Commit Graph
52 Commits
Author SHA1 Message Date
Simo 2b8f73a91d feat(housekeeping): cut over administration to ase 2026-08-30 20:35:22 +02:00
openhands ca59a1065f perf: use lzma-wasm for SWF decompression and drop vite
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 59s
Replace the pure-JS lzma decoder with lzma-wasm (Rust/WASM, base64-inlined,
zero-alloc decompress), giving an order-of-magnitude speedup on furni
imports. Remove the obsolete lzma type shim and the redundant top-level
vite dev dependency, which nothing imports directly.
2026-08-29 19:27:27 +02:00
openhands 944e8ff1d8 fix: harden update pipeline and restore a clean production build
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m0s
- update-Nitrov3.sh: build CMS into .next-staging and swap atomically so a
  failed build never takes the live site down; auto-merge new variables
  from .env.example; validate env for duplicates/broken lines; restart the
  emulator/CMS only when rebuilt or unhealthy; fix step renumbering
- next.config.ts: support NEXT_DIST_DIR for staged production builds
- fix all TS errors (unused imports, missing tryDownloadCandidates helper)
  so tsc and the production build pass clean
- add Dockerfile/.dockerignore and switch docker-compose to a CMS container
- include prevailing UI/refactor changes (SurfaceCard, ticketing, tsconfig)
2026-08-28 12:48:04 +02:00
openhands 9d0da5d65a Perf: cache Nitro client assets and parallelize client page
CI / check (push) Successful in 31s
CI / release (push) Skipped
CI / deploy (push) Successful in 59s
- Serve /swf and /nitro-assets (~2.8GB) with 7-day Cache-Control plus
  stale-while-revalidate so client opens stop re-fetching hundreds of
  files while asset updates still propagate in the background
- Issue the SSO ticket and the online count query in parallel on the
  client page to shave a round-trip off the critical render path
2026-08-26 15:06:16 +02:00
openhands 0201d21c38 Fix site crash by restoring next-intl plugin and lost next.config.ts options
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Successful in 54s
Recent optimization commits accidentally gutted next.config.ts, removing
the createNextIntlPlugin wrapper. This caused every page to crash at
runtime with 'Couldn't find next-intl config file', showing the error
page after a successful build.

Restores:
- next-intl plugin (./src/i18n/request.ts)
- Security headers (HSTS, X-Frame-Options, nosniff, etc.)
- Redirects from /admin/import/* to /admin/studio/*
- Cache headers for /assets and /images, AVIF/WebP image formats
- compress and productionBrowserSourceMaps

