Files
websitedev/proto
Do SikiandClaude Sonnet 5 8407b45367
CI Pipeline with Test Management / 🧪 Run Tests & Generate Reports (push) Waiting to run
CI Pipeline with Test Management / 🐳 Docker Integration Tests (push) Blocked by required conditions
CI Pipeline with Test Management / 🏗️ Build Docker Image (push) Blocked by required conditions
CI Pipeline with Test Management / 📊 Generate Test Summary (push) Blocked by required conditions
Test Reporting & Gherkin Analysis / 🧪 Run Tests & Generate Reports (push) Waiting to run
Test Reporting & Gherkin Analysis / 📊 Analyze Test Coverage (push) Blocked by required conditions
Test Reporting & Gherkin Analysis / 🔄 Sync with Linear (push) Blocked by required conditions
Test Reporting & Gherkin Analysis / ⚡ Performance Monitoring (push) Blocked by required conditions
feat(cms): Users access control + lockout policy (MITHOME-90)
Explicit, documented decisions instead of relying on implicit Payload
defaults:

- auth.maxLoginAttempts: 5, lockTime: 10 min — codifies the lockout
  policy rather than leaving it as an unstated library default.
- auth.cookies: { secure: NODE_ENV === 'production', sameSite: 'Lax' }
  — secure cookies once behind HTTPS (MITHOME-15), harmless over plain
  HTTP in local dev.
- access.{create,read,update,delete,unlock}: explicit
  requireAuthenticatedUser (== Payload's defaultAccess, Boolean(user)).
  Investigated the known open advisory flagged in MITHOME-86
  (GHSA-jg8r-5jh2-v2xj — any authenticated user can unlock any other
  account) by reading Payload's unlock operation source: the gap only
  matters when a less-privileged authenticated identity exists that
  needs protecting from a more-privileged one. This project's single
  "admin" role model (no role hierarchy — MITHOME-85 epic decision)
  has no such identity, so the default is accepted as-is, with the
  reasoning and a MITHOME-46 (central IDM/SSO) revisit trigger written
  into the code comment rather than left implicit.
- Added an optional `name` field for a nicer admin identity than a
  bare email (audit trail, header display).

Verified live: existing dev@mozdit.hu user unaffected (name column
shows "<No Name>", backward compatible). Reproduced the lockout for
real — 5 wrong POST /api/users/login attempts, 6th attempt with the
*correct* password still rejected ("locked due to too many failed
login attempts"), unlocked via Local API (overrideAccess), then the
correct password logged in successfully. build/lint/tsc/test (58
passed) all clean.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 13:26:41 +02:00
..
2026-08-23 12:11:59 +02:00

mozdIT Bt. Website - Next.js Application

Modern Next.js 15 website for mozdIT Bt. - Hungarian IT services company.

🚀 Quick Start

# Install dependencies
npm install

# Development server (with Turbopack)
npm run dev

# Production build
npm run build

# Run tests
npm test

Open http://localhost:3000 to view the site.

📁 Project Structure

src/
├── app/                 # Next.js App Router
│   ├── page.tsx        # Homepage
│   ├── rolunk/         # About page
│   ├── szolgaltatasok/ # Services page
│   ├── kapcsolat/      # Contact page
│   ├── api/            # API routes
│   └── globals.css     # Design system & styles
├── components/         # React components
│   ├── Header.tsx      # Navigation header
│   ├── Footer.tsx      # Site footer
│   └── ThemeProvider.tsx # Dark mode provider
├── content/            # JSON content management
│   ├── types.ts        # Content type definitions
│   ├── index.ts        # Content loader
│   ├── common.json     # Shared texts
│   └── pages/          # Page-specific content
├── config/             # Site configuration
├── lib/                # Utilities
└── types/              # TypeScript definitions

🎨 Design System

The project uses a comprehensive design system defined in globals.css:

CSS Variables

  • Brand colors (--color-primary-*)
  • Semantic colors (--color-background, --color-foreground)
  • Shadows, transitions, border radius

Dark Mode

  • Automatic system preference detection
  • Manual toggle via ThemeProvider
  • Uses data-theme="dark" attribute

Animations

  • animate-fade-in-up - Fade in with upward motion
  • animate-float - Floating effect
  • animate-pulse-slow - Slow pulsing
  • hover-lift, hover-scale, hover-glow - Hover effects

Utility Classes

  • .card - Card component styling
  • .btn, .btn-primary, .btn-secondary - Button styles
  • .icon-container - Icon wrapper styling

📝 Content Management

All page content is managed through JSON files in src/content/:

import { content, getPageContent } from '@/content'

// Access specific page content
const aboutContent = content.pages.about

// Or use the helper function
const servicesContent = getPageContent('services')

Content Files

File Description
common.json Shared texts (buttons, labels, validation)
pages/home.json Homepage CTA section
pages/about.json About page (hero, story, mission, team, CTA)
pages/services.json Services (hero, details, support, CTA)
pages/contact.json Contact (form labels, FAQ, info)

🧪 Testing

# Unit tests
npm test

# Watch mode
npm run test:watch

# Coverage report
npm run test:coverage

# All test suites
npm run test:all

🐳 Docker Development

For full-stack development with MongoDB and monitoring:

# From project root
docker-compose -f docker-compose.dev.yml up -d

Services:

📚 Learn More