-
Notifications
You must be signed in to change notification settings - Fork 5
Release: merge development into beta #1983
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
159 commits
Select commit
Hold shift + click to select a range
595e0b4
chore(release): sync main back into development
github-actions[bot] da4216f
chore(release): 0.4.7-unstable.20260912204215
github-actions[bot] 29139a5
Merge pull request #1982 from ConductionNL/release/v0.4.7-unstable.20…
rubenvdlinde 43c24a0
Merge pull request #1975 from ConductionNL/sync/main-to-development-0…
rubenvdlinde c5b1d93
spec(openspec): vendor document generation adapter, gap register row …
rubenvdlinde a31a880
chore(sync): carry beta back into development
github-actions[bot] 7b14bdd
Merge pull request #1989 from ConductionNL/sync/beta-to-development-2…
rubenvdlinde 634e724
spec(openspec): the two integriq gaps the regenerated register still …
rubenvdlinde 08a120d
docs(openspec): index the competitor parity changes under one umbrell…
rubenvdlinde 3d222e8
feat(connections): a connection registry every app can show (#1996)
rubenvdlinde 98b140c
docs(openspec): a registry-backed field is a small type plus a declar…
rubenvdlinde aad5ac5
docs(openspec): wave 3, five integriq clusters plus the migration sou…
rubenvdlinde 605a877
feat(connections): the registry reads provider names, trusts reported…
rubenvdlinde b08e6c4
docs(openspec): open the outbound sender identity cluster and index i…
rubenvdlinde d570132
spec(parity): the pending-proposal half, rows 5.19 and 6.23 open, 6.2…
rubenvdlinde 0f50e2b
feat(directory): a directory connection that keeps Nextcloud groups i…
rubenvdlinde 69cdd3a
docs: retire the last two dead Codeberg issue URLs in archived opensp…
rubenvdlinde c8e4d83
feat(connections): a settings refresh retires older observations (#2020)
rubenvdlinde a936658
feat(connections): requiredConfig reads false as empty and can look i…
rubenvdlinde 64b437f
feat(connections): a switched-off connection reads disabled, and an e…
rubenvdlinde 8d3e0e8
fix(deps): lift symfony/cache past the ext-redis conflict that blocks…
WilcoLouwerse 2dbc441
style: format the files the connection registry wave merged unformatt…
rubenvdlinde b236aa8
fix(e2e): directory-sync runs pass the CSRF check and find their row …
rubenvdlinde ccaf7db
fix(connections): read connection rows unscoped, so webcron stops wri…
rubenvdlinde f766b87
fix(e2e): the directory connections read sends OCS-APIRequest too (#2…
rubenvdlinde e38a076
chore(deps): Nextcloud 35 support (max-version 34 -> 35)
rjzondervan 9c8e3f2
Merge remote-tracking branch 'origin/development' into fix/composer-l…
WilcoLouwerse 778e220
Merge pull request #2040 from ConductionNL/fix/composer-lock-ext-redi…
WilcoLouwerse 4432053
feat(property-source): resolve a field from a registry, with the prov…
rubenvdlinde e8e127f
feat(mail-intake): a mailbox is a source and a message is offered to …
rubenvdlinde 9866e81
feat(registry-subscriptions): follow a person or a company at the reg…
rubenvdlinde 20ef2c9
feat(ownership): say who owns a record, and what happens when the sou…
rubenvdlinde e6d5ed3
feat(intake): a channel is an adapter with a routing rule, not a rele…
rubenvdlinde 9713f18
feat(migration): read an incumbent or a delivered file, and write not…
rubenvdlinde f99b5ea
feat(outbound): the log of what was sent, per recipient and per step …
rubenvdlinde 1e31789
feat(gateways): say which laws this instance reaches, and where data …
rubenvdlinde d64e703
feat(outbound-identity): an identity is the face on an account Nextcl…
rubenvdlinde 024e8a5
feat(call-log): a call is a record, a replay is an attempt, a dry run…
rubenvdlinde 5bce690
ci(matrix): derive the Nextcloud test matrix from info.xml
rjzondervan 86eaea9
test(appinfo): inject the container type the server declares
rjzondervan 49b22ec
Merge remote-tracking branch 'origin/development' into feature/integr…
rjzondervan 4b43807
feat(events): bound the CloudEvent loop, and recognise our own rows w…
rubenvdlinde 010a6b2
feat(events): let a subscription actually be saved with the flow kind…
rubenvdlinde b259044
test(ownership): cover the engine's refusal of a policy it does not k…
rubenvdlinde f0d4463
feat(expression): a prefixed value source, and an env allowlist that …
rubenvdlinde 8f03c0e
feat(registry): bind the subscription request to the handler that ful…
rubenvdlinde 3db280a
feat(cti): the telephony seam, and a caller number this never guesses…
rubenvdlinde fe1704f
feat(zgw): the six packaged consumer sets, and the bindings the insta…
rubenvdlinde 91dc487
feat(recipients): who was kept off a message, and why the record says…
rubenvdlinde c9a57e2
feat(webhooks): a push subscription signs unless somebody says otherw…
rubenvdlinde fdb7f18
feat(objecten): the declared mapping, the token matrix and the leak g…
rubenvdlinde c836108
feat(objecten): serve the routes — six read, four write (#2077)
rubenvdlinde 626d8da
feat(digital-post): one seam for digital post, and a flag that refuse…
rubenvdlinde 82bfbe6
feat(cti): the endpoint, and a caller lookup that refuses what it can…
rubenvdlinde 1fbcdbd
fix(system-writes): stop falling through to a bare call, and find the…
rubenvdlinde 472b072
feat(document generation): the SmartDocuments and Xential seam, behin…
rubenvdlinde 88c78dd
merge development into parity/round2
rubenvdlinde 6eca2b8
fix(quality): put the two digital post jobs back on the schedule, and…
rubenvdlinde 4bb26b8
fix(quality): a ceiling on the public objecten routes, a contract tes…
rubenvdlinde d1ad45b
fix(quality): answer phpmd on the lines this branch wrote, with a rea…
rubenvdlinde cac78dc
fix(quality): delete a branch that could never run, and an injected c…
rubenvdlinde c13a20c
docs(openspec): a Teams message opens a case, over the channel contra…
rubenvdlinde c8c4801
style(e2e): prettier the one spec file this branch added
rubenvdlinde e4e9fda
feat(l10n): the document generation job speaks Dutch, and its title s…
rubenvdlinde f74f549
fix(migration): a delivery path that names a folder says so
rubenvdlinde 9d2b6ea
fix(digital-post): attach the message schema to the register it is wr…
rubenvdlinde f0b77f0
Merge pull request #2083 from ConductionNL/parity/round2
rubenvdlinde e8a2dea
fix(routes): two entries shared a route name, so two routes never reg…
rubenvdlinde 5544808
style(tests): run prettier over the specs that fail format
rjzondervan 03e5fb4
fix(lib): three narrowing and error-handling fixes phpstan refused
rjzondervan 8032222
chore(quality): baseline the debt the feature merges brought with them
rjzondervan a7f43af
feat(l10n): give the backend catalogue the keys the schemas need
rjzondervan d3a41f5
fix(quality): psalm and phpstan read two OpenRegister runtime types a…
rubenvdlinde 70ede26
style(lib): replace the elvis operators the standard refuses
rjzondervan c29c122
fix(l10n): four source strings were never added to the catalogue
rubenvdlinde e32e4f2
chore(format): prettier was never run over eighteen frontend files
rubenvdlinde 215ba41
style(lib): convert the first 37 inline ifs to statements
rjzondervan 040f549
Merge pull request #2087 from ConductionNL/fix/psalm-phpstan-inherited
rubenvdlinde 3646591
Merge pull request #2088 from ConductionNL/fix/l10n-missing-source-st…
rubenvdlinde cd55d2d
Merge pull request #2089 from ConductionNL/chore/prettier-format
rubenvdlinde 86211f1
style(lib): hoist another 26 inline ifs out of arguments and array va…
rjzondervan 7f26508
style(lib): clear the last inline ifs
rjzondervan 12ac22a
fix(icons): seven icons rendered as nothing at all
rubenvdlinde deb86cf
style(lib): name the arguments in 296 internal calls
rjzondervan 70d359d
fix(sync): a record the source carried again stayed flagged as gone
rubenvdlinde 48f9bb4
Merge pull request #2091 from ConductionNL/fix/hydra-gate-60-icons
rubenvdlinde e506a77
style(lib): name the last 41 arguments — phpcs is clean
rjzondervan 38b8a7a
Merge remote-tracking branch 'origin/development' into feature/integr…
rjzondervan 002900d
test(outbound): the alignment endpoint shipped with no contract test
rubenvdlinde ac1997c
Merge pull request #2092 from ConductionNL/fix/hydra-gate-57-record-c…
rubenvdlinde a46558a
style(lib): re-clear the gates the development merge reopened
rjzondervan 50de109
Merge pull request #2094 from ConductionNL/test/gate-25-alignment-con…
rubenvdlinde 775d6c5
fix(quality): my own phpmd findings fixed, the merged ones baselined
rjzondervan 29fd89a
fix(migration): any signed-in account could read an incumbent system
rubenvdlinde d072f2b
fix(types): correct two types my own refactors got wrong
rjzondervan e88268a
Merge pull request #2097 from ConductionNL/fix/hydra-gate-7-migration…
rubenvdlinde fe15ed1
chore(release): 0.4.8-unstable.20260919141023
github-actions[bot] 51aab9f
fix(security): scope two unguarded reads, and account for the other five
rjzondervan 10c7abb
fix(quality): close gate-25, gate-106 and gate-16
rjzondervan d7fa287
Merge remote-tracking branch 'origin/development' into feature/integr…
rjzondervan f131874
refactor(migration): lift the uid resolution out of readFile()
rjzondervan 96e76d7
Merge pull request #2098 from ConductionNL/release/v0.4.8-unstable.20…
rubenvdlinde 0684e2c
fix(manifest): point the mail-intake widget at the renamed schema
rjzondervan 5282982
test(manifest): follow the schema rename into the frontend spec
rjzondervan bc3336b
style(tests): reflow the line the schema rename made too long
rjzondervan 8fbbd6f
chore(demo-data): regenerate the mock register so every schema has sa…
rjzondervan 2d25638
fix(demo-data): keep the schemas block the register validator requires
rjzondervan 658cafe
Merge pull request #2065 from ConductionNL/feature/integriq-nc35-support
rjzondervan ec95b1a
docs(outbound): spec enrolling sender_identity in the credential broker
rjzondervan 5463865
docs(outbound): mint the S/MIME key under generic-apikey for now
rjzondervan 65f6023
docs(outbound): keep the certificate literal; file the multi-field gap
rjzondervan e5f41c3
docs(outbound): link the four brokered-credential gap issues
rjzondervan 212eb1c
feat(outbound): hold the S/MIME signing key in the credential broker
rjzondervan 507d405
feat(outbound): migrate the S/MIME key into the broker, and refuse PE…
rjzondervan 857e37c
fix(mail): close the nine world-readable mail schemas
rjzondervan 16dc6ce
fix(directory): refuse SCIM writes to admin and to unmanaged groups
rjzondervan bd3e313
fix(l10n): cover the new schema strings, and capitalise two comments
rjzondervan 651eb55
docs(mail): point the lockdown at its follow-up issue
rjzondervan 1314e32
fix(outbound): write-only stripping is a render rule, not an RBAC one
rjzondervan 3d3e1ed
fix(security): a real migration run reaches every schema, not just so…
