Skip to content

Port missing 2.1 features + security dep bumps to master (#474, #480) - #522

Merged
navneetkumar-pim-webkul merged 3 commits into
masterfrom
port/2.1-help-installer-and-deps
Jun 26, 2026
Merged

navneetkumar-pim-webkul merged 3 commits into
masterfrom
port/2.1-help-installer-and-deps

Conversation

@navneetkumar-pim-webkul

Copy link
Copy Markdown
Collaborator

Summary

Backports the features present in 2.1 but missing from master, and closes outstanding dependency CVEs. All 2.1 security fixes were already in master (via #497 + individual twins) — this PR fills the remaining feature gap and clears composer audit.

Commits

Commit What
b513a795 #474 — Help & Resources admin page (sidebar menu, ACL entry, reusable card component) + promo banner (cloud-hosting + upgrade-available) with per-admin dismissal (new admin_promo_dismissals table + model/proxy/contract/repository) + installer optional-packages selector + cloud-hosting banner + translations for all 33 locales
2784385b #480 — promo banner sticky z-[9999] fix (no scroll gap, sits below modal/drawer overlays) + rebuilt CSS
086b91b9 deps — security-relevant bumps

Dependency bumps (086b91b9)

composer audit → no advisories. Only composer.lock changed; composer.json constraints untouched.

Scope notes

  • The original 2.1 PR Feat/help and installer 2.1 #474 bundled unrelated dead-file / upgrade_*.sh deletions — dropped here. Master docs and Core::VERSION preserved.
  • Admin + installer Vite assets rebuilt.

Verification

  • ✅ Pint clean
  • ✅ unopim:translations:check — 100% / all 33 locales
  • ✅ Help feature suite: 23 pass · Installer optional-packages: 4 pass
  • ✅ User + Installer regression suites pass on clean reseed (1 unrelated pre-existing Passport test bug — $confidential named param mismatch — not introduced here)
  • ✅ composer audit: no advisories · Laravel 12.62.0 boots · Core unit suite 48 pass

…ges from 2.1 (#474)

Backport of 2.1 PR #474 onto master:
- Help & Resources admin page: sidebar menu, ACL entry, reusable card component
- Promo banner (cloud-hosting + upgrade-available) with per-admin dismissal
  (new admin_promo_dismissals table + model/proxy/contract/repository)
- Installer optional-packages selector + cloud-hosting banner
- Translations for all 33 locales

Drops the unrelated dead-file/upgrade-script deletions bundled in the original
PR; keeps master docs and VERSION. Admin + installer assets rebuilt.

(cherry picked from 9177845 on origin/2.1)
* fix: make promo banner sticky to remove empty gap on scroll

Promo banner used position:relative, so it scrolled out of view while
the layout already offsets the header by 3rem (its height). When the
banner scrolled away the sticky header stayed pinned at top:48px,
leaving a 48px empty gap above it.

Make the banner sticky (top-0, z above header) so it stays pinned and
the header sits flush below it.

* fix: drop promo bar z-index to avoid modal overlay collision

Addresses review feedback: z-[10002] tied modal overlays (confirm/history/
bulk-edit all use z-[10002]) and, being rendered later in the DOM, painted
above them — leaving the banner visible/clickable over an open modal.

The banner only needs to stay above scrolling page content (which it does
via position:sticky alone, as a positioned element) and below modal
overlays. Removing the explicit z-index achieves both. Also avoids relying
on a new arbitrary Tailwind value (z-[10000]) that the committed build CSS
does not contain (CI does not rebuild assets).

* fix: give promo bar z-[9999] to sit above transform-stacked charts

Dashboard chart SVGs use CSS transform, so each creates its own stacking
context. With the banner at z-index:auto, those contexts painted at the
same level and (being later in the DOM) bled over the sticky banner on
scroll — e.g. completeness donut charts appeared inside the banner.

A positive z-index is required to beat transform stacking contexts.
z-[9999] sits above all page content (<=1000) while staying below the
header/modal/drawer overlays (10001/10002), so modals and drawers still
cover the banner correctly. z-[9999] already exists in the committed
build CSS (CI does not rebuild assets), so no asset rebuild is needed.

(cherry picked from commit e6e35fb)
Sync dependency versions toward 2.1 and resolve outstanding composer audit
advisories:
- phpseclib/phpseclib       3.0.52 -> 3.0.55
- guzzlehttp/psr7           2.10.2 -> 2.12.3
- laravel/framework         12.61.0 -> 12.62.0
- phpoffice/phpspreadsheet  1.30.4 -> 1.30.5  (CVE-2026-45034, parity with 2.1 #487)
- mtdowling/jmespath.php    2.8.0  -> 2.9.1   (CVE-2026-54133)

composer audit now reports no advisories. Only composer.lock changed;
composer.json constraints untouched.
Copilot AI review requested due to automatic review settings June 26, 2026 13:01

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@navneetkumar-pim-webkul
navneetkumar-pim-webkul merged commit e679fe1 into master Jun 26, 2026
29 of 31 checks passed
@navneetkumar-pim-webkul
navneetkumar-pim-webkul deleted the port/2.1-help-installer-and-deps branch June 26, 2026 13:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants