Compare commits

...
2 Commits
Author SHA1 Message Date
klevze 8a80aae21e Ship production optimization M1-M12.5A: queues, metrics, HTTP observability, and vector search reliability.
Keep similar-ai from tripping the global circuit on a lone URL 502, clamp Qdrant search to 100, and add Server-Timing plus slow-request logging. Studio shared props, Academy S3 exists caching, heat chunking, and Redis/scheduler hygiene stay in this rollout.
2026-08-25 07:58:47 +02:00
klevze f52879edbb Current state with latest updates 2026-08-23 13:28:34 +02:00
178 changed files with 14445 additions and 1222 deletions
+41
View File
@@ -4,6 +4,15 @@ APP_KEY=
APP_DEBUG=true
APP_URL=http://localhost
SECURITY_REPORT_ENABLED=true
SECURITY_REPORT_NOTIFY_EMAIL=
SECURITY_REPORT_SCAN_NPM=true
SECURITY_REPORT_SCAN_COMPOSER=true
SECURITY_REPORT_STORE_RAW=true
SECURITY_REPORT_MAX_RAW_KB=512
SECURITY_REPORT_FAIL_ON_HIGH=false
SECURITY_REPORT_FAIL_ON_CRITICAL=false
APP_LOCALE=en
APP_FALLBACK_LOCALE=en
APP_FAKER_LOCALE=en_US
@@ -20,6 +29,11 @@ LOG_STACK=single
LOG_DEPRECATIONS_CHANNEL=null
LOG_LEVEL=debug
# M12 — slow Laravel HTTP log (threshold only; disable for zero overhead)
HTTP_SLOW_REQUEST_LOG_ENABLED=false
HTTP_SLOW_REQUEST_MS=750
HTTP_SLOW_REQUEST_LOG_DAYS=14
DB_CONNECTION=mysql
DB_HOST=127.0.0.1
DB_PORT=3306
@@ -52,6 +66,28 @@ SKINBASE_SESSION_DEBUG_HEADER=false
BROADCAST_CONNECTION=reverb
FILESYSTEM_DISK=local
QUEUE_CONNECTION=redis
# Must exceed Horizon supervisor-default timeout (960s). Production used 90s
# and nightly RecComputeSimilar* jobs failed with MaxAttemptsExceeded.
REDIS_QUEUE_RETRY_AFTER=1080
# Collection maintenance / forum AI jobs have no Horizon consumer.
# Leave false until a dedicated supervisor exists (M7).
COLLECTIONS_V5_DISPATCH_ENABLED=false
FORUM_QUEUE_DISPATCH_ENABLED=false
ONLINE_VISITOR_INDEX_READ_LIMIT=2000
ONLINE_VISITOR_INDEX_PRUNE_ENABLED=false
ONLINE_VISITOR_INDEX_PRUNE_SCAN_COUNT=500
ONLINE_VISITOR_INDEX_PRUNE_MAX_BATCHES=200
ONLINE_VISITOR_INDEX_PRUNE_SLEEP_MS=25
# RankBuildScopeListsJob unique lock (seconds). Must exceed queue wait + 300s timeout.
RANK_SCOPE_JOB_UNIQUE_FOR=21600
# Hourly artwork metric snapshots (heat / rising / monthly leaderboards).
# Production currently holds ~7 days because the scheduler passed --keep-days=7.
# Monthly leaderboards and Studio 30d views need 30 days of hourly history.
ARTWORK_METRIC_HOURLY_RETENTION_DAYS=30
ARTWORK_METRIC_HOURLY_PRUNE_CHUNK=5000
ARTWORK_METRIC_HOURLY_PRUNE_SLEEP_MS=50
MESSAGING_REALTIME=true
MESSAGING_BROADCAST_QUEUE=broadcasts
@@ -114,6 +150,11 @@ VISION_VECTOR_GATEWAY_RETRIES=1
VISION_VECTOR_GATEWAY_RETRY_DELAY_MS=250
VISION_VECTOR_GATEWAY_UPSERT_ENDPOINT=/vectors/upsert
VISION_VECTOR_GATEWAY_SEARCH_ENDPOINT=/vectors/search
VISION_VECTOR_GATEWAY_SEARCH_FILE_ENDPOINT=/vectors/search/file
VISION_VECTOR_GATEWAY_SEARCH_TIMEOUT=6
VISION_VECTOR_GATEWAY_SEARCH_CONNECT_TIMEOUT=2
VISION_VECTOR_GATEWAY_SEARCH_RETRIES=0
VISION_VECTOR_GATEWAY_CIRCUIT_SECONDS=30
VISION_VECTOR_GATEWAY_DELETE_ENDPOINT=/vectors/delete
VISION_VECTOR_GATEWAY_COLLECTIONS_ENDPOINT=/vectors/collections
+32 -2
View File
@@ -49,10 +49,10 @@ final class BuildSitemapsCommand extends Command
$t = microtime(true);
$this->line(' Building sitemap index…');
$index = $build->buildIndex(force: true, persist: false, families: $families);
$disk->put('sitemap.xml', $index['content']);
$disk->put('sitemaps/sitemap.xml', $index['content']);
$written++;
$this->line(sprintf(
' <info>✔</info> sitemap.xml %d entries <comment>%.3fs</comment>',
' <info>✔</info> sitemaps/sitemap.xml %d entries <comment>%.3fs</comment>',
$index['url_count'],
microtime(true) - $t,
));
@@ -112,6 +112,36 @@ final class BuildSitemapsCommand extends Command
));
}
foreach ($build->enabledGroupIndexes() as $groupName => $groupFamilies) {
foreach ($groupFamilies as $family) {
if (! in_array($family, $families, true)) {
continue 2;
}
}
$t = microtime(true);
$this->line(sprintf(' Building grouped sitemap %s…', $groupName));
$built = $build->buildNamed($groupName, force: true, persist: false);
if ($built === null) {
$this->line(sprintf(' <comment>–</comment> %s.xml <fg=red>SKIPPED</> (group builder returned null)', $groupName));
$failed++;
continue;
}
$disk->put('sitemaps/' . $groupName . '.xml', $built['content']);
$written++;
$this->line(sprintf(
' <info>✔</info> %s %d entries <comment>%.3fs</comment>',
$groupName . '.xml',
$built['url_count'] ?? 0,
microtime(true) - $t,
));
}
// ── Summary ───────────────────────────────────────────────────────
$this->newLine();
$this->info(sprintf(
@@ -18,6 +18,12 @@ class DispatchCollectionMaintenanceCommand extends Command
public function handle(CollectionBackgroundJobService $jobs): int
{
if (! (bool) config('collections.v5.queue.dispatch_enabled', false)) {
$this->warn('Collection maintenance dispatch is disabled (COLLECTIONS_V5_DISPATCH_ENABLED). No jobs queued.');
return self::SUCCESS;
}
$runHealth = (bool) $this->option('health');
$runRecommendations = (bool) $this->option('recommendations');
$runDuplicates = (bool) $this->option('duplicates');
@@ -48,13 +48,32 @@ final class GenerateSitemapsCommand extends Command
$this->newLine();
// ── Root sitemap index ────────────────────────────────────────────
// Write several paths so nginx `location = /sitemap.xml` and child
// listings stay in sync. `sitemaps/index.xml` is the canonical generated
// index: it is a new filename, so a scheduler user can create it even
// when a stale `sitemaps/sitemap.xml` is owned by another account.
$t = microtime(true);
$index = $build->buildIndex(force: true, persist: false, families: $families);
$disk->put('sitemaps/sitemap.xml', $index['content']);
$indexPaths = ['sitemaps/index.xml', 'sitemaps/sitemap.xml', 'sitemap.xml'];
$indexWritten = 0;
foreach ($indexPaths as $path) {
if ($this->writeXml($disk, $path, $index['content'])) {
$written++;
$indexWritten++;
}
}
if ($indexWritten === 0) {
$this->error('Failed to write any root sitemap index file. Check ownership of public/sitemap.xml and public/sitemaps/.');
return self::FAILURE;
}
$this->line(sprintf(
' <info>✔</info> sitemaps/sitemap.xml %d entries <comment>%.3fs</comment>',
' <info>✔</info> sitemap index %d entries %d path(s) <comment>%.3fs</comment>',
$index['url_count'],
$indexWritten,
microtime(true) - $t,
));
@@ -78,7 +97,12 @@ final class GenerateSitemapsCommand extends Command
}
$path = 'sitemaps/' . $documentName . '.xml';
$disk->put($path, $built['content']);
if (! $this->writeXml($disk, $path, $built['content'])) {
$this->line(sprintf(' <fg=red>✖</> %s write failed', $documentName . '.xml'));
$failed++;
continue;
}
$written++;
$this->line(sprintf(
@@ -96,6 +120,40 @@ final class GenerateSitemapsCommand extends Command
));
}
foreach ($build->enabledGroupIndexes() as $groupName => $groupFamilies) {
foreach ($groupFamilies as $family) {
if (! in_array($family, $families, true)) {
continue 2;
}
}
$t = microtime(true);
$built = $build->buildNamed($groupName, force: true, persist: false);
if ($built === null) {
$this->line(sprintf(' <comment>–</comment> %s.xml <fg=red>SKIPPED</> (group builder returned null)', $groupName));
$failed++;
continue;
}
$path = 'sitemaps/' . $groupName . '.xml';
if (! $this->writeXml($disk, $path, $built['content'])) {
$this->line(sprintf(' <fg=red>✖</> %s.xml write failed', $groupName));
$failed++;
continue;
}
$written++;
$this->line(sprintf(
' <info>✔</info> %s %d entries <comment>%.3fs</comment>',
$groupName . '.xml',
$built['url_count'] ?? 0,
microtime(true) - $t,
));
}
// ── Summary ───────────────────────────────────────────────────────
$this->newLine();
$this->info(sprintf(
@@ -130,4 +188,17 @@ final class GenerateSitemapsCommand extends Command
return array_values(array_filter($enabled, fn (string $f): bool => in_array($f, $only, true)));
}
private function writeXml(\Illuminate\Contracts\Filesystem\Filesystem $disk, string $path, string $content): bool
{
$ok = $disk->put($path, $content);
if ($ok !== true) {
$this->warn(' Could not write '.$path);
return false;
}
return true;
}
}
@@ -7,34 +7,137 @@ use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Log;
/**
* Prune old hourly metric snapshots to prevent unbounded table growth.
* Prune old hourly metric snapshots in bounded batches.
*
* Usage: php artisan nova:prune-metric-snapshots
* php artisan nova:prune-metric-snapshots --keep-days=7
* Usage:
* php artisan nova:prune-metric-snapshots
* php artisan nova:prune-metric-snapshots --keep-days=30 --chunk=5000 --dry-run
*/
class PruneMetricSnapshotsCommand extends Command
{
protected $signature = 'nova:prune-metric-snapshots
{--keep-days=7 : Keep snapshots for this many days}';
{--keep-days= : Keep snapshots for this many days (default: config metrics.hourly_snapshot_retention_days)}
{--chunk= : Rows to delete per batch (default: config metrics.hourly_snapshot_prune_chunk)}
{--sleep-ms= : Pause between batches in milliseconds}
{--max-batches=0 : Stop after N batches (0 = until done)}
{--dry-run : Count rows that would be deleted without deleting}';
protected $description = 'Delete old hourly metric snapshots beyond the retention window';
protected $description = 'Delete old hourly metric snapshots beyond the retention window (batched)';
public function handle(): int
{
$keepDays = (int) $this->option('keep-days');
$keepDays = $this->resolveKeepDays();
$chunk = $this->resolvePositiveInt('chunk', (int) config('metrics.hourly_snapshot_prune_chunk', 5000), 1);
$sleepMs = $this->resolveNonNegativeInt('sleep-ms', (int) config('metrics.hourly_snapshot_prune_sleep_ms', 50));
$maxBatches = max(0, (int) $this->option('max-batches'));
$dryRun = (bool) $this->option('dry-run');
$cutoff = now()->subDays($keepDays);
$deleted = DB::table('artwork_metric_snapshots_hourly')
if ($keepDays < 1) {
$this->error('keep-days must be >= 1.');
return self::FAILURE;
}
$eligible = (int) DB::table('artwork_metric_snapshots_hourly')
->where('bucket_hour', '<', $cutoff)
->delete();
->count();
$this->info("Pruned {$deleted} snapshot rows older than {$keepDays} days.");
$this->info(sprintf(
'[nova:prune-metric-snapshots] cutoff=%s keep_days=%d eligible=%d chunk=%d sleep_ms=%d max_batches=%s%s',
$cutoff->toDateTimeString(),
$keepDays,
$eligible,
$chunk,
$sleepMs,
$maxBatches === 0 ? 'unlimited' : (string) $maxBatches,
$dryRun ? ' (dry-run)' : ''
));
Log::info('[nova:prune-metric-snapshots] completed', [
'deleted' => $deleted,
if ($dryRun) {
Log::info('[nova:prune-metric-snapshots] dry-run', [
'eligible' => $eligible,
'keep_days' => $keepDays,
'cutoff' => $cutoff->toDateTimeString(),
]);
return self::SUCCESS;
}
$deleted = 0;
$batches = 0;
while (true) {
if ($maxBatches > 0 && $batches >= $maxBatches) {
$this->warn("Stopped after max-batches={$maxBatches}.");
break;
}
$ids = DB::table('artwork_metric_snapshots_hourly')
->where('bucket_hour', '<', $cutoff)
->orderBy('id')
->limit($chunk)
->pluck('id');
if ($ids->isEmpty()) {
break;
}
$batchDeleted = DB::table('artwork_metric_snapshots_hourly')
->whereIn('id', $ids->all())
->delete();
$deleted += $batchDeleted;
$batches++;
Log::info('[nova:prune-metric-snapshots] batch', [
'batch' => $batches,
'deleted' => $batchDeleted,
'deleted_total' => $deleted,
]);
if ($sleepMs > 0) {
usleep($sleepMs * 1000);
}
}
$this->info("Pruned {$deleted} snapshot rows older than {$keepDays} days in {$batches} batch(es).");
Log::info('[nova:prune-metric-snapshots] completed', [
'deleted' => $deleted,
'batches' => $batches,
'keep_days' => $keepDays,
'cutoff' => $cutoff->toDateTimeString(),
'eligible_at_start' => $eligible,
]);
return self::SUCCESS;
}
private function resolveKeepDays(): int
{
$option = $this->option('keep-days');
if ($option === null || $option === '') {
return (int) config('metrics.hourly_snapshot_retention_days', 30);
}
return (int) $option;
}
private function resolvePositiveInt(string $option, int $default, int $minimum): int
{
$raw = $this->option($option);
$value = ($raw === null || $raw === '') ? $default : (int) $raw;
return max($minimum, $value);
}
private function resolveNonNegativeInt(string $option, int $default): int
{
$raw = $this->option($option);
$value = ($raw === null || $raw === '') ? $default : (int) $raw;
return max(0, $value);
}
}
@@ -0,0 +1,88 @@
<?php
declare(strict_types=1);
namespace App\Console\Commands;
use App\Services\Traffic\OnlineVisitorRepository;
use App\Services\Traffic\PresenceIndexPruner;
use Illuminate\Console\Command;
use Illuminate\Support\Facades\Log;
use Illuminate\Support\Facades\Redis;
class PruneOnlineVisitorIndexCommand extends Command
{
protected $signature = 'skinbase:prune-online-visitor-index
{--dry-run : Count stale members without SREM}
{--execute : Remove stale members}
{--scan-count= : SSCAN COUNT}
{--max-batches= : Batches this run}
{--max-members= : Members to inspect this run}
{--sleep-ms= : Pause between batches}
{--time-limit= : Stop after N seconds (0 = none)}';
protected $description = 'Remove stale members from the online-visitor Redis set (SSCAN, never SMEMBERS)';
public function handle(PresenceIndexPruner $pruner): int
{
$dryRun = (bool) $this->option('dry-run');
$execute = (bool) $this->option('execute');
if ($dryRun === $execute) {
$this->error('Pass exactly one of --dry-run or --execute.');
return self::FAILURE;
}
$scanCount = $this->intOption('scan-count', (int) config('traffic.online_visitors.prune_scan_count', 500));
$maxBatches = $this->intOption('max-batches', (int) config('traffic.online_visitors.prune_max_batches', 200));
$maxMembers = $this->intOption('max-members', (int) config('traffic.online_visitors.prune_max_members', 100000));
$sleepMs = $this->intOption('sleep-ms', (int) config('traffic.online_visitors.prune_sleep_ms', 25));
$timeLimit = $this->intOption('time-limit', 0);
$scard = (int) Redis::scard(OnlineVisitorRepository::INDEX_KEY);
$this->info(sprintf(
'[prune-online-visitor-index] key=%s prefix=%s scard=%d scan_count=%d max_batches=%d max_members=%d sleep_ms=%d %s',
OnlineVisitorRepository::INDEX_KEY,
(string) config('database.redis.options.prefix'),
$scard,
$scanCount,
$maxBatches,
$maxMembers,
$sleepMs,
$dryRun ? 'dry-run' : 'execute'
));
$result = $pruner->prune(
$scanCount,
$maxBatches,
$maxMembers,
$sleepMs,
$dryRun,
$timeLimit > 0 ? $timeLimit : null,
);
$this->info(sprintf(
'scanned=%d stale=%d live=%d removed=%d batches=%d',
$result['scanned'],
$result['stale'],
$result['live'],
$result['removed'],
$result['batches']
));
Log::info('[prune-online-visitor-index] completed', $result + ['scard_before' => $scard]);
return self::SUCCESS;
}
private function intOption(string $name, int $default): int
{
$raw = $this->option($name);
if ($raw === null || $raw === '') {
return $default;
}
return max(0, (int) $raw);
}
}
@@ -0,0 +1,94 @@
<?php
declare(strict_types=1);
namespace App\Console\Commands;
use App\Jobs\RecComputeSimilarByTagsJob;
use App\Support\Queues\QueuedJobClassMatcher;
use Illuminate\Console\Command;
use Illuminate\Support\Facades\Log;
use Illuminate\Support\Facades\Redis;
/**
* Deployment cleanup: remove waiting RecComputeSimilarByTagsJob payloads only.
*
* Does not run from the scheduler. Operator must pass --dry-run or --execute.
*
* Usage:
* php artisan skinbase:purge-queued-rec-tags --dry-run
* php artisan skinbase:purge-queued-rec-tags --execute
*/
class PurgeQueuedRecComputeTagsCommand extends Command
{
protected $signature = 'skinbase:purge-queued-rec-tags
{--queue=default : Redis queue name (waiting list only)}
{--dry-run : Count matches without removing}
{--execute : Remove matched waiting payloads}';
protected $description = 'Remove waiting RecComputeSimilarByTagsJob payloads from a Redis queue (opt-in)';
public function handle(): int
{
$dryRun = (bool) $this->option('dry-run');
$execute = (bool) $this->option('execute');
if ($dryRun === $execute) {
$this->error('Pass exactly one of --dry-run or --execute.');
return self::FAILURE;
}
$queue = (string) $this->option('queue');
if (! preg_match('/^[A-Za-z0-9_-]+$/', $queue)) {
$this->error('Invalid queue name.');
return self::FAILURE;
}
$key = 'queues:'.$queue;
$target = RecComputeSimilarByTagsJob::class;
$redis = Redis::connection();
$len = (int) $redis->llen($key);
$matchedPayloads = [];
$chunk = 200;
$this->info(sprintf(
'[purge-queued-rec-tags] queue=%s waiting=%d target=%s %s',
$queue,
$len,
$target,
$dryRun ? 'dry-run' : 'execute'
));
for ($start = 0; $start < $len; $start += $chunk) {
$rows = $redis->lrange($key, $start, min($start + $chunk - 1, $len - 1));
foreach ($rows as $raw) {
if (QueuedJobClassMatcher::isClass((string) $raw, $target)) {
$matchedPayloads[] = (string) $raw;
}
}
}
$matched = count($matchedPayloads);
$removed = 0;
if (! $dryRun) {
foreach ($matchedPayloads as $raw) {
$removed += (int) $redis->lrem($key, 1, $raw);
}
}
$this->info(sprintf('matched=%d removed=%d preserved_other=%s', $matched, $removed, $dryRun ? 'yes' : 'yes'));
Log::info('[purge-queued-rec-tags] completed', [
'queue' => $queue,
'waiting' => $len,
'matched' => $matched,
'removed' => $removed,
'dry_run' => $dryRun,
]);
return self::SUCCESS;
}
}
@@ -57,7 +57,7 @@ class RecalculateHeatCommand extends Command
$updatedCount = 0;
$skippedCount = 0;
// Process in chunks using artwork IDs that have at least one snapshot in the smoothing window
// Distinct IDs only — do not hydrate the full 24h snapshot window in one query.
$artworkIds = DB::table('artwork_metric_snapshots_hourly')
->whereBetween('bucket_hour', [$lookbackStart, $currentHour])
->distinct()
@@ -68,17 +68,25 @@ class RecalculateHeatCommand extends Command
return self::SUCCESS;
}
// Load all snapshots for the lookback window in bulk
foreach ($artworkIds->chunk($chunk) as $chunkIds) {
$snapshots = DB::table('artwork_metric_snapshots_hourly')
->select([
'artwork_id',
'bucket_hour',
'views_count',
'downloads_count',
'favourites_count',
'comments_count',
'shares_count',
])
->whereBetween('bucket_hour', [$lookbackStart, $currentHour])
->whereIn('artwork_id', $artworkIds)
->whereIn('artwork_id', $chunkIds)
->orderBy('bucket_hour')
->get()
->groupBy('artwork_id');
// Load artwork published_at dates for age factor (use published_at, fall back to created_at)
$artworkDates = DB::table('artworks')
->whereIn('id', $artworkIds)
->whereIn('id', $chunkIds)
->whereNull('deleted_at')
->where('is_approved', true)
->select('id', 'published_at', 'created_at')
@@ -87,8 +95,6 @@ class RecalculateHeatCommand extends Command
$row->id => \Carbon\Carbon::parse($row->published_at ?? $row->created_at),
]);
// Process in chunks
foreach ($artworkIds->chunk($chunk) as $chunkIds) {
$upsertRows = [];
foreach ($chunkIds as $artworkId) {
@@ -0,0 +1,139 @@
<?php
declare(strict_types=1);
namespace App\Console\Commands;
use Illuminate\Console\Command;
use Illuminate\Support\Facades\Log;
use Predis\Client as PredisClient;
class RedisCleanupLegacyPrefixCommand extends Command
{
protected $signature = 'skinbase:redis-cleanup-legacy-prefix
{--dry-run : SCAN and report only}
{--execute : UNLINK matching obsolete keys}
{--max-keys=500 : Cap keys this run}';
protected $description = 'UNLINK obsolete skinbasenova-database-* and skinbasenova_horizon:* keys only';
private const LEGACY_PREFIXES = [
'skinbasenova-database-',
'skinbasenova_horizon:',
];
private const PROTECTED_PREFIXES = [
'skinbase-database-',
'skinbase_horizon:',
];
public function handle(): int
{
$dryRun = (bool) $this->option('dry-run');
$execute = (bool) $this->option('execute');
if ($dryRun === $execute) {
$this->error('Pass exactly one of --dry-run or --execute.');
return self::FAILURE;
}
$maxKeys = max(1, (int) $this->option('max-keys'));
$currentPrefix = (string) config('database.redis.options.prefix');
$horizonPrefix = (string) config('horizon.prefix');
$this->info(sprintf(
'[redis-cleanup-legacy-prefix] current_prefix=%s horizon_prefix=%s max_keys=%d %s',
$currentPrefix,
$horizonPrefix,
$maxKeys,
$dryRun ? 'dry-run' : 'execute'
));
if (in_array($currentPrefix, self::LEGACY_PREFIXES, true) || in_array($horizonPrefix, self::LEGACY_PREFIXES, true)) {
$this->error('Current process still uses a legacy prefix. Aborting.');
return self::FAILURE;
}
$client = $this->unprefixedClient();
$found = [];
$cursor = '0';
do {
[$cursor, $keys] = $client->scan($cursor, ['COUNT' => 200, 'MATCH' => '*']);
foreach ($keys as $key) {
$key = (string) $key;
if ($this->isProtected($key)) {
continue;
}
if (! $this->isLegacy($key)) {
continue;
}
$found[] = $key;
if (count($found) >= $maxKeys) {
$cursor = '0';
break;
}
}
} while ($cursor !== '0' && $cursor !== 0);
$this->info('matched='.count($found));
foreach (array_slice($found, 0, 20) as $key) {
$this->line('key='.$key);
}
if (count($found) > 20) {
$this->line('... truncated listing');
}
$unlinked = 0;
if (! $dryRun && $found !== []) {
foreach (array_chunk($found, 50) as $chunk) {
$unlinked += (int) $client->unlink(...$chunk);
}
}
$this->info('unlinked='.$unlinked);
Log::info('[redis-cleanup-legacy-prefix] completed', [
'matched' => count($found),
'unlinked' => $unlinked,
'dry_run' => $dryRun,
]);
return self::SUCCESS;
}
private function isLegacy(string $key): bool
{
foreach (self::LEGACY_PREFIXES as $prefix) {
if (str_starts_with($key, $prefix)) {
return true;
}
}
return false;
}
private function isProtected(string $key): bool
{
foreach (self::PROTECTED_PREFIXES as $prefix) {
if (str_starts_with($key, $prefix)) {
return true;
}
}
return false;
}
private function unprefixedClient(): PredisClient
{
$redis = config('database.redis.default', []);
return new PredisClient([
'scheme' => 'tcp',
'host' => $redis['host'] ?? '127.0.0.1',
'port' => (int) ($redis['port'] ?? 6379),
'password' => $redis['password'] ?? null,
'database' => (int) ($redis['database'] ?? 0),
]);
}
}
@@ -0,0 +1,79 @@
<?php
declare(strict_types=1);
namespace App\Console\Commands;
use App\Support\Redis\OrphanQueueCleanup;
use Illuminate\Console\Command;
use Illuminate\Support\Facades\Log;
use RuntimeException;
class RedisCleanupOrphansCommand extends Command
{
protected $signature = 'skinbase:redis-cleanup-orphans
{target : forum-moderation, forum-security, or collections}
{--dry-run : Inspect and report without UNLINK}
{--execute : UNLINK the waiting queue and notify list}
{--force : Allow unexpected sampled job classes}';
protected $description = 'UNLINK an orphan Redis queue after producer and class checks (operator only)';
public function handle(OrphanQueueCleanup $cleanup): int
{
$dryRun = (bool) $this->option('dry-run');
$execute = (bool) $this->option('execute');
if ($dryRun === $execute) {
$this->error('Pass exactly one of --dry-run or --execute.');
return self::FAILURE;
}
$target = (string) $this->argument('target');
$force = (bool) $this->option('force');
$this->info(sprintf(
'[redis-cleanup-orphans] prefix=%s connection=default target=%s force=%s mode=%s',
(string) config('database.redis.options.prefix'),
$target,
$force ? 'yes' : 'no',
$dryRun ? 'dry-run' : 'execute'
));
try {
$plan = $execute
? $cleanup->execute($target, $force)
: $cleanup->plan($target, $force);
} catch (RuntimeException $e) {
$this->error($e->getMessage());
Log::warning('[redis-cleanup-orphans] refused', ['target' => $target, 'error' => $e->getMessage()]);
return self::FAILURE;
}
$this->line('logical_key='.$plan['logical_key']);
$this->line('notify_key='.$plan['notify_key']);
$this->line('llen='.$plan['llen'].' reserved='.$plan['reserved'].' delayed='.$plan['delayed']);
$this->line('sampled='.$plan['sampled'].' est_bytes='.$plan['est_bytes']);
$this->line('classes='.json_encode($plan['classes']));
if ($plan['unexpected_classes'] !== []) {
$this->warn('unexpected_classes='.json_encode($plan['unexpected_classes']));
}
if ($plan['errors'] !== []) {
$this->error('errors='.implode(',', $plan['errors']));
}
if ($execute) {
$this->info('unlinked='.($plan['unlinked'] ?? 0));
}
Log::info('[redis-cleanup-orphans] completed', [
'target' => $target,
'dry_run' => $dryRun,
'llen' => $plan['llen'],
'errors' => $plan['errors'],
'unlinked' => $plan['unlinked'] ?? 0,
]);
return ($plan['errors'] === [] || $dryRun) ? self::SUCCESS : self::FAILURE;
}
}
@@ -0,0 +1,83 @@
<?php
declare(strict_types=1);
namespace App\Console\Commands;
use App\Notifications\SecurityReportDangerNotification;
use App\Services\SecurityReport\SecurityReportScanner;
use Illuminate\Console\Command;
use Illuminate\Support\Facades\Notification;
final class SecurityReportScanCommand extends Command
{
protected $signature = 'security:scan
{--notify : Send configured email notification when high or critical findings exist}
{--triggered-by=artisan : Mark the scan source}
{--user-id= : Associate the scan with a specific user id}';
protected $description = 'Run Composer and npm security audits and store a private admin report.';
public function handle(SecurityReportScanner $scanner): int
{
if (! (bool) config('security-report.enabled', true)) {
$this->warn('Security report scanning is disabled.');
return self::INVALID;
}
$this->info('Running security report scan...');
$report = $scanner->scan(
(string) $this->option('triggered-by'),
$this->option('user-id') !== null ? (int) $this->option('user-id') : null,
);
if ($report->status === 'failed') {
$this->error('Security scan failed: ' . (string) ($report->error_message ?? 'Unknown error'));
return self::FAILURE;
}
$this->table(
['Status', 'Critical', 'High', 'Medium', 'Low', 'Unknown', 'Composer outdated', 'npm outdated'],
[[
$report->status,
$report->total_critical,
$report->total_high,
$report->total_medium,
$report->total_low,
$report->total_unknown,
$report->composer_outdated_count,
$report->npm_outdated_count,
]],
);
if ((bool) $this->option('notify') && $report->hasDangerFindings()) {
$this->sendDangerNotification($report);
$this->info('Danger notification sent.');
}
if ($report->hasCriticalFindings() && (bool) config('security-report.fail_on.critical', false)) {
return self::FAILURE;
}
if ($report->hasHighFindings() && (bool) config('security-report.fail_on.high', false)) {
return self::FAILURE;
}
return self::SUCCESS;
}
private function sendDangerNotification(\App\Models\SecurityReport $report): void
{
$email = trim((string) config('security-report.notify_email', ''));
if ($email === '') {
return;
}
Notification::route('mail', $email)
->notify(new SecurityReportDangerNotification($report));
}
}
@@ -363,8 +363,17 @@ final class AcademyBillingController extends Controller
/** @var User|null $user */
$user = $request->user();
$currentTier = $this->access->currentTier($user);
$seo = \app(SeoFactory::class)
->simplePage(
'Academy Subscription Confirmed — Skinbase',
'Payment confirmation for your Skinbase Academy subscription.',
\route('academy.billing.success'),
false,
)
->toArray();
return \Inertia\Inertia::render('Academy/Billing/Success', [
'seo' => $seo,
'message' => 'Payment is being confirmed. Your access will update automatically.',
'currentTier' => $currentTier,
'isSubscribed' => $user instanceof User ? $this->access->hasActiveAcademySubscription($user) : false,
@@ -381,8 +390,17 @@ final class AcademyBillingController extends Controller
public function cancel(): \Inertia\Response
{
\abort_unless((bool) \config('academy.enabled', true), 404);
$seo = \app(SeoFactory::class)
->simplePage(
'Academy Billing Canceled — Skinbase',
'Checkout was canceled before starting a Skinbase Academy subscription.',
\route('academy.billing.cancel'),
false,
)
->toArray();
return \Inertia\Inertia::render('Academy/Billing/Cancel', [
'seo' => $seo,
'message' => 'Checkout was canceled. No payment was made.',
'links' => [
'pricing' => \route('academy.pricing'),
@@ -495,10 +513,19 @@ final class AcademyBillingController extends Controller
/** @var User $user */
$user = $request->user();
$subscription = $this->academySubscription($user);
$seo = \app(SeoFactory::class)
->simplePage(
'Academy Subscription Account — Skinbase',
'Manage your Skinbase Academy subscription and billing access.',
\route('academy.billing.account'),
false,
)
->toArray();
$activePlan = $this->activePlan($user);
return \Inertia\Inertia::render('Academy/Billing/Account', [
'seo' => $seo,
'currentTier' => $this->access->currentTier($user),
'isSubscribed' => $this->access->hasActiveAcademySubscription($user),
'activePlan' => $activePlan ? [
@@ -10,6 +10,7 @@ use App\Services\Academy\AcademyAccessService;
use App\Services\Academy\AcademyInteractionService;
use App\Support\AcademyAnalytics\AcademyAnalyticsContentType;
use App\Support\Seo\SeoFactory;
use App\Support\Seo\SeoDataBuilder;
use Illuminate\Http\Request;
use Illuminate\Support\Str;
use Inertia\Inertia;
@@ -44,6 +45,13 @@ final class AcademyChallengeController extends Controller
route('academy.challenges.index'),
)
->toArray();
$seo = SeoDataBuilder::fromArray($seo)
->breadcrumbs([
['name' => 'Academy', 'url' => route('academy.index')],
['name' => 'Challenges', 'url' => route('academy.challenges.index')],
])
->build()
->toArray();
return Inertia::render('Academy/List', [
'pageType' => 'challenges',
@@ -94,12 +102,24 @@ final class AcademyChallengeController extends Controller
'submitted_at' => $submission->submitted_at?->toISOString(),
])->values()->all();
$seo = app(SeoFactory::class)->collectionPage(
$canonical = route('academy.challenges.show', ['slug' => $challenge->slug]);
$description = Str::limit((string) ($challenge->excerpt ?? $challenge->description ?? ''), 160, '...');
$seo = SeoDataBuilder::fromArray(
app(SeoFactory::class)->collectionPage(
$challenge->title . ' — Skinbase Academy',
Str::limit((string) ($challenge->excerpt ?? $challenge->description ?? ''), 160, '...'),
route('academy.challenges.show', ['slug' => $challenge->slug]),
$description,
$canonical,
$challenge->cover_image,
)->toArray();
)->toArray()
)
->breadcrumbs([
['name' => 'Academy', 'url' => route('academy.index')],
['name' => 'Challenges', 'url' => route('academy.challenges.index')],
['name' => (string) $challenge->title, 'url' => $canonical],
])
->addJsonLd($this->challengeStructuredData($payload, $canonical, $description))
->build()
->toArray();
$interaction = $this->interactions->getInteractionState($request->user(), AcademyAnalyticsContentType::CHALLENGE, (int) $challenge->id);
@@ -128,4 +148,46 @@ final class AcademyChallengeController extends Controller
],
])->rootView('academy');
}
/**
* @param array<string, mixed> $payload
* @return array<string, mixed>
*/
private function challengeStructuredData(array $payload, string $canonical, string $description): array
{
$image = trim((string) ($payload['cover_image'] ?? ''));
$imageUrl = $image !== '' && preg_match('/^https?:\/\//i', $image) === 1 ? $image : ($image !== '' ? url($image) : null);
$requiredTags = array_values((array) ($payload['required_tags'] ?? []));
$status = strtolower(trim((string) ($payload['status'] ?? '')));
$eventStatus = match ($status) {
'scheduled' => 'https://schema.org/EventScheduled',
'active', 'voting' => 'https://schema.org/EventInProgress',
'completed', 'archived' => 'https://schema.org/EventCompleted',
default => null,
};
return array_filter([
'@context' => 'https://schema.org',
'@type' => 'Event',
'name' => (string) ($payload['title'] ?? 'Skinbase Academy challenge'),
'description' => $description,
'url' => $canonical,
'image' => $imageUrl,
'startDate' => $payload['starts_at'] ?? null,
'endDate' => $payload['ends_at'] ?? null,
'eventStatus' => $eventStatus,
'eventAttendanceMode' => 'https://schema.org/OnlineEventAttendanceMode',
'location' => [
'@type' => 'VirtualLocation',
'url' => $canonical,
],
'organizer' => [
'@type' => 'Organization',
'name' => config('seo.site_name', 'Skinbase'),
'url' => url('/'),
],
'keywords' => $requiredTags !== [] ? $requiredTags : null,
'isAccessibleForFree' => (string) ($payload['access_level'] ?? 'free') === 'free',
], fn (mixed $value): bool => $value !== null && $value !== '' && $value !== []);
}
}
@@ -35,6 +35,8 @@ final class AcademyChallengeSubmissionController extends Controller
'Submit to ' . $challenge->title . ' — Skinbase Academy',
'Attach one of your artworks to this Academy challenge submission.',
route('academy.challenges.submit', ['slug' => $challenge->slug]),
null,
false,
)->toArray();
return Inertia::render('Academy/ChallengeSubmit', [
@@ -14,6 +14,7 @@ use App\Services\Academy\AcademyCourseNavigationService;
use App\Services\Academy\AcademyCourseProgressService;
use App\Support\AcademyAnalytics\AcademyAnalyticsContentType;
use App\Support\Seo\SeoFactory;
use App\Support\Seo\SeoDataBuilder;
use Illuminate\Http\Request;
use Inertia\Inertia;
use Inertia\Response;
@@ -37,6 +38,7 @@ final class AcademyCourseController extends Controller
'difficulty' => ['nullable', 'string', 'max:40'],
'access' => ['nullable', 'string', 'max:40'],
]);
$hasActiveFilters = filled($filters['difficulty'] ?? null) || filled($filters['access'] ?? null);
$query = AcademyCourse::query()->published()->ordered();
@@ -77,6 +79,13 @@ final class AcademyCourseController extends Controller
)
->toArray();
if ($hasActiveFilters) {
$seo = SeoDataBuilder::fromArray($seo)
->indexable(false)
->build()
->toArray();
}
return Inertia::render('Academy/CoursesIndex', [
'seo' => $seo,
'title' => 'Academy courses',
@@ -13,6 +13,7 @@ use App\Services\Academy\AcademyCourseNavigationService;
use App\Services\Academy\AcademyCourseProgressService;
use App\Support\AcademyAnalytics\AcademyAnalyticsContentType;
use App\Support\Seo\SeoFactory;
use App\Support\Seo\SeoDataBuilder;
use Illuminate\Support\Str;
use Illuminate\Http\Request;
use Inertia\Inertia;
@@ -52,7 +53,7 @@ final class AcademyCourseLessonController extends Controller
->all();
$payload = $this->access->courseLessonPayload($courseLesson, $request->user(), true);
$canonical = route('academy.courses.lessons.show', ['course' => $course->slug, 'lesson' => $lesson->slug]);
$canonical = route('academy.lessons.show', ['slug' => $lesson->slug]);
$description = Str::limit(trim((string) ($lesson->seo_description ?? $lesson->excerpt ?? 'Skinbase Academy course lesson.')), 160, '...');
$seo = app(SeoFactory::class)->academyLessonPage(
(string) ($lesson->seo_title ?? ($lesson->title . ' — ' . $course->title)),
@@ -70,6 +71,10 @@ final class AcademyCourseLessonController extends Controller
$lesson->updated_at?->toAtomString(),
(string) $course->title,
)->toArray();
$seo = SeoDataBuilder::fromArray($seo)
->indexable(false)
->build()
->toArray();
$interaction = $this->interactions->getInteractionState($request->user(), AcademyAnalyticsContentType::LESSON, (int) $lesson->id);
@@ -13,6 +13,7 @@ use App\Services\Academy\AcademyCacheService;
use App\Services\Academy\AcademyInteractionService;
use App\Support\AcademyAnalytics\AcademyAnalyticsContentType;
use App\Support\Seo\SeoFactory;
use App\Support\Seo\SeoDataBuilder;
use Illuminate\Http\JsonResponse;
use Illuminate\Http\Request;
use Illuminate\Support\Str;
@@ -37,6 +38,9 @@ final class AcademyLessonController extends Controller
'category' => ['nullable', 'string', 'max:140'],
'difficulty' => ['nullable', 'string', 'max:40'],
]);
$hasActiveFilters = filled($filters['q'] ?? null)
|| filled($filters['category'] ?? null)
|| filled($filters['difficulty'] ?? null);
$query = AcademyLesson::query()
->with('category')
@@ -78,6 +82,13 @@ final class AcademyLessonController extends Controller
)
->toArray();
if ($hasActiveFilters) {
$seo = SeoDataBuilder::fromArray($seo)
->indexable(false)
->build()
->toArray();
}
return Inertia::render('Academy/List', [
'pageType' => 'lessons',
'title' => 'Academy lessons',
@@ -13,6 +13,7 @@ use App\Services\Academy\AcademyInteractionService;
use App\Services\Academy\AcademyPopularityService;
use App\Support\AcademyAnalytics\AcademyAnalyticsContentType;
use App\Support\Seo\SeoFactory;
use App\Support\Seo\SeoDataBuilder;
use Illuminate\Http\Request;
use Illuminate\Http\JsonResponse;
use Illuminate\Support\Str;
@@ -41,6 +42,10 @@ final class AcademyPromptController extends Controller
'difficulty' => ['nullable', 'string', 'max:40'],
'tag' => ['nullable', 'string', 'max:60'],
]);
$hasActiveFilters = filled($filters['q'] ?? null)
|| filled($filters['category'] ?? null)
|| filled($filters['difficulty'] ?? null)
|| filled($filters['tag'] ?? null);
$query = AcademyPromptTemplate::query()
->with('category')
@@ -87,6 +92,13 @@ final class AcademyPromptController extends Controller
)
->toArray();
if ($hasActiveFilters) {
$seo = SeoDataBuilder::fromArray($seo)
->indexable(false)
->build()
->toArray();
}
return Inertia::render('Academy/List', [
'pageType' => 'prompts',
'promptView' => 'library',
@@ -203,6 +215,13 @@ final class AcademyPromptController extends Controller
)
->toArray();
if ($selectedPeriod['value'] !== '30d') {
$seo = SeoDataBuilder::fromArray($seo)
->indexable(false)
->build()
->toArray();
}
return Inertia::render('Academy/List', [
'pageType' => 'prompts',
'promptView' => 'popular',
@@ -10,6 +10,7 @@ use App\Services\Academy\AcademyAccessService;
use App\Services\Academy\AcademyInteractionService;
use App\Support\AcademyAnalytics\AcademyAnalyticsContentType;
use App\Support\Seo\SeoFactory;
use App\Support\Seo\SeoDataBuilder;
use Illuminate\Http\Request;
use Illuminate\Support\Str;
use Inertia\Inertia;
@@ -44,6 +45,13 @@ final class AcademyPromptPackController extends Controller
route('academy.packs.index'),
)
->toArray();
$seo = SeoDataBuilder::fromArray($seo)
->breadcrumbs([
['name' => 'Academy', 'url' => route('academy.index')],
['name' => 'Prompt Packs', 'url' => route('academy.packs.index')],
])
->build()
->toArray();
return Inertia::render('Academy/List', [
'pageType' => 'packs',
@@ -79,12 +87,24 @@ final class AcademyPromptPackController extends Controller
->firstOrFail();
$payload = $this->access->packPayload($pack, $request->user(), true);
$seo = app(SeoFactory::class)->collectionPage(
$canonical = route('academy.packs.show', ['slug' => $pack->slug]);
$description = Str::limit((string) ($pack->excerpt ?? $pack->description ?? ''), 160, '...');
$seo = SeoDataBuilder::fromArray(
app(SeoFactory::class)->collectionPage(
$pack->title . ' — Skinbase Academy',
Str::limit((string) ($pack->excerpt ?? $pack->description ?? ''), 160, '...'),
route('academy.packs.show', ['slug' => $pack->slug]),
$description,
$canonical,
$pack->cover_image,
)->toArray();
)->toArray()
)
->breadcrumbs([
['name' => 'Academy', 'url' => route('academy.index')],
['name' => 'Prompt Packs', 'url' => route('academy.packs.index')],
['name' => (string) $pack->title, 'url' => $canonical],
])
->addJsonLd($this->packStructuredData($payload, $canonical, $description))
->build()
->toArray();
$interaction = $this->interactions->getInteractionState($request->user(), AcademyAnalyticsContentType::PROMPT_PACK, (int) $pack->id);
@@ -112,4 +132,58 @@ final class AcademyPromptPackController extends Controller
],
])->rootView('academy');
}
/**
* @param array<string, mixed> $payload
* @return array<string, mixed>
*/
private function packStructuredData(array $payload, string $canonical, string $description): array
{
$image = trim((string) ($payload['cover_image'] ?? ''));
$imageUrl = $image !== '' && preg_match('/^https?:\/\//i', $image) === 1 ? $image : ($image !== '' ? url($image) : null);
$keywords = array_values((array) ($payload['tags'] ?? []));
$isFree = (string) ($payload['access_level'] ?? 'free') === 'free';
$promptEntries = collect((array) ($payload['prompts'] ?? []))
->map(function (array $prompt): ?array {
$title = trim((string) ($prompt['title'] ?? ''));
$slug = trim((string) ($prompt['slug'] ?? ''));
if ($title === '' || $slug === '') {
return null;
}
return [
'@type' => 'ListItem',
'position' => null,
'item' => [
'@type' => 'CreativeWork',
'name' => $title,
'url' => route('academy.prompts.show', ['slug' => $slug]),
],
];
})
->filter()
->values()
->map(function (array $item, int $index): array {
$item['position'] = $index + 1;
return $item;
})
->all();
return array_filter([
'@context' => 'https://schema.org',
'@type' => ['CreativeWork', 'LearningResource'],
'name' => (string) ($payload['title'] ?? 'Skinbase Academy prompt pack'),
'description' => $description,
'url' => $canonical,
'image' => $imageUrl,
'keywords' => $keywords !== [] ? $keywords : null,
'isAccessibleForFree' => $isFree,
'hasPart' => $promptEntries !== [] ? [
'@type' => 'ItemList',
'itemListElement' => $promptEntries,
] : null,
], fn (mixed $value): bool => $value !== null && $value !== '' && $value !== []);
}
}
@@ -0,0 +1,130 @@
<?php
declare(strict_types=1);
namespace App\Http\Controllers\Admin;
use App\Http\Controllers\Controller;
use App\Jobs\RunSecurityReportScanJob;
use App\Models\SecurityReport;
use Illuminate\Http\RedirectResponse;
use Illuminate\Http\Request;
use Inertia\Inertia;
use Inertia\Response;
final class SecurityReportController extends Controller
{
public function index(): Response
{
abort_unless((bool) config('security-report.enabled', true), 404);
$latest = SecurityReport::query()->latest('id')->with('user:id,name,username')->first();
$reports = SecurityReport::query()
->with('user:id,name,username')
->latest('id')
->paginate(20)
->through(fn (SecurityReport $report): array => $this->mapListItem($report));
return Inertia::render('Admin/System/SecurityReportIndex', [
'latest' => $latest ? $this->mapDetail($latest) : null,
'reports' => $reports,
'canRunScan' => true,
])->rootView('moderation');
}
public function show(SecurityReport $securityReport): Response
{
abort_unless((bool) config('security-report.enabled', true), 404);
$securityReport->load('user:id,name,username');
return Inertia::render('Admin/System/SecurityReportShow', [
'report' => $this->mapDetail($securityReport),
])->rootView('moderation');
}
public function run(Request $request): RedirectResponse
{
abort_unless((bool) config('security-report.enabled', true), 404);
RunSecurityReportScanJob::dispatch($request->user()?->id);
return redirect()
->route('admin.system.security-report.index')
->with('success', 'Security scan has been queued.');
}
/**
* @return array<string, mixed>
*/
private function mapListItem(SecurityReport $report): array
{
return [
'id' => (int) $report->id,
'status' => (string) $report->status,
'risk_label' => (string) $report->risk_label,
'finished_at' => optional($report->finished_at)?->toIso8601String(),
'total_critical' => (int) $report->total_critical,
'total_high' => (int) $report->total_high,
'total_medium' => (int) $report->total_medium,
'total_low' => (int) $report->total_low,
'composer_outdated_count' => (int) $report->composer_outdated_count,
'npm_outdated_count' => (int) $report->npm_outdated_count,
'show_url' => route('admin.system.security-report.show', ['securityReport' => $report]),
'triggered_by' => (string) ($report->triggered_by ?? ''),
'user' => $report->user ? [
'id' => (int) $report->user->id,
'name' => (string) $report->user->name,
'username' => (string) ($report->user->username ?? ''),
] : null,
];
}
/**
* @return array<string, mixed>
*/
private function mapDetail(SecurityReport $report): array
{
return [
'id' => (int) $report->id,
'status' => (string) $report->status,
'risk_label' => (string) $report->risk_label,
'started_at' => optional($report->started_at)?->toIso8601String(),
'finished_at' => optional($report->finished_at)?->toIso8601String(),
'composer_critical' => (int) $report->composer_critical,
'composer_high' => (int) $report->composer_high,
'composer_medium' => (int) $report->composer_medium,
'composer_low' => (int) $report->composer_low,
'composer_unknown' => (int) $report->composer_unknown,
'npm_critical' => (int) $report->npm_critical,
'npm_high' => (int) $report->npm_high,
'npm_moderate' => (int) $report->npm_moderate,
'npm_low' => (int) $report->npm_low,
'npm_info' => (int) $report->npm_info,
'npm_unknown' => (int) $report->npm_unknown,
'total_critical' => (int) $report->total_critical,
'total_high' => (int) $report->total_high,
'total_medium' => (int) $report->total_medium,
'total_low' => (int) $report->total_low,
'total_unknown' => (int) $report->total_unknown,
'composer_outdated_count' => (int) $report->composer_outdated_count,
'npm_outdated_count' => (int) $report->npm_outdated_count,
'summary' => $report->summary ?? [],
'triggered_by' => (string) ($report->triggered_by ?? ''),
'error_message' => (string) ($report->error_message ?? ''),
'show_url' => route('admin.system.security-report.show', ['securityReport' => $report]),
'index_url' => route('admin.system.security-report.index'),
'composer_audit' => $report->composer_audit,
'composer_outdated' => $report->composer_outdated,
'npm_audit' => $report->npm_audit,
'npm_outdated' => $report->npm_outdated,
'composer_advisories' => $report->composerAdvisories(),
'npm_vulnerabilities' => $report->npmVulnerabilities(),
'user' => $report->user ? [
'id' => (int) $report->user->id,
'name' => (string) $report->user->name,
'username' => (string) ($report->user->username ?? ''),
] : null,
];
}
}
@@ -48,10 +48,7 @@ class MessageSearchController extends Controller
$estimated = 0;
try {
$client = new Client(
config('scout.meilisearch.host'),
config('scout.meilisearch.key')
);
$client = app(Client::class);
$prefix = (string) config('scout.prefix', '');
$indexName = $prefix . (string) config('messaging.search.index', 'messages');
@@ -6,10 +6,12 @@ namespace App\Http\Controllers\Api;
use App\Http\Controllers\Controller;
use App\Models\Artwork;
use App\Services\Vision\VectorGatewayException;
use App\Services\Vision\VectorService;
use Illuminate\Http\JsonResponse;
use Illuminate\Http\Request;
use RuntimeException;
use Illuminate\Support\Facades\Log;
use Throwable;
final class SimilarAiArtworksController extends Controller
{
@@ -35,11 +37,12 @@ final class SimilarAiArtworksController extends Controller
try {
$items = $this->vectors->similarToArtwork($artwork, $limit);
} catch (RuntimeException $e) {
} catch (Throwable $e) {
$this->logSimilarityFailure($artwork->id, $e);
return response()->json([
'data' => [],
'reason' => 'vector_gateway_error',
'message' => $e->getMessage(),
], 502);
}
@@ -52,4 +55,19 @@ final class SimilarAiArtworksController extends Controller
],
]);
}
private function logSimilarityFailure(int $artworkId, Throwable $e): void
{
$gateway = $e instanceof VectorGatewayException ? $e : null;
Log::warning('Vector similarity search failed', [
'artwork_id' => $artworkId,
'route' => 'api.art.similar-ai',
'failure_stage' => $gateway?->operation ?? 'unknown',
'exception_class' => $e::class,
'http_status' => $gateway?->httpStatus,
'circuit_worthy' => $gateway?->circuitWorthy ?? false,
'circuit_open' => app(\App\Services\Vision\VectorGatewayClient::class)->circuitOpen(),
]);
}
}
@@ -58,6 +58,16 @@ final class ArtworkDownloadController extends Controller
abort(404);
}
if (! File::isFile($filePath)) {
Log::warning('Artwork original file missing for download.', [
'artwork_id' => $artwork->id,
'ext' => $ext,
'resolved_path' => $filePath,
]);
abort(404);
}
$this->recordDownload($request, $artwork->id);
$this->incrementDownloadCountIfAvailable($artwork->id);
@@ -70,16 +80,6 @@ final class ArtworkDownloadController extends Controller
]);
}
if (! File::isFile($filePath)) {
Log::warning('Artwork original file missing for download.', [
'artwork_id' => $artwork->id,
'ext' => $ext,
'resolved_path' => $filePath,
]);
abort(404);
}
$downloadName = $this->buildDownloadFilename((string) $artwork->file_name, $ext);
// X-Accel-Redirect is safe only when nginx is explicitly configured to
+31 -7
View File
@@ -5,6 +5,7 @@ declare(strict_types=1);
namespace App\Http\Controllers;
use App\Services\Sitemaps\PublishedSitemapResolver;
use App\Services\Sitemaps\SitemapBuildService;
use App\Services\Sitemaps\SitemapXmlRenderer;
use Symfony\Component\HttpFoundation\BinaryFileResponse;
use Symfony\Component\HttpKernel\Exception\NotFoundHttpException;
@@ -14,34 +15,50 @@ final class SitemapController extends Controller
{
public function __construct(
private readonly PublishedSitemapResolver $published,
private readonly SitemapBuildService $build,
private readonly SitemapXmlRenderer $renderer,
) {
}
public function index(): Response|BinaryFileResponse
{
// 1. Static file written by the build/generate commands.
