d207e5653e4b0748ee38f63f3f86d811e64fb1f6
CI Pipeline with Test Management / 🧪 Run Tests & Generate Reports (push) Canceled after 0s
Test Reporting & Gherkin Analysis / 🧪 Run Tests & Generate Reports (push) Canceled after 0s
CI Pipeline with Test Management / 🐳 Docker Integration Tests (push) Canceled after 0s
CI Pipeline with Test Management / 🏗️ Build Docker Image (push) Canceled after 0s
CI Pipeline with Test Management / 📊 Generate Test Summary (push) Canceled after 0s
Test Reporting & Gherkin Analysis / 📊 Analyze Test Coverage (push) Canceled after 0s
Test Reporting & Gherkin Analysis / 🔄 Sync with Linear (push) Canceled after 0s
Test Reporting & Gherkin Analysis / ⚡ Performance Monitoring (push) Canceled after 0s
User request: don't force a logo upload to save a Partner — allow
saving name+url first, logo later. Removed `required: true` from
Partners.ts logo field. The frontend (getPartners(), payload-content.ts)
already filters out logo-less partners before rendering, so this is
safe: a partner without a logo just doesn't show on the public site
yet, nothing breaks.
While verifying this live (create a partner without a logo, check the
public homepage doesn't break), found a real, previously-undetected
bug that predates this change: partner logos never actually loaded on
the public site at all. Payload's default collection read access is
"authenticated users only" (Boolean(user)), and Media.ts never
overrode it — so GET /api/media/file/<name> always 403'd for anyone
not logged into the admin. Next.js's image optimizer (/_next/image)
fetches that URL server-side without forwarding the browser's admin
session cookie, so it always got a 403 back, which it reports as "The
requested resource isn't a valid image" (400) — the <img> silently
rendered as a broken image icon on the homepage the whole time. Fixed
by adding `access: { read: () => true }` to Media.ts — write
operations (create/update/delete) stay admin-only via Payload's
default.
Verified live in the browser: created a Partner with only name+url via
the admin (saved successfully, no required-field error), confirmed it
correctly does NOT appear on the public homepage (no logo yet), then
deleted that test record. Separately, in a fresh unauthenticated tab,
confirmed the existing Partner's logo now actually renders on /hu
(previously a broken image icon) — curl-verified both
/api/media/file/<name> and /_next/image?url=... return 200 without any
auth. Zero console errors. Gate: tsc, lint, unit tests (51 passed),
production build all green.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
mozdIT Bt. — Weboldal fejlesztés (websitedev)
Modern Next.js weboldal a mozdIT Bt. számára — webtárhely, email- és DNS-szolgáltatás, magyar IT vállalkozás.
Stack
- Frontend: Next.js 15 (Turbopack), React 19, TypeScript, Tailwind CSS 4
- CMS: Payload CMS (self-hosted,
/admin), MongoDB adapter, draft/publish + verziózás, hu/en lokalizáció - Tartalom: Payload Globals/Collections (a korábbi JSON-alapú content rendszer,
proto/src/content/, csak a migrációs script forrásaként és teszt-fixture-ként él tovább — MITHOME-91/93) - Backend: Next.js API routes, MongoDB
- Tesztelés: Jest, React Testing Library, Playwright (smoke)
- Deploy: natív Docker Compose (
deploy.sh) + Gitea Actions nélkül, lokálisan vezérelt - Monitoring: Winston + Loki, plusz
scripts/security-scan.sh(ntfy riasztással)
Gyors indítás
# Fejlesztői szerver
cd proto && npm run dev
# Docker fejlesztői környezet
docker-compose -f docker-compose.dev.yml up -d
# Teljes pre-deploy tesztkészlet
scripts/pre-deploy-tests.sh
Feladatkezelés (Plane)
- Projekt: MITHOME (workspace:
developments) - TODO.md: helyi tükör, a Plane az elsődleges forrás
- Szinkron:
node plane-sync.js(Plane → TODO.md) - Ticket-azonosítók:
MITHOME-XX
Deploy
./scripts/deploy_to_stage_on_local.sh # staging: teljes tesztkészlet + push + deploy + smoke
./deploy.sh production # éles (szerveren, staging ellenőrzése után)
A CMS „Publikálás" gombja szintén commitol + pushol + deployol (csak a beállított környezetre). Részletek: .agent/workflows/deploy.md, docs/helyi-staging-deploy.md.
Tartalomkezelés
A weboldal szövegei és a CMS a proto/src/content/ JSON-fájljaiból jönnek:
proto/src/content/
├── schema.js # közös séma-validátor (Next + CMS)
├── types.ts # TypeScript típusok
├── index.ts # tartalom-betöltő
├── common.json # közös szövegek (gombok, lábléc, a11y)
└── pages/ # oldalankénti tartalom (home, about, services, …)
Használat:
import { content, getPageContent } from '@/content'
const about = content.pages.about
Dokumentáció
- Agent-szabályok:
.agent/AGENTS.md,.agent/steering/,.agent/workflows/ - CMS felhasználói útmutató:
docs/felhasznaloi-utmutato.md(a CMS-ben a ❓ Súgó is ezt rendereli) - Plane szinkron:
PLANE-SYNC-GUIDE.md - Staging deploy:
docs/helyi-staging-deploy.md - Gitea runner:
docs/gitea-runner-telepites.md
Környezetek
- Staging: https://stage.mozdit.hu
- CMS (staging): https://cms.stage.llmdev.mozdit.hu
- ntfy (riasztás):
st_limidev_securitytopic
Biztonsági monitoring
scripts/security-scan.sh (cron, 5 percenként) kriptominer/backdoor indikátorokat figyel
(álcázott folyamatnevek, /tmp/.kworkerd-jellegű maradványok, magas CPU), és találat esetén
ntfy push-t küld a st_limidev_security topicra.
Languages
TypeScript
60.3%
JavaScript
24.8%
HTML
7%
Shell
4.4%
CSS
3%
Other
0.4%