Skip to content

Add plugin ratings and admin-only reporting - #495

Merged
simonhamp merged 5 commits into
NativePHP:mainfrom
lessevv:feat/plugin-ratings-and-reports
Sep 5, 2026
Merged

simonhamp merged 5 commits into
NativePHP:mainfrom
lessevv:feat/plugin-ratings-and-reports

Conversation

@lessevv

@lessevv lessevv commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Logged-in users can leave a 1–5 star rating on a plugin they own or have access to (free plugins: any logged-in user; paid: requires a license/access, reusing User::hasPluginAccess()) — one rating per user, editable, removable.
  • Logged-in users can report a plugin as malicious or its author as unresponsive — a private, admin-only channel, distinct from the existing developer support/messaging flow. One open report per user per plugin; a new one can be filed once the prior one is resolved or dismissed.
  • Admins get a Plugin Reports resource (Filament) with resolve/dismiss actions, a nav badge for open reports, and an open-reports column on the Plugins list. Ratings can be moderated (deleted) from a new relation manager on the Plugin resource.
  • The public plugin page shows the star average/count, a rating widget, and a collapsible "Report this plugin" panel that's explicitly not for bugs — it links out to the plugin's GitHub Issues (or its support channel) first, before showing the report form.
  • Notification support address (support@nativephp.com) is pulled into config('mail.support_address') instead of being hardcoded in 7 different places.

🤖 Generated with Claude Code

lessevv and others added 5 commits September 4, 2026 21:40
Adds PluginRating and PluginReport models with their own migrations,
enums, policies, form requests, controllers, and routes. Free plugins
can be rated by any logged-in user; paid plugins reuse the existing
User::hasPluginAccess() check. Reports are a private admin-only channel
(distinct from the existing developer messaging thread) capped at one
open report per user per plugin.

Also extracts the hardcoded support@nativephp.com address used across
7 notification call sites into config('mail.support_address').

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Adds a Filament-only PluginReportResource with resolve/dismiss actions
and a nav badge for open reports, plus an open-reports count column on
the Plugins list and a RatingsRelationManager so admins can moderate
abusive or fake ratings.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Shows the star average/count in the header, a rating widget for
eligible logged-in users, and a collapsible "Report this plugin"
panel. The report panel is not for bugs — it surfaces the plugin's
GitHub Issues link (or its support channel) first, before the report
form itself.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
… rate

The "Log in to rate this plugin" link now passes the plugin page as a
redirect param, which showLogin() stores as url.intended. Login,
registration and GitHub sign-in all already end in redirect()->intended(),
so all three routes back to the plugin. Only same-site paths are accepted
so the param can't be used as an open redirect.

Also hides the rating in the plugin header until there is at least one,
dropping the "No ratings yet" line, and shows the average on the
marketplace cards.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013QiSkWpoC7KpTegPeM1Z78
@simonhamp

Copy link
Copy Markdown
Member

This is great! Thanks @lessevv

@simonhamp
simonhamp merged commit 00dfefb into NativePHP:main Sep 5, 2026
1 check passed
@lessevv
lessevv deleted the feat/plugin-ratings-and-reports branch September 5, 2026 21:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants