- JavaScript 92.5%
- CSS 2.1%
- HTML 2%
- PLpgSQL 1.8%
- Python 1%
- Other 0.6%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
| .forgejo/workflows | ||
| docker | ||
| docs | ||
| e2e | ||
| ops | ||
| public | ||
| ratelimits | ||
| scripts | ||
| server | ||
| test | ||
| .dockerignore | ||
| .env.example | ||
| .gitignore | ||
| .openclaw-smoke-test | ||
| API.md | ||
| ARCHITECTURE.md | ||
| CONTEXT.md | ||
| CONTRIBUTING.md | ||
| css-bhop-map-index@2.0.0 | ||
| docker-compose.yml | ||
| Dockerfile | ||
| Dockerfile.e2e | ||
| Dockerfile.e2e.dockerignore | ||
| Dockerfile.slow-map-probe | ||
| LICENSE | ||
| NEXT.md | ||
| node | ||
| openclaw-restart.sh | ||
| package-lock.json | ||
| package.json | ||
| PERFORMANCE.md | ||
| playwright.config.js | ||
| README.md | ||
| REPORT.md | ||
| ROLES.md | ||
| RUN.md | ||
| smi.50x.html | ||
| sourceindex.net.nginx.conf | ||
| tsconfig.backend.json | ||
| tsconfig.typecheck.json | ||
CSS BHOP Map Index
A searchable Counter-Strike: Source bunnyhop map index with Steam login, Postgres-backed metadata, community ratings, screenshots, tags, and server-aware discovery features.
License
To the extent copyright is held in original SourceIndex source code and
documentation, they are available under the
GNU Affero General Public License, version 3 (AGPL-3.0-only).
This notice does not assert copyright in material where none exists. The grant
does not cover third-party dependencies,
game assets, user uploads, or the tracked PNG/SVG/video files under public/;
their provenance and permission to relicense are not yet established. See
ops/public-release-audit.md before publishing
a repository export.
Repo boundary note
The product can be checked out as site/ on a deployment host or as a standalone development worktree. Work from the repository root reported by Git, not an assumed path:
git rev-parse --show-toplevel
git status --short --branch
History rewrite
On 2026-10-08, the maintainers rewrote this repository's Git history to remove
accidentally tracked private configuration and assistant-workspace files. The
project commits, branches, pull requests, and issues remain in this Forgejo
repository, but commit IDs from older clones no longer match. Re-clone the
repository instead of merging an old local branch into the rewritten history.
Pre-rewrite verified/* tags were invalidated; use only tags published by a
successful current master workflow.
Features
- searchable and filterable map index
- random and ranked map browsing modes
- Steam-based authentication
- community ratings and difficulty voting
- tag taxonomy with moderation workflow
- screenshots and map asset management
- profile, leaderboard, and contribution tracking
- optional SourceJump-backed map and record integrations
Tech stack
- Node.js
- Express
- PostgreSQL
- vanilla JS modules on the frontend
Project layout
server/application server, auth, DB access, schema, integrationspublic/static pages, frontend modules, assetstest/regression testse2e/isolated Chromium journeysops/release and operational contractsARCHITECTURE.mdsystem overviewCONTRIBUTING.mdcontributor guidance
Local setup
Install dependencies:
npm ci --include=dev
Copy env template and adjust values for your environment:
cp .env.example .env
Important before publishing or deploying:
- keep real secrets only in uncommitted
.envfiles or your deployment secret manager docker-compose.ymlis now secret-free and reads runtime config from.env- review
ALLOW_DEV_AUTH,SESSION_SECRET,DATABASE_URL,STEAM_API_KEY, and all admin credentials before going public
Initialize the database schema:
npm run db:init
Start the app:
npm start
Default local port is 3000 unless overridden.
Testing
Run the full test suite:
npm test
Optional checks:
npm run typecheck
npm run deploy:smoke
If npm run typecheck fails because node_modules/typescript is missing, refresh dependencies with npm ci and verify the lockfile and install state match before treating it as an app regression.
Key environment variables
Common settings are documented in .env.example.
Important ones include:
DATABASE_URLPOSTGRES_USER,POSTGRES_PASSWORD,POSTGRES_DBSESSION_SECRETSTEAM_REALMSTEAM_RETURN_URLSTEAM_API_KEYALLOW_DEV_AUTHCOOKIE_SECURE- SourceJump and records-provider settings
- conservative SourceJump mirror settings (
SOURCEJUMP_MIRROR_*): one queued map/minute, one incomplete record detail/5 seconds, and one duplicate-bounded latest-record walk/hour - slow-probe credentials/files via the root
.envplusscripts/source-server-probe/.envfor local probe tooling
Security notes
Minimum safe production expectations:
ALLOW_DEV_AUTH=falseCOOKIE_SECURE=trueSESSION_SECRETshould be long and random- use a non-default database password
- never commit filled
.env, probe credentials, generated tickets, local storage, or coverage artifacts
The app also enforces additional production auth checks in code.
Operations notes
The app uses in-memory caches and background prewarm/refresh loops for hot routes such as /api/maps and /api/servers.
Map contributor suggestions and Steam-ID lookups use indexed per-person rows in map_contributors; existing map writes synchronize them transactionally while legacy fields remain available for compatibility. The normalization audit is in ops/data-normalization-audit.md.
Long-lived metadata caches use bounded LRU eviction so arbitrary query, profile, map, and viewer keys cannot grow process memory without limit. Their capacities are configurable through the *_CACHE_MAX_ENTRIES settings in .env.example; current entry and eviction counts are visible in the Admin runtime-performance panel. Cache invalidation is generation-aware, so a request that started before a map mutation cannot restore stale list or detail data after the mutation completes.
At startup, frontend source is copied into .runtime/public-releases/<content-hash>, all local JS/CSS references are rewritten to immutable /_assets/<content-hash>/... URLs, and the current symlink is replaced atomically only after the complete tree is ready. Source imports use the stable ?v=source marker; manual cache-token bumps are no longer required.
For more detail, see ARCHITECTURE.md.
Contributing
See CONTRIBUTING.md for project conventions and safe refactor guidance.