diff --git a/.dockerignore b/.dockerignore index 42dc9d58b..92bd5419d 100644 --- a/.dockerignore +++ b/.dockerignore @@ -1,23 +1,57 @@ -node_modules -tmp +# Version control +.git +.gitignore + +# Sensitive config (user may mount their own) app/Config/Email.php + +# Build artifacts +node_modules/ +dist/ +tmp/ *.patch patches/ + +# IDE and editor files .idea/ -git-svn-diff.py -*.bash +.vscode/ .swp +*.swp .buildpath .project -.settings/* -.git -dist/ -node_modules/ -*.swp +.settings/ + +# Development tools and configs +tests/ +phpunit.xml +.php-cs-fixer.* +phpstan.neon +*.bash +git-svn-diff.py + +# Documentation +*.md +!LICENSE +branding/ + +# Build configs (not needed at runtime) +composer.json +composer.lock +package.json +package-lock.json +gulpfile.js +.env +.env.* +.dockerignore + +# Temporary and backup files *.rej *.orig *~ *.~ *.log -app/writable/session/* -!app/writable/session/index.html + +# CI +.github/ +.github/workflows/ +build/ diff --git a/.env.example b/.env.example index 17298ab69..d055638c1 100644 --- a/.env.example +++ b/.env.example @@ -2,62 +2,116 @@ # ENVIRONMENT #-------------------------------------------------------------------- -CI_ENVIRONMENT = production +CI_ENVIRONMENT=production + +#-------------------------------------------------------------------- +# SECURITY: ALLOWED HOSTNAMES +#-------------------------------------------------------------------- +# CRITICAL: Whitelist of allowed hostnames to prevent Host Header +# Injection attacks (GHSA-jchf-7hr6-h4f3). +# +# REQUIRED IN PRODUCTION: Application will fail to start if not configured. +# In development, falls back to 'localhost' with an error log. +# +# Configure with comma-separated list of domains/subdomains: +# app.allowedHostnames='yourdomain.com,www.yourdomain.com' +# +# Or via environment variable (useful for Docker/Compose): +# ALLOWED_HOSTNAMES=yourdomain.com,www.yourdomain.com +# +# For local development: +# app.allowedHostnames='localhost' +# +# Note: Do not include protocol (http/https) or port numbers. +app.allowedHostnames='' #-------------------------------------------------------------------- # DATABASE #-------------------------------------------------------------------- -database.default.hostname = 'localhost' -database.default.database = 'ospos' -database.default.username = 'admin' -database.default.password = 'pointofsale' -database.default.DBDriver = 'MySQLi' -database.default.DBPrefix = 'ospos_' +database.default.hostname='localhost' +database.default.database='ospos' +database.default.username='admin' +database.default.password='pointofsale' +database.default.DBDriver='MySQLi' +database.default.DBPrefix='ospos_' -database.development.hostname = 'localhost' -database.development.database = 'ospos' -database.development.username = 'admin' -database.development.password = 'pointofsale' -database.development.DBDriver = 'MySQLi' -database.development.DBPrefix = 'ospos_' +database.development.hostname='localhost' +database.development.database='ospos' +database.development.username='admin' +database.development.password='pointofsale' +database.development.DBDriver='MySQLi' +database.development.DBPrefix='ospos_' -database.tests.hostname = 'localhost' -database.tests.database = 'ospos' -database.tests.username = 'admin' -database.tests.password = 'pointofsale' -database.tests.DBDriver = 'MySQLi' -database.tests.DBPrefix = 'ospos_' +database.tests.hostname='localhost' +database.tests.database='ospos_test' +database.tests.username='admin' +database.tests.password='pointofsale' +database.tests.DBDriver='MySQLi' +database.tests.DBPrefix='ospos_' #-------------------------------------------------------------------- # ENCRYPTION #-------------------------------------------------------------------- -encryption.key = '' +# Leave blank and the application auto-generates a unique key on first use. +# For Docker/Compose, pass it via the ENCRYPTION_KEY env var instead: +# docker run -e ENCRYPTION_KEY="$(openssl rand -hex 32)" opensourcepos +# ENCRYPTION_KEY is read as a fallback when encryption.key is empty, so no +# shared key needs to be committed or baked into the shipped image. +encryption.key='' +# Persistent secret for HMAC-hashing login-throttle cache keys. Left blank and +# provisioned on startup (php spark env:provision); independent of encryption.key. +# For Docker/Compose, pass it via the THROTTLE_KEY env var instead: +# docker run -e THROTTLE_KEY="$(openssl rand -hex 32)" opensourcepos +# THROTTLE_KEY is read as a fallback when throttle.key is empty, so no +# shared secret needs to be committed or baked into the shipped image. +throttle.key='' #-------------------------------------------------------------------- # LOGGER -# - 0 = Disables logging, Error logging TURNED OFF -# - 1 = Emergency Messages - System is unusable -# - 2 = Alert Messages - Action Must Be Taken Immediately -# - 3 = Critical Messages - Application component unavailable, unexpected exception. -# - 4 = Runtime Errors - Don't need immediate action, but should be monitored. -# - 5 = Warnings - Exceptional occurrences that are not errors. -# - 6 = Notices - Normal but significant events. -# - 7 = Info - Interesting events, like user logging in, etc. -# - 8 = Debug - Detailed debug information. -# - 9 = All Messages +# - 0=Disables logging, Error logging TURNED OFF +# - 1=Emergency Messages - System is unusable +# - 2=Alert Messages - Action Must Be Taken Immediately +# - 3=Critical Messages - Application component unavailable, unexpected exception. +# - 4=Runtime Errors - Don't need immediate action, but should be monitored. +# - 5=Warnings - Exceptional occurrences that are not errors. +# - 6=Notices - Normal but significant events. +# - 7=Info - Interesting events, like user logging in, etc. +# - 8=Debug - Detailed debug information. +# - 9=All Messages #-------------------------------------------------------------------- -logger.threshold = 0 -app.db_log_enabled = false +logger.threshold=0 +app.db_log_enabled=false #-------------------------------------------------------------------- # HONEYPOT #-------------------------------------------------------------------- -honeypot.hidden = true -honeypot.label = 'Fill This Field' -honeypot.name = 'honeypot' -honeypot.template = '' -honeypot.container = '
' +honeypot.hidden=true +honeypot.label='Fill This Field' +honeypot.name='honeypot' +honeypot.template='' +honeypot.container='' + +#-------------------------------------------------------------------- +# SECURITY: DISALLOW PASSWORD CHANGE +#-------------------------------------------------------------------- +# When true, disables the "change password" feature for all employees. +# Useful when passwords are managed by an external system (e.g. SSO/LDAP). +# +# DISALLOW_PASSWORD_CHANGE=false + +DISALLOW_PASSWORD_CHANGE=false + +#-------------------------------------------------------------------- +# SECURITY: DISALLOW GRANT CHANGE +#-------------------------------------------------------------------- +# When true, disables changing an employee's grants for all employees. +# New employees cannot be created with grants while this is enabled. +# Useful for demo deployments. +# +# DISALLOW_GRANT_CHANGE=false + +DISALLOW_GRANT_CHANGE=false diff --git a/.github/ISSUE_TEMPLATE/bug report.yml b/.github/ISSUE_TEMPLATE/bug report.yml index c026d3144..fddd1ddcc 100644 --- a/.github/ISSUE_TEMPLATE/bug report.yml +++ b/.github/ISSUE_TEMPLATE/bug report.yml @@ -1,121 +1,187 @@ -name: Bug Report -description: File a bug report -title: "[Bug]: " -labels: ["bug", "triage"] -projects: ["ospos/3", "ospos/4"] -assignees: - - none -body: - - type: markdown - attributes: - value: | - Bug reports indicate that something is not working as intended. - Please include as much detail as possible and submit a separate bug report for each problem. - Do not include personal identifying information such as email addresses or encryption keys. - - type: textarea - id: bug-description - attributes: - label: Bug Description? - description: Describe the problem that you are seeing - placeholder: "Describe the problem that you are seeing" - validations: - required: true - - type: textarea - id: steps-reproduce - attributes: - label: Steps to Reproduce? - description: List the steps to reproduce this issue - placeholder: "Steps to Reproduce" - validations: - required: true - - type: textarea - id: expected-behavior - attributes: - label: Expected Behavior? - description: Tell us what did you expect to happen? - placeholder: "Expected Behavior" - validations: - required: true - - type: dropdown - id: ospos-version - attributes: - label: OpensourcePOS Version - description: What version of our software are you running? - options: - - development (unreleased) - - opensourcepos 3.4.1 - - opensourcepos 3.4.0 - - opensourcepos 3.3.9 - - opensourcepos 3.3.8 - - opensourcepos 3.3.7 - default: 0 - validations: - required: true - - type: dropdown - id: php-version - attributes: - label: Php version - description: What version of Php? - options: - - Php 7.2 - - Php 7.3 - - Php 7.4 - - Php 8.1 - - Php 8.2 - - Php 8.3 - - Php 8.4 - default: 0 - validations: - required: true - - type: dropdown - id: browsers - attributes: - label: What browsers are you seeing the problem on? - multiple: true - options: - - Firefox - - Chrome - - Safari - - Microsoft Edge - - Other - - type: input - id: server - attributes: - label: Server Operating System and version - description: "Server Operating System " - placeholder: "Server Operating System " - validations: - required: true - - type: input - id: database - attributes: - label: Database Management System and version - description: "Database Management System" - placeholder: "Database Management" - validations: - required: true - - type: input - id: webserver - attributes: - label: Web Server and version - description: "Web Server and version " - placeholder: "Web Server and version " - validations: - required: true - - type: textarea - id: servers - attributes: - label: System Information Report (optional) - description: Copy and paste from OSPOS > Configuration > Setup & Conf > Setup & Conf? - placeholder: System Information Report - value: "System Information Report" - validations: - required: true - - type: checkboxes - id: terms - attributes: - label: Unmodified copy of OpensourcePOS - description: By submitting this issue you agree this copy has not been modified - options: - - label: I agree this copy has not been modified - required: true +name: š Bug Report +description: File a bug report to help us improve +title: "[Bug]: " +labels: ["bug", "triage"] +projects: ["ospos/3", "ospos/4"] +assignees: [] +body: + # āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā + # INTRODUCTION + # āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā + - type: markdown + attributes: + value: | + ## Thanks for taking the time to fill out this bug report! š + + Bug reports help us identify and fix issues. Please provide as much detail as possible. + + > ā ļø **Important:** Submit a separate bug report for each problem you encounter. + > + > š« Do not include personal identifying information such as email addresses or encryption keys. + + # āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā + # PROBLEM DESCRIPTION + # āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā + - type: textarea + id: bug-description + attributes: + label: š Bug Description + description: A clear and concise description of what the bug is. + placeholder: | + Example: When I try to print a receipt, the application crashes + with an error message saying "Unable to connect to printer". + validations: + required: true + + - type: textarea + id: steps-reproduce + attributes: + label: š Steps to Reproduce + description: Detailed steps to reproduce the behavior. + placeholder: | + 1. Go to '...' + 2. Click on '...' + 3. Scroll down to '...' + 4. See error + validations: + required: true + + - type: textarea + id: expected-behavior + attributes: + label: ā Expected Behavior + description: A clear and concise description of what you expected to happen. + placeholder: | + Example: The receipt should print successfully without any errors. + validations: + required: true + + # āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā + # ENVIRONMENT DETAILS + # āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā + - type: dropdown + id: ospos-version + attributes: + label: š¦ OpenSourcePOS Version + description: What version of our software are you running? + options: + - development (unreleased) + - OpenSourcePOS 3.4.2 + - OpenSourcePOS 3.4.1 + - OpenSourcePOS 3.4.0 + - OpenSourcePOS 3.3.9 + - OpenSourcePOS 3.3.8 + default: 0 + validations: + required: true + + - type: dropdown + id: php-version + attributes: + label: š§ PHP Version + description: What version of PHP are you running? + options: + - PHP 8.4 + - PHP 8.3 + - PHP 8.2 + - PHP 8.1 + - PHP 7.4 + - Other + default: 0 + validations: + required: true + + - type: dropdown + id: browsers + attributes: + label: š Browser(s) + description: What browser(s) are you seeing the problem on? + multiple: true + options: + - Firefox + - Chrome + - Safari + - Microsoft Edge + - Other + + - type: input + id: server + attributes: + label: š„ļø Server Operating System + description: What server OS and version are you running? + placeholder: "e.g., Ubuntu 22.04, CentOS 7, Windows Server 2022" + validations: + required: true + + - type: input + id: database + attributes: + label: šļø Database + description: What database management system and version are you using? + placeholder: "e.g., MySQL 8.0, MariaDB 10.11, Percona 8.0" + validations: + required: true + + - type: input + id: webserver + attributes: + label: š Web Server + description: What web server and version are you using? + placeholder: "e.g., Apache 2.4, Nginx 1.24, Caddy 2.7" + validations: + required: true + + # āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā + # ADDITIONAL INFORMATION + # āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā + - type: textarea + id: system-info + attributes: + label: š System Information Report + description: | + Copy and paste the system information from OSPOS: + + **Navigation:** Configuration ā Setup & Conf ā System Info + placeholder: | + Paste the System Information Report here... + render: text + validations: + required: true + + - type: textarea + id: logs + attributes: + label: š Relevant Log Output + description: | + Please copy and paste any relevant log output. + + **Log locations:** + - OSPOS logs: `writable/logs/` + - Web server logs: `/var/log/apache2/` or `/var/log/nginx/` + - PHP logs: Check your `php.ini` for `error_log` location + placeholder: | + Paste log output here... + render: shell + + - type: textarea + id: screenshots + attributes: + label: šø Screenshots + description: If applicable, add screenshots to help explain your problem. + placeholder: Drag and drop images here... + + # āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā + # CONFIRMATION + # āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā + - type: checkboxes + id: terms + attributes: + label: ā Confirmation + description: Please confirm the following before submitting + options: + - label: I certify that this is an unmodified copy of OpenSourcePOS + required: true + - label: I have searched existing issues to ensure this bug has not already been reported + required: true + - label: I have provided all the information requested above + required: true diff --git a/.github/ISSUE_TEMPLATE/feature_request.yml b/.github/ISSUE_TEMPLATE/feature_request.yml index 028fa0b3d..16714eb90 100644 --- a/.github/ISSUE_TEMPLATE/feature_request.yml +++ b/.github/ISSUE_TEMPLATE/feature_request.yml @@ -1,63 +1,136 @@ -name: ⨠Feature Request -description: Suggest an idea for this project -title: "[Feature]: " -labels: ["enhancement"] -assignees: ["none"] -body: - - type: markdown - attributes: - value: | - Thanks for taking the time to fill out this feature request! š¤ - Please make sure this feature request hasn't been already submitted by someone by looking through other open/closed issues. š - - - type: dropdown - attributes: - multiple: false - label: Type of Feature - description: Select the type of feature request. - options: - - "⨠New Feature" - - "š Documentation" - - "šØ Style and UI" - - "šØ Code Refactor" - - "ā” Performance Improvements" - - "ā New Test" - validations: - required: true - - - type: dropdown - id: ospos-version - attributes: - label: OpensourcePOS Version - description: What version of our software are you running? - options: - - opensourcepos 3.3.9 - - opensourcepos 3.3.8 - - opensourcepos 3.3.7 - default: 0 - validations: - required: true - - - type: textarea - id: description - attributes: - label: Description - description: Give us a brief description of the feature or enhancement you would like - validations: - required: true - - - type: textarea - id: additional-information - attributes: - label: Additional Information - description: Give us some additional information on the feature request like proposed solutions, links, screenshots, etc. - - - type: checkboxes - id: terms - attributes: - label: Verify you searched open requests in OpensourcePOS - description: By submitting this request you agree that you have searched Open Requests in the Tracker - options: - - label: I agree I have searched Open Requests - required: true - +name: ⨠Feature Request +description: Suggest an idea or enhancement for this project +title: "[Feature]: " +labels: ["enhancement"] +assignees: [] +body: + # āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā + # INTRODUCTION + # āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā + - type: markdown + attributes: + value: | + ## Thanks for suggesting a new feature! š” + + We appreciate you taking the time to help improve OpenSourcePOS. + + > š **Before submitting:** Please search [existing feature requests](https://github.com/opensourcepos/opensourcepos/issues?q=is%3Aissue+is%3Aopen+label%3Aenhancement) to ensure your idea hasn't already been suggested. + + # āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā + # FEATURE DETAILS + # āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā + - type: dropdown + id: feature-type + attributes: + label: š·ļø Feature Type + description: What type of feature are you requesting? + options: + - "⨠New Feature" + - "š Documentation Improvement" + - "šØ UI/UX Enhancement" + - "šØ Code Refactoring" + - "ā” Performance Improvement" + - "ā New Test Coverage" + - "š Plugin/Integration" + default: 0 + validations: + required: true + + - type: dropdown + id: ospos-version + attributes: + label: š¦ OpenSourcePOS Version + description: What version are you currently running? + options: + - development (unreleased) + - OpenSourcePOS 3.4.2 + - OpenSourcePOS 3.4.1 + - OpenSourcePOS 3.4.0 + - OpenSourcePOS 3.3.9 + - OpenSourcePOS 3.3.8 + default: 0 + validations: + required: true + + - type: textarea + id: problem-statement + attributes: + label: šÆ Problem Statement + description: | + Is your feature request related to a problem? Please describe. + + A clear description of what the problem is. Ex: I'm always frustrated when [...] + placeholder: | + Example: I always have to manually calculate taxes for different regions, + which is time-consuming and error-prone. + validations: + required: true + + - type: textarea + id: proposed-solution + attributes: + label: š” Proposed Solution + description: A clear and concise description of what you want to happen. + placeholder: | + Example: Add an automatic tax calculation feature that: + - Detects the customer's region + - Applies the correct tax rate + - Generates a tax report automatically + validations: + required: true + + - type: textarea + id: alternatives + attributes: + label: š Alternatives Considered + description: A clear description of any alternative solutions or features you've considered. + placeholder: | + Example: I considered using an external tax service, but it would be + better to have this integrated directly into OpenSourcePOS. + + # āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā + # ADDITIONAL INFORMATION + # āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā + - type: textarea + id: additional-context + attributes: + label: š Additional Context + description: | + Add any other context, screenshots, mockups, or references about the feature request here. + + **Helpful additions:** + - Links to similar features in other software + - Mockups or diagrams + - Code examples + - Documentation references + placeholder: | + Any other relevant information, links, or screenshots... + + - type: textarea + id: acceptance-criteria + attributes: + label: ā Acceptance Criteria + description: | + (Optional) Define what "done" looks like for this feature. + + Format: **Given** [context], **When** [action], **Then** [outcome] + placeholder: | + Given a customer is selected from region X + When the sale is completed + Then the tax rate for region X is automatically applied + And the tax amount is correctly calculated + And a tax entry is logged in the report + + # āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā + # CONFIRMATION + # āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā + - type: checkboxes + id: terms + attributes: + label: ā Confirmation + description: Please confirm before submitting + options: + - label: I have searched existing feature requests to ensure this is not a duplicate + required: true + - label: I have provided a clear problem statement and proposed solution + required: true \ No newline at end of file diff --git a/.github/workflows/README.md b/.github/workflows/README.md new file mode 100644 index 000000000..e4adb1f83 --- /dev/null +++ b/.github/workflows/README.md @@ -0,0 +1,63 @@ +# GitHub Actions + +This document describes the CI/CD workflows for OSPOS. + +## Build and Release Workflow (`.github/workflows/build-release.yml`) + +### Build Process +- Setup PHP 8.2 with required extensions +- Setup Node.js 20 +- Install composer dependencies +- Install npm dependencies +- Build frontend assets with Gulp + +### Docker Images +- Build and push `opensourcepos` Docker image for multiple architectures (linux/amd64, linux/arm64) +- On `master`: tagged `master` and `
-
+
@@ -102,11 +102,11 @@ NOTE: If you're running non-release code, please make sure you always run the la
- If you have suhosin installed and face an issue with CSRF, please make sure you read [issue #1492](https://github.com/opensourcepos/opensourcepos/issues/1492).
-- PHP `ā„ 8.1` is required to run this app.
+- PHP `ā„ 8.2` is required to run this app.
## š Keep the Machine Running
-If you like our project, please consider buying us a coffee through the button below so we can keep adding features.
+If you like our project, please consider buying us a coffee through the button below so we can keep adding features. Please star the project if you like it!
[](https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=MUN6AEG7NY6H8)\
Or refer to the [FUNDING.yml](.github/FUNDING.yml) file.
@@ -137,7 +137,7 @@ Any person or company found breaching the license agreement might find a bunch o
## š Credits
-|