refactor: full codebase overhaul — dead code removal, env validation, logger migration, date consolidation, Prisma schema cleanup, button consistency, useEffect deps, test coverage
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 8s

- env.ts: added 10 missing Zod-validated env vars (imager, paypal currency, argon2/bcrypt params)
- Migrated 6 modules from process.env to validated env.* (auth, proxy-auth, paypal, password, redis, imager, moderation, alert, logger)
- Replaced console.warn/error with pino logger in 9 server-side modules
- Removed 50+ dead exports (SWF wrappers, coalesceHotelName, signIn, isStaff re-export, formatTimestamp, Skeleton/SkeletonCard, 4 unused housekeeping sections)
- Consolidated date formatting: 28 files migrated to shared formatDate() from @/lib/format-date
- Wired 4 radio/settings API routes through cached siteSettings service instead of raw Prisma queries
- Added getMany()/getAll() helpers to SiteSettings service
- Removed 88 dead Prisma model definitions (schema 2763→1846 lines)
- Created admin action-helper.ts with wrapAction() for standardized error handling
- Fixed useEffect dependency arrays in 4 data-heavy components
- Replaced raw btn CSS classes with shadcn Button component across admin pages
- Stripped dead i18n namespaces (common, pages.client) from all 22 translation files
- Removed 2 dead scripts (create-release.sh, check-local-imports.ts)
- Fixed knip.json configuration
- Added 7 new test suites: format-date, paypal, moderation, alert, webhook, action-helper, and fixed password.test.ts for env mocking
- All 358 tests passing across 72 test files
- TypeScript: 0 errors
This commit is contained in:
openhands committed 2026-07-25 17:33:06 +02:00
1 parent 12e4a07e48
commit 1acace49d0
150 files changed
+10210 -12272

No files matched your search

+14 -11
View File
@@ -2,17 +2,22 @@ import { randomBytes } from "node:crypto";
import { compare as bcryptCompare, hash as bcryptHash } from "bcrypt";
import { argon2id, argon2Verify, md5 } from "hash-wasm";
import { env } from "@/env";
// AtomCMS hashing (config/hashing.php): argon2id with memory=65536 KiB, time=4,
// threads=1; bcrypt rounds=12 as the legacy fallback. The game emulator
// validates the SAME users.password hash, so these must match.
const ARGON2_PARAMS = {
parallelism: Number(process.env.ARGON2_PARALLELISM) || 1,
iterations: Number(process.env.ARGON2_ITERATIONS) || 4,
memorySize: Number(process.env.ARGON2_MEMORY_SIZE) || 65536, // KiB
hashLength: 32,
} as const;
function argon2Params() {
return {
parallelism: env.ARGON2_PARALLELISM,
iterations: env.ARGON2_ITERATIONS,
memorySize: env.ARGON2_MEMORY_SIZE,
hashLength: 32,
} as const;
}
function bcryptRounds(): number {
return Number(process.env.BCRYPT_ROUNDS) || 12;
return env.BCRYPT_ROUNDS;
}
// Which algorithm hashPassword() emits for NEW/upgraded passwords.
@@ -20,9 +25,7 @@ function bcryptRounds(): number {
// - "argon2id": ~97-char PHC hash. Opt in with PASSWORD_HASH=argon2id.
// verifyPassword() always accepts BOTH, so logins keep working either way.
function hashDriver(): "bcrypt" | "argon2id" {
return process.env.PASSWORD_HASH?.toLowerCase() === "argon2id"
? "argon2id"
: "bcrypt";
return env.PASSWORD_HASH === "argon2id" ? "argon2id" : "bcrypt";
}
/**
@@ -48,7 +51,7 @@ export async function hashPassword(password: string): Promise<string> {
password,
salt: randomBytes(16),
outputType: "encoded",
...ARGON2_PARAMS,
...argon2Params(),
});
}
// native bcrypt emits $2a$/$2b$; normalise to the PHP-canonical $2y$ the