Commit Graph
609 Commits
Author SHA1 Message Date
openhands 847febbe64 fix: handle cleanup errors gracefully in cf-fetch
CI / check (push) Successful in 25s
CI / release (push) Skipped
CI / deploy (push) Successful in 46s
2026-08-04 18:13:41 +02:00
openhands af8b59e024 fix: use dynamic imports for puppeteer to prevent Next.js build errors
CI / check (push) Successful in 24s
CI / release (push) Skipped
CI / deploy (push) Successful in 48s
puppeteer-extra cannot be statically imported in Next.js server bundles.
Using dynamic import() so puppeteer is only loaded at runtime, not at build time.
2026-08-04 18:05:01 +02:00
openhands a338f9cb72 feat: add Cloudflare bypass to fetchSourceFurnidata using puppeteer
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Failing after 41s
- Add cf-fetch.ts with puppeteer-extra + stealth plugin for CF bypass
- Modify fetchSourceFurnidata to detect CF challenge and retry with puppeteer
- Restore Leet, Hubbly, and Habblet City to clone sources (now CF-protected)
2026-08-04 18:02:16 +02:00
openhands 624edf751a chore: restore Habbo, Wibbo, Hubba.cc, Hubbly, Soda Ho to clone sources
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 40s
2026-08-04 17:49:33 +02:00
openhands 1258fd8e7b chore: only keep clone sources where all URLs (furnidata, nitro, icons) are verified working
CI / check (push) Successful in 25s
CI / release (push) Skipped
CI / deploy (push) Successful in 45s
Kept only:
- Leet (all 3 URLs working)
- Habblet City (all 3 URLs working)

Removed sources with broken or missing nitro/icon URLs:
- Habbo (no nitro/icons)
- Wibbo (nitro/icons return 403)
- Hubba.cc (nitro returns 404)
- Soda Ho (nitro/icons return 404)
2026-08-04 17:30:46 +02:00
openhands fa7fc75c9a feat: add leet.ws and hubbly.pw clone sources; add retro hotel prefixes to EVENT_PREFIXES
CI / check (push) Successful in 24s
CI / release (push) Skipped
CI / deploy (push) Successful in 46s
2026-08-04 16:50:05 +02:00
openhands 04b84e6055 feat: add organizeSql option for organized catalog_pages with English captions
CI / check (push) Successful in 24s
CI / release (push) Skipped
CI / deploy (push) Successful in 44s
2026-08-04 16:43:53 +02:00
openhands 2ee5ba5c4c feat: group unrepairable legacy items separately in catalog audit
CI / check (push) Successful in 25s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m2s
After a repair attempt, items whose nitro/icon assets cannot be restored
from any source are reclassified from hard errors into a dedicated
'Unrepairable (legacy)' group (info), so a fully repaired catalog can
reach 0 errors while still listing exactly what is not restorable. Adds
an unrepairable summary count and a dedicated tab in the audit UI.
2026-08-04 11:18:37 +02:00
openhands d587749b50 fix: precise item classification in catalog audit and repair
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m3s
Detect badges by items_base.type='b' (authoritative, album gifs as
fallback), recognize pet/animals (a0 pet<N>, pet<N> interaction) and
system items (effects, bots, sticky notes), and resolve asset names for
dot/star classname variants so the audit no longer floods with false
missing nitro/icon errors and repair skips non-furni items.
2026-08-04 11:07:04 +02:00
openhands b1a1e5125c fix: identify badge items by .gif presence in album1584 directory
CI / check (push) Successful in 30s
CI / release (push) Skipped
CI / deploy (push) Successful in 58s
Badge items like HC_Badge, BADGE_SHREK_03 have item_names that don't start
with 'badge_' and interaction_type='default'. Now loads known badge codes
from <gamedataRoot>/album1584/*.gif files and uses that set to exclude
badge items from .nitro and icon audit checks. Also removes incorrect
startsWith('badge_') check that would wrongly skip badge display cases
which DO have .nitro files.
2026-08-03 22:05:49 +02:00
openhands 750973de38 fix: correct badge item detection by checking classname prefix
CI / check (push) Successful in 30s
CI / release (push) Skipped
CI / deploy (push) Successful in 57s
Badge item_names already start with 'badge_' (e.g. badge_citycpa3),
so checking for badge_<item_name>_icon.png produces a double prefix
(badge_badge_citycpa3_icon.png). Now uses item_name.startsWith('badge_')
instead, which correctly identifies badge items without depending on
icon files existing in the directory.
2026-08-03 21:47:10 +02:00
openhands 1167a48344 fix: use badge icon file pattern to exclude badge items from audit and repair
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 55s
Previously identified badge items by interaction_type='badge', but
clone-imported badges have interaction_type='default'. Now checks for
badge_<code>_icon.png file existence instead.
2026-08-03 21:39:27 +02:00
openhands 40da24bd8c Fix badge icon detection in catalog audit and repair
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m6s
Badge icons are stored as badge_<code>_icon.png (with badge_ prefix)
instead of <code>_icon.png like regular furni. Update the audit and
icon repair to check for both patterns so badge items are not falsely
flagged as missing icons.
2026-08-03 21:34:11 +02:00
openhands e97213e5d1 Exclude badge items from missing icon check in catalog audit
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Successful in 57s
Badge items use .gif icons, not .png icons, so they should not
be flagged as missing icons in the catalog audit.
2026-08-03 21:28:30 +02:00
openhands 86d59195ec Exclude badge items from catalog audit and repair checks
CI / check (push) Successful in 24s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m5s
Badge items use .gif files, not .nitro bundles, so they should not
be flagged as missing .nitro or missing catalog entries. Also add
badge logicType handling in furni-import.ts so badges get the correct
interaction_type when imported.
2026-08-03 21:23:13 +02:00
openhands 1cbb33a4e2 perf: speed up catalog audit by batching file checks and parallelizing source fetches
CI / check (push) Successful in 38s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m13s
2026-08-03 19:52:09 +02:00
openhands 40a21ba767 fix: wrap SSE state updates in flushSync to resolve React error #418
CI / check (push) Successful in 24s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m3s
2026-08-03 19:42:20 +02:00
openhands 2fba923a3a feat: browser headers on audit fetches + verified clone furnidata sources
CI / check (push) Successful in 32s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m18s
2026-08-03 19:00:45 +02:00
openhands 080dc34e23 fix: never cache HTML so deploys always serve current chunks
CI / check (push) Successful in 30s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m2s
Anonymous HTML was sent with 'public, max-age=60, s-maxage=300,
stale-while-revalidate=300'. After a rebuild the old chunk URLs (keyed by
deploy id) are deleted, so any browser/CDN holding the stale HTML got 404s
for up to five minutes. Since the deploy id is the git commit, the HTML must
be re-fetched after every deploy; only content-hashed static assets should
be cached. Return no-store for all HTML documents.
2026-08-03 18:39:41 +02:00
openhands 450e7e8d00 fix: suppress hydration warning on html for theme-init class
CI / check (push) Successful in 25s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m6s
theme-init.js adds the 'dark' class to <html> before React hydrates,
causing a hydration mismatch (React #418) for users with a saved dark
theme. Mark the root element with suppressHydrationWarning.
2026-08-03 18:29:22 +02:00
openhands 30ed2b8ce2 refactor: switch password hashing from argon2 to bcrypt
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m0s
- hashPassword now emits bcrypt (cost 12) instead of argon2id
- checkLogin migrates legacy md5/argon2id hashes to bcrypt on sign-in
- keep argon2id verification only as a one-time migration path
- replace ARGON2_* env vars with BCRYPT_COST
2026-08-03 18:08:57 +02:00
openhands 6fc14b9b84 feat: catalog audit can repair orphaned refs and duplicate classnames
- add repairOrphanedCatalog: remove catalog_items rows whose item_ids only
  reference missing items_base entries, strip orphaned ids from mixed rows
- add repairDuplicateClassnames: merge items_base duplicates into one
  canonical row per classname, remap references, delete duplicate rows
- add 'repair structural issues' checkbox + result display in audit UI
2026-08-03 18:08:45 +02:00
openhands bee55e1fd4 fix: skip icon-repair integration test when no DB is configured
CI / check (push) Successful in 24s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m2s
2026-08-03 17:47:07 +02:00
openhands 44c34dbae6 fix: catalog-repair - allocate sequential ids in generateCatalogSql
CI / check (push) Successful in 45s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m13s
Previously allocateCatalogItemId was called per entry, but since generation
does not INSERT, MAX(id) never advanced and every entry got the same id.
Now MAX(id) is read once and a local counter hands out sequential ids.
2026-08-02 19:57:21 +02:00
openhands 5308ce6a12 feat: parallelize audit repair and add nitro/SQL repair options
CI / check (push) Successful in 48s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m55s
- Parallelize icon and nitro downloads in the audit repair with a
  sliding-window worker pool (6 concurrent) to speed up large catalogs
- Add repairMissingNitros: fetch missing .nitro bundles from configured
  nitro sources (Wibbo default), validating each bundle before writing
- Add catalog-repair service: generate/apply catalog_items SQL for furni
  missing a catalog entry and repair FurnitureData.json (add missing +
  dedupe classnames)
- Wire all options through the audit API and client UI with live progress
  and result stats (icons, nitros, SQL, furnidata)
- Add Wibbo as default nitro source alongside existing icon sources
- Ignore runtime furni assets downloaded into public/ during repair
2026-08-02 19:12:28 +02:00
Simo 0c8e62357f fix: preserve runtime furni assets during deploy
CI / check (push) Successful in 46s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m33s
2026-08-02 17:32:32 +02:00
openhands cde15ad022 fix: mirror repaired icons to gamedata
CI / check (push) Successful in 25s
CI / release (push) Skipped
CI / deploy (push) Failing after 1m18s
Repair Icons now resolves all furni asset write targets (webroot plus
the live gamedata like /var/www/Gamedata) and writes downloaded or
extracted icons to every missing location. Icons already present in one
target are copied across instead of re-downloaded, and local .nitro
bundles are searched in every target.
2026-08-02 16:56:22 +02:00
openhands 1f9e8a0eec feat: add default furni icon repair sources
CI / check (push) Successful in 26s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m1s
Fall back to well-known public furni icon hosts (HabboAssets, Hubbly,
Leet) when no clone sources are configured, so Repair Icons can download
missing icons out of the box. Also handle variant classnames (base name
and '*' replaced with '_') and extract icons from remote .nitro bundles.
Send a browser User-Agent on downloads to avoid being blocked by hotels.
2026-08-02 16:44:24 +02:00
Simo bac2f653af feat: add manual recent furni resync action
CI / check (push) Successful in 24s
CI / release (push) Skipped
CI / deploy (push) Successful in 44s
2026-08-02 14:59:31 +02:00
Simo 88ac5ac1ba feat: add recent furni resync client contract 2026-08-02 14:56:12 +02:00
Simo ab43f5d63c fix: use JSON FurnitureData from gamedata
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 42s
2026-08-02 14:42:23 +02:00
Simo c78f8812ad fix: use configured furni source and catalog assets 2026-08-02 14:22:05 +02:00
Simo 86cd43def9 fix: mirror manual furni uploads to live assets
CI / check (push) Successful in 24s
CI / release (push) Skipped
CI / deploy (push) Successful in 46s
2026-08-02 13:24:15 +02:00
Simo 01570874a8 fix: map furni imports to production gamedata 2026-08-02 13:16:51 +02:00
Simo b3245a18ea fix: bootstrap admin CSRF tokens
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 41s
2026-08-02 11:46:43 +02:00
Simo a57c73055f fix: retry login across deploy cutovers
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 41s
2026-08-02 11:31:35 +02:00
Simo bfc951cfd9 fix: minimize deploy cutover downtime
CI / check (push) Successful in 22s
CI / release (push) Skipped
CI / deploy (push) Successful in 40s
2026-08-02 11:25:03 +02:00
Simo 828fda63e7 fix: keep app online during deploy preparation
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 44s
2026-08-02 11:19:53 +02:00
Simo 1f4aadb3d7 chore: remove Sentry integration
CI / check (push) Successful in 21s
CI / release (push) Skipped
CI / deploy (push) Successful in 53s
2026-08-01 22:12:31 +02:00
openhands c7fb37356e fix: remove nonce from style-src to allow unsafe-inline to work
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m11s
2026-08-01 22:09:22 +02:00
openhands 95b1955218 fix: allow unsafe-inline for styles to fix CSP permanently
CI / check (push) Failing after 31s
CI / release (push) Skipped
CI / deploy (push) Skipped
2026-08-01 21:58:13 +02:00
Simo d173dd3194 fix: add automatic deployment skew protection
CI / check (push) Successful in 37s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m28s
2026-08-01 21:52:28 +02:00
openhands 0dc16e832d fix: add additional CSP hashes for inline styles
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m28s
2026-08-01 21:51:32 +02:00
openhands 59f03827bc fix: add CSP hashes for inline styles from Google Fonts/Tailwind
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m12s
2026-08-01 21:46:00 +02:00
openhands 0d6032d444 chore: remove standalone output mode, fix Sentry DSN validation, add dev CSP unsafe-inline for styles
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m15s
- Remove output: 'standalone' from next.config.ts to allow normal 'next start'
- Allow empty SENTRY_DSN/NEXT_PUBLIC_SENTRY_DSN in env validation (zod)
- Add 'unsafe-inline' to style-src CSP only in development for Turbopack HMR
- Clear placeholder Sentry DSN values from .env
2026-08-01 21:30:51 +02:00
openhands cc02851be3 perf(html): fix Cache-Control on response headers (was on request)
CI / check (push) Successful in 32s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m21s
2026-08-01 18:41:08 +02:00
openhands 7c1f8d709e perf(html): replace proxyAuth with getToken to remove set-cookie; add Cache-Control per auth state
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m20s
2026-08-01 18:37:19 +02:00
openhands 2799b63943 perf(client): drop unused Sentry session-replay SDK from the client bundle
CI / check (push) Successful in 30s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m21s
2026-08-01 18:18:53 +02:00
openhands fd8ab7db93 perf(imaging): add s-maxage so Cloudflare caches avatar images
CI / check (push) Successful in 38s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m22s
Avatars are proxied from the slow Habbo upstream on every request
(~350ms each) and Cloudflare was serving them as DYNAMIC because the
Cache-Control had no s-maxage. Add s-maxage=86400 + stale-while-revalidate
so edge/CDN caches avatars and repeats are served instantly.
2026-08-01 18:00:43 +02:00
openhands 22d455da7a fix(auth): drop nonexistent account_blocked column from login lookup
CI / check (push) Successful in 34s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m42s
getLoginUser selected users.account_blocked, which does not exist in the
DB (nor the Drizzle schema). Every credentials authorize() call threw a
SQL error -> NextAuth CallbackRouteError -> 'error=Configuration', so no
login could ever succeed. Remove the phantom column from the query and
LoginUser interface.

Also fix all remaining biome noNonNullAssertion / noExplicitAny lint
warnings so CI's check job (biome:lint) passes and the push deploy runs.
2026-08-01 17:38:43 +02:00