- Remove production DB dump (db_backup_*.sql) and update.log from git tracking
- Add DB backups to .gitignore
- Replace all console.log/console.error with structured logger module
- Translate Dutch error messages to English (link-discord.ts)
- Remove dead code blocks (register-form.tsx false && pattern)
- Add ESLint flat config with TypeScript, React, Next.js, jsx-a11y, and security plugins
- Add Prettier config
- Add eslint-plugin-security for security-aware linting
- Fix all 119+ ESLint warnings across the codebase:
- Resolve security/detect-object-injection with safe access patterns
- Resolve security/detect-non-literal-fs-filename with path traversal validation
- Replace <img> with next/image <Image> component
- Remove unused variables and imports
- Replace non-null assertions with proper type guards
- Replace <a> with <Link> for internal navigation
- Use next/script Script component for external scripts
- Fix setState-in-useEffect anti-patterns (navbar-color-picker, logo-generator, theme-switcher)
- Add lint and format scripts to package.json
All checks: typecheck ✓, tests 58/58 ✓, lint 0 errors 0 warnings ✓
- Run renderer and client builds in parallel (background + wait) for
faster updates
- Cache detected git branches in interactive menu (avoid re-running
git branch -r on every redraw); re-cache after switching branches
- Add health check after emulator restart (poll until active or retries
exhausted)
- Add service_active() helper with systemd/service/pgrep fallback for
non-systemd systems; replace all systemctl is-active calls
- Add 30s read timeout (-t 30) on all interactive prompts to prevent
hanging on non-terminal stdin
- Add set -E for ERR trap inheritance in subshells
- Security: replace eval-based load_branches with nameref+readarray,
remove export MYSQL_PWD (leaks to child processes), fix URL-decode
via Python's urllib.parse, fix JSON injection in notify via json.dumps,
add package.json guard before sudo rm -rf
- Portability: replace seq (external) with repeat() built-in, add
mysql/mysqldump fallback alongside mariadb, add format_size() fallback
when numfmt is unavailable, remove -maxdepth from list_sorted helper
- Robustness: add set -o pipefail, fix spinner zombie (remove disown),
wrap git_update/detect_best_branch in subshells to prevent cd leaks,
capture full mvn/yarn build output to log instead of tail, add -r to
xargs basename, make ssl-verify-server-cert configurable via .env
- UX: add --dry-run/-n flag for preview without changes
- Add DB index on bans.user_id to speed up per-request ban lookups (migration 0008)
- Replace in-process rate limiter with Redis-backed implementation with in-memory fallback
- Add Redis caching layer for site settings with TTL invalidation (migration 0009)
- Add rate limiting to resetPassword to prevent token brute-force attacks
- Update all rateLimit callers to await the now-async function
- Flesh out RadioContests and RadioGiveaways models with title, description, prize, date, and winner columns
- Update radio contest/giveaway pages to display new fields
- Add tests for rate limiter (4 tests) and password-reset actions (3 tests)
- Add REDIS_URL environment variable (optional, falls back to in-memory)
- H1: Add missing sanitize() to help center content rendering
- H2: Tighten CSP by removing unsafe-inline/unsafe-eval from script-src;
move theme init to external JS file with meta tag for defaultDark
- M1: Add SSRF protection for radio API URLs (block private IPs)
- M2: Add rate limiting to SSO ticket endpoint (5 req/30s per user)
- M4: Document locale validation safety in i18n dynamic import
- L1: Truncate stacktraces in admin commandocentrum to first 20 lines