Commit Graph
138 Commits
Author SHA1 Message Date
openhands f53d25e0a5 feat: add view transitions, smooth scroll, bundle analyzer, SSE radio stream, and AnimatePresence animations 2026-07-20 14:06:43 +02:00
SimoandCursor dd806d2527 Reorganize admin nav by feature and soften light mode.
Sidebar lists one entry per feature; keep hub tabs only for sibling views (events, tickets, ranks/permissions, moderation, radio, analytics, devops). Soft cool-gray light canvas/surface replaces harsh white.

Co-authored-by: Cursor <[email protected]>
2026-07-18 22:06:41 +02:00
SimoandCursor 224ccd654b perf(deploy): keep .next/cache while clearing stale generated types
Nuclear src replace already guarantees clean sources; restoring the build cache speeds deploys without reintroducing sticky typecheck ghosts.

Co-authored-by: Cursor <[email protected]>
2026-07-18 21:15:52 +02:00
SimoandCursor 80c6559143 fix(deploy): stop hanging on per-file sticky-bit scan
Only clear paths that already have skip-worktree/assume-unchanged; keep nuclear src replace and content verify.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:34:34 +02:00
openhands 3eaffe658d refactor: remove explicit any across admin forms and catalog actions
- Type resolveAsChild generically over Base UI render-prop type
- Type catalog/rooms/catalog-items Prisma updates with Prisma.*UpdateInput
- Type EventForm/PollForm with explicit form-value interfaces
- Type EventPrizesManager/PollQuestionsManager with validator input types
- All typecheck, lint, and 312 tests pass
2026-07-18 20:31:18 +02:00
SimoandCursor d0f9b3ef95 fix(deploy): nuclear-replace src to defeat skip-worktree ghosts
Host built a different event-form than HEAD while git looked clean; delete src, restore from git objects, and hash-verify every tracked blob.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:30:21 +02:00
SimoandCursor 968f6ff7db fix(deploy): unstick nitro Json typecheck and wipe poisoned .next cache
Host next build still saw Json on nitro while tsc passed; use any helpers, verify blob hash, and delete .next entirely before build.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:14:50 +02:00
SimoandCursor 1abbf3fde7 fix(deploy): sync rooms Prisma types and harden checkout against stale host files
next build failed on host-local rooms.ts using Prisma without import while tsc incremental passed; force non-incremental typecheck and verify src matches HEAD.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:06:34 +02:00
SimoandCursor c053b8de87 fix(deploy): reclaim www-data ownership before git reset
Stale host sources survived reset when files were owned by www-data, leaving an old nitro editor with a removed Json type that failed typecheck.

Co-authored-by: Cursor <[email protected]>
2026-07-18 20:01:25 +02:00
SimoandCursor b22725d3a9 fix: type-safe nitro editor helpers and stabilize deploy build
Rewrite getNested/updateNested without fragile any/Json inference, clear stale .next types before build, and skip env refine during compile.

Co-authored-by: Cursor <[email protected]>
2026-07-18 19:57:33 +02:00
SimoandCursor 557138e40b fix: admin panel resiste a fallimento cookie CSRF
Il layout admin non deve crashare se cookies().set() fallisce (__Host-/Secure dietro proxy). Fallback su csrf-token, meta solo con token valido.

Co-authored-by: Cursor <[email protected]>
2026-07-18 19:48:30 +02:00
SimoandCursor 2de3696993 Enforce admin CSRF, harden catalog translate, use CMS hotel name for PayPal.
Mutating withAdmin routes now require a double-submit CSRF token; translate is capped at 500 items with audit logging; PayPal descriptions prefer siteSettings hotel_name.

Co-authored-by: Cursor <[email protected]>
2026-07-18 19:38:42 +02:00
SimoandCursor 6b884ad25a Harden deploy gates, prod AUTH_SECRET, and Sentry error reporting.
Align onlyBuiltDependencies with the workspace, fail fast without AUTH_SECRET in production, and delete catalog_items via VARCHAR-safe SQL so page deletes do not leave orphans.

