openhands
3527cbd34f
Add AUTH_URL to env example
2026-07-04 20:06:21 +02:00
openhands
c9d951aa86
Fix login CSP and auth host trust
2026-07-04 20:04:44 +02:00
openhands
83d1483ecd
[skip ci] Remove CI workflow
2026-07-04 19:50:42 +02:00
openhands
d5f5e0a973
Revert "Remove CI workflows (no Gitea runner available)"
...
CI / check (push) Has been cancelled
This reverts commit 55175b5332 .
2026-07-04 19:49:40 +02:00
openhands
55175b5332
Remove CI workflows (no Gitea runner available)
2026-07-04 19:48:44 +02:00
openhands
8bcbc501ba
Performance, SEO, a11y, and code quality improvements
...
CI / check (push) Has been cancelled
1. Performance: 25 pages switched from force-dynamic to revalidate=300 (ISR);
2 pages (community, developers) now fully static (SSG)
2. DB indexes: Added @@index on foreign keys for WebsiteArticles,
WebsiteArticleReactions, WebsiteArticleComments, WebsiteHelpCenterTickets,
WebsiteShopArticles, RadioSongRequests, StaffActivities
3. SEO: Added robots.ts, sitemap.ts, canonical URLs, Open Graph + Twitter
Card metadata on root layout and news articles
4. A11Y: Replaced <details>/<summary> dropdowns with accessible button-based
NavDropdown (aria-expanded, aria-haspopup, role=menu). MobileNav now
uses translated aria-label, aria-expanded, aria-controls, role=menu
5. Code quality: Added try/catch to updateArticle/deleteArticle; deleteArticle
now uses prisma. for atomicity
6. CI/CD: Added GitHub Actions workflow (typecheck + test)
7. i18n: Added openMenu/closeMenu keys to all 6 locales
8. Observability: Health endpoint now checks SMTP reachability when configured
9. Loading states: Added loading.tsx for root, admin, and news sections
10. Word filter cache: Added 60s TTL auto-refresh instead of manual cache bust
2026-07-04 19:41:04 +02:00
openhands
10523e58ce
Fix remaining security vulnerabilities
...
- H1: Add missing sanitize() to help center content rendering
- H2: Tighten CSP by removing unsafe-inline/unsafe-eval from script-src;
move theme init to external JS file with meta tag for defaultDark
- M1: Add SSRF protection for radio API URLs (block private IPs)
- M2: Add rate limiting to SSO ticket endpoint (5 req/30s per user)
- M4: Document locale validation safety in i18n dynamic import
- L1: Truncate stacktraces in admin commandocentrum to first 20 lines
2026-07-04 19:10:43 +02:00
openhands
5628e7d6b7
Security hardening: 12 improvements across the stack
...
1. env.ts: APP_KEY placeholder detection with validation
2. schema.prisma: password column widened to varchar(255) for argon2id
3. auth.ts: trustHost restricted to development only
4. next.config.ts: added CSP, HSTS, X-Frame-Options, and other security headers
5. api.ts: CORS restricted to APP_URL instead of wildcard
6. register-form.tsx: migrated from REST API fetch to server action (useActionState)
7. twofactor.ts + 2fa page: TOTP recovery codes (8 one-time codes, generated and displayed)
8. register.ts: password min length 8 + complexity requirements (upper, lower, digit)
9. register.ts + help-tickets.ts + radio-shouts.ts: Zod schema validation
10. rate-limit.ts: improved periodic cleanup with aggressive eviction at 10k buckets
11. guard.ts + admin actions: rate-limited admin actions (30 req/min per staff)
12. help-tickets.ts + radio-shouts.ts: content moderation via moderateOrThrow
2026-07-04 18:52:00 +02:00
openhands
a1950e5b65
fix: correct sprite font vertical offset and use avg char width fallback
2026-07-03 18:37:05 +02:00
openhands
77ae4838c0
feat: 100% self-hosted Habbo fonts via sprite sheets + client-side compositor
2026-07-03 18:22:30 +02:00
openhands
8a58bcb252
fix: restore word-level proxy for Habbo fonts, pre-cache all 175 fonts for 'Atom'
