Scaffold Symfony 8 app with Bootstrap/DataTables and Docker stack

- Symfony 8.1 webapp skeleton on PHP 8.5 (AssetMapper/importmap, no Node)
- Form-login gate: User entity, security.yaml, SecurityController,
  app:user:create command, initial migration (user + messenger_messages)
- Bootstrap 5 + DataTables layout (base/login/home templates); any
  table.datatable is auto-initialised
- trusted_proxies/headers wired for the shared Nginx Proxy Manager
- Docker (servers only): docker-compose.yml (php:8.5-fpm-alpine,
  nginx:1.30-alpine, mariadb:12.3; host ports 8085/3310; external
  docker_default network) + docker/{Dockerfile,php.ini,nginx,setup.sh,restart.sh}
- .env with CHANGEME placeholders (no secrets), .gitattributes enforces
  LF so the deploy scripts stay runnable on Linux

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Frank
2026-09-06 14:11:36 +02:00
co-authored by Claude Sonnet 5
parent 39240a98ec
commit 9f6763040e
74 changed files with 14050 additions and 1 deletions
+10
View File
@@ -0,0 +1,10 @@
.git
.gitignore
.idea
var/
vendor/
node_modules/
.env.local
.env.*.local
docker-compose.yml
README.md
+17
View File
@@ -0,0 +1,17 @@
# editorconfig.org
root = true
[*]
charset = utf-8
end_of_line = lf
indent_size = 4
indent_style = space
insert_final_newline = true
trim_trailing_whitespace = true
[{compose.yaml,compose.*.yaml}]
indent_size = 2
[*.md]
trim_trailing_whitespace = false
+60
View File
@@ -0,0 +1,60 @@
# In all environments, the following files are loaded if they exist,
# the latter taking precedence over the former:
#
# * .env contains default values for the environment variables needed by the app
# * .env.local uncommitted file with local overrides
# * .env.$APP_ENV committed environment-specific defaults
# * .env.$APP_ENV.local uncommitted environment-specific overrides
#
# Real environment variables win over .env files.
#
# DO NOT DEFINE PRODUCTION SECRETS IN THIS FILE NOR IN ANY OTHER COMMITTED FILES.
# https://symfony.com/doc/current/configuration/secrets.html
#
# Run "composer dump-env prod" to compile .env files for production use (requires symfony/flex >=1.2).
# https://symfony.com/doc/current/best_practices.html#use-environment-variables-for-infrastructure-configuration
###> symfony/framework-bundle ###
# Committed default is the server (prod) profile. On the dev box, override in
# .env.local: APP_ENV=dev, a real APP_SECRET, and a local DATABASE_URL.
APP_ENV=prod
APP_SECRET=
APP_SHARE_DIR=var/share
# CIDR ranges the Nginx Proxy Manager / Docker network live in (loopback +
# RFC1918). Lets Symfony trust X-Forwarded-* from the reverse proxy.
TRUSTED_PROXIES=127.0.0.1,10.0.0.0/8,172.16.0.0/12,192.168.0.0/16
###< symfony/framework-bundle ###
###> symfony/routing ###
# Configure how to generate URLs in non-HTTP contexts, such as CLI commands.
# See https://symfony.com/doc/current/routing.html#generating-urls-in-commands
DEFAULT_URI=https://dmtools.fvandenberg.nl
###< symfony/routing ###
###> doctrine/doctrine-bundle ###
# Format described at https://www.doctrine-project.org/projects/doctrine-dbal/en/latest/reference/configuration.html#connecting-using-a-url
#
# In Docker (servers) the host is the `database` service and these parts come
# from docker-compose.yml / .env.local. On the dev box, point DATABASE_URL at
# your local MariaDB in .env.local, e.g.:
# DATABASE_URL="mysql://root:@127.0.0.1:3306/dmtools?serverVersion=10.10.2-MariaDB&charset=utf8mb4"
DB_HOST=database
DB_PORT=3306
DB_NAME=dmtools
DB_USER=dmtools
DB_PASSWORD=ChangeMe
DB_ROOT_PASSWORD=ChangeMeRoot
DB_SERVER_VERSION=mariadb-12.3.2
DATABASE_URL="mysql://${DB_USER}:${DB_PASSWORD}@${DB_HOST}:${DB_PORT}/${DB_NAME}?serverVersion=${DB_SERVER_VERSION}&charset=utf8mb4"
###< doctrine/doctrine-bundle ###
###> symfony/messenger ###
# Choose one of the transports below
# MESSENGER_TRANSPORT_DSN=amqp://guest:guest@localhost:5672/%2f/messages
# MESSENGER_TRANSPORT_DSN=redis://localhost:6379/messages
MESSENGER_TRANSPORT_DSN=doctrine://default?auto_setup=0
###< symfony/messenger ###
###> symfony/mailer ###
MAILER_DSN=null://null
###< symfony/mailer ###
+4
View File
@@ -0,0 +1,4 @@
###> symfony/framework-bundle ###
APP_SECRET=6aa12054a217aa12c9be49a4c9de3774
###< symfony/framework-bundle ###
+3
View File
@@ -0,0 +1,3 @@
# define your env variables for the test env here
KERNEL_CLASS='App\Kernel'
APP_SECRET='$ecretf0rt3st'
+20
View File
@@ -0,0 +1,20 @@
# Normalise everything to LF in the repo (and in working trees). Keeps the
# Docker shell scripts runnable on the Linux servers regardless of the OS a
# commit was made from. Matches .editorconfig (end_of_line = lf).
* text=auto eol=lf
*.sh text eol=lf
/bin/console text eol=lf
/bin/phpunit text eol=lf
# Binaries - never touch.
*.png binary
*.jpg binary
*.jpeg binary
*.gif binary
*.ico binary
*.woff binary
*.woff2 binary
*.ttf binary
*.eot binary
*.pdf binary
+23
View File
@@ -0,0 +1,23 @@
###> symfony/framework-bundle ###
/.env.local
/.env.local.php
/.env.*.local
/config/secrets/prod/prod.decrypt.private.php
/public/bundles/
/var/
/vendor/
###< symfony/framework-bundle ###
###> phpunit/phpunit ###
/phpunit.xml
/.phpunit.cache/
###< phpunit/phpunit ###
###> symfony/asset-mapper ###
/public/assets/
/assets/vendor/
###< symfony/asset-mapper ###
# JetBrains IDE metadata (local, machine-specific)
/.idea/
+1
View File
@@ -0,0 +1 @@
8.5
+108
View File
@@ -0,0 +1,108 @@
# AGENTS.md
This is a Symfony project. Check `composer.json` for the exact Symfony/PHP version
in use, and read `symfony.lock` to see which recipes ran. Don't assume Doctrine,
Twig, API Platform, Messenger, or Lock are installed unless one of those says so.
## Ask before generating
If the task doesn't specify, ask rather than guess:
- Persistence: Doctrine ORM, Doctrine ODM, or none?
- Interface: server-rendered (Twig), API (Serializer, maybe API Platform), or both?
- Auth: SecurityBundle, and which authenticator?
If you can't ask (no interactive channel), state the assumption you're making and
pick the smallest option (e.g. no persistence layer) rather than scaffolding a
full stack nobody asked for.
## Adding features: Flex, not hand-wiring
Install new capabilities with `composer require <package>` (e.g. `symfony/lock`,
`symfony/messenger`, `orm-pack`) and let the Flex recipe register the bundle and
generate its config. Don't hand-edit `config/bundles.php` or hand-write a bundle's
base config; that's what the recipe is for. Don't skip a good-fit component just
because it isn't installed yet; installing it is one command.
## Conventions
Follow https://symfony.com/doc/current/best_practices.html to write idiomatic
Symfony:
- Use PHP attributes for framework metadata, and not only on controllers:
`#[Route]`, `#[MapRequestPayload]`, `#[IsGranted]` on actions, `#[Assert\...]`
on properties, `#[AsCommand]`, `#[AsEventListener]`, `#[AsMessageHandler]`, and
`#[AsAlias]` / `#[AsTaggedItem]` / `#[Autoconfigure]` on services. No YAML or
XML routing.
- Rely on autowiring and autoconfiguration. Type-hint constructor arguments and
let the container resolve them. Where a type-hint can't express it, stay in the
class with `#[Autowire]` (parameters, env vars, expressions) or `#[Target]` (one
of several implementations of an interface). A YAML service definition is the
last resort, not the first.
- Controllers extend `AbstractController`, stay thin, and delegate to services.
- Use the framework for what it already does: Form for server-rendered forms,
Validator for validation, Serializer for JSON, Messenger for async work,
Security (voters, authenticators) for access control, Twig `path()`/`url()`
instead of hardcoded URLs.
- Before hand-writing infrastructure (locks, queues, caches, HTTP clients,
mailers, schedulers) or reaching for a third-party library, check whether a
Symfony component covers it. It usually does.
Three specifics worth spelling out, because they are easy to get wrong:
- Bind request data with `#[MapRequestPayload]` / `#[MapQueryString]` on action
arguments, which wires up Serializer and Validator for you, instead of calling
`json_decode()` or `SerializerInterface` by hand. If neither package is
installed yet, `composer require` them rather than falling back to manual
parsing.
- Use constructor property promotion, and `readonly` for DTOs and value objects.
Don't mark a service `readonly` if it might become `lazy: true`: a lazy proxy
can't extend a `readonly` class.
- Use `symfony/lock` (`LockFactory`) for mutual exclusion. A hand-built flag or
lock file looks fine in review and is usually wrong under concurrency.
## Everyday workflow
- Run the app with `symfony serve -d`, and commands with `symfony console ...`
(or `bin/console` when the Symfony CLI isn't available).
- When something fails, read `var/log/dev.log` and the web profiler
(`/_profiler`) before changing code.
- If `maker-bundle` is installed, prefer `bin/console make:*` with every argument
passed up front and `--no-interaction` where supported: makers prompt on a
terminal by default, which hangs a non-interactive shell. If a maker still
needs interactive input, hand-write the code instead.
- If Doctrine ORM is installed, schema changes go through migrations
(`bin/console make:migration`, then `doctrine:migrations:migrate`), never
`doctrine:schema:update` or hand-written SQL.
- `.env` is committed and holds defaults only. Real secrets belong in `.env.local`
(git-ignored) or the secrets vault (`bin/console secrets:set`), read via
`%env(...)%`.
## Testing
Install `symfony/test-pack` if it isn't already. Functional/HTTP tests extend
`WebTestCase`; service-level tests extend `KernelTestCase`. Run
`php bin/phpunit` (falls back to `vendor/bin/phpunit`). A feature isn't done
until it has a test that exercises it the way a caller would, an HTTP request for
a controller or a service call for a service, not just "it didn't throw."
## Code style
Symfony's coding standard, the `@Symfony` php-cs-fixer ruleset (a PSR-12-derived
superset). Run `vendor/bin/php-cs-fixer fix` if `friendsofphp/php-cs-fixer` is
installed; it isn't part of the skeleton by default.
## Discover, don't guess
Framework APIs change between versions and your training data may be stale. Look
things up in the project instead of relying on memory:
- `bin/console about`: versions, environment, paths.
- `bin/console debug:router`, `debug:container`, `debug:autowiring <name>`,
`debug:config <bundle>`, `config:dump-reference <bundle>`: what exists and how
it is configured.
- `bin/console lint:container`, plus `lint:twig templates/` and
`lint:yaml config/` where those packages are installed: validate before running.
- Read the installed source and docblocks under `vendor/`.
- Docs: https://symfony.com/doc/current/ (switch to the version matching
`composer.json` if it differs).
+3
View File
@@ -0,0 +1,3 @@
# CLAUDE.md
@AGENTS.md
+83 -1
View File
@@ -1,3 +1,85 @@
# dmtools # dmtools
DM tools for the monday evening campaign DM tools for the Monday-evening D&D campaign.
Symfony 8 (PHP 8.5) web app with a Bootstrap 5 + DataTables front end served
through Symfony AssetMapper (no Node build step). Behind a form-login gate; there
is no self-registration.
- **Not** run in Docker locally (Windows dev box uses the Symfony CLI + local
MariaDB).
- **Is** Dockerized on the testing and live servers, behind the shared Nginx
Proxy Manager at `https://dmtools.fvandenberg.nl`.
Repo: <https://gitea.fvandenberg.nl/Frank/dmtools.git>
---
## Local development (dev box)
Prerequisites: PHP 8.5 at `C:\php` (on `PATH` so the Symfony CLI discovers it —
`symfony local:php:list` should show 8.5), the Symfony CLI, Composer, and a local
MariaDB/MySQL (WAMP is fine). `.php-version` pins this directory to PHP 8.5.
```bash
# 1. Point the app at your local database + dev mode
cp .env .env.local
# then edit .env.local:
# APP_ENV=dev
# DATABASE_URL="mysql://root:@127.0.0.1:3306/dmtools?serverVersion=10.10.2-MariaDB&charset=utf8mb4"
# 2. Install and build
symfony composer install
symfony console doctrine:database:create
symfony console doctrine:migrations:migrate -n
symfony console importmap:install
# 3. First user, then run
symfony console app:user:create you@example.com --admin
symfony serve -d
symfony open:local
```
`serverVersion` must match your local engine (`SELECT VERSION();`).
## Servers (testing + live)
Docker only. `docker/setup.sh` pins the compose project name to `dmtools`
(containers `dmtools-php`, `dmtools-nginx`, `dmtools-db`).
```bash
git pull
cp .env .env.local # first time only
# edit .env.local: real APP_SECRET (or let setup.sh generate it),
# DB_PASSWORD, DB_ROOT_PASSWORD, and NGINX_PORT / DB_PORT if 8085 / 3310 clash
./docker/setup.sh
docker compose -p dmtools exec php php bin/console app:user:create you@example.com --admin
```
Ports (bound to `127.0.0.1` on the host): nginx `8085` → `:80`, db `3310` → `:3306`.
### Reverse proxy (Nginx Proxy Manager)
Add a proxy host: `dmtools.fvandenberg.nl` → forward to host `dmtools-nginx`,
port `80`, scheme `http`; request a Let's Encrypt certificate. NPM and
`dmtools-nginx` must share the external `docker_default` Docker network (the
compose file attaches nginx to it as `proxy`).
### Common commands
```bash
docker compose -p dmtools logs -f php
docker compose -p dmtools exec php bash
docker compose -p dmtools exec php php bin/console doctrine:migrations:migrate
./docker/restart.sh # full down + bring-up (no rebuild)
./docker/setup.sh --down # stop the stack
```
## Layout notes
- `table.datatable` in any Twig template is auto-initialised as a DataTable
(`assets/app.js`). Opt out with `data-datatable="false"`; pass options as JSON
in `data-datatable-options`.
- `assets/vendor/` and `public/assets/` are generated (git-ignored);
`importmap:install` on the server re-downloads vendored packages, so the
servers need outbound HTTPS to jsDelivr at deploy time.
+36
View File
@@ -0,0 +1,36 @@
/*
* dmtools front-end entrypoint (Symfony AssetMapper / importmap).
* Loaded from base.html.twig via {{ importmap('app') }}.
*/
import './stimulus_bootstrap.js';
import 'bootstrap/dist/css/bootstrap.min.css';
import 'datatables.net-bs5/css/dataTables.bootstrap5.min.css';
import './styles/app.css';
import * as bootstrap from 'bootstrap';
import DataTable from 'datatables.net-bs5';
window.bootstrap = bootstrap;
// Turn any <table class="datatable"> into a DataTable. Opt out per-table with
// data-datatable="false"; pass options as a JSON object in data-datatable-options.
function initDataTables(root = document) {
root.querySelectorAll('table.datatable').forEach((table) => {
if (table.dataset.datatable === 'false' || DataTable.isDataTable(table)) {
return;
}
let options = { pageLength: 25, order: [] };
if (table.dataset.datatableOptions) {
try {
options = { ...options, ...JSON.parse(table.dataset.datatableOptions) };
} catch (e) {
console.error('Invalid data-datatable-options on', table, e);
}
}
new DataTable(table, options);
});
}
document.addEventListener('DOMContentLoaded', () => initDataTables());
document.addEventListener('turbo:load', () => initDataTables());
+18
View File
@@ -0,0 +1,18 @@
{
"controllers": {
"@symfony/ux-turbo": {
"turbo-core": {
"enabled": true,
"fetch": "eager",
"autoimport": {
"@symfony/ux-turbo/dist/mercure_stream_source_element.js": true
}
},
"mercure-turbo-stream": {
"enabled": false,
"fetch": "eager"
}
}
},
"entrypoints": []
}
@@ -0,0 +1,81 @@
const nameCheck = /^[-_a-zA-Z0-9]{4,22}$/;
const tokenCheck = /^[-_/+a-zA-Z0-9]{24,}$/;
// Generate and double-submit a CSRF token in a form field and a cookie, as defined by Symfony's SameOriginCsrfTokenManager
// Use `form.requestSubmit()` to ensure that the submit event is triggered. Using `form.submit()` will not trigger the event
// and thus this event-listener will not be executed.
document.addEventListener('submit', function (event) {
generateCsrfToken(event.target);
}, true);
// When @hotwired/turbo handles form submissions, send the CSRF token in a header in addition to a cookie
// The `framework.csrf_protection.check_header` config option needs to be enabled for the header to be checked
document.addEventListener('turbo:submit-start', function (event) {
const h = generateCsrfHeaders(event.detail.formSubmission.formElement);
Object.keys(h).map(function (k) {
event.detail.formSubmission.fetchRequest.headers[k] = h[k];
});
});
// When @hotwired/turbo handles form submissions, remove the CSRF cookie once a form has been submitted
document.addEventListener('turbo:submit-end', function (event) {
removeCsrfToken(event.detail.formSubmission.formElement);
});
export function generateCsrfToken (formElement) {
const csrfField = formElement.querySelector('input[data-controller="csrf-protection"], input[name="_csrf_token"]');
if (!csrfField) {
return;
}
let csrfCookie = csrfField.getAttribute('data-csrf-protection-cookie-value');
let csrfToken = csrfField.value;
if (!csrfCookie && nameCheck.test(csrfToken)) {
csrfField.setAttribute('data-csrf-protection-cookie-value', csrfCookie = csrfToken);
csrfField.defaultValue = csrfToken = btoa(String.fromCharCode.apply(null, (window.crypto || window.msCrypto).getRandomValues(new Uint8Array(18))));
}
csrfField.dispatchEvent(new Event('change', { bubbles: true }));
if (csrfCookie && tokenCheck.test(csrfToken)) {
const cookie = csrfCookie + '_' + csrfToken + '=' + csrfCookie + '; path=/; samesite=strict';
document.cookie = window.location.protocol === 'https:' ? '__Host-' + cookie + '; secure' : cookie;
}
}
export function generateCsrfHeaders (formElement) {
const headers = {};
const csrfField = formElement.querySelector('input[data-controller="csrf-protection"], input[name="_csrf_token"]');
if (!csrfField) {
return headers;
}
const csrfCookie = csrfField.getAttribute('data-csrf-protection-cookie-value');
if (tokenCheck.test(csrfField.value) && nameCheck.test(csrfCookie)) {
headers[csrfCookie] = csrfField.value;
}
return headers;
}
export function removeCsrfToken (formElement) {
const csrfField = formElement.querySelector('input[data-controller="csrf-protection"], input[name="_csrf_token"]');
if (!csrfField) {
return;
}
const csrfCookie = csrfField.getAttribute('data-csrf-protection-cookie-value');
if (tokenCheck.test(csrfField.value) && nameCheck.test(csrfCookie)) {
const cookie = csrfCookie + '_' + csrfField.value + '=0; path=/; samesite=strict; max-age=0';
document.cookie = window.location.protocol === 'https:' ? '__Host-' + cookie + '; secure' : cookie;
}
}
/* stimulusFetch: 'lazy' */
export default 'csrf-protection-controller';
+16
View File
@@ -0,0 +1,16 @@
import { Controller } from '@hotwired/stimulus';
/*
* This is an example Stimulus controller!
