Skip to content

Sync Telescope, Tinker, Wayfinder and Laravel documentation updates - #51

Merged
binaryfire merged 25 commits into
0.4from
upstream-sync-framework-16
Oct 3, 2026
Merged

binaryfire merged 25 commits into
0.4from
upstream-sync-framework-16

Conversation

@binaryfire

@binaryfire binaryfire commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

This brings Telescope up to laravel/telescope 5.x at bedfc50a35, Tinker up to laravel/tinker 3.x at 8f4063c64b and Wayfinder up to laravel/wayfinder main at dd454ed0a7. It also brings the first group of laravel/docs 13.x changes, at 156fc7fde1, into Hypervel's documentation. Porting one of the Wayfinder changes exposed a framework bug: middleware that a provider added to a group during boot was lost once the HTTP kernel was built. That's fixed too.

Upstream Updates

Telescope

  • laravel/telescope pull requests 1763 and 1766 add the telescope:list and telescope:show commands. telescope:list lists recent entries, optionally of one type, filtered by tag, batch or family hash, with --before pagination and JSON output. telescope:show displays one entry and its related batch entries, and accepts a full or shortened UUID, latest or latest:{type}. Telescope doesn't record either command. Hypervel's commands return integer exit codes, throw on JSON encoding errors and show a scheduled task's recorded status, exit code and exception. Upstream has no user documentation for the commands, so the Telescope page gains a section on viewing entries from the command line.
  • A shortened UUID finds the latest entry whose UUID starts with it, ignoring case. On PostgreSQL, looking up a malformed entry ID failed with a query error, because the uuid column can't be compared with it. The dashboard returned a 500 and telescope:show printed a raw SQL error. Malformed IDs now throw ModelNotFoundException, and the lookup is tested on PostgreSQL, MariaDB, MySQL and SQLite.
  • laravel/telescope pull request 1764 cancels a dashboard screen's pending index, preview and polling requests when you leave it, so a slow response from the previous screen can't overwrite the current one. The exception preview also ignores a response for an entry you've already left. The dashboard assets are rebuilt.
  • laravel/telescope pull request 1769 hides set-cookie as well as cookie in the published TelescopeServiceProvider, so cookies issued in responses aren't stored. Response headers use the same hidden list.
  • laravel/telescope pull requests 1752 and 1756 added Telescope::cspNonce() and escaped its value. Hypervel already had both, with the nonce held per coroutine. Its tests move to upstream's CspNonceTest, keeping Hypervel's checks on each style and script tag, the escaped value and coroutine isolation. Upstream's CSP nonce documentation is added to the Telescope page.
  • laravel/telescope pull request 1741 clears the exception and failed tag when a job that another worker already failed is later marked processed. Hypervel already did this, and its test is replaced by upstream's.
  • laravel/telescope pull request 1658 updated the test harness for PHP 8.5. Hypervel's tests already used the new attributes, but its batch watcher test had become a mocked event test. It now runs upstream's batch through the database queue worker, with a processed and a failed job, and checks the batch entry's job counts. The worker gets a 1024MB memory limit, as the other queue worker tests do, because the limit counts the whole test process and the default could stop the worker after the first job.
  • laravel/telescope pull request 1707 disables npm install scripts for the dashboard's build dependencies. Telescope's .npmrc already set a minimum release age, and now disables install scripts too, as Horizon and Workbench do.
  • laravel/telescope pull request 1746 bumped axios. Telescope's axios and moment versions were inside ranges with published security advisories. They now require ^1.20.0 and ^2.31.0, matching Horizon.

Tinker

  • laravel/tinker pull request 214 removes Mockery from the class alias autoloader tests. Each test now gives the loader a real PsySH shell with buffered output, and checks the exact alias message, or no output when a class is excluded.

Wayfinder

  • laravel/wayfinder pull request 303 keys the routes in a multi-route action export by verb and URI, such as 'get /photos' and 'post /photos', when two routes share a URI. Hypervel merged those routes into one entry with combined verbs, and rejected registrations whose parameter metadata differed. It now uses upstream's keys, so each registration keeps its own defaults. A route registered for several verbs joins them with |, and HEAD is dropped when GET is present. The generator test, fixture controller and documentation follow upstream.
  • laravel/wayfinder pull request 317 fixes a barrel importing itself when a route name is both a leaf and a prefix. Hypervel's barrels already imported the right file. Upstream's test and routes replace the fixture route that covered the same case.
  • laravel/wayfinder pull request 295 resolves middleware aliases, groups and global middleware when inferring URL defaults. Hypervel already read route middleware through the router, and now also applies URL defaults from the HTTP kernel's global middleware, with route middleware taking precedence. Upstream's six cases are ported.
  • laravel/wayfinder pull request 252 raises the minimum happy-dom development dependency to the release with its security fixes.

Laravel documentation

This brings Laravel documentation changes made since Hypervel's documentation was imported into a first group of pages. Where Hypervel had its own wording for the same content, upstream's wording replaces it, adapted for Hypervel. Hypervel-only features and intentional differences stay, and each documented behavior was checked against Hypervel's source. The numbers below are laravel/docs pull requests.

  • Validation documents ratio constraints and ratioBetween (11174), uses arrays for every rule definition (11176, 11179) and lists Min among the file rules (11255).
  • Fortify's passkeys section follows upstream's structure (11186): enabling passkeys, the JavaScript client, authenticating, confirming the password, registering and deleting. Hypervel's configuration, callbacks, customization, models and standalone sections stay. Custom clients are told to send an Accept: application/json header, which selects the JSON responses.
  • New documentation for named concurrency results (11202), Number::parse (11217), by-reference reduceInto (11283), Sanctum's remember me support (11211), Echo's useSocketId (11222), the attributed #[Scope] variant's limitations (11229), SIGTERM handling (11208) and --timeout with --once (11287).
  • Image manipulation in the filesystem docs (11264), the disk report option (11367), queue routes for broadcasts and queued listeners (11366), Mercure installation (11379), encrypted private channels (11394), SES tenants (commit 68f903aca7) and the migration events table (11244, 11393).
  • Corrections: polymorphic _type columns before _id (11188), app.js instead of the removed bootstrap.js (11199), no beta notice for automatic eager loading (11317), crossJoin combinations (11321) and the duplicate notifications testing anchor (11291).
  • Table of contents entries and labels (11335, 11341, 11353, commits b0fbeae094 and a52b24e4db), code block languages (11337), the groupByRaw heading (11336), table overflow wrappers (11248) and the Mailgun regions link (11250).
  • Wording and spelling (11253, 11258, 11260, 11304, 11360, 11362, commit 4350436469).
  • Code example syntax, signatures and outputs (11364, 11384, 11391), and descriptions that didn't match framework behavior (11387, 11392, 11393).

Pull requests 11364, 11387, 11392 and 11393 and commit a52b24e4db also change pages that aren't reconciled yet. Those pages will be updated separately.

Additional Hypervel Fixes

  • Building the HTTP kernel writes its middleware groups and aliases onto the router, replacing existing entries. Laravel builds the kernel before bootstrapping, but Hypervel first built it after providers booted: at server start, in route:list and in Wayfinder. Middleware a provider pushed onto a group during boot, or an alias it replaced, was lost. Application::boot() now builds the bound HTTP kernel before providers boot, and the separate builds in route:list, Wayfinder and the route middleware testing concern are removed. Tests cover the boot order, and a provider's group and alias changes surviving a real request with the default and a custom kernel.
  • Telescope stored a scheduled task's DateTimeZone as a JSON object with its internal fields. The dashboard displayed that object, and telescope:show failed rendering it. Telescope now records the timezone name. Upstream has the same bug.
  • Telescope's exception code preview starts ten lines before the exception. For an exception on lines 1 to 9, that offset was negative, so the preview showed the file's last lines instead. It now starts at the first line. Upstream has the same bug.
  • Telescope stored closure middleware as an empty JSON object, so the dashboard showed a blank item and telescope:show failed. Closures are now recorded as Closure, as closure routes already appear in the controller action. Upstream has the same bug.
  • Opening a Telescope entry that no longer exists showed a permanent "stopped listening for new entries" alert above the not found card, and when you moved to another entry that failed to load, the previous entry stayed on screen. Only polling of a loaded entry now retries or reports that it stopped, and the preview clears the previous entry when the ID changes. Leaving the monitoring screen while it loads no longer causes an unhandled promise rejection. Upstream has the same bugs.
  • telescope:list and telescope:show printed recorded data through the console formatter, which strips text that looks like a console style tag, such as <info>, and drops a backslash before < or >. SQL, messages, code lines and response bodies could show different text from what was recorded, and --json output could become invalid JSON. JSON output and content blocks are now written raw, and recorded text in styled lines and tables is escaped. telescope:list also validates --before, which caused a SQL error on PostgreSQL and returned the wrong page on MySQL and SQLite. Upstream has the same bugs.
  • Other commands wrote data they don't control through the same formatter. The concurrency process driver's failure envelope could become unreadable to the parent process. queue:work --json altered exception messages, and dropped the failed-job line entirely when a message contained invalid UTF-8. The JSON output of db:show, db:table, model:show, dev:list and schedule:list could change or break on table comments, defaults and shell commands. These commands now write raw JSON, and the database commands escape comments and defaults in their text output. Laravel writes these the same way.
  • Telescope's README now lists its differences from Laravel. Recording state, the recorded entries and updates, and the CSP nonce are held per coroutine, so the static $shouldRecord, $entriesQueue, $updatesQueue and $nonceAttribute properties are replaced by isRecording(), getEntriesQueue() and getUpdatesQueue(). Telescope::store() waits for the current coroutine to finish unless telescope.defer is false.
  • The Permission README repeated the documentation's features and installation steps. It now follows the standard package layout, with its differences from Spatie Laravel Permission linking to the documentation. Two entries are removed: the cache store failing fast is a fix rather than a difference, so the documentation's own list drops it too, and Spatie's models don't use soft deletes either.
  • A queues documentation link to scoping named rate limiters pointed at a missing routing anchor, and now points to the rate limiting documentation. The authentication docs also note that Hypervel's Passport port is coming soon.
  • The Telescope CSP example passed a fixed nonce and sent no policy header. It now generates a nonce for each request and sends the matching Content-Security-Policy header, as the Horizon docs do. The migration events table now says DatabaseRefreshed fires before any seeders run.
  • The upstream sync registry records the Reverb, Scout, Telescope and Tinker checkpoints. It also gains notes for later syncs: Scout's checkpoint doesn't cover its Laravel AI SDK integrations, Telescope's assets need npm 11.10 or newer to rebuild, Wayfinder stays on main until Wayfinder v1, and how Laravel documentation changes are reconciled.

The changed tests, the Telescope, Tinker, Testbench, Database, Console, Queue, Concurrency and Horizon suites, the Wayfinder PHP and JavaScript suites with and without cached routes, the Wayfinder type check, formatting and static analysis pass locally. The Telescope dashboard builds with install scripts disabled, and every internal documentation link and anchor resolves. The full suite also ran locally, and its one failure was the batch watcher test's memory limit, fixed above.


Summary by cubic

Brings Hypervel's Telescope, Tinker, Wayfinder and first group of Laravel documentation pages up to date with their upstream counterparts, and fixes a framework ordering bug this exposed: middleware and aliases a provider applied to the router during boot were lost once the HTTP kernel was built.

Upstream Updates

  • Telescope gains telescope:list and telescope:show, cancels dashboard requests when leaving a screen, hides set-cookie headers, and rebuilds its assets with updated axios and moment; malformed UUID lookups now throw ModelNotFoundException.
  • Wayfinder keys multi-route action exports by verb and URI instead of merging them, applies URL defaults from global middleware, and fixes a barrel self-import when a route name is both a leaf and a prefix.
  • Tinker's class alias autoloader tests use a real PsySH shell instead of mocks.
  • The first group of laravel/docs changes is reconciled across the documentation pages, with Hypervel-only content kept.
  • Telescope also fixes upstream defects: scheduled task timezones record the name, exception previews start at the first line for near-top exceptions, and closure middleware is stored as Closure.

Hypervel Fixes

  • Application::boot() now resolves the HTTP kernel before providers boot, so provider middleware group and alias changes survive real requests; the separate builds in route:list, Wayfinder and the route middleware test concern are removed.
  • Command JSON output is written raw so console formatting no longer strips style tags or drops backslashes from recorded data, in telescope:list, telescope:show, db:show, db:table, model:show, dev:list, schedule:list and the concurrency process driver's envelope; queue:work --json substitutes invalid UTF-8 instead of failing. Database text output escapes comments and defaults.
  • Telescope's dashboard clears stale entries when a preview fails to load, only reports polling failures for loaded entries, and ignores aborted monitoring requests; telescope:list also validates its --before cursor.
  • Telescope and Permission READMEs now document their differences from Laravel.

Written for commit 2217eae. Summary will update on new commits.

Review in cubic

Note

Add telescope:list and telescope:show CLI commands and sync Telescope, Tinker, Wayfinder docs

  • Adds telescope:list and telescope:show console commands with filtering by type, tag, batch, and cursor, plus JSON output; registered in TelescopeServiceProvider and supported by a shared FormatsOutput trait
  • Entries repository find now accepts string UUIDs and resolves shortened UUID prefixes; closure middleware and DateTimeZone values serialize correctly in request and schedule entries
  • Application boot now resolves the HTTP kernel centrally in Application.boot, replacing per-command and test-trait kernel resolution; Wayfinder GenerateCommand collects URL defaults from global middleware and keys shared-URI routes by verb
  • Console JSON output across schedule, database, model, table, and concurrency commands now bypasses Symfony formatting so shell commands and markup survive verbatim
  • Documentation updates cover Telescope CLI viewing, CSP nonces, broadcasting, Fortify passkeys, validation arrays, Wayfinder multi-verb routes, and many smaller corrections
  • Risk: EntriesRepository::find parameter narrowed from mixed to string; malformed identifiers now raise ModelNotFoundException immediately, and generated Wayfinder route dictionaries use verb-prefixed keys for duplicate URIs

Macroscope summarized 2217eae.

laravel/telescope #1658 updated the test harness for PHP 8.5. Hypervel
already uses #[WithConfig], #[DataProvider] and defineEnvironment(), so
the remaining difference was BatchWatcherTest, which had diverged into
a mocked BatchDispatched event test.

The test now runs upstream's batch through the database queue worker:
a processed and a failed job, then the batch entry with its job counts.
The worker runs each job in its own coroutine, so the test stores the
dispatch-time entries first, as the dispatching request would, for the
job updates to apply. It keeps Hypervel's batch UUID, connection and
allowsFailures assertions, and the job fixtures are fully typed.

Upstream reference: laravel/telescope 5.x at bedfc50a35.

Validation: BatchWatcherTest and the Telescope suite pass.
laravel/telescope #1707 added an .npmrc with ignore-scripts=true, so
installing the dashboard's build dependencies cannot run package
install scripts. Telescope's .npmrc already set Hypervel's seven-day
min-release-age; it now disables install scripts too, as Horizon and
Workbench do. The dashboard build succeeds with scripts disabled.

Upstream reference: laravel/telescope 5.x at bedfc50a35.
laravel/telescope #1741 clears the exception and failed tag when a job
that another worker already failed is later marked processed. Hypervel's
JobWatcher already did this, and its own test covered the same case.
That test is replaced by upstream's, under its name and position: a
second reservation fails the job with MaxAttemptsExceededException
while the original worker completes it, and the stored entry must end
up processed with no exception or failed tag.

Upstream reference: laravel/telescope 5.x at bedfc50a35.

Validation: JobWatcherTest and the Telescope suite pass.
laravel/telescope #1746 bumped axios. Telescope was on axios 1.19.0
and moment 2.30.1, both inside ranges with published security
advisories, as upstream's lock still is. They now require ^1.20.0 and
^2.31.0, matching Horizon. The dashboard bundle is rebuilt with them in
the following asset commit.

The remaining npm audit reports are for the vite and esbuild
development servers and nanoid, which the production build does not
use in an affected way, and Vue 2, which has no fixed release.

Upstream reference: laravel/telescope 5.x at bedfc50a35.
laravel/telescope #1752 added Telescope::cspNonce(), with #1756
escaping the attribute value. Hypervel already had both, with the
nonce held per coroutine, and CspTest covered them. The tests move to
upstream's CspNonceTest: upstream's tests render the dashboard page,
and keep Hypervel's assertions on each style and script tag, the
escaped attribute value and the coroutine isolation of the nonce.
Upstream's nonce documentation is added with the next documentation
change to the Telescope page.

Upstream reference: laravel/telescope 5.x at bedfc50a35.

Validation: CspNonceTest and the Telescope suite pass.
Ports laravel/telescope #1763 and #1766 together, because #1766
changes how telescope:show finds entries and extends its tests.

telescope:list lists recent entries, optionally of one type, filtered
by tag, batch or family hash, with --before pagination and JSON
output. telescope:show displays one entry and its related batch
entries, accepting a full or shortened UUID, latest or latest:{type}.
Both run without recording themselves and are on the ignored-command
list. EntryType::all() lists the types, including Hypervel's Reverb
type.

Hypervel adaptations: the commands return integer exit codes, JSON
output throws on encoding errors, the exception code context marks the
failing line with a strict comparison, and scheduled-task entries show
Hypervel's recorded status, exit code and exception.

DatabaseEntriesRepository::find() resolves a shortened UUID to the
latest matching entry with a case-insensitive prefix match and loads
tags by the resolved UUID. It takes a string, as the contract now
declares. A defect is also fixed: on PostgreSQL, comparing the uuid
column with a malformed ID raised a query error, so the dashboard
returned a 500 and telescope:show printed a raw SQL error. Malformed
IDs now throw ModelNotFoundException. QueueBatchesControllerTest uses
real UUIDs for its batch IDs, as the batch repository generates.

Upstream has no user documentation for the commands; the Telescope
page gains a section on viewing entries from the command line. The
page also gains upstream's CSP nonce documentation from #1752,
adapted to Hypervel's imports. Upstream's Boost skill for the commands
is excluded under the global Boost exclusion.

Upstream reference: laravel/telescope 5.x at bedfc50a35; docs 13.x
at faaa1c9db7.

Validation: ListCommandTest, ShowCommandTest, TelescopeTest and
QueueBatchesControllerTest pass, and the entry lookup test passes on
PostgreSQL 17, MariaDB 11.8, MySQL 8.4 and SQLite. Formatting, PHPStan
and the Telescope suite pass.
Ports laravel/telescope #1764. Leaving a dashboard screen now cancels
its pending index, preview and polling requests, so a slow response
from the previous screen can no longer overwrite the current one. The
exception preview also ignores a response for an entry the user has
already navigated away from.

The base, index-screen, preview-screen, dumps and monitoring sources
match upstream; the exception preview guard is applied to Hypervel's
version of that screen. The bundle is rebuilt with the updated axios
and moment dependencies.

Upstream reference: laravel/telescope 5.x at bedfc50a35.

Validation: npm ci and the production build succeed with install
scripts disabled.
Ports laravel/telescope #1769. The published TelescopeServiceProvider
now hides set-cookie alongside cookie, so session and other cookies
issued in responses are not stored. Telescope applies the same hidden
header list to response headers.

Upstream reference: laravel/telescope 5.x at bedfc50a35.
Scheduled tasks accept a DateTimeZone as well as a timezone name.
ScheduleWatcher stored the object as is, so it was encoded as a JSON
object with its internal fields. The dashboard displayed that object,
and telescope:show failed when rendering it. The watcher now records
the timezone name. Upstream Telescope has the same defect.

Validation: ScheduleWatcherTest and the Telescope suite pass.
Telescope's exception code preview starts ten lines before the
exception's line. For an exception on lines 1 to 9, that offset was
negative, so the collection slice counted from the end of the file and
the dashboard and telescope:show previewed the file's last lines
instead. The offset now starts at zero, previewing the first twenty
lines. Upstream Telescope has the same defect.

Validation: ExceptionWatcherTest and the Telescope suite pass.
Controllers may define middleware as closures. RequestWatcher stored
the route's middleware list as is, so each closure was encoded as an
empty JSON object: the dashboard showed a blank item, and
telescope:show failed converting it to a string. Closures are now
recorded as "Closure", as closure routes already appear in the
controller action. Upstream Telescope has the same defect.

Validation: RequestWatchersTest and the Telescope suite pass.
Telescope's README had no differences section, although parts of its
public behavior differ in ways that matter when porting Laravel code.
Recording state, the recorded entries and updates, and the CSP nonce
are held per coroutine, so the static $shouldRecord, $entriesQueue,
$updatesQueue and $nonceAttribute properties are replaced by
isRecording(), getEntriesQueue() and getUpdatesQueue(). Telescope::store()
waits for the current coroutine to finish unless telescope.defer is
false. Each entry links to the relevant documentation.
laravel/tinker #214 removes Mockery from the class alias autoloader
tests. Instead of mocking the shell's writeStdout() call, each test now
gives the loader a real PsySH shell writing to a buffered output and
asserts the exact alias message, or no output when a class is excluded.

The vendor-exclusion test keeps calling aliasClass() directly. PHP class
aliases last for the whole process, so class_exists() could already be
satisfied by the whitelisting test. The package's composer.json has no
Mockery requirement to remove.

Upstream reference: laravel/tinker 3.x at 8f4063c64b.

Validation: the Tinker suite passes.
laravel/reverb is reviewed through
74c8c4082c07f428d6399cc2f9bc5c6fd1cb1179, up to PR 410.
laravel/scout is reviewed through
ce2542f5a7297d21975ddcd7115dbf798fd8ba00, up to PR 1012.
laravel/telescope is reviewed through
bedfc50a3561c93cd89064643139a51c56bfd8a6, up to PR 1769.
laravel/tinker is reviewed through
8f4063c64bb5a39c2ae46d400995ce7d28a2e593, up to PR 214.

Every upstream change in those ranges is ported, already present, or
does not apply to Hypervel, except Scout's Laravel AI SDK integrations
from PRs 1007, 1008, 1009 and 1012. Those wait for Hypervel's AI SDK, so
the Scout entry gains a note saying the checkpoint does not cover them.

The Telescope entry gains a note for later syncs: rebuild its dist with
npm 11.10 or newer after resource or frontend dependency changes.
Wayfinder development continues on its next branch, which rebuilds
generation on laravel/ranger and laravel/surveyor and extends it to
models, enums, form requests, Inertia page data, broadcasting and Vite
environment variables. The registry now tracks that branch; its
checkpoint stays unset until the port lands.

The Laravel docs entry gains a note for later syncs: reconcile upstream
changes with existing Hypervel documentation, including independently
written pages, use upstream wording for equivalent content adapted for
Hypervel, keep Hypervel enhancements and intentional differences, and
avoid duplicate coverage.
This replaces the previous commit's switch to next. Wayfinder's next
branch rebuilds generation on laravel/surveyor, laravel/ranger and
spatie/php-structure-discoverer, which Hypervel would need to port as
new packages. That rewrite waits for Wayfinder v1, so the registry keeps
tracking main for applicable fixes.

The entry's note records the deferral: each Wayfinder sync checks
whether v1 has been released, and changing the tracked branch or
starting the dependency ports needs approval first.
laravel/wayfinder #252 raises the happy-dom development dependency to
the release with its security fixes. The lockfile already resolves a
newer 20.x release, so only the specifier changes.

Upstream reference: laravel/wayfinder main at dd454ed0a7.

Validation: the Wayfinder JavaScript suite and type check pass.
laravel/wayfinder #303 keys the routes in a multi-route action export
by verb and URI (for example 'get /photos' and 'post /photos') when two
routes share a URI. Hypervel previously merged such routes into one
entry with combined verbs and rejected registrations whose parameter
metadata differed. That merge is replaced with upstream's keys, so each
registration keeps its own defaults. A route registered for several
verbs joins them with '|', and HEAD is dropped when GET is present. The
generator test, fixture controller and documentation follow upstream.

laravel/wayfinder #317 fixes a barrel importing itself when a route
name is both a leaf and a prefix. Hypervel's barrel code already imports
'./index/index'; its upstream test and routes are ported, replacing the
duplicate fixture route that covered the same case.

laravel/wayfinder #295 resolves middleware aliases, kernel groups and
global middleware when inferring URL defaults. Hypervel already reads
route middleware through the router, so it adds the global middleware
defaults from the HTTP kernel, with route middleware defaults taking
precedence. Upstream's six cases are ported as MiddlewareUrlDefaultsTest.

Porting #295 exposed a framework ordering bug. Constructing the HTTP
kernel writes its middleware groups and aliases onto the router,
replacing existing entries. Laravel builds the kernel before
bootstrapping, but Hypervel first resolved it after providers booted
(at server start, in route:list and in Wayfinder), so middleware a
provider pushed onto a group, or an alias it replaced, during boot was
lost. Application::boot() now resolves the bound HTTP kernel before the
booting callbacks run, and the separate resolutions in route:list,
Wayfinder and the route middleware testing concern are removed. Tests
cover the boot order and a provider's group and alias changes surviving
a real request, with the default and a custom kernel. Tests that
configure the kernel now do so before the application boots.

Upstream reference: laravel/wayfinder main at dd454ed0a7.

Validation: lint and static analysis pass, as do the Wayfinder PHP and
JavaScript suites (with and without cached routes), the Wayfinder type
check and the Testbench suite. The full parallel suite's only failure
was a Telescope queue worker test, fixed separately.
The batch watcher test runs queue:work in the test process. The worker
stops once memory use passes its limit, 128MB by default, and that
measures the whole long-running test process. Under the parallel suite
it could stop after the first job, leaving the failing job pending.

The test now passes --memory=1024, as the other queue worker tests do.

Validation: the test fails the same way with --memory=1 and passes with
the new limit.
Reconciles laravel/docs 13.x changes since April 22, 2026 with
Hypervel's documentation for these pages. Where Hypervel had its own
wording for the same content, upstream's wording replaces it, adapted
for Hypervel. Hypervel-only features and intentional differences stay.
Each documented behavior was checked against Hypervel's source.

Feature documentation:

- Validation ratio constraints and ratioBetween (#11174), arrays for
  all rule definitions (#11176, #11179) and Min in the file rules list
  (#11255).
- Fortify passkeys (#11186). Hypervel's passkeys section follows
  upstream's structure (enabling, JavaScript client, authenticating,
  confirming the password, registering and deleting), keeping
  Hypervel's configuration, callbacks, customization, models and
  standalone sections. Custom clients are told to send an
  Accept: application/json header, which selects the JSON responses.
- Concurrency named results (#11202), Number::parse (#11217),
  by-reference reduceInto (#11283), Sanctum remember me (#11211), Echo's
  useSocketId (#11222), attributed scope limits (#11229), SIGTERM
  handling (#11208) and --timeout with --once (#11287).
- Image manipulation in the filesystem docs (#11264), the disk report
  option (#11367), queue routes for broadcasts and queued listeners
  (#11366), Mercure installation (#11379), encrypted private channels
  (#11394), SES tenants (direct 68f903aca7) and the migration events
  table (#11244, #11393).

Corrections:

- Polymorphic _type columns before _id (#11188), app.js instead of the
  removed bootstrap.js (#11199), the automatic eager loading beta
  notice (#11317), crossJoin combinations (#11321) and the duplicate
  notifications testing anchor (#11291).
- Table of contents entries and labels (#11335, #11341, #11353, direct
  b0fbeae094, direct a52b24e4db), code block languages (#11337), the
  groupByRaw heading (#11336), table overflow wrappers (#11248) and the
  Mailgun regions link (#11250).
- Wording and spelling (#11253, #11258, #11260, #11304, #11360, #11362,
  direct 4350436469).
- Code example syntax, signatures and outputs (#11364, #11384, #11391)
  and descriptions that did not match framework behavior (#11387,
  #11392, #11393).

#11364, #11387, #11392 and #11393 also change pages not yet reconciled;
those pages follow separately.

Also fixes a queues.md link to the rate limiting docs' named limiter
scoping section, which pointed at a missing routing anchor, and notes
in the authentication docs that Hypervel's Passport port is coming.

Upstream reference: laravel/docs 13.x at 156fc7fde1.

Validation: every internal link and anchor in src/docs resolves.
The README repeated the documentation's features and installation
steps, put the upstream link first and pointed at the docs source file
instead of the published page. It now has the standard header, the
documentation link, the differences from Spatie Laravel Permission and
the upstream link.

The differences list keeps the public contract differences (denied
permissions, unit enums, row partitioning and the cache configuration)
and links to their documentation instead of repeating it. Two entries
are removed: the cache store failing fast is a correctness fix rather
than a contract difference, and Spatie's models do not use soft deletes
either. The documentation's own differences list drops the same cache
store entry.
@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: hypervel/components-backup/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: af5a1dbd-7aa3-44f5-954d-33fae58320d1

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Sync Telescope, Tinker, Wayfinder, and Laravel documentation

✨ Enhancement 🐞 Bug fix 📝 Documentation 🧪 Tests ⚙️ Configuration changes 🕐 40+ Minutes

Grey Divider

AI Description

• Add Telescope entry commands and synchronize dashboard, watcher, and security updates.
• Preserve provider-configured middleware and generate distinct Wayfinder routes for shared URIs.
• Reconcile Laravel documentation with Hypervel behavior and expand cross-package regression
 coverage.
Diagram

graph TD
  App["Application boot"] --> Kernel["HTTP kernel"] --> Router["Middleware router"] --> Wayfinder["Wayfinder generator"] --> Routes["TypeScript routes"]
  Commands["Telescope commands"] --> Entries["Entries repository"]
  Dashboard["Telescope dashboard"] --> Entries
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Merge kernel middleware after provider boot
  • ➕ Could avoid constructing the HTTP kernel during application boot.
  • ➖ Requires conflict and ordering rules for groups and aliases.
  • ➖ Leaves separate server, console, and generator initialization paths to coordinate.
2. Coalesce Wayfinder routes sharing a URI
  • ➕ Preserves a single URI-only export key.
  • ➖ Loses each registration's defaults and method metadata.
  • ➖ Cannot represent conflicting parameter metadata faithfully.

Recommendation: Keep the PR's approach. Resolving the bound kernel before providers boot removes the middleware overwrite at its source, while verb-prefixed keys preserve separate Wayfinder registrations. The alternatives introduce synchronization rules or discard route information.

Files changed (92) +3363 / -654

Enhancement (10) +1117 / -149
app.jsPublish rebuilt Telescope dashboard bundle +59/-58

Publish rebuilt Telescope dashboard bundle

• Updates the distributed asset to incorporate dashboard request-cancellation changes and refreshed frontend dependencies.

src/telescope/dist/app.js

FormatsOutput.phpShare Telescope command formatting +158/-0

Share Telescope command formatting

• Introduces entry-type validation, summaries, JSON encoding, timestamps, units, and colored status formatting for the new commands.

src/telescope/src/Console/Concerns/FormatsOutput.php

ListCommand.phpAdd telescope:list for recorded entries +208/-0

Add telescope:list for recorded entries

• Lists entries by type with tag, batch, family, limit, and cursor filters. Supports human-readable tables, JSON, and failure codes.

src/telescope/src/Console/ListCommand.php

ShowCommand.phpAdd telescope:show with batch context +566/-0

Add telescope:show with batch context

• Displays full, shortened, or latest entry IDs with type-aware detail and related batch entries. Supports filtering, untruncated output, JSON, and useful errors.

src/telescope/src/Console/ShowCommand.php

EntryType.phpExpose the supported Telescope entry types +30/-0

Expose the supported Telescope entry types

• Adds an all method used to validate command entry-type arguments.

src/telescope/src/EntryType.php

Telescope.phpExclude inspection commands from recording +2/-0

Exclude inspection commands from recording

• Adds telescope:list and telescope:show to commands that Telescope does not record.

src/telescope/src/Telescope.php

TelescopeServiceProvider.phpRegister Telescope inspection commands +2/-0

Register Telescope inspection commands

• Makes the list and show commands available through Telescope's service provider.

src/telescope/src/TelescopeServiceProvider.php

multi-method.blade.tsRender distinct keys for shared-URI actions +4/-3

Render distinct keys for shared-URI actions

• Uses generated route keys in action dictionaries and explains verb prefixes where routes share a URI.

src/wayfinder/resources/multi-method.blade.ts

GenerateCommand.phpPreserve individual routes and infer global URL defaults +39/-67

Preserve individual routes and infer global URL defaults

• Generates separate entries for routes sharing a URI rather than merging metadata. Reads global middleware defaults from the kernel and lets route defaults take precedence.

src/wayfinder/src/GenerateCommand.php

Route.phpProvide verb-prefixed route identifiers +49/-21

Provide verb-prefixed route identifiers

• Extracts raw URI construction for reuse in route keys and joins identifying verbs, omitting HEAD when GET is present.

src/wayfinder/src/Route.php

Bug fix (14) +177 / -52
Application.phpInitialize the bound HTTP kernel before providers boot +8/-0

Initialize the bound HTTP kernel before providers boot

• Resolves the bound kernel before boot callbacks so its router middleware installation cannot erase provider changes.

src/foundation/src/Application.php

RouteListCommand.phpStop rebuilding middleware during route listing +0/-5

Stop rebuilding middleware during route listing

• Removes command-local kernel resolution now that application boot initializes it.

src/foundation/src/Console/RouteListCommand.php

InteractsWithRouteMiddleware.phpUse boot-initialized middleware in route assertions +0/-4

Use boot-initialized middleware in route assertions

• Removes redundant kernel resolution from the route middleware testing concern.

src/foundation/src/Testing/Concerns/InteractsWithRouteMiddleware.php

base.jsCentralize dashboard polling retry decisions +20/-0

Centralize dashboard polling retry decisions

• Adds a helper that stops retries after HTTP responses or cancellation while allowing transient connection failures to retry.

src/telescope/resources/js/base.js

IndexScreen.vueCancel stale Telescope index and job requests +60/-27

Cancel stale Telescope index and job requests

• Aborts index and polling requests when filters change or the screen closes. Resets loading state and prevents outdated responses from replacing current entries.

src/telescope/resources/js/components/IndexScreen.vue

PreviewScreen.vueCancel obsolete entry previews and polls +22/-5

Cancel obsolete entry previews and polls

• Aborts prior preview requests and timers when the entry changes or the screen closes, and avoids duplicate ready watchers.

src/telescope/resources/js/components/PreviewScreen.vue

index.vueCancel abandoned dump requests +23/-3

Cancel abandoned dump requests

• Aborts dump loading and polling on screen destruction and applies the shared retry policy.

src/telescope/resources/js/screens/dumps/index.vue

preview.vueIgnore late exception-resolution responses +2/-0

Ignore late exception-resolution responses

• Only applies a resolved-entry response when the user is still viewing that exception.

src/telescope/resources/js/screens/exceptions/preview.vue

index.vueAbort monitoring requests on navigation +15/-2

Abort monitoring requests on navigation

• Cancels the pending monitored-tags request when its screen is destroyed.

src/telescope/resources/js/screens/monitoring/index.vue

ExceptionContext.phpClamp exception previews to the file start +2/-1

Clamp exception previews to the file start

• Prevents exceptions near the top of a file from producing a negative slice offset and displaying its final lines.

src/telescope/src/ExceptionContext.php

DatabaseEntriesRepository.phpFind UUIDs and latest matching prefixes safely +16/-3

Find UUIDs and latest matching prefixes safely

• Supports case-insensitive hexadecimal UUID prefixes and returns the newest match. Rejects malformed IDs with ModelNotFoundException instead of invalid PostgreSQL UUID comparisons.

src/telescope/src/Storage/DatabaseEntriesRepository.php

RequestWatcher.phpRecord closure middleware as readable text +6/-1

Record closure middleware as readable text

• Serializes route closure middleware as Closure instead of an empty object that breaks CLI display.

src/telescope/src/Watchers/RequestWatcher.php

ScheduleWatcher.phpStore scheduled-task timezone names +2/-1

Store scheduled-task timezone names

• Converts DateTimeZone values to names so dashboard and console output can display them.

src/telescope/src/Watchers/ScheduleWatcher.php

TelescopeServiceProvider.stubHide response cookie headers in published configuration +1/-0

Hide response cookie headers in published configuration

• Adds set-cookie to the published service provider's hidden-header list.

src/telescope/stubs/TelescopeServiceProvider.stub

Refactor (1) +1 / -1
EntriesRepository.phpSpecify string entry identifiers +1/-1

Specify string entry identifiers

• Narrows the repository find contract to the string IDs used by the dashboard and CLI.

src/telescope/src/Contracts/EntriesRepository.php

Tests (26) +1421 / -116
IdentifierCollisions.test.tsAlign barrel collision checks with new fixtures +3/-5

Align barrel collision checks with new fixtures

• Moves the explicit namespace-import assertion to the albums fixture and removes redundant reports-route coverage.

src/wayfinder/tests/IdentifierCollisions.test.ts

IndexNamedRoute.test.tsTest named-route leaf and prefix collisions +12/-0

Test named-route leaf and prefix collisions

• Checks generated barrels when index is both a route and namespace, or only a namespace.

src/wayfinder/tests/IndexNamedRoute.test.ts

SharedUriController.test.tsTest verb-prefixed action exports +28/-0

Test verb-prefixed action exports

• Exercises generated GET, POST, and combined PUT/PATCH keys for routes sharing one controller and URI.

src/wayfinder/tests/SharedUriController.test.ts

TwoRoutesSameAction.test.tsTest separate shared-action registrations +7/-5

Test separate shared-action registrations

• Replaces the coalesced-verbs expectation with independent GET and POST export assertions.

src/wayfinder/tests/TwoRoutesSameAction.test.ts

RouteListCommandMiddlewareTest.phpTest route listing with boot-initialized middleware +20/-14

Test route listing with boot-initialized middleware

• Moves kernel configuration to environment setup and verifies listing and subsequent requests retain the configured group and alias.

tests/Foundation/Console/RouteListCommandMiddlewareTest.php

RouteListCommandTest.phpAdjust route-list test kernel registrations +3/-4

Adjust route-list test kernel registrations

• Registers test kernels by concrete class after removing the command's explicit contract resolution.

tests/Foundation/Console/RouteListCommandTest.php

FoundationApplicationTest.phpVerify kernel initialization precedes boot callbacks +20/-0

Verify kernel initialization precedes boot callbacks

• Asserts that application boot resolves a bound HTTP kernel before executing booting callbacks.

tests/Foundation/FoundationApplicationTest.php

KernelProviderMiddlewareTest.phpTest provider middleware changes on real requests +102/-0

Test provider middleware changes on real requests

• Verifies provider-added group middleware and a replaced alias survive kernel construction with default and custom kernels.

tests/Foundation/Http/KernelProviderMiddlewareTest.php

TelescopeMigrationTestCase.phpTest UUID lookup across database backends +38/-0

Test UUID lookup across database backends

• Checks full and uppercase prefix lookups, newest-match selection, associated tags, and malformed-ID rejection in the shared database integration test.

tests/Integration/Telescope/Database/TelescopeMigrationTestCase.php

CreatesTelescopeEntries.phpProvide Telescope command entry fixtures +56/-0

Provide Telescope command entry fixtures

• Adds shared builders for request, query, exception, and other persisted entries.

tests/Telescope/Console/CreatesTelescopeEntries.php

ListCommandTest.phpCover Telescope listing options and output +146/-0

Cover Telescope listing options and output

• Tests filtering, pagination, limit validation, mixed entries, empty results, and JSON output.

tests/Telescope/Console/ListCommandTest.php

ShowCommandTest.phpCover Telescope entry and batch inspection +402/-0

Cover Telescope entry and batch inspection

• Tests UUID shortcuts, type-aware rendering, batch summaries and filters, full and JSON modes, invalid types, and missing entries.

tests/Telescope/Console/ShowCommandTest.php

CspNonceTest.phpConsolidate CSP nonce coverage +86/-0

Consolidate CSP nonce coverage

• Tests nonce rendering and escaping on style and script tags and isolation between concurrent coroutines, replacing the older CSP test.

tests/Telescope/Http/CspNonceTest.php

QueueBatchesControllerTest.phpUse valid UUIDs in deleted-batch coverage +7/-4

Use valid UUIDs in deleted-batch coverage

• Replaces placeholder entry IDs with UUIDs to satisfy validated repository lookups.

tests/Telescope/Http/QueueBatchesControllerTest.php

TelescopeTest.phpVerify inspection commands are ignored +2/-0

Verify inspection commands are ignored

• Adds telescope:list and telescope:show to ignored-command test cases.

tests/Telescope/Telescope/TelescopeTest.php

BatchWatcherTest.phpExercise batch watching through a real queue worker +96/-24

Exercise batch watching through a real queue worker

• Replaces a mocked dispatch with a database batch containing processed and failed jobs. Checks persisted job and batch counts and raises the worker memory limit.

tests/Telescope/Watchers/BatchWatcherTest.php

ExceptionWatcherTest.phpRegress exception previews near line one +27/-0

Regress exception previews near line one

• Checks that an exception near the beginning of a source file records its first twenty lines, not the end of the file.

tests/Telescope/Watchers/ExceptionWatcherTest.php

JobWatcherTest.phpTest duplicate-reservation failure cleanup +43/-21

Test duplicate-reservation failure cleanup

• Replaces the prior stale-failure test with a failed-then-processed reservation scenario and checks status, exception, and failed tag.

tests/Telescope/Watchers/JobWatcherTest.php

RequestWatchersTest.phpTest closure middleware recording +34/-0

Test closure middleware recording

• Makes a request through controller closure middleware and verifies Telescope stores a readable Closure marker.

tests/Telescope/Watchers/RequestWatchersTest.php

ScheduleWatcherTest.phpTest timezone object serialization +12/-0

Test timezone object serialization

• Verifies a scheduled task using DateTimeZone records its timezone name.

tests/Telescope/Watchers/ScheduleWatcherTest.php

ClassAliasAutoloaderTest.phpAssert Tinker alias messages with a real PsySH shell +22/-22

Assert Tinker alias messages with a real PsySH shell

• Replaces mocked shells with buffered output, checking exact alias notices and silence for excluded classes.

tests/Tinker/ClassAliasAutoloaderTest.php

SharedUriController.phpAdd a shared-URI action fixture +15/-0

Add a shared-URI action fixture

• Provides an invokable controller for routes registered under multiple verbs with one URI.

tests/Wayfinder/Fixtures/Controllers/SharedUriController.php

GlobalUrlDefaultsMiddleware.phpAdd a global URL defaults fixture +25/-0

Add a global URL defaults fixture

• Provides global middleware assigning a locale default for precedence tests.

tests/Wayfinder/Fixtures/Middleware/GlobalUrlDefaultsMiddleware.php

routes.phpAdd shared-URI and index-name route fixtures +10/-1

Add shared-URI and index-name route fixtures

• Registers GET, POST, and multi-verb routes for one controller and route names that exercise index barrel generation.

tests/Wayfinder/Fixtures/routes.php

GenerateCommandTest.phpTest independent defaults for shared-URI routes +41/-16

Test independent defaults for shared-URI routes

• Replaces the rejection expectation with assertions that each verb keeps its middleware-derived default. Configures parameterized middleware before boot.

tests/Wayfinder/GenerateCommandTest.php

MiddlewareUrlDefaultsTest.phpCover middleware-derived Wayfinder URL defaults +164/-0

Cover middleware-derived Wayfinder URL defaults

• Tests aliases, kernel groups, global middleware, provider-style group additions, exclusions, and route-over-global precedence.

tests/Wayfinder/MiddlewareUrlDefaultsTest.php

Documentation (36) +626 / -319
artisan.mdClarify Artisan wording and signal handling +3/-3

Clarify Artisan wording and signal handling

• Refines command guidance and describes SIGTERM as a graceful-termination request.

src/docs/artisan.md

authentication.mdClarify Passport availability +4/-1

Clarify Passport availability

• Notes that Hypervel's Passport port is forthcoming and fixes remember-me wording.

src/docs/authentication.md

blade.mdCorrect Blade examples and component labels +5/-5

Correct Blade examples and component labels

• Fixes component terminology, example namespaces, code-block language, and a missing terminator.

src/docs/blade.md

broadcasting.mdDocument encrypted channels and broadcasting setup +115/-9

Document encrypted channels and broadcasting setup

• Adds encrypted private-channel setup, Mercure installation guidance, and Echo socket-ID hooks. Updates frontend references and queue-routing guidance.

src/docs/broadcasting.md

collections.mdCorrect collection examples and explain reference reduction +27/-17

Correct collection examples and explain reference reduction

• Documents by-reference mutation for scalar and array reduceInto accumulators. Corrects example outputs, signatures, and descriptions.

src/docs/collections.md

concurrency.mdGive named concurrency results their own section +19/-12

Give named concurrency results their own section

• Moves the associative-task example into a dedicated Named Results section while retaining Hypervel's coroutine-context guidance.

src/docs/concurrency.md

controllers.mdCorrect a translated resource route parameter +1/-1

Correct a translated resource route parameter

• Uses the singular parameter name in the localized resource route example.

src/docs/controllers.md

eloquent-relationships.mdAlign polymorphic diagrams and eager-loading guidance +4/-7

Align polymorphic diagrams and eager-loading guidance

• Shows polymorphic type columns before ID columns, fixes an example, and removes the obsolete automatic eager-loading beta warning.

src/docs/eloquent-relationships.md

eloquent.mdClarify timestamp format and attributed scopes +4/-2

Clarify timestamp format and attributed scopes

• Limits the documented dateFormat effect to database storage and explains protected attributed scopes and builder-based calls.

src/docs/eloquent.md

errors.mdList status pages excluded from fallback templates +1/-1

List status pages excluded from fallback templates

• Expands the list of status codes with dedicated error pages that fallback templates do not override.

src/docs/errors.md

events.mdDocument queue routing for listeners +3/-1

Document queue routing for listeners

• Links queued-listener guidance to routing the ShouldQueue contract to a shared queue and corrects a contents label.

src/docs/events.md

filesystem.mdDocument image manipulation and disk failure defaults +21/-0

Document image manipulation and disk failure defaults

• Adds stored-image manipulation examples and clarifies behavior when neither disk throw nor report is configured.

src/docs/filesystem.md

fortify.mdRestructure Fortify passkey guidance +122/-30

Restructure Fortify passkey guidance

• Separates enabling, client integration, authentication, confirmation, registration, and deletion. Retains Hypervel-specific configuration and explains JSON responses for custom clients.

src/docs/fortify.md

helpers.mdCorrect helper examples and localized number parsing +13/-13

Correct helper examples and localized number parsing

• Updates Number::parse examples and corrects code fences, encoded query output, and PHP example syntax.

src/docs/helpers.md

horizon.mdPolish Horizon CSP and supervisor examples +2/-2

Polish Horizon CSP and supervisor examples

• Refines CSP nonce wording and removes a stray character from a configuration example.

src/docs/horizon.md

http-tests.mdRepair HTTP testing example syntax +2/-2

Repair HTTP testing example syntax

• Corrects a closure expression and terminates a route declaration.

src/docs/http-tests.md

installation.mdRefresh installation wording +3/-3

Refresh installation wording

• Simplifies application-creation, development-server, and configuration prose without changing the instructions.

src/docs/installation.md

mail.mdExplain SES tenant headers and repair Mailgun link +13/-2

Explain SES tenant headers and repair Mailgun link

• Shows how a mailable supplies the SES tenant header and updates the Mailgun regions URL.

src/docs/mail.md

migrations.mdCorrect morph column order and migration events +21/-21

Correct morph column order and migration events

• Documents type-before-ID morph columns, clarifies migration event interfaces and descriptions, and fixes an example terminator.

src/docs/migrations.md

notifications.mdCorrect the on-demand testing anchor +1/-1

Correct the on-demand testing anchor

• Renames the duplicate testing anchor so the section has a distinct link target.

src/docs/notifications.md

permission.mdRemove a non-difference from Permission documentation +0/-1

Remove a non-difference from Permission documentation

• Drops the cache-store failure behavior from the list of differences from Spatie.

src/docs/permission.md

queries.mdCorrect the groupByRaw heading level +1/-1

Correct the groupByRaw heading level

• Nests groupByRaw under the appropriate query-builder section.

src/docs/queries.md

queues.mdClarify queue routing, timeout, and deduplication +13/-7

Clarify queue routing, timeout, and deduplication

• Adds broadcast queue-routing guidance, corrects the rate-limit link, documents --once timeout behavior, and fixes the queued-listener deduplicator example.

src/docs/queues.md

requests.mdClarify integer input casting +1/-1

Clarify integer input casting

• Describes integer input conversion as an attempted cast rather than an unconditional result.

src/docs/requests.md

sanctum.mdClarify SPA remember-me support +5/-2

Clarify SPA remember-me support

• Documents session-based remember-me support and updates frontend and application-bootstrap examples.

src/docs/sanctum.md

scheduling.mdCorrect scheduling example and timezone warning +2/-2

Correct scheduling example and timezone warning

• Fixes a missing terminator and aligns daylight-saving terminology.

src/docs/scheduling.md

scout.mdAdd Scout engine links to the contents +4/-0

Add Scout engine links to the contents

• Lists Algolia, Meilisearch, Typesense, and Turbopuffer under driver prerequisites.

src/docs/scout.md

starter-kits.mdMake starter-kit tables horizontally scrollable +8/-0

Make starter-kit tables horizontally scrollable

• Wraps authentication-route and action-file tables for narrower screens.

src/docs/starter-kits.md

strings.mdCorrect string helper descriptions and examples +11/-11

Correct string helper descriptions and examples

• Fixes Str::password, mask argument positions, and the no-argument str helper description, alongside syntax and wording corrections.

src/docs/strings.md

telescope.mdDocument Telescope CLI inspection and CSP nonces +52/-0

Document Telescope CLI inspection and CSP nonces

• Adds telescope:list and telescope:show usage, including filtering, pagination, and JSON output. Documents middleware-based CSP nonce configuration.

src/docs/telescope.md

validation.mdRefresh validation examples and image ratio rules +105/-107

Refresh validation examples and image ratio rules

• Uses array-form rules throughout, adds image ratio-range constraints and fluent helpers, and lists Min among file rules. Corrects examples and validation messages.

src/docs/validation.md

vite.mdDistinguish static assets from Vite font handling +4/-2

Distinguish static assets from Vite font handling

• Explains when to use the assets option rather than the fonts option and polishes the example.

src/docs/vite.md

wayfinder.mdExplain verb-prefixed shared-URI exports +20/-2

Explain verb-prefixed shared-URI exports

• Documents selection of separately registered routes sharing a URI, multi-verb keys, and unchanged keys for unique URIs.

src/docs/wayfinder.md

Server.phpClarify server bootstrap's kernel lifecycle +2/-2

Clarify server bootstrap's kernel lifecycle

• Adjusts comments to reflect kernel initialization during application boot and the later bootstrap call's possible no-op behavior.

src/http-server/src/Server.php

README.mdFocus Permission README on genuine package differences +8/-48

Focus Permission README on genuine package differences

• Replaces duplicated installation instructions with a documentation link. Retains linked Hypervel-specific differences and removes incorrect distinctions.

src/permission/README.md

README.mdExplain coroutine-specific Telescope behavior +6/-0

Explain coroutine-specific Telescope behavior

• Documents per-coroutine recording, queues, deferred storage, and CSP nonce behavior as differences from Laravel Telescope.

src/telescope/README.md

Other (5) +21 / -17
sync.yamlRecord upstream checkpoints and sync guidance +16/-13

Record upstream checkpoints and sync guidance

• Records Reverb, Scout, Telescope, and Tinker checkpoints. Adds guidance on deferred integrations, asset builds, Wayfinder's tracked branch, and documentation reconciliation.

docs/upstream-sync/sync.yaml

pnpm-lock.yamlAlign Wayfinder's happy-dom lockfile requirement +1/-1

Align Wayfinder's happy-dom lockfile requirement

• Updates the happy-dom specifier to match Wayfinder's raised minimum; the resolved version remains 20.9.0.

pnpm-lock.yaml

.npmrcDisable dashboard dependency install scripts +1/-0

Disable dashboard dependency install scripts

• Adds ignore-scripts alongside the existing minimum release age.

src/telescope/.npmrc

package.jsonRaise Telescope axios and moment minimums +2/-2

Raise Telescope axios and moment minimums

• Requires axios ^1.20.0 and moment ^2.31.0 to avoid advisory-affected ranges.

src/telescope/package.json

package.jsonRaise Wayfinder's happy-dom minimum +1/-1

Raise Wayfinder's happy-dom minimum

• Requires a happy-dom release containing security fixes.

src/wayfinder/package.json

@greptile-apps

greptile-apps Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Medium risk] Syncs documentation and updates console output formatting across multiple packages.

The PR appears safe to merge with non-blocking console display and malformed-cursor issues remaining.

Fix All in Claude CodeFindings

  1. P2 Database metadata gains escape characters ▶
  2. P2 Oversized cursors reach database ▶
  3. P2 Initial preview never retries ▶
  4. P2 Batch inspection loads everything ▶

Summary

The PR syncs Telescope, Tinker, Wayfinder, and documentation changes while moving HTTP-kernel construction ahead of provider boot. Recent commits also adjust console output escaping, JSON output, and dashboard request handling.

  • Console component escaping can visibly alter database metadata.
  • An oversized Telescope pagination cursor can reach the database instead of being rejected.

Reviews (2) · Last reviewed commit: "Keep console formatting from altering re..."

Comment thread src/wayfinder/src/GenerateCommand.php
Comment on lines +115 to +117
this.ready = true;

if (this.mayRetry(error, signal)) this.updateEntry();

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Initial preview never retries If the first preview request fails without an HTTP response, this retry path calls updateEntry(). That method returns while entry is still null, and it always returns for non-job previews. A transient failure therefore leaves the screen showing “No entry found” without another attempt. Retry the initial load separately from polling a loaded job.

Fix in Claude Code Fix in Codex

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not changed. The first load has never retried, and previews other than jobs never poll, so a retry timer would be new behavior rather than a fix. The real problem on this line was the alert: a failed first load called mayRetry(), which couldn't retry anything but could show the "stopped listening" alert. In 3cf5542 only polling of a loaded entry retries or reports that it stopped, and a failed first load shows the not found card.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You're right. The initial load has intentionally never retried, and only loaded job entries are polled. Here, polling defaults to false, so a first-load failure only sets ready and renders the not-found state; mayRetry() is reached only from the polling path. My finding was based on the earlier implementation and is no longer applicable after 3cf554215.

Comment thread src/docs/telescope.md Outdated
Comment on lines +58 to +59
$batchEntries = $batchId
? collect($storage->get(null, EntryQueryOptions::forBatchId($batchId)->limit(-1)))->reverse()->values()

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Batch inspection loads everything telescope:show fetches and holds every entry in a batch even though its tables display only a limited number of rows. Inspecting a batch with many queries or logs can use substantial database and process memory. Bound or page the entries fetched for display, and obtain totals separately.

Knowledge Base Used: External API and observability integrations

Fix in Claude Code Fix in Codex

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not changed. The JSON output includes the whole batch, and the text summary counts queries, duplicate groups, cache hits and logs across all of it, so the command needs every entry. A batch is the entries recorded for one request, job or command, and upstream Telescope loads it the same way.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You're right—the full batch is required for the JSON contract and accurate aggregate statistics, and matching upstream behavior makes this intentional rather than a defect. I’m withdrawing the memory concern.

Comment thread src/telescope/src/Console/ShowCommand.php Outdated
@qodo-free-for-open-source-projects

qodo-free-for-open-source-projects Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (2) 📘 Rule violations (0) 📎 Requirement gaps (0) 🎨 UX issues (0) 🔗 Cross-repo conflicts (0) 📜 Skill insights (0)

Grey Divider


Action required

1. Short entry IDs fail on PostgreSQL 🐞 Bug ≡ Correctness
Description
DatabaseEntriesRepository::find() applies whereLike() to the native UUID column when an ID is
shorter than 36 characters. On PostgreSQL, that becomes a UUID-versus-text ILIKE comparison, so
telescope:show cannot resolve the shortened IDs displayed by telescope:list.
Code

src/telescope/src/Storage/DatabaseEntriesRepository.php[R69-70]

+        if (strlen($id) < 36 && ctype_xdigit($id)) {
+            $query->whereLike('uuid', $id . '%')->orderByDesc('sequence');
Evidence
The new prefix branch uses whereLike on uuid; the PostgreSQL query grammar emits ILIKE, while
the Telescope migration and PostgreSQL schema grammar define that column as a native UUID.

src/telescope/src/Storage/DatabaseEntriesRepository.php[65-78]
src/database/src/Query/Grammars/PostgresGrammar.php[83-88]
src/telescope/database/migrations/2025_02_08_000000_create_telescope_entries_table.php[22-26]
src/database/src/Schema/Grammars/PostgresGrammar.php[903-908]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
Shortened Telescope entry IDs use a text-prefix comparison against a native PostgreSQL UUID column, causing a query error.
## Fix Focus Areas
- src/telescope/src/Storage/DatabaseEntriesRepository.php[69-70]
## Recommended Fix
Use a PostgreSQL-compatible text cast for prefix matching while preserving case-insensitive lookup and the existing behavior on other databases. Add a PostgreSQL test for a shortened ID.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools



Remediation recommended

2. Boot-time kernel hooks can be skipped 🐞 Bug ≡ Correctness
Description
Application::boot() now resolves the HTTP kernel before running application booting callbacks. If
one of those callbacks registers an afterResolving hook for the kernel, subsequent resolutions
return the cached instance without invoking that hook, leaving its kernel configuration unapplied.
Code

src/foundation/src/Application.php[R1135-1136]

+        if ($this->bound(HttpKernelContract::class)) {
+            $this->make(HttpKernelContract::class);
Evidence
The added resolution precedes fireAppCallbacks($this->bootingCallbacks). The container stores
newly registered after-resolving callbacks but returns an already cached auto-singleton without
firing them; the application builder demonstrates that these hooks configure kernel middleware.

src/foundation/src/Application.php[1132-1145]
src/container/src/Container.php[1168-1178]
src/container/src/Container.php[2123-2134]
src/foundation/src/Configuration/ApplicationBuilder.php[220-236]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
Resolving the HTTP kernel before booting callbacks prevents kernel after-resolving hooks registered by those callbacks from running.
## Fix Focus Areas
- src/foundation/src/Application.php[1135-1142]
## Recommended Fix
Keep booting callbacks ahead of the first kernel resolution while still constructing the kernel before providers modify router middleware. Add a test that registers a kernel after-resolving hook in an application booting callback.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


3. Leaving Monitoring rejects a request ✓ Resolved
Description
The Monitoring screen passes an abort signal to its Axios request but attaches only a success
handler. Navigating away while monitored tags are loading calls abort() and leaves the resulting
cancellation rejection unhandled.
Code

src/telescope/resources/js/screens/monitoring/index.vue[R26-29]

+        const {signal} = this.requestController;
+
+        axios.get(Telescope.basePath + '/telescope-api/monitored-tags', {signal}).then(response => {
+            if (signal.aborted) return;
Evidence
The modified request supplies the controller signal and has no .catch(); the new destruction hook
aborts that same controller.

src/telescope/resources/js/screens/monitoring/index.vue[23-35]
src/telescope/resources/js/screens/monitoring/index.vue[38-43]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
Destroying the Monitoring screen aborts a pending Axios request whose promise has no rejection handler.
## Fix Focus Areas
- src/telescope/resources/js/screens/monitoring/index.vue[26-34]
- src/telescope/resources/js/screens/monitoring/index.vue[41-43]
## Recommended Fix
Attach a rejection handler that ignores cancellations from the screen's abort signal and handles other request failures appropriately.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


4. The CSP example reuses one nonce ✓ Resolved
Description
The new Telescope middleware example passes the constant 'csp-nonce' to Telescope::cspNonce()
rather than generating a value per request. Applications that copy the example reuse an
authorization value across requests because the implementation emits the supplied value without
rotating it.
Code

src/docs/telescope.md[128]

+    Telescope::cspNonce('csp-nonce');
Evidence
The documentation calls for a new nonce on each request but supplies a literal constant.
Telescope::cspNonce() stores that exact string and the HTML attribute uses it unchanged.

src/docs/telescope.md[115-131]
src/telescope/src/Telescope.php[869-886]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The new CSP middleware example hard-codes the nonce despite instructing readers to assign a new one for each request.
## Fix Focus Areas
- src/docs/telescope.md[118-130]
## Recommended Fix
Show a cryptographically random per-request nonce and explain that the same generated value must be used in the request's CSP header.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


View medium (1)
5. Missing entries show a misleading error banner ✓ Resolved
Description
loadEntry in PreviewScreen.vue now calls mayRetry on every failure, and mayRetry raises an
alert that never closes ('Telescope stopped listening for new entries…') whenever the server
responded. Opening a pruned, deleted or malformed entry ID returns a 404 on the first load, so every
preview type shows this banner on top of the existing 'No entry found.' panel.
Code

src/telescope/resources/js/components/PreviewScreen.vue[R113-117]

+                if (signal.aborted) return;
+
              this.ready = true;
+
+                if (this.mayRetry(error, signal)) this.updateEntry();
Evidence
mayRetry calls alertError whenever error.response is set, and alertError sets `autoClose =
false. loadEntry` also handles the initial load for every entry type. The template already handles
a missing entry with the ready && !entry 'No entry found.' panel.

