diff --git a/.docker/.bashrc b/.docker/.bashrc
new file mode 100644
index 0000000..e1b259a
--- /dev/null
+++ b/.docker/.bashrc
@@ -0,0 +1,4 @@
+# Aliases
+alias ls='ls --color=auto -F'
+alias ll='ls --color=auto -lF'
+alias art='php artisan'
\ No newline at end of file
diff --git a/.docker/apache/Dockerfile b/.docker/apache/Dockerfile
new file mode 100644
index 0000000..b9febd4
--- /dev/null
+++ b/.docker/apache/Dockerfile
@@ -0,0 +1,23 @@
+FROM httpd:2.4-bookworm AS base_build
+
+ARG DOCUMENT_ROOT
+ENV DOCUMENT_ROOT=${DOCUMENT_ROOT:-/var/www/html}
+
+RUN mkdir -p /var/www/html
+COPY .docker/.bashrc /root/.bashrc
+
+# Local Dev
+FROM base_build AS local_build
+COPY .docker/apache/httpd.conf /usr/local/apache2/conf/httpd.conf
+
+# Staging
+FROM base_build AS staging_build
+COPY .docker/apache/httpd.conf /usr/local/apache2/conf/httpd.conf
+WORKDIR ${DOCUMENT_ROOT}
+COPY ./public public
+
+# Production
+FROM base_build AS production_build
+COPY .docker/apache/httpd.conf /usr/local/apache2/conf/httpd.conf
+WORKDIR ${DOCUMENT_ROOT}
+COPY ./public public
\ No newline at end of file
diff --git a/.docker/apache/httpd.conf b/.docker/apache/httpd.conf
new file mode 100644
index 0000000..69c9f42
--- /dev/null
+++ b/.docker/apache/httpd.conf
@@ -0,0 +1,553 @@
+#
+# This is the main Apache HTTP server configuration file. It contains the
+# configuration directives that give the server its instructions.
+# See for detailed information.
+# In particular, see
+#
+# for a discussion of each configuration directive.
+#
+# Do NOT simply read the instructions in here without understanding
+# what they do. They're here only as hints or reminders. If you are unsure
+# consult the online docs. You have been warned.
+#
+# Configuration and logfile names: If the filenames you specify for many
+# of the server's control files begin with "/" (or "drive:/" for Win32), the
+# server will use that explicit path. If the filenames do *not* begin
+# with "/", the value of ServerRoot is prepended -- so "logs/access_log"
+# with ServerRoot set to "/usr/local/apache2" will be interpreted by the
+# server as "/usr/local/apache2/logs/access_log", whereas "/logs/access_log"
+# will be interpreted as '/logs/access_log'.
+
+#
+# ServerRoot: The top of the directory tree under which the server's
+# configuration, error, and log files are kept.
+#
+# Do not add a slash at the end of the directory path. If you point
+# ServerRoot at a non-local disk, be sure to specify a local disk on the
+# Mutex directive, if file-based mutexes are used. If you wish to share the
+# same ServerRoot for multiple httpd daemons, you will need to change at
+# least PidFile.
+#
+ServerRoot "/usr/local/apache2"
+
+#
+# Mutex: Allows you to set the mutex mechanism and mutex file directory
+# for individual mutexes, or change the global defaults
+#
+# Uncomment and change the directory if mutexes are file-based and the default
+# mutex file directory is not on a local disk or is not appropriate for some
+# other reason.
+#
+# Mutex default:logs
+
+#
+# Listen: Allows you to bind Apache to specific IP addresses and/or
+# ports, instead of the default. See also the
+# directive.
+#
+# Change this to Listen on specific IP addresses as shown below to
+# prevent Apache from glomming onto all bound IP addresses.
+#
+#Listen 12.34.56.78:80
+Listen 80
+
+#
+# Dynamic Shared Object (DSO) Support
+#
+# To be able to use the functionality of a module which was built as a DSO you
+# have to place corresponding `LoadModule' lines at this location so the
+# directives contained in it are actually available _before_ they are used.
+# Statically compiled modules (those listed by `httpd -l') do not need
+# to be loaded here.
+#
+# Example:
+# LoadModule foo_module modules/mod_foo.so
+#
+LoadModule mpm_event_module modules/mod_mpm_event.so
+#LoadModule mpm_prefork_module modules/mod_mpm_prefork.so
+#LoadModule mpm_worker_module modules/mod_mpm_worker.so
+LoadModule authn_file_module modules/mod_authn_file.so
+#LoadModule authn_dbm_module modules/mod_authn_dbm.so
+#LoadModule authn_anon_module modules/mod_authn_anon.so
+#LoadModule authn_dbd_module modules/mod_authn_dbd.so
+#LoadModule authn_socache_module modules/mod_authn_socache.so
+LoadModule authn_core_module modules/mod_authn_core.so
+LoadModule authz_host_module modules/mod_authz_host.so
+LoadModule authz_groupfile_module modules/mod_authz_groupfile.so
+LoadModule authz_user_module modules/mod_authz_user.so
+#LoadModule authz_dbm_module modules/mod_authz_dbm.so
+#LoadModule authz_owner_module modules/mod_authz_owner.so
+#LoadModule authz_dbd_module modules/mod_authz_dbd.so
+LoadModule authz_core_module modules/mod_authz_core.so
+LoadModule authnz_ldap_module modules/mod_authnz_ldap.so
+#LoadModule authnz_fcgi_module modules/mod_authnz_fcgi.so
+LoadModule access_compat_module modules/mod_access_compat.so
+LoadModule auth_basic_module modules/mod_auth_basic.so
+#LoadModule auth_form_module modules/mod_auth_form.so
+#LoadModule auth_digest_module modules/mod_auth_digest.so
+#LoadModule allowmethods_module modules/mod_allowmethods.so
+#LoadModule isapi_module modules/mod_isapi.so
+#LoadModule file_cache_module modules/mod_file_cache.so
+#LoadModule cache_module modules/mod_cache.so
+#LoadModule cache_disk_module modules/mod_cache_disk.so
+#LoadModule cache_socache_module modules/mod_cache_socache.so
+#LoadModule socache_shmcb_module modules/mod_socache_shmcb.so
+#LoadModule socache_dbm_module modules/mod_socache_dbm.so
+#LoadModule socache_memcache_module modules/mod_socache_memcache.so
+#LoadModule socache_redis_module modules/mod_socache_redis.so
+#LoadModule watchdog_module modules/mod_watchdog.so
+#LoadModule macro_module modules/mod_macro.so
+#LoadModule dbd_module modules/mod_dbd.so
+#LoadModule bucketeer_module modules/mod_bucketeer.so
+#LoadModule dumpio_module modules/mod_dumpio.so
+#LoadModule echo_module modules/mod_echo.so
+#LoadModule example_hooks_module modules/mod_example_hooks.so
+#LoadModule case_filter_module modules/mod_case_filter.so
+#LoadModule case_filter_in_module modules/mod_case_filter_in.so
+#LoadModule example_ipc_module modules/mod_example_ipc.so
+#LoadModule buffer_module modules/mod_buffer.so
+#LoadModule data_module modules/mod_data.so
+#LoadModule ratelimit_module modules/mod_ratelimit.so
+LoadModule reqtimeout_module modules/mod_reqtimeout.so
+#LoadModule ext_filter_module modules/mod_ext_filter.so
+#LoadModule request_module modules/mod_request.so
+#LoadModule include_module modules/mod_include.so
+LoadModule filter_module modules/mod_filter.so
+#LoadModule reflector_module modules/mod_reflector.so
+#LoadModule substitute_module modules/mod_substitute.so
+#LoadModule sed_module modules/mod_sed.so
+#LoadModule charset_lite_module modules/mod_charset_lite.so
+#LoadModule deflate_module modules/mod_deflate.so
+#LoadModule xml2enc_module modules/mod_xml2enc.so
+#LoadModule proxy_html_module modules/mod_proxy_html.so
+#LoadModule brotli_module modules/mod_brotli.so
+LoadModule mime_module modules/mod_mime.so
+LoadModule ldap_module modules/mod_ldap.so
+LoadModule log_config_module modules/mod_log_config.so
+#LoadModule log_debug_module modules/mod_log_debug.so
+#LoadModule log_forensic_module modules/mod_log_forensic.so
+#LoadModule logio_module modules/mod_logio.so
+#LoadModule lua_module modules/mod_lua.so
+LoadModule env_module modules/mod_env.so
+#LoadModule mime_magic_module modules/mod_mime_magic.so
+#LoadModule cern_meta_module modules/mod_cern_meta.so
+#LoadModule expires_module modules/mod_expires.so
+LoadModule headers_module modules/mod_headers.so
+#LoadModule ident_module modules/mod_ident.so
+#LoadModule usertrack_module modules/mod_usertrack.so
+#LoadModule unique_id_module modules/mod_unique_id.so
+LoadModule setenvif_module modules/mod_setenvif.so
+LoadModule version_module modules/mod_version.so
+#LoadModule remoteip_module modules/mod_remoteip.so
+
+LoadModule proxy_module modules/mod_proxy.so
+# LoadModule proxy_connect_module modules/mod_proxy_connect.so
+# LoadModule proxy_ftp_module modules/mod_proxy_ftp.so
+LoadModule proxy_http_module modules/mod_proxy_http.so
+LoadModule proxy_fcgi_module modules/mod_proxy_fcgi.so
+# LoadModule proxy_scgi_module modules/mod_proxy_scgi.so
+# LoadModule proxy_uwsgi_module modules/mod_proxy_uwsgi.so
+# LoadModule proxy_fdpass_module modules/mod_proxy_fdpass.so
+# LoadModule proxy_wstunnel_module modules/mod_proxy_wstunnel.so
+# LoadModule proxy_ajp_module modules/mod_proxy_ajp.so
+# LoadModule proxy_balancer_module modules/mod_proxy_balancer.so
+# LoadModule proxy_express_module modules/mod_proxy_express.so
+# LoadModule proxy_hcheck_module modules/mod_proxy_hcheck.so
+
+#LoadModule session_module modules/mod_session.so
+#LoadModule session_cookie_module modules/mod_session_cookie.so
+#LoadModule session_crypto_module modules/mod_session_crypto.so
+#LoadModule session_dbd_module modules/mod_session_dbd.so
+#LoadModule slotmem_shm_module modules/mod_slotmem_shm.so
+#LoadModule slotmem_plain_module modules/mod_slotmem_plain.so
+#LoadModule ssl_module modules/mod_ssl.so
+#LoadModule optional_hook_export_module modules/mod_optional_hook_export.so
+#LoadModule optional_hook_import_module modules/mod_optional_hook_import.so
+#LoadModule optional_fn_import_module modules/mod_optional_fn_import.so
+#LoadModule optional_fn_export_module modules/mod_optional_fn_export.so
+#LoadModule dialup_module modules/mod_dialup.so
+#LoadModule http2_module modules/mod_http2.so
+#LoadModule proxy_http2_module modules/mod_proxy_http2.so
+#LoadModule md_module modules/mod_md.so
+LoadModule lbmethod_byrequests_module modules/mod_lbmethod_byrequests.so
+LoadModule lbmethod_bytraffic_module modules/mod_lbmethod_bytraffic.so
+LoadModule lbmethod_bybusyness_module modules/mod_lbmethod_bybusyness.so
+LoadModule lbmethod_heartbeat_module modules/mod_lbmethod_heartbeat.so
+LoadModule unixd_module modules/mod_unixd.so
+#LoadModule heartbeat_module modules/mod_heartbeat.so
+#LoadModule heartmonitor_module modules/mod_heartmonitor.so
+#LoadModule dav_module modules/mod_dav.so
+LoadModule status_module modules/mod_status.so
+LoadModule autoindex_module modules/mod_autoindex.so
+#LoadModule asis_module modules/mod_asis.so
+#LoadModule info_module modules/mod_info.so
+#LoadModule suexec_module modules/mod_suexec.so
+
+ #LoadModule cgid_module modules/mod_cgid.so
+
+
+ #LoadModule cgi_module modules/mod_cgi.so
+
+#LoadModule dav_fs_module modules/mod_dav_fs.so
+#LoadModule dav_lock_module modules/mod_dav_lock.so
+#LoadModule vhost_alias_module modules/mod_vhost_alias.so
+#LoadModule negotiation_module modules/mod_negotiation.so
+LoadModule dir_module modules/mod_dir.so
+#LoadModule imagemap_module modules/mod_imagemap.so
+#LoadModule actions_module modules/mod_actions.so
+#LoadModule speling_module modules/mod_speling.so
+#LoadModule userdir_module modules/mod_userdir.so
+LoadModule alias_module modules/mod_alias.so
+LoadModule rewrite_module modules/mod_rewrite.so
+
+
+#
+# If you wish httpd to run as a different user or group, you must run
+# httpd as root initially and it will switch.
+#
+# User/Group: The name (or #number) of the user/group to run httpd as.
+# It is usually good practice to create a dedicated user and group for
+# running httpd, as with most system services.
+#
+User www-data
+Group www-data
+
+
+
+# 'Main' server configuration
+#
+# The directives in this section set up the values used by the 'main'
+# server, which responds to any requests that aren't handled by a
+# definition. These values also provide defaults for
+# any containers you may define later in the file.
+#
+# All of these directives may appear inside containers,
+# in which case these default settings will be overridden for the
+# virtual host being defined.
+#
+
+#
+# ServerAdmin: Your address, where problems with the server should be
+# e-mailed. This address appears on some server-generated pages, such
+# as error documents. e.g. admin@your-domain.com
+#
+ServerAdmin you@example.com
+
+#
+# ServerName gives the name and port that the server uses to identify itself.
+# This can often be determined automatically, but we recommend you specify
+# it explicitly to prevent problems during startup.
+#
+# If your host doesn't have a registered DNS name, enter its IP address here.
+#
+ServerName profiles.test:80
+
+#
+# Deny access to the entirety of your server's filesystem. You must
+# explicitly permit access to web content directories in other
+# blocks below.
+#
+
+ AllowOverride none
+ Require all denied
+
+
+#
+# Note that from this point forward you must specifically allow
+# particular features to be enabled - so if something's not working as
+# you might expect, make sure that you have specifically enabled it
+# below.
+#
+
+#
+# DocumentRoot: The directory out of which you will serve your
+# documents. By default, all requests are taken from this directory, but
+# symbolic links and aliases may be used to point to other locations.
+#
+DocumentRoot "/var/www/html/public"
+
+
+ Options Indexes FollowSymLinks
+ AllowOverride None
+ Require all granted
+
+
+
+ Options Indexes FollowSymLinks
+ AllowOverride All
+ Require all granted
+
+
+
+ Options Indexes FollowSymLinks
+ AllowOverride None
+ Require all granted
+
+
+#
+# DirectoryIndex: sets the file that Apache will serve if a directory
+# is requested.
+#
+
+ DirectoryIndex index.php index.html
+
+
+#
+# PHP
+#
+
+ # SSLOptions +StdEnvVars
+ SetHandler "proxy:fcgi://php.profiles:9000"
+ #SetHandler proxy:unix:/run/php-fpm/www.sock|fcgi://localhost
+
+
+#
+# The following lines prevent .htaccess and .htpasswd files from being
+# viewed by Web clients.
+#
+
+ Require all denied
+
+
+#
+# ErrorLog: The location of the error log file.
+# If you do not specify an ErrorLog directive within a
+# container, error messages relating to that virtual host will be
+# logged here. If you *do* define an error logfile for a
+# container, that host's errors will be logged there and not here.
+#
+ErrorLog /proc/self/fd/2
+
+#
+# LogLevel: Control the number of messages logged to the error_log.
+# Possible values include: debug, info, notice, warn, error, crit,
+# alert, emerg.
+#
+LogLevel warn
+
+
+ #
+ # The following directives define some format nicknames for use with
+ # a CustomLog directive (see below).
+ #
+ LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combined
+ LogFormat "%h %l %u %t \"%r\" %>s %b" common
+
+
+ # You need to enable mod_logio.c to use %I and %O
+ LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\" %I %O" combinedio
+
+
+ #
+ # The location and format of the access logfile (Common Logfile Format).
+ # If you do not define any access logfiles within a
+ # container, they will be logged here. Contrariwise, if you *do*
+ # define per- access logfiles, transactions will be
+ # logged therein and *not* in this file.
+ #
+ # CustomLog /proc/self/fd/1 common
+
+ #
+ # If you prefer a logfile with access, agent, and referer information
+ # (Combined Logfile Format) you can use the following directive.
+ #
+ CustomLog /proc/self/fd/1 combined
+
+
+
+ #
+ # Redirect: Allows you to tell clients about documents that used to
+ # exist in your server's namespace, but do not anymore. The client
+ # will make a new request for the document at its new location.
+ # Example:
+ # Redirect permanent /foo http://www.example.com/bar
+
+ #
+ # Alias: Maps web paths into filesystem paths and is used to
+ # access content that does not live under the DocumentRoot.
+ # Example:
+ # Alias /webpath /full/filesystem/path
+ #
+ # If you include a trailing / on /webpath then the server will
+ # require it to be present in the URL. You will also likely
+ # need to provide a section to allow access to
+ # the filesystem path.
+
+ #
+ # ScriptAlias: This controls which directories contain server scripts.
+ # ScriptAliases are essentially the same as Aliases, except that
+ # documents in the target directory are treated as applications and
+ # run by the server when requested rather than as documents sent to the
+ # client. The same rules about trailing "/" apply to ScriptAlias
+ # directives as to Alias.
+ #
+ ScriptAlias /cgi-bin/ "/usr/local/apache2/cgi-bin/"
+
+
+
+
+ #
+ # ScriptSock: On threaded servers, designate the path to the UNIX
+ # socket used to communicate with the CGI daemon of mod_cgid.
+ #
+ #Scriptsock cgisock
+
+
+#
+# "/usr/local/apache2/cgi-bin" should be changed to whatever your ScriptAliased
+# CGI directory exists, if you have that configured.
+#
+
+ AllowOverride None
+ Options None
+ Require all granted
+
+
+
+ #
+ # Avoid passing HTTP_PROXY environment to CGI's on this or any proxied
+ # backend servers which have lingering "httpoxy" defects.
+ # 'Proxy' request header is undefined by the IETF, not listed by IANA
+ #
+ RequestHeader unset Proxy early
+
+
+
+ #
+ # TypesConfig points to the file containing the list of mappings from
+ # filename extension to MIME-type.
+ #
+ TypesConfig conf/mime.types
+
+ #
+ # AddType allows you to add to or override the MIME configuration
+ # file specified in TypesConfig for specific file types.
+ #
+ #AddType application/x-gzip .tgz
+ #
+ # AddEncoding allows you to have certain browsers uncompress
+ # information on the fly. Note: Not all browsers support this.
+ #
+ #AddEncoding x-compress .Z
+ #AddEncoding x-gzip .gz .tgz
+ #
+ # If the AddEncoding directives above are commented-out, then you
+ # probably should define those extensions to indicate media types:
+ #
+ AddType application/x-compress .Z
+ AddType application/x-gzip .gz .tgz
+
+ #
+ # AddHandler allows you to map certain file extensions to "handlers":
+ # actions unrelated to filetype. These can be either built into the server
+ # or added with the Action directive (see below)
+ #
+ # To use CGI scripts outside of ScriptAliased directories:
+ # (You will also need to add "ExecCGI" to the "Options" directive.)
+ #
+ #AddHandler cgi-script .cgi
+
+ # For type maps (negotiated resources):
+ #AddHandler type-map var
+
+ #
+ # Filters allow you to process content before it is sent to the client.
+ #
+ # To parse .shtml files for server-side includes (SSI):
+ # (You will also need to add "Includes" to the "Options" directive.)
+ #
+ #AddType text/html .shtml
+ #AddOutputFilter INCLUDES .shtml
+
+
+#
+# The mod_mime_magic module allows the server to use various hints from the
+# contents of the file itself to determine its type. The MIMEMagicFile
+# directive tells the module where the hint definitions are located.
+#
+#MIMEMagicFile conf/magic
+
+#
+# Customizable error responses come in three flavors:
+# 1) plain text 2) local redirects 3) external redirects
+#
+# Some examples:
+#ErrorDocument 500 "The server made a boo boo."
+#ErrorDocument 404 /missing.html
+#ErrorDocument 404 "/cgi-bin/missing_handler.pl"
+#ErrorDocument 402 http://www.example.com/subscription_info.html
+#
+
+#
+# MaxRanges: Maximum number of Ranges in a request before
+# returning the entire resource, or one of the special
+# values 'default', 'none' or 'unlimited'.
+# Default setting is to accept 200 Ranges.
+#MaxRanges unlimited
+
+#
+# EnableMMAP and EnableSendfile: On systems that support it,
+# memory-mapping or the sendfile syscall may be used to deliver
+# files. This usually improves server performance, but must
+# be turned off when serving from networked-mounted
+# filesystems or if support for these functions is otherwise
+# broken on your system.
+# Defaults: EnableMMAP On, EnableSendfile Off
+#
+#EnableMMAP off
+#EnableSendfile on
+
+# Supplemental configuration
+#
+# The configuration files in the conf/extra/ directory can be
+# included to add extra features or to modify the default configuration of
+# the server, or you may simply copy their contents here and change as
+# necessary.
+
+# Server-pool management (MPM specific)
+#Include conf/extra/httpd-mpm.conf
+
+# Multi-language error messages
+#Include conf/extra/httpd-multilang-errordoc.conf
+
+# Fancy directory listings
+#Include conf/extra/httpd-autoindex.conf
+
+# Language settings
+#Include conf/extra/httpd-languages.conf
+
+# User home directories
+#Include conf/extra/httpd-userdir.conf
+
+# Real-time info on requests and configuration
+#Include conf/extra/httpd-info.conf
+
+# Virtual hosts
+#Include conf/extra/httpd-vhosts.conf
+
+# Local access to the Apache HTTP Server Manual
+#Include conf/extra/httpd-manual.conf
+
+# Distributed authoring and versioning (WebDAV)
+#Include conf/extra/httpd-dav.conf
+
+# Various default settings
+#Include conf/extra/httpd-default.conf
+
+# Configure mod_proxy_html to understand HTML4/XHTML1
+
+Include conf/extra/proxy-html.conf
+
+
+# Secure (SSL/TLS) connections
+#Include conf/extra/httpd-ssl.conf
+#
+# Note: The following must must be present to support
+# starting without SSL on platforms with no /dev/random equivalent
+# but a statically compiled-in mod_ssl.
+#
+
+SSLRandomSeed startup builtin
+SSLRandomSeed connect builtin
+
+
diff --git a/.docker/compose-overrides/production.yml b/.docker/compose-overrides/production.yml
new file mode 100644
index 0000000..5147b7b
--- /dev/null
+++ b/.docker/compose-overrides/production.yml
@@ -0,0 +1,12 @@
+services:
+ web.profiles:
+ # don't bind mount host volume
+ volumes: !reset []
+ # networks: !override
+ # - profiles
+
+ php.profiles:
+ # don't bind mount host volume
+ volumes: !reset []
+ # networks: !override
+ # - profiles
\ No newline at end of file
diff --git a/.docker/php/Dockerfile b/.docker/php/Dockerfile
new file mode 100644
index 0000000..16f8589
--- /dev/null
+++ b/.docker/php/Dockerfile
@@ -0,0 +1,92 @@
+FROM php:8.3-fpm AS base_build
+
+ARG APP_ENV
+ENV APP_ENV=${APP_ENV:-production}
+
+ARG DOCUMENT_ROOT
+ENV DOCUMENT_ROOT=${DOCUMENT_ROOT:-/var/www/html}
+
+# Common
+RUN apt-get update
+COPY .docker/.bashrc /root/.bashrc
+
+# PHP
+COPY .docker/php/php.ini $PHP_INI_DIR/conf.d/zzz-01-custom.ini
+RUN apt-get install -y libzip-dev libldap2-dev
+RUN rm -rf /var/lib/apt/lists/*
+RUN docker-php-ext-configure ldap --with-libdir=lib/$(arch)-linux-gnu/
+RUN docker-php-ext-install opcache pdo pdo_mysql mysqli zip exif pcntl ldap
+
+# Composer
+COPY --from=composer:latest /usr/bin/composer /usr/local/bin/composer
+
+# Sendmail (for Mailpit)
+FROM base_build AS mail_build
+RUN apt-get update \
+ && apt-get install -y git \
+ && cd ~ \
+ && curl -o go.tar.gz https://dl.google.com/go/go1.23.8.linux-arm64.tar.gz \
+ && tar -C /usr/local -xzf go.tar.gz \
+ && export PATH=$PATH:/usr/local/go/bin \
+ && git clone https://github.com/axllent/mailpit.git \
+ && cd mailpit/sendmail \
+ && go build -ldflags "-s -w" \
+ && cp ~/mailpit/sendmail/sendmail /usr/local/bin/sendmail
+
+# App files
+FROM base_build AS app_files
+WORKDIR $DOCUMENT_ROOT
+COPY . .
+RUN cp ".env.${APP_ENV}" .env
+RUN chown -R www-data:www-data storage
+
+# Vendor files
+FROM app_files AS vendor_files
+WORKDIR $DOCUMENT_ROOT
+RUN php -d allow_url_fopen=On /usr/local/bin/composer install
+
+# Local Dev
+FROM base_build AS local_build
+RUN cp "$PHP_INI_DIR/php.ini-development" "$PHP_INI_DIR/php.ini"
+
+# Imagick
+RUN apt-get update && apt-get install -y libmagickwand-dev \
+ && pecl install imagick \
+ && docker-php-ext-enable imagick
+
+# Xdebug
+RUN pecl install xdebug \
+ && docker-php-ext-enable xdebug
+COPY .docker/php/xdebug.ini $PHP_INI_DIR/conf.d/zzz-xdebug.ini
+
+COPY --from=mail_build /usr/local/bin/sendmail /usr/local/bin/sendmail
+COPY .docker/php/email.ini $PHP_INI_DIR/conf.d/zzz-email.ini
+
+# Node.js and Puppeteer for Browsershot
+RUN apt-get update && apt-get install -y \
+ nodejs \
+ npm \
+ --no-install-recommends \
+ && npm install -g puppeteer \
+ && apt-get clean && rm -rf /var/lib/apt/lists/*
+
+# Entrypoint
+COPY .docker/php/entrypoint.sh /usr/local/bin/entrypoint.sh
+RUN chmod +x /usr/local/bin/entrypoint.sh
+ENTRYPOINT ["/usr/local/bin/entrypoint.sh"]
+
+# Staging
+FROM base_build AS staging_build
+RUN cp "$PHP_INI_DIR/php.ini-production" "$PHP_INI_DIR/php.ini"
+WORKDIR $DOCUMENT_ROOT
+COPY --from=app_files $DOCUMENT_ROOT .
+COPY --from=vendor_files $DOCUMENT_ROOT/vendor vendor
+RUN mkdir /var/www/html/shared
+
+# Prod
+FROM base_build AS production_build
+RUN cp "$PHP_INI_DIR/php.ini-production" "$PHP_INI_DIR/php.ini"
+WORKDIR $DOCUMENT_ROOT
+COPY --from=app_files $DOCUMENT_ROOT .
+COPY --from=vendor_files $DOCUMENT_ROOT/vendor vendor
+RUN mkdir /var/www/html/shared
\ No newline at end of file
diff --git a/.docker/php/email.ini b/.docker/php/email.ini
new file mode 100644
index 0000000..3c45473
--- /dev/null
+++ b/.docker/php/email.ini
@@ -0,0 +1,9 @@
+[mail function]
+; For Unix only. You may supply arguments as well (default: "sendmail -t -i").
+; http://php.net/sendmail-path
+
+; Use mailpit
+; sendmail_path = "/usr/local/bin/mailpit sendmail"
+sendmail_path = "/usr/local/bin/sendmail -S email:1025"
+; Use mailhog for sending emails
+; sendmail_path = "/usr/local/bin/mhsendmail --smtp-addr=mailhog:1025"
\ No newline at end of file
diff --git a/.docker/php/entrypoint.sh b/.docker/php/entrypoint.sh
new file mode 100644
index 0000000..8301440
--- /dev/null
+++ b/.docker/php/entrypoint.sh
@@ -0,0 +1,7 @@
+#!/bin/bash
+
+if [ ! -L public/storage ]; then
+ php artisan storage:link
+fi
+
+exec php-fpm
\ No newline at end of file
diff --git a/.docker/php/php.ini b/.docker/php/php.ini
new file mode 100644
index 0000000..8885e60
--- /dev/null
+++ b/.docker/php/php.ini
@@ -0,0 +1,51 @@
+; Add America/Chicago string for replacing with machine timezone
+date.timezone = "America/Chicago"
+
+; Max execution time per request
+max_execution_time = 300
+
+; Max memory per instance
+memory_limit = 2G
+
+;The maximum size of an uploaded file.
+upload_max_filesize = 128M
+
+;Sets max size of post data allowed. This setting also affects file upload. To upload large files, this value must be larger than upload_max_filesize
+post_max_size = 128M
+
+session.auto_start = off
+session.gc_probability = 0
+session.save_path = "/tmp"
+suhosin.session.cryptua = off
+
+; Disable garbage collector
+zend.enable_gc = off
+
+[opcache]
+opcache.enable = 1
+opcache.enable_cli = 1
+opcache.memory_consumption = 2048
+opcache.interned_strings_buffer = 20
+opcache.file_cache=1
+opcache.max_accelerated_files = 80000
+opcache.max_wasted_percentage = 5
+opcache.use_cwd = 1
+opcache.validate_timestamps = 1
+opcache.revalidate_freq = 0
+opcache.file_update_protection = 2
+opcache.revalidate_path = 0
+opcache.save_comments = 1
+opcache.load_comments = 1
+opcache.fast_shutdown = 1
+opcache.enable_file_override = 0
+opcache.optimization_level = 0xffffffff
+opcache.inherited_hack = 1
+opcache.blacklist_filename = ""
+opcache.max_file_size = 0
+opcache.consistency_checks = 0
+opcache.force_restart_timeout = 180
+opcache.error_log = ""
+opcache.log_verbosity_level = 1
+opcache.preferred_memory_model = ""
+opcache.protect_memory = 0
+apc.cache_by_default = false
diff --git a/.docker/php/xdebug.ini b/.docker/php/xdebug.ini
new file mode 100644
index 0000000..50a3ffa
--- /dev/null
+++ b/.docker/php/xdebug.ini
@@ -0,0 +1,7 @@
+[xdebug]
+xdebug.mode=debug
+xdebug.start_with_request=yes
+xdebug.client_host=host.docker.internal
+xdebug.client_port=9003
+xdebug.idekey=VSCODE
+xdebug.log=/tmp/xdebug.log
\ No newline at end of file
diff --git a/.dockerignore b/.dockerignore
new file mode 100644
index 0000000..03a268b
--- /dev/null
+++ b/.dockerignore
@@ -0,0 +1,34 @@
+# Include any files or directories that you don't want to be copied to your
+# container here (e.g., local build artifacts, temporary files, etc.).
