Commit Graph
55 Commits
Author SHA1 Message Date
openhands 108c6ce03d fix(ci): make the lint gate fail for real and stop byparr leaking disk
Gitea Actions Runner Test / test-job (push) Successful in 2s
CI / check (push) Successful in 36s
CI / tests-integration (push) Successful in 2m3s
CI / tests-unit (push) Successful in 2m18s
CI / tests-ui (push) Successful in 3m6s
CI / preflight (push) Skipped
CI / deploy (push) Failing after 3m14s
The CI lint step was `biome check . || true`, so it could never fail: 14 real
violations were passing unnoticed. Drop the `|| true` and fix what it found.

Lint fixes, none of which change behaviour:
- give list items their natural identity instead of the array index
  (key={c} / key={char}, key={`skeleton-${i}`})
- document the two useEffect dependency lists that must keep their
  function-declaration handlers, with the reasoning that dropping them broke
  the tree and save-on-Ctrl+S once already (704e3363)
- scope the remaining noArrayIndexKey / useExhaustiveDependencies exemptions to
  the three files that need them, in biome.json instead of scattered comments

Storage, on a host that had grown to 81% disk:
- byparr starts a Firefox per request and never removes the profile it leaves in
  the container's writable layer. With no volume mounted, nothing else reclaimed
  it: 716 profiles / 6.8 GB in two days, ~1.7 GB/day. docker-prune.sh now removes
  orphaned profiles, identifying live ones by the open fd in /proc/<pid>/fd rather
  than by age, because browsers stay warm for ~27 hours here — longer than the
  leak window, so no age threshold can be both safe and useful.
- bound the build cache properly: buildx treats --max-used-space and --filter as
  mutually exclusive, so passing both silently dropped the 4 GB cap and the cache
  reached 49 GB.
- escalate to the emergency prune when / drops below 8 GB free, so the bound holds
  even if the schedule stops.
- clear multi-GB tmp_pack files left behind by a gc that was OOM-killed
  mid-repack; git only removes those on the next successful gc.
- make setup-cron.sh append instead of replacing the crontab (`crontab -`
  overwrites the whole file, which had been dropping the other scheduled jobs),
  and run the prune daily rather than weekly to match the leak rate.

Volumes are still never pruned: mariadb-turbo-data is a database.
2026-10-05 17:24:12 +02:00
openhands eddb7edea4 fix: make all CI jobs pass (integration, ui) and restore prefix dialog reset
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 28s
CI / tests-integration (push) Successful in 1m34s
CI / tests-unit (push) Successful in 1m35s
CI / tests-ui (push) Successful in 2m20s
CI / preflight (push) Skipped
CI / deploy (push) Failing after 2m37s
Three failing test suites blocked CI. All three were test defects, not
application bugs.

Integration tests (integration/database.test.ts)
------------------------------------------------
The suite set NODE_ENV=test, which makes cache.cached() short-circuit both
its Redis read (src/lib/cache.ts:226) and its write (:249). A suite whose
stated purpose is exercising the real Redis path therefore never touched
Redis. Switched to NODE_ENV=development, the only non-production value
src/env.ts accepts, so the shared-cache code paths are genuinely covered.

Three assertions then needed correcting for real Redis semantics:

- `await cache.cached(...)` followed by `.resolves` can never hold: await
  yields a value, not a Promise. Assert the value directly.
- A cached negative result is stored as the JSON encoding of null, so
  `redis.get(key)` returns "null", not null.
- The news negative-cache key does not exist at all, so `ttl()` returned -2.
  Now that the write path is live the key is created and the TTL assertion
  holds as originally written.

UI tests (src/app/admin/prefixes/prefix-dialog.tsx)
---------------------------------------------------
The form-reset effect had `isOpen` removed from its dependency array. The
component returns null when closed, so the effect only ever ran on mount:
reopening the dialog no longer cleared the fields and a dismissed-but-
unsaved edit reappeared. Two tests in e2e/ui/unsaved-changes.spec.ts caught
this. Restored the dependency and documented why it is load-bearing.

The remaining edits in this branch drop stale biome-ignore comments that
suppressed useExhaustiveDependencies and noArrayIndexKey diagnostics. Where
the suppression had been load-bearing for behaviour, the underlying
dependency is now listed explicitly rather than silenced.

