Commit Graph

85 Commits

Author SHA1 Message Date
Jakub Zych
3ac1d64ab4 fix(12-05): cast floats to strings with PHP's 14-digit precision in request validation
PHP 8's (string) cast of a float formats with the precision ini (14
significant digits, %.14G), not the shortest round-trip form: 1/3 is
0.33333333333333, 1e14 is 1.0E+14 and 5e-324 is 4.9406564584125E-324.
phpFloatString, used for the string form of JSON floats in size, in, regex
and integer checks, printed up to 17 digits and switched to the exponent
form only from 1e15. TestPHPFloatStringMatchesPHPCast pins 27 values to
php -r output.
2026-10-02 15:46:24 +02:00
Jakub Zych
36983bc87e fix(12-05): match Laravel's in and not_in rules on array values
A 162-case truth table recorded from WinterCMS's validator (the vendored
winter/storm Factory, Laravel 9) found three divergences, all on arrays:

- in compared array elements loosely; Laravel uses array_diff, an exact
  string comparison, so ["1.0"] is not in 1,2;
- not_in failed when any element was listed; Laravel's validateNotIn is
  !validateIn, so an array passes unless every element is listed;
- not_in failed an array without the array rule; Laravel passes it.

validate_rules_test.go keeps the whole table (accepted, array keys,
boolean, numeric, integer, in/not_in, sizes by type, regex, dates and
comparisons, url, presence, nested and map wildcards, bail and order).
2026-10-02 15:42:47 +02:00
Jakub Zych
1307060e15 fix(12-05): store WinterCMS's broken-image thumbnail for an unusable original (T-12-16)
A photo whose original is missing, does not decode or declares more than
4096x4096 pixels made attach.File.Thumb return an error, and every listing
that shows the photo answered 500 from then on: one 100-byte PNG uploaded
by any household member broke GET collections and the album for everyone.

Thumb now follows WinterCMS's File::makeThumb catch branch: it logs the
reason at warn level, stores WinterCMS's BrokenImage picture (exported as
attach.BrokenImagePNG) under the thumbnail key and returns its URL. Invalid
arguments, storage errors and encode failures are still errors.
2026-10-02 15:15:26 +02:00
Jakub Zych
3ae49bb6f4 feat(12-01): report the search engine's found count and field weights
- optional beachcomber.PageSearcher returns a page of candidate ids plus
  the engine's found count; beachcomber.SearchPage falls back to
  SearchIDs for engines without it, so Engine is unchanged
- Query.QueryByWeights is sent to Typesense as query_by_weights; a
  mismatched weight list or a page above typesense.MaxPerPage (250) is
  refused before any request
2026-10-02 11:37:01 +02:00
Jakub Zych
e06e0cc8bf feat(12-01): record multipart uploads and match Winter upload URLs
- attach.PublicURL and (*File).URL build Winter File::getPath() URLs; the
  thumbnailer decodes webp via golang.org/x/image v0.46.0 and checks the
  image size from the header before decoding
- tide requests carry multipart parts (files beside the fixture pinned by
  sha256) encoded with the fixed MultipartBoundary, so PHP and Go receive
  byte-identical bodies
- tide masks the random partition, disk name and file id of url/thumb_url
  upload URLs while still diffing prefix, size, mode and extension, and
  NormalizePublications masks Carbon dates in the published album
2026-10-02 11:33:42 +02:00
Jakub Zych
f9b7f2ea33 feat(12-01): add Laravel request validation to lagoon
- lagoon.ValidateRequest ports Laravel 9 request validation: wildcard
  expansion, implicit-rule stop, bail, sometimes/nullable/blank skipping,
  size messages split by type and character-counted string lengths
- ParseRules, In, CustomRule, UploadedFile and ErrorKeys for rule tables
- pl/en lagoon::validation catalogs ported verbatim from WinterCMS
- lagoon.Validate answers a numeric range failure with the bound that
  failed (min, max or numeric between) instead of always max
2026-10-02 11:25:36 +02:00
Jakub Zych
2da8112dbb fix(09): WR-11 enforce case-insensitive unique backend user emails
Add a backend admin migration that creates a unique index on
lower(backend_users.email). Rows copied from WinterCMS may hold emails
that differ only in case, so the migration refuses to run and names the
clashing logins instead of choosing an account to drop.