src/telescope/resources/js/base.js[72-87]
src/telescope/resources/js/components/PreviewScreen.vue[167-172]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
When the preview's first load fails with a server response (such as a 404 for a missing entry), `PreviewScreen.loadEntry` calls `mayRetry`. That shows a red 'stopped listening' alert which does not close on its own, even though no polling was ever running.
## Fix Focus Areas
- src/telescope/resources/js/components/PreviewScreen.vue[112-118]
## Recommended Fix
Guard the retry with an already-loaded entry: `if (this.entry && this.mayRetry(error, signal)) this.updateEntry();`. On the initial load, keep showing only the 'No entry found.' panel.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools



Informational

6. Bad --before value crashes with a SQL error ✓ Resolved
Description
ListCommand::queryOptions passes the raw --before option to beforeSequence, and EntryModel
then uses it in where('sequence', '<', …) without validation. A non-numeric value such as
--before=abc fails inside the database (on PostgreSQL the bigint column rejects it) and prints a
raw QueryException, while --limit gets a clean validation message.
Code

src/telescope/src/Console/ListCommand.php[94]

+            ->familyHash($this->option('family'))
Evidence
--limit is checked with ctype_digit, but --before is not. EntryQueryOptions::beforeSequence
only turns an empty string into null, and EntryModel applies the value directly in a where on
sequence.

src/telescope/src/Console/ListCommand.php[52-56]
src/telescope/src/Storage/EntryQueryOptions.php[86-90]
src/telescope/src/Storage/EntryModel.php[152-153]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
`telescope:list --before=<non-numeric>` reaches the SQL query unvalidated and fails with a raw database error.
## Fix Focus Areas
- src/telescope/src/Console/ListCommand.php[52-56]
- src/telescope/src/Console/ListCommand.php[88-96]
## Recommended Fix
In `handle`, when `--before` is set and `! ctype_digit((string) $before)`, print 'The --before option must be a positive integer.' and return 1. Then pass `(int) $before` to `beforeSequence`.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Tip of the day
💡 Did you know, you can copy the agent prompt from any finding and feed it to your IDE agent

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread src/telescope/src/Storage/DatabaseEntriesRepository.php
Comment thread src/foundation/src/Application.php
Comment thread src/telescope/resources/js/screens/monitoring/index.vue
Comment thread src/docs/telescope.md Outdated
Comment thread src/telescope/resources/js/components/PreviewScreen.vue Outdated
Comment thread src/telescope/src/Console/ListCommand.php
The preview screen is reused when the route ID changes, but it kept the
previous entry and batch while loading the next one. When the new entry
failed to load, the old entry stayed on screen under the new URL instead
of the not found card. Preparing an entry now clears the component's and
the parent screen's entry state.

A failed first load also went through the polling retry path, so opening
an entry that no longer exists showed a permanent "stopped listening"
alert above the not found card. Only polling of a loaded entry now
retries or reports that it stopped; a loaded job keeps its data when a
later poll fails.

Leaving the monitoring screen while its tags were loading aborted the
request and surfaced an unhandled rejection. Aborted loads are now
ignored there, matching the other screens.

The bundle is rebuilt.

Validation: the preview methods were exercised for a successful load
followed by a 404 on a new ID, first-load 404 and network failures, and
polling network and server failures of a pending job.
telescope:list and telescope:show wrote recorded data through the
console formatter. The formatter strips text that looks like a console
style tag (such as <info>) and drops a backslash written before < or >.
SQL with inlined bindings, exception messages, code lines, log messages
and response bodies could therefore show different text from what was
recorded, and --json output could become invalid JSON.

- --json output is written raw.
- Content blocks such as payloads, responses and job data are written
  raw.
- Free-text values placed into styled lines and tables (SQL, messages,
  URIs, cache keys, subjects, addresses, commands, code lines and entry
  summaries) are escaped with Symfony's OutputFormatter::escape(), after
  truncation. The commands' own colors are unchanged.

telescope:list also validates --before. A non-numeric or non-positive
cursor caused a raw SQL error on PostgreSQL and silently returned the
wrong page on MySQL and SQLite; it now fails with a clear message, like
--limit.

The list test also drops an unused variable.

Validation: new tests cover markup and backslashes in JSON output, in
show's content blocks, batch tables, listings, exception messages and
code context, and in list's typed and summary columns. Each failed
before its fix. The Telescope suite passes.
The Telescope CSP example passed a fixed 'csp-nonce' string and sent no
policy header, so it neither gave each request a fresh nonce nor showed
how the nonce reaches the browser. It now generates a random nonce per
request, passes it to Telescope::cspNonce() and sends the matching
Content-Security-Policy header, as the Horizon documentation does.

The migration events table said DatabaseRefreshed fires when the
migrate:fresh or migrate:refresh command has run. It is dispatched after
the migrations run and before any seeders, which matters for listeners
that prepare data the seeders rely on. The description now says so.
Text written through a command's normal output goes through Symfony's
output formatter. It strips text that looks like a console style tag
(such as <info>) and drops a backslash written before < or >. Several
commands wrote data they don't control that way:

- The concurrency process driver's child command returns its result
  and failure details to the parent as a JSON envelope. A failing task
  whose exception message contained style tags or a backslash before
  < or > could produce an envelope the parent couldn't decode.
- queue:work --json changed exception messages in its failed-job line.
  A message containing invalid UTF-8 made json_encode() return false,
  so the line was never written at all.
- db:show, db:table, model:show, dev:list and schedule:list --json
  output could be changed or made invalid by table comments, column and
  attribute defaults, and shell commands.
- db:table, db:show and model:show text output showed changed
  comments and defaults.

JSON output from these commands is now written raw, and queue:work's
line substitutes invalid UTF-8 instead of failing. In the database
commands' text output, comments and defaults are escaped with
OutputFormatter::escape() before the commands' own styles are applied.

The database console test now covers text as well as JSON output, so it
is renamed to DatabaseConsoleOutputTest.

Validation: new and extended tests cover markup and backslashes in each
JSON writer, the concurrency failure envelope, a failed job with
invalid UTF-8, and the database commands' text output. Each failed
before its fix. The Database, Console, Integration Console, Queue,
Integration Queue (database driver) and Concurrency suites pass.
$this->newLine();

$this->components->twoColumnDetail('<fg=green;options=bold>' . $table['schema_qualified_name'] . '</>', $table['comment'] ? '<fg=gray>' . $table['comment'] . '</>' : null);
$this->components->twoColumnDetail('<fg=green;options=bold>' . $table['schema_qualified_name'] . '</>', $table['comment'] ? '<fg=gray>' . OutputFormatter::escape($table['comment']) . '</>' : null);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Database metadata gains escape characters OutputFormatter::escape() prepares text for Symfony's console formatter, but twoColumnDetail renders through Termwind and already HTML-escapes its values. A table comment such as <info>Pending</info> will display with added escape characters instead of its original text. The same problem affects column defaults here and the escaped values in db:show and model:show.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

Fix in Claude Code Fix in Codex

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not an issue. The escape only adds a backslash before < and >, and the console formatter removes it again when the line is written, so plain values such as Pending are unchanged. I rendered values through both twoColumnDetail and the bullet list: Pending, a < b, x > 0 && y and Tom & Jerry display exactly as stored, and <info>Pending</info> a\>b, which used to display as Pending a>b, now displays unchanged. The new DatabaseConsoleOutputTest and ModelInspectorTest cases assert the rendered text.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You're right — my original concern was incorrect. OutputFormatter::escape() is appropriate here: the console formatter removes the protective backslashes when rendering while preserving literal style-looking text and comparison operators. The rendered cases and added DatabaseConsoleOutputTest/ModelInspectorTest coverage confirm that twoColumnDetail and bullet-list output match the stored values, so this is not an issue.


$before = $this->option('before');

if ($before !== null && (! ctype_digit((string) $before) || (int) $before < 1)) {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Oversized cursors reach database An all-digit --before value larger than the database's BIGINT range passes this check because casting it to a PHP integer still yields a positive value. The original string is then used in the sequence query, so a database that rejects the out-of-range comparison returns a query error instead of an invalid-option message.

Fix in Claude Code Fix in Codex

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not changed. The cursor comes from the command's own Use --before=… hint, so an out-of-range value only appears when one is mistyped. SQLite treats it as a cursor above every sequence and returns the newest page, and PostgreSQL fails with value "99999999999999999999" is out of range for type bigint, which already names the problem. A check would only reword that error.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That’s fair. Since --before is an opaque cursor emitted by the command itself, an out-of-range value is only an invalid, manually supplied cursor; SQLite’s empty/newest-page behavior and PostgreSQL’s explicit bigint error are acceptable handling here. I’m withdrawing this finding.

@binaryfire
binaryfire merged commit 1485780 into 0.4 Oct 3, 2026
55 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant