docs(openspec): OpenSpec pass batch 3, contracts, insight, operations, organisations, security and sharing changes - #1121
Merged
Conversation
…responsible user per contract
… in a register fragment
…ght against in use
… organisation export and custom reports
…applications and services
…d to applications
… last run and a sync page for functional administrators
…ts read in the app
…logy with runs-on relations and end of support
…and merge for applications and services
…oups from chosen groups and an access review page
…roup note with the role mapping change
…rity and confidentiality per application in use
…nto parity/openspec-pass-3
…o parity/openspec-pass-3
…aintainer rule, not the empty admin-group list
Contributor
Quality Report — ConductionNL/stackiq @
|
| Check | PHP | Vue | Security | License | Tests |
|---|---|---|---|---|---|
| lint | ✅ | ||||
| phpcs | ✅ | ||||
| phpmd | ✅ | ||||
| psalm | ✅ | ||||
| phpstan | ✅ | ||||
| phpmetrics | ✅ | ||||
| eslint | ✅ | ||||
| stylelint | ✅ | ||||
| build | ✅ | ||||
| check-manifest | ✅ | ||||
| check-vue-demi | ✅ | ||||
| test-l10n | ✅ | ||||
| format | ✅ | ||||
| check-schema-l10n | ✅ | ||||
| check-l10n-js | ✅ | ||||
| composer | ✅ | ✅ 130/130 | |||
| npm | ✅ | ✅ 807/807 | |||
| app:check-code | ⏭️ | ||||
| info.xml | ✅ | ||||
| REUSE | ❌ | ||||
| lockfile sync | ✅ | ||||
| PHPUnit | ⏭️ not run for this diff — no file in this diff matches the code globs, and none carries a source extension — the heavy tier has nothing to decide about it. | ||||
| Newman | ⏭️ | ||||
| Playwright | ⏭️ deferred: E2E runs locally and on the promotion path only. This pull request targets development, so the suite is asked once per promotion into beta and main rather than once per push per open pull request. Run it on any branch from the Actions tab, or locally with npx playwright test. |
||||
| Hydra gates | ❌ |
Quality workflow — 2026-09-27 18:38 UTC
Download the full PDF report from the workflow artifacts.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
OpenSpec pass for stackiq, batch 3 of 3: 13 changes for contracts, insight, operations, organisations, security and sharing, 22 matrix rows. Specs only, nothing is implemented. The decisions for every row, the reading of the rule and the defects found are in batch 1 (#1094); this batch adds its build rows to
openspec/parity/gap-decisions.jsonand sets them tospecifiedin the matrix.Changes in this batch
contracts-expiry-and-owner:ctr-status,ctr-contract-ownercontracts-licence-seats:ctr-seat-count,ctr-licence-modelinsight-exports-and-custom-reports:ins-export-list,share-export,ins-custom-reportinsight-supplier-facet:ins-faceted-searchinsight-knowledge-base:ins-kboperations-sync-status-and-progress:ins-progress,ops-scheduled-syncoperations-technology-components:ops-hardware-assets,ops-ci-relations,life-tech-obsolescenceoperations-record-reconciliation:ops-reconciliation,land-duplicate-mergeorganisations-role-mapping-and-access-review:org-roles,org-access-reviewsecurity-baseline-classification:sec-baseline-classificationsharing-generated-api-docs:share-api-docssharing-compliance-documents:share-compliance-documentssharing-itsm-exchange:share-itsm-integrationRows below the bar that ride with a build row of the same change:
ctr-licence-model(withctr-seat-count),life-tech-obsolescence(withops-hardware-assets),land-duplicate-merge(withops-reconciliation).Matrix edits in this batch
specified, each note naming its change directory.gap-decisions.jsongains their 22 build entries and now holds all 125 decisions.Defects found while reading the code
Written into the change that touches each, not filed as issues:
catalogContractlifecycle names Dutch states no row holds (lib/Settings/softwarecatalogus_register.json:3531);contracts-expiry-and-ownermoves it onto the enum values.SettingsService::getOrganizationAdminGroups()always returns an empty list (lib/Service/SettingsService.php:2105-2110), so every "organisation admin" check falls back to Nextcloud admins only.Schemahas noexportablefield andhydrate()drops the key (openregisterlib/Db/Schema.php:1972-1977), so the library's Export menu can never render; that half is OpenRegister's.ProgressTrackerkeeps progress in the PHP session, so a background job or another request never sees it; the organisation sync job ignores the admin enable switch (OrganizationContactSyncJob::run()does not readcronjob_config.enabled).module.provider,catalogService.provider,usage.provider,organization.deelnames,organization.participantsandmodel.organizations(lib/Service/MergeOrganisatieService.php:111).getRoleGroupByOrganizationType()keys on Dutch organisation types (ContactPersonHandler.php:1624) andupdateRoleBasedGroups()compares capitalised roles with lower-case group names (GroupHandler.php:286).x-openregister-deduponmoduleis wired in OpenRegister (its/duplicatespage) but nothing in stackiq links to it.Sibling halves named in the changes
exportableflag; relink every reference inside a merge; accept register and schema in the/duplicatesURL.x-openregister-dependent-valuesinCnFormDialog(from batch 1).Correction to batch 1
landscape-move-between-organisationsandlandscape-owner-attestationguarded their endpoints onSettingsService::getOrganizationAdminGroups(), which helper B found returns an empty list. Both designs now use the maintainer rule ofOrganisationMembersController::authorizeMaintainer()(lib/Controller/OrganisationMembersController.php:207) instead.Checks
openspec validate: every change of this batch is valid with--strict.openspec validate --changes: 53 passed, 3 failed (the three failures are the pre-existingadopt-apphost,beta-surface-alignmentandrename-app-id-to-stackiq).parity_verify.py --strict: only the unknown-cells census (469 cells, as after batch 1), no other finding, no schema error.composer check:strict(private HOME and TMPDIR): exit 0 (lint, phpcs, phpmd, psalm and phpstan pass;test:allprints SKIPPED because it needs a Nextcloud server tree).npm run lint: exit 0 (217 warnings, 0 errors, none in files this PR touches).openspec/: its change directories,openspec/parity/capabilities.jsonandopenspec/parity/gap-decisions.json.🤖 Generated with Claude Code