Commit Graph
1599 Commits
Author SHA1 Message Date
openhands 7fe3220359 Inline SSO ticket generation in server component, prefetch client page from home, remove client API roundtrip 2026-07-09 18:41:04 +02:00
openhands cfb36e8007 Preconnect to Nitro client URL for faster client page load 2026-07-09 18:35:18 +02:00
openhands da505ae643 Optimize client page: combine fetch calls, extract ToolbarBtn component, reduce duplicated inline styles 2026-07-09 18:30:46 +02:00
openhands deac10e00a Add in-memory caching for online count, enable compression, and add staleTimes for router cache 2026-07-09 18:24:58 +02:00
openhands b058a3827b Fix theme consistency, i18n completeness, CSS variable naming, and hardcoded strings 2026-07-09 18:13:22 +02:00
openhands 0abd490f67 Improve update-Nitrov3.sh parallelism, UX, and compatibility
- Run renderer and client builds in parallel (background + wait) for
  faster updates
- Cache detected git branches in interactive menu (avoid re-running
  git branch -r on every redraw); re-cache after switching branches
- Add health check after emulator restart (poll until active or retries
  exhausted)
- Add service_active() helper with systemd/service/pgrep fallback for
  non-systemd systems; replace all systemctl is-active calls
- Add 30s read timeout (-t 30) on all interactive prompts to prevent
  hanging on non-terminal stdin
- Add set -E for ERR trap inheritance in subshells
2026-07-08 19:27:27 +02:00
openhands f9b0ec78d1 Improve update-Nitrov3.sh security, reliability, and portability
- Security: replace eval-based load_branches with nameref+readarray,
  remove export MYSQL_PWD (leaks to child processes), fix URL-decode
  via Python's urllib.parse, fix JSON injection in notify via json.dumps,
  add package.json guard before sudo rm -rf
- Portability: replace seq (external) with repeat() built-in, add
  mysql/mysqldump fallback alongside mariadb, add format_size() fallback
  when numfmt is unavailable, remove -maxdepth from list_sorted helper
- Robustness: add set -o pipefail, fix spinner zombie (remove disown),
  wrap git_update/detect_best_branch in subshells to prevent cd leaks,
  capture full mvn/yarn build output to log instead of tail, add -r to
  xargs basename, make ssl-verify-server-cert configurable via .env
- UX: add --dry-run/-n flag for preview without changes
2026-07-08 19:12:28 +02:00
openhands 04e1da7caf docs: rewrite README with comprehensive English setup instructions 2026-07-08 14:22:42 +02:00
openhands 5519a64583 fix: add missing nav-credit-icon, nav-ducket-icon and nav-diamond-icon CSS classes for topbar currency icons 2026-07-08 14:14:44 +02:00
openhands fc57fb06d1 chore: remove dead code, unused CSS, unused components, and clean up git tracking
- Remove storage/logs/ and prod.log from git tracking; add to .gitignore
- Remove unused AvatarCarousel and ArticleSlider components
- Remove unused SkeletonTable export from ui.tsx
- Remove unused ChevronDown import from admin layout
- Remove 13 unused CSS classes (icon-base, nav-*, navigation-icon*, .app.dark,
  text-body, transition-base, card-base, admin-info-grid, .coin.*)
- Remove duplicate translation keys (openMenu/closeMenu in en.json)
- Fix admin-bans to use Prisma-generated bans_type enum
- Create shared AdminPageHeader component and formatDate utility
- Add logger and generateRequestId for structured logging
- All 58 tests pass, typecheck clean, build succeeds
2026-07-08 13:27:01 +02:00
openhands c5db7f5156 fix: production hardening — migration script, security fixes, structured logging, API docs, component splitting
- Create apply-migrations.ts and jobs-worker.ts scripts (package.json references)
- Convert badge leaderboard from $queryRawUnsafe to $queryRaw with Prisma.sql templates
- Fix OAuth email binding: add oauth_require_link site setting, skip 2FA-protected accounts
- Add per-user 2FA rate limiting (5/30s) to prevent TOTP brute-force
- Add structured JSON logger with levels (debug/info/warn/error)
- Split 341-line HomePage into GuestView + UserView components
- Add OpenAPI v3.1 spec at /api/openapi.json
- Add LOG_LEVEL env var, regenerate Prisma client
