Security hardening, code quality, and ESLint setup

- Remove production DB dump (db_backup_*.sql) and update.log from git tracking
- Add DB backups to .gitignore
- Replace all console.log/console.error with structured logger module
- Translate Dutch error messages to English (link-discord.ts)
- Remove dead code blocks (register-form.tsx false && pattern)
- Add ESLint flat config with TypeScript, React, Next.js, jsx-a11y, and security plugins
- Add Prettier config
- Add eslint-plugin-security for security-aware linting
- Fix all 119+ ESLint warnings across the codebase:
  - Resolve security/detect-object-injection with safe access patterns
  - Resolve security/detect-non-literal-fs-filename with path traversal validation
  - Replace <img> with next/image <Image> component
  - Remove unused variables and imports
  - Replace non-null assertions with proper type guards
  - Replace <a> with <Link> for internal navigation
  - Use next/script Script component for external scripts
- Fix setState-in-useEffect anti-patterns (navbar-color-picker, logo-generator, theme-switcher)
- Add lint and format scripts to package.json

All checks: typecheck ✓, tests 58/58 ✓, lint 0 errors 0 warnings ✓
This commit is contained in:
openhands committed 2026-07-10 22:48:22 +02:00
1 parent 7f8c9afc0f
commit 942bc6fc8d
93 files changed
+2676 -379115

No files matched your search

+4 -3
View File
@@ -9,6 +9,7 @@ import {
import { rcon } from "@/lib/services/rcon";
import { sendCurrency } from "@/lib/services/send-currency";
import { env } from "@/env";
import { logger } from "@/lib/logger";
export const dynamic = "force-dynamic";
@@ -78,7 +79,7 @@ export async function POST(req: Request): Promise<Response> {
try {
result = await captureOrder(orderId);
} catch (e) {
console.error("[paypal/capture]", (e as Error).message);
logger.error("PayPal capture failed", { module: "paypal/capture", error: (e as Error).message });
return NextResponse.json(
{ error: "Could not capture the PayPal payment. If you were charged, contact staff." },
{ status: 502 },
@@ -127,7 +128,7 @@ export async function POST(req: Request): Promise<Response> {
},
});
} catch (e) {
console.error("[paypal/capture] record failed", (e as Error).message);
logger.error("PayPal capture record failed", { module: "paypal/capture", error: (e as Error).message });
return NextResponse.json(
{ error: "Payment captured but could not be recorded. Contact staff with your order id." },
{ status: 500 },
@@ -138,7 +139,7 @@ export async function POST(req: Request): Promise<Response> {
try {
await sendCurrency({ rcon, db: prisma }, userId, "credits", credits);
} catch (e) {
console.error("[paypal/capture] credit failed", (e as Error).message);
logger.error("PayPal capture credit failed", { module: "paypal/capture", error: (e as Error).message });
return NextResponse.json(
{
ok: false,
+2 -1
View File
@@ -7,6 +7,7 @@ import {
PAYPAL_CURRENCY,
} from "@/lib/services/paypal";
import { env } from "@/env";
import { logger } from "@/lib/logger";
export const dynamic = "force-dynamic";
@@ -75,7 +76,7 @@ export async function POST(req: Request): Promise<Response> {
credits,
});
} catch (e) {
console.error("[paypal/create]", (e as Error).message);
logger.error("PayPal create order failed", { module: "paypal/create", error: (e as Error).message });
return NextResponse.json(
{ error: "Could not start the PayPal checkout. Please try again." },
{ status: 502 },