Commit Graph
30 Commits
Author SHA1 Message Date
openhands 67b67798b9 feat(client): polished toolbar, live online count via SSE
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m27s
- Redesign in-game client toolbar with refined glass styling and buttons
- Live online count + emulator status streamed over SSE multicast
- Who's-online tooltip throttled to reduce repeated requests
- Fix show button so it always returns the hidden toolbar
- Use theme CSS variables instead of hardcoded colors
- Add toolbar translations across all 25 locales
2026-09-02 21:14:42 +02:00
openhands 58c35a2920 feat: enforce no hardcoded colors across entire CMS
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 32s
CI / release (push) Skipped
CI / deploy (push) Successful in 58s
Added scripts/check-admin-colors.mjs — scans all src/ files for:
- text-white, text-black (use theme text vars)
- bg-white, bg-black (use theme background/overlay vars)
- bg/text/border/ring with gray/slate/zinc/stone palette
- bg/text/border/ring with red/green/blue/etc palette

Fixed 21 violations across 11 files:
- Overlays: bg-black/* → bg-foreground/*
- Text: text-white → text-primary-foreground
- Backgrounds: bg-white/10 → bg-background/10
- Green accents: bg-green-* → bg-primary
- Red accents: bg-red-* → bg-destructive

Integrated into:
- lint-staged: runs on every *.ts/*.tsx commit
- vitest: src/lib/no-hardcoded-colors.test.ts replaces old audit test
- Allowlist: shadcn/ui primitives (button, badge, dialog) + 4 graphical files
2026-09-01 19:33:50 +02:00
openhands b59d6c21af feat: prioritize game iframe, gated register terms and polished register page
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 55s
Fetch the Nitro client iframe with high priority so the browser starts the
game document before competing resources, and replace the bare /client
spinner with a branded boot screen. Preconnect and eager loading were already
in place; typing support for the iframe fetchPriority prop is added in a
React type augmentation.

Rework the register terms block into a single clickable accept control with
a custom check state, error shake and inline hint, and dim the submit button
until the terms are accepted. The register page gets labeled sections
(account details / credentials), a corrected banner overlay, translated
show/hide toggles and a captcha slot that reserves height to avoid layout
shifts. English is the source of truth; other locales fall back to it.
2026-08-29 21:14:02 +02:00
openhands 7f39ba4257 fix: harden SSO ticket flow and revoke tickets on logout
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 54s
Reuse the outstanding auth_ticket instead of minting a fresh one on every
/client load, so reloading the page or opening a second tab no longer
invalidates a game session that is still connecting. New tickets are minted
with a guard against the previously-read value so concurrent launches
converge on the same ticket.

Revoke the auth_ticket when signing out (toolbar, header and sign-out
everywhere) so a leaked ticket can no longer be replayed against the
emulator, and prevent SSO leakage via referral by setting no-referrer on the
client iframe. Strip all whitespace from the ticket prefix and build the
launch URL through a tested helper that handles query strings, existing sso
params and URL fragments correctly.
2026-08-29 20:54:06 +02:00
openhands 7a41775c7e fix: disable route prefetching app-wide to avoid spurious requests
Wrap next/link in a shared Link component that ships prefetch=false by
default, so no route is ever prefetched (viewport or hover) anymore, and
drop the DNS prefetch hint. Removes hidden background requests that were
the source of intermittent issues.
2026-08-29 19:27:13 +02:00
openhands 416c31643b perf: optimize dashboard database queries and remove unused imports
CI / check (push) Failing after 10s
CI / deploy (push) Skipped
CI / release (push) Skipped
2026-08-25 21:52:18 +02:00
openhands dacc4cadfd chore(deps): upgrade to typescript 7 bridge and clean up pnpm v11 workspace configs
CI / check (push) Failing after 58s
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 11s
2026-07-27 23:14:00 +02:00
openhands 423a33200e chore: improve tooling, linting, testing, and CI
CI / check (push) Failing after 14s
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m38s
- Add LICENSE file (CC BY-NC-SA 4.0)
- Add .nvmrc pinning Node 22
- Add Renovate config with daily schedule and Gitea Actions workflow
- Reduce ESLint max-warnings from 1000 to 50
- Re-enable Biome a11y/security recommended rules
- Fix Biome lint issues (a11y, hook deps, SVG labels, checkbox semantics)
- Improve CI: run on pushes to feat/fix branches, add pnpm audit
- Add Vitest coverage with v8 provider and thresholds
- Add E2E tests (auth, admin, navigation specs)
- Add admin-maintenance server action test
- Install @vitest/coverage-v8
- Ignore coverage/ directory
2026-07-27 17:03:09 +02:00
openhands 4bb908ecf7 Center client toolbar at top by default instead of right side
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m55s
2026-07-26 21:37:38 +02:00
openhands 17847545dd Improvements: remove dead config, fix ESM, add URL validation, unify types, add missing logging
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m52s
- Remove .prettierrc (dead config, Biome replaces Prettier)
- Rename lighthouserc.json to lighthouserc.cjs with module.exports for ESM compat
- Add logger.warn to empty catch blocks in auth, register, site-settings, prisma-cache, redis, security, rate-limit
- Unify ActionResult type: action-helper.ts uses 'ok' consistent with safe-action-shared.ts
- Add noUnusedLocals + noUnusedParameters to tsconfig + fix 25 pre-existing unused vars
- Replace barrel export src/types/index.ts with direct @/types/common imports
- Make trustHost conditional (development only) in auth.ts
- Add pre-flight URL validation to update-Nitrov3.sh to catch image.library.url misconfigurations
- Improve NITRO_IMAGE_LIBRARY_URL content validation in pre-flight & post-compute checks
2026-07-26 20:28:11 +02:00
openhands b922f6d49f fix: remove auto-hide, toolbar always visible
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m54s
2026-07-26 18:47:04 +02:00
openhands 8c2fe603d1 fix: keep toolbar interactive when hidden (opacity 8% instead of pointer-events-none) so mouse-enter brings it back
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m2s
2026-07-26 18:38:23 +02:00
openhands 1e0dd183b1 feat: premium toolbar with glassmorphism, auto-hide, edge snap, and smooth snap animation
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m52s
2026-07-26 18:17:32 +02:00
openhands ea71a574a4 refactor: useLayoutEffect for no-flash position init, clean localStorage save, hide toolbar until ready
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m3s
2026-07-26 18:11:12 +02:00
openhands b77dbb65f6 fix: cleanup old position system, add proper useRef import
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m50s
2026-07-26 18:04:50 +02:00
openhands 7f7e11adcf feat: freely draggable toolbar with pixel-position saved to localStorage
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 32s
2026-07-26 18:02:43 +02:00
openhands 86d15d0d92 fix: toolbar now renders outside overflow container, supports 4 corner positions (top-left/right, bottom-left/right)
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m3s
2026-07-26 17:59:04 +02:00
openhands e336ac3c66 feat: configurable toolbar position (site setting + localStorage toggle + URL override)
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m53s
2026-07-26 17:52:24 +02:00
openhands 623cced64e fix: move toolbar to right side
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m47s
2026-07-26 17:46:57 +02:00
openhands e464fac102 fix: render toolbar via portal to body so it stays visible in fullscreen
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m49s
2026-07-26 17:36:00 +02:00
openhands 2a727b2a71 refactor: smaller toolbar icons, remove language and theme switchers from client
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m49s
2026-07-26 17:29:18 +02:00
openhands f072a28aee refactor: remove logo from client toolbar, move language and logout to left group
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m50s
2026-07-26 17:24:46 +02:00
openhands d010344423 feat: add language switcher, theme switcher, logout, and hotel logo to client toolbar
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m48s
2026-07-26 17:17:56 +02:00
openhands d189bb5af4 fix: mobile responsive improvements
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m2s
- Audit: responsive summary cards (grid-cols-2 mobile, p-3), responsive empty states
- Repair-icons/sync-all: log area horizontal scroll (overflow-x-auto, whitespace-nowrap)
- Upload furni: tighter mobile padding (p-4 sm:p-5)
- Nitro client: compact toolbar on mobile (smaller buttons, tighter gap, top-2/left-2)
2026-07-21 16:47:02 +02:00
openhands 5e8a13a84f fix: resolve all biomaly lint errors and warnings across CMS
Deploy / release (push) Successful in 4s
Deploy / deploy (push) Skipped
- Fix CSS parser config (tailwindDirectives enabled)
- Fix noDangerouslySetInnerHtml via SanitizedHtml component
- Fix useExhaustiveDependencies in catalog-manager-dialog
- Fix noArrayIndexKey across 26 files (stable keys)
- Fix SVG a11y (titles, roles, aria-labels)
- Fix label/input associations (htmlFor/id pairs)
- Fix static element interactions (role + keyboard support)
- Fix noImgElement, noDescendingSpecificity (disabled - external Habbo URLs)
- Fix noNonNullAssertion, useTemplate, unused vars/imports
- Add SanitizedHtml shared component
- Migrate biome.json to 2.5.4 schema
2026-07-20 17:41:53 +02:00
openhands df38dccbf1 style: format code biome
Local Build and Deploy / deploy (push) Failing after 46s
2026-07-13 21:57:41 +02:00
Simo 4a1e1115b3 Harden CMS security and theme contrast 2026-07-11 20:27:20 +02:00
openhands 41be6835bf Add missing admin action files and navigation links
- Add 11 missing server action files: badges, bulk-users, catalog, catalog-bc, catalog-items, import-badges, import-furni, multi-account-detect, permissions, rooms, soundtracks
- Add missing admin navigation links: tickets, sounds, translations, import, radio sub-pages
- Add translation keys for all new navigation items
2026-07-11 12:01:05 +02:00
openhands 942bc6fc8d Security hardening, code quality, and ESLint setup
- Remove production DB dump (db_backup_*.sql) and update.log from git tracking
- Add DB backups to .gitignore
- Replace all console.log/console.error with structured logger module
- Translate Dutch error messages to English (link-discord.ts)
- Remove dead code blocks (register-form.tsx false && pattern)
- Add ESLint flat config with TypeScript, React, Next.js, jsx-a11y, and security plugins
- Add Prettier config
- Add eslint-plugin-security for security-aware linting
- Fix all 119+ ESLint warnings across the codebase:
  - Resolve security/detect-object-injection with safe access patterns
  - Resolve security/detect-non-literal-fs-filename with path traversal validation
  - Replace <img> with next/image <Image> component
  - Remove unused variables and imports
  - Replace non-null assertions with proper type guards
  - Replace <a> with <Link> for internal navigation
  - Use next/script Script component for external scripts
- Fix setState-in-useEffect anti-patterns (navbar-color-picker, logo-generator, theme-switcher)
- Add lint and format scripts to package.json

All checks: typecheck ✓, tests 58/58 ✓, lint 0 errors 0 warnings ✓
2026-07-10 22:48:22 +02:00
openhands 7fe3220359 Inline SSO ticket generation in server component, prefetch client page from home, remove client API roundtrip 2026-07-09 18:41:04 +02:00