fix: auto-recover from stale CSRF token instead of failing add-to-car… #52
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: ["**"] | |
| pull_request: | |
| branches: [main] | |
| concurrency: | |
| group: ci-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| # ───────────────────────────────────────────────────────────── | |
| # 1. Code style — Pint (fail fast before running full suite) | |
| # ───────────────────────────────────────────────────────────── | |
| format: | |
| name: Code Style (Pint) | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Setup PHP | |
| uses: shivammathur/setup-php@v2 | |
| with: | |
| php-version: "8.4" | |
| extensions: mbstring, xml, ctype, json, bcmath | |
| coverage: none | |
| - name: Cache Composer dependencies | |
| uses: actions/cache@v4 | |
| with: | |
| path: vendor | |
| key: composer-${{ hashFiles('composer.lock') }} | |
| restore-keys: composer- | |
| - name: Install dependencies | |
| run: composer install --prefer-dist --no-interaction --no-progress --no-scripts | |
| - name: Check code style | |
| run: vendor/bin/pint --test | |
| # ───────────────────────────────────────────────────────────── | |
| # 2. Static analysis — Rector (no changes expected on CI) | |
| # ───────────────────────────────────────────────────────────── | |
| rector: | |
| name: Static Analysis (Rector) | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Setup PHP | |
| uses: shivammathur/setup-php@v2 | |
| with: | |
| php-version: "8.4" | |
| extensions: mbstring, xml, ctype, json, bcmath | |
| coverage: none | |
| - name: Cache Composer dependencies | |
| uses: actions/cache@v4 | |
| with: | |
| path: vendor | |
| key: composer-${{ hashFiles('composer.lock') }} | |
| restore-keys: composer- | |
| - name: Install dependencies | |
| run: composer install --prefer-dist --no-interaction --no-progress --no-scripts | |
| - name: Run Rector (dry-run) | |
| run: vendor/bin/rector --dry-run --no-progress-bar | |
| # ───────────────────────────────────────────────────────────── | |
| # 3. Tests — Pest on PHP 8.4 with SQLite in-memory | |
| # ───────────────────────────────────────────────────────────── | |
| tests: | |
| name: Tests (PHP ${{ matrix.php }}) | |
| runs-on: ubuntu-latest | |
| needs: [format] | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| php: ["8.4"] | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Setup PHP | |
| uses: shivammathur/setup-php@v2 | |
| with: | |
| php-version: ${{ matrix.php }} | |
| extensions: mbstring, xml, ctype, json, bcmath, pdo, pdo_sqlite, sqlite3, zip, curl | |
| coverage: none | |
| - name: Copy environment file | |
| run: cp .env.example .env | |
| - name: Cache Composer dependencies | |
| uses: actions/cache@v4 | |
| with: | |
| path: vendor | |
| key: composer-${{ matrix.php }}-${{ hashFiles('composer.lock') }} | |
| restore-keys: composer-${{ matrix.php }}- | |
| - name: Install PHP dependencies | |
| run: composer install --prefer-dist --no-interaction --no-progress | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: "20" | |
| cache: "npm" | |
| - name: Install Node dependencies | |
| run: npm ci | |
| - name: Build frontend assets | |
| run: npm run build | |
| - name: Generate application key | |
| run: php artisan key:generate | |
| - name: Run migrations | |
| run: php artisan migrate --force | |
| env: | |
| DB_CONNECTION: sqlite | |
| DB_DATABASE: ":memory:" | |
| - name: Run tests | |
| run: php artisan test --compact | |
| env: | |
| DB_CONNECTION: sqlite | |
| DB_DATABASE: ":memory:" | |
| SCOUT_DRIVER: collection | |
| # ───────────────────────────────────────────────────────────── | |
| # 4. Security audit — check for known vulnerabilities | |
| # ───────────────────────────────────────────────────────────── | |
| security: | |
| name: Security Audit | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Setup PHP | |
| uses: shivammathur/setup-php@v2 | |
| with: | |
| php-version: "8.4" | |
| coverage: none | |
| - name: Install dependencies | |
| run: composer install --prefer-dist --no-interaction --no-progress --no-scripts | |
| - name: Run PHP security audit | |
| run: composer audit --no-dev | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: "20" | |
| cache: "npm" | |
| - name: Install Node dependencies | |
| run: npm ci | |
| - name: Run npm security audit | |
| run: npm audit --audit-level=high |