Commit Graph
52 Commits
Author SHA1 Message Date
openhands 203399aab7 fix(cache): true LRU, stale-while-revalidate and cross-process invalidation
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 32s
CI / tests-integration (push) Successful in 1m38s
CI / tests-unit (push) Successful in 1m42s
CI / tests-ui (push) Successful in 2m33s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m43s
The in-process cache was a FIFO of 500 entries that was never touched on a
read, so a key polled on every request could be evicted by an unrelated burst
of dynamic keys. That looked exactly like the cache being cleared at random,
and it is what made the site fall back to the database unpredictably.

- Evict least-recently-used instead, and raise the default budget to 2000
  (CACHE_MEMORY_MAX_ENTRIES). Reading a key now marks it as used, so a hot key
  only leaves when a hotter one takes its place.
- Add opt-in stale-while-revalidate (CachedOptions.staleMs). The grace window
  lives on the entry, so one call site opting in protects every reader of that
  key. A failed background refresh keeps serving the last good value instead of
  falling through to the origin, and is reported once rather than per read.
- Invalidate across processes. invalidateKey() now clears memory, deletes the
  Redis key and publishes a signal, so a value written by one process is no
  longer served stale by the others for the rest of its TTL. A failed Redis
  delete no longer skips the broadcast.
- Guard against a refresh that started before an invalidation writing its
  outdated result back into the cache.
- Read the news revision at most once a second per process instead of on every
  call, with a pub/sub signal to drop the local copy when it rotates. A Redis
  outage now degrades to the in-process cache rather than to no cache at all.
- Warm the hot public keys on boot, so the first visitors after a deploy do not
  each pay for a miss.
- Count hits, misses, stale serves, errors and evictions per key, exposed at
  GET /api/admin/devops/cache. Without it a wrong REDIS_URL, a full budget and
  a dead origin all look identical from the outside.
- Enforce the imaging cache budget for real: records are .img/.json pairs, so
  the old cap counted files and never removed anything while entries were
  fresh. Sweeps are throttled per directory and prune to a low-water mark.
- Cap the JWT version map, and stop per-test scratch roots from littering the
  runtime imaging cache.

Public read-only endpoints get grace windows; admin, account and auth data
deliberately stays fresh. Redis TTLs get a little jitter so keys written
together no longer expire together.

3209 tests pass. next build could not be verified on this host: the optimized
build is OOM-killed before prerender, so this has not run in a real Next
runtime yet.
2026-09-25 18:26:45 +02:00
openhands 8486ac4053 feat(security): add darklist.de source and raise the blocklist cap to 1M 2026-09-24 23:22:27 +02:00
openhands 9562a75378 feat(security): external IP blocklist sync for the local CrowdSec engine
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Successful in 1m43s
CI / tests-ui (push) Successful in 2m35s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m3s
2026-09-24 18:39:38 +02:00
openhands 84d53139a9 feat(security): opt-in local CrowdSec LAPI bouncer on the Docker engine
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-unit (push) Successful in 1m37s
CI / tests-integration (push) Successful in 1m55s
CI / tests-ui (push) Successful in 2m23s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m38s
2026-09-24 18:08:18 +02:00
openhands 301edd2c9a feat(security): ops alerts, shared backoff, atomic quota and daily stats for CrowdSec
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 29s
CI / tests-integration (push) Successful in 1m36s
CI / tests-unit (push) Successful in 1m40s
CI / tests-ui (push) Successful in 2m28s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m3s
Add an alerting/stats layer over the existing CrowdSec integration:

