After a repair attempt, items whose nitro/icon assets cannot be restored
from any source are reclassified from hard errors into a dedicated
'Unrepairable (legacy)' group (info), so a fully repaired catalog can
reach 0 errors while still listing exactly what is not restorable. Adds
an unrepairable summary count and a dedicated tab in the audit UI.
Detect badges by items_base.type='b' (authoritative, album gifs as
fallback), recognize pet/animals (a0 pet<N>, pet<N> interaction) and
system items (effects, bots, sticky notes), and resolve asset names for
dot/star classname variants so the audit no longer floods with false
missing nitro/icon errors and repair skips non-furni items.
Badge items like HC_Badge, BADGE_SHREK_03 have item_names that don't start
with 'badge_' and interaction_type='default'. Now loads known badge codes
from <gamedataRoot>/album1584/*.gif files and uses that set to exclude
badge items from .nitro and icon audit checks. Also removes incorrect
startsWith('badge_') check that would wrongly skip badge display cases
which DO have .nitro files.
Badge item_names already start with 'badge_' (e.g. badge_citycpa3),
so checking for badge_<item_name>_icon.png produces a double prefix
(badge_badge_citycpa3_icon.png). Now uses item_name.startsWith('badge_')
instead, which correctly identifies badge items without depending on
icon files existing in the directory.
Previously identified badge items by interaction_type='badge', but
clone-imported badges have interaction_type='default'. Now checks for
badge_<code>_icon.png file existence instead.
Badge icons are stored as badge_<code>_icon.png (with badge_ prefix)
instead of <code>_icon.png like regular furni. Update the audit and
icon repair to check for both patterns so badge items are not falsely
flagged as missing icons.
Badge items use .gif files, not .nitro bundles, so they should not
be flagged as missing .nitro or missing catalog entries. Also add
badge logicType handling in furni-import.ts so badges get the correct
interaction_type when imported.
Anonymous HTML was sent with 'public, max-age=60, s-maxage=300,
stale-while-revalidate=300'. After a rebuild the old chunk URLs (keyed by
deploy id) are deleted, so any browser/CDN holding the stale HTML got 404s
for up to five minutes. Since the deploy id is the git commit, the HTML must
be re-fetched after every deploy; only content-hashed static assets should
be cached. Return no-store for all HTML documents.
theme-init.js adds the 'dark' class to <html> before React hydrates,
causing a hydration mismatch (React #418) for users with a saved dark
theme. Mark the root element with suppressHydrationWarning.
- hashPassword now emits bcrypt (cost 12) instead of argon2id
- checkLogin migrates legacy md5/argon2id hashes to bcrypt on sign-in
- keep argon2id verification only as a one-time migration path
- replace ARGON2_* env vars with BCRYPT_COST
- fix emulator git path (repo root vs Maven submodule) and SQL/backup dirs
- auto-detect branch; track real parallel job exit status
- verify vite presence and clean+full install when node_modules is incomplete
- fix health-check label handling and skip jsonc/example files in JSON scan
- stop hardcoding the Nitro client path in chown
- drop JSON5: sync config URLs to .jsonc, remove legacy .json5 files
- bump to v8.0.2
Previously allocateCatalogItemId was called per entry, but since generation
does not INSERT, MAX(id) never advanced and every entry got the same id.
Now MAX(id) is read once and a local counter hands out sequential ids.
- Parallelize icon and nitro downloads in the audit repair with a
sliding-window worker pool (6 concurrent) to speed up large catalogs
- Add repairMissingNitros: fetch missing .nitro bundles from configured
nitro sources (Wibbo default), validating each bundle before writing
- Add catalog-repair service: generate/apply catalog_items SQL for furni
missing a catalog entry and repair FurnitureData.json (add missing +
dedupe classnames)
- Wire all options through the audit API and client UI with live progress
and result stats (icons, nitros, SQL, furnidata)
- Add Wibbo as default nitro source alongside existing icon sources
- Ignore runtime furni assets downloaded into public/ during repair
Repair Icons now resolves all furni asset write targets (webroot plus
the live gamedata like /var/www/Gamedata) and writes downloaded or
extracted icons to every missing location. Icons already present in one
target are copied across instead of re-downloaded, and local .nitro
bundles are searched in every target.
Fall back to well-known public furni icon hosts (HabboAssets, Hubbly,
Leet) when no clone sources are configured, so Repair Icons can download
missing icons out of the box. Also handle variant classnames (base name
and '*' replaced with '_') and extract icons from remote .nitro bundles.
Send a browser User-Agent on downloads to avoid being blocked by hotels.
- Remove output: 'standalone' from next.config.ts to allow normal 'next start'
- Allow empty SENTRY_DSN/NEXT_PUBLIC_SENTRY_DSN in env validation (zod)
- Add 'unsafe-inline' to style-src CSP only in development for Turbopack HMR
- Clear placeholder Sentry DSN values from .env
Avatars are proxied from the slow Habbo upstream on every request
(~350ms each) and Cloudflare was serving them as DYNAMIC because the
Cache-Control had no s-maxage. Add s-maxage=86400 + stale-while-revalidate
so edge/CDN caches avatars and repeats are served instantly.
getLoginUser selected users.account_blocked, which does not exist in the
DB (nor the Drizzle schema). Every credentials authorize() call threw a
SQL error -> NextAuth CallbackRouteError -> 'error=Configuration', so no
login could ever succeed. Remove the phantom column from the query and
LoginUser interface.
Also fix all remaining biome noNonNullAssertion / noExplicitAny lint
warnings so CI's check job (biome:lint) passes and the push deploy runs.
- hashPassword now emits argon2id (same params as the legacy AtomCMS
Laravel setup: memory 64MB, iterations 4, parallelism 1)
- legacy md5 and bcrypt hashes are verified and auto-upgraded to
argon2id on successful login (CONVERT_PASSWORDS=true)
- replace BCRYPT_ROUNDS env with ARGON2_MEMORY_KB / ARGON2_ITERATIONS /
ARGON2_PARALLELISM
- update README and add tests for argon2id and bcrypt upgrade paths
- Update CI comments to reference Drizzle ORM + Prisma facade (not legacy Prisma runtime)
- Clarify that src/db/schema.ts is committed (no drizzle-kit generate needed in CI)
- Update release notes template: 'Prisma 7' -> 'Drizzle ORM'
- Rename release 'Generate Prisma Client' section to 'Generate Prisma Type Stubs (Dev Only)'
- Note that Prisma type stubs are for facade type-checking only (no runtime engine)
- Replace next/font/google with <link> tags in <head> (loads fonts client-side at runtime)
- Define --font-nunito and --font-pixel CSS variables in globals.css with font-family fallbacks
- Remove @prisma/client from serverExternalPackages in next.config.ts (devDep only)
- Fix noPrecisionLoss on BIGINT UNSIGNED max value (2^64-1) with biome-ignore comments
- Fix noThenProperty on custom thenable with biome-ignore comment
- Auto-format remaining files (biome check --write)
- Re-stage auto-fixed files from previous commit
- Replace Prisma client runtime with Drizzle ORM (zero Prisma engine/query engine in production)
- Add Prisma-compatible facade (@/lib/prisma-facade.ts) backed by Drizzle for backwards compatibility
- Runtime queries route through Drizzle ORM; @prisma/client is now devDependency (types only)
- Remove @prisma/adapter-mariadb dependency; delete prisma-pool.ts and types/prisma.ts
- New Drizzle schema layer: src/db/schema.ts (176 tables) and src/lib/db.ts (connection)
- Update README documenting the dual-layer ORM architecture
- Restore src/generated/ gitignore (build artifact for local type generation)
- 0 TypeScript errors, 583 tests passing
The facade intentionally uses `any` types to match the Prisma Client API surface,
allowing existing code to run unmodified while routing queries through Drizzle at runtime.
prisma:generate needs DATABASE_URL to resolve the schema but doesn't
connect to the DB. After generate, unset the placeholder so that
pnpm build and pnpm db:migrate pick up the real DATABASE_URL from
the live .env (symlinked into the stage directory).
The deploy job was overwriting DATABASE_URL with a placeholder for
prisma:generate, but this persisted when db:migrate ran later, causing
ER_ACCESS_DENIED_ERROR. Since the stage directory already symlinks to
the live .env, the real DATABASE_URL is available without override.
- Remove babel-plugin-react-compiler (Next.js 16 has built-in reactCompiler)
- Update postcss to 8.5.25
- Add output: 'standalone' to next.config.ts for smaller/faster deployments
- Update ecosystem.config.cjs to use standalone server.js
Prisma requires DATABASE_URL even for client generation.
The CI workflow cloned to a fresh temp dir has no .env file,
so these must be provided as env vars.
The health check URL was hardcoded to http://127.0.0.1:3000 but the
production .env sets PORT=3002. Read the PORT from .env dynamically
so the health check matches the actual server port.
Changing ownership to www-data at end of deploy breaks permission
handling when pm2 runs as a different user (e.g., root or the deploy
user). Keep ownership as the deploy user throughout.
The hash-wasm package now handles both argon2id and bcrypt hashing,
making @node-rs/argon2 unused. Leaving it in package.json causes
native binary compilation failures on deploy servers (EACCES/build
errors), which breaks the deploy pipeline entirely.
Also restore .gitea/workflows/ci.yaml so CI pipelines run again.