Rename lists -> projects and items -> cards throughout

Project scope shifts from a todo list to a project-management app. This is a
straight terminology rename across code, comments, migrations, tests, and
docs — no behaviour change.

- DB: table todo_lists -> projects, todo_items -> cards, column
  todo_items.list_id -> cards.project_id, indexes renamed. Migrations 003/004
  rewritten in place (destructive; recreate the volume with `down -v`).
- API: /api/lists -> /api/projects, nested /items -> /cards, reorder body
  item_ids -> card_ids, JSON keys list/lists/item/items -> project/projects/
  card/cards, item_count -> card_count, list_id -> project_id, and the
  matching error messages.
- PHP: TodoList/TodoItem Repository + Controller -> Project/Card; shared SQL
  aliases l/i -> p/c.
- Frontend: stores lists.ts/items.ts -> projects.ts/cards.ts (useProjectsStore
  / useCardsStore, MAX_PROJECTS), ListView -> ProjectView, TodoItemRow ->
  CardRow, route /lists/:id -> /projects/:id (name "project"), types TodoList/
  TodoItem -> Project/Card, and all UI copy. CSS .lists*/.list-head* ->
  .projects*/.project-head*, .item* -> .card-row* (kept the generic .card
  panel class), .items -> .cards.
- Product name in the header, PWA manifest, index.html title and package
  descriptions -> "Project Manager" / "Projects".

Backend suite: 37 passing.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-09-04 11:28:59 +01:00
co-authored by Claude Sonnet 5
parent be592f38fc
commit c66e5ceb9b
30 changed files with 1068 additions and 1065 deletions
+187
View File
@@ -0,0 +1,187 @@
<?php
declare(strict_types=1);
namespace App\Http\Controllers;
use App\Exception\ApiException;
use App\Repository\CardRepository;
use App\Repository\ProjectRepository;
use App\Support\Validator;
use Psr\Http\Message\ResponseInterface as Response;
use Psr\Http\Message\ServerRequestInterface as Request;
/**
* CRUD for the cards within one project. Every route first checks that the
* parent project is owned by the authenticated user; otherwise it responds 404.
*/
final class CardController extends Controller
{
private const TEXT_MAX = 1000;
public function __construct(
private readonly ProjectRepository $projects,
private readonly CardRepository $cards,
) {
}
/**
* GET /api/projects/{projectId}/cards
*/
public function index(Request $request, Response $response, array $args): Response
{
$projectId = $this->requireOwnedProjectId($request, $args);
return $this->json($response, [
'cards' => array_map($this->present(...), $this->cards->allForProject($projectId)),
]);
}
/**
* POST /api/projects/{projectId}/cards
*/
public function store(Request $request, Response $response, array $args): Response
{
$projectId = $this->requireOwnedProjectId($request, $args);
$validator = new Validator($this->body($request));
$text = $validator->requiredString('text', self::TEXT_MAX);
$complete = $validator->optionalBool('complete') ?? false;
$position = $validator->optionalInt('position', 0);
$validator->assert();
$card = $this->cards->create($projectId, $text, $complete, $position);
$this->projects->touch($projectId);
return $this->json($response, ['card' => $this->present($card)], 201);
}
/**
* GET /api/projects/{projectId}/cards/{cardId}
*/
public function show(Request $request, Response $response, array $args): Response
{
$projectId = $this->requireOwnedProjectId($request, $args);
return $this->json($response, ['card' => $this->present($this->requireCard($projectId, $args))]);
}
/**
* PATCH /api/projects/{projectId}/cards/{cardId}
*/
public function update(Request $request, Response $response, array $args): Response
{
$projectId = $this->requireOwnedProjectId($request, $args);
$card = $this->requireCard($projectId, $args);
$validator = new Validator($this->body($request));
$fields = [];
if ($validator->has('text')) {
$fields['text'] = $validator->requiredString('text', self::TEXT_MAX);
}
if ($validator->has('complete')) {
$fields['complete'] = $validator->optionalBool('complete');
}
if ($validator->has('position')) {
$fields['position'] = $validator->optionalInt('position', 0);
}
if ($fields === [] && !$validator->failed()) {
$validator->add('text', 'Provide at least one of: text, complete, position.');
}
$validator->assert();
$updated = $this->cards->update($card['id'], $projectId, $fields);
$this->projects->touch($projectId);
return $this->json($response, ['card' => $this->present($updated)]);
}
/**
* DELETE /api/projects/{projectId}/cards/{cardId}
*/
public function destroy(Request $request, Response $response, array $args): Response
{
$projectId = $this->requireOwnedProjectId($request, $args);
$this->cards->delete($this->requireCard($projectId, $args)['id']);
$this->projects->touch($projectId);
return $response->withStatus(204);
}
/**
* PUT /api/projects/{projectId}/cards/order
*
* Body: { "card_ids": [3, 1, 2] } — every card in the project, exactly once,
* in the desired order. Positions are rewritten to 0..n-1.
*/
public function reorder(Request $request, Response $response, array $args): Response
{
$projectId = $this->requireOwnedProjectId($request, $args);
$order = $this->body($request)['card_ids'] ?? null;
if (!is_array($order) || array_filter($order, static fn ($id) => !is_int($id)) !== []) {
throw new ApiException('card_ids must be an array of card IDs.', 422);
}
/** @var int[] $order */
$expected = $this->cards->idsForProject($projectId);
$given = $order;
sort($given);
sort($expected);
if ($given !== $expected) {
throw new ApiException('card_ids must contain every card in the project exactly once.', 422);
}
$cards = $this->cards->reorder($projectId, $order);
$this->projects->touch($projectId);
return $this->json($response, ['cards' => array_map($this->present(...), $cards)]);
}
/**
* @param array<string, string> $args
*/
private function requireOwnedProjectId(Request $request, array $args): int
{
$project = $this->projects->findOwnedBy((int) $args['projectId'], $this->user($request)['id']);
if ($project === null) {
throw new ApiException('Project not found.', 404);
}
return $project['id'];
}
/**
* @param array<string, string> $args
* @return array{id: int, project_id: int, text: string, complete: bool, position: int, created_at: string, updated_at: string}
*/
private function requireCard(int $projectId, array $args): array
{
$card = $this->cards->findInProject((int) $args['cardId'], $projectId);
if ($card === null) {
throw new ApiException('Card not found.', 404);
}
return $card;
}
/**
* @param array{id: int, project_id: int, text: string, complete: bool, position: int, created_at: string, updated_at: string} $card
* @return array<string, mixed>
*/
private function present(array $card): array
{
return [
'id' => $card['id'],
'project_id' => $card['project_id'],
'text' => $card['text'],
'complete' => $card['complete'],
'position' => $card['position'],
'created_at' => $card['created_at'],
'updated_at' => $card['updated_at'],
];
}
}
+139
View File
@@ -0,0 +1,139 @@
<?php
declare(strict_types=1);
namespace App\Http\Controllers;
use App\Exception\ApiException;
use App\Repository\ProjectRepository;
use App\Support\Validator;
use Psr\Http\Message\ResponseInterface as Response;
use Psr\Http\Message\ServerRequestInterface as Request;
/**
* CRUD for the authenticated user's projects. A project is only ever visible to
* its owner; anything else responds 404.
