openhands
f86f73b128
Add image preview to news listing cards
2026-07-07 19:10:32 +02:00
openhands
8818d5364e
Replace checkbox with React state-driven toggle for reliable terms acceptance
2026-07-07 19:03:33 +02:00
openhands
3becaf5f4f
Fix terms checkbox: wrap input inside label for reliable toggling
2026-07-07 19:00:07 +02:00
openhands
7412bd2dda
Remove outfit selection from register form and fix terms checkbox not toggling
2026-07-07 18:53:13 +02:00
openhands
4ba26fd814
Close dropdown and mobile menu when clicking a page link
2026-07-07 18:34:54 +02:00
openhands
0272da09c1
Fix logo generator: remove decorative fonts and fix missing char spacing
2026-07-07 16:50:58 +02:00
openhands
2f0233a0c0
Add /api/badges/leaderboard endpoint for Nitro v3 badge leaderboard
2026-07-07 16:00:46 +02:00
openhands
29f8a44f0f
Add favicon generator with color picker and text
2026-07-05 23:32:24 +02:00
openhands
4a80742e1c
Add default SVG favicon fallback
2026-07-05 23:25:36 +02:00
openhands
25c3040949
Add favicon upload option in admin panel
2026-07-05 23:22:44 +02:00
openhands
befa4ec282
Translate admin panel to all 6 languages
2026-07-04 21:21:15 +02:00
openhands
f381aa987f
Fix dropdown visibility and add missing translations
2026-07-04 20:18:30 +02:00
openhands
c9d951aa86
Fix login CSP and auth host trust
2026-07-04 20:04:44 +02:00
openhands
8bcbc501ba
Performance, SEO, a11y, and code quality improvements
...
CI / check (push) Has been cancelled
1. Performance: 25 pages switched from force-dynamic to revalidate=300 (ISR);
2 pages (community, developers) now fully static (SSG)
2. DB indexes: Added @@index on foreign keys for WebsiteArticles,
WebsiteArticleReactions, WebsiteArticleComments, WebsiteHelpCenterTickets,
WebsiteShopArticles, RadioSongRequests, StaffActivities
3. SEO: Added robots.ts, sitemap.ts, canonical URLs, Open Graph + Twitter
Card metadata on root layout and news articles
4. A11Y: Replaced <details>/<summary> dropdowns with accessible button-based
NavDropdown (aria-expanded, aria-haspopup, role=menu). MobileNav now
uses translated aria-label, aria-expanded, aria-controls, role=menu
5. Code quality: Added try/catch to updateArticle/deleteArticle; deleteArticle
now uses prisma. for atomicity
6. CI/CD: Added GitHub Actions workflow (typecheck + test)
7. i18n: Added openMenu/closeMenu keys to all 6 locales
8. Observability: Health endpoint now checks SMTP reachability when configured
9. Loading states: Added loading.tsx for root, admin, and news sections
10. Word filter cache: Added 60s TTL auto-refresh instead of manual cache bust
2026-07-04 19:41:04 +02:00
openhands
10523e58ce
Fix remaining security vulnerabilities
...
- H1: Add missing sanitize() to help center content rendering
- H2: Tighten CSP by removing unsafe-inline/unsafe-eval from script-src;
move theme init to external JS file with meta tag for defaultDark
- M1: Add SSRF protection for radio API URLs (block private IPs)
- M2: Add rate limiting to SSO ticket endpoint (5 req/30s per user)
- M4: Document locale validation safety in i18n dynamic import
- L1: Truncate stacktraces in admin commandocentrum to first 20 lines
2026-07-04 19:10:43 +02:00
openhands
5628e7d6b7
Security hardening: 12 improvements across the stack
...
1. env.ts: APP_KEY placeholder detection with validation
2. schema.prisma: password column widened to varchar(255) for argon2id
3. auth.ts: trustHost restricted to development only
4. next.config.ts: added CSP, HSTS, X-Frame-Options, and other security headers
5. api.ts: CORS restricted to APP_URL instead of wildcard
6. register-form.tsx: migrated from REST API fetch to server action (useActionState)
7. twofactor.ts + 2fa page: TOTP recovery codes (8 one-time codes, generated and displayed)
8. register.ts: password min length 8 + complexity requirements (upper, lower, digit)
9. register.ts + help-tickets.ts + radio-shouts.ts: Zod schema validation
10. rate-limit.ts: improved periodic cleanup with aggressive eviction at 10k buckets
11. guard.ts + admin actions: rate-limited admin actions (30 req/min per staff)
12. help-tickets.ts + radio-shouts.ts: content moderation via moderateOrThrow
2026-07-04 18:52:00 +02:00
openhands
a1950e5b65
fix: correct sprite font vertical offset and use avg char width fallback
2026-07-03 18:37:05 +02:00
openhands
77ae4838c0
feat: 100% self-hosted Habbo fonts via sprite sheets + client-side compositor
2026-07-03 18:22:30 +02:00
openhands
8a58bcb252
fix: restore word-level proxy for Habbo fonts, pre-cache all 175 fonts for 'Atom'
2026-07-03 17:58:56 +02:00
openhands
ac75f9c80a
feat: 100% self-hosted Habbo fonts - 6300 char GIFs + local canvas compositor, no habbofont.net dependency
2026-07-03 17:36:34 +02:00
openhands
a5110a62dc
feat: add download-all-fonts ZIP button, proxy fonts locally via /api/font
2026-07-03 17:25:55 +02:00
openhands
d5ec7ba0f8
feat: self-host all Habbo fonts via proxy route /api/font/[style]/[text]
2026-07-03 17:21:05 +02:00
openhands
f3367e9b7b
feat: save logos to media/logo/ subdir, add Logo generator link to admin dropdown
2026-07-03 17:14:44 +02:00
openhands
917437c5ef
fix: use server-side fetch for logo save (bypass CORS), detect file MIME on extension
2026-07-03 17:05:25 +02:00
openhands
073f8e1b6a
fix: detect actual MIME type for save-logo extension instead of hardcoded png
2026-07-03 17:00:08 +02:00
openhands
a84cbfa4f0
feat: add all 191+ Habbo fonts from habbofont.net to logo generator
2026-07-03 16:55:59 +02:00
openhands
af2d5b4943
feat: add save as site logo button to logo generator
2026-07-03 16:45:43 +02:00
openhands
98506fea1e
feat: add Habbo pixel font to logo generator, revert site-header toggle
2026-07-03 16:35:54 +02:00
openhands
4f79d5a0ae
feat: add pixel font for hotel name, toggle text/logo on click in site header
2026-07-03 16:31:17 +02:00
openhands
01e7f84d18
feat: append '- Hotel' to hotel name in title bar, site header and client header
2026-07-03 16:22:42 +02:00
openhands
187af2e147
fix: strip existing sso param from clientUrl, add aria roles to dropdowns, add x-pathname fallback, move .dropdown-menu into @layer components
2026-07-03 16:17:42 +02:00
openhands
7e616ca6b3
refactor: extract duplicate header into shared renderHeader function
2026-07-03 16:05:56 +02:00
openhands
98c9b951c4
fix: remove duplicate site-bg, handle fullscreen promise rejection, unify tooltip language, improve dropdown CSS compat and accessibility
2026-07-03 16:03:09 +02:00
openhands
e5b0649bf1
fix: remove debug console.log from root layout
2026-07-03 15:51:33 +02:00
openhands
7e5813bd97
Fix client loading as atomcms normal
2026-07-03 15:16:47 +02:00
openhands
518c072491
refactor: convert admin pages to Tailwind and improve media uploads; fix TypeScript error in commandocentrum
2026-07-02 17:26:16 +02:00
openhands
72ef74fc87
refactor: enhance admin panel styling with better card patterns
...
- Dashboard: use admin-card for sections, refine progress bars and action badges
- Applications: enhanced card styling with p-3 and better text hierarchy
- Emulator: convert remaining 'card' classes to 'admin-card'
- All changes eliminate inline styles and use consistent Tailwind patterns
Co-authored-by: openhands <[email protected] >
2026-07-02 16:27:06 +02:00
openhands
928544100b
Convert admin pages to new Tailwind design pattern
...
- Replace 'card' class with 'admin-card' (gradient cards, dark mode support)
- Replace 'muted' class with consistent Tailwind muted states
- Standardize page headers with gradient backgrounds and Lucide icons
- Convert all inline styles to Tailwind classes
- Add admin-page CSS helpers (admin-card, admin-filter-bar, admin-section-title)
- Apply pattern to all 42 admin pages (was only 6 before)
- Zero TypeScript errors, production builds successfully
Co-authored-by: openhands <[email protected] >
2026-07-02 16:05:35 +02:00
remco
b621ec79a3
refactor: improve admin panel styling with new CSS helpers and page layout patterns
...
- Add .admin-card, .admin-filter-bar, .admin-stat-row, .admin-stat-chip, .admin-section-title, .admin-info-grid, .admin-empty CSS helpers
- Improve admin table styling (uppercase headers, better spacing, border-separate)
- Add dark mode support for admin tables and cards
- Update housekeeping and settings pages to use new layout components
- Clean up inline styles in housekeeping and settings pages
2026-07-02 15:38:17 +02:00
remco
1ea953fd65
fix: housekeeping page onClick in server component replaced with Link
2026-07-02 15:36:05 +02:00
remco
cf287dbc8b
feat: redesign admin panel with Lucide icons and modern styling
...
- Add lucide-react for SVG icons throughout the admin
- Redesign sidebar with gradient background, icons per nav item, and sticky layout
- Redesign topbar with cleaner user info display
- Redesign dashboard with icon-backed stat cards, gradient progress bars, activity feed
- Update AdminNavLink with icon support and new active state styling
- Improve table styling in admin-page CSS (rounded corners, hover, spacing)
- Clean up unused admin CSS
2026-07-02 15:33:23 +02:00
remco
bd299be55d
refactor: convert admin panel to Tailwind CSS
...
- Convert admin layout, sidebar, and navigation to Tailwind classes
- Convert dashboard components (StatusCard, DiagnosticRow, etc.) to Tailwind
- Convert all ~48 admin page files from admin CSS classes to Tailwind
- Remove unused admin CSS from globals.css (973 → 712 lines)
- Convert developers page badges to Tailwind
- Remove <style jsx> block from OnlineUsersWidget
2026-07-02 15:23:07 +02:00
remco
64f50b2dde
fix: resolve auth security issues - 2FA require TOTP on disable, rate limiting, timing-safe login, token expiry check
2026-07-02 14:54:25 +02:00
remco
4a06b30263
feat: complete admin error handling improvements - add error display to articles pages
...
- Add error display to articles pages (overview, edit, new)
- Improve createArticle action to handle database errors gracefully
- Redirect with error query params for user feedback on failure
- Completes error handling improvements across admin pages
- Enhances error reporting for better user experience
2026-07-01 21:32:59 +02:00
remco
0323c3fcaa
fix: improve error handling in admin pages to show user-friendly error messages
...
- Add error display to help questions new/edit pages
- Improve error visibility in admin-badges, admin-applications, admin-logs, admin-users pages
- Update createHelpQuestion action to properly handle and display unique name collisions and database errors
- Add user-friendly error messages to admin error handling
- Enhances admin page error reporting for better user experience
2026-07-01 21:25:30 +02:00
remco
2efd03de0f
fix: complete user admin actions - form-based inline actions and API endpoint for bulk operations
2026-07-01 19:05:18 +02:00
remco
c3de7cb576
style: complete housekeeping improvements - online users widget, sidebar cleanup
2026-07-01 18:57:10 +02:00
remco
dca77a891b
feat: enhance housekeeping page with search, import mode and inline form editing
2026-07-01 18:45:01 +02:00
remco
393e6ccbee
feat: add Staff Activity Log (audit trail) page
2026-07-01 18:44:32 +02:00
remco
beb36d2dbf
feat: improve users page with inline staff actions and commandocentrum cleanup
2026-07-01 18:38:50 +02:00