Commit Graph
478 Commits
Author SHA1 Message Date
SimoandCursor cd4233b430 fix(i18n): fill missing Dutch shop, transactions, and voucher admin keys
Align nl.json with en/it for admin shop orders columns and related payment hub labels.

Co-authored-by: Cursor <[email protected]>
2026-07-18 21:11:50 +02:00
Simo b7fd19b6d9 Merge pull request 'feat(catalog): Visual Manager BC + honest canEdit' (#2) from feat/visual-manager-bc-canedit into main
Local Build and Deploy / deploy (push) Successful in 1m27s
Reviewed-on: #2
2026-07-18 21:04:39 +02:00
SimoandCursor 7d50b72ade feat(catalog): Visual Manager for Builder Club with honest canEdit
Mount BC Visual Manager, thread catalogType through tree/editor actions, and stop hardcoding canEdit=true in items/translate tabs.

Co-authored-by: Cursor <[email protected]>
2026-07-18 21:03:07 +02:00
openhands 8ccade73cc chore: verified clean state, type-safety refactor and deploy fix in place
Local Build and Deploy / deploy (push) Successful in 1m27s
2026-07-18 20:53:01 +02:00
SimoandCursor 80c6559143 fix(deploy): stop hanging on per-file sticky-bit scan
Local Build and Deploy / deploy (push) Successful in 1m48s
Only clear paths that already have skip-worktree/assume-unchanged; keep nuclear src replace and content verify.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:34:34 +02:00
openhands 3eaffe658d refactor: remove explicit any across admin forms and catalog actions
Local Build and Deploy / deploy (push) Canceled after 40s
- Type resolveAsChild generically over Base UI render-prop type
- Type catalog/rooms/catalog-items Prisma updates with Prisma.*UpdateInput
- Type EventForm/PollForm with explicit form-value interfaces
- Type EventPrizesManager/PollQuestionsManager with validator input types
- All typecheck, lint, and 312 tests pass
2026-07-18 20:31:18 +02:00
openhands 907a4399d0 refactor: type PollQuestionsManager form with PollQuestionInput 2026-07-18 20:31:18 +02:00
openhands 0d027dba99 refactor: type EventPrizesManager form with EventPrizeInput 2026-07-18 20:31:18 +02:00
openhands 41f5269b4e refactor: type PollForm with explicit PollFormValues 2026-07-18 20:31:18 +02:00
openhands 4991008159 refactor: type EventForm with explicit EventFormValues 2026-07-18 20:31:18 +02:00
SimoandCursor d0f9b3ef95 fix(deploy): nuclear-replace src to defeat skip-worktree ghosts
Local Build and Deploy / deploy (push) Canceled after 9m26s
Host built a different event-form than HEAD while git looked clean; delete src, restore from git objects, and hash-verify every tracked blob.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:30:21 +02:00
SimoandCursor 968f6ff7db fix(deploy): unstick nitro Json typecheck and wipe poisoned .next cache
Local Build and Deploy / deploy (push) Failing after 1m21s
Host next build still saw Json on nitro while tsc passed; use any helpers, verify blob hash, and delete .next entirely before build.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:14:50 +02:00
SimoandCursor 1abbf3fde7 fix(deploy): sync rooms Prisma types and harden checkout against stale host files
Local Build and Deploy / deploy (push) Failing after 1m19s
next build failed on host-local rooms.ts using Prisma without import while tsc incremental passed; force non-incremental typecheck and verify src matches HEAD.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:06:34 +02:00
SimoandCursor c053b8de87 fix(deploy): reclaim www-data ownership before git reset
Local Build and Deploy / deploy (push) Failing after 1m16s
Stale host sources survived reset when files were owned by www-data, leaving an old nitro editor with a removed Json type that failed typecheck.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:01:25 +02:00
SimoandCursor 1f552c2822 Polish public error and 404 screens with brand atmosphere.
Local Build and Deploy / deploy (push) Successful in 1m31s
Shared ErrorScreen composition, i18n for en/nl/it, Sentry on route errors, and a self-contained global-error fallback that matches the hotel gold theme.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:00:04 +02:00
SimoandCursor b22725d3a9 fix: type-safe nitro editor helpers and stabilize deploy build
Local Build and Deploy / deploy (push) Failing after 29s
Rewrite getNested/updateNested without fragile any/Json inference, clear stale .next types before build, and skip env refine during compile.

