Commit Graph
1174 Commits
Author SHA1 Message Date
openhands 3baac5e885 chore: update nextjs and react to latest versionb to fix cve eploits
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 43s
2026-08-29 21:30:44 +02:00
openhands a6e69fe00e perf: declutter home page by removing duplicated sections and queries
CI / check (push) Successful in 33s
CI / release (push) Skipped
CI / deploy (push) Successful in 55s
The landing page showed the same information more than once. Drop the second
avatar grid (latest users) and its DB query, move the online users grid into
the left column, remove the register banner card and the bottom join CTA so
registration is only offered once in the hero, and show the online count a
single time in the hero badge instead of also in the stats row. The online
users query now fetches 12 rows instead of 30, saving bandwidth on every
uncached render. The avatar presentation contract test now expects one
thumbnail call site on the home page.
2026-08-29 21:26:30 +02:00
openhands b59d6c21af feat: prioritize game iframe, gated register terms and polished register page
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 55s
Fetch the Nitro client iframe with high priority so the browser starts the
game document before competing resources, and replace the bare /client
spinner with a branded boot screen. Preconnect and eager loading were already
in place; typing support for the iframe fetchPriority prop is added in a
React type augmentation.

Rework the register terms block into a single clickable accept control with
a custom check state, error shake and inline hint, and dim the submit button
until the terms are accepted. The register page gets labeled sections
(account details / credentials), a corrected banner overlay, translated
show/hide toggles and a captcha slot that reserves height to avoid layout
shifts. English is the source of truth; other locales fall back to it.
2026-08-29 21:14:02 +02:00
openhands 7f39ba4257 fix: harden SSO ticket flow and revoke tickets on logout
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 54s
Reuse the outstanding auth_ticket instead of minting a fresh one on every
/client load, so reloading the page or opening a second tab no longer
invalidates a game session that is still connecting. New tickets are minted
with a guard against the previously-read value so concurrent launches
converge on the same ticket.

Revoke the auth_ticket when signing out (toolbar, header and sign-out
everywhere) so a leaked ticket can no longer be replayed against the
emulator, and prevent SSO leakage via referral by setting no-referrer on the
client iframe. Strip all whitespace from the ticket prefix and build the
launch URL through a tested helper that handles query strings, existing sso
params and URL fragments correctly.
2026-08-29 20:54:06 +02:00
openhands ca59a1065f perf: use lzma-wasm for SWF decompression and drop vite
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 59s
Replace the pure-JS lzma decoder with lzma-wasm (Rust/WASM, base64-inlined,
zero-alloc decompress), giving an order-of-magnitude speedup on furni
imports. Remove the obsolete lzma type shim and the redundant top-level
vite dev dependency, which nothing imports directly.
2026-08-29 19:27:27 +02:00
openhands 7a41775c7e fix: disable route prefetching app-wide to avoid spurious requests
Wrap next/link in a shared Link component that ships prefetch=false by
default, so no route is ever prefetched (viewport or hover) anymore, and
drop the DNS prefetch hint. Removes hidden background requests that were
the source of intermittent issues.
2026-08-29 19:27:13 +02:00
openhands 944e8ff1d8 fix: harden update pipeline and restore a clean production build
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m0s
- update-Nitrov3.sh: build CMS into .next-staging and swap atomically so a
  failed build never takes the live site down; auto-merge new variables
  from .env.example; validate env for duplicates/broken lines; restart the
  emulator/CMS only when rebuilt or unhealthy; fix step renumbering
- next.config.ts: support NEXT_DIST_DIR for staged production builds
- fix all TS errors (unused imports, missing tryDownloadCandidates helper)
  so tsc and the production build pass clean
- add Dockerfile/.dockerignore and switch docker-compose to a CMS container
- include prevailing UI/refactor changes (SurfaceCard, ticketing, tsconfig)
2026-08-28 12:48:04 +02:00
openhands 750fcb2e5c refactor: resolve hotel name directly from HOTEL_NAME env
CI / check (push) Successful in 41s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m1s
resolveHotelName() now returns env.HOTEL_NAME directly — the single source
of truth. The CMS hotel_name site setting and its DEFAULTS entry are removed
as dead code since they no longer influence the displayed name.

