Simo
6ed1b03e24
chore: align Node 26.7.0 toolchain
CI / check (push) Successful in 35s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m0s
2026-08-24 19:12:11 +02:00
openhands
ca1756fbb0
Fix pre-existing type errors in diagnostics scripts (blocked pre-push tsc hook)
CI / check (push) Failing after 31s
CI / release (push) Skipped
CI / deploy (push) Skipped
2026-08-23 15:07:58 +02:00
openhands
536b61c7e7
Add catalog maintenance page with sprite-id, dedup and FurnitureData id-alignment repairs
2026-08-23 15:05:49 +02:00
openhands
3d832cceff
scripts: fix translate call for furni18n
CI / check (push) Failing after 28s
CI / release (push) Skipped
CI / deploy (push) Skipped
2026-08-21 20:06:27 +02:00
openhands
f2a023efb3
scripts: fix build/translate calls for furni18n
2026-08-21 20:06:02 +02:00
openhands
e66b2c1a5a
scripts: add full build/translate scripts for furnidata i18n
2026-08-21 20:04:53 +02:00
openhands
9e453666e5
fix: use jsonc-parser in config merge and make updater reliably restart all services
...
CI / check (push) Successful in 25s
CI / release (push) Skipped
CI / deploy (push) Successful in 58s
merge-config.cjs loaded json5 (not installed, and unable to parse JSONC
comments), so sync_configs crashed mid-update and do_restart never ran —
leaving the emulator running the old JAR.
- merge-config.cjs: switch from json5 to jsonc-parser (already a
dependency) to parse .jsonc configs including comments
- update-Nitrov3.sh: always run renderer/client parallel builds instead
of gating them on the emulator's update status
- update-Nitrov3.sh: isolate each repo's yarn cache (--cache-folder) so
parallel installs can't corrupt a shared cache and silently drop
vite/pixi.js; replace invalid --no-cache flag with per-repo cache reset
- update-Nitrov3.sh: fix misleading [DRY-RUN] label on real updates
2026-08-11 19:06:29 +02:00
openhands
abc06e438c
fix: load .env in standalone tsx scripts
CI / check (push) Successful in 25s
CI / release (push) Skipped
CI / deploy (push) Successful in 52s
2026-08-11 17:08:23 +02:00
openhands
e867b675fc
fix: replace jsonc with jsonc-parser and cleanup build config
2026-08-11 16:50:10 +02:00
openhands
3edc987281
feat: integrate FlareSolverr for Cloudflare bypass on clone sources
...
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 46s
- Add FLARESOLVERR_URL env var to .env.example
- Update fetchSourceFurnidata to fall back to FlareSolverr on CF challenges (403/HTML)
- Add docker-compose.yml with FlareSolverr service
- Add scripts/health-check.sh for FlareSolverr readiness check
- Add health:check script to package.json
- Document FlareSolverr setup in README
2026-08-04 19:00:30 +02:00
openhands
2e87e5bf09
chore: remove test-cf.ts (puppeteer no longer used)
CI / check (push) Successful in 25s
CI / release (push) Skipped
CI / deploy (push) Successful in 56s
2026-08-04 18:46:31 +02:00
openhands
9fbfd2f51a
chore: verify clone sources with Cloudflare bypass test script; remove broken Hubbly URLs
...
CI / check (push) Successful in 26s
CI / release (push) Skipped
CI / deploy (push) Successful in 55s
Verified working sources via puppeteer Cloudflare bypass test:
- Habbo (GitHub) - 200
- Wibbo - 200 furnidata, 403/403 nitro/icons
- Hubba.cc - 200 furnidata, 404 nitro
- Leet - 200 304 304 (all working)
- Habblet City - 200 200 200 (all working)
- Soda Ho - 200 furnidata, 404 nitro/icons
Cloudflare-blocked sources removed (habba.io, habcrush.pw, fobba.net, etc)
Hubbly URLs removed (all 404) pending verification
Added test-cf.ts script for future source validation
2026-08-04 17:28:01 +02:00
Simo
1f4aadb3d7
chore: remove Sentry integration
CI / check (push) Successful in 21s
CI / release (push) Skipped
CI / deploy (push) Successful in 53s
2026-08-01 22:12:31 +02:00
openhands
14a3de0f2a
style(scripts): format schema generator to satisfy biome check
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Failing after 1m0s
2026-08-01 17:50:16 +02:00
openhands
8275842e78
fix(scripts): resolve noAssignInExpressions lint error in schema generator
CI / check (push) Successful in 30s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m28s
2026-08-01 17:14:48 +02:00
Simo and Cursor
db957d7fb1
fix(ops): narrow DB_BACKUP_DIR for jobs-worker typecheck
...