Co-authored-by: Cursor <[email protected]>
2026-07-18 19:57:33 +02:00
SimoandCursor 1273f9aa46 fix: typecheck event prizes form for deploy gate
Local Build and Deploy / deploy (push) Failing after 1m25s
Narrow prizeType to the Select union and keep badgeCode as a string so pnpm typecheck passes on the server.

Co-authored-by: Cursor <[email protected]>
2026-07-18 19:50:39 +02:00
SimoandCursor 557138e40b fix: admin panel resiste a fallimento cookie CSRF
Local Build and Deploy / deploy (push) Failing after 34s
Il layout admin non deve crashare se cookies().set() fallisce (__Host-/Secure dietro proxy). Fallback su csrf-token, meta solo con token valido.

Co-authored-by: Cursor <[email protected]>
2026-07-18 19:48:30 +02:00
SimoandCursor 2de3696993 Enforce admin CSRF, harden catalog translate, use CMS hotel name for PayPal.
Local Build and Deploy / deploy (push) Successful in 1m38s
Mutating withAdmin routes now require a double-submit CSRF token; translate is capped at 500 items with audit logging; PayPal descriptions prefer siteSettings hotel_name.

Co-authored-by: Cursor <[email protected]>
2026-07-18 19:38:42 +02:00
SimoandCursor 6b884ad25a Harden deploy gates, prod AUTH_SECRET, and Sentry error reporting.
Local Build and Deploy / deploy (push) Successful in 1m42s
Align onlyBuiltDependencies with the workspace, fail fast without AUTH_SECRET in production, and delete catalog_items via VARCHAR-safe SQL so page deletes do not leave orphans.

Co-authored-by: Cursor <[email protected]>
2026-07-18 19:32:15 +02:00
openhands b9c6001f08 refactor: centralize duplicated formatDate helper
Local Build and Deploy / deploy (push) Successful in 1m7s
21 files defined their own local formatDate (with three different output
formats: date, datetime, datetime-seconds, and varying null fallbacks).
Replace them with a single shared helper at src/lib/format-date.ts that
takes a variant + optional fallback, preserving the exact previous output
per call site (verified identical string results).

Removes ~21 copies of the same logic. photos.tsx and media-grid.tsx keep
their epoch-ms based formatters since those are a different input shape.

Verified: tsc --noEmit clean, full test suite green (301/301).
2026-07-18 19:17:17 +02:00
openhands 3c9c1311ec chore: remove dead code flagged by knip
Local Build and Deploy / deploy (push) Successful in 1m7s
Remove 19 unused source files (no importers anywhere in src/):
- src/actions/admin-permissions.ts, admin-radio.ts, admin-user-edit.ts,
  admin-users.ts (functionality lives in @/actions/users and
  @/actions/permissions)
- src/components/admin/confirm-action.tsx, page-header.tsx
- src/components/motion-elements.tsx
- src/lib/format-date.ts
- src/lib/catalog-categories/* (incl. re-export barrel)
- src/lib/foundation/{index,database,middleware,validation}.ts (errors/action
  kept, still imported directly)
- src/lib/services/imager/{avatar-renderer,memory-cache}.ts
- src/lib/services/nitro-assets.ts

Update admin-operations-contract test to drop the two removed action-file
gates (their permission coverage already exists in users.ts/permissions.ts).

Add knip.json for repeatable dead-code audits.

Verified: tsc --noEmit clean, next build succeeds, full test suite green
(301/301).
2026-07-18 19:08:17 +02:00
openhands 60eb45be73 fix(admin): use theme-aware destructive foreground instead of hardcoded text-white
Local Build and Deploy / deploy (push) Successful in 1m14s
The danger confirm button used a hardcoded text-white class which failed the
admin theme source audit and could render unreadable against custom admin
themes. Switch to the semantic text-destructive-foreground token.

Also add media-grid.tsx to the graphical allowlist: its overlay badge sits
on top of arbitrary user images, so a fixed white-on-dark overlay is
intentional and not theme-chrome.

Restores the full test suite to green (303/303).
2026-07-18 18:57:14 +02:00
remco 7dc15c1f59 revert 8292cc8ffb
Local Build and Deploy / deploy (push) Successful in 1m22s
revert fix(infra): serve full TLS chain for epicnabbo.nl to resolve Cloudflare 525

Traefik's ACME resolver stored the epicnabbo.nl leaf certificate without
the Let's Encrypt intermediate. With Cloudflare in Full (strict) mode the
origin TLS handshake failed (HTTP 525), breaking every asset and the whole
site layout (JS/CSS chunks, Nitro client, toolbar).

Configure the epicnabbo router to use a file-based certificate that
includes the full chain (leaf + LE YR2 intermediate), referenced from
dynamic/epicnabbo-tls.yml. Add a regeneration script and README.
2026-07-18 18:53:03 +02:00
remco 871e6951eb revert 8292cc8ffb
Local Build and Deploy / deploy (push) Successful in 1m17s
revert fix(infra): serve full TLS chain for epicnabbo.nl to resolve Cloudflare 525

Traefik's ACME resolver stored the epicnabbo.nl leaf certificate without
the Let's Encrypt intermediate. With Cloudflare in Full (strict) mode the
origin TLS handshake failed (HTTP 525), breaking every asset and the whole
site layout (JS/CSS chunks, Nitro client, toolbar).

Configure the epicnabbo router to use a file-based certificate that
includes the full chain (leaf + LE YR2 intermediate), referenced from
dynamic/epicnabbo-tls.yml. Add a regeneration script and README.
2026-07-18 18:49:16 +02:00
remco 1e2a348e72 revert 8292cc8ffb
Local Build and Deploy / deploy (push) Successful in 1m21s
revert fix(infra): serve full TLS chain for epicnabbo.nl to resolve Cloudflare 525

Traefik's ACME resolver stored the epicnabbo.nl leaf certificate without
the Let's Encrypt intermediate. With Cloudflare in Full (strict) mode the
origin TLS handshake failed (HTTP 525), breaking every asset and the whole
site layout (JS/CSS chunks, Nitro client, toolbar).

Configure the epicnabbo router to use a file-based certificate that
includes the full chain (leaf + LE YR2 intermediate), referenced from
dynamic/epicnabbo-tls.yml. Add a regeneration script and README.
2026-07-18 18:48:59 +02:00
remco 96f0e84818 revert 8292cc8ffb
Local Build and Deploy / deploy (push) Successful in 1m18s
revert fix(infra): serve full TLS chain for epicnabbo.nl to resolve Cloudflare 525

Traefik's ACME resolver stored the epicnabbo.nl leaf certificate without
the Let's Encrypt intermediate. With Cloudflare in Full (strict) mode the
origin TLS handshake failed (HTTP 525), breaking every asset and the whole
site layout (JS/CSS chunks, Nitro client, toolbar).

Configure the epicnabbo router to use a file-based certificate that
includes the full chain (leaf + LE YR2 intermediate), referenced from
dynamic/epicnabbo-tls.yml. Add a regeneration script and README.
2026-07-18 18:48:34 +02:00
openhands 8292cc8ffb fix(infra): serve full TLS chain for epicnabbo.nl to resolve Cloudflare 525
Local Build and Deploy / deploy (push) Successful in 1m2s
Traefik's ACME resolver stored the epicnabbo.nl leaf certificate without
the Let's Encrypt intermediate. With Cloudflare in Full (strict) mode the
origin TLS handshake failed (HTTP 525), breaking every asset and the whole
site layout (JS/CSS chunks, Nitro client, toolbar).

Configure the epicnabbo router to use a file-based certificate that
includes the full chain (leaf + LE YR2 intermediate), referenced from
dynamic/epicnabbo-tls.yml. Add a regeneration script and README.
2026-07-18 18:37:56 +02:00
openhands 243f8007d9 Fix articles list crash by moving interactive card to client component
Local Build and Deploy / deploy (push) Successful in 1m4s
Extract the article card (thumbnail onError fallback, delete confirmation)
into a Client Component so the admin articles list server page no longer
passes event handlers to server-rendered elements.
2026-07-18 17:45:15 +02:00
openhands 6215074331 Polish admin articles: card grid, thumbnails, author, slug field
Local Build and Deploy / deploy (push) Successful in 1m14s
Replace the plain articles table with a responsive card grid showing
thumbnails, title, date and author. Add a slug field to the article form
with live auto-suggestion, i18n-driven labels, a larger image preview and
delete confirmation. Persist a user-provided slug (falls back to an
auto-generated one) on create and update.
2026-07-18 17:38:01 +02:00
openhands a07d438987 Improve media manager UI: search, delete, drag-and-drop, file meta
Local Build and Deploy / deploy (push) Successful in 1m21s
Add a richer media manager with filename search, per-file delete with
confirmation, drag-and-drop uploads, copy-URL feedback, file size/type/date
metadata, and server-side upload validation that returns errors to the UI.
Extend the /api/media listing with size and uploaded timestamps.
2026-07-18 17:29:01 +02:00
openhands 6a20ccda5c Fix media route cache-control to avoid Cloudflare stale caching
Local Build and Deploy / deploy (push) Successful in 1m6s
2026-07-18 17:21:00 +02:00
openhands 1bbbf6e5a4 Persist media uploads outside public/ to survive rebuilds and redeploys
Local Build and Deploy / deploy (push) Successful in 1m9s
Move media storage from public/assets/images/media to storage/media
(outside Git and public/), so uploaded images, favicons and logos are
preserved across rebuilds and git clean. Add a shared media-storage helper,
update the upload/serve actions and API routes, and gitignore storage/.
2026-07-18 17:04:48 +02:00
openhands 0d82f1325e Fix DB connect_timeout warning and remove deprecated Sentry disableLogger
Local Build and Deploy / deploy (push) Successful in 1m10s
2026-07-18 16:54:20 +02:00
SimoandCursor 09f1bc2bd6 Add production observability: Sentry, pino, and sharp badge encoding.
Local Build and Deploy / deploy (push) Successful in 1m9s
Sentry is opt-in via DSN env vars; logger uses structured pino JSON in prod; badge uploads are normalized to GIF with sharp.

Co-authored-by: Cursor <[email protected]>
2026-07-17 23:09:57 +02:00
SimoandCursor 6c81af69ea Remove half-installed sentry/pino/sharp from the lockfile.
Local Build and Deploy / deploy (push) Successful in 1m2s
Keeps frozen-lockfile installs aligned with package.json after an interrupted dependency add.

Co-authored-by: Cursor <[email protected]>
2026-07-17 23:03:36 +02:00
SimoandCursor 6a830e7c5e Fix pnpm frozen-lockfile mismatch for postcss.
Local Build and Deploy / deploy (push) Failing after 16s
Align workspace override and lockfile specifier with package.json ^8.5.19.

Co-authored-by: Cursor <[email protected]>
2026-07-17 23:01:31 +02:00
SimoandCursor ef2c3324b4 Prune unused deps, bump safe minors, add server-only guards.
Local Build and Deploy / deploy (push) Failing after 15s
Remove unused translate/jpeg types packages; refresh patch updates; mark Redis/site-settings/gamedata hotel as server-only with a Vitest stub.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:53:56 +02:00
SimoandCursor a798999440 Refresh Suggest hotel label from live CMS setting.
Local Build and Deploy / deploy (push) Successful in 56s
Avoid stale SSR/Redis cache keeping Suggest IT after habbo_gamedata_hotel changes.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:36:10 +02:00
SimoandCursor 785c1b6976 Fix client bundle pulling Redis/Prisma via habbo gamedata hotel.
Local Build and Deploy / deploy (push) Successful in 54s
Keep hotel list helpers client-safe; load CMS setting only from a server module.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:30:46 +02:00
SimoandCursor d1baaf798a Add multi-hotel Habbo gamedata locale in CMS settings.
Local Build and Deploy / deploy (push) Failing after 33s
Furni name suggestions, import enrichment, and badge texts now follow habbo_gamedata_hotel instead of hardcoded habbo.it.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:28:18 +02:00
SimoandCursor 7bc0845932 Fix catalog items missing due to page_id VARCHAR mismatch.
Local Build and Deploy / deploy (push) Successful in 56s
Use raw SQL for counts/loads/creates/moves so Habbo DBs with VARCHAR page_id and no AUTO_INCREMENT still show and persist furni.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:21:49 +02:00
SimoandCursor 33a8a19820 Fix Visual Manager opacity and load categories like CatalogTree.
Local Build and Deploy / deploy (push) Successful in 55s
Use an opaque admin-canvas portal and lazy parentId fetches instead of mode=full, which fails on large catalogs. Search no longer loads the entire tree.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:09:01 +02:00
SimoandCursor 1d8efefce4 Fix Visual Manager empty categories: seed roots, harden tree API.
Local Build and Deploy / deploy (push) Successful in 56s
Seed root tabs from SSR, load the full tree without CLEAR_TREE races, coerce parent ids, and tolerate catalog_items page_id type mismatches so category pages actually appear.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:02:53 +02:00
openhands 385cefd0fa fix: move dynamic import with ssr:false to client component wrapper
Local Build and Deploy / deploy (push) Successful in 52s
2026-07-17 21:36:47 +02:00
SimoandCursor 8083012445 Remove unused tooltip imports from catalog root tabs.
Local Build and Deploy / deploy (push) Failing after 41s
Co-authored-by: Cursor <[email protected]>
2026-07-17 21:26:48 +02:00
SimoandCursor b668ab3547 Rebuild Visual Manager as portal overlay matching habbo-next UX.
Local Build and Deploy / deploy (push) Failing after 44s
Base UI Dialog broke the Radix-era full-viewport manager. Use a body portal shell like habbo-next behavior, without DialogTitle/Popup, so tree + editor mount and nested pickers stay usable.

Co-authored-by: Cursor <[email protected]>
2026-07-17 21:26:35 +02:00
Simo e7a6587b7f Delete directory 'docs/superpowers'
Local Build and Deploy / deploy (push) Successful in 1m11s
2026-07-17 21:26:05 +02:00
SimoandCursor f6871807c9 Fix Visual Manager for Base UI: layout, tree load, no nested dialogs.
Local Build and Deploy / deploy (push) Successful in 1m9s
Move trigger outside Dialog.Root, use portal confirms and inline create forms, and load the catalog tree atomically so the manager matches the designed full-viewport UX.

Co-authored-by: Cursor <[email protected]>
2026-07-17 21:21:40 +02:00
SimoandCursor 2ff5b47104 Harden catalog writes: bulk import batch + field allowlists.
Local Build and Deploy / deploy (push) Successful in 1m16s
Bulk import resolves names from items_base and refreshes RCON once. Page/item updates only accept an allowlisted field set.

Co-authored-by: Cursor <[email protected]>
2026-07-17 21:14:35 +02:00