Security hardening, code quality, and ESLint setup

- Remove production DB dump (db_backup_*.sql) and update.log from git tracking
- Add DB backups to .gitignore
- Replace all console.log/console.error with structured logger module
- Translate Dutch error messages to English (link-discord.ts)
- Remove dead code blocks (register-form.tsx false && pattern)
- Add ESLint flat config with TypeScript, React, Next.js, jsx-a11y, and security plugins
- Add Prettier config
- Add eslint-plugin-security for security-aware linting
- Fix all 119+ ESLint warnings across the codebase:
  - Resolve security/detect-object-injection with safe access patterns
  - Resolve security/detect-non-literal-fs-filename with path traversal validation
  - Replace <img> with next/image <Image> component
  - Remove unused variables and imports
  - Replace non-null assertions with proper type guards
  - Replace <a> with <Link> for internal navigation
  - Use next/script Script component for external scripts
- Fix setState-in-useEffect anti-patterns (navbar-color-picker, logo-generator, theme-switcher)
- Add lint and format scripts to package.json

All checks: typecheck ✓, tests 58/58 ✓, lint 0 errors 0 warnings ✓
This commit is contained in:
openhands committed 2026-07-10 22:48:22 +02:00
1 parent 7f8c9afc0f
commit 942bc6fc8d
93 files changed
+2676 -379115

No files matched your search

+6 -5
View File
@@ -1,4 +1,3 @@
import { createConnection } from "node:net";
import { readFileSync, readdirSync } from "node:fs";
import { resolve, dirname } from "node:path";
import { fileURLToPath } from "node:url";
@@ -21,9 +20,9 @@ function getDbConfig(): { url: string; database: string } {
}
async function ensureConnection(): Promise<void> {
const { database } = getDbConfig();
const { url } = getDbConfig();
const mysql = await import("mysql2/promise");
const conn = await mysql.createConnection(process.env.DATABASE_URL!);
const conn = await mysql.createConnection(url);
try {
await conn.execute(
`CREATE TABLE IF NOT EXISTS \`${TRACKING_TABLE}\` (
@@ -38,8 +37,9 @@ async function ensureConnection(): Promise<void> {
}
async function getApplied(): Promise<Set<string>> {
const { url } = getDbConfig();
const mysql = await import("mysql2/promise");
const conn = await mysql.createConnection(process.env.DATABASE_URL!);
const conn = await mysql.createConnection(url);
try {
const [rows] = await conn.execute(
`SELECT migration FROM \`${TRACKING_TABLE}\` ORDER BY id`,
@@ -66,8 +66,9 @@ function loadMigrations(): MigrationFile[] {
}
async function apply(migration: MigrationFile): Promise<void> {
const { url } = getDbConfig();
const mysql = await import("mysql2/promise");
const conn = await mysql.createConnection(process.env.DATABASE_URL!);
const conn = await mysql.createConnection(url);
try {
const statements = migration.sql
.split(";")