Commit Graph
34 Commits
Author SHA1 Message Date
openhands 3527cbd34f Add AUTH_URL to env example 2026-07-04 20:06:21 +02:00
openhands c9d951aa86 Fix login CSP and auth host trust 2026-07-04 20:04:44 +02:00
openhands 83d1483ecd [skip ci] Remove CI workflow 2026-07-04 19:50:42 +02:00
openhands d5f5e0a973 Revert "Remove CI workflows (no Gitea runner available)"
CI / check (push) Has been cancelled
This reverts commit 55175b5332.
2026-07-04 19:49:40 +02:00
openhands 55175b5332 Remove CI workflows (no Gitea runner available) 2026-07-04 19:48:44 +02:00
openhands 8bcbc501ba Performance, SEO, a11y, and code quality improvements
CI / check (push) Has been cancelled
1. Performance: 25 pages switched from force-dynamic to revalidate=300 (ISR);
   2 pages (community, developers) now fully static (SSG)
2. DB indexes: Added @@index on foreign keys for WebsiteArticles,
   WebsiteArticleReactions, WebsiteArticleComments, WebsiteHelpCenterTickets,
   WebsiteShopArticles, RadioSongRequests, StaffActivities
3. SEO: Added robots.ts, sitemap.ts, canonical URLs, Open Graph + Twitter
   Card metadata on root layout and news articles
4. A11Y: Replaced <details>/<summary> dropdowns with accessible button-based
   NavDropdown (aria-expanded, aria-haspopup, role=menu). MobileNav now
   uses translated aria-label, aria-expanded, aria-controls, role=menu
5. Code quality: Added try/catch to updateArticle/deleteArticle; deleteArticle
   now uses prisma. for atomicity
6. CI/CD: Added GitHub Actions workflow (typecheck + test)
7. i18n: Added openMenu/closeMenu keys to all 6 locales
8. Observability: Health endpoint now checks SMTP reachability when configured
9. Loading states: Added loading.tsx for root, admin, and news sections
10. Word filter cache: Added 60s TTL auto-refresh instead of manual cache bust
2026-07-04 19:41:04 +02:00
openhands 10523e58ce Fix remaining security vulnerabilities
- H1: Add missing sanitize() to help center content rendering
- H2: Tighten CSP by removing unsafe-inline/unsafe-eval from script-src;
  move theme init to external JS file with meta tag for defaultDark
- M1: Add SSRF protection for radio API URLs (block private IPs)
- M2: Add rate limiting to SSO ticket endpoint (5 req/30s per user)
- M4: Document locale validation safety in i18n dynamic import
- L1: Truncate stacktraces in admin commandocentrum to first 20 lines
2026-07-04 19:10:43 +02:00
openhands 5628e7d6b7 Security hardening: 12 improvements across the stack
1. env.ts: APP_KEY placeholder detection with validation
2. schema.prisma: password column widened to varchar(255) for argon2id
3. auth.ts: trustHost restricted to development only
4. next.config.ts: added CSP, HSTS, X-Frame-Options, and other security headers
5. api.ts: CORS restricted to APP_URL instead of wildcard
6. register-form.tsx: migrated from REST API fetch to server action (useActionState)
7. twofactor.ts + 2fa page: TOTP recovery codes (8 one-time codes, generated and displayed)
8. register.ts: password min length 8 + complexity requirements (upper, lower, digit)
9. register.ts + help-tickets.ts + radio-shouts.ts: Zod schema validation
10. rate-limit.ts: improved periodic cleanup with aggressive eviction at 10k buckets
11. guard.ts + admin actions: rate-limited admin actions (30 req/min per staff)
12. help-tickets.ts + radio-shouts.ts: content moderation via moderateOrThrow
2026-07-04 18:52:00 +02:00
openhands a1950e5b65 fix: correct sprite font vertical offset and use avg char width fallback 2026-07-03 18:37:05 +02:00
openhands 77ae4838c0 feat: 100% self-hosted Habbo fonts via sprite sheets + client-side compositor 2026-07-03 18:22:30 +02:00
openhands 8a58bcb252 fix: restore word-level proxy for Habbo fonts, pre-cache all 175 fonts for 'Atom' 2026-07-03 17:58:56 +02:00
openhands ac75f9c80a feat: 100% self-hosted Habbo fonts - 6300 char GIFs + local canvas compositor, no habbofont.net dependency 2026-07-03 17:36:34 +02:00
openhands 00b1d0a267 feat: pre-cache all 175 font GIFs for default text 'Atom' 2026-07-03 17:28:16 +02:00
openhands a5110a62dc feat: add download-all-fonts ZIP button, proxy fonts locally via /api/font 2026-07-03 17:25:55 +02:00
openhands d5ec7ba0f8 feat: self-host all Habbo fonts via proxy route /api/font/[style]/[text] 2026-07-03 17:21:05 +02:00
openhands f3367e9b7b feat: save logos to media/logo/ subdir, add Logo generator link to admin dropdown 2026-07-03 17:14:44 +02:00
openhands 917437c5ef fix: use server-side fetch for logo save (bypass CORS), detect file MIME on extension 2026-07-03 17:05:25 +02:00
openhands 6df4fe2ddd chore: remove stale test logos 2026-07-03 17:00:41 +02:00
openhands 073f8e1b6a fix: detect actual MIME type for save-logo extension instead of hardcoded png 2026-07-03 17:00:08 +02:00
openhands a84cbfa4f0 feat: add all 191+ Habbo fonts from habbofont.net to logo generator 2026-07-03 16:55:59 +02:00
openhands af2d5b4943 feat: add save as site logo button to logo generator 2026-07-03 16:45:43 +02:00
openhands 98506fea1e feat: add Habbo pixel font to logo generator, revert site-header toggle 2026-07-03 16:35:54 +02:00
openhands 4f79d5a0ae feat: add pixel font for hotel name, toggle text/logo on click in site header 2026-07-03 16:31:17 +02:00
openhands 01e7f84d18 feat: append '- Hotel' to hotel name in title bar, site header and client header 2026-07-03 16:22:42 +02:00
openhands 187af2e147 fix: strip existing sso param from clientUrl, add aria roles to dropdowns, add x-pathname fallback, move .dropdown-menu into @layer components 2026-07-03 16:17:42 +02:00
openhands 7e616ca6b3 refactor: extract duplicate header into shared renderHeader function 2026-07-03 16:05:56 +02:00
openhands 98c9b951c4 fix: remove duplicate site-bg, handle fullscreen promise rejection, unify tooltip language, improve dropdown CSS compat and accessibility 2026-07-03 16:03:09 +02:00
openhands e5b0649bf1 fix: remove debug console.log from root layout 2026-07-03 15:51:33 +02:00
openhands 7e5813bd97 Fix client loading as atomcms normal 2026-07-03 15:16:47 +02:00
openhands bedf0ee7fa chore: update nodemailer to latest, revert otplib to v12 due to breaking changes 2026-07-02 17:39:48 +02:00
openhands 1b4930af0b chore: add uploaded media files 2026-07-02 17:28:24 +02:00
openhands 518c072491 refactor: convert admin pages to Tailwind and improve media uploads; fix TypeScript error in commandocentrum 2026-07-02 17:26:16 +02:00
openhands 72ef74fc87 refactor: enhance admin panel styling with better card patterns
- Dashboard: use admin-card for sections, refine progress bars and action badges
- Applications: enhanced card styling with p-3 and better text hierarchy
- Emulator: convert remaining 'card' classes to 'admin-card'
- All changes eliminate inline styles and use consistent Tailwind patterns

Co-authored-by: openhands <[email protected]>
2026-07-02 16:27:06 +02:00
openhands 928544100b Convert admin pages to new Tailwind design pattern
- Replace 'card' class with 'admin-card' (gradient cards, dark mode support)
- Replace 'muted' class with consistent Tailwind muted states
- Standardize page headers with gradient backgrounds and Lucide icons
- Convert all inline styles to Tailwind classes
- Add admin-page CSS helpers (admin-card, admin-filter-bar, admin-section-title)
- Apply pattern to all 42 admin pages (was only 6 before)
- Zero TypeScript errors, production builds successfully

Co-authored-by: openhands <[email protected]>
2026-07-02 16:05:35 +02:00