Simo
17264dfc06
fix: protect admin routes and ignore local docs
2026-07-11 21:35:37 +02:00
Simo
8d37ae9ae0
style: normalize restored source endings
Remote Build and Deploy / deploy (push) Has been cancelled
2026-07-11 21:19:54 +02:00
Simo
0cd753c735
fix: restore complete admin feature dependencies
2026-07-11 21:15:54 +02:00
Simo
5b4228261a
Reapply "Add missing admin action files and navigation links"
...
This reverts commit 4d515bc400 .
2026-07-11 20:52:56 +02:00
Simo
96ed768f14
test: add unresolved local import scanner
2026-07-11 20:52:55 +02:00
Simo
4d515bc400
Revert "Add missing admin action files and navigation links"
...
This reverts commit 41be6835bf .
2026-07-11 20:37:56 +02:00
Simo
4a1e1115b3
Harden CMS security and theme contrast
2026-07-11 20:27:20 +02:00
openhands
2465ff2170
Add translation keys for new admin nav items in all languages
2026-07-11 12:28:52 +02:00
openhands
41be6835bf
Add missing admin action files and navigation links
...
- Add 11 missing server action files: badges, bulk-users, catalog, catalog-bc, catalog-items, import-badges, import-furni, multi-account-detect, permissions, rooms, soundtracks
- Add missing admin navigation links: tickets, sounds, translations, import, radio sub-pages
- Add translation keys for all new navigation items
2026-07-11 12:01:05 +02:00
openhands
818df3697b
Migrate from AES-256-CBC to AES-256-GCM for authenticated encryption
...
- Replace CBC+HMAC with GCM (built-in authentication via authTag)
- Remove createHmac and timingSafeEqual imports (no longer needed)
- Remove Snyk-ignore comments (no longer suppressible findings)
- Update test: tampered MAC test -> tampered auth tag test
- Add one-time migration script for existing CBC-encrypted 2FA secrets
2026-07-10 23:51:56 +02:00
openhands
259c0c96ab
Fix remaining Snyk findings: XSS in validImageUrl, cipher integrity suppression
2026-07-10 23:40:11 +02:00
openhands
d782b7c4c2
Fix Snyk security findings: XSS, open redirect, hardcoded secrets, cookie security, MD5 replacement
2026-07-10 23:34:57 +02:00
openhands
1875a69b83
Fix security scanner findings
...
- Replace hardcoded test secrets with crypto-generated values in laravel-encrypter.test.ts and totp.test.ts
- Add 'secure' attribute to locale cookie in language-switcher.tsx
- Validate image URLs before rendering in media-grid.tsx and media-picker.tsx (XSS prevention)
- Validate redirect URL is HTTPS before window.location assignment in TopUpForm.tsx (open redirect prevention)
- Document intentional MD5 usage for legacy PHP compatibility in password.ts
- Document HMAC integrity protection for CBC cipher in laravel-encrypter.ts
2026-07-10 23:08:15 +02:00
openhands
942bc6fc8d
Security hardening, code quality, and ESLint setup
...
- Remove production DB dump (db_backup_*.sql) and update.log from git tracking
- Add DB backups to .gitignore
- Replace all console.log/console.error with structured logger module
- Translate Dutch error messages to English (link-discord.ts)
- Remove dead code blocks (register-form.tsx false && pattern)
- Add ESLint flat config with TypeScript, React, Next.js, jsx-a11y, and security plugins
- Add Prettier config
- Add eslint-plugin-security for security-aware linting
- Fix all 119+ ESLint warnings across the codebase:
- Resolve security/detect-object-injection with safe access patterns
- Resolve security/detect-non-literal-fs-filename with path traversal validation
- Replace <img> with next/image <Image> component
- Remove unused variables and imports
- Replace non-null assertions with proper type guards
- Replace <a> with <Link> for internal navigation
- Use next/script Script component for external scripts
- Fix setState-in-useEffect anti-patterns (navbar-color-picker, logo-generator, theme-switcher)
- Add lint and format scripts to package.json
All checks: typecheck ✓, tests 58/58 ✓, lint 0 errors 0 warnings ✓
2026-07-10 22:48:22 +02:00
openhands
c68fccceeb
Fix: only preconnect nitro URL if absolute (prevents crash on relative URLs like /nitro-client/)
2026-07-09 19:52:19 +02:00
openhands
0ac3e4353a
Remove unused /api/client/sso route (replaced by server-side ticket generation)
2026-07-09 19:11:10 +02:00
openhands
7fe3220359
Inline SSO ticket generation in server component, prefetch client page from home, remove client API roundtrip
2026-07-09 18:41:04 +02:00
openhands
cfb36e8007
Preconnect to Nitro client URL for faster client page load
2026-07-09 18:35:18 +02:00
openhands
da505ae643
Optimize client page: combine fetch calls, extract ToolbarBtn component, reduce duplicated inline styles
2026-07-09 18:30:46 +02:00
openhands
deac10e00a
Add in-memory caching for online count, enable compression, and add staleTimes for router cache
2026-07-09 18:24:58 +02:00
openhands
b058a3827b
Fix theme consistency, i18n completeness, CSS variable naming, and hardcoded strings
2026-07-09 18:13:22 +02:00
openhands
5519a64583
fix: add missing nav-credit-icon, nav-ducket-icon and nav-diamond-icon CSS classes for topbar currency icons
2026-07-08 14:14:44 +02:00
openhands
fc57fb06d1
chore: remove dead code, unused CSS, unused components, and clean up git tracking
...
- Remove storage/logs/ and prod.log from git tracking; add to .gitignore
- Remove unused AvatarCarousel and ArticleSlider components
- Remove unused SkeletonTable export from ui.tsx
- Remove unused ChevronDown import from admin layout
- Remove 13 unused CSS classes (icon-base, nav-*, navigation-icon*, .app.dark,
text-body, transition-base, card-base, admin-info-grid, .coin.*)
- Remove duplicate translation keys (openMenu/closeMenu in en.json)
- Fix admin-bans to use Prisma-generated bans_type enum
- Create shared AdminPageHeader component and formatDate utility
- Add logger and generateRequestId for structured logging
- All 58 tests pass, typecheck clean, build succeeds
2026-07-08 13:27:01 +02:00
openhands
c5db7f5156
fix: production hardening — migration script, security fixes, structured logging, API docs, component splitting
...
- Create apply-migrations.ts and jobs-worker.ts scripts (package.json references)
- Convert badge leaderboard from $queryRawUnsafe to $queryRaw with Prisma.sql templates
- Fix OAuth email binding: add oauth_require_link site setting, skip 2FA-protected accounts
- Add per-user 2FA rate limiting (5/30s) to prevent TOTP brute-force
- Add structured JSON logger with levels (debug/info/warn/error)
- Split 341-line HomePage into GuestView + UserView components
- Add OpenAPI v3.1 spec at /api/openapi.json
- Add LOG_LEVEL env var, regenerate Prisma client
- Add mysql2 dependency for migration scripts
- All 58 tests pass, typecheck clean
2026-07-08 13:06:02 +02:00
openhands
5c638cd6bc
perf: add bans.user_id index, Redis cache layer, rate-limit improvements, radio contest/giveaway columns, and tests
...
- Add DB index on bans.user_id to speed up per-request ban lookups (migration 0008)
- Replace in-process rate limiter with Redis-backed implementation with in-memory fallback
- Add Redis caching layer for site settings with TTL invalidation (migration 0009)
- Add rate limiting to resetPassword to prevent token brute-force attacks
- Update all rateLimit callers to await the now-async function
- Flesh out RadioContests and RadioGiveaways models with title, description, prize, date, and winner columns
- Update radio contest/giveaway pages to display new fields
- Add tests for rate limiter (4 tests) and password-reset actions (3 tests)
- Add REDIS_URL environment variable (optional, falls back to in-memory)
2026-07-08 12:49:24 +02:00
openhands
43c0ba6614
Add Discord verification option for users without email
2026-07-07 20:37:42 +02:00
openhands
eb01b14379
Add ultimate file-based email fallback so mailer always works without any configuration
2026-07-07 20:18:30 +02:00
openhands
065215b4dc
Add local sendmail fallback so mailer works internally without external services
2026-07-07 20:15:29 +02:00
openhands
bf4075233d
Add Resend mailer as primary with SMTP fallback for reliable email delivery
2026-07-07 20:12:56 +02:00
openhands
f386ae2b25
Add more button/navbar colors and gradient mix section to theme editor
2026-07-07 20:04:16 +02:00
openhands
e43a768ce4
Add 4 new theme colors (success, warning, error, info) with full preset support
2026-07-07 19:48:41 +02:00
openhands
54c03c998c
Fix card text readability: use navbar-text color paired with navbar background on all cards
2026-07-07 19:40:13 +02:00
openhands
e53a9dc838
Redesign news article cards with clean image-first layout and proper spacing
2026-07-07 19:29:22 +02:00
openhands
4d4d9bc1cd
Make card and box backgrounds follow navbar theme color
2026-07-07 19:26:05 +02:00
openhands
61ae4e7f8b
Add explicit theme color to ContentCard title for consistent theming across all pages
2026-07-07 19:20:54 +02:00
openhands
63e1e6a44e
Add themed header bar and image preview to news article cards
2026-07-07 19:17:22 +02:00
openhands
f86f73b128
Add image preview to news listing cards
2026-07-07 19:10:32 +02:00
openhands
8818d5364e
Replace checkbox with React state-driven toggle for reliable terms acceptance
2026-07-07 19:03:33 +02:00
openhands
3becaf5f4f
Fix terms checkbox: wrap input inside label for reliable toggling
2026-07-07 19:00:07 +02:00
openhands
7412bd2dda
Remove outfit selection from register form and fix terms checkbox not toggling
2026-07-07 18:53:13 +02:00
openhands
4ba26fd814
Close dropdown and mobile menu when clicking a page link
2026-07-07 18:34:54 +02:00
openhands
0272da09c1
Fix logo generator: remove decorative fonts and fix missing char spacing
2026-07-07 16:50:58 +02:00
openhands
2f0233a0c0
Add /api/badges/leaderboard endpoint for Nitro v3 badge leaderboard
2026-07-07 16:00:46 +02:00
openhands
29f8a44f0f
Add favicon generator with color picker and text
2026-07-05 23:32:24 +02:00
openhands
4a80742e1c
Add default SVG favicon fallback
2026-07-05 23:25:36 +02:00
openhands
25c3040949
Add favicon upload option in admin panel
2026-07-05 23:22:44 +02:00
openhands
befa4ec282
Translate admin panel to all 6 languages
2026-07-04 21:21:15 +02:00
openhands
f381aa987f
Fix dropdown visibility and add missing translations
2026-07-04 20:18:30 +02:00
openhands
c9d951aa86
Fix login CSP and auth host trust
2026-07-04 20:04:44 +02:00
openhands
8bcbc501ba
Performance, SEO, a11y, and code quality improvements
...
CI / check (push) Has been cancelled
1. Performance: 25 pages switched from force-dynamic to revalidate=300 (ISR);
2 pages (community, developers) now fully static (SSG)
2. DB indexes: Added @@index on foreign keys for WebsiteArticles,
WebsiteArticleReactions, WebsiteArticleComments, WebsiteHelpCenterTickets,
WebsiteShopArticles, RadioSongRequests, StaffActivities
3. SEO: Added robots.ts, sitemap.ts, canonical URLs, Open Graph + Twitter
Card metadata on root layout and news articles
4. A11Y: Replaced <details>/<summary> dropdowns with accessible button-based
NavDropdown (aria-expanded, aria-haspopup, role=menu). MobileNav now
uses translated aria-label, aria-expanded, aria-controls, role=menu
5. Code quality: Added try/catch to updateArticle/deleteArticle; deleteArticle
now uses prisma. for atomicity
6. CI/CD: Added GitHub Actions workflow (typecheck + test)
7. i18n: Added openMenu/closeMenu keys to all 6 locales
8. Observability: Health endpoint now checks SMTP reachability when configured
9. Loading states: Added loading.tsx for root, admin, and news sections
10. Word filter cache: Added 60s TTL auto-refresh instead of manual cache bust
2026-07-04 19:41:04 +02:00