feat(api): mobile API Milestone 1+2 — Sanctum auth + offline sync vertical slice

Milestone 1 (auth foundation):
- Installed laravel/sanctum; HasApiTokens on User; published config + migration.
- routes/api.php with /api/v1; Sanctum 'ability' middleware alias registered.
- AuthController: POST login (long-lived revocable device token w/ ability
  mobile-sync + devices table), GET me, POST logout. New Device model/table.

Milestone 2 (vertical slice, offline-first):
- progress_updates: +uuid (client-generated) +client_updated_at.
- ProjectApiController: GET projects (accessibleBy), GET projects/{id}/bundle
  (project/phases/layers/features, membership-authorized).
- SyncController: POST sync — batch ops, idempotent by uuid, per-op result
  (applied/duplicate/error), server-set user_id, authz by permission+membership.
  Currently handles progress_update.create.

Tests: tests/Feature/Api/MobileApiTest (9 passing) — auth, accessible projects,
bundle authz, sync apply+idempotency, permission enforcement.

Also fixed a latent schema bug: projects.reference (and external_reference_1)
existed in the live DB but had no migration — added a guarded migration so fresh
installs match production.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-06-18 09:05:20 +02:00
parent ba363e7e18
commit 17a824f925
16 changed files with 794 additions and 8 deletions
@@ -0,0 +1,79 @@
<?php
namespace App\Http\Controllers\Api\V1;
use App\Http\Controllers\Controller;
use App\Models\Project;
use Illuminate\Http\Request;
class ProjectApiController extends Controller
{
/** Projects the authenticated user can access. */
public function index(Request $request)
{
$projects = Project::accessibleBy($request->user())
->orderBy('name')
->get(['id', 'reference', 'name', 'address', 'status', 'lat', 'lng', 'updated_at']);
return response()->json(['projects' => $projects]);
}
/**
* Offline bundle for one project (Milestone 2 minimal: structure, no media yet).
*/
public function bundle(Request $request, Project $project)
{
$user = $request->user();
abort_unless(
$user->can('manage all') || $project->users()->where('user_id', $user->id)->exists(),
403
);
$project->load([
'phases' => fn ($q) => $q->orderBy('order'),
'phases.layers',
'phases.layers.features',
]);
$layers = $project->phases->flatMap->layers;
$features = $layers->flatMap->features;
return response()->json([
'server_time' => now()->toIso8601String(),
'project' => [
'id' => $project->id,
'reference' => $project->reference,
'name' => $project->name,
'address' => $project->address,
'lat' => $project->lat,
'lng' => $project->lng,
'status' => $project->status,
'updated_at' => $project->updated_at?->toIso8601String(),
],
'phases' => $project->phases->map(fn ($p) => [
'id' => $p->id,
'name' => $p->name,
'order' => $p->order,
'color' => $p->color,
'progress_percent' => $p->progress_percent,
'updated_at' => $p->updated_at?->toIso8601String(),
])->values(),
'layers' => $layers->map(fn ($l) => [
'id' => $l->id,
'phase_id' => $l->phase_id,
'name' => $l->name,
'color' => $l->color,
'updated_at' => $l->updated_at?->toIso8601String(),
])->values(),
'features' => $features->map(fn ($f) => [
'id' => $f->id,
'layer_id' => $f->layer_id,
'name' => $f->name,
'geometry' => $f->geometry,
'status' => $f->status,
'progress' => $f->progress,
'updated_at' => $f->updated_at?->toIso8601String(),
])->values(),
]);
}
}