Scaffold Symfony 8 app with Bootstrap/DataTables and Docker stack
- Symfony 8.1 webapp skeleton on PHP 8.5 (AssetMapper/importmap, no Node)
- Form-login gate: User entity, security.yaml, SecurityController,
app:user:create command, initial migration (user + messenger_messages)
- Bootstrap 5 + DataTables layout (base/login/home templates); any
table.datatable is auto-initialised
- trusted_proxies/headers wired for the shared Nginx Proxy Manager
- Docker (servers only): docker-compose.yml (php:8.5-fpm-alpine,
nginx:1.30-alpine, mariadb:12.3; host ports 8085/3310; external
docker_default network) + docker/{Dockerfile,php.ini,nginx,setup.sh,restart.sh}
- .env with CHANGEME placeholders (no secrets), .gitattributes enforces
LF so the deploy scripts stay runnable on Linux
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,10 @@
|
|||||||
|
.git
|
||||||
|
.gitignore
|
||||||
|
.idea
|
||||||
|
var/
|
||||||
|
vendor/
|
||||||
|
node_modules/
|
||||||
|
.env.local
|
||||||
|
.env.*.local
|
||||||
|
docker-compose.yml
|
||||||
|
README.md
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
# editorconfig.org
|
||||||
|
|
||||||
|
root = true
|
||||||
|
|
||||||
|
[*]
|
||||||
|
charset = utf-8
|
||||||
|
end_of_line = lf
|
||||||
|
indent_size = 4
|
||||||
|
indent_style = space
|
||||||
|
insert_final_newline = true
|
||||||
|
trim_trailing_whitespace = true
|
||||||
|
|
||||||
|
[{compose.yaml,compose.*.yaml}]
|
||||||
|
indent_size = 2
|
||||||
|
|
||||||
|
[*.md]
|
||||||
|
trim_trailing_whitespace = false
|
||||||
@@ -0,0 +1,60 @@
|
|||||||
|
# In all environments, the following files are loaded if they exist,
|
||||||
|
# the latter taking precedence over the former:
|
||||||
|
#
|
||||||
|
# * .env contains default values for the environment variables needed by the app
|
||||||
|
# * .env.local uncommitted file with local overrides
|
||||||
|
# * .env.$APP_ENV committed environment-specific defaults
|
||||||
|
# * .env.$APP_ENV.local uncommitted environment-specific overrides
|
||||||
|
#
|
||||||
|
# Real environment variables win over .env files.
|
||||||
|
#
|
||||||
|
# DO NOT DEFINE PRODUCTION SECRETS IN THIS FILE NOR IN ANY OTHER COMMITTED FILES.
|
||||||
|
# https://symfony.com/doc/current/configuration/secrets.html
|
||||||
|
#
|
||||||
|
# Run "composer dump-env prod" to compile .env files for production use (requires symfony/flex >=1.2).
|
||||||
|
# https://symfony.com/doc/current/best_practices.html#use-environment-variables-for-infrastructure-configuration
|
||||||
|
|
||||||
|
###> symfony/framework-bundle ###
|
||||||
|
# Committed default is the server (prod) profile. On the dev box, override in
|
||||||
|
# .env.local: APP_ENV=dev, a real APP_SECRET, and a local DATABASE_URL.
|
||||||
|
APP_ENV=prod
|
||||||
|
APP_SECRET=
|
||||||
|
APP_SHARE_DIR=var/share
|
||||||
|
# CIDR ranges the Nginx Proxy Manager / Docker network live in (loopback +
|
||||||
|
# RFC1918). Lets Symfony trust X-Forwarded-* from the reverse proxy.
|
||||||
|
TRUSTED_PROXIES=127.0.0.1,10.0.0.0/8,172.16.0.0/12,192.168.0.0/16
|
||||||
|
###< symfony/framework-bundle ###
|
||||||
|
|
||||||
|
###> symfony/routing ###
|
||||||
|
# Configure how to generate URLs in non-HTTP contexts, such as CLI commands.
|
||||||
|
# See https://symfony.com/doc/current/routing.html#generating-urls-in-commands
|
||||||
|
DEFAULT_URI=https://dmtools.fvandenberg.nl
|
||||||
|
###< symfony/routing ###
|
||||||
|
|
||||||
|
###> doctrine/doctrine-bundle ###
|
||||||
|
# Format described at https://www.doctrine-project.org/projects/doctrine-dbal/en/latest/reference/configuration.html#connecting-using-a-url
|
||||||
|
#
|
||||||
|
# In Docker (servers) the host is the `database` service and these parts come
|
||||||
|
# from docker-compose.yml / .env.local. On the dev box, point DATABASE_URL at
|
||||||
|
# your local MariaDB in .env.local, e.g.:
|
||||||
|
# DATABASE_URL="mysql://root:@127.0.0.1:3306/dmtools?serverVersion=10.10.2-MariaDB&charset=utf8mb4"
|
||||||
|
DB_HOST=database
|
||||||
|
DB_PORT=3306
|
||||||
|
DB_NAME=dmtools
|
||||||
|
DB_USER=dmtools
|
||||||
|
DB_PASSWORD=ChangeMe
|
||||||
|
DB_ROOT_PASSWORD=ChangeMeRoot
|
||||||
|
DB_SERVER_VERSION=mariadb-12.3.2
|
||||||
|
DATABASE_URL="mysql://${DB_USER}:${DB_PASSWORD}@${DB_HOST}:${DB_PORT}/${DB_NAME}?serverVersion=${DB_SERVER_VERSION}&charset=utf8mb4"
|
||||||
|
###< doctrine/doctrine-bundle ###
|
||||||
|
|
||||||
|
###> symfony/messenger ###
|
||||||
|
# Choose one of the transports below
|
||||||
|
# MESSENGER_TRANSPORT_DSN=amqp://guest:guest@localhost:5672/%2f/messages
|
||||||
|
# MESSENGER_TRANSPORT_DSN=redis://localhost:6379/messages
|
||||||
|
MESSENGER_TRANSPORT_DSN=doctrine://default?auto_setup=0
|
||||||
|
###< symfony/messenger ###
|
||||||
|
|
||||||
|
###> symfony/mailer ###
|
||||||
|
MAILER_DSN=null://null
|
||||||
|
###< symfony/mailer ###
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
|
||||||
|
###> symfony/framework-bundle ###
|
||||||
|
APP_SECRET=6aa12054a217aa12c9be49a4c9de3774
|
||||||
|
###< symfony/framework-bundle ###
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
# define your env variables for the test env here
|
||||||
|
KERNEL_CLASS='App\Kernel'
|
||||||
|
APP_SECRET='$ecretf0rt3st'
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
# Normalise everything to LF in the repo (and in working trees). Keeps the
|
||||||
|
# Docker shell scripts runnable on the Linux servers regardless of the OS a
|
||||||
|
# commit was made from. Matches .editorconfig (end_of_line = lf).
|
||||||
|
* text=auto eol=lf
|
||||||
|
|
||||||
|
*.sh text eol=lf
|
||||||
|
/bin/console text eol=lf
|
||||||
|
/bin/phpunit text eol=lf
|
||||||
|
|
||||||
|
# Binaries - never touch.
|
||||||
|
*.png binary
|
||||||
|
*.jpg binary
|
||||||
|
*.jpeg binary
|
||||||
|
*.gif binary
|
||||||
|
*.ico binary
|
||||||
|
*.woff binary
|
||||||
|
*.woff2 binary
|
||||||
|
*.ttf binary
|
||||||
|
*.eot binary
|
||||||
|
*.pdf binary
|
||||||
+23
@@ -0,0 +1,23 @@
|
|||||||
|
|
||||||
|
###> symfony/framework-bundle ###
|
||||||
|
/.env.local
|
||||||
|
/.env.local.php
|
||||||
|
/.env.*.local
|
||||||
|
/config/secrets/prod/prod.decrypt.private.php
|
||||||
|
/public/bundles/
|
||||||
|
/var/
|
||||||
|
/vendor/
|
||||||
|
###< symfony/framework-bundle ###
|
||||||
|
|
||||||
|
###> phpunit/phpunit ###
|
||||||
|
/phpunit.xml
|
||||||
|
/.phpunit.cache/
|
||||||
|
###< phpunit/phpunit ###
|
||||||
|
|
||||||
|
###> symfony/asset-mapper ###
|
||||||
|
/public/assets/
|
||||||
|
/assets/vendor/
|
||||||
|
###< symfony/asset-mapper ###
|
||||||
|
|
||||||
|
# JetBrains IDE metadata (local, machine-specific)
|
||||||
|
/.idea/
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
8.5
|
||||||
@@ -0,0 +1,108 @@
|
|||||||
|
# AGENTS.md
|
||||||
|
|
||||||
|
This is a Symfony project. Check `composer.json` for the exact Symfony/PHP version
|
||||||
|
in use, and read `symfony.lock` to see which recipes ran. Don't assume Doctrine,
|
||||||
|
Twig, API Platform, Messenger, or Lock are installed unless one of those says so.
|
||||||
|
|
||||||
|
## Ask before generating
|
||||||
|
|
||||||
|
If the task doesn't specify, ask rather than guess:
|
||||||
|
|
||||||
|
- Persistence: Doctrine ORM, Doctrine ODM, or none?
|
||||||
|
- Interface: server-rendered (Twig), API (Serializer, maybe API Platform), or both?
|
||||||
|
- Auth: SecurityBundle, and which authenticator?
|
||||||
|
|
||||||
|
If you can't ask (no interactive channel), state the assumption you're making and
|
||||||
|
pick the smallest option (e.g. no persistence layer) rather than scaffolding a
|
||||||
|
full stack nobody asked for.
|
||||||
|
|
||||||
|
## Adding features: Flex, not hand-wiring
|
||||||
|
|
||||||
|
Install new capabilities with `composer require <package>` (e.g. `symfony/lock`,
|
||||||
|
`symfony/messenger`, `orm-pack`) and let the Flex recipe register the bundle and
|
||||||
|
generate its config. Don't hand-edit `config/bundles.php` or hand-write a bundle's
|
||||||
|
base config; that's what the recipe is for. Don't skip a good-fit component just
|
||||||
|
because it isn't installed yet; installing it is one command.
|
||||||
|
|
||||||
|
## Conventions
|
||||||
|
|
||||||
|
Follow https://symfony.com/doc/current/best_practices.html to write idiomatic
|
||||||
|
Symfony:
|
||||||
|
|
||||||
|
- Use PHP attributes for framework metadata, and not only on controllers:
|
||||||
|
`#[Route]`, `#[MapRequestPayload]`, `#[IsGranted]` on actions, `#[Assert\...]`
|
||||||
|
on properties, `#[AsCommand]`, `#[AsEventListener]`, `#[AsMessageHandler]`, and
|
||||||
|
`#[AsAlias]` / `#[AsTaggedItem]` / `#[Autoconfigure]` on services. No YAML or
|
||||||
|
XML routing.
|
||||||
|
- Rely on autowiring and autoconfiguration. Type-hint constructor arguments and
|
||||||
|
let the container resolve them. Where a type-hint can't express it, stay in the
|
||||||
|
class with `#[Autowire]` (parameters, env vars, expressions) or `#[Target]` (one
|
||||||
|
of several implementations of an interface). A YAML service definition is the
|
||||||
|
last resort, not the first.
|
||||||
|
- Controllers extend `AbstractController`, stay thin, and delegate to services.
|
||||||
|
- Use the framework for what it already does: Form for server-rendered forms,
|
||||||
|
Validator for validation, Serializer for JSON, Messenger for async work,
|
||||||
|
Security (voters, authenticators) for access control, Twig `path()`/`url()`
|
||||||
|
instead of hardcoded URLs.
|
||||||
|
- Before hand-writing infrastructure (locks, queues, caches, HTTP clients,
|
||||||
|
mailers, schedulers) or reaching for a third-party library, check whether a
|
||||||
|
Symfony component covers it. It usually does.
|
||||||
|
|
||||||
|
Three specifics worth spelling out, because they are easy to get wrong:
|
||||||
|
|
||||||
|
- Bind request data with `#[MapRequestPayload]` / `#[MapQueryString]` on action
|
||||||
|
arguments, which wires up Serializer and Validator for you, instead of calling
|
||||||
|
`json_decode()` or `SerializerInterface` by hand. If neither package is
|
||||||
|
installed yet, `composer require` them rather than falling back to manual
|
||||||
|
parsing.
|
||||||
|
- Use constructor property promotion, and `readonly` for DTOs and value objects.
|
||||||
|
Don't mark a service `readonly` if it might become `lazy: true`: a lazy proxy
|
||||||
|
can't extend a `readonly` class.
|
||||||
|
- Use `symfony/lock` (`LockFactory`) for mutual exclusion. A hand-built flag or
|
||||||
|
lock file looks fine in review and is usually wrong under concurrency.
|
||||||
|
|
||||||
|
## Everyday workflow
|
||||||
|
|
||||||
|
- Run the app with `symfony serve -d`, and commands with `symfony console ...`
|
||||||
|
(or `bin/console` when the Symfony CLI isn't available).
|
||||||
|
- When something fails, read `var/log/dev.log` and the web profiler
|
||||||
|
(`/_profiler`) before changing code.
