requireArmaServer (src/lib/arma-bridge/server.ts) wraps the shared
bridge auth + game-servers lookup that every v1 route repeated;
asJson (json.ts) narrows untrusted request values to what Payload's
json field validation accepts (strings normalize to the fallback
instead of failing the write). All four v1 routes now use both.
Also document the ARMA_BRIDGE_API_KEY env var missed when the bridge
routes landed.
Add the mission-tick Payload bin (external cron): sweeps missions
whose status is Scheduled/Active and whose scheduled calendar day
(classification.startDateTime, server-local) has fully passed and
sets them to Completed, emitting a mission:auto-complete event per
mission. Draft and terminal statuses are never touched; idempotent.
Notifies clients via the game-tick SSE path.
Logic lives in src/lib/intelligence/missionLifecycle.ts with an
integration test in tests/int/mission-lifecycle.int.spec.ts.
Cloning a mission whose array rows still carry the source doc's row
ids trips a unique-constraint violation in the drizzle adapter,
surfacing as 'ValidationError: The following field is invalid: id'.
Walk the collection's field schema (groups, tabs, rows, nested
arrays) and strip row ids before create — schema-driven so Lexical
richText blobs are cloned verbatim.
Also adopt the bin file logger and the standard fatal-error exit
path.
Add createBinLogger (src/scripts/lib/binFileLogger.ts): every log call
is appended synchronously to logs/<bin-key>/<YYYY-MM-DD>.log (UTC) in
addition to the console logger — sync writes because bin scripts
process.exit() immediately. Bin bodies are wrapped in try/catch so a
fatal error is logged to file and exits code 1. Override the directory
with BIN_LOG_DIR. logs/ is gitignored.
game-tick, market-tick, and processShipmentTick adopt the logger;
generate-mission follows with its clone fix; mission-tick lands with
its feature. Document BIN_LOG_DIR in .env.example and the logging in
AGENTS.md / README.
Mission objectives gain a redacted checkbox. Redacted objectives are
shown block-redacted to players; mission managers, authors, and Zeus
see the real text (via tooltip) and can toggle the flag from the
mission detail page. Toggles emit mission:objective-redacted-toggle
events. Also registers the mission:auto-complete event type used by
the upcoming mission-tick bin.
With the MCP plugin enabled, payload.auth() can return a
payload-mcp-api-keys doc instead of a User. Add an isPayloadUser
type guard and use it in every server action, page, and route that
treats the auth result as a real user, so API-key sessions can no
longer pass user auth checks. hasRoles now explicitly requires a
users-collection doc.
Register mcpPlugin on the Payload config. Auth now also accepts
payload-mcp-api-keys, so the generated types carry the new
collection and the user union widens accordingly. Follow-up commits
guard user auth paths against these API-key sessions.
Also apply incidental prettier formatting to generatePlainText().
Bump radix-ui primitives, tailwindcss/postcss, graphql, nodemailer,
drizzle-kit, eslint, prettier, @types/node and other runtime/dev deps.
The refreshed lockfile also carries entries for two new packages
(@payloadcms/plugin-mcp, prompt) whose package.json additions land
together with their features in follow-up commits.
Mark completed locker, inventory, qualification-gate, and profile items in the roadmap and record the sidebar navigation review report.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Move Banking and Market out of Logistics into a commerce group beside Personal, and add a quick XP mini-mode toggle synced to the saved display preference via the layout-provided preferences prop.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Add the mini XP display switch to PreferencesForm, wire it through the account page, and cover it in the integration test.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Add the xpDisplayMini checkbox to user display preferences, regenerate types, and accept it in updatePreferences.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Thread the Payload request through createAccount/ensurePersonalAccount and the Users beforeChange hook writes so nested creates share the parent transaction instead of failing FK checks on a fresh connection.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Add key-and-server-id authenticated endpoints for server heartbeat, event ingestion, and command pull/ack.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Add GameServers, ArmaSyncEvents and ArmaCommands collections plus registration in payload config and regenerated types.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Add domain-specific AGENTS.md files for collections, components, lib,
utils, and bot. Add login-return-url case study documenting the
return-URL flow design decisions and debugging lessons learned.
Replace legacy role-name checks in isStaff with hasPermission(discord:staff).
Auto-assign the 'user' role document on signup. Import hasPermission in
announce command for future permission gating.
Add LoginLink client component that captures current path via usePathname()
and passes it as returnTo query param. Update login page to read and
sanitize returnTo (open-redirect guard: must start with /, reject //).
Update LoginForm to redirect to returnTo after successful login. Wire
LandingPage CTA through LoginLink. Add returnTo redirect for already-
authed users hitting /login. Add return-URL to flappy page redirect.
Remove trailing blank line from (frontend) layout.