trypost/app/Http/Controllers/Auth/RegisteredUserController.php

62 lines
1.8 KiB
PHP
Raw Normal View History

2026-01-20 19:53:54 +00:00
<?php
declare(strict_types=1);
namespace App\Http\Controllers\Auth;
2026-03-31 00:18:07 +00:00
use App\Actions\User\CreateUser;
feat: capture ad click IDs for ad-platform conversion attribution (#276) * feat: capture ad click IDs for Meta/Google/LinkedIn/TikTok/Reddit/Pinterest attribution Adds gclid, fbclid, li_fat_id, ttclid, rdt_cid, and epik columns to users, captured the same way UTM parameters already are (query string -> session -> persisted on signup, surviving the OAuth redirect round-trip via the new PreservesClickIds trait). Forwards them as first-touch ($set_once) PostHog person properties in SyncUser, so PostHog's native ad-platform destinations (Meta Ads Conversions API, Google Ads Conversions, LinkedIn Ads, TikTok Ads, Reddit Ads, Pinterest) have first-party click IDs to match conversions back to the originating ad click. * refactor: unify PreservesUtmParameters and PreservesClickIds into one trait Both traits captured a set of query-string keys into the session and retrieved them at signup, with identical extract/store/retrieve logic and every call site always using both together — the split added no real separation, just duplicated the same mechanism twice. PreservesAttributionParameters replaces both with a single ATTRIBUTION_KEYS list and one session key. Adding a future ad network's click ID is now one line in that list instead of a second trait. * refactor: split UTM_KEYS and CLICK_ID_KEYS into separate constants Same single trait, single session key, single extract/store/retrieve mechanism — just two named arrays instead of one merged list, so it's clear at a glance which key belongs to which category. * fix: don't truncate ad click IDs to 255 chars, only UTM parameters Ad platforms explicitly warn against assuming a fixed max length for click IDs (Google: gclid has already grown from 26 to 100+ chars, and their docs say never truncate or validate against a fixed length). Truncating would silently corrupt the value into something that no longer matches the real click ID, which is worse than not capturing it at all. Widens the click-id columns from string (VARCHAR 255) to text — safe to edit the migration in place since it hasn't shipped to production yet. UTM parameters still get truncated to 255, since those are ours (our own campaign URLs) and the column stays VARCHAR(255). * refactor: use Laravel collection/Str helpers, forward UTMs to PostHog too - extractAttributionParameters now reads through collect()/Str::limit() instead of raw array_filter/array_map/mb_substr; storeAttributionParameters drops its now-redundant emptiness check since retrieveAttributionParameters already treats "absent" and "present-but-empty" the same via pull()'s default. - SyncUser forwards utm_source/medium/campaign/term/content alongside the click ids as first-touch ($set_once) PostHog person properties. UTMs were never sent to PostHog before this, on any prior code — now that PostHog is the source of truth for ad-platform attribution, it should have the full picture, not just click ids. - Adds the missing GitHub-existing-user click-id session test, mirroring the Google one (parity with the existing UTM coverage). * fix: 3 issues found by review — empty-string leak, duplicated key list, comment style - extractAttributionParameters no longer keeps an empty-string value (e.g. ?utm_source=&gclid=, which some ad/email templates always append even for unfilled slots). The refactor to collect()/Str::limit() a few commits back dropped the outer array_filter() that used to strip these, so they were slipping into User::create() as '' instead of staying null. Restored via a trailing ->filter() on the merged result, and extended the same protection to click ids (which never had it, even before that refactor). - New App\Support\AttributionKeys centralizes the UTM_KEYS/CLICK_ID_KEYS lists that PreservesAttributionParameters and SyncUser each maintained independently. SyncUser previously hand-listed the same 11 field names as a second array with no shared source of truth — a future ad network added to the trait would silently never reach PostHog unless someone remembered to update this second copy too. - Removed the // comment block from the click-id migration explaining the text-column rationale — CLAUDE.md's PHP rules reserve inline comments for exceptionally complex logic; the rationale already lives in the commit message that introduced it.
2026-08-11 18:07:23 +00:00
use App\Http\Controllers\Auth\Concerns\PreservesAttributionParameters;
2026-01-20 19:53:54 +00:00
use App\Http\Controllers\Controller;
Allow account owners to delete workspaces (#208) * Allow owners and admins to delete workspaces from settings. Expose a danger zone with name confirmation, sync Stripe quantity on SaaS, and skip billing constraints in self-hosted mode. Co-authored-by: Cursor <cursoragent@cursor.com> * Drop redundant canDelete prop from workspace settings. The settings page is already gated by update (owner/admin), which matches delete. Co-authored-by: Cursor <cursoragent@cursor.com> * Extract workspace delete danger zone into DeleteWorkspace component. Co-authored-by: Cursor <cursoragent@cursor.com> * Clarify workspace delete billing copy across locales. Co-authored-by: Cursor <cursoragent@cursor.com> * Match workspace delete card to the delete-account settings pattern. Co-authored-by: Cursor <cursoragent@cursor.com> * Harden workspace and account deletion around shared members. Enforce owner-only workspace creation, rehome stranded members to a personal account, warn about member access loss, and clarify the only-workspace SaaS exit paths. Co-authored-by: Cursor <cursoragent@cursor.com> * Harden workspace delete: owner-only billing impact and safer member rehome. Restrict delete to account owners, rehome stranded members transactionally with account-scoped fallbacks, and clean up the danger-zone UI/copy. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix workspace delete review findings. Prune pending invites and media on delete, lock the account for the last-workspace guard, fall back to account-owned workspaces for owners, redirect self-hosted last deletes to create, cancel Stripe after local cleanup, align personal-account trials, and gate Index create for owners. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Harden invite accept and account delete edge cases. Stop invite accept from demoting existing roles, expire dead invites on show, preserve flash by avoiding calendar bounces, move media file I/O outside locked delete transactions, and finish account deletion even if Stripe cancel fails. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Fix remaining invite redirect and media cleanup edge cases. Distinguish already-accepted invites from gone workspaces, rehome members removed from their last shared workspace, capture media paths inside the delete lock, extract orphaned-file cleanup, and use Wayfinder for the expired-invite home link. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Fix invite current-workspace and account-delete edge cases. Switch invitees onto an invite-account workspace when accepting, prefer same-account fallbacks when removing members, abort account deletion if Stripe cancel fails, and clear avatar media on profile delete. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Fix Stripe-failure media leak and invite cross-account redirect. Flush workspace media files before billing cancel can abort account delete, and rehome stranded non-owners before picking an invite redirect fallback so current workspace never points across accounts. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Never set cross-account current workspace on member rehome. Keep RemoveMember and account-delete member fallbacks same-account only, clarify the billing-failure flash that workspaces were already removed, and assert storage deletion in media cleanup tests. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Sync Stripe workspace quantity when account delete billing fails. After local workspaces are wiped, a stuck cancelNow must still drop seat quantity so the subscription cannot keep billing the old count. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Prune account invites when owner delete wipes workspaces. Pending and accepted invites are removed with the workspaces so a Stripe cancel failure cannot leave unique email/account rows that block re-invites to a gutted account. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Extract DeleteWorkspaceMedia to purge workspace media rows. Call sites capture returned paths inside the lock and still flush orphaned storage files after commit via DeleteOrphanedMediaFiles. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Redirect to calendar after deleting a workspace with a fallback. When DeleteWorkspace already sets another current workspace, sending the owner to the workspace picker is unnecessary — take them back into the app instead. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Use Wayfinder for invite redirect and logo home links. Replace hardcoded /invites/{id} and / hrefs in AcceptInvite with show.url() and home() route helpers. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Use Wayfinder home() for AcceptInvite logo link. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Extract AcceptInvite title and description into computeds. Keeps the expired/active copy logic out of the template and matches the existing trans() pattern used elsewhere. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Fix lazy-loading crash when deleting a workspace. isAccountOwner() no longer touches the account relation unless it is already loaded, and delete/rehome queries eager-load account when they need ownership checks under Model::shouldBeStrict(). Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Avoid isAccountOwner during workspace delete fallback. Compare against the already-loaded account owner_id so current-workspace reassignment cannot touch the account relation under shouldBeStrict(). Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Add tests for DeleteWorkspace functionality Introduce comprehensive tests for the DeleteWorkspace action, covering scenarios such as deleting stranded members, handling multiple workspaces, restoring members with personal workspaces, and managing invites. Ensure that workspace media files are deleted and verify behavior when the last workspace is blocked by SaaS settings. This enhances the reliability of workspace deletion processes and ensures proper account management during deletions. * Refactor member removal process to delete or restore stranded members Updated the RemoveMember action to utilize the new DeleteOrRestoreStrandedMember class, which handles the deletion of stranded members or restoration to personal accounts. This change improves the management of user accounts when members are removed from workspaces, ensuring that non-owner members are properly handled based on their account status. Additionally, tests have been updated to reflect these changes, ensuring that the functionality works as intended. * Enhance member removal and media management during account deletion Updated the RemoveMember action to collect media paths for orphaned files when removing members. Integrated the DeleteOrphanedMediaFiles action to ensure that any media associated with deleted users is properly purged. Additionally, refactored the DeleteOrRestoreStrandedMember class to return media paths for cleanup, improving overall resource management during user account deletions. This change ensures that all orphaned media files are handled efficiently, maintaining system integrity. * Enhance user account deletion process with force delete option Updated the DeleteOrRestoreStrandedMember class to include a forceDelete parameter, allowing for immediate deletion of members and their associated personal accounts and workspaces. This change ensures that when an account is forcefully deleted, all remnants of the user's data are purged, improving data integrity and resource management. Additionally, updated related methods and tests to accommodate this new functionality, ensuring comprehensive coverage and correct behavior during account deletions. * Extract shared delete/invite actions out of fat controllers. Centralize workspace/account/user teardown and invite accept/decline so ProfileController and AcceptInviteController stay thin HTTP wrappers. Co-authored-by: Cursor <cursoragent@cursor.com> * Harden delete/invite invariants and replace invite string outcomes. Block cross-account workspace listing/switching, cancel Stripe on owned accounts before purge, lock RemoveMember, fold owner fallback into ReassignCurrentWorkspace, and type invite results with an enum. Co-authored-by: Cursor <cursoragent@cursor.com> * Polish delete/invite teardown APIs and cancel Stripe on empty accounts. Extract DeleteEmptyOwnedAccounts, rename settle-after-invite, and expose clearer stranded-member entry points so cancel never races the invite lock. Co-authored-by: Cursor <cursoragent@cursor.com> * Finish stranded teardown craft: settle outside locks, clearer names. Defer empty-account Stripe cancel until after the account lock, rename stranded handling to SettleStrandedMember, and extract AccountsRequiringCancel. Co-authored-by: Cursor <cursoragent@cursor.com> * Harden multi-account Stripe cancel order and typed stranded settlements. Cancel member personals before the shared account, introduce CancelAccounts and StrandedSettlement::flush so partial Stripe failures leave billing intact. Co-authored-by: Cursor <cursoragent@cursor.com> * Reuse strandedMemberOnSharedAccount across delete/invite feature tests. Expand the Pest helper for shared workspaces and owner injection so stranded-member fixtures stop being hand-rolled in every suite. Co-authored-by: Cursor <cursoragent@cursor.com> * Lock the account row during owner account teardown. Serialize DeleteAccount with DeleteWorkspace/RemoveMember so concurrent stranded restores cannot move members off the account before force-delete. Co-authored-by: Cursor <cursoragent@cursor.com> * Drop personal-account restore when leaving a shared account. Invitees abandon their previous personal account on accept, and stranded members are always deleted — matching the real product flow. Co-authored-by: Cursor <cursoragent@cursor.com> * Close the account model and consolidate teardown actions. Block invites to emails that already belong to a registered user — accounts are closed (one user, one account), so members never own a personal account. This removes the whole leftover/restore surface. Consolidate: fold AccountsRequiringCancel/CancelAccounts into CancelAccountSubscription, drop DeleteEmptyOwnedAccounts/DeleteOwnedAccount/ PurgeOwnedAccounts, and fold DeleteAccount into DeleteUser. 23 -> 15 new action files. Co-authored-by: Cursor <cursoragent@cursor.com> * Remove orphaned members.errors.already_member translation key. Co-authored-by: Cursor <cursoragent@cursor.com> * Block invitees from creating a workspace on the invite shell. A pending invitee could open workspaces/create (outside EnsureHasWorkspace) and add a workspace (then billing) on their empty signup shell before accept. Accept only tears down an empty shell, so this left an abandoned, billable account. Deny create/store while an invite is pending — the invitee joins via the invite instead. Co-authored-by: Cursor <cursoragent@cursor.com> * Tighten stranded-member fixtures to the closed-account model. Drop the member's empty signup shell in strandedMemberOnSharedAccount and the billing-abort profile test so the setup matches what accept actually leaves (member owns nothing). Remove the never-overridden attachOwner param. Co-authored-by: Cursor <cursoragent@cursor.com> * Bind invite registration to the invited email. The register form shows the invited email as read-only when an invite id is present, and store() rejects a different email for a valid invite. Also fixes a latent bug: EnsureRegistrationEnabled only read the invite id from the query string, so the self-hosted invite registration POST always 404'd. Co-authored-by: Cursor <cursoragent@cursor.com> * Move register validation into RegisterRequest. Inline $request->validate() and the invite-email check move into App\Http\Requests\App\Auth\RegisterRequest (withValidator). Invite detection no longer sniffs a /invites/ redirect string — it resolves the invite id directly; the invite registration test now uses a real invite. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-01 17:00:38 +00:00
use App\Http\Requests\App\Auth\RegisterRequest;
2026-01-20 19:53:54 +00:00
use Illuminate\Auth\Events\Registered;
use Illuminate\Http\RedirectResponse;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Auth;
use Inertia\Inertia;
use Inertia\Response;
class RegisteredUserController extends Controller
{
feat: capture ad click IDs for ad-platform conversion attribution (#276) * feat: capture ad click IDs for Meta/Google/LinkedIn/TikTok/Reddit/Pinterest attribution Adds gclid, fbclid, li_fat_id, ttclid, rdt_cid, and epik columns to users, captured the same way UTM parameters already are (query string -> session -> persisted on signup, surviving the OAuth redirect round-trip via the new PreservesClickIds trait). Forwards them as first-touch ($set_once) PostHog person properties in SyncUser, so PostHog's native ad-platform destinations (Meta Ads Conversions API, Google Ads Conversions, LinkedIn Ads, TikTok Ads, Reddit Ads, Pinterest) have first-party click IDs to match conversions back to the originating ad click. * refactor: unify PreservesUtmParameters and PreservesClickIds into one trait Both traits captured a set of query-string keys into the session and retrieved them at signup, with identical extract/store/retrieve logic and every call site always using both together — the split added no real separation, just duplicated the same mechanism twice. PreservesAttributionParameters replaces both with a single ATTRIBUTION_KEYS list and one session key. Adding a future ad network's click ID is now one line in that list instead of a second trait. * refactor: split UTM_KEYS and CLICK_ID_KEYS into separate constants Same single trait, single session key, single extract/store/retrieve mechanism — just two named arrays instead of one merged list, so it's clear at a glance which key belongs to which category. * fix: don't truncate ad click IDs to 255 chars, only UTM parameters Ad platforms explicitly warn against assuming a fixed max length for click IDs (Google: gclid has already grown from 26 to 100+ chars, and their docs say never truncate or validate against a fixed length). Truncating would silently corrupt the value into something that no longer matches the real click ID, which is worse than not capturing it at all. Widens the click-id columns from string (VARCHAR 255) to text — safe to edit the migration in place since it hasn't shipped to production yet. UTM parameters still get truncated to 255, since those are ours (our own campaign URLs) and the column stays VARCHAR(255). * refactor: use Laravel collection/Str helpers, forward UTMs to PostHog too - extractAttributionParameters now reads through collect()/Str::limit() instead of raw array_filter/array_map/mb_substr; storeAttributionParameters drops its now-redundant emptiness check since retrieveAttributionParameters already treats "absent" and "present-but-empty" the same via pull()'s default. - SyncUser forwards utm_source/medium/campaign/term/content alongside the click ids as first-touch ($set_once) PostHog person properties. UTMs were never sent to PostHog before this, on any prior code — now that PostHog is the source of truth for ad-platform attribution, it should have the full picture, not just click ids. - Adds the missing GitHub-existing-user click-id session test, mirroring the Google one (parity with the existing UTM coverage). * fix: 3 issues found by review — empty-string leak, duplicated key list, comment style - extractAttributionParameters no longer keeps an empty-string value (e.g. ?utm_source=&gclid=, which some ad/email templates always append even for unfilled slots). The refactor to collect()/Str::limit() a few commits back dropped the outer array_filter() that used to strip these, so they were slipping into User::create() as '' instead of staying null. Restored via a trailing ->filter() on the merged result, and extended the same protection to click ids (which never had it, even before that refactor). - New App\Support\AttributionKeys centralizes the UTM_KEYS/CLICK_ID_KEYS lists that PreservesAttributionParameters and SyncUser each maintained independently. SyncUser previously hand-listed the same 11 field names as a second array with no shared source of truth — a future ad network added to the trait would silently never reach PostHog unless someone remembered to update this second copy too. - Removed the // comment block from the click-id migration explaining the text-column rationale — CLAUDE.md's PHP rules reserve inline comments for exceptionally complex logic; the rationale already lives in the commit message that introduced it.