Keeps recent improvements: reactStrictMode and optimizePackageImports.
2026-08-25 23:01:54 +02:00
openhands f31530b3d7 Optimize next.config.ts with package import optimizations
CI / check (push) Successful in 26s
CI / release (push) Skipped
CI / deploy (push) Successful in 47s
2026-08-25 22:31:05 +02:00
openhands 3cc201a0ce Optimize next.config.ts with SWC minification and React strict mode 2026-08-25 22:30:35 +02:00
openhands f63ca708fe Fix deploymentId in next.config.ts
CI / check (push) Failing after 26s
CI / release (push) Skipped
CI / deploy (push) Skipped
2026-08-25 22:20:41 +02:00
openhands e06596391e Fix Turbopack module resolution for lzma and restore path imports 2026-08-25 22:19:59 +02:00
openhands c7ba04bda1 feat: relocate import tools into studio and harden catalog/furnidata integrity
CI / check (push) Failing after 26s
CI / release (push) Skipped
CI / deploy (push) Skipped
- Move /admin/import/* tools under /admin/studio/* and add studio nav, layout and tabs
- Add shared catalog maintenance panel plus a /admin/studio/maintenance tab
- Make furnidata reconciliation overwrite conflicting entries with the
  DB-authoritative items_base classname/id (surfaced via fixedConflicts)
- Add furnidata_translate_enabled setting to skip the heavy localized
  furnidata build during import (manual build-languages still forces it)
- Update staff smoke contract test for the studio hub
2026-08-24 17:13:03 +02:00
openhands f285a7cd98 Add performance optimizations and component refactors
CI / check (push) Successful in 34s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m23s
- Cache read-heavy public API routes via redisCache (leaderboard, values,
  shop, articles, photos, guilds, teams, staff, users, home, radio, badges)
- Add single-flight and bounded-memory cache layer with unit tests
- Parallelize independent DB queries on search, rares, shop, staff, polls
  and profile pages
- Push radio points leaderboard aggregation to SQL with a LIMIT
- Split studio-client and import-furni-client into focused modules
- Clean up next.config.ts
2026-08-17 22:02:21 +02:00
openhands e76c530e4f Fix TypeScript errors and implement furniture import ID integrity with 18+ age verification
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m2s
- Add termsAccepted and ageVerified columns to User table
- Update register schema with new boolean fields
- Fix register form age verification checkbox (th -> t)
- Fix furni-import spriteId declaration order
- Fix batch route variable naming (id -> spriteId)
- Fix catalog-audit import path and ensure correct types
- Hardened import with per-item id conflict checks
- Added audit option for FurnitureData.json spriteId conflicts
- Updated tagline to include Leeftijdsvereiste: 18+
2026-08-14 16:37:00 +02:00
openhands e5ec3c1f06 perf: optimize CMS queries, caching, and asset delivery
CI / check (push) Successful in 27s
CI / release (push) Skipped
CI / deploy (push) Successful in 57s
Database:
- Add missing indexes (users.credits, users_currency(type,amount),
  users_settings.respects_received, camera_web.timestamp,
  messenger_offline.user_id) via migrations 0020/0021
- Use partial .select() everywhere instead of SELECT * (tickets, users,
  rooms, audit logs, catalog tree, polls, radio, password reset)
- Add queryPrepared/queryPreparedOne (server-side prepared statements)
  and switch the login check to a prepared statement; drop dead
  cache options from the pool config
- Raise total_users/total_rooms COUNT(*) cache TTL to 5m

Caching:
- Consolidate the three cache helpers (cached, redisCache, cachedQuery)
  into a single memory-first implementation backed by Redis
- invalidateKey now clears the in-process cache as well as Redis
- Cache homepage sections, news list, and leaderboard tabs; share one
  news_list cache key between homepage and news archive
- siteSettings: in-process cache with TTL so repeated getters no longer
  pay a Redis round-trip per call
- Share a 10s poll cache across all radio SSE connections
- Normalize timestamps after cache reads (Redis JSON round-trip)

Assets:
- Enable AVIF/WebP via images.formats and remove unoptimized from news
  covers and the homepage hero (149KB jpg) with proper sizes/priority
- Support ?format=webp|avif|png in the /imaging proxy via sharp

Other:
- Fix pnpm supply-chain minimumReleaseAge failures by excluding the
  freshly-published packages (next 16.3.1, hookform resolvers 5.8.0,
  resend 6.20.0)
- Remove unused before/after fields from housekeeping AuditEntry
2026-08-14 11:20:37 +02:00
openhands e867b675fc fix: replace jsonc with jsonc-parser and cleanup build config 2026-08-11 16:50:10 +02:00
openhands 4993b75608 perf: self-host fonts, drop unused generated code and add swf tests
CI / check (push) Successful in 25s
CI / release (push) Skipped
CI / deploy (push) Successful in 59s
- Self-host Nunito and Pixelify Sans via next/font instead of Google Fonts CDN
  (removes render-blocking external stylesheets and preconnects)
- Remove stale mariadb entry from serverExternalPackages (app uses mysql2)
- Exclude unused src/generated Prisma client from typecheck and remove it
- Add unit tests for swf-parser, effectmap and figuremap (0% coverage -> 90%+)
2026-08-09 12:12:02 +02:00
openhands 6a67fb6e83 refactor: remove additional dead exports and unused actions
CI / check (push) Successful in 26s
CI / release (push) Skipped
CI / deploy (push) Successful in 59s
Remove buildFontUrl, measureText, uncached, invalidateCache, fetchJsonWithFlareSolver, upsertPermission, deletePermission, bulkImportPermissions, clearAllPermissions, bulkDeletePermissions, bulkDeletePhotos, userReplyTicket, closeTicketByUser. Update staff-smoke-contract test for bulkDeletePhotos removal.
2026-08-07 19:19:05 +02:00
openhands dc8fb8a6ed feat: speed up admin clone import and enable Cache Components
- Clone import: defer FurnitureData.json writes and append all entries in a
  single batched write instead of one read-modify-write per item, removing
  the main serialization bottleneck for large batches.
- Clone import: raise SSE batch concurrency cap from 5 to 10 and bump the
  clone client/route default from 2 to 6.
- Add a flush hook to runSseBatch so callers can batch deferred work before
  batch_complete is emitted, and surface flush errors as an error event.
- Enable Next.js Cache Components (instant: false opt-out) and silence the
  related build warnings in next.config.ts.
- Switch isomorphic-dompurify to dompurify and refresh dependencies.
2026-08-05 11:10:16 +02:00
openhands b87c9a5b8d chore: remove puppeteer CF bypass (not working for Leet/Hubbly/Habblet)
CI / check (push) Failing after 14s
CI / release (push) Skipped
CI / deploy (push) Skipped
Cloudflare has strengthened protection on these hotels.
Puppeteer-based bypass returns HTML instead of JSON.
cloudscraper has dependency issues with Node.js v26.

Reverted to simple HTTP fetch with clear error messages.
2026-08-04 18:45:10 +02:00
openhands 0bf6133775 fix: add puppeteer packages to serverExternalPackages to prevent Next.js build errors
CI / check (push) Successful in 25s
CI / release (push) Skipped
CI / deploy (push) Successful in 49s
2026-08-04 18:09:08 +02:00
Simo 1f4aadb3d7 chore: remove Sentry integration
CI / check (push) Successful in 21s
CI / release (push) Skipped
CI / deploy (push) Successful in 53s
2026-08-01 22:12:31 +02:00
Simo d173dd3194 fix: add automatic deployment skew protection
CI / check (push) Successful in 37s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m28s
2026-08-01 21:52:28 +02:00
openhands 0d6032d444 chore: remove standalone output mode, fix Sentry DSN validation, add dev CSP unsafe-inline for styles
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m15s
- Remove output: 'standalone' from next.config.ts to allow normal 'next start'
- Allow empty SENTRY_DSN/NEXT_PUBLIC_SENTRY_DSN in env validation (zod)
- Add 'unsafe-inline' to style-src CSP only in development for Turbopack HMR
- Clear placeholder Sentry DSN values from .env
2026-08-01 21:30:51 +02:00
openhands 7f7971f578 fix: resolve all biome lint errors and type issues
CI / check (push) Successful in 30s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m26s
- Add file-level biome-ignore for noExplicitAny in prisma-facade.ts
  (intentional any for Prisma API compatibility surface)
- Fix noNonNullAssertion errors in cached-db.ts (redis null-guard fixes)
- Auto-fix formatting + organizeImports across modified files
- 0 tsc errors, 0 biome errors, 583 tests passing
2026-07-31 15:15:15 +02:00
openhands 2f030deb42 fix: switch Google Fonts to runtime <link> tags for build environments without internet
CI / check (push) Successful in 33s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m38s
- Replace next/font/google with <link> tags in <head> (loads fonts client-side at runtime)
- Define --font-nunito and --font-pixel CSS variables in globals.css with font-family fallbacks
- Remove @prisma/client from serverExternalPackages in next.config.ts (devDep only)
2026-07-31 14:33:33 +02:00
openhands 583d05eee9 feat: modernize with Next.js 16 standalone output, remove redundant babel compiler, update postcss
CI / check (push) Failing after 6s
Deploy / release (push) Skipped
CI / deploy (push) Skipped
Deploy / deploy (push) Failing after 5s
- Remove babel-plugin-react-compiler (Next.js 16 has built-in reactCompiler)
- Update postcss to 8.5.25
- Add output: 'standalone' to next.config.ts for smaller/faster deployments
- Update ecosystem.config.cjs to use standalone server.js
2026-07-30 20:00:31 +02:00
openhands 9ea67ecf72 fix: add useTypeScriptCli experimental flag for typescript 7 support
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m5s
2026-07-28 19:25:13 +02:00
openhands 0f5c190ab1 Suppress Sentry release warning when no auth token
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m55s
2026-07-26 21:50:31 +02:00
openhands 17847545dd Improvements: remove dead config, fix ESM, add URL validation, unify types, add missing logging
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m52s
- Remove .prettierrc (dead config, Biome replaces Prettier)
- Rename lighthouserc.json to lighthouserc.cjs with module.exports for ESM compat
- Add logger.warn to empty catch blocks in auth, register, site-settings, prisma-cache, redis, security, rate-limit
- Unify ActionResult type: action-helper.ts uses 'ok' consistent with safe-action-shared.ts
- Add noUnusedLocals + noUnusedParameters to tsconfig + fix 25 pre-existing unused vars
- Replace barrel export src/types/index.ts with direct @/types/common imports
- Make trustHost conditional (development only) in auth.ts
- Add pre-flight URL validation to update-Nitrov3.sh to catch image.library.url misconfigurations
- Improve NITRO_IMAGE_LIBRARY_URL content validation in pre-flight & post-compute checks
2026-07-26 20:28:11 +02:00
openhands 3773c6cb29 chore: switch from standalone to normal next start
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 2s
- Remove output:standalone from next.config.ts
- Remove postbuild standalone copy script
- Change start script from standalone/server.js to next start
- Update PM2 to run pnpm start
2026-07-24 13:57:21 +02:00
openhands a9f1f4f99d Fix Turbopack NFT warning
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 2m47s
- Remove import.meta.dirname from turbopack config (unnecessary filesystem op)
- Add /*turbopackIgnore: true*/ to 3 path.join calls in upload-import.ts
  that were missing the comment, causing Turbopack to trace the whole
  project unintentionally
2026-07-23 20:57:43 +02:00
openhands 7fc7412f18 Remove experimental Next.js config options
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 2m25s
staleTimes, optimizePackageImports, and staticGenerationMaxConcurrency
were all experimental-only in Next.js 16. Removed them:

- staleTimes: router cache defaults are sufficient
- optimizePackageImports: Turbopack already tree-shakes lucide-react
- staticGenerationMaxConcurrency: mitigated by DATABASE_POOL_SIZE=5

Eliminates the 'Experiments (use with caution)' warning for our custom
options. Only clientTraceMetadata remains (Next.js framework default).
2026-07-23 19:50:17 +02:00
openhands b0ad3a128e fix: resolve turbopack NFT warning and disable Sentry telemetry
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m46s
2026-07-21 23:49:23 +02:00
openhands 3608cb50cc fix: disable Next.js telemetry and enable build cache
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m37s
2026-07-21 23:44:26 +02:00
SimoandCursor 77931db775 fix: cap Prisma pool during next build to stop deploy SSG timeouts
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m28s
Next build workers were each opening up to DATABASE_POOL_SIZE connections and exhausting MySQL (pool active=0), hanging sitemap generation. Cap build pool to 5, fail connect faster, limit SSG concurrency, and make sitemap dynamic.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:28:27 +02:00
SimoandCursor 9b47668fe9 chore: CSP script nonces, deploy health check, dead-code cleanup
Add per-request CSP nonces (drop script unsafe-inline), post-deploy /api/health gate, bump next-auth to beta.32, and remove unused motion/cache/permission helpers.

Co-authored-by: Cursor <[email protected]>
2026-07-21 20:27:08 +02:00
openhands 2beba07ba5 feat: enable React Compiler, optimizePackageImports for lucide-react, add loading states for (site) and client routes
Local Build and Deploy / deploy (push) Successful in 1m19s
2026-07-20 14:25:12 +02:00
openhands ccd4994028 feat: enable React Compiler, add Redis caching for API routes, update README with requirements and install guide
Local Build and Deploy / deploy (push) Failing after 57s
2026-07-20 14:14:49 +02:00
openhands f53d25e0a5 feat: add view transitions, smooth scroll, bundle analyzer, SSE radio stream, and AnimatePresence animations
Local Build and Deploy / deploy (push) Successful in 1m24s
2026-07-20 14:06:43 +02:00
SimoandCursor 549a2fab5c Silence Sentry build warnings when no auth token is set.
Skip release creation alongside source-map upload so production compile does not warn about missing SENTRY_AUTH_TOKEN.

