openhands
|
399c047515
|
fix: harden admin actions, search, sanitization and repo hygiene
CI / check (push) Successful in 1m21s
CI / deploy (push) Successful in 1m25s
- Split approve/dismiss application workflows with distinct audit logs,
rate-limited guards and real error logging
- Validate article status/date/id input and stop resetting publishedAt
on every update
- Validate guild updates (state, forum enums, non-empty name) behind
rate-limited guard
- Fix scheduled-article publishing (ignore NULL dates, set updatedAt,
type-safe predicates)
- Harden admin search API (LIKE escaping, query cap, per-user
rate limit, round-robin result cap) and fix search dialog
abort/res.ok/loading races
- Lock down HTML sanitizer to an allowlist profile and add XSS tests
- Improve mobile nav accessibility (unique id, dialog role, focus
management, scroll lock, outside close)
- Log swallowed server errors instead of silent catch blocks
- Remove dead eslint config, drop unused dompurify deps, restore knip
CI step, add Playwright config with smoke spec
|
2026-09-04 13:04:08 +02:00 |
|
openhands
|
30c95b1a5c
|
feat: comprehensive CMS improvements
CI / runtime-diagnostics (push) Skipped
CI / release (push) Skipped
CI / check (push) Failing after 0s
CI / deploy (push) Skipped
- Fix DOMPurify SSR crash (use isomorphic-dompurify)
- Fix SanitizedHtml to sanitize by default
- Add auth guards to studio/catalog maintenance pages
- Add update/edit to vouchers CRUD
- Add update/edit to rare-values CRUD
- Add approve workflow to applications page
- Add edit form to guilds detail page
- Add SEO metadata to all public pages (21 pages)
- Fix mobile nav accessibility (focus trap, aria attributes)
- Fix missing labels and table accessibility
- Add dynamic imports for heavy client components (6 components)
- Fix silent error swallowing (40+ locations)
- Add content scheduling for articles (publishAt, status)
- Wire up 12 missing webhook notification triggers
- Add global search to admin panel
- Add bulk actions to admin users table
- Fix JSON formatting and a11y issues
|
2026-09-03 16:00:32 +02:00 |
|
Simo
|
b1ddda66ff
|
Revert "Merge pull request 'Complete Housekeeping migration and /ase cutover' (#52) from codex/housekeeping-complete into main"
CI / check (push) Successful in 27s
CI / release (push) Skipped
CI / deploy (push) Successful in 43s
This reverts commit 488b6e57c4, reversing
changes made to b506b4499a.
|
2026-08-30 21:31:34 +02:00 |
|
Simo
|
2b8f73a91d
|
feat(housekeeping): cut over administration to ase
|
2026-08-30 20:35:22 +02:00 |
|
Simo
|
91c9efcbb4
|
fix(housekeeping): complete people workflow fidelity
|
2026-08-29 14:39:38 +02:00 |
|
Simo
|
25b76437ff
|
fix(housekeeping): harden people account workflows
|
2026-08-29 13:13:04 +02:00 |
|
Simo
|
e1b31ff773
|
feat(housekeeping): deliver people account workflows
|
2026-08-29 11:45:50 +02:00 |
|
 SimoandCursor
|
ed9c23c702
|
refactor(db): migrate staff and app actions from Prisma facade to Drizzle
Co-authored-by: Cursor <[email protected]>
|
2026-07-31 21:35:05 +02:00 |
|
openhands
|
17847545dd
|
Improvements: remove dead config, fix ESM, add URL validation, unify types, add missing logging
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m52s
- Remove .prettierrc (dead config, Biome replaces Prettier)
- Rename lighthouserc.json to lighthouserc.cjs with module.exports for ESM compat
- Add logger.warn to empty catch blocks in auth, register, site-settings, prisma-cache, redis, security, rate-limit
- Unify ActionResult type: action-helper.ts uses 'ok' consistent with safe-action-shared.ts
- Add noUnusedLocals + noUnusedParameters to tsconfig + fix 25 pre-existing unused vars
- Replace barrel export src/types/index.ts with direct @/types/common imports
- Make trustHost conditional (development only) in auth.ts
- Add pre-flight URL validation to update-Nitrov3.sh to catch image.library.url misconfigurations
- Improve NITRO_IMAGE_LIBRARY_URL content validation in pre-flight & post-compute checks
|
2026-07-26 20:28:11 +02:00 |
|
 SimoandCursor
|
0e89d03940
|
Finish fine-grained ACL across remaining admin pages and actions.
Local Build and Deploy / deploy (push) Successful in 56s
Replace leftover requireStaff gates with module PERMS, drop hardcoded room rank thresholds, and expand contract tests so admin mutations cannot regress to dashboard-only checks.
Co-authored-by: Cursor <[email protected]>
|
2026-07-15 20:15:22 +02:00 |
|
openhands
|
df38dccbf1
|
style: format code biome
Local Build and Deploy / deploy (push) Failing after 46s
|
2026-07-13 21:57:41 +02:00 |
|
Simo
|
4a1e1115b3
|
Harden CMS security and theme contrast
|
2026-07-11 20:27:20 +02:00 |
|
Simo
|
e96b606e1e
|
Add remaining public + admin pages (parallel build, 26 files)
Built via two parallel agent workflows reading the real Prisma schema, then
integrated + verified.
Public: /shop (categories + storefront), /community hub, /rankings (top by
credits), /staff, /photos (camera_web gallery), /help (categories + rules),
/help/tickets (auth-gated user tickets + create), /settings (auth-gated, update
motto via RCON).
Admin: /admin/catalog (+[id] items), /admin/radio (shouts/apps/schedules +
delete shout), /admin/teams (CRUD), /admin/permissions (read), /admin/wordfilter
(CRUD + RCON push), /admin/ip (whitelist/blacklist CRUD), /admin/applications
(list + dismiss), /admin/logs (chat/command/alert read), /admin/achievements
(read). Server actions all staff-gated.
Header + admin nav extended. Verified: tsc exit 0, vitest 48/48, next build
exit 0 (33 routes); curl-probed every route — public 200/<main>, auth+admin
correctly 307-redirect when unauthorized.
|
2026-06-28 13:24:55 +02:00 |
|