Commit Graph

12730 Commits (0eae871e40a0d1a15fad83c2850752a2cbe174a8)
 

Author SHA1 Message Date
Your Name 0eae871e40 fix: replace removed Passport scope middleware with current classes
Laravel Passport 13 renamed:
- CheckScopes → CheckToken (verifies ALL listed scopes)
- CheckForAnyScope → CheckTokenForAnyScope (verifies ANY listed scope)

The old class names no longer exist, causing BindingResolutionException
on all /api/v1/admin/* routes that use the 'scope' or 'scopes' middleware
aliases.
1 month ago
Your Name 579a581de8 test: add admin access and API scope security tests (360 total)
Security/AdminAccessTest: verifies non-admin users are blocked from
  all admin web routes (dashboard, users, reports, settings, instances,
  curated onboarding) and admin API endpoints.

Security/ApiScopeSecurityTest: verifies read-only tokens cannot write
  (follow, favourite, delete, mute, block), write tokens can read+write,
  cross-user access is denied, and private statuses are protected.

BUG FOUND: CheckForAnyScope middleware (referenced in v1/admin routes)
  was removed in Passport 13. All /api/v1/admin/* routes throw
  BindingResolutionException. 6 tests skipped pending fix.
1 month ago
Your Name 0f3820e7bf test: add notification, search, compose, report, and collection tests (332 total)
Api/NotificationTest: notification isolation, correct user filtering
Api/SearchTest: v2 search auth, structure, account lookup
Api/CollectionTest: self/user collections, auth requirement
Compose/ComposeTest: page access, settings, media validation, autocomplete
Account/ReportTest: report creation, type validation, auth requirement
1 month ago
Your Name e1f883a41b test: add status, timeline, federation, and privacy tests (309 total)
Api/StatusTest: get/delete statuses, favourite/unfavourite, bookmark,
  status creation validation, ownership checks
Api/TimelineTest: public/home/hashtag timelines, private exclusion,
  pagination support
Federation/NodeInfoTest: nodeinfo, webfinger, host-meta endpoints
Account/PrivacyTest: private profile visibility, blocked user access,
  privacy settings toggle
1 month ago
Your Name 891e282808 test: add settings, mute/block, and follow tests (278 total)
Settings/ProfileUpdateTest: profile name, bio, website validation,
  password change flow with Mail::fake assertion
Account/MuteBlockTest: mute/unmute, block/unblock, self-protection,
  admin block protection, validation
Account/FollowTest: follow/unfollow via API, self-follow rejection,
  followers/following list endpoints
1 month ago
Your Name 0ed3e6192a ci: fix action versions (checkout@v7, cache@v6) and add unstable branch 1 month ago
Your Name c7473cd1a8 ci: refactor GitHub Actions with Redis service and best practices
- Tests workflow: add Redis service, cache composer deps, test PHP 8.4+8.5,
  generate Passport keys, use vendor/bin/pest directly
- Larastan workflow: cache deps, consistent checkout@v4, memory limit
- Pint workflow: use project's installed Pint (not global), cache deps
- Standardize Redis port to 6379 across CI and local docker-compose
- Remove 'unstable' branch from triggers (unused)
- Remove 'main' branch from static analysis (doesn't exist)
1 month ago
Your Name 18c288f88f chore: add TODO to replace custom FrameGuard with Laravel built-in security headers 1 month ago
Your Name 4ce28d9144 feat: add framework integration tests for Laravel 12→13 upgrade readiness
Framework tests verify core Laravel integration points:
- ServiceProviderTest: app boot, guard resolution, route loading, config_cache
- RoutingTest: named routes, duplicates, api/oauth prefixes, middleware groups
- EloquentTest: User/Profile/Status factories, relationships, casts, soft deletes
- QueueTest: job dispatch, serialization, middleware, unique IDs
- ConfigTest: config loading, env overrides, auth/cache/queue settings
- MiddlewarePipelineTest: CSRF, auth, throttle, password confirm, 2FA, admin

Also:
- Add HasFactory trait to Status model
- Fix StatusFactory: remove non-existent 'place' column, add 'rendered' field
- Add Api/AccountTest for account endpoint coverage (254 total tests)
1 month ago
Your Name ec8a393020 test: expect oauth endpoints to return 200 (will pass after route syntax fix merge) 1 month ago
Your Name 97929f0876 fix: resolve str_ends_with TypeError in RegisterController
PHP's str_ends_with() only accepts a string needle, not an array.
The username validation was passing an array of extensions which
caused a TypeError on every registration attempt.

Replace with a loop over a configurable array of disallowed extensions,
making it easy to add new entries.

Also updates RegisterTest to properly test the registration flow
including the RT anti-bot token and age verification fields.
1 month ago
Your Name 8a2649b3ff feat: add critical path test suite and fix auth/config issues
Test Infrastructure:
- Modernize phpunit.xml (bootstrap, source block, Laravel 12 env vars)
- Configure tests/Pest.php with pest()->extend(TestCase::class)->in('Feature')
- Add docker-compose.test.yml (Redis for test suite)
- Add composer test/test:quick scripts
- Rename CACHE_DRIVER to CACHE_STORE across config (backwards compatible)
- Update .env.testing for in-memory SQLite + Docker Redis

Test Coverage (190 tests):
- CriticalRoutes: public routes, auth routes, API endpoints, middleware, schedule
- Auth/LoginTest: login, logout, rate limiting, redirect behavior
- Auth/RegisterTest: registration flow, validation, disabled registration
- Auth/PasswordResetTest: reset request, token validation, password update
- Auth/TwoFactorTest: 2FA checkpoint, setup behind password confirmation
- Auth/PasswordConfirmationTest: sudo mode flow via Laravel password.confirm
- Api/ScopeTest: scope enforcement, public endpoints, admin access

Bugs Fixed:
- Fix unauthenticated API returning 500 instead of 401 (AuthenticationException
  not handled in custom exception renderer in bootstrap/app.php)
- Replace custom DangerZone middleware with Laravel password.confirm
- Add HasFactory trait to Profile model for test factories

Bugs Documented (known-bugs group):
- Registration crashes with str_ends_with TypeError (RegisterController:82)
- OAuth routes use legacy array syntax causing ReflectionFunction TypeError
1 month ago
Shlee f7126ae5ba
Merge pull request #6852 from pixelfed/revert/phpstan-auth-scope
Revert
1 month ago
Your Name 1617734907 Revert "Merge pull request #6851 from pixelfed/fix/phpstan-auth-request-scope-2"
This reverts commit ce4baf6995, reversing
changes made to 9235cb979a.
1 month ago
Shlee ce4baf6995
Merge pull request #6851 from pixelfed/fix/phpstan-auth-request-scope-2
fix: replace Auth facade with $request->user() in request-scoped classes
1 month ago
Your Name 0939f495bb fix: replace Auth facade with $request->user() in request-scoped classes
Replace Auth::user() with $request->user() and Auth::check() with
$request->user() !== null (or ! $request->user()) across all
controllers and middleware that have access to the request object.

This resolves 99 larastan.noAuthFacadeInRequestScope errors and
improves Octane compatibility.

For protected helper methods without $request in scope, uses the
request() helper instead.

Methods that previously lacked a Request parameter but used Auth
facade now accept Request $request via Laravel's auto-injection.
1 month ago
Shlee 9235cb979a
Merge pull request #6850 from pixelfed/fix/phpstan-model-relations
fix: add return type declarations to Eloquent relation methods
1 month ago
Your Name f2159197e8 fix: add return type declarations to Eloquent relation methods
Larastan 3.x requires explicit return types on relation methods to
verify relation existence when using with(), has(), etc. This adds
the appropriate return type declarations to all relation methods
flagged by the larastan.relationExistence rule.

Models fixed:
- Profile (avatar, statuses)
- User (profile)
- Status (profile, media, hashtags)
- DirectMessage (status, author, recipient)
- Report (reporter, status, reportedUser)
- Like (actor, status)
- Media (status)
- Notification (item)
- HashtagFollow (hashtag)
- OauthClient (user)
- Story (profile)
- StatusHashtag (status, hashtag, profile, media)
- AccountInterstitial (user)
- Hashtag (posts)
- CustomFilter (keywords)
- CustomFilterKeyword (customFilter)
- AdminShadowFilter (profile)
- ImportPost (status)
1 month ago
Shlee baa7774378
Merge pull request #6849 from pixelfed/fix/groups-post-undefined-status
fix: resolve undefined $status variable in GroupsPostController
1 month ago
Your Name e7ef58969c fix: resolve undefined $status variable in GroupsPostController::deletePost
Replace all references to non-existent $status with $gp (the GroupPost
instance already in scope). This was a bug where the closure variable
name was changed but references inside the method body were not updated.
1 month ago
Shlee fe9eae770e
Merge pull request #6848 from pixelfed/larascan
fix: replace backslash-prefixed facade calls with imported references
1 month ago
Your Name 7c964f3b4f fix: replace backslash-prefixed facade calls with imported references
Replace \Cache::, \Log::, \DB:: calls with their imported facade
equivalents. The backslash-prefix relies on global aliases which
PHPStan cannot resolve, causing class.notFound errors.
1 month ago
Shlee e86f424ec0
Merge pull request #6847 from pixelfed/larascan
Larascan level 0 fixes
1 month ago
Shlee 4bb9edcb22
Update StoryService.php 1 month ago
Shlee 58a34056ca
Update TimelineController.php 1 month ago
Shlee 942e15c652
Update StoryService.php 1 month ago
Shlee 2bc40e38f8
Merge pull request #6844 from pixelfed/fix/phpstan-static-method-not-found
fix: remove call to non-existent PollService::storyPoll()
1 month ago
Shlee c315b60867
Merge pull request #6843 from pixelfed/fix/phpstan-unnecessary-collection-call
fix: use query methods instead of collection methods
1 month ago
Shlee b7626891df
Merge pull request #6845 from pixelfed/fix/phpstan-variable-undefined
fix: resolve undefined variable bugs (phpstan variable.undefined)
1 month ago
Shlee 8e35d4cb21
Merge pull request #6846 from pixelfed/fix/phpstan-class-not-found
fix: add missing use imports to resolve phpstan class.notFound errors
1 month ago
Shlee 5feacc5e89
Merge pull request #6842 from pixelfed/fix/phpstan-property-not-found
fix: add missing property declarations (phpstan property.notFound)
1 month ago
Your Name e7ba43e2e1 fix: add missing use imports to resolve phpstan class.notFound errors
Add missing imports for Log, Cache, DB, FollowerService, StatusService,
LikeService, ReblogService, UserFilterService, AdminProfile, OauthClient,
and fix StatusTimelineTransformer reference (class didn't exist, replaced
with StatusTransformer).
1 month ago
Your Name 7bde84b23c fix: remove call to non-existent PollService::storyPoll()
The storyPoll() method was never implemented on PollService.
Replace with null to fix phpstan staticMethod.notFound.