*/
final class ProjectController extends Controller
{
private const TITLE_MAX = 255;
private const DESCRIPTION_MAX = 2000;
private const MAX_PROJECTS_PER_OWNER = 100;
public function __construct(private readonly ProjectRepository $projects)
{
}
/**
* GET /api/projects
*/
public function index(Request $request, Response $response): Response
{
$projects = $this->projects->allForOwner($this->user($request)['id']);
return $this->json($response, ['projects' => array_map($this->present(...), $projects)]);
}
/**
* POST /api/projects
*/
public function store(Request $request, Response $response): Response
{
$ownerId = $this->user($request)['id'];
$validator = new Validator($this->body($request));
$title = $validator->requiredString('title', self::TITLE_MAX);
$description = $validator->optionalString('description', self::DESCRIPTION_MAX) ?? '';
$validator->assert();
if ($this->projects->countForOwner($ownerId) >= self::MAX_PROJECTS_PER_OWNER) {
throw new ApiException(
sprintf('You have reached the maximum of %d projects.', self::MAX_PROJECTS_PER_OWNER),
409,
);
}
$project = $this->projects->create($ownerId, $title, $description);
return $this->json($response, ['project' => $this->present($project)], 201);
}
/**
* GET /api/projects/{projectId}
*/
public function show(Request $request, Response $response, array $args): Response
{
return $this->json($response, ['project' => $this->present($this->requireOwnedProject($request, $args))]);
}
/**
* PATCH /api/projects/{projectId}
*/
public function update(Request $request, Response $response, array $args): Response
{
$project = $this->requireOwnedProject($request, $args);
$validator = new Validator($this->body($request));
$fields = [];
if ($validator->has('title')) {
$fields['title'] = $validator->requiredString('title', self::TITLE_MAX);
}
if ($validator->has('description')) {
$fields['description'] = $validator->optionalString('description', self::DESCRIPTION_MAX) ?? '';
}
if ($fields === [] && !$validator->failed()) {
$validator->add('title', 'Provide at least one of: title, description.');
}
$validator->assert();
$updated = $this->projects->update($project['id'], $project['owner_id'], $fields);
return $this->json($response, ['project' => $this->present($updated)]);
}
/**
* DELETE /api/projects/{projectId}
*/
public function destroy(Request $request, Response $response, array $args): Response
{
$this->projects->delete($this->requireOwnedProject($request, $args)['id']);
return $response->withStatus(204);
}
/**
* Load the project named in the route, or 404 if it is missing or not owned
* by the authenticated user.
*
* @param array<string, string> $args
* @return array{id: int, owner_id: int, title: string, description: string, card_count: int, completed_count: int, created_at: string, updated_at: string}
*/
private function requireOwnedProject(Request $request, array $args): array
{
$project = $this->projects->findOwnedBy((int) $args['projectId'], $this->user($request)['id']);
if ($project === null) {
throw new ApiException('Project not found.', 404);
}
return $project;
}
/**
* @param array{id: int, owner_id: int, title: string, description: string, card_count: int, completed_count: int, created_at: string, updated_at: string} $project
* @return array<string, mixed>
*/
private function present(array $project): array
{
return [
'id' => $project['id'],
'title' => $project['title'],
'description' => $project['description'],
'owner_id' => $project['owner_id'],
'card_count' => $project['card_count'],
'completed_count' => $project['completed_count'],
'created_at' => $project['created_at'],
'updated_at' => $project['updated_at'],
];
}
}
-187
View File
@@ -1,187 +0,0 @@
<?php
declare(strict_types=1);
namespace App\Http\Controllers;
use App\Exception\ApiException;
use App\Repository\TodoItemRepository;
use App\Repository\TodoListRepository;
use App\Support\Validator;
use Psr\Http\Message\ResponseInterface as Response;
use Psr\Http\Message\ServerRequestInterface as Request;
/**
* CRUD for the items within one todo list. Every route first checks that the
* parent list is owned by the authenticated user; otherwise it responds 404.
