Category headers toggle open/closed; state is stored in localStorage and the active route group stays expanded.
Co-authored-by: Cursor <[email protected]>
Il layout admin non deve crashare se cookies().set() fallisce (__Host-/Secure dietro proxy). Fallback su csrf-token, meta solo con token valido.
Co-authored-by: Cursor <[email protected]>
Wire orphan routes into hub tabs, group Radio into primary/tools rows, show theme/language once on desktop, and remove duplicate page titles under AdminHubChrome.
Co-authored-by: Cursor <[email protected]>
Reuse ThemeSwitcher with an admin variant (Sun/Moon) next to the staff profile and in the housekeeping header.
Co-authored-by: Cursor <[email protected]>
Replace the long flat nav with hub entries, shared AdminHubChrome tabs, and AdminPageShell. Existing URLs stay stable; Settings/Radio and other sections now share one chrome.
Co-authored-by: Cursor <[email protected]>
Derive admin/public text colors from WCAG contrast, unify ThemeVars CSS emission, and keep navbar overrides in sync with readable vars.
Co-authored-by: Cursor <[email protected]>
Gate permissions on ACL manage + resolve super-admin from live user ranks, restore prefixes API routes, and anglicize hardcoded admin copy with nav i18n.
Co-authored-by: Cursor <[email protected]>
- Strong, obvious active state: accent-tinted background, bold text,
accent icon and left accent border so the current section is unmistakable
- Inactive items stay fully readable (white on dark) with a clear hover
- Separate nav sections with dividers and bolder uppercase headers
- Fix invisible mobile hamburger hover (bg-black/10 -> accent tint)
- Remap shared shadcn semantic tokens (--color-primary, --color-popover,
--color-card, --color-border, --color-ring, --color-muted-foreground,
--color-destructive, ...) onto the admin palette for any page scoped with
body:has([data-admin]); this themes every embedded Button, Badge, Input,
Select, Card, Table, Tabs, Dialog, Switch, Checkbox with the admin theme
and guaranteed contrast, without editing component files. Gated so the
public site is untouched and Radix portals (dialogs/selects) are covered.
- Tag the admin layout/sidebar with data-admin and give the admin content
area the admin canvas background so the whole HK is one cohesive dark UI.
- Fix hardcoded colors in catalog shop preview and favicon form to use
admin variables; fix white text on a light warning tint (low contrast).
- Remove production DB dump (db_backup_*.sql) and update.log from git tracking
- Add DB backups to .gitignore
- Replace all console.log/console.error with structured logger module
- Translate Dutch error messages to English (link-discord.ts)
- Remove dead code blocks (register-form.tsx false && pattern)
- Add ESLint flat config with TypeScript, React, Next.js, jsx-a11y, and security plugins
- Add Prettier config
- Add eslint-plugin-security for security-aware linting
- Fix all 119+ ESLint warnings across the codebase:
- Resolve security/detect-object-injection with safe access patterns
- Resolve security/detect-non-literal-fs-filename with path traversal validation
- Replace <img> with next/image <Image> component
- Remove unused variables and imports
- Replace non-null assertions with proper type guards
- Replace <a> with <Link> for internal navigation
- Use next/script Script component for external scripts
- Fix setState-in-useEffect anti-patterns (navbar-color-picker, logo-generator, theme-switcher)
- Add lint and format scripts to package.json
All checks: typecheck ✓, tests 58/58 ✓, lint 0 errors 0 warnings ✓
- Add lucide-react for SVG icons throughout the admin
- Redesign sidebar with gradient background, icons per nav item, and sticky layout
- Redesign topbar with cleaner user info display
- Redesign dashboard with icon-backed stat cards, gradient progress bars, activity feed
- Update AdminNavLink with icon support and new active state styling
- Improve table styling in admin-page CSS (rounded corners, hover, spacing)
- Clean up unused admin CSS
Built the admin tools previously listed as missing:
- Badge upload (/admin/badges): uploads a <code>.gif into the emulator's
badge dir via BADGE_UPLOAD_DIR (node:fs); validated code/type/size,
logged. Made configurable rather than skipped.
