Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
106 commits
Select commit Hold shift + click to select a range
3a58082
Merge branch 'fix/public-share-link-routing' into l10n/nl-bulk-transl…
remko48 Sep 4, 2026
dc533be
feat(lock-screen): open the padlock when the vault unlocks
remko48 Sep 4, 2026
d2e6a5b
fix(nav): give every vault glyph a circle and room to breathe
remko48 Sep 4, 2026
492da24
fix(l10n): translate the unlock announcement
remko48 Sep 4, 2026
1999b28
docs(lock-screen): tag beforeUnmount for the spec-coverage gate
remko48 Sep 4, 2026
6988df9
chore(dev): mount and enable thematiq in the local stack
remko48 Sep 4, 2026
4680e28
chore: ignore restyle scratch files
remko48 Sep 4, 2026
5afe845
feat(l10n): complete and de-contaminate all 36 locale files
remko48 Sep 4, 2026
5fa8abf
test(l10n): hard-enforce parity for every required locale
remko48 Sep 4, 2026
d7a5b6c
chore(sync): carry beta back into development
github-actions[bot] Sep 6, 2026
96dfc7e
Merge pull request #631 from ConductionNL/sync/beta-to-development-20…
rubenvdlinde Sep 6, 2026
4648f2b
chore(license): declare REUSE/SPDX licensing for the whole tree
remko48 Sep 7, 2026
2e134f2
chore(license): use the canonical EUPL-1.2 text in LICENSES/
remko48 Sep 7, 2026
77323a1
fix(l10n): give the Romansh unlock announcement actual Romansh
remko48 Sep 7, 2026
31ded83
fix(lock-screen): let the unlock's second channels actually fire
remko48 Sep 7, 2026
a85bafe
fix(nav): key the active-row vault disc to the highlight it sits on
remko48 Sep 7, 2026
4ff63cc
fix(lock-screen): keep the padlock's box out of its state classes
remko48 Sep 7, 2026
976506b
Merge pull request #619 from ConductionNL/feat/unlock-animation-and-v…
remko48 Sep 7, 2026
b601962
fix(dev): keep thematiq out of the committed local stack
remko48 Sep 7, 2026
0a90ecc
docs(l10n): record the real size of the parity backlog
remko48 Sep 7, 2026
897ab3e
fix(l10n): stop pointing at a ratchet the default cannot reach
remko48 Sep 7, 2026
f9f817d
fix(l10n): drop the unused unlock announcement from every catalogue
remko48 Sep 7, 2026
d5a6109
fix(l10n): give sr a single script
remko48 Sep 7, 2026
19570f0
fix(l10n): translate uk out of Russian
remko48 Sep 7, 2026
e5e9749
fix(l10n): translate be out of Russian
remko48 Sep 7, 2026
cee8d96
Merge remote-tracking branch 'origin/development' into l10n/nl-bulk-t…
remko48 Sep 7, 2026
94e62bb
chore(license): correct the REUSE.toml header comment
remko48 Sep 7, 2026
97af0f9
docs(contributing): say how REUSE licensing works for new files
remko48 Sep 7, 2026
4957694
Merge pull request #620 from ConductionNL/l10n/nl-bulk-translation
remko48 Sep 7, 2026
ab0144b
ci(quality): fail the build on REUSE findings
remko48 Sep 7, 2026
e7567c3
docs(ci): correct and tidy the code-quality comments
remko48 Sep 7, 2026
761c999
docs: drop the restyle-stage references from the tree
remko48 Sep 7, 2026
298b9e1
Merge remote-tracking branch 'origin/development' into chore/reuse-co…
remko48 Sep 7, 2026
ab8e54c
Merge pull request #636 from ConductionNL/chore/reuse-compliance
remko48 Sep 7, 2026
99f62a0
fix(deps): clear all npm audit findings by pruning the vulnerable sub…
remko48 Sep 7, 2026
d48fe7d
fix(eslint): formatting
remko48 Sep 7, 2026
7907b24
fix(secrets): give the breadcrumb Home crumb a name
SudoThijn Sep 7, 2026
f7d63c3
style(secrets): square off the actions bar's top corners
SudoThijn Sep 7, 2026
031ee94
feat(dashboard): reach the applications page from the approval queue
SudoThijn Sep 7, 2026
27b0919
chore(deps): drop the unused terser-webpack-plugin dependency
remko48 Sep 7, 2026
8ea2613
refactor(webpack): fold the publicPath override into the output literal
remko48 Sep 7, 2026
d397f56
docs(readme): correct the build and frontend rows in the tech stack
remko48 Sep 7, 2026
cd274f0
fix(bulk): the delete dialog reports once it has deleted
SudoThijn Sep 7, 2026
9f5b9ea
fix(bulk): move, share and team-folder report once they are done
SudoThijn Sep 7, 2026
4580745
Merge pull request #640 from ConductionNL/fix/drop-vulnerable-dep-sub…
remko48 Sep 7, 2026
cf0d1da
fix(e2e): assert each surface the unlock error lands on (#642)
rubenvdlinde Sep 7, 2026
6c09423
chore(deps): refresh the shared Conduction locks (#635)
rubenvdlinde Sep 7, 2026
81483a8
fix(e2e): the same ambiguous locator, one file over (#645)
rubenvdlinde Sep 7, 2026
d03070f
chore(license): declare webpack.config.js AGPL-3.0-or-later
remko48 Sep 8, 2026
92685cb
chore(license): fix the copyright marker and cross-references in the …
remko48 Sep 8, 2026
d550e4f
Merge pull request #647 from ConductionNL/chore/agpl-header-webpack-c…
remko48 Sep 8, 2026
e050431
chore: updated nextcloud-vue package
remko48 Sep 8, 2026
5625d86
chore(settings): hide the browser extension section until it ships
SudoThijn Sep 8, 2026
96324cf
fix(tests): cap PHPUnit memory and only boot an installed Nextcloud i…
rubenvdlinde Sep 8, 2026
1832b96
feat(db): rename the doriath_ tables to keepiq_ and consolidate 35 mi…
Sep 8, 2026
7c9bd88
fix(requests): rework the ask-for-a-credential dialog
SudoThijn Sep 8, 2026
2d5b349
feat(requests): file a requested credential where you asked from
SudoThijn Sep 8, 2026
41c6c3d
feat(nav): create vaults and folders from the rail
SudoThijn Sep 8, 2026
005eae0
docs: point two stale references at the consolidated migration
Sep 8, 2026
78fb3e9
