Commit Graph
121 Commits
Author SHA1 Message Date
SimoandCursor 09f1bc2bd6 Add production observability: Sentry, pino, and sharp badge encoding.
Sentry is opt-in via DSN env vars; logger uses structured pino JSON in prod; badge uploads are normalized to GIF with sharp.

Co-authored-by: Cursor <[email protected]>
2026-07-17 23:09:57 +02:00
SimoandCursor ef2c3324b4 Prune unused deps, bump safe minors, add server-only guards.
Remove unused translate/jpeg types packages; refresh patch updates; mark Redis/site-settings/gamedata hotel as server-only with a Vitest stub.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:53:56 +02:00
SimoandCursor a798999440 Refresh Suggest hotel label from live CMS setting.
Avoid stale SSR/Redis cache keeping Suggest IT after habbo_gamedata_hotel changes.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:36:10 +02:00
SimoandCursor 785c1b6976 Fix client bundle pulling Redis/Prisma via habbo gamedata hotel.
Keep hotel list helpers client-safe; load CMS setting only from a server module.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:30:46 +02:00
SimoandCursor d1baaf798a Add multi-hotel Habbo gamedata locale in CMS settings.
Furni name suggestions, import enrichment, and badge texts now follow habbo_gamedata_hotel instead of hardcoded habbo.it.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:28:18 +02:00
SimoandCursor 7bc0845932 Fix catalog items missing due to page_id VARCHAR mismatch.
Use raw SQL for counts/loads/creates/moves so Habbo DBs with VARCHAR page_id and no AUTO_INCREMENT still show and persist furni.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:21:49 +02:00
SimoandCursor 1d8efefce4 Fix Visual Manager empty categories: seed roots, harden tree API.
Seed root tabs from SSR, load the full tree without CLEAR_TREE races, coerce parent ids, and tolerate catalog_items page_id type mismatches so category pages actually appear.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:02:53 +02:00
SimoandCursor b52e25578d Harden catalog admin: fix translate/quick-add, RCON sync, and confirm UX.
Restore broken Quick Add search, correct Translate saves to items_base and FurnitureData, reparent page deletes, sync RCON on create/toggle/BC mutations, and replace native confirms/prompts with dialogs.

Co-authored-by: Cursor <[email protected]>
2026-07-17 21:12:58 +02:00
SimoandCursor 1039044e48 Improve admin UX: hub i18n, dynamic topbar, settings strings, staff logs DataTable.
Co-authored-by: Cursor <[email protected]>
2026-07-17 20:14:55 +02:00
SimoandCursor 49d204e85c Remove import/repair feature and related API routes.
Co-authored-by: Cursor <[email protected]>
2026-07-17 18:52:38 +02:00
SimoandCursor 25f01b61b3 Migrate UI primitives from Radix to Base UI.
Co-authored-by: Cursor <[email protected]>
2026-07-17 18:31:07 +02:00
SimoandCursor d2c0619f2f Clean up admin hub UX: tabs, chrome, and redundant headers.
Wire orphan routes into hub tabs, group Radio into primary/tools rows, show theme/language once on desktop, and remove duplicate page titles under AdminHubChrome.

Co-authored-by: Cursor <[email protected]>
2026-07-17 18:01:01 +02:00
openhands a3b077c488 feat: add smooth site-wide animations with framer-motion
- Add framer-motion and tailwindcss-animate for transitions
- Add page transitions via AnimatePresence in the site layout
- Convert nav dropdown and mobile menu to animated motion components
- Add entry animation to the radio player widget
- Add reveal/stagger animations to the home page views
- Add shared motion utilities and reusable animated components
2026-07-16 20:58:18 +02:00
openhands 5cbe303e43 feat: make panel border color configurable via theme editor
- Add panel_border_color to THEME_COLOR_KEYS and base palettes
- Register panel-border-color CSS variable
- Fetch and inject panel_border_color in ThemeVars
- Add Panel border field to admin theme page
- Replace hardcoded #e9b124 with var(--panel-border-color) in UserView
2026-07-16 15:53:53 +02:00
openhands ddb7e77877 Make imager URL absolute using NEXT_PUBLIC_APP_URL to avoid port issues 2026-07-15 22:45:35 +02:00
openhands 19faa5615c Serve avatars from site's own /imaging endpoint instead of habbo.com
- Change default public imager URL from habbo.com to /imaging
- /imaging and /api/imaging/avatar now proxy from upstream (habbo.com) instead of redirecting
- Add resolveUpstreamBase() to separate public URL from upstream URL
- Update admin settings default and description
2026-07-15 22:23:09 +02:00
openhands 71f154cf52 Add /imaging route for avatar proxy and prevent redirect loops 2026-07-15 22:14:58 +02:00
openhands 169f658097 Add img_format=png to imager URLs and extend navbar color picker with 10 new colors 2026-07-15 22:09:47 +02:00
SimoandCursor 8cce8837bc Serve avatars from Habbo imager instead of broken self-hosted proxy.
Co-authored-by: Cursor <[email protected]>
2026-07-15 21:51:02 +02:00
SimoandCursor 7b6c02c07d Make admin light/dark mode follow real palettes end-to-end.
Light admin derives from the public light theme; dark keeps HK overrides. Remap inputs, cards, muted text, and kill the public wallpaper on admin so fonts and boxes stay readable in both modes.

Co-authored-by: Cursor <[email protected]>
2026-07-15 21:37:25 +02:00
SimoandCursor 363c9b3d56 Reorganize admin into tabbed hubs with a condensed sidebar.
Replace the long flat nav with hub entries, shared AdminHubChrome tabs, and AdminPageShell. Existing URLs stay stable; Settings/Radio and other sections now share one chrome.

Co-authored-by: Cursor <[email protected]>
2026-07-15 21:29:36 +02:00
SimoandCursor 0096c55f96 Fix theme switcher desync and auto-correct unreadable saved colors.
Sync dark-mode state from the DOM after mount so admin text no longer needs a double toggle, and normalize text/button colors against their surfaces on theme save.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:54:46 +02:00
SimoandCursor d7278c77f9 Fix automatic readable text contrast for public and admin themes.
Derive admin/public text colors from WCAG contrast, unify ThemeVars CSS emission, and keep navbar overrides in sync with readable vars.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:41:34 +02:00
SimoandCursor 9d4d409b77 Restore self-hosted /api/imaging/avatar (and badge) endpoints.
The clothing importer and imager helpers pointed at a missing route; proxy Habbo with disk/memory cache so avatars work again.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:41:18 +02:00
SimoandCursor 3403d3b19f Fix admin permissions bounce, prefixes APIs, and Italian UI leftovers.
Gate permissions on ACL manage + resolve super-admin from live user ranks, restore prefixes API routes, and anglicize hardcoded admin copy with nav i18n.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:33:00 +02:00
SimoandCursor 0e89d03940 Finish fine-grained ACL across remaining admin pages and actions.
Replace leftover requireStaff gates with module PERMS, drop hardcoded room rank thresholds, and expand contract tests so admin mutations cannot regress to dashboard-only checks.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:15:22 +02:00
SimoandCursor 3c8a8ff888 Extend fine-grained ACL to settings, content, shop, and radio.
Gate pages and mutations on module PERMS instead of dashboard-only staff checks, add radio view/edit slugs with migration 0015, and expand the operations contract tests.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:11:55 +02:00
SimoandCursor f2427b3483 Harden admin ACL on critical write paths.
Gate translations, RCON, and user mutations on SETTINGS_EDIT, RCON_EXECUTE, and USERS_EDIT instead of dashboard/rank checks; redirect the legacy user-edit URL to the guarded canonical page.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:07:15 +02:00
openhands 59b63d6e70 Fix real Biome bugs: inner declarations, dup keys, assign-in-expr, implicit any, cookie, a11y svg/keyboard, json 2026-07-14 18:58:40 +02:00
openhands 90d249e50e Fix typecheck error: use non-null assertion after expect(pair).toBeDefined() 2026-07-14 16:12:01 +02:00
openhands 026cb55cf3 Fix mobile menu blur and improve admin sidebar text contrast 2026-07-14 15:36:17 +02:00
openhands 2455a4850e fix: make useServerAction accept void-returning actions and remove dead queryCount
- Type run()'s action param as Promise<unknown> and cast result (Biome strips void from unions)
- Remove unused queryCount field increment in DbService (dead code)
- Reformat theme-contrast test pair assertions
2026-07-13 22:25:56 +02:00
openhands 045dc06a1f fix: resolve type errors and migrate pnpm settings to pnpm-workspace.yaml
- Move pnpm.onlyBuiltDependencies/overrides from package.json to pnpm-workspace.yaml (clears pnpm WARN)
- Allow useServerAction run() to accept actions returning void
- Make adminAction/authAction input optional so no-schema actions can be called without args
- Return ActionResult from updateBcPage
- Fix categoryPageMap value type (number | undefined)
- Declare DbService.queryCount field
- Use definite assignment for release in withFurniDataLock
- Narrow pair type in theme-contrast test
2026-07-13 22:10:50 +02:00
openhands df38dccbf1 style: format code biome 2026-07-13 21:57:41 +02:00
openhands 8efd032cc6 style: format code with prettier agian 2026-07-13 21:41:52 +02:00
openhands e6d7f2280b Add named custom theme presets (save/load/rename/delete) in admin theme editor 2026-07-13 20:42:40 +02:00
openhands 8721cfcea4 Make HK sidebar menu text always 100% visible
- Set muted sidebar text equal to the readable sidebar text so inactive
  nav items and section labels are never dimmed
- Active item remains distinguished by its accent background and border
2026-07-13 20:13:35 +02:00
openhands d2243b5611 Fix HK sidebar menu text readability
- Derive sidebar text color from the main admin text against the actual
  sidebar background (not canvas/surface), guaranteeing contrast
- Brighten muted sidebar text to 82% of the readable text color so
  inactive nav items and section labels stay clearly visible
2026-07-13 20:10:52 +02:00
openhands a16d9859e8 Add admin HK color customization fields to theme editor
- Add 6 new admin color DB keys (admin_canvas, admin_surface, admin_text,
  admin_text_muted, admin_border, admin_sidebar_bg) that override the
  derived admin palette
- Extract adminPaletteCss() from themePaletteCss() for reuse
- Generate admin CSS variables in both :root and html.dark with overrides
- Persist admin color settings via saveTheme action
- Add Admin panel (HK) section to /admin/theme with color pickers
2026-07-13 19:49:19 +02:00
openhands 4dcf6fdce8 Fix admin sidebar colors: use consistent dark sidebar instead of navbar colors for professional look 2026-07-13 19:32:27 +02:00
openhands debee7300e Fix admin sidebar contrast: muted text now visually distinct from regular text 2026-07-13 19:21:53 +02:00
openhands bef458dbf8 Rename executeRaw → executeRawUnsafe to make SQL injection risk explicit
The method wraps Prisma's  which trusts the caller
to use ? placeholders. The Unsafe suffix is a naming convention
that signals 'review caller for parameterization'.
2026-07-13 12:41:11 +02:00
openhands e2fc7ea1a4 Complete security hardening: zero-migration foundation, edge headers, rate-limit atomics, body limits
- Make @/lib/safe-action re-export from foundation layer so all 13+
  existing server actions instantly get request tracing, rate limiting,
  and structured error handling without any code changes
- Add HSTS, CSP, X-Frame-Options, X-Content-Type-Options to edge proxy
  (src/proxy.ts) — ran at Cloudflare/Vercel edge for all non-asset routes
- Fix rate-limit.ts race condition: compute newCount before assignment
  to shrink the read-modify-write window; add memory-key prefix to
  avoid collisions with Redis keys
- Add request body size limit (10 MB default) to api-handler.ts with
  per-route override via maxBodyBytes option
- Remove unused imports and clean up backward-compat types
2026-07-13 12:09:43 +02:00
openhands f6ad030c5b Add EpicNext CMS foundation layer and fix critical security gaps
- Create src/lib/foundation/ (860 LOC, 9 files): typed action wrappers,
  DbService with health checks, CSRF validation, safe redirects,
  AsyncLocalStorage request tracing, branded types, reusable Zod schemas
- Migrate moderation.ts and user-settings.ts to foundation patterns
- Fix abuse-guard.ts: bound in-memory Maps with LRU eviction (was unbounded)
- Fix access-guard.ts: separate try/catch per check, log degradation
  instead of blanket fail-open
- Replace raw redirect() calls with safeRedirect() in guard.ts and
  permissions.ts to prevent open-redirect attacks
- Add CSRF validation to api-handler.ts for mutating methods
- Add canonicalizeFormData() utility for FormData input sanitization
2026-07-13 12:03:49 +02:00
openhands 2e4ed76121 style: format code with prettier 2026-07-12 21:07:34 +02:00
remco e85e4d74ea revert fb8e77bb68
revert style: clean up code with prettier and eslint
2026-07-12 21:02:03 +02:00
openhands fb8e77bb68 style: clean up code with prettier and eslint 2026-07-12 20:31:05 +02:00
Simo 60278b9e71 feat: add admin operations suite 2026-07-12 20:11:28 +02:00
Simo 21a61068fb test: define admin operations contracts 2026-07-12 20:01:25 +02:00
Simo c0ffc74f9b fix: externalize lzma for import build 2026-07-12 19:15:08 +02:00