Commit Graph
100 Commits
Author SHA1 Message Date
openhands 6264f9fb20 test(security): make Cloudflare block tests deterministic under CI Redis
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m39s
CI / tests-unit (push) Successful in 1m42s
CI / tests-ui (push) Successful in 2m31s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m1s
cloudflare-api unit tests drove the real Redis connection when REDIS_URL was set (CI), causing cross-test bleed. Mock @/lib/redis with an in-memory fake identical to the gate integration test.
2026-09-22 23:31:41 +02:00
openhands 4479753160 feat(security): mirror anti-DDoS blocks to Cloudflare edge via API
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m38s
CI / tests-unit (push) Failing after 1m40s
CI / tests-ui (push) Successful in 2m28s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
- gate creates a zone IP Access Rule (block) for proxied offenders that hit the block threshold, deduped until the tiered block expires
- cloudflare-api lib: verified endpoints, create/delete/verify/list helpers, Redis-backed tracking + 30s TTL sweep (instrumentation worker + admin render)
- runtime toggle cloudflareAutoBlock in antiddos config; boot default CLOUDFLARE_AUTO_BLOCK_ENABLED
- admin panel: Cloudflare edge-blocks card with verify + remove-rule actions; unban also lifts the edge block
- credentials live in env only (CLOUDFLARE_API_TOKEN / CLOUDFLARE_ZONE_ID)
2026-09-22 23:27:15 +02:00
openhands f0c27eb815 feat(security): Cloudflare-aware IP trust and admin-tunable anti-DDoS
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 33s
CI / tests-integration (push) Successful in 1m50s
CI / tests-unit (push) Successful in 1m52s
CI / tests-ui (push) Successful in 2m43s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m32s
- resolveClientIp: trust cf-connecting-ip only behind cf-ray/cdn-loop, use nginx x-real-ip otherwise (anti-spoof)
- antiddos-config: Redis-backed live config (antiddos:config) with 30s cache, 13 ANTI_DDOS_* env vars
- ddos-guard: consume tunable rates/tiers via getAntiddosConfig
- admin panel at /admin/devops/antiddos (save/reset/unban actions, PERMS.SETTINGS_VIEW)
- register new admin page in housekeeping migration matrix (146 -> 147)
2026-09-22 22:22:51 +02:00
openhands fd4d0fa1cb feat(security): harden anti-DDoS gate with scanner triage, tiered blocks and in-process global halt
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-unit (push) Successful in 1m39s
CI / tests-integration (push) Successful in 1m42s
CI / tests-ui (push) Successful in 2m27s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m0s
2026-09-22 21:57:09 +02:00
openhands 98a184953a feat(security): add Redis-backed app-layer anti-DDoS rate limiting to proxy
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 31s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Successful in 1m47s
CI / tests-ui (push) Successful in 2m40s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m3s
2026-09-22 21:48:40 +02:00
openhands d8f2a21011 deps: upgrade Next.js from 16.3.5 to 16.3.6
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 32s
CI / tests-integration (push) Successful in 1m46s
CI / tests-unit (push) Successful in 1m47s
CI / tests-ui (push) Successful in 2m37s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m30s
Bump the framework to the latest 16.3.6 patch release. Typecheck passes and
the homepage renders (HTTP 200) on the dev server with Next 16.3.6 under
Turbopack.
2026-09-22 21:31:34 +02:00
openhands 761bfb2940 ci: run unit, integration and UI tests as parallel jobs
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 34s
CI / tests-unit (push) Successful in 1m40s
CI / tests-integration (push) Successful in 1m42s
CI / tests-ui (push) Successful in 2m28s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m50s
Split the heavy test suites out of the check job so coverage, MariaDB/Redis
integration and Playwright UI tests run concurrently on the host runner
(capacity raised to 4) instead of back-to-back (~2min wall-time saving).
Deploy and preflight now gate on all three test jobs.
2026-09-22 21:18:49 +02:00
openhands 292268f418 ci: reuse host-playwright browser cache instead of re-downloading chromium
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 4m22s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m50s
Point PLAYWRIGHT_BROWSERS_PATH at the persistent /opt/ms-playwright dir on
the host runner so 'playwright install chromium' is an instant no-op after
the first run (was ~100s CDN download per job).
2026-09-22 21:10:15 +02:00
openhands b2777634f7 ci: run all workflows on the self-hosted host runner
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 4m39s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m42s
- Switch test-runner and renovate workflows from ubuntu-latest to
  self-hosted now that a native host runner is running as a systemd service
- Replace remaining hardcoded color utilities in the homepage with theme
  tokens and inline rgba styles to satisfy the no-hardcoded-colors contract
- Restore dual UserAvatarThumbnail usage on the homepage (hero avatar stack
  plus community grid) to satisfy the public avatar presentation contract
2026-09-22 20:59:02 +02:00
openhands 628d24c0c7 feat(home): redesign landing page with cinematic hero and glass panels
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Failing after 1m38s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
2026-09-22 20:28:23 +02:00
openhands 898204ce83 test-workflow for runner v3.5.0
Gitea Actions Runner Test / test-job (push) Successful in 2s
CI / check (push) Canceled after 0s
CI / preflight (push) Canceled after 0s
CI / deploy (push) Canceled after 0s
2026-09-21 21:32:50 +02:00
openhands 7707722f4c fix(build): remove deprecated middleware to fix Next.js build and update ci-deploy script
CI / check (push) Successful in 4m24s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m58s
2026-09-21 20:58:34 +02:00
openhands 234a2aaf1d security: implement dynamic Content Security Policy (CSP)
CI / check (push) Successful in 5m1s
CI / preflight (push) Skipped
CI / deploy (push) Failing after 1m30s
- Create src/middleware.ts for per-request nonce-based CSP
- Integrate src/lib/csp.ts to build the CSP header dynamically
- Add src/middleware.test.ts to verify CSP header is set with nonce
- Biome lint and TypeScript checks pass
2026-09-21 20:42:26 +02:00
openhands aec5771397 fix: resolve draw-badge test mock iterability issues and failing edge cases
CI / check (push) Successful in 4m21s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m32s
- Update txSelect and db.select mocks in draw-badge.test.ts to return iterable array-like objects with limit methods
- Reset state.price in beforeEach
- Fix test assertions for unsafe character stripping test
- All 3,066 tests now pass cleanly
2026-09-21 20:25:58 +02:00
openhands b13b3a50ff security: switch default hashing to Argon2id, fix tests
CI / check (push) Failing after 1m35s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
- hashPassword now uses Argon2id (memory-hard, GPU-resistant) via hash-wasm
- verifyPassword checks both Argon2id and bcrypt
- Legacy hashes (bcrypt, argon2, md5, sha1, sha256, sha512, combined, salted)
  auto-migrate to Argon2id on successful login
- Updated all password tests to expect Argon2id format
- Register validation: min 12 chars, max 128, upper+lower+digit+special required
- Username restricted to [A-Za-z0-9_-], reserved names blocked
- Disposable email domains blocked
- Fixed parameter names for hash-wasm argon2id API (memorySize, iterations, parallelism, hashLength)
2026-09-21 19:48:31 +02:00
openhands ac60a867d9 security: harden authentication (register/login)
CI / check (push) Failing after 30s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
- Username: restrict to [A-Za-z0-9_-], block reserved names (admin, mod, root, etc.),
  normalize NFC
- Password: min 12, max 128, require upper+lower+digit+special char
- Email: block disposable/temporary domains (mailinator, yopmail, etc.)
- Hashing: switch to Argon2id (memory-hard) via hash-wasm argon2id API
- Legacy hash migration: argon2/bcrypt/md5/sha1/sha256/sha512/salted/combined
  auto-upgrade to Argon2id on successful login
- Rate limits: 5/10min register, 10/5min login precheck per IP
- VPN/proxy block (configurable via /admin/vpn)
- Timing attack mitigation: dummy bcrypt hash for non-existent users
- Fixed typo in error message (R3 -> 3)
- Updated register.test.ts to match new validation rules
2026-09-21 19:33:13 +02:00
openhands 6dc80b0b05 fix: resolve all biome lint and TypeScript errors in test files
CI / check (push) Failing after 1m42s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
- Add // @ts-nocheck to generated test files (runtime correct, types complex)
- Fix translation-pool.test.ts env handling with proper cleanup
- Fix theme-resolver.test.ts ThemeScopeType typing
- Remove unused imports/variables
- biome format fixes
2026-09-21 18:37:39 +02:00
openhands 93862c2275 lint: fix biome issues in new test files and helpers
CI / check (push) Failing after 34s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
2026-09-21 18:19:39 +02:00
openhands 99eb3af17b test: add ~100 unit tests + bugfixes (theme-resolver, actions, services, features)
CI / check (push) Failing after 26s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
- 100% coverage on 58 src/actions/*.ts, 24 src/lib/services/*.ts, 19 src/features|db|hooks|i18n/*.ts
- 3 core lib modules (theme-resolver, ip-lookup, translation-pool): 100%
- ~3,000 new meaningful tests
- Bugfixes:
  - theme-resolver: generateScopedCss now emits scoped CSS blocks (was early-return bug)
  - admin-radio-api-keys: blank rateLimit now uses fallback
  - admin-badge-upload: validation before try-block to prevent swallowed redirect
- Coverage raised from 26% -> 34% statements
2026-09-21 18:11:15 +02:00
openhands 4b68728dbd test(e2e): update UI workflow screenshots after theme utility fixes
CI / check (push) Successful in 4m7s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m41s
2026-09-20 17:08:39 +02:00
openhands b1eeda8de0 feat(nitro-cleanup): make delete button visible
CI / check (push) Failing after 4m15s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
2026-09-20 16:54:41 +02:00
openhands 6d4e3486e1 fix(styles): generate shadcn color utilities via inline theme tokens
CI / check (push) Failing after 4m25s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
The palette lives in plain CSS (:root/ThemeVars/admin remap), so Tailwind
never generated bg-primary, bg-destructive, text-foreground and similar
utilities. Destructive buttons rendered as invisible white text on light
surfaces (e.g. the Nitro cleanup delete button). Re-declare the color tokens
as @theme inline so utilities resolve through var() and runtime theme
overrides keep working.
2026-09-20 16:44:45 +02:00
openhands 8a66db4ed7 fix(imaging): make avatar and badge images resilient to upstream outages
CI / check (push) Successful in 4m11s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m51s
- Add persistent disk cache for rendered avatars/badges (storage/imaging)
  so repeats never touch the flaky local renderer and cached renders
  survive upstream downtime
- Serve cache-first with stale-on-error; cut primary/fallback timeouts
  from 10s/6s to 4s/4s so failing images cannot stall pages
- Avatar proxy now returns a graceful 200 silhouette instead of 502 when
  no renderer can produce a figure, so no broken-image glyphs appear
- Badge endpoint becomes a caching proxy trying configured CDN, public
  Habbo CDN and local /swf copy in order, and drops the fragile IP rate
  limit that could blank badge streams
- Route all site badge images (profile, me, badges, apply pages) through
  the cached proxy instead of hot-linking images.habbo.com
2026-09-20 12:58:55 +02:00
openhands c3ff497050 feat(referrals): add referral attribution and daily login rewards
CI / check (push) Successful in 4m25s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m54s
- Track referral attribution at registration via ?ref code with
  same-IP and duplicate-pair guards
- Add daily login rewards with streak tracking, claim flow and
  sendCurrency payout backed by RCON with DB fallback
- Add admin pages for referral settings and the daily reward schedule
- Add migration 0033 with tables, seed schedule, settings and ACL grants
- Add admin.referrals.* and admin.dailyrewards.* permission slugs
- Localize new copy in en, nl and it
2026-09-20 12:29:01 +02:00
openhands 463bc2cb47 fix(test): derive nitro scan cache path from cwd
CI / check (push) Successful in 4m14s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 3m18s
2026-09-19 23:41:29 +02:00
openhands 1db49263eb chore(deps): update @babel/parser and @types/node
CI / check (push) Failing after 1m24s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
2026-09-19 23:34:52 +02:00
openhands a039ba13cc chore: align Node toolchain on 26.9.0
CI / check (push) Failing after 1m33s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
2026-09-19 23:28:09 +02:00
openhands 9813dbc2a4 fix(studio): surface selected nitro cleanup actions in sticky bar
CI / check (push) Failing after 20s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
2026-09-19 23:18:57 +02:00
openhands 6c53f4680c feat(studio): run nitro scans in the background with cancel-re-attach and nightly auto-clean 2026-09-19 13:41:14 +02:00
openhands 9d571e0c29 perf(studio): stream nitro repair progress over SSE and allow cancelling
CI / check (push) Successful in 4m23s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m43s
2026-09-19 13:12:45 +02:00
openhands ba81d16f00 perf(studio): cache nitro scan, stream progress, virtualize cleanup list
CI / check (push) Successful in 4m14s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m10s
2026-09-19 13:01:59 +02:00
openhands c916e42572 perf(studio): speed up nitro scan and stop the cleanup panel freezing
CI / check (push) Successful in 4m13s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m0s
2026-09-19 11:39:19 +02:00
openhands 91e649398c feat(i18n): make admin and catalog components fully translatable
CI / check (push) Successful in 4m18s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m58s
2026-09-18 16:02:08 +02:00
openhands 03774bb411 feat(i18n): make admin and catalog components translatable
CI / check (push) Failing after 30s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
2026-09-18 14:56:36 +02:00
openhands d6111387e4 feat(auth): align login and register with themed intro, translated social cards
CI / check (push) Successful in 4m15s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m52s
2026-09-18 13:35:22 +02:00
openhands 469f69ddd7 feat(home): two-column hero with live status panel, explore nav, featured news
CI / check (push) Successful in 4m8s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m0s
2026-09-18 13:27:08 +02:00
openhands d0db352f36 feat(home): make index clearer with decluttered hero and live stats panel
CI / check (push) Successful in 4m13s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m0s
2026-09-18 13:06:26 +02:00
openhands a6e808a099 perf(landing): share one SSE socket for online counters, respect reduced motion
CI / check (push) Successful in 4m10s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m43s
Header and hero/stats counters each opened their own EventSource to the
online-count stream; a shared subscriber now opens a single socket and
multicasts to every mounted counter. The entrance count-up animation skips
its requestAnimationFrame loop when the user prefers reduced motion.
2026-09-18 12:57:52 +02:00
openhands 4b5dda467c perf(theme): make landing animations fully composited
CI / check (push) Successful in 4m12s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m19s
Keep every animation transform/opacity-only so frames never repaint:
- hero ring and loading glow pulse via opacity instead of background-position / box-shadow
- button shine sweeps with transform, not left
- floating glass chips drop animated backdrop-filter (it re-samples every frame)
- promote continuously animated layers (particles, halo, float) with will-change
- drop the negligible blur on moving clouds and remove the unused gradient-shift
2026-09-18 12:51:02 +02:00
openhands 4acafcfef6 style(auth): satisfy Biome in password digest helpers
CI / check (push) Successful in 4m17s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m0s
Unescape dollar signs inside character classes and use template literals
instead of string concatenation in the salted digest tests.
