Commit Graph
100 Commits
Author SHA1 Message Date
openhands 57ef6289ff fix: generate changelog via Python subprocess for reliability
Local Build and Deploy / deploy (push) Successful in 1m26s
Previous approaches using temp files or env vars failed in Gitea runner.
Python now runs git commands directly via subprocess, reads stdout,
and builds the JSON payload — no intermediate files or shell escaping.
2026-07-20 15:21:12 +02:00
openhands 80bf3bb0d5 fix: use local checkout for changelog generation
Local Build and Deploy / deploy (push) Successful in 1m26s
Bare git repo has no HEAD; git log without --all showed nothing.
Now uses /var/www/atom-nexst (full checkout with proper HEAD).
Also adds debug output and handles first-release edge case.
2026-07-20 15:16:19 +02:00
openhands 15ed8ffbf0 fix: generate release changelog from full local repo
Local Build and Deploy / deploy (push) Successful in 1m23s
Shallow clone (depth 1) only has one commit, so git log was empty.
Now generates changelog from the bare repo before cloning, and uses
Python to build the JSON payload for proper multiline escaping.
2026-07-20 15:11:59 +02:00
openhands aea9d83865 refactor: rewrite updater to v8.0 — faster, stabler, more features
Local Build and Deploy / deploy (push) Successful in 1m28s
Faster:
- Parallel Maven builds (-T 1C, skip tests)
- yarn install with --prefer-offline
- Renderer + client installs run in parallel via parallel_run()
- Skip building if no upstream changes
- Dev mode (--only=dev) skips all builds, just syncs configs

Stabler:
- Flock-based lockfile prevents concurrent runs
- Preflight check function with fatal error handling
- Config backup before overwriting (rollback on crash)
- JSON config validation after syncing
- Disk space warning at 50% threshold
- Better Maven error logging (last 20 lines)
- Redis flush after config sync (immediate effect)
- Automatic cleanup of old config backups (keep 10)

New features:
- Dev mode (menu option 19) — skip builds, configs + restart only
- Git stash viewer (menu option 20 / stash command)
- Emulator journal viewer (service menu option 8)
- Docker system prune (clean menu option 6)
- Maven artifact cleanup (clean menu option 7)
- DB processlist viewer (database menu option 7)
- Git ahead/behind indicators in status dashboard
- Program renamed to SMaRT v8.0.0
2026-07-20 15:10:17 +02:00
openhands df604bf432 fix: copy .env into temp clone for Prisma build
Local Build and Deploy / deploy (push) Successful in 1m37s
Create Release / release (push) Successful in 1m2s
2026-07-20 15:06:25 +02:00
openhands 73a36d503a fix: combine release workflow into single run block
Local Build and Deploy / deploy (push) Successful in 1m37s
Create Release / release (push) Failing after 13s
Each Gitea Actions step is a separate shell session; git context did not
persist between steps. All steps are now in one run block.
2026-07-20 15:03:11 +02:00
openhands 9b8a0e5075 ci: add Gitea release workflow on tag push
Local Build and Deploy / deploy (push) Successful in 1m25s
Create Release / release (push) Failing after 0s
Creates an automated Gitea release with changelog when a tag (v*) is pushed.
Requires GITEA_TOKEN secret in Gitea with repository write access.
2026-07-20 14:59:51 +02:00
openhands c8ccbe1f42 perf: add Prisma query caching, ISR for news pages, and aggressive SW caching
- Introduce redis-backed Prisma query cache (prisma-cache.ts) with per-model TTL
- Replace force-dynamic with revalidate=60 + generateStaticParams on news/[slug]
- Wrap article query with Redis cache (60s TTL)
- Upgrade service worker to v2 with dedicated API cache and stale-while-revalidate
  for static assets
2026-07-20 14:54:55 +02:00
openhands d5e3bc7875 refactor: mark dead exports with TODO, deduplicate field sanitization, fix import placement
Local Build and Deploy / deploy (push) Successful in 1m36s
2026-07-20 14:47:05 +02:00
openhands 2beba07ba5 feat: enable React Compiler, optimizePackageImports for lucide-react, add loading states for (site) and client routes
Local Build and Deploy / deploy (push) Successful in 1m19s
2026-07-20 14:25:12 +02:00
openhands ccd4994028 feat: enable React Compiler, add Redis caching for API routes, update README with requirements and install guide
Local Build and Deploy / deploy (push) Failing after 57s
2026-07-20 14:14:49 +02:00
openhands f53d25e0a5 feat: add view transitions, smooth scroll, bundle analyzer, SSE radio stream, and AnimatePresence animations
Local Build and Deploy / deploy (push) Successful in 1m24s
2026-07-20 14:06:43 +02:00
openhands 8ccade73cc chore: verified clean state, type-safety refactor and deploy fix in place
Local Build and Deploy / deploy (push) Successful in 1m27s
2026-07-18 20:53:01 +02:00
openhands 3eaffe658d refactor: remove explicit any across admin forms and catalog actions
Local Build and Deploy / deploy (push) Canceled after 40s
- Type resolveAsChild generically over Base UI render-prop type
- Type catalog/rooms/catalog-items Prisma updates with Prisma.*UpdateInput
- Type EventForm/PollForm with explicit form-value interfaces
- Type EventPrizesManager/PollQuestionsManager with validator input types
- All typecheck, lint, and 312 tests pass
2026-07-18 20:31:18 +02:00
openhands 907a4399d0 refactor: type PollQuestionsManager form with PollQuestionInput 2026-07-18 20:31:18 +02:00
openhands 0d027dba99 refactor: type EventPrizesManager form with EventPrizeInput 2026-07-18 20:31:18 +02:00
openhands 41f5269b4e refactor: type PollForm with explicit PollFormValues 2026-07-18 20:31:18 +02:00
openhands 4991008159 refactor: type EventForm with explicit EventFormValues 2026-07-18 20:31:18 +02:00
openhands b9c6001f08 refactor: centralize duplicated formatDate helper
Local Build and Deploy / deploy (push) Successful in 1m7s
21 files defined their own local formatDate (with three different output
formats: date, datetime, datetime-seconds, and varying null fallbacks).
Replace them with a single shared helper at src/lib/format-date.ts that
takes a variant + optional fallback, preserving the exact previous output
per call site (verified identical string results).

Removes ~21 copies of the same logic. photos.tsx and media-grid.tsx keep
their epoch-ms based formatters since those are a different input shape.

Verified: tsc --noEmit clean, full test suite green (301/301).
2026-07-18 19:17:17 +02:00
openhands 3c9c1311ec chore: remove dead code flagged by knip
Local Build and Deploy / deploy (push) Successful in 1m7s
Remove 19 unused source files (no importers anywhere in src/):
- src/actions/admin-permissions.ts, admin-radio.ts, admin-user-edit.ts,
  admin-users.ts (functionality lives in @/actions/users and
  @/actions/permissions)
- src/components/admin/confirm-action.tsx, page-header.tsx
- src/components/motion-elements.tsx
- src/lib/format-date.ts
- src/lib/catalog-categories/* (incl. re-export barrel)
- src/lib/foundation/{index,database,middleware,validation}.ts (errors/action
  kept, still imported directly)
- src/lib/services/imager/{avatar-renderer,memory-cache}.ts
- src/lib/services/nitro-assets.ts

Update admin-operations-contract test to drop the two removed action-file
gates (their permission coverage already exists in users.ts/permissions.ts).

Add knip.json for repeatable dead-code audits.

Verified: tsc --noEmit clean, next build succeeds, full test suite green
(301/301).
2026-07-18 19:08:17 +02:00
openhands 60eb45be73 fix(admin): use theme-aware destructive foreground instead of hardcoded text-white
Local Build and Deploy / deploy (push) Successful in 1m14s
The danger confirm button used a hardcoded text-white class which failed the
admin theme source audit and could render unreadable against custom admin
themes. Switch to the semantic text-destructive-foreground token.

Also add media-grid.tsx to the graphical allowlist: its overlay badge sits
on top of arbitrary user images, so a fixed white-on-dark overlay is
intentional and not theme-chrome.

Restores the full test suite to green (303/303).
2026-07-18 18:57:14 +02:00
openhands 8292cc8ffb fix(infra): serve full TLS chain for epicnabbo.nl to resolve Cloudflare 525
Local Build and Deploy / deploy (push) Successful in 1m2s
Traefik's ACME resolver stored the epicnabbo.nl leaf certificate without
the Let's Encrypt intermediate. With Cloudflare in Full (strict) mode the
origin TLS handshake failed (HTTP 525), breaking every asset and the whole
site layout (JS/CSS chunks, Nitro client, toolbar).

Configure the epicnabbo router to use a file-based certificate that
includes the full chain (leaf + LE YR2 intermediate), referenced from
dynamic/epicnabbo-tls.yml. Add a regeneration script and README.