// On production nginx serves this directly via try_files without reaching PHP.
// On dev / misconfigured servers we stream it with sendfile — no RAM load.
$path = public_path('sitemap.xml');
if (file_exists($path)) {
if ((bool) config('sitemaps.pre_generated.enabled', true)) {
foreach ([
public_path('sitemaps/index.xml'),
public_path('sitemaps/sitemap.xml'),
public_path('sitemap.xml'),
] as $path) {
if (is_file($path) && is_readable($path)) {
return $this->xmlFileResponse($path);
}
}
}
// 2. Published release (release management pipeline fallback).
// 1. Published release (release management pipeline fallback).
$published = $this->published->resolveIndex();
if ($published !== null) {
return $this->renderer->xmlResponse($published['content']);
}
// 2. Live-build fallback when no published sitemap is available.
if ((bool) config('sitemaps.delivery.fallback_to_live_build', true)) {
$built = $this->build->buildIndex(force: true, persist: false);
return $this->renderer->xmlResponse($built['content']);
}
throw new NotFoundHttpException();
}
public function show(string $name): Response|BinaryFileResponse
{
if ($name === 'sitemap') {
return $this->index();
}
// 1. Static file.
$path = public_path('sitemaps/' . $name . '.xml');
if (file_exists($path)) {
if ((bool) config('sitemaps.pre_generated.enabled', true) && file_exists($path)) {
return $this->xmlFileResponse($path);
}
@@ -51,6 +68,13 @@ final class SitemapController extends Controller
return $this->renderer->xmlResponse($published['content']);
}
if ((bool) config('sitemaps.delivery.fallback_to_live_build', true)) {
$built = $this->build->buildNamed($name, force: true, persist: false);
if ($built !== null) {
return $this->renderer->xmlResponse($built['content']);
}
}
throw new NotFoundHttpException();
}
@@ -11,6 +11,7 @@ use App\Services\GroupDiscoveryService;
use Illuminate\Database\Eloquent\Collection as EloquentCollection;
use Illuminate\Http\RedirectResponse;
use Illuminate\Http\Request;
use Illuminate\Http\Response;
use Illuminate\Support\Arr;
use Illuminate\View\View;
use cPad\Plugins\News\Models\NewsArticle;
@@ -19,6 +20,12 @@ final class SearchController extends Controller
{
private const ALLOWED_SORTS = ['latest', 'popular', 'likes', 'downloads'];
/** Reject requests with an absurd number of query params before touching search/DB. */
private const MAX_QUERY_PARAMS = 15;
/** Reject requests with an absurdly long query string before touching search/DB. */
private const MAX_QUERY_STRING_LENGTH = 500;
public function __construct(
private readonly ArtworkSearchService $search,
private readonly GroupDiscoveryService $groups,
@@ -26,6 +33,8 @@ final class SearchController extends Controller
public function index(Request $request): View|RedirectResponse
{
$this->rejectMalformedQuery($request);
$canonicalQuery = $this->canonicalQueryParameters($request);
$canonicalUrl = $this->canonicalSearchUrl($request, $canonicalQuery);
@@ -110,6 +119,21 @@ final class SearchController extends Controller
]);
}
/**
* Bail out before any search/DB work for junk requests — e.g. scripted
* floods that repeat/nest query params (group=all&page=..&sort=.. etc.).
*/
private function rejectMalformedQuery(Request $request): void
{
$query = $request->query();
if (count($query) > self::MAX_QUERY_PARAMS
|| strlen((string) $request->getQueryString()) > self::MAX_QUERY_STRING_LENGTH
) {
abort(Response::HTTP_BAD_REQUEST);
}
}
/**
* @return array<string, int|string>
*/
+43
View File
@@ -0,0 +1,43 @@
<?php
declare(strict_types=1);
namespace App\Http\Middleware;
use Closure;
use Illuminate\Http\Request;
use Symfony\Component\HttpFoundation\Response;
/**
* Negligible-overhead request duration header for production HTTP profiling.
* Does not log queries or payloads.
*/
final class AddServerTiming
{
public function handle(Request $request, Closure $next): Response
{
$started = hrtime(true);
$response = $next($request);
$durationMs = (hrtime(true) - $started) / 1_000_000;
if (headers_sent()) {
return $response;
}
$metrics = ['app;desc="Laravel";dur='.number_format($durationMs, 1, '.', '')];
$ssrMs = $request->attributes->get('http.ssr_ms');
if (is_numeric($ssrMs) && (float) $ssrMs >= 0) {
$metrics[] = 'ssr;desc="Inertia SSR";dur='.number_format((float) $ssrMs, 1, '.', '');
}
$metric = implode(', ', $metrics);
$existing = $response->headers->get('Server-Timing');
$response->headers->set(
'Server-Timing',
$existing ? $existing.', '.$metric : $metric,
);
return $response;
}
}
+10 -3
View File
@@ -98,6 +98,15 @@ final class HandleInertiaRequests extends Middleware
? $request->session()->get($key)
: null;
if ($user !== null && ! $user->relationLoaded('profile')) {
$user->load('profile');
}
$studioGroups = [];
if ($user !== null && str_starts_with($request->path(), 'studio')) {
$studioGroups = app(GroupService::class)->studioOptionsForUser($user);
}
return array_merge(parent::share($request), [
'auth' => [
'user' => $user ? [
@@ -134,9 +143,7 @@ final class HandleInertiaRequests extends Middleware
'group_assets' => (bool) config('features.group_assets', true),
'group_activity_feed' => (bool) config('features.group_activity_feed', true),
],
'studio_groups' => $user
? app(GroupService::class)->studioOptionsForUser($user)
: [],
'studio_groups' => $studioGroups,
]);
}
}
@@ -0,0 +1,74 @@
<?php
declare(strict_types=1);
namespace App\Http\Middleware;
use App\Support\Http\HttpUriNormalizer;
use Closure;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Log;
use Inertia\Support\Header as InertiaHeader;
use Symfony\Component\HttpFoundation\Response;
final class LogSlowHttpRequest
{
public function __construct(private readonly HttpUriNormalizer $uris)
{
}
public function handle(Request $request, Closure $next): Response
{
if (! (bool) config('http_observability.slow_request.enabled', false)) {
return $next($request);
}
$started = hrtime(true);
$response = $next($request);
$durationMs = (hrtime(true) - $started) / 1_000_000;
if (app()->environment('testing')) {
$override = config('http_observability.slow_request.test_duration_ms');
if (is_numeric($override)) {
$durationMs = (float) $override;
}
}
$threshold = max(1, (int) config('http_observability.slow_request.threshold_ms', 750));
if ($durationMs < $threshold) {
return $response;
}
$route = $request->route();
$routeUri = is_object($route) && method_exists($route, 'uri')
? (string) $route->uri()
: $this->uris->normalize($request->path());
$payload = [
'time' => now()->toIso8601String(),
'method' => $request->getMethod(),
'route_name' => is_object($route) ? $route->getName() : null,
'route_uri' => $routeUri,
'status' => $response->getStatusCode(),
'duration_ms' => round($durationMs, 1),
'peak_memory_mb' => round(memory_get_peak_usage(true) / 1048576, 2),
'authenticated' => $request->user() !== null,
'inertia' => $this->isInertia($request, $response),
];
Log::channel('slow-http')->info(json_encode($payload, JSON_UNESCAPED_SLASHES));
return $response;
}
private function isInertia(Request $request, Response $response): bool
{
if ($request->headers->has(InertiaHeader::INERTIA)) {
return true;
}
return $response->headers->has(InertiaHeader::INERTIA)
|| $response->headers->get('Vary') === 'X-Inertia'
|| str_contains((string) $response->headers->get('Vary'), 'X-Inertia');
}
}
@@ -69,6 +69,11 @@ final class TrackOnlineVisitor
'email/*',
'logout',
'up',
'rss/*',
'rss-feeds',
'robots.txt',
'sitemap.xml',
'sitemaps/*',
])) {
return false;
}
@@ -0,0 +1,27 @@
<?php
declare(strict_types=1);
namespace App\Jobs\Concerns;
/**
* M1 added $afterArtworkId to RecCompute* jobs. Payloads serialized before that
* property existed leave a typed property uninitialized on unserialize, which
* fatals on first access. Constructor defaults do not apply to unserialize.
*/
trait RestoresAfterArtworkIdCursor
{
protected function restoreAfterArtworkIdCursor(): void
{
if (! isset($this->afterArtworkId)) {
$this->afterArtworkId = null;
}
}
protected function afterArtworkId(): ?int
{
$this->restoreAfterArtworkIdCursor();
return $this->afterArtworkId;
}
}
+15 -1
View File
@@ -6,6 +6,7 @@ namespace App\Jobs;
use App\Models\Artwork;
use Illuminate\Bus\Queueable;
use Illuminate\Contracts\Queue\ShouldBeUniqueUntilProcessing;
use Illuminate\Contracts\Queue\ShouldQueue;
use Illuminate\Foundation\Bus\Dispatchable;
use Illuminate\Queue\InteractsWithQueue;
@@ -21,16 +22,29 @@ use Meilisearch\Client as MeilisearchClient;
* after_commit double-dispatch problem and ensures the document lands
* in the index within this job's execution, with no extra queue hop.
*/
class IndexArtworkJob implements ShouldQueue
class IndexArtworkJob implements ShouldQueue, ShouldBeUniqueUntilProcessing
{
use Dispatchable, InteractsWithQueue, Queueable, SerializesModels;
public int $tries = 3;
public int $timeout = 60;
/**
* Unique while queued so Meilisearch isn't flooded. handle() loads the
* artwork from DB, so a dropped duplicate still indexes current state.
* UniqueUntilProcessing: a change after the worker starts can enqueue again.
*/
public int $uniqueFor = 120;
public function __construct(public readonly int $artworkId)
{
$this->afterCommit = true;
$this->onQueue((string) config('scout.queue.queue', 'search'));
}
public function uniqueId(): string
{
return (string) $this->artworkId;
}
public function handle(MeilisearchClient $client): void
+17 -2
View File
@@ -6,6 +6,7 @@ namespace App\Jobs;
use App\Models\User;
use Illuminate\Bus\Queueable;
use Illuminate\Contracts\Queue\ShouldBeUniqueUntilProcessing;
use Illuminate\Contracts\Queue\ShouldQueue;
use Illuminate\Foundation\Bus\Dispatchable;
use Illuminate\Queue\InteractsWithQueue;
@@ -15,14 +16,28 @@ use Illuminate\Queue\SerializesModels;
* Queued job: index (or re-index) a single User in Meilisearch.
* Dispatched by UserStatsService whenever stats change.
*/
class IndexUserJob implements ShouldQueue
class IndexUserJob implements ShouldQueue, ShouldBeUniqueUntilProcessing
{
use Dispatchable, InteractsWithQueue, Queueable, SerializesModels;
public int $tries = 3;
public int $timeout = 30;
public function __construct(public readonly int $userId) {}
/**
* Unique while queued. handle() loads the user from DB so the queued job
* still reflects later stats changes. uniqueFor covers a dead worker lock.
*/
public int $uniqueFor = 60;
public function __construct(public readonly int $userId)
{
$this->onQueue((string) config('scout.queue.queue', 'search'));
}
public function uniqueId(): string
{
return (string) $this->userId;
}
public function handle(): void
{
+16 -2
View File
@@ -6,6 +6,7 @@ namespace App\Jobs;
use App\Services\RankingService;
use Illuminate\Bus\Queueable;
use Illuminate\Contracts\Queue\ShouldBeUnique;
use Illuminate\Contracts\Queue\ShouldQueue;
use Illuminate\Foundation\Bus\Dispatchable;
use Illuminate\Queue\InteractsWithQueue;
@@ -13,19 +14,32 @@ use Illuminate\Queue\SerializesModels;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Log;
class RankBuildScopeListsJob implements ShouldQueue
class RankBuildScopeListsJob implements ShouldQueue, ShouldBeUnique
{
use Dispatchable, InteractsWithQueue, Queueable, SerializesModels;
public int $timeout = 300;
public int $tries = 2;
/**
* Unique until the job finishes or uniqueFor elapses.
* Must outlast the queue wait (hours) plus timeout (300s), not just 360s.
*/
public int $uniqueFor;
private const LIST_TYPES = ['trending', 'new_hot', 'best'];
public function __construct(
public readonly string $scopeType,
public readonly int $scopeId,
) {}
) {
$this->uniqueFor = max(3600, (int) config('ranking.scope_job_unique_for', 21600));
}
public function uniqueId(): string
{
return $this->scopeType . ':' . $this->scopeId;
}
public function handle(RankingService $ranking): void
{
+102 -9
View File
@@ -10,8 +10,10 @@ use Illuminate\Bus\Queueable;
use Illuminate\Contracts\Queue\ShouldQueue;
use Illuminate\Foundation\Bus\Dispatchable;
use Illuminate\Queue\InteractsWithQueue;
use App\Jobs\Concerns\RestoresAfterArtworkIdCursor;
use Illuminate\Queue\SerializesModels;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Log;
/**
* Compute behavior-based (co-like) similarity from precomputed item pairs.
@@ -21,38 +23,129 @@ use Illuminate\Support\Facades\DB;
*/
final class RecComputeSimilarByBehaviorJob implements ShouldQueue
{
use Dispatchable, InteractsWithQueue, Queueable, SerializesModels;
use Dispatchable, InteractsWithQueue, Queueable, RestoresAfterArtworkIdCursor;
use SerializesModels {
__unserialize as private unserializeQueuedModels;
}
public int $tries = 2;
public int $timeout = 600;
public int $timeout = 120;
private ?int $afterArtworkId = null;
public function __construct(
private readonly ?int $artworkId = null,
private readonly int $batchSize = 200,
?int $afterArtworkId = null,
) {
$this->afterArtworkId = $afterArtworkId;
$queue = (string) config('recommendations.queue', 'default');
if ($queue !== '') {
$this->onQueue($queue);
}
}
public function __unserialize(array $values): void
{
$this->unserializeQueuedModels($values);
$this->restoreAfterArtworkIdCursor();
}
public function cursorAfterArtworkId(): ?int
{
return $this->afterArtworkId();
}
public function handle(): void
{
$startedAt = microtime(true);
$modelVersion = (string) config('recommendations.similarity.model_version', 'sim_v1');
$resultLimit = (int) config('recommendations.similarity.result_limit', 30);
$maxPerAuthor = (int) config('recommendations.similarity.max_per_author', 2);
$query = Artwork::query()->public()->published()->select('id', 'user_id');
if ($this->artworkId !== null) {
$query->where('id', $this->artworkId);
$artwork = Artwork::query()->public()->published()->select('id', 'user_id')->find($this->artworkId);
if ($artwork instanceof Artwork) {
$this->processArtworkSafely($artwork, $modelVersion, $resultLimit, $maxPerAuthor);
$this->logBatchComplete($startedAt, 1, false);
return;
}
$query->chunkById($this->batchSize, function ($artworks) use ($modelVersion, $resultLimit, $maxPerAuthor) {
foreach ($artworks as $artwork) {
$this->processArtwork($artwork, $modelVersion, $resultLimit, $maxPerAuthor);
$this->logBatchComplete($startedAt, 0, false);
return;
}
});
$artworks = Artwork::query()
->public()
->published()
->select('id', 'user_id')
->when($this->afterArtworkId() !== null, fn ($query) => $query->where('id', '>', $this->afterArtworkId()))
->orderBy('id')
->limit($this->batchSize)
->get();
if ($artworks->isEmpty()) {
$this->logBatchComplete($startedAt, 0, false);
return;
}
foreach ($artworks as $artwork) {
$this->processArtworkSafely($artwork, $modelVersion, $resultLimit, $maxPerAuthor);
}
$hasMore = $artworks->count() === $this->batchSize;
if ($hasMore) {
static::dispatch(null, $this->batchSize, (int) $artworks->last()->id);
}
$this->logBatchComplete($startedAt, $artworks->count(), $hasMore);
}
public function failed(\Throwable $exception): void
{
Log::error('[RecComputeSimilarByBehavior] Job failed permanently.', [
'artwork_id' => $this->artworkId,
'batch_size' => $this->batchSize,
'after_artwork_id' => $this->afterArtworkId(),
'attempts' => $this->attempts(),
'exception_class' => $exception::class,
'exception_message' => $exception->getMessage(),
]);
}
private function processArtworkSafely(
Artwork $artwork,
string $modelVersion,
int $resultLimit,
int $maxPerAuthor,
): void {
try {
$this->processArtwork($artwork, $modelVersion, $resultLimit, $maxPerAuthor);
} catch (\Throwable $exception) {
Log::warning("[RecComputeSimilarByBehavior] Failed for artwork {$artwork->id}: {$exception->getMessage()}", [
'artwork_id' => $artwork->id,
'exception_class' => $exception::class,
]);
}
}
/**
* @param positive-int|0 $processed
*/
private function logBatchComplete(float $startedAt, int $processed, bool $hasMore): void
{
Log::info('[RecComputeSimilarByBehavior] Batch complete.', [
'artwork_id' => $this->artworkId,
'after_artwork_id' => $this->afterArtworkId(),
'processed' => $processed,
'has_more' => $hasMore,
'duration_ms' => (int) round((microtime(true) - $startedAt) * 1000),
'memory_mb' => round(memory_get_peak_usage(true) / 1048576, 1),
]);
}
private function processArtwork(
+49 -10
View File
@@ -11,7 +11,9 @@ use Illuminate\Contracts\Queue\ShouldQueue;
use Illuminate\Foundation\Bus\Dispatchable;
use Illuminate\Queue\Middleware\WithoutOverlapping;
use Illuminate\Queue\InteractsWithQueue;
use App\Jobs\Concerns\RestoresAfterArtworkIdCursor;
use Illuminate\Queue\SerializesModels;
use Illuminate\Support\Facades\Cache;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Log;
@@ -24,22 +26,44 @@ use Illuminate\Support\Facades\Log;
*/
final class RecComputeSimilarByTagsJob implements ShouldQueue
{
use Dispatchable, InteractsWithQueue, Queueable, SerializesModels;
use Dispatchable, InteractsWithQueue, Queueable, RestoresAfterArtworkIdCursor;
use SerializesModels {
__unserialize as private unserializeQueuedModels;
}
public int $tries = 2;
public int $timeout = 600;
/**
* Declared with a default so missing serialized payloads do not leave
* an uninitialized typed property. Constructor defaults are not applied
* on unserialize.
*/
private ?int $afterArtworkId = null;
public function __construct(
private readonly ?int $artworkId = null,
private readonly int $batchSize = 200,
private readonly ?int $afterArtworkId = null,
?int $afterArtworkId = null,
) {
$this->afterArtworkId = $afterArtworkId;
$queue = (string) config('recommendations.queue', 'default');
if ($queue !== '') {
$this->onQueue($queue);
}
}
public function __unserialize(array $values): void
{
$this->unserializeQueuedModels($values);
$this->restoreAfterArtworkIdCursor();
}
public function cursorAfterArtworkId(): ?int
{
return $this->afterArtworkId();
}
/**
* @return array<int, object>
*/
@@ -63,12 +87,7 @@ final class RecComputeSimilarByTagsJob implements ShouldQueue
$maxPerAuthor = (int) config('recommendations.similarity.max_per_author', 2);
$resultLimit = (int) config('recommendations.similarity.result_limit', 30);
// ── Tag IDF weights (global) ───────────────────────────────────────────
$tagFreqs = DB::table('artwork_tag')
->select('tag_id', DB::raw('COUNT(*) as cnt'))
->groupBy('tag_id')
->pluck('cnt', 'tag_id')
->all();
$tagFreqs = $this->tagFrequencies();
if ($this->artworkId !== null) {
$artwork = Artwork::query()->public()->published()->select('id', 'user_id')->find($this->artworkId);
@@ -86,7 +105,7 @@ final class RecComputeSimilarByTagsJob implements ShouldQueue
->public()
->published()
->select('id', 'user_id')
->when($this->afterArtworkId !== null, fn ($query) => $query->where('id', '>', $this->afterArtworkId))
->when($this->afterArtworkId() !== null, fn ($query) => $query->where('id', '>', $this->afterArtworkId()))
->orderBy('id')
->limit($this->batchSize)
->get();
@@ -109,13 +128,33 @@ final class RecComputeSimilarByTagsJob implements ShouldQueue
Log::error('[RecComputeSimilarByTags] Job failed permanently.', [
'artwork_id' => $this->artworkId,
'batch_size' => $this->batchSize,
'after_artwork_id' => $this->afterArtworkId,
'after_artwork_id' => $this->afterArtworkId(),
'attempts' => $this->attempts(),
'exception_class' => $exception::class,
'exception_message' => $exception->getMessage(),
]);
}
/**
* Global tag frequencies change slowly relative to batch jobs.
* Cache so each RecComputeSimilarByTagsJob batch does not re-scan artwork_tag.
*
* @return array<int|string, mixed>
*/
private function tagFrequencies(): array
{
$modelVersion = (string) config('recommendations.similarity.model_version', 'sim_v1');
$ttl = (int) config('recommendations.similarity.tag_idf_cache_ttl', 3600);
return Cache::remember('rec:tag-idf:'.$modelVersion, max(60, $ttl), function () {
return DB::table('artwork_tag')
->select('tag_id', DB::raw('COUNT(*) as cnt'))
->groupBy('tag_id')
->pluck('cnt', 'tag_id')
->all();
});
}
private function processArtworkSafely(
Artwork $artwork,
array $tagFreqs,
+62 -7
View File
@@ -11,6 +11,7 @@ use Illuminate\Contracts\Queue\ShouldQueue;
use Illuminate\Foundation\Bus\Dispatchable;
use Illuminate\Queue\Middleware\WithoutOverlapping;
use Illuminate\Queue\InteractsWithQueue;
use App\Jobs\Concerns\RestoresAfterArtworkIdCursor;
use Illuminate\Queue\SerializesModels;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Log;
@@ -24,24 +25,42 @@ use Illuminate\Support\Facades\Log;
*/
final class RecComputeSimilarHybridJob implements ShouldQueue
{
use Dispatchable, InteractsWithQueue, Queueable, SerializesModels;
use Dispatchable, InteractsWithQueue, Queueable, RestoresAfterArtworkIdCursor;
use SerializesModels {
__unserialize as private unserializeQueuedModels;
}
// This recompute is idempotent and already guards per-artwork execution.
// Keep retries to a minimum so transient failures do not turn into
// Horizon's max-attempt exception noise.
public int $tries = 1;
public int $timeout = 900;
public int $timeout = 180;
private ?int $afterArtworkId = null;
public function __construct(
private readonly ?int $artworkId = null,
private readonly int $batchSize = 200,
?int $afterArtworkId = null,
) {
$this->afterArtworkId = $afterArtworkId;
$queue = (string) config('recommendations.queue', 'default');
if ($queue !== '') {
$this->onQueue($queue);
}
}
public function __unserialize(array $values): void
{
$this->unserializeQueuedModels($values);
$this->restoreAfterArtworkIdCursor();
}
public function cursorAfterArtworkId(): ?int
{
return $this->afterArtworkId();
}
/**
* @return array<int, object>
*/
@@ -72,6 +91,8 @@ final class RecComputeSimilarHybridJob implements ShouldQueue
? (array) config('recommendations.similarity.weights_with_vector')
: (array) config('recommendations.similarity.weights_without_vector');
$startedAt = microtime(true);
if ($this->artworkId !== null) {
$artwork = Artwork::query()
->public()
@@ -80,6 +101,8 @@ final class RecComputeSimilarHybridJob implements ShouldQueue
->find($this->artworkId);
if (! $artwork instanceof Artwork) {
$this->logBatchComplete($startedAt, 0, false);
return;
}
@@ -93,16 +116,26 @@ final class RecComputeSimilarHybridJob implements ShouldQueue
$weights,
);
$this->logBatchComplete($startedAt, 1, false);
return;
}
Artwork::query()
$artworks = Artwork::query()
->public()
->published()
->select('id', 'user_id')
->chunkById($this->batchSize, function ($artworks) use (
$modelVersion, $vectorEnabled, $resultLimit, $maxPerAuthor, $minCatsTop12, $weights
) {
->when($this->afterArtworkId() !== null, fn ($query) => $query->where('id', '>', $this->afterArtworkId()))
->orderBy('id')
->limit($this->batchSize)
->get();
if ($artworks->isEmpty()) {
$this->logBatchComplete($startedAt, 0, false);
return;
}
$this->processArtworkSafely(
$artworks,
$modelVersion,
@@ -112,7 +145,13 @@ final class RecComputeSimilarHybridJob implements ShouldQueue
$minCatsTop12,
$weights,
);
});
$hasMore = $artworks->count() === $this->batchSize;
if ($hasMore) {
static::dispatch(null, $this->batchSize, (int) $artworks->last()->id);
}
$this->logBatchComplete($startedAt, $artworks->count(), $hasMore);
}
public function failed(\Throwable $exception): void
@@ -120,12 +159,28 @@ final class RecComputeSimilarHybridJob implements ShouldQueue
Log::error('[RecComputeSimilarHybrid] Job failed permanently.', [
'artwork_id' => $this->artworkId,
'batch_size' => $this->batchSize,
'after_artwork_id' => $this->afterArtworkId(),
'attempts' => $this->attempts(),
'exception_class' => $exception::class,
'exception_message' => $exception->getMessage(),
]);
}
/**
* @param positive-int|0 $processed
*/
private function logBatchComplete(float $startedAt, int $processed, bool $hasMore): void
{
Log::info('[RecComputeSimilarHybrid] Batch complete.', [
'artwork_id' => $this->artworkId,
'after_artwork_id' => $this->afterArtworkId(),
'processed' => $processed,
'has_more' => $hasMore,
'duration_ms' => (int) round((microtime(true) - $startedAt) * 1000),
'memory_mb' => round(memory_get_peak_usage(true) / 1048576, 1),
]);
}
/**
* @param iterable<Artwork> $artworks
*/
+47
View File
@@ -0,0 +1,47 @@
<?php
declare(strict_types=1);
namespace App\Jobs;
use App\Notifications\SecurityReportDangerNotification;
use App\Services\SecurityReport\SecurityReportScanner;
use Illuminate\Bus\Queueable;
use Illuminate\Contracts\Queue\ShouldQueue;
use Illuminate\Foundation\Bus\Dispatchable;
use Illuminate\Queue\InteractsWithQueue;
use Illuminate\Queue\SerializesModels;
use Illuminate\Support\Facades\Notification;
final class RunSecurityReportScanJob implements ShouldQueue
{
use Dispatchable;
use InteractsWithQueue;
use Queueable;
use SerializesModels;
public function __construct(public ?int $userId = null)
{
}
public function handle(SecurityReportScanner $scanner): void
{
if (! (bool) config('security-report.enabled', true)) {
return;
}
$report = $scanner->scan('manual', $this->userId);
if (! $report->hasDangerFindings()) {
return;
}
$email = trim((string) config('security-report.notify_email', ''));
if ($email === '') {
return;
}
Notification::route('mail', $email)
->notify(new SecurityReportDangerNotification($report));
}
}
+52 -3
View File
@@ -13,7 +13,6 @@ use Illuminate\Database\Eloquent\Relations\HasMany;
use Illuminate\Database\Eloquent\Relations\HasOne;
use Illuminate\Database\Eloquent\SoftDeletes;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Storage;
use Laravel\Scout\Searchable;
use Laravel\Scout\SearchableScope;
@@ -73,6 +72,8 @@ class Artwork extends Model
'has_missing_thumbnails',
'missing_thumbnail_variants_json',
'thumbnails_checked_at',
'featured_thumbnail_variants_json',
'featured_thumbnails_checked_at',
'file_size',
'mime_type',
'width',
@@ -154,6 +155,8 @@ class Artwork extends Model
'published_at' => 'datetime',
'missing_thumbnail_variants_json' => 'array',
'thumbnails_checked_at' => 'datetime',
'featured_thumbnail_variants_json' => 'array',
'featured_thumbnails_checked_at' => 'datetime',
'published_as_type' => 'string',
'published_as_id' => 'integer',
'publish_at' => 'datetime',
@@ -271,18 +274,64 @@ class Artwork extends Model
?? 'https://files.skinbase.org/default/missing_xl.webp';
}
/**
* Audit state of `featured_thumbnail_variants_json`, distinguishing "never checked"
* from "checked, nothing found":
*
* - `null` → not audited yet (FeaturedArtworkThumbnailGenerator has never
* run plan()/generate() for this artwork).
* - `[]` → audited, but no featured variant exists in object storage.
* - non-empty string[] → audited; these variant names are known to exist.
*
* A value that fails to decode as an array (e.g. legacy/malformed data) is treated
* the same as `null` — "not audited" — rather than throwing or reporting variants
* that were never actually confirmed to exist.
*
* @return array{status: 'not_audited'|'no_variants'|'available', variants: list<string>}
*/
public function featuredThumbnailAuditState(): array
{
$raw = $this->featured_thumbnail_variants_json;
if (! is_array($raw)) {
return ['status' => 'not_audited', 'variants' => []];
}
$variants = array_values(array_filter($raw, 'is_string'));
if ($variants === []) {
return ['status' => 'no_variants', 'variants' => []];
}
return ['status' => 'available', 'variants' => $variants];
}
/**
* Whether a dedicated featured-hero variant is known to exist in object storage.
*
* This reads precomputed state from `featured_thumbnail_variants_json` (see
* `featuredThumbnailAuditState()`) rather than checking the remote disk directly —
* remote existence checks must only happen from `FeaturedArtworkThumbnailGenerator`
* (admin commands / queued jobs), never during public homepage rendering, since a
* live `Storage::exists()` per variant is a synchronous network round trip.
*/
public function hasFeaturedThumbnail(?string $variant = null): bool
{
if (empty($this->hash)) {
return false;
}
$known = $this->featuredThumbnailAuditState()['variants'];
if ($known === []) {
return false;
}
$helper = app(ArtworkFeaturedImagePath::class);
$variants = $variant !== null ? [$helper->normalizeVariant($variant)] : $helper->variantNames();
$disk = Storage::disk((string) config('uploads.object_storage.disk', 's3'));
foreach ($variants as $variantName) {
if ($disk->exists($helper->objectPath($this, $variantName))) {
if (in_array($variantName, $known, true)) {
return true;
}
}
+160
View File
@@ -0,0 +1,160 @@
<?php
declare(strict_types=1);
namespace App\Models;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\BelongsTo;
final class SecurityReport extends Model
{
protected $fillable = [
'status',
'started_at',
'finished_at',
'composer_critical',
'composer_high',
'composer_medium',
'composer_low',
'composer_unknown',
'npm_critical',
'npm_high',
'npm_moderate',
'npm_low',
'npm_info',
'npm_unknown',
'total_critical',
'total_high',
'total_medium',
'total_low',
'total_unknown',
'composer_outdated_count',
'npm_outdated_count',
'summary',
'composer_audit',
'composer_outdated',
'npm_audit',
'npm_outdated',
'error_message',
'triggered_by',
'user_id',
];
protected function casts(): array
{
return [
'started_at' => 'datetime',
'finished_at' => 'datetime',
'summary' => 'array',
'composer_audit' => 'array',
'composer_outdated' => 'array',
'npm_audit' => 'array',
'npm_outdated' => 'array',
];
}
public function user(): BelongsTo
{
return $this->belongsTo(User::class);
}
public function hasCriticalFindings(): bool
{
return $this->total_critical > 0;
}
public function hasHighFindings(): bool
{
return $this->total_high > 0;
}
public function hasDangerFindings(): bool
{
return $this->hasCriticalFindings() || $this->hasHighFindings();
}
public function getRiskLabelAttribute(): string
{
if ($this->total_critical > 0) {
return 'Critical';
}
if ($this->total_high > 0) {
return 'High';
}
if ($this->total_medium > 0) {
return 'Medium';
}
if ($this->total_low > 0) {
return 'Low';
}
return 'Clean';
}
/**
* @return array<int, array<string, mixed>>
*/
public function composerAdvisories(): array
{
$advisories = $this->composer_audit['advisories'] ?? [];
$items = [];
foreach ($advisories as $package => $packageAdvisories) {
if (! is_array($packageAdvisories)) {
continue;
}
foreach ($packageAdvisories as $advisory) {
if (! is_array($advisory)) {
continue;
}
$items[] = [
'package' => (string) $package,
'severity' => strtolower((string) ($advisory['severity'] ?? 'unknown')),
'title' => (string) ($advisory['title'] ?? $advisory['advisoryId'] ?? 'Unknown advisory'),
'cve' => (string) ($advisory['cve'] ?? $advisory['link'] ?? ''),
'affected_versions' => (string) ($advisory['affectedVersions'] ?? $advisory['affected_versions'] ?? ''),
'reported_at' => (string) ($advisory['reportedAt'] ?? ''),
'link' => (string) ($advisory['link'] ?? ''),
];
}
}
return $items;
}
/**
* @return array<int, array<string, mixed>>
*/
public function npmVulnerabilities(): array
{
$vulnerabilities = $this->npm_audit['vulnerabilities'] ?? [];
$items = [];
foreach ($vulnerabilities as $package => $vulnerability) {
if (! is_array($vulnerability)) {
continue;
}
$via = collect((array) ($vulnerability['via'] ?? []))
->first(fn (mixed $item): bool => is_array($item));
$items[] = [
'package' => (string) $package,
'severity' => strtolower((string) ($vulnerability['severity'] ?? 'unknown')),
'title' => is_array($via) ? (string) ($via['title'] ?? 'Unknown advisory') : 'Unknown advisory',
'cve' => is_array($via) ? (string) ($via['cve'] ?? '') : '',
'range' => (string) ($vulnerability['range'] ?? ''),
'fix_available' => is_array($vulnerability['fixAvailable'] ?? null) ? (string) (($vulnerability['fixAvailable']['name'] ?? '') . '@' . ($vulnerability['fixAvailable']['version'] ?? '')) : ((bool) ($vulnerability['fixAvailable'] ?? false) ? 'Yes' : ''),
'url' => is_array($via) ? (string) ($via['url'] ?? '') : '',
];
}
return $items;
}
}
@@ -0,0 +1,40 @@
<?php
declare(strict_types=1);
namespace App\Notifications;
use App\Models\SecurityReport;
use Illuminate\Bus\Queueable;
use Illuminate\Contracts\Queue\ShouldQueue;
use Illuminate\Notifications\Messages\MailMessage;
use Illuminate\Notifications\Notification;
final class SecurityReportDangerNotification extends Notification implements ShouldQueue
{
use Queueable;
public function __construct(private readonly SecurityReport $report)
{
}
public function via(object $notifiable): array
{
return ['mail'];
}
public function toMail(object $notifiable): MailMessage
{
return (new MailMessage())
->subject('Skinbase Security Report Alert')
->greeting('Security report alert')
->line('High or critical dependency vulnerabilities were detected in the latest private security scan.')
->line('Status: ' . $this->report->status)
->line('Critical: ' . $this->report->total_critical)
->line('High: ' . $this->report->total_high)
->line('Medium: ' . $this->report->total_medium)
->line('Low: ' . $this->report->total_low)
->action('Open Security Report', url('/moderation/system/security-report/' . $this->report->id))
->line('This report is private and intended for administrators only.');
}
}
+29
View File
@@ -4,6 +4,7 @@ declare(strict_types=1);
namespace App\Observers;
use App\Jobs\GenerateFeaturedArtworkThumbnailsJob;
use App\Models\Artwork;
use App\Models\ArtworkFeature;
use App\Services\HomepageService;
@@ -21,12 +22,14 @@ final class ArtworkFeatureObserver
public function created(ArtworkFeature $feature): void
{
$this->homepage->clearFeaturedAndMedalCaches();
$this->queueFeaturedThumbnailRefresh($feature);
$this->queueCreatorRebuild($feature);
}
public function updated(ArtworkFeature $feature): void
{
$this->homepage->clearFeaturedAndMedalCaches();
$this->queueFeaturedThumbnailRefresh($feature);
$this->queueCreatorRebuild($feature);
}
@@ -39,6 +42,7 @@ final class ArtworkFeatureObserver
public function restored(ArtworkFeature $feature): void
{
$this->homepage->clearFeaturedAndMedalCaches();
$this->queueFeaturedThumbnailRefresh($feature);
$this->queueCreatorRebuild($feature);
}
@@ -48,6 +52,31 @@ final class ArtworkFeatureObserver
$this->queueCreatorRebuild($feature);
}
/**
* Ensure the featured hero variants (and their DB-persisted existence state)
* are ready before the next homepage guest-cache warm cycle picks this
* artwork up as the hero winner, so the public request never has to check
* the remote disk itself.
*/
private function queueFeaturedThumbnailRefresh(ArtworkFeature $feature): void
{
$artworkId = (int) $feature->artwork_id;
if ($artworkId <= 0) {
return;
}
$artwork = $feature->relationLoaded('artwork')
? $feature->artwork
: Artwork::withTrashed()->find($artworkId);
if (! $artwork instanceof Artwork || empty($artwork->hash) || empty($artwork->file_ext)) {
return;
}
GenerateFeaturedArtworkThumbnailsJob::dispatch($artworkId);
}
private function queueCreatorRebuild(ArtworkFeature $feature): void
{
$artwork = $feature->relationLoaded('artwork')
+22 -1
View File
@@ -6,6 +6,7 @@ namespace App\Observers;
use App\Events\Achievements\AchievementCheckRequested;
use App\Models\Artwork;
use App\Jobs\GenerateFeaturedArtworkThumbnailsJob;
use App\Jobs\RecComputeSimilarByTagsJob;
use App\Jobs\RecComputeSimilarHybridJob;
use App\Jobs\Posts\AutoUploadPostJob;
@@ -15,6 +16,7 @@ use App\Services\Profile\CreatorJourneyService;
use App\Services\UserStatsService;
use App\Services\XPService;
use Illuminate\Support\Facades\Cache;
use Illuminate\Support\Facades\DB;
/**
* Syncs artwork documents to Meilisearch on every relevant model event.
@@ -61,6 +63,25 @@ class ArtworkObserver
$this->indexer->update($artwork);
// A changed hash/extension means any previously persisted
// featured_thumbnail_variants_json now refers to the WRONG object paths (they
// were computed from the old hash) — the variant names would still read as
// "available" while pointing at objects that don't exist under the new hash,
// which would surface as a broken hero image. Reset the audit state immediately
// (via a direct query, not a model save, to avoid re-entering this observer) so
// hasFeaturedThumbnail() safely reports "not audited" until the queued job below
// re-verifies and repopulates it; the public homepage never blocks on that check.
if ($artwork->wasChanged(['hash', 'file_ext'])) {
DB::table('artworks')->where('id', $artwork->id)->update([
'featured_thumbnail_variants_json' => null,
'featured_thumbnails_checked_at' => null,
]);
if (! empty($artwork->hash) && ! empty($artwork->file_ext) && $artwork->features()->exists()) {
GenerateFeaturedArtworkThumbnailsJob::dispatch((int) $artwork->id, true);
}
}
// §7.5 On-demand: recompute similarity when tags/categories could have changed.
// The pivot sync happens outside this observer, so we dispatch on every
// meaningful update and let the job be idempotent (cheap if nothing changed).
@@ -146,7 +167,7 @@ class ArtworkObserver
private function shouldClearFeaturedCaches(Artwork $artwork): bool
{
if (! $artwork->wasChanged(['published_at', 'is_public', 'is_approved', 'deleted_at', 'has_missing_thumbnails'])) {
if (! $artwork->wasChanged(['published_at', 'is_public', 'is_approved', 'deleted_at', 'has_missing_thumbnails', 'hash', 'file_ext'])) {
return false;
}
+52
View File
@@ -58,6 +58,11 @@ class AppServiceProvider extends ServiceProvider
*/
public function register(): void
{
$this->app->bind(
\Inertia\Ssr\Gateway::class,
\App\Support\Http\TimedInertiaSsrGateway::class,
);
$this->app->singleton(
\App\Services\Countries\CountryRemoteProviderInterface::class,
\App\Services\Countries\CountryRemoteProvider::class,
@@ -87,6 +92,21 @@ class AppServiceProvider extends ServiceProvider
$app->make(NullSubjectDetector::class),
]);
});
// Override Scout's default Meilisearch client binding: Scout registers it
// with no HTTP timeout, so a slow/overloaded Meilisearch leaves PHP-FPM
// workers blocked forever in curl_exec(), draining the whole pool under
// a search traffic spike. Fail fast instead.
$this->app->singleton(\Meilisearch\Client::class, function ($app) {
$config = $app['config']->get('scout.meilisearch');
$httpClient = new \GuzzleHttp\Client([
'connect_timeout' => 2,
'timeout' => 5,
]);
return new \Meilisearch\Client($config['host'], $config['key'], $httpClient);
});
}
/**
@@ -111,6 +131,8 @@ class AppServiceProvider extends ServiceProvider
$this->configureUploadRateLimiters();
$this->configureMessagingRateLimiters();
$this->configureDownloadRateLimiter();
$this->configureSearchRateLimiter();
$this->configureVectorSearchRateLimiter();
$this->configureArtworkRateLimiters();
$this->configureNovaCardRateLimiters();
$this->configureReactionRateLimiters();
@@ -468,6 +490,36 @@ class AppServiceProvider extends ServiceProvider
});
}
private function configureSearchRateLimiter(): void
{
RateLimiter::for('search', function (Request $request): array {
$userId = $request->user()?->id;
// Search fans out to Meilisearch + DB queries per request, so IP
// limits are kept tight to blunt scripted floods of /search traffic.
return [
Limit::perMinute(20)->by('search:user:' . ($userId ?? 'guest')),
Limit::perMinute(30)->by('search:ip:' . $request->ip()),
];
});
}
private function configureVectorSearchRateLimiter(): void
{
RateLimiter::for('vector-search', function (Request $request): array {
$userId = $request->user()?->id;
// Each hit here can trigger synchronous outbound HTTP to the vision
// vector gateway (image download + similarity search), so keep the
// per-IP allowance tight — unlike cached list endpoints, a flood of
// distinct artwork IDs can't be absorbed by cache alone.
return [
Limit::perMinute(30)->by('vector-search:user:' . ($userId ?? 'guest')),
Limit::perMinute(20)->by('vector-search:ip:' . $request->ip()),
];
});
}
private function configureArtworkRateLimiters(): void
{
RateLimiter::for('artwork-awards', function (Request $request): array {
+11 -2
View File
@@ -13,6 +13,7 @@ use App\Models\AcademyLessonBlock;
use App\Models\AcademyPromptPack;
use App\Models\AcademyPromptTemplate;
use App\Models\User;
use Illuminate\Support\Facades\Cache;
use Illuminate\Support\Facades\Storage;
use Illuminate\Support\Str;
use Laravel\Cashier\Subscription;
@@ -280,7 +281,9 @@ final class AcademyAccessService
public function coursePayload(AcademyCourse $course, ?User $viewer, array $options = []): array
{
$progress = is_array($options['progress'] ?? null) ? $options['progress'] : null;
$lessonCount = (int) ($course->lessons_count_cache ?: $course->courseLessons()->count());
$lessonCount = $course->relationLoaded('courseLessons')
? $course->courseLessons->count()
: (int) $course->lessons_count_cache;
return [
'id' => (int) $course->id,
@@ -1089,7 +1092,13 @@ final class AcademyAccessService
}
try {
$exists = Storage::disk((string) config('uploads.object_storage.disk', 's3'))->exists($normalizedPath);
$exists = (bool) Cache::remember(
'academy:asset-exists:'.$cacheKey,
3600,
function () use ($normalizedPath): bool {
return Storage::disk((string) config('uploads.object_storage.disk', 's3'))->exists($normalizedPath);
},
);
} catch (\Throwable) {
$exists = false;
}
@@ -16,6 +16,10 @@ class CollectionBackgroundJobService
{
public function dispatchQualityRefresh(Collection $collection, ?User $actor = null): array
{
if (! $this->dispatchEnabled()) {
return $this->disabledPayload('quality_refresh', $collection ? collect([$collection]) : collect());
}
RefreshCollectionQualityJob::dispatch((int) $collection->id, $actor?->id)->afterCommit();
return [
@@ -30,6 +34,10 @@ class CollectionBackgroundJobService
public function dispatchHealthRefresh(?Collection $collection = null, ?User $actor = null): array
{
if (! $this->dispatchEnabled()) {
return $this->disabledPayload('health_refresh', $collection ? collect([$collection]) : collect());
}
$targets = $collection ? collect([$collection]) : $this->healthTargets();
$targets->each(fn (Collection $item) => RefreshCollectionHealthJob::dispatch((int) $item->id, $actor?->id, 'programming-eligibility')->afterCommit());
@@ -39,6 +47,10 @@ class CollectionBackgroundJobService
public function dispatchRecommendationRefresh(?Collection $collection = null, ?User $actor = null, string $context = 'default'): array
{
if (! $this->dispatchEnabled()) {
return $this->disabledPayload('recommendation_refresh', $collection ? collect([$collection]) : collect());
}
$targets = $collection ? collect([$collection]) : $this->recommendationTargets();
$targets->each(fn (Collection $item) => RefreshCollectionRecommendationJob::dispatch((int) $item->id, $actor?->id, $context)->afterCommit());
@@ -48,6 +60,10 @@ class CollectionBackgroundJobService
public function dispatchDuplicateScan(?Collection $collection = null, ?User $actor = null): array
{
if (! $this->dispatchEnabled()) {
return $this->disabledPayload('duplicate_scan', $collection ? collect([$collection]) : collect());
}
$targets = $collection ? collect([$collection]) : $this->duplicateTargets();
$targets->each(fn (Collection $item) => ScanCollectionDuplicateCandidatesJob::dispatch((int) $item->id, $actor?->id)->afterCommit());
@@ -128,6 +144,29 @@ class CollectionBackgroundJobService
->get(['id']);
}
private function dispatchEnabled(): bool
{
return (bool) config('collections.v5.queue.dispatch_enabled', false);
}
/**
* @param SupportCollection<int, Collection> $targets
*/
private function disabledPayload(string $job, SupportCollection $targets): array
{
$ids = $targets->pluck('id')->map(static fn ($id): int => (int) $id)->values()->all();
return [
'status' => 'disabled',
'job' => $job,
'scope' => count($ids) === 1 ? 'single' : 'batch',
'count' => 0,
'collection_ids' => $ids,
'items' => [],
'message' => 'Collection queue dispatch is disabled until a Horizon consumer exists.',
];
}
/**
* @param SupportCollection<int, Collection> $targets
*/
@@ -7,8 +7,10 @@ namespace App\Services\Images;
use App\Models\Artwork;
use App\Services\Cdn\ArtworkCdnPurgeService;
use App\Services\ArtworkOriginalFileLocator;
use App\Services\HomepageService;
use App\Services\Uploads\UploadStorageService;
use App\Support\ArtworkFeaturedImagePath;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\File;
use Illuminate\Support\Facades\Storage;
use Intervention\Image\Drivers\Gd\Driver as GdDriver;
@@ -28,6 +30,7 @@ final class FeaturedArtworkThumbnailGenerator
private readonly ArtworkOriginalFileLocator $locator,
private readonly UploadStorageService $storage,
private readonly ArtworkCdnPurgeService $cdnPurge,
private readonly HomepageService $homepage,
) {
try {
$this->manager = extension_loaded('gd')
@@ -59,6 +62,8 @@ final class FeaturedArtworkThumbnailGenerator
$missing[] = $variant;
}
$this->persistVariantState($artwork, $existing);
return [
'existing' => $existing,
'missing' => $missing,
@@ -66,6 +71,52 @@ final class FeaturedArtworkThumbnailGenerator
];
}
/**
* Record which featured variants are known to exist so the public homepage can read
* this state instead of checking the remote disk during a request.
*
* saveQuietly() intentionally bypasses model observers (ArtworkObserver /
* ArtworkFeatureObserver never fire for this write), so cache invalidation for the
* homepage hero cannot be delegated to them here — it has to happen inline, and only
* when the persisted availability actually changed for an artwork that is currently
* an active feature (otherwise routine --all/--missing-only audits over thousands of
* non-featured artworks would repeatedly invalidate the guest payload cache for no
* reason and cause a stampede).
*
* @param list<string> $existingVariants
*/
private function persistVariantState(Artwork $artwork, array $existingVariants): void
{
$existingVariants = array_values(array_unique($existingVariants));
sort($existingVariants);
$previousVariants = (array) ($artwork->featured_thumbnail_variants_json ?? []);
sort($previousVariants);
$changed = $previousVariants !== $existingVariants;
$artwork->forceFill([
'featured_thumbnail_variants_json' => $existingVariants,
'featured_thumbnails_checked_at' => now(),
])->saveQuietly();
if ($changed && $this->isActivelyFeatured($artwork)) {
$this->homepage->clearFeaturedAndMedalCaches();
}
}
private function isActivelyFeatured(Artwork $artwork): bool
{
return DB::table('artwork_features')
->where('artwork_id', $artwork->id)
->where('is_active', true)
->whereNull('deleted_at')
->where(function ($query): void {
$query->whereNull('expires_at')->orWhere('expires_at', '>', now());
})
->exists();
}
/**
* @return array{existing:list<string>,missing:list<string>,target_variants:list<string>,generated:int,skipped:int,generated_variants:list<string>,generated_paths:list<string>,failed:array<string,string>}
*/
@@ -129,6 +180,10 @@ final class FeaturedArtworkThumbnailGenerator
]);
}
if ($generatedVariants !== []) {
$this->persistVariantState($artwork, array_values(array_unique([...$plan['existing'], ...$generatedVariants])));
}
return $plan + [
'generated' => count($generatedVariants),
'skipped' => max(0, count($targetVariants) - count($generatedVariants) - count($failed)) + count($plan['existing']),
+3 -24
View File
@@ -5,8 +5,8 @@ declare(strict_types=1);
namespace App\Services;
use App\Models\Artwork;
use App\Models\ArtworkMetricSnapshotHourly;
use App\Models\Group;
use App\Services\Metrics\ArtworkHourlySnapshotWindow;
use App\Models\Leaderboard;
use App\Models\Story;
use App\Models\StoryLike;
@@ -28,6 +28,7 @@ class LeaderboardService
public function __construct(
private readonly GroupReputationService $groupReputation,
private readonly ArtworkHourlySnapshotWindow $snapshotWindow,
) {
}
@@ -835,29 +836,7 @@ class LeaderboardService
private function artworkSnapshotDeltas(CarbonImmutable $start): \Illuminate\Database\Query\Builder
{
return ArtworkMetricSnapshotHourly::query()
->from('artwork_metric_snapshots_hourly as snapshots')
->where('snapshots.bucket_hour', '>=', $start)
->select([
'snapshots.artwork_id',
DB::raw($this->nonNegativeSnapshotDelta('views_count', 'views_delta')),
DB::raw($this->nonNegativeSnapshotDelta('downloads_count', 'downloads_delta')),
DB::raw($this->nonNegativeSnapshotDelta('favourites_count', 'favourites_delta')),
DB::raw($this->nonNegativeSnapshotDelta('comments_count', 'comments_delta')),
])
->groupBy('snapshots.artwork_id')
->toBase();
}
private function nonNegativeSnapshotDelta(string $column, string $alias): string
{
$delta = sprintf('MAX(snapshots.%1$s) - MIN(snapshots.%1$s)', $column);
if (DB::connection()->getDriverName() === 'sqlite') {
return sprintf('CASE WHEN %1$s > 0 THEN %1$s ELSE 0 END as %2$s', $delta, $alias);
}
return sprintf('GREATEST(%s, 0) as %s', $delta, $alias);
return $this->snapshotWindow->artworkPeriodDeltas($start);
}
private function creatorEntities(array $ids): array
@@ -0,0 +1,260 @@
<?php
declare(strict_types=1);
namespace App\Services\Metrics;
use Carbon\CarbonInterface;
use Illuminate\Database\Query\Builder;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
/**
* Windowed deltas from cumulative hourly artwork metric snapshots.
*
* Each snapshot stores running totals. Period growth is:
* latest in window
* - baseline at or immediately before the window start
*
* If the artwork was created/published during the window, baseline is 0.
* If an older artwork has no pre-window snapshot (warm-up / missing hours),
* fall back to MIN in the window — never SUM cumulatives, never lifetime totals.
*/
final class ArtworkHourlySnapshotWindow
{
/**
* How far before the window start to look for a baseline snapshot.
* Keeps the baseline scan bounded at 30-day table scale.
*/
public const BASELINE_LOOKBACK_HOURS = 36;
/**
* @return array{
* views: int,
* downloads: int,
* favourites: int,
* comments: int,
* shares: int,
* requested_days: int,
* table_coverage_days: float,
* user_coverage_days: float,
* window_complete: bool,
* oldest_bucket: ?string,
* newest_bucket: ?string,
* user_oldest_bucket: ?string,
* user_newest_bucket: ?string,
* }
*/
public function userWindow(int $userId, int $days = 30): array
{
$days = max(1, $days);
$coverage = $this->tableCoverage($days);
$empty = $this->emptyResult($days, $coverage);
if ($userId <= 0 || ! Schema::hasTable('artwork_metric_snapshots_hourly')) {
return $empty;
}
$since = now()->subDays($days);
$row = DB::query()
->fromSub($this->artworkPeriodDeltas($since, $userId), 'deltas')
->selectRaw('COALESCE(SUM(views_delta), 0) as views')
->selectRaw('COALESCE(SUM(downloads_delta), 0) as downloads')
->selectRaw('COALESCE(SUM(favourites_delta), 0) as favourites')
->selectRaw('COALESCE(SUM(comments_delta), 0) as comments')
->selectRaw('COALESCE(SUM(shares_delta), 0) as shares')
->first();
$userBounds = DB::table('artwork_metric_snapshots_hourly as snapshots')
->join('artworks', 'artworks.id', '=', 'snapshots.artwork_id')
->where('artworks.user_id', $userId)
->whereNull('artworks.deleted_at')
->where('snapshots.bucket_hour', '>=', $since)
->selectRaw('MIN(snapshots.bucket_hour) as oldest_bucket')
->selectRaw('MAX(snapshots.bucket_hour) as newest_bucket')
->first();
$userCoverageDays = $this->coverageDays(
$userBounds->oldest_bucket ?? null,
$userBounds->newest_bucket ?? null,
);
return [
'views' => (int) ($row->views ?? 0),
'downloads' => (int) ($row->downloads ?? 0),
'favourites' => (int) ($row->favourites ?? 0),
'comments' => (int) ($row->comments ?? 0),
'shares' => (int) ($row->shares ?? 0),
'requested_days' => $days,
'table_coverage_days' => $coverage['coverage_days'],
'user_coverage_days' => $userCoverageDays,
'window_complete' => $coverage['window_complete'],
'oldest_bucket' => $coverage['oldest_bucket'],
'newest_bucket' => $coverage['newest_bucket'],
'user_oldest_bucket' => $userBounds->oldest_bucket ?? null,
'user_newest_bucket' => $userBounds->newest_bucket ?? null,
];
}
/**
* Per-artwork non-negative period deltas for cumulative snapshot columns.
*/
public function artworkPeriodDeltas(CarbonInterface|\DateTimeInterface $start, ?int $userId = null): Builder
{
$inWindow = DB::table('artwork_metric_snapshots_hourly as snapshots');
$this->constrainOwner($inWindow, $userId);
$inWindow
->where('snapshots.bucket_hour', '>=', $start)
->groupBy('snapshots.artwork_id')
->select('snapshots.artwork_id')
->selectRaw('MAX(snapshots.views_count) as views_latest')
->selectRaw('MIN(snapshots.views_count) as views_min')
->selectRaw('MAX(snapshots.downloads_count) as downloads_latest')
->selectRaw('MIN(snapshots.downloads_count) as downloads_min')
->selectRaw('MAX(snapshots.favourites_count) as favourites_latest')
->selectRaw('MIN(snapshots.favourites_count) as favourites_min')
->selectRaw('MAX(snapshots.comments_count) as comments_latest')
->selectRaw('MIN(snapshots.comments_count) as comments_min')
->selectRaw('MAX(snapshots.shares_count) as shares_latest')
->selectRaw('MIN(snapshots.shares_count) as shares_min');
$baselineFrom = \Carbon\Carbon::parse($start)->subHours(self::BASELINE_LOOKBACK_HOURS);
$baseline = DB::table('artwork_metric_snapshots_hourly as snapshots');
$this->constrainOwner($baseline, $userId);
$baseline
->where('snapshots.bucket_hour', '<', $start)
->where('snapshots.bucket_hour', '>=', $baselineFrom)
->groupBy('snapshots.artwork_id')
->select('snapshots.artwork_id')
->selectRaw('MAX(snapshots.views_count) as views_baseline')
->selectRaw('MAX(snapshots.downloads_count) as downloads_baseline')
->selectRaw('MAX(snapshots.favourites_count) as favourites_baseline')
->selectRaw('MAX(snapshots.comments_count) as comments_baseline')
->selectRaw('MAX(snapshots.shares_count) as shares_baseline');
$bornSql = $this->quotedTimestamp($start);
return DB::query()
->fromSub($inWindow, 'win')
->leftJoinSub($baseline, 'base', 'base.artwork_id', '=', 'win.artwork_id')
->join('artworks', 'artworks.id', '=', 'win.artwork_id')
->select('win.artwork_id')
->selectRaw($this->deltaExpression('views', $bornSql) . ' as views_delta')
->selectRaw($this->deltaExpression('downloads', $bornSql) . ' as downloads_delta')
->selectRaw($this->deltaExpression('favourites', $bornSql) . ' as favourites_delta')
->selectRaw($this->deltaExpression('comments', $bornSql) . ' as comments_delta')
->selectRaw($this->deltaExpression('shares', $bornSql) . ' as shares_delta');
}
/**
* @return array{oldest_bucket: ?string, newest_bucket: ?string, coverage_days: float, window_complete: bool, requested_days: int}
*/
public function tableCoverage(int $days = 30): array
{
$days = max(1, $days);
if (! Schema::hasTable('artwork_metric_snapshots_hourly')) {
return [
'oldest_bucket' => null,
'newest_bucket' => null,
'coverage_days' => 0.0,
'window_complete' => false,
'requested_days' => $days,
];
}
$bounds = DB::table('artwork_metric_snapshots_hourly')
->selectRaw('MIN(bucket_hour) as oldest_bucket')
->selectRaw('MAX(bucket_hour) as newest_bucket')
->first();
$coverageDays = $this->coverageDays(
$bounds->oldest_bucket ?? null,
$bounds->newest_bucket ?? null,
);
return [
'oldest_bucket' => $bounds->oldest_bucket ?? null,
'newest_bucket' => $bounds->newest_bucket ?? null,
'coverage_days' => $coverageDays,
'window_complete' => $coverageDays + (1 / 24) >= $days,
'requested_days' => $days,
];
}
private function constrainOwner(Builder $query, ?int $userId): void
{
if ($userId === null) {
return;
}
$query->join('artworks as owner_artworks', 'owner_artworks.id', '=', 'snapshots.artwork_id')
->where('owner_artworks.user_id', $userId)
->whereNull('owner_artworks.deleted_at');
}
private function quotedTimestamp(CarbonInterface|\DateTimeInterface $start): string
{
return DB::getPdo()->quote(\Carbon\Carbon::parse($start)->toDateTimeString());
}
private function deltaExpression(string $metric, string $bornSql): string
{
$latest = "COALESCE(win.{$metric}_latest, 0)";
$min = "COALESCE(win.{$metric}_min, 0)";
$base = "base.{$metric}_baseline";
$bornInWindow = "COALESCE(artworks.published_at, artworks.created_at) >= {$bornSql}";
$observed = $this->clampNonNegative("{$latest} - {$min}");
$fromBaseline = $this->clampNonNegative("{$latest} - {$base}");
return "CASE WHEN {$bornInWindow} THEN {$latest} WHEN {$base} IS NOT NULL THEN {$fromBaseline} ELSE {$observed} END";
}
private function clampNonNegative(string $expression): string
{
if (DB::connection()->getDriverName() === 'sqlite') {
return "CASE WHEN ({$expression}) > 0 THEN ({$expression}) ELSE 0 END";
}
return "GREATEST({$expression}, 0)";
}
/**
* @return array<string, mixed>
*/
private function emptyResult(int $days, array $coverage): array
{
return [
'views' => 0,
'downloads' => 0,
'favourites' => 0,
'comments' => 0,
'shares' => 0,
'requested_days' => $days,
'table_coverage_days' => $coverage['coverage_days'],
'user_coverage_days' => 0.0,
'window_complete' => $coverage['window_complete'],
'oldest_bucket' => $coverage['oldest_bucket'],
'newest_bucket' => $coverage['newest_bucket'],
'user_oldest_bucket' => null,
'user_newest_bucket' => null,
];
}
private function coverageDays(?string $oldest, ?string $newest): float
{
if ($oldest === null || $newest === null) {
return 0.0;
}
$rangeStart = \Carbon\Carbon::parse($oldest);
$rangeEnd = \Carbon\Carbon::parse($newest);
if ($rangeEnd->lessThan($rangeStart)) {
return 0.0;
}
return round(abs($rangeStart->diffInMinutes($rangeEnd)) / 1440, 2);
}
}
@@ -204,7 +204,7 @@ final class CreatorJourneyService
[
'title' => 'Biggest download spike',
'headline' => (string) $bestSpike['artwork']->title,
'summary' => 'Captured the strongest one-hour download burst recorded for a public artwork.',
'summary' => 'Captured the strongest one-hour download burst in the retained hourly snapshot window.',
'value' => (int) $bestSpike['downloads_in_hour'] . ' downloads in 1 hour',
'artwork' => $this->artworkSnapshot($bestSpike['artwork']),
'metrics' => [
@@ -425,8 +425,12 @@ final class CreatorJourneyService
$publicArtworkIds = $artworks->pluck('id')->map(fn ($id): int => (int) $id)->all();
if ($publicArtworkIds !== [] && DB::getSchemaBuilder()->hasTable('artwork_metric_snapshots_hourly')) {
$lookbackDays = max(1, (int) config('metrics.hourly_snapshot_retention_days', 30));
$since = now()->subDays($lookbackDays);
$snapshots = DB::table('artwork_metric_snapshots_hourly as ms')
->whereIn('ms.artwork_id', $publicArtworkIds)
->where('ms.bucket_hour', '>=', $since)
->orderBy('ms.artwork_id')
->orderBy('ms.bucket_hour')
->get([
@@ -0,0 +1,364 @@
<?php
declare(strict_types=1);
namespace App\Services\SecurityReport;
use App\Models\SecurityReport;
use Illuminate\Support\Facades\Log;
use Symfony\Component\Process\Process;
use Throwable;
final class SecurityReportScanner
{
public function scan(string $triggeredBy = 'artisan', ?int $userId = null): SecurityReport
{
$report = SecurityReport::query()->create([
'status' => 'running',
'started_at' => now(),
'triggered_by' => $triggeredBy,
'user_id' => $userId,
]);
try {
$composerAudit = null;
$composerOutdated = null;
$npmAudit = null;
$npmOutdated = null;
if ((bool) config('security-report.scan.composer', true)) {
$composerAudit = $this->runJsonCommand((array) config('security-report.commands.composer_audit', []));
$composerOutdated = $this->runJsonCommand((array) config('security-report.commands.composer_outdated', []));
}
if ((bool) config('security-report.scan.npm', true)) {
$npmAudit = $this->runJsonCommand((array) config('security-report.commands.npm_audit', []));
$npmOutdated = $this->runJsonCommand((array) config('security-report.commands.npm_outdated', []));
}
$normalized = $this->summarizePayloads($composerAudit, $composerOutdated, $npmAudit, $npmOutdated);
$status = ($normalized['total_critical'] > 0 || $normalized['total_high'] > 0 || $normalized['total_medium'] > 0 || $normalized['total_low'] > 0)
? 'completed_with_findings'
: 'completed';
$report->update(array_merge($normalized, [
'status' => $status,
'finished_at' => now(),
'composer_audit' => $this->shouldStoreRaw() ? $this->limitRaw($composerAudit) : null,
'composer_outdated' => $this->shouldStoreRaw() ? $this->limitRaw($composerOutdated) : null,
'npm_audit' => $this->shouldStoreRaw() ? $this->limitRaw($npmAudit) : null,
'npm_outdated' => $this->shouldStoreRaw() ? $this->limitRaw($npmOutdated) : null,
]));
return $report->fresh();
} catch (Throwable $exception) {
Log::error('Security report scan failed', [
'message' => $exception->getMessage(),
]);
$report->update([
'status' => 'failed',
'finished_at' => now(),
'error_message' => $this->sanitizeText($exception->getMessage()),
]);
return $report->fresh();
}
}
/**
* @param array<string, mixed>|null $composerAudit
* @param array<string, mixed>|null $composerOutdated
* @param array<string, mixed>|null $npmAudit
* @param array<string, mixed>|null $npmOutdated
* @return array<string, mixed>
*/
public function summarizePayloads(?array $composerAudit, ?array $composerOutdated, ?array $npmAudit, ?array $npmOutdated): array
{
$composerCounts = $this->summarizeComposerAudit($composerAudit);
$npmCounts = $this->summarizeNpmAudit($npmAudit);
$composerOutdatedCount = $this->countComposerOutdated($composerOutdated);
$npmOutdatedCount = $this->countNpmOutdated($npmOutdated);
$totalCritical = $composerCounts['critical'] + $npmCounts['critical'];
$totalHigh = $composerCounts['high'] + $npmCounts['high'];
$totalMedium = $composerCounts['medium'] + $npmCounts['moderate'];
$totalLow = $composerCounts['low'] + $npmCounts['low'];
$totalUnknown = $composerCounts['unknown'] + $npmCounts['unknown'] + $npmCounts['info'];
return [
'composer_critical' => $composerCounts['critical'],
'composer_high' => $composerCounts['high'],
'composer_medium' => $composerCounts['medium'],
'composer_low' => $composerCounts['low'],
'composer_unknown' => $composerCounts['unknown'],
'npm_critical' => $npmCounts['critical'],
'npm_high' => $npmCounts['high'],
'npm_moderate' => $npmCounts['moderate'],
'npm_low' => $npmCounts['low'],
'npm_info' => $npmCounts['info'],
'npm_unknown' => $npmCounts['unknown'],
'total_critical' => $totalCritical,
'total_high' => $totalHigh,
'total_medium' => $totalMedium,
'total_low' => $totalLow,
'total_unknown' => $totalUnknown,
'composer_outdated_count' => $composerOutdatedCount,
'npm_outdated_count' => $npmOutdatedCount,
'summary' => [
'total' => [
'critical' => $totalCritical,
'high' => $totalHigh,
'medium' => $totalMedium,
'low' => $totalLow,
'unknown' => $totalUnknown,
],
'composer' => $composerCounts,
'npm' => $npmCounts,
'outdated' => [
'composer' => $composerOutdatedCount,
'npm' => $npmOutdatedCount,
],
],
];
}
/**
* @param array<string, mixed>|null $audit
* @return array{critical:int,high:int,medium:int,low:int,unknown:int}
*/
public function summarizeComposerAudit(?array $audit): array
{
$counts = [
'critical' => 0,
'high' => 0,
'medium' => 0,
'low' => 0,
'unknown' => 0,
];
if (! is_array($audit)) {
return $counts;
}
$advisories = $audit['advisories'] ?? [];
foreach ($advisories as $packageAdvisories) {
if (! is_array($packageAdvisories)) {
continue;
}
foreach ($packageAdvisories as $advisory) {
if (! is_array($advisory)) {
continue;
}
$severity = strtolower((string) ($advisory['severity'] ?? 'unknown'));
if (array_key_exists($severity, $counts)) {
$counts[$severity]++;
} else {
$counts['unknown']++;
}
}
}
return $counts;
}
/**
* @param array<string, mixed>|null $audit
* @return array{critical:int,high:int,moderate:int,low:int,info:int,unknown:int}
*/
public function summarizeNpmAudit(?array $audit): array
{
$counts = [
'critical' => 0,
'high' => 0,
'moderate' => 0,
'low' => 0,
'info' => 0,
'unknown' => 0,
];
if (! is_array($audit)) {
return $counts;
}
if (isset($audit['metadata']['vulnerabilities']) && is_array($audit['metadata']['vulnerabilities'])) {
$vulnerabilities = $audit['metadata']['vulnerabilities'];
$counts['critical'] = (int) ($vulnerabilities['critical'] ?? 0);
$counts['high'] = (int) ($vulnerabilities['high'] ?? 0);
$counts['moderate'] = (int) ($vulnerabilities['moderate'] ?? 0);
$counts['low'] = (int) ($vulnerabilities['low'] ?? 0);
$counts['info'] = (int) ($vulnerabilities['info'] ?? 0);
return $counts;
}
$vulnerabilities = $audit['vulnerabilities'] ?? [];
foreach ($vulnerabilities as $vulnerability) {
if (! is_array($vulnerability)) {
continue;
}
$severity = strtolower((string) ($vulnerability['severity'] ?? 'unknown'));
if (array_key_exists($severity, $counts)) {
$counts[$severity]++;
} else {
$counts['unknown']++;
}
}
return $counts;
}
/**
* @param array<int, string> $command
* @return array<string, mixed>|null
*/
private function runJsonCommand(array $command): ?array
{
if ($command === []) {
return null;
}
$process = new Process(
$command,
base_path(),
null,
null,
(float) config('security-report.timeout_seconds', 180),
);
$process->run();
$output = trim($process->getOutput());
$errorOutput = trim($process->getErrorOutput());
if ($output === '') {
return [
'_status' => $errorOutput !== '' ? 'no_json_output' : 'empty_output',
'_exit_code' => $process->getExitCode(),
'_error' => $errorOutput !== '' ? $this->sanitizeText(mb_substr($errorOutput, 0, 5000)) : null,
];
}
$json = json_decode($output, true);
if (json_last_error() !== JSON_ERROR_NONE || ! is_array($json)) {
return [
'_status' => 'invalid_json',
'_exit_code' => $process->getExitCode(),
'_json_error' => json_last_error_msg(),
'_output_preview' => $this->sanitizeText(mb_substr($output, 0, 5000)),
'_error_preview' => $this->sanitizeText(mb_substr($errorOutput, 0, 5000)),
];
}
$json['_exit_code'] = $process->getExitCode();
return $this->sanitizeArray($json);
}
/**
* @param array<string, mixed>|null $outdated
*/
private function countComposerOutdated(?array $outdated): int
{
if (! is_array($outdated)) {
return 0;
}
return isset($outdated['installed']) && is_array($outdated['installed'])
? count($outdated['installed'])
: 0;
}
/**
* @param array<string, mixed>|null $outdated
*/
private function countNpmOutdated(?array $outdated): int
{
if (! is_array($outdated)) {
return 0;
}
return count(array_filter(
$outdated,
static fn (mixed $value, mixed $key): bool => is_array($value) && ! str_starts_with((string) $key, '_'),
ARRAY_FILTER_USE_BOTH,
));
}
private function shouldStoreRaw(): bool
{
return (bool) config('security-report.store_raw', true);
}
/**
* @param array<string, mixed>|null $data
* @return array<string, mixed>|null
*/
private function limitRaw(?array $data): ?array
{
if ($data === null) {
return null;
}
$sanitized = $this->sanitizeArray($data);
$maxBytes = max(64, (int) config('security-report.max_raw_kb', 512)) * 1024;
$json = json_encode($sanitized, JSON_UNESCAPED_SLASHES | JSON_INVALID_UTF8_SUBSTITUTE);
if (! is_string($json)) {
return [
'_status' => 'raw_encode_failed',
];
}
if (strlen($json) <= $maxBytes) {
return $sanitized;
}
return [
'_status' => 'truncated',
'_max_kb' => (int) config('security-report.max_raw_kb', 512),
'_preview' => mb_substr($json, 0, $maxBytes),
];
}
/**
* @param array<mixed> $data
* @return array<mixed>
*/
private function sanitizeArray(array $data): array
{
$sanitized = [];
foreach ($data as $key => $value) {
if (is_array($value)) {
$sanitized[$key] = $this->sanitizeArray($value);
continue;
}
if (is_string($value)) {
$sanitized[$key] = $this->sanitizeText($value);
continue;
}
$sanitized[$key] = $value;
}
return $sanitized;
}
private function sanitizeText(string $value): string
{
$normalized = str_replace(["\r\n", "\r"], "\n", $value);
$normalized = str_replace(base_path(), '[project-root]', $normalized);
$normalized = preg_replace('/[A-Z]:\\\\[^\s"\']+/', '[path]', $normalized) ?? $normalized;
return trim($normalized);
}
}
@@ -0,0 +1,38 @@
<?php
declare(strict_types=1);
namespace App\Services\Sitemaps\Builders;
use App\Services\Sitemaps\AbstractSitemapBuilder;
use App\Services\Sitemaps\SitemapUrlBuilder;
use DateTimeInterface;
final class AcademyPagesSitemapBuilder extends AbstractSitemapBuilder
{
public function __construct(private readonly SitemapUrlBuilder $urls)
{
}
public function name(): string
{
return 'academy-pages';
}
public function items(): array
{
if (! (bool) config('academy.enabled', true)) {
return [];
}
return [
$this->urls->staticRoute('/academy'),
$this->urls->staticRoute('/academy/pricing'),
];
}
public function lastModified(): ?DateTimeInterface
{
return null;
}
}
@@ -27,7 +27,10 @@ final class AcademyPromptsSitemapBuilder extends AbstractSitemapBuilder
return [];
}
$items = [$this->urls->staticRoute('/academy/prompts')];
$items = [
$this->urls->staticRoute('/academy/prompts'),
$this->urls->staticRoute('/academy/prompts/popular'),
];
$details = AcademyPromptTemplate::query()
->active()
@@ -24,8 +24,6 @@ final class StaticPagesSitemapBuilder extends AbstractSitemapBuilder
{
$items = [
$this->urls->staticRoute('/'),
$this->urls->staticRoute('/academy'),
$this->urls->staticRoute('/academy/pricing'),
$this->urls->staticRoute('/web-stories'),
$this->urls->staticRoute('/faq'),
$this->urls->staticRoute('/rules-and-guidelines'),
@@ -5,12 +5,12 @@ declare(strict_types=1);
namespace App\Services\Sitemaps\Builders;
use App\Models\Tag;
use App\Services\Sitemaps\AbstractSitemapBuilder;
use App\Services\Sitemaps\SitemapUrl;
use App\Services\Sitemaps\SitemapUrlBuilder;
use DateTimeInterface;
use Illuminate\Database\Eloquent\Builder;
use Illuminate\Database\Eloquent\Model;
final class TagsSitemapBuilder extends AbstractSitemapBuilder
final class TagsSitemapBuilder extends AbstractIdShardableSitemapBuilder
{
public function __construct(private readonly SitemapUrlBuilder $urls)
{
@@ -21,25 +21,21 @@ final class TagsSitemapBuilder extends AbstractSitemapBuilder
return 'tags';
}
public function items(): array
protected function shardConfigKey(): string
{
return 'tags';
}
protected function mapRecord(Model $record): ?SitemapUrl
{
return $this->urls->tag($record);
}
protected function query(): Builder
{
return Tag::query()
->where('is_active', true)
->where('usage_count', '>', 0)
->whereHas('artworks', fn ($query) => $query->public()->published())
->orderByDesc('usage_count')
->orderBy('slug')
->get()
->map(fn (Tag $tag): SitemapUrl => $this->urls->tag($tag))
->values()
->all();
}
public function lastModified(): ?DateTimeInterface
{
return $this->dateTime(Tag::query()
->where('is_active', true)
->where('usage_count', '>', 0)
->max('updated_at'));
->whereHas('artworks', fn ($query) => $query->public()->published());
}
}
@@ -102,6 +102,14 @@ final class PublishedSitemapResolver
}
}
foreach ((array) ($manifest['groups'] ?? []) as $groupName => $group) {
$entryName = (string) ($group['entry_name'] ?? '');
if ($requestedName === $groupName && $entryName !== '') {
return $entryName;
}
}
return null;
}
}
@@ -42,6 +42,23 @@ final class SitemapBuildService
*/
public function buildNamed(string $name, bool $force = false, bool $persist = true): ?array
{
$groupFamilies = $this->groupFamilies($name);
if ($groupFamilies !== null) {
$built = $this->cache->remember(
$name,
fn (): string => $this->renderer->renderIndex($this->index->itemsForFamilies($groupFamilies)),
$force,
$persist,
);
return $built + [
'type' => SitemapTarget::TYPE_INDEX,
'url_count' => count($this->index->itemsForFamilies($groupFamilies)),
'shard_count' => 0,
'name' => $name,
];
}
$target = $this->shards->resolve($this->registry, $name);
if ($target === null) {
@@ -111,6 +128,24 @@ final class SitemapBuildService
));
}
/**
* @return list<string>|null
*/
public function groupFamilies(string $name): ?array
{
$families = $this->index->activeGroupIndexes($this->enabledFamilies())[$name] ?? null;
return is_array($families) && $families !== [] ? $families : null;
}
/**
* @return array<string, list<string>>
*/
public function enabledGroupIndexes(): array
{
return $this->index->activeGroupIndexes($this->enabledFamilies());
}
private function renderTarget(SitemapTarget $target): string
{
if ($target->type === SitemapTarget::TYPE_INDEX) {
+110 -1
View File
@@ -4,6 +4,9 @@ declare(strict_types=1);
namespace App\Services\Sitemaps;
use DateTimeImmutable;
use DateTimeInterface;
final class SitemapIndexService
{
public function __construct(
@@ -18,8 +21,25 @@ final class SitemapIndexService
public function items(?array $families = null): array
{
$items = [];
$selectedFamilies = $families ?? (array) config('sitemaps.enabled', []);
$groupedFamilies = [];
foreach ($this->activeGroupIndexes($selectedFamilies) as $groupName => $groupFamilies) {
$items[] = new SitemapIndexItem(
url('/sitemaps/' . $groupName . '.xml'),
$this->lastModifiedForFamilies($groupFamilies),
);
foreach ($groupFamilies as $family) {
$groupedFamilies[$family] = true;
}
}
foreach ($selectedFamilies as $name) {
if (isset($groupedFamilies[(string) $name])) {
continue;
}
foreach ($families ?? (array) config('sitemaps.enabled', []) as $name) {
$builder = $this->registry->get((string) $name);
if ($builder === null) {
@@ -35,6 +55,30 @@ final class SitemapIndexService
return $items;
}
/**
* @param list<string> $families
* @return list<SitemapIndexItem>
*/
public function itemsForFamilies(array $families): array
{
$items = [];
foreach ($families as $family) {
$builder = $this->registry->get($family);
if ($builder === null) {
continue;
}
$items[] = new SitemapIndexItem(
url('/sitemaps/' . $this->shards->rootEntryName($builder) . '.xml'),
$builder->lastModified(),
);
}
return $items;
}
/**
* @return list<SitemapIndexItem>
*/
@@ -58,4 +102,69 @@ final class SitemapIndexService
$builder->lastModified(),
)];
}
/**
* @param list<string> $selectedFamilies
* @return array<string, list<string>>
*/
public function activeGroupIndexes(array $selectedFamilies): array
{
$selectedLookup = array_fill_keys($selectedFamilies, true);
$groups = [];
foreach ((array) config('sitemaps.group_indexes', []) as $groupName => $groupFamilies) {
if (! is_string($groupName) || $groupName === '') {
continue;
}
$validFamilies = array_values(array_filter(
(array) $groupFamilies,
fn (mixed $family): bool => is_string($family) && $family !== '' && $this->registry->get($family) !== null,
));
if ($validFamilies === []) {
continue;
}
foreach ($validFamilies as $family) {
if (! isset($selectedLookup[$family])) {
continue 2;
}
}
$groups[$groupName] = $validFamilies;
}
return $groups;
}
/**
* @param list<string> $families
*/
private function lastModifiedForFamilies(array $families): ?DateTimeInterface
{
$latest = null;
foreach ($families as $family) {
$builder = $this->registry->get($family);
if ($builder === null) {
continue;
}
$lastModified = $builder->lastModified();
if ($lastModified !== null) {
$candidate = $lastModified instanceof DateTimeInterface
? $lastModified
: new DateTimeImmutable((string) $lastModified);
if ($latest === null || $candidate->getTimestamp() > $latest->getTimestamp()) {
$latest = $candidate;
}
}
}
return $latest;
}
}
@@ -130,6 +130,7 @@ final class SitemapPublishService
$releaseId ??= $this->releases->generateReleaseId();
$familyManifest = [];
$groupManifest = [];
$documents = [
SitemapCacheService::INDEX_DOCUMENT => $this->releases->documentRelativePath(SitemapCacheService::INDEX_DOCUMENT),
];
@@ -180,15 +181,43 @@ final class SitemapPublishService
];
}
foreach ($this->build->enabledGroupIndexes() as $groupName => $groupFamilies) {
foreach ($groupFamilies as $family) {
if (! in_array($family, $selectedFamilies, true)) {
continue 2;
}
}
$built = $this->build->buildNamed($groupName, true, false);
if ($built === null) {
throw new \RuntimeException('Failed to build sitemap group [' . $groupName . '].');
}
$this->releases->putDocument($releaseId, $groupName, (string) $built['content']);
$documents[$groupName] = $this->releases->documentRelativePath($groupName);
$groupManifest[$groupName] = [
'name' => $groupName,
'entry_name' => $groupName,
'families' => $groupFamilies,
'documents' => [$groupName],
'url_count' => (int) $built['url_count'],
'type' => SitemapTarget::TYPE_INDEX,
];
}
$manifest = [
'release_id' => $releaseId,
'status' => 'built',
'built_at' => now()->toAtomString(),
'published_at' => null,
'families' => $familyManifest,
'groups' => $groupManifest,
'documents' => $documents,
'totals' => [
'families' => count($familyManifest),
'groups' => count($groupManifest),
'documents' => count($documents),
'urls' => $totalUrls,
],
@@ -8,6 +8,7 @@ use App\Services\Sitemaps\Builders\ArtworksSitemapBuilder;
use App\Services\Sitemaps\Builders\AcademyChallengesSitemapBuilder;
use App\Services\Sitemaps\Builders\AcademyCoursesSitemapBuilder;
use App\Services\Sitemaps\Builders\AcademyLessonsSitemapBuilder;
use App\Services\Sitemaps\Builders\AcademyPagesSitemapBuilder;
use App\Services\Sitemaps\Builders\AcademyPacksSitemapBuilder;
use App\Services\Sitemaps\Builders\AcademyPromptsSitemapBuilder;
use App\Services\Sitemaps\Builders\CardsSitemapBuilder;
@@ -33,6 +34,7 @@ final class SitemapRegistry
public function __construct(
ArtworksSitemapBuilder $artworks,
AcademyPagesSitemapBuilder $academyPages,
AcademyCoursesSitemapBuilder $academyCourses,
AcademyLessonsSitemapBuilder $academyLessons,
AcademyPromptsSitemapBuilder $academyPrompts,
@@ -54,6 +56,7 @@ final class SitemapRegistry
) {
$this->builders = [
$artworks->name() => $artworks,
$academyPages->name() => $academyPages,
$academyCourses->name() => $academyCourses,
$academyLessons->name() => $academyLessons,
$academyPrompts->name() => $academyPrompts,
@@ -32,6 +32,7 @@ final class SitemapReleaseValidator
$errors = [];
$families = (array) ($manifest['families'] ?? []);
$groups = (array) ($manifest['groups'] ?? []);
$documents = (array) ($manifest['documents'] ?? []);
$rootContent = $this->releases->getDocument($releaseId, SitemapCacheService::INDEX_DOCUMENT);
@@ -41,10 +42,9 @@ final class SitemapReleaseValidator
$errors[] = 'Root sitemap.xml is missing or invalid.';
} else {
$rootLocs = $this->extractLocs($rootXml, 'sitemap');
$expectedRootLocs = array_map(
fn (string $entryName): string => url('/sitemaps/' . $entryName . '.xml'),
array_values(array_map(static fn (array $family): string => (string) ($family['entry_name'] ?? ''), $families)),
);
$expectedRoot = $this->build->buildIndex(true, false, array_keys($families));
$expectedRootXml = $this->loadXml((string) $expectedRoot['content']);
$expectedRootLocs = $expectedRootXml ? $this->extractLocs($expectedRootXml, 'sitemap') : [];
if ($rootLocs !== $expectedRootLocs) {
$errors[] = 'Root sitemap index does not match the manifest family entries.';
@@ -147,13 +147,48 @@ final class SitemapReleaseValidator
}
}
$groupReports = [];
foreach ($groups as $groupName => $group) {
$groupErrors = [];
$documentName = (string) ($group['entry_name'] ?? $groupName);
$artifact = $this->releases->getDocument($releaseId, $documentName);
if (! is_string($artifact) || $artifact === '') {
$groupErrors[] = 'Missing artifact [' . $documentName . '].';
} else {
$artifactXml = $this->loadXml($artifact);
$expected = $this->build->buildNamed($documentName, true, false);
$expectedXml = $expected !== null ? $this->loadXml((string) $expected['content']) : null;
if ($artifactXml === null || $expectedXml === null) {
$groupErrors[] = 'Invalid XML in group artifact [' . $documentName . '].';
} elseif ($this->extractLocs($artifactXml, 'sitemap') !== $this->extractLocs($expectedXml, 'sitemap')) {
$groupErrors[] = 'Group index artifact [' . $documentName . '] does not match expected sitemap references.';
}
}
$groupReports[] = [
'group' => $groupName,
'documents' => count((array) ($group['documents'] ?? [])),
'url_count' => (int) ($group['url_count'] ?? 0),
'errors' => $groupErrors,
];
foreach ($groupErrors as $groupError) {
$errors[] = $groupName . ': ' . $groupError;
}
}
return [
'ok' => $errors === [],
'release_id' => $releaseId,
'errors' => $errors,
'families' => $reports,
'groups' => $groupReports,
'totals' => [
'families' => count($families),
'groups' => count($groups),
'documents' => count($documents),
'urls' => array_sum(array_map(static fn (array $family): int => (int) ($family['url_count'] ?? 0), $families)),
'shards' => array_sum(array_map(static fn (array $family): int => (int) ($family['shard_count'] ?? 0), $families)),
@@ -8,8 +8,8 @@ use Illuminate\Support\Facades\Storage;
/**
* Writes every document from a published release to the public disk so nginx
* can serve sitemap.xml and sitemaps/{name}.xml as plain static files,
* bypassing PHP entirely on subsequent requests.
* can serve sitemaps/{name}.xml as plain static files, bypassing PHP on
* subsequent child-sitemap requests. The root /sitemap.xml stays dynamic.
*/
final class SitemapStaticPublisher
{
@@ -50,6 +50,7 @@ final class SitemapStaticPublisher
}
$disk->put((string) $relativePath, $content);
$written++;
}
@@ -29,15 +29,7 @@ final class SitemapValidationService
? array_values(array_filter($onlyFamilies, fn (string $family): bool => $this->registry->get($family) !== null))
: $this->build->enabledFamilies();
$expectedIndexLocs = array_map(
static fn (SitemapIndexItem $item): string => $item->loc,
array_values(array_filter(
$this->index->items(),
fn (SitemapIndexItem $item): bool => $this->isFamilySelected($families, $item->loc),
)),
);
$indexBuild = $this->build->buildIndex(true, false);
$indexBuild = $this->build->buildIndex(true, false, $families);
$indexErrors = [];
$indexXml = $this->loadXml($indexBuild['content']);
@@ -45,6 +37,7 @@ final class SitemapValidationService
$indexErrors[] = 'The main sitemap index XML could not be parsed.';
}
$expectedIndexLocs = $this->extractLocsFromContent((string) $indexBuild['content'], 'sitemap');
$actualIndexLocs = $indexXml ? $this->extractLocs($indexXml, 'sitemap') : [];
if ($indexXml !== null && $actualIndexLocs !== $expectedIndexLocs) {
$indexErrors[] = 'Main sitemap index child references do not match the expected shard-aware manifest.';
@@ -214,15 +207,14 @@ final class SitemapValidationService
return $locs;
}
private function isFamilySelected(array $families, string $loc): bool
/**
* @return list<string>
*/
private function extractLocsFromContent(string $content, string $nodeName): array
{
foreach ($families as $family) {
if (str_contains($loc, '/sitemaps/' . $family . '.xml') || str_contains($loc, '/sitemaps/' . $family . '-')) {
return true;
}
}
$document = $this->loadXml($content);
return false;
return $document === null ? [] : $this->extractLocs($document, $nodeName);
}
private function urlError(string $family, string $loc): ?string
@@ -8,6 +8,7 @@ use App\Models\CollectionComment;
use App\Models\NovaCardComment;
use App\Models\StoryComment;
use App\Models\User;
use App\Services\Metrics\ArtworkHourlySnapshotWindow;
use App\Support\AvatarUrl;
use Illuminate\Support\Facades\DB;
@@ -21,6 +22,7 @@ final class CreatorStudioOverviewService
private readonly CreatorStudioPreferenceService $preferences,
private readonly CreatorStudioChallengeService $challenges,
private readonly CreatorStudioGrowthService $growth,
private readonly ArtworkHourlySnapshotWindow $snapshotWindow,
) {
}
@@ -32,15 +34,24 @@ final class CreatorStudioOverviewService
$challengeData = $this->challenges->build($user);
$growthData = $this->growth->build($user, $preferences['analytics_range_days']);
$featuredContent = $this->content->selectedItems($user, $preferences['featured_content']);
$window = $this->snapshotWindow->userWindow((int) $user->id, 30);
return [
'kpis' => [
'total_content' => $analytics['totals']['content_count'],
'views_30d' => $analytics['totals']['views'],
'appreciation_30d' => $analytics['totals']['appreciation'],
'shares_30d' => $analytics['totals']['shares'],
'comments_30d' => $analytics['totals']['comments'],
'views_30d' => $window['views'],
'appreciation_30d' => $window['favourites'],
'shares_30d' => $window['shares'],
'comments_30d' => $window['comments'],
'followers' => $analytics['totals']['followers'],
'snapshot_window' => [
'requested_days' => $window['requested_days'],
'table_coverage_days' => $window['table_coverage_days'],
'user_coverage_days' => $window['user_coverage_days'],
'window_complete' => $window['window_complete'],
'oldest_bucket' => $window['oldest_bucket'],
'newest_bucket' => $window['newest_bucket'],
],
],
'module_summaries' => $moduleSummaries,
'quick_create' => $this->content->quickCreate(),
+32 -36
View File
@@ -6,6 +6,7 @@ namespace App\Services\Studio;
use App\Models\Artwork;
use App\Models\ArtworkStats;
use App\Services\Metrics\ArtworkHourlySnapshotWindow;
use Illuminate\Support\Facades\Cache;
use Illuminate\Support\Facades\DB;
@@ -16,10 +17,26 @@ final class StudioMetricsService
{
private const CACHE_TTL = 300; // 5 minutes
public function __construct(
private readonly ArtworkHourlySnapshotWindow $snapshotWindow,
) {
}
/**
* Get dashboard KPI metrics for a creator.
*
* @return array{total_artworks: int, views_30d: int, favourites_30d: int, shares_30d: int, followers: int}
* 30-day counters are latest-minus-baseline deltas of cumulative hourly snapshots, never SUM.
*
* @return array{
* total_artworks: int,
* views_30d: int,
* favourites_30d: int,
* shares_30d: int,
* downloads_30d: int,
* comments_30d: int,
* followers: int,
* snapshot_window: array<string, mixed>
* }
*/
public function getDashboardKpis(int $userId): array
{
@@ -30,35 +47,7 @@ final class StudioMetricsService
->whereNull('deleted_at')
->count();
// Aggregate stats from artwork_stats for this user's artworks
$statsAgg = DB::table('artwork_stats')
->join('artworks', 'artworks.id', '=', 'artwork_stats.artwork_id')
->where('artworks.user_id', $userId)
->whereNull('artworks.deleted_at')
->selectRaw('
COALESCE(SUM(artwork_stats.views), 0) as total_views,
COALESCE(SUM(artwork_stats.favorites), 0) as total_favourites,
COALESCE(SUM(artwork_stats.shares_count), 0) as total_shares
')
->first();
// Views in last 30 days from hourly snapshots if available, fallback to totals
$views30d = 0;
try {
if (\Illuminate\Support\Facades\Schema::hasTable('artwork_metric_snapshots_hourly')) {
$views30d = (int) DB::table('artwork_metric_snapshots_hourly')
->join('artworks', 'artworks.id', '=', 'artwork_metric_snapshots_hourly.artwork_id')
->where('artworks.user_id', $userId)
->where('artwork_metric_snapshots_hourly.bucket_hour', '>=', now()->subDays(30))
->sum('artwork_metric_snapshots_hourly.views_count');
}
} catch (\Throwable $e) {
// Table or column doesn't exist — fall back to totals
}
if ($views30d === 0) {
$views30d = (int) ($statsAgg->total_views ?? 0);
}
$window = $this->snapshotWindow->userWindow($userId, 30);
$followers = DB::table('user_followers')
->where('user_id', $userId)
@@ -66,10 +55,20 @@ final class StudioMetricsService
return [
'total_artworks' => $totalArtworks,
'views_30d' => $views30d,
'favourites_30d' => (int) ($statsAgg->total_favourites ?? 0),
'shares_30d' => (int) ($statsAgg->total_shares ?? 0),
'views_30d' => $window['views'],
'favourites_30d' => $window['favourites'],
'shares_30d' => $window['shares'],
'downloads_30d' => $window['downloads'],
'comments_30d' => $window['comments'],
'followers' => $followers,
'snapshot_window' => [
'requested_days' => $window['requested_days'],
'table_coverage_days' => $window['table_coverage_days'],
'user_coverage_days' => $window['user_coverage_days'],
'window_complete' => $window['window_complete'],
'oldest_bucket' => $window['oldest_bucket'],
'newest_bucket' => $window['newest_bucket'],
],
];
});
}
@@ -145,7 +144,6 @@ final class StudioMetricsService
$cacheKey = "studio.analytics_overview.{$userId}";
return Cache::remember($cacheKey, self::CACHE_TTL, function () use ($userId) {
// Totals
$totals = DB::table('artwork_stats')
->join('artworks', 'artworks.id', '=', 'artwork_stats.artwork_id')
->where('artworks.user_id', $userId)
@@ -161,7 +159,6 @@ final class StudioMetricsService
')
->first();
// Top 10 artworks by ranking score
$topArtworks = Artwork::where('user_id', $userId)
->whereNull('deleted_at')
->where('is_public', true)
@@ -188,7 +185,6 @@ final class StudioMetricsService
'heat_score' => (float) ($art->stats?->heat_score ?? 0),
]);
// Content type breakdown
$contentBreakdown = DB::table('artworks')
->join('artwork_category', 'artwork_category.artwork_id', '=', 'artworks.id')
->join('categories', 'categories.id', '=', 'artwork_category.category_id')
@@ -181,7 +181,29 @@ class OnlineVisitorRepository
*/
protected function readIndexMembers(): array
{
return array_map('strval', Redis::smembers(self::INDEX_KEY));
$members = [];
$cursor = '0';
$limit = max(1, (int) config('traffic.online_visitors.index_read_limit', 2000));
do {
$result = Redis::sscan(self::INDEX_KEY, (int) $cursor, ['count' => 200]);
if (! is_array($result) || count($result) < 2) {
break;
}
$cursor = (string) $result[0];
foreach ($result[1] as $member) {
$members[] = (string) $member;
if (count($members) >= $limit) {
return $members;
}
}
} while ($cursor !== '0');
return $members;
}
/**
@@ -0,0 +1,116 @@
<?php
declare(strict_types=1);
namespace App\Services\Traffic;
use Illuminate\Support\Facades\Redis;
final class PresenceIndexPruner
{
private const SREM_IF_EXPIRED = <<<'LUA'
if redis.call('EXISTS', KEYS[1]) == 0 then
return redis.call('SREM', KEYS[2], ARGV[1])
end
return 0
LUA;
/**
* @return array{scanned:int,stale:int,removed:int,live:int,batches:int,dry_run:bool}
*/
public function prune(
int $scanCount,
int $maxBatches,
int $maxMembers,
int $sleepMs,
bool $dryRun,
?int $timeLimitSeconds = null,
): array {
$scanCount = max(10, $scanCount);
$maxBatches = max(1, $maxBatches);
$maxMembers = max(1, $maxMembers);
$started = microtime(true);
$cursor = 0;
$scanned = 0;
$stale = 0;
$removed = 0;
$live = 0;
$batches = 0;
while ($batches < $maxBatches && $scanned < $maxMembers) {
if ($timeLimitSeconds !== null && (microtime(true) - $started) >= $timeLimitSeconds) {
break;
}
$result = Redis::sscan(OnlineVisitorRepository::INDEX_KEY, $cursor, ['count' => $scanCount]);
if (! is_array($result) || count($result) < 2) {
break;
}
$cursor = (int) $result[0];
$members = $result[1];
$batches++;
if ($members === []) {
if ($cursor === 0) {
break;
}
continue;
}
$recordKeys = [];
foreach ($members as $member) {
$member = (string) $member;
$recordKeys[$member] = OnlineVisitorRepository::KEY_PREFIX.':'.$member;
}
$exists = Redis::pipeline(function ($pipe) use ($recordKeys): void {
foreach ($recordKeys as $recordKey) {
$pipe->exists($recordKey);
}
});
if (! is_array($exists)) {
$exists = [];
}
$i = 0;
foreach ($recordKeys as $member => $recordKey) {
$scanned++;
$isLive = (int) ($exists[$i] ?? 0) === 1;
$i++;
if ($isLive) {
$live++;
continue;
}
$stale++;
if ($dryRun) {
continue;
}
$removed += (int) Redis::eval(
self::SREM_IF_EXPIRED,
2,
$recordKey,
OnlineVisitorRepository::INDEX_KEY,
$member,
);
}
if ($sleepMs > 0) {
usleep($sleepMs * 1000);
}
if ($cursor === 0) {
break;
}
}
return [
'scanned' => $scanned,
'stale' => $stale,
'removed' => $removed,
'live' => $live,
'batches' => $batches,
'dry_run' => $dryRun,
];
}
}
@@ -8,12 +8,18 @@ use App\Models\Artwork;
use Illuminate\Http\UploadedFile;
use Illuminate\Support\Facades\Cache;
use Illuminate\Support\Facades\Http;
use RuntimeException;
use Throwable;
final class AiArtworkVectorSearchService
{
private const MAX_SIMILAR_RESULTS = 120;
/** qdrant-svc /vectors/search* reject limit > 100. */
private const VECTOR_GATEWAY_MAX_SEARCH_RESULTS = 100;
/**
* Public similar-ai may request at most 99 items because we fetch one extra
* candidate so the source artwork can be excluded from the result set.
*/
private const MAX_ARTWORK_SIMILAR_RESULTS = 99;
public function __construct(
private readonly VectorGatewayClient $client,
@@ -31,12 +37,13 @@ final class AiArtworkVectorSearchService
*/
public function similarToArtwork(Artwork $artwork, int $limit = 12): array
{
$safeLimit = max(1, min(self::MAX_SIMILAR_RESULTS, $limit));
$safeLimit = max(1, min(self::MAX_ARTWORK_SIMILAR_RESULTS, $limit));
$cacheKey = sprintf('rec:artwork:%d:similar-ai:%d', $artwork->id, $safeLimit);
$ttl = max(60, (int) config('recommendations.ttl.similar_artworks', 30 * 60));
return Cache::remember($cacheKey, $ttl, function () use ($artwork, $safeLimit): array {
$matches = $this->searchMatchesForArtwork($artwork, $safeLimit + 1);
$gatewayLimit = min(self::VECTOR_GATEWAY_MAX_SEARCH_RESULTS, $safeLimit + 1);
$matches = $this->searchMatchesForArtwork($artwork, $gatewayLimit);
return $this->resolveMatches($matches, $safeLimit, $artwork->id);
});
@@ -47,7 +54,7 @@ final class AiArtworkVectorSearchService
*/
public function searchByUploadedImage(UploadedFile $file, int $limit = 12): array
{
$safeLimit = max(1, min(self::MAX_SIMILAR_RESULTS, $limit));
$safeLimit = max(1, min(self::VECTOR_GATEWAY_MAX_SEARCH_RESULTS, $limit));
$matches = $this->client->searchByUploadedFile($file, $safeLimit);
return $this->resolveMatches($matches, $safeLimit);
@@ -58,10 +65,12 @@ final class AiArtworkVectorSearchService
*/
private function downloadArtworkImage(Artwork $artwork, string $url): ?array
{
// Runs synchronously in the web request path — keep the budget tight
// so a slow origin can't pin an FPM worker for 20s+.
$response = Http::accept('*/*')
->connectTimeout(5)
->timeout(20)
->retry(1, 200, throw: false)
->connectTimeout(2)
->timeout(6)
->retry(0)
->get($url);
if (! $response->ok()) {
@@ -91,11 +100,15 @@ final class AiArtworkVectorSearchService
return [];
}
$this->client->assertCircuitClosed();
$fileFailure = null;
$fileGatewayAttempted = false;
try {
$payload = $this->downloadArtworkImage($artwork, $url);
if ($payload !== null) {
$fileGatewayAttempted = true;
return $this->client->searchByFileContents($payload['contents'], $payload['filename'], $limit);
}
} catch (Throwable $e) {
@@ -104,24 +117,69 @@ final class AiArtworkVectorSearchService
try {
return $this->client->searchByUrl($url, $limit);
} catch (Throwable $e) {
throw $this->normalizeSearchFailure($fileFailure, $e);
} catch (Throwable $fallbackFailure) {
if ($this->shouldTripSimilarAiCircuit($fileGatewayAttempted, $fileFailure, $fallbackFailure)) {
$this->client->tripIfCircuitWorthy(
[$fileFailure, $fallbackFailure],
'similar_ai',
['artwork_id' => (int) $artwork->id],
);
}
throw $this->normalizeSearchFailure($fileFailure, $fallbackFailure);
}
}
private function normalizeSearchFailure(?Throwable $fileFailure, Throwable $fallbackFailure): RuntimeException
private function normalizeSearchFailure(?Throwable $fileFailure, Throwable $fallbackFailure): VectorGatewayException
{
if ($fileFailure === null) {
return $fallbackFailure instanceof RuntimeException
? $fallbackFailure
: new RuntimeException($fallbackFailure->getMessage(), 0, $fallbackFailure);
if ($fallbackFailure instanceof VectorGatewayException && $fileFailure === null) {
return $fallbackFailure;
}
return new RuntimeException(sprintf(
'Vector search failed via file endpoint (%s) and URL fallback (%s).',
$fileFailure->getMessage(),
$fallbackFailure->getMessage(),
), 0, $fallbackFailure);
$status = $fallbackFailure instanceof VectorGatewayException
? $fallbackFailure->httpStatus
: null;
$circuitWorthy = $this->isCircuitWorthyFailure($fileFailure)
&& $this->isCircuitWorthyFailure($fallbackFailure);
if ($fileFailure === null) {
return $fallbackFailure instanceof VectorGatewayException
? $fallbackFailure
: new VectorGatewayException(
'Vector gateway search failed.',
'search_url',
$status,
$this->isCircuitWorthyFailure($fallbackFailure),
$fallbackFailure,
);
}
return new VectorGatewayException(
'Vector gateway search failed.',
'search_combined',
$status,
$circuitWorthy,
$fallbackFailure,
);
}
private function isCircuitWorthyFailure(Throwable $failure): bool
{
return $failure instanceof VectorGatewayException && $failure->circuitWorthy;
}
private function shouldTripSimilarAiCircuit(
bool $fileGatewayAttempted,
?Throwable $fileFailure,
Throwable $fallbackFailure,
): bool {
return $fileGatewayAttempted
&& $fileFailure instanceof VectorGatewayException
&& $fileFailure->operation === 'search_file'
&& $fileFailure->circuitWorthy
&& $fallbackFailure instanceof VectorGatewayException
&& $fallbackFailure->operation === 'search_url'
&& $fallbackFailure->circuitWorthy;
}
/**
+207 -7
View File
@@ -5,13 +5,22 @@ declare(strict_types=1);
namespace App\Services\Vision;
use Illuminate\Http\UploadedFile;
use Illuminate\Http\Client\ConnectionException;
use Illuminate\Http\Client\PendingRequest;
use Illuminate\Http\Client\RequestException;
use Illuminate\Http\Client\Response;
use Illuminate\Support\Facades\Cache;
use Illuminate\Support\Facades\Http;
use Illuminate\Support\Facades\Log;
use RuntimeException;
use Throwable;
final class VectorGatewayClient
{
private const CIRCUIT_KEY = 'vision.vector_gateway.circuit_open';
private const MAX_SEARCH_LIMIT = 100;
public function isConfigured(): bool
{
return (bool) config('vision.vector_gateway.enabled', true)
@@ -19,9 +28,35 @@ final class VectorGatewayClient
&& $this->apiKey() !== '';
}
/**
* True while the gateway is presumed down after a recent failure — callers
* on the request path should skip the network round trip entirely.
*/
public function circuitOpen(): bool
{
return Cache::has(self::CIRCUIT_KEY);
}
/**
* @param array<string, mixed> $context
*/
public function tripCircuit(array $context = []): void
{
$alreadyOpen = $this->circuitOpen();
$seconds = max(1, (int) config('vision.vector_gateway.circuit_breaker_seconds', 30));
Cache::put(self::CIRCUIT_KEY, true, $seconds);
if ($alreadyOpen) {
return;
}
$this->logCircuitOpened($context, $seconds);
}
public function upsertByUrl(string $imageUrl, int|string $id, array $metadata = []): array
{
$response = $this->postJson(
$this->request(),
$this->url((string) config('vision.vector_gateway.upsert_endpoint', '/vectors/upsert')),
[
'url' => $imageUrl,
@@ -65,16 +100,21 @@ final class VectorGatewayClient
*/
public function searchByUrl(string $imageUrl, int $limit = 5): array
{
try {
$response = $this->postJson(
$this->searchRequest(),
$this->url((string) config('vision.vector_gateway.search_endpoint', '/vectors/search')),
[
'url' => $imageUrl,
'limit' => max(1, $limit),
'limit' => $this->clampSearchLimit($limit),
]
);
} catch (Throwable $e) {
throw $this->classifyThrowable('search_url', $e);
}
if ($response->failed()) {
throw new RuntimeException($this->failureMessage('Vector search', $response));
throw $this->classifyHttpFailure('search_url', $response);
}
return $this->extractMatches($response->json());
@@ -85,17 +125,21 @@ final class VectorGatewayClient
*/
public function searchByFileContents(string $contents, string $filename, int $limit = 5): array
{
$response = $this->request()
try {
$response = $this->searchRequest()
->attach('file', $contents, $filename)
->post(
$this->url((string) config('vision.vector_gateway.search_file_endpoint', '/vectors/search/file')),
[
'limit' => max(1, $limit),
'limit' => $this->clampSearchLimit($limit),
]
);
} catch (Throwable $e) {
throw $this->classifyThrowable('search_file', $e);
}
if ($response->failed()) {
throw new RuntimeException($this->failureMessage('Vector search', $response));
throw $this->classifyHttpFailure('search_file', $response);
}
return $this->extractMatches($response->json());
@@ -106,6 +150,8 @@ final class VectorGatewayClient
*/
public function searchByUploadedFile(UploadedFile $file, int $limit = 5): array
{
$this->assertCircuitClosed();
$realPath = $file->getRealPath();
if (! is_string($realPath) || $realPath === '') {
throw new RuntimeException('Uploaded file has no readable temporary path for vector search.');
@@ -116,12 +162,53 @@ final class VectorGatewayClient
throw new RuntimeException('Unable to read uploaded image bytes for vector search.');
}
try {
return $this->searchByFileContents($contents, $file->getClientOriginalName() ?: 'search-image', $limit);
} catch (VectorGatewayException $e) {
$this->tripIfCircuitWorthy([$e], 'uploaded_image');
throw $e;
}
}
/**
* Open the circuit only when every attempted search failure is transient/gateway-wide.
*
* @param list<VectorGatewayException> $failures
* @param array{artwork_id?: int} $context
*/
public function tripIfCircuitWorthy(array $failures, string $source = 'unknown', array $context = []): void
{
if ($failures === []) {
return;
}
foreach ($failures as $failure) {
if (! $failure->circuitWorthy) {
return;
}
}
$this->tripCircuit([
'source' => $source,
'artwork_id' => isset($context['artwork_id']) ? (int) $context['artwork_id'] : null,
'failures' => array_map(static fn (VectorGatewayException $failure): array => [
'operation' => $failure->operation,
'http_status' => $failure->httpStatus,
'circuit_worthy' => $failure->circuitWorthy,
'exception_class' => $failure::class,
], $failures),
]);
}
public function assertCircuitClosed(): void
{
$this->guardCircuit();
}
public function deleteByIds(array $ids): array
{
$response = $this->postJson(
$this->request(),
$this->url((string) config('vision.vector_gateway.delete_endpoint', '/vectors/delete')),
[
'ids' => array_values(array_map(static fn (int|string $id): string => (string) $id, $ids)),
@@ -137,6 +224,10 @@ final class VectorGatewayClient
return is_array($json) ? $json : [];
}
/**
* Used by upsert/delete — only ever called from queued/console indexing
* jobs, so a more generous budget is fine.
*/
private function request(): PendingRequest
{
if (! $this->isConfigured()) {
@@ -156,12 +247,121 @@ final class VectorGatewayClient
);
}
/**
* Used by search — runs synchronously inside web requests, so it gets a
* tight timeout budget and no retries to avoid pinning FPM workers.
*/
private function searchRequest(): PendingRequest
{
if (! $this->isConfigured()) {
throw new RuntimeException('Vision vector gateway is not configured. Set VISION_VECTOR_GATEWAY_URL and VISION_VECTOR_GATEWAY_API_KEY.');
}
return Http::acceptJson()
->withHeaders([
'X-API-Key' => $this->apiKey(),
])
->connectTimeout(max(1, (int) config('vision.vector_gateway.search_connect_timeout_seconds', 2)))
->timeout(max(1, (int) config('vision.vector_gateway.search_timeout_seconds', 6)))
->retry(
max(0, (int) config('vision.vector_gateway.search_retries', 0)),
max(0, (int) config('vision.vector_gateway.retry_delay_ms', 250)),
throw: false,
);
}
/**
* @param array<string, mixed> $context
*/
private function logCircuitOpened(array $context, int $ttlSeconds): void
{
$payload = [
'source' => (string) ($context['source'] ?? 'unknown'),
'failures' => is_array($context['failures'] ?? null) ? $context['failures'] : [],
'circuit_ttl_seconds' => $ttlSeconds,
'php_sapi' => PHP_SAPI,
'running_in_console' => app()->runningInConsole(),
];
if (isset($context['artwork_id']) && is_int($context['artwork_id']) && $context['artwork_id'] > 0) {
$payload['artwork_id'] = $context['artwork_id'];
}
Log::warning('Vector gateway circuit opened', $payload);
}
private function clampSearchLimit(int $limit): int
{
return max(1, min(self::MAX_SEARCH_LIMIT, $limit));
}
private function guardCircuit(): void
{
if ($this->circuitOpen()) {
throw new VectorGatewayException(
'Vector gateway temporarily unavailable.',
'circuit',
null,
true,
);
}
}
private function classifyHttpFailure(string $operation, Response $response): VectorGatewayException
{
$status = $response->status();
return new VectorGatewayException(
'Vector gateway '.$operation.' failed with HTTP '.$status.'.',
$operation,
$status,
$this->isCircuitWorthyStatus($status),
);
}
private function classifyThrowable(string $operation, Throwable $e): VectorGatewayException
{
if ($e instanceof VectorGatewayException) {
return $e;
}
if ($e instanceof RequestException && $e->response instanceof Response) {
return $this->classifyHttpFailure($operation, $e->response);
}
$circuitWorthy = $e instanceof ConnectionException || $this->looksLikeTimeout($e);
return new VectorGatewayException(
'Vector gateway '.$operation.' failed.',
$operation,
null,
$circuitWorthy,
$e,
);
}
private function isCircuitWorthyStatus(int $status): bool
{
return $status === 408 || $status === 429 || $status >= 500;
}
private function looksLikeTimeout(Throwable $e): bool
{
$message = strtolower($e->getMessage());
return str_contains($message, 'timed out')
|| str_contains($message, 'timeout')
|| str_contains($message, 'curl error 28')
|| str_contains($message, 'connection refused')
|| str_contains($message, 'could not resolve');
}
/**
* @param array<string, mixed> $payload
*/
private function postJson(string $url, array $payload): Response
private function postJson(PendingRequest $request, string $url, array $payload): Response
{
$response = $this->request()->post($url, $payload);
$response = $request->post($url, $payload);
if (! $response instanceof Response) {
throw new RuntimeException('Vector gateway request did not return an HTTP response.');
@@ -0,0 +1,21 @@
<?php
declare(strict_types=1);
namespace App\Services\Vision;
use RuntimeException;
use Throwable;
final class VectorGatewayException extends RuntimeException
{
public function __construct(
string $message,
public readonly string $operation,
public readonly ?int $httpStatus = null,
public readonly bool $circuitWorthy = false,
?Throwable $previous = null,
) {
parent::__construct($message, 0, $previous);
}
}
@@ -0,0 +1,322 @@
<?php
declare(strict_types=1);
namespace App\Support\Http;
/**
* Read-only parser for nginx skinbase_perf JSON lines.
*
* Multi-value upstream timings (retries): use the **sum** of numeric parts
* as the upstream total for that request. "-" and empty → null.
* Percentiles use nearest-rank (ceil(p * n), 1-indexed).
*/
final class HttpPerformanceLogAnalyzer
{
public function __construct(private readonly HttpUriNormalizer $uris)
{
}
/**
* @param array{
* since?: ?string,
* min_requests?: int,
* top?: int,
* status?: ?string,
* uri?: ?string,
* host?: ?string,
* slow_ms?: ?float,
* now?: ?\DateTimeImmutable
* } $options
* @return array<string, mixed>
*/
public function analyze(string $file, array $options = []): array
{
$since = $this->sinceCutoff($options['since'] ?? null, $options['now'] ?? new \DateTimeImmutable('now'));
$minRequests = max(1, (int) ($options['min_requests'] ?? 1));
$top = max(1, (int) ($options['top'] ?? 20));
$statusFilter = isset($options['status']) ? strtolower((string) $options['status']) : null;
$uriFilter = $options['uri'] ?? null;
$hostFilter = isset($options['host']) ? (string) $options['host'] : '';
$slowMs = isset($options['slow_ms']) ? (float) $options['slow_ms'] / 1000 : null;
$skipped = 0;
$families = [];
$slowest = [];
$statusCounts = ['4xx' => 0, '5xx' => 0, '499' => 0, 'total' => 0];
$handle = fopen($file, 'r');
if ($handle === false) {
throw new \RuntimeException('Unable to open performance log: '.$file);
}
try {
while (($line = fgets($handle)) !== false) {
$line = trim($line);
if ($line === '') {
continue;
}
$row = json_decode($line, true);
if (! is_array($row)) {
$skipped++;
continue;
}
$time = $this->parseTime((string) ($row['time'] ?? ''));
if ($since !== null && ($time === null || $time < $since)) {
continue;
}
$requestTime = $this->parseFloat($row['request_time'] ?? null);
if ($requestTime === null) {
$skipped++;
continue;
}
$status = (int) ($row['status'] ?? 0);
if ($statusFilter === '5xx' && ($status < 500 || $status > 599)) {
continue;
}
if ($statusFilter === '4xx' && ($status < 400 || $status > 499)) {
continue;
}
if ($statusFilter === '499' && $status !== 499) {
continue;
}
$host = (string) ($row['host'] ?? '');
if ($hostFilter !== '' && $host !== $hostFilter) {
continue;
}
$uri = $this->uris->normalize((string) ($row['uri'] ?? '/'));
if (is_string($uriFilter) && $uriFilter !== '' && ! str_starts_with($uri, $uriFilter)) {
continue;
}
if ($slowMs !== null && $requestTime < $slowMs) {
continue;
}
$upstreamResponse = $this->parseUpstream($row['upstream_response_time'] ?? null);
$upstreamHeader = $this->parseUpstream($row['upstream_header_time'] ?? null);
$bytes = (int) ($row['bytes'] ?? 0);
$method = (string) ($row['method'] ?? '');
$statusCounts['total']++;
if ($status === 499) {
$statusCounts['499']++;
} elseif ($status >= 500) {
$statusCounts['5xx']++;
} elseif ($status >= 400) {
$statusCounts['4xx']++;
}
$familyKey = $host."\n".$uri;
$families[$familyKey] ??= [
'host' => $host,
'uri' => $uri,
'count' => 0,
'times' => [],
'upstream_sum' => 0.0,
'upstream_n' => 0,
'header_sum' => 0.0,
'header_n' => 0,
'bytes_sum' => 0,
'4xx' => 0,
'5xx' => 0,
'499' => 0,
'404' => 0,
];
$families[$familyKey]['count']++;
$families[$familyKey]['times'][] = $requestTime;
$families[$familyKey]['bytes_sum'] += $bytes;
if ($upstreamResponse !== null) {
$families[$familyKey]['upstream_sum'] += $upstreamResponse;
$families[$familyKey]['upstream_n']++;
}
if ($upstreamHeader !== null) {
$families[$familyKey]['header_sum'] += $upstreamHeader;
$families[$familyKey]['header_n']++;
}
if ($status === 499) {
$families[$familyKey]['499']++;
} elseif ($status >= 500) {
$families[$familyKey]['5xx']++;
} elseif ($status >= 400) {
$families[$familyKey]['4xx']++;
if ($status === 404) {
$families[$familyKey]['404']++;
}
}
$slowest[] = [
'time' => $row['time'] ?? null,
'host' => $host,
'uri' => $uri,
'method' => $method,
'status' => $status,
'request_time' => $requestTime,
'upstream_response_time' => $upstreamResponse,
];
}
} finally {
fclose($handle);
}
usort($slowest, static fn (array $a, array $b): int => $b['request_time'] <=> $a['request_time']);
$slowest = array_slice($slowest, 0, $top);
$summaries = [];
foreach ($families as $family) {
if ($family['count'] < $minRequests) {
continue;
}
$times = $family['times'];
sort($times, SORT_NUMERIC);
$avg = array_sum($times) / $family['count'];
$summaries[] = [
'host' => $family['host'],
'uri' => $family['uri'],
'count' => $family['count'],
'p50' => $this->percentile($times, 0.50),
'p95' => $this->percentile($times, 0.95),
'p99' => $this->percentile($times, 0.99),
'max' => $times[array_key_last($times)],
'avg' => round($avg, 4),
'total' => round(array_sum($times), 4),
'avg_upstream_response' => $family['upstream_n'] > 0 ? round($family['upstream_sum'] / $family['upstream_n'], 4) : null,
'avg_upstream_header' => $family['header_n'] > 0 ? round($family['header_sum'] / $family['header_n'], 4) : null,
'avg_bytes' => (int) round($family['bytes_sum'] / $family['count']),
'4xx' => $family['4xx'],
'4xx_rate' => round($family['4xx'] / $family['count'], 4),
'404' => $family['404'],
'5xx' => $family['5xx'],
'5xx_rate' => round($family['5xx'] / $family['count'], 4),
'499' => $family['499'],
];
}
$byP95 = $summaries;
usort($byP95, static fn (array $a, array $b): int => ($b['p95'] ?? 0) <=> ($a['p95'] ?? 0));
$byP99 = $summaries;
usort($byP99, static fn (array $a, array $b): int => ($b['p99'] ?? 0) <=> ($a['p99'] ?? 0));
$byTotal = $summaries;
usort($byTotal, static fn (array $a, array $b): int => $b['total'] <=> $a['total']);
$byCount = $summaries;
usort($byCount, static fn (array $a, array $b): int => $b['count'] <=> $a['count']);
$byCost = $summaries;
usort($byCost, static fn (array $a, array $b): int => ($b['count'] * $b['avg']) <=> ($a['count'] * $a['avg']));
$by5xx = array_values(array_filter($summaries, static fn (array $row): bool => $row['5xx'] > 0));
usort($by5xx, static fn (array $a, array $b): int => $b['5xx'] <=> $a['5xx']);
$by404 = array_values(array_filter($summaries, static fn (array $row): bool => ($row['404'] ?? 0) > 0));
usort($by404, static fn (array $a, array $b): int => $b['404'] <=> $a['404']);
return [
'skipped' => $skipped,
'totals' => $statusCounts,
'by_p95' => array_slice($byP95, 0, $top),
'by_p99' => array_slice($byP99, 0, $top),
'by_total_time' => array_slice($byTotal, 0, $top),
'by_count' => array_slice($byCount, 0, $top),
'by_cost' => array_slice($byCost, 0, $top),
'by_5xx' => array_slice($by5xx, 0, $top),
'by_4xx' => array_slice($by404, 0, $top),
'slowest' => $slowest,
'percentile_method' => 'nearest-rank (ceil(p * n), 1-indexed)',
'upstream_aggregation' => 'sum of numeric comma-separated upstream timings; "-" is null',
];
}
/**
* Nearest-rank: rank = ceil(p * n), 1-indexed.
*
* @param list<float> $sorted
*/
public function percentile(array $sorted, float $p): ?float
{
$n = count($sorted);
if ($n === 0) {
return null;
}
$rank = (int) ceil($p * $n);
$index = max(0, min($n - 1, $rank - 1));
return round($sorted[$index], 4);
}
public function parseUpstream(mixed $value): ?float
{
if ($value === null || $value === '' || $value === '-') {
return null;
}
if (is_int($value) || is_float($value)) {
return (float) $value;
}
$parts = preg_split('/\s*,\s*/', (string) $value) ?: [];
$sum = 0.0;
$found = false;
foreach ($parts as $part) {
if ($part === '' || $part === '-') {
continue;
}
if (! is_numeric($part)) {
continue;
}
$sum += (float) $part;
$found = true;
}
return $found ? $sum : null;
}
private function parseFloat(mixed $value): ?float
{
if ($value === null || $value === '' || $value === '-') {
return null;
}
if (! is_numeric($value)) {
return null;
}
return (float) $value;
}
private function parseTime(string $value): ?\DateTimeImmutable
{
if ($value === '') {
return null;
}
try {
return new \DateTimeImmutable($value);
} catch (\Exception) {
return null;
}
}
private function sinceCutoff(?string $since, \DateTimeImmutable $now): ?\DateTimeImmutable
{
if ($since === null || $since === '') {
return null;
}
if (preg_match('/^(\d+)(h|d|m)$/', strtolower($since), $matches) !== 1) {
return null;
}
$n = (int) $matches[1];
$unit = $matches[2];
$interval = match ($unit) {
'm' => new \DateInterval('PT'.$n.'M'),
'h' => new \DateInterval('PT'.$n.'H'),
'd' => new \DateInterval('P'.$n.'D'),
};
return $now->sub($interval);
}
}
+96
View File
@@ -0,0 +1,96 @@
<?php
declare(strict_types=1);
namespace App\Support\Http;
final class HttpUriNormalizer
{
public function normalize(string $uri): string
{
$path = parse_url($uri, PHP_URL_PATH);
if (! is_string($path) || $path === '') {
$path = $uri;
}
$path = '/'.ltrim($path, '/');
if ($path !== '/') {
$path = rtrim($path, '/');
}
if (preg_match('#^/@([^/]+)(/.*)?$#', $path, $matches) === 1) {
$rest = $matches[2] ?? '';
return '/@{user}'.$this->normalizeSegments($rest);
}
return $this->normalizeSegments($path);
}
private function normalizeSegments(string $path): string
{
if ($path === '' || $path === '/') {
return $path === '' ? '' : '/';
}
$segments = explode('/', $path);
$normalized = [];
foreach ($segments as $index => $segment) {
if ($segment === '') {
$normalized[] = '';
continue;
}
$normalized[] = $this->normalizeSegment($segment, $index, $segments);
}
$result = implode('/', $normalized);
return $result === '' ? '/' : $result;
}
/**
* @param array<int, string> $segments
*/
private function normalizeSegment(string $segment, int $index, array $segments): string
{
if (ctype_digit($segment)) {
return '{id}';
}
if (preg_match('/^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$/i', $segment) === 1) {
return '{uuid}';
}
if (preg_match('/^[0-9a-f]{32,64}$/i', $segment) === 1) {
return '{hash}';
}
if ($this->isArtworkPublicSlug($segment, $index, $segments)) {
return '{slug}';
}
return $segment;
}
/**
* /art/{id}/{slug} stays distinct from /art/{id}/similar and other actions.
*
* @param array<int, string> $segments
*/
private function isArtworkPublicSlug(string $segment, int $index, array $segments): bool
{
if ($index !== 3 || ($segments[1] ?? '') !== 'art') {
return false;
}
if (! ctype_digit((string) ($segments[2] ?? ''))) {
return false;
}
$actions = ['similar', 'view', 'download', 'edit', 'comments', 'favourite', 'favorite'];
return ! in_array(strtolower($segment), $actions, true);
}
}
@@ -0,0 +1,34 @@
<?php
declare(strict_types=1);
namespace App\Support\Http;
use Illuminate\Http\Request;
use Inertia\Ssr\Gateway;
use Inertia\Ssr\HttpGateway;
use Inertia\Ssr\Response;
/**
* Times the existing Inertia SSR HTTP round-trip. Does not change SSR behavior.
*/
final class TimedInertiaSsrGateway implements Gateway
{
public function __construct(private readonly HttpGateway $inner)
{
}
public function dispatch(array $page): ?Response
{
$started = hrtime(true);
$response = $this->inner->dispatch($page);
$durationMs = (hrtime(true) - $started) / 1_000_000;
$request = request();
if ($request instanceof Request) {
$request->attributes->set('http.ssr_ms', round($durationMs, 1));
}
return $response;
}
}
@@ -0,0 +1,33 @@
<?php
declare(strict_types=1);
namespace App\Support\Queues;
final class QueuedJobClassMatcher
{
public static function className(string $rawPayload): ?string
{
$decoded = json_decode($rawPayload, true);
if (! is_array($decoded)) {
return null;
}
$display = $decoded['displayName'] ?? null;
if (is_string($display) && $display !== '') {
return $display;
}
$command = $decoded['data']['commandName'] ?? null;
if (is_string($command) && $command !== '') {
return $command;
}
return null;
}
public static function isClass(string $rawPayload, string $class): bool
{
return self::className($rawPayload) === $class;
}
}
+159
View File
@@ -0,0 +1,159 @@
<?php
declare(strict_types=1);
namespace App\Support\Redis;
use App\Jobs\RefreshCollectionHealthJob;
use App\Jobs\RefreshCollectionRecommendationJob;
use App\Jobs\ScanCollectionDuplicateCandidatesJob;
use App\Support\Queues\QueuedJobClassMatcher;
use Illuminate\Support\Facades\Redis;
use RuntimeException;
final class OrphanQueueCleanup
{
public const PROTECTED_QUEUES = ['default', 'search', 'mail', 'broadcasts', 'notifications'];
/**
* @var array<string, array{expected: list<string>, dispatch_config: string}>
*/
public const TARGETS = [
'forum-moderation' => [
'expected' => ['cPad\\Plugins\\Forum\\Jobs\\AnalyzeForumPostJob'],
'dispatch_config' => 'skinbase_ai_moderation.queue.dispatch_enabled',
],
'forum-security' => [
'expected' => [
'cPad\\Plugins\\Forum\\Jobs\\FirewallActivityMonitor',
'cPad\\Plugins\\Forum\\Jobs\\BotActivityMonitor',
],
'dispatch_config' => 'forum_security.queues.dispatch_enabled',
],
'collections' => [
'expected' => [
RefreshCollectionHealthJob::class,
RefreshCollectionRecommendationJob::class,
ScanCollectionDuplicateCandidatesJob::class,
],
'dispatch_config' => 'collections.v5.queue.dispatch_enabled',
],
];
/**
* @return array<string, mixed>
*/
public function inspect(string $queue, int $sampleSize = 400): array
{
$this->assertQueueName($queue);
$redis = Redis::connection();
$waitingKey = 'queues:'.$queue;
$llen = (int) $redis->llen($waitingKey);
$delayed = (int) $redis->zcard('queues:'.$queue.':delayed');
$reserved = (int) $redis->zcard('queues:'.$queue.':reserved');
$notify = (int) $redis->llen('queues:'.$queue.':notify');
$prefix = (string) config('database.redis.options.prefix', '');
$classes = [];
$bytes = [];
$sampled = 0;
if ($llen > 0) {
$step = max(1, (int) floor($llen / max(1, $sampleSize)));
for ($i = 0; $i < $llen && $sampled < $sampleSize; $i += $step) {
$raw = $redis->lindex($waitingKey, $i);
if (! is_string($raw) || $raw === '') {
continue;
}
$sampled++;
$class = QueuedJobClassMatcher::className($raw) ?? 'unknown';
$classes[$class] = ($classes[$class] ?? 0) + 1;
$bytes[] = strlen($raw);
}
}
arsort($classes);
$avg = $bytes !== [] ? (int) round(array_sum($bytes) / count($bytes)) : 0;
return [
'queue' => $queue,
'logical_key' => $waitingKey,
'notify_key' => 'queues:'.$queue.':notify',
'prefix' => $prefix,
'llen' => $llen,
'delayed' => $delayed,
'reserved' => $reserved,
'notify' => $notify,
'sampled' => $sampled,
'classes' => $classes,
'avg_bytes' => $avg,
'est_bytes' => $llen * $avg,
];
}
/**
* @return array<string, mixed>
*/
public function plan(string $queue, bool $force = false): array
{
if (in_array($queue, self::PROTECTED_QUEUES, true)) {
throw new RuntimeException("Refusing protected queue [{$queue}].");
}
if (! isset(self::TARGETS[$queue])) {
throw new RuntimeException("Unknown orphan target [{$queue}].");
}
$meta = self::TARGETS[$queue];
$dispatchEnabled = (bool) config($meta['dispatch_config'], false);
$inspect = $this->inspect($queue);
$unexpected = array_values(array_diff(array_keys($inspect['classes']), $meta['expected']));
$errors = [];
if ($dispatchEnabled) {
$errors[] = 'producer_dispatch_enabled';
}
if ($inspect['reserved'] > 0) {
$errors[] = 'reserved_jobs_present';
}
if ($inspect['delayed'] > 0) {
$errors[] = 'delayed_jobs_present';
}
if ($unexpected !== [] && ! $force) {
$errors[] = 'unexpected_job_classes';
}
return $inspect + [
'expected_classes' => $meta['expected'],
'unexpected_classes' => $unexpected,
'dispatch_enabled' => $dispatchEnabled,
'errors' => $errors,
'can_execute' => $errors === [],
];
}
/**
* @return array<string, mixed>
*/
public function execute(string $queue, bool $force = false): array
{
$plan = $this->plan($queue, $force);
if (! $plan['can_execute']) {
throw new RuntimeException('Cleanup refused: '.implode(',', $plan['errors']));
}
$redis = Redis::connection();
$keys = ['queues:'.$queue, 'queues:'.$queue.':notify'];
$unlinked = 0;
foreach ($keys as $key) {
$unlinked += (int) $redis->unlink($key);
}
return $plan + ['unlinked_keys' => $keys, 'unlinked' => $unlinked];
}
private function assertQueueName(string $queue): void
{
if (! preg_match('/^[A-Za-z0-9_-]+$/', $queue)) {
throw new RuntimeException('Invalid queue name.');
}
}
}
+5
View File
@@ -33,6 +33,11 @@ return Application::configure(basePath: dirname(__DIR__))
'stripe/*',
]);
$middleware->prepend([
\App\Http\Middleware\LogSlowHttpRequest::class,
\App\Http\Middleware\AddServerTiming::class,
]);
$middleware->web(append: [
\App\Http\Middleware\SecurityHeaders::class,
\App\Http\Middleware\RedirectLegacyProfileSubdomain::class,
+2
View File
@@ -2073,6 +2073,8 @@
"resources/js/Pages/Admin/HomepageAnnouncements/Index.jsx": [],
"resources/js/Pages/Admin/Settings.jsx": [],
"resources/js/Pages/Admin/Stories.jsx": [],
"resources/js/Pages/Admin/System/SecurityReportIndex.jsx": [],
"resources/js/Pages/Admin/System/SecurityReportShow.jsx": [],
"resources/js/Pages/Admin/UploadQueue.jsx": [],
"resources/js/Pages/Admin/UsernameQueue.jsx": [],
"resources/js/Pages/Admin/Users/Index.jsx": [],
+508 -360
View File
File diff suppressed because one or more lines are too long
+3
View File
@@ -114,6 +114,9 @@
"pestphp/pest-plugin": true,
"php-http/discovery": true
},
"audit": {
"abandoned": "report"
},
"platform": {
"ext-pcntl": "8.4.0",
"ext-posix": "8.4.0"
Generated
+371 -346
View File
File diff suppressed because it is too large Load Diff
+3
View File
@@ -83,6 +83,9 @@ return [
'low_engagement_after_days' => (int) env('COLLECTIONS_V5_LOW_ENGAGEMENT_AFTER_DAYS', 14),
],
'queue' => [
// No Horizon supervisor consumes this queue today. Keep dispatch
// off until a consumer exists (M7). Existing jobs are not deleted.
'dispatch_enabled' => (bool) env('COLLECTIONS_V5_DISPATCH_ENABLED', false),
'name' => env('COLLECTIONS_V5_QUEUE', 'collections'),
'health_batch_size' => (int) env('COLLECTIONS_V5_HEALTH_BATCH_SIZE', 40),
'recommendation_batch_size' => (int) env('COLLECTIONS_V5_RECOMMENDATION_BATCH_SIZE', 40),
+2
View File
@@ -15,6 +15,8 @@ return [
'queues' => [
'moderation' => env('FORUM_SECURITY_MODERATION_QUEUE', 'forum-moderation'),
'firewall' => env('FORUM_SECURITY_FIREWALL_QUEUE', 'forum-security'),
// Plugin jobs have no Horizon consumer. Pause enqueue until a worker exists.
'dispatch_enabled' => (bool) env('FORUM_QUEUE_DISPATCH_ENABLED', false),
],
'firewall' => [
+25 -3
View File
@@ -99,6 +99,7 @@ return [
'waits' => [
'redis:broadcasts' => 15,
'redis:default' => 60,
'redis:mail' => 60,
'redis:notifications' => 90,
],
@@ -209,9 +210,9 @@ return [
'maxJobs' => 0,
'memory' => 128,
'tries' => 1,
// Long-running recommendation rebuild jobs declare timeouts up to 900s.
// Keep the worker timeout above that ceiling so Horizon does not kill
// healthy jobs before Laravel can enforce the job-level timeout.
// Must stay below config/queue.php redis.retry_after (default 1080).
// Nightly recommendation rebuilds are chunked; keep headroom for
// remaining long jobs on the default queue.
'timeout' => 960,
'nice' => 0,
],
@@ -228,6 +229,21 @@ return [
'timeout' => 90,
'nice' => 0,
],
// Mail is intentionally isolated: SMTP latency must not block
// search/recommendation workers, and mail jobs declare tries=3–5.
'supervisor-mail' => [
'connection' => 'redis',
'queue' => ['mail'],
'balance' => 'simple',
'autoScalingStrategy' => 'time',
'maxProcesses' => 1,
'maxTime' => 0,
'maxJobs' => 0,
'memory' => 128,
'tries' => 5,
'timeout' => 90,
'nice' => 0,
],
],
'environments' => [
@@ -242,6 +258,9 @@ return [
'balanceMaxShift' => 1,
'balanceCooldown' => 3,
],
'supervisor-mail' => [
'maxProcesses' => 2,
],
],
'local' => [
@@ -251,6 +270,9 @@ return [
'supervisor-messaging' => [
'maxProcesses' => 2,
],
'supervisor-mail' => [
'maxProcesses' => 1,
],
],
],
+14
View File
@@ -0,0 +1,14 @@
<?php
declare(strict_types=1);
return [
'slow_request' => [
'enabled' => (bool) env('HTTP_SLOW_REQUEST_LOG_ENABLED', false),
'threshold_ms' => (int) env('HTTP_SLOW_REQUEST_MS', 750),
/*
* Testing only. When set, replaces measured duration so tests do not sleep.
*/
'test_duration_ms' => env('HTTP_SLOW_REQUEST_TEST_DURATION_MS'),
],
];
+8
View File
@@ -123,6 +123,14 @@ return [
'handler' => NullHandler::class,
],
'slow-http' => [
'driver' => 'daily',
'path' => storage_path('logs/slow-http.log'),
'level' => 'info',
'days' => (int) env('HTTP_SLOW_REQUEST_LOG_DAYS', 14),
'replace_placeholders' => false,
],
'emergency' => [
'path' => storage_path('logs/laravel.log'),
],
+20
View File
@@ -0,0 +1,20 @@
<?php
declare(strict_types=1);
/**
* Hourly artwork metric snapshots (heat, rising, windowed leaderboards).
*
* Default retention is 30 days so monthly leaderboards and Studio 30d KPIs
* have a complete window after warm-up. Override with env; never hardcode.
* Studio 30d KPIs use MAX-MIN of cumulative counters, never SUM.
*/
return [
'hourly_snapshot_retention_days' => (int) env('ARTWORK_METRIC_HOURLY_RETENTION_DAYS', 30),
'hourly_snapshot_prune_chunk' => (int) env('ARTWORK_METRIC_HOURLY_PRUNE_CHUNK', 5000),
'hourly_snapshot_prune_sleep_ms' => (int) env('ARTWORK_METRIC_HOURLY_PRUNE_SLEEP_MS', 50),
];
+4 -1
View File
@@ -68,7 +68,10 @@ return [
'driver' => 'redis',
'connection' => env('REDIS_QUEUE_CONNECTION', 'default'),
'queue' => env('REDIS_QUEUE', 'default'),
'retry_after' => (int) env('REDIS_QUEUE_RETRY_AFTER', 90),
// Must exceed the longest Horizon worker timeout (960s) plus a buffer.
// If retry_after is shorter than a running job, Redis re-queues it as a
// new attempt and Horizon (--tries=1) marks MaxAttemptsExceeded.
'retry_after' => (int) env('REDIS_QUEUE_RETRY_AFTER', 1080),
'block_for' => null,
'after_commit' => false,
],
+5
View File
@@ -77,6 +77,11 @@ return [
'candidate_pool' => 200, // top N candidates to run diversity filter on
],
// Unique lock for RankBuildScopeListsJob. Must exceed queue wait + job
// timeout (300s). Production wait has been ~2.5h; 6h prevents hourly
// stacking while still recovering a dead lock the same day.
'scope_job_unique_for' => (int) env('RANK_SCOPE_JOB_UNIQUE_FOR', 21600),
// ── Anti-spam / burst-view damping ──────────────────────────────────────
'spam' => [
'views_24h_threshold' => 2000,
+30
View File
@@ -0,0 +1,30 @@
<?php
return [
'enabled' => env('SECURITY_REPORT_ENABLED', true),
'notify_email' => env('SECURITY_REPORT_NOTIFY_EMAIL', env('MAIL_FROM_ADDRESS')),
'scan' => [
'composer' => env('SECURITY_REPORT_SCAN_COMPOSER', true),
'npm' => env('SECURITY_REPORT_SCAN_NPM', true),
],
'store_raw' => env('SECURITY_REPORT_STORE_RAW', true),
'max_raw_kb' => (int) env('SECURITY_REPORT_MAX_RAW_KB', 512),
'fail_on' => [
'high' => env('SECURITY_REPORT_FAIL_ON_HIGH', false),
'critical' => env('SECURITY_REPORT_FAIL_ON_CRITICAL', false),
],
'commands' => [
'composer_audit' => ['composer', 'audit', '--format=json', '--locked'],
'composer_outdated' => ['composer', 'outdated', '--direct', '--format=json'],
'npm_audit' => ['npm', 'audit', '--json'],
'npm_outdated' => ['npm', 'outdated', '--json'],
],
'timeout_seconds' => 180,
];
+9
View File
@@ -54,6 +54,9 @@ return [
'forum-threads' => [
'size' => (int) env('SITEMAPS_SHARD_FORUM_THREADS_SIZE', 10000),
],
'tags' => [
'size' => (int) env('SITEMAPS_SHARD_TAGS_SIZE', 25000),
],
'collections' => [
'size' => (int) env('SITEMAPS_SHARD_COLLECTIONS_SIZE', 10000),
],
@@ -83,6 +86,12 @@ return [
'enabled' => [
'artworks',
'academy-pages',
'academy-courses',
'academy-lessons',
'academy-prompts',
'academy-packs',
'academy-challenges',
'users',
'tags',
'categories',
+1
View File
@@ -7,6 +7,7 @@ return [
'queue' => [
'name' => env('SKINBASE_AI_MODERATION_QUEUE', 'forum-moderation'),
'dispatch_enabled' => (bool) env('FORUM_QUEUE_DISPATCH_ENABLED', false),
],
'preflight' => [
+15
View File
@@ -0,0 +1,15 @@
<?php
declare(strict_types=1);
return [
'online_visitors' => [
// Cap SSCAN/all() so moderation pages never SMEMBERS the 2.4M-member index.
'index_read_limit' => (int) env('ONLINE_VISITOR_INDEX_READ_LIMIT', 2000),
'prune_enabled' => (bool) env('ONLINE_VISITOR_INDEX_PRUNE_ENABLED', false),
'prune_scan_count' => (int) env('ONLINE_VISITOR_INDEX_PRUNE_SCAN_COUNT', 500),
'prune_max_batches' => (int) env('ONLINE_VISITOR_INDEX_PRUNE_MAX_BATCHES', 200),
'prune_max_members' => (int) env('ONLINE_VISITOR_INDEX_PRUNE_MAX_MEMBERS', 100000),
'prune_sleep_ms' => (int) env('ONLINE_VISITOR_INDEX_PRUNE_SLEEP_MS', 25),
],
];
+13
View File
@@ -83,6 +83,19 @@ return [
'connect_timeout_seconds' => (int) env('VISION_VECTOR_GATEWAY_CONNECT_TIMEOUT', 5),
'retries' => (int) env('VISION_VECTOR_GATEWAY_RETRIES', 1),
'retry_delay_ms' => (int) env('VISION_VECTOR_GATEWAY_RETRY_DELAY_MS', 250),
// Tighter budget for the read/search path, which runs synchronously inside
// web requests (unlike upsert/delete, which only run from queued/console
// indexing jobs). Keeps a slow or unreachable gateway from pinning FPM
// workers for 20s+ per request.
'search_timeout_seconds' => (int) env('VISION_VECTOR_GATEWAY_SEARCH_TIMEOUT', 6),
'search_connect_timeout_seconds' => (int) env('VISION_VECTOR_GATEWAY_SEARCH_CONNECT_TIMEOUT', 2),
'search_retries' => (int) env('VISION_VECTOR_GATEWAY_SEARCH_RETRIES', 0),
// Once a search call fails, stop attempting new ones for this many seconds
// (circuit breaker) — avoids every concurrent request for a different
// artwork independently blocking on the same downed/slow gateway.
'circuit_breaker_seconds' => (int) env('VISION_VECTOR_GATEWAY_CIRCUIT_SECONDS', 30),
'upsert_endpoint' => env('VISION_VECTOR_GATEWAY_UPSERT_ENDPOINT', '/vectors/upsert'),
'upsert_file_endpoint' => env('VISION_VECTOR_GATEWAY_UPSERT_FILE_ENDPOINT', '/vectors/upsert/file'),
'search_endpoint' => env('VISION_VECTOR_GATEWAY_SEARCH_ENDPOINT', '/vectors/search'),
@@ -0,0 +1,64 @@
<?php
declare(strict_types=1);
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
public function up(): void
{
Schema::create('security_reports', function (Blueprint $table): void {
$table->id();
$table->string('status', 32)->default('completed');
$table->timestamp('started_at')->nullable();
$table->timestamp('finished_at')->nullable();
$table->unsignedInteger('composer_critical')->default(0);
$table->unsignedInteger('composer_high')->default(0);
$table->unsignedInteger('composer_medium')->default(0);
$table->unsignedInteger('composer_low')->default(0);
$table->unsignedInteger('composer_unknown')->default(0);
$table->unsignedInteger('npm_critical')->default(0);
$table->unsignedInteger('npm_high')->default(0);
$table->unsignedInteger('npm_moderate')->default(0);
$table->unsignedInteger('npm_low')->default(0);
$table->unsignedInteger('npm_info')->default(0);
$table->unsignedInteger('npm_unknown')->default(0);
$table->unsignedInteger('total_critical')->default(0);
$table->unsignedInteger('total_high')->default(0);
$table->unsignedInteger('total_medium')->default(0);
$table->unsignedInteger('total_low')->default(0);
$table->unsignedInteger('total_unknown')->default(0);
$table->unsignedInteger('composer_outdated_count')->default(0);
$table->unsignedInteger('npm_outdated_count')->default(0);
$table->json('summary')->nullable();
$table->json('composer_audit')->nullable();
$table->json('composer_outdated')->nullable();
$table->json('npm_audit')->nullable();
$table->json('npm_outdated')->nullable();
$table->longText('error_message')->nullable();
$table->string('triggered_by', 64)->nullable();
$table->foreignId('user_id')->nullable()->constrained()->nullOnDelete();
$table->timestamps();
$table->index('status');
$table->index('finished_at');
$table->index(['total_critical', 'total_high']);
});
}
public function down(): void
{
Schema::dropIfExists('security_reports');
}
};
@@ -0,0 +1,53 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
public function up(): void
{
Schema::table('artworks', function (Blueprint $table): void {
if (! Schema::hasColumn('artworks', 'featured_thumbnail_variants_json')) {
$table->json('featured_thumbnail_variants_json')
->nullable()
->after('thumbnails_checked_at');
}
if (! Schema::hasColumn('artworks', 'featured_thumbnails_checked_at')) {
$table->timestamp('featured_thumbnails_checked_at')
->nullable()
->after('featured_thumbnail_variants_json');
}
});
Schema::table('artworks', function (Blueprint $table): void {
if (Schema::hasColumn('artworks', 'featured_thumbnails_checked_at')) {
$table->index('featured_thumbnails_checked_at', 'artworks_featured_thumbnails_checked_idx');
}
});
}
public function down(): void
{
Schema::table('artworks', function (Blueprint $table): void {
try {
$table->dropIndex('artworks_featured_thumbnails_checked_idx');
} catch (Throwable) {
}
$columns = [];
foreach (['featured_thumbnail_variants_json', 'featured_thumbnails_checked_at'] as $column) {
if (Schema::hasColumn('artworks', $column)) {
$columns[] = $column;
}
}
if ($columns !== []) {
$table->dropColumn($columns);
}
});
}
};
@@ -0,0 +1,71 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
/**
* M10 — proposed production schema change. Do not run on production until
* a dedicated deploy window. idx_artwork_bucket is an exact duplicate of
* UNIQUE uq_artwork_bucket (artwork_id, bucket_hour).
*
* idx_bucket_hour is a left prefix of idx_bucket_artwork and is documented
* as a later candidate only — not dropped here.
*/
return new class extends Migration
{
public function up(): void
{
if (! Schema::hasTable('artwork_metric_snapshots_hourly')) {
return;
}
if (! $this->indexExists('artwork_metric_snapshots_hourly', 'idx_artwork_bucket')) {
return;
}
Schema::table('artwork_metric_snapshots_hourly', function (Blueprint $table) {
$table->dropIndex('idx_artwork_bucket');
});
}
public function down(): void
{
if (! Schema::hasTable('artwork_metric_snapshots_hourly')) {
return;
}
if ($this->indexExists('artwork_metric_snapshots_hourly', 'idx_artwork_bucket')) {
return;
}
Schema::table('artwork_metric_snapshots_hourly', function (Blueprint $table) {
$table->index(['artwork_id', 'bucket_hour'], 'idx_artwork_bucket');
});
}
private function indexExists(string $table, string $indexName): bool
{
if (DB::getDriverName() === 'sqlite') {
$indexes = DB::select("PRAGMA index_list({$table})");
foreach ($indexes as $index) {
if (($index->name ?? '') === $indexName) {
return true;
}
}
return false;
}
$database = Schema::getConnection()->getDatabaseName();
$row = DB::selectOne(
'SELECT COUNT(*) AS c FROM information_schema.statistics
WHERE table_schema = ? AND table_name = ? AND index_name = ?',
[$database, $table, $indexName]
);
return (int) ($row->c ?? 0) > 0;
}
};
@@ -0,0 +1,23 @@
# M12 — structured HTTP performance log format.
# Install into /etc/nginx/conf.d/ (already included from nginx.conf http {}).
# Do not replace the existing combined access log.
# Activate with a second access_log on the Skinbase server block.
#
# Variables validated against nginx/1.26.3 on server3.
# $uri is used (not $request_uri) so query strings are not logged.
# No $remote_addr, cookies, or Authorization.
log_format skinbase_perf escape=json
'{"time":"$time_iso8601",'
'"host":"$host",'
'"method":"$request_method",'
'"uri":"$uri",'
'"status":$status,'
'"request_time":$request_time,'
'"upstream_response_time":"$upstream_response_time",'
'"upstream_connect_time":"$upstream_connect_time",'
'"upstream_header_time":"$upstream_header_time",'
'"bytes":$body_bytes_sent,'
'"request_length":$request_length,'
'"content_type":"$sent_http_content_type",'
'"cache":"$upstream_cache_status"}';
+43
View File
@@ -0,0 +1,43 @@
# -----------------------------------------------------------------------
# Rate limiting for /search and the AI vector-search endpoints
#
# Laravel already throttles these routes at the application layer
# (see App\Providers\AppServiceProvider::configureSearchRateLimiter /
# configureVectorSearchRateLimiter), but that still costs one PHP-FPM
# worker per request just to run the rate limiter and reject the
# request. This nginx-level limiter rejects floods with a 503 before
# they ever reach FPM, which is what actually protects worker capacity
# during a scripted flood or bot storm.
#
# Setup:
# 1. Add the `limit_req_zone` and `limit_req_status` lines to the
# `http {}` block (nginx.conf or conf.d/00-rate-limit-zones.conf) —
# zones MUST be declared at http level, not inside server {}.
# 2. Include the `location` blocks below inside the relevant
# `server {}` block, ABOVE the general `location ~ \.php$` /
# PHP-FPM passthrough.
# -----------------------------------------------------------------------
# --- Add to the http {} block ---------------------------------------------
# limit_req_zone $binary_remote_addr zone=search_zone:10m rate=20r/m;
# limit_req_zone $binary_remote_addr zone=ai_search_zone:10m rate=10r/m;
# limit_req_status 429;
# limit_req_log_level warn;
# ---------------------------------------------------------------------------
# Human search traffic: /search page + /api/search/* (Meilisearch-backed,
# cheap once app-level caching is warm — burst allowance covers pagination
# clicks / autocomplete without tripping on normal use).
location ~ ^/(search|api/search) {
limit_req zone=search_zone burst=15 nodelay;
try_files $uri $uri/ /index.php?$query_string;
}
# AI similarity / image-search endpoints: each request can trigger an
# outbound HTTP call to the vision vector gateway (see
# App\Services\Vision\VectorGatewayClient), so keep the burst tight —
# a flood here is the "consuming FPM workers" scenario from the slow log.
location ~ ^/api/(art/[0-9]+/similar-ai|search/image) {
limit_req zone=ai_search_zone burst=5 nodelay;
try_files $uri $uri/ /index.php?$query_string;
}
+27 -18
View File
@@ -1,38 +1,47 @@
# ---------------------------------------------------------------------------
# Nginx static sitemap file serving
# ---------------------------------------------------------------------------
# Include this snippet inside your `server {}` block BEFORE the main
# `location /` (or `location ~ \.php$`) block so nginx serves the pre-built
# static XML files without ever touching PHP/FPM.
# Compatible with the production skinbase.org vhost, which has NO named
# location @php. Laravel is already wired as:
#
# The GenerateSitemapsCommand writes these files on a schedule (every 6 h):
# public/sitemap.xml <- root sitemap index
# public/sitemaps/{name}.xml <- per-family / per-shard documents
# location / {
# try_files $uri $uri/ /index.php?$query_string;
# }
# location = /index.php {
# fastcgi_pass unix:/run/php/php8.4-fpm-skinbase.sock;
# ...
# }
#
# When a file has not been generated yet (first deploy, cold start) the
# request falls through to @php and Laravel's SitemapController builds it
# live on the first hit.
# Do not add `try_files ... @php` — that named location does not exist on
# server3 and nginx -t / runtime would fail (or 500) when the static file
# is missing.
#
# GenerateSitemapsCommand writes:
# public/sitemaps/index.xml <- canonical generated root index
# public/sitemaps/sitemap.xml <- legacy filename (best-effort)
# public/sitemap.xml <- legacy $uri (often unwritable on prod)
# public/sitemaps/{name}.xml <- child / shard documents
#
# Place these location blocks BEFORE `location /` is not required if they are
# more specific (`=` and regex), but they must remain inside the 443 server.
# ---------------------------------------------------------------------------
# Root sitemap index
location = /sitemap.xml {
# Serve the static file if it exists; otherwise fall through to PHP.
try_files $uri @php;
# Prefer the scheduler-writable generated index. Fall back to the legacy
# sitemaps/sitemap.xml, then Laravel front controller (not @php).
try_files /sitemaps/index.xml /sitemaps/sitemap.xml /index.php?$query_string;
# Instruct downstream caches / crawlers how long the file is fresh.
add_header Cache-Control "public, max-age=21600" always; # 6 h
add_header Cache-Control "public, max-age=21600" always;
add_header Content-Type "application/xml; charset=UTF-8" always;
# Optional: let nginx set a strong ETag automatically (default behaviour).
etag on;
}
# Per-family / per-shard sitemap documents
location ~ ^/sitemaps/[A-Za-z0-9_\-]++\.xml$ {
try_files $uri @php;
try_files $uri /index.php?$query_string;
add_header Cache-Control "public, max-age=21600" always; # 6 h
add_header Cache-Control "public, max-age=21600" always;
add_header Content-Type "application/xml; charset=UTF-8" always;
etag on;
}
@@ -0,0 +1,16 @@
# M12 — add INSIDE the HTTPS server { } for skinbase.org, next to the
# existing combined access_log. Keep the original line unchanged.
#
# access_log /var/log/nginx/skinbase.org-access.log;
# access_log /var/log/nginx/skinbase-performance.log skinbase_perf;
#
# Locations that already set `access_log off;` (static assets, /photo/*.jpg)
# remain excluded from both logs.
# File is created as 0640 www-data adm by nginx; logrotate /var/log/nginx/*.log
# already rotates it (daily, 14 copies).
#
# After install:
# sudo nginx -t && sudo systemctl reload nginx
# Never `restart` nginx for this change.
access_log /var/log/nginx/skinbase-performance.log skinbase_perf;
+2
View File
@@ -39,6 +39,8 @@ The example worker listens on the application queues currently used by Skinbase
search,forum-security,forum-moderation,vision,recommendations,discovery,mail,default
```
Production uses **Horizon**, not this standalone `queue:work` example. Horizon supervisors must list every queue that application code pushes to. The `mail` queue is consumed by `supervisor-mail` in `config/horizon.php` (isolated from search/recommendation workers).
If you split workloads across dedicated workers, make sure the Scout/Meilisearch `search` queue and any queues configured through `VISION_QUEUE`, `RECOMMENDATIONS_QUEUE`, or `DISCOVERY_QUEUE` are explicitly covered by at least one worker process.
To use it on a Debian/Ubuntu server:

Some files were not shown because too many files have changed in this diff Show More