Skip to content

VITE LOGIN INBOX: Migrating Login and Inbox paths to Vite - #8916

Merged
nolanpro merged 99 commits into
developfrom
VITE_INBOX
Sep 16, 2026
Merged

nolanpro merged 99 commits into
developfrom
VITE_INBOX

Conversation

@henryjonathanquispe

@henryjonathanquispe henryjonathanquispe commented Jul 20, 2026 •

Copy link
Copy Markdown
Contributor

Related Tickets & Packages

#Instructions to install

> npm run i
> npm run dev
> npm run vite:build

To update the routes:
php artisan config:clear

#MInimal changes
PACKAGE-DATA-SOURCES
https://github.com/ProcessMaker/package-data-sources/pull/492

PACKAGE-VARIABLE-FINDER
https://github.com/ProcessMaker/package-variable-finder/pull/70

Code Review Checklist

  • I have pulled this code locally and tested it on my instance, along with any associated packages.
  • This code adheres to ProcessMaker Coding Guidelines.
  • This code includes a unit test or an E2E test that tests its functionality, or is covered by an existing test.
  • This solution fixes the bug reported in the original ticket.
  • This solution does not alter the expected output of a component in a way that would break existing Processes.
  • This solution does not implement any breaking changes that would invalidate documentation or cause existing Processes to fail.
  • This solution has been tested with enterprise packages that rely on its functionality and does not introduce bugs in those packages.
  • This code does not duplicate functionality that already exists in the framework or in ProcessMaker.
  • This ticket conforms to the PRD associated with this part of ProcessMaker.

ci:deploy
ci:package-data-sources:VITE_INBOX
ci:package-variable-finder:VITE_INBOX

@henryjonathanquispe
henryjonathanquispe changed the base branch from VITE_JONAS to develop July 23, 2026 19:44
@henryjonathanquispe henryjonathanquispe changed the title VITE INBOX: POC to test the ease of migrating other views to vite VITE LOGIN INBOX: Migrating Login and Inbox to Vite Jul 23, 2026
@gitguardian

gitguardian Bot commented Jul 23, 2026 •

Copy link
Copy Markdown

⚠️ GitGuardian has uncovered 1 secret following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Detected hardcoded secret in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
34069781 Triggered Generic Password bc1d2d6 resources/views/vite/auth/login.blade.php View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secret safely. Learn here the best practices.
  3. Revoke and rotate this secret.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

@nolanpro

Copy link
Copy Markdown
Contributor

@henryjonathanquispe a few suggestions

  • See if we can avoid adding .vue to all import statements by adding it to the extensions in the config:
     // vite.config.js
     resolve: {
       extensions: ['.mjs', '.js', '.ts', '.jsx', '.tsx', '.json', '.vue'],
       // ...existing aliases
     }
    
  • Once we transition a route, we should full-on commit to it and delete the old one. So I would get rid of the VITE_VIEW and config/app.php setting, and instead, hard-code the new blade template in the controller and remove .js("resources/js/tasks/index.js", "public/js/tasks/index.js") form webpack.mix.js.
  • Going along with the above, as part of this PR, convert all login templates to use vite. For example, change.blade.php, newLogin.blade.php (is this 'newLogin' template even necessary any more?), and any template that uses auth-language-scripts and auth-language-scripts-minimal partials. That way we can get this PR super clean and self contained!
  • Update package.json: "production": "mix --production && mix --mix-config=webpack-login.mix.js --production && vite build"

@henryjonathanquispe
henryjonathanquispe force-pushed the VITE_INBOX branch 3 times, most recently from 58441fd to 327120d Compare July 24, 2026 20:11
@henryjonathanquispe

Copy link
Copy Markdown
Contributor Author

@nolanpro the PR has been updated!

@henryjonathanquispe
henryjonathanquispe force-pushed the VITE_INBOX branch 2 times, most recently from b33d3b1 to 4af7386 Compare July 27, 2026 21:01
VITE_INBOX: update AGENTS.md

VITE_INBOX: remove webpack-login, change to vite

VITE_INBOX: update task controller, remove unnecesary files changed

VITE_INBOX: remove unnecesary files changed by extension, reduce the PR

VITE_INBOX: remove tasks js files from webpack

VITE_INBOX: remove tasks js files from webpack

VITE_INBOX: update testCase

VITE_INBOX: update rutes password/* because the last changes in login
@henryjonathanquispe
henryjonathanquispe changed the base branch from develop to VITE_JONAS July 29, 2026 14:27
@henryjonathanquispe
henryjonathanquispe changed the base branch from VITE_JONAS to develop July 29, 2026 14:27
@henryjonathanquispe
henryjonathanquispe force-pushed the VITE_INBOX branch 3 times, most recently from 998c120 to 29fc119 Compare July 29, 2026 17:15
@vladyrichter

