Skip to content

[Fix] Remove Ziggy and use frontend URL paths - #1266

Merged
saeedvaziry merged 2 commits into
4.xfrom
remove-ziggy-routes
Oct 2, 2026
Merged

saeedvaziry merged 2 commits into
4.xfrom
remove-ziggy-routes

Conversation

@saeedvaziry

@saeedvaziry saeedvaziry commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Replace all frontend Ziggy route() calls with root-relative URL paths, preserving query parameters, optional segments, URL encoding, and dynamic resource IDs.
  • Remove the Ziggy Composer dependency, cached route-script endpoint/action, Blade script injection, SSR integration, global types, and build aliases.
  • Resolve table links server-side and update navigation matching for relative paths.
  • Add regression coverage for guest pages with SSR enabled/disabled, the removed route endpoint, and resolved table links.

Closes #1265

Validation

  • TypeScript: tsc --noEmit passed.
  • ESLint on changed frontend files passed.
  • git diff --check passed.
  • With APP_ENV=testing, authentication and related architecture tests passed: 26 tests, 48 assertions.
  • The server-table link regression passed.
  • Project PHP/Laravel, frontend, and security reviewers reported no issues.

Notes

  • Frontend assets must be rebuilt before deployment; tracked public/build output was intentionally left unchanged. No builds or formatters were run, per project instructions.
  • Test setup still emits local libcrypto key-generation warnings, but the verified assertions pass.

Summary by CodeRabbit

  • Improvements

    • Navigation and requests now use direct URL paths across the application, with query parameters handled separately.
    • Table links use URLs provided with their data, and active navigation follows the current page path.
    • Admin dashboard links are shown when the relevant dashboard URLs are available.
  • Documentation

    • Updated guidance and release notes to reflect direct URL navigation and URL handling.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (1)
CLAUDE.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: vitodeploy/vito/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 76e9285e-fa6d-4c47-8986-ac52885e43e9

📥 Commits

Reviewing files that changed from the base of the PR and between 6b637b2 and 82f0b84.

📒 Files selected for processing (4)
  • app/Actions/Bootstrap/GetBootstrap.php
  • resources/js/components/app-sidebar.tsx
  • resources/js/types/index.d.ts
  • tests/Feature/BootstrapTest.php

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

The pull request removes Ziggy’s client-side route catalogue and replaces named-route URL generation with root-relative paths across the frontend. It also updates Inertia data, table link handling, bootstrap dashboard URLs, guidance, configuration and tests.

Changes

Frontend routing migration

Layer / File(s) Summary
Remove Ziggy runtime and route data
app/Actions/Ziggy/*, app/Http/Controllers/ZiggyRoutesController.php, app/Http/Middleware/HandleInertiaRequests.php, resources/js/ssr.tsx, resources/js/types/*, resources/views/app.blade.php, config/inertia-table.php, composer.json, tsconfig.json, vite.config.ts, tests/*, .claude/skills/inertia-table/SKILL.md, .github/instructions/frontend.instructions.md, docs/4.x/prologue/release-notes.md, .prettierignore
The Ziggy script endpoint, route catalogue sharing, SSR route setup, and Ziggy dependency mappings are removed. The Inertia table configuration sets use_ziggy to false. Guidance, release notes, formatting configuration and tests reflect direct paths and the removed route catalogue.
Shared navigation and links
resources/js/components/*, resources/js/hooks/use-log-content.ts, resources/js/layouts/*, resources/js/lib/utils.ts, resources/js/stores/*
Shared components and layouts use literal paths for navigation and requests. Active-path checks use currentPath(), which returns the pathname. Table links read their URL from the row’s href_key.
Server and site feature requests
resources/js/pages/api-keys/*, resources/js/pages/application/*, resources/js/pages/backups/*, resources/js/pages/commands/*, resources/js/pages/cronjobs/*, resources/js/pages/database-users/*, resources/js/pages/databases/*, resources/js/pages/firewall/*, resources/js/pages/monitoring/*, resources/js/pages/php/*, resources/js/pages/security/*, resources/js/pages/server-features/*, resources/js/pages/server-logs/*, resources/js/pages/server-network/*, resources/js/pages/server-settings/*, resources/js/pages/server-ssh-keys/*, resources/js/pages/server-ssls/*, resources/js/pages/servers/*, resources/js/pages/services/*, resources/js/pages/site-features/*, resources/js/pages/site-settings/*, resources/js/pages/site-tooling/*, resources/js/pages/sites/*, resources/js/pages/workers/*
Feature links and requests use directly constructed paths instead of named routes. Existing request methods, conditions and callbacks remain as described in the change summaries.
Domain and network requests
resources/js/pages/domains/*, resources/js/pages/hosted-domains/*, resources/js/pages/networks/*
Domain, hosted-domain and network actions use direct paths. Query parameters and encoded path segments use request options or URL construction.
Admin, settings and workflow requests
resources/js/pages/dns-providers/*, resources/js/pages/github-app/*, resources/js/pages/notification-channels/*, resources/js/pages/plugins/*, resources/js/pages/redirects/*, resources/js/pages/scripts/*, resources/js/pages/server-providers/*, resources/js/pages/source-controls/*, resources/js/pages/ssh-keys/*, resources/js/pages/storage-providers/*, resources/js/pages/users/*, resources/js/pages/vito-settings/*, resources/js/pages/workflow-runs/*, resources/js/pages/workflows/*
Administration, settings, provider, plugin, script and workflow links and requests use direct paths instead of named routes.
Bootstrap dashboard URLs
app/Actions/Bootstrap/GetBootstrap.php, resources/js/components/app-sidebar.tsx, resources/js/types/index.d.ts, tests/Feature/BootstrapTest.php
Bootstrap configuration includes Horizon and log viewer URLs. The sidebar uses those values for dashboard links, and the type declaration and tests cover the URLs.

