Commit Graph

12778 Commits (1696dfacaa86c4b98b5ff629b75c9936db6ec621)
 

Author SHA1 Message Date
Your Name 1696dfacaa chore: remove unused direct dependencies
- Remove endroid/qr-code: never imported in app code; only
  bacon/bacon-qr-code is used directly (for 2FA QR generation).
- Remove nesbot/carbon: already pulled in transitively by
  laravel/framework, laravel/horizon, and laravel/pulse.
1 month ago
Shlee 1f3e472a7e
Merge pull request #6875 from pixelfed/fix/unpin-symfony-http-foundation
fix: unpin symfony/http-foundation to allow patch updates
1 month ago
Your Name 0c849ca4e7 fix: unpin symfony/http-foundation to allow patch updates
Changes constraint from exact '7.4.13' to '^7.4.13'. The pin was
introduced for CVE-2026-48736 but is overly restrictive — any 7.4.x
release >= 7.4.13 includes the fix. This allows future security
patches to install via composer update.

Note: Symfony 8.x is blocked by laravel/framework ^12 which requires
symfony/http-foundation ^7.2.0. Symfony 8 support arrives with Laravel 13.
1 month ago
Shlee f81d7ba666
Merge pull request #6873 from pixelfed/fix/deprecated-starts-with
fix: replace deprecated starts_with() with str_starts_with()
1 month ago
Your Name 26b8a0a6b0 fix: replace deprecated starts_with() with str_starts_with()
The starts_with() helper was removed in Laravel 6. Use PHP 8's native
str_starts_with() instead.
1 month ago
Shlee cf714c6fb7
Merge pull request #6872 from pixelfed/larastan0
refactor: replace $fillable with $guarded = [] across all models
1 month ago
Your Name 570a30d037 refactor: replace $fillable with $guarded = [] across all models
Aligns all models with the project convention (see .ai/rules/models.md).
Model::shouldBeStrict() in non-production will catch any issues early.
1 month ago
Shlee 2fbb9fa428
Merge pull request #6871 from pixelfed/larastan0
polish
1 month ago
Your Name c891f34df6 polish 1 month ago
Shlee b5c9f2d062
Merge pull request #6870 from pixelfed/shleeable-patch-1
Update DOCKER_COMPOSE_SETUP.md
1 month ago
Shlee 4086f07783
Fix duplicate command in Docker Compose setup 1 month ago
Shlee e2c6162b35
Update DOCKER_COMPOSE_SETUP.md 1 month ago
Shlee 1b3c8150b0
Merge pull request #6869 from pixelfed/larastan0
Larastan0
1 month ago
Your Name f54e6280bc comment dead code 1 month ago
Your Name ea2d054a40 Revert "fix: remove dead publicApi/homeApi methods from TimelineController"
This reverts commit 8cf5321566.
1 month ago
Your Name 8cf5321566 fix: remove dead publicApi/homeApi methods from TimelineController
- publicApi referenced non-existent StatusTimelineTransformer class
- Neither method is routed anywhere
- Removes unused imports (Fractal, Cache, Status, Profile, UserFilter)
1 month ago
Shlee d4fc25907c
Merge pull request #6868 from pixelfed/larastan0
fix: remove dead RemoteFollowPipeline (old code before AP)
1 month ago
Your Name 7042ea5367 fix: remove dead RemoteFollowPipeline (references uninstalled HttpSignatures package)
- Delete app/Jobs/RemoteFollowPipeline/RemoteFollowPipeline.php
- Delete app/Jobs/RemoteFollowPipeline/RemoteFollowImportRecent.php
- Neither job is dispatched anywhere in the codebase
- Remote follow is handled by ActivityPub Inbox and FollowPipeline
1 month ago
Shlee eb8806f37d
Merge pull request #6867 from pixelfed/fix/passport-v13-cleanup
fix: remove deprecated Passport::personalAccessClientId()
1 month ago
Your Name 5a364be58b fix: remove deprecated Passport::personalAccessClientId() and enableImplicitGrant()
- Remove Passport::personalAccessClientId() (removed in Passport v13, auto-discovers now)
- Remove Passport::enableImplicitGrant() (legacy grant, no clients use it)
- Flatten config instance.oauth.pat to pat_enabled (remove dead pat.id key)
- Add OAUTH_PAT_ENABLED=false to .env.example and .env.docker.example
- Show swal alert when PATs disabled instead of hidden API error
- Improve store() error handling to surface 403 messages in the UI
- Remove OAUTH_PAT_ID row from admin diagnostics blade
1 month ago
Shlee 190e7da6e1
Merge pull request #6866 from pixelfed/tests/critical-path-smoke-tests
Tests/critical path smoke tests
1 month ago
Your Name 6a34458c3a Merge branch 'staging' into tests/critical-path-smoke-tests
# Conflicts:
#	app/Http/Controllers/Settings/ExportSettings.php
#	app/Http/Controllers/Settings/HomeSettings.php
#	app/Http/Controllers/Settings/PrivacySettings.php
#	app/Http/Controllers/Settings/SecuritySettings.php
#	app/Http/Controllers/SettingsController.php
1 month ago
Shlee 6dd0604133
Merge pull request #6865 from pixelfed/shleeable-patch-1
Update AccountController.php
1 month ago
Shlee 3c6280111e
Update AccountController.php 1 month ago
Shlee 8778273c7c
Merge pull request #6854 from pixelfed/fix/phpstan-auth-request-scope-3
Larascan: Replace Auth::user() with $request->user()
1 month ago
Your Name ffcef3eb2d fix: replace Auth facade with $request->user() in request-scoped classes
Replace Auth::user() with $request->user() and Auth::check() with
$request->user() !== null (or ! $request->user()) across all
controllers and middleware that have access to the request object.

