From 1a7e8704d031fd7f5260bc1790b8ae83f0c370c1 Mon Sep 17 00:00:00 2001 From: Konstantinos Arvanitakis Date: Tue, 29 Sep 2026 14:30:52 +0300 Subject: [PATCH 01/13] Feat: Adding temp logging to for stripe webhook --- .../Http/Middleware/StripeWebhookMiddleware.php | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/src/Payment/Http/Middleware/StripeWebhookMiddleware.php b/src/Payment/Http/Middleware/StripeWebhookMiddleware.php index 6a1fd4c..2a2e72b 100644 --- a/src/Payment/Http/Middleware/StripeWebhookMiddleware.php +++ b/src/Payment/Http/Middleware/StripeWebhookMiddleware.php @@ -33,6 +33,17 @@ class StripeWebhookMiddleware $secret ); } catch (UnexpectedValueException|SignatureVerificationException $e) { + \Illuminate\Support\Facades\Log::error('Stripe webhook signature verification failed', [ + 'signature_header' => $stripeSig, + 'secret_prefix' => substr((string) $secret, 0, 12), + 'secret_length' => strlen((string) $secret), + 'body_length' => strlen($request->getContent()), + 'body_sha256' => hash('sha256', $request->getContent()), + 'body_raw' => $request->getContent(), + 'content_type' => $request->header('Content-Type'), + 'content_encoding' => $request->header('Content-Encoding'), + ]); + abort(400, $e->getMessage()); } From cceeb83d5e1d92e47eb36c221eb93e744f32d7fa Mon Sep 17 00:00:00 2001 From: Konstantinos Arvanitakis Date: Tue, 29 Sep 2026 14:32:36 +0300 Subject: [PATCH 02/13] Bump version to 0.27.1 --- CHANGELOG.md | 4 ++++ composer.json | 2 +- package.json | 2 +- 3 files changed, 6 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index a76c73f..8aa12d7 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,10 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/). +## [0.27.1] - 2026-09-29 +### Added +- Temp logger for Stripe webhook + ## [0.27.0] - 2026-09-29 ### Added diff --git a/composer.json b/composer.json index ece4e5f..238dba6 100644 --- a/composer.json +++ b/composer.json @@ -2,7 +2,7 @@ "name": "boboko/core", "description": "Core module — authentication and shared panel behaviour", "type": "library", - "version": "0.27.0", + "version": "0.27.1", "autoload": { "psr-4": { "Modules\\Core\\": "src/" diff --git a/package.json b/package.json index 6698e9f..679bd63 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@boboko/core", - "version": "0.27.0", + "version": "0.27.1", "private": true, "type": "module", "description": "Portable Stimulus controllers and styles for boboko-core's cart + checkout module. Installed as a real npm dependency (file:../boboko-core in dev, a tagged git install in prod) so a consuming app's `npm install` resolves this package's own dependencies (leaflet, @hotwired/stimulus) transitively, the same way `composer update boboko/*` does for PHP. See CONTRIBUTE.md's \"JS/CSS: a real npm package\" section.", From 332bf92e4429cf5b787e106b9e8613d912dfcc4a Mon Sep 17 00:00:00 2001 From: Konstantinos Arvanitakis Date: Tue, 29 Sep 2026 14:53:08 +0300 Subject: [PATCH 03/13] Fix: Adding check for duplicate transaction --- CHANGELOG.md | 11 +++++++++++ composer.json | 2 +- package.json | 2 +- src/Order/Services/TransactionRecorder.php | 18 ++++++++++++++++++ 4 files changed, 31 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 8aa12d7..7500af5 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,17 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/). +## [0.27.2] - 2026-09-29 +### Fixed +- `Modules\Core\Order\Services\TransactionRecorder::record()` — made idempotent + on `(order_id, type, reference)`. A successful Stripe payment can legitimately + report `PaymentCaptured` twice for the same PaymentIntent (checkout's + synchronous capture via `pay()`, then the webhook confirming the same + outcome asynchronously via `handleCallback()`), both routing through + `resultFromIntent()`. With no dedupe check, this wrote two identical + `Transaction` rows for one real payment. Now returns the existing row + instead of creating a duplicate. + ## [0.27.1] - 2026-09-29 ### Added - Temp logger for Stripe webhook diff --git a/composer.json b/composer.json index 238dba6..594dcf7 100644 --- a/composer.json +++ b/composer.json @@ -2,7 +2,7 @@ "name": "boboko/core", "description": "Core module — authentication and shared panel behaviour", "type": "library", - "version": "0.27.1", + "version": "0.27.2", "autoload": { "psr-4": { "Modules\\Core\\": "src/" diff --git a/package.json b/package.json index 679bd63..7fbc5fd 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@boboko/core", - "version": "0.27.1", + "version": "0.27.2", "private": true, "type": "module", "description": "Portable Stimulus controllers and styles for boboko-core's cart + checkout module. Installed as a real npm dependency (file:../boboko-core in dev, a tagged git install in prod) so a consuming app's `npm install` resolves this package's own dependencies (leaflet, @hotwired/stimulus) transitively, the same way `composer update boboko/*` does for PHP. See CONTRIBUTE.md's \"JS/CSS: a real npm package\" section.", diff --git a/src/Order/Services/TransactionRecorder.php b/src/Order/Services/TransactionRecorder.php index 423959a..2d75745 100644 --- a/src/Order/Services/TransactionRecorder.php +++ b/src/Order/Services/TransactionRecorder.php @@ -39,8 +39,26 @@ class TransactionRecorder * elsewhere in this codebase (see the old, now-removed * TransactionRecorder this replaces). */ + /** + * Idempotent on (order_id, type, reference): a successful payment + * outcome can legitimately be reported twice for the same gateway + * reference — e.g. Stripe's pay()/handleCallback() both call + * resultFromIntent() and both dispatch PaymentCaptured once a + * PaymentIntent reaches "succeeded" (checkout's synchronous capture, + * then the webhook confirming the same outcome asynchronously) — so + * this returns the existing row instead of writing a duplicate. + */ public function record(Order $order, string $type, string $driver, PaymentResult $result): Transaction { + $existing = $order->transactions() + ->where('type', $type) + ->where('reference', $result->reference) + ->first(); + + if ($existing !== null) { + return $existing; + } + return $order->transactions()->create([ 'success' => $result->status === PaymentResultStatus::Succeeded, 'type' => $type, From c43682ef0cb9b92bc81f6093236c3221e7e36d7d Mon Sep 17 00:00:00 2001 From: elvira Date: Tue, 29 Sep 2026 20:25:43 +0300 Subject: [PATCH 04/13] Feat: Show bank transfer instructions on order confirmation page --- resources/css/checkout.css | 31 ++++++++++++++++++- .../views/checkout/confirmation.blade.php | 10 ++++++ .../Seeders/CheckoutTranslationsSeeder.php | 4 +++ .../Http/Controllers/CheckoutController.php | 3 ++ src/Store/Services/StoreDetailsService.php | 30 ++++++++++++++++-- 5 files changed, 74 insertions(+), 4 deletions(-) diff --git a/resources/css/checkout.css b/resources/css/checkout.css index fb05402..7aed5b6 100644 --- a/resources/css/checkout.css +++ b/resources/css/checkout.css @@ -975,12 +975,41 @@ textarea.bbk-field-input { resize: vertical; } gap: 1.5rem; } -.bbk-confirmation-address-heading { +.bbk-confirmation-address-heading, +.bbk-confirmation-bank-transfer-heading { margin: 0 0 0.5rem; font-size: 0.9375rem; font-weight: 700; } +.bbk-confirmation-bank-transfer { + padding-top: 1.5rem; + border-top: 1px solid var(--bbk-color-border); +} + +/* Store-authored rich text (ManageStoreDetails' RichEditor) — may be + paragraphs, bold text or a bank/IBAN/BIC table. */ +.bbk-confirmation-bank-transfer-body { + font-size: 0.875rem; + overflow-wrap: anywhere; +} + +.bbk-confirmation-bank-transfer-body > :first-child { margin-top: 0; } +.bbk-confirmation-bank-transfer-body > :last-child { margin-bottom: 0; } + +.bbk-confirmation-bank-transfer-body table { + width: 100%; + border-collapse: collapse; +} + +.bbk-confirmation-bank-transfer-body th, +.bbk-confirmation-bank-transfer-body td { + padding: 0.375rem 0.5rem; + border: 1px solid var(--bbk-color-border); + text-align: left; + vertical-align: top; +} + .bbk-address-lines { font-style: normal; display: flex; diff --git a/resources/views/checkout/confirmation.blade.php b/resources/views/checkout/confirmation.blade.php index 466b117..d7b127a 100644 --- a/resources/views/checkout/confirmation.blade.php +++ b/resources/views/checkout/confirmation.blade.php @@ -2,6 +2,9 @@ Order confirmation. Reached only via a session flash of the placed order id (CheckoutController::confirmation) — not deep-linkable. $order is a Lunar\Models\Order with lines + shipping/billing addresses eager-loaded. + $bankTransferInstructions is already-sanitized HTML from + StoreDetailsService::bankTransferInstructionsFor(), or null unless this + is a bank transfer order with instructions filled in for this locale. --}} @extends('layouts.app') @@ -128,5 +131,12 @@ @endif + + @if ($bankTransferInstructions) +
+

{{ __('checkout.page.confirmation_bank_transfer_heading') }}

+
{!! $bankTransferInstructions !!}
+
+ @endif @endsection diff --git a/src/Checkout/Database/Seeders/CheckoutTranslationsSeeder.php b/src/Checkout/Database/Seeders/CheckoutTranslationsSeeder.php index 1a10180..61057eb 100644 --- a/src/Checkout/Database/Seeders/CheckoutTranslationsSeeder.php +++ b/src/Checkout/Database/Seeders/CheckoutTranslationsSeeder.php @@ -190,6 +190,10 @@ class CheckoutTranslationsSeeder extends Seeder 'Θέλεις να παρακολουθείς την παραγγελία σου; Δημιούργησε λογαριασμό ή', ], 'page.confirmation_billing' => ['Billing', 'Χρέωση'], + 'page.confirmation_bank_transfer_heading' => [ + 'Bank transfer details', + 'Στοιχεία τραπεζικής μεταφοράς', + ], 'page.confirmation_continue' => ['Continue shopping', 'Συνέχεια αγορών'], 'page.box_now_locker_label' => [ 'Choose a Box Now locker', diff --git a/src/Checkout/Http/Controllers/CheckoutController.php b/src/Checkout/Http/Controllers/CheckoutController.php index f7da5ec..c831c70 100644 --- a/src/Checkout/Http/Controllers/CheckoutController.php +++ b/src/Checkout/Http/Controllers/CheckoutController.php @@ -28,6 +28,7 @@ use Modules\Core\Customer\Services\CustomerAccountService; use Modules\Core\Payment\Enums\PaymentResultStatus; use Modules\Core\Payment\Models\PaymentMethod; use Modules\Core\Shipping\Carriers\BoxNow\BoxNowClient; +use Modules\Core\Store\Services\StoreDetailsService; /** * The checkout page — one page, sections (contact / billing / shipping / @@ -554,6 +555,8 @@ class CheckoutController extends Controller return view('checkout::confirmation', [ 'order' => $order, 'paymentMethodName' => $paymentMethodName, + 'bankTransferInstructions' => app(StoreDetailsService::class) + ->bankTransferInstructionsFor($order, $locale), ]); } diff --git a/src/Store/Services/StoreDetailsService.php b/src/Store/Services/StoreDetailsService.php index 90c9931..b91e8e5 100644 --- a/src/Store/Services/StoreDetailsService.php +++ b/src/Store/Services/StoreDetailsService.php @@ -8,6 +8,7 @@ use Illuminate\Support\Facades\Event; use Lunar\Models\Language; use Lunar\Models\Order; use Modules\Core\Order\Services\OrderStatusFlow; +use Modules\Core\Order\Support\OrderReferenceDisplay; use Modules\Core\Store\Events\StoreDetailsUpdated; use Modules\Core\Store\Models\StoreDetails; @@ -39,8 +40,8 @@ class StoreDetailsService } /** - * Null for any non-bank-transfer order — the confirmation email only - * shows this block when there's actually a wire to send (see + * Null for any non-bank-transfer order — the confirmation email and page + * only show this block when there's actually a wire to send (see * BankTransferPaymentDriver's own docblock for why a bank transfer * order stays at 'awaiting_payment' until staff confirm the wire * arrived). Null also when the store hasn't filled the field in for @@ -66,7 +67,30 @@ class StoreDetailsService return null; } - return RichContentRenderer::make($content)->toHtml(); + return $this->fillOrderReference( + RichContentRenderer::make($content)->toHtml(), + $order, + ); + } + + /** + * Replaces a `{order_reference}` (or `{{ order_reference }}`) the shop + * owner typed into the instructions with the order's display reference + * (OrderReferenceDisplay — same form as the email subject). + * + * A plain text replace rather than RichContentRenderer::mergeTags(): + * that only fills genuine Tiptap mergeTag nodes, which this editor never + * creates — Lunar's TranslatedText can't pass mergeTags() through to its + * per-locale RichEditors, so the placeholder is always stored as + * ordinary typed text. + */ + private function fillOrderReference(string $html, Order $order): string + { + return preg_replace( + '/\{\{?\s*order_reference\s*\}\}?/', + e(OrderReferenceDisplay::resolve($order)), + $html, + ); } public function update(array $attributes): StoreDetails From 47851d36ec7922eb13af9526047c9573efc5bc3f Mon Sep 17 00:00:00 2001 From: elvira Date: Tue, 29 Sep 2026 20:29:04 +0300 Subject: [PATCH 05/13] Bump version to 0.27.3 --- CHANGELOG.md | 15 +++++++++++++++ composer.json | 2 +- package.json | 2 +- 3 files changed, 17 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 7500af5..478d47c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,21 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/). +## [0.27.3] - 2026-09-29 +### Added +- The checkout confirmation page now ends with the store's bank transfer + instructions (Store Details → Bank transfer) for a bank transfer order, + via `StoreDetailsService::bankTransferInstructionsFor()`. New translation + line `checkout.page.confirmation_bank_transfer_heading` — re-run + `CheckoutTranslationsSeeder` in consuming apps to add it. + +### Fixed +- `StoreDetailsService::bankTransferInstructionsFor()` now fills a + `{order_reference}` (or `{{ order_reference }}`) typed into the bank + transfer instructions with the order's display reference + (`OrderReferenceDisplay`). It previously rendered literally in the order + confirmation email. + ## [0.27.2] - 2026-09-29 ### Fixed - `Modules\Core\Order\Services\TransactionRecorder::record()` — made idempotent diff --git a/composer.json b/composer.json index 594dcf7..4fd1c8e 100644 --- a/composer.json +++ b/composer.json @@ -2,7 +2,7 @@ "name": "boboko/core", "description": "Core module — authentication and shared panel behaviour", "type": "library", - "version": "0.27.2", + "version": "0.27.3", "autoload": { "psr-4": { "Modules\\Core\\": "src/" diff --git a/package.json b/package.json index 7fbc5fd..cbd533c 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@boboko/core", - "version": "0.27.2", + "version": "0.27.3", "private": true, "type": "module", "description": "Portable Stimulus controllers and styles for boboko-core's cart + checkout module. Installed as a real npm dependency (file:../boboko-core in dev, a tagged git install in prod) so a consuming app's `npm install` resolves this package's own dependencies (leaflet, @hotwired/stimulus) transitively, the same way `composer update boboko/*` does for PHP. See CONTRIBUTE.md's \"JS/CSS: a real npm package\" section.", From 6cf142e35b84afbfb733b6082b47bfd04744dfe0 Mon Sep 17 00:00:00 2001 From: elvira Date: Tue, 29 Sep 2026 21:25:28 +0300 Subject: [PATCH 06/13] Feat: Rework cart drawer line layout and order confirmation page --- resources/css/checkout.css | 115 ++++++++++++---- resources/js/checkout/bbk-cart-controller.js | 85 +++++++++++- .../views/checkout/confirmation.blade.php | 116 +++++++++------- resources/views/checkout/drawer.blade.php | 15 +- resources/views/checkout/page.blade.php | 10 +- .../checkout/partials/cart-line.blade.php | 128 ++++++++++-------- .../Seeders/CheckoutTranslationsSeeder.php | 1 + 7 files changed, 329 insertions(+), 141 deletions(-) diff --git a/resources/css/checkout.css b/resources/css/checkout.css index 7aed5b6..7cf136e 100644 --- a/resources/css/checkout.css +++ b/resources/css/checkout.css @@ -53,6 +53,7 @@ --bbk-color-accent: #18181b; --bbk-color-accent-text: #ffffff; --bbk-color-danger: #dc2626; + --bbk-color-info: #2563eb; --bbk-radius: 8px; --bbk-radius-sm: 4px; @@ -153,6 +154,11 @@ outline-offset: 2px; } +/* Programmatic focus targets only (tabindex=-1) — never reached by Tab, so + no ring needed. */ +.bbk-cart-heading:focus, +.bbk-checkout-summary-heading:focus { outline: none; } + .bbk-visually-hidden { position: absolute; width: 1px; @@ -183,7 +189,7 @@ .bbk-cart-item { display: grid; - grid-template-columns: 72px 1fr auto; + grid-template-columns: 72px 1fr; gap: 0.875rem; align-items: start; } @@ -199,8 +205,23 @@ .bbk-cart-item-detail { min-width: 0; } +/* Title + remove button share the first row; quantity stepper + line total + share the last one. */ +.bbk-cart-item-head, +.bbk-cart-item-foot { + display: flex; + justify-content: space-between; + gap: 0.75rem; +} + +.bbk-cart-item-head { align-items: flex-start; } +.bbk-cart-item-foot { align-items: center; } + +.bbk-cart-item-remove-form { flex: 0 0 auto; } + .bbk-cart-item-title { display: block; + min-width: 0; margin: 0 0 0.25rem; font-weight: 600; color: inherit; @@ -252,24 +273,24 @@ a.bbk-cart-item-title:hover { text-decoration: underline; } color: var(--bbk-color-muted); } -.bbk-cart-item-aside { - display: flex; - flex-direction: column; - align-items: flex-end; - gap: 0.5rem; -} - -.bbk-cart-item-total { margin: 0; font-weight: 600; } +.bbk-cart-item-total { margin: 0; font-weight: 600; white-space: nowrap; } +/* 2.5rem hit area (same as the drawer's own close button), pulled up/right by + negative margins so the glyph lines up with the title's first line instead + of pushing the row taller. */ .bbk-cart-item-remove { - font-size: 1.125rem; - width: 1.5rem; - height: 1.5rem; + font-size: 1.75rem; + width: 2.5rem; + height: 2.5rem; + margin: -0.5rem -0.5rem 0 0; display: inline-flex; align-items: center; justify-content: center; + border-radius: var(--bbk-radius-sm); } +.bbk-cart-item-remove:hover { background: var(--bbk-color-bg-muted); } + .bbk-cart-qty { display: inline-flex; align-items: center; @@ -905,10 +926,39 @@ textarea.bbk-field-input { resize: vertical; } to { transform: rotate(360deg); } } +/* ── Notice ──────────────────────────────────────────────────────────── + Inline, static message box: `.bbk-notice` + a tone modifier. Static + content, so no live-region role — for messages injected after load, add + role="status" (or role="alert" for errors) on the element itself. */ + +.bbk-notice { + --bbk-notice-color: var(--bbk-color-text); + display: flex; + align-items: flex-start; + gap: 0.625rem; + padding: 0.875rem 1rem; + border: 1px solid color-mix(in srgb, var(--bbk-notice-color) 25%, transparent); + border-radius: var(--bbk-radius-sm); + background: color-mix(in srgb, var(--bbk-notice-color) 6%, var(--bbk-color-bg)); + color: var(--bbk-color-text); + font-size: 0.875rem; +} + +.bbk-notice--info { --bbk-notice-color: var(--bbk-color-info); } + +.bbk-notice-icon { + flex: 0 0 auto; + width: 1.25rem; + height: 1.25rem; + color: var(--bbk-notice-color); +} + +.bbk-notice-text { margin: 0; align-self: center; } + /* ── Confirmation page ─────────────────────────────────────────────── */ .bbk-confirmation { - max-width: 720px; + max-width: 560px; margin: 0 auto; padding: 3rem 1.5rem 5rem; font-family: var(--bbk-font); @@ -916,7 +966,7 @@ textarea.bbk-field-input { resize: vertical; } } .bbk-confirmation-heading { - margin: 0 0 1rem; + margin: 0 0 1.25rem; font-size: 1.75rem; font-weight: 700; } @@ -924,7 +974,7 @@ textarea.bbk-field-input { resize: vertical; } .bbk-confirmation-ref { margin: 0 0 0.25rem; } .bbk-confirmation-meta { - margin: 0 0 1rem; + margin: 1.5rem 0 1rem; display: flex; flex-direction: column; gap: 0.25rem; @@ -940,17 +990,22 @@ textarea.bbk-field-input { resize: vertical; } .bbk-confirmation-meta-row dt { color: var(--bbk-color-muted); } .bbk-confirmation-meta-row dd { margin: 0; font-weight: 600; } -.bbk-confirmation-body { - margin: 2rem 0; - display: grid; - gap: 2.5rem; +.bbk-confirmation-section { + margin-top: 2rem; + padding-top: 1.5rem; + border-top: 1px solid var(--bbk-color-border); } -@media (min-width: 640px) { - .bbk-confirmation-body { grid-template-columns: 1fr 1fr; } +.bbk-confirmation-section-heading { + margin: 0 0 1rem; + font-size: 1.125rem; + font-weight: 700; } .bbk-confirmation-lines { + list-style: none; + margin: 0 0 1.25rem; + padding: 0; display: flex; flex-direction: column; gap: 0.75rem; @@ -965,16 +1020,21 @@ textarea.bbk-field-input { resize: vertical; } .bbk-confirmation-line-detail { min-width: 0; } +.bbk-confirmation-line-name { margin: 0 0 0.25rem; } + +.bbk-confirmation-line-total { margin: 0; white-space: nowrap; } + .bbk-confirmation-line-qty { color: var(--bbk-color-muted); } -.bbk-confirmation-lines .bbk-cart-summary { margin-top: 0.75rem; } - .bbk-confirmation-addresses { - display: flex; - flex-direction: column; + display: grid; gap: 1.5rem; } +@media (min-width: 480px) { + .bbk-confirmation-addresses { grid-template-columns: 1fr 1fr; } +} + .bbk-confirmation-address-heading, .bbk-confirmation-bank-transfer-heading { margin: 0 0 0.5rem; @@ -982,11 +1042,6 @@ textarea.bbk-field-input { resize: vertical; } font-weight: 700; } -.bbk-confirmation-bank-transfer { - padding-top: 1.5rem; - border-top: 1px solid var(--bbk-color-border); -} - /* Store-authored rich text (ManageStoreDetails' RichEditor) — may be paragraphs, bold text or a bank/IBAN/BIC table. */ .bbk-confirmation-bank-transfer-body { diff --git a/resources/js/checkout/bbk-cart-controller.js b/resources/js/checkout/bbk-cart-controller.js index dfe5901..5834150 100644 --- a/resources/js/checkout/bbk-cart-controller.js +++ b/resources/js/checkout/bbk-cart-controller.js @@ -9,11 +9,13 @@ import { csrfToken } from './csrf' // - handles the in-drawer quantity / remove forms (fetch + method spoofing) // - re-emits `bbk-cart:updated` {count, total} after every render so the host // (e.g. the header bag icon) can react +// - dialog focus handling: focus moves into the panel on open, Tab is kept +// inside it, and focus returns to whatever opened it on close // // Appearance is entirely CSS-driven: open state is the data-bbk-cart-state // attribute on the root, nothing here touches styles or class lists. export default class extends Controller { - static targets = ['panel', 'body', 'error'] + static targets = ['panel', 'body', 'error', 'heading', 'status'] connect() { this.onChanged = this.onChanged.bind(this) @@ -40,19 +42,31 @@ export default class extends Controller { } onKeydown(event) { - if (event.key === 'Escape' && !this.element.hidden) this.close() + // Only the drawer instance is a dialog — the checkout page's summary + // reuses this controller without a panel. + if (!this.hasPanelTarget || this.element.hidden) return + + if (event.key === 'Escape') this.close() + if (event.key === 'Tab') this.trapFocus(event) } open() { if (!this.element.hidden) return + this.returnFocusTo = document.activeElement this.element.hidden = false // Next frame, so the panel transitions from its off-canvas start. - requestAnimationFrame(() => this.element.setAttribute('data-bbk-cart-state', 'open')) + requestAnimationFrame(() => { + this.element.setAttribute('data-bbk-cart-state', 'open') + if (this.hasHeadingTarget) this.headingTarget.focus({ preventScroll: true }) + }) } close() { this.element.removeAttribute('data-bbk-cart-state') + if (this.returnFocusTo?.isConnected) this.returnFocusTo.focus({ preventScroll: true }) + this.returnFocusTo = null + const panel = this.panelTarget const done = () => { this.element.hidden = true @@ -132,6 +146,28 @@ export default class extends Controller { } } + // aria-modal hides the page from screen readers but doesn't stop Tab from + // walking out of the panel into it — wrap at either end instead. + trapFocus(event) { + const focusable = [...this.panelTarget.querySelectorAll( + 'a[href], button:not([disabled]), input:not([disabled]):not([type="hidden"]), select:not([disabled]), textarea:not([disabled]), [tabindex]:not([tabindex="-1"])', + )].filter((el) => !el.closest('[hidden], [aria-hidden="true"]')) + + if (!focusable.length) return + + const first = focusable[0] + const last = focusable[focusable.length - 1] + const active = document.activeElement + + if (event.shiftKey && (active === first || !this.panelTarget.contains(active) || (this.hasHeadingTarget && active === this.headingTarget))) { + event.preventDefault() + last.focus() + } else if (!event.shiftKey && (active === last || !this.panelTarget.contains(active))) { + event.preventDefault() + first.focus() + } + } + showError(message) { if (!this.hasErrorTarget || !message) return this.errorTarget.textContent = message @@ -144,10 +180,53 @@ export default class extends Controller { } replaceBody(html) { + const restore = this.focusSnapshot() this.bodyTarget.innerHTML = html + restore() + this.announce() this.emitUpdated(this.bodyTarget.querySelector('[data-bbk-cart-count]')) } + // Swapping the body destroys whatever control had focus (a qty stepper, + // a remove button, the coupon field), dropping keyboard/screen-reader + // users back at the top of the document. Returns a callback that, after + // the swap, re-focuses the equivalent control in the new markup — or the + // heading, when that control is gone (e.g. its line was just removed). + focusSnapshot() { + const active = document.activeElement + if (!active || !this.bodyTarget.contains(active)) return () => {} + + let selector = null + if (active.id) { + selector = `#${CSS.escape(active.id)}` + } else { + const lineId = active.closest('[data-bbk-line-id]')?.dataset.bbkLineId + const dir = active.dataset.bbkCartDirParam + const control = ['bbk-cart-qty-input', 'bbk-cart-qty-btn', 'bbk-cart-item-remove'] + .find((name) => active.classList.contains(name)) + + if (lineId && control) { + selector = `[data-bbk-line-id="${CSS.escape(lineId)}"] .${control}` + + (dir ? `[data-bbk-cart-dir-param="${CSS.escape(dir)}"]` : '') + } + } + + return () => { + const target = selector && this.bodyTarget.querySelector(selector) + if (target) target.focus({ preventScroll: true }) + else if (this.hasHeadingTarget) this.headingTarget.focus({ preventScroll: true }) + } + } + + // Polite "Cart updated" — cleared first so an identical message is + // re-announced on the next update. + announce() { + if (!this.hasStatusTarget) return + const message = this.statusTarget.dataset.bbkCartMessage || '' + this.statusTarget.textContent = '' + requestAnimationFrame(() => { this.statusTarget.textContent = message }) + } + emitUpdated(node) { if (!node) return diff --git a/resources/views/checkout/confirmation.blade.php b/resources/views/checkout/confirmation.blade.php index d7b127a..39ad613 100644 --- a/resources/views/checkout/confirmation.blade.php +++ b/resources/views/checkout/confirmation.blade.php @@ -14,10 +14,19 @@

{{ __('checkout.page.confirmation_heading') }}

+
+ +

{{ __('checkout.page.confirmation_email_note') }}

+
+
{{ __('checkout.page.confirmation_order_number') }}
-
{{ \Modules\Core\Order\Support\OrderReferenceDisplay::resolve($order) }}
+
#{{ \Modules\Core\Order\Support\OrderReferenceDisplay::resolve($order) }}
@if ($order->billingAddress?->contact_email) @@ -42,8 +51,6 @@ @endif
-

{{ __('checkout.page.confirmation_email_note') }}

- {{-- Guests: logging in with the order's email attaches it to an account (boboko-core's Modules\Core\Customer\Listeners\ClaimGuestOrdersOnLogin), so it shows in their history. --}} @@ -56,21 +63,29 @@ @endif @endguest -
-
+
+

+ {{ __('checkout.page.order_summary_heading') }} +

+ +
    @foreach ($order->lines->where('type', '!=', 'shipping') as $line) -
    +
  • + {{-- alt="" — the description is right beside it. --}} @if ($thumb = $line->purchasable?->getThumbnailImage()) - {{ $line->description }} + @endif
    - +

    {{ $line->description }} - × {{ $line->quantity }} - + + + — {{ __('checkout.cart.quantity') }}: {{ $line->quantity }} + +

