Commit Graph
166 Commits
Author SHA1 Message Date
openhands fb8e77bb68 style: clean up code with prettier and eslint 2026-07-12 20:31:05 +02:00
Simo 60278b9e71 feat: add admin operations suite 2026-07-12 20:11:28 +02:00
Simo 21a61068fb test: define admin operations contracts 2026-07-12 20:01:25 +02:00
Simo c0ffc74f9b fix: externalize lzma for import build 2026-07-12 19:15:08 +02:00
Simo eb759f54bf feat: connect guarded asset import api 2026-07-12 19:12:25 +02:00
Simo 3497df9dfd feat: add asset import services 2026-07-12 19:12:25 +02:00
Simo 4b596226e0 fix: complete acl management 2026-07-12 19:12:24 +02:00
Simo 667ec9af4c test: define acl and import backend contracts 2026-07-12 19:01:28 +02:00
Simo 84e4123f09 fix: use semantic colors across admin pages 2026-07-12 18:50:45 +02:00
Simo 0fe482009c fix: isolate shared admin styling 2026-07-12 18:50:44 +02:00
Simo 4ce35e91fb feat: add semantic admin palette 2026-07-12 18:47:23 +02:00
Simo d4bcf89449 test: enforce admin theme isolation 2026-07-12 18:46:16 +02:00
Simo 2606092337 feat: add admin content module pages 2026-07-12 15:27:07 +02:00
Simo f422bb4a0b feat: add admin content module actions 2026-07-12 15:27:07 +02:00
Simo b9525c8e6b feat: add schema for admin content modules 2026-07-12 15:27:06 +02:00
Simo 41002aa36d fix: preserve Next.js deploy cache 2026-07-12 15:17:16 +02:00
Simo f0b4bc1630 fix: enforce semantic contrast across admin 2026-07-12 15:14:15 +02:00
Simo b1a60adbc2 feat: rebrand CMS information as EpicNext 2026-07-12 14:49:37 +02:00
Simo 9cdd0b4000 feat: persist complete multitheme palettes 2026-07-12 14:49:36 +02:00
Simo 3fd2a27719 feat: generate preset-aware dark theme variables 2026-07-12 14:49:36 +02:00
Simo 48c596cf41 feat: add complete light and dark presets 2026-07-12 14:45:11 +02:00
Simo 5261cfaa1a feat: add CMS info footer popup 2026-07-12 14:37:00 +02:00
Simo 7d3430aeca fix: seed production ACL permissions 2026-07-12 14:29:01 +02:00
Simo cdf180ee3f fix: isolate proxy session decoding 2026-07-12 13:39:25 +02:00
Simo c4bf6488d0 fix: use canonical Auth.js session in proxy 2026-07-11 22:55:26 +02:00
Simo cfa7998dd7 fix: detect deployed Auth.js session cookie 2026-07-11 22:46:04 +02:00
Simo 02bbcba240 fix: decode production admin session cookie 2026-07-11 22:42:19 +02:00
Simo f08e56cf53 fix: authorize super admins by dynamic highest rank 2026-07-11 22:35:40 +02:00
Simo b695a33ead fix: enforce public contrast and audit rank errors 2026-07-11 22:06:45 +02:00
Simo 17264dfc06 fix: protect admin routes and ignore local docs 2026-07-11 21:35:37 +02:00
Simo 8d37ae9ae0 style: normalize restored source endings 2026-07-11 21:19:54 +02:00
Simo 0cd753c735 fix: restore complete admin feature dependencies 2026-07-11 21:15:54 +02:00
Simo 5b4228261a Reapply "Add missing admin action files and navigation links"
This reverts commit 4d515bc400.
2026-07-11 20:52:56 +02:00
Simo 96ed768f14 test: add unresolved local import scanner 2026-07-11 20:52:55 +02:00
Simo 4d515bc400 Revert "Add missing admin action files and navigation links"
This reverts commit 41be6835bf.
2026-07-11 20:37:56 +02:00
Simo 4a1e1115b3 Harden CMS security and theme contrast 2026-07-11 20:27:20 +02:00
openhands 2465ff2170 Add translation keys for new admin nav items in all languages 2026-07-11 12:28:52 +02:00
openhands 41be6835bf Add missing admin action files and navigation links
- Add 11 missing server action files: badges, bulk-users, catalog, catalog-bc, catalog-items, import-badges, import-furni, multi-account-detect, permissions, rooms, soundtracks
- Add missing admin navigation links: tickets, sounds, translations, import, radio sub-pages
- Add translation keys for all new navigation items
2026-07-11 12:01:05 +02:00
openhands 818df3697b Migrate from AES-256-CBC to AES-256-GCM for authenticated encryption
- Replace CBC+HMAC with GCM (built-in authentication via authTag)
- Remove createHmac and timingSafeEqual imports (no longer needed)
- Remove Snyk-ignore comments (no longer suppressible findings)
- Update test: tampered MAC test -> tampered auth tag test
- Add one-time migration script for existing CBC-encrypted 2FA secrets
2026-07-10 23:51:56 +02:00
openhands 259c0c96ab Fix remaining Snyk findings: XSS in validImageUrl, cipher integrity suppression 2026-07-10 23:40:11 +02:00
openhands d782b7c4c2 Fix Snyk security findings: XSS, open redirect, hardcoded secrets, cookie security, MD5 replacement 2026-07-10 23:34:57 +02:00
openhands 1875a69b83 Fix security scanner findings
- Replace hardcoded test secrets with crypto-generated values in laravel-encrypter.test.ts and totp.test.ts
- Add 'secure' attribute to locale cookie in language-switcher.tsx
- Validate image URLs before rendering in media-grid.tsx and media-picker.tsx (XSS prevention)
- Validate redirect URL is HTTPS before window.location assignment in TopUpForm.tsx (open redirect prevention)
- Document intentional MD5 usage for legacy PHP compatibility in password.ts
- Document HMAC integrity protection for CBC cipher in laravel-encrypter.ts
2026-07-10 23:08:15 +02:00
openhands 942bc6fc8d Security hardening, code quality, and ESLint setup
- Remove production DB dump (db_backup_*.sql) and update.log from git tracking
- Add DB backups to .gitignore
- Replace all console.log/console.error with structured logger module
- Translate Dutch error messages to English (link-discord.ts)
- Remove dead code blocks (register-form.tsx false && pattern)
- Add ESLint flat config with TypeScript, React, Next.js, jsx-a11y, and security plugins
- Add Prettier config
- Add eslint-plugin-security for security-aware linting
- Fix all 119+ ESLint warnings across the codebase:
  - Resolve security/detect-object-injection with safe access patterns
  - Resolve security/detect-non-literal-fs-filename with path traversal validation
  - Replace <img> with next/image <Image> component
  - Remove unused variables and imports
  - Replace non-null assertions with proper type guards
  - Replace <a> with <Link> for internal navigation
  - Use next/script Script component for external scripts
- Fix setState-in-useEffect anti-patterns (navbar-color-picker, logo-generator, theme-switcher)
- Add lint and format scripts to package.json

All checks: typecheck ✓, tests 58/58 ✓, lint 0 errors 0 warnings ✓
2026-07-10 22:48:22 +02:00
openhands c68fccceeb Fix: only preconnect nitro URL if absolute (prevents crash on relative URLs like /nitro-client/) 2026-07-09 19:52:19 +02:00
openhands 0ac3e4353a Remove unused /api/client/sso route (replaced by server-side ticket generation) 2026-07-09 19:11:10 +02:00
openhands 7fe3220359 Inline SSO ticket generation in server component, prefetch client page from home, remove client API roundtrip 2026-07-09 18:41:04 +02:00
openhands cfb36e8007 Preconnect to Nitro client URL for faster client page load 2026-07-09 18:35:18 +02:00
openhands da505ae643 Optimize client page: combine fetch calls, extract ToolbarBtn component, reduce duplicated inline styles 2026-07-09 18:30:46 +02:00
openhands deac10e00a Add in-memory caching for online count, enable compression, and add staleTimes for router cache 2026-07-09 18:24:58 +02:00
openhands b058a3827b Fix theme consistency, i18n completeness, CSS variable naming, and hardcoded strings 2026-07-09 18:13:22 +02:00