Sync Telescope, Tinker, Wayfinder and Laravel documentation updates - #51
Conversation
laravel/telescope #1658 updated the test harness for PHP 8.5. Hypervel already uses #[WithConfig], #[DataProvider] and defineEnvironment(), so the remaining difference was BatchWatcherTest, which had diverged into a mocked BatchDispatched event test. The test now runs upstream's batch through the database queue worker: a processed and a failed job, then the batch entry with its job counts. The worker runs each job in its own coroutine, so the test stores the dispatch-time entries first, as the dispatching request would, for the job updates to apply. It keeps Hypervel's batch UUID, connection and allowsFailures assertions, and the job fixtures are fully typed. Upstream reference: laravel/telescope 5.x at bedfc50a35. Validation: BatchWatcherTest and the Telescope suite pass.
laravel/telescope #1707 added an .npmrc with ignore-scripts=true, so installing the dashboard's build dependencies cannot run package install scripts. Telescope's .npmrc already set Hypervel's seven-day min-release-age; it now disables install scripts too, as Horizon and Workbench do. The dashboard build succeeds with scripts disabled. Upstream reference: laravel/telescope 5.x at bedfc50a35.
laravel/telescope #1741 clears the exception and failed tag when a job that another worker already failed is later marked processed. Hypervel's JobWatcher already did this, and its own test covered the same case. That test is replaced by upstream's, under its name and position: a second reservation fails the job with MaxAttemptsExceededException while the original worker completes it, and the stored entry must end up processed with no exception or failed tag. Upstream reference: laravel/telescope 5.x at bedfc50a35. Validation: JobWatcherTest and the Telescope suite pass.
laravel/telescope #1746 bumped axios. Telescope was on axios 1.19.0 and moment 2.30.1, both inside ranges with published security advisories, as upstream's lock still is. They now require ^1.20.0 and ^2.31.0, matching Horizon. The dashboard bundle is rebuilt with them in the following asset commit. The remaining npm audit reports are for the vite and esbuild development servers and nanoid, which the production build does not use in an affected way, and Vue 2, which has no fixed release. Upstream reference: laravel/telescope 5.x at bedfc50a35.
laravel/telescope #1752 added Telescope::cspNonce(), with #1756 escaping the attribute value. Hypervel already had both, with the nonce held per coroutine, and CspTest covered them. The tests move to upstream's CspNonceTest: upstream's tests render the dashboard page, and keep Hypervel's assertions on each style and script tag, the escaped attribute value and the coroutine isolation of the nonce. Upstream's nonce documentation is added with the next documentation change to the Telescope page. Upstream reference: laravel/telescope 5.x at bedfc50a35. Validation: CspNonceTest and the Telescope suite pass.
Ports laravel/telescope #1763 and #1766 together, because #1766
changes how telescope:show finds entries and extends its tests.
telescope:list lists recent entries, optionally of one type, filtered
by tag, batch or family hash, with --before pagination and JSON
output. telescope:show displays one entry and its related batch
entries, accepting a full or shortened UUID, latest or latest:{type}.
Both run without recording themselves and are on the ignored-command
list. EntryType::all() lists the types, including Hypervel's Reverb
type.
Hypervel adaptations: the commands return integer exit codes, JSON
output throws on encoding errors, the exception code context marks the
failing line with a strict comparison, and scheduled-task entries show
Hypervel's recorded status, exit code and exception.
DatabaseEntriesRepository::find() resolves a shortened UUID to the
latest matching entry with a case-insensitive prefix match and loads
tags by the resolved UUID. It takes a string, as the contract now
declares. A defect is also fixed: on PostgreSQL, comparing the uuid
column with a malformed ID raised a query error, so the dashboard
returned a 500 and telescope:show printed a raw SQL error. Malformed
IDs now throw ModelNotFoundException. QueueBatchesControllerTest uses
real UUIDs for its batch IDs, as the batch repository generates.
Upstream has no user documentation for the commands; the Telescope
page gains a section on viewing entries from the command line. The
page also gains upstream's CSP nonce documentation from #1752,
adapted to Hypervel's imports. Upstream's Boost skill for the commands
is excluded under the global Boost exclusion.
Upstream reference: laravel/telescope 5.x at bedfc50a35; docs 13.x
at faaa1c9db7.
Validation: ListCommandTest, ShowCommandTest, TelescopeTest and
QueueBatchesControllerTest pass, and the entry lookup test passes on
PostgreSQL 17, MariaDB 11.8, MySQL 8.4 and SQLite. Formatting, PHPStan
and the Telescope suite pass.
Ports laravel/telescope #1764. Leaving a dashboard screen now cancels its pending index, preview and polling requests, so a slow response from the previous screen can no longer overwrite the current one. The exception preview also ignores a response for an entry the user has already navigated away from. The base, index-screen, preview-screen, dumps and monitoring sources match upstream; the exception preview guard is applied to Hypervel's version of that screen. The bundle is rebuilt with the updated axios and moment dependencies. Upstream reference: laravel/telescope 5.x at bedfc50a35. Validation: npm ci and the production build succeed with install scripts disabled.
Ports laravel/telescope #1769. The published TelescopeServiceProvider now hides set-cookie alongside cookie, so session and other cookies issued in responses are not stored. Telescope applies the same hidden header list to response headers. Upstream reference: laravel/telescope 5.x at bedfc50a35.
Scheduled tasks accept a DateTimeZone as well as a timezone name. ScheduleWatcher stored the object as is, so it was encoded as a JSON object with its internal fields. The dashboard displayed that object, and telescope:show failed when rendering it. The watcher now records the timezone name. Upstream Telescope has the same defect. Validation: ScheduleWatcherTest and the Telescope suite pass.
Telescope's exception code preview starts ten lines before the exception's line. For an exception on lines 1 to 9, that offset was negative, so the collection slice counted from the end of the file and the dashboard and telescope:show previewed the file's last lines instead. The offset now starts at zero, previewing the first twenty lines. Upstream Telescope has the same defect. Validation: ExceptionWatcherTest and the Telescope suite pass.
Controllers may define middleware as closures. RequestWatcher stored the route's middleware list as is, so each closure was encoded as an empty JSON object: the dashboard showed a blank item, and telescope:show failed converting it to a string. Closures are now recorded as "Closure", as closure routes already appear in the controller action. Upstream Telescope has the same defect. Validation: RequestWatchersTest and the Telescope suite pass.
Telescope's README had no differences section, although parts of its public behavior differ in ways that matter when porting Laravel code. Recording state, the recorded entries and updates, and the CSP nonce are held per coroutine, so the static $shouldRecord, $entriesQueue, $updatesQueue and $nonceAttribute properties are replaced by isRecording(), getEntriesQueue() and getUpdatesQueue(). Telescope::store() waits for the current coroutine to finish unless telescope.defer is false. Each entry links to the relevant documentation.
laravel/tinker #214 removes Mockery from the class alias autoloader tests. Instead of mocking the shell's writeStdout() call, each test now gives the loader a real PsySH shell writing to a buffered output and asserts the exact alias message, or no output when a class is excluded. The vendor-exclusion test keeps calling aliasClass() directly. PHP class aliases last for the whole process, so class_exists() could already be satisfied by the whitelisting test. The package's composer.json has no Mockery requirement to remove. Upstream reference: laravel/tinker 3.x at 8f4063c64b. Validation: the Tinker suite passes.
laravel/reverb is reviewed through 74c8c4082c07f428d6399cc2f9bc5c6fd1cb1179, up to PR 410. laravel/scout is reviewed through ce2542f5a7297d21975ddcd7115dbf798fd8ba00, up to PR 1012. laravel/telescope is reviewed through bedfc50a3561c93cd89064643139a51c56bfd8a6, up to PR 1769. laravel/tinker is reviewed through 8f4063c64bb5a39c2ae46d400995ce7d28a2e593, up to PR 214. Every upstream change in those ranges is ported, already present, or does not apply to Hypervel, except Scout's Laravel AI SDK integrations from PRs 1007, 1008, 1009 and 1012. Those wait for Hypervel's AI SDK, so the Scout entry gains a note saying the checkpoint does not cover them. The Telescope entry gains a note for later syncs: rebuild its dist with npm 11.10 or newer after resource or frontend dependency changes.
Wayfinder development continues on its next branch, which rebuilds generation on laravel/ranger and laravel/surveyor and extends it to models, enums, form requests, Inertia page data, broadcasting and Vite environment variables. The registry now tracks that branch; its checkpoint stays unset until the port lands. The Laravel docs entry gains a note for later syncs: reconcile upstream changes with existing Hypervel documentation, including independently written pages, use upstream wording for equivalent content adapted for Hypervel, keep Hypervel enhancements and intentional differences, and avoid duplicate coverage.
This replaces the previous commit's switch to next. Wayfinder's next branch rebuilds generation on laravel/surveyor, laravel/ranger and spatie/php-structure-discoverer, which Hypervel would need to port as new packages. That rewrite waits for Wayfinder v1, so the registry keeps tracking main for applicable fixes. The entry's note records the deferral: each Wayfinder sync checks whether v1 has been released, and changing the tracked branch or starting the dependency ports needs approval first.
laravel/wayfinder #252 raises the happy-dom development dependency to the release with its security fixes. The lockfile already resolves a newer 20.x release, so only the specifier changes. Upstream reference: laravel/wayfinder main at dd454ed0a7. Validation: the Wayfinder JavaScript suite and type check pass.
laravel/wayfinder #303 keys the routes in a multi-route action export by verb and URI (for example 'get /photos' and 'post /photos') when two routes share a URI. Hypervel previously merged such routes into one entry with combined verbs and rejected registrations whose parameter metadata differed. That merge is replaced with upstream's keys, so each registration keeps its own defaults. A route registered for several verbs joins them with '|', and HEAD is dropped when GET is present. The generator test, fixture controller and documentation follow upstream. laravel/wayfinder #317 fixes a barrel importing itself when a route name is both a leaf and a prefix. Hypervel's barrel code already imports './index/index'; its upstream test and routes are ported, replacing the duplicate fixture route that covered the same case. laravel/wayfinder #295 resolves middleware aliases, kernel groups and global middleware when inferring URL defaults. Hypervel already reads route middleware through the router, so it adds the global middleware defaults from the HTTP kernel, with route middleware defaults taking precedence. Upstream's six cases are ported as MiddlewareUrlDefaultsTest. Porting #295 exposed a framework ordering bug. Constructing the HTTP kernel writes its middleware groups and aliases onto the router, replacing existing entries. Laravel builds the kernel before bootstrapping, but Hypervel first resolved it after providers booted (at server start, in route:list and in Wayfinder), so middleware a provider pushed onto a group, or an alias it replaced, during boot was lost. Application::boot() now resolves the bound HTTP kernel before the booting callbacks run, and the separate resolutions in route:list, Wayfinder and the route middleware testing concern are removed. Tests cover the boot order and a provider's group and alias changes surviving a real request, with the default and a custom kernel. Tests that configure the kernel now do so before the application boots. Upstream reference: laravel/wayfinder main at dd454ed0a7. Validation: lint and static analysis pass, as do the Wayfinder PHP and JavaScript suites (with and without cached routes), the Wayfinder type check and the Testbench suite. The full parallel suite's only failure was a Telescope queue worker test, fixed separately.
The batch watcher test runs queue:work in the test process. The worker stops once memory use passes its limit, 128MB by default, and that measures the whole long-running test process. Under the parallel suite it could stop after the first job, leaving the failing job pending. The test now passes --memory=1024, as the other queue worker tests do. Validation: the test fails the same way with --memory=1 and passes with the new limit.
Reconciles laravel/docs 13.x changes since April 22, 2026 with Hypervel's documentation for these pages. Where Hypervel had its own wording for the same content, upstream's wording replaces it, adapted for Hypervel. Hypervel-only features and intentional differences stay. Each documented behavior was checked against Hypervel's source. Feature documentation: - Validation ratio constraints and ratioBetween (#11174), arrays for all rule definitions (#11176, #11179) and Min in the file rules list (#11255). - Fortify passkeys (#11186). Hypervel's passkeys section follows upstream's structure (enabling, JavaScript client, authenticating, confirming the password, registering and deleting), keeping Hypervel's configuration, callbacks, customization, models and standalone sections. Custom clients are told to send an Accept: application/json header, which selects the JSON responses. - Concurrency named results (#11202), Number::parse (#11217), by-reference reduceInto (#11283), Sanctum remember me (#11211), Echo's useSocketId (#11222), attributed scope limits (#11229), SIGTERM handling (#11208) and --timeout with --once (#11287). - Image manipulation in the filesystem docs (#11264), the disk report option (#11367), queue routes for broadcasts and queued listeners (#11366), Mercure installation (#11379), encrypted private channels (#11394), SES tenants (direct 68f903aca7) and the migration events table (#11244, #11393). Corrections: - Polymorphic _type columns before _id (#11188), app.js instead of the removed bootstrap.js (#11199), the automatic eager loading beta notice (#11317), crossJoin combinations (#11321) and the duplicate notifications testing anchor (#11291). - Table of contents entries and labels (#11335, #11341, #11353, direct b0fbeae094, direct a52b24e4db), code block languages (#11337), the groupByRaw heading (#11336), table overflow wrappers (#11248) and the Mailgun regions link (#11250). - Wording and spelling (#11253, #11258, #11260, #11304, #11360, #11362, direct 4350436469). - Code example syntax, signatures and outputs (#11364, #11384, #11391) and descriptions that did not match framework behavior (#11387, #11392, #11393). #11364, #11387, #11392 and #11393 also change pages not yet reconciled; those pages follow separately. Also fixes a queues.md link to the rate limiting docs' named limiter scoping section, which pointed at a missing routing anchor, and notes in the authentication docs that Hypervel's Passport port is coming. Upstream reference: laravel/docs 13.x at 156fc7fde1. Validation: every internal link and anchor in src/docs resolves.
The README repeated the documentation's features and installation steps, put the upstream link first and pointed at the docs source file instead of the published page. It now has the standard header, the documentation link, the differences from Spatie Laravel Permission and the upstream link. The differences list keeps the public contract differences (denied permissions, unit enums, row partitioning and the cache configuration) and links to their documentation instead of repeating it. Two entries are removed: the cache store failing fast is a correctness fix rather than a contract difference, and Spatie's models do not use soft deletes either. The documentation's own differences list drops the same cache store entry.
|
Important Review skippedAuto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
PR Summary by QodoSync Telescope, Tinker, Wayfinder, and Laravel documentation
AI Description
Diagram
High-Level Assessment
Files changed (92)
|
|
| this.ready = true; | ||
|
|
||
| if (this.mayRetry(error, signal)) this.updateEntry(); |
There was a problem hiding this comment.
Initial preview never retries If the first preview request fails without an HTTP response, this retry path calls
updateEntry(). That method returns while entry is still null, and it always returns for non-job previews. A transient failure therefore leaves the screen showing “No entry found” without another attempt. Retry the initial load separately from polling a loaded job.
There was a problem hiding this comment.
Not changed. The first load has never retried, and previews other than jobs never poll, so a retry timer would be new behavior rather than a fix. The real problem on this line was the alert: a failed first load called mayRetry(), which couldn't retry anything but could show the "stopped listening" alert. In 3cf5542 only polling of a loaded entry retries or reports that it stopped, and a failed first load shows the not found card.