This resolves 99 larastan.noAuthFacadeInRequestScope errors and
improves Octane compatibility.

For protected helper methods without $request in scope, uses the
request() helper instead.

Methods that previously lacked a Request parameter but used Auth
facade now accept Request $request via Laravel's auto-injection.
1 month ago
Shlee 827a56be00
Merge pull request #6861 from pixelfed/tests/critical-path-smoke-tests-clean
Tests/critical path smoke tests clean
1 month ago
Your Name 47d98bfb55 revert: restore original GitHub Actions workflow names 1 month ago
Your Name a486f509a5 test: add auth scope migration tests and update CI action versions
AuthScope/RequestUserTest: 22 tests verifying all controllers and
middleware that were migrated from Auth::user() to $request->user().
CI: update to checkout@v7, cache@v6
1 month ago
Your Name 918e49136a test: add auth scope migration verification tests (390 total, all green)
AuthScope/RequestUserTest: exercises every controller and middleware
that was refactored from Auth::user()/Auth::check() to $request->user().
Covers web routes (follow requests, compose, collections, discover,
profile, status, timeline, newsroom), API routes (verify_credentials,
timelines, notifications, blocks, mutes, favourites, bookmarks), and
middleware (admin, password.confirm, account interstitial).

All 390 tests pass with the auth-scope-3 and passport middleware fixes
applied together.
1 month ago
Shlee 71c755a807
Merge pull request #6860 from pixelfed/tests/critical-path-smoke-tests
Tests/critical path smoke tests
1 month ago
Your Name b4e9a20af0 Merge remote-tracking branch 'origin/fix/phpstan-auth-request-scope-3' into tests/critical-path-smoke-tests
# Conflicts:
#	app/Http/Controllers/AccountController.php
1 month ago
Your Name 9f81a5b425 test: un-skip Passport scope tests now that middleware is fixed
All v1 admin route security tests now pass with proper assertions
after the CheckForAnyScope → CheckTokenForAnyScope fix.
1 month ago
Shlee bed4efa77e
Merge pull request #6859 from pixelfed/fix/passport-scope-middleware
fix: replace removed Passport scope middleware with current classes
1 month ago
Your Name 0eae871e40 fix: replace removed Passport scope middleware with current classes
Laravel Passport 13 renamed:
- CheckScopes → CheckToken (verifies ALL listed scopes)
- CheckForAnyScope → CheckTokenForAnyScope (verifies ANY listed scope)