    @if ($line->option)

    {{ $line->option }}

    @@ -79,62 +94,67 @@ @include('checkout::partials.line-custom-fields', ['line' => $line])
    - {{ $line->sub_total?->formatted() }} -
  • +

    + {{ __('checkout.cart.total') }}: + {{ $line->sub_total?->formatted() }} +

    + @endforeach +
-
+
+
+ {{ __('checkout.cart.subtotal') }} + {{ $order->sub_total?->formatted() }} +
+ + @if ($order->discount_total?->value > 0) +
+ {{ __('checkout.cart.discount') }} + −{{ $order->discount_total->formatted() }} +
+ @endif + +
+ {{ __('checkout.cart.shipping') }} + {{ $order->shipping_total?->formatted() }} +
+ + @if ($order->tax_total?->value > 0)
- {{ __('checkout.cart.subtotal') }} - {{ $order->sub_total?->formatted() }} + {{ __('checkout.cart.tax') }} + {{ $order->tax_total->formatted() }}
+ @endif - @if ($order->discount_total?->value > 0) -
- {{ __('checkout.cart.discount') }} - −{{ $order->discount_total->formatted() }} -
- @endif - -
- {{ __('checkout.cart.shipping') }} - {{ $order->shipping_total?->formatted() }} -
- - @if ($order->tax_total?->value > 0) -
- {{ __('checkout.cart.tax') }} - {{ $order->tax_total->formatted() }} -
- @endif - -
- {{ __('checkout.cart.total') }} - {{ $order->total?->formatted() }} -
+
+ {{ __('checkout.cart.total') }} + {{ $order->total?->formatted() }}
+
-
+ @if ($order->shippingAddress || $order->billingAddress) +
@if ($order->shippingAddress) -
-

{{ __('checkout.page.confirmation_shipping_to') }}

+
+

{{ __('checkout.page.confirmation_shipping_to') }}

-
+ @endif @if ($order->billingAddress) -
-

{{ __('checkout.page.confirmation_billing') }}

+
+

{{ __('checkout.page.confirmation_billing') }}

-
+ @endif
-
+ @endif @if ($bankTransferInstructions) -
-

{{ __('checkout.page.confirmation_bank_transfer_heading') }}

+
+

{{ __('checkout.page.confirmation_bank_transfer_heading') }}

{!! $bankTransferInstructions !!}
@endif diff --git a/resources/views/checkout/drawer.blade.php b/resources/views/checkout/drawer.blade.php index 24a98ed..570553b 100644 --- a/resources/views/checkout/drawer.blade.php +++ b/resources/views/checkout/drawer.blade.php @@ -15,7 +15,9 @@ data-bbk-cart-target="panel" >
-

{{ __('checkout.cart.title') }}

+ {{-- tabindex=-1: the controller moves focus here on open, and back + here when the focused line is removed from under the user. --}} +

{{ __('checkout.cart.title') }}

+ +
+ @if ($variantLabel)

{{ $variantLabel }}

@endif @include('checkout::partials.line-custom-fields', ['line' => $line])

{{ $line->unitPrice?->formatted() }}

-
- @csrf - @method('PATCH') - - - + {{-- role=group + the title as its name: entering the stepper + announces which product's quantity is being changed. --}} + + @csrf + @method('PATCH') + - -
-
+ -
-

{{ $line->subTotal?->formatted() }}

+ + -
- @csrf - @method('DELETE') - -
+

+ {{ __('checkout.cart.total') }}: + {{ $line->subTotal?->formatted() }} +

+
diff --git a/src/Checkout/Database/Seeders/CheckoutTranslationsSeeder.php b/src/Checkout/Database/Seeders/CheckoutTranslationsSeeder.php index 61057eb..4df6858 100644 --- a/src/Checkout/Database/Seeders/CheckoutTranslationsSeeder.php +++ b/src/Checkout/Database/Seeders/CheckoutTranslationsSeeder.php @@ -60,6 +60,7 @@ class CheckoutTranslationsSeeder extends Seeder 'cart.increase' => ['Increase quantity', 'Αύξηση ποσότητας'], 'cart.decrease' => ['Decrease quantity', 'Μείωση ποσότητας'], 'cart.remove' => ['Remove', 'Αφαίρεση'], + 'cart.updated' => ['Cart updated', 'Το καλάθι ενημερώθηκε'], 'cart.subtotal' => ['Subtotal', 'Υποσύνολο'], 'cart.discount' => ['Discount', 'Έκπτωση'], 'cart.shipping' => ['Shipping', 'Μεταφορικά'], From 004f2382cb4260c80bbef1f941b318e9a6ba194d Mon Sep 17 00:00:00 2001 From: elvira Date: Tue, 29 Sep 2026 21:30:41 +0300 Subject: [PATCH 07/13] Bump version to 0.27.4 --- CHANGELOG.md | 20 ++++++++++++++++++++ composer.json | 2 +- package.json | 2 +- 3 files changed, 22 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 478d47c..21e4e34 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,26 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/). +## [0.27.4] - 2026-09-29 +### Added +- Generic `.bbk-notice` / `.bbk-notice--info` message box and a + `--bbk-color-info` custom property in `checkout.css`. +- Cart drawer focus handling: focus moves into the drawer on open, stays + inside it, returns to the opener on close, and is restored after each + cart update. Updates are announced as "Cart updated" instead of re-reading + the whole cart. New translation line `checkout.cart.updated` — re-run + `CheckoutTranslationsSeeder` in consuming apps to add it. + +### Changed +- Cart drawer line: larger remove button on the title row, line total on + the quantity-stepper row, and screen-reader labels tied to the product + name. `.bbk-cart-item-aside` is removed — hosts restyling it should target + `.bbk-cart-item-head` / `.bbk-cart-item-foot` instead. +- Order confirmation page: narrower (560px), the confirmation-email note is + now an info box under the heading, the order summary comes before + shipping/billing (shown side by side), and the order number is prefixed + with `#`. + ## [0.27.3] - 2026-09-29 ### Added - The checkout confirmation page now ends with the store's bank transfer diff --git a/composer.json b/composer.json index 4fd1c8e..3b28e84 100644 --- a/composer.json +++ b/composer.json @@ -2,7 +2,7 @@ "name": "boboko/core", "description": "Core module — authentication and shared panel behaviour", "type": "library", - "version": "0.27.3", + "version": "0.27.4", "autoload": { "psr-4": { "Modules\\Core\\": "src/" diff --git a/package.json b/package.json index cbd533c..d939f0c 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@boboko/core", - "version": "0.27.3", + "version": "0.27.4", "private": true, "type": "module", "description": "Portable Stimulus controllers and styles for boboko-core's cart + checkout module. Installed as a real npm dependency (file:../boboko-core in dev, a tagged git install in prod) so a consuming app's `npm install` resolves this package's own dependencies (leaflet, @hotwired/stimulus) transitively, the same way `composer update boboko/*` does for PHP. See CONTRIBUTE.md's \"JS/CSS: a real npm package\" section.", From 52f303696015a5f27b9a4a66d362ceda5f081d8e Mon Sep 17 00:00:00 2001 From: Konstantinos Arvanitakis Date: Wed, 30 Sep 2026 11:15:27 +0300 Subject: [PATCH 08/13] Feat: Adding hashes for otp codes --- ...30_000001_hash_otp_code_on_users_table.php | 43 +++++++++++++++++++ ...002_hash_otp_code_on_lunar_staff_table.php | 37 ++++++++++++++++ docs/lunar.md | 2 +- docs/otp-auth.md | 5 ++- src/Auth/Models/Staff.php | 14 +++++- src/Auth/Services/OtpService.php | 14 ++++-- src/Auth/Services/UserOtpService.php | 26 +++++++---- src/CorePlugin.php | 2 +- src/Customer/Privacy/CustomerDataProvider.php | 2 +- .../Services/CustomerEmailChangeService.php | 2 +- 10 files changed, 128 insertions(+), 19 deletions(-) create mode 100644 database/migrations/2026_09_30_000001_hash_otp_code_on_users_table.php create mode 100644 database/migrations/2026_09_30_000002_hash_otp_code_on_lunar_staff_table.php diff --git a/database/migrations/2026_09_30_000001_hash_otp_code_on_users_table.php b/database/migrations/2026_09_30_000001_hash_otp_code_on_users_table.php new file mode 100644 index 0000000..70dd2ac --- /dev/null +++ b/database/migrations/2026_09_30_000001_hash_otp_code_on_users_table.php @@ -0,0 +1,43 @@ +string('otp_code_hash')->nullable()->after('password'); + }); + + Schema::table('users', function (Blueprint $table) { + $table->dropColumn('otp_code'); + }); + } + + public function down(): void + { + Schema::table('users', function (Blueprint $table) { + $table->string('otp_code', 6)->nullable()->after('password'); + }); + + Schema::table('users', function (Blueprint $table) { + $table->dropColumn('otp_code_hash'); + }); + } +}; diff --git a/database/migrations/2026_09_30_000002_hash_otp_code_on_lunar_staff_table.php b/database/migrations/2026_09_30_000002_hash_otp_code_on_lunar_staff_table.php new file mode 100644 index 0000000..a8f2efd --- /dev/null +++ b/database/migrations/2026_09_30_000002_hash_otp_code_on_lunar_staff_table.php @@ -0,0 +1,37 @@ +string('otp_code_hash')->nullable()->after('password'); + }); + + Schema::table('lunar_staff', function (Blueprint $table) { + $table->dropColumn('otp_code'); + }); + } + + public function down(): void + { + Schema::table('lunar_staff', function (Blueprint $table) { + $table->string('otp_code', 6)->nullable()->after('password'); + }); + + Schema::table('lunar_staff', function (Blueprint $table) { + $table->dropColumn('otp_code_hash'); + }); + } +}; diff --git a/docs/lunar.md b/docs/lunar.md index f21eb27..6db907a 100644 --- a/docs/lunar.md +++ b/docs/lunar.md @@ -393,7 +393,7 @@ Because Filament instantiates `Lunar\Admin\Models\Staff` directly (not a subclas ```php use Lunar\Admin\Models\Staff as LunarStaff; -LunarStaff::addActivitylogExcept(['otp_code', 'otp_expires_at', 'password']); +LunarStaff::addActivitylogExcept(['otp_code_hash', 'otp_expires_at', 'password']); ``` --- diff --git a/docs/otp-auth.md b/docs/otp-auth.md index 5dd8832..e07663a 100644 --- a/docs/otp-auth.md +++ b/docs/otp-auth.md @@ -30,11 +30,12 @@ Codes expire after **10 minutes**. After a successful validation the code is cle ### Database -Two columns on the `lunar_staff` table (added by `2026_05_06_000001_add_otp_to_lunar_staff_table`): +Two columns on the `lunar_staff` table (added by `2026_05_06_000001_add_otp_to_lunar_staff_table`, +`otp_code` replaced with a hashed column by `2026_09_30_000002_hash_otp_code_on_lunar_staff_table`): | Column | Type | Purpose | |---|---|---| -| `otp_code` | string, nullable | The generated code | +| `otp_code_hash` | string, nullable | Bcrypt hash of the generated code (`'hashed'` cast on `Staff`) | | `otp_expires_at` | timestamp, nullable | Expiry time | ### Login Page diff --git a/src/Auth/Models/Staff.php b/src/Auth/Models/Staff.php index 900d39e..5d2ba2a 100644 --- a/src/Auth/Models/Staff.php +++ b/src/Auth/Models/Staff.php @@ -11,7 +11,7 @@ class Staff extends ModelsStaff 'last_name', 'admin', 'email', - 'otp_code', + 'otp_code_hash', 'otp_expires_at', ]; @@ -19,6 +19,18 @@ class Staff extends ModelsStaff 'admin' => 'bool', 'email_verified_at' => 'datetime', 'password' => 'hashed', + 'otp_code_hash' => 'hashed', 'otp_expires_at' => 'datetime', ]; + + // Overrides (doesn't merge with) Lunar\Admin\Models\Staff's own + // $hidden — repeats its password/remember_token here so this class + // doesn't silently drop that protection while adding otp_code_hash/ + // otp_expires_at, which the base model has no reason to know about. + protected $hidden = [ + 'password', + 'remember_token', + 'otp_code_hash', + 'otp_expires_at', + ]; } diff --git a/src/Auth/Services/OtpService.php b/src/Auth/Services/OtpService.php index d5b813f..d524df3 100644 --- a/src/Auth/Services/OtpService.php +++ b/src/Auth/Services/OtpService.php @@ -2,6 +2,7 @@ namespace Modules\Core\Auth\Services; +use Illuminate\Support\Facades\Hash; use Illuminate\Support\Facades\Mail; use Modules\Core\Auth\Mail\OtpMail; use Modules\Core\Auth\Models\Staff; @@ -27,7 +28,10 @@ class OtpService $code = str_pad((string) random_int(0, 999999), self::CODE_LENGTH, '0', STR_PAD_LEFT); - $staff->otp_code = $code; + // otp_code_hash's 'hashed' cast (see Staff's own $casts) hashes + // this automatically on assignment, same as password — never + // stored or compared in plaintext. + $staff->otp_code_hash = $code; $staff->otp_expires_at = now()->addMinutes(self::EXPIRY_MINUTES); $staff->save(); @@ -44,11 +48,15 @@ class OtpService return null; } - if (! $staff->otp_expires_at || $staff->otp_code != $code || now()->isAfter($staff->otp_expires_at)) { + if (! $staff->otp_code_hash || ! $staff->otp_expires_at || now()->isAfter($staff->otp_expires_at)) { return null; } - $staff->otp_code = null; + if (! Hash::check($code, $staff->otp_code_hash)) { + return null; + } + + $staff->otp_code_hash = null; $staff->otp_expires_at = null; $staff->save(); diff --git a/src/Auth/Services/UserOtpService.php b/src/Auth/Services/UserOtpService.php index 8a43380..df5c4ef 100644 --- a/src/Auth/Services/UserOtpService.php +++ b/src/Auth/Services/UserOtpService.php @@ -8,6 +8,7 @@ use Illuminate\Support\Facades\Auth; use Illuminate\Support\Facades\Cache; use Illuminate\Support\Facades\DB; use Illuminate\Support\Facades\Event; +use Illuminate\Support\Facades\Hash; use Illuminate\Support\Facades\Mail; use Illuminate\Support\Facades\RateLimiter; use Modules\Core\Auth\Events\UserAuthenticated; @@ -40,8 +41,11 @@ use Modules\Core\Auth\Mail\UserOtpMail; * at all — firstOrCreate() and UserCreated only fire from validate(), and * only once the code has actually been proven correct. An email that * already has a User row is unaffected: its OTP state still lives on that - * row's own otp_code/otp_expires_at/otp_attempts columns exactly as - * before, so a returning shopper's login is unchanged. + * row's own otp_code_hash/otp_expires_at/otp_attempts columns exactly as + * before, so a returning shopper's login is unchanged. otp_code_hash + * holds a bcrypt hash of the code (the 'otp_code_hash' => 'hashed' cast + * on App\Models\User hashes it automatically on assignment, same as + * password), not the code itself — compared via Hash::check(). * * Two independent throttles, both configured under core.auth.otp — see * config/core.php's own comment for why they're separate: max_attempts @@ -87,7 +91,7 @@ class UserOtpService $code = str_pad((string) random_int(0, 999999), self::CODE_LENGTH, '0', STR_PAD_LEFT); if ($user) { - $user->otp_code = $code; + $user->otp_code_hash = $code; $user->otp_expires_at = now()->addMinutes(self::EXPIRY_MINUTES); $user->otp_attempts = 0; $user->save(); @@ -96,8 +100,12 @@ class UserOtpService // class's own docblock for why: creating one on every // generateAndSend() call let anyone mint real User/Customer // rows for an email nobody proved they owned. + // + // Hashed