Commit Graph
368 Commits
Author SHA1 Message Date
SimoandCursor d7278c77f9 Fix automatic readable text contrast for public and admin themes.
Local Build and Deploy / deploy (push) Successful in 55s
Derive admin/public text colors from WCAG contrast, unify ThemeVars CSS emission, and keep navbar overrides in sync with readable vars.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:41:34 +02:00
SimoandCursor 9d4d409b77 Restore self-hosted /api/imaging/avatar (and badge) endpoints.
Local Build and Deploy / deploy (push) Successful in 54s
The clothing importer and imager helpers pointed at a missing route; proxy Habbo with disk/memory cache so avatars work again.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:41:18 +02:00
SimoandCursor 3403d3b19f Fix admin permissions bounce, prefixes APIs, and Italian UI leftovers.
Local Build and Deploy / deploy (push) Successful in 56s
Gate permissions on ACL manage + resolve super-admin from live user ranks, restore prefixes API routes, and anglicize hardcoded admin copy with nav i18n.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:33:00 +02:00
SimoandCursor 0e89d03940 Finish fine-grained ACL across remaining admin pages and actions.
Local Build and Deploy / deploy (push) Successful in 56s
Replace leftover requireStaff gates with module PERMS, drop hardcoded room rank thresholds, and expand contract tests so admin mutations cannot regress to dashboard-only checks.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:15:22 +02:00
SimoandCursor 3c8a8ff888 Extend fine-grained ACL to settings, content, shop, and radio.
Local Build and Deploy / deploy (push) Successful in 54s
Gate pages and mutations on module PERMS instead of dashboard-only staff checks, add radio view/edit slugs with migration 0015, and expand the operations contract tests.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:11:55 +02:00
SimoandCursor f2427b3483 Harden admin ACL on critical write paths.
Local Build and Deploy / deploy (push) Successful in 54s
Gate translations, RCON, and user mutations on SETTINGS_EDIT, RCON_EXECUTE, and USERS_EDIT instead of dashboard/rank checks; redirect the legacy user-edit URL to the guarded canonical page.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:07:15 +02:00
SimoandCursor bae543baf6 Fix admin regressions from Biome refactor: theme init, mobile nav, i18n.
Local Build and Deploy / deploy (push) Successful in 54s
Restore valid browser JS in theme-init, close mobile sidebar on navigation, and split autoDjForm title/trackTitle across locales.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:02:25 +02:00
openhands 59b63d6e70 Fix real Biome bugs: inner declarations, dup keys, assign-in-expr, implicit any, cookie, a11y svg/keyboard, json
Local Build and Deploy / deploy (push) Successful in 51s
2026-07-14 18:58:40 +02:00
openhands 8d5c8ec96f Visibility polish: admin sidebar contrast/focus, table header readability, nav focus rings
Local Build and Deploy / deploy (push) Successful in 57s
2026-07-14 16:50:43 +02:00
openhands db1875b40b Close mobile nav menu when a link inside is tapped
Local Build and Deploy / deploy (push) Successful in 58s
2026-07-14 16:44:07 +02:00
openhands af1b18d866 Fix mobile nav: hamburger left, brand right, polished menu panel
Local Build and Deploy / deploy (push) Successful in 57s
2026-07-14 16:41:19 +02:00
openhands 48a5394204 Complete nav rewrite: native details/summary, zero JS state, zero transforms
Local Build and Deploy / deploy (push) Successful in 1m5s
- Mobile nav: uses <details>/<summary> for toggle, no useState, no useEffect
- Nav dropdown: uses <details>/<summary>, no useState, no event listeners
- Desktop: separate div with desktop nav items (hidden on mobile)
- Mobile: hamburger dropdown with absolute positioned panel
- CSS: removed ::after pseudo-element with transform, replaced hover
  with background-color only, added details[open] CSS rules
- No backdrop-filter, no will-change, no transition-all, no GPU hacks
- Works on every device without JS state management
2026-07-14 16:25:36 +02:00
openhands 5978b3c13d Rebuild mobile nav: absolute positioned dropdown panel, outside doc flow
Local Build and Deploy / deploy (push) Successful in 1m4s
2026-07-14 16:16:19 +02:00
openhands 90d249e50e Fix typecheck error: use non-null assertion after expect(pair).toBeDefined()
Local Build and Deploy / deploy (push) Successful in 59s
2026-07-14 16:12:01 +02:00
openhands c7c4617f2a Rebuild all menus from scratch for pixel-perfect rendering on every device
Local Build and Deploy / deploy (push) Successful in 59s
- mobile-nav: pure block/hidden toggle, no transforms, no transition-all
- nav-dropdown: clean block/hidden toggle, no CSS animation hacks
- navigation: removed shadow-sm, no will-change, no GPU compositing
- top-header: consistent mobile layout, clean details/summary dropdowns
- admin-mobile-wrapper: inline transition instead of CSS class for sidebar
- globals.css: removed transition-all from nav-item/dropdown-item, replaced
  with specific color/background-color transitions only, added hover bg
2026-07-14 16:10:01 +02:00
openhands 9910fd52c7 Fix blurry normal navigation on mobile: remove transition-all and shadow-sm from nav items
Local Build and Deploy / deploy (push) Successful in 59s
2026-07-14 16:01:46 +02:00
openhands bfa8aedb25 Fix blurry mobile nav: use block/hidden instead of max-h transition, add will-change to sticky nav
Local Build and Deploy / deploy (push) Successful in 57s
2026-07-14 15:47:46 +02:00
openhands 7b3e3c1531 Fix blurry mobile menu by removing CSS transform from animation
Local Build and Deploy / deploy (push) Successful in 57s
2026-07-14 15:42:24 +02:00
openhands 026cb55cf3 Fix mobile menu blur and improve admin sidebar text contrast
Local Build and Deploy / deploy (push) Successful in 57s
2026-07-14 15:36:17 +02:00
openhands 76d18e2645 Fix mobile layout issues in admin sidebar and top-header
Local Build and Deploy / deploy (push) Successful in 50s
2026-07-14 15:29:52 +02:00
openhands 2455a4850e fix: make useServerAction accept void-returning actions and remove dead queryCount
Local Build and Deploy / deploy (push) Successful in 53s
- Type run()'s action param as Promise<unknown> and cast result (Biome strips void from unions)
- Remove unused queryCount field increment in DbService (dead code)
- Reformat theme-contrast test pair assertions
2026-07-13 22:25:56 +02:00
openhands 1908136071 ci: kill lingering next-server before restarting service to avoid EADDRINUSE
Local Build and Deploy / deploy (push) Successful in 1m5s
2026-07-13 22:16:20 +02:00
openhands 045dc06a1f fix: resolve type errors and migrate pnpm settings to pnpm-workspace.yaml
Local Build and Deploy / deploy (push) Failing after 56s
- Move pnpm.onlyBuiltDependencies/overrides from package.json to pnpm-workspace.yaml (clears pnpm WARN)
- Allow useServerAction run() to accept actions returning void
- Make adminAction/authAction input optional so no-schema actions can be called without args
- Return ActionResult from updateBcPage
- Fix categoryPageMap value type (number | undefined)
- Declare DbService.queryCount field
- Use definite assignment for release in withFurniDataLock
- Narrow pair type in theme-contrast test
2026-07-13 22:10:50 +02:00
openhands df38dccbf1 style: format code biome
Local Build and Deploy / deploy (push) Failing after 46s
2026-07-13 21:57:41 +02:00
openhands 8efd032cc6 style: format code with prettier agian
Local Build and Deploy / deploy (push) Failing after 49s
2026-07-13 21:41:52 +02:00
openhands e6d7f2280b Add named custom theme presets (save/load/rename/delete) in admin theme editor
Local Build and Deploy / deploy (push) Successful in 58s
2026-07-13 20:42:40 +02:00
openhands 01b70c2369 Make HK sidebar menu clearly readable and structured
Local Build and Deploy / deploy (push) Successful in 1m2s
- Strong, obvious active state: accent-tinted background, bold text,
  accent icon and left accent border so the current section is unmistakable
- Inactive items stay fully readable (white on dark) with a clear hover
- Separate nav sections with dividers and bolder uppercase headers
- Fix invisible mobile hamburger hover (bg-black/10 -> accent tint)
2026-07-13 20:29:24 +02:00
openhands 0b18a16a2d Make entire HK admin panel cohesive and always readable
Local Build and Deploy / deploy (push) Successful in 1m4s
- Remap shared shadcn semantic tokens (--color-primary, --color-popover,
  --color-card, --color-border, --color-ring, --color-muted-foreground,
  --color-destructive, ...) onto the admin palette for any page scoped with
  body:has([data-admin]); this themes every embedded Button, Badge, Input,
  Select, Card, Table, Tabs, Dialog, Switch, Checkbox with the admin theme
  and guaranteed contrast, without editing component files. Gated so the
  public site is untouched and Radix portals (dialogs/selects) are covered.
- Tag the admin layout/sidebar with data-admin and give the admin content
  area the admin canvas background so the whole HK is one cohesive dark UI.
- Fix hardcoded colors in catalog shop preview and favicon form to use
  admin variables; fix white text on a light warning tint (low contrast).
2026-07-13 20:24:02 +02:00
openhands 8721cfcea4 Make HK sidebar menu text always 100% visible
Local Build and Deploy / deploy (push) Successful in 1m8s
- Set muted sidebar text equal to the readable sidebar text so inactive
  nav items and section labels are never dimmed
- Active item remains distinguished by its accent background and border
2026-07-13 20:13:35 +02:00
openhands d2243b5611 Fix HK sidebar menu text readability
Local Build and Deploy / deploy (push) Successful in 58s
- Derive sidebar text color from the main admin text against the actual
  sidebar background (not canvas/surface), guaranteeing contrast
- Brighten muted sidebar text to 82% of the readable text color so
  inactive nav items and section labels stay clearly visible
2026-07-13 20:10:52 +02:00
openhands cb4a6a8f3e Fix theme editor lint warnings
Local Build and Deploy / deploy (push) Successful in 59s
- Remove unused eslint-disable directive in preset swatches
- Add safe eslint-disable for controlled bgKey lookup in ColorField renderer
2026-07-13 20:06:48 +02:00
openhands acc820284b Add live contrast preview to theme editor for guaranteed readability
Local Build and Deploy / deploy (push) Successful in 1m0s
- New client ColorField component shows a live 'Aa' text preview on the
  relevant background and a WCAG contrast ratio badge (✓ / ⚠)
- Flags low-contrast (<4.5:1) text fields with a red border and a
  one-click 'Use readable color' fix
- Map each text color to the background it sits on (body text -> surface,
  button text -> button color, navbar text -> navbar, admin text -> canvas)
2026-07-13 20:04:58 +02:00
openhands 17894db3e9 Improve theme editor clarity with labels and descriptions
Local Build and Deploy / deploy (push) Successful in 1m20s
- Add a description to every color field explaining what it affects
- Regroup colors into Page & text / Buttons & links / Gradients with
  explanatory section intros for both light and dark mode
- Add section intros for light, dark, and admin (HK) modes
- Widen color field layout and show descriptions under each label
2026-07-13 19:58:38 +02:00
openhands a16d9859e8 Add admin HK color customization fields to theme editor
Local Build and Deploy / deploy (push) Successful in 58s
- Add 6 new admin color DB keys (admin_canvas, admin_surface, admin_text,
  admin_text_muted, admin_border, admin_sidebar_bg) that override the
  derived admin palette
- Extract adminPaletteCss() from themePaletteCss() for reuse
- Generate admin CSS variables in both :root and html.dark with overrides
- Persist admin color settings via saveTheme action
- Add Admin panel (HK) section to /admin/theme with color pickers
2026-07-13 19:49:19 +02:00
openhands 4dcf6fdce8 Fix admin sidebar colors: use consistent dark sidebar instead of navbar colors for professional look
Local Build and Deploy / deploy (push) Successful in 1m0s
2026-07-13 19:32:27 +02:00
openhands 17722acc69 Add global mobile-friendly CSS rules
Local Build and Deploy / deploy (push) Successful in 1m30s
2026-07-13 19:29:17 +02:00
openhands 3fe3846ad5 Fix blurry mobile menu: use GPU-friendly opacity+transform instead of max-height transition
Local Build and Deploy / deploy (push) Successful in 1m1s
2026-07-13 19:26:02 +02:00
openhands debee7300e Fix admin sidebar contrast: muted text now visually distinct from regular text
Local Build and Deploy / deploy (push) Successful in 59s
2026-07-13 19:21:53 +02:00
openhands adbd651350 Add mobile sidebar toggle for admin panel
Local Build and Deploy / deploy (push) Successful in 1m5s
2026-07-13 19:17:27 +02:00
openhands 7b67ef893c Fix admin sidebar height, language dropdown overflow, pagination wrap, nav dropdown min-width