2026-07-18 18:37:56 +02:00
openhands 243f8007d9 Fix articles list crash by moving interactive card to client component
Local Build and Deploy / deploy (push) Successful in 1m4s
Extract the article card (thumbnail onError fallback, delete confirmation)
into a Client Component so the admin articles list server page no longer
passes event handlers to server-rendered elements.
2026-07-18 17:45:15 +02:00
openhands 6215074331 Polish admin articles: card grid, thumbnails, author, slug field
Local Build and Deploy / deploy (push) Successful in 1m14s
Replace the plain articles table with a responsive card grid showing
thumbnails, title, date and author. Add a slug field to the article form
with live auto-suggestion, i18n-driven labels, a larger image preview and
delete confirmation. Persist a user-provided slug (falls back to an
auto-generated one) on create and update.
2026-07-18 17:38:01 +02:00
openhands a07d438987 Improve media manager UI: search, delete, drag-and-drop, file meta
Local Build and Deploy / deploy (push) Successful in 1m21s
Add a richer media manager with filename search, per-file delete with
confirmation, drag-and-drop uploads, copy-URL feedback, file size/type/date
metadata, and server-side upload validation that returns errors to the UI.
Extend the /api/media listing with size and uploaded timestamps.
2026-07-18 17:29:01 +02:00
openhands 6a20ccda5c Fix media route cache-control to avoid Cloudflare stale caching
Local Build and Deploy / deploy (push) Successful in 1m6s
2026-07-18 17:21:00 +02:00
openhands 1bbbf6e5a4 Persist media uploads outside public/ to survive rebuilds and redeploys
Local Build and Deploy / deploy (push) Successful in 1m9s
Move media storage from public/assets/images/media to storage/media
(outside Git and public/), so uploaded images, favicons and logos are
preserved across rebuilds and git clean. Add a shared media-storage helper,
update the upload/serve actions and API routes, and gitignore storage/.
2026-07-18 17:04:48 +02:00
openhands 0d82f1325e Fix DB connect_timeout warning and remove deprecated Sentry disableLogger
Local Build and Deploy / deploy (push) Successful in 1m10s
2026-07-18 16:54:20 +02:00
openhands 385cefd0fa fix: move dynamic import with ssr:false to client component wrapper
Local Build and Deploy / deploy (push) Successful in 52s
2026-07-17 21:36:47 +02:00
openhands de9f837da1 fix(i18n/nl): add missing hubs/tickets/cfh sections to Dutch translations
Local Build and Deploy / deploy (push) Successful in 1m14s
2026-07-17 21:05:45 +02:00
openhands b78d691281 fix(i18n): add missing save/importTitle keys, sync admin keys across all languages
Local Build and Deploy / deploy (push) Successful in 1m6s
2026-07-17 20:46:58 +02:00
openhands 604e63da51 fix(i18n): auto-translate housekeeping keys via existing translation pairs
Local Build and Deploy / deploy (push) Successful in 1m12s
For each language, ~55 housekeeping keys that were English fallbacks have
been translated by matching against existing translations in the same file.
Remaining ~35 keys per language stay as English fallbacks where no
existing translation pair was available in that locale.
2026-07-17 20:10:05 +02:00
openhands 5c58a2b469 refactor(housekeeping): sortable columns, inline edit Enter/Escape, select all matching, i18n date
Local Build and Deploy / deploy (push) Successful in 1m0s
- Sortable columns: click headers to sort by permission/description/group/rank
- Inline edit: click rank value to edit, Enter to save, Escape to cancel
- Select all matching button when partial selection is active
- Select-all checkbox shows all-pages selection state
- AuditSection uses Intl.DateTimeFormat with CMS locale instead of toLocaleString
- Add selectAllMatching translation key to all 22 locales
2026-07-17 20:03:42 +02:00
openhands f1e4e32a1e refactor(housekeeping): modal confirm, bulk delete, search debounce, audit inline, form reset
Local Build and Deploy / deploy (push) Successful in 1m6s
- Replace browser confirm() with custom ConfirmModal component
- Add search debounce (300ms) before syncing URL params
- Reset add-permission form after successful submit
- Add bulk select/delete with checkbox column and bulkDeletePermissions action
- AuditSection fetches logs server-side via getAuditLogs and shows inline table
- Add 10 new i18n keys (cancel, confirm, confirmDeletePermission,
  confirmBulkDelete, deleteSelected, confirmClearAllDesc,
  auditTime, auditUser, auditAction, auditTarget) synced to all 22 locales
2026-07-17 19:53:53 +02:00
openhands d693d169dd refactor(housekeeping): return result from bulkImport, remove dead server calls, sync i18n
Local Build and Deploy / deploy (push) Successful in 1m15s
- bulkImportPermissions now returns {count, errors} instead of void
- ImportSection shows per-entry error details in toast
- Remove testRankPermission server action (test is 100% client-side)
- Clean up unused testing state in TestSection
- Sync pages.admin.{import,translations} keys to all 20 languages
- Add importedWithErrors translation key to all locales
2026-07-17 19:44:15 +02:00
openhands 702ab9fc67 fix(i18n): sync housekeeping translation keys to all 20 languages
Local Build and Deploy / deploy (push) Successful in 1m25s
All languages now have the full housekeeping key set (78 keys) from en.json,
including loading, pagination, presets, test, import/export, audit, etc.
Previously only en.json and nl.json had these keys.
2026-07-17 19:36:54 +02:00
openhands c0680d7ae5 fix(i18n): remove trailing commas in en.json and nl.json
Local Build and Deploy / deploy (push) Successful in 1m1s
2026-07-17 19:31:09 +02:00
openhands 70f5e37373 refactor(housekeeping): split client, add loading states, URL persistence, fix dead code
Local Build and Deploy / deploy (push) Failing after 48s
- Split ManageClient into ManageSection, PresetsSection, TestSection,
  ImportSection, ExportSection - each tab only renders what it needs
- Add loading/disabled states to preset, import, export, clear buttons
- Persist search and group filter via URL searchParams (survives refresh)
- Remove dead getAuditHistory export from actions
- Fix testRankPermission - remove unnecessary revalidatePath with JSON result
- Clean up unused errors/count variables in bulkImportPermissions
- Add 'loading' translation key to housekeeping section (en/nl)
2026-07-17 19:28:19 +02:00
openhands 0a350a354e fix(i18n): move toast/pagination keys into housekeeping section
Local Build and Deploy / deploy (push) Failing after 44s
- Move saved, deleted, errorOccurred, emptyInput, invalidJson, imported,
  presetApplied, cleared, invalidRank, testDone, testing, prev, next
  from translations section into pages.admin.housekeeping
- Remove duplicate misplaced keys
2026-07-17 19:23:21 +02:00
openhands 6ba8928791 fix(admin): add client-side search, pagination, toast feedback, confirm dialogs and test result display
Local Build and Deploy / deploy (push) Successful in 1m21s
- Rewrite manage/import/presets/test tabs as client component with sonner toasts
- Add client-side search filtering (no page reload)
- Add pagination (25 per page)
- Add confirm dialog before delete and clear-all
- Show test results inline after submission
- Add toast feedback for import, preset apply, save, delete
- Add prev/next pagination labels
2026-07-17 19:17:12 +02:00
openhands 98d4b715df feat(admin): extend housekeeping permissions page with groups, presets, audit, test, import/export, rank overview and dependency tracking
Local Build and Deploy / deploy (push) Successful in 1m14s
- Add group_name, depends_on and updated_by columns to website_housekeeping_permissions
- Add migration 0016 for new columns
- Rewrite housekeeping page with 7 tabs: Overview, Manage, Import/Export, Rank overview, Presets, Test, Audit log
- Add permission groups/categories with filtering
- Add bulk JSON import/export
- Add rank overview grouped by permission category
- Add permission presets for Moderator (rank 5), Admin (rank 7), Super Admin (rank 8)
- Add audit logging for all permission changes via AdminAuditLog
- Add test mode to check permissions by rank
- Add dependency tracking with warnings for missing dependencies
- Add overview dashboard with statistics
- Add Dutch and English translations for all new features
2026-07-17 19:02:23 +02:00
openhands a3b077c488 feat: add smooth site-wide animations with framer-motion
Local Build and Deploy / deploy (push) Successful in 53s
- Add framer-motion and tailwindcss-animate for transitions
- Add page transitions via AnimatePresence in the site layout
- Convert nav dropdown and mobile menu to animated motion components
- Add entry animation to the radio player widget
- Add reveal/stagger animations to the home page views
- Add shared motion utilities and reusable animated components
2026-07-16 20:58:18 +02:00
openhands ac1b412756 remove outer panel border
Local Build and Deploy / deploy (push) Successful in 1m7s
2026-07-16 16:38:30 +02:00
openhands b71a45e45b fix: fetch real motto from user account in home page
Local Build and Deploy / deploy (push) Successful in 48s
2026-07-16 16:36:41 +02:00
openhands e023210382 feat: use panel-border-color for avatar ring and surface color for username panel
Local Build and Deploy / deploy (push) Successful in 59s
2026-07-16 15:58:49 +02:00
openhands 5cbe303e43 feat: make panel border color configurable via theme editor
Local Build and Deploy / deploy (push) Successful in 47s
- Add panel_border_color to THEME_COLOR_KEYS and base palettes
- Register panel-border-color CSS variable
- Fetch and inject panel_border_color in ThemeVars
- Add Panel border field to admin theme page
- Replace hardcoded #e9b124 with var(--panel-border-color) in UserView
2026-07-16 15:53:53 +02:00
openhands ddb7e77877 Make imager URL absolute using NEXT_PUBLIC_APP_URL to avoid port issues
Local Build and Deploy / deploy (push) Successful in 53s
2026-07-15 22:45:35 +02:00
openhands a5e085e04c Add NEXT_PUBLIC_IMAGER_URL example to .env.example
Local Build and Deploy / deploy (push) Successful in 1m0s
2026-07-15 22:28:44 +02:00
openhands 19faa5615c Serve avatars from site's own /imaging endpoint instead of habbo.com
Local Build and Deploy / deploy (push) Successful in 1m7s
- Change default public imager URL from habbo.com to /imaging
- /imaging and /api/imaging/avatar now proxy from upstream (habbo.com) instead of redirecting
- Add resolveUpstreamBase() to separate public URL from upstream URL
- Update admin settings default and description
2026-07-15 22:23:09 +02:00
openhands 71f154cf52 Add /imaging route for avatar proxy and prevent redirect loops
Local Build and Deploy / deploy (push) Successful in 1m10s
2026-07-15 22:14:58 +02:00
openhands 169f658097 Add img_format=png to imager URLs and extend navbar color picker with 10 new colors
Local Build and Deploy / deploy (push) Successful in 56s
2026-07-15 22:09:47 +02:00
openhands 59b63d6e70 Fix real Biome bugs: inner declarations, dup keys, assign-in-expr, implicit any, cookie, a11y svg/keyboard, json
Local Build and Deploy / deploy (push) Successful in 51s
2026-07-14 18:58:40 +02:00
openhands 8d5c8ec96f Visibility polish: admin sidebar contrast/focus, table header readability, nav focus rings
Local Build and Deploy / deploy (push) Successful in 57s
2026-07-14 16:50:43 +02:00
openhands db1875b40b Close mobile nav menu when a link inside is tapped
Local Build and Deploy / deploy (push) Successful in 58s
2026-07-14 16:44:07 +02:00
openhands af1b18d866 Fix mobile nav: hamburger left, brand right, polished menu panel
Local Build and Deploy / deploy (push) Successful in 57s
2026-07-14 16:41:19 +02:00
openhands 48a5394204 Complete nav rewrite: native details/summary, zero JS state, zero transforms
Local Build and Deploy / deploy (push) Successful in 1m5s
- Mobile nav: uses <details>/<summary> for toggle, no useState, no useEffect
- Nav dropdown: uses <details>/<summary>, no useState, no event listeners
- Desktop: separate div with desktop nav items (hidden on mobile)
- Mobile: hamburger dropdown with absolute positioned panel
- CSS: removed ::after pseudo-element with transform, replaced hover
  with background-color only, added details[open] CSS rules
- No backdrop-filter, no will-change, no transition-all, no GPU hacks
- Works on every device without JS state management
2026-07-14 16:25:36 +02:00
openhands 5978b3c13d Rebuild mobile nav: absolute positioned dropdown panel, outside doc flow
Local Build and Deploy / deploy (push) Successful in 1m4s
2026-07-14 16:16:19 +02:00
openhands 90d249e50e Fix typecheck error: use non-null assertion after expect(pair).toBeDefined()
Local Build and Deploy / deploy (push) Successful in 59s
2026-07-14 16:12:01 +02:00
openhands c7c4617f2a Rebuild all menus from scratch for pixel-perfect rendering on every device
Local Build and Deploy / deploy (push) Successful in 59s
- mobile-nav: pure block/hidden toggle, no transforms, no transition-all
- nav-dropdown: clean block/hidden toggle, no CSS animation hacks
- navigation: removed shadow-sm, no will-change, no GPU compositing
- top-header: consistent mobile layout, clean details/summary dropdowns
- admin-mobile-wrapper: inline transition instead of CSS class for sidebar
- globals.css: removed transition-all from nav-item/dropdown-item, replaced
  with specific color/background-color transitions only, added hover bg
2026-07-14 16:10:01 +02:00
openhands 9910fd52c7 Fix blurry normal navigation on mobile: remove transition-all and shadow-sm from nav items
Local Build and Deploy / deploy (push) Successful in 59s
2026-07-14 16:01:46 +02:00
openhands bfa8aedb25 Fix blurry mobile nav: use block/hidden instead of max-h transition, add will-change to sticky nav
Local Build and Deploy / deploy (push) Successful in 57s
2026-07-14 15:47:46 +02:00
openhands 7b3e3c1531 Fix blurry mobile menu by removing CSS transform from animation
Local Build and Deploy / deploy (push) Successful in 57s
2026-07-14 15:42:24 +02:00
openhands 026cb55cf3 Fix mobile menu blur and improve admin sidebar text contrast
Local Build and Deploy / deploy (push) Successful in 57s
2026-07-14 15:36:17 +02:00
openhands 76d18e2645 Fix mobile layout issues in admin sidebar and top-header
Local Build and Deploy / deploy (push) Successful in 50s
2026-07-14 15:29:52 +02:00
openhands 2455a4850e fix: make useServerAction accept void-returning actions and remove dead queryCount
Local Build and Deploy / deploy (push) Successful in 53s
- Type run()'s action param as Promise<unknown> and cast result (Biome strips void from unions)
- Remove unused queryCount field increment in DbService (dead code)
- Reformat theme-contrast test pair assertions
2026-07-13 22:25:56 +02:00
openhands 1908136071 ci: kill lingering next-server before restarting service to avoid EADDRINUSE
Local Build and Deploy / deploy (push) Successful in 1m5s
2026-07-13 22:16:20 +02:00
openhands 045dc06a1f fix: resolve type errors and migrate pnpm settings to pnpm-workspace.yaml
Local Build and Deploy / deploy (push) Failing after 56s
- Move pnpm.onlyBuiltDependencies/overrides from package.json to pnpm-workspace.yaml (clears pnpm WARN)
- Allow useServerAction run() to accept actions returning void
- Make adminAction/authAction input optional so no-schema actions can be called without args
- Return ActionResult from updateBcPage
- Fix categoryPageMap value type (number | undefined)
- Declare DbService.queryCount field
- Use definite assignment for release in withFurniDataLock
- Narrow pair type in theme-contrast test
2026-07-13 22:10:50 +02:00
openhands df38dccbf1 style: format code biome
Local Build and Deploy / deploy (push) Failing after 46s
2026-07-13 21:57:41 +02:00
openhands 8efd032cc6 style: format code with prettier agian
Local Build and Deploy / deploy (push) Failing after 49s
2026-07-13 21:41:52 +02:00
openhands e6d7f2280b Add named custom theme presets (save/load/rename/delete) in admin theme editor
Local Build and Deploy / deploy (push) Successful in 58s
2026-07-13 20:42:40 +02:00
openhands 01b70c2369 Make HK sidebar menu clearly readable and structured
Local Build and Deploy / deploy (push) Successful in 1m2s
- Strong, obvious active state: accent-tinted background, bold text,
  accent icon and left accent border so the current section is unmistakable
- Inactive items stay fully readable (white on dark) with a clear hover
- Separate nav sections with dividers and bolder uppercase headers
- Fix invisible mobile hamburger hover (bg-black/10 -> accent tint)
2026-07-13 20:29:24 +02:00
openhands 0b18a16a2d Make entire HK admin panel cohesive and always readable
Local Build and Deploy / deploy (push) Successful in 1m4s
- Remap shared shadcn semantic tokens (--color-primary, --color-popover,
  --color-card, --color-border, --color-ring, --color-muted-foreground,
  --color-destructive, ...) onto the admin palette for any page scoped with
  body:has([data-admin]); this themes every embedded Button, Badge, Input,
  Select, Card, Table, Tabs, Dialog, Switch, Checkbox with the admin theme
  and guaranteed contrast, without editing component files. Gated so the
  public site is untouched and Radix portals (dialogs/selects) are covered.
- Tag the admin layout/sidebar with data-admin and give the admin content
  area the admin canvas background so the whole HK is one cohesive dark UI.
- Fix hardcoded colors in catalog shop preview and favicon form to use
  admin variables; fix white text on a light warning tint (low contrast).
2026-07-13 20:24:02 +02:00
openhands 8721cfcea4 Make HK sidebar menu text always 100% visible
Local Build and Deploy / deploy (push) Successful in 1m8s
- Set muted sidebar text equal to the readable sidebar text so inactive
  nav items and section labels are never dimmed
- Active item remains distinguished by its accent background and border
2026-07-13 20:13:35 +02:00
openhands d2243b5611 Fix HK sidebar menu text readability
Local Build and Deploy / deploy (push) Successful in 58s
- Derive sidebar text color from the main admin text against the actual
  sidebar background (not canvas/surface), guaranteeing contrast
- Brighten muted sidebar text to 82% of the readable text color so
  inactive nav items and section labels stay clearly visible
2026-07-13 20:10:52 +02:00
openhands cb4a6a8f3e Fix theme editor lint warnings
Local Build and Deploy / deploy (push) Successful in 59s
- Remove unused eslint-disable directive in preset swatches
- Add safe eslint-disable for controlled bgKey lookup in ColorField renderer
2026-07-13 20:06:48 +02:00
openhands acc820284b Add live contrast preview to theme editor for guaranteed readability
Local Build and Deploy / deploy (push) Successful in 1m0s
- New client ColorField component shows a live 'Aa' text preview on the
  relevant background and a WCAG contrast ratio badge (✓ / ⚠)
- Flags low-contrast (<4.5:1) text fields with a red border and a
  one-click 'Use readable color' fix
- Map each text color to the background it sits on (body text -> surface,
  button text -> button color, navbar text -> navbar, admin text -> canvas)
2026-07-13 20:04:58 +02:00
openhands 17894db3e9 Improve theme editor clarity with labels and descriptions
Local Build and Deploy / deploy (push) Successful in 1m20s
- Add a description to every color field explaining what it affects
- Regroup colors into Page & text / Buttons & links / Gradients with
  explanatory section intros for both light and dark mode
- Add section intros for light, dark, and admin (HK) modes
- Widen color field layout and show descriptions under each label
2026-07-13 19:58:38 +02:00
openhands a16d9859e8 Add admin HK color customization fields to theme editor
Local Build and Deploy / deploy (push) Successful in 58s
- Add 6 new admin color DB keys (admin_canvas, admin_surface, admin_text,
  admin_text_muted, admin_border, admin_sidebar_bg) that override the
  derived admin palette
- Extract adminPaletteCss() from themePaletteCss() for reuse
- Generate admin CSS variables in both :root and html.dark with overrides
- Persist admin color settings via saveTheme action
- Add Admin panel (HK) section to /admin/theme with color pickers
2026-07-13 19:49:19 +02:00
openhands 4dcf6fdce8 Fix admin sidebar colors: use consistent dark sidebar instead of navbar colors for professional look
Local Build and Deploy / deploy (push) Successful in 1m0s
2026-07-13 19:32:27 +02:00
openhands 17722acc69 Add global mobile-friendly CSS rules
Local Build and Deploy / deploy (push) Successful in 1m30s
2026-07-13 19:29:17 +02:00
openhands 3fe3846ad5 Fix blurry mobile menu: use GPU-friendly opacity+transform instead of max-height transition
Local Build and Deploy / deploy (push) Successful in 1m1s
2026-07-13 19:26:02 +02:00
openhands debee7300e Fix admin sidebar contrast: muted text now visually distinct from regular text
Local Build and Deploy / deploy (push) Successful in 59s
2026-07-13 19:21:53 +02:00
openhands adbd651350 Add mobile sidebar toggle for admin panel
Local Build and Deploy / deploy (push) Successful in 1m5s
2026-07-13 19:17:27 +02:00
openhands 7b67ef893c Fix admin sidebar height, language dropdown overflow, pagination wrap, nav dropdown min-width
Local Build and Deploy / deploy (push) Successful in 58s
2026-07-13 19:12:28 +02:00
openhands a241448e9e Revert admin sidebar toggle, fix hamburger position directly
Local Build and Deploy / deploy (push) Successful in 1m4s
2026-07-13 19:02:09 +02:00
openhands 53b760a815 Add admin sidebar toggle on mobile, fix table wrapping, fix grids
Local Build and Deploy / deploy (push) Successful in 50s
2026-07-13 18:52:13 +02:00
openhands c7768d8668 Move hamburger to right, fix nav overflow, add auto language detection
Local Build and Deploy / deploy (push) Successful in 1m4s
2026-07-13 18:20:04 +02:00
openhands eba61d2fb9 Fix mobile responsive issues
Local Build and Deploy / deploy (push) Successful in 53s
- Remove duplicate home link in mobile nav
- Remove overflow-hidden clipping main content
- Improve mobile menu scrolling and spacing
- Make top-header currencies wrap on small screens
- Reduce site-header height on mobile
- Add global mobile CSS overrides for tables, padding, fonts
2026-07-13 18:10:16 +02:00
openhands bef458dbf8 Rename executeRaw → executeRawUnsafe to make SQL injection risk explicit
Local Build and Deploy / deploy (push) Successful in 1m1s
The method wraps Prisma's  which trusts the caller
to use ? placeholders. The Unsafe suffix is a naming convention
that signals 'review caller for parameterization'.
2026-07-13 12:41:11 +02:00
openhands e5ae51bff7 Add NFC normalization to all FormData inputs across 41 server actions
Local Build and Deploy / deploy (push) Successful in 59s
All user-supplied string values from FormData now go through
String.prototype.normalize('NFC') to prevent Unicode homoglyph
attacks and canonicalization bypasses. NFC is idempotent for
already-normalized strings, so this is a pure security improvement
with zero behavioral change for legitimate users.
2026-07-13 12:21:37 +02:00
openhands e2fc7ea1a4 Complete security hardening: zero-migration foundation, edge headers, rate-limit atomics, body limits
Local Build and Deploy / deploy (push) Successful in 58s
- Make @/lib/safe-action re-export from foundation layer so all 13+
  existing server actions instantly get request tracing, rate limiting,
  and structured error handling without any code changes
- Add HSTS, CSP, X-Frame-Options, X-Content-Type-Options to edge proxy
  (src/proxy.ts) — ran at Cloudflare/Vercel edge for all non-asset routes
- Fix rate-limit.ts race condition: compute newCount before assignment
  to shrink the read-modify-write window; add memory-key prefix to
  avoid collisions with Redis keys
- Add request body size limit (10 MB default) to api-handler.ts with
  per-route override via maxBodyBytes option
- Remove unused imports and clean up backward-compat types
2026-07-13 12:09:43 +02:00
openhands f6ad030c5b Add EpicNext CMS foundation layer and fix critical security gaps
Local Build and Deploy / deploy (push) Successful in 1m1s
- Create src/lib/foundation/ (860 LOC, 9 files): typed action wrappers,
  DbService with health checks, CSRF validation, safe redirects,
  AsyncLocalStorage request tracing, branded types, reusable Zod schemas
- Migrate moderation.ts and user-settings.ts to foundation patterns
- Fix abuse-guard.ts: bound in-memory Maps with LRU eviction (was unbounded)
- Fix access-guard.ts: separate try/catch per check, log degradation
  instead of blanket fail-open
- Replace raw redirect() calls with safeRedirect() in guard.ts and
  permissions.ts to prevent open-redirect attacks
- Add CSRF validation to api-handler.ts for mutating methods
- Add canonicalizeFormData() utility for FormData input sanitization
2026-07-13 12:03:49 +02:00
openhands 8bf1aa2fa7 Use translations for emulator page (was hardcoded Italian)
Local Build and Deploy / deploy (push) Successful in 58s
2026-07-12 23:14:35 +02:00
openhands 5ae29e2a58 Add i18n support for import page and translations tabs
Local Build and Deploy / deploy (push) Successful in 1m7s
2026-07-12 23:11:59 +02:00
openhands 574a499e14 Change language switcher search placeholder to English
Local Build and Deploy / deploy (push) Successful in 1m3s
2026-07-12 23:04:33 +02:00
openhands 7b85f8f3db Make admin CMS translation language tabs horizontally scrollable
Local Build and Deploy / deploy (push) Successful in 1m4s
2026-07-12 23:02:59 +02:00
openhands 187e008914 Add search to language switcher dropdown, remove translation script
Local Build and Deploy / deploy (push) Successful in 1m6s
2026-07-12 22:58:40 +02:00
openhands 72a3284ddd Fix Cyrillic-translated HTML tags in Serbian and Bulgarian translations
Local Build and Deploy / deploy (push) Successful in 49s
2026-07-12 22:54:27 +02:00
openhands 6ddfcafa67 Fix placeholders in machine translations and add Russian translation
Local Build and Deploy / deploy (push) Successful in 54s
2026-07-12 22:37:52 +02:00
openhands b5179c682f Limit language switcher dropdown height with scrollbar
Local Build and Deploy / deploy (push) Successful in 1m8s
2026-07-12 21:55:17 +02:00