Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
159 commits
Select commit Hold shift + click to select a range
595e0b4
chore(release): sync main back into development
github-actions[bot] Sep 12, 2026
da4216f
chore(release): 0.4.7-unstable.20260912204215
github-actions[bot] Sep 12, 2026
29139a5
Merge pull request #1982 from ConductionNL/release/v0.4.7-unstable.20…
rubenvdlinde Sep 13, 2026
43c24a0
Merge pull request #1975 from ConductionNL/sync/main-to-development-0…
rubenvdlinde Sep 13, 2026
c5b1d93
spec(openspec): vendor document generation adapter, gap register row …
rubenvdlinde Sep 13, 2026
a31a880
chore(sync): carry beta back into development
github-actions[bot] Sep 13, 2026
7b14bdd
Merge pull request #1989 from ConductionNL/sync/beta-to-development-2…
rubenvdlinde Sep 13, 2026
634e724
spec(openspec): the two integriq gaps the regenerated register still …
rubenvdlinde Sep 13, 2026
08a120d
docs(openspec): index the competitor parity changes under one umbrell…
rubenvdlinde Sep 13, 2026
3d222e8
feat(connections): a connection registry every app can show (#1996)
rubenvdlinde Sep 14, 2026
98b140c
docs(openspec): a registry-backed field is a small type plus a declar…
rubenvdlinde Sep 14, 2026
aad5ac5
docs(openspec): wave 3, five integriq clusters plus the migration sou…
rubenvdlinde Sep 14, 2026
605a877
feat(connections): the registry reads provider names, trusts reported…
rubenvdlinde Sep 14, 2026
b08e6c4
docs(openspec): open the outbound sender identity cluster and index i…
rubenvdlinde Sep 14, 2026
d570132
spec(parity): the pending-proposal half, rows 5.19 and 6.23 open, 6.2…
rubenvdlinde Sep 14, 2026
0f50e2b
feat(directory): a directory connection that keeps Nextcloud groups i…
rubenvdlinde Sep 14, 2026
69cdd3a
docs: retire the last two dead Codeberg issue URLs in archived opensp…
rubenvdlinde Sep 14, 2026
c8e4d83
feat(connections): a settings refresh retires older observations (#2020)
rubenvdlinde Sep 14, 2026
a936658
feat(connections): requiredConfig reads false as empty and can look i…
rubenvdlinde Sep 14, 2026
64b437f
feat(connections): a switched-off connection reads disabled, and an e…
rubenvdlinde Sep 15, 2026
8d3e0e8
fix(deps): lift symfony/cache past the ext-redis conflict that blocks…
WilcoLouwerse Sep 15, 2026
2dbc441
style: format the files the connection registry wave merged unformatt…
rubenvdlinde Sep 16, 2026
b236aa8
fix(e2e): directory-sync runs pass the CSRF check and find their row …
rubenvdlinde Sep 16, 2026
ccaf7db
fix(connections): read connection rows unscoped, so webcron stops wri…
rubenvdlinde Sep 16, 2026
f766b87
fix(e2e): the directory connections read sends OCS-APIRequest too (#2…
rubenvdlinde Sep 16, 2026
e38a076
chore(deps): Nextcloud 35 support (max-version 34 -> 35)
rjzondervan Sep 17, 2026
9c8e3f2
Merge remote-tracking branch 'origin/development' into fix/composer-l…
WilcoLouwerse Sep 17, 2026
778e220
Merge pull request #2040 from ConductionNL/fix/composer-lock-ext-redi…
WilcoLouwerse Sep 17, 2026
4432053
feat(property-source): resolve a field from a registry, with the prov…
rubenvdlinde Sep 18, 2026
e8e127f
feat(mail-intake): a mailbox is a source and a message is offered to …
rubenvdlinde Sep 18, 2026
9866e81
feat(registry-subscriptions): follow a person or a company at the reg…
rubenvdlinde Sep 18, 2026
20ef2c9
feat(ownership): say who owns a record, and what happens when the sou…
rubenvdlinde Sep 18, 2026
e6d5ed3
feat(intake): a channel is an adapter with a routing rule, not a rele…
rubenvdlinde Sep 18, 2026
9713f18
feat(migration): read an incumbent or a delivered file, and write not…
rubenvdlinde Sep 18, 2026
f99b5ea
feat(outbound): the log of what was sent, per recipient and per step …
rubenvdlinde Sep 18, 2026
1e31789
feat(gateways): say which laws this instance reaches, and where data …
rubenvdlinde Sep 18, 2026
d64e703
feat(outbound-identity): an identity is the face on an account Nextcl…
rubenvdlinde Sep 18, 2026
024e8a5
feat(call-log): a call is a record, a replay is an attempt, a dry run…
rubenvdlinde Sep 18, 2026
5bce690
ci(matrix): derive the Nextcloud test matrix from info.xml
rjzondervan Sep 18, 2026
86eaea9
test(appinfo): inject the container type the server declares
rjzondervan Sep 18, 2026
49b22ec
Merge remote-tracking branch 'origin/development' into feature/integr…
rjzondervan Sep 18, 2026
4b43807
feat(events): bound the CloudEvent loop, and recognise our own rows w…
rubenvdlinde Sep 18, 2026
010a6b2
feat(events): let a subscription actually be saved with the flow kind…
rubenvdlinde Sep 18, 2026
b259044
test(ownership): cover the engine's refusal of a policy it does not k…
rubenvdlinde Sep 18, 2026
f0d4463
feat(expression): a prefixed value source, and an env allowlist that …
rubenvdlinde Sep 18, 2026
8f03c0e
feat(registry): bind the subscription request to the handler that ful…
rubenvdlinde Sep 18, 2026
3db280a
feat(cti): the telephony seam, and a caller number this never guesses…
rubenvdlinde Sep 18, 2026
fe1704f
feat(zgw): the six packaged consumer sets, and the bindings the insta…
rubenvdlinde Sep 18, 2026
91dc487
feat(recipients): who was kept off a message, and why the record says…
rubenvdlinde Sep 18, 2026
c9a57e2
feat(webhooks): a push subscription signs unless somebody says otherw…
rubenvdlinde Sep 18, 2026
fdb7f18
feat(objecten): the declared mapping, the token matrix and the leak g…
rubenvdlinde Sep 18, 2026
c836108
feat(objecten): serve the routes — six read, four write (#2077)
rubenvdlinde Sep 18, 2026
626d8da
feat(digital-post): one seam for digital post, and a flag that refuse…
rubenvdlinde Sep 18, 2026
82bfbe6
feat(cti): the endpoint, and a caller lookup that refuses what it can…
rubenvdlinde Sep 18, 2026
1fbcdbd
fix(system-writes): stop falling through to a bare call, and find the…
rubenvdlinde Sep 18, 2026
472b072
feat(document generation): the SmartDocuments and Xential seam, behin…
rubenvdlinde Sep 18, 2026
88c78dd
merge development into parity/round2
rubenvdlinde Sep 18, 2026
6eca2b8
fix(quality): put the two digital post jobs back on the schedule, and…
rubenvdlinde Sep 18, 2026
4bb26b8
fix(quality): a ceiling on the public objecten routes, a contract tes…
rubenvdlinde Sep 18, 2026
d1ad45b
fix(quality): answer phpmd on the lines this branch wrote, with a rea…
rubenvdlinde Sep 18, 2026
cac78dc
fix(quality): delete a branch that could never run, and an injected c…
rubenvdlinde Sep 18, 2026
c13a20c
docs(openspec): a Teams message opens a case, over the channel contra…
rubenvdlinde Sep 18, 2026
c8c4801
style(e2e): prettier the one spec file this branch added
rubenvdlinde Sep 18, 2026
e4e9fda
feat(l10n): the document generation job speaks Dutch, and its title s…
rubenvdlinde Sep 18, 2026
f74f549
fix(migration): a delivery path that names a folder says so
rubenvdlinde Sep 18, 2026
9d2b6ea
fix(digital-post): attach the message schema to the register it is wr…
rubenvdlinde Sep 18, 2026
f0b77f0
Merge pull request #2083 from ConductionNL/parity/round2
rubenvdlinde Sep 19, 2026
e8a2dea
fix(routes): two entries shared a route name, so two routes never reg…
rubenvdlinde Sep 19, 2026
5544808
style(tests): run prettier over the specs that fail format
rjzondervan Sep 19, 2026
03e5fb4
fix(lib): three narrowing and error-handling fixes phpstan refused
rjzondervan Sep 19, 2026
8032222
chore(quality): baseline the debt the feature merges brought with them
rjzondervan Sep 19, 2026
a7f43af
feat(l10n): give the backend catalogue the keys the schemas need
rjzondervan Sep 19, 2026
d3a41f5
fix(quality): psalm and phpstan read two OpenRegister runtime types a…
rubenvdlinde Sep 19, 2026
70ede26
style(lib): replace the elvis operators the standard refuses
rjzondervan Sep 19, 2026
c29c122
fix(l10n): four source strings were never added to the catalogue
rubenvdlinde Sep 19, 2026
e32e4f2
chore(format): prettier was never run over eighteen frontend files
rubenvdlinde Sep 19, 2026
215ba41
style(lib): convert the first 37 inline ifs to statements
rjzondervan Sep 19, 2026
040f549
Merge pull request #2087 from ConductionNL/fix/psalm-phpstan-inherited
rubenvdlinde Sep 19, 2026
3646591
Merge pull request #2088 from ConductionNL/fix/l10n-missing-source-st…
rubenvdlinde Sep 19, 2026
cd55d2d
Merge pull request #2089 from ConductionNL/chore/prettier-format
rubenvdlinde Sep 19, 2026
86211f1
style(lib): hoist another 26 inline ifs out of arguments and array va…
rjzondervan Sep 19, 2026
7f26508
style(lib): clear the last inline ifs
rjzondervan Sep 19, 2026
12ac22a
fix(icons): seven icons rendered as nothing at all
rubenvdlinde Sep 19, 2026
deb86cf
style(lib): name the arguments in 296 internal calls
rjzondervan Sep 19, 2026
70d359d
fix(sync): a record the source carried again stayed flagged as gone
rubenvdlinde Sep 19, 2026
48f9bb4
Merge pull request #2091 from ConductionNL/fix/hydra-gate-60-icons
rubenvdlinde Sep 19, 2026
e506a77
style(lib): name the last 41 arguments — phpcs is clean
rjzondervan Sep 19, 2026
38b8a7a
Merge remote-tracking branch 'origin/development' into feature/integr…
rjzondervan Sep 19, 2026
002900d
test(outbound): the alignment endpoint shipped with no contract test
rubenvdlinde Sep 19, 2026
ac1997c
Merge pull request #2092 from ConductionNL/fix/hydra-gate-57-record-c…
rubenvdlinde Sep 19, 2026
a46558a
style(lib): re-clear the gates the development merge reopened
rjzondervan Sep 19, 2026
50de109
Merge pull request #2094 from ConductionNL/test/gate-25-alignment-con…
rubenvdlinde Sep 19, 2026
775d6c5
fix(quality): my own phpmd findings fixed, the merged ones baselined
rjzondervan Sep 19, 2026
29fd89a
fix(migration): any signed-in account could read an incumbent system
rubenvdlinde Sep 19, 2026
d072f2b
fix(types): correct two types my own refactors got wrong
rjzondervan Sep 19, 2026
e88268a
Merge pull request #2097 from ConductionNL/fix/hydra-gate-7-migration…
rubenvdlinde Sep 19, 2026
fe15ed1
chore(release): 0.4.8-unstable.20260919141023
github-actions[bot] Sep 19, 2026
51aab9f
fix(security): scope two unguarded reads, and account for the other five
rjzondervan Sep 19, 2026
10c7abb
fix(quality): close gate-25, gate-106 and gate-16
rjzondervan Sep 19, 2026
d7fa287
Merge remote-tracking branch 'origin/development' into feature/integr…
rjzondervan Sep 19, 2026
f131874
refactor(migration): lift the uid resolution out of readFile()
rjzondervan Sep 19, 2026
96e76d7
Merge pull request #2098 from ConductionNL/release/v0.4.8-unstable.20…
rubenvdlinde Sep 19, 2026
0684e2c
fix(manifest): point the mail-intake widget at the renamed schema
rjzondervan Sep 19, 2026
5282982
test(manifest): follow the schema rename into the frontend spec
rjzondervan Sep 19, 2026
bc3336b
style(tests): reflow the line the schema rename made too long
rjzondervan Sep 19, 2026
8fbbd6f
chore(demo-data): regenerate the mock register so every schema has sa…
rjzondervan Sep 19, 2026
2d25638
fix(demo-data): keep the schemas block the register validator requires
rjzondervan Sep 19, 2026
658cafe
Merge pull request #2065 from ConductionNL/feature/integriq-nc35-support
rjzondervan Sep 19, 2026
ec95b1a
docs(outbound): spec enrolling sender_identity in the credential broker
rjzondervan Sep 20, 2026
5463865
docs(outbound): mint the S/MIME key under generic-apikey for now
rjzondervan Sep 20, 2026
65f6023
docs(outbound): keep the certificate literal; file the multi-field gap
rjzondervan Sep 20, 2026
e5f41c3
docs(outbound): link the four brokered-credential gap issues
rjzondervan Sep 20, 2026
212eb1c
feat(outbound): hold the S/MIME signing key in the credential broker
rjzondervan Sep 20, 2026
507d405
feat(outbound): migrate the S/MIME key into the broker, and refuse PE…
rjzondervan Sep 20, 2026
857e37c
fix(mail): close the nine world-readable mail schemas
rjzondervan Sep 20, 2026
16dc6ce
fix(directory): refuse SCIM writes to admin and to unmanaged groups
rjzondervan Sep 20, 2026
bd3e313
fix(l10n): cover the new schema strings, and capitalise two comments
rjzondervan Sep 20, 2026
651eb55
docs(mail): point the lockdown at its follow-up issue
rjzondervan Sep 20, 2026
1314e32
fix(outbound): write-only stripping is a render rule, not an RBAC one
rjzondervan Sep 21, 2026
3d3e1ed
fix(security): a real migration run reaches every schema, not just so…
rjzondervan Sep 21, 2026
dcb3539
fix(directory): guard the SCIM user routes, and cap the page size
rjzondervan Sep 21, 2026
a1f94d7
fix(spec): REQ-OSI-012 says what shipped, and now has the tests it cl…
rjzondervan Sep 21, 2026
3d84f77
fix(directory): scope the admin refusal honestly, and ratchet schema …
rjzondervan Sep 21, 2026
231bb6c
fix(quality): close the three CI checks my review fixes broke
rjzondervan Sep 21, 2026
95cce12
fix(directory): clamp SCIM paging on both routes, and make the PEM te…
rjzondervan Sep 21, 2026
6021550
refactor(security): close the three minors from the re-review
rjzondervan Sep 21, 2026
a32af47
fix(l10n): sentence case for the S/MIME field titles, per ADR-007
rjzondervan Sep 21, 2026
2f4a1ae
test(directory): cover the per-schema table, and align the two list r…
rjzondervan Sep 21, 2026
095fbfe
docs(directory): the /Groups membership read is an authorization ques…
rjzondervan Sep 22, 2026
2c2ee64
fix(directory): validate SCIM `count` instead of coercing it silently
rjzondervan Sep 22, 2026
f370f87
Merge pull request #2104 from ConductionNL/fix/integriq-1983-review-f…
rjzondervan Sep 22, 2026
4cfd03f
fix(di): bind DnsResolverInterface and CallDispatcherInterface
rjzondervan Sep 22, 2026
80d6999
fix(records): correct a false IDOR exemption, and land three minors t…
rjzondervan Sep 22, 2026
cc989dd
fix(appinfo): RenameDutchColumns was registered twice
rjzondervan Sep 22, 2026
cdbbf5d
fix(property-sources): gate the registry lookups admin-only by default
rjzondervan Sep 22, 2026
eed289d
docs(appinfo): record the NC35 / OpenRegister channel pairing as a de…
rjzondervan Sep 22, 2026
7ced8f3
style(actions): restore actions.seed.json formatting, keep only the t…
rjzondervan Sep 22, 2026
ccea98d
Revert "fix(property-sources): gate the registry lookups admin-only b…
rjzondervan Sep 22, 2026
5724a83
docs(sources): the convention for connectors that return personal data
rjzondervan Sep 22, 2026
5a07583
feat(webhooks): read the Microsoft Teams signature scheme on inbound …
rubenvdlinde Sep 22, 2026
35bca0c
feat(intake): a Microsoft Teams message opens or joins a case
rubenvdlinde Sep 22, 2026
c87912e
test(di): execute register() so the two new bindings are covered, not…
rjzondervan Sep 22, 2026
9d93c7b
refactor(intake): split the two methods phpmd flagged, and move the b…
rubenvdlinde Sep 22, 2026
a1a5611
Merge pull request #2128 from ConductionNL/feat/teams-messages-open-c…
rubenvdlinde Sep 22, 2026
d640e27
feat(events): a matched CloudEvent can go to a message broker
rubenvdlinde Sep 22, 2026
fc93c24
refactor(events,broker): split the two methods phpmd flagged, and bas…
rubenvdlinde Sep 22, 2026
8a392b7
Merge pull request #2130 from ConductionNL/feat/event-broker-transport
rubenvdlinde Sep 22, 2026
c60bd7d
feat(auth): the government identity broker, minus the vendor half
rubenvdlinde Sep 22, 2026
2f8c37b
fix(auth): use named arguments for the parent controller constructor,…
rubenvdlinde Sep 22, 2026
7fe3352
Merge pull request #2132 from ConductionNL/feat/idp-broker-envelope-r…
rubenvdlinde Sep 22, 2026
2db487a
fix(events): give the broker schema strings a catalogue key, and form…
rubenvdlinde Sep 22, 2026
637c049
Merge pull request #2134 from ConductionNL/fix/broker-schema-l10n-cov…
rubenvdlinde Sep 22, 2026
e62d4d8
fix(docs,test): the authorization example granted nothing, and the sw…
rjzondervan Sep 23, 2026
9cd5755
Merge pull request #2127 from ConductionNL/fix/bind-app-owned-interfaces
rjzondervan Sep 23, 2026
ab13bfd
fix(intake): act on the bytes that were signed, and allow-list the Te…
rjzondervan Sep 23, 2026
bdedf31
test(intake): cover the new decode and trusted-host branches
rjzondervan Sep 23, 2026
85e5de8
Merge pull request #2137 from ConductionNL/fix/intake-signature-desyn…
rjzondervan Sep 23, 2026
de67807
fix(property-source): gate registry queries, exempting the public reg…
rjzondervan Sep 23, 2026
bd5e54f
Merge pull request #2143 from ConductionNL/fix/gate-sensitive-propert…
rjzondervan Sep 23, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
57 changes: 29 additions & 28 deletions .github/workflows/code-quality.yml
Original file line number Diff line number Diff line change
Expand Up @@ -161,34 +161,35 @@ jobs:
# need the matching runtime or `vendor/composer/platform_check.php` aborts
# with `Composer dependencies require a PHP version ">= 8.3.0"`.
php-version: "8.3"
# Set explicitly, because the shared workflow defaults to
# `["stable31", "stable32"]` and stable31 CANNOT WORK here. integriq
# declares <app>openregister</app> as a hard dependency, and openregister
# declares min-version="32". On NC31 the E2E job logs
# App "Open Register" cannot be installed because it is not compatible
# with this version of the server.
# then continues with a WARNING, so the run proceeds without its central
# dependency and fails ~70s later on missing tables — which reads like a
# migration fault rather than a missing app. Testing a version the app
# cannot support produces red that says nothing. See issue #1172.
#
# WHY THIS IS NOW stable34 AND NOT `["stable32", "stable33"]`. This PR
# moves the dev requirement to `nextcloud/ocp ^34`, so the stubs every
# static-analysis leg resolves against are NC34's. Running the suite
# against an older server would check the app under one set of API
# signatures and analyse it under another, and the two disagreeing is
# exactly the class of defect the analysers exist to find.
#
# ✅ THE NARROWING IS CLOSED, THE FIRST WAY. The previous revision of this
# comment recorded a deliberate trade: info.xml declared three server
# versions while the suite exercised one, leaving NC32 and NC33 unmeasured
# rather than known-broken. It named its own closure condition — "restoring
# the older refs alongside stable34 once ocp ^34 stubs are proven compatible
# with them" — and that condition is now met: portaliq runs stable32,
# stable33 and stable34 against `nextcloud/ocp ^34` and all six PHPUnit
# legs pass (run 31599055849). So the refs come back rather than info.xml's
# floor going up, and the two numbers agree again.
nextcloud-test-refs: '["stable34", "stable32", "stable33"]'
# NO `nextcloud-test-refs` HERE, DELIBERATELY. Unset, the shared workflow
# derives the PHPUnit matrix from appinfo/info.xml, so the tested range and
# the declared range cannot disagree.
#
# THIS BUMP IS WHY IT HAD TO GO. The list read
# `["stable34", "stable32", "stable33"]` while info.xml now declares NC
# 32-35 — gate-65 rule 11, NC 35 advertised to the App Store and exercised
# by nothing. Appending "stable35" would clear the gate for this PR and
# re-arm the same trap for NC 36; worse, it would arm it on `development`
# rather than here, because the gate fires on the manifest/matrix
# disagreement for EVERY later PR, not just the one that introduced it.
# openregister#3777 took the same decision for the same reason.
#
# WHAT THE OLD LIST WAS PROTECTING, AND WHY IT NO LONGER HAS TO. Its first
# entry mattered: E2E, newman and journeydoc-capture ran against
# `fromJSON(nextcloud-test-refs)[0]`, so stable34 had to lead to keep them
# off a server openregister cannot load — openregister declares
# min-version="32", and on NC31 the E2E job logged `App "Open Register"
# cannot be installed…`, continued with a WARNING, and failed ~70s later on
# missing tables (issue #1172). Those jobs now consume the workflow's
# `single-server` output — the numerically highest branch in the resolved
# set — so list order is inert and the floor is carried by info.xml's
# min-version="32" instead of by a hand-written array.
#
# THE stable35 LEG DEPENDS ON openregister. `additional-apps` below installs
# openregister from `development`, and the shared workflow aborts a job whose
# `occ app:enable` fails for an additional app. openregister#3777 (max-version
# 34 -> 35) is merged, so that leg can enable it; if openregister's declared
# ceiling ever lags this one again, this leg is where it will show.
# `hydra-gates-require-full-coverage: false` is REMOVED here, exactly as
# the comment it replaced instructed: "Remove this line in the change
# that wires those producers up, so the coverage requirement arrives with
Expand Down
98 changes: 82 additions & 16 deletions appinfo/info.xml
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@
- 📋 Pas bedrijfsregels toe op endpoint-verkeer en houd een audit trail per object bij

]]></description>
<version>0.4.6-unstable.20260912101736</version>
<version>0.4.8-unstable.20260919141023</version>
<licence>EUPL-1.2</licence>
<author mail="info@conduction.nl" homepage="https://www.conduction.nl/">Conduction</author>
<namespace>Integriq</namespace>
Expand Down Expand Up @@ -59,13 +59,45 @@
object — so the app cannot function there. Declaring 28 advertised a range
this app cannot deliver. See issue #1172.

max-version is 34, NOT 35, for the same "do not advertise a range you
cannot deliver" reason in the other direction: NC 35 does not exist —
there is no tag, no branch, and this app's own CI matrix has no leg past
stable33. The rest of the fleet declares 34; integriq was the only
repo claiming 35, so the claim was untested everywhere it mattered.
max-version is 35. The previous 34 was recorded here because "NC 35 does
not exist — there is no tag, no branch"; nextcloud/server now carries
stable35 and nextcloud/ocp has shipped v35.0.0, so that reason has
expired. This app's own surface was checked against the change rather
than assumed: of the eleven OCP classes removed in 35 (the OCP\Remote\*
family, AutoCompleteEvent, CacheInsertEvent, CacheUpdateEvent) integriq
references none, and the migration-signature break that NC 35 introduced
— ISchemaWrapper handing out OCP\DB\Schema\ITable where Doctrine's
Schema\Table used to be — cannot reach this app: it ships ONE migration
and that migration type-hints no table at all. The two symfony packages
NC 35 core ships and an app can collide with, console and
http-foundation, are already required at ^7.4 here, which is what
stable35's 3rdparty declares (^7.4.15).

THE CLAIM STILL DEPENDS ON openregister. min-version above is 32 because
openregister is a HARD dependency and declares 32; the same sentence
governs this end of the range. openregister declares max-version="34"
today, so on NC 35 it refuses to install and every integriq entity —
each one an OpenRegister object — has nowhere to live. This bump is
therefore correct about integriq and premature about the stack until
ConductionNL/openregister#3777 (max-version 34 -> 35) merges. Landing it
first would re-advertise a range this app cannot deliver, which is the
exact mistake the deleted paragraph above was written to record.

SEQUENCING, decided rather than assumed (integriq#1983 review
5278999788, @rjzondervan 2026-09-22): openregister#3777 has merged and
is on OpenRegister's `beta` and `development`, while its `main` is still
at 34. So an instance taking OpenRegister from the app store's stable
channel gets a combination that has not shipped together.

That is accepted because the channels are paired: integriq `beta` runs
against OpenRegister `beta`, and the promotion into `main` waits on
OpenRegister's. A beta channel is where an unshipped combination is
meant to be exercised. If that pairing ever changes — beta expected to
run against OpenRegister `main` — this bump becomes a blocker rather
than a sequencing note, so the assumption is written here rather than
held in someone's head.
-->
<nextcloud min-version="32" max-version="34"/>
<nextcloud min-version="32" max-version="35"/>
Comment thread
WilcoLouwerse marked this conversation as resolved.
</dependencies>

<background-jobs>
Expand All @@ -90,6 +122,31 @@
<job>OCA\Integriq\BackgroundJob\ApprovalTimeoutSweepJob</job>
<job>OCA\Integriq\BackgroundJob\IwmoIjwRetryJob</job>
<job>OCA\Integriq\BackgroundJob\StufZknRetryJob</job>
<!-- document-generation-vendor-adapter: every five minutes, ask the
vendor again about a render it has not settled. This is what keeps
`unreachable` a state rather than a dead end: a render nobody could
ask about is unfinished business, not a failure. -->
<job>OCA\Integriq\BackgroundJob\DocumentGenerationStatusJob</job>
<!-- directory-and-group-sync: hourly. A membership that ended in the
directory has to end here without anyone acting, which is the whole
difference between synchronising membership and authenticating
against a directory. -->
<job>OCA\Integriq\BackgroundJob\DirectorySyncJob</job>
<!-- connection-registry D7: hourly. Syncs declarations whose app
version moved, probes at most 25 linked sources, oldest first,
then resolves every connection row without an outbound call. -->
<job>OCA\Integriq\BackgroundJob\ConnectionHealthJob</job>
<!-- registry-subscription-connector: every fifteen minutes. Asks each
registry binding what changed about the identities it follows and
posts that to OpenRegister. Nothing about the changed record is
written here. -->
<job>OCA\Integriq\BackgroundJob\RegistrySubscriptionPollJob</job>
<!-- berichtenbox-digital-post-adapter: the status job asks the providers
what became of the letters they took, every ten minutes, and only
about letters still on their way. The inbound job offers what
arrived to the document intake inbox. -->
<job>OCA\Integriq\BackgroundJob\DigitalPostStatusJob</job>
<job>OCA\Integriq\BackgroundJob\DigitalPostInboundJob</job>
</background-jobs>

<!-- ⚠️ CHILD ORDER IS FIXED BY THE APP STORE SCHEMA, and it is NOT the order
Expand Down Expand Up @@ -209,6 +266,11 @@
keeps all five fields on purpose (see the step's docblock). -->
<step>OCA\Integriq\Repair\RemoveMigratedSourceSecretFields</step>
<step>OCA\Integriq\Repair\MaterializeCatalogItems</step>
<!-- connection-registry D5: every enabled app's
lib/Settings/connections.json becomes connection rows. After
InitializeRegister, so the app_connection schema exists. Idempotent
and never throws. -->
<step>OCA\Integriq\Repair\SyncConnectionDeclarations</step>
<!-- WRITTEN BUT NEVER REGISTERED until now, which meant it never
ran anywhere. gate-98 (repair-step-registration) found it.

Expand Down Expand Up @@ -262,15 +324,14 @@
same migration on demand. -->
<step>OCA\Integriq\Repair\MigrateFlowStepsToGraph</step>
<step>OCA\Integriq\Repair\RemoveRetiredCronJobs</step>
<!-- Written but never registered, so it had never run once: a class
that exists is not a class that runs. It moves openconnector
data out of the Dutch columns into the English ones, so every
instance that predates the column rename still holds its data
where nothing reads it.

post-migration only: a fresh install has no Dutch columns to
move, and the step is idempotent either way. -->
<step>OCA\Integriq\Repair\RenameDutchColumns</step>
<!-- RenameDutchColumns is NOT repeated here. It was registered twice
— once above, after InitializeRegister and MagicMapper where its
own comment reasons the placement out, and once here under a note
saying it had "never been registered", which the earlier entry
disproves. The duplicate ran the step twice per upgrade; it is
idempotent, so nothing broke, but the second registration's
stated reason was false and the placement above is the
deliberate one (integriq#1983 review 5278999788). -->
</post-migration>
<!-- ocon#1180. A FIRST install runs neither `postSchemaChange` nor the
`post-migration` steps above: `Installer::installAppLastSteps()` passes
Expand Down Expand Up @@ -369,6 +430,11 @@
<step>OCA\Integriq\Repair\InitializeActions</step>
<step>OCA\Integriq\Repair\MigrateLegacyStorage</step>
<step>OCA\Integriq\Repair\MaterializeCatalogItems</step>
<!-- connection-registry D5: every enabled app's
lib/Settings/connections.json becomes connection rows. After
InitializeRegister, so the app_connection schema exists. Idempotent
and never throws. -->
<step>OCA\Integriq\Repair\SyncConnectionDeclarations</step>
<!-- The three inline-secret steps are deliberately NOT here. A first
install has no sources, so they would have nothing to migrate,
and RemoveMigratedSourceSecretFields is IRREVERSIBLE: it would
Expand Down
Loading
Loading