2026-04-15 23:18:21 +00:00
|
|
|
<?php
|
|
|
|
|
|
|
|
|
|
declare(strict_types=1);
|
|
|
|
|
|
|
|
|
|
use App\Enums\UserWorkspace\Role;
|
feat: @mentions in comments, AI Action layer + MCP tools, settings tabs
Mentions in post comments
- @mention autocomplete (workspace members, current user excluded) with
marker syntax @[uuid] persisted, display names rendered via CommentBody
chips; live edit replaces markers with names and converts back on save.
- NotifyMentions action with workspace-scoped membership check, dedupes
same user, only newly-added mentions on update.
- Email + in-app via SendNotification job, respecting per-user
notification_preferences.mentioned_in_comment.
- Heartbeat-based presence (Cache, 60s TTL, 30s ping) so online recipients
get only the in-app notification — no email noise.
- Real-time bell on workspace.{id}.user.{id} private channel
(NotificationCreated event), scoped channel name avoids client-side
filtering and lays out a convention for future workspace channels.
- Mailable localized via lang/{en,es,pt-BR}/mail.php; Maizzle source
template for the email is committed and built into resources/views/mail.
AI generation refactor (Action layer + MCP)
- Extracted Actions/Ai/Generate{Image,Video} with QuotaExhaustedException
so agent tools and MCP tools share a single domain entry point.
- Mcp/Tools/Ai/Generate{Image,Video}Tool registered in TryPostServer; both
return MediaResource payloads.
- Orientation::imageApiSize maps non-OpenAI ratios to 1:1/2:3/3:2.
- config/ai.php is now the single source of truth driven by env, removing
the trypost.ai shim. Default text/image providers flipped to OpenAI.
Settings/UX
- /settings/workspace split into shadcn Tabs (Workspace / Brand / Users)
with three components.
- /assets and the in-editor MediaPicker open the ImagePreviewDialog
lightbox on image click while preserving action button behaviour.
- Comments tab landed via ?tab=comments&comment=<id> from notification
click (scroll-to + temporary highlight).
- Mention autocomplete popover flips above when near the viewport bottom.
- Real social platform PNGs replace Tabler brand glyphs in schedule
pills and post list, with hover tooltip carrying display_name + handle.
Bug fixes
- AcceptInvite: controller now passes workspace + role payload that the
Vue page expects; login/register CTAs preselect the invite email.
- WorkspaceInvite mailable: stopped referencing nonexistent
$invite->workspace and $invite->role; column added to the migration,
Invite model casts role to WorkspaceRole, CreateInvite persists it.
- PostCommentCreated: added broadcastAs so .PostCommentCreated actually
matches the Echo listener; payload now includes mentioned_users so
receivers render the chip correctly without a refetch.
- Preview components for X/Pinterest/Threads/Bluesky/LinkedIn/Mastodon/
TikTok/YouTube switched from item.type === 'image' to
!isVideoMedia(item) so media without a persisted type still renders.
- UpdatePostRequest now accepts media.*.{type,mime_type,size,...} so the
posts.media JSON keeps the metadata that the previews need.
- Removed throttle:6,1 from social connect routes (was 429ing legitimate
OAuth retries).
- Used MediaType enum cases instead of literal 'image'/'video' strings
when creating media rows.
Tests
- MentionParser unit tests, NotifyMentions feature tests including
online/offline channel selection and preference gating, MCP AI tool
happy paths, MentionedInComment mailable rendering, AcceptInvite +
search-members + index mentioned_users path. 1229 passing.
2026-05-01 23:59:03 +00:00
|
|
|
use App\Jobs\SendNotification;
|
2026-04-15 23:18:21 +00:00
|
|
|
use App\Models\Post;
|
|
|
|
|
use App\Models\PostComment;
|
|
|
|
|
use App\Models\User;
|
|
|
|
|
use App\Models\Workspace;
|
feat: @mentions in comments, AI Action layer + MCP tools, settings tabs
Mentions in post comments
- @mention autocomplete (workspace members, current user excluded) with
marker syntax @[uuid] persisted, display names rendered via CommentBody
chips; live edit replaces markers with names and converts back on save.
- NotifyMentions action with workspace-scoped membership check, dedupes
same user, only newly-added mentions on update.
- Email + in-app via SendNotification job, respecting per-user
notification_preferences.mentioned_in_comment.
- Heartbeat-based presence (Cache, 60s TTL, 30s ping) so online recipients
get only the in-app notification — no email noise.