|
||||||
|
- If `maker-bundle` is installed, prefer `bin/console make:*` with every argument
|
||||||
|
passed up front and `--no-interaction` where supported: makers prompt on a
|
||||||
|
terminal by default, which hangs a non-interactive shell. If a maker still
|
||||||
|
needs interactive input, hand-write the code instead.
|
||||||
|
- If Doctrine ORM is installed, schema changes go through migrations
|
||||||
|
(`bin/console make:migration`, then `doctrine:migrations:migrate`), never
|
||||||
|
`doctrine:schema:update` or hand-written SQL.
|
||||||
|
- `.env` is committed and holds defaults only. Real secrets belong in `.env.local`
|
||||||
|
(git-ignored) or the secrets vault (`bin/console secrets:set`), read via
|
||||||
|
`%env(...)%`.
|
||||||
|
|
||||||
|
## Testing
|
||||||
|
|
||||||
|
Install `symfony/test-pack` if it isn't already. Functional/HTTP tests extend
|
||||||
|
`WebTestCase`; service-level tests extend `KernelTestCase`. Run
|
||||||
|
`php bin/phpunit` (falls back to `vendor/bin/phpunit`). A feature isn't done
|
||||||
|
until it has a test that exercises it the way a caller would, an HTTP request for
|
||||||
|
a controller or a service call for a service, not just "it didn't throw."
|
||||||
|
|
||||||
|
## Code style
|
||||||
|
|
||||||
|
Symfony's coding standard, the `@Symfony` php-cs-fixer ruleset (a PSR-12-derived
|
||||||
|
superset). Run `vendor/bin/php-cs-fixer fix` if `friendsofphp/php-cs-fixer` is
|
||||||
|
installed; it isn't part of the skeleton by default.
|
||||||
|
|
||||||
|
## Discover, don't guess
|
||||||
|
|
||||||
|
Framework APIs change between versions and your training data may be stale. Look
|
||||||
|
things up in the project instead of relying on memory:
|
||||||
|
|
||||||
|
- `bin/console about`: versions, environment, paths.
|
||||||
|
- `bin/console debug:router`, `debug:container`, `debug:autowiring <name>`,
|
||||||
|
`debug:config <bundle>`, `config:dump-reference <bundle>`: what exists and how
|
||||||
|
it is configured.
|
||||||
|
- `bin/console lint:container`, plus `lint:twig templates/` and
|
||||||
|
`lint:yaml config/` where those packages are installed: validate before running.
|
||||||
|
- Read the installed source and docblocks under `vendor/`.
|
||||||
|
- Docs: https://symfony.com/doc/current/ (switch to the version matching
|
||||||
|
`composer.json` if it differs).
|
||||||
@@ -1,3 +1,85 @@
|
|||||||
# dmtools
|
# dmtools
|
||||||
|
|
||||||
DM tools for the monday evening campaign
|
DM tools for the Monday-evening D&D campaign.
|
||||||
|
|
||||||
|
Symfony 8 (PHP 8.5) web app with a Bootstrap 5 + DataTables front end served
|
||||||
|
through Symfony AssetMapper (no Node build step). Behind a form-login gate; there
|
||||||
|
is no self-registration.
|
||||||
|
|
||||||
|
- **Not** run in Docker locally (Windows dev box uses the Symfony CLI + local
|
||||||
|
MariaDB).
|
||||||
|
- **Is** Dockerized on the testing and live servers, behind the shared Nginx
|
||||||
|
Proxy Manager at `https://dmtools.fvandenberg.nl`.
|
||||||
|
|
||||||
|
Repo: <https://gitea.fvandenberg.nl/Frank/dmtools.git>
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Local development (dev box)
|
||||||
|
|
||||||
|
Prerequisites: PHP 8.5 at `C:\php` (on `PATH` so the Symfony CLI discovers it —
|
||||||
|
`symfony local:php:list` should show 8.5), the Symfony CLI, Composer, and a local
|
||||||
|
MariaDB/MySQL (WAMP is fine). `.php-version` pins this directory to PHP 8.5.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# 1. Point the app at your local database + dev mode
|
||||||
|
cp .env .env.local
|
||||||
|
# then edit .env.local:
|
||||||
|
# APP_ENV=dev
|
||||||
|
# DATABASE_URL="mysql://root:@127.0.0.1:3306/dmtools?serverVersion=10.10.2-MariaDB&charset=utf8mb4"
|
||||||
|
|
||||||
|
# 2. Install and build
|
||||||
|
symfony composer install
|
||||||
|
symfony console doctrine:database:create
|
||||||
|
symfony console doctrine:migrations:migrate -n
|
||||||
|
symfony console importmap:install
|
||||||
|
|
||||||
|
# 3. First user, then run
|
||||||
|
symfony console app:user:create you@example.com --admin
|
||||||
|
symfony serve -d
|
||||||
|
symfony open:local
|
||||||
|
```
|
||||||
|
|
||||||
|
`serverVersion` must match your local engine (`SELECT VERSION();`).
|
||||||
|
|
||||||
|
## Servers (testing + live)
|
||||||
|
|
||||||
|
Docker only. `docker/setup.sh` pins the compose project name to `dmtools`
|
||||||
|
(containers `dmtools-php`, `dmtools-nginx`, `dmtools-db`).
|
||||||
|
|
||||||
|
```bash
|
||||||
|
git pull
|
||||||
|
cp .env .env.local # first time only
|
||||||
|
# edit .env.local: real APP_SECRET (or let setup.sh generate it),
|
||||||
|
# DB_PASSWORD, DB_ROOT_PASSWORD, and NGINX_PORT / DB_PORT if 8085 / 3310 clash
|
||||||
|
./docker/setup.sh
|
||||||
|
docker compose -p dmtools exec php php bin/console app:user:create you@example.com --admin
|
||||||
|
```
|
||||||
|
|
||||||
|
Ports (bound to `127.0.0.1` on the host): nginx `8085` → `:80`, db `3310` → `:3306`.
|
||||||
|
|
||||||
|
### Reverse proxy (Nginx Proxy Manager)
|
||||||
|
|
||||||
|
Add a proxy host: `dmtools.fvandenberg.nl` → forward to host `dmtools-nginx`,
|
||||||
|
port `80`, scheme `http`; request a Let's Encrypt certificate. NPM and
|
||||||
|
`dmtools-nginx` must share the external `docker_default` Docker network (the
|
||||||
|
compose file attaches nginx to it as `proxy`).
|
||||||
|
|
||||||
|
### Common commands
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker compose -p dmtools logs -f php
|
||||||
|
docker compose -p dmtools exec php bash
|
||||||
|
docker compose -p dmtools exec php php bin/console doctrine:migrations:migrate
|
||||||
|
./docker/restart.sh # full down + bring-up (no rebuild)
|
||||||
|
./docker/setup.sh --down # stop the stack
|
||||||
|
```
|
||||||
|
|
||||||
|
## Layout notes
|
||||||
|
|
||||||
|
- `table.datatable` in any Twig template is auto-initialised as a DataTable
|
||||||
|
(`assets/app.js`). Opt out with `data-datatable="false"`; pass options as JSON
|
||||||
|
in `data-datatable-options`.
|
||||||
|
- `assets/vendor/` and `public/assets/` are generated (git-ignored);
|
||||||
|
`importmap:install` on the server re-downloads vendored packages, so the
|
||||||
|
servers need outbound HTTPS to jsDelivr at deploy time.
|
||||||
|
|||||||
@@ -0,0 +1,36 @@
|
|||||||
|
/*
|
||||||
|
* dmtools front-end entrypoint (Symfony AssetMapper / importmap).
|
||||||
|
* Loaded from base.html.twig via {{ importmap('app') }}.
|
||||||
|
*/
|
||||||
|
import './stimulus_bootstrap.js';
|
||||||
|
|
||||||
|
import 'bootstrap/dist/css/bootstrap.min.css';
|
||||||
|
import 'datatables.net-bs5/css/dataTables.bootstrap5.min.css';
|
||||||
|
import './styles/app.css';
|
||||||
|
|
||||||
|
import * as bootstrap from 'bootstrap';
|
||||||
|
import DataTable from 'datatables.net-bs5';
|
||||||
|
|
||||||
|
window.bootstrap = bootstrap;
|
||||||
|
|
||||||
|
// Turn any <table class="datatable"> into a DataTable. Opt out per-table with
|
||||||
|
// data-datatable="false"; pass options as a JSON object in data-datatable-options.
|
||||||
|
function initDataTables(root = document) {
|
||||||
|
root.querySelectorAll('table.datatable').forEach((table) => {
|
||||||
|
if (table.dataset.datatable === 'false' || DataTable.isDataTable(table)) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
let options = { pageLength: 25, order: [] };
|
||||||
|
if (table.dataset.datatableOptions) {
|
||||||
|
try {
|
||||||
|
options = { ...options, ...JSON.parse(table.dataset.datatableOptions) };
|
||||||
|
} catch (e) {
|
||||||
|
console.error('Invalid data-datatable-options on', table, e);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
new DataTable(table, options);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
document.addEventListener('DOMContentLoaded', () => initDataTables());
|
||||||
|
document.addEventListener('turbo:load', () => initDataTables());
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
{
|
||||||
|
"controllers": {
|
||||||
|
"@symfony/ux-turbo": {
|
||||||
|
"turbo-core": {
|
||||||
|
"enabled": true,
|
||||||
|
"fetch": "eager",
|
||||||
|
"autoimport": {
|
||||||
|
"@symfony/ux-turbo/dist/mercure_stream_source_element.js": true
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"mercure-turbo-stream": {
|
||||||
|
"enabled": false,
|
||||||
|
"fetch": "eager"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"entrypoints": []
|
||||||
|
}
|
||||||
@@ -0,0 +1,81 @@
|
|||||||
|
const nameCheck = /^[-_a-zA-Z0-9]{4,22}$/;
|
||||||
|
const tokenCheck = /^[-_/+a-zA-Z0-9]{24,}$/;
|
||||||
|
|
||||||
|
// Generate and double-submit a CSRF token in a form field and a cookie, as defined by Symfony's SameOriginCsrfTokenManager
|
||||||
|
// Use `form.requestSubmit()` to ensure that the submit event is triggered. Using `form.submit()` will not trigger the event
|
||||||
|
// and thus this event-listener will not be executed.
|
||||||
|
document.addEventListener('submit', function (event) {
|
||||||
|
generateCsrfToken(event.target);
|
||||||
|
}, true);
|
||||||
|
|
||||||
|
// When @hotwired/turbo handles form submissions, send the CSRF token in a header in addition to a cookie
|
||||||
|
// The `framework.csrf_protection.check_header` config option needs to be enabled for the header to be checked
|
||||||
|
document.addEventListener('turbo:submit-start', function (event) {
|
||||||
|
const h = generateCsrfHeaders(event.detail.formSubmission.formElement);
|
||||||
|
Object.keys(h).map(function (k) {
|
||||||
|
event.detail.formSubmission.fetchRequest.headers[k] = h[k];
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
// When @hotwired/turbo handles form submissions, remove the CSRF cookie once a form has been submitted
|
||||||
|
document.addEventListener('turbo:submit-end', function (event) {
|
||||||
|
removeCsrfToken(event.detail.formSubmission.formElement);
|
||||||
|
});
|
||||||
|
|
||||||
|
export function generateCsrfToken (formElement) {
|
||||||
|
const csrfField = formElement.querySelector('input[data-controller="csrf-protection"], input[name="_csrf_token"]');
|
||||||
|
|
||||||
|
if (!csrfField) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
let csrfCookie = csrfField.getAttribute('data-csrf-protection-cookie-value');
|
||||||
|
let csrfToken = csrfField.value;
|
||||||
|
|
||||||
|
if (!csrfCookie && nameCheck.test(csrfToken)) {
|
||||||
|
csrfField.setAttribute('data-csrf-protection-cookie-value', csrfCookie = csrfToken);
|
||||||
|
csrfField.defaultValue = csrfToken = btoa(String.fromCharCode.apply(null, (window.crypto || window.msCrypto).getRandomValues(new Uint8Array(18))));
|
||||||
|
}
|
||||||
|
csrfField.dispatchEvent(new Event('change', { bubbles: true }));
|
||||||
|
|
||||||
|
if (csrfCookie && tokenCheck.test(csrfToken)) {
|
||||||
|
const cookie = csrfCookie + '_' + csrfToken + '=' + csrfCookie + '; path=/; samesite=strict';
|
||||||
|
document.cookie = window.location.protocol === 'https:' ? '__Host-' + cookie + '; secure' : cookie;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export function generateCsrfHeaders (formElement) {
|
||||||
|
const headers = {};
|
||||||
|
const csrfField = formElement.querySelector('input[data-controller="csrf-protection"], input[name="_csrf_token"]');
|
||||||
|
|
||||||
|
if (!csrfField) {
|
||||||
|
return headers;
|
||||||
|
}
|
||||||
|
|
||||||
|
const csrfCookie = csrfField.getAttribute('data-csrf-protection-cookie-value');
|
||||||
|
|
||||||
|
if (tokenCheck.test(csrfField.value) && nameCheck.test(csrfCookie)) {
|
||||||
|
headers[csrfCookie] = csrfField.value;
|
||||||
|
}
|
||||||
|
|
||||||
|
return headers;
|
||||||
|
}
|
||||||
|
|
||||||
|
export function removeCsrfToken (formElement) {
|
||||||
|
const csrfField = formElement.querySelector('input[data-controller="csrf-protection"], input[name="_csrf_token"]');
|
||||||
|
|
||||||
|
if (!csrfField) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
const csrfCookie = csrfField.getAttribute('data-csrf-protection-cookie-value');
|
||||||
|
|
||||||
|
if (tokenCheck.test(csrfField.value) && nameCheck.test(csrfCookie)) {
|
||||||
|
const cookie = csrfCookie + '_' + csrfField.value + '=0; path=/; samesite=strict; max-age=0';
|
||||||
|
|
||||||
|
document.cookie = window.location.protocol === 'https:' ? '__Host-' + cookie + '; secure' : cookie;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/* stimulusFetch: 'lazy' */
|
||||||
|
export default 'csrf-protection-controller';
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
import { Controller } from '@hotwired/stimulus';
|
||||||
|
|
||||||
|
/*
|
||||||
|
* This is an example Stimulus controller!
|
||||||
|
*
|
||||||
|
* Any element with a data-controller="hello" attribute will cause
|
||||||
|
* this controller to be executed. The name "hello" comes from the filename:
|
||||||
|
* hello_controller.js -> "hello"
|
||||||
|
*
|
||||||
|
* Delete this file or adapt it for your use!
|
||||||
|
*/
|
||||||
|
export default class extends Controller {
|
||||||
|
connect() {
|
||||||
|
this.element.textContent = 'Hello Stimulus! Edit me in assets/controllers/hello_controller.js';
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
import { startStimulusApp } from '@symfony/stimulus-bundle';
|
||||||
|
|
||||||
|
const app = startStimulusApp();
|
||||||
|
// register any custom, 3rd party controllers here
|
||||||
|
// app.register('some_controller_name', SomeImportedController);
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
/* dmtools project styles. Bootstrap + DataTables (bs5) are imported from app.js. */
|
||||||
|
|
||||||
|
body {
|
||||||
|
min-height: 100vh;
|
||||||
|
}
|
||||||
|
|
||||||
|
main.app-main {
|
||||||
|
padding-top: 1.5rem;
|
||||||
|
padding-bottom: 3rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.navbar-brand {
|
||||||
|
font-weight: 600;
|
||||||
|
letter-spacing: 0.02em;
|
||||||
|
}
|
||||||
|
|
||||||
|
.login-card {
|
||||||
|
max-width: 24rem;
|
||||||
|
margin: 8vh auto 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Let DataTables' controls breathe inside a Bootstrap card. */
|
||||||
|
table.dataTable {
|
||||||
|
width: 100% !important;
|
||||||
|
}
|
||||||
Executable
+21
@@ -0,0 +1,21 @@
|
|||||||
|
#!/usr/bin/env php
|
||||||
|
<?php
|
||||||
|
|
||||||
|
use App\Kernel;
|
||||||
|
use Symfony\Bundle\FrameworkBundle\Console\Application;
|
||||||
|
|
||||||
|
if (!is_dir(dirname(__DIR__).'/vendor')) {
|
||||||
|
throw new LogicException('Dependencies are missing. Try running "composer install".');
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!is_file(dirname(__DIR__).'/vendor/autoload_runtime.php')) {
|
||||||
|
throw new LogicException('Symfony Runtime is missing. Try running "composer require symfony/runtime".');
|
||||||
|
}
|
||||||
|
|
||||||
|
require_once dirname(__DIR__).'/vendor/autoload_runtime.php';
|
||||||
|
|
||||||
|
return function (array $context) {
|
||||||
|
$kernel = new Kernel($context['APP_ENV'], (bool) $context['APP_DEBUG']);
|
||||||
|
|
||||||
|
return new Application($kernel);
|
||||||
|
};
|
||||||
Executable
+4
@@ -0,0 +1,4 @@
|
|||||||
|
#!/usr/bin/env php
|
||||||
|
<?php
|
||||||
|
|
||||||
|
require dirname(__DIR__).'/vendor/phpunit/phpunit/phpunit';
|
||||||
+114
@@ -0,0 +1,114 @@
|
|||||||
|
{
|
||||||
|
"name": "frank/dmtools",
|
||||||
|
"description": "DM tools for the Monday-evening D&D campaign",
|
||||||
|
"type": "project",
|
||||||
|
"license": "proprietary",
|
||||||
|
"minimum-stability": "stable",
|
||||||
|
"prefer-stable": true,
|
||||||
|
"require": {
|
||||||
|
"php": ">=8.4",
|
||||||
|
"ext-ctype": "*",
|
||||||
|
"ext-iconv": "*",
|
||||||
|
"doctrine/doctrine-bundle": "^3.3",
|
||||||
|
"doctrine/doctrine-migrations-bundle": "^4.0",
|
||||||
|
"doctrine/orm": "^3.6",
|
||||||
|
"phpdocumentor/reflection-docblock": "^6.0",
|
||||||
|
"phpstan/phpdoc-parser": "^2.3",
|
||||||
|
"symfony/asset": "8.1.*",
|
||||||
|
"symfony/asset-mapper": "8.1.*",
|
||||||
|
"symfony/console": "8.1.*",
|
||||||
|
"symfony/doctrine-messenger": "8.1.*",
|
||||||
|
"symfony/dotenv": "8.1.*",
|
||||||
|
"symfony/expression-language": "8.1.*",
|
||||||
|
"symfony/flex": "^2",
|
||||||
|
"symfony/form": "8.1.*",
|
||||||
|
"symfony/framework-bundle": "8.1.*",
|
||||||
|
"symfony/http-client": "8.1.*",
|
||||||
|
"symfony/intl": "8.1.*",
|
||||||
|
"symfony/mailer": "8.1.*",
|
||||||
|
"symfony/mime": "8.1.*",
|
||||||
|
"symfony/monolog-bundle": "^3.0|^4.0",
|
||||||
|
"symfony/notifier": "8.1.*",
|
||||||
|
"symfony/process": "8.1.*",
|
||||||
|
"symfony/property-access": "8.1.*",
|
||||||
|
"symfony/property-info": "8.1.*",
|
||||||
|
"symfony/runtime": "8.1.*",
|
||||||
|
"symfony/security-bundle": "8.1.*",
|
||||||
|
"symfony/serializer": "8.1.*",
|
||||||
|
"symfony/stimulus-bundle": "^3.4",
|
||||||
|
"symfony/string": "8.1.*",
|
||||||
|
"symfony/translation": "8.1.*",
|
||||||
|
"symfony/twig-bundle": "8.1.*",
|
||||||
|
"symfony/ux-turbo": "^3.4",
|
||||||
|
"symfony/validator": "8.1.*",
|
||||||
|
"symfony/web-link": "8.1.*",
|
||||||
|
"symfony/yaml": "8.1.*",
|
||||||
|
"twig/extra-bundle": "^2.12|^3.0",
|
||||||
|
"twig/twig": "^2.12|^3.0"
|
||||||
|
},
|
||||||
|
"config": {
|
||||||
|
"allow-plugins": {
|
||||||
|
"php-http/discovery": true,
|
||||||
|
"symfony/flex": true,
|
||||||
|
"symfony/runtime": true
|
||||||
|
},
|
||||||
|
"bump-after-update": true,
|
||||||
|
"sort-packages": true,
|
||||||
|
"platform": {
|
||||||
|
"php": "8.5"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"autoload": {
|
||||||
|
"psr-4": {
|
||||||
|
"App\\": "src/"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"autoload-dev": {
|
||||||
|
"psr-4": {
|
||||||
|
"App\\Tests\\": "tests/"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"replace": {
|
||||||
|
"symfony/polyfill-ctype": "*",
|
||||||
|
"symfony/polyfill-iconv": "*",
|
||||||
|
"symfony/polyfill-php72": "*",
|
||||||
|
"symfony/polyfill-php73": "*",
|
||||||
|
"symfony/polyfill-php74": "*",
|
||||||
|
"symfony/polyfill-php80": "*",
|
||||||
|
"symfony/polyfill-php81": "*",
|
||||||
|
"symfony/polyfill-php82": "*",
|
||||||
|
"symfony/polyfill-php83": "*",
|
||||||
|
"symfony/polyfill-php84": "*"
|
||||||
|
},
|
||||||
|
"scripts": {
|
||||||
|
"auto-scripts": {
|
||||||
|
"cache:clear": "symfony-cmd",
|
||||||
|
"assets:install %PUBLIC_DIR%": "symfony-cmd",
|
||||||
|
"importmap:install": "symfony-cmd"
|
||||||
|
},
|
||||||
|
"post-install-cmd": [
|
||||||
|
"@auto-scripts"
|
||||||
|
],
|
||||||
|
"post-update-cmd": [
|
||||||
|
"@auto-scripts"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"conflict": {
|
||||||
|
"symfony/symfony": "*"
|
||||||
|
},
|
||||||
|
"extra": {
|
||||||
|
"symfony": {
|
||||||
|
"allow-contrib": false,
|
||||||
|
"require": "8.1.*"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"require-dev": {
|
||||||
|
"phpunit/phpunit": "^13.3",
|
||||||
|
"symfony/browser-kit": "8.1.*",
|
||||||
|
"symfony/css-selector": "8.1.*",
|
||||||
|
"symfony/debug-bundle": "8.1.*",
|
||||||
|
"symfony/maker-bundle": "^1.0",
|
||||||
|
"symfony/stopwatch": "8.1.*",
|
||||||
|
"symfony/web-profiler-bundle": "8.1.*"
|
||||||
|
}
|
||||||
|
}
|
||||||
Generated
+10118
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,16 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
return [
|
||||||
|
Symfony\Bundle\FrameworkBundle\FrameworkBundle::class => ['all' => true],
|
||||||
|
Doctrine\Bundle\DoctrineBundle\DoctrineBundle::class => ['all' => true],
|
||||||
|
Doctrine\Bundle\MigrationsBundle\DoctrineMigrationsBundle::class => ['all' => true],
|
||||||
|
Symfony\Bundle\DebugBundle\DebugBundle::class => ['dev' => true],
|
||||||
|
Symfony\Bundle\TwigBundle\TwigBundle::class => ['all' => true],
|
||||||
|
Symfony\Bundle\WebProfilerBundle\WebProfilerBundle::class => ['dev' => true, 'test' => true],
|
||||||
|
Symfony\UX\StimulusBundle\StimulusBundle::class => ['all' => true],
|
||||||
|
Symfony\UX\Turbo\TurboBundle::class => ['all' => true],
|
||||||
|
Twig\Extra\TwigExtraBundle\TwigExtraBundle::class => ['all' => true],
|
||||||
|
Symfony\Bundle\SecurityBundle\SecurityBundle::class => ['all' => true],
|
||||||
|
Symfony\Bundle\MonologBundle\MonologBundle::class => ['all' => true],
|
||||||
|
Symfony\Bundle\MakerBundle\MakerBundle::class => ['dev' => true],
|
||||||
|
];
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
framework:
|
||||||
|
asset_mapper:
|
||||||
|
# The paths to make available to the asset mapper.
|
||||||
|
paths:
|
||||||
|
- assets/
|
||||||
|
missing_import_mode: strict
|
||||||
|
|
||||||
|
when@prod:
|
||||||
|
framework:
|
||||||
|
asset_mapper:
|
||||||
|
missing_import_mode: warn
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
framework:
|
||||||
|
cache:
|
||||||
|
# Unique name of your app: used to compute stable namespaces for cache keys.
|
||||||
|
#prefix_seed: your_vendor_name/app_name
|
||||||
|
|
||||||
|
# The "app" cache stores to the filesystem by default.
|
||||||
|
# The data in this cache should persist between deploys.
|
||||||
|
# Other options include:
|
||||||
|
|
||||||
|
# Redis
|
||||||
|
#app: cache.adapter.redis
|
||||||
|
#default_redis_provider: redis://localhost
|
||||||
|
|
||||||
|
# APCu (not recommended with heavy random-write workloads as memory fragmentation can cause perf issues)
|
||||||
|
#app: cache.adapter.apcu
|
||||||
|
|
||||||
|
# Namespaced pools use the above "app" backend by default
|
||||||
|
#pools:
|
||||||
|
#my.dedicated.cache: null
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
# Enable stateless CSRF protection for forms and logins/logouts
|
||||||
|
framework:
|
||||||
|
form:
|
||||||
|
csrf_protection:
|
||||||
|
token_id: submit
|
||||||
|
|
||||||
|
csrf_protection:
|
||||||
|
stateless_token_ids:
|
||||||
|
- submit
|
||||||
|
- authenticate
|
||||||
|
- logout
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
when@dev:
|
||||||
|
debug:
|
||||||
|
# Forwards VarDumper Data clones to a centralized server allowing to inspect dumps on CLI or in your browser.
|
||||||
|
# See the "server:dump" command to start a new server.
|
||||||
|
dump_destination: "tcp://%env(VAR_DUMPER_SERVER)%"
|
||||||
@@ -0,0 +1,46 @@
|
|||||||
|
doctrine:
|
||||||
|
dbal:
|
||||||
|
url: '%env(resolve:DATABASE_URL)%'
|
||||||
|
|
||||||
|
# IMPORTANT: You MUST configure your server version,
|
||||||
|
# either here or in the DATABASE_URL env var (see .env file)
|
||||||
|
#server_version: '16'
|
||||||
|
|
||||||
|
profiling_collect_backtrace: '%kernel.debug%'
|
||||||
|
orm:
|
||||||
|
validate_xml_mapping: true
|
||||||
|
naming_strategy: doctrine.orm.naming_strategy.underscore
|
||||||
|
identity_generation_preferences:
|
||||||
|
Doctrine\DBAL\Platforms\PostgreSQLPlatform: identity
|
||||||
|
auto_mapping: true
|
||||||
|
mappings:
|
||||||
|
App:
|
||||||
|
type: attribute
|
||||||
|
is_bundle: false
|
||||||
|
dir: '%kernel.project_dir%/src/Entity'
|
||||||
|
prefix: 'App\Entity'
|
||||||
|
alias: App
|
||||||
|
|
||||||
|
when@test:
|
||||||
|
doctrine:
|
||||||
|
dbal:
|
||||||
|
# "TEST_TOKEN" is typically set by ParaTest
|
||||||
|
dbname_suffix: '_test%env(default::TEST_TOKEN)%'
|
||||||
|
|
||||||
|
when@prod:
|
||||||
|
doctrine:
|
||||||
|
orm:
|
||||||
|
query_cache_driver:
|
||||||
|
type: pool
|
||||||
|
pool: doctrine.system_cache_pool
|
||||||
|
result_cache_driver:
|
||||||
|
type: pool
|
||||||
|
pool: doctrine.result_cache_pool
|
||||||
|
|
||||||
|
framework:
|
||||||
|
cache:
|
||||||
|
pools:
|
||||||
|
doctrine.result_cache_pool:
|
||||||
|
adapter: cache.app
|
||||||
|
doctrine.system_cache_pool:
|
||||||
|
adapter: cache.system
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
doctrine_migrations:
|
||||||
|
migrations_paths:
|
||||||
|
# namespace is arbitrary but should be different from App\Migrations
|
||||||
|
# as migrations classes should NOT be autoloaded
|
||||||
|
'DoctrineMigrations': '%kernel.project_dir%/migrations'
|
||||||
|
enable_profiler: false
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
# see https://symfony.com/doc/current/reference/configuration/framework.html
|
||||||
|
framework:
|
||||||
|
secret: '%env(APP_SECRET)%'
|
||||||
|
|
||||||
|
# Note that the session will be started ONLY if you read or write from it.
|
||||||
|
session: true
|
||||||
|
|
||||||
|
# dmtools runs behind the shared Nginx Proxy Manager on the servers, which
|
||||||
|
# terminates TLS and forwards over the Docker network. Trust the private
|
||||||
|
# ranges the proxy/containers live in, and honour its X-Forwarded-* headers
|
||||||
|
# so Symfony builds https:// URLs and detects the real client IP.
|
||||||
|
trusted_proxies: '%env(TRUSTED_PROXIES)%'
|
||||||
|
trusted_headers: ['x-forwarded-for', 'x-forwarded-host', 'x-forwarded-proto', 'x-forwarded-port', 'x-forwarded-prefix']
|
||||||
|
|
||||||
|
#esi: true
|
||||||
|
#fragments: true
|
||||||
|
|
||||||
|
when@test:
|
||||||
|
framework:
|
||||||
|
test: true
|
||||||
|
session:
|
||||||
|
storage_factory_id: session.storage.factory.mock_file
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
framework:
|
||||||
|
mailer:
|
||||||
|
dsn: '%env(MAILER_DSN)%'
|
||||||
@@ -0,0 +1,26 @@
|
|||||||
|
framework:
|
||||||
|
messenger:
|
||||||
|
failure_transport: failed
|
||||||
|
|
||||||
|
transports:
|
||||||
|
# https://symfony.com/doc/current/messenger.html#transport-configuration
|
||||||
|
async:
|
||||||
|
dsn: '%env(MESSENGER_TRANSPORT_DSN)%'
|
||||||
|
retry_strategy:
|
||||||
|
max_retries: 3
|
||||||
|
multiplier: 2
|
||||||
|
failed: 'doctrine://default?queue_name=failed'
|
||||||
|
# sync: 'sync://'
|
||||||
|
|
||||||
|
default_bus: messenger.bus.default
|
||||||
|
|
||||||
|
buses:
|
||||||
|
messenger.bus.default: []
|
||||||
|
|
||||||
|
routing:
|
||||||
|
Symfony\Component\Mailer\Messenger\SendEmailMessage: async
|
||||||
|
Symfony\Component\Notifier\Message\ChatMessage: async
|
||||||
|
Symfony\Component\Notifier\Message\SmsMessage: async
|
||||||
|
|
||||||
|
# Route your messages to the transports
|
||||||
|
# 'App\Message\YourMessage': async
|
||||||
@@ -0,0 +1,55 @@
|
|||||||
|
monolog:
|
||||||
|
channels: # To see all channels, run bin/console debug:autowiring logger
|
||||||
|
- deprecation # Deprecations are logged in the dedicated "deprecation" channel when it exists
|
||||||
|
|
||||||
|
when@dev:
|
||||||
|
monolog:
|
||||||
|
handlers:
|
||||||
|
main:
|
||||||
|
type: stream
|
||||||
|
path: "%kernel.logs_dir%/%kernel.environment%.log"
|
||||||
|
level: debug
|
||||||
|
channels: ["!event"]
|
||||||
|
console:
|
||||||
|
type: console
|
||||||
|
process_psr_3_messages: false
|
||||||
|
channels: ["!event", "!doctrine", "!console"]
|
||||||
|
|
||||||
|
when@test:
|
||||||
|
monolog:
|
||||||
|
handlers:
|
||||||
|
main:
|
||||||
|
type: fingers_crossed
|
||||||
|
action_level: error
|
||||||
|
handler: nested
|
||||||
|
excluded_http_codes: [404, 405]
|
||||||
|
channels: ["!event"]
|
||||||
|
nested:
|
||||||
|
type: stream
|
||||||
|
path: "%kernel.logs_dir%/%kernel.environment%.log"
|
||||||
|
level: debug
|
||||||
|
|
||||||
|
when@prod:
|
||||||
|
monolog:
|
||||||
|
handlers:
|
||||||
|
main:
|
||||||
|
type: fingers_crossed
|
||||||
|
action_level: error
|
||||||
|
handler: nested
|
||||||
|
excluded_http_codes: [404, 405]
|
||||||
|
channels: ["!deprecation"]
|
||||||
|
buffer_size: 50 # How many messages should be saved? Prevent memory leaks
|
||||||
|
nested:
|
||||||
|
type: stream
|
||||||
|
path: php://stderr
|
||||||
|
level: debug
|
||||||
|
formatter: monolog.formatter.json
|
||||||
|
console:
|
||||||
|
type: console
|
||||||
|
process_psr_3_messages: false
|
||||||
|
channels: ["!event", "!doctrine"]
|
||||||
|
deprecation:
|
||||||
|
type: stream
|
||||||
|
channels: [deprecation]
|
||||||
|
path: php://stderr
|
||||||
|
formatter: monolog.formatter.json
|
||||||
@@ -0,0 +1,12 @@
|
|||||||
|
framework:
|
||||||
|
notifier:
|
||||||
|
chatter_transports:
|
||||||
|
texter_transports:
|
||||||
|
channel_policy:
|
||||||
|
# use chat/slack, chat/telegram, sms/twilio or sms/nexmo
|
||||||
|
urgent: ['email']
|
||||||
|
high: ['email']
|
||||||
|
medium: ['email']
|
||||||
|
low: ['email']
|
||||||
|
admin_recipients:
|
||||||
|
- { email: admin@example.com }
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
framework:
|
||||||
|
property_info:
|
||||||
|
with_constructor_extractor: true
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
framework:
|
||||||
|
router:
|
||||||
|
# Configure how to generate URLs in non-HTTP contexts, such as CLI commands.
|
||||||
|
# See https://symfony.com/doc/current/routing.html#generating-urls-in-commands
|
||||||
|
default_uri: '%env(DEFAULT_URI)%'
|
||||||
|
|
||||||
|
when@prod:
|
||||||
|
framework:
|
||||||
|
router:
|
||||||
|
strict_requirements: null
|
||||||
@@ -0,0 +1,46 @@
|
|||||||
|
security:
|
||||||
|
# https://symfony.com/doc/current/security.html#registering-the-user-hashing-passwords
|
||||||
|
password_hashers:
|
||||||
|
Symfony\Component\Security\Core\User\PasswordAuthenticatedUserInterface: 'auto'
|
||||||
|
|
||||||
|
# https://symfony.com/doc/current/security.html#loading-the-user-the-user-provider
|
||||||
|
providers:
|
||||||
|
app_user_provider:
|
||||||
|
entity:
|
||||||
|
class: App\Entity\User
|
||||||
|
property: email
|
||||||
|
|
||||||
|
firewalls:
|
||||||
|
dev:
|
||||||
|
pattern: ^/(_(profiler|wdt)|assets)/
|
||||||
|
security: false
|
||||||
|
main:
|
||||||
|
lazy: true
|
||||||
|
provider: app_user_provider
|
||||||
|
form_login:
|
||||||
|
login_path: app_login
|
||||||
|
check_path: app_login
|
||||||
|
enable_csrf: true
|
||||||
|
default_target_path: app_home
|
||||||
|
logout:
|
||||||
|
path: app_logout
|
||||||
|
target: app_login
|
||||||
|
|
||||||
|
# Note: Only the *first* matching rule is applied
|
||||||
|
access_control:
|
||||||
|
- { path: ^/login$, roles: PUBLIC_ACCESS }
|
||||||
|
- { path: ^/, roles: IS_AUTHENTICATED_FULLY }
|
||||||
|
|
||||||
|
role_hierarchy:
|
||||||
|
ROLE_ADMIN: [ROLE_USER]
|
||||||
|
|
||||||
|
when@test:
|
||||||
|
security:
|
||||||
|
password_hashers:
|
||||||
|
# Password hashers are resource-intensive by design to ensure security.
|
||||||
|
# In tests, it's safe to reduce their cost to improve performance.
|
||||||
|
Symfony\Component\Security\Core\User\PasswordAuthenticatedUserInterface:
|
||||||
|
algorithm: auto
|
||||||
|
cost: 4 # Lowest possible value for bcrypt
|
||||||
|
time_cost: 3 # Lowest possible value for argon
|
||||||
|
memory_cost: 10 # Lowest possible value for argon
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
framework:
|
||||||
|
default_locale: en
|
||||||
|
translator:
|
||||||
|
default_path: '%kernel.project_dir%/translations'
|
||||||
|
providers:
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
twig:
|
||||||
|
file_name_pattern: '*.twig'
|
||||||
|
|
||||||
|
when@test:
|
||||||
|
twig:
|
||||||
|
strict_variables: true
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
# Enable stateless CSRF protection for forms and logins/logouts
|
||||||
|
framework:
|
||||||
|
csrf_protection:
|
||||||
|
check_header: true
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
framework:
|
||||||
|
validation:
|
||||||
|
# Enables validator auto-mapping support.
|
||||||
|
# For instance, basic validation constraints will be inferred from Doctrine's metadata.
|
||||||
|
#auto_mapping:
|
||||||
|
# App\Entity\: []
|
||||||
|
|
||||||
|
when@test:
|
||||||
|
framework:
|
||||||
|
validation:
|
||||||
|
not_compromised_password: false
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
when@dev:
|
||||||
|
web_profiler:
|
||||||
|
toolbar: true
|
||||||
|
|
||||||
|
framework:
|
||||||
|
profiler: true
|
||||||
|
|
||||||
|
when@test:
|
||||||
|
framework:
|
||||||
|
profiler:
|
||||||
|
collect: false
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
foreach (glob(dirname(__DIR__).'/var/cache/prod/*.preload.php') ?: [] as $file) {
|
||||||
|
require $file;
|
||||||
|
}
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,11 @@
|
|||||||
|
# yaml-language-server: $schema=../vendor/symfony/routing/Loader/schema/routing.schema.json
|
||||||
|
|
||||||
|
# This file is the entry point to configure the routes of your app.
|
||||||
|
# Methods with the #[Route] attribute are automatically imported.
|
||||||
|
# See also https://symfony.com/doc/current/routing.html
|
||||||
|
|
||||||
|
# To list all registered routes, run the following command:
|
||||||
|
# bin/console debug:router
|
||||||
|
|
||||||
|
controllers:
|
||||||
|
resource: routing.controllers
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
when@dev:
|
||||||
|
_errors:
|
||||||
|
resource: '@FrameworkBundle/Resources/config/routing/errors.php'
|
||||||
|
prefix: /_error
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
_security_logout:
|
||||||
|
resource: security.route_loader.logout
|
||||||
|
type: service
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
when@dev:
|
||||||
|
web_profiler_wdt:
|
||||||
|
resource: '@WebProfilerBundle/Resources/config/routing/wdt.php'
|
||||||
|
prefix: /_wdt
|
||||||
|
|
||||||
|
web_profiler_profiler:
|
||||||
|
resource: '@WebProfilerBundle/Resources/config/routing/profiler.php'
|
||||||
|
prefix: /_profiler
|
||||||
@@ -0,0 +1,23 @@
|
|||||||
|
# yaml-language-server: $schema=../vendor/symfony/dependency-injection/Loader/schema/services.schema.json
|
||||||
|
|
||||||
|
# This file is the entry point to configure your own services.
|
||||||
|
# Files in the packages/ subdirectory configure your dependencies.
|
||||||
|
# See also https://symfony.com/doc/current/service_container/import.html
|
||||||
|
|
||||||
|
# Put parameters here that don't need to change on each machine where the app is deployed
|
||||||
|
# https://symfony.com/doc/current/best_practices.html#use-parameters-for-application-configuration
|
||||||
|
parameters:
|
||||||
|
|
||||||
|
services:
|
||||||
|
# default configuration for services in *this* file
|
||||||
|
_defaults:
|
||||||
|
autowire: true # Automatically injects dependencies in your services.
|
||||||
|
autoconfigure: true # Automatically registers your services as commands, event subscribers, etc.
|
||||||
|
|
||||||
|
# makes classes in src/ available to be used as services
|
||||||
|
# this creates a service per class whose id is the fully-qualified class name
|
||||||
|
App\:
|
||||||
|
resource: '../src/'
|
||||||
|
|
||||||
|
# add more service definitions when explicit configuration is needed
|
||||||
|
# please note that last definitions always *replace* previous ones
|
||||||
@@ -0,0 +1,75 @@
|
|||||||
|
# dmtools stack - servers only (testing + live). Not used locally.
|
||||||
|
#
|
||||||
|
# Reached only through the shared Nginx Proxy Manager, which terminates TLS for
|
||||||
|
# dmtools.fvandenberg.nl and forwards to the `nginx` container by name over the
|
||||||
|
# external `docker_default` network. Published host ports are bound to loopback
|
||||||
|
# for local curl / DB-client access on the server itself.
|
||||||
|
#
|
||||||
|
# Bring up with docker/setup.sh (pins the compose project name to `dmtools`).
|
||||||
|
|
||||||
|
services:
|
||||||
|
php:
|
||||||
|
build:
|
||||||
|
context: .
|
||||||
|
dockerfile: docker/php/Dockerfile
|
||||||
|
container_name: dmtools-php
|
||||||
|
env_file:
|
||||||
|
- path: .env
|
||||||
|
- path: .env.local
|
||||||
|
required: false
|
||||||
|
volumes:
|
||||||
|
- .:/var/www/html:cached
|
||||||
|
- php_var:/var/www/html/var
|
||||||
|
depends_on:
|
||||||
|
database:
|
||||||
|
condition: service_healthy
|
||||||
|
restart: unless-stopped
|
||||||
|
|
||||||
|
nginx:
|
||||||
|
image: nginx:1.30-alpine
|
||||||
|
container_name: dmtools-nginx
|
||||||
|
ports:
|
||||||
|
- "127.0.0.1:${NGINX_PORT:-8085}:80"
|
||||||
|
volumes:
|
||||||
|
- .:/var/www/html:ro
|
||||||
|
- ./docker/nginx/default.conf:/etc/nginx/conf.d/default.conf:ro
|
||||||
|
depends_on:
|
||||||
|
- php
|
||||||
|
networks:
|
||||||
|
- default
|
||||||
|
- proxy
|
||||||
|
restart: unless-stopped
|
||||||
|
|
||||||
|
database:
|
||||||
|
image: mariadb:12.3
|
||||||
|
container_name: dmtools-db
|
||||||
|
environment:
|
||||||
|
MARIADB_DATABASE: ${DB_NAME:-dmtools}
|
||||||
|
MARIADB_USER: ${DB_USER:-dmtools}
|
||||||
|
MARIADB_PASSWORD: ${DB_PASSWORD:-ChangeMe}
|
||||||
|
MARIADB_ROOT_PASSWORD: ${DB_ROOT_PASSWORD:-ChangeMeRoot}
|
||||||
|
command:
|
||||||
|
- --character-set-server=utf8mb4
|
||||||
|
- --collation-server=utf8mb4_unicode_ci
|
||||||
|
ports:
|
||||||
|
- "127.0.0.1:${DB_PORT:-3310}:3306"
|
||||||
|
volumes:
|
||||||
|
- database_data:/var/lib/mysql
|
||||||
|
healthcheck:
|
||||||
|
test: ["CMD", "healthcheck.sh", "--connect", "--innodb_initialized"]
|
||||||
|
interval: 10s
|
||||||
|
timeout: 5s
|
||||||
|
retries: 10
|
||||||
|
start_period: 30s
|
||||||
|
restart: unless-stopped
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
database_data:
|
||||||
|
php_var:
|
||||||
|
|
||||||
|
networks:
|
||||||
|
# Pre-existing network the server's Nginx Proxy Manager uses to reach backend
|
||||||
|
# containers. Created outside this stack - must already exist on the host.
|
||||||
|
proxy:
|
||||||
|
name: docker_default
|
||||||
|
external: true
|
||||||
@@ -0,0 +1,55 @@
|
|||||||
|
server {
|
||||||
|
listen 80;
|
||||||
|
# Only ever reached via the server's shared Nginx Proxy Manager, which
|
||||||
|
# terminates TLS and forwards traffic for this domain here - this container
|
||||||
|
# itself doesn't need to know about HTTPS or other domains.
|
||||||
|
server_name dmtools.fvandenberg.nl;
|
||||||
|
root /var/www/html/public;
|
||||||
|
|
||||||
|
location / {
|
||||||
|
try_files $uri /index.php$is_args$args;
|
||||||
|
}
|
||||||
|
|
||||||
|
location ~ ^/index\.php(/|$) {
|
||||||
|
# A plain "fastcgi_pass php:9000" resolves once at worker start and
|
||||||
|
# caches that IP forever - if the php container is recreated without
|
||||||
|
# also restarting nginx, every request 502s. Routing through a variable
|
||||||
|
# forces re-resolution per the resolver TTL. 127.0.0.11 is Compose's
|
||||||
|
# embedded DNS. Use the globally-unique container name, not the bare
|
||||||
|
# "php" alias: this nginx is also on the shared proxy network where
|
||||||
|
# another project may also have a service called "php".
|
||||||
|
resolver 127.0.0.11 valid=10s;
|
||||||
|
set $php_upstream dmtools-php:9000;
|
||||||
|
fastcgi_pass $php_upstream;
|
||||||
|
fastcgi_split_path_info ^(.+\.php)(/.*)$;
|
||||||
|
include fastcgi_params;
|
||||||
|
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
|
||||||
|
fastcgi_param DOCUMENT_ROOT $document_root;
|
||||||
|
|
||||||
|
# fastcgi_params never forwards Host - forward the real one explicitly.
|
||||||
|
fastcgi_param HTTP_HOST $http_host;
|
||||||
|
|
||||||
|
# fastcgi_pass does NOT auto-forward incoming headers. Without these,
|
||||||
|
# Symfony can't tell the original request was HTTPS and redirects to
|
||||||
|
# itself forever. if_not_empty: NPM omits some of these entirely, and an
|
||||||
|
# empty-but-present header can behave differently from an absent one.
|
||||||
|
fastcgi_param HTTP_X_FORWARDED_PROTO $http_x_forwarded_proto if_not_empty;
|
||||||
|
fastcgi_param HTTP_X_FORWARDED_FOR $http_x_forwarded_for if_not_empty;
|
||||||
|
fastcgi_param HTTP_X_FORWARDED_HOST $http_x_forwarded_host if_not_empty;
|
||||||
|
fastcgi_param HTTP_X_FORWARDED_PORT $http_x_forwarded_port if_not_empty;
|
||||||
|
|
||||||
|
fastcgi_read_timeout 120;
|
||||||
|
internal;
|
||||||
|
}
|
||||||
|
|
||||||
|
# Everything else under public/ (compiled assets, favicon, robots) is served
|
||||||
|
# straight off disk; only index.php is ever executed.
|
||||||
|
location ~ \.php$ {
|
||||||
|
return 404;
|
||||||
|
}
|
||||||
|
|
||||||
|
error_log /var/log/nginx/dmtools_error.log;
|
||||||
|
access_log /var/log/nginx/dmtools_access.log;
|
||||||
|
|
||||||
|
client_max_body_size 20M;
|
||||||
|
}
|
||||||
@@ -0,0 +1,43 @@
|
|||||||
|
FROM php:8.5-fpm-alpine
|
||||||
|
|
||||||
|
RUN apk add --no-cache \
|
||||||
|
bash \
|
||||||
|
git \
|
||||||
|
icu-dev \
|
||||||
|
libzip-dev \
|
||||||
|
zip \
|
||||||
|
unzip \
|
||||||
|
$PHPIZE_DEPS \
|
||||||
|
&& docker-php-ext-configure intl \
|
||||||
|
&& docker-php-ext-install -j"$(nproc)" \
|
||||||
|
intl \
|
||||||
|
pdo_mysql \
|
||||||
|
opcache \
|
||||||
|
zip \
|
||||||
|
&& apk del $PHPIZE_DEPS
|
||||||
|
|
||||||
|
COPY --from=composer:2 /usr/bin/composer /usr/bin/composer
|
||||||
|
|
||||||
|
COPY docker/php/php.ini /usr/local/etc/php/conf.d/app.ini
|
||||||
|
|
||||||
|
WORKDIR /var/www/html
|
||||||
|
|
||||||
|
COPY composer.json composer.lock symfony.lock ./
|
||||||
|
RUN composer install --no-interaction --no-scripts --no-autoloader --prefer-dist
|
||||||
|
|
||||||
|
COPY . .
|
||||||
|
RUN composer dump-autoload --optimize --classmap-authoritative
|
||||||
|
|
||||||
|
# var/ is a .dockerignore'd host concern and gets a named volume mounted over it
|
||||||
|
# at runtime; create + own it so php-fpm (www-data) can write cache/logs/sessions.
|
||||||
|
RUN mkdir -p var && chown -R www-data:www-data var
|
||||||
|
|
||||||
|
# /var/www/html is bind-mounted from the host at runtime, owned by whoever
|
||||||
|
# deployed it - keep git from refusing to touch it.
|
||||||
|
RUN git config --system --add safe.directory /var/www/html
|
||||||
|
|
||||||
|
USER www-data
|
||||||
|
|
||||||
|
EXPOSE 9000
|
||||||
|
|
||||||
|
CMD ["php-fpm"]
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
; dmtools - PHP-FPM runtime tuning (servers).
|
||||||
|
|
||||||
|
expose_php = Off
|
||||||
|
memory_limit = 256M
|
||||||
|
max_execution_time = 60
|
||||||
|
date.timezone = Europe/Amsterdam
|
||||||
|
|
||||||
|
upload_max_filesize = 20M
|
||||||
|
post_max_size = 21M
|
||||||
|
|
||||||
|
realpath_cache_size = 4096K
|
||||||
|
realpath_cache_ttl = 600
|
||||||
|
|
||||||
|
opcache.enable = 1
|
||||||
|
opcache.enable_cli = 0
|
||||||
|
opcache.memory_consumption = 128
|
||||||
|
opcache.max_accelerated_files = 20000
|
||||||
|
opcache.validate_timestamps = 0
|
||||||
|
opcache.preload_user = www-data
|
||||||
|
opcache.preload = /var/www/html/config/preload.php
|
||||||
Executable
+40
@@ -0,0 +1,40 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
# Fully restart the dmtools stack for this checkout (testing or live). Scoped to
|
||||||
|
# the compose project name, so running it from the test checkout never touches
|
||||||
|
# the prod stack.
|
||||||
|
#
|
||||||
|
# ./docker/restart.sh # down + rebuildless bring-up via setup.sh
|
||||||
|
# ./docker/restart.sh --prune-all # also run host-wide docker prune
|
||||||
|
|
||||||
|
DOCKER_DIR=$(cd "$(dirname "$0")" && pwd)
|
||||||
|
ROOT_DIR=$(cd "$DOCKER_DIR/.." && pwd)
|
||||||
|
PROJECT=dmtools
|
||||||
|
|
||||||
|
PRUNE_ALL=0
|
||||||
|
for arg in "$@"; do
|
||||||
|
case "$arg" in
|
||||||
|
--prune-all) PRUNE_ALL=1 ;;
|
||||||
|
*) echo "Unknown option: $arg" >&2; exit 1 ;;
|
||||||
|
esac
|
||||||
|
done
|
||||||
|
|
||||||
|
echo "Restarting stack: $PROJECT"
|
||||||
|
(cd "$ROOT_DIR" && docker compose -p "$PROJECT" -f docker-compose.yml down --remove-orphans) || true
|
||||||
|
|
||||||
|
docker rm -f dmtools-php dmtools-nginx dmtools-db 2>/dev/null || true
|
||||||
|
for net in $(docker network ls -q --filter "name=^${PROJECT}_" 2>/dev/null); do
|
||||||
|
docker network rm "$net" || true
|
||||||
|
done
|
||||||
|
|
||||||
|
if [ "$PRUNE_ALL" -eq 1 ]; then
|
||||||
|
echo "Host-wide prune..."
|
||||||
|
docker system prune -f || true
|
||||||
|
docker builder prune -af || true
|
||||||
|
else
|
||||||
|
echo "Skipping host-wide prune (pass --prune-all to force it)."
