index.php 4.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138
  1. <?php
  2. declare(strict_types=1);
  3. use App\Auth\LocalAdmin;
  4. use App\Auth\OidcClient;
  5. use App\Auth\SessionGuard;
  6. use App\Controllers\AuthController;
  7. use App\Controllers\SprintController;
  8. use App\Controllers\WorkerController;
  9. use App\Db\Connection;
  10. use App\Db\Migrator;
  11. use App\Http\Request;
  12. use App\Http\Response;
  13. use App\Http\Router;
  14. use App\Http\View;
  15. use App\Repositories\SprintRepository;
  16. use App\Repositories\UserRepository;
  17. use App\Repositories\WorkerRepository;
  18. use App\Services\AuditLogger;
  19. // Buffer output so a stray warning/notice can't send headers before
  20. // Response::send() gets a chance to set them. send() will flush.
  21. ob_start();
  22. define('APP_ROOT', dirname(__DIR__));
  23. // ---------------------------------------------------------------------------
  24. // Autoload
  25. // ---------------------------------------------------------------------------
  26. $autoload = APP_ROOT . '/vendor/autoload.php';
  27. if (!is_file($autoload)) {
  28. http_response_code(500);
  29. header('Content-Type: text/plain; charset=utf-8');
  30. echo "Composer dependencies are not installed.\n";
  31. echo "Run: composer install (or rebuild the container).\n";
  32. exit;
  33. }
  34. require $autoload;
  35. // ---------------------------------------------------------------------------
  36. // Environment
  37. // ---------------------------------------------------------------------------
  38. if (is_file(APP_ROOT . '/.env')) {
  39. $dotenv = Dotenv\Dotenv::createImmutable(APP_ROOT);
  40. $dotenv->safeLoad();
  41. }
  42. $appEnv = getenv('APP_ENV') ?: 'production';
  43. if ($appEnv !== 'production') {
  44. ini_set('display_errors', '1');
  45. error_reporting(E_ALL);
  46. } else {
  47. ini_set('display_errors', '0');
  48. }
  49. // ---------------------------------------------------------------------------
  50. // Migrations — cheap no-op when already current
  51. // ---------------------------------------------------------------------------
  52. try {
  53. $pdo = Connection::pdo();
  54. (new Migrator($pdo))->migrate();
  55. } catch (\Throwable $e) {
  56. http_response_code(500);
  57. header('Content-Type: text/plain; charset=utf-8');
  58. echo "Database bootstrap failed.\n";
  59. if ($appEnv !== 'production') {
  60. echo $e->getMessage() . "\n";
  61. }
  62. exit;
  63. }
  64. // ---------------------------------------------------------------------------
  65. // Shared services
  66. // ---------------------------------------------------------------------------
  67. $view = new View(APP_ROOT . '/views');
  68. $users = new UserRepository($pdo);
  69. $workers = new WorkerRepository($pdo);
  70. $sprints = new SprintRepository($pdo);
  71. $audit = new AuditLogger($pdo);
  72. $auth = new AuthController($pdo, $users, $audit, $view);
  73. $workerCtrl = new WorkerController($pdo, $users, $workers, $audit, $view);
  74. $sprintCtrl = new SprintController($pdo, $users, $sprints, $audit, $view);
  75. // ---------------------------------------------------------------------------
  76. // Routing
  77. // ---------------------------------------------------------------------------
  78. $router = new Router();
  79. $router->get('/', function (Request $req) use ($view, $pdo, $users, $sprints, $appEnv): Response {
  80. $currentUser = SessionGuard::currentUser($users);
  81. $schemaVersion = (int) $pdo->query(
  82. 'SELECT COALESCE(MAX(version), 0) FROM schema_version'
  83. )->fetchColumn();
  84. $sprintRows = $currentUser === null ? [] : $sprints->allWithCounts();
  85. return Response::html($view->render('home', [
  86. 'title' => 'Sprint Planner',
  87. 'currentUser' => $currentUser,
  88. 'schemaVersion' => $schemaVersion,
  89. 'dbPath' => Connection::path(),
  90. 'appEnv' => $appEnv,
  91. 'oidcConfigured' => OidcClient::isConfigured(),
  92. 'localAdminEnabled' => LocalAdmin::isEnabled(),
  93. 'authError' => isset($req->query['auth_error']),
  94. 'csrfToken' => SessionGuard::csrfToken(),
  95. 'sprintRows' => $sprintRows,
  96. ]));
  97. });
  98. $router->get('/healthz', fn() => Response::text('ok'));
  99. $router->get('/auth/login', $auth->login(...));
  100. $router->get('/auth/callback', $auth->callback(...));
  101. $router->post('/auth/logout', $auth->logout(...));
  102. $router->get('/auth/local', $auth->loginLocalForm(...));
  103. $router->post('/auth/local', $auth->loginLocal(...));
  104. $router->get('/workers', $workerCtrl->index(...));
  105. $router->post('/workers', $workerCtrl->create(...));
  106. $router->post('/workers/{id}', $workerCtrl->update(...));
  107. $router->get('/sprints/new', $sprintCtrl->newForm(...));
  108. $router->post('/sprints', $sprintCtrl->create(...));
  109. $router->get('/sprints/{id}', $sprintCtrl->show(...));
  110. // ---------------------------------------------------------------------------
  111. // Dispatch
  112. // ---------------------------------------------------------------------------
  113. $request = Request::fromGlobals();
  114. $response = $router->dispatch($request);
  115. $response->send();
  116. // Flush the output buffer opened at the top.
  117. if (ob_get_level() > 0) {
  118. @ob_end_flush();
  119. }