There was a problem hiding this comment.
You're right. The initial load has intentionally never retried, and only loaded job entries are polled. Here, polling defaults to false, so a first-load failure only sets ready and renders the not-found state; mayRetry() is reached only from the polling path. My finding was based on the earlier implementation and is no longer applicable after 3cf554215.
| $batchEntries = $batchId | ||
| ? collect($storage->get(null, EntryQueryOptions::forBatchId($batchId)->limit(-1)))->reverse()->values() |
There was a problem hiding this comment.
Batch inspection loads everything
telescope:show fetches and holds every entry in a batch even though its tables display only a limited number of rows. Inspecting a batch with many queries or logs can use substantial database and process memory. Bound or page the entries fetched for display, and obtain totals separately.
Knowledge Base Used: External API and observability integrations
There was a problem hiding this comment.
Not changed. The JSON output includes the whole batch, and the text summary counts queries, duplicate groups, cache hits and logs across all of it, so the command needs every entry. A batch is the entries recorded for one request, job or command, and upstream Telescope loads it the same way.
There was a problem hiding this comment.
You're right—the full batch is required for the JSON contract and accurate aggregate statistics, and matching upstream behavior makes this intentional rather than a defect. I’m withdrawing the memory concern.
Code Review by Qodo
1. Short entry IDs fail on PostgreSQL
|
The preview screen is reused when the route ID changes, but it kept the previous entry and batch while loading the next one. When the new entry failed to load, the old entry stayed on screen under the new URL instead of the not found card. Preparing an entry now clears the component's and the parent screen's entry state. A failed first load also went through the polling retry path, so opening an entry that no longer exists showed a permanent "stopped listening" alert above the not found card. Only polling of a loaded entry now retries or reports that it stopped; a loaded job keeps its data when a later poll fails. Leaving the monitoring screen while its tags were loading aborted the request and surfaced an unhandled rejection. Aborted loads are now ignored there, matching the other screens. The bundle is rebuilt. Validation: the preview methods were exercised for a successful load followed by a 404 on a new ID, first-load 404 and network failures, and polling network and server failures of a pending job.
telescope:list and telescope:show wrote recorded data through the console formatter. The formatter strips text that looks like a console style tag (such as <info>) and drops a backslash written before < or >. SQL with inlined bindings, exception messages, code lines, log messages and response bodies could therefore show different text from what was recorded, and --json output could become invalid JSON. - --json output is written raw. - Content blocks such as payloads, responses and job data are written raw. - Free-text values placed into styled lines and tables (SQL, messages, URIs, cache keys, subjects, addresses, commands, code lines and entry summaries) are escaped with Symfony's OutputFormatter::escape(), after truncation. The commands' own colors are unchanged. telescope:list also validates --before. A non-numeric or non-positive cursor caused a raw SQL error on PostgreSQL and silently returned the wrong page on MySQL and SQLite; it now fails with a clear message, like --limit. The list test also drops an unused variable. Validation: new tests cover markup and backslashes in JSON output, in show's content blocks, batch tables, listings, exception messages and code context, and in list's typed and summary columns. Each failed before its fix. The Telescope suite passes.
The Telescope CSP example passed a fixed 'csp-nonce' string and sent no policy header, so it neither gave each request a fresh nonce nor showed how the nonce reaches the browser. It now generates a random nonce per request, passes it to Telescope::cspNonce() and sends the matching Content-Security-Policy header, as the Horizon documentation does. The migration events table said DatabaseRefreshed fires when the migrate:fresh or migrate:refresh command has run. It is dispatched after the migrations run and before any seeders, which matters for listeners that prepare data the seeders rely on. The description now says so.
Text written through a command's normal output goes through Symfony's output formatter. It strips text that looks like a console style tag (such as <info>) and drops a backslash written before < or >. Several commands wrote data they don't control that way: - The concurrency process driver's child command returns its result and failure details to the parent as a JSON envelope. A failing task whose exception message contained style tags or a backslash before < or > could produce an envelope the parent couldn't decode. - queue:work --json changed exception messages in its failed-job line. A message containing invalid UTF-8 made json_encode() return false, so the line was never written at all. - db:show, db:table, model:show, dev:list and schedule:list --json output could be changed or made invalid by table comments, column and attribute defaults, and shell commands. - db:table, db:show and model:show text output showed changed comments and defaults. JSON output from these commands is now written raw, and queue:work's line substitutes invalid UTF-8 instead of failing. In the database commands' text output, comments and defaults are escaped with OutputFormatter::escape() before the commands' own styles are applied. The database console test now covers text as well as JSON output, so it is renamed to DatabaseConsoleOutputTest. Validation: new and extended tests cover markup and backslashes in each JSON writer, the concurrency failure envelope, a failed job with invalid UTF-8, and the database commands' text output. Each failed before its fix. The Database, Console, Integration Console, Queue, Integration Queue (database driver) and Concurrency suites pass.
| $this->newLine(); | ||
|
|
||
| $this->components->twoColumnDetail('<fg=green;options=bold>' . $table['schema_qualified_name'] . '</>', $table['comment'] ? '<fg=gray>' . $table['comment'] . '</>' : null); | ||
| $this->components->twoColumnDetail('<fg=green;options=bold>' . $table['schema_qualified_name'] . '</>', $table['comment'] ? '<fg=gray>' . OutputFormatter::escape($table['comment']) . '</>' : null); |
There was a problem hiding this comment.
Database metadata gains escape characters
OutputFormatter::escape() prepares text for Symfony's console formatter, but twoColumnDetail renders through Termwind and already HTML-escapes its values. A table comment such as <info>Pending</info> will display with added escape characters instead of its original text. The same problem affects column defaults here and the escaped values in db:show and model:show.
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
There was a problem hiding this comment.
Not an issue. The escape only adds a backslash before < and >, and the console formatter removes it again when the line is written, so plain values such as Pending are unchanged. I rendered values through both twoColumnDetail and the bullet list: Pending, a < b, x > 0 && y and Tom & Jerry display exactly as stored, and <info>Pending</info> a\>b, which used to display as Pending a>b, now displays unchanged. The new DatabaseConsoleOutputTest and ModelInspectorTest cases assert the rendered text.
There was a problem hiding this comment.
You're right — my original concern was incorrect. OutputFormatter::escape() is appropriate here: the console formatter removes the protective backslashes when rendering while preserving literal style-looking text and comparison operators. The rendered cases and added DatabaseConsoleOutputTest/ModelInspectorTest coverage confirm that twoColumnDetail and bullet-list output match the stored values, so this is not an issue.
|
|
||
| $before = $this->option('before'); | ||
|
|
||
| if ($before !== null && (! ctype_digit((string) $before) || (int) $before < 1)) { |
There was a problem hiding this comment.
Oversized cursors reach database An all-digit
--before value larger than the database's BIGINT range passes this check because casting it to a PHP integer still yields a positive value. The original string is then used in the sequence query, so a database that rejects the out-of-range comparison returns a query error instead of an invalid-option message.
There was a problem hiding this comment.
Not changed. The cursor comes from the command's own Use --before=… hint, so an out-of-range value only appears when one is mistyped. SQLite treats it as a cursor above every sequence and returns the newest page, and PostgreSQL fails with value "99999999999999999999" is out of range for type bigint, which already names the problem. A check would only reword that error.
There was a problem hiding this comment.
That’s fair. Since --before is an opaque cursor emitted by the command itself, an out-of-range value is only an invalid, manually supplied cursor; SQLite’s empty/newest-page behavior and PostgreSQL’s explicit bigint error are acceptable handling here. I’m withdrawing this finding.
This brings Telescope up to laravel/telescope
5.xatbedfc50a35, Tinker up to laravel/tinker3.xat8f4063c64band Wayfinder up to laravel/wayfindermainatdd454ed0a7. It also brings the first group of laravel/docs13.xchanges, at156fc7fde1, into Hypervel's documentation. Porting one of the Wayfinder changes exposed a framework bug: middleware that a provider added to a group during boot was lost once the HTTP kernel was built. That's fixed too.Upstream Updates
Telescope
telescope:listandtelescope:showcommands.telescope:listlists recent entries, optionally of one type, filtered by tag, batch or family hash, with--beforepagination and JSON output.telescope:showdisplays one entry and its related batch entries, and accepts a full or shortened UUID,latestorlatest:{type}. Telescope doesn't record either command. Hypervel's commands return integer exit codes, throw on JSON encoding errors and show a scheduled task's recorded status, exit code and exception. Upstream has no user documentation for the commands, so the Telescope page gains a section on viewing entries from the command line.uuidcolumn can't be compared with it. The dashboard returned a 500 andtelescope:showprinted a raw SQL error. Malformed IDs now throwModelNotFoundException, and the lookup is tested on PostgreSQL, MariaDB, MySQL and SQLite.set-cookieas well ascookiein the publishedTelescopeServiceProvider, so cookies issued in responses aren't stored. Response headers use the same hidden list.Telescope::cspNonce()and escaped its value. Hypervel already had both, with the nonce held per coroutine. Its tests move to upstream'sCspNonceTest, keeping Hypervel's checks on each style and script tag, the escaped value and coroutine isolation. Upstream's CSP nonce documentation is added to the Telescope page..npmrcalready set a minimum release age, and now disables install scripts too, as Horizon and Workbench do.^1.20.0and^2.31.0, matching Horizon.Tinker
Wayfinder
'get /photos'and'post /photos', when two routes share a URI. Hypervel merged those routes into one entry with combined verbs, and rejected registrations whose parameter metadata differed. It now uses upstream's keys, so each registration keeps its own defaults. A route registered for several verbs joins them with|, and HEAD is dropped when GET is present. The generator test, fixture controller and documentation follow upstream.Laravel documentation
This brings Laravel documentation changes made since Hypervel's documentation was imported into a first group of pages. Where Hypervel had its own wording for the same content, upstream's wording replaces it, adapted for Hypervel. Hypervel-only features and intentional differences stay, and each documented behavior was checked against Hypervel's source. The numbers below are laravel/docs pull requests.
ratioBetween(11174), uses arrays for every rule definition (11176, 11179) and listsMinamong the file rules (11255).Accept: application/jsonheader, which selects the JSON responses.Number::parse(11217), by-referencereduceInto(11283), Sanctum's remember me support (11211), Echo'suseSocketId(11222), the attributed#[Scope]variant's limitations (11229), SIGTERM handling (11208) and--timeoutwith--once(11287).reportoption (11367), queue routes for broadcasts and queued listeners (11366), Mercure installation (11379), encrypted private channels (11394), SES tenants (commit68f903aca7) and the migration events table (11244, 11393)._typecolumns before_id(11188),app.jsinstead of the removedbootstrap.js(11199), no beta notice for automatic eager loading (11317),crossJoincombinations (11321) and the duplicate notifications testing anchor (11291).b0fbeae094anda52b24e4db), code block languages (11337), thegroupByRawheading (11336), table overflow wrappers (11248) and the Mailgun regions link (11250).4350436469).Pull requests 11364, 11387, 11392 and 11393 and commit
a52b24e4dbalso change pages that aren't reconciled yet. Those pages will be updated separately.Additional Hypervel Fixes
