Skip to content

Latest commit

 

History

History
366 lines (261 loc) · 18.9 KB

File metadata and controls

366 lines (261 loc) · 18.9 KB
=== foundation rules ===

Laravel Boost Guidelines

The Laravel Boost guidelines are specifically curated by Laravel maintainers for this application. These guidelines should be followed closely to enhance the user's satisfaction building Laravel applications.

Foundational Context

This application is a Laravel application and its main Laravel ecosystems package & versions are below. You are an expert with them all. Ensure you abide by these specific packages & versions.

  • php - 8.3.24
  • filament/filament (FILAMENT) - v5
  • laravel/framework (LARAVEL) - v13
  • laravel/prompts (PROMPTS) - v0
  • laravel/sanctum (SANCTUM) - v4
  • livewire/livewire (LIVEWIRE) - v4
  • laravel/mcp (MCP) - v0
  • laravel/pint (PINT) - v1
  • laravel/sail (SAIL) - v1
  • phpunit/phpunit (PHPUNIT) - v12

Conventions

  • You must follow all existing code conventions used in this application. When creating or editing a file, check sibling files for the correct structure, approach, naming.
  • Use descriptive names for variables and methods. For example, isRegisteredForDiscounts, not discount().
  • Check for existing components to reuse before writing a new one.

Verification Scripts

  • Do not create verification scripts or tinker when tests cover that functionality and prove it works. Unit and feature tests are more important.

Application Structure & Architecture

  • Stick to existing directory structure - don't create new base folders without approval.
  • Do not change the application's dependencies without approval.

Frontend Bundling

  • If the user doesn't see a frontend change reflected in the UI, it could mean they need to run npm run build, npm run dev, or composer run dev. Ask them.

Replies

  • Be concise in your explanations - focus on what's important rather than explaining obvious details.

Documentation Files

  • You must only create documentation files if explicitly requested by the user.

=== boost rules ===

Laravel Boost

  • Laravel Boost is an MCP server that comes with powerful tools designed specifically for this application. Use them.

Artisan

  • Use the list-artisan-commands tool when you need to call an Artisan command to double check the available parameters.

URLs

  • Whenever you share a project URL with the user you should use the get-absolute-url tool to ensure you're using the correct scheme, domain / IP, and port.

Tinker / Debugging

  • You should use the tinker tool when you need to execute PHP to debug code or query Eloquent models directly.
  • Use the database-query tool when you only need to read from the database.

Reading Browser Logs With the browser-logs Tool

  • You can read browser logs, errors, and exceptions using the browser-logs tool from Boost.
  • Only recent browser logs will be useful - ignore old logs.

Searching Documentation (Critically Important)

  • Boost comes with a powerful search-docs tool you should use before any other approaches. This tool automatically passes a list of installed packages and their versions to the remote Boost API, so it returns only version-specific documentation specific for the user's circumstance. You should pass an array of packages to filter on if you know you need docs for particular packages.
  • The 'search-docs' tool is perfect for all Laravel related packages, including Laravel, Inertia, Livewire, Filament, Tailwind, Pest, Nova, Nightwatch, etc.
  • You must use this tool to search for Laravel-ecosystem documentation before falling back to other approaches.
  • Search the documentation before making code changes to ensure we are taking the correct approach.
  • Use multiple, broad, simple, topic based queries to start. For example: ['rate limiting', 'routing rate limiting', 'routing'].
  • Do not add package names to queries - package information is already shared. For example, use test resource table, not filament 4 test resource table.

Available Search Syntax

  • You can and should pass multiple queries at once. The most relevant results will be returned first.
  1. Simple Word Searches with auto-stemming - query=authentication - finds 'authenticate' and 'auth'
  2. Multiple Words (AND Logic) - query=rate limit - finds knowledge containing both "rate" AND "limit"
  3. Quoted Phrases (Exact Position) - query="infinite scroll" - Words must be adjacent and in that order
  4. Mixed Queries - query=middleware "rate limit" - "middleware" AND exact phrase "rate limit"
  5. Multiple Queries - queries=["authentication", "middleware"] - ANY of these terms

=== php rules ===

PHP

  • Always use curly braces for control structures, even if it has one line.

Constructors

  • Use PHP 8 constructor property promotion in __construct().
    • public function __construct(public GitHub $github) { }
  • Do not allow empty __construct() methods with zero parameters.

Type Declarations

  • Always use explicit return type declarations for methods and functions.
  • Use appropriate PHP type hints for method parameters.
protected function isAccessible(User $user, ?string $path = null): bool { ... }

Comments

  • Prefer PHPDoc blocks over comments. Never use comments within the code itself unless there is something very complex going on.

PHPDoc Blocks

  • Add useful array shape type definitions for arrays when appropriate.

Enums

  • Typically, keys in an Enum should be TitleCase. For example: FavoritePerson, BestLake, Monthly.

=== laravel/core rules ===

Do Things the Laravel Way

  • Use php artisan make: commands to create new files (i.e. migrations, controllers, models, etc.). You can list available Artisan commands using the list-artisan-commands tool.
  • If you're creating a generic PHP class, use artisan make:class.
  • Pass --no-interaction to all Artisan commands to ensure they work without user input. You should also pass the correct --options to ensure correct behavior.

Database

  • Always use proper Eloquent relationship methods with return type hints. Prefer relationship methods over raw queries or manual joins.
  • Use Eloquent models and relationships before suggesting raw database queries
  • Avoid DB::; prefer Model::query(). Generate code that leverages Laravel's ORM capabilities rather than bypassing them.
  • Generate code that prevents N+1 query problems by using eager loading.
  • Use Laravel's query builder for very complex database operations.

Model Creation

  • When creating new models, create useful factories and seeders for them too. Ask the user if they need any other things, using list-artisan-commands to check the available options to php artisan make:model.

APIs & Eloquent Resources

  • For APIs, default to using Eloquent API Resources and API versioning unless existing API routes do not, then you should follow existing application convention.

Controllers & Validation

  • Always create Form Request classes for validation rather than inline validation in controllers. Include both validation rules and custom error messages.
  • Check sibling Form Requests to see if the application uses array or string based validation rules.

Queues

  • Use queued jobs for time-consuming operations with the ShouldQueue interface.

Authentication & Authorization

  • Use Laravel's built-in authentication and authorization features (gates, policies, Sanctum, etc.).

URL Generation

  • When generating links to other pages, prefer named routes and the route() function.

Configuration

  • Use environment variables only in configuration files - never use the env() function directly outside of config files. Always use config('app.name'), not env('APP_NAME').

Testing

  • When creating models for tests, use the factories for the models. Check if the factory has custom states that can be used before manually setting up the model.
  • Faker: Use methods such as $this->faker->word() or fake()->randomDigit(). Follow existing conventions whether to use $this->faker or fake().
  • When creating tests, make use of php artisan make:test [options] <name> to create a feature test, and pass --unit to create a unit test. Most tests should be feature tests.

Vite Error

  • If you receive an "Illuminate\Foundation\ViteException: Unable to locate file in Vite manifest" error, you can run npm run build or ask the user to run npm run dev or composer run dev.

=== laravel/v13 rules ===

Laravel 13

  • Use the search-docs tool to get version specific documentation.
  • Since Laravel 11, Laravel has a new streamlined file structure which this project uses.

Laravel 13 Structure

  • No middleware files in app/Http/Middleware/.
  • bootstrap/app.php is the file to register middleware, exceptions, and routing files.
  • bootstrap/providers.php contains application specific service providers.
  • No app\Console\Kernel.php - use bootstrap/app.php or routes/console.php for console configuration.
  • Commands auto-register - files in app/Console/Commands/ are automatically available and do not require manual registration.

Database

  • When modifying a column, the migration must include all of the attributes that were previously defined on the column. Otherwise, they will be dropped and lost.
  • Laravel 11 allows limiting eagerly loaded records natively, without external packages: $query->latest()->limit(10);.

Models

  • Casts can and likely should be set in a casts() method on a model rather than the $casts property. Follow existing conventions from other models.

=== livewire/core rules ===

Livewire Core

  • Use the search-docs tool to find exact version specific documentation for how to write Livewire & Livewire tests.
  • Use the php artisan make:livewire [Posts\CreatePost] artisan command to create new components
  • State should live on the server, with the UI reflecting it.
  • All Livewire requests hit the Laravel backend, they're like regular HTTP requests. Always validate form data, and run authorization checks in Livewire actions.

Livewire Best Practices

  • Livewire components require a single root element.

  • Use wire:loading and wire:dirty for delightful loading states.

  • Add wire:key in loops:

    @foreach ($items as $item)
        <div wire:key="item-{{ $item->id }}">
            {{ $item->name }}
        </div>
    @endforeach
  • Prefer lifecycle hooks like mount(), updatedFoo() for initialization and reactive side effects:

public function mount(User $user) { $this->user = $user; } public function updatedSearch() { $this->resetPage(); }

Testing Livewire

Livewire::test(Counter::class) ->assertSet('count', 0) ->call('increment') ->assertSet('count', 1) ->assertSee(1) ->assertStatus(200);
<code-snippet name="Testing a Livewire component exists within a page" lang="php">
    $this->get('/posts/create')
    ->assertSeeLivewire(CreatePost::class);
</code-snippet>

=== livewire/v4 rules ===

Livewire 4

Component And API Conventions

  • Verify Livewire code against the v4 documentation before making assumptions based on older v2/v3 behavior.
  • Use the App\Livewire namespace for class-based components unless the existing codebase is intentionally using one of Livewire 4's newer component formats.
  • Use $this->dispatch() for server-side event dispatching.
  • When using wire:model modifiers, remember Livewire 4 changed some client-side sync timing semantics; prefer explicit modifiers such as wire:model.live when immediate synchronization is required.

Newer Livewire 4 Capabilities

  • Livewire 4 supports additional component formats, async actions, islands, and newer directives such as wire:intersect, wire:ref, and wire:sort.
  • Use these capabilities only when they fit the existing codebase and verify exact syntax with the search-docs tool.

Alpine And JavaScript

  • Alpine is included with Livewire; do not manually add a separate Alpine bundle.
  • Livewire 4 deprecates parts of the older JavaScript hook API in favor of interceptors. If you need custom client-side hooks or request interception, verify the current v4 pattern in the docs before implementing it.

Infrastructure Notes

  • Livewire 4 assets and endpoints now use a hash-based /livewire-{hash}/... prefix. If you touch middleware, proxies, or route customizations around Livewire endpoints, preserve that hashed path format.

=== pint/core rules ===

Laravel Pint Code Formatter

  • You must run vendor/bin/pint --dirty before finalizing changes to ensure your code matches the project's expected style.
  • Do not run vendor/bin/pint --test, simply run vendor/bin/pint to fix any formatting issues.

=== github-actions/core rules ===

GitHub Actions CI

  • Continuous Integration runs on pull requests and pushes to master. It classifies changed files and runs only the relevant checks: backend changes receive the Vite build plus PHP and MariaDB tests; frontend changes receive the Vite build; infrastructure changes receive Compose, installer, and container backup/restore checks. Workflow changes run the full CI suite.
  • Security Audit runs a secret scan on every pull request and master push. Dependency audits run for dependency or workflow changes; SAST runs for source changes on master and in the scheduled weekly audit. The required merge checks are CI gate and Security gate.
  • CI is validation-only: do not add deployment steps, repository write permissions, or secrets without explicit approval.
  • The frontend workflows use Node.js 24; local frontend checks require Node.js 22.18 or later.
  • Tags matching v0.*.* validate the release again, publish a GHCR container image with provenance and an SBOM, smoke-test its digest, and generate GitHub release notes; they must not deploy the application.
  • Before handing off PHP or frontend changes, run the applicable local equivalent of the CI checks. CI runs full Pint and fails if it produces a diff.

=== phpunit/core rules ===

PHPUnit Core

  • This application uses PHPUnit for testing. All tests must be written as PHPUnit classes. Use php artisan make:test --phpunit <name> to create a new test.
  • If you see a test using "Pest", convert it to PHPUnit.
  • Every time a test has been updated, run that singular test.
  • When the tests relating to your feature are passing, ask the user if they would like to also run the entire test suite to make sure everything is still passing.
  • Tests should test all of the happy paths, failure paths, and weird paths.
  • You must not remove any tests or test files from the tests directory without approval. These are not temporary or helper files, these are core to the application.

Running Tests

  • Run the minimal number of tests, using an appropriate filter, before finalizing.
  • To run all tests: php artisan test.
  • To run all tests in a file: php artisan test tests/Feature/ExampleTest.php.
  • To filter on a particular test name: php artisan test --filter=testName (recommended after making a change to a related file).

Beads Issue Tracker

This project uses bd (beads) for issue tracking. Run bd prime to see full workflow context and commands.

Quick Reference

bd ready              # Find available work
bd show <id>          # View issue details
bd update <id> --claim  # Claim work
bd close <id>         # Complete work

Rules

  • Use bd for ALL task tracking — do NOT use TodoWrite, TaskCreate, or markdown TODO lists
  • Run bd prime for detailed command reference and session close protocol
  • Use bd remember for persistent knowledge — do NOT use MEMORY.md files

Architecture in one line: issues live in a local Dolt DB; sync uses refs/dolt/data on your git remote; .beads/issues.jsonl is a passive export. See https://github.com/gastownhall/beads/blob/main/docs/SYNC_CONCEPTS.md for details and anti-patterns.

Agent Context Profiles

The managed Beads block is task-tracking guidance, not permission to override repository, user, or orchestrator instructions.

  • Conservative (default): Use bd for task tracking. Do not run git commits, git pushes, or Dolt remote sync unless explicitly asked. At handoff, report changed files, validation, and suggested next commands.
  • Minimal: Keep tool instruction files as pointers to bd prime; use the same conservative git policy unless active instructions say otherwise.
  • Team-maintainer: Only when the repository explicitly opts in, agents may close beads, run quality gates, commit, and push as part of session close. A current "do not commit" or "do not push" instruction still wins.

Session Completion

This protocol applies when ending a Beads implementation workflow. It is subordinate to explicit user, repository, and orchestrator instructions.

  1. File issues for remaining work - Create beads for anything that needs follow-up
  2. Run quality gates (if code changed) - Tests, linters, builds
  3. Update issue status - Close finished work, update in-progress items
  4. Handle git/sync by active profile:
    # Conservative/minimal/default: report status and proposed commands; wait for approval.
    git status
    
    # Team-maintainer opt-in only, unless current instructions forbid it:
    git pull --rebase
    bd dolt push
    git push
    git status
  5. Hand off - Summarize changes, validation, issue status, and any blocked sync/commit/push step

Critical rules:

  • Explicit user or orchestrator instructions override this Beads block.
  • Do not commit or push without clear authority from the active profile or the current user request.
  • If a required sync or push is blocked, stop and report the exact command and error.

Beads Issue Tracker

Use Beads (bd) for durable task tracking in repositories that include it. Use the beads skill at .agents/skills/beads/SKILL.md (project install) or ~/.agents/skills/beads/SKILL.md (global install) for Beads workflow guidance, then use the bd CLI for issue operations.

Quick Reference

bd ready                # Find available work
bd show <id>            # View issue details
bd update <id> --claim  # Claim work
bd close <id>           # Complete work
bd prime                # Refresh Beads context

Rules

  • Use bd for all task tracking; do not create markdown TODO lists.
  • Run bd prime when Beads context is missing or stale. Codex 0.129.0+ can load Beads context automatically through native hooks; use /hooks to inspect or toggle them.
  • Keep persistent project memory in Beads via bd remember; do not create ad hoc memory files.

Architecture in one line: issues live in a local Dolt DB; sync uses refs/dolt/data on your git remote; .beads/issues.jsonl is a passive export. See https://github.com/gastownhall/beads/blob/main/docs/SYNC_CONCEPTS.md for details and anti-patterns.