- Add mysql2 dependency for migration scripts
- All 58 tests pass, typecheck clean
2026-07-08 13:06:02 +02:00
openhands 5c638cd6bc perf: add bans.user_id index, Redis cache layer, rate-limit improvements, radio contest/giveaway columns, and tests
- Add DB index on bans.user_id to speed up per-request ban lookups (migration 0008)
- Replace in-process rate limiter with Redis-backed implementation with in-memory fallback
- Add Redis caching layer for site settings with TTL invalidation (migration 0009)
- Add rate limiting to resetPassword to prevent token brute-force attacks
- Update all rateLimit callers to await the now-async function
- Flesh out RadioContests and RadioGiveaways models with title, description, prize, date, and winner columns
- Update radio contest/giveaway pages to display new fields
- Add tests for rate limiter (4 tests) and password-reset actions (3 tests)
- Add REDIS_URL environment variable (optional, falls back to in-memory)
2026-07-08 12:49:24 +02:00
openhands 43c0ba6614 Add Discord verification option for users without email 2026-07-07 20:37:42 +02:00
openhands eb01b14379 Add ultimate file-based email fallback so mailer always works without any configuration 2026-07-07 20:18:30 +02:00
openhands 065215b4dc Add local sendmail fallback so mailer works internally without external services 2026-07-07 20:15:29 +02:00
openhands bf4075233d Add Resend mailer as primary with SMTP fallback for reliable email delivery 2026-07-07 20:12:56 +02:00
openhands f386ae2b25 Add more button/navbar colors and gradient mix section to theme editor 2026-07-07 20:04:16 +02:00
openhands e43a768ce4 Add 4 new theme colors (success, warning, error, info) with full preset support 2026-07-07 19:48:41 +02:00
openhands 54c03c998c Fix card text readability: use navbar-text color paired with navbar background on all cards 2026-07-07 19:40:13 +02:00
openhands e53a9dc838 Redesign news article cards with clean image-first layout and proper spacing 2026-07-07 19:29:22 +02:00
openhands 4d4d9bc1cd Make card and box backgrounds follow navbar theme color 2026-07-07 19:26:05 +02:00
openhands 61ae4e7f8b Add explicit theme color to ContentCard title for consistent theming across all pages 2026-07-07 19:20:54 +02:00
openhands 63e1e6a44e Add themed header bar and image preview to news article cards 2026-07-07 19:17:22 +02:00
openhands f86f73b128 Add image preview to news listing cards 2026-07-07 19:10:32 +02:00
openhands 8818d5364e Replace checkbox with React state-driven toggle for reliable terms acceptance 2026-07-07 19:03:33 +02:00
openhands 3becaf5f4f Fix terms checkbox: wrap input inside label for reliable toggling 2026-07-07 19:00:07 +02:00
openhands 7412bd2dda Remove outfit selection from register form and fix terms checkbox not toggling 2026-07-07 18:53:13 +02:00
openhands 4ba26fd814 Close dropdown and mobile menu when clicking a page link 2026-07-07 18:34:54 +02:00
openhands 0272da09c1 Fix logo generator: remove decorative fonts and fix missing char spacing 2026-07-07 16:50:58 +02:00
openhands 9a7b40eae6 Add favicon assets, update Nitro v3 script, and update logs 2026-07-07 16:04:25 +02:00
openhands 2f0233a0c0 Add /api/badges/leaderboard endpoint for Nitro v3 badge leaderboard 2026-07-07 16:00:46 +02:00
openhands efb9758cba working 2026-07-06 22:43:27 +02:00
openhands 29f8a44f0f Add favicon generator with color picker and text 2026-07-05 23:32:24 +02:00
openhands 4a80742e1c Add default SVG favicon fallback 2026-07-05 23:25:36 +02:00
openhands 25c3040949 Add favicon upload option in admin panel 2026-07-05 23:22:44 +02:00
openhands befa4ec282 Translate admin panel to all 6 languages 2026-07-04 21:21:15 +02:00
openhands f381aa987f Fix dropdown visibility and add missing translations 2026-07-04 20:18:30 +02:00
openhands 3527cbd34f Add AUTH_URL to env example 2026-07-04 20:06:21 +02:00
openhands c9d951aa86 Fix login CSP and auth host trust 2026-07-04 20:04:44 +02:00
openhands 83d1483ecd [skip ci] Remove CI workflow 2026-07-04 19:50:42 +02:00
openhands d5f5e0a973 Revert "Remove CI workflows (no Gitea runner available)"
CI / check (push) Has been cancelled
This reverts commit 55175b5332.
2026-07-04 19:49:40 +02:00
openhands 55175b5332 Remove CI workflows (no Gitea runner available) 2026-07-04 19:48:44 +02:00
openhands 8bcbc501ba Performance, SEO, a11y, and code quality improvements
CI / check (push) Has been cancelled
1. Performance: 25 pages switched from force-dynamic to revalidate=300 (ISR);
   2 pages (community, developers) now fully static (SSG)
2. DB indexes: Added @@index on foreign keys for WebsiteArticles,
   WebsiteArticleReactions, WebsiteArticleComments, WebsiteHelpCenterTickets,
   WebsiteShopArticles, RadioSongRequests, StaffActivities
3. SEO: Added robots.ts, sitemap.ts, canonical URLs, Open Graph + Twitter
   Card metadata on root layout and news articles
4. A11Y: Replaced <details>/<summary> dropdowns with accessible button-based
   NavDropdown (aria-expanded, aria-haspopup, role=menu). MobileNav now
   uses translated aria-label, aria-expanded, aria-controls, role=menu
5. Code quality: Added try/catch to updateArticle/deleteArticle; deleteArticle
   now uses prisma. for atomicity
6. CI/CD: Added GitHub Actions workflow (typecheck + test)
7. i18n: Added openMenu/closeMenu keys to all 6 locales
8. Observability: Health endpoint now checks SMTP reachability when configured
9. Loading states: Added loading.tsx for root, admin, and news sections
10. Word filter cache: Added 60s TTL auto-refresh instead of manual cache bust
2026-07-04 19:41:04 +02:00
openhands 10523e58ce Fix remaining security vulnerabilities
- H1: Add missing sanitize() to help center content rendering
- H2: Tighten CSP by removing unsafe-inline/unsafe-eval from script-src;
  move theme init to external JS file with meta tag for defaultDark
- M1: Add SSRF protection for radio API URLs (block private IPs)
- M2: Add rate limiting to SSO ticket endpoint (5 req/30s per user)
- M4: Document locale validation safety in i18n dynamic import
- L1: Truncate stacktraces in admin commandocentrum to first 20 lines
2026-07-04 19:10:43 +02:00
openhands 5628e7d6b7 Security hardening: 12 improvements across the stack
1. env.ts: APP_KEY placeholder detection with validation
2. schema.prisma: password column widened to varchar(255) for argon2id
3. auth.ts: trustHost restricted to development only
4. next.config.ts: added CSP, HSTS, X-Frame-Options, and other security headers
5. api.ts: CORS restricted to APP_URL instead of wildcard
6. register-form.tsx: migrated from REST API fetch to server action (useActionState)
7. twofactor.ts + 2fa page: TOTP recovery codes (8 one-time codes, generated and displayed)
8. register.ts: password min length 8 + complexity requirements (upper, lower, digit)
9. register.ts + help-tickets.ts + radio-shouts.ts: Zod schema validation
10. rate-limit.ts: improved periodic cleanup with aggressive eviction at 10k buckets
11. guard.ts + admin actions: rate-limited admin actions (30 req/min per staff)
12. help-tickets.ts + radio-shouts.ts: content moderation via moderateOrThrow
2026-07-04 18:52:00 +02:00
openhands a1950e5b65 fix: correct sprite font vertical offset and use avg char width fallback 2026-07-03 18:37:05 +02:00
openhands 77ae4838c0 feat: 100% self-hosted Habbo fonts via sprite sheets + client-side compositor 2026-07-03 18:22:30 +02:00
openhands 8a58bcb252 fix: restore word-level proxy for Habbo fonts, pre-cache all 175 fonts for 'Atom' 2026-07-03 17:58:56 +02:00
openhands ac75f9c80a feat: 100% self-hosted Habbo fonts - 6300 char GIFs + local canvas compositor, no habbofont.net dependency 2026-07-03 17:36:34 +02:00
openhands 00b1d0a267 feat: pre-cache all 175 font GIFs for default text 'Atom' 2026-07-03 17:28:16 +02:00