Community코딩 & 개발github.com

Taldres/laravel-waitlist

Operate a taldres/laravel-waitlist installation: answer access and erasure requests, withdraw a purpose on request, apply retention, erase a list once its purpose is fulfilled, rotate APP_KEY with waitlist:rekey, export a list, and check the setup before going live.

laravel-waitlist란 무엇인가요?

laravel-waitlist is a Claude Code agent skill that operate a taldres/laravel-waitlist installation: answer access and erasure requests, withdraw a purpose on request, apply retention, erase a list once its purpose is fulfilled, rotate APP_KEY with waitlist:rekey, export a list, and check the setup before going live.

지원 대상~Claude Code~Codex CLI~Cursor
npx skills add https://github.com/Taldres/laravel-waitlist/tree/HEAD/resources/boost/skills/laravel-waitlist-privacy-operations

Installed? Explore more 코딩 & 개발 skills: steipete/bluebubbles, steipete/eightctl, steipete/blucli · View all 6 →

즐겨 사용하는 AI에게 물어보기

이 에이전트 스킬이 미리 로드된 새 채팅을 엽니다.

문서

Laravel Waitlist: privacy operations

Use this skill for day-to-day data protection tasks around taldres/laravel-waitlist: requests from people on the list, retention, key rotation, exports and the go-live check.

Primary Goal

  • carry out each request with the package's own APIs and commands, across every project where the request concerns the person, and say what stays outside the package

Workflow

Access request

php artisan waitlist:show [email protected] --pretty   # every project; --json for a machine-readable copy
Waitlist::allProjects()->personalData('[email protected]'); // Collection<PersonalData>

Erasure request

php artisan waitlist:forget [email protected]          # every project
Waitlist::allProjects()->forget('[email protected]');  // number of entries erased

Erasure deletes the address, its cycles and consents, and clears identifying fields in its log rows; it fires EntryForgotten per entry, which listeners use to delete copies at providers. Backups, queues, logs, exports and provider copies need separate handling.

Withdrawal that arrives by mail

Waitlist::for('beta')->withdraw('[email protected]', 'newsletter'); // optional purpose: every list of the project
Waitlist::for('beta')->unsubscribe('[email protected]');            // leave this list

Erase a list once its purpose is fulfilled

php artisan waitlist:forget --list=beta --all          # asks first; --force without a terminal
Waitlist::for('beta')->forgetAll();

Retention

waitlist:prune runs on the package's schedule (waitlist.retention.schedule, 15 3 * * *; null leaves scheduling to you, a cron expression that can never run is refused); Laravel's scheduler must run (php artisan schedule:run every minute). Periods in waitlist.retention: pending_days (30), unsubscribed_days (1095), request_metadata_days (30); null keeps data, while a period reaching back before 1970 (a 36500-day "forever") is refused. waitlist:prune applies every period that reads, then reports the ones that do not and fails the run: watch the logs and the exit code. These are technical defaults, not legal recommendations. Active confirmed entries and the remaining reporting rows do not expire automatically.

Rotate APP_KEY

  1. Put the old key into APP_PREVIOUS_KEYS, set the new APP_KEY, deploy.
  2. php artisan waitlist:rekey
  3. Remove the old key once no queued job or backup needs it.

Without the old key, addresses can neither be read nor found by email, and each unsubscribe token is replaced the next time it is needed, so links sent earlier stop working from then on.

Export

php artisan waitlist:export beta --status=confirmed --path=storage/app/beta.csv

Columns come from waitlist.export.columns, limited to CsvExporter::EXPORTABLE (no tokens). The file holds addresses in plain text; delete it when done.

Record of processing

php artisan waitlist:privacy [--project=]

It describes configured package storage, purposes, the metadata fields of each list, retention and listeners registered for package events. It is input, not a complete record: it does not audit infrastructure or find every recipient.

Go-live check

  • APP_KEY backed up apart from the database
  • double opt-in on; IP and user agent off unless needed
  • fields per project and list (->fields()) as few as possible, none if in doubt
  • scheduler running; retention periods chosen and justified
  • config reads: no empty WAITLIST_*= line in .env (an empty value is refused; delete the line for the default), php artisan config:cache run again after a package update (and route:cache after a routes setting changed), no InvalidConfigurationException in the logs
  • signup form renders Waitlist::purposes() or GET /waitlist/purposes; optional purposes unticked
  • confirmation listener records Waitlist::confirmationMailed()
  • every mail has a per-purpose unsubscribe link and one-click headers
  • ManageLinkRequested mailed only to the address
  • queued listeners implement ShouldBeEncrypted; EntryForgotten, EntryUnsubscribed and ConsentWithdrawn reach every provider
  • bot protection and trusted proxies configured when the routes are on

Rules, References, and Templates

Examples

  • "A user asked us to delete their data": verify the request, then php artisan waitlist:forget <email>, and check providers and exports.
  • "We launched, the beta list has served its purpose": waitlist:forget --list=beta --all.
  • "We rotated APP_KEY and lookups fail": restore the old key in APP_PREVIOUS_KEYS, then waitlist:rekey.

