1
0

index.php 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298
  1. <?php
  2. declare(strict_types=1);
  3. use App\Auth\LocalAdmin;
  4. use App\Auth\OidcClient;
  5. use App\Auth\SessionGuard;
  6. use App\Controllers\AuditController;
  7. use App\Controllers\AuthController;
  8. use App\Controllers\ImportController;
  9. use App\Controllers\SettingsController;
  10. use App\Controllers\SprintController;
  11. use App\Controllers\TaskController;
  12. use App\Controllers\UserController;
  13. use App\Controllers\WorkerController;
  14. use App\Db\Connection;
  15. use App\Db\Migrator;
  16. use App\Http\Request;
  17. use App\Http\Response;
  18. use App\Http\Router;
  19. use App\Http\TrustedProxies;
  20. use App\Http\View;
  21. use App\Repositories\AppSettingsRepository;
  22. use App\Repositories\AuditRepository;
  23. use App\Repositories\AuthThrottleRepository;
  24. use App\Repositories\SprintRepository;
  25. use App\Repositories\SprintWeekRepository;
  26. use App\Repositories\SprintWorkerDayRepository;
  27. use App\Repositories\SprintWorkerRepository;
  28. use App\Repositories\TaskAssignmentRepository;
  29. use App\Repositories\TaskRepository;
  30. use App\Repositories\UserRepository;
  31. use App\Repositories\WorkerRepository;
  32. use App\Services\AuditLogger;
  33. use App\Services\Import\SprintImporter;
  34. use App\Services\Import\XlsxSprintImporter;
  35. // Buffer output so a stray warning/notice can't send headers before
  36. // Response::send() gets a chance to set them. send() will flush.
  37. ob_start();
  38. define('APP_ROOT', dirname(__DIR__));
  39. // ---------------------------------------------------------------------------
  40. // Autoload
  41. // ---------------------------------------------------------------------------
  42. $autoload = APP_ROOT . '/vendor/autoload.php';
  43. if (!is_file($autoload)) {
  44. http_response_code(500);
  45. header('Content-Type: text/plain; charset=utf-8');
  46. echo "Composer dependencies are not installed.\n";
  47. echo "Run: composer install (or rebuild the container).\n";
  48. exit;
  49. }
  50. require $autoload;
  51. // ---------------------------------------------------------------------------
  52. // Environment
  53. // ---------------------------------------------------------------------------
  54. if (is_file(APP_ROOT . '/.env')) {
  55. $dotenv = Dotenv\Dotenv::createImmutable(APP_ROOT);
  56. $dotenv->safeLoad();
  57. }
  58. $appEnv = getenv('APP_ENV') ?: 'production';
  59. if ($appEnv !== 'production') {
  60. ini_set('display_errors', '1');
  61. error_reporting(E_ALL);
  62. } else {
  63. ini_set('display_errors', '0');
  64. }
  65. // ---------------------------------------------------------------------------
  66. // Migrations — cheap no-op when already current
  67. // ---------------------------------------------------------------------------
  68. try {
  69. $pdo = Connection::pdo();
  70. (new Migrator($pdo))->migrate();
  71. } catch (\Throwable $e) {
  72. http_response_code(500);
  73. header('Content-Type: text/plain; charset=utf-8');
  74. echo "Database bootstrap failed.\n";
  75. if ($appEnv !== 'production') {
  76. echo $e->getMessage() . "\n";
  77. }
  78. exit;
  79. }
  80. // ---------------------------------------------------------------------------
  81. // Shared services
  82. // ---------------------------------------------------------------------------
  83. $twigCacheDir = APP_ROOT . '/data/twig-cache';
  84. if (!is_dir($twigCacheDir)) {
  85. @mkdir($twigCacheDir, 0775, true);
  86. }
  87. $view = new View(APP_ROOT . '/views', $twigCacheDir);
  88. $users = new UserRepository($pdo);
  89. $workers = new WorkerRepository($pdo);
  90. $sprints = new SprintRepository($pdo);
  91. $sprintWeeks = new SprintWeekRepository($pdo);
  92. $sprintWorkers = new SprintWorkerRepository($pdo);
  93. $swDays = new SprintWorkerDayRepository($pdo);
  94. $tasks = new TaskRepository($pdo);
  95. $taskAssign = new TaskAssignmentRepository($pdo);
  96. $auditRepo = new AuditRepository($pdo);
  97. $appSettings = new AppSettingsRepository($pdo);
  98. $authThrottle = new AuthThrottleRepository($pdo);
  99. $audit = new AuditLogger($pdo);
  100. $auth = new AuthController($pdo, $users, $audit, $view, $authThrottle);
  101. $workerCtrl = new WorkerController($pdo, $users, $workers, $audit, $view);
  102. $sprintCtrl = new SprintController(
  103. $pdo, $users, $sprints, $sprintWeeks, $sprintWorkers, $swDays,
  104. $tasks, $taskAssign, $workers, $audit, $view, $appSettings,
  105. );
  106. $taskCtrl = new TaskController(
  107. $pdo, $users, $sprints, $sprintWorkers, $swDays,
  108. $tasks, $taskAssign, $workers, $audit, $appSettings,
  109. );
  110. $auditCtrl = new AuditController($users, $auditRepo, $view);
  111. $userCtrl = new UserController($pdo, $users, $audit, $view);
  112. $settingsCtrl = new SettingsController($pdo, $users, $appSettings, $audit, $view);
  113. $xlsxParser = new XlsxSprintImporter();
  114. $importCommit = new SprintImporter(
  115. $pdo, $sprints, $sprintWeeks, $sprintWorkers, $swDays,
  116. $tasks, $taskAssign, $workers, $audit,
  117. );
  118. $importCtrl = new ImportController(
  119. $pdo, $users, $sprints, $xlsxParser, $importCommit, $view,
  120. );
  121. // ---------------------------------------------------------------------------
  122. // Routing
  123. // ---------------------------------------------------------------------------
  124. $router = new Router();
  125. $router->get('/', function (Request $req) use ($view, $pdo, $users, $sprints, $appEnv): Response {
  126. $currentUser = SessionGuard::currentUser($users);
  127. $schemaVersion = (int) $pdo->query(
  128. 'SELECT COALESCE(MAX(version), 0) FROM schema_version'
  129. )->fetchColumn();
  130. $sprintRows = $currentUser === null ? [] : $sprints->allWithCounts();
  131. return Response::html($view->render('home', [
  132. 'title' => 'Sprint Planner',
  133. 'currentUser' => $currentUser,
  134. 'schemaVersion' => $schemaVersion,
  135. 'dbPath' => Connection::path(),
  136. 'appEnv' => $appEnv,
  137. 'oidcConfigured' => OidcClient::isConfigured(),
  138. 'localAdminEnabled' => LocalAdmin::isEnabled(),
  139. 'authError' => isset($req->query['auth_error']),
  140. 'deletedSprintName' => $req->queryString('deleted'),
  141. 'csrfToken' => SessionGuard::csrfToken(),
  142. 'sprintRows' => $sprintRows,
  143. ]));
  144. });
  145. $router->get('/healthz', fn() => Response::text('ok'));
  146. $router->get('/auth/login', $auth->login(...));
  147. $router->get('/auth/callback', $auth->callback(...));
  148. $router->post('/auth/logout', $auth->logout(...));
  149. $router->get('/auth/local', $auth->loginLocalForm(...));
  150. $router->post('/auth/local', $auth->loginLocal(...));
  151. $router->get('/workers', $workerCtrl->index(...));
  152. $router->post('/workers', $workerCtrl->create(...));
  153. $router->post('/workers/{id}', $workerCtrl->update(...));
  154. $router->get('/users', $userCtrl->index(...));
  155. $router->post('/users/{id}', $userCtrl->update(...));
  156. $router->get('/sprints/import', $importCtrl->newForm(...));
  157. $router->post('/sprints/import', $importCtrl->upload(...));
  158. $router->get('/sprints/import/{token}', $importCtrl->preview(...));
  159. $router->post('/sprints/import/{token}', $importCtrl->commit(...));
  160. $router->get('/sprints/new', $sprintCtrl->newForm(...));
  161. $router->post('/sprints', $sprintCtrl->create(...));
  162. $router->get('/sprints/{id}', $sprintCtrl->show(...));
  163. $router->get('/sprints/{id}/present', $sprintCtrl->present(...));
  164. $router->get('/sprints/{id}/settings', $sprintCtrl->settings(...));
  165. $router->post('/sprints/{id}/delete', $sprintCtrl->delete(...));
  166. // JSON mutation endpoints (admin, CSRF via X-CSRF-Token header):
  167. $router->patch('/sprints/{id}', $sprintCtrl->updateMeta(...));
  168. $router->post('/sprints/{id}/weeks', $sprintCtrl->replaceWeeks(...));
  169. $router->post('/sprints/{id}/workers', $sprintCtrl->addWorker(...));
  170. $router->delete('/sprints/{id}/workers/{sw_id}', $sprintCtrl->removeWorker(...));
  171. $router->post('/sprints/{id}/workers/reorder', $sprintCtrl->reorderWorkers(...));
  172. $router->patch('/sprints/{id}/workers/{sw_id}', $sprintCtrl->updateWorker(...));
  173. // Phase 5 — Arbeitstage grid:
  174. $router->patch('/sprints/{id}/week-cells', $sprintCtrl->updateWeekCells(...));
  175. $router->patch('/sprints/{id}/week/{week_id}', $sprintCtrl->updateWeekDays(...));
  176. // Phase 6 — Task list:
  177. $router->get('/audit', $auditCtrl->index(...));
  178. $router->post('/sprints/{id}/tasks', $taskCtrl->create(...));
  179. $router->post('/sprints/{id}/tasks/reorder', $taskCtrl->reorder(...));
  180. $router->patch('/tasks/{id}', $taskCtrl->update(...));
  181. $router->delete('/tasks/{id}', $taskCtrl->delete(...));
  182. $router->patch('/tasks/{id}/assignments', $taskCtrl->updateAssignments(...));
  183. // Phase 18 — task-cell status (any signed-in user, gated by global flag):
  184. $router->patch('/tasks/{id}/assignments/status', $taskCtrl->updateAssignmentsStatus(...));
  185. // Phase 22 — task move/copy across sprints (admin):
  186. $router->post('/tasks/{id}/move', $taskCtrl->moveToSprint(...));
  187. $router->post('/tasks/{id}/copy', $taskCtrl->copyToSprint(...));
  188. // Phase 18 — global app settings (admin):
  189. $router->get('/settings', $settingsCtrl->show(...));
  190. $router->post('/settings', $settingsCtrl->update(...));
  191. // ---------------------------------------------------------------------------
  192. // Dispatch
  193. // ---------------------------------------------------------------------------
  194. $request = Request::fromGlobals();
  195. // R01-N05: when `APP_BASE_URL` declares HTTPS, refuse to serve sensitive
  196. // flows over plain HTTP — redirect the user to the canonical scheme before
  197. // any controller, session, or auth logic runs. `/healthz` is exempt so
  198. // liveness probes continue to work over either scheme. The decision uses
  199. // the trusted-proxy helper so a TLS-terminating reverse proxy can pass
  200. // `X-Forwarded-Proto: https` and the app will treat the request as secure.
  201. $baseUrl = (string) (getenv('APP_BASE_URL') ?: '');
  202. $baseIsHttps = str_starts_with($baseUrl, 'https://');
  203. $proxies = TrustedProxies::fromEnv();
  204. $requestIsHttps = $proxies->isHttps($_SERVER);
  205. // Only redirect when we can be SURE the live request is genuinely HTTP —
  206. // otherwise a TLS proxy that forgot to set `X-Forwarded-Proto` would loop
  207. // forever (proxy talks HTTPS to user, talks HTTP to us, we redirect, …).
  208. // Sure cases:
  209. // * no `TRUSTED_PROXIES` configured → REMOTE_ADDR is the user, so the
  210. // server-side scheme is authoritative;
  211. // * `TRUSTED_PROXIES` configured AND REMOTE_ADDR is a trusted proxy AND
  212. // it explicitly told us `X-Forwarded-Proto: http`.
  213. $xfpRaw = (string) ($_SERVER['HTTP_X_FORWARDED_PROTO'] ?? '');
  214. $xfp = strtolower(trim(strtok($xfpRaw, ',') ?: ''));
  215. $remote = (string) ($_SERVER['REMOTE_ADDR'] ?? '');
  216. $noProxy = getenv('TRUSTED_PROXIES') === false || trim((string) getenv('TRUSTED_PROXIES')) === '';
  217. $knownHttp = !$requestIsHttps && (
  218. $noProxy
  219. || ($remote !== '' && $proxies->isTrusted($remote) && $xfp === 'http')
  220. );
  221. if ($baseIsHttps && $knownHttp && $request->path !== '/healthz') {
  222. $target = rtrim($baseUrl, '/') . ($_SERVER['REQUEST_URI'] ?? '/');
  223. Response::redirect($target, 308)->send();
  224. if (ob_get_level() > 0) {
  225. @ob_end_flush();
  226. }
  227. exit;
  228. }
  229. $response = $router->dispatch($request);
  230. // Apply security headers to every response (spec §9). Kept here (instead of
  231. // Response::send) so the policy is visible + editable in one place.
  232. // HSTS is emitted whenever the canonical base URL is HTTPS — sticking the
  233. // header on plain-HTTP responses is harmless (browsers ignore it from
  234. // non-secure contexts) and avoids a gap during the very first redirect.
  235. $isHttps = $baseIsHttps;
  236. // Strict CSP (Phase 11 + Phase 19). Tailwind is pre-compiled at image-build
  237. // time, jQuery / jQuery UI are gone, and Alpine (CSP build), htmx, and
  238. // SortableJS are vendored under /assets/js/vendor/ — so script-src and
  239. // style-src are 'self' only, no 'unsafe-eval', no 'unsafe-inline', no CDN
  240. // hosts. font-src keeps `data:` for the few inline data-URL glyphs.
  241. $csp = implode('; ', [
  242. "default-src 'self'",
  243. "script-src 'self'",
  244. "style-src 'self'",
  245. "img-src 'self' data:",
  246. "font-src 'self' data:",
  247. "connect-src 'self'",
  248. "frame-ancestors 'none'",
  249. "base-uri 'self'",
  250. "form-action 'self' https://login.microsoftonline.com",
  251. ]);
  252. $response
  253. ->withHeader('X-Content-Type-Options', 'nosniff')
  254. ->withHeader('X-Frame-Options', 'DENY')
  255. ->withHeader('Referrer-Policy', 'strict-origin-when-cross-origin')
  256. ->withHeader('Content-Security-Policy', $csp);
  257. if ($isHttps) {
  258. $response->withHeader('Strict-Transport-Security', 'max-age=31536000; includeSubDomains');
  259. }
  260. $response->send();
  261. // Flush the output buffer opened at the top.
  262. if (ob_get_level() > 0) {
  263. @ob_end_flush();
  264. }