docs(openspec): OpenSpec pass batch 2 of 3, ten keepiq admin and apps changes - #769
Merged
Merged
Conversation
… roles, public admin API and auto-confirm Five OpenSpec changes for the keepiq parity pass (rows admin-04, admin-12, admin-10, admin-22, admin-11, admin-13, admin-25). Specs only, no code.
…, client libraries and CI, rotation runner and Terraform provider Five OpenSpec changes for the keepiq parity pass (rows admin-27, apps-17, apps-18, apps-21, apps-20, apps-25, apps-22). Specs only, no code.
admin-04, admin-10, admin-11, admin-12, admin-13, admin-22, admin-25, admin-27, apps-17, apps-18, apps-20, apps-21, apps-22 and apps-25 are specified by the ten admin and apps changes of this batch. apps-20's copied evidence loses a double dash, and the admin-04 Bitwarden quote matches the matrix text exactly.
Contributor
Quality Report — ConductionNL/keepiq @
|
| Check | PHP | Vue | Security | License | Tests |
|---|---|---|---|---|---|
| lint | ✅ | ||||
| phpcs | ✅ | ||||
| phpmd | ✅ | ||||
| psalm | ✅ | ||||
| phpstan | ✅ | ||||
| phpmetrics | ✅ | ||||
| eslint | ✅ | ||||
| stylelint | ✅ | ||||
| build | ✅ | ||||
| check-manifest | ✅ | ||||
| test-l10n | ✅ | ||||
| format | ✅ | ||||
| check-l10n-js | ✅ | ||||
| check-schema-l10n | ✅ | ||||
| composer | ✅ | ✅ 114/114 | |||
| npm | ✅ | ✅ 660/660 | |||
| app:check-code | ⏭️ | ||||
| info.xml | ✅ | ||||
| REUSE | ✅ | ||||
| lockfile sync | ✅ | ||||
| PHPUnit | ⏭️ not run for this diff — no file in this diff matches the code globs, and none carries a source extension — the heavy tier has nothing to decide about it. | ||||
| Newman | ✅ | ||||
| Playwright | ⏭️ deferred: E2E runs locally and on the promotion path only. This pull request targets development, so the suite is asked once per promotion into beta and main rather than once per push per open pull request. Run it on any branch from the Actions tab, or locally with npx playwright test. |
||||
| Hydra gates | ✅ |
Quality workflow — 2026-09-27 18:45 UTC
Download the full PDF report from the workflow artifacts.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The OpenSpec pass for keepiq, batch 2 of 3: the ten admin and apps changes. The decisions for every keepiq gap row landed in #767; this PR adds the changes for 14 of the build rows and marks those rows specified in the matrix. It writes specs only; nothing is implemented.
Changes in this PR
admin-member-overview-and-offboarding: admin-04, admin-12admin-vault-policies: admin-10, admin-22admin-scoped-roles: admin-11admin-public-api: admin-13admin-auto-confirm-members: admin-25admin-scheduled-vault-backups: admin-27apps-kubernetes-injection: apps-17apps-client-libraries-and-ci: apps-18, apps-21apps-secret-sync-and-rotation-runner: apps-20, apps-25apps-terraform-provider: apps-22Design calls worth a reviewer's eye:
admin-vault-policiesspecifies the vault half of admin-10 only: a personal-export ban and a rule that the vault does not unlock without Nextcloud two-factor login (the server withholds the wrapped private key). Enforcing two-factor login itself stays Nextcloud's. admin-22 (a tender row) keeps work logins in team folders and addsPOST /api/v1/team-folders/{id}/secretsso a write-grade member can comply.admin-scoped-rolesmodels a role as a Nextcloud group delegated some of five Keepiq admin areas, each its ownIDelegatedSettingsclass; no Keepiq role tables.admin-auto-confirm-membersruns the team folder fan-out in an authorised member's unlocked browser, because the server cannot do it under ADR-003.admin-scheduled-vault-backupsbacks up ciphertext and metadata only, with occ create, list, verify and restore; a restored vault still needs each user's key.apps-secret-sync-and-rotation-runnerputs rotation and cloud sync in a separatekeepiq-runnerunderintegrations/runner/that holds an application key, so the server never sees plaintext; the Go CLI stays stdlib-only.apps-client-libraries-and-ci,apps-kubernetes-injectionandapps-terraform-providerbuild on a Go SDK extracted from the CLI. The Terraform provider needs a mirror repositoryConductionNL/terraform-provider-keepiqcreated by an org admin (its task 3.3).Matrix edits in this PR
specifiedon admin-04, admin-10, admin-11, admin-12, admin-13, admin-22, admin-25, admin-27, apps-17, apps-18, apps-20, apps-21, apps-22 and apps-25, each naming its change.Found while writing, not in these rows
schemeandpayload.value(cli/internal/client/client.go:201,cli/ci.go:65), while the server sendsencryption.schemeandciphertext.key,loginandadditionalFields(lib/Service/MachineSecretEnvelopeService.php:129-150). The CLI unit test fakes its own shape (cli/internal/client/client_test.go:28), sokeepiq ci fetchandkeepiq ci runprobably cannot decrypt a real envelope. Needs a live check; folded intoapps-client-libraries-and-citask 1.2 and going to the issues lane.SecretService::create()storesfolderIdwithout checking who owns the folder (lib/Service/SecretService.php:266). Unverified; the team folder fan-out is not affected.Checks, by exit code
openspec validate --changes: 29 passed, 1 failed; the failure (migrate-emergency-access-on-rotation) is on development and untouched. Each of the ten changes passesopenspec validate <name> --type change --strict.parity_verify.py --strict: no strict finding; only the census of 150 unknown cells, unchanged. Schema validation ran and passed.npm run lint: exit 0.composer check:strict(private HOME and TMPDIR,COMPOSER_PROCESS_TIMEOUT=0): exit 1, the same 2 inherited PHPUnit errors as docs(openspec): OpenSpec pass batch 1 of 3, keepiq gap decisions and 11 changes #767 intests/Unit/Migration/ConsolidatedSchemaMigrationTest.php(1,346 tests); lint, phpcs, phpmd, psalm and phpstan pass. The branch changes nothing outsideopenspec/.tasks.mdhas at most 14 checkboxes.🤖 Generated with Claude Code