Priority: ⬆️ High

Estimated code review effort: 4 (Complex) | ~45 minutes

Change: Bug fix · Severity of issue fixed: High

Suggested reviewers: richardanderson

Merge Risk: ⚪ Minimal · up to 82f0b

The change removes Ziggy and builds frontend URLs from root-relative paths, and moves dashboard links into bootstrap data. No actionable merge-blocking risk was identified. Frontend assets must be rebuilt before deployment.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 82f0b

Dashboard destinations remain server-configured, and dashboard access controls remain unchanged. No new authorization bypass was established. Deployment still needs coordinated frontend assets and bootstrap cache handling, which were not fully verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The inspected exposure is instance-level navigation metadata available to authenticated bootstrap callers. Learning those destinations does not itself grant access to queue operations or logs. Effective dashboard-host ownership and TLS behavior remain outside the available deployment evidence.

Trust Boundaries and Controls

  • observed — Bootstrap requires authentication. Horizon defines an administrator gate for non-local access, while log-viewer page and API middleware require authentication and MustBeAdminMiddleware. These endpoint controls remain separate from frontend link visibility and were unchanged in the inspected base/head comparison.
  • inferred — Dashboard destination discovery is not established as newly expanded exposure. The base sidebar constructed both URLs before applying hidden attributes, and the deleted catalogue endpoint intentionally served route data without authentication. New bootstrap metadata alone is therefore insufficient evidence of increased disclosure.

Resilience and Maintainability Implications

  • observed — Bootstrap fetches are deduplicated, failures preserve already-ready configuration, and completion releases the in-flight marker. Logout clears stored configuration but does not cancel an existing fetch, which can subsequently repopulate it. This lifecycle behavior predates the PR; the new URLs do not carry user-specific authority, and dashboard visibility still checks the current identity.
🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely summarises the main change: removing Ziggy and replacing frontend route helpers with URL paths.
Linked Issues check ✅ Passed The PR meets the coding requirements in [#1265]. It removes Ziggy, its cached /ziggy/{version}.js endpoint, Blade injection, SSR integration, global types, dependency, and build aliases. Frontend re…
Out of Scope Changes check ✅ Passed The changes remain within [#1265]. The route migration, server-side table-link resolution, bootstrap dashboard URLs, SSR and build updates, documentation, and regression tests support the removal of t…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Expose typed, host-independent dashboard URLs through bootstrap and use them in the sidebar once loaded. Add coverage for default and custom paths, configured domains, root paths, and stable bootstrap versions across request hosts.
@saeedvaziry
saeedvaziry merged commit aadd9f9 into 4.x Oct 2, 2026
6 checks passed
@saeedvaziry
saeedvaziry deleted the remove-ziggy-routes branch October 2, 2026 10:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Ziggy routes file is cached forever with the host of the first request (panel sends requests to 127.0.0.1)

1 participant