Commit Graph
198 Commits
Author SHA1 Message Date
Simo 01570874a8 fix: map furni imports to production gamedata 2026-08-02 13:16:51 +02:00
Simo b3245a18ea fix: bootstrap admin CSRF tokens 2026-08-02 11:46:43 +02:00
Simo 1f4aadb3d7 chore: remove Sentry integration 2026-08-01 22:12:31 +02:00
openhands 22d455da7a fix(auth): drop nonexistent account_blocked column from login lookup
getLoginUser selected users.account_blocked, which does not exist in the
DB (nor the Drizzle schema). Every credentials authorize() call threw a
SQL error -> NextAuth CallbackRouteError -> 'error=Configuration', so no
login could ever succeed. Remove the phantom column from the query and
LoginUser interface.

Also fix all remaining biome noNonNullAssertion / noExplicitAny lint
warnings so CI's check job (biome:lint) passes and the push deploy runs.
2026-08-01 17:38:43 +02:00
SimoandCursor 16191cef14 fix(admin): harden clothing/pets/effects/clone imports
Align grids on data.items, only treat SSE done as success, hard-fail
clothing sets when libs fail, and add Cancel via AbortController.

Co-authored-by: Cursor <[email protected]>
2026-08-01 15:56:38 +02:00
SimoandCursor 9c4949186c feat(admin): server-safe StatusCard and Import hub polish
Split OnlineUsersWidget from StatusCard, decouple ad delete button, sync badge import to ExternalTexts+WebsiteBadges, add Import section hub with cancelable SSE jobs and upload SQL option.

Co-authored-by: Cursor <[email protected]>
2026-08-01 15:48:21 +02:00
SimoandCursor 725e1cb338 feat(ops): health-fail alerts, optional DB backup, admin UX polish
Wire jobs-worker health probes to Discord/email alerts with cooldown, optional mysqldump, rate-limit /api/health, mark-all-read alerts, ConfirmDialog on destructive admin actions, and raise coverage floors.

Co-authored-by: Cursor <[email protected]>
2026-08-01 15:25:47 +02:00
SimoandCursor 3bd712e744 fix(admin): polish tickets, photos purge note, drizzle contracts
Add queue banners/counts on ticket detail pages, document local-only photo purge, and harden Drizzle Kit smoke contracts after Prisma removal.

Co-authored-by: Cursor <[email protected]>
2026-08-01 15:07:54 +02:00
SimoandCursor d8199ea1e4 feat(admin): unified ticket inbox over CMS and help-center queues
Merged read-model inbox at /admin/tickets and /mod/tickets with type badges and deep links; CMS-only lists moved to /desk. No DB schema merge.

Co-authored-by: Cursor <[email protected]>
2026-08-01 14:49:19 +02:00
SimoandCursor 9aa4f331bf refactor(db): migrate app pages and APIs from Prisma facade to Drizzle (4)
Co-authored-by: Cursor <[email protected]>
2026-08-01 14:15:36 +02:00
SimoandCursor 580972c0a0 refactor(db): migrate app pages and APIs from Prisma facade to Drizzle (3)
Co-authored-by: Cursor <[email protected]>
2026-08-01 14:15:32 +02:00
SimoandCursor 2cd0863cb8 refactor(db): migrate app pages and APIs from Prisma facade to Drizzle (2)
Co-authored-by: Cursor <[email protected]>
2026-08-01 14:15:28 +02:00
openhands beae86194d fix: resolve biome lint errors in prisma-facade
- Fix noPrecisionLoss on BIGINT UNSIGNED max value (2^64-1) with biome-ignore comments
- Fix noThenProperty on custom thenable with biome-ignore comment
- Auto-format remaining files (biome check --write)
- Re-stage auto-fixed files from previous commit
2026-07-31 14:17:06 +02:00
openhands 56061e41d4 refactor: replace Prisma ORM runtime with Drizzle ORM facade
- Replace Prisma client runtime with Drizzle ORM (zero Prisma engine/query engine in production)
- Add Prisma-compatible facade (@/lib/prisma-facade.ts) backed by Drizzle for backwards compatibility
- Runtime queries route through Drizzle ORM; @prisma/client is now devDependency (types only)
- Remove @prisma/adapter-mariadb dependency; delete prisma-pool.ts and types/prisma.ts
- New Drizzle schema layer: src/db/schema.ts (176 tables) and src/lib/db.ts (connection)
- Update README documenting the dual-layer ORM architecture
- Restore src/generated/ gitignore (build artifact for local type generation)
- 0 TypeScript errors, 583 tests passing

The facade intentionally uses `any` types to match the Prisma Client API surface,
allowing existing code to run unmodified while routing queries through Drizzle at runtime.
2026-07-31 14:11:03 +02:00
SimoandCursor 0224b34f15 feat(admin): configurable sidebar menu order and visibility
Co-authored-by: Cursor <[email protected]>
2026-07-30 21:45:53 +02:00
SimoandCursor 3ac5d6f4f6 chore(ops): strip redundant force-dynamic and probe Redis in ops health
Co-authored-by: Cursor <[email protected]>
2026-07-30 21:33:40 +02:00
SimoandCursor 98613af875 feat(admin): items_base browser and AdminPageShell on core pages
Co-authored-by: Cursor <[email protected]>
2026-07-30 20:41:31 +02:00
SimoandCursor 3ad3f9512c feat(admin): ban appeals, photos polish, economy adjust, staff smoke
Co-authored-by: Cursor <[email protected]>
2026-07-30 20:23:03 +02:00
SimoandCursor 58fae1f90f feat(admin): analytics redis cache, shared ops health, ticket queue clarity
Co-authored-by: Cursor <[email protected]>
2026-07-30 19:57:00 +02:00
SimoandCursor 6eab5e5343 feat(admin): ACL repair, mod users, ticket clarity, ops online hub
Add Repair nav grants on permissions, /mod/users without email/IP, shared ticket queue banners, and shared online roster on CommandoCentrum.

