Skip to content

docs(openspec): OpenSpec pass batch 2 of 3, ten keepiq admin and apps changes - #769

Merged
rubenvdlinde merged 4 commits into
developmentfrom
parity/openspec-pass-2
Sep 27, 2026
Merged

rubenvdlinde merged 4 commits into
developmentfrom
parity/openspec-pass-2

Conversation

@rubenvdlinde

Copy link
Copy Markdown
Contributor

The OpenSpec pass for keepiq, batch 2 of 3: the ten admin and apps changes. The decisions for every keepiq gap row landed in #767; this PR adds the changes for 14 of the build rows and marks those rows specified in the matrix. It writes specs only; nothing is implemented.

Changes in this PR

  • admin-member-overview-and-offboarding: admin-04, admin-12
  • admin-vault-policies: admin-10, admin-22
  • admin-scoped-roles: admin-11
  • admin-public-api: admin-13
  • admin-auto-confirm-members: admin-25
  • admin-scheduled-vault-backups: admin-27
  • apps-kubernetes-injection: apps-17
  • apps-client-libraries-and-ci: apps-18, apps-21
  • apps-secret-sync-and-rotation-runner: apps-20, apps-25
  • apps-terraform-provider: apps-22

Design calls worth a reviewer's eye:

  • admin-vault-policies specifies the vault half of admin-10 only: a personal-export ban and a rule that the vault does not unlock without Nextcloud two-factor login (the server withholds the wrapped private key). Enforcing two-factor login itself stays Nextcloud's. admin-22 (a tender row) keeps work logins in team folders and adds POST /api/v1/team-folders/{id}/secrets so a write-grade member can comply.
  • admin-scoped-roles models a role as a Nextcloud group delegated some of five Keepiq admin areas, each its own IDelegatedSettings class; no Keepiq role tables.
  • admin-auto-confirm-members runs the team folder fan-out in an authorised member's unlocked browser, because the server cannot do it under ADR-003.
  • admin-scheduled-vault-backups backs up ciphertext and metadata only, with occ create, list, verify and restore; a restored vault still needs each user's key.
  • apps-secret-sync-and-rotation-runner puts rotation and cloud sync in a separate keepiq-runner under integrations/runner/ that holds an application key, so the server never sees plaintext; the Go CLI stays stdlib-only.
  • apps-client-libraries-and-ci, apps-kubernetes-injection and apps-terraform-provider build on a Go SDK extracted from the CLI. The Terraform provider needs a mirror repository ConductionNL/terraform-provider-keepiq created by an org admin (its task 3.3).

Matrix edits in this PR

Found while writing, not in these rows

  • The CLI's machine envelope does not match the server's: the CLI expects a top-level scheme and payload.value (cli/internal/client/client.go:201, cli/ci.go:65), while the server sends encryption.scheme and ciphertext.key, login and additionalFields (lib/Service/MachineSecretEnvelopeService.php:129-150). The CLI unit test fakes its own shape (cli/internal/client/client_test.go:28), so keepiq ci fetch and keepiq ci run probably cannot decrypt a real envelope. Needs a live check; folded into apps-client-libraries-and-ci task 1.2 and going to the issues lane.
  • SecretService::create() stores folderId without checking who owns the folder (lib/Service/SecretService.php:266). Unverified; the team folder fan-out is not affected.

Checks, by exit code

  • openspec validate --changes: 29 passed, 1 failed; the failure (migrate-emergency-access-on-rotation) is on development and untouched. Each of the ten changes passes openspec validate <name> --type change --strict.
  • parity_verify.py --strict: no strict finding; only the census of 150 unknown cells, unchanged. Schema validation ran and passed.
  • npm run lint: exit 0.
  • composer check:strict (private HOME and TMPDIR, COMPOSER_PROCESS_TIMEOUT=0): exit 1, the same 2 inherited PHPUnit errors as docs(openspec): OpenSpec pass batch 1 of 3, keepiq gap decisions and 11 changes #767 in tests/Unit/Migration/ConsolidatedSchemaMigrationTest.php (1,346 tests); lint, phpcs, phpmd, psalm and phpstan pass. The branch changes nothing outside openspec/.
  • No em-dash, en-dash or double dash in any new file; every tasks.md has at most 14 checkboxes.

🤖 Generated with Claude Code

… roles, public admin API and auto-confirm

Five OpenSpec changes for the keepiq parity pass (rows admin-04, admin-12,
admin-10, admin-22, admin-11, admin-13, admin-25). Specs only, no code.
…, client libraries and CI, rotation runner and Terraform provider

Five OpenSpec changes for the keepiq parity pass (rows admin-27, apps-17,
apps-18, apps-21, apps-20, apps-25, apps-22). Specs only, no code.
admin-04, admin-10, admin-11, admin-12, admin-13, admin-22, admin-25,
admin-27, apps-17, apps-18, apps-20, apps-21, apps-22 and apps-25 are
specified by the ten admin and apps changes of this batch. apps-20's
copied evidence loses a double dash, and the admin-04 Bitwarden quote
matches the matrix text exactly.
@rubenvdlinde
rubenvdlinde merged commit 58cd98f into development Sep 27, 2026
36 checks passed
@github-actions

Copy link
Copy Markdown
Contributor

Quality Report — ConductionNL/keepiq @ 317b583

Check PHP Vue Security License Tests
lint ✅
phpcs ✅
phpmd ✅
psalm ✅
phpstan ✅
phpmetrics ✅
eslint ✅
stylelint ✅
build ✅
check-manifest ✅
test-l10n ✅
format ✅
check-l10n-js ✅
check-schema-l10n ✅
composer ✅ ✅ 114/114
npm ✅ ✅ 660/660
app:check-code ⏭️
info.xml ✅
REUSE ✅
lockfile sync ✅
PHPUnit ⏭️ not run for this diff — no file in this diff matches the code globs, and none carries a source extension — the heavy tier has nothing to decide about it.
Newman ✅
Playwright ⏭️ deferred: E2E runs locally and on the promotion path only. This pull request targets development, so the suite is asked once per promotion into beta and main rather than once per push per open pull request. Run it on any branch from the Actions tab, or locally with npx playwright test.
Hydra gates ✅

Quality workflow — 2026-09-27 18:45 UTC

Download the full PDF report from the workflow artifacts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant