Commit Graph
85 Commits
Author SHA1 Message Date
openhands 1fd6f7146b fix: improve error handling for Cloudflare-protected clone sources
CI / check (push) Successful in 26s
CI / release (push) Skipped
CI / deploy (push) Successful in 54s
- Detect HTML responses from FlareSolverr and throw descriptive error
  instead of letting JSON.parse fail with cryptic 'Unexpected token' error
- Add try/catch to clone/route.ts GET handler to return 502 with
  clear message instead of Internal Server Error 500
- Add FLARESOLVERR_URL to .env
2026-08-04 19:21:31 +02:00
openhands 6fc14b9b84 feat: catalog audit can repair orphaned refs and duplicate classnames
- add repairOrphanedCatalog: remove catalog_items rows whose item_ids only
  reference missing items_base entries, strip orphaned ids from mixed rows
- add repairDuplicateClassnames: merge items_base duplicates into one
  canonical row per classname, remap references, delete duplicate rows
- add 'repair structural issues' checkbox + result display in audit UI
2026-08-03 18:08:45 +02:00
openhands 5308ce6a12 feat: parallelize audit repair and add nitro/SQL repair options
CI / check (push) Successful in 48s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m55s
- Parallelize icon and nitro downloads in the audit repair with a
  sliding-window worker pool (6 concurrent) to speed up large catalogs
- Add repairMissingNitros: fetch missing .nitro bundles from configured
  nitro sources (Wibbo default), validating each bundle before writing
- Add catalog-repair service: generate/apply catalog_items SQL for furni
  missing a catalog entry and repair FurnitureData.json (add missing +
  dedupe classnames)
- Wire all options through the audit API and client UI with live progress
  and result stats (icons, nitros, SQL, furnidata)
- Add Wibbo as default nitro source alongside existing icon sources
- Ignore runtime furni assets downloaded into public/ during repair
2026-08-02 19:12:28 +02:00
Simo c78f8812ad fix: use configured furni source and catalog assets 2026-08-02 14:22:05 +02:00
Simo b3245a18ea fix: bootstrap admin CSRF tokens
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 41s
2026-08-02 11:46:43 +02:00
openhands 22d455da7a fix(auth): drop nonexistent account_blocked column from login lookup
CI / check (push) Successful in 34s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m42s
getLoginUser selected users.account_blocked, which does not exist in the
DB (nor the Drizzle schema). Every credentials authorize() call threw a
SQL error -> NextAuth CallbackRouteError -> 'error=Configuration', so no
login could ever succeed. Remove the phantom column from the query and
LoginUser interface.

Also fix all remaining biome noNonNullAssertion / noExplicitAny lint
warnings so CI's check job (biome:lint) passes and the push deploy runs.
2026-08-01 17:38:43 +02:00
SimoandCursor 9c4949186c feat(admin): server-safe StatusCard and Import hub polish
CI / check (push) Failing after 8s
CI / release (push) Skipped
CI / deploy (push) Skipped
Split OnlineUsersWidget from StatusCard, decouple ad delete button, sync badge import to ExternalTexts+WebsiteBadges, add Import section hub with cancelable SSE jobs and upload SQL option.

Co-authored-by: Cursor <[email protected]>
2026-08-01 15:48:21 +02:00
SimoandCursor 725e1cb338 feat(ops): health-fail alerts, optional DB backup, admin UX polish
Wire jobs-worker health probes to Discord/email alerts with cooldown, optional mysqldump, rate-limit /api/health, mark-all-read alerts, ConfirmDialog on destructive admin actions, and raise coverage floors.

Co-authored-by: Cursor <[email protected]>
2026-08-01 15:25:47 +02:00
SimoandCursor 30b54e99e7 refactor(db): migrate app pages and APIs from Prisma facade to Drizzle (5)
Co-authored-by: Cursor <[email protected]>
2026-08-01 14:15:39 +02:00
SimoandCursor 9aa4f331bf refactor(db): migrate app pages and APIs from Prisma facade to Drizzle (4)
Co-authored-by: Cursor <[email protected]>
2026-08-01 14:15:36 +02:00
openhands 7f7971f578 fix: resolve all biome lint errors and type issues
CI / check (push) Successful in 30s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m26s
- Add file-level biome-ignore for noExplicitAny in prisma-facade.ts
  (intentional any for Prisma API compatibility surface)
- Fix noNonNullAssertion errors in cached-db.ts (redis null-guard fixes)
- Auto-fix formatting + organizeImports across modified files
- 0 tsc errors, 0 biome errors, 583 tests passing
2026-07-31 15:15:15 +02:00
openhands d1807ca814 perf: cache online API endpoints with Redis-first cache
CI / check (push) Successful in 31s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m27s
- Upgrade lib/cache.ts: Redis-first cached() with in-memory fallback
  (was in-memory only, broken across PM2 instances)
- Cache /api/online user list (10s TTL, was uncached per-request)
  eliminates DB query on every poll request
- Add uncached() invalidation helper for write-after-cache patterns
- 0 tsc errors, 583 tests passing
2026-07-31 15:09:56 +02:00
openhands beae86194d fix: resolve biome lint errors in prisma-facade
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Failing after 1m23s
- Fix noPrecisionLoss on BIGINT UNSIGNED max value (2^64-1) with biome-ignore comments
- Fix noThenProperty on custom thenable with biome-ignore comment
- Auto-format remaining files (biome check --write)
- Re-stage auto-fixed files from previous commit
2026-07-31 14:17:06 +02:00
openhands 56061e41d4 refactor: replace Prisma ORM runtime with Drizzle ORM facade
CI / check (push) Failing after 12s
CI / deploy (push) Skipped
CI / release (push) Skipped
- Replace Prisma client runtime with Drizzle ORM (zero Prisma engine/query engine in production)
- Add Prisma-compatible facade (@/lib/prisma-facade.ts) backed by Drizzle for backwards compatibility
- Runtime queries route through Drizzle ORM; @prisma/client is now devDependency (types only)
- Remove @prisma/adapter-mariadb dependency; delete prisma-pool.ts and types/prisma.ts
- New Drizzle schema layer: src/db/schema.ts (176 tables) and src/lib/db.ts (connection)
- Update README documenting the dual-layer ORM architecture
- Restore src/generated/ gitignore (build artifact for local type generation)
- 0 TypeScript errors, 583 tests passing

The facade intentionally uses `any` types to match the Prisma Client API surface,
allowing existing code to run unmodified while routing queries through Drizzle at runtime.
2026-07-31 14:11:03 +02:00
SimoandCursor 3ac5d6f4f6 chore(ops): strip redundant force-dynamic and probe Redis in ops health
CI / check (push) Successful in 25s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m8s
Co-authored-by: Cursor <[email protected]>
2026-07-30 21:33:40 +02:00
SimoandCursor 58fae1f90f feat(admin): analytics redis cache, shared ops health, ticket queue clarity
CI / check (push) Successful in 29s
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m25s
CI / deploy (push) Failing after 10s
Co-authored-by: Cursor <[email protected]>
2026-07-30 19:57:00 +02:00
openhands a513d9b7bd Migrate dependencies: bcrypt→@node-rs/argon2, sanitize-html→isomorphic-dompurify, remove nodemailer/next-view-transitions
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 27s
2026-07-28 19:03:04 +02:00
openhands 17847545dd Improvements: remove dead config, fix ESM, add URL validation, unify types, add missing logging
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m52s
- Remove .prettierrc (dead config, Biome replaces Prettier)
- Rename lighthouserc.json to lighthouserc.cjs with module.exports for ESM compat
- Add logger.warn to empty catch blocks in auth, register, site-settings, prisma-cache, redis, security, rate-limit
- Unify ActionResult type: action-helper.ts uses 'ok' consistent with safe-action-shared.ts
- Add noUnusedLocals + noUnusedParameters to tsconfig + fix 25 pre-existing unused vars
- Replace barrel export src/types/index.ts with direct @/types/common imports
- Make trustHost conditional (development only) in auth.ts
- Add pre-flight URL validation to update-Nitrov3.sh to catch image.library.url misconfigurations