Note: Passport::personalAccessClientId() is also flagged but deferred
to a separate PAT refactoring effort.
1 month ago
Your Name 49b85e9f22 fix: use query methods instead of collection methods (phpstan noUnnecessaryCollectionCall)
- PollService: pluck()->first() → value()
- StoryService: groupBy()->pluck()->count() → distinct()->count()
- Inbox: find($objects)->count() → whereIn('id', $objects)->count()
1 month ago
Your Name ccd75dd903 fix: resolve undefined variable bugs (phpstan variable.undefined)
- AdminReportController: fix closure param name and remove reference to
  undefined $meta variable
- GroupsPostController: replace $status with $gp (the actual GroupPost
  variable in scope)
- PortfolioController: replace undefined $metadata with null
- DeleteWorker: remove Cache::set() call with undefined $key
1 month ago
Your Name 43040a2275 fix: add missing property declarations (phpstan property.notFound)
- Add $fractal property and initialization to NewPublicPost event
- Add $mastodon and $pleroma property declarations to AudienceScopeTest
1 month ago
Shlee d048ce74d6
Merge pull request #6841 from pixelfed/shleeable-patch-1
Update CHANGELOG.md
1 month ago
Shlee eeda06cee8
Update CHANGELOG.md
Updated changelog with recent refactor details and fixes.
1 month ago
Shlee 636cc67a55
Merge pull request #6840 from pixelfed/fix/missing-feedunfollowpipeline-import
fix: add missing FeedUnfollowPipeline import
1 month ago
Shlee 2289c87981
Merge pull request #6839 from pixelfed/refactor/phpstan-config-best-practices
refactor: update phpstan.neon with Larastan 3.x best practices
1 month ago
Shlee d8a122a9cd
Update phpstan.neon 1 month ago
Your Name 58efefb878 fix: add missing FeedUnfollowPipeline import
Add missing use statement for FeedUnfollowPipeline in PrivacySettings
and FollowerObserver. These caused PHPStan internal errors blocking
full analysis.
1 month ago
Your Name 890dc55342 refactor: update phpstan.neon with Larastan 3.x best practices
- Add databaseMigrationsPath for model property type inference
- Add configDirectories for config key validation
- Add parseModelCastsMethod to read casts() methods
- Add enableMigrationCache for faster repeated analysis
- Ignore intentional 'new static()' pattern (Autolink has subclass)
- Remove stale baseline reference and outdated comments
1 month ago
Shlee fc3dd0db4e
Merge pull request #6838 from pixelfed/shleeable-patch-2
Delete phpstan-baseline.neon
1 month ago
Shlee afbbd9ea01
Update phpstan.neon 1 month ago
Shlee 412ac5fd97
Delete phpstan-baseline.neon 1 month ago
Shlee ab2d06c082
Merge pull request #6837 from pixelfed/shleeable-patch-1
Update docker-tag.yml
1 month ago
Shlee 28a56d047e
Update docker-push.yml 1 month ago
Shlee de656d12dc
Update docker-tag.yml 1 month ago
Shlee 31aedf9464
Merge pull request #6836 from pixelfed/shleeable-patch-1
Update CHANGELOG.md
1 month ago