1 Commits

Author SHA1 Message Date
Sebastian fb657a1f64 chore(deps): update dependency vuetify to v4.1.7
Build Test / build (pull_request) Successful in 17s
JS Unit Tests / test (pull_request) Successful in 15s
PHP Unit Tests / test (pull_request) Failing after 1m17s
PHP Integration Tests / Integration Tests (pull_request) Failing after 1m20s
2026-08-04 03:01:49 +00:00
140 changed files with 1049 additions and 6720 deletions
Generated
+8 -8
View File
@@ -4,7 +4,7 @@
"Read more about it at https://getcomposer.org/doc/01-basic-usage.md#installing-dependencies",
"This file is @generated automatically"
],
"content-hash": "25e4604f76b54a60904f1517dd3b210d",
"content-hash": "68916c1b58d9ce06a59f6c58e4a2d226",
"packages": [
{
"name": "laravel/serializable-closure",
@@ -606,16 +606,16 @@
},
{
"name": "symfony/console",
"version": "v7.4.18",
"version": "v7.4.14",
"source": {
"type": "git",
"url": "https://github.com/symfony/console.git",
"reference": "23d6f88a29f6d0eac45bd77d70307adf83ba7ab0"
"reference": "92f58bc4bf97a92ed1b9f367f0cd44f20bde0e87"
},
"dist": {
"type": "zip",
"url": "https://api.github.com/repos/symfony/console/zipball/23d6f88a29f6d0eac45bd77d70307adf83ba7ab0",
"reference": "23d6f88a29f6d0eac45bd77d70307adf83ba7ab0",
"url": "https://api.github.com/repos/symfony/console/zipball/92f58bc4bf97a92ed1b9f367f0cd44f20bde0e87",
"reference": "92f58bc4bf97a92ed1b9f367f0cd44f20bde0e87",
"shasum": ""
},
"require": {
@@ -680,7 +680,7 @@
"terminal"
],
"support": {
"source": "https://github.com/symfony/console/tree/v7.4.18"
"source": "https://github.com/symfony/console/tree/v7.4.14"
},
"funding": [
{
@@ -700,7 +700,7 @@
"type": "tidelift"
}
],
"time": "2026-08-25T14:18:37+00:00"
"time": "2026-06-16T11:50:14+00:00"
},
{
"name": "symfony/deprecation-contracts",
@@ -3057,5 +3057,5 @@
"ext-iconv": "*"
},
"platform-dev": {},
"plugin-api-version": "2.9.0"
"plugin-api-version": "2.6.0"
}
@@ -15,9 +15,6 @@ final readonly class TerminationReport
public array $failures = [],
public bool $deadlineExceeded = false,
public bool $limitExceeded = false,
public int $deferredListenerInvocations = 0,
public bool $deferredEventLimitExceeded = false,
public bool $deferredListenerInvocationLimitExceeded = false,
) {
}
}
@@ -4,7 +4,7 @@ declare(strict_types=1);
namespace KTXC\Console\Event;
use KTXC\Event\EventListenerRegistry;
use KTXF\Event\EventListenerRegistry;
use Symfony\Component\Console\Attribute\AsCommand;
use Symfony\Component\Console\Command\Command;
use Symfony\Component\Console\Input\InputInterface;
@@ -4,12 +4,10 @@ declare(strict_types=1);
namespace KTXC\Console\Tenant;
use KTXC\Context\TenantContext;
use KTXC\Models\Tenant\DomainCollection;
use KTXC\Models\Tenant\TenantConfiguration;
use KTXC\Models\Tenant\TenantObject;
use KTXC\Service\TenantService;
use KTXC\Service\UserAccountsService;
use KTXC\Stores\UserAccountsStore;
use KTXC\Stores\UserRolesStore;
use KTXF\Utile\UUID;
@@ -37,8 +35,6 @@ class TenantCreateCommand extends Command
private readonly TenantService $tenantService,
private readonly UserRolesStore $rolesStore,
private readonly UserAccountsStore $userStore,
private readonly UserAccountsService $userService,
private readonly TenantContext $tenantContext,
private readonly LoggerInterface $logger
) {
parent::__construct();
@@ -101,10 +97,6 @@ class TenantCreateCommand extends Command
$io->error('Failed to create tenant.');
return Command::FAILURE;
}
if (!$this->tenantContext->resolveIdentifier($identifier)) {
throw new \RuntimeException("Failed to initialize tenant context for '{$identifier}'.");
}
$identifier = $this->tenantContext->requireIdentifier();
$this->logger->info('Tenant created via console', [
'identifier' => $identifier,
@@ -142,7 +134,7 @@ class TenantCreateCommand extends Command
if ($this->userStore->fetchByIdentity($identifier, $adminIdentity)) {
$io->warning("User '{$adminIdentity}' already exists in tenant '{$identifier}'; skipping admin user creation.");
} else {
$this->userService->createUser([
$this->userStore->createUser($identifier, [
'identity' => $adminIdentity,
'label' => 'Administrator',
'enabled' => true,
@@ -1,51 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Console\Tenant;
use KTXC\SystemStore\SystemStoreConfigurationService;
use Symfony\Component\Console\Attribute\AsCommand;
use Symfony\Component\Console\Command\Command;
use Symfony\Component\Console\Input\InputArgument;
use Symfony\Component\Console\Input\InputInterface;
use Symfony\Component\Console\Output\OutputInterface;
use Symfony\Component\Console\Style\SymfonyStyle;
#[AsCommand(name: 'tenant:store:list', description: 'List logical stores configured for a tenant')]
class TenantStoreListCommand extends Command
{
public function __construct(private readonly SystemStoreConfigurationService $stores)
{
parent::__construct();
}
protected function configure(): void
{
$this->addArgument('tenant', InputArgument::REQUIRED, 'Tenant identifier');
}
protected function execute(InputInterface $input, OutputInterface $output): int
{
$io = new SymfonyStyle($input, $output);
$tenant = (string) $input->getArgument('tenant');
try {
$stores = $this->stores->list($tenant);
if ($stores === []) {
$io->text("No logical stores configured for tenant '{$tenant}'.");
return Command::SUCCESS;
}
$rows = [];
foreach ($stores as $name => $store) {
$rows[] = [$name, $store->provider, (string) $store->service, $store->namespace];
}
$io->table(['Name', 'Provider', 'Service', 'Namespace'], $rows);
return Command::SUCCESS;
} catch (\Throwable $error) {
$io->error('Failed to list tenant stores: ' . $error->getMessage());
return Command::FAILURE;
}
}
}
@@ -1,58 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Console\Tenant;
use KTXC\SystemStore\SystemStoreConfigurationService;
use Psr\Log\LoggerInterface;
use Symfony\Component\Console\Attribute\AsCommand;
use Symfony\Component\Console\Command\Command;
use Symfony\Component\Console\Input\InputArgument;
use Symfony\Component\Console\Input\InputInterface;
use Symfony\Component\Console\Output\OutputInterface;
use Symfony\Component\Console\Style\SymfonyStyle;
#[AsCommand(name: 'tenant:store:remove', description: 'Remove a logical store from a tenant')]
class TenantStoreRemoveCommand extends Command
{
public function __construct(
private readonly SystemStoreConfigurationService $stores,
private readonly LoggerInterface $logger,
) {
parent::__construct();
}
protected function configure(): void
{
$this
->addArgument('tenant', InputArgument::REQUIRED, 'Tenant identifier')
->addArgument('name', InputArgument::REQUIRED, 'Logical store name');
}
protected function execute(InputInterface $input, OutputInterface $output): int
{
$io = new SymfonyStyle($input, $output);
$tenant = (string) $input->getArgument('tenant');
$name = (string) $input->getArgument('name');
try {
if (!$this->stores->remove($tenant, $name)) {
$io->warning("Logical store '{$name}' was not configured for tenant '{$tenant}'.");
return Command::SUCCESS;
}
$this->logger->info('Tenant logical store removed via console', compact('tenant', 'name'));
$io->success("Logical store '{$name}' removed from tenant '{$tenant}'.");
return Command::SUCCESS;
} catch (\Throwable $error) {
$this->logger->error('Tenant logical store removal failed', [
'tenant' => $tenant,
'name' => $name,
'error' => $error->getMessage(),
]);
$io->error('Failed to remove tenant store: ' . $error->getMessage());
return Command::FAILURE;
}
}
}
@@ -1,62 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Console\Tenant;
use KTXC\SystemStore\SystemStoreConfigurationService;
use Psr\Log\LoggerInterface;
use Symfony\Component\Console\Attribute\AsCommand;
use Symfony\Component\Console\Command\Command;
use Symfony\Component\Console\Input\InputArgument;
use Symfony\Component\Console\Input\InputInterface;
use Symfony\Component\Console\Output\OutputInterface;
use Symfony\Component\Console\Style\SymfonyStyle;
#[AsCommand(name: 'tenant:store:set', description: 'Configure a logical store for a tenant')]
class TenantStoreSetCommand extends Command
{
public function __construct(
private readonly SystemStoreConfigurationService $stores,
private readonly LoggerInterface $logger,
) {
parent::__construct();
}
protected function configure(): void
{
$this
->addArgument('tenant', InputArgument::REQUIRED, 'Tenant identifier')
->addArgument('name', InputArgument::REQUIRED, 'Logical store name, such as previews')
->addArgument('provider', InputArgument::REQUIRED, 'System-store provider identifier')
->addArgument('service', InputArgument::REQUIRED, 'System-store service identifier')
->addArgument('namespace', InputArgument::REQUIRED, 'Provider key namespace');
}
protected function execute(InputInterface $input, OutputInterface $output): int
{
$io = new SymfonyStyle($input, $output);
$tenant = (string) $input->getArgument('tenant');
$name = (string) $input->getArgument('name');
$provider = (string) $input->getArgument('provider');
$service = (string) $input->getArgument('service');
$namespace = (string) $input->getArgument('namespace');
try {
$this->stores->set($tenant, $name, $provider, $service, $namespace);
$this->logger->info('Tenant logical store configured via console', compact(
'tenant', 'name', 'provider', 'service', 'namespace',
));
$io->success("Logical store '{$name}' configured for tenant '{$tenant}'.");
return Command::SUCCESS;
} catch (\Throwable $error) {
$this->logger->error('Tenant logical store configuration failed', [
'tenant' => $tenant,
'name' => $name,
'error' => $error->getMessage(),
]);
$io->error('Failed to configure tenant store: ' . $error->getMessage());
return Command::FAILURE;
}
}
}
+5 -7
View File
@@ -4,8 +4,7 @@ declare(strict_types=1);
namespace KTXC\Console\User;
use KTXC\Context\TenantContext;
use KTXC\Service\UserAccountsService;
use KTXC\Service\TenantService;
use KTXC\Stores\UserAccountsStore;
use KTXC\Stores\UserRolesStore;
use Psr\Log\LoggerInterface;
@@ -29,9 +28,8 @@ use Symfony\Component\Console\Style\SymfonyStyle;
class UserCreateCommand extends Command
{
public function __construct(
private readonly TenantContext $tenantContext,
private readonly TenantService $tenantService,
private readonly UserAccountsStore $userStore,
private readonly UserAccountsService $userService,
private readonly UserRolesStore $rolesStore,
private readonly LoggerInterface $logger
) {
@@ -61,11 +59,11 @@ class UserCreateCommand extends Command
$io->title('Create User');
try {
if (!$this->tenantContext->resolveIdentifier($tenant)) {
// Ensure the tenant exists
if (!$this->tenantService->fetchById($tenant)) {
$io->error("Tenant '{$tenant}' not found.");
return Command::FAILURE;
}
$tenant = $this->tenantContext->requireIdentifier();
// Ensure identity is unique within the tenant
if ($this->userStore->fetchByIdentity($tenant, $identity)) {
@@ -97,7 +95,7 @@ class UserCreateCommand extends Command
$userData['uid'] = $input->getOption('uid');
}
$user = $this->userService->createUser($userData);
$user = $this->userStore->createUser($tenant, $userData);
$this->logger->info('User created via console', [
'tenant' => $tenant,
+1 -11
View File
@@ -4,8 +4,6 @@ declare(strict_types=1);
namespace KTXC\Console\User;
use KTXC\Context\TenantContext;
use KTXC\Service\UserAccountsService;
use KTXC\Stores\UserAccountsStore;
use Psr\Log\LoggerInterface;
use Symfony\Component\Console\Attribute\AsCommand;
@@ -28,9 +26,7 @@ use Symfony\Component\Console\Style\SymfonyStyle;
class UserDeleteCommand extends Command
{
public function __construct(
private readonly TenantContext $tenantContext,
private readonly UserAccountsStore $userStore,
private readonly UserAccountsService $userService,
private readonly LoggerInterface $logger
) {
parent::__construct();
@@ -56,12 +52,6 @@ class UserDeleteCommand extends Command
$io->title('Delete User');
try {
if (!$this->tenantContext->resolveIdentifier($tenant)) {
$io->error("Tenant '{$tenant}' not found.");
return Command::FAILURE;
}
$tenant = $this->tenantContext->requireIdentifier();
$user = $this->userStore->fetchByIdentity($tenant, $identity);
if (!$user) {
@@ -74,7 +64,7 @@ class UserDeleteCommand extends Command
return Command::SUCCESS;
}
if (!$this->userService->deleteUser($user['uid'])) {
if (!$this->userStore->deleteUser($tenant, $user['uid'])) {
$io->error("Failed to delete user '{$identity}'.");
return Command::FAILURE;
}
@@ -92,9 +92,9 @@ class AuthenticationController extends ControllerAbstract
}
$request = AuthenticationRequest::verify($session, $method, $response);
$response = $this->authManager->handle($request);
$authResponse = $this->authManager->handle($request);
return $this->buildJsonResponse($response);
return $this->buildJsonResponse($authResponse);
}
/**
@@ -120,8 +120,8 @@ class AuthenticationController extends ControllerAbstract
$host = $request->getHost();
$callbackUrl = "{$scheme}://{$host}/auth/callback/{$method}";
$request = AuthenticationRequest::redirect($sessionId, $method, $callbackUrl, $returnUrl);
$response = $this->authManager->handle($request);
$authRequest = AuthenticationRequest::redirect($sessionId, $method, $callbackUrl, $returnUrl);
$response = $this->authManager->handle($authRequest);
return $this->buildJsonResponse($response);
}
@@ -142,8 +142,8 @@ class AuthenticationController extends ControllerAbstract
return $this->redirectWithError('Missing state parameter');
}
$request = AuthenticationRequest::callback($sessionId, $provider, $params);
$response = $this->authManager->handle($request);
$authRequest = AuthenticationRequest::callback($sessionId, $provider, $params);
$response = $this->authManager->handle($authRequest);
if ($response->isSuccess()) {
$returnUrl = $response->returnUrl ?? '/';
@@ -178,8 +178,8 @@ class AuthenticationController extends ControllerAbstract
);
}
$request = AuthenticationRequest::status($sessionId);
$response = $this->authManager->handle($request);
$authRequest = AuthenticationRequest::status($sessionId);
$response = $this->authManager->handle($authRequest);
return $this->buildJsonResponse($response);
}
@@ -192,8 +192,8 @@ class AuthenticationController extends ControllerAbstract
{
$sessionId = $request->query->get('session', '');
$request = AuthenticationRequest::cancel($sessionId);
$this->authManager->handle($request);
$authRequest = AuthenticationRequest::cancel($sessionId);
$this->authManager->handle($authRequest);
return new JsonResponse(['status' => 'cancelled', 'message' => 'Session cancelled']);
}
@@ -217,8 +217,8 @@ class AuthenticationController extends ControllerAbstract
);
}
$request = AuthenticationRequest::refresh($refreshToken);
$response = $this->authManager->handle($request);
$authRequest = AuthenticationRequest::refresh($refreshToken);
$response = $this->authManager->handle($authRequest);
if ($response->isFailed()) {
$httpResponse = new JsonResponse($response->toArray(), $response->httpStatus);
@@ -259,8 +259,8 @@ class AuthenticationController extends ControllerAbstract
{
$token = $request->cookies->get('accessToken');
$request = AuthenticationRequest::logout($token, false);
$this->authManager->handle($request);
$authRequest = AuthenticationRequest::logout($token, false);
$this->authManager->handle($authRequest);
$response = new JsonResponse(['status' => 'success', 'message' => 'Logged out successfully']);
return $this->clearTokenCookies($response);
@@ -274,8 +274,8 @@ class AuthenticationController extends ControllerAbstract
{
$token = $request->cookies->get('accessToken');
$request = AuthenticationRequest::logout($token, true);
$this->authManager->handle($request);
$authRequest = AuthenticationRequest::logout($token, true);
$this->authManager->handle($authRequest);
$response = new JsonResponse(['status' => 'success', 'message' => 'Logged out from all devices']);
return $this->clearTokenCookies($response);
+5 -10
View File
@@ -6,7 +6,6 @@ use KTXC\Http\Request\Request;
use KTXC\Http\Response\JsonResponse;
use KTXC\L10N\LocaleResolver;
use KTXC\Module\ModuleManager;
use KTXC\Module\Configuration\BrowserModuleContext;
use KTXC\Security\Authorization\PermissionChecker;
use KTXC\Service\UserAccountsService;
use KTXC\Context\IdentityContextInterface;
@@ -31,11 +30,7 @@ class InitController extends ControllerAbstract
$configuration = [];
// modules - filter by permissions
$browserContext = new BrowserModuleContext(
$this->tenantContext->requireIdentifier(),
$this->identityContext->requireIdentifier(),
);
$configuration['modules'] = [];
foreach ($this->moduleManager->list(true, true) as $module) {
// Check if user has permission to view this module
// Allow access if user has: {module_handle}, {module_handle}.*, or * permission
@@ -44,12 +39,12 @@ class InitController extends ControllerAbstract
continue;
}
$module->configure($browserContext);
$integrations = $module->registerBI();
if ($integrations !== null) {
$configuration['modules'][$handle] = $integrations;
}
}
$configuration['modules'] = $browserContext->modules();
$configuration = array_merge($configuration, $browserContext->configuration());
// localization
$configuration['l10n'] = [
'locale' => $this->localeResolver->resolve($request),
-161
View File
@@ -1,161 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Event;
use KTXF\Event\DeliveryMode;
use KTXF\Event\Event;
use KTXF\Event\EventDispatcherInterface;
use KTXF\Event\FailurePolicy;
use Psr\Container\ContainerInterface;
use Psr\Log\LoggerInterface;
final class EventDispatcher implements EventDispatcherInterface, DeferredEventProcessorInterface
{
private const DEFAULT_DEFERRED_PROCESSING_TIMEOUT_SECONDS = 300.0;
private const DEFAULT_MAX_DEFERRED_EVENTS = 1000;
private const DEFAULT_MAX_DEFERRED_LISTENER_INVOCATIONS = 50000;
/** @var array<string, list<Event>> */
private array $deferred = [];
private ?string $activeExecution = null;
private int $dispatchDepth = 0;
public function __construct(
private readonly EventListenerRegistry $registry,
private readonly ContainerInterface $container,
private readonly LoggerInterface $logger,
private readonly float $deferredProcessingTimeoutSeconds = self::DEFAULT_DEFERRED_PROCESSING_TIMEOUT_SECONDS,
private readonly int $maxDeferredEvents = self::DEFAULT_MAX_DEFERRED_EVENTS,
private readonly int $maxDeferredListenerInvocations = self::DEFAULT_MAX_DEFERRED_LISTENER_INVOCATIONS,
) {
if ($this->deferredProcessingTimeoutSeconds <= 0) {
throw new \InvalidArgumentException('The deferred processing timeout must be greater than zero.');
}
if ($this->maxDeferredEvents <= 0) {
throw new \InvalidArgumentException('The deferred event limit must be greater than zero.');
}
if ($this->maxDeferredListenerInvocations <= 0) {
throw new \InvalidArgumentException('The deferred listener invocation limit must be greater than zero.');
}
}
public function dispatch(Event $event): void
{
if (++$this->dispatchDepth > 32) {
--$this->dispatchDepth;
throw new \RuntimeException('Event dispatch recursion limit exceeded.');
}
try {
$this->invoke($event, DeliveryMode::Immediate);
if ($this->registry->listeners($event->label(), DeliveryMode::Deferred) !== []) {
if ($this->activeExecution === null) {
throw new \LogicException('Deferred events require an active execution scope.');
}
$this->deferred[$this->activeExecution][] = $event;
}
} finally {
--$this->dispatchDepth;
}
}
public function beginExecution(string $executionId): void
{
if ($this->activeExecution !== null) {
throw new \LogicException('An event execution scope is already active.');
}
$this->activeExecution = $executionId;
$this->deferred[$executionId] = [];
}
public function processDeferred(string $executionId): DeferredProcessingResult
{
if ($this->activeExecution !== $executionId) {
throw new \LogicException('Cannot process deferred events for an inactive execution.');
}
try {
$processedEvents = 0;
$listenerInvocations = 0;
$deadline = microtime(true) + $this->deferredProcessingTimeoutSeconds;
$deadlineExceeded = false;
$eventLimitExceeded = false;
$listenerInvocationLimitExceeded = false;
while (($event = array_shift($this->deferred[$executionId])) !== null) {
if ($processedEvents >= $this->maxDeferredEvents) {
$eventLimitExceeded = true;
array_unshift($this->deferred[$executionId], $event);
break;
}
if (microtime(true) >= $deadline) {
$deadlineExceeded = true;
array_unshift($this->deferred[$executionId], $event);
break;
}
$eventListenerCount = count($this->registry->listeners(
$event->label(),
DeliveryMode::Deferred,
));
if ($listenerInvocations + $eventListenerCount > $this->maxDeferredListenerInvocations) {
$listenerInvocationLimitExceeded = true;
array_unshift($this->deferred[$executionId], $event);
break;
}
$listenerInvocations += $this->invoke($event, DeliveryMode::Deferred);
$processedEvents++;
}
return new DeferredProcessingResult(
processed: $processedEvents,
remaining: count($this->deferred[$executionId]),
deadlineExceeded: $deadlineExceeded,
limitExceeded: $eventLimitExceeded || $listenerInvocationLimitExceeded,
listenerInvocations: $listenerInvocations,
eventLimitExceeded: $eventLimitExceeded,
listenerInvocationLimitExceeded: $listenerInvocationLimitExceeded,
);
} finally {
$this->discardDeferred($executionId);
}
}
public function discardDeferred(string $executionId): void
{
unset($this->deferred[$executionId]);
if ($this->activeExecution === $executionId) {
$this->activeExecution = null;
}
}
private function invoke(Event $event, DeliveryMode $delivery): int
{
$processed = 0;
foreach ($this->registry->listeners($event->label(), $delivery) as $listener) {
if ($event->isPropagationStopped()) {
break;
}
$processed++;
try {
$service = $this->container->get($listener->service);
$service->{$listener->method}($event);
} catch (\Throwable $error) {
$this->logger->error('Event listener failed.', [
'event' => $event->label(),
'module' => $listener->module,
'listener' => $listener->service . '::' . $listener->method,
'exception' => $error,
]);
if ($listener->failurePolicy === FailurePolicy::Propagate) {
throw $error;
}
}
}
return $processed;
}
}
-32
View File
@@ -1,32 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Http\Request;
/**
* Holds the HTTP request for the duration of the current runtime execution.
*/
final class RequestContext
{
private ?Request $request = null;
public function initialize(Request $request): void
{
if ($this->request !== null) {
throw new \LogicException('The request context has already been initialized.');
}
$this->request = $request;
}
public function current(): ?Request
{
return $this->request;
}
public function clear(): void
{
$this->request = null;
}
}
+3 -14
View File
@@ -27,11 +27,10 @@ use KTXC\Module\ModuleManager;
use Psr\Log\LoggerInterface;
use KTXC\Logger\LoggerFactory;
use KTXC\Logger\TenantAwareLogger;
use KTXC\Event\DeferredEventProcessorInterface;
use KTXC\Event\EventDispatcher;
use KTXC\Event\EventListenerRegistry;
use KTXF\Event\DeferredEventProcessorInterface;
use KTXF\Event\EventDispatcher;
use KTXF\Event\EventDispatcherInterface;
use KTXF\Event\EventListenerRegistrarInterface;
use KTXF\Event\EventListenerRegistry;
use KTXF\Cache\EphemeralCacheInterface;
use KTXF\Cache\PersistentCacheInterface;
use KTXF\Cache\BlobCacheInterface;
@@ -238,9 +237,6 @@ class Kernel implements KernelInterface
$remaining = 0;
$deadlineExceeded = false;
$limitExceeded = false;
$listenerInvocations = 0;
$eventLimitExceeded = false;
$listenerInvocationLimitExceeded = false;
$failures = [];
try {
@@ -252,9 +248,6 @@ class Kernel implements KernelInterface
$remaining = $result->remaining;
$deadlineExceeded = $result->deadlineExceeded;
$limitExceeded = $result->limitExceeded;
$listenerInvocations = $result->listenerInvocations;
$eventLimitExceeded = $result->eventLimitExceeded;
$listenerInvocationLimitExceeded = $result->listenerInvocationLimitExceeded;
}
} catch (\Throwable $e) {
$failures[] = $e;
@@ -293,9 +286,6 @@ class Kernel implements KernelInterface
failures: $failures,
deadlineExceeded: $deadlineExceeded,
limitExceeded: $limitExceeded,
deferredListenerInvocations: $listenerInvocations,
deferredEventLimitExceeded: $eventLimitExceeded,
deferredListenerInvocationLimitExceeded: $listenerInvocationLimitExceeded,
);
}
@@ -420,7 +410,6 @@ class Kernel implements KernelInterface
EventDispatcherInterface::class => \DI\get(EventDispatcher::class),
DeferredEventProcessorInterface::class => \DI\get(EventDispatcher::class),
EventListenerRegistrarInterface::class => \DI\get(EventListenerRegistry::class),
// Ephemeral Cache - for short-lived data (sessions, rate limits, challenges)
EphemeralCacheInterface::class => function(ContainerInterface $c) use ($projectDir) {
$storeType = $c->has('cache.ephemeral') ? $c->get('cache.ephemeral') : 'file';
@@ -12,17 +12,12 @@ class TenantConfiguration extends JsonSerializableObject
protected TenantAuthentication $authentication;
protected TenantSecurity $security;
protected TenantFirewall $firewall;
protected TenantStores $stores;
protected TenantPreview $preview;
protected array $services = [];
public function __construct()
{
$this->authentication = new TenantAuthentication();
$this->security = new TenantSecurity();
$this->firewall = new TenantFirewall();
$this->stores = new TenantStores();
$this->preview = new TenantPreview();
}
public function authentication(): TenantAuthentication {
@@ -37,16 +32,4 @@ class TenantConfiguration extends JsonSerializableObject
return $this->firewall;
}
public function services(): array {
return $this->services;
}
public function stores(): TenantStores {
return $this->stores;
}
public function preview(): TenantPreview {
return $this->preview;
}
}
-82
View File
@@ -1,82 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Models\Tenant;
use InvalidArgumentException;
use KTXF\Json\JsonSerializableObject;
final class TenantPreview extends JsonSerializableObject
{
protected bool $enabled = true;
protected string $store = 'previews';
protected int $maxSourceSize = 26214400;
protected TenantPreviewVariants $variants;
public function __construct()
{
$this->variants = new TenantPreviewVariants();
}
public function jsonDeserialize(array|string $data): static
{
if (is_string($data)) {
$data = json_decode($data, true, flags: JSON_THROW_ON_ERROR);
}
if (array_key_exists('enabled', $data)) {
if (!is_bool($data['enabled'])) {
throw new InvalidArgumentException('Preview enabled must be a boolean');
}
$this->enabled = $data['enabled'];
}
if (array_key_exists('store', $data)) {
if (!is_string($data['store']) || preg_match('/^[a-z][a-z0-9-]*$/', $data['store']) !== 1) {
throw new InvalidArgumentException('Preview store must be a logical system-store name');
}
$this->store = $data['store'];
}
if (array_key_exists('maxSourceSize', $data)) {
if (!is_int($data['maxSourceSize']) || $data['maxSourceSize'] < 1) {
throw new InvalidArgumentException('Preview maximum source size must be a positive integer');
}
$this->maxSourceSize = $data['maxSourceSize'];
}
if (array_key_exists('variants', $data)) {
if (!is_array($data['variants'])) {
throw new InvalidArgumentException('Preview variants configuration must be an object');
}
$this->variants->jsonDeserialize($data['variants']);
}
if ($this->enabled && $this->variants->all() === []) {
throw new InvalidArgumentException('At least one preview variant is required when previews are enabled');
}
return $this;
}
public function enabled(): bool
{
return $this->enabled;
}
public function store(): string
{
return $this->store;
}
public function maxSourceSize(): int
{
return $this->maxSourceSize;
}
public function variants(): TenantPreviewVariants
{
return $this->variants;
}
}
@@ -1,53 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Models\Tenant;
use InvalidArgumentException;
use KTXF\Preview\MimeType;
final readonly class TenantPreviewVariant
{
public string $format;
public function __construct(
public int $width,
public int $height,
string $format,
public int $quality,
) {
if ($this->width < 1 || $this->height < 1) {
throw new InvalidArgumentException('Preview variant dimensions must be positive');
}
if ($this->quality < 1 || $this->quality > 100) {
throw new InvalidArgumentException('Preview variant quality must be between 1 and 100');
}
$this->format = MimeType::normalize($format);
}
public static function fromArray(array $data, ?self $defaults = null): self
{
$width = $data['width'] ?? $defaults?->width;
$height = $data['height'] ?? $defaults?->height;
$format = $data['format'] ?? $defaults?->format;
$quality = $data['quality'] ?? $defaults?->quality;
if (!is_int($width) || !is_int($height) || !is_string($format) || !is_int($quality)) {
throw new InvalidArgumentException('Preview variants require integer dimensions and quality plus a MIME format');
}
return new self($width, $height, $format, $quality);
}
/** @return array{width:int,height:int,format:string,quality:int} */
public function toArray(): array
{
return [
'width' => $this->width,
'height' => $this->height,
'format' => $this->format,
'quality' => $this->quality,
];
}
}
@@ -1,70 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Models\Tenant;
use InvalidArgumentException;
use KTXF\Json\JsonSerializableObject;
final class TenantPreviewVariants extends JsonSerializableObject
{
/** @var array<string, TenantPreviewVariant> */
private array $entries;
public function __construct()
{
$this->entries = self::defaults();
}
public function jsonDeserialize(array|string $data): static
{
if (is_string($data)) {
$data = json_decode($data, true, flags: JSON_THROW_ON_ERROR);
}
$defaults = self::defaults();
$entries = [];
foreach ($data as $name => $variant) {
if (!is_string($name) || preg_match('/^[a-z][a-z0-9-]*$/', $name) !== 1) {
throw new InvalidArgumentException('Invalid preview variant name');
}
if (!is_array($variant)) {
throw new InvalidArgumentException('Preview variant configuration must be an object');
}
$entries[$name] = TenantPreviewVariant::fromArray($variant, $defaults[$name] ?? null);
}
$this->entries = $entries;
return $this;
}
public function variant(string $name): ?TenantPreviewVariant
{
return $this->entries[$name] ?? null;
}
/** @return array<string, TenantPreviewVariant> */
public function all(): array
{
return $this->entries;
}
public function jsonSerialize(): array
{
return array_map(
static fn(TenantPreviewVariant $variant): array => $variant->toArray(),
$this->entries,
);
}
/** @return array<string, TenantPreviewVariant> */
private static function defaults(): array
{
return [
'thumbnail' => new TenantPreviewVariant(128, 128, 'image/webp', 70),
'inline' => new TenantPreviewVariant(640, 640, 'image/webp', 80),
'fullscreen' => new TenantPreviewVariant(2560, 2560, 'image/webp', 90),
];
}
}
-57
View File
@@ -1,57 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Models\Tenant;
use InvalidArgumentException;
use KTXF\Json\JsonSerializableObject;
use KTXF\SystemStore\StoreReference;
/**
* Logical system stores configured for a tenant.
*/
final class TenantStores extends JsonSerializableObject
{
/** @var array<string, StoreReference> */
private array $entries = [];
public function jsonDeserialize(array|string $data): static
{
if (is_string($data)) {
$data = json_decode($data, true);
}
$this->entries = [];
foreach ($data as $name => $store) {
if (!is_string($name) || preg_match('/^[a-z][a-z0-9-]*$/', $name) !== 1) {
throw new InvalidArgumentException('Invalid logical system-store name');
}
if (!is_array($store)) {
throw new InvalidArgumentException('Invalid tenant store configuration entry');
}
$this->entries[$name] = StoreReference::fromArray($store);
}
return $this;
}
public function jsonSerialize(): array
{
return array_map(
static fn(StoreReference $store): array => $store->toArray(),
$this->entries,
);
}
public function store(string $name): ?StoreReference
{
return $this->entries[$name] ?? null;
}
/** @return array<string, StoreReference> */
public function all(): array
{
return $this->entries;
}
}
@@ -1,93 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Module\Configuration;
use InvalidArgumentException;
use LogicException;
use KTXF\Module\Configuration\BrowserModuleContextInterface;
use KTXF\Module\Configuration\ModuleContextType;
use KTXF\Module\ModuleInstanceInterface;
final class BrowserModuleContext implements BrowserModuleContextInterface
{
private const RESERVED_KEYS = ['modules', 'tenant', 'user', 'l10n'];
/** @var array<string,array<string,mixed>> */
private array $modules = [];
/** @var array<string,mixed> */
private array $configuration = [];
public function __construct(
private readonly string $tenantIdentifier,
private readonly string $identityIdentifier,
) {
}
public function type(): ModuleContextType
{
return ModuleContextType::Browser;
}
public function registerModule(
ModuleInstanceInterface $module,
string $namespace,
?string $boot = null,
): void {
if (trim($namespace) === '' || ($boot !== null && trim($boot) === '')) {
throw new InvalidArgumentException('Browser namespace must not be empty and boot path must be null or non-empty');
}
$handle = $module->handle();
if (isset($this->modules[$handle])) {
throw new LogicException("Browser module '{$handle}' is already registered");
}
$entry = [
'handle' => $handle,
'namespace' => $namespace,
'version' => $module->version(),
'label' => $module->label(),
'author' => $module->author(),
'description' => $module->description(),
];
if ($boot !== null) {
$entry['boot'] = $boot;
}
$this->modules[$handle] = $entry;
}
public function set(string $key, mixed $value): void
{
if (trim($key) === '') {
throw new InvalidArgumentException('Browser configuration key must not be empty');
}
if (in_array($key, self::RESERVED_KEYS, true) || array_key_exists($key, $this->configuration)) {
throw new LogicException("Browser configuration '{$key}' is already reserved or registered");
}
$this->configuration[$key] = $value;
}
public function tenantIdentifier(): string
{
return $this->tenantIdentifier;
}
public function identityIdentifier(): string
{
return $this->identityIdentifier;
}
public function modules(): array
{
return $this->modules;
}
public function configuration(): array
{
return $this->configuration;
}
}
@@ -1,34 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Module\Configuration;
use InvalidArgumentException;
use KTXF\Module\Configuration\ConsoleModuleContextInterface;
use KTXF\Module\Configuration\ModuleContextType;
final class ConsoleModuleContext implements ConsoleModuleContextInterface
{
/** @var array<class-string,true> */
private array $commands = [];
public function type(): ModuleContextType
{
return ModuleContextType::Console;
}
public function registerCommand(string $command): void
{
if (trim($command) === '') {
throw new InvalidArgumentException('Console command class must not be empty');
}
$this->commands[$command] = true;
}
public function commands(): array
{
return array_keys($this->commands);
}
}
+26 -59
View File
@@ -4,7 +4,6 @@ namespace KTXC\Module;
use KTXC\Console\Firewall\FirewallMaintenanceCommand;
use KTXC\Console\Firewall\FirewallSetupCommand;
use KTXC\Preview\PreviewManager;
use KTXC\Service\FirewallService;
use KTXC\Service\SystemFirewallLogService;
use KTXC\Service\SystemFirewallRuleService;
@@ -12,23 +11,11 @@ use KTXC\Service\SystemFirewallStatusService;
use KTXC\Service\TenantFirewallLogService;
use KTXC\Service\TenantFirewallRuleService;
use KTXC\Service\TenantFirewallStatusService;
use KTXC\Security\Event\AccessDeniedEvent;
use KTXC\Security\Event\AuthenticationFailedEvent;
use KTXC\Security\Event\AuthenticationSucceededEvent;
use KTXC\Security\Event\BruteForceDetectedEvent;
use KTXC\Security\Event\FirewallRuleCreatedEvent;
use KTXC\Security\Event\FirewallRuleDisabledEvent;
use KTXC\Security\Event\FirewallRuleEnabledEvent;
use KTXC\Security\Event\FirewallRuleExtendedEvent;
use KTXC\Security\Event\FirewallRuleRemovedEvent;
use KTXC\Security\Event\FirewallSettingsUpdatedEvent;
use KTXC\Security\Event\RateLimitExceededEvent;
use KTXC\Security\Event\SuspiciousActivityEvent;
use KTXF\Event\DeliveryMode;
use KTXF\Event\EventListenerRegistrarInterface;
use KTXF\Module\Configuration\BrowserModuleContextInterface;
use KTXF\Module\Configuration\ConsoleModuleContextInterface;
use KTXF\Module\Configuration\ModuleContextInterface;
use KTXF\Event\EventListenerRegistry;
use KTXF\Event\SecurityEvent;
use KTXF\Module\ModuleBrowserInterface;
use KTXF\Module\ModuleConsoleInterface;
use KTXF\Module\ModuleInstanceAbstract;
/**
@@ -36,11 +23,10 @@ use KTXF\Module\ModuleInstanceAbstract;
*
* Provides core system functionality and permissions
*/
class Module extends ModuleInstanceAbstract
class Module extends ModuleInstanceAbstract implements ModuleConsoleInterface, ModuleBrowserInterface
{
public function __construct(
private readonly EventListenerRegistrarInterface $events,
private readonly PreviewManager $previews,
private readonly EventListenerRegistry $events,
) {
}
@@ -48,32 +34,24 @@ class Module extends ModuleInstanceAbstract
{
$this->events->listen(
'core',
AuthenticationFailedEvent::class,
SecurityEvent::AUTH_FAILURE,
FirewallService::class,
'handleAuthFailure',
DeliveryMode::Immediate,
priority: 100,
);
$this->events->listen(
'core',
AuthenticationSucceededEvent::class,
FirewallService::class,
'logAuthenticationSuccess',
DeliveryMode::Deferred,
);
foreach ([
AccessDeniedEvent::class,
BruteForceDetectedEvent::class,
RateLimitExceededEvent::class,
SuspiciousActivityEvent::class,
FirewallRuleCreatedEvent::class,
FirewallRuleExtendedEvent::class,
FirewallRuleEnabledEvent::class,
FirewallRuleDisabledEvent::class,
FirewallRuleRemovedEvent::class,
FirewallSettingsUpdatedEvent::class,
SecurityEvent::AUTH_SUCCESS,
SecurityEvent::ACCESS_DENIED,
SecurityEvent::BRUTE_FORCE_DETECTED,
SecurityEvent::RATE_LIMIT_EXCEEDED,
SecurityEvent::SUSPICIOUS_ACTIVITY,
SecurityEvent::FIREWALL_RULE_CREATED,
SecurityEvent::FIREWALL_RULE_EXTENDED,
SecurityEvent::FIREWALL_RULE_ENABLED,
SecurityEvent::FIREWALL_RULE_DISABLED,
SecurityEvent::FIREWALL_RULE_REMOVED,
SecurityEvent::FIREWALL_SETTINGS_UPDATED,
] as $event) {
$this->events->listen(
'core',
@@ -216,20 +194,9 @@ class Module extends ModuleInstanceAbstract
];
}
public function configure(ModuleContextInterface $context): void
public function registerCI(): array
{
if ($context instanceof BrowserModuleContextInterface) {
$context->set(
'preview',
$this->previews->availability($context->tenantIdentifier()),
);
}
if (!$context instanceof ConsoleModuleContextInterface) {
return;
}
foreach ([
return [
FirewallSetupCommand::class,
FirewallMaintenanceCommand::class,
\KTXC\Console\Event\EventsDebugCommand::class,
@@ -243,9 +210,6 @@ class Module extends ModuleInstanceAbstract
\KTXC\Console\Tenant\TenantListCommand::class,
\KTXC\Console\Tenant\TenantDeleteCommand::class,
\KTXC\Console\Tenant\TenantAuthEnableCommand::class,
\KTXC\Console\Tenant\TenantStoreListCommand::class,
\KTXC\Console\Tenant\TenantStoreSetCommand::class,
\KTXC\Console\Tenant\TenantStoreRemoveCommand::class,
\KTXC\Console\User\UserCreateCommand::class,
\KTXC\Console\User\UserListCommand::class,
\KTXC\Console\User\UserDeleteCommand::class,
@@ -254,8 +218,11 @@ class Module extends ModuleInstanceAbstract
\KTXC\Console\Role\RoleDeleteCommand::class,
\KTXC\Console\Role\RoleAssignCommand::class,
\KTXC\Console\Role\RoleRevokeCommand::class,
] as $command) {
$context->registerCommand($command);
}
];
}
public function registerBI(): array
{
return [];
}
}
+15 -3
View File
@@ -4,7 +4,8 @@ namespace KTXC\Module;
use JsonSerializable;
use KTXC\Module\Store\ModuleEntry;
use KTXF\Module\Configuration\ModuleContextInterface;
use KTXF\Module\ModuleBrowserInterface;
use KTXF\Module\ModuleConsoleInterface;
use KTXF\Module\ModuleInstanceInterface;
/**
@@ -174,9 +175,20 @@ class ModuleObject implements JsonSerializable
$this->instance?->upgrade();
}
public function configure(ModuleContextInterface $context): void
public function registerBI(): array | null
{
$this->instance?->configure($context);
if ($this->instance instanceof ModuleBrowserInterface) {
return $this->instance->registerBI();
}
return null;
}
public function registerCI(): array | null
{
if ($this->instance instanceof ModuleConsoleInterface) {
return $this->instance->registerCI();
}
return null;
}
}
-19
View File
@@ -1,19 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Preview;
use KTXF\Resource\BinaryResource;
final readonly class Preview
{
public function __construct(
public BinaryResource $resource,
public int $size,
public string $etag,
public ?int $width = null,
public ?int $height = null,
) {
}
}
-284
View File
@@ -1,284 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Preview;
use InvalidArgumentException;
use KTXC\Resource\ProviderManager;
use KTXC\Service\TenantService;
use KTXC\SystemStore\SystemStoreManager;
use KTXF\Preview\MimeType;
use KTXF\Preview\PreviewGenerationException;
use KTXF\Preview\PreviewRequest;
use KTXF\Preview\PreviewResult;
use KTXF\Preview\PreviewSource;
use KTXF\Preview\Provider\PreviewProviderInterface;
use KTXF\Resource\Provider\ProviderInterface;
use KTXF\SystemStore\BlobInfo;
use Psr\Log\LoggerInterface;
use Throwable;
final readonly class PreviewManager
{
public function __construct(
private TenantService $tenants,
private ProviderManager $providers,
private SystemStoreManager $stores,
private LoggerInterface $logger,
) {
}
/** @return array{enabled:bool,storage:bool,generation:bool} */
public function availability(string $tenantId): array
{
$tenant = $this->tenants->fetchById($tenantId);
if ($tenant === null) {
return ['enabled' => false, 'storage' => false, 'generation' => false];
}
$configuration = $tenant->getConfiguration()->preview();
$enabled = $configuration->enabled();
$storage = $enabled
&& $tenant->getConfiguration()->stores()->store($configuration->store()) !== null;
$generation = $storage && $this->previewProviders() !== [];
if ($enabled && !$storage) {
$this->logger->debug('Preview storage is not configured', ['tenantId' => $tenantId]);
} elseif ($enabled && $storage && !$generation) {
$this->logger->debug('No preview generation provider is available', ['tenantId' => $tenantId]);
}
return compact('enabled', 'storage', 'generation');
}
public function fetch(
string $tenantId,
PreviewSource $source,
string $variant = 'inline',
): ?Preview {
$tenant = $this->tenants->fetchById($tenantId);
if ($tenant === null) {
return null;
}
$configuration = $tenant->getConfiguration()->preview();
$variantConfiguration = $configuration->variants()->variant($variant);
if (
!$configuration->enabled()
|| $variantConfiguration === null
|| ($source->size !== null && $source->size > $configuration->maxSourceSize())
|| $tenant->getConfiguration()->stores()->store($configuration->store()) === null
) {
return null;
}
$request = new PreviewRequest(
maxWidth: $variantConfiguration->width,
maxHeight: $variantConfiguration->height,
preferredMimeType: $variantConfiguration->format,
quality: $variantConfiguration->quality,
maxSourceSize: $configuration->maxSourceSize(),
);
try {
$cached = $this->readCache(
$tenantId,
$configuration->store(),
$source,
$request,
);
if ($cached !== null) {
return $cached;
}
$provider = $this->selectProvider($source->mimeType, $request);
if ($provider === null) {
return null;
}
$result = $provider->generate($source, $request);
$blob = $this->writeCache(
$tenantId,
$configuration->store(),
$source,
$request,
$result,
);
return $this->readStoredPreview(
$tenantId,
$configuration->store(),
$blob,
$request,
);
} catch (Throwable $exception) {
$this->logger->warning('Preview unavailable', [
'tenantId' => $tenantId,
'sourceType' => $source->sourceType,
'variant' => $variant,
'exception' => $exception,
]);
return null;
}
}
private function readCache(
string $tenantId,
string $store,
PreviewSource $source,
PreviewRequest $request,
): ?Preview {
$key = $this->cacheKey($tenantId, $source, $request);
$blob = $this->stores->stat($tenantId, $store, $key);
if (!$this->validBlob($blob, $key, $request)) {
return null;
}
return $this->readStoredPreview($tenantId, $store, $blob, $request);
}
private function readStoredPreview(
string $tenantId,
string $store,
BlobInfo $blob,
PreviewRequest $request,
): ?Preview {
$resource = $this->stores->read($tenantId, $store, $blob->key);
if ($resource === null) {
return null;
}
try {
if (MimeType::normalize($resource->mimeType()) !== $request->preferredMimeType) {
return null;
}
} catch (Throwable) {
return null;
}
return new Preview(
resource: $resource,
size: $blob->size,
etag: $blob->etag,
width: $blob->attributes['width'] ?? null,
height: $blob->attributes['height'] ?? null,
);
}
private function writeCache(
string $tenantId,
string $store,
PreviewSource $source,
PreviewRequest $request,
PreviewResult $result,
): BlobInfo {
$outputMimeType = MimeType::normalize($result->resource->mimeType());
if ($outputMimeType !== $request->preferredMimeType) {
throw new PreviewGenerationException('Generated preview MIME does not match the requested output MIME');
}
if (
($result->width !== null && $result->width > $request->maxWidth)
|| ($result->height !== null && $result->height > $request->maxHeight)
) {
throw new PreviewGenerationException('Generated preview dimensions exceed the requested limits');
}
return $this->stores->write(
$tenantId,
$store,
$this->cacheKey($tenantId, $source, $request),
$result->resource,
['width' => $result->width, 'height' => $result->height],
);
}
private function cacheKey(
string $tenantId,
PreviewSource $source,
PreviewRequest $request,
): string {
if (trim($tenantId) === '') {
throw new InvalidArgumentException('Preview cache keys require a tenant identifier');
}
$canonical = json_encode([
'version' => 2, // Regenerate previews with opaque document pages and outlines.
'tenantId' => $tenantId,
'source' => [
'type' => $source->sourceType,
'identity' => $source->identity,
'signature' => $source->signature,
'mimeType' => $source->mimeType,
],
'request' => [
'maxWidth' => $request->maxWidth,
'maxHeight' => $request->maxHeight,
'preferredMimeType' => $request->preferredMimeType,
'quality' => $request->quality,
],
], JSON_THROW_ON_ERROR | JSON_UNESCAPED_SLASHES | JSON_UNESCAPED_UNICODE | JSON_PRESERVE_ZERO_FRACTION);
$digest = hash('sha256', $canonical);
return "generated/{$source->sourceType}/" . substr($digest, 0, 2) . "/{$digest}";
}
private function validBlob(?BlobInfo $blob, string $key, PreviewRequest $request): bool
{
if ($blob === null || $blob->key !== $key || $blob->size < 1) {
return false;
}
$width = $blob->attributes['width'] ?? null;
$height = $blob->attributes['height'] ?? null;
if (
($width !== null && (!is_int($width) || $width < 1 || $width > $request->maxWidth))
|| ($height !== null && (!is_int($height) || $height < 1 || $height > $request->maxHeight))
) {
return false;
}
try {
return MimeType::normalize($blob->mimeType) === $request->preferredMimeType;
} catch (Throwable) {
return false;
}
}
private function selectProvider(
string $sourceMimeType,
PreviewRequest $request,
): ?PreviewProviderInterface {
$sourceMimeType = MimeType::normalize($sourceMimeType);
$candidates = [];
foreach ($this->previewProviders() as $identifier => $provider) {
if (
!$provider instanceof PreviewProviderInterface
|| !$provider->supports($sourceMimeType, $request)
) {
continue;
}
$candidates[] = ['identifier' => $identifier, 'provider' => $provider];
}
if ($candidates === []) {
return null;
}
usort($candidates, static function (array $left, array $right): int {
return ($right['provider']->priority() <=> $left['provider']->priority())
?: strcmp($left['identifier'], $right['identifier']);
});
return $candidates[0]['provider'];
}
/** @return array<string, PreviewProviderInterface> */
private function previewProviders(): array
{
return array_filter(
$this->providers->providers(ProviderInterface::TYPE_PREVIEW),
static fn(ProviderInterface $provider): bool => $provider instanceof PreviewProviderInterface,
);
}
}
+8 -6
View File
@@ -7,8 +7,8 @@ namespace KTXC\Runtime\Console;
use KTXC\Application\Execution\ExecutionDescriptor;
use KTXC\Kernel;
use KTXC\KernelInterface;
use KTXC\Module\Configuration\ConsoleModuleContext;
use KTXC\Module\ModuleManager;
use KTXF\Module\ModuleConsoleInterface;
use Psr\Container\ContainerInterface;
use Symfony\Component\Console\Application as ConsoleApplication;
use Symfony\Component\Console\Attribute\AsCommand;
@@ -34,13 +34,15 @@ final class ConsoleRuntime
/** @var ModuleManager $moduleManager */
$moduleManager = $container->get(ModuleManager::class);
$moduleContext = new ConsoleModuleContext();
foreach ($moduleManager->list() as $module) {
$module->configure($moduleContext);
}
$instance = $module->instance();
if (!$instance instanceof ModuleConsoleInterface) {
continue;
}
foreach ($moduleContext->commands() as $commandClass) {
$this->registerCommand($console, $container, $commandClass);
foreach ($instance->registerCI() as $commandClass) {
$this->registerCommand($console, $container, $commandClass);
}
}
return $console->run($input, $output);
+17 -26
View File
@@ -11,7 +11,6 @@ use KTXC\Http\Middleware\MiddlewarePipeline;
use KTXC\Http\Middleware\RouterMiddleware;
use KTXC\Http\Middleware\TenantMiddleware;
use KTXC\Http\Request\Request;
use KTXC\Http\Request\RequestContext;
use KTXC\Http\Response\Response;
use KTXC\KernelInterface;
@@ -26,34 +25,26 @@ final class HttpRuntime
public function run(?Request $request = null, bool $send = true): Response
{
$request ??= Request::createFromGlobals();
$requestContext = null;
try {
return $this->kernel->executionRunner()->execute(
ExecutionDescriptor::http(),
function () use ($request, $send, &$requestContext): Response {
$requestContext = $this->kernel->container()->get(RequestContext::class);
$requestContext->initialize($request);
return $this->kernel->executionRunner()->execute(
ExecutionDescriptor::http(),
function () use ($request, $send): Response {
$response = $this->pipeline()->handle($request);
if ($send) {
$response->send();
}
$response = $this->pipeline()->handle($request);
if ($send) {
$response->send();
}
return $response;
},
function (\Throwable $error) use ($send): Response {
$response = $this->errorResponse($error);
if ($send) {
$response->send();
}
return $response;
},
function (\Throwable $error) use ($send): Response {
$response = $this->errorResponse($error);
if ($send) {
$response->send();
}
return $response;
},
);
} finally {
$requestContext?->clear();
}
return $response;
},
);
}
private function pipeline(): MiddlewarePipeline
+1 -38
View File
@@ -8,14 +8,11 @@ use KTXC\Models\Identity\User;
use KTXC\Resource\ProviderManager;
use KTXC\Security\Authentication\AuthenticationRequest;
use KTXC\Security\Authentication\AuthenticationResponse;
use KTXC\Security\Event\AuthenticationFailedEvent;
use KTXC\Security\Event\AuthenticationSucceededEvent;
use KTXC\Service\TokenService;
use KTXC\Service\UserAccountsService;
use KTXC\Context\TenantContextInterface;
use KTXF\Cache\CacheScope;
use KTXF\Cache\EphemeralCacheInterface;
use KTXF\Event\EventDispatcherInterface;
use KTXF\Security\Authentication\AuthenticationProviderInterface;
use KTXF\Security\Authentication\AuthenticationSession;
use KTXF\Security\Authentication\ProviderContext;
@@ -34,7 +31,6 @@ class AuthenticationManager
private readonly ProviderManager $providerManager,
private readonly TokenService $tokenService,
private readonly UserAccountsService $userService,
private readonly EventDispatcherInterface $events,
) {
$this->securityCode = $this->tenantContext->configuration()->security()->code();
}
@@ -191,10 +187,6 @@ class AuthenticationManager
if (!$result->isSuccess()) {
$this->saveSession($session);
$this->publishAuthenticationFailure(
$session,
$result->errorCode ?? AuthenticationResponse::ERROR_INVALID_CREDENTIALS,
);
return AuthenticationResponse::failed(
AuthenticationResponse::ERROR_INVALID_CREDENTIALS,
'Authentication failed. If you haven\'t set up this method, try another option.',
@@ -397,10 +389,6 @@ class AuthenticationManager
$result = $provider->completeRedirect($context, $request->params);
if ($result->isFailed()) {
$this->publishAuthenticationFailure(
$session,
$result->errorCode ?? AuthenticationResponse::ERROR_INVALID_CREDENTIALS,
);
$this->deleteSession($session->id);
return AuthenticationResponse::failed(
AuthenticationResponse::ERROR_INVALID_CREDENTIALS,
@@ -578,17 +566,6 @@ class AuthenticationManager
// Helper Methods
// =========================================================================
private function publishAuthenticationFailure(
AuthenticationSession $session,
string $reason,
): void {
$this->events->dispatch(new AuthenticationFailedEvent(
userId: $session->userIdentifier,
reason: $reason,
tenantId: $session->tenantIdentifier,
));
}
/**
* Build provider context from session
*/
@@ -617,16 +594,7 @@ class AuthenticationManager
*/
private function completeAuthentication(AuthenticationSession $session): AuthenticationResponse
{
$userId = $session->userIdentifier;
if ($userId === null) {
return AuthenticationResponse::failed(
AuthenticationResponse::ERROR_INVALID_SESSION,
'Authenticated user is missing',
401,
);
}
$userData = $this->userService->fetchByIdentifier($userId);
$userData = $this->userService->fetchByIdentifier($session->userIdentifier);
if ($userData === null) {
return AuthenticationResponse::failed(
@@ -643,11 +611,6 @@ class AuthenticationManager
$this->deleteSession($session->id);
$this->events->dispatch(new AuthenticationSucceededEvent(
$userId,
$session->tenantIdentifier,
));
return AuthenticationResponse::success(
$this->buildUserData($user),
$tokens
@@ -1,88 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Security\Event;
use KTXC\Models\Firewall\FirewallRuleObject;
use KTXF\Event\Event;
final class AccessDeniedEvent extends Event implements SecurityRequestEventInterface
{
public function __construct(
private readonly string $ipAddress,
private readonly string $ruleId,
private readonly string $ruleScope,
private readonly ?string $deviceFingerprint = null,
private readonly ?string $reason = null,
?string $tenantId = null,
?string $identityId = null,
) {
if ($ipAddress === '') {
throw new \InvalidArgumentException('Access denial requires an IP address.');
}
if ($ruleId === '') {
throw new \InvalidArgumentException('Access denial requires a firewall rule ID.');
}
if (!in_array($ruleScope, [FirewallRuleObject::SCOPE_SYSTEM, FirewallRuleObject::SCOPE_TENANT], true)) {
throw new \InvalidArgumentException('Access denial requires a valid firewall rule scope.');
}
parent::__construct(
self::class,
['ruleId' => $ruleId, 'ruleScope' => $ruleScope, 'reason' => $reason],
$tenantId,
$identityId,
);
}
public function getIpAddress(): string
{
return $this->ipAddress;
}
public function getRuleId(): string
{
return $this->ruleId;
}
public function getRuleScope(): string
{
return $this->ruleScope;
}
public function getDeviceFingerprint(): ?string
{
return $this->deviceFingerprint;
}
public function getUserAgent(): ?string
{
return null;
}
public function getRequestPath(): ?string
{
return null;
}
public function getRequestMethod(): ?string
{
return null;
}
public function getUserId(): ?string
{
return null;
}
public function getReason(): ?string
{
return $this->reason;
}
public function getSeverity(): SecurityEventSeverity
{
return SecurityEventSeverity::WARNING;
}
}
@@ -1,39 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Security\Event;
use KTXF\Event\Event;
final class AuthenticationFailedEvent extends Event implements SecurityEventInterface
{
public function __construct(
private readonly ?string $userId = null,
private readonly ?string $reason = null,
?string $tenantId = null,
?string $identityId = null,
) {
parent::__construct(
self::class,
['userId' => $userId, 'reason' => $reason],
$tenantId,
$identityId,
);
}
public function getUserId(): ?string
{
return $this->userId;
}
public function getReason(): ?string
{
return $this->reason;
}
public function getSeverity(): SecurityEventSeverity
{
return SecurityEventSeverity::WARNING;
}
}
@@ -1,40 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Security\Event;
use KTXF\Event\Event;
final class AuthenticationSucceededEvent extends Event implements SecurityEventInterface
{
public function __construct(
private readonly string $userId,
?string $tenantId = null,
) {
if ($userId === '') {
throw new \InvalidArgumentException('Successful authentication requires a user ID.');
}
parent::__construct(
self::class,
['userId' => $userId],
$tenantId,
);
}
public function getUserId(): string
{
return $this->userId;
}
public function getReason(): ?string
{
return null;
}
public function getSeverity(): SecurityEventSeverity
{
return SecurityEventSeverity::INFO;
}
}
@@ -1,91 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Security\Event;
use KTXF\Event\Event;
final class BruteForceDetectedEvent extends Event implements SecurityRequestEventInterface
{
private readonly string $reason;
public function __construct(
private readonly string $ipAddress,
private readonly int $failureCount,
private readonly int $windowSeconds,
?string $tenantId = null,
) {
if ($ipAddress === '') {
throw new \InvalidArgumentException('Brute-force detection requires an IP address.');
}
if ($failureCount < 1) {
throw new \InvalidArgumentException('Brute-force detection requires at least one failure.');
}
if ($windowSeconds < 1) {
throw new \InvalidArgumentException('Brute-force detection requires a positive window.');
}
$this->reason = sprintf(
'%d failed attempts in %d seconds',
$failureCount,
$windowSeconds,
);
parent::__construct(
self::class,
['failureCount' => $failureCount, 'windowSeconds' => $windowSeconds],
$tenantId,
);
}
public function getIpAddress(): string
{
return $this->ipAddress;
}
public function getFailureCount(): int
{
return $this->failureCount;
}
public function getWindowSeconds(): int
{
return $this->windowSeconds;
}
public function getDeviceFingerprint(): ?string
{
return null;
}
public function getUserAgent(): ?string
{
return null;
}
public function getRequestPath(): ?string
{
return null;
}
public function getRequestMethod(): ?string
{
return null;
}
public function getUserId(): ?string
{
return null;
}
public function getReason(): string
{
return $this->reason;
}
public function getSeverity(): SecurityEventSeverity
{
return SecurityEventSeverity::CRITICAL;
}
}
@@ -1,66 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Security\Event;
use KTXF\Event\Event;
final class DeviceBlockedEvent extends Event implements SecurityRequestEventInterface
{
public function __construct(
private readonly string $deviceFingerprint,
private readonly ?string $reason = null,
?string $tenantId = null,
) {
if ($deviceFingerprint === '') {
throw new \InvalidArgumentException('Device-block events require a fingerprint.');
}
parent::__construct(
self::class,
['device' => $deviceFingerprint, 'reason' => $reason],
$tenantId,
);
}
public function getIpAddress(): ?string
{
return null;
}
public function getDeviceFingerprint(): string
{
return $this->deviceFingerprint;
}
public function getUserAgent(): ?string
{
return null;
}
public function getRequestPath(): ?string
{
return null;
}
public function getRequestMethod(): ?string
{
return null;
}
public function getUserId(): ?string
{
return null;
}
public function getReason(): ?string
{
return $this->reason;
}
public function getSeverity(): SecurityEventSeverity
{
return SecurityEventSeverity::CRITICAL;
}
}
@@ -1,68 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Security\Event;
use KTXF\Event\Event;
abstract class FirewallIpEvent extends Event implements SecurityRequestEventInterface
{
protected const SecurityEventSeverity SEVERITY = SecurityEventSeverity::INFO;
final public function __construct(
private readonly string $ipAddress,
private readonly ?string $reason = null,
?string $tenantId = null,
) {
if ($ipAddress === '') {
throw new \InvalidArgumentException('Firewall IP events require an IP address.');
}
parent::__construct(
static::class,
['ip' => $ipAddress, 'reason' => $reason],
$tenantId,
);
}
public function getIpAddress(): string
{
return $this->ipAddress;
}
public function getDeviceFingerprint(): ?string
{
return null;
}
public function getUserAgent(): ?string
{
return null;
}
public function getRequestPath(): ?string
{
return null;
}
public function getRequestMethod(): ?string
{
return null;
}
public function getUserId(): ?string
{
return null;
}
public function getReason(): ?string
{
return $this->reason;
}
public function getSeverity(): SecurityEventSeverity
{
return static::SEVERITY;
}
}
@@ -1,9 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Security\Event;
final class FirewallRuleCreatedEvent extends FirewallRuleEvent
{
}
@@ -1,9 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Security\Event;
final class FirewallRuleDisabledEvent extends FirewallRuleEvent
{
}
@@ -1,9 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Security\Event;
final class FirewallRuleEnabledEvent extends FirewallRuleEvent
{
}
@@ -1,158 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Security\Event;
use KTXC\Models\Firewall\FirewallRuleObject;
use KTXF\Event\Event;
abstract class FirewallRuleEvent extends Event implements SecurityEventInterface
{
final protected function __construct(
private readonly string $ruleId,
private readonly string $ruleScope,
private readonly string $ruleType,
private readonly string $ruleAction,
private readonly string $ruleValue,
private readonly ?string $reason,
private readonly string $origin,
private readonly ?string $expiresAt,
private readonly array $details,
?string $tenantId,
?string $identityId,
) {
if ($ruleId === '') {
throw new \InvalidArgumentException('Firewall rule events require a rule ID.');
}
foreach ([
'scope' => $ruleScope,
'type' => $ruleType,
'action' => $ruleAction,
'value' => $ruleValue,
'origin' => $origin,
] as $field => $value) {
if ($value === '') {
throw new \InvalidArgumentException("Firewall rule events require a rule {$field}.");
}
}
foreach ([
'scope' => $ruleScope,
'type' => $ruleType,
'action' => $ruleAction,
'value' => $ruleValue,
'origin' => $origin,
] as $field => $value) {
if ($value === '') {
throw new \InvalidArgumentException("Firewall rule events require a rule {$field}.");
}
}
parent::__construct(
static::class,
[
'ruleId' => $ruleId,
'ruleScope' => $ruleScope,
'ruleType' => $ruleType,
'ruleAction' => $ruleAction,
'ruleValue' => $ruleValue,
'reason' => $reason,
'origin' => $origin,
'expiresAt' => $expiresAt,
...$details,
],
$tenantId,
$identityId,
);
}
public static function fromRule(
FirewallRuleObject $rule,
?string $actorId = null,
array $change = [],
): static {
$metadata = $rule->getMetadata() ?? [];
$details = [...$metadata, ...$change];
foreach ([
'ruleId',
'ruleScope',
'ruleType',
'ruleAction',
'ruleValue',
'reason',
'origin',
'expiresAt',
] as $reservedKey) {
unset($details[$reservedKey]);
}
return new static(
ruleId: (string) $rule->getId(),
ruleScope: (string) $rule->getScope(),
ruleType: (string) $rule->getType(),
ruleAction: (string) $rule->getAction(),
ruleValue: (string) $rule->getValue(),
reason: $rule->getReason(),
origin: (string) ($metadata['origin'] ?? 'manual'),
expiresAt: $rule->getExpiresAt()?->format(\DateTimeInterface::ATOM),
details: $details,
tenantId: $rule->getTenantId(),
identityId: $actorId ?? $rule->getCreatedBy(),
);
}
public function getRuleId(): string
{
return $this->ruleId;
}
public function getRuleScope(): string
{
return $this->ruleScope;
}
public function getRuleType(): string
{
return $this->ruleType;
}
public function getRuleAction(): string
{
return $this->ruleAction;
}
public function getRuleValue(): string
{
return $this->ruleValue;
}
public function getOrigin(): string
{
return $this->origin;
}
public function getExpiresAt(): ?string
{
return $this->expiresAt;
}
public function getDetails(): array
{
return $this->details;
}
public function getUserId(): ?string
{
return null;
}
public function getReason(): ?string
{
return $this->reason;
}
public function getSeverity(): SecurityEventSeverity
{
return SecurityEventSeverity::INFO;
}
}
@@ -1,9 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Security\Event;
final class FirewallRuleExtendedEvent extends FirewallRuleEvent
{
}
@@ -1,9 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Security\Event;
final class FirewallRuleRemovedEvent extends FirewallRuleEvent
{
}
@@ -1,76 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Security\Event;
use KTXF\Event\Event;
final class FirewallSettingsUpdatedEvent extends Event implements SecurityEventInterface
{
public function __construct(
private readonly string $changeReason,
private readonly array $previous,
private readonly array $current,
string $tenantId,
?string $actorId = null,
private readonly string $changeOrigin = 'manual',
) {
if ($changeReason === '') {
throw new \InvalidArgumentException('Firewall settings updates require a change reason.');
}
if ($tenantId === '') {
throw new \InvalidArgumentException('Firewall settings updates require a tenant ID.');
}
if ($changeOrigin === '') {
throw new \InvalidArgumentException('Firewall settings updates require a change origin.');
}
parent::__construct(
self::class,
[
'changeReason' => $changeReason,
'changeOrigin' => $changeOrigin,
'previous' => $previous,
'current' => $current,
],
$tenantId,
$actorId,
);
}
public function getChangeReason(): string
{
return $this->changeReason;
}
public function getPrevious(): array
{
return $this->previous;
}
public function getCurrent(): array
{
return $this->current;
}
public function getChangeOrigin(): string
{
return $this->changeOrigin;
}
public function getUserId(): ?string
{
return null;
}
public function getReason(): string
{
return $this->changeReason;
}
public function getSeverity(): SecurityEventSeverity
{
return SecurityEventSeverity::INFO;
}
}
@@ -1,9 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Security\Event;
final class IpAllowedEvent extends FirewallIpEvent
{
}
@@ -1,10 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Security\Event;
final class IpBlockedEvent extends FirewallIpEvent
{
protected const SecurityEventSeverity SEVERITY = SecurityEventSeverity::CRITICAL;
}
@@ -1,104 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Security\Event;
use KTXF\Event\Event;
final class RateLimitExceededEvent extends Event implements SecurityRequestEventInterface
{
private readonly string $reason;
public function __construct(
private readonly string $ipAddress,
private readonly int $requestCount,
private readonly int $windowSeconds,
private readonly ?string $endpoint = null,
?string $tenantId = null,
) {
if ($ipAddress === '') {
throw new \InvalidArgumentException('Rate-limit detection requires an IP address.');
}
if ($requestCount < 1) {
throw new \InvalidArgumentException('Rate-limit detection requires at least one request.');
}
if ($windowSeconds < 1) {
throw new \InvalidArgumentException('Rate-limit detection requires a positive window.');
}
if ($endpoint === '') {
throw new \InvalidArgumentException('A supplied rate-limit endpoint cannot be empty.');
}
$this->reason = sprintf(
'%d requests in %d seconds',
$requestCount,
$windowSeconds,
);
parent::__construct(
self::class,
[
'requestCount' => $requestCount,
'windowSeconds' => $windowSeconds,
'endpoint' => $endpoint,
],
$tenantId,
);
}
public function getIpAddress(): string
{
return $this->ipAddress;
}
public function getRequestCount(): int
{
return $this->requestCount;
}
public function getWindowSeconds(): int
{
return $this->windowSeconds;
}
public function getEndpoint(): ?string
{
return $this->endpoint;
}
public function getDeviceFingerprint(): ?string
{
return null;
}
public function getUserAgent(): ?string
{
return null;
}
public function getRequestPath(): ?string
{
return $this->endpoint;
}
public function getRequestMethod(): ?string
{
return null;
}
public function getUserId(): ?string
{
return null;
}
public function getReason(): string
{
return $this->reason;
}
public function getSeverity(): SecurityEventSeverity
{
