Commit Graph
40 Commits
Author SHA1 Message Date
openhands e867b675fc fix: replace jsonc with jsonc-parser and cleanup build config 2026-08-11 16:50:10 +02:00
openhands 79b82e0a31 fix: badge import uses configured gamedata root for ExternalTexts.json
CI / check (push) Successful in 30s
CI / release (push) Skipped
CI / deploy (push) Successful in 44s
- import-badge.ts, badges route, and badges edit route now resolve
  ExternalTexts.json via getGamedataRoot() instead of the hardcoded
  public/nitro-assets/gamedata/ path
- writeBadgeToExternalTexts creates the file (and parent dirs) when
  missing, so fresh deployments no longer fail with ENOENT
- upload-import SQL maker now classifies furni via classifyFurni and
  generates correct category sub-pages (imp_<catKey>) instead of
  hardcoded imp_other
2026-08-05 15:34:40 +02:00
openhands 423a33200e chore: improve tooling, linting, testing, and CI
CI / check (push) Failing after 14s
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m38s
- Add LICENSE file (CC BY-NC-SA 4.0)
- Add .nvmrc pinning Node 22
- Add Renovate config with daily schedule and Gitea Actions workflow
- Reduce ESLint max-warnings from 1000 to 50
- Re-enable Biome a11y/security recommended rules
- Fix Biome lint issues (a11y, hook deps, SVG labels, checkbox semantics)
- Improve CI: run on pushes to feat/fix branches, add pnpm audit
- Add Vitest coverage with v8 provider and thresholds
- Add E2E tests (auth, admin, navigation specs)
- Add admin-maintenance server action test
- Install @vitest/coverage-v8
- Ignore coverage/ directory
2026-07-27 17:03:09 +02:00
openhands c432d4e95d fix: service worker cache busting — unregister old sw on load, bump cache version, stop caching HTML
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m53s
- Bump sw.js cache from v2 to v3
- Unregister all old service workers on page load
- Stop caching HTML/navigation (caused stale CSS refs after rebuild)
2026-07-24 13:50:45 +02:00
openhands 24c4279a7e Update duckets icon from hubbly.pw
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 2m0s
2026-07-23 16:46:20 +02:00
openhands db46453912 Use next_header.jpg as index hero background
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m55s
2026-07-22 20:27:23 +02:00
openhands 5e8a13a84f fix: resolve all biomaly lint errors and warnings across CMS
Deploy / release (push) Successful in 4s
Deploy / deploy (push) Skipped
- Fix CSS parser config (tailwindDirectives enabled)
- Fix noDangerouslySetInnerHtml via SanitizedHtml component
- Fix useExhaustiveDependencies in catalog-manager-dialog
- Fix noArrayIndexKey across 26 files (stable keys)
- Fix SVG a11y (titles, roles, aria-labels)
- Fix label/input associations (htmlFor/id pairs)
- Fix static element interactions (role + keyboard support)
- Fix noImgElement, noDescendingSpecificity (disabled - external Habbo URLs)
- Fix noNonNullAssertion, useTemplate, unused vars/imports
- Add SanitizedHtml shared component
- Migrate biome.json to 2.5.4 schema
2026-07-20 17:41:53 +02:00
openhands c8ccbe1f42 perf: add Prisma query caching, ISR for news pages, and aggressive SW caching
- Introduce redis-backed Prisma query cache (prisma-cache.ts) with per-model TTL
- Replace force-dynamic with revalidate=60 + generateStaticParams on news/[slug]
- Wrap article query with Redis cache (60s TTL)
- Upgrade service worker to v2 with dedicated API cache and stale-while-revalidate
  for static assets
2026-07-20 14:54:55 +02:00
openhands 1bbbf6e5a4 Persist media uploads outside public/ to survive rebuilds and redeploys
Local Build and Deploy / deploy (push) Successful in 1m9s
Move media storage from public/assets/images/media to storage/media
(outside Git and public/), so uploaded images, favicons and logos are
preserved across rebuilds and git clean. Add a shared media-storage helper,
update the upload/serve actions and API routes, and gitignore storage/.
2026-07-18 17:04:48 +02:00
openhands 70f5e37373 refactor(housekeeping): split client, add loading states, URL persistence, fix dead code
Local Build and Deploy / deploy (push) Failing after 48s
- Split ManageClient into ManageSection, PresetsSection, TestSection,
  ImportSection, ExportSection - each tab only renders what it needs
- Add loading/disabled states to preset, import, export, clear buttons
- Persist search and group filter via URL searchParams (survives refresh)
- Remove dead getAuditHistory export from actions
- Fix testRankPermission - remove unnecessary revalidatePath with JSON result
- Clean up unused errors/count variables in bulkImportPermissions
- Add 'loading' translation key to housekeeping section (en/nl)
2026-07-17 19:28:19 +02:00
SimoandCursor d7278c77f9 Fix automatic readable text contrast for public and admin themes.
