Simo and Cursor
255c09b9fd
fix(admin): restore sidebar categories via ACL grant repair
...
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m49s
Co-authored-by: Cursor <[email protected] >
2026-07-22 21:47:23 +02:00
Simo and Cursor
75cace41ea
feat(mod): tickets+team tabs; retire HK writes for live ACL
...
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 30s
Co-authored-by: Cursor <[email protected] >
2026-07-22 21:35:35 +02:00
Simo and Cursor
084cca6ea4
feat(mod): lite /mod panel + clarify ACL vs housekeeping legacy
...
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m31s
Co-authored-by: Cursor <[email protected] >
2026-07-22 21:29:32 +02:00
Simo and Cursor
f150aea8b9
feat(admin): P1 — clearer tickets labels, pagination, min_staff_rank, analytics errors
...
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m37s
Co-authored-by: Cursor <[email protected] >
2026-07-22 19:04:45 +02:00
openhands
d5e3bc7875
refactor: mark dead exports with TODO, deduplicate field sanitization, fix import placement
Local Build and Deploy / deploy (push) Successful in 1m36s
2026-07-20 14:47:05 +02:00
Simo and Cursor
3c8a8ff888
Extend fine-grained ACL to settings, content, shop, and radio.
...
Local Build and Deploy / deploy (push) Successful in 54s
Gate pages and mutations on module PERMS instead of dashboard-only staff checks, add radio view/edit slugs with migration 0015, and expand the operations contract tests.
Co-authored-by: Cursor <[email protected] >
2026-07-15 20:11:55 +02:00
Simo and Cursor
f2427b3483
Harden admin ACL on critical write paths.
...
Local Build and Deploy / deploy (push) Successful in 54s
Gate translations, RCON, and user mutations on SETTINGS_EDIT, RCON_EXECUTE, and USERS_EDIT instead of dashboard/rank checks; redirect the legacy user-edit URL to the guarded canonical page.
Co-authored-by: Cursor <[email protected] >
2026-07-15 20:07:15 +02:00
openhands
df38dccbf1
style: format code biome
Local Build and Deploy / deploy (push) Failing after 46s
2026-07-13 21:57:41 +02:00
openhands
8efd032cc6
style: format code with prettier agian
Local Build and Deploy / deploy (push) Failing after 49s
2026-07-13 21:41:52 +02:00
openhands
f6ad030c5b
Add EpicNext CMS foundation layer and fix critical security gaps
...
Local Build and Deploy / deploy (push) Successful in 1m1s
- Create src/lib/foundation/ (860 LOC, 9 files): typed action wrappers,
DbService with health checks, CSRF validation, safe redirects,
AsyncLocalStorage request tracing, branded types, reusable Zod schemas
- Migrate moderation.ts and user-settings.ts to foundation patterns
- Fix abuse-guard.ts: bound in-memory Maps with LRU eviction (was unbounded)
- Fix access-guard.ts: separate try/catch per check, log degradation
instead of blanket fail-open
- Replace raw redirect() calls with safeRedirect() in guard.ts and
permissions.ts to prevent open-redirect attacks
- Add CSRF validation to api-handler.ts for mutating methods
- Add canonicalizeFormData() utility for FormData input sanitization
2026-07-13 12:03:49 +02:00
openhands
2e4ed76121
style: format code with prettier
Local Build and Deploy / deploy (push) Successful in 49s
2026-07-12 21:07:34 +02:00
remco
e85e4d74ea
revert fb8e77bb68
...
Local Build and Deploy / deploy (push) Successful in 1m11s
revert style: clean up code with prettier and eslint
2026-07-12 21:02:03 +02:00
openhands
fb8e77bb68
style: clean up code with prettier and eslint
2026-07-12 20:31:05 +02:00
Simo
667ec9af4c
test: define acl and import backend contracts
2026-07-12 19:01:28 +02:00
Simo
7d3430aeca
fix: seed production ACL permissions
Local Build and Deploy / deploy (push) Successful in 56s
2026-07-12 14:29:01 +02:00
Simo
f08e56cf53
fix: authorize super admins by dynamic highest rank
Remote Build and Deploy / deploy (push) Successful in 42s
2026-07-11 22:35:40 +02:00
Simo
b695a33ead
fix: enforce public contrast and audit rank errors
2026-07-11 22:06:45 +02:00
Simo
4a1e1115b3
Harden CMS security and theme contrast
2026-07-11 20:27:20 +02:00
openhands
5c638cd6bc
perf: add bans.user_id index, Redis cache layer, rate-limit improvements, radio contest/giveaway columns, and tests
...
- Add DB index on bans.user_id to speed up per-request ban lookups (migration 0008)
- Replace in-process rate limiter with Redis-backed implementation with in-memory fallback
- Add Redis caching layer for site settings with TTL invalidation (migration 0009)
- Add rate limiting to resetPassword to prevent token brute-force attacks
- Update all rateLimit callers to await the now-async function
- Flesh out RadioContests and RadioGiveaways models with title, description, prize, date, and winner columns
- Update radio contest/giveaway pages to display new fields
- Add tests for rate limiter (4 tests) and password-reset actions (3 tests)
- Add REDIS_URL environment variable (optional, falls back to in-memory)
2026-07-08 12:49:24 +02:00
openhands
5628e7d6b7
Security hardening: 12 improvements across the stack
...
1. env.ts: APP_KEY placeholder detection with validation
2. schema.prisma: password column widened to varchar(255) for argon2id
3. auth.ts: trustHost restricted to development only
4. next.config.ts: added CSP, HSTS, X-Frame-Options, and other security headers
5. api.ts: CORS restricted to APP_URL instead of wildcard
6. register-form.tsx: migrated from REST API fetch to server action (useActionState)
7. twofactor.ts + 2fa page: TOTP recovery codes (8 one-time codes, generated and displayed)
8. register.ts: password min length 8 + complexity requirements (upper, lower, digit)
9. register.ts + help-tickets.ts + radio-shouts.ts: Zod schema validation
10. rate-limit.ts: improved periodic cleanup with aggressive eviction at 10k buckets
11. guard.ts + admin actions: rate-limited admin actions (30 req/min per staff)
12. help-tickets.ts + radio-shouts.ts: content moderation via moderateOrThrow
2026-07-04 18:52:00 +02:00
Simo
9f81096f05
Add admin foundation + Users resource (Filament replacement, slice 1)
...
Plain App Router admin (aligned to habbo-next, no Refine):
- rank surfaced on the NextAuth session; staff guard isStaff() [pure,
unit-tested] + requireStaff() reading min_staff_rank, gating /admin.
- /admin dashboard (counts), /admin/users (paginated + search),
/admin/users/[id] detail.
- src/actions/admin-users.ts: staff-gated server actions wiring the user editor
to the existing services — giveCurrency (RCON or DB fallback), setMotto/setRank
(DB + RCON), alertUser, disconnectUser.
Verified: tsc exit 0, vitest 45/45, next build exit 0 (/admin routes).
2026-06-27 16:51:47 +02:00