229 refonte des graphes 5 - #234
Conversation
…hentication and exercise management
…hentication and dashboard
…hentication and dashboard
…tion for development
…ations for production and development
…n to session variables
…(email-verification.php et pending-approval.php)
…il storage and improving error handling
…d streamline admin login process
…ending registration data for the view
…flect user status
…nController and PdoUserRepository
…ing getPdo method in PdoUserRepository
…uccess messages in admin dashboard
…ans in PdoUserRepository
… PdoUserRepository
… error handling in resources_list
…nd improve error handling
Refactor logo links and user account status handling for navigation
en : sexy graph test (part 10.5) es : Prueba de gráfico sexy (parte 10.5) it : test del grafico sexy (parte 10.5) ger : Sexy-Graph-Test (Teil 10.5) chi : 性感图表测试(第一部分) jp : セクシーグラフテスト(パート10.5) kr : 섹시 그래프 테스트 (10.5부) br : test grafek sexy (lodenn 10.5) ar : اختبار الرسم البياني المثير (الجزء 10.5) ru : Сексуальный графический тест (часть 10.5) table d'enchantement : ℸᒷᓭℸ ⊣∷ᔑ!¡⍑ᒷ ᓭᒷ̇/|| (!¡ᔑ∷ℸ 10.5) renardien : tɛst græf sɛksi (part ten point five) hylien : → ᛏᛖᛋᛏ ᚷᚱᚨᛈᚺᛖ ᛋᛖᛉᛁ (ᛈᚨᚱᛏ 10.5) binaire : 01110100 01100101 01110011 01110100 00100000 01100111 01110010 01100001 01110000 01101000 01100101 00100000 01110011 01100101 01111000 01111001 00100000 00101000 01110000 01100001 01110010 01110100 00100000 00110001 00110000 00101110 00110101 00101001 hiéroglif : 𓏏𓋴𓏏 𓎼𓂋𓆑 𓋴𓎡𓋴 (𓊪𓂋𓏏 𓎆𓏾) braille : ⠞⠑⠎⠞ ⠛⠗⠁⠏⠓⠑ ⠎⠑⠭⠽ ⠷⠏⠁⠗⠞ ⠼⠁⠚⠲⠑⠾
…229-refonte-des-graphes-5
en : sexy graph test (part 10.6) es : Prueba de gráfico sexy (parte 10.6) it : test del grafico sexy (parte 10.6) ger : Sexy-Graph-Test (Teil 10.6) chi : 性感图表测试(第一部分) jp : セクシーグラフテスト(パート10.6) kr : 섹시 그래프 테스트 (10.6부) br : test grafek sexy (lodenn 10.6) ar : اختبار الرسم البياني المثير (الجزء 10.6) ru : Сексуальный графический тест (часть 10.6) table d'enchantement : ℸᒷᓭℸ ⊣∷ᔑ!¡⍑ᒷ ᓭᒷ̇/|| (!¡ᔑ∷ℸ 10.6) renardien : tɛst græf sɛksi (part ten point six) hylien : → ᛏᛖᛋᛏ ᚷᚱᚨᛈᚺᛖ ᛋᛖᛉᛁ (ᛈᚨᚱᛏ 10.6) binaire : 01110100 01100101 01110011 01110100 00100000 01100111 01110010 01100001 01110000 01101000 01100101 00100000 01110011 01100101 01111000 01111001 00100000 00101000 01110000 01100001 01110010 01110100 00100000 00110001 00110000 00101110 00110110 00101001 hiéroglif : 𓏏𓋴𓏏 𓎼𓂋𓆑 𓋴𓎡𓋴 (𓊪𓂋𓏏 𓎆𓏿) braille : ⠞⠑⠎⠞ ⠛⠗⠁⠏⠓⠑ ⠎⠑⠭⠽ ⠷⠏⠁⠗⠞ ⠼⠁⠚⠲⠋⠾
en : sexy graph test (part 10.7) es : Prueba de gráfico sexy (parte 10.7) it : test del grafico sexy (parte 10.7) ger : Sexy-Graph-Test (Teil 10.7) chi : 性感图表测试(第一部分) jp : セクシーグラフテスト(パート10.7) kr : 섹시 그래프 테스트 (10.7부) br : test grafek sexy (lodenn 10.7) ar : اختبار الرسم البياني المثير (الجزء 10.7) ru : Сексуальный графический тест (часть 10.7) table d'enchantement : ℸᒷᓭℸ ⊣∷ᔑ!¡⍑ᒷ ᓭᒷ̇/|| (!¡ᔑ∷ℸ 10.7) renardien : tɛst græf sɛksi (part ten point seven) hylien : → ᛏᛖᛋᛏ ᚷᚱᚨᛈᚺᛖ ᛋᛖᛉᛁ (ᛈᚨᚱᛏ 10.7) binaire : 01110100 01100101 01110011 01110100 00100000 01100111 01110010 01100001 01110000 01101000 01100101 00100000 01110011 01100101 01111000 01111001 00100000 00101000 01110000 01100001 01110010 01110100 00100000 00110001 00110000 00101110 00110111 00101001 hiéroglif : 𓏏𓋴𓏏 𓎼𓂋𓆑 𓋴𓎡𓋴 (𓊪𓂋𓏏 𓎆𓐀) braille : ⠞⠑⠎⠞ ⠛⠗⠁⠏⠓⠑ ⠎⠑⠭⠽ ⠷⠏⠁⠗⠞ ⠼⠁⠚⠲⠛⠾
