Simo 54ec99de6d 101%: app-level DDoS guard, PWA, /api/health, API docs, worker JAR backup
Beyond parity — the web-feasible versions of the "host-only" items plus
extras AtomCMS doesn't have:
- App-level abuse/DDoS guard (src/lib/services/abuse-guard.ts): counts
  requests per IP and auto-adds flooders to website_ip_blacklist (enforced
  by the access guard) + fires ddosDetected(). OFF by default, tunable via
  settings. The iptables layer stays host-only; this is the real app-tier
  mitigation. Access guard now also enforces the IP blacklist (cached).
- PWA: a themeable web manifest (src/app/manifest.ts) + a service worker
  (public/sw.js, cache-first assets / network-first pages) registered after
  hydration — the hotel is now installable.
- /api/health: DB + emulator(RCON) + runtime status probe.
- /developers: a public API documentation page covering every REST endpoint
  with its method, path and auth requirement.
- jobs-worker: daily emulator JAR backup (runs host-side in the worker, like
  AtomCMS's backup command) — copies + prunes; no-ops unless EMULATOR_JAR_PATH
  + EMULATOR_BACKUP_DIR are set.

Verified live (prod, amx_test): /api/health ok, manifest + sw served, docs
page renders, normal pages unaffected by the guard. tsc 0, vitest 49/49,
next build 0.
2026-06-29 18:39:23 +02:00

atomcms-next

AtomCMS (Laravel) converted to Next.js 16 (App Router) + Prisma 7 against the same Arcturus-emulator MySQL/MariaDB database. Auth via NextAuth (argon2id/bcrypt + md5→argon2id upgrade), RCON to the emulator, full public site + admin panel.

Try it now (no database)

The dev/preview server is already running — open:

http://localhost:3000

Public pages render with fallback defaults (empty data). Login / register / admin need a database (below).

Try it for real (your AtomCMS database)

Point it at your live (or a copy of your) AtomCMS database to log in with real accounts and see real data:

  1. Edit atomcms-next/.env:
    DATABASE_URL=mysql://USER:PASSWORD@HOST:3306/DBNAME
    DATABASE_CONNECT_TIMEOUT_MS=10000
    AUTH_SECRET=any-long-random-string-at-least-32-chars
    HOTEL_NAME=YourHotel
    # Optional emulator link (for RCON: give credits, ban, motto, disconnect):
    RCON_HOST=127.0.0.1
    RCON_PORT=3001
    
  2. Restart the server (pnpm -C atomcms-next start, or pnpm dev).
  3. Log in at /login with any existing account. Staff (rank ≥ min_staff_rank, default 7) get the /admin panel. New users can /register.

It reads the schema you already have — no migrations are run against the emulator tables (introspect/conform only). prisma generate is already done; if you add tables, pnpm -C atomcms-next prisma:generate.

Run it yourself

cd atomcms-next
pnpm install          # already done
pnpm dev              # dev server (hot reload) on :3000
# or:
pnpm build && pnpm start   # production
pnpm typecheck        # tsc --noEmit
pnpm test             # vitest (unit tests)

What's built

  • Public: home, news (+comments/reactions), shop, marketplace, community, rankings, staff, photos, guilds, rares, leaderboard, help (+tickets), profile /u/<name> (badges/photos/guestbook), client launcher /client (SSO ticket), login / register / logout, settings, voucher redeem.
  • Admin (/admin, staff-gated): users (give currency/motto/rank/alert/kick via RCON), rooms, articles, catalog, vouchers, badges, radio, achievements, rare-values, photos, bans, applications, word-filter, IP, logs, teams, housekeeping, permissions, emulator config, email templates, calendar, subscriptions, CMS settings.
  • Core: Prisma data layer (190 models), NextAuth auth core (byte-compatible argon2id/bcrypt/md5 + SSO ticket + Laravel encrypter + TOTP), RCON client + currency service, atom visual theme (self-hosted Nunito).
S
Description
No description provided
Readme CC-BY-SA-4.0
172 MiB
1 Stars 1 Watchers 0 Forks
Languages
TypeScript 95.9%
JavaScript 1.4%
Shell 1.1%
CSS 1.1%
PHP 0.3%
Other 0.1%