Staging terminates SSL at a reverse proxy in front of the app, but
Laravel had no trustProxies() configured, so it never saw the request
as HTTPS and generated http:// asset URLs on the https:// page.
Browsers block that as mixed content, which silently broke every
JS-enhanced Filament field (FileUpload, Textarea, etc.) — e.g. the
Ev Company logo field falling back to a bare native file input.
- bootstrap/app.php: trust the proxy via X-Forwarded-* headers.
- AppServiceProvider: force the https scheme when APP_URL is https,
as a fallback in case the forwarded header is ever missing.
- T6.1: named rate limiters (api-read/api-write/api-auth/api-webhooks),
applied per module route group with tighter limits on booking/payment
writes and the KBZ webhook than read-only catalog/routing endpoints.
- T6.2: install spatie/laravel-activitylog; LogsActivity on Booking/
Payment/Refund status transitions and catalog/pricing admin CRUD
(EvCompany, Destination, DepartureTimeSlot, EvRoute, RoutePricing).
New IdentityPlugin with a read-only AuditLogResource gated by
view_audit_log.
- T6.3: JSON error envelope for api/* in bootstrap/app.php (401/403/404/
405/429/500 fallback), plus PaymentGatewayException (422 declined /
502 unavailable).
- T6.4: feature tests proving the FastAPI agent token gets 403 on
refund/cancel-not-owned and 405 (no write handler) on catalog/routing
writes.
- T6.5: install gboquizosanchez/filament-log-viewer with a custom
Filament admin theme (required for its views' Tailwind classes to
compile), LOG_CHANNEL/FILAMENT_LOG_VIEWER_DRIVER=daily, registered
under Operations in the sidebar.
252 tests passing.