+#
+# For more help, visit the .dockerignore file reference guide at
+# https://docs.docker.com/go/build-context-dockerignore/
+
+**/.DS_Store
+**/__pycache__
+**/.venv
+**/.classpath
+**/.dockerignore
+**/.env
+**/.git
+**/.gitignore
+**/.project
+**/.settings
+**/.toolstarget
+**/.vs
+**/.vscode
+**/*.*proj.user
+**/*.dbmdl
+**/*.jfm
+**/bin
+**/charts
+**/docker-compose*
+**/compose.y*ml
+**/Dockerfile*
+**/node_modules
+**/npm-debug.log
+**/obj
+**/secrets.dev.yaml
+**/values.dev.yaml
+LICENSE
+README.md
diff --git a/.env.example b/.env.example
index 90ff1b8..14320c6 100644
--- a/.env.example
+++ b/.env.example
@@ -4,6 +4,8 @@ APP_KEY=
APP_DEBUG=true
APP_LOG_LEVEL=debug
APP_URL=http://profiles.test
+APP_ADDRESS="profiles.test"
+CONTAINER_ENV=local
#APP_BANNER_MESSAGE="This is a test of the banner message."
TESTING_MENU=true
@@ -24,6 +26,7 @@ DB_PASSWORD=
# SENTRY_ENABLE_LOGS=true
# SENTRY_LOG_LEVEL=debug
+REDIS_HOST=redis
BROADCAST_DRIVER=log
CACHE_DRIVER=file
SESSION_DRIVER=file
diff --git a/Dockerfile b/Dockerfile
new file mode 100644
index 0000000..a1b74e6
--- /dev/null
+++ b/Dockerfile
@@ -0,0 +1,63 @@
+# syntax=docker/dockerfile:1
+
+# Comments are provided throughout this file to help you get started.
+# If you need more help, visit the Dockerfile reference guide at
+# https://docs.docker.com/go/dockerfile-reference/
+
+# Want to help us make this template better? Share your feedback here: https://forms.gle/ybq9Krt8jtBL3iCk7
+
+################################################################################
+# Pick a base image to serve as the foundation for the other build stages in
+# this file.
+#
+# For illustrative purposes, the following FROM command
+# is using the alpine image (see https://hub.docker.com/_/alpine).
+# By specifying the "latest" tag, it will also use whatever happens to be the
+# most recent version of that image when you build your Dockerfile.
+# If reproducibility is important, consider using a versioned tag
+# (e.g., alpine:3.17.2) or SHA (e.g., alpine@sha256:c41ab5c992deb4fe7e5da09f67a8804a46bd0592bfdf0b1847dde0e0889d2bff).
+FROM alpine:latest AS base
+
+################################################################################
+# Create a stage for building/compiling the application.
+#
+# The following commands will leverage the "base" stage above to generate
+# a "hello world" script and make it executable, but for a real application, you
+# would issue a RUN command for your application's build process to generate the
+# executable. For language-specific examples, take a look at the Dockerfiles in
+# the Awesome Compose repository: https://github.com/docker/awesome-compose
+FROM base AS build
+RUN echo -e '#!/bin/sh\n\
+echo Hello world from $(whoami)! In order to get your application running in a container, take a look at the comments in the Dockerfile to get started.'\
+> /bin/hello.sh
+RUN chmod +x /bin/hello.sh
+
+################################################################################
+# Create a final stage for running your application.
+#
+# The following commands copy the output from the "build" stage above and tell
+# the container runtime to execute it when the image is run. Ideally this stage
+# contains the minimal runtime dependencies for the application as to produce
+# the smallest image possible. This often means using a different and smaller
+# image than the one used for building the application, but for illustrative
+# purposes the "base" image is used here.
+FROM base AS final
+
+# Create a non-privileged user that the app will run under.
+# See https://docs.docker.com/go/dockerfile-user-best-practices/
+ARG UID=10001
+RUN adduser \
+ --disabled-password \
+ --gecos "" \
+ --home "/nonexistent" \
+ --shell "/sbin/nologin" \
+ --no-create-home \
+ --uid "${UID}" \
+ appuser
+USER appuser
+
+# Copy the executable from the "build" stage.
+COPY --from=build /bin/hello.sh /bin/
+
+# What the container should run when it is started.
+ENTRYPOINT [ "/bin/hello.sh" ]
diff --git a/README.Docker.md b/README.Docker.md
new file mode 100644
index 0000000..ffca340
--- /dev/null
+++ b/README.Docker.md
@@ -0,0 +1,17 @@
+### Building and running your application
+
+When you're ready, start your application by running:
+`docker compose up --build`.
+
+### Deploying your application to the cloud
+
+First, build your image, e.g.: `docker build -t myapp .`.
+If your cloud uses a different CPU architecture than your development
+machine (e.g., you are on a Mac M1 and your cloud provider is amd64),
+you'll want to build the image for that platform, e.g.:
+`docker build --platform=linux/amd64 -t myapp .`.
+
+Then, push it to your registry, e.g. `docker push myregistry.com/myapp`.
+
+Consult Docker's [getting started](https://docs.docker.com/go/get-started-sharing/)
+docs for more detail on building and pushing.
