
||||||
'has_billing_extension' => $hasBilling,
|
'has_billing_extension' => $hasBilling,
|
||||||
@@ -60,8 +60,6 @@ class HandleInertiaRequests extends Middleware
|
|||||||
] : null,
|
] : null,
|
||||||
'flash' => [
|
'flash' => [
|
||||||
'message' => fn () => $request->session()->get('message'),
|
'message' => fn () => $request->session()->get('message'),
|
||||||
'bannerText' => fn () => $request->session()->get('bannerText'),
|
|
||||||
'bannerStyle' => fn () => $request->session()->get('bannerStyle'),
|
|
||||||
],
|
],
|
||||||
]);
|
]);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -15,7 +15,7 @@ class RedirectIfAuthenticated
|
|||||||
/**
|
/**
|
||||||
* Handle an incoming request.
|
* Handle an incoming request.
|
||||||
*
|
*
|
||||||
* @param Closure(Request): (Response) $next
|
* @param \Closure(\Illuminate\Http\Request): (\Symfony\Component\HttpFoundation\Response) $next
|
||||||
*/
|
*/
|
||||||
public function handle(Request $request, Closure $next, string ...$guards): Response
|
public function handle(Request $request, Closure $next, string ...$guards): Response
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -9,10 +9,12 @@ use App\Models\User;
|
|||||||
use App\Service\PermissionStore;
|
use App\Service\PermissionStore;
|
||||||
use Closure;
|
use Closure;
|
||||||
use Illuminate\Http\Request;
|
use Illuminate\Http\Request;
|
||||||
|
use Illuminate\Support\Facades\Gate;
|
||||||
use Illuminate\Support\Facades\Session;
|
use Illuminate\Support\Facades\Session;
|
||||||
use Illuminate\Support\MessageBag;
|
use Illuminate\Support\MessageBag;
|
||||||
use Inertia\Inertia;
|
use Inertia\Inertia;
|
||||||
use Laravel\Fortify\Features;
|
use Laravel\Fortify\Features;
|
||||||
|
use Laravel\Jetstream\Jetstream;
|
||||||
use Symfony\Component\HttpFoundation\Response;
|
use Symfony\Component\HttpFoundation\Response;
|
||||||
|
|
||||||
class ShareInertiaData
|
class ShareInertiaData
|
||||||
@@ -25,8 +27,28 @@ class ShareInertiaData
|
|||||||
/** @var PermissionStore $permissions */
|
/** @var PermissionStore $permissions */
|
||||||
$permissions = app(PermissionStore::class);
|
$permissions = app(PermissionStore::class);
|
||||||
Inertia::share([
|
Inertia::share([
|
||||||
|
'jetstream' => function () use ($request) {
|
||||||
|
/** @var User|null $user */
|
||||||
|
$user = $request->user();
|
||||||
|
|
||||||
|
return [
|
||||||
|
'canCreateTeams' => $user !== null &&
|
||||||
|
Jetstream::userHasTeamFeatures($user) &&
|
||||||
|
Gate::forUser($user)->check('create', Jetstream::newTeamModel()),
|
||||||
|
'canManageTwoFactorAuthentication' => Features::canManageTwoFactorAuthentication(),
|
||||||
|
'canUpdatePassword' => Features::enabled(Features::updatePasswords()),
|
||||||
|
'canUpdateProfileInformation' => Features::canUpdateProfileInformation(),
|
||||||
|
'hasEmailVerification' => Features::enabled(Features::emailVerification()),
|
||||||
|
'flash' => $request->session()->get('flash', []),
|
||||||
|
'hasAccountDeletionFeatures' => Jetstream::hasAccountDeletionFeatures(),
|
||||||
|
'hasApiFeatures' => Jetstream::hasApiFeatures(),
|
||||||
|
'hasTeamFeatures' => Jetstream::hasTeamFeatures(),
|
||||||
|
'hasTermsAndPrivacyPolicyFeature' => Jetstream::hasTermsAndPrivacyPolicyFeature(),
|
||||||
|
'managesProfilePhotos' => Jetstream::managesProfilePhotos(),
|
||||||
|
];
|
||||||
|
},
|
||||||
'auth' => [
|
'auth' => [
|
||||||
'permissions' => $request->user() !== null && $request->user()->currentOrganization !== null ? $permissions->getPermissions($request->user()->currentOrganization) : [],
|
'permissions' => $request->user() !== null && $request->user()->currentTeam !== null ? $permissions->getPermissions($request->user()->currentTeam) : [],
|
||||||
'user' => function () use ($request): array {
|
'user' => function () use ($request): array {
|
||||||
/** @var User|null $user */
|
/** @var User|null $user */
|
||||||
$user = $request->user();
|
$user = $request->user();
|
||||||
@@ -35,8 +57,6 @@ class ShareInertiaData
|
|||||||
return [];
|
return [];
|
||||||
}
|
}
|
||||||
|
|
||||||
$currentOrganization = $user->currentOrganization;
|
|
||||||
|
|
||||||
return array_merge([
|
return array_merge([
|
||||||
'id' => $user->id,
|
'id' => $user->id,
|
||||||
'name' => $user->name,
|
'name' => $user->name,
|
||||||
@@ -49,12 +69,12 @@ class ShareInertiaData
|
|||||||
'profile_photo_url' => $user->profile_photo_url,
|
'profile_photo_url' => $user->profile_photo_url,
|
||||||
'two_factor_enabled' => Features::enabled(Features::twoFactorAuthentication())
|
'two_factor_enabled' => Features::enabled(Features::twoFactorAuthentication())
|
||||||
&& ! is_null($user->two_factor_secret),
|
&& ! is_null($user->two_factor_secret),
|
||||||
'current_team' => $currentOrganization !== null ? [
|
'current_team' => $user->currentTeam !== null ? [
|
||||||
'id' => $currentOrganization->id,
|
'id' => $user->currentTeam->id,
|
||||||
'user_id' => $currentOrganization->user_id,
|
'user_id' => $user->currentTeam->user_id,
|
||||||
'name' => $currentOrganization->name,
|
'name' => $user->currentTeam->name,
|
||||||
'personal_team' => $currentOrganization->personal_team,
|
'personal_team' => $user->currentTeam->personal_team,
|
||||||
'currency' => $currentOrganization->currency,
|
'currency' => $user->currentTeam->currency,
|
||||||
] : null,
|
] : null,
|
||||||
], array_filter([
|
], array_filter([
|
||||||
'all_teams' => $user->organizations->map(function (Organization $organization): array {
|
'all_teams' => $user->organizations->map(function (Organization $organization): array {
|
||||||
|
|||||||
@@ -7,7 +7,6 @@ namespace App\Http\Requests\V1\Member;
|
|||||||
use App\Http\Requests\V1\BaseFormRequest;
|
use App\Http\Requests\V1\BaseFormRequest;
|
||||||
use App\Models\Member;
|
use App\Models\Member;
|
||||||
use App\Models\Organization;
|
use App\Models\Organization;
|
||||||
use Illuminate\Contracts\Validation\Rule;
|
|
||||||
use Illuminate\Contracts\Validation\ValidationRule;
|
use Illuminate\Contracts\Validation\ValidationRule;
|
||||||
use Illuminate\Database\Eloquent\Builder;
|
use Illuminate\Database\Eloquent\Builder;
|
||||||
use Korridor\LaravelModelValidationRules\Rules\ExistsEloquent;
|
use Korridor\LaravelModelValidationRules\Rules\ExistsEloquent;
|
||||||
@@ -20,7 +19,7 @@ class MemberMergeIntoRequest extends BaseFormRequest
|
|||||||
/**
|
/**
|
||||||
* Get the validation rules that apply to the request.
|
* Get the validation rules that apply to the request.
|
||||||
*
|
*
|
||||||
* @return array<string, array<string|ValidationRule|Rule>>
|
* @return array<string, array<string|ValidationRule|\Illuminate\Contracts\Validation\Rule>>
|
||||||
*/
|
*/
|
||||||
public function rules(): array
|
public function rules(): array
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -1,48 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace App\Http\Requests\V1\Organization;
|
|
||||||
|
|
||||||
use App\Http\Requests\V1\BaseFormRequest;
|
|
||||||
use Illuminate\Support\Facades\Hash;
|
|
||||||
use Illuminate\Validation\Validator;
|
|
||||||
|
|
||||||
class OrganizationDestroyRequest extends BaseFormRequest
|
|
||||||
{
|
|
||||||
/**
|
|
||||||
* Get the validation rules that apply to the request.
|
|
||||||
*
|
|
||||||
* @return array<string, array<string>>
|
|
||||||
*/
|
|
||||||
public function rules(): array
|
|
||||||
{
|
|
||||||
return [
|
|
||||||
'password' => [
|
|
||||||
'required',
|
|
||||||
'string',
|
|
||||||
],
|
|
||||||
];
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* @return array<int, callable(Validator): void>
|
|
||||||
*/
|
|
||||||
public function after(): array
|
|
||||||
{
|
|
||||||
return [
|
|
||||||
function (Validator $validator): void {
|
|
||||||
if ($validator->errors()->has('password')) {
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
$user = $this->user();
|
|
||||||
$password = $this->input('password');
|
|
||||||
|
|
||||||
if (! is_string($password) || $user === null || ! Hash::check($password, (string) $user->password)) {
|
|
||||||
$validator->errors()->add('password', __('The password is incorrect.'));
|
|
||||||
}
|
|
||||||
},
|
|
||||||
];
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,36 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace App\Http\Requests\V1\Organization;
|
|
||||||
|
|
||||||
use App\Http\Requests\V1\BaseFormRequest;
|
|
||||||
use App\Models\Organization;
|
|
||||||
use Illuminate\Contracts\Validation\Rule;
|
|
||||||
|
|
||||||
/**
|
|
||||||
* @property Organization $organization Organization from model binding
|
|
||||||
*/
|
|
||||||
class OrganizationStoreRequest extends BaseFormRequest
|
|
||||||
{
|
|
||||||
/**
|
|
||||||
* Get the validation rules that apply to the request.
|
|
||||||
*
|
|
||||||
* @return array<string, array<string|Rule>>
|
|
||||||
*/
|
|
||||||
public function rules(): array
|
|
||||||
{
|
|
||||||
return [
|
|
||||||
'name' => [
|
|
||||||
'required',
|
|
||||||
'string',
|
|
||||||
'max:255',
|
|
||||||
],
|
|
||||||
];
|
|
||||||
}
|
|
||||||
|
|
||||||
public function getName(): string
|
|
||||||
{
|
|
||||||
return (string) $this->input('name');
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -11,8 +11,6 @@ use App\Enums\NumberFormat;
|
|||||||
use App\Enums\TimeFormat;
|
use App\Enums\TimeFormat;
|
||||||
use App\Http\Requests\V1\BaseFormRequest;
|
use App\Http\Requests\V1\BaseFormRequest;
|
||||||
use App\Models\Organization;
|
use App\Models\Organization;
|
||||||
use App\Rules\CurrencyRule;
|
|
||||||
use Illuminate\Contracts\Validation\ValidationRule;
|
|
||||||
use Illuminate\Validation\Rule;
|
use Illuminate\Validation\Rule;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -23,7 +21,7 @@ class OrganizationUpdateRequest extends BaseFormRequest
|
|||||||
/**
|
/**
|
||||||
* Get the validation rules that apply to the request.
|
* Get the validation rules that apply to the request.
|
||||||
*
|
*
|
||||||
* @return array<string, array<string|\Illuminate\Contracts\Validation\Rule|ValidationRule>>
|
* @return array<string, array<string|\Illuminate\Contracts\Validation\Rule>>
|
||||||
*/
|
*/
|
||||||
public function rules(): array
|
public function rules(): array
|
||||||
{
|
{
|
||||||
@@ -32,10 +30,6 @@ class OrganizationUpdateRequest extends BaseFormRequest
|
|||||||
'string',
|
'string',
|
||||||
'max:255',
|
'max:255',
|
||||||
],
|
],
|
||||||
'currency' => [
|
|
||||||
'string',
|
|
||||||
new CurrencyRule,
|
|
||||||
],
|
|
||||||
'billable_rate' => array_merge(
|
'billable_rate' => array_merge(
|
||||||
[
|
[
|
||||||
'nullable',
|
'nullable',
|
||||||
@@ -74,11 +68,6 @@ class OrganizationUpdateRequest extends BaseFormRequest
|
|||||||
return $this->has('name') ? (string) $this->input('name') : null;
|
return $this->has('name') ? (string) $this->input('name') : null;
|
||||||
}
|
}
|
||||||
|
|
||||||
public function getCurrency(): ?string
|
|
||||||
{
|
|
||||||
return $this->has('currency') ? (string) $this->input('currency') : null;
|
|
||||||
}
|
|
||||||
|
|
||||||
public function getNumberFormat(): ?NumberFormat
|
public function getNumberFormat(): ?NumberFormat
|
||||||
{
|
{
|
||||||
return $this->has('number_format') ? NumberFormat::from($this->input('number_format')) : null;
|
return $this->has('number_format') ? NumberFormat::from($this->input('number_format')) : null;
|
||||||
|
|||||||
@@ -1,48 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace App\Http\Requests\V1\User;
|
|
||||||
|
|
||||||
use App\Http\Requests\V1\BaseFormRequest;
|
|
||||||
use Illuminate\Support\Facades\Hash;
|
|
||||||
use Illuminate\Validation\Validator;
|
|
||||||
|
|
||||||
class UserDestroyRequest extends BaseFormRequest
|
|
||||||
{
|
|
||||||
/**
|
|
||||||
* Get the validation rules that apply to the request.
|
|
||||||
*
|
|
||||||
* @return array<string, array<string>>
|
|
||||||
*/
|
|
||||||
public function rules(): array
|
|
||||||
{
|
|
||||||
return [
|
|
||||||
'password' => [
|
|
||||||
'required',
|
|
||||||
'string',
|
|
||||||
],
|
|
||||||
];
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* @return array<int, callable(Validator): void>
|
|
||||||
*/
|
|
||||||
public function after(): array
|
|
||||||
{
|
|
||||||
return [
|
|
||||||
function (Validator $validator): void {
|
|
||||||
if ($validator->errors()->has('password')) {
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
$user = $this->user();
|
|
||||||
$password = $this->input('password');
|
|
||||||
|
|
||||||
if (! is_string($password) || $user === null || ! Hash::check($password, (string) $user->password)) {
|
|
||||||
$validator->errors()->add('password', __('The password is incorrect.'));
|
|
||||||
}
|
|
||||||
},
|
|
||||||
];
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,32 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace App\Http\Requests\V1\User;
|
|
||||||
|
|
||||||
use App\Http\Requests\V1\BaseFormRequest;
|
|
||||||
use Illuminate\Contracts\Validation\ValidationRule;
|
|
||||||
|
|
||||||
class UserUpdateCurrentOrganizationRequest extends BaseFormRequest
|
|
||||||
{
|
|
||||||
/**
|
|
||||||
* Get the validation rules that apply to the request.
|
|
||||||
*
|
|
||||||
* @return array<string, array<string|ValidationRule>>
|
|
||||||
*/
|
|
||||||
public function rules(): array
|
|
||||||
{
|
|
||||||
return [
|
|
||||||
'organization_id' => [
|
|
||||||
'required',
|
|
||||||
'string',
|
|
||||||
'uuid',
|
|
||||||
],
|
|
||||||
];
|
|
||||||
}
|
|
||||||
|
|
||||||
public function getOrganizationId(): string
|
|
||||||
{
|
|
||||||
return (string) $this->input('organization_id');
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,95 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace App\Http\Requests\V1\User;
|
|
||||||
|
|
||||||
use App\Enums\Weekday;
|
|
||||||
use App\Http\Requests\V1\BaseFormRequest;
|
|
||||||
use App\Models\User;
|
|
||||||
use App\Rules\Base64ImageRule;
|
|
||||||
use Illuminate\Contracts\Validation\ValidationRule;
|
|
||||||
use Illuminate\Database\Eloquent\Builder;
|
|
||||||
use Illuminate\Support\Str;
|
|
||||||
use Illuminate\Validation\Rule;
|
|
||||||
use Korridor\LaravelModelValidationRules\Rules\UniqueEloquent;
|
|
||||||
|
|
||||||
/**
|
|
||||||
* @property User $user User from model binding
|
|
||||||
*/
|
|
||||||
class UserUpdateRequest extends BaseFormRequest
|
|
||||||
{
|
|
||||||
protected function prepareForValidation(): void
|
|
||||||
{
|
|
||||||
if ($this->has('email') && is_string($this->input('email'))) {
|
|
||||||
$this->merge([
|
|
||||||
'email' => Str::lower((string) $this->input('email')),
|
|
||||||
]);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Get the validation rules that apply to the request.
|
|
||||||
*
|
|
||||||
* @return array<string, array<string|\Illuminate\Contracts\Validation\Rule|ValidationRule>>
|
|
||||||
*/
|
|
||||||
public function rules(): array
|
|
||||||
{
|
|
||||||
return [
|
|
||||||
'name' => [
|
|
||||||
'string',
|
|
||||||
'max:255',
|
|
||||||
],
|
|
||||||
'email' => [
|
|
||||||
'email',
|
|
||||||
'max:255',
|
|
||||||
UniqueEloquent::make(User::class, 'email')->ignore($this->user->id)->query(function (Builder $query) {
|
|
||||||
/** @var Builder<User> $query */
|
|
||||||
return $query->where('is_placeholder', '=', false);
|
|
||||||
}),
|
|
||||||
],
|
|
||||||
'photo' => [
|
|
||||||
'nullable',
|
|
||||||
new Base64ImageRule,
|
|
||||||
],
|
|
||||||
'timezone' => [
|
|
||||||
'timezone:all',
|
|
||||||
],
|
|
||||||
'week_start' => [
|
|
||||||
Rule::enum(Weekday::class),
|
|
||||||
],
|
|
||||||
];
|
|
||||||
}
|
|
||||||
|
|
||||||
public function getName(): ?string
|
|
||||||
{
|
|
||||||
return $this->has('name') ? (string) $this->input('name') : null;
|
|
||||||
}
|
|
||||||
|
|
||||||
public function getEmail(): ?string
|
|
||||||
{
|
|
||||||
return $this->has('email') ? Str::lower((string) $this->input('email')) : null;
|
|
||||||
}
|
|
||||||
|
|
||||||
public function getTimezone(): ?string
|
|
||||||
{
|
|
||||||
return $this->has('timezone') ? (string) $this->input('timezone') : null;
|
|
||||||
}
|
|
||||||
|
|
||||||
public function getWeekStart(): ?Weekday
|
|
||||||
{
|
|
||||||
return $this->has('week_start') ? Weekday::from($this->input('week_start')) : null;
|
|
||||||
}
|
|
||||||
|
|
||||||
public function hasPhotoKey(): bool
|
|
||||||
{
|
|
||||||
return $this->has('photo');
|
|
||||||
}
|
|
||||||
|
|
||||||
public function getPhoto(): ?string
|
|
||||||
{
|
|
||||||
$value = $this->input('photo');
|
|
||||||
|
|
||||||
return is_string($value) ? $value : null;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -28,8 +28,6 @@ class UserResource extends BaseResource
|
|||||||
'name' => $this->resource->name,
|
'name' => $this->resource->name,
|
||||||
/** @var string $email Email of user */
|
/** @var string $email Email of user */
|
||||||
'email' => $this->resource->email,
|
'email' => $this->resource->email,
|
||||||
/** @var string|null $pending_email Email address awaiting verification (set when the user has requested an email change but not yet verified the new address) */
|
|
||||||
'pending_email' => $this->resource->pending_email,
|
|
||||||
/** @var string $profile_photo_url Profile photo URL */
|
/** @var string $profile_photo_url Profile photo URL */
|
||||||
'profile_photo_url' => $this->resource->profile_photo_url,
|
'profile_photo_url' => $this->resource->profile_photo_url,
|
||||||
/** @var string $timezone Timezone (f.e. Europe/Berlin or America/New_York) */
|
/** @var string $timezone Timezone (f.e. Europe/Berlin or America/New_York) */
|
||||||
|
|||||||
43
app/Listeners/RemovePlaceholder.php
Normal file
43
app/Listeners/RemovePlaceholder.php
Normal file
@@ -0,0 +1,43 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Listeners;
|
||||||
|
|
||||||
|
use App\Models\Member;
|
||||||
|
use App\Models\User;
|
||||||
|
use App\Service\MemberService;
|
||||||
|
use Illuminate\Database\Eloquent\Builder;
|
||||||
|
use Laravel\Jetstream\Events\TeamMemberAdded;
|
||||||
|
|
||||||
|
class RemovePlaceholder
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* Handle the event.
|
||||||
|
*/
|
||||||
|
public function handle(TeamMemberAdded $event): void
|
||||||
|
{
|
||||||
|
$memberService = app(MemberService::class);
|
||||||
|
$member = Member::query()
|
||||||
|
->whereBelongsTo($event->team, 'organization')
|
||||||
|
->whereBelongsTo($event->user, 'user')
|
||||||
|
->firstOrFail();
|
||||||
|
$placeholders = Member::query()
|
||||||
|
->whereHas('user', function (Builder $query) use ($event): void {
|
||||||
|
/** @var Builder<User> $query */
|
||||||
|
$query->where('is_placeholder', '=', true)
|
||||||
|
->where('email', '=', $event->user->email);
|
||||||
|
})
|
||||||
|
->whereBelongsTo($event->team, 'organization')
|
||||||
|
->with(['user'])
|
||||||
|
->get();
|
||||||
|
|
||||||
|
foreach ($placeholders as $placeholder) {
|
||||||
|
/** @var Member $placeholder */
|
||||||
|
$placeholderUser = $placeholder->user;
|
||||||
|
$memberService->assignOrganizationEntitiesToDifferentMember($event->team, $placeholder, $member);
|
||||||
|
$placeholder->delete();
|
||||||
|
$placeholderUser->delete();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -8,7 +8,6 @@ use App\Models\OrganizationInvitation;
|
|||||||
use Illuminate\Bus\Queueable;
|
use Illuminate\Bus\Queueable;
|
||||||
use Illuminate\Mail\Mailable;
|
use Illuminate\Mail\Mailable;
|
||||||
use Illuminate\Queue\SerializesModels;
|
use Illuminate\Queue\SerializesModels;
|
||||||
use Illuminate\Support\Carbon;
|
|
||||||
use Illuminate\Support\Facades\URL;
|
use Illuminate\Support\Facades\URL;
|
||||||
|
|
||||||
class OrganizationInvitationMail extends Mailable
|
class OrganizationInvitationMail extends Mailable
|
||||||
@@ -33,12 +32,9 @@ class OrganizationInvitationMail extends Mailable
|
|||||||
public function build(): self
|
public function build(): self
|
||||||
{
|
{
|
||||||
return $this->markdown('emails.organization-invitation', [
|
return $this->markdown('emails.organization-invitation', [
|
||||||
'acceptUrl' => URL::to(URL::signedRoute(
|
'acceptUrl' => URL::signedRoute('team-invitations.accept', [
|
||||||
'organization-invitations.accept',
|
'invitation' => $this->invitation,
|
||||||
['invitation' => $this->invitation->getKey()],
|
]),
|
||||||
Carbon::now()->addDays(90),
|
|
||||||
false
|
|
||||||
)),
|
|
||||||
])->subject(__('Organization Invitation'));
|
])->subject(__('Organization Invitation'));
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,48 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace App\Mail;
|
|
||||||
|
|
||||||
use App\Models\User;
|
|
||||||
use Illuminate\Bus\Queueable;
|
|
||||||
use Illuminate\Mail\Mailable;
|
|
||||||
use Illuminate\Queue\SerializesModels;
|
|
||||||
use Illuminate\Support\Carbon;
|
|
||||||
use Illuminate\Support\Facades\URL;
|
|
||||||
use Illuminate\Support\Str;
|
|
||||||
|
|
||||||
class VerifyUpdatedEmailMail extends Mailable
|
|
||||||
{
|
|
||||||
use Queueable, SerializesModels;
|
|
||||||
|
|
||||||
public User $user;
|
|
||||||
|
|
||||||
public string $email;
|
|
||||||
|
|
||||||
public function __construct(User $user, string $email)
|
|
||||||
{
|
|
||||||
$this->user = $user;
|
|
||||||
$this->email = Str::lower($email);
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Build the message.
|
|
||||||
*/
|
|
||||||
public function build(): self
|
|
||||||
{
|
|
||||||
$verificationUrl = URL::temporarySignedRoute(
|
|
||||||
'users.verify-email-change',
|
|
||||||
Carbon::now()->addMinutes((int) config('auth.verification.expire', 60)),
|
|
||||||
[
|
|
||||||
'user' => $this->user->getKey(),
|
|
||||||
'email' => $this->email,
|
|
||||||
],
|
|
||||||
false
|
|
||||||
);
|
|
||||||
|
|
||||||
return $this->markdown('emails.verify-updated-email', [
|
|
||||||
'verificationUrl' => URL::to($verificationUrl),
|
|
||||||
])->subject(__('Verify Email Address'));
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -9,11 +9,10 @@ use App\Models\Concerns\HasUuids;
|
|||||||
use Database\Factories\MemberFactory;
|
use Database\Factories\MemberFactory;
|
||||||
use Illuminate\Database\Eloquent\Collection;
|
use Illuminate\Database\Eloquent\Collection;
|
||||||
use Illuminate\Database\Eloquent\Factories\HasFactory;
|
use Illuminate\Database\Eloquent\Factories\HasFactory;
|
||||||
use Illuminate\Database\Eloquent\Model;
|
|
||||||
use Illuminate\Database\Eloquent\Relations\BelongsTo;
|
use Illuminate\Database\Eloquent\Relations\BelongsTo;
|
||||||
use Illuminate\Database\Eloquent\Relations\HasMany;
|
use Illuminate\Database\Eloquent\Relations\HasMany;
|
||||||
use Illuminate\Database\Eloquent\Relations\Pivot;
|
|
||||||
use Illuminate\Support\Carbon;
|
use Illuminate\Support\Carbon;
|
||||||
|
use Laravel\Jetstream\Membership as JetstreamMembership;
|
||||||
use OwenIt\Auditing\Contracts\Auditable as AuditableContract;
|
use OwenIt\Auditing\Contracts\Auditable as AuditableContract;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -31,7 +30,7 @@ use OwenIt\Auditing\Contracts\Auditable as AuditableContract;
|
|||||||
*
|
*
|
||||||
* @method static MemberFactory factory()
|
* @method static MemberFactory factory()
|
||||||
*/
|
*/
|
||||||
class Member extends Pivot implements AuditableContract
|
class Member extends JetstreamMembership implements AuditableContract
|
||||||
{
|
{
|
||||||
use CustomAuditable;
|
use CustomAuditable;
|
||||||
|
|
||||||
|
|||||||
@@ -14,7 +14,6 @@ use App\Models\Concerns\HasUuids;
|
|||||||
use Database\Factories\OrganizationFactory;
|
use Database\Factories\OrganizationFactory;
|
||||||
use Illuminate\Database\Eloquent\Collection;
|
use Illuminate\Database\Eloquent\Collection;
|
||||||
use Illuminate\Database\Eloquent\Factories\HasFactory;
|
use Illuminate\Database\Eloquent\Factories\HasFactory;
|
||||||
use Illuminate\Database\Eloquent\Model;
|
|
||||||
use Illuminate\Database\Eloquent\ModelNotFoundException;
|
use Illuminate\Database\Eloquent\ModelNotFoundException;
|
||||||
use Illuminate\Database\Eloquent\Relations\BelongsTo;
|
use Illuminate\Database\Eloquent\Relations\BelongsTo;
|
||||||
use Illuminate\Database\Eloquent\Relations\BelongsToMany;
|
use Illuminate\Database\Eloquent\Relations\BelongsToMany;
|
||||||
@@ -22,6 +21,10 @@ use Illuminate\Database\Eloquent\Relations\HasMany;
|
|||||||
use Illuminate\Database\Eloquent\Relations\Pivot;
|
use Illuminate\Database\Eloquent\Relations\Pivot;
|
||||||
use Illuminate\Support\Carbon;
|
use Illuminate\Support\Carbon;
|
||||||
use Illuminate\Support\Str;
|
use Illuminate\Support\Str;
|
||||||
|
use Laravel\Jetstream\Events\TeamCreated;
|
||||||
|
use Laravel\Jetstream\Events\TeamDeleted;
|
||||||
|
use Laravel\Jetstream\Events\TeamUpdated;
|
||||||
|
use Laravel\Jetstream\Team as JetstreamTeam;
|
||||||
use OwenIt\Auditing\Contracts\Auditable as AuditableContract;
|
use OwenIt\Auditing\Contracts\Auditable as AuditableContract;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -33,13 +36,12 @@ use OwenIt\Auditing\Contracts\Auditable as AuditableContract;
|
|||||||
* @property string $user_id
|
* @property string $user_id
|
||||||
* @property bool $employees_can_see_billable_rates
|
* @property bool $employees_can_see_billable_rates
|
||||||
* @property bool $employees_can_manage_tasks
|
* @property bool $employees_can_manage_tasks
|
||||||
* @property bool $prevent_overlapping_time_entries
|
|
||||||
* @property User $owner
|
* @property User $owner
|
||||||
* @property Carbon|null $created_at
|
* @property Carbon|null $created_at
|
||||||
* @property Carbon|null $updated_at
|
* @property Carbon|null $updated_at
|
||||||
* @property Collection<int, User> $users
|
* @property Collection<int, User> $users
|
||||||
* @property Collection<int, User> $realUsers
|
* @property Collection<int, User> $realUsers
|
||||||
* @property-read Collection<int, OrganizationInvitation> $organizationInvitations
|
* @property-read Collection<int, OrganizationInvitation> $teamInvitations
|
||||||
* @property Member $membership
|
* @property Member $membership
|
||||||
* @property NumberFormat $number_format
|
* @property NumberFormat $number_format
|
||||||
* @property CurrencyFormat $currency_format
|
* @property CurrencyFormat $currency_format
|
||||||
@@ -47,9 +49,10 @@ use OwenIt\Auditing\Contracts\Auditable as AuditableContract;
|
|||||||
* @property IntervalFormat $interval_format
|
* @property IntervalFormat $interval_format
|
||||||
* @property TimeFormat $time_format
|
* @property TimeFormat $time_format
|
||||||
*
|
*
|
||||||
|
* @method HasMany<OrganizationInvitation, $this> teamInvitations()
|
||||||
* @method static OrganizationFactory factory()
|
* @method static OrganizationFactory factory()
|
||||||
*/
|
*/
|
||||||
class Organization extends Model implements AuditableContract
|
class Organization extends JetstreamTeam implements AuditableContract
|
||||||
{
|
{
|
||||||
use CustomAuditable;
|
use CustomAuditable;
|
||||||
|
|
||||||
@@ -87,6 +90,17 @@ class Organization extends Model implements AuditableContract
|
|||||||
'personal_team',
|
'personal_team',
|
||||||
];
|
];
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The event map for the model.
|
||||||
|
*
|
||||||
|
* @var array<string, class-string>
|
||||||
|
*/
|
||||||
|
protected $dispatchesEvents = [
|
||||||
|
'created' => TeamCreated::class,
|
||||||
|
'updated' => TeamUpdated::class,
|
||||||
|
'deleted' => TeamDeleted::class,
|
||||||
|
];
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* The model's default values for attributes.
|
* The model's default values for attributes.
|
||||||
*
|
*
|
||||||
@@ -95,6 +109,23 @@ class Organization extends Model implements AuditableContract
|
|||||||
protected $attributes = [
|
protected $attributes = [
|
||||||
];
|
];
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Get all the non-placeholder users of the organization including its owner.
|
||||||
|
*
|
||||||
|
* @return Collection<int, User>
|
||||||
|
*/
|
||||||
|
public function allRealUsers(): Collection
|
||||||
|
{
|
||||||
|
return $this->realUsers->merge([$this->owner]);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function hasRealUserWithEmail(string $email): bool
|
||||||
|
{
|
||||||
|
return $this->allRealUsers()->contains(function (User $user) use ($email): bool {
|
||||||
|
return $user->email === $email;
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get all the users that belong to the team.
|
* Get all the users that belong to the team.
|
||||||
*
|
*
|
||||||
@@ -140,21 +171,12 @@ class Organization extends Model implements AuditableContract
|
|||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @return HasMany<OrganizationInvitation, $this>
|
* This method prevents an unhandled exception when the ID is not a UUID.
|
||||||
*/
|
* Normally this can be fixed with a route pattern, but Jetstream does not use route model binding.
|
||||||
public function organizationInvitations(): HasMany
|
|
||||||
{
|
|
||||||
return $this->hasMany(OrganizationInvitation::class, 'organization_id');
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Find a model by its primary key or throw an exception.
|
|
||||||
*
|
*
|
||||||
* @param array<int, string> $columns
|
* @param array<string> $columns
|
||||||
*
|
|
||||||
* @throws ModelNotFoundException<Model>
|
|
||||||
*/
|
*/
|
||||||
public static function findOrFail(string $id, array $columns = ['*']): Model
|
public function findOrFail(string $id, array $columns = ['*']): \Laravel\Jetstream\Team
|
||||||
{
|
{
|
||||||
if (! Str::isUuid($id)) {
|
if (! Str::isUuid($id)) {
|
||||||
throw (new ModelNotFoundException)->setModel(
|
throw (new ModelNotFoundException)->setModel(
|
||||||
|
|||||||
@@ -8,9 +8,9 @@ use App\Models\Concerns\CustomAuditable;
|
|||||||
use App\Models\Concerns\HasUuids;
|
use App\Models\Concerns\HasUuids;
|
||||||
use Database\Factories\OrganizationInvitationFactory;
|
use Database\Factories\OrganizationInvitationFactory;
|
||||||
use Illuminate\Database\Eloquent\Factories\HasFactory;
|
use Illuminate\Database\Eloquent\Factories\HasFactory;
|
||||||
use Illuminate\Database\Eloquent\Model;
|
|
||||||
use Illuminate\Database\Eloquent\Relations\BelongsTo;
|
use Illuminate\Database\Eloquent\Relations\BelongsTo;
|
||||||
use Illuminate\Support\Carbon;
|
use Illuminate\Support\Carbon;
|
||||||
|
use Laravel\Jetstream\TeamInvitation as JetstreamTeamInvitation;
|
||||||
use OwenIt\Auditing\Contracts\Auditable as AuditableContract;
|
use OwenIt\Auditing\Contracts\Auditable as AuditableContract;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -18,14 +18,13 @@ use OwenIt\Auditing\Contracts\Auditable as AuditableContract;
|
|||||||
* @property string $email
|
* @property string $email
|
||||||
* @property string $role
|
* @property string $role
|
||||||
* @property string $organization_id
|
* @property string $organization_id
|
||||||
* @property Carbon|null $accepted_at
|
|
||||||
* @property Carbon|null $updated_at
|
* @property Carbon|null $updated_at
|
||||||
* @property Carbon|null $created_at
|
* @property Carbon|null $created_at
|
||||||
* @property-read Organization $organization
|
* @property-read Organization $organization
|
||||||
*
|
*
|
||||||
* @method static OrganizationInvitationFactory factory()
|
* @method static OrganizationInvitationFactory factory()
|
||||||
*/
|
*/
|
||||||
class OrganizationInvitation extends Model implements AuditableContract
|
class OrganizationInvitation extends JetstreamTeamInvitation implements AuditableContract
|
||||||
{
|
{
|
||||||
use CustomAuditable;
|
use CustomAuditable;
|
||||||
|
|
||||||
@@ -42,16 +41,14 @@ class OrganizationInvitation extends Model implements AuditableContract
|
|||||||
protected $table = 'organization_invitations';
|
protected $table = 'organization_invitations';
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get the attributes that should be cast.
|
* The attributes that are mass assignable.
|
||||||
*
|
*
|
||||||
* @return array<string, string>
|
* @var array<int, string>
|
||||||
*/
|
*/
|
||||||
public function casts(): array
|
protected $fillable = [
|
||||||
{
|
'email',
|
||||||
return [
|
'role',
|
||||||
'accepted_at' => 'datetime',
|
];
|
||||||
];
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get the organization that the invitation belongs to.
|
* Get the organization that the invitation belongs to.
|
||||||
|
|||||||
@@ -4,7 +4,6 @@ declare(strict_types=1);
|
|||||||
|
|
||||||
namespace App\Models;
|
namespace App\Models;
|
||||||
|
|
||||||
use App\Enums\Role;
|
|
||||||
use App\Enums\Weekday;
|
use App\Enums\Weekday;
|
||||||
use App\Models\Concerns\CustomAuditable;
|
use App\Models\Concerns\CustomAuditable;
|
||||||
use App\Models\Concerns\HasUuids;
|
use App\Models\Concerns\HasUuids;
|
||||||
@@ -26,6 +25,8 @@ use Illuminate\Notifications\Notifiable;
|
|||||||
use Illuminate\Support\Carbon;
|
use Illuminate\Support\Carbon;
|
||||||
use Illuminate\Support\Facades\Storage;
|
use Illuminate\Support\Facades\Storage;
|
||||||
use Laravel\Fortify\TwoFactorAuthenticatable;
|
use Laravel\Fortify\TwoFactorAuthenticatable;
|
||||||
|
use Laravel\Jetstream\HasProfilePhoto;
|
||||||
|
use Laravel\Jetstream\HasTeams;
|
||||||
use Laravel\Passport\AuthCode;
|
use Laravel\Passport\AuthCode;
|
||||||
use Laravel\Passport\Contracts\OAuthenticatable;
|
use Laravel\Passport\Contracts\OAuthenticatable;
|
||||||
use Laravel\Passport\HasApiTokens;
|
use Laravel\Passport\HasApiTokens;
|
||||||
@@ -35,7 +36,6 @@ use OwenIt\Auditing\Contracts\Auditable as AuditableContract;
|
|||||||
* @property string $id
|
* @property string $id
|
||||||
* @property string $name
|
* @property string $name
|
||||||
* @property string $email
|
* @property string $email
|
||||||
* @property string|null $pending_email
|
|
||||||
* @property Carbon|null $email_verified_at
|
* @property Carbon|null $email_verified_at
|
||||||
* @property string|null $password
|
* @property string|null $password
|
||||||
* @property string|null $two_factor_secret
|
* @property string|null $two_factor_secret
|
||||||
@@ -44,13 +44,13 @@ use OwenIt\Auditing\Contracts\Auditable as AuditableContract;
|
|||||||
* @property Weekday $week_start
|
* @property Weekday $week_start
|
||||||
* @property string|null $profile_photo_path
|
* @property string|null $profile_photo_path
|
||||||
* @property-read Organization|null $currentOrganization
|
* @property-read Organization|null $currentOrganization
|
||||||
|
* @property-read Organization|null $currentTeam
|
||||||
* @property-read string $profile_photo_url
|
* @property-read string $profile_photo_url
|
||||||
* @property-read Collection<int, Token> $tokens
|
* @property-read Collection<int, Token> $tokens
|
||||||
* @property Carbon|null $created_at
|
* @property Carbon|null $created_at
|
||||||
* @property Carbon|null $updated_at
|
* @property Carbon|null $updated_at
|
||||||
* @property string|null $current_team_id
|
* @property string|null $current_team_id
|
||||||
* @property Collection<int, Organization> $organizations
|
* @property Collection<int, Organization> $organizations
|
||||||
* @property Collection<int, Organization> $ownedOrganizations
|
|
||||||
* @property Collection<int, TimeEntry> $timeEntries
|
* @property Collection<int, TimeEntry> $timeEntries
|
||||||
* @property Member $membership
|
* @property Member $membership
|
||||||
*
|
*
|
||||||
@@ -68,6 +68,8 @@ class User extends Authenticatable implements AuditableContract, FilamentUser, M
|
|||||||
/** @use HasFactory<UserFactory> */
|
/** @use HasFactory<UserFactory> */
|
||||||
use HasFactory;
|
use HasFactory;
|
||||||
|
|
||||||
|
use HasProfilePhoto;
|
||||||
|
use HasTeams;
|
||||||
use HasUuids;
|
use HasUuids;
|
||||||
use Notifiable;
|
use Notifiable;
|
||||||
use TwoFactorAuthenticatable;
|
use TwoFactorAuthenticatable;
|
||||||
@@ -103,7 +105,6 @@ class User extends Authenticatable implements AuditableContract, FilamentUser, M
|
|||||||
protected $casts = [
|
protected $casts = [
|
||||||
'name' => 'string',
|
'name' => 'string',
|
||||||
'email' => 'string',
|
'email' => 'string',
|
||||||
'pending_email' => 'string',
|
|
||||||
'email_verified_at' => 'datetime',
|
'email_verified_at' => 'datetime',
|
||||||
'is_admin' => 'boolean',
|
'is_admin' => 'boolean',
|
||||||
'is_placeholder' => 'boolean',
|
'is_placeholder' => 'boolean',
|
||||||
@@ -128,39 +129,16 @@ class User extends Authenticatable implements AuditableContract, FilamentUser, M
|
|||||||
{
|
{
|
||||||
return Attribute::get(function (): string {
|
return Attribute::get(function (): string {
|
||||||
return $this->profile_photo_path
|
return $this->profile_photo_path
|
||||||
? Storage::disk(config('filesystems.public'))->url($this->profile_photo_path)
|
? Storage::disk($this->profilePhotoDisk())->url($this->profile_photo_path)
|
||||||
: $this->defaultProfilePhotoUrl();
|
: $this->defaultProfilePhotoUrl();
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
|
||||||
* Get the default profile photo URL if no profile photo has been uploaded.
|
|
||||||
*/
|
|
||||||
protected function defaultProfilePhotoUrl(): string
|
|
||||||
{
|
|
||||||
$name = trim(collect(explode(' ', $this->name))->map(function ($segment) {
|
|
||||||
return mb_substr($segment, 0, 1);
|
|
||||||
})->join(' '));
|
|
||||||
|
|
||||||
return 'https://ui-avatars.com/api/?name='.urlencode($name).'&color=7F9CF5&background=EBF4FF';
|
|
||||||
}
|
|
||||||
|
|
||||||
public function canAccessPanel(Panel $panel): bool
|
public function canAccessPanel(Panel $panel): bool
|
||||||
{
|
{
|
||||||
return in_array($this->email, config('auth.super_admins', []), true) && $this->hasVerifiedEmail();
|
return in_array($this->email, config('auth.super_admins', []), true) && $this->hasVerifiedEmail();
|
||||||
}
|
}
|
||||||
|
|
||||||
public function isMemberOfOrganization(Organization $organization): bool
|
|
||||||
{
|
|
||||||
if ($this->relationLoaded('organizations')) {
|
|
||||||
return $this->organizations->contains(function (Organization $o) use ($organization): bool {
|
|
||||||
return $o->getKey() === $organization->getKey();
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
return $this->organizations()->whereKey($organization->getKey())->exists();
|
|
||||||
}
|
|
||||||
|
|
||||||
public function canBeImpersonated(): bool
|
public function canBeImpersonated(): bool
|
||||||
{
|
{
|
||||||
return $this->is_placeholder === false;
|
return $this->is_placeholder === false;
|
||||||
@@ -181,14 +159,6 @@ class User extends Authenticatable implements AuditableContract, FilamentUser, M
|
|||||||
->as('membership');
|
->as('membership');
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
|
||||||
* @return BelongsToMany<Organization, $this, Pivot, 'membership'>
|
|
||||||
*/
|
|
||||||
public function ownedOrganizations(): BelongsToMany
|
|
||||||
{
|
|
||||||
return $this->organizations()->wherePivot('role', Role::Owner->value);
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @return HasMany<TimeEntry, $this>
|
* @return HasMany<TimeEntry, $this>
|
||||||
*/
|
*/
|
||||||
@@ -243,8 +213,12 @@ class User extends Authenticatable implements AuditableContract, FilamentUser, M
|
|||||||
*/
|
*/
|
||||||
public function scopeBelongsToOrganization(Builder $builder, Organization $organization): Builder
|
public function scopeBelongsToOrganization(Builder $builder, Organization $organization): Builder
|
||||||
{
|
{
|
||||||
return $builder->whereHas('organizations', function (Builder $query) use ($organization): void {
|
return $builder->where(function (Builder $builder) use ($organization): Builder {
|
||||||
$query->whereKey($organization->getKey());
|
return $builder->whereHas('organizations', function (Builder $query) use ($organization): void {
|
||||||
|
$query->whereKey($organization->getKey());
|
||||||
|
})->orWhereHas('ownedTeams', function (Builder $query) use ($organization): void {
|
||||||
|
$query->whereKey($organization->getKey());
|
||||||
|
});
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
114
app/Policies/OrganizationPolicy.php
Normal file
114
app/Policies/OrganizationPolicy.php
Normal file
@@ -0,0 +1,114 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Policies;
|
||||||
|
|
||||||
|
use App\Models\Organization;
|
||||||
|
use App\Models\User;
|
||||||
|
use App\Service\PermissionStore;
|
||||||
|
use Filament\Facades\Filament;
|
||||||
|
use Illuminate\Auth\Access\HandlesAuthorization;
|
||||||
|
|
||||||
|
class OrganizationPolicy
|
||||||
|
{
|
||||||
|
use HandlesAuthorization;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Determine whether the user can view any models.
|
||||||
|
*/
|
||||||
|
public function viewAny(User $user): bool
|
||||||
|
{
|
||||||
|
if (Filament::isServing()) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Determine whether the user can view the model.
|
||||||
|
*/
|
||||||
|
public function view(User $user, Organization $organization): bool
|
||||||
|
{
|
||||||
|
if (Filament::isServing()) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
return $user->belongsToTeam($organization);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Determine whether the user can create models.
|
||||||
|
*/
|
||||||
|
public function create(User $user): bool
|
||||||
|
{
|
||||||
|
if (Filament::isServing()) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Determine whether the user can update the model.
|
||||||
|
*/
|
||||||
|
public function update(User $user, Organization $organization): bool
|
||||||
|
{
|
||||||
|
if (Filament::isServing()) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
return app(PermissionStore::class)->userHas($organization, $user, 'organizations:update');
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Determine whether the user can add team members.
|
||||||
|
*/
|
||||||
|
public function addTeamMember(User $user, Organization $organization): bool
|
||||||
|
{
|
||||||
|
if (Filament::isServing()) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Determine whether the user can update team member permissions.
|
||||||
|
*/
|
||||||
|
public function updateTeamMember(User $user, Organization $organization): bool
|
||||||
|
{
|
||||||
|
if (Filament::isServing()) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Note: since this policy is only used for jetstream endpoints, we can return false here
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Determine whether the user can remove team members.
|
||||||
|
*/
|
||||||
|
public function removeTeamMember(User $user, Organization $organization): bool
|
||||||
|
{
|
||||||
|
if (Filament::isServing()) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Note: since this policy is only used for jetstream endpoints that are no longer in use, we can return false here
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Determine whether the user can delete the model.
|
||||||
|
*/
|
||||||
|
public function delete(User $user, Organization $organization): bool
|
||||||
|
{
|
||||||
|
if (Filament::isServing()) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
return $user->ownsTeam($organization);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -4,11 +4,14 @@ declare(strict_types=1);
|
|||||||
|
|
||||||
namespace App\Providers;
|
namespace App\Providers;
|
||||||
|
|
||||||
|
use App\Models\Organization;
|
||||||
use App\Models\Passport\AuthCode;
|
use App\Models\Passport\AuthCode;
|
||||||
use App\Models\Passport\Client;
|
use App\Models\Passport\Client;
|
||||||
use App\Models\Passport\RefreshToken;
|
use App\Models\Passport\RefreshToken;
|
||||||
use App\Models\Passport\Token;
|
use App\Models\Passport\Token;
|
||||||
|
use App\Policies\OrganizationPolicy;
|
||||||
use Illuminate\Foundation\Support\Providers\AuthServiceProvider as ServiceProvider;
|
use Illuminate\Foundation\Support\Providers\AuthServiceProvider as ServiceProvider;
|
||||||
|
use Laravel\Jetstream\Jetstream;
|
||||||
use Laravel\Passport\Passport;
|
use Laravel\Passport\Passport;
|
||||||
|
|
||||||
class AuthServiceProvider extends ServiceProvider
|
class AuthServiceProvider extends ServiceProvider
|
||||||
@@ -19,6 +22,7 @@ class AuthServiceProvider extends ServiceProvider
|
|||||||
* @var array<class-string, class-string>
|
* @var array<class-string, class-string>
|
||||||
*/
|
*/
|
||||||
protected $policies = [
|
protected $policies = [
|
||||||
|
Organization::class => OrganizationPolicy::class,
|
||||||
];
|
];
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -52,5 +56,11 @@ class AuthServiceProvider extends ServiceProvider
|
|||||||
// Passport::tokensExpireIn(now()->addDays(15));
|
// Passport::tokensExpireIn(now()->addDays(15));
|
||||||
// Passport::refreshTokensExpireIn(now()->addDays(30));
|
// Passport::refreshTokensExpireIn(now()->addDays(30));
|
||||||
Passport::personalAccessTokensExpireIn(now()->addMonths(12));
|
Passport::personalAccessTokensExpireIn(now()->addMonths(12));
|
||||||
|
|
||||||
|
// same as passport default above
|
||||||
|
Jetstream::defaultApiTokenPermissions(['read']);
|
||||||
|
|
||||||
|
// use passport scopes for jetstream token permissions
|
||||||
|
Jetstream::permissions(Passport::scopeIds());
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -4,9 +4,11 @@ declare(strict_types=1);
|
|||||||
|
|
||||||
namespace App\Providers;
|
namespace App\Providers;
|
||||||
|
|
||||||
|
use App\Listeners\RemovePlaceholder;
|
||||||
use Illuminate\Auth\Events\Registered;
|
use Illuminate\Auth\Events\Registered;
|
||||||
use Illuminate\Auth\Listeners\SendEmailVerificationNotification;
|
use Illuminate\Auth\Listeners\SendEmailVerificationNotification;
|
||||||
use Illuminate\Foundation\Support\Providers\EventServiceProvider as ServiceProvider;
|
use Illuminate\Foundation\Support\Providers\EventServiceProvider as ServiceProvider;
|
||||||
|
use Laravel\Jetstream\Events\TeamMemberAdded;
|
||||||
|
|
||||||
class EventServiceProvider extends ServiceProvider
|
class EventServiceProvider extends ServiceProvider
|
||||||
{
|
{
|
||||||
@@ -19,6 +21,9 @@ class EventServiceProvider extends ServiceProvider
|
|||||||
Registered::class => [
|
Registered::class => [
|
||||||
SendEmailVerificationNotification::class,
|
SendEmailVerificationNotification::class,
|
||||||
],
|
],
|
||||||
|
TeamMemberAdded::class => [
|
||||||
|
RemovePlaceholder::class,
|
||||||
|
],
|
||||||
];
|
];
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -15,13 +15,11 @@ use Illuminate\Cache\RateLimiting\Limit;
|
|||||||
use Illuminate\Http\Request;
|
use Illuminate\Http\Request;
|
||||||
use Illuminate\Support\Facades\Hash;
|
use Illuminate\Support\Facades\Hash;
|
||||||
use Illuminate\Support\Facades\RateLimiter;
|
use Illuminate\Support\Facades\RateLimiter;
|
||||||
use Illuminate\Support\Facades\Route;
|
|
||||||
use Illuminate\Support\ServiceProvider;
|
use Illuminate\Support\ServiceProvider;
|
||||||
use Illuminate\Support\Str;
|
use Illuminate\Support\Str;
|
||||||
use Inertia\Inertia;
|
|
||||||
use Laravel\Fortify\Contracts\LoginResponse as LoginResponseContract;
|
|
||||||
use Laravel\Fortify\Contracts\TwoFactorLoginResponse;
|
use Laravel\Fortify\Contracts\TwoFactorLoginResponse;
|
||||||
use Laravel\Fortify\Fortify;
|
use Laravel\Fortify\Fortify;
|
||||||
|
use Laravel\Fortify\Http\Responses\LoginResponse;
|
||||||
|
|
||||||
class FortifyServiceProvider extends ServiceProvider
|
class FortifyServiceProvider extends ServiceProvider
|
||||||
{
|
{
|
||||||
@@ -43,48 +41,6 @@ class FortifyServiceProvider extends ServiceProvider
|
|||||||
Fortify::updateUserPasswordsUsing(UpdateUserPassword::class);
|
Fortify::updateUserPasswordsUsing(UpdateUserPassword::class);
|
||||||
Fortify::resetUserPasswordsUsing(ResetUserPassword::class);
|
Fortify::resetUserPasswordsUsing(ResetUserPassword::class);
|
||||||
|
|
||||||
Fortify::registerView(function () {
|
|
||||||
return Inertia::render('Auth/Register', [
|
|
||||||
'terms_url' => config('auth.terms_url'),
|
|
||||||
'privacy_policy_url' => config('auth.privacy_policy_url'),
|
|
||||||
'newsletter_consent' => config('auth.newsletter_consent'),
|
|
||||||
]);
|
|
||||||
});
|
|
||||||
|
|
||||||
Fortify::loginView(function () {
|
|
||||||
return Inertia::render('Auth/Login', [
|
|
||||||
'canResetPassword' => Route::has('password.request'),
|
|
||||||
'status' => session('status'),
|
|
||||||
]);
|
|
||||||
});
|
|
||||||
|
|
||||||
Fortify::requestPasswordResetLinkView(function () {
|
|
||||||
return Inertia::render('Auth/ForgotPassword', [
|
|
||||||
'status' => session('status'),
|
|
||||||
]);
|
|
||||||
});
|
|
||||||
|
|
||||||
Fortify::resetPasswordView(function (Request $request) {
|
|
||||||
return Inertia::render('Auth/ResetPassword', [
|
|
||||||
'email' => $request->input('email'),
|
|
||||||
'token' => $request->route('token'),
|
|
||||||
]);
|
|
||||||
});
|
|
||||||
|
|
||||||
Fortify::verifyEmailView(function () {
|
|
||||||
return Inertia::render('Auth/VerifyEmail', [
|
|
||||||
'status' => session('status'),
|
|
||||||
]);
|
|
||||||
});
|
|
||||||
|
|
||||||
Fortify::twoFactorChallengeView(function () {
|
|
||||||
return Inertia::render('Auth/TwoFactorChallenge');
|
|
||||||
});
|
|
||||||
|
|
||||||
Fortify::confirmPasswordView(function () {
|
|
||||||
return Inertia::render('Auth/ConfirmPassword');
|
|
||||||
});
|
|
||||||
|
|
||||||
Fortify::authenticateUsing(function (Request $request): ?User {
|
Fortify::authenticateUsing(function (Request $request): ?User {
|
||||||
/** @var User|null $user */
|
/** @var User|null $user */
|
||||||
$user = User::query()
|
$user = User::query()
|
||||||
@@ -109,7 +65,7 @@ class FortifyServiceProvider extends ServiceProvider
|
|||||||
return Limit::perMinute(5)->by($request->session()->get('login.id'));
|
return Limit::perMinute(5)->by($request->session()->get('login.id'));
|
||||||
});
|
});
|
||||||
|
|
||||||
$this->app->instance(LoginResponseContract::class, new CustomLoginResponse);
|
$this->app->instance(LoginResponse::class, new CustomLoginResponse);
|
||||||
$this->app->instance(TwoFactorLoginResponse::class, new CustomTwoFactorLoginResponse);
|
$this->app->instance(TwoFactorLoginResponse::class, new CustomTwoFactorLoginResponse);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
337
app/Providers/JetstreamServiceProvider.php
Normal file
337
app/Providers/JetstreamServiceProvider.php
Normal file
@@ -0,0 +1,337 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Providers;
|
||||||
|
|
||||||
|
use App\Actions\Jetstream\AddOrganizationMember;
|
||||||
|
use App\Actions\Jetstream\CreateOrganization;
|
||||||
|
use App\Actions\Jetstream\DeleteOrganization;
|
||||||
|
use App\Actions\Jetstream\DeleteUser;
|
||||||
|
use App\Actions\Jetstream\InviteOrganizationMember;
|
||||||
|
use App\Actions\Jetstream\RemoveOrganizationMember;
|
||||||
|
use App\Actions\Jetstream\UpdateMemberRole;
|
||||||
|
use App\Actions\Jetstream\UpdateOrganization;
|
||||||
|
use App\Actions\Jetstream\ValidateOrganizationDeletion;
|
||||||
|
use App\Enums\Role;
|
||||||
|
use App\Enums\Weekday;
|
||||||
|
use App\Models\Member;
|
||||||
|
use App\Models\Organization;
|
||||||
|
use App\Models\OrganizationInvitation;
|
||||||
|
use App\Models\User;
|
||||||
|
use App\Service\TimezoneService;
|
||||||
|
use Brick\Money\Currency;
|
||||||
|
use Brick\Money\ISOCurrencyProvider;
|
||||||
|
use Illuminate\Http\Request;
|
||||||
|
use Illuminate\Support\Facades\Gate;
|
||||||
|
use Illuminate\Support\ServiceProvider;
|
||||||
|
use Inertia\Inertia;
|
||||||
|
use Laravel\Fortify\Fortify;
|
||||||
|
use Laravel\Jetstream\Actions\UpdateTeamMemberRole;
|
||||||
|
use Laravel\Jetstream\Actions\ValidateTeamDeletion;
|
||||||
|
use Laravel\Jetstream\Jetstream;
|
||||||
|
|
||||||
|
class JetstreamServiceProvider extends ServiceProvider
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* Register any application services.
|
||||||
|
*/
|
||||||
|
public function register(): void
|
||||||
|
{
|
||||||
|
//
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Bootstrap any application services.
|
||||||
|
*/
|
||||||
|
public function boot(): void
|
||||||
|
{
|
||||||
|
$this->configurePermissions();
|
||||||
|
|
||||||
|
Jetstream::createTeamsUsing(CreateOrganization::class);
|
||||||
|
Jetstream::updateTeamNamesUsing(UpdateOrganization::class);
|
||||||
|
Jetstream::addTeamMembersUsing(AddOrganizationMember::class);
|
||||||
|
Jetstream::inviteTeamMembersUsing(InviteOrganizationMember::class);
|
||||||
|
Jetstream::removeTeamMembersUsing(RemoveOrganizationMember::class);
|
||||||
|
Jetstream::deleteTeamsUsing(DeleteOrganization::class);
|
||||||
|
Jetstream::deleteUsersUsing(DeleteUser::class);
|
||||||
|
Jetstream::useTeamModel(Organization::class);
|
||||||
|
Jetstream::useMembershipModel(Member::class);
|
||||||
|
Jetstream::useTeamInvitationModel(OrganizationInvitation::class);
|
||||||
|
app()->singleton(UpdateTeamMemberRole::class, UpdateMemberRole::class);
|
||||||
|
app()->singleton(ValidateTeamDeletion::class, ValidateOrganizationDeletion::class);
|
||||||
|
Fortify::registerView(function () {
|
||||||
|
return Inertia::render('Auth/Register', [
|
||||||
|
'terms_url' => config('auth.terms_url'),
|
||||||
|
'privacy_policy_url' => config('auth.privacy_policy_url'),
|
||||||
|
'newsletter_consent' => config('auth.newsletter_consent'),
|
||||||
|
]);
|
||||||
|
});
|
||||||
|
Gate::define('removeTeamMember', function (User $user, Organization $team) {
|
||||||
|
return false;
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Configure the roles and permissions that are available within the application.
|
||||||
|
*/
|
||||||
|
protected function configurePermissions(): void
|
||||||
|
{
|
||||||
|
Jetstream::defaultApiTokenPermissions([]);
|
||||||
|
|
||||||
|
Jetstream::role(Role::Owner->value, 'Owner', [
|
||||||
|
'charts:view:own',
|
||||||
|
'charts:view:all',
|
||||||
|
'projects:view',
|
||||||
|
'projects:view:all',
|
||||||
|
'projects:create',
|
||||||
|
'projects:update',
|
||||||
|
'projects:delete',
|
||||||
|
'project-members:view',
|
||||||
|
'project-members:create',
|
||||||
|
'project-members:update',
|
||||||
|
'project-members:delete',
|
||||||
|
'tasks:view',
|
||||||
|
'tasks:view:all',
|
||||||
|
'tasks:create',
|
||||||
|
'tasks:create:all',
|
||||||
|
'tasks:update',
|
||||||
|
'tasks:update:all',
|
||||||
|
'tasks:delete',
|
||||||
|
'tasks:delete:all',
|
||||||
|
'time-entries:view:all',
|
||||||
|
'time-entries:create:all',
|
||||||
|
'time-entries:update:all',
|
||||||
|
'time-entries:delete:all',
|
||||||
|
'time-entries:view:own',
|
||||||
|
'time-entries:create:own',
|
||||||
|
'time-entries:update:own',
|
||||||
|
'time-entries:delete:own',
|
||||||
|
'tags:view',
|
||||||
|
'tags:create',
|
||||||
|
'tags:update',
|
||||||
|
'tags:delete',
|
||||||
|
'clients:view',
|
||||||
|
'clients:view:all',
|
||||||
|
'clients:create',
|
||||||
|
'clients:update',
|
||||||
|
'clients:delete',
|
||||||
|
'organizations:view',
|
||||||
|
'organizations:update',
|
||||||
|
'organizations:delete',
|
||||||
|
'import',
|
||||||
|
'export',
|
||||||
|
'invitations:view',
|
||||||
|
'invitations:create',
|
||||||
|
'invitations:resend',
|
||||||
|
'invitations:remove',
|
||||||
|
'members:view',
|
||||||
|
'members:invite-placeholder',
|
||||||
|
'members:change-ownership',
|
||||||
|
'members:make-placeholder',
|
||||||
|
'members:merge-into',
|
||||||
|
'members:update',
|
||||||
|
'members:delete',
|
||||||
|
'billing',
|
||||||
|
'reports:view',
|
||||||
|
'reports:create',
|
||||||
|
'reports:update',
|
||||||
|
'reports:delete',
|
||||||
|
'invoices:view',
|
||||||
|
'invoices:create',
|
||||||
|
'invoices:update',
|
||||||
|
'invoices:download',
|
||||||
|
'invoices:delete',
|
||||||
|
'invoice-settings:view',
|
||||||
|
'invoice-settings:update',
|
||||||
|
])->description('Owner users can perform any action. There is only one owner per organization.');
|
||||||
|
|
||||||
|
Jetstream::role(Role::Admin->value, 'Administrator', [
|
||||||
|
'charts:view:own',
|
||||||
|
'charts:view:all',
|
||||||
|
'projects:view',
|
||||||
|
'projects:view:all',
|
||||||
|
'projects:create',
|
||||||
|
'projects:update',
|
||||||
|
'projects:delete',
|
||||||
|
'project-members:view',
|
||||||
|
'project-members:create',
|
||||||
|
'project-members:update',
|
||||||
|
'project-members:delete',
|
||||||
|
'tasks:view',
|
||||||
|
'tasks:view:all',
|
||||||
|
'tasks:create',
|
||||||
|
'tasks:create:all',
|
||||||
|
'tasks:update',
|
||||||
|
'tasks:update:all',
|
||||||
|
'tasks:delete',
|
||||||
|
'tasks:delete:all',
|
||||||
|
'time-entries:view:all',
|
||||||
|
'time-entries:create:all',
|
||||||
|
'time-entries:update:all',
|
||||||
|
'time-entries:delete:all',
|
||||||
|
'time-entries:view:own',
|
||||||
|
'time-entries:create:own',
|
||||||
|
'time-entries:update:own',
|
||||||
|
'time-entries:delete:own',
|
||||||
|
'tags:view',
|
||||||
|
'tags:create',
|
||||||
|
'tags:update',
|
||||||
|
'tags:delete',
|
||||||
|
'clients:view',
|
||||||
|
'clients:view:all',
|
||||||
|
'clients:create',
|
||||||
|
'clients:update',
|
||||||
|
'clients:delete',
|
||||||
|
'organizations:view',
|
||||||
|
'organizations:update',
|
||||||
|
'import',
|
||||||
|
'export',
|
||||||
|
'invitations:view',
|
||||||
|
'invitations:create',
|
||||||
|
'invitations:resend',
|
||||||
|
'invitations:remove',
|
||||||
|
'members:view',
|
||||||
|
'members:invite-placeholder',
|
||||||
|
'members:make-placeholder',
|
||||||
|
'members:merge-into',
|
||||||
|
'members:delete',
|
||||||
|
'members:update',
|
||||||
|
'reports:view',
|
||||||
|
'reports:create',
|
||||||
|
'reports:update',
|
||||||
|
'reports:delete',
|
||||||
|
'invoices:view',
|
||||||
|
'invoices:create',
|
||||||
|
'invoices:update',
|
||||||
|
'invoices:download',
|
||||||
|
'invoices:delete',
|
||||||
|
'invoice-settings:view',
|
||||||
|
'invoice-settings:update',
|
||||||
|
])->description('Administrator users can perform any action, except accessing the billing dashboard.');
|
||||||
|
|
||||||
|
Jetstream::role(Role::Manager->value, 'Manager', [
|
||||||
|
'charts:view:own',
|
||||||
|
'charts:view:all',
|
||||||
|
'projects:view',
|
||||||
|
'projects:view:all',
|
||||||
|
'projects:create',
|
||||||
|
'projects:update',
|
||||||
|
'projects:delete',
|
||||||
|
'project-members:view',
|
||||||
|
'project-members:create',
|
||||||
|
'project-members:update',
|
||||||
|
'project-members:delete',
|
||||||
|
'tasks:view',
|
||||||
|
'tasks:view:all',
|
||||||
|
'tasks:create',
|
||||||
|
'tasks:create:all',
|
||||||
|
'tasks:update',
|
||||||
|
'tasks:update:all',
|
||||||
|
'tasks:delete',
|
||||||
|
'tasks:delete:all',
|
||||||
|
'time-entries:view:all',
|
||||||
|
'time-entries:create:all',
|
||||||
|
'time-entries:update:all',
|
||||||
|
'time-entries:delete:all',
|
||||||
|
'time-entries:view:own',
|
||||||
|
'time-entries:create:own',
|
||||||
|
'time-entries:update:own',
|
||||||
|
'time-entries:delete:own',
|
||||||
|
'tags:view',
|
||||||
|
'tags:create',
|
||||||
|
'tags:update',
|
||||||
|
'tags:delete',
|
||||||
|
'clients:view',
|
||||||
|
'clients:view:all',
|
||||||
|
'clients:create',
|
||||||
|
'clients:update',
|
||||||
|
'clients:delete',
|
||||||
|
'organizations:view',
|
||||||
|
'invitations:view',
|
||||||
|
'members:view',
|
||||||
|
'reports:view',
|
||||||
|
'reports:create',
|
||||||
|
'reports:update',
|
||||||
|
'reports:delete',
|
||||||
|
'invoices:view',
|
||||||
|
'invoices:create',
|
||||||
|
'invoices:update',
|
||||||
|
'invoices:download',
|
||||||
|
'invoices:delete',
|
||||||
|
'invoice-settings:view',
|
||||||
|
'invoice-settings:update',
|
||||||
|
])->description('Managers have full access to all projects, time entries, ect. but cannot manage the organization (add/remove member, edit the organization, ect.).');
|
||||||
|
|
||||||
|
Jetstream::role(Role::Employee->value, 'Employee', [
|
||||||
|
'charts:view:own',
|
||||||
|
'projects:view',
|
||||||
|
'tags:view',
|
||||||
|
'tasks:view',
|
||||||
|
'clients:view',
|
||||||
|
'time-entries:view:own',
|
||||||
|
'time-entries:create:own',
|
||||||
|
'time-entries:update:own',
|
||||||
|
'time-entries:delete:own',
|
||||||
|
'organizations:view',
|
||||||
|
])->description('Employees have the ability to read, create, and update their own time entries, they can see the projects that they are members of and the clients they are assigned to.');
|
||||||
|
|
||||||
|
Jetstream::role(Role::Placeholder->value, 'Placeholder', [
|
||||||
|
])->description('Placeholders are used for importing data. They cannot log in and have no permissions.');
|
||||||
|
|
||||||
|
Jetstream::inertia()
|
||||||
|
->whenRendering(
|
||||||
|
'Profile/Show',
|
||||||
|
function (Request $request, array $data): array {
|
||||||
|
return array_merge($data, [
|
||||||
|
'timezones' => $this->app->get(TimezoneService::class)->getSelectOptions(),
|
||||||
|
'weekdays' => Weekday::toSelectArray(),
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
)
|
||||||
|
->whenRendering(
|
||||||
|
'Teams/Show',
|
||||||
|
function (Request $request, array $data): array {
|
||||||
|
/** @var Organization $teamModel */
|
||||||
|
$teamModel = $data['team'];
|
||||||
|
$owner = $teamModel->owner;
|
||||||
|
|
||||||
|
return array_merge($data, [
|
||||||
|
'team' => [
|
||||||
|
'id' => $teamModel->getKey(),
|
||||||
|
'name' => $teamModel->name,
|
||||||
|
'currency' => $teamModel->currency,
|
||||||
|
'owner' => [
|
||||||
|
'id' => $owner->getKey(),
|
||||||
|
'name' => $owner->name,
|
||||||
|
'email' => $owner->email,
|
||||||
|
'profile_photo_url' => $owner->profile_photo_url,
|
||||||
|
],
|
||||||
|
'users' => $teamModel->users->map(function (User $user): array {
|
||||||
|
return [
|
||||||
|
'id' => $user->getKey(),
|
||||||
|
'name' => $user->name,
|
||||||
|
'email' => $user->email,
|
||||||
|
'profile_photo_url' => $user->profile_photo_url,
|
||||||
|
'membership' => [
|
||||||
|
'id' => $user->membership->id,
|
||||||
|
'role' => $user->membership->role,
|
||||||
|
],
|
||||||
|
];
|
||||||
|
}),
|
||||||
|
'team_invitations' => $teamModel->teamInvitations->map(function (OrganizationInvitation $invitation): array {
|
||||||
|
return [
|
||||||
|
'id' => $invitation->getKey(),
|
||||||
|
'email' => $invitation->email,
|
||||||
|
'role' => $invitation->role,
|
||||||
|
];
|
||||||
|
}),
|
||||||
|
],
|
||||||
|
'currencies' => array_map(function (Currency $currency): string {
|
||||||
|
return $currency->getName();
|
||||||
|
}, ISOCurrencyProvider::getInstance()->getAvailableCurrencies()),
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -1,45 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace App\Rules;
|
|
||||||
|
|
||||||
use App\Support\Base64File;
|
|
||||||
use Closure;
|
|
||||||
use Illuminate\Contracts\Validation\ValidationRule;
|
|
||||||
use Illuminate\Translation\PotentiallyTranslatedString;
|
|
||||||
|
|
||||||
class Base64ImageRule implements ValidationRule
|
|
||||||
{
|
|
||||||
private const array ALLOWED_MIME_TYPES = [
|
|
||||||
'image/jpeg',
|
|
||||||
'image/png',
|
|
||||||
];
|
|
||||||
|
|
||||||
private const int MAX_BYTES = 1024 * 1024;
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Run the validation rule.
|
|
||||||
*
|
|
||||||
* @param Closure(string): PotentiallyTranslatedString $fail
|
|
||||||
*/
|
|
||||||
public function validate(string $attribute, mixed $value, Closure $fail): void
|
|
||||||
{
|
|
||||||
if (! is_string($value)) {
|
|
||||||
$fail(__('validation.string'));
|
|
||||||
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
$file = Base64File::decode($value);
|
|
||||||
if ($file === null || ! in_array($file['mime_type'], self::ALLOWED_MIME_TYPES, true)) {
|
|
||||||
$fail(__('validation.mimes', ['values' => 'jpg, png']));
|
|
||||||
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (strlen($file['data']) > self::MAX_BYTES) {
|
|
||||||
$fail(__('validation.max.file', ['max' => (string) (self::MAX_BYTES / 1024)]));
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -173,7 +173,7 @@ class DeletionService
|
|||||||
$user->authCodes()->delete();
|
$user->authCodes()->delete();
|
||||||
|
|
||||||
// Note: Since the deletion of the profile photo is not reversible via a database rollback this needs to be done last
|
// Note: Since the deletion of the profile photo is not reversible via a database rollback this needs to be done last
|
||||||
$this->userService->deleteProfilePhoto($user);
|
$user->deleteProfilePhoto();
|
||||||
|
|
||||||
$user->delete();
|
$user->delete();
|
||||||
|
|
||||||
|
|||||||
@@ -1,179 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
declare(strict_types=1);
|
|
||||||
|
|
||||||
namespace App\Service\Dto;
|
|
||||||
|
|
||||||
use Closure;
|
|
||||||
use Detection\MobileDetect;
|
|
||||||
|
|
||||||
/**
|
|
||||||
* @copyright Originally created by Jens Segers: https://github.com/jenssegers/agent
|
|
||||||
*/
|
|
||||||
class UserAgentDto extends MobileDetect
|
|
||||||
{
|
|
||||||
/**
|
|
||||||
* List of additional operating systems.
|
|
||||||
*
|
|
||||||
* @var array<string, string>
|
|
||||||
*/
|
|
||||||
protected static array $additionalOperatingSystems = [
|
|
||||||
'Windows' => 'Windows',
|
|
||||||
'Windows NT' => 'Windows NT',
|
|
||||||
'OS X' => 'Mac OS X',
|
|
||||||
'Debian' => 'Debian',
|
|
||||||
'Ubuntu' => 'Ubuntu',
|
|
||||||
'Macintosh' => 'PPC',
|
|
||||||
'OpenBSD' => 'OpenBSD',
|
|
||||||
'Linux' => 'Linux',
|
|
||||||
'ChromeOS' => 'CrOS',
|
|
||||||
];
|
|
||||||
|
|
||||||
/**
|
|
||||||
* List of additional browsers.
|
|
||||||
*
|
|
||||||
* @var array<string, string>
|
|
||||||
*/
|
|
||||||
protected static array $additionalBrowsers = [
|
|
||||||
'Opera Mini' => 'Opera Mini',
|
|
||||||
'Opera' => 'Opera|OPR',
|
|
||||||
'Edge' => 'Edge|Edg',
|
|
||||||
'Coc Coc' => 'coc_coc_browser',
|
|
||||||
'UCBrowser' => 'UCBrowser',
|
|
||||||
'Vivaldi' => 'Vivaldi',
|
|
||||||
'Chrome' => 'Chrome',
|
|
||||||
'Firefox' => 'Firefox',
|
|
||||||
'Safari' => 'Safari',
|
|
||||||
'IE' => 'MSIE|IEMobile|MSIEMobile|Trident/[.0-9]+',
|
|
||||||
'Netscape' => 'Netscape',
|
|
||||||
'Mozilla' => 'Mozilla',
|
|
||||||
'WeChat' => 'MicroMessenger',
|
|
||||||
];
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Key value store for resolved strings.
|
|
||||||
*
|
|
||||||
* @var array<string, mixed>
|
|
||||||
*/
|
|
||||||
protected array $store = [];
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Get the platform name from the User Agent.
|
|
||||||
*/
|
|
||||||
public function platform(): ?string
|
|
||||||
{
|
|
||||||
return $this->retrieveUsingCacheOrResolve('platform', function () {
|
|
||||||
return $this->findDetectionRulesAgainstUserAgent(
|
|
||||||
$this->mergeRules(MobileDetect::getOperatingSystems(), static::$additionalOperatingSystems)
|
|
||||||
);
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Get the browser name from the User Agent.
|
|
||||||
*/
|
|
||||||
public function browser(): ?string
|
|
||||||
{
|
|
||||||
return $this->retrieveUsingCacheOrResolve('browser', function (): ?string {
|
|
||||||
return $this->findDetectionRulesAgainstUserAgent(
|
|
||||||
$this->mergeRules(static::$additionalBrowsers, MobileDetect::getBrowsers())
|
|
||||||
);
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Determine if the device is a desktop computer.
|
|
||||||
*/
|
|
||||||
public function isDesktop(): bool
|
|
||||||
{
|
|
||||||
return $this->retrieveUsingCacheOrResolve('desktop', function (): bool {
|
|
||||||
// Check specifically for cloudfront headers if the useragent === 'Amazon CloudFront'
|
|
||||||
if (
|
|
||||||
$this->getUserAgent() === static::$cloudFrontUA
|
|
||||||
&& $this->getHttpHeader('HTTP_CLOUDFRONT_IS_DESKTOP_VIEWER') === 'true'
|
|
||||||
) {
|
|
||||||
return true;
|
|
||||||
}
|
|
||||||
|
|
||||||
return ! $this->isMobile() && ! $this->isTablet();
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Match a detection rule and return the matched key.
|
|
||||||
*
|
|
||||||
* @param array<string, string|list<string>> $rules
|
|
||||||
*/
|
|
||||||
protected function findDetectionRulesAgainstUserAgent(array $rules): ?string
|
|
||||||
{
|
|
||||||
$userAgent = $this->getUserAgent();
|
|
||||||
|
|
||||||
foreach ($rules as $key => $regex) {
|
|
||||||
if (is_array($regex)) {
|
|
||||||
$regex = implode('|', $regex);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (empty($regex)) {
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
|
|
||||||
if ($this->match($regex, $userAgent)) {
|
|
||||||
if ($key !== '') {
|
|
||||||
return $key;
|
|
||||||
}
|
|
||||||
|
|
||||||
$match = reset($this->matchesArray);
|
|
||||||
|
|
||||||
return is_string($match) ? $match : null;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return null;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Retrieve from the given key from the cache or resolve the value.
|
|
||||||
*
|
|
||||||
* @template TReturn of string|bool|null
|
|
||||||
*
|
|
||||||
* @param Closure():TReturn $callback
|
|
||||||
* @return TReturn
|
|
||||||
*/
|
|
||||||
protected function retrieveUsingCacheOrResolve(string $key, Closure $callback): string|bool|null
|
|
||||||
{
|
|
||||||
$cacheKey = $this->createCacheKey($key);
|
|
||||||
|
|
||||||
if (! is_null($cacheItem = $this->store[$cacheKey] ?? null)) {
|
|
||||||
return $cacheItem;
|
|
||||||
}
|
|
||||||
|
|
||||||
return tap(call_user_func($callback), function ($result) use ($cacheKey): void {
|
|
||||||
$this->store[$cacheKey] = $result;
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Merge multiple rules into one array.
|
|
||||||
*
|
|
||||||
* @param array<string, string|list<string>> ...$all
|
|
||||||
* @return array<string, string>
|
|
||||||
*/
|
|
||||||
protected function mergeRules(array ...$all): array
|
|
||||||
{
|
|
||||||
$merged = [];
|
|
||||||
|
|
||||||
foreach ($all as $rules) {
|
|
||||||
foreach ($rules as $key => $value) {
|
|
||||||
$value = is_array($value) ? implode('|', $value) : $value;
|
|
||||||
|
|
||||||
if (empty($merged[$key])) {
|
|
||||||
$merged[$key] = $value;
|
|
||||||
} else {
|
|
||||||
$merged[$key] .= '|'.$value;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return $merged;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -5,7 +5,6 @@ declare(strict_types=1);
|
|||||||
namespace App\Service\Import\Importers;
|
namespace App\Service\Import\Importers;
|
||||||
|
|
||||||
use Exception;
|
use Exception;
|
||||||
use Illuminate\Support\Carbon;
|
|
||||||
use Illuminate\Support\Str;
|
use Illuminate\Support\Str;
|
||||||
use League\Csv\Exception as CsvException;
|
use League\Csv\Exception as CsvException;
|
||||||
use League\Csv\Reader;
|
use League\Csv\Reader;
|
||||||
@@ -25,7 +24,6 @@ class ClockifyProjectsImporter extends DefaultImporter
|
|||||||
$header = $reader->getHeader();
|
$header = $reader->getHeader();
|
||||||
$this->validateHeader($header);
|
$this->validateHeader($header);
|
||||||
$billableRateKey = $this->getBillableRateKey($header);
|
$billableRateKey = $this->getBillableRateKey($header);
|
||||||
$tasksKey = $this->getTasksKey($header);
|
|
||||||
$records = $reader->getRecords();
|
$records = $reader->getRecords();
|
||||||
foreach ($records as $record) {
|
foreach ($records as $record) {
|
||||||
$clientId = null;
|
$clientId = null;
|
||||||
@@ -46,12 +44,11 @@ class ClockifyProjectsImporter extends DefaultImporter
|
|||||||
'is_billable' => $record['Billability'] === 'Yes',
|
'is_billable' => $record['Billability'] === 'Yes',
|
||||||
'billable_rate' => $billableRateKey !== null && $record[$billableRateKey] !== '' ? (int) (((float) $record[$billableRateKey]) * 100) : null,
|
'billable_rate' => $billableRateKey !== null && $record[$billableRateKey] !== '' ? (int) (((float) $record[$billableRateKey]) * 100) : null,
|
||||||
'estimated_time' => $record['Estimated (h)'] !== '' && is_numeric($record['Estimated (h)']) ? (int) ($record['Estimated (h)'] * 3600) : null,
|
'estimated_time' => $record['Estimated (h)'] !== '' && is_numeric($record['Estimated (h)']) ? (int) ($record['Estimated (h)'] * 3600) : null,
|
||||||
'archived_at' => $record['Status'] === 'Archived' ? Carbon::now() : null,
|
|
||||||
]);
|
]);
|
||||||
}
|
}
|
||||||
|
|
||||||
if ($record[$tasksKey] !== '') {
|
if ($record['Task'] !== '') {
|
||||||
$tasks = explode(', ', $record[$tasksKey]);
|
$tasks = explode(', ', $record['Task']);
|
||||||
foreach ($tasks as $task) {
|
foreach ($tasks as $task) {
|
||||||
$this->taskImportHelper->getKey([
|
$this->taskImportHelper->getKey([
|
||||||
'name' => $task,
|
'name' => $task,
|
||||||
@@ -84,26 +81,13 @@ class ClockifyProjectsImporter extends DefaultImporter
|
|||||||
'Status',
|
'Status',
|
||||||
'Visibility',
|
'Visibility',
|
||||||
'Billability',
|
'Billability',
|
||||||
|
'Task',
|
||||||
];
|
];
|
||||||
foreach ($requiredFields as $requiredField) {
|
foreach ($requiredFields as $requiredField) {
|
||||||
if (! in_array($requiredField, $header, true)) {
|
if (! in_array($requiredField, $header, true)) {
|
||||||
throw new ImportException('Invalid CSV header, missing field: '.$requiredField);
|
throw new ImportException('Invalid CSV header, missing field: '.$requiredField);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
// Clockify renamed the "Task" column to "Tasks" in newer exports; accept either.
|
|
||||||
if (! in_array('Task', $header, true) && ! in_array('Tasks', $header, true)) {
|
|
||||||
throw new ImportException('Invalid CSV header, missing field: Tasks');
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Clockify renamed the "Task" column to "Tasks" in newer exports.
