9 Commits

Author SHA1 Message Date
03c6ec7cae v1.4.0
Co nowego:
- Wsparcie Active Directory dla LDAP (obok LLDAP/OpenLDAP), przełącznik typu
  katalogu w Admin > Integracje.
- Wyszukiwarka klientów dla operatora (Operator > Klienci).
- Stronicowanie kolejki operatora (50/stronę) i dashboardu klienta (20/stronę).
- Globalna wyszukiwarka zgłoszeń (Ctrl+K/Cmd+K) z operatorami w stylu Gmaila
  (od:, temat:, treść:, numer:), plus przycisk "Szukaj" w panelu bocznym.
- Ostatnio przeglądane zgłoszenia w panelu bocznym operatora.
- Przeprojektowany pasek nawigacji: suwak Klient/Operator/Administrator
  zamiast rozwijanego menu, bogatsze menu profilu (nazwa/e-mail/role),
  dynamiczne tytuły kart przeglądarki na każdej podstronie.
- Narzędzie do jednorazowego importu historii zgłoszeń z Heska 3.x
  (scripts/hesk-import/).
- Poprawka: paginacja pokazywała surowe klucze tłumaczeń zamiast tekstu
  (brakujący lang/pl/pagination.php).

Zaktualizowana dokumentacja: README, CLAUDE.md, install.md, ARCHITECTURE.md,
CHANGELOG.md, wiki/*.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-05 00:58:35 +02:00
7a8cf2037c v1.3.0
- Snipe-IT asset inventory integration (Admin > Integracje), optional and off
  by default: connect by API address + personal token (+ SSL-verification
  bypass). Three independent toggles: client can pick which of their own
  Snipe-IT assets a ticket concerns (scoped to admin-selected subcategories,
  empty = never shows), operator sees the requester's assets in a ticket-view
  sidebar, operator can search the whole inventory from that same sidebar (not
  a separate page) for shared equipment. Assets shown as "numer środka - numer
  seryjny - producent model" + category; a linked asset's live status is
  fetched fresh on the ticket page, and unlinking stays available to an
  operator even with both view/search toggles off.
- AI summary: a "Wygeneruj teraz" button for an immediate on-demand refresh,
  plus a new admin toggle to regenerate right after every new reply/note
  instead of only on the next scheduled sweep. The transcript sent to the
  model now also includes the ticket's own opening body, fixing summaries
  missing the original request on long threads.
- Fixed: the status dropdown in the operator ticket view could keep showing
  the pre-change status after a status-changing quick action until the next
  page load (Livewire/Alpine-morph quirk for wire:change-bound selects).
- Docs: README/ARCHITECTURE/CHANGELOG/install/wiki updated for all of the
  above, including correcting the AI-summary refresh description left over
  from the 1.2.1 release notes.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-27 21:11:21 +02:00
1df697afce v1.2.2
- Subcategories can now be reordered within their category — up/down arrow
  buttons next to "Edytuj" in Admin > Kategorie. The order set there is used
  everywhere a subcategory list is shown (pickers, admin listings, etc.).
2026-07-24 13:58:18 +02:00
313e01ad24 v1.2.1
- Generic AI integration (Admin > Integracje > "Integracja AI"), optional and
  off by default: an OpenAI-compatible /chat/completions client (Groq, OpenAI,
  or a self-hosted Ollama instance) configured by base URL, optional API key,
  model, and an SSL-verification toggle. Foundation for the two AI features
  below and anything else that wants an LLM call in the future.
- BookStack automatic content tagging (AI): "Otaguj nową treść"/"Otaguj
  wszystko ponownie" buttons plus `php artisan bookstack:tag-content`
  (--dry-run/--force/--limit=N) tag every book/chapter/page with matching
  helpdesk subcategory names, idempotent by default.
- BookStack search refinement: "Przeszukuj" is now three independent
  checkboxes (Książki/Strony/Rozdziały) instead of a single dropdown, plus a
  new "Szukaj po" setting (nazwa/tagi/oba) — tag matching uses the bare
  subcategory name, matching what auto-tagging writes.
- AI-driven ticket triage + summary (Admin > Integracje > "Automatyzacja AI
  dla zgłoszeń", via new scheduled ai:run-ticket-automation): five toggles
  auto-assign/correct category+subcategory, rewrite an unclear subject, and
  set priority from content, once per ticket in the background; every change
  is logged in the ticket's history. Separately, an AI summary + suggested
  action for every ticket, shown to operators only, with an admin-editable
  prompt.
- Operators can now reassign a ticket to any team, not just one they belong
  to.
- The auto-refresh countdown badges (ticket view, operator queue) are now
  clickable — fetch immediately and reset the countdown.
- All 7 "cyclical" intervals (3 browser refresh countdowns, the notification
  bell poll, and the 4 background scheduled commands) are now configurable
  from Admin > Konfiguracja instead of fixed in code.
- Fixed: an operator viewing a ticket that's deleted or moved outside their
  team scope mid-session is now redirected to the operator queue instead of
  hitting an error.
- Docs: README/ARCHITECTURE/CLAUDE/install/wiki updated for all of the above.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-24 13:38:39 +02:00
0d116dfd98 v1.2.0
- E-mail intake (IMAP), optional and off by default: clients can create a
  ticket or reply to an existing one just by sending/replying to an e-mail.
  Configure any number of mailboxes in the new Admin > Poczta page (SMTP +
  IMAP together, replacing the old "E-MAIL" tab), each routed to a specific
  subcategory or a whole category (new tickets.category_id column). Replies
  are matched to their ticket via the number/checksum already in every
  notification subject; autoresponders/bounces are detected and rejected;
  "restrict tickets to LDAP" is enforced for e-mail like the guest web form.
  Manual "Pobierz teraz" per-mailbox fetch button; dedicated
  storage/logs/imap-*.log regardless of the app's log level; mail-icon badges
  on e-mail-originated tickets/messages in the operator queue and ticket view.
- Operator queue: "select all" checkbox in the table header for every
  currently visible ticket under the active filter/tab.
- Fixed: scheduled commands (SLA breach check, automation rules, and now IMAP
  fetch) always sent notifications through .env's default mailer instead of
  the configured SMTP server, because AppServiceProvider's Settings override
  used to skip itself for any console command, not just migrate.
- Fixed: visiting a ticket that no longer exists (deleted mid-session, or a
  stale background refresh) showed a raw 404 instead of redirecting back to
  the operator queue / client dashboard.
- Docs: README/ARCHITECTURE/CLAUDE/install/wiki updated for all of the above,
  including the previously-missing host crontab entry for schedule:run.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 12:44:30 +02:00
63178b366e v1.1.4
- Configurable ticket numbering (Admin > Konfiguracja > Ogólne): admin-set
  prefix and minimum zero-padded length for the ticket number.
- "Ukryj kolejność zgłoszeń": an opt-in mode that displays a stable,
  HMAC-derived checksum instead of the sequential ticket number, so it gives
  no indication of ticket volume or creation order. Ticket URLs switch to
  the same checksum when this is on, so a link and the number on the page it
  points to always match. The REST API is unaffected — pinned to `id`
  regardless of this setting. Search now also matches by checksum.
- Fixed: attachments no longer show an inline image thumbnail in the
  message thread — every attachment (images included) shows as just its
  filename, opening in a new tab on click.
- Docs: README/ARCHITECTURE/wiki updated for all of the above.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 09:57:39 +02:00
ab90abcaa3 v1.1.3
- Triggers (Admin > Wyzwalacze): event-driven rules that fire immediately on
  a ticket lifecycle event (created/updated/status/priority/assignee/team/
  category changed, new reply), with AND-conditions and ordered actions
  (set status/priority/team/assignee, send e-mail). Ships its own dedicated,
  freely add/edit/delete-able e-mail templates, kept separate from the fixed
  system templates.
- Ticket watching: operators can star/"Obserwuj" any ticket to follow it
  regardless of assignment/team.
- Real-time notification bell (private per-user broadcast channel, 30s
  fallback poll) with an opt-in in-tab browser push notification.
- Per-user notification preferences (/settings/notifications): scope
  (mine/unassigned/watched/all) and e-mail toggle per event category.
- Admin > Integracje: new tab for LDAP/AD + BookStack config, split out of
  Konfiguracja.
- Operator queue: Podkategoria/Zespół/Utworzono columns (off by default).
- Obserwuj button moved next to the auto-refresh countdown; trigger
  condition builder shows subcategory/zgłaszający as name dropdowns instead
  of raw IDs; /settings/notifications got a back link, full-width push
  card, and a bordered table container; admin panel tab and operator queue
  view now persist across a plain page refresh.
- Docs: README/ARCHITECTURE/wiki updated for all of the above.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-22 23:43:01 +02:00
0b06687ea1 v1.1.2
- Real-time updates (Laravel Reverb): live operator queue, live ticket
  chat/detail updates for operator and client, periodic fallback refresh
  with a visible countdown as a backstop for dropped websocket connections.
- SLA automation rules (Admin > Automatyzacja SLA): act on a ticket after
  N minutes of customer silence (change priority/status/team/assignee),
  evaluated every 15 minutes, reusing TicketService's own setters so
  automated changes get the same history/notification/broadcast a manual
  change would.
- New notification: every operator on a matching team gets notified when
  a new ticket lands in one of their subcategories.
- BookStack knowledge-base sidebar now also shown on the client's own
  ticket view (previously operator-only); suggestions everywhere now load
  in after first paint instead of blocking it.
- Client ticket view: shows assigned operator + team; page widened to
  match the operator's.
- Notification bell shows unread only; read notifications disappear
  instead of just dimming.
- Stats dashboard: sectioned layout, new breakdowns (by subcategory, CSAT
  by team/operator, top clients, client x subcategory cross-tab).
- Mobile: nav dropdowns (theme/notifications/profile) now expand full
  width instead of overflowing off-screen below 640px.
- Fixed two bugs that silently disabled all real-time updates (missing
  CSRF header on Echo's private-channel auth; a script-load-order race
  that could miss the livewire:init event) and the mariadb healthcheck
  (world-writable credentials file on this stack's NFS mount).
- Assorted test-suite fixes (roles virtual attribute needs the roles
  table seeded; a few missing seeds/wrong assertions found along the way).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-22 20:43:05 +02:00
def7c70887 Add pcntl/posix PHP extensions for Reverb signal handling
All checks were successful
Build and push image / build (push) Successful in 1m25s
The Reverb websocket server (artisan reverb:start) needs pcntl for
SIGINT/SIGTERM/SIGTSTP signal handling on shutdown; the base php:apache
image doesn't enable it by default.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-22 16:33:08 +02:00
174 changed files with 15640 additions and 615 deletions

3
.gitignore vendored
View File

@@ -1,3 +1,4 @@
/mysql/
.env
compose.yaml
compose.yaml
scripts/hesk-import/.env

View File

@@ -63,13 +63,94 @@ queue + unassigned + anything assigned to them, an admin sees everything), and
work-timer tracking (`timerElapsedSeconds()`). Keep ticket-shaped logic here
rather than spreading it across Livewire components.
## Ticket numbering & URLs
A ticket carries three distinct identifiers, each with a different job:
- **`id`** — the DB primary key. Never shown to users; the REST API
(`routes/api.php`) is deliberately pinned to it (`{ticket:id}` explicit
binding on every `{ticket}` route) so external integrations have a stable
contract regardless of the numbering settings below.
- **`number`** — a plain sequential string (`Ticket::nextNumber()`, max+1
starting at 1001), unique but otherwise unremarkable. Backs `scopeSearch()`
and the numeric sort in `Operator/Queue.php` regardless of display mode.
- **`checksum`** — a 6-digit HMAC-derived value (salted with `app.key`,
keyed off `id`), assigned once in a `Ticket::booted()` `created` listener
and never changed afterward. Collisions are handled for real, not just
assumed away: `Ticket::generateUniqueChecksum()` walks a nonce forward
until the candidate is free (checked against the DB), and the column has a
`unique()` constraint as a hard backstop.
`Ticket::displayNumber()`/`formattedNumber()` pick between `number` (zero-padded
to `Settings::get('ticket_number_min_length')`) and `checksum` based on
`Settings::bool('ticket_number_obfuscate')` — the "Ukryj kolejność zgłoszeń"
toggle in Admin > Konfiguracja. `Ticket` also overrides `getRouteKey()` and
`resolveRouteBinding()` to mirror that same choice, so **the web routes**
(`routes/web.php`, all plain `{ticket}` implicit bindings — no explicit field)
resolve and generate URLs against whichever column is currently the display
number: flip the setting and both the visible number *and* every link
(`route('client.ticket', $ticket)` etc.) switch together, and a bookmarked URL
built under the old mode stops resolving. This is why the API routes need the
explicit `{ticket:id}` override — without it, the same global `getRouteKey()`
change would silently start requiring `number`/`checksum` in API path params
too, breaking the documented `integer` "Ticket id" contract.
The `{numer}` placeholder available in admin-editable e-mail templates
(Admin > Szablony e-mail / Wyzwalacze) resolves to `formattedNumber()`
*without* `displayNumber()`'s prefix — those templates already hardcode their
own `#{numer}`, so adding the prefix there too would double it up or clash
with a non-default prefix.
A ticket route binding that resolves to nothing (most commonly: the ticket
was deleted while someone had it open, and a later request — typically
Livewire's own "model missing during hydration" recovery, which does a full
`window.location.reload()` of the same page — hits `{ticket}` again) no
longer surfaces Laravel's default 404 page. `bootstrap/app.php` registers a
`NotFoundHttpException` render callback (note: `Handler::prepareException()`
already converts `ModelNotFoundException` into `NotFoundHttpException`,
wrapped as `getPrevious()`, *before* any render callback runs — a callback
typed against `ModelNotFoundException` itself would never match) that
redirects to `operator.queue`/`client.dashboard` instead, for any
authenticated request under `operator/*`/`client/*`.
That global handler only ever sees a full HTTP request (a page load/reload),
not Livewire's own AJAX update endpoint (`/livewire/update`, which doesn't
match the `operator/*`/`client/*` path check) — so it doesn't cover an
operator who already has a ticket open when it's deleted, or whose team gets
reassigned (by anyone, including via their own action — see "Teams" in
[README.md](README.md)) to one outside their visible scope
(`Ticket::isVisibleToOperator()`) mid-session. `Operator\TicketShow` handles
that case itself: a Livewire component's typed public model property
(`public Ticket $ticket`) is re-fetched by id on every subsequent request via
`firstOrFail()` (`Livewire\Features\SupportModels\ModelSynth::hydrate()`),
which throws `ModelNotFoundException` *before* any of the component's own
method code runs if the row is gone — too early for an ordinary try/catch
inside an action method to ever catch. The component instead defines
Livewire's `exception($e, $stopPropagation)` lifecycle hook (called for any
exception raised anywhere in the component's request lifecycle, hydration
included) to catch that case and redirect. The narrower case — ticket still
exists but is no longer visible, e.g. after a team reassignment — doesn't
throw at all, so it's caught separately: `refreshOrRedirectAway()` re-checks
`isVisibleToOperator()` after every live-update refresh
(`onQueueChanged()`/`refreshTicketData()`) and after the operator's own
`setTeam()` call, redirecting immediately rather than leaving them on a
ticket they can no longer legitimately keep viewing.
## Roles & permissions
Roles are a plain array on the user (`$user->roles`), not a separate pivot-backed
package — checked via `EnsureRole` at the route level. Every account gets
`client` by default (`App\Ldap\Handlers\AssignDefaultRole` for LDAP-provisioned
accounts); staff switch areas via the header role switcher, but always land on
`/client` first after login.
`$user->roles` reads/writes as a plain array (`['client', 'operator']`), but
it's a **virtual attribute** (`User::getAttribute()`/`setAttribute()`
overrides) backed by a real `roles` lookup table + `role_user` pivot, not an
actual column — assigning `'roles' => [...]` on create/update stashes the keys
until the model's `saved` hook resolves them against `roles.key` and syncs the
pivot. This matters for tests/seeders: a role key must exist in the `roles`
table *before* it can be assigned this way, or the assignment silently becomes
a no-op (`Tests\TestCase::setUp()` seeds the 3 fixed roles for exactly this
reason, since almost every test creates a role-bearing user). Checked via
`EnsureRole` at the route level. Every account gets `client` by default
(`App\Ldap\Handlers\AssignDefaultRole` for LDAP-provisioned accounts); staff
switch areas via the header role switcher, but always land on `/client` first
after login.
## Authentication
@@ -86,12 +167,23 @@ the account used for first login after a fresh install (see
`SyncUserFieldsFromLdap` keeps `UserFieldValue` rows in sync with directory
attributes.
`app/Ldap/` has two directory-schema models — `LldapUser` (LLDAP/OpenLDAP,
the default) and `AdUser` (Active Directory, `LdapRecord\Models\ActiveDirectory\User`
under the hood). `Settings::ldapUserModelClass()` picks between them based on
the `ldap_directory_type` setting, and `AppServiceProvider::applyLdapSettingsOverride()`
wires the chosen class into `config('auth.providers.users.model')` on every
request — same live-override mechanism as the connection host/base DN below.
`LdapUserProvisioner` (used for sync + guest auto-provisioning) resolves the
same setting at call time rather than caching the class, so switching
directory type takes effect without a redeploy.
## Settings override ("live config")
`App\Support\Settings` (`app/Support/Settings.php`) is a cached key/value reader
over the `settings` table, with hardcoded defaults for every key (company name,
LDAP/SMTP connection details, attachment limits, session lifetime, timezone,
branding/email HTML, etc.). Admin > Konfiguracja writes to this table, and
branding/email HTML, etc.). Admin > Konfiguracja (general/attachments/session),
Poczta (SMTP) and Integracje (LDAP, BookStack) all write to this same table, and
`AppServiceProvider::boot()` re-applies the relevant subset of it over
`config()` on every request — meaning **`Setting` rows win over `.env`** for
LDAP, mail, session lifetime and timezone once they're non-empty. This is by
@@ -100,6 +192,19 @@ source of the "seeded placeholder overrides real `.env` values" gotcha
documented in [install.md](install.md) — anything touching LDAP/mail/session/
timezone config should go through `Settings`, not raw `config()`/`.env` reads.
`settingsTableUsable()` gates all four overrides on whether the `settings`
table is safe to query yet — but is deliberately scoped to just the `migrate`
command family (`runningConsoleCommand('migrate', 'migrate:fresh', ...)`), not
"any console command". It used to blanket-skip for every console invocation
(exempting only unit tests), which silently broke every scheduled command's
outbound mail: `AppServiceProvider::boot()` runs on each process including
`schedule:run`-invoked commands, so `tickets:check-sla-breaches`,
`automation:run-rules` and `emails:fetch-imap` (below) all sent notifications
through whatever `.env`'s `MAIL_MAILER` happened to be (`log`, i.e. nowhere)
instead of the admin-configured SMTP server — with no error, since the `log`
mailer never throws. If a scheduled command's notification/lookup ever again
seems to silently use `.env` defaults instead of `Settings`, check here first.
## Notifications
`TicketService::notify(Ticket $ticket, string $triggerKey)` is the single
@@ -118,15 +223,232 @@ since one account can hold both — this decides whether the ticket link (both
the e-mail body and the in-app notification's `url`) points into `/client/...`
or `/operator/...`.
## Real-time broadcasting (Reverb)
Two private channels, authorized in `routes/channels.php`:
- **`operator.queue`** — one shared channel for every operator/admin (not
scoped per team/ticket), so the receiving `Operator\Queue` component just
re-queries through its own already-correct `Ticket::scopeVisibleToOperator()`
on any event instead of the channel-auth callback needing to duplicate that
ACL logic. Payloads stay minimal (ticket id + reason + actor id) for the
same reason.
- **`ticket.{id}`** — per-ticket channel for the message thread and detail
changes, authorized for an operator with `isVisibleToOperator()` **or** the
ticket's own customer (OR, not else-if — the one real account in this app
holds both roles at once). An internal note broadcasts on the same channel
a client can subscribe to, but the payload never carries the message body —
each side's Livewire component only ever re-queries whatever its own
already-authorized computed property returns, so there's nothing to leak.
Two events, both `App\Events\TicketQueueChanged` (broadcasts on **both**
channels above — a status/priority/team/assignee change needs to reach a
client watching their own ticket too) and `App\Events\TicketMessagePosted`
(broadcasts on `ticket.{id}` only). Both implement `ShouldBroadcastNow`, not
`ShouldBroadcast` — this app runs with no queue worker by design (see
`TicketNotification`), so broadcasting happens synchronously within the
request like everything else here. `TicketService` dispatches both from every
ticket-mutating method (create/setStatus/setPriority/setAssignee/setTeam/
operatorReply/operatorNote/clientReply/apiMessage/merge); the two ad hoc
delete call sites (`Operator\Queue::confirmDeleteSelected()`,
`Operator\TicketShow::confirmDeleteTicket()`) dispatch `TicketQueueChanged`
directly since there's no `TicketService::delete()` to hook into.
Browser side, `resources/js/echo.js` bridges Reverb events into plain
Livewire events (`Livewire.dispatch('queue-changed', ...)` /
`'ticket-message-posted'`) rather than using the `#[On('echo-private:...')]`
attribute directly — version-agnostic, and each Livewire component just
declares a plain `#[On(...)]` listener that no-ops if the payload's `actorId`
matches the viewer's own id (self-echo suppression) or the ticket id doesn't
match the component's own ticket. Two easy-to-reintroduce bugs to know about
if "nothing updates live" ever comes back:
1. **CSRF on `/broadcasting/auth`.** Echo's private-channel subscription
POSTs there under the app's normal CSRF middleware; the `Echo` constructor
must pass `auth.headers['X-CSRF-TOKEN']` (read from the `<meta
name="csrf-token">` tag in `layouts/app.blade.php`) or every subscription
attempt is silently rejected.
2. **Script load order.** `resources/js/app.js` (which imports `echo.js`)
loads via `@vite` as `type="module"`, which the HTML spec defers until
after the document is parsed — meaning Livewire's own bootstrap script
(`@livewireScripts`, a plain synchronous `<script>` near the end of
`<body>`) has already run by the time `echo.js` executes. Don't gate
anything in `echo.js` behind `document.addEventListener('livewire:init',
...)` — that event fires as part of Livewire's own (earlier) script, so a
listener registered this late permanently misses it. The one place this
still matters is the per-ticket subscription triggered from a Livewire
`@script` block in the ticket-show views, which can run before or after
`echo.js` depending on exactly when Livewire processes it — it queues the
ticket id onto `window.__pendingTicketChannelIds` if `echo.js` hasn't
defined `window.subscribeToTicketChannel` yet, and `echo.js` flushes that
queue once it has.
As a defense against a dropped websocket connection (backgrounded tab,
network blip), the operator queue and both ticket-detail views also poll
themselves via a small Alpine countdown calling `$wire.refreshQueue()` /
`$wire.refreshTicketData()` — broadcasting is best-effort, not the only way
these views ever update. The countdown badge is also clickable
(`x-on:click="remaining = total; $wire.refresh...()"` on the same element
the `x-init="setInterval(...)"` already lives on) to fetch immediately and
reset the countdown, rather than only ever firing on its own schedule. Its
interval — like the notification bell's `wire:poll` and the 4 scheduled
commands below — reads from `Settings` (`refresh_queue_seconds`/
`refresh_ticket_view_seconds`/`refresh_notifications_seconds`, admin-editable
in Konfiguracja) rather than a hardcoded number: `wire:poll.{{ $seconds }}s`
and Alpine's `x-data="{ remaining: {{ $seconds }}, ... }"` both just
interpolate to plain text in the rendered HTML, so a `Settings`-sourced value
works exactly like a literal one would.
A third private channel, **`App.Models.User.{id}`** (Laravel's default
per-notifiable convention, kept verbatim rather than a shorter alias),
carries realtime bell delivery: `AppServiceProvider::broadcastBellNotifications()`
listens for the framework's own `NotificationSent` event, and — only for the
`database` channel of a `TicketNotification` — dispatches `NotificationCreated`
on the recipient's own channel. This is a single choke point rather than
threading a broadcast call into every `TicketService` notification call site
(including the Trigger engine's `send_notification` action, below).
`resources/js/echo.js` bridges it into a `bell-notification-received` Livewire
event (refreshing `NotificationBell` instantly) and, if the viewer opted in via
the toggle on `/settings/notifications`, also raises a native in-tab
`Notification` popup — no service worker or push subscription, so this only
fires while the tab is open, same limitation as the other Echo listeners here.
## SLA
`SlaRule` holds per-priority response/resolution targets in minutes. The
scheduled command `tickets:check-sla-breaches` (registered in
`routes/console.php`, run every 15 minutes via `schedule:run`) flags overdue
tickets and can notify the assigned operator — see [install.md](install.md) for
`routes/console.php`, default every 15 minutes, interval admin-configurable —
see "Configurable scheduled-command intervals" below) flags overdue tickets
and can notify the assigned operator — see [install.md](install.md) for
why this requires an external cron entry (the Docker image ships no
cron/supervisor of its own).
## SLA automation rules
`AutomationRule` (label, `condition_minutes`, optional `scope_priority_key`/
`scope_subcategory_id`/`scope_team_id`, `action_type` + `action_value`) lets an
admin configure "if a ticket has been silent for N minutes, change its
priority/status/team/assignee" without code — Admin > Automatyzacja SLA. The
scheduled command `automation:run-rules` (default also every 15 minutes,
independently configurable) evaluates every enabled rule against
`Ticket.last_customer_activity_at` (falling back to
`created_at` if never set — mirrors how `resolutionDeadline()` treats a
missing `SlaRule` as "no SLA" rather than backfilling one), and applies a
match through the same `TicketService` setters a manual operator action would
use, so the automated change gets the same history entry, notification, and
broadcast for free. Idempotency is a per-(rule, ticket) row in
`automation_rule_ticket_logs`, cleared by `TicketService` whenever the silence
that triggered it is broken (a fresh `clientReply()`) or the ticket
closes/reopens (`setStatus()`) — so a rule can fire again after a new period
of silence instead of being permanently latched. Multiple matching rules on
the same ticket in the same run all fire independently, in `id` order; a rule
that closes the ticket doesn't block earlier-ordered rules already applied
this run, but a later rule's own query naturally excludes an already-closed
ticket.
## Configurable scheduled-command intervals
All 4 scheduled commands (`tickets:check-sla-breaches`, `automation:run-rules`,
`emails:fetch-imap`, `ai:run-ticket-automation`) have an admin-configurable
interval (Admin > Konfiguracja — `schedule_sla_check_minutes`/
`schedule_automation_rules_minutes`/`schedule_imap_fetch_minutes`/
`schedule_ai_automation_minutes`), defaulting to their previous hardcoded
values (15/15/5/5 minutes). `routes/console.php` registers all 4 as
`->everyMinute()->when(fn () => Settings::dueEveryMinutes($key, $default))`
rather than an eagerly-built `->cron('*/N * * * *')` string — this is a
deliberate choice, not just a style preference: `routes/console.php` is
`require`'d on **every** artisan boot (`migrate`, `tinker`, `php artisan
test`, not just `schedule:run`, since it's wired in via `bootstrap/app.php`'s
`commands:` key), so anything at its *top level* that queries the database
would run before a fresh/test database necessarily has the `settings` table
yet — an early version of this feature that built the cron string eagerly at
the top level broke exactly this way. A closure passed to `->when()` is only
ever evaluated later, when `schedule:run` actually processes due events, so
`Settings::dueEveryMinutes()` never runs at boot. One visible side effect:
`php artisan schedule:list` shows `* * * * *` for all four regardless of
their actual configured interval, since the real interval only exists inside
the closure — expected, not a bug.
## IMAP e-mail intake
Optional, off by default (`ImapMailbox.enabled` per row — there is no single
global toggle since this is a list of N mailboxes, not a `Settings`
singleton). Split across three layers, mirroring the plan that shipped it:
- **`App\Models\ImapMailbox`** — one row per polled mailbox (host/port/
encryption/username, `password` cast `'encrypted'` — the first model in
this codebase to use Laravel's native encrypted cast rather than the
manual `Crypt::` pattern `Settings` uses, since this is a list of records
rather than key/value config). `default_subcategory_id` XOR
`default_category_id` (enforced by the admin form's single combined
selector, not a DB constraint) route new tickets; `category_id` only ever
gets populated when there's no subcategory to derive one from (see
`Ticket::categoryLabel()`/`TicketService::create()`).
- **`App\Services\ImapMessageClassifier`** — pure decision logic, no IMAP
connection, fully Pest-testable: `rejectionReason()` (auto-reply/bounce
detection via `Auto-Submitted`/`Precedence`/`X-Autoreply` headers + EN/PL
subject phrases + a per-mailbox sender blocklist), `matchTicket()`
(extracts every digit run ≥4 chars from the subject — after stripping
`Re:`/`Odp:`/`Fwd:`/`FW:`/`Aw:` — and tries each through
`Ticket::resolveRouteBinding()`, so it transparently matches either the
plain sequential number or the obfuscated checksum, whichever mode is
active; no changes to outbound mail were needed since every notification
subject already carries `{numer}`), `isSenderAllowed()` (mirrors
`Landing::emailIsKnown()` — enforces `restrict_tickets_to_ldap` for e-mail
exactly like the guest web form), `resolveSender()` (existing local user,
or `LdapUserProvisioner::findOrCreateByEmail()` if enabled).
- **`App\Services\ImapMailboxFetcher`** — the I/O layer (`webklex/php-imap`,
a pure-PHP IMAP client with no `ext-imap` dependency — confirmed available
extensions were sufficient, no Dockerfile change needed). Fetches
`whereUnseen()` per mailbox, flags/moves a message **before** creating the
ticket (a crash mid-batch then risks a "processed but no ticket" message —
visible and easy to fix manually — rather than a duplicate ticket on the
next run), converts attachments to `UploadedFile` via a temp file (`$test
= true` bypasses the `is_uploaded_file()` check outside a real HTTP
request) so they flow through the existing `Settings::validateAttachments()`
+ `TicketService::attachFiles()` unchanged. Logs every connection attempt
and per-message decision to a dedicated `imap` log channel
(`storage/logs/imap-*.log`, always `debug` level regardless of the app's
own `LOG_LEVEL` — see `config/logging.php`) since this app commonly runs
at `LOG_LEVEL=error`, which would otherwise silently swallow this
activity entirely.
- One real bug worth remembering if IMAP rejection logic ever seems too
aggressive again: Webklex's `Header::get($name)` returns an *empty*
`Attribute` (not `null`) for a header that isn't present at all, and
`Attribute::first()` on that empty instance is `''`, not `null` — a
naive `$header !== null` check therefore treats *every* message as
carrying *every* header. Guarded in two places: `ImapMailboxFetcher`
only keeps a header value that's non-empty, and
`InboundEmail::header()` itself also treats `''` as absent, so the bug
can't resurface even if some other header source stops filtering.
- **`TicketService::guestReply()`** — the one new method added to the
existing service: a customer reply with no `User` account (mirrors
`clientReply()` — real customer activity, resets SLA silence, fires
`comment_added` so an admin-configured Trigger can reopen a closed ticket
— rather than `apiMessage()`, which tags a system/integration note, not
client content). Both `clientReply()` and `guestReply()` take an optional
trailing `string $source = 'web'`, stored as `TicketMessage.source`
(`null` for `'web'`) — the per-message counterpart to `Ticket.source`,
since a ticket opened on the web can later get an e-mail reply or vice
versa. Both surface as a small mail-icon badge (operator queue: next to
the ticket number; ticket view: per-message in the thread, plus a tag next
to the ticket number in the header).
- **`emails:fetch-imap`** (`app/Console/Commands/FetchImapEmails.php`),
registered in `routes/console.php` with `->withoutOverlapping()` (like
`ai:run-ticket-automation`, unlike the SLA-check/automation-rules
commands — both make real outbound HTTP/IMAP calls per record, so a slow
run risks overlapping the next tick in a way a pure-DB command doesn't).
Early-returns if no `ImapMailbox` is enabled. Also callable directly per
mailbox from Admin > Poczta's "Pobierz teraz" button
(`ImapMailboxFetcher::fetchMailbox()`, bypassing the enabled-only
`fetchAll()` used by the schedule) for on-demand fetching/diagnosis
without shell access.
Requires the same external `schedule:run` cron entry as SLA/automation (see
[install.md](install.md) and the crontab note in
[CLAUDE.md](CLAUDE.md)) — without it, only the manual "Pobierz teraz" button
does anything.
## API
`routes/api.php` + `app/Http/Controllers/Api/` expose a small ability-scoped REST
@@ -138,26 +460,224 @@ tighter per-IP limit for unauthenticated requests
generated by L5-Swagger at `/admin/api-docs`; there is no static Markdown API
reference in-repo.
## Generic AI integration
`App\Services\AiClient` is a small, feature-agnostic wrapper around an
OpenAI-compatible `/chat/completions` endpoint (`chat(array $messages, array
$options = []): ?string`) — works against Groq, OpenAI itself, or a
self-hosted Ollama instance, whichever `ai_base_url` points at.
`Settings`-driven like everything else here: `ai_enabled`, `ai_base_url`,
`ai_api_key` (encrypted, optional — deliberately not required by `enabled()`,
since a self-hosted Ollama instance typically has no auth at all),
`ai_model`, `ai_verify_ssl`. Every call is wrapped in `try/catch(\Throwable)`
and returns `null` on any failure (network, non-2xx, unexpected shape),
matching `BookStackClient`'s safe-default convention — callers are expected
to treat `null` as "AI unavailable" and degrade gracefully rather than throw.
Not tied to any single feature: `BookStackContentTagger`,
`TicketAiTriageService` and `TicketAiSummaryService` (below) are just its
first three consumers, each with their own prompt-building/parsing logic
layered on top rather than baked into the client itself.
## BookStack integration
`App\Services\BookStackClient` is the only outbound HTTP client in the
codebase (Laravel's `Http` facade) — everything else here only ever receives
requests. It's entirely `Settings`-driven, no `.env`/`config()` involved:
`bookstack_enabled`, `bookstack_base_url`, `bookstack_token_id`/
`bookstack_token_secret` (encrypted, same as the LDAP/SMTP passwords),
`bookstack_verify_ssl`, `bookstack_search_types` ('both'|'page'|'book'), and
**two independent** allow-lists of BookStack shelf IDs —
`bookstack_allowed_shelf_ids_creation` (ticket-wizard suggestions) and
`bookstack_allowed_shelf_ids_ticket_view` (the operator's sidebar on an
existing ticket) — `search()` takes a `$context` (`CONTEXT_CREATION` /
`CONTEXT_TICKET_VIEW`) that selects which one applies. **An empty allow-list
means "search nothing"**, not "search everything" — nothing is ever
suggested until an admin explicitly opts shelves in, independently per
context. BookStack has no "which shelf is this book on" field in its own
search response, so `BookStackClient` fetches `/api/shelves` +
`/api/shelves/{id}` once (cached 30 min) into a shelf→book-ids map, used both
to resolve the allow-list to book IDs and to build the "Shelf > Book"
breadcrumb shown next to each suggestion. Per-query search results are cached
10 minutes, keyed on the query text **and** the active allow-list, so toggling
which shelves are allowed is reflected immediately instead of serving a
pre-change result for up to 10 minutes.
`App\Services\BookStackClient` is one of three outbound HTTP clients in the
codebase (Laravel's `Http` facade), alongside `AiClient` above and
`SnipeItClient` below — everything else here only ever receives requests.
It's entirely `Settings`-driven, no
`.env`/`config()` involved: `bookstack_enabled`, `bookstack_base_url`,
`bookstack_token_id`/`bookstack_token_secret` (encrypted, same as the
LDAP/SMTP passwords), `bookstack_verify_ssl`, and **two independent**
allow-lists of BookStack shelf IDs — `bookstack_allowed_shelf_ids_creation`
(ticket-wizard suggestions) and `bookstack_allowed_shelf_ids_ticket_view`
(the operator's sidebar on an existing ticket) — `search()` takes a
`$context` (`CONTEXT_CREATION` / `CONTEXT_TICKET_VIEW`) that selects which
one applies. **An empty allow-list means "search nothing"**, not "search
everything" — nothing is ever suggested until an admin explicitly opts
shelves in, independently per context. BookStack has no "which shelf is this
book on" field in its own search response, so `BookStackClient` fetches
`/api/shelves` + `/api/shelves/{id}` once (cached 30 min) into a
shelf→book-ids map, used both to resolve the allow-list to book IDs and to
build the "Shelf > Book" breadcrumb shown next to each suggestion. Per-query
search results are cached 10 minutes, keyed on the query text **and** the
active allow-list, so toggling which shelves are allowed is reflected
immediately instead of serving a pre-change result for up to 10 minutes.
**Content-type filter and "search by" mode**: `bookstack_search_types` is a
comma-separated subset of `BookStackClient::SEARCH_TYPES` (`book`, `page`,
`chapter` — checkboxes in the admin UI, no more single-select "both/page/book"
dropdown), combined into BookStack's own `{type:a|b}` query syntax.
`bookstack_search_by` (`'name'`/`'tags'`/`'both'`) picks between matching the
title (`{in_name:...}`) and matching a tag whose name equals the query
(`[...]` — see BookStack content auto-tagging below for what actually writes
those tags); `'both'` runs one request per mode and merges/dedupes the
results, since BookStack's own query syntax ANDs filters together rather than
OR-ing them, so there's no single-request way to ask for "name OR tag".
`search()` takes both a `$query` (full "Category Subcategory" text, used for
the name-match variant) and an optional `$tagQuery` (bare subcategory name,
used for the tag-match variant) — the two differ because a tag is expected to
hold just the subcategory name, not the combined category+subcategory text.
## BookStack content auto-tagging
`App\Services\BookStackContentTagger` (used by the "Otaguj nową
treść"/"Otaguj wszystko ponownie" buttons on the BookStack admin card and by
`php artisan bookstack:tag-content`) is the reason the tag-based search mode
above has anything to match: it walks every book/chapter/page via
`BookStackClient::listAll()`/`detail()`, builds a Polish prompt naming the
current, live `Subcategory` list as the only allowed vocabulary, and asks
`AiClient` (above) to return which subcategory name(s) fit each item — a
single response per batch of 20 items, to keep prompt size/cost down.
Defensive JSON parsing (`parseAssignments()`) regex-extracts the first
`{...}` block before decoding, so a chatty or malformed response fails just
that one batch (`failed_batches` in the run summary) instead of crashing the
whole pass; every returned label is matched case-insensitively against the
real subcategory list before being trusted, so a hallucinated name is
silently dropped rather than written as a tag. Idempotent by default — an
item already carrying a tag matching a current subcategory name is skipped
unless `--force`/the "wszystko ponownie" button is used — and new tags are
merged into an item's existing tags (`updateTags()` PUTs the whole array;
BookStack has no "append a tag" endpoint), never overwriting unrelated ones.
## Snipe-IT asset inventory integration
`App\Services\SnipeItClient` talks to a Snipe-IT instance's REST API
(`/api/v1/...`, bearer token auth), entirely `Settings`-driven like
`BookStackClient`: `snipeit_enabled`, `snipeit_base_url`,
`snipeit_api_token` (encrypted), `snipeit_verify_ssl`. Every call is wrapped
in `try/catch(\Throwable)` returning `[]`/`null` on failure, same
safe-default convention as `AiClient`/`BookStackClient`. Three independently
toggleable settings gate what a client/operator can actually do with it —
none of them affect `SnipeItClient` itself, only which Livewire methods are
willing to call it:
- `snipeit_client_can_select_asset` (+ `snipeit_client_asset_subcategory_ids`,
a comma-separated allow-list) — gates `Client\NewTicket`'s asset picker.
Mirrors BookStack's shelf allow-lists: an **empty** subcategory list means
the picker never shows for any subcategory, not "every subcategory" —
`NewTicket::snipeitAssets()` checks both the toggle and that the currently
selected `subcategoryId` is in the list before calling
`assetsForEmail()`. `selectCategory()`/`selectSubcategory()` reset any
already-picked asset, so switching to an out-of-scope subcategory can't
silently carry a stale selection through to `submit()`.
- `snipeit_operator_view_requester_assets` — gates the same
`assetsForEmail()` lookup (by the ticket's own `email`, not the viewing
operator's) in `Operator\TicketShow`'s sidebar.
- `snipeit_operator_search_inventory` — gates `searchAssets()`, a free-text
`/hardware?search=` lookup across the *whole* inventory, for linking
equipment the requester doesn't personally own (e.g. a shared printer).
Rendered inline in the same sidebar card as the requester-assets list, not
a separate route/page.
`Operator\TicketShow::linkSnipeitAsset(int $id)` deliberately does **not**
fall back to a direct `SnipeItClient::asset($id)` lookup by id — it only
accepts an id present in `snipeitRequesterAssets`/`snipeitSearchResults`,
and each of those is itself empty unless its own setting above is on. This
means an operator can't link an arbitrary asset through a source the admin
has switched off for them, even by tampering with the Livewire request
payload. `unlinkSnipeitAsset()` has no such gate — clearing an existing link
is a correction, not a new way to browse Snipe-IT, so it stays available
even with both toggles off.
`SnipeItClient::assetsForEmail()` has to resolve an e-mail to a Snipe-IT user
first (`GET /users?search=`, no "assets by e-mail" endpoint exists), then
lists what's checked out to them (`GET /users/{id}/assets`) — cached 5
minutes per e-mail. `normalizeAsset()` is the single place that turns a raw
Snipe-IT hardware row into the shape every caller/view uses (`id`, `label`,
`serial`, `manufacturer`, `model`, `category`, `status`, `url`); `label`
joins whichever of asset tag / serial / "manufacturer model" are actually
present with `" - "`, falling back to `Zasób #{id}` if all three are blank —
Snipe-IT doesn't guarantee any of them are filled in. The `x-snipeit-assets`
Blade component renders that shape everywhere an asset list shows up
(client picker, requester sidebar, search results), with a `card` prop that
skips its own wrapping `<div class="card">` when embedded inside a
caller-provided one (the inventory-search box + its results share one card).
A linked ticket only stores `tickets.snipeit_asset_id` + a cached
`snipeit_asset_name` label (`TicketService::setSnipeitAsset()`, which also
writes a ticket-history line) — no other Snipe-IT fields are persisted.
Anywhere a linked asset's live detail is shown (the "Powiązany sprzęt" card),
it's re-fetched fresh via `SnipeItClient::asset($id)` rather than trusted
from the cache, so a status/reassignment change made directly in Snipe-IT is
reflected immediately; the cached label is only ever the fallback shown when
that live fetch fails (instance unreachable, or the asset was deleted
there).
## AI ticket triage & summary
Two independent services, both consuming `AiClient` above, both run from a
single scheduled command (`ai:run-ticket-automation`) — **never
synchronously at ticket creation**, so an LLM call never adds latency to a
live customer submitting a ticket:
- **`App\Services\TicketAiTriageService`** — a one-shot classification pass
per ticket, gated by 5 independent toggles
(`ai_triage_category_when_missing`/`subcategory_when_category_only`/
`recheck_categorized`/`fix_subject`/`set_priority`). `buildPrompt()` picks
one of 3 mutually-exclusive category scenarios from the ticket's *current*
state (no category/subcategory at all → assign both; category but no
subcategory → pick one within it; already has a subcategory → recheck and
possibly correct), independently of the subject/priority toggles. Every
scanned ticket gets `tickets.ai_triaged_at` stamped exactly once — this is
a one-shot pass, not a continuous recheck, and there's deliberately no
manual per-ticket re-trigger. Resolution is fail-closed the same way as the
BookStack tagger: every value the model returns is matched against the
real category/subcategory/priority vocabulary before being trusted: a
hallucinated or out-of-scope value (e.g. a subcategory claimed under the
wrong category) is silently dropped. Applying changes goes through a new
`TicketService::applyAiTriage(Ticket $ticket, array $changes, array
$historyLines)` — a single `$ticket->update()` for whichever
category/subcategory/subject/priority fields actually changed, one
specific history line per changed field plus a final "Automatyzacja:
klasyfikacja AI" attribution line (mirrors how `RunAutomationRules` logs
its own SLA-automation changes), and `notify()`/`TriggerEngine::handle()`
fired only for the fields that actually changed — deliberately not
composed from the existing `setPriority()`/`updateDetails()` setters, since
one AI pass can touch several fields at once and those would each write
their own generic line and fire notifications per-field instead of once
per pass.
- **`App\Services\TicketAiSummaryService`** — a summary + suggested next
action for **every** ticket (gated by a single `ai_summary_enabled`
toggle), cached on `tickets.ai_summary`/`ai_suggested_action`/
`ai_summary_generated_at` and shown only in the operator ticket view (a
"Podsumowanie AI" sidebar card, lazy-loaded via `wire:init` like the
BookStack suggestions card next to it). `run()` (the scheduled sweep)
regenerates whenever a ticket's latest message postdates its last summary
— deliberately compared against `ticket_messages.created_at`, not
`tickets.updated_at` (which also changes on unrelated actions like a
status/priority edit, which would otherwise trigger spurious
re-summarization on every tick for an active ticket). `buildTranscript()`
includes the ticket's own `body` (the opening description, outside
`ticket_messages`) ahead of the message transcript — needed because that
row would otherwise fall outside `TRANSCRIPT_MESSAGE_LIMIT` (30) on any
thread longer than that, silently dropping the original request from the
prompt. Unlike the triage service, a malformed AI response here leaves the
previous summary untouched rather than stamping "done" — the ticket stays
in the "stale" set and gets retried next run, since this feature is meant
to keep refreshing indefinitely, not run once. The system prompt is
admin-editable (`ai_summary_prompt` setting, plain textarea with a
"Resetuj" button restoring `Settings::default('ai_summary_prompt')`
same pattern as the e-mail footer editor) and asks the model for a small
JSON object (`{"summary": "...", "suggested_action": "..."}`), parsed with
the same defensive regex-extract-then-decode approach used throughout
these AI services.
Besides `run()`'s scheduled sweep, two paths call `generateFor(Ticket
$ticket): bool` directly, bypassing the staleness check entirely:
`Operator\TicketShow::regenerateAiSummary()` (the sidebar's "Wygeneruj
teraz" button, a synchronous Livewire call — its `wire:loading` state covers
the wait, no need to dispatch anything in the background) and a
`TicketMessagePosted` listener registered in
`AppServiceProvider::regenerateAiSummaryOnNewMessage()`, active only when
both `ai_summary_enabled` and `ai_summary_regenerate_on_message` (off by
default) are on. That listener dispatches `App\Jobs\GenerateTicketAiSummaryJob`
via `::dispatchAfterResponse()` rather than the normal queue — deliberately
**not** `ShouldQueue`, since this deployment's queue worker is optional
infrastructure (see install.md) and anything pushed onto the `jobs` table
has no guarantee of ever being picked up; `dispatchAfterResponse()` instead
runs the job in-process right after the triggering HTTP/console response is
sent, needing no worker at all.
Its own interval (`ai:run-ticket-automation`) is admin-configurable the same
way the other 3 scheduled commands are — see "Configurable scheduled-command
intervals" above for the mechanism and a boot-time trap worth knowing about
before touching `routes/console.php` again.

View File

@@ -3,6 +3,398 @@
All notable changes to this project are documented in this file. Format loosely
follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
## [1.4.0] - 2026-08-05
### Added
- **Active Directory support for LDAP auth** (Admin > Integracje > "LDAP /
Active Directory") — a "Typ katalogu" dropdown switches between LLDAP/
OpenLDAP (the original, still the default) and Active Directory. AD uses a
different schema (no inetOrgPerson/posixAccount, a binary `objectGUID`
instead of `entryUUID`) and login attribute (`sAMAccountName`, not `uid`);
both are now auto-detected from the directory type instead of requiring
LLDAP's schema everywhere.
- **Operator client search** (Operator > Klienci) — a dedicated search page
(name or e-mail, any account, not just role=client) showing each match's
role badges and ticket count, linking straight into the queue pre-filtered
to that customer.
- **Paginated ticket lists** — the operator queue (50/page) and client
dashboard (20/page, current/archive tracked as separate pages so switching
tabs doesn't lose your place) no longer render every matching ticket at
once; sorting still happens over the full filtered result first.
- **Command-palette global search (Ctrl+K / Cmd+K)** — searches tickets from
anywhere in the app, scoped to what the searching user can actually see
(operators/admins search everything visible to them, clients only their
own). Supports Gmail-style operators — `od:` (reporter), `temat:`
(subject only), `treść:`/`tresc:` (message content only), `numer:`/`nr:`
(ticket number), combinable and AND'd together (`od:kacper
temat:drukarka`) — plain text with no operator still searches everything
as before. A "Szukaj" button in the operator/admin sidebars opens the same
dialog for anyone who doesn't know the shortcut.
- **Recently viewed tickets** (operator sidebar) — the last 6 tickets an
operator actually opened, most-recent first, re-bumped (not duplicated) on
a repeat visit.
- **Navbar redesign: panel switcher.** The old dropdown-only role switcher
(in the profile menu) and the plain "Panel Klienta/Operatora/Administratora"
text label are replaced by a single segmented control centered in the top
bar — Klient / Operator / Administrator — showing only the areas the
logged-in user actually holds, highlighting the current one, and sliding a
preview to whichever option is hovered before you click. Adapts to a
full-width row below the icons on narrow screens instead of overlapping
them.
- **Richer profile dropdown** — now shows the account's name, e-mail, and
role badges above the existing Powiadomienia/Wyloguj się links.
- **Per-page browser tab titles** — every page sets its own `<title>`
(e.g. the ticket subject, the selected queue, the active admin tab)
instead of every tab just showing the company name, always anchored with
the company name as a suffix so it's still identifiable once the browser
truncates a long tab title.
- **Hesk 3.x historical import** (`scripts/hesk-import/`) — a one-time,
read-only migration of tickets (with full reply/note history) from an old
Hesk helpdesk database, filtered by e-mail domain. Dry-run by default,
resumable, auto-maps categories (exact name match) and teams (when
unambiguous). See `scripts/hesk-import/README.md`.
### Fixed
- Pagination controls ("« Poprzednia" / "Następna »") were showing the raw
translation keys `pagination.previous`/`pagination.next` instead of
actual text — the app's `APP_LOCALE=pl` had no matching `lang/pl/`
translation file and no English fallback (`APP_FALLBACK_LOCALE` is also
`pl`), so Laravel had nothing to resolve those strings to.
## [1.3.0] - 2026-07-27
### Added
- **Snipe-IT asset inventory integration** (Admin > Integracje), optional and
off by default — connects to a Snipe-IT instance by API address + personal
API token (plus a "Nie sprawdzaj SSL" toggle for self-signed instances) and
surfaces three independently switchable capabilities:
- **Klient może wybrać sprzęt, którego dotyczy zgłoszenie** — while
creating a ticket, a client sees the devices checked out to them in
Snipe-IT (matched by e-mail) and can pick the one the ticket is about.
Scoped to admin-selected subcategories via a multi-select picker that
only appears once this is turned on — same "nothing shows until
explicitly opted in" convention as BookStack's shelf allow-lists.
- **Operator może zobaczyć sprzęt zgłaszającego w widoku zgłoszenia** — the
same per-requester asset list, shown in a sidebar card on the ticket
view, with a "Powiąż" button per item.
- **Zezwól operatorowi na przeszukiwanie całego inwentarza** — a search
box + button in the same sidebar (not a separate page) letting an
operator link any asset in Snipe-IT, not just the requester's own — for
shared equipment like printers.
- A linked asset shows live status/category/current assignment (fetched
fresh from Snipe-IT, not just the cached label) with an "Odepnij" button
that stays available to the operator regardless of the two toggles above
— clearing an existing link is a correction, not new Snipe-IT access.
Every asset is displayed as "numer środka - numer seryjny - producent
model" plus its Snipe-IT category, joining whichever of those pieces are
actually present.
- **AI summary: manual regenerate + regenerate on new message.** A
"Wygeneruj teraz" button now sits on the operator's "Podsumowanie AI" card
for an immediate, on-demand refresh. Separately, a new admin toggle
("Regeneruj podsumowanie od razu po każdej nowej wiadomości", off by
default) re-runs the summary right after any reply/note lands on a ticket,
instead of only ever picking it up on the next scheduled
`ai:run-ticket-automation` sweep. The transcript sent to the model now also
includes the ticket's own opening body text (previously only the reply
thread), fixing summaries silently missing the original request on long
tickets whose first message had scrolled out of the transcript window.
### Fixed
- The status dropdown in the operator ticket view could keep showing the
pre-change status after sending a reply via a status-changing quick action
(e.g. "Wyślij i oznacz jako rozwiązane") until the next full page load — a
Livewire/Alpine-morph quirk for `<select>` elements bound via `wire:change`
rather than `wire:model`. Fixed by keying the element to the status value
so the DOM node is force-replaced instead of morphed.
## [1.2.2] - 2026-07-24
### Added
- Subcategories can now be reordered within their category — up/down arrow
buttons next to "Edytuj" in Admin > Kategorie, right beside each
subcategory's edit/delete buttons. The order set there is used everywhere a
subcategory list is shown (subcategory pickers, admin listings, etc.), not
just the admin panel itself.
## [1.2.1] - 2026-07-24
### Added
- **Generic AI integration** (Admin > Integracje > "Integracja AI"), optional
and off by default — an OpenAI-compatible `/chat/completions` client (works
against Groq, OpenAI itself, or a self-hosted Ollama instance) configured by
base URL, optional API key, model name, and an SSL-verification toggle for
self-signed local endpoints. Not tied to any one feature — it's the shared
foundation for the two AI-driven features below, and for anything else that
wants an LLM call in the future.
- **BookStack automatic content tagging (AI)** — a "Otaguj nową treść"/"Otaguj
wszystko ponownie (force)" button pair in the BookStack card, plus
`php artisan bookstack:tag-content` (`--dry-run`/`--force`/`--limit=N`) for
the command line. Uses the AI integration above to classify every
book/chapter/page's title+content against the current list of helpdesk
subcategories and tags matching ones by name — idempotent by default
(skips already-tagged content), so re-running after adding a few pages is
cheap. This is what gives the BookStack "search by tags" option below
something to actually match against.
- **BookStack search refinement** — "Przeszukuj" is now three independent
checkboxes (Książki / Strony / Rozdziały) instead of a single dropdown with
no chapter option, plus a new "Szukaj po" setting: słowa kluczowe w nazwie /
tagi / oba. Tag matching uses the bare subcategory name (e.g. "Drukarki i
skanery"), matching what the auto-tagging feature above writes.
- **AI-driven ticket triage + summary** (Admin > Integracje >
"Automatyzacja AI dla zgłoszeń", runs via a new scheduled
`ai:run-ticket-automation`) — five independent toggles: assign a
category/subcategory when a ticket has neither, pick a subcategory when it
only has a category, recheck and possibly correct an already-categorized
ticket, rewrite an unclear subject, and set a priority based on content.
Runs once per ticket in the background (never synchronously at submission,
so it adds no latency for a client), and every applied change leaves a
specific line plus a "Automatyzacja: klasyfikacja AI" entry in the ticket's
history, same convention as the existing SLA automation rules. Separately,
an AI-generated summary + suggested next action for **every** ticket, shown
only to operators in a new "Podsumowanie AI" sidebar card, refreshed
whenever the thread gets a new message — its system prompt is admin-editable
as a plain-text field with a "Resetuj" button back to the shipped default.
- Operators can now reassign a ticket to **any** team, not just one they
belong to (previously the dropdown only ever offered the operator's own
teams).
- The auto-refresh countdown badges (ticket view, operator queue) are now
**clickable** — fetch immediately and reset the countdown, instead of only
ever refreshing on their own fixed schedule.
- **All 7 "cyclical" intervals** in the app are now configurable from
Admin > Konfiguracja instead of fixed in code: the 3 browser auto-refresh
countdowns (ticket view, operator queue), the notification bell's poll,
and the 4 background scheduled commands (SLA breach check, SLA automation
rules, IMAP fetch, AI ticket automation). Defaults match the previous
hardcoded values, so nothing changes until an admin edits them.
### Fixed
- An operator viewing a ticket that gets deleted by someone else, or whose
team changes to one outside the operator's own scope (including via their
own reassignment above), is now redirected back to the operator queue
instead of hitting an error mid-session.
## [1.2.0] - 2026-07-23
### Added
- **E-mail intake (IMAP)**, optional and off by default — clients can create a
ticket or reply to an existing one just by sending/replying to an e-mail.
Configure any number of mailboxes in the new **Admin > Poczta** page (which
now hosts SMTP alongside IMAP, replacing the old "E-MAIL" tab), each with
its own host/port/encryption/credentials/folder and routed to either a
specific subcategory (routes to that subcategory's team, same as a web
ticket) or a whole category with no subcategory (a new `tickets.category_id`
column covers this case — previously a ticket's category only ever came
through a subcategory).
- A reply is matched back to its ticket via the number/checksum already
present in every notification e-mail's subject — works with either the
plain sequential number or the obfuscated checksum, whichever numbering
mode is active, no changes to outbound templates needed.
- Automatic replies (autoresponders, "out of office", bounces/mailer-daemon)
are detected via headers and common EN/PL subject phrasing and rejected
instead of creating a ticket; a per-mailbox sender blocklist covers the
rest. The "tylko użytkownicy z LDAP" restriction is enforced for e-mail
exactly like the guest web form.
- A "Pobierz teraz" button per mailbox fetches immediately, outside the
5-minute schedule — useful for testing a freshly-configured mailbox or
diagnosing why a specific e-mail didn't turn into a ticket.
- Every connection attempt and per-message decision (accepted/rejected/
matched to which ticket) is logged to a dedicated `storage/logs/imap-*.log`
file, independent of the app's own log level.
- Tickets and individual messages that came in by e-mail show a small
mail-icon badge in the operator queue and ticket view, distinguishing them
from ones created/replied to on the web.
- **Operator queue**: a "select all" checkbox in the table header
selects/deselects every ticket currently visible under the active
filter/tab in one click, instead of clicking each row's checkbox.
### Changed
- Admin's old **"E-MAIL"** tab is now **"Poczta"** and also lists/manages the
IMAP mailboxes above — the two halves of "reply by e-mail" (send/receive)
now live together instead of SMTP being off on its own.
### Fixed
- **Scheduled-command notifications were silently going nowhere.**
`AppServiceProvider`'s Settings-based config override (SMTP/LDAP/session/
timezone) used to skip itself for *any* console command, not just
`migrate` — meaning `tickets:check-sla-breaches` and `automation:run-rules`
(and now `emails:fetch-imap`) always sent their e-mails through whatever
`.env`'s `MAIL_MAILER` happened to be (`log`, i.e. nowhere) instead of the
admin-configured SMTP server, with no visible error. Now scoped to just the
`migrate` command family, so every scheduled command gets the same live
config a web request would.
- Visiting a ticket that no longer exists (most commonly: it was deleted
while the viewer had it open, and a later background refresh hit the same
URL) no longer shows Laravel's default 404 page — redirects back to the
operator queue or client dashboard instead.
- This host had no crontab entry at all for `php artisan schedule:run`
meaning SLA breach checks and automation rules had never actually run on
their own, only ever on request. Documented and configured (see
[CLAUDE.md](CLAUDE.md)).
## [1.1.4] - 2026-07-23
### Added
- **Configurable ticket numbering** (Admin > Konfiguracja > Ogólne) — an
admin-set prefix (default `#`) and a minimum zero-padded length for the
ticket number.
- **"Ukryj kolejność zgłoszeń"** — an opt-in mode that displays a stable,
HMAC-derived checksum instead of the sequential ticket number, so the
number shown gives no indication of ticket volume or creation order. Every
ticket gets its checksum assigned once, on creation, guaranteed unique.
When this mode is on, ticket URLs switch to the same checksum too (custom
`Ticket::getRouteKey()`/`resolveRouteBinding()`), so a link and the number
on the page it points to always match — and a URL built under the other
mode stops resolving. The REST API is unaffected; it's pinned to `id`
regardless of this setting. Search (queue/dashboard) now also matches
against the checksum. A live preview against a real ticket from the
database shows exactly how the number will look before saving.
### Changed
- **Attachments**: dropped the inline image thumbnail preview in the message
thread — every attachment (images included) now shows as just its
filename, opening in a new tab on click, consistent with how non-image
attachments already worked.
## [1.1.3] - 2026-07-22
### Added
- **Triggers** (Admin > Wyzwalacze) — event-driven business rules that fire
immediately on a ticket lifecycle event (created, any field updated, status/
priority/assignee/team/category changed, new public reply). AND-combined
conditions gate a sequence of ordered actions (set status/priority/team/
assignee, or send an e-mail). Ships with its own dedicated, freely
add/edit/delete-able trigger e-mail templates — kept separate from the
fixed, per-event system templates, which stay exactly as fixed as before.
Complements the time-based SLA automation rules rather than replacing them,
guarded against runaway loops (a depth limit plus a same-value no-op check).
- **Ticket watching** — operators can star/"Obserwuj" any ticket to follow it
regardless of assignment or team.
- **Real-time notification bell** — the bell now updates the instant a
notification is created (broadcast on a new private per-user channel),
with the existing 30s poll kept as a fallback for a dropped websocket.
Optionally also raises a native in-tab browser push notification.
- **Per-user notification preferences** (`/settings/notifications`) — each
operator/admin chooses, per event category (new ticket, ticket update,
escalation), which scope of tickets (mine, unassigned, watched, all)
notifies them via the bell and whether that also sends an e-mail, plus an
opt-in toggle for the browser push notifications above.
- **Admin > Integracje** — new tab hosting LDAP/AD and BookStack
configuration, split out of Konfiguracja so that tab is just general
system settings (attachments, session, timezone).
- Operator queue: three more optional columns (off by default, toggle via
"Kolumny") — Podkategoria, Zespół, Utworzono.
### Changed
- The "Obserwuj" button on the operator ticket view moved next to the
auto-refresh countdown badge, both now grouped on the right.
- `/settings/notifications`: added a "← Wróć" link back to the operator/admin
area, the browser-push card now spans the full page width, and the
preferences table sits in a bordered card like the rest of the app.
- Trigger conditions on Podkategoria/Zgłaszający now show a name dropdown
instead of a raw ID field.
- The admin panel's active tab and the operator queue's active view now
persist across a plain page refresh (bound to the URL query string), so
reloading no longer bounces back to the first tab.
## [1.1.2] - 2026-07-22
### Added
- **Real-time updates (Laravel Reverb)** — the operator ticket queue now
updates live: new tickets appear, status/priority/team/assignee changes
and new replies re-sort/refresh the affected row, and closed/deleted/
reassigned-away tickets disappear, all without a manual refresh. The
ticket message thread is now "live chat": a reply from either side
appears for the other party instantly. Clients also see status/priority/
team/assignee changes and new history entries on their own ticket live.
Backed by two private channels (`operator.queue`, `ticket.{id}`) and two
broadcast events (`TicketQueueChanged`, `TicketMessagePosted`), sent
synchronously (no queue worker needed, consistent with how e-mail
notifications already work in this app).
- **Periodic fallback refresh** — since a websocket connection can drop
silently (backgrounded tab, network blip), the operator queue and both
ticket-detail views also poll themselves every 3060 seconds regardless
of broadcasting, with a small visible countdown badge so it's clear the
page is still refreshing on its own.
- **SLA automation rules** (Admin > Automatyzacja SLA) — configurable rules
that act on a ticket after N minutes of customer silence (optionally
scoped to a priority/category/team): change priority, status, team, or
assignee. Reuses the same `TicketService` setters a manual operator
action would, so automated changes get the same history entry,
notification, and (now) live broadcast as a human doing it. A new
scheduled command (`automation:run-rules`, every 15 minutes) evaluates
all enabled rules; each rule only fires once per ticket until a fresh
reply or a close/reopen resets it.
- **New notification: ticket landed in your team** — every operator on a
team whose subcategories match a newly created ticket now gets notified
(enabled by default; toggle like any other trigger in Admin > Szablony
e-mail).
- **BookStack knowledge-base sidebar on the client's own ticket view** —
previously only shown to operators; clients now see the same
category/subcategory-matched suggestions on their ticket page that they
saw while creating it.
- **Operator ticket view / client ticket view now show the assigned
operator and team** in the "Status i priorytet" card (client side).
- **Stats dashboard**: new breakdowns — tickets by subcategory, CSAT
average by team and by operator, top 10 clients by ticket volume (+ one
"Goście" bucket for guest submissions), and a client × subcategory
cross-tab (top 10 clients × top 5 subcategories, rest folded into
"Inne"). The whole dashboard is now organized into labeled sections
(Podsumowanie / Rozkład zgłoszeń / Obciążenie / Klienci / Ocena obsługi /
Trend) instead of one flat wall of cards.
### Changed
- BookStack suggestions (ticket-creation wizards, guest landing page,
operator/client ticket views) now load in a beat after the page's first
paint (`wire:init`) instead of blocking the initial render on BookStack's
API response.
- The notification bell shows **unread notifications only** — reading one
(by clicking it or "mark all as read") now removes it from the list
instead of just dimming it.
- The client ticket-view page is now the same width as the operator's
(1180px, up from 920px) — the main message-thread column is unaffected.
- Mobile: the theme/notifications/profile-menu dropdowns in the top nav
now expand to the full screen width below 640px instead of a fixed
narrow width that could overflow off-screen.
### Fixed
- Two bugs that silently disabled all real-time updates from the moment
Reverb was first wired in: (1) the Echo client never sent a CSRF token
when authorizing private channels, so every subscription attempt was
rejected by the app's own CSRF middleware; (2) the Echo setup script
(loaded as a deferred ES module) raced against Livewire's own
synchronously-loaded bootstrap script and could miss the `livewire:init`
event entirely, silently skipping the operator-queue subscription.
- The `mariadb` container's healthcheck was failing (`Access denied ...
using password: NO`) because its auto-generated credentials file had
world-writable permissions (an artifact of this stack's NFS-backed bind
mount) and MariaDB's client refuses to read credentials from a file
anyone can modify — the healthcheck now passes.
- Several pre-existing test-suite gaps found while working in this area:
`User::roles` (a virtual attribute backed by the `roles`/`role_user`
pivot, not a plain column) needs the `roles` table seeded before
assigning a role by key — now seeded automatically for every test in
`Tests\TestCase`. A handful of other tests were missing
`NotificationSetting`/`ReplyQuickAction` seed data, asserting a stale set
of default-enabled notification triggers, or using the wrong Notification
Fake assertion for a real (non-guest) recipient.
## [1.1.0] - 2026-07-22
### Added

View File

@@ -21,7 +21,12 @@ roles). Treat the running database as production, not a sandbox:
## Container operations: use `sudo`, never build the image locally
All Docker commands against this stack need `sudo` (e.g.
`sudo docker compose exec servicedesk ...`, `sudo docker exec servicedesk-servicedesk-1 ...`).
`sudo docker compose exec app ...`, `sudo docker exec servicedesk-app-1 ...`).
The stack is four services sharing the one `servicedesk` image — `app` (Apache,
what actually serves HTTP), `reverb` (websocket server, `php artisan
reverb:start`), `cron` (scheduler loop, `php artisan schedule:work` — see
below), and `mariadb`. Only `app` and `reverb` are reachable from Traefik.
**Never run `docker build`, `docker compose build`, or `--build`.** The
`servicedesk` image is built by CI (`.gitea/workflows/build.yml`, triggered on
@@ -29,7 +34,7 @@ All Docker commands against this stack need `sudo` (e.g.
`compose.yaml` only ever `pull`s a tag (`sudo docker compose pull && sudo docker
compose up -d`, see [install.md](install.md) 1.3/1.3a) — building locally would
just diverge from what CI produces. The app container
(`servicedesk-servicedesk-1`) mounts `./src` from the host over NFS
(`servicedesk-app-1`) mounts `./src` from the host over NFS
(`/mnt/rabbit-containers` → NFS export), so plain file edits already take effect
with no rebuild or restart:
@@ -56,10 +61,50 @@ with no rebuild or restart:
surfaces in production as a 500 with `touch(): Utime failed: Operation not
permitted`. If you ran `php artisan test`/`tinker`/any artisan command via
`docker exec` in a session where you also edited Blade files afterward,
finish with `sudo docker exec servicedesk-servicedesk-1 php artisan
finish with `sudo docker exec servicedesk-app-1 php artisan
view:clear` to flush any root-owned compiled views before ending the
session — don't wait for a report of a broken page to catch it.
## Scheduled commands run in the dedicated `cron` container
The Docker image ships no cron/supervisor of its own (see [install.md](install.md)),
so `tickets:check-sla-breaches`, `automation:run-rules`, `emails:fetch-imap`,
and `ai:run-ticket-automation` (all registered in `routes/console.php` via
`Schedule::command(...)`) only ever run if something calls `php artisan
schedule:run` on a timer. **As of 2026-08-04 this is the `cron` service** in
`compose.yaml` — same `servicedesk` image, running `php artisan schedule:work`
(Laravel's own foreground scheduler loop, ticks every minute internally, no
external trigger needed). Before this it was a root crontab entry on the host
calling `docker compose exec -T servicedesk schedule:run`; that entry has been
removed from `sudo crontab -l -u root` now that the container replaces it —
don't re-add it, the two would double-run every scheduled command.
If the `cron` container isn't running (`sudo docker compose ps cron`), none of
the four scheduled commands fire — same failure mode as the old missing-crontab
case, just check the container instead of the crontab. IMAP-specific activity
(connect attempts, per-message accept/reject decisions, created/replied ticket
ids) is logged separately from the app's normal `LOG_LEVEL` to
`storage/logs/imap-*.log` (see the `imap` channel in `config/logging.php`) —
check there first when a mailbox isn't behaving as expected, before assuming
the scheduler itself isn't firing.
All four commands' intervals are admin-configurable (Admin > Konfiguracja —
`schedule_sla_check_minutes`/`schedule_automation_rules_minutes`/
`schedule_imap_fetch_minutes`/`schedule_ai_automation_minutes`), which is why
`routes/console.php` registers them as `->everyMinute()->when(fn () =>
Settings::dueEveryMinutes(...))` instead of a plain `->everyFifteenMinutes()`/
`->cron(...)` call — **never build a cron expression (or otherwise read
`Settings`) at that file's top level**. `routes/console.php` is `require`'d on
every artisan boot (`migrate`, `tinker`, `php artisan test`, not just
`schedule:run` — it's wired in via `bootstrap/app.php`'s `commands:` key), so
a top-level `Settings::get(...)` call runs before a fresh/test database
necessarily has the `settings` table, and crashes every single artisan
invocation, not just the scheduler. A `->when($closure)` guard is the fix —
the closure is only ever evaluated later, when `schedule:run` processes due
events. One visible side effect: `php artisan schedule:list` shows
`* * * * *` for all four regardless of the actual configured interval, since
that only exists inside the closure — expected, not a bug worth chasing.
## Apache `/icons/` alias trap
The stock `php:apache` image enables `mods-enabled/alias.conf`, which defines

View File

@@ -16,11 +16,11 @@ build through a throwaway `node:22` container as documented there.
1. **Run the test suite** — see [TESTING.md](TESTING.md) for details:
```bash
docker compose exec servicedesk php artisan test
docker compose exec app php artisan test
```
2. **Run Pint** (Laravel's code-style fixer, default preset, no project overrides):
```bash
docker compose exec servicedesk ./vendor/bin/pint
docker compose exec app ./vendor/bin/pint
```
3. If you changed anything under `resources/`, rebuild the frontend bundle and
commit the result if `public/build/` is tracked, or confirm the deploy step

View File

@@ -8,7 +8,7 @@ RUN apt-get update && apt-get install -y \
unzip \
git \
libldap2-dev \
&& docker-php-ext-install curl mysqli pdo pdo_mysql ldap zip
&& docker-php-ext-install curl mysqli pdo pdo_mysql ldap zip pcntl posix
# Kopiowanie Composera z oficjalnego obrazu
COPY --from=composer:latest /usr/bin/composer /usr/bin/composer

209
README.md
View File

@@ -13,7 +13,7 @@ The app has three areas, gated by role (a user can hold more than one at once):
|---|---|---|---|
| Client | `/client` | `client` | Submit tickets, track status, reply, see resolution |
| Operator | `/operator` | `operator` | Work the ticket queue, reply/resolve, see team statistics |
| Admin | `/admin` | `admin` | Configure categories, users, teams, SLA, templates, branding, LDAP/SMTP |
| Admin | `/admin` | `admin` | Configure categories, users, teams, SLA, templates, triggers, branding, LDAP/SMTP/BookStack |
Every account gets the `client` role by default (see `AssignDefaultRole` for LDAP-provisioned
accounts), and always lands on `/client` first after login regardless of what other
@@ -23,33 +23,91 @@ and **[wiki/admin](wiki/admin/README.md)** for role-specific how-to guides.
## Feature overview
- **Navigation** — a segmented Klient/Operator/Administrator switcher in the
top bar (only the areas a user actually holds, current one highlighted,
hover-previews the destination before you click) replaces the old dropdown
role switcher; the profile menu shows name/e-mail/role badges above
Powiadomienia/Wyloguj się; every page sets its own browser-tab title
(ticket subject, selected queue, active admin tab, ...) anchored with the
company name; and a command-palette global search (Ctrl+K/Cmd+K, or a
"Szukaj" sidebar button) finds tickets from anywhere, scoped to what the
searching user can see, with Gmail-style `od:`/`temat:`/`treść:`/`numer:`
operators. The operator sidebar also lists the last 6 tickets they
actually opened ("Ostatnio przeglądane").
- **Tickets** — number, subject, body, category/subcategory, status, priority, team,
assignee, custom fields (per subcategory), attachments, full message thread
(public replies + internal notes), history log, merge, delete.
(public replies + internal notes), history log, merge, delete. The operator
queue (50/page) and client dashboard (20/page, current/archive tracked
separately) paginate rather than rendering every matching ticket at once.
- **SLA** — per-priority response/resolution time targets; a scheduled command
(`tickets:check-sla-breaches`, every 15 min) flags overdue tickets and can notify
the assigned operator.
- **SLA automation rules** (Admin > Automatyzacja SLA) — configurable rules that
change a ticket's priority/status/team/assignee after N minutes of customer
silence (optionally scoped to a priority/category/team), evaluated every 15
minutes (`automation:run-rules`). Reuses the same `TicketService` setters a
manual operator action would, so an automated change gets the same history
entry, notification, and live broadcast as a human doing it; each rule fires
once per ticket until a fresh customer reply or a close/reopen resets it.
- **Real-time updates** — the operator ticket queue and both ticket-detail views
(operator and client) update live over WebSockets (Laravel Reverb): new
tickets, status/priority/team/assignee changes, and new replies ("live chat")
all show up without a manual refresh. A periodic fallback refresh (with a
visible, clickable countdown badge — click it to fetch immediately and reset
the countdown) covers a dropped websocket connection. All of the refresh/poll
intervals in the app, browser-side and the background scheduled commands
alike, are configurable from Admin > Konfiguracja (see below).
- **Categories & custom fields** — admin-defined categories/subcategories, each with
its own set of custom fields (text/textarea/select/checkbox/date/number) and an
optional default priority.
optional default priority. Subcategories within a category can be reordered with
up/down arrows in Admin > Kategorie; the order set there is what clients/operators
see everywhere a subcategory picker is shown.
- **Teams** — subcategories auto-route to a team; operators only see their own
team's queue (plus unrouted tickets and anything assigned to them) unless they're
an admin.
an admin. Reassigning a ticket to a team, though, is unrestricted — an operator
can route a ticket to any team, not just one they belong to.
- **Client search** (Operator > Klienci) — find any account by name or e-mail
(not just role=client — a ticket's customer can be any user), see its role
badges and ticket count, and jump straight into the queue pre-filtered to
that customer.
- **Templates** — canned response snippets for the reply box, admin-configurable
"quick actions" (send + transition status in one click), and HTML e-mail
templates for every ticket lifecycle event (created, status/priority/category/
team changed, closed, operator replied, SLA breached), each independently
enable/disable-able.
- **Operator statistics** (`/operator/stats`) — filterable dashboard (date range,
team, priority, category, assignee) with KPI tiles (volume, SLA breach rate,
average first-response/resolution time) and breakdowns by status, priority,
category, team and operator workload, plus a daily created-vs-closed trend.
team, priority, category, assignee) organized into sections: KPI tiles (volume,
SLA breach rate, average first-response/resolution time, CSAT); breakdowns by
status, priority, category and subcategory; team/operator workload; top 10
clients by ticket volume plus a client × subcategory cross-tab (top 5
subcategories, rest folded into "Inne"); CSAT average by team and by operator;
and a daily created-vs-closed trend.
- **Branding & config** — company name/logo/favicon/accent color, login notice,
e-mail layout/footer, LDAP connection + user sync, SMTP connection, attachment
limits, session lifetime, timezone — all editable from Admin > Konfiguracja.
- **LDAP auth** — logins bind against an LDAP/LLDAP directory (`config/auth.php`,
e-mail layout/footer, SMTP connection (Admin > E-MAIL), attachment limits,
session lifetime, timezone (Admin > Konfiguracja), and LDAP connection + user
sync + BookStack (Admin > Integracje).
- **LDAP auth** — logins bind against a directory (`config/auth.php`,
`config/ldap.php`); local accounts (e.g. the emergency `admin` account) fall back
to e-mail + local password when the LDAP bind doesn't match.
to e-mail + local password when the LDAP bind doesn't match. A "Typ katalogu"
toggle (Admin > Integracje) switches between LLDAP/OpenLDAP (default) and
Active Directory, which auto-selects the right schema/login attribute
(`sAMAccountName` + `objectGUID` for AD, vs. `uid` + `entryUUID`).
- **Triggers** (Admin > Wyzwalacze) — event-driven business rules that fire
immediately on a ticket lifecycle event (created, any field updated, status/
priority/assignee/team/category changed, new public reply): AND-combined
conditions gate a sequence of actions (set status/priority/team/assignee, or
send an e-mail using a dedicated set of freely add/edit/delete-able trigger
e-mail templates, kept separate from the fixed per-event system templates).
Complements the time-based SLA automation rules above rather than replacing
them.
- **Ticket watching** — operators can star/"Obserwuj" any ticket to follow it
regardless of assignment/team, which feeds the "Obserwowane zgłoszenia" scope
in their notification preferences.
- **Per-user notification preferences** (`/settings/notifications`) — each
operator/admin chooses, per event category (new ticket, ticket update,
escalation), which scope of tickets (mine, unassigned, watched, all) notifies
them via the in-app bell, and whether that also sends an e-mail; plus an
opt-in toggle for native in-tab browser push notifications.
- **REST API** (`/api/v1/...`, Sanctum token auth, ability-scoped: `tickets:read`,
`tickets:write`, `dictionaries:read`, `users:read`) for tickets/messages/users/
categories/statuses/priorities/teams — issued via admin-managed API clients.
@@ -57,9 +115,34 @@ and **[wiki/admin](wiki/admin/README.md)** for role-specific how-to guides.
- **PWA** — installable manifest + icons for the client-facing area.
- **In-app notifications** — a bell in the top bar (client/operator/admin areas)
backed by Laravel's database notification channel, alongside the existing
e-mail notifications (same per-trigger enable toggle drives both).
- **Attachments** — drag-and-drop upload (in addition to the file picker) and
inline image thumbnails in the message thread instead of a plain download link.
e-mail notifications (same per-trigger enable toggle drives both); shows
unread notifications only — reading one removes it from the list. Updates
live over WebSockets the moment a notification is created (with a 30s
fallback poll), and can optionally raise a native browser push notification
while the tab is open (see per-user notification preferences above).
Includes a dedicated trigger notifying every operator on a team whose
subcategories match a newly created ticket.
- **Attachments** — drag-and-drop upload (in addition to the file picker); every
attachment shows in the message thread as just its filename, opening in a new
tab on click (no inline image preview).
- **E-mail intake (IMAP)** *(optional, off by default)* — clients can create
tickets or reply to an existing one just by sending/replying to an e-mail;
configure any number of mailboxes in Admin > Poczta (e.g. one address per
team), each routed to a specific subcategory or a whole category. A reply
is matched back to its ticket via the number/checksum already present in
every notification's subject; automatic replies (autoresponders, bounces)
are detected and rejected instead of creating junk tickets, and the
"restrict tickets to LDAP" setting is enforced for e-mail exactly like the
guest web form. A manual "Pobierz teraz" button fetches immediately
outside the 5-minute schedule; all activity is logged separately to
`storage/logs/imap-*.log`. Tickets/messages that came in by e-mail show a
small mail-icon badge in the operator queue and ticket view.
- **Configurable ticket numbering** (Admin > Konfiguracja) — a custom prefix and
minimum zero-padded length for the ticket number, plus an optional "hide
ticket order" mode that displays a stable per-ticket checksum instead of the
sequential number. When enabled, ticket URLs switch to the same checksum too,
so the number in the link always matches the one on the page; the REST API is
unaffected and always addresses tickets by `id`.
- **Customer satisfaction (CSAT)** — clients rate a ticket 15 stars (+ optional
comment) once it's closed; average/response-rate surfaced as a KPI on the
operator stats dashboard, with a link in the "ticket closed" e-mail.
@@ -73,29 +156,81 @@ and **[wiki/admin](wiki/admin/README.md)** for role-specific how-to guides.
- **BookStack knowledge-base integration** *(optional, off by default)*
suggests relevant BookStack articles by category/subcategory while a ticket
is being created, and in a separate sidebar panel on an existing ticket for
operators (with a copy-link button). Configured entirely from Admin >
Konfiguracja: connection + API token, optional SSL-verification bypass for
self-signed instances, page/book search-type filter, and two independent
per-shelf allow-lists (nothing is searched until an admin opts specific
shelves in, separately for ticket-creation suggestions vs. the operator
sidebar).
both operators and clients (with a copy-link button for operators). Loads in
after the page's first paint rather than blocking it. Configured entirely
from Admin > Integracje: connection + API token, optional SSL-verification
bypass for self-signed instances, a content-type filter (books/pages/
chapters, independently toggleable) and a "search by" mode (name / tags /
both), and two independent per-shelf allow-lists (nothing is searched until
an admin opts specific shelves in, separately for ticket-creation
suggestions vs. the operator/client ticket-view sidebar). A pair of
"Otaguj nową treść"/"Otaguj wszystko ponownie" buttons (also available as
`php artisan bookstack:tag-content`) use the AI integration below to
auto-tag every book/chapter/page with matching subcategory names, so the
tag-based search mode has something to find.
- **Generic AI integration** (Admin > Integracje > "Integracja AI") *(optional,
off by default)* — an OpenAI-compatible chat-completions client (Groq,
OpenAI, or a self-hosted Ollama instance) configured by base URL, optional
API key, model, and an SSL-verification toggle. Not tied to a single
feature — it backs the BookStack auto-tagging above and the AI ticket
triage/summary below, and is meant to be reused by anything that needs an
LLM call in the future.
- **AI-driven ticket triage + summary** (Admin > Integracje >
"Automatyzacja AI dla zgłoszeń") *(optional, off by default, requires the AI
integration above)* — five independent toggles run once per new ticket, in
the background (`ai:run-ticket-automation`, never synchronously at
submission): assign a category/subcategory when missing, pick a
subcategory when only a category is set, recheck/correct an
already-categorized ticket, rewrite an unclear subject, and set a priority
from the ticket's content. Every applied change is logged in the ticket's
history. Separately, an AI-generated summary + suggested next action for
every ticket, shown to operators only in a "Podsumowanie AI" sidebar card
with a manual "Wygeneruj teraz" button, an admin-editable prompt
(reset-to-default button included), and a per-transcript excerpt of the
ticket's own opening body alongside the reply thread (so long tickets
don't lose the original request once it scrolls out of the message
window). Refreshed by the same periodic sweep by default; an optional
admin toggle regenerates it immediately after every new reply/note
instead of waiting for the next scheduled run.
- **Snipe-IT asset inventory integration** *(optional, off by default)*
connects to a Snipe-IT instance (API address + personal API token, plus an
SSL-verification bypass for self-signed instances) and adds three
independently toggleable capabilities from Admin > Integracje: a client
can pick which of their own Snipe-IT assets a ticket concerns while
creating it (scoped to admin-selected subcategories, empty selection means
it never shows — same convention as BookStack's shelf allow-lists), an
operator sees the requester's own assets in a ticket-view sidebar card,
and an operator can search the entire Snipe-IT inventory from that same
sidebar (not a separate page) to link shared equipment the requester isn't
the current owner of. Every asset is shown as "numer środka - numer
seryjny - producent model" plus its Snipe-IT category; a linked asset's
live status/assignment is fetched fresh on the ticket page, and unlinking
stays available to an operator even if both view/search toggles are later
turned off.
## Tech stack
- **Backend**: Laravel, Livewire (server-driven UI, no SPA build beyond Tailwind/Vite
for CSS), LdapRecord for directory auth, Sanctum for API tokens, L5-Swagger for
API docs.
API docs, Laravel Reverb for WebSocket broadcasting (real-time queue/chat
updates — see [ARCHITECTURE.md](ARCHITECTURE.md)), webklex/php-imap for the
optional e-mail intake fetcher (pure-PHP IMAP client, no `ext-imap` needed).
- **Frontend**: Blade + Livewire + a little Alpine.js for local UI state; Tailwind
v4 via Vite for `resources/css/app.css`. No JS charting library — the statistics
v4 via Vite for `resources/css/app.css`; Laravel Echo + Pusher-protocol client
(`resources/js/echo.js`) for Reverb. No JS charting library — the statistics
dashboard is hand-rolled inline-styled bar/column charts, so it needs no client
build step beyond the CSS bundle.
- **Database**: MariaDB.
- **Deployment**: `compose.yaml``servicedesk` (source bind-mounted from `./src`,
no image rebuild needed for PHP/Blade/route changes) + `mariadb`, fronted by
Traefik with a private-CA TLS cert. The `servicedesk` image itself is built and
pushed by Gitea Actions (`.gitea/workflows/build.yml`) to the Gitea container
registry whenever `Dockerfile` changes — `compose.yaml` just pulls a tag, it
never builds locally.
- **Deployment**: `compose.yaml``app` (source bind-mounted from `./src`,
no image rebuild needed for PHP/Blade/route changes) + `mariadb` + `reverb`
(same image, `php artisan reverb:start`) + `cron` (same image, `php artisan
schedule:work` — runs the scheduled commands below without needing a host
crontab), fronted by Traefik with a private-CA TLS cert (the websocket path
is routed to `reverb` by a higher-priority Traefik rule; everything else
goes to `app`). The `servicedesk` image
itself is built and pushed by Gitea Actions (`.gitea/workflows/build.yml`) to
the Gitea container registry whenever `Dockerfile` changes — `compose.yaml`
just pulls a tag, it never builds locally.
See **[install.md](install.md)** for full step-by-step deployment instructions —
both via Docker Compose (this stack) and directly on a server with Apache/Nginx,
@@ -114,7 +249,7 @@ Compose-level and Laravel-level) and the LDAP/SMTP gotcha after a fresh seed.
```
- Fresh install / reset:
```bash
sudo docker exec servicedesk-servicedesk-1 php artisan migrate:fresh --seed
sudo docker exec servicedesk-app-1 php artisan migrate:fresh --seed
```
Seeds real reference data (categories, custom fields, statuses/priorities/SLA,
teams, quick actions, response/e-mail templates, branding/config with example
@@ -128,16 +263,28 @@ Compose-level and Laravel-level) and the LDAP/SMTP gotcha after a fresh seed.
src/ Laravel application
app/Livewire/ Client/Operator/Admin Livewire components
app/Models/ Eloquent models
app/Services/ TicketService (ticket lifecycle + notifications), BookStackClient
app/Ldap/ LDAP user model + sync handlers
app/Events/ Broadcast events (TicketQueueChanged, TicketMessagePosted)
app/Console/Commands/ Scheduled commands (SLA breach check, automation rules, IMAP fetch,
AI ticket triage/summary) + bookstack:tag-content + hesk:import
(one-time historical migration, see scripts/hesk-import/)
app/Services/ TicketService (ticket lifecycle + notifications), BookStackClient,
ImapMailboxFetcher (I/O) + ImapMessageClassifier (pure logic),
AiClient (generic LLM client), BookStackContentTagger,
TicketAiTriageService, TicketAiSummaryService, SnipeItClient
app/Ldap/ LDAP user models — LldapUser (LLDAP/OpenLDAP, default) and
AdUser (Active Directory) — plus sync handlers
database/migrations/ Schema (one file per table group, final shape)
database/seeders/ DatabaseSeeder — reference data, no ticket data
resources/css/ Tailwind entrypoint (needs `npm run build` after edits)
resources/js/echo.js Laravel Echo/Reverb client + broadcast → Livewire event bridge
resources/views/ Blade templates
routes/web.php Client/Operator/Admin routes (role-gated)
routes/api.php REST API (Sanctum, ability-gated)
routes/channels.php Broadcasting channel authorization (operator.queue, ticket.{id})
wiki/
client/ How-to guide for the Client role
operator/ How-to guide for the Operator role
admin/ How-to guide for the Admin role
scripts/
hesk-import/ One-time Hesk 3.x ticket history import — see its own README.md
```

View File

@@ -13,20 +13,20 @@ fast in-process fakes (`array`/`sync`) for the same reason.
From inside the app container (or on a bare-metal install, from `src/`):
```bash
docker compose exec servicedesk php artisan test
docker compose exec app php artisan test
```
or directly with Pest:
```bash
docker compose exec servicedesk ./vendor/bin/pest
docker compose exec app ./vendor/bin/pest
```
Run a single file or filter by name:
```bash
docker compose exec servicedesk php artisan test --filter=SlaBreachNotificationTest
docker compose exec servicedesk ./vendor/bin/pest tests/Feature/TicketApiTest.php
docker compose exec app php artisan test --filter=SlaBreachNotificationTest
docker compose exec app ./vendor/bin/pest tests/Feature/TicketApiTest.php
```
There is no CI pipeline configured for this repository — running the suite
@@ -60,5 +60,5 @@ automatically without extra boilerplate.
on Laravel's default preset). Run it before committing:
```bash
docker compose exec servicedesk ./vendor/bin/pint
docker compose exec app ./vendor/bin/pint
```

View File

@@ -24,7 +24,7 @@ osobne pliki, w dwóch różnych miejscach.
- Docker + wtyczka `docker compose`.
- Zewnętrzna sieć Docker `traefik_public`, jeśli używasz Traefika tak jak w
`compose.yaml` (`docker network create traefik_public`, jeśli jeszcze nie
istnieje). Bez Traefika trzeba samodzielnie zmapować porty serwisu `servicedesk`
istnieje). Bez Traefika trzeba samodzielnie zmapować porty serwisu `app`
na hosta (`ports: ["8080:80"]`) i obsłużyć TLS inaczej (patrz sekcja 2 niżej, w
razie potrzeby reverse-proxy przed kontenerem).
@@ -74,7 +74,7 @@ APP_LOCALE=pl
APP_FALLBACK_LOCALE=pl
AUTHOR_CONTACT=helpdesk@twoja-domena.pl # widoczne w Admin > O aplikacji
VERSION=1.1.0 # rezerwa na przyszłość, jeszcze nigdzie nie wyświetlane
VERSION=1.3.0 # widoczne w Admin > O aplikacji
DB_CONNECTION=mysql
DB_HOST=mariadb # nazwa serwisu z compose.yaml, NIE 127.0.0.1
@@ -90,8 +90,8 @@ QUEUE_CONNECTION=database
`APP_KEY` wygenerujesz komendą artisan (krok 1.4) — zostaw puste w pliku.
`LDAP_*` i `MAIL_*` w `src/.env` są tylko **wartościami startowymi/awaryjnymi**.
Docelowo LDAP i SMTP konfiguruje się wygodniej z poziomu **Admin > Konfiguracja**
w samej aplikacji (patrz ramka ostrzegawcza w kroku 1.6) — ale jeśli chcesz mieć
Docelowo LDAP konfiguruje się wygodniej z poziomu **Admin > Integracje**, a SMTP
z **Admin > Poczta** (patrz ramka ostrzegawcza w kroku 1.6) — ale jeśli chcesz mieć
sensowny fallback zanim ktokolwiek się zaloguje do panelu admina, warto je od razu
uzupełnić:
@@ -173,13 +173,77 @@ obrazu `servicedesk`) — poczekaj, aż workflow CI przejdzie choć raz (np. prz
push/PR zmieniający `Dockerfile`, albo ręczne odpalenie z zakładki Actions w
Gitea), zanim spróbujesz `docker compose pull` na serwerze.
### 1.3b. Real-time (Laravel Reverb)
Realtime (kolejka operatora, czat na żywo) wymaga trzeciej usługi w
`compose.yaml`, `reverb` — tego samego obrazu `servicedesk`, tylko z innym
`command: php artisan reverb:start --host=0.0.0.0 --port=8080`. Obraz musi
mieć rozszerzenia PHP `pcntl`/`posix` (potrzebne serwerowi Reverb do obsługi
sygnałów) — jeśli `Dockerfile` ich nie instaluje, `reverb` będzie się zapętlać
w restartach z błędem `Undefined constant "...SIGINT"`; dodaj `pcntl posix` do
listy w `docker-php-ext-install` i poczekaj na przebudowanie obrazu przez CI.
Traefik musi kierować ścieżkę websocketu (`/app*`) do `reverb`, a resztę do
`app` — na tej samej domenie, więc bez dodatkowego wpisu DNS/certyfikatu:
```yaml
reverb:
image: gitea.kzbikowski.pl/kzbkowski/servicedesk:${IMAGE_TAG:-latest}
command: php artisan reverb:start --host=0.0.0.0 --port=8080
volumes:
- ./src:/var/www/html
restart: unless-stopped
depends_on:
mariadb:
condition: service_healthy
networks:
- internal
- traefik_public
labels:
- traefik.enable=true
- traefik.docker.network=traefik_public
- traefik.http.routers.reverb.rule=Host(`${HOSTNAME}`) && PathPrefix(`/app`)
- traefik.http.routers.reverb.priority=1000
- traefik.http.routers.reverb.entrypoints=websecure
- traefik.http.routers.reverb.tls=true
- traefik.http.services.reverb.loadbalancer.server.port=8080
```
`priority=1000` jest ważne — Traefik domyślnie liczy priorytet reguły na
podstawie długości jej zapisu, co może dać samemu `Host(...)` z `servicedesk`
wyższy priorytet niż oczekiwano, przez co ścieżkowa reguła `reverb` przegrywa i
nic nie działa mimo poprawnej konfiguracji.
W `src/.env``BROADCAST_CONNECTION=reverb` plus:
```env
REVERB_APP_ID=wygeneruj-losowy-id
REVERB_APP_KEY=wygeneruj-losowy-klucz
REVERB_APP_SECRET=wygeneruj-losowy-sekret
REVERB_HOST=reverb # nazwa usługi compose — ruch serwer-serwer po sieci internal
REVERB_PORT=8080
REVERB_SCHEME=http
VITE_REVERB_APP_KEY="${REVERB_APP_KEY}"
VITE_REVERB_HOST=servicedesk.twoja-domena.pl # publiczna domena — to, z czym łączy się przeglądarka
VITE_REVERB_PORT=443
VITE_REVERB_SCHEME=https
```
`REVERB_HOST` (serwer→serwer, wewnętrzna sieć Docker) i `VITE_REVERB_HOST`
(przeglądarka→Traefik, publiczna domena) to celowo dwie różne wartości —
pomylenie ich to najczęstszy błąd przy pierwszym wdrożeniu tej funkcji.
Po zmianie zmiennych `VITE_REVERB_*` trzeba przebudować front-end (krok 1.5) —
te wartości są wypiekane w zbudowany bundle JS, nie czytane w runtime.
### 1.4. Instalacja aplikacji wewnątrz kontenera
```bash
docker compose exec servicedesk composer install --no-dev --optimize-autoloader
docker compose exec servicedesk php artisan key:generate
docker compose exec servicedesk php artisan migrate --seed
docker compose exec servicedesk php artisan storage:link
docker compose exec app composer install --no-dev --optimize-autoloader
docker compose exec app php artisan key:generate
docker compose exec app php artisan migrate --seed
docker compose exec app php artisan storage:link
```
`migrate --seed` (bez `--fresh`) na pustej bazie utworzy wszystkie tabele i
@@ -190,7 +254,7 @@ po pierwszym zalogowaniu (Admin > Użytkownicy).
### 1.5. Zbudowanie zasobów front-endowych (CSS/Tailwind)
Ani host, ani kontener `servicedesk` nie mają zainstalowanego Node.js — buduj
Ani host, ani kontener `app` nie mają zainstalowanego Node.js — buduj
przez jednorazowy kontener `node:22` zamiast dorzucać Node do obrazu aplikacji:
```bash
@@ -201,16 +265,43 @@ docker run --rm -v "$(pwd)/src":/app -w /app node:22 npm run build
Powtarzaj drugi krok po każdej zmianie w `resources/css/` lub `resources/js/`.
### 1.6. Zadanie cykliczne (SLA) i kolejka
### 1.6. Zadanie cykliczne (SLA, automatyzacje, poczta IMAP, AI) i kolejka
`routes/console.php` planuje `tickets:check-sla-breaches` co 15 minut, ale **obraz
Dockera nie ma wbudowanego cron/supervisora** — bez dodatkowego kroku to zadanie
nigdy się nie uruchomi. Najprościej dodać wpis crona **na hoście**:
`routes/console.php` planuje `tickets:check-sla-breaches` i `automation:run-rules`
co 15 minut, oraz `emails:fetch-imap` (odbieranie zgłoszeń/odpowiedzi e-mailem —
patrz Admin > Poczta) i `ai:run-ticket-automation` (opcjonalna automatyczna
kategoryzacja/podsumowania AI zgłoszeń — patrz Admin > Integracje) co 5 minut,
ale **obraz Dockera nie ma wbudowanego cron/supervisora** — bez dodatkowego
kroku żadne z tych zadań nigdy się nie uruchomi (poczta IMAP nadal da się
sprawdzić ręcznie przyciskiem „Pobierz teraz”, ale bez tego nic nie dzieje się
samo). Wszystkie cztery interwały są też konfigurowalne z poziomu **Admin >
Konfiguracja** (bez potrzeby edycji kodu czy restartu — nowa wartość obowiązuje
od najbliższego tyknięcia harmonogramu).
```cron
* * * * * cd /ścieżka/do/repo && docker compose exec -T servicedesk php artisan schedule:run >> /dev/null 2>&1
`compose.yaml` rozwiązuje to czwartą usługą, `cron` — tego samego obrazu
`servicedesk`, tylko z innym poleceniem:
```yaml
cron:
image: gitea.kzbikowski.pl/kzbkowski/servicedesk:${IMAGE_TAG:-latest}
command: php artisan schedule:work
volumes:
- ./src:/var/www/html
restart: unless-stopped
depends_on:
mariadb:
condition: service_healthy
networks:
- internal
```
`schedule:work` to własna, pierwszoplanowa pętla harmonogramu Laravela —
odpowiednik odpalania `schedule:run` co minutę, ale bez potrzeby zewnętrznego
triggera. Ten kontener nie musi być widoczny w Traefiku (nie obsługuje ruchu
HTTP), stąd tylko sieć `internal`. Sprawdź, że działa: `docker compose ps cron`
oraz `docker compose logs -f cron` (loguje każde odpalenie zaplanowanego
zadania).
Powiadomienia e-mail wysyłają się synchronicznie (nie trafiają do kolejki), więc
`php artisan queue:work` nie jest obowiązkowy — `QUEUE_CONNECTION=database` w
`.env` wystarcza jako bezpieczny domyślny driver, gdyby coś w przyszłości zaczęło
@@ -219,8 +310,9 @@ kolejkować zadania.
### ⚠️ Ważne: LDAP/SMTP z panelu Admina nadpisują `.env` w locie
`AppServiceProvider` na starcie żądania sprawdza tabelę `settings` — jeśli w
Admin > Konfiguracja pole **host LDAP** albo **SMTP włączony + host** jest
ustawione, **te wartości wygrywają z `.env`**, bez potrzeby restartu czy redeployu.
Admin > Integracje pole **host LDAP** albo w Admin > Poczta **SMTP włączony +
host** jest ustawione, **te wartości wygrywają z `.env`**, bez potrzeby
restartu czy redeployu.
Po świeżym `migrate --seed` te pola zawierają **przykładowe placeholdery**
(`ldap.example.com`, `smtp.example.com`, `changeme-*-password`) — to znaczy, że
@@ -229,20 +321,43 @@ adresami**, nawet jeśli w `.env` wpisałeś prawdziwe dane! Zanim oddasz system
użytku:
1. Zaloguj się lokalnym kontem `admin@example.com` / `admin`.
2. Wejdź w **Admin > Konfiguracja** i wpisz prawdziwe dane LDAP/SMTP (albo wyczyść
pole hosta LDAP, żeby wrócić do wartości z `.env`).
3. Użyj przycisków **„Testuj połączenie”** przy obu sekcjach, zanim zaczniesz
polegać na logowaniu przez katalog.
2. Wejdź w **Admin > Integracje** i wpisz prawdziwe dane LDAP (wybierz też
właściwy **Typ katalogu** LLDAP/OpenLDAP albo Active Directory — jeśli
katalog to nie LLDAP; albo wyczyść pole hosta LDAP, żeby wrócić do
wartości z `.env`), a w **Admin > Poczta** dane SMTP.
3. Użyj przycisku **„Testuj połączenie”** w Integracje i **„Wyślij testową
wiadomość”** w Poczta, zanim zaczniesz polegać na logowaniu przez katalog
albo na powiadomieniach e-mail.
### Integracje opcjonalne (BookStack)
### Integracje opcjonalne (BookStack, AI)
Podpowiedzi artykułów z bazy wiedzy BookStack (przy tworzeniu zgłoszenia i w
panelu operatora) są **domyślnie wyłączone** i nie wymagają żadnej zmiennej w
`.env` — całość konfiguruje się w **Admin > Konfiguracja**: adres instancji,
`.env` — całość konfiguruje się w **Admin > Integracje**: adres instancji,
Token ID/Secret (rola/użytkownik właściciela tokenu musi mieć w BookStacku
uprawnienie „Access System API”), oraz osobne listy dozwolonych półek dla
podpowiedzi przy tworzeniu zgłoszenia i dla panelu operatora — dopóki żadna
półka nie jest zaznaczona, wyszukiwanie nic nie zwraca.
uprawnienie „Access System API”), filtr typu treści (książki/strony/rozdziały,
niezależne checkboxy), tryb wyszukiwania (po nazwie / po tagach / oba), oraz
osobne listy dozwolonych półek dla podpowiedzi przy tworzeniu zgłoszenia i dla
panelu operatora — dopóki żadna półka nie jest zaznaczona, wyszukiwanie nic
nie zwraca.
Integracja AI (Admin > Integracje > „Integracja AI”) jest **domyślnie
wyłączona** i tak samo nie wymaga żadnej zmiennej w `.env` — adres API
(dowolny dostawca kompatybilny z OpenAI: Groq, OpenAI, lokalny Ollama),
opcjonalny klucz API, nazwa modelu i przełącznik weryfikacji SSL. Sama w
sobie nic nie robi — dopiero po jej włączeniu można włączyć automatyczne
tagowanie treści BookStack (przyciski przy integracji BookStack) oraz
automatyczną kategoryzację/podsumowania AI zgłoszeń (Admin > Integracje >
„Automatyzacja AI dla zgłoszeń”, wymaga też wpisu crona z kroku 1.6/2.6
powyżej — to ten sam harmonogram co SLA/automatyzacje/IMAP).
### Import historycznych zgłoszeń z Heska (opcjonalnie)
Jeśli migrujesz z helpdesku Hesk 3.x, `scripts/hesk-import/` zawiera
jednorazowe (nie ciągłe) narzędzie migracyjne — importuje zgłoszenia wraz z
pełną historią odpowiedzi/notatek, ograniczone do jednej domeny e-mail, w
trybie dry-run domyślnie. Nie dotyka bazy Heska poza odczytem. Zobacz
`scripts/hesk-import/README.md` po pełną instrukcję.
---
@@ -285,7 +400,7 @@ APP_LOCALE=pl
APP_FALLBACK_LOCALE=pl
AUTHOR_CONTACT=helpdesk@twoja-domena.pl
VERSION=1.1.0
VERSION=1.3.0
DB_CONNECTION=mysql
DB_HOST=127.0.0.1 # albo adres IP/hostname prawdziwego serwera DB
@@ -299,7 +414,7 @@ QUEUE_CONNECTION=database
```
Uzupełnij też `LDAP_*`/`MAIL_*` jak w sekcji 1.2 (to samo ostrzeżenie o
Admin > Konfiguracja nadpisującym te wartości w locie dotyczy tu identycznie).
Admin > Integracje/Poczta nadpisującym te wartości w locie dotyczy tu identycznie).
```bash
php artisan key:generate
@@ -393,9 +508,11 @@ server {
}
```
### 2.6. Zadanie cykliczne (SLA) i kolejka
### 2.6. Zadanie cykliczne (SLA, automatyzacje, poczta IMAP, AI) i kolejka
Crontab użytkownika, pod którym stoi aplikacja (np. `www-data`):
Crontab użytkownika, pod którym stoi aplikacja (np. `www-data`) — obsługuje też
`automation:run-rules`, `emails:fetch-imap` i `ai:run-ticket-automation`
(patrz 1.6 wyżej, w tym konfigurowalne interwały w Admin > Konfiguracja):
```cron
* * * * * cd /var/www/servicedesk/src && php artisan schedule:run >> /dev/null 2>&1
@@ -405,12 +522,42 @@ Jak w wersji Docker — kolejka (`php artisan queue:work`) nie jest obowiązkowa
skoro powiadomienia wysyłają się synchronicznie; zostaw `QUEUE_CONNECTION=database`
jako bezpieczny domyślny driver na przyszłość.
Realtime (patrz 1.3b) potrzebuje tu **długo działającego procesu**
`php artisan reverb:start` — PHP musi mieć rozszerzenia `pcntl`/`posix`
(standardowo dostępne, ale sprawdź `php -m`). Najprościej pod systemd:
```ini
# /etc/systemd/system/servicedesk-reverb.service
[Unit]
Description=Servicedesk Reverb websocket server
After=network.target
[Service]
User=www-data
WorkingDirectory=/var/www/servicedesk/src
ExecStart=/usr/bin/php artisan reverb:start --host=0.0.0.0 --port=8080
Restart=always
[Install]
WantedBy=multi-user.target
```
```bash
systemctl enable --now servicedesk-reverb
```
Ustaw też te same zmienne `.env` co w 1.3b (`BROADCAST_CONNECTION=reverb`,
`REVERB_*`, `VITE_REVERB_*` — tu `REVERB_HOST` to po prostu `127.0.0.1`, nie
nazwa usługi compose) i skieruj serwer WWW tak, by ścieżka `/app*` trafiała do
portu 8080 zamiast do PHP-FPM/Apache (osobny `location`/`VirtualHost` dla tej
jednej ścieżki, analogicznie do reguły Traefika w 1.3b).
### 2.7. Pierwsze logowanie i dalsza konfiguracja
Identycznie jak w kroku 1.6 — zaloguj się `admin@example.com` / `admin`, zmień
hasło, uzupełnij prawdziwe LDAP/SMTP w Admin > Konfiguracja (placeholdery z seeda
inaczej realnie próbują łączyć się z fałszywymi adresami), przetestuj oba
połączenia przyciskiem „Testuj połączenie”.
hasło, uzupełnij prawdziwe LDAP w Admin > Integracje i SMTP w Admin > Poczta
(placeholdery z seeda inaczej realnie próbują łączyć się z fałszywymi
adresami), przetestuj oba połączenia.
### 2.8. Aktualizacje (bez przestoju)

View File

@@ -0,0 +1,5 @@
HESK_DB_HOST=
HESK_DB_PORT=3306
HESK_DB_DATABASE=
HESK_DB_USERNAME=
HESK_DB_PASSWORD=

View File

@@ -0,0 +1,83 @@
# Hesk 3.x import
One-time historical migration of tickets (with full reply/note history) from a
Hesk 3.x helpdesk database into this app, restricted to a single e-mail
domain. Read-only against the Hesk database — never writes there.
This is **not** an ongoing sync. Run it once to backfill history from an
old Hesk install; it doesn't pick up edits made in Hesk afterward.
## What it does
- Matches Hesk tickets by requester e-mail domain (`--domain=firma.pl`).
- Imports each ticket's subject/body, status, priority, and full reply +
internal-note history, converting Hesk's `<br />`-laden "plain" text into
real line breaks.
- Maps Hesk categories to this app's categories by exact (case/whitespace-
insensitive) name match. A Hesk category with no match is skipped by
default — pass `--include-unmapped-categories` to import those tickets
anyway, uncategorized.
- Auto-assigns a team when every subcategory under the matched category
routes to the same single team (same rule `TicketService::autoAssignTeam()`
uses for normal ticket creation); ambiguous categories are left unrouted.
- Finds or creates a client account per requester e-mail, reusing an existing
account (adding the `client` role if it doesn't have it yet) rather than
duplicating.
- Hesk staff replies are **not** linked to a real operator account (this
script never creates operator accounts) — the reply still shows the
correct staff name and "operator" badge via `author_name`, just without a
clickable user behind it.
## Setup
```bash
cp scripts/hesk-import/.env.example scripts/hesk-import/.env
```
Fill in `scripts/hesk-import/.env` with the Hesk database's
host/port/database/username/password. That file is gitignored — it holds
real credentials for a database this app otherwise has no access to.
## Usage
Always dry-run first — it reports what *would* happen without writing
anything:
```bash
scripts/hesk-import/hesk-import.sh --domain=firma.pl
```
Try a small batch for real before committing to the whole thing:
```bash
scripts/hesk-import/hesk-import.sh --domain=firma.pl --limit=10 --commit
```
Then the full import:
```bash
scripts/hesk-import/hesk-import.sh --domain=firma.pl --commit
```
Safe to re-run (including after an interrupted/crashed run): already-imported
Hesk ticket ids are tracked in `storage/app/hesk-import-state.json` inside the
app container and skipped on subsequent runs.
### Backfilling team assignment
If tickets were already imported before team-by-category mapping existed (or
teams/subcategories changed since), backfill `team_id` on existing imported
tickets without importing anything new:
```bash
scripts/hesk-import/hesk-import.sh --assign-teams --commit
```
## How it's wired up
`hesk-import.sh` is a thin wrapper: it loads `.env` in this folder, then runs
`php artisan hesk:import` inside the `app` container via `docker compose
exec`, passing the Hesk DB credentials as one-off environment variables (they
never touch the app's own `.env` or get persisted anywhere but the state
file). The actual import logic lives in
[`../../src/app/Console/Commands/ImportHeskTickets.php`](../../src/app/Console/Commands/ImportHeskTickets.php).

View File

@@ -0,0 +1,49 @@
#!/usr/bin/env bash
#
# Imports tickets from a Hesk 3.x helpdesk database into this app, filtered
# to one e-mail domain. Thin wrapper around `php artisan hesk:import` (see
# ../../src/app/Console/Commands/ImportHeskTickets.php for the actual logic)
# — this script only wires up the Hesk DB credentials and runs it inside the
# app container. See README.md in this folder for full setup/usage docs.
#
# Setup: copy .env.example (this folder) to .env (gitignored) and fill in
# your Hesk database's host/port/database/username/password.
#
# Usage:
# scripts/hesk-import/hesk-import.sh --domain=firma.pl # dry run (default, writes nothing)
# scripts/hesk-import/hesk-import.sh --domain=firma.pl --limit=10 --commit # real run, first 10 tickets only
# scripts/hesk-import/hesk-import.sh --domain=firma.pl --commit # real run, everything
#
# Safe to re-run: already-imported Hesk tickets are tracked in
# storage/app/hesk-import-state.json inside the app container and skipped.
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
REPO_ROOT="$(cd "$SCRIPT_DIR/../.." && pwd)"
ENV_FILE="$SCRIPT_DIR/.env"
if [[ ! -f "$ENV_FILE" ]]; then
echo "Brak $ENV_FILE — skopiuj scripts/hesk-import/.env.example i uzupełnij dane dostępowe do bazy Heska." >&2
exit 1
fi
set -a
# shellcheck disable=SC1090
source "$ENV_FILE"
set +a
: "${HESK_DB_HOST:?ustaw HESK_DB_HOST w $ENV_FILE}"
: "${HESK_DB_DATABASE:?ustaw HESK_DB_DATABASE w $ENV_FILE}"
: "${HESK_DB_USERNAME:?ustaw HESK_DB_USERNAME w $ENV_FILE}"
HESK_DB_PORT="${HESK_DB_PORT:-3306}"
cd "$REPO_ROOT"
exec sudo docker compose exec \
-e HESK_DB_HOST="$HESK_DB_HOST" \
-e HESK_DB_PORT="$HESK_DB_PORT" \
-e HESK_DB_DATABASE="$HESK_DB_DATABASE" \
-e HESK_DB_USERNAME="$HESK_DB_USERNAME" \
-e HESK_DB_PASSWORD="$HESK_DB_PASSWORD" \
app php artisan hesk:import "$@"

View File

@@ -1,11 +1,11 @@
APP_NAME=Laravel
APP_ENV=local
APP_KEY=
APP_DEBUG=true
APP_DEBUG=false
APP_URL=http://localhost
AUTHOR_CONTACT=helpdesk@kzbikowski.pl
VERSION=1.1.0
VERSION=1.4.0
APP_LOCALE=en
APP_FALLBACK_LOCALE=en
@@ -40,6 +40,24 @@ BROADCAST_CONNECTION=log
FILESYSTEM_DISK=local
QUEUE_CONNECTION=database
# Reverb (real-time broadcasting) — set BROADCAST_CONNECTION=reverb to enable.
# REVERB_HOST/PORT/SCHEME are server-to-server (this container calling the
# "reverb" compose service over the internal docker network) — REVERB_HOST
# should be the compose service name ("reverb"), not a public hostname.
# VITE_REVERB_* is what gets baked into the built frontend bundle and is what
# the browser connects to — same public hostname/TLS as the rest of the app.
REVERB_APP_ID=wygeneruj-losowy-id
REVERB_APP_KEY=wygeneruj-losowy-klucz
REVERB_APP_SECRET=wygeneruj-losowy-sekret
REVERB_HOST=reverb
REVERB_PORT=8080
REVERB_SCHEME=http
VITE_REVERB_APP_KEY="${REVERB_APP_KEY}"
VITE_REVERB_HOST=servicedesk.twoja-domena.pl
VITE_REVERB_PORT=443
VITE_REVERB_SCHEME=https
CACHE_STORE=database
# CACHE_PREFIX=

View File

@@ -0,0 +1,35 @@
<?php
namespace App\Console\Commands;
use App\Services\BookStackContentTagger;
use Illuminate\Console\Command;
class BookstackTagContent extends Command
{
protected $signature = 'bookstack:tag-content
{--dry-run : Klasyfikuj i pokaż wynik bez zapisu tagów do BookStack}
{--force : Klasyfikuj ponownie elementy, które już mają tag podkategorii}
{--limit= : Zatrzymaj się po przetworzeniu N elementów}';
protected $description = 'Otaguj każdą książkę/rozdział/stronę w BookStack pasującymi nazwami podkategorii helpdesku, z pomocą skonfigurowanego dostawcy AI';
public function handle(BookStackContentTagger $tagger): int
{
$totals = $tagger->run(
dryRun: (bool) $this->option('dry-run'),
force: (bool) $this->option('force'),
limit: $this->option('limit') !== null ? (int) $this->option('limit') : null,
);
$this->info(sprintf(
'BookStack tagging: przeskanowano %d, otagowano %d, pominięto %d, nieudanych paczek %d.',
$totals['scanned'],
$totals['tagged'],
$totals['skipped'],
$totals['failed_batches'],
));
return self::SUCCESS;
}
}

View File

@@ -0,0 +1,33 @@
<?php
namespace App\Console\Commands;
use App\Models\ImapMailbox;
use App\Services\ImapMailboxFetcher;
use Illuminate\Console\Command;
class FetchImapEmails extends Command
{
protected $signature = 'emails:fetch-imap';
protected $description = 'Poll every enabled IMAP mailbox and turn new messages into tickets/replies';
public function handle(ImapMailboxFetcher $fetcher): int
{
if (! ImapMailbox::query()->where('enabled', true)->exists()) {
return self::SUCCESS;
}
$totals = $fetcher->fetchAll();
$this->info(sprintf(
'IMAP fetch: %d nowych, %d odpowiedzi, %d odrzuconych, %d błędów.',
$totals['created'],
$totals['replied'],
$totals['rejected'],
$totals['errors'],
));
return self::SUCCESS;
}
}

View File

@@ -0,0 +1,504 @@
<?php
namespace App\Console\Commands;
use App\Models\Category;
use App\Models\Role;
use App\Models\Team;
use App\Models\Ticket;
use App\Models\User;
use Illuminate\Console\Command;
use Illuminate\Support\Collection;
use Illuminate\Support\Facades\Config;
use Illuminate\Support\Facades\DB;
use PDO;
/**
* One-off migration from a Hesk 3.x helpdesk database into this app's own
* tickets/users. Never writes to the Hesk database read-only there.
*
* Runs in dry-run mode by default (reports what it would do); pass --commit
* to actually write. Resumable: every successfully imported Hesk ticket id
* is recorded in a local state file (--state, defaults to
* storage/app/hesk-import-state.json), so a re-run (interrupted connection,
* crashed midway, etc.) skips tickets already imported instead of
* duplicating them. Not idempotent across *edits* on the Hesk side this is
* a one-time historical import, not an ongoing sync.
*/
class ImportHeskTickets extends Command
{
protected $signature = 'hesk:import
{--domain= : Only import tickets whose requester e-mail ends in @this-domain}
{--commit : Actually write to the database (default is a dry run)}
{--limit= : Only process this many Hesk tickets (after the domain filter), useful for a test run}
{--state= : Path to the resume-state JSON file (default storage/app/hesk-import-state.json)}
{--include-unmapped-categories : Also import tickets whose Hesk category has no matching servicedesk category (default: skip them)}
{--assign-teams : Backfill team_id (by category) on already-imported tickets that don\'t have one yet, then exit — does not import anything}';
protected $description = 'Import tickets (with full reply/note history) from a Hesk 3.x database, restricted to one e-mail domain';
/**
* Hesk ticket.status -> our status_key. Hesk's built-in codes are
* 0=New, 1=Waiting reply (for staff), 2=Replied (waiting on customer),
* 3=Resolved. Any other value (seen: a handful of "5" rows, presumably
* a since-deleted custom status) falls back to 'open'.
*/
private const STATUS_MAP = [
0 => 'new',
1 => 'waiting_operator',
2 => 'waiting_customer',
3 => 'closed',
];
/**
* Hesk ticket.priority -> our priority_key. Hesk's enum is 1=Critical,
* 2=High, 3=Medium (the near-universal default every Hesk category
* here defaults new tickets to priority 3); 0 is an unused/rare edge
* value, treated as the closest thing Hesk has to "Low".
*/
private const PRIORITY_MAP = [
0 => 'low',
1 => 'critical',
2 => 'high',
3 => 'medium',
];
private array $categoryMap = [];
/** @var array<int, int> servicedesk category id => servicedesk team id, only when unambiguous */
private array $teamByCategory = [];
/** @var array<int, string> Hesk help_users.id => name, loaded once */
private array $heskStaffNames = [];
private array $state = ['imported' => []];
private string $statePath;
public function handle(): int
{
if ($this->option('assign-teams')) {
return $this->runAssignTeams((bool) $this->option('commit'));
}
$domain = trim((string) $this->option('domain'), " \t\n\r\0\x0B@");
if ($domain === '') {
$this->error('Podaj --domain=twoja-domena.pl (bez @).');
return self::FAILURE;
}
$commit = (bool) $this->option('commit');
$limit = $this->option('limit') !== null ? (int) $this->option('limit') : null;
$includeUnmapped = (bool) $this->option('include-unmapped-categories');
$this->statePath = $this->option('state') ?: storage_path('app/hesk-import-state.json');
if (! $this->configureHeskConnection()) {
return self::FAILURE;
}
$this->loadState();
$this->buildCategoryMap();
$this->buildTeamMap();
$this->loadHeskStaffNames();
$tickets = DB::connection('hesk')->table('help_tickets')
->where('email', 'like', '%@'.$domain)
->orderBy('id')
->when($limit, fn ($q) => $q->limit($limit))
->get();
$this->info(sprintf(
'%s tryb: %d zgłoszeń z Heska pasuje do domeny @%s (%d już zaimportowanych wcześniej, zostaną pominięte).',
$commit ? 'KOMMIT' : 'DRY-RUN',
$tickets->count(),
$domain,
$tickets->whereIn('id', $this->state['imported'])->count(),
));
$stats = ['created' => 0, 'skipped' => 0, 'skipped_unmapped_category' => 0, 'failed' => 0, 'messages' => 0, 'customers_created' => 0];
$unmappedCategories = [];
$bar = $this->output->createProgressBar($tickets->count());
$bar->start();
foreach ($tickets as $heskTicket) {
$bar->advance();
if (in_array($heskTicket->id, $this->state['imported'], true)) {
$stats['skipped']++;
continue;
}
$categoryMapped = array_key_exists($heskTicket->category, $this->categoryMap);
if (! $categoryMapped && ! in_array($heskTicket->category, $unmappedCategories, true)) {
$unmappedCategories[] = $heskTicket->category;
}
// Default: a Hesk category with no servicedesk equivalent means
// this ticket is skipped entirely rather than imported without
// a category — --include-unmapped-categories opts back in.
if (! $categoryMapped && ! $includeUnmapped) {
$stats['skipped_unmapped_category']++;
continue;
}
if (! $commit) {
$stats['created']++;
continue;
}
try {
DB::transaction(function () use ($heskTicket, &$stats) {
$this->importOneTicket($heskTicket, $stats);
});
$this->state['imported'][] = $heskTicket->id;
$this->saveState();
} catch (\Throwable $e) {
$stats['failed']++;
$this->newLine();
$this->error("Zgłoszenie Hesk #{$heskTicket->id} ({$heskTicket->trackid}) nie zostało zaimportowane: ".$e->getMessage());
}
}
$bar->finish();
$this->newLine(2);
$this->table(['Miara', 'Wartość'], [
['Zgłoszenia utworzone', $stats['created']],
['Wiadomości/notatki utworzone', $stats['messages']],
['Nowe konta klientów', $stats['customers_created']],
['Pominięte (już zaimportowane)', $stats['skipped']],
['Pominięte (kategoria bez odpowiednika)', $stats['skipped_unmapped_category']],
['Błędy', $stats['failed']],
]);
if ($unmappedCategories) {
$names = collect($unmappedCategories)
->map(fn ($id) => DB::connection('hesk')->table('help_categories')->where('id', $id)->value('name') ?? "id={$id}")
->implode(', ');
$action = $includeUnmapped ? 'zgłoszenia zaimportowane bez kategorii' : 'zgłoszenia POMINIĘTE — użyj --include-unmapped-categories, żeby jednak je zaimportować bez kategorii';
$this->warn("Kategorie Heska bez odpowiednika w servicedesk ({$action}): {$names}");
}
if (! $commit) {
$this->newLine();
$this->comment('To był dry-run — nic nie zostało zapisane. Uruchom ponownie z --commit, żeby faktycznie zaimportować.');
}
return self::SUCCESS;
}
private function configureHeskConnection(): bool
{
$host = env('HESK_DB_HOST');
$port = env('HESK_DB_PORT', 3306);
$database = env('HESK_DB_DATABASE');
$username = env('HESK_DB_USERNAME');
$password = env('HESK_DB_PASSWORD');
if (! $host || ! $database || ! $username) {
$this->error('Brakuje HESK_DB_HOST / HESK_DB_DATABASE / HESK_DB_USERNAME w środowisku (patrz scripts/hesk-import/hesk-import.sh).');
return false;
}
Config::set('database.connections.hesk', [
'driver' => 'mysql',
'host' => $host,
'port' => $port,
'database' => $database,
'username' => $username,
'password' => $password,
'charset' => 'utf8mb4',
'collation' => 'utf8mb4_unicode_ci',
'options' => [PDO::ATTR_TIMEOUT => 10],
]);
try {
DB::connection('hesk')->getPdo();
} catch (\Throwable $e) {
$this->error('Nie udało się połączyć z bazą Heska: '.$e->getMessage());
return false;
}
return true;
}
/**
* Hesk category name (normalized) -> servicedesk category id. Only
* exact (case/whitespace-insensitive) name matches are mapped; anything
* else is left uncategorized and reported at the end instead of guessed at.
*/
private function buildCategoryMap(): void
{
$ours = Category::query()->get()->keyBy(fn (Category $c) => $this->normalizeCategoryName($c->name));
foreach (DB::connection('hesk')->table('help_categories')->get() as $heskCategory) {
$match = $ours->get($this->normalizeCategoryName($heskCategory->name));
if ($match) {
$this->categoryMap[$heskCategory->id] = $match->id;
}
}
}
private function normalizeCategoryName(string $name): string
{
return mb_strtolower(trim($name));
}
/**
* servicedesk category id -> servicedesk team id, only when every
* subcategory under that category belongs to the same single team (the
* existing team_subcategory routing see TicketService::autoAssignTeam()
* for the same rule applied to normal in-app ticket creation, there scoped
* to a specific subcategory rather than a whole category). A category
* whose subcategories are split across more than one team is left
* unmapped rather than guessed at.
*/
private function buildTeamMap(): void
{
foreach (Category::query()->pluck('id') as $categoryId) {
$teamIds = Team::query()
->whereHas('subcategories', fn ($q) => $q->where('subcategories.category_id', $categoryId))
->pluck('id')
->unique();
if ($teamIds->count() === 1) {
$this->teamByCategory[$categoryId] = $teamIds->first();
}
}
}
/**
* Backfill mode (--assign-teams): sets team_id on tickets that already
* exist (from an earlier --commit run, before team assignment was added)
* and don't have one yet — doesn't import anything, doesn't touch the
* Hesk database at all.
*/
private function runAssignTeams(bool $commit): int
{
$this->buildTeamMap();
if (! $this->teamByCategory) {
$this->warn('Żadna kategoria nie ma jednoznacznie przypisanego zespołu (na podstawie podkategorii) — nie ma czego przypisać.');
return self::SUCCESS;
}
$totalUpdated = 0;
foreach ($this->teamByCategory as $categoryId => $teamId) {
$query = Ticket::query()->where('category_id', $categoryId)->whereNull('team_id');
$count = $query->count();
if ($count === 0) {
continue;
}
$this->line(sprintf(
'Kategoria "%s" -> zespół "%s": %d zgłoszeń%s',
Category::query()->find($categoryId)?->name ?? "id={$categoryId}",
Team::query()->find($teamId)?->name ?? "id={$teamId}",
$count,
$commit ? '' : ' (dry-run)',
));
if ($commit) {
$query->update(['team_id' => $teamId]);
}
$totalUpdated += $count;
}
$this->newLine();
$this->info(($commit ? 'Zaktualizowano' : 'Do zaktualizowania').': '.$totalUpdated.' zgłoszeń.');
if (! $commit) {
$this->comment('To był dry-run — uruchom ponownie z --assign-teams --commit, żeby faktycznie zapisać.');
}
return self::SUCCESS;
}
private function loadHeskStaffNames(): void
{
$this->heskStaffNames = DB::connection('hesk')->table('help_users')->pluck('name', 'id')->all();
}
private function importOneTicket(object $heskTicket, array &$stats): void
{
$customer = $this->resolveCustomer($heskTicket->email, $heskTicket->name, $stats);
$categoryId = $this->categoryMap[$heskTicket->category] ?? null;
$ticket = Ticket::query()->create([
'number' => Ticket::nextNumber(),
'customer_id' => $customer->id,
'email' => $heskTicket->email,
'name' => $heskTicket->name ?: $heskTicket->email,
'category_id' => $categoryId,
'team_id' => $categoryId ? ($this->teamByCategory[$categoryId] ?? null) : null,
'subject' => $this->cleanText($heskTicket->subject) ?: '(bez tematu)',
'body' => $this->cleanText($heskTicket->message),
'status_key' => self::STATUS_MAP[(int) $heskTicket->status] ?? 'open',
'priority_key' => self::PRIORITY_MAP[(int) $heskTicket->priority] ?? 'medium',
'source' => 'hesk_import',
'last_customer_activity_at' => $heskTicket->lastchange,
'created_at' => $heskTicket->dt,
'updated_at' => $heskTicket->lastchange,
]);
// Ticket::booted() re-saves the row right after create() to stamp a
// checksum, which — being a normal Eloquent save() — stomps
// updated_at back to "now". Restore the historical value via the
// query builder so it bypasses Eloquent's timestamp handling.
DB::table('tickets')->where('id', $ticket->id)->update(['updated_at' => $heskTicket->lastchange]);
$opening = $ticket->messages()->create([
'author_name' => $heskTicket->name ?: $heskTicket->email,
'body' => $this->cleanText($heskTicket->message),
'created_at' => $heskTicket->dt,
'updated_at' => $heskTicket->dt,
]);
$opening->attachAuthor($customer->id, 'client');
$stats['messages']++;
foreach ($this->heskReplies($heskTicket->id) as $reply) {
$this->importReply($ticket, $reply, $customer, $stats);
}
foreach ($this->heskNotes($heskTicket->id) as $note) {
$this->importNote($ticket, $note, $stats);
}
$stats['created']++;
}
private function heskReplies(int $heskTicketId): Collection
{
return DB::connection('hesk')->table('help_replies')
->where('replyto', $heskTicketId)
->orderBy('dt')
->get();
}
private function heskNotes(int $heskTicketId): Collection
{
return DB::connection('hesk')->table('help_notes')
->where('ticket', $heskTicketId)
->orderBy('dt')
->get();
}
private function importReply(Ticket $ticket, object $reply, User $customer, array &$stats): void
{
$isStaff = (int) $reply->staffid > 0;
$authorName = $isStaff
? ($this->heskStaffNames[$reply->staffid] ?? 'Personel')
: ($reply->name ?: $customer->name);
$message = $ticket->messages()->create([
'author_name' => $authorName,
'body' => $this->cleanText($reply->message),
'created_at' => $reply->dt,
'updated_at' => $reply->dt,
]);
// Staff replies aren't linked to a real User (we deliberately don't
// create operator accounts for imported Hesk staff — see the
// migration script's design questions) — attachAuthor(null,
// 'operator') still tags the role/badge correctly via author_name.
$message->attachAuthor($isStaff ? null : $customer->id, $isStaff ? 'operator' : 'client');
$stats['messages']++;
}
private function importNote(Ticket $ticket, object $note, array &$stats): void
{
$message = $ticket->messages()->create([
'author_name' => $this->heskStaffNames[$note->who] ?? 'Personel',
'internal' => true,
'body' => $this->cleanText($note->message),
'created_at' => $note->dt,
'updated_at' => $note->dt,
]);
$message->attachAuthor(null, 'operator');
$stats['messages']++;
}
/**
* Finds or creates the local client account for a Hesk requester e-mail.
* Reuses an existing account (e.g. the one real admin account, or one
* already created by an earlier ticket from the same person) rather than
* duplicating, and only ever adds the 'client' role never removes
* whatever roles the account already had.
*/
private function resolveCustomer(string $email, ?string $name, array &$stats): User
{
$email = trim($email);
$user = User::query()->where('email', $email)->first();
if (! $user) {
$user = User::query()->create([
'name' => $name ?: $email,
'email' => $email,
'roles' => ['client'],
]);
$stats['customers_created']++;
return $user;
}
if (! in_array('client', $user->roles, true)) {
$user->roles = [...$user->roles, 'client'];
$user->save();
}
return $user;
}
/**
* Hesk's "plain" message/subject columns still carry <br /> tags (and
* occasionally other inline HTML) from HTML-formatted source e-mails
* this app renders ticket/message bodies as escaped plain text
* (white-space:pre-wrap), so raw tags would show up literally instead
* of as line breaks.
*/
private function cleanText(?string $value): string
{
if ($value === null || $value === '') {
return '';
}
$text = preg_replace('/<br\s*\/?>/i', "\n", $value);
$text = strip_tags($text);
$text = html_entity_decode($text, ENT_QUOTES | ENT_HTML5, 'UTF-8');
return trim($text);
}
private function loadState(): void
{
if (is_file($this->statePath)) {
$decoded = json_decode(file_get_contents($this->statePath), true);
$this->state = is_array($decoded) ? $decoded : $this->state;
$this->state['imported'] ??= [];
}
}
private function saveState(): void
{
$dir = dirname($this->statePath);
if (! is_dir($dir)) {
mkdir($dir, 0755, true);
}
file_put_contents($this->statePath, json_encode($this->state));
}
}

View File

@@ -0,0 +1,35 @@
<?php
namespace App\Console\Commands;
use App\Services\TicketAiSummaryService;
use App\Services\TicketAiTriageService;
use Illuminate\Console\Command;
class RunAiTicketAutomation extends Command
{
protected $signature = 'ai:run-ticket-automation';
protected $description = 'Run AI-driven ticket triage (categorize/prioritize new tickets) and refresh AI ticket summaries for the operator view';
public function handle(TicketAiTriageService $triage, TicketAiSummaryService $summary): int
{
$triageTotals = $triage->run();
$summaryTotals = $summary->run();
$this->info(sprintf(
'AI triage: scanned %d, changed %d, failed %d.',
$triageTotals['scanned'],
$triageTotals['changed'],
$triageTotals['failed'],
));
$this->info(sprintf(
'AI summaries: scanned %d, updated %d, failed %d.',
$summaryTotals['scanned'],
$summaryTotals['updated'],
$summaryTotals['failed'],
));
return self::SUCCESS;
}
}

View File

@@ -0,0 +1,80 @@
<?php
namespace App\Console\Commands;
use App\Models\AutomationRule;
use App\Models\AutomationRuleTicketLog;
use App\Models\Status;
use App\Models\Team;
use App\Models\Ticket;
use App\Models\User;
use App\Services\TicketService;
use Illuminate\Console\Command;
class RunAutomationRules extends Command
{
protected $signature = 'automation:run-rules';
protected $description = 'Apply enabled SLA automation rules to tickets that have been silent past their condition threshold';
public function handle(TicketService $tickets): int
{
$rules = AutomationRule::query()->where('enabled', true)->orderBy('id')->get();
$fired = 0;
foreach ($rules as $rule) {
$query = Ticket::query()->whereNotIn('status_key', Status::closedKeys());
if ($rule->scope_priority_key) {
$query->where('priority_key', $rule->scope_priority_key);
}
if ($rule->scope_subcategory_id) {
$query->where('subcategory_id', $rule->scope_subcategory_id);
}
if ($rule->scope_team_id) {
$query->where('team_id', $rule->scope_team_id);
}
$candidates = $query->get()->filter(function (Ticket $ticket) use ($rule) {
if ($rule->hasFiredFor($ticket)) {
return false;
}
$since = $ticket->last_customer_activity_at ?? $ticket->created_at;
// Carbon 3 defaults diffInMinutes() to a signed result (negative
// when $since is in the past) rather than always-absolute — be
// explicit, same trap as Ticket::secondsSinceTimerStarted().
return now()->diffInMinutes($since, absolute: true) >= $rule->condition_minutes;
});
foreach ($candidates as $ticket) {
$this->apply($tickets, $rule, $ticket);
$fired++;
}
}
$this->info("Ran automation rules: {$fired} action(s) applied.");
return self::SUCCESS;
}
protected function apply(TicketService $tickets, AutomationRule $rule, Ticket $ticket): void
{
match ($rule->action_type) {
'change_priority' => $tickets->setPriority($ticket, $rule->action_value),
'change_status' => $tickets->setStatus($ticket, $rule->action_value),
'change_team' => $tickets->setTeam($ticket, Team::query()->find($rule->action_value)),
'change_assignee' => $tickets->setAssignee($ticket, User::query()->find($rule->action_value)),
default => null,
};
$ticket->addHistory("Automatyzacja: {$rule->label}");
AutomationRuleTicketLog::query()->create([
'automation_rule_id' => $rule->id,
'ticket_id' => $ticket->id,
'triggered_at' => now(),
]);
}
}

View File

@@ -0,0 +1,47 @@
<?php
namespace App\Events;
use Illuminate\Broadcasting\Channel;
use Illuminate\Broadcasting\InteractsWithSockets;
use Illuminate\Broadcasting\PrivateChannel;
use Illuminate\Contracts\Broadcasting\ShouldBroadcastNow;
use Illuminate\Foundation\Events\Dispatchable;
/**
* Fired once per database (bell) notification actually created for a real
* user see the NotificationSent listener in AppServiceProvider::boot(),
* which is the single choke point that dispatches this regardless of which
* of the several TicketService call sites created the underlying
* notification. Drives both the realtime bell badge (NotificationBell) and,
* when the viewing browser has granted permission, an in-tab
* `Notification` API popup.
*/
class NotificationCreated implements ShouldBroadcastNow
{
use Dispatchable, InteractsWithSockets;
public function __construct(
public int $userId,
public string $notificationId,
public string $message,
public string $url,
) {}
/**
* @return array<int, Channel>
*/
public function broadcastOn(): array
{
return [new PrivateChannel('App.Models.User.'.$this->userId)];
}
public function broadcastWith(): array
{
return [
'notificationId' => $this->notificationId,
'message' => $this->message,
'url' => $this->url,
];
}
}

View File

@@ -0,0 +1,52 @@
<?php
namespace App\Events;
use Illuminate\Broadcasting\Channel;
use Illuminate\Broadcasting\InteractsWithSockets;
use Illuminate\Broadcasting\PrivateChannel;
use Illuminate\Contracts\Broadcasting\ShouldBroadcastNow;
use Illuminate\Foundation\Events\Dispatchable;
/**
* Fired on ticket.{id} whenever a new message (public reply, internal note,
* or API message) is posted drives the live message thread ("live chat")
* for both operator and client views of the same ticket.
*
* The payload deliberately never carries the message body, only metadata
* both public and internal messages broadcast on the same per-ticket
* channel, and a client subscriber must never be able to read an internal
* note's content from the socket frame itself. Each side's Livewire
* component only ever re-queries whatever its own already-authorized
* computed property returns (the client's never touches internalMessages()
* regardless of which event arrived), so this is safe by construction.
*/
class TicketMessagePosted implements ShouldBroadcastNow
{
use Dispatchable, InteractsWithSockets;
public function __construct(
public int $ticketId,
public int $messageId,
public bool $internal,
public ?int $actorId,
) {}
/**
* @return array<int, Channel>
*/
public function broadcastOn(): array
{
return [new PrivateChannel('ticket.'.$this->ticketId)];
}
public function broadcastWith(): array
{
return [
'ticketId' => $this->ticketId,
'messageId' => $this->messageId,
'internal' => $this->internal,
'actorId' => $this->actorId,
];
}
}

View File

@@ -0,0 +1,56 @@
<?php
namespace App\Events;
use Illuminate\Broadcasting\Channel;
use Illuminate\Broadcasting\InteractsWithSockets;
use Illuminate\Broadcasting\PrivateChannel;
use Illuminate\Contracts\Broadcasting\ShouldBroadcastNow;
use Illuminate\Foundation\Events\Dispatchable;
/**
* Fired on operator.queue whenever a ticket is created, changes in a way
* that affects the operator queue table (status/priority/team/assignee, or
* a new message bumping its updated_at, which the queue sorts by), or is
* deleted. Payload stays minimal the receiving Queue component just
* re-queries through its own already-correct visibleToOperator() scope
* rather than this event needing to encode per-viewer visibility itself.
*
* Also broadcast on the ticket's own channel, so a client (who can't
* subscribe to operator.queue at all see routes/channels.php) still sees
* status/priority/team/assignee changes live while viewing that one ticket.
*
* ShouldBroadcastNow (not ShouldBroadcast) this app runs with no queue
* worker by design (see TicketNotification), so broadcasts happen
* synchronously within the request like everything else here.
*/
class TicketQueueChanged implements ShouldBroadcastNow
{
use Dispatchable, InteractsWithSockets;
public function __construct(
public int $ticketId,
public string $reason,
public ?int $actorId,
) {}
/**
* @return array<int, Channel>
*/
public function broadcastOn(): array
{
return [
new PrivateChannel('operator.queue'),
new PrivateChannel('ticket.'.$this->ticketId),
];
}
public function broadcastWith(): array
{
return [
'ticketId' => $this->ticketId,
'reason' => $this->reason,
'actorId' => $this->actorId,
];
}
}

View File

@@ -0,0 +1,30 @@
<?php
namespace App\Jobs;
use App\Models\Ticket;
use App\Services\TicketAiSummaryService;
use Illuminate\Foundation\Bus\Dispatchable;
/**
* Deliberately NOT a queued job (no ShouldQueue) this app's queue worker
* is optional infrastructure (see install.md), so anything pushed onto the
* `jobs` table has no guarantee of ever being picked up. Dispatched with
* ::dispatchAfterResponse() instead, which runs it in-process right after
* the triggering HTTP/console response is sent, needing no worker at all.
*/
class GenerateTicketAiSummaryJob
{
use Dispatchable;
public function __construct(protected int $ticketId) {}
public function handle(TicketAiSummaryService $summary): void
{
$ticket = Ticket::find($this->ticketId);
if ($ticket) {
$summary->generateFor($ticket);
}
}
}

18
src/app/Ldap/AdUser.php Normal file
View File

@@ -0,0 +1,18 @@
<?php
namespace App\Ldap;
use LdapRecord\Models\ActiveDirectory\User as ActiveDirectoryUser;
/**
* Active Directory counterpart to LldapUser same role (the LdapRecord
* model backing the 'users' auth provider), but for AD's schema instead of
* LLDAP/OpenLDAP's. AD user objects carry objectClass top/person/
* organizationalPerson/user (no inetOrgPerson/posixAccount/mailAccount, so
* LldapUser's object-class scope matches zero AD entries) and expose a
* binary objectGUID rather than entryUUID both already handled correctly
* by LdapRecord's stock ActiveDirectory\User, so no overrides are needed
* here, only the swap in AppServiceProvider::applyLdapSettingsOverride()
* (driven by the ldap_directory_type setting).
*/
class AdUser extends ActiveDirectoryUser {}

View File

@@ -0,0 +1,335 @@
<?php
namespace App\Livewire\Admin;
use App\Models\Category;
use App\Models\ImapMailbox;
use App\Services\ImapMailboxFetcher;
use App\Support\Settings;
use Illuminate\Support\Collection;
use Illuminate\Support\Facades\Auth;
use Illuminate\Support\Facades\Config;
use Illuminate\Support\Facades\Mail;
use Livewire\Attributes\Computed;
use Livewire\Component;
/**
* SMTP (outbound) + IMAP mailboxes (inbound turns e-mails into tickets or
* replies) on their own dedicated admin page, split out of the generic
* "Integracje" grab-bag since IMAP is a repeatable list (N mailboxes) rather
* than a singleton config, and both halves of "reply by e-mail" belong
* together rather than split across tabs.
*/
class MailSettings extends Component
{
public array $mailConfig = [];
public ?string $mailTestResult = null;
public bool $mailboxFormOpen = false;
public array $mailboxForm = [
'id' => null,
'name' => '',
'enabled' => true,
'host' => '',
'port' => 993,
'encryption' => 'ssl',
'validateCert' => true,
'username' => '',
'password' => '',
'folder' => 'INBOX',
'processedFolder' => '',
'rejectedFolder' => '',
'target' => '',
'blocklistSenders' => 'mailer-daemon,postmaster,no-reply,noreply',
];
public ?int $mailboxTestResultId = null;
public ?string $mailboxTestResult = null;
public ?string $mailboxTestMessage = null;
public ?int $mailboxFetchResultId = null;
public ?string $mailboxFetchSummary = null;
public function mount(): void
{
$this->mailConfig = [
'smtpEnabled' => Settings::bool('mail_smtp_enabled'),
'smtpHost' => Settings::get('mail_smtp_host'),
'smtpPort' => Settings::get('mail_smtp_port'),
'smtpUsername' => Settings::get('mail_smtp_username'),
'smtpPassword' => Settings::get('mail_smtp_password'),
'smtpEncryption' => Settings::get('mail_smtp_encryption'),
'fromAddress' => Settings::get('mail_from_address'),
'fromName' => Settings::get('mail_from_name'),
];
}
#[Computed]
public function mailboxes(): Collection
{
return ImapMailbox::query()->with(['defaultSubcategory.category', 'defaultCategory'])->orderBy('name')->get();
}
/**
* Categories with their subcategories nested, for the mailbox form's
* single combined "cała kategoria albo konkretna podkategoria" selector.
*/
#[Computed]
public function categoryOptions(): Collection
{
return Category::query()->with('subcategories')->orderBy('name')->get()
->map(fn (Category $c) => [
'id' => $c->id,
'name' => $c->name,
'subcategories' => $c->subcategories->map(fn ($s) => ['id' => $s->id, 'name' => $s->name])->values(),
])
->values();
}
// ===================== SMTP =====================
public function saveMailConfig(): void
{
Settings::set('mail_smtp_enabled', $this->mailConfig['smtpEnabled'] ? '1' : '0');
Settings::set('mail_smtp_host', $this->mailConfig['smtpHost']);
Settings::set('mail_smtp_port', (string) $this->mailConfig['smtpPort']);
Settings::set('mail_smtp_username', $this->mailConfig['smtpUsername']);
if ($this->mailConfig['smtpPassword']) {
Settings::set('mail_smtp_password', $this->mailConfig['smtpPassword']);
}
Settings::set('mail_smtp_encryption', $this->mailConfig['smtpEncryption']);
Settings::set('mail_from_address', $this->mailConfig['fromAddress']);
Settings::set('mail_from_name', $this->mailConfig['fromName']);
$this->mailTestResult = null;
}
/**
* Sends a real test e-mail to the logged-in admin using the form's
* current (unsaved) values, temporarily overriding the mail config the
* same way AppServiceProvider does for real once saved.
*/
public function testMailConnection(): void
{
$cfg = $this->mailConfig;
if (empty($cfg['smtpHost']) || empty($cfg['fromAddress'])) {
$this->mailTestResult = 'error';
return;
}
$original = Config::get('mail');
try {
Config::set('mail.default', 'smtp');
Config::set('mail.mailers.smtp.host', $cfg['smtpHost']);
Config::set('mail.mailers.smtp.port', (int) $cfg['smtpPort']);
Config::set('mail.mailers.smtp.username', $cfg['smtpUsername'] ?: null);
Config::set('mail.mailers.smtp.password', $cfg['smtpPassword'] ?: Settings::get('mail_smtp_password'));
Config::set('mail.mailers.smtp.scheme', match ($cfg['smtpEncryption']) {
'ssl' => 'smtps',
'tls' => 'smtp',
default => null,
});
Config::set('mail.from.address', $cfg['fromAddress']);
Config::set('mail.from.name', $cfg['fromName'] ?: Settings::get('company_name'));
app()->forgetInstance('mail.manager');
app()->forgetInstance('mailer');
Mail::raw('To jest testowa wiadomość wysłana z panelu administratora Servicedesk.', function ($message) {
$message->to(Auth::user()->email)->subject('Test konfiguracji SMTP');
});
$this->mailTestResult = 'ok';
} catch (\Throwable) {
$this->mailTestResult = 'error';
} finally {
Config::set('mail', $original);
app()->forgetInstance('mail.manager');
app()->forgetInstance('mailer');
}
}
// ===================== IMAP MAILBOXES =====================
public function openMailboxForm(): void
{
$this->reset('mailboxForm');
$this->mailboxForm = [
'id' => null,
'name' => '',
'enabled' => true,
'host' => '',
'port' => 993,
'encryption' => 'ssl',
'validateCert' => true,
'username' => '',
'password' => '',
'folder' => 'INBOX',
'processedFolder' => '',
'rejectedFolder' => '',
'target' => '',
'blocklistSenders' => 'mailer-daemon,postmaster,no-reply,noreply',
];
$this->mailboxTestResultId = null;
$this->resetErrorBag();
$this->mailboxFormOpen = true;
}
public function editMailbox(int $id): void
{
$mailbox = ImapMailbox::query()->findOrFail($id);
$target = match (true) {
(bool) $mailbox->default_subcategory_id => "subcategory:{$mailbox->default_subcategory_id}",
(bool) $mailbox->default_category_id => "category:{$mailbox->default_category_id}",
default => '',
};
$this->mailboxForm = [
'id' => $mailbox->id,
'name' => $mailbox->name,
'enabled' => $mailbox->enabled,
'host' => $mailbox->host,
'port' => $mailbox->port,
'encryption' => $mailbox->encryption,
'validateCert' => $mailbox->validate_cert,
'username' => $mailbox->username,
'password' => $mailbox->password,
'folder' => $mailbox->folder,
'processedFolder' => $mailbox->processed_folder,
'rejectedFolder' => $mailbox->rejected_folder,
'target' => $target,
'blocklistSenders' => $mailbox->blocklist_senders,
];
$this->mailboxTestResultId = null;
$this->resetErrorBag();
$this->mailboxFormOpen = true;
}
public function closeMailboxForm(): void
{
$this->mailboxFormOpen = false;
}
public function submitMailboxForm(): void
{
$this->validate([
'mailboxForm.name' => ['required', 'string', 'max:255'],
'mailboxForm.host' => ['required', 'string', 'max:255'],
'mailboxForm.port' => ['required', 'integer', 'min:1', 'max:65535'],
'mailboxForm.encryption' => ['required', 'in:ssl,tls,none'],
'mailboxForm.username' => ['required', 'string', 'max:255'],
'mailboxForm.folder' => ['required', 'string', 'max:255'],
]);
[$targetType, $targetId] = str_contains((string) $this->mailboxForm['target'], ':')
? explode(':', $this->mailboxForm['target'], 2)
: [null, null];
$data = [
'name' => $this->mailboxForm['name'],
'enabled' => (bool) $this->mailboxForm['enabled'],
'host' => $this->mailboxForm['host'],
'port' => (int) $this->mailboxForm['port'],
'encryption' => $this->mailboxForm['encryption'],
'validate_cert' => (bool) $this->mailboxForm['validateCert'],
'username' => $this->mailboxForm['username'],
'folder' => $this->mailboxForm['folder'],
'processed_folder' => $this->mailboxForm['processedFolder'] ?: null,
'rejected_folder' => $this->mailboxForm['rejectedFolder'] ?: null,
// Exactly one of these (or neither) — never both — driven by the
// form's single "cała kategoria albo konkretna podkategoria" selector.
'default_subcategory_id' => $targetType === 'subcategory' ? $targetId : null,
'default_category_id' => $targetType === 'category' ? $targetId : null,
'blocklist_senders' => $this->mailboxForm['blocklistSenders'],
];
$mailbox = ImapMailbox::query()->find($this->mailboxForm['id']);
if ($mailbox) {
if ($this->mailboxForm['password']) {
$data['password'] = $this->mailboxForm['password'];
}
$mailbox->update($data);
} else {
$data['password'] = $this->mailboxForm['password'];
ImapMailbox::query()->create($data);
}
$this->mailboxFormOpen = false;
unset($this->mailboxes);
}
public function toggleMailboxEnabled(int $id): void
{
$mailbox = ImapMailbox::query()->findOrFail($id);
$mailbox->update(['enabled' => ! $mailbox->enabled]);
unset($this->mailboxes);
}
public function removeMailbox(int $id): void
{
ImapMailbox::query()->findOrFail($id)->delete();
unset($this->mailboxes);
}
/**
* Runs a real fetch against one mailbox right now, outside the 5-minute
* schedule for checking a freshly-configured mailbox without waiting,
* and for diagnosing "why didn't my e-mail turn into a ticket" without
* needing shell access. Allowed even while the mailbox is disabled
* (fetchAll(), used by the scheduled command, is the one that respects
* the enabled flag this is an explicit admin action).
*/
public function fetchMailboxNow(int $id): void
{
$mailbox = ImapMailbox::query()->findOrFail($id);
$result = app(ImapMailboxFetcher::class)->fetchMailbox($mailbox);
$this->mailboxFetchResultId = $id;
$this->mailboxFetchSummary = "Nowe: {$result['created']}, odpowiedzi: {$result['replied']}, odrzucone: {$result['rejected']}, błędy: {$result['errors']}.";
unset($this->mailboxes);
}
/**
* Tests the form's current (unsaved) values against a throwaway
* ImapMailbox instance mirrors testMailConnection()'s "don't require a
* save first" behavior. Falls back to the stored password when editing
* an existing mailbox and the password field was left blank.
*/
public function testMailboxConnection(): void
{
$mailbox = new ImapMailbox([
'host' => $this->mailboxForm['host'],
'port' => (int) $this->mailboxForm['port'],
'encryption' => $this->mailboxForm['encryption'],
'validate_cert' => (bool) $this->mailboxForm['validateCert'],
'username' => $this->mailboxForm['username'],
'folder' => $this->mailboxForm['folder'] ?: 'INBOX',
]);
$mailbox->password = $this->mailboxForm['password']
?: ($this->mailboxForm['id'] ? ImapMailbox::query()->find($this->mailboxForm['id'])?->password : null);
$error = app(ImapMailboxFetcher::class)->testConnection($mailbox);
$this->mailboxTestResultId = (int) ($this->mailboxForm['id'] ?? 0);
$this->mailboxTestResult = $error === null ? 'ok' : 'error';
$this->mailboxTestMessage = $error;
}
public function render()
{
return view('livewire.admin.mail-settings');
}
}

View File

@@ -2,6 +2,7 @@
namespace App\Livewire\Admin;
use App\Models\AutomationRule;
use App\Models\Category;
use App\Models\CustomField;
use App\Models\EmailTemplate;
@@ -13,18 +14,21 @@ use App\Models\SlaRule;
use App\Models\Status;
use App\Models\Subcategory;
use App\Models\Team;
use App\Models\Ticket;
use App\Models\User;
use App\Models\UserField;
use App\Services\AiClient;
use App\Services\BookStackClient;
use App\Services\BookStackContentTagger;
use App\Services\LdapUserProvisioner;
use App\Services\SnipeItClient;
use App\Support\Settings;
use Illuminate\Support\Collection;
use Illuminate\Support\Facades\Auth;
use Illuminate\Support\Facades\Config;
use Illuminate\Support\Facades\Mail;
use Illuminate\Support\Facades\Storage;
use LdapRecord\Connection;
use Livewire\Attributes\Computed;
use Livewire\Attributes\Url;
use Livewire\Component;
use Livewire\WithFileUploads;
@@ -32,6 +36,7 @@ class Panel extends Component
{
use WithFileUploads;
#[Url]
public string $tab = 'categories';
// ---- categories ----
@@ -100,6 +105,15 @@ class Panel extends Component
public array $responseTemplateForm = ['id' => null, 'label' => '', 'body' => ''];
// ---- automation rules ----
public bool $automationRuleFormOpen = false;
public array $automationRuleForm = [
'id' => null, 'label' => '', 'enabled' => true, 'condition_minutes' => 60,
'scope_priority_key' => '', 'scope_subcategory_id' => '', 'scope_team_id' => '',
'action_type' => 'change_priority', 'action_value' => '',
];
// ---- templates ----
public ?int $editingTemplateId = null;
@@ -135,16 +149,38 @@ class Panel extends Component
public ?string $ldapTestResult = null;
public array $mailConfig = [];
public ?string $mailTestResult = null;
public array $bookstackConfig = [];
public ?string $bookstackTestResult = null;
public ?string $bookstackTestMessage = null;
public ?array $bookstackTagResult = null;
public ?string $bookstackTagError = null;
public array $snipeitConfig = [];
public ?string $snipeitTestResult = null;
public ?string $snipeitTestMessage = null;
public array $aiConfig = [];
public ?string $aiTestResult = null;
public ?string $aiTestMessage = null;
public array $aiTriageConfig = [];
public bool $aiSummaryEnabled = false;
public bool $aiSummaryRegenerateOnMessage = false;
public string $aiSummaryPrompt = '';
public int $aiSummaryPromptVersion = 0;
// ---- generic pending-delete confirm ----
public ?string $pendingDeleteType = null;
@@ -169,10 +205,21 @@ class Panel extends Component
'attachmentAllowedTypes' => Settings::get('attachment_allowed_types'),
'sessionLifetimeMinutes' => Settings::get('session_lifetime_minutes'),
'timezone' => Settings::timezone(),
'ticketNumberPrefix' => Settings::get('ticket_number_prefix'),
'ticketNumberObfuscate' => Settings::bool('ticket_number_obfuscate'),
'ticketNumberMinLength' => Settings::get('ticket_number_min_length'),
'refreshTicketViewSeconds' => Settings::get('refresh_ticket_view_seconds'),
'refreshQueueSeconds' => Settings::get('refresh_queue_seconds'),
'refreshNotificationsSeconds' => Settings::get('refresh_notifications_seconds'),
'scheduleSlaCheckMinutes' => Settings::get('schedule_sla_check_minutes'),
'scheduleAutomationRulesMinutes' => Settings::get('schedule_automation_rules_minutes'),
'scheduleImapFetchMinutes' => Settings::get('schedule_imap_fetch_minutes'),
'scheduleAiAutomationMinutes' => Settings::get('schedule_ai_automation_minutes'),
];
$this->ldapConfig = [
'enabled' => Settings::bool('ldap_enabled'),
'directoryType' => Settings::get('ldap_directory_type', 'lldap'),
'host' => Settings::get('ldap_host'),
'port' => Settings::get('ldap_port'),
'baseDn' => Settings::get('ldap_base_dn'),
@@ -185,17 +232,6 @@ class Panel extends Component
'restrictTicketsToLdap' => Settings::bool('restrict_tickets_to_ldap'),
];
$this->mailConfig = [
'smtpEnabled' => Settings::bool('mail_smtp_enabled'),
'smtpHost' => Settings::get('mail_smtp_host'),
'smtpPort' => Settings::get('mail_smtp_port'),
'smtpUsername' => Settings::get('mail_smtp_username'),
'smtpPassword' => Settings::get('mail_smtp_password'),
'smtpEncryption' => Settings::get('mail_smtp_encryption'),
'fromAddress' => Settings::get('mail_from_address'),
'fromName' => Settings::get('mail_from_name'),
];
$this->bookstackConfig = [
'enabled' => Settings::bool('bookstack_enabled'),
'baseUrl' => Settings::get('bookstack_base_url'),
@@ -203,10 +239,41 @@ class Panel extends Component
'tokenSecret' => Settings::get('bookstack_token_secret'),
'verifySsl' => Settings::bool('bookstack_verify_ssl'),
'showToGuests' => Settings::bool('bookstack_show_to_guests'),
'searchTypes' => Settings::get('bookstack_search_types', 'both'),
'searchTypes' => BookStackClient::normalizeSearchTypes(Settings::get('bookstack_search_types', '')),
'searchBy' => in_array($searchBy = Settings::get('bookstack_search_by', 'both'), BookStackClient::SEARCH_BY_OPTIONS, true) ? $searchBy : 'both',
'allowedShelfIdsCreation' => $this->parseShelfIds(Settings::get('bookstack_allowed_shelf_ids_creation', '')),
'allowedShelfIdsTicketView' => $this->parseShelfIds(Settings::get('bookstack_allowed_shelf_ids_ticket_view', '')),
];
$this->snipeitConfig = [
'enabled' => Settings::bool('snipeit_enabled'),
'baseUrl' => Settings::get('snipeit_base_url'),
'apiToken' => Settings::get('snipeit_api_token'),
'skipSslVerification' => ! Settings::bool('snipeit_verify_ssl'),
'clientCanSelectAsset' => Settings::bool('snipeit_client_can_select_asset'),
'clientAssetSubcategoryIds' => $this->parseShelfIds(Settings::get('snipeit_client_asset_subcategory_ids', '')),
'operatorViewRequesterAssets' => Settings::bool('snipeit_operator_view_requester_assets'),
'operatorSearchInventory' => Settings::bool('snipeit_operator_search_inventory'),
];
$this->aiConfig = [
'enabled' => Settings::bool('ai_enabled'),
'baseUrl' => Settings::get('ai_base_url'),
'apiKey' => Settings::get('ai_api_key'),
'model' => Settings::get('ai_model'),
'verifySsl' => Settings::bool('ai_verify_ssl'),
];
$this->aiTriageConfig = [
'categoryWhenMissing' => Settings::bool('ai_triage_category_when_missing'),
'subcategoryWhenCategoryOnly' => Settings::bool('ai_triage_subcategory_when_category_only'),
'recheckCategorized' => Settings::bool('ai_triage_recheck_categorized'),
'fixSubject' => Settings::bool('ai_triage_fix_subject'),
'setPriority' => Settings::bool('ai_triage_set_priority'),
];
$this->aiSummaryEnabled = Settings::bool('ai_summary_enabled');
$this->aiSummaryRegenerateOnMessage = Settings::bool('ai_summary_regenerate_on_message');
$this->aiSummaryPrompt = Settings::get('ai_summary_prompt');
}
public function setTab(string $tab): void
@@ -271,10 +338,55 @@ class Panel extends Component
return;
}
Category::query()->find($categoryId)?->subcategories()->create(['name' => $name]);
$category = Category::query()->find($categoryId);
if (! $category) {
return;
}
$nextPosition = ((int) $category->subcategories()->max('sort_order')) + 1;
$category->subcategories()->create(['name' => $name, 'sort_order' => $nextPosition]);
$this->newSubNames[$categoryId] = '';
}
public function moveSubcategoryUp(int $subcategoryId): void
{
$this->swapSubcategoryOrder($subcategoryId, -1);
}
public function moveSubcategoryDown(int $subcategoryId): void
{
$this->swapSubcategoryOrder($subcategoryId, 1);
}
protected function swapSubcategoryOrder(int $subcategoryId, int $direction): void
{
$sub = Subcategory::query()->find($subcategoryId);
if (! $sub) {
return;
}
$siblings = Subcategory::query()
->where('category_id', $sub->category_id)
->orderBy('sort_order')
->orderBy('id')
->get();
$idx = $siblings->search(fn (Subcategory $s) => $s->id === $sub->id);
$swapIdx = $idx + $direction;
if ($idx === false || $swapIdx < 0 || $swapIdx >= $siblings->count()) {
return;
}
$other = $siblings[$swapIdx];
[$order, $otherOrder] = [$sub->sort_order, $other->sort_order];
$sub->update(['sort_order' => $otherOrder]);
$other->update(['sort_order' => $order]);
}
public function openSubcategoryEditForm(int $subcategoryId): void
{
$sub = Subcategory::query()->with('customFields')->findOrFail($subcategoryId);
@@ -854,6 +966,96 @@ class Panel extends Component
$this->requestDelete('response-template', $id, 'Szablon odpowiedzi zostanie usunięty z listy dostępnej operatorom.');
}
// ===================== AUTOMATION RULES =====================
#[Computed]
public function automationRules()
{
return AutomationRule::query()->orderBy('id')->get();
}
public function openAutomationRuleForm(): void
{
$this->automationRuleForm = [
'id' => null, 'label' => '', 'enabled' => true, 'condition_minutes' => 60,
'scope_priority_key' => '', 'scope_subcategory_id' => '', 'scope_team_id' => '',
'action_type' => 'change_priority', 'action_value' => '',
];
$this->automationRuleFormOpen = true;
}
public function editAutomationRule(int $id): void
{
$rule = AutomationRule::query()->findOrFail($id);
$this->automationRuleForm = [
'id' => $rule->id,
'label' => $rule->label,
'enabled' => $rule->enabled,
'condition_minutes' => $rule->condition_minutes,
'scope_priority_key' => $rule->scope_priority_key ?? '',
'scope_subcategory_id' => $rule->scope_subcategory_id ?? '',
'scope_team_id' => $rule->scope_team_id ?? '',
'action_type' => $rule->action_type,
'action_value' => $rule->action_value,
];
$this->automationRuleFormOpen = true;
}
public function closeAutomationRuleForm(): void
{
$this->automationRuleFormOpen = false;
}
// Switching action_type invalidates whichever action_value was picked for
// the previous type (e.g. a priority key isn't a valid team id).
public function updatedAutomationRuleFormActionType(): void
{
$this->automationRuleForm['action_value'] = '';
}
public function submitAutomationRule(): void
{
$this->validate([
'automationRuleForm.label' => 'required|string|max:255',
'automationRuleForm.condition_minutes' => 'required|integer|min:1',
'automationRuleForm.action_type' => 'required|in:'.implode(',', AutomationRule::ACTION_TYPES),
'automationRuleForm.action_value' => 'required|string',
]);
$data = [
'label' => $this->automationRuleForm['label'],
'enabled' => (bool) $this->automationRuleForm['enabled'],
'condition_minutes' => (int) $this->automationRuleForm['condition_minutes'],
'scope_priority_key' => $this->automationRuleForm['scope_priority_key'] ?: null,
'scope_subcategory_id' => $this->automationRuleForm['scope_subcategory_id'] ?: null,
'scope_team_id' => $this->automationRuleForm['scope_team_id'] ?: null,
'action_type' => $this->automationRuleForm['action_type'],
'action_value' => $this->automationRuleForm['action_value'],
];
if ($this->automationRuleForm['id']) {
AutomationRule::query()->find($this->automationRuleForm['id'])?->update($data);
} else {
AutomationRule::query()->create($data);
}
$this->automationRuleFormOpen = false;
unset($this->automationRules);
}
public function toggleAutomationRuleEnabled(int $id): void
{
$rule = AutomationRule::query()->find($id);
$rule?->update(['enabled' => ! $rule->enabled]);
unset($this->automationRules);
}
public function removeAutomationRule(int $id): void
{
$this->requestDelete('automation-rule', $id, 'Reguła automatyzacji zostanie usunięta.');
}
// ===================== STATUSES / PRIORITIES =====================
#[Computed]
@@ -1255,6 +1457,41 @@ class Panel extends Component
if (in_array($this->systemConfig['timezone'], \DateTimeZone::listIdentifiers(), true)) {
Settings::set('timezone', $this->systemConfig['timezone']);
}
Settings::set('ticket_number_prefix', trim((string) $this->systemConfig['ticketNumberPrefix']));
Settings::set('ticket_number_obfuscate', $this->systemConfig['ticketNumberObfuscate'] ? '1' : '0');
Settings::set('ticket_number_min_length', (string) max(1, (int) $this->systemConfig['ticketNumberMinLength']));
Settings::set('refresh_ticket_view_seconds', (string) max(1, (int) $this->systemConfig['refreshTicketViewSeconds']));
Settings::set('refresh_queue_seconds', (string) max(1, (int) $this->systemConfig['refreshQueueSeconds']));
Settings::set('refresh_notifications_seconds', (string) max(1, (int) $this->systemConfig['refreshNotificationsSeconds']));
Settings::set('schedule_sla_check_minutes', (string) max(1, (int) $this->systemConfig['scheduleSlaCheckMinutes']));
Settings::set('schedule_automation_rules_minutes', (string) max(1, (int) $this->systemConfig['scheduleAutomationRulesMinutes']));
Settings::set('schedule_imap_fetch_minutes', (string) max(1, (int) $this->systemConfig['scheduleImapFetchMinutes']));
Settings::set('schedule_ai_automation_minutes', (string) max(1, (int) $this->systemConfig['scheduleAiAutomationMinutes']));
}
/**
* Live preview for the "Numeracja zgłoszeń" settings renders a real
* ticket's id/number against the form's current (not-yet-saved) values,
* so the admin sees exactly how numbers will look before hitting Zapisz.
*/
#[Computed]
public function ticketNumberPreview(): array
{
$ticket = Ticket::query()->latest('id')->first();
$id = $ticket->id ?? 1;
$raw = $ticket->number ?? '1001';
$checksum = $ticket->checksum ?? Ticket::generateUniqueChecksum($id);
$obfuscate = (bool) ($this->systemConfig['ticketNumberObfuscate'] ?? false);
$minLength = max(1, (int) ($this->systemConfig['ticketNumberMinLength'] ?? 4));
$number = $obfuscate ? $checksum : str_pad($raw, $minLength, '0', STR_PAD_LEFT);
return [
'id' => $id,
'formatted' => trim((string) ($this->systemConfig['ticketNumberPrefix'] ?? '')).$number,
];
}
// ===================== LDAP CONFIG =====================
@@ -1262,6 +1499,7 @@ class Panel extends Component
public function saveLdapConfig(): void
{
Settings::set('ldap_enabled', $this->ldapConfig['enabled'] ? '1' : '0');
Settings::set('ldap_directory_type', $this->ldapConfig['directoryType'] === 'ad' ? 'ad' : 'lldap');
Settings::set('ldap_host', $this->ldapConfig['host']);
Settings::set('ldap_port', (string) $this->ldapConfig['port']);
Settings::set('ldap_base_dn', $this->ldapConfig['baseDn']);
@@ -1323,8 +1561,10 @@ class Panel extends Component
Settings::set('bookstack_verify_ssl', $this->bookstackConfig['verifySsl'] ? '1' : '0');
Settings::set('bookstack_show_to_guests', $this->bookstackConfig['showToGuests'] ? '1' : '0');
if (in_array($this->bookstackConfig['searchTypes'], ['both', 'page', 'book'], true)) {
Settings::set('bookstack_search_types', $this->bookstackConfig['searchTypes']);
Settings::set('bookstack_search_types', implode(',', BookStackClient::normalizeSearchTypes($this->bookstackConfig['searchTypes'])));
if (in_array($this->bookstackConfig['searchBy'], BookStackClient::SEARCH_BY_OPTIONS, true)) {
Settings::set('bookstack_search_by', $this->bookstackConfig['searchBy']);
}
Settings::set('bookstack_allowed_shelf_ids_creation', implode(',', $this->bookstackConfig['allowedShelfIdsCreation']));
@@ -1374,6 +1614,15 @@ class Panel extends Component
: [...$ids, $id];
}
public function toggleBookstackSearchType(string $type): void
{
$types = $this->bookstackConfig['searchTypes'];
$this->bookstackConfig['searchTypes'] = in_array($type, $types, true)
? array_values(array_diff($types, [$type]))
: [...$types, $type];
}
public function testBookstackConnection(): void
{
$cfg = $this->bookstackConfig;
@@ -1392,73 +1641,140 @@ class Panel extends Component
$this->bookstackTestMessage = $result['message'];
}
// ===================== MAIL / SMTP CONFIG =====================
public function saveMailConfig(): void
{
Settings::set('mail_smtp_enabled', $this->mailConfig['smtpEnabled'] ? '1' : '0');
Settings::set('mail_smtp_host', $this->mailConfig['smtpHost']);
Settings::set('mail_smtp_port', (string) $this->mailConfig['smtpPort']);
Settings::set('mail_smtp_username', $this->mailConfig['smtpUsername']);
if ($this->mailConfig['smtpPassword']) {
Settings::set('mail_smtp_password', $this->mailConfig['smtpPassword']);
}
Settings::set('mail_smtp_encryption', $this->mailConfig['smtpEncryption']);
Settings::set('mail_from_address', $this->mailConfig['fromAddress']);
Settings::set('mail_from_name', $this->mailConfig['fromName']);
$this->mailTestResult = null;
}
/**
* Sends a real test e-mail to the logged-in admin using the form's
* current (unsaved) values, temporarily overriding the mail config the
* same way AppServiceProvider does for real once saved so this test
* exercises the exact path production notifications will use.
* Runs synchronously in the request (no queue worker runs in this
* deployment see CLAUDE.md so a dispatched job would just sit in the
* `jobs` table). Safe to click again if it times out on a large wiki:
* every write is idempotent, so a re-run just skips whatever already got
* tagged (or, for the --force variant, re-classifies from scratch).
*/
public function testMailConnection(): void
public function runBookstackTagging(bool $force = false): void
{
$cfg = $this->mailConfig;
if (empty($cfg['smtpHost']) || empty($cfg['fromAddress'])) {
$this->mailTestResult = 'error';
if (! app(BookStackClient::class)->enabled() || ! app(AiClient::class)->enabled()) {
$this->bookstackTagResult = null;
$this->bookstackTagError = 'Włącz i skonfiguruj obie integracje — BookStack oraz AI — przed uruchomieniem tagowania.';
return;
}
$original = Config::get('mail');
$this->bookstackTagError = null;
try {
Config::set('mail.default', 'smtp');
Config::set('mail.mailers.smtp.host', $cfg['smtpHost']);
Config::set('mail.mailers.smtp.port', (int) $cfg['smtpPort']);
Config::set('mail.mailers.smtp.username', $cfg['smtpUsername'] ?: null);
Config::set('mail.mailers.smtp.password', $cfg['smtpPassword'] ?: Settings::get('mail_smtp_password'));
Config::set('mail.mailers.smtp.scheme', match ($cfg['smtpEncryption']) {
'ssl' => 'smtps',
'tls' => 'smtp',
default => null,
});
Config::set('mail.from.address', $cfg['fromAddress']);
Config::set('mail.from.name', $cfg['fromName'] ?: Settings::get('company_name'));
set_time_limit(0);
$this->bookstackTagResult = app(BookStackContentTagger::class)->run(force: $force);
}
app()->forgetInstance('mail.manager');
app()->forgetInstance('mailer');
public function runBookstackTaggingForce(): void
{
$this->runBookstackTagging(force: true);
}
Mail::raw('To jest testowa wiadomość wysłana z panelu administratora Servicedesk.', function ($message) {
$message->to(Auth::user()->email)->subject('Test konfiguracji SMTP');
});
// ===================== SNIPE-IT CONFIG =====================
$this->mailTestResult = 'ok';
} catch (\Throwable) {
$this->mailTestResult = 'error';
} finally {
Config::set('mail', $original);
app()->forgetInstance('mail.manager');
app()->forgetInstance('mailer');
public function saveSnipeitConfig(): void
{
Settings::set('snipeit_enabled', $this->snipeitConfig['enabled'] ? '1' : '0');
Settings::set('snipeit_base_url', $this->snipeitConfig['baseUrl']);
if ($this->snipeitConfig['apiToken']) {
Settings::set('snipeit_api_token', $this->snipeitConfig['apiToken']);
}
Settings::set('snipeit_verify_ssl', $this->snipeitConfig['skipSslVerification'] ? '0' : '1');
Settings::set('snipeit_client_can_select_asset', $this->snipeitConfig['clientCanSelectAsset'] ? '1' : '0');
Settings::set('snipeit_client_asset_subcategory_ids', implode(',', $this->snipeitConfig['clientAssetSubcategoryIds']));
Settings::set('snipeit_operator_view_requester_assets', $this->snipeitConfig['operatorViewRequesterAssets'] ? '1' : '0');
Settings::set('snipeit_operator_search_inventory', $this->snipeitConfig['operatorSearchInventory'] ? '1' : '0');
$this->snipeitTestResult = null;
$this->snipeitTestMessage = null;
}
public function toggleSnipeitClientSubcategory(int $id): void
{
$ids = $this->snipeitConfig['clientAssetSubcategoryIds'];
$this->snipeitConfig['clientAssetSubcategoryIds'] = in_array($id, $ids, true)
? array_values(array_diff($ids, [$id]))
: [...$ids, $id];
}
public function testSnipeitConnection(): void
{
$cfg = $this->snipeitConfig;
if (empty($cfg['baseUrl'])) {
$this->snipeitTestResult = 'error';
$this->snipeitTestMessage = 'Uzupełnij adres API.';
return;
}
$token = $cfg['apiToken'] ?: Settings::get('snipeit_api_token');
$result = app(SnipeItClient::class)->testConnection($cfg['baseUrl'], $token ?? '', ! $cfg['skipSslVerification']);
$this->snipeitTestResult = $result['ok'] ? 'ok' : 'error';
$this->snipeitTestMessage = $result['message'];
}
// ===================== AI CONFIG =====================
public function saveAiConfig(): void
{
Settings::set('ai_enabled', $this->aiConfig['enabled'] ? '1' : '0');
Settings::set('ai_base_url', $this->aiConfig['baseUrl']);
if ($this->aiConfig['apiKey']) {
Settings::set('ai_api_key', $this->aiConfig['apiKey']);
}
Settings::set('ai_model', $this->aiConfig['model']);
Settings::set('ai_verify_ssl', $this->aiConfig['verifySsl'] ? '1' : '0');
$this->aiTestResult = null;
$this->aiTestMessage = null;
}
public function testAiConnection(): void
{
$cfg = $this->aiConfig;
if (empty($cfg['baseUrl']) || empty($cfg['model'])) {
$this->aiTestResult = 'error';
$this->aiTestMessage = 'Uzupełnij adres API i nazwę modelu.';
return;
}
$apiKey = $cfg['apiKey'] ?: Settings::get('ai_api_key');
$result = app(AiClient::class)->testConnection($cfg['baseUrl'], $apiKey ?? '', $cfg['model'], (bool) $cfg['verifySsl']);
$this->aiTestResult = $result['ok'] ? 'ok' : 'error';
$this->aiTestMessage = $result['message'];
}
public function saveAiTriageConfig(): void
{
Settings::set('ai_triage_category_when_missing', $this->aiTriageConfig['categoryWhenMissing'] ? '1' : '0');
Settings::set('ai_triage_subcategory_when_category_only', $this->aiTriageConfig['subcategoryWhenCategoryOnly'] ? '1' : '0');
Settings::set('ai_triage_recheck_categorized', $this->aiTriageConfig['recheckCategorized'] ? '1' : '0');
Settings::set('ai_triage_fix_subject', $this->aiTriageConfig['fixSubject'] ? '1' : '0');
Settings::set('ai_triage_set_priority', $this->aiTriageConfig['setPriority'] ? '1' : '0');
Settings::set('ai_summary_enabled', $this->aiSummaryEnabled ? '1' : '0');
Settings::set('ai_summary_regenerate_on_message', $this->aiSummaryRegenerateOnMessage ? '1' : '0');
}
public function saveAiSummaryPrompt(string $value): void
{
Settings::set('ai_summary_prompt', $value);
$this->aiSummaryPrompt = $value;
}
public function resetAiSummaryPrompt(): void
{
$default = Settings::default('ai_summary_prompt');
Settings::set('ai_summary_prompt', $default);
$this->aiSummaryPrompt = $default;
$this->aiSummaryPromptVersion++;
}
// ===================== GENERIC DELETE CONFIRM =====================
@@ -1491,16 +1807,46 @@ class Panel extends Component
'user-field' => UserField::query()->find($this->pendingDeleteId)?->delete(),
'reply-quick-action' => ReplyQuickAction::query()->find($this->pendingDeleteId)?->delete(),
'response-template' => ResponseTemplate::query()->find($this->pendingDeleteId)?->delete(),
'automation-rule' => AutomationRule::query()->find($this->pendingDeleteId)?->delete(),
default => null,
};
unset($this->categories, $this->customFields, $this->statuses, $this->priorities, $this->teams, $this->users, $this->userFields, $this->replyQuickActions, $this->responseTemplates, $this->notificationSettings);
unset($this->categories, $this->customFields, $this->statuses, $this->priorities, $this->teams, $this->users, $this->userFields, $this->replyQuickActions, $this->responseTemplates, $this->notificationSettings, $this->automationRules);
$this->cancelPendingDelete();
}
/**
* Mirrors the labels in the $tabGroups array built inline in
* admin/panel.blade.php (icons/grouping live only there this is just
* the page-title-sized subset, not worth threading the whole structure
* through the PHP side for).
*/
private const TAB_LABELS = [
'categories' => 'Kategorie',
'fields' => 'Pola dodatkowe',
'statuses' => 'Statusy',
'priorities' => 'Priorytety i SLA',
'reply-quick-actions' => 'Szybkie akcje odpowiedzi',
'response-templates' => 'Szablony odpowiedzi',
'automation-rules' => 'Automatyzacja SLA',
'triggers' => 'Wyzwalacze',
'users' => 'Użytkownicy',
'teams' => 'Zespoły',
'user-fields' => 'Pola dodatkowe',
'templates' => 'Szablony e-mail',
'email' => 'Poczta',
'branding' => 'Wygląd i branding',
'config' => 'Konfiguracja',
'integrations' => 'Integracje',
'api-keys' => 'Klucze API',
'about' => 'O aplikacji',
];
public function render()
{
return view('livewire.admin.panel');
$tabLabel = self::TAB_LABELS[$this->tab] ?? 'Panel administratora';
return view('livewire.admin.panel')->title(Settings::pageTitle($tabLabel));
}
}

View File

@@ -0,0 +1,342 @@
<?php
namespace App\Livewire\Admin;
use App\Models\Priority;
use App\Models\Status;
use App\Models\Subcategory;
use App\Models\Team;
use App\Models\Trigger;
use App\Models\TriggerEmailTemplate;
use App\Models\User;
use Illuminate\Support\Collection;
use Livewire\Attributes\Computed;
use Livewire\Component;
class Triggers extends Component
{
public bool $formOpen = false;
public ?int $editingId = null;
public array $form = [
'name' => '',
'enabled' => true,
'event' => 'ticket_created',
'conditions' => [],
'actions' => [],
];
public bool $templateFormOpen = false;
public ?int $editingTemplateId = null;
public array $templateForm = ['name' => '', 'subject' => '', 'body' => ''];
public static function eventLabels(): array
{
return [
'ticket_created' => 'Zgłoszenie utworzone',
'ticket_updated' => 'Zgłoszenie zaktualizowane (dowolne pole)',
'status_changed' => 'Zmiana statusu',
'priority_changed' => 'Zmiana priorytetu',
'assignee_changed' => 'Zmiana przypisanego operatora',
'team_changed' => 'Zmiana zespołu',
'category_changed' => 'Zmiana kategorii',
'comment_added' => 'Nowa wiadomość (publiczna)',
];
}
public static function fieldLabels(): array
{
return [
'status_key' => 'Status',
'priority_key' => 'Priorytet',
'team_id' => 'Zespół',
'subcategory_id' => 'Podkategoria',
'assignee_id' => 'Operator przypisany',
'customer_id' => 'Zgłaszający',
'subject' => 'Temat',
'body' => 'Treść',
];
}
public static function operatorLabels(): array
{
return [
'equals' => 'jest równe',
'not_equals' => 'jest różne od',
'is_empty' => 'jest puste',
'is_not_empty' => 'nie jest puste',
'contains' => 'zawiera',
];
}
public static function actionTypeLabels(): array
{
return [
'set_status' => 'Ustaw status',
'set_priority' => 'Ustaw priorytet',
'set_team' => 'Ustaw zespół',
'set_assignee' => 'Ustaw operatora',
'send_notification' => 'Wyślij powiadomienie e-mail',
];
}
#[Computed]
public function triggers(): Collection
{
return Trigger::query()->orderBy('sort_order')->get();
}
#[Computed]
public function statuses(): Collection
{
return Status::query()->orderBy('sort_order')->get();
}
#[Computed]
public function priorities(): Collection
{
return Priority::query()->orderBy('sort_order')->get();
}
#[Computed]
public function teams(): Collection
{
return Team::query()->orderBy('name')->get();
}
#[Computed]
public function operators(): Collection
{
return User::query()->whereHas('roleAssignments', fn ($q) => $q->whereIn('key', ['operator', 'admin']))->orderBy('name')->get();
}
#[Computed]
public function subcategories(): Collection
{
return Subcategory::query()->with('category')->get()
->sortBy(fn (Subcategory $s) => $s->category->name.' / '.$s->name, SORT_NATURAL | SORT_FLAG_CASE)
->values();
}
#[Computed]
public function customers(): Collection
{
return User::query()->whereHas('roleAssignments', fn ($q) => $q->where('key', 'client'))->orderBy('name')->get();
}
#[Computed]
public function emailTemplates(): Collection
{
return TriggerEmailTemplate::query()->orderBy('name')->get();
}
public function openForm(): void
{
$this->editingId = null;
$this->form = ['name' => '', 'enabled' => true, 'event' => 'ticket_created', 'conditions' => [], 'actions' => []];
$this->resetErrorBag();
$this->formOpen = true;
}
public function editTrigger(int $id): void
{
$trigger = Trigger::query()->findOrFail($id);
$this->editingId = $trigger->id;
$this->form = [
'name' => $trigger->name,
'enabled' => $trigger->enabled,
'event' => $trigger->event,
'conditions' => $trigger->conditions,
'actions' => $trigger->actions,
];
$this->resetErrorBag();
$this->formOpen = true;
}
public function closeForm(): void
{
$this->formOpen = false;
}
public function addCondition(): void
{
$this->form['conditions'][] = ['field' => Trigger::CONDITION_FIELDS[0], 'operator' => 'equals', 'value' => ''];
}
public function removeCondition(int $index): void
{
unset($this->form['conditions'][$index]);
$this->form['conditions'] = array_values($this->form['conditions']);
}
public function addAction(): void
{
$this->form['actions'][] = ['type' => Trigger::ACTION_TYPES[0], 'value' => '', 'recipient' => 'client', 'email_template_id' => ''];
}
public function removeAction(int $index): void
{
unset($this->form['actions'][$index]);
$this->form['actions'] = array_values($this->form['actions']);
}
public function moveActionUp(int $index): void
{
$this->swapFormActions($index, $index - 1);
}
public function moveActionDown(int $index): void
{
$this->swapFormActions($index, $index + 1);
}
protected function swapFormActions(int $a, int $b): void
{
if ($b < 0 || $b >= count($this->form['actions'])) {
return;
}
[$this->form['actions'][$a], $this->form['actions'][$b]] = [$this->form['actions'][$b], $this->form['actions'][$a]];
}
public function submit(): void
{
$this->validate([
'form.name' => ['required', 'string', 'max:255'],
'form.event' => ['required', 'string', 'in:'.implode(',', Trigger::EVENTS)],
'form.conditions' => ['array'],
'form.conditions.*.field' => ['required', 'string', 'in:'.implode(',', Trigger::CONDITION_FIELDS)],
'form.conditions.*.operator' => ['required', 'string', 'in:'.implode(',', Trigger::CONDITION_OPERATORS)],
'form.actions' => ['required', 'array', 'min:1'],
'form.actions.*.type' => ['required', 'string', 'in:'.implode(',', Trigger::ACTION_TYPES)],
]);
$data = [
'name' => $this->form['name'],
'enabled' => (bool) $this->form['enabled'],
'event' => $this->form['event'],
'conditions' => array_values($this->form['conditions']),
'actions' => array_values($this->form['actions']),
];
if ($this->editingId) {
Trigger::query()->findOrFail($this->editingId)->update($data);
} else {
$data['sort_order'] = (Trigger::query()->max('sort_order') ?? 0) + 1;
Trigger::query()->create($data);
}
$this->formOpen = false;
unset($this->triggers);
}
public function toggleEnabled(int $id): void
{
$trigger = Trigger::query()->findOrFail($id);
$trigger->update(['enabled' => ! $trigger->enabled]);
unset($this->triggers);
}
public function removeTrigger(int $id): void
{
Trigger::query()->findOrFail($id)->delete();
unset($this->triggers);
}
public function moveUp(int $id): void
{
$this->swapAdjacentSortOrder($id, -1);
}
public function moveDown(int $id): void
{
$this->swapAdjacentSortOrder($id, 1);
}
protected function swapAdjacentSortOrder(int $id, int $direction): void
{
$ordered = $this->triggers;
$index = $ordered->search(fn ($row) => $row->id === $id);
$swapIndex = $index + $direction;
if ($index === false || $swapIndex < 0 || $swapIndex >= $ordered->count()) {
return;
}
$row = $ordered[$index];
$neighbor = $ordered[$swapIndex];
[$rowOrder, $neighborOrder] = [$row->sort_order, $neighbor->sort_order];
$row->update(['sort_order' => $neighborOrder]);
$neighbor->update(['sort_order' => $rowOrder]);
unset($this->triggers);
}
// ===================== TEMPLATES (wyzwalaczy) =====================
public function openTemplateForm(): void
{
$this->editingTemplateId = null;
$this->templateForm = ['name' => '', 'subject' => '', 'body' => ''];
$this->resetErrorBag();
$this->templateFormOpen = true;
}
public function editTemplate(int $id): void
{
$template = TriggerEmailTemplate::query()->findOrFail($id);
$this->editingTemplateId = $template->id;
$this->templateForm = [
'name' => $template->name,
'subject' => $template->subject,
'body' => $template->body,
];
$this->resetErrorBag();
$this->templateFormOpen = true;
}
public function closeTemplateForm(): void
{
$this->templateFormOpen = false;
}
public function setTemplateBodyDraft(string $value): void
{
$this->templateForm['body'] = $value;
}
public function submitTemplate(): void
{
$this->validate([
'templateForm.name' => ['required', 'string', 'max:255'],
'templateForm.subject' => ['required', 'string', 'max:255'],
'templateForm.body' => ['required', 'string'],
]);
if ($this->editingTemplateId) {
TriggerEmailTemplate::query()->findOrFail($this->editingTemplateId)->update($this->templateForm);
} else {
TriggerEmailTemplate::query()->create($this->templateForm);
}
$this->templateFormOpen = false;
unset($this->emailTemplates);
}
public function removeTemplate(int $id): void
{
TriggerEmailTemplate::query()->findOrFail($id)->delete();
unset($this->emailTemplates);
}
public function render()
{
return view('livewire.admin.triggers');
}
}

View File

@@ -75,6 +75,6 @@ class Login extends Component
public function render()
{
return view('livewire.auth.login');
return view('livewire.auth.login')->title(Settings::pageTitle('Logowanie'));
}
}

View File

@@ -3,36 +3,52 @@
namespace App\Livewire\Client;
use App\Models\Status;
use App\Support\Settings;
use Illuminate\Support\Facades\Auth;
use Livewire\Attributes\Computed;
use Livewire\Component;
use Livewire\WithPagination;
class Dashboard extends Component
{
use WithPagination;
private const PER_PAGE = 20;
public string $tab = 'current';
public string $search = '';
#[Computed]
public function tickets()
protected function baseQuery()
{
return Auth::user()->ticketsAsCustomer()
->search($this->search)
->with('subcategory.category')
->orderByDesc('updated_at')
->get();
->orderByDesc('updated_at');
}
/**
* Separate named paginators (see pageName below) so switching tabs
* doesn't reset whichever page the other tab was on.
*/
#[Computed]
public function currentTickets()
{
return $this->tickets->whereNotIn('status_key', Status::closedKeys());
return $this->baseQuery()->whereNotIn('status_key', Status::closedKeys())
->paginate(self::PER_PAGE, pageName: 'currentPage');
}
#[Computed]
public function archiveTickets()
{
return $this->tickets->whereIn('status_key', Status::closedKeys());
return $this->baseQuery()->whereIn('status_key', Status::closedKeys())
->paginate(self::PER_PAGE, pageName: 'archivePage');
}
public function updatedSearch(): void
{
$this->resetPage('currentPage');
$this->resetPage('archivePage');
}
public function setTab(string $tab): void
@@ -42,6 +58,6 @@ class Dashboard extends Component
public function render()
{
return view('livewire.client.dashboard');
return view('livewire.client.dashboard')->title(Settings::pageTitle('Moje zgłoszenia'));
}
}

View File

@@ -5,6 +5,7 @@ namespace App\Livewire\Client;
use App\Models\Category;
use App\Models\Subcategory;
use App\Services\BookStackClient;
use App\Services\SnipeItClient;
use App\Services\TicketService;
use App\Support\Settings;
use Illuminate\Support\Facades\Auth;
@@ -30,6 +31,71 @@ class NewTicket extends Component
public array $attachments = [];
// Set via wire:init (see the blade view) rather than on the initial
// render, so the BookStack HTTP call in suggestedArticles() never
// delays the page's first paint — it loads in a beat later instead.
public bool $suggestedArticlesLoaded = false;
public function loadSuggestedArticles(): void
{
$this->suggestedArticlesLoaded = true;
}
// Same wire:init-deferred pattern as suggestedArticlesLoaded above,
// for the Snipe-IT "Twój sprzęt" picker.
public bool $snipeitAssetsLoaded = false;
public ?int $selectedSnipeitAssetId = null;
public function loadSnipeitAssets(): void
{
$this->snipeitAssetsLoaded = true;
}
/**
* Empty unless the admin turned the picker on AND allow-listed the
* currently selected subcategory for it (see
* snipeit_client_asset_subcategory_ids) an empty allow-list means
* "no subcategory", not "every subcategory", mirroring how BookStack's
* shelf allow-lists work.
*
* @return array<int, array{id: int, label: string, serial: ?string, manufacturer: ?string, model: ?string, category: ?string, status: ?string, url: string}>
*/
#[Computed]
public function snipeitAssets(): array
{
if (! $this->snipeitAssetsLoaded || ! Settings::bool('snipeit_client_can_select_asset') || ! $this->subcategoryId) {
return [];
}
if (! in_array($this->subcategoryId, $this->snipeitAllowedSubcategoryIds(), true)) {
return [];
}
return app(SnipeItClient::class)->assetsForEmail(Auth::user()->email);
}
/**
* @return int[]
*/
protected function snipeitAllowedSubcategoryIds(): array
{
return collect(explode(',', Settings::get('snipeit_client_asset_subcategory_ids', '')))
->map(fn ($v) => (int) trim($v))
->filter()
->values()
->all();
}
public function selectSnipeitAsset(int $id): void
{
if (! Settings::bool('snipeit_client_can_select_asset')) {
return;
}
$this->selectedSnipeitAssetId = $this->selectedSnipeitAssetId === $id ? null : $id;
}
#[Computed]
public function categories()
{
@@ -52,12 +118,14 @@ class NewTicket extends Component
{
$this->categoryId = $id;
$this->subcategoryId = null;
$this->selectedSnipeitAssetId = null;
$this->step = 2;
}
public function selectSubcategory(int $id): void
{
$this->subcategoryId = $id;
$this->selectedSnipeitAssetId = null;
$this->step = 3;
}
@@ -67,9 +135,14 @@ class NewTicket extends Component
#[Computed]
public function suggestedArticles(): array
{
$query = trim(($this->selectedCategory?->name ?? '').' '.($this->selectedSubcategory?->name ?? ''));
if (! $this->suggestedArticlesLoaded) {
return [];
}
return app(BookStackClient::class)->search($query);
$query = trim(($this->selectedCategory?->name ?? '').' '.($this->selectedSubcategory?->name ?? ''));
$tagQuery = trim($this->selectedSubcategory?->name ?? '');
return app(BookStackClient::class)->search($query, tagQuery: $tagQuery);
}
public function backToCategory(): void
@@ -115,12 +188,18 @@ class NewTicket extends Component
$user = Auth::user();
$selectedAsset = $this->selectedSnipeitAssetId
? collect($this->snipeitAssets)->firstWhere('id', $this->selectedSnipeitAssetId)
: null;
$ticket = app(TicketService::class)->create([
'email' => $user->email,
'subcategory_id' => $this->subcategoryId,
'subject' => $this->subject,
'body' => $this->body,
'custom_values' => $this->customValues,
'snipeit_asset_id' => $selectedAsset['id'] ?? null,
'snipeit_asset_name' => $selectedAsset['label'] ?? null,
], $user);
app(TicketService::class)->attachFiles($ticket, $ticket->messages()->first(), $this->attachments);
@@ -130,6 +209,6 @@ class NewTicket extends Component
public function render()
{
return view('livewire.client.new-ticket');
return view('livewire.client.new-ticket')->title(Settings::pageTitle('Nowe zgłoszenie'));
}
}

View File

@@ -4,10 +4,12 @@ namespace App\Livewire\Client;
use App\Models\Ticket;
use App\Models\TicketMessage;
use App\Services\BookStackClient;
use App\Services\TicketService;
use App\Support\Settings;
use Illuminate\Support\Facades\Auth;
use Livewire\Attributes\Computed;
use Livewire\Attributes\On;
use Livewire\Component;
use Livewire\WithFileUploads;
@@ -31,6 +33,20 @@ class TicketShow extends Component
public string $csatComment = '';
public bool $showAllOtherTickets = false;
private const OTHER_TICKETS_PREVIEW_COUNT = 5;
// Set via wire:init (see the blade view) rather than on the initial
// render, so the BookStack HTTP call in suggestedArticles() never
// delays the ticket page's first paint — it loads in a beat later instead.
public bool $suggestedArticlesLoaded = false;
public function loadSuggestedArticles(): void
{
$this->suggestedArticlesLoaded = true;
}
public function mount(Ticket $ticket): void
{
abort_unless($ticket->customer_id === Auth::id(), 403);
@@ -44,10 +60,89 @@ class TicketShow extends Component
return $this->ticket->publicMessages()->with(['author', 'authorLink.role', 'attachments'])->get();
}
/**
* Bridged from a TicketMessagePosted broadcast on this ticket's own
* channel (see resources/js/echo.js) an operator's reply appears
* without the client refreshing, the "live chat" effect. Ignores events
* for any other ticket id since Livewire dispatches are page-wide.
*/
#[On('ticket-message-posted')]
public function onTicketMessagePosted(int $ticketId): void
{
if ($ticketId !== $this->ticket->id) {
return;
}
unset($this->ticketMessages);
$this->ticket->refresh();
}
/**
* Bridged from a TicketQueueChanged broadcast on this ticket's own
* channel lets the client see a status/priority/team/assignee change
* (and the resulting history entry) made by an operator, or by an
* automation rule firing in the background, without refreshing.
*/
#[On('queue-changed')]
public function onQueueChanged(int $ticketId): void
{
if ($ticketId !== $this->ticket->id) {
return;
}
$this->ticket->refresh();
}
/**
* Periodic fallback refresh (see the countdown badge in the blade view)
* broadcasting is best-effort, a dropped websocket connection
* shouldn't mean the thread/ticket silently stops updating.
*/
public function refreshTicketData(): void
{
unset($this->ticketMessages);
$this->ticket->refresh();
}
#[Computed]
public function otherTickets()
{
return Auth::user()->ticketsAsCustomer()->where('id', '!=', $this->ticket->id)->get();
$query = Auth::user()->ticketsAsCustomer()->where('id', '!=', $this->ticket->id)->latest();
return $this->showAllOtherTickets ? $query->get() : $query->take(self::OTHER_TICKETS_PREVIEW_COUNT)->get();
}
#[Computed]
public function otherTicketsCount(): int
{
return Auth::user()->ticketsAsCustomer()->where('id', '!=', $this->ticket->id)->count();
}
public function revealAllOtherTickets(): void
{
$this->showAllOtherTickets = true;
unset($this->otherTickets);
}
/**
* Same allow-listed shelves (CONTEXT_CREATION) and category/subcategory
* query the ticket-creation wizard used, so the client sees the same
* suggestions here as they did while writing the ticket.
*
* @return array<int, array{name: string, url: ?string, type: string, book: ?string, shelf: ?string}>
*/
#[Computed]
public function suggestedArticles(): array
{
if (! $this->suggestedArticlesLoaded) {
return [];
}
$subcategory = $this->ticket->subcategory;
$query = trim(($subcategory?->category?->name ?? '').' '.($subcategory?->name ?? ''));
$tagQuery = trim($subcategory?->name ?? '');
return app(BookStackClient::class)->search($query, tagQuery: $tagQuery);
}
public function updatedAttachments(): void
@@ -145,6 +240,6 @@ class TicketShow extends Component
public function render()
{
return view('livewire.client.ticket-show');
return view('livewire.client.ticket-show')->title(Settings::pageTitle($this->ticket->displayNumber().' — '.$this->ticket->subject));
}
}

View File

@@ -0,0 +1,141 @@
<?php
namespace App\Livewire;
use App\Models\Ticket;
use App\Models\User;
use Illuminate\Support\Facades\Auth;
use Illuminate\Support\Facades\DB;
use Livewire\Attributes\Computed;
use Livewire\Component;
class GlobalSearch extends Component
{
public string $search = '';
/**
* Gmail-style "field:value" operators recognized keys (accent-
* insensitive, a couple of Polish synonyms each) narrow the match to
* that one field; anything left over after stripping them still runs
* through the broad Ticket::scopeSearch() default. Multiple operators
* combine with AND, same as Gmail's "from:x subject:y".
*/
private const FIELD_PREFIXES = [
'od' => 'from',
'nadawca' => 'from',
'temat' => 'subject',
'tytul' => 'subject',
'tytuł' => 'subject',
'tresc' => 'body',
'treść' => 'body',
'numer' => 'number',
'nr' => 'number',
];
#[Computed]
public function results()
{
$term = trim($this->search);
if ($term === '' || ! ($user = Auth::user())) {
return collect();
}
$query = $this->baseQuery($user);
if (! $query) {
return collect();
}
[$fields, $free] = $this->parseQuery($term);
foreach ($fields as $field => $values) {
foreach ($values as $value) {
$this->applyFieldFilter($query, $field, $value);
}
}
// search() itself no-ops on an empty term, so this is safe to call
// unconditionally — it only matters when there was no operator at
// all, or an operator left some free text behind.
$query->search($free);
return $query->orderByDesc('updated_at')->limit(8)->get();
}
/**
* Splits "od:kacper temat:drukarka reszta" into recognized field
* operators plus whatever free text is left over. An unrecognized
* "key:value" (e.g. a pasted URL) is left untouched in the free text
* rather than silently dropped.
*/
private function parseQuery(string $term): array
{
$fields = [];
$free = preg_replace_callback(
'/(\pL+):(\S+)/u',
function ($m) use (&$fields) {
$key = mb_strtolower($m[1]);
if (! isset(self::FIELD_PREFIXES[$key])) {
return $m[0];
}
$fields[self::FIELD_PREFIXES[$key]][] = $m[2];
return '';
},
$term
);
return [$fields, trim(preg_replace('/\s+/', ' ', $free))];
}
private function applyFieldFilter($query, string $field, string $value): void
{
$like = '%'.$value.'%';
match ($field) {
'from' => $query->where(fn ($q) => $q->where('name', 'like', $like)->orWhere('email', 'like', $like)),
'subject' => $query->where('subject', 'like', $like),
'number' => $query->where('number', 'like', $like),
'body' => $query->where(fn ($q) => $q->where('body', 'like', $like)
->orWhereIn('id', DB::table('ticket_messages')->where('body', 'like', $like)->pluck('ticket_id'))),
default => null,
};
}
public function urlFor(Ticket $ticket): string
{
$user = Auth::user();
return $user->isOperator()
? route('operator.ticket', $ticket)
: route('client.ticket', $ticket);
}
/**
* Scoped (and routed, see urlFor()) by the operator role specifically
* rather than isAdmin() admin alone doesn't grant the operator.*
* routes (see routes/web.php's role:operator middleware), so a result
* pointing there would 404 for an admin-only account.
*/
protected function baseQuery(User $user)
{
if ($user->isOperator()) {
return Ticket::query()->visibleToOperator($user);
}
if ($user->isClient()) {
return $user->ticketsAsCustomer();
}
return null;
}
public function render()
{
return view('livewire.global-search');
}
}

View File

@@ -10,6 +10,7 @@ use App\Services\BookStackClient;
use App\Services\LdapUserProvisioner;
use App\Services\TicketService;
use App\Support\Settings;
use Illuminate\Support\Facades\Auth;
use Livewire\Attributes\Computed;
use Livewire\Component;
use Livewire\WithFileUploads;
@@ -36,6 +37,23 @@ class Landing extends Component
public ?int $submittedTicketId = null;
// Set via wire:init (see the blade view) rather than on the initial
// render, so the BookStack HTTP call in suggestedArticles() never
// delays the page's first paint — it loads in a beat later instead.
public bool $suggestedArticlesLoaded = false;
public function mount(): void
{
if (Auth::check()) {
$this->redirect(route('client.dashboard'), navigate: true);
}
}
public function loadSuggestedArticles(): void
{
$this->suggestedArticlesLoaded = true;
}
#[Computed]
public function categories()
{
@@ -85,13 +103,14 @@ class Landing extends Component
#[Computed]
public function suggestedArticles(): array
{
if (! Settings::bool('bookstack_show_to_guests')) {
if (! $this->suggestedArticlesLoaded || ! Settings::bool('bookstack_show_to_guests')) {
return [];
}
$query = trim(($this->selectedCategory?->name ?? '').' '.($this->selectedSubcategory?->name ?? ''));
$tagQuery = trim($this->selectedSubcategory?->name ?? '');
return app(BookStackClient::class)->search($query);
return app(BookStackClient::class)->search($query, tagQuery: $tagQuery);
}
public function backToCategory(): void
@@ -176,6 +195,8 @@ class Landing extends Component
public function render()
{
return view('livewire.landing');
$context = $this->submittedTicketId ? 'Zgłoszenie utworzone' : 'Zgłoś problem';
return view('livewire.landing')->title(Settings::pageTitle($context));
}
}

View File

@@ -4,14 +4,33 @@ namespace App\Livewire;
use Illuminate\Support\Facades\Auth;
use Livewire\Attributes\Computed;
use Livewire\Attributes\On;
use Livewire\Component;
class NotificationBell extends Component
{
/**
* Fired by echo.js the moment a NotificationCreated broadcast arrives on
* this user's private channel refreshes the badge/list instantly
* instead of waiting for the next 30s poll, which stays in place below
* as a fallback for dropped websocket connections.
*/
#[On('bell-notification-received')]
public function onBellNotification(): void
{
unset($this->notifications, $this->unreadCount);
}
/**
* Only unread once a notification is read (clicked through, or via
* "mark all as read"), it disappears from the bell rather than staying
* listed dimmed. The full history still lives in the notifications
* table for anyone querying it directly, just not surfaced here.
*/
#[Computed]
public function notifications()
{
return Auth::user()->notifications()->latest()->limit(20)->get();
return Auth::user()->unreadNotifications()->latest()->limit(20)->get();
}
#[Computed]

View File

@@ -0,0 +1,51 @@
<?php
namespace App\Livewire\Operator;
use App\Models\User;
use App\Support\Settings;
use Livewire\Attributes\Computed;
use Livewire\Attributes\Url;
use Livewire\Component;
class ClientSearch extends Component
{
#[Url]
public string $search = '';
/**
* A search box, not a browse-everything list capped rather than
* paginated, same reasoning as the debounced search inputs elsewhere
* (queue/dashboard): once there's a match count this large, the fix is a
* narrower search term, not another page to click through.
*/
private const MAX_RESULTS = 20;
/**
* Matches by name or e-mail across every account, not just role=client
* a ticket's customer_id can point at any user (e.g. an operator who
* also filed a ticket), so narrowing to clients only would hide valid
* results. Role badges in the view make it clear who's who.
*/
#[Computed]
public function results()
{
$term = trim($this->search);
if ($term === '') {
return collect();
}
return User::query()
->where(fn ($q) => $q->where('name', 'like', "%{$term}%")->orWhere('email', 'like', "%{$term}%"))
->withCount('ticketsAsCustomer')
->orderBy('name')
->limit(self::MAX_RESULTS)
->get();
}
public function render()
{
return view('livewire.operator.client-search')->title(Settings::pageTitle('Klienci'));
}
}

View File

@@ -33,6 +33,16 @@ class NewTicket extends Component
public array $attachments = [];
// Set via wire:init (see the blade view) rather than on the initial
// render, so the BookStack HTTP call in suggestedArticles() never
// delays the page's first paint — it loads in a beat later instead.
public bool $suggestedArticlesLoaded = false;
public function loadSuggestedArticles(): void
{
$this->suggestedArticlesLoaded = true;
}
#[Computed]
public function clients()
{
@@ -76,9 +86,14 @@ class NewTicket extends Component
#[Computed]
public function suggestedArticles(): array
{
$query = trim(($this->selectedCategory?->name ?? '').' '.($this->selectedSubcategory?->name ?? ''));
if (! $this->suggestedArticlesLoaded) {
return [];
}
return app(BookStackClient::class)->search($query);
$query = trim(($this->selectedCategory?->name ?? '').' '.($this->selectedSubcategory?->name ?? ''));
$tagQuery = trim($this->selectedSubcategory?->name ?? '');
return app(BookStackClient::class)->search($query, tagQuery: $tagQuery);
}
public function backToCategory(): void
@@ -145,6 +160,6 @@ class NewTicket extends Component
public function render()
{
return view('livewire.operator.new-ticket');
return view('livewire.operator.new-ticket')->title(Settings::pageTitle('Nowe zgłoszenie'));
}
}

View File

@@ -2,6 +2,7 @@
namespace App\Livewire\Operator;
use App\Events\TicketQueueChanged;
use App\Models\Category;
use App\Models\Priority;
use App\Models\Status;
@@ -9,13 +10,31 @@ use App\Models\Team;
use App\Models\Ticket;
use App\Models\User;
use App\Services\TicketService;
use App\Support\Settings;
use Illuminate\Pagination\LengthAwarePaginator;
use Illuminate\Support\Facades\Auth;
use Livewire\Attributes\Computed;
use Livewire\Attributes\On;
use Livewire\Attributes\Url;
use Livewire\Component;
use Livewire\WithPagination;
class Queue extends Component
{
use WithPagination;
/**
* Rows per page for the ticket table below. Sorting (see sortTickets())
* still happens in PHP over the full filtered result several sortable
* columns (kategoria, przypisany, zespół...) are derived labels with no
* single backing SQL column so this slices the already-sorted
* collection rather than using a query-level ->paginate(). That still
* bounds how many rows ever hit the DOM at once, which is what actually
* mattered once the ticket count grew into the thousands.
*/
private const PER_PAGE = 50;
#[Url]
public string $queue = 'all';
public string $filterStatus = 'all';
@@ -65,6 +84,33 @@ class Queue extends Component
}
}
/**
* Bridged from a TicketQueueChanged broadcast via resources/js/echo.js
* see that file for why this is a plain Livewire event rather than an
* `#[On('echo-private:...')]` attribute. Re-queries through the same
* visibleToOperator()-scoped computed property a manual refresh would
* use, so a ticket that just became invisible to this operator (closed,
* reassigned away, moved to another team) simply won't come back, and
* its id is pruned from the current selection so a stale checkbox
* doesn't linger for a row that's no longer on screen.
*/
#[On('queue-changed')]
public function onQueueChanged(int $ticketId = 0): void
{
$this->refreshQueue();
}
/**
* Periodic fallback refresh (see the countdown badge next to "Kolumny"
* in the blade view) broadcasting is best-effort, a dropped websocket
* connection shouldn't mean the queue silently stops updating.
*/
public function refreshQueue(): void
{
unset($this->filteredTickets);
$this->selectedIds = array_values(array_intersect($this->selectedIds, $this->filteredTickets->pluck('id')->all()));
}
#[Computed]
public function savedViews()
{
@@ -99,6 +145,32 @@ class Queue extends Component
$this->sortDir = $filters['sortDir'] ?? $this->sortDir;
$this->visibleColumns = $filters['visibleColumns'] ?? $this->visibleColumns;
$this->selectedIds = [];
$this->resetPage();
}
/**
* Any change to a filter/search/queue-tab input can shrink the result
* set out from under whatever page the operator was on snap back to
* page 1 rather than showing an empty table.
*/
public function updatedSearch(): void
{
$this->resetPage();
}
public function updatedFilterStatus(): void
{
$this->resetPage();
}
public function updatedFilterPriority(): void
{
$this->resetPage();
}
public function updatedFilterCategory(): void
{
$this->resetPage();
}
public function saveCurrentView(): void
@@ -255,6 +327,21 @@ class Queue extends Component
return $groups;
}
/**
* Last few tickets this operator actually opened (see
* Ticket::recordViewBy(), called from TicketShow::mount()) re-scoped
* through visibleToOperator() in case a team reassignment since the
* view happened would now hide it from them.
*/
#[Computed]
public function recentlyViewed()
{
return Auth::user()->recentlyViewedTickets()
->visibleToOperator(Auth::user())
->take(6)
->get();
}
#[Computed]
public function filteredTickets()
{
@@ -268,7 +355,13 @@ class Queue extends Component
$query->where('priority_key', $this->filterPriority);
}
if ($this->filterCategory !== 'all') {
$query->whereHas('subcategory', fn ($q) => $q->where('category_id', $this->filterCategory));
// A ticket carries a category either via its subcategory or,
// when routed to a whole category with no subcategory (e.g. an
// IMAP mailbox), directly on tickets.category_id.
$query->where(function ($q) {
$q->whereHas('subcategory', fn ($sq) => $sq->where('category_id', $this->filterCategory))
->orWhere('category_id', $this->filterCategory);
});
}
if ($this->filterCustomerId) {
$query->where('customer_id', $this->filterCustomerId);
@@ -277,9 +370,16 @@ class Queue extends Component
$query->search($this->search);
}
$tickets = $query->with(['subcategory.category', 'assignee', 'priority', 'status'])->get();
$tickets = $query->with(['subcategory.category', 'category', 'assignee', 'priority', 'status', 'team'])->get();
$sorted = $this->sortTickets($tickets);
return $this->sortTickets($tickets);
return new LengthAwarePaginator(
$sorted->forPage($this->getPage(), self::PER_PAGE)->values(),
$sorted->count(),
self::PER_PAGE,
$this->getPage(),
['path' => request()->url()],
);
}
/**
@@ -301,6 +401,9 @@ class Queue extends Component
'priority' => $tickets->sortBy(fn (Ticket $t) => $t->priority?->sort_order ?? PHP_INT_MAX, SORT_REGULAR, $desc),
'status' => $tickets->sortBy(fn (Ticket $t) => $t->status?->sort_order ?? PHP_INT_MAX, SORT_REGULAR, $desc),
'assignee' => $tickets->sortBy(fn (Ticket $t) => $t->assignee?->name ?? '', SORT_NATURAL | SORT_FLAG_CASE, $desc),
'team' => $tickets->sortBy(fn (Ticket $t) => $t->team?->name ?? '', SORT_NATURAL | SORT_FLAG_CASE, $desc),
'subcategory' => $tickets->sortBy(fn (Ticket $t) => $t->subcategory?->name ?? '', SORT_NATURAL | SORT_FLAG_CASE, $desc),
'created' => $tickets->sortBy(fn (Ticket $t) => $t->created_at, SORT_REGULAR, $desc),
default => $tickets->sortBy('updated_at', SORT_REGULAR, $desc),
};
@@ -317,10 +420,13 @@ class Queue extends Component
'subject' => 'Temat',
'customer' => 'Klient',
'category' => 'Kategoria',
'subcategory' => 'Podkategoria',
'priority' => 'Priorytet',
'status' => 'Status',
'sla' => 'SLA',
'assignee' => 'Przypisany',
'team' => 'Zespół',
'created' => 'Utworzono',
];
}
@@ -331,7 +437,7 @@ class Queue extends Component
*/
public function sortableColumns(): array
{
return ['number', 'subject', 'customer', 'category', 'priority', 'status', 'assignee'];
return ['number', 'subject', 'customer', 'category', 'subcategory', 'priority', 'status', 'assignee', 'team', 'created'];
}
public function sortByColumn(string $column): void
@@ -373,11 +479,14 @@ class Queue extends Component
if ($key !== 'closed' && $this->filterStatus !== 'all' && Status::stageFor($this->filterStatus) === 'closed') {
$this->filterStatus = 'all';
}
$this->resetPage();
}
public function clearCustomerFilter(): void
{
$this->filterCustomerId = null;
$this->resetPage();
}
public function toggleSelect(int $id): void
@@ -389,6 +498,20 @@ class Queue extends Component
}
}
/**
* Selects every ticket currently visible under the active filters/queue
* (not every ticket in the system) toggles off if all of them are
* already selected, matching the usual "header checkbox" convention.
*/
public function toggleSelectAll(): void
{
$visibleIds = $this->filteredTickets->pluck('id')->all();
$this->selectedIds = empty(array_diff($visibleIds, $this->selectedIds))
? array_values(array_diff($this->selectedIds, $visibleIds))
: array_values(array_unique(array_merge($this->selectedIds, $visibleIds)));
}
public function mergeSelected(): void
{
$ids = $this->selectedIdsInScope();
@@ -417,7 +540,13 @@ class Queue extends Component
public function confirmDeleteSelected(): void
{
Ticket::query()->visibleToOperator(Auth::user())->whereIn('id', $this->selectedIds)->delete();
$ids = Ticket::query()->visibleToOperator(Auth::user())->whereIn('id', $this->selectedIds)->pluck('id');
Ticket::query()->whereIn('id', $ids)->delete();
foreach ($ids as $id) {
TicketQueueChanged::dispatch($id, 'deleted', Auth::id());
}
$this->selectedIds = [];
$this->pendingDeleteSelected = false;
}
@@ -434,6 +563,8 @@ class Queue extends Component
public function render()
{
return view('livewire.operator.queue');
$queueLabel = $this->queueDefs()[$this->queue]['label'] ?? 'Kolejka';
return view('livewire.operator.queue')->title(Settings::pageTitle($queueLabel));
}
}

View File

@@ -9,6 +9,7 @@ use App\Models\Status;
use App\Models\Team;
use App\Models\Ticket;
use App\Models\User;
use App\Support\Settings;
use Illuminate\Support\Carbon;
use Illuminate\Support\Facades\Auth;
use Illuminate\Support\Facades\DB;
@@ -312,6 +313,25 @@ class Stats extends Component
->map(fn ($row) => ['label' => $row->label, 'count' => (int) $row->count]);
}
/**
* One level deeper than byCategory() same shape, but grouped by the
* actual subcategory, labeled "Category / Subcategory" to disambiguate
* subcategories that share a name across different parent categories.
*/
#[Computed]
public function bySubcategory()
{
return (clone $this->baseQuery)
->whereNotNull('tickets.subcategory_id')
->join('subcategories', 'subcategories.id', '=', 'tickets.subcategory_id')
->join('categories', 'categories.id', '=', 'subcategories.category_id')
->select('subcategories.id', 'categories.name as category_name', 'subcategories.name as sub_name', DB::raw('count(*) as count'))
->groupBy('subcategories.id', 'categories.name', 'subcategories.name')
->orderByDesc('count')
->get()
->map(fn ($row) => ['label' => $row->category_name.' / '.$row->sub_name, 'count' => (int) $row->count]);
}
#[Computed]
public function byTeam()
{
@@ -351,6 +371,170 @@ class Stats extends Component
return $rows;
}
/**
* Unlike teams/operators (small, fixed sets), the customer list is
* unbounded capped to the top 10 by ticket volume in the current
* filtered range rather than listing every client who ever wrote in.
* Guest submissions (no account) are summed into one "Goście" bucket
* rather than grouped by e-mail, since a guest has no stable identity
* to rank against registered clients.
*/
#[Computed]
public function byCustomer()
{
$rows = (clone $this->baseQuery)
->whereNotNull('tickets.customer_id')
->join('users', 'users.id', '=', 'tickets.customer_id')
->select('users.id', 'users.name as label', DB::raw('count(*) as count'))
->groupBy('users.id', 'users.name')
->orderByDesc('count')
->limit(10)
->get()
->map(fn ($row) => ['label' => $row->label, 'count' => (int) $row->count]);
$guestCount = (clone $this->baseQuery)->whereNull('tickets.customer_id')->count();
if ($guestCount > 0) {
$rows->push(['label' => 'Goście (bez konta)', 'count' => $guestCount]);
}
return $rows->sortByDesc('count')->values();
}
/**
* Client × subcategory cross-tab which clients' tickets fall into
* which kind of subcategory. Both dimensions are unbounded (unlike
* teams/operators), so this caps to the top 10 clients by overall
* volume (rows, mirroring byCustomer()) and the top 5 subcategories by
* overall volume (columns, mirroring assigneeSubcategoryMatrix()'s
* "Inne" folding) otherwise the table could grow arbitrarily in both
* directions. Guest tickets (no customer_id) are excluded entirely
* rather than folded into one "guest" row, since mixing a real client's
* per-subcategory pattern with an anonymous aggregate wouldn't mean
* anything.
*
* @return array{columns: array<int, string>, hasOther: bool, rows: array<int, array{label: string, cells: array<int, int>, other: ?int, total: int}>}
*/
#[Computed]
public function customerSubcategoryMatrix(): array
{
$raw = (clone $this->baseQuery)
->whereNotNull('tickets.customer_id')
->whereNotNull('tickets.subcategory_id')
->join('subcategories', 'subcategories.id', '=', 'tickets.subcategory_id')
->join('categories', 'categories.id', '=', 'subcategories.category_id')
->join('users', 'users.id', '=', 'tickets.customer_id')
->select(
'tickets.customer_id',
'users.name as customer_name',
'subcategories.id as subcategory_id',
'categories.name as category_name',
'subcategories.name as subcategory_name',
DB::raw('count(*) as total'),
)
->groupBy('tickets.customer_id', 'users.name', 'subcategories.id', 'categories.name', 'subcategories.name')
->get();
if ($raw->isEmpty()) {
return ['columns' => [], 'hasOther' => false, 'rows' => []];
}
$subcategoryTotals = $raw->groupBy('subcategory_id')->map(fn ($g) => $g->sum('total'));
$topSubcategoryIds = $subcategoryTotals->sortDesc()->keys()->take(5);
$subcategoryLabels = $raw->unique('subcategory_id')->keyBy('subcategory_id')
->map(fn ($r) => $r->category_name.' / '.$r->subcategory_name);
$columns = $topSubcategoryIds->map(fn ($id) => $subcategoryLabels[$id])->values()->all();
$hasOther = $subcategoryTotals->keys()->diff($topSubcategoryIds)->isNotEmpty();
$byCustomer = $raw->groupBy('customer_id');
$customerNames = $raw->unique('customer_id')->keyBy('customer_id')->map(fn ($r) => $r->customer_name);
$topCustomerIds = $byCustomer->map(fn ($g) => $g->sum('total'))->sortDesc()->keys()->take(10);
$rows = $topCustomerIds
->map(function ($customerId) use ($byCustomer, $customerNames, $topSubcategoryIds, $hasOther) {
$entries = $byCustomer->get($customerId, collect());
$bySubcategory = $entries->keyBy('subcategory_id');
return [
'label' => $customerNames[$customerId],
'cells' => $topSubcategoryIds->map(fn ($id) => (int) ($bySubcategory[$id]->total ?? 0))->values()->all(),
'other' => $hasOther ? (int) $entries->whereNotIn('subcategory_id', $topSubcategoryIds->all())->sum('total') : null,
'total' => (int) $entries->sum('total'),
];
})
->values()
->all();
return ['columns' => $columns, 'hasOther' => $hasOther, 'rows' => $rows];
}
/**
* Average CSAT rating per team, only among rated tickets in the current
* filtered range mirrors byTeam()'s "Bez zespołu" bucket handling, but
* teams/buckets with zero ratings are dropped entirely (an average of
* nothing isn't a meaningful bar to draw).
*/
#[Computed]
public function csatByTeam()
{
$stats = (clone $this->baseQuery)
->whereNotNull('csat_rating')
->select('team_id', DB::raw('avg(csat_rating) as avg_rating'), DB::raw('count(*) as rated_count'))
->groupBy('team_id')
->get();
$avgs = $stats->pluck('avg_rating', 'team_id');
$counts = $stats->pluck('rated_count', 'team_id');
$rows = $this->teams
->map(fn (Team $t) => [
'label' => $t->name,
'avg' => isset($avgs[$t->id]) ? round((float) $avgs[$t->id], 2) : null,
'count' => (int) ($counts[$t->id] ?? 0),
])
->filter(fn ($row) => $row['count'] > 0)
->values();
if ($counts->get(null, 0)) {
$rows->push(['label' => 'Bez zespołu', 'avg' => round((float) $avgs->get(null), 2), 'count' => (int) $counts->get(null)]);
}
return $rows->sortByDesc('avg')->values();
}
/**
* Average CSAT rating per assignee, same shape/semantics as csatByTeam().
*/
#[Computed]
public function csatByAssignee()
{
$stats = (clone $this->baseQuery)
->whereNotNull('csat_rating')
->select('assignee_id', DB::raw('avg(csat_rating) as avg_rating'), DB::raw('count(*) as rated_count'))
->groupBy('assignee_id')
->get();
$avgs = $stats->pluck('avg_rating', 'assignee_id');
$counts = $stats->pluck('rated_count', 'assignee_id');
$rows = $this->operators
->map(fn (User $u) => [
'label' => $u->name,
'avg' => isset($avgs[$u->id]) ? round((float) $avgs[$u->id], 2) : null,
'count' => (int) ($counts[$u->id] ?? 0),
])
->filter(fn ($row) => $row['count'] > 0)
->values();
if ($counts->get(null, 0)) {
$rows->push(['label' => 'Nieprzypisane', 'avg' => round((float) $avgs->get(null), 2), 'count' => (int) $counts->get(null)]);
}
return $rows->sortByDesc('avg')->values();
}
/**
* Daily created-vs-closed volume, capped at the most recent 60 days so a
* wide range (or "Cały okres") never renders an unreadably thin column
@@ -422,7 +606,7 @@ class Stats extends Component
foreach ($tickets as $ticket) {
fputcsv($out, [
$ticket->number,
$ticket->displayNumber(),
$ticket->subject,
$ticket->statusLabel(),
$ticket->priorityLabel(),
@@ -441,6 +625,6 @@ class Stats extends Component
public function render()
{
return view('livewire.operator.stats');
return view('livewire.operator.stats')->title(Settings::pageTitle('Statystyki'));
}
}

View File

@@ -2,6 +2,7 @@
namespace App\Livewire\Operator;
use App\Events\TicketQueueChanged;
use App\Models\Category;
use App\Models\Priority;
use App\Models\ReplyQuickAction;
@@ -13,10 +14,14 @@ use App\Models\Ticket;
use App\Models\TicketMessage;
use App\Models\User;
use App\Services\BookStackClient;
use App\Services\SnipeItClient;
use App\Services\TicketAiSummaryService;
use App\Services\TicketService;
use App\Support\Settings;
use Illuminate\Database\Eloquent\ModelNotFoundException;
use Illuminate\Support\Facades\Auth;
use Livewire\Attributes\Computed;
use Livewire\Attributes\On;
use Livewire\Component;
use Livewire\WithFileUploads;
@@ -66,6 +71,48 @@ class TicketShow extends Component
public string $editTimerSeconds = '0';
// Set via wire:init (see the blade view) rather than on the initial
// render, so the BookStack HTTP call in suggestedArticles() never
// delays the ticket page's first paint — it loads in a beat later instead.
public bool $suggestedArticlesLoaded = false;
public function loadSuggestedArticles(): void
{
$this->suggestedArticlesLoaded = true;
}
// Same wire:init-deferred pattern — the AI summary card just displays
// whatever the scheduled ai:run-ticket-automation command last computed
// (no live AI call from the ticket page), but refreshing the ticket here
// picks up a summary the command generated after this page's initial load.
public bool $aiSummaryLoaded = false;
public function loadAiSummary(): void
{
$this->aiSummaryLoaded = true;
$this->ticket->refresh();
}
public ?string $aiSummaryRegenerateError = null;
// Manual regeneration is an explicit operator action (unlike the
// wire:init-deferred load above), so it's fine to block on the AI call
// here rather than deferring it — the button's wire:loading state covers
// the wait.
public function regenerateAiSummary(): void
{
$this->aiSummaryRegenerateError = null;
set_time_limit(0);
if (! app(TicketAiSummaryService::class)->generateFor($this->ticket)) {
$this->aiSummaryRegenerateError = 'Nie udało się wygenerować podsumowania. Sprawdź konfigurację integracji AI.';
return;
}
$this->ticket->refresh();
}
public function mount(Ticket $ticket): void
{
abort_unless($ticket->isVisibleToOperator(Auth::user()), 403);
@@ -77,6 +124,38 @@ class TicketShow extends Component
// ticket-show.blade.php) — so every open resumes it, not just the
// very first one.
$this->ticket->resumeTimer();
$this->ticket->recordViewBy(Auth::user());
}
/**
* Livewire lifecycle hook, called for any exception raised while
* handling a request for this component including one thrown while
* re-hydrating the typed $ticket property itself (Livewire re-fetches
* it by id on every request), which happens before any of this
* component's own methods run and so can't be caught locally the way
* refreshOrRedirectAway() catches it during an explicit refresh().
* Covers a ticket deleted by someone else while an operator still has
* it open sends them back to their queue instead of a hard error.
*/
public function exception(\Throwable $e, $stopPropagation): void
{
if ($e instanceof ModelNotFoundException) {
$this->redirect(route('operator.queue'), navigate: true);
$stopPropagation();
}
}
#[Computed]
public function isWatching(): bool
{
return $this->ticket->isWatchedBy(Auth::user());
}
public function toggleWatch(): void
{
app(TicketService::class)->toggleWatch($this->ticket, Auth::user());
unset($this->isWatching);
}
// -------- time tracking --------
@@ -168,6 +247,83 @@ class TicketShow extends Component
return $this->ticket->internalMessages()->with(['author', 'authorLink.role', 'attachments'])->get();
}
/**
* Bridged from a TicketMessagePosted broadcast on this ticket's own
* channel (see resources/js/echo.js) a new reply/note from the other
* party appears without the viewer refreshing, the "live chat" effect.
* Ignores events for any other ticket id, since Livewire dispatches are
* page-wide and this component only cares about its own ticket.
*/
#[On('ticket-message-posted')]
public function onTicketMessagePosted(int $ticketId): void
{
if ($ticketId !== $this->ticket->id) {
return;
}
unset($this->publicMessages, $this->internalMessages);
}
/**
* Re-fetches the ticket and, for a non-admin operator, sends them back
* to their queue instead of leaving them stuck on a page that can no
* longer legitimately show anything either because the ticket was
* deleted (refresh() throws ModelNotFoundException, same as
* Model::findOrFail() internally) or because a team/assignee change
* (by this operator or anyone else) moved it out of their visible
* scope. Returns false when it redirected, so callers can bail out of
* whatever they were doing instead of continuing to operate on a
* ticket that's about to disappear from under them.
*/
protected function refreshOrRedirectAway(): bool
{
try {
$this->ticket->refresh();
} catch (ModelNotFoundException) {
$this->redirect(route('operator.queue'), navigate: true);
return false;
}
if (! $this->ticket->isVisibleToOperator(Auth::user())) {
$this->redirect(route('operator.queue'), navigate: true);
return false;
}
return true;
}
/**
* Bridged from a TicketQueueChanged broadcast (see resources/js/echo.js
* and Queue::onQueueChanged()) lets a status/priority/team/assignee
* change made by another operator, or by an automation rule firing in
* the background, show up live on a ticket someone currently has open.
*/
#[On('queue-changed')]
public function onQueueChanged(int $ticketId): void
{
if ($ticketId !== $this->ticket->id) {
return;
}
$this->refreshOrRedirectAway();
}
/**
* Periodic fallback refresh (see the countdown badge in the blade view)
* broadcasting is best-effort, a dropped websocket connection
* shouldn't mean the thread/ticket silently stops updating.
*/
public function refreshTicketData(): void
{
if (! $this->refreshOrRedirectAway()) {
return;
}
unset($this->publicMessages, $this->internalMessages);
}
#[Computed]
public function statuses()
{
@@ -192,26 +348,127 @@ class TicketShow extends Component
#[Computed]
public function suggestedArticles(): array
{
if (! $this->suggestedArticlesLoaded) {
return [];
}
$subcategory = $this->ticket->subcategory;
$query = trim(($subcategory?->category?->name ?? '').' '.($subcategory?->name ?? ''));
$tagQuery = trim($subcategory?->name ?? '');
return app(BookStackClient::class)->search($query, 5, BookStackClient::CONTEXT_TICKET_VIEW);
return app(BookStackClient::class)->search($query, 5, BookStackClient::CONTEXT_TICKET_VIEW, $tagQuery);
}
// -------- Snipe-IT --------
// Same wire:init-deferred pattern as suggestedArticlesLoaded above — the
// requester's asset list is a Snipe-IT HTTP call, deferred so it never
// delays the ticket page's first paint.
public bool $snipeitAssetsLoaded = false;
public function loadSnipeitAssets(): void
{
$this->snipeitAssetsLoaded = true;
}
public string $snipeitSearchQuery = '';
public array $snipeitSearchResults = [];
/**
* @return array<int, array{id: int, label: string, serial: ?string, manufacturer: ?string, model: ?string, category: ?string, status: ?string, url: string}>
*/
#[Computed]
public function snipeitRequesterAssets(): array
{
if (! $this->snipeitAssetsLoaded || ! Settings::bool('snipeit_operator_view_requester_assets') || ! $this->ticket->email) {
return [];
}
return app(SnipeItClient::class)->assetsForEmail($this->ticket->email);
}
/**
* A non-admin operator can only reassign a ticket to one of their own
* teams (mirrors the visibility scoping in Operator\Queue).
* Live detail for the ticket's linked asset (if any) always fetched
* fresh so a status/assignment change made directly in Snipe-IT shows up
* without an operator having to re-link anything. Not gated behind
* snipeit_operator_view_requester_assets/snipeit_operator_search_inventory:
* showing what's already on the ticket isn't the same permission as
* browsing the rest of Snipe-IT. Falls back to the ticket's own cached
* snipeit_asset_name in the view when this comes back null (unreachable
* instance or the asset was deleted there).
*
* @return array{id: int, label: string, serial: ?string, manufacturer: ?string, model: ?string, category: ?string, status: ?string, assignedTo: ?string, url: string}|null
*/
#[Computed]
public function snipeitLinkedAsset(): ?array
{
return $this->ticket->snipeit_asset_id
? app(SnipeItClient::class)->asset($this->ticket->snipeit_asset_id)
: null;
}
public function searchSnipeitAssets(): void
{
if (! Settings::bool('snipeit_operator_search_inventory')) {
return;
}
$this->snipeitSearchResults = app(SnipeItClient::class)->searchAssets($this->snipeitSearchQuery);
}
/**
* $id must come from whichever list it was clicked from the requester's
* assets (gated on snipeit_operator_view_requester_assets) or an
* inventory search result (gated on snipeit_operator_search_inventory)
* rather than a direct Snipe-IT lookup by id, so an operator can't link
* an arbitrary asset via a source that's admin-disabled for them.
*/
public function linkSnipeitAsset(int $id): void
{
$fromRequesterAssets = Settings::bool('snipeit_operator_view_requester_assets')
? collect($this->snipeitRequesterAssets)->firstWhere('id', $id)
: null;
$fromSearchResults = Settings::bool('snipeit_operator_search_inventory')
? collect($this->snipeitSearchResults)->firstWhere('id', $id)
: null;
$asset = $fromRequesterAssets ?? $fromSearchResults;
if (! $asset) {
return;
}
app(TicketService::class)->setSnipeitAsset($this->ticket, ['id' => $asset['id'], 'label' => $asset['label']]);
$this->ticket->refresh();
unset($this->snipeitLinkedAsset);
}
/**
* Unlike linkSnipeitAsset(), not gated behind either visibility setting
* clearing a link a ticket already has is a correction, not a new way
* to browse Snipe-IT, so it stays available even if an admin later turns
* both of those off.
*/
public function unlinkSnipeitAsset(): void
{
app(TicketService::class)->setSnipeitAsset($this->ticket, null);
$this->ticket->refresh();
unset($this->snipeitLinkedAsset);
}
/**
* Every team, regardless of the viewing operator's own membership
* unlike ticket *visibility* (Operator\Queue, scoped to an operator's
* own teams), reassignment isn't restricted: an operator working a
* ticket needs to be able to route it to whichever team actually owns
* the problem, even one they don't personally belong to.
*/
#[Computed]
public function teams()
{
$query = Team::query();
if (! Auth::user()->isAdmin()) {
$query->whereHas('members', fn ($q) => $q->where('users.id', Auth::id()));
}
return $query->get();
return Team::query()->get();
}
#[Computed]
@@ -285,7 +542,12 @@ class TicketShow extends Component
public function setTeam(string $id): void
{
app(TicketService::class)->setTeam($this->ticket, $id ? Team::query()->find($id) : null);
$this->ticket->refresh();
// Reassigning to a team the operator doesn't belong to can move the
// ticket out of their own visible scope (see Ticket::isVisibleToOperator())
// — send them back to their queue rather than leaving them on a
// ticket they can no longer legitimately keep viewing.
$this->refreshOrRedirectAway();
}
// -------- reporter --------
@@ -500,7 +762,9 @@ class TicketShow extends Component
public function confirmDeleteTicket(): void
{
$ticketId = $this->ticket->id;
$this->ticket->delete();
TicketQueueChanged::dispatch($ticketId, 'deleted', Auth::id());
$this->redirect(route('operator.queue'), navigate: true);
}
@@ -511,6 +775,6 @@ class TicketShow extends Component
// progress is saved incrementally rather than only on explicit stop.
$this->ticket->flushTimer();
return view('livewire.operator.ticket-show');
return view('livewire.operator.ticket-show')->title(Settings::pageTitle($this->ticket->displayNumber().' — '.$this->ticket->subject));
}
}

View File

@@ -0,0 +1,46 @@
<?php
namespace App\Livewire\Settings;
use App\Models\NotificationPreference;
use App\Support\Settings;
use Illuminate\Support\Facades\Auth;
use Livewire\Component;
class NotificationPreferences extends Component
{
protected const SCOPE_FIELDS = ['scope_mine', 'scope_unassigned', 'scope_watched', 'scope_all', 'email'];
public function mount(): void
{
abort_unless(Auth::user()->isOperator() || Auth::user()->isAdmin(), 403);
}
public function rows(): array
{
$user = Auth::user();
return collect(NotificationPreference::CATEGORIES)
->mapWithKeys(fn (string $category) => [$category => NotificationPreference::rowFor($user, $category)])
->all();
}
public function toggle(string $category, string $field): void
{
abort_unless(in_array($category, NotificationPreference::CATEGORIES, true), 404);
abort_unless(in_array($field, self::SCOPE_FIELDS, true), 404);
$preference = NotificationPreference::query()->firstOrCreate(
['user_id' => Auth::id(), 'event_category' => $category],
array_merge(['user_id' => Auth::id(), 'event_category' => $category], NotificationPreference::DEFAULTS[$category])
);
$preference->update([$field => ! $preference->$field]);
}
public function render()
{
return view('livewire.settings.notification-preferences', ['rows' => $this->rows()])
->title(Settings::pageTitle('Powiadomienia'));
}
}

View File

@@ -0,0 +1,35 @@
<?php
namespace App\Models;
use Illuminate\Database\Eloquent\Attributes\Fillable;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\HasMany;
#[Fillable([
'label', 'enabled', 'condition_minutes',
'scope_priority_key', 'scope_subcategory_id', 'scope_team_id',
'action_type', 'action_value',
])]
class AutomationRule extends Model
{
public const ACTION_TYPES = ['change_priority', 'change_status', 'change_team', 'change_assignee'];
protected function casts(): array
{
return [
'enabled' => 'boolean',
'condition_minutes' => 'integer',
];
}
public function logs(): HasMany
{
return $this->hasMany(AutomationRuleTicketLog::class);
}
public function hasFiredFor(Ticket $ticket): bool
{
return $this->logs()->where('ticket_id', $ticket->id)->exists();
}
}

View File

@@ -0,0 +1,28 @@
<?php
namespace App\Models;
use Illuminate\Database\Eloquent\Attributes\Fillable;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\BelongsTo;
#[Fillable(['automation_rule_id', 'ticket_id', 'triggered_at'])]
class AutomationRuleTicketLog extends Model
{
public $timestamps = false;
protected function casts(): array
{
return ['triggered_at' => 'datetime'];
}
public function rule(): BelongsTo
{
return $this->belongsTo(AutomationRule::class, 'automation_rule_id');
}
public function ticket(): BelongsTo
{
return $this->belongsTo(Ticket::class);
}
}

View File

@@ -11,6 +11,6 @@ class Category extends Model
{
public function subcategories(): HasMany
{
return $this->hasMany(Subcategory::class);
return $this->hasMany(Subcategory::class)->orderBy('sort_order');
}
}

View File

@@ -0,0 +1,65 @@
<?php
namespace App\Models;
use Illuminate\Database\Eloquent\Attributes\Fillable;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\BelongsTo;
/**
* One inbound mailbox polled by `emails:fetch-imap` an admin can configure
* several (e.g. zgloszenia-it@ vs zgloszenia-delegacje@), each landing new
* tickets in its own default subcategory. Unlike LDAP/SMTP/BookStack, this is
* a list of N configs rather than a Settings singleton, so it's a real model
* rather than key/value rows.
*/
#[Fillable([
'name', 'enabled', 'host', 'port', 'encryption', 'validate_cert',
'username', 'password', 'folder', 'processed_folder', 'rejected_folder',
'default_subcategory_id', 'default_category_id', 'blocklist_senders', 'last_checked_at', 'last_error',
])]
class ImapMailbox extends Model
{
protected function casts(): array
{
return [
'enabled' => 'boolean',
'validate_cert' => 'boolean',
'password' => 'encrypted',
'last_checked_at' => 'datetime',
];
}
public function defaultSubcategory(): BelongsTo
{
return $this->belongsTo(Subcategory::class, 'default_subcategory_id');
}
/**
* Only meaningful when default_subcategory_id is null a mailbox is
* routed to either a specific subcategory or a whole category, never
* both (enforced by the admin form's single combined selector).
*/
public function defaultCategory(): BelongsTo
{
return $this->belongsTo(Category::class, 'default_category_id');
}
public function blocklistedSenders(): array
{
return array_filter(array_map('trim', explode(',', (string) $this->blocklist_senders)));
}
public function targetLabel(): string
{
if ($this->defaultSubcategory) {
return $this->defaultSubcategory->category->name.' / '.$this->defaultSubcategory->name;
}
if ($this->defaultCategory) {
return 'Cała kategoria: '.$this->defaultCategory->name;
}
return '—';
}
}

View File

@@ -0,0 +1,68 @@
<?php
namespace App\Models;
use Illuminate\Database\Eloquent\Attributes\Fillable;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\BelongsTo;
#[Fillable(['user_id', 'event_category', 'scope_mine', 'scope_unassigned', 'scope_watched', 'scope_all', 'email'])]
class NotificationPreference extends Model
{
public const CATEGORIES = ['new_ticket', 'ticket_update', 'escalation'];
/**
* Applied whenever a user has never touched a given row including
* every user created after this feature ships (new hires, LDAP JIT
* provisioning). new_ticket defaults to exactly what
* TicketService::notifyOperatorsForNewTicket() used to do
* unconditionally (notify every relevant operator, by mail and bell),
* so shipping this feature doesn't silently change what the existing
* admin account already receives. ticket_update/escalation have no
* current staff-facing equivalent, so any default there is purely
* additive rather than a behavior change.
*/
public const DEFAULTS = [
'new_ticket' => ['scope_mine' => false, 'scope_unassigned' => false, 'scope_watched' => false, 'scope_all' => true, 'email' => true],
'ticket_update' => ['scope_mine' => true, 'scope_unassigned' => false, 'scope_watched' => true, 'scope_all' => false, 'email' => false],
'escalation' => ['scope_mine' => true, 'scope_unassigned' => false, 'scope_watched' => true, 'scope_all' => false, 'email' => true],
];
protected function casts(): array
{
return [
'scope_mine' => 'boolean',
'scope_unassigned' => 'boolean',
'scope_watched' => 'boolean',
'scope_all' => 'boolean',
'email' => 'boolean',
];
}
public function user(): BelongsTo
{
return $this->belongsTo(User::class);
}
/**
* Always returns a usable row the persisted one if the user has ever
* toggled this category, DEFAULTS[$category] otherwise so callers
* never need to null-check.
*/
public static function rowFor(User $user, string $category): array
{
$row = static::query()->where('user_id', $user->id)->where('event_category', $category)->first();
if (! $row) {
return static::DEFAULTS[$category];
}
return [
'scope_mine' => $row->scope_mine,
'scope_unassigned' => $row->scope_unassigned,
'scope_watched' => $row->scope_watched,
'scope_all' => $row->scope_all,
'email' => $row->email,
];
}
}

View File

@@ -8,7 +8,7 @@ use Illuminate\Database\Eloquent\Relations\BelongsTo;
use Illuminate\Database\Eloquent\Relations\BelongsToMany;
use Illuminate\Database\Eloquent\Relations\HasMany;
#[Fillable(['category_id', 'name', 'description', 'default_priority_key'])]
#[Fillable(['category_id', 'name', 'description', 'default_priority_key', 'sort_order'])]
class Subcategory extends Model
{
public function category(): BelongsTo

View File

@@ -2,31 +2,53 @@
namespace App\Models;
use App\Support\Settings;
use Illuminate\Database\Eloquent\Attributes\Fillable;
use Illuminate\Database\Eloquent\Builder;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\BelongsTo;
use Illuminate\Database\Eloquent\Relations\BelongsToMany;
use Illuminate\Database\Eloquent\Relations\HasMany;
use Illuminate\Support\Carbon;
use Illuminate\Support\Facades\DB;
#[Fillable([
'number', 'customer_id', 'email', 'name', 'subcategory_id', 'subject', 'body',
'status_key', 'priority_key', 'team_id', 'assignee_id', 'custom_fields', 'api_client_id',
'sla_notified_at', 'time_spent_seconds', 'timer_started_at', 'created_at', 'updated_at',
'csat_rating', 'csat_comment', 'csat_rated_at',
'number', 'checksum', 'customer_id', 'email', 'name', 'subcategory_id', 'category_id', 'subject', 'body',
'status_key', 'priority_key', 'team_id', 'assignee_id', 'custom_fields', 'api_client_id', 'source',
'sla_notified_at', 'last_customer_activity_at', 'time_spent_seconds', 'timer_started_at',
'created_at', 'updated_at', 'csat_rating', 'csat_comment', 'csat_rated_at',
'ai_triaged_at', 'ai_summary', 'ai_suggested_action', 'ai_summary_generated_at',
'snipeit_asset_id', 'snipeit_asset_name',
])]
class Ticket extends Model
{
/**
* Every ticket gets a stable, unique checksum the moment its id is known
* it never needs to change afterward, and having it always populated
* (regardless of whether obfuscation is currently on) means toggling the
* "Ukryj kolejność zgłoszeń" setting doesn't need a backfill pass.
*/
protected static function booted(): void
{
static::created(function (Ticket $ticket) {
$ticket->checksum = static::generateUniqueChecksum($ticket->id);
$ticket->saveQuietly();
});
}
protected function casts(): array
{
return [
'custom_fields' => 'array',
'sla_notified_at' => 'datetime',
'last_customer_activity_at' => 'datetime',
'time_spent_seconds' => 'integer',
'timer_started_at' => 'datetime',
'csat_rating' => 'integer',
'csat_rated_at' => 'datetime',
'ai_triaged_at' => 'datetime',
'ai_summary_generated_at' => 'datetime',
'snipeit_asset_id' => 'integer',
];
}
@@ -55,6 +77,46 @@ class Ticket extends Model
return $this->belongsTo(Subcategory::class);
}
/**
* Only ever set when there's no subcategory to derive a category from
* (subcategory_id already implies one via Subcategory::category()) see
* categoryLabel() and the migration that introduced this column.
*/
public function category(): BelongsTo
{
return $this->belongsTo(Category::class);
}
public function watchers(): BelongsToMany
{
return $this->belongsToMany(User::class, 'ticket_watchers');
}
public function isWatchedBy(User $user): bool
{
return $this->watchers()->where('users.id', $user->id)->exists();
}
public function viewers(): BelongsToMany
{
return $this->belongsToMany(User::class, 'ticket_views')->withPivot('viewed_at');
}
/**
* Bumps viewed_at for an existing view rather than duplicating it sync()
* updates pivot columns on already-attached rows, not just new ones.
*
* Formatted explicitly with microseconds: a plain Carbon instance gets
* bound through the connection's default date format (whole seconds,
* regardless of the column's own declared precision), so two views in
* the same second would otherwise tie and silently fall back to sorting
* by row id instead of actual recency.
*/
public function recordViewBy(User $user): void
{
$this->viewers()->syncWithoutDetaching([$user->id => ['viewed_at' => now()->format('Y-m-d H:i:s.u')]]);
}
public function status(): BelongsTo
{
return $this->belongsTo(Status::class, 'status_key');
@@ -90,6 +152,11 @@ class Ticket extends Model
return $this->hasMany(TicketHistory::class)->orderByDesc('created_at');
}
public function automationRuleLogs(): HasMany
{
return $this->hasMany(AutomationRuleTicketLog::class);
}
public static function nextNumber(): string
{
$max = static::query()->pluck('number')->map(fn ($n) => (int) $n)->max();
@@ -97,9 +164,92 @@ class Ticket extends Model
return (string) (($max ?: 1000) + 1);
}
/**
* The number shown to users: the admin-configured prefix in front of
* formattedNumber(). Kept separate from formattedNumber() because the
* `{numer}` placeholder in admin-editable e-mail templates historically
* carries no prefix (templates hardcode their own, e.g. "Zgłoszenie
* #{numer}") — changing that would double up or mismatch a
* non-default prefix in every existing template.
*/
public function displayNumber(): string
{
return Settings::get('ticket_number_prefix', '#').$this->formattedNumber();
}
/**
* The ticket number without any prefix: either the raw sequential
* `number` (zero-padded to the admin-configured minimum length), or
* when obfuscation is enabled this ticket's stored checksum. The
* checksum is a fixed-width HMAC output, so minimum-length padding
* doesn't apply to it (padding a checksum has no real meaning — it's
* only meant to make a short *sequential* number look consistent).
* This is also the value getRouteKey()/resolveRouteBinding() use, so
* the number shown on the page and the one in the URL always match.
* The underlying `number` column itself is left alone, since it still
* backs the numeric sort in Operator/Queue.php.
*/
public function formattedNumber(): string
{
if (Settings::bool('ticket_number_obfuscate')) {
return $this->checksum ?? $this->number;
}
$minLength = max(1, (int) Settings::get('ticket_number_min_length', '4'));
return str_pad($this->number, $minLength, '0', STR_PAD_LEFT);
}
/**
* The value used when generating a URL for this ticket (route($name,
* $ticket)) mirrors formattedNumber() minus the prefix, so a link
* never shows the raw sequential number while the page itself shows an
* obfuscated one (or vice versa).
*/
public function getRouteKey()
{
return Settings::bool('ticket_number_obfuscate') ? ($this->checksum ?? $this->number) : $this->number;
}
/**
* Inbound counterpart to getRouteKey() resolves a URL segment back to
* a ticket via whichever column matches the current numbering mode.
*/
public function resolveRouteBinding($value, $field = null)
{
if ($field) {
return $this->where($field, $value)->first();
}
$column = Settings::bool('ticket_number_obfuscate') ? 'checksum' : 'number';
return $this->where($column, $value)->first();
}
/**
* A short, HMAC-derived checksum for this ticket, carrying no relation
* to creation order salted with the app key so it can't be predicted
* or reversed back into id/creation order without server-side secrets.
* Collisions are rare but not astronomically so at 6 digits, so this
* walks a nonce forward until it lands on a value no other ticket
* already has (enforced for real by the column's unique constraint).
*/
public static function generateUniqueChecksum(int $id): string
{
$nonce = 0;
do {
$hash = hash_hmac('sha256', $id.'|'.$nonce, (string) config('app.key'));
$candidate = (string) (hexdec(substr($hash, 0, 8)) % 900000 + 100000);
$nonce++;
} while (static::query()->where('checksum', $candidate)->exists());
return $candidate;
}
public function categoryLabel(): string
{
return $this->subcategory?->label() ?? '';
return $this->subcategory?->label() ?? $this->category?->name ?? '';
}
/**
@@ -167,6 +317,7 @@ class Ticket extends Model
}
$q->orWhere('number', 'like', $like)
->orWhere('checksum', 'like', $like)
->orWhere('name', 'like', $like)
->orWhere('email', 'like', $like)
->orWhereIn('id', $messageTicketIds);

View File

@@ -9,7 +9,7 @@ use Illuminate\Database\Eloquent\Relations\HasMany;
use Illuminate\Database\Eloquent\Relations\HasOne;
use Illuminate\Database\Eloquent\Relations\HasOneThrough;
#[Fillable(['ticket_id', 'author_name', 'internal', 'body', 'edited', 'api_client_id', 'created_at', 'updated_at'])]
#[Fillable(['ticket_id', 'author_name', 'internal', 'body', 'edited', 'api_client_id', 'source', 'created_at', 'updated_at'])]
class TicketMessage extends Model
{
protected function casts(): array

View File

@@ -0,0 +1,33 @@
<?php
namespace App\Models;
use Illuminate\Database\Eloquent\Attributes\Fillable;
use Illuminate\Database\Eloquent\Model;
#[Fillable(['name', 'enabled', 'event', 'conditions', 'actions', 'sort_order'])]
class Trigger extends Model
{
public const EVENTS = [
'ticket_created', 'ticket_updated', 'status_changed', 'priority_changed',
'assignee_changed', 'team_changed', 'category_changed', 'comment_added',
];
public const CONDITION_FIELDS = [
'status_key', 'priority_key', 'team_id', 'subcategory_id', 'assignee_id', 'customer_id', 'subject', 'body',
];
public const CONDITION_OPERATORS = ['equals', 'not_equals', 'is_empty', 'is_not_empty', 'contains'];
public const ACTION_TYPES = ['set_status', 'set_priority', 'set_team', 'set_assignee', 'send_notification'];
protected function casts(): array
{
return [
'enabled' => 'boolean',
'conditions' => 'array',
'actions' => 'array',
'sort_order' => 'integer',
];
}
}

View File

@@ -0,0 +1,26 @@
<?php
namespace App\Models;
use Illuminate\Database\Eloquent\Attributes\Fillable;
use Illuminate\Database\Eloquent\Model;
#[Fillable(['name', 'subject', 'body'])]
class TriggerEmailTemplate extends Model
{
public function render(array $placeholders): array
{
$replace = function (string $text) use ($placeholders): string {
foreach ($placeholders as $key => $value) {
$text = str_replace('{'.$key.'}', (string) $value, $text);
}
return $text;
};
return [
'subject' => $replace($this->subject),
'body' => $replace($this->body),
];
}
}

View File

@@ -184,6 +184,18 @@ class User extends Authenticatable implements LdapAuthenticatable
return $this->hasMany(Ticket::class, 'customer_id');
}
public function watchedTickets(): BelongsToMany
{
return $this->belongsToMany(Ticket::class, 'ticket_watchers');
}
public function recentlyViewedTickets(): BelongsToMany
{
return $this->belongsToMany(Ticket::class, 'ticket_views')
->withPivot('viewed_at')
->orderByPivot('viewed_at', 'desc');
}
public function ticketsAssigned(): HasMany
{
return $this->hasMany(Ticket::class, 'assignee_id');

View File

@@ -4,6 +4,7 @@ namespace App\Notifications;
use App\Models\EmailTemplate;
use App\Models\Ticket;
use App\Models\TriggerEmailTemplate;
use App\Support\Settings;
use Illuminate\Bus\Queueable;
use Illuminate\Notifications\AnonymousNotifiable;
@@ -20,8 +21,25 @@ class TicketNotification extends Notification
* user can hold both roles at once, so this can't be inferred from the
* notifiable itself; it decides which ticket URL (client vs operator
* area) both the e-mail link and the in-app notification point to.
*
* $channels lets a caller with a real per-recipient preference (see
* TicketService::notifyStaffForCategory()) send only 'database' (bell,
* no e-mail) for a given recipient defaults to the original
* unconditional "both" behaviour so every existing call site is
* unaffected.
*
* $templateSource picks which table $emailTemplateId is looked up in:
* 'email_template' (the fixed, built-in templates) or
* 'trigger_email_template' (the freely add/edit/delete-able templates
* used by trigger "send_notification" actions see TriggerEngine).
*/
public function __construct(protected Ticket $ticket, protected int $emailTemplateId, protected string $recipientRole = 'client') {}
public function __construct(
protected Ticket $ticket,
protected int $emailTemplateId,
protected string $recipientRole = 'client',
protected array $channels = ['mail', 'database'],
protected string $templateSource = 'email_template',
) {}
/**
* A guest customer with no account is routed anonymously (see
@@ -30,7 +48,7 @@ class TicketNotification extends Notification
*/
public function via(object $notifiable): array
{
return $notifiable instanceof AnonymousNotifiable ? ['mail'] : ['mail', 'database'];
return $notifiable instanceof AnonymousNotifiable ? ['mail'] : $this->channels;
}
protected function ticketUrl(): string
@@ -44,19 +62,21 @@ class TicketNotification extends Notification
'ticket_id' => $this->ticket->id,
'number' => $this->ticket->number,
'subject' => $this->ticket->subject,
'message' => 'Zgłoszenie #'.$this->ticket->number.' — '.$this->ticket->subject,
'message' => 'Zgłoszenie '.$this->ticket->displayNumber().' — '.$this->ticket->subject,
'url' => $this->ticketUrl(),
];
}
public function toMail(object $notifiable): MailMessage
{
$template = EmailTemplate::query()->find($this->emailTemplateId);
$template = $this->templateSource === 'trigger_email_template'
? TriggerEmailTemplate::query()->find($this->emailTemplateId)
: EmailTemplate::query()->find($this->emailTemplateId);
$firstName = trim(explode(' ', $this->ticket->name)[0] ?? $this->ticket->name);
$rendered = $template?->render([
'numer' => $this->ticket->number,
'numer' => $this->ticket->formattedNumber(),
'imie' => $firstName,
'temat' => $this->ticket->subject,
'status' => $this->ticket->statusLabel(),
@@ -67,7 +87,7 @@ class TicketNotification extends Notification
'link' => $this->ticketUrl(),
'ocena' => route('client.ticket', $this->ticket).'#csat',
]) ?? [
'subject' => 'Zgłoszenie #'.$this->ticket->number,
'subject' => 'Zgłoszenie '.$this->ticket->displayNumber(),
'body' => $this->ticket->subject,
];

View File

@@ -2,13 +2,19 @@
namespace App\Providers;
use App\Events\NotificationCreated;
use App\Events\TicketMessagePosted;
use App\Jobs\GenerateTicketAiSummaryJob;
use App\Models\ApiClient;
use App\Models\User;
use App\Notifications\TicketNotification;
use App\Support\Settings;
use Illuminate\Cache\RateLimiting\Limit;
use Illuminate\Database\Eloquent\Relations\Relation;
use Illuminate\Http\Request;
use Illuminate\Notifications\Events\NotificationSent;
use Illuminate\Support\Facades\Config;
use Illuminate\Support\Facades\Event;
use Illuminate\Support\Facades\RateLimiter;
use Illuminate\Support\Facades\Schema;
use Illuminate\Support\ServiceProvider;
@@ -35,12 +41,55 @@ class AppServiceProvider extends ServiceProvider
$this->applySessionSettingsOverride();
$this->applyTimezoneSettingsOverride();
$this->configureApiRateLimiting();
$this->broadcastBellNotifications();
$this->regenerateAiSummaryOnNewMessage();
// 'user' backs the polymorphic notifiable_type column on the
// database-notifications table (in-app notification bell).
Relation::enforceMorphMap(['api_client' => ApiClient::class, 'user' => User::class]);
}
/**
* A single choke point for realtime bell delivery hooks Laravel's own
* post-send event instead of threading a broadcast dispatch into every
* TicketService call site that creates a "database" notification
* (client leg, staff fan-out, and eventually the Trigger engine's
* send_notification action). $event->response is the DatabaseChannel's
* return value: the DatabaseNotification row that was just created,
* whose id is the same one the bell already reads.
*/
protected function broadcastBellNotifications(): void
{
Event::listen(NotificationSent::class, function (NotificationSent $event) {
if ($event->channel !== 'database' || ! $event->notification instanceof TicketNotification) {
return;
}
$data = $event->notification->toDatabase($event->notifiable);
NotificationCreated::dispatch($event->notifiable->id, $event->response->id, $data['message'], $data['url']);
});
}
/**
* Admin-optional: when enabled, every reply/note/API message re-runs the
* AI summary for its ticket right away instead of waiting for the next
* ai:run-ticket-automation sweep (up to schedule_ai_automation_minutes
* stale). dispatchAfterResponse() runs in-process after the triggering
* request finishes rather than going through the queue table see
* GenerateTicketAiSummaryJob's docblock for why.
*/
protected function regenerateAiSummaryOnNewMessage(): void
{
Event::listen(TicketMessagePosted::class, function (TicketMessagePosted $event) {
if (! Settings::bool('ai_summary_enabled') || ! Settings::bool('ai_summary_regenerate_on_message')) {
return;
}
GenerateTicketAiSummaryJob::dispatchAfterResponse($event->ticketId);
});
}
/**
* API keys get a generous per-key budget; unauthenticated requests (which
* only ever hit the guard before rejecting with 401) get a much smaller
@@ -58,13 +107,21 @@ class AppServiceProvider extends ServiceProvider
}
/**
* Avoid touching the DB during artisan commands that run before the
* `settings` table exists (e.g. `migrate` itself), or before it can be
* queried at all shared by every settings-driven config override below.
* Avoid touching the DB during the specific artisan commands that run
* before the `settings` table exists or could be mid-schema-change (the
* migrate family) shared by every settings-driven config override
* below. Deliberately scoped to just those commands rather than "any
* console command": scheduled commands (`schedule:run` → e.g.
* `emails:fetch-imap`, `tickets:check-sla-breaches`) also run in the
* console and need the real SMTP/LDAP/timezone overrides exactly like a
* web request does, or their notifications/lookups silently fall back
* to whatever's in `.env` (this was a real bug: scheduled-command
* notifications were always going out via the `.env` `log` mailer
* instead of the configured SMTP server).
*/
protected function settingsTableUsable(): bool
{
if ($this->app->runningInConsole() && ! $this->app->runningUnitTests()) {
if ($this->app->runningConsoleCommand('migrate', 'migrate:fresh', 'migrate:refresh', 'migrate:reset', 'migrate:rollback', 'migrate:install')) {
return false;
}
@@ -101,6 +158,12 @@ class AppServiceProvider extends ServiceProvider
Config::set('ldap.connections.default', $config);
Container::addConnection(new Connection($config), 'default');
// Active Directory's objectClass chain (top/person/organizationalPerson/
// user) and login attribute (sAMAccountName) differ from the
// LLDAP/OpenLDAP schema LldapUser is scoped to — swap in AdUser so a
// directory switch doesn't leave every login matching zero entries.
Config::set('auth.providers.users.model', Settings::ldapUserModelClass());
}
/**

View File

@@ -0,0 +1,95 @@
<?php
namespace App\Services;
use App\Support\Settings;
use Illuminate\Support\Facades\Http;
/**
* Generic OpenAI-compatible chat-completions client works against Groq,
* OpenAI itself, or a self-hosted Ollama instance's OpenAI-compat endpoint,
* whichever the admin points ai_base_url at. Not BookStack-specific; the
* BookStack content tagger is just the first consumer.
*/
class AiClient
{
public function enabled(): bool
{
// Deliberately no api-key requirement here — a self-hosted Ollama
// instance typically has no auth at all.
return Settings::bool('ai_enabled')
&& Settings::get('ai_base_url')
&& Settings::get('ai_model');
}
/**
* @param array<int, array{role: string, content: string}> $messages
* @return string|null the assistant message content, or null on any failure
*/
public function chat(array $messages, array $options = []): ?string
{
if (! $this->enabled()) {
return null;
}
try {
$response = $this->client()->post('/chat/completions', [
'model' => Settings::get('ai_model'),
'messages' => $messages,
...$options,
]);
if (! $response->successful()) {
return null;
}
return $response->json('choices.0.message.content');
} catch (\Throwable) {
return null;
}
}
/**
* Tests unsaved admin-form values directly, rather than whatever's
* currently stored mirrors BookStackClient::testConnection().
*
* @return array{ok: bool, message: ?string}
*/
public function testConnection(string $baseUrl, string $apiKey, string $model, bool $verifySsl = true): array
{
try {
$http = Http::withOptions(['verify' => $verifySsl])
->timeout(10)
->baseUrl(rtrim($baseUrl, '/'));
if ($apiKey !== '') {
$http = $http->withToken($apiKey);
}
$response = $http->post('/chat/completions', [
'model' => $model,
'messages' => [['role' => 'user', 'content' => 'ping']],
'max_tokens' => 1,
]);
if ($response->successful()) {
return ['ok' => true, 'message' => null];
}
return ['ok' => false, 'message' => $response->json('error.message') ?? ('HTTP '.$response->status())];
} catch (\Throwable $e) {
return ['ok' => false, 'message' => $e->getMessage()];
}
}
protected function client()
{
$http = Http::withOptions(['verify' => Settings::bool('ai_verify_ssl')])
->timeout(60)
->baseUrl(rtrim(Settings::get('ai_base_url'), '/'));
$apiKey = Settings::get('ai_api_key');
return $apiKey ? $http->withToken($apiKey) : $http;
}
}

View File

@@ -23,6 +23,31 @@ class BookStackClient
self::CONTEXT_TICKET_VIEW => 'bookstack_allowed_shelf_ids_ticket_view',
];
/**
* Content types selectable via the admin's "Przeszukuj" checkboxes.
* Deliberately excludes 'bookshelf' shelves are only ever a filter
* (dozwolone półki), never a suggestion result in their own right.
*/
public const SEARCH_TYPES = ['book', 'page', 'chapter'];
/**
* How the query text is matched, via the admin's "Szukaj po" option
* 'name' restricts to the title ({in_name:...}), 'tags' matches a tag
* whose name equals the query (expected to hold the helpdesk
* category/subcategory name, e.g. a "Drukarki" tag on the relevant
* BookStack pages), 'both' runs both and merges the results (BookStack's
* query syntax ANDs filters together, so there's no single-query way to
* express "name OR tag").
*/
public const SEARCH_BY_OPTIONS = ['name', 'tags', 'both'];
/**
* Content types the bulk-tagging command operates over same set as
* SEARCH_TYPES (book/page/chapter, no bookshelf), named separately since
* the two consts serve different features that happen to share a domain.
*/
public const CONTENT_TYPES = self::SEARCH_TYPES;
public function enabled(): bool
{
return Settings::bool('bookstack_enabled')
@@ -39,44 +64,56 @@ class BookStackClient
* before any content is ever suggested, independently per context).
* Cached briefly since the same category/subcategory query repeats
* across every ticket created/viewed with that combination. Respects the
* admin-configured bookstack_search_types setting ('both'|'page'|'book')
* via BookStack's own `{type:x}` query syntax. The cache key folds in the
* allowed-shelf list so changing it in Admin > Konfiguracja is reflected
* immediately, instead of possibly serving a pre-change result for up to
* 10 minutes.
* admin-configured bookstack_search_types (subset of SEARCH_TYPES, via
* BookStack's `{type:a|b}` syntax) and bookstack_search_by ('name'|
* 'tags'|'both', via `{in_name:...}`/`[...]`) settings. The cache key
* folds in the allowed-shelf list so changing it in Admin > Konfiguracja
* is reflected immediately, instead of possibly serving a pre-change
* result for up to 10 minutes.
*
* $tagQuery is the text matched by the 'tags' variant, separate from
* $query (matched by the 'name' variant) callers pass the bare
* subcategory name here (what bookstack:tag-content actually writes as
* a tag), while $query stays the fuller "Category Subcategory" text
* that's more useful for a plain title/body search. Defaults to $query
* so existing call sites that don't pass it keep working.
*
* @return array<int, array{name: string, url: ?string, type: string, book: ?string, shelf: ?string}>
*/
public function search(string $query, int $limit = 5, string $context = self::CONTEXT_CREATION): array
public function search(string $query, int $limit = 5, string $context = self::CONTEXT_CREATION, ?string $tagQuery = null): array
{
$query = trim($query);
$tagQuery = trim($tagQuery ?? $query);
$allowedShelfIds = $this->allowedShelfIds($context);
if (! $this->enabled() || $query === '' || ! $allowedShelfIds) {
return [];
}
$typeFilter = Settings::get('bookstack_search_types', 'both');
$searchBy = $this->searchBy();
$bookstackQueries = $searchBy === 'both'
? [$this->buildQuery($query, 'name'), $this->buildQuery($tagQuery, 'tags')]
: [$this->buildQuery($searchBy === 'tags' ? $tagQuery : $query, $searchBy)];
if (in_array($typeFilter, ['page', 'book'], true)) {
$query .= " {type:{$typeFilter}}";
}
$cacheKey = 'bookstack:search:'.md5(implode('||', $bookstackQueries).'|'.$limit.'|'.implode(',', $allowedShelfIds));
$cacheKey = 'bookstack:search:'.md5($query.'|'.$limit.'|'.implode(',', $allowedShelfIds));
return Cache::remember($cacheKey, now()->addMinutes(10), function () use ($query, $limit, $allowedShelfIds) {
return Cache::remember($cacheKey, now()->addMinutes(10), function () use ($bookstackQueries, $limit, $allowedShelfIds) {
try {
$response = $this->client()->get('/api/search', ['query' => $query, 'count' => $limit]);
if (! $response->successful()) {
return [];
}
$shelfMap = $this->shelfBookMap();
$allowedBookIds = $this->bookIdsForShelves($shelfMap, $allowedShelfIds);
$bookShelfNames = $this->bookShelfNames($shelfMap);
return collect($response->json('data', []))
$items = collect();
foreach ($bookstackQueries as $bookstackQuery) {
$response = $this->client()->get('/api/search', ['query' => $bookstackQuery, 'count' => $limit]);
if ($response->successful()) {
$items = $items->concat($response->json('data', []));
}
}
return $items
->filter(function (array $item) use ($allowedShelfIds, $allowedBookIds) {
$type = $item['type'] ?? null;
@@ -103,6 +140,8 @@ class BookStackClient
];
})
->filter(fn (array $item) => $item['name'] !== '')
->unique(fn (array $item) => $item['url'] ?? $item['name'])
->take($limit)
->values()
->all();
} catch (\Throwable) {
@@ -111,6 +150,68 @@ class BookStackClient
});
}
/**
* Builds one BookStack search-syntax query string for $query, restricted
* to $by ('name' -> `{in_name:...}`, 'tags' -> `[...]`) and to the
* configured content types (`{type:a|b}`, omitted if all types are
* allowed since that's equivalent to no filter).
*/
protected function buildQuery(string $query, string $by): string
{
$parts = [$by === 'tags' ? "[{$query}]" : "{in_name:{$query}}"];
$types = $this->searchTypes();
if (array_diff(self::SEARCH_TYPES, $types)) {
$parts[] = '{type:'.implode('|', $types).'}';
}
return implode(' ', $parts);
}
/**
* @return string[] non-empty subset of SEARCH_TYPES
*/
protected function searchTypes(): array
{
return self::normalizeSearchTypes(Settings::get('bookstack_search_types', ''));
}
/**
* Normalizes bookstack_search_types storage into a non-empty subset of
* SEARCH_TYPES shared with Admin\Panel so the checkbox UI and the
* actual search agree on the same format. Also understands the legacy
* single-value 'both'/'page'/'book' storage from before the setting
* became a checkbox list, so existing configuration keeps working.
*
* @param string[]|string $raw
* @return string[]
*/
public static function normalizeSearchTypes(array|string $raw): array
{
$legacy = ['both' => self::SEARCH_TYPES, 'page' => ['page'], 'book' => ['book']];
if (is_string($raw) && isset($legacy[$raw])) {
return $legacy[$raw];
}
$types = collect(is_array($raw) ? $raw : explode(',', $raw))
->map(fn ($v) => trim((string) $v))
->filter(fn ($v) => in_array($v, self::SEARCH_TYPES, true))
->unique()
->values()
->all();
return $types ?: self::SEARCH_TYPES;
}
protected function searchBy(): string
{
$raw = Settings::get('bookstack_search_by', 'both');
return in_array($raw, self::SEARCH_BY_OPTIONS, true) ? $raw : 'both';
}
/**
* Drops the cached shelf list and shelf>book membership map used by
* the admin's "Odśwież listę półek" button so a shelf renamed/added/
@@ -155,6 +256,103 @@ class BookStackClient
});
}
/**
* Every book/chapter/page of $type across the whole BookStack instance
* NOT filtered by the allowed-shelf settings, unlike search(). Those only
* gate which suggestions are ever shown to a client/operator; the bulk
* tagger is meant to cover every piece of content regardless. Paginates
* through BookStack's count/offset list endpoints (count capped at 500,
* the API's own per-page maximum). Uncached this is a one-shot batch
* read, not a repeated request-path lookup.
*
* @return array<int, array{id: int, name: string}>
*/
public function listAll(string $type): array
{
if (! $this->enabled() || ! in_array($type, self::CONTENT_TYPES, true)) {
return [];
}
$items = [];
$offset = 0;
try {
do {
$response = $this->client()->get("/api/{$type}s", ['count' => 500, 'offset' => $offset]);
if (! $response->successful()) {
break;
}
$page = $response->json('data', []);
$items = [...$items, ...$page];
$offset += 500;
$total = $response->json('total', 0);
} while (count($page) > 0 && count($items) < $total);
} catch (\Throwable) {
return $items;
}
return $items;
}
/**
* Full detail for a single book/chapter/page its current tags (needed
* to merge rather than clobber when the tagger writes new ones) and the
* text used to classify it (a page's markdown source, or a book/
* chapter's description). Null if $type is invalid or the item can't be
* fetched.
*
* @return array{id: int, name: string, tags: array<int, array{name: string, value: string}>, content: string}|null
*/
public function detail(string $type, int $id): ?array
{
if (! $this->enabled() || ! in_array($type, self::CONTENT_TYPES, true)) {
return null;
}
try {
$response = $this->client()->get("/api/{$type}s/{$id}");
if (! $response->successful()) {
return null;
}
$data = $response->json();
return [
'id' => $data['id'],
'name' => $data['name'] ?? '',
'tags' => $data['tags'] ?? [],
'content' => $data['markdown'] ?? $data['description'] ?? '',
];
} catch (\Throwable) {
return null;
}
}
/**
* Overwrites just the tags field on a book/chapter/page BookStack
* treats every field on its update endpoints as optional, so this never
* touches the item's name/content/other attributes. Callers are
* responsible for merging in any tags they want to keep (this replaces
* the whole array, it doesn't append).
*
* @param array<int, array{name: string, value: string}> $tags
*/
public function updateTags(string $type, int $id, array $tags): bool
{
if (! $this->enabled() || ! in_array($type, self::CONTENT_TYPES, true)) {
return false;
}
try {
return $this->client()->put("/api/{$type}s/{$id}", ['tags' => $tags])->successful();
} catch (\Throwable) {
return false;
}
}
/**
* @return int[]
*/

View File

@@ -0,0 +1,260 @@
<?php
namespace App\Services;
use App\Models\Subcategory;
use Illuminate\Support\Str;
/**
* Bulk-assigns BookStack tags to every book/chapter/page, using the
* configured AiClient to classify each item's title+content against the
* helpdesk's current subcategory vocabulary — so BookStackClient::search()'s
* 'tags'/'both' mode has something to actually match against. Idempotent by
* default: an item already carrying a tag matching a current subcategory
* name is skipped, so re-running after adding a handful of new pages is
* cheap; $force re-classifies everything.
*/
class BookStackContentTagger
{
protected const BATCH_SIZE = 20;
protected const CONTENT_EXCERPT_CHARS = 2000;
public function __construct(
protected BookStackClient $bookstack,
protected AiClient $ai,
) {}
/**
* @return array{scanned: int, tagged: int, skipped: int, failed_batches: int}
*/
public function run(bool $dryRun = false, bool $force = false, ?int $limit = null): array
{
$totals = ['scanned' => 0, 'tagged' => 0, 'skipped' => 0, 'failed_batches' => 0];
if (! $this->bookstack->enabled() || ! $this->ai->enabled()) {
return $totals;
}
$vocabulary = $this->subcategoryVocabulary();
if (! $vocabulary) {
return $totals;
}
foreach (BookStackClient::CONTENT_TYPES as $type) {
foreach ($this->itemsToProcess($type, $vocabulary, $force, $limit, $totals) as $batch) {
$this->processBatch($type, $batch, $vocabulary, $dryRun, $totals);
if ($limit !== null && $totals['scanned'] >= $limit) {
break 2;
}
}
}
return $totals;
}
/**
* @return string[] current subcategory names, deduped case-insensitively
*/
protected function subcategoryVocabulary(): array
{
return Subcategory::query()
->pluck('name')
->filter()
->unique(fn (string $name) => Str::lower($name))
->values()
->all();
}
/**
* Yields item detail records (id, name, tags, content) in chunks of
* BATCH_SIZE, skipping already-tagged items unless $force. Detail is
* fetched per item since BookStack's list endpoints don't include
* tags/content acceptable here since this is an offline batch job, not
* a request-path call.
*
* @param string[] $vocabulary
* @param array{scanned: int, tagged: int, skipped: int, failed_batches: int} $totals
* @return \Generator<int, array<int, array{id: int, name: string, tags: array, content: string}>>
*/
protected function itemsToProcess(string $type, array $vocabulary, bool $force, ?int $limit, array &$totals): \Generator
{
$batch = [];
foreach ($this->bookstack->listAll($type) as $summary) {
if ($limit !== null && $totals['scanned'] >= $limit) {
return;
}
$detail = $this->bookstack->detail($type, $summary['id']);
if (! $detail) {
continue;
}
$totals['scanned']++;
if (! $force && $this->alreadyTagged($detail['tags'], $vocabulary)) {
$totals['skipped']++;
continue;
}
$batch[] = $detail;
if (count($batch) >= self::BATCH_SIZE) {
yield $batch;
$batch = [];
}
}
if ($batch) {
yield $batch;
}
}
/**
* @param array<int, array{name: string, value: string}> $tags
* @param string[] $vocabulary
*/
protected function alreadyTagged(array $tags, array $vocabulary): bool
{
$existing = collect($tags)->map(fn (array $t) => Str::lower($t['name'] ?? ''));
$vocabLower = collect($vocabulary)->map(fn (string $v) => Str::lower($v));
return $existing->intersect($vocabLower)->isNotEmpty();
}
/**
* @param array<int, array{id: int, name: string, tags: array, content: string}> $batch
* @param string[] $vocabulary
* @param array{scanned: int, tagged: int, skipped: int, failed_batches: int} $totals
*/
protected function processBatch(string $type, array $batch, array $vocabulary, bool $dryRun, array &$totals): void
{
$prompt = $this->buildPrompt($batch, $vocabulary);
$raw = $this->ai->chat([
['role' => 'system', 'content' => $prompt['system']],
['role' => 'user', 'content' => $prompt['user']],
], ['temperature' => 0]);
$assignments = $this->parseAssignments($raw, $vocabulary);
if ($assignments === null) {
$totals['failed_batches']++;
return;
}
foreach ($batch as $item) {
$labels = $assignments[(string) $item['id']] ?? [];
if (! $labels) {
continue;
}
if ($dryRun) {
$totals['tagged']++;
continue;
}
$mergedTags = $this->mergeTags($item['tags'], $labels);
if ($this->bookstack->updateTags($type, $item['id'], $mergedTags)) {
$totals['tagged']++;
}
}
}
/**
* @param array<int, array{id: int, name: string, tags: array, content: string}> $batch
* @param string[] $vocabulary
* @return array{system: string, user: string}
*/
protected function buildPrompt(array $batch, array $vocabulary): array
{
$system = 'Klasyfikujesz artykuły bazy wiedzy do kategorii zgłoszeń helpdesk. '
.'Dostępne kategorie (użyj DOKŁADNIE tej pisowni): '.implode(', ', $vocabulary).'. '
.'Dla każdego elementu przypisz 0, 1 lub więcej pasujących kategorii — nie zgaduj '
.'kategorii, jeśli żadna sensownie nie pasuje, zwróć pustą tablicę. '
.'Odpowiedz WYŁĄCZNIE obiektem JSON, bez żadnego innego tekstu ani formatowania, '
.'gdzie klucz to id elementu (jako string), a wartość to tablica dopasowanych nazw '
.'kategorii. Przykład: {"12": ["Drukarki i skanery"], "13": []}';
$user = collect($batch)->map(function (array $item) {
$excerpt = Str::limit(strip_tags($item['content']), self::CONTENT_EXCERPT_CHARS, '');
return "id={$item['id']} nazwa=\"{$item['name']}\"\n{$excerpt}";
})->implode("\n---\n");
return ['system' => $system, 'user' => $user];
}
/**
* Defensively parses the LLM's JSON response not every OpenAI-
* compatible provider (esp. self-hosted Ollama models) reliably honors a
* "respond with only JSON" instruction, so this first tries to pull out
* the first {...} block (in case the model wrapped it in prose or a
* markdown code fence) before decoding. A malformed/non-JSON response
* fails just this one batch (caller counts it in failed_batches) rather
* than aborting the whole run. Only vocabulary-matching labels survive
* (case-insensitive); anything else the model returns is discarded.
*
* @param string[] $vocabulary
* @return array<string, string[]>|null
*/
protected function parseAssignments(?string $raw, array $vocabulary): ?array
{
if (! $raw) {
return null;
}
if (! preg_match('/\{.*\}/s', $raw, $matches)) {
return null;
}
$decoded = json_decode($matches[0], true);
if (! is_array($decoded)) {
return null;
}
$vocabByLower = collect($vocabulary)->mapWithKeys(fn (string $v) => [Str::lower($v) => $v]);
$result = [];
foreach ($decoded as $id => $labels) {
if (! is_array($labels)) {
continue;
}
$result[(string) $id] = collect($labels)
->map(fn ($l) => $vocabByLower[Str::lower((string) $l)] ?? null)
->filter()
->unique()
->values()
->all();
}
return $result;
}
/**
* @param array<int, array{name: string, value: string}> $existing
* @param string[] $newLabels
* @return array<int, array{name: string, value: string}>
*/
protected function mergeTags(array $existing, array $newLabels): array
{
$existingLower = collect($existing)->map(fn (array $t) => Str::lower($t['name'] ?? ''));
$additions = collect($newLabels)
->reject(fn (string $label) => $existingLower->contains(Str::lower($label)))
->map(fn (string $label) => ['name' => $label, 'value' => '']);
return [...$existing, ...$additions->values()->all()];
}
}

View File

@@ -0,0 +1,282 @@
<?php
namespace App\Services;
use App\Models\ImapMailbox;
use App\Support\Imap\InboundEmail;
use App\Support\Settings;
use Illuminate\Http\UploadedFile;
use Illuminate\Support\Facades\Log;
use Psr\Log\LoggerInterface;
use Throwable;
use Webklex\PHPIMAP\Client;
use Webklex\PHPIMAP\ClientManager;
use Webklex\PHPIMAP\Message;
/**
* I/O layer for the "reply/create ticket by e-mail" feature connects to
* every enabled ImapMailbox, fetches unseen messages and delegates every
* decision to ImapMessageClassifier (pure logic) + TicketService (the
* existing ticket-mutation API). Kept thin and mostly untested directly;
* ImapMessageClassifier carries the actual test coverage.
*/
class ImapMailboxFetcher
{
private const HEADER_FIELDS = ['auto-submitted', 'x-autoreply', 'x-autorespond', 'precedence'];
public function __construct(
private readonly ImapMessageClassifier $classifier,
private readonly TicketService $tickets,
) {}
/**
* @return array{created: int, replied: int, rejected: int, errors: int}
*/
public function fetchAll(): array
{
$totals = ['created' => 0, 'replied' => 0, 'rejected' => 0, 'errors' => 0];
foreach (ImapMailbox::query()->where('enabled', true)->get() as $mailbox) {
foreach ($this->fetchMailbox($mailbox) as $key => $value) {
$totals[$key] += $value;
}
}
return $totals;
}
/**
* @return array{created: int, replied: int, rejected: int, errors: int}
*/
public function fetchMailbox(ImapMailbox $mailbox): array
{
$result = ['created' => 0, 'replied' => 0, 'rejected' => 0, 'errors' => 0];
$log = Log::channel('imap');
$log->info("[{$mailbox->name}] łączenie z {$mailbox->host}:{$mailbox->port} (folder: {$mailbox->folder})");
try {
$client = $this->connect($mailbox);
$folder = $client->getFolder($mailbox->folder ?: 'INBOX');
$messages = $folder->messages()->whereUnseen()->get();
$log->info("[{$mailbox->name}] {$messages->count()} nieprzeczytanych wiadomości");
foreach ($messages as $message) {
try {
$this->processMessage($mailbox, $message, $result, $log);
} catch (Throwable $e) {
$result['errors']++;
$log->error("[{$mailbox->name}] błąd przetwarzania wiadomości (uid={$message->getUid()}) — {$e->getMessage()}");
}
}
$client->disconnect();
$mailbox->update(['last_checked_at' => now(), 'last_error' => null]);
$log->info("[{$mailbox->name}] zakończono: {$result['created']} nowych, {$result['replied']} odpowiedzi, {$result['rejected']} odrzuconych, {$result['errors']} błędów");
} catch (Throwable $e) {
$result['errors']++;
$mailbox->update(['last_checked_at' => now(), 'last_error' => $e->getMessage()]);
$log->error("[{$mailbox->name}] połączenie nieudane — {$e->getMessage()}");
}
return $result;
}
/**
* Opens a connection and lists the configured folder, without fetching
* or touching any message used by the admin "Testuj połączenie" button.
* Returns null on success, the exception message on failure.
*/
public function testConnection(ImapMailbox $mailbox): ?string
{
try {
$client = $this->connect($mailbox);
$client->getFolder($mailbox->folder ?: 'INBOX');
$client->disconnect();
return null;
} catch (Throwable $e) {
return $e->getMessage();
}
}
private function connect(ImapMailbox $mailbox): Client
{
$manager = new ClientManager;
$client = $manager->make([
'host' => $mailbox->host,
'port' => $mailbox->port,
'protocol' => 'imap',
'encryption' => $mailbox->encryption === 'none' ? false : $mailbox->encryption,
'validate_cert' => $mailbox->validate_cert,
'username' => $mailbox->username,
'password' => $mailbox->password,
]);
$client->connect();
return $client;
}
/**
* @param array{created: int, replied: int, rejected: int, errors: int} $result
*/
private function processMessage(ImapMailbox $mailbox, Message $message, array &$result, LoggerInterface $log): void
{
$email = $this->toInboundEmail($message);
$uid = $message->getUid();
$log->debug("[{$mailbox->name}] uid={$uid} od={$email->fromEmail} temat=\"{$email->subject}\" nagłówki=".json_encode($email->headers, JSON_UNESCAPED_UNICODE));
$rejectReason = $this->classifier->rejectionReason($email, $mailbox->blocklistedSenders());
if ($rejectReason === null && ! $this->classifier->isSenderAllowed($email->fromEmail)) {
$rejectReason = "nadawca spoza LDAP ({$email->fromEmail}), a restrict_tickets_to_ldap jest włączone";
}
if ($rejectReason !== null) {
$this->finish($message, $mailbox->rejected_folder);
$result['rejected']++;
$log->info("[{$mailbox->name}] uid={$uid} ODRZUCONO od {$email->fromEmail} \"{$email->subject}\"{$rejectReason}");
return;
}
// Oznacz/przenieś PRZED utworzeniem ticketu: awaria w tym miejscu
// zostawia co najwyżej "przetworzoną" wiadomość bez ticketu (widoczne,
// łatwe do naprawienia ręcznie) zamiast duplikatu ticketu przy
// ponownym uruchomieniu.
$this->finish($message, $mailbox->processed_folder);
$ticket = $this->classifier->matchTicket($email->subject);
$sender = $this->classifier->resolveSender($email->fromEmail);
$attachments = $this->buildAttachments($email, $mailbox, $log);
$authorName = $email->fromName !== '' ? $email->fromName : $email->fromEmail;
if ($ticket) {
if ($sender) {
$this->tickets->clientReply($ticket, $sender, $email->body(), $attachments, source: 'email');
} else {
$this->tickets->guestReply($ticket, $authorName, $email->body(), $attachments, source: 'email');
}
$result['replied']++;
$log->info("[{$mailbox->name}] uid={$uid} ODPOWIEDŹ od {$email->fromEmail} dopisana do zgłoszenia #{$ticket->id} ({$ticket->displayNumber()})");
return;
}
$newTicket = $this->tickets->create([
'email' => $email->fromEmail,
'name' => $authorName,
'subcategory_id' => $mailbox->default_subcategory_id,
'category_id' => $mailbox->default_category_id,
'subject' => $email->subject !== '' ? $email->subject : '(bez tematu)',
'body' => $email->body(),
'source' => 'email',
], $sender, $authorName);
$result['created']++;
$log->info("[{$mailbox->name}] uid={$uid} NOWE zgłoszenie #{$newTicket->id} ({$newTicket->displayNumber()}) od {$email->fromEmail}");
}
private function finish(Message $message, ?string $moveToFolder): void
{
try {
$message->setFlag('Seen');
} catch (Throwable $e) {
Log::channel('imap')->warning("IMAP: nie udało się oznaczyć wiadomości jako przeczytanej — {$e->getMessage()}");
}
if ($moveToFolder) {
$message->move($moveToFolder);
}
}
private function toInboundEmail(Message $message): InboundEmail
{
$fromAddress = $message->getFrom()->first();
$header = $message->getHeader();
// Webklex's Header::get() returns an *empty* Attribute (not null)
// for a header that isn't present at all, and Attribute::first() on
// that empty instance comes back as '' rather than null — so a
// plain "!== null" check on the resulting value is always true,
// making every message look like it carries every one of these
// headers. Only keep a header that actually has content.
$headers = [];
foreach (self::HEADER_FIELDS as $name) {
$value = $header?->get($name)->first();
if ($value !== null && $value !== '') {
$headers[$name] = (string) $value;
}
}
return new InboundEmail(
fromEmail: $fromAddress?->mail ?? '',
fromName: $this->decodeHeaderText(trim((string) ($fromAddress?->personal ?? ''), '"')),
subject: $this->decodeHeaderText((string) $message->getSubject()),
textBody: (string) $message->getTextBody(),
htmlBody: (string) $message->getHTMLBody(),
headers: $headers,
attachments: $this->extractAttachments($message),
);
}
/**
* Some senders' mail clients leave the Subject/From display-name as raw
* RFC 2047 encoded-words (e.g. "=?utf-8?Q?...?=") instead of the
* decoded UTF-8 webklex's own config claims to produce decode
* defensively rather than showing garbled text on the ticket.
*/
private function decodeHeaderText(string $value): string
{
return $value !== '' ? mb_decode_mimeheader($value) : $value;
}
/**
* @return array<int, array{filename: string, mime: string, content: string}>
*/
private function extractAttachments(Message $message): array
{
$attachments = [];
foreach ($message->getAttachments() as $attachment) {
$attachments[] = [
'filename' => $attachment->getName() ?: 'attachment',
'mime' => $attachment->getMimeType() ?: 'application/octet-stream',
'content' => $attachment->getContent(),
];
}
return $attachments;
}
/**
* Converts raw attachment bytes into UploadedFile instances (via a temp
* file + the $test=true flag, which lets Symfony's UploadedFile skip the
* is_uploaded_file() check outside of a real HTTP request) so they flow
* through TicketService::attachFiles() unchanged. Validated the same way
* every other caller validates before calling attachFiles() a mail
* carrying an oversized/disallowed attachment still creates the
* ticket/reply, just without that attachment, rather than being dropped
* entirely or silently bypassing the admin's attachment policy.
*
* @return UploadedFile[]
*/
private function buildAttachments(InboundEmail $email, ImapMailbox $mailbox, LoggerInterface $log): array
{
$files = [];
foreach ($email->attachments as $attachment) {
$path = tempnam(sys_get_temp_dir(), 'imap_');
file_put_contents($path, $attachment['content']);
$files[] = new UploadedFile($path, $attachment['filename'], $attachment['mime'], null, true);
}
if ($files && ($error = Settings::validateAttachments($files))) {
$log->warning("[{$mailbox->name}] pominięto załączniki wiadomości od {$email->fromEmail}{$error}");
return [];
}
return $files;
}
}

View File

@@ -0,0 +1,137 @@
<?php
namespace App\Services;
use App\Models\Ticket;
use App\Models\User;
use App\Support\Imap\InboundEmail;
use App\Support\Settings;
/**
* Pure decision logic for the IMAP fetcher no IMAP connection, no
* side effects, so it's fully Pest-testable against hand-built
* InboundEmail instances. ImapMailboxFetcher does all the I/O and calls
* into this for every decision.
*/
class ImapMessageClassifier
{
/**
* RFC 3834 (Auto-Submitted) + common vendor headers, plus EN/PL subject
* phrasing for autoresponders/bounces that don't set those headers at
* all the two layers catch most real-world autoresponders/mailer-daemons.
*/
private const AUTO_REPLY_SUBJECT_PATTERNS = [
'/\bout of office\b/i',
'/\bautomatic reply\b/i',
'/\bautomatyczna odpowiedz\b/iu',
'/\bautoresponder\b/i',
'/\bundeliverable\b/i',
'/\bundelivered\b/i',
'/\bmail delivery failed\b/i',
'/\bdelivery status notification\b/i',
'/\bnieobecnosc\b.*\bbiurze\b/iu',
];
/**
* Returns a human-readable rejection reason, or null if the message
* should be processed as a genuine ticket/reply.
*
* @param string[] $extraBlocklist additional blocked sender local-parts/addresses (per-mailbox)
*/
public function rejectionReason(InboundEmail $email, array $extraBlocklist = []): ?string
{
$autoSubmitted = strtolower((string) $email->header('auto-submitted'));
if ($autoSubmitted !== '' && $autoSubmitted !== 'no') {
return "Auto-Submitted: {$autoSubmitted}";
}
if ($email->header('x-autoreply') !== null || $email->header('x-autorespond') !== null) {
return 'X-Autoreply/X-Autorespond header present';
}
$precedence = strtolower((string) $email->header('precedence'));
if (in_array($precedence, ['bulk', 'junk', 'list'], true)) {
return "Precedence: {$precedence}";
}
$senderLocalPart = strtolower(explode('@', $email->fromEmail)[0] ?? '');
$blocked = array_map('strtolower', $extraBlocklist);
if ($senderLocalPart !== '' && in_array($senderLocalPart, $blocked, true)) {
return "Blocked sender: {$email->fromEmail}";
}
if (in_array(strtolower($email->fromEmail), $blocked, true)) {
return "Blocked sender: {$email->fromEmail}";
}
foreach (self::AUTO_REPLY_SUBJECT_PATTERNS as $pattern) {
if (preg_match($pattern, $email->subject) === 1) {
return "Subject matched auto-reply pattern ({$pattern})";
}
}
return null;
}
/**
* Same gate Landing::submit() applies to web/guest ticket creation
* (Settings::bool('restrict_tickets_to_ldap')) must apply identically
* to mail-originated tickets/replies, or the restriction has a hole.
*/
public function isSenderAllowed(string $email): bool
{
if (! Settings::bool('restrict_tickets_to_ldap')) {
return true;
}
return User::query()->where('email', $email)->exists()
|| app(LdapUserProvisioner::class)->existsInLdap($email);
}
/**
* Existing local user, or an LDAP-provisioned one if enabled mirrors
* TicketService::create()'s own guest-resolution branch. Returns null
* for a genuine, unprovisionable guest.
*/
public function resolveSender(string $email): ?User
{
if ($user = User::query()->where('email', $email)->first()) {
return $user;
}
if (Settings::bool('ldap_auto_provision_guests')) {
return app(LdapUserProvisioner::class)->findOrCreateByEmail($email);
}
return null;
}
/**
* Strips common reply/forward prefixes, then tries every digit run of
* length >= 4 (longest first) against Ticket::resolveRouteBinding()
* covers both the plain sequential number and the obfuscated checksum,
* since both are plain digit strings and every outbound notification
* subject already carries one (see database/seeders/DatabaseSeeder.php).
* Prefix-aware matching was considered and rejected: {numer} email
* templates hardcode their own literal '#', independent of the
* admin-configurable ticket_number_prefix setting, and templates are
* themselves admin-editable.
*/
public function matchTicket(string $subject): ?Ticket
{
$cleaned = preg_replace('/^\s*(re|odp|fwd|fw|aw)\s*:\s*/i', '', $subject) ?? $subject;
$cleaned = preg_replace('/^\s*(re|odp|fwd|fw|aw)\s*:\s*/i', '', $cleaned) ?? $cleaned;
preg_match_all('/\d{4,}/', $cleaned, $matches);
$tokens = $matches[0] ?? [];
usort($tokens, fn ($a, $b) => strlen($b) <=> strlen($a));
foreach ($tokens as $token) {
$ticket = (new Ticket)->resolveRouteBinding($token);
if ($ticket) {
return $ticket;
}
}
return null;
}
}

View File

@@ -2,10 +2,11 @@
namespace App\Services;
use App\Ldap\LldapUser;
use App\Models\User;
use App\Models\UserField;
use App\Support\Settings;
use Illuminate\Support\Facades\Log;
use LdapRecord\Models\Model as LdapModel;
use Throwable;
/**
@@ -80,11 +81,26 @@ class LdapUserProvisioner
return $matched;
}
protected function findLdapEntryForUser(User $user): ?LldapUser
/**
* The LdapRecord model class for whichever directory is currently
* configured (LLDAP vs Active Directory see
* Settings::ldapUserModelClass()) resolved fresh on every call rather
* than cached, since an admin can flip the directory type mid-session.
*/
protected function ldapUserModel(): string
{
return Settings::ldapUserModelClass();
}
protected function findLdapEntryForUser(User $user): ?LdapModel
{
if ($user->guid) {
try {
$byGuid = LldapUser::query()->where('entryuuid', '=', $user->guid)->first();
// findByGuid() builds the right raw filter for either a
// binary objectGUID (AD) or a plain entryUUID string
// (LLDAP/OpenLDAP) — unlike a plain ->where(), it doesn't
// need to know which attribute that is.
$byGuid = $this->ldapUserModel()::query()->findByGuid($user->guid);
} catch (Throwable $e) {
Log::warning('LDAP lookup by guid failed: '.$e->getMessage());
$byGuid = null;
@@ -98,10 +114,10 @@ class LdapUserProvisioner
return $this->findLdapEntryByEmail($user->email);
}
protected function findLdapEntryByEmail(string $email): ?LldapUser
protected function findLdapEntryByEmail(string $email): ?LdapModel
{
try {
return LldapUser::query()->where('mail', '=', $email)->first();
return $this->ldapUserModel()::query()->where('mail', '=', $email)->first();
} catch (Throwable $e) {
Log::warning('LDAP lookup by email failed: '.$e->getMessage());
@@ -109,7 +125,7 @@ class LdapUserProvisioner
}
}
public function applyFieldsFromLdap(User $user, LldapUser $ldapEntry): void
public function applyFieldsFromLdap(User $user, LdapModel $ldapEntry): void
{
$values = $user->custom_field_values ?? [];

View File

@@ -0,0 +1,212 @@
<?php
namespace App\Services;
use App\Support\Settings;
use Illuminate\Support\Facades\Cache;
use Illuminate\Support\Facades\Http;
class SnipeItClient
{
public function enabled(): bool
{
return Settings::bool('snipeit_enabled')
&& Settings::get('snipeit_base_url')
&& Settings::get('snipeit_api_token');
}
/**
* Assets Snipe-IT has checked out to $email feeds the "Sprzęt
* zgłaszającego" sidebar shown to a client creating a ticket and to an
* operator viewing one. Snipe-IT has no "assets by e-mail" endpoint, so
* this looks the requester up as a Snipe-IT user first, then lists what's
* assigned to them. Cached briefly per e-mail since the ticket-creation
* form and ticket-view page both re-render this on every interaction.
*
* @return array<int, array{id: int, label: string, serial: ?string, manufacturer: ?string, model: ?string, category: ?string, status: ?string, url: string}>
*/
public function assetsForEmail(string $email): array
{
$email = trim($email);
if (! $this->enabled() || $email === '') {
return [];
}
return Cache::remember('snipeit:user-assets:'.md5(strtolower($email)), now()->addMinutes(5), function () use ($email) {
try {
$user = $this->findUserByEmail($email);
if (! $user) {
return [];
}
$response = $this->client()->get("/users/{$user['id']}/assets");
if (! $response->successful()) {
return [];
}
return collect($response->json('rows', []))
->map(fn (array $a) => $this->normalizeAsset($a))
->values()
->all();
} catch (\Throwable) {
return [];
}
});
}
/**
* Full-inventory search behind the operator's "przeszukaj cały
* inwentarz" picker — unlike assetsForEmail() this isn't scoped to any
* one requester. Uncached: it's a live, as-you-type lookup.
*
* @return array<int, array{id: int, label: string, serial: ?string, manufacturer: ?string, model: ?string, category: ?string, status: ?string, url: string}>
*/
public function searchAssets(string $query, int $limit = 10): array
{
$query = trim($query);
if (! $this->enabled() || $query === '') {
return [];
}
try {
$response = $this->client()->get('/hardware', ['search' => $query, 'limit' => $limit]);
if (! $response->successful()) {
return [];
}
return collect($response->json('rows', []))
->map(fn (array $a) => $this->normalizeAsset($a))
->values()
->all();
} catch (\Throwable) {
return [];
}
}
/**
* Live detail for a ticket's linked asset fetched fresh rather than
* trusting the ticket's cached snipeit_asset_name, so a status/
* reassignment change in Snipe-IT is reflected immediately. Null if
* unreachable or the asset was deleted there; callers fall back to the
* cached label in that case.
*
* @return array{id: int, label: string, serial: ?string, manufacturer: ?string, model: ?string, category: ?string, status: ?string, assignedTo: ?string, url: string}|null
*/
public function asset(int $id): ?array
{
if (! $this->enabled()) {
return null;
}
try {
$response = $this->client()->get("/hardware/{$id}");
if (! $response->successful()) {
return null;
}
$data = $response->json();
return [
...$this->normalizeAsset($data),
'assignedTo' => $data['assigned_to']['name'] ?? null,
];
} catch (\Throwable) {
return null;
}
}
/**
* Tests unsaved admin-form values directly, rather than whatever's
* currently stored mirrors BookStackClient::testConnection(). Hits a
* plain list endpoint (rather than e.g. /users/me, which isn't present
* on every Snipe-IT version) so this works as a version-agnostic
* auth+reachability check.
*
* @return array{ok: bool, message: ?string}
*/
public function testConnection(string $baseUrl, string $token, bool $verifySsl = true): array
{
try {
$response = Http::withToken($token)
->acceptJson()
->withOptions(['verify' => $verifySsl])
->timeout(6)
->get(rtrim($baseUrl, '/').'/api/v1/hardware', ['limit' => 1]);
if ($response->successful()) {
return ['ok' => true, 'message' => null];
}
$message = $response->json('messages') ?? $response->json('message');
return [
'ok' => false,
'message' => is_string($message) ? $message : ($message ? json_encode($message) : ('HTTP '.$response->status())),
];
} catch (\Throwable $e) {
return ['ok' => false, 'message' => $e->getMessage()];
}
}
protected function findUserByEmail(string $email): ?array
{
$response = $this->client()->get('/users', ['search' => $email, 'limit' => 5]);
if (! $response->successful()) {
return null;
}
return collect($response->json('rows', []))
->first(fn (array $u) => isset($u['email']) && strcasecmp($u['email'], $email) === 0);
}
/**
* label is "numer środka - numer seryjny - producent model" joining
* whichever of those three pieces is actually present (Snipe-IT doesn't
* guarantee any of them), falling back to the bare asset id if all three
* are blank. The display format requested for the "Sprzęt zgłaszającego"
* picker and sidebar, everywhere an asset is listed.
*
* @return array{id: int, label: string, serial: ?string, manufacturer: ?string, model: ?string, category: ?string, status: ?string, url: string}
*/
protected function normalizeAsset(array $a): array
{
$assetTag = $a['asset_tag'] ?? null;
$serial = $a['serial'] ?? null;
$manufacturer = $a['manufacturer']['name'] ?? null;
$model = $a['model']['name'] ?? null;
$modelDisplay = trim(($manufacturer ? "{$manufacturer} " : '').($model ?? ''));
$labelParts = collect([$assetTag, $serial, $modelDisplay])
->map(fn ($v) => trim((string) $v))
->filter(fn ($v) => $v !== '');
$label = $labelParts->isNotEmpty() ? $labelParts->implode(' - ') : 'Zasób #'.$a['id'];
return [
'id' => $a['id'],
'label' => $label,
'serial' => $serial,
'manufacturer' => $manufacturer,
'model' => $model,
'category' => $a['category']['name'] ?? null,
'status' => $a['status_label']['name'] ?? null,
'url' => rtrim(Settings::get('snipeit_base_url'), '/').'/hardware/'.$a['id'],
];
}
protected function client()
{
return Http::withToken(Settings::get('snipeit_api_token'))
->acceptJson()
->withOptions(['verify' => Settings::bool('snipeit_verify_ssl')])
->timeout(6)
->baseUrl(rtrim(Settings::get('snipeit_base_url'), '/').'/api/v1');
}
}

View File

@@ -0,0 +1,166 @@
<?php
namespace App\Services;
use App\Models\Ticket;
use App\Support\Settings;
use Illuminate\Database\Eloquent\Builder;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Str;
/**
* Generates an AI summary + suggested next action for every ticket, cached
* on the ticket row and shown only in the operator view (see
* TicketAiTriageService's docblock for why this runs from the scheduled
* ai:run-ticket-automation command rather than live on page load). Stays
* reasonably fresh by regenerating whenever a ticket's latest message
* postdates its last summary, not on every scheduler tick for every ticket.
*/
class TicketAiSummaryService
{
protected const BATCH_LIMIT = 25;
protected const MESSAGE_EXCERPT_CHARS = 1500;
protected const BODY_EXCERPT_CHARS = 4000;
protected const TRANSCRIPT_MESSAGE_LIMIT = 30;
public function __construct(protected AiClient $ai) {}
/**
* @return array{scanned: int, updated: int, failed: int}
*/
public function run(?int $limit = null): array
{
$totals = ['scanned' => 0, 'updated' => 0, 'failed' => 0];
if (! $this->ai->enabled() || ! Settings::bool('ai_summary_enabled')) {
return $totals;
}
$this->staleQuery()
->limit($limit ?? self::BATCH_LIMIT)
->get()
->each(function (Ticket $ticket) use (&$totals) {
$totals['scanned']++;
$this->summarizeOne($ticket) ? $totals['updated']++ : $totals['failed']++;
});
return $totals;
}
/**
* Tickets with no summary yet, or whose latest message postdates the
* last summary generation. Deliberately compares against
* ticket_messages.created_at rather than tickets.updated_at the
* latter also changes on unrelated actions (status/priority/timer
* edits), which would otherwise trigger spurious re-summarization on
* every scheduler tick for an active ticket.
*/
protected function staleQuery(): Builder
{
return Ticket::query()->where(function (Builder $q) {
$q->whereNull('ai_summary_generated_at')
->orWhere(function (Builder $q2) {
$q2->whereNotNull('ai_summary_generated_at')
->whereColumn('ai_summary_generated_at', '<', DB::raw(
'(select max(ticket_messages.created_at) from ticket_messages where ticket_messages.ticket_id = tickets.id)'
));
});
})->orderBy('id');
}
/**
* Regenerates the summary for a single ticket right now, bypassing the
* staleness check used by the manual "regenerate" button and the
* on-new-message hook, as opposed to run()'s scheduled batch sweep.
*/
public function generateFor(Ticket $ticket): bool
{
if (! $this->ai->enabled() || ! Settings::bool('ai_summary_enabled')) {
return false;
}
return $this->summarizeOne($ticket);
}
protected function summarizeOne(Ticket $ticket): bool
{
$raw = $this->ai->chat([
['role' => 'system', 'content' => Settings::get('ai_summary_prompt')],
['role' => 'user', 'content' => $this->buildTranscript($ticket)],
], ['temperature' => 0.2]);
$parsed = $this->parseResponse($raw);
if ($parsed === null) {
// Leaves any prior summary untouched and generated_at unchanged,
// so the ticket stays in the stale set and gets retried next run
// rather than silently losing a working summary.
return false;
}
$ticket->update([
'ai_summary' => $parsed['summary'],
'ai_suggested_action' => $parsed['suggested_action'],
'ai_summary_generated_at' => now(),
]);
return true;
}
/**
* Includes tickets.body explicitly (the opening description, separate
* from ticket_messages) rather than relying on it showing up as the
* thread's first message that row falls outside the last-N transcript
* window on any ticket with more than TRANSCRIPT_MESSAGE_LIMIT messages,
* which would otherwise silently drop the original request from long
* threads. Mirrors TicketAiTriageService's own subject+body framing.
*/
protected function buildTranscript(Ticket $ticket): string
{
$lines = [
"Temat: {$ticket->subject}",
"Treść:\n".Str::limit(strip_tags($ticket->body), self::BODY_EXCERPT_CHARS),
];
$ticket->messages()->latest('created_at')->limit(self::TRANSCRIPT_MESSAGE_LIMIT)->get()
->sortBy('created_at')
->each(function ($message) use (&$lines) {
$role = $message->internal ? 'notatka wewnętrzna' : ($message->role === 'client' ? 'klient' : 'operator');
$body = Str::limit(strip_tags($message->body), self::MESSAGE_EXCERPT_CHARS, '');
$lines[] = "[{$role}] {$message->author_name}: {$body}";
});
return implode("\n\n", $lines);
}
/**
* Same defensive-parsing shape used elsewhere in this app's AI services
* (BookStackContentTagger, TicketAiTriageService) extracts the first
* {...} block before decoding.
*
* @return array{summary: string, suggested_action: ?string}|null
*/
protected function parseResponse(?string $raw): ?array
{
if (! $raw || ! preg_match('/\{.*\}/s', $raw, $matches)) {
return null;
}
$decoded = json_decode($matches[0], true);
if (! is_array($decoded) || empty($decoded['summary']) || ! is_string($decoded['summary'])) {
return null;
}
return [
'summary' => trim($decoded['summary']),
'suggested_action' => ! empty($decoded['suggested_action']) && is_string($decoded['suggested_action'])
? trim($decoded['suggested_action'])
: null,
];
}
}

View File

@@ -0,0 +1,311 @@
<?php
namespace App\Services;
use App\Models\Category;
use App\Models\Priority;
use App\Models\Ticket;
use App\Support\Settings;
use Illuminate\Support\Str;
/**
* One-shot AI classification of new tickets, gated by 5 independent
* settings toggles (ai_triage_category_when_missing/
* subcategory_when_category_only/recheck_categorized/fix_subject/
* set_priority). Runs from the scheduled ai:run-ticket-automation command,
* never synchronously at ticket creation, so it never adds LLM latency to a
* live customer submitting a ticket. Every scanned ticket gets
* ai_triaged_at stamped exactly once this is a one-shot pass per ticket,
* not a continuous recheck, and there's no manual re-trigger by design.
*/
class TicketAiTriageService
{
protected const BATCH_LIMIT = 25;
protected const BODY_EXCERPT_CHARS = 4000;
public function __construct(
protected AiClient $ai,
protected TicketService $tickets,
) {}
/**
* @return array{scanned: int, changed: int, failed: int}
*/
public function run(?int $limit = null): array
{
$totals = ['scanned' => 0, 'changed' => 0, 'failed' => 0];
if (! $this->ai->enabled() || ! $this->anyToggleEnabled()) {
return $totals;
}
$vocabulary = $this->buildVocabulary();
$priorities = Priority::query()->orderBy('sort_order')->pluck('label', 'key')->all();
Ticket::query()->whereNull('ai_triaged_at')
->orderBy('id')
->limit($limit ?? self::BATCH_LIMIT)
->get()
->each(function (Ticket $ticket) use ($vocabulary, $priorities, &$totals) {
$totals['scanned']++;
$this->triageOne($ticket, $vocabulary, $priorities, $totals);
});
return $totals;
}
protected function anyToggleEnabled(): bool
{
return Settings::bool('ai_triage_category_when_missing')
|| Settings::bool('ai_triage_subcategory_when_category_only')
|| Settings::bool('ai_triage_recheck_categorized')
|| Settings::bool('ai_triage_fix_subject')
|| Settings::bool('ai_triage_set_priority');
}
/**
* @param array<int, array{id: int, name: string, subcategories: array<int, array{id: int, name: string}>}> $vocabulary
* @param array<string, string> $priorities
* @param array{scanned: int, changed: int, failed: int} $totals
*/
protected function triageOne(Ticket $ticket, array $vocabulary, array $priorities, array &$totals): void
{
$prompt = $this->buildPrompt($ticket, $vocabulary, $priorities);
if ($prompt === null) {
$ticket->update(['ai_triaged_at' => now()]);
return;
}
$raw = $this->ai->chat([
['role' => 'system', 'content' => $prompt['system']],
['role' => 'user', 'content' => $prompt['user']],
], ['temperature' => 0]);
$parsed = $this->parseResponse($raw);
// A response came back but couldn't be parsed — not fatal to the
// run, just means this ticket wasn't classified this time.
// ai_triaged_at is still stamped below so a persistently-bad
// response doesn't get retried forever.
if ($raw !== null && $parsed === null) {
$totals['failed']++;
}
[$changes, $historyLines] = $parsed
? $this->resolveChanges($ticket, $parsed, $vocabulary, $priorities, $prompt['scope'])
: [[], []];
if ($changes) {
$this->tickets->applyAiTriage($ticket, $changes, $historyLines);
$totals['changed']++;
}
$ticket->update(['ai_triaged_at' => now()]);
}
/**
* @return array<int, array{id: int, name: string, subcategories: array<int, array{id: int, name: string}>}>
*/
protected function buildVocabulary(): array
{
return Category::query()->with('subcategories')->get()
->map(fn (Category $c) => [
'id' => $c->id,
'name' => $c->name,
'subcategories' => $c->subcategories->map(fn ($s) => ['id' => $s->id, 'name' => $s->name])->all(),
])
->all();
}
/**
* Determines which of the 3 mutually-exclusive category scenarios (if
* any) applies to $ticket's current state, and whether subject/priority
* are also in scope, then builds the prompt around exactly that. Returns
* null when nothing is applicable/enabled for this ticket, so the caller
* can skip straight to stamping ai_triaged_at without an AI call.
*
* @param array<int, array{id: int, name: string, subcategories: array}> $vocabulary
* @param array<string, string> $priorities
* @return array{system: string, user: string, scope: ?string}|null
*/
protected function buildPrompt(Ticket $ticket, array $vocabulary, array $priorities): ?array
{
$scope = null;
if (! $ticket->category_id && ! $ticket->subcategory_id && Settings::bool('ai_triage_category_when_missing')) {
$scope = 'missing';
} elseif ($ticket->category_id && ! $ticket->subcategory_id && Settings::bool('ai_triage_subcategory_when_category_only')) {
$scope = 'category_only';
} elseif ($ticket->subcategory_id && Settings::bool('ai_triage_recheck_categorized')) {
$scope = 'recheck';
}
$wantSubject = Settings::bool('ai_triage_fix_subject');
$wantPriority = Settings::bool('ai_triage_set_priority');
if ($scope === null && ! $wantSubject && ! $wantPriority) {
return null;
}
$parts = ['Klasyfikujesz zgłoszenia helpdesku na podstawie tematu i treści.'];
if ($scope === 'missing') {
$parts[] = 'To zgłoszenie nie ma jeszcze przypisanej kategorii ani podkategorii. Wybierz najlepiej '
.'pasującą kategorię z listy poniżej (użyj DOKŁADNIE tej pisowni) i, jeśli to możliwe, także '
.'konkretną podkategorię w jej ramach. Jeśli żadna kategoria sensownie nie pasuje, zwróć null dla obu pól.';
} elseif ($scope === 'category_only') {
$parts[] = "To zgłoszenie ma już przypisaną kategorię \"{$ticket->category->name}\", ale brak konkretnej "
.'podkategorii. Wybierz najlepiej pasującą podkategorię z listy poniżej (należącą do tej kategorii, '
.'użyj DOKŁADNIE tej pisowni). Jeśli żadna nie pasuje dobrze, zwróć null.';
} elseif ($scope === 'recheck') {
$parts[] = "To zgłoszenie ma już przypisaną podkategorię \"{$ticket->subcategory->label()}\". Sprawdź, "
.'czy to nadal najlepsze dopasowanie na podstawie treści. Jeśli tak — zwróć null (nic nie zmieniaj). '
.'Jeśli lepiej pasuje inna kategoria/podkategoria z listy poniżej, zwróć ją.';
}
if ($scope !== null) {
$parts[] = "Dostępne kategorie i podkategorie:\n".$this->vocabularyText($vocabulary, $scope, $ticket);
}
if ($wantSubject) {
$parts[] = 'Jeśli obecny temat zgłoszenia jest niejasny lub mylący, zaproponuj lepszy, zwięzły temat po '
.'polsku w polu "subject" (w przeciwnym razie null).';
}
if ($wantPriority) {
$priorityList = collect($priorities)->map(fn ($label, $key) => "{$key} ({$label})")->implode(', ');
$parts[] = 'Na podstawie treści oceń priorytet zgłoszenia i zwróć jego klucz w polu "priority" — '
."dostępne klucze: {$priorityList}.";
}
$parts[] = 'Odpowiedz WYŁĄCZNIE obiektem JSON, bez żadnego innego tekstu ani formatowania: '
.'{"category": "...", "subcategory": "...", "subject": "...", "priority": "..."} — pola, o które nie '
.'proszono powyżej, ustaw na null.';
$user = "Temat: {$ticket->subject}\n\nTreść:\n".Str::limit(strip_tags($ticket->body), self::BODY_EXCERPT_CHARS);
return ['system' => implode("\n\n", $parts), 'user' => $user, 'scope' => $scope];
}
/**
* @param array<int, array{id: int, name: string, subcategories: array<int, array{id: int, name: string}>}> $vocabulary
*/
protected function vocabularyText(array $vocabulary, string $scope, Ticket $ticket): string
{
$categories = $scope === 'category_only'
? collect($vocabulary)->filter(fn (array $c) => $c['id'] === $ticket->category_id)
: collect($vocabulary);
return $categories
->map(fn (array $c) => "- {$c['name']}: ".collect($c['subcategories'])->pluck('name')->implode(', '))
->implode("\n");
}
/**
* Same defensive-parsing shape as BookStackContentTagger::parseAssignments()
* extracts the first {...} block before decoding, so prose-wrapped or
* malformed responses fail gracefully instead of crashing the run.
*/
protected function parseResponse(?string $raw): ?array
{
if (! $raw || ! preg_match('/\{.*\}/s', $raw, $matches)) {
return null;
}
$decoded = json_decode($matches[0], true);
return is_array($decoded) ? $decoded : null;
}
/**
* Fail-closed resolution: every value from the model is matched against
* the real vocabulary/priority list before being trusted an
* unmatched/hallucinated category, a subcategory outside its claimed
* category, or an unknown priority key is silently dropped rather than
* written to the ticket. Only fields whose resolved value actually
* differs from the ticket's current value produce a change + history
* line, so e.g. a "recheck" that confirms the existing subcategory
* leaves no trace.
*
* @param array<int, array{id: int, name: string, subcategories: array<int, array{id: int, name: string}>}> $vocabulary
* @param array<string, string> $priorities
* @return array{0: array<string, mixed>, 1: string[]}
*/
protected function resolveChanges(Ticket $ticket, array $parsed, array $vocabulary, array $priorities, ?string $scope): array
{
$changes = [];
$historyLines = [];
if ($scope !== null) {
$resolved = $this->resolveCategory($parsed, $vocabulary, $scope, $ticket);
if ($resolved) {
[$categoryId, $subcategoryId, $label] = $resolved;
if ($categoryId !== $ticket->category_id || $subcategoryId !== $ticket->subcategory_id) {
$changes['category_id'] = $categoryId;
$changes['subcategory_id'] = $subcategoryId;
$historyLines[] = "Kategoria zmieniona na: {$label}";
}
}
}
if (Settings::bool('ai_triage_fix_subject') && ! empty($parsed['subject']) && is_string($parsed['subject'])) {
$newSubject = Str::limit(trim($parsed['subject']), 255, '');
if ($newSubject !== '' && $newSubject !== $ticket->subject) {
$changes['subject'] = $newSubject;
$historyLines[] = "Temat zmieniony na: „{$newSubject}";
}
}
if (Settings::bool('ai_triage_set_priority') && ! empty($parsed['priority']) && is_string($parsed['priority'])) {
$key = collect($priorities)->keys()->first(fn ($k) => Str::lower($k) === Str::lower($parsed['priority']));
if ($key !== null && $key !== $ticket->priority_key) {
$changes['priority_key'] = $key;
$historyLines[] = 'Priorytet zmieniony na: '.Priority::labelFor($key);
}
}
return [$changes, $historyLines];
}
/**
* @param array<int, array{id: int, name: string, subcategories: array<int, array{id: int, name: string}>}> $vocabulary
* @return array{0: ?int, 1: ?int, 2: string}|null [category_id, subcategory_id, display label]
*/
protected function resolveCategory(array $parsed, array $vocabulary, string $scope, Ticket $ticket): ?array
{
$categories = $scope === 'category_only'
? collect($vocabulary)->filter(fn (array $c) => $c['id'] === $ticket->category_id)
: collect($vocabulary);
$subName = $parsed['subcategory'] ?? null;
if (is_string($subName) && $subName !== '') {
foreach ($categories as $category) {
foreach ($category['subcategories'] as $sub) {
if (Str::lower($sub['name']) === Str::lower($subName)) {
return [null, $sub['id'], "{$category['name']} / {$sub['name']}"];
}
}
}
}
$catName = $parsed['category'] ?? null;
if (is_string($catName) && $catName !== '') {
foreach ($categories as $category) {
if (Str::lower($category['name']) === Str::lower($catName)) {
return [$category['id'], null, $category['name']];
}
}
}
return null;
}
}

View File

@@ -2,7 +2,10 @@
namespace App\Services;
use App\Events\TicketMessagePosted;
use App\Events\TicketQueueChanged;
use App\Models\ApiClient;
use App\Models\NotificationPreference;
use App\Models\NotificationSetting;
use App\Models\Priority;
use App\Models\Status;
@@ -14,6 +17,7 @@ use App\Models\User;
use App\Notifications\TicketNotification;
use App\Support\Settings;
use Illuminate\Http\UploadedFile;
use Illuminate\Support\Facades\Auth;
use Illuminate\Support\Facades\Notification;
use Illuminate\Support\Facades\Storage;
@@ -38,6 +42,10 @@ class TicketService
'email' => $customer?->email ?? $data['email'],
'name' => $customer?->name ?? ($data['name'] ?? $data['email']),
'subcategory_id' => $subcategory?->id,
// category_id only ever carries a value when there's no
// subcategory to derive one from (e.g. an IMAP mailbox routed to
// a whole category rather than a specific subcategory).
'category_id' => $subcategory ? null : ($data['category_id'] ?? null),
'subject' => $data['subject'],
'body' => $data['body'],
'status_key' => Settings::get('default_status', 'new'),
@@ -45,6 +53,10 @@ class TicketService
'team_id' => $this->autoAssignTeam($subcategory),
'assignee_id' => $data['assignee_id'] ?? null,
'custom_fields' => $data['custom_values'] ?? [],
'last_customer_activity_at' => now(),
'source' => $data['source'] ?? 'web',
'snipeit_asset_id' => $data['snipeit_asset_id'] ?? null,
'snipeit_asset_name' => $data['snipeit_asset_name'] ?? null,
]);
$message = $ticket->messages()->create([
@@ -54,6 +66,9 @@ class TicketService
$message->attachAuthor($customer?->id, 'client');
$this->notify($ticket, 'ticket_created');
$this->notify($ticket, 'ticket_created_team');
app(TriggerEngine::class)->handle($ticket, 'ticket_created');
TicketQueueChanged::dispatch($ticket->id, 'created', Auth::id());
return $ticket;
}
@@ -87,9 +102,17 @@ class TicketService
// the running segment (if any) the moment a ticket is closed,
// regardless of which flow triggered the status change.
$ticket->stopTimer();
// A closed ticket that reopens later should give every automation
// rule a clean slate rather than staying latched from before.
$ticket->automationRuleLogs()->delete();
} else {
$this->notify($ticket, 'status_changed');
}
app(TriggerEngine::class)->handle($ticket, 'status_changed');
app(TriggerEngine::class)->handle($ticket, 'ticket_updated');
TicketQueueChanged::dispatch($ticket->id, 'status_changed', Auth::id());
}
public function submitCsat(Ticket $ticket, int $rating, ?string $comment = null): void
@@ -113,6 +136,9 @@ class TicketService
$ticket->update(['priority_key' => $priorityKey]);
$ticket->addHistory('Priorytet zmieniony na: '.Priority::labelFor($priorityKey));
$this->notify($ticket, 'priority_changed');
app(TriggerEngine::class)->handle($ticket, 'priority_changed');
app(TriggerEngine::class)->handle($ticket, 'ticket_updated');
TicketQueueChanged::dispatch($ticket->id, 'priority_changed', Auth::id());
}
public function setAssignee(Ticket $ticket, ?User $assignee): void
@@ -122,6 +148,9 @@ class TicketService
$ticket->update(['assignee_id' => $assignee?->id, 'sla_notified_at' => null]);
$ticket->addHistory('Przypisano do: '.($assignee?->name ?? 'Nieprzypisane'));
$this->notify($ticket, 'assignee_changed');
app(TriggerEngine::class)->handle($ticket, 'assignee_changed');
app(TriggerEngine::class)->handle($ticket, 'ticket_updated');
TicketQueueChanged::dispatch($ticket->id, 'assignee_changed', Auth::id());
}
public function setTeam(Ticket $ticket, ?Team $team): void
@@ -129,6 +158,55 @@ class TicketService
$ticket->update(['team_id' => $team?->id]);
$ticket->addHistory('Zespół zmieniony na: '.($team?->name ?? 'Brak'));
$this->notify($ticket, 'team_changed');
app(TriggerEngine::class)->handle($ticket, 'team_changed');
app(TriggerEngine::class)->handle($ticket, 'ticket_updated');
TicketQueueChanged::dispatch($ticket->id, 'team_changed', Auth::id());
}
/**
* Applies one AI-triage pass's changes (see TicketAiTriageService) in a
* single update, rather than composing setPriority()/updateDetails()
* a pass can touch category, subcategory, subject and priority
* together, and those would each write their own generic history line
* and fire notify()/TriggerEngine::handle() per field instead of once
* per pass, fragmenting one semantic AI decision into several
* unrelated-looking edits. $historyLines carries one mechanical
* "X changed to: Y" line per changed field (built by the caller, since
* it already knows the human-readable labels); this always appends one
* more attribution line on top, mirroring how RunAutomationRules logs
* "Automatyzacja: {label}" after its own field-change lines.
*
* @param array<string, mixed> $changes column => value, only the fields that actually changed
* @param string[] $historyLines
*/
public function applyAiTriage(Ticket $ticket, array $changes, array $historyLines): void
{
if (! $changes) {
return;
}
$categoryChanged = array_key_exists('category_id', $changes) || array_key_exists('subcategory_id', $changes);
$priorityChanged = array_key_exists('priority_key', $changes);
$ticket->update($changes);
foreach ($historyLines as $line) {
$ticket->addHistory($line);
}
$ticket->addHistory('Automatyzacja: klasyfikacja AI');
if ($categoryChanged) {
$this->notify($ticket, 'category_changed');
app(TriggerEngine::class)->handle($ticket, 'category_changed');
}
if ($priorityChanged) {
$this->notify($ticket, 'priority_changed');
app(TriggerEngine::class)->handle($ticket, 'priority_changed');
}
app(TriggerEngine::class)->handle($ticket, 'ticket_updated');
TicketQueueChanged::dispatch($ticket->id, 'ai_triage', Auth::id());
}
public function setReporter(Ticket $ticket, User $customer): void
@@ -137,6 +215,27 @@ class TicketService
$ticket->addHistory('Zgłaszający zmieniony na: '.$customer->name);
}
/**
* Links/unlinks the Snipe-IT asset attached to a ticket $asset null
* unlinks. Only the label (not live status/assignment) is cached on the
* ticket row, so it still shows something if Snipe-IT later becomes
* unreachable or the asset is deleted there, without a live API call on
* every ticket list render (see SnipeItClient::asset() for the live
* fetch used on the ticket-detail page itself).
*
* @param array{id: int, label: string}|null $asset
*/
public function setSnipeitAsset(Ticket $ticket, ?array $asset): void
{
$ticket->update([
'snipeit_asset_id' => $asset['id'] ?? null,
'snipeit_asset_name' => $asset['label'] ?? null,
]);
$ticket->addHistory($asset
? 'Powiązano sprzęt (inwentarz): '.$asset['label']
: 'Odpięto powiązany sprzęt (inwentarz)');
}
public function updateDetails(Ticket $ticket, array $data): void
{
$categoryChanged = ($data['subcategory_id'] ?? null) !== $ticket->subcategory_id;
@@ -151,7 +250,10 @@ class TicketService
if ($categoryChanged) {
$this->notify($ticket, 'category_changed');
app(TriggerEngine::class)->handle($ticket, 'category_changed');
}
app(TriggerEngine::class)->handle($ticket, 'ticket_updated');
}
public function operatorReply(Ticket $ticket, User $operator, string $body, ?string $statusAfter = null, array $attachments = []): void
@@ -164,6 +266,9 @@ class TicketService
$ticket->touch();
$this->attachFiles($ticket, $message, $attachments);
$this->notify($ticket, 'operator_replied');
app(TriggerEngine::class)->handle($ticket, 'comment_added');
TicketMessagePosted::dispatch($ticket->id, $message->id, false, $operator->id);
TicketQueueChanged::dispatch($ticket->id, 'message_posted', $operator->id);
if ($statusAfter) {
$this->setStatus($ticket, $statusAfter);
@@ -179,17 +284,76 @@ class TicketService
]);
$message->attachAuthor($operator->id, 'operator');
$this->attachFiles($ticket, $message, $attachments);
TicketMessagePosted::dispatch($ticket->id, $message->id, true, $operator->id);
}
public function clientReply(Ticket $ticket, User $client, string $body, array $attachments = []): void
public function clientReply(Ticket $ticket, User $client, string $body, array $attachments = [], string $source = 'web'): void
{
$message = $ticket->messages()->create([
'author_name' => $client->name,
'body' => $body,
'source' => $source === 'web' ? null : $source,
]);
$message->attachAuthor($client->id, 'client');
$ticket->touch();
$this->attachFiles($ticket, $message, $attachments);
// A fresh customer reply breaks whatever silence an automation rule
// fired on, so it should be able to fire again after a new period of
// silence rather than staying latched from before.
$ticket->update(['last_customer_activity_at' => now()]);
$ticket->automationRuleLogs()->delete();
// Unlike notify(), clientReply() never had a NotificationSetting
// trigger_key of its own — comment_added is a Trigger-engine-only
// hook, e.g. for a rule that reopens a closed ticket on a fresh
// customer reply.
app(TriggerEngine::class)->handle($ticket, 'comment_added');
TicketMessagePosted::dispatch($ticket->id, $message->id, false, $client->id);
TicketQueueChanged::dispatch($ticket->id, 'message_posted', $client->id);
}
/**
* A reply from a customer with no User account e.g. an e-mail reply
* from an address the IMAP fetcher couldn't resolve to a local/LDAP
* user. Mirrors clientReply() (real customer activity: resets SLA
* silence, fires comment_added so an admin-configured Trigger can reopen
* a closed ticket) rather than apiMessage() (attachAuthor(null, null)
* a system/integration note, not client content). attachAuthor(null,
* 'client') matches how create() already tags a guest's opening message.
*/
public function guestReply(Ticket $ticket, string $authorName, string $body, array $attachments = [], string $source = 'web'): TicketMessage
{
$message = $ticket->messages()->create([
'author_name' => $authorName,
'body' => $body,
'source' => $source === 'web' ? null : $source,
]);
$message->attachAuthor(null, 'client');
$ticket->touch();
$this->attachFiles($ticket, $message, $attachments);
$ticket->update(['last_customer_activity_at' => now()]);
$ticket->automationRuleLogs()->delete();
app(TriggerEngine::class)->handle($ticket, 'comment_added');
TicketMessagePosted::dispatch($ticket->id, $message->id, false, null);
TicketQueueChanged::dispatch($ticket->id, 'message_posted', null);
return $message;
}
public function toggleWatch(Ticket $ticket, User $user): bool
{
if ($ticket->isWatchedBy($user)) {
$ticket->watchers()->detach($user->id);
return false;
}
$ticket->watchers()->attach($user->id);
return true;
}
/**
@@ -212,8 +376,12 @@ class TicketService
if (! $internal) {
$this->notify($ticket, 'operator_replied');
app(TriggerEngine::class)->handle($ticket, 'comment_added');
}
TicketMessagePosted::dispatch($ticket->id, $message->id, $internal, null);
TicketQueueChanged::dispatch($ticket->id, 'message_posted', null);
return $message;
}
@@ -265,7 +433,7 @@ class TicketService
$primary->messages()->create([
'author_name' => 'System',
'body' => 'Scalono zgłoszenia: '.$others->map(fn (Ticket $o) => '#'.$o->number)->implode(', '),
'body' => 'Scalono zgłoszenia: '.$others->map(fn (Ticket $o) => $o->displayNumber())->implode(', '),
]);
foreach ($others as $other) {
@@ -283,23 +451,50 @@ class TicketService
$note = $other->messages()->create([
'author_name' => 'System',
'internal' => true,
'body' => 'Scalone ze zgłoszeniem #'.$primary->number,
'body' => 'Scalone ze zgłoszeniem '.$primary->displayNumber(),
]);
$note->attachAuthor(null, 'operator');
TicketQueueChanged::dispatch($other->id, 'merged', Auth::id());
}
$primary->touch();
TicketQueueChanged::dispatch($primary->id, 'message_posted', Auth::id());
}
/**
* Maps the fixed NotificationSetting trigger_keys onto the 3 event
* categories a staff member can tune on their personal notification
* preferences page (see NotificationPreference::CATEGORIES). Triggers
* absent from this map (currently just the client-only 'ticket_created'
* ack) have no staff-facing leg at all.
*/
private const STAFF_EVENT_MAP = [
'ticket_created_team' => 'new_ticket',
'status_changed' => 'ticket_update',
'priority_changed' => 'ticket_update',
'assignee_changed' => 'ticket_update',
'team_changed' => 'ticket_update',
'category_changed' => 'ticket_update',
'operator_replied' => 'ticket_update',
'ticket_closed' => 'ticket_update',
'sla_breached' => 'escalation',
];
/**
* Public so the scheduled SLA-breach check (which isn't a ticket lifecycle
* event raised from within this service) can trigger the same way.
*
* Routes through the recipient's own User model (so it lands in the
* in-app notification bell in addition to e-mail) whenever one exists;
* falls back to an anonymous mail-only route for a guest customer with
* no account. One shared NotificationSetting.enabled flag gates both
* channels there's no separate in-app on/off switch.
* NotificationSetting.enabled is the global kill switch, layered above
* every per-user preference below disabling a trigger here silences
* both legs regardless of what any individual staff member configured;
* the personal matrix can only narrow within an enabled trigger, never
* widen past it.
*
* Sends exactly one notification to the trigger's fixed
* NotificationSetting.recipient (a client, or the ticket's single
* assignee) exactly as before, then for triggers mapped in
* STAFF_EVENT_MAP additionally fans out to every other operator/admin
* whose own notification preferences put this ticket in scope.
*/
public function notify(Ticket $ticket, string $triggerKey): void
{
@@ -310,20 +505,93 @@ class TicketService
}
$notifiable = $setting->recipient === 'operator' ? $ticket->assignee : $ticket->customer;
$fallbackEmail = $setting->recipient === 'operator' ? $ticket->assignee?->email : $ticket->email;
$this->deliverTicketNotification($ticket, $setting->recipient, $setting->email_template_id, notifiable: $notifiable, fallbackEmail: $fallbackEmail);
if ($category = self::STAFF_EVENT_MAP[$triggerKey] ?? null) {
$this->notifyStaffForCategory($ticket, $category, $setting->email_template_id, skip: $notifiable);
}
}
/**
* Notifies every operator/admin whose personal notification preferences
* (see NotificationPreference) put this ticket into one of their chosen
* scopes for $category "Wszystkie zgłoszenia" deliberately reuses the
* existing Ticket::isVisibleToOperator() ACL rather than meaning
* literally every ticket, so it naturally stays within a non-admin
* operator's own team(s) + unrouted tickets. $skip excludes whoever
* notify() already notified directly via the fixed recipient (so an
* assignee with scope_mine enabled doesn't get the same event twice),
* and the acting user is always excluded so nobody gets notified about
* their own action.
*/
protected function notifyStaffForCategory(Ticket $ticket, string $category, int $templateId, ?User $skip = null): void
{
$staff = User::query()->whereHas('roleAssignments', fn ($q) => $q->whereIn('key', ['operator', 'admin']))->get();
foreach ($staff as $user) {
if ($user->id === Auth::id() || ($skip && $user->id === $skip->id)) {
continue;
}
$pref = NotificationPreference::rowFor($user, $category);
$inScope = ($pref['scope_mine'] && $ticket->assignee_id === $user->id)
|| ($pref['scope_unassigned'] && $ticket->assignee_id === null)
|| ($pref['scope_watched'] && $ticket->isWatchedBy($user))
|| ($pref['scope_all'] && $ticket->isVisibleToOperator($user));
if (! $inScope) {
continue;
}
$this->deliverTicketNotification($ticket, 'operator', $templateId, $pref['email'] ? ['mail', 'database'] : ['database'], notifiable: $user);
}
}
/**
* Entry point for the Trigger engine's send_notification action (see
* TriggerEngine) an admin-authored, explicit business action, not one
* of the fixed system lifecycle events, so unlike notify() it doesn't
* consult NotificationSetting or any per-user preference; it always
* sends both mail and bell, same as the original unconditional
* TicketNotification behaviour.
*/
public function sendCustomNotification(Ticket $ticket, string $recipient, int $templateId): void
{
$notifiable = $recipient === 'operator' ? $ticket->assignee : $ticket->customer;
$fallbackEmail = $recipient === 'operator' ? $ticket->assignee?->email : $ticket->email;
$this->deliverTicketNotification($ticket, $recipient, $templateId, notifiable: $notifiable, fallbackEmail: $fallbackEmail, templateSource: 'trigger_email_template');
}
/**
* Shared by notify()'s fixed-recipient leg, notifyStaffForCategory()'s
* per-user fan-out, and sendCustomNotification(). $notifiable, when
* given a real User, always wins over $fallbackEmail the fallback
* only exists for a guest customer with no account, where the
* "database" (bell) channel has nothing to attach to, so
* TicketNotification::via() drops it to mail-only anyway.
*/
private function deliverTicketNotification(
Ticket $ticket,
string $recipientRole,
int $templateId,
array $channels = ['mail', 'database'],
?User $notifiable = null,
?string $fallbackEmail = null,
string $templateSource = 'email_template',
): void {
if ($notifiable) {
$notifiable->notify(new TicketNotification($ticket, $setting->email_template_id, $setting->recipient));
$notifiable->notify(new TicketNotification($ticket, $templateId, $recipientRole, $channels, $templateSource));
return;
}
$email = $setting->recipient === 'operator' ? $ticket->assignee?->email : $ticket->email;
if (! $email) {
return;
if ($fallbackEmail) {
Notification::route('mail', $fallbackEmail)
->notify(new TicketNotification($ticket, $templateId, $recipientRole, $channels, $templateSource));
}
Notification::route('mail', $email)
->notify(new TicketNotification($ticket, $setting->email_template_id, $setting->recipient));
}
}

View File

@@ -0,0 +1,164 @@
<?php
namespace App\Services;
use App\Models\Priority;
use App\Models\Status;
use App\Models\Team;
use App\Models\Ticket;
use App\Models\Trigger;
use App\Models\User;
use Illuminate\Support\Facades\Log;
/**
* Event-based business rules, configured entirely by admins through the
* Wyzwalacze tab additive and independent from AutomationRule (which is
* time/silence-based and evaluated by a scheduled command instead). Fires
* synchronously on every matching ticket-lifecycle event (see the
* TicketService call sites), same as the app's other side effects there
* is no queue worker in this stack to defer work to.
*/
class TriggerEngine
{
private static int $depth = 0;
private const MAX_DEPTH = 5;
public function __construct(protected TicketService $tickets) {}
/**
* Guarded two ways against runaway loops: an action that would only
* reassert the ticket's current value is a no-op before it ever gets
* here (see the apply* methods below), which kills the common case of a
* trigger re-matching its own result; the depth counter below is the
* hard backstop for genuine cycles between two or more different
* triggers.
*/
public function handle(Ticket $ticket, string $event): void
{
if (self::$depth >= self::MAX_DEPTH) {
Log::warning('TriggerEngine: max depth reached, aborting further evaluation', [
'ticket_id' => $ticket->id,
'event' => $event,
]);
return;
}
self::$depth++;
try {
$triggers = Trigger::query()->where('enabled', true)->where('event', $event)->orderBy('sort_order')->get();
foreach ($triggers as $trigger) {
$current = $ticket->fresh();
if ($current && $this->matches($trigger, $current)) {
$this->applyActions($trigger, $current);
}
}
} finally {
self::$depth--;
}
}
protected function matches(Trigger $trigger, Ticket $ticket): bool
{
foreach ($trigger->conditions as $condition) {
$field = $condition['field'] ?? null;
if (! in_array($field, Trigger::CONDITION_FIELDS, true)) {
return false;
}
if (! $this->conditionMatches($condition, $ticket->{$field})) {
return false;
}
}
return true;
}
protected function conditionMatches(array $condition, mixed $actual): bool
{
$value = $condition['value'] ?? null;
return match ($condition['operator'] ?? null) {
'equals' => (string) $actual === (string) $value,
'not_equals' => (string) $actual !== (string) $value,
'is_empty' => $actual === null || $actual === '',
'is_not_empty' => $actual !== null && $actual !== '',
'contains' => is_string($actual) && $value !== null && str_contains(mb_strtolower($actual), mb_strtolower((string) $value)),
default => false,
};
}
protected function applyActions(Trigger $trigger, Ticket $ticket): void
{
foreach ($trigger->actions as $action) {
match ($action['type'] ?? null) {
'set_status' => $this->applySetStatus($ticket, $action['value'] ?? null),
'set_priority' => $this->applySetPriority($ticket, $action['value'] ?? null),
'set_team' => $this->applySetTeam($ticket, $action['value'] ?? null),
'set_assignee' => $this->applySetAssignee($ticket, $action['value'] ?? null),
'send_notification' => $this->applySendNotification($ticket, $action),
default => null,
};
}
}
protected function applySetStatus(Ticket $ticket, ?string $value): void
{
if (! $value || ! Status::query()->where('key', $value)->exists() || $ticket->status_key === $value) {
return;
}
$this->tickets->setStatus($ticket, $value);
}
protected function applySetPriority(Ticket $ticket, ?string $value): void
{
if (! $value || ! Priority::query()->where('key', $value)->exists() || $ticket->priority_key === $value) {
return;
}
$this->tickets->setPriority($ticket, $value);
}
protected function applySetTeam(Ticket $ticket, null|string|int $value): void
{
if ($value === null || (int) $ticket->team_id === (int) $value) {
return;
}
$team = Team::query()->find($value);
if ($team) {
$this->tickets->setTeam($ticket, $team);
}
}
protected function applySetAssignee(Ticket $ticket, null|string|int $value): void
{
if ($value === null || (int) $ticket->assignee_id === (int) $value) {
return;
}
$assignee = User::query()->find($value);
if ($assignee) {
$this->tickets->setAssignee($ticket, $assignee);
}
}
protected function applySendNotification(Ticket $ticket, array $action): void
{
$templateId = $action['email_template_id'] ?? null;
if (! $templateId) {
return;
}
$this->tickets->sendCustomNotification($ticket, $action['recipient'] ?? 'client', (int) $templateId);
}
}

View File

@@ -0,0 +1,49 @@
<?php
namespace App\Support\Imap;
/**
* Normalized view of one inbound message, independent of the IMAP client
* library the seam between ImapMailboxFetcher (I/O, effectively
* untestable without a real mailbox) and ImapMessageClassifier (pure
* decision logic, fully Pest-testable against hand-built instances).
*/
class InboundEmail
{
/**
* @param array<string, string> $headers lower-cased header names
* @param array<int, array{filename: string, mime: string, content: string}> $attachments
*/
public function __construct(
public readonly string $fromEmail,
public readonly string $fromName,
public readonly string $subject,
public readonly string $textBody,
public readonly string $htmlBody,
public readonly array $headers,
public readonly array $attachments = [],
) {}
/**
* Treats an empty string the same as an absent header the IMAP
* library backing ImapMailboxFetcher represents "header not present" as
* an empty value rather than a missing array key in some cases, so
* callers checking `header($x) !== null` alone would otherwise
* misdetect every message as carrying every header.
*/
public function header(string $name): ?string
{
$value = $this->headers[strtolower($name)] ?? null;
return $value !== null && $value !== '' ? $value : null;
}
public function body(): string
{
if (trim($this->textBody) !== '') {
return $this->textBody;
}
return trim(html_entity_decode(strip_tags($this->htmlBody)));
}
}

View File

@@ -2,6 +2,8 @@
namespace App\Support;
use App\Ldap\AdUser;
use App\Ldap\LldapUser;
use App\Models\Setting;
use Illuminate\Http\UploadedFile;
use Illuminate\Support\Facades\Crypt;
@@ -22,6 +24,16 @@ class Settings
'attachment_allowed_types' => 'jpg,jpeg,png,pdf,doc,docx,xls,xlsx,zip,txt',
'session_lifetime_minutes' => '120',
'timezone' => 'UTC',
'ticket_number_prefix' => '#',
'ticket_number_obfuscate' => '0',
'ticket_number_min_length' => '4',
'refresh_ticket_view_seconds' => '30',
'refresh_queue_seconds' => '60',
'refresh_notifications_seconds' => '30',
'schedule_sla_check_minutes' => '15',
'schedule_automation_rules_minutes' => '15',
'schedule_imap_fetch_minutes' => '5',
'schedule_ai_automation_minutes' => '5',
'ldap_enabled' => '1',
'ldap_host' => '',
'ldap_port' => '389',
@@ -45,9 +57,37 @@ class Settings
'bookstack_token_secret' => '',
'bookstack_verify_ssl' => '1',
'bookstack_show_to_guests' => '0',
'bookstack_search_types' => 'both',
'bookstack_search_types' => 'book,page,chapter',
'bookstack_search_by' => 'both',
'bookstack_allowed_shelf_ids_creation' => '',
'bookstack_allowed_shelf_ids_ticket_view' => '',
'snipeit_enabled' => '0',
'snipeit_base_url' => '',
'snipeit_api_token' => '',
'snipeit_verify_ssl' => '1',
'snipeit_client_can_select_asset' => '0',
'snipeit_client_asset_subcategory_ids' => '',
'snipeit_operator_view_requester_assets' => '1',
'snipeit_operator_search_inventory' => '1',
'ai_enabled' => '0',
'ai_base_url' => '',
'ai_api_key' => '',
'ai_model' => '',
'ai_verify_ssl' => '1',
'ai_triage_category_when_missing' => '0',
'ai_triage_subcategory_when_category_only' => '0',
'ai_triage_recheck_categorized' => '0',
'ai_triage_fix_subject' => '0',
'ai_triage_set_priority' => '0',
'ai_summary_enabled' => '0',
'ai_summary_regenerate_on_message' => '0',
'ai_summary_prompt' => 'Jesteś asystentem operatora helpdesku. Otrzymujesz temat, treść oraz historię '
.'wiadomości zgłoszenia. Podsumuj sprawę rzeczowo po polsku (2-3 zdania, czego dotyczy problem i na '
.'jakim jest etapie — np. czeka na odpowiedź klienta czy na działanie operatora) i zaproponuj krótką, '
.'konkretną kolejną akcję (jedno zdanie), np. "Poproś klienta o zrzut ekranu błędu" albo "Zamknij '
.'zgłoszenie — klient potwierdził rozwiązanie". Odpowiedz WYŁĄCZNIE obiektem JSON, bez innego tekstu: '
.'{"summary": "...", "suggested_action": "..."}. Jeśli nie da się ocenić kolejnego kroku, ustaw '
.'"suggested_action" na pusty string.',
'email_footer' => '<p>Ta wiadomość została wygenerowana automatycznie przez system {firma} — prosimy na nią nie odpowiadać.</p>',
'accent_color' => '#7c6fd6',
'login_notice_type' => 'info',
@@ -60,7 +100,7 @@ class Settings
.'</div>',
];
protected static array $encrypted = ['ldap_bind_password', 'mail_smtp_password', 'bookstack_token_secret'];
protected static array $encrypted = ['ldap_bind_password', 'mail_smtp_password', 'bookstack_token_secret', 'ai_api_key', 'snipeit_api_token'];
public static function get(string $key, ?string $default = null): ?string
{
@@ -191,6 +231,20 @@ class Settings
return $path ? Storage::disk('public')->url($path) : asset('branding/default-mark.svg');
}
/**
* Per-page <title>: the context first (so it's still visible once the
* browser truncates a long tab title, and so tabs are distinguishable
* at a glance) with the company name as a trailing, always-present
* anchor. Falls back to just the company name for pages with no more
* specific context (landing, login).
*/
public static function pageTitle(?string $context = null): string
{
$company = static::get('company_name');
return $context ? "{$context}{$company}" : $company;
}
/**
* The admin-configured timezone (IANA identifier, e.g. "Europe/Warsaw"),
* applied at runtime by AppServiceProvider so every date/time displayed
@@ -206,6 +260,24 @@ class Settings
: static::$defaults['timezone'];
}
/**
* Whether an admin-configurable "every N minutes" scheduled command
* (schedule_*_minutes, routes/console.php) is due to run this minute.
* Used inside a Schedule::command(...)->when(...) closure rather than
* building a cron string up front a closure is only evaluated when
* schedule:run actually processes due events, whereas eagerly reading
* Settings (which queries the DB) at routes/console.php's top level
* would run on every artisan boot (migrate, tinker, tests, ...), before
* the settings table necessarily even exists. Clamped to a minimum of 1
* so a blank/zero/negative stored value can never busy-loop.
*/
public static function dueEveryMinutes(string $key, int $default): bool
{
$minutes = max(1, (int) static::get($key, (string) $default));
return now()->minute % $minutes === 0;
}
/**
* Wraps a single e-mail template's rendered HTML body in the fixed
* "box" layout company name, ticket content and footer so every
@@ -230,19 +302,46 @@ class Settings
]);
}
/**
* Whether the admin has pointed LDAP auth at Active Directory rather
* than an LLDAP/OpenLDAP-schema directory changes which LdapRecord
* model class backs logins (see ldapUserModelClass()) and which
* attribute a bare username search defaults to (see
* ldapUsernameAttribute()), since AD's objectClass chain and login
* attribute (sAMAccountName, not uid) differ from LLDAP's.
*/
public static function isActiveDirectory(): bool
{
return static::get('ldap_directory_type') === 'ad';
}
/**
* The LdapRecord model class the 'users' auth provider should use
* wired into config('auth.providers.users.model') at runtime by
* AppServiceProvider::applyLdapSettingsOverride(), same as the
* connection host/base DN below.
*/
public static function ldapUserModelClass(): string
{
return static::isActiveDirectory() ? AdUser::class : LldapUser::class;
}
/**
* Parses the admin-configurable LDAP user filter (e.g. "(uid={0})") to
* find which LDAP attribute logins are matched against.
* find which LDAP attribute logins are matched against. Defaults to
* Active Directory's sAMAccountName when no filter is set and the
* directory type is AD uid is never populated on a stock AD user.
*/
public static function ldapUsernameAttribute(): string
{
$filter = static::get('ldap_user_filter', '(uid={0})');
$default = static::isActiveDirectory() ? '(sAMAccountName={0})' : '(uid={0})';
$filter = static::get('ldap_user_filter') ?: $default;
if (preg_match('/\(([a-zA-Z0-9-]+)=\{0\}\)/', (string) $filter, $matches)) {
return $matches[1];
}
return 'uid';
return static::isActiveDirectory() ? 'sAMAccountName' : 'uid';
}
/**