*/
final class TodoItemController extends Controller
{
private const TEXT_MAX = 1000;
public function __construct(
private readonly TodoListRepository $lists,
private readonly TodoItemRepository $items,
) {
}
/**
* GET /api/lists/{listId}/items
*/
public function index(Request $request, Response $response, array $args): Response
{
$listId = $this->requireOwnedListId($request, $args);
return $this->json($response, [
'items' => array_map($this->present(...), $this->items->allForList($listId)),
]);
}
/**
* POST /api/lists/{listId}/items
*/
public function store(Request $request, Response $response, array $args): Response
{
$listId = $this->requireOwnedListId($request, $args);
$validator = new Validator($this->body($request));
$text = $validator->requiredString('text', self::TEXT_MAX);
$complete = $validator->optionalBool('complete') ?? false;
$position = $validator->optionalInt('position', 0);
$validator->assert();
$item = $this->items->create($listId, $text, $complete, $position);
$this->lists->touch($listId);
return $this->json($response, ['item' => $this->present($item)], 201);
}
/**
* GET /api/lists/{listId}/items/{itemId}
*/
public function show(Request $request, Response $response, array $args): Response
{
$listId = $this->requireOwnedListId($request, $args);
return $this->json($response, ['item' => $this->present($this->requireItem($listId, $args))]);
}
/**
* PATCH /api/lists/{listId}/items/{itemId}
*/
public function update(Request $request, Response $response, array $args): Response
{
$listId = $this->requireOwnedListId($request, $args);
$item = $this->requireItem($listId, $args);
$validator = new Validator($this->body($request));
$fields = [];
if ($validator->has('text')) {
$fields['text'] = $validator->requiredString('text', self::TEXT_MAX);
}
if ($validator->has('complete')) {
$fields['complete'] = $validator->optionalBool('complete');
}
if ($validator->has('position')) {
$fields['position'] = $validator->optionalInt('position', 0);
}
if ($fields === [] && !$validator->failed()) {
$validator->add('text', 'Provide at least one of: text, complete, position.');
}
$validator->assert();
$updated = $this->items->update($item['id'], $listId, $fields);
$this->lists->touch($listId);
return $this->json($response, ['item' => $this->present($updated)]);
}
/**
* DELETE /api/lists/{listId}/items/{itemId}
*/
public function destroy(Request $request, Response $response, array $args): Response
{
$listId = $this->requireOwnedListId($request, $args);
$this->items->delete($this->requireItem($listId, $args)['id']);
$this->lists->touch($listId);
return $response->withStatus(204);
}
/**
* PUT /api/lists/{listId}/items/order
*
* Body: { "item_ids": [3, 1, 2] } — every item in the list, exactly once,
* in the desired order. Positions are rewritten to 0..n-1.
*/
public function reorder(Request $request, Response $response, array $args): Response
{
$listId = $this->requireOwnedListId($request, $args);
$order = $this->body($request)['item_ids'] ?? null;
if (!is_array($order) || array_filter($order, static fn ($id) => !is_int($id)) !== []) {
throw new ApiException('item_ids must be an array of item IDs.', 422);
}
/** @var int[] $order */
$expected = $this->items->idsForList($listId);
$given = $order;
sort($given);
sort($expected);
if ($given !== $expected) {
throw new ApiException('item_ids must contain every item in the list exactly once.', 422);
}
$items = $this->items->reorder($listId, $order);
$this->lists->touch($listId);
return $this->json($response, ['items' => array_map($this->present(...), $items)]);
}
/**
* @param array<string, string> $args
*/
private function requireOwnedListId(Request $request, array $args): int
{
$list = $this->lists->findOwnedBy((int) $args['listId'], $this->user($request)['id']);
if ($list === null) {
throw new ApiException('List not found.', 404);
}
return $list['id'];
}
/**
* @param array<string, string> $args
* @return array{id: int, list_id: int, text: string, complete: bool, position: int, created_at: string, updated_at: string}
*/
private function requireItem(int $listId, array $args): array
{
$item = $this->items->findInList((int) $args['itemId'], $listId);
if ($item === null) {
throw new ApiException('Item not found.', 404);
}
return $item;
}
/**
* @param array{id: int, list_id: int, text: string, complete: bool, position: int, created_at: string, updated_at: string} $item
* @return array<string, mixed>
*/
private function present(array $item): array
{
return [
'id' => $item['id'],
'list_id' => $item['list_id'],
'text' => $item['text'],
'complete' => $item['complete'],
'position' => $item['position'],
'created_at' => $item['created_at'],
'updated_at' => $item['updated_at'],
];
}
}
-139
View File
@@ -1,139 +0,0 @@
<?php
declare(strict_types=1);
namespace App\Http\Controllers;
use App\Exception\ApiException;
use App\Repository\TodoListRepository;
use App\Support\Validator;
use Psr\Http\Message\ResponseInterface as Response;
use Psr\Http\Message\ServerRequestInterface as Request;
/**
* CRUD for the authenticated user's todo lists. A list is only ever visible to
* its owner; anything else responds 404.
