Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
800 commits
Select commit Hold shift + click to select a range
8f259bc
fix(spec): repoint broken @spec anchors to canonical specs
rubenvdlinde Jul 16, 2026
e2de51a
docs(openspec): spec-anchor-repair change (proposal/design/tasks/resi…
rubenvdlinde Jul 16, 2026
4a736af
Merge pull request 'softwarecatalog: spec-anchor-repair (apply) — 116…
Jul 16, 2026
a6bcd39
chore(openspec): archive spec-anchor-repair change
rubenvdlinde Jul 16, 2026
11fe62b
Merge pull request 'softwarecatalog: archive the spec-anchor-repair c…
Jul 16, 2026
f785b88
docs(openspec): market-gap wave 2026-07-23 — 7 ff spec changes
rubenvdlinde Jul 23, 2026
5da3814
Merge pull request #376 from ConductionNL/wip/market-gap-specs-2026-0…
rubenvdlinde Jul 23, 2026
bdd2eef
fix(security): close vendor and municipality cross-org read leaks
rubenvdlinde Jul 23, 2026
92d7711
test(security): regression + negative tests for vendor-visibility-rbac
rubenvdlinde Jul 23, 2026
b3954a8
docs(openspec): archive vendor-visibility-rbac + route audit
rubenvdlinde Jul 23, 2026
0b38bb1
Merge pull request #377 from ConductionNL/wip/vendor-visibility-rbac
rubenvdlinde Jul 23, 2026
aa27b9b
feat(organisation-merge): admin merge for gemeentelijke herindeling /…
rubenvdlinde Jul 23, 2026
903b493
feat(organisation-merge): admin merge panel on the organisation detai…
rubenvdlinde Jul 23, 2026
d9aa3bb
docs(organisation-merge): document dry-run, execute, tombstone, and U…
rubenvdlinde Jul 23, 2026
531ab22
chore(openspec): archive organisation-merge — apply spec deltas
rubenvdlinde Jul 23, 2026
45a70b1
Merge pull request #381 from ConductionNL/wip/organisation-merge
rubenvdlinde Jul 23, 2026
324265d
feat(facets): GEMMA-dimension facet aggregation endpoint (gemma-facet…
rubenvdlinde Jul 23, 2026
ffd2810
feat(facets): faceted catalog index pages + facet store/UI (gemma-fac…
rubenvdlinde Jul 23, 2026
a981cc3
i18n(facets): NL+EN translations for GEMMA facet UI strings
rubenvdlinde Jul 23, 2026
15e81ca
docs(facets): document GEMMA faceted search in the features README
rubenvdlinde Jul 23, 2026
64f4c7a
test(facets): Postman collection entries for the facets API
rubenvdlinde Jul 23, 2026
1e16f3e
chore(openspec): archive gemma-faceted-search
rubenvdlinde Jul 23, 2026
7b57988
Merge pull request #382 from ConductionNL/wip/gemma-faceted-search
rubenvdlinde Jul 23, 2026
6a96b04
feat(eol-feed-integration): matcher + sync service + scheduled job
rubenvdlinde Jul 23, 2026
903bcfb
feat(eol-feed-integration): admin settings panel + i18n
rubenvdlinde Jul 23, 2026
2c82c20
docs(eol-feed-integration): document mapping, sync, and degradation
rubenvdlinde Jul 23, 2026
71f076c
chore(openspec): archive eol-feed-integration — apply spec deltas
rubenvdlinde Jul 23, 2026
92bc6b1
Merge pull request #383 from ConductionNL/wip/eol-feed-integration
rubenvdlinde Jul 23, 2026
cf584e0
feat(portfolio-rationalization-time): add TIME classification fields …
rubenvdlinde Jul 23, 2026
9b36692
feat(portfolio-rationalization-time): add PortfolioReportController/S…
rubenvdlinde Jul 23, 2026
1622adc
feat(portfolio-rationalization-time): render enum-on-string schema fi…
rubenvdlinde Jul 23, 2026
f9c95ac
feat(portfolio-rationalization-time): add portfolio rationalization r…
rubenvdlinde Jul 23, 2026
28e050d
i18n(portfolio-rationalization-time): add NL/EN translation strings
rubenvdlinde Jul 23, 2026
afc7a4b
docs(portfolio-rationalization-time): document TIME classification an…
rubenvdlinde Jul 23, 2026
487a5a4
chore(openspec): archive portfolio-rationalization-time
rubenvdlinde Jul 23, 2026
bb3a774
Merge pull request #384 from ConductionNL/wip/portfolio-rationalizati…
rubenvdlinde Jul 23, 2026
ce20efa
feat(sbom-import): register schema — sbomComponent + moduleVersie pro…
rubenvdlinde Jul 23, 2026
5f8e189
feat(sbom-import): backend — pure parser, import service, upload cont…
rubenvdlinde Jul 23, 2026
42402d3
feat(sbom-import): frontend — Components tab, render-time vulnerabili…
rubenvdlinde Jul 23, 2026
2e186ab
feat(sbom-import): i18n — Dutch + English strings
rubenvdlinde Jul 23, 2026
6a0c10e
docs(sbom-import): feature doc + Playwright e2e coverage
rubenvdlinde Jul 23, 2026
db834e4
chore(openspec): archive sbom-import — apply spec deltas
rubenvdlinde Jul 23, 2026
382d4c0
Merge pull request #385 from ConductionNL/wip/sbom-import
rubenvdlinde Jul 23, 2026
5e00580
feat(bio-compliance-assessment): register schema — bioMaatregel catal…
rubenvdlinde Jul 23, 2026
dfe562d
feat(bio-compliance-assessment): frontend — BIO catalog pages, module…
rubenvdlinde Jul 23, 2026
14b1497
test(bio-compliance-assessment): register-shape PHPUnit coverage + BI…
rubenvdlinde Jul 23, 2026
c550d3f
i18n(bio-compliance-assessment): NL + EN + EN_US strings for the BIO …
rubenvdlinde Jul 23, 2026
b64da1f
docs(bio-compliance-assessment): feature doc + organisation-merge fil…
rubenvdlinde Jul 23, 2026
d58f832
chore(openspec): archive bio-compliance-assessment
rubenvdlinde Jul 23, 2026
f1c09e7
fix(bio-compliance-assessment): reconcile catalog filtering onto the …
rubenvdlinde Jul 23, 2026
44a243c
Merge pull request #389 from ConductionNL/wip/bio-compliance-assessment
rubenvdlinde Jul 23, 2026
f5c8b3e
fix(facets): normalize ObjectEntity results in FacetService — endpoin…
rubenvdlinde Jul 24, 2026
8e9bbd4
fix(portfolio-report): register organisatie by schema slug — picker w…
rubenvdlinde Jul 24, 2026
88b81b6
fix(sbom): translate DoesNotExistException to 404 in SbomController
rubenvdlinde Jul 24, 2026
330a821
fix(routes): postfix the SPA catch-all so the app root stops 404ing
rubenvdlinde Jul 24, 2026
3959eb3
Merge pull request #392 from ConductionNL/fix/facet-objectentity-norm…
rubenvdlinde Jul 24, 2026
4b01b7b
fix(security): scope schema RBAC reads for gebruik/koppeling/organisa…
rubenvdlinde Jul 24, 2026
0276e26
test(security): schema-RBAC denial + regression tests for schema-rbac…
rubenvdlinde Jul 24, 2026
051b3f5
docs(openspec): archive schema-rbac-hardening + route audit update
rubenvdlinde Jul 24, 2026
3d2f09c
Merge pull request #395 from ConductionNL/wip/schema-rbac-hardening
rubenvdlinde Jul 24, 2026
fbd389b
fix(settings): fold monolith content into import version + fix broken…
rubenvdlinde Jul 24, 2026
e7ea4e9
docs(settings): document register delivery path + i18n for verificati…
rubenvdlinde Jul 24, 2026
79ea681
docs(openspec): archive register-import-reliability change
rubenvdlinde Jul 24, 2026
bb98e6e
Merge pull request #396 from ConductionNL/wip/register-import-reliabi…
rubenvdlinde Jul 24, 2026
c7e82dc
feat(suite-wizard): frontend — guided suite creation wizard, suite in…
rubenvdlinde Jul 24, 2026
892cddd
test(suite-wizard): pure-logic unit tests for wizard payload/validation
rubenvdlinde Jul 24, 2026
07be013
i18n(suite-wizard): NL + EN + EN_US strings for the suite wizard UI
rubenvdlinde Jul 24, 2026
4efddc3
docs(suite-wizard): feature doc for the suite wizard
rubenvdlinde Jul 24, 2026
8e88d71
chore(openspec): archive suite-wizard
rubenvdlinde Jul 24, 2026
b90cdd4
Merge pull request #398 from ConductionNL/wip/suite-wizard
rubenvdlinde Jul 24, 2026
f4e238d
docs(openspec): catalog-ratings proposal, design, specs — archived
rubenvdlinde Jul 24, 2026
fc2fbd4
fix(security): close beoordeeling authorization hole (softwarecatalog…
rubenvdlinde Jul 24, 2026
017a28f
feat(reviews): authenticated submission, approved-only aggregate, mod…
rubenvdlinde Jul 24, 2026
e1e7632
feat(reviews): ratings & reviews UI — submit flow, aggregate panel, r…
rubenvdlinde Jul 24, 2026
4e80622
i18n(reviews): Dutch + English strings for ratings & reviews (ADR-005)
rubenvdlinde Jul 24, 2026
2832f56
docs(reviews): feature doc for catalog ratings (ADR-010)
rubenvdlinde Jul 24, 2026
4ae39ea
Merge pull request #399 from ConductionNL/wip/catalog-ratings
rubenvdlinde Jul 24, 2026
c9860dd
fix(settings): force importFromApp when computed version differs from…
rubenvdlinde Jul 24, 2026
69c73b6
Merge pull request #400 from ConductionNL/fix/force-import-when-versi…
rubenvdlinde Jul 24, 2026
46f207e
feat(multi-org-membership): beheerder-gated self-service colleague ac…
rubenvdlinde Jul 24, 2026
9aa7c5a
feat(multi-org-membership): organisation switcher + self-service acce…
rubenvdlinde Jul 24, 2026
8fcb51c
i18n(multi-org-membership): NL + EN_US strings for the switcher and a…
rubenvdlinde Jul 24, 2026
f8ab78c
docs(multi-org-membership): feature doc for the organisation switcher…
rubenvdlinde Jul 24, 2026
1f63f26
docs(openspec): archive multi-org-membership
rubenvdlinde Jul 24, 2026
52c5a76
fix(multi-org-membership): correct @spec anchor kebab-casing for apos…
rubenvdlinde Jul 24, 2026
51266a6
docs(multi-org-membership): reason-bearing @e2e exclude — no live dep…
rubenvdlinde Jul 24, 2026
73ae1f0
Merge pull request #401 from ConductionNL/wip/multi-org-membership
rubenvdlinde Jul 24, 2026
414469b
fix(suite-wizard): read the collection envelope, not a bare array
rubenvdlinde Jul 24, 2026
a8eb288
Merge pull request #405 from ConductionNL/fix/suite-wizard-collection…
rubenvdlinde Jul 24, 2026
d492f43
i18n(schema): author softwarecatalog property titles in English + NL …
rubenvdlinde Jul 25, 2026
d2da799
Merge pull request #406 from ConductionNL/wip/schema-titles-en
rubenvdlinde Jul 25, 2026
4f890f7
fix(ratings): resolve beoordeeling register+schema so reviews work (#…
rubenvdlinde Jul 25, 2026
e8f51dc
test(ratings): regression cover for catalog-type register/schema reso…
rubenvdlinde Jul 25, 2026
8b22ffe
Merge pull request #407 from ConductionNL/fix/review-register-resolution
rubenvdlinde Jul 25, 2026
f6bca7b
fix(sbom): move SBOM provenance props to moduleVersie schema (#385)
rubenvdlinde Jul 25, 2026
8add861
test(e2e): make nav-drill helper survive collapsed submenus and the o…
rubenvdlinde Jul 25, 2026
12f0128
test(sbom): make the sbom-import e2e executable + add register-shape …
rubenvdlinde Jul 25, 2026
3f8cd1d
chore(deps): @conduction/nextcloud-vue ^1.0.0-beta.221 — activate sch…
rubenvdlinde Jul 26, 2026
c4c0b9c
Merge pull request #408 from ConductionNL/wip/ncvue-beta221
rubenvdlinde Jul 26, 2026
13215dd
i18n(schema): author softwarecatalog schema-level titles in English +…
rubenvdlinde Jul 26, 2026
1082c77
Merge pull request #409 from ConductionNL/wip/schema-level-titles
rubenvdlinde Jul 26, 2026
47a2872
i18n(l10n): complete en/nl runtime translation coverage
rubenvdlinde Jul 26, 2026
a1d6e95
Merge pull request #410 from ConductionNL/wip/l10n-coverage
rubenvdlinde Jul 26, 2026
85b4e42
test(l10n): parity opt-in + add l10n coverage CI gate
rubenvdlinde Jul 30, 2026
4af52fc
Merge pull request #411 from ConductionNL/wip/l10n-parity-optin
rubenvdlinde Jul 30, 2026
0ce32eb
feat(icons): adopt the ADR-077 semantic icon vocabulary (#412)
rubenvdlinde Jul 30, 2026
a76cedb
feat(icons): extend ADR-077 to page, widget and action icons (#413)
rubenvdlinde Jul 30, 2026
319b47e
ci: point the reusable workflows at the org and branch that exist (#414)
rubenvdlinde Aug 2, 2026
e2d2b48
feat(vue3): migrate softwarecatalog to Vue 3 + @nextcloud/vue v9 (#416)
rubenvdlinde Aug 2, 2026
c864469
build: make composer check:strict able to fail (#415)
rubenvdlinde Aug 2, 2026
4d16cdb
fix(ci): make composer check:strict able to fail on tests (#417)
rubenvdlinde Aug 2, 2026
3a9defb
ci: enable the shared E2E Tests (Playwright) job
Aug 3, 2026
d2819f7
fix(deps): bump guzzlehttp/{guzzle,psr7,promises} to clear composer a…
Aug 3, 2026
8e6730e
fix(e2e): CI playwright config died on a glob inside its own block co…
Aug 3, 2026
00882fd
fix(security): bump guzzlehttp/guzzle 7.10.0 -> 7.15.2 and psr7 2.11.…
rubenvdlinde Aug 3, 2026
74bbdd0
Merge pull request #420 from ConductionNL/fix/composer-security-advis…
rubenvdlinde Aug 3, 2026
8d905c9
fix(quality): phpmd DevelopmentCodeFragment could never fire on names…
rubenvdlinde Aug 3, 2026
d3dd7ce
chore(security): refresh roave/security-advisories guard (2026-03-03 …
rubenvdlinde Aug 3, 2026
43e5427
fix(e2e): the suite addressed the app by a path that only exists behi…
Aug 3, 2026
a48654e
fix(e2e): bring the suite up to date with the schema/manifest it tests
Aug 3, 2026
c91dcfd
TEMPORARY: truncate the webpack bundle to prove the e2e specs exercis…
Aug 3, 2026
a43b4f0
Revert "TEMPORARY: truncate the webpack bundle to prove the e2e specs…
Aug 3, 2026
53d27b0
docs(e2e): the moduleVersie create 'bug' was a stale dev instance, no…
Aug 3, 2026
77d7e01
Merge pull request #418 from ConductionNL/ci/e2e-enable
rubenvdlinde Aug 3, 2026
8bcc138
ci: bound the l10n coverage job runtime (#422)
rubenvdlinde Aug 3, 2026
ba50b08
fix(quality): clear the psalm/phpstan quality backlog and 54 phpmd fi…
rubenvdlinde Aug 3, 2026
2696ce0
chore(quality): make composer check:strict green by suppressing phpmd…
rubenvdlinde Aug 3, 2026
6cdae8e
chore(deps): upgrade @conduction/nextcloud-vue to 3.0.0-vue3.4 (#426)
rubenvdlinde Aug 4, 2026
09f9b5c
feat(schema): mark the GEMMA AMEF Element reference component shareab…
rubenvdlinde Aug 4, 2026
68df2ce
fix(events): stop broadcasting object lifecycle to the disabled SWC l…
rubenvdlinde Aug 4, 2026
1190403
chore(deps): @conduction/nextcloud-vue 3.0.0-vue3.6
Aug 4, 2026
f51fd61
Merge pull request #429 from ConductionNL/chore/ncvue-vue3.6
rubenvdlinde Aug 4, 2026
568bbec
ci(quality): enable the Code Quality gates this repo was silently ski…
rubenvdlinde Aug 4, 2026
c984e19
ci(quality): restore the missing push trigger (#432)
rubenvdlinde Aug 4, 2026
cd5259a
chore(deps): repin @conduction/nextcloud-vue to 2.2.0-vue3.3 (3.0.0-v…
rubenvdlinde Aug 5, 2026
5657c3c
ci(quality): move hydra-gates-ref v1.0.1 -> v1.3.0, which is what is …
rubenvdlinde Aug 5, 2026
a9a4c49
chore: normalise all licence declarations to EUPL-1.2 (#437)
rubenvdlinde Aug 5, 2026
473623a
fix(phpmd): scope the lib/Migration UnusedFormalParameter exclusion t…
rubenvdlinde Aug 5, 2026
a09ff02
chore(ci): move hydra-gates-ref v1.3.0 -> v1.4.0 (#438)
rubenvdlinde Aug 6, 2026
84bd566
ci(quality): move hydra-gates-ref to v1.5.0, the pin the floating wor…
rubenvdlinde Aug 6, 2026
ed6db8c
chore(ci): stop pinning hydra-gates — track the package at @main (#439)
rubenvdlinde Aug 6, 2026
db27a7c
fix(ci): compare the coverage ratchet against the measured merge base…
rubenvdlinde Aug 6, 2026
9c217ab
ci: publish an installable build of development (#441)
rubenvdlinde Aug 6, 2026
c8efc67
fix(gate-57): delete the dead user-provisioning stub that only logged
rubenvdlinde Aug 6, 2026
0d2d60f
Merge pull request #442 from ConductionNL/fix/gate-57-dead-user-provi…
rubenvdlinde Aug 6, 2026
98a4612
chore(deps): clear all critical + high npm advisories on development …
rubenvdlinde Aug 6, 2026
59fbd11
fix(security): PHP_CodeSniffer 3.13.5 -> 3.13.6 (CVE-2026-67434, OS c…
rubenvdlinde Aug 6, 2026
8f14a11
chore(ci): point Dependabot at development, where the gates actually …
rubenvdlinde Aug 6, 2026
0d9eb65
chore(deps): remove 4 dead remark packages — nothing invokes them (#448)
rubenvdlinde Aug 7, 2026
a7d2490
fix(federation): delete the orphaned publish wrapper and test the sea…
rubenvdlinde Aug 7, 2026
47c00ba
chore(deps): remove dead runtime deps — bare axios, @fortawesome, @vu…
rubenvdlinde Aug 7, 2026
d777e52
fix(mail): install the 4 mailer bridges the code already builds DSNs …
rubenvdlinde Aug 7, 2026
0bb4d3d
fix: declare NC 32 as the floor — openregister cannot install below i…
rubenvdlinde Aug 7, 2026
8bf2436
fix: restore the 16 branch bodies commit 651a055f deleted (#455)
rubenvdlinde Aug 8, 2026
9566d08
fix(auth): guard the aggregate user-groups route and align 10 auth an…
rubenvdlinde Aug 8, 2026
dea9b54
fix(phpcs): stop the SpecTagSniff instructing the pattern gate-46 rej…
rubenvdlinde Aug 8, 2026
d826781
fix(e2e): retain-on-failure traces + a globalTimeout under the 45m CI…
rubenvdlinde Aug 8, 2026
99264e3
Merge pull request #462 from ConductionNL/fix/spec-tag-sniff-canonica…
rubenvdlinde Aug 8, 2026
b3838c6
feat(settings): add canonical PUT /api/settings (settings#update) (#464)
rubenvdlinde Aug 8, 2026
3a542f2
fix(a11y): four widget icons rendered the wrong glyph, three controls…
rubenvdlinde Aug 9, 2026
eff9e05
fix(auth): scope the contact-person read-outs to the caller's organis…
rubenvdlinde Aug 9, 2026
df0a21f
refactor(archimate): delete the unreachable private getVoorzieningenC…
rubenvdlinde Aug 9, 2026
f5538e7
fix(a11y): label 19 form fields, scope 19 tables, honour reduced moti…
rubenvdlinde Aug 9, 2026
b2c070a
fix(gates): one settings home, four dangling $refs, two mistyped spec…
rubenvdlinde Aug 9, 2026
f0bea90
test: pin the public review-aggregate wire contract and prove five pa…
rubenvdlinde Aug 9, 2026
f8c32f7
fix(archimate): unset AMEF ids were handed on as empty strings past a…
rubenvdlinde Aug 9, 2026
0020132
docs(spec): trace 64 frontend methods to their spec, and sync the spe…
rubenvdlinde Aug 9, 2026
0586437
fix(register): drop the unresolvable $ref on the cross-app decisions …
rubenvdlinde Aug 9, 2026
5b4fe42
chore(deps): pin @conduction/nextcloud-vue to 2.2.0-vue3.7
rubenvdlinde Aug 10, 2026
d2616b8
Merge pull request #474 from ConductionNL/chore/pin-ncvue-2.2.0-vue3.7
rubenvdlinde Aug 10, 2026
39a3333
chore(deps): pin @conduction/nextcloud-vue to 2.2.0-vue3.9
rubenvdlinde Aug 10, 2026
4fbb85b
Merge pull request #475 from ConductionNL/chore/pin-ncvue-2.2.0-vue3.9
rubenvdlinde Aug 10, 2026
72f92f4
ci: this workflow could not be run on purpose (#476)
rubenvdlinde Aug 10, 2026
274790f
fix(spec): four @spec tags named a Scenario as if it were a Requireme…
rubenvdlinde Aug 10, 2026
f699b5a
fix(fe): gate-13 — extract four inline modals, and fix the slot typo …
rubenvdlinde Aug 10, 2026
126eda6
test(gates): real contract tests close gate-25 (41 -> 0); gate-26 3 -…
rubenvdlinde Aug 11, 2026
ebc93ff
test(e2e): 18 real Playwright tests close gate-19 137 -> 112 (#486)
rubenvdlinde Aug 11, 2026
ea4dc7e
fix(security): bump phpcsstandards/phpcsutils to 1.2.3 for CVE-2026-6…
rubenvdlinde Aug 11, 2026
d401ab7
fix(merge): organisation merge re-points nothing — probe a magic acce…
rubenvdlinde Aug 12, 2026
f2dcacc
chore(softwarecatalog): remove two committed debug scripts (#487)
rubenvdlinde Aug 12, 2026
088e14c
feat(repair): migrate softwarecatalog's Dutch columns to English (#488)
rubenvdlinde Aug 12, 2026
514d9c0
chore: adopt Nextcloud's coding standard, .editorconfig and NC 34 (#493)
rubenvdlinde Aug 12, 2026
5546f7d
fix(ci): test the whole declared Nextcloud range, not only the ceilin…
rubenvdlinde Aug 12, 2026
bbe8883
chore: delete the inert .prettierrc (#495)
rubenvdlinde Aug 12, 2026
d788cd5
fix(install): seed on a FRESH install, not only on upgrade (#496)
rubenvdlinde Aug 12, 2026
11c54b6
chore(quality): point PHPMD at the central ruleset (#498)
rubenvdlinde Aug 12, 2026
4ef32fe
chore(quality): adopt the central PHPStan base config (#497)
rubenvdlinde Aug 12, 2026
021fc72
chore(deps): pin @conduction/nextcloud-vue to 2.2.0-vue3.16 (#499)
rubenvdlinde Aug 12, 2026
051aa85
chore(deps): resolve conduction/hydra-gates v1.7.3 in composer.lock (…
rubenvdlinde Aug 12, 2026
ee2152d
fix(repair): guard the Dutch column rename on what the schema declare…
rubenvdlinde Aug 13, 2026
bd9751a
fix(auth): four admin actions were reachable by any authenticated use…
rubenvdlinde Aug 13, 2026
cd27979
feat(format): adopt Nextcloud's prettier config, so styles are tabs t…
rubenvdlinde Aug 13, 2026
34d8318
ci: run `format` (prettier --check) as a Frontend Check leg (#507)
rubenvdlinde Aug 13, 2026
c8e82f4
ci(stylelint): cover css/ as well as src/, and fix what it found (#508)
rubenvdlinde Aug 14, 2026
c016ae8
fix(security): rate-limit the public review aggregate endpoint
rubenvdlinde Aug 14, 2026
702f24a
Merge pull request #510 from ConductionNL/fix/public-endpoint-rate-li…
rubenvdlinde Aug 14, 2026
bc57048
build(lint): migrate to eslint 10 + @nextcloud/eslint-config 9
rubenvdlinde Aug 14, 2026
aab66d5
refactor(softwarecatalog): translate Dutch vocabulary to English (#506)
rubenvdlinde Aug 14, 2026
6aceb6e
Merge remote-tracking branch 'origin/development' into feat/eslint-10
rubenvdlinde Aug 14, 2026
b7916e9
Merge pull request #511 from ConductionNL/feat/eslint-10
rubenvdlinde Aug 14, 2026
8c6798b
ci: a branch nobody named got no checks at all (#512)
rubenvdlinde Aug 14, 2026
f4e57eb
fix(security): give every public endpoint a volume ceiling (ADR-082) …
rubenvdlinde Aug 14, 2026
517f650
refactor(deps): inject OpenRegister instead of looking it up (ADR-083)
rubenvdlinde Aug 14, 2026
386771d
refactor(softwarecatalog): translate 12 pre-existing Dutch property n…
rubenvdlinde Aug 14, 2026
d3fa65a
refactor(softwarecatalog): one Dutch name, two English targets — let …
rubenvdlinde Aug 15, 2026
58c3c30
refactor(deps): type-hint OpenRegister's published contract (ADR-084)
rubenvdlinde Aug 15, 2026
826bf1b
fix(adr-084): complete the conversion the first transformer under-did
rubenvdlinde Aug 15, 2026
c15e6fd
refactor(softwarecatalog): translate eight schema slugs, and migrate …
rubenvdlinde Aug 15, 2026
153a7e5
refactor(softwarecatalog): translate the stored enum values, and migr…
rubenvdlinde Aug 15, 2026
2020f87
test: pass the ObjectServiceInterface the constructors now require
rubenvdlinde Aug 15, 2026
153e850
fix: the contract lives in Contract\, not Service\
rubenvdlinde Aug 15, 2026
5e7ae8d
ci: adopt development's Code Quality workflow — the branch had the pr…
rubenvdlinde Aug 15, 2026
26fae3e
chore(deps): track @conduction/nextcloud-vue ^2.3.0 (#521)
rubenvdlinde Aug 15, 2026
3e16612
test: complete the ADR-083 constructor changes and make the stubs sat…
rubenvdlinde Aug 15, 2026
4619549
refactor: persist through the published contract, not OpenRegister's …
rubenvdlinde Aug 15, 2026
701ad8b
refactor: convert the last two MagicMapper lookups on their own terms
rubenvdlinde Aug 15, 2026
684384e
fix: finish the MagicMapper removal and wire the composition root
rubenvdlinde Aug 15, 2026
cee771e
fix: repair references to the local $objectService ADR-083 deleted
rubenvdlinde Aug 15, 2026
4f6da66
fix(tests): drop constructor arguments belonging to a same-named class
rubenvdlinde Aug 15, 2026
bc36d9c
fix: clear the docblocks and dead code ADR-083 left behind
rubenvdlinde Aug 15, 2026
67e7eff
Merge development, and restore two parameters my dangling-reference p…
rubenvdlinde Aug 15, 2026
d5f5e69
chore(deps): move @conduction/nextcloud-vue to ^2.3.0 (#522)
rubenvdlinde Aug 15, 2026
785b9f2
fix(build): make local-lib opt-in and test the -vue3 marker, not the …
rubenvdlinde Aug 15, 2026
0856704
refactor(facets): translate the four facet dimensions as one set (#524)
rubenvdlinde Aug 15, 2026
34bdf86
chore(security): enable the npm supply-chain cooldown on npm 11 (#523)
rubenvdlinde Aug 16, 2026
9ecc2fa
Put register and schema back inside findAll()'s config (2 sites)
rubenvdlinde Aug 16, 2026
d639397
fix(lint): clear 3 of 4 tranche-A suppressions (#525)
rubenvdlinde Aug 16, 2026
0335cb2
Merge pull request #519 from ConductionNL/refactor/adr-084-type-hint-…
rubenvdlinde Aug 16, 2026
103a102
fix(tests): the ObjectEntity stub declared return types wider than th…
rubenvdlinde Aug 16, 2026
6d19682
fix(register): point three x-relation-filter tokens at the renamed pr…
rubenvdlinde Aug 16, 2026
01cc731
fix: the errors the class-load fatal was hiding
rubenvdlinde Aug 16, 2026
7cf3afa
fix(coverage-guard): scope the ratchet to the files a change touches …
rubenvdlinde Aug 16, 2026
89a7ea1
Merge pull request #528 from ConductionNL/fix/stub-return-types-match…
rubenvdlinde Aug 16, 2026
57f6c7a
fix(me): pass the two ADR-084 arguments the /me factory stopped suppl…
rubenvdlinde Aug 16, 2026
ece273a
fix(register): two dangling objectDescriptionField values detached th…
rubenvdlinde Aug 16, 2026
1a1632a
fix(gate-57): delete six orphaned write capabilities (#530)
rubenvdlinde Aug 16, 2026
2466541
fix(phpcs): clear all 19 errors — phpcs exits 0
rubenvdlinde Aug 16, 2026
5380993
Merge pull request #534 from ConductionNL/fix/phpcs-docblocks
rubenvdlinde Aug 16, 2026
e58efc9
fix: close the ADR-084 contract drift behind 19 PHPUnit failures and …
rubenvdlinde Aug 16, 2026
8fd9130
Merge pull request #535 from ConductionNL/fix/green-softwarecatalog
rubenvdlinde Aug 16, 2026
583f538
fix: close the last three Hydra Gates and the five E2E failures
rubenvdlinde Aug 16, 2026
a539753
test: cover getOrganisationMapper(), which the coverage ratchet caugh…
rubenvdlinde Aug 16, 2026
24c2fa1
fix(e2e): the Organisations index filtered on values #520 deleted, an…
rubenvdlinde Aug 16, 2026
95aabce
Merge origin/development — resolve #536 for the union, keeping the fi…
rubenvdlinde Aug 16, 2026
68202d5
Merge pull request #537 from ConductionNL/fix/green-softwarecatalog-2
rubenvdlinde Aug 17, 2026
edd4320
fix(manifest): the Standards pages read `element` from a register tha…
rubenvdlinde Aug 17, 2026
ee6b389
test(e2e): seed the AMEF register and assert the Standards page LISTS…
rubenvdlinde Aug 17, 2026
bac20b4
test(unit): pin manifest register sentinels to a register that attach…
rubenvdlinde Aug 17, 2026
6d91a5b
Merge pull request #540 from ConductionNL/fix/swc-standards-register
rubenvdlinde Aug 17, 2026
d1aff37
chore(deps): correct composer cooldown — default-days 1 to 2, add con…
rubenvdlinde Aug 17, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
223 changes: 223 additions & 0 deletions .claude/openspec/architecture/adr-001-data-layer.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,223 @@
- ALL domain data → OpenRegister objects. NO custom Entity/Mapper for domain data.
- App config → `IAppConfig`. NOT OpenRegister.
- Cross-entity references: OpenRegister relations (register+schema+objectId). NO foreign keys.
MUST NOT store foreign keys or embed full objects.

### Schema standards

- Schemas: PascalCase, schema.org vocabulary, explicit types + required flags + description field.
- MUST NOT invent custom property names when a schema.org equivalent exists.
- Contact schemas MUST align with vCard properties (fn, email, tel, adr).
- Dutch government fields SHOULD use a mapping layer translating between international standards
and Dutch specs — do not hardcode Dutch field names as primary.
- Schema changes that remove or rename properties are BREAKING. Adding optional properties is non-breaking.

### Register templates

- Location: `lib/Settings/{app}_register.json` (OpenAPI 3.0 + `x-openregister` extensions).
- Three template categories:
- **App configuration** — define data models (schemas/registers/views/mappings).
Mark with `x-openregister.type: "application"`.
- **Mock data** — fictional but realistic seed data for dev/test.
Mark with `x-openregister.type: "mock"`.
- **Government standards** — aligned to Dutch API specs (BAG, BRP, KVK, DSO).
- Import mechanism: `ConfigurationService::importFromApp(appId, data, version, force)` →
`ImportHandler::importFromApp()`. Called from repair step or `SettingsLoadService`.
- Idempotency: re-importing with `force: false` MUST NOT create duplicates. Match by slug
using `ObjectService::searchObjects` with `_rbac: false` and `_multitenancy: false`.
Use `version_compare` for skip logic.

### Seed data

Apps that store data in OpenRegister are empty on first install. An empty app cannot be
meaningfully tested — there are no objects to view, search, filter, or interact with.
This blocks both automated browser testing and manual QA. The Loadable Register Template
pattern (see Register templates above) already supports seed data via `components.objects[]`
with the `@self` envelope.

**Requirements:**

- Every app using OpenRegister MUST include 3-5 realistic objects per schema in
`lib/Settings/{app}_register.json`.
- Use `@self` envelope: `{ "@self": { "register": ..., "schema": ..., "slug": ... }, ...properties }`.
Register/schema MUST match keys; slug is unique human-readable identifier for matching.
- Use general organisation data (municipality, consultancy, travel agency, non-profit) —
NOT context-specific. Varied, realistic field values.
- Mock data quality: real Dutch street names, valid postcodes (`[1-9][0-9]{3}[A-Z]{2}`),
correct municipality/KVK codes, BSNs that pass 11-proef. Fictional but distinguishable from real.
- Cross-register consistency: BRP→BAG, KVK→BAG, DSO→BAG references must be valid.
- Loaded on install alongside schemas via same `importFromApp()` pipeline.
- MUST be idempotent — re-importing skips existing objects matched by slug.

**In OpenSpec artifacts:**

- **In design.md**: MUST include a Seed Data section when change introduces/modifies schemas —
define seed objects per schema with concrete field values and related items (files, notes, tasks, contacts).
- **In tasks.md**: MUST include a seed data generation task when change introduces/modifies schemas.

**Exceptions** (no seed data required):

- **nldesign** — has no OpenRegister schemas.
- **ExApp sidecar wrappers** (openklant, opentalk, openzaak, valtimo, n8n-nextcloud) — proxy
external services and do not use OpenRegister.
- **nextcloud-vue** — shared library, no seed data applicable.
- Changes that only modify frontend components or non-schema backend logic (e.g., settings,
permissions) do not require seed data.

**Limitations:** OpenRegister's `ImportHandler` currently supports only flat seed objects.
Related items (files, notes, tasks, contacts) linked through the relation system are tracked
in OpenRegister's pending `seed-related-items` openspec change (see
`openregister/openspec/changes/seed-related-items/`). Until that lands, seed data is limited
to object properties defined in schemas.

### Deduplication check

- Before proposing new capability: search `openspec/specs/` and `openregister/lib/Service/` for overlap
with ObjectService, RegisterService, SchemaService, ConfigurationService, and shared Vue components.
- If similar capability exists: MUST reference it and explain why new code is needed rather than extending.
- Proposals duplicating existing functionality without justification MUST be rejected.
- **In design.md**: MUST include a "Reuse Analysis" section listing existing OpenRegister services leveraged.
- **In tasks.md**: MUST include a "Deduplication Check" task verifying no overlap — document findings
even if "no overlap found".

### Schema migrations

- Breaking schema changes → new migration in repair step. NEVER modify existing migrations.

### OpenRegister + @conduction/nextcloud-vue — DO NOT REBUILD

The platform provides 258+ backend methods and 69+ frontend components. Apps ONLY build
custom logic for domain-specific business rules. Everything below is provided for FREE.

**CRUD & Data Management** (use ObjectService + CnIndexPage + CnDetailPage):
- Single & bulk create, read, update, delete — `ObjectService.saveObject()`, `deleteObject()`
- List with pagination, sorting, filtering — `ObjectService.findAll()` + `CnDataTable`
- Schema-driven forms — `CnFormDialog` (auto-generates from schema) or `CnAdvancedFormDialog`
- Detail views — `CnDetailPage` with `CnDetailGrid`, `CnDetailCard` sections
- Record merging/deduplication — `ObjectService.mergeObjects()`
- Object locking — `ObjectService.lockObject()` / `unlockObject()`

**Import & Export** (use ImportService/ExportService + CnMassImportDialog/CnMassExportDialog):
- CSV, Excel, JSON import with intelligent field mapping — `ImportService`
- CSV, Excel, JSON export with column selection — `ExportService`
- Bulk import with validation and progress — `CnMassImportDialog`
- Filtered export with format picker — `CnMassExportDialog`
- NO custom import dialogs, parsers, upload handlers, or export controllers

**Search & Discovery** (use IndexService + CnFilterBar + CnFacetSidebar):
- Full-text search with field weighting — `IndexService`
- Faceted navigation with counts — `FacetBuilder` + `CnFacetSidebar`
- Semantic search with embeddings — `VectorizationService`
- Hybrid search (keyword + semantic) — automatic
- Search analytics — `SearchTrailService` (popular terms, activity)
- NO custom search endpoints, query builders, or search pages

**File Management** (use FileService + CnObjectSidebar):
- Upload (single/multipart), download, share links — `FileService`
- File tagging, public/private toggle — `FileService`
- Bulk download as ZIP — `createObjectFilesZip()`
- Text extraction from PDFs/Office docs — `TextExtractionService`
- File tab in object sidebar — `CnObjectSidebar` → `CnFilesTab`
- NO custom file upload components, file controllers, or download handlers

**Audit & Compliance** (use AuditTrailService + CnObjectSidebar):
- Full change tracking with before/after snapshots — automatic
- Audit trail tab — `CnObjectSidebar` → `CnAuditTrailTab`
- GDPR data subject access requests — `inzageverzoek()`, `verwerkingsregister()`
- Audit export and analytics — `AuditTrailController`
- NO custom audit logging, change tracking, or compliance controllers

**Dashboard & Analytics** (use CnDashboardPage + CnChartWidget + CnStatsBlock):
- Drag-drop widget dashboard — `CnDashboardPage` with GridStack
- KPI cards — `CnKpiGrid`, `CnStatsBlock`, `CnStatsPanel`
- Charts (line/bar/pie/donut) — `CnChartWidget` (ApexCharts)
- Data tables as widgets — `CnTableWidget`
- Editable data grids — `CnObjectDataWidget`
- NO custom dashboard layouts, chart components, or KPI cards

**Forms & Dialogs** (use CnFormDialog + schema-driven generation):
- Auto-generated create/edit forms — `CnFormDialog` reads schema → generates fields
- JSON/metadata editing — `CnAdvancedFormDialog` with Properties/Data/Metadata tabs
- Schema editor — `CnSchemaFormDialog`
- Delete/Copy/Mass operations — `CnDeleteDialog`, `CnCopyDialog`, `CnMassDeleteDialog`
- NO custom form components, validation logic, or dialog wrappers

**Navigation & Pagination** (use CnPagination + CnActionsBar + useListView):
- Pagination control with size selector — `CnPagination`
- Action bar (add, search, toggle views) — `CnActionsBar`
- List state management — `useListView` composable (handles search, filter, sort, page)
- Detail state management — `useDetailView` composable
- NO custom pagination logic, debounced search, or list state management

**Authorization & RBAC** (use AuthorizationService + PropertyRbacHandler):
- Role-based access control — `AuthorizationService`
- Field-level permissions — `PropertyRbacHandler`
- Object-level restrictions — `PermissionHandler`
- Authorization audit — `AuthorizationAuditService`
- NO custom permission checks, role systems, or access control middleware

**Webhooks & Events** (use WebhookService):
- Create, test, retry webhooks — `WebhookService`
- CloudEvents format — automatic
- Event subscriptions — selective per schema/action
- NO custom webhook controllers or event dispatchers

**Notifications & Activity** (use NotificationService + ActivityService):
- Nextcloud notifications — `NotificationService`
- Activity feed — `ActivityService`
- Calendar events — `CalendarEventService`
- Deck/Kanban cards — `DeckCardService`

**Store & State** (use createObjectStore + plugins):
- Object stores — `createObjectStore(name)` generates Pinia CRUD store
- Store plugins: `auditTrails`, `files`, `lifecycle`, `relations`, `search`, `selection`
- Column/field/filter generation from schema — `columnsFromSchema()`, `fieldsFromSchema()`
- NO custom Pinia stores for CRUD, Vuex, or manual API call management

**Chat & AI** (use ChatService):
- Multi-turn conversation — `ChatService`
- RAG-based knowledge retrieval — `ContextRetrievalHandler`
- LLM response generation — `ResponseGenerationHandler`

**Data Retention & Archival** (use ArchivalService):
- Legal hold — `LegalHoldService`
- Destruction schedules — `DestructionService`
- Retention policies — `RetentionService`

**Semantic & Hybrid Search** (use SolrController + SettingsController):
- Semantic search via vector embeddings — `SettingsController.semanticSearch()`
- Hybrid search (keyword + semantic combined) — `SolrController.hybridSearch()`
- Vector embedding generation — `VectorizationService`
- NO custom search algorithms — configure via OpenRegister settings

**GraphQL API** (use GraphQLController):
- Query objects across schemas via GraphQL — `GraphQLController.execute()`
- Alternative to REST for complex cross-entity queries

**Organization / Multi-Tenancy** (use OrganisationController):
- Organization CRUD — `OrganisationController`
- Tenant-scoped data isolation — automatic via `TenantLifecycleService`
- NO custom multi-tenancy logic

**Task & Workflow Management** (use TasksController + WorkflowEngineController):
- Task creation and tracking — `TasksController`
- Workflow orchestration — `WorkflowEngineRegistry`
- Scheduled workflows — `ScheduledWorkflowController`
- NO custom task/workflow systems

**Text Extraction** (use FileTextController):
- Extract text from PDFs and Office docs — `TextExtractionService`
- Entity recognition (PII detection) — `EntityRecognitionHandler`
- Content anonymization — automatic

**Timeline & Stages** (use CnTimelineStages):
- Workflow progression visualization — `CnTimelineStages` component
- Stage tracking with status colors

### What apps SHOULD build (custom business logic only):
- External API integrations (SAP, Peppol, TenderNed, etc.)
- PDF/document generation with business-specific templates
- Workflow triggers and business rules specific to the domain
- Notification dispatch with app-specific event types
- Custom settings pages with app-specific configuration
- Background jobs for domain-specific processing
6 changes: 6 additions & 0 deletions .claude/openspec/architecture/adr-002-api.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
- URL pattern: `/index.php/apps/{app}/api/{resource}` — lowercase plural, hyphens.
- Methods: GET=read, POST=create, PUT=update, DELETE=remove. No custom methods.
- Pagination: support `_page` + `_limit`. Response includes `total`, `page`, `pages`.
- Errors: appropriate HTTP status + `message` field. NO stack traces in responses.
- Auth: Nextcloud built-in only. NO custom login/session/token flows.
- Public endpoints: annotate `#[PublicPage]` + `#[NoCSRFRequired]`. Register CORS OPTIONS route.
14 changes: 14 additions & 0 deletions .claude/openspec/architecture/adr-003-backend.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
- **Controller → Service → Mapper** (strict 3-layer). Controllers NEVER call mappers directly.
- Controllers: thin (<10 lines/method). Routing + validation + response only.
- Services: ALL business logic. Stateless — no instance state between requests.
- Mappers: DB CRUD only. No business logic.
- DI: constructor injection with `private readonly`. NO `\OC::$server` or static locators.
- Entity setters: POSITIONAL args only. `$e->setName('val')` — NEVER `$e->setName(name: 'val')`.
(`__call` passes `['name' => val]` but `setter()` uses `$args[0]`.)
- Routes: `appinfo/routes.php`. Specific routes BEFORE wildcard `{slug}` routes.
- Config: `IAppConfig` with sensitive flag for secrets. NEVER read DB directly.
- Lifecycle: schema init via repair steps (`IRepairStep`), background via job queue, events via dispatcher.
- **Spec traceability**: every class and public method MUST have `@spec` PHPDoc tag(s) linking to
the OpenSpec change that caused it: `@spec openspec/changes/{name}/tasks.md#task-N`.
Multiple `@spec` tags allowed (code touched by multiple changes). File-level `@spec` in header docblock.
This enables: code → docblock → spec traceability alongside code → git blame → commit → issue → spec.
Loading
Loading