Commit Graph
228 Commits
Author SHA1 Message Date
openhands 7138ae4445 fix: correct indentation in deploy workflow shell block
CI / check (push) Successful in 27s
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m19s
CI / deploy (push) Failing after 9s
The prisma:generate block had inconsistent indentation (11 spaces
instead of 10), causing YAML to misinterpret the shell block structure.
2026-07-30 20:29:19 +02:00
openhands fe46bd0544 fix: unset placeholder DATABASE_URL after prisma:generate so build/migrate use real .env
CI / check (push) Successful in 25s
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m13s
CI / deploy (push) Failing after 9s
prisma:generate needs DATABASE_URL to resolve the schema but doesn't
connect to the DB. After generate, unset the placeholder so that
pnpm build and pnpm db:migrate pick up the real DATABASE_URL from
the live .env (symlinked into the stage directory).
2026-07-30 20:20:39 +02:00
openhands 822dfd6a1c fix: use real DATABASE_URL from .env for migrations in deploy workflow
CI / check (push) Successful in 24s
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m12s
CI / deploy (push) Failing after 10s
The deploy job was overwriting DATABASE_URL with a placeholder for
prisma:generate, but this persisted when db:migrate ran later, causing
ER_ACCESS_DENIED_ERROR. Since the stage directory already symlinks to
the live .env, the real DATABASE_URL is available without override.
2026-07-30 20:16:24 +02:00
openhands 525f58cd24 fix: provide dummy DATABASE_URL for prisma generate during deploy
CI / check (push) Successful in 29s
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 2m8s
CI / deploy (push) Failing after 10s
2026-07-30 20:07:49 +02:00
openhands 686279eb25 fix: remove test from deploy job (runs in CI already)
CI / check (push) Failing after 21s
Deploy / release (push) Skipped
CI / deploy (push) Skipped
Deploy / deploy (push) Successful in 56s
2026-07-30 19:17:22 +02:00
openhands 4b2d893905 feat: add deploy step in release workflow (build + PM2 restart) and set coverage thresholds to 100
CI / check (push) Failing after 22s
Deploy / release (push) Skipped
CI / deploy (push) Skipped
Deploy / deploy (push) Failing after 20s
2026-07-30 19:11:58 +02:00
openhands e07da3d052 ci: add deploy job to CI pipeline (build + pm2 restart)
CI / check (push) Successful in 22s
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m9s
CI / deploy (push) Failing after 10s
2026-07-30 19:07:21 +02:00
SimoandCursor 540bce911f fix(deploy): free PORT before PM2 start to clear EADDRINUSE orphans
Co-authored-by: Cursor <[email protected]>
2026-07-30 18:40:42 +02:00
SimoandCursor 749dc237f1 fix(deploy): export PORT from .env before PM2 reload so health check matches
CI / check (push) Successful in 26s
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 2m6s
Co-authored-by: Cursor <[email protected]>
2026-07-30 18:33:38 +02:00
openhands 84f64b6615 ci: fix CI trigger - run on push too, remove duplicate 2026-07-30 17:53:22 +02:00
openhands 91357aca3b ci: fix Gitea Actions workflow 2026-07-30 17:51:24 +02:00
openhands cc95a0d690 ci: add Gitea Actions workflow 2026-07-30 17:49:38 +02:00
openhands 4bd717d627 fix: restore renovate workflow 2026-07-30 16:44:15 +02:00
openhands 3bf0644a9a fix(ci): repair corrupted UTF-8 in renovate.yaml breaking all workflows 2026-07-29 23:26:47 +02:00
openhands 7cdb785218 Remove argon2id, use bcrypt-only password hashing 2026-07-29 22:50:17 +02:00
openhands a8d86a10bc fix(ci): add missing env vars for robust CI builds
Add NODE_ENV=test and REDIS_URL so tests run cleanly
and Prisma can resolve all required configuration.
2026-07-28 23:09:15 +02:00
openhands b926ffa93c fix(ci): set DATABASE_URL and AUTH_SECRET for Prisma in CI
Prisma requires DATABASE_URL even for client generation.
The CI workflow cloned to a fresh temp dir has no .env file,
so these must be provided as env vars.
2026-07-28 23:05:11 +02:00
openhands 22a9fc13f7 fix(deploy): use correct PORT for health check (was hardcoded to 3000, env uses 3002)
The health check URL was hardcoded to http://127.0.0.1:3000 but the
production .env sets PORT=3002. Read the PORT from .env dynamically
so the health check matches the actual server port.
