Commit Graph
73 Commits
Author SHA1 Message Date
Simo 9ec9ab31ad feat: export Catalog Studio assets and SQL to catalog repository
CI / check (pull_request) Failing after 1m21s
CI / deploy (pull_request) Skipped
CI / e2e (pull_request) Skipped
2026-09-05 11:49:00 +02:00
openhands 399c047515 fix: harden admin actions, search, sanitization and repo hygiene
CI / check (push) Successful in 1m21s
CI / deploy (push) Successful in 1m25s
- Split approve/dismiss application workflows with distinct audit logs,
  rate-limited guards and real error logging
- Validate article status/date/id input and stop resetting publishedAt
  on every update
- Validate guild updates (state, forum enums, non-empty name) behind
  rate-limited guard
- Fix scheduled-article publishing (ignore NULL dates, set updatedAt,
  type-safe predicates)
- Harden admin search API (LIKE escaping, query cap, per-user
  rate limit, round-robin result cap) and fix search dialog
  abort/res.ok/loading races
- Lock down HTML sanitizer to an allowlist profile and add XSS tests
- Improve mobile nav accessibility (unique id, dialog role, focus
  management, scroll lock, outside close)
- Log swallowed server errors instead of silent catch blocks
- Remove dead eslint config, drop unused dompurify deps, restore knip
  CI step, add Playwright config with smoke spec
2026-09-04 13:04:08 +02:00
openhands 30c95b1a5c feat: comprehensive CMS improvements
CI / runtime-diagnostics (push) Skipped
CI / release (push) Skipped
CI / check (push) Failing after 0s
CI / deploy (push) Skipped
- Fix DOMPurify SSR crash (use isomorphic-dompurify)
- Fix SanitizedHtml to sanitize by default
- Add auth guards to studio/catalog maintenance pages
- Add update/edit to vouchers CRUD
- Add update/edit to rare-values CRUD
- Add approve workflow to applications page
- Add edit form to guilds detail page
- Add SEO metadata to all public pages (21 pages)
- Fix mobile nav accessibility (focus trap, aria attributes)
- Fix missing labels and table accessibility
- Add dynamic imports for heavy client components (6 components)
- Fix silent error swallowing (40+ locations)
- Add content scheduling for articles (publishAt, status)
- Wire up 12 missing webhook notification triggers
- Add global search to admin panel
- Add bulk actions to admin users table
- Fix JSON formatting and a11y issues
2026-09-03 16:00:32 +02:00
openhands 037b295b93 feat(ci): automated docker update script + nightly cron
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 33s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m3s
- scripts/docker-update.sh: git pull --ff-only, host db:migrate, docker compose
  build + up -d, health-check wait, keeps host-side PM2 'next' stopped.
  Fails safe on dirty working tree (exit 1) and on health failure (exit 3).
- cron entry: daily 03:30 -> logs/docker-update.cron.log
- README: Automatic Updates section + docker commands row
2026-09-02 12:25:42 +02:00
openhands 58c35a2920 feat: enforce no hardcoded colors across entire CMS
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 32s
CI / release (push) Skipped
CI / deploy (push) Successful in 58s
Added scripts/check-admin-colors.mjs — scans all src/ files for:
- text-white, text-black (use theme text vars)
- bg-white, bg-black (use theme background/overlay vars)
- bg/text/border/ring with gray/slate/zinc/stone palette
- bg/text/border/ring with red/green/blue/etc palette

Fixed 21 violations across 11 files:
- Overlays: bg-black/* → bg-foreground/*
- Text: text-white → text-primary-foreground
- Backgrounds: bg-white/10 → bg-background/10
- Green accents: bg-green-* → bg-primary
- Red accents: bg-red-* → bg-destructive

Integrated into:
- lint-staged: runs on every *.ts/*.tsx commit
- vitest: src/lib/no-hardcoded-colors.test.ts replaces old audit test
- Allowlist: shadcn/ui primitives (button, badge, dialog) + 4 graphical files
2026-09-01 19:33:50 +02:00
Simo 9a0b6e091a ci: inspect permission value limits
CI / runtime-diagnostics (push) Skipped
CI / check (push) Successful in 27s
CI / release (push) Skipped
CI / deploy (push) Successful in 43s
2026-08-31 21:19:06 +02:00
Simo 75b85dcdd9 ci: probe permission page database reads
CI / runtime-diagnostics (push) Skipped
CI / check (push) Failing after 27s
CI / release (push) Skipped
CI / deploy (push) Skipped
2026-08-31 21:13:03 +02:00
Simo b1ddda66ff Revert "Merge pull request 'Complete Housekeeping migration and /ase cutover' (#52) from codex/housekeeping-complete into main"
CI / check (push) Successful in 27s
CI / release (push) Skipped
CI / deploy (push) Successful in 43s
This reverts commit 488b6e57c4, reversing
changes made to b506b4499a.
2026-08-30 21:31:34 +02:00
Simo 2b8f73a91d feat(housekeeping): cut over administration to ase 2026-08-30 20:35:22 +02:00
Simo 8a31556d51 test(housekeeping): prove 137 route parity
CI / check (pull_request) Successful in 1m9s
CI / release (pull_request) Skipped
CI / deploy (pull_request) Skipped
2026-08-30 19:11:14 +02:00
openhands d57424a9ee style: fix biome formatting in sync-nitro-urls
CI / check (push) Successful in 27s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m3s
2026-08-30 18:24:07 +02:00
openhands 678d22ceab feat: bulletproof updater + fixes for client links (icons/furniture/gamedata)
CI / check (push) Failing after 8s
CI / release (push) Skipped
CI / deploy (push) Skipped
2026-08-30 18:19:46 +02:00
Simo 2a36ba1956 Merge branch 'main' into codex/housekeeping-foundation
CI / check (pull_request) Successful in 28s
CI / release (pull_request) Skipped
CI / deploy (pull_request) Skipped
2026-08-26 19:50:26 +02:00
openhands e7f70bb429 Chore: remove unused e2e register debug script
Flagged by knip as unused. It was a one-off DB smoke test with a
hardcoded database password that should never have been committed.
2026-08-26 15:06:14 +02:00
openhands 2d09a4a92c Add missing migrations
CI / check (push) Failing after 26s
CI / deploy (push) Skipped
CI / release (push) Skipped
2026-08-26 14:28:28 +02:00
openhands 4eded4ec61 Apply Biome lint fixes
CI / check (push) Failing after 26s
CI / release (push) Skipped
CI / deploy (push) Skipped
2026-08-25 22:26:05 +02:00
openhands a5044c80d7 fix: resolve biome linter warnings and code formatting
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Successful in 46s
2026-08-25 21:54:02 +02:00
openhands 416c31643b perf: optimize dashboard database queries and remove unused imports
CI / check (push) Failing after 10s
CI / deploy (push) Skipped
CI / release (push) Skipped
2026-08-25 21:52:18 +02:00
Simo 3b3d7780c9 docs: complete housekeeping migration matrix 2026-08-25 18:49:58 +02:00
Simo 6ed1b03e24 chore: align Node 26.7.0 toolchain
CI / check (push) Successful in 35s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m0s
2026-08-24 19:12:11 +02:00
openhands ca1756fbb0 Fix pre-existing type errors in diagnostics scripts (blocked pre-push tsc hook)
CI / check (push) Failing after 31s
CI / release (push) Skipped
CI / deploy (push) Skipped
2026-08-23 15:07:58 +02:00
openhands 536b61c7e7 Add catalog maintenance page with sprite-id, dedup and FurnitureData id-alignment repairs 2026-08-23 15:05:49 +02:00
openhands 3d832cceff scripts: fix translate call for furni18n
CI / check (push) Failing after 28s
CI / release (push) Skipped
CI / deploy (push) Skipped
2026-08-21 20:06:27 +02:00
openhands f2a023efb3 scripts: fix build/translate calls for furni18n 2026-08-21 20:06:02 +02:00
openhands e66b2c1a5a scripts: add full build/translate scripts for furnidata i18n 2026-08-21 20:04:53 +02:00
openhands 9e453666e5 fix: use jsonc-parser in config merge and make updater reliably restart all services
CI / check (push) Successful in 25s
CI / release (push) Skipped
CI / deploy (push) Successful in 58s
merge-config.cjs loaded json5 (not installed, and unable to parse JSONC
comments), so sync_configs crashed mid-update and do_restart never ran —
leaving the emulator running the old JAR.

- merge-config.cjs: switch from json5 to jsonc-parser (already a
  dependency) to parse .jsonc configs including comments
- update-Nitrov3.sh: always run renderer/client parallel builds instead
  of gating them on the emulator's update status
- update-Nitrov3.sh: isolate each repo's yarn cache (--cache-folder) so
  parallel installs can't corrupt a shared cache and silently drop
  vite/pixi.js; replace invalid --no-cache flag with per-repo cache reset
- update-Nitrov3.sh: fix misleading [DRY-RUN] label on real updates
2026-08-11 19:06:29 +02:00
openhands abc06e438c fix: load .env in standalone tsx scripts
CI / check (push) Successful in 25s
CI / release (push) Skipped
CI / deploy (push) Successful in 52s
2026-08-11 17:08:23 +02:00
openhands e867b675fc fix: replace jsonc with jsonc-parser and cleanup build config 2026-08-11 16:50:10 +02:00
openhands 3edc987281 feat: integrate FlareSolverr for Cloudflare bypass on clone sources
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 46s
- Add FLARESOLVERR_URL env var to .env.example
- Update fetchSourceFurnidata to fall back to FlareSolverr on CF challenges (403/HTML)
- Add docker-compose.yml with FlareSolverr service
- Add scripts/health-check.sh for FlareSolverr readiness check
- Add health:check script to package.json
- Document FlareSolverr setup in README
2026-08-04 19:00:30 +02:00
openhands 2e87e5bf09 chore: remove test-cf.ts (puppeteer no longer used)
CI / check (push) Successful in 25s
CI / release (push) Skipped
CI / deploy (push) Successful in 56s
2026-08-04 18:46:31 +02:00
openhands 9fbfd2f51a chore: verify clone sources with Cloudflare bypass test script; remove broken Hubbly URLs
CI / check (push) Successful in 26s
CI / release (push) Skipped
CI / deploy (push) Successful in 55s
Verified working sources via puppeteer Cloudflare bypass test:
- Habbo (GitHub) - 200
- Wibbo - 200 furnidata, 403/403 nitro/icons
- Hubba.cc - 200 furnidata, 404 nitro
- Leet - 200 304 304 (all working)
- Habblet City - 200 200 200 (all working)
- Soda Ho - 200 furnidata, 404 nitro/icons

Cloudflare-blocked sources removed (habba.io, habcrush.pw, fobba.net, etc)
Hubbly URLs removed (all 404) pending verification
Added test-cf.ts script for future source validation
2026-08-04 17:28:01 +02:00
Simo 1f4aadb3d7 chore: remove Sentry integration
CI / check (push) Successful in 21s
CI / release (push) Skipped
CI / deploy (push) Successful in 53s
2026-08-01 22:12:31 +02:00
openhands 14a3de0f2a style(scripts): format schema generator to satisfy biome check
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Failing after 1m0s
2026-08-01 17:50:16 +02:00
openhands 8275842e78 fix(scripts): resolve noAssignInExpressions lint error in schema generator
CI / check (push) Successful in 30s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m28s
2026-08-01 17:14:48 +02:00
SimoandCursor db957d7fb1 fix(ops): narrow DB_BACKUP_DIR for jobs-worker typecheck
CI / check (push) Failing after 9s
CI / release (push) Skipped
CI / deploy (push) Skipped
Co-authored-by: Cursor <[email protected]>
2026-08-01 15:27:01 +02:00
SimoandCursor 725e1cb338 feat(ops): health-fail alerts, optional DB backup, admin UX polish
Wire jobs-worker health probes to Discord/email alerts with cooldown, optional mysqldump, rate-limit /api/health, mark-all-read alerts, ConfirmDialog on destructive admin actions, and raise coverage floors.

Co-authored-by: Cursor <[email protected]>
2026-08-01 15:25:47 +02:00
SimoandCursor ba82789166 chore(db): finish Prisma cutover to Drizzle Kit tooling
CI / check (push) Failing after 9s
CI / release (push) Skipped
CI / deploy (push) Skipped
Move CMS SQL to drizzle/migrations, drop prisma packages/schema, wire drizzle-kit scripts, and regenerate schema names from src/db/schema.ts.

Co-authored-by: Cursor <[email protected]>
2026-08-01 15:02:21 +02:00
SimoandCursor 422567272c chore(db): remove Prisma facade and drop prisma:generate from CI
Co-authored-by: Cursor <[email protected]>
2026-08-01 14:38:42 +02:00
openhands e5ff7ec9e5 chore: clean up biome lint warnings — all non- intentional resolved
CI / check (push) Successful in 33s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m25s
- Remove 25 unused imports across 14 test files
- Remove 1 unused variable (rename with _ prefix)
- Fix 2 noBannedTypes (Function → (...args: unknown[]) => unknown)
- Fix 1 useTemplate lint (string concat → template literal in merge-config.cjs)
- Fix 1 useNodejsImportProtocol (merge-config.cjs)
- Fix 2 noTemplateCurlyInString (generate-drizzle-schema.mjs generator code)
- Auto-fix formatting + import sorting across modified files
- 221 remaining warnings: intentional noExplicitAny in prisma-facade.ts (Prisma compat layer)
- 0 tsc errors, 583 tests passing
2026-07-31 15:26:39 +02:00
openhands beae86194d fix: resolve biome lint errors in prisma-facade
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Failing after 1m23s
- Fix noPrecisionLoss on BIGINT UNSIGNED max value (2^64-1) with biome-ignore comments
- Fix noThenProperty on custom thenable with biome-ignore comment
- Auto-format remaining files (biome check --write)
- Re-stage auto-fixed files from previous commit
2026-07-31 14:17:06 +02:00
openhands 56061e41d4 refactor: replace Prisma ORM runtime with Drizzle ORM facade
CI / check (push) Failing after 12s
CI / deploy (push) Skipped
CI / release (push) Skipped
- Replace Prisma client runtime with Drizzle ORM (zero Prisma engine/query engine in production)
- Add Prisma-compatible facade (@/lib/prisma-facade.ts) backed by Drizzle for backwards compatibility
- Runtime queries route through Drizzle ORM; @prisma/client is now devDependency (types only)
- Remove @prisma/adapter-mariadb dependency; delete prisma-pool.ts and types/prisma.ts
- New Drizzle schema layer: src/db/schema.ts (176 tables) and src/lib/db.ts (connection)
- Update README documenting the dual-layer ORM architecture
- Restore src/generated/ gitignore (build artifact for local type generation)
- 0 TypeScript errors, 583 tests passing

The facade intentionally uses `any` types to match the Prisma Client API surface,
allowing existing code to run unmodified while routing queries through Drizzle at runtime.
2026-07-31 14:11:03 +02:00
openhands 91357aca3b ci: fix Gitea Actions workflow 2026-07-30 17:51:24 +02:00
openhands 17847545dd Improvements: remove dead config, fix ESM, add URL validation, unify types, add missing logging
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m52s
- Remove .prettierrc (dead config, Biome replaces Prettier)
- Rename lighthouserc.json to lighthouserc.cjs with module.exports for ESM compat
- Add logger.warn to empty catch blocks in auth, register, site-settings, prisma-cache, redis, security, rate-limit
- Unify ActionResult type: action-helper.ts uses 'ok' consistent with safe-action-shared.ts
- Add noUnusedLocals + noUnusedParameters to tsconfig + fix 25 pre-existing unused vars
- Replace barrel export src/types/index.ts with direct @/types/common imports
- Make trustHost conditional (development only) in auth.ts
- Add pre-flight URL validation to update-Nitrov3.sh to catch image.library.url misconfigurations
- Improve NITRO_IMAGE_LIBRARY_URL content validation in pre-flight & post-compute checks
2026-07-26 20:28:11 +02:00
openhands 1acace49d0 refactor: full codebase overhaul — dead code removal, env validation, logger migration, date consolidation, Prisma schema cleanup, button consistency, useEffect deps, test coverage
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 8s
- env.ts: added 10 missing Zod-validated env vars (imager, paypal currency, argon2/bcrypt params)
- Migrated 6 modules from process.env to validated env.* (auth, proxy-auth, paypal, password, redis, imager, moderation, alert, logger)
- Replaced console.warn/error with pino logger in 9 server-side modules
- Removed 50+ dead exports (SWF wrappers, coalesceHotelName, signIn, isStaff re-export, formatTimestamp, Skeleton/SkeletonCard, 4 unused housekeeping sections)
- Consolidated date formatting: 28 files migrated to shared formatDate() from @/lib/format-date
- Wired 4 radio/settings API routes through cached siteSettings service instead of raw Prisma queries
- Added getMany()/getAll() helpers to SiteSettings service
- Removed 88 dead Prisma model definitions (schema 2763→1846 lines)
- Created admin action-helper.ts with wrapAction() for standardized error handling
- Fixed useEffect dependency arrays in 4 data-heavy components
- Replaced raw btn CSS classes with shadcn Button component across admin pages
- Stripped dead i18n namespaces (common, pages.client) from all 22 translation files
- Removed 2 dead scripts (create-release.sh, check-local-imports.ts)
- Fixed knip.json configuration
- Added 7 new test suites: format-date, paypal, moderation, alert, webhook, action-helper, and fixed password.test.ts for env mocking
- All 358 tests passing across 72 test files
- TypeScript: 0 errors
2026-07-25 17:33:06 +02:00
openhands f7f6e09174 Fix migration connection exhaustion and polish auth pages
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m49s
- apply-migrations.ts: use single shared connection instead of one per operation
- Increase MariaDB max_connections from 151 to 300 in server config
- home-login-form.tsx: replace hardcoded gray colors with theme variables
- register-form.tsx: add password strength meter, spinner, theme-aligned inputs
- login-form.tsx: add Discord/Google SVG icons, spinner, smoother 2FA animation
- page/register/login: apply premium animations (float, stagger, glow, gradient)
2026-07-24 11:30:58 +02:00
openhands 7eb3ba1ce8 feat: add create-release.sh for manual release creation
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m30s
2026-07-20 15:56:45 +02:00
SimoandCursor 6b884ad25a Harden deploy gates, prod AUTH_SECRET, and Sentry error reporting.
Local Build and Deploy / deploy (push) Successful in 1m42s
Align onlyBuiltDependencies with the workspace, fail fast without AUTH_SECRET in production, and delete catalog_items via VARCHAR-safe SQL so page deletes do not leave orphans.

Co-authored-by: Cursor <[email protected]>
2026-07-18 19:32:15 +02:00
openhands 0d82f1325e Fix DB connect_timeout warning and remove deprecated Sentry disableLogger
Local Build and Deploy / deploy (push) Successful in 1m10s
2026-07-18 16:54:20 +02:00
SimoandCursor 09f1bc2bd6 Add production observability: Sentry, pino, and sharp badge encoding.
Local Build and Deploy / deploy (push) Successful in 1m9s
Sentry is opt-in via DSN env vars; logger uses structured pino JSON in prod; badge uploads are normalized to GIF with sharp.

Co-authored-by: Cursor <[email protected]>
2026-07-17 23:09:57 +02:00
openhands df38dccbf1 style: format code biome
Local Build and Deploy / deploy (push) Failing after 46s
2026-07-13 21:57:41 +02:00