Leantime › Source Documentation
44
Domain Modules
25+
Core Services
36
CSS Components
70+
npm Packages
14
Middleware
🏠

Introduction

What Leantime is and how it works

Leantime is an open-source project management system built specifically for non-project managers and neurodivergent teams. It blends the simplicity of Trello with the power of Jira. The codebase is a monolith with a clean separation between a PHP/Laravel backend and a JavaScript/LESS/Tailwind frontend, bundled by Laravel Mix (Webpack).

ℹ️

License: AGPL-3.0  |  Author: Marcel Folaron  |  Homepage: leantime.io  |  Support: support@leantime.io

🐘

Backend Stack

PHP 8.2+, Laravel 11, MySQL/PDO, Redis for caching, custom event bus, REST + MCP API surface.

PHP 8.2Laravel 11MySQL
🌐

Frontend Stack

Vanilla JS + jQuery, HTMX for partial page updates, LESS + Tailwind CSS, Webpack (Laravel Mix) build pipeline.

JavaScriptHTMXLESSTailwind
🔌

Integrations

AWS S3, Stripe, LDAP, OIDC, SAML2, CalDAV (SabreDAV), AI via Prism-PHP & NeuronAI, Sentry monitoring.

AWS S3OIDCAI
🏗️

Architecture Overview

Request lifecycle & high-level design

Every HTTP request enters through public/index.php, which bootstraps the Application (a Laravel Foundation app) and delegates to the Bootloader singleton. The bootloader captures the request type, picks the right kernel (HTTP vs CLI), runs middleware, and dispatches to the appropriate domain controller.

Browser / CLI
Client
→
public/index.php
Entry Point
→
Application.php
Laravel App
→
Bootloader
Singleton
→
HttpKernel
Middleware Stack
→
Domain Controller
Business Logic
→
View / JSON
Response
public/index.php — Application Bootstrap
// 1. Composer autoloader
require __DIR__.'/../vendor/autoload.php';

// 2. Instantiate Laravel-based Application
$app = new Leantime\Core\Application(dirname(__DIR__));

// 3. Bootloader picks HTTP or Console kernel
Leantime\Core\Bootloader::getInstance()->boot($app);
📁

Directory Structure

Top-level project layout
leantime-master/ ├── app/ ⇦ All PHP source (PSR-4 Leantime\) │ ├── Core/ ⇦ Framework kernel, DB, Auth, Events... │ ├── Domain/ ⇦ 44 business modules (Tickets, Projects...) │ ├── Views/ ⇦ Blade composers + shared templates │ ├── Language/ ⇦ i18n translation files │ ├── Plugins/ ⇦ Installed Leantime plugins │ └── helpers.php ⇦ Global helper functions ├── public/ ⇦ Web root (served by nginx/Apache) │ ├── assets/ │ │ ├── js/app/ ⇦ App JS source files │ │ ├── css/components/ ⇦ 36 CSS component files │ │ └── less/ ⇦ LESS entry points (main, app) │ └── dist/ ⇦ Compiled & versioned output ├── config/ ⇦ Laravel config + .env ├── storage/ ⇦ Logs, cache, file uploads ├── tests/ ⇦ Codeception test suites ├── webpack.mix.js ⇦ Frontend build definition ├── package.json ⇦ Node dependencies └── composer.json ⇦ PHP dependencies
⚙️ BACKEND SOURCE CODE

PHP / Laravel Backend

Built on Laravel 11 with a custom application bootstrap, domain-driven folder structure, a powerful event bus, and multi-layer middleware stack.

🔧

Core Layer app/Core/

Framework infrastructure — Application, Http, Auth, Cache, Events...
🚀

Application.php

Extends Illuminate\Foundation\Application. Overrides all path bindings to Leantime's custom layout, registers base service providers (Events, Log, Routing) and fires bootstrap events.

Laravel IoCService Providers
🏁

Bootloader.php

Singleton that captures the HTTP request via IncomingRequest::capture(), selects HttpKernel or ConsoleKernel, handles the request, and terminates the lifecycle.

SingletonLifecycle
🌐

Http / HttpKernel.php

Defines the middleware stack for web, API, and HTMX routes. IncomingRequest auto-detects request type (web, API, CLI, HTMX).

MiddlewareRequest Types
🗄️

Database/

DatabaseManager extends Laravel's manager. LtPostgresConnection adds PostgreSQL support. DatabaseServiceProvider binds it into the container.

MySQLPostgreSQLPDO
🟢

Cache/

Redis-first caching via CacheServiceProvider. Falls back to Laravel's file driver. Used across domain repositories for query caching.

RedisCache
🔒

Auth/

AuthenticationServiceProvider wires token-based authentication. RoleResolver resolves user roles. Contracts define AuthenticatableInterface.

RBACTokensSessions
🗺️

Routing/

RouteLoader dynamically discovers and registers routes from all domain modules. FrontcontrollerServiceProvider wires it into Laravel's router.

Dynamic RoutesFrontcontroller

Mailer.php

Wraps PHPMailer with Leantime-specific templates, SMTP configuration from environment, and HTML-to-Markdown fallback for plain-text emails.

PHPMailerSMTP
app/Core/Http/HttpKernel.php — Middleware Groups (simplified)
protected $middlewareGroups = [
    'web' => [
        InitialHeaders::class,
        StartSession::class,
        Localization::class,
        AuthCheck::class,
        LoadPlugins::class,
        SetCacheHeaders::class,
    ],
    'api' => [
        RequestRateLimiter::class,
        VerifyCsrfToken::class,
    ],
];
🗀

Domain Layer app/Domain/

44 independent business modules — each following the same internal structure
💡

Convention: Every domain module follows the same internal layout: Controllers/ → Services/ → Repositories/ → Models/, with optional Hxcontrollers/ (HTMX partials), Templates/, Js/, and Permissions/ sub-directories.

app/Domain/Tickets/ ⇦ Example module (same for all 44) ├── Controllers/ ⇦ HTTP controllers (web routes) ├── Hxcontrollers/ ⇦ HTMX partial controllers ├── Services/ ⇦ Business logic layer ├── Repositories/ ⇦ Data access (DB queries) ├── Models/ ⇦ Eloquent / value objects ├── Templates/ ⇦ Blade/PHP view templates ├── Js/ ⇦ Module-specific JS ├── Permissions/ ⇦ RBAC permission definitions ├── Events/ ⇦ Domain events └── Support/ ⇦ DTOs, helpers, enums

All 44 Domain Modules

ModuleDescriptionKey Features
TicketsCore task & ticket managementKanban Gantt Sprints
ProjectsProject lifecycle managementCRUD Archive
UsersUser profiles & rolesRBAC Avatars
AuthAuthentication flowsLogin 2FA LDAP
DashboardConfigurable dashboardsWidgets GridStack
TimesheetsTime tracking & loggingReports CSV
WikiKnowledge base & docsTipTap Markdown
CalendarEvent & schedule managementFullCalendar iCal
NotificationsIn-app & email notificationsQueue Real-time
ReportsAnalytics & reportingChart.js PDF
Canvas / GoalcanvasStrategy & goal canvasesVisual Planning
FilesFile upload & media managementAWS S3 Uppy
Comments & ReactionsThreaded comments & emoji reactionsHTMX
Oidc / TwoFA / LdapSSO & securitySAML2 TOTP
ApiREST API surfaceSanctum MCP
PluginsPlugin management UIMarketplace
Queue / CronBackground job processingAsync Scheduled
Ideas / GamecenterIdea board & gamificationEngagement
SprintsAgile sprint managementScrum Velocity
AuditActivity & change audit logCompliance
SettingSystem & user settingsConfig
TagsTagging & classificationCross-domain
ClientsClient CRM recordsB2B
BlueprintsProject & ticket templatesReusability
🛡

Middleware Stack app/Core/Middleware/

14 middleware classes protecting every request
MiddlewareResponsibility
AuthCheck.phpVerifies user is authenticated; redirects to login if not.
AuthenticateSession.phpValidates session integrity and prevents session fixation attacks.
InitialHeaders.phpSets security headers (CSP, X-Frame-Options, HSTS).
Installed.phpChecks that Leantime has been installed; redirects to setup wizard if not.
Updated.phpChecks for pending DB migrations and forces the update flow.
LoadPlugins.phpBoots enabled plugins into the service container.
Localization.phpSets locale from user profile / browser headers.
StartSession.phpCustom session driver with Redis support.
RequestRateLimiter.phpToken-bucket rate limiting for API & login endpoints.
SetCacheHeaders.phpAdds appropriate Cache-Control headers to responses.
TrustProxies.phpTrusts reverse proxy headers (X-Forwarded-For).
VerifyCsrfToken.phpCSRF verification (excludes API routes).
TrimStrings.phpTrims whitespace from all incoming string inputs.
RateLimiter.phpGeneral Laravel rate limiter binding.
⚡