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "Running setup script..."
|
||||||
|
"$DOCKER_DIR/setup.sh" --no-build
|
||||||
Executable
+134
@@ -0,0 +1,134 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
# Bootstraps the Dockerized dmtools stack (php, nginx, database) on a server.
|
||||||
|
# - Builds and starts the containers
|
||||||
|
# - Installs composer dependencies
|
||||||
|
# - Ensures APP_SECRET is set (generated into .env.local if empty)
|
||||||
|
# - Creates and migrates the database
|
||||||
|
# - Installs + compiles AssetMapper assets
|
||||||
|
# - Prints helpful info on success
|
||||||
|
#
|
||||||
|
# Usage:
|
||||||
|
# ./docker/setup.sh # full setup
|
||||||
|
# ./docker/setup.sh --no-build # skip image rebuild
|
||||||
|
# ./docker/setup.sh --recreate # force-recreate containers
|
||||||
|
# ./docker/setup.sh --down # stop and remove containers
|
||||||
|
#
|
||||||
|
# NGINX_PORT=8086 ./docker/setup.sh # if 8085 is already taken on this host
|
||||||
|
# (or set NGINX_PORT / DB_PORT once in .env.local and every run picks it up)
|
||||||
|
|
||||||
|
ROOT_DIR=$(cd "$(dirname "$0")"/.. && pwd)
|
||||||
|
PROJECT=dmtools
|
||||||
|
|
||||||
|
for var in NGINX_PORT DB_PORT; do
|
||||||
|
if [ -z "${!var:-}" ] && grep -q "^${var}=" "$ROOT_DIR/.env.local" 2>/dev/null; then
|
||||||
|
export "$var=$(grep "^${var}=" "$ROOT_DIR/.env.local" | tail -1 | cut -d= -f2-)"
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
if docker compose version >/dev/null 2>&1; then
|
||||||
|
DOCKER_COMPOSE="docker compose"
|
||||||
|
elif command -v docker-compose >/dev/null 2>&1; then
|
||||||
|
DOCKER_COMPOSE="docker-compose"
|
||||||
|
else
|
||||||
|
echo "Error: Docker Compose not found." >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
dc() { (cd "$ROOT_DIR" && $DOCKER_COMPOSE -p "$PROJECT" -f docker-compose.yml "$@"); }
|
||||||
|
|
||||||
|
REBUILD=1
|
||||||
|
RECREATE=0
|
||||||
|
DOWN_ONLY=0
|
||||||
|
for arg in "$@"; do
|
||||||
|
case "$arg" in
|
||||||
|
--no-build) REBUILD=0 ;;
|
||||||
|
--recreate) RECREATE=1 ;;
|
||||||
|
--down) DOWN_ONLY=1 ;;
|
||||||
|
*) echo "Unknown option: $arg" >&2; exit 1 ;;
|
||||||
|
esac
|
||||||
|
done
|
||||||
|
|
||||||
|
command -v docker >/dev/null 2>&1 || { echo "Error: docker is required." >&2; exit 1; }
|
||||||
|
|
||||||
|
if [ ! -f "$ROOT_DIR/.env.local" ]; then
|
||||||
|
echo "Error: .env.local is missing. Copy .env to .env.local and set real" >&2
|
||||||
|
echo " APP_SECRET, DB_PASSWORD and DB_ROOT_PASSWORD first." >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ "$DOWN_ONLY" -eq 1 ]; then
|
||||||
|
dc down
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
# docker-compose v1 can choke recreating a container in place on any config
|
||||||
|
# change; removing them first sidesteps that. Safe: state lives in named volumes.
|
||||||
|
dc rm -fs php nginx database 2>/dev/null || true
|
||||||
|
|
||||||
|
BUILD_ARGS=()
|
||||||
|
[ "$REBUILD" -eq 1 ] && BUILD_ARGS+=("--build")
|
||||||
|
[ "$RECREATE" -eq 1 ] && BUILD_ARGS+=("--force-recreate")
|
||||||
|
|
||||||
|
dc up -d "${BUILD_ARGS[@]}"
|
||||||
|
|
||||||
|
# Setup one-offs run as root: the bind-mounted project dir is owned by the
|
||||||
|
# deploying user, not the image's www-data, so www-data can't write vendor/ etc.
|
||||||
|
pexec() { dc exec -T -u root php "$@"; }
|
||||||
|
|
||||||
|
printf "Waiting for database to be healthy..."
|
||||||
|
for i in {1..60}; do
|
||||||
|
id=$(dc ps -q database 2>/dev/null || true)
|
||||||
|
status=$([ -n "$id" ] && docker inspect -f '{{.State.Health.Status}}' "$id" 2>/dev/null || echo "")
|
||||||
|
if [ "$status" = "healthy" ]; then echo " OK"; break; fi
|
||||||
|
printf "."; sleep 2
|
||||||
|
[ "$i" -eq 60 ] && echo -e "\nWarning: database not healthy yet, continuing anyway."
|
||||||
|
done
|
||||||
|
|
||||||
|
pexec composer install --no-interaction
|
||||||
|
|
||||||
|
# Prod compiles config into a cached container under var/cache/prod/ (persistent
|
||||||
|
# php_var volume) and does NOT auto-detect config changes - clear it every run.
|
||||||
|
echo "Clearing and warming the cache..."
|
||||||
|
pexec php bin/console cache:clear --no-interaction
|
||||||
|
|
||||||
|
if grep -q '^APP_SECRET=$' "$ROOT_DIR/.env" 2>/dev/null \
|
||||||
|
&& ! grep -q '^APP_SECRET=' "$ROOT_DIR/.env.local" 2>/dev/null; then
|
||||||
|
echo "Generating APP_SECRET in .env.local..."
|
||||||
|
printf 'APP_SECRET=%s\n' "$(openssl rand -hex 16)" >> "$ROOT_DIR/.env.local"
|
||||||
|
dc up -d php # pick up the new env value
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "Creating database if it doesn't exist..."
|
||||||
|
pexec php bin/console doctrine:database:create --if-not-exists
|
||||||
|
|
||||||
|
echo "Running migrations..."
|
||||||
|
pexec php bin/console doctrine:migrations:migrate -n --allow-no-migration
|
||||||
|
|
||||||
|
echo "Installing and compiling assets..."
|
||||||
|
pexec php bin/console importmap:install
|
||||||
|
pexec php bin/console asset-map:compile
|
||||||
|
|
||||||
|
# LAST: the root-run commands above leave new files under var/ root-owned;
|
||||||
|
# php-fpm runs as www-data and must be able to write there at runtime.
|
||||||
|
pexec chown -R www-data:www-data var
|
||||||
|
|
||||||
|
APP_URL="http://localhost:${NGINX_PORT:-8085}"
|
||||||
|
cat <<EOT
|
||||||
|
|
||||||
|
Setup complete!
|
||||||
|
|
||||||
|
Open the app: $APP_URL (real access is via https://dmtools.fvandenberg.nl through NPM)
|
||||||
|
|
||||||
|
Create the first user:
|
||||||
|
$DOCKER_COMPOSE -p $PROJECT exec php php bin/console app:user:create you@example.com --admin
|
||||||
|
|
||||||
|
Common commands (from the project root):
|
||||||
|
$DOCKER_COMPOSE -p $PROJECT logs -f nginx
|
||||||
|
$DOCKER_COMPOSE -p $PROJECT logs -f php
|
||||||
|
$DOCKER_COMPOSE -p $PROJECT exec php bash
|
||||||
|
$DOCKER_COMPOSE -p $PROJECT down
|
||||||
|
|
||||||
|
Re-run this script any time. Use --no-build to skip rebuilding images.
|
||||||
|
EOT
|
||||||
@@ -0,0 +1,36 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Returns the importmap for this application.
|
||||||
|
*
|
||||||
|
* - "path" is a path inside the asset mapper system. Use the
|
||||||
|
* "debug:asset-map" command to see the full list of paths.
|
||||||
|
*
|
||||||
|
* - "entrypoint" (JavaScript only) set to true for any module that will
|
||||||
|
* be used as an "entrypoint" (and passed to the importmap() Twig function).
|
||||||
|
*
|
||||||
|
* The "importmap:require" command can be used to add new entries to this file.
|
||||||
|
*
|
||||||
|
* @return array<string, array{ // Import name as key, description of the imported file as value
|
||||||
|
* path: string, // Logical, relative or absolute path to the file
|
||||||
|
* type?: 'js'|'css'|'json', // Type of the file, defaults to 'js'
|
||||||
|
* entrypoint?: bool, // Whether the file is an entrypoint, for 'js' only
|
||||||
|
* }|array{
|
||||||
|
* version: string, // Version of the remote package
|
||||||
|
* package_specifier?: string, // Remote "package-name/path" specifier, defaults to the import name
|
||||||
|
* type?: 'js'|'css'|'json',
|
||||||
|
* entrypoint?: bool,
|
||||||
|
* }>
|
||||||
|
*/
|
||||||
|
return [
|
||||||
|
'app' => ['path' => './assets/app.js', 'entrypoint' => true],
|
||||||
|
'@hotwired/stimulus' => ['version' => '3.2.2'],
|
||||||
|
'@symfony/stimulus-bundle' => ['path' => './vendor/symfony/stimulus-bundle/assets/dist/loader.js'],
|
||||||
|
'@hotwired/turbo' => ['version' => '8.0.23'],
|
||||||
|
'bootstrap' => ['version' => '5.3.8'],
|
||||||
|
'@popperjs/core' => ['version' => '2.11.8'],
|
||||||
|
'datatables.net-bs5' => ['version' => '3.0.3'],
|
||||||
|
'datatables.net' => ['version' => '3.0.3'],
|
||||||
|
'bootstrap/dist/css/bootstrap.min.css' => ['version' => '5.3.8', 'type' => 'css'],
|
||||||
|
'datatables.net-bs5/css/dataTables.bootstrap5.min.css' => ['version' => '3.0.3', 'type' => 'css'],
|
||||||
|
];
|
||||||
@@ -0,0 +1,31 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace DoctrineMigrations;
|
||||||
|
|
||||||
|
use Doctrine\DBAL\Schema\Schema;
|
||||||
|
use Doctrine\Migrations\AbstractMigration;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Initial schema: `user` (form-login) and `messenger_messages` (async transport).
|
||||||
|
*/
|
||||||
|
final class Version20260906115952 extends AbstractMigration
|
||||||
|
{
|
||||||
|
public function getDescription(): string
|
||||||
|
{
|
||||||
|
return 'Initial schema: user and messenger_messages tables';
|
||||||
|
}
|
||||||
|
|
||||||
|
public function up(Schema $schema): void
|
||||||
|
{
|
||||||
|
$this->addSql('CREATE TABLE `user` (id INT AUTO_INCREMENT NOT NULL, email VARCHAR(180) NOT NULL, roles JSON NOT NULL, password VARCHAR(255) NOT NULL, UNIQUE INDEX UNIQ_8D93D649E7927C74 (email), PRIMARY KEY (id)) DEFAULT CHARACTER SET utf8mb4');
|
||||||
|
$this->addSql('CREATE TABLE messenger_messages (id BIGINT AUTO_INCREMENT NOT NULL, body LONGTEXT NOT NULL, headers LONGTEXT NOT NULL, queue_name VARCHAR(190) NOT NULL, created_at DATETIME NOT NULL, available_at DATETIME NOT NULL, delivered_at DATETIME DEFAULT NULL, INDEX IDX_75EA56E0FB7336F0E3BD61CE16BA31DBBF396750 (queue_name, available_at, delivered_at, id), PRIMARY KEY (id)) DEFAULT CHARACTER SET utf8mb4');
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(Schema $schema): void
|
||||||
|
{
|
||||||
|
$this->addSql('DROP TABLE `user`');
|
||||||
|
$this->addSql('DROP TABLE messenger_messages');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,44 @@
|
|||||||
|
<?xml version="1.0" encoding="UTF-8"?>
|
||||||
|
|
||||||
|
<!-- https://phpunit.readthedocs.io/en/latest/configuration.html -->
|
||||||
|
<phpunit xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
|
||||||
|
xsi:noNamespaceSchemaLocation="vendor/phpunit/phpunit/phpunit.xsd"
|
||||||
|
colors="true"
|
||||||
|
failOnDeprecation="true"
|
||||||
|
failOnNotice="true"
|
||||||
|
failOnWarning="true"
|
||||||
|
bootstrap="tests/bootstrap.php"
|
||||||
|
cacheDirectory=".phpunit.cache"
|
||||||
|
>
|
||||||
|
<php>
|
||||||
|
<ini name="display_errors" value="1" />
|
||||||
|
<ini name="error_reporting" value="-1" />
|
||||||
|
<server name="APP_ENV" value="test" force="true" />
|
||||||
|
<server name="SHELL_VERBOSITY" value="-1" />
|
||||||
|
</php>
|
||||||
|
|
||||||
|
<testsuites>
|
||||||
|
<testsuite name="Project Test Suite">
|
||||||
|
<directory>tests</directory>
|
||||||
|
</testsuite>
|
||||||
|
</testsuites>
|
||||||
|
|
||||||
|
<source ignoreSuppressionOfDeprecations="true"
|
||||||
|
ignoreIndirectDeprecations="true"
|
||||||
|
restrictNotices="true"
|
||||||
|
restrictWarnings="true"
|
||||||
|
>
|
||||||
|
<include>
|
||||||
|
<directory>src</directory>
|
||||||
|
</include>
|
||||||
|
|
||||||
|
<deprecationTrigger>
|
||||||
|
<method>Doctrine\Deprecations\Deprecation::trigger</method>
|
||||||
|
<method>Doctrine\Deprecations\Deprecation::delegateTriggerToBackend</method>
|
||||||
|
<function>trigger_deprecation</function>
|
||||||
|
</deprecationTrigger>
|
||||||
|
</source>
|
||||||
|
|
||||||
|
<extensions>
|
||||||
|
</extensions>
|
||||||
|
</phpunit>
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use App\Kernel;
|
||||||
|
|
||||||
|
require_once dirname(__DIR__).'/vendor/autoload_runtime.php';
|
||||||
|
|
||||||
|
return static function (array $context) {
|
||||||
|
return new Kernel($context['APP_ENV'], (bool) $context['APP_DEBUG']);
|
||||||
|
};
|
||||||
@@ -0,0 +1,84 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace App\Command;
|
||||||
|
|
||||||
|
use App\Entity\User;
|
||||||
|
use App\Repository\UserRepository;
|
||||||
|
use Doctrine\ORM\EntityManagerInterface;
|
||||||
|
use Symfony\Component\Console\Attribute\AsCommand;
|
||||||
|
use Symfony\Component\Console\Command\Command;
|
||||||
|
use Symfony\Component\Console\Input\InputArgument;
|
||||||
|
use Symfony\Component\Console\Input\InputInterface;
|
||||||
|
use Symfony\Component\Console\Input\InputOption;
|
||||||
|
use Symfony\Component\Console\Output\OutputInterface;
|
||||||
|
use Symfony\Component\Console\Style\SymfonyStyle;
|
||||||
|
use Symfony\Component\PasswordHasher\Hasher\UserPasswordHasherInterface;
|
||||||
|
use Symfony\Component\Validator\Validator\ValidatorInterface;
|
||||||
|
|
||||||
|
#[AsCommand(
|
||||||
|
name: 'app:user:create',
|
||||||
|
description: 'Create a dmtools user (there is no self-registration).',
|
||||||
|
)]
|
||||||
|
class CreateUserCommand extends Command
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
private readonly EntityManagerInterface $em,
|
||||||
|
private readonly UserRepository $users,
|
||||||
|
private readonly UserPasswordHasherInterface $hasher,
|
||||||
|
private readonly ValidatorInterface $validator,
|
||||||
|
) {
|
||||||
|
parent::__construct();
|
||||||
|
}
|
||||||
|
|
||||||
|
protected function configure(): void
|
||||||
|
{
|
||||||
|
$this
|
||||||
|
->addArgument('email', InputArgument::REQUIRED, 'Login email')
|
||||||
|
->addArgument('password', InputArgument::OPTIONAL, 'Password (prompted if omitted)')
|
||||||
|
->addOption('admin', null, InputOption::VALUE_NONE, 'Grant ROLE_ADMIN');
|
||||||
|
}
|
||||||
|
|
||||||
|
protected function execute(InputInterface $input, OutputInterface $output): int
|
||||||
|
{
|
||||||
|
$io = new SymfonyStyle($input, $output);
|
||||||
|
|
||||||
|
$email = (string) $input->getArgument('email');
|
||||||
|
$password = $input->getArgument('password');
|
||||||
|
|
||||||
|
if (null === $password || '' === $password) {
|
||||||
|
$password = $io->askHidden('Password');
|
||||||
|
}
|
||||||
|
if (null === $password || '' === $password) {
|
||||||
|
$io->error('A password is required.');
|
||||||
|
|
||||||
|
return Command::FAILURE;
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($this->users->findOneBy(['email' => $email])) {
|
||||||
|
$io->error(sprintf('A user with email "%s" already exists.', $email));
|
||||||
|
|
||||||
|
return Command::FAILURE;
|
||||||
|
}
|
||||||
|
|
||||||
|
$user = new User();
|
||||||
|
$user->setEmail($email);
|
||||||
|
$user->setRoles($input->getOption('admin') ? ['ROLE_ADMIN'] : []);
|
||||||
|
$user->setPassword($this->hasher->hashPassword($user, $password));
|
||||||
|
|
||||||
|
$violations = $this->validator->validate($user);
|
||||||
|
if (\count($violations) > 0) {
|
||||||
|
foreach ($violations as $violation) {
|
||||||
|
$io->error((string) $violation->getMessage());
|
||||||
|
}
|
||||||
|
|
||||||
|
return Command::FAILURE;
|
||||||
|
}
|
||||||
|
|
||||||
|
$this->em->persist($user);
|
||||||
|
$this->em->flush();
|
||||||
|
|
||||||
|
$io->success(sprintf('Created %s%s', $email, $input->getOption('admin') ? ' (admin)' : ''));
|
||||||
|
|
||||||
|
return Command::SUCCESS;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace App\Controller;
|
||||||
|
|
||||||
|
use Symfony\Bundle\FrameworkBundle\Controller\AbstractController;
|
||||||
|
use Symfony\Component\HttpFoundation\Response;
|
||||||
|
use Symfony\Component\Routing\Attribute\Route;
|
||||||
|
use Symfony\Component\Security\Http\Attribute\IsGranted;
|
||||||
|
|
||||||
|
#[IsGranted('IS_AUTHENTICATED_FULLY')]
|
||||||
|
class HomeController extends AbstractController
|
||||||
|
{
|
||||||
|
#[Route('/', name: 'app_home')]
|
||||||
|
public function index(): Response
|
||||||
|
{
|
||||||
|
return $this->render('home/index.html.twig');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace App\Controller;
|
||||||
|
|
||||||
|
use Symfony\Bundle\FrameworkBundle\Controller\AbstractController;
|
||||||
|
use Symfony\Component\HttpFoundation\Response;
|
||||||
|
use Symfony\Component\Routing\Attribute\Route;
|
||||||
|
use Symfony\Component\Security\Http\Authentication\AuthenticationUtils;
|
||||||
|
|
||||||
|
class SecurityController extends AbstractController
|
||||||
|
{
|
||||||
|
#[Route('/login', name: 'app_login')]
|
||||||
|
public function login(AuthenticationUtils $authenticationUtils): Response
|
||||||
|
{
|
||||||
|
if ($this->getUser()) {
|
||||||
|
return $this->redirectToRoute('app_home');
|
||||||
|
}
|
||||||
|
|
||||||
|
return $this->render('security/login.html.twig', [
|
||||||
|
'last_username' => $authenticationUtils->getLastUsername(),
|
||||||
|
'error' => $authenticationUtils->getLastAuthenticationError(),
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[Route('/logout', name: 'app_logout')]
|
||||||
|
public function logout(): never
|
||||||
|
{
|
||||||
|
throw new \LogicException('This method can be blank - it will be intercepted by the logout key on your firewall.');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,111 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace App\Entity;
|
||||||
|
|
||||||
|
use App\Repository\UserRepository;
|
||||||
|
use Doctrine\DBAL\Types\Types;
|
||||||
|
use Doctrine\ORM\Mapping as ORM;
|
||||||
|
use Symfony\Bridge\Doctrine\Validator\Constraints\UniqueEntity;
|
||||||
|
use Symfony\Component\Security\Core\User\PasswordAuthenticatedUserInterface;
|
||||||
|
use Symfony\Component\Security\Core\User\UserInterface;
|
||||||
|
|
||||||
|
#[ORM\Entity(repositoryClass: UserRepository::class)]
|
||||||
|
#[ORM\Table(name: '`user`')]
|
||||||
|
#[UniqueEntity(fields: ['email'], message: 'There is already an account with this email')]
|
||||||
|
class User implements UserInterface, PasswordAuthenticatedUserInterface
|
||||||
|
{
|
||||||
|
#[ORM\Id]
|
||||||
|
#[ORM\GeneratedValue]
|
||||||
|
#[ORM\Column]
|
||||||
|
private ?int $id = null;
|
||||||
|
|
||||||
|
#[ORM\Column(length: 180, unique: true)]
|
||||||
|
private ?string $email = null;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var list<string> The user roles
|
||||||
|
*/
|
||||||
|
#[ORM\Column(type: Types::JSON)]
|
||||||
|
private array $roles = [];
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @var string The hashed password
|
||||||
|
*/
|
||||||
|
#[ORM\Column]
|
||||||
|
private ?string $password = null;
|
||||||
|
|
||||||
|
public function getId(): ?int
|
||||||
|
{
|
||||||
|
return $this->id;
|
||||||
|
}
|
||||||
|
|
||||||
|
public function getEmail(): ?string
|
||||||
|
{
|
||||||
|
return $this->email;
|
||||||
|
}
|
||||||
|
|
||||||
|
public function setEmail(string $email): static
|
||||||
|
{
|
||||||
|
$this->email = $email;
|
||||||
|
|
||||||
|
return $this;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A visual identifier that represents this user.
|
||||||
|
*
|
||||||
|
* @see UserInterface
|
||||||
|
*/
|
||||||
|
public function getUserIdentifier(): string
|
||||||
|
{
|
||||||
|
return (string) $this->email;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @see UserInterface
|
||||||
|
*
|
||||||
|
* @return list<string>
|
||||||
|
*/
|
||||||
|
public function getRoles(): array
|
||||||
|
{
|
||||||
|
$roles = $this->roles;
|
||||||
|
// guarantee every user at least has ROLE_USER
|
||||||
|
$roles[] = 'ROLE_USER';
|
||||||
|
|
||||||
|
return array_values(array_unique($roles));
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param list<string> $roles
|
||||||
|
*/
|
||||||
|
public function setRoles(array $roles): static
|
||||||
|
{
|
||||||
|
$this->roles = $roles;
|
||||||
|
|
||||||
|
return $this;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @see PasswordAuthenticatedUserInterface
|
||||||
|
*/
|
||||||
|
public function getPassword(): ?string
|
||||||
|
{
|
||||||
|
return $this->password;
|
||||||
|
}
|
||||||
|
|
||||||
|
public function setPassword(string $password): static
|
||||||
|
{
|
||||||
|
$this->password = $password;
|
||||||
|
|
||||||
|
return $this;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @see UserInterface
|
||||||
|
*/
|
||||||
|
public function eraseCredentials(): void
|
||||||
|
{
|
||||||
|
// If you store any temporary, sensitive data on the user, clear it here
|
||||||
|
// $this->plainPassword = null;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace App;
|
||||||
|
|
||||||
|
use Symfony\Bundle\FrameworkBundle\Kernel\MicroKernelTrait;
|
||||||
|
use Symfony\Component\HttpKernel\Kernel as BaseKernel;
|
||||||
|
|
||||||
|
class Kernel extends BaseKernel
|
||||||
|
{
|
||||||
|
use MicroKernelTrait;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return list<string> An array of allowed values for APP_ENV
|
||||||
|
*/
|
||||||
|
private function getAllowedEnvs(): array
|
||||||
|
{
|
||||||
|
return ['prod', 'dev', 'test'];
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,35 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace App\Repository;
|
||||||
|
|
||||||
|
use App\Entity\User;
|
||||||
|
use Doctrine\Bundle\DoctrineBundle\Repository\ServiceEntityRepository;
|
||||||
|
use Doctrine\Persistence\ManagerRegistry;
|
||||||
|
use Symfony\Component\Security\Core\Exception\UnsupportedUserException;
|
||||||
|
use Symfony\Component\Security\Core\User\PasswordAuthenticatedUserInterface;
|
||||||
|
use Symfony\Component\Security\Core\User\PasswordUpgraderInterface;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @extends ServiceEntityRepository<User>
|
||||||
|
*/
|
||||||
|
class UserRepository extends ServiceEntityRepository implements PasswordUpgraderInterface
|
||||||
|
{
|
||||||
|
public function __construct(ManagerRegistry $registry)
|
||||||
|
{
|
||||||
|
parent::__construct($registry, User::class);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Used to upgrade (rehash) the user's password automatically over time.
