Simo and Cursor
09f1bc2bd6
Add production observability: Sentry, pino, and sharp badge encoding.
...
Local Build and Deploy / deploy (push) Successful in 1m9s
Sentry is opt-in via DSN env vars; logger uses structured pino JSON in prod; badge uploads are normalized to GIF with sharp.
Co-authored-by: Cursor <[email protected] >
2026-07-17 23:09:57 +02:00
openhands
df38dccbf1
style: format code biome
Local Build and Deploy / deploy (push) Failing after 46s
2026-07-13 21:57:41 +02:00
Simo
c0ffc74f9b
fix: externalize lzma for import build
Local Build and Deploy / deploy (push) Successful in 49s
2026-07-12 19:15:08 +02:00
Simo
5b4228261a
Reapply "Add missing admin action files and navigation links"
...
This reverts commit 4d515bc400 .
2026-07-11 20:52:56 +02:00
Simo
4d515bc400
Revert "Add missing admin action files and navigation links"
...
This reverts commit 41be6835bf .
2026-07-11 20:37:56 +02:00
openhands
41be6835bf
Add missing admin action files and navigation links
...
- Add 11 missing server action files: badges, bulk-users, catalog, catalog-bc, catalog-items, import-badges, import-furni, multi-account-detect, permissions, rooms, soundtracks
- Add missing admin navigation links: tickets, sounds, translations, import, radio sub-pages
- Add translation keys for all new navigation items
2026-07-11 12:01:05 +02:00
openhands
deac10e00a
Add in-memory caching for online count, enable compression, and add staleTimes for router cache
2026-07-09 18:24:58 +02:00
openhands
c9d951aa86
Fix login CSP and auth host trust
2026-07-04 20:04:44 +02:00
openhands
10523e58ce
Fix remaining security vulnerabilities
...
- H1: Add missing sanitize() to help center content rendering
- H2: Tighten CSP by removing unsafe-inline/unsafe-eval from script-src;
move theme init to external JS file with meta tag for defaultDark
- M1: Add SSRF protection for radio API URLs (block private IPs)
- M2: Add rate limiting to SSO ticket endpoint (5 req/30s per user)
- M4: Document locale validation safety in i18n dynamic import
- L1: Truncate stacktraces in admin commandocentrum to first 20 lines
2026-07-04 19:10:43 +02:00
openhands
5628e7d6b7
Security hardening: 12 improvements across the stack
...
1. env.ts: APP_KEY placeholder detection with validation
2. schema.prisma: password column widened to varchar(255) for argon2id
3. auth.ts: trustHost restricted to development only
4. next.config.ts: added CSP, HSTS, X-Frame-Options, and other security headers
5. api.ts: CORS restricted to APP_URL instead of wildcard
6. register-form.tsx: migrated from REST API fetch to server action (useActionState)
7. twofactor.ts + 2fa page: TOTP recovery codes (8 one-time codes, generated and displayed)
8. register.ts: password min length 8 + complexity requirements (upper, lower, digit)
9. register.ts + help-tickets.ts + radio-shouts.ts: Zod schema validation
10. rate-limit.ts: improved periodic cleanup with aggressive eviction at 10k buckets
11. guard.ts + admin actions: rate-limited admin actions (30 req/min per staff)
12. help-tickets.ts + radio-shouts.ts: content moderation via moderateOrThrow
2026-07-04 18:52:00 +02:00
Simo
7daeccb832
Add dark mode, i18n, messenger/moderation/verify, admin CRUD parity
...
Web-tier features completing the AtomCMS→Next.js conversion (slice 2):
UI/UX:
- Dark mode: html.dark CSS-var overrides + ThemeSwitcher (localStorage,
no-flash boot script) wired into the nav.
- i18n (next-intl, cookie-based / no URL routing): en + it catalogs,
request.ts, provider in root layout, LanguageSwitcher; shell (nav,
header, footer) fully translated. URLs + access-guard unchanged.
- globals.css: --muted/--border aliases used across admin pages.
User features:
- /messages: offline messages + friend-request accept (server action
re-reads session, two directional rows, idempotent).
- Email verification: signed-token /verify route + sendVerification wired
into register (best-effort, never blocks signup).
- Article reactions: toggle UI on news/[slug] + server action.
- Content moderation service (website_wordfilter + optional OpenAI
moderations, fail-open) wired into article comments + guestbook.
Admin CRUD parity (Filament replacement):
- /admin/shop (+ new/[id]) packages CRUD + read-only orders.
- /admin/transactions read-only PayPal log.
- /admin/permissions, /admin/tags, /admin/ads (+ new/[id]),
/admin/help-questions (+ new/[id]), /admin/radio/history,
/admin/users/[id]/edit. All gated by requireStaff + logStaffActivity.
Verified: tsc 0, vitest 48/48, next build 0 (all routes incl. new
admin CRUD + /messages + /verify).
2026-06-28 16:06:42 +02:00
Simo
443d908909
Scaffold Next.js 16 app + wire NextAuth Credentials to auth core
...
Minimal but real App Router app that builds (next build exit 0):
- src/lib/auth.ts: NextAuth v5 Credentials provider calling checkLogin()
(argon2id/bcrypt + md5->argon2id upgrade gated by CONVERT_PASSWORDS), JWT
session, /api/auth/[...nextauth] route handler.
- src/app: root layout, home (force-dynamic, reads hotel_name via siteSettings),
/login client form (signIn).
- next.config.ts: pinned turbopack.root, serverExternalPackages for the Prisma
MariaDB adapter; tsconfig set up for Next.
Routes: / (dynamic), /login, /api/auth. Verified: next build exit 0, 28 tests.
Still needs DB+APP_KEY to run auth end-to-end. i18n/middleware/pages to follow.
2026-06-27 16:11:52 +02:00