index.php 8.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217
  1. <?php
  2. declare(strict_types=1);
  3. use App\Auth\LocalAdmin;
  4. use App\Auth\OidcClient;
  5. use App\Auth\SessionGuard;
  6. use App\Controllers\AuditController;
  7. use App\Controllers\AuthController;
  8. use App\Controllers\SprintController;
  9. use App\Controllers\TaskController;
  10. use App\Controllers\UserController;
  11. use App\Controllers\WorkerController;
  12. use App\Db\Connection;
  13. use App\Db\Migrator;
  14. use App\Http\Request;
  15. use App\Http\Response;
  16. use App\Http\Router;
  17. use App\Http\View;
  18. use App\Repositories\AuditRepository;
  19. use App\Repositories\SprintRepository;
  20. use App\Repositories\SprintWeekRepository;
  21. use App\Repositories\SprintWorkerDayRepository;
  22. use App\Repositories\SprintWorkerRepository;
  23. use App\Repositories\TaskAssignmentRepository;
  24. use App\Repositories\TaskRepository;
  25. use App\Repositories\UserRepository;
  26. use App\Repositories\WorkerRepository;
  27. use App\Services\AuditLogger;
  28. // Buffer output so a stray warning/notice can't send headers before
  29. // Response::send() gets a chance to set them. send() will flush.
  30. ob_start();
  31. define('APP_ROOT', dirname(__DIR__));
  32. // ---------------------------------------------------------------------------
  33. // Autoload
  34. // ---------------------------------------------------------------------------
  35. $autoload = APP_ROOT . '/vendor/autoload.php';
  36. if (!is_file($autoload)) {
  37. http_response_code(500);
  38. header('Content-Type: text/plain; charset=utf-8');
  39. echo "Composer dependencies are not installed.\n";
  40. echo "Run: composer install (or rebuild the container).\n";
  41. exit;
  42. }
  43. require $autoload;
  44. // ---------------------------------------------------------------------------
  45. // Environment
  46. // ---------------------------------------------------------------------------
  47. if (is_file(APP_ROOT . '/.env')) {
  48. $dotenv = Dotenv\Dotenv::createImmutable(APP_ROOT);
  49. $dotenv->safeLoad();
  50. }
  51. $appEnv = getenv('APP_ENV') ?: 'production';
  52. if ($appEnv !== 'production') {
  53. ini_set('display_errors', '1');
  54. error_reporting(E_ALL);
  55. } else {
  56. ini_set('display_errors', '0');
  57. }
  58. // ---------------------------------------------------------------------------
  59. // Migrations — cheap no-op when already current
  60. // ---------------------------------------------------------------------------
  61. try {
  62. $pdo = Connection::pdo();
  63. (new Migrator($pdo))->migrate();
  64. } catch (\Throwable $e) {
  65. http_response_code(500);
  66. header('Content-Type: text/plain; charset=utf-8');
  67. echo "Database bootstrap failed.\n";
  68. if ($appEnv !== 'production') {
  69. echo $e->getMessage() . "\n";
  70. }
  71. exit;
  72. }
  73. // ---------------------------------------------------------------------------
  74. // Shared services
  75. // ---------------------------------------------------------------------------
  76. $view = new View(APP_ROOT . '/views');
  77. $users = new UserRepository($pdo);
  78. $workers = new WorkerRepository($pdo);
  79. $sprints = new SprintRepository($pdo);
  80. $sprintWeeks = new SprintWeekRepository($pdo);
  81. $sprintWorkers = new SprintWorkerRepository($pdo);
  82. $swDays = new SprintWorkerDayRepository($pdo);
  83. $tasks = new TaskRepository($pdo);
  84. $taskAssign = new TaskAssignmentRepository($pdo);
  85. $auditRepo = new AuditRepository($pdo);
  86. $audit = new AuditLogger($pdo);
  87. $auth = new AuthController($pdo, $users, $audit, $view);
  88. $workerCtrl = new WorkerController($pdo, $users, $workers, $audit, $view);
  89. $sprintCtrl = new SprintController(
  90. $pdo, $users, $sprints, $sprintWeeks, $sprintWorkers, $swDays,
  91. $tasks, $taskAssign, $workers, $audit, $view,
  92. );
  93. $taskCtrl = new TaskController(
  94. $pdo, $users, $sprints, $sprintWorkers, $swDays,
  95. $tasks, $taskAssign, $workers, $audit,
  96. );
  97. $auditCtrl = new AuditController($users, $auditRepo, $view);
  98. $userCtrl = new UserController($pdo, $users, $audit, $view);
  99. // ---------------------------------------------------------------------------
  100. // Routing
  101. // ---------------------------------------------------------------------------
  102. $router = new Router();
  103. $router->get('/', function (Request $req) use ($view, $pdo, $users, $sprints, $appEnv): Response {
  104. $currentUser = SessionGuard::currentUser($users);
  105. $schemaVersion = (int) $pdo->query(
  106. 'SELECT COALESCE(MAX(version), 0) FROM schema_version'
  107. )->fetchColumn();
  108. $sprintRows = $currentUser === null ? [] : $sprints->allWithCounts();
  109. return Response::html($view->render('home', [
  110. 'title' => 'Sprint Planner',
  111. 'currentUser' => $currentUser,
  112. 'schemaVersion' => $schemaVersion,
  113. 'dbPath' => Connection::path(),
  114. 'appEnv' => $appEnv,
  115. 'oidcConfigured' => OidcClient::isConfigured(),
  116. 'localAdminEnabled' => LocalAdmin::isEnabled(),
  117. 'authError' => isset($req->query['auth_error']),
  118. 'csrfToken' => SessionGuard::csrfToken(),
  119. 'sprintRows' => $sprintRows,
  120. ]));
  121. });
  122. $router->get('/healthz', fn() => Response::text('ok'));
  123. $router->get('/auth/login', $auth->login(...));
  124. $router->get('/auth/callback', $auth->callback(...));
  125. $router->post('/auth/logout', $auth->logout(...));
  126. $router->get('/auth/local', $auth->loginLocalForm(...));
  127. $router->post('/auth/local', $auth->loginLocal(...));
  128. $router->get('/workers', $workerCtrl->index(...));
  129. $router->post('/workers', $workerCtrl->create(...));
  130. $router->post('/workers/{id}', $workerCtrl->update(...));
  131. $router->get('/users', $userCtrl->index(...));
  132. $router->post('/users/{id}', $userCtrl->update(...));
  133. $router->get('/sprints/new', $sprintCtrl->newForm(...));
  134. $router->post('/sprints', $sprintCtrl->create(...));
  135. $router->get('/sprints/{id}', $sprintCtrl->show(...));
  136. $router->get('/sprints/{id}/present', $sprintCtrl->present(...));
  137. $router->get('/sprints/{id}/settings', $sprintCtrl->settings(...));
  138. // JSON mutation endpoints (admin, CSRF via X-CSRF-Token header):
  139. $router->patch('/sprints/{id}', $sprintCtrl->updateMeta(...));
  140. $router->post('/sprints/{id}/weeks', $sprintCtrl->replaceWeeks(...));
  141. $router->post('/sprints/{id}/workers', $sprintCtrl->addWorker(...));
  142. $router->delete('/sprints/{id}/workers/{sw_id}', $sprintCtrl->removeWorker(...));
  143. $router->post('/sprints/{id}/workers/reorder', $sprintCtrl->reorderWorkers(...));
  144. $router->patch('/sprints/{id}/workers/{sw_id}', $sprintCtrl->updateWorker(...));
  145. // Phase 5 — Arbeitstage grid:
  146. $router->patch('/sprints/{id}/week-cells', $sprintCtrl->updateWeekCells(...));
  147. $router->patch('/sprints/{id}/week/{week_id}', $sprintCtrl->updateWeekDays(...));
  148. // Phase 6 — Task list:
  149. $router->get('/audit', $auditCtrl->index(...));
  150. $router->post('/sprints/{id}/tasks', $taskCtrl->create(...));
  151. $router->post('/sprints/{id}/tasks/reorder', $taskCtrl->reorder(...));
  152. $router->patch('/tasks/{id}', $taskCtrl->update(...));
  153. $router->delete('/tasks/{id}', $taskCtrl->delete(...));
  154. $router->patch('/tasks/{id}/assignments', $taskCtrl->updateAssignments(...));
  155. // ---------------------------------------------------------------------------
  156. // Dispatch
  157. // ---------------------------------------------------------------------------
  158. $request = Request::fromGlobals();
  159. $response = $router->dispatch($request);
  160. // Apply security headers to every response (spec §9). Kept here (instead of
  161. // Response::send) so the policy is visible + editable in one place.
  162. $isHttps = str_starts_with((string) (getenv('APP_BASE_URL') ?: ''), 'https://');
  163. // Strict CSP (Phase 11). With Tailwind pre-compiled at image-build time and
  164. // the last inline onclick replaced by `public/assets/js/app.js`, neither
  165. // 'unsafe-inline' nor the Tailwind CDN host are needed anymore.
  166. $csp = implode('; ', [
  167. "default-src 'self'",
  168. "script-src 'self' https://code.jquery.com",
  169. "style-src 'self' https://code.jquery.com",
  170. "img-src 'self' data:",
  171. "font-src 'self' data: https://code.jquery.com",
  172. "connect-src 'self'",
  173. "frame-ancestors 'none'",
  174. "base-uri 'self'",
  175. "form-action 'self' https://login.microsoftonline.com",
  176. ]);
  177. $response
  178. ->withHeader('X-Content-Type-Options', 'nosniff')
  179. ->withHeader('X-Frame-Options', 'DENY')
  180. ->withHeader('Referrer-Policy', 'strict-origin-when-cross-origin')
  181. ->withHeader('Content-Security-Policy', $csp);
  182. if ($isHttps) {
  183. $response->withHeader('Strict-Transport-Security', 'max-age=31536000; includeSubDomains');
  184. }
  185. $response->send();
  186. // Flush the output buffer opened at the top.
  187. if (ob_get_level() > 0) {
  188. @ob_end_flush();
  189. }