The old class names no longer exist, causing BindingResolutionException
on all /api/v1/admin/* routes that use the 'scope' or 'scopes' middleware
aliases.
1 month ago
Your Name 7a96cd2e91 fix: replace removed Passport scope middleware with current classes
Laravel Passport 13 renamed:
- CheckScopes → CheckToken (verifies ALL listed scopes)
- CheckForAnyScope → CheckTokenForAnyScope (verifies ANY listed scope)

The old class names no longer exist, causing BindingResolutionException
on all /api/v1/admin/* routes that use the 'scope' or 'scopes' middleware
aliases.
1 month ago
Shlee 8078255c2e
Merge pull request #6858 from pixelfed/tests/critical-path-smoke-tests
Tests/critical path smoke tests
1 month ago
Your Name 579a581de8 test: add admin access and API scope security tests (360 total)
Security/AdminAccessTest: verifies non-admin users are blocked from
  all admin web routes (dashboard, users, reports, settings, instances,
  curated onboarding) and admin API endpoints.

Security/ApiScopeSecurityTest: verifies read-only tokens cannot write
  (follow, favourite, delete, mute, block), write tokens can read+write,
  cross-user access is denied, and private statuses are protected.

BUG FOUND: CheckForAnyScope middleware (referenced in v1/admin routes)
  was removed in Passport 13. All /api/v1/admin/* routes throw
  BindingResolutionException. 6 tests skipped pending fix.
1 month ago
Your Name 0f3820e7bf test: add notification, search, compose, report, and collection tests (332 total)
Api/NotificationTest: notification isolation, correct user filtering
Api/SearchTest: v2 search auth, structure, account lookup
Api/CollectionTest: self/user collections, auth requirement
Compose/ComposeTest: page access, settings, media validation, autocomplete
Account/ReportTest: report creation, type validation, auth requirement
1 month ago
Your Name e1f883a41b test: add status, timeline, federation, and privacy tests (309 total)
Api/StatusTest: get/delete statuses, favourite/unfavourite, bookmark,
  status creation validation, ownership checks
Api/TimelineTest: public/home/hashtag timelines, private exclusion,
  pagination support
Federation/NodeInfoTest: nodeinfo, webfinger, host-meta endpoints
Account/PrivacyTest: private profile visibility, blocked user access,
  privacy settings toggle
1 month ago
Your Name 891e282808 test: add settings, mute/block, and follow tests (278 total)
Settings/ProfileUpdateTest: profile name, bio, website validation,
  password change flow with Mail::fake assertion
Account/MuteBlockTest: mute/unmute, block/unblock, self-protection,
  admin block protection, validation
Account/FollowTest: follow/unfollow via API, self-follow rejection,
  followers/following list endpoints
1 month ago
Shlee 5ea0a1fc13
Merge pull request #6857 from pixelfed/shleeable-patch-1
Update CHANGELOG.md
1 month ago
Shlee df99433689
Revise CHANGELOG.md for recent updates
Updated changelog to reflect recent changes and fixes.
1 month ago
Shlee f6a3df88d1
Update CHANGELOG.md
Updated changelog to reflect recent refactors and testing improvements.
1 month ago
Shlee 25256af551
Merge pull request #6856 from pixelfed/tests/critical-path-smoke-tests
MAJOR TESTING REFACTORING - 250+ Passing Tests
1 month ago
Shlee 0f6ed0d918
Rename workflow to PHP - Pint 1 month ago
Shlee 2adbb65079
Update php-laravel-tests.yml 1 month ago
Shlee b2af987888
Update php-larastan.yml 1 month ago
Your Name 0ed3e6192a ci: fix action versions (checkout@v7, cache@v6) and add unstable branch 1 month ago
Your Name c7473cd1a8 ci: refactor GitHub Actions with Redis service and best practices
- Tests workflow: add Redis service, cache composer deps, test PHP 8.4+8.5,
  generate Passport keys, use vendor/bin/pest directly
- Larastan workflow: cache deps, consistent checkout@v4, memory limit
- Pint workflow: use project's installed Pint (not global), cache deps
- Standardize Redis port to 6379 across CI and local docker-compose
- Remove 'unstable' branch from triggers (unused)
- Remove 'main' branch from static analysis (doesn't exist)
1 month ago