Co-authored-by: Cursor <[email protected]>
2026-07-18 21:32:25 +02:00
openhands 0d82f1325e Fix DB connect_timeout warning and remove deprecated Sentry disableLogger
Local Build and Deploy / deploy (push) Successful in 1m10s
2026-07-18 16:54:20 +02:00
SimoandCursor 09f1bc2bd6 Add production observability: Sentry, pino, and sharp badge encoding.
Local Build and Deploy / deploy (push) Successful in 1m9s
Sentry is opt-in via DSN env vars; logger uses structured pino JSON in prod; badge uploads are normalized to GIF with sharp.

Co-authored-by: Cursor <[email protected]>
2026-07-17 23:09:57 +02:00
openhands df38dccbf1 style: format code biome
Local Build and Deploy / deploy (push) Failing after 46s
2026-07-13 21:57:41 +02:00
Simo c0ffc74f9b fix: externalize lzma for import build
Local Build and Deploy / deploy (push) Successful in 49s
2026-07-12 19:15:08 +02:00
Simo 5b4228261a Reapply "Add missing admin action files and navigation links"
This reverts commit 4d515bc400.
2026-07-11 20:52:56 +02:00
Simo 4d515bc400 Revert "Add missing admin action files and navigation links"
This reverts commit 41be6835bf.
2026-07-11 20:37:56 +02:00
openhands 41be6835bf Add missing admin action files and navigation links
- Add 11 missing server action files: badges, bulk-users, catalog, catalog-bc, catalog-items, import-badges, import-furni, multi-account-detect, permissions, rooms, soundtracks
- Add missing admin navigation links: tickets, sounds, translations, import, radio sub-pages
- Add translation keys for all new navigation items
2026-07-11 12:01:05 +02:00
openhands deac10e00a Add in-memory caching for online count, enable compression, and add staleTimes for router cache 2026-07-09 18:24:58 +02:00
openhands c9d951aa86 Fix login CSP and auth host trust 2026-07-04 20:04:44 +02:00
openhands 10523e58ce Fix remaining security vulnerabilities
- H1: Add missing sanitize() to help center content rendering
- H2: Tighten CSP by removing unsafe-inline/unsafe-eval from script-src;
  move theme init to external JS file with meta tag for defaultDark
- M1: Add SSRF protection for radio API URLs (block private IPs)
- M2: Add rate limiting to SSO ticket endpoint (5 req/30s per user)
- M4: Document locale validation safety in i18n dynamic import
- L1: Truncate stacktraces in admin commandocentrum to first 20 lines
2026-07-04 19:10:43 +02:00
openhands 5628e7d6b7 Security hardening: 12 improvements across the stack
1. env.ts: APP_KEY placeholder detection with validation
2. schema.prisma: password column widened to varchar(255) for argon2id
3. auth.ts: trustHost restricted to development only
4. next.config.ts: added CSP, HSTS, X-Frame-Options, and other security headers
5. api.ts: CORS restricted to APP_URL instead of wildcard
6. register-form.tsx: migrated from REST API fetch to server action (useActionState)
7. twofactor.ts + 2fa page: TOTP recovery codes (8 one-time codes, generated and displayed)
8. register.ts: password min length 8 + complexity requirements (upper, lower, digit)
9. register.ts + help-tickets.ts + radio-shouts.ts: Zod schema validation
10. rate-limit.ts: improved periodic cleanup with aggressive eviction at 10k buckets
11. guard.ts + admin actions: rate-limited admin actions (30 req/min per staff)
12. help-tickets.ts + radio-shouts.ts: content moderation via moderateOrThrow
2026-07-04 18:52:00 +02:00