Commit Graph
105 Commits
Author SHA1 Message Date
openhands df38dccbf1 style: format code biome 2026-07-13 21:57:41 +02:00
openhands 8efd032cc6 style: format code with prettier agian 2026-07-13 21:41:52 +02:00
openhands e6d7f2280b Add named custom theme presets (save/load/rename/delete) in admin theme editor 2026-07-13 20:42:40 +02:00
openhands 01b70c2369 Make HK sidebar menu clearly readable and structured
- Strong, obvious active state: accent-tinted background, bold text,
  accent icon and left accent border so the current section is unmistakable
- Inactive items stay fully readable (white on dark) with a clear hover
- Separate nav sections with dividers and bolder uppercase headers
- Fix invisible mobile hamburger hover (bg-black/10 -> accent tint)
2026-07-13 20:29:24 +02:00
openhands 0b18a16a2d Make entire HK admin panel cohesive and always readable
- Remap shared shadcn semantic tokens (--color-primary, --color-popover,
  --color-card, --color-border, --color-ring, --color-muted-foreground,
  --color-destructive, ...) onto the admin palette for any page scoped with
  body:has([data-admin]); this themes every embedded Button, Badge, Input,
  Select, Card, Table, Tabs, Dialog, Switch, Checkbox with the admin theme
  and guaranteed contrast, without editing component files. Gated so the
  public site is untouched and Radix portals (dialogs/selects) are covered.
- Tag the admin layout/sidebar with data-admin and give the admin content
  area the admin canvas background so the whole HK is one cohesive dark UI.
- Fix hardcoded colors in catalog shop preview and favicon form to use
  admin variables; fix white text on a light warning tint (low contrast).
2026-07-13 20:24:02 +02:00
openhands a16d9859e8 Add admin HK color customization fields to theme editor
- Add 6 new admin color DB keys (admin_canvas, admin_surface, admin_text,
  admin_text_muted, admin_border, admin_sidebar_bg) that override the
  derived admin palette
- Extract adminPaletteCss() from themePaletteCss() for reuse
- Generate admin CSS variables in both :root and html.dark with overrides
- Persist admin color settings via saveTheme action
- Add Admin panel (HK) section to /admin/theme with color pickers
2026-07-13 19:49:19 +02:00
openhands 3fe3846ad5 Fix blurry mobile menu: use GPU-friendly opacity+transform instead of max-height transition 2026-07-13 19:26:02 +02:00
openhands adbd651350 Add mobile sidebar toggle for admin panel 2026-07-13 19:17:27 +02:00
openhands 7b67ef893c Fix admin sidebar height, language dropdown overflow, pagination wrap, nav dropdown min-width 2026-07-13 19:12:28 +02:00
openhands a241448e9e Revert admin sidebar toggle, fix hamburger position directly 2026-07-13 19:02:09 +02:00
openhands 53b760a815 Add admin sidebar toggle on mobile, fix table wrapping, fix grids 2026-07-13 18:52:13 +02:00
openhands c7768d8668 Move hamburger to right, fix nav overflow, add auto language detection 2026-07-13 18:20:04 +02:00
openhands eba61d2fb9 Fix mobile responsive issues
- Remove duplicate home link in mobile nav
- Remove overflow-hidden clipping main content
- Improve mobile menu scrolling and spacing
- Make top-header currencies wrap on small screens
- Reduce site-header height on mobile
- Add global mobile CSS overrides for tables, padding, fonts
2026-07-13 18:10:16 +02:00
openhands 574a499e14 Change language switcher search placeholder to English 2026-07-12 23:04:33 +02:00
openhands 187e008914 Add search to language switcher dropdown, remove translation script 2026-07-12 22:58:40 +02:00
openhands b5179c682f Limit language switcher dropdown height with scrollbar 2026-07-12 21:55:17 +02:00
openhands efe467d352 Add 12 more languages: ro, hu, cs, sk, da, no, el, bg, hr, sr, uk, ru 2026-07-12 21:52:22 +02:00
openhands 395b43081c Add Turkish language support 2026-07-12 21:47:50 +02:00
openhands e3b792f5a3 Add Portuguese, Polish, and Swedish language support with flags 2026-07-12 21:45:35 +02:00
openhands 2e4ed76121 style: format code with prettier 2026-07-12 21:07:34 +02:00
remco e85e4d74ea revert fb8e77bb68
revert style: clean up code with prettier and eslint
2026-07-12 21:02:03 +02:00
openhands fb8e77bb68 style: clean up code with prettier and eslint 2026-07-12 20:31:05 +02:00
Simo 60278b9e71 feat: add admin operations suite 2026-07-12 20:11:28 +02:00
Simo 0fe482009c fix: isolate shared admin styling 2026-07-12 18:50:44 +02:00
Simo 4ce35e91fb feat: add semantic admin palette 2026-07-12 18:47:23 +02:00
Simo 2606092337 feat: add admin content module pages 2026-07-12 15:27:07 +02:00
Simo f0b4bc1630 fix: enforce semantic contrast across admin 2026-07-12 15:14:15 +02:00
Simo b1a60adbc2 feat: rebrand CMS information as EpicNext 2026-07-12 14:49:37 +02:00
Simo 3fd2a27719 feat: generate preset-aware dark theme variables 2026-07-12 14:49:36 +02:00
Simo 5261cfaa1a feat: add CMS info footer popup 2026-07-12 14:37:00 +02:00
Simo b695a33ead fix: enforce public contrast and audit rank errors 2026-07-11 22:06:45 +02:00
Simo 8d37ae9ae0 style: normalize restored source endings 2026-07-11 21:19:54 +02:00
Simo 0cd753c735 fix: restore complete admin feature dependencies 2026-07-11 21:15:54 +02:00
Simo 5b4228261a Reapply "Add missing admin action files and navigation links"
This reverts commit 4d515bc400.
2026-07-11 20:52:56 +02:00
Simo 4d515bc400 Revert "Add missing admin action files and navigation links"
This reverts commit 41be6835bf.
2026-07-11 20:37:56 +02:00
Simo 4a1e1115b3 Harden CMS security and theme contrast 2026-07-11 20:27:20 +02:00
openhands 41be6835bf Add missing admin action files and navigation links
- Add 11 missing server action files: badges, bulk-users, catalog, catalog-bc, catalog-items, import-badges, import-furni, multi-account-detect, permissions, rooms, soundtracks
- Add missing admin navigation links: tickets, sounds, translations, import, radio sub-pages
- Add translation keys for all new navigation items
2026-07-11 12:01:05 +02:00
openhands 259c0c96ab Fix remaining Snyk findings: XSS in validImageUrl, cipher integrity suppression 2026-07-10 23:40:11 +02:00
openhands d782b7c4c2 Fix Snyk security findings: XSS, open redirect, hardcoded secrets, cookie security, MD5 replacement 2026-07-10 23:34:57 +02:00
openhands 1875a69b83 Fix security scanner findings
- Replace hardcoded test secrets with crypto-generated values in laravel-encrypter.test.ts and totp.test.ts
- Add 'secure' attribute to locale cookie in language-switcher.tsx
- Validate image URLs before rendering in media-grid.tsx and media-picker.tsx (XSS prevention)
- Validate redirect URL is HTTPS before window.location assignment in TopUpForm.tsx (open redirect prevention)
- Document intentional MD5 usage for legacy PHP compatibility in password.ts
- Document HMAC integrity protection for CBC cipher in laravel-encrypter.ts
2026-07-10 23:08:15 +02:00
openhands 942bc6fc8d Security hardening, code quality, and ESLint setup
- Remove production DB dump (db_backup_*.sql) and update.log from git tracking
- Add DB backups to .gitignore
- Replace all console.log/console.error with structured logger module
- Translate Dutch error messages to English (link-discord.ts)
- Remove dead code blocks (register-form.tsx false && pattern)
- Add ESLint flat config with TypeScript, React, Next.js, jsx-a11y, and security plugins
- Add Prettier config
- Add eslint-plugin-security for security-aware linting
- Fix all 119+ ESLint warnings across the codebase:
  - Resolve security/detect-object-injection with safe access patterns
  - Resolve security/detect-non-literal-fs-filename with path traversal validation
  - Replace <img> with next/image <Image> component
  - Remove unused variables and imports
  - Replace non-null assertions with proper type guards
  - Replace <a> with <Link> for internal navigation
  - Use next/script Script component for external scripts
- Fix setState-in-useEffect anti-patterns (navbar-color-picker, logo-generator, theme-switcher)
- Add lint and format scripts to package.json

All checks: typecheck ✓, tests 58/58 ✓, lint 0 errors 0 warnings ✓
2026-07-10 22:48:22 +02:00
openhands 7fe3220359 Inline SSO ticket generation in server component, prefetch client page from home, remove client API roundtrip 2026-07-09 18:41:04 +02:00
openhands deac10e00a Add in-memory caching for online count, enable compression, and add staleTimes for router cache 2026-07-09 18:24:58 +02:00
openhands b058a3827b Fix theme consistency, i18n completeness, CSS variable naming, and hardcoded strings 2026-07-09 18:13:22 +02:00
openhands fc57fb06d1 chore: remove dead code, unused CSS, unused components, and clean up git tracking
- Remove storage/logs/ and prod.log from git tracking; add to .gitignore
- Remove unused AvatarCarousel and ArticleSlider components
- Remove unused SkeletonTable export from ui.tsx
- Remove unused ChevronDown import from admin layout
- Remove 13 unused CSS classes (icon-base, nav-*, navigation-icon*, .app.dark,
  text-body, transition-base, card-base, admin-info-grid, .coin.*)
- Remove duplicate translation keys (openMenu/closeMenu in en.json)
- Fix admin-bans to use Prisma-generated bans_type enum
- Create shared AdminPageHeader component and formatDate utility
- Add logger and generateRequestId for structured logging
- All 58 tests pass, typecheck clean, build succeeds
2026-07-08 13:27:01 +02:00
openhands c5db7f5156 fix: production hardening — migration script, security fixes, structured logging, API docs, component splitting
- Create apply-migrations.ts and jobs-worker.ts scripts (package.json references)
- Convert badge leaderboard from $queryRawUnsafe to $queryRaw with Prisma.sql templates
- Fix OAuth email binding: add oauth_require_link site setting, skip 2FA-protected accounts
- Add per-user 2FA rate limiting (5/30s) to prevent TOTP brute-force
- Add structured JSON logger with levels (debug/info/warn/error)
- Split 341-line HomePage into GuestView + UserView components
- Add OpenAPI v3.1 spec at /api/openapi.json
- Add LOG_LEVEL env var, regenerate Prisma client
- Add mysql2 dependency for migration scripts
- All 58 tests pass, typecheck clean
2026-07-08 13:06:02 +02:00
openhands 43c0ba6614 Add Discord verification option for users without email 2026-07-07 20:37:42 +02:00
openhands f386ae2b25 Add more button/navbar colors and gradient mix section to theme editor 2026-07-07 20:04:16 +02:00
openhands e43a768ce4 Add 4 new theme colors (success, warning, error, info) with full preset support 2026-07-07 19:48:41 +02:00
openhands 8818d5364e Replace checkbox with React state-driven toggle for reliable terms acceptance 2026-07-07 19:03:33 +02:00