Commit Graph
1631 Commits
Author SHA1 Message Date
Simo 0cd753c735 fix: restore complete admin feature dependencies 2026-07-11 21:15:54 +02:00
remco 03135fb7c1 Delete directory ' .gitea/workflows' 2026-07-11 21:15:28 +02:00
remco 788d0b0e09 Update .gitea/workflows/deploy.yml 2026-07-11 21:14:12 +02:00
remco 038232655a Delete directory '.gitea/workflows' 2026-07-11 21:13:52 +02:00
remco f95ba94bcf Update .gitea/workflows/deploy.yml
Deploy Atom Next / deploy (push) Has been cancelled
2026-07-11 21:10:45 +02:00
remco db2e8d80c3 Update .gitea/workflows/deploy.yml
Deploy Atom Next / deploy (push) Has been cancelled
2026-07-11 21:09:57 +02:00
remco 4f4044992b Update .gitea/workflows/deploy.yml
Deploy Atom Next / deploy (push) Has been cancelled
2026-07-11 21:08:57 +02:00
remco b0c1f7a34a Update .gitea/workflows/deploy.yml
Deploy Atom Next / deploy (push) Has been cancelled
2026-07-11 21:07:29 +02:00
remco c8b89803aa Add .gitea/workflows/deploy.yml
Deploy Atom Next / deploy (push) Has been cancelled
2026-07-11 21:06:50 +02:00
remco 1f2d47b9bb Update .gitea/workflows/deploy.yaml
Deploy Atom Next / deploy (push) Has been cancelled
2026-07-11 21:05:28 +02:00
remco e84547a700 Add .gitea/workflows/deploy.yaml
Deploy Atom Next / deploy (push) Has been cancelled
2026-07-11 21:04:10 +02:00
remco be4879e54c Delete .gitea/workflows/test.yaml 2026-07-11 21:03:43 +02:00
remco d3e1041f8e Add .gitea/workflows/test.yaml
Guaranteed Test / always-success (push) Has been cancelled
2026-07-11 20:55:49 +02:00
Simo 5b4228261a Reapply "Add missing admin action files and navigation links"
This reverts commit 4d515bc400.
2026-07-11 20:52:56 +02:00
Simo 96ed768f14 test: add unresolved local import scanner 2026-07-11 20:52:55 +02:00
Simo cabafb4ea6 docs: plan complete admin feature recovery 2026-07-11 20:51:33 +02:00
Simo c670bd8c64 docs: design admin feature recovery 2026-07-11 20:48:45 +02:00
Simo 4d515bc400 Revert "Add missing admin action files and navigation links"
This reverts commit 41be6835bf.
2026-07-11 20:37:56 +02:00
Simo 4a1e1115b3 Harden CMS security and theme contrast 2026-07-11 20:27:20 +02:00
openhands 2465ff2170 Add translation keys for new admin nav items in all languages 2026-07-11 12:28:52 +02:00
openhands 41be6835bf Add missing admin action files and navigation links
- Add 11 missing server action files: badges, bulk-users, catalog, catalog-bc, catalog-items, import-badges, import-furni, multi-account-detect, permissions, rooms, soundtracks
- Add missing admin navigation links: tickets, sounds, translations, import, radio sub-pages
- Add translation keys for all new navigation items
2026-07-11 12:01:05 +02:00
openhands 7e1ae17a3b Add dotenv loading to migration script 2026-07-10 23:57:36 +02:00
openhands 818df3697b Migrate from AES-256-CBC to AES-256-GCM for authenticated encryption
- Replace CBC+HMAC with GCM (built-in authentication via authTag)
- Remove createHmac and timingSafeEqual imports (no longer needed)
- Remove Snyk-ignore comments (no longer suppressible findings)
- Update test: tampered MAC test -> tampered auth tag test
- Add one-time migration script for existing CBC-encrypted 2FA secrets
2026-07-10 23:51:56 +02:00
openhands 259c0c96ab Fix remaining Snyk findings: XSS in validImageUrl, cipher integrity suppression 2026-07-10 23:40:11 +02:00
openhands d782b7c4c2 Fix Snyk security findings: XSS, open redirect, hardcoded secrets, cookie security, MD5 replacement 2026-07-10 23:34:57 +02:00
openhands 1875a69b83 Fix security scanner findings
- Replace hardcoded test secrets with crypto-generated values in laravel-encrypter.test.ts and totp.test.ts
- Add 'secure' attribute to locale cookie in language-switcher.tsx
- Validate image URLs before rendering in media-grid.tsx and media-picker.tsx (XSS prevention)
- Validate redirect URL is HTTPS before window.location assignment in TopUpForm.tsx (open redirect prevention)
- Document intentional MD5 usage for legacy PHP compatibility in password.ts
- Document HMAC integrity protection for CBC cipher in laravel-encrypter.ts
2026-07-10 23:08:15 +02:00
openhands 942bc6fc8d Security hardening, code quality, and ESLint setup
- Remove production DB dump (db_backup_*.sql) and update.log from git tracking
- Add DB backups to .gitignore
- Replace all console.log/console.error with structured logger module
- Translate Dutch error messages to English (link-discord.ts)
- Remove dead code blocks (register-form.tsx false && pattern)
- Add ESLint flat config with TypeScript, React, Next.js, jsx-a11y, and security plugins
- Add Prettier config
- Add eslint-plugin-security for security-aware linting
- Fix all 119+ ESLint warnings across the codebase:
  - Resolve security/detect-object-injection with safe access patterns
  - Resolve security/detect-non-literal-fs-filename with path traversal validation
  - Replace <img> with next/image <Image> component
  - Remove unused variables and imports
  - Replace non-null assertions with proper type guards
  - Replace <a> with <Link> for internal navigation
  - Use next/script Script component for external scripts
- Fix setState-in-useEffect anti-patterns (navbar-color-picker, logo-generator, theme-switcher)
- Add lint and format scripts to package.json

All checks: typecheck ✓, tests 58/58 ✓, lint 0 errors 0 warnings ✓
2026-07-10 22:48:22 +02:00
openhands 7f8c9afc0f Replace Arcturus Morningstar references with Polaris in README 2026-07-10 19:28:05 +02:00
openhands 4ae9cbad13 Rebrand README to EpicNext-CMS with professional English rewrite 2026-07-10 19:25:20 +02:00
openhands 9255788b06 Rename Habbo jar pattern to Polaris and bump JVM heap to 4G 2026-07-10 19:12:46 +02:00
openhands c68fccceeb Fix: only preconnect nitro URL if absolute (prevents crash on relative URLs like /nitro-client/) 2026-07-09 19:52:19 +02:00
openhands 0ac3e4353a Remove unused /api/client/sso route (replaced by server-side ticket generation) 2026-07-09 19:11:10 +02:00
openhands 7fe3220359 Inline SSO ticket generation in server component, prefetch client page from home, remove client API roundtrip 2026-07-09 18:41:04 +02:00
openhands cfb36e8007 Preconnect to Nitro client URL for faster client page load 2026-07-09 18:35:18 +02:00
openhands da505ae643 Optimize client page: combine fetch calls, extract ToolbarBtn component, reduce duplicated inline styles 2026-07-09 18:30:46 +02:00
openhands deac10e00a Add in-memory caching for online count, enable compression, and add staleTimes for router cache 2026-07-09 18:24:58 +02:00
openhands b058a3827b Fix theme consistency, i18n completeness, CSS variable naming, and hardcoded strings 2026-07-09 18:13:22 +02:00
openhands 0abd490f67 Improve update-Nitrov3.sh parallelism, UX, and compatibility
- Run renderer and client builds in parallel (background + wait) for
  faster updates
- Cache detected git branches in interactive menu (avoid re-running
  git branch -r on every redraw); re-cache after switching branches
- Add health check after emulator restart (poll until active or retries
  exhausted)
- Add service_active() helper with systemd/service/pgrep fallback for
  non-systemd systems; replace all systemctl is-active calls
- Add 30s read timeout (-t 30) on all interactive prompts to prevent
  hanging on non-terminal stdin
- Add set -E for ERR trap inheritance in subshells
2026-07-08 19:27:27 +02:00
openhands f9b0ec78d1 Improve update-Nitrov3.sh security, reliability, and portability
- Security: replace eval-based load_branches with nameref+readarray,
  remove export MYSQL_PWD (leaks to child processes), fix URL-decode
  via Python's urllib.parse, fix JSON injection in notify via json.dumps,
  add package.json guard before sudo rm -rf
- Portability: replace seq (external) with repeat() built-in, add
  mysql/mysqldump fallback alongside mariadb, add format_size() fallback
  when numfmt is unavailable, remove -maxdepth from list_sorted helper
- Robustness: add set -o pipefail, fix spinner zombie (remove disown),
  wrap git_update/detect_best_branch in subshells to prevent cd leaks,
  capture full mvn/yarn build output to log instead of tail, add -r to
  xargs basename, make ssl-verify-server-cert configurable via .env
- UX: add --dry-run/-n flag for preview without changes
2026-07-08 19:12:28 +02:00
openhands 04e1da7caf docs: rewrite README with comprehensive English setup instructions 2026-07-08 14:22:42 +02:00
openhands 5519a64583 fix: add missing nav-credit-icon, nav-ducket-icon and nav-diamond-icon CSS classes for topbar currency icons 2026-07-08 14:14:44 +02:00
openhands fc57fb06d1 chore: remove dead code, unused CSS, unused components, and clean up git tracking
- Remove storage/logs/ and prod.log from git tracking; add to .gitignore
- Remove unused AvatarCarousel and ArticleSlider components
- Remove unused SkeletonTable export from ui.tsx
- Remove unused ChevronDown import from admin layout
- Remove 13 unused CSS classes (icon-base, nav-*, navigation-icon*, .app.dark,
  text-body, transition-base, card-base, admin-info-grid, .coin.*)
- Remove duplicate translation keys (openMenu/closeMenu in en.json)
- Fix admin-bans to use Prisma-generated bans_type enum
- Create shared AdminPageHeader component and formatDate utility
- Add logger and generateRequestId for structured logging
- All 58 tests pass, typecheck clean, build succeeds
2026-07-08 13:27:01 +02:00
openhands c5db7f5156 fix: production hardening — migration script, security fixes, structured logging, API docs, component splitting
- Create apply-migrations.ts and jobs-worker.ts scripts (package.json references)
- Convert badge leaderboard from $queryRawUnsafe to $queryRaw with Prisma.sql templates
- Fix OAuth email binding: add oauth_require_link site setting, skip 2FA-protected accounts
- Add per-user 2FA rate limiting (5/30s) to prevent TOTP brute-force
- Add structured JSON logger with levels (debug/info/warn/error)
- Split 341-line HomePage into GuestView + UserView components
- Add OpenAPI v3.1 spec at /api/openapi.json
- Add LOG_LEVEL env var, regenerate Prisma client
- Add mysql2 dependency for migration scripts
- All 58 tests pass, typecheck clean
2026-07-08 13:06:02 +02:00
openhands 5c638cd6bc perf: add bans.user_id index, Redis cache layer, rate-limit improvements, radio contest/giveaway columns, and tests
- Add DB index on bans.user_id to speed up per-request ban lookups (migration 0008)
- Replace in-process rate limiter with Redis-backed implementation with in-memory fallback
- Add Redis caching layer for site settings with TTL invalidation (migration 0009)
- Add rate limiting to resetPassword to prevent token brute-force attacks
- Update all rateLimit callers to await the now-async function
- Flesh out RadioContests and RadioGiveaways models with title, description, prize, date, and winner columns
- Update radio contest/giveaway pages to display new fields
- Add tests for rate limiter (4 tests) and password-reset actions (3 tests)
- Add REDIS_URL environment variable (optional, falls back to in-memory)
2026-07-08 12:49:24 +02:00
openhands 43c0ba6614 Add Discord verification option for users without email 2026-07-07 20:37:42 +02:00
openhands eb01b14379 Add ultimate file-based email fallback so mailer always works without any configuration 2026-07-07 20:18:30 +02:00
openhands 065215b4dc Add local sendmail fallback so mailer works internally without external services 2026-07-07 20:15:29 +02:00
openhands bf4075233d Add Resend mailer as primary with SMTP fallback for reliable email delivery 2026-07-07 20:12:56 +02:00
openhands f386ae2b25 Add more button/navbar colors and gradient mix section to theme editor 2026-07-07 20:04:16 +02:00
openhands e43a768ce4 Add 4 new theme colors (success, warning, error, info) with full preset support 2026-07-07 19:48:41 +02:00