Compare commits

..
50 Commits
Author SHA1 Message Date
klevze 69edffdfee Rebuild Inertia SSR assets after the upload and artwork UI changes.
Replace hashed SSR bundles so server-rendered pages match the current frontend.
2026-09-20 14:51:12 +02:00
klevze fe1054aa32 Update the optimization roadmap through the latest milestones.
Keep the production optimization plan aligned with the work already landed on develop.
2026-09-20 14:51:12 +02:00
klevze a206981914 Wire new routes and environment keys for the recent modules.
Register AdSense, artwork review, comment captcha, lazy collections, and upload review props, and document the matching env vars and CLI commands.
2026-09-20 14:51:04 +02:00
klevze 02861b5a2f Expand profile gender options and cover country plus activity persistence.
Allow the broader gender enum and add tests for country saves and discovery event recording.
2026-09-20 14:50:59 +02:00
klevze 1b8853b0c9 Harden legacy user profile lookups.
Keep the old user controller aligned with current profile fields and safer query handling.
2026-09-20 14:50:59 +02:00
klevze 12da3c5081 Tighten artwork hourly snapshot window queries.
Reduce snapshot work to the active hour window so metrics aggregation stays cheaper on the hot path.
2026-09-20 14:50:59 +02:00
klevze 0b6f3a95e3 Limit anonymous community activity queries to the latest page.
Skip unused activity sources and historical over-fetching for guests while keeping authenticated feeds filterable.
2026-09-20 14:50:58 +02:00
klevze 5d703b8da4 Warn newer creators that uploads go through review first.
Show a level-based notice on /upload without revealing the internal approved-artwork threshold, and mention the usual 48-hour review window.
2026-09-20 14:50:39 +02:00
klevze 6b00652a20 Allow artworks to have one primary category and extra secondaries.
Keep artwork_category as membership, store a deterministic primary_category_id, and let upload plus studio pick up to five additional same-type categories without changing canonical URLs.
2026-09-20 14:50:12 +02:00
klevze ce0f278bac Add a read-only Google AdSense analytics module for admins.
Connect AdSense over OAuth, sync entities and daily reports locally, and show placement performance in the admin panel without calling the Management API from public pages.
2026-09-20 14:49:48 +02:00
klevze 04a60a981e Keep AdSense rendering limited to anonymous visitors.
Show guest-only ad units on public pages and skip the AdSense script entirely for signed-in users.
2026-09-20 14:49:34 +02:00
klevze 822b96e92a Lazy-load profile collections until the tab is opened.
Keep the profile payload smaller on first paint and fetch collections through a dedicated API when the collections tab is needed.
2026-09-20 14:49:33 +02:00
klevze a5e51617a6 Extract related artwork lookup into a dedicated service.
Reuse the same related-artwork ranking on similar-art pages and keep category and tag matches from duplicating results.
2026-09-20 14:49:32 +02:00
klevze 1053a38eee Harden vision vector search and embedding jobs.
Add point search, circuit-breaking, and safer gateway limits so artwork similarity lookups fail closed instead of hanging the request path.
2026-09-20 14:49:19 +02:00
klevze 04b8160d9e Track original artwork file availability more accurately.
Resolve local and object-storage originals, persist download status, and audit missing files without guessing from a single path.
2026-09-20 14:49:19 +02:00
klevze 0f52803b05 Send new artwork uploads through a trust-based review policy.
Require review for untrusted accounts, add admin artwork review APIs, and keep queued or auto-trusted publishes from counting as established history.
2026-09-20 14:49:06 +02:00
klevze 31c87e4977 Move model observers onto attributes and tidy provider bindings.
Register observers with ObservedBy, bind the comment spam classifier, and keep AppServiceProvider focused on application wiring.
2026-09-20 14:49:00 +02:00
klevze 586c44ba74 Add comment spam classification and captcha checks.
Score artwork comments with local signatures plus Together AI, and optionally require Turnstile before posting.
2026-09-20 14:48:50 +02:00
klevze 37bacc1334 Defer Carbon package discovery until it is needed.
Keep Laravel from auto-discovering nesbot/carbon so the app can boot the lazy Carbon provider instead.
2026-09-20 14:48:37 +02:00
test 58e5b3f648 Expose safe production build metadata 2026-08-30 12:16:22 +02:00
test aba2017273 Update production deploy safeguards 2026-08-30 12:02:25 +02:00
test 937f484cc9 Defer profile world history until needed 2026-08-30 12:02:07 +02:00
test 5c80402aed fix 2026-08-30 11:06:07 +02:00
test e7c878525d Update optimization roadmap through M19 2026-08-30 09:33:36 +02:00
test 6a6900435c Require reproducible production deploy sources 2026-08-30 09:33:36 +02:00
test 7c38ffff57 Finalize Supervisor-owned SSR deployment 2026-08-30 09:28:44 +02:00
test 71972afb87 Make profile formatting hydration-safe 2026-08-30 09:28:07 +02:00
klevze 5db36cb29f Align group profile summary contract 2026-08-30 08:48:03 +02:00
klevze 7805baa17d Collapse profile group contribution queries 2026-08-30 07:58:38 +02:00
klevze dba1f73e01 Defer profile favourites until needed 2026-08-30 07:30:15 +02:00
klevze 187292a374 Make XP progress formatting hydration-safe 2026-08-29 21:28:26 +02:00
klevze 99d94c9333 Make profile SSR formatting deterministic 2026-08-29 20:24:38 +02:00
klevze 872f420190 Defer profile featured artworks 2026-08-29 16:33:36 +02:00
klevze ff80f5bf97 Rollback comments observer margin 2026-08-29 14:12:51 +02:00
klevze 29e6dee609 Reduce deferred comments observer margin 2026-08-29 13:53:00 +02:00
klevze 2f8f7472ca tests cleanup 2026-08-29 13:49:13 +02:00
klevze 771f9f4350 Document M1-M18 production optimization status.
Record what landed, what is in flight, and what remains so later deploys can pick up the plan without archaeology.
2026-08-29 12:25:50 +02:00
klevze 4c409ceb81 Rebuild Inertia SSR artifacts after deferred artwork UI.
Keep bootstrap/ssr in sync with the client Vite build shipped in this stack.
2026-08-29 12:25:50 +02:00
klevze ab8fa6d845 Fix Windows/WSL production deploy hang and permissions.
Skip slow Git worktree walks on /mnt, run Vite on Windows npm, reuse Windows SSH keys, and stop rewriting the klevze-owned public app symlink that skinbase cannot replace.
2026-08-29 12:25:50 +02:00
klevze bf9ca12469 Add a public profile followers tab.
Expose follower lists on public profiles with a dedicated tab and API path instead of only showing counts.
2026-08-29 12:25:49 +02:00
klevze 1d350c9bca Defer similar-AI recommendations until the rail is near view.
ArtworkPage already imports this hook; ship the implementation so similar-AI work stays off the initial render.
2026-08-29 12:25:49 +02:00
klevze 437d943827 Prefetch artwork prev/next navigation off the critical path.
Move neighbor lookup into a dedicated service and let the viewer load adjacent artworks after first paint instead of blocking the detail request.
2026-08-29 12:25:49 +02:00
klevze bf902f509a Batch-load comment reaction counts on artwork comments.
Avoid per-comment reaction queries on the deferred comments API by aggregating counts in one service call.
2026-08-29 12:25:37 +02:00
klevze bfcbfec357 Cache Schema::hasTable lookups on artwork JSON.
Artwork detail was paying repeated information_schema hits per request. Keep public detail edge-case behavior covered by regression tests.
2026-08-29 12:25:37 +02:00
klevze b9beb8f5c5 Speed legacy photo serving and skip tracking on download routes.
Tighten thumbnail/legacy photo handling and exclude download/photo traffic from session visitor tracking so those hot paths stay cheap.
2026-08-29 12:25:37 +02:00
klevze e9cf754b37 Enable nginx X-Accel for original artwork downloads.
Hand originals to nginx after auth so PHP is not in the byte path. Keep DOWNLOAD_ACCEL_ENABLED off until the internal location is verified.
2026-08-29 12:25:37 +02:00
klevze fb560fb7dd Add HTTP performance log analyzer (M12.6).
Parse rotated nginx JSON access logs into host/route timings so production hotspots can be measured without ad-hoc one-off scripts.
2026-08-29 12:25:27 +02:00
klevze 4ab315e9d7 Defer artwork comments from initial render 2026-08-29 12:07:08 +02:00
klevze 8a80aae21e Ship production optimization M1-M12.5A: queues, metrics, HTTP observability, and vector search reliability.
Keep similar-ai from tripping the global circuit on a lone URL 502, clamp Qdrant search to 100, and add Server-Timing plus slow-request logging. Studio shared props, Academy S3 exists caching, heat chunking, and Redis/scheduler hygiene stay in this rollout.
2026-08-25 07:58:47 +02:00
klevze f52879edbb Current state with latest updates 2026-08-23 13:28:34 +02:00
489 changed files with 37754 additions and 5601 deletions
+83
View File
@@ -4,6 +4,23 @@ APP_KEY=
APP_DEBUG=true
APP_URL=http://localhost
# Maximum secondary artwork categories in addition to the primary category.
CATEGORIES_MAX_SECONDARY=5
# Artwork original downloads: PHP fallback unless nginx X-Accel is configured.
# Leave false until the internal location exists and has been verified.
DOWNLOAD_ACCEL_ENABLED=false
DOWNLOAD_ACCEL_PATH=/internal/originals
SECURITY_REPORT_ENABLED=true
SECURITY_REPORT_NOTIFY_EMAIL=
SECURITY_REPORT_SCAN_NPM=true
SECURITY_REPORT_SCAN_COMPOSER=true
SECURITY_REPORT_STORE_RAW=true
SECURITY_REPORT_MAX_RAW_KB=512
SECURITY_REPORT_FAIL_ON_HIGH=false
SECURITY_REPORT_FAIL_ON_CRITICAL=false
APP_LOCALE=en
APP_FALLBACK_LOCALE=en
APP_FAKER_LOCALE=en_US
@@ -20,6 +37,11 @@ LOG_STACK=single
LOG_DEPRECATIONS_CHANNEL=null
LOG_LEVEL=debug
# M12 — slow Laravel HTTP log (threshold only; disable for zero overhead)
HTTP_SLOW_REQUEST_LOG_ENABLED=false
HTTP_SLOW_REQUEST_MS=750
HTTP_SLOW_REQUEST_LOG_DAYS=14
DB_CONNECTION=mysql
DB_HOST=127.0.0.1
DB_PORT=3306
@@ -53,6 +75,48 @@ BROADCAST_CONNECTION=reverb
FILESYSTEM_DISK=local
QUEUE_CONNECTION=redis
# Comment spam protection: observe records scores without changing visibility.
COMMENT_SPAM_ENABLED=true
COMMENT_SPAM_MODE=enforce
COMMENT_SPAM_AI_ENABLED=true
COMMENT_SPAM_AI_PROVIDER=together
# Supported: Prism-ML/Ternary-Bonsai-27B or meta-llama/Llama-3.2-3B-Instruct-Turbo
COMMENT_SPAM_AI_MODEL=meta-llama/Llama-3.2-3B-Instruct-Turbo
COMMENT_SPAM_AI_TIMEOUT=5
TOGETHER_API_KEY=
TOGETHER_API_BASE_URL=https://api.together.xyz/v1
COMMENT_SPAM_LOCAL_SAFE_MAX=29
COMMENT_SPAM_LOCAL_SPAM_MIN=70
COMMENT_SPAM_AI_SPAM_MIN=70
COMMENT_SPAM_SIGNATURE_CACHE_MINUTES=1440
COMMENT_TURNSTILE_ENABLED=false
COMMENT_TURNSTILE_SITE_KEY=
COMMENT_TURNSTILE_SECRET_KEY=
COMMENT_TURNSTILE_RISK_THRESHOLD=40
COMMENT_TURNSTILE_FAIL_OPEN=false
# Must exceed Horizon supervisor-default timeout (960s). Production used 90s
# and nightly RecComputeSimilar* jobs failed with MaxAttemptsExceeded.
REDIS_QUEUE_RETRY_AFTER=1080
# Collection maintenance / forum AI jobs have no Horizon consumer.
# Leave false until a dedicated supervisor exists (M7).
COLLECTIONS_V5_DISPATCH_ENABLED=false
FORUM_QUEUE_DISPATCH_ENABLED=false
ONLINE_VISITOR_INDEX_READ_LIMIT=2000
ONLINE_VISITOR_INDEX_PRUNE_ENABLED=false
ONLINE_VISITOR_INDEX_PRUNE_SCAN_COUNT=500
ONLINE_VISITOR_INDEX_PRUNE_MAX_BATCHES=200
ONLINE_VISITOR_INDEX_PRUNE_SLEEP_MS=25
# RankBuildScopeListsJob unique lock (seconds). Must exceed queue wait + 300s timeout.
RANK_SCOPE_JOB_UNIQUE_FOR=21600
# Hourly artwork metric snapshots (heat / rising / monthly leaderboards).
# Production currently holds ~7 days because the scheduler passed --keep-days=7.
# Monthly leaderboards and Studio 30d views need 30 days of hourly history.
ARTWORK_METRIC_HOURLY_RETENTION_DAYS=30
ARTWORK_METRIC_HOURLY_PRUNE_CHUNK=5000
ARTWORK_METRIC_HOURLY_PRUNE_SLEEP_MS=50
MESSAGING_REALTIME=true
MESSAGING_BROADCAST_QUEUE=broadcasts
MESSAGING_TYPING_TTL=8
@@ -92,6 +156,13 @@ UPLOAD_CHUNK_REQUEST_TIMEOUT_MS=45000
UPLOAD_RATE_CHUNK_USER=180
UPLOAD_RATE_CHUNK_IP=360
# New accounts without this many moderator/legacy published artworks go to review.
# Queued uploads and trusted_auto publishes do not count, so a new user's 6th upload stays hidden.
UPLOAD_MIN_APPROVED_UPLOADS=5
UPLOAD_MIN_ACCOUNT_AGE_DAYS=7
UPLOAD_MAX_UNTRUSTED_LEVEL=1
UPLOAD_BOT_RISK_REVIEW_THRESHOLD=40
# Draft abuse prevention controls
SKINBASE_MAX_DRAFTS=10
SKINBASE_MAX_DRAFT_STORAGE_MB=1024
@@ -114,6 +185,11 @@ VISION_VECTOR_GATEWAY_RETRIES=1
VISION_VECTOR_GATEWAY_RETRY_DELAY_MS=250
VISION_VECTOR_GATEWAY_UPSERT_ENDPOINT=/vectors/upsert
VISION_VECTOR_GATEWAY_SEARCH_ENDPOINT=/vectors/search
VISION_VECTOR_GATEWAY_SEARCH_FILE_ENDPOINT=/vectors/search/file
VISION_VECTOR_GATEWAY_SEARCH_TIMEOUT=6
VISION_VECTOR_GATEWAY_SEARCH_CONNECT_TIMEOUT=2
VISION_VECTOR_GATEWAY_SEARCH_RETRIES=0
VISION_VECTOR_GATEWAY_CIRCUIT_SECONDS=30
VISION_VECTOR_GATEWAY_DELETE_ENDPOINT=/vectors/delete
VISION_VECTOR_GATEWAY_COLLECTIONS_ENDPOINT=/vectors/collections
@@ -399,6 +475,13 @@ GOOGLE_CLIENT_ID=
GOOGLE_CLIENT_SECRET=
GOOGLE_REDIRECT_URI=/auth/google/callback
# Google AdSense Management API (admin analytics, read-only)
# Redirect URI must match the Google Cloud OAuth client exactly.
ADSENSE_CLIENT_ID=
ADSENSE_CLIENT_SECRET=
ADSENSE_REDIRECT_URI=https://skinbase.org/admin/adsense/oauth/callback
ADSENSE_SYNC_ENABLED=true
# Optional light theme feature
# Set LIGHT_THEME_ENABLED=true to allow a light theme in the client-side toggle.
# Set LIGHT_THEME_SHOW_SWITCH=true to display the theme switch in the toolbar.
+2
View File
@@ -13,6 +13,7 @@
/.deploy
/.zed
/auth.json
/build-info.json
/node_modules
/public/build
/public/hot
@@ -45,6 +46,7 @@
/storage/*.tar.xz
/storage/*.tar
/storage/*.tgz
/var/deploy/
/vendor
Homestead.json
Homestead.yaml
+137
View File
@@ -0,0 +1,137 @@
<?php
declare(strict_types=1);
namespace App\Console\Commands;
use App\Models\AdsenseConnection;
use App\Services\Adsense\AdsenseSyncResult;
use App\Services\Adsense\AdsenseSyncService;
use Illuminate\Console\Command;
use Illuminate\Support\Carbon;
final class AdsenseSyncCommand extends Command
{
protected $signature = 'adsense:sync
{--days= : Number of trailing days to synchronize, including today}
{--from= : Inclusive start date (YYYY-MM-DD)}
{--to= : Inclusive end date (YYYY-MM-DD)}
{--entities-only : Synchronize ad units and custom channels without reports}
{--force : Run even when ADSENSE_SYNC_ENABLED is false}';
protected $description = 'Synchronize Google AdSense entities and daily reporting into Skinbase';
public function handle(AdsenseSyncService $sync): int
{
if (! (bool) config('adsense.sync_enabled', true) && ! $this->option('force')) {
$this->warn('AdSense synchronization is disabled. Use --force to run anyway.');
return self::SUCCESS;
}
try {
[$from, $to] = $this->resolveRange();
} catch (\InvalidArgumentException $exception) {
$this->error($exception->getMessage());
return self::INVALID;
}
$connection = AdsenseConnection::current();
if ($connection === null || ! $connection->hasRefreshToken()) {
$this->error('Google AdSense is not connected.');
return self::FAILURE;
}
if ($connection->status === AdsenseConnection::STATUS_RECONNECT_REQUIRED) {
$this->error('AdSense authorization expired or was revoked. Reconnect Google AdSense.');
return self::FAILURE;
}
if ((string) $connection->account_resource_name === '') {
$this->error('No AdSense account is selected.');
return self::FAILURE;
}
$entitiesOnly = (bool) $this->option('entities-only');
$result = $sync->sync($connection, $from, $to, $entitiesOnly);
$this->renderResult($result, $entitiesOnly);
if ($result->reconnectRequired) {
$this->error('AdSense authorization expired or was revoked. Reconnect Google AdSense.');
return self::FAILURE;
}
if ($result->failedReports !== []) {
$this->warn('Synchronization completed with partial report failures: '.implode(', ', $result->failedReports));
return self::SUCCESS;
}
$this->info('Synchronization completed successfully.');
return self::SUCCESS;
}
/**
* @return array{0: Carbon, 1: Carbon}
*/
private function resolveRange(): array
{
$days = $this->option('days');
$from = $this->option('from');
$to = $this->option('to');
if ($days !== null && ($from !== null || $to !== null)) {
throw new \InvalidArgumentException('The --days option cannot be combined with --from or --to.');
}
if (($from !== null) !== ($to !== null)) {
throw new \InvalidArgumentException('Both --from and --to are required for a custom range.');
}
if (is_string($from) && is_string($to)) {
$start = Carbon::parse($from)->startOfDay();
$end = Carbon::parse($to)->startOfDay();
if ($end->lt($start)) {
throw new \InvalidArgumentException('The --to date must be on or after --from.');
}
return [$start, $end];
}
$trailingDays = $days !== null ? max(1, (int) $days) : 3;
$end = now()->startOfDay();
$start = $end->copy()->subDays($trailingDays - 1);
return [$start, $end];
}
private function renderResult(AdsenseSyncResult $result, bool $entitiesOnly): void
{
$this->line('AdSense account: '.($result->accountDisplayName !== '' ? $result->accountDisplayName : 'unknown'));
$this->line('Range: '.$result->from.' -> '.$result->to);
$this->newLine();
$this->line('Entities:');
$this->line(' Ad units: '.$result->adUnits);
$this->line(' Custom channels: '.$result->customChannels);
if ($entitiesOnly) {
return;
}
$this->newLine();
$this->line('Reports:');
$this->line(' Total: '.$result->totalRows);
$this->line(' Ad units: '.$result->adUnitRows);
$this->line(' Custom channels: '.$result->customChannelRows);
$this->line(' Platform: '.$result->platformRows);
$this->line(' Countries: '.$result->countryRows);
$this->newLine();
}
}
@@ -18,6 +18,9 @@ final class AuditArtworkDownloadFilesCommand extends Command
{--id= : Audit only this artwork ID}
{--limit= : Stop after processing this many artworks}
{--chunk=500 : Number of artworks to scan per batch}
{--status= : Only inspect records with this persisted download status}
{--missing-only : Only report unresolved records}
{--mark-status : Persist the resolved availability status (explicit write)}
{--restore-missing : Copy missing local originals from object storage when available}';
protected $description = 'Scan artworks in descending ID order and report missing local download files with full URLs.';
@@ -28,6 +31,8 @@ final class AuditArtworkDownloadFilesCommand extends Command
$limit = $this->option('limit') !== null ? max(1, (int) $this->option('limit')) : null;
$chunkSize = max(1, min((int) $this->option('chunk'), 2000));
$restoreMissing = (bool) $this->option('restore-missing');
$markStatus = (bool) $this->option('mark-status');
$statusFilter = $this->option('status');
$this->info(sprintf(
'Starting download file audit. order=desc include_trashed=yes chunk=%d limit=%s restore_missing=%s',
@@ -41,10 +46,11 @@ final class AuditArtworkDownloadFilesCommand extends Command
$unresolved = 0;
$restored = 0;
$restoreFailed = 0;
$classifications = [];
$lastSeenId = null;
do {
$artworks = $this->nextChunk($artworkId, $chunkSize, $lastSeenId);
$artworks = $this->nextChunk($artworkId, $chunkSize, $lastSeenId, is_string($statusFilter) ? $statusFilter : null);
if ($artworks->isEmpty()) {
break;
}
@@ -54,18 +60,36 @@ final class AuditArtworkDownloadFilesCommand extends Command
break 2;
}
$localPath = $locator->resolveLocalPath($artwork);
$missingReason = null;
if ($localPath === '') {
$missingReason = 'unresolved_local_path';
$resolution = $locator->resolve($artwork);
$classification = match ($resolution['status']) {
'available' => strtoupper((string) $resolution['source']).'_OK',
'pending' => 'PENDING',
'unknown' => 'AMBIGUOUS',
default => 'MISSING_EVERYWHERE',
};
$classifications[$classification] = ($classifications[$classification] ?? 0) + 1;
$localPath = (string) $resolution['path'];
$missingReason = $resolution['status'] === 'missing' ? 'missing_everywhere' : null;
if ($missingReason !== null) {
$unresolved++;
} elseif (! File::isFile($localPath)) {
$missingReason = 'missing_local_file';
}
if ($markStatus) {
$this->persistStatus($artwork, $resolution);
}
if ($missingReason === null && (bool) $this->option('missing-only')) {
$processed++;
continue;
}
if ($missingReason === null) {
$this->line(sprintf('Artwork %d %s source=%s', (int) $artwork->id, $classification, (string) $resolution['source']));
}
if ($missingReason !== null) {
$objectPath = $locator->resolveObjectPath($artwork);
$objectPath = (string) $resolution['object_key'];
$objectUrl = $locator->resolveObjectUrl($artwork);
$missing++;
@@ -88,7 +112,7 @@ final class AuditArtworkDownloadFilesCommand extends Command
$this->line(' local_path: '.$localPath);
}
if ($restoreMissing && $missingReason === 'missing_local_file' && $localPath !== '') {
if ($restoreMissing && $missingReason === 'missing_everywhere' && $localPath !== '') {
$restoreResult = $this->restoreLocalFile($storage, $objectPath, $localPath);
if ($restoreResult === 'restored') {
@@ -120,6 +144,9 @@ final class AuditArtworkDownloadFilesCommand extends Command
$restored,
$restoreFailed,
));
foreach ($classifications as $classification => $count) {
$this->line(sprintf('classification=%s count=%d', $classification, $count));
}
return self::SUCCESS;
}
@@ -127,11 +154,15 @@ final class AuditArtworkDownloadFilesCommand extends Command
/**
* @return Collection<int, Artwork>
*/
private function nextChunk(?int $artworkId, int $chunkSize, ?int $lastSeenId): Collection
private function nextChunk(?int $artworkId, int $chunkSize, ?int $lastSeenId, ?string $status): Collection
{
if ($artworkId !== null && $lastSeenId !== null) {
return collect();
}
$query = Artwork::query()
->withTrashed()
->select(['id', 'slug', 'file_path', 'hash', 'file_ext'])
->select(['id', 'slug', 'file_name', 'file_path', 'hash', 'file_ext'])
->orderByDesc('id');
if ($artworkId !== null) {
@@ -140,9 +171,30 @@ final class AuditArtworkDownloadFilesCommand extends Command
$query->where('id', '<', $lastSeenId);
}
if ($status !== null && $status !== '') {
$query->where('download_status', $status);
}
return $query->limit($chunkSize)->get();
}
/** @param array{status:string,source:?string} $resolution */
private function persistStatus(Artwork $artwork, array $resolution): void
{
$status = match ($resolution['status']) {
'available' => 'available',
'pending' => 'pending',
'unknown' => 'unknown',
default => 'missing',
};
$artwork->forceFill([
'download_status' => $status,
'download_source' => $resolution['source'],
'download_checked_at' => now(),
])->saveQuietly();
}
private function restoreLocalFile(UploadStorageService $storage, string $objectPath, string $localPath): string
{
if ($objectPath === '') {
@@ -0,0 +1,139 @@
<?php
declare(strict_types=1);
namespace App\Console\Commands;
use App\Models\Artwork;
use Illuminate\Console\Command;
use Illuminate\Support\Collection;
use Illuminate\Support\Facades\DB;
final class BackfillArtworkPrimaryCategoryCommand extends Command
{
protected $signature = 'artworks:backfill-primary-category
{--dry-run : Report without writing (default unless --apply is passed)}
{--report : Print category-count distribution and conflicts}
{--apply : Write primary_category_id for artworks with exactly one category}
{--force : Overwrite existing primary_category_id values}';
protected $description = 'Backfill artworks.primary_category_id from unique artwork_category memberships';
public function handle(): int
{
$apply = (bool) $this->option('apply');
$force = (bool) $this->option('force');
$report = (bool) $this->option('report') || ! $apply;
if ($report) {
$this->printDistribution();
}
$conflicts = $this->conflictArtworkIds();
$zeros = $this->zeroCategoryArtworkIds();
$eligible = $this->eligibleArtworkIds($force);
$this->info('Zero-category artworks: '.$zeros->count());
$this->info('Single-category eligible for backfill: '.$eligible->count());
$this->info('Multi-category conflicts (not auto-resolved): '.$conflicts->count());
if ($conflicts->isNotEmpty()) {
$this->warn('Multi-category artwork IDs (first 50): '.$conflicts->take(50)->implode(', '));
}
if (! $apply) {
$this->comment('Dry run only. Re-run with --apply to write primary_category_id for single-category artworks.');
return self::SUCCESS;
}
$updated = 0;
foreach ($eligible->chunk(500) as $chunk) {
$rows = DB::table('artwork_category')
->select('artwork_id', 'category_id')
->whereIn('artwork_id', $chunk->all())
->get()
->groupBy('artwork_id');
foreach ($rows as $artworkId => $memberships) {
if ($memberships->count() !== 1) {
continue;
}
$query = Artwork::query()->where('id', (int) $artworkId);
if (! $force) {
$query->whereNull('primary_category_id');
}
$updated += $query->update([
'primary_category_id' => (int) $memberships->first()->category_id,
]);
}
}
$this->info("Updated {$updated} artwork(s).");
return self::SUCCESS;
}
private function printDistribution(): void
{
$distribution = DB::query()
->fromSub(function ($query): void {
$query->from('artwork_category')
->select('artwork_id', DB::raw('COUNT(*) as category_count'))
->groupBy('artwork_id');
}, 'x')
->select('category_count', DB::raw('COUNT(*) as artworks'))
->groupBy('category_count')
->orderBy('category_count')
->get();
$this->table(['category_count', 'artworks'], $distribution->map(fn ($row): array => [
(int) $row->category_count,
(int) $row->artworks,
])->all());
}
/**
* @return Collection<int, int>
*/
private function eligibleArtworkIds(bool $force)
{
$query = DB::table('artwork_category')
->select('artwork_id')
->groupBy('artwork_id')
->havingRaw('COUNT(*) = 1');
if (! $force) {
$query->whereIn('artwork_id', Artwork::query()->whereNull('primary_category_id')->select('id'));
}
return $query->pluck('artwork_id')->map(fn ($id): int => (int) $id);
}
/**
* @return Collection<int, int>
*/
private function conflictArtworkIds()
{
return DB::table('artwork_category')
->select('artwork_id')
->groupBy('artwork_id')
->havingRaw('COUNT(*) > 1')
->orderByRaw('COUNT(*) DESC')
->pluck('artwork_id')
->map(fn ($id): int => (int) $id);
}
/**
* @return Collection<int, int>
*/
private function zeroCategoryArtworkIds()
{
return Artwork::query()
->whereDoesntHave('categories')
->pluck('id')
->map(fn ($id): int => (int) $id);
}
}
+32 -2
View File
@@ -49,10 +49,10 @@ final class BuildSitemapsCommand extends Command
$t = microtime(true);
$this->line(' Building sitemap index…');
$index = $build->buildIndex(force: true, persist: false, families: $families);
$disk->put('sitemap.xml', $index['content']);
$disk->put('sitemaps/sitemap.xml', $index['content']);
$written++;
$this->line(sprintf(
' <info>✔</info> sitemap.xml %d entries <comment>%.3fs</comment>',
' <info>✔</info> sitemaps/sitemap.xml %d entries <comment>%.3fs</comment>',
$index['url_count'],
microtime(true) - $t,
));
@@ -112,6 +112,36 @@ final class BuildSitemapsCommand extends Command
));
}
foreach ($build->enabledGroupIndexes() as $groupName => $groupFamilies) {
foreach ($groupFamilies as $family) {
if (! in_array($family, $families, true)) {
continue 2;
}
}
$t = microtime(true);
$this->line(sprintf(' Building grouped sitemap %s…', $groupName));
$built = $build->buildNamed($groupName, force: true, persist: false);
if ($built === null) {
$this->line(sprintf(' <comment>–</comment> %s.xml <fg=red>SKIPPED</> (group builder returned null)', $groupName));
$failed++;
continue;
}
$disk->put('sitemaps/' . $groupName . '.xml', $built['content']);
$written++;
$this->line(sprintf(
' <info>✔</info> %s %d entries <comment>%.3fs</comment>',
$groupName . '.xml',
$built['url_count'] ?? 0,
microtime(true) - $t,
));
}
// ── Summary ───────────────────────────────────────────────────────
$this->newLine();
$this->info(sprintf(
@@ -18,6 +18,12 @@ class DispatchCollectionMaintenanceCommand extends Command
public function handle(CollectionBackgroundJobService $jobs): int
{
if (! (bool) config('collections.v5.queue.dispatch_enabled', false)) {
$this->warn('Collection maintenance dispatch is disabled (COLLECTIONS_V5_DISPATCH_ENABLED). No jobs queued.');
return self::SUCCESS;
}
$runHealth = (bool) $this->option('health');
$runRecommendations = (bool) $this->option('recommendations');
$runDuplicates = (bool) $this->option('duplicates');
@@ -48,13 +48,32 @@ final class GenerateSitemapsCommand extends Command
$this->newLine();
// ── Root sitemap index ────────────────────────────────────────────
// Write several paths so nginx `location = /sitemap.xml` and child
// listings stay in sync. `sitemaps/index.xml` is the canonical generated
// index: it is a new filename, so a scheduler user can create it even
// when a stale `sitemaps/sitemap.xml` is owned by another account.
$t = microtime(true);
$index = $build->buildIndex(force: true, persist: false, families: $families);
$disk->put('sitemaps/sitemap.xml', $index['content']);
$indexPaths = ['sitemaps/index.xml', 'sitemaps/sitemap.xml', 'sitemap.xml'];
$indexWritten = 0;
foreach ($indexPaths as $path) {
if ($this->writeXml($disk, $path, $index['content'])) {
$written++;
$indexWritten++;
}
}
if ($indexWritten === 0) {
$this->error('Failed to write any root sitemap index file. Check ownership of public/sitemap.xml and public/sitemaps/.');
return self::FAILURE;
}
$this->line(sprintf(
' <info>✔</info> sitemaps/sitemap.xml %d entries <comment>%.3fs</comment>',
' <info>✔</info> sitemap index %d entries %d path(s) <comment>%.3fs</comment>',
$index['url_count'],
$indexWritten,
microtime(true) - $t,
));
@@ -78,7 +97,12 @@ final class GenerateSitemapsCommand extends Command
}
$path = 'sitemaps/' . $documentName . '.xml';
$disk->put($path, $built['content']);
if (! $this->writeXml($disk, $path, $built['content'])) {
$this->line(sprintf(' <fg=red>✖</> %s write failed', $documentName . '.xml'));
$failed++;
continue;
}
$written++;
$this->line(sprintf(
@@ -96,6 +120,40 @@ final class GenerateSitemapsCommand extends Command
));
}
foreach ($build->enabledGroupIndexes() as $groupName => $groupFamilies) {
foreach ($groupFamilies as $family) {
if (! in_array($family, $families, true)) {
continue 2;
}
}
$t = microtime(true);
$built = $build->buildNamed($groupName, force: true, persist: false);
if ($built === null) {
$this->line(sprintf(' <comment>–</comment> %s.xml <fg=red>SKIPPED</> (group builder returned null)', $groupName));
$failed++;
continue;
}
$path = 'sitemaps/' . $groupName . '.xml';
if (! $this->writeXml($disk, $path, $built['content'])) {
$this->line(sprintf(' <fg=red>✖</> %s.xml write failed', $groupName));
$failed++;
continue;
}
$written++;
$this->line(sprintf(
' <info>✔</info> %s %d entries <comment>%.3fs</comment>',
$groupName . '.xml',
$built['url_count'] ?? 0,
microtime(true) - $t,
));
}
// ── Summary ───────────────────────────────────────────────────────
$this->newLine();
$this->info(sprintf(
@@ -130,4 +188,17 @@ final class GenerateSitemapsCommand extends Command
return array_values(array_filter($enabled, fn (string $f): bool => in_array($f, $only, true)));
}
private function writeXml(\Illuminate\Contracts\Filesystem\Filesystem $disk, string $path, string $content): bool
{
$ok = $disk->put($path, $content);
if ($ok !== true) {
$this->warn(' Could not write '.$path);
return false;
}
return true;
}
}
@@ -7,34 +7,137 @@ use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Log;
/**
* Prune old hourly metric snapshots to prevent unbounded table growth.
* Prune old hourly metric snapshots in bounded batches.
*
* Usage: php artisan nova:prune-metric-snapshots
* php artisan nova:prune-metric-snapshots --keep-days=7
* Usage:
* php artisan nova:prune-metric-snapshots
* php artisan nova:prune-metric-snapshots --keep-days=30 --chunk=5000 --dry-run
*/
class PruneMetricSnapshotsCommand extends Command
{
protected $signature = 'nova:prune-metric-snapshots
{--keep-days=7 : Keep snapshots for this many days}';
{--keep-days= : Keep snapshots for this many days (default: config metrics.hourly_snapshot_retention_days)}
{--chunk= : Rows to delete per batch (default: config metrics.hourly_snapshot_prune_chunk)}
{--sleep-ms= : Pause between batches in milliseconds}
{--max-batches=0 : Stop after N batches (0 = until done)}
{--dry-run : Count rows that would be deleted without deleting}';
protected $description = 'Delete old hourly metric snapshots beyond the retention window';
protected $description = 'Delete old hourly metric snapshots beyond the retention window (batched)';
public function handle(): int
{
$keepDays = (int) $this->option('keep-days');
$keepDays = $this->resolveKeepDays();
$chunk = $this->resolvePositiveInt('chunk', (int) config('metrics.hourly_snapshot_prune_chunk', 5000), 1);
$sleepMs = $this->resolveNonNegativeInt('sleep-ms', (int) config('metrics.hourly_snapshot_prune_sleep_ms', 50));
$maxBatches = max(0, (int) $this->option('max-batches'));
$dryRun = (bool) $this->option('dry-run');
$cutoff = now()->subDays($keepDays);
$deleted = DB::table('artwork_metric_snapshots_hourly')
if ($keepDays < 1) {
$this->error('keep-days must be >= 1.');
return self::FAILURE;
}
$eligible = (int) DB::table('artwork_metric_snapshots_hourly')
->where('bucket_hour', '<', $cutoff)
->delete();
->count();
$this->info("Pruned {$deleted} snapshot rows older than {$keepDays} days.");
$this->info(sprintf(
'[nova:prune-metric-snapshots] cutoff=%s keep_days=%d eligible=%d chunk=%d sleep_ms=%d max_batches=%s%s',
$cutoff->toDateTimeString(),
$keepDays,
$eligible,
$chunk,
$sleepMs,
$maxBatches === 0 ? 'unlimited' : (string) $maxBatches,
$dryRun ? ' (dry-run)' : ''
));
Log::info('[nova:prune-metric-snapshots] completed', [
'deleted' => $deleted,
if ($dryRun) {
Log::info('[nova:prune-metric-snapshots] dry-run', [
'eligible' => $eligible,
'keep_days' => $keepDays,
'cutoff' => $cutoff->toDateTimeString(),
]);
return self::SUCCESS;
}
$deleted = 0;
$batches = 0;
while (true) {
if ($maxBatches > 0 && $batches >= $maxBatches) {
$this->warn("Stopped after max-batches={$maxBatches}.");
break;
}
$ids = DB::table('artwork_metric_snapshots_hourly')
->where('bucket_hour', '<', $cutoff)
->orderBy('id')
->limit($chunk)
->pluck('id');
if ($ids->isEmpty()) {
break;
}
$batchDeleted = DB::table('artwork_metric_snapshots_hourly')
->whereIn('id', $ids->all())
->delete();
$deleted += $batchDeleted;
$batches++;
Log::info('[nova:prune-metric-snapshots] batch', [
'batch' => $batches,
'deleted' => $batchDeleted,
'deleted_total' => $deleted,
]);
if ($sleepMs > 0) {
usleep($sleepMs * 1000);
}
}
$this->info("Pruned {$deleted} snapshot rows older than {$keepDays} days in {$batches} batch(es).");
Log::info('[nova:prune-metric-snapshots] completed', [
'deleted' => $deleted,
'batches' => $batches,
'keep_days' => $keepDays,
'cutoff' => $cutoff->toDateTimeString(),
'eligible_at_start' => $eligible,
]);
return self::SUCCESS;
}
private function resolveKeepDays(): int
{
$option = $this->option('keep-days');
if ($option === null || $option === '') {
return (int) config('metrics.hourly_snapshot_retention_days', 30);
}
return (int) $option;
}
private function resolvePositiveInt(string $option, int $default, int $minimum): int
{
$raw = $this->option($option);
$value = ($raw === null || $raw === '') ? $default : (int) $raw;
return max($minimum, $value);
}
private function resolveNonNegativeInt(string $option, int $default): int
{
$raw = $this->option($option);
$value = ($raw === null || $raw === '') ? $default : (int) $raw;
return max(0, $value);
}
}
@@ -0,0 +1,88 @@
<?php
declare(strict_types=1);
namespace App\Console\Commands;
use App\Services\Traffic\OnlineVisitorRepository;
use App\Services\Traffic\PresenceIndexPruner;
use Illuminate\Console\Command;
use Illuminate\Support\Facades\Log;
use Illuminate\Support\Facades\Redis;
class PruneOnlineVisitorIndexCommand extends Command
{
protected $signature = 'skinbase:prune-online-visitor-index
{--dry-run : Count stale members without SREM}
{--execute : Remove stale members}
{--scan-count= : SSCAN COUNT}
{--max-batches= : Batches this run}
{--max-members= : Members to inspect this run}
{--sleep-ms= : Pause between batches}
{--time-limit= : Stop after N seconds (0 = none)}';
protected $description = 'Remove stale members from the online-visitor Redis set (SSCAN, never SMEMBERS)';
public function handle(PresenceIndexPruner $pruner): int
{
$dryRun = (bool) $this->option('dry-run');
$execute = (bool) $this->option('execute');
if ($dryRun === $execute) {
$this->error('Pass exactly one of --dry-run or --execute.');
return self::FAILURE;
}
$scanCount = $this->intOption('scan-count', (int) config('traffic.online_visitors.prune_scan_count', 500));
$maxBatches = $this->intOption('max-batches', (int) config('traffic.online_visitors.prune_max_batches', 200));
$maxMembers = $this->intOption('max-members', (int) config('traffic.online_visitors.prune_max_members', 100000));
$sleepMs = $this->intOption('sleep-ms', (int) config('traffic.online_visitors.prune_sleep_ms', 25));
$timeLimit = $this->intOption('time-limit', 0);
$scard = (int) Redis::scard(OnlineVisitorRepository::INDEX_KEY);
$this->info(sprintf(
'[prune-online-visitor-index] key=%s prefix=%s scard=%d scan_count=%d max_batches=%d max_members=%d sleep_ms=%d %s',
OnlineVisitorRepository::INDEX_KEY,
(string) config('database.redis.options.prefix'),
$scard,
$scanCount,
$maxBatches,
$maxMembers,
$sleepMs,
$dryRun ? 'dry-run' : 'execute'
));
$result = $pruner->prune(
$scanCount,
$maxBatches,
$maxMembers,
$sleepMs,
$dryRun,
$timeLimit > 0 ? $timeLimit : null,
);
$this->info(sprintf(
'scanned=%d stale=%d live=%d removed=%d batches=%d',
$result['scanned'],
$result['stale'],
$result['live'],
$result['removed'],
$result['batches']
));
Log::info('[prune-online-visitor-index] completed', $result + ['scard_before' => $scard]);
return self::SUCCESS;
}
private function intOption(string $name, int $default): int
{
$raw = $this->option($name);
if ($raw === null || $raw === '') {
return $default;
}
return max(0, (int) $raw);
}
}
@@ -0,0 +1,94 @@
<?php
declare(strict_types=1);
namespace App\Console\Commands;
use App\Jobs\RecComputeSimilarByTagsJob;
use App\Support\Queues\QueuedJobClassMatcher;
use Illuminate\Console\Command;
use Illuminate\Support\Facades\Log;
use Illuminate\Support\Facades\Redis;
/**
* Deployment cleanup: remove waiting RecComputeSimilarByTagsJob payloads only.
*
* Does not run from the scheduler. Operator must pass --dry-run or --execute.
*
* Usage:
* php artisan skinbase:purge-queued-rec-tags --dry-run
* php artisan skinbase:purge-queued-rec-tags --execute
*/
class PurgeQueuedRecComputeTagsCommand extends Command
{
protected $signature = 'skinbase:purge-queued-rec-tags
{--queue=default : Redis queue name (waiting list only)}
{--dry-run : Count matches without removing}
{--execute : Remove matched waiting payloads}';
protected $description = 'Remove waiting RecComputeSimilarByTagsJob payloads from a Redis queue (opt-in)';
public function handle(): int
{
$dryRun = (bool) $this->option('dry-run');
$execute = (bool) $this->option('execute');
if ($dryRun === $execute) {
$this->error('Pass exactly one of --dry-run or --execute.');
return self::FAILURE;
}
$queue = (string) $this->option('queue');
if (! preg_match('/^[A-Za-z0-9_-]+$/', $queue)) {
$this->error('Invalid queue name.');
return self::FAILURE;
}
$key = 'queues:'.$queue;
$target = RecComputeSimilarByTagsJob::class;
$redis = Redis::connection();
$len = (int) $redis->llen($key);
$matchedPayloads = [];
$chunk = 200;
$this->info(sprintf(
'[purge-queued-rec-tags] queue=%s waiting=%d target=%s %s',
$queue,
$len,
$target,
$dryRun ? 'dry-run' : 'execute'
));
for ($start = 0; $start < $len; $start += $chunk) {
$rows = $redis->lrange($key, $start, min($start + $chunk - 1, $len - 1));
foreach ($rows as $raw) {
if (QueuedJobClassMatcher::isClass((string) $raw, $target)) {
$matchedPayloads[] = (string) $raw;
}
}
}
$matched = count($matchedPayloads);
$removed = 0;
if (! $dryRun) {
foreach ($matchedPayloads as $raw) {
$removed += (int) $redis->lrem($key, 1, $raw);
}
}
$this->info(sprintf('matched=%d removed=%d preserved_other=%s', $matched, $removed, $dryRun ? 'yes' : 'yes'));
Log::info('[purge-queued-rec-tags] completed', [
'queue' => $queue,
'waiting' => $len,
'matched' => $matched,
'removed' => $removed,
'dry_run' => $dryRun,
]);
return self::SUCCESS;
}
}
@@ -57,7 +57,7 @@ class RecalculateHeatCommand extends Command
$updatedCount = 0;
$skippedCount = 0;
// Process in chunks using artwork IDs that have at least one snapshot in the smoothing window
// Distinct IDs only — do not hydrate the full 24h snapshot window in one query.
$artworkIds = DB::table('artwork_metric_snapshots_hourly')
->whereBetween('bucket_hour', [$lookbackStart, $currentHour])
->distinct()
@@ -68,17 +68,25 @@ class RecalculateHeatCommand extends Command
return self::SUCCESS;
}
// Load all snapshots for the lookback window in bulk
foreach ($artworkIds->chunk($chunk) as $chunkIds) {
$snapshots = DB::table('artwork_metric_snapshots_hourly')
->select([
'artwork_id',
'bucket_hour',
'views_count',
'downloads_count',
'favourites_count',
'comments_count',
'shares_count',
])
->whereBetween('bucket_hour', [$lookbackStart, $currentHour])
->whereIn('artwork_id', $artworkIds)
->whereIn('artwork_id', $chunkIds)
->orderBy('bucket_hour')
->get()
->groupBy('artwork_id');
// Load artwork published_at dates for age factor (use published_at, fall back to created_at)
$artworkDates = DB::table('artworks')
->whereIn('id', $artworkIds)
->whereIn('id', $chunkIds)
->whereNull('deleted_at')
->where('is_approved', true)
->select('id', 'published_at', 'created_at')
@@ -87,8 +95,6 @@ class RecalculateHeatCommand extends Command
$row->id => \Carbon\Carbon::parse($row->published_at ?? $row->created_at),
]);
// Process in chunks
foreach ($artworkIds->chunk($chunk) as $chunkIds) {
$upsertRows = [];
foreach ($chunkIds as $artworkId) {
@@ -0,0 +1,139 @@
<?php
declare(strict_types=1);
namespace App\Console\Commands;
use Illuminate\Console\Command;
use Illuminate\Support\Facades\Log;
use Predis\Client as PredisClient;
class RedisCleanupLegacyPrefixCommand extends Command
{
protected $signature = 'skinbase:redis-cleanup-legacy-prefix
{--dry-run : SCAN and report only}
{--execute : UNLINK matching obsolete keys}
{--max-keys=500 : Cap keys this run}';
protected $description = 'UNLINK obsolete skinbasenova-database-* and skinbasenova_horizon:* keys only';
private const LEGACY_PREFIXES = [
'skinbasenova-database-',
'skinbasenova_horizon:',
];
private const PROTECTED_PREFIXES = [
'skinbase-database-',
'skinbase_horizon:',
];
public function handle(): int
{
$dryRun = (bool) $this->option('dry-run');
$execute = (bool) $this->option('execute');
if ($dryRun === $execute) {
$this->error('Pass exactly one of --dry-run or --execute.');
return self::FAILURE;
}
$maxKeys = max(1, (int) $this->option('max-keys'));
$currentPrefix = (string) config('database.redis.options.prefix');
$horizonPrefix = (string) config('horizon.prefix');
$this->info(sprintf(
'[redis-cleanup-legacy-prefix] current_prefix=%s horizon_prefix=%s max_keys=%d %s',
$currentPrefix,
$horizonPrefix,
$maxKeys,
$dryRun ? 'dry-run' : 'execute'
));
if (in_array($currentPrefix, self::LEGACY_PREFIXES, true) || in_array($horizonPrefix, self::LEGACY_PREFIXES, true)) {
$this->error('Current process still uses a legacy prefix. Aborting.');
return self::FAILURE;
}
$client = $this->unprefixedClient();
$found = [];
$cursor = '0';
do {
[$cursor, $keys] = $client->scan($cursor, ['COUNT' => 200, 'MATCH' => '*']);
foreach ($keys as $key) {
$key = (string) $key;
if ($this->isProtected($key)) {
continue;
}
if (! $this->isLegacy($key)) {
continue;
}
$found[] = $key;
if (count($found) >= $maxKeys) {
$cursor = '0';
break;
}
}
} while ($cursor !== '0' && $cursor !== 0);
$this->info('matched='.count($found));
foreach (array_slice($found, 0, 20) as $key) {
$this->line('key='.$key);
}
if (count($found) > 20) {
$this->line('... truncated listing');
}
$unlinked = 0;
if (! $dryRun && $found !== []) {
foreach (array_chunk($found, 50) as $chunk) {
$unlinked += (int) $client->unlink(...$chunk);
}
}
$this->info('unlinked='.$unlinked);
Log::info('[redis-cleanup-legacy-prefix] completed', [
'matched' => count($found),
'unlinked' => $unlinked,
'dry_run' => $dryRun,
]);
return self::SUCCESS;
}
private function isLegacy(string $key): bool
{
foreach (self::LEGACY_PREFIXES as $prefix) {
if (str_starts_with($key, $prefix)) {
return true;
}
}
return false;
}
private function isProtected(string $key): bool
{
foreach (self::PROTECTED_PREFIXES as $prefix) {
if (str_starts_with($key, $prefix)) {
return true;
}
}
return false;
}
private function unprefixedClient(): PredisClient
{
$redis = config('database.redis.default', []);
return new PredisClient([
'scheme' => 'tcp',
'host' => $redis['host'] ?? '127.0.0.1',
'port' => (int) ($redis['port'] ?? 6379),
'password' => $redis['password'] ?? null,
'database' => (int) ($redis['database'] ?? 0),
]);
}
}
@@ -0,0 +1,79 @@
<?php
declare(strict_types=1);
namespace App\Console\Commands;
use App\Support\Redis\OrphanQueueCleanup;
use Illuminate\Console\Command;
use Illuminate\Support\Facades\Log;
use RuntimeException;
class RedisCleanupOrphansCommand extends Command
{
protected $signature = 'skinbase:redis-cleanup-orphans
{target : forum-moderation, forum-security, or collections}
{--dry-run : Inspect and report without UNLINK}
{--execute : UNLINK the waiting queue and notify list}
{--force : Allow unexpected sampled job classes}';
protected $description = 'UNLINK an orphan Redis queue after producer and class checks (operator only)';
public function handle(OrphanQueueCleanup $cleanup): int
{
$dryRun = (bool) $this->option('dry-run');
$execute = (bool) $this->option('execute');
if ($dryRun === $execute) {
$this->error('Pass exactly one of --dry-run or --execute.');
return self::FAILURE;
}
$target = (string) $this->argument('target');
$force = (bool) $this->option('force');
$this->info(sprintf(
'[redis-cleanup-orphans] prefix=%s connection=default target=%s force=%s mode=%s',
(string) config('database.redis.options.prefix'),
$target,
$force ? 'yes' : 'no',
$dryRun ? 'dry-run' : 'execute'
));
try {
$plan = $execute
? $cleanup->execute($target, $force)
: $cleanup->plan($target, $force);
} catch (RuntimeException $e) {
$this->error($e->getMessage());
Log::warning('[redis-cleanup-orphans] refused', ['target' => $target, 'error' => $e->getMessage()]);
return self::FAILURE;
}
$this->line('logical_key='.$plan['logical_key']);
$this->line('notify_key='.$plan['notify_key']);
$this->line('llen='.$plan['llen'].' reserved='.$plan['reserved'].' delayed='.$plan['delayed']);
$this->line('sampled='.$plan['sampled'].' est_bytes='.$plan['est_bytes']);
$this->line('classes='.json_encode($plan['classes']));
if ($plan['unexpected_classes'] !== []) {
$this->warn('unexpected_classes='.json_encode($plan['unexpected_classes']));
}
if ($plan['errors'] !== []) {
$this->error('errors='.implode(',', $plan['errors']));
}
if ($execute) {
$this->info('unlinked='.($plan['unlinked'] ?? 0));
}
Log::info('[redis-cleanup-orphans] completed', [
'target' => $target,
'dry_run' => $dryRun,
'llen' => $plan['llen'],
'errors' => $plan['errors'],
'unlinked' => $plan['unlinked'] ?? 0,
]);
return ($plan['errors'] === [] || $dryRun) ? self::SUCCESS : self::FAILURE;
}
}
@@ -0,0 +1,83 @@
<?php
declare(strict_types=1);
namespace App\Console\Commands;
use App\Notifications\SecurityReportDangerNotification;
use App\Services\SecurityReport\SecurityReportScanner;
use Illuminate\Console\Command;
use Illuminate\Support\Facades\Notification;
final class SecurityReportScanCommand extends Command
{
protected $signature = 'security:scan
{--notify : Send configured email notification when high or critical findings exist}
{--triggered-by=artisan : Mark the scan source}
{--user-id= : Associate the scan with a specific user id}';
protected $description = 'Run Composer and npm security audits and store a private admin report.';
public function handle(SecurityReportScanner $scanner): int
{
if (! (bool) config('security-report.enabled', true)) {
$this->warn('Security report scanning is disabled.');
return self::INVALID;
}
$this->info('Running security report scan...');
$report = $scanner->scan(
(string) $this->option('triggered-by'),
$this->option('user-id') !== null ? (int) $this->option('user-id') : null,
);
if ($report->status === 'failed') {
$this->error('Security scan failed: ' . (string) ($report->error_message ?? 'Unknown error'));
return self::FAILURE;
}
$this->table(
['Status', 'Critical', 'High', 'Medium', 'Low', 'Unknown', 'Composer outdated', 'npm outdated'],
[[
$report->status,
$report->total_critical,
$report->total_high,
$report->total_medium,
$report->total_low,
$report->total_unknown,
$report->composer_outdated_count,
$report->npm_outdated_count,
]],
);
if ((bool) $this->option('notify') && $report->hasDangerFindings()) {
$this->sendDangerNotification($report);
$this->info('Danger notification sent.');
}
if ($report->hasCriticalFindings() && (bool) config('security-report.fail_on.critical', false)) {
return self::FAILURE;
}
if ($report->hasHighFindings() && (bool) config('security-report.fail_on.high', false)) {
return self::FAILURE;
}
return self::SUCCESS;
}
private function sendDangerNotification(\App\Models\SecurityReport $report): void
{
$email = trim((string) config('security-report.notify_email', ''));
if ($email === '') {
return;
}
Notification::route('mail', $email)
->notify(new SecurityReportDangerNotification($report));
}
}
@@ -0,0 +1,10 @@
<?php
namespace App\Contracts\Moderation;
use App\Data\Moderation\CommentSpamClassification;
interface CommentSpamClassifier
{
public function classify(string $content): CommentSpamClassification;
}
@@ -0,0 +1,15 @@
<?php
namespace App\Data\Moderation;
final class CommentSpamClassification
{
public function __construct(
public readonly bool $spam,
public readonly float $confidence,
public readonly string $reason,
public readonly string $provider,
public readonly string $model,
public readonly int $latencyMs,
) {}
}
@@ -363,8 +363,17 @@ final class AcademyBillingController extends Controller
/** @var User|null $user */
$user = $request->user();
$currentTier = $this->access->currentTier($user);
$seo = \app(SeoFactory::class)
->simplePage(
'Academy Subscription Confirmed — Skinbase',
'Payment confirmation for your Skinbase Academy subscription.',
\route('academy.billing.success'),
false,
)
->toArray();
return \Inertia\Inertia::render('Academy/Billing/Success', [
'seo' => $seo,
'message' => 'Payment is being confirmed. Your access will update automatically.',
'currentTier' => $currentTier,
'isSubscribed' => $user instanceof User ? $this->access->hasActiveAcademySubscription($user) : false,
@@ -381,8 +390,17 @@ final class AcademyBillingController extends Controller
public function cancel(): \Inertia\Response
{
\abort_unless((bool) \config('academy.enabled', true), 404);
$seo = \app(SeoFactory::class)
->simplePage(
'Academy Billing Canceled — Skinbase',
'Checkout was canceled before starting a Skinbase Academy subscription.',
\route('academy.billing.cancel'),
false,
)
->toArray();
return \Inertia\Inertia::render('Academy/Billing/Cancel', [
'seo' => $seo,
'message' => 'Checkout was canceled. No payment was made.',
'links' => [
'pricing' => \route('academy.pricing'),
@@ -495,10 +513,19 @@ final class AcademyBillingController extends Controller
/** @var User $user */
$user = $request->user();
$subscription = $this->academySubscription($user);
$seo = \app(SeoFactory::class)
->simplePage(
'Academy Subscription Account — Skinbase',
'Manage your Skinbase Academy subscription and billing access.',
\route('academy.billing.account'),
false,
)
->toArray();
$activePlan = $this->activePlan($user);
return \Inertia\Inertia::render('Academy/Billing/Account', [
'seo' => $seo,
'currentTier' => $this->access->currentTier($user),
'isSubscribed' => $this->access->hasActiveAcademySubscription($user),
'activePlan' => $activePlan ? [
@@ -10,6 +10,7 @@ use App\Services\Academy\AcademyAccessService;
use App\Services\Academy\AcademyInteractionService;
use App\Support\AcademyAnalytics\AcademyAnalyticsContentType;
use App\Support\Seo\SeoFactory;
use App\Support\Seo\SeoDataBuilder;
use Illuminate\Http\Request;
use Illuminate\Support\Str;
use Inertia\Inertia;
@@ -44,6 +45,13 @@ final class AcademyChallengeController extends Controller
route('academy.challenges.index'),
)
->toArray();
$seo = SeoDataBuilder::fromArray($seo)
->breadcrumbs([
['name' => 'Academy', 'url' => route('academy.index')],
['name' => 'Challenges', 'url' => route('academy.challenges.index')],
])
->build()
->toArray();
return Inertia::render('Academy/List', [
'pageType' => 'challenges',
@@ -94,12 +102,24 @@ final class AcademyChallengeController extends Controller
'submitted_at' => $submission->submitted_at?->toISOString(),
])->values()->all();
$seo = app(SeoFactory::class)->collectionPage(
$canonical = route('academy.challenges.show', ['slug' => $challenge->slug]);
$description = Str::limit((string) ($challenge->excerpt ?? $challenge->description ?? ''), 160, '...');
$seo = SeoDataBuilder::fromArray(
app(SeoFactory::class)->collectionPage(
$challenge->title . ' — Skinbase Academy',
Str::limit((string) ($challenge->excerpt ?? $challenge->description ?? ''), 160, '...'),
route('academy.challenges.show', ['slug' => $challenge->slug]),
$description,
$canonical,
$challenge->cover_image,
)->toArray();
)->toArray()
)
->breadcrumbs([
['name' => 'Academy', 'url' => route('academy.index')],
['name' => 'Challenges', 'url' => route('academy.challenges.index')],
['name' => (string) $challenge->title, 'url' => $canonical],
])
->addJsonLd($this->challengeStructuredData($payload, $canonical, $description))
->build()
->toArray();
$interaction = $this->interactions->getInteractionState($request->user(), AcademyAnalyticsContentType::CHALLENGE, (int) $challenge->id);
@@ -128,4 +148,46 @@ final class AcademyChallengeController extends Controller
],
])->rootView('academy');
}
/**
* @param array<string, mixed> $payload
* @return array<string, mixed>
*/
private function challengeStructuredData(array $payload, string $canonical, string $description): array
{
$image = trim((string) ($payload['cover_image'] ?? ''));
$imageUrl = $image !== '' && preg_match('/^https?:\/\//i', $image) === 1 ? $image : ($image !== '' ? url($image) : null);
$requiredTags = array_values((array) ($payload['required_tags'] ?? []));
$status = strtolower(trim((string) ($payload['status'] ?? '')));
$eventStatus = match ($status) {
'scheduled' => 'https://schema.org/EventScheduled',
'active', 'voting' => 'https://schema.org/EventInProgress',
'completed', 'archived' => 'https://schema.org/EventCompleted',
default => null,
};
return array_filter([
'@context' => 'https://schema.org',
'@type' => 'Event',
'name' => (string) ($payload['title'] ?? 'Skinbase Academy challenge'),
'description' => $description,
'url' => $canonical,
'image' => $imageUrl,
'startDate' => $payload['starts_at'] ?? null,
'endDate' => $payload['ends_at'] ?? null,
'eventStatus' => $eventStatus,
'eventAttendanceMode' => 'https://schema.org/OnlineEventAttendanceMode',
'location' => [
'@type' => 'VirtualLocation',
'url' => $canonical,
],
'organizer' => [
'@type' => 'Organization',
'name' => config('seo.site_name', 'Skinbase'),
'url' => url('/'),
],
'keywords' => $requiredTags !== [] ? $requiredTags : null,
'isAccessibleForFree' => (string) ($payload['access_level'] ?? 'free') === 'free',
], fn (mixed $value): bool => $value !== null && $value !== '' && $value !== []);
}
}
@@ -35,6 +35,8 @@ final class AcademyChallengeSubmissionController extends Controller
'Submit to ' . $challenge->title . ' — Skinbase Academy',
'Attach one of your artworks to this Academy challenge submission.',
route('academy.challenges.submit', ['slug' => $challenge->slug]),
null,
false,
)->toArray();
return Inertia::render('Academy/ChallengeSubmit', [
@@ -14,6 +14,7 @@ use App\Services\Academy\AcademyCourseNavigationService;
use App\Services\Academy\AcademyCourseProgressService;
use App\Support\AcademyAnalytics\AcademyAnalyticsContentType;
use App\Support\Seo\SeoFactory;
use App\Support\Seo\SeoDataBuilder;
use Illuminate\Http\Request;
use Inertia\Inertia;
use Inertia\Response;
@@ -37,6 +38,7 @@ final class AcademyCourseController extends Controller
'difficulty' => ['nullable', 'string', 'max:40'],
'access' => ['nullable', 'string', 'max:40'],
]);
$hasActiveFilters = filled($filters['difficulty'] ?? null) || filled($filters['access'] ?? null);
$query = AcademyCourse::query()->published()->ordered();
@@ -77,6 +79,13 @@ final class AcademyCourseController extends Controller
)
->toArray();
if ($hasActiveFilters) {
$seo = SeoDataBuilder::fromArray($seo)
->indexable(false)
->build()
->toArray();
}
return Inertia::render('Academy/CoursesIndex', [
'seo' => $seo,
'title' => 'Academy courses',
@@ -13,6 +13,7 @@ use App\Services\Academy\AcademyCourseNavigationService;
use App\Services\Academy\AcademyCourseProgressService;
use App\Support\AcademyAnalytics\AcademyAnalyticsContentType;
use App\Support\Seo\SeoFactory;
use App\Support\Seo\SeoDataBuilder;
use Illuminate\Support\Str;
use Illuminate\Http\Request;
use Inertia\Inertia;
@@ -52,7 +53,7 @@ final class AcademyCourseLessonController extends Controller
->all();
$payload = $this->access->courseLessonPayload($courseLesson, $request->user(), true);
$canonical = route('academy.courses.lessons.show', ['course' => $course->slug, 'lesson' => $lesson->slug]);
$canonical = route('academy.lessons.show', ['slug' => $lesson->slug]);
$description = Str::limit(trim((string) ($lesson->seo_description ?? $lesson->excerpt ?? 'Skinbase Academy course lesson.')), 160, '...');
$seo = app(SeoFactory::class)->academyLessonPage(
(string) ($lesson->seo_title ?? ($lesson->title . ' — ' . $course->title)),
@@ -70,6 +71,10 @@ final class AcademyCourseLessonController extends Controller
$lesson->updated_at?->toAtomString(),
(string) $course->title,
)->toArray();
$seo = SeoDataBuilder::fromArray($seo)
->indexable(false)
->build()
->toArray();
$interaction = $this->interactions->getInteractionState($request->user(), AcademyAnalyticsContentType::LESSON, (int) $lesson->id);
@@ -13,6 +13,7 @@ use App\Services\Academy\AcademyCacheService;
use App\Services\Academy\AcademyInteractionService;
use App\Support\AcademyAnalytics\AcademyAnalyticsContentType;
use App\Support\Seo\SeoFactory;
use App\Support\Seo\SeoDataBuilder;
use Illuminate\Http\JsonResponse;
use Illuminate\Http\Request;
use Illuminate\Support\Str;
@@ -37,6 +38,9 @@ final class AcademyLessonController extends Controller
'category' => ['nullable', 'string', 'max:140'],
'difficulty' => ['nullable', 'string', 'max:40'],
]);
$hasActiveFilters = filled($filters['q'] ?? null)
|| filled($filters['category'] ?? null)
|| filled($filters['difficulty'] ?? null);
$query = AcademyLesson::query()
->with('category')
@@ -78,6 +82,13 @@ final class AcademyLessonController extends Controller
)
->toArray();
if ($hasActiveFilters) {
$seo = SeoDataBuilder::fromArray($seo)
->indexable(false)
->build()
->toArray();
}
return Inertia::render('Academy/List', [
'pageType' => 'lessons',
'title' => 'Academy lessons',
@@ -13,6 +13,7 @@ use App\Services\Academy\AcademyInteractionService;
use App\Services\Academy\AcademyPopularityService;
use App\Support\AcademyAnalytics\AcademyAnalyticsContentType;
use App\Support\Seo\SeoFactory;
use App\Support\Seo\SeoDataBuilder;
use Illuminate\Http\Request;
use Illuminate\Http\JsonResponse;
use Illuminate\Support\Str;
@@ -41,6 +42,10 @@ final class AcademyPromptController extends Controller
'difficulty' => ['nullable', 'string', 'max:40'],
'tag' => ['nullable', 'string', 'max:60'],
]);
$hasActiveFilters = filled($filters['q'] ?? null)
|| filled($filters['category'] ?? null)
|| filled($filters['difficulty'] ?? null)
|| filled($filters['tag'] ?? null);
$query = AcademyPromptTemplate::query()
->with('category')
@@ -87,6 +92,13 @@ final class AcademyPromptController extends Controller
)
->toArray();
if ($hasActiveFilters) {
$seo = SeoDataBuilder::fromArray($seo)
->indexable(false)
->build()
->toArray();
}
return Inertia::render('Academy/List', [
'pageType' => 'prompts',
'promptView' => 'library',
@@ -203,6 +215,13 @@ final class AcademyPromptController extends Controller
)
->toArray();
if ($selectedPeriod['value'] !== '30d') {
$seo = SeoDataBuilder::fromArray($seo)
->indexable(false)
->build()
->toArray();
}
return Inertia::render('Academy/List', [
'pageType' => 'prompts',
'promptView' => 'popular',
@@ -10,6 +10,7 @@ use App\Services\Academy\AcademyAccessService;
use App\Services\Academy\AcademyInteractionService;
use App\Support\AcademyAnalytics\AcademyAnalyticsContentType;
use App\Support\Seo\SeoFactory;
use App\Support\Seo\SeoDataBuilder;
use Illuminate\Http\Request;
use Illuminate\Support\Str;
use Inertia\Inertia;
@@ -44,6 +45,13 @@ final class AcademyPromptPackController extends Controller
route('academy.packs.index'),
)
->toArray();
$seo = SeoDataBuilder::fromArray($seo)
->breadcrumbs([
['name' => 'Academy', 'url' => route('academy.index')],
['name' => 'Prompt Packs', 'url' => route('academy.packs.index')],
])
->build()
->toArray();
return Inertia::render('Academy/List', [
'pageType' => 'packs',
@@ -79,12 +87,24 @@ final class AcademyPromptPackController extends Controller
->firstOrFail();
$payload = $this->access->packPayload($pack, $request->user(), true);
$seo = app(SeoFactory::class)->collectionPage(
$canonical = route('academy.packs.show', ['slug' => $pack->slug]);
$description = Str::limit((string) ($pack->excerpt ?? $pack->description ?? ''), 160, '...');
$seo = SeoDataBuilder::fromArray(
app(SeoFactory::class)->collectionPage(
$pack->title . ' — Skinbase Academy',
Str::limit((string) ($pack->excerpt ?? $pack->description ?? ''), 160, '...'),
route('academy.packs.show', ['slug' => $pack->slug]),
$description,
$canonical,
$pack->cover_image,
)->toArray();
)->toArray()
)
->breadcrumbs([
['name' => 'Academy', 'url' => route('academy.index')],
['name' => 'Prompt Packs', 'url' => route('academy.packs.index')],
['name' => (string) $pack->title, 'url' => $canonical],
])
->addJsonLd($this->packStructuredData($payload, $canonical, $description))
->build()
->toArray();
$interaction = $this->interactions->getInteractionState($request->user(), AcademyAnalyticsContentType::PROMPT_PACK, (int) $pack->id);
@@ -112,4 +132,58 @@ final class AcademyPromptPackController extends Controller
],
])->rootView('academy');
}
/**
* @param array<string, mixed> $payload
* @return array<string, mixed>
*/
private function packStructuredData(array $payload, string $canonical, string $description): array
{
$image = trim((string) ($payload['cover_image'] ?? ''));
$imageUrl = $image !== '' && preg_match('/^https?:\/\//i', $image) === 1 ? $image : ($image !== '' ? url($image) : null);
$keywords = array_values((array) ($payload['tags'] ?? []));
$isFree = (string) ($payload['access_level'] ?? 'free') === 'free';
$promptEntries = collect((array) ($payload['prompts'] ?? []))
->map(function (array $prompt): ?array {
$title = trim((string) ($prompt['title'] ?? ''));
$slug = trim((string) ($prompt['slug'] ?? ''));
if ($title === '' || $slug === '') {
return null;
}
return [
'@type' => 'ListItem',
'position' => null,
'item' => [
'@type' => 'CreativeWork',
'name' => $title,
'url' => route('academy.prompts.show', ['slug' => $slug]),
],
];
})
->filter()
->values()
->map(function (array $item, int $index): array {
$item['position'] = $index + 1;
return $item;
})
->all();
return array_filter([
'@context' => 'https://schema.org',
'@type' => ['CreativeWork', 'LearningResource'],
'name' => (string) ($payload['title'] ?? 'Skinbase Academy prompt pack'),
'description' => $description,
'url' => $canonical,
'image' => $imageUrl,
'keywords' => $keywords !== [] ? $keywords : null,
'isAccessibleForFree' => $isFree,
'hasPart' => $promptEntries !== [] ? [
'@type' => 'ItemList',
'itemListElement' => $promptEntries,
] : null,
], fn (mixed $value): bool => $value !== null && $value !== '' && $value !== []);
}
}
@@ -0,0 +1,266 @@
<?php
declare(strict_types=1);
namespace App\Http\Controllers\Admin;
use App\Http\Controllers\Controller;
use App\Jobs\SyncAdsenseJob;
use App\Models\AdsenseConnection;
use App\Services\Adsense\AdsenseAnalyticsQueryService;
use App\Services\Adsense\AdsenseApiClient;
use App\Services\Adsense\AdsenseLogSanitizer;
use App\Services\Adsense\AdsenseOAuthService;
use App\Services\Adsense\Exceptions\AdsenseApiException;
use App\Services\Adsense\Exceptions\AdsenseAuthorizationException;
use App\Services\Adsense\Exceptions\AdsenseOAuthException;
use Illuminate\Http\RedirectResponse;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Log;
use Inertia\Inertia;
use Inertia\Response;
final class AdsenseAnalyticsController extends Controller
{
public function __construct(
private readonly AdsenseOAuthService $oauth,
private readonly AdsenseApiClient $api,
private readonly AdsenseAnalyticsQueryService $query,
) {}
public function index(Request $request): Response
{
$connection = AdsenseConnection::current();
$range = $this->query->resolveRange(
$request->query('period'),
$request->string('from')->toString() ?: null,
$request->string('to')->toString() ?: null,
);
$dashboard = null;
if ($connection !== null && $connection->isConnected() && filled($connection->account_resource_name)) {
$dashboard = $this->query->dashboard(
$connection,
$range['from'],
$range['to'],
$range['previous_from'],
$range['previous_to'],
);
}
return Inertia::render('Admin/Adsense/Index', [
'connection' => $this->connectionPayload($connection),
'configured' => $this->oauth->isConfigured(),
'pendingAccounts' => $request->session()->get(AdsenseOAuthService::SESSION_PENDING_ACCOUNTS_KEY, []),
'recommendedPlacements' => array_values((array) config('adsense.recommended_placement_names', [])),
'range' => [
'period' => $range['period'],
'from' => $range['from']->toDateString(),
'to' => $range['to']->toDateString(),
'previous_from' => $range['previous_from']->toDateString(),
'previous_to' => $range['previous_to']->toDateString(),
],
'dashboard' => $dashboard,
'routes' => [
'index' => route('admin.adsense.index'),
'connect' => route('admin.adsense.connect'),
'account' => route('admin.adsense.account'),
'sync' => route('admin.adsense.sync'),
'disconnect' => route('admin.adsense.disconnect'),
],
]);
}
public function connect(Request $request): RedirectResponse
{
if (! $this->oauth->isConfigured()) {
return redirect()
->route('admin.adsense.index')
->with('error', 'Google AdSense OAuth is not configured.');
}
try {
return redirect()->away($this->oauth->authorizationUrl($request, true));
} catch (AdsenseOAuthException $exception) {
return redirect()
->route('admin.adsense.index')
->with('error', $exception->getMessage());
}
}
public function callback(Request $request): RedirectResponse
{
try {
$code = $this->oauth->assertValidCallback($request);
$tokens = $this->oauth->exchangeAuthorizationCode($code);
$connection = AdsenseConnection::current() ?? new AdsenseConnection;
$connection->status = AdsenseConnection::STATUS_PENDING;
$this->oauth->persistTokens($connection, $tokens, $request->user()?->id);
$accounts = $this->api->listAccounts($connection);
} catch (AdsenseOAuthException|AdsenseAuthorizationException|AdsenseApiException $exception) {
Log::warning('AdSense OAuth callback failed.', AdsenseLogSanitizer::context([
'message' => $exception->getMessage(),
]));
return redirect()
->route('admin.adsense.index')
->with('error', $exception->getMessage());
}
$normalized = collect($accounts)
->map(function (array $account): ?array {
$name = (string) ($account['name'] ?? '');
if ($name === '') {
return null;
}
return [
'resource_name' => $name,
'display_name' => (string) ($account['displayName'] ?? $name),
];
})
->filter()
->values()
->all();
if ($normalized === []) {
$connection->status = AdsenseConnection::STATUS_ERROR;
$connection->last_error = 'No Google AdSense accounts were available for this Google account.';
$connection->save();
$request->session()->forget(AdsenseOAuthService::SESSION_PENDING_ACCOUNTS_KEY);
return redirect()
->route('admin.adsense.index')
->with('error', $connection->last_error);
}
if (count($normalized) === 1) {
$this->assignAccount($connection, $normalized[0]['resource_name'], $normalized[0]['display_name']);
$this->queueAdsenseSync($connection, 30);
$request->session()->forget(AdsenseOAuthService::SESSION_PENDING_ACCOUNTS_KEY);
return redirect()
->route('admin.adsense.index')
->with('success', 'Google AdSense connected. Initial synchronization has started.');
}
$request->session()->put(AdsenseOAuthService::SESSION_PENDING_ACCOUNTS_KEY, $normalized);
$connection->status = AdsenseConnection::STATUS_PENDING;
$connection->save();
return redirect()
->route('admin.adsense.index')
->with('warning', 'Select the Google AdSense account to use for Skinbase analytics.');
}
public function selectAccount(Request $request): RedirectResponse
{
$validated = $request->validate([
'account_resource_name' => ['required', 'string', 'max:128'],
]);
$connection = AdsenseConnection::current();
if ($connection === null || ! $connection->hasRefreshToken()) {
return redirect()
->route('admin.adsense.index')
->with('error', 'Connect Google AdSense before selecting an account.');
}
$pending = collect($request->session()->get(AdsenseOAuthService::SESSION_PENDING_ACCOUNTS_KEY, []));
$selected = $pending->firstWhere('resource_name', $validated['account_resource_name']);
if (! is_array($selected)) {
return redirect()
->route('admin.adsense.index')
->with('error', 'The selected AdSense account is not available.');
}
$this->assignAccount(
$connection,
(string) $selected['resource_name'],
(string) ($selected['display_name'] ?? $selected['resource_name']),
);
$this->queueAdsenseSync($connection, 30);
$request->session()->forget(AdsenseOAuthService::SESSION_PENDING_ACCOUNTS_KEY);
return redirect()
->route('admin.adsense.index')
->with('success', 'AdSense account selected. Initial synchronization has started.');
}
public function sync(Request $request): RedirectResponse
{
$connection = AdsenseConnection::current();
if ($connection === null || ! $connection->isConnected()) {
return redirect()
->route('admin.adsense.index')
->with('error', $connection?->needsReconnect()
? 'AdSense authorization expired or was revoked. Reconnect Google AdSense.'
: 'Google AdSense is not connected.');
}
$this->queueAdsenseSync($connection, 3);
return redirect()
->route('admin.adsense.index')
->with('success', 'AdSense synchronization has been queued.');
}
public function disconnect(): RedirectResponse
{
$connection = AdsenseConnection::current();
if ($connection !== null) {
$this->oauth->disconnect($connection);
}
return redirect()
->route('admin.adsense.index')
->with('success', 'Google AdSense has been disconnected. Historical statistics were kept.');
}
/**
* @return array<string, mixed>|null
*/
private function connectionPayload(?AdsenseConnection $connection): ?array
{
if ($connection === null) {
return null;
}
return [
'status' => $connection->status,
'account_resource_name' => $connection->account_resource_name,
'account_display_name' => $connection->account_display_name,
'connected_at' => optional($connection->connected_at)?->toIso8601String(),
'last_sync_attempt_at' => optional($connection->last_sync_attempt_at)?->toIso8601String(),
'last_successful_sync_at' => optional($connection->last_successful_sync_at)?->toIso8601String(),
'last_error' => $connection->last_error,
'needs_reconnect' => $connection->needsReconnect(),
];
}
private function assignAccount(AdsenseConnection $connection, string $resourceName, string $displayName): void
{
$connection->account_resource_name = $resourceName;
$connection->account_display_name = $displayName;
$connection->status = AdsenseConnection::STATUS_CONNECTED;
$connection->last_error = null;
if ($connection->connected_at === null) {
$connection->connected_at = now();
}
$connection->save();
}
private function queueAdsenseSync(AdsenseConnection $connection, int $days): void
{
$to = now()->startOfDay();
$from = $to->copy()->subDays(max(1, $days) - 1);
SyncAdsenseJob::dispatch(
(int) $connection->id,
$from->toDateString(),
$to->toDateString(),
);
}
}
@@ -0,0 +1,130 @@
<?php
declare(strict_types=1);
namespace App\Http\Controllers\Admin;
use App\Http\Controllers\Controller;
use App\Jobs\RunSecurityReportScanJob;
use App\Models\SecurityReport;
use Illuminate\Http\RedirectResponse;
use Illuminate\Http\Request;
use Inertia\Inertia;
use Inertia\Response;
final class SecurityReportController extends Controller
{
public function index(): Response
{
abort_unless((bool) config('security-report.enabled', true), 404);
$latest = SecurityReport::query()->latest('id')->with('user:id,name,username')->first();
$reports = SecurityReport::query()
->with('user:id,name,username')
->latest('id')
->paginate(20)
->through(fn (SecurityReport $report): array => $this->mapListItem($report));
return Inertia::render('Admin/System/SecurityReportIndex', [
'latest' => $latest ? $this->mapDetail($latest) : null,
'reports' => $reports,
'canRunScan' => true,
])->rootView('moderation');
}
public function show(SecurityReport $securityReport): Response
{
abort_unless((bool) config('security-report.enabled', true), 404);
$securityReport->load('user:id,name,username');
return Inertia::render('Admin/System/SecurityReportShow', [
'report' => $this->mapDetail($securityReport),
])->rootView('moderation');
}
public function run(Request $request): RedirectResponse
{
abort_unless((bool) config('security-report.enabled', true), 404);
RunSecurityReportScanJob::dispatch($request->user()?->id);
return redirect()
->route('admin.system.security-report.index')
->with('success', 'Security scan has been queued.');
}
/**
* @return array<string, mixed>
*/
private function mapListItem(SecurityReport $report): array
{
return [
'id' => (int) $report->id,
'status' => (string) $report->status,
'risk_label' => (string) $report->risk_label,
'finished_at' => optional($report->finished_at)?->toIso8601String(),
'total_critical' => (int) $report->total_critical,
'total_high' => (int) $report->total_high,
'total_medium' => (int) $report->total_medium,
'total_low' => (int) $report->total_low,
'composer_outdated_count' => (int) $report->composer_outdated_count,
'npm_outdated_count' => (int) $report->npm_outdated_count,
'show_url' => route('admin.system.security-report.show', ['securityReport' => $report]),
'triggered_by' => (string) ($report->triggered_by ?? ''),
'user' => $report->user ? [
'id' => (int) $report->user->id,
'name' => (string) $report->user->name,
'username' => (string) ($report->user->username ?? ''),
] : null,
];
}
/**
* @return array<string, mixed>
*/
private function mapDetail(SecurityReport $report): array
{
return [
'id' => (int) $report->id,
'status' => (string) $report->status,
'risk_label' => (string) $report->risk_label,
'started_at' => optional($report->started_at)?->toIso8601String(),
'finished_at' => optional($report->finished_at)?->toIso8601String(),
'composer_critical' => (int) $report->composer_critical,
'composer_high' => (int) $report->composer_high,
'composer_medium' => (int) $report->composer_medium,
'composer_low' => (int) $report->composer_low,
'composer_unknown' => (int) $report->composer_unknown,
'npm_critical' => (int) $report->npm_critical,
'npm_high' => (int) $report->npm_high,
'npm_moderate' => (int) $report->npm_moderate,
'npm_low' => (int) $report->npm_low,
'npm_info' => (int) $report->npm_info,
'npm_unknown' => (int) $report->npm_unknown,
'total_critical' => (int) $report->total_critical,
'total_high' => (int) $report->total_high,
'total_medium' => (int) $report->total_medium,
'total_low' => (int) $report->total_low,
'total_unknown' => (int) $report->total_unknown,
'composer_outdated_count' => (int) $report->composer_outdated_count,
'npm_outdated_count' => (int) $report->npm_outdated_count,
'summary' => $report->summary ?? [],
'triggered_by' => (string) ($report->triggered_by ?? ''),
'error_message' => (string) ($report->error_message ?? ''),
'show_url' => route('admin.system.security-report.show', ['securityReport' => $report]),
'index_url' => route('admin.system.security-report.index'),
'composer_audit' => $report->composer_audit,
'composer_outdated' => $report->composer_outdated,
'npm_audit' => $report->npm_audit,
'npm_outdated' => $report->npm_outdated,
'composer_advisories' => $report->composerAdvisories(),
'npm_vulnerabilities' => $report->npmVulnerabilities(),
'user' => $report->user ? [
'id' => (int) $report->user->id,
'name' => (string) $report->user->name,
'username' => (string) ($report->user->username ?? ''),
] : null,
];
}
}
@@ -0,0 +1,130 @@
<?php
declare(strict_types=1);
namespace App\Http\Controllers\Api\Admin;
use App\Http\Controllers\Controller;
use App\Jobs\IndexArtworkJob;
use App\Models\Artwork;
use App\Services\NotificationService;
use Illuminate\Http\JsonResponse;
use Illuminate\Http\Request;
use Symfony\Component\HttpFoundation\Response;
final class ArtworkModerationController extends Controller
{
public function pending(): JsonResponse
{
$artworks = Artwork::query()
->with([
'user:id,name,username,level,email',
'tags:id,name,slug',
'categories:id,name,slug',
])
->where('artwork_status', 'review')
->where('is_approved', false)
->latest('created_at')
->limit(100)
->get([
'id', 'user_id', 'title', 'description', 'hash', 'thumb_ext',
'artwork_status', 'moderation_note', 'created_at', 'slug',
'is_mature', 'maturity_status', 'visibility',
])
->map(fn (Artwork $artwork): array => $this->present($artwork))
->values();
return response()->json(['data' => $artworks], Response::HTTP_OK);
}
public function approve(int $id, Request $request, NotificationService $notifications): JsonResponse
{
$artwork = Artwork::query()->with('user')->where('artwork_status', 'review')->find($id);
if (! $artwork) {
return response()->json(['message' => 'Artwork not found in review queue.'], Response::HTTP_NOT_FOUND);
}
$artwork->forceFill([
'is_approved' => true,
'is_public' => $artwork->visibility !== Artwork::VISIBILITY_PRIVATE,
'artwork_status' => 'published',
'published_at' => now(),
'approval_source' => 'moderator',
'moderated_at' => now(),
'moderated_by' => $request->user()->id,
'moderation_note' => $request->input('note'),
])->save();
IndexArtworkJob::dispatch((int) $artwork->id);
if ($artwork->user) {
$notifications->notifyArtworkApproved($artwork->user, $request->user(), $artwork);
}
return response()->json(['success' => true, 'id' => $artwork->id, 'status' => 'published']);
}
public function reject(int $id, Request $request, NotificationService $notifications): JsonResponse
{
$artwork = Artwork::query()->with('user')->where('artwork_status', 'review')->find($id);
if (! $artwork) {
return response()->json(['message' => 'Artwork not found in review queue.'], Response::HTTP_NOT_FOUND);
}
$note = (string) $request->input('note', 'Rejected during upload moderation.');
$artwork->forceFill([
'is_approved' => false,
'is_public' => false,
'artwork_status' => 'rejected',
'published_at' => null,
'moderated_at' => now(),
'moderated_by' => $request->user()->id,
'moderation_note' => $note,
])->save();
IndexArtworkJob::dispatch((int) $artwork->id);
if ($artwork->user) {
$notifications->notifyArtworkRejected($artwork->user, $request->user(), $artwork, $note);
}
return response()->json(['success' => true, 'id' => $artwork->id, 'status' => 'rejected']);
}
private function present(Artwork $artwork): array
{
$previewUrl = $artwork->thumbUrl('md') ?: $artwork->thumbUrl('sm');
$previewLgUrl = $artwork->thumbUrl('lg') ?: $previewUrl;
return [
'id' => (int) $artwork->id,
'title' => (string) ($artwork->title ?: '(untitled artwork)'),
'description' => (string) ($artwork->description ?? ''),
'type' => 'artwork',
'preview_url' => $previewUrl,
'preview_lg_url' => $previewLgUrl,
'tags' => $artwork->tags
->map(fn ($tag): string => trim((string) ($tag->name ?: $tag->slug)))
->filter()
->values()
->all(),
'categories' => $artwork->categories
->map(fn ($category): string => trim((string) ($category->name ?: $category->slug)))
->filter()
->values()
->all(),
'user' => $artwork->user ? [
'id' => (int) $artwork->user->id,
'name' => (string) $artwork->user->name,
'username' => $artwork->user->username,
] : null,
'slug' => $artwork->slug,
'is_mature' => (bool) $artwork->is_mature,
'maturity_status' => $artwork->maturity_status,
'visibility' => $artwork->visibility,
'moderation_note' => $artwork->moderation_note,
'created_at' => optional($artwork->created_at)?->toISOString(),
];
}
}
@@ -8,33 +8,51 @@ use App\Http\Controllers\Controller;
use App\Models\Upload;
use Illuminate\Http\JsonResponse;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Storage;
use Illuminate\Support\Facades\URL;
use Symfony\Component\HttpFoundation\Response;
use Symfony\Component\HttpFoundation\StreamedResponse;
final class UploadModerationController extends Controller
{
public function pending(): JsonResponse
{
$uploads = Upload::query()
->with(['user:id,name,username', 'category:id,name,slug'])
->where('status', 'draft')
->where('moderation_status', 'pending')
->orderBy('created_at')
->get([
'id',
'user_id',
'type',
'status',
'processing_state',
'title',
'preview_path',
'created_at',
'moderation_status',
]);
->get()
->map(fn (Upload $upload): array => $this->present($upload))
->values();
return response()->json([
'data' => $uploads,
], Response::HTTP_OK);
}
public function preview(string $id): StreamedResponse|JsonResponse
{
$upload = Upload::query()
->where('status', 'draft')
->where('moderation_status', 'pending')
->find($id);
if (! $upload) {
return response()->json(['message' => 'Upload not found.'], Response::HTTP_NOT_FOUND);
}
$path = $this->safePreviewPath($upload);
if ($path === null || ! Storage::disk('local')->exists($path)) {
return response()->json(['message' => 'Preview not found.'], Response::HTTP_NOT_FOUND);
}
return Storage::disk('local')->response($path, 'preview.webp', [
'Content-Type' => 'image/webp',
'Cache-Control' => 'private, max-age=120',
]);
}
public function approve(string $id, Request $request): JsonResponse
{
$upload = Upload::query()->find($id);
@@ -80,4 +98,56 @@ final class UploadModerationController extends Controller
'moderation_status' => (string) $upload->moderation_status,
], Response::HTTP_OK);
}
private function present(Upload $upload): array
{
$tags = collect($upload->tags ?? [])
->map(function (mixed $tag): string {
if (is_array($tag)) {
return trim((string) ($tag['name'] ?? $tag['slug'] ?? ''));
}
return trim((string) $tag);
})
->filter()
->values()
->all();
$hasPreview = $this->safePreviewPath($upload) !== null;
return [
'id' => (string) $upload->id,
'title' => (string) ($upload->title ?: '(untitled upload)'),
'description' => (string) ($upload->description ?? ''),
'type' => (string) ($upload->type ?? 'image'),
'preview_url' => $hasPreview
? URL::temporarySignedRoute('api.admin.uploads.preview', now()->addMinutes(30), ['id' => $upload->id])
: null,
'preview_lg_url' => $hasPreview
? URL::temporarySignedRoute('api.admin.uploads.preview', now()->addMinutes(30), ['id' => $upload->id])
: null,
'tags' => $tags,
'categories' => $upload->category?->name ? [(string) $upload->category->name] : [],
'user' => $upload->user ? [
'id' => (int) $upload->user->id,
'name' => (string) $upload->user->name,
'username' => $upload->user->username,
] : null,
'nsfw' => (bool) $upload->nsfw,
'license' => $upload->license,
'created_at' => optional($upload->created_at)?->toISOString(),
];
}
private function safePreviewPath(Upload $upload): ?string
{
$path = str_replace('\\', '/', ltrim((string) $upload->preview_path, '/'));
$expectedPrefix = 'tmp/drafts/'.$upload->id.'/';
if ($path === '' || str_contains($path, '..') || ! str_starts_with($path, $expectedPrefix)) {
return null;
}
return $path;
}
}
@@ -3,14 +3,17 @@
namespace App\Http\Controllers\Api;
use App\Http\Controllers\Controller;
use App\Services\Activity\UserActivityService;
use App\Models\ActivityEvent;
use App\Models\Artwork;
use App\Models\ArtworkComment;
use App\Models\User;
use App\Models\UserMention;
use App\Notifications\ArtworkCommentedNotification;
use App\Notifications\ArtworkMentionedNotification;
use App\Services\Activity\UserActivityService;
use App\Services\CommentReactionService;
use App\Services\ContentSanitizer;
use App\Services\Moderation\CommentSpamService;
use App\Support\AvatarUrl;
use Carbon\Carbon;
use Illuminate\Http\JsonResponse;
@@ -30,6 +33,11 @@ class ArtworkCommentController extends Controller
{
private const MAX_LENGTH = 10_000;
public function __construct(
private readonly CommentReactionService $commentReactions,
private readonly CommentSpamService $commentSpam,
) {}
// ─────────────────────────────────────────────────────────────────────────
// List
// ─────────────────────────────────────────────────────────────────────────
@@ -53,7 +61,9 @@ class ArtworkCommentController extends Controller
->paginate($perPage, ['*'], 'page', $page);
$userId = $request->user()?->id;
$items = $comments->getCollection()->map(fn ($c) => $this->formatComment($c, $userId, true));
$commentIds = $this->commentIds($comments->getCollection());
$reactionTotals = $this->commentReactions->forComments($commentIds, $userId);
$items = $comments->getCollection()->map(fn ($c) => $this->formatComment($c, $userId, true, $reactionTotals));
return response()->json([
'data' => $items,
@@ -110,35 +120,48 @@ class ArtworkCommentController extends Controller
'content' => $raw, // legacy column (plain text fallback)
'raw_content' => $raw,
'rendered_content' => $rendered,
'is_approved' => true, // auto-approve; extend with moderation as needed
'is_approved' => true,
]);
$moderation = $this->commentSpam->moderate($comment, $request->user());
// Bust the comments cache for this user's 'all' feed
Cache::forget('comments.latest.all.page1');
$comment->load(['user', 'user.profile']);
if ($comment->is_approved) {
$this->notifyRecipients($artwork, $comment, $request->user(), $parentId ? (int) $parentId : null);
}
// Record activity event (fire-and-forget; never break the response)
try {
\App\Models\ActivityEvent::record(
ActivityEvent::record(
actorId: $request->user()->id,
type: \App\Models\ActivityEvent::TYPE_COMMENT,
targetType: \App\Models\ActivityEvent::TARGET_ARTWORK,
type: ActivityEvent::TYPE_COMMENT,
targetType: ActivityEvent::TARGET_ARTWORK,
targetId: $artwork->id,
);
} catch (\Throwable) {}
} catch (\Throwable) {
}
try {
if ($comment->is_approved) {
app(UserActivityService::class)->logComment(
(int) $request->user()->id,
(int) $comment->id,
$parentId !== null,
['artwork_id' => (int) $artwork->id],
);
} catch (\Throwable) {}
}
} catch (\Throwable) {
}
return response()->json(['data' => $this->formatComment($comment, $request->user()->id, false)], 201);
$reactionTotals = $this->commentReactions->forComments([$comment->id], $request->user()->id);
return response()->json([
'data' => $this->formatComment($comment, $request->user()->id, false, $reactionTotals),
'moderation' => ['status' => $moderation['status']],
], 201);
}
// ─────────────────────────────────────────────────────────────────────────
@@ -197,7 +220,7 @@ class ArtworkCommentController extends Controller
// Helpers
// ─────────────────────────────────────────────────────────────────────────
private function formatComment(ArtworkComment $c, ?int $currentUserId, bool $includeReplies = false): array
private function formatComment(ArtworkComment $c, ?int $currentUserId, bool $includeReplies = false, array $reactionTotals = []): array
{
$user = $c->user;
$userId = (int) ($c->user_id ?? 0);
@@ -221,12 +244,13 @@ class ArtworkCommentController extends Controller
'level' => (int) ($user?->level ?? 1),
'rank' => (string) ($user?->rank ?? 'Newbie'),
],
'reactions' => $reactionTotals[(int) $c->id] ?? [],
];
if ($includeReplies && $c->relationLoaded('approvedReplies')) {
$data['replies'] = $c->approvedReplies->map(fn ($r) => $this->formatComment($r, $currentUserId, true))->values()->toArray();
$data['replies'] = $c->approvedReplies->map(fn ($r) => $this->formatComment($r, $currentUserId, true, $reactionTotals))->values()->toArray();
} elseif ($includeReplies && $c->relationLoaded('replies')) {
$data['replies'] = $c->replies->map(fn ($r) => $this->formatComment($r, $currentUserId, true))->values()->toArray();
$data['replies'] = $c->replies->map(fn ($r) => $this->formatComment($r, $currentUserId, true, $reactionTotals))->values()->toArray();
} else {
$data['replies'] = [];
}
@@ -234,6 +258,24 @@ class ArtworkCommentController extends Controller
return $data;
}
/** @param iterable<int, ArtworkComment> $comments */
private function commentIds(iterable $comments): array
{
$ids = [];
$walk = function (iterable $items) use (&$walk, &$ids): void {
foreach ($items as $comment) {
$ids[] = (int) $comment->id;
if ($comment->relationLoaded('approvedReplies')) {
$walk($comment->approvedReplies);
}
}
};
$walk($comments);
return array_values(array_unique($ids));
}
private function renderCommentContent(ArtworkComment $comment): string
{
$rawContent = (string) ($comment->raw_content ?? $comment->content ?? '');
@@ -1,13 +1,14 @@
<?php
namespace App\Http\Controllers\Api;
use App\Http\Controllers\Controller;
use App\Http\Requests\Artworks\ArtworkCreateRequest;
use App\Http\Resources\ArtworkListResource;
use App\Http\Resources\ArtworkResource;
use App\Services\ArtworkService;
use App\Services\Artworks\ArtworkDraftService;
use App\Models\Category;
use App\Services\Artworks\ArtworkDraftService;
use App\Services\ArtworkService;
use Illuminate\Http\Request;
use Symfony\Component\HttpFoundation\Response;
@@ -29,9 +30,12 @@ class ArtworkController extends Controller
$user = $request->user();
$data = $request->validated();
$categoryId = isset($data['category']) && ctype_digit((string) $data['category'])
$categoryId = isset($data['primary_category_id']) && ctype_digit((string) $data['primary_category_id'])
? (int) $data['primary_category_id']
: (isset($data['category']) && ctype_digit((string) $data['category'])
? (int) $data['category']
: null;
: null);
$secondaryCategoryIds = array_values(array_map('intval', $data['secondary_category_ids'] ?? []));
$result = $drafts->createDraft(
$user,
@@ -40,6 +44,7 @@ class ArtworkController extends Controller
$categoryId,
(bool) ($data['is_mature'] ?? false),
$data['group'] ?? null,
$secondaryCategoryIds,
);
return response()->json([
@@ -5,11 +5,15 @@ namespace App\Http\Controllers\Api;
use App\Http\Controllers\Controller;
use App\Http\Resources\ArtworkResource;
use App\Models\Artwork;
use App\Services\ArtworkNavigationService;
use App\Services\ThumbnailPresenter;
use Illuminate\Http\JsonResponse;
use Illuminate\Support\Str;
use Illuminate\Http\Request;
class ArtworkNavigationController extends Controller
{
public function __construct(private readonly ArtworkNavigationService $navigation) {}
/**
* GET /api/artworks/navigation/{id}
*
@@ -26,35 +30,11 @@ class ArtworkNavigationController extends Controller
'prev_id' => null, 'next_id' => null,
'prev_url' => null, 'next_url' => null,
'prev_slug' => null, 'next_slug' => null,
'prev_preview' => null, 'next_preview' => null,
]);
}
$scope = Artwork::published()
->select(['id', 'title', 'slug'])
->where('user_id', $artwork->user_id);
$prev = (clone $scope)->where('id', '<', $id)->orderByDesc('id')->first();
$next = (clone $scope)->where('id', '>', $id)->orderBy('id')->first();
// Infinite loop: wrap around when reaching the first or last artwork
if (! $prev) {
$prev = (clone $scope)->where('id', '!=', $id)->orderByDesc('id')->first();
}
if (! $next) {
$next = (clone $scope)->where('id', '!=', $id)->orderBy('id')->first();
}
$prevSlug = $prev ? (Str::slug($prev->slug ?: $prev->title) ?: (string) $prev->id) : null;
$nextSlug = $next ? (Str::slug($next->slug ?: $next->title) ?: (string) $next->id) : null;
return response()->json([
'prev_id' => $prev?->id,
'next_id' => $next?->id,
'prev_url' => $prev ? url('/art/' . $prev->id . '/' . $prevSlug) : null,
'next_url' => $next ? url('/art/' . $next->id . '/' . $nextSlug) : null,
'prev_slug' => $prevSlug,
'next_slug' => $nextSlug,
]);
return response()->json($this->navigation->navigationFor($artwork));
}
/**
@@ -62,8 +42,12 @@ class ArtworkNavigationController extends Controller
*
* Returns full artwork resource by numeric ID for client-side (no-reload) navigation.
*/
public function pageData(int $id): JsonResponse
public function pageData(Request $request, int $id): JsonResponse
{
if ($request->boolean('prefetch')) {
return $this->prefetchData($id);
}
$artwork = Artwork::with(['user.profile', 'categories.contentType', 'categories.parent.contentType', 'tags', 'stats'])
->published()
->find($id);
@@ -73,7 +57,30 @@ class ArtworkNavigationController extends Controller
}
$resource = (new ArtworkResource($artwork))->toArray(request());
$resource['navigation'] = $this->navigation->navigationFor($artwork);
return response()->json($resource);
}
private function prefetchData(int $id): JsonResponse
{
$artwork = Artwork::query()
->published()
->select(['id', 'title', 'slug', 'hash', 'file_path', 'file_name'])
->find($id);
if (! $artwork) {
return response()->json(['error' => 'Not found'], 404);
}
return response()->json([
'id' => (int) $artwork->id,
'title' => (string) $artwork->title,
'slug' => (string) $artwork->slug,
'thumbs' => [
'md' => ThumbnailPresenter::present($artwork, 'md'),
'lg' => ThumbnailPresenter::present($artwork, 'lg'),
],
]);
}
}
@@ -182,10 +182,9 @@ final class DiscoveryNegativeSignalController extends Controller
return;
}
$categoryId = DB::table('artwork_category')
->where('artwork_id', $artworkId)
->orderBy('category_id')
->value('category_id');
$categoryId = DB::table('artworks')
->where('id', $artworkId)
->value('primary_category_id');
DB::table('user_discovery_events')->insert([
'event_id' => (string) Str::uuid(),
+20 -40
View File
@@ -5,12 +5,10 @@ namespace App\Http\Controllers\Api;
use App\Http\Controllers\Controller;
use App\Models\User;
use App\Services\FollowService;
use App\Support\AvatarUrl;
use App\Support\UsernamePolicy;
use Illuminate\Http\JsonResponse;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Auth;
use Illuminate\Support\Facades\DB;
/**
* API endpoints for the follow system.
@@ -72,26 +70,17 @@ final class FollowController extends Controller
{
$target = $this->resolveUser($username);
$perPage = min((int) $request->query('per_page', 24), 100);
$page = max(1, (int) $request->query('page', 1));
$rows = DB::table('user_followers as uf')
->join('users as u', 'u.id', '=', 'uf.follower_id')
->leftJoin('user_profiles as up', 'up.user_id', '=', 'u.id')
->where('uf.user_id', $target->id)
->whereNull('u.deleted_at')
->orderByDesc('uf.created_at')
->select([
'u.id', 'u.username', 'u.name',
'up.avatar_hash',
'uf.created_at as followed_at',
])
->paginate($perPage)
->through(fn ($row) => [
'id' => $row->id,
'username' => $row->username,
'display_name'=> $row->username ?? $row->name,
'avatar_url' => AvatarUrl::forUser((int) $row->id, $row->avatar_hash, 50),
'profile_url' => '/@' . strtolower((string) ($row->username ?? $row->id)),
'followed_at' => $row->followed_at,
$rows = $this->followService
->paginatedFollowers((int) $target->id, $perPage, $page)
->through(fn (array $row) => [
'id' => $row['id'],
'username' => $row['username'],
'display_name' => $row['display_name'],
'avatar_url' => $row['avatar_url'],
'profile_url' => $row['profile_url'],
'followed_at' => $row['followed_at'],
]);
return response()->json($rows);
@@ -103,26 +92,17 @@ final class FollowController extends Controller
{
$target = $this->resolveUser($username);
$perPage = min((int) $request->query('per_page', 24), 100);
$page = max(1, (int) $request->query('page', 1));
$rows = DB::table('user_followers as uf')
->join('users as u', 'u.id', '=', 'uf.user_id')
->leftJoin('user_profiles as up', 'up.user_id', '=', 'u.id')
->where('uf.follower_id', $target->id)
->whereNull('u.deleted_at')
->orderByDesc('uf.created_at')
->select([
'u.id', 'u.username', 'u.name',
'up.avatar_hash',
'uf.created_at as followed_at',
])
->paginate($perPage)
->through(fn ($row) => [
'id' => $row->id,
'username' => $row->username,
'display_name'=> $row->username ?? $row->name,
'avatar_url' => AvatarUrl::forUser((int) $row->id, $row->avatar_hash, 50),
'profile_url' => '/@' . strtolower((string) ($row->username ?? $row->id)),
'followed_at' => $row->followed_at,
$rows = $this->followService
->paginatedFollowing((int) $target->id, $perPage, $page)
->through(fn (array $row) => [
'id' => $row['id'],
'username' => $row['username'],
'display_name' => $row['display_name'],
'avatar_url' => $row['avatar_url'],
'profile_url' => $row['profile_url'],
'followed_at' => $row['followed_at'],
]);
return response()->json($rows);
@@ -48,10 +48,7 @@ class MessageSearchController extends Controller
$estimated = 0;
try {
$client = new Client(
config('scout.meilisearch.host'),
config('scout.meilisearch.key')
);
$client = app(Client::class);
$prefix = (string) config('scout.prefix', '');
$indexName = $prefix . (string) config('messaging.search.index', 'messages');
@@ -7,9 +7,11 @@ namespace App\Http\Controllers\Api;
use App\Http\Controllers\Controller;
use App\Models\Artwork;
use App\Models\User;
use Carbon\CarbonInterface;
use App\Services\CollectionService;
use App\Services\Maturity\ArtworkMaturityService;
use App\Services\ThumbnailPresenter;
use App\Support\UsernamePolicy;
use Carbon\CarbonInterface;
use Illuminate\Database\Eloquent\Builder;
use Illuminate\Http\JsonResponse;
use Illuminate\Http\Request;
@@ -25,6 +27,28 @@ use UnexpectedValueException;
*/
final class ProfileApiController extends Controller
{
public function __construct(private readonly CollectionService $collections) {}
/**
* GET /api/profile/{username}/collections
* Returns the profile collection cards without rendering the profile page.
*/
public function collections(Request $request, string $username): JsonResponse
{
$user = $this->resolveUser($username);
if (! $user) {
return response()->json(['error' => 'User not found'], 404);
}
$viewer = $request->user();
$isOwner = $viewer && (int) $viewer->id === (int) $user->id;
$profileCollections = $this->collections->getProfileCollections($user, $viewer);
return response()->json([
'data' => $this->collections->mapCollectionCardPayloads($profileCollections, $isOwner, $viewer),
]);
}
/**
* GET /api/profile/{username}/artworks
* Returns cursor-paginated artworks for the profile page tabs.
@@ -106,7 +130,7 @@ final class ProfileApiController extends Controller
return response()->json(['error' => 'User not found'], 404);
}
$perPage = 24;
$perPage = 12;
$offset = max(0, (int) base64_decode((string) $request->input('cursor', ''), true));
$favIds = DB::table($favouriteTable.' as af')
@@ -116,6 +140,10 @@ final class ProfileApiController extends Controller
->where('a.is_public', true)
->where('a.is_approved', true)
->whereNotNull('a.published_at')
->when(app(ArtworkMaturityService::class)->viewerPreferences($request->user())['visibility'] === ArtworkMaturityService::VIEW_HIDE, function ($query): void {
$query->whereRaw('COALESCE(a.is_mature, 0) = 0')
->whereRaw("COALESCE(a.maturity_status, 'clear') != ?", [ArtworkMaturityService::STATUS_SUSPECTED]);
})
->orderByDesc('af.created_at')
->orderByDesc('af.artwork_id')
->offset($offset)
@@ -185,6 +213,7 @@ final class ProfileApiController extends Controller
private function resolveUser(string $username): ?User
{
$normalized = UsernamePolicy::normalize($username);
return User::query()->whereRaw('LOWER(username) = ?', [$normalized])->first();
}
@@ -230,7 +259,7 @@ final class ProfileApiController extends Controller
private function mapArtworkCardPayload(Artwork $art): array
{
$present = ThumbnailPresenter::present($art, 'md');
$category = $art->categories->first();
$category = $art->resolvedPrimaryCategory();
$contentType = $category?->contentType;
$stats = $art->stats;
$group = $art->group;
@@ -246,6 +275,8 @@ final class ProfileApiController extends Controller
return [
'id' => $art->id,
'name' => $art->title,
'picture' => $art->file_name,
'datum' => $this->formatIsoDate($art->published_at),
'thumb' => $present['url'],
'thumb_srcset' => $present['srcset'] ?? $present['url'],
'width' => $art->width,
@@ -6,10 +6,12 @@ namespace App\Http\Controllers\Api;
use App\Http\Controllers\Controller;
use App\Models\Artwork;
use App\Services\Vision\VectorGatewayException;
use App\Services\Vision\VectorService;
use Illuminate\Http\JsonResponse;
use Illuminate\Http\Request;
use RuntimeException;
use Illuminate\Support\Facades\Log;
use Throwable;
final class SimilarAiArtworksController extends Controller
{
@@ -35,11 +37,12 @@ final class SimilarAiArtworksController extends Controller
try {
$items = $this->vectors->similarToArtwork($artwork, $limit);
} catch (RuntimeException $e) {
} catch (Throwable $e) {
$this->logSimilarityFailure($artwork->id, $e);
return response()->json([
'data' => [],
'reason' => 'vector_gateway_error',
'message' => $e->getMessage(),
], 502);
}
@@ -52,4 +55,19 @@ final class SimilarAiArtworksController extends Controller
],
]);
}
private function logSimilarityFailure(int $artworkId, Throwable $e): void
{
$gateway = $e instanceof VectorGatewayException ? $e : null;
Log::warning('Vector similarity search failed', [
'artwork_id' => $artworkId,
'route' => 'api.art.similar-ai',
'failure_stage' => $gateway?->operation ?? 'unknown',
'exception_class' => $e::class,
'http_status' => $gateway?->httpStatus,
'circuit_worthy' => $gateway?->circuitWorthy ?? false,
'circuit_open' => app(\App\Services\Vision\VectorGatewayClient::class)->circuitOpen(),
]);
}
}
+111 -50
View File
@@ -5,52 +5,58 @@ declare(strict_types=1);
namespace App\Http\Controllers\Api;
use App\Http\Controllers\Controller;
use App\Http\Requests\Uploads\UploadCancelRequest;
use App\Http\Requests\Uploads\UploadChunkRequest;
use App\Http\Requests\Uploads\UploadFinishRequest;
use App\Http\Requests\Uploads\UploadInitRequest;
use App\Http\Requests\Uploads\UploadChunkRequest;
use App\Http\Requests\Uploads\UploadCancelRequest;
use App\Http\Requests\Uploads\UploadStatusRequest;
use App\Jobs\GenerateDerivativesJob;
use App\Jobs\AnalyzeArtworkAiAssistJob;
use App\Jobs\IndexArtworkJob;
use App\Jobs\AutoTagArtworkJob;
use App\Jobs\DetectArtworkMaturityJob;
use App\Jobs\GenerateArtworkEmbeddingJob;
use App\Jobs\GenerateDerivativesJob;
use App\Jobs\IndexArtworkJob;
use App\Models\ActivityEvent;
use App\Models\Artwork;
use App\Models\Group;
use App\Models\Tag;
use App\Notifications\NewArtworkReviewNotification;
use App\Repositories\Uploads\UploadSessionRepository;
use App\Services\Uploads\UploadChunkService;
use App\Services\Uploads\UploadCancelService;
use App\Services\Uploads\UploadAuditService;
use App\Services\Uploads\UploadPipelineService;
use App\Services\Uploads\UploadQuotaService;
use App\Services\Uploads\UploadQueueService;
use App\Services\Uploads\UploadSessionStatus;
use App\Services\Uploads\UploadStatusService;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Log;
use Symfony\Component\HttpFoundation\Response;
use Throwable;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Validator;
use App\Services\Upload\Contracts\UploadDraftServiceInterface;
use Carbon\Carbon;
use App\Uploads\Jobs\VirusScanJob;
use App\Uploads\Services\PublishService;
use App\Services\Activity\UserActivityService;
use App\Services\ArtworkAttributionService;
use App\Services\Artworks\ArtworkCategoryService;
use App\Services\GroupArtworkReviewService;
use App\Services\Maturity\ArtworkMaturityService;
use App\Services\Moderation\ArtworkUploadPolicy;
use App\Services\Upload\Contracts\UploadDraftServiceInterface;
use App\Services\Uploads\UploadAuditService;
use App\Services\Uploads\UploadCancelService;
use App\Services\Uploads\UploadChunkService;
use App\Services\Uploads\UploadPipelineService;
use App\Services\Uploads\UploadQueueService;
use App\Services\Uploads\UploadQuotaService;
use App\Services\Uploads\UploadSessionStatus;
use App\Services\Uploads\UploadStatusService;
use App\Services\Worlds\WorldSubmissionService;
use App\Support\ArtworkDescriptionContentValidator;
use App\Uploads\Exceptions\DraftQuotaException;
use App\Uploads\Exceptions\UploadNotFoundException;
use App\Uploads\Exceptions\UploadOwnershipException;
use App\Uploads\Exceptions\UploadPublishValidationException;
use App\Uploads\Jobs\VirusScanJob;
use App\Uploads\Services\ArchiveInspectorService;
use App\Uploads\Services\DraftQuotaService;
use App\Uploads\Exceptions\DraftQuotaException;
use App\Models\Artwork;
use App\Models\Group;
use App\Services\GroupArtworkReviewService;
use App\Support\ArtworkDescriptionContentValidator;
use App\Services\Worlds\WorldSubmissionService;
use Illuminate\Validation\ValidationException;
use App\Uploads\Services\PublishService;
use Carbon\Carbon;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Log;
use Illuminate\Support\Facades\Notification;
use Illuminate\Support\Facades\Validator;
use Illuminate\Support\Str;
use Illuminate\Validation\ValidationException;
use Symfony\Component\HttpFoundation\Response;
use Throwable;
final class UploadController extends Controller
{
@@ -59,8 +65,7 @@ final class UploadController extends Controller
UploadPipelineService $pipeline,
UploadQuotaService $quota,
UploadAuditService $audit
)
{
) {
$user = $request->user();
try {
@@ -251,6 +256,7 @@ final class UploadController extends Controller
if ((bool) config('vision.upload.ai_assist.enabled', false)) {
AnalyzeArtworkAiAssistJob::dispatch($artworkId)->afterCommit();
}
return UploadSessionStatus::PROCESSED;
});
@@ -305,7 +311,7 @@ final class UploadController extends Controller
'realpath' => $chunkFile->getRealPath(),
]);
}
} catch (\Throwable $e) {
} catch (Throwable $e) {
logger()->warning('Chunk upload debug logging failed', ['error' => $e->getMessage()]);
}
@@ -333,7 +339,7 @@ final class UploadController extends Controller
'total_bytes' => $result->totalBytes,
'progress' => $result->progress,
], Response::HTTP_OK);
} catch (\Throwable $e) {
} catch (Throwable $e) {
logger()->warning('Upload chunk failed', [
'session_id' => (string) $request->input('session_id'),
'error' => $e->getMessage(),
@@ -383,7 +389,7 @@ final class UploadController extends Controller
'session_id' => $result['session_id'],
'status' => $result['status'],
], Response::HTTP_OK);
} catch (\Throwable $e) {
} catch (Throwable $e) {
logger()->warning('Upload cancel failed', [
'session_id' => (string) $request->input('session_id'),
'error' => $e->getMessage(),
@@ -512,6 +518,7 @@ final class UploadController extends Controller
return response()->json($response, Response::HTTP_OK);
} catch (Throwable $e) {
logger()->error('Upload preload failed', ['error' => $e->getMessage()]);
return response()->json(['message' => 'Preload failed.'], Response::HTTP_INTERNAL_SERVER_ERROR);
}
}
@@ -538,6 +545,8 @@ final class UploadController extends Controller
$validated = $request->validate([
'title' => ['nullable', 'string', 'max:255'],
'category_id' => ['nullable', 'exists:categories,id'],
'secondary_category_ids' => ['nullable', 'array', 'max:'.(int) config('categories.max_secondary_categories', 5)],
'secondary_category_ids.*' => ['integer', 'exists:categories,id'],
'description' => ['nullable', 'string'],
'tags' => ['nullable', 'array'],
'license' => ['nullable', 'string'],
@@ -547,7 +556,7 @@ final class UploadController extends Controller
$this->ensureValidArtworkDescription($validated);
$updates = [];
foreach (['title', 'category_id', 'description', 'tags', 'license', 'nsfw'] as $field) {
foreach (['title', 'category_id', 'secondary_category_ids', 'description', 'tags', 'license', 'nsfw'] as $field) {
if (array_key_exists($field, $validated)) {
$updates[$field] = $validated[$field];
}
@@ -557,7 +566,7 @@ final class UploadController extends Controller
foreach ($updates as $field => $value) {
$current = $upload->{$field} ?? null;
if ($field === 'tags') {
if ($field === 'tags' || $field === 'secondary_category_ids') {
$current = $current ? json_decode((string) $current, true) : null;
}
@@ -575,6 +584,10 @@ final class UploadController extends Controller
$dirty['tags'] = json_encode($dirty['tags']);
}
if (array_key_exists('secondary_category_ids', $dirty)) {
$dirty['secondary_category_ids'] = json_encode($dirty['secondary_category_ids']);
}
if (! empty($dirty)) {
$dirty['updated_at'] = now();
DB::table('uploads')->where('id', $id)->update($dirty);
@@ -616,7 +629,7 @@ final class UploadController extends Controller
], Response::HTTP_OK);
}
public function publish(string $id, Request $request, PublishService $publishService, ArtworkAttributionService $attribution, ArtworkMaturityService $maturity, WorldSubmissionService $submissions)
public function publish(string $id, Request $request, PublishService $publishService, ArtworkAttributionService $attribution, ArtworkMaturityService $maturity, WorldSubmissionService $submissions, ArtworkUploadPolicy $uploadPolicy)
{
$user = $request->user();
@@ -624,6 +637,9 @@ final class UploadController extends Controller
'title' => ['nullable', 'string', 'max:150'],
'description' => ['nullable', 'string'],
'category' => ['nullable', 'integer', 'exists:categories,id'],
'primary_category_id' => ['nullable', 'integer', 'exists:categories,id'],
'secondary_category_ids' => ['nullable', 'array', 'max:'.(int) config('categories.max_secondary_categories', 5)],
'secondary_category_ids.*' => ['integer', 'exists:categories,id'],
'tags' => ['nullable', 'array', 'max:'.(int) config('tags.max_user_tags', 30)],
'tags.*' => ['string', 'max:64'],
'is_mature' => ['nullable', 'boolean'],
@@ -656,14 +672,14 @@ final class UploadController extends Controller
$publishAt = null;
if ($mode === 'schedule' && ! empty($validated['publish_at'])) {
try {
$publishAt = \Carbon\Carbon::parse($validated['publish_at'])->utc();
$publishAt = Carbon::parse($validated['publish_at'])->utc();
// Must be at least 1 minute in the future (server-side guard)
if ($publishAt->lte(now()->addMinute())) {
return response()->json([
'message' => 'Scheduled publish time must be at least 1 minute in the future.',
], Response::HTTP_UNPROCESSABLE_ENTITY);
}
} catch (\Throwable) {
} catch (Throwable) {
return response()->json(['message' => 'Invalid publish_at datetime.'], Response::HTTP_UNPROCESSABLE_ENTITY);
}
}
@@ -701,17 +717,20 @@ final class UploadController extends Controller
$artwork->uploaded_by_user_id = $artwork->uploaded_by_user_id ?: (int) $user->id;
$artwork->primary_author_user_id = $artwork->primary_author_user_id ?: (int) $user->id;
// Sync category if provided
$categoryId = isset($validated['category']) ? (int) $validated['category'] : null;
if ($categoryId && \App\Models\Category::where('id', $categoryId)->exists()) {
$artwork->categories()->sync([$categoryId]);
$categoryId = isset($validated['primary_category_id'])
? (int) $validated['primary_category_id']
: (isset($validated['category']) ? (int) $validated['category'] : null);
$secondaryCategoryIds = array_values(array_map('intval', $validated['secondary_category_ids'] ?? []));
if ($categoryId) {
app(ArtworkCategoryService::class)
->sync($artwork, $categoryId, $secondaryCategoryIds, 'user', false);
}
// Sync tags if provided
if (! empty($validated['tags']) && is_array($validated['tags'])) {
$tagIds = [];
foreach ($validated['tags'] as $tagSlug) {
$tag = \App\Models\Tag::firstOrCreate(
$tag = Tag::firstOrCreate(
['slug' => Str::slug($tagSlug)],
['name' => $tagSlug, 'is_active' => true, 'usage_count' => 0]
);
@@ -747,10 +766,47 @@ final class UploadController extends Controller
], Response::HTTP_OK);
}
// Publish immediately
// New and suspicious accounts are quarantined. Never let the client
// decide that an artwork is approved.
$policy = $uploadPolicy->assess($user, $artwork);
if ($policy['requires_review']) {
$artwork->visibility = $visibility;
$artwork->is_public = false;
$artwork->is_approved = false;
$artwork->approval_source = null;
$artwork->artwork_status = 'review';
$artwork->published_at = null;
$artwork->publish_at = null;
$artwork->moderated_at = null;
$artwork->moderated_by = null;
$artwork->moderation_note = implode(', ', $policy['reasons']);
$artwork->save();
$notifyEmail = trim((string) config('uploads.moderation.notify_email', ''));
if ($notifyEmail !== '') {
try {
Notification::route('mail', $notifyEmail)->notify(
new NewArtworkReviewNotification($artwork, $user, $policy['reasons'])
);
} catch (Throwable) {
// Email failure must not expose the artwork.
}
}
return response()->json([
'success' => true,
'artwork_id' => (int) $artwork->id,
'status' => 'submitted_for_review',
'message' => 'Upload received and queued for moderation.',
'review_reasons' => $policy['reasons'],
], Response::HTTP_OK);
}
// Publish immediately for trusted users only.
$artwork->visibility = $visibility;
$artwork->is_public = ($visibility !== 'private');
$artwork->is_approved = true;
$artwork->approval_source = 'trusted_auto';
$artwork->published_at = now();
$artwork->artwork_status = 'published';
$artwork->publish_at = null;
@@ -760,17 +816,19 @@ final class UploadController extends Controller
// Record upload activity event
try {
\App\Models\ActivityEvent::record(
ActivityEvent::record(
actorId: (int) $user->id,
type: \App\Models\ActivityEvent::TYPE_UPLOAD,
targetType: \App\Models\ActivityEvent::TARGET_ARTWORK,
type: ActivityEvent::TYPE_UPLOAD,
targetType: ActivityEvent::TARGET_ARTWORK,
targetId: (int) $artwork->id,
);
} catch (\Throwable) {}
} catch (Throwable) {
}
try {
app(UserActivityService::class)->logUpload((int) $user->id, (int) $artwork->id);
} catch (\Throwable) {}
} catch (Throwable) {
}
return response()->json([
'success' => true,
@@ -808,6 +866,9 @@ final class UploadController extends Controller
'title' => ['nullable', 'string', 'max:150'],
'description' => ['nullable', 'string'],
'category' => ['nullable', 'integer', 'exists:categories,id'],
'primary_category_id' => ['nullable', 'integer', 'exists:categories,id'],
'secondary_category_ids' => ['nullable', 'array', 'max:'.(int) config('categories.max_secondary_categories', 5)],
'secondary_category_ids.*' => ['integer', 'exists:categories,id'],
'tags' => ['nullable', 'array', 'max:'.(int) config('tags.max_user_tags', 30)],
'tags.*' => ['string', 'max:64'],
'is_mature' => ['nullable', 'boolean'],
@@ -8,11 +8,13 @@ use App\Models\Artwork;
use App\Models\ArtworkDownload;
use App\Services\ArtworkOriginalFileLocator;
use App\Services\ArtworkStatsService;
use Illuminate\Http\RedirectResponse;
use Illuminate\Http\Request;
use Illuminate\Http\Response;
use Illuminate\Support\Facades\File;
use Illuminate\Support\Facades\Log;
use Illuminate\Support\Facades\Schema;
use Illuminate\Support\Facades\Storage;
use Illuminate\Support\Str;
use Symfony\Component\HttpFoundation\BinaryFileResponse;
@@ -43,19 +45,76 @@ final class ArtworkDownloadController extends Controller
private readonly ArtworkOriginalFileLocator $originalFiles,
) {}
public function __invoke(Request $request, int $id): BinaryFileResponse|Response
public function __invoke(Request $request, int $id): BinaryFileResponse|RedirectResponse|Response
{
$artwork = Artwork::query()->find($id);
if (! $artwork) {
abort(404);
return $this->notFound();
}
$filePath = $this->originalFiles->resolveLocalPath($artwork);
$ext = strtolower(ltrim((string) pathinfo($filePath, PATHINFO_EXTENSION), '.'));
$resolution = $this->originalFiles->resolve($artwork);
$filePath = (string) $resolution['path'];
$objectKey = (string) $resolution['object_key'];
$ext = strtolower((string) ($resolution['file_ext'] ?: pathinfo($filePath !== '' ? $filePath : $objectKey, PATHINFO_EXTENSION)));
if ($filePath === '' || ! in_array($ext, self::ALLOWED_EXTENSIONS, true)) {
abort(404);
if (($filePath === '' && $objectKey === '') || ! in_array($ext, self::ALLOWED_EXTENSIONS, true)) {
return $this->notFound();
}
if (! $resolution['exists']) {
Log::warning('Artwork original file missing for download.', [
'artwork_id' => $artwork->id,
'ext' => $ext,
'download_status' => $artwork->download_status,
'canonical_local_exists' => $filePath !== '' && File::isFile($filePath),
'object_exists' => false,
'resolution_status' => $resolution['status'],
]);
return $this->notFound();
}
$downloadName = $this->buildDownloadFilename((string) $artwork->file_name, $ext);
$temporaryUrl = null;
if ($resolution['source'] === 'object') {
try {
$temporaryUrl = Storage::disk((string) $resolution['disk'])->temporaryUrl(
$objectKey,
now()->addMinutes(5),
[
'ResponseContentDisposition' => 'attachment; filename="'.addslashes($downloadName).'"',
],
);
} catch (\Throwable $exception) {
Log::warning('Artwork object temporary URL generation failed.', [
'artwork_id' => $artwork->id,
'disk' => $resolution['disk'],
'object_key' => $objectKey,
'object_exists' => true,
'object_size' => $resolution['size'],
'exception_class' => $exception::class,
'exception_message' => mb_substr($exception->getMessage(), 0, 300),
]);
return $this->notFound();
}
if (! is_string($temporaryUrl) || trim($temporaryUrl) === '') {
Log::warning('Artwork object temporary URL generation failed.', [
'artwork_id' => $artwork->id,
'disk' => $resolution['disk'],
'object_key' => $objectKey,
'resolution_status' => $resolution['status'],
'object_exists' => true,
'object_size' => $resolution['size'],
'exception_class' => 'InvalidTemporaryUrl',
'exception_message' => 'Storage adapter did not return a temporary URL.',
]);
return $this->notFound();
}
}
$this->recordDownload($request, $artwork->id);
@@ -70,18 +129,14 @@ final class ArtworkDownloadController extends Controller
]);
}
if (! File::isFile($filePath)) {
Log::warning('Artwork original file missing for download.', [
'artwork_id' => $artwork->id,
'ext' => $ext,
'resolved_path' => $filePath,
]);
abort(404);
if (array_key_exists('download_status', $artwork->getAttributes())) {
$artwork->forceFill([
'download_status' => 'available',
'download_source' => $resolution['source'],
'download_checked_at' => now(),
])->saveQuietly();
}
$downloadName = $this->buildDownloadFilename((string) $artwork->file_name, $ext);
// X-Accel-Redirect is safe only when nginx is explicitly configured to
// map the internal URI to the originals root. Otherwise fallback to the
// normal Laravel download response.
@@ -95,9 +150,21 @@ final class ArtworkDownloadController extends Controller
]);
}
if ($resolution['source'] === 'object') {
return redirect()->away($temporaryUrl);
}
return response()->download($filePath, $downloadName);
}
private function notFound(): Response
{
return response('', 404, [
'Content-Type' => 'text/plain; charset=UTF-8',
'Cache-Control' => 'no-store',
]);
}
private function resolveAccelUri(string $filePath): ?string
{
if (! config('app.download_accel_enabled')) {
@@ -0,0 +1,43 @@
<?php
declare(strict_types=1);
namespace App\Http\Controllers;
use Illuminate\Http\JsonResponse;
final class BuildInfoController extends Controller
{
public function __invoke(): JsonResponse
{
$path = base_path('build-info.json');
if (! is_file($path) || ! is_readable($path)) {
return response()->json(['error' => 'Build info unavailable'], 404)
->header('Cache-Control', 'no-store, max-age=0');
}
$decoded = json_decode((string) file_get_contents($path), true);
if (! is_array($decoded)) {
return response()->json(['error' => 'Build info unavailable'], 404)
->header('Cache-Control', 'no-store, max-age=0');
}
$commit = trim((string) ($decoded['git_sha'] ?? ''));
$release = trim((string) ($decoded['release_id'] ?? ''));
$builtAt = trim((string) ($decoded['deployed_at_utc'] ?? ''));
if ($commit === '' || $release === '' || $builtAt === '') {
return response()->json(['error' => 'Build info unavailable'], 404)
->header('Cache-Control', 'no-store, max-age=0');
}
return response()->json([
'environment' => app()->environment(),
'commit' => $commit,
'built_at' => $builtAt,
'release' => $release,
])->header('Cache-Control', 'no-store, max-age=0');
}
}
@@ -3,12 +3,14 @@
namespace App\Http\Controllers\Dashboard;
use App\Http\Controllers\Controller;
use App\Http\Requests\Manage\ManageArtworkDestroyRequest;
use App\Http\Requests\Manage\ManageArtworkEditRequest;
use App\Http\Requests\Manage\ManageArtworkUpdateRequest;
use App\Http\Requests\Manage\ManageArtworkDestroyRequest;
use App\Models\Artwork;
use App\Services\Artworks\ArtworkCategoryService;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Storage;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Storage;
class ManageController extends Controller
{
@@ -17,14 +19,12 @@ class ManageController extends Controller
$userId = $request->user()->id;
$perPage = 50;
$categorySub = DB::table('artwork_category as ac')
->join('categories as c', 'ac.category_id', '=', 'c.id')
->select('ac.artwork_id', DB::raw('MIN(c.name) as category_name'))
->groupBy('ac.artwork_id');
$categorySub = DB::table('categories as c')
->select('c.id as category_id', 'c.name as category_name');
$query = DB::table('artworks as a')
->leftJoinSub($categorySub, 'cat', function ($join) {
$join->on('a.id', '=', 'cat.artwork_id');
$join->on('a.primary_category_id', '=', 'cat.category_id');
})
->leftJoin('artwork_stats as s', 'a.id', '=', 's.artwork_id')
->where('a.user_id', $userId)
@@ -52,8 +52,8 @@ class ManageController extends Controller
{
$artwork = $request->artwork();
$selectedCategory = DB::table('artwork_category')->where('artwork_id', (int)$id)->value('category_id');
$artwork->category = $selectedCategory;
$selectedCategory = (int) ($artwork->primary_category_id ?: DB::table('artwork_category')->where('artwork_id', (int) $id)->value('category_id'));
$artwork->category = $selectedCategory ?: null;
$categories = DB::table('categories')
->where('content_type_id', 0)
@@ -94,11 +94,11 @@ class ManageController extends Controller
DB::table('artworks')->where('id', (int) $id)->update($update);
if (isset($data['section'])) {
DB::table('artwork_category')->where('artwork_id', (int)$id)->delete();
DB::table('artwork_category')->insert([
'artwork_id' => (int)$id,
'category_id' => (int)$data['section'],
]);
$model = Artwork::query()->find((int) $id);
if ($model) {
app(ArtworkCategoryService::class)
->sync($model, (int) $data['section'], [], 'moderator');
}
}
return redirect()->route('manage')->with('status', 'Artwork was successfully updated.');
@@ -8,6 +8,7 @@ use App\Http\Controllers\Controller;
use App\Models\Artwork;
use Illuminate\Database\Eloquent\Builder;
use Illuminate\Http\RedirectResponse;
use Illuminate\Http\Response;
use Illuminate\Support\Facades\Schema;
final class LegacyArtworkPhotoController extends Controller
@@ -26,25 +27,39 @@ final class LegacyArtworkPhotoController extends Controller
private static ?bool $hasLegacyIdColumn = null;
public function __invoke(string $encoded, string $size, string $extension): RedirectResponse
public function __invoke(string $encoded, string $size, string $extension): RedirectResponse|Response
{
$artworkId = $this->decodeBase62($encoded);
$sizeCode = (int) $size;
abort_if($artworkId === null || $artworkId < 1, 404);
if ($artworkId === null || $artworkId < 1) {
return $this->notFound();
}
$artwork = $this->resolveArtwork($artworkId);
abort_unless($artwork !== null, 404);
if ($artwork === null) {
return $this->notFound();
}
$targetUrl = $sizeCode === 7
? $this->resolveOriginalUrl($artwork)
: $artwork->thumbUrl(self::THUMB_SIZE_MAP[$sizeCode] ?? 'md');
abort_if(empty($targetUrl), 404);
if ($targetUrl === null || $targetUrl === '') {
return $this->notFound();
}
return redirect()->away($targetUrl, 301);
}
private function notFound(): Response
{
return response('', 404, [
'Content-Type' => 'text/plain; charset=UTF-8',
'Cache-Control' => 'no-store',
]);
}
private function decodeBase62(string $value): ?int
{
if ($value === '') {
@@ -86,11 +101,6 @@ final class LegacyArtworkPhotoController extends Controller
{
$cdn = rtrim((string) config('cdn.files_url', 'https://cdn.skinbase.org'), '/');
$filePath = trim((string) ($artwork->file_path ?? ''), '/');
if ($filePath !== '') {
return $cdn . '/' . $filePath;
}
$hash = strtolower((string) preg_replace('/[^a-f0-9]/i', '', (string) ($artwork->hash ?? '')));
$ext = ltrim((string) ($artwork->file_ext ?: $artwork->thumb_ext ?: 'webp'), '.');
@@ -98,6 +108,10 @@ final class LegacyArtworkPhotoController extends Controller
return $artwork->thumbUrl('xl') ?? $artwork->thumbUrl('lg') ?? $artwork->thumbUrl('md');
}
if ($filePath !== '') {
return $cdn . '/' . $filePath;
}
$prefix = trim((string) config('uploads.object_storage.prefix', 'artworks'), '/');
$firstDir = substr($hash, 0, 2);
$secondDir = substr($hash, 2, 2);
@@ -3,11 +3,12 @@
namespace App\Http\Controllers\Legacy;
use App\Http\Controllers\Controller;
use Illuminate\Http\Request;
use App\Models\Artwork;
use App\Models\ArtworkDownload;
use Illuminate\Support\Facades\Storage;
use Illuminate\Support\Str;
use App\Services\ThumbnailPresenter;
use Carbon\Carbon;
use Illuminate\Http\Request;
use Illuminate\Support\Str;
class TodayDownloadsController extends Controller
{
@@ -35,16 +36,16 @@ class TodayDownloadsController extends Controller
$art = $row->artwork ?? null;
// If Eloquent didn't eager load artwork (group queries sometimes don't), fetch it
if (! $art && isset($row->artwork_id)) {
$art = \App\Models\Artwork::find($row->artwork_id);
$art = Artwork::find($row->artwork_id);
}
$name = $art->title ?? null;
$picture = $art->file_name ?? null;
$ext = pathinfo($picture ?? '', PATHINFO_EXTENSION) ?: 'jpg';
$encoded = null; // legacy encoding unavailable; leave null
$present = $art ? \App\Services\ThumbnailPresenter::present($art, 'md') : null;
$present = $art ? ThumbnailPresenter::present($art, 'md') : null;
$thumb = $present ? $present['url'] : 'https://files.skinbase.org/default/missing_md.webp';
$categoryId = $art->categories->first()->id ?? null;
$categoryId = $art->resolvedPrimaryCategory()?->id;
return (object) [
'id' => $art->id ?? null,
+59 -22
View File
@@ -3,12 +3,12 @@
namespace App\Http\Controllers\Legacy;
use App\Http\Controllers\Controller;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Hash;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
use App\Services\AvatarService;
use Carbon\Carbon;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Hash;
use Illuminate\Support\Facades\Schema;
class UserController extends Controller
{
@@ -46,11 +46,21 @@ class UserController extends Controller
// Collect other profile updates to persist into `user_profiles` when available
$profileUpdates = [];
if (!empty($data['web'])) $profileUpdates['website'] = $data['web'];
if (!empty($data['signature'])) $profileUpdates['signature'] = $data['signature'];
if (!empty($data['description'])) $profileUpdates['description'] = $data['description'];
if (!empty($data['about_me'])) $profileUpdates['about'] = $data['about_me'];
if (!empty($data['country_code'])) $profileUpdates['country_code'] = $data['country_code'];
if (! empty($data['web'])) {
$profileUpdates['website'] = $data['web'];
}
if (! empty($data['signature'])) {
$profileUpdates['signature'] = $data['signature'];
}
if (! empty($data['description'])) {
$profileUpdates['description'] = $data['description'];
}
if (! empty($data['about_me'])) {
$profileUpdates['about'] = $data['about_me'];
}
if (! empty($data['country_code'])) {
$profileUpdates['country_code'] = $data['country_code'];
}
$d1 = $request->input('date1');
$d2 = $request->input('date2');
@@ -60,10 +70,19 @@ class UserController extends Controller
}
$userGender = $request->input('gender', $user->gender);
if (!empty($userGender)) {
$g = strtolower($userGender);
$map = ['m' => 'M', 'f' => 'F', 'n' => 'X', 'x' => 'X'];
$profileUpdates['gender'] = $map[$g] ?? strtoupper($userGender);
if ($userGender !== null && $userGender !== '') {
$g = strtolower(trim((string) $userGender));
$map = [
'm' => 'M',
'male' => 'M',
'f' => 'F',
'female' => 'F',
'n' => 'X',
'x' => 'X',
'na' => 'X',
'n/a' => 'X',
];
$profileUpdates['gender'] = $map[$g] ?? null;
}
$profileUpdates['mlist'] = $request->has('newsletter') ? 1 : 0;
@@ -143,15 +162,33 @@ class UserController extends Controller
$profile = DB::table('user_profiles')->where('user_id', $user->id)->first();
if ($profile) {
// map modern profile fields onto the legacy user properties/helpers used by the view
if (isset($profile->website)) $user->homepage = $profile->website;
if (isset($profile->about)) $user->about_me = $profile->about;
if (isset($profile->birthdate)) $user->birth = $profile->birthdate;
if (isset($profile->gender)) $user->gender = $profile->gender;
if (isset($profile->country_code)) $user->country_code = $profile->country_code;
if (isset($profile->avatar_hash)) $user->icon = $profile->avatar_hash;
if (isset($profile->cover_image)) $user->picture = $profile->cover_image;
if (isset($profile->signature)) $user->signature = $profile->signature;
if (isset($profile->description)) $user->description = $profile->description;
if (isset($profile->website)) {
$user->homepage = $profile->website;
}
if (isset($profile->about)) {
$user->about_me = $profile->about;
}
if (isset($profile->birthdate)) {
$user->birth = $profile->birthdate;
}
if (isset($profile->gender)) {
$user->gender = $profile->gender;
}
if (isset($profile->country_code)) {
$user->country_code = $profile->country_code;
}
if (isset($profile->avatar_hash)) {
$user->icon = $profile->avatar_hash;
}
if (isset($profile->cover_image)) {
$user->picture = $profile->cover_image;
}
if (isset($profile->signature)) {
$user->signature = $profile->signature;
}
if (isset($profile->description)) {
$user->description = $profile->description;
}
}
}
} catch (\Throwable $e) {
+31 -7
View File
@@ -5,6 +5,7 @@ declare(strict_types=1);
namespace App\Http\Controllers;
use App\Services\Sitemaps\PublishedSitemapResolver;
use App\Services\Sitemaps\SitemapBuildService;
use App\Services\Sitemaps\SitemapXmlRenderer;
use Symfony\Component\HttpFoundation\BinaryFileResponse;
use Symfony\Component\HttpKernel\Exception\NotFoundHttpException;
@@ -14,34 +15,50 @@ final class SitemapController extends Controller
{
public function __construct(
private readonly PublishedSitemapResolver $published,
private readonly SitemapBuildService $build,
private readonly SitemapXmlRenderer $renderer,
) {
}
public function index(): Response|BinaryFileResponse
{
// 1. Static file written by the build/generate commands.
// On production nginx serves this directly via try_files without reaching PHP.
// On dev / misconfigured servers we stream it with sendfile — no RAM load.
$path = public_path('sitemap.xml');
if (file_exists($path)) {
if ((bool) config('sitemaps.pre_generated.enabled', true)) {
foreach ([
public_path('sitemaps/index.xml'),
public_path('sitemaps/sitemap.xml'),
public_path('sitemap.xml'),
] as $path) {
if (is_file($path) && is_readable($path)) {
return $this->xmlFileResponse($path);
}
}
}
// 2. Published release (release management pipeline fallback).
// 1. Published release (release management pipeline fallback).
$published = $this->published->resolveIndex();
if ($published !== null) {
return $this->renderer->xmlResponse($published['content']);
}
// 2. Live-build fallback when no published sitemap is available.
if ((bool) config('sitemaps.delivery.fallback_to_live_build', true)) {
$built = $this->build->buildIndex(force: true, persist: false);
return $this->renderer->xmlResponse($built['content']);
}
throw new NotFoundHttpException();
}
public function show(string $name): Response|BinaryFileResponse
{
if ($name === 'sitemap') {
return $this->index();
}
// 1. Static file.
$path = public_path('sitemaps/' . $name . '.xml');
if (file_exists($path)) {
if ((bool) config('sitemaps.pre_generated.enabled', true) && file_exists($path)) {
return $this->xmlFileResponse($path);
}
@@ -51,6 +68,13 @@ final class SitemapController extends Controller
return $this->renderer->xmlResponse($published['content']);
}
if ((bool) config('sitemaps.delivery.fallback_to_live_build', true)) {
$built = $this->build->buildNamed($name, force: true, persist: false);
if ($built !== null) {
return $this->renderer->xmlResponse($built['content']);
}
}
throw new NotFoundHttpException();
}
@@ -6,27 +6,34 @@ namespace App\Http\Controllers\Studio;
use App\Http\Controllers\Controller;
use App\Models\Artwork;
use App\Models\ArtworkVersion;
use App\Models\Category;
use App\Models\ContentType;
use App\Models\ArtworkVersion;
use App\Services\ArtworkEvolutionService;
use App\Services\Cdn\ArtworkCdnPurgeService;
use App\Services\ArtworkSearchIndexer;
use App\Notifications\NewArtworkReviewNotification;
use App\Repositories\Uploads\ArtworkFileRepository;
use App\Services\ArtworkAttributionService;
use App\Services\ArtworkEvolutionService;
use App\Services\Artworks\ArtworkCategoryService;
use App\Services\Artworks\ArtworkPublicationService;
use App\Services\TagService;
use App\Services\ArtworkSearchIndexer;
use App\Services\ArtworkVersioningService;
use App\Services\Cdn\ArtworkCdnPurgeService;
use App\Services\Moderation\ArtworkUploadPolicy;
use App\Services\Studio\StudioArtworkQueryService;
use App\Services\Studio\StudioBulkActionService;
use App\Support\ArtworkDescriptionContentValidator;
use App\Services\Tags\TagDiscoveryService;
use App\Services\TagService;
use App\Services\Uploads\UploadDerivativesService;
use App\Services\Uploads\UploadStorageService;
use App\Services\Worlds\WorldSubmissionService;
use App\Support\ArtworkDescriptionContentValidator;
use Carbon\Carbon;
use Illuminate\Http\JsonResponse;
use Illuminate\Http\Request;
use Illuminate\Http\UploadedFile;
use Illuminate\Support\Facades\Log;
use Illuminate\Support\Facades\File;
use Illuminate\Support\Facades\Log;
use Illuminate\Support\Facades\Notification;
use Illuminate\Support\Facades\Validator;
use Illuminate\Validation\ValidationException;
use Symfony\Component\HttpKernel\Exception\TooManyRequestsHttpException;
@@ -45,6 +52,7 @@ final class StudioArtworksApiController extends Controller
private readonly TagService $tagService,
private readonly ArtworkCdnPurgeService $cdnPurge,
private readonly ArtworkPublicationService $artworkPublication,
private readonly ArtworkCategoryService $artworkCategories,
) {}
/**
@@ -127,7 +135,7 @@ final class StudioArtworksApiController extends Controller
* PUT /api/studio/artworks/{id}
* Update artwork details (title, description, visibility).
*/
public function update(Request $request, int $id, ArtworkAttributionService $attribution, WorldSubmissionService $submissions): JsonResponse
public function update(Request $request, int $id, ArtworkAttributionService $attribution, WorldSubmissionService $submissions, ArtworkUploadPolicy $uploadPolicy): JsonResponse
{
$artwork = $request->user()->artworks()->findOrFail($id);
$evolution = app(ArtworkEvolutionService::class);
@@ -141,6 +149,9 @@ final class StudioArtworksApiController extends Controller
'publish_at' => 'sometimes|nullable|string|date',
'timezone' => 'sometimes|nullable|string|max:64',
'category_id' => 'sometimes|nullable|integer|exists:categories,id',
'primary_category_id' => 'sometimes|nullable|integer|exists:categories,id',
'secondary_category_ids' => 'sometimes|array|max:'.(int) config('categories.max_secondary_categories', 5),
'secondary_category_ids.*' => 'integer|exists:categories,id',
'content_type_id' => 'sometimes|nullable|integer|exists:content_types,id',
'tags' => 'sometimes|array|max:'.(int) config('tags.max_user_tags', 30),
'tags.*' => 'string|max:64',
@@ -210,14 +221,18 @@ final class StudioArtworksApiController extends Controller
// Extract tags and category before updating core fields
$tags = $validated['tags'] ?? null;
$categoryId = $validated['category_id'] ?? null;
$categoryId = $validated['primary_category_id'] ?? $validated['category_id'] ?? null;
$secondaryCategoryIds = array_key_exists('secondary_category_ids', $validated)
? array_values(array_map('intval', $validated['secondary_category_ids'] ?? []))
: [];
$hasSecondaryCategoryUpdate = array_key_exists('secondary_category_ids', $validated);
$contentTypeId = $validated['content_type_id'] ?? null;
$evolutionPayload = [
'target_artwork_id' => $validated['evolution_target_artwork_id'] ?? null,
'relation_type' => $validated['evolution_relation_type'] ?? null,
'note' => $validated['evolution_note'] ?? null,
];
unset($validated['tags'], $validated['category_id'], $validated['content_type_id'], $validated['visibility'], $validated['mode'], $validated['publish_at'], $validated['timezone'], $validated['group'], $validated['primary_author_user_id'], $validated['contributor_user_ids'], $validated['contributor_credits'], $validated['world_submissions']);
unset($validated['tags'], $validated['category_id'], $validated['primary_category_id'], $validated['secondary_category_ids'], $validated['content_type_id'], $validated['visibility'], $validated['mode'], $validated['publish_at'], $validated['timezone'], $validated['group'], $validated['primary_author_user_id'], $validated['contributor_user_ids'], $validated['contributor_credits'], $validated['world_submissions']);
unset($validated['evolution_target_artwork_id'], $validated['evolution_relation_type'], $validated['evolution_note']);
$validated['visibility'] = $visibility;
@@ -231,9 +246,17 @@ final class StudioArtworksApiController extends Controller
$validated['artwork_status'] = 'scheduled';
} else {
$validated['is_public'] = $visibility !== Artwork::VISIBILITY_PRIVATE;
$validated['is_approved'] = true;
$policy = $uploadPolicy->assess($request->user(), $artwork);
$validated['is_approved'] = ! $policy['requires_review'];
$validated['approval_source'] = $policy['requires_review'] ? null : 'trusted_auto';
$validated['publish_at'] = null;
$validated['artwork_status'] = 'published';
$validated['artwork_status'] = $policy['requires_review'] ? 'review' : 'published';
if ($policy['requires_review']) {
$validated['is_public'] = false;
$validated['published_at'] = null;
$validated['moderation_note'] = implode(', ', $policy['reasons']);
}
if (($validated['is_public'] ?? false) && ! $artwork->published_at) {
$validated['published_at'] = now();
@@ -249,10 +272,19 @@ final class StudioArtworksApiController extends Controller
}
$artwork->update($validated);
$requiresReview = ($policy['requires_review'] ?? false) === true;
// Sync category
if ($categoryId !== null) {
$artwork->categories()->sync([(int) $categoryId]);
if ($categoryId !== null || $hasSecondaryCategoryUpdate) {
try {
$this->artworkCategories->sync(
$artwork,
$categoryId !== null ? (int) $categoryId : (int) $artwork->primary_category_id,
$hasSecondaryCategoryUpdate ? $secondaryCategoryIds : ($categoryId !== null ? [] : null),
(string) ($validated['category_source'] ?? $artwork->category_source ?? 'manual'),
);
} catch (ValidationException $exception) {
return response()->json(['errors' => $exception->errors()], 422);
}
}
// Sync tags through the shared tag service so pivot source/usage rules stay valid.
@@ -291,12 +323,28 @@ final class StudioArtworksApiController extends Controller
// Reindex in Meilisearch — dispatches IndexArtworkJob which writes directly, no Scout hop.
$this->searchIndexer->update($artwork);
if ($requiresReview) {
$notifyEmail = trim((string) config('uploads.moderation.notify_email', ''));
if ($notifyEmail !== '') {
try {
Notification::route('mail', $notifyEmail)->notify(
new NewArtworkReviewNotification($artwork, $request->user(), $policy['reasons'])
);
} catch (\Throwable) {
// Keep the artwork private if notification delivery fails.
}
}
}
// Reload relationships for response
$artwork->load(['categories.contentType', 'tags', 'group', 'primaryAuthor.profile', 'contributors.user.profile']);
$primaryCategory = $artwork->categories->first();
$artwork->load(['categories.contentType', 'primaryCategory.contentType', 'tags', 'group', 'primaryAuthor.profile', 'contributors.user.profile']);
$primaryCategory = $artwork->resolvedPrimaryCategory();
return response()->json([
'success' => true,
'status' => $requiresReview ? 'submitted_for_review' : 'published',
'message' => $requiresReview ? 'Artwork saved and queued for moderation.' : 'Artwork updated successfully.',
'review_reasons' => $requiresReview ? $policy['reasons'] : [],
'artwork' => [
'id' => $artwork->id,
'title' => $artwork->title,
@@ -318,6 +366,13 @@ final class StudioArtworksApiController extends Controller
])->values()->all(),
'content_type_id' => $primaryCategory?->contentType?->id,
'category_id' => $primaryCategory?->id,
'primary_category_id' => $primaryCategory?->id,
'secondary_category_ids' => $artwork->categories
->reject(fn ($category): bool => (int) $category->id === (int) ($primaryCategory?->id ?? 0))
->pluck('id')
->map(fn ($id): int => (int) $id)
->values()
->all(),
'tags' => $artwork->tags->map(fn ($t) => ['id' => $t->id, 'name' => $t->name, 'slug' => $t->slug])->values()->all(),
'title_source' => $artwork->title_source ?: 'manual',
'description_source' => $artwork->description_source ?: 'manual',
@@ -461,8 +516,8 @@ final class StudioArtworksApiController extends Controller
'artwork_status' => $artwork->artwork_status,
'created_at' => $artwork->created_at?->toIso8601String(),
'deleted_at' => $artwork->deleted_at?->toIso8601String(),
'category' => $artwork->categories->first()?->name,
'category_slug' => $artwork->categories->first()?->slug,
'category' => $artwork->resolvedPrimaryCategory()?->name,
'category_slug' => $artwork->resolvedPrimaryCategory()?->slug,
'tags' => $artwork->tags->pluck('slug')->values()->all(),
'views' => (int) ($stats?->views ?? 0),
'favourites' => (int) ($stats?->favorites ?? 0),
@@ -523,9 +578,9 @@ final class StudioArtworksApiController extends Controller
}
try {
$derivatives = app(\App\Services\Uploads\UploadDerivativesService::class);
$storage = app(\App\Services\Uploads\UploadStorageService::class);
$artworkFiles = app(\App\Repositories\Uploads\ArtworkFileRepository::class);
$derivatives = app(UploadDerivativesService::class);
$storage = app(UploadStorageService::class);
$artworkFiles = app(ArtworkFileRepository::class);
// 1. Store original on disk (preserve extension when possible)
$originalAsset = $derivatives->storeOriginal($tempPath, $hash);
@@ -610,6 +665,7 @@ final class StudioArtworksApiController extends Controller
'artwork_id' => $artwork->id,
'error' => $e->getMessage(),
]);
return response()->json(['success' => false, 'error' => 'File processing failed: '.$e->getMessage()], 500);
}
}
@@ -678,8 +734,8 @@ final class StudioArtworksApiController extends Controller
return response()->json(['success' => false, 'error' => $e->getMessage()], 429);
}
$derivatives = app(\App\Services\Uploads\UploadDerivativesService::class);
$storage = app(\App\Services\Uploads\UploadStorageService::class);
$derivatives = app(UploadDerivativesService::class);
$storage = app(UploadStorageService::class);
$cleanupLocalPaths = [];
$cleanupObjectPaths = [];
@@ -918,7 +974,8 @@ final class StudioArtworksApiController extends Controller
// Reindex
try {
$this->searchIndexer->update($artwork);
} catch (\Throwable) {}
} catch (\Throwable) {
}
return response()->json([
'success' => true,
@@ -938,7 +995,7 @@ final class StudioArtworksApiController extends Controller
* This is best-effort; failures are logged but never fatal.
* Configure a CDN purge webhook via ARTWORK_CDN_PURGE_URL if needed.
*/
private function purgeCdnCache(\App\Models\Artwork $artwork, string $oldHash): void
private function purgeCdnCache(Artwork $artwork, string $oldHash): void
{
try {
$this->cdnPurge->purgeArtworkHashVariants($oldHash, 'webp', ['xs', 'sm', 'md', 'lg', 'xl', 'sq'], [
@@ -5,26 +5,27 @@ declare(strict_types=1);
namespace App\Http\Controllers\Studio;
use App\Http\Controllers\Controller;
use App\Models\Group;
use App\Models\ContentType;
use App\Models\Group;
use App\Services\ArtworkEvolutionService;
use App\Services\Artworks\ArtworkPublicationService;
use App\Services\GroupMembershipService;
use App\Services\GroupService;
use App\Services\Studio\CreatorStudioActivityService;
use App\Services\Studio\CreatorStudioAnalyticsService;
use App\Services\Studio\CreatorStudioAssetService;
use App\Services\Studio\CreatorStudioCalendarService;
use App\Services\Studio\CreatorStudioChallengeService;
use App\Services\Studio\CreatorStudioCommentService;
use App\Services\Studio\CreatorStudioContentService;
use App\Services\Studio\CreatorStudioFollowersService;
use App\Services\Studio\CreatorStudioGrowthService;
use App\Services\Studio\CreatorStudioActivityService;
use App\Services\Studio\CreatorStudioInboxService;
use App\Services\Studio\CreatorStudioOverviewService;
use App\Services\Studio\CreatorStudioPreferenceService;
use App\Services\Studio\CreatorStudioChallengeService;
use App\Services\Studio\CreatorStudioSearchService;
use App\Services\Studio\CreatorStudioScheduledService;
use App\Services\Studio\CreatorStudioSearchService;
use App\Services\Uploads\UploadQueueService;
use App\Services\Worlds\WorldSubmissionService;
use App\Support\CoverUrl;
use Illuminate\Http\RedirectResponse;
@@ -132,7 +133,7 @@ final class StudioController extends Controller
public function uploadQueue(Request $request): Response
{
$queue = app(\App\Services\Uploads\UploadQueueService::class)->listPayload(
$queue = app(UploadQueueService::class)->listPayload(
$request->user(),
$request->only(['batch_id', 'status', 'sort'])
);
@@ -449,13 +450,13 @@ final class StudioController extends Controller
{
$user = $request->user();
$artwork = $user->artworks()
->with(['stats', 'categories.contentType', 'tags', 'artworkAiAssist', 'group.members', 'primaryAuthor.profile', 'contributors.user.profile'])
->with(['stats', 'categories.contentType', 'primaryCategory.contentType', 'tags', 'artworkAiAssist', 'group.members', 'primaryAuthor.profile', 'contributors.user.profile'])
->findOrFail($id);
$artwork = app(ArtworkPublicationService::class)->publishIfDue($artwork);
$artwork->loadMissing(['stats', 'categories.contentType', 'tags', 'artworkAiAssist', 'group.members', 'primaryAuthor.profile', 'contributors.user.profile']);
$artwork->loadMissing(['stats', 'categories.contentType', 'primaryCategory.contentType', 'tags', 'artworkAiAssist', 'group.members', 'primaryAuthor.profile', 'contributors.user.profile']);
$primaryCategory = $artwork->categories->first();
$primaryCategory = $artwork->resolvedPrimaryCategory();
$availableGroups = app(GroupService::class)->studioOptionsForUser($user);
$membershipService = app(GroupMembershipService::class);
$contributorOptionsByGroup = [];
@@ -503,9 +504,17 @@ final class StudioController extends Controller
])->values()->all(),
'content_type_id' => $primaryCategory?->contentType?->id,
'category_id' => $primaryCategory?->id,
'primary_category_id' => $primaryCategory?->id,
'parent_category_id' => $primaryCategory?->parent_id ? $primaryCategory->parent_id : $primaryCategory?->id,
'sub_category_id' => $primaryCategory?->parent_id ? $primaryCategory->id : null,
'categories' => $artwork->categories->map(fn ($c) => ['id' => $c->id, 'name' => $c->name, 'slug' => $c->slug])->values()->all(),
'secondary_category_ids' => $artwork->categories
->reject(fn ($category): bool => (int) $category->id === (int) ($primaryCategory?->id ?? 0))
->pluck('id')
->map(fn ($id): int => (int) $id)
->values()
->all(),
'max_secondary_categories' => (int) config('categories.max_secondary_categories', 5),
'categories' => $artwork->categories->map(fn ($c) => ['id' => $c->id, 'name' => $c->name, 'slug' => $c->slug, 'is_primary' => (int) $c->id === (int) ($primaryCategory?->id ?? 0)])->values()->all(),
'tags' => $artwork->tags->map(fn ($t) => ['id' => $t->id, 'name' => $t->name, 'slug' => $t->slug])->values()->all(),
'ai_status' => $artwork->ai_status,
'title_source' => $artwork->title_source ?: 'manual',
+356 -130
View File
@@ -25,44 +25,49 @@ use App\Models\GroupReleaseContributor;
use App\Models\ProfileComment;
use App\Models\Story;
use App\Models\User;
use Carbon\CarbonInterface;
use App\Services\Security\CaptchaVerifier;
use App\Services\AvatarService;
use App\Services\ArtworkService;
use App\Services\FollowService;
use App\Services\AchievementService;
use App\Services\ArtworkService;
use App\Services\AvatarService;
use App\Services\CollectionService;
use App\Services\FollowAnalyticsService;
use App\Services\LeaderboardService;
use App\Services\UserSuggestionService;
use App\Services\Countries\CountryCatalogService;
use App\Services\FollowAnalyticsService;
use App\Services\FollowService;
use App\Services\LeaderboardService;
use App\Services\Maturity\ArtworkMaturityService;
use App\Services\ThumbnailPresenter;
use App\Services\Worlds\WorldRewardService;
use App\Services\XPService;
use App\Services\UsernameApprovalService;
use App\Services\Profile\CreatorJourneyService;
use App\Services\Profile\WorldProfileHistoryService;
use App\Services\Security\CaptchaVerifier;
use App\Services\ThumbnailPresenter;
use App\Services\UsernameApprovalService;
use App\Services\UserStatsService;
use App\Services\UserSuggestionService;
use App\Services\Worlds\WorldRewardService;
use App\Services\XPService;
use App\Support\AvatarUrl;
use App\Support\CoverUrl;
use App\Support\Seo\SeoFactory;
use App\Support\UsernamePolicy;
use Carbon\Carbon;
use Carbon\CarbonInterface;
use Illuminate\Http\JsonResponse;
use Illuminate\Http\RedirectResponse;
use Illuminate\Http\Request;
use Illuminate\Support\Collection;
use Illuminate\Support\Facades\Auth;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Redirect;
use Illuminate\Support\Facades\Schema;
use Illuminate\View\View;
use Illuminate\Support\Facades\Hash;
use Illuminate\Support\Facades\Mail;
use Illuminate\Support\Facades\Redirect;
use Illuminate\Support\Facades\Schema;
use Illuminate\Support\Facades\Storage;
use Illuminate\Validation\Rules\Password as PasswordRule;
use Illuminate\View\View;
use Inertia\Inertia;
class ProfileController extends Controller
{
private const SSR_WORLD_HISTORY_TABS = ['achievements', 'worlds'];
private const PROFILE_TABS = [
'posts',
'artworks',
@@ -74,6 +79,7 @@ class ProfileController extends Controller
'stats',
'favourites',
'activity',
'followers',
];
public function __construct(
@@ -92,9 +98,7 @@ class ProfileController extends Controller
private readonly CreatorJourneyService $creatorJourney,
private readonly WorldRewardService $worldRewards,
private readonly WorldProfileHistoryService $worldProfileHistory,
)
{
}
) {}
public function showByUsername(Request $request, string $username)
{
@@ -188,6 +192,44 @@ class ProfileController extends Controller
return $this->renderProfilePage($request, $user, 'Profile/ProfileShow', false, $normalizedTab);
}
/**
* Read-only featured artwork payload for the client-side Artworks tab.
* This deliberately does not render the profile document or track a view.
*/
public function featuredArtworks(Request $request, string $username): JsonResponse
{
$normalized = UsernamePolicy::normalize($username);
$user = User::query()->whereRaw('LOWER(username) = ?', [$normalized])->first();
if (! $user) {
return response()->json(['error' => 'User not found'], 404);
}
return response()->json([
'data' => $this->loadFeaturedArtworks($user, $request->user())->values(),
]);
}
/**
* Read-only world history payload for profile tabs that are loaded client-side.
* This deliberately does not render the profile document or track a view.
*/
public function worldHistory(Request $request, string $username): JsonResponse
{
$normalized = UsernamePolicy::normalize($username);
$user = User::query()->whereRaw('LOWER(username) = ?', [$normalized])->first();
if (! $user) {
return response()->json(['error' => 'User not found'], 404);
}
$isOwner = Auth::check() && Auth::id() === $user->id;
return response()->json($isOwner
? $this->worldProfileHistory->ownerPayloadForUser($user)
: $this->worldProfileHistory->publicPayloadForUser($user));
}
public function legacyById(Request $request, int $id, ?string $username = null)
{
$user = User::query()->findOrFail($id);
@@ -200,6 +242,28 @@ class ProfileController extends Controller
return redirect()->route('profile.show', ['username' => UsernamePolicy::normalize($username)], 301);
}
/**
* Legacy "All followers" URL from old profile templates:
* GET /following/{id}/{slug?} → /@{canonical-username}/followers
*/
public function legacyFollowingById(Request $request, int $id, ?string $slug = null)
{
$user = User::query()->find($id);
if (! $user) {
abort(404);
}
$url = url('/@'.strtolower((string) $user->username).'/followers');
$query = $request->query();
if ($query !== []) {
$url .= '?'.http_build_query($query);
}
return redirect()->to($url, 301);
}
/** Toggle follow/unfollow for the profile of $username (auth required). */
public function toggleFollow(Request $request, string $username): JsonResponse
{
@@ -284,27 +348,49 @@ class ProfileController extends Controller
$profile = DB::table('user_profiles')->where('user_id', $user->id)->first();
if ($profile) {
$profileData = (array) $profile;
if (isset($profile->website)) $user->homepage = $profile->website;
if (isset($profile->about)) $user->about_me = $profile->about;
if (isset($profile->birthdate)) $user->birth = $profile->birthdate;
if (isset($profile->gender)) $user->gender = $profile->gender;
if (isset($profile->country_code)) $user->country_code = $profile->country_code;
if (isset($profile->signature)) $user->signature = $profile->signature;
if (isset($profile->description)) $user->description = $profile->description;
if (isset($profile->mlist)) $user->mlist = $profile->mlist;
if (isset($profile->friend_upload_notice)) $user->friend_upload_notice = $profile->friend_upload_notice;
if (isset($profile->auto_post_upload)) $user->auto_post_upload = $profile->auto_post_upload;
if (isset($profile->website)) {
$user->homepage = $profile->website;
}
if (isset($profile->about)) {
$user->about_me = $profile->about;
}
if (isset($profile->birthdate)) {
$user->birth = $profile->birthdate;
}
if (isset($profile->gender)) {
$user->gender = $profile->gender;
}
if (isset($profile->country_code)) {
$user->country_code = $profile->country_code;
}
if (isset($profile->signature)) {
$user->signature = $profile->signature;
}
if (isset($profile->description)) {
$user->description = $profile->description;
}
if (isset($profile->mlist)) {
$user->mlist = $profile->mlist;
}
if (isset($profile->friend_upload_notice)) {
$user->friend_upload_notice = $profile->friend_upload_notice;
}
if (isset($profile->auto_post_upload)) {
$user->auto_post_upload = $profile->auto_post_upload;
}
}
} catch (\Throwable $e) {}
}
} catch (\Throwable $e) {
}
if (! empty($user->birth)) {
try {
$dt = \Carbon\Carbon::parse($user->birth);
$dt = Carbon::parse($user->birth);
$birthDay = $dt->format('d');
$birthMonth = $dt->format('m');
$birthYear = $dt->format('Y');
} catch (\Throwable $e) {}
} catch (\Throwable $e) {
}
}
$selectedCountry = $this->countryCatalog->resolveUserCountry($user);
@@ -568,8 +654,8 @@ class ProfileController extends Controller
'country_code' => $selectedCountry?->iso2,
];
if (!empty($validated['gender'])) {
$profileUpdates['gender'] = strtoupper((string) $validated['gender']);
if (array_key_exists('gender', $validated)) {
$profileUpdates['gender'] = $this->normalizeProfileGender($validated['gender'] ?? null);
}
$this->persistProfileUpdates((int) $request->user()->id, $profileUpdates);
@@ -653,6 +739,29 @@ class ProfileController extends Controller
DB::table('user_profiles')->updateOrInsert(['user_id' => $userId], $filtered);
}
/**
* Normalize gender to the MySQL enum values used by user_profiles.gender.
*/
private function normalizeProfileGender(mixed $value): ?string
{
if ($value === null) {
return null;
}
$normalized = strtolower(trim((string) $value));
if ($normalized === '') {
return null;
}
return match ($normalized) {
'm', 'male', 'man', 'boy' => 'M',
'f', 'female', 'woman', 'girl' => 'F',
'x', 'n', 'na', 'n/a', 'nonbinary', 'non-binary', 'prefer_not_to_say', 'prefer not to say' => 'X',
default => null,
};
}
private function resolveCountrySelection(int|string|null $countryId = null, ?string $countryCode = null): ?Country
{
if (is_numeric($countryId) && (int) $countryId > 0) {
@@ -736,7 +845,7 @@ class ProfileController extends Controller
);
}
public function update(ProfileUpdateRequest $request, \App\Services\AvatarService $avatarService): RedirectResponse|JsonResponse
public function update(ProfileUpdateRequest $request, AvatarService $avatarService): RedirectResponse|JsonResponse
{
$user = $request->user();
@@ -763,6 +872,7 @@ class ProfileController extends Controller
if ($request->expectsJson()) {
return response()->json(['errors' => $error], 422);
}
return Redirect::back()->withErrors($error);
}
@@ -775,6 +885,7 @@ class ProfileController extends Controller
if ($request->expectsJson()) {
return response()->json(['errors' => $error], 422);
}
return Redirect::back()->withErrors($error);
}
@@ -797,7 +908,9 @@ class ProfileController extends Controller
$user->save();
$profileUpdates = [];
if (!empty($validated['about'])) $profileUpdates['about'] = $validated['about'];
if (! empty($validated['about'])) {
$profileUpdates['about'] = $validated['about'];
}
if (! empty($validated['web'])) {
$profileUpdates['website'] = $validated['web'];
@@ -812,10 +925,8 @@ class ProfileController extends Controller
$profileUpdates['birthdate'] = sprintf('%04d-%02d-%02d', (int) $year, (int) $month, (int) $day);
}
if (!empty($validated['gender'])) {
$g = strtolower($validated['gender']);
$map = ['m' => 'M', 'f' => 'F', 'n' => 'X', 'x' => 'X'];
$profileUpdates['gender'] = $map[$g] ?? strtoupper($validated['gender']);
if (array_key_exists('gender', $validated)) {
$profileUpdates['gender'] = $this->normalizeProfileGender($validated['gender'] ?? null);
}
if (array_key_exists('country_id', $validated) || array_key_exists('country', $validated)) {
@@ -839,10 +950,16 @@ class ProfileController extends Controller
$profileUpdates['auto_post_upload'] = filter_var($validated['auto_post_upload'], FILTER_VALIDATE_BOOLEAN) ? 1 : 0;
}
if (isset($validated['signature'])) $profileUpdates['signature'] = $validated['signature'];
if (isset($validated['description'])) $profileUpdates['description'] = $validated['description'];
if (isset($validated['signature'])) {
$profileUpdates['signature'] = $validated['signature'];
}
if (isset($validated['description'])) {
$profileUpdates['description'] = $validated['description'];
}
if (isset($validated['about'])) $profileUpdates['about'] = $validated['about'];
if (isset($validated['about'])) {
$profileUpdates['about'] = $validated['about'];
}
if ($request->hasFile('avatar')) {
try {
@@ -851,6 +968,7 @@ class ProfileController extends Controller
if ($request->expectsJson()) {
return response()->json(['errors' => ['avatar' => ['Avatar processing failed: '.$e->getMessage()]]], 422);
}
return Redirect::back()->with('error', 'Avatar processing failed: '.$e->getMessage());
}
}
@@ -862,10 +980,11 @@ class ProfileController extends Controller
if (in_array($file->getMimeType(), $allowedImageMimes, true)) {
$ext = $file->guessExtension() ?: 'jpg';
$fname = $user->id.'_emoticon_'.time().'.'.$ext;
\Illuminate\Support\Facades\Storage::disk('public')->putFileAs('user-emoticons/'.$user->id, $file, $fname);
Storage::disk('public')->putFileAs('user-emoticons/'.$user->id, $file, $fname);
try {
\Illuminate\Support\Facades\DB::table('users')->where('id', $user->id)->update(['eicon' => $fname]);
} catch (\Exception $e) {}
DB::table('users')->where('id', $user->id)->update(['eicon' => $fname]);
} catch (\Exception $e) {
}
}
}
@@ -874,25 +993,26 @@ class ProfileController extends Controller
if (in_array($file->getMimeType(), $allowedImageMimes, true)) {
$ext = $file->guessExtension() ?: 'jpg';
$fname = $user->id.'_photo_'.time().'.'.$ext;
\Illuminate\Support\Facades\Storage::disk('public')->putFileAs('user-picture/'.$user->id, $file, $fname);
if (\Illuminate\Support\Facades\Schema::hasTable('user_profiles')) {
Storage::disk('public')->putFileAs('user-picture/'.$user->id, $file, $fname);
if (Schema::hasTable('user_profiles')) {
$profileUpdates['cover_image'] = $fname;
} else {
try {
\Illuminate\Support\Facades\DB::table('users')->where('id', $user->id)->update(['picture' => $fname]);
} catch (\Exception $e) {}
DB::table('users')->where('id', $user->id)->update(['picture' => $fname]);
} catch (\Exception $e) {
}
}
}
}
try {
if (\Illuminate\Support\Facades\Schema::hasTable('user_profiles')) {
if (Schema::hasTable('user_profiles')) {
if (! empty($profileUpdates)) {
\Illuminate\Support\Facades\DB::table('user_profiles')->updateOrInsert(['user_id' => $user->id], $profileUpdates);
DB::table('user_profiles')->updateOrInsert(['user_id' => $user->id], $profileUpdates);
}
} else {
if (! empty($profileUpdates)) {
\Illuminate\Support\Facades\DB::table('users')->where('id', $user->id)->update($profileUpdates);
DB::table('users')->where('id', $user->id)->update($profileUpdates);
}
}
} catch (\Exception $e) {
@@ -953,8 +1073,7 @@ class ProfileController extends Controller
string $component = 'Profile/ProfileShow',
bool $galleryOnly = false,
?string $initialTab = null,
)
{
) {
$isOwner = Auth::check() && Auth::id() === $user->id;
$viewer = Auth::user();
$perPage = 24;
@@ -966,51 +1085,21 @@ class ProfileController extends Controller
});
// ── Featured artworks for this user ─────────────────────────────────
$featuredArtworks = collect();
if (Schema::hasTable('artwork_features')) {
$featuredQuery = Artwork::query()
->with([
'user:id,name,username,level,rank',
'user.profile:user_id,avatar_hash',
'group:id,name,slug,avatar_path',
'stats:artwork_id,views,downloads,favorites',
'categories' => function ($query) {
$query->select('categories.id', 'categories.content_type_id', 'categories.parent_id', 'categories.name', 'categories.slug', 'categories.sort_order')
->with(['parent:id,parent_id,content_type_id,name,slug', 'contentType:id,slug,name']);
},
])
->join('artwork_features as af', 'af.artwork_id', '=', 'artworks.id')
->where('artworks.user_id', $user->id)
->where('af.is_active', true)
->whereNull('af.deleted_at')
->whereNull('artworks.deleted_at')
->where('artworks.is_public', true)
->where('artworks.is_approved', true)
->whereNotNull('artworks.published_at')
->select(['artworks.*', 'af.label as featured_label', 'af.featured_at as featured_slot_at'])
->orderByDesc('af.featured_at')
->limit(3);
$featuredArtworks = $initialTab === 'artworks'
? $this->loadFeaturedArtworks($user, $viewer)
: null;
app(ArtworkMaturityService::class)->applyViewerFilter($featuredQuery, $viewer);
$featuredArtworks = $featuredQuery
->get()
->map(function (Artwork $artwork) {
return (object) array_merge($this->mapArtworkCardPayload($artwork), [
'label' => $artwork->featured_label,
'featured_at' => $this->formatIsoDate($artwork->featured_slot_at),
]);
});
}
// ── Favourites ───────────────────────────────────────────────────────
// ── Favourites (only needed for the direct Favourites tab) ───────────
$favourites = null;
if ($initialTab === 'favourites') {
$favouriteLimit = 12;
$favouriteTable = $this->resolveFavouriteTable();
$favourites = [
'data' => [],
'next_cursor' => null,
];
if ($favouriteTable !== null) {
}
if ($favourites !== null && $favouriteTable !== null) {
$favIds = DB::table($favouriteTable.' as af')
->join('artworks as a', 'a.id', '=', 'af.artwork_id')
->where('af.user_id', $user->id)
@@ -1223,8 +1312,11 @@ class ProfileController extends Controller
'published_at' => $story->published_at?->toISOString(),
]);
$profileCollectionsPayload = null;
if ($initialTab === 'collections') {
$profileCollections = $this->collections->getProfileCollections($user, $viewer);
$profileCollectionsPayload = $this->collections->mapCollectionCardPayloads($profileCollections, $isOwner, $viewer);
}
// ── Profile data ─────────────────────────────────────────────────────
$profile = $user->profile;
@@ -1243,7 +1335,8 @@ class ProfileController extends Controller
if (! $isOwner) {
try {
$this->userStats->incrementProfileViews($user->id);
} catch (\Throwable) {}
} catch (\Throwable) {
}
}
// ── Normalise artworks for JSON serialisation ────────────────────
@@ -1260,7 +1353,7 @@ class ProfileController extends Controller
// ── Auth context for JS ───────────────────────────────────────────
$authData = null;
if (Auth::check()) {
/** @var \App\Models\User $authUser */
/** @var User $authUser */
$authUser = Auth::user();
$authAvatarUrl = AvatarUrl::forUser((int) $authUser->id, $authUser->profile?->avatar_hash, 64);
$authData = [
@@ -1281,9 +1374,11 @@ class ProfileController extends Controller
->all();
$achievementSummary = $this->achievements->summary((int) $user->id);
$worldRewardSummary = $this->worldRewards->summaryForUser($user);
$worldHistory = $isOwner
$worldHistory = in_array($initialTab, self::SSR_WORLD_HISTORY_TABS, true)
? ($isOwner
? $this->worldProfileHistory->ownerPayloadForUser($user)
: $this->worldProfileHistory->publicPayloadForUser($user);
: $this->worldProfileHistory->publicPayloadForUser($user))
: null;
$leaderboardRank = $this->leaderboards->creatorRankSummary((int) $user->id);
$groupContributionHistory = $this->buildGroupContributionHistory($user);
$journey = $this->creatorJourney->publicPayloadForUser($user);
@@ -1293,9 +1388,37 @@ class ProfileController extends Controller
? ($profileTabUrls[$resolvedInitialTab] ?? $canonical)
: $canonical;
$tabMetaLabel = $resolvedInitialTab !== null
? ucfirst($resolvedInitialTab)
? ($resolvedInitialTab === 'followers' ? 'Followers' : ucfirst($resolvedInitialTab))
: null;
$followersListing = null;
if (! $galleryOnly && $resolvedInitialTab === 'followers') {
$followersPage = max(1, (int) $request->query('page', 1));
$followersListing = [
'data' => [],
'current_page' => $followersPage,
'last_page' => 1,
'per_page' => 24,
'total' => 0,
'next_page_url' => null,
'prev_page_url' => null,
];
if (Schema::hasTable('user_followers')) {
$followersPaginator = $this->followService->paginatedFollowers((int) $user->id, 24, $followersPage);
$followersListing = [
'data' => array_values($followersPaginator->items()),
'current_page' => $followersPaginator->currentPage(),
'last_page' => $followersPaginator->lastPage(),
'per_page' => $followersPaginator->perPage(),
'total' => $followersPaginator->total(),
'next_page_url' => $followersPaginator->nextPageUrl(),
'prev_page_url' => $followersPaginator->previousPageUrl(),
];
}
}
$pageTitle = $galleryOnly
? (($user->username ?? $user->name ?? 'User').' Gallery on Skinbase')
: ($isTabLanding
@@ -1303,9 +1426,11 @@ class ProfileController extends Controller
: (($user->username ?? $user->name ?? 'User').' on Skinbase'));
$pageDescription = $galleryOnly
? ('Browse the public gallery of '.($user->username ?? $user->name).' on Skinbase.')
: ($resolvedInitialTab === 'followers'
? ('People who follow '.($user->username ?? $user->name).' on Skinbase.')
: ($isTabLanding
? ('Explore the '.strtolower((string) $tabMetaLabel).' section for '.($user->username ?? $user->name).' on Skinbase.')
: ('View the profile of ' . ($user->username ?? $user->name) . ' on Skinbase — artworks, favourites and more.'));
: ('View the profile of '.($user->username ?? $user->name).' on Skinbase — artworks, favourites and more.')));
$profileSeo = app(SeoFactory::class)->profilePage(
$pageTitle,
$galleryOnly ? $galleryUrl : $activeProfileUrl,
@@ -1344,12 +1469,13 @@ class ProfileController extends Controller
'cover_image' => $profile->cover_image ?? null,
] : null,
'artworks' => $artworkPayload,
'featuredArtworks' => $featuredArtworks->values(),
'featuredArtworks' => $featuredArtworks?->values(),
'favourites' => $favourites,
'stats' => $statsPayload,
'socialLinks' => $socialLinks,
'followerCount' => $followerCount,
'recentFollowers' => $recentFollowers->values(),
'followersListing' => $followersListing,
'followContext' => $followContext,
'followAnalytics' => $followAnalytics,
'suggestedUsers' => $suggestedUsers,
@@ -1386,6 +1512,50 @@ class ProfileController extends Controller
]);
}
/**
* Build the canonical featured artwork representation shared by SSR and
* the lazy Artworks-tab endpoint.
*/
private function loadFeaturedArtworks(User $user, ?User $viewer): ?Collection
{
if (! Schema::hasTable('artwork_features')) {
return collect();
}
$featuredQuery = Artwork::query()
->with([
'user:id,name,username,level,rank',
'user.profile:user_id,avatar_hash',
'group:id,name,slug,avatar_path',
'stats:artwork_id,views,downloads,favorites',
'categories' => function ($query) {
$query->select('categories.id', 'categories.content_type_id', 'categories.parent_id', 'categories.name', 'categories.slug', 'categories.sort_order')
->with(['parent:id,parent_id,content_type_id,name,slug', 'contentType:id,slug,name']);
},
])
->join('artwork_features as af', 'af.artwork_id', '=', 'artworks.id')
->where('artworks.user_id', $user->id)
->where('af.is_active', true)
->whereNull('af.deleted_at')
->whereNull('artworks.deleted_at')
->where('artworks.is_public', true)
->where('artworks.is_approved', true)
->whereNotNull('artworks.published_at')
->select(['artworks.*', 'af.label as featured_label', 'af.featured_at as featured_slot_at'])
->orderByDesc('af.featured_at')
->limit(3);
app(ArtworkMaturityService::class)->applyViewerFilter($featuredQuery, $viewer);
return $featuredQuery->get()
->map(function (Artwork $artwork) {
return (object) array_merge($this->mapArtworkCardPayload($artwork), [
'label' => $artwork->featured_label,
'featured_at' => $this->formatIsoDate($artwork->featured_slot_at),
]);
});
}
private function normalizeProfileTab(mixed $tab): ?string
{
if (! is_string($tab)) {
@@ -1413,7 +1583,7 @@ class ProfileController extends Controller
private function buildGroupContributionHistory(User $user): array
{
return GroupContributorStat::query()
$stats = GroupContributorStat::query()
->with(['group.owner.profile'])
->where('user_id', $user->id)
->whereHas('group', fn ($query) => $query
@@ -1422,29 +1592,60 @@ class ProfileController extends Controller
->orderByDesc('release_count')
->orderByDesc('credited_artworks_count')
->limit(8)
->get();
$groupIds = $stats->pluck('group_id')->map(static fn ($id): int => (int) $id)->values()->all();
if ($groupIds === []) {
return [];
}
$membershipsByGroup = GroupMember::query()
->whereIn('group_id', $groupIds)
->where('user_id', $user->id)
->where('status', Group::STATUS_ACTIVE)
->get()
->map(function (GroupContributorStat $stat) use ($user): ?array {
->keyBy('group_id');
$releaseRolesByGroup = GroupReleaseContributor::query()
->join('group_releases as bulk_releases', 'bulk_releases.id', '=', 'group_release_contributors.group_release_id')
->where('group_release_contributors.user_id', $user->id)
->whereIn('bulk_releases.group_id', $groupIds)
->whereNull('bulk_releases.deleted_at')
->orderBy('group_release_contributors.id')
->get([
'bulk_releases.group_id',
'group_release_contributors.role_label',
])
->groupBy('group_id');
$projectRolesByGroup = GroupProjectMember::query()
->join('group_projects as bulk_projects', 'bulk_projects.id', '=', 'group_project_members.group_project_id')
->where('group_project_members.user_id', $user->id)
->whereIn('bulk_projects.group_id', $groupIds)
->whereNull('bulk_projects.deleted_at')
->orderBy('group_project_members.id')
->get([
'bulk_projects.group_id',
'group_project_members.role_label',
])
->groupBy('group_id');
$recentReleasesByGroup = $this->loadRecentGroupReleaseTitles($user, $groupIds);
return $stats
->map(function (GroupContributorStat $stat) use ($user, $membershipsByGroup, $releaseRolesByGroup, $projectRolesByGroup, $recentReleasesByGroup): ?array {
$group = $stat->group;
if (! $group) {
return null;
}
$member = GroupMember::query()
->where('group_id', $group->id)
->where('user_id', $user->id)
->where('status', Group::STATUS_ACTIVE)
->first();
$groupId = (int) $group->id;
$member = $membershipsByGroup->get($groupId);
$roleLabels = collect()
->merge(GroupReleaseContributor::query()
->where('user_id', $user->id)
->whereHas('release', fn ($query) => $query->where('group_id', $group->id))
->pluck('role_label'))
->merge(GroupProjectMember::query()
->where('user_id', $user->id)
->whereHas('project', fn ($query) => $query->where('group_id', $group->id))
->pluck('role_label'))
->merge($releaseRolesByGroup->get($groupId, collect())->pluck('role_label'))
->merge($projectRolesByGroup->get($groupId, collect())->pluck('role_label'))
->filter()
->map(fn ($label): string => trim((string) $label))
->filter()
@@ -1452,21 +1653,7 @@ class ProfileController extends Controller
->values()
->all();
$recentReleaseTitles = GroupRelease::query()
->where('group_id', $group->id)
->where('visibility', GroupRelease::VISIBILITY_PUBLIC)
->where(function ($query) use ($user): void {
$query->where('lead_user_id', $user->id)
->orWhere('created_by_user_id', $user->id)
->orWhereHas('contributorLinks', fn ($contributorQuery) => $contributorQuery->where('user_id', $user->id));
})
->orderByDesc('released_at')
->latest('updated_at')
->limit(3)
->pluck('title')
->map(fn ($title): string => (string) $title)
->values()
->all();
$recentReleaseTitles = $recentReleasesByGroup->get($groupId, collect())->all();
$joinedAt = $group->isOwnedBy($user)
? $group->created_at?->toISOString()
@@ -1503,6 +1690,45 @@ class ProfileController extends Controller
->all();
}
/**
* Load the same top-three public releases per group as the previous
* per-group LIMIT query, while keeping the existing two-column ordering.
*
* @param array<int, int> $groupIds
* @return Collection<int, Collection<int, string>>
*/
private function loadRecentGroupReleaseTitles(User $user, array $groupIds): Collection
{
$eligibleReleases = GroupRelease::query()
->whereIn('group_id', $groupIds)
->where('visibility', GroupRelease::VISIBILITY_PUBLIC)
->where(function ($query) use ($user): void {
$query->where('lead_user_id', $user->id)
->orWhere('created_by_user_id', $user->id)
->orWhereHas('contributorLinks', fn ($contributorQuery) => $contributorQuery->where('user_id', $user->id));
})
->select(['id', 'group_id', 'title', 'released_at', 'updated_at']);
$ranked = DB::query()
->fromSub($eligibleReleases, 'eligible_group_releases')
->select([
'group_id',
'title',
'released_at',
'updated_at',
])
->selectRaw('ROW_NUMBER() OVER (PARTITION BY group_id ORDER BY released_at DESC, updated_at DESC) as release_rank');
return DB::query()
->fromSub($ranked, 'ranked_group_releases')
->where('release_rank', '<=', 3)
->orderBy('group_id')
->orderBy('release_rank')
->get(['group_id', 'title'])
->groupBy('group_id')
->map(fn ($rows) => $rows->pluck('title')->map(fn ($title): string => (string) $title)->values());
}
private function resolveFavouriteTable(): ?string
{
foreach (['artwork_favourites', 'user_favorites', 'artworks_favourites', 'favourites'] as $table) {
@@ -1520,7 +1746,7 @@ class ProfileController extends Controller
private function mapArtworkCardPayload(Artwork $art): array
{
$present = ThumbnailPresenter::present($art, 'md');
$category = $art->categories->first();
$category = $art->resolvedPrimaryCategory();
$contentType = $category?->contentType;
$stats = $art->stats;
$group = $art->group;
@@ -3,7 +3,10 @@
namespace App\Http\Controllers\User;
use App\Http\Controllers\Controller;
use App\Models\Artwork;
use App\Models\ArtworkDownload;
use App\Services\ThumbnailPresenter;
use App\Support\AvatarUrl;
use Carbon\Carbon;
use Illuminate\Http\Request;
use Illuminate\Support\Str;
@@ -54,7 +57,7 @@ class TodayDownloadsController extends Controller
$paginator->getCollection()->transform(function ($row) {
$art = $row->artwork ?? null;
if (! $art && isset($row->artwork_id)) {
$art = \App\Models\Artwork::find($row->artwork_id);
$art = Artwork::find($row->artwork_id);
}
if (! $art) {
@@ -75,9 +78,9 @@ class TodayDownloadsController extends Controller
$picture = $art->file_name ?? null;
$ext = pathinfo($picture ?? '', PATHINFO_EXTENSION) ?: 'jpg';
$encoded = null;
$present = $art ? \App\Services\ThumbnailPresenter::present($art, 'md') : null;
$present = $art ? ThumbnailPresenter::present($art, 'md') : null;
$thumb = $present ? $present['url'] : 'https://files.skinbase.org/default/missing_md.webp';
$primaryCategory = $art->categories->first();
$primaryCategory = $art->resolvedPrimaryCategory();
$categoryId = $primaryCategory->id ?? null;
$categoryName = $primaryCategory->name ?? '';
$categorySlug = $primaryCategory->slug ?? '';
@@ -98,7 +101,7 @@ class TodayDownloadsController extends Controller
'category_slug' => $categorySlug,
'uname' => $art->user->name ?? 'Skinbase',
'username' => $art->user->username ?? '',
'avatar_url' => \App\Support\AvatarUrl::forUser((int) ($art->user->id ?? 0), $avatarHash, 64),
'avatar_url' => AvatarUrl::forUser((int) ($art->user->id ?? 0), $avatarHash, 64),
'width' => $art->width,
'height' => $art->height,
'published_at' => $art->published_at,
@@ -8,20 +8,19 @@ use App\Enums\ReactionType;
use App\Http\Controllers\Controller;
use App\Http\Resources\ArtworkResource;
use App\Models\Artwork;
use App\Models\ArtworkComment;
use Illuminate\Support\Facades\DB;
use App\Services\ContentSanitizer;
use App\Services\ThumbnailPresenter;
use App\Models\Category;
use App\Services\ArtworkNavigationService;
use App\Services\ArtworkRelatedService;
use App\Services\ErrorSuggestionService;
use App\Services\GroupService;
use App\Services\Maturity\ArtworkMaturityService;
use App\Services\ThumbnailPresenter;
use App\Support\Seo\SeoFactory;
use App\Support\AvatarUrl;
use Illuminate\Support\Carbon;
use Illuminate\Support\Collection;
use Illuminate\Http\RedirectResponse;
use Illuminate\Http\Request;
use Illuminate\Http\Response;
use Illuminate\Support\Collection;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Str;
use Illuminate\View\View;
use Inertia\Inertia;
@@ -32,6 +31,8 @@ final class ArtworkPageController extends Controller
public function __construct(
private readonly GroupService $groups,
private readonly ArtworkMaturityService $maturity,
private readonly ArtworkNavigationService $navigation,
private readonly ArtworkRelatedService $relatedArtworks,
) {}
public function show(Request $request, int $id, ?string $slug = null): View|RedirectResponse|Response|InertiaResponse
@@ -42,6 +43,7 @@ final class ArtworkPageController extends Controller
if (! $raw) {
// Artwork never existed → contextual 404
$suggestions = app(ErrorSuggestionService::class);
return response(view('errors.contextual.artwork-not-found', [
'trendingArtworks' => $this->safeSuggestions(fn () => $suggestions->trendingArtworks()),
]), 404);
@@ -76,8 +78,9 @@ final class ArtworkPageController extends Controller
->limit(6)
->get()
->map(function (Artwork $a) {
$slug = \Illuminate\Support\Str::slug((string) ($a->slug ?: $a->title)) ?: (string) $a->id;
$md = \App\Services\ThumbnailPresenter::present($a, 'md');
$slug = Str::slug((string) ($a->slug ?: $a->title)) ?: (string) $a->id;
$md = ThumbnailPresenter::present($a, 'md');
return [
'id' => $a->id,
'title' => html_entity_decode((string) $a->title, ENT_QUOTES | ENT_HTML5, 'UTF-8'),
@@ -98,14 +101,21 @@ final class ArtworkPageController extends Controller
]), 403);
}
// ── Step 2: full load with all relations ───────────────────────────
$artwork = Artwork::with(['user.profile', 'group.owner.profile', 'uploadedBy.profile', 'primaryAuthor.profile', 'contributors.user.profile', 'categories.contentType', 'categories.parent.contentType', 'tags', 'stats', 'awardStat'])
->where('id', $id)
->public()
->published()
->firstOrFail();
// ── Step 2: hydrate the already-validated model ────────────────────
// The initial withTrashed lookup is intentionally retained so that
// missing, deleted, private, and unpublished artwork keep their
// distinct responses. Reusing that model avoids a second identical
// primary-key lookup on the public path.
$artwork = $raw;
$artwork->load(['user.profile', 'group.owner.profile', 'uploadedBy.profile', 'primaryAuthor.profile', 'contributors.user.profile', 'categories.contentType', 'categories.parent.contentType', 'primaryCategory.contentType', 'primaryCategory.parent.contentType', 'tags', 'stats', 'awardStat']);
$this->loadCategoryAncestors($artwork->categories);
$this->loadCategoryAncestors(
$artwork->categories
->concat(collect([$artwork->resolvedPrimaryCategory()]))
->filter()
->unique('id')
->values()
);
$canonicalSlug = Str::slug((string) ($artwork->slug ?: $artwork->title));
if ($canonicalSlug === '') {
@@ -119,12 +129,15 @@ final class ArtworkPageController extends Controller
], 301);
}
$thumbMd = ThumbnailPresenter::present($artwork, 'md');
$thumbLg = ThumbnailPresenter::present($artwork, 'lg');
$thumbXl = ThumbnailPresenter::present($artwork, 'xl');
$thumbSq = ThumbnailPresenter::present($artwork, 'sq');
$artworkData = (new ArtworkResource($artwork))->toArray($request);
$navigationData = $this->navigation->navigationFor($artwork);
// ArtworkResource is the canonical thumbnail projection. Reuse its
// exact values for page props and SEO instead of presenting each
// variant a second time in the controller.
$thumbMd = $artworkData['thumbs']['md'] ?? [];
$thumbLg = $artworkData['thumbs']['lg'] ?? [];
$thumbXl = $artworkData['thumbs']['xl'] ?? [];
$thumbSq = $artworkData['thumbs']['sq'] ?? [];
$groupSummary = null;
if ($artwork->group) {
@@ -151,37 +164,7 @@ final class ArtworkPageController extends Controller
'xl' => $thumbXl,
], $canonical, $this->artworkBreadcrumbs($artwork, $canonical))->toArray();
$categoryIds = $artwork->categories->pluck('id')->filter()->values();
$tagIds = $artwork->tags->pluck('id')->filter()->values();
$related = Artwork::query()
->with(['user', 'group', 'categories.contentType'])
->whereKeyNot($artwork->id)
->public()
->published()
->tap(fn ($builder) => $this->maturity->applyViewerFilter($builder, $request->user()))
->where(function ($query) use ($artwork, $categoryIds, $tagIds): void {
$query->where('user_id', $artwork->user_id);
if ($artwork->group_id) {
$query->orWhere('group_id', $artwork->group_id);
}
if ($categoryIds->isNotEmpty()) {
$query->orWhereHas('categories', function ($categoryQuery) use ($categoryIds): void {
$categoryQuery->whereIn('categories.id', $categoryIds->all());
});
}
if ($tagIds->isNotEmpty()) {
$query->orWhereHas('tags', function ($tagQuery) use ($tagIds): void {
$tagQuery->whereIn('tags.id', $tagIds->all());
});
}
})
->latest('published_at')
->limit(12)
->get()
$related = $this->relatedArtworks->related($artwork, $request->user(), 12)
->map(function (Artwork $item): array {
$itemSlug = Str::slug((string) ($item->slug ?: $item->title));
if ($itemSlug === '') {
@@ -206,84 +189,21 @@ final class ArtworkPageController extends Controller
->values()
->all();
$approvedComments = ArtworkComment::query()
->with('user.profile')
->where('artwork_id', $artwork->id)
->where('is_approved', true)
->orderBy('created_at')
->limit(500)
->get();
$commentsByParent = $approvedComments->groupBy(
static fn (ArtworkComment $comment): string => $comment->parent_id === null
? 'root'
: (string) $comment->parent_id
);
// Recursive helper to format a comment and its nested replies.
$formatComment = null;
$formatComment = function (ArtworkComment $c) use (&$formatComment, $commentsByParent): array {
/** @var Collection<int, ArtworkComment> $replies */
$replies = $commentsByParent->get((string) $c->id, collect());
$user = $c->user;
$userId = (int) ($c->user_id ?? 0);
$avatarHash = $user?->profile?->avatar_hash ?? null;
$canPublishLinks = (int) ($user?->level ?? 1) > 1 && strtolower((string) ($user?->rank ?? 'Newbie')) !== 'newbie';
$rawContent = (string) ($c->raw_content ?? $c->content ?? '');
$renderedContent = $c->rendered_content;
if (! is_string($renderedContent) || trim($renderedContent) === '') {
$renderedContent = $rawContent !== ''
? ContentSanitizer::render($rawContent)
: nl2br(e(strip_tags((string) ($c->content ?? ''))));
}
return [
'id' => $c->id,
'parent_id' => $c->parent_id,
'content' => html_entity_decode((string) $c->content, ENT_QUOTES | ENT_HTML5, 'UTF-8'),
'raw_content' => $c->raw_content ?? $c->content,
'rendered_content' => ContentSanitizer::sanitizeRenderedHtml($renderedContent, $canPublishLinks),
'created_at' => $c->created_at?->toIso8601String(),
'time_ago' => $c->created_at ? Carbon::parse($c->created_at)->diffForHumans() : null,
'user' => [
'id' => $userId,
'name' => $user?->name,
'username' => $user?->username,
'display' => $user?->username ?? $user?->name ?? 'User',
'profile_url' => $user?->username ? '/@' . $user->username : ($userId > 0 ? '/profile/' . $userId : null),
'avatar_url' => $avatarHash !== null
? AvatarUrl::forUser($userId, $avatarHash, 64)
: AvatarUrl::default(),
'level' => (int) ($user?->level ?? 1),
'rank' => (string) ($user?->rank ?? 'Newbie'),
],
'replies' => $replies->map($formatComment)->values()->all(),
];
};
$comments = $commentsByParent
->get('root', collect())
->map($formatComment)
->values()
->all();
$canReadSession = $request->hasSession() && ! $request->attributes->get('skinbase.session_skipped');
$userId = ($canReadSession && $request->user() !== null) ? (int) $request->user()->id : null;
$viewerId = ($canReadSession && $request->user() !== null) ? (int) $request->user()->id : null;
return Inertia::render('ArtworkPage', [
'artwork' => $artworkData,
'navigation' => $navigationData,
'presentMd' => $thumbMd,
'presentLg' => $thumbLg,
'presentXl' => $thumbXl,
'presentSq' => $thumbSq,
'related' => $related,
'canonicalUrl' => $canonical,
'comments' => $comments,
'groupSummary' => $groupSummary,
'isAuthenticated' => $userId !== null,
'reactionTotals' => $this->artworkReactionTotals((int) $artwork->id, $userId),
'isAuthenticated' => $viewerId !== null,
'reactionTotals' => $this->artworkReactionTotals((int) $artwork->id, $viewerId),
'seo' => $seo,
])->rootView('artworks.show');
}
@@ -343,7 +263,7 @@ final class ArtworkPageController extends Controller
->values();
if ($missingParentIds->isNotEmpty()) {
$fetchedParents = \App\Models\Category::query()
$fetchedParents = Category::query()
->with('contentType')
->whereIn('id', $missingParentIds->all())
->get()
@@ -369,12 +289,7 @@ final class ArtworkPageController extends Controller
*/
private function artworkBreadcrumbs(Artwork $artwork, string $canonical): array
{
$primaryCategory = $artwork->categories
->sortBy(fn ($category) => [
(int) ($category->sort_order ?? 0),
(string) ($category->name ?? ''),
])
->first();
$primaryCategory = $artwork->resolvedPrimaryCategory();
if ($primaryCategory === null) {
return [
@@ -11,6 +11,7 @@ use App\Services\GroupDiscoveryService;
use Illuminate\Database\Eloquent\Collection as EloquentCollection;
use Illuminate\Http\RedirectResponse;
use Illuminate\Http\Request;
use Illuminate\Http\Response;
use Illuminate\Support\Arr;
use Illuminate\View\View;
use cPad\Plugins\News\Models\NewsArticle;
@@ -19,6 +20,12 @@ final class SearchController extends Controller
{
private const ALLOWED_SORTS = ['latest', 'popular', 'likes', 'downloads'];
/** Reject requests with an absurd number of query params before touching search/DB. */
private const MAX_QUERY_PARAMS = 15;
/** Reject requests with an absurdly long query string before touching search/DB. */
private const MAX_QUERY_STRING_LENGTH = 500;
public function __construct(
private readonly ArtworkSearchService $search,
private readonly GroupDiscoveryService $groups,
@@ -26,6 +33,8 @@ final class SearchController extends Controller
public function index(Request $request): View|RedirectResponse
{
$this->rejectMalformedQuery($request);
$canonicalQuery = $this->canonicalQueryParameters($request);
$canonicalUrl = $this->canonicalSearchUrl($request, $canonicalQuery);
@@ -110,6 +119,21 @@ final class SearchController extends Controller
]);
}
/**
* Bail out before any search/DB work for junk requests — e.g. scripted
* floods that repeat/nest query params (group=all&page=..&sort=.. etc.).
*/
private function rejectMalformedQuery(Request $request): void
{
$query = $request->query();
if (count($query) > self::MAX_QUERY_PARAMS
|| strlen((string) $request->getQueryString()) > self::MAX_QUERY_STRING_LENGTH
) {
abort(Response::HTTP_BAD_REQUEST);
}
}
/**
* @return array<string, int|string>
*/
@@ -171,16 +171,13 @@ final class SimilarArtworksPageController extends Controller
*/
private function resolveSimilarArtworks(Artwork $source, int $page, string $baseUrl): array
{
// Priority 1 — Qdrant visual (vision) similarity
// Priority 1 — Qdrant visual (vision) similarity.
// Paginate IDs before hydrating/presenting full Artwork models so a
// request only pays the relation/presenter cost for the current page.
if ($this->vectors->isConfigured()) {
$qdrantItems = $this->resolveViaQdrant($source);
if ($qdrantItems !== null && $qdrantItems->isNotEmpty()) {
$paginator = $this->paginateCollection(
$qdrantItems->map(fn ($a) => $this->presentArtwork($a)),
$page,
$baseUrl,
);
return [$paginator, 'visual'];
$qdrantPaginator = $this->resolveViaQdrant($source, $page, $baseUrl);
if ($qdrantPaginator !== null && $qdrantPaginator->total() > 0) {
return [$qdrantPaginator, 'visual'];
}
}
@@ -192,38 +189,77 @@ final class SimilarArtworksPageController extends Controller
$page,
$baseUrl,
);
return [$paginator, 'hybrid'];
}
// Priority 3 — Meilisearch tag/category overlap
$paginator = $this->meilisearchFallback($source, $page);
return [$paginator, 'tags'];
}
/**
* Query Qdrant via VectorGateway, then re-hydrate full Artwork models
* (so we have category/dimension data for the masonry grid).
* Query Qdrant via VectorGateway, preserve relevance order, then paginate
* candidate IDs before hydrating full Artwork models for the current page.
*
* Returns null when the gateway call fails, so the caller can fall through.
* The light eligibility query keeps the existing public/published semantics
* for cached Qdrant results without loading relations for every candidate.
* Returns null when the gateway call fails or no eligible candidates remain,
* allowing the caller to continue to the existing hybrid/tag fallbacks.
*/
private function resolveViaQdrant(Artwork $source): ?Collection
{
private function resolveViaQdrant(
Artwork $source,
int $page,
string $baseUrl,
): ?LengthAwarePaginator {
try {
$raw = $this->vectors->similarToArtwork($source, self::QDRANT_LIMIT);
} catch (RuntimeException) {
return null;
}
if (empty($raw)) {
if ($raw === []) {
return null;
}
// Preserve Qdrant relevance order; IDs are already filtered to public+published
$orderedIds = array_column($raw, 'id');
// Preserve Qdrant relevance order while normalising IDs defensively.
$orderedIds = collect(array_column($raw, 'id'))
->map(static fn ($id): int => is_numeric($id) ? (int) $id : 0)
->filter(static fn (int $id): bool => $id > 0 && $id !== (int) $source->id)
->unique()
->values();
if ($orderedIds->isEmpty()) {
return null;
}
// Keep cached Qdrant results honest if an artwork has since become
// private/unpublished. Fetch IDs only; do not hydrate relations yet.
$eligibleSet = Artwork::query()
->whereIn('id', $orderedIds->all())
->public()
->published()
->pluck('id')
->mapWithKeys(static fn ($id): array => [(int) $id => true]);
$eligibleIds = $orderedIds
->filter(static fn (int $id): bool => $eligibleSet->has($id))
->values();
if ($eligibleIds->isEmpty()) {
return null;
}
$perPage = self::PER_PAGE;
$total = $eligibleIds->count();
$pageIds = $eligibleIds->forPage($page, $perPage)->values();
$items = collect();
if ($pageIds->isNotEmpty()) {
$artworks = Artwork::query()
->whereIn('id', $orderedIds)
->where('id', '!=', $source->id) // belt-and-braces exclusion
->whereIn('id', $pageIds->all())
->public()
->published()
->with([
@@ -236,12 +272,25 @@ final class SimilarArtworksPageController extends Controller
->get()
->keyBy('id');
return collect($orderedIds)
$items = $pageIds
->map(fn (int $id) => $artworks->get($id))
->filter()
->map(fn (Artwork $artwork) => $this->presentArtwork($artwork))
->values();
}
return new LengthAwarePaginator(
$items,
$total,
$perPage,
$page,
[
'path' => $baseUrl,
'query' => [],
],
);
}
/**
* Meilisearch tag-overlap query with category fallback.
*/
+43
View File
@@ -0,0 +1,43 @@
<?php
declare(strict_types=1);
namespace App\Http\Middleware;
use Closure;
use Illuminate\Http\Request;
use Symfony\Component\HttpFoundation\Response;
/**
* Negligible-overhead request duration header for production HTTP profiling.
* Does not log queries or payloads.
*/
final class AddServerTiming
{
public function handle(Request $request, Closure $next): Response
{
$started = hrtime(true);
$response = $next($request);
$durationMs = (hrtime(true) - $started) / 1_000_000;
if (headers_sent()) {
return $response;
}
$metrics = ['app;desc="Laravel";dur='.number_format($durationMs, 1, '.', '')];
$ssrMs = $request->attributes->get('http.ssr_ms');
if (is_numeric($ssrMs) && (float) $ssrMs >= 0) {
$metrics[] = 'ssr;desc="Inertia SSR";dur='.number_format((float) $ssrMs, 1, '.', '');
}
$metric = implode(', ', $metrics);
$existing = $response->headers->get('Server-Timing');
$response->headers->set(
'Server-Timing',
$existing ? $existing.', '.$metric : $metric,
);
return $response;
}
}
@@ -0,0 +1,65 @@
<?php
namespace App\Http\Middleware;
use Closure;
use cPad\Plugins\Forum\Services\Security\BotProtectionService;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Http;
use Symfony\Component\HttpFoundation\Response;
class CommentCaptchaMiddleware
{
public function __construct(private readonly BotProtectionService $botProtection) {}
public function handle(Request $request, Closure $next): Response
{
if (! (bool) config('comment_spam.captcha.enabled', false)) {
return $next($request);
}
$assessment = $this->botProtection->assess($request, 'comment_create');
if ((bool) ($assessment['blocked'] ?? false)) {
return response()->json(['message' => 'Suspicious activity detected.', 'errors' => ['bot' => ['Suspicious activity detected.']]], 429);
}
$threshold = (int) config('comment_spam.captcha.threshold', 40);
if ((int) ($assessment['risk_score'] ?? 0) < $threshold) {
return $next($request);
}
$token = (string) ($request->input('comment-turnstile-response') ?: $request->header('X-Turnstile-Token', ''));
$valid = false;
if ($token !== '') {
try {
$valid = (bool) Http::asForm()->timeout(5)->post(
(string) config('comment_spam.captcha.verify_url'),
['secret' => (string) config('comment_spam.captcha.secret_key'), 'response' => $token, 'remoteip' => $request->ip()],
)->json('success', false);
} catch (\Throwable) {
$valid = (bool) config('comment_spam.captcha.fail_open', false);
}
}
if ($valid) {
return $next($request);
}
$payload = [
'message' => 'Complete the captcha challenge to continue.',
'errors' => ['captcha' => ['Complete the captcha challenge to continue.']],
'requires_captcha' => true,
'captcha' => [
'provider' => 'turnstile',
'siteKey' => (string) config('comment_spam.captcha.site_key'),
'inputName' => 'comment-turnstile-response',
'scriptUrl' => (string) config('comment_spam.captcha.script_url'),
],
'captcha_provider' => 'turnstile',
'captcha_site_key' => (string) config('comment_spam.captcha.site_key'),
'captcha_input' => 'comment-turnstile-response',
'captcha_script_url' => (string) config('comment_spam.captcha.script_url'),
];
return response()->json($payload, 422);
}
}
+10 -3
View File
@@ -98,6 +98,15 @@ final class HandleInertiaRequests extends Middleware
? $request->session()->get($key)
: null;
if ($user !== null && ! $user->relationLoaded('profile')) {
$user->load('profile');
}
$studioGroups = [];
if ($user !== null && str_starts_with($request->path(), 'studio')) {
$studioGroups = app(GroupService::class)->studioOptionsForUser($user);
}
return array_merge(parent::share($request), [
'auth' => [
'user' => $user ? [
@@ -134,9 +143,7 @@ final class HandleInertiaRequests extends Middleware
'group_assets' => (bool) config('features.group_assets', true),
'group_activity_feed' => (bool) config('features.group_activity_feed', true),
],
'studio_groups' => $user
? app(GroupService::class)->studioOptionsForUser($user)
: [],
'studio_groups' => $studioGroups,
]);
}
}
@@ -0,0 +1,74 @@
<?php
declare(strict_types=1);
namespace App\Http\Middleware;
use App\Support\Http\HttpUriNormalizer;
use Closure;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Log;
use Inertia\Support\Header as InertiaHeader;
use Symfony\Component\HttpFoundation\Response;
final class LogSlowHttpRequest
{
public function __construct(private readonly HttpUriNormalizer $uris)
{
}
public function handle(Request $request, Closure $next): Response
{
if (! (bool) config('http_observability.slow_request.enabled', false)) {
return $next($request);
}
$started = hrtime(true);
$response = $next($request);
$durationMs = (hrtime(true) - $started) / 1_000_000;
if (app()->environment('testing')) {
$override = config('http_observability.slow_request.test_duration_ms');
if (is_numeric($override)) {
$durationMs = (float) $override;
}
}
$threshold = max(1, (int) config('http_observability.slow_request.threshold_ms', 750));
if ($durationMs < $threshold) {
return $response;
}
$route = $request->route();
$routeUri = is_object($route) && method_exists($route, 'uri')
? (string) $route->uri()
: $this->uris->normalize($request->path());
$payload = [
'time' => now()->toIso8601String(),
'method' => $request->getMethod(),
'route_name' => is_object($route) ? $route->getName() : null,
'route_uri' => $routeUri,
'status' => $response->getStatusCode(),
'duration_ms' => round($durationMs, 1),
'peak_memory_mb' => round(memory_get_peak_usage(true) / 1048576, 2),
'authenticated' => $request->user() !== null,
'inertia' => $this->isInertia($request, $response),
];
Log::channel('slow-http')->info(json_encode($payload, JSON_UNESCAPED_SLASHES));
return $response;
}
private function isInertia(Request $request, Response $response): bool
{
if ($request->headers->has(InertiaHeader::INERTIA)) {
return true;
}
return $response->headers->has(InertiaHeader::INERTIA)
|| $response->headers->get('Vary') === 'X-Inertia'
|| str_contains((string) $response->headers->get('Vary'), 'X-Inertia');
}
}
@@ -69,6 +69,13 @@ final class TrackOnlineVisitor
'email/*',
'logout',
'up',
'rss/*',
'rss-feeds',
'robots.txt',
'sitemap.xml',
'sitemaps/*',
'download/artwork/*',
'photo/*',
])) {
return false;
}
@@ -27,6 +27,9 @@ final class ArtworkCreateRequest extends FormRequest
'title' => 'required|string|max:150',
'description' => 'nullable|string',
'category' => 'nullable|integer|exists:categories,id',
'primary_category_id' => 'nullable|integer|exists:categories,id',
'secondary_category_ids' => 'nullable|array|max:'.(int) config('categories.max_secondary_categories', 5),
'secondary_category_ids.*' => 'integer|exists:categories,id',
'tags' => 'nullable|string|max:200',
'license' => 'nullable|boolean',
'is_mature' => 'nullable|boolean',
@@ -45,7 +48,7 @@ final class ArtworkCreateRequest extends FormRequest
private function denyAsNotFound(): void
{
throw new NotFoundHttpException();
throw new NotFoundHttpException;
}
private function logUnauthorized(string $reason): void
@@ -27,6 +27,9 @@ final class ApplyArtworkAiAssistRequest extends FormRequest
'tags.*' => ['string', 'max:64'],
'tag_mode' => ['sometimes', Rule::in(['add', 'replace', 'remove'])],
'category_id' => ['sometimes', 'nullable', 'integer', 'exists:categories,id'],
'primary_category_id' => ['sometimes', 'nullable', 'integer', 'exists:categories,id'],
'secondary_category_ids' => ['sometimes', 'array', 'max:'.(int) config('categories.max_secondary_categories', 5)],
'secondary_category_ids.*' => ['integer', 'exists:categories,id'],
'content_type_id' => ['sometimes', 'nullable', 'integer', 'exists:content_types,id'],
'similar_actions' => ['sometimes', 'array', 'max:10'],
'similar_actions.*.artwork_id' => ['required_with:similar_actions', 'integer'],
+60 -34
View File
@@ -1,9 +1,10 @@
<?php
namespace App\Http\Resources;
use App\Models\World;
use App\Models\WorldRelation;
use App\Models\WorldSubmission;
use App\Models\World;
use App\Services\ArtworkEvolutionService;
use App\Services\ContentSanitizer;
use App\Services\Maturity\ArtworkMaturityService;
@@ -12,15 +13,19 @@ use App\Services\Worlds\WorldRewardService;
use Illuminate\Http\Resources\Json\JsonResource;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
use Illuminate\Support\Str;
class ArtworkResource extends JsonResource
{
/** @var array<string, bool> */
private array $tablePresence = [];
/**
* Transform the resource into an array.
*/
public function toArray($request): array
{
$this->resource->loadMissing(['group', 'uploadedBy.profile', 'primaryAuthor.profile', 'contributors.user.profile', 'worldSubmissions.world', 'worldRewardGrants.world']);
$this->resource->loadMissing(['group', 'uploadedBy.profile', 'primaryAuthor.profile', 'contributors.user.profile', 'worldSubmissions.world']);
$md = ThumbnailPresenter::present($this->resource, 'md');
$lg = ThumbnailPresenter::present($this->resource, 'lg');
@@ -28,21 +33,19 @@ class ArtworkResource extends JsonResource
$sq = ThumbnailPresenter::present($this->resource, 'sq');
$screenshots = $this->resolveScreenshotAssets();
$canonicalSlug = \Illuminate\Support\Str::slug((string) ($this->slug ?: $this->title));
$canonicalSlug = Str::slug((string) ($this->slug ?: $this->title));
if ($canonicalSlug === '') {
$canonicalSlug = (string) $this->id;
}
$followerCount = 0;
if (! empty($this->user?->id)) {
if (Schema::hasTable('user_statistics')) {
$followerCount = (int) DB::table('user_statistics')
->where('user_id', (int) $this->user->id)
->value('followers_count');
}
// Legacy fallback for environments where new tables are unavailable.
if (($followerCount <= 0) && Schema::hasTable('friends_list')) {
if (($followerCount <= 0) && $this->hasTable('friends_list')) {
$followerCount = (int) DB::table('friends_list')
->where('friend_id', (int) $this->user->id)
->count();
@@ -58,24 +61,22 @@ class ArtworkResource extends JsonResource
$viewerAward = null;
$isOwner = $viewerId > 0 && $viewerId === (int) ($this->user?->id ?? 0);
$bookmarksCount = Schema::hasTable('artwork_bookmarks')
? (int) DB::table('artwork_bookmarks')->where('artwork_id', (int) $this->id)->count()
: 0;
$bookmarksCount = (int) DB::table('artwork_bookmarks')
->where('artwork_id', (int) $this->id)
->count();
if ($viewerId > 0) {
if (Schema::hasTable('artwork_likes')) {
if ($this->hasTable('artwork_likes')) {
$isLiked = DB::table('artwork_likes')
->where('user_id', $viewerId)
->where('artwork_id', (int) $this->id)
->exists();
}
if (Schema::hasTable('artwork_bookmarks')) {
$isBookmarked = DB::table('artwork_bookmarks')
->where('user_id', $viewerId)
->where('artwork_id', (int) $this->id)
->exists();
}
$isFavorited = DB::table('artwork_favourites')
->where('user_id', $viewerId)
@@ -83,12 +84,12 @@ class ArtworkResource extends JsonResource
->exists();
if (! empty($this->user?->id)) {
if (Schema::hasTable('user_followers')) {
if ($this->hasTable('user_followers')) {
$isFollowing = DB::table('user_followers')
->where('user_id', (int) $this->user->id)
->where('follower_id', $viewerId)
->exists();
} elseif (Schema::hasTable('friends_list')) {
} elseif ($this->hasTable('friends_list')) {
// Legacy fallback only.
$isFollowing = DB::table('friends_list')
->where('user_id', $viewerId)
@@ -97,14 +98,14 @@ class ArtworkResource extends JsonResource
}
}
if (!empty($this->group?->id) && Schema::hasTable('group_follows')) {
if (! empty($this->group?->id) && $this->hasTable('group_follows')) {
$isFollowingGroup = DB::table('group_follows')
->where('group_id', (int) $this->group->id)
->where('user_id', $viewerId)
->exists();
}
if (Schema::hasTable('artwork_medals')) {
if ($this->hasTable('artwork_medals')) {
$viewerAward = DB::table('artwork_medals')
->where('user_id', $viewerId)
->where('artwork_id', (int) $this->id)
@@ -176,6 +177,8 @@ class ArtworkResource extends JsonResource
'title' => $decode($this->title),
'description' => $decode($this->description),
'description_html' => $this->renderDescriptionHtml(),
'download_status' => (string) ($this->download_status ?? 'unknown'),
'download_source' => $this->download_source,
'dimensions' => [
'width' => (int) ($this->width ?? 0),
'height' => (int) ($this->height ?? 0),
@@ -255,12 +258,31 @@ class ArtworkResource extends JsonResource
'maturity' => app(ArtworkMaturityService::class)->presentation($this->resource, $request->user()),
'evolution' => app(ArtworkEvolutionService::class)->publicPayload($this->resource, $request->user()),
'world_participation' => $this->resolveWorldParticipation(),
'categories' => $this->categories->map(fn ($category) => [
'category' => ($primary = $this->resolvedPrimaryCategory()) ? [
'id' => (int) $primary->id,
'slug' => (string) $primary->slug,
'name' => html_entity_decode((string) $primary->name, ENT_QUOTES | ENT_HTML5, 'UTF-8'),
'content_type_slug' => (string) ($primary->contentType?->slug ?? ''),
'url' => $primary->contentType ? $primary->url : null,
'is_primary' => true,
] : null,
'primary_category' => ($primary = $this->resolvedPrimaryCategory()) ? [
'id' => (int) $primary->id,
'slug' => (string) $primary->slug,
'name' => html_entity_decode((string) $primary->name, ENT_QUOTES | ENT_HTML5, 'UTF-8'),
'content_type_slug' => (string) ($primary->contentType?->slug ?? ''),
'url' => $primary->contentType ? $primary->url : null,
] : null,
'categories' => $this->categories->map(function ($category) {
$primaryId = (int) ($this->primary_category_id ?? 0);
return [
'id' => (int) $category->id,
'slug' => (string) $category->slug,
'name' => html_entity_decode((string) $category->name, ENT_QUOTES | ENT_HTML5, 'UTF-8'),
'content_type_slug' => (string) ($category->contentType?->slug ?? ''),
'url' => $category->contentType ? $category->url : null,
'is_primary' => $primaryId > 0 && (int) $category->id === $primaryId,
'parent' => $category->parent ? [
'id' => (int) $category->parent->id,
'slug' => (string) $category->parent->slug,
@@ -268,7 +290,8 @@ class ArtworkResource extends JsonResource
'content_type_slug' => (string) ($category->parent->contentType?->slug ?? ''),
'url' => $category->parent->contentType ? $category->parent->url : null,
] : null,
])->values(),
];
})->values(),
'tags' => $this->tags->map(fn ($tag) => [
'id' => (int) $tag->id,
'slug' => (string) $tag->slug,
@@ -279,10 +302,6 @@ class ArtworkResource extends JsonResource
private function resolveScreenshotAssets(): array
{
if (! Schema::hasTable('artwork_files')) {
return [];
}
return DB::table('artwork_files')
->where('artwork_id', (int) $this->id)
->where('variant', 'like', 'shot%')
@@ -339,7 +358,6 @@ class ArtworkResource extends JsonResource
$items = collect();
$participationWorlds = collect();
if (Schema::hasTable('world_relations') && Schema::hasTable('worlds')) {
$relations = WorldRelation::query()
->with('world')
->where('related_type', WorldRelation::TYPE_ARTWORK)
@@ -348,7 +366,9 @@ class ArtworkResource extends JsonResource
->filter(fn (WorldRelation $relation): bool => $relation->world !== null && $relation->world->isPubliclyVisible())
->values();
$participationWorlds = $participationWorlds->concat($relations->pluck('world')->filter());
$participationWorlds = $participationWorlds->concat(
$relations->pluck('world')->filter()
);
$items = $items->concat(
$relations->map(function (WorldRelation $relation): array {
@@ -367,9 +387,7 @@ class ArtworkResource extends JsonResource
];
})
);
}
if (Schema::hasTable('world_submissions')) {
$liveSubmissions = $this->worldSubmissions
->filter(function (WorldSubmission $submission): bool {
return (string) $submission->status === WorldSubmission::STATUS_LIVE
@@ -378,8 +396,13 @@ class ArtworkResource extends JsonResource
})
->values();
$participationWorlds = $participationWorlds->concat($liveSubmissions->pluck('world')->filter());
World::primeCanonicalEditionIds($participationWorlds->pluck('recurrence_key')->all());
$participationWorlds = $participationWorlds->concat(
$liveSubmissions->pluck('world')->filter()
);
World::primeCanonicalEditionIds(
$participationWorlds->pluck('recurrence_key')->all()
);
$items = $items->concat(
$liveSubmissions->map(function (WorldSubmission $submission): array {
@@ -399,13 +422,11 @@ class ArtworkResource extends JsonResource
];
})
);
} elseif ($participationWorlds->isNotEmpty()) {
World::primeCanonicalEditionIds($participationWorlds->pluck('recurrence_key')->all());
}
if (Schema::hasTable('world_reward_grants')) {
$items = $items->concat(app(WorldRewardService::class)->artworkRewardBadges($this->resource));
}
$items = $items->concat(
app(WorldRewardService::class)
->artworkRewardBadges($this->resource)
);
return $items
->sortBy('sort_priority')
@@ -421,6 +442,11 @@ class ArtworkResource extends JsonResource
->all();
}
private function hasTable(string $table): bool
{
return $this->tablePresence[$table] ??= Schema::hasTable($table);
}
private function authorCanPublishLinks(): bool
{
$level = (int) ($this->user?->level ?? 1);
@@ -0,0 +1,27 @@
<?php
declare(strict_types=1);
namespace App\Jobs\Concerns;
/**
* M1 added $afterArtworkId to RecCompute* jobs. Payloads serialized before that
* property existed leave a typed property uninitialized on unserialize, which
* fatals on first access. Constructor defaults do not apply to unserialize.
*/
trait RestoresAfterArtworkIdCursor
{
protected function restoreAfterArtworkIdCursor(): void
{
if (! isset($this->afterArtworkId)) {
$this->afterArtworkId = null;
}
}
protected function afterArtworkId(): ?int
{
$this->restoreAfterArtworkIdCursor();
return $this->afterArtworkId;
}
}
+165 -11
View File
@@ -7,9 +7,8 @@ namespace App\Jobs;
use App\Models\Artwork;
use App\Models\ArtworkEmbedding;
use App\Services\Vision\ArtworkEmbeddingClient;
use App\Services\Vision\ArtworkVisionImageUrl;
use App\Services\Vision\ArtworkVectorIndexService;
use App\Services\Vision\VectorService;
use App\Services\Vision\ArtworkVisionImageUrl;
use Illuminate\Bus\Queueable;
use Illuminate\Contracts\Queue\ShouldQueue;
use Illuminate\Foundation\Bus\Dispatchable;
@@ -49,8 +48,7 @@ final class GenerateArtworkEmbeddingJob implements ShouldQueue
ArtworkEmbeddingClient $client,
ArtworkVisionImageUrl $imageUrlBuilder,
ArtworkVectorIndexService $vectors,
): void
{
): void {
if (! (bool) config('recommendations.embedding.enabled', true)) {
return;
}
@@ -78,17 +76,73 @@ final class GenerateArtworkEmbeddingJob implements ShouldQueue
->where('model_version', $modelVersion)
->first();
if ($existing && (string) ($existing->source_hash ?? '') === $sourceHash) {
if (
$existing
&& (string) ($existing->source_hash ?? '') === $sourceHash
&& $this->vectorIndexCoversEmbedding(
$artwork,
$existing
)
) {
return;
}
}
$lockKey = $this->lockKey($artwork->id, $model, $modelVersion);
$lockKey = $this->lockKey(
$artwork->id,
$model,
$modelVersion
);
if (! $this->acquireLock($lockKey)) {
return;
}
try {
/*
* Another worker may have generated or indexed the
* embedding between our first read and lock acquisition.
* Re-read both records under the lock.
*/
if (! $this->force) {
$artwork->refresh();
$existing = ArtworkEmbedding::query()
->where('artwork_id', $artwork->id)
->where('model', $model)
->where('model_version', $modelVersion)
->first();
if (
$existing
&& (string) ($existing->source_hash ?? '')
=== $sourceHash
) {
if (
$this->vectorIndexCoversEmbedding(
$artwork,
$existing
)
) {
return;
}
$storedVector = $this->decodeStoredVector(
$existing
);
if ($storedVector !== []) {
$this->upsertVectorIndex(
$vectors,
$artwork,
$storedVector
);
return;
}
}
}
$imageUrl = $imageUrlBuilder->fromArtwork($artwork);
if ($imageUrl === null) {
return;
@@ -121,23 +175,33 @@ final class GenerateArtworkEmbeddingJob implements ShouldQueue
]
);
$this->upsertVectorIndex($vectors, $artwork);
$this->upsertVectorIndex(
$vectors,
$artwork,
$normalized
);
} finally {
$this->releaseLock($lockKey);
}
}
/**
* @param array<int, float> $vector
*/
private function upsertVectorIndex(
ArtworkVectorIndexService $vectors,
Artwork $artwork
): void
{
Artwork $artwork,
array $vector
): void {
if (! $vectors->isConfigured()) {
return;
}
try {
$vectors->upsertArtwork($artwork);
$vectors->upsertArtworkVector(
$artwork,
$vector
);
} catch (\Throwable $e) {
Log::warning('GenerateArtworkEmbeddingJob vector upsert failed', [
'artwork_id' => (int) $artwork->id,
@@ -146,6 +210,94 @@ final class GenerateArtworkEmbeddingJob implements ShouldQueue
}
}
private function vectorIndexCoversEmbedding(
Artwork $artwork,
ArtworkEmbedding $embedding
): bool {
$indexedAt = $artwork->last_vector_indexed_at;
$generatedAt = $embedding->generated_at;
if ($indexedAt === null || $generatedAt === null) {
return false;
}
return $indexedAt->greaterThanOrEqualTo(
$generatedAt
);
}
/**
* @return array<int, float>
*/
private function decodeStoredVector(
ArtworkEmbedding $embedding
): array {
try {
$decoded = json_decode(
(string) $embedding->embedding_json,
true,
512,
JSON_THROW_ON_ERROR
);
} catch (\Throwable) {
return [];
}
if (! is_array($decoded) || $decoded === []) {
return [];
}
$vector = [];
foreach ($decoded as $value) {
if (! is_int($value) && ! is_float($value)) {
return [];
}
$value = (float) $value;
if (! is_finite($value)) {
return [];
}
$vector[] = $value;
}
$count = count($vector);
$minDim = max(
1,
(int) config(
'recommendations.embedding.min_dim',
64
)
);
$maxDim = max(
$minDim,
(int) config(
'recommendations.embedding.max_dim',
4096
)
);
if (
$count < $minDim
|| $count > $maxDim
) {
return [];
}
if (
(int) $embedding->dim > 0
&& $count !== (int) $embedding->dim
) {
return [];
}
return $vector;
}
/**
* @param array<int, float> $vector
* @return array<int, float>
@@ -162,6 +314,7 @@ final class GenerateArtworkEmbeddingJob implements ShouldQueue
}
$norm = sqrt($sumSquares);
return array_map(static fn (float $value): float => $value / $norm, $vector);
}
@@ -177,6 +330,7 @@ final class GenerateArtworkEmbeddingJob implements ShouldQueue
if ($didSet) {
Redis::expire($key, 1800);
}
return (bool) $didSet;
} catch (\Throwable) {
return true;
+15 -1
View File
@@ -6,6 +6,7 @@ namespace App\Jobs;
use App\Models\Artwork;
use Illuminate\Bus\Queueable;
use Illuminate\Contracts\Queue\ShouldBeUniqueUntilProcessing;
use Illuminate\Contracts\Queue\ShouldQueue;
use Illuminate\Foundation\Bus\Dispatchable;
use Illuminate\Queue\InteractsWithQueue;
@@ -21,16 +22,29 @@ use Meilisearch\Client as MeilisearchClient;
* after_commit double-dispatch problem and ensures the document lands
* in the index within this job's execution, with no extra queue hop.
*/
class IndexArtworkJob implements ShouldQueue
class IndexArtworkJob implements ShouldQueue, ShouldBeUniqueUntilProcessing
{
use Dispatchable, InteractsWithQueue, Queueable, SerializesModels;
public int $tries = 3;
public int $timeout = 60;
/**
* Unique while queued so Meilisearch isn't flooded. handle() loads the
* artwork from DB, so a dropped duplicate still indexes current state.
* UniqueUntilProcessing: a change after the worker starts can enqueue again.
*/
public int $uniqueFor = 120;
public function __construct(public readonly int $artworkId)
{
$this->afterCommit = true;
$this->onQueue((string) config('scout.queue.queue', 'search'));
}
public function uniqueId(): string
{
return (string) $this->artworkId;
}
public function handle(MeilisearchClient $client): void
+17 -2
View File
@@ -6,6 +6,7 @@ namespace App\Jobs;
use App\Models\User;
use Illuminate\Bus\Queueable;
use Illuminate\Contracts\Queue\ShouldBeUniqueUntilProcessing;
use Illuminate\Contracts\Queue\ShouldQueue;
use Illuminate\Foundation\Bus\Dispatchable;
use Illuminate\Queue\InteractsWithQueue;
@@ -15,14 +16,28 @@ use Illuminate\Queue\SerializesModels;
* Queued job: index (or re-index) a single User in Meilisearch.
* Dispatched by UserStatsService whenever stats change.
*/
class IndexUserJob implements ShouldQueue
class IndexUserJob implements ShouldQueue, ShouldBeUniqueUntilProcessing
{
use Dispatchable, InteractsWithQueue, Queueable, SerializesModels;
public int $tries = 3;
public int $timeout = 30;
public function __construct(public readonly int $userId) {}
/**
* Unique while queued. handle() loads the user from DB so the queued job
* still reflects later stats changes. uniqueFor covers a dead worker lock.
*/
public int $uniqueFor = 60;
public function __construct(public readonly int $userId)
{
$this->onQueue((string) config('scout.queue.queue', 'search'));
}
public function uniqueId(): string
{
return (string) $this->userId;
}
public function handle(): void
{
+5 -7
View File
@@ -4,8 +4,8 @@ declare(strict_types=1);
namespace App\Jobs;
use App\Services\Recommendations\UserInterestProfileService;
use App\Services\Recommendations\SessionRecoService;
use App\Services\Recommendations\UserInterestProfileService;
use Carbon\CarbonImmutable;
use Illuminate\Bus\Queueable;
use Illuminate\Contracts\Queue\ShouldQueue;
@@ -40,8 +40,7 @@ final class IngestUserDiscoveryEventJob implements ShouldQueue
public readonly string $algoVersion,
public readonly string $occurredAt,
public readonly array $meta = []
) {
}
) {}
public function handle(UserInterestProfileService $profileService, SessionRecoService $sessionRecoService): void
{
@@ -70,10 +69,9 @@ final class IngestUserDiscoveryEventJob implements ShouldQueue
$eventVersion = (string) config('discovery.event_version', 'event-v1');
$eventWeight = (float) ((array) config('discovery.weights', []))[$this->eventType] ?? 1.0;
$categoryId = DB::table('artwork_category')
->where('artwork_id', $this->artworkId)
->orderBy('category_id')
->value('category_id');
$categoryId = DB::table('artworks')
->where('id', $this->artworkId)
->value('primary_category_id');
$insertPayload = [
'event_id' => $this->eventId,
+16 -2
View File
@@ -6,6 +6,7 @@ namespace App\Jobs;
use App\Services\RankingService;
use Illuminate\Bus\Queueable;
use Illuminate\Contracts\Queue\ShouldBeUnique;
use Illuminate\Contracts\Queue\ShouldQueue;
use Illuminate\Foundation\Bus\Dispatchable;
use Illuminate\Queue\InteractsWithQueue;
@@ -13,19 +14,32 @@ use Illuminate\Queue\SerializesModels;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Log;
class RankBuildScopeListsJob implements ShouldQueue
class RankBuildScopeListsJob implements ShouldQueue, ShouldBeUnique
{
use Dispatchable, InteractsWithQueue, Queueable, SerializesModels;
public int $timeout = 300;
public int $tries = 2;
/**
* Unique until the job finishes or uniqueFor elapses.
* Must outlast the queue wait (hours) plus timeout (300s), not just 360s.
*/
public int $uniqueFor;
private const LIST_TYPES = ['trending', 'new_hot', 'best'];
public function __construct(
public readonly string $scopeType,
public readonly int $scopeId,
) {}
) {
$this->uniqueFor = max(3600, (int) config('ranking.scope_job_unique_for', 21600));
}
public function uniqueId(): string
{
return $this->scopeType . ':' . $this->scopeId;
}
public function handle(RankingService $ranking): void
{
+102 -9
View File
@@ -10,8 +10,10 @@ use Illuminate\Bus\Queueable;
use Illuminate\Contracts\Queue\ShouldQueue;
use Illuminate\Foundation\Bus\Dispatchable;
use Illuminate\Queue\InteractsWithQueue;
use App\Jobs\Concerns\RestoresAfterArtworkIdCursor;
use Illuminate\Queue\SerializesModels;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Log;
/**
* Compute behavior-based (co-like) similarity from precomputed item pairs.
@@ -21,38 +23,129 @@ use Illuminate\Support\Facades\DB;
*/
final class RecComputeSimilarByBehaviorJob implements ShouldQueue
{
use Dispatchable, InteractsWithQueue, Queueable, SerializesModels;
use Dispatchable, InteractsWithQueue, Queueable, RestoresAfterArtworkIdCursor;
use SerializesModels {
__unserialize as private unserializeQueuedModels;
}
public int $tries = 2;
public int $timeout = 600;
public int $timeout = 120;
private ?int $afterArtworkId = null;
public function __construct(
private readonly ?int $artworkId = null,
private readonly int $batchSize = 200,
?int $afterArtworkId = null,
) {
$this->afterArtworkId = $afterArtworkId;
$queue = (string) config('recommendations.queue', 'default');
if ($queue !== '') {
$this->onQueue($queue);
}
}
public function __unserialize(array $values): void
{
$this->unserializeQueuedModels($values);
$this->restoreAfterArtworkIdCursor();
}
public function cursorAfterArtworkId(): ?int
{
return $this->afterArtworkId();
}
public function handle(): void
{
$startedAt = microtime(true);
$modelVersion = (string) config('recommendations.similarity.model_version', 'sim_v1');
$resultLimit = (int) config('recommendations.similarity.result_limit', 30);
$maxPerAuthor = (int) config('recommendations.similarity.max_per_author', 2);
$query = Artwork::query()->public()->published()->select('id', 'user_id');
if ($this->artworkId !== null) {
$query->where('id', $this->artworkId);
$artwork = Artwork::query()->public()->published()->select('id', 'user_id')->find($this->artworkId);
if ($artwork instanceof Artwork) {
$this->processArtworkSafely($artwork, $modelVersion, $resultLimit, $maxPerAuthor);
$this->logBatchComplete($startedAt, 1, false);
return;
}
$query->chunkById($this->batchSize, function ($artworks) use ($modelVersion, $resultLimit, $maxPerAuthor) {
foreach ($artworks as $artwork) {
$this->processArtwork($artwork, $modelVersion, $resultLimit, $maxPerAuthor);
$this->logBatchComplete($startedAt, 0, false);
return;
}
});
$artworks = Artwork::query()
->public()
->published()
->select('id', 'user_id')
->when($this->afterArtworkId() !== null, fn ($query) => $query->where('id', '>', $this->afterArtworkId()))
->orderBy('id')
->limit($this->batchSize)
->get();
if ($artworks->isEmpty()) {
$this->logBatchComplete($startedAt, 0, false);
return;
}
foreach ($artworks as $artwork) {
$this->processArtworkSafely($artwork, $modelVersion, $resultLimit, $maxPerAuthor);
}
$hasMore = $artworks->count() === $this->batchSize;
if ($hasMore) {
static::dispatch(null, $this->batchSize, (int) $artworks->last()->id);
}
$this->logBatchComplete($startedAt, $artworks->count(), $hasMore);
}
public function failed(\Throwable $exception): void
{
Log::error('[RecComputeSimilarByBehavior] Job failed permanently.', [
'artwork_id' => $this->artworkId,
'batch_size' => $this->batchSize,
'after_artwork_id' => $this->afterArtworkId(),
'attempts' => $this->attempts(),
'exception_class' => $exception::class,
'exception_message' => $exception->getMessage(),
]);
}
private function processArtworkSafely(
Artwork $artwork,
string $modelVersion,
int $resultLimit,
int $maxPerAuthor,
): void {
try {
$this->processArtwork($artwork, $modelVersion, $resultLimit, $maxPerAuthor);
} catch (\Throwable $exception) {
Log::warning("[RecComputeSimilarByBehavior] Failed for artwork {$artwork->id}: {$exception->getMessage()}", [
'artwork_id' => $artwork->id,
'exception_class' => $exception::class,
]);
}
}
/**
* @param positive-int|0 $processed
*/
private function logBatchComplete(float $startedAt, int $processed, bool $hasMore): void
{
Log::info('[RecComputeSimilarByBehavior] Batch complete.', [
'artwork_id' => $this->artworkId,
'after_artwork_id' => $this->afterArtworkId(),
'processed' => $processed,
'has_more' => $hasMore,
'duration_ms' => (int) round((microtime(true) - $startedAt) * 1000),
'memory_mb' => round(memory_get_peak_usage(true) / 1048576, 1),
]);
}
private function processArtwork(
+49 -10
View File
@@ -11,7 +11,9 @@ use Illuminate\Contracts\Queue\ShouldQueue;
use Illuminate\Foundation\Bus\Dispatchable;
use Illuminate\Queue\Middleware\WithoutOverlapping;
use Illuminate\Queue\InteractsWithQueue;
use App\Jobs\Concerns\RestoresAfterArtworkIdCursor;
use Illuminate\Queue\SerializesModels;
use Illuminate\Support\Facades\Cache;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Log;
@@ -24,22 +26,44 @@ use Illuminate\Support\Facades\Log;
*/
final class RecComputeSimilarByTagsJob implements ShouldQueue
{
use Dispatchable, InteractsWithQueue, Queueable, SerializesModels;
use Dispatchable, InteractsWithQueue, Queueable, RestoresAfterArtworkIdCursor;
use SerializesModels {
__unserialize as private unserializeQueuedModels;
}
public int $tries = 2;
public int $timeout = 600;
/**
* Declared with a default so missing serialized payloads do not leave
* an uninitialized typed property. Constructor defaults are not applied
* on unserialize.
*/
private ?int $afterArtworkId = null;
public function __construct(
private readonly ?int $artworkId = null,
private readonly int $batchSize = 200,
private readonly ?int $afterArtworkId = null,
?int $afterArtworkId = null,
) {
$this->afterArtworkId = $afterArtworkId;
$queue = (string) config('recommendations.queue', 'default');
if ($queue !== '') {
$this->onQueue($queue);
}
}
public function __unserialize(array $values): void
{
$this->unserializeQueuedModels($values);
$this->restoreAfterArtworkIdCursor();
}
public function cursorAfterArtworkId(): ?int
{
return $this->afterArtworkId();
}
/**
* @return array<int, object>
*/
@@ -63,12 +87,7 @@ final class RecComputeSimilarByTagsJob implements ShouldQueue
$maxPerAuthor = (int) config('recommendations.similarity.max_per_author', 2);
$resultLimit = (int) config('recommendations.similarity.result_limit', 30);
// ── Tag IDF weights (global) ───────────────────────────────────────────
$tagFreqs = DB::table('artwork_tag')
->select('tag_id', DB::raw('COUNT(*) as cnt'))
->groupBy('tag_id')
->pluck('cnt', 'tag_id')
->all();
$tagFreqs = $this->tagFrequencies();
if ($this->artworkId !== null) {
$artwork = Artwork::query()->public()->published()->select('id', 'user_id')->find($this->artworkId);
@@ -86,7 +105,7 @@ final class RecComputeSimilarByTagsJob implements ShouldQueue
->public()
->published()
->select('id', 'user_id')
->when($this->afterArtworkId !== null, fn ($query) => $query->where('id', '>', $this->afterArtworkId))
->when($this->afterArtworkId() !== null, fn ($query) => $query->where('id', '>', $this->afterArtworkId()))
->orderBy('id')
->limit($this->batchSize)
->get();
@@ -109,13 +128,33 @@ final class RecComputeSimilarByTagsJob implements ShouldQueue
Log::error('[RecComputeSimilarByTags] Job failed permanently.', [
'artwork_id' => $this->artworkId,
'batch_size' => $this->batchSize,
'after_artwork_id' => $this->afterArtworkId,
'after_artwork_id' => $this->afterArtworkId(),
'attempts' => $this->attempts(),
'exception_class' => $exception::class,
'exception_message' => $exception->getMessage(),
]);
}
/**
* Global tag frequencies change slowly relative to batch jobs.
* Cache so each RecComputeSimilarByTagsJob batch does not re-scan artwork_tag.
*
* @return array<int|string, mixed>
*/
private function tagFrequencies(): array
{
$modelVersion = (string) config('recommendations.similarity.model_version', 'sim_v1');
$ttl = (int) config('recommendations.similarity.tag_idf_cache_ttl', 3600);
return Cache::remember('rec:tag-idf:'.$modelVersion, max(60, $ttl), function () {
return DB::table('artwork_tag')
->select('tag_id', DB::raw('COUNT(*) as cnt'))
->groupBy('tag_id')
->pluck('cnt', 'tag_id')
->all();
});
}
private function processArtworkSafely(
Artwork $artwork,
array $tagFreqs,
+62 -7
View File
@@ -11,6 +11,7 @@ use Illuminate\Contracts\Queue\ShouldQueue;
use Illuminate\Foundation\Bus\Dispatchable;
use Illuminate\Queue\Middleware\WithoutOverlapping;
use Illuminate\Queue\InteractsWithQueue;
use App\Jobs\Concerns\RestoresAfterArtworkIdCursor;
use Illuminate\Queue\SerializesModels;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Log;
@@ -24,24 +25,42 @@ use Illuminate\Support\Facades\Log;
*/
final class RecComputeSimilarHybridJob implements ShouldQueue
{
use Dispatchable, InteractsWithQueue, Queueable, SerializesModels;
use Dispatchable, InteractsWithQueue, Queueable, RestoresAfterArtworkIdCursor;
use SerializesModels {
__unserialize as private unserializeQueuedModels;
}
// This recompute is idempotent and already guards per-artwork execution.
// Keep retries to a minimum so transient failures do not turn into
// Horizon's max-attempt exception noise.
public int $tries = 1;
public int $timeout = 900;
public int $timeout = 180;
private ?int $afterArtworkId = null;
public function __construct(
private readonly ?int $artworkId = null,
private readonly int $batchSize = 200,
?int $afterArtworkId = null,
) {
$this->afterArtworkId = $afterArtworkId;
$queue = (string) config('recommendations.queue', 'default');
if ($queue !== '') {
$this->onQueue($queue);
}
}
public function __unserialize(array $values): void
{
$this->unserializeQueuedModels($values);
$this->restoreAfterArtworkIdCursor();
}
public function cursorAfterArtworkId(): ?int
{
return $this->afterArtworkId();
}
/**
* @return array<int, object>
*/
@@ -72,6 +91,8 @@ final class RecComputeSimilarHybridJob implements ShouldQueue
? (array) config('recommendations.similarity.weights_with_vector')
: (array) config('recommendations.similarity.weights_without_vector');
$startedAt = microtime(true);
if ($this->artworkId !== null) {
$artwork = Artwork::query()
->public()
@@ -80,6 +101,8 @@ final class RecComputeSimilarHybridJob implements ShouldQueue
->find($this->artworkId);
if (! $artwork instanceof Artwork) {
$this->logBatchComplete($startedAt, 0, false);
return;
}
@@ -93,16 +116,26 @@ final class RecComputeSimilarHybridJob implements ShouldQueue
$weights,
);
$this->logBatchComplete($startedAt, 1, false);
return;
}
Artwork::query()
$artworks = Artwork::query()
->public()
->published()
->select('id', 'user_id')
->chunkById($this->batchSize, function ($artworks) use (
$modelVersion, $vectorEnabled, $resultLimit, $maxPerAuthor, $minCatsTop12, $weights
) {
->when($this->afterArtworkId() !== null, fn ($query) => $query->where('id', '>', $this->afterArtworkId()))
->orderBy('id')
->limit($this->batchSize)
->get();
if ($artworks->isEmpty()) {
$this->logBatchComplete($startedAt, 0, false);
return;
}
$this->processArtworkSafely(
$artworks,
$modelVersion,
@@ -112,7 +145,13 @@ final class RecComputeSimilarHybridJob implements ShouldQueue
$minCatsTop12,
$weights,
);
});
$hasMore = $artworks->count() === $this->batchSize;
if ($hasMore) {
static::dispatch(null, $this->batchSize, (int) $artworks->last()->id);
}
$this->logBatchComplete($startedAt, $artworks->count(), $hasMore);
}
public function failed(\Throwable $exception): void
@@ -120,12 +159,28 @@ final class RecComputeSimilarHybridJob implements ShouldQueue
Log::error('[RecComputeSimilarHybrid] Job failed permanently.', [
'artwork_id' => $this->artworkId,
'batch_size' => $this->batchSize,
'after_artwork_id' => $this->afterArtworkId(),
'attempts' => $this->attempts(),
'exception_class' => $exception::class,
'exception_message' => $exception->getMessage(),
]);
}
/**
* @param positive-int|0 $processed
*/
private function logBatchComplete(float $startedAt, int $processed, bool $hasMore): void
{
Log::info('[RecComputeSimilarHybrid] Batch complete.', [
'artwork_id' => $this->artworkId,
'after_artwork_id' => $this->afterArtworkId(),
'processed' => $processed,
'has_more' => $hasMore,
'duration_ms' => (int) round((microtime(true) - $startedAt) * 1000),
'memory_mb' => round(memory_get_peak_usage(true) / 1048576, 1),
]);
}
/**
* @param iterable<Artwork> $artworks
*/
+47
View File
@@ -0,0 +1,47 @@
<?php
declare(strict_types=1);
namespace App\Jobs;
use App\Notifications\SecurityReportDangerNotification;
use App\Services\SecurityReport\SecurityReportScanner;
use Illuminate\Bus\Queueable;
use Illuminate\Contracts\Queue\ShouldQueue;
use Illuminate\Foundation\Bus\Dispatchable;
use Illuminate\Queue\InteractsWithQueue;
use Illuminate\Queue\SerializesModels;
use Illuminate\Support\Facades\Notification;
final class RunSecurityReportScanJob implements ShouldQueue
{
use Dispatchable;
use InteractsWithQueue;
use Queueable;
use SerializesModels;
public function __construct(public ?int $userId = null)
{
}
public function handle(SecurityReportScanner $scanner): void
{
if (! (bool) config('security-report.enabled', true)) {
return;
}
$report = $scanner->scan('manual', $this->userId);
if (! $report->hasDangerFindings()) {
return;
}
$email = trim((string) config('security-report.notify_email', ''));
if ($email === '') {
return;
}
Notification::route('mail', $email)
->notify(new SecurityReportDangerNotification($report));
}
}
+56
View File
@@ -0,0 +1,56 @@
<?php
declare(strict_types=1);
namespace App\Jobs;
use App\Models\AdsenseConnection;
use App\Services\Adsense\AdsenseSyncService;
use Illuminate\Bus\Queueable;
use Illuminate\Contracts\Queue\ShouldBeUnique;
use Illuminate\Contracts\Queue\ShouldQueue;
use Illuminate\Foundation\Bus\Dispatchable;
use Illuminate\Queue\InteractsWithQueue;
use Illuminate\Queue\SerializesModels;
use Illuminate\Support\Carbon;
final class SyncAdsenseJob implements ShouldBeUnique, ShouldQueue
{
use Dispatchable;
use InteractsWithQueue;
use Queueable;
use SerializesModels;
public int $tries = 1;
public int $timeout = 180;
public int $uniqueFor = 600;
public function __construct(
public readonly int $connectionId,
public readonly string $from,
public readonly string $to,
public readonly bool $entitiesOnly = false,
) {}
public function uniqueId(): string
{
return (string) $this->connectionId;
}
public function handle(AdsenseSyncService $sync): void
{
$connection = AdsenseConnection::query()->find($this->connectionId);
if ($connection === null || ! $connection->hasRefreshToken()) {
return;
}
$sync->sync(
$connection,
Carbon::parse($this->from)->startOfDay(),
Carbon::parse($this->to)->startOfDay(),
$this->entitiesOnly,
);
}
}
+80
View File
@@ -0,0 +1,80 @@
<?php
declare(strict_types=1);
namespace App\Models;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\BelongsTo;
final class AdsenseConnection extends Model
{
public const STATUS_PENDING = 'pending';
public const STATUS_CONNECTED = 'connected';
public const STATUS_RECONNECT_REQUIRED = 'reconnect_required';
public const STATUS_ERROR = 'error';
public const STATUS_DISCONNECTED = 'disconnected';
protected $fillable = [
'account_resource_name',
'account_display_name',
'encrypted_refresh_token',
'status',
'connected_by_user_id',
'connected_at',
'last_sync_attempt_at',
'last_successful_sync_at',
'last_error',
];
protected $hidden = [
'encrypted_refresh_token',
];
protected function casts(): array
{
return [
'encrypted_refresh_token' => 'encrypted',
'connected_at' => 'datetime',
'last_sync_attempt_at' => 'datetime',
'last_successful_sync_at' => 'datetime',
];
}
public function connectedBy(): BelongsTo
{
return $this->belongsTo(User::class, 'connected_by_user_id');
}
public static function current(): ?self
{
return self::query()->latest('id')->first();
}
public function hasRefreshToken(): bool
{
return filled($this->encrypted_refresh_token);
}
public function isConnected(): bool
{
return $this->status === self::STATUS_CONNECTED && $this->hasRefreshToken();
}
public function needsReconnect(): bool
{
return $this->status === self::STATUS_RECONNECT_REQUIRED || (
in_array($this->status, [self::STATUS_PENDING, self::STATUS_CONNECTED, self::STATUS_ERROR], true)
&& ! $this->hasRefreshToken()
);
}
public function isDisconnected(): bool
{
return $this->status === self::STATUS_DISCONNECTED || ! $this->hasRefreshToken();
}
}
+68
View File
@@ -0,0 +1,68 @@
<?php
declare(strict_types=1);
namespace App\Models;
use Illuminate\Database\Eloquent\Model;
final class AdsenseDailyStat extends Model
{
public const DIMENSION_TOTAL = 'total';
public const DIMENSION_AD_UNIT = 'ad_unit';
public const DIMENSION_CUSTOM_CHANNEL = 'custom_channel';
public const DIMENSION_PLATFORM = 'platform';
public const DIMENSION_COUNTRY = 'country';
public const TOTAL_DIMENSION_KEY = '__total__';
protected $fillable = [
'date',
'account_resource_name',
'dimension_type',
'dimension_key',
'dimension_label',
'currency_code',
'page_views',
'ad_requests',
'matched_ad_requests',
'impressions',
'clicks',
'estimated_earnings',
'page_views_ctr',
'page_views_rpm',
'ad_requests_coverage',
'ad_requests_ctr',
'ad_requests_rpm',
'impressions_ctr',
'impressions_rpm',
'cost_per_click',
'last_synced_at',
];
protected function casts(): array
{
return [
'date' => 'date',
'page_views' => 'integer',
'ad_requests' => 'integer',
'matched_ad_requests' => 'integer',
'impressions' => 'integer',
'clicks' => 'integer',
'estimated_earnings' => 'decimal:6',
'page_views_ctr' => 'decimal:8',
'page_views_rpm' => 'decimal:6',
'ad_requests_coverage' => 'decimal:8',
'ad_requests_ctr' => 'decimal:8',
'ad_requests_rpm' => 'decimal:6',
'impressions_ctr' => 'decimal:8',
'impressions_rpm' => 'decimal:6',
'cost_per_click' => 'decimal:6',
'last_synced_at' => 'datetime',
];
}
}
+33
View File
@@ -0,0 +1,33 @@
<?php
declare(strict_types=1);
namespace App\Models;
use Illuminate\Database\Eloquent\Model;
final class AdsenseEntity extends Model
{
public const TYPE_AD_UNIT = 'ad_unit';
public const TYPE_CUSTOM_CHANNEL = 'custom_channel';
protected $fillable = [
'account_resource_name',
'ad_client_resource_name',
'type',
'resource_name',
'reporting_dimension_id',
'display_name',
'active',
'last_seen_at',
];
protected function casts(): array
{
return [
'active' => 'boolean',
'last_seen_at' => 'datetime',
];
}
}
+107 -11
View File
@@ -13,7 +13,6 @@ use Illuminate\Database\Eloquent\Relations\HasMany;
use Illuminate\Database\Eloquent\Relations\HasOne;
use Illuminate\Database\Eloquent\SoftDeletes;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Storage;
use Laravel\Scout\Searchable;
use Laravel\Scout\SearchableScope;
@@ -67,12 +66,17 @@ class Artwork extends Model
'description',
'file_name',
'file_path',
'download_status',
'download_source',
'download_checked_at',
'hash',
'file_ext',
'thumb_ext',
'has_missing_thumbnails',
'missing_thumbnail_variants_json',
'thumbnails_checked_at',
'featured_thumbnail_variants_json',
'featured_thumbnails_checked_at',
'file_size',
'mime_type',
'width',
@@ -80,6 +84,10 @@ class Artwork extends Model
'is_public',
'visibility',
'is_approved',
'approval_source',
'moderated_at',
'moderated_by',
'moderation_note',
'is_mature',
'maturity_level',
'maturity_source',
@@ -116,6 +124,7 @@ class Artwork extends Model
'description_source',
'tags_source',
'category_source',
'primary_category_id',
// Versioning
'current_version_id',
'version_count',
@@ -131,6 +140,7 @@ class Artwork extends Model
'is_public' => 'boolean',
'visibility' => 'string',
'is_approved' => 'boolean',
'moderated_at' => 'datetime',
'is_mature' => 'boolean',
'maturity_level' => 'string',
'maturity_source' => 'string',
@@ -154,6 +164,8 @@ class Artwork extends Model
'published_at' => 'datetime',
'missing_thumbnail_variants_json' => 'array',
'thumbnails_checked_at' => 'datetime',
'featured_thumbnail_variants_json' => 'array',
'featured_thumbnails_checked_at' => 'datetime',
'published_as_type' => 'string',
'published_as_id' => 'integer',
'publish_at' => 'datetime',
@@ -168,6 +180,7 @@ class Artwork extends Model
'category_source' => 'string',
'version_updated_at' => 'datetime',
'requires_reapproval' => 'boolean',
'download_checked_at' => 'datetime',
];
/**
@@ -271,18 +284,64 @@ class Artwork extends Model
?? 'https://files.skinbase.org/default/missing_xl.webp';
}
/**
* Audit state of `featured_thumbnail_variants_json`, distinguishing "never checked"
* from "checked, nothing found":
*
* - `null` → not audited yet (FeaturedArtworkThumbnailGenerator has never
* run plan()/generate() for this artwork).
* - `[]` → audited, but no featured variant exists in object storage.
* - non-empty string[] → audited; these variant names are known to exist.
*
* A value that fails to decode as an array (e.g. legacy/malformed data) is treated
* the same as `null` — "not audited" — rather than throwing or reporting variants
* that were never actually confirmed to exist.
*
* @return array{status: 'not_audited'|'no_variants'|'available', variants: list<string>}
*/
public function featuredThumbnailAuditState(): array
{
$raw = $this->featured_thumbnail_variants_json;
if (! is_array($raw)) {
return ['status' => 'not_audited', 'variants' => []];
}
$variants = array_values(array_filter($raw, 'is_string'));
if ($variants === []) {
return ['status' => 'no_variants', 'variants' => []];
}
return ['status' => 'available', 'variants' => $variants];
}
/**
* Whether a dedicated featured-hero variant is known to exist in object storage.
*
* This reads precomputed state from `featured_thumbnail_variants_json` (see
* `featuredThumbnailAuditState()`) rather than checking the remote disk directly —
* remote existence checks must only happen from `FeaturedArtworkThumbnailGenerator`
* (admin commands / queued jobs), never during public homepage rendering, since a
* live `Storage::exists()` per variant is a synchronous network round trip.
*/
public function hasFeaturedThumbnail(?string $variant = null): bool
{
if (empty($this->hash)) {
return false;
}
$known = $this->featuredThumbnailAuditState()['variants'];
if ($known === []) {
return false;
}
$helper = app(ArtworkFeaturedImagePath::class);
$variants = $variant !== null ? [$helper->normalizeVariant($variant)] : $helper->variantNames();
$disk = Storage::disk((string) config('uploads.object_storage.disk', 's3'));
foreach ($variants as $variantName) {
if ($disk->exists($helper->objectPath($this, $variantName))) {
if (in_array($variantName, $known, true)) {
return true;
}
}
@@ -400,6 +459,32 @@ class Artwork extends Model
return $this->belongsToMany(Category::class, 'artwork_category', 'artwork_id', 'category_id');
}
public function primaryCategory(): BelongsTo
{
return $this->belongsTo(Category::class, 'primary_category_id');
}
public function resolvedPrimaryCategory(): ?Category
{
if ($this->relationLoaded('primaryCategory') && $this->getRelation('primaryCategory') instanceof Category) {
return $this->getRelation('primaryCategory');
}
$primaryId = $this->primary_category_id !== null ? (int) $this->primary_category_id : 0;
if ($primaryId > 0 && $this->relationLoaded('categories')) {
$match = $this->categories->firstWhere('id', $primaryId);
if ($match instanceof Category) {
return $match;
}
}
if ($primaryId > 0) {
return $this->primaryCategory;
}
return null;
}
public function collections(): BelongsToMany
{
return $this->belongsToMany(Collection::class, 'collection_artwork', 'artwork_id', 'collection_id')
@@ -510,19 +595,25 @@ class Artwork extends Model
*/
public function toSearchableArray(): array
{
$this->loadMissing(['user', 'group', 'tags', 'categories.contentType', 'stats', 'awardStat']);
$this->loadMissing(['user', 'group', 'tags', 'categories.contentType', 'primaryCategory.contentType', 'stats', 'awardStat']);
$stat = $this->stats;
$awardStat = $this->awardStat;
$publishedSortAt = $this->published_at ?? $this->created_at;
$sortedCategories = $this->categories->sortBy(
fn ($category) => sprintf(
'%010d|%s|%010d',
$primaryCategory = $this->resolvedPrimaryCategory();
$sortedCategories = $this->categories
->sortBy(function ($category) use ($primaryCategory) {
$isPrimary = $primaryCategory && (int) $category->id === (int) $primaryCategory->id;
return sprintf(
'%d|%010d|%s|%010d',
$isPrimary ? 0 : 1,
(int) ($category->sort_order ?? 999999999),
strtolower((string) ($category->name ?? '')),
(int) ($category->id ?? 0)
)
)->values();
);
})
->values();
// Orientation derived from pixel dimensions
$orientation = 'square';
@@ -539,8 +630,6 @@ class Artwork extends Model
? $this->width.'x'.$this->height
: '';
// Primary category slug follows the same sort_order-first semantics used by page presenters.
$primaryCategory = $sortedCategories->first();
$categorySlugs = $sortedCategories
->pluck('slug')
->filter()
@@ -570,6 +659,13 @@ class Artwork extends Model
'author_name' => $this->group?->name ?? $this->user?->name ?? 'Skinbase',
'published_as_type' => $this->publishedAsType(),
'category' => $category,
'primary_category_id' => $primaryCategory?->id ? (int) $primaryCategory->id : null,
'category_ids' => $this->categories
->pluck('id')
->map(static fn ($id): int => (int) $id)
->unique()
->values()
->all(),
'categories' => $categorySlugs,
'content_type' => $content_type,
'content_types' => $contentTypeSlugs,
+3
View File
@@ -4,9 +4,12 @@ declare(strict_types=1);
namespace App\Models;
use App\Observers\ArtworkAwardObserver;
use Illuminate\Database\Eloquent\Attributes\ObservedBy;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\BelongsTo;
#[ObservedBy([ArtworkAwardObserver::class])]
class ArtworkAward extends Model
{
protected $table = 'artwork_medals';
+18 -3
View File
@@ -1,11 +1,16 @@
<?php
namespace App\Models;
use App\Observers\ArtworkCommentObserver;
use App\Services\ContentSanitizer;
use Illuminate\Database\Eloquent\Attributes\ObservedBy;
use Illuminate\Database\Eloquent\Collection;
use Illuminate\Database\Eloquent\Factories\HasFactory;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\SoftDeletes;
use Illuminate\Database\Eloquent\Relations\BelongsTo;
use Illuminate\Database\Eloquent\Relations\HasMany;
use Illuminate\Database\Eloquent\SoftDeletes;
/**
* App\Models\ArtworkComment
@@ -19,8 +24,9 @@ use Illuminate\Database\Eloquent\Relations\HasMany;
* @property bool $is_approved
* @property-read Artwork $artwork
* @property-read User $user
* @property-read \Illuminate\Database\Eloquent\Collection|CommentReaction[] $reactions
* @property-read Collection|CommentReaction[] $reactions
*/
#[ObservedBy([ArtworkCommentObserver::class])]
class ArtworkComment extends Model
{
use HasFactory, SoftDeletes;
@@ -36,10 +42,18 @@ class ArtworkComment extends Model
'raw_content',
'rendered_content',
'is_approved',
'spam_score',
'spam_probability',
'spam_reason',
'moderation_source',
'moderated_at',
];
protected $casts = [
'is_approved' => 'boolean',
'spam_score' => 'integer',
'spam_probability' => 'integer',
'moderated_at' => 'datetime',
];
public function artwork(): BelongsTo
@@ -90,6 +104,7 @@ class ArtworkComment extends Model
// Lazy render: raw_content takes priority over legacy content
$raw = $this->raw_content ?? $this->content ?? '';
return \App\Services\ContentSanitizer::render($raw);
return ContentSanitizer::render($raw);
}
}
+6 -3
View File
@@ -2,6 +2,9 @@
namespace App\Models;
use App\Observers\ArtworkFavouriteObserver;
use Carbon\Carbon;
use Illuminate\Database\Eloquent\Attributes\ObservedBy;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\BelongsTo;
@@ -12,12 +15,12 @@ use Illuminate\Database\Eloquent\Relations\BelongsTo;
* @property int $user_id
* @property int $artwork_id
* @property int|null $legacy_id Original favourite_id from the old site
* @property \Carbon\Carbon $created_at
* @property \Carbon\Carbon $updated_at
*
* @property Carbon $created_at
* @property Carbon $updated_at
* @property-read User $user
* @property-read Artwork $artwork
*/
#[ObservedBy([ArtworkFavouriteObserver::class])]
class ArtworkFavourite extends Model
{
protected $table = 'artwork_favourites';
+4
View File
@@ -1,10 +1,14 @@
<?php
namespace App\Models;
use App\Observers\ArtworkFeatureObserver;
use Illuminate\Database\Eloquent\Attributes\ObservedBy;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\BelongsTo;
use Illuminate\Database\Eloquent\SoftDeletes;
#[ObservedBy([ArtworkFeatureObserver::class])]
class ArtworkFeature extends Model
{
use SoftDeletes;
+3
View File
@@ -2,6 +2,8 @@
namespace App\Models;
use App\Observers\ArtworkReactionObserver;
use Illuminate\Database\Eloquent\Attributes\ObservedBy;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\BelongsTo;
@@ -11,6 +13,7 @@ use Illuminate\Database\Eloquent\Relations\BelongsTo;
* @property int $user_id
* @property string $reaction ReactionType slug (e.g. thumbs_up, heart, fire…)
*/
#[ObservedBy([ArtworkReactionObserver::class])]
class ArtworkReaction extends Model
{
public $timestamps = false;
+22
View File
@@ -0,0 +1,22 @@
<?php
namespace App\Models;
use Illuminate\Database\Eloquent\Model;
class CommentSpamSignature extends Model
{
public $timestamps = false;
protected $fillable = [
'content_hash', 'pattern_signature', 'source', 'reason',
'confidence', 'hit_count', 'reviewed_by', 'metadata', 'created_at',
];
protected $casts = [
'confidence' => 'integer',
'hit_count' => 'integer',
'metadata' => 'array',
'created_at' => 'datetime',
];
}
+4 -3
View File
@@ -2,12 +2,13 @@
namespace App\Models;
use App\Observers\ContentTypeObserver;
use Illuminate\Database\Eloquent\Attributes\ObservedBy;
use Illuminate\Database\Eloquent\Builder as EloquentBuilder;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\HasMany;
use Illuminate\Database\Eloquent\Builder as EloquentBuilder;
use App\Models\Artwork;
#[ObservedBy([ContentTypeObserver::class])]
class ContentType extends Model
{
protected $fillable = ['name', 'slug', 'description', 'order', 'hide_from_menu', 'mascot_path', 'cover_art_path'];
+17
View File
@@ -4,6 +4,8 @@ declare(strict_types=1);
namespace App\Models;
use App\Observers\GroupReleaseObserver;
use Illuminate\Database\Eloquent\Attributes\ObservedBy;
use Illuminate\Database\Eloquent\Factories\HasFactory;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\BelongsTo;
@@ -11,29 +13,44 @@ use Illuminate\Database\Eloquent\Relations\BelongsToMany;
use Illuminate\Database\Eloquent\Relations\HasMany;
use Illuminate\Database\Eloquent\SoftDeletes;
#[ObservedBy([GroupReleaseObserver::class])]
class GroupRelease extends Model
{
use HasFactory;
use SoftDeletes;
public const STATUS_PLANNED = 'planned';
public const STATUS_IN_PROGRESS = 'in_progress';
public const STATUS_INTERNAL_REVIEW = 'internal_review';
public const STATUS_SCHEDULED = 'scheduled';
public const STATUS_RELEASED = 'released';
public const STATUS_ARCHIVED = 'archived';
public const STATUS_CANCELLED = 'cancelled';
public const STAGE_CONCEPT = 'concept';
public const STAGE_PRODUCTION = 'production';
public const STAGE_REVIEW = 'review';
public const STAGE_PACKAGING = 'packaging';
public const STAGE_APPROVAL = 'approval';
public const STAGE_PUBLISHING = 'publishing';
public const STAGE_RELEASED = 'released';
public const VISIBILITY_PUBLIC = 'public';
public const VISIBILITY_UNLISTED = 'unlisted';
public const VISIBILITY_PRIVATE = 'private';
protected $fillable = [
+3
View File
@@ -4,10 +4,13 @@ declare(strict_types=1);
namespace App\Models;
use App\Observers\GroupReleaseContributorObserver;
use Illuminate\Database\Eloquent\Attributes\ObservedBy;
use Illuminate\Database\Eloquent\Factories\HasFactory;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\BelongsTo;
#[ObservedBy([GroupReleaseContributorObserver::class])]
class GroupReleaseContributor extends Model
{
use HasFactory;
+27
View File
@@ -4,48 +4,75 @@ declare(strict_types=1);
namespace App\Models;
use App\Observers\HomepageAnnouncementObserver;
use Illuminate\Database\Eloquent\Attributes\ObservedBy;
use Illuminate\Database\Eloquent\Builder;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\BelongsTo;
use Illuminate\Database\Eloquent\SoftDeletes;
use Illuminate\Support\Carbon;
#[ObservedBy([HomepageAnnouncementObserver::class])]
class HomepageAnnouncement extends Model
{
use SoftDeletes;
public const STATUS_DRAFT = 'draft';
public const STATUS_PUBLISHED = 'published';
public const STATUS_ARCHIVED = 'archived';
public const TYPE_ANNOUNCEMENT = 'announcement';
public const TYPE_LAUNCH = 'launch';
public const TYPE_NEWS = 'news';
public const TYPE_WORLD = 'world';
public const TYPE_EVENT = 'event';
public const TYPE_NOTICE = 'notice';
public const TYPE_MAINTENANCE = 'maintenance';
public const PLACEMENT_HOMEPAGE_AFTER_FEATURED = 'homepage_after_featured';
public const LINK_TYPE_NONE = 'none';
public const LINK_TYPE_CUSTOM_URL = 'custom_url';
public const LINK_TYPE_NEWS = 'news';
public const LINK_TYPE_WORLD = 'world';
public const LINK_TYPE_ARTWORK = 'artwork';
public const LINK_TYPE_COLLECTION = 'collection';
public const LINK_TYPE_GROUP = 'group';
public const LINK_TYPE_PROFILE = 'profile';
public const LINK_TYPE_EXPLORE = 'explore';
public const LINK_TYPE_UPLOAD = 'upload';
public const GRADIENT_NOVA_AURORA = 'nova_aurora';
public const GRADIENT_DEEP_SPACE = 'deep_space';
public const GRADIENT_SUNRISE = 'sunrise';
public const GRADIENT_OCEAN_GLOW = 'ocean_glow';
public const GRADIENT_SPRING_VIBES = 'spring_vibes';
public const GRADIENT_FANTASY_REALMS = 'fantasy_realms';
public const GRADIENT_MINIMAL_LIGHT = 'minimal_light';
public const GRADIENT_DARK_GLASS = 'dark_glass';
protected $table = 'homepage_announcements';
+160
View File
@@ -0,0 +1,160 @@
<?php
declare(strict_types=1);
namespace App\Models;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\BelongsTo;
final class SecurityReport extends Model
{
protected $fillable = [
'status',
'started_at',
'finished_at',
'composer_critical',
'composer_high',
'composer_medium',
'composer_low',
'composer_unknown',
'npm_critical',
'npm_high',
'npm_moderate',
'npm_low',
'npm_info',
'npm_unknown',
'total_critical',
'total_high',
'total_medium',
'total_low',
'total_unknown',
'composer_outdated_count',
'npm_outdated_count',
'summary',
'composer_audit',
'composer_outdated',
'npm_audit',
'npm_outdated',
'error_message',
'triggered_by',
'user_id',
];
protected function casts(): array
{
return [
'started_at' => 'datetime',
'finished_at' => 'datetime',
'summary' => 'array',
'composer_audit' => 'array',
'composer_outdated' => 'array',
'npm_audit' => 'array',
'npm_outdated' => 'array',
];
}
public function user(): BelongsTo
{
return $this->belongsTo(User::class);
}
public function hasCriticalFindings(): bool
{
return $this->total_critical > 0;
}
public function hasHighFindings(): bool
{
return $this->total_high > 0;
}
public function hasDangerFindings(): bool
{
return $this->hasCriticalFindings() || $this->hasHighFindings();
}
public function getRiskLabelAttribute(): string
{
if ($this->total_critical > 0) {
return 'Critical';
}
if ($this->total_high > 0) {
return 'High';
}
if ($this->total_medium > 0) {
return 'Medium';
}
if ($this->total_low > 0) {
return 'Low';
}
return 'Clean';
}
/**
* @return array<int, array<string, mixed>>
*/
public function composerAdvisories(): array
{
$advisories = $this->composer_audit['advisories'] ?? [];
$items = [];
foreach ($advisories as $package => $packageAdvisories) {
if (! is_array($packageAdvisories)) {
continue;
}
foreach ($packageAdvisories as $advisory) {
if (! is_array($advisory)) {
continue;
}
$items[] = [
'package' => (string) $package,
'severity' => strtolower((string) ($advisory['severity'] ?? 'unknown')),
'title' => (string) ($advisory['title'] ?? $advisory['advisoryId'] ?? 'Unknown advisory'),
'cve' => (string) ($advisory['cve'] ?? $advisory['link'] ?? ''),
'affected_versions' => (string) ($advisory['affectedVersions'] ?? $advisory['affected_versions'] ?? ''),
'reported_at' => (string) ($advisory['reportedAt'] ?? ''),
'link' => (string) ($advisory['link'] ?? ''),
];
}
}
return $items;
}
/**
* @return array<int, array<string, mixed>>
*/
public function npmVulnerabilities(): array
{
$vulnerabilities = $this->npm_audit['vulnerabilities'] ?? [];
$items = [];
foreach ($vulnerabilities as $package => $vulnerability) {
if (! is_array($vulnerability)) {
continue;
}
$via = collect((array) ($vulnerability['via'] ?? []))
->first(fn (mixed $item): bool => is_array($item));
$items[] = [
'package' => (string) $package,
'severity' => strtolower((string) ($vulnerability['severity'] ?? 'unknown')),
'title' => is_array($via) ? (string) ($via['title'] ?? 'Unknown advisory') : 'Unknown advisory',
'cve' => is_array($via) ? (string) ($via['cve'] ?? '') : '',
'range' => (string) ($vulnerability['range'] ?? ''),
'fix_available' => is_array($vulnerability['fixAvailable'] ?? null) ? (string) (($vulnerability['fixAvailable']['name'] ?? '') . '@' . ($vulnerability['fixAvailable']['version'] ?? '')) : ((bool) ($vulnerability['fixAvailable'] ?? false) ? 'Yes' : ''),
'url' => is_array($via) ? (string) ($via['url'] ?? '') : '',
];
}
return $items;
}
}
+13
View File
@@ -5,6 +5,7 @@ declare(strict_types=1);
namespace App\Models;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\BelongsTo;
class Upload extends Model
{
@@ -23,6 +24,7 @@ class Upload extends Model
'title',
'slug',
'category_id',
'secondary_category_ids',
'description',
'tags',
'license',
@@ -41,6 +43,7 @@ class Upload extends Model
protected $casts = [
'tags' => 'array',
'secondary_category_ids' => 'array',
'nsfw' => 'boolean',
'is_scanned' => 'boolean',
'has_tags' => 'boolean',
@@ -48,4 +51,14 @@ class Upload extends Model
'expires_at' => 'datetime',
'moderated_at' => 'datetime',
];
public function user(): BelongsTo
{
return $this->belongsTo(User::class);
}
public function category(): BelongsTo
{
return $this->belongsTo(Category::class);
}
}
@@ -0,0 +1,39 @@
<?php
declare(strict_types=1);
namespace App\Notifications;
use App\Models\Artwork;
use App\Models\User;
use Illuminate\Bus\Queueable;
use Illuminate\Contracts\Queue\ShouldQueue;
use Illuminate\Notifications\Messages\MailMessage;
use Illuminate\Notifications\Notification;
final class NewArtworkReviewNotification extends Notification implements ShouldQueue
{
use Queueable;
public function __construct(
private readonly Artwork $artwork,
private readonly User $uploader,
private readonly array $reasons,
) {}
public function via(object $notifiable): array
{
return ['mail'];
}
public function toMail(object $notifiable): MailMessage
{
return (new MailMessage)
->subject('Skinbase: new artwork awaiting review')
->greeting('New artwork review')
->line(sprintf('“%s” by %s is being held before publication.', $this->artwork->title ?: 'Untitled artwork', $this->uploader->username ?: $this->uploader->name))
->line('Reasons: '.implode(', ', $this->reasons))
->action('Open moderation queue', url('/moderation/uploads'))
->line('The artwork is not public until it is approved.');
}
}
@@ -0,0 +1,40 @@
<?php
declare(strict_types=1);
namespace App\Notifications;
use App\Models\SecurityReport;
use Illuminate\Bus\Queueable;
use Illuminate\Contracts\Queue\ShouldQueue;
use Illuminate\Notifications\Messages\MailMessage;
use Illuminate\Notifications\Notification;
final class SecurityReportDangerNotification extends Notification implements ShouldQueue
{
use Queueable;
public function __construct(private readonly SecurityReport $report)
{
}
public function via(object $notifiable): array
{
return ['mail'];
}
public function toMail(object $notifiable): MailMessage
{
return (new MailMessage())
->subject('Skinbase Security Report Alert')
->greeting('Security report alert')
->line('High or critical dependency vulnerabilities were detected in the latest private security scan.')
->line('Status: ' . $this->report->status)
->line('Critical: ' . $this->report->total_critical)
->line('High: ' . $this->report->total_high)
->line('Medium: ' . $this->report->total_medium)
->line('Low: ' . $this->report->total_low)
->action('Open Security Report', url('/moderation/system/security-report/' . $this->report->id))
->line('This report is private and intended for administrators only.');
}
}
+29
View File
@@ -4,6 +4,7 @@ declare(strict_types=1);
namespace App\Observers;
use App\Jobs\GenerateFeaturedArtworkThumbnailsJob;
use App\Models\Artwork;
use App\Models\ArtworkFeature;
use App\Services\HomepageService;
@@ -21,12 +22,14 @@ final class ArtworkFeatureObserver
public function created(ArtworkFeature $feature): void
{
$this->homepage->clearFeaturedAndMedalCaches();
$this->queueFeaturedThumbnailRefresh($feature);
$this->queueCreatorRebuild($feature);
}
public function updated(ArtworkFeature $feature): void
{
$this->homepage->clearFeaturedAndMedalCaches();
$this->queueFeaturedThumbnailRefresh($feature);
$this->queueCreatorRebuild($feature);
}
@@ -39,6 +42,7 @@ final class ArtworkFeatureObserver
public function restored(ArtworkFeature $feature): void
{
$this->homepage->clearFeaturedAndMedalCaches();
$this->queueFeaturedThumbnailRefresh($feature);
$this->queueCreatorRebuild($feature);
}
@@ -48,6 +52,31 @@ final class ArtworkFeatureObserver
$this->queueCreatorRebuild($feature);
}
/**
* Ensure the featured hero variants (and their DB-persisted existence state)
* are ready before the next homepage guest-cache warm cycle picks this
* artwork up as the hero winner, so the public request never has to check
* the remote disk itself.
*/
private function queueFeaturedThumbnailRefresh(ArtworkFeature $feature): void
{
$artworkId = (int) $feature->artwork_id;
if ($artworkId <= 0) {
return;
}
$artwork = $feature->relationLoaded('artwork')
? $feature->artwork
: Artwork::withTrashed()->find($artworkId);
if (! $artwork instanceof Artwork || empty($artwork->hash) || empty($artwork->file_ext)) {
return;
}
GenerateFeaturedArtworkThumbnailsJob::dispatch($artworkId);
}
private function queueCreatorRebuild(ArtworkFeature $feature): void
{
$artwork = $feature->relationLoaded('artwork')
+22 -1
View File
@@ -6,6 +6,7 @@ namespace App\Observers;
use App\Events\Achievements\AchievementCheckRequested;
use App\Models\Artwork;
use App\Jobs\GenerateFeaturedArtworkThumbnailsJob;
use App\Jobs\RecComputeSimilarByTagsJob;
use App\Jobs\RecComputeSimilarHybridJob;
use App\Jobs\Posts\AutoUploadPostJob;
@@ -15,6 +16,7 @@ use App\Services\Profile\CreatorJourneyService;
use App\Services\UserStatsService;
use App\Services\XPService;
use Illuminate\Support\Facades\Cache;
use Illuminate\Support\Facades\DB;
/**
* Syncs artwork documents to Meilisearch on every relevant model event.
@@ -61,6 +63,25 @@ class ArtworkObserver
$this->indexer->update($artwork);
// A changed hash/extension means any previously persisted
// featured_thumbnail_variants_json now refers to the WRONG object paths (they
// were computed from the old hash) — the variant names would still read as
// "available" while pointing at objects that don't exist under the new hash,
// which would surface as a broken hero image. Reset the audit state immediately
// (via a direct query, not a model save, to avoid re-entering this observer) so
// hasFeaturedThumbnail() safely reports "not audited" until the queued job below
// re-verifies and repopulates it; the public homepage never blocks on that check.
if ($artwork->wasChanged(['hash', 'file_ext'])) {
DB::table('artworks')->where('id', $artwork->id)->update([
'featured_thumbnail_variants_json' => null,
'featured_thumbnails_checked_at' => null,
]);
if (! empty($artwork->hash) && ! empty($artwork->file_ext) && $artwork->features()->exists()) {
GenerateFeaturedArtworkThumbnailsJob::dispatch((int) $artwork->id, true);
}
}
// §7.5 On-demand: recompute similarity when tags/categories could have changed.
// The pivot sync happens outside this observer, so we dispatch on every
// meaningful update and let the job be idempotent (cheap if nothing changed).
@@ -146,7 +167,7 @@ class ArtworkObserver
private function shouldClearFeaturedCaches(Artwork $artwork): bool
{
if (! $artwork->wasChanged(['published_at', 'is_public', 'is_approved', 'deleted_at', 'has_missing_thumbnails'])) {
if (! $artwork->wasChanged(['published_at', 'is_public', 'is_approved', 'deleted_at', 'has_missing_thumbnails', 'hash', 'file_ext'])) {
return false;
}
+150 -73
View File
@@ -3,53 +3,59 @@
namespace App\Providers;
use App\Contracts\Images\SubjectDetectorInterface;
use Illuminate\Cache\RateLimiting\Limit;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\RateLimiter;
use Illuminate\Support\ServiceProvider;
use App\Contracts\Moderation\CommentSpamClassifier;
use App\Events\Achievements\AchievementCheckRequested;
use App\Events\Achievements\UserXpUpdated;
use App\Events\Posts\ArtworkShared;
use App\Events\Posts\PostCommented;
use App\Http\Middleware\ConditionalCors;
use App\Listeners\Academy\HandleAcademyStripeWebhook;
use App\Listeners\Academy\HandleAcademyStripeWebhookHandled;
use App\Listeners\Achievements\CheckUserAchievements;
use App\Listeners\Posts\AwardXpForPostCommented;
use App\Listeners\Posts\SendArtworkSharedNotification;
use App\Listeners\Posts\SendPostCommentedNotification;
use App\Models\Artwork;
use App\Models\ArtworkAward;
use App\Models\ArtworkComment;
use App\Models\ArtworkFeature;
use App\Models\ArtworkFavourite;
use App\Models\ArtworkMedal;
use App\Models\ArtworkReaction;
use App\Models\ContentType;
use App\Models\GroupRelease;
use App\Models\GroupReleaseContributor;
use App\Models\HomepageAnnouncement;
use App\Observers\ArtworkAwardObserver;
use App\Observers\ArtworkCommentObserver;
use App\Observers\ArtworkFeatureObserver;
use App\Observers\ArtworkFavouriteObserver;
use App\Observers\ArtworkObserver;
use App\Observers\ArtworkReactionObserver;
use App\Observers\ContentTypeObserver;
use App\Observers\GroupReleaseContributorObserver;
use App\Observers\GroupReleaseObserver;
use App\Observers\HomepageAnnouncementObserver;
use App\Services\Upload\Contracts\UploadDraftServiceInterface;
use App\Services\Upload\UploadDraftService;
use App\Services\ContentTypes\ContentTypeSlugResolver;
use App\Services\Worlds\WorldService;
use Illuminate\Support\Facades\Blade;
use Illuminate\Support\Facades\View;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Cache;
use Illuminate\Support\Facades\Auth;
use Illuminate\Support\Facades\Event;
use Illuminate\Support\Facades\Log;
use Illuminate\Queue\Events\JobFailed;
use App\Services\ReceivedCommentsInboxService;
use App\Services\Countries\CountryRemoteProvider;
use App\Services\Countries\CountryRemoteProviderInterface;
use App\Services\EarlyGrowth\SpotlightEngine;
use App\Services\EarlyGrowth\SpotlightEngineInterface;
use App\Services\Images\Detectors\ChainedSubjectDetector;
use App\Services\Images\Detectors\HeuristicSubjectDetector;
use App\Services\Images\Detectors\NullSubjectDetector;
use App\Services\Images\Detectors\VisionSubjectDetector;
use App\Services\Moderation\TogetherCommentSpamClassifier;
use App\Services\ReceivedCommentsInboxService;
use App\Services\Recommendations\VectorSimilarity\VectorAdapterFactory;
use App\Services\Recommendations\VectorSimilarity\VectorAdapterInterface;
use App\Services\Upload\Contracts\UploadDraftServiceInterface;
use App\Services\Upload\UploadDraftService;
use App\Services\Worlds\WorldService;
use App\Support\Http\TimedInertiaSsrGateway;
use Illuminate\Cache\RateLimiting\Limit;
use Illuminate\Contracts\Http\Kernel;
use Illuminate\Foundation\Configuration\Middleware;
use Illuminate\Http\Middleware\HandleCors;
use Illuminate\Http\Request;
use Illuminate\Queue\Events\JobFailed;
use Illuminate\Support\Facades\Auth;
use Illuminate\Support\Facades\Cache;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Event;
use Illuminate\Support\Facades\Log;
use Illuminate\Support\Facades\RateLimiter;
use Illuminate\Support\ServiceProvider;
use Illuminate\View\Factory;
use Inertia\Ssr\Gateway;
use Klevze\ControlPanel\Framework\Core\Menu;
use Laravel\Cashier\Events\WebhookHandled;
use Laravel\Cashier\Events\WebhookReceived;
use App\Listeners\Academy\HandleAcademyStripeWebhook;
use App\Listeners\Academy\HandleAcademyStripeWebhookHandled;
use Meilisearch\Client;
use SocialiteProviders\Discord\DiscordExtendSocialite;
use SocialiteProviders\Manager\SocialiteWasCalled;
class AppServiceProvider extends ServiceProvider
{
@@ -58,9 +64,18 @@ class AppServiceProvider extends ServiceProvider
*/
public function register(): void
{
$this->app->bind(CommentSpamClassifier::class, function ($app) {
return $app->make(TogetherCommentSpamClassifier::class);
});
$this->app->bind(
Gateway::class,
TimedInertiaSsrGateway::class,
);
$this->app->singleton(
\App\Services\Countries\CountryRemoteProviderInterface::class,
\App\Services\Countries\CountryRemoteProvider::class,
CountryRemoteProviderInterface::class,
CountryRemoteProvider::class,
);
// Bind UploadDraftService interface to implementation
@@ -70,14 +85,14 @@ class AppServiceProvider extends ServiceProvider
// Bind vector adapter interface for similarity system (resolves via factory)
$this->app->bind(
\App\Services\Recommendations\VectorSimilarity\VectorAdapterInterface::class,
fn () => \App\Services\Recommendations\VectorSimilarity\VectorAdapterFactory::make(),
VectorAdapterInterface::class,
fn () => VectorAdapterFactory::make(),
);
// EGS: bind SpotlightEngineInterface to the concrete SpotlightEngine
$this->app->singleton(
\App\Services\EarlyGrowth\SpotlightEngineInterface::class,
\App\Services\EarlyGrowth\SpotlightEngine::class,
SpotlightEngineInterface::class,
SpotlightEngine::class,
);
$this->app->singleton(SubjectDetectorInterface::class, function ($app) {
@@ -87,6 +102,21 @@ class AppServiceProvider extends ServiceProvider
$app->make(NullSubjectDetector::class),
]);
});
// Override Scout's default Meilisearch client binding: Scout registers it
// with no HTTP timeout, so a slow/overloaded Meilisearch leaves PHP-FPM
// workers blocked forever in curl_exec(), draining the whole pool under
// a search traffic spike. Fail fast instead.
$this->app->singleton(Client::class, function ($app) {
$config = $app['config']->get('scout.meilisearch');
$httpClient = new \GuzzleHttp\Client([
'connect_timeout' => 2,
'timeout' => 5,
]);
return new Client($config['host'], $config['key'], $httpClient);
});
}
/**
@@ -99,18 +129,37 @@ class AppServiceProvider extends ServiceProvider
// Map the 'legacy' view namespace to resources/views/_legacy so all
// view('legacy::foo') and @include('legacy::foo') calls resolve correctly
// after the folder was renamed from legacy/ to _legacy/.
View::addNamespace('legacy', resource_path('views/_legacy'));
$legacyViewPath = resource_path('views/_legacy');
$registerLegacyViewNamespace = static function (Factory $view) use ($legacyViewPath): void {
$view->addNamespace('legacy', $legacyViewPath);
};
if ($this->app->resolved('view')) {
$registerLegacyViewNamespace($this->app->make('view'));
} else {
$this->app->afterResolving('view', $registerLegacyViewNamespace);
}
$exceptionRendererComponentsPath = base_path('vendor/laravel/framework/src/Illuminate/Foundation/resources/exceptions/renderer/components');
$registerExceptionRendererComponents = static function ($compiler) use ($exceptionRendererComponentsPath): void {
if (is_dir($exceptionRendererComponentsPath)) {
Blade::anonymousComponentNamespace($exceptionRendererComponentsPath, 'laravel-exceptions-renderer');
$compiler->anonymousComponentNamespace($exceptionRendererComponentsPath, 'laravel-exceptions-renderer');
}
};
if ($this->app->resolved('blade.compiler')) {
$registerExceptionRendererComponents($this->app->make('blade.compiler'));
} else {
$this->app->afterResolving('blade.compiler', $registerExceptionRendererComponents);
}
$this->configureAuthRateLimiters();
$this->configureUploadRateLimiters();
$this->configureMessagingRateLimiters();
$this->configureDownloadRateLimiter();
$this->configureSearchRateLimiter();
$this->configureVectorSearchRateLimiter();
$this->configureArtworkRateLimiters();
$this->configureNovaCardRateLimiters();
$this->configureReactionRateLimiters();
@@ -118,45 +167,35 @@ class AppServiceProvider extends ServiceProvider
$this->configureSettingsRateLimiters();
$this->configureMailFailureLogging();
ArtworkAward::observe(ArtworkAwardObserver::class);
ArtworkMedal::observe(ArtworkAwardObserver::class);
Artwork::observe(ArtworkObserver::class);
ArtworkFeature::observe(ArtworkFeatureObserver::class);
ArtworkFavourite::observe(ArtworkFavouriteObserver::class);
ArtworkComment::observe(ArtworkCommentObserver::class);
ArtworkReaction::observe(ArtworkReactionObserver::class);
ContentType::observe(ContentTypeObserver::class);
GroupRelease::observe(GroupReleaseObserver::class);
GroupReleaseContributor::observe(GroupReleaseContributorObserver::class);
HomepageAnnouncement::observe(HomepageAnnouncementObserver::class);
// ── OAuth / SocialiteProviders ──────────────────────────────────────
Event::listen(
\SocialiteProviders\Manager\SocialiteWasCalled::class,
\SocialiteProviders\Discord\DiscordExtendSocialite::class,
SocialiteWasCalled::class,
DiscordExtendSocialite::class,
);
// Apple provider removed — no listener registered
// ── Posts / Feed System Events ──────────────────────────────────────
Event::listen(
\App\Events\Posts\ArtworkShared::class,
\App\Listeners\Posts\SendArtworkSharedNotification::class,
ArtworkShared::class,
SendArtworkSharedNotification::class,
);
Event::listen(
\App\Events\Posts\PostCommented::class,
\App\Listeners\Posts\SendPostCommentedNotification::class,
PostCommented::class,
SendPostCommentedNotification::class,
);
Event::listen(
\App\Events\Posts\PostCommented::class,
\App\Listeners\Posts\AwardXpForPostCommented::class,
PostCommented::class,
AwardXpForPostCommented::class,
);
Event::listen(
\App\Events\Achievements\AchievementCheckRequested::class,
\App\Listeners\Achievements\CheckUserAchievements::class,
AchievementCheckRequested::class,
CheckUserAchievements::class,
);
Event::listen(
\App\Events\Achievements\UserXpUpdated::class,
\App\Listeners\Achievements\CheckUserAchievements::class,
UserXpUpdated::class,
CheckUserAchievements::class,
);
Event::listen(
WebhookReceived::class,
@@ -168,7 +207,8 @@ class AppServiceProvider extends ServiceProvider
);
// Provide toolbar counts and user info to layout views (port of legacy toolbar logic)
View::composer(['layouts.nova', 'layouts.nova.*'], function ($view) {
$registerNovaLayoutComposer = function (Factory $factory): void {
$factory->composer(['layouts.nova', 'layouts.nova.*'], function ($view) {
$uploadCount = $favCount = $msgCount = $noticeCount = $receivedCommentsCount = 0;
$avatarHash = null;
$displayName = null;
@@ -176,7 +216,7 @@ class AppServiceProvider extends ServiceProvider
$toolbarContentTypes = collect();
$toolbarActiveCampaign = null;
$request = request();
$canReadSessionAuth = $request instanceof \Illuminate\Http\Request
$canReadSessionAuth = $request instanceof Request
&& $request->hasSession()
&& $request->attributes->get('skinbase.session_skipped') !== true;
$authUser = $canReadSessionAuth ? Auth::user() : null;
@@ -279,19 +319,26 @@ class AppServiceProvider extends ServiceProvider
$view->with(compact('userId', 'uploadCount', 'favCount', 'msgCount', 'noticeCount', 'receivedCommentsCount', 'avatarHash', 'displayName', 'toolbarContentTypes', 'toolbarActiveCampaign'));
});
};
if ($this->app->resolved('view')) {
$registerNovaLayoutComposer($this->app->make('view'));
} else {
$this->app->afterResolving('view', $registerNovaLayoutComposer);
}
// Replace the framework HandleCors with our ConditionalCors so the
// CP_ENABLE_CORS / config('cors.paths') toggle takes effect.
try {
$middlewareConfig = $this->app->make(\Illuminate\Foundation\Configuration\Middleware::class);
$middlewareConfig = $this->app->make(Middleware::class);
$middlewareConfig->replace(
\Illuminate\Http\Middleware\HandleCors::class,
\App\Http\Middleware\ConditionalCors::class
HandleCors::class,
ConditionalCors::class
);
} catch (\Throwable $_) {
// Fallback: push to kernel if replace isn't available in this app instance
$this->app->make(\Illuminate\Contracts\Http\Kernel::class)
->pushMiddleware(\App\Http\Middleware\ConditionalCors::class);
$this->app->make(Kernel::class)
->pushMiddleware(ConditionalCors::class);
}
}
@@ -468,6 +515,36 @@ class AppServiceProvider extends ServiceProvider
});
}
private function configureSearchRateLimiter(): void
{
RateLimiter::for('search', function (Request $request): array {
$userId = $request->user()?->id;
// Search fans out to Meilisearch + DB queries per request, so IP
// limits are kept tight to blunt scripted floods of /search traffic.
return [
Limit::perMinute(20)->by('search:user:'.($userId ?? 'guest')),
Limit::perMinute(30)->by('search:ip:'.$request->ip()),
];
});
}
private function configureVectorSearchRateLimiter(): void
{
RateLimiter::for('vector-search', function (Request $request): array {
$userId = $request->user()?->id;
// Each hit here can trigger synchronous outbound HTTP to the vision
// vector gateway (image download + similarity search), so keep the
// per-IP allowance tight — unlike cached list endpoints, a flood of
// distinct artwork IDs can't be absorbed by cache alone.
return [
Limit::perMinute(30)->by('vector-search:user:'.($userId ?? 'guest')),
Limit::perMinute(20)->by('vector-search:ip:'.$request->ip()),
];
});
}
private function configureArtworkRateLimiters(): void
{
RateLimiter::for('artwork-awards', function (Request $request): array {
@@ -0,0 +1,98 @@
<?php
declare(strict_types=1);
namespace App\Providers;
use Carbon\Carbon;
use Carbon\CarbonImmutable;
use Carbon\CarbonInterval;
use Carbon\CarbonPeriod;
use Illuminate\Contracts\Events\Dispatcher as DispatcherContract;
use Illuminate\Foundation\Events\LocaleUpdated;
use Illuminate\Support\Carbon as IlluminateCarbon;
use Illuminate\Support\Facades\Date;
use Illuminate\Support\ServiceProvider;
use Throwable;
final class LazyCarbonServiceProvider extends ServiceProvider
{
private bool $localeListenerRegistered = false;
public function register(): void
{
$registerListener = function (DispatcherContract $events): void {
if ($this->localeListenerRegistered) {
return;
}
$this->localeListenerRegistered = true;
$events->listen(
LocaleUpdated::class,
function (LocaleUpdated $event): void {
$this->synchronizeCarbonLocale($event->locale);
}
);
};
if ($this->app->resolved('events')) {
$registerListener(
$this->app->make('events')
);
return;
}
$this->app->afterResolving(
'events',
$registerListener
);
}
private function synchronizeCarbonLocale(string $locale): void
{
$fallback = (string) $this->app['config']->get(
'app.fallback_locale',
'en'
);
Carbon::setLocale($locale);
CarbonImmutable::setLocale($locale);
CarbonPeriod::setLocale($locale);
CarbonInterval::setLocale($locale);
Carbon::setFallbackLocale($fallback);
CarbonImmutable::setFallbackLocale($fallback);
CarbonPeriod::setFallbackLocale($fallback);
CarbonInterval::setFallbackLocale($fallback);
IlluminateCarbon::setLocale($locale);
if (
method_exists(
IlluminateCarbon::class,
'setFallbackLocale'
)
) {
IlluminateCarbon::setFallbackLocale($fallback);
}
try {
$date = Date::getFacadeRoot();
if ($date && method_exists($date, 'setLocale')) {
$date->setLocale($locale);
}
if (
$date &&
method_exists($date, 'setFallbackLocale')
) {
$date->setFallbackLocale($fallback);
}
} catch (Throwable) {
// Preserve Carbon provider tolerance for custom Date drivers.
}
}
}
+11 -2
View File
@@ -13,6 +13,7 @@ use App\Models\AcademyLessonBlock;
use App\Models\AcademyPromptPack;
use App\Models\AcademyPromptTemplate;
use App\Models\User;
use Illuminate\Support\Facades\Cache;
use Illuminate\Support\Facades\Storage;
use Illuminate\Support\Str;
use Laravel\Cashier\Subscription;
@@ -280,7 +281,9 @@ final class AcademyAccessService
public function coursePayload(AcademyCourse $course, ?User $viewer, array $options = []): array
{
$progress = is_array($options['progress'] ?? null) ? $options['progress'] : null;
$lessonCount = (int) ($course->lessons_count_cache ?: $course->courseLessons()->count());
$lessonCount = $course->relationLoaded('courseLessons')
? $course->courseLessons->count()
: (int) $course->lessons_count_cache;
return [
'id' => (int) $course->id,
@@ -1089,7 +1092,13 @@ final class AcademyAccessService
}
try {
$exists = Storage::disk((string) config('uploads.object_storage.disk', 's3'))->exists($normalizedPath);
$exists = (bool) Cache::remember(
'academy:asset-exists:'.$cacheKey,
3600,
function () use ($normalizedPath): bool {
return Storage::disk((string) config('uploads.object_storage.disk', 's3'))->exists($normalizedPath);
},
);
} catch (\Throwable) {
$exists = false;
}
@@ -0,0 +1,288 @@
<?php
declare(strict_types=1);
namespace App\Services\Adsense;
use App\Models\AdsenseConnection;
use App\Models\AdsenseDailyStat;
use App\Models\AdsenseEntity;
use App\Models\Country;
use Illuminate\Support\Carbon;
use Illuminate\Support\Collection;
use Illuminate\Support\Facades\Schema;
final class AdsenseAnalyticsQueryService
{
/**
* @return array{from: Carbon, to: Carbon, previous_from: Carbon, previous_to: Carbon, period: string}
*/
public function resolveRange(?string $period, ?string $from, ?string $to): array
{
$period = $period ?: '30d';
$today = now()->startOfDay();
[$start, $end] = match ($period) {
'today' => [$today->copy(), $today->copy()],
'yesterday' => [$today->copy()->subDay(), $today->copy()->subDay()],
'7d' => [$today->copy()->subDays(6), $today->copy()],
'custom' => [
Carbon::parse($from ?: $today->copy()->subDays(29)->toDateString())->startOfDay(),
Carbon::parse($to ?: $today->toDateString())->startOfDay(),
],
default => [$today->copy()->subDays(29), $today->copy()],
};
if ($end->lt($start)) {
[$start, $end] = [$end, $start];
}
$days = $start->diffInDays($end) + 1;
$previousEnd = $start->copy()->subDay();
$previousStart = $previousEnd->copy()->subDays($days - 1);
return [
'from' => $start,
'to' => $end,
'previous_from' => $previousStart,
'previous_to' => $previousEnd,
'period' => $period === 'custom' ? 'custom' : (in_array($period, ['today', 'yesterday', '7d', '30d'], true) ? $period : '30d'),
];
}
/**
* @return array<string, mixed>
*/
public function dashboard(AdsenseConnection $connection, Carbon $from, Carbon $to, Carbon $previousFrom, Carbon $previousTo): array
{
$account = (string) $connection->account_resource_name;
$current = $this->totals($account, $from, $to);
$previous = $this->totals($account, $previousFrom, $previousTo);
$currency = $current['currency_code'] ?? $previous['currency_code'] ?? 'USD';
return [
'kpis' => [
$this->kpi('estimated_earnings', 'Estimated Earnings', $current['estimated_earnings'], $previous['estimated_earnings'], 'money', $currency),
$this->kpi('page_views', 'Page Views', $current['page_views'], $previous['page_views'], 'integer'),
$this->kpi('impressions', 'Ad Impressions', $current['impressions'], $previous['impressions'], 'integer'),
$this->kpi('clicks', 'Clicks', $current['clicks'], $previous['clicks'], 'integer'),
$this->kpi('page_views_ctr', 'Page CTR', $this->ratio($current['clicks'], $current['page_views']), $this->ratio($previous['clicks'], $previous['page_views']), 'percent'),
$this->kpi('page_views_rpm', 'Page RPM', $this->rpm($current['estimated_earnings'], $current['page_views']), $this->rpm($previous['estimated_earnings'], $previous['page_views']), 'money', $currency),
$this->kpi('ad_requests_coverage', 'Ad Request Coverage', $this->ratio($current['matched_ad_requests'], $current['ad_requests']), $this->ratio($previous['matched_ad_requests'], $previous['ad_requests']), 'percent'),
$this->kpi('cost_per_click', 'CPC', $this->cpc($current['estimated_earnings'], $current['clicks']), $this->cpc($previous['estimated_earnings'], $previous['clicks']), 'money', $currency),
],
'chart' => $this->chart($account, $from, $to),
'placements' => $this->dimensionTable($account, AdsenseDailyStat::DIMENSION_AD_UNIT, $from, $to, $currency),
'platforms' => $this->dimensionTable($account, AdsenseDailyStat::DIMENSION_PLATFORM, $from, $to, $currency),
'countries' => array_slice($this->dimensionTable($account, AdsenseDailyStat::DIMENSION_COUNTRY, $from, $to, $currency), 0, 20),
'currency_code' => $currency,
];
}
/**
* @return array<string, mixed>
*/
private function totals(string $account, Carbon $from, Carbon $to): array
{
$row = AdsenseDailyStat::query()
->where('account_resource_name', $account)
->where('dimension_type', AdsenseDailyStat::DIMENSION_TOTAL)
->whereDate('date', '>=', $from->toDateString())
->whereDate('date', '<=', $to->toDateString())
->selectRaw('
SUM(page_views) as page_views,
SUM(ad_requests) as ad_requests,
SUM(matched_ad_requests) as matched_ad_requests,
SUM(impressions) as impressions,
SUM(clicks) as clicks,
SUM(estimated_earnings) as estimated_earnings,
MAX(currency_code) as currency_code
')
->first();
return [
'page_views' => (int) ($row?->page_views ?? 0),
'ad_requests' => (int) ($row?->ad_requests ?? 0),
'matched_ad_requests' => (int) ($row?->matched_ad_requests ?? 0),
'impressions' => (int) ($row?->impressions ?? 0),
'clicks' => (int) ($row?->clicks ?? 0),
'estimated_earnings' => (string) ($row?->estimated_earnings ?? '0'),
'currency_code' => $row?->currency_code,
];
}
/**
* @return list<array<string, mixed>>
*/
private function chart(string $account, Carbon $from, Carbon $to): array
{
$rows = AdsenseDailyStat::query()
->where('account_resource_name', $account)
->where('dimension_type', AdsenseDailyStat::DIMENSION_TOTAL)
->whereDate('date', '>=', $from->toDateString())
->whereDate('date', '<=', $to->toDateString())
->orderBy('date')
->get();
return $rows->map(function (AdsenseDailyStat $row): array {
return [
'date' => optional($row->date)?->toDateString(),
'estimated_earnings' => (float) $row->estimated_earnings,
'page_views' => (int) $row->page_views,
'page_views_rpm' => (float) $row->page_views_rpm,
'clicks' => (int) $row->clicks,
];
})->values()->all();
}
/**
* @return list<array<string, mixed>>
*/
private function dimensionTable(string $account, string $dimensionType, Carbon $from, Carbon $to, ?string $currency): array
{
$rows = AdsenseDailyStat::query()
->where('account_resource_name', $account)
->where('dimension_type', $dimensionType)
->whereDate('date', '>=', $from->toDateString())
->whereDate('date', '<=', $to->toDateString())
->selectRaw('
dimension_key,
MAX(dimension_label) as dimension_label,
SUM(page_views) as page_views,
SUM(impressions) as impressions,
SUM(clicks) as clicks,
SUM(estimated_earnings) as estimated_earnings
')
->groupBy('dimension_key')
->orderByDesc('estimated_earnings')
->get();
$labels = $this->entityLabels($account, $dimensionType);
$countryNames = $dimensionType === AdsenseDailyStat::DIMENSION_COUNTRY ? $this->countryNames() : collect();
return $rows->map(function ($row) use ($labels, $countryNames, $currency, $dimensionType): array {
$key = (string) $row->dimension_key;
$label = (string) ($labels[$key] ?? $countryNames[$key] ?? $row->dimension_label ?? $key);
if ($dimensionType === AdsenseDailyStat::DIMENSION_PLATFORM) {
$label = $this->platformLabel($key, $label);
}
$pageViews = (int) $row->page_views;
$impressions = (int) $row->impressions;
$clicks = (int) $row->clicks;
$earnings = (string) ($row->estimated_earnings ?? '0');
return [
'key' => $key,
'label' => $label,
'page_views' => $pageViews,
'impressions' => $impressions,
'clicks' => $clicks,
'ctr' => $this->ratio($clicks, $pageViews),
'rpm' => $this->rpm($earnings, $pageViews),
'revenue' => $earnings,
'currency_code' => $currency,
];
})->values()->all();
}
/**
* @return array<string, string>
*/
private function entityLabels(string $account, string $dimensionType): array
{
if (! in_array($dimensionType, [AdsenseDailyStat::DIMENSION_AD_UNIT, AdsenseDailyStat::DIMENSION_CUSTOM_CHANNEL], true)) {
return [];
}
return AdsenseEntity::query()
->where('account_resource_name', $account)
->where('type', $dimensionType)
->pluck('display_name', 'reporting_dimension_id')
->all();
}
/**
* @return Collection<string, string>
*/
private function countryNames(): Collection
{
if (! Schema::hasTable('countries')) {
return collect();
}
return Country::query()
->get(['iso2', 'name', 'name_common'])
->mapWithKeys(function (Country $country): array {
$code = strtoupper((string) $country->iso2);
$name = (string) ($country->name_common ?: $country->name ?: $code);
return $code !== '' ? [$code => $name] : [];
});
}
private function platformLabel(string $key, string $fallback): string
{
return match (strtoupper($key)) {
'DESKTOP' => 'Desktop',
'HIGH_END_MOBILE', 'MOBILE' => 'Mobile',
'TABLET' => 'Tablet',
default => $fallback !== '' ? $fallback : $key,
};
}
/**
* @return array<string, mixed>
*/
private function kpi(string $key, string $label, mixed $current, mixed $previous, string $format, ?string $currency = null): array
{
return [
'key' => $key,
'label' => $label,
'value' => $current,
'previous' => $previous,
'change_percent' => $this->changePercent($current, $previous),
'format' => $format,
'currency_code' => $currency,
];
}
private function changePercent(mixed $current, mixed $previous): ?float
{
$current = (float) $current;
$previous = (float) $previous;
if ($previous == 0.0) {
return null;
}
return (($current - $previous) / $previous) * 100;
}
private function ratio(int $numerator, int $denominator): ?float
{
if ($denominator === 0) {
return null;
}
return $numerator / $denominator;
}
private function rpm(string|float|int|null $earnings, int $pageViews): ?float
{
if ($pageViews === 0) {
return null;
}
return ((float) $earnings / $pageViews) * 1000;
}
private function cpc(string|float|int|null $earnings, int $clicks): ?float
{
if ($clicks === 0) {
return null;
}
return (float) $earnings / $clicks;
}
}
+350
View File
@@ -0,0 +1,350 @@
<?php
declare(strict_types=1);
namespace App\Services\Adsense;
use App\Models\AdsenseConnection;
use App\Services\Adsense\Exceptions\AdsenseApiException;
use App\Services\Adsense\Exceptions\AdsenseAuthorizationException;
use Illuminate\Http\Client\ConnectionException;
use Illuminate\Http\Client\Response;
use Illuminate\Support\Carbon;
use Illuminate\Support\Facades\Http;
use Illuminate\Support\Facades\Log;
use Illuminate\Support\Str;
final class AdsenseApiClient
{
public function __construct(private readonly AdsenseOAuthService $oauth) {}
/**
* @return list<array<string, mixed>>
*/
public function listAccounts(AdsenseConnection $connection): array
{
return $this->paginate($connection, '/accounts', 'accounts');
}
/**
* @return list<array<string, mixed>>
*/
public function listAdClients(AdsenseConnection $connection, string $accountResourceName): array
{
return $this->paginate($connection, '/'.$this->trimPath($accountResourceName).'/adclients', 'adClients');
}
/**
* @return list<array<string, mixed>>
*/
public function listAdUnits(AdsenseConnection $connection, string $adClientResourceName): array
{
return $this->paginate($connection, '/'.$this->trimPath($adClientResourceName).'/adunits', 'adUnits');
}
/**
* @return list<array<string, mixed>>
*/
public function listCustomChannels(AdsenseConnection $connection, string $adClientResourceName): array
{
return $this->paginate($connection, '/'.$this->trimPath($adClientResourceName).'/customchannels', 'customChannels');
}
/**
* @param list<string> $dimensions
* @param list<string> $metrics
* @return array<string, mixed>
*/
public function generateReport(
AdsenseConnection $connection,
string $accountResourceName,
array $dimensions,
array $metrics,
Carbon $from,
Carbon $to,
string $report = '',
): array {
$path = '/'.$this->trimPath($accountResourceName).'/reports:generate';
$merged = [
'headers' => [],
'rows' => [],
];
$pageToken = null;
do {
$query = $this->reportQuery($dimensions, $metrics, $from, $to, $pageToken);
$json = $this->getJson($connection, $path, $query, $report);
if ($merged['headers'] === [] && isset($json['headers']) && is_array($json['headers'])) {
$merged['headers'] = $json['headers'];
}
$rows = $json['rows'] ?? [];
if (is_array($rows) && $rows !== []) {
$merged['rows'] = array_merge($merged['rows'], $rows);
}
foreach (['totals', 'averages', 'startDate', 'endDate', 'warnings'] as $metaKey) {
if (! isset($merged[$metaKey]) && isset($json[$metaKey])) {
$merged[$metaKey] = $json[$metaKey];
}
}
$pageToken = isset($json['nextPageToken']) && is_string($json['nextPageToken']) && $json['nextPageToken'] !== ''
? $json['nextPageToken']
: null;
} while ($pageToken !== null);
return $merged;
}
/**
* @param array<string, scalar|null> $query
* @return list<array<string, mixed>>
*/
private function paginate(AdsenseConnection $connection, string $path, string $itemsKey): array
{
$items = [];
$pageToken = null;
do {
$query = [];
if ($pageToken !== null) {
$query['pageToken'] = $pageToken;
}
$json = $this->getJson($connection, $path, $query);
$pageItems = $json[$itemsKey] ?? [];
if (is_array($pageItems)) {
foreach ($pageItems as $item) {
if (is_array($item)) {
$items[] = $item;
}
}
}
$pageToken = isset($json['nextPageToken']) && is_string($json['nextPageToken']) && $json['nextPageToken'] !== ''
? $json['nextPageToken']
: null;
} while ($pageToken !== null);
return $items;
}
/**
* @param list<string> $dimensions
* @param list<string> $metrics
* @return array<string, scalar>
*/
private function reportQuery(array $dimensions, array $metrics, Carbon $from, Carbon $to, ?string $pageToken): array
{
$query = [
'startDate.year' => $from->year,
'startDate.month' => $from->month,
'startDate.day' => $from->day,
'endDate.year' => $to->year,
'endDate.month' => $to->month,
'endDate.day' => $to->day,
];
foreach ($dimensions as $index => $dimension) {
$query['dimensions'.$index] = $dimension;
}
foreach ($metrics as $index => $metric) {
$query['metrics'.$index] = $metric;
}
if ($pageToken !== null) {
$query['pageToken'] = $pageToken;
}
return $query;
}
/**
* @param array<string, scalar|null> $query
* @return array<string, mixed>
*/
private function getJson(AdsenseConnection $connection, string $path, array $query = [], string $report = ''): array
{
$url = $this->url($path, $query);
$response = $this->send($connection, $url, $report);
$json = $response->json();
if (! is_array($json)) {
throw new AdsenseApiException('Malformed AdSense API response.', $response->status(), $report);
}
return $json;
}
private function send(AdsenseConnection $connection, string $url, string $report = ''): Response
{
$maxAttempts = max(1, (int) config('adsense.retry_times', 3));
$sleepMs = max(0, (int) config('adsense.retry_sleep_ms', 400));
$refreshed = false;
$attempt = 0;
while (true) {
$attempt++;
try {
$response = Http::acceptJson()
->withToken($this->oauth->accessToken($connection))
->timeout((int) config('adsense.timeout', 20))
->connectTimeout((int) config('adsense.connect_timeout', 5))
->get($url);
} catch (AdsenseAuthorizationException $exception) {
throw $exception;
} catch (ConnectionException $exception) {
if ($attempt < $maxAttempts) {
$this->backoff($sleepMs, $attempt);
continue;
}
Log::warning('AdSense API connection failed.', AdsenseLogSanitizer::context([
'message' => $exception->getMessage(),
'report' => $report,
]));
throw new AdsenseApiException('AdSense API connection failed.', 0, $report, $exception);
}
$status = $response->status();
if ($status === 401 && ! $refreshed) {
$this->oauth->forgetAccessToken((int) $connection->id);
try {
$this->oauth->accessToken($connection, true);
} catch (AdsenseAuthorizationException $exception) {
throw $exception;
}
$refreshed = true;
$attempt--;
continue;
}
if (in_array($status, [429, 500, 502, 503, 504], true) && $attempt < $maxAttempts) {
$this->backoff($sleepMs, $attempt);
continue;
}
if ($status === 401 || $status === 403) {
$message = $this->errorMessage($response, 'AdSense API authorization failed.');
Log::warning('AdSense API authorization failed.', AdsenseLogSanitizer::context([
'status' => $status,
'report' => $report,
]));
if ($this->isRevoked($response, $message)) {
$this->oauth->markReconnectRequired($connection, 'AdSense authorization expired or was revoked.');
throw new AdsenseAuthorizationException('AdSense authorization expired or was revoked.');
}
throw new AdsenseApiException($message, $status, $report);
}
if ($response->failed()) {
$message = $this->errorMessage($response, 'AdSense API request failed.');
Log::warning('AdSense API request failed.', AdsenseLogSanitizer::context([
'status' => $status,
'report' => $report,
]));
throw new AdsenseApiException($message, $status, $report);
}
return $response;
}
}
/**
* @param array<string, scalar|null> $query
*/
private function url(string $path, array $query): string
{
$base = rtrim((string) config('adsense.api_base'), '/');
$url = $base.'/'.$this->trimPath($path);
$parts = [];
foreach ($query as $key => $value) {
if ($value === null || $value === '') {
continue;
}
if (str_starts_with((string) $key, 'dimensions')) {
$parts[] = 'dimensions='.rawurlencode((string) $value);
continue;
}
if (str_starts_with((string) $key, 'metrics')) {
$parts[] = 'metrics='.rawurlencode((string) $value);
continue;
}
$parts[] = rawurlencode((string) $key).'='.rawurlencode((string) $value);
}
if ($parts === []) {
return $url;
}
return $url.'?'.implode('&', $parts);
}
private function trimPath(string $path): string
{
return ltrim($path, '/');
}
private function backoff(int $sleepMs, int $attempt): void
{
if ($sleepMs <= 0) {
return;
}
usleep($sleepMs * 1000 * $attempt);
}
private function errorMessage(Response $response, string $fallback): string
{
$json = $response->json();
if (! is_array($json)) {
return $fallback;
}
$error = $json['error'] ?? null;
if (is_string($error) && $error !== '') {
return $error;
}
if (is_array($error)) {
$status = (string) ($error['status'] ?? '');
$message = (string) ($error['message'] ?? '');
$combined = trim($status.' '.$message);
return $combined !== '' ? $combined : $fallback;
}
return $fallback;
}
private function isRevoked(Response $response, string $message): bool
{
$haystack = Str::lower($message.' '.$response->body());
return str_contains($haystack, 'invalid_grant')
|| str_contains($haystack, 'invalid credentials')
|| str_contains($haystack, 'revoked');
}
}
@@ -0,0 +1,68 @@
<?php
declare(strict_types=1);
namespace App\Services\Adsense;
final class AdsenseLogSanitizer
{
/**
* @var list<string>
*/
private const SENSITIVE_KEYS = [
'access_token',
'refresh_token',
'id_token',
'token',
'code',
'client_secret',
'authorization',
'encrypted_refresh_token',
];
/**
* @param array<string, mixed> $context
* @return array<string, mixed>
*/
public static function context(array $context): array
{
$clean = [];
foreach ($context as $key => $value) {
$normalized = strtolower((string) $key);
if (in_array($normalized, self::SENSITIVE_KEYS, true) || str_contains($normalized, 'token') || str_contains($normalized, 'secret')) {
continue;
}
if (is_array($value)) {
$clean[$key] = self::context($value);
continue;
}
if (is_string($value) && self::looksLikeSecret($value)) {
continue;
}
$clean[$key] = $value;
}
return $clean;
}
public static function looksLikeSecret(string $value): bool
{
if ($value === '') {
return false;
}
foreach (['refresh-secret', 'access-secret', 'ya29.', '1//'] as $marker) {
if (str_contains($value, $marker)) {
return true;
}
}
return false;
}
}
@@ -0,0 +1,327 @@
<?php
declare(strict_types=1);
namespace App\Services\Adsense;
use App\Models\AdsenseConnection;
use App\Services\Adsense\Exceptions\AdsenseAuthorizationException;
use App\Services\Adsense\Exceptions\AdsenseOAuthException;
use Illuminate\Http\Client\ConnectionException;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Cache;
use Illuminate\Support\Facades\Http;
use Illuminate\Support\Facades\Log;
use Illuminate\Support\Str;
final class AdsenseOAuthService
{
public const SESSION_STATE_KEY = 'adsense.oauth_state';
public const SESSION_PENDING_ACCOUNTS_KEY = 'adsense.pending_accounts';
public function isConfigured(): bool
{
return $this->clientId() !== '' && $this->clientSecret() !== '' && $this->redirectUri() !== '';
}
public function authorizationUrl(Request $request, bool $promptConsent = true): string
{
if (! $this->isConfigured()) {
throw new AdsenseOAuthException('Google AdSense OAuth is not configured.');
}
$state = bin2hex(random_bytes(32));
$request->session()->put(self::SESSION_STATE_KEY, $state);
$query = [
'client_id' => $this->clientId(),
'redirect_uri' => $this->redirectUri(),
'response_type' => 'code',
'scope' => (string) config('adsense.scope'),
'access_type' => 'offline',
'include_granted_scopes' => 'true',
'state' => $state,
];
if ($promptConsent) {
$query['prompt'] = 'consent';
}
return (string) config('adsense.oauth_authorize_url').'?'.http_build_query($query);
}
/**
* @return array{access_token: string, refresh_token: ?string, expires_in: int}
*/
public function exchangeAuthorizationCode(string $code): array
{
return $this->requestToken([
'grant_type' => 'authorization_code',
'code' => $code,
'redirect_uri' => $this->redirectUri(),
'client_id' => $this->clientId(),
'client_secret' => $this->clientSecret(),
]);
}
/**
* @return array{access_token: string, refresh_token: ?string, expires_in: int}
*/
public function refreshAccessToken(string $refreshToken): array
{
try {
return $this->requestToken([
'grant_type' => 'refresh_token',
'refresh_token' => $refreshToken,
'client_id' => $this->clientId(),
'client_secret' => $this->clientSecret(),
]);
} catch (AdsenseOAuthException $exception) {
if ($this->isInvalidGrant($exception)) {
throw new AdsenseAuthorizationException(
'AdSense authorization expired or was revoked.',
0,
$exception,
);
}
throw $exception;
}
}
public function persistTokens(AdsenseConnection $connection, array $tokens, ?int $userId = null): void
{
$refreshToken = $tokens['refresh_token'] ?? null;
if (is_string($refreshToken) && $refreshToken !== '') {
$connection->encrypted_refresh_token = $refreshToken;
}
if (! $connection->hasRefreshToken()) {
throw new AdsenseOAuthException('Google did not return a refresh token. Reconnect with consent.');
}
if ($userId !== null) {
$connection->connected_by_user_id = $userId;
}
if ($connection->connected_at === null) {
$connection->connected_at = now();
}
if ($connection->status === AdsenseConnection::STATUS_DISCONNECTED) {
$connection->status = AdsenseConnection::STATUS_PENDING;
}
$connection->last_error = null;
$connection->save();
if (isset($tokens['access_token']) && is_string($tokens['access_token']) && $tokens['access_token'] !== '') {
$this->cacheAccessToken(
(int) $connection->id,
$tokens['access_token'],
(int) ($tokens['expires_in'] ?? 3600),
);
}
}
public function accessToken(AdsenseConnection $connection, bool $forceRefresh = false): string
{
if (! $connection->hasRefreshToken()) {
$this->markReconnectRequired($connection, 'AdSense authorization expired or was revoked.');
throw new AdsenseAuthorizationException('AdSense authorization expired or was revoked.');
}
$cacheKey = $this->cacheKey((int) $connection->id);
if (! $forceRefresh) {
$cached = Cache::get($cacheKey);
if (is_string($cached) && $cached !== '') {
return $cached;
}
}
try {
$tokens = $this->refreshAccessToken((string) $connection->encrypted_refresh_token);
} catch (AdsenseAuthorizationException $exception) {
$this->forgetAccessToken((int) $connection->id);
$this->markReconnectRequired($connection, $exception->getMessage());
throw $exception;
}
$accessToken = (string) ($tokens['access_token'] ?? '');
if ($accessToken === '') {
throw new AdsenseOAuthException('Google did not return an access token.');
}
if (isset($tokens['refresh_token']) && is_string($tokens['refresh_token']) && $tokens['refresh_token'] !== '') {
$connection->encrypted_refresh_token = $tokens['refresh_token'];
$connection->save();
}
$this->cacheAccessToken((int) $connection->id, $accessToken, (int) ($tokens['expires_in'] ?? 3600));
return $accessToken;
}
public function cacheAccessToken(int $connectionId, string $accessToken, int $expiresIn): void
{
$ttl = max(30, $expiresIn - (int) config('adsense.access_token_skew_seconds', 60));
Cache::put($this->cacheKey($connectionId), $accessToken, $ttl);
}
public function forgetAccessToken(int $connectionId): void
{
Cache::forget($this->cacheKey($connectionId));
}
public function markReconnectRequired(AdsenseConnection $connection, string $message): void
{
$connection->status = AdsenseConnection::STATUS_RECONNECT_REQUIRED;
$connection->last_error = $message;
$connection->save();
}
public function disconnect(AdsenseConnection $connection): void
{
$refreshToken = $connection->encrypted_refresh_token;
$this->forgetAccessToken((int) $connection->id);
if (is_string($refreshToken) && $refreshToken !== '') {
$this->revokeToken($refreshToken);
}
$connection->encrypted_refresh_token = null;
$connection->status = AdsenseConnection::STATUS_DISCONNECTED;
$connection->last_error = null;
$connection->save();
}
public function revokeToken(string $token): void
{
try {
Http::asForm()
->timeout((int) config('adsense.timeout', 20))
->connectTimeout((int) config('adsense.connect_timeout', 5))
->post((string) config('adsense.oauth_revoke_url'), [
'token' => $token,
]);
} catch (\Throwable $exception) {
Log::warning('AdSense token revocation failed.', AdsenseLogSanitizer::context([
'message' => $exception->getMessage(),
]));
}
}
public function assertValidCallback(Request $request): string
{
$error = trim((string) $request->query('error', ''));
if ($error !== '') {
$description = trim((string) $request->query('error_description', ''));
$request->session()->forget(self::SESSION_STATE_KEY);
throw new AdsenseOAuthException(
$description !== ''
? 'Google AdSense authorization was denied: '.$description
: 'Google AdSense authorization was denied.'
);
}
$expected = (string) $request->session()->pull(self::SESSION_STATE_KEY, '');
$provided = (string) $request->query('state', '');
if ($expected === '' || $provided === '' || ! hash_equals($expected, $provided)) {
throw new AdsenseOAuthException('Invalid OAuth state.');
}
$code = trim((string) $request->query('code', ''));
if ($code === '') {
throw new AdsenseOAuthException('Missing authorization code.');
}
return $code;
}
/**
* @param array<string, string> $payload
* @return array{access_token: string, refresh_token: ?string, expires_in: int}
*/
private function requestToken(array $payload): array
{
try {
$response = Http::asForm()
->acceptJson()
->timeout((int) config('adsense.timeout', 20))
->connectTimeout((int) config('adsense.connect_timeout', 5))
->post((string) config('adsense.oauth_token_url'), $payload);
} catch (ConnectionException $exception) {
Log::warning('AdSense OAuth token request failed.', AdsenseLogSanitizer::context([
'message' => $exception->getMessage(),
]));
throw new AdsenseOAuthException('Unable to contact Google OAuth.', 0, $exception);
}
$json = $response->json();
$json = is_array($json) ? $json : [];
if ($response->failed()) {
$error = $json['error'] ?? 'oauth_error';
if (is_array($error)) {
$error = (string) ($error['message'] ?? $error['status'] ?? 'oauth_error');
} else {
$error = (string) $error;
}
Log::warning('AdSense OAuth token request rejected.', AdsenseLogSanitizer::context([
'status' => $response->status(),
'error' => $error,
]));
throw new AdsenseOAuthException($error, $response->status());
}
$accessToken = (string) ($json['access_token'] ?? '');
if ($accessToken === '') {
throw new AdsenseOAuthException('Google did not return an access token.');
}
$refreshToken = $json['refresh_token'] ?? null;
return [
'access_token' => $accessToken,
'refresh_token' => is_string($refreshToken) && $refreshToken !== '' ? $refreshToken : null,
'expires_in' => (int) ($json['expires_in'] ?? 3600),
];
}
private function isInvalidGrant(AdsenseOAuthException $exception): bool
{
$message = Str::lower($exception->getMessage());
return str_contains($message, 'invalid_grant')
|| str_contains($message, 'revoked')
|| str_contains($message, 'invalid_token');
}
private function cacheKey(int $connectionId): string
{
return (string) config('adsense.access_token_cache_prefix', 'adsense.access_token.').$connectionId;
}
private function clientId(): string
{
return trim((string) config('adsense.client_id'));
}
private function clientSecret(): string
{
return trim((string) config('adsense.client_secret'));
}
public function redirectUri(): string
{
return trim((string) config('adsense.redirect_uri'));
}
}
@@ -0,0 +1,216 @@
<?php
declare(strict_types=1);
namespace App\Services\Adsense;
use App\Models\AdsenseDailyStat;
final class AdsenseReportParser
{
/**
* @var array<string, string>
*/
private const METRIC_COLUMNS = [
'ESTIMATED_EARNINGS' => 'estimated_earnings',
'PAGE_VIEWS' => 'page_views',
'PAGE_VIEWS_CTR' => 'page_views_ctr',
'PAGE_VIEWS_RPM' => 'page_views_rpm',
'AD_REQUESTS' => 'ad_requests',
'AD_REQUESTS_COVERAGE' => 'ad_requests_coverage',
'AD_REQUESTS_CTR' => 'ad_requests_ctr',
'AD_REQUESTS_RPM' => 'ad_requests_rpm',
'MATCHED_AD_REQUESTS' => 'matched_ad_requests',
'IMPRESSIONS' => 'impressions',
'IMPRESSIONS_CTR' => 'impressions_ctr',
'IMPRESSIONS_RPM' => 'impressions_rpm',
'CLICKS' => 'clicks',
'COST_PER_CLICK' => 'cost_per_click',
];
/**
* @var list<string>
*/
private const INTEGER_COLUMNS = [
'page_views',
'ad_requests',
'matched_ad_requests',
'impressions',
'clicks',
];
/**
* @param array<string, mixed> $report
* @return list<array<string, mixed>>
*/
public function parse(array $report, string $dimensionType, string $accountResourceName): array
{
$indexByName = $this->headerIndex($report['headers'] ?? []);
$currencyCode = $this->currencyCode($report['headers'] ?? []);
$rows = [];
foreach ($report['rows'] ?? [] as $row) {
if (! is_array($row)) {
continue;
}
$cells = $row['cells'] ?? [];
if (! is_array($cells)) {
continue;
}
$date = $this->cell($cells, $indexByName, 'DATE');
if (! is_string($date) || $date === '') {
continue;
}
$dimensionKey = $this->dimensionKey($cells, $indexByName, $dimensionType);
if ($dimensionKey === null || $dimensionKey === '') {
continue;
}
$parsed = [
'date' => $date,
'account_resource_name' => $accountResourceName,
'dimension_type' => $dimensionType,
'dimension_key' => $dimensionKey,
'dimension_label' => $this->dimensionLabel($cells, $indexByName, $dimensionType, $dimensionKey),
'currency_code' => $currencyCode,
];
foreach (self::METRIC_COLUMNS as $header => $column) {
$parsed[$column] = $this->metricValue($cells, $indexByName, $header, $column);
}
$rows[] = $parsed;
}
return $rows;
}
public function currencyCode(array $headers): ?string
{
foreach ($headers as $header) {
if (! is_array($header)) {
continue;
}
$type = strtoupper((string) ($header['type'] ?? ''));
$code = trim((string) ($header['currencyCode'] ?? ''));
if ($type === 'METRIC_CURRENCY' && $code !== '') {
return $code;
}
}
return null;
}
/**
* @return array<string, int>
*/
private function headerIndex(mixed $headers): array
{
$index = [];
if (! is_array($headers)) {
return $index;
}
foreach ($headers as $position => $header) {
if (! is_array($header)) {
continue;
}
$name = strtoupper(trim((string) ($header['name'] ?? '')));
if ($name === '') {
continue;
}
$index[$name] = (int) $position;
}
return $index;
}
/**
* @param array<int, mixed> $cells
* @param array<string, int> $indexByName
*/
private function dimensionKey(array $cells, array $indexByName, string $dimensionType): ?string
{
return match ($dimensionType) {
AdsenseDailyStat::DIMENSION_TOTAL => AdsenseDailyStat::TOTAL_DIMENSION_KEY,
AdsenseDailyStat::DIMENSION_AD_UNIT => $this->cell($cells, $indexByName, 'AD_UNIT_ID')
?? $this->cell($cells, $indexByName, 'AD_UNIT_NAME'),
AdsenseDailyStat::DIMENSION_CUSTOM_CHANNEL => $this->cell($cells, $indexByName, 'CUSTOM_CHANNEL_ID')
?? $this->cell($cells, $indexByName, 'CUSTOM_CHANNEL_NAME'),
AdsenseDailyStat::DIMENSION_PLATFORM => $this->cell($cells, $indexByName, 'PLATFORM_TYPE_CODE')
?? $this->cell($cells, $indexByName, 'PLATFORM_TYPE_NAME'),
AdsenseDailyStat::DIMENSION_COUNTRY => $this->cell($cells, $indexByName, 'COUNTRY_CODE')
?? $this->cell($cells, $indexByName, 'COUNTRY_NAME'),
default => null,
};
}
/**
* @param array<int, mixed> $cells
* @param array<string, int> $indexByName
*/
private function dimensionLabel(array $cells, array $indexByName, string $dimensionType, string $dimensionKey): string
{
$label = match ($dimensionType) {
AdsenseDailyStat::DIMENSION_TOTAL => 'Total',
AdsenseDailyStat::DIMENSION_AD_UNIT => $this->cell($cells, $indexByName, 'AD_UNIT_NAME'),
AdsenseDailyStat::DIMENSION_CUSTOM_CHANNEL => $this->cell($cells, $indexByName, 'CUSTOM_CHANNEL_NAME'),
AdsenseDailyStat::DIMENSION_PLATFORM => $this->cell($cells, $indexByName, 'PLATFORM_TYPE_NAME')
?? $this->cell($cells, $indexByName, 'PLATFORM_TYPE_CODE'),
AdsenseDailyStat::DIMENSION_COUNTRY => $this->cell($cells, $indexByName, 'COUNTRY_NAME')
?? $this->cell($cells, $indexByName, 'COUNTRY_CODE'),
default => $dimensionKey,
};
return is_string($label) && $label !== '' ? $label : $dimensionKey;
}
/**
* @param array<int, mixed> $cells
* @param array<string, int> $indexByName
*/
private function cell(array $cells, array $indexByName, string $name): ?string
{
$name = strtoupper($name);
if (! array_key_exists($name, $indexByName)) {
return null;
}
$cell = $cells[$indexByName[$name]] ?? null;
if (is_array($cell)) {
$value = $cell['value'] ?? null;
return is_scalar($value) ? (string) $value : null;
}
return is_scalar($cell) ? (string) $cell : null;
}
/**
* @param array<int, mixed> $cells
* @param array<string, int> $indexByName
*/
private function metricValue(array $cells, array $indexByName, string $header, string $column): int|string|null
{
$raw = $this->cell($cells, $indexByName, $header);
if ($raw === null || $raw === '') {
return null;
}
if (in_array($column, self::INTEGER_COLUMNS, true)) {
return (int) $raw;
}
if (! is_numeric($raw)) {
return null;
}
return $raw;
}
}
@@ -0,0 +1,32 @@
<?php
declare(strict_types=1);
namespace App\Services\Adsense;
final class AdsenseSyncResult
{
/**
* @param list<string> $failedReports
*/
public function __construct(
public string $accountDisplayName = '',
public string $from = '',
public string $to = '',
public int $adUnits = 0,
public int $customChannels = 0,
public int $totalRows = 0,
public int $adUnitRows = 0,
public int $customChannelRows = 0,
public int $platformRows = 0,
public int $countryRows = 0,
public array $failedReports = [],
public bool $entitiesSynced = false,
public bool $reconnectRequired = false,
) {}
public function succeeded(): bool
{
return ! $this->reconnectRequired && $this->failedReports === [];
}
}

Some files were not shown because too many files have changed in this diff Show More