Commit Graph
98 Commits
Author SHA1 Message Date
Simo 8dc187483c fix(ci): verify registry upload against exported OCI config 2026-09-09 20:33:14 +02:00
Simo e617ed176a fix(ci): resolve OCI platform before verifying published config 2026-09-09 20:27:03 +02:00
Simo 2af244b634 fix(ci): publish registry blobs in bounded chunks 2026-09-09 20:22:07 +02:00
Simo 867113d5d4 fix(ci): publish container under token account namespace 2026-09-09 19:53:16 +02:00
Simo c389c3893d feat(cms): improve catalog, editorial recovery and operations 2026-09-09 19:36:15 +02:00
openhands ecadef904d chore: remove knip, husky and lint-staged
Drop the unused knip dead-code check and the husky+lint-staged pre-commit hook pipeline. All checks remain covered by the CI workflow (lint, typecheck, i18n, tests).
2026-09-08 16:56:55 +02:00
openhands 2a1aef1c1b fix: complete Playwright removal in CI deploy workflow
Drop the leftover Playwright browser install and e2e smoke test from the deployment script, and update the deployment contract tests to cover the verify-deployed-release smoke check instead.
2026-09-08 16:47:39 +02:00
openhands 25f4d74209 feat(ci): switch Cloudflare bypass from FlareSolverr to Byparr 2026-09-08 16:02:12 +02:00
openhands fabd160250 fix(ci): bound Docker build cache with BuildKit cache mounts
- Move the pnpm store, apk and .next caches into --mount=type=cache so
  dependencies are shared across builds instead of duplicated in fresh
  image layers (was the source of unbounded disk growth).
- Replace the deprecated --keep-storage prune flag in ci-deploy.sh with
  the working --max-used-space=4g (buildx v0.37 renamed the flag). The
  deprecated flag silently did nothing, so the BuildKit cache kept
  growing unbounded (was 15.86GB); it is now capped at 4GB after every
  deploy.
2026-09-08 15:39:13 +02:00
Simo c4496e710b feat(docker): prepare portable images with runtime hotel configuration 2026-09-07 22:37:53 +02:00
Simo 745d0b7247 feat(docker): restore failed Compose updates and retain recent releases 2026-09-07 22:10:13 +02:00
Simo fe1ee8a6fe fix(deploy): replace both legacy and CI containers during cutover 2026-09-07 21:40:26 +02:00
Simo 6cbcb50191 chore(deploy): identify the existing CMS listener before cutover 2026-09-07 21:35:17 +02:00
Simo c35fc764bc fix(deploy): wait for the expected HTTP release and report failed probes 2026-09-07 21:28:18 +02:00
Simo cbaa115d56 fix(deploy): verify Docker clone updates against the served release 2026-09-07 21:17:34 +02:00
openhands 2650d325ec fix(scripts): drop unlisted dotenv dep in schema generator
generate-drizzle-schema.mjs imported 'dotenv/config' but dotenv is not a
dependency, failing knip and crashing 'pnpm db:schema:generate'. Load .env
with Node's built-in process.loadEnvFile like the other scripts do
(scripts/load-env.ts), never overriding vars already set in the shell.
2026-09-07 17:13:34 +02:00
openhands 52459c0b74 feat(db): add self-tuned mariadb-turbo container and bulk JSON importer
- docker-compose: opt-in mariadb-turbo service (profile 'db') with inline
  mysqld tuning (max_allowed_packet=512M, innodb_flush_log_at_trx_commit=2,
  2G buffer pool, net_read/write_timeout=600) for >50 MB JSON bulk loads;
  named volume for the datadir + node_modules host-sync guidance
- scripts/bulk-import-json.ts: chunked (2000-row) idempotent importer with
  ON DUPLICATE KEY UPDATE, resumable, habbo furnidata or flat-array input
- src/db/schema-gamedata.ts: promote+index JSON storage schema (furnidata,
  docs, texts) incl. VIRTUAL generated columns for MariaDB
- package.json: add db:bulk, db:up, db:down, db:introspect, db:schema:generate
2026-09-07 16:54:44 +02:00
openhands a640e40a5d fix(docker): clear build cache on every build to stop unbounded disk growth 2026-09-07 16:18:04 +02:00
openhands 1a9b361420 fix(docker): inject real commit id into build via NEXT_DEPLOYMENT_ID
next.config.ts falls back to `git rev-parse HEAD`, but the build context has
no .git (excluded by .dockerignore), so every CI build printed fatal git
errors and stamped the release as "unknown". Pass the deploy commit sha as a
NEXT_DEPLOYMENT_ID build-arg so git is never invoked and the actual commit
reaches NEXT_PUBLIC_CMS_RELEASE and deploymentId.
2026-09-07 11:39:29 +02:00
openhands 539e6d3fad fix(docker): harden image and automate safe VPS updates
- Use floating node:alpine that tracks the latest supported LTS; pnpm
  bootstrap follows package.json's packageManager pin.
- Drop corepack (removed from node:26), install pnpm via npm global.
- Add pnpm fetch + offline install for stable dependency-layer caching.
- Run as non-root nextjs (UID/GID 33 = host www-data) with tini as PID 1
  for correct signal handling.
- Open node engines to >=20.9.0 so patches/minors float automatically.
- Add docker-preflight.sh (per-VPS checks incl. --fix) and gate docker-update.sh
  so Node major upgrades require explicit review while patches deploy silently.
2026-09-07 11:22:30 +02:00
Simo 9b0ea2fb16 fix(news): restore publication flow and deduplicate dashboard friends 2026-09-06 18:32:43 +02:00
Simo ef94646d60 fix(i18n): persist CMS translations and validate message catalogs 2026-09-06 17:55:11 +02:00
openhands 9dc9d1fa4b perf: pre-compress gamedata JSON, tune MariaDB, fix avatar imager, docs
- scripts/compress-gamedata.mjs: pre-compress large gamedata JSON to .gz
  (gzip level 9, idempotent mtime check) served via nginx gzip_static
  (48 MB FurnitureData.json -> ~2.4 MB, ~0.3s -> ~0.005s per request)
- package.json: add gamedata:compress script
- fix(imaging): accept real Habbo figure strings in avatar route
  (allow optional second number per part, e.g. hd-180-1.ch-210-66)
- README: document avatar imager container (avatar-imaging-pixinode,
  port 8082, /docker/Polaris-imager), nginx /imaging proxying, MariaDB
  tuning, gamedata pre-compression cron and caching layers
2026-09-06 12:06:38 +02:00
Simo 7c1f109a9d ci: serialize deployments and restore previous release on smoke failure 2026-09-06 11:48:20 +02:00
Simo 816e3875c2 feat(admin): add production error center and refresh CMS dependencies 2026-09-05 19:53:09 +02:00
Simo 9ec9ab31ad feat: export Catalog Studio assets and SQL to catalog repository 2026-09-05 11:49:00 +02:00
openhands 399c047515 fix: harden admin actions, search, sanitization and repo hygiene
- Split approve/dismiss application workflows with distinct audit logs,
  rate-limited guards and real error logging
- Validate article status/date/id input and stop resetting publishedAt
  on every update
- Validate guild updates (state, forum enums, non-empty name) behind
  rate-limited guard
- Fix scheduled-article publishing (ignore NULL dates, set updatedAt,
  type-safe predicates)
- Harden admin search API (LIKE escaping, query cap, per-user
  rate limit, round-robin result cap) and fix search dialog
  abort/res.ok/loading races
- Lock down HTML sanitizer to an allowlist profile and add XSS tests
- Improve mobile nav accessibility (unique id, dialog role, focus
  management, scroll lock, outside close)
- Log swallowed server errors instead of silent catch blocks
- Remove dead eslint config, drop unused dompurify deps, restore knip
  CI step, add Playwright config with smoke spec
2026-09-04 13:04:08 +02:00
openhands 30c95b1a5c feat: comprehensive CMS improvements
- Fix DOMPurify SSR crash (use isomorphic-dompurify)
- Fix SanitizedHtml to sanitize by default
- Add auth guards to studio/catalog maintenance pages
- Add update/edit to vouchers CRUD
- Add update/edit to rare-values CRUD
- Add approve workflow to applications page
- Add edit form to guilds detail page
- Add SEO metadata to all public pages (21 pages)
- Fix mobile nav accessibility (focus trap, aria attributes)
- Fix missing labels and table accessibility
- Add dynamic imports for heavy client components (6 components)
- Fix silent error swallowing (40+ locations)
- Add content scheduling for articles (publishAt, status)
- Wire up 12 missing webhook notification triggers
- Add global search to admin panel
- Add bulk actions to admin users table
- Fix JSON formatting and a11y issues
2026-09-03 16:00:32 +02:00
openhands 037b295b93 feat(ci): automated docker update script + nightly cron
- scripts/docker-update.sh: git pull --ff-only, host db:migrate, docker compose
  build + up -d, health-check wait, keeps host-side PM2 'next' stopped.
  Fails safe on dirty working tree (exit 1) and on health failure (exit 3).
- cron entry: daily 03:30 -> logs/docker-update.cron.log
- README: Automatic Updates section + docker commands row
2026-09-02 12:25:42 +02:00
openhands 58c35a2920 feat: enforce no hardcoded colors across entire CMS
Added scripts/check-admin-colors.mjs — scans all src/ files for:
- text-white, text-black (use theme text vars)
- bg-white, bg-black (use theme background/overlay vars)
- bg/text/border/ring with gray/slate/zinc/stone palette
- bg/text/border/ring with red/green/blue/etc palette

Fixed 21 violations across 11 files:
- Overlays: bg-black/* → bg-foreground/*
- Text: text-white → text-primary-foreground
- Backgrounds: bg-white/10 → bg-background/10
- Green accents: bg-green-* → bg-primary
- Red accents: bg-red-* → bg-destructive

Integrated into:
- lint-staged: runs on every *.ts/*.tsx commit
- vitest: src/lib/no-hardcoded-colors.test.ts replaces old audit test
- Allowlist: shadcn/ui primitives (button, badge, dialog) + 4 graphical files
2026-09-01 19:33:50 +02:00
Simo 9a0b6e091a ci: inspect permission value limits 2026-08-31 21:19:06 +02:00
Simo 75b85dcdd9 ci: probe permission page database reads 2026-08-31 21:13:03 +02:00
Simo b1ddda66ff Revert "Merge pull request 'Complete Housekeeping migration and /ase cutover' (#52) from codex/housekeeping-complete into main"
This reverts commit 488b6e57c4, reversing
changes made to b506b4499a.
2026-08-30 21:31:34 +02:00
Simo 2b8f73a91d feat(housekeeping): cut over administration to ase 2026-08-30 20:35:22 +02:00
Simo 8a31556d51 test(housekeeping): prove 137 route parity 2026-08-30 19:11:14 +02:00
openhands d57424a9ee style: fix biome formatting in sync-nitro-urls 2026-08-30 18:24:07 +02:00
openhands 678d22ceab feat: bulletproof updater + fixes for client links (icons/furniture/gamedata) 2026-08-30 18:19:46 +02:00
Simo 2a36ba1956 Merge branch 'main' into codex/housekeeping-foundation 2026-08-26 19:50:26 +02:00
openhands e7f70bb429 Chore: remove unused e2e register debug script
Flagged by knip as unused. It was a one-off DB smoke test with a
hardcoded database password that should never have been committed.
2026-08-26 15:06:14 +02:00
openhands 2d09a4a92c Add missing migrations 2026-08-26 14:28:28 +02:00
openhands 4eded4ec61 Apply Biome lint fixes 2026-08-25 22:26:05 +02:00
openhands a5044c80d7 fix: resolve biome linter warnings and code formatting 2026-08-25 21:54:02 +02:00
openhands 416c31643b perf: optimize dashboard database queries and remove unused imports 2026-08-25 21:52:18 +02:00
Simo 3b3d7780c9 docs: complete housekeeping migration matrix 2026-08-25 18:49:58 +02:00
Simo 6ed1b03e24 chore: align Node 26.7.0 toolchain 2026-08-24 19:12:11 +02:00
openhands ca1756fbb0 Fix pre-existing type errors in diagnostics scripts (blocked pre-push tsc hook) 2026-08-23 15:07:58 +02:00
openhands 536b61c7e7 Add catalog maintenance page with sprite-id, dedup and FurnitureData id-alignment repairs 2026-08-23 15:05:49 +02:00
openhands 3d832cceff scripts: fix translate call for furni18n 2026-08-21 20:06:27 +02:00
openhands f2a023efb3 scripts: fix build/translate calls for furni18n 2026-08-21 20:06:02 +02:00
openhands e66b2c1a5a scripts: add full build/translate scripts for furnidata i18n 2026-08-21 20:04:53 +02:00