Events System app/Core/Events/

Custom event bus for cross-domain communication & plugin hooks

Leantime uses a custom EventDispatcher on top of Laravel's event system. The DispatchesEvents trait is mixed into any class that needs to fire events. Listeners are auto-discovered at boot time — earlier than Laravel's default discovery.

app/Core/Events/EventDispatcher.php — firing & filtering events
// Dispatch a filter event (returns modified value)
$filteredValue = self::applyFilter('leantime.core.tickets.afterSave', $ticket);

// Dispatch an action event (fire and forget)
self::dispatchEvent('leantime.domain.users.afterCreate', [
    'user' => $newUser
]);

// Register a listener (typically in a ServiceProvider)
self::addEventListener(
    'leantime.core.afterBootingServiceProviders',
    function() { /* custom setup */ }
);
ℹ️

Plugin Integration: Plugins tap into the event bus to extend or override any domain behavior without modifying core files — this is the primary extension point for the plugin marketplace.

🔌

API & Authentication

REST API, Laravel Sanctum, OAuth/OIDC & social login providers
🔑

Laravel Sanctum

Token-based API authentication. Every API key is stored as a PersonalAccessToken. Rate limiting is enforced per token via RequestRateLimiter middleware.

Bearer TokenSPA Cookie
🌐

Social Login / OIDC

Laravel Socialite supports 13 providers: Google, GitHub, GitLab, Microsoft, Azure, Okta, Keycloak, Auth0, Gitea, Authentik, PropelAuth, EduID, and generic SAML2.

OAuth2SAML2OIDC
🤖

MCP API

Model Context Protocol API powered by laravel/mcp, allowing AI agents to interact with Leantime's data programmatically via a standardized protocol.

AI AgentsMCP
🔐

Two-Factor Auth

TOTP-based 2FA via robthree/twofactorauth with QR code generation through endroid/qr-code. Enforced per-user or globally by admins.

TOTPQR Code
🎨 FRONTEND SOURCE CODE

JavaScript / CSS Frontend

jQuery + Vanilla JS core, HTMX for partial updates, TipTap rich editor, LESS + Tailwind CSS for styling, compiled by Laravel Mix (Webpack 5).

📜

JavaScript Modules public/assets/js/

Core app JS, HTMX integration, design tokens, and domain-specific scripts
📱

app.js

Main application entry point. Initialises jQuery, HTMX event hooks, global error handlers, accessibility helpers, and bootstraps the SPA-like navigation model.

Entry PointjQuery
⚡

htmx.js & htmx-extensions.js

HTMX 1.9 loaded separately (compiled independently so it can be updated without a full rebuild). Extensions add custom swap strategies and loading indicators.

HTMXPartial Updates
🎨

designtokens.js

19 KB of design system tokens exposed to JavaScript — colors, spacing, typography, breakpoints. Keeps CSS variables & JS in sync for chart and canvas rendering.

Design TokensCSS Variables
✏️

core/tiptap/

Custom TipTap 2 rich text editor setup with 20+ extensions: tables, task lists, mentions, code blocks (Lowlight), images, formatting toolbar, and floating menus.

TipTap 2ProseMirror
📅

core/datePickers.js

Unified date picker abstraction wrapping jQuery UI datepicker with Luxon for timezone-aware parsing and formatting across all form inputs.

LuxonjQuery UI
♿

core/accessibility.js

12 KB of accessibility helpers: keyboard navigation, focus trapping in modals, skip-link management, ARIA attribute updates, and high-contrast mode detection.

WCAGA11y
🛷

core/modals.js

Global modal system using jQuery nyroModal with HTMX integration. Supports full-page modal loads, form submission inside modals, and focus management.

nyroModalHTMX
🕘

core/dateHelper.js

10 KB date utility library. Provides relative date formatting, business-day calculations, ISO 8601 parsing, and multi-timezone display helpers using Luxon & Moment.

LuxonMoment.js

📦 Compiled JS Bundles

Bundle FileContents
compiled-frameworks.min.jsjQuery 3.7.1 + Bootstrap JS
compiled-framework-plugins.min.jsjQuery UI, Chosen, Growl, TagsInput, touch-punch...
compiled-global-component.min.jsLuxon, Moment, Popper, Tippy, Shepherd, SlimSelect, Croppie, Packery, Mermaid, Marked...
compiled-app.min.jsapp.js + all core/ modules + all Domain/**/*.js (auto-discovered)
compiled-htmx.min.jsHTMX 1.9
compiled-tiptap-editor.min.jsTipTap 2 + all extensions (Webpack bundled with tree-shaking)
compiled-tiptap-toolbar.min.jsTipTap toolbar UI component
compiled-calendar-component.min.jsFullCalendar 6 + iCal + Google Calendar + Luxon adapter
compiled-table-component.min.jsDataTables + RowGroup + RowReorder + Buttons
compiled-gantt-component.min.jsFrappe Gantt + Snap.svg
compiled-chart-component.min.jsChart.js 3 + Luxon adapter
compiled-footer.min.jsPrism.js syntax highlighter
html2canvas.min.js + jspdf.umd.min.jsLazy-loaded for PDF/PNG export (unversioned, stable URL)
🖌

