Commit Graph
104 Commits
Author SHA1 Message Date
SimoandCursor 968ca15c27 feat: jwt cache, redis health, help-ticket admin, and write rate limits
Cut Auth.js DB load with cached jwtVersion checks, surface Redis in /api/health and deploy warnings, add admin help-center ticket reply UI, rate-limit API tickets/reactions/referral claims, and revoke PATs on sign-out-everywhere.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:58:48 +02:00
SimoandCursor fa40eebeed fix(deploy): migrate after stop and shrink DB pool
Stage migrate hit ER_CON_COUNT_ERROR while live still held the pool. Build in stage with DATABASE_POOL_SIZE=5, run db:migrate only after stopping the service (with retries), and lower the default pool from 40 to 10.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:44:06 +02:00
SimoandCursor 687e1f9fb0 fix(deploy): stage worktree build and short .next cutover
Build install/test/migrate in a detached worktree while the live site keeps serving, then swap .next and node_modules during a brief stop. Drops nuclear rm -rf src and rolls back .next.prev on cutover failure.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:39:45 +02:00
SimoandCursor 9b47668fe9 chore: CSP script nonces, deploy health check, dead-code cleanup
Add per-request CSP nonces (drop script unsafe-inline), post-deploy /api/health gate, bump next-auth to beta.32, and remove unused motion/cache/permission helpers.

Co-authored-by: Cursor <[email protected]>
2026-07-21 20:27:08 +02:00
SimoandCursor c46dadeda4 chore: harden deps, env validation, admin errors, and redis warnings
Align nodemailer with Auth.js peers, bump patch deps, validate env on deploy builds, add admin error boundary, and warn when Redis is missing in production.

Co-authored-by: Cursor <[email protected]>
2026-07-21 20:19:05 +02:00
openhands 7fc53396b4 fix: menu links use bare slugs (Gitea auto-prefixes href with user-content-) 2026-07-20 21:03:02 +02:00
openhands c0975f8a43 fix: scope deploy contract test to deploy job; menu links use Gitea user-content anchors 2026-07-20 20:59:37 +02:00
openhands 43a624bbe7 docs: add self-contained setup reference configs (emulator + nitro) and bold-link buttons 2026-07-20 20:54:26 +02:00
openhands c4532dd340 style: use inline style for release buttons (Gitea strips class) 2026-07-20 20:47:07 +02:00
openhands 039b46d12b docs: expand release wizard with emulator/Nitro/Catalogus steps + buttons 2026-07-20 20:43:43 +02:00
openhands 43ca6dc4b0 fix: add explicit plain-id anchors so the release menu jumps to sections 2026-07-20 20:38:50 +02:00
openhands 45b7a1d9ef test: add explicit anchor for System Requirements to verify Gitea keeps id 2026-07-20 20:35:38 +02:00
openhands a741e6103d fix: menu anchors use Gitea user-content- prefix so TOC links work 2026-07-20 20:31:34 +02:00
openhands 6e27d9c4fe docs: expand release notes with menu, requirements, install wizard, usage 2026-07-20 20:25:45 +02:00
openhands e5de0b53d4 fix: single JSON-encode release body so newlines render (no literal \n) 2026-07-20 20:21:33 +02:00
openhands cb91fbef6c chore: cleaner release notes (cap changelog, concise initial release) 2026-07-20 20:15:44 +02:00
openhands d103316945 refactor: drop pack.yaml; v*-tag release now includes linked repo URLs + commits 2026-07-20 20:04:45 +02:00
openhands dd66a5ba2e fix: use TOKEN from env with fallback to secret 2026-07-20 16:03:13 +02:00
openhands 0c0540cf59 fix: yaml syntax in deploy workflow 2026-07-20 15:52:40 +02:00
openhands 0913e9d529 fix: merge release into deploy workflow for Gitea compatibility 2026-07-20 15:50:03 +02:00
SimoandCursor 224ccd654b perf(deploy): keep .next/cache while clearing stale generated types
Nuclear src replace already guarantees clean sources; restoring the build cache speeds deploys without reintroducing sticky typecheck ghosts.

Co-authored-by: Cursor <[email protected]>
2026-07-18 21:15:52 +02:00
SimoandCursor 80c6559143 fix(deploy): stop hanging on per-file sticky-bit scan
Only clear paths that already have skip-worktree/assume-unchanged; keep nuclear src replace and content verify.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:34:34 +02:00
SimoandCursor d0f9b3ef95 fix(deploy): nuclear-replace src to defeat skip-worktree ghosts
Host built a different event-form than HEAD while git looked clean; delete src, restore from git objects, and hash-verify every tracked blob.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:30:21 +02:00
SimoandCursor 968f6ff7db fix(deploy): unstick nitro Json typecheck and wipe poisoned .next cache
Host next build still saw Json on nitro while tsc passed; use any helpers, verify blob hash, and delete .next entirely before build.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:14:50 +02:00
SimoandCursor 1abbf3fde7 fix(deploy): sync rooms Prisma types and harden checkout against stale host files
next build failed on host-local rooms.ts using Prisma without import while tsc incremental passed; force non-incremental typecheck and verify src matches HEAD.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:06:34 +02:00
SimoandCursor c053b8de87 fix(deploy): reclaim www-data ownership before git reset
Stale host sources survived reset when files were owned by www-data, leaving an old nitro editor with a removed Json type that failed typecheck.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:01:25 +02:00
SimoandCursor b22725d3a9 fix: type-safe nitro editor helpers and stabilize deploy build
Rewrite getNested/updateNested without fragile any/Json inference, clear stale .next types before build, and skip env refine during compile.

Co-authored-by: Cursor <[email protected]>
2026-07-18 19:57:33 +02:00
SimoandCursor 6b884ad25a Harden deploy gates, prod AUTH_SECRET, and Sentry error reporting.
Align onlyBuiltDependencies with the workspace, fail fast without AUTH_SECRET in production, and delete catalog_items via VARCHAR-safe SQL so page deletes do not leave orphans.

Co-authored-by: Cursor <[email protected]>
2026-07-18 19:32:15 +02:00
SimoandCursor bb7d581084 Add exportPermissions and clean stray untracked src on deploy.
Co-authored-by: Cursor <[email protected]>
2026-07-17 18:48:34 +02:00
remco 15966bcf6d Update .gitea/workflows/deploy.yaml 2026-07-15 21:57:02 +02:00
remco 64db83c5d3 Update .gitea/workflows/deploy.yaml 2026-07-15 21:54:27 +02:00
remco 3802a1cfb0 Update .gitea/workflows/deploy.yaml 2026-07-15 21:52:39 +02:00
openhands 1908136071 ci: kill lingering next-server before restarting service to avoid EADDRINUSE 2026-07-13 22:16:20 +02:00
openhands 2e4ed76121 style: format code with prettier 2026-07-12 21:07:34 +02:00
remco e85e4d74ea revert fb8e77bb68
revert style: clean up code with prettier and eslint
2026-07-12 21:02:03 +02:00
openhands fb8e77bb68 style: clean up code with prettier and eslint 2026-07-12 20:31:05 +02:00
Simo 41002aa36d fix: preserve Next.js deploy cache 2026-07-12 15:17:16 +02:00
remco 2e1c258bf4 Update .gitea/workflows/deploy.yaml 2026-07-12 14:25:13 +02:00
Simo 685033dcbd Update .gitea/workflows/deploy.yaml 2026-07-12 14:22:07 +02:00
remco 149dc215f0 Update .gitea/workflows/deploy.yaml 2026-07-12 14:20:07 +02:00
Simo 48047f2782 Update .gitea/workflows/deploy.yaml 2026-07-12 14:11:06 +02:00
Simo ec7257f4ea Update .gitea/workflows/deploy.yaml 2026-07-12 14:09:57 +02:00
Simo 50496b20be Update .gitea/workflows/deploy.yaml 2026-07-12 14:08:44 +02:00
remco 41f0ae38b6 Update .gitea/workflows/deploy.yaml 2026-07-12 14:06:26 +02:00
remco 62e3c1f777 Update .gitea/workflows/deploy.yaml 2026-07-12 14:01:53 +02:00
remco 3d7bd16e29 Update .gitea/workflows/deploy.yaml 2026-07-12 13:52:17 +02:00
remco e588fc8162 Update .gitea/workflows/deploy.yaml 2026-07-12 13:51:29 +02:00
remco a758cb3bfe Update .gitea/workflows/deploy.yaml 2026-07-12 13:50:24 +02:00
Simo 9b1bc2fd09 Update .gitea/workflows/deploy.yaml 2026-07-12 13:48:13 +02:00
Simo 69ca4b035b Update .gitea/workflows/deploy.yaml 2026-07-12 13:45:34 +02:00