Commit Graph

37 Commits

Author SHA1 Message Date
f2d1acac35 scan flow: fire scan immediately on tag-page load (location is an upgrade, not a gate) so a tag view always records+alerts; add request logging middleware (method/path/status/duration) to stdout for diagnostics 2026-08-10 18:51:35 +10:00
1fae314eb4 tag claim flow: scanned code auto-fills Add Tag field (?code=), unclaimed tag page shows 'Add this tag to my account' when logged in, login honors next= so code survives the login step 2026-08-10 17:04:21 +10:00
04fd5ac63a fix: legacy QR URLs without '?' (productid in path) redirect to /t/CODE (new tag 97 now scans); preview page photo portrait aspect; Preview button on user tags list; admin photo form = preview + standalone Upload button (removed URL TextInput — no duplicate, no stale placeholder) 2026-08-10 16:54:10 +10:00
ae0290b343 admin: photo preview fixed size (inline styles); preview mode ?preview=1 (banner, no scan functionality) with Preview buttons in admin row action + owner edit link 2026-08-10 16:36:22 +10:00
eb3e4f45ad admin: Tags-list photo thumbnail (null when no photo — fixes empty src), edit-form photo preview (blade view), 'View live page' row action; owner: 'View the live tag page' link on edit 2026-08-10 16:27:40 +10:00
fd91d3c53e fix: admin upload action fillForm()->refreshFormData(['photo_url']) (fillForm threw in action closure); photo cache-busting (?v=updated_at) so overwritten photos don't show stale browser cache (user 'reverting to old images') 2026-08-10 16:18:08 +10:00
aaad9f2db6 fix (research-backed): admin upload limits via mounted php.ini conf.d (artisan serve child ignores -d flags — Filament docs: set php.ini); user photo preview always rendered (was conditional -> FileReader target missing); PNG upload+save+display verified 2026-08-10 15:34:13 +10:00
ab3aa5aee9 fix: remove photo_url text input from user form (photo only via file upload; handler keeps existing photo when no file); livewire config published (disk=local, 12MB, 2min upload — was 5s default breaking admin temp uploads) 2026-08-10 15:07:15 +10:00
ef20af0d92 fix: user photo upload now INSIDE the main edit form (one Save = file+fields, no JS); admin resource FQNs corrected (relative Filament\Forms refs = panel-wide 500) 2026-08-10 14:47:07 +10:00
fc7f3bf675 fix: user photo_url input type=text (type=url rejected relative /photos/ paths = form block); admin inline upload action leading-backslash namespace (was panel-wide 500) 2026-08-10 14:41:04 +10:00
704cc4606f fix: user photo form explicit method=post+enctype (405 when htmx missed it); admin upload action moved inline as suffix on the photo field; verified real PNG upload+serve 2026-08-10 14:31:24 +10:00
3001e816cd fix: admin 'Upload photo' action (modal FileUpload, stores to MinIO, sets photo_url — no foreach 500); user upload limit 5MB->10MB; photo_url input shows full value (visual truncation only) 2026-08-10 14:20:35 +10:00
b14341e344 fix: admin photo fields -> TextInput + ImageColumn (FileUpload foreach 500 gone); user upload syncs photo_url input so Save keeps the photo; ProductResource photo added 2026-08-10 14:13:18 +10:00
bcf6f3115d fix: admin FileUpload single-path columns (array state + dehydrate — was foreach error = admin edit 500); user photo upload targets thumb div only so the form/button survives re-uploads 2026-08-10 14:01:55 +10:00
f38beb4cfe fix: user tag edit photo upload — standalone form (was nested inside main form, invalid HTML), thumbnail on success; restore sms_enabled on tag 6; admin upload accepts HEIC (no image() rule) 2026-08-10 13:51:49 +10:00
23508fc468 fix: Edit link navigates to the full tag edit page (was intercepted by hx-get inline); admin upload limits raised (12M via php -d) + FileUpload maxSize 10MB — fixes 'failed to upload' on phone photos 2026-08-10 13:14:47 +10:00
e38128c33f fix per feedback: remove home recent-scans; admin dashboard recent-scans -> tag edit links + item column; inline tag edit gets photo upload; explicit deploy sync (no dir-rsync flakiness) 2026-08-10 13:04:43 +10:00
83d75cb29f home: recent-scans list (links + tag ids); admin tags: item_type column, searchable tag code/description/owner; admin photo upload: drop imageEditor (unbundled JS); owner edit photo upload confirmed 2026-08-10 12:52:52 +10:00
9158681001 fix batch: admin login rehash->password_hash mapping (500); geolocation timeout 20s + hide button on approval + 'location shared' notice; sms: link includes typed number (Alpine); location page = found-dog + map + finder number + tag details; nicer closed page; password visibility toggles; product photos; templates use x-text (no {{}} in Alpine) 2026-08-10 12:27:20 +10:00
b5db858ef8 fix: seed-admin emits $2y$ bcrypt prefix so Laravel admin login works (was $2a$ -> 500 'does not use the Bcrypt algorithm') 2026-08-10 12:00:03 +10:00
ae231c97f6 compat: /index.php?productid= legacy URL form redirects to /t/{code} (covers old printed QR URLs) 2026-08-10 11:51:58 +10:00
97cf0974a3 tag-lifecycle: owner close (status closed, gating + page) + move (copy details to new tag, close source) + legacy ?productid= redirect — verified with real tags 6 & 17 2026-08-10 11:36:11 +10:00
9d43403f6f renewal-unlock: orders.renews_at lazy expiry + owner unlock notices (ntfy/sms channels, exempt from metering) — verified 2026-08-10 10:10:50 +10:00
17150c405d ops: live SMS creds on .13; seed-admin cmd in make db-up (admin survives DB resets) 2026-08-10 10:07:29 +10:00
e1044f8c32 admin-insights-pages: dashboard customers+revenue (orders.amount), users->tags relation, pause customer (gates alerts), About/What-is-this/Contact pages 2026-08-10 09:19:14 +10:00
426c99296d auth: shared session cookie domain (SESSION_COOKIE_DOMAIN) so apex + www stay logged in 2026-08-08 15:23:40 +10:00
5487cee966 sms-metering-location-link: per-tag SMS credits (allocated/used, admin top-up), short URLs + owner location page (map embed + finder details) — 13/13 scenarios 2026-08-08 14:38:32 +10:00
d5919315fa photo-object-storage: MinIO on .13 (9010/9011), Go upload+serve /photos, admin S3 disk + Filament upload, migrated, deployed 2026-08-08 10:01:02 +10:00
3d242fdcaa scan-limits-gating: paid-order gating + per-tag daily cap + per-IP hourly rate (6/6 scenarios) — no gateway 2026-08-08 09:25:06 +10:00
0ee211d156 tuxedo notes: photo upload, username/email display + confirm-email, favicon; verified owner-only edit 2026-08-07 19:46:08 +10:00
aa023cf89e Phase 3: HTMX inline tag editing, swap animations, loading indicators, Alpine phone validation 2026-08-07 18:18:49 +10:00
61737825ea scan-alert-hardening: different-finder re-alert within 250m window + fingerprint 24h block (12/12 scenarios pass) 2026-08-07 17:29:47 +10:00
e3bcd2e6e0 tag-registry-product-link: seed 100 real preset IDs (seed-registry cmd), products/orders schema + tag linkage, fix case-sensitive tag-code bind 2026-08-07 16:56:50 +10:00
0dbf728f00 Fix transposed test number: +61 423 274 487 (61423274487) everywhere 2026-08-07 16:17:55 +10:00
d4679068ba scan-flow step 9: real SMS via SMSGlobal HTTP API (smshttp sender, proven live OK:0) + docs 2026-08-07 16:10:52 +10:00
c2fa04afd0 scan-flow: geolocation scan, location-aware SMS throttle (log sender), finder contact, sms_enabled toggle, branding — 19/19 phase-2 scenarios pass 2026-08-05 18:23:34 +10:00
133e375b6b frontend-foundation: GOAT front-end Phase 1 — auth, tag management, public tag page (22/22 spec scenarios pass) 2026-08-05 13:46:50 +10:00