BUG B — navigation.blade.php crashed on null auth()->user() for
unauthenticated visitors of /dev/quick-login. Two-layer fix:
- DevQuickLogin: add #[Layout('components.layouts.auth')] so page
renders without the authenticated navigation bar
- navigation.blade.php: null-safe ?-> on all auth()->user() calls
(three occurrences: name, name again, email) as defense-in-depth
BUG A — @vite() generated http:// asset URLs causing Mixed Content
on HTTPS domain. Root cause: ASSET_URL removed but APP_URL changed to
http://localhost by previous agent. Fixed: APP_URL restored to
https://app.dev.lernschiff.com so URL::forceScheme('https') activates
and assets render as https://app.dev.lernschiff.com/build/assets/*.
TDD: test written → RED (500) → fix → GREEN. 46/46 pass.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Codex <noreply@openai.com>
- Add config/cors.php with supports_credentials=true and allowed_origins for app.dev.lernschiff.com
- Add routes/api_v1.php with auth:web-guarded /api/v1/me and /api/v1/users endpoints
- Add CrossSubdomainSessionTest covering OPTIONS 204 preflight and authenticated GET /api/v1/me
- Wire api_v1.php into routes/web.php
- Note: sanctum not installed; auth:web guard used instead of auth:sanctum,web
- Restore app.css with Tailwind v4 @import and @theme design tokens (Breeze had overwritten with v3 directives)
- Add @tailwindcss/vite tailwindcss() plugin back to vite.config.js
- Upgrade tailwindcss in package.json from ^3.1.0 to ^4.0.0; remove @tailwindcss/forms and autoprefixer (v3-only)
- Delete postcss.config.js (v3 PostCSS plugin, not needed for v4 Vite plugin)
- Comment out Volt::route('register', ...) in routes/auth.php — platform is invite-only
- Update RegistrationTest to assert /register returns 404 instead of 200
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>