История коммитов

.
build: stop tracking the Vite build output
The compiled bundle in public/build is now generated by "npm run build" after installation instead of being committed.
.
build: migrate frontend to Vite and Vue 3
Replace the Laravel Mix / Webpack build with Vite and upgrade Vue 2.7 to Vue 3.5, keeping the server-rendered island setup where every .vue_app element is mounted as its own app.

Add a Vite view extension that renders entry point tags from the manifest in production and from the dev server (with HMR) when the hot file is present. RTL keeps a separate app.rtl.css, emitted next to every stylesheet via rtlcss.

Publish jQuery/axios/lodash globals from a dedicated module so libraries that read window.jQuery load after them, switch Bootstrap and flatpickr calls to native APIs, and load Prism in manual mode (currentScript is null in a module). Drop the frontend part of the wysibb editor; the backend stays untouched.
.
docs: switch the documentation submodule to the 10.0 branch
The 10.0 branch of the documentation repository was a dead line from 2024: it
shares no history with 9.9 and predates most of the current docs. It has been
recreated from 9.9 and now carries the public document root guides; the old
branch is kept as 10.0-legacy-2024.

.gitmodules records the branch, so submodule update --remote follows 10.0
instead of the repository default.
.
refactor(core): deprecate the base path argument of Assets::urlFromPath
The base path is PUBLIC_PATH in every call site, so the argument became
optional and defaults to it. Passing it explicitly still works, which keeps
third party themes and modules building.
.
refactor(core)!: move the document root to the public directory
Everything reachable over HTTP now lives in public/, the code stays in the
repository root and is no longer served. The layout below public/ mirrors the
old one, so not a single URL changes.

The preparation landed earlier: PUBLIC_PATH switching to ROOT_PATH . 'public'
is what actually moves the application.

- nginx: root points at /app/public in both templates.
- webpack: setPublicPath('public') keeps the mix-manifest keys as /themes/...,
the build output moves under public/.
- a root .htaccess forwards requests into public/ and denies access to the code,
for Apache hosting where the document root cannot be changed.

BREAKING CHANGE: the document root must be pointed at public/. Restart php-fpm
after updating, the realpath cache holds the old paths.
.
refactor(admin): scan public directories in the file integrity scanner
The scanned folders were suffixes appended to ROOT_PATH, so assets and upload
would have silently dropped out of the snapshot once they move into public/.
They are now absolute roots, taken from the constants that follow them.

The implicit rule that only the repository root is scanned without recursion
became an explicit flag.

The installer directory is now covered as well: it is reachable by URL but was
never scanned. Existing snapshots keep working, since scan() only compares the
paths they already contain.
.
fix(admin): install theme assets of language packs into the public path
A language pack ships both system/locale/xx.ini and a theme flag under
themes/default/assets/. Extracting the archive straight into ROOT_PATH would
drop the flag outside of the document root once themes assets move into
public/, leaving a stray themes/default/assets/ directory in the root.

The archive is now extracted into a temporary directory and moved into place:
theme assets go under PUBLIC_THEMES_PATH, everything else into ROOT_PATH.
.
refactor(core): resolve front controller paths from __DIR__
Both paths were relative to the current working directory. They run before
vendor/autoload.php, so they use __DIR__ rather than the path constants.
.
refactor(install): make the installer independent of the current working directory
The installer resolved the autoloader, the config check and the step files
relative to the current working directory, and the translation domain relative
to ROOT_PATH. They now come from __DIR__ or from the path constants.

step_3 read the .env file through dirname(__DIR__, 2), a hardcoded depth that
would silently break and drop the database autofill under Docker. step_2 lists
the writable directories as absolute paths and labels them by subtracting
ROOT_PATH; PUBLIC_PATH joins the list, the sitemap and robots.txt are written
there.
.
refactor(assets): resolve paths in asset scripts from constants
Both scripts addressed the upload directory relative to the current working
directory. Once assets and upload move into public/ together, those relative
paths would keep working while ../../../vendor/autoload.php would resolve to
public/vendor and fail.

thumbinal.php did not load the autoloader at all, so it had no constants to
work with.

preview.php accepts the path with or without a leading slash, since one caller
passes each form, and now refuses to serve anything resolving outside of the
document root.