tickets: makeUser now assigns roleDocs because getStaffUserIds queries the RBAC relationship and the legacy roles select field is not synced at runtime. Both specs: teardown deletes profiles (and user-notifications in market) before users, since those relationships are NOT NULL.
Add a Profiles afterChange hook that diffs progression.awards against previousDoc (row id, falling back to award+date composite key) and sends an award:granted notification including the grant reason and issuer. Register award:granted as a muteable notification type.
When the structure type has an image, render it as a full-bleed
cover behind the page header with vertical and horizontal gradient
overlays; text shifts to white for contrast. Headers without an
image keep the previous plain layout.
Add src/tools/cli with a CliFlow helper (boxed headers, labeled log
lines) and a reset-password command stub wired to the prompt package.
Runnable via 'bun run u:reset-password'; interactive flow to follow.
Add gap-1.5 to the roster tab triggers so icons and labels are not
glued together, and let the org chart tab scroll horizontally instead
of overflowing the page.
requireArmaServer (src/lib/arma-bridge/server.ts) wraps the shared
bridge auth + game-servers lookup that every v1 route repeated;
asJson (json.ts) narrows untrusted request values to what Payload's
json field validation accepts (strings normalize to the fallback
instead of failing the write). All four v1 routes now use both.
Also document the ARMA_BRIDGE_API_KEY env var missed when the bridge
routes landed.
Add the mission-tick Payload bin (external cron): sweeps missions
whose status is Scheduled/Active and whose scheduled calendar day
(classification.startDateTime, server-local) has fully passed and
sets them to Completed, emitting a mission:auto-complete event per
mission. Draft and terminal statuses are never touched; idempotent.
Notifies clients via the game-tick SSE path.
Logic lives in src/lib/intelligence/missionLifecycle.ts with an
integration test in tests/int/mission-lifecycle.int.spec.ts.
Cloning a mission whose array rows still carry the source doc's row
ids trips a unique-constraint violation in the drizzle adapter,
surfacing as 'ValidationError: The following field is invalid: id'.
Walk the collection's field schema (groups, tabs, rows, nested
arrays) and strip row ids before create — schema-driven so Lexical
richText blobs are cloned verbatim.
Also adopt the bin file logger and the standard fatal-error exit
path.
Add createBinLogger (src/scripts/lib/binFileLogger.ts): every log call
is appended synchronously to logs/<bin-key>/<YYYY-MM-DD>.log (UTC) in
addition to the console logger — sync writes because bin scripts
process.exit() immediately. Bin bodies are wrapped in try/catch so a
fatal error is logged to file and exits code 1. Override the directory
with BIN_LOG_DIR. logs/ is gitignored.
game-tick, market-tick, and processShipmentTick adopt the logger;
generate-mission follows with its clone fix; mission-tick lands with
its feature. Document BIN_LOG_DIR in .env.example and the logging in
AGENTS.md / README.
Mission objectives gain a redacted checkbox. Redacted objectives are
shown block-redacted to players; mission managers, authors, and Zeus
see the real text (via tooltip) and can toggle the flag from the
mission detail page. Toggles emit mission:objective-redacted-toggle
events. Also registers the mission:auto-complete event type used by
the upcoming mission-tick bin.
With the MCP plugin enabled, payload.auth() can return a
payload-mcp-api-keys doc instead of a User. Add an isPayloadUser
type guard and use it in every server action, page, and route that
treats the auth result as a real user, so API-key sessions can no
longer pass user auth checks. hasRoles now explicitly requires a
users-collection doc.
Register mcpPlugin on the Payload config. Auth now also accepts
payload-mcp-api-keys, so the generated types carry the new
collection and the user union widens accordingly. Follow-up commits
guard user auth paths against these API-key sessions.
Also apply incidental prettier formatting to generatePlainText().
Bump radix-ui primitives, tailwindcss/postcss, graphql, nodemailer,
drizzle-kit, eslint, prettier, @types/node and other runtime/dev deps.
The refreshed lockfile also carries entries for two new packages
(@payloadcms/plugin-mcp, prompt) whose package.json additions land
together with their features in follow-up commits.
Mark completed locker, inventory, qualification-gate, and profile items in the roadmap and record the sidebar navigation review report.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>