|
|
||||||
*
|
|
||||||
* @param array<string> $header
|
|
||||||
*/
|
|
||||||
private function getTasksKey(array $header): string
|
|
||||||
{
|
|
||||||
return in_array('Tasks', $header, true) ? 'Tasks' : 'Task';
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -116,12 +116,10 @@ class ClockifyTimeEntriesImporter extends DefaultImporter
|
|||||||
throw new ImportException('Time entry description is too long');
|
throw new ImportException('Time entry description is too long');
|
||||||
}
|
}
|
||||||
$timeEntry->description = $record['Description'];
|
$timeEntry->description = $record['Description'];
|
||||||
if (isset($record['Billable'])) {
|
if (! in_array($record['Billable'], ['Yes', 'No'], true)) {
|
||||||
if (! in_array($record['Billable'], ['Yes', 'No'], true)) {
|
throw new ImportException('Invalid billable value');
|
||||||
throw new ImportException('Invalid billable value');
|
|
||||||
}
|
|
||||||
$timeEntry->billable = $record['Billable'] === 'Yes';
|
|
||||||
}
|
}
|
||||||
|
$timeEntry->billable = $record['Billable'] === 'Yes';
|
||||||
$timeEntry->tags = $this->getTags($record['Tags']);
|
$timeEntry->tags = $this->getTags($record['Tags']);
|
||||||
$timeEntry->is_imported = true;
|
$timeEntry->is_imported = true;
|
||||||
|
|
||||||
@@ -221,6 +219,7 @@ class ClockifyTimeEntriesImporter extends DefaultImporter
|
|||||||
'Group',
|
'Group',
|
||||||
'Email',
|
'Email',
|
||||||
'Tags',
|
'Tags',
|
||||||
|
'Billable',
|
||||||
'Start Date',
|
'Start Date',
|
||||||
'Start Time',
|
'Start Time',
|
||||||
'End Date',
|
'End Date',
|
||||||
|
|||||||
@@ -5,25 +5,27 @@ declare(strict_types=1);
|
|||||||
namespace App\Service;
|
namespace App\Service;
|
||||||
|
|
||||||
use App\Enums\Role;
|
use App\Enums\Role;
|
||||||
use App\Events\OrganizationInvitationAdding;
|
|
||||||
use App\Exceptions\Api\InvitationForTheEmailAlreadyExistsApiException;
|
use App\Exceptions\Api\InvitationForTheEmailAlreadyExistsApiException;
|
||||||
use App\Exceptions\Api\UserIsAlreadyMemberOfOrganizationApiException;
|
use App\Exceptions\Api\UserIsAlreadyMemberOfOrganizationApiException;
|
||||||
use App\Mail\OrganizationInvitationMail;
|
use App\Mail\OrganizationInvitationMail;
|
||||||
|
use App\Models\Member;
|
||||||
use App\Models\Organization;
|
use App\Models\Organization;
|
||||||
use App\Models\OrganizationInvitation;
|
use App\Models\OrganizationInvitation;
|
||||||
use App\Models\User;
|
|
||||||
use Illuminate\Support\Collection;
|
|
||||||
use Illuminate\Support\Facades\Log;
|
|
||||||
use Illuminate\Support\Facades\Mail;
|
use Illuminate\Support\Facades\Mail;
|
||||||
|
use Laravel\Jetstream\Events\InvitingTeamMember;
|
||||||
|
|
||||||
class InvitationService
|
class InvitationService
|
||||||
{
|
{
|
||||||
/**
|
/**
|
||||||
* @throws UserIsAlreadyMemberOfOrganizationApiException|InvitationForTheEmailAlreadyExistsApiException
|
* @throws UserIsAlreadyMemberOfOrganizationApiException|InvitationForTheEmailAlreadyExistsApiException
|
||||||
*/
|
*/
|
||||||
public function inviteUser(Organization $organization, string $email, Role $role, User $inviter): OrganizationInvitation
|
public function inviteUser(Organization $organization, string $email, Role $role): OrganizationInvitation
|
||||||
{
|
{
|
||||||
if (app(MemberService::class)->isEmailAlreadyMember($organization, $email)) {
|
if (Member::query()
|
||||||
|
->whereBelongsTo($organization, 'organization')
|
||||||
|
->whereRelation('user', 'email', '=', $email)
|
||||||
|
->where('role', '!=', Role::Placeholder->value)
|
||||||
|
->exists()) {
|
||||||
throw new UserIsAlreadyMemberOfOrganizationApiException;
|
throw new UserIsAlreadyMemberOfOrganizationApiException;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -34,7 +36,7 @@ class InvitationService
|
|||||||
throw new InvitationForTheEmailAlreadyExistsApiException;
|
throw new InvitationForTheEmailAlreadyExistsApiException;
|
||||||
}
|
}
|
||||||
|
|
||||||
OrganizationInvitationAdding::dispatch($organization, $email, $role, $inviter);
|
InvitingTeamMember::dispatch($organization, $email, $role->value);
|
||||||
|
|
||||||
$invitation = new OrganizationInvitation;
|
$invitation = new OrganizationInvitation;
|
||||||
$invitation->email = $email;
|
$invitation->email = $email;
|
||||||
@@ -46,37 +48,4 @@ class InvitationService
|
|||||||
|
|
||||||
return $invitation;
|
return $invitation;
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
|
||||||
* @return Collection<int, Organization>
|
|
||||||
*/
|
|
||||||
public function processAcceptedInvitations(User $user): Collection
|
|
||||||
{
|
|
||||||
$organizations = new Collection;
|
|
||||||
|
|
||||||
$invitations = OrganizationInvitation::query()
|
|
||||||
->where('email', $user->email)
|
|
||||||
->whereNotNull('accepted_at')
|
|
||||||
->get();
|
|
||||||
|
|
||||||
foreach ($invitations as $invitation) {
|
|
||||||
$organization = $invitation->organization;
|
|
||||||
$role = Role::tryFrom($invitation->role);
|
|
||||||
if ($role === null) {
|
|
||||||
Log::error('Invalid role in invitation', [
|
|
||||||
'invitation' => $invitation->getKey(),
|
|
||||||
'role' => $invitation->role,
|
|
||||||
]);
|
|
||||||
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
app(MemberService::class)->addMember($user, $organization, $role);
|
|
||||||
|
|
||||||
$invitation->delete();
|
|
||||||
|
|
||||||
$organizations->push($organization);
|
|
||||||
}
|
|
||||||
|
|
||||||
return $organizations;
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -96,30 +96,6 @@ class LocalizationService
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
|
||||||
* Format a duration for reporting contexts (PDF reports, places that display duration
|
|
||||||
* directly next to cost). Promotes the verbose `Hh Mm` format to the compact `HH:MM:SS`
|
|
||||||
* so totals stay narrow and reconcile with cost, which is always computed to the second.
|
|
||||||
*/
|
|
||||||
public function formatIntervalForReporting(CarbonInterval $interval): string
|
|
||||||
{
|
|
||||||
$promoted = [
|
|
||||||
IntervalFormat::HoursMinutes,
|
|
||||||
IntervalFormat::HoursMinutesColonSeparated,
|
|
||||||
];
|
|
||||||
if (! in_array($this->intervalFormat, $promoted, true)) {
|
|
||||||
return $this->formatInterval($interval);
|
|
||||||
}
|
|
||||||
|
|
||||||
$previous = $this->intervalFormat;
|
|
||||||
$this->intervalFormat = IntervalFormat::HoursMinutesSecondsColonSeparated;
|
|
||||||
try {
|
|
||||||
return $this->formatInterval($interval);
|
|
||||||
} finally {
|
|
||||||
$this->intervalFormat = $previous;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
public function formatCurrency(Money $money): string
|
public function formatCurrency(Money $money): string
|
||||||
{
|
{
|
||||||
$currencyService = app(CurrencyService::class);
|
$currencyService = app(CurrencyService::class);
|
||||||
|
|||||||
@@ -5,8 +5,6 @@ declare(strict_types=1);
|
|||||||
namespace App\Service;
|
namespace App\Service;
|
||||||
|
|
||||||
use App\Enums\Role;
|
use App\Enums\Role;
|
||||||
use App\Events\MemberAdded;
|
|
||||||
use App\Events\MemberAdding;
|
|
||||||
use App\Events\MemberRemoved;
|
use App\Events\MemberRemoved;
|
||||||
use App\Exceptions\Api\CanNotRemoveOwnerFromOrganization;
|
use App\Exceptions\Api\CanNotRemoveOwnerFromOrganization;
|
||||||
use App\Exceptions\Api\ChangingRoleOfPlaceholderIsNotAllowed;
|
use App\Exceptions\Api\ChangingRoleOfPlaceholderIsNotAllowed;
|
||||||
@@ -23,6 +21,8 @@ use App\Models\User;
|
|||||||
use Illuminate\Database\Eloquent\Builder;
|
use Illuminate\Database\Eloquent\Builder;
|
||||||
use Illuminate\Support\Facades\DB;
|
use Illuminate\Support\Facades\DB;
|
||||||
use InvalidArgumentException;
|
use InvalidArgumentException;
|
||||||
|
use Laravel\Jetstream\Events\AddingTeamMember;
|
||||||
|
use Laravel\Jetstream\Events\TeamMemberAdded;
|
||||||
|
|
||||||
class MemberService
|
class MemberService
|
||||||
{
|
{
|
||||||
@@ -36,7 +36,7 @@ class MemberService
|
|||||||
public function addMember(User $user, Organization $organization, Role $role, bool $asSuperAdmin = false): Member
|
public function addMember(User $user, Organization $organization, Role $role, bool $asSuperAdmin = false): Member
|
||||||
{
|
{
|
||||||
if (! $asSuperAdmin) {
|
if (! $asSuperAdmin) {
|
||||||
MemberAdding::dispatch($user, $organization, $role);
|
AddingTeamMember::dispatch($organization, $user);
|
||||||
}
|
}
|
||||||
|
|
||||||
$member = new Member;
|
$member = new Member;
|
||||||
@@ -49,36 +49,14 @@ class MemberService
|
|||||||
$user->currentOrganization()->associate($organization);
|
$user->currentOrganization()->associate($organization);
|
||||||
$user->save();
|
$user->save();
|
||||||
});
|
});
|
||||||
$this->mergePlaceholderMembersIntoExistingMember($member, $organization, $user);
|
|
||||||
|
|
||||||
if (! $asSuperAdmin) {
|
if (! $asSuperAdmin) {
|
||||||
MemberAdded::dispatch($member, $organization, $user);
|
TeamMemberAdded::dispatch($organization, $user);
|
||||||
}
|
}
|
||||||
|
|
||||||
return $member;
|
return $member;
|
||||||
}
|
}
|
||||||
|
|
||||||
private function mergePlaceholderMembersIntoExistingMember(Member $member, Organization $organization, User $user): void
|
|
||||||
{
|
|
||||||
$placeholders = Member::query()
|
|
||||||
->whereHas('user', function (Builder $query) use ($user): void {
|
|
||||||
/** @var Builder<User> $query */
|
|
||||||
$query->where('is_placeholder', '=', true)
|
|
||||||
->where('email', '=', $user->email);
|
|
||||||
})
|
|
||||||
->whereBelongsTo($organization, 'organization')
|
|
||||||
->with(['user'])
|
|
||||||
->get();
|
|
||||||
|
|
||||||
foreach ($placeholders as $placeholder) {
|
|
||||||
/** @var Member $placeholder */
|
|
||||||
$placeholderUser = $placeholder->user;
|
|
||||||
$this->assignOrganizationEntitiesToDifferentMember($organization, $placeholder, $member);
|
|
||||||
$placeholder->delete();
|
|
||||||
$placeholderUser->delete();
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @throws CanNotRemoveOwnerFromOrganization
|
* @throws CanNotRemoveOwnerFromOrganization
|
||||||
* @throws EntityStillInUseApiException
|
* @throws EntityStillInUseApiException
|
||||||
@@ -93,7 +71,7 @@ class MemberService
|
|||||||
$isPlaceholder = $user->is_placeholder;
|
$isPlaceholder = $user->is_placeholder;
|
||||||
|
|
||||||
if (! $isPlaceholder && $user->current_team_id === $member->organization_id) {
|
if (! $isPlaceholder && $user->current_team_id === $member->organization_id) {
|
||||||
$user->currentOrganization()->disassociate();
|
$user->currentTeam()->disassociate();
|
||||||
$user->save();
|
$user->save();
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -212,7 +190,7 @@ class MemberService
|
|||||||
{
|
{
|
||||||
$user = $member->user;
|
$user = $member->user;
|
||||||
if ($user->current_team_id === $member->organization_id) {
|
if ($user->current_team_id === $member->organization_id) {
|
||||||
$user->currentOrganization()->disassociate();
|
$user->currentTeam()->disassociate();
|
||||||
$user->save();
|
$user->save();
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -231,13 +209,4 @@ class MemberService
|
|||||||
$this->userService->makeSureUserHasCurrentOrganization($user);
|
$this->userService->makeSureUserHasCurrentOrganization($user);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
public function isEmailAlreadyMember(Organization $organization, string $email): bool
|
|
||||||
{
|
|
||||||
return Member::query()
|
|
||||||
->whereBelongsTo($organization, 'organization')
|
|
||||||
->whereRelation('user', 'email', '=', $email)
|
|
||||||
->where('role', '!=', Role::Placeholder->value)
|
|
||||||
->exists();
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user