Files
xamxam/todo/02-php-components.md
Pontoporeia 9a58b97cb8 Extract SearchController from public/search.php
Move all data-fetching and request logic out of the 285-line search page
into src/SearchController.php:

- SearchController::create() — static factory; builds RateLimit + Database
  dependencies, sends HTTP 429 (and exits) if rate limit is exceeded,
  runs probabilistic cleanup, returns ready instance
- SearchController::handle() — sanitises GET params (query/year/orientation/
  ap_program/keyword), runs all DB queries (searchTheses, countSearchResults,
  getAvailableYears, getAllOrientations, getAllAPPrograms, getUsedTags,
  getPublishedAuthors), builds alphabetical author→id map, assembles
  OG/meta tags, returns a flat array of view variables
- Rate-limit 429 HTML response moved into private sendRateLimitResponse()

public/search.php is now a 6-line dispatcher:
  require SearchController; extract(SearchController::create()->handle());
followed by the unchanged view template (162 lines total, was 285).

The view template is byte-for-byte equivalent: same HTML, same variable
names, same pagination partial include.
2026-04-06 15:33:08 +02:00

3.1 KiB

PHP Components (Reusable Partials)

Form field partials — templates/partials/form/

  • text-field.php — already implemented; used across add.php and edit.php for all single-line fields
  • select-field.php — already implemented; used for orientation, ap, finality, license, access type, etc.
  • checkbox-list.php — already implemented with <fieldset>/<legend class="sr-only">/<ul> structure for WCAG 1.3.1
  • file-field.php — already implemented; used for cover image, banner, and TFE files
  • jury-fieldset.php — already implemented; single partial shared by add.php and edit.php; includes all WCAG aria-labels and JS for dynamic rows

Shared UI partials — templates/partials/

  • pagination.php — partial created and used in both search.php and (now) admin/index.php; admin/index.php also gained proper server-side pagination (25/page) with filter-aware $baseParams
  • status-badge.php — partial fully implemented (templates/partials/status-badge.php) with $badgeType/$badgeValue API; CSS rules in admin.css; used in admin/index.php for publish + access badges
  • admin-alert.php — already done; flash-messages.php calls App::consumeFlash() which handles all legacy key variants (_flash_error, error, admin_error, edit_error, form_error, success, admin_success, edit_success) and clears them all

Controller Extraction (In Progress)

  • Extract SearchControllersrc/SearchController.php; rate-limiting, param sanitisation, DB queries, OG meta, and author-map construction moved out of public/search.php; entry point is now a 6-line dispatcher (create() + handle() + extract()); view template unchanged
  • Extract SystemController — biggest single-file win, 500→8 lines
  • Extract ThesisEditController — merges edit.php + actions/edit.php, deduplicates jury fieldset
  • Extract remaining controllers one by one
  • Consolidate action handlers into controller methods
  • Unify flash message keys project-wide to _flash_error / _flash_success — all callers already use App::flash(); removed dead legacy-key fallback chains (error, admin_error, edit_error, form_error, success, admin_success, edit_success) from consumeFlash()
  • Move OG tag construction into controller logic
  • Extract inline CSS/JS from system.php into separate assets — JS moved to public/assets/js/system.js (loaded via $extraJs); 4 inline style= attributes replaced with CSS classes; only dynamic CSS custom properties (--disk-pct, --disk-color) remain as inline styles because they carry PHP runtime values

Backend Maintenance

  • RateLimit cache dir — already in storage/cache/rate_limit; justfile deploy excludes storage/cache/* from rsync. APCu/SQLite migration deferred (not blocking).
  • apropos.php contacts and credits — moved to config/apropos.php config array (contacts[], credits[], erg_url); apropos.php loops over the config with htmlspecialchars; update names/emails by editing only the config file