Do SikiandClaude Sonnet 5 8407b45367
CI Pipeline with Test Management / đŸ§Ș Run Tests & Generate Reports (push) Waiting to run
CI Pipeline with Test Management / 🐳 Docker Integration Tests (push) Blocked by required conditions
CI Pipeline with Test Management / đŸ—ïž Build Docker Image (push) Blocked by required conditions
CI Pipeline with Test Management / 📊 Generate Test Summary (push) Blocked by required conditions
Test Reporting & Gherkin Analysis / đŸ§Ș Run Tests & Generate Reports (push) Waiting to run
Test Reporting & Gherkin Analysis / 📊 Analyze Test Coverage (push) Blocked by required conditions
Test Reporting & Gherkin Analysis / 🔄 Sync with Linear (push) Blocked by required conditions
Test Reporting & Gherkin Analysis / ⚡ Performance Monitoring (push) Blocked by required conditions
feat(cms): Users access control + lockout policy (MITHOME-90)
Explicit, documented decisions instead of relying on implicit Payload
defaults:

- auth.maxLoginAttempts: 5, lockTime: 10 min — codifies the lockout
  policy rather than leaving it as an unstated library default.
- auth.cookies: { secure: NODE_ENV === 'production', sameSite: 'Lax' }
  — secure cookies once behind HTTPS (MITHOME-15), harmless over plain
  HTTP in local dev.
- access.{create,read,update,delete,unlock}: explicit
  requireAuthenticatedUser (== Payload's defaultAccess, Boolean(user)).
  Investigated the known open advisory flagged in MITHOME-86
  (GHSA-jg8r-5jh2-v2xj — any authenticated user can unlock any other
  account) by reading Payload's unlock operation source: the gap only
  matters when a less-privileged authenticated identity exists that
  needs protecting from a more-privileged one. This project's single
  "admin" role model (no role hierarchy — MITHOME-85 epic decision)
  has no such identity, so the default is accepted as-is, with the
  reasoning and a MITHOME-46 (central IDM/SSO) revisit trigger written
  into the code comment rather than left implicit.
- Added an optional `name` field for a nicer admin identity than a
  bare email (audit trail, header display).

Verified live: existing dev@mozdit.hu user unaffected (name column
shows "<No Name>", backward compatible). Reproduced the lockout for
real — 5 wrong POST /api/users/login attempts, 6th attempt with the
*correct* password still rejected ("locked due to too many failed
login attempts"), unlocked via Local API (overrideAccess), then the
correct password logged in successfully. build/lint/tsc/test (58
passed) all clean.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 13:26:41 +02:00

mozdIT Bt. — Weboldal fejlesztĂ©s (websitedev)

Modern Next.js weboldal a mozdIT Bt. szĂĄmĂĄra — webtĂĄrhely, email- Ă©s DNS-szolgĂĄltatĂĄs, magyar IT vĂĄllalkozĂĄs.

Stack

  • Frontend: Next.js 15 (Turbopack), React 19, TypeScript, Tailwind CSS 4
  • Tartalom: JSON-alapĂș, sĂ©ma-validĂĄlt content rendszer (proto/src/content/)
  • CMS: sajĂĄt, dependency-mentes content-editor.js (böngĂ©szƑs szerkesztƑ)
  • Backend: Next.js API routes, MongoDB
  • TesztelĂ©s: Jest, React Testing Library, Playwright (smoke), valĂłdi szervert indĂ­tĂł CMS-tesztek
  • Deploy: natĂ­v Docker Compose (deploy.sh) + Gitea Actions nĂ©lkĂŒl, lokĂĄlisan vezĂ©relt
  • Monitoring: Winston + Loki, plusz scripts/security-scan.sh (ntfy riasztĂĄssal)

Gyors indĂ­tĂĄs

# FejlesztƑi szerver
cd proto && npm run dev

# Docker fejlesztƑi környezet
docker-compose -f docker-compose.dev.yml up -d

# Teljes pre-deploy tesztkészlet
scripts/pre-deploy-tests.sh

Feladatkezelés (Plane)

  • Projekt: MITHOME (workspace: developments)
  • TODO.md: helyi tĂŒkör, a Plane az elsƑdleges forrĂĄs
  • Szinkron: node plane-sync.js (Plane → TODO.md)
  • Ticket-azonosĂ­tĂłk: MITHOME-XX

Deploy

./scripts/deploy_to_stage_on_local.sh   # staging: teljes tesztkészlet + push + deploy + smoke
./deploy.sh production                  # Ă©les (szerveren, staging ellenƑrzĂ©se utĂĄn)

A CMS „PublikĂĄlĂĄs" gombja szintĂ©n commitol + pushol + deployol (csak a beĂĄllĂ­tott környezetre). RĂ©szletek: .agent/workflows/deploy.md, docs/helyi-staging-deploy.md.

Tartalomkezelés

A weboldal szövegei és a CMS a proto/src/content/ JSON-fåjljaiból jönnek:

proto/src/content/
├── schema.js        # közös sĂ©ma-validĂĄtor (Next + CMS)
├── types.ts         # TypeScript típusok
├── index.ts         # tartalom-betöltƑ
├── common.json      # közös szövegek (gombok, lĂĄblĂ©c, a11y)
└── pages/           # oldalankĂ©nti tartalom (home, about, services, 
)

HasznĂĄlat:

import { content, getPageContent } from '@/content'
const about = content.pages.about

DokumentĂĄciĂł

  • Agent-szabĂĄlyok: .agent/AGENTS.md, .agent/steering/, .agent/workflows/
  • CMS felhasznĂĄlĂłi ĂștmutatĂł: docs/felhasznaloi-utmutato.md (a CMS-ben a ❓ SĂșgĂł is ezt rendereli)
  • Plane szinkron: PLANE-SYNC-GUIDE.md
  • Staging deploy: docs/helyi-staging-deploy.md
  • Gitea runner: docs/gitea-runner-telepites.md

Környezetek

BiztonsĂĄgi monitoring

scripts/security-scan.sh (cron, 5 percenkĂ©nt) kriptominer/backdoor indikĂĄtorokat figyel (ĂĄlcĂĄzott folyamatnevek, /tmp/.kworkerd-jellegƱ maradvĂĄnyok, magas CPU), Ă©s talĂĄlat esetĂ©n ntfy push-t kĂŒld a st_limidev_security topicra.

S
Description
No description provided
Readme MIT
2.5 MiB
Languages
TypeScript 60.3%
JavaScript 24.8%
HTML 7%
Shell 4.4%
CSS 3%
Other 0.4%