Co-authored-by: Cursor <[email protected]>
2026-07-18 19:32:15 +02:00
openhands b9c6001f08 refactor: centralize duplicated formatDate helper
21 files defined their own local formatDate (with three different output
formats: date, datetime, datetime-seconds, and varying null fallbacks).
Replace them with a single shared helper at src/lib/format-date.ts that
takes a variant + optional fallback, preserving the exact previous output
per call site (verified identical string results).

Removes ~21 copies of the same logic. photos.tsx and media-grid.tsx keep
their epoch-ms based formatters since those are a different input shape.

Verified: tsc --noEmit clean, full test suite green (301/301).
2026-07-18 19:17:17 +02:00
openhands 3c9c1311ec chore: remove dead code flagged by knip
Remove 19 unused source files (no importers anywhere in src/):
- src/actions/admin-permissions.ts, admin-radio.ts, admin-user-edit.ts,
  admin-users.ts (functionality lives in @/actions/users and
  @/actions/permissions)
- src/components/admin/confirm-action.tsx, page-header.tsx
- src/components/motion-elements.tsx
- src/lib/format-date.ts
- src/lib/catalog-categories/* (incl. re-export barrel)
- src/lib/foundation/{index,database,middleware,validation}.ts (errors/action
  kept, still imported directly)
- src/lib/services/imager/{avatar-renderer,memory-cache}.ts
- src/lib/services/nitro-assets.ts

Update admin-operations-contract test to drop the two removed action-file
gates (their permission coverage already exists in users.ts/permissions.ts).

Add knip.json for repeatable dead-code audits.

Verified: tsc --noEmit clean, next build succeeds, full test suite green
(301/301).
2026-07-18 19:08:17 +02:00
openhands 60eb45be73 fix(admin): use theme-aware destructive foreground instead of hardcoded text-white
The danger confirm button used a hardcoded text-white class which failed the
admin theme source audit and could render unreadable against custom admin
themes. Switch to the semantic text-destructive-foreground token.

Also add media-grid.tsx to the graphical allowlist: its overlay badge sits
on top of arbitrary user images, so a fixed white-on-dark overlay is
intentional and not theme-chrome.

Restores the full test suite to green (303/303).
2026-07-18 18:57:14 +02:00
openhands 1bbbf6e5a4 Persist media uploads outside public/ to survive rebuilds and redeploys
Move media storage from public/assets/images/media to storage/media
(outside Git and public/), so uploaded images, favicons and logos are
preserved across rebuilds and git clean. Add a shared media-storage helper,
update the upload/serve actions and API routes, and gitignore storage/.
2026-07-18 17:04:48 +02:00
SimoandCursor 09f1bc2bd6 Add production observability: Sentry, pino, and sharp badge encoding.
Sentry is opt-in via DSN env vars; logger uses structured pino JSON in prod; badge uploads are normalized to GIF with sharp.

Co-authored-by: Cursor <[email protected]>
2026-07-17 23:09:57 +02:00
SimoandCursor ef2c3324b4 Prune unused deps, bump safe minors, add server-only guards.
Remove unused translate/jpeg types packages; refresh patch updates; mark Redis/site-settings/gamedata hotel as server-only with a Vitest stub.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:53:56 +02:00
SimoandCursor a798999440 Refresh Suggest hotel label from live CMS setting.
Avoid stale SSR/Redis cache keeping Suggest IT after habbo_gamedata_hotel changes.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:36:10 +02:00
SimoandCursor 785c1b6976 Fix client bundle pulling Redis/Prisma via habbo gamedata hotel.
Keep hotel list helpers client-safe; load CMS setting only from a server module.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:30:46 +02:00
SimoandCursor d1baaf798a Add multi-hotel Habbo gamedata locale in CMS settings.
Furni name suggestions, import enrichment, and badge texts now follow habbo_gamedata_hotel instead of hardcoded habbo.it.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:28:18 +02:00
SimoandCursor 7bc0845932 Fix catalog items missing due to page_id VARCHAR mismatch.
Use raw SQL for counts/loads/creates/moves so Habbo DBs with VARCHAR page_id and no AUTO_INCREMENT still show and persist furni.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:21:49 +02:00
SimoandCursor 1d8efefce4 Fix Visual Manager empty categories: seed roots, harden tree API.
Seed root tabs from SSR, load the full tree without CLEAR_TREE races, coerce parent ids, and tolerate catalog_items page_id type mismatches so category pages actually appear.