|
||||||
|
*/
|
||||||
|
public function upgradePassword(PasswordAuthenticatedUserInterface $user, string $newHashedPassword): void
|
||||||
|
{
|
||||||
|
if (!$user instanceof User) {
|
||||||
|
throw new UnsupportedUserException(sprintf('Instances of "%s" are not supported.', $user::class));
|
||||||
|
}
|
||||||
|
|
||||||
|
$user->setPassword($newHashedPassword);
|
||||||
|
$this->getEntityManager()->persist($user);
|
||||||
|
$this->getEntityManager()->flush();
|
||||||
|
}
|
||||||
|
}
|
||||||
+327
@@ -0,0 +1,327 @@
|
|||||||
|
{
|
||||||
|
"doctrine/deprecations": {
|
||||||
|
"version": "1.1",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "1.0",
|
||||||
|
"ref": "fdd756167454623e21f1d769c5b814b243782a67"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"doctrine/doctrine-bundle": {
|
||||||
|
"version": "3.3",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "3.0",
|
||||||
|
"ref": "d39a3bd844edfe90c20ae520b804a3bf4f82b4ad"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./config/packages/doctrine.yaml",
|
||||||
|
"./src/Entity/.gitignore",
|
||||||
|
"./src/Repository/.gitignore"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"doctrine/doctrine-migrations-bundle": {
|
||||||
|
"version": "4.0",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "3.1",
|
||||||
|
"ref": "1d01ec03c6ecbd67c3375c5478c9a423ae5d6a33"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./config/packages/doctrine_migrations.yaml",
|
||||||
|
"./migrations/.gitignore"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"phpunit/phpunit": {
|
||||||
|
"version": "13.3",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "11.1",
|
||||||
|
"ref": "ca0bc067abfb40a8de1b2561b96cbfc2b833c314"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./.env.test",
|
||||||
|
"./phpunit.dist.xml",
|
||||||
|
"./tests/bootstrap.php",
|
||||||
|
"./bin/phpunit"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"symfony/asset-mapper": {
|
||||||
|
"version": "8.1",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "6.4",
|
||||||
|
"ref": "c01c47af2ec66a74ec046eccb919cfe27d3464ec"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./assets/app.js",
|
||||||
|
"./assets/styles/app.css",
|
||||||
|
"./config/packages/asset_mapper.yaml",
|
||||||
|
"./importmap.php"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"symfony/console": {
|
||||||
|
"version": "8.1",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "5.3",
|
||||||
|
"ref": "1781ff40d8a17d87cf53f8d4cf0c8346ed2bb461"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./bin/console"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"symfony/debug-bundle": {
|
||||||
|
"version": "8.1",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "5.3",
|
||||||
|
"ref": "5aa8aa48234c8eb6dbdd7b3cd5d791485d2cec4b"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./config/packages/debug.yaml"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"symfony/flex": {
|
||||||
|
"version": "2.11",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "2.4",
|
||||||
|
"ref": "52e9754527a15e2b79d9a610f98185a1fe46622a"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./.env",
|
||||||
|
"./.env.dev"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"symfony/form": {
|
||||||
|
"version": "8.1",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "7.2",
|
||||||
|
"ref": "7d86a6723f4a623f59e2bf966b6aad2fc461d36b"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./config/packages/csrf.yaml"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"symfony/framework-bundle": {
|
||||||
|
"version": "8.1",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "8.1",
|
||||||
|
"ref": "5295b2b1ef2170b272383b2b0ae0b66702883822"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./config/packages/cache.yaml",
|
||||||
|
"./config/packages/framework.yaml",
|
||||||
|
"./config/preload.php",
|
||||||
|
"./config/routes/framework.yaml",
|
||||||
|
"./config/services.yaml",
|
||||||
|
"./public/index.php",
|
||||||
|
"./src/Controller/.gitignore",
|
||||||
|
"./src/Kernel.php",
|
||||||
|
"./.editorconfig",
|
||||||
|
"./AGENTS.md",
|
||||||
|
"./CLAUDE.md"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"symfony/mailer": {
|
||||||
|
"version": "8.1",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "4.3",
|
||||||
|
"ref": "09051cfde49476e3c12cd3a0e44289ace1c75a4f"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./config/packages/mailer.yaml"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"symfony/maker-bundle": {
|
||||||
|
"version": "1.67",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "1.0",
|
||||||
|
"ref": "fadbfe33303a76e25cb63401050439aa9b1a9c7f"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"symfony/messenger": {
|
||||||
|
"version": "8.1",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "6.0",
|
||||||
|
"ref": "d8936e2e2230637ef97e5eecc0eea074eecae58b"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./config/packages/messenger.yaml"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"symfony/monolog-bundle": {
|
||||||
|
"version": "4.0",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "3.7",
|
||||||
|
"ref": "feb8fd9520b5694c7d0d2ba17fd4b4d33f9dd9cf"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./config/packages/monolog.yaml"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"symfony/notifier": {
|
||||||
|
"version": "8.1",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "5.0",
|
||||||
|
"ref": "178877daf79d2dbd62129dd03612cb1a2cb407cc"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./config/packages/notifier.yaml"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"symfony/property-info": {
|
||||||
|
"version": "8.1",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "7.3",
|
||||||
|
"ref": "dae70df71978ae9226ae915ffd5fad817f5ca1f7"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./config/packages/property_info.yaml"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"symfony/routing": {
|
||||||
|
"version": "8.1",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "7.4",
|
||||||
|
"ref": "bc94c4fd86f393f3ab3947c18b830ea343e51ded"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./config/packages/routing.yaml",
|
||||||
|
"./config/routes.yaml"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"symfony/security-bundle": {
|
||||||
|
"version": "8.1",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "7.4",
|
||||||
|
"ref": "c42fee7802181cdd50f61b8622715829f5d2335c"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./config/packages/security.yaml",
|
||||||
|
"./config/routes/security.yaml"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"symfony/stimulus-bundle": {
|
||||||
|
"version": "3.4",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "3.3",
|
||||||
|
"ref": "30f7461c215766d446f3c990b2b18f08ff51386e"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./assets/controllers.json",
|
||||||
|
"./assets/controllers/csrf_protection_controller.js",
|
||||||
|
"./assets/controllers/hello_controller.js",
|
||||||
|
"./assets/stimulus_bootstrap.js"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"symfony/translation": {
|
||||||
|
"version": "8.1",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "6.3",
|
||||||
|
"ref": "620a1b84865ceb2ba304c8f8bf2a185fbf32a843"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./config/packages/translation.yaml",
|
||||||
|
"./translations/.gitignore"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"symfony/twig-bundle": {
|
||||||
|
"version": "8.1",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "6.4",
|
||||||
|
"ref": "06dacf16872358cb1f2494e089070ff2d045233a"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./config/packages/twig.yaml",
|
||||||
|
"./templates/base.html.twig"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"symfony/ux-turbo": {
|
||||||
|
"version": "3.4",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "2.20",
|
||||||
|
"ref": "287f7c6eb6e9b65e422d34c00795b360a787380b"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./config/packages/ux_turbo.yaml"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"symfony/validator": {
|
||||||
|
"version": "8.1",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "7.0",
|
||||||
|
"ref": "8c1c4e28d26a124b0bb273f537ca8ce443472bfd"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./config/packages/validator.yaml"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"symfony/web-profiler-bundle": {
|
||||||
|
"version": "8.1",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "8.1",
|
||||||
|
"ref": "6bdd46f712bbed33a27130b6e055391cb1ab73d9"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./config/packages/web_profiler.yaml",
|
||||||
|
"./config/routes/web_profiler.yaml"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"symfony/webapp-pack": {
|
||||||
|
"version": "1.4",
|
||||||
|
"recipe": {
|
||||||
|
"repo": "github.com/symfony/recipes",
|
||||||
|
"branch": "main",
|
||||||
|
"version": "1.0",
|
||||||
|
"ref": "b9e6cc8e7b6069d0e8a816665809a423864eb4dd"
|
||||||
|
},
|
||||||
|
"files": [
|
||||||
|
"./config/packages/messenger.yaml"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"twig/extra-bundle": {
|
||||||
|
"version": "v3.24.0"
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,47 @@
|
|||||||
|
<!DOCTYPE html>
|
||||||
|
<html lang="en" data-bs-theme="dark">
|
||||||
|
<head>
|
||||||
|
<meta charset="UTF-8">
|
||||||
|
<meta name="viewport" content="width=device-width, initial-scale=1">
|
||||||
|
<title>{% block title %}dmtools{% endblock %}</title>
|
||||||
|
<link rel="icon" href="data:image/svg+xml,<svg xmlns=%22http://www.w3.org/2000/svg%22 viewBox=%220 0 128 128%22><text y=%221.1em%22 font-size=%22104%22>🎲</text></svg>">
|
||||||
|
|
||||||
|
{% block stylesheets %}{% endblock %}
|
||||||
|
|
||||||
|
{% block javascripts %}
|
||||||
|
{% block importmap %}{{ importmap('app') }}{% endblock %}
|
||||||
|
{% endblock %}
|
||||||
|
</head>
|
||||||
|
<body class="d-flex flex-column">
|
||||||
|
{% block navbar %}
|
||||||
|
<nav class="navbar navbar-expand-lg bg-body-tertiary border-bottom">
|
||||||
|
<div class="container">
|
||||||
|
<a class="navbar-brand" href="{{ path('app_home') }}">🎲 dmtools</a>
|
||||||
|
{% if app.user %}
|
||||||
|
<div class="d-flex align-items-center gap-3">
|
||||||
|
<span class="navbar-text small">{{ app.user.userIdentifier }}</span>
|
||||||
|
<a class="btn btn-outline-secondary btn-sm" href="{{ path('app_logout') }}">Log out</a>
|
||||||
|
</div>
|
||||||
|
{% endif %}
|
||||||
|
</div>
|
||||||
|
</nav>
|
||||||
|
{% endblock %}
|
||||||
|
|
||||||
|
<main class="app-main flex-grow-1">
|
||||||
|
<div class="container">
|
||||||
|
{% block flashes %}
|
||||||
|
{% for label, messages in app.flashes %}
|
||||||
|
{% for message in messages %}
|
||||||
|
<div class="alert alert-{{ label == 'error' ? 'danger' : label }} alert-dismissible fade show" role="alert">
|
||||||
|
{{ message }}
|
||||||
|
<button type="button" class="btn-close" data-bs-dismiss="alert" aria-label="Close"></button>
|
||||||
|
</div>
|
||||||
|
{% endfor %}
|
||||||
|
{% endfor %}
|
||||||
|
{% endblock %}
|
||||||
|
|
||||||
|
{% block body %}{% endblock %}
|
||||||
|
</div>
|
||||||
|
</main>
|
||||||
|
</body>
|
||||||
|
</html>
|
||||||
@@ -0,0 +1,39 @@
|
|||||||
|
{% extends 'base.html.twig' %}
|
||||||
|
|
||||||
|
{% block title %}Overview · dmtools{% endblock %}
|
||||||
|
|
||||||
|
{% block body %}
|
||||||
|
<div class="d-flex justify-content-between align-items-center mb-3">
|
||||||
|
<h1 class="h3 mb-0">Overview</h1>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<p class="text-body-secondary">
|
||||||
|
Starting point for the Monday-evening campaign tools. The table below is a
|
||||||
|
placeholder that shows the Bootstrap + DataTables layout wiring works
|
||||||
|
(search, sort, paging).
|
||||||
|
</p>
|
||||||
|
|
||||||
|
<div class="card shadow-sm">
|
||||||
|
<div class="card-body">
|
||||||
|
<table class="table table-striped table-hover align-middle datatable"
|
||||||
|
data-datatable-options='{"order": [[0, "asc"]]}'>
|
||||||
|
<thead>
|
||||||
|
<tr>
|
||||||
|
<th scope="col">Name</th>
|
||||||
|
<th scope="col">Type</th>
|
||||||
|
<th scope="col">Location</th>
|
||||||
|
<th scope="col">Notes</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
<tbody>
|
||||||
|
<tr><td>Seraphina Vane</td><td>NPC</td><td>Blackreach</td><td>Owes the party a favour</td></tr>
|
||||||
|
<tr><td>Goblin ambush</td><td>Encounter</td><td>Old Kings Road</td><td>CR 2, 6 goblins</td></tr>
|
||||||
|
<tr><td>The Sunken Vault</td><td>Location</td><td>Lake Nydra</td><td>Water-breathing required</td></tr>
|
||||||
|
<tr><td>Rusted Key</td><td>Item</td><td>Party inventory</td><td>Opens the vault antechamber</td></tr>
|
||||||
|
<tr><td>Captain Dorae</td><td>NPC</td><td>Saltmarsh docks</td><td>Will smuggle cargo for coin</td></tr>
|
||||||
|
<tr><td>Owlbear den</td><td>Encounter</td><td>Whisperwood</td><td>CR 3, mother + 2 cubs</td></tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
{% endblock %}
|
||||||
@@ -0,0 +1,44 @@
|
|||||||
|
{% extends 'base.html.twig' %}
|
||||||
|
|
||||||
|
{% block title %}Sign in · dmtools{% endblock %}
|
||||||
|
|
||||||
|
{% block navbar %}
|
||||||
|
<nav class="navbar bg-body-tertiary border-bottom">
|
||||||
|
<div class="container">
|
||||||
|
<span class="navbar-brand">🎲 dmtools</span>
|
||||||
|
</div>
|
||||||
|
</nav>
|
||||||
|
{% endblock %}
|
||||||
|
|
||||||
|
{% block body %}
|
||||||
|
<div class="card login-card shadow-sm">
|
||||||
|
<div class="card-body p-4">
|
||||||
|
<h1 class="h4 mb-3 text-center">Sign in</h1>
|
||||||
|
|
||||||
|
<form method="post">
|
||||||
|
{% if error %}
|
||||||
|
<div class="alert alert-danger" role="alert">
|
||||||
|
{{ error.messageKey|trans(error.messageData, 'security') }}
|
||||||
|
</div>
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
|
<div class="mb-3">
|
||||||
|
<label for="username" class="form-label">Email</label>
|
||||||
|
<input type="email" value="{{ last_username }}" name="_username" id="username"
|
||||||
|
class="form-control" autocomplete="email" required autofocus>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="mb-3">
|
||||||
|
<label for="password" class="form-label">Password</label>
|
||||||
|
<input type="password" name="_password" id="password"
|
||||||
|
class="form-control" autocomplete="current-password" required>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<input type="hidden" name="_csrf_token" data-controller="csrf-protection"
|
||||||
|
value="{{ csrf_token('authenticate') }}">
|
||||||
|
|
||||||
|
<button class="btn btn-primary w-100" type="submit">Sign in</button>
|
||||||
|
</form>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
{% endblock %}
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Symfony\Component\Dotenv\Dotenv;
|
||||||
|
|
||||||
|
require dirname(__DIR__).'/vendor/autoload.php';
|
||||||
|
|
||||||
|
if (method_exists(Dotenv::class, 'bootEnv')) {
|
||||||
|
(new Dotenv())->bootEnv(dirname(__DIR__).'/.env');
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($_SERVER['APP_DEBUG']) {
|
||||||
|
umask(0000);
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user