Current state with latest updates
This commit is contained in:
+52
-3
@@ -13,7 +13,6 @@ use Illuminate\Database\Eloquent\Relations\HasMany;
|
||||
use Illuminate\Database\Eloquent\Relations\HasOne;
|
||||
use Illuminate\Database\Eloquent\SoftDeletes;
|
||||
use Illuminate\Support\Facades\DB;
|
||||
use Illuminate\Support\Facades\Storage;
|
||||
use Laravel\Scout\Searchable;
|
||||
use Laravel\Scout\SearchableScope;
|
||||
|
||||
@@ -73,6 +72,8 @@ class Artwork extends Model
|
||||
'has_missing_thumbnails',
|
||||
'missing_thumbnail_variants_json',
|
||||
'thumbnails_checked_at',
|
||||
'featured_thumbnail_variants_json',
|
||||
'featured_thumbnails_checked_at',
|
||||
'file_size',
|
||||
'mime_type',
|
||||
'width',
|
||||
@@ -154,6 +155,8 @@ class Artwork extends Model
|
||||
'published_at' => 'datetime',
|
||||
'missing_thumbnail_variants_json' => 'array',
|
||||
'thumbnails_checked_at' => 'datetime',
|
||||
'featured_thumbnail_variants_json' => 'array',
|
||||
'featured_thumbnails_checked_at' => 'datetime',
|
||||
'published_as_type' => 'string',
|
||||
'published_as_id' => 'integer',
|
||||
'publish_at' => 'datetime',
|
||||
@@ -271,18 +274,64 @@ class Artwork extends Model
|
||||
?? 'https://files.skinbase.org/default/missing_xl.webp';
|
||||
}
|
||||
|
||||
/**
|
||||
* Audit state of `featured_thumbnail_variants_json`, distinguishing "never checked"
|
||||
* from "checked, nothing found":
|
||||
*
|
||||
* - `null` → not audited yet (FeaturedArtworkThumbnailGenerator has never
|
||||
* run plan()/generate() for this artwork).
|
||||
* - `[]` → audited, but no featured variant exists in object storage.
|
||||
* - non-empty string[] → audited; these variant names are known to exist.
|
||||
*
|
||||
* A value that fails to decode as an array (e.g. legacy/malformed data) is treated
|
||||
* the same as `null` — "not audited" — rather than throwing or reporting variants
|
||||
* that were never actually confirmed to exist.
|
||||
*
|
||||
* @return array{status: 'not_audited'|'no_variants'|'available', variants: list<string>}
|
||||
*/
|
||||
public function featuredThumbnailAuditState(): array
|
||||
{
|
||||
$raw = $this->featured_thumbnail_variants_json;
|
||||
|
||||
if (! is_array($raw)) {
|
||||
return ['status' => 'not_audited', 'variants' => []];
|
||||
}
|
||||
|
||||
$variants = array_values(array_filter($raw, 'is_string'));
|
||||
|
||||
if ($variants === []) {
|
||||
return ['status' => 'no_variants', 'variants' => []];
|
||||
}
|
||||
|
||||
return ['status' => 'available', 'variants' => $variants];
|
||||
}
|
||||
|
||||
/**
|
||||
* Whether a dedicated featured-hero variant is known to exist in object storage.
|
||||
*
|
||||
* This reads precomputed state from `featured_thumbnail_variants_json` (see
|
||||
* `featuredThumbnailAuditState()`) rather than checking the remote disk directly —
|
||||
* remote existence checks must only happen from `FeaturedArtworkThumbnailGenerator`
|
||||
* (admin commands / queued jobs), never during public homepage rendering, since a
|
||||
* live `Storage::exists()` per variant is a synchronous network round trip.
|
||||
*/
|
||||
public function hasFeaturedThumbnail(?string $variant = null): bool
|
||||
{
|
||||
if (empty($this->hash)) {
|
||||
return false;
|
||||
}
|
||||
|
||||
$known = $this->featuredThumbnailAuditState()['variants'];
|
||||
|
||||
if ($known === []) {
|
||||
return false;
|
||||
}
|
||||
|
||||
$helper = app(ArtworkFeaturedImagePath::class);
|
||||
$variants = $variant !== null ? [$helper->normalizeVariant($variant)] : $helper->variantNames();
|
||||
$disk = Storage::disk((string) config('uploads.object_storage.disk', 's3'));
|
||||
|
||||
foreach ($variants as $variantName) {
|
||||
if ($disk->exists($helper->objectPath($this, $variantName))) {
|
||||
if (in_array($variantName, $known, true)) {
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,160 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Models;
|
||||
|
||||
use Illuminate\Database\Eloquent\Model;
|
||||
use Illuminate\Database\Eloquent\Relations\BelongsTo;
|
||||
|
||||
final class SecurityReport extends Model
|
||||
{
|
||||
protected $fillable = [
|
||||
'status',
|
||||
'started_at',
|
||||
'finished_at',
|
||||
'composer_critical',
|
||||
'composer_high',
|
||||
'composer_medium',
|
||||
'composer_low',
|
||||
'composer_unknown',
|
||||
'npm_critical',
|
||||
'npm_high',
|
||||
'npm_moderate',
|
||||
'npm_low',
|
||||
'npm_info',
|
||||
'npm_unknown',
|
||||
'total_critical',
|
||||
'total_high',
|
||||
'total_medium',
|
||||
'total_low',
|
||||
'total_unknown',
|
||||
'composer_outdated_count',
|
||||
'npm_outdated_count',
|
||||
'summary',
|
||||
'composer_audit',
|
||||
'composer_outdated',
|
||||
'npm_audit',
|
||||
'npm_outdated',
|
||||
'error_message',
|
||||
'triggered_by',
|
||||
'user_id',
|
||||
];
|
||||
|
||||
protected function casts(): array
|
||||
{
|
||||
return [
|
||||
'started_at' => 'datetime',
|
||||
'finished_at' => 'datetime',
|
||||
'summary' => 'array',
|
||||
'composer_audit' => 'array',
|
||||
'composer_outdated' => 'array',
|
||||
'npm_audit' => 'array',
|
||||
'npm_outdated' => 'array',
|
||||
];
|
||||
}
|
||||
|
||||
public function user(): BelongsTo
|
||||
{
|
||||
return $this->belongsTo(User::class);
|
||||
}
|
||||
|
||||
public function hasCriticalFindings(): bool
|
||||
{
|
||||
return $this->total_critical > 0;
|
||||
}
|
||||
|
||||
public function hasHighFindings(): bool
|
||||
{
|
||||
return $this->total_high > 0;
|
||||
}
|
||||
|
||||
public function hasDangerFindings(): bool
|
||||
{
|
||||
return $this->hasCriticalFindings() || $this->hasHighFindings();
|
||||
}
|
||||
|
||||
public function getRiskLabelAttribute(): string
|
||||
{
|
||||
if ($this->total_critical > 0) {
|
||||
return 'Critical';
|
||||
}
|
||||
|
||||
if ($this->total_high > 0) {
|
||||
return 'High';
|
||||
}
|
||||
|
||||
if ($this->total_medium > 0) {
|
||||
return 'Medium';
|
||||
}
|
||||
|
||||
if ($this->total_low > 0) {
|
||||
return 'Low';
|
||||
}
|
||||
|
||||
return 'Clean';
|
||||
}
|
||||
|
||||
/**
|
||||
* @return array<int, array<string, mixed>>
|
||||
*/
|
||||
public function composerAdvisories(): array
|
||||
{
|
||||
$advisories = $this->composer_audit['advisories'] ?? [];
|
||||
$items = [];
|
||||
|
||||
foreach ($advisories as $package => $packageAdvisories) {
|
||||
if (! is_array($packageAdvisories)) {
|
||||
continue;
|
||||
}
|
||||
|
||||
foreach ($packageAdvisories as $advisory) {
|
||||
if (! is_array($advisory)) {
|
||||
continue;
|
||||
}
|
||||
|
||||
$items[] = [
|
||||
'package' => (string) $package,
|
||||
'severity' => strtolower((string) ($advisory['severity'] ?? 'unknown')),
|
||||
'title' => (string) ($advisory['title'] ?? $advisory['advisoryId'] ?? 'Unknown advisory'),
|
||||
'cve' => (string) ($advisory['cve'] ?? $advisory['link'] ?? ''),
|
||||
'affected_versions' => (string) ($advisory['affectedVersions'] ?? $advisory['affected_versions'] ?? ''),
|
||||
'reported_at' => (string) ($advisory['reportedAt'] ?? ''),
|
||||
'link' => (string) ($advisory['link'] ?? ''),
|
||||
];
|
||||
}
|
||||
}
|
||||
|
||||
return $items;
|
||||
}
|
||||
|
||||
/**
|
||||
* @return array<int, array<string, mixed>>
|
||||
*/
|
||||
public function npmVulnerabilities(): array
|
||||
{
|
||||
$vulnerabilities = $this->npm_audit['vulnerabilities'] ?? [];
|
||||
$items = [];
|
||||
|
||||
foreach ($vulnerabilities as $package => $vulnerability) {
|
||||
if (! is_array($vulnerability)) {
|
||||
continue;
|
||||
}
|
||||
|
||||
$via = collect((array) ($vulnerability['via'] ?? []))
|
||||
->first(fn (mixed $item): bool => is_array($item));
|
||||
|
||||
$items[] = [
|
||||
'package' => (string) $package,
|
||||
'severity' => strtolower((string) ($vulnerability['severity'] ?? 'unknown')),
|
||||
'title' => is_array($via) ? (string) ($via['title'] ?? 'Unknown advisory') : 'Unknown advisory',
|
||||
'cve' => is_array($via) ? (string) ($via['cve'] ?? '') : '',
|
||||
'range' => (string) ($vulnerability['range'] ?? ''),
|
||||
'fix_available' => is_array($vulnerability['fixAvailable'] ?? null) ? (string) (($vulnerability['fixAvailable']['name'] ?? '') . '@' . ($vulnerability['fixAvailable']['version'] ?? '')) : ((bool) ($vulnerability['fixAvailable'] ?? false) ? 'Yes' : ''),
|
||||
'url' => is_array($via) ? (string) ($via['url'] ?? '') : '',
|
||||
];
|
||||
}
|
||||
|
||||
return $items;
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user