Security hardening, code quality, and ESLint setup

- Remove production DB dump (db_backup_*.sql) and update.log from git tracking
- Add DB backups to .gitignore
- Replace all console.log/console.error with structured logger module
- Translate Dutch error messages to English (link-discord.ts)
- Remove dead code blocks (register-form.tsx false && pattern)
- Add ESLint flat config with TypeScript, React, Next.js, jsx-a11y, and security plugins
- Add Prettier config
- Add eslint-plugin-security for security-aware linting
- Fix all 119+ ESLint warnings across the codebase:
  - Resolve security/detect-object-injection with safe access patterns
  - Resolve security/detect-non-literal-fs-filename with path traversal validation
  - Replace <img> with next/image <Image> component
  - Remove unused variables and imports
  - Replace non-null assertions with proper type guards
  - Replace <a> with <Link> for internal navigation
  - Use next/script Script component for external scripts
- Fix setState-in-useEffect anti-patterns (navbar-color-picker, logo-generator, theme-switcher)
- Add lint and format scripts to package.json

All checks: typecheck ✓, tests 58/58 ✓, lint 0 errors 0 warnings ✓
This commit is contained in:
openhands committed 2026-07-10 22:48:22 +02:00
1 parent 7f8c9afc0f
commit 942bc6fc8d
93 files changed
+2676 -379115

No files matched your search

+5 -4
View File
@@ -1,6 +1,7 @@
import { prisma } from "@/lib/prisma";
import { sendMail } from "@/lib/services/email";
import { env } from "@/env";
import { logger } from "@/lib/logger";
// === Alert service (AtomCMS → Next.js) ===========================================
//
@@ -111,12 +112,12 @@ async function postDiscord(input: SendAlertInput): Promise<boolean> {
body: JSON.stringify(body),
});
if (!res.ok) {
console.error("[alert] Discord webhook returned", res.status);
logger.error("Discord webhook returned non-OK status", { module: "alert", status: res.status });
return false;
}
return true;
} catch (e) {
console.error("[alert] Discord webhook failed:", (e as Error).message);
logger.error("Discord webhook failed", { module: "alert", error: (e as Error).message });
return false;
}
}
@@ -152,7 +153,7 @@ async function emailStaff(input: SendAlertInput): Promise<boolean> {
try {
return await sendMail(to, subject, html);
} catch (e) {
console.error("[alert] staff email failed:", (e as Error).message);
logger.error("Staff email failed", { module: "alert", error: (e as Error).message });
return false;
}
}
@@ -189,7 +190,7 @@ export async function sendAlert(input: SendAlertInput): Promise<SendAlertResult>
} catch (e) {
// DB unreachable / schema drift: keep the alert best-effort. We already
// notified Discord/email above, so the alert isn't lost.
console.error("[alert] failed to persist alert_logs row:", (e as Error).message);
logger.error("Failed to persist alert_logs row", { module: "alert", error: (e as Error).message });
}
return { logged, sentViaDiscord, sentViaEmail };