2026-07-03 17:58:56 +02:00
openhands
ac75f9c80a
feat: 100% self-hosted Habbo fonts - 6300 char GIFs + local canvas compositor, no habbofont.net dependency
2026-07-03 17:36:34 +02:00
openhands
00b1d0a267
feat: pre-cache all 175 font GIFs for default text 'Atom'
2026-07-03 17:28:16 +02:00
openhands
a5110a62dc
feat: add download-all-fonts ZIP button, proxy fonts locally via /api/font
2026-07-03 17:25:55 +02:00
openhands
d5ec7ba0f8
feat: self-host all Habbo fonts via proxy route /api/font/[style]/[text]
2026-07-03 17:21:05 +02:00
openhands
f3367e9b7b
feat: save logos to media/logo/ subdir, add Logo generator link to admin dropdown
2026-07-03 17:14:44 +02:00
openhands
917437c5ef
fix: use server-side fetch for logo save (bypass CORS), detect file MIME on extension
2026-07-03 17:05:25 +02:00
openhands
6df4fe2ddd
chore: remove stale test logos
2026-07-03 17:00:41 +02:00
openhands
073f8e1b6a
fix: detect actual MIME type for save-logo extension instead of hardcoded png
2026-07-03 17:00:08 +02:00
openhands
a84cbfa4f0
feat: add all 191+ Habbo fonts from habbofont.net to logo generator
2026-07-03 16:55:59 +02:00
openhands
af2d5b4943
feat: add save as site logo button to logo generator
2026-07-03 16:45:43 +02:00
openhands
98506fea1e
feat: add Habbo pixel font to logo generator, revert site-header toggle
2026-07-03 16:35:54 +02:00
openhands
4f79d5a0ae
feat: add pixel font for hotel name, toggle text/logo on click in site header
2026-07-03 16:31:17 +02:00
openhands
01e7f84d18
feat: append '- Hotel' to hotel name in title bar, site header and client header
2026-07-03 16:22:42 +02:00
openhands
187af2e147
fix: strip existing sso param from clientUrl, add aria roles to dropdowns, add x-pathname fallback, move .dropdown-menu into @layer components
2026-07-03 16:17:42 +02:00
openhands
7e616ca6b3
refactor: extract duplicate header into shared renderHeader function
2026-07-03 16:05:56 +02:00
openhands
98c9b951c4
fix: remove duplicate site-bg, handle fullscreen promise rejection, unify tooltip language, improve dropdown CSS compat and accessibility
2026-07-03 16:03:09 +02:00
openhands
e5b0649bf1
fix: remove debug console.log from root layout
2026-07-03 15:51:33 +02:00
openhands
7e5813bd97
Fix client loading as atomcms normal
2026-07-03 15:16:47 +02:00
openhands
bedf0ee7fa
chore: update nodemailer to latest, revert otplib to v12 due to breaking changes
2026-07-02 17:39:48 +02:00
openhands
1b4930af0b
chore: add uploaded media files
2026-07-02 17:28:24 +02:00
openhands
518c072491
refactor: convert admin pages to Tailwind and improve media uploads; fix TypeScript error in commandocentrum
2026-07-02 17:26:16 +02:00
openhands
72ef74fc87
refactor: enhance admin panel styling with better card patterns
...
- Dashboard: use admin-card for sections, refine progress bars and action badges
- Applications: enhanced card styling with p-3 and better text hierarchy
- Emulator: convert remaining 'card' classes to 'admin-card'
- All changes eliminate inline styles and use consistent Tailwind patterns
Co-authored-by: openhands <[email protected] >
2026-07-02 16:27:06 +02:00
openhands
928544100b
Convert admin pages to new Tailwind design pattern
...
- Replace 'card' class with 'admin-card' (gradient cards, dark mode support)
- Replace 'muted' class with consistent Tailwind muted states
- Standardize page headers with gradient backgrounds and Lucide icons
- Convert all inline styles to Tailwind classes
- Add admin-page CSS helpers (admin-card, admin-filter-bar, admin-section-title)
- Apply pattern to all 42 admin pages (was only 6 before)
- Zero TypeScript errors, production builds successfully
Co-authored-by: openhands <[email protected] >
2026-07-02 16:05:35 +02:00