Local Build and Deploy / deploy (push) Successful in 55s
Derive admin/public text colors from WCAG contrast, unify ThemeVars CSS emission, and keep navbar overrides in sync with readable vars.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:41:34 +02:00
SimoandCursor bae543baf6 Fix admin regressions from Biome refactor: theme init, mobile nav, i18n.
Local Build and Deploy / deploy (push) Successful in 54s
Restore valid browser JS in theme-init, close mobile sidebar on navigation, and split autoDjForm title/trackTitle across locales.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:02:25 +02:00
openhands 59b63d6e70 Fix real Biome bugs: inner declarations, dup keys, assign-in-expr, implicit any, cookie, a11y svg/keyboard, json
Local Build and Deploy / deploy (push) Successful in 51s
2026-07-14 18:58:40 +02:00
openhands df38dccbf1 style: format code biome
Local Build and Deploy / deploy (push) Failing after 46s
2026-07-13 21:57:41 +02:00
openhands efe467d352 Add 12 more languages: ro, hu, cs, sk, da, no, el, bg, hr, sr, uk, ru
Local Build and Deploy / deploy (push) Successful in 1m0s
2026-07-12 21:52:22 +02:00
Simo 5b4228261a Reapply "Add missing admin action files and navigation links"
This reverts commit 4d515bc400.
2026-07-11 20:52:56 +02:00
Simo 4d515bc400 Revert "Add missing admin action files and navigation links"
This reverts commit 41be6835bf.
2026-07-11 20:37:56 +02:00
openhands 41be6835bf Add missing admin action files and navigation links
- Add 11 missing server action files: badges, bulk-users, catalog, catalog-bc, catalog-items, import-badges, import-furni, multi-account-detect, permissions, rooms, soundtracks
- Add missing admin navigation links: tickets, sounds, translations, import, radio sub-pages
- Add translation keys for all new navigation items
2026-07-11 12:01:05 +02:00
openhands c5db7f5156 fix: production hardening — migration script, security fixes, structured logging, API docs, component splitting
- Create apply-migrations.ts and jobs-worker.ts scripts (package.json references)
- Convert badge leaderboard from $queryRawUnsafe to $queryRaw with Prisma.sql templates
- Fix OAuth email binding: add oauth_require_link site setting, skip 2FA-protected accounts
- Add per-user 2FA rate limiting (5/30s) to prevent TOTP brute-force
- Add structured JSON logger with levels (debug/info/warn/error)
- Split 341-line HomePage into GuestView + UserView components
- Add OpenAPI v3.1 spec at /api/openapi.json
- Add LOG_LEVEL env var, regenerate Prisma client
- Add mysql2 dependency for migration scripts
- All 58 tests pass, typecheck clean
2026-07-08 13:06:02 +02:00
openhands 7412bd2dda Remove outfit selection from register form and fix terms checkbox not toggling 2026-07-07 18:53:13 +02:00
openhands 9a7b40eae6 Add favicon assets, update Nitro v3 script, and update logs 2026-07-07 16:04:25 +02:00
openhands 4a80742e1c Add default SVG favicon fallback 2026-07-05 23:25:36 +02:00
openhands 10523e58ce Fix remaining security vulnerabilities
- H1: Add missing sanitize() to help center content rendering
- H2: Tighten CSP by removing unsafe-inline/unsafe-eval from script-src;
  move theme init to external JS file with meta tag for defaultDark
- M1: Add SSRF protection for radio API URLs (block private IPs)
- M2: Add rate limiting to SSO ticket endpoint (5 req/30s per user)
- M4: Document locale validation safety in i18n dynamic import
- L1: Truncate stacktraces in admin commandocentrum to first 20 lines
2026-07-04 19:10:43 +02:00
openhands 5628e7d6b7 Security hardening: 12 improvements across the stack
1. env.ts: APP_KEY placeholder detection with validation
2. schema.prisma: password column widened to varchar(255) for argon2id
3. auth.ts: trustHost restricted to development only
4. next.config.ts: added CSP, HSTS, X-Frame-Options, and other security headers
5. api.ts: CORS restricted to APP_URL instead of wildcard
6. register-form.tsx: migrated from REST API fetch to server action (useActionState)
7. twofactor.ts + 2fa page: TOTP recovery codes (8 one-time codes, generated and displayed)
8. register.ts: password min length 8 + complexity requirements (upper, lower, digit)
9. register.ts + help-tickets.ts + radio-shouts.ts: Zod schema validation
10. rate-limit.ts: improved periodic cleanup with aggressive eviction at 10k buckets
11. guard.ts + admin actions: rate-limited admin actions (30 req/min per staff)
12. help-tickets.ts + radio-shouts.ts: content moderation via moderateOrThrow
2026-07-04 18:52:00 +02:00
openhands a1950e5b65 fix: correct sprite font vertical offset and use avg char width fallback 2026-07-03 18:37:05 +02:00
openhands 77ae4838c0 feat: 100% self-hosted Habbo fonts via sprite sheets + client-side compositor 2026-07-03 18:22:30 +02:00
openhands 8a58bcb252 fix: restore word-level proxy for Habbo fonts, pre-cache all 175 fonts for 'Atom' 2026-07-03 17:58:56 +02:00
openhands ac75f9c80a feat: 100% self-hosted Habbo fonts - 6300 char GIFs + local canvas compositor, no habbofont.net dependency 2026-07-03 17:36:34 +02:00
openhands 00b1d0a267 feat: pre-cache all 175 font GIFs for default text 'Atom' 2026-07-03 17:28:16 +02:00
openhands a5110a62dc feat: add download-all-fonts ZIP button, proxy fonts locally via /api/font 2026-07-03 17:25:55 +02:00
openhands d5ec7ba0f8 feat: self-host all Habbo fonts via proxy route /api/font/[style]/[text] 2026-07-03 17:21:05 +02:00
openhands f3367e9b7b feat: save logos to media/logo/ subdir, add Logo generator link to admin dropdown 2026-07-03 17:14:44 +02:00
openhands 6df4fe2ddd chore: remove stale test logos 2026-07-03 17:00:41 +02:00
openhands a84cbfa4f0 feat: add all 191+ Habbo fonts from habbofont.net to logo generator 2026-07-03 16:55:59 +02:00
openhands 1b4930af0b chore: add uploaded media files 2026-07-02 17:28:24 +02:00
openhands 518c072491 refactor: convert admin pages to Tailwind and improve media uploads; fix TypeScript error in commandocentrum 2026-07-02 17:26:16 +02:00
remco f2d13cf644 fix: serve uploaded images via /api/media/[name] to avoid Next.js static 404 2026-07-01 17:10:43 +02:00
remco 1de72863db latest changes 2026-07-01 15:06:52 +02:00
Simo 54ec99de6d 101%: app-level DDoS guard, PWA, /api/health, API docs, worker JAR backup
Beyond parity — the web-feasible versions of the "host-only" items plus
extras AtomCMS doesn't have:
- App-level abuse/DDoS guard (src/lib/services/abuse-guard.ts): counts
  requests per IP and auto-adds flooders to website_ip_blacklist (enforced
  by the access guard) + fires ddosDetected(). OFF by default, tunable via
  settings. The iptables layer stays host-only; this is the real app-tier
  mitigation. Access guard now also enforces the IP blacklist (cached).
- PWA: a themeable web manifest (src/app/manifest.ts) + a service worker
  (public/sw.js, cache-first assets / network-first pages) registered after
  hydration — the hotel is now installable.
- /api/health: DB + emulator(RCON) + runtime status probe.
- /developers: a public API documentation page covering every REST endpoint
  with its method, path and auth requirement.
- jobs-worker: daily emulator JAR backup (runs host-side in the worker, like
  AtomCMS's backup command) — copies + prunes; no-ops unless EMULATOR_JAR_PATH
  + EMULATOR_BACKUP_DIR are set.

Verified live (prod, amx_test): /api/health ok, manifest + sw served, docs
page renders, normal pages unaffected by the guard. tsc 0, vitest 49/49,
next build 0.
2026-06-29 18:39:23 +02:00
Simo e19debb795 Port AtomCMS atom theme faithfully (Tailwind v4 + real CSS/assets + shell)
Make the template match the atom theme, not just approximate it:
- Add Tailwind v4 (+forms/typography plugins, postcss) and port the real atom
  CSS (global.css + atom app.css) into globals.css: nav-item underline, currency
  + navigation icon classes, site-bg, card-base/hover-lift, text utils — asset
  paths adapted to /assets.
- Copy the real theme assets (backgrounds, icons/currency/navigation, profile,
  leaderboards) into public/assets.
- Rebuild the shell 1:1 from the atom Blade: TopHeader (currency pills +
  user/admin dropdowns, auth-only), SiteHeader (header image + black/50 overlay,
  logo+online+Nitro client / guest Login+Create-account CTA), Navigation (white
  bar, nav-item + Community/Assistance dropdowns), Footer. ThemeVars injects the
  DB-driven CSS custom properties into :root like app.blade.php. Layout uses the
  atom body/site-bg + grid-cols-12 max-w-7xl content wrapper.

Verified: tsc 0, next build exit 0; curl confirms the atom markup, compiled CSS
references the assets, and background-light.jpg + currency/navigation icons all
serve 200.
2026-06-28 14:50:09 +02:00