Production hardening: error pages, rate limiting, metadata

- Custom not-found (404) + error / global-error boundaries, styled with
  the public design system; raw errors logged, never shown to users.
- In-process rate limiter (src/lib/rate-limit.ts) wired into the abuse-
  prone flows: login (10/5min/IP), register (5/10min/IP), password-reset
  request (3/15min/IP), keyed by the proxy-forwarded client IP.
- SEO/metadata: root generateMetadata sets a `%s · {hotel}` title
  template from the live hotel_name; dynamic generateMetadata on
  news/[slug] (article title + excerpt) and u/[username] (name + motto);
  static titles on 12 primary public pages.
- env.ts: added the vars introduced since (PASSWORD_HASH, OPENAI_API_KEY,
  DISCORD_WEBHOOK_URL, ALERT_EMAIL, PAYPAL_*) so env stays authoritative.

Verified on the prod server: /missing → 404 card, news title renders
"News · Habbo". tsc 0, vitest 49/49, next build 0.
This commit is contained in:
Simo committed 2026-06-28 20:12:12 +02:00
1 parent e9ea19795a
commit 6f15e0c8a3
23 files changed
+276 -5

No files matched your search

+2
View File
@@ -3,6 +3,8 @@ import { prisma } from "@/lib/prisma";
export const dynamic = "force-dynamic";
export const metadata = { title: "Badges" };
// Canonical Habbo badge image CDN. A badge_key (e.g. "ADM") maps to a .gif here.
const BADGE_IMG_BASE = "https://images.habbo.com/c_images/album1584";
+2
View File
@@ -3,6 +3,8 @@ import { ContentCard } from "@/components/public/ui";
export const dynamic = "force-dynamic";
export const metadata = { title: "Community" };
const LINKS = [
{
href: "/rankings",
+54
View File
@@ -0,0 +1,54 @@
"use client";
import { useEffect } from "react";
/**
* Route-segment error boundary. Renders inside the root layout (so the shell
* stays), shows a friendly card, and offers a reset. The raw error is logged to
* the console, never shown to the user.
*/
export default function Error({
error,
reset,
}: {
error: Error & { digest?: string };
reset: () => void;
}) {
useEffect(() => {
console.error(error);
}, [error]);
return (
<main style={{ display: "grid", gap: "1.5rem" }}>
<div className="content-card">
<div className="content-card-head">
<span className="content-card-icon" aria-hidden>
⚠️
</span>
<div className="content-card-head-text">
<p className="content-card-title">Something went wrong</p>
<p className="content-card-subtitle">An unexpected error occurred</p>
</div>
</div>
<div className="content-card-body">
<p className="muted" style={{ marginTop: 0 }}>
Try again — if the problem persists, please contact a member of staff.
</p>
<div style={{ display: "flex", gap: "0.6rem", flexWrap: "wrap" }}>
<button type="button" className="btn btn-primary" onClick={() => reset()}>
Try again
</button>
<a className="btn btn-outline" href="/">
Back home
</a>
</div>
{error.digest ? (
<p className="muted" style={{ marginTop: "0.75rem", fontSize: "0.75rem" }}>
Reference: {error.digest}
</p>
) : null}
</div>
</div>
</main>
);
}
+2
View File
@@ -8,6 +8,8 @@ import { siteSettings } from "@/lib/services/site-settings";
export const dynamic = "force-dynamic";
export const metadata = { title: "Friends" };
export default async function FriendsPage() {
const session = await auth();
if (!session?.user?.id) redirect("/login");
+60
View File
@@ -0,0 +1,60 @@
"use client";
import { useEffect } from "react";
/**
* Last-resort boundary for errors thrown in the root layout itself. It replaces
* the whole document, so it must render its own <html>/<body> and can't rely on
* the app shell or its CSS variables.
*/
export default function GlobalError({
error,
reset,
}: {
error: Error & { digest?: string };
reset: () => void;
}) {
useEffect(() => {
console.error(error);
}, [error]);
return (
<html lang="en">
<body
style={{
margin: 0,
minHeight: "100vh",
display: "grid",
placeItems: "center",
fontFamily: "Nunito, system-ui, sans-serif",
background: "#0f1117",
color: "#e5e7eb",
}}
>
<div style={{ textAlign: "center", padding: "2rem", maxWidth: 420 }}>
<div style={{ fontSize: "2.5rem" }}>⚠️</div>
<h1 style={{ margin: "0.5rem 0", fontSize: "1.4rem" }}>Something went wrong</h1>
<p style={{ color: "#9ca3af", marginTop: 0 }}>
The hotel ran into an unexpected error. Please try again.
</p>
<button
type="button"
onClick={() => reset()}
style={{
marginTop: "1rem",
padding: "0.55rem 1.4rem",
border: "none",
borderRadius: 10,
fontWeight: 700,
cursor: "pointer",
background: "#f59e0b",
color: "#1a1a2e",
}}
>
Try again
</button>
</div>
</body>
</html>
);
}
+2
View File
@@ -5,6 +5,8 @@ import { prisma } from "@/lib/prisma";
export const dynamic = "force-dynamic";
export const metadata = { title: "Guilds" };
type GuildCard = {
id: number;
name: string;
+8 -4
View File
@@ -9,6 +9,7 @@ import { SiteHeader } from "@/components/site-header";
import { ThemeVars } from "@/components/theme-vars";
import { TopHeader } from "@/components/top-header";
import { enforceSiteAccess } from "@/lib/access-guard";
import { siteSettings } from "@/lib/services/site-settings";
import "./globals.css";
const nunito = Nunito({
@@ -18,10 +19,13 @@ const nunito = Nunito({
variable: "--font-nunito",
});
export const metadata: Metadata = {
title: "AtomCMS",
description: "AtomCMS — retro hotel CMS (Next.js conversion)",
};
export async function generateMetadata(): Promise<Metadata> {
const hotel = (await siteSettings.get("hotel_name", "Atom")) ?? "Atom";
return {
title: { default: hotel, template: `%s · ${hotel}` },
description: `${hotel} — a Habbo retro hotel. Hang out, collect furni and meet friends.`,
};
}
export default async function RootLayout({ children }: { children: ReactNode }) {
await enforceSiteAccess();
+2
View File
@@ -6,6 +6,8 @@ import { siteSettings } from "@/lib/services/site-settings";
export const dynamic = "force-dynamic";
export const metadata = { title: "Leaderboard" };
// AtomCMS-faithful currency type ids (see prisma/schema.prisma UsersCurrency):
// Credits = -1 (lives on users.credits), Duckets = 0, Diamonds = 5.
const TABS = [
+2
View File
@@ -3,6 +3,8 @@ import { prisma } from "@/lib/prisma";
export const dynamic = "force-dynamic";
export const metadata = { title: "Marketplace" };
// state == 1 → an active, unsold offer in the Arcturus marketplace.
const STATE_ACTIVE = 1;
+15
View File
@@ -1,13 +1,28 @@
import type { Metadata } from "next";
import Link from "next/link";
import { notFound } from "next/navigation";
import { ContentCard, EmptyState } from "@/components/public/ui";
import { auth } from "@/lib/auth";
import { excerpt } from "@/lib/format";
import { prisma } from "@/lib/prisma";
import { postComment } from "@/actions/article-comments";
import { toggleReaction } from "@/actions/article-reactions";
export const dynamic = "force-dynamic";
export async function generateMetadata({
params,
}: {
params: Promise<{ slug: string }>;
}): Promise<Metadata> {
const { slug } = await params;
const article = await prisma.websiteArticles
.findUnique({ where: { slug }, select: { title: true, shortStory: true } })
.catch(() => null);
if (!article) return { title: "Article" };
return { title: article.title, description: excerpt(article.shortStory, 160) };
}
// The reaction set offered by the voting UI. Must stay in sync with
// ALLOWED_REACTIONS in src/actions/article-reactions.ts.
const REACTIONS: { key: string; label: string }[] = [
+2
View File
@@ -5,6 +5,8 @@ import { prisma } from "@/lib/prisma";
export const dynamic = "force-dynamic";
export const metadata = { title: "News" };
function formatDate(d: Date | null): string {
return d ? d.toISOString().slice(0, 10) : "";
}
+22
View File
@@ -0,0 +1,22 @@
import Link from "next/link";
import { ContentCard } from "@/components/public/ui";
export default function NotFound() {
return (
<main style={{ display: "grid", gap: "1.5rem" }}>
<ContentCard icon="🧭" title="Page not found" subtitle="Error 404">
<p className="muted" style={{ marginTop: 0 }}>
The page you’re looking for doesn’t exist or has moved.
</p>
<div style={{ display: "flex", gap: "0.6rem", flexWrap: "wrap" }}>
<Link className="btn btn-primary" href="/">
Back home
</Link>
<Link className="btn btn-outline" href="/news">
Latest news
</Link>
</div>
</ContentCard>
</main>
);
}
+2
View File
@@ -3,6 +3,8 @@ import { prisma } from "@/lib/prisma";
export const dynamic = "force-dynamic";
export const metadata = { title: "Photos" };
type Photo = {
id: number;
userId: number;
+2
View File
@@ -6,6 +6,8 @@ import { siteSettings } from "@/lib/services/site-settings";
export const dynamic = "force-dynamic";
export const metadata = { title: "Rankings" };
type TopUser = {
username: string;
look: string;
+2
View File
@@ -5,6 +5,8 @@ import { siteSettings } from "@/lib/services/site-settings";
export const dynamic = "force-dynamic";
export const metadata = { title: "Rare values" };
type CategoryRow = {
id: bigint;
name: string;
+2
View File
@@ -5,6 +5,8 @@ import { prisma } from "@/lib/prisma";
export const dynamic = "force-dynamic";
export const metadata = { title: "Shop" };
// Faithful to AtomCMS WebsiteShopArticle::price(): costs are stored in cents,
// the displayed price is costs/100 with a floor of 1.
function priceLabel(costs: number): string {
+2
View File
@@ -5,6 +5,8 @@ import { siteSettings } from "@/lib/services/site-settings";
export const dynamic = "force-dynamic";
export const metadata = { title: "Staff" };
type StaffMember = {
username: string;
look: string;
+14
View File
@@ -1,3 +1,4 @@
import type { Metadata } from "next";
import { notFound } from "next/navigation";
import { ContentCard, EmptyState, OnlineBadge, StatBlock } from "@/components/public/ui";
import { auth } from "@/lib/auth";
@@ -8,6 +9,19 @@ import { postGuestbook } from "@/actions/guestbook";
export const dynamic = "force-dynamic";
export async function generateMetadata({
params,
}: {
params: Promise<{ username: string }>;
}): Promise<Metadata> {
const { username } = await params;
const user = await prisma.user
.findUnique({ where: { username }, select: { username: true, motto: true } })
.catch(() => null);
if (!user) return { title: "Profile" };
return { title: user.username, description: user.motto || `${user.username}'s profile` };
}
// Canonical Habbo badge image CDN. Badge codes (e.g. "ADM") map to a .gif here.
const BADGE_IMG_BASE = "https://images.habbo.com/c_images/album1584";