Co-authored-by: Cursor <[email protected]>
2026-07-17 22:02:53 +02:00
SimoandCursor b52e25578d Harden catalog admin: fix translate/quick-add, RCON sync, and confirm UX.
Restore broken Quick Add search, correct Translate saves to items_base and FurnitureData, reparent page deletes, sync RCON on create/toggle/BC mutations, and replace native confirms/prompts with dialogs.

Co-authored-by: Cursor <[email protected]>
2026-07-17 21:12:58 +02:00
SimoandCursor 1039044e48 Improve admin UX: hub i18n, dynamic topbar, settings strings, staff logs DataTable.
Co-authored-by: Cursor <[email protected]>
2026-07-17 20:14:55 +02:00
SimoandCursor 49d204e85c Remove import/repair feature and related API routes.
Co-authored-by: Cursor <[email protected]>
2026-07-17 18:52:38 +02:00
SimoandCursor 25f01b61b3 Migrate UI primitives from Radix to Base UI.
Co-authored-by: Cursor <[email protected]>
2026-07-17 18:31:07 +02:00
SimoandCursor d2c0619f2f Clean up admin hub UX: tabs, chrome, and redundant headers.
Wire orphan routes into hub tabs, group Radio into primary/tools rows, show theme/language once on desktop, and remove duplicate page titles under AdminHubChrome.

Co-authored-by: Cursor <[email protected]>
2026-07-17 18:01:01 +02:00
openhands a3b077c488 feat: add smooth site-wide animations with framer-motion
- Add framer-motion and tailwindcss-animate for transitions
- Add page transitions via AnimatePresence in the site layout
- Convert nav dropdown and mobile menu to animated motion components
- Add entry animation to the radio player widget
- Add reveal/stagger animations to the home page views
- Add shared motion utilities and reusable animated components
2026-07-16 20:58:18 +02:00
openhands 5cbe303e43 feat: make panel border color configurable via theme editor
- Add panel_border_color to THEME_COLOR_KEYS and base palettes
- Register panel-border-color CSS variable
- Fetch and inject panel_border_color in ThemeVars
- Add Panel border field to admin theme page
- Replace hardcoded #e9b124 with var(--panel-border-color) in UserView
2026-07-16 15:53:53 +02:00
openhands ddb7e77877 Make imager URL absolute using NEXT_PUBLIC_APP_URL to avoid port issues 2026-07-15 22:45:35 +02:00
openhands 19faa5615c Serve avatars from site's own /imaging endpoint instead of habbo.com
- Change default public imager URL from habbo.com to /imaging
- /imaging and /api/imaging/avatar now proxy from upstream (habbo.com) instead of redirecting
- Add resolveUpstreamBase() to separate public URL from upstream URL
- Update admin settings default and description
2026-07-15 22:23:09 +02:00
openhands 71f154cf52 Add /imaging route for avatar proxy and prevent redirect loops 2026-07-15 22:14:58 +02:00
openhands 169f658097 Add img_format=png to imager URLs and extend navbar color picker with 10 new colors 2026-07-15 22:09:47 +02:00
SimoandCursor 8cce8837bc Serve avatars from Habbo imager instead of broken self-hosted proxy.
Co-authored-by: Cursor <[email protected]>
2026-07-15 21:51:02 +02:00
SimoandCursor 7b6c02c07d Make admin light/dark mode follow real palettes end-to-end.
Light admin derives from the public light theme; dark keeps HK overrides. Remap inputs, cards, muted text, and kill the public wallpaper on admin so fonts and boxes stay readable in both modes.

Co-authored-by: Cursor <[email protected]>
2026-07-15 21:37:25 +02:00
SimoandCursor 363c9b3d56 Reorganize admin into tabbed hubs with a condensed sidebar.
Replace the long flat nav with hub entries, shared AdminHubChrome tabs, and AdminPageShell. Existing URLs stay stable; Settings/Radio and other sections now share one chrome.

Co-authored-by: Cursor <[email protected]>
2026-07-15 21:29:36 +02:00
SimoandCursor 0096c55f96 Fix theme switcher desync and auto-correct unreadable saved colors.
Sync dark-mode state from the DOM after mount so admin text no longer needs a double toggle, and normalize text/button colors against their surfaces on theme save.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:54:46 +02:00
SimoandCursor d7278c77f9 Fix automatic readable text contrast for public and admin themes.
Derive admin/public text colors from WCAG contrast, unify ThemeVars CSS emission, and keep navbar overrides in sync with readable vars.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:41:34 +02:00
SimoandCursor 9d4d409b77 Restore self-hosted /api/imaging/avatar (and badge) endpoints.
The clothing importer and imager helpers pointed at a missing route; proxy Habbo with disk/memory cache so avatars work again.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:41:18 +02:00
SimoandCursor 3403d3b19f Fix admin permissions bounce, prefixes APIs, and Italian UI leftovers.
Gate permissions on ACL manage + resolve super-admin from live user ranks, restore prefixes API routes, and anglicize hardcoded admin copy with nav i18n.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:33:00 +02:00
SimoandCursor 0e89d03940 Finish fine-grained ACL across remaining admin pages and actions.
Replace leftover requireStaff gates with module PERMS, drop hardcoded room rank thresholds, and expand contract tests so admin mutations cannot regress to dashboard-only checks.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:15:22 +02:00
SimoandCursor 3c8a8ff888 Extend fine-grained ACL to settings, content, shop, and radio.
Gate pages and mutations on module PERMS instead of dashboard-only staff checks, add radio view/edit slugs with migration 0015, and expand the operations contract tests.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:11:55 +02:00
SimoandCursor f2427b3483 Harden admin ACL on critical write paths.
Gate translations, RCON, and user mutations on SETTINGS_EDIT, RCON_EXECUTE, and USERS_EDIT instead of dashboard/rank checks; redirect the legacy user-edit URL to the guarded canonical page.

Co-authored-by: Cursor <[email protected]>
2026-07-15 20:07:15 +02:00
openhands 59b63d6e70 Fix real Biome bugs: inner declarations, dup keys, assign-in-expr, implicit any, cookie, a11y svg/keyboard, json 2026-07-14 18:58:40 +02:00
openhands 90d249e50e Fix typecheck error: use non-null assertion after expect(pair).toBeDefined() 2026-07-14 16:12:01 +02:00
openhands 026cb55cf3 Fix mobile menu blur and improve admin sidebar text contrast 2026-07-14 15:36:17 +02:00
openhands 2455a4850e fix: make useServerAction accept void-returning actions and remove dead queryCount
- Type run()'s action param as Promise<unknown> and cast result (Biome strips void from unions)
- Remove unused queryCount field increment in DbService (dead code)
- Reformat theme-contrast test pair assertions
2026-07-13 22:25:56 +02:00
openhands 045dc06a1f fix: resolve type errors and migrate pnpm settings to pnpm-workspace.yaml
- Move pnpm.onlyBuiltDependencies/overrides from package.json to pnpm-workspace.yaml (clears pnpm WARN)
- Allow useServerAction run() to accept actions returning void
- Make adminAction/authAction input optional so no-schema actions can be called without args
- Return ActionResult from updateBcPage
- Fix categoryPageMap value type (number | undefined)
- Declare DbService.queryCount field
- Use definite assignment for release in withFurniDataLock
- Narrow pair type in theme-contrast test
2026-07-13 22:10:50 +02:00