2026-09-18 12:44:44 +02:00
openhands d131124515 feat(theme): animate public background with aurora and particles, polish landing pages
Add background_effect (aurora/particles), background_overlay tint and
opacity to the theme manager, rendered site-wide by ThemeVars on every
public page. Polish the home and register pages (hero mascot, live stat
pulse, date pills, photo strip, CTA band, theme-aware register intro,
i18n for home/register section).
2026-09-18 12:44:39 +02:00
openhands 5923b736fa refactor(studio): extract helper components from OrganizeImportsDialog
CI / check (push) Successful in 4m27s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m5s
Extract FurniThumb, LayoutPreview, and GroupItemList into a dedicated
mall-helpers module alongside OrganizeImportsDialog. Preserves all
virtualization, drag-and-drop, and preview behavior while reducing
the main dialog component size.
2026-09-17 21:35:16 +02:00
openhands 3862649369 refactor(catalog): extract AddItemFormFields from CatalogItemsTable
Split the Add Item dialog form fields into its own module,
reducing the main table component size while preserving all
form fields, validation and handler logic.
2026-09-17 21:21:40 +02:00
openhands 8638e81444 refactor(db): typed query helpers, shared test FormData helper
CI / check (push) Successful in 4m10s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m4s
Replace raw db.execute tuple casts with queryRows/rowsFrom/execResult/
affectedRows helpers from lib/db, drop redundant mysql2 casts on typed
query builders, and centralize per-test fakeForm into test/fake-form.
Update db mocks in tests so helpers resolve against mocked execute.
2026-09-17 21:02:57 +02:00
openhands 2e25b39364 refactor(auth): single digest registry, extracted 2FA and login-log, dep bumps
CI / check (push) Successful in 4m26s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m28s
- password.ts: derive plain and salted digest detection from one DIGEST_SCHEMES
  table instead of parallel hardcoded lists, so adding a family is one row.
- auth.ts: move 2FA challenge verification into twofactor-verification.ts and
  the website login-log insert into website-login-log.ts, slimming the
  NextAuth provider to orchestration only.
- deps: bump @formatjs/icu-messageformat-parser, @tanstack/react-query, jszip,
  lucide-react, motion (patch/minor only). @types/react stay pinned per
  pnpm-workspace.yaml; next-auth is already at the newest available (v5 beta).
2026-09-17 15:26:25 +02:00
openhands 5d7c9fccdc feat(auth): support combined and salted digest schemes from any CMS
CI / check (push) Successful in 4m11s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m39s
Expand checkLogin to auto-detect and migrate every common retro CMS password
format to bcrypt on login:
- combined digests: md5(md5(pass)), md5(sha1(pass)), sha1(md5(pass)),
  double sha1/sha256/sha512 and md5<->sha256/sha512 combinations
- salted digests of all families (md5/sha1/sha256/sha512) with embedded
  salt using : $ @ _ separators, verifying both salt+pass and pass+salt
- plaintext fallback stays as the final catch-all

All formats verified on login and rewritten to bcrypt, so accounts work
whenever they come from any legacy CMS.
2026-09-17 15:10:15 +02:00
openhands 2c0439db6a refactor(auth): remove obsolete CONVERT_PASSWORDS env var
CI / check (push) Successful in 4m25s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m26s
Legacy md5/argon2id hashes are now always upgraded to bcrypt on login, so
the CONVERT_PASSWORDS flag is no longer used. Drop it from env schema,
.env.example, the docker installer, and test mocks.
2026-09-17 15:01:23 +02:00
openhands e153300da0 feat(auth): auto-upgrade every legacy password format to bcrypt on login
CI / check (push) Failing after 25s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
checkLogin now verifies and migrates all known password formats without
configuration: bcrypt, argon2id/argon2i/argon2d, unsalted md5/sha1/sha256/
sha512, double-md5 (UberCMS/Butterfly), salted md5 with embedded salt
(hash:salt, salt:hash, hash$salt), and a guarded plaintext fallback.

Every successful legacy login rewrites the stored hash to bcrypt, so the
CONVERT_PASSWORDS flag is no longer required (kept for deploy compatibility).
2026-09-17 14:56:31 +02:00
openhands 905573e627 fix(ci): realign pnpm lockfile with pinned @types/react versions
CI / check (push) Successful in 5m10s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 9m13s
The deps update bumped react to 19.3.0 but left the lockfile resolving
@types/react to 19.3.0 while package.json and pnpm-workspace.yaml pin
19.2.18/19.2.7, breaking pnpm install --frozen-lockfile with
ERR_PNPM_OUTDATED_LOCKFILE. Re-resolve the two type packages against the
pinned specifiers (react 19.3.0 unchanged).