2026-08-11 18:07:23 +00:00
use PreservesAttributionParameters;
2026-01-20 19:53:54 +00:00
public function create(Request $request): Response
{
feat: capture ad click IDs for ad-platform conversion attribution (#276) * feat: capture ad click IDs for Meta/Google/LinkedIn/TikTok/Reddit/Pinterest attribution Adds gclid, fbclid, li_fat_id, ttclid, rdt_cid, and epik columns to users, captured the same way UTM parameters already are (query string -> session -> persisted on signup, surviving the OAuth redirect round-trip via the new PreservesClickIds trait). Forwards them as first-touch ($set_once) PostHog person properties in SyncUser, so PostHog's native ad-platform destinations (Meta Ads Conversions API, Google Ads Conversions, LinkedIn Ads, TikTok Ads, Reddit Ads, Pinterest) have first-party click IDs to match conversions back to the originating ad click. * refactor: unify PreservesUtmParameters and PreservesClickIds into one trait Both traits captured a set of query-string keys into the session and retrieved them at signup, with identical extract/store/retrieve logic and every call site always using both together — the split added no real separation, just duplicated the same mechanism twice. PreservesAttributionParameters replaces both with a single ATTRIBUTION_KEYS list and one session key. Adding a future ad network's click ID is now one line in that list instead of a second trait. * refactor: split UTM_KEYS and CLICK_ID_KEYS into separate constants Same single trait, single session key, single extract/store/retrieve mechanism — just two named arrays instead of one merged list, so it's clear at a glance which key belongs to which category. * fix: don't truncate ad click IDs to 255 chars, only UTM parameters Ad platforms explicitly warn against assuming a fixed max length for click IDs (Google: gclid has already grown from 26 to 100+ chars, and their docs say never truncate or validate against a fixed length). Truncating would silently corrupt the value into something that no longer matches the real click ID, which is worse than not capturing it at all. Widens the click-id columns from string (VARCHAR 255) to text — safe to edit the migration in place since it hasn't shipped to production yet. UTM parameters still get truncated to 255, since those are ours (our own campaign URLs) and the column stays VARCHAR(255). * refactor: use Laravel collection/Str helpers, forward UTMs to PostHog too - extractAttributionParameters now reads through collect()/Str::limit() instead of raw array_filter/array_map/mb_substr; storeAttributionParameters drops its now-redundant emptiness check since retrieveAttributionParameters already treats "absent" and "present-but-empty" the same via pull()'s default. - SyncUser forwards utm_source/medium/campaign/term/content alongside the click ids as first-touch ($set_once) PostHog person properties. UTMs were never sent to PostHog before this, on any prior code — now that PostHog is the source of truth for ad-platform attribution, it should have the full picture, not just click ids. - Adds the missing GitHub-existing-user click-id session test, mirroring the Google one (parity with the existing UTM coverage). * fix: 3 issues found by review — empty-string leak, duplicated key list, comment style - extractAttributionParameters no longer keeps an empty-string value (e.g. ?utm_source=&gclid=, which some ad/email templates always append even for unfilled slots). The refactor to collect()/Str::limit() a few commits back dropped the outer array_filter() that used to strip these, so they were slipping into User::create() as '' instead of staying null. Restored via a trailing ->filter() on the merged result, and extended the same protection to click ids (which never had it, even before that refactor). - New App\Support\AttributionKeys centralizes the UTM_KEYS/CLICK_ID_KEYS lists that PreservesAttributionParameters and SyncUser each maintained independently. SyncUser previously hand-listed the same 11 field names as a second array with no shared source of truth — a future ad network added to the trait would silently never reach PostHog unless someone remembered to update this second copy too. - Removed the // comment block from the click-id migration explaining the text-column rationale — CLAUDE.md's PHP rules reserve inline comments for exceptionally complex logic; the rationale already lives in the commit message that introduced it.
