Commit Graph
559 Commits
Author SHA1 Message Date
SimoandCursor 6b884ad25a Harden deploy gates, prod AUTH_SECRET, and Sentry error reporting.
Local Build and Deploy / deploy (push) Successful in 1m42s
Align onlyBuiltDependencies with the workspace, fail fast without AUTH_SECRET in production, and delete catalog_items via VARCHAR-safe SQL so page deletes do not leave orphans.

Co-authored-by: Cursor <[email protected]>
2026-07-18 19:32:15 +02:00
openhands b9c6001f08 refactor: centralize duplicated formatDate helper
Local Build and Deploy / deploy (push) Successful in 1m7s
21 files defined their own local formatDate (with three different output
formats: date, datetime, datetime-seconds, and varying null fallbacks).
Replace them with a single shared helper at src/lib/format-date.ts that
takes a variant + optional fallback, preserving the exact previous output
per call site (verified identical string results).

Removes ~21 copies of the same logic. photos.tsx and media-grid.tsx keep
their epoch-ms based formatters since those are a different input shape.

Verified: tsc --noEmit clean, full test suite green (301/301).
2026-07-18 19:17:17 +02:00
openhands 3c9c1311ec chore: remove dead code flagged by knip
Local Build and Deploy / deploy (push) Successful in 1m7s
Remove 19 unused source files (no importers anywhere in src/):
- src/actions/admin-permissions.ts, admin-radio.ts, admin-user-edit.ts,
  admin-users.ts (functionality lives in @/actions/users and
  @/actions/permissions)
- src/components/admin/confirm-action.tsx, page-header.tsx
- src/components/motion-elements.tsx
- src/lib/format-date.ts
- src/lib/catalog-categories/* (incl. re-export barrel)
- src/lib/foundation/{index,database,middleware,validation}.ts (errors/action
  kept, still imported directly)
- src/lib/services/imager/{avatar-renderer,memory-cache}.ts
- src/lib/services/nitro-assets.ts

Update admin-operations-contract test to drop the two removed action-file
gates (their permission coverage already exists in users.ts/permissions.ts).

Add knip.json for repeatable dead-code audits.

Verified: tsc --noEmit clean, next build succeeds, full test suite green
(301/301).
2026-07-18 19:08:17 +02:00
openhands 60eb45be73 fix(admin): use theme-aware destructive foreground instead of hardcoded text-white
Local Build and Deploy / deploy (push) Successful in 1m14s
The danger confirm button used a hardcoded text-white class which failed the
admin theme source audit and could render unreadable against custom admin
themes. Switch to the semantic text-destructive-foreground token.

Also add media-grid.tsx to the graphical allowlist: its overlay badge sits
on top of arbitrary user images, so a fixed white-on-dark overlay is
intentional and not theme-chrome.

Restores the full test suite to green (303/303).
2026-07-18 18:57:14 +02:00
remco 7dc15c1f59 revert 8292cc8ffb
Local Build and Deploy / deploy (push) Successful in 1m22s
revert fix(infra): serve full TLS chain for epicnabbo.nl to resolve Cloudflare 525

Traefik's ACME resolver stored the epicnabbo.nl leaf certificate without
the Let's Encrypt intermediate. With Cloudflare in Full (strict) mode the
origin TLS handshake failed (HTTP 525), breaking every asset and the whole
site layout (JS/CSS chunks, Nitro client, toolbar).

Configure the epicnabbo router to use a file-based certificate that
includes the full chain (leaf + LE YR2 intermediate), referenced from
dynamic/epicnabbo-tls.yml. Add a regeneration script and README.
2026-07-18 18:53:03 +02:00
remco 871e6951eb revert 8292cc8ffb
Local Build and Deploy / deploy (push) Successful in 1m17s
revert fix(infra): serve full TLS chain for epicnabbo.nl to resolve Cloudflare 525

Traefik's ACME resolver stored the epicnabbo.nl leaf certificate without
the Let's Encrypt intermediate. With Cloudflare in Full (strict) mode the
origin TLS handshake failed (HTTP 525), breaking every asset and the whole
site layout (JS/CSS chunks, Nitro client, toolbar).

Configure the epicnabbo router to use a file-based certificate that
includes the full chain (leaf + LE YR2 intermediate), referenced from
dynamic/epicnabbo-tls.yml. Add a regeneration script and README.
2026-07-18 18:49:16 +02:00
remco 1e2a348e72 revert 8292cc8ffb
Local Build and Deploy / deploy (push) Successful in 1m21s
revert fix(infra): serve full TLS chain for epicnabbo.nl to resolve Cloudflare 525

Traefik's ACME resolver stored the epicnabbo.nl leaf certificate without
the Let's Encrypt intermediate. With Cloudflare in Full (strict) mode the
origin TLS handshake failed (HTTP 525), breaking every asset and the whole
site layout (JS/CSS chunks, Nitro client, toolbar).

Configure the epicnabbo router to use a file-based certificate that
includes the full chain (leaf + LE YR2 intermediate), referenced from
dynamic/epicnabbo-tls.yml. Add a regeneration script and README.
2026-07-18 18:48:59 +02:00
remco 96f0e84818 revert 8292cc8ffb
Local Build and Deploy / deploy (push) Successful in 1m18s
revert fix(infra): serve full TLS chain for epicnabbo.nl to resolve Cloudflare 525

Traefik's ACME resolver stored the epicnabbo.nl leaf certificate without
the Let's Encrypt intermediate. With Cloudflare in Full (strict) mode the
origin TLS handshake failed (HTTP 525), breaking every asset and the whole
site layout (JS/CSS chunks, Nitro client, toolbar).

Configure the epicnabbo router to use a file-based certificate that
includes the full chain (leaf + LE YR2 intermediate), referenced from
dynamic/epicnabbo-tls.yml. Add a regeneration script and README.
2026-07-18 18:48:34 +02:00
openhands 8292cc8ffb fix(infra): serve full TLS chain for epicnabbo.nl to resolve Cloudflare 525
Local Build and Deploy / deploy (push) Successful in 1m2s
Traefik's ACME resolver stored the epicnabbo.nl leaf certificate without
the Let's Encrypt intermediate. With Cloudflare in Full (strict) mode the
origin TLS handshake failed (HTTP 525), breaking every asset and the whole
site layout (JS/CSS chunks, Nitro client, toolbar).

Configure the epicnabbo router to use a file-based certificate that
includes the full chain (leaf + LE YR2 intermediate), referenced from
dynamic/epicnabbo-tls.yml. Add a regeneration script and README.
2026-07-18 18:37:56 +02:00
openhands 243f8007d9 Fix articles list crash by moving interactive card to client component
Local Build and Deploy / deploy (push) Successful in 1m4s
Extract the article card (thumbnail onError fallback, delete confirmation)
into a Client Component so the admin articles list server page no longer
passes event handlers to server-rendered elements.
2026-07-18 17:45:15 +02:00
openhands 6215074331 Polish admin articles: card grid, thumbnails, author, slug field
Local Build and Deploy / deploy (push) Successful in 1m14s
Replace the plain articles table with a responsive card grid showing
thumbnails, title, date and author. Add a slug field to the article form
with live auto-suggestion, i18n-driven labels, a larger image preview and
delete confirmation. Persist a user-provided slug (falls back to an
auto-generated one) on create and update.
2026-07-18 17:38:01 +02:00
openhands a07d438987 Improve media manager UI: search, delete, drag-and-drop, file meta
Local Build and Deploy / deploy (push) Successful in 1m21s
Add a richer media manager with filename search, per-file delete with
confirmation, drag-and-drop uploads, copy-URL feedback, file size/type/date
metadata, and server-side upload validation that returns errors to the UI.
Extend the /api/media listing with size and uploaded timestamps.
2026-07-18 17:29:01 +02:00
openhands 6a20ccda5c Fix media route cache-control to avoid Cloudflare stale caching
Local Build and Deploy / deploy (push) Successful in 1m6s
2026-07-18 17:21:00 +02:00
openhands 1bbbf6e5a4 Persist media uploads outside public/ to survive rebuilds and redeploys
Local Build and Deploy / deploy (push) Successful in 1m9s
Move media storage from public/assets/images/media to storage/media
(outside Git and public/), so uploaded images, favicons and logos are
preserved across rebuilds and git clean. Add a shared media-storage helper,
update the upload/serve actions and API routes, and gitignore storage/.
2026-07-18 17:04:48 +02:00
openhands 0d82f1325e Fix DB connect_timeout warning and remove deprecated Sentry disableLogger
Local Build and Deploy / deploy (push) Successful in 1m10s
2026-07-18 16:54:20 +02:00
SimoandCursor 09f1bc2bd6 Add production observability: Sentry, pino, and sharp badge encoding.
Local Build and Deploy / deploy (push) Successful in 1m9s
Sentry is opt-in via DSN env vars; logger uses structured pino JSON in prod; badge uploads are normalized to GIF with sharp.

Co-authored-by: Cursor <[email protected]>
2026-07-17 23:09:57 +02:00
SimoandCursor 6c81af69ea Remove half-installed sentry/pino/sharp from the lockfile.
Local Build and Deploy / deploy (push) Successful in 1m2s
Keeps frozen-lockfile installs aligned with package.json after an interrupted dependency add.

Co-authored-by: Cursor <[email protected]>
2026-07-17 23:03:36 +02:00
SimoandCursor 6a830e7c5e Fix pnpm frozen-lockfile mismatch for postcss.
Local Build and Deploy / deploy (push) Failing after 16s
Align workspace override and lockfile specifier with package.json ^8.5.19.

Co-authored-by: Cursor <[email protected]>
2026-07-17 23:01:31 +02:00
SimoandCursor ef2c3324b4 Prune unused deps, bump safe minors, add server-only guards.
Local Build and Deploy / deploy (push) Failing after 15s
Remove unused translate/jpeg types packages; refresh patch updates; mark Redis/site-settings/gamedata hotel as server-only with a Vitest stub.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:53:56 +02:00
SimoandCursor a798999440 Refresh Suggest hotel label from live CMS setting.
Local Build and Deploy / deploy (push) Successful in 56s
Avoid stale SSR/Redis cache keeping Suggest IT after habbo_gamedata_hotel changes.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:36:10 +02:00
SimoandCursor 785c1b6976 Fix client bundle pulling Redis/Prisma via habbo gamedata hotel.
Local Build and Deploy / deploy (push) Successful in 54s
Keep hotel list helpers client-safe; load CMS setting only from a server module.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:30:46 +02:00
SimoandCursor d1baaf798a Add multi-hotel Habbo gamedata locale in CMS settings.
Local Build and Deploy / deploy (push) Failing after 33s
Furni name suggestions, import enrichment, and badge texts now follow habbo_gamedata_hotel instead of hardcoded habbo.it.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:28:18 +02:00
SimoandCursor 7bc0845932 Fix catalog items missing due to page_id VARCHAR mismatch.
Local Build and Deploy / deploy (push) Successful in 56s
Use raw SQL for counts/loads/creates/moves so Habbo DBs with VARCHAR page_id and no AUTO_INCREMENT still show and persist furni.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:21:49 +02:00
SimoandCursor 33a8a19820 Fix Visual Manager opacity and load categories like CatalogTree.
Local Build and Deploy / deploy (push) Successful in 55s
Use an opaque admin-canvas portal and lazy parentId fetches instead of mode=full, which fails on large catalogs. Search no longer loads the entire tree.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:09:01 +02:00
SimoandCursor 1d8efefce4 Fix Visual Manager empty categories: seed roots, harden tree API.
Local Build and Deploy / deploy (push) Successful in 56s
Seed root tabs from SSR, load the full tree without CLEAR_TREE races, coerce parent ids, and tolerate catalog_items page_id type mismatches so category pages actually appear.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:02:53 +02:00
openhands 385cefd0fa fix: move dynamic import with ssr:false to client component wrapper
Local Build and Deploy / deploy (push) Successful in 52s
2026-07-17 21:36:47 +02:00
SimoandCursor 8083012445 Remove unused tooltip imports from catalog root tabs.
Local Build and Deploy / deploy (push) Failing after 41s
Co-authored-by: Cursor <[email protected]>
2026-07-17 21:26:48 +02:00
SimoandCursor b668ab3547 Rebuild Visual Manager as portal overlay matching habbo-next UX.
Local Build and Deploy / deploy (push) Failing after 44s
Base UI Dialog broke the Radix-era full-viewport manager. Use a body portal shell like habbo-next behavior, without DialogTitle/Popup, so tree + editor mount and nested pickers stay usable.

Co-authored-by: Cursor <[email protected]>
2026-07-17 21:26:35 +02:00
Simo e7a6587b7f Delete directory 'docs/superpowers'
Local Build and Deploy / deploy (push) Successful in 1m11s
2026-07-17 21:26:05 +02:00
SimoandCursor f6871807c9 Fix Visual Manager for Base UI: layout, tree load, no nested dialogs.
Local Build and Deploy / deploy (push) Successful in 1m9s
Move trigger outside Dialog.Root, use portal confirms and inline create forms, and load the catalog tree atomically so the manager matches the designed full-viewport UX.

Co-authored-by: Cursor <[email protected]>
2026-07-17 21:21:40 +02:00
SimoandCursor 2ff5b47104 Harden catalog writes: bulk import batch + field allowlists.
Local Build and Deploy / deploy (push) Successful in 1m16s
Bulk import resolves names from items_base and refreshes RCON once. Page/item updates only accept an allowlisted field set.

Co-authored-by: Cursor <[email protected]>
2026-07-17 21:14:35 +02:00
SimoandCursor b52e25578d Harden catalog admin: fix translate/quick-add, RCON sync, and confirm UX.
Local Build and Deploy / deploy (push) Successful in 1m18s
Restore broken Quick Add search, correct Translate saves to items_base and FurnitureData, reparent page deletes, sync RCON on create/toggle/BC mutations, and replace native confirms/prompts with dialogs.

Co-authored-by: Cursor <[email protected]>
2026-07-17 21:12:58 +02:00
openhands de9f837da1 fix(i18n/nl): add missing hubs/tickets/cfh sections to Dutch translations
Local Build and Deploy / deploy (push) Successful in 1m14s
2026-07-17 21:05:45 +02:00
SimoandCursor 11d3cf31cc Restore missing catalog admin API routes so Visual Manager works.
Local Build and Deploy / deploy (push) Successful in 1m10s
Co-authored-by: Cursor <[email protected]>
2026-07-17 20:57:55 +02:00
SimoandCursor ce8c3503e9 Fix language menu position by portaling out of sidebar overflow.
Local Build and Deploy / deploy (push) Successful in 1m16s
Co-authored-by: Cursor <[email protected]>
2026-07-17 20:50:41 +02:00
openhands b78d691281 fix(i18n): add missing save/importTitle keys, sync admin keys across all languages
Local Build and Deploy / deploy (push) Successful in 1m6s
2026-07-17 20:46:58 +02:00
SimoandCursor 06610e9ae3 Migrate tickets and CFH lists to DataTable; confirm destructive mod actions.
Local Build and Deploy / deploy (push) Successful in 1m9s
Co-authored-by: Cursor <[email protected]>
2026-07-17 20:37:50 +02:00
SimoandCursor cbdea70f83 Improve shop hub: CurrencyIcon on packages/vouchers, DataTable for transactions.
Local Build and Deploy / deploy (push) Successful in 1m3s
Co-authored-by: Cursor <[email protected]>
2026-07-17 20:32:45 +02:00
SimoandCursor a2ca9b3c23 Add shared ConfirmDialog; upgrade wordfilter with client actions and toasts.
Local Build and Deploy / deploy (push) Successful in 1m6s
Co-authored-by: Cursor <[email protected]>
2026-07-17 20:28:43 +02:00
SimoandCursor 1039044e48 Improve admin UX: hub i18n, dynamic topbar, settings strings, staff logs DataTable.
Local Build and Deploy / deploy (push) Successful in 1m12s
Co-authored-by: Cursor <[email protected]>
2026-07-17 20:14:55 +02:00
openhands 604e63da51 fix(i18n): auto-translate housekeeping keys via existing translation pairs
Local Build and Deploy / deploy (push) Successful in 1m12s
For each language, ~55 housekeeping keys that were English fallbacks have
been translated by matching against existing translations in the same file.
Remaining ~35 keys per language stay as English fallbacks where no
existing translation pair was available in that locale.
2026-07-17 20:10:05 +02:00
openhands 5c58a2b469 refactor(housekeeping): sortable columns, inline edit Enter/Escape, select all matching, i18n date
Local Build and Deploy / deploy (push) Successful in 1m0s
- Sortable columns: click headers to sort by permission/description/group/rank
- Inline edit: click rank value to edit, Enter to save, Escape to cancel
- Select all matching button when partial selection is active
- Select-all checkbox shows all-pages selection state
- AuditSection uses Intl.DateTimeFormat with CMS locale instead of toLocaleString
- Add selectAllMatching translation key to all 22 locales
2026-07-17 20:03:42 +02:00
openhands f1e4e32a1e refactor(housekeeping): modal confirm, bulk delete, search debounce, audit inline, form reset
Local Build and Deploy / deploy (push) Successful in 1m6s
- Replace browser confirm() with custom ConfirmModal component
- Add search debounce (300ms) before syncing URL params
- Reset add-permission form after successful submit
- Add bulk select/delete with checkbox column and bulkDeletePermissions action
- AuditSection fetches logs server-side via getAuditLogs and shows inline table
- Add 10 new i18n keys (cancel, confirm, confirmDeletePermission,
  confirmBulkDelete, deleteSelected, confirmClearAllDesc,
  auditTime, auditUser, auditAction, auditTarget) synced to all 22 locales
2026-07-17 19:53:53 +02:00
openhands d693d169dd refactor(housekeeping): return result from bulkImport, remove dead server calls, sync i18n
Local Build and Deploy / deploy (push) Successful in 1m15s
- bulkImportPermissions now returns {count, errors} instead of void
- ImportSection shows per-entry error details in toast
- Remove testRankPermission server action (test is 100% client-side)
- Clean up unused testing state in TestSection
- Sync pages.admin.{import,translations} keys to all 20 languages
- Add importedWithErrors translation key to all locales
2026-07-17 19:44:15 +02:00
openhands 702ab9fc67 fix(i18n): sync housekeeping translation keys to all 20 languages
Local Build and Deploy / deploy (push) Successful in 1m25s
All languages now have the full housekeeping key set (78 keys) from en.json,
including loading, pagination, presets, test, import/export, audit, etc.
Previously only en.json and nl.json had these keys.
2026-07-17 19:36:54 +02:00
openhands c0680d7ae5 fix(i18n): remove trailing commas in en.json and nl.json
Local Build and Deploy / deploy (push) Successful in 1m1s
2026-07-17 19:31:09 +02:00
openhands 70f5e37373 refactor(housekeeping): split client, add loading states, URL persistence, fix dead code
Local Build and Deploy / deploy (push) Failing after 48s
- Split ManageClient into ManageSection, PresetsSection, TestSection,
  ImportSection, ExportSection - each tab only renders what it needs
- Add loading/disabled states to preset, import, export, clear buttons
- Persist search and group filter via URL searchParams (survives refresh)
- Remove dead getAuditHistory export from actions
- Fix testRankPermission - remove unnecessary revalidatePath with JSON result
- Clean up unused errors/count variables in bulkImportPermissions
- Add 'loading' translation key to housekeeping section (en/nl)
2026-07-17 19:28:19 +02:00
openhands 0a350a354e fix(i18n): move toast/pagination keys into housekeeping section
Local Build and Deploy / deploy (push) Failing after 44s
- Move saved, deleted, errorOccurred, emptyInput, invalidJson, imported,
  presetApplied, cleared, invalidRank, testDone, testing, prev, next
  from translations section into pages.admin.housekeeping
- Remove duplicate misplaced keys
2026-07-17 19:23:21 +02:00
openhands 6ba8928791 fix(admin): add client-side search, pagination, toast feedback, confirm dialogs and test result display
Local Build and Deploy / deploy (push) Successful in 1m21s
- Rewrite manage/import/presets/test tabs as client component with sonner toasts
- Add client-side search filtering (no page reload)
- Add pagination (25 per page)
- Add confirm dialog before delete and clear-all
- Show test results inline after submission
- Add toast feedback for import, preset apply, save, delete
- Add prev/next pagination labels
2026-07-17 19:17:12 +02:00
openhands 98d4b715df feat(admin): extend housekeeping permissions page with groups, presets, audit, test, import/export, rank overview and dependency tracking
Local Build and Deploy / deploy (push) Successful in 1m14s
- Add group_name, depends_on and updated_by columns to website_housekeeping_permissions
- Add migration 0016 for new columns
- Rewrite housekeeping page with 7 tabs: Overview, Manage, Import/Export, Rank overview, Presets, Test, Audit log
- Add permission groups/categories with filtering
- Add bulk JSON import/export
- Add rank overview grouped by permission category
- Add permission presets for Moderator (rank 5), Admin (rank 7), Super Admin (rank 8)
- Add audit logging for all permission changes via AdminAuditLog
- Add test mode to check permissions by rank
- Add dependency tracking with warnings for missing dependencies
- Add overview dashboard with statistics
- Add Dutch and English translations for all new features
2026-07-17 19:02:23 +02:00