Commit Graph
1632 Commits
Author SHA1 Message Date
openhands 6264f9fb20 test(security): make Cloudflare block tests deterministic under CI Redis
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m39s
CI / tests-unit (push) Successful in 1m42s
CI / tests-ui (push) Successful in 2m31s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m1s
cloudflare-api unit tests drove the real Redis connection when REDIS_URL was set (CI), causing cross-test bleed. Mock @/lib/redis with an in-memory fake identical to the gate integration test.
2026-09-22 23:31:41 +02:00
openhands 4479753160 feat(security): mirror anti-DDoS blocks to Cloudflare edge via API
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m38s
CI / tests-unit (push) Failing after 1m40s
CI / tests-ui (push) Successful in 2m28s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
- gate creates a zone IP Access Rule (block) for proxied offenders that hit the block threshold, deduped until the tiered block expires
- cloudflare-api lib: verified endpoints, create/delete/verify/list helpers, Redis-backed tracking + 30s TTL sweep (instrumentation worker + admin render)
- runtime toggle cloudflareAutoBlock in antiddos config; boot default CLOUDFLARE_AUTO_BLOCK_ENABLED
- admin panel: Cloudflare edge-blocks card with verify + remove-rule actions; unban also lifts the edge block
- credentials live in env only (CLOUDFLARE_API_TOKEN / CLOUDFLARE_ZONE_ID)
2026-09-22 23:27:15 +02:00
openhands f0c27eb815 feat(security): Cloudflare-aware IP trust and admin-tunable anti-DDoS
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 33s
CI / tests-integration (push) Successful in 1m50s
CI / tests-unit (push) Successful in 1m52s
CI / tests-ui (push) Successful in 2m43s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m32s
- resolveClientIp: trust cf-connecting-ip only behind cf-ray/cdn-loop, use nginx x-real-ip otherwise (anti-spoof)
- antiddos-config: Redis-backed live config (antiddos:config) with 30s cache, 13 ANTI_DDOS_* env vars
- ddos-guard: consume tunable rates/tiers via getAntiddosConfig
- admin panel at /admin/devops/antiddos (save/reset/unban actions, PERMS.SETTINGS_VIEW)
- register new admin page in housekeeping migration matrix (146 -> 147)
2026-09-22 22:22:51 +02:00
openhands fd4d0fa1cb feat(security): harden anti-DDoS gate with scanner triage, tiered blocks and in-process global halt
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-unit (push) Successful in 1m39s
CI / tests-integration (push) Successful in 1m42s
CI / tests-ui (push) Successful in 2m27s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m0s
2026-09-22 21:57:09 +02:00
openhands 98a184953a feat(security): add Redis-backed app-layer anti-DDoS rate limiting to proxy
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 31s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Successful in 1m47s
CI / tests-ui (push) Successful in 2m40s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m3s
2026-09-22 21:48:40 +02:00
openhands d8f2a21011 deps: upgrade Next.js from 16.3.5 to 16.3.6
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 32s
CI / tests-integration (push) Successful in 1m46s
CI / tests-unit (push) Successful in 1m47s
CI / tests-ui (push) Successful in 2m37s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m30s
Bump the framework to the latest 16.3.6 patch release. Typecheck passes and
the homepage renders (HTTP 200) on the dev server with Next 16.3.6 under
Turbopack.
2026-09-22 21:31:34 +02:00
openhands 761bfb2940 ci: run unit, integration and UI tests as parallel jobs
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 34s
CI / tests-unit (push) Successful in 1m40s
CI / tests-integration (push) Successful in 1m42s
CI / tests-ui (push) Successful in 2m28s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m50s
Split the heavy test suites out of the check job so coverage, MariaDB/Redis
integration and Playwright UI tests run concurrently on the host runner
(capacity raised to 4) instead of back-to-back (~2min wall-time saving).
Deploy and preflight now gate on all three test jobs.
2026-09-22 21:18:49 +02:00
openhands 292268f418 ci: reuse host-playwright browser cache instead of re-downloading chromium
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 4m22s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m50s
Point PLAYWRIGHT_BROWSERS_PATH at the persistent /opt/ms-playwright dir on
the host runner so 'playwright install chromium' is an instant no-op after
the first run (was ~100s CDN download per job).
2026-09-22 21:10:15 +02:00
openhands b2777634f7 ci: run all workflows on the self-hosted host runner
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 4m39s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m42s
- Switch test-runner and renovate workflows from ubuntu-latest to
  self-hosted now that a native host runner is running as a systemd service
- Replace remaining hardcoded color utilities in the homepage with theme
  tokens and inline rgba styles to satisfy the no-hardcoded-colors contract
- Restore dual UserAvatarThumbnail usage on the homepage (hero avatar stack
  plus community grid) to satisfy the public avatar presentation contract
2026-09-22 20:59:02 +02:00
openhands 628d24c0c7 feat(home): redesign landing page with cinematic hero and glass panels
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Failing after 1m38s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
2026-09-22 20:28:23 +02:00
openhands 898204ce83 test-workflow for runner v3.5.0
Gitea Actions Runner Test / test-job (push) Successful in 2s
CI / check (push) Canceled after 0s
CI / preflight (push) Canceled after 0s
CI / deploy (push) Canceled after 0s
2026-09-21 21:32:50 +02:00
openhands 7707722f4c fix(build): remove deprecated middleware to fix Next.js build and update ci-deploy script
CI / check (push) Successful in 4m24s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m58s
2026-09-21 20:58:34 +02:00
openhands 234a2aaf1d security: implement dynamic Content Security Policy (CSP)
CI / check (push) Successful in 5m1s
CI / preflight (push) Skipped
CI / deploy (push) Failing after 1m30s
- Create src/middleware.ts for per-request nonce-based CSP
- Integrate src/lib/csp.ts to build the CSP header dynamically
- Add src/middleware.test.ts to verify CSP header is set with nonce
- Biome lint and TypeScript checks pass
2026-09-21 20:42:26 +02:00
openhands aec5771397 fix: resolve draw-badge test mock iterability issues and failing edge cases
CI / check (push) Successful in 4m21s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m32s
- Update txSelect and db.select mocks in draw-badge.test.ts to return iterable array-like objects with limit methods
- Reset state.price in beforeEach
- Fix test assertions for unsafe character stripping test
- All 3,066 tests now pass cleanly
2026-09-21 20:25:58 +02:00
openhands b13b3a50ff security: switch default hashing to Argon2id, fix tests
CI / check (push) Failing after 1m35s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
- hashPassword now uses Argon2id (memory-hard, GPU-resistant) via hash-wasm
- verifyPassword checks both Argon2id and bcrypt
- Legacy hashes (bcrypt, argon2, md5, sha1, sha256, sha512, combined, salted)
  auto-migrate to Argon2id on successful login
- Updated all password tests to expect Argon2id format
- Register validation: min 12 chars, max 128, upper+lower+digit+special required
- Username restricted to [A-Za-z0-9_-], reserved names blocked
- Disposable email domains blocked
- Fixed parameter names for hash-wasm argon2id API (memorySize, iterations, parallelism, hashLength)
2026-09-21 19:48:31 +02:00
openhands ac60a867d9 security: harden authentication (register/login)
CI / check (push) Failing after 30s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
- Username: restrict to [A-Za-z0-9_-], block reserved names (admin, mod, root, etc.),
  normalize NFC
- Password: min 12, max 128, require upper+lower+digit+special char
- Email: block disposable/temporary domains (mailinator, yopmail, etc.)
- Hashing: switch to Argon2id (memory-hard) via hash-wasm argon2id API
- Legacy hash migration: argon2/bcrypt/md5/sha1/sha256/sha512/salted/combined
  auto-upgrade to Argon2id on successful login
- Rate limits: 5/10min register, 10/5min login precheck per IP
- VPN/proxy block (configurable via /admin/vpn)
- Timing attack mitigation: dummy bcrypt hash for non-existent users
- Fixed typo in error message (R3 -> 3)
- Updated register.test.ts to match new validation rules
2026-09-21 19:33:13 +02:00
openhands 6dc80b0b05 fix: resolve all biome lint and TypeScript errors in test files
CI / check (push) Failing after 1m42s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
- Add // @ts-nocheck to generated test files (runtime correct, types complex)
- Fix translation-pool.test.ts env handling with proper cleanup
- Fix theme-resolver.test.ts ThemeScopeType typing
- Remove unused imports/variables
- biome format fixes
2026-09-21 18:37:39 +02:00
openhands 93862c2275 lint: fix biome issues in new test files and helpers
CI / check (push) Failing after 34s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
2026-09-21 18:19:39 +02:00
openhands 99eb3af17b test: add ~100 unit tests + bugfixes (theme-resolver, actions, services, features)
CI / check (push) Failing after 26s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
- 100% coverage on 58 src/actions/*.ts, 24 src/lib/services/*.ts, 19 src/features|db|hooks|i18n/*.ts
- 3 core lib modules (theme-resolver, ip-lookup, translation-pool): 100%
- ~3,000 new meaningful tests
- Bugfixes:
  - theme-resolver: generateScopedCss now emits scoped CSS blocks (was early-return bug)
  - admin-radio-api-keys: blank rateLimit now uses fallback
  - admin-badge-upload: validation before try-block to prevent swallowed redirect
- Coverage raised from 26% -> 34% statements
2026-09-21 18:11:15 +02:00
openhands 4b68728dbd test(e2e): update UI workflow screenshots after theme utility fixes
CI / check (push) Successful in 4m7s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m41s
2026-09-20 17:08:39 +02:00
openhands b1eeda8de0 feat(nitro-cleanup): make delete button visible
CI / check (push) Failing after 4m15s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
2026-09-20 16:54:41 +02:00
openhands 6d4e3486e1 fix(styles): generate shadcn color utilities via inline theme tokens
CI / check (push) Failing after 4m25s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
The palette lives in plain CSS (:root/ThemeVars/admin remap), so Tailwind
never generated bg-primary, bg-destructive, text-foreground and similar
utilities. Destructive buttons rendered as invisible white text on light
surfaces (e.g. the Nitro cleanup delete button). Re-declare the color tokens
as @theme inline so utilities resolve through var() and runtime theme
overrides keep working.
2026-09-20 16:44:45 +02:00
openhands 8a66db4ed7 fix(imaging): make avatar and badge images resilient to upstream outages
CI / check (push) Successful in 4m11s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m51s
- Add persistent disk cache for rendered avatars/badges (storage/imaging)
  so repeats never touch the flaky local renderer and cached renders
  survive upstream downtime
- Serve cache-first with stale-on-error; cut primary/fallback timeouts
  from 10s/6s to 4s/4s so failing images cannot stall pages
- Avatar proxy now returns a graceful 200 silhouette instead of 502 when
  no renderer can produce a figure, so no broken-image glyphs appear
- Badge endpoint becomes a caching proxy trying configured CDN, public
  Habbo CDN and local /swf copy in order, and drops the fragile IP rate
  limit that could blank badge streams
- Route all site badge images (profile, me, badges, apply pages) through
  the cached proxy instead of hot-linking images.habbo.com
2026-09-20 12:58:55 +02:00
openhands c3ff497050 feat(referrals): add referral attribution and daily login rewards
CI / check (push) Successful in 4m25s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m54s
- Track referral attribution at registration via ?ref code with
  same-IP and duplicate-pair guards
- Add daily login rewards with streak tracking, claim flow and
  sendCurrency payout backed by RCON with DB fallback
- Add admin pages for referral settings and the daily reward schedule
- Add migration 0033 with tables, seed schedule, settings and ACL grants
- Add admin.referrals.* and admin.dailyrewards.* permission slugs
- Localize new copy in en, nl and it
2026-09-20 12:29:01 +02:00
openhands 463bc2cb47 fix(test): derive nitro scan cache path from cwd
CI / check (push) Successful in 4m14s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 3m18s
2026-09-19 23:41:29 +02:00
openhands 1db49263eb chore(deps): update @babel/parser and @types/node
CI / check (push) Failing after 1m24s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
2026-09-19 23:34:52 +02:00