route:listand in Wayfinder. Middleware a provider pushed onto a group during boot, or an alias it replaced, was lost.Application::boot()now builds the bound HTTP kernel before providers boot, and the separate builds inroute:list, Wayfinder and the route middleware testing concern are removed. Tests cover the boot order, and a provider's group and alias changes surviving a real request with the default and a custom kernel.DateTimeZoneas a JSON object with its internal fields. The dashboard displayed that object, andtelescope:showfailed rendering it. Telescope now records the timezone name. Upstream has the same bug.telescope:showfailed. Closures are now recorded asClosure, as closure routes already appear in the controller action. Upstream has the same bug.telescope:listandtelescope:showprinted recorded data through the console formatter, which strips text that looks like a console style tag, such as<info>, and drops a backslash before<or>. SQL, messages, code lines and response bodies could show different text from what was recorded, and--jsonoutput could become invalid JSON. JSON output and content blocks are now written raw, and recorded text in styled lines and tables is escaped.telescope:listalso validates--before, which caused a SQL error on PostgreSQL and returned the wrong page on MySQL and SQLite. Upstream has the same bugs.queue:work --jsonaltered exception messages, and dropped the failed-job line entirely when a message contained invalid UTF-8. The JSON output ofdb:show,db:table,model:show,dev:listandschedule:listcould change or break on table comments, defaults and shell commands. These commands now write raw JSON, and the database commands escape comments and defaults in their text output. Laravel writes these the same way.$shouldRecord,$entriesQueue,$updatesQueueand$nonceAttributeproperties are replaced byisRecording(),getEntriesQueue()andgetUpdatesQueue().Telescope::store()waits for the current coroutine to finish unlesstelescope.deferis false.Content-Security-Policyheader, as the Horizon docs do. The migration events table now saysDatabaseRefreshedfires before any seeders run.mainuntil Wayfinder v1, and how Laravel documentation changes are reconciled.The changed tests, the Telescope, Tinker, Testbench, Database, Console, Queue, Concurrency and Horizon suites, the Wayfinder PHP and JavaScript suites with and without cached routes, the Wayfinder type check, formatting and static analysis pass locally. The Telescope dashboard builds with install scripts disabled, and every internal documentation link and anchor resolves. The full suite also ran locally, and its one failure was the batch watcher test's memory limit, fixed above.
Summary by cubic
Brings Hypervel's Telescope, Tinker, Wayfinder and first group of Laravel documentation pages up to date with their upstream counterparts, and fixes a framework ordering bug this exposed: middleware and aliases a provider applied to the router during boot were lost once the HTTP kernel was built.
Upstream Updates
telescope:listandtelescope:show, cancels dashboard requests when leaving a screen, hidesset-cookieheaders, and rebuilds its assets with updated axios and moment; malformed UUID lookups now throwModelNotFoundException.laravel/docschanges is reconciled across the documentation pages, with Hypervel-only content kept.Closure.Hypervel Fixes
Application::boot()now resolves the HTTP kernel before providers boot, so provider middleware group and alias changes survive real requests; the separate builds inroute:list, Wayfinder and the route middleware test concern are removed.telescope:list,telescope:show,db:show,db:table,model:show,dev:list,schedule:listand the concurrency process driver's envelope;queue:work --jsonsubstitutes invalid UTF-8 instead of failing. Database text output escapes comments and defaults.telescope:listalso validates its--beforecursor.Written for commit 2217eae. Summary will update on new commits.
Note
Add
telescope:listandtelescope:showCLI commands and sync Telescope, Tinker, Wayfinder docstelescope:listandtelescope:showconsole commands with filtering by type, tag, batch, and cursor, plus JSON output; registered inTelescopeServiceProviderand supported by a sharedFormatsOutputtraitfindnow accepts string UUIDs and resolves shortened UUID prefixes; closure middleware andDateTimeZonevalues serialize correctly in request and schedule entriesApplication.boot, replacing per-command and test-trait kernel resolution; WayfinderGenerateCommandcollects URL defaults from global middleware and keys shared-URI routes by verbEntriesRepository::findparameter narrowed frommixedtostring; malformed identifiers now raiseModelNotFoundExceptionimmediately, and generated Wayfinder route dictionaries use verb-prefixed keys for duplicate URIsMacroscope summarized 2217eae.