CI / check (push) Failing after 9s
CI / release (push) Skipped
CI / deploy (push) Skipped
Co-authored-by: Cursor <[email protected] >
2026-08-01 15:27:01 +02:00
Simo and Cursor
725e1cb338
feat(ops): health-fail alerts, optional DB backup, admin UX polish
...
Wire jobs-worker health probes to Discord/email alerts with cooldown, optional mysqldump, rate-limit /api/health, mark-all-read alerts, ConfirmDialog on destructive admin actions, and raise coverage floors.
Co-authored-by: Cursor <[email protected] >
2026-08-01 15:25:47 +02:00
Simo and Cursor
ba82789166
chore(db): finish Prisma cutover to Drizzle Kit tooling
...
CI / check (push) Failing after 9s
CI / release (push) Skipped
CI / deploy (push) Skipped
Move CMS SQL to drizzle/migrations, drop prisma packages/schema, wire drizzle-kit scripts, and regenerate schema names from src/db/schema.ts.
Co-authored-by: Cursor <[email protected] >
2026-08-01 15:02:21 +02:00
Simo and Cursor
422567272c
chore(db): remove Prisma facade and drop prisma:generate from CI
...
Co-authored-by: Cursor <[email protected] >
2026-08-01 14:38:42 +02:00
openhands
e5ff7ec9e5
chore: clean up biome lint warnings — all non- intentional resolved
...
CI / check (push) Successful in 33s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m25s
- Remove 25 unused imports across 14 test files
- Remove 1 unused variable (rename with _ prefix)
- Fix 2 noBannedTypes (Function → (...args: unknown[]) => unknown)
- Fix 1 useTemplate lint (string concat → template literal in merge-config.cjs)
- Fix 1 useNodejsImportProtocol (merge-config.cjs)
- Fix 2 noTemplateCurlyInString (generate-drizzle-schema.mjs generator code)
- Auto-fix formatting + import sorting across modified files
- 221 remaining warnings: intentional noExplicitAny in prisma-facade.ts (Prisma compat layer)
- 0 tsc errors, 583 tests passing
2026-07-31 15:26:39 +02:00
openhands
beae86194d
fix: resolve biome lint errors in prisma-facade
...
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Failing after 1m23s
- Fix noPrecisionLoss on BIGINT UNSIGNED max value (2^64-1) with biome-ignore comments
- Fix noThenProperty on custom thenable with biome-ignore comment
- Auto-format remaining files (biome check --write)
- Re-stage auto-fixed files from previous commit
2026-07-31 14:17:06 +02:00
openhands
56061e41d4
refactor: replace Prisma ORM runtime with Drizzle ORM facade
...
CI / check (push) Failing after 12s
CI / deploy (push) Skipped
CI / release (push) Skipped
- Replace Prisma client runtime with Drizzle ORM (zero Prisma engine/query engine in production)
- Add Prisma-compatible facade (@/lib/prisma-facade.ts) backed by Drizzle for backwards compatibility
- Runtime queries route through Drizzle ORM; @prisma/client is now devDependency (types only)
- Remove @prisma/adapter-mariadb dependency; delete prisma-pool.ts and types/prisma.ts
- New Drizzle schema layer: src/db/schema.ts (176 tables) and src/lib/db.ts (connection)
- Update README documenting the dual-layer ORM architecture
- Restore src/generated/ gitignore (build artifact for local type generation)
- 0 TypeScript errors, 583 tests passing
The facade intentionally uses `any` types to match the Prisma Client API surface,
allowing existing code to run unmodified while routing queries through Drizzle at runtime.
2026-07-31 14:11:03 +02:00
openhands
91357aca3b
ci: fix Gitea Actions workflow
2026-07-30 17:51:24 +02:00
openhands
17847545dd
Improvements: remove dead config, fix ESM, add URL validation, unify types, add missing logging
...
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m52s
- Remove .prettierrc (dead config, Biome replaces Prettier)
- Rename lighthouserc.json to lighthouserc.cjs with module.exports for ESM compat
- Add logger.warn to empty catch blocks in auth, register, site-settings, prisma-cache, redis, security, rate-limit
- Unify ActionResult type: action-helper.ts uses 'ok' consistent with safe-action-shared.ts
- Add noUnusedLocals + noUnusedParameters to tsconfig + fix 25 pre-existing unused vars
- Replace barrel export src/types/index.ts with direct @/types/common imports
- Make trustHost conditional (development only) in auth.ts
- Add pre-flight URL validation to update-Nitrov3.sh to catch image.library.url misconfigurations
- Improve NITRO_IMAGE_LIBRARY_URL content validation in pre-flight & post-compute checks
2026-07-26 20:28:11 +02:00
openhands
1acace49d0
refactor: full codebase overhaul — dead code removal, env validation, logger migration, date consolidation, Prisma schema cleanup, button consistency, useEffect deps, test coverage
...
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 8s
- env.ts: added 10 missing Zod-validated env vars (imager, paypal currency, argon2/bcrypt params)
- Migrated 6 modules from process.env to validated env.* (auth, proxy-auth, paypal, password, redis, imager, moderation, alert, logger)
- Replaced console.warn/error with pino logger in 9 server-side modules
- Removed 50+ dead exports (SWF wrappers, coalesceHotelName, signIn, isStaff re-export, formatTimestamp, Skeleton/SkeletonCard, 4 unused housekeeping sections)
- Consolidated date formatting: 28 files migrated to shared formatDate() from @/lib/format-date
- Wired 4 radio/settings API routes through cached siteSettings service instead of raw Prisma queries
- Added getMany()/getAll() helpers to SiteSettings service
- Removed 88 dead Prisma model definitions (schema 2763→1846 lines)
- Created admin action-helper.ts with wrapAction() for standardized error handling
- Fixed useEffect dependency arrays in 4 data-heavy components
- Replaced raw btn CSS classes with shadcn Button component across admin pages
- Stripped dead i18n namespaces (common, pages.client) from all 22 translation files
- Removed 2 dead scripts (create-release.sh, check-local-imports.ts)
- Fixed knip.json configuration
- Added 7 new test suites: format-date, paypal, moderation, alert, webhook, action-helper, and fixed password.test.ts for env mocking
- All 358 tests passing across 72 test files
- TypeScript: 0 errors
2026-07-25 17:33:06 +02:00
openhands
f7f6e09174
Fix migration connection exhaustion and polish auth pages
...
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m49s
- apply-migrations.ts: use single shared connection instead of one per operation
- Increase MariaDB max_connections from 151 to 300 in server config
- home-login-form.tsx: replace hardcoded gray colors with theme variables
- register-form.tsx: add password strength meter, spinner, theme-aligned inputs
- login-form.tsx: add Discord/Google SVG icons, spinner, smoother 2FA animation
- page/register/login: apply premium animations (float, stagger, glow, gradient)
2026-07-24 11:30:58 +02:00
openhands
7eb3ba1ce8
feat: add create-release.sh for manual release creation
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m30s
2026-07-20 15:56:45 +02:00
Simo and Cursor
6b884ad25a
Harden deploy gates, prod AUTH_SECRET, and Sentry error reporting.
...
Local Build and Deploy / deploy (push) Successful in 1m42s
Align onlyBuiltDependencies with the workspace, fail fast without AUTH_SECRET in production, and delete catalog_items via VARCHAR-safe SQL so page deletes do not leave orphans.
Co-authored-by: Cursor <[email protected] >
2026-07-18 19:32:15 +02:00
openhands
0d82f1325e
Fix DB connect_timeout warning and remove deprecated Sentry disableLogger
Local Build and Deploy / deploy (push) Successful in 1m10s
2026-07-18 16:54:20 +02:00
Simo and Cursor
09f1bc2bd6
Add production observability: Sentry, pino, and sharp badge encoding.
...
Local Build and Deploy / deploy (push) Successful in 1m9s
Sentry is opt-in via DSN env vars; logger uses structured pino JSON in prod; badge uploads are normalized to GIF with sharp.
Co-authored-by: Cursor <[email protected] >
2026-07-17 23:09:57 +02:00
openhands
df38dccbf1
style: format code biome
Local Build and Deploy / deploy (push) Failing after 46s
2026-07-13 21:57:41 +02:00
openhands
187e008914
Add search to language switcher dropdown, remove translation script
Local Build and Deploy / deploy (push) Successful in 1m6s
2026-07-12 22:58:40 +02:00
openhands
6ddfcafa67
Fix placeholders in machine translations and add Russian translation
Local Build and Deploy / deploy (push) Successful in 54s
2026-07-12 22:37:52 +02:00
openhands
2e4ed76121
style: format code with prettier
Local Build and Deploy / deploy (push) Successful in 49s
2026-07-12 21:07:34 +02:00
remco
e85e4d74ea
revert fb8e77bb68
...
Local Build and Deploy / deploy (push) Successful in 1m11s
revert style: clean up code with prettier and eslint
2026-07-12 21:02:03 +02:00
openhands
fb8e77bb68
style: clean up code with prettier and eslint
2026-07-12 20:31:05 +02:00
Simo
d99b71a2d3
fix: make radio migrations safe for existing schemas
2026-07-11 22:18:45 +02:00
Simo
48ed1c20b6
fix: load environment for database migrations
2026-07-11 22:11:30 +02:00
Simo
c4454a292c
fix: parse SQL migration comments safely
2026-07-11 21:27:18 +02:00
Simo
5b4228261a
Reapply "Add missing admin action files and navigation links"
...
This reverts commit 4d515bc400 .
2026-07-11 20:52:56 +02:00
Simo
96ed768f14
test: add unresolved local import scanner
2026-07-11 20:52:55 +02:00
Simo
4d515bc400
Revert "Add missing admin action files and navigation links"
...
This reverts commit 41be6835bf .
2026-07-11 20:37:56 +02:00
openhands
41be6835bf
Add missing admin action files and navigation links
...
- Add 11 missing server action files: badges, bulk-users, catalog, catalog-bc, catalog-items, import-badges, import-furni, multi-account-detect, permissions, rooms, soundtracks
- Add missing admin navigation links: tickets, sounds, translations, import, radio sub-pages
- Add translation keys for all new navigation items
2026-07-11 12:01:05 +02:00
openhands
7e1ae17a3b
Add dotenv loading to migration script
2026-07-10 23:57:36 +02:00
openhands
818df3697b
Migrate from AES-256-CBC to AES-256-GCM for authenticated encryption
...
- Replace CBC+HMAC with GCM (built-in authentication via authTag)
- Remove createHmac and timingSafeEqual imports (no longer needed)
- Remove Snyk-ignore comments (no longer suppressible findings)
- Update test: tampered MAC test -> tampered auth tag test
- Add one-time migration script for existing CBC-encrypted 2FA secrets
2026-07-10 23:51:56 +02:00
openhands
942bc6fc8d
Security hardening, code quality, and ESLint setup
...
- Remove production DB dump (db_backup_*.sql) and update.log from git tracking
- Add DB backups to .gitignore
- Replace all console.log/console.error with structured logger module
- Translate Dutch error messages to English (link-discord.ts)
- Remove dead code blocks (register-form.tsx false && pattern)
- Add ESLint flat config with TypeScript, React, Next.js, jsx-a11y, and security plugins
- Add Prettier config
- Add eslint-plugin-security for security-aware linting
- Fix all 119+ ESLint warnings across the codebase:
- Resolve security/detect-object-injection with safe access patterns
- Resolve security/detect-non-literal-fs-filename with path traversal validation
- Replace <img> with next/image <Image> component
- Remove unused variables and imports
- Replace non-null assertions with proper type guards
- Replace <a> with <Link> for internal navigation
- Use next/script Script component for external scripts
- Fix setState-in-useEffect anti-patterns (navbar-color-picker, logo-generator, theme-switcher)
- Add lint and format scripts to package.json
All checks: typecheck ✓, tests 58/58 ✓, lint 0 errors 0 warnings ✓
2026-07-10 22:48:22 +02:00
openhands
c5db7f5156
fix: production hardening — migration script, security fixes, structured logging, API docs, component splitting
...
- Create apply-migrations.ts and jobs-worker.ts scripts (package.json references)
- Convert badge leaderboard from $queryRawUnsafe to $queryRaw with Prisma.sql templates
- Fix OAuth email binding: add oauth_require_link site setting, skip 2FA-protected accounts
- Add per-user 2FA rate limiting (5/30s) to prevent TOTP brute-force
- Add structured JSON logger with levels (debug/info/warn/error)
- Split 341-line HomePage into GuestView + UserView components
- Add OpenAPI v3.1 spec at /api/openapi.json
- Add LOG_LEVEL env var, regenerate Prisma client
- Add mysql2 dependency for migration scripts
- All 58 tests pass, typecheck clean
2026-07-08 13:06:02 +02:00
openhands
8a58bcb252
fix: restore word-level proxy for Habbo fonts, pre-cache all 175 fonts for 'Atom'
2026-07-03 17:58:56 +02:00
openhands
ac75f9c80a
feat: 100% self-hosted Habbo fonts - 6300 char GIFs + local canvas compositor, no habbofont.net dependency
2026-07-03 17:36:34 +02:00
openhands
00b1d0a267
feat: pre-cache all 175 font GIFs for default text 'Atom'
2026-07-03 17:28:16 +02:00