even in the cache (not just on the DB-backed path) + // — a code sitting in Cache::get()-able storage is the same + // exposure as a plaintext DB column if anything can read it. Cache::put($this->pendingKey($email), [ - 'code' => $code, + 'code_hash' => Hash::make($code), 'expires_at' => now()->addMinutes(self::EXPIRY_MINUTES)->timestamp, 'attempts' => 0, ], now()->addMinutes(self::EXPIRY_MINUTES)); @@ -154,15 +162,15 @@ class UserOtpService return DB::transaction(function () use ($model, $email, $code) { $user = $model::where('email', $email)->lockForUpdate()->first(); - if (! $user || ! $user->otp_expires_at || now()->isAfter($user->otp_expires_at)) { + if (! $user || ! $user->otp_code_hash || ! $user->otp_expires_at || now()->isAfter($user->otp_expires_at)) { return null; } - if (! hash_equals((string) $user->otp_code, $code)) { + if (! Hash::check($code, $user->otp_code_hash)) { $user->otp_attempts++; if ($user->otp_attempts >= (int) config('core.auth.otp.max_attempts', 5)) { - $user->otp_code = null; + $user->otp_code_hash = null; $user->otp_expires_at = null; $user->otp_attempts = 0; } @@ -172,7 +180,7 @@ class UserOtpService return null; } - $user->otp_code = null; + $user->otp_code_hash = null; $user->otp_expires_at = null; $user->otp_attempts = 0; $user->save(); @@ -200,7 +208,7 @@ class UserOtpService return null; } - if (! hash_equals((string) $pending['code'], $code)) { + if (! Hash::check($code, $pending['code_hash'])) { $pending['attempts']++; if ($pending['attempts'] >= (int) config('core.auth.otp.max_attempts', 5)) { diff --git a/src/CorePlugin.php b/src/CorePlugin.php index afd9a47..1966a68 100644 --- a/src/CorePlugin.php +++ b/src/CorePlugin.php @@ -150,7 +150,7 @@ class CorePlugin implements Plugin }); LunarStaff::addActivitylogExcept([ - 'otp_code', + 'otp_code_hash', 'otp_expires_at', 'password', 'remember_token', diff --git a/src/Customer/Privacy/CustomerDataProvider.php b/src/Customer/Privacy/CustomerDataProvider.php index 7019be6..f4c12df 100644 --- a/src/Customer/Privacy/CustomerDataProvider.php +++ b/src/Customer/Privacy/CustomerDataProvider.php @@ -115,7 +115,7 @@ class CustomerDataProvider implements PersonalDataProvider // secret tied to an identity that no longer exists here — clear // it alongside name/email rather than leaving it to expire on // its own 10-minute window. - 'otp_code' => null, + 'otp_code_hash' => null, 'otp_expires_at' => null, 'otp_attempts' => 0, ]); diff --git a/src/Customer/Services/CustomerEmailChangeService.php b/src/Customer/Services/CustomerEmailChangeService.php index 54ceb5f..a5292c5 100644 --- a/src/Customer/Services/CustomerEmailChangeService.php +++ b/src/Customer/Services/CustomerEmailChangeService.php @@ -23,7 +23,7 @@ use Modules\Core\Customer\Exceptions\InvalidEmailChangeCodeException; * hash of the code, expiry, wrong-guess count) lives on the user's own * row (see the migration adding pending_email/pending_email_code_hash/ * pending_email_expires_at/pending_email_attempts) — the same convention - * Auth\Services\UserOtpService's otp_code/otp_expires_at/otp_attempts + * Auth\Services\UserOtpService's otp_code_hash/otp_expires_at/otp_attempts * already use — rather than the session, since a code arrives by email * and is often opened on a different device/session than the one that * requested it; a session-scoped pending change couldn't be confirmed From 44a2ddda4a119a312e783e19c1a2d54a212bdb75 Mon Sep 17 00:00:00 2001 From: Konstantinos Arvanitakis Date: Wed, 30 Sep 2026 11:15:38 +0300 Subject: [PATCH 09/13] Bump version to 0.27.5 --- CHANGELOG.md | 20 ++++++++++++++++++++ composer.json | 2 +- package.json | 2 +- 3 files changed, 22 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 21e4e34..8740811 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,26 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/). +## [0.27.5] - 2026-09-30 +### Security +- OTP codes (both customer login via `UserOtpService` and staff login via + `OtpService`) were stored in plaintext in `users.otp_code`/`lunar_staff.otp_code` + and compared against the plaintext guess. The staff path was additionally + weaker — a loose `!=` comparison with no timing-attack protection and no + attempt-limiting at all. Both columns are replaced with `otp_code_hash` + (bcrypt, via a `'hashed'` cast — same convention `password` already uses), + compared with `Hash::check()`. The cache-backed pending-signup OTP path + (an email with no `User` row yet) is hashed the same way. No backfill — + any code mid-flight when this deploys is invalidated (codes expire in 10 + minutes regardless, so the practical impact is limited to a re-request). +- `App\Models\User`'s (3dealer) and `Modules\Core\Auth\Models\Staff`'s + `$hidden` arrays didn't list `otp_code`/`otp_expires_at`/`otp_attempts`/ + `pending_email_code_hash`/etc. at all — any serialization of either model + (an API response, `Auth::user()` returned somewhere) would have leaked + those fields, including the (now-hashed, previously plaintext) OTP code + itself. `Staff` additionally never overrode Lunar's own base `$hidden`, so + it also lacked `password`/`remember_token` protection until now. + ## [0.27.4] - 2026-09-29 ### Added - Generic `.bbk-notice` / `.bbk-notice--info` message box and a diff --git a/composer.json b/composer.json index 3b28e84..c374fe5 100644 --- a/composer.json +++ b/composer.json @@ -2,7 +2,7 @@ "name": "boboko/core", "description": "Core module — authentication and shared panel behaviour", "type": "library", - "version": "0.27.4", + "version": "0.27.5", "autoload": { "psr-4": { "Modules\\Core\\": "src/" diff --git a/package.json b/package.json index d939f0c..42e91c1 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@boboko/core", - "version": "0.27.4", + "version": "0.27.5", "private": true, "type": "module", "description": "Portable Stimulus controllers and styles for boboko-core's cart + checkout module. Installed as a real npm dependency (file:../boboko-core in dev, a tagged git install in prod) so a consuming app's `npm install` resolves this package's own dependencies (leaflet, @hotwired/stimulus) transitively, the same way `composer update boboko/*` does for PHP. See CONTRIBUTE.md's \"JS/CSS: a real npm package\" section.", From d19fe1b6ea9d96277d254efa5070d2f6b3d4b7f4 Mon Sep 17 00:00:00 2001 From: Konstantinos Arvanitakis Date: Wed, 30 Sep 2026 11:33:39 +0300 Subject: [PATCH 10/13] Docs: Updating CONTRIBUTE.md and index.js documentation for correct deploy --- CONTRIBUTE.md | 143 ++++++++++++++++++++++++++++-------------- resources/js/index.js | 2 +- 2 files changed, 98 insertions(+), 47 deletions(-) diff --git a/CONTRIBUTE.md b/CONTRIBUTE.md index b441007..6cbb432 100644 --- a/CONTRIBUTE.md +++ b/CONTRIBUTE.md @@ -1,85 +1,136 @@ # Contributing to boboko-core -This is a Composer library, not a runnable app — you can't `php artisan serve` it directly. To develop and verify changes, you need a consumer app wired to a local checkout via a Composer path repository, plus a real database, since a large part of this package (Lunar models, migrations, Filament panel resources) can only be meaningfully verified against a live Lunar install. +This is a Composer library (and an npm package of the same name — see [JS/CSS](#jscss-a-real-npm-package)), not a runnable app — you can't `php artisan serve` it directly. To develop and verify changes, you need a consumer app wired to a local checkout, plus a real database, since a large part of this package (Lunar models, migrations, Filament panel resources) can only be meaningfully verified against a live Lunar install. ## Local dev setup -This works against any consumer app that follows the same convention — `boboko-test`, `boboko-starter`, `boboko-3dealer`, etc. — checked out next to this repo: +Consumer apps (`3dealer`, `boboko-test`, …) are checked out next to this repo: ``` RadicalElements/ ├── boboko-core/ (this repo) -└── boboko-test/ (or boboko-starter, boboko-3dealer, ... — consumer app, Docker-based) +└── 3dealer/ (or boboko-test, ... — consumer app, Docker-based) ``` -Each of these consumer apps ships a `bin/dc-core.sh` helper that wraps the Docker Compose overlay needed to bind-mount a local `boboko-core` checkout into the app container: +### Two modes: local and repo + +A consumer app can consume core in one of two modes, and carries the wiring for both. The inactive one is parked under an underscore-prefixed key: + +| | **local** — your `../boboko-core` checkout | **repo** — tagged releases from the forge | +|---|---|---| +| `composer.json` | `repositories`: path repo `../boboko-core` (`"symlink": true`) | `repositories`: VCS repo `https://code.radical-elements.com/boboko/core.git` | +| `package.json` | `@boboko/core`: `file:../boboko-core` | `@boboko/core`: `git+https://code.radical-elements.com/boboko/core.git#semver:0.x` | +| Docker Compose | `bin/dc-core.sh` (dev + `docker-compose.core-dev.yml` overlay) | `bin/dc` (dev only) | + +- **The committed state is always repo mode.** Local mode rewrites both lockfiles to point at `../boboko-core`, which doesn't exist on the server — never commit it. +- Both sides use an open `0.x` range: `"boboko/core": "0.*"` in Composer, `#semver:0.x` in npm. Don't use a caret: below 1.0.0, `^0.27.0` means `>=0.27.0 <0.28.0` in both tools, so it would silently refuse the next minor. +- `docker-compose.core-dev.yml` bind-mounts `../boboko-core` into the containers — at `/var/www/boboko-core` for `app`/`queue`/`scheduler` (where the path repo resolves from `/var/www/html`) and at `/boboko-core` for `vite` (where `file:../boboko-core` resolves from `/app`). Inside the app container, `vendor/boboko/core` is a symlink into that mount. + +### Switching modes: `bin/core-mode` + +Don't swap the keys by hand — each consumer app ships a `bin/core-mode` script: ```bash -./bin/dc-core.sh exec app +bin/core-mode # print the current mode +bin/core-mode local # work against ../boboko-core +bin/core-mode repo # back to tagged releases ``` -This is shorthand for `docker compose -f docker-compose.dev.yml -f docker-compose.core-dev.yml exec app `. Use `./bin/dc-core.sh` for everything below instead of typing the full compose invocation. +It swaps the `composer.json` / `package.json` wiring, runs `down` with the old mode's Compose wrapper and `up` with the new one, then waits until the entrypoints have re-resolved core. Running it for the mode you're already in skips the edits and just restarts the stack — in repo mode, that's how you pick up a newly pushed tag. -1. **Path repository.** In the consumer app's `composer.json`, the `repositories` array needs a path entry pointing at `../boboko-core`. If it only exists in a disabled block (e.g. `_repositories`), move it into the live array. -2. **Relaxed version constraint.** The consumer app's `composer.json` should require `"boboko/core": "0.*"` (not a tight `^0.0.1` caret) — otherwise Composer rejects newer `0.0.x` versions resolved from the path repo. -3. **Bind mount.** The consumer app's `docker-compose.core-dev.yml` overlays `../boboko-core` into the container at `/var/www/boboko-core`, matching where the path repo resolves it relative to `/var/www/html`. -4. **Re-resolve after every change.** Composer's path repo does not hot-reload — after editing anything in `boboko-core` (including adding new files, which need autoload discovery), the container needs to re-run `composer update boboko/core`. In `boboko-test`, the entrypoint does this automatically on every dev boot (see `docker/entrypoint.sh`), so `./bin/dc-core.sh up` alone picks up local core changes. If a consumer app's entrypoint doesn't do this yet, run it manually: +(`3dealer` has `bin/core-mode` and `bin/deploy`; they're app-agnostic, so other consumer apps can copy them as-is.) - ```bash - ./bin/dc-core.sh exec app composer update boboko/core --with-all-dependencies - ``` +### Day to day in local mode - Skipping this step is the most common cause of "my change isn't showing up." +Use `bin/dc-core.sh` for every Compose command (`bin/dc-core.sh exec app …`, `bin/dc-core.sh logs -f`, …) — plain `docker compose` or `bin/dc` leaves the core mount out. -## JS/CSS: no separate npm package +The dev entrypoints re-resolve core on **every boot**: `docker/entrypoint.sh` runs `composer update "boboko/*"` and `docker/entrypoint-vite.sh` runs `npm update @boboko/core`. So: -This package's JS (Stimulus controllers) and CSS ship as plain source files under `resources/js/` and `resources/css/`, read directly by a consumer app's own Vite build — there is no separate `@boboko/core` npm package, and no `npm install`/`file:` dependency step of any kind. +- **Whatever branch is checked out in `../boboko-core` is what the app runs.** Switching core branches switches the app's code — check which branch you're on before debugging "missing" features. +- PHP edits to existing files show up immediately (it's a symlink). **New classes, new migrations, or `composer.json` changes** need a re-resolve: restart the stack, or run -The reason: Composer already gives every environment one single, unconditional path — `vendor/boboko/core` — whether that resolves to a real symlink into `../boboko-core` (local path repo) or a real installed copy (tagged VCS release). A consumer's `vite.config.js` and JS entry point just read straight from that path, so there is nothing to toggle on the JS side — whatever Composer resolved is exactly what Vite sees, automatically, in both dev and prod. + ```bash + bin/dc-core.sh exec app composer update boboko/core --with-all-dependencies + ``` -**Stable entry point.** A consumer imports from [resources/js/index.js](resources/js/index.js) only — never from a path reaching into a specific module's internals (e.g. `resources/js/checkout/index.js` directly). That barrel file re-exports whatever a consumer needs (currently just `registerCheckout`), so this package's internal file layout can change without breaking every consumer's own entry point: + Skipping this is the most common cause of "my change isn't showing up." +- In `3dealer`, the app container's `vendor/` is a named Docker volume, so the host's `vendor/` directory is stale — inspect packages inside the container, not on the host. + +## JS/CSS: a real npm package + +Core's Stimulus controllers and CSS ship as the `@boboko/core` npm package, installed into the consumer's `node_modules` — as a symlink to `../boboko-core` in local mode, as a real copy of the tagged release in repo mode. It's a real package (rather than files read out of `vendor/`) so npm installs core's own dependencies (`leaflet`, `@hotwired/stimulus`) transitively, the same way Composer does for PHP. + +Public entry points (`package.json` `exports`): + +| Import | File | +|---|---| +| `@boboko/core` | `resources/js/index.js` — the stable barrel (`registerCheckout`, `registerWishlist`, …) | +| `@boboko/core/vite-plugin` | `vite-plugin.js` — `boboko()` | +| `@boboko/core/css/*` | `resources/css/*` | +| `@boboko/core/checkout`, `@boboko/core/checkout/*` | `resources/js/checkout/…` | + +A consumer imports from the `@boboko/core` barrel only — not from a module's internal files — so the internal layout here can change without breaking every consumer: ```js // consumer app's resources/js/app.js -import { registerCheckout } from "../../vendor/boboko/core/resources/js/index.js"; +import { registerCheckout, registerWishlist } from "@boboko/core"; registerCheckout(application); +registerWishlist(application); +``` + +```js +// consumer app's vite.config.js +import { boboko } from "@boboko/core/vite-plugin"; + +export default defineConfig({ + plugins: [ + laravel({ + input: [ + // Core's structural checkout styles load first, so the app's own theming wins. + "node_modules/@boboko/core/resources/css/checkout.css", + "resources/css/app.css", + "resources/js/app.js", + ], + }), + boboko(), + ], +}); ``` ```php {{-- consumer app's layout --}} -@vite(['vendor/boboko/core/resources/css/checkout.css', 'resources/css/app.css', 'resources/js/app.js']) +@vite(['node_modules/@boboko/core/resources/css/checkout.css', 'resources/css/app.css', 'resources/js/app.js']) ``` -**What a consumer's `vite.config.js` needs**, because `vendor/boboko/core` is a symlink in local path-repo dev (not a real directory): +`boboko()` owns the Vite settings the local-mode symlink needs, so consumers don't hand-copy them: it excludes `@boboko/core` from dependency pre-bundling (otherwise Vite serves a stale cached copy after you edit core), pre-bundles `leaflet`/`@hotwired/stimulus` explicitly, and turns on `resolve.preserveSymlinks` and `server.watch.followSymlinks` so bare imports resolve from the consumer's `node_modules` and core edits trigger HMR. All of it is a harmless no-op against a real installed copy in repo mode. -```js -export default defineConfig({ - server: { - watch: { - // vendor/boboko/core is a symlink into ../boboko-core in local - // path-repo dev. Vite/chokidar don't follow symlinks for watched - // files by default, so edits to core's source wouldn't otherwise - // trigger HMR. No-op against a real installed copy (tagged VCS - // release) in production — there's no symlink to follow, and - // production only ever runs a one-shot `npm run build`, which - // doesn't watch anything regardless. - followSymlinks: true, - }, - }, -}); -``` +## Releasing a version -Bare imports inside this package's own JS (`leaflet`, `@hotwired/stimulus`) resolve against the *consumer's* `node_modules` — Node's normal upward `node_modules` resolution walks from `vendor/boboko/core/resources/js/...` up through `vendor/boboko/`, `vendor/`, to the consumer app's root, where `node_modules` lives. This works with zero extra config as long as `vendor/boboko/core` sits inside the consumer's own directory tree (true for both the symlink and the real-copy case) — a consuming app's `vite`-equivalent Docker service just needs the same bind mount PHP containers already get, landing at the same path: +1. Bump `"version"` in **both** `composer.json` and `package.json` — they must match. +2. Add a `CHANGELOG.md` entry under the new version. While pre-1.0, a new capability for consuming apps is a **minor** bump (`0.27.x` → `0.28.0`); a fix, redesign or internal swap with no new capability is a **patch** bump. +3. Commit, tag `vX.Y.Z`, and push the commit **and** the tag: -```yaml -# consumer app's docker-compose.core-dev.yml -services: - vite: - volumes: - - ../boboko-core:/app/vendor/boboko/core -``` + ```bash + git tag v0.27.5 + git push origin master v0.27.5 + ``` -(Match whatever the consumer's Vite container's working directory actually is — `/app` above, `/var/www/html` for the PHP containers in `boboko-test`'s convention.) +A tag alone changes nothing in production — each consumer app has to pick it up and deploy (below). + +## Deploying a consumer app + +Production only ever runs what the app's **committed lockfiles** pin. Each consumer app ships `bin/deploy`, which: + +1. Refuses to run on the wrong branch, with uncommitted changes (other than the core wiring files), or behind `origin`. +2. Runs `bin/core-mode repo` — switching from local mode if needed, restarting either way — so both lockfiles resolve the newest `0.x` tag. It warns if `../boboko-core` has a newer tag than what resolved (usually an unpushed tag). +3. Commits the lockfile bump (`Chore: Bumping boboko/core to X.Y.Z`) if there is one, shows what will be pushed, and asks for confirmation. +4. Pushes, then runs `vendor/bin/envoy run deploy` against the host in `.env.envoy`. + +Envoy (`Envoy.blade.php`) then, on the server: `git reset --hard` + `git pull`, `docker compose build` (the `production` image target runs `composer install --no-dev` and `npm ci` from the committed lockfiles — this is where the core tag actually lands), `up -d`, caches config/routes/events, restarts `queue` and `scheduler`, and regenerates Stoic thumbnails. The production entrypoint skips Composer entirely and runs migrations (including core's), seeders, the Meilisearch sync, and `artisan optimize`. + +After deploying you're left in repo mode — `bin/core-mode local` to go back. + +When a change spans core and the app (e.g. a core migration plus an app model cast that depends on it), ship them together: tag core first, then commit the app change and deploy — `bin/deploy` bumps the lock to the new tag in the same deploy. ## Verifying changes against a real database diff --git a/resources/js/index.js b/resources/js/index.js index 154fb46..74b4918 100644 --- a/resources/js/index.js +++ b/resources/js/index.js @@ -1,5 +1,5 @@ // Single stable JS entry point for this package. A consuming app imports -// from here (vendor/boboko/core/resources/js/index.js), never from a path +// from here (`import { … } from "@boboko/core"`), never from a path // reaching into a specific module's internals — so this file's exports can // grow or its modules' internal layout can change without breaking every // consumer's own entry point. From 82931953953fc94614b90bf2c35ff8285c7c0b00 Mon Sep 17 00:00:00 2001 From: Konstantinos Arvanitakis Date: Wed, 30 Sep 2026 12:07:26 +0300 Subject: [PATCH 11/13] Feat: Adding Translations Pull Command --- src/Command/PullTranslationsCommand.php | 159 ++++++++++++++++++ .../Seeders/StorefrontTranslationsSeeder.php | 8 + src/Providers/LocalizationServiceProvider.php | 5 + 3 files changed, 172 insertions(+) create mode 100644 src/Command/PullTranslationsCommand.php diff --git a/src/Command/PullTranslationsCommand.php b/src/Command/PullTranslationsCommand.php new file mode 100644 index 0000000..af17de4 --- /dev/null +++ b/src/Command/PullTranslationsCommand.php @@ -0,0 +1,159 @@ +> */ + private const SEEDERS = [ + 'storefront' => StorefrontTranslationsSeeder::class, + 'checkout' => CheckoutTranslationsSeeder::class, + 'validation' => ValidationTranslationsSeeder::class, + ]; + + public function handle(): int + { + $dryRun = (bool) $this->option('dry-run'); + $total = 0; + + foreach (self::SEEDERS as $group => $seederClass) { + $file = realpath((new ReflectionClass($seederClass))->getFileName()); + + if (! $dryRun && str_contains($file, '/vendor/')) { + $this->error("{$file} is an installed copy, not your ../boboko-core checkout."); + $this->line('Switch to local mode first (bin/core-mode local), or use --dry-run.'); + + return self::FAILURE; + } + + $known = (new ReflectionMethod($seederClass, 'lines'))->invoke(new $seederClass); + + $missing = LanguageLine::query() + ->where('group', $group) + ->whereNotIn('key', array_keys($known)) + ->orderBy('key') + ->get(); + + if ($missing->isEmpty()) { + $this->line("{$group}: nothing missing"); + + continue; + } + + $entries = ''; + + foreach ($missing as $line) { + $en = $line->text['en'] ?? ''; + $el = $line->text['el'] ?? ''; + + if ($en === '' || $el === '') { + $this->warn(" {$group}.