openhands
59b63d6e70
Fix real Biome bugs: inner declarations, dup keys, assign-in-expr, implicit any, cookie, a11y svg/keyboard, json
Local Build and Deploy / deploy (push) Successful in 51s
2026-07-14 18:58:40 +02:00
openhands
90d249e50e
Fix typecheck error: use non-null assertion after expect(pair).toBeDefined()
Local Build and Deploy / deploy (push) Successful in 59s
2026-07-14 16:12:01 +02:00
openhands
026cb55cf3
Fix mobile menu blur and improve admin sidebar text contrast
Local Build and Deploy / deploy (push) Successful in 57s
2026-07-14 15:36:17 +02:00
openhands
2455a4850e
fix: make useServerAction accept void-returning actions and remove dead queryCount
...
Local Build and Deploy / deploy (push) Successful in 53s
- Type run()'s action param as Promise<unknown> and cast result (Biome strips void from unions)
- Remove unused queryCount field increment in DbService (dead code)
- Reformat theme-contrast test pair assertions
2026-07-13 22:25:56 +02:00
openhands
045dc06a1f
fix: resolve type errors and migrate pnpm settings to pnpm-workspace.yaml
...
Local Build and Deploy / deploy (push) Failing after 56s
- Move pnpm.onlyBuiltDependencies/overrides from package.json to pnpm-workspace.yaml (clears pnpm WARN)
- Allow useServerAction run() to accept actions returning void
- Make adminAction/authAction input optional so no-schema actions can be called without args
- Return ActionResult from updateBcPage
- Fix categoryPageMap value type (number | undefined)
- Declare DbService.queryCount field
- Use definite assignment for release in withFurniDataLock
- Narrow pair type in theme-contrast test
2026-07-13 22:10:50 +02:00
openhands
df38dccbf1
style: format code biome
Local Build and Deploy / deploy (push) Failing after 46s
2026-07-13 21:57:41 +02:00
openhands
8efd032cc6
style: format code with prettier agian
Local Build and Deploy / deploy (push) Failing after 49s
2026-07-13 21:41:52 +02:00
openhands
e6d7f2280b
Add named custom theme presets (save/load/rename/delete) in admin theme editor
Local Build and Deploy / deploy (push) Successful in 58s
2026-07-13 20:42:40 +02:00
openhands
8721cfcea4
Make HK sidebar menu text always 100% visible
...
Local Build and Deploy / deploy (push) Successful in 1m8s
- Set muted sidebar text equal to the readable sidebar text so inactive
nav items and section labels are never dimmed
- Active item remains distinguished by its accent background and border
2026-07-13 20:13:35 +02:00
openhands
d2243b5611
Fix HK sidebar menu text readability
...
Local Build and Deploy / deploy (push) Successful in 58s
- Derive sidebar text color from the main admin text against the actual
sidebar background (not canvas/surface), guaranteeing contrast
- Brighten muted sidebar text to 82% of the readable text color so
inactive nav items and section labels stay clearly visible
2026-07-13 20:10:52 +02:00
openhands
a16d9859e8
Add admin HK color customization fields to theme editor
...
Local Build and Deploy / deploy (push) Successful in 58s
- Add 6 new admin color DB keys (admin_canvas, admin_surface, admin_text,
admin_text_muted, admin_border, admin_sidebar_bg) that override the
derived admin palette
- Extract adminPaletteCss() from themePaletteCss() for reuse
- Generate admin CSS variables in both :root and html.dark with overrides
- Persist admin color settings via saveTheme action
- Add Admin panel (HK) section to /admin/theme with color pickers
2026-07-13 19:49:19 +02:00
openhands
4dcf6fdce8
Fix admin sidebar colors: use consistent dark sidebar instead of navbar colors for professional look
Local Build and Deploy / deploy (push) Successful in 1m0s
2026-07-13 19:32:27 +02:00
openhands
debee7300e
Fix admin sidebar contrast: muted text now visually distinct from regular text
Local Build and Deploy / deploy (push) Successful in 59s
2026-07-13 19:21:53 +02:00
openhands
bef458dbf8
Rename executeRaw → executeRawUnsafe to make SQL injection risk explicit
...
Local Build and Deploy / deploy (push) Successful in 1m1s
The method wraps Prisma's which trusts the caller
to use ? placeholders. The Unsafe suffix is a naming convention
that signals 'review caller for parameterization'.
2026-07-13 12:41:11 +02:00
openhands
e2fc7ea1a4
Complete security hardening: zero-migration foundation, edge headers, rate-limit atomics, body limits
...
Local Build and Deploy / deploy (push) Successful in 58s
- Make @/lib/safe-action re-export from foundation layer so all 13+
existing server actions instantly get request tracing, rate limiting,
and structured error handling without any code changes
- Add HSTS, CSP, X-Frame-Options, X-Content-Type-Options to edge proxy
(src/proxy.ts) — ran at Cloudflare/Vercel edge for all non-asset routes
- Fix rate-limit.ts race condition: compute newCount before assignment
to shrink the read-modify-write window; add memory-key prefix to
avoid collisions with Redis keys
- Add request body size limit (10 MB default) to api-handler.ts with
per-route override via maxBodyBytes option
- Remove unused imports and clean up backward-compat types
2026-07-13 12:09:43 +02:00
openhands
f6ad030c5b
Add EpicNext CMS foundation layer and fix critical security gaps
...
Local Build and Deploy / deploy (push) Successful in 1m1s
- Create src/lib/foundation/ (860 LOC, 9 files): typed action wrappers,
DbService with health checks, CSRF validation, safe redirects,
AsyncLocalStorage request tracing, branded types, reusable Zod schemas
- Migrate moderation.ts and user-settings.ts to foundation patterns
- Fix abuse-guard.ts: bound in-memory Maps with LRU eviction (was unbounded)
- Fix access-guard.ts: separate try/catch per check, log degradation
instead of blanket fail-open
- Replace raw redirect() calls with safeRedirect() in guard.ts and
permissions.ts to prevent open-redirect attacks
- Add CSRF validation to api-handler.ts for mutating methods
- Add canonicalizeFormData() utility for FormData input sanitization
2026-07-13 12:03:49 +02:00
openhands
2e4ed76121
style: format code with prettier
Local Build and Deploy / deploy (push) Successful in 49s
2026-07-12 21:07:34 +02:00
remco
e85e4d74ea
revert fb8e77bb68
...
Local Build and Deploy / deploy (push) Successful in 1m11s
revert style: clean up code with prettier and eslint
2026-07-12 21:02:03 +02:00
openhands
fb8e77bb68
style: clean up code with prettier and eslint
2026-07-12 20:31:05 +02:00
Simo
60278b9e71
feat: add admin operations suite
Local Build and Deploy / deploy (push) Successful in 50s
2026-07-12 20:11:28 +02:00
Simo
21a61068fb
test: define admin operations contracts
2026-07-12 20:01:25 +02:00
Simo
c0ffc74f9b
fix: externalize lzma for import build
Local Build and Deploy / deploy (push) Successful in 49s
2026-07-12 19:15:08 +02:00
Simo
3497df9dfd
feat: add asset import services
2026-07-12 19:12:25 +02:00
Simo
4b596226e0
fix: complete acl management
2026-07-12 19:12:24 +02:00
Simo
667ec9af4c
test: define acl and import backend contracts
2026-07-12 19:01:28 +02:00
Simo
84e4123f09
fix: use semantic colors across admin pages
Local Build and Deploy / deploy (push) Successful in 49s
2026-07-12 18:50:45 +02:00
Simo
0fe482009c
fix: isolate shared admin styling
2026-07-12 18:50:44 +02:00
Simo
4ce35e91fb
feat: add semantic admin palette
2026-07-12 18:47:23 +02:00
Simo
d4bcf89449
test: enforce admin theme isolation
2026-07-12 18:46:16 +02:00
Simo
f422bb4a0b
feat: add admin content module actions
2026-07-12 15:27:07 +02:00
Simo
b9525c8e6b
feat: add schema for admin content modules
2026-07-12 15:27:06 +02:00
Simo
41002aa36d
fix: preserve Next.js deploy cache
Local Build and Deploy / deploy (push) Successful in 45s
2026-07-12 15:17:16 +02:00
Simo
f0b4bc1630
fix: enforce semantic contrast across admin
Local Build and Deploy / deploy (push) Successful in 44s
2026-07-12 15:14:15 +02:00
Simo
9cdd0b4000
feat: persist complete multitheme palettes
2026-07-12 14:49:36 +02:00
Simo
3fd2a27719
feat: generate preset-aware dark theme variables
2026-07-12 14:49:36 +02:00
Simo
48c596cf41
feat: add complete light and dark presets
2026-07-12 14:45:11 +02:00
Simo
7d3430aeca
fix: seed production ACL permissions
Local Build and Deploy / deploy (push) Successful in 56s
2026-07-12 14:29:01 +02:00
Simo
cdf180ee3f
fix: isolate proxy session decoding
Local Build and Deploy / deploy (push) Successful in 1m2s
2026-07-12 13:39:25 +02:00
Simo
c4bf6488d0
fix: use canonical Auth.js session in proxy
Remote Build and Deploy / deploy (push) Successful in 43s
2026-07-11 22:55:26 +02:00
Simo
cfa7998dd7
fix: detect deployed Auth.js session cookie
Remote Build and Deploy / deploy (push) Successful in 44s
2026-07-11 22:46:04 +02:00
Simo
02bbcba240
fix: decode production admin session cookie
Remote Build and Deploy / deploy (push) Successful in 47s
2026-07-11 22:42:19 +02:00
Simo
f08e56cf53
fix: authorize super admins by dynamic highest rank
Remote Build and Deploy / deploy (push) Successful in 42s
2026-07-11 22:35:40 +02:00
Simo
b695a33ead
fix: enforce public contrast and audit rank errors
2026-07-11 22:06:45 +02:00
Simo
17264dfc06
fix: protect admin routes and ignore local docs
2026-07-11 21:35:37 +02:00
Simo
8d37ae9ae0
style: normalize restored source endings
Remote Build and Deploy / deploy (push) Has been cancelled
2026-07-11 21:19:54 +02:00
Simo
0cd753c735
fix: restore complete admin feature dependencies
2026-07-11 21:15:54 +02:00
Simo
5b4228261a
Reapply "Add missing admin action files and navigation links"
...
This reverts commit 4d515bc400 .
2026-07-11 20:52:56 +02:00
Simo
96ed768f14
test: add unresolved local import scanner
2026-07-11 20:52:55 +02:00
Simo
4d515bc400
Revert "Add missing admin action files and navigation links"
...
This reverts commit 41be6835bf .
2026-07-11 20:37:56 +02:00
Simo
4a1e1115b3
Harden CMS security and theme contrast
2026-07-11 20:27:20 +02:00