Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
732 commits
Select commit Hold shift + click to select a range
2472609
chore(deps): bump @conduction/nextcloud-vue to ^1.0.0-beta.154
rubenvdlinde Jul 6, 2026
6d0d016
feat(dashboard): migrate ConceptOrganisatiesWidget to CnDataTable (AD…
rubenvdlinde Jul 6, 2026
9e51e22
Merge pull request 'feat(dashboard): ConceptOrganisatiesWidget on uni…
Jul 6, 2026
fa5ab3b
feat(app): opt in to the AI-chat companion (:ai-companion="true" on C…
rubenvdlinde Jul 6, 2026
ef6db97
Merge pull request 'feat(softwarecatalog): opt in to the AI-chat comp…
Jul 6, 2026
44a0845
feat(portal): ADR-046 portal contribution — vendor-org + participant-…
rubenvdlinde Jul 6, 2026
903b5ab
openspec: propose fix-licence-declaration-consistency
juanclaude-conduction Jul 7, 2026
f62d099
openspec: propose vendor-product-master-data
juanclaude-conduction Jul 7, 2026
3d960ba
openspec: propose module-vulnerability-tracking
juanclaude-conduction Jul 7, 2026
a268f29
openspec: propose software-license-posture
juanclaude-conduction Jul 7, 2026
3cf5bfd
fix(licence): declare EUPL-1.2 consistently (info.xml + 66 lib SPDX h…
juanclaude-conduction Jul 7, 2026
5717868
feat(mdm): vendor/product master-data semantic types + OR MDM markers
juanclaude-conduction Jul 7, 2026
95975ab
feat(vulnerabilities): module vulnerability tracking + exposure
juanclaude-conduction Jul 7, 2026
b2b0d9a
feat(license-posture): portfolio software-license posture (SAM overview)
juanclaude-conduction Jul 7, 2026
295a876
chore(openspec): remove archived change source dirs (moved to changes…
juanclaude-conduction Jul 7, 2026
5593d05
chore(appstore): codeberg links + wire real screenshots
infoconductionnl Jul 7, 2026
2f4e774
Merge pull request 'Software Catalogus: fix Codeberg repo slug + real…
Jul 7, 2026
98b9915
openspec: import 6 change proposals for reapply (proposals only, no c…
rubenvdlinde Jul 7, 2026
0e4e955
fix(security): contract approval per-object ownership guard (IDOR)
rubenvdlinde Jul 7, 2026
9d69f36
perf: bound unbounded searchObjects() full-table scans
rubenvdlinde Jul 7, 2026
4e1150c
fix: implement view products enrichment (was a hardcoded [] stub)
rubenvdlinde Jul 7, 2026
00867ee
fix: restore organisation parent-child hierarchy (create-then-link)
rubenvdlinde Jul 7, 2026
85c57ba
chore(bundle): drop unused apexcharts dep, scope lodash imports
rubenvdlinde Jul 7, 2026
ab2625c
i18n: wrap hardcoded strings in the object-action dialog family
rubenvdlinde Jul 7, 2026
65d2f15
feat(detail-pages): purposeful per-schema detail page design (widgets…
rubenvdlinde Jul 7, 2026
d88a58f
fix(detail-pages): audit sidebar tab via built-in widget type (compon…
rubenvdlinde Jul 7, 2026
f6f4fe1
feat(register): x-relation-filter scoping on relation pickers
rubenvdlinde Jul 8, 2026
6aa5034
feat(detail-pages): ADR-062 rollout — add OrganisatieDetail page, rel…
rubenvdlinde Jul 8, 2026
10ba5bd
chore(deps): bump @conduction/nextcloud-vue to beta.160 + version bum…
rubenvdlinde Jul 8, 2026
72fc305
Merge origin/development (keep 0.2.14)
rubenvdlinde Jul 8, 2026
abd471c
Merge pull request 'feat(detail-pages): ADR-062 rounds 1+2 — NEW Orga…
Jul 8, 2026
f21b4cf
fix(swc): ContractDetail whitespace hole, clipped row, bare approval …
rubenvdlinde Jul 9, 2026
202028c
fix(swc): ReviewDetail whitespace hole and truncated widget title
rubenvdlinde Jul 9, 2026
8447765
fix(swc): quiet empty-state copy on compliance-claims widgets
rubenvdlinde Jul 9, 2026
140b0e0
fix(swc): KwetsbaarheidDetail audit sidebar tab uses unresolvable wid…
rubenvdlinde Jul 9, 2026
7f270de
Merge pull request 'fix(detail-pages): ContractDetail layout+approval…
Jul 9, 2026
f7161a4
chore(deps): nc-vue 1.0.0-beta.162 + version bump (visual-audit fix r…
rubenvdlinde Jul 9, 2026
6b483f6
docs: FEATURES + GOVERNMENT-FEATURES
rubenvdlinde Jul 9, 2026
4c69b14
Merge pull request 'Merge feat/ai-companion-opt-in' (#79) from feat/a…
Jul 9, 2026
c74cfa0
fix(detail-pages): split multi-entry KPI stats-blocks into individual…
rubenvdlinde Jul 9, 2026
f8507a9
fix(softwarecatalog detail pages): individual KPI widgets per ADR-062…
rubenvdlinde Jul 9, 2026
39df375
sync development
rubenvdlinde Jul 9, 2026
0a95dae
chore: pin @conduction/nextcloud-vue 1.0.0-beta.164
rubenvdlinde Jul 9, 2026
15241e8
Catalog UI moves onto the July component release (#81)
rubenvdlinde Jul 9, 2026
c9b30ed
feat(contract): cross-app decision relation to Decidesk (ADR-066 roll…
rubenvdlinde Jul 10, 2026
e433e81
Catalog library pinned to the cross-register foundation build (#83)
rubenvdlinde Jul 10, 2026
8c2c2f6
docs(openspec): preserve authored-but-uncommitted spec changes (2026-…
rubenvdlinde Jul 10, 2026
c9548c4
Merge apply/softwarecatalog-reapply (consolidation 2026-07-10)
rubenvdlinde Jul 10, 2026
ed7e72f
Merge feat/portal-contribution (consolidation 2026-07-10)
rubenvdlinde Jul 10, 2026
4da4b66
Merge fix/adr062-kpi-split (consolidation 2026-07-10)
rubenvdlinde Jul 10, 2026
ef0e74f
Merge specs/authored-2026-07-10 (consolidation 2026-07-10)
rubenvdlinde Jul 10, 2026
17fd879
fix(icon): carry the white fill on the <svg> element, not inner nodes
rubenvdlinde Jul 10, 2026
5a3445e
Merge pull request 'fix: softwarecatalog app.svg root fill for NC34 r…
Jul 10, 2026
f29fcd7
fix(deps): bump dialogs so password-confirmation can resolve
rubenvdlinde Jul 12, 2026
4e2363e
build: add path:false resolve fallback for dialogs v6 FilePicker chunk
rubenvdlinde Jul 12, 2026
b6353df
Merge pull request 'fix(deps): bump dialogs so password-confirmation …
Jul 12, 2026
af1b659
deps: bump shared component library to beta.190 (#87)
rubenvdlinde Jul 12, 2026
ee18b13
fix(settings): stop leaking email secrets to every authenticated user…
rubenvdlinde Jul 12, 2026
c083980
fix(settings): stop hourly 404 fetch of dead remote config + force sc…
rubenvdlinde Jul 12, 2026
4a540d0
Merge pull request 'fix(settings): silence hourly log noise — dead re…
Jul 12, 2026
a728b08
fix(repair): run contacts migration OR calls as system operation
rubenvdlinde Jul 12, 2026
938361f
Merge pull request 'fix(repair): contacts migration runs OR reads/wri…
Jul 13, 2026
01f881b
docs(openspec): add softwarecatalog-mcp-adoption ff change (ADR-063)
rubenvdlinde Jul 13, 2026
090f402
Merge pull request 'softwarecatalog: ADR-063 MCP adoption spec — 9 of…
Jul 13, 2026
61a3737
feat(live-updates): subscribe the module views via nc-vue beta.212
rubenvdlinde Jul 15, 2026
90a6e5d
Merge pull request 'Module views auto-refresh on OR pushes (nc-vue be…
Jul 15, 2026
892b0fe
chore(deps): refresh nextcloud-vue to beta.213
rubenvdlinde Jul 16, 2026
b427d65
Merge pull request 'chore(deps): catalog picks up the manifest realti…
Jul 16, 2026
8f259bc
fix(spec): repoint broken @spec anchors to canonical specs
rubenvdlinde Jul 16, 2026
e2de51a
docs(openspec): spec-anchor-repair change (proposal/design/tasks/resi…
rubenvdlinde Jul 16, 2026
4a736af
Merge pull request 'softwarecatalog: spec-anchor-repair (apply) — 116…
Jul 16, 2026
a6bcd39
chore(openspec): archive spec-anchor-repair change
rubenvdlinde Jul 16, 2026
11fe62b
Merge pull request 'softwarecatalog: archive the spec-anchor-repair c…
Jul 16, 2026
f785b88
docs(openspec): market-gap wave 2026-07-23 — 7 ff spec changes
rubenvdlinde Jul 23, 2026
5da3814
Merge pull request #376 from ConductionNL/wip/market-gap-specs-2026-0…
rubenvdlinde Jul 23, 2026
bdd2eef
fix(security): close vendor and municipality cross-org read leaks
rubenvdlinde Jul 23, 2026
92d7711
test(security): regression + negative tests for vendor-visibility-rbac
rubenvdlinde Jul 23, 2026
b3954a8
docs(openspec): archive vendor-visibility-rbac + route audit
rubenvdlinde Jul 23, 2026
0b38bb1
Merge pull request #377 from ConductionNL/wip/vendor-visibility-rbac
rubenvdlinde Jul 23, 2026
aa27b9b
feat(organisation-merge): admin merge for gemeentelijke herindeling /…
rubenvdlinde Jul 23, 2026
903b493
feat(organisation-merge): admin merge panel on the organisation detai…
rubenvdlinde Jul 23, 2026
d9aa3bb
docs(organisation-merge): document dry-run, execute, tombstone, and U…
rubenvdlinde Jul 23, 2026
531ab22
chore(openspec): archive organisation-merge — apply spec deltas
rubenvdlinde Jul 23, 2026
45a70b1
Merge pull request #381 from ConductionNL/wip/organisation-merge
rubenvdlinde Jul 23, 2026
324265d
feat(facets): GEMMA-dimension facet aggregation endpoint (gemma-facet…
rubenvdlinde Jul 23, 2026
ffd2810
feat(facets): faceted catalog index pages + facet store/UI (gemma-fac…
rubenvdlinde Jul 23, 2026
a981cc3
i18n(facets): NL+EN translations for GEMMA facet UI strings
rubenvdlinde Jul 23, 2026
15e81ca
docs(facets): document GEMMA faceted search in the features README
rubenvdlinde Jul 23, 2026
64f4c7a
test(facets): Postman collection entries for the facets API
rubenvdlinde Jul 23, 2026
1e16f3e
chore(openspec): archive gemma-faceted-search
rubenvdlinde Jul 23, 2026
7b57988
Merge pull request #382 from ConductionNL/wip/gemma-faceted-search
rubenvdlinde Jul 23, 2026
6a96b04
feat(eol-feed-integration): matcher + sync service + scheduled job
rubenvdlinde Jul 23, 2026
903bcfb
feat(eol-feed-integration): admin settings panel + i18n
rubenvdlinde Jul 23, 2026
2c82c20
docs(eol-feed-integration): document mapping, sync, and degradation
rubenvdlinde Jul 23, 2026
71f076c
chore(openspec): archive eol-feed-integration — apply spec deltas
rubenvdlinde Jul 23, 2026
92bc6b1
Merge pull request #383 from ConductionNL/wip/eol-feed-integration
rubenvdlinde Jul 23, 2026
cf584e0
feat(portfolio-rationalization-time): add TIME classification fields …
rubenvdlinde Jul 23, 2026
9b36692
feat(portfolio-rationalization-time): add PortfolioReportController/S…
rubenvdlinde Jul 23, 2026
1622adc
feat(portfolio-rationalization-time): render enum-on-string schema fi…
rubenvdlinde Jul 23, 2026
f9c95ac
feat(portfolio-rationalization-time): add portfolio rationalization r…
rubenvdlinde Jul 23, 2026
28e050d
i18n(portfolio-rationalization-time): add NL/EN translation strings
rubenvdlinde Jul 23, 2026
afc7a4b
docs(portfolio-rationalization-time): document TIME classification an…
rubenvdlinde Jul 23, 2026
487a5a4
chore(openspec): archive portfolio-rationalization-time
rubenvdlinde Jul 23, 2026
bb3a774
Merge pull request #384 from ConductionNL/wip/portfolio-rationalizati…
rubenvdlinde Jul 23, 2026
ce20efa
feat(sbom-import): register schema — sbomComponent + moduleVersie pro…
rubenvdlinde Jul 23, 2026
5f8e189
feat(sbom-import): backend — pure parser, import service, upload cont…
rubenvdlinde Jul 23, 2026
42402d3
feat(sbom-import): frontend — Components tab, render-time vulnerabili…
rubenvdlinde Jul 23, 2026
2e186ab
feat(sbom-import): i18n — Dutch + English strings
rubenvdlinde Jul 23, 2026
6a0c10e
docs(sbom-import): feature doc + Playwright e2e coverage
rubenvdlinde Jul 23, 2026
db834e4
chore(openspec): archive sbom-import — apply spec deltas
rubenvdlinde Jul 23, 2026
382d4c0
Merge pull request #385 from ConductionNL/wip/sbom-import
rubenvdlinde Jul 23, 2026
5e00580
feat(bio-compliance-assessment): register schema — bioMaatregel catal…
rubenvdlinde Jul 23, 2026
dfe562d
feat(bio-compliance-assessment): frontend — BIO catalog pages, module…
rubenvdlinde Jul 23, 2026
14b1497
test(bio-compliance-assessment): register-shape PHPUnit coverage + BI…
rubenvdlinde Jul 23, 2026
c550d3f
i18n(bio-compliance-assessment): NL + EN + EN_US strings for the BIO …
rubenvdlinde Jul 23, 2026
b64da1f
docs(bio-compliance-assessment): feature doc + organisation-merge fil…
rubenvdlinde Jul 23, 2026
d58f832
chore(openspec): archive bio-compliance-assessment
rubenvdlinde Jul 23, 2026
f1c09e7
fix(bio-compliance-assessment): reconcile catalog filtering onto the …
rubenvdlinde Jul 23, 2026
44a243c
Merge pull request #389 from ConductionNL/wip/bio-compliance-assessment
rubenvdlinde Jul 23, 2026
f5c8b3e
fix(facets): normalize ObjectEntity results in FacetService — endpoin…
rubenvdlinde Jul 24, 2026
8e9bbd4
fix(portfolio-report): register organisatie by schema slug — picker w…
rubenvdlinde Jul 24, 2026
88b81b6
fix(sbom): translate DoesNotExistException to 404 in SbomController
rubenvdlinde Jul 24, 2026
330a821
fix(routes): postfix the SPA catch-all so the app root stops 404ing
rubenvdlinde Jul 24, 2026
3959eb3
Merge pull request #392 from ConductionNL/fix/facet-objectentity-norm…
rubenvdlinde Jul 24, 2026
4b01b7b
fix(security): scope schema RBAC reads for gebruik/koppeling/organisa…
rubenvdlinde Jul 24, 2026
0276e26
test(security): schema-RBAC denial + regression tests for schema-rbac…
rubenvdlinde Jul 24, 2026
051b3f5
docs(openspec): archive schema-rbac-hardening + route audit update
rubenvdlinde Jul 24, 2026
3d2f09c
Merge pull request #395 from ConductionNL/wip/schema-rbac-hardening
rubenvdlinde Jul 24, 2026
fbd389b
fix(settings): fold monolith content into import version + fix broken…
rubenvdlinde Jul 24, 2026
e7ea4e9
docs(settings): document register delivery path + i18n for verificati…
rubenvdlinde Jul 24, 2026
79ea681
docs(openspec): archive register-import-reliability change
rubenvdlinde Jul 24, 2026
bb98e6e
Merge pull request #396 from ConductionNL/wip/register-import-reliabi…
rubenvdlinde Jul 24, 2026
c7e82dc
feat(suite-wizard): frontend — guided suite creation wizard, suite in…
rubenvdlinde Jul 24, 2026
892cddd
test(suite-wizard): pure-logic unit tests for wizard payload/validation
rubenvdlinde Jul 24, 2026
07be013
i18n(suite-wizard): NL + EN + EN_US strings for the suite wizard UI
rubenvdlinde Jul 24, 2026
4efddc3
docs(suite-wizard): feature doc for the suite wizard
rubenvdlinde Jul 24, 2026
8e88d71
chore(openspec): archive suite-wizard
rubenvdlinde Jul 24, 2026
b90cdd4
Merge pull request #398 from ConductionNL/wip/suite-wizard
rubenvdlinde Jul 24, 2026
f4e238d
docs(openspec): catalog-ratings proposal, design, specs — archived
rubenvdlinde Jul 24, 2026
fc2fbd4
fix(security): close beoordeeling authorization hole (softwarecatalog…
rubenvdlinde Jul 24, 2026
017a28f
feat(reviews): authenticated submission, approved-only aggregate, mod…
rubenvdlinde Jul 24, 2026
e1e7632
feat(reviews): ratings & reviews UI — submit flow, aggregate panel, r…
rubenvdlinde Jul 24, 2026
4e80622
i18n(reviews): Dutch + English strings for ratings & reviews (ADR-005)
rubenvdlinde Jul 24, 2026
2832f56
docs(reviews): feature doc for catalog ratings (ADR-010)
rubenvdlinde Jul 24, 2026
4ae39ea
Merge pull request #399 from ConductionNL/wip/catalog-ratings
rubenvdlinde Jul 24, 2026
c9860dd
fix(settings): force importFromApp when computed version differs from…
rubenvdlinde Jul 24, 2026
69c73b6
Merge pull request #400 from ConductionNL/fix/force-import-when-versi…
rubenvdlinde Jul 24, 2026
46f207e
feat(multi-org-membership): beheerder-gated self-service colleague ac…
rubenvdlinde Jul 24, 2026
9aa7c5a
feat(multi-org-membership): organisation switcher + self-service acce…
rubenvdlinde Jul 24, 2026
8fcb51c
i18n(multi-org-membership): NL + EN_US strings for the switcher and a…
rubenvdlinde Jul 24, 2026
f8ab78c
docs(multi-org-membership): feature doc for the organisation switcher…
rubenvdlinde Jul 24, 2026
1f63f26
docs(openspec): archive multi-org-membership
rubenvdlinde Jul 24, 2026
52c5a76
fix(multi-org-membership): correct @spec anchor kebab-casing for apos…
rubenvdlinde Jul 24, 2026
51266a6