2026-10-01 23:12:29 +02:00
Jakub Zych
4ae272e3cc fix(09): WR-19 expose the write transaction to hooks and scopes through TxFromContext 2026-10-01 21:37:13 +02:00
Jakub Zych
8479defe53 fix(09): WR-17 merge an admin's own permissions over the role's, honouring denies 2026-10-01 21:33:07 +02:00
Jakub Zych
629fac4d29 fix(09): WR-16 resolve model columns through embedded structs and explicit column tags 2026-10-01 21:31:46 +02:00
Jakub Zych
2d96adf775 fix(09): WR-10 keep cabana's own backend guard when it is activated twice on one application 2026-10-01 21:31:46 +02:00
Jakub Zych
299d220b51 fix(09): WR-14 let logout revoke an expired token that is still refreshable and always clear the cookie 2026-10-01 21:23:42 +02:00
Jakub Zych
c9bb14944a fix(09): WR-13 read admin passwords from a prompt or stdin and deprecate the --password flag 2026-10-01 21:20:20 +02:00
Jakub Zych
331351a73c fix(09): WR-11 reject ambiguous admin logins and cross-field login or email collisions 2026-10-01 21:17:50 +02:00
Jakub Zych
eb8c727790 fix(09): WR-12 time a missing admin login at the configured bcrypt cost 2026-10-01 21:17:37 +02:00
Jakub Zych
3f476164f9 fix(09): WR-10 fail boot when another plugin already owns the backend guard 2026-10-01 21:15:05 +02:00
Jakub Zych
8b48eea4e1 fix(09): WR-08 search non-text list columns as text instead of failing in SQL 2026-10-01 21:11:38 +02:00
Jakub Zych
b026aec162 fix(09): WR-07 keep relation column order from the YAML itself, not a fixed indentation 2026-10-01 21:10:09 +02:00
Jakub Zych
889250c8fb fix(09): WR-06 default a relation list to its first sortable column 2026-10-01 21:07:54 +02:00
Jakub Zych
9bca815b1b fix(09): WR-05 refuse relation link and unlink the panel does not declare 2026-10-01 21:07:11 +02:00
Jakub Zych
b8084080cb fix(09): WR-04 apply a form field's required flag only in the contexts that can supply it 2026-10-01 21:05:33 +02:00
Jakub Zych
f2ab93f291 fix(09): WR-03 refuse writes that the compiled list and form do not declare 2026-10-01 21:04:31 +02:00
Jakub Zych
28aa073de0 fix(09): WR-02 drop a denied main menu item and never link it to a controller the admin cannot open 2026-10-01 20:59:26 +02:00
Jakub Zych
b4b8b5df64 fix(09): WR-01 match wildcard required permissions and treat several codes as any, like Winter 2026-10-01 20:58:16 +02:00
Jakub Zych
037dc53030 feat(lagoon): per-query collation for OrderBy, drop the database locale check
- lagoon.OrderBy takes variadic lagoon.OrderOption values; lagoon.Collate(name)
  emits a validated, double-quoted COLLATE clause (e.g. "pl-x-icu")
- remove the exported CheckLocale and the ICU pl-PL check from Open and Use
- framework test containers and per-test databases are plain PostgreSQL
- lagoon README, root README and docs pages drop the locale requirement;
  queries-and-pagination gains a "Sorting with a collation" section
  backed by ExampleCollate
2026-10-01 09:51:03 +02:00
Jakub Zych
44bd1446f5 feat(11.1-04): add the Backend section, the remaining Services pages and the concept map links
- docs/backend: admin controllers, forms, lists and filters, relation
  manager, users and permissions, settings, partials and widgets, admin SPA
- docs/services: storage, outbound HTTP, realtime, Web Push, search, parity
  testing and the Frontend and AJAX (not provided) page
- Examples for cabana (with testdata/docs YAML), fetchguard, lighthouse and
  its centrifugo driver, flare, beachcomber and typesense, tide; lighthouse
  and beachcomber TestDocs* regions run on their Postgres harnesses
- concept map rows link their guide pages and the not-provided rows the
  Frontend and AJAX page; index lists Backend, Database and Services
- TestDocsRequiredPages asserts the D-08 section order
2026-09-30 23:18:35 +02:00
Jakub Zych
efb35a2d35 feat(11.1-04): add the Database section and the core Services pages
- docs/database: models, migrations, queries and pagination, relations,
  casts and validation, attachments and transactions (lagoon.Transaction,
  lagoon.AfterCommit, nested savepoints, lagoon.OnDatabase)
- docs/services: configuration, events, routing with auth groups, rate
  limiting, authentication, the OAuth server, mail and localization
- runnable Examples for lagoon, attach, compass, surf, wire, bouncer,
  wristband, postcard, phrasebook and festival; lagoon TestDocs* regions
  run on the package's Postgres harness through DocsDB
- 15 new required pages
2026-09-30 22:59:25 +02:00
Jakub Zych
9d37d56486 feat(11.1-04): add the Services section with a verified Queued jobs page
- docs/services/jobs.md: declaring, registering and dispatching jobs, the
  summer_jobs record, progress, cancellation and workers
- conga ExampleJob plus dispatch and status regions run by TestDocsDispatch
  on the package's Postgres harness (DocsApp in export_docs_test.go)
- concept map links the queued jobs row; services/jobs is a required page
2026-09-30 22:35:22 +02:00
Jakub Zych
9526b6b638 fix(11-08): bind nested callbacks to parent transaction 2026-09-30 22:24:04 +02:00
Jakub Zych
a896f3ff81 feat(11.1-03): add the Setup and Console docs sections
- setup: introduction, installation rewritten from install to serve,
  configuration with the keys an application sets
- console: introduction, setup and maintenance, scaffolding, writing
  commands, utilities; every command name is checker-verified
- bonfire ExampleCatalog shows arguments, bare and repeatable flags
- index links the section introductions; TestDocsRequiredPages lists
  the seven new pages
2026-09-30 22:16:36 +02:00
Jakub Zych
1f8f5e1b51 feat(11.1-03): add the Architecture and Plugins docs sections
- architecture: introduction, Go modules and workspaces, application
  lifecycle, request lifecycle
- plugins: registration, scheduling, extending, testing
- verified Examples for backpack services, towel request context,
  pact schedules and festival events
- TestDocsRequiredPages lists the eight new pages
2026-09-30 22:12:08 +02:00
Jakub Zych
d6003cd84b feat(11.1-03): add the Coming from WinterCMS concept map with a verified plugin example
- docs/setup/coming-from-wintercms.md maps WinterCMS concepts to checked
  pkg.Ident spans and lists what SummerCMS does not provide
- party BlogPlugin and ExamplePlugin, shown through src= fences
- TestDocsRequiredPages asserts required pages build as .html and .md
- index links the new page
2026-09-30 22:06:45 +02:00
Jakub Zych
dc6a03c714 feat(11.1-01): verify src= code blocks and add summer docs:sync
- src= fences name a file, a Go declaration or Example body, or a docs:start region
- confinement: relative clean paths inside the root, no dotfiles or .env,
  no nested go.mod modules, Examples need // Output:, test regions must run
- a drifted or missing snippet is a problem, so docs:build writes nothing
- docs:sync rewrites drifted fence bodies in place
- fences render in figure.code with a source caption; .md fences keep only the language
- bonfire ExampleCall is the first verified example, shown in setup/installation
2026-09-30 21:26:52 +02:00
Jakub Zych
8e0083ed41 fix(11-08): document foreign and nested transaction refusal
- lagoon.Transaction doc and README state that a nested call over a root
  handle returns an error instead of opening an independent transaction
- beachcomber README no longer promises an immediate sync inside a plain
  GORM transaction; it is warned and skipped since 11-08
2026-09-30 21:00:20 +02:00
Jakub Zych
2766f34d99 test(11-08): keep sync failure coverage managed 2026-09-30 20:49:31 +02:00
Jakub Zych
a33b1ada80 fix(11-08): refuse unmanaged after-commit work 2026-09-30 20:14:42 +02:00
Jakub Zych
f7b6b0c313 fix(11-08): make cabana writes commit-safe 2026-09-30 20:14:23 +02:00
Jakub Zych
e55d2345b7 test(11-07): pin that a keyless Typesense engine is never configured
- TestSyncEngineRegistration: the typesense import registers the driver
  and a missing or blank api_key reports Configured false, the gate that
  keeps beachcomber from sending anything
2026-09-30 14:34:33 +02:00
Jakub Zych
11b5b4cdf4 test(11-07): cover the fake Centrifugo recorder edges
- TestCentrifugoRecorder: info/unsubscribe answers, 405 with Allow, 413
  above the body cap (not recorded), authorization as a comparison that is
  never stored, empty key never authorized, loopback ListenAndServe and
  shutdown, waitListening and sleepCtx failures
- TestFlowIDNames: default masked id variables
2026-09-30 14:28:51 +02:00
Jakub Zych
18d3097be5 test(11-07): pin the Typesense engine wire contract
- TestEngineWire: API key and Accept on every request, create on 404 with
  the schema or auto fields, 409 as success, JSONL import with
  success:false and unreadable lines as errors (message capped, no
  document), 404-tolerant delete/flush with id escaping, SearchIDs
  parameters and id parsing, typed errors without bodies, transport
  errors without the URL, timeout
- TestEngineConfig: search.typesense.* parsing and the registered engine
  (coverage 95.6%)
2026-09-30 14:28:02 +02:00
Jakub Zych
6df43d45b8 fix(11-07): roll back the savepoint when a swallowed read failed
- beachcomber and lighthouse released their savepoint whenever the inner
  function reported no error; a Gate that counts a failed read as off,
  or a channel function or delete snapshot that swallows one, left the
  caller's Postgres transaction aborted (25P02) and failed the write
- a failed RELEASE now rolls back to the savepoint, as the READMEs promise
- beachcomber gets its testcontainers harness and sync tests
  (TestSyncGates, TestSyncAfterCommit, TestSyncDeleteAndSoftDelete,
  TestSyncFailuresNonFatal, TestServiceSetup); lighthouse gets
  TestBroadcastSwallowedReadFailure
2026-09-30 14:26:51 +02:00
Jakub Zych
6dadbf6957 test(11-07): cover flare VAPID, allowlist, statuses and config
- TestVAPIDHeader (origin rules, exp, subject), TestVAPIDKeys,
  TestSendAllowlist (T-11-22 host table), TestSendStatuses (2xx, 404/410,
  StatusError without body, disabled, host-only transport errors),
  TestFlareConfig, TestAgo, TestEncryptRejects (coverage 90.0%)
2026-09-30 14:22:44 +02:00
Jakub Zych
33194a1f98 test(11-07): cover lighthouse realtime and the Centrifugo driver
- lighthouse: TestSuppression (Widget silenced, Gadget not, nesting,
  stale outer ctx), TestBulkEmitsOnce, TestBroadcastEdges (zero-key batch,
  update actor, id-only delete, method contract, multi-channel, savepoint),
  TestBroadcastPublishFailure, TestFromSelectsDriver, TestMountSurfaces,
  TestRegistry under -race, drivers, args JSON, Bind (coverage 91.7%)
- centrifugo: TestTokenClaims, TestTokenHandler, TestClientRequests,
  TestClientLoadConfig and a TestProxy table porting the WinterCMS WS-005,
  WS-007 and WS-013 cases (coverage 92.4%)
2026-09-30 14:21:03 +02:00
Jakub Zych
35ac96d664 test(11-07): cover jobs, scheduler and lagoon seams branch by branch
- conga: TestOutcome*, TestCancelQueuedNeverRuns, TestCancelRunningCancelsCtx,
  TestStopJobFromWorker, TestManagerPHPSemantics, principal, delay,
  registration, worker and queue-setting branches; TestQueueClear and
  TestQueueWork move to commands_test.go with the batch/state and
  queue-filter cases (coverage 92.5%)
- scheduler: validation, ordering, missing catalog, log writer, dueAt
- lagoon: TestQueueMigrationsUpDown (River v7 + summer_jobs, rollback,
  idempotent rerun), OnDatabase isolation, Transaction edges
- bonfire TestCallEdges, pact TestCadence
2026-09-30 14:14:39 +02:00
Jakub Zych
6f50b6c940 fix(11-07): enqueue broadcast jobs before GORM commits a single write
- lighthouse:after_create/update/delete also declare
  Before(gorm:commit_or_rollback_transaction); an After-only anchor put
  them past GORM's own commit, so a plain gdb.Create enqueued its
  broadcast job after the commit on the pool (deferred from 11-05)
- lighthouse gets the testcontainers Postgres harness and TestBroadcastTx
  (commit publishes once, rollback nothing, single-statement write
  enqueues on its own transaction, failed write enqueues nothing)
2026-09-30 14:05:17 +02:00
Jakub Zych
c544319cec fix(11-07): hand after-commit callbacks a clean statement
- lagoon.Transaction, the lagoon:after_commit flush and the immediate
  AfterCommit path pass a handle with an empty statement on the write's
  connection (Session NewDB+Context, Clauses(), Session NewDB)
- a WithContext query through the handle no longer continues from the
  written model's statement (deferred from 11-05)
- TestTransactionAfterCommit/callback_handle_has_a_clean_statement covers
  the implicit, plain-transaction and lagoon.Transaction paths
2026-09-30 14:01:22 +02:00
Jakub Zych
f55cb444ab feat(11-04): add the websockets health, VAPID key and test-push commands
- centrifugo.Client.Info probes the info API method; an error body fails
- websockets:health ports CentrifugoHealthCheck: exits 1 without an API
  key or when the probe fails, prints the Setting/Value table otherwise
- websockets:generate-vapid-keys prints a new P-256 pair, shows configured
  keys only truncated, and --update persists them to overrides.yaml
- websockets:test-push reads subscriptions from an app-published
  SubscriptionSource, refuses to send while push is disabled and sends
  one encrypted push per subscription
- no command prints a configured private key or the Centrifugo API key
- flare and lighthouse READMEs document the CLI commands
2026-09-30 13:52:44 +02:00
Jakub Zych
5fb22c28d0 fix(11-04): keep earlier overrides when compass Persist saves
Persist rewrote overrides.yaml with only this process's runtime values,
so saving one key (for example websockets:generate-vapid-keys --update)
dropped every key persisted earlier. It now starts from the saved file
and lets runtime values win.
2026-09-30 13:45:13 +02:00
Jakub Zych
a9af0d77c7 feat(11-04): add flare Web Push with a stdlib VAPID driver
- RFC 8291 aes128gcm encryption from crypto/ecdh, crypto/hkdf and AES-GCM,
  matching the RFC 8291 Appendix A vector byte for byte
- RFC 8292 vapid t=<ES256 JWT>, k=<key> header (aud origin, exp +12h, sub)
- Pusher, Subscription, SendOptions, SubscriptionSource, Service and From
  reading push.* (enabled, keys, subject, ttl, allowed_hosts)
- sends only to https endpoints on push.allowed_hosts, checked before
  dialing, and never follows redirects; 404/410 map to ErrSubscriptionGone
- module README and root modules row
2026-09-30 13:43:09 +02:00
Jakub Zych
5382947ef8 fix(11-06): send Cache-Control: no-cache, private on the jwt.auth 401
The recorded PHP 401 for a missing bearer (realtime token no-bearer
case) carries Laravel's default Cache-Control header; the Go guard's
401 omitted it, so the replay failed on header.Cache-Control.
2026-09-30 13:31:55 +02:00