CSS System public/assets/css/ & less/

LESS entry points + 36 CSS component files + Tailwind utility layer
💡

Layered approach: LESS compiles the core design system (variables, typography, layout), component CSS files provide scoped component styles, and Tailwind CSS adds utility classes. All three are merged into main.{version}.min.css.

🕀

structure.css

Core layout grid, sidebar, main content area, page wrapper. The structural backbone of every Leantime page.

🧭

nav.css

27 KB of navigation styles — top bar, left sidebar, breadcrumbs, dropdowns, active states and responsive collapse.

📋

kanban.css

37 KB Kanban board styles. Columns, card drag handles, swimlanes, WIP limits indicator, and responsive stacking.

📊

report-deck.css

83 KB — the largest component. Full slide-deck and reporting view, including chart containers, data tables, and print-ready layout.

📝

forms.css

49 KB form styles. Input groups, validation states, custom checkboxes/radios, date pickers, and file upload dropzones.

📱

mobile.css

57 KB responsive overrides. Transforms every view for touch & small screens, including swipeable sidebars and collapsible sections.

✏️

tiptap-editor.css

95 KB — the largest single CSS file. Full TipTap rich editor chrome: toolbar, bubble menu, table editing UI, code block themes, and placeholder animations.

♿

accessibility.css

Focus rings, skip links, high-contrast colour overrides, and screen-reader-only utility classes. WCAG 2.1 AA compliant.

All CSS Component Files

FilePurposeSize
style.default.cssDefault theme — colours, shadows, brand tokens54 KB
tiptap-editor.cssRich text editor chrome96 KB
report-deck.cssReport & slide deck views83 KB
resource-allocation.cssResource planning board53 KB
mobile.cssResponsive / mobile overrides58 KB
forms.cssAll form elements & validation50 KB
kanban.cssKanban board & cards38 KB
wiki.cssWiki / knowledge base views25 KB
nav.cssNavigation & sidebar27 KB
reverse-wizard.cssOnboarding wizard UI20 KB
progressbars.cssProgress bars & gauges19 KB
tables.cssData tables & grids18 KB
dropdowns.cssDropdown menus16 KB
tab-group.cssTab navigation groups10 KB
calendar.cssCalendar view overrides11 KB
stat-tiles.cssDashboard stat tile cards9 KB
sortableList.cssDraggable sortable lists5 KB
period-picker.cssDate period picker widget6 KB
print.cssPrint media stylesheet3 KB
accessibility.cssFocus, ARIA, high-contrast2 KB
🔨

Build System

Laravel Mix (Webpack 5) with LESS, Tailwind, ESLint & versioned output

The build system is defined in webpack.mix.js. It reads the version from package.json and stamps every compiled file with a version suffix to bust browser caches on deployment.

webpack.mix.js — Build Pipeline Summary
const version = pjson.version; // "3.10.1"

mix
  // 1. Framework JS (jQuery + Bootstrap)
  .combine(['jquery.js', 'bootstrap.min.js'],
           `compiled-frameworks.${version}.min.js`)

  // 2. Application JS (all Domain JS auto-discovered via glob)
  .combine(['app.js', 'snippets.js',
            '...glob.sync("app/Domain/**/*.js")'],
           `compiled-app.${version}.min.js`)

  // 3. LESS -> CSS
  .less('./less/main.less', `main.${version}.min.css`)

  // 4. Tailwind utility layer
  .tailwind()

  // 5. TipTap (full Webpack bundle with tree-shaking)
  .js('./tiptap/index.js', `compiled-tiptap-editor.${version}.min.js`)

  // 6. ESLint (auto-fix on build)
  .eslint({ fix: true });
⚠️

Domain JS Discovery: All .js files under app/Domain/**/ are automatically picked up via glob.sync() and merged into compiled-app.min.js. Adding a new JS file in any domain module folder is enough to include it in the bundle.

📦

UI Libraries

Key frontend dependencies and their roles
LibraryVersionPurpose
jQuery3.7.1DOM manipulation, AJAX, event handling — primary JS runtime
HTMX^1.9.12Server-driven partial page updates without full-page reloads
TipTap 2^2.11.5ProseMirror-based rich text editor with 20+ extensions
FullCalendar^6.1.20Calendar & scheduling view with iCal & Google Calendar feeds
Chart.js^3.6.0Line, bar, doughnut charts on dashboards & reports
DataTables^1.13.11Server-side sortable/filterable tables
GridStack^12.1.1Drag-and-drop dashboard widget grid
Frappe Ganttlibs/Gantt chart view for project timelines
Shepherd.js^11.2.0User onboarding tour overlays
Uppy^3.25.3File upload UI with AWS S3 direct upload support
Mermaid^11.12.3Diagram-as-code rendering in wiki/comments
Lottie Player^2.0.4JSON-based animations (loading, empty states)
Croppie^2.6.5In-browser image cropper for avatar uploads
Tippy.js^6.3.7Tooltip & popover positioning
Luxon + Moment^3.4.4 / ^2.29.4Date parsing, formatting, timezone support
jsTree^3.3.16Hierarchical tree widget for project structure
Isotope + Packery^3.0.6 / ^2.1.2Masonry & filterable grid layouts (Idea board)
Leader Line^1.0.7SVG connector lines between DOM elements (canvas diagrams)
KaTeX^0.17.0LaTeX math rendering in wiki & comments
Font Awesome 6^6.5.2Icon set used throughout the UI
📦

PHP Dependencies

Key Composer packages powering the backend
PackagePurpose
laravel/framework ^v11.44Application framework — IoC, ORM, routing, queues, mail
laravel/sanctum ^4.0API token authentication & SPA cookie auth
laravel/socialite ^5.16OAuth2 social login (13 providers)
laravel/mcp ^0.1.1Model Context Protocol API for AI agent integration
guzzlehttp/guzzle ^7.9HTTP client for external API calls
phpmailer/phpmailer ^6.6Transactional email delivery
aws/aws-sdk-php ^3.344AWS S3 file storage & other AWS services
sabre/dav ^4.7CalDAV/WebDAV server for calendar sync
prism-php/prism ^0.57AI completions via OpenAI, Anthropic, etc.
inspector-apm/neuron-ai 1.12.8NeuronAI agent framework for AI features
sentry/sentry-laravel ^4.13Error tracking & performance monitoring
stripe/stripe-php ^v17.3Payment processing
robthree/twofactorauth ^1.8TOTP 2FA generation & verification
league/flysystem-aws-s3-v3S3 filesystem adapter for file uploads
symfony/cache ^7.2PSR-6/16 cache abstraction
ramsey/uuid ^4.3UUID generation throughout the domain layer
spatie/icalendar-generator ^2.6Generate iCal feeds for events & tasks
hkulekci/qdrant ^0.5.8Qdrant vector database client for AI semantic search
phpseclib/phpseclib ~3.0Cryptography primitives for SAML2 & OIDC
⚙️

Configuration

Key environment variables & runtime configuration
config/.env — Key Environment Variables
# Application
APP_NAME=Leantime
APP_ENV=production            # production | local | testing
APP_DEBUG=false
APP_URL=https://your-domain.com

# Database
DB_CONNECTION=mysql          # mysql | pgsql
DB_HOST=127.0.0.1
DB_PORT=3306
DB_DATABASE=leantime
DB_USERNAME=leantime
DB_PASSWORD=secret

# Cache / Sessions
CACHE_DRIVER=redis           # redis | file | array
SESSION_DRIVER=redis
REDIS_HOST=127.0.0.1

# File Storage
FILESYSTEM_DISK=local        # local | s3
AWS_BUCKET=my-leantime-bucket

# Mail
MAIL_MAILER=smtp
MAIL_HOST=smtp.example.com
MAIL_FROM_ADDRESS=noreply@leantime.io

# AI / Sentry / Stripe (optional)
OPENAI_API_KEY=sk-...
SENTRY_LARAVEL_DSN=https://...
STRIPE_SECRET=sk_live_...
💡

Node Requirements: Node ≥18 and npm are required to build frontend assets. Run npm install then npx mix (dev) or npx mix --production (prod) to compile all JS & CSS bundles.

ℹ️

PHP Requirements: PHP ≥8.2 with extensions: mysqli, pdo_mysql, ldap, zip, mbstring, pcntl, posix, bcmath, simplexml, openssl, gd, fileinfo, dom. Install with composer install.