2026-08-11 18:07:23 +00:00
$this->storeAttributionParameters($request);
2026-01-20 19:53:54 +00:00
return Inertia::render('auth/Register', [
'email' => $request->query('email'),
'redirect' => $request->query('redirect'),
Allow account owners to delete workspaces (#208) * Allow owners and admins to delete workspaces from settings. Expose a danger zone with name confirmation, sync Stripe quantity on SaaS, and skip billing constraints in self-hosted mode. Co-authored-by: Cursor <cursoragent@cursor.com> * Drop redundant canDelete prop from workspace settings. The settings page is already gated by update (owner/admin), which matches delete. Co-authored-by: Cursor <cursoragent@cursor.com> * Extract workspace delete danger zone into DeleteWorkspace component. Co-authored-by: Cursor <cursoragent@cursor.com> * Clarify workspace delete billing copy across locales. Co-authored-by: Cursor <cursoragent@cursor.com> * Match workspace delete card to the delete-account settings pattern. Co-authored-by: Cursor <cursoragent@cursor.com> * Harden workspace and account deletion around shared members. Enforce owner-only workspace creation, rehome stranded members to a personal account, warn about member access loss, and clarify the only-workspace SaaS exit paths. Co-authored-by: Cursor <cursoragent@cursor.com> * Harden workspace delete: owner-only billing impact and safer member rehome. Restrict delete to account owners, rehome stranded members transactionally with account-scoped fallbacks, and clean up the danger-zone UI/copy. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix workspace delete review findings. Prune pending invites and media on delete, lock the account for the last-workspace guard, fall back to account-owned workspaces for owners, redirect self-hosted last deletes to create, cancel Stripe after local cleanup, align personal-account trials, and gate Index create for owners. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Harden invite accept and account delete edge cases. Stop invite accept from demoting existing roles, expire dead invites on show, preserve flash by avoiding calendar bounces, move media file I/O outside locked delete transactions, and finish account deletion even if Stripe cancel fails. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Fix remaining invite redirect and media cleanup edge cases. Distinguish already-accepted invites from gone workspaces, rehome members removed from their last shared workspace, capture media paths inside the delete lock, extract orphaned-file cleanup, and use Wayfinder for the expired-invite home link. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Fix invite current-workspace and account-delete edge cases. Switch invitees onto an invite-account workspace when accepting, prefer same-account fallbacks when removing members, abort account deletion if Stripe cancel fails, and clear avatar media on profile delete. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Fix Stripe-failure media leak and invite cross-account redirect. Flush workspace media files before billing cancel can abort account delete, and rehome stranded non-owners before picking an invite redirect fallback so current workspace never points across accounts. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Never set cross-account current workspace on member rehome. Keep RemoveMember and account-delete member fallbacks same-account only, clarify the billing-failure flash that workspaces were already removed, and assert storage deletion in media cleanup tests. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Sync Stripe workspace quantity when account delete billing fails. After local workspaces are wiped, a stuck cancelNow must still drop seat quantity so the subscription cannot keep billing the old count. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Prune account invites when owner delete wipes workspaces. Pending and accepted invites are removed with the workspaces so a Stripe cancel failure cannot leave unique email/account rows that block re-invites to a gutted account. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Extract DeleteWorkspaceMedia to purge workspace media rows. Call sites capture returned paths inside the lock and still flush orphaned storage files after commit via DeleteOrphanedMediaFiles. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Redirect to calendar after deleting a workspace with a fallback. When DeleteWorkspace already sets another current workspace, sending the owner to the workspace picker is unnecessary — take them back into the app instead. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Use Wayfinder for invite redirect and logo home links. Replace hardcoded /invites/{id} and / hrefs in AcceptInvite with show.url() and home() route helpers. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Use Wayfinder home() for AcceptInvite logo link. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Extract AcceptInvite title and description into computeds. Keeps the expired/active copy logic out of the template and matches the existing trans() pattern used elsewhere. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Fix lazy-loading crash when deleting a workspace. isAccountOwner() no longer touches the account relation unless it is already loaded, and delete/rehome queries eager-load account when they need ownership checks under Model::shouldBeStrict(). Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Avoid isAccountOwner during workspace delete fallback. Compare against the already-loaded account owner_id so current-workspace reassignment cannot touch the account relation under shouldBeStrict(). Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Add tests for DeleteWorkspace functionality Introduce comprehensive tests for the DeleteWorkspace action, covering scenarios such as deleting stranded members, handling multiple workspaces, restoring members with personal workspaces, and managing invites. Ensure that workspace media files are deleted and verify behavior when the last workspace is blocked by SaaS settings. This enhances the reliability of workspace deletion processes and ensures proper account management during deletions. * Refactor member removal process to delete or restore stranded members Updated the RemoveMember action to utilize the new DeleteOrRestoreStrandedMember class, which handles the deletion of stranded members or restoration to personal accounts. This change improves the management of user accounts when members are removed from workspaces, ensuring that non-owner members are properly handled based on their account status. Additionally, tests have been updated to reflect these changes, ensuring that the functionality works as intended. * Enhance member removal and media management during account deletion Updated the RemoveMember action to collect media paths for orphaned files when removing members. Integrated the DeleteOrphanedMediaFiles action to ensure that any media associated with deleted users is properly purged. Additionally, refactored the DeleteOrRestoreStrandedMember class to return media paths for cleanup, improving overall resource management during user account deletions. This change ensures that all orphaned media files are handled efficiently, maintaining system integrity. * Enhance user account deletion process with force delete option Updated the DeleteOrRestoreStrandedMember class to include a forceDelete parameter, allowing for immediate deletion of members and their associated personal accounts and workspaces. This change ensures that when an account is forcefully deleted, all remnants of the user's data are purged, improving data integrity and resource management. Additionally, updated related methods and tests to accommodate this new functionality, ensuring comprehensive coverage and correct behavior during account deletions. * Extract shared delete/invite actions out of fat controllers. Centralize workspace/account/user teardown and invite accept/decline so ProfileController and AcceptInviteController stay thin HTTP wrappers. Co-authored-by: Cursor <cursoragent@cursor.com> * Harden delete/invite invariants and replace invite string outcomes. Block cross-account workspace listing/switching, cancel Stripe on owned accounts before purge, lock RemoveMember, fold owner fallback into ReassignCurrentWorkspace, and type invite results with an enum. Co-authored-by: Cursor <cursoragent@cursor.com> * Polish delete/invite teardown APIs and cancel Stripe on empty accounts. Extract DeleteEmptyOwnedAccounts, rename settle-after-invite, and expose clearer stranded-member entry points so cancel never races the invite lock. Co-authored-by: Cursor <cursoragent@cursor.com> * Finish stranded teardown craft: settle outside locks, clearer names. Defer empty-account Stripe cancel until after the account lock, rename stranded handling to SettleStrandedMember, and extract AccountsRequiringCancel. Co-authored-by: Cursor <cursoragent@cursor.com> * Harden multi-account Stripe cancel order and typed stranded settlements. Cancel member personals before the shared account, introduce CancelAccounts and StrandedSettlement::flush so partial Stripe failures leave billing intact. Co-authored-by: Cursor <cursoragent@cursor.com> * Reuse strandedMemberOnSharedAccount across delete/invite feature tests. Expand the Pest helper for shared workspaces and owner injection so stranded-member fixtures stop being hand-rolled in every suite. Co-authored-by: Cursor <cursoragent@cursor.com> * Lock the account row during owner account teardown. Serialize DeleteAccount with DeleteWorkspace/RemoveMember so concurrent stranded restores cannot move members off the account before force-delete. Co-authored-by: Cursor <cursoragent@cursor.com> * Drop personal-account restore when leaving a shared account. Invitees abandon their previous personal account on accept, and stranded members are always deleted — matching the real product flow. Co-authored-by: Cursor <cursoragent@cursor.com> * Close the account model and consolidate teardown actions. Block invites to emails that already belong to a registered user — accounts are closed (one user, one account), so members never own a personal account. This removes the whole leftover/restore surface. Consolidate: fold AccountsRequiringCancel/CancelAccounts into CancelAccountSubscription, drop DeleteEmptyOwnedAccounts/DeleteOwnedAccount/ PurgeOwnedAccounts, and fold DeleteAccount into DeleteUser. 23 -> 15 new action files. Co-authored-by: Cursor <cursoragent@cursor.com> * Remove orphaned members.errors.already_member translation key. Co-authored-by: Cursor <cursoragent@cursor.com> * Block invitees from creating a workspace on the invite shell. A pending invitee could open workspaces/create (outside EnsureHasWorkspace) and add a workspace (then billing) on their empty signup shell before accept. Accept only tears down an empty shell, so this left an abandoned, billable account. Deny create/store while an invite is pending — the invitee joins via the invite instead. Co-authored-by: Cursor <cursoragent@cursor.com> * Tighten stranded-member fixtures to the closed-account model. Drop the member's empty signup shell in strandedMemberOnSharedAccount and the billing-abort profile test so the setup matches what accept actually leaves (member owns nothing). Remove the never-overridden attachOwner param. Co-authored-by: Cursor <cursoragent@cursor.com> * Bind invite registration to the invited email. The register form shows the invited email as read-only when an invite id is present, and store() rejects a different email for a valid invite. Also fixes a latent bug: EnsureRegistrationEnabled only read the invite id from the query string, so the self-hosted invite registration POST always 404'd. Co-authored-by: Cursor <cursoragent@cursor.com> * Move register validation into RegisterRequest. Inline $request->validate() and the invite-email check move into App\Http\Requests\App\Auth\RegisterRequest (withValidator). Invite detection no longer sniffs a /invites/ redirect string — it resolves the invite id directly; the invite registration test now uses a real invite. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-01 17:00:38 +00:00
'invite' => $request->query('invite'),
2026-01-20 19:53:54 +00:00
]);
}
Allow account owners to delete workspaces (#208) * Allow owners and admins to delete workspaces from settings. Expose a danger zone with name confirmation, sync Stripe quantity on SaaS, and skip billing constraints in self-hosted mode. Co-authored-by: Cursor <cursoragent@cursor.com> * Drop redundant canDelete prop from workspace settings. The settings page is already gated by update (owner/admin), which matches delete. Co-authored-by: Cursor <cursoragent@cursor.com> * Extract workspace delete danger zone into DeleteWorkspace component. Co-authored-by: Cursor <cursoragent@cursor.com> * Clarify workspace delete billing copy across locales. Co-authored-by: Cursor <cursoragent@cursor.com> * Match workspace delete card to the delete-account settings pattern. Co-authored-by: Cursor <cursoragent@cursor.com> * Harden workspace and account deletion around shared members. Enforce owner-only workspace creation, rehome stranded members to a personal account, warn about member access loss, and clarify the only-workspace SaaS exit paths. Co-authored-by: Cursor <cursoragent@cursor.com> * Harden workspace delete: owner-only billing impact and safer member rehome. Restrict delete to account owners, rehome stranded members transactionally with account-scoped fallbacks, and clean up the danger-zone UI/copy. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix workspace delete review findings. Prune pending invites and media on delete, lock the account for the last-workspace guard, fall back to account-owned workspaces for owners, redirect self-hosted last deletes to create, cancel Stripe after local cleanup, align personal-account trials, and gate Index create for owners. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Harden invite accept and account delete edge cases. Stop invite accept from demoting existing roles, expire dead invites on show, preserve flash by avoiding calendar bounces, move media file I/O outside locked delete transactions, and finish account deletion even if Stripe cancel fails. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Fix remaining invite redirect and media cleanup edge cases. Distinguish already-accepted invites from gone workspaces, rehome members removed from their last shared workspace, capture media paths inside the delete lock, extract orphaned-file cleanup, and use Wayfinder for the expired-invite home link. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Fix invite current-workspace and account-delete edge cases. Switch invitees onto an invite-account workspace when accepting, prefer same-account fallbacks when removing members, abort account deletion if Stripe cancel fails, and clear avatar media on profile delete. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Fix Stripe-failure media leak and invite cross-account redirect. Flush workspace media files before billing cancel can abort account delete, and rehome stranded non-owners before picking an invite redirect fallback so current workspace never points across accounts. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Never set cross-account current workspace on member rehome. Keep RemoveMember and account-delete member fallbacks same-account only, clarify the billing-failure flash that workspaces were already removed, and assert storage deletion in media cleanup tests. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Sync Stripe workspace quantity when account delete billing fails. After local workspaces are wiped, a stuck cancelNow must still drop seat quantity so the subscription cannot keep billing the old count. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Prune account invites when owner delete wipes workspaces. Pending and accepted invites are removed with the workspaces so a Stripe cancel failure cannot leave unique email/account rows that block re-invites to a gutted account. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Extract DeleteWorkspaceMedia to purge workspace media rows. Call sites capture returned paths inside the lock and still flush orphaned storage files after commit via DeleteOrphanedMediaFiles. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Redirect to calendar after deleting a workspace with a fallback. When DeleteWorkspace already sets another current workspace, sending the owner to the workspace picker is unnecessary — take them back into the app instead. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Use Wayfinder for invite redirect and logo home links. Replace hardcoded /invites/{id} and / hrefs in AcceptInvite with show.url() and home() route helpers. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Use Wayfinder home() for AcceptInvite logo link. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Extract AcceptInvite title and description into computeds. Keeps the expired/active copy logic out of the template and matches the existing trans() pattern used elsewhere. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Fix lazy-loading crash when deleting a workspace. isAccountOwner() no longer touches the account relation unless it is already loaded, and delete/rehome queries eager-load account when they need ownership checks under Model::shouldBeStrict(). Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Avoid isAccountOwner during workspace delete fallback. Compare against the already-loaded account owner_id so current-workspace reassignment cannot touch the account relation under shouldBeStrict(). Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Add tests for DeleteWorkspace functionality Introduce comprehensive tests for the DeleteWorkspace action, covering scenarios such as deleting stranded members, handling multiple workspaces, restoring members with personal workspaces, and managing invites. Ensure that workspace media files are deleted and verify behavior when the last workspace is blocked by SaaS settings. This enhances the reliability of workspace deletion processes and ensures proper account management during deletions. * Refactor member removal process to delete or restore stranded members Updated the RemoveMember action to utilize the new DeleteOrRestoreStrandedMember class, which handles the deletion of stranded members or restoration to personal accounts. This change improves the management of user accounts when members are removed from workspaces, ensuring that non-owner members are properly handled based on their account status. Additionally, tests have been updated to reflect these changes, ensuring that the functionality works as intended. * Enhance member removal and media management during account deletion Updated the RemoveMember action to collect media paths for orphaned files when removing members. Integrated the DeleteOrphanedMediaFiles action to ensure that any media associated with deleted users is properly purged. Additionally, refactored the DeleteOrRestoreStrandedMember class to return media paths for cleanup, improving overall resource management during user account deletions. This change ensures that all orphaned media files are handled efficiently, maintaining system integrity. * Enhance user account deletion process with force delete option Updated the DeleteOrRestoreStrandedMember class to include a forceDelete parameter, allowing for immediate deletion of members and their associated personal accounts and workspaces. This change ensures that when an account is forcefully deleted, all remnants of the user's data are purged, improving data integrity and resource management. Additionally, updated related methods and tests to accommodate this new functionality, ensuring comprehensive coverage and correct behavior during account deletions. * Extract shared delete/invite actions out of fat controllers. Centralize workspace/account/user teardown and invite accept/decline so ProfileController and AcceptInviteController stay thin HTTP wrappers. Co-authored-by: Cursor <cursoragent@cursor.com> * Harden delete/invite invariants and replace invite string outcomes. Block cross-account workspace listing/switching, cancel Stripe on owned accounts before purge, lock RemoveMember, fold owner fallback into ReassignCurrentWorkspace, and type invite results with an enum. Co-authored-by: Cursor <cursoragent@cursor.com> * Polish delete/invite teardown APIs and cancel Stripe on empty accounts. Extract DeleteEmptyOwnedAccounts, rename settle-after-invite, and expose clearer stranded-member entry points so cancel never races the invite lock. Co-authored-by: Cursor <cursoragent@cursor.com> * Finish stranded teardown craft: settle outside locks, clearer names. Defer empty-account Stripe cancel until after the account lock, rename stranded handling to SettleStrandedMember, and extract AccountsRequiringCancel. Co-authored-by: Cursor <cursoragent@cursor.com> * Harden multi-account Stripe cancel order and typed stranded settlements. Cancel member personals before the shared account, introduce CancelAccounts and StrandedSettlement::flush so partial Stripe failures leave billing intact. Co-authored-by: Cursor <cursoragent@cursor.com> * Reuse strandedMemberOnSharedAccount across delete/invite feature tests. Expand the Pest helper for shared workspaces and owner injection so stranded-member fixtures stop being hand-rolled in every suite. Co-authored-by: Cursor <cursoragent@cursor.com> * Lock the account row during owner account teardown. Serialize DeleteAccount with DeleteWorkspace/RemoveMember so concurrent stranded restores cannot move members off the account before force-delete. Co-authored-by: Cursor <cursoragent@cursor.com> * Drop personal-account restore when leaving a shared account. Invitees abandon their previous personal account on accept, and stranded members are always deleted — matching the real product flow. Co-authored-by: Cursor <cursoragent@cursor.com> * Close the account model and consolidate teardown actions. Block invites to emails that already belong to a registered user — accounts are closed (one user, one account), so members never own a personal account. This removes the whole leftover/restore surface. Consolidate: fold AccountsRequiringCancel/CancelAccounts into CancelAccountSubscription, drop DeleteEmptyOwnedAccounts/DeleteOwnedAccount/ PurgeOwnedAccounts, and fold DeleteAccount into DeleteUser. 23 -> 15 new action files. Co-authored-by: Cursor <cursoragent@cursor.com> * Remove orphaned members.errors.already_member translation key. Co-authored-by: Cursor <cursoragent@cursor.com> * Block invitees from creating a workspace on the invite shell. A pending invitee could open workspaces/create (outside EnsureHasWorkspace) and add a workspace (then billing) on their empty signup shell before accept. Accept only tears down an empty shell, so this left an abandoned, billable account. Deny create/store while an invite is pending — the invitee joins via the invite instead. Co-authored-by: Cursor <cursoragent@cursor.com> * Tighten stranded-member fixtures to the closed-account model. Drop the member's empty signup shell in strandedMemberOnSharedAccount and the billing-abort profile test so the setup matches what accept actually leaves (member owns nothing). Remove the never-overridden attachOwner param. Co-authored-by: Cursor <cursoragent@cursor.com> * Bind invite registration to the invited email. The register form shows the invited email as read-only when an invite id is present, and store() rejects a different email for a valid invite. Also fixes a latent bug: EnsureRegistrationEnabled only read the invite id from the query string, so the self-hosted invite registration POST always 404'd. Co-authored-by: Cursor <cursoragent@cursor.com> * Move register validation into RegisterRequest. Inline $request->validate() and the invite-email check move into App\Http\Requests\App\Auth\RegisterRequest (withValidator). Invite detection no longer sniffs a /invites/ redirect string — it resolves the invite id directly; the invite registration test now uses a real invite. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-01 17:00:38 +00:00
public function store(RegisterRequest $request): RedirectResponse
2026-01-20 19:53:54 +00:00
{
feat: capture ad click IDs for ad-platform conversion attribution (#276) * feat: capture ad click IDs for Meta/Google/LinkedIn/TikTok/Reddit/Pinterest attribution Adds gclid, fbclid, li_fat_id, ttclid, rdt_cid, and epik columns to users, captured the same way UTM parameters already are (query string -> session -> persisted on signup, surviving the OAuth redirect round-trip via the new PreservesClickIds trait). Forwards them as first-touch ($set_once) PostHog person properties in SyncUser, so PostHog's native ad-platform destinations (Meta Ads Conversions API, Google Ads Conversions, LinkedIn Ads, TikTok Ads, Reddit Ads, Pinterest) have first-party click IDs to match conversions back to the originating ad click. * refactor: unify PreservesUtmParameters and PreservesClickIds into one trait Both traits captured a set of query-string keys into the session and retrieved them at signup, with identical extract/store/retrieve logic and every call site always using both together — the split added no real separation, just duplicated the same mechanism twice. PreservesAttributionParameters replaces both with a single ATTRIBUTION_KEYS list and one session key. Adding a future ad network's click ID is now one line in that list instead of a second trait. * refactor: split UTM_KEYS and CLICK_ID_KEYS into separate constants Same single trait, single session key, single extract/store/retrieve mechanism — just two named arrays instead of one merged list, so it's clear at a glance which key belongs to which category. * fix: don't truncate ad click IDs to 255 chars, only UTM parameters Ad platforms explicitly warn against assuming a fixed max length for click IDs (Google: gclid has already grown from 26 to 100+ chars, and their docs say never truncate or validate against a fixed length). Truncating would silently corrupt the value into something that no longer matches the real click ID, which is worse than not capturing it at all. Widens the click-id columns from string (VARCHAR 255) to text — safe to edit the migration in place since it hasn't shipped to production yet. UTM parameters still get truncated to 255, since those are ours (our own campaign URLs) and the column stays VARCHAR(255). * refactor: use Laravel collection/Str helpers, forward UTMs to PostHog too - extractAttributionParameters now reads through collect()/Str::limit() instead of raw array_filter/array_map/mb_substr; storeAttributionParameters drops its now-redundant emptiness check since retrieveAttributionParameters already treats "absent" and "present-but-empty" the same via pull()'s default. - SyncUser forwards utm_source/medium/campaign/term/content alongside the click ids as first-touch ($set_once) PostHog person properties. UTMs were never sent to PostHog before this, on any prior code — now that PostHog is the source of truth for ad-platform attribution, it should have the full picture, not just click ids. - Adds the missing GitHub-existing-user click-id session test, mirroring the Google one (parity with the existing UTM coverage). * fix: 3 issues found by review — empty-string leak, duplicated key list, comment style - extractAttributionParameters no longer keeps an empty-string value (e.g. ?utm_source=&gclid=, which some ad/email templates always append even for unfilled slots). The refactor to collect()/Str::limit() a few commits back dropped the outer array_filter() that used to strip these, so they were slipping into User::create() as '' instead of staying null. Restored via a trailing ->filter() on the merged result, and extended the same protection to click ids (which never had it, even before that refactor). - New App\Support\AttributionKeys centralizes the UTM_KEYS/CLICK_ID_KEYS lists that PreservesAttributionParameters and SyncUser each maintained independently. SyncUser previously hand-listed the same 11 field names as a second array with no shared source of truth — a future ad network added to the trait would silently never reach PostHog unless someone remembered to update this second copy too. - Removed the // comment block from the click-id migration explaining the text-column rationale — CLAUDE.md's PHP rules reserve inline comments for exceptionally complex logic; the rationale already lives in the commit message that introduced it.