Local Build and Deploy / deploy (push) Successful in 58s
2026-07-13 19:12:28 +02:00
openhands a241448e9e Revert admin sidebar toggle, fix hamburger position directly
Local Build and Deploy / deploy (push) Successful in 1m4s
2026-07-13 19:02:09 +02:00
openhands 53b760a815 Add admin sidebar toggle on mobile, fix table wrapping, fix grids
Local Build and Deploy / deploy (push) Successful in 50s
2026-07-13 18:52:13 +02:00
openhands c7768d8668 Move hamburger to right, fix nav overflow, add auto language detection
Local Build and Deploy / deploy (push) Successful in 1m4s
2026-07-13 18:20:04 +02:00
openhands eba61d2fb9 Fix mobile responsive issues
Local Build and Deploy / deploy (push) Successful in 53s
- Remove duplicate home link in mobile nav
- Remove overflow-hidden clipping main content
- Improve mobile menu scrolling and spacing
- Make top-header currencies wrap on small screens
- Reduce site-header height on mobile
- Add global mobile CSS overrides for tables, padding, fonts
2026-07-13 18:10:16 +02:00
openhands bef458dbf8 Rename executeRaw → executeRawUnsafe to make SQL injection risk explicit
Local Build and Deploy / deploy (push) Successful in 1m1s
The method wraps Prisma's  which trusts the caller
to use ? placeholders. The Unsafe suffix is a naming convention
that signals 'review caller for parameterization'.
2026-07-13 12:41:11 +02:00
openhands e5ae51bff7 Add NFC normalization to all FormData inputs across 41 server actions
Local Build and Deploy / deploy (push) Successful in 59s
All user-supplied string values from FormData now go through
String.prototype.normalize('NFC') to prevent Unicode homoglyph
attacks and canonicalization bypasses. NFC is idempotent for
already-normalized strings, so this is a pure security improvement
with zero behavioral change for legitimate users.
2026-07-13 12:21:37 +02:00
openhands e2fc7ea1a4 Complete security hardening: zero-migration foundation, edge headers, rate-limit atomics, body limits
Local Build and Deploy / deploy (push) Successful in 58s
- Make @/lib/safe-action re-export from foundation layer so all 13+
  existing server actions instantly get request tracing, rate limiting,
  and structured error handling without any code changes
- Add HSTS, CSP, X-Frame-Options, X-Content-Type-Options to edge proxy
  (src/proxy.ts) — ran at Cloudflare/Vercel edge for all non-asset routes
- Fix rate-limit.ts race condition: compute newCount before assignment
  to shrink the read-modify-write window; add memory-key prefix to
  avoid collisions with Redis keys
- Add request body size limit (10 MB default) to api-handler.ts with
  per-route override via maxBodyBytes option
- Remove unused imports and clean up backward-compat types
2026-07-13 12:09:43 +02:00
openhands f6ad030c5b Add EpicNext CMS foundation layer and fix critical security gaps
Local Build and Deploy / deploy (push) Successful in 1m1s
- Create src/lib/foundation/ (860 LOC, 9 files): typed action wrappers,
  DbService with health checks, CSRF validation, safe redirects,
  AsyncLocalStorage request tracing, branded types, reusable Zod schemas
- Migrate moderation.ts and user-settings.ts to foundation patterns
- Fix abuse-guard.ts: bound in-memory Maps with LRU eviction (was unbounded)
- Fix access-guard.ts: separate try/catch per check, log degradation
  instead of blanket fail-open
- Replace raw redirect() calls with safeRedirect() in guard.ts and
  permissions.ts to prevent open-redirect attacks
- Add CSRF validation to api-handler.ts for mutating methods
- Add canonicalizeFormData() utility for FormData input sanitization
2026-07-13 12:03:49 +02:00
openhands 8bf1aa2fa7 Use translations for emulator page (was hardcoded Italian)
Local Build and Deploy / deploy (push) Successful in 58s
2026-07-12 23:14:35 +02:00
openhands 5ae29e2a58 Add i18n support for import page and translations tabs
Local Build and Deploy / deploy (push) Successful in 1m7s
2026-07-12 23:11:59 +02:00