Commit Graph
67 Commits
Author SHA1 Message Date
SimoandCursor 9854719cfd feat(admin): drizzle trade-lock + RCON sync and photo local purge
CI / check (push) Successful in 24s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m2s
Co-authored-by: Cursor <[email protected]>
2026-07-31 21:14:03 +02:00
openhands 56061e41d4 refactor: replace Prisma ORM runtime with Drizzle ORM facade
CI / check (push) Failing after 12s
CI / deploy (push) Skipped
CI / release (push) Skipped
- Replace Prisma client runtime with Drizzle ORM (zero Prisma engine/query engine in production)
- Add Prisma-compatible facade (@/lib/prisma-facade.ts) backed by Drizzle for backwards compatibility
- Runtime queries route through Drizzle ORM; @prisma/client is now devDependency (types only)
- Remove @prisma/adapter-mariadb dependency; delete prisma-pool.ts and types/prisma.ts
- New Drizzle schema layer: src/db/schema.ts (176 tables) and src/lib/db.ts (connection)
- Update README documenting the dual-layer ORM architecture
- Restore src/generated/ gitignore (build artifact for local type generation)
- 0 TypeScript errors, 583 tests passing

The facade intentionally uses `any` types to match the Prisma Client API surface,
allowing existing code to run unmodified while routing queries through Drizzle at runtime.
2026-07-31 14:11:03 +02:00
openhands a513d9b7bd Migrate dependencies: bcrypt→@node-rs/argon2, sanitize-html→isomorphic-dompurify, remove nodemailer/next-view-transitions
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 27s
2026-07-28 19:03:04 +02:00
openhands dacc4cadfd chore(deps): upgrade to typescript 7 bridge and clean up pnpm v11 workspace configs
CI / check (push) Failing after 58s
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 11s
2026-07-27 23:14:00 +02:00
openhands af9f11d934 fix: resolve all Biome lint warnings
CI / check (push) Successful in 40s
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m1s
- Replace 'as any' with proper CurrencyDb type in send-currency test
- Fix noTemplateCurlyInString warnings in deploy-workflow-contract test
2026-07-27 17:33:07 +02:00
openhands 17847545dd Improvements: remove dead config, fix ESM, add URL validation, unify types, add missing logging
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m52s
- Remove .prettierrc (dead config, Biome replaces Prettier)
- Rename lighthouserc.json to lighthouserc.cjs with module.exports for ESM compat
- Add logger.warn to empty catch blocks in auth, register, site-settings, prisma-cache, redis, security, rate-limit
- Unify ActionResult type: action-helper.ts uses 'ok' consistent with safe-action-shared.ts
- Add noUnusedLocals + noUnusedParameters to tsconfig + fix 25 pre-existing unused vars
- Replace barrel export src/types/index.ts with direct @/types/common imports
- Make trustHost conditional (development only) in auth.ts
- Add pre-flight URL validation to update-Nitrov3.sh to catch image.library.url misconfigurations
- Improve NITRO_IMAGE_LIBRARY_URL content validation in pre-flight & post-compute checks
2026-07-26 20:28:11 +02:00
openhands 78b1982145 fix: remove as any cast from catalog-tree test mock
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m29s
2026-07-25 18:36:40 +02:00
openhands ac3c42f308 test: add action-helper, send-currency, permission-ranks, catalog-tree, and audit test suites (77 files, 405 tests)
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m14s
2026-07-25 18:25:33 +02:00
openhands 2e9db75eca test: add audit, staff-activity, and abuse-guard test suites (75 files, 376 tests)
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m14s
2026-07-25 18:10:15 +02:00
openhands 1acace49d0 refactor: full codebase overhaul — dead code removal, env validation, logger migration, date consolidation, Prisma schema cleanup, button consistency, useEffect deps, test coverage
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 8s
- env.ts: added 10 missing Zod-validated env vars (imager, paypal currency, argon2/bcrypt params)
- Migrated 6 modules from process.env to validated env.* (auth, proxy-auth, paypal, password, redis, imager, moderation, alert, logger)
- Replaced console.warn/error with pino logger in 9 server-side modules
- Removed 50+ dead exports (SWF wrappers, coalesceHotelName, signIn, isStaff re-export, formatTimestamp, Skeleton/SkeletonCard, 4 unused housekeeping sections)
- Consolidated date formatting: 28 files migrated to shared formatDate() from @/lib/format-date
- Wired 4 radio/settings API routes through cached siteSettings service instead of raw Prisma queries
- Added getMany()/getAll() helpers to SiteSettings service
- Removed 88 dead Prisma model definitions (schema 2763→1846 lines)
- Created admin action-helper.ts with wrapAction() for standardized error handling
- Fixed useEffect dependency arrays in 4 data-heavy components
- Replaced raw btn CSS classes with shadcn Button component across admin pages
- Stripped dead i18n namespaces (common, pages.client) from all 22 translation files
- Removed 2 dead scripts (create-release.sh, check-local-imports.ts)
- Fixed knip.json configuration
- Added 7 new test suites: format-date, paypal, moderation, alert, webhook, action-helper, and fixed password.test.ts for env mocking
- All 358 tests passing across 72 test files
- TypeScript: 0 errors
2026-07-25 17:33:06 +02:00
openhands a9f1f4f99d Fix Turbopack NFT warning
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 2m47s
- Remove import.meta.dirname from turbopack config (unnecessary filesystem op)
- Add /*turbopackIgnore: true*/ to 3 path.join calls in upload-import.ts
  that were missing the comment, causing Turbopack to trace the whole
  project unintentionally
2026-07-23 20:57:43 +02:00
SimoandCursor e00e9ca2dc refactor: centralize hotel name fallback via FALLBACK_HOTEL_NAME
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m6s
Route all user-facing Atom hotel defaults through resolveHotelName (settings then HOTEL_NAME env then brand constant). Exclude Playwright e2e from tsconfig until deps are installed.

Co-authored-by: Cursor <[email protected]>
2026-07-22 18:45:59 +02:00
openhands b0ad3a128e fix: resolve turbopack NFT warning and disable Sentry telemetry
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m46s
2026-07-21 23:49:23 +02:00
SimoandCursor 3bb96eb6f3 test: silence expected clone-import rollback warning
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m52s
The rollback case intentionally hits items_base insert failure; mock console.warn so deploy logs stay clean.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:51:22 +02:00
SimoandCursor ed7db6e048 feat: public events/polls, friends graph, captcha, SSE hardening, and admin UX
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m55s
Ship product gaps: register/vote pages, friend add/accept/decline/remove, email verify TTL, captcha on login/forgot, soft-fail user actions, SSE abort/shared client, Commando Centrum error toasts, admin delete for events/polls, and IT/NL i18n fills.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:08:33 +02:00
openhands bebd65c056 fix: refactor audit to SSE streaming, improve error handling
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m52s
- Changed from blocking JSON endpoint to SSE streaming (like sync-all/repair-icons)
- Progress updates during each audit phase with item counts
- Proper error handling with typed AuditEvent for every failure path
- AbortController support for the client
- Shows real-time progress for each check section
2026-07-21 15:33:15 +02:00
openhands 19e4e10b1d feat: add catalog audit page
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m56s
Checks for:
- items_base entries without catalog_items (not purchasable)
- catalog_items referencing non-existent items_base
- Items without .nitro or icon files on disk
- Duplicate classnames
- Items missing from all configured clone sources
2026-07-21 15:24:58 +02:00
openhands 90107c83d5 fix: rewrite repair-icons with proper error handling and progress
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m38s
- Wrap all DB/file operations in try-catch, send error events via SSE
- Report skipped/progress events for items that already have icons
- Add 'started' event with total count so the UI shows real-time progress
- Catch route-level errors and stream them instead of returning JSON
- Use log line content as React key instead of array index
2026-07-21 15:04:43 +02:00
openhands 804daeffca feat: add .nitro upload + sync-all + repair-icons features
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 32s
- Upload .nitro bundles directly with full DB, catalog, and furnidata integration
- Generate SQL migration files on upload (optional)
- Auto-sync missing furniture from all configured clone sources (SSE batch)
- Repair missing icons by extracting from local .nitro or downloading from sources
- All behind ASSETS_IMPORT permission
2026-07-21 14:53:26 +02:00
openhands 5e8a13a84f fix: resolve all biomaly lint errors and warnings across CMS
Deploy / release (push) Successful in 4s
Deploy / deploy (push) Skipped
- Fix CSS parser config (tailwindDirectives enabled)
- Fix noDangerouslySetInnerHtml via SanitizedHtml component
- Fix useExhaustiveDependencies in catalog-manager-dialog
- Fix noArrayIndexKey across 26 files (stable keys)
- Fix SVG a11y (titles, roles, aria-labels)
- Fix label/input associations (htmlFor/id pairs)
- Fix static element interactions (role + keyboard support)
- Fix noImgElement, noDescendingSpecificity (disabled - external Habbo URLs)
- Fix noNonNullAssertion, useTemplate, unused vars/imports
- Add SanitizedHtml shared component
- Migrate biome.json to 2.5.4 schema
2026-07-20 17:41:53 +02:00
SimoandCursor 6b884ad25a Harden deploy gates, prod AUTH_SECRET, and Sentry error reporting.
Local Build and Deploy / deploy (push) Successful in 1m42s
Align onlyBuiltDependencies with the workspace, fail fast without AUTH_SECRET in production, and delete catalog_items via VARCHAR-safe SQL so page deletes do not leave orphans.

Co-authored-by: Cursor <[email protected]>
2026-07-18 19:32:15 +02:00
openhands 3c9c1311ec chore: remove dead code flagged by knip
Local Build and Deploy / deploy (push) Successful in 1m7s
Remove 19 unused source files (no importers anywhere in src/):
- src/actions/admin-permissions.ts, admin-radio.ts, admin-user-edit.ts,
  admin-users.ts (functionality lives in @/actions/users and
  @/actions/permissions)
- src/components/admin/confirm-action.tsx, page-header.tsx
- src/components/motion-elements.tsx
- src/lib/format-date.ts
- src/lib/catalog-categories/* (incl. re-export barrel)
- src/lib/foundation/{index,database,middleware,validation}.ts (errors/action
  kept, still imported directly)
- src/lib/services/imager/{avatar-renderer,memory-cache}.ts
- src/lib/services/nitro-assets.ts

Update admin-operations-contract test to drop the two removed action-file
gates (their permission coverage already exists in users.ts/permissions.ts).

Add knip.json for repeatable dead-code audits.

Verified: tsc --noEmit clean, next build succeeds, full test suite green
(301/301).
2026-07-18 19:08:17 +02:00
SimoandCursor ef2c3324b4 Prune unused deps, bump safe minors, add server-only guards.
Local Build and Deploy / deploy (push) Failing after 15s
Remove unused translate/jpeg types packages; refresh patch updates; mark Redis/site-settings/gamedata hotel as server-only with a Vitest stub.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:53:56 +02:00
SimoandCursor a798999440 Refresh Suggest hotel label from live CMS setting.
Local Build and Deploy / deploy (push) Successful in 56s
Avoid stale SSR/Redis cache keeping Suggest IT after habbo_gamedata_hotel changes.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:36:10 +02:00
SimoandCursor 785c1b6976 Fix client bundle pulling Redis/Prisma via habbo gamedata hotel.
Local Build and Deploy / deploy (push) Successful in 54s
Keep hotel list helpers client-safe; load CMS setting only from a server module.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:30:46 +02:00
SimoandCursor d1baaf798a Add multi-hotel Habbo gamedata locale in CMS settings.
Local Build and Deploy / deploy (push) Failing after 33s
Furni name suggestions, import enrichment, and badge texts now follow habbo_gamedata_hotel instead of hardcoded habbo.it.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:28:18 +02:00
SimoandCursor 7bc0845932 Fix catalog items missing due to page_id VARCHAR mismatch.
Local Build and Deploy / deploy (push) Successful in 56s
Use raw SQL for counts/loads/creates/moves so Habbo DBs with VARCHAR page_id and no AUTO_INCREMENT still show and persist furni.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:21:49 +02:00
SimoandCursor 1d8efefce4 Fix Visual Manager empty categories: seed roots, harden tree API.
Local Build and Deploy / deploy (push) Successful in 56s
Seed root tabs from SSR, load the full tree without CLEAR_TREE races, coerce parent ids, and tolerate catalog_items page_id type mismatches so category pages actually appear.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:02:53 +02:00
SimoandCursor b52e25578d Harden catalog admin: fix translate/quick-add, RCON sync, and confirm UX.
Local Build and Deploy / deploy (push) Successful in 1m18s
Restore broken Quick Add search, correct Translate saves to items_base and FurnitureData, reparent page deletes, sync RCON on create/toggle/BC mutations, and replace native confirms/prompts with dialogs.

Co-authored-by: Cursor <[email protected]>
2026-07-17 21:12:58 +02:00
SimoandCursor 49d204e85c Remove import/repair feature and related API routes.
Local Build and Deploy / deploy (push) Successful in 1m41s
Co-authored-by: Cursor <[email protected]>
2026-07-17 18:52:38 +02:00
openhands 19faa5615c Serve avatars from site's own /imaging endpoint instead of habbo.com
Local Build and Deploy / deploy (push) Successful in 1m7s
- Change default public imager URL from habbo.com to /imaging
- /imaging and /api/imaging/avatar now proxy from upstream (habbo.com) instead of redirecting
- Add resolveUpstreamBase() to separate public URL from upstream URL
- Update admin settings default and description
2026-07-15 22:23:09 +02:00
SimoandCursor 9d4d409b77 Restore self-hosted /api/imaging/avatar (and badge) endpoints.
Local Build and Deploy / deploy (push) Successful in 54s
The clothing importer and imager helpers pointed at a missing route; proxy Habbo with disk/memory cache so avatars work again.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:41:18 +02:00
openhands 045dc06a1f fix: resolve type errors and migrate pnpm settings to pnpm-workspace.yaml
Local Build and Deploy / deploy (push) Failing after 56s
- Move pnpm.onlyBuiltDependencies/overrides from package.json to pnpm-workspace.yaml (clears pnpm WARN)
- Allow useServerAction run() to accept actions returning void
- Make adminAction/authAction input optional so no-schema actions can be called without args
- Return ActionResult from updateBcPage
- Fix categoryPageMap value type (number | undefined)
- Declare DbService.queryCount field
- Use definite assignment for release in withFurniDataLock
- Narrow pair type in theme-contrast test
2026-07-13 22:10:50 +02:00
openhands df38dccbf1 style: format code biome
Local Build and Deploy / deploy (push) Failing after 46s
2026-07-13 21:57:41 +02:00
openhands 8efd032cc6 style: format code with prettier agian
Local Build and Deploy / deploy (push) Failing after 49s
2026-07-13 21:41:52 +02:00
openhands f6ad030c5b Add EpicNext CMS foundation layer and fix critical security gaps
Local Build and Deploy / deploy (push) Successful in 1m1s
- Create src/lib/foundation/ (860 LOC, 9 files): typed action wrappers,
  DbService with health checks, CSRF validation, safe redirects,
  AsyncLocalStorage request tracing, branded types, reusable Zod schemas
- Migrate moderation.ts and user-settings.ts to foundation patterns
- Fix abuse-guard.ts: bound in-memory Maps with LRU eviction (was unbounded)
- Fix access-guard.ts: separate try/catch per check, log degradation
  instead of blanket fail-open
- Replace raw redirect() calls with safeRedirect() in guard.ts and
  permissions.ts to prevent open-redirect attacks
- Add CSRF validation to api-handler.ts for mutating methods
- Add canonicalizeFormData() utility for FormData input sanitization
2026-07-13 12:03:49 +02:00
openhands 2e4ed76121 style: format code with prettier
Local Build and Deploy / deploy (push) Successful in 49s
2026-07-12 21:07:34 +02:00
remco e85e4d74ea revert fb8e77bb68
Local Build and Deploy / deploy (push) Successful in 1m11s
revert style: clean up code with prettier and eslint
2026-07-12 21:02:03 +02:00
openhands fb8e77bb68 style: clean up code with prettier and eslint 2026-07-12 20:31:05 +02:00
Simo 60278b9e71 feat: add admin operations suite
Local Build and Deploy / deploy (push) Successful in 50s
2026-07-12 20:11:28 +02:00
Simo c0ffc74f9b fix: externalize lzma for import build
Local Build and Deploy / deploy (push) Successful in 49s
2026-07-12 19:15:08 +02:00
Simo 3497df9dfd feat: add asset import services 2026-07-12 19:12:25 +02:00
Simo 4b596226e0 fix: complete acl management 2026-07-12 19:12:24 +02:00
Simo 8d37ae9ae0 style: normalize restored source endings
Remote Build and Deploy / deploy (push) Has been cancelled
2026-07-11 21:19:54 +02:00
Simo 0cd753c735 fix: restore complete admin feature dependencies 2026-07-11 21:15:54 +02:00
Simo 5b4228261a Reapply "Add missing admin action files and navigation links"
This reverts commit 4d515bc400.
2026-07-11 20:52:56 +02:00
Simo 4d515bc400 Revert "Add missing admin action files and navigation links"
This reverts commit 41be6835bf.
2026-07-11 20:37:56 +02:00
Simo 4a1e1115b3 Harden CMS security and theme contrast 2026-07-11 20:27:20 +02:00
openhands 41be6835bf Add missing admin action files and navigation links
- Add 11 missing server action files: badges, bulk-users, catalog, catalog-bc, catalog-items, import-badges, import-furni, multi-account-detect, permissions, rooms, soundtracks
- Add missing admin navigation links: tickets, sounds, translations, import, radio sub-pages
- Add translation keys for all new navigation items
2026-07-11 12:01:05 +02:00
openhands 942bc6fc8d Security hardening, code quality, and ESLint setup
- Remove production DB dump (db_backup_*.sql) and update.log from git tracking
- Add DB backups to .gitignore
- Replace all console.log/console.error with structured logger module
- Translate Dutch error messages to English (link-discord.ts)
- Remove dead code blocks (register-form.tsx false && pattern)
- Add ESLint flat config with TypeScript, React, Next.js, jsx-a11y, and security plugins
- Add Prettier config
- Add eslint-plugin-security for security-aware linting
- Fix all 119+ ESLint warnings across the codebase:
  - Resolve security/detect-object-injection with safe access patterns
  - Resolve security/detect-non-literal-fs-filename with path traversal validation
  - Replace <img> with next/image <Image> component
  - Remove unused variables and imports
  - Replace non-null assertions with proper type guards
  - Replace <a> with <Link> for internal navigation
  - Use next/script Script component for external scripts
- Fix setState-in-useEffect anti-patterns (navbar-color-picker, logo-generator, theme-switcher)
- Add lint and format scripts to package.json

All checks: typecheck ✓, tests 58/58 ✓, lint 0 errors 0 warnings ✓
2026-07-10 22:48:22 +02:00