Co-authored-by: Cursor <[email protected]>
2026-07-30 19:37:01 +02:00
SimoandCursor b6b8625246 feat(mod): help-center tickets queue with reduced PII
Co-authored-by: Cursor <[email protected]>
2026-07-28 20:26:57 +02:00
SimoandCursor 01126207dc fix(admin): live online widget, ticket queue clarity, i18n+contract coverage
Co-authored-by: Cursor <[email protected]>
2026-07-28 20:22:50 +02:00
openhands 423a33200e chore: improve tooling, linting, testing, and CI
- Add LICENSE file (CC BY-NC-SA 4.0)
- Add .nvmrc pinning Node 22
- Add Renovate config with daily schedule and Gitea Actions workflow
- Reduce ESLint max-warnings from 1000 to 50
- Re-enable Biome a11y/security recommended rules
- Fix Biome lint issues (a11y, hook deps, SVG labels, checkbox semantics)
- Improve CI: run on pushes to feat/fix branches, add pnpm audit
- Add Vitest coverage with v8 provider and thresholds
- Add E2E tests (auth, admin, navigation specs)
- Add admin-maintenance server action test
- Install @vitest/coverage-v8
- Ignore coverage/ directory
2026-07-27 17:03:09 +02:00
openhands 17847545dd Improvements: remove dead config, fix ESM, add URL validation, unify types, add missing logging
- Remove .prettierrc (dead config, Biome replaces Prettier)
- Rename lighthouserc.json to lighthouserc.cjs with module.exports for ESM compat
- Add logger.warn to empty catch blocks in auth, register, site-settings, prisma-cache, redis, security, rate-limit
- Unify ActionResult type: action-helper.ts uses 'ok' consistent with safe-action-shared.ts
- Add noUnusedLocals + noUnusedParameters to tsconfig + fix 25 pre-existing unused vars
- Replace barrel export src/types/index.ts with direct @/types/common imports
- Make trustHost conditional (development only) in auth.ts
- Add pre-flight URL validation to update-Nitrov3.sh to catch image.library.url misconfigurations
- Improve NITRO_IMAGE_LIBRARY_URL content validation in pre-flight & post-compute checks
2026-07-26 20:28:11 +02:00
openhands 1acace49d0 refactor: full codebase overhaul — dead code removal, env validation, logger migration, date consolidation, Prisma schema cleanup, button consistency, useEffect deps, test coverage
- env.ts: added 10 missing Zod-validated env vars (imager, paypal currency, argon2/bcrypt params)
- Migrated 6 modules from process.env to validated env.* (auth, proxy-auth, paypal, password, redis, imager, moderation, alert, logger)
- Replaced console.warn/error with pino logger in 9 server-side modules
- Removed 50+ dead exports (SWF wrappers, coalesceHotelName, signIn, isStaff re-export, formatTimestamp, Skeleton/SkeletonCard, 4 unused housekeeping sections)
- Consolidated date formatting: 28 files migrated to shared formatDate() from @/lib/format-date
- Wired 4 radio/settings API routes through cached siteSettings service instead of raw Prisma queries
- Added getMany()/getAll() helpers to SiteSettings service
- Removed 88 dead Prisma model definitions (schema 2763→1846 lines)
- Created admin action-helper.ts with wrapAction() for standardized error handling
- Fixed useEffect dependency arrays in 4 data-heavy components
- Replaced raw btn CSS classes with shadcn Button component across admin pages
- Stripped dead i18n namespaces (common, pages.client) from all 22 translation files
- Removed 2 dead scripts (create-release.sh, check-local-imports.ts)
- Fixed knip.json configuration
- Added 7 new test suites: format-date, paypal, moderation, alert, webhook, action-helper, and fixed password.test.ts for env mocking
- All 358 tests passing across 72 test files
- TypeScript: 0 errors
2026-07-25 17:33:06 +02:00
openhands 5fa342018d chore: remove dead code and unused dependencies
- Delete 4 unused files detected by knip
- Remove lint-staged, eslint-config-prettier, plausible-tracker
- Clean up knip.json entry patterns
2026-07-24 11:59:50 +02:00
SimoandCursor 255c09b9fd fix(admin): restore sidebar categories via ACL grant repair
Co-authored-by: Cursor <[email protected]>
2026-07-22 21:47:23 +02:00
SimoandCursor ce6e8235cc fix(admin): housekeeping TS returns + clearer permissions UX
Co-authored-by: Cursor <[email protected]>
2026-07-22 21:39:01 +02:00
SimoandCursor 75cace41ea feat(mod): tickets+team tabs; retire HK writes for live ACL
Co-authored-by: Cursor <[email protected]>
2026-07-22 21:35:35 +02:00
SimoandCursor 084cca6ea4 feat(mod): lite /mod panel + clarify ACL vs housekeeping legacy
Co-authored-by: Cursor <[email protected]>
2026-07-22 21:29:32 +02:00
SimoandCursor a384c9a8bb feat(admin): guilds console + user sanctions timeline
Co-authored-by: Cursor <[email protected]>
2026-07-22 21:19:16 +02:00
SimoandCursor 025af147cd feat(admin): marketplace console + analytics degraded banners
Co-authored-by: Cursor <[email protected]>
2026-07-22 19:06:54 +02:00
SimoandCursor f150aea8b9 feat(admin): P1 — clearer tickets labels, pagination, min_staff_rank, analytics errors
Co-authored-by: Cursor <[email protected]>
2026-07-22 19:04:45 +02:00
SimoandCursor 75cdfdebe4 fix(admin): P0 integrity — permanent bans, ACL sidebar, rank guards
Co-authored-by: Cursor <[email protected]>
2026-07-22 19:01:59 +02:00
SimoandCursor 8d28739ca6 feat(admin): expand/collapse all sidebar groups with scrollable nav
Co-authored-by: Cursor <[email protected]>
2026-07-22 18:49:49 +02:00
SimoandCursor e00e9ca2dc refactor: centralize hotel name fallback via FALLBACK_HOTEL_NAME
Route all user-facing Atom hotel defaults through resolveHotelName (settings then HOTEL_NAME env then brand constant). Exclude Playwright e2e from tsconfig until deps are installed.

Co-authored-by: Cursor <[email protected]>
2026-07-22 18:45:59 +02:00
SimoandCursor 968ca15c27 feat: jwt cache, redis health, help-ticket admin, and write rate limits
Cut Auth.js DB load with cached jwtVersion checks, surface Redis in /api/health and deploy warnings, add admin help-center ticket reply UI, rate-limit API tickets/reactions/referral claims, and revoke PATs on sign-out-everywhere.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:58:48 +02:00
SimoandCursor 803e8f36c1 feat: shop buy, forum replies, tickets, messages, sessions, and UX hardening
Complete remaining product gaps: credit-based shop purchases, guild thread replies, help ticket detail/reply/close, offline message compose, sign-out-everywhere via JWT version, ads delete confirm, soft-fail feedback, rate limits, loading states, and single auth() in site layout.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:21:02 +02:00
SimoandCursor ed7db6e048 feat: public events/polls, friends graph, captcha, SSE hardening, and admin UX
Ship product gaps: register/vote pages, friend add/accept/decline/remove, email verify TTL, captcha on login/forgot, soft-fail user actions, SSE abort/shared client, Commando Centrum error toasts, admin delete for events/polls, and IT/NL i18n fills.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:08:33 +02:00
SimoandCursor c46dadeda4 chore: harden deps, env validation, admin errors, and redis warnings
Align nodemailer with Auth.js peers, bump patch deps, validate env on deploy builds, add admin error boundary, and warn when Redis is missing in production.

Co-authored-by: Cursor <[email protected]>
2026-07-21 20:19:05 +02:00
openhands 827595ef00 fix: mobile responsiveness for all admin pages
- DataTable: overflow-x-auto on table wrapper (affects users, rooms, tickets)
- Radio: overflow-x-auto wrappers around all 3 tables (shouts, applications, schedules)
- Catalog items: responsive grids (grid-cols-1 sm:grid-cols-3) in Add/Edit dialogs
- Catalog tabs: TabsList overflow-x-auto for narrow screens
- Import clone: pagination flex-wrap to prevent overlap on small screens
2026-07-21 16:52:58 +02:00
openhands d189bb5af4 fix: mobile responsive improvements
- Audit: responsive summary cards (grid-cols-2 mobile, p-3), responsive empty states
- Repair-icons/sync-all: log area horizontal scroll (overflow-x-auto, whitespace-nowrap)
- Upload furni: tighter mobile padding (p-4 sm:p-5)
- Nitro client: compact toolbar on mobile (smaller buttons, tighter gap, top-2/left-2)
2026-07-21 16:47:02 +02:00
openhands 43dacea672 fix: add auth error detection to sync-all client 2026-07-21 15:39:38 +02:00
openhands e4b6d5db21 fix: detect auth errors in SSE clients
Audit and repair-icons clients now check the Content-Type before reading the
stream. If the server returns JSON (e.g. CSRF/permission error), the error
message is shown as a toast instead of silently consuming the response as
an empty SSE stream.
2026-07-21 15:37:52 +02:00
openhands bebd65c056 fix: refactor audit to SSE streaming, improve error handling
- Changed from blocking JSON endpoint to SSE streaming (like sync-all/repair-icons)
- Progress updates during each audit phase with item counts
- Proper error handling with typed AuditEvent for every failure path
- AbortController support for the client
- Shows real-time progress for each check section
2026-07-21 15:33:15 +02:00
openhands 19e4e10b1d feat: add catalog audit page
Checks for:
- items_base entries without catalog_items (not purchasable)
- catalog_items referencing non-existent items_base
- Items without .nitro or icon files on disk
- Duplicate classnames
- Items missing from all configured clone sources
2026-07-21 15:24:58 +02:00
openhands 90107c83d5 fix: rewrite repair-icons with proper error handling and progress
- Wrap all DB/file operations in try-catch, send error events via SSE
- Report skipped/progress events for items that already have icons
- Add 'started' event with total count so the UI shows real-time progress
- Catch route-level errors and stream them instead of returning JSON
- Use log line content as React key instead of array index
2026-07-21 15:04:43 +02:00
openhands 13cb5f8670 fix: use admin theme CSS variables in upload-furni-client
Replace hardcoded border-gray-300 and text-yellow-* classes
with semantic admin theme tokens (border-input, --admin-warning).
2026-07-21 14:56:38 +02:00
openhands 804daeffca feat: add .nitro upload + sync-all + repair-icons features
- Upload .nitro bundles directly with full DB, catalog, and furnidata integration
- Generate SQL migration files on upload (optional)
- Auto-sync missing furniture from all configured clone sources (SSE batch)
- Repair missing icons by extracting from local .nitro or downloading from sources
- All behind ASSETS_IMPORT permission
2026-07-21 14:53:26 +02:00
openhands 5e8a13a84f fix: resolve all biomaly lint errors and warnings across CMS
- Fix CSS parser config (tailwindDirectives enabled)
- Fix noDangerouslySetInnerHtml via SanitizedHtml component
- Fix useExhaustiveDependencies in catalog-manager-dialog
- Fix noArrayIndexKey across 26 files (stable keys)
- Fix SVG a11y (titles, roles, aria-labels)
- Fix label/input associations (htmlFor/id pairs)
- Fix static element interactions (role + keyboard support)
- Fix noImgElement, noDescendingSpecificity (disabled - external Habbo URLs)
- Fix noNonNullAssertion, useTemplate, unused vars/imports
- Add SanitizedHtml shared component
- Migrate biome.json to 2.5.4 schema
2026-07-20 17:41:53 +02:00