View File

@@ -1,18 +1,21 @@
<?php
use App\Http\Middleware\EnsureRole;
use Illuminate\Database\Eloquent\ModelNotFoundException;
use Illuminate\Foundation\Application;
use Illuminate\Foundation\Configuration\Exceptions;
use Illuminate\Foundation\Configuration\Middleware;
use Illuminate\Http\Request;
use Laravel\Sanctum\Http\Middleware\CheckAbilities;
use Laravel\Sanctum\Http\Middleware\CheckForAnyAbility;
use Symfony\Component\HttpKernel\Exception\NotFoundHttpException;
return Application::configure(basePath: dirname(__DIR__))
->withRouting(
web: __DIR__.'/../routes/web.php',
api: __DIR__.'/../routes/api.php',
commands: __DIR__.'/../routes/console.php',
channels: __DIR__.'/../routes/channels.php',
health: '/up',
)
->withMiddleware(function (Middleware $middleware): void {
@@ -43,4 +46,29 @@ return Application::configure(basePath: dirname(__DIR__))
$exceptions->shouldRenderJsonWhen(
fn (Request $request) => $request->is('api/*'),
);
// A ticket deleted mid-session (typically by the operator/client
// currently viewing it) leaves any later request for that same
// {ticket} route binding 404ing — most commonly Livewire's own
// "model missing during hydration" recovery, which does a full
// window.location.reload() of the very page whose ticket just
// disappeared (e.g. the ticket-show view's periodic fallback
// refresh polling a few seconds after a delete+redirect). Land back
// on that area's own list page instead of a raw 404.
//
// Handler::prepareException() already converts ModelNotFoundException
// into NotFoundHttpException (wrapping the original as getPrevious())
// before any render() callback is dispatched — a callback typed
// against ModelNotFoundException itself would simply never match.
$exceptions->render(function (NotFoundHttpException $e, Request $request) {
if (! $e->getPrevious() instanceof ModelNotFoundException || ! $request->user()) {
return null;
}
return match (true) {
$request->is('operator/*') => redirect()->route('operator.queue'),
$request->is('client/*') => redirect()->route('client.dashboard'),
default => null,
};
});
})->create();

View File

@@ -13,9 +13,11 @@
"darkaonline/l5-swagger": "*",
"directorytree/ldaprecord-laravel": "*",
"laravel/framework": "^13.8",
"laravel/reverb": "*",
"laravel/sanctum": "*",
"laravel/tinker": "^3.0",
"livewire/livewire": "*"
"livewire/livewire": "*",
"webklex/php-imap": "*"
},
"require-dev": {
"fakerphp/faker": "^1.23",

988
src/composer.lock generated

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1,82 @@
<?php
return [
/*
|--------------------------------------------------------------------------
| Default Broadcaster
|--------------------------------------------------------------------------
|
| This option controls the default broadcaster that will be used by the
| framework when an event needs to be broadcast. You may set this to
| any of the connections defined in the "connections" array below.
|
| Supported: "reverb", "pusher", "ably", "redis", "log", "null"
|
*/
'default' => env('BROADCAST_CONNECTION', 'null'),
/*
|--------------------------------------------------------------------------
| Broadcast Connections
|--------------------------------------------------------------------------
|
| Here you may define all of the broadcast connections that will be used
| to broadcast events to other systems or over WebSockets. Samples of
| each available type of connection are provided inside this array.
|
*/
'connections' => [
'reverb' => [
'driver' => 'reverb',
'key' => env('REVERB_APP_KEY'),
'secret' => env('REVERB_APP_SECRET'),
'app_id' => env('REVERB_APP_ID'),
'options' => [
'host' => env('REVERB_HOST'),
'port' => env('REVERB_PORT', 443),
'scheme' => env('REVERB_SCHEME', 'https'),
'useTLS' => env('REVERB_SCHEME', 'https') === 'https',
],
'client_options' => [
// Guzzle client options: https://docs.guzzlephp.org/en/stable/request-options.html
],
],
'pusher' => [
'driver' => 'pusher',
'key' => env('PUSHER_APP_KEY'),
'secret' => env('PUSHER_APP_SECRET'),
'app_id' => env('PUSHER_APP_ID'),
'options' => [
'cluster' => env('PUSHER_APP_CLUSTER'),
'host' => env('PUSHER_HOST') ?: 'api-'.env('PUSHER_APP_CLUSTER', 'mt1').'.pusher.com',
'port' => env('PUSHER_PORT', 443),
'scheme' => env('PUSHER_SCHEME', 'https'),
'encrypted' => true,
'useTLS' => env('PUSHER_SCHEME', 'https') === 'https',
],
'client_options' => [
// Guzzle client options: https://docs.guzzlephp.org/en/stable/request-options.html
],
],
'ably' => [
'driver' => 'ably',
'key' => env('ABLY_KEY'),
],
'log' => [
'driver' => 'log',
],
'null' => [
'driver' => 'null',
],
],
];

View File

@@ -73,6 +73,19 @@ return [
'replace_placeholders' => true,
],
// Dedicated, always-verbose channel for the IMAP fetcher
// (emails:fetch-imap) — kept separate from 'single'/LOG_LEVEL so a
// production app typically running at LOG_LEVEL=error still gets
// full visibility into what the fetcher did on every run, without
// that verbosity going into the main laravel.log.
'imap' => [
'driver' => 'daily',
'path' => storage_path('logs/imap.log'),
'level' => 'debug',
'days' => 14,
'replace_placeholders' => true,
],
'slack' => [
'driver' => 'slack',
'url' => env('LOG_SLACK_WEBHOOK_URL'),

102
src/config/reverb.php Normal file
View File

@@ -0,0 +1,102 @@
<?php
return [
/*
|--------------------------------------------------------------------------
| Default Reverb Server
|--------------------------------------------------------------------------
|
| This option controls the default server used by Reverb to handle
| incoming messages as well as broadcasting message to all your
| connected clients. At this time only "reverb" is supported.
|
*/
'default' => env('REVERB_SERVER', 'reverb'),
/*
|--------------------------------------------------------------------------
| Reverb Servers
|--------------------------------------------------------------------------
|
| Here you may define details for each of the supported Reverb servers.
| Each server has its own configuration options that are defined in
| the array below. You should ensure all the options are present.
|
*/
'servers' => [
'reverb' => [
'host' => env('REVERB_SERVER_HOST', '0.0.0.0'),
'port' => env('REVERB_SERVER_PORT', 8080),
'path' => env('REVERB_SERVER_PATH', ''),
'hostname' => env('REVERB_HOST'),
'options' => [
'tls' => [],
],
'max_request_size' => env('REVERB_MAX_REQUEST_SIZE', 10_000),
'scaling' => [
'enabled' => env('REVERB_SCALING_ENABLED', false),
'channel' => env('REVERB_SCALING_CHANNEL', 'reverb'),
'server' => [
'url' => env('REDIS_URL'),
'host' => env('REDIS_HOST', '127.0.0.1'),
'port' => env('REDIS_PORT', '6379'),
'username' => env('REDIS_USERNAME'),
'password' => env('REDIS_PASSWORD'),
'database' => env('REDIS_DB', '0'),
'timeout' => env('REDIS_TIMEOUT', 60),
],
],
'pulse_ingest_interval' => env('REVERB_PULSE_INGEST_INTERVAL', 15),
'telescope_ingest_interval' => env('REVERB_TELESCOPE_INGEST_INTERVAL', 15),
],
],
/*
|--------------------------------------------------------------------------
| Reverb Applications
|--------------------------------------------------------------------------
|
| Here you may define how Reverb applications are managed. If you choose
| to use the "config" provider, you may define an array of apps which
| your server will support, including their connection credentials.
|
*/
'apps' => [
'provider' => 'config',
'apps' => [
[
'key' => env('REVERB_APP_KEY'),
'secret' => env('REVERB_APP_SECRET'),
'app_id' => env('REVERB_APP_ID'),
'options' => [
'host' => env('REVERB_HOST'),
'port' => env('REVERB_PORT', 443),
'scheme' => env('REVERB_SCHEME', 'https'),
'useTLS' => env('REVERB_SCHEME', 'https') === 'https',
],
'allowed_origins' => ['*'],
'ping_interval' => env('REVERB_APP_PING_INTERVAL', 60),
'activity_timeout' => env('REVERB_APP_ACTIVITY_TIMEOUT', 30),
'max_connections' => env('REVERB_APP_MAX_CONNECTIONS'),
'max_message_size' => env('REVERB_APP_MAX_MESSAGE_SIZE', 10_000),
'accept_client_events_from' => env('REVERB_APP_ACCEPT_CLIENT_EVENTS_FROM', 'members'),
'rate_limiting' => [
'enabled' => env('REVERB_APP_RATE_LIMITING_ENABLED', false),
'max_attempts' => env('REVERB_APP_RATE_LIMIT_MAX_ATTEMPTS', 60),
'decay_seconds' => env('REVERB_APP_RATE_LIMIT_DECAY_SECONDS', 60),
'terminate_on_limit' => env('REVERB_APP_RATE_LIMIT_TERMINATE', false),
],
],
],
],
];

View File

@@ -0,0 +1,36 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
/**
* scope_* columns are soft references (like tickets.status_key) no FK,
* so deleting a priority/subcategory/team in Admin never blocks or
* cascades into a rule; a null scope column means "any" for that filter.
* action_value likewise soft-holds whichever kind of key/id action_type
* needs (priority_key/status_key/team_id/user_id).
*/
public function up(): void
{
Schema::create('automation_rules', function (Blueprint $table) {
$table->id();
$table->string('label');
$table->boolean('enabled')->default(true);
$table->unsignedInteger('condition_minutes');
$table->string('scope_priority_key')->nullable();
$table->unsignedBigInteger('scope_subcategory_id')->nullable();
$table->unsignedBigInteger('scope_team_id')->nullable();
$table->string('action_type');
$table->string('action_value');
$table->timestamps();
});
}
public function down(): void
{
Schema::dropIfExists('automation_rules');
}
};

View File

@@ -0,0 +1,31 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
/**
* One row per (rule, ticket) firing the idempotency latch that stops
* RunAutomationRules from re-applying the same rule to the same ticket
* every scheduler tick. Rows are deleted (not flagged) by TicketService
* whenever the underlying silence is broken, so the rule can fire again.
*/
public function up(): void
{
Schema::create('automation_rule_ticket_logs', function (Blueprint $table) {
$table->id();
$table->foreignId('automation_rule_id')->constrained()->cascadeOnDelete();
$table->foreignId('ticket_id')->constrained()->cascadeOnDelete();
$table->timestamp('triggered_at');
$table->unique(['automation_rule_id', 'ticket_id']);
});
}
public function down(): void
{
Schema::dropIfExists('automation_rule_ticket_logs');
}
};

View File

@@ -0,0 +1,27 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
/**
* Nullable, no backfill of existing rows RunAutomationRules falls back
* to created_at when this is null, mirroring how resolutionDeadline()
* treats a missing SlaRule as "no SLA" rather than backfilling one.
*/
public function up(): void
{
Schema::table('tickets', function (Blueprint $table) {
$table->timestamp('last_customer_activity_at')->nullable()->after('sla_notified_at');
});
}
public function down(): void
{
Schema::table('tickets', function (Blueprint $table) {
$table->dropColumn('last_customer_activity_at');
});
}
};

View File

@@ -0,0 +1,51 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Support\Facades\DB;
return new class extends Migration
{
/**
* Backfills the new 'ticket_created_team' trigger + its email template
* for an already-seeded database (mirrors DatabaseSeeder::
* seedEmailTemplatesAndNotifications(), which only runs on a fresh
* install) guarded so re-running, or a fresh seed that already has
* both rows, is a no-op.
*/
public function up(): void
{
$templateId = DB::table('email_templates')->where('key', 'tpl-team-new-ticket')->value('id');
if (! $templateId) {
$templateId = DB::table('email_templates')->insertGetId([
'key' => 'tpl-team-new-ticket',
'name' => 'Nowe zgłoszenie w zespole',
'trigger_label' => 'Nowe zgłoszenie w zespole — operator',
'subject' => 'Nowe zgłoszenie w Twoim zespole (#{numer})',
'body' => '<p>Cześć,</p><p>Nowe zgłoszenie „{temat}” (#{numer}, kategoria: {kategoria}) trafiło do zespołu {zespol}.</p><p>Podgląd zgłoszenia: <a href="{link}" rel="noopener noreferrer" target="_blank">Kliknij tu</a></p><p>Pozdrawiamy,<br>Zespół Wsparcia</p>',
'created_at' => now(),
'updated_at' => now(),
]);
}
if (DB::table('notification_settings')->where('trigger_key', 'ticket_created_team')->exists()) {
return;
}
DB::table('notification_settings')->insert([
'trigger_key' => 'ticket_created_team',
'trigger_label' => 'Nowe zgłoszenie w zespole (powiadom operatorów)',
'enabled' => true,
'recipient' => 'operator',
'email_template_id' => $templateId,
'created_at' => now(),
'updated_at' => now(),
]);
}
public function down(): void
{
DB::table('notification_settings')->where('trigger_key', 'ticket_created_team')->delete();
DB::table('email_templates')->where('key', 'tpl-team-new-ticket')->delete();
}
};

View File

@@ -0,0 +1,25 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
public function up(): void
{
Schema::create('ticket_watchers', function (Blueprint $table) {
$table->id();
$table->foreignId('ticket_id')->constrained()->cascadeOnDelete();
$table->foreignId('user_id')->constrained()->cascadeOnDelete();
$table->timestamps();
$table->unique(['ticket_id', 'user_id']);
});
}
public function down(): void
{
Schema::dropIfExists('ticket_watchers');
}
};

View File

@@ -0,0 +1,37 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
/**
* One row per (user, event_category) only written the first time a
* user actually toggles a checkbox on their notification-preferences
* page. A missing row is not "notifications off"; callers must fall
* back to NotificationPreference::DEFAULTS, never treat absence as
* all-false (see NotificationPreference::rowFor()).
*/
public function up(): void
{
Schema::create('notification_preferences', function (Blueprint $table) {
$table->id();
$table->foreignId('user_id')->constrained()->cascadeOnDelete();
$table->string('event_category');
$table->boolean('scope_mine')->default(false);
$table->boolean('scope_unassigned')->default(false);
$table->boolean('scope_watched')->default(false);
$table->boolean('scope_all')->default(false);
$table->boolean('email')->default(false);
$table->timestamps();
$table->unique(['user_id', 'event_category']);
});
}
public function down(): void
{
Schema::dropIfExists('notification_preferences');
}
};

View File

@@ -0,0 +1,34 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
/**
* Event-driven business rules (see App\Services\TriggerEngine)
* conditions/actions are JSON so an admin can add/edit rules entirely
* through the UI, with no migration needed per rule. Deliberately no
* dedup/log table here (unlike automation_rule_ticket_logs): a trigger
* is meant to re-fire on every matching event, not latch until reset.
*/
public function up(): void
{
Schema::create('triggers', function (Blueprint $table) {
$table->id();
$table->string('name');
$table->boolean('enabled')->default(true);
$table->string('event');
$table->json('conditions');
$table->json('actions');
$table->unsignedInteger('sort_order')->default(0);
$table->timestamps();
});
}
public function down(): void
{
Schema::dropIfExists('triggers');
}
};

View File

@@ -0,0 +1,31 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
/**
* Separate from email_templates on purpose: those are fixed 1:1 to a
* built-in notification trigger (no add/delete/reassign see
* Admin\Panel::editingTemplate()), while these are freely add/edit/
* delete-able by admins for use in the "Wyślij powiadomienie e-mail"
* trigger action (App\Services\TriggerEngine::applySendNotification).
*/
public function up(): void
{
Schema::create('trigger_email_templates', function (Blueprint $table) {
$table->id();
$table->string('name');
$table->string('subject');
$table->text('body');
$table->timestamps();
});
}
public function down(): void
{
Schema::dropIfExists('trigger_email_templates');
}
};

View File

@@ -0,0 +1,46 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
public function up(): void
{
Schema::table('tickets', function (Blueprint $table) {
$table->string('checksum', 20)->nullable()->unique()->after('number');
});
// Backfill: every existing ticket gets a stable, HMAC-derived
// checksum (mirrors Ticket::generateUniqueChecksum()) so the
// "hide ticket order" numbering mode has a real, unique, indexed
// column to resolve ticket URLs against instead of only being a
// display-time computation.
$assigned = [];
DB::table('tickets')->orderBy('id')->select('id')->chunkById(500, function ($tickets) use (&$assigned) {
foreach ($tickets as $ticket) {
$nonce = 0;
do {
$hash = hash_hmac('sha256', $ticket->id.'|'.$nonce, (string) config('app.key'));
$candidate = (string) (hexdec(substr($hash, 0, 8)) % 900000 + 100000);
$nonce++;
} while (isset($assigned[$candidate]));
$assigned[$candidate] = true;
DB::table('tickets')->where('id', $ticket->id)->update(['checksum' => $candidate]);
}
});
}
public function down(): void
{
Schema::table('tickets', function (Blueprint $table) {
$table->dropColumn('checksum');
});
}
};

View File

@@ -0,0 +1,36 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
public function up(): void
{
Schema::create('imap_mailboxes', function (Blueprint $table) {
$table->id();
$table->string('name');
$table->boolean('enabled')->default(false);
$table->string('host');
$table->unsignedSmallInteger('port')->default(993);
$table->string('encryption')->default('ssl');
$table->boolean('validate_cert')->default(true);
$table->string('username');
$table->text('password')->nullable();
$table->string('folder')->default('INBOX');
$table->string('processed_folder')->nullable();
$table->string('rejected_folder')->nullable();
$table->foreignId('default_subcategory_id')->nullable()->constrained('subcategories')->nullOnDelete();
$table->string('blocklist_senders')->default('mailer-daemon,postmaster,no-reply,noreply');
$table->timestamp('last_checked_at')->nullable();
$table->text('last_error')->nullable();
$table->timestamps();
});
}
public function down(): void
{
Schema::dropIfExists('imap_mailboxes');
}
};

View File

@@ -0,0 +1,42 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
/**
* category_id lets a ticket carry just a Category with no specific
* Subcategory (e.g. an IMAP mailbox routed to "całą kategorię" rather
* than one subcategory) subcategory_id already implies a category via
* its own relation, so category_id is only ever populated when there's
* no subcategory to derive it from (see Ticket::categoryLabel()).
*
* source records how the ticket was created (web/e-mail/...), surfaced
* as a badge in the operator queue/ticket view.
*/
public function up(): void
{
Schema::table('tickets', function (Blueprint $table) {
$table->foreignId('category_id')->nullable()->after('subcategory_id')->constrained('categories')->nullOnDelete();
$table->string('source')->default('web')->after('api_client_id');
});
Schema::table('imap_mailboxes', function (Blueprint $table) {
$table->foreignId('default_category_id')->nullable()->after('default_subcategory_id')->constrained('categories')->nullOnDelete();
});
}
public function down(): void
{
Schema::table('imap_mailboxes', function (Blueprint $table) {
$table->dropConstrainedForeignId('default_category_id');
});
Schema::table('tickets', function (Blueprint $table) {
$table->dropConstrainedForeignId('category_id');
$table->dropColumn('source');
});
}
};

View File

@@ -0,0 +1,29 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
/**
* Mirrors tickets.source at the individual-message level a ticket
* created on the web can still later receive a reply by e-mail (or vice
* versa), so this needs tracking per message, not just per ticket.
* Null means "web" (the original/default channel); only IMAP-originated
* messages ever set it to 'email'.
*/
public function up(): void
{
Schema::table('ticket_messages', function (Blueprint $table) {
$table->string('source')->nullable()->after('api_client_id');
});
}
public function down(): void
{
Schema::table('ticket_messages', function (Blueprint $table) {
$table->dropColumn('source');
});
}
};

View File

@@ -0,0 +1,35 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
/**
* ai_triaged_at marks that the AI auto-triage pass has run for this
* ticket (regardless of whether it changed anything) never reset, so
* the scheduled command's query is just "tickets where this is null".
*
* ai_summary/ai_suggested_action/ai_summary_generated_at cache the AI
* ticket summary shown to operators; generated_at lets the summary
* command cheaply tell whether a ticket's summary is stale relative to
* its latest message, without re-summarizing every ticket every run.
*/
public function up(): void
{
Schema::table('tickets', function (Blueprint $table) {
$table->timestamp('ai_triaged_at')->nullable()->after('source');
$table->text('ai_summary')->nullable()->after('ai_triaged_at');
$table->text('ai_suggested_action')->nullable()->after('ai_summary');
$table->timestamp('ai_summary_generated_at')->nullable()->after('ai_suggested_action');
});
}
public function down(): void
{
Schema::table('tickets', function (Blueprint $table) {
$table->dropColumn(['ai_triaged_at', 'ai_summary', 'ai_suggested_action', 'ai_summary_generated_at']);
});
}
};

View File

@@ -0,0 +1,27 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
public function up(): void
{
Schema::table('subcategories', function (Blueprint $table) {
$table->unsignedInteger('sort_order')->default(0)->after('default_priority_key');
});
foreach (DB::table('subcategories')->orderBy('category_id')->orderBy('id')->get() as $position => $sub) {
DB::table('subcategories')->where('id', $sub->id)->update(['sort_order' => $position]);
}
}
public function down(): void
{
Schema::table('subcategories', function (Blueprint $table) {
$table->dropColumn('sort_order');
});
}
};

View File

@@ -0,0 +1,29 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
/**
* snipeit_asset_name is a cached label (asset tag + name/model) captured
* at link time kept alongside the id so the ticket list/header still
* shows something meaningful if Snipe-IT is unreachable or the asset was
* later deleted there, without depending on a live API call.
*/
public function up(): void
{
Schema::table('tickets', function (Blueprint $table) {
$table->unsignedInteger('snipeit_asset_id')->nullable()->after('ai_summary_generated_at');
$table->string('snipeit_asset_name')->nullable()->after('snipeit_asset_id');
});
}
public function down(): void
{
Schema::table('tickets', function (Blueprint $table) {
$table->dropColumn(['snipeit_asset_id', 'snipeit_asset_name']);
});
}
};

View File

@@ -0,0 +1,29 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
public function up(): void
{
Schema::create('ticket_views', function (Blueprint $table) {
$table->id();
$table->foreignId('ticket_id')->constrained()->cascadeOnDelete();
$table->foreignId('user_id')->constrained()->cascadeOnDelete();
// Microsecond precision (not the plain-timestamp default) so two
// views landing in the same second — plausible with fast repeat
// clicks, not just test speed — still order correctly instead of
// tying and falling back to row id.
$table->timestamp('viewed_at', 6);
$table->unique(['ticket_id', 'user_id']);
});
}
public function down(): void
{
Schema::dropIfExists('ticket_views');
}
};

View File

@@ -55,7 +55,7 @@ class DatabaseSeeder extends Seeder
['key' => 'operator', 'label' => 'Operator'],
['key' => 'admin', 'label' => 'Administrator'],
] as $role) {
Role::query()->create($role);
Role::query()->firstOrCreate(['key' => $role['key']], $role);
}
}
@@ -259,6 +259,11 @@ class DatabaseSeeder extends Seeder
{
foreach ([
['label' => 'Wyślij i „Oczekuje na klienta”', 'status_key' => 'waiting_customer', 'sort_order' => 1],
// Used to point at the now-removed "resolved" status, folded into
// "closed" by the status restructure — same target as "Wyślij i
// zamknij" today, kept as a separate quick action for continuity
// with the old hardcoded menu (see ReplyQuickActionsTest).
['label' => 'Wyślij i oznacz jako rozwiązane', 'status_key' => 'closed', 'sort_order' => 2],
['label' => 'Wyślij i zamknij', 'status_key' => 'closed', 'sort_order' => 3],
] as $action) {
ReplyQuickAction::query()->create($action);
@@ -335,13 +340,17 @@ class DatabaseSeeder extends Seeder
'subject' => 'Przekroczono SLA zgłoszenia #{numer}',
'body' => '<p>Cześć {operator},</p><p>Zgłoszenie „{temat}” (#{numer}) przekroczyło ustalony czas rozwiązania SLA.</p>'.$link.$footer,
],
'tpl-team-new-ticket' => [
'name' => 'Nowe zgłoszenie w zespole', 'trigger_label' => 'Nowe zgłoszenie w zespole — operator',
'subject' => 'Nowe zgłoszenie w Twoim zespole (#{numer})',
'body' => '<p>Cześć,</p><p>Nowe zgłoszenie „{temat}” (#{numer}, kategoria: {kategoria}) trafiło do zespołu {zespol}.</p>'.$link.$footer,
],
];
$ids = [];
foreach ($templates as $key => $tpl) {
$ids[$key] = EmailTemplate::query()->create([
'key' => $key,
$ids[$key] = EmailTemplate::query()->firstOrCreate(['key' => $key], [
'name' => $tpl['name'],
'trigger_label' => $tpl['trigger_label'],
'subject' => $tpl['subject'],
@@ -359,9 +368,9 @@ class DatabaseSeeder extends Seeder
['trigger_key' => 'ticket_closed', 'trigger_label' => 'Zgłoszenie zamknięte', 'enabled' => true, 'recipient' => 'client', 'template' => 'tpl-closed'],
['trigger_key' => 'operator_replied', 'trigger_label' => 'Nowa odpowiedź operatora', 'enabled' => true, 'recipient' => 'client', 'template' => 'tpl-reply'],
['trigger_key' => 'sla_breached', 'trigger_label' => 'Przekroczono SLA (powiadom operatora)', 'enabled' => false, 'recipient' => 'operator', 'template' => 'tpl-sla-breach'],
['trigger_key' => 'ticket_created_team', 'trigger_label' => 'Nowe zgłoszenie w zespole (powiadom operatorów)', 'enabled' => true, 'recipient' => 'operator', 'template' => 'tpl-team-new-ticket'],
] as $setting) {
NotificationSetting::query()->create([
'trigger_key' => $setting['trigger_key'],
NotificationSetting::query()->firstOrCreate(['trigger_key' => $setting['trigger_key']], [
'trigger_label' => $setting['trigger_label'],
'enabled' => $setting['enabled'],
'recipient' => $setting['recipient'],

View File

@@ -0,0 +1,8 @@
<?php
return [
'previous' => '&laquo; Poprzednia',
'next' => 'Następna &raquo;',
];

40
src/package-lock.json generated
View File

@@ -4,6 +4,10 @@
"requires": true,
"packages": {
"": {
"dependencies": {
"laravel-echo": "^2.1.0",
"pusher-js": "^8.4.0"
},
"devDependencies": {
"@tailwindcss/vite": "^4.0.0",
"concurrently": "^9.0.1",
@@ -909,6 +913,27 @@
"jiti": "lib/jiti-cli.mjs"
}
},
"node_modules/laravel-echo": {
"version": "2.4.0",
"resolved": "https://registry.npmjs.org/laravel-echo/-/laravel-echo-2.4.0.tgz",
"integrity": "sha512-8w0fAGSNt6THfbNyqdKc29bhfeNpJg13CGx2fcLgoX0/f0mTJm/AIkYTTakmcr9pc42ZB68cSoE00j4/xNaFGQ==",
"license": "MIT",
"engines": {
"node": ">=20"
},
"peerDependencies": {
"pusher-js": "*",
"socket.io-client": "*"
},
"peerDependenciesMeta": {
"pusher-js": {
"optional": true
},
"socket.io-client": {
"optional": true
}
}
},
"node_modules/laravel-vite-plugin": {
"version": "3.1.3",
"resolved": "https://registry.npmjs.org/laravel-vite-plugin/-/laravel-vite-plugin-3.1.3.tgz",
@@ -1275,6 +1300,15 @@
"node": "^10 || ^12 || >=14"
}
},
"node_modules/pusher-js": {
"version": "8.5.0",
"resolved": "https://registry.npmjs.org/pusher-js/-/pusher-js-8.5.0.tgz",
"integrity": "sha512-V7uzGi9bqOOOyM/6IkJdpFyjGZj7llz1v0oWnYkZKcYLvbz6VcHVLmzKqkvegjuMumpfIEKGLmWHwFb39XFCpw==",
"license": "MIT",
"dependencies": {
"tweetnacl": "^1.0.3"
}
},
"node_modules/require-directory": {
"version": "2.1.1",
"resolved": "https://registry.npmjs.org/require-directory/-/require-directory-2.1.1.tgz",
@@ -1451,6 +1485,12 @@
"dev": true,
"license": "0BSD"
},
"node_modules/tweetnacl": {
"version": "1.0.3",
"resolved": "https://registry.npmjs.org/tweetnacl/-/tweetnacl-1.0.3.tgz",
"integrity": "sha512-6rt+RN7aOi1nGMyC4Xa5DdYiukl2UWCbcJft7YhxReBGQD7OAM8Pbxw6YMo4r2diNEA8FEmu32YOn9rhaiE5yw==",
"license": "Unlicense"
},
"node_modules/vite": {
"version": "8.1.5",
"resolved": "https://registry.npmjs.org/vite/-/vite-8.1.5.tgz",

View File

@@ -6,6 +6,10 @@
"build": "vite build",
"dev": "vite"
},
"dependencies": {
"laravel-echo": "^2.1.0",
"pusher-js": "^8.4.0"
},
"devDependencies": {
"@tailwindcss/vite": "^4.0.0",
"concurrently": "^9.0.1",

View File

@@ -211,6 +211,63 @@ body {
.seg-opt:has(input:checked) { background: color-mix(in srgb, var(--color-accent) 16%, transparent); color: var(--color-accent); }
.seg-opt input { position: absolute; opacity: 0; width: 0; height: 0; }
.panel-switch {
display: inline-flex;
padding: 3px;
border: 1px solid var(--color-divider);
border-radius: 999px;
background: color-mix(in srgb, var(--color-text) 4%, transparent);
max-width: 100%;
overflow-x: auto;
scrollbar-width: none;
}
.panel-switch::-webkit-scrollbar { display: none; }
.panel-switch-indicator {
position: absolute;
top: 0;
bottom: 0;
left: 0;
border-radius: 999px;
background: var(--color-accent);
transition: transform 0.2s ease;
z-index: 0;
}
.nav .panel-switch-option {
position: relative;
z-index: 1;
flex: 1 1 0;
min-width: 128px;
display: flex;
align-items: center;
justify-content: center;
padding: 6px 16px;
font-size: 12.5px;
font-weight: 500;
color: var(--color-text);
text-decoration: none;
white-space: nowrap;
border-radius: 999px;
}
.nav .panel-switch-option:hover { color: #fff; text-decoration: none; }
.nav .panel-switch-option-active, .nav .panel-switch-option-active:hover { color: #fff; }
/* Preview the destination before the click actually navigates there:
the indicator follows whichever option is under the cursor (falling
back to the real active position, set inline per-request by
panel-switcher.blade.php, the moment the pointer leaves). Position is
purely by hovered index independent of how many roles/options
exist so these three rules cover the max of three areas regardless
of which subset a given user has. */
.panel-switch:has(> .panel-switch-option:nth-of-type(1):hover) .panel-switch-indicator { transform: translateX(0%) !important; }
.panel-switch:has(> .panel-switch-option:nth-of-type(2):hover) .panel-switch-indicator { transform: translateX(100%) !important; }
.panel-switch:has(> .panel-switch-option:nth-of-type(3):hover) .panel-switch-indicator { transform: translateX(200%) !important; }
/* The real active option's white text is only correct while the
indicator sits under it once hover has pulled the indicator away to
a neighboring option, drop it back to normal text color so it doesn't
read as near-invisible white-on-track. */
.panel-switch:hover .panel-switch-option-active:not(:hover) { color: var(--color-text); }
.theme-toggle-option {
display: flex;
align-items: center;
@@ -341,8 +398,42 @@ body {
@media (max-width: 640px) {
.page-pad { padding: 16px !important; }
.nav { padding-left: 14px !important; padding-right: 14px !important; gap: 10px; }
.nav-panel-label { display: none; }
.nav { padding-left: 14px !important; padding-right: 14px !important; gap: 10px; flex-wrap: wrap; }
/* At this width the switcher's own centered slot collides with the
brand text and the icon buttons sharing the row (nothing left to
shrink once labels are already at their minimum width) same
"restructure instead of cram" fix as the mobile table pattern above:
drop it to its own full-width row below instead of fighting for
space with everything else in the bar. */
.panel-switch {
position: relative !important;
left: auto !important;
top: auto !important;
transform: none !important;
order: 10;
width: 100%;
max-width: 100%;
justify-content: center;
margin-top: 10px;
}
.nav .panel-switch-option { padding: 10px; font-size: 11.5px; min-width: 92px; }
/* Theme/notifications/profile dropdowns are anchored (position:absolute)
to their own small trigger button by default, which overflows off the
edge of narrow screens once their fixed width no longer fits between
the button and the viewport edge. Dropping the wrapper's own
positioning context makes .nav itself (already position:relative) the
containing block instead, so left/right:0 spans the whole navbar
width rather than the button's. */
.nav-dropdown-wrap { position: static !important; }
.nav-dropdown {
left: 0 !important;
right: 0 !important;
width: auto !important;
min-width: 0 !important;
margin-top: 8px !important;
}
.profile-menu-name { display: none; }
.main-col { min-width: 0; }
.aside-col { width: 100%; }

View File

@@ -1 +1,9 @@
//
/**
* Echo exposes an expressive API for subscribing to channels and listening
* for events that are broadcast by Laravel. Echo and event broadcasting
* allow your team to quickly build robust real-time web applications.
*/
import './echo';

112
src/resources/js/echo.js Normal file
View File

@@ -0,0 +1,112 @@
import Echo from 'laravel-echo';
import Pusher from 'pusher-js';
window.Pusher = Pusher;
// Private channel subscriptions POST to /broadcasting/auth, which sits
// behind the app's normal CSRF middleware like any other POST route —
// without this header every private-channel auth request 419s silently
// (pusher-js swallows it as a subscription error), so nothing broadcast
// ever reaches the browser even though the socket connection itself works.
const csrfToken = document.querySelector('meta[name="csrf-token"]')?.getAttribute('content');
window.Echo = new Echo({
broadcaster: 'reverb',
key: import.meta.env.VITE_REVERB_APP_KEY,
wsHost: import.meta.env.VITE_REVERB_HOST,
wsPort: import.meta.env.VITE_REVERB_PORT ?? 80,
wssPort: import.meta.env.VITE_REVERB_PORT ?? 443,
forceTLS: (import.meta.env.VITE_REVERB_SCHEME ?? 'https') === 'https',
enabledTransports: ['ws', 'wss'],
auth: {
headers: {
'X-CSRF-TOKEN': csrfToken,
},
},
});
/**
* Bridges Reverb broadcast events into plain Livewire events rather than
* using the `#[On('echo-private:...')]` attribute directly on components —
* this indirection is deliberately version-agnostic and easy to verify from
* the browser console regardless of Livewire's internals.
*
* This file is loaded via @vite as `type="module"`, which the HTML spec
* defers until after the document is parsed — meaning any plain
* (non-deferred) <script> earlier in the page, including Livewire's own
* bootstrap script from @livewireScripts, has ALREADY run by the time this
* executes. So `window.Livewire` is already available here; there's no
* reason to wait for the 'livewire:init' event. Waiting for it was actually
* a bug: Livewire dispatches that event synchronously as part of its own
* (earlier-running) script, so a listener registered this late permanently
* missed it — silently disabling this whole subscription, every time.
*/
if (window.currentUserId) {
window.Echo.private('operator.queue')
.listen('.TicketQueueChanged', (e) => {
if (e.actorId !== window.currentUserId) {
// Only ticketId is passed through — Livewire calls #[On] methods
// with the payload as named arguments, so keeping this to a
// single well-known key avoids every listener having to declare
// (and ignore) every field this event might ever carry.
Livewire.dispatch('queue-changed', { ticketId: e.ticketId });
}
})
.error((error) => console.error('operator.queue subscription error', error));
}
/**
* Every logged-in user's own private notification stream — refreshes the
* bell instantly (see NotificationBell::onBellNotification()) and, when the
* viewer has opted in via the toggle on the notification-preferences page,
* also raises an in-tab browser Notification. Deliberately lightweight: no
* service worker, no push subscription — this only fires while the tab
* calling it is open, same limitation as the operator.queue block above.
*/
if (window.currentUserId) {
window.Echo.private('App.Models.User.' + window.currentUserId)
.listen('.NotificationCreated', (e) => {
Livewire.dispatch('bell-notification-received', { notificationId: e.notificationId });
if (
localStorage.getItem('browserNotificationsEnabled') === '1'
&& typeof Notification !== 'undefined'
&& Notification.permission === 'granted'
) {
const popup = new Notification(e.message, { tag: e.notificationId });
popup.onclick = () => {
window.focus();
window.location.href = e.url;
};
}
})
.error((error) => console.error('user notification channel subscription error', error));
}
/**
* Subscribes to a single ticket's channel — called by the Blade view of
* whichever TicketShow component (operator or client) is currently mounted,
* since the channel name needs the ticket id that only the page knows.
*/
window.subscribeToTicketChannel = function (ticketId) {
window.Echo.private('ticket.' + ticketId)
.listen('.TicketMessagePosted', (e) => {
if (e.actorId !== window.currentUserId) {
Livewire.dispatch('ticket-message-posted', { ticketId: e.ticketId });
}
})
.listen('.TicketQueueChanged', (e) => {
if (e.actorId !== window.currentUserId) {
Livewire.dispatch('queue-changed', { ticketId: e.ticketId });
}
})
.error((error) => console.error('ticket.' + ticketId + ' subscription error', error));
};
// The @script block in ticket-show.blade.php calls subscribeToTicketChannel()
// as soon as Livewire processes that component — which can happen either
// before or after this deferred module has run, depending on exactly when
// Livewire gets to it. If it ran first, it queued the ticket id here instead
// of finding the function undefined; flush that queue now that we're ready.
(window.__pendingTicketChannelIds || []).forEach((id) => window.subscribeToTicketChannel(id));
window.__pendingTicketChannelIds = null;

View File

@@ -2,24 +2,12 @@
@php
$url = \Illuminate\Support\Facades\Storage::disk('public')->url($attachment->path);
$isImage = \Illuminate\Support\Str::startsWith($attachment->mime ?? '', 'image/');
@endphp
@if ($isImage)
<a href="{{ $url }}" target="_blank" style="display:block;margin-top:8px">
<img
src="{{ $url }}"
alt="{{ $attachment->original_name }}"
loading="lazy"
style="max-width:220px;max-height:160px;border-radius:8px;border:1px solid var(--color-divider);object-fit:cover;cursor:zoom-in;display:block"
>
</a>
@else
<a
href="{{ $url }}"
target="_blank"
style="display:inline-flex;align-items:center;gap:6px;margin-top:8px;padding:5px 10px;border:1px solid var(--color-divider);border-radius:6px;font-size:12.5px;color:inherit;text-decoration:none;background:color-mix(in srgb, var(--color-text) 5%, transparent)"
>
<span class="material-symbols-outlined" style="font-size:15px">attach_file</span>{{ $attachment->original_name }}
</a>
@endif
<a
href="{{ $url }}"
target="_blank"
style="display:inline-flex;align-items:center;gap:6px;margin-top:8px;padding:5px 10px;border:1px solid var(--color-divider);border-radius:6px;font-size:12.5px;color:inherit;text-decoration:none;background:color-mix(in srgb, var(--color-text) 5%, transparent)"
>
<span class="material-symbols-outlined" style="font-size:15px">attach_file</span>{{ $attachment->original_name }}
</a>

View File

@@ -0,0 +1,50 @@
@props(['area' => null])
@php
// $area is passed explicitly by each page (e.g. <x-topbar area="operator" />)
// rather than inferred from request()->routeIs() here: this component is
// rendered as part of each top-level Livewire page's own template, so it
// re-renders on every wire:click/wire:model round-trip on that page (tab
// switches, pagination, search, ...) — and during that AJAX request,
// request()->route() is Livewire's own update route, not client./operator./
// admin.*, which silently broke the highlight on every in-page interaction
// when this used to key off the ambient request instead of an explicit prop.
$user = auth()->user();
$areas = [];
if ($user) {
if ($user->isClient()) {
$areas[] = ['label' => 'Klient', 'url' => route('client.dashboard'), 'active' => $area === 'client'];
}
if ($user->isOperator()) {
$areas[] = ['label' => 'Operator', 'url' => route('operator.queue'), 'active' => $area === 'operator'];
}
if ($user->isAdmin()) {
$areas[] = ['label' => 'Administrator', 'url' => route('admin.panel'), 'active' => $area === 'admin'];
}
}
$activeIndex = collect($areas)->search(fn ($area) => $area['active']);
@endphp
@if (count($areas))
<div
class="panel-switch"
style="position:absolute;left:50%;top:50%;transform:translate(-50%, -50%)"
>
@if ($activeIndex !== false)
<span
class="panel-switch-indicator"
style="width:calc(100% / {{ count($areas) }});transform:translateX({{ $activeIndex * 100 }}%)"
></span>
@endif
@foreach ($areas as $item)
<a
href="{{ $item['url'] }}"
wire:navigate
class="panel-switch-option {{ $item['active'] ? 'panel-switch-option-active' : '' }}"
>{{ $item['label'] }}</a>
@endforeach
</div>
@endif

View File

@@ -1,22 +1,9 @@
@php
$user = auth()->user();
$areas = [];
if ($user) {
if ($user->isClient()) {
$areas[] = ['label' => 'Panel Klienta', 'url' => route('client.dashboard'), 'active' => request()->routeIs('client.*')];
}
if ($user->isOperator()) {
$areas[] = ['label' => 'Panel Operatora', 'url' => route('operator.queue'), 'active' => request()->routeIs('operator.*')];
}
if ($user->isAdmin()) {
$areas[] = ['label' => 'Panel Administratora', 'url' => route('admin.panel'), 'active' => request()->routeIs('admin.*')];
}
}
@endphp
@if ($user)
<div x-data="{ open: false }" @click.outside="open = false" style="position:relative;display:inline-block">
<div x-data="{ open: false }" @click.outside="open = false" class="nav-dropdown-wrap" style="position:relative;display:inline-block">
<button type="button" class="btn btn-secondary" @click="open = !open" style="display:flex;align-items:center;gap:6px">
<span class="material-symbols-outlined" style="font-size:18px">account_circle</span>
<span class="profile-menu-name">{{ $user->name }}</span>
@@ -25,19 +12,36 @@
<div
x-show="open"
x-cloak
style="position:absolute;top:100%;right:0;margin-top:6px;background:var(--color-surface);border:1px solid var(--color-divider);border-radius:8px;box-shadow:var(--shadow-md);min-width:200px;overflow:hidden;z-index:30"
class="nav-dropdown"
style="position:absolute;top:100%;right:0;margin-top:6px;background:var(--color-surface);border:1px solid var(--color-divider);border-radius:8px;box-shadow:var(--shadow-md);min-width:220px;overflow:hidden;z-index:30"
>
@foreach ($areas as $area)
<div style="display:flex;flex-direction:column;gap:6px;padding:12px">
<span style="font-weight:600;font-size:13px;overflow:hidden;text-overflow:ellipsis;white-space:nowrap">{{ $user->name }}</span>
<span style="font-size:11.5px;color:color-mix(in srgb, var(--color-text) 60%, transparent);overflow:hidden;text-overflow:ellipsis;white-space:nowrap">{{ $user->email }}</span>
<div style="display:flex;flex-wrap:wrap;gap:4px;margin-top:2px">
@if ($user->isClient())
<span class="tag tag-neutral">Klient</span>
@endif
@if ($user->isOperator())
<span class="tag tag-accent-2">Operator</span>
@endif
@if ($user->isAdmin())
<span class="tag tag-accent">Administrator</span>
@endif
</div>
</div>
<div style="border-top:1px solid var(--color-divider)"></div>
@if ($user->isOperator() || $user->isAdmin())
<a
href="{{ $area['url'] }}"
href="{{ route('settings.notifications') }}"
wire:navigate
@click="open = false"
class="theme-toggle-option"
style="text-decoration:none;color:{{ $area['active'] ? 'var(--color-accent)' : 'var(--color-text)' }};font-size:12.5px"
>{{ $area['label'] }}</a>
@endforeach
style="text-decoration:none;color:{{ request()->routeIs('settings.*') ? 'var(--color-accent)' : 'var(--color-text)' }};font-size:12.5px"
>Powiadomienia</a>
@if (count($areas))
<div style="border-top:1px solid var(--color-divider)"></div>
@endif

View File

@@ -0,0 +1,64 @@
@props([
'assets',
'variant' => 'banner',
'title' => 'Twój sprzęt (inwentarz)',
'selectable' => false,
'selectAction' => 'selectSnipeitAsset',
'selectedId' => null,
// false when embedded inside a caller-provided card (e.g. the operator's
// "Przeszukaj inwentarz" search box + results in one container) — skips
// this component's own wrapping card/title so the two don't nest.
'card' => true,
])
@php
$isSidebar = $variant === 'sidebar';
@endphp
@if (count($assets))
@if ($card)
<div class="card" style="{{ $isSidebar ? 'padding:16px;gap:8px' : 'padding:14px;gap:10px;background:color-mix(in srgb, var(--color-accent) 6%, transparent);border-color:color-mix(in srgb, var(--color-accent) 25%, var(--color-divider))' }}">
@if ($isSidebar)
<div class="card-kicker">{{ $title }}</div>
@else
<div style="display:flex;align-items:center;gap:6px;font-size:12.5px;font-weight:600">
<span class="material-symbols-outlined" style="font-size:16px">devices</span>
{{ $title }}
</div>
@endif
@endif
<div style="display:flex;flex-direction:column;gap:2px">
@foreach ($assets as $a)
@php $isSelected = $selectedId === $a['id']; @endphp
<div style="display:flex;gap:8px;align-items:center;padding:8px;border-radius:6px;{{ $isSelected ? 'background:color-mix(in srgb, var(--color-accent) 10%, transparent)' : '' }}">
<a
href="{{ $a['url'] }}"
target="_blank"
rel="noopener noreferrer"
style="display:flex;gap:10px;align-items:flex-start;flex:1;min-width:0;text-decoration:none;color:inherit"
>
<span class="material-symbols-outlined" style="font-size:18px;flex:none;margin-top:1px;color:var(--color-accent)">devices</span>
<span style="min-width:0;flex:1">
<span style="display:block;font-size:13px;font-weight:500;{{ $isSelected ? 'color:var(--color-accent)' : '' }}">{{ $a['label'] }}</span>
@if (! empty($a['category']))
<span style="display:block;font-size:11px;color:color-mix(in srgb, var(--color-text) 55%, transparent);margin-top:1px">{{ $a['category'] }}</span>
@endif
</span>
</a>
@if ($selectable)
@if ($isSelected)
<span style="flex:none;display:flex;align-items:center;gap:4px;font-size:11px;color:var(--color-accent);white-space:nowrap">
<span class="material-symbols-outlined" style="font-size:16px">check_circle</span>
Powiązano
</span>
@else
<button type="button" class="btn btn-secondary" style="flex:none;font-size:11px;padding:4px 8px;white-space:nowrap" wire:click="{{ $selectAction }}({{ $a['id'] }})">Powiąż</button>
@endif
@endif
</div>
@endforeach
</div>
@if ($card)
</div>
@endif
@endif

View File

@@ -12,6 +12,7 @@
}
}"
@click.outside="open = false"
class="nav-dropdown-wrap"
style="position:relative;display:inline-block"
>
<button type="button" class="btn btn-secondary btn-icon" @click="open = !open">
@@ -20,6 +21,7 @@
<div
x-show="open"
x-cloak
class="nav-dropdown"
style="position:absolute;top:100%;right:0;margin-top:6px;background:var(--color-surface);border:1px solid var(--color-divider);border-radius:8px;box-shadow:var(--shadow-md);min-width:150px;overflow:hidden;z-index:20"
>
<button type="button" class="theme-toggle-option" @click="apply('light')">

View File

@@ -1,18 +1,9 @@
@php
$panelLabel = match (true) {
request()->routeIs('client.*') => 'Panel Klienta',
request()->routeIs('operator.*') => 'Panel Operatora',
request()->routeIs('admin.*') => 'Panel Administratora',
default => null,
};
@endphp
@props(['area' => null])
<div class="nav" style="position:relative;padding:16px 28px;border-bottom:1px solid var(--color-divider)">
<span class="nav-brand">{{ \App\Support\Settings::get('company_name') }}</span>
@if ($panelLabel)
<span class="nav-panel-label" style="position:absolute;left:50%;top:50%;transform:translate(-50%, -50%);font-weight:500;font-size:13.5px;white-space:nowrap">{{ $panelLabel }}</span>
@endif
<x-panel-switcher :area="$area" />
<x-theme-toggle />
@@ -20,6 +11,7 @@
@auth
<livewire:notification-bell />
<livewire:global-search />
@endauth
<x-profile-menu />

Some files were not shown because too many files have changed in this diff Show More