- Radio tools: /admin/radio/api-keys (CRUD, server-generated keys),
/admin/radio/autodj (Auto-DJ playlist CRUD), /admin/radio/embed (embed
snippet generator), /admin/radio/points (points settings),
/admin/radio/monitoring (live stream/now-playing/listeners status).
radio_api_keys + radio_auto_dj_playlist already had real columns.
- /admin/vpn: VPN/proxy detection config (block toggle + provider + key),
complementing /admin/ip's raw blacklist.
- Writeable boxes: new website_writeable_boxes table (model + migration
0006) + /admin/writeable-boxes CRUD; active boxes render on the public
home page. env: BADGE_UPLOAD_DIR.
Verified live (prod, amx_test): all 8 pages render with real data; a test
writeable box appeared on the public home and was reverted. tsc 0,
vitest 49/49, next build 0 (7 new admin routes).
- New /admin/theme: recolour the whole site from housekeeping. 6 atom-
faithful presets (Atom/Midnight/Ocean/Forest/Sunset/Candy) + per-colour
pickers for the 12 settings ThemeVars injects + border radius. Writes to
website_settings, busts the siteSettings cache, and revalidates the
layout so the new palette applies live with no rebuild. Constants live
in src/lib/theme-presets.ts (a "use server" file can't export objects).
Added to the admin sidebar (System).
- radio/contests/[id] + giveaways/[id] wrapped in ContentCard to match
the public design system.
- Skipped a separate VPN page: /admin/ip already manages the IP
white/blacklist, so it would only duplicate it.
Verified live (prod, amx_test): applied the Ocean preset → home renders
--color-primary #0ea5e9 site-wide; reverted the test rows. tsc 0,
vitest 49/49, next build 0.
The admin pages used bare inline-styled tables on the default page
background. Rebuilt the admin shell + added a scoped .admin CSS layer so
the whole panel matches the original AtomCMS Filament look:
- Dark #2d2d44 sidebar (the AtomCMS admin navbar colour) with the nav
grouped into Overview / Content / Users & access / Economy / Radio /
System (mirrors the Filament resource groups), an avatar + rank badge
header, and amber active-link highlighting via a client AdminNavLink
(usePathname).
- A topbar ("Housekeeping" + signed-in user) over a light content area.
- Carded tables (surface bg, rounded, shadow, tinted header, row hover)
and a page-title treatment, applied globally so every admin page is
styled without per-page edits.
Verified in a real authenticated admin session (production server,
amx_test): sidebar renders #2d2d44 sticky, active link amber on dark
text, /admin/users table carded with 7 real rows; dev server serves the
admin rules after a cache refresh. tsc 0, vitest 49/49, next build 0.
Security (launch blockers):
- src/middleware.ts (edge): forwards x-pathname + real client IP.
- access-guard.ts (Node, from root layout): routes non-staff to /maintenance
when maintenance mode is on, banned users to /banned. New /banned + /maintenance
pages (the consumers the admin toggle was missing). Admin layout enforces
force_staff_2fa before /admin.
- staff-activity.ts audit log wired into ban/lift/give-currency/set-rank actions.
Infra (parallel agents): alert service (alert_logs + Discord embed + email),
PayPal top-up (create/capture API routes + /shop/topup), cron worker
(scripts/jobs-worker.ts via croner: emulator-ping->alert, maintenance-check,
bans-cleanup), social connections page, admin radio settings/banners/ranks.
Public radio subsystem: /radio (+schedule, shouts+post, contests, giveaways,
apply, leaderboard) and /apply/staff + /apply/team submission forms. Radio nav
link added. .env.example documents the new optional vars.
(radio song-requests dropped: its table is a stub in AtomCMS — columns added by
un-modeled alter-migrations.)
Verified: tsc exit 0, vitest 48/48, next build exit 0 (82 page routes).