test(migration): cover the consolidated schema migration
Sep 8, 2026
0920239
feat(sharing): batch recipient-certificate lookup for share dialogs
rjzondervan Sep 8, 2026
d21537b
Merge pull request #652 from ConductionNL/feat/rename-tables-and-cons…
rubenvdlinde Sep 8, 2026
a29ab1d
refactor(storage): move attachment blobs to the keepiq AppData namespace
rjzondervan Sep 8, 2026
ffd4dff
feat(api): accept both keepiq and doriath as assertion audience
rjzondervan Sep 8, 2026
9180d01
docs(spec): specify blob addressing and relocation safety
rjzondervan Sep 8, 2026
09c0457
feat(api): dual-serve the discovery path, announce the envelope succe…
rjzondervan Sep 8, 2026
80b8a89
Merge remote-tracking branch 'origin/development' into feat/batch-rec…
rjzondervan Sep 8, 2026
7babe0e
fix(tests): a mid-boot Nextcloud failure warns, it does not abort the…
rubenvdlinde Sep 8, 2026
a8fe6ed
feat(team-folders): pick members from the users who hold a suite
SudoThijn Sep 8, 2026
4affa8f
feat(team-folders): pick group members from the server's groups
SudoThijn Sep 8, 2026
a3a2f90
Merge pull request #649 from ConductionNL/chore/nextcloud-vue-package…
remko48 Sep 8, 2026
301c95b
fix(repair): bump the app version so the blob move actually runs
rjzondervan Sep 8, 2026
3ccb742
refactor(sharing): resolve a recipient through one code path
rjzondervan Sep 8, 2026
679668c
refactor(auth): give the audience contract its own class
rjzondervan Sep 8, 2026
7d6418a
docs(openspec): the revoke citation names the wrong test class (#660)
rubenvdlinde Sep 8, 2026
6be924d
fix(spec): point a stale @e2e citation at the class that holds the tests
rjzondervan Sep 8, 2026
4ce7938
fix(spec): point a stale @e2e citation at the class that holds the tests
rjzondervan Sep 8, 2026
906aa3e
fix(sharing): restore @spec on recipientCertificate, fix a stale cita…
rjzondervan Sep 8, 2026
fd446dc
fix(sharing): deduplicate without a quadratic scan, correlate results…
rjzondervan Sep 8, 2026
4d2b2d7
fix(auth): read the aud claim strictly instead of coercing it
rjzondervan Sep 8, 2026
01a7b0d
fix(attachments): fall back to the old namespace on read
rjzondervan Sep 8, 2026
016a8e2
style(team-folders): keep the add-member row on one line
SudoThijn Sep 8, 2026
1426e59
Merge pull request #656 from ConductionNL/feat/batch-recipient-certif…
rjzondervan Sep 8, 2026
c54f673
Merge branch 'development' into feature/changes
SudoThijn Sep 8, 2026
65a7df2
Merge pull request #654 from ConductionNL/refactor/move-attachment-bl…
rjzondervan Sep 8, 2026
211ccd3
feat(team-folders): pick user members through the shareability probe
SudoThijn Sep 8, 2026
9f165dc
fix(api): enforce the deprecation deadline, assert the published audi…
rjzondervan Sep 8, 2026
8e5298c
fix(select): theme the unselectable options in a teleported dropdown
SudoThijn Sep 8, 2026
772b5d7
feat(team-folders): leave users without a suite out of the picker
SudoThijn Sep 8, 2026
e14b3fd
fix(team-folders): keep the member field a picker when the list is empty
SudoThijn Sep 8, 2026
478b753
style(tests): format the two bulk dialog specs
SudoThijn Sep 8, 2026
5b51723
docs(spec): satisfy the two Hydra gates this branch tripped
SudoThijn Sep 8, 2026
f10b8a8
fix(auth): reject object-valued audiences, report only after authenti…
rjzondervan Sep 8, 2026
0d4c3a9
build(deps): bump web-token/jwt-library from 4.2.1 to 4.2.2 (#664)
dependabot[bot] Sep 9, 2026
3b406ce
build(deps-dev): bump conduction/hydra-gates from 1.16.0 to 1.16.1 (#…
dependabot[bot] Sep 9, 2026
c1cac29
build(deps-dev): bump phpstan/phpstan from 2.2.10 to 2.2.13 (#662)
dependabot[bot] Sep 9, 2026
a8d1d6c
fix(team-folders): address review on the member picker
SudoThijn Sep 9, 2026
869afae
Merge pull request #655 from ConductionNL/feat/pre-stable-wire-deprec…
rjzondervan Sep 9, 2026
9d8d0ac
Merge pull request #667 from ConductionNL/feature/changes
SudoThijn Sep 9, 2026
582e3d8
chore(release): 0.3.2-unstable.20260910105221 (#672)
rubenvdlinde Sep 10, 2026
8156ee7
docs: correct an inverted numeric-key example and a stale test docblo…
rjzondervan Sep 12, 2026
2b140e1
fix(encryption-suites): scope suite self-service ops to the owner (#6…
rjzondervan Sep 12, 2026
af77222
ci: run the fast tier on pull requests (path filter, one PHPUnit leg)…
rubenvdlinde Sep 12, 2026
cb821d8
chore(sync): carry beta back into development
github-actions[bot] Sep 12, 2026
d813683
Merge pull request #686 from ConductionNL/sync/beta-to-development-20…
rubenvdlinde Sep 12, 2026
0ad3cb6
feat(e2e): refuse the shared instance unless the run names it (#689)
rubenvdlinde Sep 12, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
64 changes: 29 additions & 35 deletions .github/workflows/code-quality.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,10 +13,6 @@ on:
# nothing ran; and `feat/**` was uncovered in openregister, because the
# list said `feature/**`.
#
# The comment that stood here said adding prefixes was not the durable fix,
# and that the durable fix was to let the pull_request trigger gate it.
# THIS IS THAT CHANGE.
#
# What forced it now: a push to a branch with an open PR ran the SAME 34
# jobs TWICE on the same commit. `concurrency` cannot dedupe them — the
# group is suffixed by event name deliberately (.github#540: a
Expand Down Expand Up @@ -46,32 +42,6 @@ on:
branches: [main, master, development, beta]
workflow_dispatch:

# Deduplicating a `push` run against the `pull_request` run for the SAME head
# ref is the point of this block, and for a feature branch it is exactly right:
# two runs of identical jobs, one of them wasted.
#
# It is wrong for `main` and `development`, because the push run there is NOT a
# duplicate — it is the only carrier of the push-only jobs: "Coverage Baseline
# Check" (`github.event_name == 'push'`), "SBOM" and "Features Extract". And
# those two branches always have an open PR whose `head_ref` IS the branch
# name: the standing "Release: merge development into beta" (#126 here).
# `github.head_ref` on that PR run and `github.ref_name` on the push run both
# render the identical group `quality-development`, and `cancel-in-progress`
# then kills whichever started first — normally the push run.
#
# HONEST SCOPE OF THE EVIDENCE HERE: unlike most of the fleet, this repo shows
# NO concurrency-cancelled `development` push run in its last 20 (its two
# cancellations are the shared workflow's 45-minute cap, not this block), and
# its push-only jobs demonstrably DO execute — run 31035521461 and 31030407282
# both report Coverage Baseline Check success. So this change is PREVENTIVE,
# not a repair of an observed outage: the collision is latent in the expression
# and has simply not won the race here yet. It is applied for fleet uniformity
# with openconnector#1158, where the same expression cancelled 15 of the last
# 20 push runs.
#
# Suffixing only the default-branch push keeps feature-branch dedup untouched
# (`quality-feature/x` for both events, exactly as before) and gives the two
# default branches' push runs a lane of their own.
concurrency:
# SUFFIXED BY EVENT NAME, not just by `-push`.
#
Expand All @@ -92,11 +62,8 @@ concurrency:
# cancelled and report neither pass nor fail — and a routine that produces
# no verdict is indistinguishable from one that never ran.
#
# This is hermiq's form, already live there. Pull requests keep the bare
# group (so a PR still supersedes its own earlier run); push, dispatch and
# schedule each get their own lane.
#
# THE BRANCH RESTRICTION IS GONE, because it contradicted the sentence above.
# Pull requests keep the bare group (so a PR still supersedes its own
# earlier run); push, dispatch and schedule each get their own lane.
#
# The suffix used to apply only when `ref_name` was `main` or `development`,
# so on every OTHER branch push and pull_request computed the SAME group —
Expand Down Expand Up @@ -143,6 +110,8 @@ permissions:

jobs:
quality:
# Skips the standing "development → beta" sync PR, which would otherwise
# re-run the whole pipeline on every merge into development.
if: (github.event_name != 'pull_request' || github.head_ref != 'development')
uses: ConductionNL/.github/.github/workflows/quality.yml@main
with:
Expand Down Expand Up @@ -206,6 +175,20 @@ jobs:
additional-apps: '[{"repo":"ConductionNL/openregister","app":"openregister","ref":"development"}]'
enable-sbom: true

# ── Licensing ────────────────────────────────────────────────────────
# REUSE findings fail the build. The shared workflow defaults this OFF
# because most fleet apps ship no REUSE.toml or LICENSES/ directory;
# keepiq ships both and lints at 1467/1467, 0 missing, 0 unused,
# compliant with version 3.3 of the REUSE specification.
#
# The blanket `path = "**"` annotation in REUSE.toml makes every new file
# compliant on arrival, whatever its type, so ordinary work cannot trip
# this. One regression mode remains — vendoring a file whose own SPDX
# header names a licence with no text in LICENSES/ — and non-blocking
# that surfaces only as REUSE ❌ in the Quality Report comment, which is
# easy to miss.
reuse-blocking: true

# ── E2E browser tests ────────────────────────────────────────────────
# `playwright-test-path` does double duty in the shared workflow:
# 1. it is the directory the "Validate Playwright tests exist" step
Expand Down Expand Up @@ -298,3 +281,14 @@ jobs:
# To hold this repo still for a specific reason, set the input explicitly
# and say why — it is still honoured. To roll back for everyone, revert on
# ConductionNL/.github main.
# ── Cost controls (see ConductionNL/.github#596, #599) ───────────────
# Run PHPUnit and Playwright only when the diff could change their
# verdict. Fails safe TOWARDS running: an unreadable diff, a force-push,
# a branch creation or a dispatch all run everything, and a filtered
# skip is a declared state in the Quality Report, not a missing one.
enable-path-filtering: true
# PR-time PHPUnit runs the primary PHP against the newest declared
# Nextcloud; the full matrix still runs on every push to a default
# branch and on the release PR into beta. Breadth moves from
# per-commit to per-merge, it is not dropped.
reduce-pr-matrix: true
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -122,6 +122,9 @@ openspec/test-site-results/**/*.webp
docs/node_modules/
docs/build/

RESTYLE-PLAN.md
screens/

# Agent/test scratch and tool caches — generated, never source.
# Added by the 2026-08-25 fleet hygiene sweep (ADR-100 Decision 2).
.stale/
Expand Down
2 changes: 2 additions & 0 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -268,3 +268,5 @@ Add labels to categorize your PR in the automated changelog:
## License

By contributing, you agree that your contributions will be licensed under the same license as the project (EUPL-1.2 unless stated otherwise).

Licensing is declared repo-wide in `REUSE.toml`, so a new file needs no SPDX header to be compliant; if you add one, it wins over the blanket. Vendoring a file that carries someone else's licence header additionally requires that licence's text in `LICENSES/<SPDX-id>.txt` — otherwise `quality / REUSE compliance` fails the build.
Loading
Loading