- Real-time bell on workspace.{id}.user.{id} private channel
(NotificationCreated event), scoped channel name avoids client-side
filtering and lays out a convention for future workspace channels.
- Mailable localized via lang/{en,es,pt-BR}/mail.php; Maizzle source
template for the email is committed and built into resources/views/mail.
AI generation refactor (Action layer + MCP)
- Extracted Actions/Ai/Generate{Image,Video} with QuotaExhaustedException
so agent tools and MCP tools share a single domain entry point.
- Mcp/Tools/Ai/Generate{Image,Video}Tool registered in TryPostServer; both
return MediaResource payloads.
- Orientation::imageApiSize maps non-OpenAI ratios to 1:1/2:3/3:2.
- config/ai.php is now the single source of truth driven by env, removing
the trypost.ai shim. Default text/image providers flipped to OpenAI.
Settings/UX
- /settings/workspace split into shadcn Tabs (Workspace / Brand / Users)
with three components.
- /assets and the in-editor MediaPicker open the ImagePreviewDialog
lightbox on image click while preserving action button behaviour.
- Comments tab landed via ?tab=comments&comment=<id> from notification
click (scroll-to + temporary highlight).
- Mention autocomplete popover flips above when near the viewport bottom.
- Real social platform PNGs replace Tabler brand glyphs in schedule
pills and post list, with hover tooltip carrying display_name + handle.
Bug fixes
- AcceptInvite: controller now passes workspace + role payload that the
Vue page expects; login/register CTAs preselect the invite email.
- WorkspaceInvite mailable: stopped referencing nonexistent
$invite->workspace and $invite->role; column added to the migration,
Invite model casts role to WorkspaceRole, CreateInvite persists it.
- PostCommentCreated: added broadcastAs so .PostCommentCreated actually
matches the Echo listener; payload now includes mentioned_users so
receivers render the chip correctly without a refetch.
- Preview components for X/Pinterest/Threads/Bluesky/LinkedIn/Mastodon/
TikTok/YouTube switched from item.type === 'image' to
!isVideoMedia(item) so media without a persisted type still renders.
- UpdatePostRequest now accepts media.*.{type,mime_type,size,...} so the
posts.media JSON keeps the metadata that the previews need.
- Removed throttle:6,1 from social connect routes (was 429ing legitimate
OAuth retries).
- Used MediaType enum cases instead of literal 'image'/'video' strings
when creating media rows.
Tests
- MentionParser unit tests, NotifyMentions feature tests including
online/offline channel selection and preference gating, MCP AI tool
happy paths, MentionedInComment mailable rendering, AcceptInvite +
search-members + index mentioned_users path. 1229 passing.
2026-05-01 23:59:03 +00:00
|
|
|
use Illuminate\Support\Facades\Queue;
|
2026-04-15 23:18:21 +00:00
|
|
|
|
|
|
|
|
beforeEach(function () {
|
2026-04-17 02:05:51 +00:00
|
|
|
$this->user = User::factory()->create([]);
|
2026-04-15 23:18:21 +00:00
|
|
|
$this->workspace = Workspace::factory()->create(['user_id' => $this->user->id]);
|
|
|
|
|
$this->workspace->members()->attach($this->user->id, ['role' => Role::Member->value]);
|
|
|
|
|
$this->user->update(['current_workspace_id' => $this->workspace->id]);
|
|
|
|
|
|
|
|
|
|
$this->post = Post::factory()->create([
|
|
|
|
|
'workspace_id' => $this->workspace->id,
|
|
|
|
|
'user_id' => $this->user->id,
|
|
|
|
|
]);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('index returns paginated comments with replies', function () {
|
|
|
|
|
$parent = PostComment::factory()->create([
|
|
|
|
|
'post_id' => $this->post->id,
|
|
|
|
|
'user_id' => $this->user->id,
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$reply = PostComment::factory()->reply($parent)->create([
|
|
|
|
|
'user_id' => $this->user->id,
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$response = $this->actingAs($this->user)
|
|
|
|
|
->getJson(route('app.posts.comments.index', $this->post));
|
|
|
|
|
|
|
|
|
|
$response->assertOk();
|
|
|
|
|
$response->assertJsonCount(1, 'data');
|
|
|
|
|
$response->assertJsonPath('data.0.id', $parent->id);
|
|
|
|
|
$response->assertJsonCount(1, 'data.0.replies');
|
|
|
|
|
$response->assertJsonPath('data.0.replies.0.id', $reply->id);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('store creates a comment', function () {
|
|
|
|
|
$response = $this->actingAs($this->user)
|
|
|
|
|
->postJson(route('app.posts.comments.store', $this->post), [
|
|
|
|
|
'body' => 'This is a comment.',
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$response->assertCreated();
|
|
|
|
|
$response->assertJsonPath('body', 'This is a comment.');
|
|
|
|
|
|
|
|
|
|
$this->assertDatabaseHas('post_comments', [
|
|
|
|
|
'post_id' => $this->post->id,
|
|
|
|
|
'user_id' => $this->user->id,
|
|
|
|
|
'body' => 'This is a comment.',
|
|
|
|
|
'parent_id' => null,
|
|
|
|
|
]);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('store creates a reply', function () {
|
|
|
|
|
$parent = PostComment::factory()->create([
|
|
|
|
|
'post_id' => $this->post->id,
|
|
|
|
|
'user_id' => $this->user->id,
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$response = $this->actingAs($this->user)
|
|
|
|
|
->postJson(route('app.posts.comments.store', $this->post), [
|
|
|
|
|
'body' => 'This is a reply.',
|
|
|
|
|
'parent_id' => $parent->id,
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$response->assertCreated();
|
|
|
|
|
$response->assertJsonPath('parent_id', $parent->id);
|
|
|
|
|
|
|
|
|
|
$this->assertDatabaseHas('post_comments', [
|
|
|
|
|
'post_id' => $this->post->id,
|
|
|
|
|
'parent_id' => $parent->id,
|
|
|
|
|
'body' => 'This is a reply.',
|
|
|
|
|
]);
|
|
|
|
|
});
|
|
|
|
|
|
feat: @mentions in comments, AI Action layer + MCP tools, settings tabs
Mentions in post comments
- @mention autocomplete (workspace members, current user excluded) with
marker syntax @[uuid] persisted, display names rendered via CommentBody
chips; live edit replaces markers with names and converts back on save.
- NotifyMentions action with workspace-scoped membership check, dedupes
same user, only newly-added mentions on update.
- Email + in-app via SendNotification job, respecting per-user
notification_preferences.mentioned_in_comment.
- Heartbeat-based presence (Cache, 60s TTL, 30s ping) so online recipients
get only the in-app notification — no email noise.
- Real-time bell on workspace.{id}.user.{id} private channel
(NotificationCreated event), scoped channel name avoids client-side
filtering and lays out a convention for future workspace channels.
- Mailable localized via lang/{en,es,pt-BR}/mail.php; Maizzle source
template for the email is committed and built into resources/views/mail.
AI generation refactor (Action layer + MCP)
- Extracted Actions/Ai/Generate{Image,Video} with QuotaExhaustedException
so agent tools and MCP tools share a single domain entry point.
- Mcp/Tools/Ai/Generate{Image,Video}Tool registered in TryPostServer; both
return MediaResource payloads.
- Orientation::imageApiSize maps non-OpenAI ratios to 1:1/2:3/3:2.
- config/ai.php is now the single source of truth driven by env, removing
the trypost.ai shim. Default text/image providers flipped to OpenAI.
Settings/UX
- /settings/workspace split into shadcn Tabs (Workspace / Brand / Users)
with three components.
- /assets and the in-editor MediaPicker open the ImagePreviewDialog
lightbox on image click while preserving action button behaviour.
- Comments tab landed via ?tab=comments&comment=<id> from notification
click (scroll-to + temporary highlight).
- Mention autocomplete popover flips above when near the viewport bottom.
- Real social platform PNGs replace Tabler brand glyphs in schedule
pills and post list, with hover tooltip carrying display_name + handle.
Bug fixes
- AcceptInvite: controller now passes workspace + role payload that the
Vue page expects; login/register CTAs preselect the invite email.
- WorkspaceInvite mailable: stopped referencing nonexistent
$invite->workspace and $invite->role; column added to the migration,
Invite model casts role to WorkspaceRole, CreateInvite persists it.
- PostCommentCreated: added broadcastAs so .PostCommentCreated actually
matches the Echo listener; payload now includes mentioned_users so
receivers render the chip correctly without a refetch.
- Preview components for X/Pinterest/Threads/Bluesky/LinkedIn/Mastodon/
TikTok/YouTube switched from item.type === 'image' to
!isVideoMedia(item) so media without a persisted type still renders.
- UpdatePostRequest now accepts media.*.{type,mime_type,size,...} so the
posts.media JSON keeps the metadata that the previews need.
- Removed throttle:6,1 from social connect routes (was 429ing legitimate
OAuth retries).
- Used MediaType enum cases instead of literal 'image'/'video' strings
when creating media rows.
Tests
- MentionParser unit tests, NotifyMentions feature tests including
online/offline channel selection and preference gating, MCP AI tool
happy paths, MentionedInComment mailable rendering, AcceptInvite +
search-members + index mentioned_users path. 1229 passing.
2026-05-01 23:59:03 +00:00
|
|
|
test('index returns mentioned_users map for chip rendering', function () {
|
|
|
|
|
$other = User::factory()->create(['name' => 'Other Member']);
|
|
|
|
|
$this->workspace->members()->attach($other->id, ['role' => Role::Member->value]);
|
|
|
|
|
|
|
|
|
|
PostComment::factory()->create([
|
|
|
|
|
'post_id' => $this->post->id,
|
|
|
|
|
'user_id' => $this->user->id,
|
|
|
|
|
'body' => "Ping @[{$other->id}] please",
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$response = $this->actingAs($this->user)
|
|
|
|
|
->getJson(route('app.posts.comments.index', $this->post));
|
|
|
|
|
|
|
|
|
|
$response->assertOk();
|
|
|
|
|
$response->assertJsonPath("mentioned_users.{$other->id}", 'Other Member');
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('store dispatches a mention notification to a workspace member', function () {
|
|
|
|
|
Queue::fake();
|
|
|
|
|
|
|
|
|
|
$other = User::factory()->create();
|
|
|
|
|
$this->workspace->members()->attach($other->id, ['role' => Role::Member->value]);
|
|
|
|
|
|
|
|
|
|
$response = $this->actingAs($this->user)
|
|
|
|
|
->postJson(route('app.posts.comments.store', $this->post), [
|
|
|
|
|
'body' => "Hey @[{$other->id}] please review",
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$response->assertCreated();
|
|
|
|
|
|
|
|
|
|
Queue::assertPushed(
|
|
|
|
|
SendNotification::class,
|
|
|
|
|
fn ($job) => $job->user->id === $other->id
|
|
|
|
|
);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('update with newly added mention dispatches a notification', function () {
|
|
|
|
|
Queue::fake();
|
|
|
|
|
|
|
|
|
|
$other = User::factory()->create();
|
|
|
|
|
$this->workspace->members()->attach($other->id, ['role' => Role::Member->value]);
|
|
|
|
|
|
|
|
|
|
$comment = PostComment::factory()->create([
|
|
|
|
|
'post_id' => $this->post->id,
|
|
|
|
|
'user_id' => $this->user->id,
|
|
|
|
|
'body' => 'Plain body, no mention.',
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$response = $this->actingAs($this->user)
|
|
|
|
|
->putJson(route('app.posts.comments.update', [$this->post, $comment]), [
|
|
|
|
|
'body' => "Updated to mention @[{$other->id}]",
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$response->assertOk();
|
|
|
|
|
|
|
|
|
|
Queue::assertPushed(
|
|
|
|
|
SendNotification::class,
|
|
|
|
|
fn ($job) => $job->user->id === $other->id
|
|
|
|
|
);
|
|
|
|
|
});
|
|
|
|
|
|
2026-04-15 23:18:21 +00:00
|
|
|
test('store rejects reply to a reply', function () {
|
|
|
|
|
$parent = PostComment::factory()->create([
|
|
|
|
|
'post_id' => $this->post->id,
|
|
|
|
|
'user_id' => $this->user->id,
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$reply = PostComment::factory()->reply($parent)->create([
|
|
|
|
|
'user_id' => $this->user->id,
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$response = $this->actingAs($this->user)
|
|
|
|
|
->postJson(route('app.posts.comments.store', $this->post), [
|
|
|
|
|
'body' => 'Nested reply attempt.',
|
|
|
|
|
'parent_id' => $reply->id,
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$response->assertStatus(422);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('update own comment', function () {
|
|
|
|
|
$comment = PostComment::factory()->create([
|
|
|
|
|
'post_id' => $this->post->id,
|
|
|
|
|
'user_id' => $this->user->id,
|
|
|
|
|
'body' => 'Original body.',
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$response = $this->actingAs($this->user)
|
|
|
|
|
->putJson(route('app.posts.comments.update', [$this->post, $comment]), [
|
|
|
|
|
'body' => 'Updated body.',
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$response->assertOk();
|
|
|
|
|
$response->assertJsonPath('body', 'Updated body.');
|
|
|
|
|
|
|
|
|
|
$this->assertDatabaseHas('post_comments', [
|
|
|
|
|
'id' => $comment->id,
|
|
|
|
|
'body' => 'Updated body.',
|
|
|
|
|
]);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('cannot update other user comment', function () {
|
2026-04-17 02:05:51 +00:00
|
|
|
$otherUser = User::factory()->create([]);
|
2026-04-15 23:18:21 +00:00
|
|
|
$this->workspace->members()->attach($otherUser->id, ['role' => Role::Member->value]);
|
|
|
|
|
$otherUser->update(['current_workspace_id' => $this->workspace->id]);
|
|
|
|
|
|
|
|
|
|
$comment = PostComment::factory()->create([
|
|
|
|
|
'post_id' => $this->post->id,
|
|
|
|
|
'user_id' => $this->user->id,
|
|
|
|
|
'body' => 'Original body.',
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$response = $this->actingAs($otherUser)
|
|
|
|
|
->putJson(route('app.posts.comments.update', [$this->post, $comment]), [
|
|
|
|
|
'body' => 'Hacked body.',
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$response->assertForbidden();
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('delete own comment', function () {
|
|
|
|
|
$comment = PostComment::factory()->create([
|
|
|
|
|
'post_id' => $this->post->id,
|
|
|
|
|
'user_id' => $this->user->id,
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$response = $this->actingAs($this->user)
|
|
|
|
|
->deleteJson(route('app.posts.comments.destroy', [$this->post, $comment]));
|
|
|
|
|
|
|
|
|
|
$response->assertNoContent();
|
|
|
|
|
|
|
|
|
|
$this->assertDatabaseMissing('post_comments', [
|
|
|
|
|
'id' => $comment->id,
|
|
|
|
|
]);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('cannot delete other user comment', function () {
|
2026-04-17 02:05:51 +00:00
|
|
|
$otherUser = User::factory()->create([]);
|
2026-04-15 23:18:21 +00:00
|
|
|
$this->workspace->members()->attach($otherUser->id, ['role' => Role::Member->value]);
|
|
|
|
|
$otherUser->update(['current_workspace_id' => $this->workspace->id]);
|
|
|
|
|
|
|
|
|
|
$comment = PostComment::factory()->create([
|
|
|
|
|
'post_id' => $this->post->id,
|
|
|
|
|
'user_id' => $this->user->id,
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$response = $this->actingAs($otherUser)
|
|
|
|
|
->deleteJson(route('app.posts.comments.destroy', [$this->post, $comment]));
|
|
|
|
|
|
|
|
|
|
$response->assertForbidden();
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('react toggles emoji', function () {
|
|
|
|
|
$comment = PostComment::factory()->create([
|
|
|
|
|
'post_id' => $this->post->id,
|
|
|
|
|
'user_id' => $this->user->id,
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
// First reaction adds the emoji
|
|
|
|
|
$response = $this->actingAs($this->user)
|
|
|
|
|
->postJson(route('app.posts.comments.react', [$this->post, $comment]), [
|
|
|
|
|
'emoji' => '👍',
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$response->assertOk();
|
|
|
|
|
$comment->refresh();
|
|
|
|
|
expect($comment->reactions)->toHaveCount(1);
|
|
|
|
|
expect($comment->reactions[0]['emoji'])->toBe('👍');
|
|
|
|
|
expect($comment->reactions[0]['user_id'])->toBe($this->user->id);
|
|
|
|
|
|
|
|
|
|
// Same reaction again removes the emoji
|
|
|
|
|
$response = $this->actingAs($this->user)
|
|
|
|
|
->postJson(route('app.posts.comments.react', [$this->post, $comment]), [
|
|
|
|
|
'emoji' => '👍',
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$response->assertOk();
|
|
|
|
|
$comment->refresh();
|
|
|
|
|
expect($comment->reactions)->toHaveCount(0);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('cannot comment on post from other workspace', function () {
|
2026-04-17 02:05:51 +00:00
|
|
|
$otherUser = User::factory()->create([]);
|
2026-04-15 23:18:21 +00:00
|
|
|
$otherWorkspace = Workspace::factory()->create(['user_id' => $otherUser->id]);
|
|
|
|
|
$otherWorkspace->members()->attach($otherUser->id, ['role' => Role::Member->value]);
|
|
|
|
|
$otherUser->update(['current_workspace_id' => $otherWorkspace->id]);
|
|
|
|
|
|
|
|
|
|
$response = $this->actingAs($otherUser)
|
|
|
|
|
->postJson(route('app.posts.comments.store', $this->post), [
|
|
|
|
|
'body' => 'Cross-workspace comment.',
|
|
|
|
|
]);
|
|
|
|
|
|
|
|
|
|
$response->assertForbidden();
|
|
|
|
|
});
|