- Replace next/font/google with <link> tags in <head> (loads fonts client-side at runtime)
- Define --font-nunito and --font-pixel CSS variables in globals.css with font-family fallbacks
- Remove @prisma/client from serverExternalPackages in next.config.ts (devDep only)
- Remove babel-plugin-react-compiler (Next.js 16 has built-in reactCompiler)
- Update postcss to 8.5.25
- Add output: 'standalone' to next.config.ts for smaller/faster deployments
- Update ecosystem.config.cjs to use standalone server.js
- Remove output:standalone from next.config.ts
- Remove postbuild standalone copy script
- Change start script from standalone/server.js to next start
- Update PM2 to run pnpm start
- Remove import.meta.dirname from turbopack config (unnecessary filesystem op)
- Add /*turbopackIgnore: true*/ to 3 path.join calls in upload-import.ts
that were missing the comment, causing Turbopack to trace the whole
project unintentionally
staleTimes, optimizePackageImports, and staticGenerationMaxConcurrency
were all experimental-only in Next.js 16. Removed them:
- staleTimes: router cache defaults are sufficient
- optimizePackageImports: Turbopack already tree-shakes lucide-react
- staticGenerationMaxConcurrency: mitigated by DATABASE_POOL_SIZE=5
Eliminates the 'Experiments (use with caution)' warning for our custom
options. Only clientTraceMetadata remains (Next.js framework default).
Next build workers were each opening up to DATABASE_POOL_SIZE connections and exhausting MySQL (pool active=0), hanging sitemap generation. Cap build pool to 5, fail connect faster, limit SSG concurrency, and make sitemap dynamic.
Co-authored-by: Cursor <[email protected]>
Skip release creation alongside source-map upload so production compile does not warn about missing SENTRY_AUTH_TOKEN.
Co-authored-by: Cursor <[email protected]>
Sentry is opt-in via DSN env vars; logger uses structured pino JSON in prod; badge uploads are normalized to GIF with sharp.
Co-authored-by: Cursor <[email protected]>
- H1: Add missing sanitize() to help center content rendering
- H2: Tighten CSP by removing unsafe-inline/unsafe-eval from script-src;
move theme init to external JS file with meta tag for defaultDark
- M1: Add SSRF protection for radio API URLs (block private IPs)
- M2: Add rate limiting to SSO ticket endpoint (5 req/30s per user)
- M4: Document locale validation safety in i18n dynamic import
- L1: Truncate stacktraces in admin commandocentrum to first 20 lines
Minimal but real App Router app that builds (next build exit 0):
- src/lib/auth.ts: NextAuth v5 Credentials provider calling checkLogin()
(argon2id/bcrypt + md5->argon2id upgrade gated by CONVERT_PASSWORDS), JWT
session, /api/auth/[...nextauth] route handler.
- src/app: root layout, home (force-dynamic, reads hotel_name via siteSettings),
/login client form (signIn).
- next.config.ts: pinned turbopack.root, serverExternalPackages for the Prisma
MariaDB adapter; tsconfig set up for Next.
Routes: / (dynamic), /login, /api/auth. Verified: next build exit 0, 28 tests.
Still needs DB+APP_KEY to run auth end-to-end. i18n/middleware/pages to follow.