return SecurityEventSeverity::ERROR;
}
}
@@ -1,26 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Security\Event;
interface SecurityEventInterface
{
public function label(): string;
public function get(string $key, mixed $default = null): mixed;
public function context(): array;
public function identifier(): string;
public function tenantIdentifier(): ?string;
public function actorIdentity(): ?string;
public function getUserId(): ?string;
public function getReason(): ?string;
public function getSeverity(): SecurityEventSeverity;
}
@@ -1,14 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Security\Event;
enum SecurityEventSeverity: int
{
case DEBUG = 0;
case INFO = 1;
case WARNING = 2;
case ERROR = 3;
case CRITICAL = 4;
}
@@ -1,18 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Security\Event;
interface SecurityRequestEventInterface extends SecurityEventInterface
{
public function getIpAddress(): ?string;
public function getDeviceFingerprint(): ?string;
public function getUserAgent(): ?string;
public function getRequestPath(): ?string;
public function getRequestMethod(): ?string;
}
@@ -1,100 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\Security\Event;
use KTXF\Event\Event;
final class SuspiciousActivityEvent extends Event implements SecurityRequestEventInterface
{
public function __construct(
private readonly string $ipAddress,
private readonly string $detector,
private readonly array $detectionData = [],
?string $tenantId = null,
?string $identityId = null,
private readonly ?string $deviceFingerprint = null,
private readonly ?string $userAgent = null,
private readonly ?string $requestPath = null,
private readonly ?string $requestMethod = null,
private readonly ?string $userId = null,
private readonly ?string $reason = null,
) {
if ($ipAddress === '') {
throw new \InvalidArgumentException('Suspicious activity requires an IP address.');
}
if ($detector === '') {
throw new \InvalidArgumentException('Suspicious activity requires a detector.');
}
if (array_key_exists('detector', $detectionData)) {
throw new \InvalidArgumentException('Detection data cannot replace the detector.');
}
if (array_key_exists('detector', $detectionData)) {
throw new \InvalidArgumentException('Detection data cannot replace the detector.');
}
if ($requestPath === '') {
throw new \InvalidArgumentException('A supplied request path cannot be empty.');
}
if ($requestMethod === '') {
throw new \InvalidArgumentException('A supplied request method cannot be empty.');
}
parent::__construct(
self::class,
['detector' => $detector] + $detectionData,
$tenantId,
$identityId,
);
}
public function getIpAddress(): string
{
return $this->ipAddress;
}
public function getDetector(): string
{
return $this->detector;
}
public function getDetectionData(): array
{
return $this->detectionData;
}
public function getDeviceFingerprint(): ?string
{
return $this->deviceFingerprint;
}
public function getUserAgent(): ?string
{
return $this->userAgent;
}
public function getRequestPath(): ?string
{
return $this->requestPath;
}
public function getRequestMethod(): ?string
{
return $this->requestMethod;
}
public function getUserId(): ?string
{
return $this->userId;
}
public function getReason(): ?string
{
return $this->reason;
}
public function getSeverity(): SecurityEventSeverity
{
return SecurityEventSeverity::ERROR;
}
}
+38 -25
View File
@@ -5,17 +5,9 @@ declare(strict_types=1);
namespace KTXC\Service;
use KTXC\Models\Firewall\FirewallRuleObject;
use KTXC\Security\Event\FirewallRuleCreatedEvent;
use KTXC\Security\Event\FirewallRuleDisabledEvent;
use KTXC\Security\Event\FirewallRuleEnabledEvent;
use KTXC\Security\Event\FirewallRuleEvent;
use KTXC\Security\Event\FirewallRuleExtendedEvent;
use KTXC\Security\Event\FirewallRuleRemovedEvent;
use KTXC\Security\Event\DeviceBlockedEvent;
use KTXC\Security\Event\IpAllowedEvent;
use KTXC\Security\Event\IpBlockedEvent;
use KTXC\Stores\FirewallStore;
use KTXF\Event\EventDispatcherInterface;
use KTXF\Event\SecurityEvent;
use KTXF\IpUtils;
final class FirewallRuleManager
@@ -194,7 +186,7 @@ final class FirewallRuleManager
$origin,
$metadata
);
$this->events->dispatch(new IpBlockedEvent($ipAddress, $reason, $scope->tenantId));
$this->publishIpEvent(SecurityEvent::IP_BLOCKED, $scope, $ipAddress, $reason);
return $rule;
}
@@ -217,7 +209,7 @@ final class FirewallRuleManager
null,
$origin
);
$this->events->dispatch(new IpAllowedEvent($ipAddress, $reason, $scope->tenantId));
$this->publishIpEvent(SecurityEvent::IP_ALLOWED, $scope, $ipAddress, $reason);
return $rule;
}
@@ -262,7 +254,8 @@ final class FirewallRuleManager
$origin
);
$event = new DeviceBlockedEvent($fingerprint, $reason, $scope->tenantId);
$event = new SecurityEvent(SecurityEvent::DEVICE_BLOCKED, ['device' => $fingerprint, 'reason' => $reason]);
$event->setDeviceFingerprint($fingerprint)->setReason($reason)->setTenantId($scope->tenantId);
$this->events->dispatch($event);
return $rule;
@@ -284,7 +277,7 @@ final class FirewallRuleManager
$this->store->depositRule($rule);
$this->cache->invalidate();
$this->publishLifecycleEvent(
FirewallRuleDisabledEvent::class,
SecurityEvent::FIREWALL_RULE_DISABLED,
$rule,
$actorId,
['changeReason' => $reason, 'changeOrigin' => self::ORIGIN_MANUAL]
@@ -323,7 +316,7 @@ final class FirewallRuleManager
$this->store->depositRule($rule);
$this->cache->invalidate();
$this->publishLifecycleEvent(
FirewallRuleEnabledEvent::class,
SecurityEvent::FIREWALL_RULE_ENABLED,
$rule,
$actorId,
['changeReason' => $reason, 'changeOrigin' => self::ORIGIN_MANUAL]
@@ -367,7 +360,7 @@ final class FirewallRuleManager
$this->store->depositRule($rule);
$this->cache->invalidate();
$this->publishLifecycleEvent(
FirewallRuleExtendedEvent::class,
SecurityEvent::FIREWALL_RULE_EXTENDED,
$rule,
$actorId,
[
@@ -394,7 +387,7 @@ final class FirewallRuleManager
$this->store->destroyRule($rule);
$this->cache->invalidate();
$this->publishLifecycleEvent(
FirewallRuleRemovedEvent::class,
SecurityEvent::FIREWALL_RULE_REMOVED,
$rule,
$actorId,
['changeReason' => $reason, 'changeOrigin' => self::ORIGIN_MANUAL]
@@ -449,10 +442,9 @@ final class FirewallRuleManager
}
$rule->setMetadata($metadata);
$rule = $this->store->depositRule($rule)
?? throw new \RuntimeException('Failed to persist firewall rule.');
$this->store->depositRule($rule);
$this->cache->invalidate();
$this->publishLifecycleEvent(FirewallRuleCreatedEvent::class, $rule);
$this->publishLifecycleEvent(SecurityEvent::FIREWALL_RULE_CREATED, $rule);
return $rule;
}
@@ -489,7 +481,7 @@ final class FirewallRuleManager
$this->store->depositRule($rule);
$this->cache->invalidate();
$this->publishLifecycleEvent(FirewallRuleExtendedEvent::class, $rule);
$this->publishLifecycleEvent(SecurityEvent::FIREWALL_RULE_EXTENDED, $rule);
return $rule;
}
@@ -501,17 +493,38 @@ final class FirewallRuleManager
return $rule && $scope->owns($rule) ? $rule : null;
}
/**
* @param class-string<FirewallRuleEvent> $eventClass
*/
private function publishIpEvent(
string $name,
FirewallRuleScope $scope,
string $ipAddress,
?string $reason
): void {
$event = new SecurityEvent($name, ['ip' => $ipAddress, 'reason' => $reason]);
$event->setIpAddress($ipAddress)->setReason($reason)->setTenantId($scope->tenantId);
$this->events->dispatch($event);
}
private function publishLifecycleEvent(
string $eventClass,
string $name,
FirewallRuleObject $rule,
?string $actorId = null,
array $change = []
): void
{
$event = $eventClass::fromRule($rule, $actorId, $change);
$event = new SecurityEvent($name, [
'ruleId' => $rule->getId(),
'ruleScope' => $rule->getScope(),
'ruleType' => $rule->getType(),
'ruleAction' => $rule->getAction(),
'ruleValue' => $rule->getValue(),
'reason' => $rule->getReason(),
'origin' => $rule->getMetadata()['origin'] ?? self::ORIGIN_MANUAL,
'expiresAt' => $rule->getExpiresAt()?->format(\DateTimeInterface::ATOM),
...($rule->getMetadata() ?? []),
...$change,
]);
$event->setTenantId($rule->getTenantId())
->setIdentityId($actorId ?? $rule->getCreatedBy());
$this->events->dispatch($event);
}
}
+49 -83
View File
@@ -5,26 +5,12 @@ declare(strict_types=1);
namespace KTXC\Service;
use KTXC\Http\Request\Request;
use KTXC\Http\Request\RequestContext;
use KTXC\Models\Firewall\FirewallRuleObject;
use KTXC\Models\Firewall\FirewallLogObject;
use KTXC\Stores\FirewallStore;
use KTXC\Context\TenantContextInterface;
use KTXC\Security\Event\AccessDeniedEvent;
use KTXC\Security\Event\AuthenticationFailedEvent;
use KTXC\Security\Event\AuthenticationSucceededEvent;
use KTXC\Security\Event\BruteForceDetectedEvent;
use KTXC\Security\Event\FirewallRuleCreatedEvent;
use KTXC\Security\Event\FirewallRuleDisabledEvent;
use KTXC\Security\Event\FirewallRuleEnabledEvent;
use KTXC\Security\Event\FirewallRuleExtendedEvent;
use KTXC\Security\Event\FirewallRuleRemovedEvent;
use KTXC\Security\Event\FirewallSettingsUpdatedEvent;
use KTXC\Security\Event\RateLimitExceededEvent;
use KTXC\Security\Event\SuspiciousActivityEvent;
use KTXC\Security\Event\SecurityEventInterface;
use KTXC\Security\Event\SecurityRequestEventInterface;
use KTXF\Event\EventDispatcherInterface;
use KTXF\Event\SecurityEvent;
use KTXF\IpUtils;
/**
@@ -59,7 +45,6 @@ class FirewallService
private readonly EventDispatcherInterface $events,
private readonly FirewallRuleManager $rules,
private readonly FirewallRuleCache $ruleCache,
private readonly RequestContext $requestContext,
) {
}
@@ -145,17 +130,17 @@ class FirewallService
/**
* Handle authentication failure event
*/
public function handleAuthFailure(AuthenticationFailedEvent $event): void
public function handleAuthFailure(SecurityEvent $event): void
{
$request = $this->requestContext->current();
$ipAddress = $request?->getClientIp();
$tenantId = $event->tenantIdentifier() ?? $this->tenantContext->identifier();
$ipAddress = $event->getIpAddress();
$tenantId = $event->getTenantId() ?? $this->tenantContext->identifier();
if (!$ipAddress || !$tenantId) {
return;
}
$log = $this->securityLog($event, $request);
$event->setTenantId($tenantId);
$log = $this->securityLog($event);
if ($log === null || !$this->store->createLogOnce($log)) {
return;
}
@@ -210,12 +195,8 @@ class FirewallService
int $blockDuration
): void {
// Publish brute force event
$event = new BruteForceDetectedEvent(
$ipAddress,
$failureCount,
$windowSeconds,
$tenantId,
);
$event = SecurityEvent::bruteForceDetected($ipAddress, $failureCount, $windowSeconds);
$event->setTenantId($tenantId);
$this->events->dispatch($event);
$this->rules->blockIp(
@@ -241,7 +222,7 @@ class FirewallService
/**
* Log security event to firewall logs
*/
public function logSecurityEvent(SecurityEventInterface $event): void
public function logSecurityEvent(SecurityEvent $event): void
{
$log = $this->securityLog($event);
if ($log !== null) {
@@ -249,45 +230,29 @@ class FirewallService
}
}
public function logAuthenticationSuccess(AuthenticationSucceededEvent $event): void
private function securityLog(SecurityEvent $event): ?FirewallLogObject
{
$log = $this->securityLog($event, $this->requestContext->current());
if ($log !== null) {
$this->store->createLog($log);
}
}
private function securityLog(
SecurityEventInterface $event,
?Request $request = null,
): ?FirewallLogObject
{
$tenantId = $event->tenantIdentifier() ?? $this->tenantContext->identifier();
$tenantId = $event->getTenantId() ?? $this->tenantContext->identifier();
$ruleScope = $event->get('ruleScope');
if (!$tenantId && $ruleScope !== FirewallRuleObject::SCOPE_SYSTEM) {
return null;
}
$requestEvent = $event instanceof SecurityRequestEventInterface ? $event : null;
$log = new FirewallLogObject();
return $log->setEventId($event->identifier())
return $log->setEventId($event->getEventId())
->setTenantId($tenantId)
->setIpAddress($request?->getClientIp() ?? $requestEvent?->getIpAddress())
->setDeviceFingerprint(
$request?->headers->get('X-Device-Fingerprint')
?? $requestEvent?->getDeviceFingerprint()
)
->setUserAgent($request?->headers->get('User-Agent') ?? $requestEvent?->getUserAgent())
->setRequestPath($request?->getPathInfo() ?? $requestEvent?->getRequestPath())
->setRequestMethod($request?->getMethod() ?? $requestEvent?->getRequestMethod())
->setEventType($this->mapEventToLogType($event->label()))
->setIpAddress($event->getIpAddress())
->setDeviceFingerprint($event->getDeviceFingerprint())
->setUserAgent($event->getUserAgent())
->setRequestPath($event->getRequestPath())
->setRequestMethod($event->getRequestMethod())
->setEventType($this->mapEventToLogType($event->getName()))
->setResult($this->mapEventToResult($event))
->setRuleId($event->get('ruleId'))
->setRuleScope($ruleScope)
->setIdentityId($event->getUserId() ?? $event->actorIdentity())
->setIdentityId($event->getUserId() ?? $event->getIdentityId())
->setTimestamp(new \DateTimeImmutable())
->setMetadata($event->context());
->setMetadata($event->getData());
}
/**
@@ -296,18 +261,18 @@ class FirewallService
private function mapEventToLogType(string $eventName): string
{
return match ($eventName) {
AuthenticationFailedEvent::class => FirewallLogObject::EVENT_AUTH_FAILURE,
AuthenticationSucceededEvent::class => FirewallLogObject::EVENT_ACCESS_CHECK,
BruteForceDetectedEvent::class => FirewallLogObject::EVENT_BRUTE_FORCE,
RateLimitExceededEvent::class => FirewallLogObject::EVENT_RATE_LIMIT,
AccessDeniedEvent::class => FirewallLogObject::EVENT_RULE_MATCH,
SuspiciousActivityEvent::class => FirewallLogObject::EVENT_SUSPICIOUS,
FirewallRuleCreatedEvent::class => FirewallLogObject::EVENT_RULE_CREATED,
FirewallRuleExtendedEvent::class => FirewallLogObject::EVENT_RULE_EXTENDED,
FirewallRuleEnabledEvent::class => FirewallLogObject::EVENT_RULE_ENABLED,
FirewallRuleDisabledEvent::class => FirewallLogObject::EVENT_RULE_DISABLED,
FirewallRuleRemovedEvent::class => FirewallLogObject::EVENT_RULE_REMOVED,
FirewallSettingsUpdatedEvent::class => FirewallLogObject::EVENT_SETTINGS_UPDATED,
SecurityEvent::AUTH_FAILURE => FirewallLogObject::EVENT_AUTH_FAILURE,
SecurityEvent::AUTH_SUCCESS => FirewallLogObject::EVENT_ACCESS_CHECK,
SecurityEvent::BRUTE_FORCE_DETECTED => FirewallLogObject::EVENT_BRUTE_FORCE,
SecurityEvent::RATE_LIMIT_EXCEEDED => FirewallLogObject::EVENT_RATE_LIMIT,
SecurityEvent::ACCESS_DENIED => FirewallLogObject::EVENT_RULE_MATCH,
SecurityEvent::SUSPICIOUS_ACTIVITY => FirewallLogObject::EVENT_SUSPICIOUS,
SecurityEvent::FIREWALL_RULE_CREATED => FirewallLogObject::EVENT_RULE_CREATED,
SecurityEvent::FIREWALL_RULE_EXTENDED => FirewallLogObject::EVENT_RULE_EXTENDED,
SecurityEvent::FIREWALL_RULE_ENABLED => FirewallLogObject::EVENT_RULE_ENABLED,
SecurityEvent::FIREWALL_RULE_DISABLED => FirewallLogObject::EVENT_RULE_DISABLED,
SecurityEvent::FIREWALL_RULE_REMOVED => FirewallLogObject::EVENT_RULE_REMOVED,
SecurityEvent::FIREWALL_SETTINGS_UPDATED => FirewallLogObject::EVENT_SETTINGS_UPDATED,
default => FirewallLogObject::EVENT_ACCESS_CHECK,
};
}
@@ -315,16 +280,17 @@ class FirewallService
/**
* Map security event to result
*/
private function mapEventToResult(SecurityEventInterface $event): string
private function mapEventToResult(SecurityEvent $event): string
{
return match ($event->label()) {
AuthenticationSucceededEvent::class => FirewallLogObject::RESULT_ALLOWED,
FirewallRuleCreatedEvent::class,
FirewallRuleExtendedEvent::class,
FirewallRuleEnabledEvent::class,
FirewallRuleDisabledEvent::class,
FirewallRuleRemovedEvent::class,
FirewallSettingsUpdatedEvent::class => FirewallLogObject::RESULT_RECORDED,
return match ($event->getName()) {
SecurityEvent::AUTH_SUCCESS,
SecurityEvent::ACCESS_GRANTED => FirewallLogObject::RESULT_ALLOWED,
SecurityEvent::FIREWALL_RULE_CREATED,
SecurityEvent::FIREWALL_RULE_EXTENDED,
SecurityEvent::FIREWALL_RULE_ENABLED,
SecurityEvent::FIREWALL_RULE_DISABLED,
SecurityEvent::FIREWALL_RULE_REMOVED,
SecurityEvent::FIREWALL_SETTINGS_UPDATED => FirewallLogObject::RESULT_RECORDED,
default => FirewallLogObject::RESULT_BLOCKED,
};
}
@@ -337,14 +303,14 @@ class FirewallService
?string $deviceFingerprint,
FirewallRuleObject $rule
): void {
$event = new AccessDeniedEvent(
ipAddress: $ipAddress,
ruleId: $rule->getId(),
ruleScope: $rule->getScope(),
deviceFingerprint: $deviceFingerprint,
reason: $rule->getReason(),
tenantId: $this->tenantContext->identifier(),
$event = SecurityEvent::accessDenied(
$ipAddress,
$deviceFingerprint,
$rule->getId(),
$rule->getScope(),
$rule->getReason()
);
$event->setTenantId($this->tenantContext->identifier());
$this->events->dispatch($event);
}
+8 -9
View File
@@ -6,7 +6,7 @@ namespace KTXC\Service;
use KTXC\Models\Tenant\TenantConfiguration;
use KTXF\Event\EventDispatcherInterface;
use KTXC\Security\Event\FirewallSettingsUpdatedEvent;
use KTXF\Event\SecurityEvent;
final class FirewallSettingsService
{
@@ -52,14 +52,13 @@ final class FirewallSettingsService
$tenant->setConfiguration($configuration);
$this->tenants->deposit($tenant);
$event = new FirewallSettingsUpdatedEvent(
changeReason: $reason,
previous: $previous,
current: $current,
tenantId: $tenantId,
actorId: $actorId,
changeOrigin: FirewallRuleManager::ORIGIN_MANUAL,
);
$event = new SecurityEvent(SecurityEvent::FIREWALL_SETTINGS_UPDATED, [
'changeReason' => $reason,
'changeOrigin' => FirewallRuleManager::ORIGIN_MANUAL,
'previous' => $previous,
'current' => $current,
]);
$event->setTenantId($tenantId)->setIdentityId($actorId);
$this->events->dispatch($event);
return $current;
-11
View File
@@ -73,15 +73,4 @@ class TenantService
{
return $this->store->storeSettings($identifier, $settings);
}
public function fetchServiceConfiguration(string $identifier, string $name): ?array
{
return $this->store->fetchServiceConfiguration($identifier, $name);
}
public function storeServiceConfiguration(string $identifier, string $name, array $configuration): bool
{
return $this->store->storeServiceConfiguration($identifier, $name, $configuration);
}
}
+11 -48
View File
@@ -6,19 +6,14 @@ use KTXC\Models\Identity\User;
use KTXC\Context\IdentityContextInterface;
use KTXC\Context\TenantContextInterface;
use KTXC\Stores\UserAccountsStore;
use KTXC\User\Event\UserCreatedEvent;
use KTXC\User\Event\UserDeletingEvent;
use KTXC\User\Event\UserUpdatedEvent;
use KTXF\Event\EventDispatcherInterface;
class UserAccountsService
{
public function __construct(
private readonly TenantContextInterface $tenantContext,
private readonly IdentityContextInterface $identityContext,
private readonly UserAccountsStore $userStore,
private readonly EventDispatcherInterface $events,
private readonly IdentityContextInterface $identityContext,
private readonly UserAccountsStore $userStore
) {
}
@@ -70,53 +65,17 @@ class UserAccountsService
public function createUser(array $userData): array
{
$tenantId = $this->tenantContext->requireIdentifier();
$user = $this->userStore->createUser($tenantId, $userData);
$this->events->dispatch(UserCreatedEvent::fromUser(
$user,
$tenantId,
$this->identityContext->identifier(),
));
return $user;
return $this->userStore->createUser($this->tenantContext->identifier(), $userData);
}
public function updateUser(string $userId, array $updates): bool
public function updateUser(string $uid, array $updates): bool
{
$tenantId = $this->tenantContext->requireIdentifier();
if (!$this->userStore->updateUser($tenantId, $userId, $updates)) {
return false;
}
$user = $this->userStore->fetchByIdentifier($tenantId, $userId);
if ($user === null) {
throw new \RuntimeException("Updated user '{$userId}' could not be retrieved.");
}
$this->events->dispatch(UserUpdatedEvent::fromUser(
$user,
$tenantId,
$this->identityContext->identifier(),
));
return true;
return $this->userStore->updateUser($this->tenantContext->identifier(), $uid, $updates);
}
public function deleteUser(string $userId): bool
public function deleteUser(string $uid): bool
{
$tenantId = $this->tenantContext->requireIdentifier();
$user = $this->userStore->fetchByIdentifier($tenantId, $userId);
if ($user === null) {
return false;
}
$this->events->dispatch(UserDeletingEvent::fromUser(
$user,
$tenantId,
$this->identityContext->identifier(),
));
return $this->userStore->deleteUser($tenantId, $userId);
return $this->userStore->deleteUser($this->tenantContext->identifier(), $uid);
}
// =========================================================================
@@ -167,6 +126,10 @@ class UserAccountsService
return $this->userStore->storeSettings($this->tenantContext->identifier(), $this->identityContext->identifier(), $settings);
}
// =========================================================================
// Helper Methods
// =========================================================================
/**
* Check if a profile field is editable by the user
*
-93
View File
@@ -77,49 +77,6 @@ class TenantStore
$this->dataStore->selectCollection(self::COLLECTION_NAME)->deleteOne(['_id' => new ObjectId($id)]);
}
// =========================================================================
// Configuration Operations
// =========================================================================
public function fetchConfiguration(string $identifier, string $path): ?array
{
$entry = $this->dataStore->selectCollection(self::COLLECTION_NAME)->findOne(
['identifier' => $identifier],
['projection' => ['configuration.' . $path => 1]],
);
if (!$entry) {
return null;
}
$value = $this->readPath($entry, "configuration.{$path}");
return $value === null ? null : (array) $value;
}
public function storeConfiguration(string $identifier, string $path, array $value): bool
{
$result = $this->dataStore->selectCollection(self::COLLECTION_NAME)->updateOne(
['identifier' => $identifier],
['$set' => ['configuration.' . $path => $value]],
);
return $result->getMatchedCount() > 0;
}
public function removeConfiguration(string $identifier, string $path): ?bool
{
$result = $this->dataStore->selectCollection(self::COLLECTION_NAME)->updateOne(
['identifier' => $identifier],
['$unset' => ['configuration.' . $path => '']],
);
if ($result->getMatchedCount() === 0) {
return null;
}
return $result->getModifiedCount() > 0;
}
// =========================================================================
// Settings Operations
// =========================================================================
@@ -173,54 +130,4 @@ class TenantStore
return $result->getMatchedCount() > 0;
}
/**
* Atomically creates or replaces one logical store reference.