2026-08-11 18:07:23 +00:00
$attributionParameters = $this->retrieveAttributionParameters();
2026-03-31 00:18:07 +00:00
$user = CreateUser::execute([
Allow account owners to delete workspaces (#208) * Allow owners and admins to delete workspaces from settings. Expose a danger zone with name confirmation, sync Stripe quantity on SaaS, and skip billing constraints in self-hosted mode. Co-authored-by: Cursor <cursoragent@cursor.com> * Drop redundant canDelete prop from workspace settings. The settings page is already gated by update (owner/admin), which matches delete. Co-authored-by: Cursor <cursoragent@cursor.com> * Extract workspace delete danger zone into DeleteWorkspace component. Co-authored-by: Cursor <cursoragent@cursor.com> * Clarify workspace delete billing copy across locales. Co-authored-by: Cursor <cursoragent@cursor.com> * Match workspace delete card to the delete-account settings pattern. Co-authored-by: Cursor <cursoragent@cursor.com> * Harden workspace and account deletion around shared members. Enforce owner-only workspace creation, rehome stranded members to a personal account, warn about member access loss, and clarify the only-workspace SaaS exit paths. Co-authored-by: Cursor <cursoragent@cursor.com> * Harden workspace delete: owner-only billing impact and safer member rehome. Restrict delete to account owners, rehome stranded members transactionally with account-scoped fallbacks, and clean up the danger-zone UI/copy. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix workspace delete review findings. Prune pending invites and media on delete, lock the account for the last-workspace guard, fall back to account-owned workspaces for owners, redirect self-hosted last deletes to create, cancel Stripe after local cleanup, align personal-account trials, and gate Index create for owners. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Harden invite accept and account delete edge cases. Stop invite accept from demoting existing roles, expire dead invites on show, preserve flash by avoiding calendar bounces, move media file I/O outside locked delete transactions, and finish account deletion even if Stripe cancel fails. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Fix remaining invite redirect and media cleanup edge cases. Distinguish already-accepted invites from gone workspaces, rehome members removed from their last shared workspace, capture media paths inside the delete lock, extract orphaned-file cleanup, and use Wayfinder for the expired-invite home link. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Fix invite current-workspace and account-delete edge cases. Switch invitees onto an invite-account workspace when accepting, prefer same-account fallbacks when removing members, abort account deletion if Stripe cancel fails, and clear avatar media on profile delete. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Fix Stripe-failure media leak and invite cross-account redirect. Flush workspace media files before billing cancel can abort account delete, and rehome stranded non-owners before picking an invite redirect fallback so current workspace never points across accounts. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Never set cross-account current workspace on member rehome. Keep RemoveMember and account-delete member fallbacks same-account only, clarify the billing-failure flash that workspaces were already removed, and assert storage deletion in media cleanup tests. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Sync Stripe workspace quantity when account delete billing fails. After local workspaces are wiped, a stuck cancelNow must still drop seat quantity so the subscription cannot keep billing the old count. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Prune account invites when owner delete wipes workspaces. Pending and accepted invites are removed with the workspaces so a Stripe cancel failure cannot leave unique email/account rows that block re-invites to a gutted account. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Extract DeleteWorkspaceMedia to purge workspace media rows. Call sites capture returned paths inside the lock and still flush orphaned storage files after commit via DeleteOrphanedMediaFiles. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Redirect to calendar after deleting a workspace with a fallback. When DeleteWorkspace already sets another current workspace, sending the owner to the workspace picker is unnecessary — take them back into the app instead. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Use Wayfinder for invite redirect and logo home links. Replace hardcoded /invites/{id} and / hrefs in AcceptInvite with show.url() and home() route helpers. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Use Wayfinder home() for AcceptInvite logo link. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Extract AcceptInvite title and description into computeds. Keeps the expired/active copy logic out of the template and matches the existing trans() pattern used elsewhere. Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Fix lazy-loading crash when deleting a workspace. isAccountOwner() no longer touches the account relation unless it is already loaded, and delete/rehome queries eager-load account when they need ownership checks under Model::shouldBeStrict(). Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Avoid isAccountOwner during workspace delete fallback. Compare against the already-loaded account owner_id so current-workspace reassignment cannot touch the account relation under shouldBeStrict(). Co-authored-by: Paulo Castellano <hello@paulocastellano.com> * Add tests for DeleteWorkspace functionality Introduce comprehensive tests for the DeleteWorkspace action, covering scenarios such as deleting stranded members, handling multiple workspaces, restoring members with personal workspaces, and managing invites. Ensure that workspace media files are deleted and verify behavior when the last workspace is blocked by SaaS settings. This enhances the reliability of workspace deletion processes and ensures proper account management during deletions. * Refactor member removal process to delete or restore stranded members Updated the RemoveMember action to utilize the new DeleteOrRestoreStrandedMember class, which handles the deletion of stranded members or restoration to personal accounts. This change improves the management of user accounts when members are removed from workspaces, ensuring that non-owner members are properly handled based on their account status. Additionally, tests have been updated to reflect these changes, ensuring that the functionality works as intended. * Enhance member removal and media management during account deletion Updated the RemoveMember action to collect media paths for orphaned files when removing members. Integrated the DeleteOrphanedMediaFiles action to ensure that any media associated with deleted users is properly purged. Additionally, refactored the DeleteOrRestoreStrandedMember class to return media paths for cleanup, improving overall resource management during user account deletions. This change ensures that all orphaned media files are handled efficiently, maintaining system integrity. * Enhance user account deletion process with force delete option Updated the DeleteOrRestoreStrandedMember class to include a forceDelete parameter, allowing for immediate deletion of members and their associated personal accounts and workspaces. This change ensures that when an account is forcefully deleted, all remnants of the user's data are purged, improving data integrity and resource management. Additionally, updated related methods and tests to accommodate this new functionality, ensuring comprehensive coverage and correct behavior during account deletions. * Extract shared delete/invite actions out of fat controllers. Centralize workspace/account/user teardown and invite accept/decline so ProfileController and AcceptInviteController stay thin HTTP wrappers. Co-authored-by: Cursor <cursoragent@cursor.com> * Harden delete/invite invariants and replace invite string outcomes. Block cross-account workspace listing/switching, cancel Stripe on owned accounts before purge, lock RemoveMember, fold owner fallback into ReassignCurrentWorkspace, and type invite results with an enum. Co-authored-by: Cursor <cursoragent@cursor.com> * Polish delete/invite teardown APIs and cancel Stripe on empty accounts. Extract DeleteEmptyOwnedAccounts, rename settle-after-invite, and expose clearer stranded-member entry points so cancel never races the invite lock. Co-authored-by: Cursor <cursoragent@cursor.com> * Finish stranded teardown craft: settle outside locks, clearer names. Defer empty-account Stripe cancel until after the account lock, rename stranded handling to SettleStrandedMember, and extract AccountsRequiringCancel. Co-authored-by: Cursor <cursoragent@cursor.com> * Harden multi-account Stripe cancel order and typed stranded settlements. Cancel member personals before the shared account, introduce CancelAccounts and StrandedSettlement::flush so partial Stripe failures leave billing intact. Co-authored-by: Cursor <cursoragent@cursor.com> * Reuse strandedMemberOnSharedAccount across delete/invite feature tests. Expand the Pest helper for shared workspaces and owner injection so stranded-member fixtures stop being hand-rolled in every suite. Co-authored-by: Cursor <cursoragent@cursor.com> * Lock the account row during owner account teardown. Serialize DeleteAccount with DeleteWorkspace/RemoveMember so concurrent stranded restores cannot move members off the account before force-delete. Co-authored-by: Cursor <cursoragent@cursor.com> * Drop personal-account restore when leaving a shared account. Invitees abandon their previous personal account on accept, and stranded members are always deleted — matching the real product flow. Co-authored-by: Cursor <cursoragent@cursor.com> * Close the account model and consolidate teardown actions. Block invites to emails that already belong to a registered user — accounts are closed (one user, one account), so members never own a personal account. This removes the whole leftover/restore surface. Consolidate: fold AccountsRequiringCancel/CancelAccounts into CancelAccountSubscription, drop DeleteEmptyOwnedAccounts/DeleteOwnedAccount/ PurgeOwnedAccounts, and fold DeleteAccount into DeleteUser. 23 -> 15 new action files. Co-authored-by: Cursor <cursoragent@cursor.com> * Remove orphaned members.errors.already_member translation key. Co-authored-by: Cursor <cursoragent@cursor.com> * Block invitees from creating a workspace on the invite shell. A pending invitee could open workspaces/create (outside EnsureHasWorkspace) and add a workspace (then billing) on their empty signup shell before accept. Accept only tears down an empty shell, so this left an abandoned, billable account. Deny create/store while an invite is pending — the invitee joins via the invite instead. Co-authored-by: Cursor <cursoragent@cursor.com> * Tighten stranded-member fixtures to the closed-account model. Drop the member's empty signup shell in strandedMemberOnSharedAccount and the billing-abort profile test so the setup matches what accept actually leaves (member owns nothing). Remove the never-overridden attachOwner param. Co-authored-by: Cursor <cursoragent@cursor.com> * Bind invite registration to the invited email. The register form shows the invited email as read-only when an invite id is present, and store() rejects a different email for a valid invite. Also fixes a latent bug: EnsureRegistrationEnabled only read the invite id from the query string, so the self-hosted invite registration POST always 404'd. Co-authored-by: Cursor <cursoragent@cursor.com> * Move register validation into RegisterRequest. Inline $request->validate() and the invite-email check move into App\Http\Requests\App\Auth\RegisterRequest (withValidator). Invite detection no longer sniffs a /invites/ redirect string — it resolves the invite id directly; the invite registration test now uses a real invite. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-01 17:00:38 +00:00
'name' => $request->validated('name'),
'email' => $request->validated('email'),
'password' => $request->validated('password'),
'is_invite' => $request->isInviteRegistration(),
'registration_ip' => $request->ip(),
feat: capture ad click IDs for ad-platform conversion attribution (#276) * feat: capture ad click IDs for Meta/Google/LinkedIn/TikTok/Reddit/Pinterest attribution Adds gclid, fbclid, li_fat_id, ttclid, rdt_cid, and epik columns to users, captured the same way UTM parameters already are (query string -> session -> persisted on signup, surviving the OAuth redirect round-trip via the new PreservesClickIds trait). Forwards them as first-touch ($set_once) PostHog person properties in SyncUser, so PostHog's native ad-platform destinations (Meta Ads Conversions API, Google Ads Conversions, LinkedIn Ads, TikTok Ads, Reddit Ads, Pinterest) have first-party click IDs to match conversions back to the originating ad click. * refactor: unify PreservesUtmParameters and PreservesClickIds into one trait Both traits captured a set of query-string keys into the session and retrieved them at signup, with identical extract/store/retrieve logic and every call site always using both together — the split added no real separation, just duplicated the same mechanism twice. PreservesAttributionParameters replaces both with a single ATTRIBUTION_KEYS list and one session key. Adding a future ad network's click ID is now one line in that list instead of a second trait. * refactor: split UTM_KEYS and CLICK_ID_KEYS into separate constants Same single trait, single session key, single extract/store/retrieve mechanism — just two named arrays instead of one merged list, so it's clear at a glance which key belongs to which category. * fix: don't truncate ad click IDs to 255 chars, only UTM parameters Ad platforms explicitly warn against assuming a fixed max length for click IDs (Google: gclid has already grown from 26 to 100+ chars, and their docs say never truncate or validate against a fixed length). Truncating would silently corrupt the value into something that no longer matches the real click ID, which is worse than not capturing it at all. Widens the click-id columns from string (VARCHAR 255) to text — safe to edit the migration in place since it hasn't shipped to production yet. UTM parameters still get truncated to 255, since those are ours (our own campaign URLs) and the column stays VARCHAR(255). * refactor: use Laravel collection/Str helpers, forward UTMs to PostHog too - extractAttributionParameters now reads through collect()/Str::limit() instead of raw array_filter/array_map/mb_substr; storeAttributionParameters drops its now-redundant emptiness check since retrieveAttributionParameters already treats "absent" and "present-but-empty" the same via pull()'s default. - SyncUser forwards utm_source/medium/campaign/term/content alongside the click ids as first-touch ($set_once) PostHog person properties. UTMs were never sent to PostHog before this, on any prior code — now that PostHog is the source of truth for ad-platform attribution, it should have the full picture, not just click ids. - Adds the missing GitHub-existing-user click-id session test, mirroring the Google one (parity with the existing UTM coverage). * fix: 3 issues found by review — empty-string leak, duplicated key list, comment style - extractAttributionParameters no longer keeps an empty-string value (e.g. ?utm_source=&gclid=, which some ad/email templates always append even for unfilled slots). The refactor to collect()/Str::limit() a few commits back dropped the outer array_filter() that used to strip these, so they were slipping into User::create() as '' instead of staying null. Restored via a trailing ->filter() on the merged result, and extended the same protection to click ids (which never had it, even before that refactor). - New App\Support\AttributionKeys centralizes the UTM_KEYS/CLICK_ID_KEYS lists that PreservesAttributionParameters and SyncUser each maintained independently. SyncUser previously hand-listed the same 11 field names as a second array with no shared source of truth — a future ad network added to the trait would silently never reach PostHog unless someone remembered to update this second copy too. - Removed the // comment block from the click-id migration explaining the text-column rationale — CLAUDE.md's PHP rules reserve inline comments for exceptionally complex logic; the rationale already lives in the commit message that introduced it.
2026-08-11 18:07:23 +00:00
], $attributionParameters);
2026-01-20 19:53:54 +00:00
event(new Registered($user));
Auth::login($user);
$request->session()->forget('pending_invite_id');
2026-01-20 19:53:54 +00:00
if ($redirect = $request->input('redirect')) {
if (str_starts_with($redirect, '/') && ! str_starts_with($redirect, '//')) {
return redirect($redirect);
}
2026-01-20 19:53:54 +00:00
}
2026-03-31 00:32:43 +00:00
session()->flash('auth_provider', 'email');
feat: capture ad click IDs for ad-platform conversion attribution (#276) * feat: capture ad click IDs for Meta/Google/LinkedIn/TikTok/Reddit/Pinterest attribution Adds gclid, fbclid, li_fat_id, ttclid, rdt_cid, and epik columns to users, captured the same way UTM parameters already are (query string -> session -> persisted on signup, surviving the OAuth redirect round-trip via the new PreservesClickIds trait). Forwards them as first-touch ($set_once) PostHog person properties in SyncUser, so PostHog's native ad-platform destinations (Meta Ads Conversions API, Google Ads Conversions, LinkedIn Ads, TikTok Ads, Reddit Ads, Pinterest) have first-party click IDs to match conversions back to the originating ad click. * refactor: unify PreservesUtmParameters and PreservesClickIds into one trait Both traits captured a set of query-string keys into the session and retrieved them at signup, with identical extract/store/retrieve logic and every call site always using both together — the split added no real separation, just duplicated the same mechanism twice. PreservesAttributionParameters replaces both with a single ATTRIBUTION_KEYS list and one session key. Adding a future ad network's click ID is now one line in that list instead of a second trait. * refactor: split UTM_KEYS and CLICK_ID_KEYS into separate constants Same single trait, single session key, single extract/store/retrieve mechanism — just two named arrays instead of one merged list, so it's clear at a glance which key belongs to which category. * fix: don't truncate ad click IDs to 255 chars, only UTM parameters Ad platforms explicitly warn against assuming a fixed max length for click IDs (Google: gclid has already grown from 26 to 100+ chars, and their docs say never truncate or validate against a fixed length). Truncating would silently corrupt the value into something that no longer matches the real click ID, which is worse than not capturing it at all. Widens the click-id columns from string (VARCHAR 255) to text — safe to edit the migration in place since it hasn't shipped to production yet. UTM parameters still get truncated to 255, since those are ours (our own campaign URLs) and the column stays VARCHAR(255). * refactor: use Laravel collection/Str helpers, forward UTMs to PostHog too - extractAttributionParameters now reads through collect()/Str::limit() instead of raw array_filter/array_map/mb_substr; storeAttributionParameters drops its now-redundant emptiness check since retrieveAttributionParameters already treats "absent" and "present-but-empty" the same via pull()'s default. - SyncUser forwards utm_source/medium/campaign/term/content alongside the click ids as first-touch ($set_once) PostHog person properties. UTMs were never sent to PostHog before this, on any prior code — now that PostHog is the source of truth for ad-platform attribution, it should have the full picture, not just click ids. - Adds the missing GitHub-existing-user click-id session test, mirroring the Google one (parity with the existing UTM coverage). * fix: 3 issues found by review — empty-string leak, duplicated key list, comment style - extractAttributionParameters no longer keeps an empty-string value (e.g. ?utm_source=&gclid=, which some ad/email templates always append even for unfilled slots). The refactor to collect()/Str::limit() a few commits back dropped the outer array_filter() that used to strip these, so they were slipping into User::create() as '' instead of staying null. Restored via a trailing ->filter() on the merged result, and extended the same protection to click ids (which never had it, even before that refactor). - New App\Support\AttributionKeys centralizes the UTM_KEYS/CLICK_ID_KEYS lists that PreservesAttributionParameters and SyncUser each maintained independently. SyncUser previously hand-listed the same 11 field names as a second array with no shared source of truth — a future ad network added to the trait would silently never reach PostHog unless someone remembered to update this second copy too. - Removed the // comment block from the click-id migration explaining the text-column rationale — CLAUDE.md's PHP rules reserve inline comments for exceptionally complex logic; the rationale already lives in the commit message that introduced it.
2026-08-11 18:07:23 +00:00
return redirect()->route('register.success', $attributionParameters);
2026-01-20 19:53:54 +00:00
}
}