Commit Graph
179 Commits
Author SHA1 Message Date
Simo abc707cfb2 feat(housekeeping): deliver hotel operations
CI / check (pull_request) Failing after 36s
CI / release (pull_request) Skipped
CI / deploy (pull_request) Skipped
2026-08-30 14:34:26 +02:00
Simo bfc5bd78a1 fix(housekeeping): preserve banner server actions 2026-08-30 14:33:50 +02:00
Simo 9c4b973faf feat(housekeeping): deliver economy vertical
CI / check (pull_request) Successful in 40s
CI / release (pull_request) Skipped
CI / deploy (pull_request) Skipped
2026-08-30 13:47:06 +02:00
Simo b70bd401d1 fix(housekeeping): retain admin banner shim
CI / check (pull_request) Failing after 31s
CI / release (pull_request) Skipped
CI / deploy (pull_request) Skipped
2026-08-30 12:11:14 +02:00
Simo 08358b8aa4 style: satisfy housekeeping biome gate 2026-08-30 11:59:24 +02:00
Simo d1160eb65a fix(housekeeping): address task 14 review round 3 2026-08-30 11:48:52 +02:00
Simo c524b305d7 fix(housekeeping): address task 14 review round 2 2026-08-30 11:30:17 +02:00
Simo d09eaa33d6 fix(housekeeping): address task 14 review round 1 2026-08-30 10:53:50 +02:00
Simo fd68819d9b feat(housekeeping): deliver content vertical 2026-08-30 01:54:43 +02:00
Simo 3fa1119f5a fix(housekeeping): address people moderation review
CI / check (pull_request) Failing after 9s
CI / release (pull_request) Skipped
CI / deploy (pull_request) Skipped
2026-08-29 23:53:38 +02:00
Simo 29fe22297b feat(housekeeping): complete people moderation parity 2026-08-29 22:38:50 +02:00
Simo 3d385d1869 Merge branch 'main' of https://gitlab.epicnabbo.nl/remco/EpicNext-Cms into codex/housekeeping-complete 2026-08-29 21:16:46 +02:00
Simo a6a288d9ff fix(housekeeping): restore people partial compatibility
CI / check (pull_request) Successful in 42s
CI / release (pull_request) Skipped
CI / deploy (pull_request) Skipped
2026-08-29 21:03:43 +02:00
openhands 7f39ba4257 fix: harden SSO ticket flow and revoke tickets on logout
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 54s
Reuse the outstanding auth_ticket instead of minting a fresh one on every
/client load, so reloading the page or opening a second tab no longer
invalidates a game session that is still connecting. New tickets are minted
with a guard against the previously-read value so concurrent launches
converge on the same ticket.

Revoke the auth_ticket when signing out (toolbar, header and sign-out
everywhere) so a leaked ticket can no longer be replayed against the
emulator, and prevent SSO leakage via referral by setting no-referrer on the
client iframe. Strip all whitespace from the ticket prefix and build the
launch URL through a tested helper that handles query strings, existing sso
params and URL fragments correctly.
2026-08-29 20:54:06 +02:00
Simo 91c9efcbb4 fix(housekeeping): complete people workflow fidelity 2026-08-29 14:39:38 +02:00
Simo 25b76437ff fix(housekeeping): harden people account workflows 2026-08-29 13:13:04 +02:00
Simo e1b31ff773 feat(housekeeping): deliver people account workflows 2026-08-29 11:45:50 +02:00
Simo c325c53774 fix(housekeeping): harden system workflow boundaries
CI / check (pull_request) Successful in 33s
CI / release (pull_request) Skipped
CI / deploy (pull_request) Skipped
2026-08-29 00:25:47 +02:00
Simo 3788ecd9f1 feat(housekeeping): deliver system vertical 2026-08-28 23:31:47 +02:00
Simo 139e8cfc3a Merge branch 'main' of https://gitlab.epicnabbo.nl/remco/EpicNext-Cms into codex/housekeeping-complete 2026-08-28 20:21:13 +02:00
openhands 944e8ff1d8 fix: harden update pipeline and restore a clean production build
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m0s
- update-Nitrov3.sh: build CMS into .next-staging and swap atomically so a
  failed build never takes the live site down; auto-merge new variables
  from .env.example; validate env for duplicates/broken lines; restart the
  emulator/CMS only when rebuilt or unhealthy; fix step renumbering
- next.config.ts: support NEXT_DIST_DIR for staged production builds
- fix all TS errors (unused imports, missing tryDownloadCandidates helper)
  so tsc and the production build pass clean
- add Dockerfile/.dockerignore and switch docker-compose to a CMS container
- include prevailing UI/refactor changes (SurfaceCard, ticketing, tsconfig)
2026-08-28 12:48:04 +02:00
Simo 00618fb2a3 fix(housekeeping): harden command dispatch boundaries 2026-08-27 19:32:19 +02:00
Simo 796d009c07 fix(housekeeping): harden audited command dispatch 2026-08-27 18:58:14 +02:00
Simo 6aed71a8b2 feat(housekeeping): dispatch audited commands 2026-08-27 18:30:44 +02:00
Simo 60968409aa fix(housekeeping): count preference payload bytes 2026-08-27 17:53:16 +02:00
Simo 4e0bf598ed fix(housekeeping): harden preference persistence 2026-08-27 17:44:53 +02:00
Simo 64bb230de5 Merge branch 'main' of https://gitlab.epicnabbo.nl/remco/EpicNext-Cms into codex/housekeeping-complete 2026-08-27 17:25:31 +02:00
openhands 89c1751e79 refactor: extract shared login credential verification into auth/login-core
CI / check (push) Successful in 35s
CI / release (push) Skipped
CI / deploy (push) Successful in 58s
The username normalization, dummy-hash constant, password check and
email-verification gate were duplicated between precheckLogin and the
NextAuth credentials authorize handler. Move them into a single
login-core module so both paths share one source of truth and stay
consistent.
2026-08-27 15:17:54 +02:00
openhands ac5cd6bc3f fix: normalize username and password with NFC in login flow
CI / check (push) Failing after 5s
CI / release (push) Skipped
CI / deploy (push) Skipped
precheckLogin already normalized the username with NFC, but the
NextAuth credentials authorize handler only trimmed it. This caused a
mismatch for accounts with accented/non-ASCII usernames: the precheck
passed while the actual sign-in lookup found no user and returned
'invalid username or password'.

Also normalize the password to NFC in both the precheck and the
authorize handler to match how register.ts hashes it.
2026-08-27 15:09:43 +02:00
Simo 2eb0456999 feat(housekeeping): persist operator preferences 2026-08-26 22:17:52 +02:00
openhands f25a26a93e Register: auto sign-in to /me and speed/cleanup improvements
CI / check (push) Failing after 30s
CI / release (push) Skipped
CI / deploy (push) Skipped
- Send the verification email after the response via after() so it
  never blocks sign-up
- Invalidate the cached login lookup right after account creation so
  the automatic sign-in always finds the fresh row
- Auto sign in with the submitted credentials and go straight to /me,
  with a fallback to /login?registered=1 if sign-in is refused (e.g.
  email verification required)
- Cache the register page's online/latest user queries to cut DB load
  under traffic
- Fix terms checkbox label double-toggle cancelling the selection
- Add pages.register.redirecting translation to all locales
2026-08-26 14:57:51 +02:00
openhands 2d09a4a92c Add missing migrations
CI / check (push) Failing after 26s
CI / deploy (push) Skipped
CI / release (push) Skipped
2026-08-26 14:28:28 +02:00
openhands 3a292a44f1 feat: make catalog-pages dedup a choosable step in Fix alles
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m3s
The maintenance "Fix alles" now has a checkbox to include or skip the
duplicate catalog_pages merge, so admins can choose whether to run it.
removeDuplicates takes an includePages flag and fixEverything threads it
through to the action.
2026-08-24 18:35:00 +02:00
openhands 6dced0fb54 feat: per-import translation toggle and language picker in studio
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 53s
Furni imports can now choose whether to translate (per import) and which
languages to build, instead of always rebuilding all 13 FurnitureData_<lang>
files. The studio header also has a global switch that persists the
furnidata_translate_enabled setting, seeding the per-import default.
2026-08-24 18:16:42 +02:00
openhands 34475e9bc2 Fix dedup to also remove duplicate catalog_items/catalog_items_bc rows (comma-list-aware item_ids remap)
CI / check (push) Successful in 37s
CI / release (push) Skipped
CI / deploy (push) Successful in 58s
2026-08-23 15:30:52 +02:00
openhands 536b61c7e7 Add catalog maintenance page with sprite-id, dedup and FurnitureData id-alignment repairs 2026-08-23 15:05:49 +02:00
openhands 3d89e108f3 Fix terms acceptance enforcement in register
CI / check (push) Failing after 1m13s
CI / release (push) Skipped
CI / deploy (push) Skipped
- Add termsAccepted to raw form data object
- Check if terms were accepted before DB insert
- Return error if terms not accepted
- All TypeScript and Biome checks pass
2026-08-14 17:10:40 +02:00
openhands e76c530e4f Fix TypeScript errors and implement furniture import ID integrity with 18+ age verification
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m2s
- Add termsAccepted and ageVerified columns to User table
- Update register schema with new boolean fields
- Fix register form age verification checkbox (th -> t)
- Fix furni-import spriteId declaration order
- Fix batch route variable naming (id -> spriteId)
- Fix catalog-audit import path and ensure correct types
- Hardened import with per-item id conflict checks
- Added audit option for FurnitureData.json spriteId conflicts
- Updated tagline to include Leeftijdsvereiste: 18+
2026-08-14 16:37:00 +02:00
openhands e5ec3c1f06 perf: optimize CMS queries, caching, and asset delivery
CI / check (push) Successful in 27s
CI / release (push) Skipped
CI / deploy (push) Successful in 57s
Database:
- Add missing indexes (users.credits, users_currency(type,amount),
  users_settings.respects_received, camera_web.timestamp,
  messenger_offline.user_id) via migrations 0020/0021
- Use partial .select() everywhere instead of SELECT * (tickets, users,
  rooms, audit logs, catalog tree, polls, radio, password reset)
- Add queryPrepared/queryPreparedOne (server-side prepared statements)
  and switch the login check to a prepared statement; drop dead
  cache options from the pool config
- Raise total_users/total_rooms COUNT(*) cache TTL to 5m