Verified: check (toolchain, audit, lint, i18n, typecheck), unit 3315
passed, integration 20 passed, UI 72 passed / 2 skipped.
2026-10-03 17:02:49 +02:00
Simo 8abfe352ef fix(security): authorize site uploads and harden tokens, media and request identity
CI / check (push) Successful in 3m15s
CI / deploy (push) Successful in 1m19s
CI / publish-container (push) Successful in 48s
2026-09-13 19:24:43 +02:00
openhands e5e17d75ae perf(site): inline small classic icons and favicon as base64
CI / check (push) Successful in 2m27s
CI / deploy (push) Successful in 1m34s
CI / publish-container (push) Successful in 50s
- New src/lib/site-icons.ts: base64 data URIs for the 13 tiny classic
  icons actually referenced in markup (100–2000 bytes), replacing extra
  requests with inline payloads. home.png, dynamic flags and currency
  sets stay on the filesystem.
- Default favicon is now served server-side as a base64 SVG data URI
  (memoized), while a DB-configured custom favicon still takes priority.
- Icons render through <Image unoptimized>, so data URIs pass through
  untouched on all affected pages (home, login, register, settings,
  navigation, auth top bar, client loading).
2026-09-12 17:28:01 +02:00
openhands b810b16672 fix: show/hide arrow always visible and null-safe
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m2s
- Show arrow (›) appears when toolbar is hidden, regardless of pos state
- Null-safe pos top/left (?. ?? 8) to prevent TS errors
- Arrow positioned fixed top-right instead of depending on balk-positie
2026-09-02 22:02:31 +02:00
openhands a30e4af32e feat: polish toolbar, live online count via SSE + emulator 3-state
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 30s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m5s
- Add emulator status 3-state (unknown/green/red) with tooltip
- Extract shared primary button style/constants for DRY toolbar code
- Add emulatorUnknown translations to all 25 locales
- Bump Next.js to 16.3.4
- Fix RCON delivery timeout caching (15s TTL / shared across clients)
- Who's-online tooltip throttled to max 1 request per 30s
2026-09-02 21:34:30 +02:00
openhands 67b67798b9 feat(client): polished toolbar, live online count via SSE
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m27s
- Redesign in-game client toolbar with refined glass styling and buttons
- Live online count + emulator status streamed over SSE multicast
- Who's-online tooltip throttled to reduce repeated requests
- Fix show button so it always returns the hidden toolbar
- Use theme CSS variables instead of hardcoded colors
- Add toolbar translations across all 25 locales
2026-09-02 21:14:42 +02:00
openhands 58c35a2920 feat: enforce no hardcoded colors across entire CMS
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 32s
CI / release (push) Skipped
CI / deploy (push) Successful in 58s
Added scripts/check-admin-colors.mjs — scans all src/ files for:
- text-white, text-black (use theme text vars)
- bg-white, bg-black (use theme background/overlay vars)
- bg/text/border/ring with gray/slate/zinc/stone palette
- bg/text/border/ring with red/green/blue/etc palette

Fixed 21 violations across 11 files:
- Overlays: bg-black/* → bg-foreground/*
- Text: text-white → text-primary-foreground
- Backgrounds: bg-white/10 → bg-background/10
- Green accents: bg-green-* → bg-primary
- Red accents: bg-red-* → bg-destructive

Integrated into:
- lint-staged: runs on every *.ts/*.tsx commit
- vitest: src/lib/no-hardcoded-colors.test.ts replaces old audit test
- Allowlist: shadcn/ui primitives (button, badge, dialog) + 4 graphical files
2026-09-01 19:33:50 +02:00
openhands b59d6c21af feat: prioritize game iframe, gated register terms and polished register page
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 55s
Fetch the Nitro client iframe with high priority so the browser starts the
game document before competing resources, and replace the bare /client
spinner with a branded boot screen. Preconnect and eager loading were already
in place; typing support for the iframe fetchPriority prop is added in a
React type augmentation.

Rework the register terms block into a single clickable accept control with
a custom check state, error shake and inline hint, and dim the submit button
until the terms are accepted. The register page gets labeled sections
(account details / credentials), a corrected banner overlay, translated
show/hide toggles and a captcha slot that reserves height to avoid layout
shifts. English is the source of truth; other locales fall back to it.
2026-08-29 21:14:02 +02:00
openhands 7f39ba4257 fix: harden SSO ticket flow and revoke tickets on logout
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 54s
Reuse the outstanding auth_ticket instead of minting a fresh one on every
/client load, so reloading the page or opening a second tab no longer
invalidates a game session that is still connecting. New tickets are minted
with a guard against the previously-read value so concurrent launches
converge on the same ticket.

Revoke the auth_ticket when signing out (toolbar, header and sign-out
everywhere) so a leaked ticket can no longer be replayed against the
emulator, and prevent SSO leakage via referral by setting no-referrer on the
client iframe. Strip all whitespace from the ticket prefix and build the
launch URL through a tested helper that handles query strings, existing sso
params and URL fragments correctly.
2026-08-29 20:54:06 +02:00
openhands 7a41775c7e fix: disable route prefetching app-wide to avoid spurious requests
Wrap next/link in a shared Link component that ships prefetch=false by
default, so no route is ever prefetched (viewport or hover) anymore, and
drop the DNS prefetch hint. Removes hidden background requests that were
the source of intermittent issues.
2026-08-29 19:27:13 +02:00
openhands 9d0da5d65a Perf: cache Nitro client assets and parallelize client page
CI / check (push) Successful in 31s
CI / release (push) Skipped
CI / deploy (push) Successful in 59s
- Serve /swf and /nitro-assets (~2.8GB) with 7-day Cache-Control plus
  stale-while-revalidate so client opens stop re-fetching hundreds of
  files while asset updates still propagate in the background
- Issue the SSO ticket and the online count query in parallel on the
  client page to shave a round-trip off the critical render path
2026-08-26 15:06:16 +02:00
openhands 416c31643b perf: optimize dashboard database queries and remove unused imports
CI / check (push) Failing after 10s
CI / deploy (push) Skipped
CI / release (push) Skipped
2026-08-25 21:52:18 +02:00
openhands 51ef7602ca perf: migrate pages to Cache Components via root layout opt-out
Remove the per-route 'export const instant = false' opt-outs now that the root layout carries the single Cache Components opt-out. Child pages inherit the opt-out, so admin/mod/radio leaf pages that only access cached or DB data stay instant while runtime-dependent pages remain dynamic. Update the staff-smoke contract test to assert the root-layout contract.
2026-08-07 18:51:45 +02:00
openhands dc8fb8a6ed feat: speed up admin clone import and enable Cache Components
- Clone import: defer FurnitureData.json writes and append all entries in a
  single batched write instead of one read-modify-write per item, removing
  the main serialization bottleneck for large batches.
- Clone import: raise SSE batch concurrency cap from 5 to 10 and bump the
  clone client/route default from 2 to 6.
- Add a flush hook to runSseBatch so callers can batch deferred work before
  batch_complete is emitted, and surface flush errors as an error event.
- Enable Next.js Cache Components (instant: false opt-out) and silence the
  related build warnings in next.config.ts.
- Switch isomorphic-dompurify to dompurify and refresh dependencies.
2026-08-05 11:10:16 +02:00
SimoandCursor 30b54e99e7 refactor(db): migrate app pages and APIs from Prisma facade to Drizzle (5)
Co-authored-by: Cursor <[email protected]>
2026-08-01 14:15:39 +02:00
openhands dacc4cadfd chore(deps): upgrade to typescript 7 bridge and clean up pnpm v11 workspace configs
CI / check (push) Failing after 58s
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 11s
2026-07-27 23:14:00 +02:00
openhands 423a33200e chore: improve tooling, linting, testing, and CI
CI / check (push) Failing after 14s
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m38s
- Add LICENSE file (CC BY-NC-SA 4.0)
- Add .nvmrc pinning Node 22
- Add Renovate config with daily schedule and Gitea Actions workflow
- Reduce ESLint max-warnings from 1000 to 50
- Re-enable Biome a11y/security recommended rules
- Fix Biome lint issues (a11y, hook deps, SVG labels, checkbox semantics)
- Improve CI: run on pushes to feat/fix branches, add pnpm audit
- Add Vitest coverage with v8 provider and thresholds
- Add E2E tests (auth, admin, navigation specs)
- Add admin-maintenance server action test
- Install @vitest/coverage-v8
- Ignore coverage/ directory
2026-07-27 17:03:09 +02:00
openhands 4bb908ecf7 Center client toolbar at top by default instead of right side
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m55s
2026-07-26 21:37:38 +02:00
openhands 17847545dd Improvements: remove dead config, fix ESM, add URL validation, unify types, add missing logging
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m52s
- Remove .prettierrc (dead config, Biome replaces Prettier)
- Rename lighthouserc.json to lighthouserc.cjs with module.exports for ESM compat
- Add logger.warn to empty catch blocks in auth, register, site-settings, prisma-cache, redis, security, rate-limit
- Unify ActionResult type: action-helper.ts uses 'ok' consistent with safe-action-shared.ts
- Add noUnusedLocals + noUnusedParameters to tsconfig + fix 25 pre-existing unused vars
- Replace barrel export src/types/index.ts with direct @/types/common imports
- Make trustHost conditional (development only) in auth.ts
- Add pre-flight URL validation to update-Nitrov3.sh to catch image.library.url misconfigurations
- Improve NITRO_IMAGE_LIBRARY_URL content validation in pre-flight & post-compute checks
2026-07-26 20:28:11 +02:00
openhands b922f6d49f fix: remove auto-hide, toolbar always visible
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m54s
2026-07-26 18:47:04 +02:00
openhands 8c2fe603d1 fix: keep toolbar interactive when hidden (opacity 8% instead of pointer-events-none) so mouse-enter brings it back
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m2s
2026-07-26 18:38:23 +02:00
openhands 1e0dd183b1 feat: premium toolbar with glassmorphism, auto-hide, edge snap, and smooth snap animation
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m52s
2026-07-26 18:17:32 +02:00
openhands ea71a574a4 refactor: useLayoutEffect for no-flash position init, clean localStorage save, hide toolbar until ready
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m3s
2026-07-26 18:11:12 +02:00
openhands b77dbb65f6 fix: cleanup old position system, add proper useRef import
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m50s
2026-07-26 18:04:50 +02:00
openhands 7f7e11adcf feat: freely draggable toolbar with pixel-position saved to localStorage
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 32s
2026-07-26 18:02:43 +02:00
openhands 86d15d0d92 fix: toolbar now renders outside overflow container, supports 4 corner positions (top-left/right, bottom-left/right)
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m3s
2026-07-26 17:59:04 +02:00
openhands e336ac3c66 feat: configurable toolbar position (site setting + localStorage toggle + URL override)
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m53s
2026-07-26 17:52:24 +02:00
openhands 623cced64e fix: move toolbar to right side
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m47s
2026-07-26 17:46:57 +02:00
openhands e464fac102 fix: render toolbar via portal to body so it stays visible in fullscreen
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m49s
2026-07-26 17:36:00 +02:00
openhands 2a727b2a71 refactor: smaller toolbar icons, remove language and theme switchers from client
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m49s
2026-07-26 17:29:18 +02:00
openhands f072a28aee refactor: remove logo from client toolbar, move language and logout to left group
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m50s
2026-07-26 17:24:46 +02:00
openhands d010344423 feat: add language switcher, theme switcher, logout, and hotel logo to client toolbar
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m48s
2026-07-26 17:17:56 +02:00
SimoandCursor e00e9ca2dc refactor: centralize hotel name fallback via FALLBACK_HOTEL_NAME
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m6s
Route all user-facing Atom hotel defaults through resolveHotelName (settings then HOTEL_NAME env then brand constant). Exclude Playwright e2e from tsconfig until deps are installed.

Co-authored-by: Cursor <[email protected]>
2026-07-22 18:45:59 +02:00
openhands d189bb5af4 fix: mobile responsive improvements
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m2s
- Audit: responsive summary cards (grid-cols-2 mobile, p-3), responsive empty states
- Repair-icons/sync-all: log area horizontal scroll (overflow-x-auto, whitespace-nowrap)
- Upload furni: tighter mobile padding (p-4 sm:p-5)
- Nitro client: compact toolbar on mobile (smaller buttons, tighter gap, top-2/left-2)
2026-07-21 16:47:02 +02:00
openhands 5e8a13a84f fix: resolve all biomaly lint errors and warnings across CMS
Deploy / release (push) Successful in 4s
Deploy / deploy (push) Skipped
- Fix CSS parser config (tailwindDirectives enabled)
- Fix noDangerouslySetInnerHtml via SanitizedHtml component
- Fix useExhaustiveDependencies in catalog-manager-dialog
- Fix noArrayIndexKey across 26 files (stable keys)
- Fix SVG a11y (titles, roles, aria-labels)
- Fix label/input associations (htmlFor/id pairs)
- Fix static element interactions (role + keyboard support)
- Fix noImgElement, noDescendingSpecificity (disabled - external Habbo URLs)
- Fix noNonNullAssertion, useTemplate, unused vars/imports
- Add SanitizedHtml shared component
- Migrate biome.json to 2.5.4 schema
2026-07-20 17:41:53 +02:00
openhands 2beba07ba5 feat: enable React Compiler, optimizePackageImports for lucide-react, add loading states for (site) and client routes
Local Build and Deploy / deploy (push) Successful in 1m19s
2026-07-20 14:25:12 +02:00
openhands df38dccbf1 style: format code biome
Local Build and Deploy / deploy (push) Failing after 46s
2026-07-13 21:57:41 +02:00
Simo 4a1e1115b3 Harden CMS security and theme contrast 2026-07-11 20:27:20 +02:00
openhands 41be6835bf Add missing admin action files and navigation links
- Add 11 missing server action files: badges, bulk-users, catalog, catalog-bc, catalog-items, import-badges, import-furni, multi-account-detect, permissions, rooms, soundtracks
- Add missing admin navigation links: tickets, sounds, translations, import, radio sub-pages
- Add translation keys for all new navigation items
2026-07-11 12:01:05 +02:00
openhands 942bc6fc8d Security hardening, code quality, and ESLint setup
- Remove production DB dump (db_backup_*.sql) and update.log from git tracking
- Add DB backups to .gitignore
- Replace all console.log/console.error with structured logger module
- Translate Dutch error messages to English (link-discord.ts)
- Remove dead code blocks (register-form.tsx false && pattern)
- Add ESLint flat config with TypeScript, React, Next.js, jsx-a11y, and security plugins
- Add Prettier config
- Add eslint-plugin-security for security-aware linting
- Fix all 119+ ESLint warnings across the codebase:
  - Resolve security/detect-object-injection with safe access patterns
  - Resolve security/detect-non-literal-fs-filename with path traversal validation
  - Replace <img> with next/image <Image> component
  - Remove unused variables and imports
  - Replace non-null assertions with proper type guards
  - Replace <a> with <Link> for internal navigation
  - Use next/script Script component for external scripts
- Fix setState-in-useEffect anti-patterns (navbar-color-picker, logo-generator, theme-switcher)
- Add lint and format scripts to package.json

All checks: typecheck ✓, tests 58/58 ✓, lint 0 errors 0 warnings ✓
2026-07-10 22:48:22 +02:00
openhands 7fe3220359 Inline SSO ticket generation in server component, prefetch client page from home, remove client API roundtrip 2026-07-09 18:41:04 +02:00
openhands da505ae643 Optimize client page: combine fetch calls, extract ToolbarBtn component, reduce duplicated inline styles 2026-07-09 18:30:46 +02:00
openhands 01e7f84d18 feat: append '- Hotel' to hotel name in title bar, site header and client header 2026-07-03 16:22:42 +02:00
openhands 187af2e147 fix: strip existing sso param from clientUrl, add aria roles to dropdowns, add x-pathname fallback, move .dropdown-menu into @layer components 2026-07-03 16:17:42 +02:00
openhands 7e616ca6b3 refactor: extract duplicate header into shared renderHeader function 2026-07-03 16:05:56 +02:00
openhands 98c9b951c4 fix: remove duplicate site-bg, handle fullscreen promise rejection, unify tooltip language, improve dropdown CSS compat and accessibility 2026-07-03 16:03:09 +02:00
openhands e5b0649bf1 fix: remove debug console.log from root layout 2026-07-03 15:51:33 +02:00
openhands 7e5813bd97 Fix client loading as atomcms normal 2026-07-03 15:16:47 +02:00
remco d6ccc250f6 feat: mobile nav, radio layout/requests, leaderboard tabs, client i18n, habbo background, navbar fixes 2026-07-01 15:59:02 +02:00