<laravel-boost-guidelines>
=== .ai/domain-glossary rules ===

# Domain Glossary

This document defines **canonical domain terminology**.
All contributors and AI assistants must use these terms consistently.

---

## Core Market Concepts

### Deregulated Market

A geographic electricity market where customers may choose their energy supplier independently of the utility that delivers power.

---

### Utility

The regulated entity responsible for:
- Power delivery
- Metering
- Billing coordination

**Key characteristics:**
- Operates in specific states and zip codes
- Enforces strict enrollment identifier requirements
- Owns the service territory

**Examples:**  
Oncor (TX), CenterPoint (TX), ComEd (IL)

---

### Service Territory

The geographic area served by a utility, defined by zip codes and/or municipalities.

A product is valid **only** within the service territory of its utility.

---

### Supplier (Retail Energy Provider)

A third-party company that sells electricity products to customers.

**Key characteristics:**
- Can operate in multiple states
- Can offer multiple products per utility
- Does not own delivery infrastructure

---

### Product

A commercial electricity offering made by a supplier for a specific utility.

A product is uniquely defined by:
- Supplier
- Utility
- Rate structure
- Contract term
- Pricing rules

Products are **immutable snapshots** for a given effective period.

---

## Enrollment & Identity

### Service Identifier

A utility-defined identifier used to associate a customer with a meter or service location.

**Examples:**
- ESIID (Texas)
- POD (Europe)
- Account Number

Formatting rules are utility-specific and strictly enforced.

---

### Enrollment

The process of switching a customer to a selected product.

Enrollment requires:
- Valid service identifiers
- Customer contact details
- Utility-specific validation rules

Enrollment logic must be deterministic and auditable.

---

## Usage & Pricing

### Usage (Consumption)

Electricity consumption, measured in kilowatt-hours (kWh).

Usage may be:
- Actual (month-specific)
- Estimated or typical (average)

Usage is an **input** to pricing, never inferred unless explicitly allowed.

---

### Billing Month

The calendar month associated with a reported or estimated usage value.

Used to:
- Apply seasonal pricing
- Resolve TOU rates
- Validate tier thresholds

---

### Rate Structure

The mathematical model defining how usage converts into cost.

Examples:
- Flat rate
- Tiered rate
- Time-of-Use (TOU)
- Hybrid models

---

### Tier

A usage range within a tiered rate structure.

Each tier defines:
- Lower and upper kWh bounds
- Price per kWh

Tiers must:
- Be non-overlapping
- Cover the entire usage domain (or fail loudly)

---

### Time-of-Use (TOU)

A rate structure where pricing varies by time period.

Common periods:
- On-peak
- Off-peak
- Shoulder

TOU requires a usage profile or assumptions defined explicitly.

---

### Passthrough Fees

Non-energy charges passed directly to the customer.

Examples:
- TDU charges
- Regulatory fees
- Capacity charges

Passthrough fees must be itemized and traceable.

---

## System & Architecture Concepts

### Normalization

The process of converting supplier-provided product data into a standardized internal format.

Normalization:
- Does not correct invalid data
- Rejects ambiguous definitions
- Preserves source metadata

---

### Pricing Determinism

Given:
- The same product definition
- The same usage inputs

The pricing engine must produce:
- The same output
- Every time
- With no hidden state

---

### Untrusted Data

Any data sourced externally (suppliers, APIs, uploads).

Untrusted data must:
- Be validated
- Never silently coerced
- Fail explicitly if invalid

---

### Canonical Source

The single authoritative source of truth for a data concept.

Example:
- Utility identifier formats come from utilities
- Product pricing rules come from suppliers
- Calculation logic comes from this codebase

=== .ai/architecture rules ===

# System Architecture

This document describes the **high-level architecture** of the Energy Marketplace backend.
It explains how the system is structured, how responsibilities are separated,
and how major components interact.

This architecture prioritizes:
- Correctness in pricing and enrollment
- Clear domain boundaries
- Long-term extensibility
- Effective AI-assisted development

---

## 1. Architectural Overview

The system is a **Laravel-based backend application** that provides:

- Public product search and comparison APIs
- Accurate pricing calculations based on usage inputs
- Supplier and admin management APIs
- Enrollment validation and orchestration

The frontend (React SPA) is **out of scope** and treated as an external consumer.

---

## 2. High-Level Component Diagram (Logical)

```text
Client (SPA / API Consumer)
        |
        v
API Layer (Controllers)
        |
        v
Application Services
        |
        v
Domain Layer
        |
        +------------------+
        |                  |
        v                  v
Pricing Engines     Enrollment Validators
        |
        v
Persistence Layer (DB / Cache)

```

---

## 3. Layered Responsibilities

### 3.1 API Layer (Controllers)

**Responsibilities**
- Accept and validate HTTP requests
- Perform authentication and authorization
- Transaction requests into domain-friendly DTOs
- Return serialized responses

**Non-responsibilities**
- Business logic
- Pricing calculations
- Enrollment rule enforcement

Controllers should be thin and orchestration-focused.

### 3.2 Application Services

**Purpose**

Application services coordinate workflows across multiple domain components.

** Examples **

- ProductSearchService
- PricingCalculatorService
- EnrollmentService

**Responsibilities**

- Combine domain operations
- Enforce use-case-specific rules
- Handle transactions when required

Services **may**:
- Call repositories
- Select pricing engines via factories
- Perform caching

Services **must not**:
- Embed pricing math
- Encode utility-specific rules inline

### 3.3 Domain layer

The domain layer models the business concepts and rules.

This includes:
- Utilities
- Suppliers
- Products
- Pricing
- Enrollment

** Key principles **
- Domain logic is framework-agnostic
- Inputs and outputs are explicit
- All logic must be deterministic and testable

---

## 4. Pricing Architecture

Pricing is intentionally isolated due to its complexity and regulatory sensitivity.

### 4.1 Pricing Flow

```text
Usage Input
    |
    v
PricingInput DTO
    |
    v
Pricing Engine Factory
    |
    v
Concrete Pricing Engine
    |
    v
PricingResult DTO

```

### 4.2 Design Guarantees

- No hidden state: All inputs are explicit
- No implicit database reads: Pricing engines receive all data via DTOs
- Same input -> same output: Deterministic calculations
- Fail loudly on invalid input or configurations

Pricing engines are **pure computation units**.

### 4.3 Search and Pricing Sequence Diagram

## Search + Pricing Sequence Diagram

The following sequence describes a **single API request** where the user searches for products and requests pricing based on usage input.

> Notes:
> - Pricing is computed **after** candidate products are identified.
> - Pricing engines are pure and deterministic (no hidden DB reads).
> - Optional caching can occur at search and pricing stages.

```mermaid
sequenceDiagram
    autonumber
    actor Client as Client (SPA)
    participant API as API Controller
    participant Auth as Auth/Policy
    participant SearchSvc as ProductSearchService
    participant ProdRepo as ProductRepository
    participant RefRepo as ReferenceDataRepository
    participant Cache as Cache
    participant PriceSvc as PricingCalculatorService
    participant EngineFactory as PricingEngineFactory
    participant Engine as PricingEngine
    participant ResultFmt as Result Formatter

    Client->>API: POST /api/products/search\n{location, filters, usage?}
    API->>Auth: Authorize (public search / rate limits / guards)
    Auth-->>API: OK

    API->>SearchSvc: search(criteria)
    SearchSvc->>Cache: get(searchKey)
    alt Search cache hit
        Cache-->>SearchSvc: productIds + metadata
    else Search cache miss
        SearchSvc->>RefRepo: resolveUtility(location)\n(zip/state → utility/service territory)
        RefRepo-->>SearchSvc: utilityId + constraints

        SearchSvc->>ProdRepo: findProducts(utilityId, filters)
        ProdRepo-->>SearchSvc: productList (unpriced)

        SearchSvc->>Cache: put(searchKey, productList)
    end

    alt usage provided
        API->>PriceSvc: priceProducts(productList, usageInput)
        PriceSvc->>RefRepo: loadReferenceInputs(productList)\n(tiers, TOU defs, passthrough rules)
        RefRepo-->>PriceSvc: pricingDefinitions

        loop for each product (or batched)
            PriceSvc->>Cache: get(priceKey(productId, usage, month, assumptions))
            alt Pricing cache hit
                Cache-->>PriceSvc: PricingResult
            else Pricing cache miss
                PriceSvc->>EngineFactory: makeEngine(product.rateStructure)
                EngineFactory-->>PriceSvc: Engine

                PriceSvc->>Engine: calculate(PricingInput)
                Engine-->>PriceSvc: PricingResult

                PriceSvc->>Cache: put(priceKey, PricingResult)
            end
        end

        PriceSvc-->>API: pricedProductList
    else usage not provided
        SearchSvc-->>API: unpricedProductList
    end

    API->>ResultFmt: normalizeResponse(products)\n(include line items, assumptions)
    ResultFmt-->>API: response payload
    API-->>Client: 200 OK\n{products, pricing?, meta}
```

---

## 5. Enrollment Architecture

Enrollment logic enforces utility-specific constraints.

**Key rules**
- Utility identifier formats are authoritative
- Validate is deterministic
- All validation failures are explicit

Enrollment consists of:
- Input validation
- Utility rule enforcement
- Supplier compatibility checks
- State transitions (pending -> submitted -> confirmed)

---

## 6. Data Architecture

### 6.1 Primary Database (MySQL)

Used for:
- Core domain data
- Transactions
- Application state

### 6.2 Secondary Database (MySQL, Read-only)

Although not currently implemented, a read-only replica is planned for:
- Offloading read-heavy queries
- Improving scalability
- Analytics style queries

Raw SQL is acceptable and preferred for complex reports.

---

## 7. Reference Data Strategy

Certain data is treated as reference data:
- Utilities
- States
- Service territories
- Identifier formats

Reference data:
- Changes slowly
- Is version-controlled when possible
- Should not be duplicated across systems

---

## 8. Caching Strategy

Caching is used for:
- Product search results
- Pricing results for identical inputs
- Reference data

Caching rules:
- Never cache partial or invalid results
- Cache keys must include all pricing inputs
- Cached pricing must be able to be invalidated on product changes

---

## 9. Error Handling Philosopgy

- Never silently correct invalid data
- Prefer explicit exceptions to soft failures
- Errors should be explainable and traceable

Pricing and enrollment errors are first-class outcomes, not edge cases.

---

## 10. Security and Authorization

**Authentication**
- Public APIs: unauthenticated (search only)
- Admin/Supplier APIs: authenticated

**Authorization**
- Role-based via Spatie permissions
- Authorization enforced at controller and service boundaries

---

## 11. Testing Strategy

**Unit Tests**
- Domain logic
- Pricing engines
- Validation rules

**Feature Tests**
- API behavior
- Authorization
- Error Cases

Pricing logic must have **high test coverage** due to financial risk.

---

## 12. AI-Assisted Development Rules

AI tools must:
- Treat ai-context.md as canonical
- Follow domain glossary terminology
- Avoid inventing business rules
- Ask before changing assumptions

If documentation and code disaggree, documentation wins until corrected.

---

## 13. Evolution Guidelines

When extending the system:
- Add new pricing engines rather than modifying existing ones
- Add new utilities without altering core pricing logic
- Preserve backward compatibility where possible, especially in APIs

Architecture changes must update this document.

=== .ai/ai-context rules ===

# AI Context — Project Canonical Reference

This document defines the **authoritative project context**.
Any AI assistant (ChatGPT, GitHub Copilot, IDE agents) MUST treat this
file as canonical.

---

## Project Overview

- **Purpose**
  A backend Laravel application that powers a public energy-product
  search and enrollment system for deregulated markets.

- **Primary Responsibilities**
    - Aggregate energy products from multiple suppliers
    - Normalize product data across utilities and states
    - Calculate usage-based pricing accurately
    - Expose clean APIs for a frontend SPA (not developed here)
    - Support enrollment workflows and future customer portals

---

## Core Domain Concepts

### Utilities

- Utilities operate in **specific states and zip codes**
- Each utility defines:
    - Enrollment identifier(s)
        - e.g. ESIID, POD, Account Number
    - Strict formatting rules
- A product is always tied to **exactly one utility**

### Suppliers

- Third-party retailers providing products
- A supplier can offer products in multiple utilities and states
- Products from different suppliers can target the same utility

### Products

- Products are defined by:
    - Utility
    - Rate structure
    - Contract term
    - Pricing rules
- Product data may come from:
    - Manual admin entry
    - Automated API ingestion

---

## Usage & Pricing Rules

- Customers may provide:
    - Actual monthly usage + month
    - OR typical monthly usage
- Pricing calculations MUST support:
    - Tiered kWh pricing
    - Time-of-Use (TOU) models
    - Passthrough and regulatory fees
- Calculations must be deterministic and reproducible

---

## Architecture & Tech Stack

- **Framework**: Laravel (current target: Laravel 12)
- **PHP**: 8.4+
- **Primary DB**: MySQL (write)
- **Caching / Queues**: Database-backed queues and caching
- **Auth**:
    - Public search (unauthenticated)
    - Supplier/admin APIs (role-based via Spatie)
- **Frontend**:
    - External SPA (React)
    - Backend provides auth + APIs only

---

## Design Principles

- Domain logic over framework magic
- Prefer explicit services over fat models
- Raw SQL acceptable for reporting and performance-critical queries
- Idempotent operations where possible
- Defensive validation of all third-party data

---

## Hard Constraints (Do Not Violate)

- Utilities dictate identifier formats — never “guess”
- Pricing math must never silently fail
- Supplier data is considered untrusted
- Frontend assumptions must not leak into backend logic

---

## AI Assistance Guidelines

When generating code:
- Follow existing naming conventions
- Prefer small, testable services
- Avoid premature abstraction
- Ask before changing domain assumptions

When unsure:
- Ask clarifying questions rather than inventing behavior

=== .ai/ai-handoff rules ===

# Project AI Handoff Summary

## What This System Is

A Laravel backend for searching, comparing, and enrolling in
deregulated electricity products across multiple utilities,
states, and suppliers.

## The Problem Domain

- Utilities define where power is delivered and how accounts are identified
- Suppliers sell products within utility territories
- Products differ by rate structure, term length, and pricing rules
- Customers must be shown fair, accurate comparisons

## Key Challenges

- Normalizing inconsistent supplier data
- Enforcing utility-specific enrollment rules
- Calculating pricing with tiers, TOU, and passthrough fees
- Scaling search and pricing logic without data duplication

## What We Optimize For

- Correctness over cleverness
- Predictable pricing math
- Clear domain modeling
- Future extensibility (new states, utilities, suppliers)

## What This Repo Is NOT

- Not a frontend SPA
- Not responsible for UX or presentation
- Not making regulatory decisions

## Mental Model to Use

Utilities define the “grid reality”.
Suppliers define commercial offerings.
Products sit at the intersection.
Search filters narrow utility → supplier → product.
Pricing resolves last, using customer usage input.

=== foundation rules ===

# Laravel Boost Guidelines

The Laravel Boost guidelines are specifically curated by Laravel maintainers for this application. These guidelines should be followed closely to ensure the best experience when building Laravel applications.

## Foundational Context

This application is a Laravel application and its main Laravel ecosystems package & versions are below. You are an expert with them all. Ensure you abide by these specific packages & versions.

- php - 8.4.17
- inertiajs/inertia-laravel (INERTIA) - v2
- laravel/fortify (FORTIFY) - v1
- laravel/framework (LARAVEL) - v12
- laravel/prompts (PROMPTS) - v0
- laravel/wayfinder (WAYFINDER) - v0
- laravel/mcp (MCP) - v0
- laravel/pint (PINT) - v1
- laravel/sail (SAIL) - v1
- pestphp/pest (PEST) - v4
- phpunit/phpunit (PHPUNIT) - v12
- @inertiajs/react (INERTIA) - v2
- react (REACT) - v19
- tailwindcss (TAILWINDCSS) - v4
- @laravel/vite-plugin-wayfinder (WAYFINDER) - v0
- eslint (ESLINT) - v9
- prettier (PRETTIER) - v3

## Skills Activation

This project has domain-specific skills available. You MUST activate the relevant skill whenever you work in that domain—don't wait until you're stuck.

- `wayfinder-development` — Activates whenever referencing backend routes in frontend components. Use when importing from @/actions or @/routes, calling Laravel routes from TypeScript, or working with Wayfinder route functions.
- `pest-testing` — Tests applications using the Pest 4 PHP framework. Activates when writing tests, creating unit or feature tests, adding assertions, testing Livewire components, browser testing, debugging test failures, working with datasets or mocking; or when the user mentions test, spec, TDD, expects, assertion, coverage, or needs to verify functionality works.
- `inertia-react-development` — Develops Inertia.js v2 React client-side applications. Activates when creating React pages, forms, or navigation; using &lt;Link&gt;, &lt;Form&gt;, useForm, or router; working with deferred props, prefetching, or polling; or when user mentions React with Inertia, React pages, React forms, or React navigation.
- `tailwindcss-development` — Styles applications using Tailwind CSS v4 utilities. Activates when adding styles, restyling components, working with gradients, spacing, layout, flex, grid, responsive design, dark mode, colors, typography, or borders; or when the user mentions CSS, styling, classes, Tailwind, restyle, hero section, cards, buttons, or any visual/UI changes.

## Conventions

- You must follow all existing code conventions used in this application. When creating or editing a file, check sibling files for the correct structure, approach, and naming.
- Use descriptive names for variables and methods. For example, `isRegisteredForDiscounts`, not `discount()`.
- Check for existing components to reuse before writing a new one.

## Verification Scripts

- Do not create verification scripts or tinker when tests cover that functionality and prove they work. Unit and feature tests are more important.

## Application Structure & Architecture

- Stick to existing directory structure; don't create new base folders without approval.
- Do not change the application's dependencies without approval.

## Frontend Bundling

- If the user doesn't see a frontend change reflected in the UI, it could mean they need to run `npm run build`, `npm run dev`, or `composer run dev`. Ask them.

## Documentation Files

- You must only create documentation files if explicitly requested by the user.

## Replies

- Be concise in your explanations - focus on what's important rather than explaining obvious details.

=== boost rules ===

# Laravel Boost

- Laravel Boost is an MCP server that comes with powerful tools designed specifically for this application. Use them.

## Artisan

- Use the `list-artisan-commands` tool when you need to call an Artisan command to double-check the available parameters.

## URLs

- Whenever you share a project URL with the user, you should use the `get-absolute-url` tool to ensure you're using the correct scheme, domain/IP, and port.

## Tinker / Debugging

- You should use the `tinker` tool when you need to execute PHP to debug code or query Eloquent models directly.
- Use the `database-query` tool when you only need to read from the database.

## Reading Browser Logs With the `browser-logs` Tool

- You can read browser logs, errors, and exceptions using the `browser-logs` tool from Boost.
- Only recent browser logs will be useful - ignore old logs.

## Searching Documentation (Critically Important)

- Boost comes with a powerful `search-docs` tool you should use before trying other approaches when working with Laravel or Laravel ecosystem packages. This tool automatically passes a list of installed packages and their versions to the remote Boost API, so it returns only version-specific documentation for the user's circumstance. You should pass an array of packages to filter on if you know you need docs for particular packages.
- Search the documentation before making code changes to ensure we are taking the correct approach.
- Use multiple, broad, simple, topic-based queries at once. For example: `['rate limiting', 'routing rate limiting', 'routing']`. The most relevant results will be returned first.
- Do not add package names to queries; package information is already shared. For example, use `test resource table`, not `filament 4 test resource table`.

### Available Search Syntax

1. Simple Word Searches with auto-stemming - query=authentication - finds 'authenticate' and 'auth'.
2. Multiple Words (AND Logic) - query=rate limit - finds knowledge containing both "rate" AND "limit".
3. Quoted Phrases (Exact Position) - query="infinite scroll" - words must be adjacent and in that order.
4. Mixed Queries - query=middleware "rate limit" - "middleware" AND exact phrase "rate limit".
5. Multiple Queries - queries=["authentication", "middleware"] - ANY of these terms.