docs(multi-org-membership): reason-bearing @e2e exclude — no live dep…
rubenvdlinde Jul 24, 2026
73ae1f0
Merge pull request #401 from ConductionNL/wip/multi-org-membership
rubenvdlinde Jul 24, 2026
414469b
fix(suite-wizard): read the collection envelope, not a bare array
rubenvdlinde Jul 24, 2026
a8eb288
Merge pull request #405 from ConductionNL/fix/suite-wizard-collection…
rubenvdlinde Jul 24, 2026
d492f43
i18n(schema): author softwarecatalog property titles in English + NL …
rubenvdlinde Jul 25, 2026
d2da799
Merge pull request #406 from ConductionNL/wip/schema-titles-en
rubenvdlinde Jul 25, 2026
4f890f7
fix(ratings): resolve beoordeeling register+schema so reviews work (#…
rubenvdlinde Jul 25, 2026
e8f51dc
test(ratings): regression cover for catalog-type register/schema reso…
rubenvdlinde Jul 25, 2026
8b22ffe
Merge pull request #407 from ConductionNL/fix/review-register-resolution
rubenvdlinde Jul 25, 2026
f6bca7b
fix(sbom): move SBOM provenance props to moduleVersie schema (#385)
rubenvdlinde Jul 25, 2026
8add861
test(e2e): make nav-drill helper survive collapsed submenus and the o…
rubenvdlinde Jul 25, 2026
12f0128
test(sbom): make the sbom-import e2e executable + add register-shape …
rubenvdlinde Jul 25, 2026
3f8cd1d
chore(deps): @conduction/nextcloud-vue ^1.0.0-beta.221 — activate sch…
rubenvdlinde Jul 26, 2026
c4c0b9c
Merge pull request #408 from ConductionNL/wip/ncvue-beta221
rubenvdlinde Jul 26, 2026
13215dd
i18n(schema): author softwarecatalog schema-level titles in English +…
rubenvdlinde Jul 26, 2026
1082c77
Merge pull request #409 from ConductionNL/wip/schema-level-titles
rubenvdlinde Jul 26, 2026
47a2872
i18n(l10n): complete en/nl runtime translation coverage
rubenvdlinde Jul 26, 2026
a1d6e95
Merge pull request #410 from ConductionNL/wip/l10n-coverage
rubenvdlinde Jul 26, 2026
85b4e42
test(l10n): parity opt-in + add l10n coverage CI gate
rubenvdlinde Jul 30, 2026
4af52fc
Merge pull request #411 from ConductionNL/wip/l10n-parity-optin
rubenvdlinde Jul 30, 2026
0ce32eb
feat(icons): adopt the ADR-077 semantic icon vocabulary (#412)
rubenvdlinde Jul 30, 2026
a76cedb
feat(icons): extend ADR-077 to page, widget and action icons (#413)
rubenvdlinde Jul 30, 2026
319b47e
ci: point the reusable workflows at the org and branch that exist (#414)
rubenvdlinde Aug 2, 2026
e2d2b48
feat(vue3): migrate softwarecatalog to Vue 3 + @nextcloud/vue v9 (#416)
rubenvdlinde Aug 2, 2026
c864469
build: make composer check:strict able to fail (#415)
rubenvdlinde Aug 2, 2026
4d16cdb
fix(ci): make composer check:strict able to fail on tests (#417)
rubenvdlinde Aug 2, 2026
3a9defb
ci: enable the shared E2E Tests (Playwright) job
Aug 3, 2026
d2819f7
fix(deps): bump guzzlehttp/{guzzle,psr7,promises} to clear composer a…
Aug 3, 2026
8e6730e
fix(e2e): CI playwright config died on a glob inside its own block co…
Aug 3, 2026
00882fd
fix(security): bump guzzlehttp/guzzle 7.10.0 -> 7.15.2 and psr7 2.11.…
rubenvdlinde Aug 3, 2026
74bbdd0
Merge pull request #420 from ConductionNL/fix/composer-security-advis…
rubenvdlinde Aug 3, 2026
8d905c9
fix(quality): phpmd DevelopmentCodeFragment could never fire on names…
rubenvdlinde Aug 3, 2026
d3dd7ce
chore(security): refresh roave/security-advisories guard (2026-03-03 …
rubenvdlinde Aug 3, 2026
43e5427
fix(e2e): the suite addressed the app by a path that only exists behi…
Aug 3, 2026
a48654e
fix(e2e): bring the suite up to date with the schema/manifest it tests
Aug 3, 2026
c91dcfd
TEMPORARY: truncate the webpack bundle to prove the e2e specs exercis…
Aug 3, 2026
a43b4f0
Revert "TEMPORARY: truncate the webpack bundle to prove the e2e specs…
Aug 3, 2026
53d27b0
docs(e2e): the moduleVersie create 'bug' was a stale dev instance, no…
Aug 3, 2026
77d7e01
Merge pull request #418 from ConductionNL/ci/e2e-enable
rubenvdlinde Aug 3, 2026
8bcc138
ci: bound the l10n coverage job runtime (#422)
rubenvdlinde Aug 3, 2026
ba50b08
fix(quality): clear the psalm/phpstan quality backlog and 54 phpmd fi…
rubenvdlinde Aug 3, 2026
2696ce0
chore(quality): make composer check:strict green by suppressing phpmd…
rubenvdlinde Aug 3, 2026
6cdae8e
chore(deps): upgrade @conduction/nextcloud-vue to 3.0.0-vue3.4 (#426)
rubenvdlinde Aug 4, 2026
09f9b5c
feat(schema): mark the GEMMA AMEF Element reference component shareab…
rubenvdlinde Aug 4, 2026
68df2ce
fix(events): stop broadcasting object lifecycle to the disabled SWC l…
rubenvdlinde Aug 4, 2026
1190403
chore(deps): @conduction/nextcloud-vue 3.0.0-vue3.6
Aug 4, 2026
f51fd61
Merge pull request #429 from ConductionNL/chore/ncvue-vue3.6
rubenvdlinde Aug 4, 2026
568bbec
ci(quality): enable the Code Quality gates this repo was silently ski…
rubenvdlinde Aug 4, 2026
c984e19
ci(quality): restore the missing push trigger (#432)
rubenvdlinde Aug 4, 2026
cd5259a
chore(deps): repin @conduction/nextcloud-vue to 2.2.0-vue3.3 (3.0.0-v…
rubenvdlinde Aug 5, 2026
5657c3c
ci(quality): move hydra-gates-ref v1.0.1 -> v1.3.0, which is what is …
rubenvdlinde Aug 5, 2026
a9a4c49
chore: normalise all licence declarations to EUPL-1.2 (#437)
rubenvdlinde Aug 5, 2026
473623a
fix(phpmd): scope the lib/Migration UnusedFormalParameter exclusion t…
rubenvdlinde Aug 5, 2026
a09ff02
chore(ci): move hydra-gates-ref v1.3.0 -> v1.4.0 (#438)
rubenvdlinde Aug 6, 2026
84bd566
ci(quality): move hydra-gates-ref to v1.5.0, the pin the floating wor…
rubenvdlinde Aug 6, 2026
ed6db8c
chore(ci): stop pinning hydra-gates — track the package at @main (#439)
rubenvdlinde Aug 6, 2026
db27a7c
fix(ci): compare the coverage ratchet against the measured merge base…
rubenvdlinde Aug 6, 2026
9c217ab
ci: publish an installable build of development (#441)
rubenvdlinde Aug 6, 2026
c8efc67
fix(gate-57): delete the dead user-provisioning stub that only logged
rubenvdlinde Aug 6, 2026
0d2d60f
Merge pull request #442 from ConductionNL/fix/gate-57-dead-user-provi…
rubenvdlinde Aug 6, 2026
98a4612
chore(deps): clear all critical + high npm advisories on development …
rubenvdlinde Aug 6, 2026
59fbd11
fix(security): PHP_CodeSniffer 3.13.5 -> 3.13.6 (CVE-2026-67434, OS c…
rubenvdlinde Aug 6, 2026
8f14a11
chore(ci): point Dependabot at development, where the gates actually …
rubenvdlinde Aug 6, 2026
0d9eb65
chore(deps): remove 4 dead remark packages — nothing invokes them (#448)
rubenvdlinde Aug 7, 2026
a7d2490
fix(federation): delete the orphaned publish wrapper and test the sea…
rubenvdlinde Aug 7, 2026
47c00ba
chore(deps): remove dead runtime deps — bare axios, @fortawesome, @vu…
rubenvdlinde Aug 7, 2026
d777e52
fix(mail): install the 4 mailer bridges the code already builds DSNs …
rubenvdlinde Aug 7, 2026
0bb4d3d
fix: declare NC 32 as the floor — openregister cannot install below i…
rubenvdlinde Aug 7, 2026
8bf2436
fix: restore the 16 branch bodies commit 651a055f deleted (#455)
rubenvdlinde Aug 8, 2026
9566d08
fix(auth): guard the aggregate user-groups route and align 10 auth an…
rubenvdlinde Aug 8, 2026
dea9b54
fix(phpcs): stop the SpecTagSniff instructing the pattern gate-46 rej…
rubenvdlinde Aug 8, 2026
d826781
fix(e2e): retain-on-failure traces + a globalTimeout under the 45m CI…
rubenvdlinde Aug 8, 2026
99264e3
Merge pull request #462 from ConductionNL/fix/spec-tag-sniff-canonica…
rubenvdlinde Aug 8, 2026
b3838c6
feat(settings): add canonical PUT /api/settings (settings#update) (#464)
rubenvdlinde Aug 8, 2026
3a542f2
fix(a11y): four widget icons rendered the wrong glyph, three controls…
rubenvdlinde Aug 9, 2026
eff9e05
fix(auth): scope the contact-person read-outs to the caller's organis…
rubenvdlinde Aug 9, 2026
df0a21f
refactor(archimate): delete the unreachable private getVoorzieningenC…
rubenvdlinde Aug 9, 2026
f5538e7
fix(a11y): label 19 form fields, scope 19 tables, honour reduced moti…
rubenvdlinde Aug 9, 2026
b2c070a
fix(gates): one settings home, four dangling $refs, two mistyped spec…
rubenvdlinde Aug 9, 2026
f0bea90
test: pin the public review-aggregate wire contract and prove five pa…
rubenvdlinde Aug 9, 2026
f8c32f7
fix(archimate): unset AMEF ids were handed on as empty strings past a…
rubenvdlinde Aug 9, 2026
0020132
docs(spec): trace 64 frontend methods to their spec, and sync the spe…
rubenvdlinde Aug 9, 2026
0586437
fix(register): drop the unresolvable $ref on the cross-app decisions …
rubenvdlinde Aug 9, 2026
5b4fe42
chore(deps): pin @conduction/nextcloud-vue to 2.2.0-vue3.7
rubenvdlinde Aug 10, 2026
d2616b8
Merge pull request #474 from ConductionNL/chore/pin-ncvue-2.2.0-vue3.7
rubenvdlinde Aug 10, 2026
39a3333
chore(deps): pin @conduction/nextcloud-vue to 2.2.0-vue3.9
rubenvdlinde Aug 10, 2026
4fbb85b
Merge pull request #475 from ConductionNL/chore/pin-ncvue-2.2.0-vue3.9
rubenvdlinde Aug 10, 2026
72f92f4
ci: this workflow could not be run on purpose (#476)
rubenvdlinde Aug 10, 2026
274790f
fix(spec): four @spec tags named a Scenario as if it were a Requireme…
rubenvdlinde Aug 10, 2026
f699b5a
fix(fe): gate-13 — extract four inline modals, and fix the slot typo …
rubenvdlinde Aug 10, 2026
126eda6
test(gates): real contract tests close gate-25 (41 -> 0); gate-26 3 -…
rubenvdlinde Aug 11, 2026
ebc93ff
test(e2e): 18 real Playwright tests close gate-19 137 -> 112 (#486)
rubenvdlinde Aug 11, 2026
ea4dc7e
fix(security): bump phpcsstandards/phpcsutils to 1.2.3 for CVE-2026-6…
rubenvdlinde Aug 11, 2026
d401ab7
fix(merge): organisation merge re-points nothing — probe a magic acce…
rubenvdlinde Aug 12, 2026
f2dcacc
chore(softwarecatalog): remove two committed debug scripts (#487)
rubenvdlinde Aug 12, 2026
088e14c
feat(repair): migrate softwarecatalog's Dutch columns to English (#488)
rubenvdlinde Aug 12, 2026
514d9c0
chore: adopt Nextcloud's coding standard, .editorconfig and NC 34 (#493)
rubenvdlinde Aug 12, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
223 changes: 223 additions & 0 deletions .claude/openspec/architecture/adr-001-data-layer.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,223 @@
- ALL domain data → OpenRegister objects. NO custom Entity/Mapper for domain data.
- App config → `IAppConfig`. NOT OpenRegister.
- Cross-entity references: OpenRegister relations (register+schema+objectId). NO foreign keys.
MUST NOT store foreign keys or embed full objects.

### Schema standards

- Schemas: PascalCase, schema.org vocabulary, explicit types + required flags + description field.
- MUST NOT invent custom property names when a schema.org equivalent exists.
- Contact schemas MUST align with vCard properties (fn, email, tel, adr).
- Dutch government fields SHOULD use a mapping layer translating between international standards
and Dutch specs — do not hardcode Dutch field names as primary.
- Schema changes that remove or rename properties are BREAKING. Adding optional properties is non-breaking.

### Register templates

- Location: `lib/Settings/{app}_register.json` (OpenAPI 3.0 + `x-openregister` extensions).
- Three template categories:
- **App configuration** — define data models (schemas/registers/views/mappings).
Mark with `x-openregister.type: "application"`.
- **Mock data** — fictional but realistic seed data for dev/test.
Mark with `x-openregister.type: "mock"`.
- **Government standards** — aligned to Dutch API specs (BAG, BRP, KVK, DSO).
- Import mechanism: `ConfigurationService::importFromApp(appId, data, version, force)` →
`ImportHandler::importFromApp()`. Called from repair step or `SettingsLoadService`.
- Idempotency: re-importing with `force: false` MUST NOT create duplicates. Match by slug
using `ObjectService::searchObjects` with `_rbac: false` and `_multitenancy: false`.
Use `version_compare` for skip logic.

### Seed data

Apps that store data in OpenRegister are empty on first install. An empty app cannot be
meaningfully tested — there are no objects to view, search, filter, or interact with.
This blocks both automated browser testing and manual QA. The Loadable Register Template
pattern (see Register templates above) already supports seed data via `components.objects[]`
with the `@self` envelope.

**Requirements:**

- Every app using OpenRegister MUST include 3-5 realistic objects per schema in
`lib/Settings/{app}_register.json`.
- Use `@self` envelope: `{ "@self": { "register": ..., "schema": ..., "slug": ... }, ...properties }`.
Register/schema MUST match keys; slug is unique human-readable identifier for matching.
- Use general organisation data (municipality, consultancy, travel agency, non-profit) —
NOT context-specific. Varied, realistic field values.
- Mock data quality: real Dutch street names, valid postcodes (`[1-9][0-9]{3}[A-Z]{2}`),
correct municipality/KVK codes, BSNs that pass 11-proef. Fictional but distinguishable from real.
- Cross-register consistency: BRP→BAG, KVK→BAG, DSO→BAG references must be valid.
- Loaded on install alongside schemas via same `importFromApp()` pipeline.
- MUST be idempotent — re-importing skips existing objects matched by slug.

**In OpenSpec artifacts:**

- **In design.md**: MUST include a Seed Data section when change introduces/modifies schemas —
define seed objects per schema with concrete field values and related items (files, notes, tasks, contacts).
- **In tasks.md**: MUST include a seed data generation task when change introduces/modifies schemas.

**Exceptions** (no seed data required):

- **nldesign** — has no OpenRegister schemas.
- **ExApp sidecar wrappers** (openklant, opentalk, openzaak, valtimo, n8n-nextcloud) — proxy
external services and do not use OpenRegister.
- **nextcloud-vue** — shared library, no seed data applicable.
- Changes that only modify frontend components or non-schema backend logic (e.g., settings,
permissions) do not require seed data.

**Limitations:** OpenRegister's `ImportHandler` currently supports only flat seed objects.
Related items (files, notes, tasks, contacts) linked through the relation system are tracked
in OpenRegister's pending `seed-related-items` openspec change (see
`openregister/openspec/changes/seed-related-items/`). Until that lands, seed data is limited
to object properties defined in schemas.

### Deduplication check

- Before proposing new capability: search `openspec/specs/` and `openregister/lib/Service/` for overlap
with ObjectService, RegisterService, SchemaService, ConfigurationService, and shared Vue components.
- If similar capability exists: MUST reference it and explain why new code is needed rather than extending.
- Proposals duplicating existing functionality without justification MUST be rejected.
- **In design.md**: MUST include a "Reuse Analysis" section listing existing OpenRegister services leveraged.
- **In tasks.md**: MUST include a "Deduplication Check" task verifying no overlap — document findings
even if "no overlap found".

### Schema migrations

- Breaking schema changes → new migration in repair step. NEVER modify existing migrations.

### OpenRegister + @conduction/nextcloud-vue — DO NOT REBUILD

The platform provides 258+ backend methods and 69+ frontend components. Apps ONLY build
custom logic for domain-specific business rules. Everything below is provided for FREE.

**CRUD & Data Management** (use ObjectService + CnIndexPage + CnDetailPage):
- Single & bulk create, read, update, delete — `ObjectService.saveObject()`, `deleteObject()`
- List with pagination, sorting, filtering — `ObjectService.findAll()` + `CnDataTable`
- Schema-driven forms — `CnFormDialog` (auto-generates from schema) or `CnAdvancedFormDialog`
- Detail views — `CnDetailPage` with `CnDetailGrid`, `CnDetailCard` sections
- Record merging/deduplication — `ObjectService.mergeObjects()`
- Object locking — `ObjectService.lockObject()` / `unlockObject()`

**Import & Export** (use ImportService/ExportService + CnMassImportDialog/CnMassExportDialog):
- CSV, Excel, JSON import with intelligent field mapping — `ImportService`
- CSV, Excel, JSON export with column selection — `ExportService`
- Bulk import with validation and progress — `CnMassImportDialog`
- Filtered export with format picker — `CnMassExportDialog`
- NO custom import dialogs, parsers, upload handlers, or export controllers

**Search & Discovery** (use IndexService + CnFilterBar + CnFacetSidebar):
- Full-text search with field weighting — `IndexService`
- Faceted navigation with counts — `FacetBuilder` + `CnFacetSidebar`
- Semantic search with embeddings — `VectorizationService`
- Hybrid search (keyword + semantic) — automatic
- Search analytics — `SearchTrailService` (popular terms, activity)
- NO custom search endpoints, query builders, or search pages

**File Management** (use FileService + CnObjectSidebar):
- Upload (single/multipart), download, share links — `FileService`
- File tagging, public/private toggle — `FileService`
- Bulk download as ZIP — `createObjectFilesZip()`
- Text extraction from PDFs/Office docs — `TextExtractionService`
- File tab in object sidebar — `CnObjectSidebar` → `CnFilesTab`
- NO custom file upload components, file controllers, or download handlers

**Audit & Compliance** (use AuditTrailService + CnObjectSidebar):
- Full change tracking with before/after snapshots — automatic
- Audit trail tab — `CnObjectSidebar` → `CnAuditTrailTab`
- GDPR data subject access requests — `inzageverzoek()`, `verwerkingsregister()`
- Audit export and analytics — `AuditTrailController`
- NO custom audit logging, change tracking, or compliance controllers

**Dashboard & Analytics** (use CnDashboardPage + CnChartWidget + CnStatsBlock):
- Drag-drop widget dashboard — `CnDashboardPage` with GridStack
- KPI cards — `CnKpiGrid`, `CnStatsBlock`, `CnStatsPanel`
- Charts (line/bar/pie/donut) — `CnChartWidget` (ApexCharts)
- Data tables as widgets — `CnTableWidget`
- Editable data grids — `CnObjectDataWidget`
- NO custom dashboard layouts, chart components, or KPI cards

**Forms & Dialogs** (use CnFormDialog + schema-driven generation):
- Auto-generated create/edit forms — `CnFormDialog` reads schema → generates fields
- JSON/metadata editing — `CnAdvancedFormDialog` with Properties/Data/Metadata tabs
- Schema editor — `CnSchemaFormDialog`
- Delete/Copy/Mass operations — `CnDeleteDialog`, `CnCopyDialog`, `CnMassDeleteDialog`
- NO custom form components, validation logic, or dialog wrappers

**Navigation & Pagination** (use CnPagination + CnActionsBar + useListView):
- Pagination control with size selector — `CnPagination`
- Action bar (add, search, toggle views) — `CnActionsBar`
- List state management — `useListView` composable (handles search, filter, sort, page)
- Detail state management — `useDetailView` composable
- NO custom pagination logic, debounced search, or list state management

**Authorization & RBAC** (use AuthorizationService + PropertyRbacHandler):
- Role-based access control — `AuthorizationService`
- Field-level permissions — `PropertyRbacHandler`
- Object-level restrictions — `PermissionHandler`
- Authorization audit — `AuthorizationAuditService`
- NO custom permission checks, role systems, or access control middleware

**Webhooks & Events** (use WebhookService):
- Create, test, retry webhooks — `WebhookService`
- CloudEvents format — automatic
- Event subscriptions — selective per schema/action
- NO custom webhook controllers or event dispatchers

**Notifications & Activity** (use NotificationService + ActivityService):
- Nextcloud notifications — `NotificationService`
- Activity feed — `ActivityService`
- Calendar events — `CalendarEventService`
- Deck/Kanban cards — `DeckCardService`

**Store & State** (use createObjectStore + plugins):
- Object stores — `createObjectStore(name)` generates Pinia CRUD store
- Store plugins: `auditTrails`, `files`, `lifecycle`, `relations`, `search`, `selection`
- Column/field/filter generation from schema — `columnsFromSchema()`, `fieldsFromSchema()`
- NO custom Pinia stores for CRUD, Vuex, or manual API call management

**Chat & AI** (use ChatService):
- Multi-turn conversation — `ChatService`
- RAG-based knowledge retrieval — `ContextRetrievalHandler`
- LLM response generation — `ResponseGenerationHandler`

**Data Retention & Archival** (use ArchivalService):
- Legal hold — `LegalHoldService`
- Destruction schedules — `DestructionService`
- Retention policies — `RetentionService`

**Semantic & Hybrid Search** (use SolrController + SettingsController):
- Semantic search via vector embeddings — `SettingsController.semanticSearch()`
- Hybrid search (keyword + semantic combined) — `SolrController.hybridSearch()`
- Vector embedding generation — `VectorizationService`
- NO custom search algorithms — configure via OpenRegister settings

**GraphQL API** (use GraphQLController):
- Query objects across schemas via GraphQL — `GraphQLController.execute()`
- Alternative to REST for complex cross-entity queries

**Organization / Multi-Tenancy** (use OrganisationController):
- Organization CRUD — `OrganisationController`
- Tenant-scoped data isolation — automatic via `TenantLifecycleService`
- NO custom multi-tenancy logic

**Task & Workflow Management** (use TasksController + WorkflowEngineController):
- Task creation and tracking — `TasksController`
- Workflow orchestration — `WorkflowEngineRegistry`
- Scheduled workflows — `ScheduledWorkflowController`
- NO custom task/workflow systems

**Text Extraction** (use FileTextController):
- Extract text from PDFs and Office docs — `TextExtractionService`
- Entity recognition (PII detection) — `EntityRecognitionHandler`
- Content anonymization — automatic

**Timeline & Stages** (use CnTimelineStages):
- Workflow progression visualization — `CnTimelineStages` component
- Stage tracking with status colors

### What apps SHOULD build (custom business logic only):
- External API integrations (SAP, Peppol, TenderNed, etc.)
- PDF/document generation with business-specific templates
- Workflow triggers and business rules specific to the domain
- Notification dispatch with app-specific event types
- Custom settings pages with app-specific configuration
- Background jobs for domain-specific processing
6 changes: 6 additions & 0 deletions .claude/openspec/architecture/adr-002-api.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
- URL pattern: `/index.php/apps/{app}/api/{resource}` — lowercase plural, hyphens.
- Methods: GET=read, POST=create, PUT=update, DELETE=remove. No custom methods.
- Pagination: support `_page` + `_limit`. Response includes `total`, `page`, `pages`.
- Errors: appropriate HTTP status + `message` field. NO stack traces in responses.
- Auth: Nextcloud built-in only. NO custom login/session/token flows.
- Public endpoints: annotate `#[PublicPage]` + `#[NoCSRFRequired]`. Register CORS OPTIONS route.
14 changes: 14 additions & 0 deletions .claude/openspec/architecture/adr-003-backend.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
- **Controller → Service → Mapper** (strict 3-layer). Controllers NEVER call mappers directly.
- Controllers: thin (<10 lines/method). Routing + validation + response only.
- Services: ALL business logic. Stateless — no instance state between requests.
- Mappers: DB CRUD only. No business logic.
- DI: constructor injection with `private readonly`. NO `\OC::$server` or static locators.
- Entity setters: POSITIONAL args only. `$e->setName('val')` — NEVER `$e->setName(name: 'val')`.
(`__call` passes `['name' => val]` but `setter()` uses `$args[0]`.)
- Routes: `appinfo/routes.php`. Specific routes BEFORE wildcard `{slug}` routes.
- Config: `IAppConfig` with sensitive flag for secrets. NEVER read DB directly.
- Lifecycle: schema init via repair steps (`IRepairStep`), background via job queue, events via dispatcher.
- **Spec traceability**: every class and public method MUST have `@spec` PHPDoc tag(s) linking to
the OpenSpec change that caused it: `@spec openspec/changes/{name}/tasks.md#task-N`.
Multiple `@spec` tags allowed (code touched by multiple changes). File-level `@spec` in header docblock.
This enables: code → docblock → spec traceability alongside code → git blame → commit → issue → spec.
Loading
Loading