rjzondervan dcb3539
fix(directory): guard the SCIM user routes, and cap the page size
rjzondervan a1f94d7
fix(spec): REQ-OSI-012 says what shipped, and now has the tests it cl…
rjzondervan 3d84f77
fix(directory): scope the admin refusal honestly, and ratchet schema …
rjzondervan 231bb6c
fix(quality): close the three CI checks my review fixes broke
rjzondervan 95cce12
fix(directory): clamp SCIM paging on both routes, and make the PEM te…
rjzondervan 6021550
refactor(security): close the three minors from the re-review
rjzondervan a32af47
fix(l10n): sentence case for the S/MIME field titles, per ADR-007
rjzondervan 2f4a1ae
test(directory): cover the per-schema table, and align the two list r…
rjzondervan 095fbfe
docs(directory): the /Groups membership read is an authorization ques…
rjzondervan 2c2ee64
fix(directory): validate SCIM `count` instead of coercing it silently
rjzondervan f370f87
Merge pull request #2104 from ConductionNL/fix/integriq-1983-review-f…
rjzondervan 4cfd03f
fix(di): bind DnsResolverInterface and CallDispatcherInterface
rjzondervan 80d6999
fix(records): correct a false IDOR exemption, and land three minors t…
rjzondervan cc989dd
fix(appinfo): RenameDutchColumns was registered twice
rjzondervan cdbbf5d
fix(property-sources): gate the registry lookups admin-only by default
rjzondervan eed289d
docs(appinfo): record the NC35 / OpenRegister channel pairing as a de…
rjzondervan 7ced8f3
style(actions): restore actions.seed.json formatting, keep only the t…
rjzondervan ccea98d
Revert "fix(property-sources): gate the registry lookups admin-only b…
rjzondervan 5724a83
docs(sources): the convention for connectors that return personal data
rjzondervan 5a07583
feat(webhooks): read the Microsoft Teams signature scheme on inbound …
rubenvdlinde 35bca0c
feat(intake): a Microsoft Teams message opens or joins a case
rubenvdlinde c87912e
test(di): execute register() so the two new bindings are covered, not…
rjzondervan 9d93c7b
refactor(intake): split the two methods phpmd flagged, and move the b…
rubenvdlinde a1a5611
Merge pull request #2128 from ConductionNL/feat/teams-messages-open-c…
rubenvdlinde d640e27
feat(events): a matched CloudEvent can go to a message broker
rubenvdlinde fc93c24
refactor(events,broker): split the two methods phpmd flagged, and bas…
rubenvdlinde 8a392b7
Merge pull request #2130 from ConductionNL/feat/event-broker-transport
rubenvdlinde c60bd7d
feat(auth): the government identity broker, minus the vendor half
rubenvdlinde 2f8c37b
fix(auth): use named arguments for the parent controller constructor,…
rubenvdlinde 7fe3352
Merge pull request #2132 from ConductionNL/feat/idp-broker-envelope-r…
rubenvdlinde 2db487a
fix(events): give the broker schema strings a catalogue key, and form…
rubenvdlinde 637c049
Merge pull request #2134 from ConductionNL/fix/broker-schema-l10n-cov…
rubenvdlinde e62d4d8
fix(docs,test): the authorization example granted nothing, and the sw…
rjzondervan 9cd5755
Merge pull request #2127 from ConductionNL/fix/bind-app-owned-interfaces
rjzondervan ab13bfd
fix(intake): act on the bytes that were signed, and allow-list the Te…
rjzondervan bdedf31
test(intake): cover the new decode and trusted-host branches
rjzondervan 85e5de8
Merge pull request #2137 from ConductionNL/fix/intake-signature-desyn…
rjzondervan de67807
fix(property-source): gate registry queries, exempting the public reg…
rjzondervan bd5e54f
Merge pull request #2143 from ConductionNL/fix/gate-sensitive-propert…
rjzondervan File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.