2026-07-28 23:00:19 +02:00
openhands 72079050f4 fix(deploy): use deploy user for file ownership instead of www-data
Changing ownership to www-data at end of deploy breaks permission
handling when pm2 runs as a different user (e.g., root or the deploy
user). Keep ownership as the deploy user throughout.
2026-07-28 22:36:39 +02:00
openhands e08e366266 fix: remove orphaned @node-rs/argon2 and restore CI workflow
The hash-wasm package now handles both argon2id and bcrypt hashing,
making @node-rs/argon2 unused. Leaving it in package.json causes
native binary compilation failures on deploy servers (EACCES/build
errors), which breaks the deploy pipeline entirely.

Also restore .gitea/workflows/ci.yaml so CI pipelines run again.
2026-07-28 22:32:56 +02:00
openhands a637d09ca5 ci: fix permissies en extensie 2026-07-28 21:39:06 +02:00
openhands 15eeab8a59 ci: probeer self-hosted runner label 2026-07-28 21:37:03 +02:00
openhands 54fa1aecdd ci: test of de pipeline start 2026-07-28 21:35:35 +02:00
openhands 5140784dc7 ci: update workflow to use checkout action 2026-07-28 21:33:55 +02:00
SimoandCursor ab63de000b fix(ci): clone bare repo and fetch PR branch tip
Co-authored-by: Cursor <[email protected]>
2026-07-28 20:55:00 +02:00
SimoandCursor 3532972357 fix(ci): checkout PR SHA via bare-repo worktree
CI / check (pull_request) Failing after 11s
Co-authored-by: Cursor <[email protected]>
2026-07-28 20:53:21 +02:00
openhands 01a297884a Voeg Gitea workflows toe
Deploy / release (push) Successful in 7s
Deploy / deploy (push) Skipped
2026-07-28 18:07:26 +02:00
openhands 01196b0843 test: trigger geautomatiseerde pm2 deploy 2026-07-28 17:56:33 +02:00
openhands 48bdd6f2e6 ci: add workflows to correct repository path 2026-07-28 17:50:48 +02:00
openhands 14b9e77c1a fix(ci): add DATABASE_URL for Prisma 7 config
CI / check (push) Successful in 47s
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m21s
2026-07-27 17:11:23 +02:00
openhands 423a33200e chore: improve tooling, linting, testing, and CI
CI / check (push) Failing after 14s
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m38s
- Add LICENSE file (CC BY-NC-SA 4.0)
- Add .nvmrc pinning Node 22
- Add Renovate config with daily schedule and Gitea Actions workflow
- Reduce ESLint max-warnings from 1000 to 50
- Re-enable Biome a11y/security recommended rules
- Fix Biome lint issues (a11y, hook deps, SVG labels, checkbox semantics)
- Improve CI: run on pushes to feat/fix branches, add pnpm audit
- Add Vitest coverage with v8 provider and thresholds
- Add E2E tests (auth, admin, navigation specs)
- Add admin-maintenance server action test
- Install @vitest/coverage-v8
- Ignore coverage/ directory
2026-07-27 17:03:09 +02:00
openhands e8ade7afa3 fix(deploy): remove standalone logic, fix chown errors in workspace
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m10s
- Remove standalone static file verification (no longer needed)
- Make chown commands tolerate already-deleted temp files
- Update PM2 fallback to use pnpm start
2026-07-24 14:01:30 +02:00
openhands f6ee99801d Fix migration 'Too many connections' error during deploy
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 2m56s
- pm2 stop now uses --kill-timeout 10000 for graceful shutdown
- Wait 10s after stopping (was 3s) for MariaDB to reclaim connections
- Migration retries increased from 5 to 10 with 5s wait (was 3s)
- Total retry window: ~50s instead of ~15s
2026-07-23 20:04:34 +02:00
openhands dae381e07c Persist .next/cache across deploys for faster rebuilds
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m2s
Each deploy creates a fresh worktree and deletes .next, losing the
Turbopack build cache. Now restore .next/cache from the live site
into the stage before pnpm build, so Next.js can do incremental
compilation. After cutover the cache persists in the live .next/ for
the next deploy.
