Commit Graph
71 Commits
Author SHA1 Message Date
SimoandCursor 9b411e69b4 Fix CMS translations path to src/messages.
Local Build and Deploy / deploy (push) Failing after 1m5s
Co-authored-by: Cursor <[email protected]>
2026-07-17 18:43:34 +02:00
SimoandCursor e101ea474e Fix rooms list crash and rebuild CMS settings UI.
Rooms queried the wrong Prisma model and a non-existent owner relation. Settings now use grouped managed fields plus a searchable advanced key/value panel.

Co-authored-by: Cursor <[email protected]>
2026-07-15 21:02:57 +02:00
SimoandCursor 0096c55f96 Fix theme switcher desync and auto-correct unreadable saved colors.
Local Build and Deploy / deploy (push) Successful in 53s
Sync dark-mode state from the DOM after mount so admin text no longer needs a double toggle, and normalize text/button colors against their surfaces on theme save.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:54:46 +02:00
SimoandCursor 3403d3b19f Fix admin permissions bounce, prefixes APIs, and Italian UI leftovers.
Local Build and Deploy / deploy (push) Successful in 56s
Gate permissions on ACL manage + resolve super-admin from live user ranks, restore prefixes API routes, and anglicize hardcoded admin copy with nav i18n.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:33:00 +02:00
SimoandCursor 0e89d03940 Finish fine-grained ACL across remaining admin pages and actions.
Local Build and Deploy / deploy (push) Successful in 56s
Replace leftover requireStaff gates with module PERMS, drop hardcoded room rank thresholds, and expand contract tests so admin mutations cannot regress to dashboard-only checks.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:15:22 +02:00
SimoandCursor 3c8a8ff888 Extend fine-grained ACL to settings, content, shop, and radio.
Local Build and Deploy / deploy (push) Successful in 54s
Gate pages and mutations on module PERMS instead of dashboard-only staff checks, add radio view/edit slugs with migration 0015, and expand the operations contract tests.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:11:55 +02:00
SimoandCursor f2427b3483 Harden admin ACL on critical write paths.
Local Build and Deploy / deploy (push) Successful in 54s
Gate translations, RCON, and user mutations on SETTINGS_EDIT, RCON_EXECUTE, and USERS_EDIT instead of dashboard/rank checks; redirect the legacy user-edit URL to the guarded canonical page.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:07:15 +02:00
openhands 59b63d6e70 Fix real Biome bugs: inner declarations, dup keys, assign-in-expr, implicit any, cookie, a11y svg/keyboard, json
Local Build and Deploy / deploy (push) Successful in 51s
2026-07-14 18:58:40 +02:00
openhands 045dc06a1f fix: resolve type errors and migrate pnpm settings to pnpm-workspace.yaml
Local Build and Deploy / deploy (push) Failing after 56s
- Move pnpm.onlyBuiltDependencies/overrides from package.json to pnpm-workspace.yaml (clears pnpm WARN)
- Allow useServerAction run() to accept actions returning void
- Make adminAction/authAction input optional so no-schema actions can be called without args
- Return ActionResult from updateBcPage
- Fix categoryPageMap value type (number | undefined)
- Declare DbService.queryCount field
- Use definite assignment for release in withFurniDataLock
- Narrow pair type in theme-contrast test
2026-07-13 22:10:50 +02:00
openhands df38dccbf1 style: format code biome
Local Build and Deploy / deploy (push) Failing after 46s
2026-07-13 21:57:41 +02:00
openhands 8efd032cc6 style: format code with prettier agian
Local Build and Deploy / deploy (push) Failing after 49s
2026-07-13 21:41:52 +02:00
openhands e6d7f2280b Add named custom theme presets (save/load/rename/delete) in admin theme editor
Local Build and Deploy / deploy (push) Successful in 58s
2026-07-13 20:42:40 +02:00
openhands a16d9859e8 Add admin HK color customization fields to theme editor
Local Build and Deploy / deploy (push) Successful in 58s
- Add 6 new admin color DB keys (admin_canvas, admin_surface, admin_text,
  admin_text_muted, admin_border, admin_sidebar_bg) that override the
  derived admin palette
- Extract adminPaletteCss() from themePaletteCss() for reuse
- Generate admin CSS variables in both :root and html.dark with overrides
- Persist admin color settings via saveTheme action
- Add Admin panel (HK) section to /admin/theme with color pickers
2026-07-13 19:49:19 +02:00
openhands e5ae51bff7 Add NFC normalization to all FormData inputs across 41 server actions
Local Build and Deploy / deploy (push) Successful in 59s
All user-supplied string values from FormData now go through
String.prototype.normalize('NFC') to prevent Unicode homoglyph
attacks and canonicalization bypasses. NFC is idempotent for
already-normalized strings, so this is a pure security improvement
with zero behavioral change for legitimate users.
2026-07-13 12:21:37 +02:00
openhands f6ad030c5b Add EpicNext CMS foundation layer and fix critical security gaps
Local Build and Deploy / deploy (push) Successful in 1m1s
- Create src/lib/foundation/ (860 LOC, 9 files): typed action wrappers,
  DbService with health checks, CSRF validation, safe redirects,
  AsyncLocalStorage request tracing, branded types, reusable Zod schemas
- Migrate moderation.ts and user-settings.ts to foundation patterns
- Fix abuse-guard.ts: bound in-memory Maps with LRU eviction (was unbounded)
- Fix access-guard.ts: separate try/catch per check, log degradation
  instead of blanket fail-open
- Replace raw redirect() calls with safeRedirect() in guard.ts and
  permissions.ts to prevent open-redirect attacks
- Add CSRF validation to api-handler.ts for mutating methods
- Add canonicalizeFormData() utility for FormData input sanitization
2026-07-13 12:03:49 +02:00
openhands efe467d352 Add 12 more languages: ro, hu, cs, sk, da, no, el, bg, hr, sr, uk, ru
Local Build and Deploy / deploy (push) Successful in 1m0s
2026-07-12 21:52:22 +02:00
openhands 395b43081c Add Turkish language support
Local Build and Deploy / deploy (push) Successful in 1m6s
2026-07-12 21:47:50 +02:00
openhands e3b792f5a3 Add Portuguese, Polish, and Swedish language support with flags
Local Build and Deploy / deploy (push) Failing after 1m7s
2026-07-12 21:45:35 +02:00
openhands 6933fb77d5 Add admin import overview page and extend CMS translations to all 6 locales
Local Build and Deploy / deploy (push) Successful in 51s
2026-07-12 21:28:16 +02:00
openhands 2e4ed76121 style: format code with prettier
Local Build and Deploy / deploy (push) Successful in 49s
2026-07-12 21:07:34 +02:00
remco e85e4d74ea revert fb8e77bb68
Local Build and Deploy / deploy (push) Successful in 1m11s
revert style: clean up code with prettier and eslint
2026-07-12 21:02:03 +02:00
openhands fb8e77bb68 style: clean up code with prettier and eslint 2026-07-12 20:31:05 +02:00
Simo 60278b9e71 feat: add admin operations suite
Local Build and Deploy / deploy (push) Successful in 50s
2026-07-12 20:11:28 +02:00
Simo eb759f54bf feat: connect guarded asset import api 2026-07-12 19:12:25 +02:00
Simo 4b596226e0 fix: complete acl management 2026-07-12 19:12:24 +02:00
Simo f422bb4a0b feat: add admin content module actions 2026-07-12 15:27:07 +02:00
Simo 9cdd0b4000 feat: persist complete multitheme palettes 2026-07-12 14:49:36 +02:00
Simo 8d37ae9ae0 style: normalize restored source endings
Remote Build and Deploy / deploy (push) Has been cancelled
2026-07-11 21:19:54 +02:00
Simo 0cd753c735 fix: restore complete admin feature dependencies 2026-07-11 21:15:54 +02:00
Simo 5b4228261a Reapply "Add missing admin action files and navigation links"
This reverts commit 4d515bc400.
2026-07-11 20:52:56 +02:00
Simo 4d515bc400 Revert "Add missing admin action files and navigation links"
This reverts commit 41be6835bf.
2026-07-11 20:37:56 +02:00
Simo 4a1e1115b3 Harden CMS security and theme contrast 2026-07-11 20:27:20 +02:00
openhands 41be6835bf Add missing admin action files and navigation links
- Add 11 missing server action files: badges, bulk-users, catalog, catalog-bc, catalog-items, import-badges, import-furni, multi-account-detect, permissions, rooms, soundtracks
- Add missing admin navigation links: tickets, sounds, translations, import, radio sub-pages
- Add translation keys for all new navigation items
2026-07-11 12:01:05 +02:00
openhands 942bc6fc8d Security hardening, code quality, and ESLint setup
- Remove production DB dump (db_backup_*.sql) and update.log from git tracking
- Add DB backups to .gitignore
- Replace all console.log/console.error with structured logger module
- Translate Dutch error messages to English (link-discord.ts)
- Remove dead code blocks (register-form.tsx false && pattern)
- Add ESLint flat config with TypeScript, React, Next.js, jsx-a11y, and security plugins
- Add Prettier config
- Add eslint-plugin-security for security-aware linting
- Fix all 119+ ESLint warnings across the codebase:
  - Resolve security/detect-object-injection with safe access patterns
  - Resolve security/detect-non-literal-fs-filename with path traversal validation
  - Replace <img> with next/image <Image> component
  - Remove unused variables and imports
  - Replace non-null assertions with proper type guards
  - Replace <a> with <Link> for internal navigation
  - Use next/script Script component for external scripts
- Fix setState-in-useEffect anti-patterns (navbar-color-picker, logo-generator, theme-switcher)
- Add lint and format scripts to package.json

All checks: typecheck ✓, tests 58/58 ✓, lint 0 errors 0 warnings ✓
2026-07-10 22:48:22 +02:00
openhands fc57fb06d1 chore: remove dead code, unused CSS, unused components, and clean up git tracking
- Remove storage/logs/ and prod.log from git tracking; add to .gitignore
- Remove unused AvatarCarousel and ArticleSlider components
- Remove unused SkeletonTable export from ui.tsx
- Remove unused ChevronDown import from admin layout
- Remove 13 unused CSS classes (icon-base, nav-*, navigation-icon*, .app.dark,
  text-body, transition-base, card-base, admin-info-grid, .coin.*)
- Remove duplicate translation keys (openMenu/closeMenu in en.json)
- Fix admin-bans to use Prisma-generated bans_type enum
- Create shared AdminPageHeader component and formatDate utility
- Add logger and generateRequestId for structured logging
- All 58 tests pass, typecheck clean, build succeeds
2026-07-08 13:27:01 +02:00
openhands 5c638cd6bc perf: add bans.user_id index, Redis cache layer, rate-limit improvements, radio contest/giveaway columns, and tests
- Add DB index on bans.user_id to speed up per-request ban lookups (migration 0008)
- Replace in-process rate limiter with Redis-backed implementation with in-memory fallback
- Add Redis caching layer for site settings with TTL invalidation (migration 0009)
- Add rate limiting to resetPassword to prevent token brute-force attacks
- Update all rateLimit callers to await the now-async function
- Flesh out RadioContests and RadioGiveaways models with title, description, prize, date, and winner columns
- Update radio contest/giveaway pages to display new fields
- Add tests for rate limiter (4 tests) and password-reset actions (3 tests)
- Add REDIS_URL environment variable (optional, falls back to in-memory)
2026-07-08 12:49:24 +02:00
openhands 43c0ba6614 Add Discord verification option for users without email 2026-07-07 20:37:42 +02:00
openhands f386ae2b25 Add more button/navbar colors and gradient mix section to theme editor 2026-07-07 20:04:16 +02:00
openhands 25c3040949 Add favicon upload option in admin panel 2026-07-05 23:22:44 +02:00
openhands 8bcbc501ba Performance, SEO, a11y, and code quality improvements
CI / check (push) Has been cancelled
1. Performance: 25 pages switched from force-dynamic to revalidate=300 (ISR);
   2 pages (community, developers) now fully static (SSG)
2. DB indexes: Added @@index on foreign keys for WebsiteArticles,
   WebsiteArticleReactions, WebsiteArticleComments, WebsiteHelpCenterTickets,
   WebsiteShopArticles, RadioSongRequests, StaffActivities
3. SEO: Added robots.ts, sitemap.ts, canonical URLs, Open Graph + Twitter
   Card metadata on root layout and news articles
4. A11Y: Replaced <details>/<summary> dropdowns with accessible button-based
   NavDropdown (aria-expanded, aria-haspopup, role=menu). MobileNav now
   uses translated aria-label, aria-expanded, aria-controls, role=menu
5. Code quality: Added try/catch to updateArticle/deleteArticle; deleteArticle
   now uses prisma. for atomicity
6. CI/CD: Added GitHub Actions workflow (typecheck + test)
7. i18n: Added openMenu/closeMenu keys to all 6 locales
8. Observability: Health endpoint now checks SMTP reachability when configured
9. Loading states: Added loading.tsx for root, admin, and news sections
10. Word filter cache: Added 60s TTL auto-refresh instead of manual cache bust
2026-07-04 19:41:04 +02:00
openhands 5628e7d6b7 Security hardening: 12 improvements across the stack
1. env.ts: APP_KEY placeholder detection with validation
2. schema.prisma: password column widened to varchar(255) for argon2id
3. auth.ts: trustHost restricted to development only
4. next.config.ts: added CSP, HSTS, X-Frame-Options, and other security headers
5. api.ts: CORS restricted to APP_URL instead of wildcard
6. register-form.tsx: migrated from REST API fetch to server action (useActionState)
7. twofactor.ts + 2fa page: TOTP recovery codes (8 one-time codes, generated and displayed)
8. register.ts: password min length 8 + complexity requirements (upper, lower, digit)
9. register.ts + help-tickets.ts + radio-shouts.ts: Zod schema validation
10. rate-limit.ts: improved periodic cleanup with aggressive eviction at 10k buckets
11. guard.ts + admin actions: rate-limited admin actions (30 req/min per staff)
12. help-tickets.ts + radio-shouts.ts: content moderation via moderateOrThrow
2026-07-04 18:52:00 +02:00
openhands f3367e9b7b feat: save logos to media/logo/ subdir, add Logo generator link to admin dropdown 2026-07-03 17:14:44 +02:00
openhands 917437c5ef fix: use server-side fetch for logo save (bypass CORS), detect file MIME on extension 2026-07-03 17:05:25 +02:00
openhands 073f8e1b6a fix: detect actual MIME type for save-logo extension instead of hardcoded png 2026-07-03 17:00:08 +02:00
openhands af2d5b4943 feat: add save as site logo button to logo generator 2026-07-03 16:45:43 +02:00
remco 64f50b2dde fix: resolve auth security issues - 2FA require TOTP on disable, rate limiting, timing-safe login, token expiry check 2026-07-02 14:54:25 +02:00
remco 4a06b30263 feat: complete admin error handling improvements - add error display to articles pages
- Add error display to articles pages (overview, edit, new)
- Improve createArticle action to handle database errors gracefully
- Redirect with error query params for user feedback on failure
- Completes error handling improvements across admin pages
- Enhances error reporting for better user experience
2026-07-01 21:32:59 +02:00
remco 0323c3fcaa fix: improve error handling in admin pages to show user-friendly error messages
- Add error display to help questions new/edit pages
- Improve error visibility in admin-badges, admin-applications, admin-logs, admin-users pages
- Update createHelpQuestion action to properly handle and display unique name collisions and database errors
- Add user-friendly error messages to admin error handling
- Enhances admin page error reporting for better user experience
2026-07-01 21:25:30 +02:00
remco beb36d2dbf feat: improve users page with inline staff actions and commandocentrum cleanup 2026-07-01 18:38:50 +02:00
remco f2d13cf644 fix: serve uploaded images via /api/media/[name] to avoid Next.js static 404 2026-07-01 17:10:43 +02:00