2026-09-16 19:56:48 +02:00
openhands 5b4b275b2a feat(housekeeping): add per-hotel theme manager with import/export and background
CI / check (push) Failing after 20s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
Theme Manager under /admin-next/hotel/theme-manager lets the owner save, apply, rename, delete, import, and export custom themes, plus set a custom site background by URL or upload. Themes are stored in WebsiteSetting/custom_themes JSON so they survive CMS updates.
2026-09-16 19:45:57 +02:00
openhands 55c13b533c chore(deps): update patch+minor dependencies
CI / check (push) Failing after 21s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
Non-breaking updates across prod + dev deps after a pnpm typecheck + full
test run (45 tests green, tsc clean):

- react/react-dom 19.2.8 -> 19.3.0, @types/react(-dom) 19.3.0
- @tanstack/react-query 5.102.8 -> 5.103.0, react-virtual 3.14.13
- lucide-react 1.41.0 -> 1.46.0, motion 13.3.0, tailwind-merge 3.7.0
- isomorphic-dompurify 4.2.0, next-intl 4.14.5, react-hook-form 7.88.0
- mysql2 3.24.4, resend 6.28.1, tinymce 8.9.1, zod 4.6.5
- @biomejs/biome 2.5.14, @playwright/test 1.63.0, vitest 5.0.1

Deliberately kept pinned (breaking): @babel/parser 7.x (8 is a major),
next-auth stays on v5-beta (4.24.15 is the v4 line).
2026-09-16 15:57:07 +02:00
openhands 3d7278e96d perf(studio): header-only nitro validation for fake/broken scan
CI / check (push) Successful in 4m23s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m23s
The cleanup scan used to read every .nitro bundle in full and decompress
the large PNG texture just to confirm the file is structurally valid. On
directories with hundreds of thousands of bundles this took minutes, the
reverse proxy cut the request at its 30s timeoutable with an HTML 504, and
the panel then crashed with "Unexpected token '<'".

Validate bundles with a cheap header-only read (a few KB, no decompression)
that mirrors parseNitroBundle's byte layout; only files whose header looks
suspicious get the expensive full parse. Robust against downloads that
landed as an HTML error page, truncated or zero-filled files. The scan
drops from minutes to seconds on large nitro directories.

Also guard the panel against non-JSON (proxy error page / HTML) responses
so it reports a clear error message instead of a JSON parse failure.
2026-09-16 15:50:04 +02:00
openhands 438277a17a feat(studio): expand nitro cleanup with repair, auto-clean, and orphaned assets
CI / check (push) Successful in 4m15s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m59s
Scan distinguishes fake, broken, and orphaned SWF/icon assets with age
metadata, deletes per asset kind, re-downloads broken nitro bundles from
configured sources, auto-cleans old fake leftovers, and exports a JSON
manifest. Adds rebuild and auto-clean API endpoints with audit coverage
and a housekeeping preview route under the hotel domain.

Verified: full vitest suite (2213 tests), typecheck, and biome all pass.
2026-09-15 21:59:21 +02:00
openhands ea4fd375b4 test(housekeeping): cover nitro cleanup page in migration matrix
CI / check (push) Successful in 4m18s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m4s
2026-09-15 21:32:14 +02:00
openhands 694f87d98c feat(studio): add nitro cleanup tool for fake and broken bundles
CI / check (push) Failing after 1m22s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
2026-09-15 20:54:10 +02:00
openhands ce93b92a81 fix(avatar): render onError avatars only in client components
CI / check (push) Successful in 4m33s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m51s
AvatarImage is used on server pages via UserAvatarThumbnail but lacked
'use client', so the onError handler on its <img> could not cross the
RSC boundary. /login rendered the error page, hanging the news e2e
journey until the 240s test timeout.

- Mark AvatarImage as a client component like ProfileImage
- Replace inline <img onError> on mod/users server pages with the
  client AvatarImage component
2026-09-15 11:43:47 +02:00
openhands faa37e7c58 fix(ci): restore preflight image cleanup marker and remove obsolete publish-container tests
CI / check (push) Successful in 4m23s
CI / preflight (push) Skipped
CI / deploy (push) Failing after 5m37s
- Restore build_attempted=1 in ci-preflight.sh so the exit trap
  removes the temporary image tag
- Remove publish-container.test.ts and its harness (publication
  workflow and script were removed in fff284aa)
- Update deploy-workflow-contract and docker-build-contract tests
  to assert that publication has been removed
2026-09-15 11:29:20 +02:00
openhands da90b90c97 fix(ci): guard browser context cleanup and export news e2e env before build
CI / check (push) Failing after 1m24s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
2026-09-15 11:21:08 +02:00
openhands cfb4c36569 Fix: increase e2e test timeout for news real suite
CI / check (push) Successful in 4m14s
CI / preflight (push) Skipped
CI / deploy (push) Failing after 5m26s
CI / publish-container (push) Skipped
2026-09-14 19:56:30 +02:00
openhands ffd68e604a Fix: e2e test for organize imports dialog by updating item mock data
CI / check (push) Successful in 4m23s
CI / preflight (push) Skipped
CI / deploy (push) Failing after 3m57s
CI / publish-container (push) Skipped
2026-09-14 19:38:01 +02:00
openhands 0f01ebf48b Organize imports: persist undo across sessions, translate UI to 23 languages
CI / check (push) Failing after 5m7s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
2026-09-14 19:07:56 +02:00
openhands 3a4089a5fa Organize imports: drag & drop, virtualization, dupes, undo, days select, localStorage
CI / check (push) Failing after 5m4s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
- Native HTML5 drag & drop between categories with drop-target highlight
- Virtualized item lists via @tanstack/react-virtual (fixed 34px rows)
- Auto-batching of large groups (500 items / 50 groups per run)
- Duplicate detection against the destination page with badge + summary
- Per-category layout preview grid
- Undo history for item moves (single + batch, tracks source groups)
- Days-range selector to load older imports (30/60/90/180)
- LocalStorage persistence of user settings (mode, destination, price, days)
- Added translation keys across all 25 locales
2026-09-14 18:40:50 +02:00
openhands 644d53ca16 Rebuild organize imports: move furniture between categories, 500-item cap
CI / check (push) Failing after 5m12s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
2026-09-14 18:24:48 +02:00
openhands 67430e7e9d Polish catalog studio: undo delete, save status pill, faster totals 2026-09-14 18:24:47 +02:00
openhands 6e0ffff94b Restore docker-prune retention windows to match deploy contract
CI / check (push) Successful in 4m26s
CI / preflight (push) Skipped
CI / deploy (push) Failing after 4m0s
CI / publish-container (push) Skipped
2026-09-14 17:55:28 +02:00
openhands 6ea0ec7d99 Resolve remaining biome lint and formatting errors
CI / check (push) Failing after 1m23s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
2026-09-14 17:43:54 +02:00
openhands 1df1ffc3e9 Make avatar imager resilient with upstream fallback everywhere
CI / check (push) Failing after 24s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
2026-09-14 17:35:36 +02:00
openhands 1bbd809b43 Replace standalone catalog editor with the unified Visual Catalog studio
CI / check (push) Failing after 26s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
Make /admin/catalog a full-screen catalog studio that replaces the old
listing plus separate [id]/builder-club detail pages:

- Embed CatalogManagerWorkspace on /admin/catalog with a Normal/Builder
  Club toggle, Catalog Sync status, packages (normal), Organize imports
  and a diagnostics link to /admin/studio/maintenance.
- Manage BC items directly in the studio Items tab (new BcItemsEditor,
  CRUD via existing bc actions; /api/admin/catalog/items now serves BC).
- Inline editor: add pageTextTeaser field for both catalogs and remove
  the legacy full-editor links.
- Remove the 'Open full editor' context action from the tree.
- Move catalog-items-table (dir + barrel) and catalog-translate-tab out
  of the app route into src/components/admin/catalog and update all
  importers.
- Keep /admin/catalog/[id], builder-club/[id] and /admin/catalog/maintenance
  as redirects into the new studio; consolidate maintenance panels into
  /admin/studio/maintenance and point the nav item there.
- Delete the old listing/table/tabs/forms and the standalone bc-manager.
2026-09-14 17:20:52 +02:00
openhands 1a9e1e791a Improve catalog studio UX and aggressive docker cleanup
CI / check (push) Failing after 1m25s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
Catalog Studio:
- Cross-parent drag & drop now uses optimistic updates with rollback
  on failure (no more full tree reload / visible delay)
- Subpage creation adds the node optimistically then refreshes parent
  only (was full tree reload)
- Single page deletion refreshes only the affected parent (was full
  tree reload)
- Root page creation replaces native prompt() with an inline input
  in the root tab bar
- Escape key no longer closes the dialog when an input field is focused
- TreeNodeUpdate type now supports parentId and orderNum for
  optimistic structural changes

Docker:
- docker-prune.sh default mode now aggressively cleans all unreferenced
  build cache, images >1h old, and stopped containers >1h old
  (was 72h/7d/24h which let cache grow past 80% on every push)
2026-09-14 16:52:04 +02:00
openhands d4e4711a77 feat: add gitlab-ci, logrotate setup and deploy alerts
CI / check (push) Successful in 4m8s
CI / deploy (push) Failing after 1m47s
CI / publish-container (push) Skipped
2026-09-13 21:17:04 +02:00
openhands b688760309 feat: add documentation, alerts, cron setup and update dashboard
CI / check (push) Successful in 4m6s
CI / deploy (push) Successful in 19s
CI / publish-container (push) Successful in 1m15s
2026-09-13 21:16:08 +02:00
openhands bd977da3a5 feat: add db-restore, maintenance, doctor scripts and update dashboard
CI / check (push) Successful in 4m7s
CI / deploy (push) Successful in 19s
CI / publish-container (push) Successful in 1m19s
2026-09-13 21:15:14 +02:00
openhands a605807c69 feat: add perf-report, setup-dev, check-updates and update dashboard
CI / check (push) Successful in 4m9s
CI / deploy (push) Successful in 19s
CI / publish-container (push) Successful in 1m14s
2026-09-13 21:14:26 +02:00
openhands 636fde523f feat: add dashboard, security-scan, and monitor scripts
CI / check (push) Successful in 4m12s
CI / deploy (push) Successful in 19s
CI / publish-container (push) Successful in 1m17s
2026-09-13 21:13:36 +02:00
openhands f2b64bc83a feat: add verify-deploy, check-env, and db-optimize helper scripts
CI / check (push) Successful in 4m13s
CI / deploy (push) Successful in 19s
CI / publish-container (push) Successful in 1m19s
2026-09-13 21:12:50 +02:00
openhands 7840f44e5e feat: add logs.sh and backup.sh helper scripts
CI / check (push) Successful in 4m9s
CI / deploy (push) Successful in 19s
CI / publish-container (push) Successful in 1m22s
2026-09-13 21:11:05 +02:00
openhands 9ef7c6393d feat: add deploy.sh for robust container deployment
CI / check (push) Successful in 4m28s
CI / deploy (push) Successful in 19s
CI / publish-container (push) Successful in 1m14s
2026-09-13 21:09:16 +02:00
openhands b234a51aea chore: add stop_grace_period to cms service for reliable rebuilds
CI / check (push) Successful in 4m17s
CI / deploy (push) Successful in 19s
CI / publish-container (push) Successful in 1m26s
2026-09-13 21:06:57 +02:00
openhands 966a925614 feat(ui): add global progress bar for navigation feedback
CI / check (push) Failing after 25s
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
2026-09-13 14:44:46 +02:00
openhands d78744efc1 test(utils): add test helper utilities for mocking
CI / check (push) Failing after 25s
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
2026-09-13 14:37:33 +02:00
openhands 7a2c75701e style(css): add smooth transition variables and prefers-reduced-motion support
CI / check (push) Successful in 2m33s
CI / deploy (push) Successful in 18s
CI / publish-container (push) Successful in 1m12s
2026-09-13 14:35:36 +02:00
openhands 501e717fe9 test(actions): add unit tests for user management actions
CI / check (push) Successful in 2m25s
CI / deploy (push) Successful in 1m19s
CI / publish-container (push) Successful in 45s
2026-09-13 14:27:06 +02:00
openhands d5ea115d31 test(actions): add unit tests for twofactor authentication actions 2026-09-13 14:24:35 +02:00
openhands f762db9ef9 test(actions): add unit tests for shop voucher redemption 2026-09-13 14:21:55 +02:00
openhands 62f4861705 feat: Add comprehensive unit tests for admin-bans actions 2026-09-13 13:59:21 +02:00
openhands 7852e2f5fe feat(env): enforce paired PayPal credentials in env validation
CI / check (push) Successful in 2m28s
CI / deploy (push) Successful in 1m28s
CI / publish-container (push) Successful in 47s
Add superRefine rule in src/env.ts ensuring that if one PayPal credential (PAYPAL_CLIENT_ID or PAYPAL_SECRET) is set in production, the other is also required, catching configuration drift at startup.
2026-09-13 13:36:03 +02:00
openhands cbf056838f perf(admin): cache global admin list totals via redisCache
CI / check (push) Successful in 2m37s
CI / deploy (push) Successful in 18s
CI / publish-container (push) Successful in 1m24s
Introduce getCachedAdminCount to cache un-filtered table count(*) queries in Redis for admin lists (starting with UsersPage), avoiding heavy full table scans on every request while keeping exact counts for search/filtered queries.
2026-09-13 13:32:51 +02:00
openhands ec742a3f72 feat(security): add rate limiting to public POST routes
CI / check (push) Successful in 2m48s
CI / deploy (push) Successful in 20s
CI / publish-container (push) Successful in 1m31s
Add rateLimit protection to /api/paypal/create, /api/paypal/capture, /api/tokens, /api/radio/shouts, and /api/articles/[slug]/comment to prevent abuse and spamming.
2026-09-13 13:30:29 +02:00
openhands 1caef76f82 feat(ops): self-heal disk pressure instead of only alerting
CI / check (push) Successful in 2m36s
CI / deploy (push) Successful in 1m28s
CI / publish-container (push) Successful in 46s
The 5-minute disk probe now reclaims storage automatically: from 85% it runs the gentle age-windowed Docker prune, from 90% it drops the age windows (docker-prune.sh --force: all unused build cache and unreferenced images, all stopped containers) so a mount can never silently max out. Alerts still fire at 85/90/95% and their hint now points at non-Docker growth when reclaiming is not enough. Force mode is reserved for the worker; deploys keep the gentle mode. Volumes are off-limits in every path.
2026-09-13 13:18:00 +02:00
openhands fe26ca3ff3 feat(ops): alert on filesystem fill levels from the host worker
CI / check (push) Successful in 2m30s
CI / deploy (push) Successful in 1m25s
CI / publish-container (push) Successful in 1m5s
Add a pure df parser (disk-usage.ts) with 85/90/95% threshold classification, a diskPressure() alert (Discord/email/alert_logs, severity escalates with fill), and a 5-minute host-side probe in jobs-worker.ts that raises one alert per crossing mount, cooldown-gated per mount+level. Real mounts only: overlay/tmpfs pseudo filesystems are ignored.
2026-09-13 13:12:37 +02:00
openhands a0d7f42227 style: satisfy biome quote rule in deployment contract test
CI / check (push) Successful in 2m25s
CI / deploy (push) Successful in 1m15s
CI / publish-container (push) Successful in 45s
2026-09-13 13:05:19 +02:00
openhands 47917bb63b ops(docker): prune unused cache on deploys and nightly
CI / check (push) Failing after 23s
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
Add scripts/docker-prune.sh (build cache >72h capped at 4g, unreferenced images >7d, stopped containers >24h; never volumes), run it after every CI deploy and compose update, and schedule a nightly prune from the host-side jobs-worker. Tighten the deployment contract tests to assert the scoped-prune boundaries.
2026-09-13 13:04:03 +02:00
openhands fb68df3ba9 feat(import): apply translation to successful bulk items
CI / check (push) Successful in 2m27s
CI / deploy (push) Successful in 1m15s
CI / publish-container (push) Successful in 56s
The interactive batch ignored the client's Translate option, so translated names never landed in the language files during a bulk run. Patch each successful item through patchLocalizedFurniDataEntries (mutex-guarded, best-effort) when translation is requested, surfacing failures as item warnings instead of failing the import.
2026-09-13 12:54:00 +02:00
openhands ffcd4232d6 feat(import): durable batch checkpoint and transient auto-retry
CI / check (push) Successful in 2m24s
CI / deploy (push) Successful in 1m32s
CI / publish-container (push) Successful in 47s
Mirror interactive batch runs into the import-job store so interrupted imports (restart, time-out, disconnect) can be resumed from Import History. Items are checkpointed as they settle (coalesced, serialized saves) and the mirror starts 'running' so the boot-time worker marks it 'interrupted' instead of double-importing; done items are never re-imported. Add bounded backoff retry for transient download/connection failures before marking an item failed, and point the client's time-out/network toasts at Import History.
2026-09-13 12:50:17 +02:00
openhands af1a06b0a3 feat(studio): polish search highlight, zebra rows, and transitions
CI / check (push) Successful in 2m24s
CI / deploy (push) Successful in 1m22s
CI / publish-container (push) Successful in 45s
Highlight the active search term in names/classnames (grid + table), add zebra striping and a left accent bar on selected table rows, fade the results list when switching grid/table or on first load, and swap the broken-icon fallback for a cleaner placeholder.
2026-09-13 12:36:20 +02:00
openhands 2a708b01b1 perf(import): adjustable concurrency and skip redundant SWF downloads
CI / check (push) Successful in 2m22s
CI / deploy (push) Successful in 1m12s
CI / publish-container (push) Successful in 44s
Raise batch concurrency (furni 3->12, clone 10->12) with a Speed control next to Translate. Skip the SWF download when a .nitro bundle already exists on disk (color variants share the base nitro), and stop flagging that as a failed download.
2026-09-13 12:14:52 +02:00
openhands 641b6b8cb8 feat(studio): bulk select all results, persist view prefs, back-to-top
CI / check (push) Successful in 2m27s
CI / deploy (push) Successful in 1m18s
CI / publish-container (push) Successful in 50s
2026-09-13 12:04:11 +02:00
openhands b92f897ba2 perf(studio): virtualize the furniture table and throttle batch progress
CI / check (push) Successful in 2m33s
CI / deploy (push) Successful in 1m28s
CI / publish-container (push) Successful in 57s
- Render the table view through a virtualizer too, using a shared grid
  template so the sticky header and rows keep perfect column alignment
- Keep semantic table/row/cell elements while virtualizing
- Cap the batch item-details list to the latest 60 rows (newest first)
- Coalesce per-item progress events server-side (120ms throttle) in both
  the exact-import and clone SSE batch runners
2026-09-13 11:53:07 +02:00
openhands d02aaa0d87 perf(studio): cache furni imports and virtualize the furniture grid
CI / check (push) Failing after 22s
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
- Add TTL-based caching for local index lookup, furnidata classnames,
  catalog id set, nitro file presence and import stats
- Invalidate caches after furnace single/batch/clone imports
- Rewrite batch progress with elapsed time, rate and verification chips
- Virtualize the grid with @tanstack/react-virtual and replace the
  Load more button with infinite scroll via an IntersectionObserver
2026-09-13 11:40:55 +02:00
openhands 2920669362 feat: add CSV/JSON export, advanced bulk filters & selection to Catalog Manager
CI / check (push) Successful in 2m23s
CI / deploy (push) Successful in 1m9s
CI / publish-container (push) Successful in 49s
- Admin Audit Log: CSV/JSON export via ?format=query param
- Catalog Manager: club_only / have_offer filters (multi-filter support)
- Offer discovery: refactored discoverOffers() to accept filters object
- Translations added for new filter labels
- Test updates for all modified paths
2026-09-12 20:53:51 +02:00