*/
final class TodoListController extends Controller
{
private const TITLE_MAX = 255;
private const DESCRIPTION_MAX = 2000;
private const MAX_LISTS_PER_OWNER = 100;
public function __construct(private readonly TodoListRepository $lists)
{
}
/**
* GET /api/lists
*/
public function index(Request $request, Response $response): Response
{
$lists = $this->lists->allForOwner($this->user($request)['id']);
return $this->json($response, ['lists' => array_map($this->present(...), $lists)]);
}
/**
* POST /api/lists
*/
public function store(Request $request, Response $response): Response
{
$ownerId = $this->user($request)['id'];
$validator = new Validator($this->body($request));
$title = $validator->requiredString('title', self::TITLE_MAX);
$description = $validator->optionalString('description', self::DESCRIPTION_MAX) ?? '';
$validator->assert();
if ($this->lists->countForOwner($ownerId) >= self::MAX_LISTS_PER_OWNER) {
throw new ApiException(
sprintf('You have reached the maximum of %d lists.', self::MAX_LISTS_PER_OWNER),
409,
);
}
$list = $this->lists->create($ownerId, $title, $description);
return $this->json($response, ['list' => $this->present($list)], 201);
}
/**
* GET /api/lists/{listId}
*/
public function show(Request $request, Response $response, array $args): Response
{
return $this->json($response, ['list' => $this->present($this->requireOwnedList($request, $args))]);
}
/**
* PATCH /api/lists/{listId}
*/
public function update(Request $request, Response $response, array $args): Response
{
$list = $this->requireOwnedList($request, $args);
$validator = new Validator($this->body($request));
$fields = [];
if ($validator->has('title')) {
$fields['title'] = $validator->requiredString('title', self::TITLE_MAX);
}
if ($validator->has('description')) {
$fields['description'] = $validator->optionalString('description', self::DESCRIPTION_MAX) ?? '';
}
if ($fields === [] && !$validator->failed()) {
$validator->add('title', 'Provide at least one of: title, description.');
}
$validator->assert();
$updated = $this->lists->update($list['id'], $list['owner_id'], $fields);
return $this->json($response, ['list' => $this->present($updated)]);
}
/**
* DELETE /api/lists/{listId}
*/
public function destroy(Request $request, Response $response, array $args): Response
{
$this->lists->delete($this->requireOwnedList($request, $args)['id']);
return $response->withStatus(204);
}
/**
* Load the list named in the route, or 404 if it is missing or not owned by
* the authenticated user.
*
* @param array<string, string> $args
* @return array{id: int, owner_id: int, title: string, description: string, item_count: int, completed_count: int, created_at: string, updated_at: string}
*/
private function requireOwnedList(Request $request, array $args): array
{
$list = $this->lists->findOwnedBy((int) $args['listId'], $this->user($request)['id']);
if ($list === null) {
throw new ApiException('List not found.', 404);
}
return $list;
}
/**
* @param array{id: int, owner_id: int, title: string, description: string, item_count: int, completed_count: int, created_at: string, updated_at: string} $list
* @return array<string, mixed>
*/
private function present(array $list): array
{
return [
'id' => $list['id'],
'title' => $list['title'],
'description' => $list['description'],
'owner_id' => $list['owner_id'],
'item_count' => $list['item_count'],
'completed_count' => $list['completed_count'],
'created_at' => $list['created_at'],
'updated_at' => $list['updated_at'],
];
}
}