Call sites are unchanged (still await resolveHotelName()); only the lookup
behind it is gone, so the public site always shows the configured env name
with no DB round-trip and no preset.
2026-08-27 16:42:12 +02:00
openhands 164a4f4ef6 refactor: remove hotel-name fallback, fail fast when unconfigured
CI / check (push) Failing after 39s
CI / release (push) Skipped
CI / deploy (push) Skipped
Drop the hardcoded FALLBACK_HOTEL_NAME ("Atom") preset and the brand.ts
module. HOTEL_NAME is now a required env var: if it (and the CMS hotel_name
setting) is missing the site fails validation at startup/build with a clear
message instead of silently rendering a placeholder hotel name.

resolveHotelName() resolves CMS hotel_name -> required HOTEL_NAME only.
Callers that used the preset (api/home route catch branch, CMS settings form
default, mobile-nav/logo-generator prop defaults) now use the configured name
or an empty default; the real name is already passed in by server parents.
2026-08-27 16:35:00 +02:00
openhands 555c783d55 refactor: consolidate card components into a single SurfaceCard
CI / check (push) Successful in 41s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m22s
Replace the three near-identical public card primitives (ContentCard for
content pages, SectionCard for auth/account, and the new SurfaceCard) by
merging SectionCard into SurfaceCard, which now supports an optional header
(title/icon/action). Every remaining ad-hoc inline `rounded-2xl border`
card across (site) is converted to SurfaceCard, preserving each card's unique
visuals (background images, blur, gradients) via the style passthrough.

Net result: the public site uses exactly two card components — ContentCard
(CMS/content pages) and SurfaceCard (everything else) — and the shadcn Card
in components/ui/card.tsx is left untouched for admin.

Also deletes the now-unused components/home-section.tsx.
2026-08-27 16:17:09 +02:00
openhands ed6eaf33a0 style: convert remaining ad-hoc inline cards to shared SurfaceCard
CI / check (push) Successful in 40s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m11s
Introduce components/surface-card.tsx (Card + CardBody) mirroring the
.content-card / SectionCard token set, and use it on the (site) pages that
still hand-rolled card markup: me, search, and verify. This puts every
public page on one of the shared card components (ContentCard, SectionCard,
or SurfaceCard) for consistent radius/shadow/border.
2026-08-27 15:59:15 +02:00
openhands a3e3356ea7 style: align both card systems to shared design tokens
CI / check (push) Successful in 37s
CI / release (push) Skipped
CI / deploy (push) Successful in 58s
Unify the public site by making SectionCard and the verify status card use
the same --radius-lg / --shadow-card tokens and primary-tint header as the
existing CSS .content-card used by all content pages. This makes the entire
(site) group visually consistent without rewriting every page, and keeps the
shadcn Card in components/ui/card.tsx (used by admin) intact.
2026-08-27 15:51:32 +02:00
openhands b3340dbfdf style: unify remaining site card headers with SectionCard
CI / check (push) Successful in 35s
CI / release (push) Skipped
CI / deploy (push) Successful in 57s
Convert the settings page neon gradient section headers (blue/purple/green)
to the shared SectionCard, and replace the verify page's harsh multi-stop
status gradients with subtle status-tinted headers while keeping the
green/amber/red/blue semantics. The me page already used a consistent
rounded-2xl card style, so it needed no change.
2026-08-27 15:42:30 +02:00
openhands 087dd7d873 style: apply consistent professional layout to login page
CI / check (push) Successful in 35s
CI / release (push) Skipped
CI / deploy (push) Successful in 52s
Reuse the SectionCard component to unify the neon section headers, center
the page in a max-w-6xl container, and give the welcome panel and login
card consistent rounded corners and subtle shadows, matching the home
and register pages.
2026-08-27 15:32:32 +02:00
openhands 9f0ee74ce8 style: apply consistent professional layout to register page
CI / check (push) Successful in 34s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m4s
Reuse the SectionCard component to unify the green/purple/blue neon
section headers, center the page in a max-w-6xl container, and give the
welcome panel and form card consistent rounded corners and subtle
shadows, matching the home page.
2026-08-27 15:24:59 +02:00
openhands 005af25773 style: make home page layout more professional
CI / check (push) Successful in 34s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m1s
Unify the per-section neon gradient headers (blue/green/purple) into a
single consistent SectionCard component with a calm surface header and
hairline divider, constrain the page to a centered max-w-6xl container,
and soften the hero/cards with rounded-3xl corners and subtle shadows.
2026-08-27 15:21:25 +02:00
openhands 89c1751e79 refactor: extract shared login credential verification into auth/login-core
CI / check (push) Successful in 35s
CI / release (push) Skipped
CI / deploy (push) Successful in 58s
The username normalization, dummy-hash constant, password check and
email-verification gate were duplicated between precheckLogin and the
NextAuth credentials authorize handler. Move them into a single
login-core module so both paths share one source of truth and stay
consistent.
2026-08-27 15:17:54 +02:00
openhands e3ed37d170 build: align pinned Node.js version with CI runtime (26.8.1)
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m1s
.nvmrc and package.json engines.node must match the exact version the
CI environment runs, otherwise scripts/check-node-toolchain.mjs fails
the strict equality assertion.
2026-08-27 15:12:03 +02:00
openhands ac5cd6bc3f fix: normalize username and password with NFC in login flow
CI / check (push) Failing after 5s
CI / release (push) Skipped
CI / deploy (push) Skipped
precheckLogin already normalized the username with NFC, but the
NextAuth credentials authorize handler only trimmed it. This caused a
mismatch for accounts with accented/non-ASCII usernames: the precheck
passed while the actual sign-in lookup found no user and returned
'invalid username or password'.

Also normalize the password to NFC in both the precheck and the
authorize handler to match how register.ts hashes it.
2026-08-27 15:09:43 +02:00
Simo d5eadeb3a7 Merge pull request 'feat: add housekeeping inventory foundation' (#51) from codex/housekeeping-foundation into main
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 42s
Reviewed-on: #51
2026-08-26 19:50:40 +02:00
Simo 2a36ba1956 Merge branch 'main' into codex/housekeeping-foundation
CI / check (pull_request) Successful in 28s
CI / release (pull_request) Skipped
CI / deploy (pull_request) Skipped
2026-08-26 19:50:26 +02:00
Simo 08f8d54888 fix: close housekeeping foundation review findings
CI / check (pull_request) Successful in 28s
CI / release (pull_request) Skipped
CI / deploy (pull_request) Skipped
2026-08-26 19:16:34 +02:00
Simo ebc263da35 test: harden housekeeping foundation boundaries 2026-08-26 18:00:35 +02:00
Simo a158c78a7c test: verify housekeeping foundation boundaries 2026-08-26 17:44:03 +02:00
openhands 9d0da5d65a Perf: cache Nitro client assets and parallelize client page
CI / check (push) Successful in 31s
CI / release (push) Skipped
CI / deploy (push) Successful in 59s
- Serve /swf and /nitro-assets (~2.8GB) with 7-day Cache-Control plus
  stale-while-revalidate so client opens stop re-fetching hundreds of
  files while asset updates still propagate in the background
- Issue the SSO ticket and the online count query in parallel on the
  client page to shave a round-trip off the critical render path
2026-08-26 15:06:16 +02:00
openhands e7f70bb429 Chore: remove unused e2e register debug script
Flagged by knip as unused. It was a one-off DB smoke test with a
hardcoded database password that should never have been committed.
2026-08-26 15:06:14 +02:00
openhands f25a26a93e Register: auto sign-in to /me and speed/cleanup improvements
CI / check (push) Failing after 30s
CI / release (push) Skipped
CI / deploy (push) Skipped
- Send the verification email after the response via after() so it
  never blocks sign-up
- Invalidate the cached login lookup right after account creation so
  the automatic sign-in always finds the fresh row
- Auto sign in with the submitted credentials and go straight to /me,
  with a fallback to /login?registered=1 if sign-in is refused (e.g.
  email verification required)
- Cache the register page's online/latest user queries to cut DB load
  under traffic
- Fix terms checkbox label double-toggle cancelling the selection
- Add pages.register.redirecting translation to all locales
2026-08-26 14:57:51 +02:00
openhands 2d09a4a92c Add missing migrations
CI / check (push) Failing after 26s
CI / deploy (push) Skipped
CI / release (push) Skipped
2026-08-26 14:28:28 +02:00
openhands 0201d21c38 Fix site crash by restoring next-intl plugin and lost next.config.ts options
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Successful in 54s
Recent optimization commits accidentally gutted next.config.ts, removing
the createNextIntlPlugin wrapper. This caused every page to crash at
runtime with 'Couldn't find next-intl config file', showing the error
page after a successful build.

Restores:
- next-intl plugin (./src/i18n/request.ts)
- Security headers (HSTS, X-Frame-Options, nosniff, etc.)
- Redirects from /admin/import/* to /admin/studio/*
- Cache headers for /assets and /images, AVIF/WebP image formats
- compress and productionBrowserSourceMaps

Keeps recent improvements: reactStrictMode and optimizePackageImports.
2026-08-25 23:01:54 +02:00
openhands 3070d85423 Perf: Optimize next.config.ts for Next.js 16
CI / check (push) Successful in 26s
CI / release (push) Skipped
CI / deploy (push) Successful in 38s
2026-08-25 22:35:46 +02:00
openhands f31530b3d7 Optimize next.config.ts with package import optimizations
CI / check (push) Successful in 26s
CI / release (push) Skipped
CI / deploy (push) Successful in 47s
2026-08-25 22:31:05 +02:00
openhands 3cc201a0ce Optimize next.config.ts with SWC minification and React strict mode 2026-08-25 22:30:35 +02:00
openhands 94b0b65ca0 Remove unused dependencies flagged by Knip
CI / check (push) Successful in 26s
CI / release (push) Skipped
CI / deploy (push) Successful in 38s
2026-08-25 22:28:02 +02:00
openhands 4eded4ec61 Apply Biome lint fixes
CI / check (push) Failing after 26s
CI / release (push) Skipped
CI / deploy (push) Skipped
2026-08-25 22:26:05 +02:00
openhands f63ca708fe Fix deploymentId in next.config.ts
CI / check (push) Failing after 26s
CI / release (push) Skipped
CI / deploy (push) Skipped
2026-08-25 22:20:41 +02:00
openhands e06596391e Fix Turbopack module resolution for lzma and restore path imports 2026-08-25 22:19:59 +02:00
openhands a5044c80d7 fix: resolve biome linter warnings and code formatting
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Successful in 46s
2026-08-25 21:54:02 +02:00
openhands 416c31643b perf: optimize dashboard database queries and remove unused imports
CI / check (push) Failing after 10s
CI / deploy (push) Skipped
CI / release (push) Skipped
2026-08-25 21:52:18 +02:00
Simo a47b4eb195 test: canonicalize housekeeping module boundaries 2026-08-25 21:35:10 +02:00
Simo b6bf5e69ca test: parse housekeeping import boundaries 2026-08-25 21:23:58 +02:00
Simo 0b46a94d57 test: close housekeeping import-policy escapes 2026-08-25 21:11:37 +02:00
Simo ff2b2af6d4 test: harden housekeeping preview boundaries 2026-08-25 21:00:22 +02:00
Simo d19ba88005 feat: add gated housekeeping foundation preview 2026-08-25 20:45:40 +02:00
Simo cc241f0b7e test: cover housekeeping palette utilities 2026-08-25 20:29:08 +02:00
Simo 8bf4663336 test: complete housekeeping shell boundary guard 2026-08-25 20:25:11 +02:00
Simo 52ec48ffe4 test: harden housekeeping shell contracts 2026-08-25 20:17:45 +02:00
Simo addc9c7b1a feat: build housekeeping command deck shell 2026-08-25 20:05:56 +02:00
Simo cfeb0f19b8 fix: refine housekeeping Italian copy 2026-08-25 19:54:58 +02:00
Simo 14cfad4029 test: harden housekeeping registry contracts 2026-08-25 19:49:31 +02:00
Simo 2d5f03048a feat: add housekeeping domain registry 2026-08-25 19:39:08 +02:00