*
* Any element with a data-controller="hello" attribute will cause
* this controller to be executed. The name "hello" comes from the filename:
* hello_controller.js -> "hello"
*
* Delete this file or adapt it for your use!
*/
export default class extends Controller {
connect() {
this.element.textContent = 'Hello Stimulus! Edit me in assets/controllers/hello_controller.js';
}
}
+5
View File
@@ -0,0 +1,5 @@
import { startStimulusApp } from '@symfony/stimulus-bundle';
const app = startStimulusApp();
// register any custom, 3rd party controllers here
// app.register('some_controller_name', SomeImportedController);
+25
View File
@@ -0,0 +1,25 @@
/* dmtools project styles. Bootstrap + DataTables (bs5) are imported from app.js. */
body {
min-height: 100vh;
}
main.app-main {
padding-top: 1.5rem;
padding-bottom: 3rem;
}
.navbar-brand {
font-weight: 600;
letter-spacing: 0.02em;
}
.login-card {
max-width: 24rem;
margin: 8vh auto 0;
}
/* Let DataTables' controls breathe inside a Bootstrap card. */
table.dataTable {
width: 100% !important;
}
Executable
+21
View File
@@ -0,0 +1,21 @@
#!/usr/bin/env php
<?php
use App\Kernel;
use Symfony\Bundle\FrameworkBundle\Console\Application;
if (!is_dir(dirname(__DIR__).'/vendor')) {
throw new LogicException('Dependencies are missing. Try running "composer install".');
}
if (!is_file(dirname(__DIR__).'/vendor/autoload_runtime.php')) {
throw new LogicException('Symfony Runtime is missing. Try running "composer require symfony/runtime".');
}
require_once dirname(__DIR__).'/vendor/autoload_runtime.php';
return function (array $context) {
$kernel = new Kernel($context['APP_ENV'], (bool) $context['APP_DEBUG']);
return new Application($kernel);
};
Executable
+4
View File
@@ -0,0 +1,4 @@
#!/usr/bin/env php
<?php
require dirname(__DIR__).'/vendor/phpunit/phpunit/phpunit';
+114
View File
@@ -0,0 +1,114 @@
{
"name": "frank/dmtools",
"description": "DM tools for the Monday-evening D&D campaign",
"type": "project",
"license": "proprietary",
"minimum-stability": "stable",
"prefer-stable": true,
"require": {
"php": ">=8.4",
"ext-ctype": "*",
"ext-iconv": "*",
"doctrine/doctrine-bundle": "^3.3",
"doctrine/doctrine-migrations-bundle": "^4.0",
"doctrine/orm": "^3.6",
"phpdocumentor/reflection-docblock": "^6.0",
"phpstan/phpdoc-parser": "^2.3",
"symfony/asset": "8.1.*",
"symfony/asset-mapper": "8.1.*",
"symfony/console": "8.1.*",
"symfony/doctrine-messenger": "8.1.*",
"symfony/dotenv": "8.1.*",
"symfony/expression-language": "8.1.*",
"symfony/flex": "^2",
"symfony/form": "8.1.*",
"symfony/framework-bundle": "8.1.*",
"symfony/http-client": "8.1.*",
"symfony/intl": "8.1.*",
"symfony/mailer": "8.1.*",
"symfony/mime": "8.1.*",
"symfony/monolog-bundle": "^3.0|^4.0",
"symfony/notifier": "8.1.*",
"symfony/process": "8.1.*",
"symfony/property-access": "8.1.*",
"symfony/property-info": "8.1.*",
"symfony/runtime": "8.1.*",
"symfony/security-bundle": "8.1.*",
"symfony/serializer": "8.1.*",
"symfony/stimulus-bundle": "^3.4",
"symfony/string": "8.1.*",
"symfony/translation": "8.1.*",
"symfony/twig-bundle": "8.1.*",
"symfony/ux-turbo": "^3.4",
"symfony/validator": "8.1.*",
"symfony/web-link": "8.1.*",
"symfony/yaml": "8.1.*",
"twig/extra-bundle": "^2.12|^3.0",
"twig/twig": "^2.12|^3.0"
},
"config": {
"allow-plugins": {
"php-http/discovery": true,
"symfony/flex": true,
"symfony/runtime": true
},
"bump-after-update": true,
"sort-packages": true,
"platform": {
"php": "8.5"
}
},
"autoload": {
"psr-4": {
"App\\": "src/"
}
},
"autoload-dev": {
"psr-4": {
"App\\Tests\\": "tests/"
}
},
"replace": {
"symfony/polyfill-ctype": "*",
"symfony/polyfill-iconv": "*",
"symfony/polyfill-php72": "*",
"symfony/polyfill-php73": "*",
"symfony/polyfill-php74": "*",
"symfony/polyfill-php80": "*",
"symfony/polyfill-php81": "*",
"symfony/polyfill-php82": "*",
"symfony/polyfill-php83": "*",
"symfony/polyfill-php84": "*"
},
"scripts": {
"auto-scripts": {
"cache:clear": "symfony-cmd",
"assets:install %PUBLIC_DIR%": "symfony-cmd",
"importmap:install": "symfony-cmd"
},
"post-install-cmd": [
"@auto-scripts"
],
"post-update-cmd": [
"@auto-scripts"
]
},
"conflict": {
"symfony/symfony": "*"
},
"extra": {
"symfony": {
"allow-contrib": false,
"require": "8.1.*"
}
},
"require-dev": {
"phpunit/phpunit": "^13.3",
"symfony/browser-kit": "8.1.*",
"symfony/css-selector": "8.1.*",
"symfony/debug-bundle": "8.1.*",
"symfony/maker-bundle": "^1.0",
"symfony/stopwatch": "8.1.*",
"symfony/web-profiler-bundle": "8.1.*"
}
}
Generated
+10118
View File
File diff suppressed because it is too large Load Diff
+16
View File
@@ -0,0 +1,16 @@
<?php
return [
Symfony\Bundle\FrameworkBundle\FrameworkBundle::class => ['all' => true],
Doctrine\Bundle\DoctrineBundle\DoctrineBundle::class => ['all' => true],
Doctrine\Bundle\MigrationsBundle\DoctrineMigrationsBundle::class => ['all' => true],
Symfony\Bundle\DebugBundle\DebugBundle::class => ['dev' => true],
Symfony\Bundle\TwigBundle\TwigBundle::class => ['all' => true],
Symfony\Bundle\WebProfilerBundle\WebProfilerBundle::class => ['dev' => true, 'test' => true],
Symfony\UX\StimulusBundle\StimulusBundle::class => ['all' => true],
Symfony\UX\Turbo\TurboBundle::class => ['all' => true],
Twig\Extra\TwigExtraBundle\TwigExtraBundle::class => ['all' => true],
Symfony\Bundle\SecurityBundle\SecurityBundle::class => ['all' => true],
Symfony\Bundle\MonologBundle\MonologBundle::class => ['all' => true],
Symfony\Bundle\MakerBundle\MakerBundle::class => ['dev' => true],
];
+11
View File
@@ -0,0 +1,11 @@
framework:
asset_mapper:
# The paths to make available to the asset mapper.
paths:
- assets/
missing_import_mode: strict
when@prod:
framework:
asset_mapper:
missing_import_mode: warn
+19
View File
@@ -0,0 +1,19 @@
framework:
cache:
# Unique name of your app: used to compute stable namespaces for cache keys.
#prefix_seed: your_vendor_name/app_name
# The "app" cache stores to the filesystem by default.
# The data in this cache should persist between deploys.
# Other options include:
# Redis
#app: cache.adapter.redis
#default_redis_provider: redis://localhost
# APCu (not recommended with heavy random-write workloads as memory fragmentation can cause perf issues)
#app: cache.adapter.apcu
# Namespaced pools use the above "app" backend by default
#pools:
#my.dedicated.cache: null
+11
View File
@@ -0,0 +1,11 @@
# Enable stateless CSRF protection for forms and logins/logouts
framework:
form:
csrf_protection:
token_id: submit
csrf_protection:
stateless_token_ids:
- submit
- authenticate
- logout
+5
View File
@@ -0,0 +1,5 @@
when@dev:
debug:
# Forwards VarDumper Data clones to a centralized server allowing to inspect dumps on CLI or in your browser.
# See the "server:dump" command to start a new server.
dump_destination: "tcp://%env(VAR_DUMPER_SERVER)%"
+46
View File
@@ -0,0 +1,46 @@
doctrine:
dbal:
url: '%env(resolve:DATABASE_URL)%'
# IMPORTANT: You MUST configure your server version,
# either here or in the DATABASE_URL env var (see .env file)
#server_version: '16'
profiling_collect_backtrace: '%kernel.debug%'
orm:
validate_xml_mapping: true
naming_strategy: doctrine.orm.naming_strategy.underscore
identity_generation_preferences:
Doctrine\DBAL\Platforms\PostgreSQLPlatform: identity
auto_mapping: true
mappings:
App:
type: attribute
is_bundle: false
dir: '%kernel.project_dir%/src/Entity'
prefix: 'App\Entity'
alias: App
when@test:
doctrine:
dbal:
# "TEST_TOKEN" is typically set by ParaTest
dbname_suffix: '_test%env(default::TEST_TOKEN)%'
when@prod:
doctrine:
orm:
query_cache_driver:
type: pool
pool: doctrine.system_cache_pool
result_cache_driver:
type: pool
pool: doctrine.result_cache_pool
framework:
cache:
pools:
doctrine.result_cache_pool:
adapter: cache.app
doctrine.system_cache_pool:
adapter: cache.system
+6
View File
@@ -0,0 +1,6 @@
doctrine_migrations:
migrations_paths:
# namespace is arbitrary but should be different from App\Migrations
# as migrations classes should NOT be autoloaded
'DoctrineMigrations': '%kernel.project_dir%/migrations'
enable_profiler: false
+22
View File
@@ -0,0 +1,22 @@
# see https://symfony.com/doc/current/reference/configuration/framework.html
framework:
secret: '%env(APP_SECRET)%'
# Note that the session will be started ONLY if you read or write from it.
session: true
# dmtools runs behind the shared Nginx Proxy Manager on the servers, which
# terminates TLS and forwards over the Docker network. Trust the private
# ranges the proxy/containers live in, and honour its X-Forwarded-* headers
# so Symfony builds https:// URLs and detects the real client IP.
trusted_proxies: '%env(TRUSTED_PROXIES)%'
trusted_headers: ['x-forwarded-for', 'x-forwarded-host', 'x-forwarded-proto', 'x-forwarded-port', 'x-forwarded-prefix']
#esi: true
#fragments: true
when@test:
framework:
test: true
session:
storage_factory_id: session.storage.factory.mock_file
+3
View File
@@ -0,0 +1,3 @@
framework:
mailer:
dsn: '%env(MAILER_DSN)%'
+26
View File
@@ -0,0 +1,26 @@
framework:
messenger:
failure_transport: failed
transports:
# https://symfony.com/doc/current/messenger.html#transport-configuration
async:
dsn: '%env(MESSENGER_TRANSPORT_DSN)%'
retry_strategy:
max_retries: 3
multiplier: 2
failed: 'doctrine://default?queue_name=failed'
# sync: 'sync://'
default_bus: messenger.bus.default
buses:
messenger.bus.default: []
routing:
Symfony\Component\Mailer\Messenger\SendEmailMessage: async
Symfony\Component\Notifier\Message\ChatMessage: async
Symfony\Component\Notifier\Message\SmsMessage: async
# Route your messages to the transports
# 'App\Message\YourMessage': async
+55
View File
@@ -0,0 +1,55 @@
monolog:
channels: # To see all channels, run bin/console debug:autowiring logger
- deprecation # Deprecations are logged in the dedicated "deprecation" channel when it exists
when@dev:
monolog:
handlers:
main:
type: stream
path: "%kernel.logs_dir%/%kernel.environment%.log"
level: debug
channels: ["!event"]
console:
type: console
process_psr_3_messages: false
channels: ["!event", "!doctrine", "!console"]
when@test:
monolog:
handlers:
main:
type: fingers_crossed
action_level: error
handler: nested
excluded_http_codes: [404, 405]
channels: ["!event"]
nested:
type: stream
path: "%kernel.logs_dir%/%kernel.environment%.log"
level: debug
when@prod:
monolog:
handlers:
main:
type: fingers_crossed
action_level: error
handler: nested
excluded_http_codes: [404, 405]
channels: ["!deprecation"]
buffer_size: 50 # How many messages should be saved? Prevent memory leaks
nested:
type: stream
path: php://stderr
level: debug
formatter: monolog.formatter.json
console:
type: console
process_psr_3_messages: false
channels: ["!event", "!doctrine"]
deprecation:
type: stream
channels: [deprecation]
path: php://stderr
formatter: monolog.formatter.json
+12
View File
@@ -0,0 +1,12 @@
framework:
notifier:
chatter_transports:
texter_transports:
channel_policy:
# use chat/slack, chat/telegram, sms/twilio or sms/nexmo
urgent: ['email']
high: ['email']
medium: ['email']
low: ['email']
admin_recipients:
- { email: admin@example.com }
+3
View File
@@ -0,0 +1,3 @@
framework:
property_info:
with_constructor_extractor: true
+10
View File
@@ -0,0 +1,10 @@
framework:
router:
# Configure how to generate URLs in non-HTTP contexts, such as CLI commands.
# See https://symfony.com/doc/current/routing.html#generating-urls-in-commands
default_uri: '%env(DEFAULT_URI)%'
when@prod:
framework:
router:
strict_requirements: null
+46
View File
@@ -0,0 +1,46 @@
security:
# https://symfony.com/doc/current/security.html#registering-the-user-hashing-passwords
password_hashers:
Symfony\Component\Security\Core\User\PasswordAuthenticatedUserInterface: 'auto'
# https://symfony.com/doc/current/security.html#loading-the-user-the-user-provider
providers:
app_user_provider:
entity:
class: App\Entity\User
property: email
firewalls:
dev:
pattern: ^/(_(profiler|wdt)|assets)/
security: false
main:
lazy: true
provider: app_user_provider
form_login:
login_path: app_login
check_path: app_login
enable_csrf: true
default_target_path: app_home
logout:
path: app_logout
target: app_login
# Note: Only the *first* matching rule is applied
access_control:
- { path: ^/login$, roles: PUBLIC_ACCESS }
- { path: ^/, roles: IS_AUTHENTICATED_FULLY }
role_hierarchy:
ROLE_ADMIN: [ROLE_USER]
when@test:
security:
password_hashers:
# Password hashers are resource-intensive by design to ensure security.
# In tests, it's safe to reduce their cost to improve performance.
Symfony\Component\Security\Core\User\PasswordAuthenticatedUserInterface:
algorithm: auto
cost: 4 # Lowest possible value for bcrypt
time_cost: 3 # Lowest possible value for argon
memory_cost: 10 # Lowest possible value for argon
+5
View File
@@ -0,0 +1,5 @@
framework:
default_locale: en
translator:
default_path: '%kernel.project_dir%/translations'
providers:
+6
View File
@@ -0,0 +1,6 @@
twig:
file_name_pattern: '*.twig'
when@test:
twig:
strict_variables: true
+4
View File
@@ -0,0 +1,4 @@
# Enable stateless CSRF protection for forms and logins/logouts
framework:
csrf_protection:
check_header: true
+11
View File
@@ -0,0 +1,11 @@
framework:
validation:
# Enables validator auto-mapping support.
# For instance, basic validation constraints will be inferred from Doctrine's metadata.
#auto_mapping:
# App\Entity\: []
when@test:
framework:
validation:
not_compromised_password: false
+11
View File
@@ -0,0 +1,11 @@
when@dev:
web_profiler:
toolbar: true
framework:
profiler: true
when@test:
framework:
profiler:
collect: false
+5
View File
@@ -0,0 +1,5 @@
<?php
foreach (glob(dirname(__DIR__).'/var/cache/prod/*.preload.php') ?: [] as $file) {
require $file;
}
+1644
View File
File diff suppressed because it is too large Load Diff
+11
View File
@@ -0,0 +1,11 @@
# yaml-language-server: $schema=../vendor/symfony/routing/Loader/schema/routing.schema.json
# This file is the entry point to configure the routes of your app.
# Methods with the #[Route] attribute are automatically imported.
# See also https://symfony.com/doc/current/routing.html
# To list all registered routes, run the following command:
# bin/console debug:router
controllers:
resource: routing.controllers
+4
View File
@@ -0,0 +1,4 @@
when@dev:
_errors:
resource: '@FrameworkBundle/Resources/config/routing/errors.php'
prefix: /_error
+3
View File
@@ -0,0 +1,3 @@
_security_logout:
resource: security.route_loader.logout
type: service
+8
View File
@@ -0,0 +1,8 @@
when@dev:
web_profiler_wdt:
resource: '@WebProfilerBundle/Resources/config/routing/wdt.php'
prefix: /_wdt
web_profiler_profiler:
resource: '@WebProfilerBundle/Resources/config/routing/profiler.php'
prefix: /_profiler
+23
View File
@@ -0,0 +1,23 @@
# yaml-language-server: $schema=../vendor/symfony/dependency-injection/Loader/schema/services.schema.json
# This file is the entry point to configure your own services.
# Files in the packages/ subdirectory configure your dependencies.
# See also https://symfony.com/doc/current/service_container/import.html
# Put parameters here that don't need to change on each machine where the app is deployed
# https://symfony.com/doc/current/best_practices.html#use-parameters-for-application-configuration
parameters:
services:
# default configuration for services in *this* file
_defaults:
autowire: true # Automatically injects dependencies in your services.
autoconfigure: true # Automatically registers your services as commands, event subscribers, etc.
# makes classes in src/ available to be used as services
# this creates a service per class whose id is the fully-qualified class name
App\:
resource: '../src/'
# add more service definitions when explicit configuration is needed
# please note that last definitions always *replace* previous ones
+75
View File
@@ -0,0 +1,75 @@
# dmtools stack - servers only (testing + live). Not used locally.
#
# Reached only through the shared Nginx Proxy Manager, which terminates TLS for
# dmtools.fvandenberg.nl and forwards to the `nginx` container by name over the
# external `docker_default` network. Published host ports are bound to loopback
# for local curl / DB-client access on the server itself.
#
# Bring up with docker/setup.sh (pins the compose project name to `dmtools`).
services:
php:
build:
context: .
dockerfile: docker/php/Dockerfile
container_name: dmtools-php
env_file:
- path: .env
- path: .env.local
required: false
volumes:
- .:/var/www/html:cached
- php_var:/var/www/html/var
depends_on:
database:
condition: service_healthy
restart: unless-stopped
nginx:
image: nginx:1.30-alpine
container_name: dmtools-nginx
ports:
- "127.0.0.1:${NGINX_PORT:-8085}:80"
volumes:
- .:/var/www/html:ro
- ./docker/nginx/default.conf:/etc/nginx/conf.d/default.conf:ro
depends_on:
- php
networks:
- default
- proxy
restart: unless-stopped
database:
image: mariadb:12.3
container_name: dmtools-db
environment:
MARIADB_DATABASE: ${DB_NAME:-dmtools}
MARIADB_USER: ${DB_USER:-dmtools}
MARIADB_PASSWORD: ${DB_PASSWORD:-ChangeMe}
MARIADB_ROOT_PASSWORD: ${DB_ROOT_PASSWORD:-ChangeMeRoot}
command:
- --character-set-server=utf8mb4
- --collation-server=utf8mb4_unicode_ci
ports:
- "127.0.0.1:${DB_PORT:-3310}:3306"
volumes:
- database_data:/var/lib/mysql
healthcheck:
test: ["CMD", "healthcheck.sh", "--connect", "--innodb_initialized"]
interval: 10s
timeout: 5s
retries: 10
start_period: 30s
restart: unless-stopped
volumes:
database_data:
php_var:
networks:
# Pre-existing network the server's Nginx Proxy Manager uses to reach backend
# containers. Created outside this stack - must already exist on the host.
proxy:
name: docker_default
external: true
+55
View File
@@ -0,0 +1,55 @@
server {
listen 80;
# Only ever reached via the server's shared Nginx Proxy Manager, which
# terminates TLS and forwards traffic for this domain here - this container
# itself doesn't need to know about HTTPS or other domains.
server_name dmtools.fvandenberg.nl;
root /var/www/html/public;
location / {
try_files $uri /index.php$is_args$args;
}
location ~ ^/index\.php(/|$) {
# A plain "fastcgi_pass php:9000" resolves once at worker start and
# caches that IP forever - if the php container is recreated without
# also restarting nginx, every request 502s. Routing through a variable
# forces re-resolution per the resolver TTL. 127.0.0.11 is Compose's
# embedded DNS. Use the globally-unique container name, not the bare
# "php" alias: this nginx is also on the shared proxy network where
# another project may also have a service called "php".
resolver 127.0.0.11 valid=10s;
set $php_upstream dmtools-php:9000;
fastcgi_pass $php_upstream;
fastcgi_split_path_info ^(.+\.php)(/.*)$;
include fastcgi_params;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
fastcgi_param DOCUMENT_ROOT $document_root;
# fastcgi_params never forwards Host - forward the real one explicitly.
fastcgi_param HTTP_HOST $http_host;
# fastcgi_pass does NOT auto-forward incoming headers. Without these,
# Symfony can't tell the original request was HTTPS and redirects to
# itself forever. if_not_empty: NPM omits some of these entirely, and an
# empty-but-present header can behave differently from an absent one.
fastcgi_param HTTP_X_FORWARDED_PROTO $http_x_forwarded_proto if_not_empty;
fastcgi_param HTTP_X_FORWARDED_FOR $http_x_forwarded_for if_not_empty;
fastcgi_param HTTP_X_FORWARDED_HOST $http_x_forwarded_host if_not_empty;
fastcgi_param HTTP_X_FORWARDED_PORT $http_x_forwarded_port if_not_empty;
fastcgi_read_timeout 120;
internal;
}
# Everything else under public/ (compiled assets, favicon, robots) is served
# straight off disk; only index.php is ever executed.
location ~ \.php$ {
return 404;
}
error_log /var/log/nginx/dmtools_error.log;
access_log /var/log/nginx/dmtools_access.log;
client_max_body_size 20M;
}
+43
View File
@@ -0,0 +1,43 @@
FROM php:8.5-fpm-alpine
RUN apk add --no-cache \
bash \
git \
icu-dev \
libzip-dev \
zip \
unzip \
$PHPIZE_DEPS \
&& docker-php-ext-configure intl \
&& docker-php-ext-install -j"$(nproc)" \
intl \
pdo_mysql \
opcache \
zip \
&& apk del $PHPIZE_DEPS
COPY --from=composer:2 /usr/bin/composer /usr/bin/composer
COPY docker/php/php.ini /usr/local/etc/php/conf.d/app.ini
WORKDIR /var/www/html
COPY composer.json composer.lock symfony.lock ./
RUN composer install --no-interaction --no-scripts --no-autoloader --prefer-dist
COPY . .
RUN composer dump-autoload --optimize --classmap-authoritative
# var/ is a .dockerignore'd host concern and gets a named volume mounted over it
# at runtime; create + own it so php-fpm (www-data) can write cache/logs/sessions.
RUN mkdir -p var && chown -R www-data:www-data var
# /var/www/html is bind-mounted from the host at runtime, owned by whoever
# deployed it - keep git from refusing to touch it.
RUN git config --system --add safe.directory /var/www/html
USER www-data
EXPOSE 9000
CMD ["php-fpm"]
+20
View File
@@ -0,0 +1,20 @@
; dmtools - PHP-FPM runtime tuning (servers).
expose_php = Off
memory_limit = 256M
max_execution_time = 60
date.timezone = Europe/Amsterdam
upload_max_filesize = 20M
post_max_size = 21M
realpath_cache_size = 4096K
realpath_cache_ttl = 600
opcache.enable = 1
opcache.enable_cli = 0
opcache.memory_consumption = 128
opcache.max_accelerated_files = 20000
opcache.validate_timestamps = 0
opcache.preload_user = www-data
opcache.preload = /var/www/html/config/preload.php
+40
View File
@@ -0,0 +1,40 @@
#!/usr/bin/env bash
set -euo pipefail
# Fully restart the dmtools stack for this checkout (testing or live). Scoped to
# the compose project name, so running it from the test checkout never touches
# the prod stack.
#
# ./docker/restart.sh # down + rebuildless bring-up via setup.sh
# ./docker/restart.sh --prune-all # also run host-wide docker prune
DOCKER_DIR=$(cd "$(dirname "$0")" && pwd)
ROOT_DIR=$(cd "$DOCKER_DIR/.." && pwd)
PROJECT=dmtools
PRUNE_ALL=0
for arg in "$@"; do
case "$arg" in
--prune-all) PRUNE_ALL=1 ;;
*) echo "Unknown option: $arg" >&2; exit 1 ;;
esac
done
echo "Restarting stack: $PROJECT"
(cd "$ROOT_DIR" && docker compose -p "$PROJECT" -f docker-compose.yml down --remove-orphans) || true
docker rm -f dmtools-php dmtools-nginx dmtools-db 2>/dev/null || true
for net in $(docker network ls -q --filter "name=^${PROJECT}_" 2>/dev/null); do
docker network rm "$net" || true
done
if [ "$PRUNE_ALL" -eq 1 ]; then
echo "Host-wide prune..."
docker system prune -f || true
docker builder prune -af || true
else
echo "Skipping host-wide prune (pass --prune-all to force it)."
fi
echo "Running setup script..."
"$DOCKER_DIR/setup.sh" --no-build
+134
View File
@@ -0,0 +1,134 @@
#!/usr/bin/env bash
set -euo pipefail
# Bootstraps the Dockerized dmtools stack (php, nginx, database) on a server.
# - Builds and starts the containers
# - Installs composer dependencies
# - Ensures APP_SECRET is set (generated into .env.local if empty)
# - Creates and migrates the database
# - Installs + compiles AssetMapper assets
# - Prints helpful info on success
#
# Usage:
# ./docker/setup.sh # full setup
# ./docker/setup.sh --no-build # skip image rebuild
# ./docker/setup.sh --recreate # force-recreate containers
# ./docker/setup.sh --down # stop and remove containers
#
# NGINX_PORT=8086 ./docker/setup.sh # if 8085 is already taken on this host
# (or set NGINX_PORT / DB_PORT once in .env.local and every run picks it up)
ROOT_DIR=$(cd "$(dirname "$0")"/.. && pwd)
PROJECT=dmtools
for var in NGINX_PORT DB_PORT; do
if [ -z "${!var:-}" ] && grep -q "^${var}=" "$ROOT_DIR/.env.local" 2>/dev/null; then
export "$var=$(grep "^${var}=" "$ROOT_DIR/.env.local" | tail -1 | cut -d= -f2-)"
fi
done
if docker compose version >/dev/null 2>&1; then
DOCKER_COMPOSE="docker compose"
elif command -v docker-compose >/dev/null 2>&1; then
DOCKER_COMPOSE="docker-compose"
else
echo "Error: Docker Compose not found." >&2
exit 1
fi
dc() { (cd "$ROOT_DIR" && $DOCKER_COMPOSE -p "$PROJECT" -f docker-compose.yml "$@"); }
REBUILD=1
RECREATE=0
DOWN_ONLY=0
for arg in "$@"; do
case "$arg" in
--no-build) REBUILD=0 ;;
--recreate) RECREATE=1 ;;
--down) DOWN_ONLY=1 ;;
*) echo "Unknown option: $arg" >&2; exit 1 ;;
esac
done
command -v docker >/dev/null 2>&1 || { echo "Error: docker is required." >&2; exit 1; }
if [ ! -f "$ROOT_DIR/.env.local" ]; then
echo "Error: .env.local is missing. Copy .env to .env.local and set real" >&2
echo " APP_SECRET, DB_PASSWORD and DB_ROOT_PASSWORD first." >&2
exit 1
fi
if [ "$DOWN_ONLY" -eq 1 ]; then
dc down
exit 0
fi
# docker-compose v1 can choke recreating a container in place on any config
# change; removing them first sidesteps that. Safe: state lives in named volumes.
dc rm -fs php nginx database 2>/dev/null || true
BUILD_ARGS=()
[ "$REBUILD" -eq 1 ] && BUILD_ARGS+=("--build")
[ "$RECREATE" -eq 1 ] && BUILD_ARGS+=("--force-recreate")
dc up -d "${BUILD_ARGS[@]}"
# Setup one-offs run as root: the bind-mounted project dir is owned by the
# deploying user, not the image's www-data, so www-data can't write vendor/ etc.
pexec() { dc exec -T -u root php "$@"; }
printf "Waiting for database to be healthy..."
for i in {1..60}; do
id=$(dc ps -q database 2>/dev/null || true)
status=$([ -n "$id" ] && docker inspect -f '{{.State.Health.Status}}' "$id" 2>/dev/null || echo "")
if [ "$status" = "healthy" ]; then echo " OK"; break; fi
printf "."; sleep 2
[ "$i" -eq 60 ] && echo -e "\nWarning: database not healthy yet, continuing anyway."
done
pexec composer install --no-interaction
# Prod compiles config into a cached container under var/cache/prod/ (persistent
# php_var volume) and does NOT auto-detect config changes - clear it every run.
echo "Clearing and warming the cache..."
pexec php bin/console cache:clear --no-interaction
if grep -q '^APP_SECRET=$' "$ROOT_DIR/.env" 2>/dev/null \
&& ! grep -q '^APP_SECRET=' "$ROOT_DIR/.env.local" 2>/dev/null; then
echo "Generating APP_SECRET in .env.local..."
printf 'APP_SECRET=%s\n' "$(openssl rand -hex 16)" >> "$ROOT_DIR/.env.local"
dc up -d php # pick up the new env value
fi
echo "Creating database if it doesn't exist..."
pexec php bin/console doctrine:database:create --if-not-exists
echo "Running migrations..."
pexec php bin/console doctrine:migrations:migrate -n --allow-no-migration
echo "Installing and compiling assets..."
pexec php bin/console importmap:install
pexec php bin/console asset-map:compile
# LAST: the root-run commands above leave new files under var/ root-owned;
# php-fpm runs as www-data and must be able to write there at runtime.
pexec chown -R www-data:www-data var
APP_URL="http://localhost:${NGINX_PORT:-8085}"
cat <<EOT
Setup complete!
Open the app: $APP_URL (real access is via https://dmtools.fvandenberg.nl through NPM)
Create the first user:
$DOCKER_COMPOSE -p $PROJECT exec php php bin/console app:user:create you@example.com --admin
Common commands (from the project root):
$DOCKER_COMPOSE -p $PROJECT logs -f nginx
$DOCKER_COMPOSE -p $PROJECT logs -f php
$DOCKER_COMPOSE -p $PROJECT exec php bash
$DOCKER_COMPOSE -p $PROJECT down
Re-run this script any time. Use --no-build to skip rebuilding images.
EOT
+36
View File
@@ -0,0 +1,36 @@
<?php
/**
* Returns the importmap for this application.
*
* - "path" is a path inside the asset mapper system. Use the
* "debug:asset-map" command to see the full list of paths.
*
* - "entrypoint" (JavaScript only) set to true for any module that will
* be used as an "entrypoint" (and passed to the importmap() Twig function).
*
* The "importmap:require" command can be used to add new entries to this file.
*
* @return array<string, array{ // Import name as key, description of the imported file as value
* path: string, // Logical, relative or absolute path to the file
* type?: 'js'|'css'|'json', // Type of the file, defaults to 'js'
* entrypoint?: bool, // Whether the file is an entrypoint, for 'js' only
* }|array{
* version: string, // Version of the remote package
* package_specifier?: string, // Remote "package-name/path" specifier, defaults to the import name
* type?: 'js'|'css'|'json',
* entrypoint?: bool,
* }>
*/
return [
'app' => ['path' => './assets/app.js', 'entrypoint' => true],
'@hotwired/stimulus' => ['version' => '3.2.2'],
'@symfony/stimulus-bundle' => ['path' => './vendor/symfony/stimulus-bundle/assets/dist/loader.js'],
'@hotwired/turbo' => ['version' => '8.0.23'],
'bootstrap' => ['version' => '5.3.8'],
'@popperjs/core' => ['version' => '2.11.8'],
'datatables.net-bs5' => ['version' => '3.0.3'],
'datatables.net' => ['version' => '3.0.3'],
'bootstrap/dist/css/bootstrap.min.css' => ['version' => '5.3.8', 'type' => 'css'],
'datatables.net-bs5/css/dataTables.bootstrap5.min.css' => ['version' => '3.0.3', 'type' => 'css'],
];
View File
+31
View File
@@ -0,0 +1,31 @@
<?php
declare(strict_types=1);
namespace DoctrineMigrations;
use Doctrine\DBAL\Schema\Schema;
use Doctrine\Migrations\AbstractMigration;
/**
* Initial schema: `user` (form-login) and `messenger_messages` (async transport).
*/
final class Version20260906115952 extends AbstractMigration
{
public function getDescription(): string
{
return 'Initial schema: user and messenger_messages tables';
}
public function up(Schema $schema): void
{
$this->addSql('CREATE TABLE `user` (id INT AUTO_INCREMENT NOT NULL, email VARCHAR(180) NOT NULL, roles JSON NOT NULL, password VARCHAR(255) NOT NULL, UNIQUE INDEX UNIQ_8D93D649E7927C74 (email), PRIMARY KEY (id)) DEFAULT CHARACTER SET utf8mb4');
$this->addSql('CREATE TABLE messenger_messages (id BIGINT AUTO_INCREMENT NOT NULL, body LONGTEXT NOT NULL, headers LONGTEXT NOT NULL, queue_name VARCHAR(190) NOT NULL, created_at DATETIME NOT NULL, available_at DATETIME NOT NULL, delivered_at DATETIME DEFAULT NULL, INDEX IDX_75EA56E0FB7336F0E3BD61CE16BA31DBBF396750 (queue_name, available_at, delivered_at, id), PRIMARY KEY (id)) DEFAULT CHARACTER SET utf8mb4');
}
public function down(Schema $schema): void
{
$this->addSql('DROP TABLE `user`');
$this->addSql('DROP TABLE messenger_messages');
}
}
+44
View File
@@ -0,0 +1,44 @@
<?xml version="1.0" encoding="UTF-8"?>
<!-- https://phpunit.readthedocs.io/en/latest/configuration.html -->
<phpunit xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:noNamespaceSchemaLocation="vendor/phpunit/phpunit/phpunit.xsd"
colors="true"
failOnDeprecation="true"
failOnNotice="true"
failOnWarning="true"
bootstrap="tests/bootstrap.php"
cacheDirectory=".phpunit.cache"
>
<php>
<ini name="display_errors" value="1" />
<ini name="error_reporting" value="-1" />
<server name="APP_ENV" value="test" force="true" />
<server name="SHELL_VERBOSITY" value="-1" />
</php>
<testsuites>
<testsuite name="Project Test Suite">
<directory>tests</directory>
</testsuite>
</testsuites>
<source ignoreSuppressionOfDeprecations="true"
ignoreIndirectDeprecations="true"
restrictNotices="true"
restrictWarnings="true"
>
<include>
<directory>src</directory>
</include>
<deprecationTrigger>
<method>Doctrine\Deprecations\Deprecation::trigger</method>
<method>Doctrine\Deprecations\Deprecation::delegateTriggerToBackend</method>
<function>trigger_deprecation</function>
</deprecationTrigger>
</source>
<extensions>
</extensions>
</phpunit>
+9
View File
@@ -0,0 +1,9 @@
<?php
use App\Kernel;
require_once dirname(__DIR__).'/vendor/autoload_runtime.php';
return static function (array $context) {
return new Kernel($context['APP_ENV'], (bool) $context['APP_DEBUG']);
};
+84
View File
@@ -0,0 +1,84 @@
<?php
namespace App\Command;
use App\Entity\User;
use App\Repository\UserRepository;
use Doctrine\ORM\EntityManagerInterface;
use Symfony\Component\Console\Attribute\AsCommand;
use Symfony\Component\Console\Command\Command;
use Symfony\Component\Console\Input\InputArgument;
use Symfony\Component\Console\Input\InputInterface;
use Symfony\Component\Console\Input\InputOption;
use Symfony\Component\Console\Output\OutputInterface;
use Symfony\Component\Console\Style\SymfonyStyle;
use Symfony\Component\PasswordHasher\Hasher\UserPasswordHasherInterface;
use Symfony\Component\Validator\Validator\ValidatorInterface;
#[AsCommand(
name: 'app:user:create',
description: 'Create a dmtools user (there is no self-registration).',
)]
class CreateUserCommand extends Command
{
public function __construct(
private readonly EntityManagerInterface $em,
private readonly UserRepository $users,
private readonly UserPasswordHasherInterface $hasher,
private readonly ValidatorInterface $validator,
) {
parent::__construct();
}
protected function configure(): void
{
$this
->addArgument('email', InputArgument::REQUIRED, 'Login email')
->addArgument('password', InputArgument::OPTIONAL, 'Password (prompted if omitted)')
->addOption('admin', null, InputOption::VALUE_NONE, 'Grant ROLE_ADMIN');
}
protected function execute(InputInterface $input, OutputInterface $output): int
{
$io = new SymfonyStyle($input, $output);
$email = (string) $input->getArgument('email');
$password = $input->getArgument('password');
if (null === $password || '' === $password) {
$password = $io->askHidden('Password');
}
if (null === $password || '' === $password) {
$io->error('A password is required.');
return Command::FAILURE;
}
if ($this->users->findOneBy(['email' => $email])) {
$io->error(sprintf('A user with email "%s" already exists.', $email));
return Command::FAILURE;
}
$user = new User();
$user->setEmail($email);
$user->setRoles($input->getOption('admin') ? ['ROLE_ADMIN'] : []);
$user->setPassword($this->hasher->hashPassword($user, $password));
$violations = $this->validator->validate($user);
if (\count($violations) > 0) {
foreach ($violations as $violation) {
$io->error((string) $violation->getMessage());
}
return Command::FAILURE;
}
$this->em->persist($user);
$this->em->flush();
$io->success(sprintf('Created %s%s', $email, $input->getOption('admin') ? ' (admin)' : ''));
return Command::SUCCESS;
}
}
View File
+18
View File
@@ -0,0 +1,18 @@
<?php
namespace App\Controller;
use Symfony\Bundle\FrameworkBundle\Controller\AbstractController;
use Symfony\Component\HttpFoundation\Response;
use Symfony\Component\Routing\Attribute\Route;
use Symfony\Component\Security\Http\Attribute\IsGranted;
#[IsGranted('IS_AUTHENTICATED_FULLY')]
class HomeController extends AbstractController
{
#[Route('/', name: 'app_home')]
public function index(): Response
{
return $this->render('home/index.html.twig');
}
}
+30
View File
@@ -0,0 +1,30 @@
<?php
namespace App\Controller;
use Symfony\Bundle\FrameworkBundle\Controller\AbstractController;
use Symfony\Component\HttpFoundation\Response;
use Symfony\Component\Routing\Attribute\Route;
use Symfony\Component\Security\Http\Authentication\AuthenticationUtils;
class SecurityController extends AbstractController
{
#[Route('/login', name: 'app_login')]
public function login(AuthenticationUtils $authenticationUtils): Response
{
if ($this->getUser()) {
return $this->redirectToRoute('app_home');
}
return $this->render('security/login.html.twig', [
'last_username' => $authenticationUtils->getLastUsername(),
'error' => $authenticationUtils->getLastAuthenticationError(),
]);
}
#[Route('/logout', name: 'app_logout')]
public function logout(): never
{
throw new \LogicException('This method can be blank - it will be intercepted by the logout key on your firewall.');
}
}
View File
+111
View File
@@ -0,0 +1,111 @@
<?php
namespace App\Entity;
use App\Repository\UserRepository;
use Doctrine\DBAL\Types\Types;
use Doctrine\ORM\Mapping as ORM;
use Symfony\Bridge\Doctrine\Validator\Constraints\UniqueEntity;
use Symfony\Component\Security\Core\User\PasswordAuthenticatedUserInterface;
use Symfony\Component\Security\Core\User\UserInterface;
#[ORM\Entity(repositoryClass: UserRepository::class)]
#[ORM\Table(name: '`user`')]
#[UniqueEntity(fields: ['email'], message: 'There is already an account with this email')]
class User implements UserInterface, PasswordAuthenticatedUserInterface
{
#[ORM\Id]
#[ORM\GeneratedValue]
#[ORM\Column]
private ?int $id = null;
#[ORM\Column(length: 180, unique: true)]
private ?string $email = null;
/**
* @var list<string> The user roles
*/
#[ORM\Column(type: Types::JSON)]
private array $roles = [];
/**
* @var string The hashed password
*/
#[ORM\Column]
private ?string $password = null;
public function getId(): ?int
{
return $this->id;
}
public function getEmail(): ?string
{
return $this->email;
}
public function setEmail(string $email): static
{
$this->email = $email;
return $this;
}
/**
* A visual identifier that represents this user.
*
* @see UserInterface
*/
public function getUserIdentifier(): string
{
return (string) $this->email;
}
/**
* @see UserInterface
*
* @return list<string>
*/
public function getRoles(): array
{
$roles = $this->roles;
// guarantee every user at least has ROLE_USER
$roles[] = 'ROLE_USER';
return array_values(array_unique($roles));
}
/**
* @param list<string> $roles
*/
public function setRoles(array $roles): static
{
$this->roles = $roles;
return $this;
}
/**
* @see PasswordAuthenticatedUserInterface
*/
public function getPassword(): ?string
{
return $this->password;
}
public function setPassword(string $password): static
{
$this->password = $password;
return $this;
}
/**
* @see UserInterface
*/
public function eraseCredentials(): void
{
// If you store any temporary, sensitive data on the user, clear it here
// $this->plainPassword = null;
}
}
+19
View File
@@ -0,0 +1,19 @@
<?php
namespace App;
use Symfony\Bundle\FrameworkBundle\Kernel\MicroKernelTrait;
use Symfony\Component\HttpKernel\Kernel as BaseKernel;
class Kernel extends BaseKernel
{
use MicroKernelTrait;
/**
* @return list<string> An array of allowed values for APP_ENV
*/
private function getAllowedEnvs(): array
{
return ['prod', 'dev', 'test'];
}
}
View File
+35
View File
@@ -0,0 +1,35 @@
<?php
namespace App\Repository;
use App\Entity\User;
use Doctrine\Bundle\DoctrineBundle\Repository\ServiceEntityRepository;
use Doctrine\Persistence\ManagerRegistry;
use Symfony\Component\Security\Core\Exception\UnsupportedUserException;
use Symfony\Component\Security\Core\User\PasswordAuthenticatedUserInterface;
use Symfony\Component\Security\Core\User\PasswordUpgraderInterface;
/**
* @extends ServiceEntityRepository<User>
*/
class UserRepository extends ServiceEntityRepository implements PasswordUpgraderInterface
{
public function __construct(ManagerRegistry $registry)
{
parent::__construct($registry, User::class);
}
/**
* Used to upgrade (rehash) the user's password automatically over time.
*/
public function upgradePassword(PasswordAuthenticatedUserInterface $user, string $newHashedPassword): void
{
if (!$user instanceof User) {
throw new UnsupportedUserException(sprintf('Instances of "%s" are not supported.', $user::class));
}
$user->setPassword($newHashedPassword);
$this->getEntityManager()->persist($user);
$this->getEntityManager()->flush();
}
}
+327
View File
@@ -0,0 +1,327 @@
{
"doctrine/deprecations": {
"version": "1.1",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "1.0",
"ref": "fdd756167454623e21f1d769c5b814b243782a67"
}
},
"doctrine/doctrine-bundle": {
"version": "3.3",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "3.0",
"ref": "d39a3bd844edfe90c20ae520b804a3bf4f82b4ad"
},
"files": [
"./config/packages/doctrine.yaml",
"./src/Entity/.gitignore",
"./src/Repository/.gitignore"
]
},
"doctrine/doctrine-migrations-bundle": {
"version": "4.0",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "3.1",
"ref": "1d01ec03c6ecbd67c3375c5478c9a423ae5d6a33"
},
"files": [
"./config/packages/doctrine_migrations.yaml",
"./migrations/.gitignore"
]
},
"phpunit/phpunit": {
"version": "13.3",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "11.1",
"ref": "ca0bc067abfb40a8de1b2561b96cbfc2b833c314"
},
"files": [
"./.env.test",
"./phpunit.dist.xml",
"./tests/bootstrap.php",
"./bin/phpunit"
]
},
"symfony/asset-mapper": {
"version": "8.1",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "6.4",
"ref": "c01c47af2ec66a74ec046eccb919cfe27d3464ec"
},
"files": [
"./assets/app.js",
"./assets/styles/app.css",
"./config/packages/asset_mapper.yaml",
"./importmap.php"
]
},
"symfony/console": {
"version": "8.1",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "5.3",
"ref": "1781ff40d8a17d87cf53f8d4cf0c8346ed2bb461"
},
"files": [
"./bin/console"
]
},
"symfony/debug-bundle": {
"version": "8.1",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "5.3",
"ref": "5aa8aa48234c8eb6dbdd7b3cd5d791485d2cec4b"
},
"files": [
"./config/packages/debug.yaml"
]
},
"symfony/flex": {
"version": "2.11",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "2.4",
"ref": "52e9754527a15e2b79d9a610f98185a1fe46622a"
},
"files": [
"./.env",
"./.env.dev"
]
},
"symfony/form": {
"version": "8.1",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "7.2",
"ref": "7d86a6723f4a623f59e2bf966b6aad2fc461d36b"
},
"files": [
"./config/packages/csrf.yaml"
]
},
"symfony/framework-bundle": {
"version": "8.1",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "8.1",
"ref": "5295b2b1ef2170b272383b2b0ae0b66702883822"
},
"files": [
"./config/packages/cache.yaml",
"./config/packages/framework.yaml",
"./config/preload.php",
"./config/routes/framework.yaml",
"./config/services.yaml",
"./public/index.php",
"./src/Controller/.gitignore",
"./src/Kernel.php",
"./.editorconfig",
"./AGENTS.md",
"./CLAUDE.md"
]
},
"symfony/mailer": {
"version": "8.1",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "4.3",
"ref": "09051cfde49476e3c12cd3a0e44289ace1c75a4f"
},
"files": [
"./config/packages/mailer.yaml"
]
},
"symfony/maker-bundle": {
"version": "1.67",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "1.0",
"ref": "fadbfe33303a76e25cb63401050439aa9b1a9c7f"
}
},
"symfony/messenger": {
"version": "8.1",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "6.0",
"ref": "d8936e2e2230637ef97e5eecc0eea074eecae58b"
},
"files": [
"./config/packages/messenger.yaml"
]
},
"symfony/monolog-bundle": {
"version": "4.0",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "3.7",
"ref": "feb8fd9520b5694c7d0d2ba17fd4b4d33f9dd9cf"
},
"files": [
"./config/packages/monolog.yaml"
]
},
"symfony/notifier": {
"version": "8.1",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "5.0",
"ref": "178877daf79d2dbd62129dd03612cb1a2cb407cc"
},
"files": [
"./config/packages/notifier.yaml"
]
},
"symfony/property-info": {
"version": "8.1",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "7.3",
"ref": "dae70df71978ae9226ae915ffd5fad817f5ca1f7"
},
"files": [
"./config/packages/property_info.yaml"
]
},
"symfony/routing": {
"version": "8.1",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "7.4",
"ref": "bc94c4fd86f393f3ab3947c18b830ea343e51ded"
},
"files": [
"./config/packages/routing.yaml",
"./config/routes.yaml"
]
},
"symfony/security-bundle": {
"version": "8.1",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "7.4",
"ref": "c42fee7802181cdd50f61b8622715829f5d2335c"
},
"files": [
"./config/packages/security.yaml",
"./config/routes/security.yaml"
]
},
"symfony/stimulus-bundle": {
"version": "3.4",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "3.3",
"ref": "30f7461c215766d446f3c990b2b18f08ff51386e"
},
"files": [
"./assets/controllers.json",
"./assets/controllers/csrf_protection_controller.js",
"./assets/controllers/hello_controller.js",
"./assets/stimulus_bootstrap.js"
]
},
"symfony/translation": {
"version": "8.1",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "6.3",
"ref": "620a1b84865ceb2ba304c8f8bf2a185fbf32a843"
},
"files": [
"./config/packages/translation.yaml",
"./translations/.gitignore"
]
},
"symfony/twig-bundle": {
"version": "8.1",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "6.4",
"ref": "06dacf16872358cb1f2494e089070ff2d045233a"
},
"files": [
"./config/packages/twig.yaml",
"./templates/base.html.twig"
]
},
"symfony/ux-turbo": {
"version": "3.4",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "2.20",
"ref": "287f7c6eb6e9b65e422d34c00795b360a787380b"
},
"files": [
"./config/packages/ux_turbo.yaml"
]
},
"symfony/validator": {
"version": "8.1",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "7.0",
"ref": "8c1c4e28d26a124b0bb273f537ca8ce443472bfd"
},
"files": [
"./config/packages/validator.yaml"
]
},
"symfony/web-profiler-bundle": {
"version": "8.1",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "8.1",
"ref": "6bdd46f712bbed33a27130b6e055391cb1ab73d9"
},
"files": [
"./config/packages/web_profiler.yaml",
"./config/routes/web_profiler.yaml"
]
},
"symfony/webapp-pack": {
"version": "1.4",
"recipe": {
"repo": "github.com/symfony/recipes",
"branch": "main",
"version": "1.0",
"ref": "b9e6cc8e7b6069d0e8a816665809a423864eb4dd"
},
"files": [
"./config/packages/messenger.yaml"
]
},
"twig/extra-bundle": {
"version": "v3.24.0"
}
}
+47
View File
@@ -0,0 +1,47 @@
<!DOCTYPE html>
<html lang="en" data-bs-theme="dark">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>{% block title %}dmtools{% endblock %}</title>
<link rel="icon" href="data:image/svg+xml,<svg xmlns=%22http://www.w3.org/2000/svg%22 viewBox=%220 0 128 128%22><text y=%221.1em%22 font-size=%22104%22>🎲</text></svg>">
{% block stylesheets %}{% endblock %}
{% block javascripts %}
{% block importmap %}{{ importmap('app') }}{% endblock %}
{% endblock %}
</head>
<body class="d-flex flex-column">
{% block navbar %}
<nav class="navbar navbar-expand-lg bg-body-tertiary border-bottom">
<div class="container">
<a class="navbar-brand" href="{{ path('app_home') }}">🎲 dmtools</a>
{% if app.user %}
<div class="d-flex align-items-center gap-3">
<span class="navbar-text small">{{ app.user.userIdentifier }}</span>
<a class="btn btn-outline-secondary btn-sm" href="{{ path('app_logout') }}">Log out</a>
</div>
{% endif %}
</div>
</nav>
{% endblock %}
<main class="app-main flex-grow-1">
<div class="container">
{% block flashes %}
{% for label, messages in app.flashes %}
{% for message in messages %}
<div class="alert alert-{{ label == 'error' ? 'danger' : label }} alert-dismissible fade show" role="alert">
{{ message }}
<button type="button" class="btn-close" data-bs-dismiss="alert" aria-label="Close"></button>
</div>
{% endfor %}
{% endfor %}
{% endblock %}
{% block body %}{% endblock %}
</div>
</main>
</body>
</html>
+39
View File
@@ -0,0 +1,39 @@
{% extends 'base.html.twig' %}
{% block title %}Overview · dmtools{% endblock %}
{% block body %}
<div class="d-flex justify-content-between align-items-center mb-3">
<h1 class="h3 mb-0">Overview</h1>
</div>
<p class="text-body-secondary">
Starting point for the Monday-evening campaign tools. The table below is a
placeholder that shows the Bootstrap + DataTables layout wiring works
(search, sort, paging).
</p>
<div class="card shadow-sm">
<div class="card-body">
<table class="table table-striped table-hover align-middle datatable"
data-datatable-options='{"order": [[0, "asc"]]}'>
<thead>
<tr>
<th scope="col">Name</th>
<th scope="col">Type</th>
<th scope="col">Location</th>
<th scope="col">Notes</th>
</tr>
</thead>
<tbody>
<tr><td>Seraphina Vane</td><td>NPC</td><td>Blackreach</td><td>Owes the party a favour</td></tr>
<tr><td>Goblin ambush</td><td>Encounter</td><td>Old Kings Road</td><td>CR 2, 6 goblins</td></tr>
<tr><td>The Sunken Vault</td><td>Location</td><td>Lake Nydra</td><td>Water-breathing required</td></tr>
<tr><td>Rusted Key</td><td>Item</td><td>Party inventory</td><td>Opens the vault antechamber</td></tr>
<tr><td>Captain Dorae</td><td>NPC</td><td>Saltmarsh docks</td><td>Will smuggle cargo for coin</td></tr>
<tr><td>Owlbear den</td><td>Encounter</td><td>Whisperwood</td><td>CR 3, mother + 2 cubs</td></tr>
</tbody>
</table>
</div>
</div>
{% endblock %}
+44
View File
@@ -0,0 +1,44 @@
{% extends 'base.html.twig' %}
{% block title %}Sign in · dmtools{% endblock %}
{% block navbar %}
<nav class="navbar bg-body-tertiary border-bottom">
<div class="container">
<span class="navbar-brand">🎲 dmtools</span>
</div>
</nav>
{% endblock %}
{% block body %}
<div class="card login-card shadow-sm">
<div class="card-body p-4">
<h1 class="h4 mb-3 text-center">Sign in</h1>
<form method="post">
{% if error %}
<div class="alert alert-danger" role="alert">
{{ error.messageKey|trans(error.messageData, 'security') }}
</div>
{% endif %}
<div class="mb-3">
<label for="username" class="form-label">Email</label>
<input type="email" value="{{ last_username }}" name="_username" id="username"
class="form-control" autocomplete="email" required autofocus>
</div>
<div class="mb-3">
<label for="password" class="form-label">Password</label>
<input type="password" name="_password" id="password"
class="form-control" autocomplete="current-password" required>
</div>
<input type="hidden" name="_csrf_token" data-controller="csrf-protection"
value="{{ csrf_token('authenticate') }}">
<button class="btn btn-primary w-100" type="submit">Sign in</button>
</form>
</div>
</div>
{% endblock %}
+13
View File
@@ -0,0 +1,13 @@
<?php
use Symfony\Component\Dotenv\Dotenv;
require dirname(__DIR__).'/vendor/autoload.php';
if (method_exists(Dotenv::class, 'bootEnv')) {
(new Dotenv())->bootEnv(dirname(__DIR__).'/.env');
}
if ($_SERVER['APP_DEBUG']) {
umask(0000);
}
View File