=== php rules ===

# PHP

- Always use curly braces for control structures, even for single-line bodies.

## Constructors

- Use PHP 8 constructor property promotion in `__construct()`.
    - <code-snippet>public function __construct(public GitHub $github) { }</code-snippet>
- Do not allow empty `__construct()` methods with zero parameters unless the constructor is private.

## Type Declarations

- Always use explicit return type declarations for methods and functions.
- Use appropriate PHP type hints for method parameters.

<code-snippet name="Explicit Return Types and Method Params" lang="php">
protected function isAccessible(User $user, ?string $path = null): bool
{
    ...
}
</code-snippet>

## Enums

- Typically, keys in an Enum should be TitleCase. For example: `FavoritePerson`, `BestLake`, `Monthly`.

## Comments

- Prefer PHPDoc blocks over inline comments. Never use comments within the code itself unless the logic is exceptionally complex.

## PHPDoc Blocks

- Add useful array shape type definitions when appropriate.

=== herd rules ===

# Laravel Herd

- The application is served by Laravel Herd and will be available at: `https?://[kebab-case-project-dir].test`. Use the `get-absolute-url` tool to generate valid URLs for the user.
- You must not run any commands to make the site available via HTTP(S). It is always available through Laravel Herd.

=== tests rules ===

# Test Enforcement

- Every change must be programmatically tested. Write a new test or update an existing test, then run the affected tests to make sure they pass.
- Run the minimum number of tests needed to ensure code quality and speed. Use `php artisan test --compact` with a specific filename or filter.

=== inertia-laravel/core rules ===

# Inertia

- Inertia creates fully client-side rendered SPAs without modern SPA complexity, leveraging existing server-side patterns.
- Components live in `resources/js/Pages` (unless specified in `vite.config.js`). Use `Inertia::render()` for server-side routing instead of Blade views.
- ALWAYS use `search-docs` tool for version-specific Inertia documentation and updated code examples.
- IMPORTANT: Activate `inertia-react-development` when working with Inertia client-side patterns.

=== inertia-laravel/v2 rules ===

# Inertia v2

- Use all Inertia features from v1 and v2. Check the documentation before making changes to ensure the correct approach.
- New features: deferred props, infinite scrolling (merging props + `WhenVisible`), lazy loading on scroll, polling, prefetching.
- When using deferred props, add an empty state with a pulsing or animated skeleton.

=== laravel/core rules ===

# Do Things the Laravel Way

- Use `php artisan make:` commands to create new files (i.e. migrations, controllers, models, etc.). You can list available Artisan commands using the `list-artisan-commands` tool.
- If you're creating a generic PHP class, use `php artisan make:class`.
- Pass `--no-interaction` to all Artisan commands to ensure they work without user input. You should also pass the correct `--options` to ensure correct behavior.

## Database

- Always use proper Eloquent relationship methods with return type hints. Prefer relationship methods over raw queries or manual joins.
- Use Eloquent models and relationships before suggesting raw database queries.
- Avoid `DB::`; prefer `Model::query()`. Generate code that leverages Laravel's ORM capabilities rather than bypassing them.
- Generate code that prevents N+1 query problems by using eager loading.
- Use Laravel's query builder for very complex database operations.

### Model Creation

- When creating new models, create useful factories and seeders for them too. Ask the user if they need any other things, using `list-artisan-commands` to check the available options to `php artisan make:model`.

### APIs & Eloquent Resources

- For APIs, default to using Eloquent API Resources and API versioning unless existing API routes do not, then you should follow existing application convention.

## Controllers & Validation

- Always create Form Request classes for validation rather than inline validation in controllers. Include both validation rules and custom error messages.
- Check sibling Form Requests to see if the application uses array or string based validation rules.

## Authentication & Authorization

- Use Laravel's built-in authentication and authorization features (gates, policies, Sanctum, etc.).

## URL Generation

- When generating links to other pages, prefer named routes and the `route()` function.

## Queues

- Use queued jobs for time-consuming operations with the `ShouldQueue` interface.

## Configuration

- Use environment variables only in configuration files - never use the `env()` function directly outside of config files. Always use `config('app.name')`, not `env('APP_NAME')`.

## Testing

- When creating models for tests, use the factories for the models. Check if the factory has custom states that can be used before manually setting up the model.
- Faker: Use methods such as `$this->faker->word()` or `fake()->randomDigit()`. Follow existing conventions whether to use `$this->faker` or `fake()`.
- When creating tests, make use of `php artisan make:test [options] {name}` to create a feature test, and pass `--unit` to create a unit test. Most tests should be feature tests.

## Vite Error

- If you receive an "Illuminate\Foundation\ViteException: Unable to locate file in Vite manifest" error, you can run `npm run build` or ask the user to run `npm run dev` or `composer run dev`.

=== laravel/v12 rules ===

# Laravel 12

- CRITICAL: ALWAYS use `search-docs` tool for version-specific Laravel documentation and updated code examples.
- Since Laravel 11, Laravel has a new streamlined file structure which this project uses.

## Laravel 12 Structure

- In Laravel 12, middleware are no longer registered in `app/Http/Kernel.php`.
- Middleware are configured declaratively in `bootstrap/app.php` using `Application::configure()->withMiddleware()`.
- `bootstrap/app.php` is the file to register middleware, exceptions, and routing files.
- `bootstrap/providers.php` contains application specific service providers.
- The `app\Console\Kernel.php` file no longer exists; use `bootstrap/app.php` or `routes/console.php` for console configuration.
- Console commands in `app/Console/Commands/` are automatically available and do not require manual registration.

## Database

- When modifying a column, the migration must include all of the attributes that were previously defined on the column. Otherwise, they will be dropped and lost.
- Laravel 12 allows limiting eagerly loaded records natively, without external packages: `$query->latest()->limit(10);`.

### Models

- Casts can and likely should be set in a `casts()` method on a model rather than the `$casts` property. Follow existing conventions from other models.

=== wayfinder/core rules ===

# Laravel Wayfinder

Wayfinder generates TypeScript functions for Laravel routes. Import from `@/actions/` (controllers) or `@/routes/` (named routes).

- IMPORTANT: Activate `wayfinder-development` skill whenever referencing backend routes in frontend components.
- Invokable Controllers: `import StorePost from '@/actions/.../StorePostController'; StorePost()`.
- Parameter Binding: Detects route keys (`{post:slug}`) — `show({ slug: "my-post" })`.
- Query Merging: `show(1, { mergeQuery: { page: 2, sort: null } })` merges with current URL, `null` removes params.
- Inertia: Use `.form()` with `<Form>` component or `form.submit(store())` with useForm.

=== pint/core rules ===

# Laravel Pint Code Formatter

- You must run `vendor/bin/pint --dirty` before finalizing changes to ensure your code matches the project's expected style.
- Do not run `vendor/bin/pint --test`, simply run `vendor/bin/pint` to fix any formatting issues.

=== pest/core rules ===

## Pest

- This project uses Pest for testing. Create tests: `php artisan make:test --pest {name}`.
- Run tests: `php artisan test --compact` or filter: `php artisan test --compact --filter=testName`.
- Do NOT delete tests without approval.
- CRITICAL: ALWAYS use `search-docs` tool for version-specific Pest documentation and updated code examples.
- IMPORTANT: Activate `pest-testing` every time you're working with a Pest or testing-related task.

=== inertia-react/core rules ===

# Inertia + React

- IMPORTANT: Activate `inertia-react-development` when working with Inertia React client-side patterns.

=== tailwindcss/core rules ===

# Tailwind CSS

- Always use existing Tailwind conventions; check project patterns before adding new ones.
- IMPORTANT: Always use `search-docs` tool for version-specific Tailwind CSS documentation and updated code examples. Never rely on training data.
- IMPORTANT: Activate `tailwindcss-development` every time you're working with a Tailwind CSS or styling-related task.
</laravel-boost-guidelines>