2026-07-23 19:33:12 +02:00
openhands 331a18e9c7 Add BCRYPT_ROUNDS env override, use 4 in CI
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m3s
- Bcrypt rounds now configurable via BCRYPT_ROUNDS env var (default 12)
- CI/deploy use BCRYPT_ROUNDS=4 for faster tests
- Argon2 test: 1161ms → 17ms (already done)
- Password test suite: 1860ms → 1330ms
2026-07-23 19:24:52 +02:00
openhands f7551166c5 Speed up tests: lower argon2 params in CI, env overrides
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m1s
- Allow ARGON2_MEMORY_SIZE, ARGON2_ITERATIONS, ARGON2_PARALLELISM env overrides
- Use m=1024,t=1 in tests (was m=65536,t=4 → ~1s per hash)
- Set fast params in CI and deploy workflows
2026-07-23 19:21:24 +02:00
openhands b6ba554386 Fix deploy error handler: cd to safe dir before pm2
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m58s
2026-07-23 19:16:34 +02:00
openhands 9226558aa0 Optimize deploy script
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 36s
- Zero-downtime PM2 reload instead of stop+start
- Keep .next.prev backup until after health check
- Add standalone static file verification
- Remove duplicate sleep
- Clean up naming
2026-07-23 19:13:06 +02:00
openhands d9e95c823a Update deploy to use PM2, add .next.prev to gitignore
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 38s
2026-07-23 19:09:05 +02:00
SimoandCursor 968ca15c27 feat: jwt cache, redis health, help-ticket admin, and write rate limits
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m33s
Cut Auth.js DB load with cached jwtVersion checks, surface Redis in /api/health and deploy warnings, add admin help-center ticket reply UI, rate-limit API tickets/reactions/referral claims, and revoke PATs on sign-out-everywhere.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:58:48 +02:00
SimoandCursor fa40eebeed fix(deploy): migrate after stop and shrink DB pool
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m52s
Stage migrate hit ER_CON_COUNT_ERROR while live still held the pool. Build in stage with DATABASE_POOL_SIZE=5, run db:migrate only after stopping the service (with retries), and lower the default pool from 40 to 10.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:44:06 +02:00
SimoandCursor 687e1f9fb0 fix(deploy): stage worktree build and short .next cutover
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 11s
Build install/test/migrate in a detached worktree while the live site keeps serving, then swap .next and node_modules during a brief stop. Drops nuclear rm -rf src and rolls back .next.prev on cutover failure.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:39:45 +02:00
SimoandCursor 2ff08e5127 chore: patch deps, CSP style nonces, otplib 13, and PR CI
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m35s
Co-authored-by: Cursor <[email protected]>
2026-07-21 20:46:02 +02:00
SimoandCursor 9b47668fe9 chore: CSP script nonces, deploy health check, dead-code cleanup
Add per-request CSP nonces (drop script unsafe-inline), post-deploy /api/health gate, bump next-auth to beta.32, and remove unused motion/cache/permission helpers.

Co-authored-by: Cursor <[email protected]>
2026-07-21 20:27:08 +02:00
SimoandCursor c46dadeda4 chore: harden deps, env validation, admin errors, and redis warnings
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m39s
Align nodemailer with Auth.js peers, bump patch deps, validate env on deploy builds, add admin error boundary, and warn when Redis is missing in production.

Co-authored-by: Cursor <[email protected]>
2026-07-21 20:19:05 +02:00
openhands 7fc53396b4 fix: menu links use bare slugs (Gitea auto-prefixes href with user-content-)
Deploy / release (push) Successful in 8s
Deploy / deploy (push) Skipped
2026-07-20 21:03:02 +02:00
openhands c0975f8a43 fix: scope deploy contract test to deploy job; menu links use Gitea user-content anchors
Deploy / release (push) Successful in 12s
Deploy / deploy (push) Skipped
2026-07-20 20:59:37 +02:00
openhands 43a624bbe7 docs: add self-contained setup reference configs (emulator + nitro) and bold-link buttons
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 33s
2026-07-20 20:54:26 +02:00
openhands c4532dd340 style: use inline style for release buttons (Gitea strips class)
Deploy / release (push) Successful in 8s
Deploy / deploy (push) Skipped
2026-07-20 20:47:07 +02:00
openhands 039b46d12b docs: expand release wizard with emulator/Nitro/Catalogus steps + buttons
Deploy / release (push) Successful in 8s
Deploy / deploy (push) Skipped
2026-07-20 20:43:43 +02:00