Commit Graph
489 Commits
Author SHA1 Message Date
openhands 399c047515 fix: harden admin actions, search, sanitization and repo hygiene
CI / check (push) Successful in 1m21s
CI / deploy (push) Successful in 1m25s
- Split approve/dismiss application workflows with distinct audit logs,
  rate-limited guards and real error logging
- Validate article status/date/id input and stop resetting publishedAt
  on every update
- Validate guild updates (state, forum enums, non-empty name) behind
  rate-limited guard
- Fix scheduled-article publishing (ignore NULL dates, set updatedAt,
  type-safe predicates)
- Harden admin search API (LIKE escaping, query cap, per-user
  rate limit, round-robin result cap) and fix search dialog
  abort/res.ok/loading races
- Lock down HTML sanitizer to an allowlist profile and add XSS tests
- Improve mobile nav accessibility (unique id, dialog role, focus
  management, scroll lock, outside close)
- Log swallowed server errors instead of silent catch blocks
- Remove dead eslint config, drop unused dompurify deps, restore knip
  CI step, add Playwright config with smoke spec
2026-09-04 13:04:08 +02:00
openhands 5e598a08b4 fix: remove ssr:false from dynamic imports in server components
CI / runtime-diagnostics (push) Skipped
CI / check (push) Failing after 0s
CI / deploy (push) Skipped
CI / release (push) Skipped
Turbopack rejects ssr:false in Server Components.
Removed from 4 dynamic imports in:
- src/app/(site)/layout.tsx (RadioPlayerGate)
- src/app/admin/analytics/economy/page.tsx (RevenueChart)
- src/app/admin/analytics/page.tsx (DashboardChart, PeakHoursHeatmap)
- src/app/admin/media/page.tsx (AdminMediaGrid)
2026-09-03 16:04:48 +02:00
openhands 30c95b1a5c feat: comprehensive CMS improvements
CI / runtime-diagnostics (push) Skipped
CI / release (push) Skipped
CI / check (push) Failing after 0s
CI / deploy (push) Skipped
- Fix DOMPurify SSR crash (use isomorphic-dompurify)
- Fix SanitizedHtml to sanitize by default
- Add auth guards to studio/catalog maintenance pages
- Add update/edit to vouchers CRUD
- Add update/edit to rare-values CRUD
- Add approve workflow to applications page
- Add edit form to guilds detail page
- Add SEO metadata to all public pages (21 pages)
- Fix mobile nav accessibility (focus trap, aria attributes)
- Fix missing labels and table accessibility
- Add dynamic imports for heavy client components (6 components)
- Fix silent error swallowing (40+ locations)
- Add content scheduling for articles (publishAt, status)
- Wire up 12 missing webhook notification triggers
- Add global search to admin panel
- Add bulk actions to admin users table
- Fix JSON formatting and a11y issues
2026-09-03 16:00:32 +02:00
openhands b810b16672 fix: show/hide arrow always visible and null-safe
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m2s
- Show arrow (›) appears when toolbar is hidden, regardless of pos state
- Null-safe pos top/left (?. ?? 8) to prevent TS errors
- Arrow positioned fixed top-right instead of depending on balk-positie
2026-09-02 22:02:31 +02:00
openhands a30e4af32e feat: polish toolbar, live online count via SSE + emulator 3-state
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 30s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m5s
- Add emulator status 3-state (unknown/green/red) with tooltip
- Extract shared primary button style/constants for DRY toolbar code
- Add emulatorUnknown translations to all 25 locales
- Bump Next.js to 16.3.4
- Fix RCON delivery timeout caching (15s TTL / shared across clients)
- Who's-online tooltip throttled to max 1 request per 30s
2026-09-02 21:34:30 +02:00
openhands 67b67798b9 feat(client): polished toolbar, live online count via SSE
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m27s
- Redesign in-game client toolbar with refined glass styling and buttons
- Live online count + emulator status streamed over SSE multicast
- Who's-online tooltip throttled to reduce repeated requests
- Fix show button so it always returns the hidden toolbar
- Use theme CSS variables instead of hardcoded colors
- Add toolbar translations across all 25 locales
2026-09-02 21:14:42 +02:00
openhands 58c35a2920 feat: enforce no hardcoded colors across entire CMS
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 32s
CI / release (push) Skipped
CI / deploy (push) Successful in 58s
Added scripts/check-admin-colors.mjs — scans all src/ files for:
- text-white, text-black (use theme text vars)
- bg-white, bg-black (use theme background/overlay vars)
- bg/text/border/ring with gray/slate/zinc/stone palette
- bg/text/border/ring with red/green/blue/etc palette

Fixed 21 violations across 11 files:
- Overlays: bg-black/* → bg-foreground/*
- Text: text-white → text-primary-foreground
- Backgrounds: bg-white/10 → bg-background/10
- Green accents: bg-green-* → bg-primary
- Red accents: bg-red-* → bg-destructive

Integrated into:
- lint-staged: runs on every *.ts/*.tsx commit
- vitest: src/lib/no-hardcoded-colors.test.ts replaces old audit test
- Allowlist: shadcn/ui primitives (button, badge, dialog) + 4 graphical files
2026-09-01 19:33:50 +02:00
openhands 52516a368d fix: skip heavy post-import consolidation on non-final clone chunks
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 38s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m2s
The flush after every 400-item chunk was running expensive operations
(reconcileOfferIds, rebuildCatalog, verifySpriteIds, rcon updates) which
caused the import to hang after ~800 items. Now only the final chunk
triggers the full consolidation. Also raised the per-request limit from
500 to 5000 items.
2026-09-01 18:29:06 +02:00
openhands 1374bd332f Studio: add clone-all-per-hotel, per-item status detail, retry, ETA, and auto-translate
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 36s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m14s
- Add 'Clone all missing' button for clone sources with confirmation dialog
- Show per-item status badges: nitro, furnidata, catalog entry
- Add status filters: missing furnidata, missing catalog entry
- Add ETA and percentage to batch progress bar
- Add retry button for failed items after batch import
- Auto-translate all languages after clone-all completes
- Fix statusFilter 'all' bug that incorrectly filtered imported items
- Bulk-load FurnitureData + catalog references for O(1) per-item checks
2026-09-01 17:29:12 +02:00
Simo 5b190cb929 chore: expose rank editor error details
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 27s
CI / release (push) Skipped
CI / deploy (push) Successful in 43s
2026-08-31 21:32:25 +02:00
Simo 9af1e62655 feat: allow rank-gated housekeeping preview in production
CI / check (push) Successful in 29s
CI / deploy (push) Successful in 56s
CI / release (push) Skipped
2026-08-31 20:29:38 +02:00
openhands 1dc8d1d46f feat: add official furnidata sync button for importing all missing items
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Successful in 55s
- API endpoint: /api/admin/import/official/sync-all
  - Fetches all official Habbo furnidata
  - Compares with database to find missing items
  - Imports missing items via SSE batch with progress reporting
  - 500 item limit for safety
  - Proper abort signal support
- Client component: OfficialSyncClient with progress UI
- Updated StudioSyncPage to include Official Furnidata sync option
- Uses existing importSingleFurni infrastructure
2026-08-31 20:24:46 +02:00
openhands 2920a6521b feat: update StudioSyncPage with clone sync client
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 56s
- StudioSyncPage toont nu Clone Sources en Official Furnidata opties
- Clone sync gebruikt bestaande SSE infrastructuur met 60s idle timeout
- DeOfficial Furnidata sectie is uitgeschreven voor toekomstige uitbreiding
2026-08-31 19:27:37 +02:00
openhands 7556b1f3fa perf: prevent import hanging with timeouts and batching
CI / check (push) Successful in 31s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m1s
- verifyAndFixInteractionModesCount: paginated DB queries (500/batch)
  instead of loading all items into memory at once
- withFurniDataLock: add 60s chain timeout to prevent deadlocks
  when a lock holder stalls or crashes
- withGamedataLock: same timeout protection for gamedata locks
- conversion-pool: add 60s per-job timeout, fall back to main thread
- furni/batch: abort signal + post_import progress events + skip
  post-import steps when client disconnects
- furni/batch-regen: abort signal + early exit when disconnected
- clone/sync-all: pre-fetch furnidata once per source instead of
  per item (eliminates 2000+ redundant fetches)
- sse-client: add 60s idle timeout to prevent infinite hangs
2026-08-31 18:25:32 +02:00
openhands f70d96b81c fix: prevent import hanging by adding abort signals and idle timeouts
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 59s
- Furni batch: wire request.signal to abort controller, send post_import
  progress events, skip post-import steps when aborted
- Clone sync-all: pre-fetch furnidata once per source instead of per item
  (eliminates 2000+ redundant DB reads + HTTP requests)
- SSE client: add 60s idle timeout to prevent infinite hangs when server
  stops responding
2026-08-31 18:11:54 +02:00
openhands adf0658916 feat: extend theme builder with block visibility, layout, effects, media, and custom CSS tabs
CI / check (push) Failing after 29s
CI / release (push) Skipped
CI / deploy (push) Skipped
- Add theme-blocks.ts registry with 24 themeable blocks across 4 categories
- Extend resolver to resolve blocks, layout, effects, media, and custom CSS per scope
- Add data-theme-block attributes to all site layout blocks
- Extend ScopedThemeVars to generate CSS for block visibility, layout vars, effect vars, media vars, and custom CSS
- Rewrite admin UI with 6 tabs: Colors, Blocks, Layout, Effects, Media, Custom
- Extend server actions to save/load all new setting types
- No database migration needed - uses existing theme_scope_values table with prefixed keys
2026-08-31 17:44:29 +02:00
openhands 4c8225720a fix: resolve test failures for theme builder integration
- Replace hardcoded text-white and text-red-* with CSS variables in theme-editor
- Add theme-builder migration entry to housekeeping matrix
- Update legacy page counts from 137 to 138 in housekeeping tests
- Add /admin/theme-builder to content test prefixes
2026-08-31 17:21:37 +02:00
openhands a98b194386 feat: add scoped theme builder system with per-route, per-module, and multi-site support
- Add theme_scopes and theme_scope_values database tables for scoped themes
- Implement theme resolver engine with inheritance: global > site > module > route
- Add module detection for 20+ routes (shop, guilds, radio, news, etc.)
- Create admin UI at /admin/theme-builder with scope tree and color editor
- Add ScopedThemeVars component for injecting scoped CSS via data-attributes
- Add ThemeScopeDetector client component for runtime module/route detection
- Add site-resolver for multi-site domain detection
- Add /api/themes/export endpoint (JSON, CSS, variables formats)
- Add /api/themes/export/embed.js for external integration widget
- Add server actions for full CRUD on scopes and theme values
- Add admin nav link and EN/NL translations
2026-08-31 17:15:42 +02:00
openhands b57697b2e0 Polish content pages: share AuthTopBar, page-grid helper and responsive tables
CI / check (push) Successful in 37s
CI / release (push) Skipped
CI / deploy (push) Successful in 59s
- Extract shared AuthTopBar frosted top bar; reuse in login & register
- Add .page-grid class replacing 48 inline grid styles
- Add .table-scroll + .table-cell-truncate helpers; wrap leaderboard/staff tables
- Constrain settings page width (max-w-5xl) and stack profile card on mobile
- Use theme background var for shop category icon (dark-mode safe)
2026-08-31 12:23:06 +02:00
openhands d4677972cd Refine dashboard hero, mobile nav, animations and touch polish
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Successful in 56s
- Stack the /me dashboard hero (avatar + info) on small screens instead of
  crowding them side by side; center the avatar and info on mobile
- Respect prefers-reduced-motion in the Reveal scroll animation
- Make the desktop pitch-in (NavDropdown) and mobile menu more consistent;
  give the mobile menu a max-height with overscroll containment so long
  navs scroll instead of overflowing on small phones
- Add safe-area insets for notched devices on header, nav and footer
- Polish whole-link content-cards (community tiles) with hover lift and a
  visible focus ring
- Enforce a comfortable min touch height on all .btn buttons
2026-08-31 12:11:04 +02:00
openhands 903d175f2d Polish responsive design across all screen sizes and refine card blocks
CI / check (push) Failing after 26s
CI / release (push) Skipped
CI / deploy (push) Skipped
- Enhance SurfaceCard with refined borders, layered shadows, and polished
  primary-tinted header with an icon container
- Update homepage blocks (hero, features, stats, login, news, photos) for
  proper mobile/tablet/desktop responsiveness and tighter mobile spacing
- Improve content-card, stat-block, card-grid and card styling with subtle
  depth (layered shadow + inner hairline) and smoother hover states
- Refine site header, footer, top header and site layout spacing for small
  screens while keeping a consistent professional look on large screens
- Add min-tap-height targets and responsive typography on mobile
2026-08-31 11:45:02 +02:00
Simo b1ddda66ff Revert "Merge pull request 'Complete Housekeeping migration and /ase cutover' (#52) from codex/housekeeping-complete into main"
CI / check (push) Successful in 27s
CI / release (push) Skipped
CI / deploy (push) Successful in 43s
This reverts commit 488b6e57c4, reversing
changes made to b506b4499a.
2026-08-30 21:31:34 +02:00
Simo 2b8f73a91d feat(housekeeping): cut over administration to ase 2026-08-30 20:35:22 +02:00
Simo 8a31556d51 test(housekeeping): prove 137 route parity
CI / check (pull_request) Successful in 1m9s
CI / release (pull_request) Skipped
CI / deploy (pull_request) Skipped
2026-08-30 19:11:14 +02:00
Simo a113e48880 feat(housekeeping): finish accessible command deck 2026-08-30 18:49:10 +02:00
Simo 85ad0452d3 feat(housekeeping): compose operations workspace
CI / check (pull_request) Successful in 37s
CI / release (pull_request) Skipped
CI / deploy (pull_request) Skipped
2026-08-30 17:23:55 +02:00
Simo bcb0ca977f feat(housekeeping): add global command deck search
CI / check (pull_request) Successful in 38s
CI / release (pull_request) Skipped
CI / deploy (pull_request) Skipped
2026-08-30 15:59:48 +02:00
Simo 9c4b973faf feat(housekeeping): deliver economy vertical
CI / check (pull_request) Successful in 40s
CI / release (pull_request) Skipped
CI / deploy (pull_request) Skipped
2026-08-30 13:47:06 +02:00
Simo 1ec05cda39 test: make media route fixture cross-platform
CI / check (pull_request) Successful in 34s
CI / release (pull_request) Skipped
CI / deploy (pull_request) Skipped
2026-08-30 12:27:12 +02:00
Simo b70bd401d1 fix(housekeeping): retain admin banner shim
CI / check (pull_request) Failing after 31s
CI / release (pull_request) Skipped
CI / deploy (pull_request) Skipped
2026-08-30 12:11:14 +02:00
Simo c524b305d7 fix(housekeeping): address task 14 review round 2 2026-08-30 11:30:17 +02:00
Simo d09eaa33d6 fix(housekeeping): address task 14 review round 1 2026-08-30 10:53:50 +02:00
Simo bdab924bdf Merge branch 'main' of https://gitlab.epicnabbo.nl/remco/EpicNext-Cms into codex/housekeeping-complete 2026-08-30 00:17:38 +02:00
openhands f2ac4745d4 feat: redesign home and register pages for cleaner overview
CI / check (push) Successful in 27s
CI / release (push) Skipped
CI / deploy (push) Successful in 54s
Rebuild the home landing layout into a streamlined, more scannable
design: a centered focused hero, feature cards, a compact stats row,
and clearer news/users sections. Rework the register page into a
balanced two-column layout with a tidier intro panel and sticky form.
Add statsArticles translation key across locale files; verified with
tsc and biome.
2026-08-29 21:56:52 +02:00
openhands a6e69fe00e perf: declutter home page by removing duplicated sections and queries
CI / check (push) Successful in 33s
CI / release (push) Skipped
CI / deploy (push) Successful in 55s
The landing page showed the same information more than once. Drop the second
avatar grid (latest users) and its DB query, move the online users grid into
the left column, remove the register banner card and the bottom join CTA so
registration is only offered once in the hero, and show the online count a
single time in the hero badge instead of also in the stats row. The online
users query now fetches 12 rows instead of 30, saving bandwidth on every
uncached render. The avatar presentation contract test now expects one
thumbnail call site on the home page.
2026-08-29 21:26:30 +02:00
Simo 3d385d1869 Merge branch 'main' of https://gitlab.epicnabbo.nl/remco/EpicNext-Cms into codex/housekeeping-complete 2026-08-29 21:16:46 +02:00
openhands b59d6c21af feat: prioritize game iframe, gated register terms and polished register page
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 55s
Fetch the Nitro client iframe with high priority so the browser starts the
game document before competing resources, and replace the bare /client
spinner with a branded boot screen. Preconnect and eager loading were already
in place; typing support for the iframe fetchPriority prop is added in a
React type augmentation.

Rework the register terms block into a single clickable accept control with
a custom check state, error shake and inline hint, and dim the submit button
until the terms are accepted. The register page gets labeled sections
(account details / credentials), a corrected banner overlay, translated
show/hide toggles and a captcha slot that reserves height to avoid layout
shifts. English is the source of truth; other locales fall back to it.
2026-08-29 21:14:02 +02:00
openhands 7f39ba4257 fix: harden SSO ticket flow and revoke tickets on logout
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 54s
Reuse the outstanding auth_ticket instead of minting a fresh one on every
/client load, so reloading the page or opening a second tab no longer
invalidates a game session that is still connecting. New tickets are minted
with a guard against the previously-read value so concurrent launches
converge on the same ticket.

Revoke the auth_ticket when signing out (toolbar, header and sign-out
everywhere) so a leaked ticket can no longer be replayed against the
emulator, and prevent SSO leakage via referral by setting no-referrer on the
client iframe. Strip all whitespace from the ticket prefix and build the
launch URL through a tested helper that handles query strings, existing sso
params and URL fragments correctly.
2026-08-29 20:54:06 +02:00
openhands 7a41775c7e fix: disable route prefetching app-wide to avoid spurious requests
Wrap next/link in a shared Link component that ships prefetch=false by
default, so no route is ever prefetched (viewport or hover) anymore, and
drop the DNS prefetch hint. Removes hidden background requests that were
the source of intermittent issues.
2026-08-29 19:27:13 +02:00
Simo 25b76437ff fix(housekeeping): harden people account workflows 2026-08-29 13:13:04 +02:00
Simo e5c230ba35 feat(housekeeping): dispatch canonical domain routes 2026-08-28 21:35:08 +02:00
Simo 64bb230de5 Merge branch 'main' of https://gitlab.epicnabbo.nl/remco/EpicNext-Cms into codex/housekeeping-complete 2026-08-27 17:25:31 +02:00
openhands 750fcb2e5c refactor: resolve hotel name directly from HOTEL_NAME env
CI / check (push) Successful in 41s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m1s
resolveHotelName() now returns env.HOTEL_NAME directly — the single source
of truth. The CMS hotel_name site setting and its DEFAULTS entry are removed
as dead code since they no longer influence the displayed name.

Call sites are unchanged (still await resolveHotelName()); only the lookup
behind it is gone, so the public site always shows the configured env name
with no DB round-trip and no preset.
2026-08-27 16:42:12 +02:00
openhands 164a4f4ef6 refactor: remove hotel-name fallback, fail fast when unconfigured
CI / check (push) Failing after 39s
CI / release (push) Skipped
CI / deploy (push) Skipped
Drop the hardcoded FALLBACK_HOTEL_NAME ("Atom") preset and the brand.ts
module. HOTEL_NAME is now a required env var: if it (and the CMS hotel_name
setting) is missing the site fails validation at startup/build with a clear
message instead of silently rendering a placeholder hotel name.

resolveHotelName() resolves CMS hotel_name -> required HOTEL_NAME only.
Callers that used the preset (api/home route catch branch, CMS settings form
default, mobile-nav/logo-generator prop defaults) now use the configured name
or an empty default; the real name is already passed in by server parents.
2026-08-27 16:35:00 +02:00
openhands 555c783d55 refactor: consolidate card components into a single SurfaceCard
CI / check (push) Successful in 41s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m22s
Replace the three near-identical public card primitives (ContentCard for
content pages, SectionCard for auth/account, and the new SurfaceCard) by
merging SectionCard into SurfaceCard, which now supports an optional header
(title/icon/action). Every remaining ad-hoc inline `rounded-2xl border`
card across (site) is converted to SurfaceCard, preserving each card's unique
visuals (background images, blur, gradients) via the style passthrough.

Net result: the public site uses exactly two card components — ContentCard
(CMS/content pages) and SurfaceCard (everything else) — and the shadcn Card
in components/ui/card.tsx is left untouched for admin.

Also deletes the now-unused components/home-section.tsx.
2026-08-27 16:17:09 +02:00
openhands ed6eaf33a0 style: convert remaining ad-hoc inline cards to shared SurfaceCard
CI / check (push) Successful in 40s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m11s
Introduce components/surface-card.tsx (Card + CardBody) mirroring the
.content-card / SectionCard token set, and use it on the (site) pages that
still hand-rolled card markup: me, search, and verify. This puts every
public page on one of the shared card components (ContentCard, SectionCard,
or SurfaceCard) for consistent radius/shadow/border.
2026-08-27 15:59:15 +02:00
openhands a3e3356ea7 style: align both card systems to shared design tokens
CI / check (push) Successful in 37s
CI / release (push) Skipped
CI / deploy (push) Successful in 58s
Unify the public site by making SectionCard and the verify status card use
the same --radius-lg / --shadow-card tokens and primary-tint header as the
existing CSS .content-card used by all content pages. This makes the entire
(site) group visually consistent without rewriting every page, and keeps the
shadcn Card in components/ui/card.tsx (used by admin) intact.
2026-08-27 15:51:32 +02:00
openhands b3340dbfdf style: unify remaining site card headers with SectionCard
CI / check (push) Successful in 35s
CI / release (push) Skipped
CI / deploy (push) Successful in 57s
Convert the settings page neon gradient section headers (blue/purple/green)
to the shared SectionCard, and replace the verify page's harsh multi-stop
status gradients with subtle status-tinted headers while keeping the
green/amber/red/blue semantics. The me page already used a consistent
rounded-2xl card style, so it needed no change.
2026-08-27 15:42:30 +02:00
openhands 087dd7d873 style: apply consistent professional layout to login page
CI / check (push) Successful in 35s
CI / release (push) Skipped
CI / deploy (push) Successful in 52s
Reuse the SectionCard component to unify the neon section headers, center
the page in a max-w-6xl container, and give the welcome panel and login
card consistent rounded corners and subtle shadows, matching the home
and register pages.
2026-08-27 15:32:32 +02:00
openhands 9f0ee74ce8 style: apply consistent professional layout to register page
CI / check (push) Successful in 34s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m4s
Reuse the SectionCard component to unify the green/purple/blue neon
section headers, center the page in a max-w-6xl container, and give the
welcome panel and form card consistent rounded corners and subtle
shadows, matching the home page.
2026-08-27 15:24:59 +02:00