Commit Graph
232 Commits
Author SHA1 Message Date
SimoandCursor e101ea474e Fix rooms list crash and rebuild CMS settings UI.
Rooms queried the wrong Prisma model and a non-existent owner relation. Settings now use grouped managed fields plus a searchable advanced key/value panel.

Co-authored-by: Cursor <[email protected]>
2026-07-15 21:02:57 +02:00
SimoandCursor c186f51ae0 Widen admin by escaping the public max-w-7xl chrome.
Render /admin outside the site header/nav/footer grid so housekeeping uses the full viewport width.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:59:53 +02:00
SimoandCursor 0096c55f96 Fix theme switcher desync and auto-correct unreadable saved colors.
Sync dark-mode state from the DOM after mount so admin text no longer needs a double toggle, and normalize text/button colors against their surfaces on theme save.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:54:46 +02:00
SimoandCursor ed56bf0917 Fix multi-theme contrast: separate public tokens from admin remap.
Public cards no longer paint with always-dark admin surfaces, and admin pages fully remap background/text/surface so shadcn UI stays readable on the admin canvas.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:51:20 +02:00
SimoandCursor d7278c77f9 Fix automatic readable text contrast for public and admin themes.
Derive admin/public text colors from WCAG contrast, unify ThemeVars CSS emission, and keep navbar overrides in sync with readable vars.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:41:34 +02:00
SimoandCursor 9d4d409b77 Restore self-hosted /api/imaging/avatar (and badge) endpoints.
The clothing importer and imager helpers pointed at a missing route; proxy Habbo with disk/memory cache so avatars work again.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:41:18 +02:00
SimoandCursor 3403d3b19f Fix admin permissions bounce, prefixes APIs, and Italian UI leftovers.
Gate permissions on ACL manage + resolve super-admin from live user ranks, restore prefixes API routes, and anglicize hardcoded admin copy with nav i18n.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:33:00 +02:00
SimoandCursor 0e89d03940 Finish fine-grained ACL across remaining admin pages and actions.
Replace leftover requireStaff gates with module PERMS, drop hardcoded room rank thresholds, and expand contract tests so admin mutations cannot regress to dashboard-only checks.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:15:22 +02:00
SimoandCursor 3c8a8ff888 Extend fine-grained ACL to settings, content, shop, and radio.
Gate pages and mutations on module PERMS instead of dashboard-only staff checks, add radio view/edit slugs with migration 0015, and expand the operations contract tests.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:11:55 +02:00
SimoandCursor f2427b3483 Harden admin ACL on critical write paths.
Gate translations, RCON, and user mutations on SETTINGS_EDIT, RCON_EXECUTE, and USERS_EDIT instead of dashboard/rank checks; redirect the legacy user-edit URL to the guarded canonical page.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:07:15 +02:00
SimoandCursor bae543baf6 Fix admin regressions from Biome refactor: theme init, mobile nav, i18n.
Restore valid browser JS in theme-init, close mobile sidebar on navigation, and split autoDjForm title/trackTitle across locales.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:02:25 +02:00
openhands 59b63d6e70 Fix real Biome bugs: inner declarations, dup keys, assign-in-expr, implicit any, cookie, a11y svg/keyboard, json 2026-07-14 18:58:40 +02:00
openhands 8d5c8ec96f Visibility polish: admin sidebar contrast/focus, table header readability, nav focus rings 2026-07-14 16:50:43 +02:00
openhands db1875b40b Close mobile nav menu when a link inside is tapped 2026-07-14 16:44:07 +02:00
openhands af1b18d866 Fix mobile nav: hamburger left, brand right, polished menu panel 2026-07-14 16:41:19 +02:00
openhands 48a5394204 Complete nav rewrite: native details/summary, zero JS state, zero transforms
- Mobile nav: uses <details>/<summary> for toggle, no useState, no useEffect
- Nav dropdown: uses <details>/<summary>, no useState, no event listeners
- Desktop: separate div with desktop nav items (hidden on mobile)
- Mobile: hamburger dropdown with absolute positioned panel
- CSS: removed ::after pseudo-element with transform, replaced hover
  with background-color only, added details[open] CSS rules
- No backdrop-filter, no will-change, no transition-all, no GPU hacks
- Works on every device without JS state management
2026-07-14 16:25:36 +02:00
openhands 5978b3c13d Rebuild mobile nav: absolute positioned dropdown panel, outside doc flow 2026-07-14 16:16:19 +02:00
openhands 90d249e50e Fix typecheck error: use non-null assertion after expect(pair).toBeDefined() 2026-07-14 16:12:01 +02:00
openhands c7c4617f2a Rebuild all menus from scratch for pixel-perfect rendering on every device
- mobile-nav: pure block/hidden toggle, no transforms, no transition-all
- nav-dropdown: clean block/hidden toggle, no CSS animation hacks
- navigation: removed shadow-sm, no will-change, no GPU compositing
- top-header: consistent mobile layout, clean details/summary dropdowns
- admin-mobile-wrapper: inline transition instead of CSS class for sidebar
- globals.css: removed transition-all from nav-item/dropdown-item, replaced
  with specific color/background-color transitions only, added hover bg
2026-07-14 16:10:01 +02:00
openhands 9910fd52c7 Fix blurry normal navigation on mobile: remove transition-all and shadow-sm from nav items 2026-07-14 16:01:46 +02:00
openhands bfa8aedb25 Fix blurry mobile nav: use block/hidden instead of max-h transition, add will-change to sticky nav 2026-07-14 15:47:46 +02:00
openhands 7b3e3c1531 Fix blurry mobile menu by removing CSS transform from animation 2026-07-14 15:42:24 +02:00
openhands 026cb55cf3 Fix mobile menu blur and improve admin sidebar text contrast 2026-07-14 15:36:17 +02:00
openhands 76d18e2645 Fix mobile layout issues in admin sidebar and top-header 2026-07-14 15:29:52 +02:00
openhands 2455a4850e fix: make useServerAction accept void-returning actions and remove dead queryCount
- Type run()'s action param as Promise<unknown> and cast result (Biome strips void from unions)
- Remove unused queryCount field increment in DbService (dead code)
- Reformat theme-contrast test pair assertions
2026-07-13 22:25:56 +02:00
openhands 045dc06a1f fix: resolve type errors and migrate pnpm settings to pnpm-workspace.yaml
- Move pnpm.onlyBuiltDependencies/overrides from package.json to pnpm-workspace.yaml (clears pnpm WARN)
- Allow useServerAction run() to accept actions returning void
- Make adminAction/authAction input optional so no-schema actions can be called without args
- Return ActionResult from updateBcPage
- Fix categoryPageMap value type (number | undefined)
- Declare DbService.queryCount field
- Use definite assignment for release in withFurniDataLock
- Narrow pair type in theme-contrast test
2026-07-13 22:10:50 +02:00
openhands df38dccbf1 style: format code biome 2026-07-13 21:57:41 +02:00
openhands 8efd032cc6 style: format code with prettier agian 2026-07-13 21:41:52 +02:00
openhands e6d7f2280b Add named custom theme presets (save/load/rename/delete) in admin theme editor 2026-07-13 20:42:40 +02:00
openhands 01b70c2369 Make HK sidebar menu clearly readable and structured
- Strong, obvious active state: accent-tinted background, bold text,
  accent icon and left accent border so the current section is unmistakable
- Inactive items stay fully readable (white on dark) with a clear hover
- Separate nav sections with dividers and bolder uppercase headers
- Fix invisible mobile hamburger hover (bg-black/10 -> accent tint)
2026-07-13 20:29:24 +02:00
openhands 0b18a16a2d Make entire HK admin panel cohesive and always readable
- Remap shared shadcn semantic tokens (--color-primary, --color-popover,
  --color-card, --color-border, --color-ring, --color-muted-foreground,
  --color-destructive, ...) onto the admin palette for any page scoped with
  body:has([data-admin]); this themes every embedded Button, Badge, Input,
  Select, Card, Table, Tabs, Dialog, Switch, Checkbox with the admin theme
  and guaranteed contrast, without editing component files. Gated so the
  public site is untouched and Radix portals (dialogs/selects) are covered.
- Tag the admin layout/sidebar with data-admin and give the admin content
  area the admin canvas background so the whole HK is one cohesive dark UI.
- Fix hardcoded colors in catalog shop preview and favicon form to use
  admin variables; fix white text on a light warning tint (low contrast).
2026-07-13 20:24:02 +02:00
openhands 8721cfcea4 Make HK sidebar menu text always 100% visible
- Set muted sidebar text equal to the readable sidebar text so inactive
  nav items and section labels are never dimmed
- Active item remains distinguished by its accent background and border
2026-07-13 20:13:35 +02:00
openhands d2243b5611 Fix HK sidebar menu text readability
- Derive sidebar text color from the main admin text against the actual
  sidebar background (not canvas/surface), guaranteeing contrast
- Brighten muted sidebar text to 82% of the readable text color so
  inactive nav items and section labels stay clearly visible
2026-07-13 20:10:52 +02:00
openhands cb4a6a8f3e Fix theme editor lint warnings
- Remove unused eslint-disable directive in preset swatches
- Add safe eslint-disable for controlled bgKey lookup in ColorField renderer
2026-07-13 20:06:48 +02:00
openhands acc820284b Add live contrast preview to theme editor for guaranteed readability
- New client ColorField component shows a live 'Aa' text preview on the
  relevant background and a WCAG contrast ratio badge (✓ / ⚠)
- Flags low-contrast (<4.5:1) text fields with a red border and a
  one-click 'Use readable color' fix
- Map each text color to the background it sits on (body text -> surface,
  button text -> button color, navbar text -> navbar, admin text -> canvas)
2026-07-13 20:04:58 +02:00
openhands 17894db3e9 Improve theme editor clarity with labels and descriptions
- Add a description to every color field explaining what it affects
- Regroup colors into Page & text / Buttons & links / Gradients with
  explanatory section intros for both light and dark mode
- Add section intros for light, dark, and admin (HK) modes
- Widen color field layout and show descriptions under each label
2026-07-13 19:58:38 +02:00
openhands a16d9859e8 Add admin HK color customization fields to theme editor
- Add 6 new admin color DB keys (admin_canvas, admin_surface, admin_text,
  admin_text_muted, admin_border, admin_sidebar_bg) that override the
  derived admin palette
- Extract adminPaletteCss() from themePaletteCss() for reuse
- Generate admin CSS variables in both :root and html.dark with overrides
- Persist admin color settings via saveTheme action
- Add Admin panel (HK) section to /admin/theme with color pickers
2026-07-13 19:49:19 +02:00
openhands 4dcf6fdce8 Fix admin sidebar colors: use consistent dark sidebar instead of navbar colors for professional look 2026-07-13 19:32:27 +02:00
openhands 17722acc69 Add global mobile-friendly CSS rules 2026-07-13 19:29:17 +02:00
openhands 3fe3846ad5 Fix blurry mobile menu: use GPU-friendly opacity+transform instead of max-height transition 2026-07-13 19:26:02 +02:00
openhands debee7300e Fix admin sidebar contrast: muted text now visually distinct from regular text 2026-07-13 19:21:53 +02:00
openhands adbd651350 Add mobile sidebar toggle for admin panel 2026-07-13 19:17:27 +02:00
openhands 7b67ef893c Fix admin sidebar height, language dropdown overflow, pagination wrap, nav dropdown min-width 2026-07-13 19:12:28 +02:00
openhands a241448e9e Revert admin sidebar toggle, fix hamburger position directly 2026-07-13 19:02:09 +02:00
openhands 53b760a815 Add admin sidebar toggle on mobile, fix table wrapping, fix grids 2026-07-13 18:52:13 +02:00
openhands c7768d8668 Move hamburger to right, fix nav overflow, add auto language detection 2026-07-13 18:20:04 +02:00
openhands eba61d2fb9 Fix mobile responsive issues
- Remove duplicate home link in mobile nav
- Remove overflow-hidden clipping main content
- Improve mobile menu scrolling and spacing
- Make top-header currencies wrap on small screens
- Reduce site-header height on mobile
- Add global mobile CSS overrides for tables, padding, fonts
2026-07-13 18:10:16 +02:00
openhands bef458dbf8 Rename executeRaw → executeRawUnsafe to make SQL injection risk explicit
The method wraps Prisma's  which trusts the caller
to use ? placeholders. The Unsafe suffix is a naming convention
that signals 'review caller for parameterization'.
2026-07-13 12:41:11 +02:00
openhands e5ae51bff7 Add NFC normalization to all FormData inputs across 41 server actions
All user-supplied string values from FormData now go through
String.prototype.normalize('NFC') to prevent Unicode homoglyph
attacks and canonicalization bypasses. NFC is idempotent for
already-normalized strings, so this is a pure security improvement
with zero behavioral change for legitimate users.
2026-07-13 12:21:37 +02:00
openhands e2fc7ea1a4 Complete security hardening: zero-migration foundation, edge headers, rate-limit atomics, body limits
- Make @/lib/safe-action re-export from foundation layer so all 13+
  existing server actions instantly get request tracing, rate limiting,
  and structured error handling without any code changes
- Add HSTS, CSP, X-Frame-Options, X-Content-Type-Options to edge proxy
  (src/proxy.ts) — ran at Cloudflare/Vercel edge for all non-asset routes
- Fix rate-limit.ts race condition: compute newCount before assignment
  to shrink the read-modify-write window; add memory-key prefix to
  avoid collisions with Redis keys
- Add request body size limit (10 MB default) to api-handler.ts with
  per-route override via maxBodyBytes option
- Remove unused imports and clean up backward-compat types
2026-07-13 12:09:43 +02:00