- New crowdsec-alerts.ts: cooldown-gated ops alerts (Redis NX lock, TTL from
  HEALTH_ALERT_COOLDOWN_MIN) fanning out through the app's sendAlert service.
  Raised for daily quota exhaustion, block bursts (5-min window past
  CROWDSEC_ALERT_BLOCK_BURST), and signal-push failures.
- New crowdsec-stats.ts: daily counters (lookups/blocks/reports/report_fail)
  in Redis with a 14-day reader for the admin panel.
- Shared 403/429 backoff: the pause marker now lives in Redis
  (crowdsec:backoff-until) so every instance honours it, not just the process
  that hit the limit.
- Atomic quota reservation: INCR-before-call with self-rollback on overshoot,
  so concurrent instances can never slip calls past the daily ceiling.
- Admin anti-DDoS page gains a last-14-days activity table next to the quota bar.
2026-09-23 14:45:35 +02:00
openhands 5e4fc9ab59 feat(security): give back to CrowdSec and harden the CTI budget
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 29s
CI / tests-integration (push) Successful in 1m34s
CI / tests-unit (push) Successful in 1m36s
CI / tests-ui (push) Successful in 2m22s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m53s
- Bound the in-process verdict cache (FIFO eviction at 2000 entries) so a
  flood of distinct bucket-tripping IPs cannot grow it without limit.
- Record block metadata (reputation, score, behaviors, category, TTL) in
  antiddos:block:meta:{ip}, surfaced as the reason in the admin block list;
  unban now also clears the metadata and report locks.
- Track daily CTI enrichment usage in Redis (crowdsec:usage:{date}); warn
  once at 80% and pause lookups until tomorrow at CROWDSEC_CTI_DAILY_QUOTA
  (default 10000, 0 = unlimited) so a via-spread DDoS cannot burn the plan.
- Add opt-in signal push to the CrowdSec community (CAPI watcher): stable
  auto-generated 48-char machine_id/password pair persisted in Redis (or via
  env), one-time registration, cached JWT login, optional Console enrollment,
  and POST /v3/signals with a ban decision, deduped per IP. Never throws and
  reports last status to the admin panel with a verify action.
- Admin page: quota usage bar, reporting status/verify channel, and CrowdSec
  block reasons in the active-blocks list.
2026-09-23 14:24:44 +02:00
openhands f32a6dadd0 feat(security): auto-block repeat offenders via CrowdSec community reputation
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Failing after 17s
CI / tests-unit (push) Skipped
CI / tests-integration (push) Skipped
CI / tests-ui (push) Skipped
CI / preflight (push) Skipped
CI / deploy (push) Skipped
- new crowdsec-api lib: CTI lookup (GET /smoke/{ip}, freemium x-api-key), verdict parser with false-positive veto, 1h Redis + in-memory verdict cache, NX lock dedupe, 403/429 backoff; writes only the shared antiddos:block:{ip} key (value "crowdsec") and never touches Cloudflare
- gate fires it fire-and-forget for IPs that already tripped a rate bucket, so known-bad IPs are hard-blocked before the local maxViolations threshold
- runtime config: crowdsecAutoBlock toggle, score threshold (0-5, default 4), block TTL (default 24h); boot defaults CROWDSEC_AUTO_BLOCK_ENABLED / CROWDSEC_BLOCK_SCORE / CROWDSEC_BLOCK_TTL_SECONDS
- admin panel: CrowdSec stat card, verify-connection action, score/TTL settings, CrowdSec source badge in the blocked-IPs list
- credentials live in env only (CROWDSEC_API_KEY); block is enforced per-request via proxy on the resolved X-Forwarded-For / CF-Connecting-IP
- tests: crowdsec-api unit suite + ddos-guard integration suite (early-block, threshold, cache dedupe, backoff)
2026-09-23 13:03:19 +02:00
openhands c56696b230 docs(env): document anti-DDoS thresholds and Cloudflare API auto-block vars
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 31s
CI / tests-integration (push) Successful in 1m44s
CI / tests-unit (push) Successful in 1m53s
CI / tests-ui (push) Successful in 3m0s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 18s
2026-09-22 23:37:39 +02:00
openhands 2c0439db6a refactor(auth): remove obsolete CONVERT_PASSWORDS env var
CI / check (push) Successful in 4m25s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m26s
Legacy md5/argon2id hashes are now always upgraded to bcrypt on login, so
the CONVERT_PASSWORDS flag is no longer used. Drop it from env schema,
.env.example, the docker installer, and test mocks.
2026-09-17 15:01:23 +02:00
openhands e153300da0 feat(auth): auto-upgrade every legacy password format to bcrypt on login
CI / check (push) Failing after 25s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
checkLogin now verifies and migrates all known password formats without
configuration: bcrypt, argon2id/argon2i/argon2d, unsalted md5/sha1/sha256/
sha512, double-md5 (UberCMS/Butterfly), salted md5 with embedded salt
(hash:salt, salt:hash, hash$salt), and a guarded plaintext fallback.

Every successful legacy login rewrites the stored hash to bcrypt, so the
CONVERT_PASSWORDS flag is no longer required (kept for deploy compatibility).
2026-09-17 14:56:31 +02:00
openhands 9a8c721111 fix: add avatar imager cache-buster for instant clothing updates
CI / check (push) Failing after 17s
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
2026-09-10 21:42:30 +02:00
openhands 25f4d74209 feat(ci): switch Cloudflare bypass from FlareSolverr to Byparr
CI / check (push) Successful in 3m59s
CI / deploy (push) Successful in 2m13s
2026-09-08 16:02:12 +02:00
Simo c4496e710b feat(docker): prepare portable images with runtime hotel configuration
CI / check (push) Successful in 1m6s
CI / deploy (push) Successful in 1m23s
2026-09-07 22:37:53 +02:00
Simo 9ec9ab31ad feat: export Catalog Studio assets and SQL to catalog repository
CI / check (pull_request) Failing after 1m21s
CI / deploy (pull_request) Skipped
CI / e2e (pull_request) Skipped
2026-09-05 11:49:00 +02:00
Simo 9af1e62655 feat: allow rank-gated housekeeping preview in production
CI / check (push) Successful in 29s
CI / deploy (push) Successful in 56s
CI / release (push) Skipped
2026-08-31 20:29:38 +02:00
Simo b1ddda66ff Revert "Merge pull request 'Complete Housekeeping migration and /ase cutover' (#52) from codex/housekeeping-complete into main"
CI / check (push) Successful in 27s
CI / release (push) Skipped
CI / deploy (push) Successful in 43s
This reverts commit 488b6e57c4, reversing
changes made to b506b4499a.
2026-08-30 21:31:34 +02:00
Simo 2b8f73a91d feat(housekeeping): cut over administration to ase 2026-08-30 20:35:22 +02:00
Simo d19ba88005 feat: add gated housekeeping foundation preview 2026-08-25 20:45:40 +02:00
openhands adb56eb80b Revert EMULATOR_MODE to rcon default, restore RCON config
CI / check (push) Successful in 28s
CI / release (push) Skipped
CI / deploy (push) Successful in 54s
2026-08-22 22:32:24 +02:00
openhands e06e419707 Replace RCON with API-only emulator transport
CI / check (push) Successful in 30s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m9s
- Switch default EMULATOR_MODE from 'rcon' to 'api'
- Remove RCON_HOST/PORT/timeout/maxRetries env vars
- Add EMULATOR_API_URL to .env and .env.example
- Update createEmulatorTransport() to use HTTP API only
- Remove rconHost/port from offline alert context
- All 827 tests pass, TypeScript compiles cleanly
2026-08-22 15:12:56 +02:00
openhands 3edc987281 feat: integrate FlareSolverr for Cloudflare bypass on clone sources
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 46s
- Add FLARESOLVERR_URL env var to .env.example
- Update fetchSourceFurnidata to fall back to FlareSolverr on CF challenges (403/HTML)
- Add docker-compose.yml with FlareSolverr service
- Add scripts/health-check.sh for FlareSolverr readiness check
- Add health:check script to package.json
- Document FlareSolverr setup in README
2026-08-04 19:00:30 +02:00
openhands 30ed2b8ce2 refactor: switch password hashing from argon2 to bcrypt
CI / check (push) Successful in 23s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m0s
- hashPassword now emits bcrypt (cost 12) instead of argon2id
- checkLogin migrates legacy md5/argon2id hashes to bcrypt on sign-in
- keep argon2id verification only as a one-time migration path
- replace ARGON2_* env vars with BCRYPT_COST
2026-08-03 18:08:57 +02:00
Simo 1f4aadb3d7 chore: remove Sentry integration
CI / check (push) Successful in 21s
CI / release (push) Skipped
CI / deploy (push) Successful in 53s
2026-08-01 22:12:31 +02:00
openhands c601ffbb76 feat(auth): switch password hashing to argon2id with legacy auto-upgrade
CI / check (push) Failing after 10s
CI / release (push) Skipped
CI / deploy (push) Skipped
- hashPassword now emits argon2id (same params as the legacy AtomCMS
  Laravel setup: memory 64MB, iterations 4, parallelism 1)
- legacy md5 and bcrypt hashes are verified and auto-upgraded to
  argon2id on successful login (CONVERT_PASSWORDS=true)
- replace BCRYPT_ROUNDS env with ARGON2_MEMORY_KB / ARGON2_ITERATIONS /
  ARGON2_PARALLELISM
- update README and add tests for argon2id and bcrypt upgrade paths
2026-08-01 17:09:29 +02:00
SimoandCursor 725e1cb338 feat(ops): health-fail alerts, optional DB backup, admin UX polish
Wire jobs-worker health probes to Discord/email alerts with cooldown, optional mysqldump, rate-limit /api/health, mark-all-read alerts, ConfirmDialog on destructive admin actions, and raise coverage floors.

Co-authored-by: Cursor <[email protected]>
2026-08-01 15:25:47 +02:00
openhands 10932a8799 feat: update .env.example RCON_PORT=3003 + EMU_PORT=3004
CI / check (push) Successful in 22s
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m14s
2026-07-30 19:06:28 +02:00
openhands d3068ce88b fix: remove invalid MySQL2 connection options parseTime/loc/socket_timeout
CI / check (push) Failing after 6s
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 4s
2026-07-30 18:08:02 +02:00
openhands 7cdb785218 Remove argon2id, use bcrypt-only password hashing 2026-07-29 22:50:17 +02:00
openhands 78fab3c9ac chore: update .env.example with high-performance Zod-proof Sentry fallbacks
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m37s
2026-07-28 18:37:41 +02:00
openhands e69c2fbb04 chore: add ultimate high-performance .env.example for Epicnextcms
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 1m15s
2026-07-28 18:32:40 +02:00
openhands 2e2aba11af Configure environment for Epicnextcms with Redis and Arcturus
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m36s
2026-07-28 18:23:51 +02:00
openhands 7f8d083763 Remove Discord and Google OAuth verification from CMS
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m58s
- Remove Discord + Google OAuth providers from NextAuth config
- Remove social login buttons (Discord/Google) from login form
- Delete link-discord.ts action and discord-verify-form.tsx component
- Simplify verify page to email-only verification flow
- Remove connections settings page and its link from settings
- Clean env.ts, .env, .env.example of Discord/Google client vars
- Remove discordUrl social icon from register, login, and homepage
- Clean translation files: remove continueWithDiscord, continueWithGoogle, connections keys
2026-07-24 11:49:16 +02:00
openhands 6985b3e6ea fix: add REDIS_URL to .env and .env.example
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m56s
2026-07-21 23:42:49 +02:00
SimoandCursor 968ca15c27 feat: jwt cache, redis health, help-ticket admin, and write rate limits
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m33s
Cut Auth.js DB load with cached jwtVersion checks, surface Redis in /api/health and deploy warnings, add admin help-center ticket reply UI, rate-limit API tickets/reactions/referral claims, and revoke PATs on sign-out-everywhere.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:58:48 +02:00
SimoandCursor fa40eebeed fix(deploy): migrate after stop and shrink DB pool
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m52s
Stage migrate hit ER_CON_COUNT_ERROR while live still held the pool. Build in stage with DATABASE_POOL_SIZE=5, run db:migrate only after stopping the service (with retries), and lower the default pool from 40 to 10.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:44:06 +02:00
SimoandCursor c46dadeda4 chore: harden deps, env validation, admin errors, and redis warnings
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m39s
Align nodemailer with Auth.js peers, bump patch deps, validate env on deploy builds, add admin error boundary, and warn when Redis is missing in production.

Co-authored-by: Cursor <[email protected]>
2026-07-21 20:19:05 +02:00
SimoandCursor 6b884ad25a Harden deploy gates, prod AUTH_SECRET, and Sentry error reporting.
Local Build and Deploy / deploy (push) Successful in 1m42s
Align onlyBuiltDependencies with the workspace, fail fast without AUTH_SECRET in production, and delete catalog_items via VARCHAR-safe SQL so page deletes do not leave orphans.

Co-authored-by: Cursor <[email protected]>
2026-07-18 19:32:15 +02:00
SimoandCursor 09f1bc2bd6 Add production observability: Sentry, pino, and sharp badge encoding.
Local Build and Deploy / deploy (push) Successful in 1m9s
Sentry is opt-in via DSN env vars; logger uses structured pino JSON in prod; badge uploads are normalized to GIF with sharp.

Co-authored-by: Cursor <[email protected]>
2026-07-17 23:09:57 +02:00
openhands ddb7e77877 Make imager URL absolute using NEXT_PUBLIC_APP_URL to avoid port issues
Local Build and Deploy / deploy (push) Successful in 53s
2026-07-15 22:45:35 +02:00
openhands a5e085e04c Add NEXT_PUBLIC_IMAGER_URL example to .env.example
Local Build and Deploy / deploy (push) Successful in 1m0s
2026-07-15 22:28:44 +02:00
openhands c5db7f5156 fix: production hardening — migration script, security fixes, structured logging, API docs, component splitting
- Create apply-migrations.ts and jobs-worker.ts scripts (package.json references)
- Convert badge leaderboard from $queryRawUnsafe to $queryRaw with Prisma.sql templates
- Fix OAuth email binding: add oauth_require_link site setting, skip 2FA-protected accounts
- Add per-user 2FA rate limiting (5/30s) to prevent TOTP brute-force
- Add structured JSON logger with levels (debug/info/warn/error)
- Split 341-line HomePage into GuestView + UserView components
- Add OpenAPI v3.1 spec at /api/openapi.json
- Add LOG_LEVEL env var, regenerate Prisma client
- Add mysql2 dependency for migration scripts
- All 58 tests pass, typecheck clean
2026-07-08 13:06:02 +02:00
openhands 5c638cd6bc perf: add bans.user_id index, Redis cache layer, rate-limit improvements, radio contest/giveaway columns, and tests
- Add DB index on bans.user_id to speed up per-request ban lookups (migration 0008)
- Replace in-process rate limiter with Redis-backed implementation with in-memory fallback
- Add Redis caching layer for site settings with TTL invalidation (migration 0009)
- Add rate limiting to resetPassword to prevent token brute-force attacks
- Update all rateLimit callers to await the now-async function
- Flesh out RadioContests and RadioGiveaways models with title, description, prize, date, and winner columns
- Update radio contest/giveaway pages to display new fields
- Add tests for rate limiter (4 tests) and password-reset actions (3 tests)
- Add REDIS_URL environment variable (optional, falls back to in-memory)
2026-07-08 12:49:24 +02:00
openhands 3527cbd34f Add AUTH_URL to env example 2026-07-04 20:06:21 +02:00
remco 16096eff0f Restore .env.example 2026-07-01 15:07:50 +02:00
remco 1de72863db latest changes 2026-07-01 15:06:52 +02:00
Simo 54ec99de6d 101%: app-level DDoS guard, PWA, /api/health, API docs, worker JAR backup
Beyond parity — the web-feasible versions of the "host-only" items plus
extras AtomCMS doesn't have:
- App-level abuse/DDoS guard (src/lib/services/abuse-guard.ts): counts
  requests per IP and auto-adds flooders to website_ip_blacklist (enforced
  by the access guard) + fires ddosDetected(). OFF by default, tunable via
  settings. The iptables layer stays host-only; this is the real app-tier
  mitigation. Access guard now also enforces the IP blacklist (cached).
- PWA: a themeable web manifest (src/app/manifest.ts) + a service worker
  (public/sw.js, cache-first assets / network-first pages) registered after
  hydration — the hotel is now installable.
- /api/health: DB + emulator(RCON) + runtime status probe.
- /developers: a public API documentation page covering every REST endpoint
  with its method, path and auth requirement.
- jobs-worker: daily emulator JAR backup (runs host-side in the worker, like
  AtomCMS's backup command) — copies + prunes; no-ops unless EMULATOR_JAR_PATH
  + EMULATOR_BACKUP_DIR are set.

Verified live (prod, amx_test): /api/health ok, manifest + sw served, docs
page renders, normal pages unaffected by the guard. tsc 0, vitest 49/49,
next build 0.
2026-06-29 18:39:23 +02:00
Simo 0cd4d06ff6 Fill the remaining gaps: badge upload, radio tools, VPN, writeable boxes
Built the admin tools previously listed as missing:
- Badge upload (/admin/badges): uploads a <code>.gif into the emulator's
  badge dir via BADGE_UPLOAD_DIR (node:fs); validated code/type/size,
  logged. Made configurable rather than skipped.
- Radio tools: /admin/radio/api-keys (CRUD, server-generated keys),
  /admin/radio/autodj (Auto-DJ playlist CRUD), /admin/radio/embed (embed
  snippet generator), /admin/radio/points (points settings),
  /admin/radio/monitoring (live stream/now-playing/listeners status).
  radio_api_keys + radio_auto_dj_playlist already had real columns.
- /admin/vpn: VPN/proxy detection config (block toggle + provider + key),
  complementing /admin/ip's raw blacklist.
- Writeable boxes: new website_writeable_boxes table (model + migration
  0006) + /admin/writeable-boxes CRUD; active boxes render on the public
  home page. env: BADGE_UPLOAD_DIR.

Verified live (prod, amx_test): all 8 pages render with real data; a test
writeable box appeared on the public home and was reverted. tsc 0,
vitest 49/49, next build 0 (7 new admin routes).
2026-06-28 21:04:34 +02:00
Simo 4eccd146ba Default password hashing to bcrypt (fits varchar(64) users.password)
Verified against the live AtomCMS DB: users.password is varchar(64), so
argon2id (~97 chars) overflows the column and registration/upgrade fail
with 'value too long'. bcrypt (60-char $2y$) fits and matches the
existing accounts. hashPassword() now emits bcrypt by default; set
PASSWORD_HASH=argon2id to opt back in (needs a widened column).
verifyPassword() still accepts both, so existing logins keep working.

Verified end-to-end against the live DB: bcrypt $2y$ login round-trips
(correct=true, wrong=false). tsc 0, vitest 8/8 (password suite).
2026-06-28 16:26:33 +02:00
Simo 7daeccb832 Add dark mode, i18n, messenger/moderation/verify, admin CRUD parity
Web-tier features completing the AtomCMS→Next.js conversion (slice 2):

UI/UX:
- Dark mode: html.dark CSS-var overrides + ThemeSwitcher (localStorage,
  no-flash boot script) wired into the nav.
- i18n (next-intl, cookie-based / no URL routing): en + it catalogs,
  request.ts, provider in root layout, LanguageSwitcher; shell (nav,
  header, footer) fully translated. URLs + access-guard unchanged.
- globals.css: --muted/--border aliases used across admin pages.

User features:
- /messages: offline messages + friend-request accept (server action
  re-reads session, two directional rows, idempotent).
- Email verification: signed-token /verify route + sendVerification wired
  into register (best-effort, never blocks signup).
- Article reactions: toggle UI on news/[slug] + server action.
- Content moderation service (website_wordfilter + optional OpenAI
  moderations, fail-open) wired into article comments + guestbook.

Admin CRUD parity (Filament replacement):
- /admin/shop (+ new/[id]) packages CRUD + read-only orders.
- /admin/transactions read-only PayPal log.
- /admin/permissions, /admin/tags, /admin/ads (+ new/[id]),
  /admin/help-questions (+ new/[id]), /admin/radio/history,
  /admin/users/[id]/edit. All gated by requireStaff + logStaffActivity.

Verified: tsc 0, vitest 48/48, next build 0 (all routes incl. new
admin CRUD + /messages + /verify).
2026-06-28 16:06:42 +02:00
Simo 22d53d0e9c Add security middleware, audit log, alerts, PayPal, cron, radio + apps
Security (launch blockers):
- src/middleware.ts (edge): forwards x-pathname + real client IP.
- access-guard.ts (Node, from root layout): routes non-staff to /maintenance
  when maintenance mode is on, banned users to /banned. New /banned + /maintenance
  pages (the consumers the admin toggle was missing). Admin layout enforces
  force_staff_2fa before /admin.
- staff-activity.ts audit log wired into ban/lift/give-currency/set-rank actions.

Infra (parallel agents): alert service (alert_logs + Discord embed + email),
PayPal top-up (create/capture API routes + /shop/topup), cron worker
(scripts/jobs-worker.ts via croner: emulator-ping->alert, maintenance-check,
bans-cleanup), social connections page, admin radio settings/banners/ranks.
Public radio subsystem: /radio (+schedule, shouts+post, contests, giveaways,
apply, leaderboard) and /apply/staff + /apply/team submission forms. Radio nav
link added. .env.example documents the new optional vars.

(radio song-requests dropped: its table is a stub in AtomCMS — columns added by
un-modeled alter-migrations.)

Verified: tsc exit 0, vitest 48/48, next build exit 0 (82 page routes).
2026-06-28 15:10:19 +02:00