Skip to content

docs(openspec): OpenSpec pass batch 1 of 3, keepiq gap decisions and 11 changes - #767

Merged
rubenvdlinde merged 3 commits into
developmentfrom
parity/openspec-pass-1
Sep 27, 2026
Merged

rubenvdlinde merged 3 commits into
developmentfrom
parity/openspec-pass-1

Conversation

@rubenvdlinde

Copy link
Copy Markdown
Contributor

The OpenSpec pass for keepiq, batch 1 of 3: every gap row decided, the matrix edits for them, and the first 11 changes. This PR writes specs only; nothing is implemented.

Decisions

openspec/parity/gap-decisions.json records one decision for each of 91 rows: the 82 keepiq-owned gap rows from the dedupe index (all in keepiq's own matrix) and the 9 keepiq-matrix rows owned by nextcloud/server.

  • build: 49 rows, in 31 changes
  • defer: 24 rows (single competitor, no demand, outside the core area, or partial and built with no demand)
  • decided-no: 18 rows (9 on a recorded record or a platform capability, 9 owned by nextcloud/server)
  • existing: 0 rows. The 38 rows with a lexical candidate were checked against the candidate's title and capabilities and, where the capability overlapped, its spec; none covers the missing capability (most candidates are the change that built the half that exists).

Readings of the rule, stated so they can be checked:

  • The core area is vault (the first 30 rows are all vault).
  • A change-level "out of scope for v1" or "a separate change" is a scope boundary, not a non-goal: the trash (bulk-actions/spec.md:94), the manage grade (folder-permission-grades/spec.md:82), the offline write queue (offline-readonly-cache/spec.md:128) and a browser-side attachment preview (encrypted-attachments/spec.md:147 rules out only a server-side one) are all build.
  • Decided no on a record: clients-11 and clients-20 on mobile-pwa/spec.md:11,:49 (no native app, the record clients-10 already rests on); crypto-22 on secrets/spec.md:14,:566 (name and address stored in plain text by design); health-13, health-14 and health-16 on password-health/spec.md:111-112 (No Server-Side Health Knowledge). crypto-22 and health-13 have three or more competitors rating yes and are flagged for review.
  • Decided no as platform: admin-08 (SCIM) and admin-23 (domain claim) because vault users are Nextcloud accounts (docs/FEATURES.md:330, :491), and admin-21 (announcements) because the Nextcloud Announcement center app provides it. Their provider and owner are corrected in the matrix.

Matrix edits in this PR

  • built.owner filled on the 6 rows that had none (apps-17, apps-18, apps-19, apps-21, apps-22, apps-24): all ConductionNL/keepiq.
  • decided-no with the source in the evidence and the note on the 18 decided-no rows.
  • Corrected: apps-20 was rated no with built.state built while its evidence shows only reminders and a manual mark-rotated flow; the state is now none before its change. admin-08 and admin-23 now have provider nextcloud and owner nextcloud/server; admin-21 provider nextcloud and owner nextcloud/announcementcenter.
  • specified on the 21 rows the 11 changes below cover. The one em-dash in the matrix (vault-04 evidence) is rewritten.

Changes in this PR

  • vault-trash-and-archive: vault-04, vault-27
  • vault-favourites-tags-and-last-used: vault-09, vault-10, vault-24
  • vault-login-totp-codes: vault-16
  • vault-item-clone-preview-and-print: vault-22, vault-26, vault-30
  • vault-duplicate-finder: vault-25
  • vault-website-addresses: vault-28, vault-31, rotation-08
  • portability-export-choice-and-restore-fidelity: portability-09, portability-11
  • health-passphrase-generator: health-08
  • health-site-security-checks: health-11, health-12, health-15
  • crypto-item-reprompt: crypto-20
  • crypto-vault-encryption-details: crypto-13

The other 20 changes follow in batches 2 and 3 (parity/openspec-pass-2, -3): the admin and apps changes, then the audit, clients, crypto and sharing changes. Their rows stay unspecified in the matrix until their batch lands.

