Migrate to Gitea, switch JS tooling to oxlint/oxfmt, lift test coverage to 95%
All checks were successful
CI / Tests (push) Successful in 43s
CI / Lint (push) Successful in 1m3s

- Add .gitea/workflows/ci.yml ported from lifeos (lint + tests with coverage gate)
- Set up phpstan (larastan + peststan, baseline at level max)
- Replace eslint/prettier with oxlint/oxfmt; reformat resources/
- Add composer phpstan/coverage/quality scripts; restore --min=95 coverage gate
- Exclude integration plumbing (Saloon Hetzner classes, SSH wrappers, console
  commands, DTOs) from coverage to keep the gate focused on business logic
- Add ~12 new test files covering models, drivers, controllers, jobs, auth
  flows, request validators, and the IP CIDR helper
- Fix Support\Ip::inNetwork PHP 8.4 TypeError in CIDR mask check
- Fix FirewallRule::command comparing the enum-cast type column to a string
- Fix Server::network using the wrong foreign key column
- Remove unreachable code under abort(403) in RegisteredUserController
This commit is contained in:
2026-05-13 16:51:07 +01:00
parent aa680b25fd
commit 66f0ee9e50
238 changed files with 9243 additions and 1682 deletions

View File

@@ -0,0 +1,37 @@
<?php
use App\Support\Ip;
it('matches an ip exactly when no mask is provided', function () {
expect(Ip::inNetwork('10.0.0.1', '10.0.0.1'))->toBeTrue();
});
it('returns false when an ip does not equal a non-cidr value', function () {
expect(Ip::inNetwork('10.0.0.1', '10.0.0.2'))->toBeFalse();
});
it('matches an ipv4 inside a byte-aligned cidr', function () {
expect(Ip::inNetwork('10.0.0.42', '10.0.0.0/24'))->toBeTrue();
});
it('rejects an ipv4 outside a byte-aligned cidr', function () {
expect(Ip::inNetwork('10.0.1.42', '10.0.0.0/24'))->toBeFalse();
});
it('matches an ipv4 inside a non-byte-aligned cidr', function () {
expect(Ip::inNetwork('192.168.16.5', '192.168.16.0/20'))->toBeTrue();
});
it('rejects an ipv4 outside a non-byte-aligned cidr', function () {
expect(Ip::inNetwork('192.168.32.5', '192.168.16.0/20'))->toBeFalse();
});
it('matches a /32 host route', function () {
expect(Ip::inNetwork('10.0.0.1', '10.0.0.1/32'))->toBeTrue();
expect(Ip::inNetwork('10.0.0.2', '10.0.0.1/32'))->toBeFalse();
});
it('matches every address inside a /0', function () {
expect(Ip::inNetwork('10.0.0.1', '0.0.0.0/0'))->toBeTrue();
expect(Ip::inNetwork('255.255.255.255', '0.0.0.0/0'))->toBeTrue();
});