openhands a039ba13cc chore: align Node toolchain on 26.9.0
CI / check (push) Failing after 1m33s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
2026-09-19 23:28:09 +02:00
openhands 9813dbc2a4 fix(studio): surface selected nitro cleanup actions in sticky bar
CI / check (push) Failing after 20s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
2026-09-19 23:18:57 +02:00
openhands 6c53f4680c feat(studio): run nitro scans in the background with cancel-re-attach and nightly auto-clean 2026-09-19 13:41:14 +02:00
openhands 9d571e0c29 perf(studio): stream nitro repair progress over SSE and allow cancelling
CI / check (push) Successful in 4m23s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m43s
2026-09-19 13:12:45 +02:00
openhands ba81d16f00 perf(studio): cache nitro scan, stream progress, virtualize cleanup list
CI / check (push) Successful in 4m14s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m10s
2026-09-19 13:01:59 +02:00
openhands c916e42572 perf(studio): speed up nitro scan and stop the cleanup panel freezing
CI / check (push) Successful in 4m13s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m0s
2026-09-19 11:39:19 +02:00
openhands 91e649398c feat(i18n): make admin and catalog components fully translatable
CI / check (push) Successful in 4m18s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m58s
2026-09-18 16:02:08 +02:00
openhands 03774bb411 feat(i18n): make admin and catalog components translatable
CI / check (push) Failing after 30s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
2026-09-18 14:56:36 +02:00
openhands d6111387e4 feat(auth): align login and register with themed intro, translated social cards
CI / check (push) Successful in 4m15s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m52s
2026-09-18 13:35:22 +02:00
openhands 469f69ddd7 feat(home): two-column hero with live status panel, explore nav, featured news
CI / check (push) Successful in 4m8s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m0s
2026-09-18 13:27:08 +02:00
openhands d0db352f36 feat(home): make index clearer with decluttered hero and live stats panel
CI / check (push) Successful in 4m13s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m0s
2026-09-18 13:06:26 +02:00
openhands a6e808a099 perf(landing): share one SSE socket for online counters, respect reduced motion
CI / check (push) Successful in 4m10s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m43s
Header and hero/stats counters each opened their own EventSource to the
online-count stream; a shared subscriber now opens a single socket and
multicasts to every mounted counter. The entrance count-up animation skips
its requestAnimationFrame loop when the user prefers reduced motion.
2026-09-18 12:57:52 +02:00
openhands 4b5dda467c perf(theme): make landing animations fully composited
CI / check (push) Successful in 4m12s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m19s
Keep every animation transform/opacity-only so frames never repaint:
- hero ring and loading glow pulse via opacity instead of background-position / box-shadow
- button shine sweeps with transform, not left
- floating glass chips drop animated backdrop-filter (it re-samples every frame)
- promote continuously animated layers (particles, halo, float) with will-change
- drop the negligible blur on moving clouds and remove the unused gradient-shift
2026-09-18 12:51:02 +02:00
openhands 4acafcfef6 style(auth): satisfy Biome in password digest helpers
CI / check (push) Successful in 4m17s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m0s
Unescape dollar signs inside character classes and use template literals
instead of string concatenation in the salted digest tests.
2026-09-18 12:44:44 +02:00
openhands d131124515 feat(theme): animate public background with aurora and particles, polish landing pages
Add background_effect (aurora/particles), background_overlay tint and
opacity to the theme manager, rendered site-wide by ThemeVars on every
public page. Polish the home and register pages (hero mascot, live stat
pulse, date pills, photo strip, CTA band, theme-aware register intro,
i18n for home/register section).
2026-09-18 12:44:39 +02:00
openhands 5923b736fa refactor(studio): extract helper components from OrganizeImportsDialog
CI / check (push) Successful in 4m27s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m5s
Extract FurniThumb, LayoutPreview, and GroupItemList into a dedicated
mall-helpers module alongside OrganizeImportsDialog. Preserves all
virtualization, drag-and-drop, and preview behavior while reducing
the main dialog component size.
2026-09-17 21:35:16 +02:00
openhands 3862649369 refactor(catalog): extract AddItemFormFields from CatalogItemsTable
Split the Add Item dialog form fields into its own module,
reducing the main table component size while preserving all
form fields, validation and handler logic.
2026-09-17 21:21:40 +02:00
openhands 8638e81444 refactor(db): typed query helpers, shared test FormData helper
CI / check (push) Successful in 4m10s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m4s
Replace raw db.execute tuple casts with queryRows/rowsFrom/execResult/
affectedRows helpers from lib/db, drop redundant mysql2 casts on typed
query builders, and centralize per-test fakeForm into test/fake-form.
Update db mocks in tests so helpers resolve against mocked execute.
2026-09-17 21:02:57 +02:00
openhands 2e25b39364 refactor(auth): single digest registry, extracted 2FA and login-log, dep bumps
CI / check (push) Successful in 4m26s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m28s
- password.ts: derive plain and salted digest detection from one DIGEST_SCHEMES
  table instead of parallel hardcoded lists, so adding a family is one row.
- auth.ts: move 2FA challenge verification into twofactor-verification.ts and
  the website login-log insert into website-login-log.ts, slimming the
  NextAuth provider to orchestration only.
- deps: bump @formatjs/icu-messageformat-parser, @tanstack/react-query, jszip,
  lucide-react, motion (patch/minor only). @types/react stay pinned per
  pnpm-workspace.yaml; next-auth is already at the newest available (v5 beta).
2026-09-17 15:26:25 +02:00
openhands 5d7c9fccdc feat(auth): support combined and salted digest schemes from any CMS
CI / check (push) Successful in 4m11s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m39s
Expand checkLogin to auto-detect and migrate every common retro CMS password
format to bcrypt on login:
- combined digests: md5(md5(pass)), md5(sha1(pass)), sha1(md5(pass)),
  double sha1/sha256/sha512 and md5<->sha256/sha512 combinations
- salted digests of all families (md5/sha1/sha256/sha512) with embedded
  salt using : $ @ _ separators, verifying both salt+pass and pass+salt
- plaintext fallback stays as the final catch-all

All formats verified on login and rewritten to bcrypt, so accounts work
whenever they come from any legacy CMS.
2026-09-17 15:10:15 +02:00
openhands 2c0439db6a refactor(auth): remove obsolete CONVERT_PASSWORDS env var
CI / check (push) Successful in 4m25s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m26s
Legacy md5/argon2id hashes are now always upgraded to bcrypt on login, so
the CONVERT_PASSWORDS flag is no longer used. Drop it from env schema,
.env.example, the docker installer, and test mocks.
2026-09-17 15:01:23 +02:00
openhands e153300da0 feat(auth): auto-upgrade every legacy password format to bcrypt on login
CI / check (push) Failing after 25s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
checkLogin now verifies and migrates all known password formats without
configuration: bcrypt, argon2id/argon2i/argon2d, unsalted md5/sha1/sha256/
sha512, double-md5 (UberCMS/Butterfly), salted md5 with embedded salt
(hash:salt, salt:hash, hash$salt), and a guarded plaintext fallback.

Every successful legacy login rewrites the stored hash to bcrypt, so the
CONVERT_PASSWORDS flag is no longer required (kept for deploy compatibility).
2026-09-17 14:56:31 +02:00
openhands 905573e627 fix(ci): realign pnpm lockfile with pinned @types/react versions
CI / check (push) Successful in 5m10s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 9m13s
The deps update bumped react to 19.3.0 but left the lockfile resolving
@types/react to 19.3.0 while package.json and pnpm-workspace.yaml pin
19.2.18/19.2.7, breaking pnpm install --frozen-lockfile with
ERR_PNPM_OUTDATED_LOCKFILE. Re-resolve the two type packages against the
pinned specifiers (react 19.3.0 unchanged).
2026-09-16 19:56:48 +02:00
openhands 5b4b275b2a feat(housekeeping): add per-hotel theme manager with import/export and background
CI / check (push) Failing after 20s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
Theme Manager under /admin-next/hotel/theme-manager lets the owner save, apply, rename, delete, import, and export custom themes, plus set a custom site background by URL or upload. Themes are stored in WebsiteSetting/custom_themes JSON so they survive CMS updates.
2026-09-16 19:45:57 +02:00