*
* @param array{provider: string, service: string|int, namespace: string} $reference
*/
public function storeConfigurationStore(string $identifier, string $name, array $reference): bool
{
return $this->storeConfiguration($identifier, "stores.{$name}", $reference);
}
/**
* Atomically removes one logical store reference.
*/
public function removeConfigurationStore(string $identifier, string $name): ?bool
{
return $this->removeConfiguration($identifier, "stores.{$name}");
}
public function fetchServiceConfiguration(string $identifier, string $name): ?array
{
$this->validateServiceName($name);
return $this->fetchConfiguration($identifier, "services.{$name}");
}
/** Save one service atomically. */
public function storeServiceConfiguration(string $identifier, string $name, array $configuration): bool
{
$this->validateServiceName($name);
return $this->storeConfiguration($identifier, "services.{$name}", $configuration);
}
private function validateServiceName(string $name): void
{
if (preg_match('/^[a-z][a-z0-9_]*$/D', $name) !== 1) {
throw new \InvalidArgumentException('Invalid service name.');
}
}
private function readPath(array $data, string $path): mixed
{
$value = $data;
foreach (explode('.', $path) as $segment) {
if (!is_array($value) || !array_key_exists($segment, $value)) {
return null;
}
$value = $value[$segment];
}
return $value;
}
}
@@ -1,65 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\SystemStore;
use KTXC\Stores\TenantStore;
use KTXF\SystemStore\StoreReference;
use KTXF\SystemStore\SystemStoreException;
/**
* Superuser-facing configuration operations for tenant logical stores.
*/
class SystemStoreConfigurationService
{
public function __construct(private readonly TenantStore $tenants)
{
}
/** @return array<string, StoreReference> */
public function list(string $tenantId): array
{
$tenant = $this->tenants->fetch($tenantId);
if ($tenant === null) {
throw new SystemStoreException("Tenant '{$tenantId}' was not found");
}
return $tenant->getConfiguration()->stores()->all();
}
public function set(
string $tenantId,
string $name,
string $provider,
string|int $service,
string $namespace,
): StoreReference {
self::validateName($name);
$reference = new StoreReference($provider, $service, $namespace);
if (!$this->tenants->storeConfigurationStore($tenantId, $name, $reference->toArray())) {
throw new SystemStoreException("Tenant '{$tenantId}' was not found");
}
return $reference;
}
public function remove(string $tenantId, string $name): bool
{
self::validateName($name);
$removed = $this->tenants->removeConfigurationStore($tenantId, $name);
if ($removed === null) {
throw new SystemStoreException("Tenant '{$tenantId}' was not found");
}
return $removed;
}
private static function validateName(string $name): void
{
if (preg_match('/^[a-z][a-z0-9-]*$/', $name) !== 1) {
throw new \InvalidArgumentException('Logical store names must use lowercase letters, numbers, and hyphens');
}
}
}
-167
View File
@@ -1,167 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\SystemStore;
use KTXC\Resource\ProviderManager;
use KTXC\Service\TenantService;
use KTXF\Resource\BinaryResource;
use KTXF\Resource\Provider\ProviderInterface;
use KTXF\Resource\SystemIdentity;
use KTXF\SystemStore\BlobInfo;
use KTXF\SystemStore\InvalidKeyException;
use KTXF\SystemStore\Provider\ProviderBaseInterface;
use KTXF\SystemStore\Service\SystemStoreServiceInterface;
use KTXF\SystemStore\StoreReference;
use KTXF\SystemStore\SystemStoreException;
use KTXF\SystemStore\SystemStoreManagerInterface;
use KTXF\SystemStore\WriteCondition;
final readonly class SystemStoreManager implements SystemStoreManagerInterface
{
public function __construct(
private TenantService $tenants,
private ProviderManager $providers,
) {
}
public function stat(string $tenantId, string $store, string $key): ?BlobInfo
{
[$service, $reference] = $this->resolve($tenantId, $store);
$info = $service->stat($this->qualify($reference, $key));
return $info === null ? null : $this->logicalInfo($info, $reference);
}
public function read(string $tenantId, string $store, string $key): ?BinaryResource
{
[$service, $reference] = $this->resolve($tenantId, $store);
return $service->read($this->qualify($reference, $key));
}
public function write(
string $tenantId,
string $store,
string $key,
BinaryResource $content,
array $metadata = [],
?WriteCondition $condition = null,
): BlobInfo {
[$service, $reference] = $this->resolve($tenantId, $store);
$info = $service->write(
$this->qualify($reference, $key),
$content,
$metadata,
$condition,
);
return $this->logicalInfo($info, $reference);
}
public function delete(
string $tenantId,
string $store,
string $key,
?WriteCondition $condition = null,
): bool {
[$service, $reference] = $this->resolve($tenantId, $store);
return $service->delete($this->qualify($reference, $key), $condition);
}
public function list(string $tenantId, string $store, string $prefix = ''): iterable
{
[$service, $reference] = $this->resolve($tenantId, $store);
$physicalPrefix = $reference->namespace . '/';
if ($prefix !== '') {
$physicalPrefix .= $this->normalizeKey($prefix, true);
}
return $this->logicalItems($service->list($physicalPrefix), $reference);
}
/** @return array{SystemStoreServiceInterface, StoreReference} */
private function resolve(string $tenantId, string $store): array
{
$tenant = $this->tenants->fetchById($tenantId);
if ($tenant === null) {
throw new SystemStoreException("Tenant '{$tenantId}' was not found");
}
$reference = $tenant->getConfiguration()->stores()->store($store);
if ($reference === null) {
throw new SystemStoreException("System store '{$store}' is not configured for tenant '{$tenantId}'");
}
$provider = $this->providers->resolve(ProviderInterface::TYPE_SYSTEM_STORE, $reference->provider);
if (!$provider instanceof ProviderBaseInterface) {
throw new SystemStoreException("System-store provider '{$reference->provider}' is unavailable or incompatible");
}
$service = $provider->serviceFetch($tenantId, SystemIdentity::USER, $reference->service);
if (!$service instanceof SystemStoreServiceInterface) {
throw new SystemStoreException("System-store service '{$reference->service}' is unavailable or incompatible");
}
return [$service, $reference];
}
private function qualify(StoreReference $reference, string $key): string
{
return $reference->namespace . '/' . $this->normalizeKey($key);
}
private function normalizeKey(string $key, bool $allowTrailingSlash = false): string
{
if (
$key === ''
|| str_starts_with($key, '/')
|| (!$allowTrailingSlash && str_ends_with($key, '/'))
|| str_contains($key, '\\')
|| str_contains($key, "\0")
) {
throw new InvalidKeyException('System-store keys must be non-empty normalized relative keys');
}
$segments = explode('/', $key);
if ($allowTrailingSlash && end($segments) === '') {
array_pop($segments);
}
if (in_array('', $segments, true) || in_array('.', $segments, true) || in_array('..', $segments, true)) {
throw new InvalidKeyException('System-store keys cannot contain empty or traversal segments');
}
return $key;
}
private function logicalInfo(BlobInfo $info, StoreReference $reference): BlobInfo
{
$prefix = $reference->namespace . '/';
if (!str_starts_with($info->key, $prefix)) {
throw new SystemStoreException('System-store provider returned a blob outside the configured namespace');
}
return new BlobInfo(
key: substr($info->key, strlen($prefix)),
mimeType: $info->mimeType,
size: $info->size,
etag: $info->etag,
modifiedAt: $info->modifiedAt,
attributes: $info->attributes,
);
}
/**
* @param iterable<BlobInfo> $items
* @return iterable<BlobInfo>
*/
private function logicalItems(iterable $items, StoreReference $reference): iterable
{
foreach ($items as $item) {
if (!$item instanceof BlobInfo) {
throw new SystemStoreException('System-store provider returned invalid listing metadata');
}
yield $this->logicalInfo($item, $reference);
}
}
}
-9
View File
@@ -1,9 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\User\Event;
final class UserCreatedEvent extends UserEvent
{
}
@@ -1,9 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\User\Event;
final class UserDeletingEvent extends UserEvent
{
}
-94
View File
@@ -1,94 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\User\Event;
use KTXF\Event\Event;
abstract class UserEvent extends Event
{
final public function __construct(
private readonly string $userIdentifier,
private readonly string $userIdentity,
private readonly string $userLabel,
private readonly bool $userEnabled,
private readonly array $userRoles,
private readonly string $tenantIdentifier,
private readonly ?string $actorIdentifier = null,
) {
if ($userIdentifier === '') {
throw new \InvalidArgumentException('User lifecycle events require a user ID.');
}
if ($userIdentity === '') {
throw new \InvalidArgumentException('User lifecycle events require a user identity.');
}
if ($tenantIdentifier === '') {
throw new \InvalidArgumentException('User lifecycle events require a tenant ID.');
}
parent::__construct(
static::class,
[
'identifier' => $userIdentifier,
'identity' => $userIdentity,
'label' => $userLabel,
'roles' => $userRoles,
'enabled' => $userEnabled,
],
$tenantIdentifier,
$actorIdentifier,
);
}
public static function fromUser(
array $user,
string $tenantIdentifier,
?string $actorIdentifier = null,
): static {
return new static(
(string) ($user['uid'] ?? ''),
(string) ($user['identity'] ?? ''),
(string) ($user['label'] ?? $user['identity'] ?? ''),
(bool) ($user['enabled'] ?? true),
array_values((array) ($user['roles'] ?? [])),
$tenantIdentifier,
$actorIdentifier,
);
}
public function userIdentifier(): string
{
return $this->userIdentifier;
}
public function tenantIdentifier(): string
{
return $this->tenantIdentifier;
}
public function userIdentity(): string
{
return $this->userIdentity;
}
public function userLabel(): string
{
return $this->userLabel;
}
public function userRoles(): array
{
return $this->userRoles;
}
public function userEnabled(): bool
{
return $this->userEnabled;
}
public function actorIdentifier(): ?string
{
return $this->actorIdentifier;
}
}
-9
View File
@@ -1,9 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXC\User\Event;
final class UserUpdatedEvent extends UserEvent
{
}
+4 -1
View File
@@ -88,9 +88,12 @@ const userAvatar = computed(() => userStore.getProfileField('avatar') || default
<template v-slot:activator="{ props }">
<v-btn class="profileBtn" variant="text" rounded="sm" v-bind="props">
<div class="d-flex align-center">
<v-avatar size="32">
<v-avatar class="mr-sm-2 mr-0" size="32">
<v-img :src="userAvatar" :alt="userAuth?.label || 'User'" cover />
</v-avatar>
<h6 class="text-subtitle-1 mb-0 d-sm-block d-none">
{{ userAuth?.label }}
</h6>
</div>
</v-btn>
</template>
+39 -50
View File
@@ -1,8 +1,7 @@
<script setup lang="ts">
import { computed, watch } from 'vue';
import { computed } from 'vue';
import { useLayoutStore, type MenuMode } from '@KTXC/stores/layoutStore';
import { useIntegrationStore } from '@KTXC/stores/integrationStore';
import type { IntegrationPointType } from '@KTXC/types/integrationTypes';
import { useL10n } from '@KTXC/composables/useL10n';
import Logo from '@KTXC/layouts/logo/LogoDark.vue';
import SystemMenuGroupStatic from './LayoutSystemMenuGroupStatic.vue';
@@ -13,33 +12,25 @@ const layoutStore = useLayoutStore();
const integrationStore = useIntegrationStore();
const { t } = useL10n('core');
const menuPointByMode: Record<MenuMode, IntegrationPointType> = {
apps: 'app_menu',
'user-settings': 'user_settings_menu',
'admin-settings': 'admin_settings_menu',
};
// Get all entries based on current menu mode
const menuEntries = computed(() => integrationStore.getPoint(menuPointByMode[layoutStore.menuMode]));
// Only show menu modes that currently have visible items.
const menuModes = computed((): Array<{ value: MenuMode; icon: string; label: string }> => {
const modes: Array<{ value: MenuMode; icon: string; label: string }> = [
{ value: 'apps', icon: 'mdi-view-dashboard', label: t('systemMenu.apps', 'Applications') },
{ value: 'user-settings', icon: 'mdi-account-cog', label: t('systemMenu.personalSettings', 'Settings') },
{ value: 'admin-settings', icon: 'mdi-shield-crown', label: t('systemMenu.adminSettings', 'System') },
];
return modes.filter(mode => integrationStore.getPoint(menuPointByMode[mode.value]).length > 0);
const menuEntries = computed(() => {
switch (layoutStore.menuMode) {
case 'user-settings':
return integrationStore.getPoint('user_settings_menu');
case 'admin-settings':
return integrationStore.getPoint('admin_settings_menu');
case 'apps':
default:
return integrationStore.getPoint('app_menu');
}
});
// If the active menu becomes empty (for example, after a module is disabled),
// move to the first menu that still has content.
watch(menuModes, (availableModes) => {
if (availableModes.length > 0 && !availableModes.some(mode => mode.value === layoutStore.menuMode)) {
layoutStore.setMenuMode(availableModes[0].value);
}
}, { immediate: true });
// Static list of menu modes shown as icon buttons
const menuModes = computed((): Array<{ value: MenuMode; icon: string; label: string }> => [
{ value: 'apps', icon: 'mdi-view-dashboard', label: t('systemMenu.apps', 'Applications') },
{ value: 'user-settings', icon: 'mdi-account-cog', label: t('systemMenu.personalSettings', 'Settings') },
{ value: 'admin-settings', icon: 'mdi-shield-crown', label: t('systemMenu.adminSettings', 'System') },
]);
</script>
<script lang="ts">
@@ -93,30 +84,28 @@ export default {
<!-- Menu Mode Switcher -->
<template v-slot:append>
<div v-if="menuModes.length">
<v-divider />
<div class="menu-mode-switcher d-flex justify-space-around align-center py-2">
<v-tooltip
v-for="mode in menuModes"
:key="mode.value"
location="right"
>
<template v-slot:activator="{ props }">
<v-btn
v-bind="props"
icon
variant="text"
density="comfortable"
:color="layoutStore.menuMode === mode.value ? 'primary' : undefined"
:class="['menu-mode-btn', { 'menu-mode-btn--active': layoutStore.menuMode === mode.value }]"
@click="layoutStore.setMenuMode(mode.value)"
>
<v-icon>{{ mode.icon }}</v-icon>
</v-btn>
</template>
<span>{{ mode.label }}</span>
</v-tooltip>
</div>
<v-divider />
<div class="menu-mode-switcher d-flex justify-space-around align-center py-2">
<v-tooltip
v-for="mode in menuModes"
:key="mode.value"
location="right"
>
<template v-slot:activator="{ props }">
<v-btn
v-bind="props"
icon
variant="text"
density="comfortable"
:color="layoutStore.menuMode === mode.value ? 'primary' : undefined"
:class="['menu-mode-btn', { 'menu-mode-btn--active': layoutStore.menuMode === mode.value }]"
@click="layoutStore.setMenuMode(mode.value)"
>
<v-icon>{{ mode.icon }}</v-icon>
</v-btn>
</template>
<span>{{ mode.label }}</span>
</v-tooltip>
</div>
</template>
</v-navigation-drawer>
+18 -9
View File
@@ -3,11 +3,13 @@ import { computed } from 'vue';
import { useUserStore } from '@KTXC/stores/userStore';
import { useIntegrationStore } from '@KTXC/stores/integrationStore';
import { useLayoutStore } from '@KTXC/stores/layoutStore';
import { useRouter } from 'vue-router';
import { useL10n, t as tGlobal } from '@KTXC/composables/useL10n';
import defaultAvatar from '@KTXC/assets/images/users/avatar-1.png';
const { t } = useL10n('core');
const router = useRouter();
const userStore = useUserStore();
const integrationStore = useIntegrationStore();
const layoutStore = useLayoutStore();
@@ -41,6 +43,12 @@ const cycleTheme = () => {
layoutStore.setTheme(nextThemeMode.value);
};
// Navigate to settings
const goToSettings = () => {
layoutStore.setMenuMode('settings');
// Navigate to first settings item or a default settings route
router.push('/modules'); // TODO: Make this dynamic based on first settings menu item
};
</script>
<template>
@@ -54,9 +62,9 @@ const cycleTheme = () => {
<v-img :src="userAvatar" :alt="userName" cover />
</v-avatar>
<div class="flex-grow-1">
<h5 class="user-menu-name mb-0 font-weight-bold">
<h6 class="text-h6 mb-0 font-weight-medium">
{{ userName }}
</h5>
</h6>
<p class="text-caption mb-0 text-medium-emphasis">{{ userEmail }}</p>
</div>
</div>
@@ -90,6 +98,14 @@ const cycleTheme = () => {
<v-list-item-title class="text-h6">{{ t(MODE_PRESENTATION[nextThemeMode].l10n, MODE_PRESENTATION[nextThemeMode].label) }}</v-list-item-title>
</v-list-item>
<!-- Go to Settings -->
<v-list-item @click="goToSettings" color="primary" rounded="0">
<template v-slot:prepend>
<v-icon>mdi-cog-outline</v-icon>
</template>
<v-list-item-title class="text-h6">{{ t('userMenu.settings', 'Settings') }}</v-list-item-title>
</v-list-item>
<v-divider class="my-2" />
<!-- Logout -->
@@ -103,10 +119,3 @@ const cycleTheme = () => {
</perfect-scrollbar>
</div>
</template>
<style scoped>
.user-menu-name {
font-size: 18px !important;
line-height: 1.2;
}
</style>
-3
View File
@@ -6,7 +6,6 @@ import { createPinia } from 'pinia'
import { PerfectScrollbarPlugin } from 'vue3-perfect-scrollbar'
import { useModuleStore } from '@KTXC/stores/moduleStore'
import { useTenantStore } from '@KTXC/stores/tenantStore'
import { usePreviewStore } from '@KTXC/stores/previewStore'
import { useUserStore } from '@KTXC/stores/userStore'
import { useL10nStore } from '@KTXC/stores/l10nStore'
import { useThemeStore } from '@KTXC/stores/themeStore'
@@ -42,7 +41,6 @@ globalWindow.Pinia = PiniaLib as unknown
(async () => {
const moduleStore = useModuleStore();
const tenantStore = useTenantStore();
const previewStore = usePreviewStore();
const userStore = useUserStore();
const l10nStore = useL10nStore();
const themeStore = useThemeStore();
@@ -51,7 +49,6 @@ globalWindow.Pinia = PiniaLib as unknown
try {
const payload = await fetchWrapper.get('/init');
moduleStore.init(payload?.modules ?? {});
previewStore.init(payload?.preview ?? null);
tenantStore.init(payload?.tenant ?? null);
userStore.init(payload?.user ?? {});
layoutStore.hydrateFromSettings();
-2
View File
@@ -9,8 +9,6 @@
// Stores
export { useModuleStore } from '../stores/moduleStore'
export { useTenantStore } from '../stores/tenantStore'
export { usePreviewStore } from '../stores/previewStore'
export type { PreviewAvailability } from '../stores/previewStore'
export { useUserStore } from '../stores/userStore'
export { useIntegrationStore } from '../stores/integrationStore'
export { useLayoutStore } from '../stores/layoutStore'
-4
View File
@@ -156,10 +156,6 @@ export const useIntegrationStore = defineStore('integrationStore', {
return Array.from(point.items.values())
.filter(entry => entry.visible !== false)
.map(entry => 'items' in entry
? { ...entry, items: entry.items.filter(item => item.visible !== false) }
: entry)
.filter(entry => !('items' in entry) || entry.items.length > 0)
.sort((a, b) => (a.priority ?? 100) - (b.priority ?? 100));
},
+2 -2
View File
@@ -32,7 +32,7 @@ export const useLayoutStore = defineStore('layout', () => {
}
const sidebarDrawer = ref<boolean>(booleanSetting('sidebar_drawer', true));
const miniSidebar = ref<boolean>(booleanSetting('mini_sidebar', true));
const miniSidebar = ref<boolean>(booleanSetting('mini_sidebar', false));
const menuMode = ref<MenuMode>('apps');
// Theme mode - user choice, falling back to the tenant default
@@ -60,7 +60,7 @@ export const useLayoutStore = defineStore('layout', () => {
hydratingFromSettings = true;
try {
sidebarDrawer.value = booleanSetting('sidebar_drawer', true);
miniSidebar.value = booleanSetting('mini_sidebar', true);
miniSidebar.value = booleanSetting('mini_sidebar', false);
theme.value = initialTheme();
} finally {
hydratingFromSettings = false;
-36
View File
@@ -1,36 +0,0 @@
import { defineStore } from 'pinia'
import { ref } from 'vue'
export interface PreviewAvailability {
enabled: boolean
storage: boolean
generation: boolean
}
const unavailable = (): PreviewAvailability => ({
enabled: false,
storage: false,
generation: false,
})
export const usePreviewStore = defineStore('previewStore', () => {
const availability = ref<PreviewAvailability>(unavailable())
function init(data?: Partial<PreviewAvailability> | null): void {
availability.value = {
enabled: data?.enabled ?? false,
storage: data?.storage ?? false,
generation: data?.generation ?? false,
}
}
function reset(): void {
availability.value = unavailable()
}
return {
availability,
init,
reset,
}
})
+20 -31
View File
@@ -1,5 +1,5 @@
<script setup lang="ts">
import { ref, onMounted, computed, watch, nextTick } from 'vue';
import { ref, onMounted, computed, watch } from 'vue';
import { useRoute } from 'vue-router';
import { useUserStore } from '@KTXC/stores/userStore';
import { authenticationService } from '@KTXC/services/authenticationService';
@@ -15,7 +15,6 @@ type LoginPhase = 'identity' | 'method' | 'mfa';
// Form state
const identity = ref('');
const authResponse = ref(''); // password, code, etc.
const authInput = ref<{ focus: () => void } | null>(null);
const showPassword = ref(false);
const rememberMe = ref(false);
@@ -61,19 +60,21 @@ const pageTitle = computed(() => {
});
// Input label/type based on selected method
const isPasswordMethod = computed(() => selectedMethod.value?.id === 'password');
const authInputLabel = computed(() => {
return isPasswordMethod.value ? 'Password' : 'Verification Code';
if (!selectedMethod.value) return 'Password';
return selectedMethod.value.method === 'credential' ? 'Password' : 'Verification Code';
});
const authInputType = computed(() => {
return isPasswordMethod.value ? 'password' : 'text';
if (!selectedMethod.value) return 'password';
return selectedMethod.value.method === 'credential' ? 'password' : 'text';
});
// Validation rules
const identityRules = [
(v: string) => !!v.trim() || 'Login ID is required',
(v: string) => !!v.trim() || 'Email is required',
(v: string) => !/\s/.test(v.trim()) || 'Email must not contain spaces',
(v: string) => /.+@.+\..+/.test(v.trim()) || 'Email must be valid'
];
const authResponseRules = [
@@ -116,9 +117,6 @@ onMounted(async () => {
// Watch for method selection changes (for challenge-based methods)
watch(selectedMethod, async (newMethod) => {
await nextTick();
authInput.value?.focus();
if (newMethod && newMethod.method === 'challenge' && !challengeSent.value) {
// Initiate challenge for methods that need it (SMS, email, TOTP)
await initiateChallenge(newMethod.id);
@@ -315,16 +313,7 @@ function backToIdentity() {
}
function getMethodIcon(method: AuthenticationMethod): string {
if (method.icon?.startsWith('mdi-') || method.icon?.startsWith('$')) {
return method.icon;
}
// Authentication providers may return a bare Material Design icon name
// (for example, "lock" or "mail") instead of Vuetify's "mdi-*" form.
if (method.icon && /^[a-z0-9-]+$/i.test(method.icon)) {
return `mdi-${method.icon}`;
}
if (method.icon) return method.icon;
switch (method.method) {
case 'credential': return 'mdi-key';
case 'challenge': return 'mdi-shield-check';
@@ -362,15 +351,16 @@ function getMethodIcon(method: AuthenticationMethod): string {
v-slot="{ errors, isSubmitting }"
>
<div class="mb-6">
<v-label>Email Address</v-label>
<v-text-field
v-model="identity"
:rules="identityRules"
aria-label="Login ID"
class="mt-2"
required
hide-details="auto"
variant="outlined"
color="primary"
autocomplete="username"
autocomplete="email"
autofocus
></v-text-field>
</div>
@@ -401,7 +391,7 @@ function getMethodIcon(method: AuthenticationMethod): string {
size="large"
@click="initiateSsoLogin(method.id)"
>
<v-icon start>{{ getMethodIcon(method) }}</v-icon>
<v-icon v-if="method.icon" start>{{ method.icon }}</v-icon>
{{ method.label }}
</v-btn>
</div>
@@ -455,18 +445,18 @@ function getMethodIcon(method: AuthenticationMethod): string {
v-slot="{ errors, isSubmitting }"
>
<div class="mb-6">
<v-label>{{ authInputLabel }}</v-label>
<v-text-field
ref="authInput"
v-model="authResponse"
:rules="authResponseRules"
:type="authInputType === 'password' && !showPassword ? 'password' : 'text'"
:aria-label="authInputLabel"
class="mt-2"
required
hide-details="auto"
variant="outlined"
color="primary"
:autocomplete="isPasswordMethod ? 'current-password' : 'off'"
:inputmode="isPasswordMethod ? undefined : 'numeric'"
:autocomplete="selectedMethod?.method === 'credential' ? 'current-password' : 'one-time-code'"
:inputmode="selectedMethod?.method !== 'credential' ? 'numeric' : undefined"
autofocus
>
<template v-if="authInputType === 'password'" v-slot:append-inner>
@@ -480,7 +470,7 @@ function getMethodIcon(method: AuthenticationMethod): string {
</v-text-field>
</div>
<div v-if="isPasswordMethod" class="d-flex align-center mt-4 mb-7 mb-sm-0">
<div v-if="selectedMethod?.method === 'credential'" class="d-flex align-center mt-4 mb-7 mb-sm-0">
<v-checkbox
v-model="rememberMe"
label="Keep me logged in"
@@ -503,7 +493,7 @@ function getMethodIcon(method: AuthenticationMethod): string {
size="large"
type="submit"
>
{{ isPasswordMethod ? 'Login' : 'Verify' }}
{{ selectedMethod?.method === 'credential' ? 'Login' : 'Verify' }}
</v-btn>
<v-btn
@@ -544,7 +534,6 @@ function getMethodIcon(method: AuthenticationMethod): string {
<div class="mb-6">
<v-label>Verification Code</v-label>
<v-text-field
ref="authInput"
v-model="authResponse"
:rules="authResponseRules"
type="text"
@@ -553,7 +542,7 @@ function getMethodIcon(method: AuthenticationMethod): string {
hide-details="auto"
variant="outlined"
color="primary"
autocomplete="off"
autocomplete="one-time-code"
inputmode="numeric"
autofocus
></v-text-field>
-24
View File
@@ -33,30 +33,6 @@ require_command()
fi
}
# Cron runs with a bare PATH, so nvm-installed npm (added to PATH only by
# .bashrc sourcing nvm.sh in an interactive shell) is invisible here even
# though it works fine when this script is run by hand. Resolve nvm's
# current npm via bash (nvm.sh is not POSIX sh compatible) and prepend it,
# so a later `nvm use`/`nvm install` doesn't require updating this script
# or the crontab.
ensure_npm_on_path()
{
command -v npm >/dev/null 2>&1 && return 0
nvm_dir=${NVM_DIR:-${HOME:-/root}/.nvm}
[ -s "$nvm_dir/nvm.sh" ] || return 0
command -v bash >/dev/null 2>&1 || return 0
npm_path=$(bash -c ". \"\$1/nvm.sh\" >/dev/null 2>&1 && command -v npm" _ "$nvm_dir" 2>/dev/null) || return 0
[ -n "$npm_path" ] || return 0
PATH=$(dirname -- "$npm_path"):$PATH
export PATH
log "Resolved npm via nvm: $npm_path"
}
ensure_npm_on_path
git_in()
{
repository=$1
+101 -158
View File
@@ -39,7 +39,7 @@
"@vue/tsconfig": "^0.9.1",
"eslint": "^10.3.0",
"eslint-plugin-vue": "^10.9.1",
"jsdom": "^30.0.0",
"jsdom": "^29.1.1",
"prettier": "^3.8.3",
"sass": "^1.99.0",
"sass-loader": "^17.0.0",
@@ -53,38 +53,56 @@
}
},
"node_modules/@asamuzakjp/css-color": {
"version": "6.0.5",
"resolved": "https://registry.npmjs.org/@asamuzakjp/css-color/-/css-color-6.0.5.tgz",
"integrity": "sha512-mbhpPMmnw/kwW19aRNmSUl1QzLbdGo1SCuE49BT98MNwqF6zaHb3o2owssFc/PEO/4t2UjqtCNwocuDtJornzA==",
"version": "5.1.11",
"resolved": "https://registry.npmjs.org/@asamuzakjp/css-color/-/css-color-5.1.11.tgz",
"integrity": "sha512-KVw6qIiCTUQhByfTd78h2yD1/00waTmm9uy/R7Ck/ctUyAPj+AEDLkQIdJW0T8+qGgj3j5bpNKK7Q3G+LedJWg==",
"dev": true,
"license": "MIT",
"dependencies": {
"@csstools/css-calc": "^3.2.1",
"@csstools/css-color-parser": "^4.1.9",
"@asamuzakjp/generational-cache": "^1.0.1",
"@csstools/css-calc": "^3.2.0",
"@csstools/css-color-parser": "^4.1.0",
"@csstools/css-parser-algorithms": "^4.0.0",
"@csstools/css-tokenizer": "^4.0.0",
"lru-cache": "^11.5.2"
"@csstools/css-tokenizer": "^4.0.0"
},
"engines": {
"node": "^22.13.0 || >=24.0.0"
"node": "^20.19.0 || ^22.12.0 || >=24.0.0"
}
},
"node_modules/@asamuzakjp/dom-selector": {
"version": "8.3.0",
"resolved": "https://registry.npmjs.org/@asamuzakjp/dom-selector/-/dom-selector-8.3.0.tgz",
"integrity": "sha512-UJLfKXBhrc8i1vH2eJXuYQMwlsLKWFw3O+CPqXSuVEiikeAim3UgrfWX0k4tA/X8cRFM8iZ7OaqBokFGbYusdg==",
"version": "7.1.1",
"resolved": "https://registry.npmjs.org/@asamuzakjp/dom-selector/-/dom-selector-7.1.1.tgz",
"integrity": "sha512-67RZDnYRc8H/8MLDgQCDE//zoqVFwajkepHZgmXrbwybzXOEwOWGPYGmALYl9J2DOLfFPPs6kKCqmbzV895hTQ==",
"dev": true,
"license": "MIT",
"dependencies": {
"@asamuzakjp/generational-cache": "^1.0.1",
"@asamuzakjp/nwsapi": "^2.3.9",
"bidi-js": "^1.0.3",
"css-tree": "^3.2.1",
"is-potential-custom-element-name": "^1.0.1",
"lru-cache": "^11.5.2"
"is-potential-custom-element-name": "^1.0.1"
},
"engines": {
"node": "^22.13.0 || >=24.0.0"
"node": "^20.19.0 || ^22.12.0 || >=24.0.0"
}
},
"node_modules/@asamuzakjp/generational-cache": {
"version": "1.0.1",
"resolved": "https://registry.npmjs.org/@asamuzakjp/generational-cache/-/generational-cache-1.0.1.tgz",
"integrity": "sha512-wajfB8KqzMCN2KGNFdLkReeHncd0AslUSrvHVvvYWuU8ghncRJoA50kT3zP9MVL0+9g4/67H+cdvBskj9THPzg==",
"dev": true,
"license": "MIT",
"engines": {
"node": "^20.19.0 || ^22.12.0 || >=24.0.0"
}
},
"node_modules/@asamuzakjp/nwsapi": {
"version": "2.3.9",
"resolved": "https://registry.npmjs.org/@asamuzakjp/nwsapi/-/nwsapi-2.3.9.tgz",
"integrity": "sha512-n8GuYSrI9bF7FFZ/SjhwevlHc8xaVlb/7HmHelnc/PZXBD2ZR49NnN9sMMuDdEGPeeRQ5d0hqlSlEpgCX3Wl0Q==",
"dev": true,
"license": "MIT"
},
"node_modules/@babel/generator": {
"version": "8.0.0",
"resolved": "https://registry.npmjs.org/@babel/generator/-/generator-8.0.0.tgz",
@@ -218,9 +236,9 @@
}
},
"node_modules/@csstools/color-helpers": {
"version": "6.1.0",
"resolved": "https://registry.npmjs.org/@csstools/color-helpers/-/color-helpers-6.1.0.tgz",
"integrity": "sha512-064IFJdjTfUqnjpCVpMOdbr8FLQBhinbZj6yRv2An2E41O/pLEXqfFRWqGq/SxlE5PEUYTlvWsG2r8MswAVvkg==",
"version": "6.0.2",
"resolved": "https://registry.npmjs.org/@csstools/color-helpers/-/color-helpers-6.0.2.tgz",
"integrity": "sha512-LMGQLS9EuADloEFkcTBR3BwV/CGHV7zyDxVRtVDTwdI2Ca4it0CCVTT9wCkxSgokjE5Ho41hEPgb8OEUwoXr6Q==",
"dev": true,
"funding": [
{
@@ -238,9 +256,9 @@
}
},
"node_modules/@csstools/css-calc": {
"version": "3.3.0",
"resolved": "https://registry.npmjs.org/@csstools/css-calc/-/css-calc-3.3.0.tgz",
"integrity": "sha512-c5ihYsPkdG6JCkU2zTMm4+k6r7RXuGxtWYhu5DHMIiF1FHzrfmHL5so11AoFpUv/tu61xfcmT4AmKoFfMPoqdQ==",
"version": "3.2.1",
"resolved": "https://registry.npmjs.org/@csstools/css-calc/-/css-calc-3.2.1.tgz",
"integrity": "sha512-DtdHlgXh5ZkA43cwBcAm+huzgJiwx3ZTWVjBs94kwz2xKqSimDA3lBgCjphYgwgVUMWatSM0pDd8TILB1yrVVg==",
"dev": true,
"funding": [
{
@@ -262,9 +280,9 @@
}
},
"node_modules/@csstools/css-color-parser": {
"version": "4.1.10",
"resolved": "https://registry.npmjs.org/@csstools/css-color-parser/-/css-color-parser-4.1.10.tgz",
"integrity": "sha512-UZhQLIUyJaaMepqehrCODwCg2KW25vFvLWBmqYFaPclYvvxzj/sG8LBOhBFCp11i9uE7t1EyS+RAoV9tztPFyw==",
"version": "4.1.1",
"resolved": "https://registry.npmjs.org/@csstools/css-color-parser/-/css-color-parser-4.1.1.tgz",
"integrity": "sha512-eZ5XOtyhK+mggRafYUWzA0tvaYOFgdY8AkgQiCJF9qNAePnUo/zmsqqYubBBb3sQ8uNUaSKTY9s9klfRaAXL0g==",
"dev": true,
"funding": [
{
@@ -278,8 +296,8 @@
],
"license": "MIT",
"dependencies": {
"@csstools/color-helpers": "^6.1.0",
"@csstools/css-calc": "^3.3.0"
"@csstools/color-helpers": "^6.0.2",
"@csstools/css-calc": "^3.2.1"
},
"engines": {
"node": ">=20.19.0"
@@ -313,9 +331,9 @@
}
},
"node_modules/@csstools/css-syntax-patches-for-csstree": {
"version": "1.1.7",
"resolved": "https://registry.npmjs.org/@csstools/css-syntax-patches-for-csstree/-/css-syntax-patches-for-csstree-1.1.7.tgz",
"integrity": "sha512-fQ+05118eQS1cofO3aJpB5efgpBZMvIzwr/sbC8kDLVA5XLG8q1kJV5yzrUAI1f7lvhPnm8fgIjzFB8/O/5Dig==",
"version": "1.1.4",
"resolved": "https://registry.npmjs.org/@csstools/css-syntax-patches-for-csstree/-/css-syntax-patches-for-csstree-1.1.4.tgz",
"integrity": "sha512-wgsqt92b7C7tQhIdPNxj0n9zuUbQlvAuI1exyzeNrOKOi62SD7ren8zqszmpVREjAOqg8cD2FqYhQfAuKjk4sw==",
"dev": true,
"funding": [
{
@@ -509,9 +527,9 @@
}
},
"node_modules/@exodus/bytes": {
"version": "1.15.1",
"resolved": "https://registry.npmjs.org/@exodus/bytes/-/bytes-1.15.1.tgz",
"integrity": "sha512-S6mL0yNB/Abt9Ei4tq8gDhcczc4S3+vQ4ra7vxnAf+YHC02srtqxKKZghx2Dq6p0e66THKwR6r8N6P95wEty7Q==",
"version": "1.15.0",
"resolved": "https://registry.npmjs.org/@exodus/bytes/-/bytes-1.15.0.tgz",
"integrity": "sha512-UY0nlA+feH81UGSHv92sLEPLCeZFjXOuHhrIo0HQydScuQc8s0A7kL/UdgwgDq8g8ilksmuoF35YVTNphV2aBQ==",
"dev": true,
"license": "MIT",
"engines": {
@@ -624,14 +642,14 @@
}
},
"node_modules/@intlify/core-base": {
"version": "11.4.10",
"resolved": "https://registry.npmjs.org/@intlify/core-base/-/core-base-11.4.10.tgz",
"integrity": "sha512-+yJ74JRWVJokdgG9zYNMyTSzeNV3O9T4vVxk8PvLFHmI+R/BYA//cITh7vhRK37hWLZ4/kTcKcUz1dlWOpypIg==",
"version": "11.4.7",
"resolved": "https://registry.npmjs.org/@intlify/core-base/-/core-base-11.4.7.tgz",
"integrity": "sha512-MSB/sBKwEWJTILvQIhg2rnIcwPpLayo3wGwvVA+dJTNeUBD9GoqQgAaSOLdI9iOPDHCm9YoVnLqpfzza98MpkQ==",
"license": "MIT",
"dependencies": {
"@intlify/devtools-types": "11.4.10",
"@intlify/message-compiler": "11.4.10",
"@intlify/shared": "11.4.10"
"@intlify/devtools-types": "11.4.7",
"@intlify/message-compiler": "11.4.7",
"@intlify/shared": "11.4.7"
},
"engines": {
"node": ">= 22"
@@ -641,13 +659,13 @@
}
},
"node_modules/@intlify/devtools-types": {
"version": "11.4.10",
"resolved": "https://registry.npmjs.org/@intlify/devtools-types/-/devtools-types-11.4.10.tgz",
"integrity": "sha512-xZxzZsAuu6/0zoLRVQWdpXWe5Kjl0LnWpjlQA3r9u9FbLYMhapqt7IwkgQyn0Tm2GUNAqhj9eZiUmYOrB024BQ==",
"version": "11.4.7",
"resolved": "https://registry.npmjs.org/@intlify/devtools-types/-/devtools-types-11.4.7.tgz",
"integrity": "sha512-GSz+J+hqH+AEpAHIYya6fSufS30OaMnG39HiZX7DmGKi3+aaLvassCfsXENEc4Wr4m68q2YP0QdMdB3D9UeAXg==",
"license": "MIT",
"dependencies": {
"@intlify/core-base": "11.4.10",
"@intlify/shared": "11.4.10"
"@intlify/core-base": "11.4.7",
"@intlify/shared": "11.4.7"
},
"engines": {
"node": ">= 22"
@@ -657,12 +675,12 @@
}
},
"node_modules/@intlify/message-compiler": {
"version": "11.4.10",
"resolved": "https://registry.npmjs.org/@intlify/message-compiler/-/message-compiler-11.4.10.tgz",
"integrity": "sha512-oUB/scz2EJENXDiUJ7JjZffOrH8UIZ1BuZeHvonbi5fWLavLt04aivuk2OIByOZA0tsci1bkeeQRmwhb5M8Imw==",
"version": "11.4.7",
"resolved": "https://registry.npmjs.org/@intlify/message-compiler/-/message-compiler-11.4.7.tgz",
"integrity": "sha512-bHxmh7n94N4N1evADeb7XTkc3jTw6Ki5biMFZVSX6Jmk+iehy8/maeH2XUsBI27rtKIK+Hzc6QnVAKggUwylKw==",
"license": "MIT",
"dependencies": {
"@intlify/shared": "11.4.10",
"@intlify/shared": "11.4.7",
"source-map-js": "^1.0.2"
},
"engines": {
@@ -673,9 +691,9 @@
}
},
"node_modules/@intlify/shared": {
"version": "11.4.10",
"resolved": "https://registry.npmjs.org/@intlify/shared/-/shared-11.4.10.tgz",
"integrity": "sha512-FeImVdPeoSHTm3NBFFZHv0eRP9gQ3F4lj2puDBX5Kw7iiM1uJW6JTf39ian0K/17pbXCI3ef5i9RVsRrALqI6Q==",
"version": "11.4.7",
"resolved": "https://registry.npmjs.org/@intlify/shared/-/shared-11.4.7.tgz",
"integrity": "sha512-OtjPZan3No2OZZFnMUiCVsXC6+j+XRwEywaFDk0AoayAbLuPesyDloXhJZLl9JUl5vHZeQUkYSbEA8VX+CWMjg==",
"license": "MIT",
"engines": {
"node": ">= 22"
@@ -2174,63 +2192,6 @@
"vuetify": ">=3"
}
},
"node_modules/@vuetify/v0": {
"version": "1.2.2",
"resolved": "https://registry.npmjs.org/@vuetify/v0/-/v0-1.2.2.tgz",
"integrity": "sha512-7AvM89l6l/pShSYKa+a5/zsht/xj/l4jFpWFOR6UqSelBrPfKxEQ8heO8iCNEGNK5yljwsdARx0JmDJjJRJdVw==",
"funding": [
{
"type": "github",
"url": "https://github.com/sponsors/johnleider"
},
{
"type": "opencollective",
"url": "https://opencollective.com/vuetify"
}
],
"license": "MIT",
"peerDependencies": {
"@adobe/leonardo-contrast-colors": ">=1.0.0",
"@ant-design/colors": ">=7.0.0",
"@flagsmith/flagsmith": ">=11.0.0",
"@floating-ui/dom": ">=1.8.0",
"@js-temporal/polyfill": ">=0.5.0",
"@material/material-color-utilities": ">=0.3.0",
"launchdarkly-js-client-sdk": "^3.0.0",
"posthog-js": "^1.0.0",
"vue": ">=3.5.0 || >=3.6.0-0",
"vue-i18n": ">=10.0.0"
},
"peerDependenciesMeta": {
"@adobe/leonardo-contrast-colors": {
"optional": true
},
"@ant-design/colors": {
"optional": true
},
"@flagsmith/flagsmith": {
"optional": true
},
"@floating-ui/dom": {
"optional": true
},
"@js-temporal/polyfill": {
"optional": true
},
"@material/material-color-utilities": {
"optional": true
},
"launchdarkly-js-client-sdk": {
"optional": true
},
"posthog-js": {
"optional": true
},
"vue-i18n": {
"optional": true
}
}
},
"node_modules/@webassemblyjs/ast": {
"version": "1.14.1",
"resolved": "https://registry.npmjs.org/@webassemblyjs/ast/-/ast-1.14.1.tgz",
@@ -4048,39 +4009,39 @@
"license": "MIT"
},
"node_modules/jsdom": {
"version": "30.0.0",
"resolved": "https://registry.npmjs.org/jsdom/-/jsdom-30.0.0.tgz",
"integrity": "sha512-JQHfRGmmKmaZoUAvIgff5jjG/0SzTQlGz8c7t72KzBzo8ZULEjAjnYE0sNwBOUA4QtWwYE2xoYitg8NFsmiYxA==",
"version": "29.1.1",
"resolved": "https://registry.npmjs.org/jsdom/-/jsdom-29.1.1.tgz",
"integrity": "sha512-ECi4Fi2f7BdJtUKTflYRTiaMxIB0O6zfR1fX0GXpUrf6flp8QIYn1UT20YQqdSOfk2dfkCwS8LAFoJDEppNK5Q==",
"dev": true,
"license": "MIT",
"dependencies": {
"@asamuzakjp/css-color": "^6.0.5",
"@asamuzakjp/dom-selector": "^8.2.5",
"@asamuzakjp/css-color": "^5.1.11",
"@asamuzakjp/dom-selector": "^7.1.1",
"@bramus/specificity": "^2.4.2",
"@csstools/css-syntax-patches-for-csstree": "^1.1.6",
"@exodus/bytes": "^1.15.1",
"@csstools/css-syntax-patches-for-csstree": "^1.1.3",
"@exodus/bytes": "^1.15.0",
"css-tree": "^3.2.1",
"data-urls": "^7.0.0",
"decimal.js": "^10.6.0",
"html-encoding-sniffer": "^6.0.0",
"is-potential-custom-element-name": "^1.0.1",
"lru-cache": "^11.5.2",
"lru-cache": "^11.3.5",
"parse5": "^8.0.1",
"saxes": "^6.0.0",
"symbol-tree": "^3.2.4",
"tough-cookie": "^6.0.2",
"undici": "^8.7.0",
"tough-cookie": "^6.0.1",
"undici": "^7.25.0",
"w3c-xmlserializer": "^5.0.0",
"webidl-conversions": "^8.0.1",
"whatwg-mimetype": "^5.0.0",
"whatwg-url": "^17.1.0",
"whatwg-url": "^16.0.1",
"xml-name-validator": "^5.0.0"
},
"engines": {
"node": "^22.22.2 || ^24.15.0 || >=26.0.0"
"node": "^20.19.0 || ^22.13.0 || >=24.0.0"
},
"peerDependencies": {
"canvas": "^3.2.3"
"canvas": "^3.0.0"
},
"peerDependenciesMeta": {
"canvas": {
@@ -4088,21 +4049,6 @@
}
}
},
"node_modules/jsdom/node_modules/whatwg-url": {
"version": "17.1.0",
"resolved": "https://registry.npmjs.org/whatwg-url/-/whatwg-url-17.1.0.tgz",
"integrity": "sha512-3GeworPmc2ZfEEHP7lEbUfBX/L75wdEsi0rLNhXcXxnoN5jyq0SL5gCy06SGW2cyTIZdTvWIDQNQoza++vKeaw==",
"dev": true,
"license": "MIT",
"dependencies": {
"@exodus/bytes": "^1.15.1",
"tr46": "^6.0.0",
"webidl-conversions": "^8.0.1"
},
"engines": {
"node": "^22.14.0 || >=24.0.0"
}
},
"node_modules/jsesc": {
"version": "3.1.0",
"resolved": "https://registry.npmjs.org/jsesc/-/jsesc-3.1.0.tgz",
@@ -4479,9 +4425,9 @@
}
},
"node_modules/lru-cache": {
"version": "11.5.2",
"resolved": "https://registry.npmjs.org/lru-cache/-/lru-cache-11.5.2.tgz",
"integrity": "sha512-4pfM1Ff0x50o0tQwb5ucw/RzNyD0/YJME6IVcStalZuMWxdt3sR3huStTtxz4PUmvZfRguvDejasvQ2kifR11g==",
"version": "11.3.6",
"resolved": "https://registry.npmjs.org/lru-cache/-/lru-cache-11.3.6.tgz",
"integrity": "sha512-Gf/KoL3C/MlI7Bt0PGI9I+TeTC/I6r/csU58N4BSNc4lppLBeKsOdFYkK+dX0ABDUMJNfCHTyPpzwwO21Awd3A==",
"dev": true,
"license": "BlueOak-1.0.0",
"engines": {
@@ -5926,9 +5872,9 @@
}
},
"node_modules/tough-cookie": {
"version": "6.0.2",
"resolved": "https://registry.npmjs.org/tough-cookie/-/tough-cookie-6.0.2.tgz",
"integrity": "sha512-exgYmnmL/sJpR3upZfXG5PoatXQii55xAiXGXzY+sROLZ/Y+SLcp9PgJNI9Vz37HpQ74WvDcLT8eqm+kV3FzrA==",
"version": "6.0.1",
"resolved": "https://registry.npmjs.org/tough-cookie/-/tough-cookie-6.0.1.tgz",
"integrity": "sha512-LktZQb3IeoUWB9lqR5EWTHgW/VTITCXg4D21M+lvybRVdylLrRMnqaIONLVb5mav8vM19m44HIcGq4qASeu2Qw==",
"dev": true,
"license": "BSD-3-Clause",
"dependencies": {
@@ -6038,13 +5984,13 @@
"license": "MIT"
},
"node_modules/undici": {
"version": "8.9.0",
"resolved": "https://registry.npmjs.org/undici/-/undici-8.9.0.tgz",
"integrity": "sha512-aWZpUj7XoGonMClx4gdDRfgBjqeA+F473aDmROQQbM9n6PRfK/u1q/a0X4wMTgcHfT8H6fpbt98PFuDUwFg2YA==",
"version": "7.25.0",
"resolved": "https://registry.npmjs.org/undici/-/undici-7.25.0.tgz",
"integrity": "sha512-xXnp4kTyor2Zq+J1FfPI6Eq3ew5h6Vl0F/8d9XU5zZQf1tX9s2Su1/3PiMmUANFULpmksxkClamIZcaUqryHsQ==",
"dev": true,
"license": "MIT",
"engines": {
"node": ">=22.19.0"
"node": ">=20.18.1"
}
},
"node_modules/undici-types": {
@@ -6591,14 +6537,14 @@
}
},
"node_modules/vue-i18n": {
"version": "11.4.10",
"resolved": "https://registry.npmjs.org/vue-i18n/-/vue-i18n-11.4.10.tgz",
"integrity": "sha512-Lp+BjOxqzOY87DS6Z8KrQrpiTr9IN/Lt4kZEilwyXG2Wrx+AcU6IVsAW92HNXtVcn1HFFPV6ty41p9e/qDpyvg==",
"version": "11.4.7",
"resolved": "https://registry.npmjs.org/vue-i18n/-/vue-i18n-11.4.7.tgz",
"integrity": "sha512-j6RyshdPPzqLiMAUpnpvZGFPM+rRoWi14Sl5yTsquvoW0/56DWyvhAj2o9TO2YXGvb6teg8T0xrYO9jR3urvdw==",
"license": "MIT",
"dependencies": {
"@intlify/core-base": "11.4.10",
"@intlify/devtools-types": "11.4.10",
"@intlify/shared": "11.4.10",
"@intlify/core-base": "11.4.7",
"@intlify/devtools-types": "11.4.7",
"@intlify/shared": "11.4.7",
"@vue/devtools-api": "^6.5.0"
},
"engines": {
@@ -6696,13 +6642,10 @@
}
},
"node_modules/vuetify": {
"version": "4.2.1",
"resolved": "https://registry.npmjs.org/vuetify/-/vuetify-4.2.1.tgz",
"integrity": "sha512-K3ZIqu7YkorQFB6//dR5KEBpbfOo+y/LkcGtknsnneE3JN1pW3R7o/JB9QDkJuP1ELhENIdBZIkiSmXu0dQ9lQ==",
"version": "4.1.7",
"resolved": "https://registry.npmjs.org/vuetify/-/vuetify-4.1.7.tgz",
"integrity": "sha512-07qxu0S1oxPjmknP/Yn5276PtIhlCvHnpcp7HuOKEHni89/6BGiM2aVdKlEGeyM5RfytDkiv0SNieabGT2D8qQ==",
"license": "MIT",
"dependencies": {
"@vuetify/v0": "^1.2.1"
},
"funding": {
"type": "github",
"url": "https://github.com/sponsors/johnleider"
@@ -6710,7 +6653,7 @@
"peerDependencies": {
"typescript": ">=4.7",
"vite-plugin-vuetify": ">=2.1.0",
"vue": "^3.5.0 || ^3.6.0-0",
"vue": "^3.5.0",
"webpack-plugin-vuetify": ">=3.1.0"
},
"peerDependenciesMeta": {
+1 -1
View File
@@ -53,7 +53,7 @@
"@vue/tsconfig": "^0.9.1",
"eslint": "^10.3.0",
"eslint-plugin-vue": "^10.9.1",
"jsdom": "^30.0.0",
"jsdom": "^29.1.1",
"prettier": "^3.8.3",
"sass": "^1.99.0",
"sass-loader": "^17.0.0",
+8 -63
View File
@@ -23,10 +23,7 @@ use finfo;
class Signature {
/** Minimum bytes needed for reliable detection */
public const SAMPLE_SIZE = 65536;
/** Cached finfo instance */
private static ?finfo $finfo = null;
public const HEADER_SIZE = 256;
/**
* Fallback magic byte signatures for when finfo is unavailable
@@ -44,32 +41,16 @@ class Signature {
['offset' => 0, 'bytes' => '52494646', 'format' => 'riff'], // WAV/AVI/WEBP
];
/**
* Zip-container marker strings used to distinguish OOXML/ODF/EPUB documents
* from a generic ZIP archive. Filenames inside a ZIP's local file headers
* (and ODF's mandatory uncompressed "mimetype" entry content) are stored
* as plain text, so a simple substring search reliably identifies these
* formats without needing to parse the archive structure.
*/
private const ZIP_CONTAINER_MARKERS = [
'word/document.xml' => ['application/vnd.openxmlformats-officedocument.wordprocessingml.document', 'docx'],
'xl/workbook.xml' => ['application/vnd.openxmlformats-officedocument.spreadsheetml.sheet', 'xlsx'],
'ppt/presentation.xml' => ['application/vnd.openxmlformats-officedocument.presentationml.presentation', 'pptx'],
'application/vnd.oasis.opendocument.text' => ['application/vnd.oasis.opendocument.text', 'odt'],
'application/vnd.oasis.opendocument.spreadsheet' => ['application/vnd.oasis.opendocument.spreadsheet', 'ods'],
'application/vnd.oasis.opendocument.presentation' => ['application/vnd.oasis.opendocument.presentation', 'odp'],
'application/epub+zip' => ['application/epub+zip', 'epub'],
];
/** Cached finfo instance */
private static ?finfo $finfo = null;
/**
* Detect both MIME type and format from content bytes in a single operation
*
* @param string $headerBytes First bytes of the file content
* @param string|null $content Full (or larger) content, when available, used to
* distinguish OOXML/ODF/EPUB documents from a generic ZIP archive
* @param string $headerBytes First bytes of the file content (256 recommended)
* @return array{mime: string, format: string} Array with 'mime' and 'format' keys
*/
public static function detect(string $headerBytes, ?string $content = null): array {
public static function detect(string $headerBytes): array {
if (strlen($headerBytes) === 0) {
return ['mime' => MimeTypes::MIME_BINARY, 'format' => MimeTypes::FORMAT_BINARY];
}
@@ -94,16 +75,6 @@ class Signature {
$format = self::detectFromMagicBytes($headerBytes);
}
// A bare "zip" result is a generic container; when more of the file is
// available, check for OOXML/ODF/EPUB markers rather than reporting the
// misleadingly generic zip mime/format for what is really a document.
if ($format === 'zip' && $content !== null) {
$container = self::detectZipContainer($content);
if ($container !== null) {
[$mime, $format] = $container;
}
}
// Ensure MIME type is set
if ($mime === null || $mime === MimeTypes::MIME_BINARY) {
$mime = MimeTypes::toMime($format) ?? MimeTypes::MIME_BINARY;
@@ -112,32 +83,6 @@ class Signature {
return ['mime' => $mime, 'format' => $format];
}
/**
* Look for known OOXML/ODF/EPUB entry markers within ZIP content
*
* Only a fixed-size window from the head and tail of the content is scanned,
* regardless of total length, so detection cost does not grow with the size
* of large archive uploads. Every entry name is mirrored in full in the ZIP
* central directory near the end of the archive, so sampling the head and
* tail is enough without scanning the whole file.
*
* @param string $data ZIP content to scan (filenames/mimetype entry are stored uncompressed)
* @return array{0: string, 1: string}|null [mime, format] pair, or null if no marker matched
*/
private static function detectZipContainer(string $data): ?array {
$length = strlen($data);
$sample = $length <= self::SAMPLE_SIZE * 2
? $data
: substr($data, 0, self::SAMPLE_SIZE) . substr($data, -self::SAMPLE_SIZE);
foreach (self::ZIP_CONTAINER_MARKERS as $marker => $result) {
if (str_contains($sample, $marker)) {
return $result;
}
}
return null;
}
/**
* Detect both MIME type and format from a stream in a single operation
*
@@ -146,7 +91,7 @@ class Signature {
*/
public static function detectFromStream($stream): array {
$position = ftell($stream);
$headerBytes = fread($stream, self::SAMPLE_SIZE);
$headerBytes = fread($stream, self::HEADER_SIZE);
fseek($stream, $position);
if ($headerBytes === false || $headerBytes === '') {
@@ -195,7 +140,7 @@ class Signature {
*/
public static function detectFormatFromStream($stream): string {
$position = ftell($stream);
$headerBytes = fread($stream, self::SAMPLE_SIZE);
$headerBytes = fread($stream, self::HEADER_SIZE);
fseek($stream, $position);
if ($headerBytes === false || $headerBytes === '') {
@@ -213,7 +158,7 @@ class Signature {
*/
public static function detectMimeTypeFromStream($stream): ?string {
$position = ftell($stream);
$headerBytes = fread($stream, self::SAMPLE_SIZE);
$headerBytes = fread($stream, self::HEADER_SIZE);
fseek($stream, $position);
if ($headerBytes === false || $headerBytes === '') {
@@ -1,84 +0,0 @@
<?php
declare(strict_types=1);
/**
* SPDX-FileCopyrightText: Sebastian Krupinski <krupinski01@gmail.com>
* SPDX-License-Identifier: AGPL-3.0-or-later
*/
namespace KTXF\Documents\Service;
use Generator;
use KTXF\Documents\Collection\CollectionBaseInterface;
use KTXF\Documents\Entity\EntityBaseInterface;
use KTXF\Resource\Filter\IFilter;
use KTXF\Resource\Range\IRange;
use KTXF\Resource\Range\RangeType;
use KTXF\Resource\Sort\ISort;
/**
* Service Node List Interface
*
* @since 2026.09.01
*/
interface ServiceNodeListInterface {
// Node capabilities
public const CAPABILITY_NODE_LIST = 'NodeList';
public const CAPABILITY_NODE_LIST_FILTER = 'NodeListFilter';
public const CAPABILITY_NODE_LIST_SORT = 'NodeListSort';
public const CAPABILITY_NODE_LIST_RANGE = 'NodeListRange';
// Filter capabilities
public const CAPABILITY_NODE_FILTER_LABEL = 'label';
// Sort capabilities
public const CAPABILITY_NODE_SORT_LABEL = 'label';
public const CAPABILITY_NODE_SORT_SIZE = 'size';
public const CAPABILITY_NODE_SORT_CREATED_ON = 'createdOn';
public const CAPABILITY_NODE_SORT_MODIFIED_ON = 'modifiedOn';
// Range capabilities
public const CAPABILITY_NODE_RANGE_TALLY = 'tally';
public const CAPABILITY_NODE_RANGE_TALLY_ABSOLUTE = 'absolute';
public const CAPABILITY_NODE_RANGE_TALLY_RELATIVE = 'relative';
/**
* Lists collections and entities within a location as one unified, ordered set
*
* Folders are always ordered before files, regardless of the sort applied within
* each group.
*
* @since 2026.09.01
*
* @param string|int|null $location Parent collection identifier to list within (null for root)
* @param IFilter|null $filter Optional filter criteria
* @param ISort|null $sort Optional sort order
* @param IRange|null $range Optional pagination
*
* @return Generator<string|int,CollectionBaseInterface|EntityBaseInterface> Nodes yielded by identifier, folders before files
*/
public function nodeList(string|int|null $location, ?IFilter $filter = null, ?ISort $sort = null, ?IRange $range = null): Generator;
/**
* Creates a filter builder for the unified node list
*
* @since 2026.09.01
*/
public function nodeListFilter(): IFilter;
/**
* Creates a sort builder for the unified node list
*
* @since 2026.09.01
*/
public function nodeListSort(): ISort;
/**
* Creates a range builder for the unified node list
*
* @since 2026.09.01
*
* @param RangeType $type Range type
*/
public function nodeListRange(RangeType $type): IRange;
}
@@ -2,7 +2,7 @@
declare(strict_types=1);
namespace KTXC\Event;
namespace KTXF\Event;
interface DeferredEventProcessorInterface
{
@@ -2,7 +2,7 @@
declare(strict_types=1);
namespace KTXC\Event;
namespace KTXF\Event;
final readonly class DeferredProcessingResult
{
@@ -11,9 +11,6 @@ final readonly class DeferredProcessingResult
public int $remaining,
public bool $deadlineExceeded,
public bool $limitExceeded = false,
public int $listenerInvocations = 0,
public bool $eventLimitExceeded = false,
public bool $listenerInvocationLimitExceeded = false,
) {
}
}
+67 -43
View File
@@ -10,74 +10,81 @@ namespace KTXF\Event;
class Event
{
private bool $propagationStopped = false;
private readonly array $context;
private readonly float $timestamp;
private readonly string $identifier;
private array $data = [];
private float $timestamp;
private string $eventId;
private ?string $tenantId = null;
private ?string $identityId = null;
public function __construct(
private readonly string $label,
array $context = [],
private readonly ?string $tenantIdentifier = null,
private readonly ?string $actorIdentity = null,
private readonly string $name,
array $data = []
) {
self::validateContext($context);
$this->context = $context;
$this->data = $data;
$this->timestamp = microtime(true);
$this->identifier = bin2hex(random_bytes(16));
$this->eventId = bin2hex(random_bytes(16));
}
/**
* Get the event label
* Get the event name
*/
public function label(): string
public function getName(): string
{
return $this->label;
return $this->name;
}
/**
* Get a context value by key
* Get a data value by key
*/
public function get(string $key, mixed $default = null): mixed
{
return $this->context[$key] ?? $default;
return $this->data[$key] ?? $default;
}
/**
* Check if a context key exists
* Set a data value
*/
public function set(string $key, mixed $value): self
{
$this->data[$key] = $value;
return $this;
}
/**
* Check if a data key exists
*/
public function has(string $key): bool
{
return array_key_exists($key, $this->context);
return array_key_exists($key, $this->data);
}
/**
* Get the event context
* Get all data
*/
public function context(): array
public function getData(): array
{
return $this->context;
return $this->data;
}
/**
* Get all event context
* Alias for getData() for backward compatibility
*/
public function all(): array
{
return $this->context;
return $this->data;
}
/**
* Get the event timestamp
*/
public function timestamp(): float
public function getTimestamp(): float
{
return $this->timestamp;
}
public function identifier(): string
public function getEventId(): string
{
return $this->identifier;
return $this->eventId;
}
/**
@@ -99,31 +106,48 @@ class Event
/**
* Get tenant ID for multi-tenant context
*/
public function tenantIdentifier(): ?string
public function getTenantId(): ?string
{
return $this->tenantIdentifier;
return $this->tenantId;
}
/**
* Get the identity of the actor who triggered the event
* Set tenant ID for multi-tenant context
*/
public function actorIdentity(): ?string
public function setTenantId(?string $tenantId): self
{
return $this->actorIdentity;
$this->tenantId = $tenantId;
return $this;
}
private static function validateContext(array $context): void
/**
* Get identity ID (user who triggered the event)
*/
public function getIdentityId(): ?string
{
foreach ($context as $value) {
if (is_array($value)) {
self::validateContext($value);
continue;
}
if ($value !== null && !is_scalar($value)) {
throw new \InvalidArgumentException(
'Event context must contain only scalar, null, or array values.',
);
}
}
return $this->identityId;
}
/**
* Set identity ID
*/
public function setIdentityId(?string $identityId): self
{
$this->identityId = $identityId;
return $this;
}
/**
* Convert event to array for serialization/logging
*/
public function toArray(): array
{
return [
'name' => $this->name,
'data' => $this->data,
'timestamp' => $this->timestamp,
'tenantId' => $this->tenantId,
'identityId' => $this->identityId,
];
}
}
+124
View File
@@ -0,0 +1,124 @@
<?php
declare(strict_types=1);
namespace KTXF\Event;
use Psr\Container\ContainerInterface;
use Psr\Log\LoggerInterface;
final class EventDispatcher implements EventDispatcherInterface, DeferredEventProcessorInterface
{
/** @var array<string, list<Event>> */
private array $deferred = [];
private ?string $activeExecution = null;
private int $dispatchDepth = 0;
public function __construct(
private readonly EventListenerRegistry $registry,
private readonly ContainerInterface $container,
private readonly LoggerInterface $logger,
) {
}
public function dispatch(Event $event): void
{
if (++$this->dispatchDepth > 32) {
--$this->dispatchDepth;
throw new \RuntimeException('Event dispatch recursion limit exceeded.');
}
try {
$this->invoke($event, DeliveryMode::Immediate);
if ($this->registry->listeners($event->getName(), DeliveryMode::Deferred) !== []) {
if ($this->activeExecution === null) {
throw new \LogicException('Deferred events require an active execution scope.');
}
$this->deferred[$this->activeExecution][] = $event;
}
} finally {
--$this->dispatchDepth;
}
}
public function beginExecution(string $executionId): void
{
if ($this->activeExecution !== null) {
throw new \LogicException('An event execution scope is already active.');
}
$this->activeExecution = $executionId;
$this->deferred[$executionId] = [];
}
public function processDeferred(string $executionId): DeferredProcessingResult
{
if ($this->activeExecution !== $executionId) {
throw new \LogicException('Cannot process deferred events for an inactive execution.');
}
$processed = 0;
$deadline = microtime(true) + 1.0;
$deadlineExceeded = false;
$limitExceeded = false;
while (($event = array_shift($this->deferred[$executionId])) !== null) {
if ($processed >= 1000) {
$limitExceeded = true;
array_unshift($this->deferred[$executionId], $event);
break;
}
if (microtime(true) >= $deadline) {
$deadlineExceeded = true;
array_unshift($this->deferred[$executionId], $event);
break;
}
$processed += $this->invoke($event, DeliveryMode::Deferred);
}
$remaining = count($this->deferred[$executionId]);
unset($this->deferred[$executionId]);
$this->activeExecution = null;
return new DeferredProcessingResult(
$processed,
$remaining,
$deadlineExceeded,
$limitExceeded,
);
}
public function discardDeferred(string $executionId): void
{
unset($this->deferred[$executionId]);
if ($this->activeExecution === $executionId) {
$this->activeExecution = null;
}
}
private function invoke(Event $event, DeliveryMode $delivery): int
{
$processed = 0;
foreach ($this->registry->listeners($event->getName(), $delivery) as $listener) {
if ($event->isPropagationStopped()) {
break;
}
try {
$service = $this->container->get($listener->service);
$service->{$listener->method}($event);
$processed++;
} catch (\Throwable $error) {
$this->logger->error('Event listener failed.', [
'event' => $event->getName(),
'module' => $listener->module,
'listener' => $listener->service . '::' . $listener->method,
'exception' => $error,
]);
if ($listener->failurePolicy === FailurePolicy::Propagate) {
throw $error;
}
}
}
return $processed;
}
}
@@ -2,10 +2,7 @@
declare(strict_types=1);
namespace KTXC\Event;
use KTXF\Event\DeliveryMode;
use KTXF\Event\FailurePolicy;
namespace KTXF\Event;
final readonly class EventListenerDefinition
{
@@ -1,21 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXF\Event;
interface EventListenerRegistrarInterface
{
/**
* @param class-string $service
*/
public function listen(
string $module,
string $event,
string $service,
string $method,
DeliveryMode $delivery = DeliveryMode::Immediate,
int $priority = 0,
FailurePolicy $failurePolicy = FailurePolicy::Continue,
): void;
}
@@ -2,14 +2,11 @@
declare(strict_types=1);
namespace KTXC\Event;
namespace KTXF\Event;
use KTXF\Event\DeliveryMode;
use KTXF\Event\EventListenerRegistrarInterface;
use KTXF\Event\FailurePolicy;
use Psr\Container\ContainerInterface;
final class EventListenerRegistry implements EventListenerRegistrarInterface
final class EventListenerRegistry
{
/** @var array<string, list<EventListenerDefinition>> */
private array $listeners = [];
+311
View File
@@ -0,0 +1,311 @@
<?php
declare(strict_types=1);
namespace KTXF\Event;
/**
* Security-specific event for authentication and access control events
*/
class SecurityEvent extends Event
{
// Event names
public const AUTH_SUCCESS = 'security.auth.success';
public const AUTH_FAILURE = 'security.auth.failure';
public const AUTH_LOGOUT = 'security.auth.logout';
public const TOKEN_REFRESH = 'security.token.refresh';
public const TOKEN_REVOKED = 'security.token.revoked';
public const ACCESS_DENIED = 'security.access.denied';
public const ACCESS_GRANTED = 'security.access.granted';
public const BRUTE_FORCE_DETECTED = 'security.brute_force.detected';
public const RATE_LIMIT_EXCEEDED = 'security.rate_limit.exceeded';
public const SUSPICIOUS_ACTIVITY = 'security.suspicious.activity';
public const IP_BLOCKED = 'security.ip.blocked';
public const IP_ALLOWED = 'security.ip.allowed';
public const DEVICE_BLOCKED = 'security.device.blocked';
public const FIREWALL_RULE_CREATED = 'security.firewall.rule.created';
public const FIREWALL_RULE_EXTENDED = 'security.firewall.rule.extended';
public const FIREWALL_RULE_ENABLED = 'security.firewall.rule.enabled';
public const FIREWALL_RULE_DISABLED = 'security.firewall.rule.disabled';
public const FIREWALL_RULE_REMOVED = 'security.firewall.rule.removed';
public const FIREWALL_SETTINGS_UPDATED = 'security.firewall.settings.updated';
private ?string $ipAddress = null;
private ?string $deviceFingerprint = null;
private ?string $userAgent = null;
private ?string $requestPath = null;
private ?string $requestMethod = null;
private ?string $userId = null;
private ?string $reason = null;
private int $severity = self::SEVERITY_INFO;
// Severity levels
public const SEVERITY_DEBUG = 0;
public const SEVERITY_INFO = 1;
public const SEVERITY_WARNING = 2;
public const SEVERITY_ERROR = 3;
public const SEVERITY_CRITICAL = 4;
/**
* Create a security event with common parameters
*/
public static function create(
string $name,
?string $ipAddress = null,
?string $deviceFingerprint = null,
array $data = []
): self {
$event = new self($name, $data);
$event->ipAddress = $ipAddress;
$event->deviceFingerprint = $deviceFingerprint;
// Set default severity based on event type
$event->severity = self::getSeverityForEvent($name);
return $event;
}
/**
* Create an authentication failure event
*/
public static function authFailure(
string $ipAddress,
?string $deviceFingerprint = null,
?string $userId = null,
?string $reason = null
): self {
$event = self::create(self::AUTH_FAILURE, $ipAddress, $deviceFingerprint, [
'userId' => $userId,
'reason' => $reason,
]);
$event->userId = $userId;
$event->reason = $reason;
return $event;
}
/**
* Create an authentication success event
*/
public static function authSuccess(
string $ipAddress,
?string $deviceFingerprint = null,
string $userId = null
): self {
$event = self::create(self::AUTH_SUCCESS, $ipAddress, $deviceFingerprint, [
'userId' => $userId,
]);
$event->userId = $userId;
return $event;
}
/**
* Create a brute force detection event
*/
public static function bruteForceDetected(
string $ipAddress,
int $failureCount,
int $windowSeconds
): self {
$event = self::create(self::BRUTE_FORCE_DETECTED, $ipAddress, null, [
'failureCount' => $failureCount,
'windowSeconds' => $windowSeconds,
]);
$event->reason = sprintf(
'%d failed attempts in %d seconds',
$failureCount,
$windowSeconds
);
return $event;
}
/**
* Create a rate limit exceeded event
*/
public static function rateLimitExceeded(
string $ipAddress,
int $requestCount,
int $windowSeconds,
?string $endpoint = null
): self {
$event = self::create(self::RATE_LIMIT_EXCEEDED, $ipAddress, null, [
'requestCount' => $requestCount,
'windowSeconds' => $windowSeconds,
'endpoint' => $endpoint,
]);
$event->requestPath = $endpoint;
$event->reason = sprintf(
'%d requests in %d seconds',
$requestCount,
$windowSeconds
);
return $event;
}
/**
* Create an access denied event
*/
public static function accessDenied(
string $ipAddress,
?string $deviceFingerprint = null,
?string $ruleId = null,
?string $ruleScope = null,
?string $reason = null
): self {
$event = self::create(self::ACCESS_DENIED, $ipAddress, $deviceFingerprint, [
'ruleId' => $ruleId,
'ruleScope' => $ruleScope,
'reason' => $reason,
]);
$event->reason = $reason;
return $event;
}
/**
* Get default severity for event types
*/
private static function getSeverityForEvent(string $eventName): int
{
return match ($eventName) {
self::AUTH_SUCCESS,
self::ACCESS_GRANTED,
self::TOKEN_REFRESH => self::SEVERITY_INFO,
self::AUTH_FAILURE,
self::ACCESS_DENIED,
self::AUTH_LOGOUT,
self::TOKEN_REVOKED => self::SEVERITY_WARNING,
self::RATE_LIMIT_EXCEEDED,
self::SUSPICIOUS_ACTIVITY => self::SEVERITY_ERROR,
self::BRUTE_FORCE_DETECTED,
self::IP_BLOCKED,
self::DEVICE_BLOCKED => self::SEVERITY_CRITICAL,
default => self::SEVERITY_INFO,
};
}
// Getters and setters
public function getIpAddress(): ?string
{
return $this->ipAddress;
}
public function setIpAddress(?string $ipAddress): self
{
$this->ipAddress = $ipAddress;
return $this;
}
public function getDeviceFingerprint(): ?string
{
return $this->deviceFingerprint;
}
public function setDeviceFingerprint(?string $deviceFingerprint): self
{
$this->deviceFingerprint = $deviceFingerprint;
return $this;
}
public function getUserAgent(): ?string
{
return $this->userAgent;
}
public function setUserAgent(?string $userAgent): self
{
$this->userAgent = $userAgent;
return $this;
}
public function getRequestPath(): ?string
{
return $this->requestPath;
}
public function setRequestPath(?string $requestPath): self
{
$this->requestPath = $requestPath;
return $this;
}
public function getRequestMethod(): ?string
{
return $this->requestMethod;
}
public function setRequestMethod(?string $requestMethod): self
{
$this->requestMethod = $requestMethod;
return $this;
}
public function getUserId(): ?string
{
return $this->userId;
}
public function setUserId(?string $userId): self
{
$this->userId = $userId;
return $this;
}
public function getReason(): ?string
{
return $this->reason;
}
public function setReason(?string $reason): self
{
$this->reason = $reason;
return $this;
}
public function getSeverity(): int
{
return $this->severity;
}
public function setSeverity(int $severity): self
{
$this->severity = $severity;
return $this;
}
public function getSeverityLabel(): string
{
return match ($this->severity) {
self::SEVERITY_DEBUG => 'DEBUG',
self::SEVERITY_INFO => 'INFO',
self::SEVERITY_WARNING => 'WARNING',
self::SEVERITY_ERROR => 'ERROR',
self::SEVERITY_CRITICAL => 'CRITICAL',
default => 'UNKNOWN',
};
}
/**
* Override toArray to include security-specific fields
*/
public function toArray(): array
{
return array_merge(parent::toArray(), [
'ipAddress' => $this->ipAddress,
'deviceFingerprint' => $this->deviceFingerprint,
'userAgent' => $this->userAgent,
'requestPath' => $this->requestPath,
'requestMethod' => $this->requestMethod,
'userId' => $this->userId,
'reason' => $this->reason,
'severity' => $this->severity,
'severityLabel' => $this->getSeverityLabel(),
]);
}
}
@@ -11,7 +11,6 @@ namespace KTXF\Mail\Provider;
use KTXF\Mail\Service\ServiceBaseInterface;
use KTXF\Resource\Provider\ResourceProviderBaseInterface;
use KTXF\Resource\SystemIdentity;
/**
* Provider Base Interface
@@ -25,9 +24,15 @@ interface ProviderBaseInterface extends ResourceProviderBaseInterface{
public const JSON_TYPE = 'mail:provider';
/**
* @deprecated Use SystemIdentity::USER.
* Reserved user identifier for system-owned mail services
*
* Services stored under this user id belong to the tenant itself rather
* than any real user (e.g. accounts used to deliver system-generated
* messages such as verification codes and password resets).
*
* @since 2026.07.01
*/
public const USER_SYSTEM = SystemIdentity::USER;
public const USER_SYSTEM = 'system';
/**
* Finds a service that handles a specific email address
@@ -56,19 +56,12 @@ interface ServiceEntityMutableInterface {
/**
* Modifies an existing entity
*
* The returned entity's identifier is authoritative and may differ from
* the target identifier. Providers without in-place update support may
* implement this as an append-and-replace (or equivalent create-then-
* destroy) operation, in which case the target identifier is superseded
* and no longer resolvable; callers must persist the returned identifier
* rather than assume the target remains valid.
*
* @since 2025.05.01
*
* @param EntityIdentifier $target Target entity identifier
* @param MessagePropertiesMutableInterface $properties Entity properties to update
*
* @return EntityBaseInterface Modified entity, with its own authoritative identifier
* @return EntityBaseInterface Modified entity
*/
public function entityModify(EntityIdentifier $target, MessagePropertiesMutableInterface $properties): EntityBaseInterface;
@@ -1,28 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXF\Module\Configuration;
use KTXF\Module\ModuleInstanceInterface;
interface BrowserModuleContextInterface extends ModuleContextInterface
{
public function registerModule(
ModuleInstanceInterface $module,
string $namespace,
?string $boot = null,
): void;
public function set(string $key, mixed $value): void;
public function tenantIdentifier(): string;
public function identityIdentifier(): string;
/** @return array<string,array<string,mixed>> */
public function modules(): array;
/** @return array<string,mixed> */
public function configuration(): array;
}
@@ -1,14 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXF\Module\Configuration;
interface ConsoleModuleContextInterface extends ModuleContextInterface
{
/** @param class-string $command */
public function registerCommand(string $command): void;
/** @return list<class-string> */
public function commands(): array;
}
@@ -1,10 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXF\Module\Configuration;
interface ModuleContextInterface
{
public function type(): ModuleContextType;
}
@@ -1,11 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXF\Module\Configuration;
enum ModuleContextType: string
{
case Browser = 'browser';
case Console = 'console';
}
@@ -0,0 +1,13 @@
<?php
declare(strict_types=1);
namespace KTXF\Module;
/**
* Module Browser Interface
*/
interface ModuleBrowserInterface
{
public function registerBI(): array;
}
@@ -0,0 +1,13 @@
<?php
declare(strict_types=1);
namespace KTXF\Module;
/**
* Module Console Interface
*/
interface ModuleConsoleInterface
{
public function registerCI(): array;
}
@@ -2,8 +2,6 @@
namespace KTXF\Module;
use KTXF\Module\Configuration\ModuleContextInterface;
abstract class ModuleInstanceAbstract implements ModuleInstanceInterface
{
// mandatory methods that must be implemented by each concrete module
@@ -48,11 +46,6 @@ abstract class ModuleInstanceAbstract implements ModuleInstanceInterface
// Override in specific modules if needed
}
public function configure(ModuleContextInterface $context): void
{
// Override when the module supplies browser or console integrations.
}
/**
* Permissions provided by this module
*
@@ -2,15 +2,8 @@
namespace KTXF\Module;
use KTXF\Module\Configuration\ModuleContextInterface;
interface ModuleInstanceInterface
{
/**
* Declare the integrations supplied by this module.
*/
public function configure(ModuleContextInterface $context): void;
/**
* Get module version
*/
-32
View File
@@ -1,32 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXF\Preview;
use InvalidArgumentException;
final class MimeType
{
public static function normalize(string $mimeType): string
{
$mimeType = strtolower(trim(explode(';', $mimeType, 2)[0]));
if (preg_match('~^[a-z0-9!#$&^_.+-]+/[a-z0-9!#$&^_.+-]+$~', $mimeType) !== 1) {
throw new InvalidArgumentException("Invalid MIME type '{$mimeType}'");
}
return $mimeType;
}
public static function matches(string $pattern, string $mimeType): bool
{
$mimeType = self::normalize($mimeType);
$pattern = strtolower(trim($pattern));
if ($pattern === '*/*') {
return true;
}
if (preg_match('~^[a-z0-9!#$&^_.+-]+/\*$~', $pattern) === 1) {
return str_starts_with($mimeType, substr($pattern, 0, -1));
}
return self::normalize($pattern) === $mimeType;
}
}
@@ -1,11 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXF\Preview;
use RuntimeException;
final class PreviewGenerationException extends RuntimeException
{
}
-32
View File
@@ -1,32 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXF\Preview;
use InvalidArgumentException;
final readonly class PreviewRequest
{
public string $preferredMimeType;
public function __construct(
public int $maxWidth,
public int $maxHeight,
string $preferredMimeType,
public int $quality,
public int $maxSourceSize = 26214400,
) {
if ($this->maxWidth < 1 || $this->maxHeight < 1) {
throw new InvalidArgumentException('Preview dimensions must be positive');
}
if ($this->quality < 1 || $this->quality > 100) {
throw new InvalidArgumentException('Preview quality must be between 1 and 100');
}
if ($this->maxSourceSize < 1) {
throw new InvalidArgumentException('Preview maximum source size must be positive');
}
$this->preferredMimeType = MimeType::normalize($preferredMimeType);
}
}
-25
View File
@@ -1,25 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXF\Preview;
use InvalidArgumentException;
use KTXF\Resource\BinaryResource;
final readonly class PreviewResult
{
public function __construct(
public BinaryResource $resource,
public ?int $width = null,
public ?int $height = null,
) {
MimeType::normalize($this->resource->mimeType());
if ($this->width !== null && $this->width < 1) {
throw new InvalidArgumentException('Preview result width must be positive');
}
if ($this->height !== null && $this->height < 1) {
throw new InvalidArgumentException('Preview result height must be positive');
}
}
}
-46
View File
@@ -1,46 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXF\Preview;
use Closure;
use InvalidArgumentException;
use KTXF\Resource\BinaryResource;
final readonly class PreviewSource
{
public string $mimeType;
/**
* @param Closure(): BinaryResource $resourceFactory
*/
public function __construct(
public string $sourceType,
public string $identity,
public string $signature,
string $mimeType,
public ?int $size,
public Closure $resourceFactory,
) {
if (preg_match('/^[a-z][a-z0-9-]*$/', $this->sourceType) !== 1) {
throw new InvalidArgumentException('Preview source type must use lowercase letters, numbers, and hyphens');
}
if ($this->identity === '' || $this->signature === '') {
throw new InvalidArgumentException('Preview sources require an identity and content signature');
}
if ($this->size !== null && $this->size < 0) {
throw new InvalidArgumentException('Preview source size cannot be negative');
}
$this->mimeType = MimeType::normalize($mimeType);
}
public function open(): BinaryResource
{
$resource = ($this->resourceFactory)();
if (!$resource instanceof BinaryResource) {
throw new PreviewGenerationException('Preview source factory did not return a BinaryResource');
}
return $resource;
}
}
@@ -1,19 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXF\Preview\Provider;
use KTXF\Preview\PreviewRequest;
use KTXF\Preview\PreviewResult;
use KTXF\Preview\PreviewSource;
use KTXF\Resource\Provider\ProviderInterface;
interface PreviewProviderInterface extends ProviderInterface
{
public function supports(string $sourceMimeType, PreviewRequest $request): bool;
public function generate(PreviewSource $source, PreviewRequest $request): PreviewResult;
public function priority(): int;
}
@@ -15,8 +15,6 @@ interface ProviderInterface
public const TYPE_PEOPLE = 'people';
public const TYPE_CHRONO = 'chrono';
public const TYPE_MAIL = 'mail';
public const TYPE_SYSTEM_STORE = 'system-store';
public const TYPE_PREVIEW = 'preview';
/**
* Provider type (e.g., 'authentication', 'document', 'people', 'chrono', 'mail')
-20
View File
@@ -1,20 +0,0 @@
<?php
declare(strict_types=1);
namespace KTXF\Resource;
/**
* Reserved identities used by tenant-scoped internal services.
*/
final class SystemIdentity
{
/**
* User identifier for resources owned by the tenant rather than a person.
*/
public const USER = 'system';
private function __construct()
{
}
}

Some files were not shown because too many files have changed in this diff Show More