Commit Graph
91 Commits
Author SHA1 Message Date
openhands b1ac2e1331 fix: move @next/bundle-analyzer to runtime deps for next start 2026-08-09 12:47:40 +02:00
openhands ae1393d3e3 refactor: clean up duplicate imports and dead code
- Merge type and value imports from the same module into single imports
- Remove dead import-badges action (flow uses /api/admin/import/badges)
- Remove unused babel-plugin-react-compiler devDependency
- Remove stray test.txt file
- Update knip config: track css imports, drop redundant ignore entries
- Update contract test to drop obsolete dead-action assertion
2026-08-09 11:51:26 +02:00
openhands bdcf1451f8 Revert "chore(deps): update dependency tsx to ^4.23.6"
This reverts commit b892786ff8.
2026-08-05 11:11:12 +02:00
openhands dc8fb8a6ed feat: speed up admin clone import and enable Cache Components
- Clone import: defer FurnitureData.json writes and append all entries in a
  single batched write instead of one read-modify-write per item, removing
  the main serialization bottleneck for large batches.
- Clone import: raise SSE batch concurrency cap from 5 to 10 and bump the
  clone client/route default from 2 to 6.
- Add a flush hook to runSseBatch so callers can batch deferred work before
  batch_complete is emitted, and surface flush errors as an error event.
- Enable Next.js Cache Components (instant: false opt-out) and silence the
  related build warnings in next.config.ts.
- Switch isomorphic-dompurify to dompurify and refresh dependencies.
2026-08-05 11:10:16 +02:00
remco b892786ff8 chore(deps): update dependency tsx to ^4.23.6 2026-08-05 02:00:27 +00:00
openhands b06f27ef89 chore: update dependencies 2026-08-04 21:27:09 +02:00
openhands b87c9a5b8d chore: remove puppeteer CF bypass (not working for Leet/Hubbly/Habblet)
Cloudflare has strengthened protection on these hotels.
Puppeteer-based bypass returns HTML instead of JSON.
cloudscraper has dependency issues with Node.js v26.

Reverted to simple HTTP fetch with clear error messages.
2026-08-04 18:45:10 +02:00
openhands 5c60ce364c chore: remove cf-fetch.ts (puppeteer CF bypass not working for Leet/Hubbly/Habblet)
Cloudflare has strengthened protection on these hotels.
Puppeteer-based bypass returns HTML instead of JSON.
cloudscraper has dependency issues with Node.js v26.

Reverting to simple HTTP fetch with clear error messages.
2026-08-04 18:42:20 +02:00
openhands 9fbfd2f51a chore: verify clone sources with Cloudflare bypass test script; remove broken Hubbly URLs
Verified working sources via puppeteer Cloudflare bypass test:
- Habbo (GitHub) - 200
- Wibbo - 200 furnidata, 403/403 nitro/icons
- Hubba.cc - 200 furnidata, 404 nitro
- Leet - 200 304 304 (all working)
- Habblet City - 200 200 200 (all working)
- Soda Ho - 200 furnidata, 404 nitro/icons

Cloudflare-blocked sources removed (habba.io, habcrush.pw, fobba.net, etc)
Hubbly URLs removed (all 404) pending verification
Added test-cf.ts script for future source validation
2026-08-04 17:28:01 +02:00
Simo 1f4aadb3d7 chore: remove Sentry integration 2026-08-01 22:12:31 +02:00
SimoandCursor ba82789166 chore(db): finish Prisma cutover to Drizzle Kit tooling
Move CMS SQL to drizzle/migrations, drop prisma packages/schema, wire drizzle-kit scripts, and regenerate schema names from src/db/schema.ts.

Co-authored-by: Cursor <[email protected]>
2026-08-01 15:02:21 +02:00
openhands 56061e41d4 refactor: replace Prisma ORM runtime with Drizzle ORM facade
- Replace Prisma client runtime with Drizzle ORM (zero Prisma engine/query engine in production)
- Add Prisma-compatible facade (@/lib/prisma-facade.ts) backed by Drizzle for backwards compatibility
- Runtime queries route through Drizzle ORM; @prisma/client is now devDependency (types only)
- Remove @prisma/adapter-mariadb dependency; delete prisma-pool.ts and types/prisma.ts
- New Drizzle schema layer: src/db/schema.ts (176 tables) and src/lib/db.ts (connection)
- Update README documenting the dual-layer ORM architecture
- Restore src/generated/ gitignore (build artifact for local type generation)
- 0 TypeScript errors, 583 tests passing

The facade intentionally uses `any` types to match the Prisma Client API surface,
allowing existing code to run unmodified while routing queries through Drizzle at runtime.
2026-07-31 14:11:03 +02:00
remco 9d1c71d926 chore(deps): update dependency lint-staged to ^17.3.0 2026-07-31 09:04:53 +00:00
remco 744e224fd0 chore(deps): update dependency knip to ^6.30.0 2026-07-31 08:00:29 +00:00
remco a2acac2c4c chore(deps): update All dependencies 2026-07-30 22:00:34 +00:00
openhands d805e54053 fix: update postcss override to 8.5.25 for lockfile consistency
- Update pnpm-workspace.yaml postcss override to ^8.5.25
- Sync lockfile with package.json postcss update
2026-07-30 20:02:11 +02:00
openhands 583d05eee9 feat: modernize with Next.js 16 standalone output, remove redundant babel compiler, update postcss
- Remove babel-plugin-react-compiler (Next.js 16 has built-in reactCompiler)
- Update postcss to 8.5.25
- Add output: 'standalone' to next.config.ts for smaller/faster deployments
- Update ecosystem.config.cjs to use standalone server.js
2026-07-30 20:00:31 +02:00
SimoandCursor 749dc237f1 fix(deploy): export PORT from .env before PM2 reload so health check matches
Co-authored-by: Cursor <[email protected]>
2026-07-30 18:33:38 +02:00
openhands 8c193936f6 chore: update pnpm-lock.yaml after removing @lhci/cli and @playwright/test 2026-07-30 18:09:44 +02:00
remco da390e447f chore(deps): update All dependencies 2026-07-30 17:01:53 +02:00
remco 1311d36933 chore(deps): update All dependencies 2026-07-30 00:00:20 +02:00
remco 65fae257ba chore(deps): update dependency @tanstack/react-virtual to ^3.14.9 2026-07-28 23:00:41 +02:00
openhands e08e366266 fix: remove orphaned @node-rs/argon2 and restore CI workflow
The hash-wasm package now handles both argon2id and bcrypt hashing,
making @node-rs/argon2 unused. Leaving it in package.json causes
native binary compilation failures on deploy servers (EACCES/build
errors), which breaks the deploy pipeline entirely.

Also restore .gitea/workflows/ci.yaml so CI pipelines run again.
2026-07-28 22:32:56 +02:00
SimoandCursor e644362d09 chore(deps): update dependency isomorphic-dompurify to v3
Co-authored-by: Cursor <[email protected]>
2026-07-28 20:51:46 +02:00
remco 9177230dc2 chore(deps): update dependency isomorphic-dompurify to ^1.13.0 2026-07-28 18:00:36 +00:00
openhands db39fb335c chore: successfully migrate atomcms-next to typescript 7 2026-07-28 19:30:10 +02:00
openhands 15a76ffe84 chore: lockfile update for typescript 7 2026-07-28 19:22:32 +02:00
openhands a513d9b7bd Migrate dependencies: bcrypt→@node-rs/argon2, sanitize-html→isomorphic-dompurify, remove nodemailer/next-view-transitions 2026-07-28 19:03:04 +02:00
openhands 3827f3e686 Migrate from framer-motion to motion/react 2026-07-28 18:49:25 +02:00
openhands e408fdd5e6 chore(deps): update dependency framer-motion to ^12.43.0 2026-07-28 18:40:53 +02:00
remco 2d003a2101 chore(deps): update dependency resend to ^6.18.1 2026-07-28 13:01:23 +00:00
remco 2f5d2b6e09 chore(deps): update All dependencies 2026-07-28 10:00:31 +00:00
openhands b12eaeef82 security(deps): patch sharp libvips and brace-expansion DoS vulnerabilities 2026-07-27 23:27:33 +02:00
openhands c6905d3865 chore(deps): update pnpm-lock.yaml with new overrides for CI validation 2026-07-27 23:25:29 +02:00
openhands dacc4cadfd chore(deps): upgrade to typescript 7 bridge and clean up pnpm v11 workspace configs 2026-07-27 23:14:00 +02:00
remco 65f118c918 chore(deps): update All dependencies 2026-07-27 20:00:33 +00:00
remco 3f43a62243 chore(deps): update dependency eslint to v10.8.0 2026-07-27 19:03:11 +00:00
remco 5f98b949ad chore(deps): Pin dependencies 2026-07-27 20:46:27 +02:00
remco cab4280e63 chore(deps): Pin dependencies 2026-07-27 18:46:12 +00:00
openhands 7df37728aa fix(deps): update nodemailer to v9 to resolve SSRF vulnerability (GHSA-p6gq-j5cr-w38f) 2026-07-27 17:56:53 +02:00
openhands 423a33200e chore: improve tooling, linting, testing, and CI
- Add LICENSE file (CC BY-NC-SA 4.0)
- Add .nvmrc pinning Node 22
- Add Renovate config with daily schedule and Gitea Actions workflow
- Reduce ESLint max-warnings from 1000 to 50
- Re-enable Biome a11y/security recommended rules
- Fix Biome lint issues (a11y, hook deps, SVG labels, checkbox semantics)
- Improve CI: run on pushes to feat/fix branches, add pnpm audit
- Add Vitest coverage with v8 provider and thresholds
- Add E2E tests (auth, admin, navigation specs)
- Add admin-maintenance server action test
- Install @vitest/coverage-v8
- Ignore coverage/ directory
2026-07-27 17:03:09 +02:00
openhands c670227ad4 fix: downgrade typescript to 5.x and nodemailer to 8.x for peer dep compatibility + update lockfile 2026-07-25 17:37:23 +02:00
openhands 5fa342018d chore: remove dead code and unused dependencies
- Delete 4 unused files detected by knip
- Remove lint-staged, eslint-config-prettier, plausible-tracker
- Clean up knip.json entry patterns
2026-07-24 11:59:50 +02:00
openhands 077bc9afc0 chore: update pnpm-lock.yaml for new dev dependencies 2026-07-21 23:38:04 +02:00
SimoandCursor 2ff08e5127 chore: patch deps, CSP style nonces, otplib 13, and PR CI
Co-authored-by: Cursor <[email protected]>
2026-07-21 20:46:02 +02:00
SimoandCursor 964c8b5f5a fix: pin TypeScript 5.9 until Next.js supports TS 7
Co-authored-by: Cursor <[email protected]>
2026-07-21 20:39:14 +02:00
SimoandCursor d2120987b0 perf: replace bcryptjs with native bcrypt for password hashing
Co-authored-by: Cursor <[email protected]>
2026-07-21 20:37:02 +02:00
SimoandCursor 830d252346 chore: upgrade Zod 4, Vitest 4, and TypeScript 7
Bump major tooling stacks and adapt Zod error APIs (issues/flattenError) plus tsconfig paths for TS 7 baseUrl removal.

Co-authored-by: Cursor <[email protected]>
2026-07-21 20:34:29 +02:00
SimoandCursor 9b47668fe9 chore: CSP script nonces, deploy health check, dead-code cleanup
Add per-request CSP nonces (drop script unsafe-inline), post-deploy /api/health gate, bump next-auth to beta.32, and remove unused motion/cache/permission helpers.

Co-authored-by: Cursor <[email protected]>
2026-07-21 20:27:08 +02:00
SimoandCursor c46dadeda4 chore: harden deps, env validation, admin errors, and redis warnings
Align nodemailer with Auth.js peers, bump patch deps, validate env on deploy builds, add admin error boundary, and warn when Redis is missing in production.

Co-authored-by: Cursor <[email protected]>
2026-07-21 20:19:05 +02:00