Skip to content

docs(openspec): OpenSpec pass batch 3, contracts, insight, operations, organisations, security and sharing changes - #1121

Merged
rubenvdlinde merged 22 commits into
developmentfrom
parity/openspec-pass-3
Sep 27, 2026
Merged

rubenvdlinde merged 22 commits into
developmentfrom
parity/openspec-pass-3

Conversation

@rubenvdlinde

Copy link
Copy Markdown
Contributor

OpenSpec pass for stackiq, batch 3 of 3: 13 changes for contracts, insight, operations, organisations, security and sharing, 22 matrix rows. Specs only, nothing is implemented. The decisions for every row, the reading of the rule and the defects found are in batch 1 (#1094); this batch adds its build rows to openspec/parity/gap-decisions.json and sets them to specified in the matrix.

Changes in this batch

  • contracts-expiry-and-owner: ctr-status, ctr-contract-owner
  • contracts-licence-seats: ctr-seat-count, ctr-licence-model
  • insight-exports-and-custom-reports: ins-export-list, share-export, ins-custom-report
  • insight-supplier-facet: ins-faceted-search
  • insight-knowledge-base: ins-kb
  • operations-sync-status-and-progress: ins-progress, ops-scheduled-sync
  • operations-technology-components: ops-hardware-assets, ops-ci-relations, life-tech-obsolescence
  • operations-record-reconciliation: ops-reconciliation, land-duplicate-merge
  • organisations-role-mapping-and-access-review: org-roles, org-access-review
  • security-baseline-classification: sec-baseline-classification
  • sharing-generated-api-docs: share-api-docs
  • sharing-compliance-documents: share-compliance-documents
  • sharing-itsm-exchange: share-itsm-integration

Rows below the bar that ride with a build row of the same change: ctr-licence-model (with ctr-seat-count), life-tech-obsolescence (with ops-hardware-assets), land-duplicate-merge (with ops-reconciliation).

Matrix edits in this batch

  • 22 rows set to specified, each note naming its change directory. gap-decisions.json gains their 22 build entries and now holds all 125 decisions.

Defects found while reading the code

Written into the change that touches each, not filed as issues:

  • The catalogContract lifecycle names Dutch states no row holds (lib/Settings/softwarecatalogus_register.json:3531); contracts-expiry-and-owner moves it onto the enum values.
  • SettingsService::getOrganizationAdminGroups() always returns an empty list (lib/Service/SettingsService.php:2105-2110), so every "organisation admin" check falls back to Nextcloud admins only.
  • OpenRegister's Schema has no exportable field and hydrate() drops the key (openregister lib/Db/Schema.php:1972-1977), so the library's Export menu can never render; that half is OpenRegister's.
  • ProgressTracker keeps progress in the PHP session, so a background job or another request never sees it; the organisation sync job ignores the admin enable switch (OrganizationContactSyncJob::run() does not read cronjob_config.enabled).
  • The organisation merge misses module.provider, catalogService.provider, usage.provider, organization.deelnames, organization.participants and model.organizations (lib/Service/MergeOrganisatieService.php:111).
  • Role groups never get assigned: getRoleGroupByOrganizationType() keys on Dutch organisation types (ContactPersonHandler.php:1624) and updateRoleBasedGroups() compares capitalised roles with lower-case group names (GroupHandler.php:286).
  • x-openregister-dedup on module is wired in OpenRegister (its /duplicates page) but nothing in stackiq links to it.

Sibling halves named in the changes

  • OpenRegister: keep and serve the schema exportable flag; relink every reference inside a merge; accept register and schema in the /duplicates URL.
  • nextcloud-vue: forward the page filter and quick filter to the export; read x-openregister-dependent-values in CnFormDialog (from batch 1).
  • integriq: service desk source templates for TOPdesk, ServiceNow and GLPI.

Correction to batch 1

landscape-move-between-organisations and landscape-owner-attestation guarded their endpoints on SettingsService::getOrganizationAdminGroups(), which helper B found returns an empty list. Both designs now use the maintainer rule of OrganisationMembersController::authorizeMaintainer() (lib/Controller/OrganisationMembersController.php:207) instead.

Checks

  • openspec validate: every change of this batch is valid with --strict. openspec validate --changes: 53 passed, 3 failed (the three failures are the pre-existing adopt-apphost, beta-surface-alignment and rename-app-id-to-stackiq).
  • parity_verify.py --strict: only the unknown-cells census (469 cells, as after batch 1), no other finding, no schema error.
  • composer check:strict (private HOME and TMPDIR): exit 0 (lint, phpcs, phpmd, psalm and phpstan pass; test:all prints SKIPPED because it needs a Nextcloud server tree).
  • npm run lint: exit 0 (217 warnings, 0 errors, none in files this PR touches).
  • No em-dash, en-dash or double dash in any file of this batch.
  • The PR touches only openspec/: its change directories, openspec/parity/capabilities.json and openspec/parity/gap-decisions.json.

🤖 Generated with Claude Code

… last run and a sync page for functional administrators
…logy with runs-on relations and end of support
…oups from chosen groups and an access review page
…rity and confidentiality per application in use
…aintainer rule, not the empty admin-group list
@rubenvdlinde
rubenvdlinde merged commit a0afae7 into development Sep 27, 2026
36 of 37 checks passed
@github-actions

Copy link
Copy Markdown
Contributor

Quality Report — ConductionNL/stackiq @ 90600cd

Check PHP Vue Security License Tests
lint ✅
phpcs ✅
phpmd ✅
psalm ✅
phpstan ✅
phpmetrics ✅
eslint ✅
stylelint ✅
build ✅
check-manifest ✅
check-vue-demi ✅
test-l10n ✅
format ✅
check-schema-l10n ✅
check-l10n-js ✅
composer ✅ ✅ 130/130
npm ✅ ✅ 807/807
app:check-code ⏭️
info.xml ✅
REUSE ❌
lockfile sync ✅
PHPUnit ⏭️ not run for this diff — no file in this diff matches the code globs, and none carries a source extension — the heavy tier has nothing to decide about it.
Newman ⏭️
Playwright ⏭️ deferred: E2E runs locally and on the promotion path only. This pull request targets development, so the suite is asked once per promotion into beta and main rather than once per push per open pull request. Run it on any branch from the Actions tab, or locally with npx playwright test.
Hydra gates ❌

Quality workflow — 2026-09-27 18:38 UTC

Download the full PDF report from the workflow artifacts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant