No description
  • JavaScript 92.5%
  • CSS 2.1%
  • HTML 2%
  • PLpgSQL 1.8%
  • Python 1%
  • Other 0.6%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Lightningblade 135ee8a7ec
All checks were successful
SourceIndex CI / verify (push) Has been skipped
SourceIndex CI / publish (push) Successful in 18s
Merge pull request 'Exclude probe auth state from Docker build context' (#129) from fix/probe-auth-build-context into master
2026-10-08 15:37:34 +02:00
.forgejo/workflows Prepare source license and gate public PR workflows 2026-10-08 08:47:57 +00:00
docker Redact database connection details from startup logs 2026-09-27 13:08:57 +00:00
docs Add coordinated backup verification 2026-08-31 17:32:08 +00:00
e2e Cover visible unresolved textures in browser journeys 2026-10-07 19:57:31 +00:00
ops Refresh rotated Steam key from current app image 2026-10-08 11:50:24 +00:00
public Handle 2.5 GiB texture BSPs with bounded staging and list failed maps 2026-10-08 06:37:13 +00:00
ratelimits Baseline after OpenClaw rescue 2026-04-17 17:13:18 +02:00
scripts Exclude probe authentication state from Docker builds 2026-10-08 13:20:44 +00:00
server Allow bounded large-source indexing to finish 2026-10-08 06:41:02 +00:00
test Set source-only propagation to logs-only 2026-10-08 13:31:10 +00:00
.dockerignore Exclude probe authentication state from Docker builds 2026-10-08 13:20:44 +00:00
.env.example Warm map caches gradually after startup 2026-10-05 13:15:51 +00:00
.gitignore Harden migrations recovery and deploy smoke 2026-09-01 07:52:34 +00:00
.openclaw-smoke-test Add .openclaw-smoke-test 2026-04-17 17:15:51 +00:00
API.md Batch texture previews and compact pixel-aware neighborhoods 2026-10-04 14:54:14 +00:00
ARCHITECTURE.md refactor: extract admin probe ticket controller and document module boundaries 2026-09-27 18:28:57 +00:00
CONTEXT.md Baseline after OpenClaw rescue 2026-04-17 17:13:18 +02:00
CONTRIBUTING.md License original source under AGPL-3.0-only 2026-10-08 09:11:52 +00:00
css-bhop-map-index@2.0.0 Baseline after OpenClaw rescue 2026-04-17 17:13:18 +02:00
docker-compose.yml Precompute texture browser buckets in limited refresh worker 2026-10-06 20:36:53 +00:00
Dockerfile Run expensive CI once per change 2026-09-16 19:58:49 +00:00
Dockerfile.e2e Add isolated Playwright test containers 2026-09-12 17:53:41 +00:00
Dockerfile.e2e.dockerignore Fix isolated release verification 2026-09-12 20:44:43 +00:00
Dockerfile.slow-map-probe Use live Steam session tickets for map probe 2026-07-31 15:51:06 +00:00
LICENSE Baseline after OpenClaw rescue 2026-04-17 17:13:18 +02:00
NEXT.md Extract map asset contribution services 2026-09-14 10:38:32 +00:00
node Baseline after OpenClaw rescue 2026-04-17 17:13:18 +02:00
openclaw-restart.sh Set source-only propagation to logs-only 2026-10-08 13:31:10 +00:00
package-lock.json Precompute texture browser buckets in limited refresh worker 2026-10-06 20:36:53 +00:00
package.json Precompute texture browser buckets in limited refresh worker 2026-10-06 20:36:53 +00:00
PERFORMANCE.md Improve cache and perf observability 2026-05-12 23:04:22 +00:00
playwright.config.js Keep browser verification out of deployment 2026-09-13 15:28:14 +00:00
README.md Document sanitized public history and release gates 2026-10-08 10:48:14 +00:00
REPORT.md Baseline after OpenClaw rescue 2026-04-17 17:13:18 +02:00
ROLES.md Baseline after OpenClaw rescue 2026-04-17 17:13:18 +02:00
RUN.md Keep last texture snapshot available during refresh 2026-10-06 21:06:52 +00:00
smi.50x.html Baseline after OpenClaw rescue 2026-04-17 17:13:18 +02:00
sourceindex.net.nginx.conf Baseline after OpenClaw rescue 2026-04-17 17:13:18 +02:00
tsconfig.backend.json Round rating displays and widen backend TS coverage 2026-05-24 23:36:53 +00:00
tsconfig.typecheck.json Make backend TypeScript-ready incrementally 2026-05-24 23:17:29 +00:00

CSS BHOP Map Index

A searchable Counter-Strike: Source bunnyhop map index with Steam login, Postgres-backed metadata, community ratings, screenshots, tags, and server-aware discovery features.

License

To the extent copyright is held in original SourceIndex source code and documentation, they are available under the GNU Affero General Public License, version 3 (AGPL-3.0-only). This notice does not assert copyright in material where none exists. The grant does not cover third-party dependencies, game assets, user uploads, or the tracked PNG/SVG/video files under public/; their provenance and permission to relicense are not yet established. See ops/public-release-audit.md before publishing a repository export.

Repo boundary note

The product can be checked out as site/ on a deployment host or as a standalone development worktree. Work from the repository root reported by Git, not an assumed path:

git rev-parse --show-toplevel
git status --short --branch

History rewrite

On 2026-10-08, the maintainers rewrote this repository's Git history to remove accidentally tracked private configuration and assistant-workspace files. The project commits, branches, pull requests, and issues remain in this Forgejo repository, but commit IDs from older clones no longer match. Re-clone the repository instead of merging an old local branch into the rewritten history. Pre-rewrite verified/* tags were invalidated; use only tags published by a successful current master workflow.

Features

  • searchable and filterable map index
  • random and ranked map browsing modes
  • Steam-based authentication
  • community ratings and difficulty voting
  • tag taxonomy with moderation workflow
  • screenshots and map asset management
  • profile, leaderboard, and contribution tracking
  • optional SourceJump-backed map and record integrations

Tech stack

  • Node.js
  • Express
  • PostgreSQL
  • vanilla JS modules on the frontend

Project layout

  • server/ application server, auth, DB access, schema, integrations
  • public/ static pages, frontend modules, assets
  • test/ regression tests
  • e2e/ isolated Chromium journeys
  • ops/ release and operational contracts
  • ARCHITECTURE.md system overview
  • CONTRIBUTING.md contributor guidance

Local setup

Install dependencies:

npm ci --include=dev

Copy env template and adjust values for your environment:

cp .env.example .env

Important before publishing or deploying:

  • keep real secrets only in uncommitted .env files or your deployment secret manager
  • docker-compose.yml is now secret-free and reads runtime config from .env
  • review ALLOW_DEV_AUTH, SESSION_SECRET, DATABASE_URL, STEAM_API_KEY, and all admin credentials before going public

Initialize the database schema:

npm run db:init

Start the app:

npm start

Default local port is 3000 unless overridden.

Testing

Run the full test suite:

npm test

Optional checks:

npm run typecheck
npm run deploy:smoke

If npm run typecheck fails because node_modules/typescript is missing, refresh dependencies with npm ci and verify the lockfile and install state match before treating it as an app regression.

Key environment variables

Common settings are documented in .env.example.

Important ones include:

  • DATABASE_URL
  • POSTGRES_USER, POSTGRES_PASSWORD, POSTGRES_DB
  • SESSION_SECRET
  • STEAM_REALM
  • STEAM_RETURN_URL
  • STEAM_API_KEY
  • ALLOW_DEV_AUTH
  • COOKIE_SECURE
  • SourceJump and records-provider settings
  • conservative SourceJump mirror settings (SOURCEJUMP_MIRROR_*): one queued map/minute, one incomplete record detail/5 seconds, and one duplicate-bounded latest-record walk/hour
  • slow-probe credentials/files via the root .env plus scripts/source-server-probe/.env for local probe tooling

Security notes

Minimum safe production expectations:

  • ALLOW_DEV_AUTH=false
  • COOKIE_SECURE=true
  • SESSION_SECRET should be long and random
  • use a non-default database password
  • never commit filled .env, probe credentials, generated tickets, local storage, or coverage artifacts

The app also enforces additional production auth checks in code.

Operations notes

The app uses in-memory caches and background prewarm/refresh loops for hot routes such as /api/maps and /api/servers. Map contributor suggestions and Steam-ID lookups use indexed per-person rows in map_contributors; existing map writes synchronize them transactionally while legacy fields remain available for compatibility. The normalization audit is in ops/data-normalization-audit.md. Long-lived metadata caches use bounded LRU eviction so arbitrary query, profile, map, and viewer keys cannot grow process memory without limit. Their capacities are configurable through the *_CACHE_MAX_ENTRIES settings in .env.example; current entry and eviction counts are visible in the Admin runtime-performance panel. Cache invalidation is generation-aware, so a request that started before a map mutation cannot restore stale list or detail data after the mutation completes.

At startup, frontend source is copied into .runtime/public-releases/<content-hash>, all local JS/CSS references are rewritten to immutable /_assets/<content-hash>/... URLs, and the current symlink is replaced atomically only after the complete tree is ready. Source imports use the stable ?v=source marker; manual cache-token bumps are no longer required.

For more detail, see ARCHITECTURE.md.

Contributing

See CONTRIBUTING.md for project conventions and safe refactor guidance.