Commit Graph

14 Commits (58e99c74e8e39aff6d6c16c26726e2edeac3825d)

Author SHA1 Message Date
Boban Blaskovic f4e3c2e6bf feat(api): UUID-only response test + WireModal pattern doc
Phase 11: NoNumericIdInResponseTest verifies /api/v1/me returns no numeric 'id' key and includes 'uuid'. WireModalDeleteTest documents the Livewire openModal pattern (skipped pending MVP-2 component).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-22 06:20:26 +02:00
Boban Blaskovic 5aeece934a feat(cors): config/cors.php supports_credentials + CORS tests + Reverb allowed_origins
- Add config/cors.php with supports_credentials=true and allowed_origins for app.dev.lernschiff.com
- Add routes/api_v1.php with auth:web-guarded /api/v1/me and /api/v1/users endpoints
- Add CrossSubdomainSessionTest covering OPTIONS 204 preflight and authenticated GET /api/v1/me
- Wire api_v1.php into routes/web.php
- Note: sanctum not installed; auth:web guard used instead of auth:sanctum,web
2026-05-22 06:14:48 +02:00
Boban Blaskovic 4854c6313d feat(dev): seeders + DevQuickLogin with double-defense guard 2026-05-22 06:09:28 +02:00
Boban Blaskovic 0f3a48604e fix(ui): restore Tailwind v4 @theme tokens + disable /register route (invite-only)
- Restore app.css with Tailwind v4 @import and @theme design tokens (Breeze had overwritten with v3 directives)
- Add @tailwindcss/vite tailwindcss() plugin back to vite.config.js
- Upgrade tailwindcss in package.json from ^3.1.0 to ^4.0.0; remove @tailwindcss/forms and autoprefixer (v3-only)
- Delete postcss.config.js (v3 PostCSS plugin, not needed for v4 Vite plugin)
- Comment out Volt::route('register', ...) in routes/auth.php — platform is invite-only
- Update RegistrationTest to assert /register returns 404 instead of 200

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-22 06:03:31 +02:00
Boban Blaskovic 26f508395d feat(auth): Breeze Livewire stack + dashboard/lizenz-abgelaufen views + layout shells
- Install laravel/breeze v2.4.2 (Livewire/Volt stack)
- Restore Livewire v4.3.0 (Breeze downgraded to v3; pinned back to ^4.0)
- Replace layouts/app.blade.php with Lernschiff-branded version (lang=de, CSS vars)
- Add layouts/auth.blade.php for auth pages
- Add components/layouts/{app,auth}.blade.php as anonymous components for <x-layouts.*>
- Add resources/views/dashboard.blade.php and lizenz-abgelaufen.blade.php (stub views)
- Rewrite routes/web.php: / redirects to /dashboard, dashboard returns view, merge Breeze routes
- Add TenantAwareUserProvider: bypasses TenantScope for Auth::attempt() credential lookups
  (TenantScope applies WHERE 0=1 for unauthenticated queries, blocking login)
- Register tenant-aware-eloquent provider in config/auth.php and AppServiceProvider
- Fix phpunit.xml.dist: force APP_ENV=testing via both env+server to override Docker shell env
  (Docker sets APP_ENV=local in $_SERVER; PHPUnit env override was silently ignored)
- Add auth.js to vite inputs for auth layout asset bundling
- Update ExampleTest: / now redirects to /dashboard (not welcome view)
- Fix RegistrationTest: skip self-registration test (Lernschiff requires tenant_id)
- Fix ProfileTest: assert soft-deleted user via withoutGlobalScope+withTrashed
- All 40 tests pass (1 skipped: self-registration not supported in Lernschiff)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-22 05:55:59 +02:00
Boban Blaskovic 331f6b2077 test(user): add parent-side cascade test, remove unused import 2026-05-22 05:20:16 +02:00
Boban Blaskovic 2fb1700075 test(user): soft-delete cascade + cross-tenant parent-child (Phase 5)
- UserSoftDeleteCascadeTest: verifies soft-delete cleans role_user,
  parent_child, license_assignments while keeping soft-deleted users row
- cross-tenant parent-child attach test confirms withoutGlobalScope works

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-22 05:17:47 +02:00
Boban Blaskovic 6de4131389 feat(license): EnsureActiveLicense full implementation + license/dashboard routes
- EnsureActiveLicense: full child-role check via licenseAssignments().isActive()
- License model: add isActive() method, fix fillable order, expires_at cast to date
- LicenseFactory: active/expired/inactive states
- routes/web.php: /dashboard with auth+license middleware, /lizenz-abgelaufen
- tests: EnsureActiveLicenseTest (3 tests — block/allow/teacher bypass)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-22 05:16:06 +02:00
Boban Blaskovic a099f2a4dc feat(auth): HasRole middleware with OR-semantics
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-22 01:41:10 +02:00
Boban Blaskovic 986f2afcff fix(tenant): forceDelete guard, hasRole eager-load, write-path test, migration timestamps
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-22 01:07:26 +02:00
Boban Blaskovic 1709f0f171 feat(models): Tenant, User, Role, ParentChild pivot + factories with withRole/withLicense
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-22 00:54:07 +02:00
Boban Blaskovic af49f091f5 feat(tenant): HasUuid + TenantScope (null-user default-deny) + BelongsToTenant
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-22 00:53:10 +02:00
Boban Blaskovic fe3b8d904f feat(testing): Pest v3 + Dusk + phpunit.xml.dist SESSION overrides + laravel/reverb
Installed pestphp/pest v4.7, pestphp/pest-plugin-laravel v4.1, laravel/dusk v8.6,
and laravel/reverb v1.10. Added phpunit.xml.dist and updated phpunit.xml with required
SESSION_SECURE_COOKIE=false, SESSION_DOMAIN=null, DB_CONNECTION=mysql overrides.
Created Browser/Smoke/AppReachableTest.php Dusk smoke test.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-22 00:32:10 +02:00
Boban Blaskovic 8eb1759d7e feat(scaffold): Laravel 12 scaffold + .env.example
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-22 00:19:49 +02:00