Commit Graph
8 Commits
Author SHA1 Message Date
jeremy bayseandClaude Sonnet 5 5ef655d16f Add "reste à dépenser" tile to the dashboard
Shows the total remaining depense budget for the selected period,
above the breakdown table — reuses the totals.reste figure already
computed per section, no new query.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 13:41:48 +02:00
jeremy bayseandClaude Sonnet 5 1b3906ade2 Show remaining budget in mobile category buttons
Each category button now displays "X € restants" below the name,
alongside the existing progress gauge and percentage — so the user
sees both how much of the budget is used and how much is left
without leaving the entry form. Remaining is floored at 0 to match
the gauge's 100% cap.

categoryProgress now returns a ['pct', 'remaining'] pair per category
instead of a bare percentage; tests updated accordingly.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 12:55:44 +02:00
jeremy bayseandClaude Sonnet 5 613220f43a Add budget progress gauge inside mobile category buttons
Each depense/epargne category button on the mobile quick-entry form
now shows a fill bar plus percentage of its monthly budget already
tracked, so the user sees at a glance which categories are close to
their limit while picking one. Categories without a budget defined
in Plan show no gauge (avoids a misleading 0%). Capped at 100% —
overspend detail already lives on the dashboard's "Manque" column.

3 new Pest tests for the percentage calculation (normal, capped,
no-budget cases). 61/61 tests pass, Pint clean, verified on mobile
against production data.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 12:48:29 +02:00
jeremy bayseandClaude Sonnet 5 5861fc49fc Replace Laravel scaffold logo with a finance-themed mark
The app still shipped the default Laravel cube icon. New mark is a
coin outline crossed by a rising trend line — ties the app's subject
(money) to its purpose (tracking growth over time). Stroke-based
single-color design inherits currentColor from the caller's text-*
class, so it drops into the existing light/dark tokens without a
separate variant.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 12:18:34 +02:00
jeremy bayseandClaude Sonnet 5 25363adde9 Trust reverse proxy headers to fix mixed-content asset URLs
Behind the prod TLS-terminating proxy, Laravel only saw the internal
HTTP hop and generated http:// URLs for Vite assets, which browsers
block as mixed content on an https:// page (suivicpt.trankil.net).

Configured trustProxies in bootstrap/app.php to honor X-Forwarded-*
headers, defaulting to trust any upstream (TRUSTED_PROXIES env var
to restrict to a specific IP if the app is ever reachable directly
over HTTP). .env.production reference updated with the real APP_URL
and the new TRUSTED_PROXIES setting.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 11:43:29 +02:00
jeremy bayseandClaude Sonnet 5 b78c314569 Add recurring transactions with monthly confirmation flow
New "Récurrences" section lets users define recurring depense/epargne
models (name, category, default amount, day of month). Nothing is
created automatically: from the day a recurrence is due, it appears
as a pending proposal in Suivi (desktop + mobile) with an editable
amount, so variable bills (electricity, etc.) can be adjusted before
confirming. Dismissing a proposal skips it for the current month
without creating a transaction, and it reappears the following month.

- recurring_transactions table (household/category scoped, active flag,
  last_generated_year/month to prevent duplicate generation)
- transactions.recurring_transaction_id nullable FK to trace origin
- RecurringTransactionPolicy mirrors CategoryPolicy tenant scoping
- 10 new Pest tests covering CRUD, tenant isolation, and the
  pending/confirm/dismiss lifecycle across month boundaries (travelTo)

58/58 tests pass, Pint clean, verified end-to-end against production
data (test recurrence created and cleaned up).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 09:10:16 +02:00
jeremy bayseandClaude Sonnet 5 674c43afea Upgrade Laravel 11 to 12 to patch CRLF injection CVE-2026-48019
The default email validation rule was vulnerable to CRLF injection
(GHSA-5vg9-5847-vvmq) in all 11.x releases with no backport available.
Upgraded to v12.64.0, the first patched line for this branch.

All 50 Pest tests pass unchanged, Pint clean, composer audit reports
no advisories. No application code changes needed.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-25 22:55:49 +02:00
jeremy bayseandClaude Sonnet 5 d8dc57a5df Initial commit: SuiviCPT personal finance tracker
Laravel 11 + Livewire 3/Volt + Alpine.js + Tailwind app for household
budget planning, transaction tracking, and financial dashboards.

- Multi-tenant households with member invites
- Plan: monthly/yearly budget per category with overrides
- Suivi: transaction log with running balance (desktop + mobile quick-entry)
- Dashboard: budget vs tracked breakdown + Chart.js donuts
- Flux: Sankey diagram of income allocation
- WCAG 2.1 AA color tokens, dark mode, accessible tables/forms
- 50 Pest tests

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-25 22:39:42 +02:00