Sitelet https://github.com/backstagephp/laravel-users/compare/main...5.x
Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: backstagephp/laravel-users
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: main
Choose a base ref
...
head repository: backstagephp/laravel-users
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: 5.x
Choose a head ref
Checking mergeability… Don’t worry, you can still create the pull request.
  • 13 commits
  • 15 files changed
  • 6 contributors

Commits on Jan 13, 2026

  1. Add user management

    mhortulanus committed Jan 13, 2026
    Configuration menu
    Copy the full SHA
    11703c2 View commit details
    Browse the repository at this point in the history

Commits on Jan 30, 2026

  1. Configuration menu
    Copy the full SHA
    90987af View commit details
    Browse the repository at this point in the history

Commits on Feb 13, 2026

  1. Configuration menu
    Copy the full SHA
    d1fd8fe View commit details
    Browse the repository at this point in the history

Commits on Feb 19, 2026

  1. perf: queue user login/logout recording to avoid slow DNS lookups (#83)

    The gethostbyaddr() call was blocking the login/logout response,
    causing delays of 1-30+ seconds depending on network conditions.
    
    Now the recording is dispatched to a queue job, so the user gets
    an instant response while the DNS lookup happens in the background.
    
    Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
    Baspa and claude authored Feb 19, 2026
    Configuration menu
    Copy the full SHA
    6e2093d View commit details
    Browse the repository at this point in the history
  2. fix: guard against missing or invalid user model config in RecordUser…

    …Login job
    
    Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
    mhortulanus and claude committed Feb 19, 2026
    Configuration menu
    Copy the full SHA
    2380191 View commit details
    Browse the repository at this point in the history

Commits on Mar 13, 2026

  1. chore: upgrade Laravel Pint to 1.29.0 and apply code style fixes

    Upgraded Pint from 1.27.1 to 1.29.0 to align local development with CI
    workflow. Applied new code style rules across 225 files including:
    - fully_qualified_strict_types
    - ordered_imports
    - braces_position
    - class_definition
    
    Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
    Baspa and claude committed Mar 13, 2026
    Configuration menu
    Copy the full SHA
    b816834 View commit details
    Browse the repository at this point in the history

Commits on Mar 16, 2026

  1. refactor: refine shop plugin models, migrations, resources and config

    Comprehensive refinement of the shop package including:
    - Update all models with proper casts, relationships and table prefixing
    - Modernize all migration stubs with consistent naming and structure
    - Improve Filament resource forms, infolists and tables
    - Add tax rate minimum value validation (must be > 0)
    - Center-align orders count column in customer table
    - Add AddressObserver, InvoiceRelationManager and OrderRelationManager
    - Fix categoriable -> categorizable typo in migration
    - Update config with table prefix support
    - Fix RecordUserLogin to handle nullable userId
    
    Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
    mhortulanus and claude committed Mar 16, 2026
    Configuration menu
    Copy the full SHA
    a513671 View commit details
    Browse the repository at this point in the history
  2. fix: styling

    mhortulanus authored and github-actions[bot] committed Mar 16, 2026
    Configuration menu
    Copy the full SHA
    0f4612f View commit details
    Browse the repository at this point in the history

Commits on Mar 25, 2026

  1. Remove spatie/laravel-ray dependency from all packages

    The dependency is unused — no ray() calls exist in the codebase. Removes it from require-dev in 9 packages, the conflict section in laravel-mails, the CI workflow removal step, and the laravel-ai configure script.
    
    Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
    markvaneijk and claude committed Mar 25, 2026
    Configuration menu
    Copy the full SHA
    d091ce4 View commit details
    Browse the repository at this point in the history

Commits on Mar 30, 2026

  1. Configuration menu
    Copy the full SHA
    d20ba89 View commit details
    Browse the repository at this point in the history

Commits on Apr 3, 2026

  1. feat: add comprehensive shop plugin documentation

    Split docs into separate files under docs/ for with-CMS and without-CMS
    setup guides. Includes configuration reference, storefront routes, payment
    and invoicing setup, authentication, subscriptions, and architecture overview.
    
    Also includes all pending shop refinements: API controllers, web controllers,
    form requests, API resources, storefront views, Alpine.js cart store, tests,
    and route updates.
    
    Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
    mhortulanus and claude committed Apr 3, 2026
    Configuration menu
    Copy the full SHA
    d0d4d8e View commit details
    Browse the repository at this point in the history
  2. fix: styling

    mhortulanus authored and github-actions[bot] committed Apr 3, 2026
    Configuration menu
    Copy the full SHA
    cbc9ce4 View commit details
    Browse the repository at this point in the history

Commits on Jul 7, 2026

  1. ci: fix the Security workflow (pin actions, dependabot cooldown, real…

    … security-check gate) (#279)
    
    * chore(ci): pin GitHub Actions to commit SHAs across the monorepo
    
    Pin every `uses:` reference to a full commit SHA (with a version comment
    so Dependabot keeps them current) across the root workflows and all
    packages/*/.github workflows. Resolves the semgrep
    github-actions-mutable-action-tag findings.
    
    Applied with pinact.
    
    Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
    
    * chore(ci): add a 7-day Dependabot cooldown to every update entry
    
    Add `cooldown: { default-days: 7 }` to each ecosystem in every
    dependabot.yml across the monorepo (and normalise the one pre-existing
    cooldown to 7 days). Resolves the semgrep dependabot-missing-cooldown
    findings and delays pulling freshly-published (possibly compromised)
    releases.
    
    Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
    
    * fix(security-check): treat empty $guarded as a warning, not a failure
    
    Backstage's 17 core models deliberately use `$guarded = []` because
    writes go through validated Filament admin forms, not raw request mass
    assignment. The security check flagged all of them as a high-severity
    failure — a false positive relative to the architecture. Split the
    mass-assignment check so empty $guarded is a medium warning while
    sensitive fields in $fillable remain a hard failure.
    
    Add a Pest test asserting `backstage:security-check --package-only`
    exits 0, and record the decision in ADR-0003.
    
    Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
    
    * chore(ci): pin actions pinact could not auto-resolve, add pinact config
    
    Three pint.yml refs pointed at non-existent tags (laravel-pint-action
    @latest / @2.4.0, git-auto-commit-action @v5.0) that pinact could not
    resolve; pin them to valid release SHAs by hand. Add .pinact.yaml so
    both the one-shot pin and the CI guard cover packages/*/.github
    workflows, not just the root.
    
    Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
    
    * ci(security): gate on the security check, add an action-pinning guard
    
    The Backstage Security Check job never actually ran: this is a package
    repo with no `artisan` binary, and it passed a non-existent `--ci`
    flag, all masked by continue-on-error. Run it through the test harness
    instead (a Pest test that boots the full provider stack), mirroring the
    run-tests MySQL service + extensions + DB env, and drop
    continue-on-error so it genuinely gates CI.
    
    Add an Action Pinning job (pinact-action, fix disabled) that fails when
    any workflow reintroduces an unpinned action.
    
    Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
    
    ---------
    
    Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
    Casmo and claude authored Jul 7, 2026
    Configuration menu
    Copy the full SHA
    22a884b View commit details
    Browse the repository at this point in the history
Loading