Commit Graph
44 Commits
Author SHA1 Message Date
openhands 2a1aef1c1b fix: complete Playwright removal in CI deploy workflow
Drop the leftover Playwright browser install and e2e smoke test from the deployment script, and update the deployment contract tests to cover the verify-deployed-release smoke check instead.
2026-09-08 16:47:39 +02:00
openhands fabd160250 fix(ci): bound Docker build cache with BuildKit cache mounts
- Move the pnpm store, apk and .next caches into --mount=type=cache so
  dependencies are shared across builds instead of duplicated in fresh
  image layers (was the source of unbounded disk growth).
- Replace the deprecated --keep-storage prune flag in ci-deploy.sh with
  the working --max-used-space=4g (buildx v0.37 renamed the flag). The
  deprecated flag silently did nothing, so the BuildKit cache kept
  growing unbounded (was 15.86GB); it is now capped at 4GB after every
  deploy.
2026-09-08 15:39:13 +02:00
Simo 814d8650be fix(deploy): build checked-out source without GitLab API request 2026-09-06 19:48:49 +02:00
Simo 7c1f109a9d ci: serialize deployments and restore previous release on smoke failure 2026-09-06 11:48:20 +02:00
Simo 2840ef5d9d perf(docker): reuse dependency layers and preserve build caches 2026-09-06 11:01:31 +02:00
openhands 85facd349a test: update deploy workflow contract test for full docker cache prune 2026-09-05 20:13:13 +02:00
openhands 4007b01da9 ci: run e2e smoke against deployed app and ignore playwright artifacts
- Add e2e job (needs deploy, main/master only) that installs the
  Playwright browser and smoke-tests the live container on :3002
- Keep deploy-job contract slice from bleeding into the e2e job
- Cover the e2e job in the CI workflow contract test
- Ignore Playwright output dirs (test-results, playwright-report,
  blob-report)
2026-09-04 13:32:51 +02:00
openhands 399c047515 fix: harden admin actions, search, sanitization and repo hygiene
- Split approve/dismiss application workflows with distinct audit logs,
  rate-limited guards and real error logging
- Validate article status/date/id input and stop resetting publishedAt
  on every update
- Validate guild updates (state, forum enums, non-empty name) behind
  rate-limited guard
- Fix scheduled-article publishing (ignore NULL dates, set updatedAt,
  type-safe predicates)
- Harden admin search API (LIKE escaping, query cap, per-user
  rate limit, round-robin result cap) and fix search dialog
  abort/res.ok/loading races
- Lock down HTML sanitizer to an allowlist profile and add XSS tests
- Improve mobile nav accessibility (unique id, dialog role, focus
  management, scroll lock, outside close)
- Log swallowed server errors instead of silent catch blocks
- Remove dead eslint config, drop unused dompurify deps, restore knip
  CI step, add Playwright config with smoke spec
2026-09-04 13:04:08 +02:00
openhands 61769e355b fix(ci): draai DB-migraties in deploy voor het vervangen van de container
Zonder dit loopt nieuwe code tegen een oud schema aan zodra een push
migraties bevat. Idempotent (toegepaste migraties worden overgeslagen),
draait op de host met de productie-.env, vóór de container-replace.
2026-09-04 12:34:49 +02:00
openhands 3fdcf028e8 fix(ci): geef runtime-env door via -e i.p.v. --env-file
docker run --env-file behoudt letterlijke quotes (bewezen test),
waardoor DATABASE_URL ongeldig was en de container crashte. Nu wordt
.env gesourced en elke sleutel met -e doorgegeven: exact dezelfde
waarden als bij de build. Contract-test verbiedt --env-file.
2026-09-04 12:29:06 +02:00
openhands 10da44ee56 fix(ci): bouw met productie-.env, deploy met env+volumes en rollback
- Deploy kopieert de productie-.env van de host in de build-context:
  Next.js bakt NEXT_PUBLIC_* in en valideert DATABASE_URL/HOTEL_NAME
  (SKIP_ENV_VALIDATION is verboden voor productie, zie src/env.ts).
- Dockerfile builder installeert git (next.config.ts deploymentId).
- Deploy-container krijgt --env-file + dezelfde volumes als compose,
  stopt ook de oude compose-container (poort 3002) en rolt terug via
  compose bij een falende health check.
2026-09-04 12:22:02 +02:00
openhands 43ecdaee19 fix(ci): docker build met --network=host tegen hangende registry-stappen
De host heeft Docker iptables uitgeschakeld, dus build-containers op
bridge hebben geen outbound internet; 'npm install -g pnpm' in de
builder-stage hing daardoor. Met --network=host krijgt de build wel
registry-toegang. Contract-test vergrendelt de flag.
2026-09-04 12:16:26 +02:00
openhands 4139aa79ff fix(ci): draai alle jobs op self-hosted voor 100% betrouwbaarheid
Root cause: de job-container (docker mode) heeft GEEN outbound
internet naar GitHub, waardoor actions/checkout@v4 faalde met
'Unable to clone ... i/o timeout'.

Oplossing: zowel check als deploy draaien nu op self-hosted (host)
waar Node 26.8.1 + pnpm 11.25.0 geïnstalleerd zijn en internet
beschikbaar is. Dit is de enige betrouwbare setup in deze omgeving.
Runner is tevens hernoemd naar 'Epic runner'.
2026-09-04 11:35:22 +02:00
openhands 3c0acc3fcf refactor(ci): volledig opnieuw geschreven CI workflow
- Check job: lint, typecheck, test in node:26 container
- Deploy job: Docker build + deploy + health check op host
- Corepack pnpm installatie
- BuildKit caching
- Contract tests herschreven (18 tests)
2026-09-04 11:26:25 +02:00
openhands a52cbead8a perf(ci): snellere workflow + Epic runner naam
- Runner hernoemd naar 'Epic runner'
- Env variabelen als global env (niet per step)
- fetch-depth: 1 voor snellere checkout
- Knip verwijderd (traag, niet kritiek)
- Docker BuildKit caching
- Health check opgeschoond
2026-09-04 11:22:28 +02:00
openhands c949319332 fix(tests): update contract tests voor Docker-based CI workflow 2026-09-04 11:16:07 +02:00
Simo 0c8e62357f fix: preserve runtime furni assets during deploy 2026-08-02 17:32:32 +02:00
Simo bfc951cfd9 fix: minimize deploy cutover downtime 2026-08-02 11:25:03 +02:00
Simo 828fda63e7 fix: keep app online during deploy preparation 2026-08-02 11:19:53 +02:00
Simo 1f4aadb3d7 chore: remove Sentry integration 2026-08-01 22:12:31 +02:00
SimoandCursor 3e584aadaf ci: unify check and production deploy into one workflow
Co-authored-by: Cursor <[email protected]>
2026-07-30 20:58:40 +02:00
SimoandCursor ed5b9a6f7c fix(test): align media path mocks and deploy contract with main
Use path.join in admin-media tests for Windows path.sep checks, and drop the deploy-job pnpm test expectation after it moved to CI.

Co-authored-by: Cursor <[email protected]>
2026-07-30 19:41:45 +02:00
SimoandCursor c433e5a52f fix(deploy): clear EADDRINUSE orphans and update deploy contract tests
Co-authored-by: Cursor <[email protected]>
2026-07-30 18:41:26 +02:00
openhands dacc4cadfd chore(deps): upgrade to typescript 7 bridge and clean up pnpm v11 workspace configs 2026-07-27 23:14:00 +02:00
openhands af9f11d934 fix: resolve all Biome lint warnings
- Replace 'as any' with proper CurrencyDb type in send-currency test
- Fix noTemplateCurlyInString warnings in deploy-workflow-contract test
2026-07-27 17:33:07 +02:00
openhands 17847545dd Improvements: remove dead config, fix ESM, add URL validation, unify types, add missing logging
- Remove .prettierrc (dead config, Biome replaces Prettier)
- Rename lighthouserc.json to lighthouserc.cjs with module.exports for ESM compat
- Add logger.warn to empty catch blocks in auth, register, site-settings, prisma-cache, redis, security, rate-limit
- Unify ActionResult type: action-helper.ts uses 'ok' consistent with safe-action-shared.ts
- Add noUnusedLocals + noUnusedParameters to tsconfig + fix 25 pre-existing unused vars
- Replace barrel export src/types/index.ts with direct @/types/common imports
- Make trustHost conditional (development only) in auth.ts
- Add pre-flight URL validation to update-Nitrov3.sh to catch image.library.url misconfigurations
- Improve NITRO_IMAGE_LIBRARY_URL content validation in pre-flight & post-compute checks
2026-07-26 20:28:11 +02:00
openhands aabf14aaf9 Fix deploy workflow tests for PM2 2026-07-23 19:14:47 +02:00
SimoandCursor 968ca15c27 feat: jwt cache, redis health, help-ticket admin, and write rate limits
Cut Auth.js DB load with cached jwtVersion checks, surface Redis in /api/health and deploy warnings, add admin help-center ticket reply UI, rate-limit API tickets/reactions/referral claims, and revoke PATs on sign-out-everywhere.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:58:48 +02:00
SimoandCursor fa40eebeed fix(deploy): migrate after stop and shrink DB pool
Stage migrate hit ER_CON_COUNT_ERROR while live still held the pool. Build in stage with DATABASE_POOL_SIZE=5, run db:migrate only after stopping the service (with retries), and lower the default pool from 40 to 10.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:44:06 +02:00
SimoandCursor 687e1f9fb0 fix(deploy): stage worktree build and short .next cutover
Build install/test/migrate in a detached worktree while the live site keeps serving, then swap .next and node_modules during a brief stop. Drops nuclear rm -rf src and rolls back .next.prev on cutover failure.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:39:45 +02:00
SimoandCursor 9b47668fe9 chore: CSP script nonces, deploy health check, dead-code cleanup
Add per-request CSP nonces (drop script unsafe-inline), post-deploy /api/health gate, bump next-auth to beta.32, and remove unused motion/cache/permission helpers.

Co-authored-by: Cursor <[email protected]>
2026-07-21 20:27:08 +02:00
SimoandCursor c46dadeda4 chore: harden deps, env validation, admin errors, and redis warnings
Align nodemailer with Auth.js peers, bump patch deps, validate env on deploy builds, add admin error boundary, and warn when Redis is missing in production.

Co-authored-by: Cursor <[email protected]>
2026-07-21 20:19:05 +02:00
openhands c0975f8a43 fix: scope deploy contract test to deploy job; menu links use Gitea user-content anchors 2026-07-20 20:59:37 +02:00
openhands 5e8a13a84f fix: resolve all biomaly lint errors and warnings across CMS
- Fix CSS parser config (tailwindDirectives enabled)
- Fix noDangerouslySetInnerHtml via SanitizedHtml component
- Fix useExhaustiveDependencies in catalog-manager-dialog
- Fix noArrayIndexKey across 26 files (stable keys)
- Fix SVG a11y (titles, roles, aria-labels)
- Fix label/input associations (htmlFor/id pairs)
- Fix static element interactions (role + keyboard support)
- Fix noImgElement, noDescendingSpecificity (disabled - external Habbo URLs)
- Fix noNonNullAssertion, useTemplate, unused vars/imports
- Add SanitizedHtml shared component
- Migrate biome.json to 2.5.4 schema
2026-07-20 17:41:53 +02:00
SimoandCursor 224ccd654b perf(deploy): keep .next/cache while clearing stale generated types
Nuclear src replace already guarantees clean sources; restoring the build cache speeds deploys without reintroducing sticky typecheck ghosts.

Co-authored-by: Cursor <[email protected]>
2026-07-18 21:15:52 +02:00
SimoandCursor 80c6559143 fix(deploy): stop hanging on per-file sticky-bit scan
Only clear paths that already have skip-worktree/assume-unchanged; keep nuclear src replace and content verify.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:34:34 +02:00
SimoandCursor d0f9b3ef95 fix(deploy): nuclear-replace src to defeat skip-worktree ghosts
Host built a different event-form than HEAD while git looked clean; delete src, restore from git objects, and hash-verify every tracked blob.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:30:21 +02:00
SimoandCursor 968f6ff7db fix(deploy): unstick nitro Json typecheck and wipe poisoned .next cache
Host next build still saw Json on nitro while tsc passed; use any helpers, verify blob hash, and delete .next entirely before build.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:14:50 +02:00
SimoandCursor 1abbf3fde7 fix(deploy): sync rooms Prisma types and harden checkout against stale host files
next build failed on host-local rooms.ts using Prisma without import while tsc incremental passed; force non-incremental typecheck and verify src matches HEAD.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:06:34 +02:00
SimoandCursor c053b8de87 fix(deploy): reclaim www-data ownership before git reset
Stale host sources survived reset when files were owned by www-data, leaving an old nitro editor with a removed Json type that failed typecheck.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:01:25 +02:00
SimoandCursor b22725d3a9 fix: type-safe nitro editor helpers and stabilize deploy build
Rewrite getNested/updateNested without fragile any/Json inference, clear stale .next types before build, and skip env refine during compile.

Co-authored-by: Cursor <[email protected]>
2026-07-18 19:57:33 +02:00
SimoandCursor 6b884ad25a Harden deploy gates, prod AUTH_SECRET, and Sentry error reporting.
Align onlyBuiltDependencies with the workspace, fail fast without AUTH_SECRET in production, and delete catalog_items via VARCHAR-safe SQL so page deletes do not leave orphans.

Co-authored-by: Cursor <[email protected]>
2026-07-18 19:32:15 +02:00
openhands df38dccbf1 style: format code biome 2026-07-13 21:57:41 +02:00
Simo 41002aa36d fix: preserve Next.js deploy cache 2026-07-12 15:17:16 +02:00