Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
1827 commits
Select commit Hold shift + click to select a range
ad0865e
fix(build): resolve async chunk URLs from entry script location
juanclaude-conduction Jul 8, 2026
64d501f
chore: 0.3.12 cache-bust after serving-copy repair
juanclaude-conduction Jul 8, 2026
9ee4c1c
Merge pull request 'fix(detail-pages): async chunk URL resolution + 0…
Jul 8, 2026
511b558
fix(consultation-detail): correct reactions KPI filter + remove dupli…
juanclaude-conduction Jul 9, 2026
c750e68
fix(meeting-detail): wire custom-widget slots, add stats-block KPI
juanclaude-conduction Jul 9, 2026
a3fff24
fix(detail-pages): amendment slots gap + card-bottom clipping (rules …
juanclaude-conduction Jul 9, 2026
18438dc
fix(workspace): remove orphaned collaboration-workspace pages, not ti…
juanclaude-conduction Jul 9, 2026
10bd38d
Merge pull request 'fix(detail-pages): slots wiring for custom widget…
Jul 9, 2026
d25bb1f
chore(deps): nc-vue 1.0.0-beta.162 + version bump (visual-audit fix r…
juanclaude-conduction Jul 9, 2026
1fab520
Merge pull request 'decidesk: merge chore/ncvue-beta162-rollout into …
Jul 9, 2026
6e74705
fix(detail-pages): split multi-entry KPI stats-blocks into individual…
juanclaude-conduction Jul 9, 2026
afc94fd
Merge pull request 'ci: adopt canonical test workflow (node fix + con…
Jul 9, 2026
32fb88c
Meeting agenda and action counters as separate tiles (#121)
Jul 9, 2026
b73b70b
sync development
juanclaude-conduction Jul 9, 2026
68cc550
chore: pin @conduction/nextcloud-vue 1.0.0-beta.164
juanclaude-conduction Jul 9, 2026
f376f06
Merge remote-tracking branch 'origin/development' into HEAD
juanclaude-conduction Jul 9, 2026
3b315db
Merge pull request 'decidesk onboarding + dashboard: walkthrough + cl…
Jul 9, 2026
ffd68ab
Meeting tooling refreshed against the latest lib (#122)
Jul 9, 2026
a5c49bd
fix(integrations): make the Besluitvorming decision leaf host-agnosti…
Jul 10, 2026
82f89e0
Governance library pinned to the cross-register foundation build (#124)
Jul 10, 2026
abe574f
docs(openspec): preserve authored-but-uncommitted spec changes (2026-…
juanclaude-conduction Jul 10, 2026
135b467
Merge decidesk-reapply-2026-07-07 (consolidation 2026-07-10)
juanclaude-conduction Jul 10, 2026
f675242
Merge fix/adr062-kpi-split (consolidation 2026-07-10)
juanclaude-conduction Jul 10, 2026
38521a2
Merge specs/authored-2026-07-10 (consolidation 2026-07-10)
juanclaude-conduction Jul 10, 2026
4ba747d
build(deps): upgrade @nextcloud/dialogs to v6 so spawnDialog resolves
juanclaude-conduction Jul 12, 2026
2b67c75
build: add path:false resolve fallback for dialogs v6 FilePicker chunk
juanclaude-conduction Jul 12, 2026
60f4c3a
Merge pull request 'build(deps): upgrade @nextcloud/dialogs to v6 so …
Jul 12, 2026
cd11584
chore(deps): nc-vue beta.190 — restores the scoped component styles
juanclaude-conduction Jul 12, 2026
0f275e8
Merge remote-tracking branch 'origin/development' into HEAD
rubenvdlinde Jul 12, 2026
cd30b13
build: upgrade shared Vue library to beta.190 (scoped CSS regression)…
rubenvdlinde Jul 12, 2026
83f3dca
chore(deps): retarget nc-vue to beta.194
rubenvdlinde Jul 12, 2026
954f8fe
Merge development; keep nc-vue at beta.194
rubenvdlinde Jul 12, 2026
8c716b8
Merge pull request 'decidesk: nc-vue beta.194 (stat/KPI cards render …
Jul 12, 2026
c6efddc
fix(openregister): repair 6 dead ObjectService::findAll() calls + rea…
juanclaude-conduction Jul 13, 2026
37ba3b9
Merge pull request 'fix(decidesk): 6 broken ObjectService::findAll() …
Jul 13, 2026
15da911
docs(openspec): add decidesk-mcp-adoption ff change (ADR-063)
juanclaude-conduction Jul 13, 2026
fd959c4
Merge pull request 'decidesk: ADR-063 MCP adoption spec — 10 of 37 sc…
Jul 13, 2026
eaedf04
fix(security): store decidesk voter_token_secret as sensitive (was cl…
juanclaude-conduction Jul 13, 2026
e513760
fix(security): store voter_token_secret as sensitive (#132)
Jul 13, 2026
16d1cc1
build(deps): update @conduction/nextcloud-vue to ^1.0.0-beta.212
juanclaude-conduction Jul 15, 2026
4599a23
Merge pull request 'fix(live-updates): beta.212 transport fix reaches…
Jul 15, 2026
3095c8f
chore(deps): advance nextcloud-vue lock to beta.213
juanclaude-conduction Jul 16, 2026
e147951
Merge pull request 'chore(deps): advance nextcloud-vue lock to beta.2…
Jul 16, 2026
5787c3a
wip: preserve work (pc reset 2026-07-16) — NOT tested, NOT ready to m…
juanclaude-conduction Jul 16, 2026
04e830d
docs(audit): decidesk seed-mechanism + done-spec audit findings (WIP)
juanclaude-conduction Jul 16, 2026
a5b72cf
fix(spec): repoint broken @spec anchors to canonical specs
rubenvdlinde Jul 16, 2026
ba73c7c
docs(openspec): spec-anchor-repair change (proposal/design/tasks/resi…
rubenvdlinde Jul 16, 2026
17eac8b
Merge pull request 'decidesk: spec-anchor-repair (apply) — 519 anchor…
Jul 16, 2026
f50214c
fix(seeds): plant 21 declarations via x-openregister.seedData + versi…
juanclaude-conduction Jul 16, 2026
6ec185c
docs(openspec): fix-inert-seeds change — proposal, design, tasks, spe…
juanclaude-conduction Jul 16, 2026
c083832
docs(openspec): satisfy strict validator on REQ-SEED-003
juanclaude-conduction Jul 16, 2026
b08373e
chore(openspec): archive spec-anchor-repair change
rubenvdlinde Jul 16, 2026
2818e85
Merge pull request 'decidesk: archive the spec-anchor-repair change' …
Jul 16, 2026
0d62b07
test(seeds): assert seeds at the location that actually plants
juanclaude-conduction Jul 16, 2026
0aa9b23
Merge remote-tracking branch 'origin/development' into fix-inert-seeds
juanclaude-conduction Jul 16, 2026
f15f89a
Merge pull request 'decidesk: fix-inert-seeds (apply)' (#138) from fi…
Jul 16, 2026
69eda13
fix(dialect): un-inert two declarative dialects the engines never read
juanclaude-conduction Jul 16, 2026
942ba20
docs(openspec): done-spec-fixes — audit of 88 done specs, gate-6 trio…
juanclaude-conduction Jul 16, 2026
875259d
Merge pull request 'decidesk: done-spec-fixes (apply)' (#140) from do…
Jul 16, 2026
1b78b0d
docs(openspec): archive fix-inert-seeds + done-spec-fixes; promote sp…
juanclaude-conduction Jul 16, 2026
d03de57
Merge pull request 'decidesk: archive fix-inert-seeds + done-spec-fix…
Jul 16, 2026
db69fb2
docs(audit): decidesk done-spec audit report 2026-07-16
juanclaude-conduction Jul 16, 2026
ded8ab5
Merge pull request 'decidesk: done-spec audit report' (#142) from arc…
Jul 16, 2026
f1e1955
docs(openspec): six market-gap changes from 2026-07-16 Decidesk deep-…
juanclaude-conduction Jul 17, 2026
a772034
Merge remote-tracking branch 'origin/development' into feat/market-ga…
juanclaude-conduction Jul 17, 2026
9157b18
Merge pull request #344 from ConductionNL/feat/market-gap-specs-20260716
rubenvdlinde Jul 17, 2026
0ddbfe8
wip(openspec): wave-2 checkpoint — wave A complete (7 changes), wave …
juanclaude-conduction Jul 17, 2026
dec1f7f
wip(openspec): wave-2 checkpoint — wave B complete (13/19 changes)
juanclaude-conduction Jul 17, 2026
05b10ea
wip(openspec): wave-2 checkpoint — wave C complete (19/19 changes)
juanclaude-conduction Jul 17, 2026
9defeb2
docs(openspec): nineteen market-gap changes — wave 2 of the Decidesk …
juanclaude-conduction Jul 17, 2026
6b1304e
Merge pull request #345 from ConductionNL/feat/market-gap-wave2-20260717
rubenvdlinde Jul 17, 2026
0f996b0
fix(openspec): records-management-archiving consumes OpenRegister's s…
juanclaude-conduction Jul 17, 2026
6bf9db3
Merge pull request #346 from ConductionNL/fix/rma-consume-or-records-…
rubenvdlinde Jul 17, 2026
954c20a
fix(register): Decision schema union types → OR-supported nullable
juanclaude-conduction Jul 18, 2026
2226016
wip(toezeggingen): declarative core (Tasks 1-4) — schemas, seed, page…
juanclaude-conduction Jul 18, 2026
8a1657b
Merge pull request #347 from ConductionNL/fix/decision-schema-union-t…
rubenvdlinde Jul 18, 2026
54b01ca
fix(toezeggingen): KPI filter uses documented in-operator; note OR mu…
juanclaude-conduction Jul 18, 2026
b0055bd
wip(apply): batch-1 declarative cores — 6 changes, 13 schemas
juanclaude-conduction Jul 18, 2026
7a8c44f
fix(delegatie): remove allOf/anyOf composition — OR treats allOf as s…
juanclaude-conduction Jul 18, 2026
bceed39
wip(apply): batch-2 declarative cores — 6 changes, 14 schemas + bodyT…
juanclaude-conduction Jul 18, 2026
a619af2
fix(batch2): remove _note key from authorization blocks (3 schemas)
juanclaude-conduction Jul 18, 2026
64eeb5c
wip(apply): batch-3 declarative cores — 7 changes
juanclaude-conduction Jul 18, 2026
7fdd8bc
fix(batch3): strip unproven x-openregister-relations/-aggregations/-c…
juanclaude-conduction Jul 18, 2026
6696244
Merge pull request #348 from ConductionNL/feat/apply-toezeggingen-ing…
rubenvdlinde Jul 18, 2026
f47da83
fix(test): load OpenRegister stubs via phpunit bootstrap, not compose…
juanclaude-conduction Jul 22, 2026
98d16bf
Merge pull request #349 from ConductionNL/fix/or-stub-autoload-shadow
rubenvdlinde Jul 22, 2026
c5d5263
docs(openspec): add portal-citizen-create-actions ff change
rubenvdlinde Jul 23, 2026
acbf243
Merge pull request #353 from ConductionNL/wip/portal-citizen-create-a…
rubenvdlinde Jul 23, 2026
ca32a5b
feat(portal): citizen create actions — reactions + budget proposals (…
juanclaude-conduction Jul 23, 2026
74985da
Merge pull request #354 from ConductionNL/wip/apply-portal-citizen-cr…
rubenvdlinde Jul 23, 2026
dd95094
chore(deps): bump @conduction/nextcloud-vue to beta.219 (#357)
rubenvdlinde Jul 24, 2026
0e41c6d
feat: migrate decidesk to Vue 3 + @conduction/nextcloud-vue v2, flip …
rubenvdlinde Jul 26, 2026
cf165af
test(e2e): green the Vue-3 e2e suite + fix detail-page slots regressi…
rubenvdlinde Jul 27, 2026
bc9d39c
feat(icons): adopt the ADR-077 semantic icon vocabulary (#363)
rubenvdlinde Jul 30, 2026
fca04e1
feat(icons): extend ADR-077 to page, widget and action icons (#364)
rubenvdlinde Jul 30, 2026
c5d0f60
perf(events): declare object-event interest at registration time (#365)
rubenvdlinde Aug 1, 2026
e37dca2
chore(deps,ci): drop the proprietary vue3-apexcharts and revive Code …
rubenvdlinde Aug 1, 2026
fc62511
build: make composer check:strict able to fail (#367)
rubenvdlinde Aug 2, 2026
063b678
chore(deps): @conduction/nextcloud-vue 2.1.0-vue3.13 -> 2.1.0-vue3.16…
rubenvdlinde Aug 2, 2026
1439fef
fix(ci): make composer check:strict able to fail on tests (#370)
rubenvdlinde Aug 2, 2026
48455c9
fix(quality): PHPStan 57 → 0 and phpcs 4 → 0, plus a 404 that was ret…
rubenvdlinde Aug 3, 2026
d21a03e
refactor(quality): PHPMD 378 → 174 — MissingImport to zero, no baseli…
rubenvdlinde Aug 3, 2026
4228687
fix(quality): phpmd DevelopmentCodeFragment could never fire on names…
rubenvdlinde Aug 3, 2026
ab28e46
chore(security): refresh roave/security-advisories guard (2026-06-25 …
rubenvdlinde Aug 3, 2026
502b10d
ci: bound every unbounded CI job with timeout-minutes (#375)
rubenvdlinde Aug 3, 2026
b4804a0
fix(quality): clear all 174 phpmd findings on development (#376)
rubenvdlinde Aug 3, 2026
36985fa
fix(quality): clear 80 PHPMD findings in decidesk (153 → 73) (#379)
rubenvdlinde Aug 3, 2026
522fe10
fix(quality): clear PHPMD architectural debt in decidesk (73 → 7) (#380)
rubenvdlinde Aug 4, 2026
45890e1
fix(quality): decompose Application bootstrap, motions and the remain…
rubenvdlinde Aug 4, 2026
f78a407
fix(quality): decompose the minutes and mail-reply cluster (23 phpmd …
rubenvdlinde Aug 4, 2026
f2f65c8
fix(quality): decompose the voting cluster (18 phpmd findings) (#385)
rubenvdlinde Aug 4, 2026
aea16b6
chore(quality): delete the dead phpmd baseline; cut the phpstan basel…
rubenvdlinde Aug 4, 2026
b3178e8
chore(deps): upgrade @conduction/nextcloud-vue to 3.0.0-vue3.4 (#387)
rubenvdlinde Aug 4, 2026
9412aa9
fix(apphost): stop one cross-app extends from 500ing every decidesk r…
rubenvdlinde Aug 4, 2026
2b65908
feat(schema): mark ProcessTemplate shareable for federated config sha…
rubenvdlinde Aug 4, 2026
a3aa93f
chore(ci): remove dead Forgejo/Codeberg CI residue (#394)
rubenvdlinde Aug 4, 2026
3ae53f5
fix(ui): NcButton `native-type` is inert on @nextcloud/vue 9 — six Sa…
rubenvdlinde Aug 4, 2026
e6a7bbf
fix(quality): remove the 'not installed, skipping' swallow from test:…
rubenvdlinde Aug 4, 2026
ecf304d
fix(ci): Newman ran against a Nextcloud with no OpenRegister — 206/28…
rubenvdlinde Aug 4, 2026
190d69a
chore(deps): @conduction/nextcloud-vue 3.0.0-vue3.6
Aug 4, 2026
1bb6fef
Merge pull request #402 from ConductionNL/chore/ncvue-vue3.6
rubenvdlinde Aug 4, 2026
fc6ce6b
ci(quality): enable the Code Quality gates this repo was silently ski…
rubenvdlinde Aug 4, 2026
2f3525e
fix(register): the decidesk register could never be created on a clea…
rubenvdlinde Aug 5, 2026
66a1756
chore(deps): repin @conduction/nextcloud-vue to 2.2.0-vue3.3 (3.0.0-v…
rubenvdlinde Aug 5, 2026
99fcf4a
ci(quality): move hydra-gates-ref v1.0.1 -> v1.3.0, which is what is …
rubenvdlinde Aug 5, 2026
5296fee
chore(license): normalise licence declarations to EUPL-1.2 (#413)
rubenvdlinde Aug 5, 2026
af1a1bc
fix(phpmd): scope the lib/Migration UnusedFormalParameter exclusion t…
rubenvdlinde Aug 5, 2026
2729239
ci(e2e): turn on the Playwright job, which has never run — honestly r…
rubenvdlinde Aug 5, 2026
4f2cbb4
fix(ci): compare the coverage ratchet against the measured merge base…
rubenvdlinde Aug 6, 2026
1bdb410
chore(ci): stop pinning hydra-gates — track the package at @main (#414)
rubenvdlinde Aug 6, 2026
a377dbf
ci: publish an installable build of development (#417)
rubenvdlinde Aug 6, 2026
506b845
fix(e2e): seed the fixture, key relation filters correctly, wire the …
juanclaude-conduction Aug 6, 2026
63d71cc
fix(e2e): unblock the quality gates, plus the objectId, findAll-conte…
juanclaude-conduction Aug 6, 2026
214505a
fix(security): PHP_CodeSniffer 3.13.5 -> 3.13.6 (CVE-2026-67434, OS c…
rubenvdlinde Aug 6, 2026
1639875
fix(e2e): the seed's own error messages went into a variable, not the…
juanclaude-conduction Aug 6, 2026
e2b9515
fix(e2e): three lying skips in voting-rules — a 404 reported as 'seed…
juanclaude-conduction Aug 6, 2026
86be804
fix(e2e): a hook signature aborted the ENTIRE suite before a single t…
juanclaude-conduction Aug 6, 2026
b61ca99
fix(quality): keep the CVE fix and stop it turning the phpcs gate red
juanclaude-conduction Aug 6, 2026
d16dfb9
fix(e2e): the workflow fixture's motion seed was missing two required…
juanclaude-conduction Aug 6, 2026
da80c8f
fix(tests): a catch-all container stub handed the ObjectService mock …
rubenvdlinde Aug 7, 2026
23ac0be
Merge pull request #418 from ConductionNL/fix/e2e-burndown-0806
rubenvdlinde Aug 7, 2026
a58706c
chore: raise the Nextcloud floor to 32 (#423)
rubenvdlinde Aug 7, 2026
cccf3f7
fix: restore the pre-32 Nextcloud floor — this repo tests stable31 (#…
rubenvdlinde Aug 7, 2026
7a68aeb
fix(phpcs): stop the SpecTagSniff instructing the pattern gate-46 rej…
rubenvdlinde Aug 8, 2026
427d8ca
fix(e2e): add a globalTimeout under the 45m CI cap (#431)
rubenvdlinde Aug 8, 2026
ee83086
Merge pull request #432 from ConductionNL/fix/spec-tag-sniff-canonica…
rubenvdlinde Aug 8, 2026
bcaf68d
fix(compat): NC 32 floor + drop the impossible stable31 CI leg (#426)
rubenvdlinde Aug 8, 2026
154df4d
fix(settings): implement settings#update — PUT /api/settings 500'd (#…
rubenvdlinde Aug 8, 2026
675addd
fix(decision): require outcome + decisionDate only in terminal states…
rubenvdlinde Aug 8, 2026
7959d03
fix(adr-005): complete the Decision-supertype migration in PHP — 500s…
rubenvdlinde Aug 9, 2026
92f56c8
fix(a11y,manifest): a blank page, five unreachable rows, and a .gitig…
rubenvdlinde Aug 9, 2026
1c6efc3
fix(auth,jobs): 13 undeclared admin endpoints, a 500 on an unknown id…
rubenvdlinde Aug 9, 2026
c3f2c4c
fix(spec): 18 @spec tags pointed at files that do not exist (#440)
rubenvdlinde Aug 9, 2026
5038943
fix(or): three endpoints answered 500 where they owed 404, and the se…
rubenvdlinde Aug 9, 2026
dedb791
fix(e2e,manifest): a wait that never settles, and a Settings > Settin…
rubenvdlinde Aug 9, 2026
d7eec08
fix(newman): two Meeting seeds violated the shipped Meeting schema (1…
rubenvdlinde Aug 10, 2026
acbae17
build(deps): bump the npm_and_yarn group across 2 directories with 16…
dependabot[bot] Aug 10, 2026
6fb701d
chore(deps): pin @conduction/nextcloud-vue to 2.2.0-vue3.9 (#446)
rubenvdlinde Aug 10, 2026
a55fe64
fix(newman): decidesk#443 was a cookie jar, and it hid five real defe…
rubenvdlinde Aug 10, 2026
c9071f1
fix(e2e): a tie is not a result, and a stock Nextcloud has no VTODO c…
rubenvdlinde Aug 11, 2026
e5f563f
fix(gates): an unregistered icon renders as nothing, not as a fallbac…
rubenvdlinde Aug 11, 2026
3511f0f
fix(gates): a widget icon outside the shared registry renders a gener…
rubenvdlinde Aug 11, 2026
012f96b
fix(lists): a newly created object landed on page 2, because no list …
rubenvdlinde Aug 11, 2026
38860b1
fix(repo): a committed node_modules symlink pointed every clone at on…
rubenvdlinde Aug 11, 2026
e03f593
test(contract): 21 public endpoints that no test had ever called (#456)
rubenvdlinde Aug 11, 2026
461952a
fix: ADR-079 D1 deletes the duplicate settings surface, and four of t…
rubenvdlinde Aug 11, 2026
443a77e
gates: close gate-54, gate-25 and gate-26 — and the three product def…
rubenvdlinde Aug 11, 2026
445776b
fix(e2e): six of decidesk's seven reds — two OpenRegister null-writes…
rubenvdlinde Aug 11, 2026
f0c8c68
fix(listener): the meeting-folder listener has never once run (#471) …
rubenvdlinde Aug 12, 2026
7a55168
feat(decidesk): English vocabulary — fleet words, with column migrati…
rubenvdlinde Aug 12, 2026
3901ad4
test(e2e): four integration surfaces nothing ever opened, and one scr…
rubenvdlinde Aug 12, 2026
05862e9
build(deps): bump the docs npm_and_yarn group with 7 security updates…
dependabot[bot] Aug 12, 2026
9ca6594
chore: adopt Nextcloud's coding standard, .editorconfig and NC 34 (#476)
rubenvdlinde Aug 12, 2026
c765391
fix(ci): test the whole declared Nextcloud range, not only the ceilin…
rubenvdlinde Aug 12, 2026
3f53523
chore: delete the inert .prettierrc (#478)
rubenvdlinde Aug 12, 2026
97f9c63
chore(quality): point PHPMD at the central ruleset (#479)
rubenvdlinde Aug 12, 2026
9f26018
chore(quality): adopt the central PHPStan base config (#480)
rubenvdlinde Aug 12, 2026
ff444fb
chore(deps): pin @conduction/nextcloud-vue to 2.2.0-vue3.16 (#481)
rubenvdlinde Aug 12, 2026
e36dbc4
chore(deps): resolve conduction/hydra-gates v1.7.3 in composer.lock (…
rubenvdlinde Aug 12, 2026
da5960e
docs(controller): declare what applyCorrectionResolution can throw (#…
rubenvdlinde Aug 13, 2026
f6c332e
refactor(decidesk): translate Dutch vocabulary to English, extending …
Aug 13, 2026
265a26b
feat(format): adopt Nextcloud's prettier config, so styles are tabs t…
rubenvdlinde Aug 13, 2026
ad0f000
ci: run `format` (prettier --check) as a Frontend Check leg (#487)
rubenvdlinde Aug 13, 2026
6d9e9e0
fix(decidesk): Newman collections POST renamed properties
Aug 13, 2026
2363aa2
fix(security): rate-limit the remaining public endpoints
rubenvdlinde Aug 14, 2026
39473b3
Merge pull request #488 from ConductionNL/fix/public-endpoint-rate-li…
rubenvdlinde Aug 14, 2026
7d4aee6
Merge pull request #486 from ConductionNL/feat/english-vocabulary-dec…
rubenvdlinde Aug 14, 2026
8d09f5d
build(lint): migrate to eslint 10 + @nextcloud/eslint-config 9
rubenvdlinde Aug 14, 2026
09e1f52
fix(decidesk): finish the translation — 29 names were half English, h…
rubenvdlinde Aug 14, 2026
10da5a5
build(lint): withhold the non-breaking-space autofix too
rubenvdlinde Aug 14, 2026
b7f588a
Merge pull request #490 from ConductionNL/feat/eslint-10
rubenvdlinde Aug 14, 2026
a3e2bc8
fix(security): rate-limit the health endpoints (#492)
rubenvdlinde Aug 14, 2026
df35774
ci: a branch nobody named got no checks at all (#491)
rubenvdlinde Aug 14, 2026
5d20c2e
refactor(deps): inject OpenRegister instead of looking it up (ADR-083)
juanclaude-conduction Aug 14, 2026
1ca1dce
refactor(decidesk): translate the 33 Dutch property names the first p…
rubenvdlinde Aug 14, 2026
46bc39a
refactor(deps): type-hint OpenRegister's published contract (ADR-084)
juanclaude-conduction Aug 15, 2026
f06690e
test: pass the ObjectServiceInterface the constructors now require
juanclaude-conduction Aug 15, 2026
ed8f454
test: remove the container argument ADR-083 deleted from these constr…
juanclaude-conduction Aug 15, 2026
cde415e
fix: the contract lives in Contract\, not Service\
juanclaude-conduction Aug 15, 2026
8dca159
ci: adopt development's Code Quality workflow — the branch had the pr…
juanclaude-conduction Aug 15, 2026
409d1f6
test: inject the SEEDED double, not a fresh empty one
juanclaude-conduction Aug 15, 2026
343ff3d
chore(deps): track @conduction/nextcloud-vue ^2.3.0 (#498)
rubenvdlinde Aug 15, 2026
bddc5ac
test: complete the ADR-083 constructor changes and make the stubs sat…
juanclaude-conduction Aug 15, 2026
5b8c13d
fix(tests): remove constructor arguments that belong to a different c…
juanclaude-conduction Aug 15, 2026
609fe5f
fix: repair references to the local $objectService ADR-083 deleted
juanclaude-conduction Aug 15, 2026
e8fa608
Revert "fix(tests): remove constructor arguments that belong to a dif…
juanclaude-conduction Aug 15, 2026
af7a29c
fix(tests): drop constructor arguments belonging to a same-named class
juanclaude-conduction Aug 15, 2026
26236b2
refactor(decidesk): translate the enum values, keeping the Dutch lega…
rubenvdlinde Aug 15, 2026
eb05e1b
fix: clear the docblocks and dead code ADR-083 left behind
juanclaude-conduction Aug 15, 2026
4276b41
Restore the parameters my dangling-reference pass shadowed
juanclaude-conduction Aug 15, 2026
016ef4d
Drop the stale container argument ADR-083 removed
juanclaude-conduction Aug 15, 2026
c93b68f
Retype the mock properties to the contract they now hold
juanclaude-conduction Aug 15, 2026
5034be1
fix(build): opt-in local-lib, semver-validated, and drop the src over…
rubenvdlinde Aug 16, 2026
ba23c0d
fix(supply-chain): make the npm cooldown actually work (gate-84) (#502)
rubenvdlinde Aug 16, 2026
f7cb78f
chore(security): enable the npm supply-chain cooldown on npm 11 (#501)
rubenvdlinde Aug 16, 2026
6ee79f3
docs(resolver): answer the redundancy question the tripwire raised — …
rubenvdlinde Aug 16, 2026
b05a1fd
fix(lint): clear the last tranche-A suppression — require.context und…
rubenvdlinde Aug 16, 2026
f3a1df8
Merge pull request #495 from ConductionNL/refactor/adr-084-type-hint-…
rubenvdlinde Aug 16, 2026
ac08148
fix(mcp): carry the object service through the whole tool chain
juanclaude-conduction Aug 16, 2026
95c2203
fix(mcp): use the injected service in the scope resolver, and let psa…
juanclaude-conduction Aug 16, 2026
3322226
fix(coverage-guard): scope the ratchet to the files a change touches …
rubenvdlinde Aug 16, 2026
d91aa18
fix(services): finish ADR-084 through the services phpstan and psalm …
juanclaude-conduction Aug 16, 2026
d1957ca
Merge pull request #506 from ConductionNL/fix/mcp-chain-lost-the-obje…
rubenvdlinde Aug 16, 2026
1d66c7c
fix(adr-084): #495 left eleven production call sites building the old…
rubenvdlinde Aug 16, 2026
ef1cb03
fix(tests): import OpenRegister's FileService in the seven tests that…
rubenvdlinde Aug 16, 2026
5d6de54
Merge pull request #510 from ConductionNL/fix/tests-import-openregist…
rubenvdlinde Aug 16, 2026
9168b2b
fix(e2e): de-race 20 test.skip() gates built on the non-waiting isVis…
rubenvdlinde Aug 16, 2026
43ab837
fix(e2e): the three LiveMeeting tests #509 un-skipped now time out — …
rubenvdlinde Aug 16, 2026
d8a2b32
fix(tests): ADR-083/084 moved the constructors and the doubles never …
juanclaude-conduction Aug 16, 2026
e8cf771
Merge pull request #512 from ConductionNL/fix/green-decidesk
rubenvdlinde Aug 16, 2026
44cf362
test(meeting): un-skip 4 MeetingServiceTest tests whose skip reason i…
rubenvdlinde Aug 16, 2026
4873003
fix(live-meeting): stop the recurring-items read evicting the chair's…
rubenvdlinde Aug 16, 2026
23da2bf
fix(gates,e2e): close gate-7's four findings and decidesk's three E2E…
juanclaude-conduction Aug 17, 2026
603e87d
Merge pull request #515 from ConductionNL/fix/green-decidesk-gates-e2e
rubenvdlinde Aug 17, 2026
79489d4
fix(e2e): the 45s raise was right, its stated reason was not (#517)
rubenvdlinde Aug 17, 2026
0fe6169
fix(security): motion history was readable by any authenticated user …
rubenvdlinde Aug 17, 2026
4b4de16
fix(gates): make gate-24 able to run, and it finds an orphan JS leaf …
rubenvdlinde Aug 17, 2026
a9de409
fix(phpcs): clear 63 PHPCS errors (#518)
rubenvdlinde Aug 17, 2026
0ac09a7
feat(adr-066): ship the server-side face of the decidesk-decisions leaf
juanclaude-conduction Aug 17, 2026
b39d4b7
feat(adr-066): declare the leaf's surfaces explicitly on the JS half too
juanclaude-conduction Aug 17, 2026
0387cda
test(adr-066): pin the leaf's server face so it cannot silently disap…
juanclaude-conduction Aug 17, 2026
7e3f229
docs(spec): REQ-DCDH-008 — the decisions leaf is declared on both layers
juanclaude-conduction Aug 17, 2026
83de7c9
fix(security): close the default-open write hole on decidesk's OpenRe…
juanclaude-conduction Aug 17, 2026
a002572
test(security): pin the authorization baseline and both deploy gates
juanclaude-conduction Aug 17, 2026
0864e38
fix(security): keep anonymous READS open — omitting `public` closed t…
juanclaude-conduction Aug 17, 2026
830e3d8
chore(deps): add composer cooldown to dependabot.yml (#522)
rubenvdlinde Aug 17, 2026
a4a6c7b
Merge development into fix/or-authorization-baseline
juanclaude-conduction Aug 17, 2026
b71037f
Merge development into fix/adr-066-decisions-leaf-face
juanclaude-conduction Aug 17, 2026
340ded3
Merge pull request #520 from ConductionNL/fix/adr-066-decisions-leaf-…
rubenvdlinde Aug 17, 2026
01f9f28
Merge pull request #521 from ConductionNL/fix/or-authorization-baseline
rubenvdlinde Aug 17, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
221 changes: 221 additions & 0 deletions .claude/openspec/architecture/adr-001-data-layer.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,221 @@
- ALL domain data → OpenRegister objects. NO custom Entity/Mapper for domain data.
- App config → `IAppConfig`. NOT OpenRegister.
- Cross-entity references: OpenRegister relations (register+schema+objectId). NO foreign keys.
MUST NOT store foreign keys or embed full objects.

### Schema standards

- Schemas: PascalCase, schema.org vocabulary, explicit types + required flags + description field.
- MUST NOT invent custom property names when a schema.org equivalent exists.
- Contact schemas MUST align with vCard properties (fn, email, tel, adr).
- Dutch government fields SHOULD use a mapping layer translating between international standards
and Dutch specs — do not hardcode Dutch field names as primary.
- Schema changes that remove or rename properties are BREAKING. Adding optional properties is non-breaking.

### Register templates

- Location: `lib/Settings/{app}_register.json` (OpenAPI 3.0 + `x-openregister` extensions).
- Three template categories:
- **App configuration** — define data models (schemas/registers/views/mappings).
Mark with `x-openregister.type: "application"`.
- **Mock data** — fictional but realistic seed data for dev/test.
Mark with `x-openregister.type: "mock"`.
- **Government standards** — aligned to Dutch API specs (BAG, BRP, KVK, DSO).
- Import mechanism: `ConfigurationService::importFromApp(appId, data, version, force)` →
`ImportHandler::importFromApp()`. Called from repair step or `SettingsLoadService`.
- Idempotency: re-importing with `force: false` MUST NOT create duplicates. Match by slug
using `ObjectService::searchObjects` with `_rbac: false` and `_multitenancy: false`.
Use `version_compare` for skip logic.

### Seed data

Apps that store data in OpenRegister are empty on first install. An empty app cannot be
meaningfully tested — there are no objects to view, search, filter, or interact with.
This blocks both automated browser testing and manual QA. The Loadable Register Template
pattern (see Register templates above) already supports seed data via `components.objects[]`
with the `@self` envelope.

**Requirements:**

- Every app using OpenRegister MUST include 3-5 realistic objects per schema in
`lib/Settings/{app}_register.json`.
- Use `@self` envelope: `{ "@self": { "register": ..., "schema": ..., "slug": ... }, ...properties }`.
Register/schema MUST match keys; slug is unique human-readable identifier for matching.
- Use general organisation data (municipality, consultancy, travel agency, non-profit) —
NOT context-specific. Varied, realistic field values.
- Mock data quality: real Dutch street names, valid postcodes (`[1-9][0-9]{3}[A-Z]{2}`),
correct municipality/KVK codes, BSNs that pass 11-proef. Fictional but distinguishable from real.
- Cross-register consistency: BRP→BAG, KVK→BAG, DSO→BAG references must be valid.
- Loaded on install alongside schemas via same `importFromApp()` pipeline.
- MUST be idempotent — re-importing skips existing objects matched by slug.

**In OpenSpec artifacts:**

- **In design.md**: MUST include a Seed Data section when change introduces/modifies schemas —
define seed objects per schema with concrete field values and related items (files, notes, tasks, contacts).
- **In tasks.md**: MUST include a seed data generation task when change introduces/modifies schemas.

**Exceptions** (no seed data required):

- **nldesign** — has no OpenRegister schemas.
- **ExApp sidecar wrappers** (openklant, opentalk, openzaak, valtimo, n8n-nextcloud) — proxy
external services and do not use OpenRegister.
- **nextcloud-vue** — shared library, no seed data applicable.
- Changes that only modify frontend components or non-schema backend logic (e.g., settings,
permissions) do not require seed data.

**Limitations:** OpenRegister's `ImportHandler` currently supports only flat seed objects.
Related items (files, notes, tasks, contacts) linked through the relation system are tracked
on the product roadmap. Until then, seed data is limited to object properties defined in schemas.

### Deduplication check

- Before proposing new capability: search `openspec/specs/` and `openregister/lib/Service/` for overlap
with ObjectService, RegisterService, SchemaService, ConfigurationService, and shared Vue components.
- If similar capability exists: MUST reference it and explain why new code is needed rather than extending.
- Proposals duplicating existing functionality without justification MUST be rejected.
- **In design.md**: MUST include a "Reuse Analysis" section listing existing OpenRegister services leveraged.
- **In tasks.md**: MUST include a "Deduplication Check" task verifying no overlap — document findings
even if "no overlap found".

### Schema migrations

- Breaking schema changes → new migration in repair step. NEVER modify existing migrations.

### OpenRegister + @conduction/nextcloud-vue — DO NOT REBUILD

The platform provides 258+ backend methods and 69+ frontend components. Apps ONLY build
custom logic for domain-specific business rules. Everything below is provided for FREE.

**CRUD & Data Management** (use ObjectService + CnIndexPage + CnDetailPage):
- Single & bulk create, read, update, delete — `ObjectService.saveObject()`, `deleteObject()`
- List with pagination, sorting, filtering — `ObjectService.findAll()` + `CnDataTable`
- Schema-driven forms — `CnFormDialog` (auto-generates from schema) or `CnAdvancedFormDialog`
- Detail views — `CnDetailPage` with `CnDetailGrid`, `CnDetailCard` sections
- Record merging/deduplication — `ObjectService.mergeObjects()`
- Object locking — `ObjectService.lockObject()` / `unlockObject()`

**Import & Export** (use ImportService/ExportService + CnMassImportDialog/CnMassExportDialog):
- CSV, Excel, JSON import with intelligent field mapping — `ImportService`
- CSV, Excel, JSON export with column selection — `ExportService`
- Bulk import with validation and progress — `CnMassImportDialog`
- Filtered export with format picker — `CnMassExportDialog`
- NO custom import dialogs, parsers, upload handlers, or export controllers

**Search & Discovery** (use IndexService + CnFilterBar + CnFacetSidebar):
- Full-text search with field weighting — `IndexService`
- Faceted navigation with counts — `FacetBuilder` + `CnFacetSidebar`
- Semantic search with embeddings — `VectorizationService`
- Hybrid search (keyword + semantic) — automatic
- Search analytics — `SearchTrailService` (popular terms, activity)
- NO custom search endpoints, query builders, or search pages

**File Management** (use FileService + CnObjectSidebar):
- Upload (single/multipart), download, share links — `FileService`
- File tagging, public/private toggle — `FileService`
- Bulk download as ZIP — `createObjectFilesZip()`
- Text extraction from PDFs/Office docs — `TextExtractionService`
- File tab in object sidebar — `CnObjectSidebar` → `CnFilesTab`
- NO custom file upload components, file controllers, or download handlers

**Audit & Compliance** (use AuditTrailService + CnObjectSidebar):
- Full change tracking with before/after snapshots — automatic
- Audit trail tab — `CnObjectSidebar` → `CnAuditTrailTab`
- GDPR data subject access requests — `inzageverzoek()`, `verwerkingsregister()`
- Audit export and analytics — `AuditTrailController`
- NO custom audit logging, change tracking, or compliance controllers

**Dashboard & Analytics** (use CnDashboardPage + CnChartWidget + CnStatsBlock):
- Drag-drop widget dashboard — `CnDashboardPage` with GridStack
- KPI cards — `CnKpiGrid`, `CnStatsBlock`, `CnStatsPanel`
- Charts (line/bar/pie/donut) — `CnChartWidget` (ApexCharts)
- Data tables as widgets — `CnTableWidget`
- Editable data grids — `CnObjectDataWidget`
- NO custom dashboard layouts, chart components, or KPI cards

**Forms & Dialogs** (use CnFormDialog + schema-driven generation):
- Auto-generated create/edit forms — `CnFormDialog` reads schema → generates fields
- JSON/metadata editing — `CnAdvancedFormDialog` with Properties/Data/Metadata tabs
- Schema editor — `CnSchemaFormDialog`
- Delete/Copy/Mass operations — `CnDeleteDialog`, `CnCopyDialog`, `CnMassDeleteDialog`
- NO custom form components, validation logic, or dialog wrappers

**Navigation & Pagination** (use CnPagination + CnActionsBar + useListView):
- Pagination control with size selector — `CnPagination`
- Action bar (add, search, toggle views) — `CnActionsBar`
- List state management — `useListView` composable (handles search, filter, sort, page)
- Detail state management — `useDetailView` composable
- NO custom pagination logic, debounced search, or list state management

**Authorization & RBAC** (use AuthorizationService + PropertyRbacHandler):
- Role-based access control — `AuthorizationService`
- Field-level permissions — `PropertyRbacHandler`
- Object-level restrictions — `PermissionHandler`
- Authorization audit — `AuthorizationAuditService`
- NO custom permission checks, role systems, or access control middleware

**Webhooks & Events** (use WebhookService):
- Create, test, retry webhooks — `WebhookService`
- CloudEvents format — automatic
- Event subscriptions — selective per schema/action
- NO custom webhook controllers or event dispatchers

**Notifications & Activity** (use NotificationService + ActivityService):
- Nextcloud notifications — `NotificationService`
- Activity feed — `ActivityService`
- Calendar events — `CalendarEventService`
- Deck/Kanban cards — `DeckCardService`

**Store & State** (use createObjectStore + plugins):
- Object stores — `createObjectStore(name)` generates Pinia CRUD store
- Store plugins: `auditTrails`, `files`, `lifecycle`, `relations`, `search`, `selection`
- Column/field/filter generation from schema — `columnsFromSchema()`, `fieldsFromSchema()`
- NO custom Pinia stores for CRUD, Vuex, or manual API call management

**Chat & AI** (use ChatService):
- Multi-turn conversation — `ChatService`
- RAG-based knowledge retrieval — `ContextRetrievalHandler`
- LLM response generation — `ResponseGenerationHandler`

**Data Retention & Archival** (use ArchivalService):
- Legal hold — `LegalHoldService`
- Destruction schedules — `DestructionService`
- Retention policies — `RetentionService`

**Semantic & Hybrid Search** (use SolrController + SettingsController):
- Semantic search via vector embeddings — `SettingsController.semanticSearch()`
- Hybrid search (keyword + semantic combined) — `SolrController.hybridSearch()`
- Vector embedding generation — `VectorizationService`
- NO custom search algorithms — configure via OpenRegister settings

**GraphQL API** (use GraphQLController):
- Query objects across schemas via GraphQL — `GraphQLController.execute()`
- Alternative to REST for complex cross-entity queries

**Organization / Multi-Tenancy** (use OrganisationController):
- Organization CRUD — `OrganisationController`
- Tenant-scoped data isolation — automatic via `TenantLifecycleService`
- NO custom multi-tenancy logic

**Task & Workflow Management** (use TasksController + WorkflowEngineController):
- Task creation and tracking — `TasksController`
- Workflow orchestration — `WorkflowEngineRegistry`
- Scheduled workflows — `ScheduledWorkflowController`
- NO custom task/workflow systems

**Text Extraction** (use FileTextController):
- Extract text from PDFs and Office docs — `TextExtractionService`
- Entity recognition (PII detection) — `EntityRecognitionHandler`
- Content anonymization — automatic

**Timeline & Stages** (use CnTimelineStages):
- Workflow progression visualization — `CnTimelineStages` component
- Stage tracking with status colors

### What apps SHOULD build (custom business logic only):
- External API integrations (SAP, Peppol, TenderNed, etc.)
- PDF/document generation with business-specific templates
- Workflow triggers and business rules specific to the domain
- Notification dispatch with app-specific event types
- Custom settings pages with app-specific configuration
- Background jobs for domain-specific processing
6 changes: 6 additions & 0 deletions .claude/openspec/architecture/adr-002-api.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
- URL pattern: `/index.php/apps/{app}/api/{resource}` — lowercase plural, hyphens.
- Methods: GET=read, POST=create, PUT=update, DELETE=remove. No custom methods.
- Pagination: support `_page` + `_limit`. Response includes `total`, `page`, `pages`.
- Errors: appropriate HTTP status + `message` field. NO stack traces in responses.
- Auth: Nextcloud built-in only. NO custom login/session/token flows.
- Public endpoints: annotate `#[PublicPage]` + `#[NoCSRFRequired]`. Register CORS OPTIONS route.
14 changes: 14 additions & 0 deletions .claude/openspec/architecture/adr-003-backend.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
- **Controller → Service → Mapper** (strict 3-layer). Controllers NEVER call mappers directly.
- Controllers: thin (<10 lines/method). Routing + validation + response only.
- Services: ALL business logic. Stateless — no instance state between requests.
- Mappers: DB CRUD only. No business logic.
- DI: constructor injection with `private readonly`. NO `\OC::$server` or static locators.
- Entity setters: POSITIONAL args only. `$e->setName('val')` — NEVER `$e->setName(name: 'val')`.
(`__call` passes `['name' => val]` but `setter()` uses `$args[0]`.)
- Routes: `appinfo/routes.php`. Specific routes BEFORE wildcard `{slug}` routes.
- Config: `IAppConfig` with sensitive flag for secrets. NEVER read DB directly.
- Lifecycle: schema init via repair steps (`IRepairStep`), background via job queue, events via dispatcher.
- **Spec traceability**: every class and public method MUST have `@spec` PHPDoc tag(s) linking to
the OpenSpec change that caused it: `@spec openspec/changes/{name}/tasks.md#task-N`.
Multiple `@spec` tags allowed (code touched by multiple changes). File-level `@spec` in header docblock.
This enables: code → docblock → spec traceability alongside code → git blame → commit → issue → spec.
Loading
Loading