Anti-patterns

  • Deleting rows with SQL or WaitlistEntry::query()->delete(); erasure must go through the package so the log is stripped and EntryForgotten fires.
  • Searching where('email', ...): addresses are encrypted; use forEmail() or the facade.
  • Erasing with Waitlist::forget() (default project only) for a person on several projects.
  • Rotating APP_KEY without APP_PREVIOUS_KEYS.
  • Presenting waitlist:privacy output as a complete Art. 30 record.

Individual skills in this repo

This repo contains 13 individual skills — each has its own dedicated page.

Taldres/laravel-waitlist

Use this skill when reviewing Laravel package compatibility across composer constraints, PHP versions, Laravel versions, Testbench versions, dependency stability lanes, Windows CI, or matrix-sensitive code and workflow changes.

Taldres/laravel-waitlist

Use this skill when creating or updating the bundled Laravel Boost skill under resources/boost/skills from the package implementation and package documentation. Trigger after public APIs, commands, config, routes, views, publish tags, README content, or examples change.

Taldres/laravel-waitlist

Use this skill when preparing Laravel package releases: CHANGELOG.md updates, generated release notes, GitHub release workflows, version checks, tags, release validation, or release automation changes. Never publish autonomously.

Taldres/laravel-waitlist

Use this skill when adding Laravel package capabilities or wiring them through the service provider: commands, migrations, routes, config merges, views, translations, assets, middleware, publish tags, workbench files, or console-only behavior.

Taldres/laravel-waitlist

Use this skill when writing, editing, fixing, or reviewing package tests with Pest 4/5 and Orchestra Testbench, including TDD, feature tests, unit tests, type coverage, arch tests, workbench behavior, commands, routes, config, migrations, and publishable resources.

Taldres/laravel-waitlist

Integrate taldres/laravel-waitlist in a Laravel application: define purposes, lists and fields, build the signup form, send the confirmation mail from events, add a preference page, and keep consent, retention and encryption intact.

Taldres/laravel-waitlist

Build the pages of a taldres/laravel-waitlist integration: the signup form with the registered wording, and the confirm, unsubscribe and preference pages, either in Laravel controllers (Blade, Livewire, Inertia) or in an SPA or static site over the package's JSON API, including CORS and bot protection.

Taldres/laravel-waitlist

Turn a taldres/laravel-waitlist waitlist into a launch: invite people in batches in signup order, let invited addresses register, announce the launch to everyone who agreed, and erase the list once its purpose is fulfilled.

Taldres/laravel-waitlist

Send the mails of a taldres/laravel-waitlist integration: the double opt-in confirmation, the preference page link, a welcome mail, launch mails and newsletters to the people who agreed, with the right unsubscribe links, one-click headers and a sender per project.

Taldres/laravel-waitlist

Run the waitlists of several products in one Laravel app with taldres/laravel-waitlist projects: define projects, scope facade calls with project(), resolve the project of HTTP signups, send mail per project, handle requests across all projects, or keep projects in a database for a central waitlist API.

Taldres/laravel-waitlist

Keep a newsletter tool such as Brevo, Mailchimp or Mailcoach in step with a taldres/laravel-waitlist waitlist: add confirmed contacts per purpose, remove them on withdrawal and erasure, and carry unsubscribes made at the provider back into the waitlist via a webhook.

Taldres/laravel-waitlist

Build waitlist statistics with taldres/laravel-waitlist: signups and confirmations per day for charts, totals and confirmation rates for a period, the confirmed count on any past day, and how many people are on a list right now, for dashboards, admin pages and API endpoints.

Taldres/laravel-waitlist

Write feature tests for an application's taldres/laravel-waitlist integration: get the plain tokens from events, assert the confirmation and other mails, test the signup, confirm and unsubscribe flows in PHP and over the package's HTTP routes, and bypass rate limits and bot checks in tests.

관련 스킬