Caching:
- Consolidate the three cache helpers (cached, redisCache, cachedQuery)
  into a single memory-first implementation backed by Redis
- invalidateKey now clears the in-process cache as well as Redis
- Cache homepage sections, news list, and leaderboard tabs; share one
  news_list cache key between homepage and news archive
- siteSettings: in-process cache with TTL so repeated getters no longer
  pay a Redis round-trip per call
- Share a 10s poll cache across all radio SSE connections
- Normalize timestamps after cache reads (Redis JSON round-trip)

Assets:
- Enable AVIF/WebP via images.formats and remove unoptimized from news
  covers and the homepage hero (149KB jpg) with proper sizes/priority
- Support ?format=webp|avif|png in the /imaging proxy via sharp

Other:
- Fix pnpm supply-chain minimumReleaseAge failures by excluding the
  freshly-published packages (next 16.3.1, hookform resolvers 5.8.0,
  resend 6.20.0)
- Remove unused before/after fields from housekeeping AuditEntry
2026-08-14 11:20:37 +02:00
openhands e867b675fc fix: replace jsonc with jsonc-parser and cleanup build config 2026-08-11 16:50:10 +02:00
openhands ae1393d3e3 refactor: clean up duplicate imports and dead code
CI / check (push) Successful in 24s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m7s
- Merge type and value imports from the same module into single imports
- Remove dead import-badges action (flow uses /api/admin/import/badges)
- Remove unused babel-plugin-react-compiler devDependency
- Remove stray test.txt file
- Update knip config: track css imports, drop redundant ignore entries
- Update contract test to drop obsolete dead-action assertion
2026-08-09 11:51:26 +02:00
openhands 6a67fb6e83 refactor: remove additional dead exports and unused actions
CI / check (push) Successful in 26s
CI / release (push) Skipped
CI / deploy (push) Successful in 59s
Remove buildFontUrl, measureText, uncached, invalidateCache, fetchJsonWithFlareSolver, upsertPermission, deletePermission, bulkImportPermissions, clearAllPermissions, bulkDeletePermissions, bulkDeletePhotos, userReplyTicket, closeTicketByUser. Update staff-smoke-contract test for bulkDeletePhotos removal.
2026-08-07 19:19:05 +02:00
openhands 1b817fe434 fix: resolve critical bugs and improve admin panel reliability
CI / check (push) Successful in 24s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m0s
- Fix missing await in pets API route causing empty responses
- Fix updateSetting to use upsert pattern instead of update-only
- Create missing /api/admin/sounds/upload route (upload was broken)
- Wire bulk delete actions in catalog table
- Replace native confirm() with useConfirmDialog() across rooms and clone pages
- Add error logging to silent catch blocks in radio actions and audit route
- Add graceful degradation to devops health endpoint
- Add cache eviction to clone icon route to prevent memory leak
- Internationalize hardcoded Italian strings to English
- Remove placeholder created_at fields from prefix API responses
- Remove dead code and fix type errors in translations and import pages
- Standardize PERMS import path in analytics export route
2026-08-06 18:32:55 +02:00
Simo c78f8812ad fix: use configured furni source and catalog assets 2026-08-02 14:22:05 +02:00
SimoandCursor d69e3f5da5 fix(test): mock db in admin-alerts suite for push hook
Co-authored-by: Cursor <[email protected]>
2026-08-01 15:58:17 +02:00
SimoandCursor 9c4949186c feat(admin): server-safe StatusCard and Import hub polish
CI / check (push) Failing after 8s
CI / release (push) Skipped
CI / deploy (push) Skipped
Split OnlineUsersWidget from StatusCard, decouple ad delete button, sync badge import to ExternalTexts+WebsiteBadges, add Import section hub with cancelable SSE jobs and upload SQL option.

Co-authored-by: Cursor <[email protected]>
2026-08-01 15:48:21 +02:00
SimoandCursor 725e1cb338 feat(ops): health-fail alerts, optional DB backup, admin UX polish
Wire jobs-worker health probes to Discord/email alerts with cooldown, optional mysqldump, rate-limit /api/health, mark-all-read alerts, ConfirmDialog on destructive admin actions, and raise coverage floors.

Co-authored-by: Cursor <[email protected]>
2026-08-01 15:25:47 +02:00
SimoandCursor 422567272c chore(db): remove Prisma facade and drop prisma:generate from CI
Co-authored-by: Cursor <[email protected]>
2026-08-01 14:38:42 +02:00
SimoandCursor 65b2fbee6a refactor(db): finish Drizzle migration for remaining actions and services
Co-authored-by: Cursor <[email protected]>
2026-08-01 13:27:59 +02:00
SimoandCursor 22234fe102 fix(test): type drizzle mock callbacks for tsc
CI / check (push) Successful in 24s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m4s
Co-authored-by: Cursor <[email protected]>
2026-08-01 13:18:10 +02:00