{$line->key} has no ".($en === '' ? 'English' : 'Greek').' text — added empty, fill it in'); + } + + $entries .= $this->entry($line->key, $en, $el); + $this->info(" + {$group}.{$line->key}"); + } + + $total += $missing->count(); + + if (! $dryRun && ! $this->append($file, $entries)) { + return self::FAILURE; + } + } + + $this->newLine(); + $this->line($dryRun + ? "{$total} line(s) would be added." + : "{$total} line(s) added — move them into the right section and commit core."); + + return self::SUCCESS; + } + + /** + * One lines() entry in the seeders' own style: single line when short, + * split over several lines when long. + */ + private function entry(string $key, string $en, string $el): string + { + [$key, $en, $el] = array_map(fn (string $value) => var_export($value, true), [$key, $en, $el]); + + $single = " {$key} => [{$en}, {$el}],\n"; + + if (mb_strlen($single) <= 120) { + return $single; + } + + return " {$key} => [\n {$en},\n {$el},\n ],\n"; + } + + /** + * Inserts the entries right before the closing `];` of lines(), then + * lints the file and restores the original if the result doesn't parse. + */ + private function append(string $file, string $entries): bool + { + $original = file_get_contents($file); + $method = strpos($original, 'function lines(): array'); + $close = $method === false ? false : strpos($original, "\n ];\n }", $method); + + if ($close === false) { + $this->error("Couldn't find the end of lines() in {$file} — add these by hand."); + + return false; + } + + $before = rtrim(substr($original, 0, $close)); + + // The last existing entry doesn't always have a trailing comma. + if (! str_ends_with($before, ',') && ! str_ends_with($before, '[')) { + $before .= ','; + } + + $updated = $before + ."\n\n // ── Pulled from the database (boboko:translations:pull) — move into the right section ──\n" + .$entries + .substr($original, $close + 1); + + file_put_contents($file, $updated); + + exec(PHP_BINARY.' -l '.escapeshellarg($file).' 2>&1', $output, $exitCode); + + if ($exitCode !== 0) { + file_put_contents($file, $original); + $this->error("Writing {$file} produced invalid PHP — restored the original:"); + $this->line(implode("\n", $output)); + + return false; + } + + return true; + } +} diff --git a/src/Localization/Database/Seeders/StorefrontTranslationsSeeder.php b/src/Localization/Database/Seeders/StorefrontTranslationsSeeder.php index ae2b61b..cdf1b05 100644 --- a/src/Localization/Database/Seeders/StorefrontTranslationsSeeder.php +++ b/src/Localization/Database/Seeders/StorefrontTranslationsSeeder.php @@ -98,6 +98,14 @@ class StorefrontTranslationsSeeder extends Seeder 'pagination.previous' => ['Previous page', 'Προηγούμενη σελίδα'], 'pagination.page' => ['Page :page', 'Σελίδα :page'], + // ── Error pages ───────────────────────────────────────────── + 'errors.404_title' => ['Page not found', 'Η σελίδα δεν βρέθηκε'], + 'errors.404_text' => [ + 'The page you are looking for does not exist or has been moved.', + 'Η σελίδα που αναζητάς δεν υπάρχει ή έχει μετακινηθεί.', + ], + 'errors.back_home' => ['Back to home', 'Επιστροφή στην αρχική'], + // ── Reviews ───────────────────────────────────────────────── 'review.rating' => ['Rating', 'Βαθμολογία'], 'review.write_label' => ['Write a review', 'Γράψε μια αξιολόγηση'], diff --git a/src/Providers/LocalizationServiceProvider.php b/src/Providers/LocalizationServiceProvider.php index 112d481..7a6906b 100644 --- a/src/Providers/LocalizationServiceProvider.php +++ b/src/Providers/LocalizationServiceProvider.php @@ -5,6 +5,7 @@ namespace Modules\Core\Providers; use Illuminate\Support\Facades\Event; use Illuminate\Support\ServiceProvider; use Lunar\Models\Language; +use Modules\Core\Command\PullTranslationsCommand; use Modules\Core\Localization\Events\LanguageCreated; use Modules\Core\Localization\Events\LanguageDeleted; use Modules\Core\Localization\Events\LanguageUpdated; @@ -46,5 +47,9 @@ class LocalizationServiceProvider extends ServiceProvider } Event::listen(LanguageUpdated::class, MigrateTranslationsForRenamedLanguage::class); + + if ($this->app->runningInConsole()) { + $this->commands([PullTranslationsCommand::class]); + } } } From 536fe32e0d59b7dae0b8b2274c67bb55883611c2 Mon Sep 17 00:00:00 2001 From: Konstantinos Arvanitakis Date: Wed, 30 Sep 2026 12:10:55 +0300 Subject: [PATCH 12/13] Docs: Adding to CONTRIBUTE.md for translations --- CONTRIBUTE.md | 18 +++++++++++++++--- 1 file changed, 15 insertions(+), 3 deletions(-) diff --git a/CONTRIBUTE.md b/CONTRIBUTE.md index 6cbb432..02872c3 100644 --- a/CONTRIBUTE.md +++ b/CONTRIBUTE.md @@ -104,6 +104,17 @@ export default defineConfig({ `boboko()` owns the Vite settings the local-mode symlink needs, so consumers don't hand-copy them: it excludes `@boboko/core` from dependency pre-bundling (otherwise Vite serves a stale cached copy after you edit core), pre-bundles `leaflet`/`@hotwired/stimulus` explicitly, and turns on `resolve.preserveSymlinks` and `server.watch.followSymlinks` so bare imports resolve from the consumer's `node_modules` and core edits trigger HMR. All of it is a harmless no-op against a real installed copy in repo mode. +## Translations added in the UI + +Default translation lines ship in core's seeders (`StorefrontTranslationsSeeder`, `CheckoutTranslationsSeeder`, `ValidationTranslationsSeeder`), which every app runs on boot and which only ever add missing keys. Lines added while building a storefront usually start in the Filament Language Lines UI instead. To move them into core: + +```bash +bin/dc-core.sh exec app php artisan boboko:translations:pull # local mode: writes into ../boboko-core +bin/dc exec app php artisan boboko:translations:pull --dry-run # any mode: just list them +``` + +It adds every `storefront` / `checkout` / `validation` key that's in the database but not in the matching seeder, appended at the end of `lines()` under a marker comment — move them into the right section before committing. Keys the seeder already has are never touched, even if their text was edited in the UI. `bin/deploy` runs it for you. + ## Releasing a version 1. Bump `"version"` in **both** `composer.json` and `package.json` — they must match. @@ -122,9 +133,10 @@ A tag alone changes nothing in production — each consumer app has to pick it u Production only ever runs what the app's **committed lockfiles** pin. Each consumer app ships `bin/deploy`, which: 1. Refuses to run on the wrong branch, with uncommitted changes (other than the core wiring files), or behind `origin`. -2. Runs `bin/core-mode repo` — switching from local mode if needed, restarting either way — so both lockfiles resolve the newest `0.x` tag. It warns if `../boboko-core` has a newer tag than what resolved (usually an unpushed tag). -3. Commits the lockfile bump (`Chore: Bumping boboko/core to X.Y.Z`) if there is one, shows what will be pushed, and asks for confirmation. -4. Pushes, then runs `vendor/bin/envoy run deploy` against the host in `.env.envoy`. +2. Runs `php artisan boboko:translations:pull` (see [Translations added in the UI](#translations-added-in-the-ui)). In local mode, if it pulls any lines into `../boboko-core`, it stops — commit, tag and push core, then rerun. In repo mode it only checks, and stops if the database has lines core doesn't. +3. Runs `bin/core-mode repo` — switching from local mode if needed, restarting either way — so both lockfiles resolve the newest `0.x` tag. It warns if `../boboko-core` has a newer tag than what resolved (usually an unpushed tag). +4. Commits the lockfile bump (`Chore: Bumping boboko/core to X.Y.Z`) if there is one, shows what will be pushed, and asks for confirmation. +5. Pushes, then runs `vendor/bin/envoy run deploy` against the host in `.env.envoy`. Envoy (`Envoy.blade.php`) then, on the server: `git reset --hard` + `git pull`, `docker compose build` (the `production` image target runs `composer install --no-dev` and `npm ci` from the committed lockfiles — this is where the core tag actually lands), `up -d`, caches config/routes/events, restarts `queue` and `scheduler`, and regenerates Stoic thumbnails. The production entrypoint skips Composer entirely and runs migrations (including core's), seeders, the Meilisearch sync, and `artisan optimize`. From ebf8fd75715f981a2ca4871a16a5ca198054441e Mon Sep 17 00:00:00 2001 From: Konstantinos Arvanitakis Date: Wed, 30 Sep 2026 12:11:12 +0300 Subject: [PATCH 13/13] Bump version to 0.28.0 --- CHANGELOG.md | 21 +++++++++++++++++++++ composer.json | 2 +- package.json | 2 +- 3 files changed, 23 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 8740811..b30b9b9 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,27 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/). +## [0.28.0] - 2026-09-30 +### Added +- `php artisan boboko:translations:pull` — the reverse of the translation + seeders: copies `storefront` / `checkout` / `validation` lines that exist in + the database (e.g. added through the Filament Language Lines UI while + building a storefront) but not in the matching seeder into that seeder's + `lines()`, appended under a marker comment. Keys a seeder already has are + never touched. Writes only against a local `../boboko-core` checkout (local + mode); `--dry-run` lists the lines from anywhere. +- Storefront translations for error pages: `storefront.errors.404_title`, + `storefront.errors.404_text`, `storefront.errors.back_home`. Re-run + `StorefrontTranslationsSeeder` in consuming apps (or restart the stack) to + add them. + +### Changed +- `CONTRIBUTE.md` rewritten to match the actual setup: the local/repo modes + and the `bin/core-mode` switch, `@boboko/core` as a real npm package (the + old "no separate npm package" section was stale), releasing a version, + deploying a consumer app with `bin/deploy`, and pulling UI-added + translations into the seeders. + ## [0.27.5] - 2026-09-30 ### Security - OTP codes (both customer login via `UserOtpService` and staff login via diff --git a/composer.json b/composer.json index c374fe5..8f2fd0b 100644 --- a/composer.json +++ b/composer.json @@ -2,7 +2,7 @@ "name": "boboko/core", "description": "Core module — authentication and shared panel behaviour", "type": "library", - "version": "0.27.5", + "version": "0.28.0", "autoload": { "psr-4": { "Modules\\Core\\": "src/" diff --git a/package.json b/package.json index 42e91c1..eb0e7a0 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@boboko/core", - "version": "0.27.5", + "version": "0.28.0", "private": true, "type": "module", "description": "Portable Stimulus controllers and styles for boboko-core's cart + checkout module. Installed as a real npm dependency (file:../boboko-core in dev, a tagged git install in prod) so a consuming app's `npm install` resolves this package's own dependencies (leaflet, @hotwired/stimulus) transitively, the same way `composer update boboko/*` does for PHP. See CONTRIBUTE.md's \"JS/CSS: a real npm package\" section.",