remco
09654fd5a8
Update README.md
Remote Build and Deploy / deploy (push) Failing after 0s
2026-07-11 21:38:04 +02:00
Simo
173274527f
Merge remote-tracking branch 'nextjs/main' into codex/publish-nextjs-current
Remote Build and Deploy / deploy (push) Failing after 0s
2026-07-11 21:36:54 +02:00
remco
28fe2e1352
Add rtrtt
Remote Build and Deploy / deploy (push) Failing after 0s
2026-07-11 21:36:32 +02:00
Simo
eaf5fc387d
Merge remote-tracking branch 'nextjs/main' into codex/publish-nextjs-current
2026-07-11 21:36:17 +02:00
Simo
17264dfc06
fix: protect admin routes and ignore local docs
2026-07-11 21:35:37 +02:00
remco
d705782df0
Add test test
Remote Build and Deploy / deploy (push) Failing after 0s
2026-07-11 21:33:33 +02:00
remco
4f9556e196
Update .gitea/workflows/deploy.yaml
Remote Build and Deploy / deploy (push) Failing after 0s
2026-07-11 21:30:07 +02:00
Simo
6a08db8dd0
style: normalize deploy workflow
Remote Build and Deploy / deploy (push) Failing after 0s
2026-07-11 21:27:42 +02:00
Simo
62db89119c
Merge remote-tracking branch 'nextjs/main' into codex/publish-nextjs-current
2026-07-11 21:27:27 +02:00
Simo
c4454a292c
fix: parse SQL migration comments safely
2026-07-11 21:27:18 +02:00
remco
675fa4ae2e
Update .gitea/workflows/deploy.yaml
Remote Build and Deploy / deploy (push) Has been cancelled
2026-07-11 21:25:04 +02:00
Simo
8d37ae9ae0
style: normalize restored source endings
Remote Build and Deploy / deploy (push) Has been cancelled
2026-07-11 21:19:54 +02:00
Simo
9552d6b938
Merge remote-tracking branch 'nextjs/main' into codex/publish-nextjs-current
2026-07-11 21:19:37 +02:00
remco
033011fd38
Add .gitea/workflows/deploy.yaml
Remote Build and Deploy / deploy (push) Has been cancelled
2026-07-11 21:16:04 +02:00
Simo
0cd753c735
fix: restore complete admin feature dependencies
2026-07-11 21:15:54 +02:00
remco
03135fb7c1
Delete directory ' .gitea/workflows'
2026-07-11 21:15:28 +02:00
remco
788d0b0e09
Update .gitea/workflows/deploy.yml
2026-07-11 21:14:12 +02:00
remco
038232655a
Delete directory '.gitea/workflows'
2026-07-11 21:13:52 +02:00
remco
f95ba94bcf
Update .gitea/workflows/deploy.yml
Deploy Atom Next / deploy (push) Has been cancelled
2026-07-11 21:10:45 +02:00
remco
db2e8d80c3
Update .gitea/workflows/deploy.yml
Deploy Atom Next / deploy (push) Has been cancelled
2026-07-11 21:09:57 +02:00
remco
4f4044992b
Update .gitea/workflows/deploy.yml
Deploy Atom Next / deploy (push) Has been cancelled
2026-07-11 21:08:57 +02:00
remco
b0c1f7a34a
Update .gitea/workflows/deploy.yml
Deploy Atom Next / deploy (push) Has been cancelled
2026-07-11 21:07:29 +02:00
remco
c8b89803aa
Add .gitea/workflows/deploy.yml
Deploy Atom Next / deploy (push) Has been cancelled
2026-07-11 21:06:50 +02:00
remco
1f2d47b9bb
Update .gitea/workflows/deploy.yaml
Deploy Atom Next / deploy (push) Has been cancelled
2026-07-11 21:05:28 +02:00
remco
e84547a700
Add .gitea/workflows/deploy.yaml
Deploy Atom Next / deploy (push) Has been cancelled
2026-07-11 21:04:10 +02:00
remco
be4879e54c
Delete .gitea/workflows/test.yaml
2026-07-11 21:03:43 +02:00
remco
d3e1041f8e
Add .gitea/workflows/test.yaml
Guaranteed Test / always-success (push) Has been cancelled
2026-07-11 20:55:49 +02:00
Simo
5b4228261a
Reapply "Add missing admin action files and navigation links"
...
This reverts commit 4d515bc400 .
2026-07-11 20:52:56 +02:00
Simo
96ed768f14
test: add unresolved local import scanner
2026-07-11 20:52:55 +02:00
Simo
cabafb4ea6
docs: plan complete admin feature recovery
2026-07-11 20:51:33 +02:00
Simo
c670bd8c64
docs: design admin feature recovery
2026-07-11 20:48:45 +02:00
Simo
4d515bc400
Revert "Add missing admin action files and navigation links"
...
This reverts commit 41be6835bf .
2026-07-11 20:37:56 +02:00
Simo
4a1e1115b3
Harden CMS security and theme contrast
2026-07-11 20:27:20 +02:00
openhands
2465ff2170
Add translation keys for new admin nav items in all languages
2026-07-11 12:28:52 +02:00
openhands
41be6835bf
Add missing admin action files and navigation links
...
- Add 11 missing server action files: badges, bulk-users, catalog, catalog-bc, catalog-items, import-badges, import-furni, multi-account-detect, permissions, rooms, soundtracks
- Add missing admin navigation links: tickets, sounds, translations, import, radio sub-pages
- Add translation keys for all new navigation items
2026-07-11 12:01:05 +02:00
openhands
7e1ae17a3b
Add dotenv loading to migration script
2026-07-10 23:57:36 +02:00
openhands
818df3697b
Migrate from AES-256-CBC to AES-256-GCM for authenticated encryption
...
- Replace CBC+HMAC with GCM (built-in authentication via authTag)
- Remove createHmac and timingSafeEqual imports (no longer needed)
- Remove Snyk-ignore comments (no longer suppressible findings)
- Update test: tampered MAC test -> tampered auth tag test
- Add one-time migration script for existing CBC-encrypted 2FA secrets
2026-07-10 23:51:56 +02:00
openhands
259c0c96ab
Fix remaining Snyk findings: XSS in validImageUrl, cipher integrity suppression
2026-07-10 23:40:11 +02:00
openhands
d782b7c4c2
Fix Snyk security findings: XSS, open redirect, hardcoded secrets, cookie security, MD5 replacement
2026-07-10 23:34:57 +02:00
openhands
1875a69b83
Fix security scanner findings
...
- Replace hardcoded test secrets with crypto-generated values in laravel-encrypter.test.ts and totp.test.ts
- Add 'secure' attribute to locale cookie in language-switcher.tsx
- Validate image URLs before rendering in media-grid.tsx and media-picker.tsx (XSS prevention)
- Validate redirect URL is HTTPS before window.location assignment in TopUpForm.tsx (open redirect prevention)
- Document intentional MD5 usage for legacy PHP compatibility in password.ts
- Document HMAC integrity protection for CBC cipher in laravel-encrypter.ts
2026-07-10 23:08:15 +02:00
openhands
942bc6fc8d
Security hardening, code quality, and ESLint setup
...
- Remove production DB dump (db_backup_*.sql) and update.log from git tracking
- Add DB backups to .gitignore
- Replace all console.log/console.error with structured logger module
- Translate Dutch error messages to English (link-discord.ts)
- Remove dead code blocks (register-form.tsx false && pattern)
- Add ESLint flat config with TypeScript, React, Next.js, jsx-a11y, and security plugins
- Add Prettier config
- Add eslint-plugin-security for security-aware linting
- Fix all 119+ ESLint warnings across the codebase:
- Resolve security/detect-object-injection with safe access patterns
- Resolve security/detect-non-literal-fs-filename with path traversal validation
- Replace <img> with next/image <Image> component
- Remove unused variables and imports
- Replace non-null assertions with proper type guards
- Replace <a> with <Link> for internal navigation
- Use next/script Script component for external scripts
- Fix setState-in-useEffect anti-patterns (navbar-color-picker, logo-generator, theme-switcher)
- Add lint and format scripts to package.json
All checks: typecheck ✓, tests 58/58 ✓, lint 0 errors 0 warnings ✓
2026-07-10 22:48:22 +02:00
openhands
7f8c9afc0f
Replace Arcturus Morningstar references with Polaris in README
2026-07-10 19:28:05 +02:00
openhands
4ae9cbad13
Rebrand README to EpicNext-CMS with professional English rewrite
2026-07-10 19:25:20 +02:00
openhands
9255788b06
Rename Habbo jar pattern to Polaris and bump JVM heap to 4G
2026-07-10 19:12:46 +02:00
openhands
c68fccceeb
Fix: only preconnect nitro URL if absolute (prevents crash on relative URLs like /nitro-client/)
2026-07-09 19:52:19 +02:00
openhands
0ac3e4353a
Remove unused /api/client/sso route (replaced by server-side ticket generation)
2026-07-09 19:11:10 +02:00
openhands
7fe3220359
Inline SSO ticket generation in server component, prefetch client page from home, remove client API roundtrip
2026-07-09 18:41:04 +02:00
openhands
cfb36e8007
Preconnect to Nitro client URL for faster client page load
2026-07-09 18:35:18 +02:00
openhands
da505ae643
Optimize client page: combine fetch calls, extract ToolbarBtn component, reduce duplicated inline styles
2026-07-09 18:30:46 +02:00
openhands
deac10e00a
Add in-memory caching for online count, enable compression, and add staleTimes for router cache
2026-07-09 18:24:58 +02:00