Copy link
Copy Markdown

QA server K8S was successfully deployed https://ci-40c01f3a09.engk8s.processmaker.net

VITE_INBOX: update npm run dev

VITE_INBOX: update npm run dev

VITE_INBOX: update npm run dev

VITE_INBOX: update broadcast pusher in ci build
@vladyrichter

Copy link
Copy Markdown

QA server K8S was successfully deployed https://ci-40c01f3a09.engk8s.processmaker.net

@vladyrichter

Copy link
Copy Markdown

QA server K8S was successfully deployed https://ci-40c01f3a09.engk8s.processmaker.net

@nolanpro

Copy link
Copy Markdown
Contributor

QA server K8S was successfully deployed https://ci-40c01f3a09.engk8s.processmaker.net

@nolanpro

nolanpro commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

QA server K8S was successfully deployed https://ci-40c01f3a09.engk8s.processmaker.net

@cursor

cursor Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Dual asset pipelines (Mix + Vite) and relocated Vite HMR can break login/inbox if builds or hot-file setup are wrong; most PHP changes are additive view variables.

Overview
Adds Vite alongside Laravel Mix for Login and Inbox front-end assets, replacing the separate webpack-login.mix.js step in dev/production with vite build (and new vite:dev / build:all scripts). Dev dependencies include Vite 7, laravel-vite-plugin, and @vitejs/plugin-vue2; public/build is gitignored for Vite output.

Laravel integration: ProcessMakerServiceProvider sets Vite::useHotFile(storage_path('vite.hot')) so Vite HMR does not use public/hot, which Mix still uses—avoiding mix() URLs incorrectly pointing at the Vite dev server.

View data: ScreenBuilderController and RequestController::screenPreview now pass an uppercased screen type (FORM default) into their Blade views, likely for Vite-driven screen/login/inbox bundles.

Mix remains for the bulk of assets; production runs both mix --production and vite build.

Reviewed by Cursor Bugbot for commit 91b5ca2. Bugbot is set up for automated code reviews on this repo. Configure here.

@nolanpro
nolanpro self-requested a review September 16, 2026 22:08
@nolanpro
nolanpro merged commit 7ea656b into develop Sep 16, 2026
7 of 8 checks passed
@nolanpro
nolanpro deleted the VITE_INBOX branch September 16, 2026 22:09
@decisions-sonarqube

Copy link
Copy Markdown

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 4 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want fixes drafted automatically? Bugbot Autofix can create code changes for findings. A team admin can enable Autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 91b5ca2. Configure here.

icons: {},
},
};

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Login wipes ProcessMaker packages

High Severity

login.js assigns a new window.ProcessMaker with packages: [] after the Blade inline has already set ProcessMaker.packages. Vite emits type="module" scripts, which run after parsing, so the module overwrites the package list used by login addons and global scripts.

Additional Locations (2)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 91b5ca2. Configure here.

@vite(['resources/js/processes/screen-builder/typeForm.js'])
@elseif ($type === 'DISPLAY')
@vite(['resources/js/processes/screen-builder/typeDisplay.js'])
@endif

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Screen type scripts load twice

Medium Severity

Screen builder and request preview now @vite typeForm.js or typeDisplay.js while ScreenBuilderStarting still adds the Mix copies via $manager->getScripts(). The same type bundle runs twice and can register controls and listeners twice.

Additional Locations (2)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 91b5ca2. Configure here.

@vite(['resources/js/vite/tasks/loaderTasks.js'])
@foreach($manager->getScripts() as $script)
<script src="{{$script}}"></script>
<script defer src="{{$script}}"></script>

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Inbox Mix scripts lack webpack runtime

Medium Severity

Inbox still injects Mix typeForm.js and typeDisplay.js from $manager->getScripts(). layoutnextvite does not load mix('js/manifest.js') or other webpack runtime, so those chunks throw and package ScreenBuilder hooks on inbox can fail.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 91b5ca2. Configure here.

return view('requests.preview', compact('request', 'screen', 'manager', 'data'));
$type = strtoupper($screen->type ?? 'FORM');

return view('requests.preview', compact('request', 'screen', 'manager', 'data', 'type'));

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Preview type disagrees with event

Medium Severity

screenPreview still starts ScreenBuilder with $request->summary_screen->type, but the new $type used by @vite comes from $screen->type. When those differ, Mix package scripts register one screen type and Vite loads the other type chunk.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 91b5ca2. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants