Commit Graph
442 Commits
Author SHA1 Message Date
openhands 43ecdaee19 fix(ci): docker build met --network=host tegen hangende registry-stappen
De host heeft Docker iptables uitgeschakeld, dus build-containers op
bridge hebben geen outbound internet; 'npm install -g pnpm' in de
builder-stage hing daardoor. Met --network=host krijgt de build wel
registry-toegang. Contract-test vergrendelt de flag.
2026-09-04 12:16:26 +02:00
openhands cdb0fef6c9 fix(ci): remove invalid --jobs flag from pnpm install
pnpm 11 has no --jobs option for install; the stray positional '1'
flipped the command into 'add' mode, which then rejected both
--frozen-lockfile and --jobs ('Unknown options', 'pnpm help add').
Reproduced locally, fixed, verified install succeeds. Add contract
regression test.
2026-09-04 12:11:35 +02:00
openhands 4139aa79ff fix(ci): draai alle jobs op self-hosted voor 100% betrouwbaarheid
Root cause: de job-container (docker mode) heeft GEEN outbound
internet naar GitHub, waardoor actions/checkout@v4 faalde met
'Unable to clone ... i/o timeout'.

Oplossing: zowel check als deploy draaien nu op self-hosted (host)
waar Node 26.8.1 + pnpm 11.25.0 geïnstalleerd zijn en internet
beschikbaar is. Dit is de enige betrouwbare setup in deze omgeving.
Runner is tevens hernoemd naar 'Epic runner'.
2026-09-04 11:35:22 +02:00
openhands 3c0acc3fcf refactor(ci): volledig opnieuw geschreven CI workflow
- Check job: lint, typecheck, test in node:26 container
- Deploy job: Docker build + deploy + health check op host
- Corepack pnpm installatie
- BuildKit caching
- Contract tests herschreven (18 tests)
2026-09-04 11:26:25 +02:00
openhands a52cbead8a perf(ci): snellere workflow + Epic runner naam
- Runner hernoemd naar 'Epic runner'
- Env variabelen als global env (niet per step)
- fetch-depth: 1 voor snellere checkout
- Knip verwijderd (traag, niet kritiek)
- Docker BuildKit caching
- Health check opgeschoond
2026-09-04 11:22:28 +02:00
openhands c949319332 fix(tests): update contract tests voor Docker-based CI workflow 2026-09-04 11:16:07 +02:00
openhands 30c95b1a5c feat: comprehensive CMS improvements
- Fix DOMPurify SSR crash (use isomorphic-dompurify)
- Fix SanitizedHtml to sanitize by default
- Add auth guards to studio/catalog maintenance pages
- Add update/edit to vouchers CRUD
- Add update/edit to rare-values CRUD
- Add approve workflow to applications page
- Add edit form to guilds detail page
- Add SEO metadata to all public pages (21 pages)
- Fix mobile nav accessibility (focus trap, aria attributes)
- Fix missing labels and table accessibility
- Add dynamic imports for heavy client components (6 components)
- Fix silent error swallowing (40+ locations)
- Add content scheduling for articles (publishAt, status)
- Wire up 12 missing webhook notification triggers
- Add global search to admin panel
- Add bulk actions to admin users table
- Fix JSON formatting and a11y issues
2026-09-03 16:00:32 +02:00
openhands 58c35a2920 feat: enforce no hardcoded colors across entire CMS
Added scripts/check-admin-colors.mjs — scans all src/ files for:
- text-white, text-black (use theme text vars)
- bg-white, bg-black (use theme background/overlay vars)
- bg/text/border/ring with gray/slate/zinc/stone palette
- bg/text/border/ring with red/green/blue/etc palette

Fixed 21 violations across 11 files:
- Overlays: bg-black/* → bg-foreground/*
- Text: text-white → text-primary-foreground
- Backgrounds: bg-white/10 → bg-background/10
- Green accents: bg-green-* → bg-primary
- Red accents: bg-red-* → bg-destructive

Integrated into:
- lint-staged: runs on every *.ts/*.tsx commit
- vitest: src/lib/no-hardcoded-colors.test.ts replaces old audit test
- Allowlist: shadcn/ui primitives (button, badge, dialog) + 4 graphical files
2026-09-01 19:33:50 +02:00
Simo 1610aa1008 fix: keep server env out of avatar client bundle 2026-08-31 21:41:40 +02:00
Simo 37ad27c5f3 fix: support legacy rank permission schema 2026-08-31 21:01:13 +02:00
Simo 384ede19c4 style: format rank permission regression test 2026-08-31 20:51:47 +02:00
Simo edfe878b2a fix: repair missing rank permission columns 2026-08-31 20:49:51 +02:00
Simo 9af1e62655 feat: allow rank-gated housekeeping preview in production 2026-08-31 20:29:38 +02:00
openhands 7556b1f3fa perf: prevent import hanging with timeouts and batching
- verifyAndFixInteractionModesCount: paginated DB queries (500/batch)
  instead of loading all items into memory at once
- withFurniDataLock: add 60s chain timeout to prevent deadlocks
  when a lock holder stalls or crashes
- withGamedataLock: same timeout protection for gamedata locks
- conversion-pool: add 60s per-job timeout, fall back to main thread
- furni/batch: abort signal + post_import progress events + skip
  post-import steps when client disconnects
- furni/batch-regen: abort signal + early exit when disconnected
- clone/sync-all: pre-fetch furnidata once per source instead of
  per item (eliminates 2000+ redundant fetches)
- sse-client: add 60s idle timeout to prevent infinite hangs
2026-08-31 18:25:32 +02:00
openhands f70d96b81c fix: prevent import hanging by adding abort signals and idle timeouts
- Furni batch: wire request.signal to abort controller, send post_import
  progress events, skip post-import steps when aborted
- Clone sync-all: pre-fetch furnidata once per source instead of per item
  (eliminates 2000+ redundant DB reads + HTTP requests)
- SSE client: add 60s idle timeout to prevent infinite hangs when server
  stops responding
2026-08-31 18:11:54 +02:00
openhands 96c33efced fix: remove unused site-resolver.ts 2026-08-31 17:50:12 +02:00
openhands a7ccc98f84 fix: resolve pre-existing lint warnings
- Remove unused siteSettings import in auth-precheck.test.ts
- Replace non-null assertions with proper null checks in furni-data-i18n.ts
- Replace non-null assertions with proper null checks in conversion-pool.ts
2026-08-31 17:48:36 +02:00
openhands adf0658916 feat: extend theme builder with block visibility, layout, effects, media, and custom CSS tabs
- Add theme-blocks.ts registry with 24 themeable blocks across 4 categories
- Extend resolver to resolve blocks, layout, effects, media, and custom CSS per scope
- Add data-theme-block attributes to all site layout blocks
- Extend ScopedThemeVars to generate CSS for block visibility, layout vars, effect vars, media vars, and custom CSS
- Rewrite admin UI with 6 tabs: Colors, Blocks, Layout, Effects, Media, Custom
- Extend server actions to save/load all new setting types
- No database migration needed - uses existing theme_scope_values table with prefixed keys
2026-08-31 17:44:29 +02:00
openhands a98b194386 feat: add scoped theme builder system with per-route, per-module, and multi-site support
- Add theme_scopes and theme_scope_values database tables for scoped themes
- Implement theme resolver engine with inheritance: global > site > module > route
- Add module detection for 20+ routes (shop, guilds, radio, news, etc.)
- Create admin UI at /admin/theme-builder with scope tree and color editor
- Add ScopedThemeVars component for injecting scoped CSS via data-attributes
- Add ThemeScopeDetector client component for runtime module/route detection
- Add site-resolver for multi-site domain detection
- Add /api/themes/export endpoint (JSON, CSS, variables formats)
- Add /api/themes/export/embed.js for external integration widget
- Add server actions for full CRUD on scopes and theme values
- Add admin nav link and EN/NL translations
2026-08-31 17:15:42 +02:00
openhands c17ef0e7ab Fix flaky TTL cache test timing
Use a 20ms TTL with a 40ms wait so the expiry window is long enough
for the immediate second read to hit the in-memory cache reliably.
2026-08-31 11:47:43 +02:00
Simo b1ddda66ff Revert "Merge pull request 'Complete Housekeeping migration and /ase cutover' (#52) from codex/housekeeping-complete into main"
This reverts commit 488b6e57c4, reversing
changes made to b506b4499a.
2026-08-30 21:31:34 +02:00
Simo cdfae0b967 fix(ci): stabilize post-cutover checks 2026-08-30 21:13:07 +02:00
Simo 222535e116 fix(housekeeping): close final authorization gaps 2026-08-30 21:01:32 +02:00
Simo 2b8f73a91d feat(housekeeping): cut over administration to ase 2026-08-30 20:35:22 +02:00
Simo 5574e601bb feat(housekeeping): personalize command deck 2026-08-30 16:55:10 +02:00
Simo 2e95a106e0 feat(housekeeping): integrate studio operations 2026-08-30 15:29:58 +02:00
Simo d09eaa33d6 fix(housekeeping): address task 14 review round 1 2026-08-30 10:53:50 +02:00
Simo fd68819d9b feat(housekeeping): deliver content vertical 2026-08-30 01:54:43 +02:00
Simo 3fa1119f5a fix(housekeeping): address people moderation review 2026-08-29 23:53:38 +02:00
Simo 29fe22297b feat(housekeeping): complete people moderation parity 2026-08-29 22:38:50 +02:00
Simo 3d385d1869 Merge branch 'main' of https://gitlab.epicnabbo.nl/remco/EpicNext-Cms into codex/housekeeping-complete 2026-08-29 21:16:46 +02:00
openhands 7f39ba4257 fix: harden SSO ticket flow and revoke tickets on logout
Reuse the outstanding auth_ticket instead of minting a fresh one on every
/client load, so reloading the page or opening a second tab no longer
invalidates a game session that is still connecting. New tickets are minted
with a guard against the previously-read value so concurrent launches
converge on the same ticket.

Revoke the auth_ticket when signing out (toolbar, header and sign-out
everywhere) so a leaked ticket can no longer be replayed against the
emulator, and prevent SSO leakage via referral by setting no-referrer on the
client iframe. Strip all whitespace from the ticket prefix and build the
launch URL through a tested helper that handles query strings, existing sso
params and URL fragments correctly.
2026-08-29 20:54:06 +02:00
openhands ca59a1065f perf: use lzma-wasm for SWF decompression and drop vite
Replace the pure-JS lzma decoder with lzma-wasm (Rust/WASM, base64-inlined,
zero-alloc decompress), giving an order-of-magnitude speedup on furni
imports. Remove the obsolete lzma type shim and the redundant top-level
vite dev dependency, which nothing imports directly.
2026-08-29 19:27:27 +02:00
Simo 91c9efcbb4 fix(housekeeping): complete people workflow fidelity 2026-08-29 14:39:38 +02:00
Simo 25b76437ff fix(housekeeping): harden people account workflows 2026-08-29 13:13:04 +02:00
Simo d1382c839e fix(housekeeping): harden people read boundaries 2026-08-29 02:13:53 +02:00
Simo c325c53774 fix(housekeeping): harden system workflow boundaries 2026-08-29 00:25:47 +02:00
Simo 3788ecd9f1 feat(housekeeping): deliver system vertical 2026-08-28 23:31:47 +02:00
Simo 139e8cfc3a Merge branch 'main' of https://gitlab.epicnabbo.nl/remco/EpicNext-Cms into codex/housekeeping-complete 2026-08-28 20:21:13 +02:00
openhands 944e8ff1d8 fix: harden update pipeline and restore a clean production build
- update-Nitrov3.sh: build CMS into .next-staging and swap atomically so a
  failed build never takes the live site down; auto-merge new variables
  from .env.example; validate env for duplicates/broken lines; restart the
  emulator/CMS only when rebuilt or unhealthy; fix step renumbering
- next.config.ts: support NEXT_DIST_DIR for staged production builds
- fix all TS errors (unused imports, missing tryDownloadCandidates helper)
  so tsc and the production build pass clean
- add Dockerfile/.dockerignore and switch docker-compose to a CMS container
- include prevailing UI/refactor changes (SurfaceCard, ticketing, tsconfig)
2026-08-28 12:48:04 +02:00
Simo 4e0bf598ed fix(housekeeping): harden preference persistence 2026-08-27 17:44:53 +02:00
Simo 64bb230de5 Merge branch 'main' of https://gitlab.epicnabbo.nl/remco/EpicNext-Cms into codex/housekeeping-complete 2026-08-27 17:25:31 +02:00
openhands 750fcb2e5c refactor: resolve hotel name directly from HOTEL_NAME env
resolveHotelName() now returns env.HOTEL_NAME directly — the single source
of truth. The CMS hotel_name site setting and its DEFAULTS entry are removed
as dead code since they no longer influence the displayed name.

Call sites are unchanged (still await resolveHotelName()); only the lookup
behind it is gone, so the public site always shows the configured env name
with no DB round-trip and no preset.
2026-08-27 16:42:12 +02:00
openhands 164a4f4ef6 refactor: remove hotel-name fallback, fail fast when unconfigured
Drop the hardcoded FALLBACK_HOTEL_NAME ("Atom") preset and the brand.ts
module. HOTEL_NAME is now a required env var: if it (and the CMS hotel_name
setting) is missing the site fails validation at startup/build with a clear
message instead of silently rendering a placeholder hotel name.

resolveHotelName() resolves CMS hotel_name -> required HOTEL_NAME only.
Callers that used the preset (api/home route catch branch, CMS settings form
default, mobile-nav/logo-generator prop defaults) now use the configured name
or an empty default; the real name is already passed in by server parents.
2026-08-27 16:35:00 +02:00
openhands 89c1751e79 refactor: extract shared login credential verification into auth/login-core
The username normalization, dummy-hash constant, password check and
email-verification gate were duplicated between precheckLogin and the
NextAuth credentials authorize handler. Move them into a single
login-core module so both paths share one source of truth and stay
consistent.
2026-08-27 15:17:54 +02:00
openhands ac5cd6bc3f fix: normalize username and password with NFC in login flow
precheckLogin already normalized the username with NFC, but the
NextAuth credentials authorize handler only trimmed it. This caused a
mismatch for accounts with accented/non-ASCII usernames: the precheck
passed while the actual sign-in lookup found no user and returned
'invalid username or password'.

Also normalize the password to NFC in both the precheck and the
authorize handler to match how register.ts hashes it.
2026-08-27 15:09:43 +02:00
Simo 483d5b8c67 fix(housekeeping): restore audit search interpolation 2026-08-26 22:04:16 +02:00
Simo 21cd88ccfd fix(housekeeping): preserve audit failure evidence 2026-08-26 22:03:02 +02:00
Simo 89dec9da05 feat(housekeeping): correlate command audit evidence 2026-08-26 21:56:51 +02:00
Simo edc165ba8d refactor(housekeeping): reuse request capability context 2026-08-26 21:20:12 +02:00