en : sexy graph test (part 10.7) es : Prueba de gráfico sexy (parte 10.7) it : test del grafico sexy (parte 10.7) ger : Sexy-Graph-Test (Teil 10.7) chi : 性感图表测试(第一部分) jp : セクシーグラフテスト(パート10.7) kr : 섹시 그래프 테스트 (10.7부) br : test grafek sexy (lodenn 10.7) ar : اختبار الرسم البياني المثير (الجزء 10.7) ru : Сексуальный графический тест (часть 10.7) table d'enchantement : ℸᒷᓭℸ ⊣∷ᔑ!¡⍑ᒷ ᓭᒷ̇/|| (!¡ᔑ∷ℸ 10.7) renardien : tɛst græf sɛksi (part ten point seven) hylien : → ᛏᛖᛋᛏ ᚷᚱᚨᛈᚺᛖ ᛋᛖᛉᛁ (ᛈᚨᚱᛏ 10.7) binaire : 01110100 01100101 01110011 01110100 00100000 01100111 01110010 01100001 01110000 01101000 01100101 00100000 01110011 01100101 01111000 01111001 00100000 00101000 01110000 01100001 01110010 01110100 00100000 00110001 00110000 00101110 00110111 00101001 hiéroglif : 𓏏𓋴𓏏 𓎼𓂋𓆑 𓋴𓎡𓋴 (𓊪𓂋𓏏 𓎆𓐀) braille : ⠞⠑⠎⠞ ⠛⠗⠁⠏⠓⠑ ⠎⠑⠭⠽ ⠷⠏⠁⠗⠞ ⠼⠁⠚⠲⠛⠾
en : sexy graph test (part 10.7) es : Prueba de gráfico sexy (parte 10.7) it : test del grafico sexy (parte 10.7) ger : Sexy-Graph-Test (Teil 10.7) chi : 性感图表测试(第一部分) jp : セクシーグラフテスト(パート10.7) kr : 섹시 그래프 테스트 (10.7부) br : test grafek sexy (lodenn 10.7) ar : اختبار الرسم البياني المثير (الجزء 10.7) ru : Сексуальный графический тест (часть 10.7) table d'enchantement : ℸᒷᓭℸ ⊣∷ᔑ!¡⍑ᒷ ᓭᒷ̇/|| (!¡ᔑ∷ℸ 10.7) renardien : tɛst græf sɛksi (part ten point seven) hylien : → ᛏᛖᛋᛏ ᚷᚱᚨᛈᚺᛖ ᛋᛖᛉᛁ (ᛈᚨᚱᛏ 10.7) binaire : 01110100 01100101 01110011 01110100 00100000 01100111 01110010 01100001 01110000 01101000 01100101 00100000 01110011 01100101 01111000 01111001 00100000 00101000 01110000 01100001 01110010 01110100 00100000 00110001 00110000 00101110 00110111 00101001 hiéroglif : 𓏏𓋴𓏏 𓎼𓂋𓆑 𓋴𓎡𓋴 (𓊪𓂋𓏏 𓎆𓐀) braille : ⠞⠑⠎⠞ ⠛⠗⠁⠏⠓⠑ ⠎⠑⠭⠽ ⠷⠏⠁⠗⠞ ⠼⠁⠚⠲⠛⠾
en : sexy graph test (part 10.7) es : Prueba de gráfico sexy (parte 10.7) it : test del grafico sexy (parte 10.7) ger : Sexy-Graph-Test (Teil 10.7) chi : 性感图表测试(第一部分) jp : セクシーグラフテスト(パート10.7) kr : 섹시 그래프 테스트 (10.7부) br : test grafek sexy (lodenn 10.7) ar : اختبار الرسم البياني المثير (الجزء 10.7) ru : Сексуальный графический тест (часть 10.7) table d'enchantement : ℸᒷᓭℸ ⊣∷ᔑ!¡⍑ᒷ ᓭᒷ̇/|| (!¡ᔑ∷ℸ 10.7) renardien : tɛst græf sɛksi (part ten point seven) hylien : → ᛏᛖᛋᛏ ᚷᚱᚨᛈᚺᛖ ᛋᛖᛉᛁ (ᛈᚨᚱᛏ 10.7) binaire : 01110100 01100101 01110011 01110100 00100000 01100111 01110010 01100001 01110000 01101000 01100101 00100000 01110011 01100101 01111000 01111001 00100000 00101000 01110000 01100001 01110010 01110100 00100000 00110001 00110000 00101110 00110111 00101001 hiéroglif : 𓏏𓋴𓏏 𓎼𓂋𓆑 𓋴𓎡𓋴 (𓊪𓂋𓏏 𓎆𓐀) braille : ⠞⠑⠎⠞ ⠛⠗⠁⠏⠓⠑ ⠎⠑⠭⠽ ⠷⠏⠁⠗⠞ ⠼⠁⠚⠲⠛⠾
en : sexy graph test (part 10.7) es : Prueba de gráfico sexy (parte 10.7) it : test del grafico sexy (parte 10.7) ger : Sexy-Graph-Test (Teil 10.7) chi : 性感图表测试(第一部分) jp : セクシーグラフテスト(パート10.7) kr : 섹시 그래프 테스트 (10.7부) br : test grafek sexy (lodenn 10.7) ar : اختبار الرسم البياني المثير (الجزء 10.7) ru : Сексуальный графический тест (часть 10.7) table d'enchantement : ℸᒷᓭℸ ⊣∷ᔑ!¡⍑ᒷ ᓭᒷ̇/|| (!¡ᔑ∷ℸ 10.7) renardien : tɛst græf sɛksi (part ten point seven) hylien : → ᛏᛖᛋᛏ ᚷᚱᚨᛈᚺᛖ ᛋᛖᛉᛁ (ᛈᚨᚱᛏ 10.7) binaire : 01110100 01100101 01110011 01110100 00100000 01100111 01110010 01100001 01110000 01101000 01100101 00100000 01110011 01100101 01111000 01111001 00100000 00101000 01110000 01100001 01110010 01110100 00100000 00110001 00110000 00101110 00110111 00101001 hiéroglif : 𓏏𓋴𓏏 𓎼𓂋𓆑 𓋴𓎡𓋴 (𓊪𓂋𓏏 𓎆𓐀) braille : ⠞⠑⠎⠞ ⠛⠗⠁⠏⠓⠑ ⠎⠑⠭⠽ ⠷⠏⠁⠗⠞ ⠼⠁⠚⠲⠛⠾
en : sexy graph test (part 10.7) es : Prueba de gráfico sexy (parte 10.7) it : test del grafico sexy (parte 10.7) ger : Sexy-Graph-Test (Teil 10.7) chi : 性感图表测试(第一部分) jp : セクシーグラフテスト(パート10.7) kr : 섹시 그래프 테스트 (10.7부) br : test grafek sexy (lodenn 10.7) ar : اختبار الرسم البياني المثير (الجزء 10.7) ru : Сексуальный графический тест (часть 10.7) table d'enchantement : ℸᒷᓭℸ ⊣∷ᔑ!¡⍑ᒷ ᓭᒷ̇/|| (!¡ᔑ∷ℸ 10.7) renardien : tɛst græf sɛksi (part ten point seven) hylien : → ᛏᛖᛋᛏ ᚷᚱᚨᛈᚺᛖ ᛋᛖᛉᛁ (ᛈᚨᚱᛏ 10.7) binaire : 01110100 01100101 01110011 01110100 00100000 01100111 01110010 01100001 01110000 01101000 01100101 00100000 01110011 01100101 01111000 01111001 00100000 00101000 01110000 01100001 01110010 01110100 00100000 00110001 00110000 00101110 00110111 00101001 hiéroglif : 𓏏𓋴𓏏 𓎼𓂋𓆑 𓋴𓎡𓋴 (𓊪𓂋𓏏 𓎆𓐀) braille : ⠞⠑⠎⠞ ⠛⠗⠁⠏⠓⠑ ⠎⠑⠭⠽ ⠷⠏⠁⠗⠞ ⠼⠁⠚⠲⠛⠾
en : sexy graph test (part 10.7) es : Prueba de gráfico sexy (parte 10.7) it : test del grafico sexy (parte 10.7) ger : Sexy-Graph-Test (Teil 10.7) chi : 性感图表测试(第一部分) jp : セクシーグラフテスト(パート10.7) kr : 섹시 그래프 테스트 (10.7부) br : test grafek sexy (lodenn 10.7) ar : اختبار الرسم البياني المثير (الجزء 10.7) ru : Сексуальный графический тест (часть 10.7) table d'enchantement : ℸᒷᓭℸ ⊣∷ᔑ!¡⍑ᒷ ᓭᒷ̇/|| (!¡ᔑ∷ℸ 10.7) renardien : tɛst græf sɛksi (part ten point seven) hylien : → ᛏᛖᛋᛏ ᚷᚱᚨᛈᚺᛖ ᛋᛖᛉᛁ (ᛈᚨᚱᛏ 10.7) binaire : 01110100 01100101 01110011 01110100 00100000 01100111 01110010 01100001 01110000 01101000 01100101 00100000 01110011 01100101 01111000 01111001 00100000 00101000 01110000 01100001 01110010 01110100 00100000 00110001 00110000 00101110 00110111 00101001 hiéroglif : 𓏏𓋴𓏏 𓎼𓂋𓆑 𓋴𓎡𓋴 (𓊪𓂋𓏏 𓎆𓐀) braille : ⠞⠑⠎⠞ ⠛⠗⠁⠏⠓⠑ ⠎⠑⠭⠽ ⠷⠏⠁⠗⠞ ⠼⠁⠚⠲⠛⠾
en : sexy graph test (part 10.7) es : Prueba de gráfico sexy (parte 10.7) it : test del grafico sexy (parte 10.7) ger : Sexy-Graph-Test (Teil 10.7) chi : 性感图表测试(第一部分) jp : セクシーグラフテスト(パート10.7) kr : 섹시 그래프 테스트 (10.7부) br : test grafek sexy (lodenn 10.7) ar : اختبار الرسم البياني المثير (الجزء 10.7) ru : Сексуальный графический тест (часть 10.7) table d'enchantement : ℸᒷᓭℸ ⊣∷ᔑ!¡⍑ᒷ ᓭᒷ̇/|| (!¡ᔑ∷ℸ 10.7) renardien : tɛst græf sɛksi (part ten point seven) hylien : → ᛏᛖᛋᛏ ᚷᚱᚨᛈᚺᛖ ᛋᛖᛉᛁ (ᛈᚨᚱᛏ 10.7) binaire : 01110100 01100101 01110011 01110100 00100000 01100111 01110010 01100001 01110000 01101000 01100101 00100000 01110011 01100101 01111000 01111001 00100000 00101000 01110000 01100001 01110010 01110100 00100000 00110001 00110000 00101110 00110111 00101001 hiéroglif : 𓏏𓋴𓏏 𓎼𓂋𓆑 𓋴𓎡𓋴 (𓊪𓂋𓏏 𓎆𓐀) braille : ⠞⠑⠎⠞ ⠛⠗⠁⠏⠓⠑ ⠎⠑⠭⠽ ⠷⠏⠁⠗⠞ ⠼⠁⠚⠲⠛⠾
en : sexy graph test (part 10.7) es : Prueba de gráfico sexy (parte 10.7) it : test del grafico sexy (parte 10.7) ger : Sexy-Graph-Test (Teil 10.7) chi : 性感图表测试(第一部分) jp : セクシーグラフテスト(パート10.7) kr : 섹시 그래프 테스트 (10.7부) br : test grafek sexy (lodenn 10.7) ar : اختبار الرسم البياني المثير (الجزء 10.7) ru : Сексуальный графический тест (часть 10.7) table d'enchantement : ℸᒷᓭℸ ⊣∷ᔑ!¡⍑ᒷ ᓭᒷ̇/|| (!¡ᔑ∷ℸ 10.7) renardien : tɛst græf sɛksi (part ten point seven) hylien : → ᛏᛖᛋᛏ ᚷᚱᚨᛈᚺᛖ ᛋᛖᛉᛁ (ᛈᚨᚱᛏ 10.7) binaire : 01110100 01100101 01110011 01110100 00100000 01100111 01110010 01100001 01110000 01101000 01100101 00100000 01110011 01100101 01111000 01111001 00100000 00101000 01110000 01100001 01110010 01110100 00100000 00110001 00110000 00101110 00110111 00101001 hiéroglif : 𓏏𓋴𓏏 𓎼𓂋𓆑 𓋴𓎡𓋴 (𓊪𓂋𓏏 𓎆𓐀) braille : ⠞⠑⠎⠞ ⠛⠗⠁⠏⠓⠑ ⠎⠑⠭⠽ ⠷⠏⠁⠗⠞ ⠼⠁⠚⠲⠛⠾
en : sexy graph test (part 10.7) es : Prueba de gráfico sexy (parte 10.7) it : test del grafico sexy (parte 10.7) ger : Sexy-Graph-Test (Teil 10.7) chi : 性感图表测试(第一部分) jp : セクシーグラフテスト(パート10.7) kr : 섹시 그래프 테스트 (10.7부) br : test grafek sexy (lodenn 10.7) ar : اختبار الرسم البياني المثير (الجزء 10.7) ru : Сексуальный графический тест (часть 10.7) table d'enchantement : ℸᒷᓭℸ ⊣∷ᔑ!¡⍑ᒷ ᓭᒷ̇/|| (!¡ᔑ∷ℸ 10.7) renardien : tɛst græf sɛksi (part ten point seven) hylien : → ᛏᛖᛋᛏ ᚷᚱᚨᛈᚺᛖ ᛋᛖᛉᛁ (ᛈᚨᚱᛏ 10.7) binaire : 01110100 01100101 01110011 01110100 00100000 01100111 01110010 01100001 01110000 01101000 01100101 00100000 01110011 01100101 01111000 01111001 00100000 00101000 01110000 01100001 01110010 01110100 00100000 00110001 00110000 00101110 00110111 00101001 hiéroglif : 𓏏𓋴𓏏 𓎼𓂋𓆑 𓋴𓎡𓋴 (𓊪𓂋𓏏 𓎆𓐀) braille : ⠞⠑⠎⠞ ⠛⠗⠁⠏⠓⠑ ⠎⠑⠭⠽ ⠷⠏⠁⠗⠞ ⠼⠁⠚⠲⠛⠾
en : sexy graph test (part 10.7) es : Prueba de gráfico sexy (parte 10.7) it : test del grafico sexy (parte 10.7) ger : Sexy-Graph-Test (Teil 10.7) chi : 性感图表测试(第一部分) jp : セクシーグラフテスト(パート10.7) kr : 섹시 그래프 테스트 (10.7부) br : test grafek sexy (lodenn 10.7) ar : اختبار الرسم البياني المثير (الجزء 10.7) ru : Сексуальный графический тест (часть 10.7) table d'enchantement : ℸᒷᓭℸ ⊣∷ᔑ!¡⍑ᒷ ᓭᒷ̇/|| (!¡ᔑ∷ℸ 10.7) renardien : tɛst græf sɛksi (part ten point seven) hylien : → ᛏᛖᛋᛏ ᚷᚱᚨᛈᚺᛖ ᛋᛖᛉᛁ (ᛈᚨᚱᛏ 10.7) binaire : 01110100 01100101 01110011 01110100 00100000 01100111 01110010 01100001 01110000 01101000 01100101 00100000 01110011 01100101 01111000 01111001 00100000 00101000 01110000 01100001 01110010 01110100 00100000 00110001 00110000 00101110 00110111 00101001 hiéroglif : 𓏏𓋴𓏏 𓎼𓂋𓆑 𓋴𓎡𓋴 (𓊪𓂋𓏏 𓎆𓐀) braille : ⠞⠑⠎⠞ ⠛⠗⠁⠏⠓⠑ ⠎⠑⠭⠽ ⠷⠏⠁⠗⠞ ⠼⠁⠚⠲⠛⠾
…thon code and handle MD5 hash names
… attempts auto-create exercise
…eries and imports
…ames during import
…and avoid duplicates
Last fix pitier
There was a problem hiding this comment.
Pull request overview
This PR performs a major migration from the legacy controllers/ + models/ + views/ MVC and index.php?action=... routing to a new Core/ + App/ architecture with a custom router, DI container, and new REST-style routes (notably /auth/*, /resources, /api/*). It also updates parts of the dashboard JS to consume the new API endpoints and improves some UI behaviors (password rules, import chunking, donut chart tooltip).
Changes:
- Introduces a new Core/App bootstrap + router + service container, and replaces action-based routing with path-based routes in
App/routes.php. - Reworks authentication flow (register/login/verify/reset) and adds stronger password validation in views/use cases.
- Updates dashboard frontend modules and import endpoints to new
/api/dashboard/*and/api/import/*routes, plus chart/renderer UI tweaks.
Reviewed changes
Copilot reviewed 122 out of 134 changed files in this pull request and generated 13 comments.
Show a summary per file
| File | Description |
|---|---|
| views/auth/register.php | Removed legacy auth register view (migrated to App/View/auth/*). |
| views/auth/login.php | Removed legacy auth login view (migrated to App/View/auth/*). |
| public/js/password-toggle.js | Adds shared password visibility toggle helper. |
| public/js/modules/utils.js | Updates logout redirect to new /auth/logout route. |
| public/js/modules/studentList.js | Switches students/exercises fetch URLs to new /api/dashboard/* endpoints; adds RESOURCE_ID injection support. |
| public/js/modules/studentContent.js | Updates student/exercise fetch URLs to new API endpoints; adds RESOURCE_ID injection support. |
| public/js/modules/import.js | Updates import endpoints to /api/import/*, improves validation, chunking, and error handling; exposes functions globally. |
| public/js/modules/detailedCharts.js | Adds donut hover interaction + tooltip; removes debug console logging. |
| public/js/modules/attemptsRenderer.js | Improves robustness for differing field names in attempt payloads. |
| public/css/style.css | Adds auth-related CSS aliases (auth-container, auth-card, etc.). |
| public/css/dashboard.css | Adds fixed dashboard footer styling and minor header tweaks. |
| phpcs.xml | Updates PHPCS scan paths to App/ and Core/. |
| models/Resource.php | Removes legacy model (replaced by new repositories/entities). |
| models/PendingRegistration.php | Removes legacy model (replaced by new repositories/entities). |
| models/Exercise.php | Removes legacy model (replaced by new entities/repositories). |
| models/EmailService.php | Removes legacy email service (replaced by App/Model/EmailService). |
| models/Dataset.php | Removes legacy dataset model. |
| models/Database.php | Removes legacy DB connector (replaced by Core/Config/DatabaseConnection). |
| index.php | New entrypoint flow: bootstrap + router + container; adds shutdown/exception handlers. |
| docs/classes/Exercise.html | Updates generated docs (but currently appears inconsistent). |
| cron/cleanup.php | Migrates cron bootstrap usage; cleanup logic now largely commented/placeholder. |
| controllers/User/ResourceListController.php | Removes legacy controller (migrated to App/Controller/*). |
| controllers/User/ResourceDetailsController.php | Removes legacy controller (migrated to App/Controller/*). |
| controllers/User/DashboardController.php | Removes legacy controller (migrated to App/Controller/*). |
| controllers/Import/ImportController.php | Removes legacy proxy controller. |
| controllers/HomeController.php | Removes legacy home controller. |
| controllers/BaseController.php | Removes legacy base controller. |
| controllers/Auth/RegisterController.php | Removes legacy auth controller. |
| controllers/Auth/PasswordResetController.php | Removes legacy auth controller. |
| controllers/Auth/LogoutController.php | Removes legacy auth controller. |
| controllers/Auth/LoginController.php | Removes legacy auth controller. |
| controllers/Auth/EmailVerificationController.php | Removes legacy auth controller. |
| controllers/Auth/AuthController.php | Removes legacy auth service/controller. |
| controllers/Admin/AdminLogin.php | Removes legacy admin login controller. |
| controllers/Admin/AdminDashboardController.php | Removes legacy admin dashboard controller. |
| composer.lock | Adds PHPMailer and platform extensions. |
| composer.json | Adds PHPMailer + ext requirements; adds PSR-4 autoload for App\\ and Core\\. |
| admin/index.php | Removes legacy admin redirect shim. |
| README.md | Updates technology notes and project structure documentation (currently mismatched vs repo layout). |
| Core/Service/SessionServiceInterface.php | Adds session abstraction interface. |
| Core/Service/SessionService.php | Adds session service implementation. |
| Core/Service/Container.php | Adds lightweight DI container used by router. |
| Core/Config/EnvLoader.php | Adds .env loader (currently uses a hard die() on missing file). |
| Core/Config/DatabaseConnection.php | Adds PDO singleton powered by EnvLoader. |
| App/routes.php | Defines new path-based routes for auth/resources/dashboard/admin/APIs. |
| App/bootstrap.php | Adds bootstrap: autoload, env loading, error reporting, BASE_URL definition. |
| App/View/user/resources_list.php | Minor header changes + text/icon regressions (encoding issues). |
| App/View/user/resource_details.php | Updates scripts/footer; injects RESOURCE_ID; some routes/fields changed. |
| App/View/user/mentions-legales.php | Adjusts back-link rendering (currently encoding issue). |
| App/View/resources/create.php | Adds new “create resource” view. |
| App/View/layouts/footer.php | Minor footer script formatting tweak. |
| App/View/home/index.php | Updates asset paths + auth links to new routes. |
| App/View/exercises/show.php | Adds new exercise show view (still contains legacy index.php?action= links). |
| App/View/exercises/list.php | Adds new exercise list view (still contains legacy index.php?action= links). |
| App/View/errors/500.php | Adds new 500 error page. |
| App/View/errors/404.php | Adds new 404 error page. |
| App/View/auth/reset-password.php | Updates reset-password route + strengthens password requirements + adds live validation UI. |
| App/View/auth/register.php | Adds new register view + password strength rules (canonical still legacy). |
| App/View/auth/pending-approval.php | Updates links to new auth routes. |
| App/View/auth/login.php | Adds new login view that uses shared password-toggle.js. |
| App/View/auth/forgot-password.php | Updates forgot-password flow to new routes; changes input name to email. |
| App/View/auth/email-verification.php | Updates verification and resend endpoints to new routes. |
| App/View/admin/admin-login.php | Updates admin login form action and home link. |
| App/Model/UseCase/RegisterUserUseCase.php | Adds registration use case + password validation + email send. |
| App/Model/UseCase/Ports/UserRegistrationPort.php | Adds port interface for registration persistence. |
| App/Model/UseCase/Ports/UserFinderPort.php | Adds base user lookup port. |
| App/Model/UseCase/Ports/UserAuthFinderPort.php | Adds auth lookup port. |
| App/Model/UseCase/Ports/ExerciseLookupPort.php | Adds exercise lookup port extension. |
| App/Model/UseCase/Ports/ExerciseListReaderPort.php | Adds exercise list reader port. |
| App/Model/UseCase/Ports/ExerciseImporterPort.php | Adds exercise import port. |
| App/Model/UseCase/Ports/ExerciseFinderPort.php | Adds base exercise finder port. |
| App/Model/UseCase/Ports/AttemptBulkInserterPort.php | Adds bulk attempt insert port. |
| App/Model/UseCase/LoginUserUseCase.php | Adds login use case with account status checks + session creation. |
| App/Model/UseCase/ListExercisesUseCase.php | Adds exercises listing use case. |
| App/Model/StudentRepository.php | Adds new student repository. |
| App/Model/ResourceRepositoryInterface.php | Adds resource repository interface for controller DI. |
| App/Model/PendingRegistrationRepository.php | Adds pending registration repository. |
| App/Model/Entity/User.php | Adds new User entity with verification/reset logic. |
| App/Model/Entity/Student.php | Adds new Student entity. |
| App/Model/Entity/Resource.php | Adds new Resource entity. |
| App/Model/Entity/PendingRegistration.php | Adds PendingRegistration entity. |
| App/Model/Entity/Exercise.php | Adds Exercise entity mapping new schema naming. |
| App/Model/Entity/Attempt.php | Adds Attempt entity. |
| App/Model/EmailService.php | Adds PHPMailer-based email service using EnvLoader config. |
| App/Model/AuthenticationServiceInterface.php | Adds auth service interface. |
| App/Model/AuthenticationService.php | Adds session-based auth service implementation. |
| App/Model/AttemptRepository.php | Adds attempt repository + bulk insert implementation. |
| App/Controller/VerifyEmailController.php | Adds controller for email verification + resend flow. |
| App/Controller/RegisterController.php | Adds controller wiring RegisterUserUseCase. |
| App/Controller/LogoutController.php | Adds controller for logout using AuthenticationService. |
| App/Controller/LoginController.php | Adds controller wiring LoginUserUseCase. |
| App/Controller/HomeController.php | Adds controller serving home view. |
| App/Controller/ForgotPasswordController.php | Adds forgot/reset password flow controller with anti-enumeration behavior. |
| App/Controller/ExercisesController.php | Adds exercises controller (list + redirect-to-resource behavior). |
| App/Controller/DashboardController.php | Adds dashboard controller enforcing auth. |
| .htaccess | Simplifies rewrites; changes error handling; removes previously defined security headers/caching rules. |
| .gitignore | Expands ignored files (env/logs/vendor/tmp/etc.). |
Comments suppressed due to low confidence (10)
App/View/user/resource_details.php:105
- Ce lien logo pointe encore vers l'ancien routeur querystring (/index.php?action=resources_list). Avec le nouveau routeur, la liste est servie par /resources ; ce lien risque de mener à une 404. Mettre à jour vers BASE_URL . '/resources' (et éviter les routes action=...).
App/View/user/resources_list.php:166 - Le texte du bouton d’édition semble corrompu (caractères illisibles à la place de l’icône ✏️). Cela ressemble à un problème d’encodage fichier/commit et dégrade l’UI. Remettre l’icône ou un libellé texte ASCII (ex: "Modifier").
App/View/user/resources_list.php:268 - Le titre de la modale de confirmation contient des caractères corrompus (à la place de l'icône
⚠️ ). Corriger l'encodage UTF-8 ou remplacer par une entité HTML/SVG pour garantir un rendu stable.
App/View/user/resource_details.php:152 - Le menu burger contient encore un lien de déconnexion vers /index.php?action=logout, alors que les routes ont été migrées vers /auth/logout. Mettre à jour ce lien pour éviter une 404 et rester cohérent avec Utils.confirmLogout().
App/View/user/resources_list.php:259 - Le libellé du bouton de suppression contient des caractères corrompus/contrôles (à la place de 🗑️). Corriger l'encodage ou remplacer par une icône SVG/texte pour éviter un rendu illisible selon les navigateurs.
App/View/user/resources_list.php:55 - Le lien du logo utilise encore l’ancien schéma /index.php?action=resources_list. Avec le nouveau routeur, la page ressources est /resources. Mettre à jour l’URL pour éviter des 404 et supprimer la dépendance au paramètre action.
App/View/user/resource_details.php:18 - window.BASE_URL est forcé à une chaîne vide, ce qui écrase la valeur injectée globalement (ex: via .env / footer) et casse les déploiements en sous-dossier. Initialiser BASE_URL depuis la constante PHP (ou ne pas le réassigner ici) plutôt que de le mettre à ''.
App/View/user/resource_details.php:187 - Le titre d'exercice utilise $exercise->hash, mais dans les modèles/entités (ancien et nouveau) le libellé est généralement exo_name / exercice_name / funcname. Si "hash" n'est pas présent, l'UI affichera une valeur vide. Utiliser un champ de nom connu (et/ou une méthode d'entité) pour afficher le titre.
App/View/user/resource_details.php:306 - Le lien "Mentions légales" pointe vers /mentions-legales, mais aucune route correspondante n'est définie dans App/routes.php. Cela mènera à une 404. Ajouter une route GET /mentions-legales vers un contrôleur dédié ou revenir à une URL existante.
App/View/user/mentions-legales.php:75 - Le lien de retour affiche des caractères corrompus (à la place de "← Retour"), ce qui indique un problème d’encodage. Remplacer par l’entité HTML ← ou s'assurer que les fichiers sont en UTF-8 sans conversion.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| $uri = $_SERVER['REQUEST_URI'] ?? ''; | ||
| if (strpos($uri, '/api/') !== false) { | ||
| if (!headers_sent()) { | ||
| header('Content-Type: application/json; charset=utf-8'); | ||
| } | ||
| echo json_encode(['success' => false, 'message' => 'Erreur interne fatale.', 'debug' => $error['message']]); | ||
| return; |
There was a problem hiding this comment.
Les réponses JSON des endpoints /api incluent systématiquement un champ "debug" qui expose le message d'erreur PHP (potentiellement sensible) aux clients. Il faudrait n'inclure les détails de debug qu'en environnement development (APP_ENV), et retourner uniquement un message générique en production.
| ``` | ||
| StudTraj/ | ||
| ├── config/ # Configuration et routage | ||
| │ └── router.php # Routeur principal de l'application | ||
| ├── controllers/ # Contrôleurs MVC | ||
| │ ├── Admin/ # Gestion administrative | ||
| │ ├── Analysis/ # Analyse et visualisation | ||
| │ ├── Auth/ # Authentification et autorisation | ||
| │ ├── Import/ # Import de données | ||
| │ └── User/ # Fonctionnalités utilisateur | ||
| ├── models/ # Modèles de données | ||
| │ ├── Database.php # Connexion base de données | ||
| │ ├── Student.php # Gestion des étudiants | ||
| │ ├── Exercise.php # Gestion des exercices | ||
| │ ├── Resource.php # Gestion des ressources | ||
| │ ├── User.php # Gestion des utilisateurs | ||
| │ └── Code2VecService.php # Service d'analyse vectorielle | ||
| ├── views/ # Vues (templates) | ||
| │ ├── admin/ # Vues administrateur | ||
| │ └── user/ # Vues utilisateur | ||
| ├── public/ # Ressources publiques | ||
| │ ├── css/ # Feuilles de style | ||
| │ └── js/ # Scripts JavaScript | ||
| ├── docs/ # Documentation générée | ||
| ├── images/ # Images uploadées | ||
| ├── cron/ # Tâches planifiées | ||
| └── index.php # Point d'entrée de l'application | ||
| ├── config/ # Configuration et routage | ||
| ├── src/ # Code source de l'application | ||
| │ ├── Application/ # Use Cases (logique applicative) | ||
| │ │ ├── Authentication/ | ||
| │ │ ├── ExerciseManagement/ | ||
| │ │ └── StudentTracking/ | ||
| │ ├── Domain/ # Entités et interfaces métier | ||
| │ │ ├── Authentication/ | ||
| │ │ ├── ExerciseManagement/ | ||
| │ │ ├── ResourceManagement/ | ||
| │ │ └── StudentTracking/ | ||
| │ ├── Infrastructure/ # Implémentations techniques | ||
| │ │ ├── DependencyInjection/ | ||
| │ │ ├── Persistence/ | ||
| │ │ ├── Repository/ | ||
| │ │ ├── Routing/ | ||
| │ │ └── Service/ | ||
| │ └── Presentation/ # Interface utilisateur | ||
| │ ├── Controller/ # Contrôleurs | ||
| │ │ ├── Authentication/ | ||
| │ │ ├── ExerciseManagement/ | ||
| │ │ ├── ResourceManagement/ | ||
| │ │ ├── StudentTracking/ | ||
| │ │ └── UserManagement/ | ||
| │ └── Views/ # Vues (templates) | ||
| │ ├── admin/ # Vues administrateur | ||
| │ ├── auth/ # Vues authentification | ||
| │ ├── layouts/ # Layouts partagés | ||
| │ └── user/ # Vues utilisateur | ||
| ├── public/ # Ressources publiques | ||
| │ ├── css/ # Feuilles de style | ||
| │ └── js/ # Scripts JavaScript | ||
| ├── scripts/ # Scripts Python (Code2Vec) | ||
| ├── docs/ # Documentation générée | ||
| ├── vendor/ # Dépendances Composer | ||
| └── index.php # Point d'entrée de l'application |
There was a problem hiding this comment.
Le README décrit une arborescence basée sur un dossier "src/" (Application/Domain/Infrastructure/Presentation), mais le dépôt contient actuellement "App/" et "Core/" (et pas de "src/"). Mettre à jour la documentation pour refléter la structure réelle afin d'éviter de tromper les nouveaux contributeurs.
| // Pour les routes API, retourner du JSON au lieu de HTML | ||
| $uri = $_SERVER['REQUEST_URI'] ?? ''; | ||
| if (strpos($uri, '/api/') !== false) { | ||
| if (!headers_sent()) { | ||
| header('Content-Type: application/json; charset=utf-8'); | ||
| } | ||
| echo json_encode([ | ||
| 'success' => false, | ||
| 'message' => 'Erreur interne du serveur.', | ||
| 'debug' => $msg . ' in ' . basename($file) . ':' . $line, | ||
| ]); | ||
| return; |
There was a problem hiding this comment.
Le handler d'exception pour les routes /api renvoie aussi des détails internes (message + fichier/ligne) via "debug". En production cela peut divulguer des informations (structure de fichiers, messages SQL, etc.). Conditionner ce champ à APP_ENV=development ou le supprimer côté production.
| ErrorDocument 404 /index.php | ||
| # NOTE: ErrorDocument 500 intentionally removed — redirecting to index.php on 500 | ||
| # would cause an infinite loop if index.php itself triggers the error. | ||
|
|
There was a problem hiding this comment.
Les règles de réécriture ne définissent plus de headers de sécurité (X-Content-Type-Options, X-Frame-Options, Referrer-Policy, etc.) présents auparavant. Si ces headers ne sont pas définis au niveau serveur, c'est une régression de sécurité. Réintroduire les headers ici ou documenter/assurer leur définition côté infra.
| # Security headers | |
| <IfModule mod_headers.c> | |
| Header always set X-Content-Type-Options "nosniff" | |
| Header always set X-Frame-Options "SAMEORIGIN" | |
| Header always set Referrer-Policy "no-referrer-when-downgrade" | |
| Header always set X-XSS-Protection "1; mode=block" | |
| </IfModule> |
| <nav class="nav-menu"> | ||
| <a href="<?= BASE_URL ?>/index.php?action=resources_list">Ressources</a> | ||
| <a href="<?= BASE_URL ?>/index.php?action=exercises" class="active">Exercices</a> | ||
| </nav> | ||
|
|
||
| <div class="header-right"> | ||
| <div class="user-profile"> | ||
| <div class="user-avatar"><?= htmlspecialchars($initials) ?></div> | ||
| <span><?= htmlspecialchars($user_firstname) ?> <?= htmlspecialchars($user_lastname) ?></span> | ||
| </div> | ||
| <a href="<?= BASE_URL ?>/index.php?action=logout" class="btn-logout"> | ||
| <svg style="width:16px; height:16px;" viewBox="0 0 24 24" fill="none" | ||
| stroke="currentColor" stroke-width="2"> |
There was a problem hiding this comment.
Les liens de navigation utilisent encore /index.php?action=... (resources_list, exercises, logout). Avec le nouveau routeur, ces URLs risquent de ne plus matcher aucune route. Mettre à jour vers /resources, /exercises et /auth/logout pour éviter des 404.
|
|
||
| <nav class="nav-menu"> | ||
| <a href="<?= BASE_URL ?>/index.php?action=resources_list">Ressources</a> | ||
| <a href="<?= BASE_URL ?>/index.php?action=exercises" class="active">Exercices</a> | ||
| </nav> | ||
|
|
||
| <div class="header-right"> | ||
| <div class="user-profile"> | ||
| <div class="user-avatar"><?= htmlspecialchars($initials) ?></div> | ||
| <span><?= htmlspecialchars($user_firstname) ?> <?= htmlspecialchars($user_lastname) ?></span> | ||
| </div> | ||
| <a href="<?= BASE_URL ?>/index.php?action=logout" class="btn-logout"> | ||
| <svg style="width:16px; height:16px;" viewBox="0 0 24 24" fill="none" |
There was a problem hiding this comment.
Les liens de navigation utilisent encore /index.php?action=... (resources_list, exercises, logout). Avec le nouveau routeur, ces URLs risquent de ne plus matcher aucune route. Mettre à jour vers /resources, /exercises et /auth/logout pour éviter des 404.
| <h4 class="phpdocumentor-element__name" id="property_exo_name"> | ||
| $exo_name | ||
| $hash | ||
| <a href="classes/Exercise.html#property_exo_name" class="headerlink"><i class="fas fa-link"></i></a> |
There was a problem hiding this comment.
Dans la doc générée, l'ancre/ID est celle de la propriété exo_name mais le libellé affiché est devenu "$hash". Cela rend la documentation incohérente/inexacte. Regénérer la documentation ou corriger le mapping pour refléter le vrai nom de propriété.
| // Récupérer l'ID de la ressource depuis window.RESOURCE_ID (injecté PHP) ou l'URL | ||
| getResourceIdFromUrl() { | ||
| if (window.RESOURCE_ID !== undefined && window.RESOURCE_ID !== null) { | ||
| return window.RESOURCE_ID; | ||
| } |
There was a problem hiding this comment.
Même problème que dans studentList.js : window.RESOURCE_ID peut être injecté comme chaîne 'null'. getResourceIdFromUrl() devrait ignorer les valeurs non numériques et normaliser en entier, sinon les fetch suivants vont construire des URLs invalides avec resource_id=null.
| if (!file_exists($envPath)) { | ||
| // Affichage direct de l'erreur pour débogage immédiat | ||
| die( | ||
| "CRITICAL: Fichier .env introuvable. Chemin testé : " | ||
| . realpath($envPath) . " (Brut: " . $envPath . ")" | ||
| ); |
There was a problem hiding this comment.
En cas de fichier .env manquant, EnvLoader::load() fait un die() avec le chemin testé. En production, cela expose des chemins internes et coupe le flux d'erreurs standard (handler 500). Préférer lever une RuntimeException (message générique côté client) et laisser le bootstrap/handler gérer l'affichage selon APP_ENV.
| <form method="post" action="<?= BASE_URL ?>/resources/create"> | ||
| <div class="form-group"> |
There was a problem hiding this comment.
Le form poste vers /resources/create, mais les routes déclarées exposent POST /resources pour la création (et aucune route /resources/create). Cela provoquera une 404 à la soumission. Aligner l'action du form sur la route existante (/resources) ou ajouter une route dédiée /resources/create.
No description provided.