openhands
17847545dd
Improvements: remove dead config, fix ESM, add URL validation, unify types, add missing logging
...
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m52s
- Remove .prettierrc (dead config, Biome replaces Prettier)
- Rename lighthouserc.json to lighthouserc.cjs with module.exports for ESM compat
- Add logger.warn to empty catch blocks in auth, register, site-settings, prisma-cache, redis, security, rate-limit
- Unify ActionResult type: action-helper.ts uses 'ok' consistent with safe-action-shared.ts
- Add noUnusedLocals + noUnusedParameters to tsconfig + fix 25 pre-existing unused vars
- Replace barrel export src/types/index.ts with direct @/types/common imports
- Make trustHost conditional (development only) in auth.ts
- Add pre-flight URL validation to update-Nitrov3.sh to catch image.library.url misconfigurations
- Improve NITRO_IMAGE_LIBRARY_URL content validation in pre-flight & post-compute checks
2026-07-26 20:28:11 +02:00
openhands
d5e3bc7875
refactor: mark dead exports with TODO, deduplicate field sanitization, fix import placement
Local Build and Deploy / deploy (push) Successful in 1m36s
2026-07-20 14:47:05 +02:00
Simo and Cursor
0e89d03940
Finish fine-grained ACL across remaining admin pages and actions.
...
Local Build and Deploy / deploy (push) Successful in 56s
Replace leftover requireStaff gates with module PERMS, drop hardcoded room rank thresholds, and expand contract tests so admin mutations cannot regress to dashboard-only checks.
Co-authored-by: Cursor <[email protected] >
2026-07-15 20:15:22 +02:00
openhands
df38dccbf1
style: format code biome
Local Build and Deploy / deploy (push) Failing after 46s
2026-07-13 21:57:41 +02:00
openhands
8efd032cc6
style: format code with prettier agian
Local Build and Deploy / deploy (push) Failing after 49s
2026-07-13 21:41:52 +02:00
openhands
e5ae51bff7
Add NFC normalization to all FormData inputs across 41 server actions
...
Local Build and Deploy / deploy (push) Successful in 59s
All user-supplied string values from FormData now go through
String.prototype.normalize('NFC') to prevent Unicode homoglyph
attacks and canonicalization bypasses. NFC is idempotent for
already-normalized strings, so this is a pure security improvement
with zero behavioral change for legitimate users.
2026-07-13 12:21:37 +02:00
Simo
5b4228261a
Reapply "Add missing admin action files and navigation links"
...
This reverts commit 4d515bc400 .
2026-07-11 20:52:56 +02:00
Simo
4d515bc400
Revert "Add missing admin action files and navigation links"
...
This reverts commit 41be6835bf .
2026-07-11 20:37:56 +02:00
Simo
4a1e1115b3
Harden CMS security and theme contrast
2026-07-11 20:27:20 +02:00
openhands
41be6835bf
Add missing admin action files and navigation links
...
- Add 11 missing server action files: badges, bulk-users, catalog, catalog-bc, catalog-items, import-badges, import-furni, multi-account-detect, permissions, rooms, soundtracks
- Add missing admin navigation links: tickets, sounds, translations, import, radio sub-pages
- Add translation keys for all new navigation items
2026-07-11 12:01:05 +02:00
openhands
942bc6fc8d
Security hardening, code quality, and ESLint setup
...
- Remove production DB dump (db_backup_*.sql) and update.log from git tracking
- Add DB backups to .gitignore
- Replace all console.log/console.error with structured logger module
- Translate Dutch error messages to English (link-discord.ts)
- Remove dead code blocks (register-form.tsx false && pattern)
- Add ESLint flat config with TypeScript, React, Next.js, jsx-a11y, and security plugins
- Add Prettier config
- Add eslint-plugin-security for security-aware linting
- Fix all 119+ ESLint warnings across the codebase:
- Resolve security/detect-object-injection with safe access patterns
- Resolve security/detect-non-literal-fs-filename with path traversal validation
- Replace <img> with next/image <Image> component
- Remove unused variables and imports
- Replace non-null assertions with proper type guards
- Replace <a> with <Link> for internal navigation
- Use next/script Script component for external scripts
- Fix setState-in-useEffect anti-patterns (navbar-color-picker, logo-generator, theme-switcher)
- Add lint and format scripts to package.json
All checks: typecheck ✓, tests 58/58 ✓, lint 0 errors 0 warnings ✓
2026-07-10 22:48:22 +02:00
remco
0323c3fcaa
fix: improve error handling in admin pages to show user-friendly error messages
...
- Add error display to help questions new/edit pages
- Improve error visibility in admin-badges, admin-applications, admin-logs, admin-users pages
- Update createHelpQuestion action to properly handle and display unique name collisions and database errors
- Add user-friendly error messages to admin error handling
- Enhances admin page error reporting for better user experience
2026-07-01 21:25:30 +02:00
Simo
7daeccb832
Add dark mode, i18n, messenger/moderation/verify, admin CRUD parity
...
Web-tier features completing the AtomCMS→Next.js conversion (slice 2):
UI/UX:
- Dark mode: html.dark CSS-var overrides + ThemeSwitcher (localStorage,
no-flash boot script) wired into the nav.
- i18n (next-intl, cookie-based / no URL routing): en + it catalogs,
request.ts, provider in root layout, LanguageSwitcher; shell (nav,
header, footer) fully translated. URLs + access-guard unchanged.
- globals.css: --muted/--border aliases used across admin pages.
User features:
- /messages: offline messages + friend-request accept (server action
re-reads session, two directional rows, idempotent).
- Email verification: signed-token /verify route + sendVerification wired
into register (best-effort, never blocks signup).
- Article reactions: toggle UI on news/[slug] + server action.
- Content moderation service (website_wordfilter + optional OpenAI
moderations, fail-open) wired into article comments + guestbook.
Admin CRUD parity (Filament replacement):
- /admin/shop (+ new/[id]) packages CRUD + read-only orders.
- /admin/transactions read-only PayPal log.
- /admin/permissions, /admin/tags, /admin/ads (+ new/[id]),
/admin/help-questions (+ new/[id]), /admin/radio/history,
/admin/users/[id]/edit. All gated by requireStaff + logStaffActivity.
Verified: tsc 0, vitest 48/48, next build 0 (all routes incl. new
admin CRUD + /messages + /verify).
2026-06-28 16:06:42 +02:00