- Improve NITRO_IMAGE_LIBRARY_URL content validation in pre-flight & post-compute checks
2026-07-26 20:28:11 +02:00
openhands 1acace49d0 refactor: full codebase overhaul — dead code removal, env validation, logger migration, date consolidation, Prisma schema cleanup, button consistency, useEffect deps, test coverage
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 8s
- env.ts: added 10 missing Zod-validated env vars (imager, paypal currency, argon2/bcrypt params)
- Migrated 6 modules from process.env to validated env.* (auth, proxy-auth, paypal, password, redis, imager, moderation, alert, logger)
- Replaced console.warn/error with pino logger in 9 server-side modules
- Removed 50+ dead exports (SWF wrappers, coalesceHotelName, signIn, isStaff re-export, formatTimestamp, Skeleton/SkeletonCard, 4 unused housekeeping sections)
- Consolidated date formatting: 28 files migrated to shared formatDate() from @/lib/format-date
- Wired 4 radio/settings API routes through cached siteSettings service instead of raw Prisma queries
- Added getMany()/getAll() helpers to SiteSettings service
- Removed 88 dead Prisma model definitions (schema 2763→1846 lines)
- Created admin action-helper.ts with wrapAction() for standardized error handling
- Fixed useEffect dependency arrays in 4 data-heavy components
- Replaced raw btn CSS classes with shadcn Button component across admin pages
- Stripped dead i18n namespaces (common, pages.client) from all 22 translation files
- Removed 2 dead scripts (create-release.sh, check-local-imports.ts)
- Fixed knip.json configuration
- Added 7 new test suites: format-date, paypal, moderation, alert, webhook, action-helper, and fixed password.test.ts for env mocking
- All 358 tests passing across 72 test files
- TypeScript: 0 errors
2026-07-25 17:33:06 +02:00
SimoandCursor 75cdfdebe4 fix(admin): P0 integrity — permanent bans, ACL sidebar, rank guards
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m36s
Co-authored-by: Cursor <[email protected]>
2026-07-22 19:01:59 +02:00
SimoandCursor e00e9ca2dc refactor: centralize hotel name fallback via FALLBACK_HOTEL_NAME
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m6s
Route all user-facing Atom hotel defaults through resolveHotelName (settings then HOTEL_NAME env then brand constant). Exclude Playwright e2e from tsconfig until deps are installed.

Co-authored-by: Cursor <[email protected]>
2026-07-22 18:45:59 +02:00
SimoandCursor 968ca15c27 feat: jwt cache, redis health, help-ticket admin, and write rate limits
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m33s
Cut Auth.js DB load with cached jwtVersion checks, surface Redis in /api/health and deploy warnings, add admin help-center ticket reply UI, rate-limit API tickets/reactions/referral claims, and revoke PATs on sign-out-everywhere.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:58:48 +02:00
SimoandCursor ed7db6e048 feat: public events/polls, friends graph, captcha, SSE hardening, and admin UX
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m55s
Ship product gaps: register/vote pages, friend add/accept/decline/remove, email verify TTL, captcha on login/forgot, soft-fail user actions, SSE abort/shared client, Commando Centrum error toasts, admin delete for events/polls, and IT/NL i18n fills.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:08:33 +02:00
SimoandCursor 2ff08e5127 chore: patch deps, CSP style nonces, otplib 13, and PR CI
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m35s
Co-authored-by: Cursor <[email protected]>
2026-07-21 20:46:02 +02:00
openhands bebd65c056 fix: refactor audit to SSE streaming, improve error handling
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m52s
- Changed from blocking JSON endpoint to SSE streaming (like sync-all/repair-icons)
- Progress updates during each audit phase with item counts
- Proper error handling with typed AuditEvent for every failure path
- AbortController support for the client
- Shows real-time progress for each check section
2026-07-21 15:33:15 +02:00
openhands 19e4e10b1d feat: add catalog audit page
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m56s
Checks for:
- items_base entries without catalog_items (not purchasable)
- catalog_items referencing non-existent items_base
- Items without .nitro or icon files on disk
- Duplicate classnames
- Items missing from all configured clone sources
2026-07-21 15:24:58 +02:00
openhands 90107c83d5 fix: rewrite repair-icons with proper error handling and progress
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m38s
- Wrap all DB/file operations in try-catch, send error events via SSE
- Report skipped/progress events for items that already have icons
- Add 'started' event with total count so the UI shows real-time progress
- Catch route-level errors and stream them instead of returning JSON
- Use log line content as React key instead of array index
2026-07-21 15:04:43 +02:00
openhands 804daeffca feat: add .nitro upload + sync-all + repair-icons features
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 32s
- Upload .nitro bundles directly with full DB, catalog, and furnidata integration
- Generate SQL migration files on upload (optional)
- Auto-sync missing furniture from all configured clone sources (SSE batch)
- Repair missing icons by extracting from local .nitro or downloading from sources
- All behind ASSETS_IMPORT permission
2026-07-21 14:53:26 +02:00
openhands 5e8a13a84f fix: resolve all biomaly lint errors and warnings across CMS
Deploy / release (push) Successful in 4s
Deploy / deploy (push) Skipped
- Fix CSS parser config (tailwindDirectives enabled)
- Fix noDangerouslySetInnerHtml via SanitizedHtml component
- Fix useExhaustiveDependencies in catalog-manager-dialog
- Fix noArrayIndexKey across 26 files (stable keys)
- Fix SVG a11y (titles, roles, aria-labels)
- Fix label/input associations (htmlFor/id pairs)
- Fix static element interactions (role + keyboard support)
- Fix noImgElement, noDescendingSpecificity (disabled - external Habbo URLs)
- Fix noNonNullAssertion, useTemplate, unused vars/imports
- Add SanitizedHtml shared component
- Migrate biome.json to 2.5.4 schema
2026-07-20 17:41:53 +02:00
openhands ccd4994028 feat: enable React Compiler, add Redis caching for API routes, update README with requirements and install guide
Local Build and Deploy / deploy (push) Failing after 57s
2026-07-20 14:14:49 +02:00
SimoandCursor 2de3696993 Enforce admin CSRF, harden catalog translate, use CMS hotel name for PayPal.
Local Build and Deploy / deploy (push) Successful in 1m38s
Mutating withAdmin routes now require a double-submit CSRF token; translate is capped at 500 items with audit logging; PayPal descriptions prefer siteSettings hotel_name.

Co-authored-by: Cursor <[email protected]>
2026-07-18 19:38:42 +02:00
openhands a07d438987 Improve media manager UI: search, delete, drag-and-drop, file meta
Local Build and Deploy / deploy (push) Successful in 1m21s
Add a richer media manager with filename search, per-file delete with
confirmation, drag-and-drop uploads, copy-URL feedback, file size/type/date
metadata, and server-side upload validation that returns errors to the UI.
Extend the /api/media listing with size and uploaded timestamps.
2026-07-18 17:29:01 +02:00
openhands 6a20ccda5c Fix media route cache-control to avoid Cloudflare stale caching
Local Build and Deploy / deploy (push) Successful in 1m6s
2026-07-18 17:21:00 +02:00
openhands 1bbbf6e5a4 Persist media uploads outside public/ to survive rebuilds and redeploys
Local Build and Deploy / deploy (push) Successful in 1m9s
Move media storage from public/assets/images/media to storage/media
(outside Git and public/), so uploaded images, favicons and logos are
preserved across rebuilds and git clean. Add a shared media-storage helper,
update the upload/serve actions and API routes, and gitignore storage/.
2026-07-18 17:04:48 +02:00
SimoandCursor 785c1b6976 Fix client bundle pulling Redis/Prisma via habbo gamedata hotel.
Local Build and Deploy / deploy (push) Successful in 54s
Keep hotel list helpers client-safe; load CMS setting only from a server module.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:30:46 +02:00
SimoandCursor d1baaf798a Add multi-hotel Habbo gamedata locale in CMS settings.
Local Build and Deploy / deploy (push) Failing after 33s
Furni name suggestions, import enrichment, and badge texts now follow habbo_gamedata_hotel instead of hardcoded habbo.it.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:28:18 +02:00
SimoandCursor 7bc0845932 Fix catalog items missing due to page_id VARCHAR mismatch.
Local Build and Deploy / deploy (push) Successful in 56s
Use raw SQL for counts/loads/creates/moves so Habbo DBs with VARCHAR page_id and no AUTO_INCREMENT still show and persist furni.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:21:49 +02:00
SimoandCursor 33a8a19820 Fix Visual Manager opacity and load categories like CatalogTree.