Not specified, and why

The 24 deferred rows and their reasons are in the decisions file; 14 of them are partial, built, with no demand and fewer than two competitors rating yes (the addendum's rule). Two defects found while reading, recorded in the portability change and not filed separately:

  • A restored backup loses every type but login: the export writes the type id (a UUID) under type (src/export/serializer.js:120) and the restore stamps a type only for the names totp, passkey, card and identity (src/store/modules/import.js:271-288). The serializer test fixture uses typeId: 'login' (tests/vitest/export-serializer.spec.js:24-26), so it cannot see this.
  • An export skips secrets it cannot decrypt without saying so (src/views/SecretList.vue:1230-1236).

Checks, by exit code

  • openspec validate --changes: 19 passed, 1 failed; the failure (migrate-emergency-access-on-rotation, a MODIFIED block that omits a scenario) is on development and untouched here. Each of the 11 new changes passes openspec validate <name> --type change --strict.
  • parity_verify.py --strict: no strict finding; the only line is the census of 150 unknown cells, unchanged from development. Schema validation ran and passed.
  • npm run lint: exit 0.
  • composer check:strict (private HOME and TMPDIR, COMPOSER_PROCESS_TIMEOUT=0): exit 1. lint, phpcs, phpmd, psalm and phpstan pass; PHPUnit has 2 errors of 1,346 tests, both in tests/Unit/Migration/ConsolidatedSchemaMigrationTest.php (its FakeTable is not an OCP\DB\Schema\ITable, which the locked nextcloud/ocp v35.0.0 declares as the return type of createTable() and getTable()). Inherited: this branch changes no file outside openspec/ (git diff origin/development...HEAD -- . ':!openspec' is empty), so development fails the same way.
  • No em-dash, en-dash or double dash in any new file; every tasks.md has at most 10 checkboxes.

🤖 Generated with Claude Code

Trash and archive (vault-04, vault-27), favourites, tags and a last-used
sort (vault-09, vault-10, vault-24), one-time codes on logins (vault-16),
clone, attachment preview and print (vault-22, vault-26, vault-30), and a
duplicate finder (vault-25). Specs only.
Website addresses, site preview and change-password link (vault-28,
vault-31, rotation-08), export choice and a lossless backup restore
(portability-09, portability-11), a passphrase generator (health-08),
site checks in the health report (health-11, health-12, health-15), a
per-item master password re-prompt (crypto-20) and the vault encryption
details (crypto-13). Specs only.
…ec pass

gap-decisions.json records all 91 rows: the 82 keepiq-owned gap rows
and the 9 keepiq-matrix rows owned by nextcloud/server. Build 49 rows
in 31 changes, defer 24, decided no 18, existing 0.

Matrix: built.owner filled on the 6 rows without one, decided-no with
its source on 18 rows, apps-20 corrected from built to none, provider
and owner corrected on admin-08, admin-21 and admin-23, and specified
on the 21 rows the 11 changes of this batch cover.
@rubenvdlinde
rubenvdlinde merged commit b165a43 into development Sep 27, 2026
36 checks passed
@github-actions

Copy link
Copy Markdown
Contributor

Quality Report — ConductionNL/keepiq @ 14f7dfc

Check PHP Vue Security License Tests
lint ✅
phpcs ✅
phpmd ✅
psalm ✅
phpstan ✅
phpmetrics ✅
eslint ✅
stylelint ✅
build ✅
check-manifest ✅
test-l10n ✅
format ✅
check-l10n-js ✅
check-schema-l10n ✅
composer ✅ ✅ 114/114
npm ✅ ✅ 660/660
app:check-code ⏭️
info.xml ✅
REUSE ✅
lockfile sync ✅
PHPUnit ⏭️ not run for this diff — no file in this diff matches the code globs, and none carries a source extension — the heavy tier has nothing to decide about it.
Newman ✅
Playwright ⏭️ deferred: E2E runs locally and on the promotion path only. This pull request targets development, so the suite is asked once per promotion into beta and main rather than once per push per open pull request. Run it on any branch from the Actions tab, or locally with npx playwright test.
Hydra gates ✅

Quality workflow — 2026-09-27 18:31 UTC

Download the full PDF report from the workflow artifacts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant