Go to file
nexxo a84251260c
tests / pest (push) Failing after 9m6s Details
tests / assets (push) Successful in 22s Details
tests / release (push) Has been skipped Details
Read the mailbox password where it actually is, and let the console test it
The inbox kept saying no mailbox was set up while the password sat right
there on the settings page. isConfigured() read
config('services.inbound_mail.password'), which is only ever the .env
value: this project deliberately does not overlay stored secrets onto config
at boot — SecretVault's own docblock says so, and HttpMonitoringClient reads
its token at the point of use for exactly that reason. My docblock even
asserted the opposite mechanism, which I never verified. It reads the vault
now, and falls back to .env because SecretVault::get() already does.

And a way to find out. "Verbindung prüfen" saves the form first — testing
what is on screen while the server still holds the previous values would
report on a mailbox nobody configured — then performs the same four verbs
the real fetch performs: LOGIN, SELECT, SEARCH UNSEEN. A check that proves
something easier than the actual job is worse than none.

What it reports back is one of five fixed words, never the server's own
prose: an IMAP error carries the command it failed on, and for LOGIN that
command contains the password. Each word maps to a sentence an operator can
act on — address and port, mailbox and password, the folder.

The line saying when the mailbox was last reached is on both pages, and it
is written by the SCHEDULED run as well as by the button. Otherwise "last
checked" would mean "last time somebody pressed a button", which is the less
interesting of the two: a mailbox that stopped answering at three in the
morning is the one worth seeing, and nobody presses a button at three in the
morning. It is also shown when the answer is "never" — an empty inbox and a
mailbox that stopped answering look identical, and this line is the whole
difference.

A fetch against a mailbox that just refused the login now takes nothing in
and records the refusal, rather than reporting "nothing new" — which was
true and useless.

Also: HostStepsTest asserted the literal clupilot.com for a host name. That
was true until CLUPILOT_DNS_ZONE was set to clupilot.cloud on this
installation, and then a correct configuration failed a test. The zone is
pinned in the test now; what it is about is the shape of the name and which
address it carries.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-30 13:12:29 +02:00
.gitea/workflows feat(deploy): releases you can pin to, and a version that tells the truth 2026-07-26 15:21:38 +02:00
.npm chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
app Read the mailbox password where it actually is, and let the console test it 2026-07-30 13:12:29 +02:00
bin Make the private hostnames look like nothing is there, and close the way past the proxy 2026-07-27 11:26:48 +02:00
bootstrap Stop the 503 page appearing during an update 2026-07-29 17:50:15 +02:00
config Fix nine defects in the provisioning pipelines 2026-07-30 01:34:55 +02:00
database Stop charging VAT to the customers who owe us none 2026-07-30 02:15:41 +02:00
deploy Stop root workers breaking every page, and let the panel be closed 2026-07-29 15:43:54 +02:00
docker Give the readiness probe long enough for a restart to finish 2026-07-27 14:46:47 +02:00
docs Break the mode switch and the readiness page into twelve steps 2026-07-30 10:23:11 +02:00
lang Read the mailbox password where it actually is, and let the console test it 2026-07-30 13:12:29 +02:00
public One wordmark, one typeface, and the address the server actually issues 2026-07-29 14:30:44 +02:00
resources Read the mailbox password where it actually is, and let the console test it 2026-07-30 13:12:29 +02:00
routes Say the same thing to the customer, the register and the bank 2026-07-30 01:30:24 +02:00
storage chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
tests Read the mailbox password where it actually is, and let the console test it 2026-07-30 13:12:29 +02:00
.dockerignore chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
.editorconfig chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
.env.example Put customer instances on their own domain, and say which domains are ours 2026-07-29 16:03:13 +02:00
.gitattributes chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
.gitignore Keep exported invoices out of the repository 2026-07-29 09:56:00 +02:00
.npmrc chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
CLAUDE.md R24: a modal is never taller than the screen 2026-07-29 23:33:57 +02:00
README.md chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
VERSION Read the mailbox password where it actually is, and let the console test it 2026-07-30 13:12:29 +02:00
artisan chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
composer.json Render an invoice, with the arithmetic held to integer cents 2026-07-29 01:41:46 +02:00
composer.lock Render an invoice, with the arithmetic held to integer cents 2026-07-29 01:41:46 +02:00
docker-compose.yml Stop root workers breaking every page, and let the panel be closed 2026-07-29 15:43:54 +02:00
package-lock.json Rebuild the public site as a document, and read prices from the catalogue 2026-07-27 03:52:25 +02:00
package.json Rebuild the public site as a document, and read prices from the catalogue 2026-07-27 03:52:25 +02:00
phpunit.xml fix(billing): a paid order opens a contract, and provisioning obeys it 2026-07-26 11:10:00 +02:00
postcss.config.js feat(portal): design foundation — Tailwind v3, tokens, self-hosted fonts 2026-07-25 00:43:01 +02:00
tailwind.config.js Rebuild the public site as a document, and read prices from the catalogue 2026-07-27 03:52:25 +02:00
vite.config.js feat(ops): update page, automatic 419 recovery, CI workflow 2026-07-26 00:58:27 +02:00

README.md

Laravel Logo

Build Status Total Downloads Latest Stable Version License

About Laravel

Laravel is a web application framework with expressive, elegant syntax. We believe development must be an enjoyable and creative experience to be truly fulfilling. Laravel takes the pain out of development by easing common tasks used in many web projects, such as:

Laravel is accessible, powerful, and provides tools required for large, robust applications.

Learning Laravel

Laravel has the most extensive and thorough documentation and video tutorial library of all modern web application frameworks, making it a breeze to get started with the framework.

In addition, Laracasts contains thousands of video tutorials on a range of topics including Laravel, modern PHP, unit testing, and JavaScript. Boost your skills by digging into our comprehensive video library.

You can also watch bite-sized lessons with real-world projects on Laravel Learn, where you will be guided through building a Laravel application from scratch while learning PHP fundamentals.

Agentic Development

Laravel's predictable structure and conventions make it ideal for AI coding agents like Claude Code, Cursor, and GitHub Copilot. Install Laravel Boost to supercharge your AI workflow:

composer require laravel/boost --dev

php artisan boost:install

Boost provides your agent 15+ tools and skills that help agents build Laravel applications while following best practices.

Contributing

Thank you for considering contributing to the Laravel framework! The contribution guide can be found in the Laravel documentation.

Code of Conduct

In order to ensure that the Laravel community is welcoming to all, please review and abide by the Code of Conduct.

Security Vulnerabilities

If you discover a security vulnerability within Laravel, please send an e-mail to Taylor Otwell via taylor@laravel.com. All security vulnerabilities will be promptly addressed.

License

The Laravel framework is open-sourced software licensed under the MIT license.