2026-06-28 23:43:09 +00:00
|
|
|
<?php
|
|
|
|
|
|
|
|
|
|
declare(strict_types=1);
|
|
|
|
|
|
|
|
|
|
namespace App\Support;
|
|
|
|
|
|
|
|
|
|
use App\Enums\Media\Source;
|
Harden per-image alt text across publishers, validation, and attach paths
Publishing:
- Only send alt text for images (isImage guards on LinkedIn, X, Discord, Mastodon); never inject altText into video/document payloads.
- X sets alt via a best-effort media/metadata call so a metadata failure no longer blocks the tweet.
Validation:
- Validate media alt_text with a closure on media.*.meta so width/height/duration/slide_* survive a post update (Laravel's excludeUnvalidatedArrayKeys was stripping them).
- Add ALT_TEXT_MAX_LENGTH constant, a proper string-type error, and a localized attribute name.
Media attach (REST + MCP):
- Support per-image alt on attach-media-from-url via structured urls: [{url, alt?}] and on the MCP upload tool via an optional alt; alt is stored only for images.
- Carry submitted meta onto hosted external-URL media so alt is no longer dropped.
Composer:
- Alt-text dialog disables Save and reddens the counter over the limit, counting code points of the trimmed value to match the backend.
- Autosave shows 'Saved' only on a successful response; the lightbox alt overlay renders for images only.
Adds unit, feature, MCP, and browser tests covering every path above.
2026-07-16 16:55:33 +00:00
|
|
|
use Closure;
|
2026-06-28 23:43:09 +00:00
|
|
|
use Illuminate\Validation\Rule;
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* Single source of truth for inline post `media` validation, shared by the post
|
|
|
|
|
* create/update flows. The web sends already-hosted media (id + path) and tracks
|
|
|
|
|
* its source; the public REST API may send a bare external `url` we download and
|
|
|
|
|
* host, so the id/path/url rules differ by contract.
|
|
|
|
|
*/
|
|
|
|
|
class PostMediaRules
|
|
|
|
|
{
|
Harden per-image alt text across publishers, validation, and attach paths
Publishing:
- Only send alt text for images (isImage guards on LinkedIn, X, Discord, Mastodon); never inject altText into video/document payloads.
- X sets alt via a best-effort media/metadata call so a metadata failure no longer blocks the tweet.
Validation:
- Validate media alt_text with a closure on media.*.meta so width/height/duration/slide_* survive a post update (Laravel's excludeUnvalidatedArrayKeys was stripping them).
- Add ALT_TEXT_MAX_LENGTH constant, a proper string-type error, and a localized attribute name.
Media attach (REST + MCP):
- Support per-image alt on attach-media-from-url via structured urls: [{url, alt?}] and on the MCP upload tool via an optional alt; alt is stored only for images.
- Carry submitted meta onto hosted external-URL media so alt is no longer dropped.
Composer:
- Alt-text dialog disables Save and reddens the counter over the limit, counting code points of the trimmed value to match the backend.
- Autosave shows 'Saved' only on a successful response; the lightbox alt overlay renders for images only.
Adds unit, feature, MCP, and browser tests covering every path above.
2026-07-16 16:55:33 +00:00
|
|
|
/**
|
|
|
|
|
* Maximum stored length (characters) for a media item's alt text. Publishers
|
|
|
|
|
* truncate further to each platform's own cap via Platform::altTextMaxLength().
|
|
|
|
|
*/
|
|
|
|
|
public const ALT_TEXT_MAX_LENGTH = 2000;
|
|
|
|
|
|
2026-06-28 23:43:09 +00:00
|
|
|
/**
|
|
|
|
|
* @param bool $hosted true (web): items must already be hosted (id + path
|
2026-06-28 23:59:21 +00:00
|
|
|
* required); false (API): a bare external `url` is
|
|
|
|
|
* accepted (and downloaded).
|
2026-06-28 23:43:09 +00:00
|
|
|
* @return array<string, mixed>
|
|
|
|
|
*/
|
|
|
|
|
public static function rules(bool $hosted): array
|
|
|
|
|
{
|
2026-06-28 23:59:21 +00:00
|
|
|
return [
|
2026-06-28 23:43:09 +00:00
|
|
|
'media' => ['sometimes', 'array'],
|
|
|
|
|
'media.*.id' => $hosted ? ['required', 'string'] : ['sometimes', 'nullable', 'string'],
|
|
|
|
|
'media.*.path' => $hosted ? ['required', 'string', 'max:500'] : ['sometimes', 'nullable', 'string', 'max:500'],
|
|
|
|
|
'media.*.url' => $hosted
|
|
|
|
|
? ['required', 'string', 'max:2048']
|
|
|
|
|
: ['required', 'string', 'max:2048', 'url:http,https'],
|
|
|
|
|
'media.*.type' => ['sometimes', 'nullable', 'string', 'max:32'],
|
|
|
|
|
'media.*.mime_type' => ['sometimes', 'nullable', 'string', 'max:255'],
|
|
|
|
|
'media.*.original_filename' => ['sometimes', 'nullable', 'string', 'max:500'],
|
|
|
|
|
'media.*.size' => ['sometimes', 'nullable', 'integer'],
|
Harden per-image alt text across publishers, validation, and attach paths
Publishing:
- Only send alt text for images (isImage guards on LinkedIn, X, Discord, Mastodon); never inject altText into video/document payloads.
- X sets alt via a best-effort media/metadata call so a metadata failure no longer blocks the tweet.
Validation:
- Validate media alt_text with a closure on media.*.meta so width/height/duration/slide_* survive a post update (Laravel's excludeUnvalidatedArrayKeys was stripping them).
- Add ALT_TEXT_MAX_LENGTH constant, a proper string-type error, and a localized attribute name.
Media attach (REST + MCP):
- Support per-image alt on attach-media-from-url via structured urls: [{url, alt?}] and on the MCP upload tool via an optional alt; alt is stored only for images.
- Carry submitted meta onto hosted external-URL media so alt is no longer dropped.
Composer:
- Alt-text dialog disables Save and reddens the counter over the limit, counting code points of the trimmed value to match the backend.
- Autosave shows 'Saved' only on a successful response; the lightbox alt overlay renders for images only.
Adds unit, feature, MCP, and browser tests covering every path above.
2026-07-16 16:55:33 +00:00
|
|
|
'media.*.meta' => ['sometimes', 'nullable', 'array', static function (string $attribute, mixed $value, Closure $fail): void {
|
|
|
|
|
$altText = data_get($value, 'alt_text');
|
|
|
|
|
|
|
|
|
|
if ($altText === null) {
|
|
|
|
|
return;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
if (! is_string($altText)) {
|
|
|
|
|
$fail('validation.string')->translate(['attribute' => trans('posts.edit.alt_text.label')]);
|
|
|
|
|
|
|
|
|
|
return;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
if (mb_strlen($altText) > self::ALT_TEXT_MAX_LENGTH) {
|
|
|
|
|
$fail('validation.max.string')->translate(['attribute' => trans('posts.edit.alt_text.label'), 'max' => self::ALT_TEXT_MAX_LENGTH]);
|
|
|
|
|
}
|
|
|
|
|
}],
|
2026-06-28 23:59:21 +00:00
|
|
|
'media.*.source' => ['sometimes', 'nullable', 'string', Rule::in(array_column(Source::cases(), 'value'))],
|
|
|
|
|
'media.*.source_meta' => ['sometimes', 'nullable', 'array'],
|
2026-06-28 23:43:09 +00:00
|
|
|
];
|
|
|
|
|
}
|
|
|
|
|
}
|