diff --git a/.agents/skills/ai-sdk-development/SKILL.md b/.agents/skills/ai-sdk-development/SKILL.md index dd340724..5071ca45 100644 --- a/.agents/skills/ai-sdk-development/SKILL.md +++ b/.agents/skills/ai-sdk-development/SKILL.md @@ -278,6 +278,20 @@ class MyAgent implements Agent The `#[UseCheapestModel]` and `#[UseSmartestModel]` attributes are also available for automatic model selection. +The `#[WithoutBroadcasting]` attribute stops the given stream event types from broadcasting (e.g. data-heavy `ToolResult` payloads that exceed the WebSocket frame limit). The events are still streamed and persisted; they just never hit the channel: + +```php +use Laravel\Ai\Attributes\WithoutBroadcasting; +use Laravel\Ai\Streaming\Events\{ToolCall, ToolResult}; + +#[WithoutBroadcasting(ToolResult::class, ToolCall::class)] +class SearchAgent implements Agent, HasTools +{ + use Promptable; + // ... +} +``` + ### Tools Implement the `HasTools` interface and scaffold tools with `php artisan make:tool`: @@ -391,6 +405,38 @@ $store->assertAdded('file_id'); - Artisan commands: `php artisan make:agent`, `php artisan make:tool` - Global helper: `agent()` for anonymous agents +## OpenAI-Compatible Provider + +Point the SDK at any OpenAI-compatible endpoint (LM Studio, vLLM, Together, etc.) with the config-driven `openai-compatible` driver. Define named instances in `config/ai.php`, no code required: + +```php +'my-llm' => [ + 'driver' => 'openai-compatible', + 'url' => env('MY_LLM_URL'), // required + 'key' => env('MY_LLM_API_KEY'), // optional Bearer token + 'models' => [ + 'text' => ['default' => 'some-chat-model'], + 'embeddings' => [ + 'default' => 'some-embedding-model', + 'dimensions' => 1024, // optional; omit to use native dimensions + ], + ], +], +``` + +Reference it by config key (or `Lab::OpenAiCompatible`). A model is required via the corresponding `models` configuration or per-call `model:`: + +```php +agent()->prompt('Hello', provider: 'my-llm', model: 'some-model'); + +Embeddings::for(['Hello'])->generate( + provider: 'my-llm', + model: 'some-embedding-model', +); +``` + +It uses OpenAI-standard shapes and supports text, streaming, tools, structured output, image attachments, and text embeddings. Embedding dimensions are optional; omit them to use the model's native dimensions. For extra request-body fields, implement `HasProviderOptions` — the returned array is merged into the body. + ## Common Pitfalls ### Wrong Namespace @@ -416,11 +462,11 @@ Calling a capability not supported by a provider throws a `LogicException`. Refe | Feature | Providers | | ---------- | --------------------------------------------------------------- | -| Text | OpenAI, Anthropic, Gemini, Azure, Groq, xAI, DeepSeek, Mistral, Ollama | +| Text | OpenAI, Anthropic, Gemini, Azure, Groq, xAI, DeepSeek, Mistral, Ollama, OpenRouter, OpenAI-compatible | | Images | OpenAI, Gemini, xAI | | TTS | OpenAI, ElevenLabs | | STT | OpenAI, ElevenLabs, Mistral | -| Embeddings | OpenAI, Gemini, Azure, Cohere, Mistral, Jina, VoyageAI | +| Embeddings | OpenAI, OpenAI-compatible, Gemini, Azure, Cohere, Mistral, Jina, VoyageAI | | Reranking | Cohere, Jina | | Files | OpenAI, Anthropic, Gemini | @@ -432,5 +478,6 @@ use Laravel\Ai\Enums\Lab; Lab::Anthropic; Lab::OpenAI; Lab::Gemini; +Lab::OpenAiCompatible; // configurable OpenAI-compatible endpoint // ... -``` \ No newline at end of file +``` diff --git a/.agents/skills/cashier-stripe-development/SKILL.md b/.agents/skills/cashier-stripe-development/SKILL.md index 355e8a92..09284646 100644 --- a/.agents/skills/cashier-stripe-development/SKILL.md +++ b/.agents/skills/cashier-stripe-development/SKILL.md @@ -8,16 +8,6 @@ metadata: # Cashier Stripe Development -## When to Apply - -Activate this skill when: - -- Installing or configuring Laravel Cashier Stripe -- Setting up subscriptions, trials, quantities, or plan swapping -- Handling webhooks or SCA/3DS payment failures -- Working with Stripe Checkout, invoices, or charges -- Testing billing scenarios with Stripe test cards or tokens - ## Documentation Use `search-docs` for detailed Cashier patterns and documentation covering subscriptions, webhooks, Stripe Checkout, invoices, payment methods, and testing. @@ -105,4 +95,4 @@ Always wrap subscription creation in a try/catch for `IncompletePayment`. When a - In MySQL, the `stripe_id` column must use `utf8_bin` collation to avoid case-sensitivity issues. - `noProrate()` has no effect when combined with `swapAndInvoice()`. That method always prorates. - Methods like `withPromotionCode()` require the Stripe API ID such as `promo_xxxx`, not the customer-facing code. Use `findPromotionCode()` to resolve a code to its ID. -- Always use `search-docs` for the latest Cashier documentation rather than relying on this skill alone. \ No newline at end of file +- Always use `search-docs` for the latest Cashier documentation rather than relying on this skill alone. diff --git a/.agents/skills/cashier-stripe-development/references/subscriptions.md b/.agents/skills/cashier-stripe-development/references/subscriptions.md index ad7113ea..980c0642 100644 --- a/.agents/skills/cashier-stripe-development/references/subscriptions.md +++ b/.agents/skills/cashier-stripe-development/references/subscriptions.md @@ -105,4 +105,4 @@ $user->newSubscription('default') $user->reportMeterEvent('emails-sent'); $user->reportMeterEvent('emails-sent', quantity: 15); -``` \ No newline at end of file +``` diff --git a/.agents/skills/cashier-stripe-development/references/testing.md b/.agents/skills/cashier-stripe-development/references/testing.md index 97e91f91..2d6b04cf 100644 --- a/.agents/skills/cashier-stripe-development/references/testing.md +++ b/.agents/skills/cashier-stripe-development/references/testing.md @@ -49,4 +49,4 @@ public function test_incomplete_payment_is_handled(): void - Use Stripe test mode keys (`sk_test_...`, `pk_test_...`) in your test environment - Cashier does not ship a global `fake()` helper. Tests hit the real Stripe test API by default. - Refer to `tests/Feature/` in the Cashier package itself for integration test patterns covering subscription creation, payment methods, and webhook handling -- Use `search-docs` for current guidance on mocking Stripe HTTP calls or using Stripe's test clock feature for time-sensitive scenarios \ No newline at end of file +- Use `search-docs` for current guidance on mocking Stripe HTTP calls or using Stripe's test clock feature for time-sensitive scenarios diff --git a/.agents/skills/cashier-stripe-development/references/webhooks.md b/.agents/skills/cashier-stripe-development/references/webhooks.md index 19d2f708..5ebf153d 100644 --- a/.agents/skills/cashier-stripe-development/references/webhooks.md +++ b/.agents/skills/cashier-stripe-development/references/webhooks.md @@ -129,4 +129,4 @@ Event::listen(WebhookReceived::class, function (WebhookReceived $event) { ## Signature Verification -`VerifyWebhookSignature` middleware is applied automatically when `cashier.webhook.secret` is set. No extra wiring is needed. \ No newline at end of file +`VerifyWebhookSignature` middleware is applied automatically when `cashier.webhook.secret` is set. No extra wiring is needed. diff --git a/.agents/skills/fortify-development/SKILL.md b/.agents/skills/fortify-development/SKILL.md index bd05dd6d..2c4e84fe 100644 --- a/.agents/skills/fortify-development/SKILL.md +++ b/.agents/skills/fortify-development/SKILL.md @@ -1,6 +1,9 @@ --- name: fortify-development -description: Laravel Fortify headless authentication backend development. Activate when implementing authentication features including login, registration, password reset, email verification, two-factor authentication (2FA/TOTP), profile updates, headless auth, authentication scaffolding, or auth guards in Laravel applications. +description: 'ACTIVATE when the user works on authentication in Laravel. This includes login, registration, password reset, email verification, two-factor authentication (2FA/TOTP/QR codes/recovery codes), passkeys, profile updates, password confirmation, or any auth-related routes and controllers. Activate when the user mentions Fortify, auth, authentication, login, register, signup, forgot password, verify email, 2FA, passkeys, WebAuthn, or references app/Actions/Fortify/, CreateNewUser, UpdateUserProfileInformation, FortifyServiceProvider, config/fortify.php, or auth guards. Fortify is the frontend-agnostic authentication backend for Laravel that registers all auth routes and controllers. Also activate when building SPA or headless authentication, customizing login redirects, overriding response contracts like LoginResponse, or configuring login throttling. Do NOT activate for Laravel Passport (OAuth2 API tokens), Socialite (OAuth social login), or non-auth Laravel features.' +license: MIT +metadata: + author: laravel --- # Laravel Fortify Development @@ -29,6 +32,7 @@ Enable in `config/fortify.php` features array: - `Features::updateProfileInformation()` - Profile updates - `Features::updatePasswords()` - Password changes - `Features::twoFactorAuthentication()` - 2FA with QR codes and recovery codes +- `Features::passkeys()` - Passwordless authentication with WebAuthn passkeys > Use `search-docs` for feature configuration options and customization patterns. @@ -47,6 +51,18 @@ Enable in `config/fortify.php` features array: > Use `search-docs` for TOTP implementation and recovery code handling patterns. +### Passkeys Setup + +``` +- [ ] Add PasskeyAuthenticatable trait to User model and implement PasskeyUser +- [ ] Enable passkeys feature in config/fortify.php +- [ ] If the passkeys table migration is missing, publish via `php artisan vendor:publish --tag=fortify-migrations` and migrate +- [ ] Configure passkeys relying_party_id, allowed_origins, user_handle_secret, and timeout if defaults are not suitable +- [ ] Build UI with @laravel/passkeys for registration, login, confirmation, and deletion +``` + +> Use `search-docs` for passkey configuration options. For `@laravel/passkeys` frontend usage, refer to the package's README on npm. + ### Email Verification Setup ``` @@ -125,4 +141,11 @@ Configure via `fortify.limiters.login` in config. Default configuration throttle | Confirm 2FA | POST | `/user/confirmed-two-factor-authentication` | | 2FA Challenge | POST | `/two-factor-challenge` | | Get QR Code | GET | `/user/two-factor-qr-code` | -| Recovery Codes | GET/POST | `/user/two-factor-recovery-codes` | \ No newline at end of file +| Recovery Codes | GET/POST | `/user/two-factor-recovery-codes` | +| Passkey Login Options | GET | `/passkeys/login/options` | +| Passkey Login | POST | `/passkeys/login` | +| Passkey Confirm Options| GET | `/passkeys/confirm/options` | +| Passkey Confirm | POST | `/passkeys/confirm` | +| Passkey Options | GET | `/user/passkeys/options` | +| Register Passkey | POST | `/user/passkeys` | +| Delete Passkey | DELETE | `/user/passkeys/{passkey}` | diff --git a/.agents/skills/inertia-react-development/SKILL.md b/.agents/skills/inertia-react-development/SKILL.md index bb01fd9c..5b3e5207 100644 --- a/.agents/skills/inertia-react-development/SKILL.md +++ b/.agents/skills/inertia-react-development/SKILL.md @@ -358,4 +358,4 @@ Server-side patterns (Inertia::render, props, middleware) are covered in inertia - Forgetting to add loading states (skeleton screens) when using deferred props - Not handling the `undefined` state of deferred props before data loads - Using `