Simo
816e3875c2
feat(admin): add production error center and refresh CMS dependencies
2026-09-05 19:53:09 +02:00
Simo
9ec9ab31ad
feat: export Catalog Studio assets and SQL to catalog repository
CI / check (pull_request) Failing after 1m21s
CI / deploy (pull_request) Skipped
CI / e2e (pull_request) Skipped
2026-09-05 11:49:00 +02:00
openhands
399c047515
fix: harden admin actions, search, sanitization and repo hygiene
...
CI / check (push) Successful in 1m21s
CI / deploy (push) Successful in 1m25s
- Split approve/dismiss application workflows with distinct audit logs,
rate-limited guards and real error logging
- Validate article status/date/id input and stop resetting publishedAt
on every update
- Validate guild updates (state, forum enums, non-empty name) behind
rate-limited guard
- Fix scheduled-article publishing (ignore NULL dates, set updatedAt,
type-safe predicates)
- Harden admin search API (LIKE escaping, query cap, per-user
rate limit, round-robin result cap) and fix search dialog
abort/res.ok/loading races
- Lock down HTML sanitizer to an allowlist profile and add XSS tests
- Improve mobile nav accessibility (unique id, dialog role, focus
management, scroll lock, outside close)
- Log swallowed server errors instead of silent catch blocks
- Remove dead eslint config, drop unused dompurify deps, restore knip
CI step, add Playwright config with smoke spec
2026-09-04 13:04:08 +02:00
openhands
30c95b1a5c
feat: comprehensive CMS improvements
...
CI / runtime-diagnostics (push) Skipped
CI / release (push) Skipped
CI / check (push) Failing after 0s
CI / deploy (push) Skipped
- Fix DOMPurify SSR crash (use isomorphic-dompurify)
- Fix SanitizedHtml to sanitize by default
- Add auth guards to studio/catalog maintenance pages
- Add update/edit to vouchers CRUD
- Add update/edit to rare-values CRUD
- Add approve workflow to applications page
- Add edit form to guilds detail page
- Add SEO metadata to all public pages (21 pages)
- Fix mobile nav accessibility (focus trap, aria attributes)
- Fix missing labels and table accessibility
- Add dynamic imports for heavy client components (6 components)
- Fix silent error swallowing (40+ locations)
- Add content scheduling for articles (publishAt, status)
- Wire up 12 missing webhook notification triggers
- Add global search to admin panel
- Add bulk actions to admin users table
- Fix JSON formatting and a11y issues
2026-09-03 16:00:32 +02:00
openhands
037b295b93
feat(ci): automated docker update script + nightly cron
...
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 33s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m3s
- scripts/docker-update.sh: git pull --ff-only, host db:migrate, docker compose
build + up -d, health-check wait, keeps host-side PM2 'next' stopped.
Fails safe on dirty working tree (exit 1) and on health failure (exit 3).
- cron entry: daily 03:30 -> logs/docker-update.cron.log
- README: Automatic Updates section + docker commands row
2026-09-02 12:25:42 +02:00
openhands
58c35a2920
feat: enforce no hardcoded colors across entire CMS
...
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 32s
CI / release (push) Skipped
CI / deploy (push) Successful in 58s
Added scripts/check-admin-colors.mjs — scans all src/ files for:
- text-white, text-black (use theme text vars)
- bg-white, bg-black (use theme background/overlay vars)
- bg/text/border/ring with gray/slate/zinc/stone palette
- bg/text/border/ring with red/green/blue/etc palette
Fixed 21 violations across 11 files:
- Overlays: bg-black/* → bg-foreground/*
- Text: text-white → text-primary-foreground
- Backgrounds: bg-white/10 → bg-background/10
- Green accents: bg-green-* → bg-primary
- Red accents: bg-red-* → bg-destructive
Integrated into:
- lint-staged: runs on every *.ts/*.tsx commit
- vitest: src/lib/no-hardcoded-colors.test.ts replaces old audit test
- Allowlist: shadcn/ui primitives (button, badge, dialog) + 4 graphical files
2026-09-01 19:33:50 +02:00
Simo
9a0b6e091a
ci: inspect permission value limits
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 27s
CI / release (push) Skipped
CI / deploy (push) Successful in 43s
2026-08-31 21:19:06 +02:00
Simo
75b85dcdd9
ci: probe permission page database reads
CI / runtime-diagnostics (push) Skipped
CI / check (push) Failing after 27s
CI / release (push) Skipped
CI / deploy (push) Skipped
2026-08-31 21:13:03 +02:00
Simo
b1ddda66ff
Revert "Merge pull request 'Complete Housekeeping migration and /ase cutover' ( #52 ) from codex/housekeeping-complete into main"
...
CI / check (push) Successful in 27s
CI / release (push) Skipped
CI / deploy (push) Successful in 43s
This reverts commit 488b6e57c4 , reversing
changes made to b506b4499a .
2026-08-30 21:31:34 +02:00
Simo
2b8f73a91d
feat(housekeeping): cut over administration to ase
2026-08-30 20:35:22 +02:00
Simo
8a31556d51
test(housekeeping): prove 137 route parity
CI / check (pull_request) Successful in 1m9s
CI / release (pull_request) Skipped
CI / deploy (pull_request) Skipped
2026-08-30 19:11:14 +02:00
openhands
d57424a9ee
style: fix biome formatting in sync-nitro-urls
CI / check (push) Successful in 27s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m3s
2026-08-30 18:24:07 +02:00
openhands
678d22ceab
feat: bulletproof updater + fixes for client links (icons/furniture/gamedata)
CI / check (push) Failing after 8s
CI / release (push) Skipped
CI / deploy (push) Skipped
2026-08-30 18:19:46 +02:00
Simo
2a36ba1956
Merge branch 'main' into codex/housekeeping-foundation
CI / check (pull_request) Successful in 28s
CI / release (pull_request) Skipped
CI / deploy (pull_request) Skipped
2026-08-26 19:50:26 +02:00
openhands
e7f70bb429
Chore: remove unused e2e register debug script
...
Flagged by knip as unused. It was a one-off DB smoke test with a
hardcoded database password that should never have been committed.
2026-08-26 15:06:14 +02:00
openhands
2d09a4a92c
Add missing migrations
CI / check (push) Failing after 26s
CI / deploy (push) Skipped
CI / release (push) Skipped
2026-08-26 14:28:28 +02:00
openhands
4eded4ec61
Apply Biome lint fixes
CI / check (push) Failing after 26s
CI / release (push) Skipped
CI / deploy (push) Skipped
2026-08-25 22:26:05 +02:00
openhands
a5044c80d7
fix: resolve biome linter warnings and code formatting
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Successful in 46s
2026-08-25 21:54:02 +02:00
openhands
416c31643b
perf: optimize dashboard database queries and remove unused imports
CI / check (push) Failing after 10s
CI / deploy (push) Skipped
CI / release (push) Skipped
2026-08-25 21:52:18 +02:00
Simo
3b3d7780c9
docs: complete housekeeping migration matrix
2026-08-25 18:49:58 +02:00
Simo
6ed1b03e24
chore: align Node 26.7.0 toolchain
CI / check (push) Successful in 35s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m0s
2026-08-24 19:12:11 +02:00
openhands
ca1756fbb0
Fix pre-existing type errors in diagnostics scripts (blocked pre-push tsc hook)
CI / check (push) Failing after 31s
CI / release (push) Skipped
CI / deploy (push) Skipped
2026-08-23 15:07:58 +02:00
openhands
536b61c7e7
Add catalog maintenance page with sprite-id, dedup and FurnitureData id-alignment repairs
2026-08-23 15:05:49 +02:00
openhands
3d832cceff
scripts: fix translate call for furni18n
CI / check (push) Failing after 28s
CI / release (push) Skipped
CI / deploy (push) Skipped
2026-08-21 20:06:27 +02:00
openhands
f2a023efb3
scripts: fix build/translate calls for furni18n
2026-08-21 20:06:02 +02:00
openhands
e66b2c1a5a
scripts: add full build/translate scripts for furnidata i18n
2026-08-21 20:04:53 +02:00
openhands
9e453666e5
fix: use jsonc-parser in config merge and make updater reliably restart all services
...
CI / check (push) Successful in 25s
CI / release (push) Skipped
CI / deploy (push) Successful in 58s
merge-config.cjs loaded json5 (not installed, and unable to parse JSONC
comments), so sync_configs crashed mid-update and do_restart never ran —
leaving the emulator running the old JAR.
- merge-config.cjs: switch from json5 to jsonc-parser (already a
dependency) to parse .jsonc configs including comments
- update-Nitrov3.sh: always run renderer/client parallel builds instead
of gating them on the emulator's update status
- update-Nitrov3.sh: isolate each repo's yarn cache (--cache-folder) so
parallel installs can't corrupt a shared cache and silently drop
vite/pixi.js; replace invalid --no-cache flag with per-repo cache reset
- update-Nitrov3.sh: fix misleading [DRY-RUN] label on real updates
2026-08-11 19:06:29 +02:00
openhands
abc06e438c
fix: load .env in standalone tsx scripts
CI / check (push) Successful in 25s
CI / release (push) Skipped
CI / deploy (push) Successful in 52s
2026-08-11 17:08:23 +02:00
openhands
e867b675fc
fix: replace jsonc with jsonc-parser and cleanup build config
2026-08-11 16:50:10 +02:00
openhands
3edc987281
feat: integrate FlareSolverr for Cloudflare bypass on clone sources
...
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 46s
- Add FLARESOLVERR_URL env var to .env.example
- Update fetchSourceFurnidata to fall back to FlareSolverr on CF challenges (403/HTML)
- Add docker-compose.yml with FlareSolverr service
- Add scripts/health-check.sh for FlareSolverr readiness check
- Add health:check script to package.json
- Document FlareSolverr setup in README
2026-08-04 19:00:30 +02:00
openhands
2e87e5bf09
chore: remove test-cf.ts (puppeteer no longer used)
CI / check (push) Successful in 25s
CI / release (push) Skipped
CI / deploy (push) Successful in 56s
2026-08-04 18:46:31 +02:00
openhands
9fbfd2f51a
chore: verify clone sources with Cloudflare bypass test script; remove broken Hubbly URLs
...
CI / check (push) Successful in 26s
CI / release (push) Skipped
CI / deploy (push) Successful in 55s
Verified working sources via puppeteer Cloudflare bypass test:
- Habbo (GitHub) - 200
- Wibbo - 200 furnidata, 403/403 nitro/icons
- Hubba.cc - 200 furnidata, 404 nitro
- Leet - 200 304 304 (all working)
- Habblet City - 200 200 200 (all working)
- Soda Ho - 200 furnidata, 404 nitro/icons
Cloudflare-blocked sources removed (habba.io, habcrush.pw, fobba.net, etc)
Hubbly URLs removed (all 404) pending verification
Added test-cf.ts script for future source validation
2026-08-04 17:28:01 +02:00
Simo
1f4aadb3d7
chore: remove Sentry integration
CI / check (push) Successful in 21s
CI / release (push) Skipped
CI / deploy (push) Successful in 53s
2026-08-01 22:12:31 +02:00
openhands
14a3de0f2a
style(scripts): format schema generator to satisfy biome check
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Failing after 1m0s
2026-08-01 17:50:16 +02:00
openhands
8275842e78
fix(scripts): resolve noAssignInExpressions lint error in schema generator
CI / check (push) Successful in 30s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m28s
2026-08-01 17:14:48 +02:00
Simo and Cursor
db957d7fb1
fix(ops): narrow DB_BACKUP_DIR for jobs-worker typecheck
...
CI / check (push) Failing after 9s
CI / release (push) Skipped
CI / deploy (push) Skipped
Co-authored-by: Cursor <[email protected] >
2026-08-01 15:27:01 +02:00
Simo and Cursor
725e1cb338
feat(ops): health-fail alerts, optional DB backup, admin UX polish
...
Wire jobs-worker health probes to Discord/email alerts with cooldown, optional mysqldump, rate-limit /api/health, mark-all-read alerts, ConfirmDialog on destructive admin actions, and raise coverage floors.
Co-authored-by: Cursor <[email protected] >
2026-08-01 15:25:47 +02:00
Simo and Cursor
ba82789166
chore(db): finish Prisma cutover to Drizzle Kit tooling
...
CI / check (push) Failing after 9s
CI / release (push) Skipped
CI / deploy (push) Skipped
Move CMS SQL to drizzle/migrations, drop prisma packages/schema, wire drizzle-kit scripts, and regenerate schema names from src/db/schema.ts.
Co-authored-by: Cursor <[email protected] >
2026-08-01 15:02:21 +02:00
Simo and Cursor
422567272c
chore(db): remove Prisma facade and drop prisma:generate from CI
...
Co-authored-by: Cursor <[email protected] >
2026-08-01 14:38:42 +02:00
openhands
e5ff7ec9e5
chore: clean up biome lint warnings — all non- intentional resolved
...
CI / check (push) Successful in 33s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m25s
- Remove 25 unused imports across 14 test files
- Remove 1 unused variable (rename with _ prefix)
- Fix 2 noBannedTypes (Function → (...args: unknown[]) => unknown)
- Fix 1 useTemplate lint (string concat → template literal in merge-config.cjs)
- Fix 1 useNodejsImportProtocol (merge-config.cjs)
- Fix 2 noTemplateCurlyInString (generate-drizzle-schema.mjs generator code)
- Auto-fix formatting + import sorting across modified files
- 221 remaining warnings: intentional noExplicitAny in prisma-facade.ts (Prisma compat layer)
- 0 tsc errors, 583 tests passing
2026-07-31 15:26:39 +02:00
openhands
beae86194d
fix: resolve biome lint errors in prisma-facade
...
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Failing after 1m23s
- Fix noPrecisionLoss on BIGINT UNSIGNED max value (2^64-1) with biome-ignore comments
- Fix noThenProperty on custom thenable with biome-ignore comment
- Auto-format remaining files (biome check --write)
- Re-stage auto-fixed files from previous commit
2026-07-31 14:17:06 +02:00
openhands
56061e41d4
refactor: replace Prisma ORM runtime with Drizzle ORM facade
...
CI / check (push) Failing after 12s
CI / deploy (push) Skipped
CI / release (push) Skipped
- Replace Prisma client runtime with Drizzle ORM (zero Prisma engine/query engine in production)
- Add Prisma-compatible facade (@/lib/prisma-facade.ts) backed by Drizzle for backwards compatibility
- Runtime queries route through Drizzle ORM; @prisma/client is now devDependency (types only)
- Remove @prisma/adapter-mariadb dependency; delete prisma-pool.ts and types/prisma.ts
- New Drizzle schema layer: src/db/schema.ts (176 tables) and src/lib/db.ts (connection)
- Update README documenting the dual-layer ORM architecture
- Restore src/generated/ gitignore (build artifact for local type generation)
- 0 TypeScript errors, 583 tests passing
The facade intentionally uses `any` types to match the Prisma Client API surface,
allowing existing code to run unmodified while routing queries through Drizzle at runtime.
2026-07-31 14:11:03 +02:00
openhands
91357aca3b
ci: fix Gitea Actions workflow
2026-07-30 17:51:24 +02:00
openhands
17847545dd
Improvements: remove dead config, fix ESM, add URL validation, unify types, add missing logging
...
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m52s
- Remove .prettierrc (dead config, Biome replaces Prettier)
- Rename lighthouserc.json to lighthouserc.cjs with module.exports for ESM compat
- Add logger.warn to empty catch blocks in auth, register, site-settings, prisma-cache, redis, security, rate-limit
- Unify ActionResult type: action-helper.ts uses 'ok' consistent with safe-action-shared.ts
- Add noUnusedLocals + noUnusedParameters to tsconfig + fix 25 pre-existing unused vars
- Replace barrel export src/types/index.ts with direct @/types/common imports
- Make trustHost conditional (development only) in auth.ts
- Add pre-flight URL validation to update-Nitrov3.sh to catch image.library.url misconfigurations
- Improve NITRO_IMAGE_LIBRARY_URL content validation in pre-flight & post-compute checks
2026-07-26 20:28:11 +02:00
openhands
1acace49d0
refactor: full codebase overhaul — dead code removal, env validation, logger migration, date consolidation, Prisma schema cleanup, button consistency, useEffect deps, test coverage
...
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 8s
- env.ts: added 10 missing Zod-validated env vars (imager, paypal currency, argon2/bcrypt params)
- Migrated 6 modules from process.env to validated env.* (auth, proxy-auth, paypal, password, redis, imager, moderation, alert, logger)
- Replaced console.warn/error with pino logger in 9 server-side modules
- Removed 50+ dead exports (SWF wrappers, coalesceHotelName, signIn, isStaff re-export, formatTimestamp, Skeleton/SkeletonCard, 4 unused housekeeping sections)
- Consolidated date formatting: 28 files migrated to shared formatDate() from @/lib/format-date
- Wired 4 radio/settings API routes through cached siteSettings service instead of raw Prisma queries
- Added getMany()/getAll() helpers to SiteSettings service
- Removed 88 dead Prisma model definitions (schema 2763→1846 lines)
- Created admin action-helper.ts with wrapAction() for standardized error handling
- Fixed useEffect dependency arrays in 4 data-heavy components
- Replaced raw btn CSS classes with shadcn Button component across admin pages
- Stripped dead i18n namespaces (common, pages.client) from all 22 translation files
- Removed 2 dead scripts (create-release.sh, check-local-imports.ts)
- Fixed knip.json configuration
- Added 7 new test suites: format-date, paypal, moderation, alert, webhook, action-helper, and fixed password.test.ts for env mocking
- All 358 tests passing across 72 test files
- TypeScript: 0 errors
2026-07-25 17:33:06 +02:00
openhands
f7f6e09174
Fix migration connection exhaustion and polish auth pages
...
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m49s
- apply-migrations.ts: use single shared connection instead of one per operation
- Increase MariaDB max_connections from 151 to 300 in server config
- home-login-form.tsx: replace hardcoded gray colors with theme variables
- register-form.tsx: add password strength meter, spinner, theme-aligned inputs
- login-form.tsx: add Discord/Google SVG icons, spinner, smoother 2FA animation
- page/register/login: apply premium animations (float, stagger, glow, gradient)
2026-07-24 11:30:58 +02:00
openhands
7eb3ba1ce8
feat: add create-release.sh for manual release creation
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m30s
2026-07-20 15:56:45 +02:00
Simo and Cursor
6b884ad25a
Harden deploy gates, prod AUTH_SECRET, and Sentry error reporting.
...
Local Build and Deploy / deploy (push) Successful in 1m42s
Align onlyBuiltDependencies with the workspace, fail fast without AUTH_SECRET in production, and delete catalog_items via VARCHAR-safe SQL so page deletes do not leave orphans.
Co-authored-by: Cursor <[email protected] >
2026-07-18 19:32:15 +02:00
openhands
0d82f1325e
Fix DB connect_timeout warning and remove deprecated Sentry disableLogger
Local Build and Deploy / deploy (push) Successful in 1m10s
2026-07-18 16:54:20 +02:00
Simo and Cursor
09f1bc2bd6
Add production observability: Sentry, pino, and sharp badge encoding.
...
Local Build and Deploy / deploy (push) Successful in 1m9s
Sentry is opt-in via DSN env vars; logger uses structured pino JSON in prod; badge uploads are normalized to GIF with sharp.
Co-authored-by: Cursor <[email protected] >
2026-07-17 23:09:57 +02:00