Local Build and Deploy / deploy (push) Successful in 55s
Use an opaque admin-canvas portal and lazy parentId fetches instead of mode=full, which fails on large catalogs. Search no longer loads the entire tree.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:09:01 +02:00
SimoandCursor 1d8efefce4 Fix Visual Manager empty categories: seed roots, harden tree API.
Local Build and Deploy / deploy (push) Successful in 56s
Seed root tabs from SSR, load the full tree without CLEAR_TREE races, coerce parent ids, and tolerate catalog_items page_id type mismatches so category pages actually appear.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:02:53 +02:00
SimoandCursor b52e25578d Harden catalog admin: fix translate/quick-add, RCON sync, and confirm UX.
Local Build and Deploy / deploy (push) Successful in 1m18s
Restore broken Quick Add search, correct Translate saves to items_base and FurnitureData, reparent page deletes, sync RCON on create/toggle/BC mutations, and replace native confirms/prompts with dialogs.

Co-authored-by: Cursor <[email protected]>
2026-07-17 21:12:58 +02:00
SimoandCursor 11d3cf31cc Restore missing catalog admin API routes so Visual Manager works.
Local Build and Deploy / deploy (push) Successful in 1m10s
Co-authored-by: Cursor <[email protected]>
2026-07-17 20:57:55 +02:00
SimoandCursor 49d204e85c Remove import/repair feature and related API routes.
Local Build and Deploy / deploy (push) Successful in 1m41s
Co-authored-by: Cursor <[email protected]>
2026-07-17 18:52:38 +02:00
openhands 19faa5615c Serve avatars from site's own /imaging endpoint instead of habbo.com
Local Build and Deploy / deploy (push) Successful in 1m7s
- Change default public imager URL from habbo.com to /imaging
- /imaging and /api/imaging/avatar now proxy from upstream (habbo.com) instead of redirecting
- Add resolveUpstreamBase() to separate public URL from upstream URL
- Update admin settings default and description
2026-07-15 22:23:09 +02:00
SimoandCursor 8cce8837bc Serve avatars from Habbo imager instead of broken self-hosted proxy.
Local Build and Deploy / deploy (push) Successful in 56s
Co-authored-by: Cursor <[email protected]>
2026-07-15 21:51:02 +02:00
SimoandCursor 9d4d409b77 Restore self-hosted /api/imaging/avatar (and badge) endpoints.
Local Build and Deploy / deploy (push) Successful in 54s
The clothing importer and imager helpers pointed at a missing route; proxy Habbo with disk/memory cache so avatars work again.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:41:18 +02:00
SimoandCursor 3403d3b19f Fix admin permissions bounce, prefixes APIs, and Italian UI leftovers.
Local Build and Deploy / deploy (push) Successful in 56s
Gate permissions on ACL manage + resolve super-admin from live user ranks, restore prefixes API routes, and anglicize hardcoded admin copy with nav i18n.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:33:00 +02:00
SimoandCursor f2427b3483 Harden admin ACL on critical write paths.
Local Build and Deploy / deploy (push) Successful in 54s
Gate translations, RCON, and user mutations on SETTINGS_EDIT, RCON_EXECUTE, and USERS_EDIT instead of dashboard/rank checks; redirect the legacy user-edit URL to the guarded canonical page.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:07:15 +02:00
openhands 59b63d6e70 Fix real Biome bugs: inner declarations, dup keys, assign-in-expr, implicit any, cookie, a11y svg/keyboard, json
Local Build and Deploy / deploy (push) Successful in 51s
2026-07-14 18:58:40 +02:00
openhands 045dc06a1f fix: resolve type errors and migrate pnpm settings to pnpm-workspace.yaml
Local Build and Deploy / deploy (push) Failing after 56s
- Move pnpm.onlyBuiltDependencies/overrides from package.json to pnpm-workspace.yaml (clears pnpm WARN)
- Allow useServerAction run() to accept actions returning void
- Make adminAction/authAction input optional so no-schema actions can be called without args
- Return ActionResult from updateBcPage
- Fix categoryPageMap value type (number | undefined)
- Declare DbService.queryCount field
- Use definite assignment for release in withFurniDataLock
- Narrow pair type in theme-contrast test
2026-07-13 22:10:50 +02:00
openhands df38dccbf1 style: format code biome
Local Build and Deploy / deploy (push) Failing after 46s
2026-07-13 21:57:41 +02:00