\ No newline at end of file
diff --git a/app/Http/Controllers/ProfilesController.php b/app/Http/Controllers/ProfilesController.php
index 64fdd2b..22bef60 100644
--- a/app/Http/Controllers/ProfilesController.php
+++ b/app/Http/Controllers/ProfilesController.php
@@ -344,36 +344,34 @@ public function restore(Profile $profile): RedirectResponse
*/
public function pdfExport(Profile $profile): Response
{
- $pdf_content = Browsershot::url("{$profile->url}?paginated=false")
- ->waitUntilNetworkIdle()
- ->ignoreHttpsErrors()
- ->margins(30, 15, 30, 15);
- if (config('pdf.node')) {
- $pdf_content = $pdf_content->setNodeBinary(config('pdf.node'));
- }
-
- if (config('pdf.npm')) {
- $pdf_content = $pdf_content->setNpmBinary(config('pdf.npm'));
- }
-
- if (config('pdf.modules')) {
- $pdf_content = $pdf_content->setIncludePath(config('pdf.modules'));
- }
-
- if (config('pdf.chrome')) {
- $pdf_content = $pdf_content->setChromePath(config('pdf.chrome'));
- }
-
- if (config('pdf.chrome_arguments')) {
- $pdf_content = $pdf_content->addChromiumArguments(config('pdf.chrome_arguments'));
- }
+ /** @var User the logged-in user */
+ $user = Auth::user();
+ $editable = $user && $user->can('update', $profile);
- if (config('pdf.http_username') && config('pdf.http_password')) {
- $pdf_content = $pdf_content->authenticate(config('pdf.http_username'), config('pdf.http_password'));
+ //Abort unless profile is public or user can edit it
+ if(!$profile->public && !$editable){
+ abort(404);
}
-
- return response($pdf_content->pdf())
- ->header('Content-Type', 'application/pdf');
+
+ $html = '';
+ $html = view('profiles.show', [
+ 'profile' => $profile,
+ 'editable' => $editable,
+ 'paginated' => false,
+ 'information' => $profile->information->first(),
+ ])->render();
+
+ $pdf_temp_path = config("pdf.pdf_temp_path", '/tmp/pdf');
+
+ $pdf_content = Browsershot::html($html)
+ ->setRemoteInstance(gethostbyname('chromium'), 9222)
+ ->setCustomTempPath($pdf_temp_path)
+ ->noSandbox()
+ ->waitUntilNetworkIdle()
+ ->margins(30, 15, 30, 15)
+ ->pdf();
+
+ return response($pdf_content)->header('Content-Type', 'application/pdf');
}
}
diff --git a/compose.yml b/compose.yml
new file mode 100644
index 0000000..1782f53
--- /dev/null
+++ b/compose.yml
@@ -0,0 +1,76 @@
+services:
+ web.profiles:
+ container_name: web.profiles
+ hostname: ${APP_ADDRESS:-profiles}
+ build:
+ context: .
+ dockerfile: .docker/apache/Dockerfile
+ target: "${CONTAINER_ENV:-production}_build"
+ args:
+ CONTAINER_ENV: ${CONTAINER_ENV:-production}
+ image: ${IMAGE_NAME_WEB:-localdev/web.profiles:web-1.0}
+ volumes:
+ - ".:/var/www/html"
+ networks:
+ - profiles
+ - nginx-proxy
+ environment:
+ VIRTUAL_HOST: ${APP_ADDRESS:-profiles}
+
+ php.profiles:
+ container_name: php.profiles
+ hostname: "php.${APP_ADDRESS:-profiles}"
+ build:
+ context: .
+ dockerfile: .docker/php/Dockerfile
+ target: "${CONTAINER_ENV:-production}_build"
+ args:
+ CONTAINER_ENV: ${CONTAINER_ENV:-production}
+ APP_ENV: ${APP_ENV:-production}
+ DB_HOST: ${DB_HOST:-db}
+ DB_PORT: ${DB_PORT:-3306}
+ DB_DATABASE: ${DB_DATABASE:-profiles}
+ DB_USERNAME: ${DB_USERNAME:-root}
+ DB_PASSWORD: ${DB_PASSWORD:-root}
+ image: ${IMAGE_NAME_PHP:-localdev/php.profiles:php-1.0}
+ volumes:
+ - ".:/var/www/html"
+ - tmpfiles:${PDF_TEMP_PATH:-/tmp/pdf}
+ depends_on:
+ - chromium
+ networks:
+ - profiles
+ - localdev-shared-services
+
+ chromium:
+ image: zenika/alpine-chrome
+ container_name: chromium
+ command:
+ - "chromium-browser"
+ - "--headless"
+ - "--disable-gpu"
+ - "--no-sandbox"
+ - "--remote-debugging-address=0.0.0.0"
+ - "--remote-debugging-port=9222"
+ cap_add:
+ - SYS_ADMIN
+ volumes:
+ - tmpfiles:${PDF_TEMP_PATH:-/tmp/pdf}
+ ports:
+ - "9222:9222"
+ networks:
+ - localdev-shared-services
+ - nginx-proxy
+
+networks:
+ profiles:
+ nginx-proxy:
+ name: nginx-proxy
+ external: true
+ localdev-shared-services:
+ name: localdev-shared-services
+ external: true
+
+volumes:
+ tmpfiles:
+ driver: local
diff --git a/config/pdf.php b/config/pdf.php
index f5d1618..24d051e 100644
--- a/config/pdf.php
+++ b/config/pdf.php
@@ -61,4 +61,7 @@
'http_username' => env('PDF_USER'),
'http_password' => env('PDF_PASS'),
+ /** PDF temp path used by Browsershot::html() */
+ 'pdf_temp_path' => env('PDF_TEMP_PATH', "/tmp/pdf"),
+
];
\ No newline at end of file
diff --git a/resources/views/layout.blade.php b/resources/views/layout.blade.php
index 2bc33c5..a549987 100644
--- a/resources/views/layout.blade.php
+++ b/resources/views/layout.blade.php
@@ -19,7 +19,7 @@
-
+