Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
540 commits
Select commit Hold shift + click to select a range
f07a0be
chore(deps-dev): bump webpack from 5.110.3 to 5.111.1 (#2298)
dependabot[bot] Oct 2, 2026
d7839f7
chore(deps-dev): bump nextcloud/ocp from 35.0.0 to 35.0.1 (#2297)
dependabot[bot] Oct 2, 2026
5e11389
chore(deps-dev): bump jest from 30.5.0 to 30.5.2 (#2296)
dependabot[bot] Oct 2, 2026
9cd1c55
chore(deps): bump marked from 18.0.11 to 18.0.14 (#2294)
dependabot[bot] Oct 2, 2026
fc76fea
chore(deps-dev): bump phpstan/phpstan from 2.2.13 to 2.2.16 (#2293)
dependabot[bot] Oct 2, 2026
dea316b
Merge pull request #2452 from ConductionNL/fix/objecten-type-url
rubenvdlinde Oct 2, 2026
413c090
Merge remote-tracking branch 'origin/development' into docs/lti-platf…
rubenvdlinde Oct 2, 2026
1af2dce
Merge remote-tracking branch 'origin/development' into feat/course-ma…
rubenvdlinde Oct 2, 2026
523c1a7
feat(sync): retire a withdrawn marketplace course to a declared lifec…
rubenvdlinde Oct 2, 2026
7fc3e8c
docs(idp): the portaliq return address carries its app path, sign-out…
rubenvdlinde Oct 2, 2026
b7ab19f
Merge remote-tracking branch 'origin/development' into docs/lti-platf…
rubenvdlinde Oct 2, 2026
d820c31
test(zgw): a bound schema holds the store's own shape, no set names a…
rubenvdlinde Oct 2, 2026
7dda0ac
test(zgw): an operator meets every installer refusal in Dutch
rubenvdlinde Oct 2, 2026
039089a
feat(zgw): a bound schema holds the store's own shape; install guide …
rubenvdlinde Oct 2, 2026
bf6ae14
Merge pull request #2457 from ConductionNL/docs/lti-platform-launch-s…
rubenvdlinde Oct 2, 2026
4531944
test(zgw): catch the refusal the installer actually throws
rubenvdlinde Oct 2, 2026
1cd941f
Merge remote-tracking branch 'origin/development' into feat/course-ma…
rubenvdlinde Oct 2, 2026
a118596
docs(sync): name the requirements applyToObject serves
rubenvdlinde Oct 2, 2026
8da6370
style(zgw): keep each Dutch refusal one translatable line under the l…
rubenvdlinde Oct 2, 2026
3213e6e
style(sync): import InvalidArgumentException where the retire and uui…
rubenvdlinde Oct 2, 2026
1820211
Merge remote-tracking branch 'origin/development' into feat/zgw-pass-…
rubenvdlinde Oct 2, 2026
ade9e6b
chore(l10n): regenerate the browser catalogues for the Dutch refusals
rubenvdlinde Oct 2, 2026
110e713
Merge pull request #2461 from ConductionNL/feat/course-marketplace-re…
rubenvdlinde Oct 2, 2026
39ed248
Merge pull request #2460 from ConductionNL/feat/zgw-pass-through
rubenvdlinde Oct 2, 2026
0c80de6
test(zgw): the Synced from tab says when the connected system refused…
rubenvdlinde Oct 2, 2026
0697441
test(zgw): an unreadable subscriptions value reads as none and every …
rubenvdlinde Oct 2, 2026
54c8641
Merge branch 'feat/zgw-pass-through' into feat/zgw-conflict-marker
rubenvdlinde Oct 2, 2026
dcaee6c
feat(zgw): the Synced from tab says when the connected system refused…
rubenvdlinde Oct 2, 2026
8e1fbe3
test(sync): a marketplace synchronization does not run before its LTI…
rubenvdlinde Oct 2, 2026
309502e
Merge remote-tracking branch 'origin/development' into feat/zgw-confl…
rubenvdlinde Oct 2, 2026
4737eb9
test(sync): name the run helper so it does not shadow TestCase::run()
rubenvdlinde Oct 2, 2026
4a64454
Merge pull request #2463 from ConductionNL/feat/zgw-conflict-marker
rubenvdlinde Oct 2, 2026
ed69cd1
feat(sync): a marketplace synchronization does not run before its LTI…
rubenvdlinde Oct 2, 2026
abbc2d4
Merge remote-tracking branch 'origin/development' into feat/course-ma…
rubenvdlinde Oct 2, 2026
2d96d5b
test(lti): a marketplace placement tells the tool which course to open
rubenvdlinde Oct 3, 2026
9a233f3
Merge pull request #2466 from ConductionNL/feat/course-marketplace-guard
rubenvdlinde Oct 3, 2026
8f2da60
feat(lti): a marketplace placement tells the tool which course to open
rubenvdlinde Oct 3, 2026
c7161b9
Merge remote-tracking branch 'origin/development' into feat/course-ma…
rubenvdlinde Oct 3, 2026
dac6101
test(demo): demo data lists one LTI deployment per course marketplace…
rubenvdlinde Oct 3, 2026
5dcf4e7
feat(demo): one LTI tool and deployment per course marketplace provid…
rubenvdlinde Oct 3, 2026
d3bbc88
Merge pull request #2468 from ConductionNL/feat/course-marketplace-la…
rubenvdlinde Oct 3, 2026
9845fbf
test(validation): the message validator checks JSON Schema, XSD witho…
rubenvdlinde Oct 3, 2026
b161e40
Merge pull request #2469 from ConductionNL/feat/course-marketplace-de…
rubenvdlinde Oct 3, 2026
75c8026
feat(validation): a message is checked against JSON Schema, an XSD wi…
rubenvdlinde Oct 3, 2026
23f96f4
docs(validation): ValidationOutcome's public methods link their requi…
rubenvdlinde Oct 3, 2026
7145d28
test(lti): contracts that cannot name a course give no custom parameter
rubenvdlinde Oct 3, 2026
c77486d
Merge remote-tracking branch 'origin/development' into feat/message-s…
rubenvdlinde Oct 3, 2026
aea87af
test(validation): a message schema is stored once, seeded twice, list…
rubenvdlinde Oct 3, 2026
d48962d
Merge pull request #2471 from ConductionNL/feat/message-schema-checkers
rubenvdlinde Oct 3, 2026
974dbe2
Merge pull request #2472 from ConductionNL/test/lti-custom-parameter-…
rubenvdlinde Oct 3, 2026
8eb98c3
feat(validation): a message schema is stored once, seeded twice, list…
rubenvdlinde Oct 3, 2026
94fbffb
test(validation): an endpoint refuses or records a request and a prox…
rubenvdlinde Oct 3, 2026
74e47c4
fix(validation): three demo message schemas for the demo register, an…
rubenvdlinde Oct 3, 2026
25247d0
Merge remote-tracking branch 'origin/feat/message-schema-object' into…
rubenvdlinde Oct 3, 2026
646feea
feat(validation): an endpoint refuses or records a request and a prox…
rubenvdlinde Oct 3, 2026
dd33a95
Merge remote-tracking branch 'origin/development' into feat/message-s…
rubenvdlinde Oct 3, 2026
6de1765
docs(openspec): store DSO attachments as files on the request object,…
rubenvdlinde Oct 3, 2026
d438654
Merge pull request #2475 from ConductionNL/feat/message-schema-object
rubenvdlinde Oct 3, 2026
0c4468c
docs(validation): the endpoint form's visible fields link their requi…
rubenvdlinde Oct 3, 2026
271aa49
Merge remote-tracking branch 'origin/development' into feat/endpoint-…
rubenvdlinde Oct 3, 2026
cd23696
feat(dso): store DSO bijlagen as files on the request, retire DSOAdap…
rubenvdlinde Oct 4, 2026
351902b
Merge remote-tracking branch 'origin/development' into feat/endpoint-…
rubenvdlinde Oct 4, 2026
da2e4ef
style(validation): sort the endpoint validation spec's imports and fo…
rubenvdlinde Oct 4, 2026
e79fbc8
docs(validation): two endpoint form docblocks sit on their own method…
rubenvdlinde Oct 4, 2026
868861b
wip: saved by the coordinator after the 4 Oct 16:59 WSL reboot (unver…
rubenvdlinde Oct 4, 2026
673e5e6
feat(validation): a synchronization checks its source objects and tar…
rubenvdlinde Oct 4, 2026
ba62d89
docs(openspec): tick the service desk docs task that landed with #2428
rubenvdlinde Oct 4, 2026
2e901e7
Merge pull request #2476 from ConductionNL/feat/endpoint-message-vali…
rubenvdlinde Oct 4, 2026
e19501a
test(sync): a purge deletes a vanished record permanently, records it…
rubenvdlinde Oct 4, 2026
beafc1d
feat(sync): a synchronization can purge a vanished record and its fil…
rubenvdlinde Oct 4, 2026
f149826
refactor(validation): the synchronization looks its message gate up o…
rubenvdlinde Oct 4, 2026
af76d60
feat(dso): intake maps the activiteiten to zaaktypen; live run finds …
rubenvdlinde Oct 4, 2026
a702cc4
test(sync): the ownership refusal lists purge among the accepted poli…
rubenvdlinde Oct 4, 2026
f77dde7
Merge pull request #2481 from ConductionNL/docs/service-desk-ticks
rubenvdlinde Oct 4, 2026
6d4bd1f
Merge remote-tracking branch 'origin/development' into feat/sync-mess…
rubenvdlinde Oct 4, 2026
5a87501
style(validation): the refusal exception takes its message as a named…
rubenvdlinde Oct 4, 2026
fb11284
Merge remote-tracking branch 'origin/development' into feat/source-de…
rubenvdlinde Oct 4, 2026
f4d9819
test(sync): a destruction notice purges one object, a forged destroye…
rubenvdlinde Oct 4, 2026
49b8306
feat(sync): a destruction notice purges one object without a full run
rubenvdlinde Oct 4, 2026
e13e53a
fix(dso): the STAM intake answers 503, not 202, when the verzoek was …
rubenvdlinde Oct 4, 2026
f7d38d2
test(sync): the editor offers purge with a cannot-be-restored warning…
rubenvdlinde Oct 4, 2026
393b6ac
docs(openspec): the DSO intake runs through an integriq connection, a…
rubenvdlinde Oct 4, 2026
5e04ec0
feat(sync): the editor offers purge and says purged files cannot be r…
rubenvdlinde Oct 4, 2026
5befbe1
fix(l10n): catalogue keys for the 16 DSO activity mapping schema strings
rubenvdlinde Oct 4, 2026
59de155
Merge pull request #2483 from ConductionNL/feat/sync-message-validation
rubenvdlinde Oct 4, 2026
4b68b4c
Merge pull request #2486 from ConductionNL/feat/source-destruction-purge
rubenvdlinde Oct 4, 2026
731b144
Merge remote-tracking branch 'origin/development' into feat/source-de…
rubenvdlinde Oct 4, 2026
1c76aff
Merge remote-tracking branch 'origin/feat/source-destruction-notice' …
rubenvdlinde Oct 4, 2026
1dbb465
test(lti): a tool's detail view shows the six platform values with co…
rubenvdlinde Oct 4, 2026
e65351c
feat(lti): a tool's page shows the six platform values with copy acti…
rubenvdlinde Oct 4, 2026
36037a6
Merge pull request #2492 from ConductionNL/feat/source-destruction-no…
rubenvdlinde Oct 4, 2026
07b1168
Merge pull request #2494 from ConductionNL/feat/source-destruction-form
rubenvdlinde Oct 4, 2026
78d9af8
test(case-system): the source editor offers case-system and writes th…
rubenvdlinde Oct 4, 2026
25646a3
wip: saved by the coordinator after the 4 Oct 20:40 session limit (un…
rubenvdlinde Oct 4, 2026
77fd06e
Merge remote-tracking branch 'origin/development' into feat/lti-platf…
rubenvdlinde Oct 4, 2026
22fc21c
Merge remote-tracking branch 'origin/development' into docs/case-syst…
rubenvdlinde Oct 4, 2026
3f14c24
feat(case-system): the source editor offers case-system and writes ev…
rubenvdlinde Oct 4, 2026
f48bc1e
docs(openspec): tick the acknowledgement event and listener that land…
rubenvdlinde Oct 4, 2026
4cea532
test(sync): a push writes its outcome back onto the object that start…
rubenvdlinde Oct 4, 2026
c9721d0
test(sync): a refused create keeps today's contract behaviour (red)
rubenvdlinde Oct 4, 2026
a4ff96f
feat(sync): a push writes its outcome back onto the object that start…
rubenvdlinde Oct 4, 2026
92d334b
feat(dso): the STAM intake runs as an integriq consumer's account (#2…
rubenvdlinde Oct 4, 2026
777c1c4
Merge remote-tracking branch 'origin/development' into feat/lti-platf…
rubenvdlinde Oct 4, 2026
4ce9d1b
Merge remote-tracking branch 'origin/development' into docs/case-syst…
rubenvdlinde Oct 4, 2026
3fdce22
Merge remote-tracking branch 'origin/development' into feat/push-outc…
rubenvdlinde Oct 4, 2026
8f1045e
Merge pull request #2496 from ConductionNL/feat/lti-platform-details
rubenvdlinde Oct 4, 2026
d08bb22
Merge pull request #2498 from ConductionNL/docs/exchange-ack-ticks
rubenvdlinde Oct 4, 2026
4bb2cd8
Merge remote-tracking branch 'origin/development' into docs/case-syst…
rubenvdlinde Oct 4, 2026
a66b20e
Merge remote-tracking branch 'origin/development' into feat/push-outc…
rubenvdlinde Oct 4, 2026
fa253d4
test(integrations): the boot test mocks an IServerContainer, so NC 32…
rubenvdlinde Oct 4, 2026
05c4553
test(sync): the editor declares what a push writes back onto its object
rubenvdlinde Oct 4, 2026
9a3804e
feat(dso): the DSO activity table in OpenRegister, kept on the admin …
rubenvdlinde Oct 4, 2026
0d72057
Merge remote-tracking branch 'origin/development' into docs/case-syst…
rubenvdlinde Oct 4, 2026
b7a8642
feat(intake): Open Formulieren on the consumer model, and access rule…
rubenvdlinde Oct 4, 2026
c5beb20
feat(sync): the synchronization editor declares what a push writes back
rubenvdlinde Oct 4, 2026
89a0cef
Merge remote-tracking branch 'origin/development' into feat/push-outc…
rubenvdlinde Oct 4, 2026
785b727
Merge branch 'feat/push-outcome-write-back' into feat/write-back-editor
rubenvdlinde Oct 4, 2026
76989c2
test(zgw): a delivery becomes a document in the case system, in parts…
rubenvdlinde Oct 4, 2026
2a616ec
test(zgw): the push test drives the real updateTarget with a variable…
rubenvdlinde Oct 4, 2026
c058ba2
feat(zgw): a delivery becomes a document in the case system, in parts…
rubenvdlinde Oct 4, 2026
d90c862
Merge remote-tracking branch 'origin/development' into docs/case-syst…
rubenvdlinde Oct 4, 2026
381a7ff
Merge remote-tracking branch 'origin/development' into feat/push-outc…
rubenvdlinde Oct 4, 2026
a89d49e
fix(e2e): the DSO activity mapping spec, live-proven; tick task 6.1 (…
rubenvdlinde Oct 4, 2026
f6a607f
Merge remote-tracking branch 'origin/feat/push-outcome-write-back' in…
rubenvdlinde Oct 4, 2026
0fe7191
Merge pull request #2505 from ConductionNL/fix/boot-test-server-conta…
rubenvdlinde Oct 4, 2026
51dbc8f
Merge remote-tracking branch 'origin/feat/push-outcome-write-back' in…
rubenvdlinde Oct 4, 2026
d012770
docs(dso): a mapping guard refusal is a 422, and an unmapped verzoek …
rubenvdlinde Oct 4, 2026
6e7baaa
Merge pull request #2497 from ConductionNL/docs/case-system-operations
rubenvdlinde Oct 4, 2026
548b751
Merge remote-tracking branch 'origin/development' into feat/push-outc…
rubenvdlinde Oct 4, 2026
33ed88b
Merge remote-tracking branch 'origin/feat/push-outcome-write-back' in…
rubenvdlinde Oct 4, 2026
cd7da6f
Merge remote-tracking branch 'origin/feat/push-outcome-write-back' in…
rubenvdlinde Oct 4, 2026
843d2f3
test(zgw): a delivery can name its file in a field (red)
rubenvdlinde Oct 4, 2026
2e9ccc2
feat(zgw): zgwDocument.fileIdField delivers the file a field names (r…
rubenvdlinde Oct 4, 2026
ac04f78
test(sync): list-shaped conditions, as the schema and editor store th…
rubenvdlinde Oct 4, 2026
926f401
fix(sync): conditions stored as a list of JsonLogic groups filter again
rubenvdlinde Oct 4, 2026
9628521
Merge remote-tracking branch 'origin/fix/sync-conditions-list-shape' …
rubenvdlinde Oct 4, 2026
0b6438f
test(case-system): the delivery seeds, their mappings against Documen…
rubenvdlinde Oct 4, 2026
2899b93
feat(case-system): seed filinq-case-system-delivery and filinq-redact…
rubenvdlinde Oct 4, 2026
dc1fb07
docs(case-system): documents to the case system, design D5, Task 4 Im…
rubenvdlinde Oct 4, 2026
749014b
test(message-schema): a document OpenRegister reads back as an array …
rubenvdlinde Oct 4, 2026
470296d
style(zgw): keep the fileIdField refusal under 150 characters
rubenvdlinde Oct 4, 2026
94adcb2
fix(message-schema): check a document OpenRegister reads back as an a…
rubenvdlinde Oct 4, 2026
bf5048b
test(endpoint): an endpoint saved without a regex must route, and sav…
rubenvdlinde Oct 4, 2026
b204f2a
fix(endpoint): an endpoint saved without a regex routes, and saving s…
rubenvdlinde Oct 4, 2026
92043eb
Merge pull request #2501 from ConductionNL/feat/push-outcome-write-back
rubenvdlinde Oct 4, 2026
9bd5f45
Merge pull request #2508 from ConductionNL/feat/write-back-editor
rubenvdlinde Oct 4, 2026
58904c6
Merge pull request #2509 from ConductionNL/feat/zgw-document-delivery
rubenvdlinde Oct 4, 2026
cfeada3
Merge remote-tracking branch 'origin/development' into fix/message-sc…
rubenvdlinde Oct 5, 2026
6a3ea2f
Merge remote-tracking branch 'origin/development' into fix/endpoint-r…
rubenvdlinde Oct 5, 2026
ac23198
Merge remote-tracking branch 'origin/development' into fix/sync-condi…
rubenvdlinde Oct 5, 2026
73fcf13
Merge remote-tracking branch 'origin/fix/sync-conditions-list-shape' …
rubenvdlinde Oct 5, 2026
e0e8dbe
test(delivery): a StUF-ZDS delivery asks an identificatie, adds the d…
rubenvdlinde Oct 5, 2026
9068488
feat(delivery): a push with stufDocument adds the document to a StUF-…
rubenvdlinde Oct 5, 2026
0a22273
docs(delivery): the StUF-ZDS leg, design D6 and Task 3 ticked
rubenvdlinde Oct 5, 2026
22eeb76
feat(webhooks): signed public webhooks on the consumer model, and a n…
rubenvdlinde Oct 5, 2026
463cc5e
fix(endpoints): narrow the saving event before setModifiedData, as th…
rubenvdlinde Oct 5, 2026
3fbcc8e
Merge pull request #2517 from ConductionNL/fix/message-schema-array-d…
rubenvdlinde Oct 5, 2026
c20d390
Merge pull request #2515 from ConductionNL/fix/sync-conditions-list-s…
rubenvdlinde Oct 5, 2026
eda84bf
Merge pull request #2516 from ConductionNL/feat/case-system-delivery-…
rubenvdlinde Oct 5, 2026
d8e347f
refactor(delivery): phpmd, a shorter parameter name and faultText und…
rubenvdlinde Oct 5, 2026
eafb28c
Merge pull request #2518 from ConductionNL/fix/endpoint-regex-derived
rubenvdlinde Oct 5, 2026
c861142
Merge pull request #2522 from ConductionNL/feat/case-system-delivery-…
rubenvdlinde Oct 5, 2026
621c262
fix(intake): access rules for intake messages and verdicts, and the k…
rubenvdlinde Oct 5, 2026
c52ee13
fix(outbound,intake): opt-outs in an integriq table with expiring lin…
rubenvdlinde Oct 5, 2026
e19441f
spec: ask the opt-out list before every send (opt-out-before-send) (#…
rubenvdlinde Oct 5, 2026
b200534
feat(outbound): ask the opt-out list before every send (opt-out-befor…
rubenvdlinde Oct 5, 2026
5601bf2
test(auth): pin inbound credential outcomes through EndpointService a…
rubenvdlinde Oct 5, 2026
ac8c64d
test(auth): callers on OpenRegister's credential checks (red: callers…
rubenvdlinde Oct 5, 2026
441f67d
refactor(auth): run inbound credential checks in OpenRegister's Autho…
rubenvdlinde Oct 5, 2026
6239d85
spec(auth): consumer-auth-on-openregister change; static analysis rea…
rubenvdlinde Oct 5, 2026
f69e91a
test(stubs): drop OpenRegister's @spec lines from the copied auth cla…
rubenvdlinde Oct 5, 2026
d0bb84e
spec: an opt-out stops one purpose, and a probe asks without logging …
rubenvdlinde Oct 5, 2026
62d12c6
feat(outbound): an opt-out stops only its purpose, and a probe asks w…
rubenvdlinde Oct 5, 2026
7f219ee
test(cti): a contact moment for a call only when the agent asks, and …
rubenvdlinde Oct 5, 2026
3e4d96b
feat(cti): record a contact moment for an ended call when the agent a…
rubenvdlinde Oct 5, 2026
324c3f8
fix(nc35): register OpenRegister autoloading via public API
claude Oct 6, 2026
75a1b1f
style(nc35): align @param continuation in OpenRegisterAutoloader for …
claude Oct 6, 2026
5a99dfa
fix(l10n): translate the 50 DSO and consumer schema strings check:sch…
WilcoLouwerse Oct 6, 2026
7f3d0ac
docs(contract): point the four retour endpoints at their contract test
WilcoLouwerse Oct 6, 2026
45709a7
Merge pull request #2547 from ConductionNL/claude/nc35-support
rubenvdlinde Oct 6, 2026
729c490
spec(woo): 11 build specs for the capability programme, Hydra complia…
rubenvdlinde Oct 6, 2026
7817834
docs(adr): record inbound consumer authentication as an ADR-022 excep…
WilcoLouwerse Oct 6, 2026
dfd1e5e
Revert "docs(adr): record inbound consumer authentication as an ADR-0…
WilcoLouwerse Oct 6, 2026
48754dc
feat(setup): each example data card loads itself (#2566)
rubenvdlinde Oct 7, 2026
22448d4
feat(nav): Reports moves under Advanced in the navigation (#2567)
rubenvdlinde Oct 7, 2026
ed85061
docs(openspec): link 66 unbuilt capabilities to the changes that spec…
rubenvdlinde Oct 7, 2026
a876c66
docs(openspec): specify connector set sharing as far as decided
rubenvdlinde Oct 7, 2026
bb484ac
docs(openspec): spec links name the change, not its path
rubenvdlinde Oct 7, 2026
4820b6e
docs(openspec): link 148 built capabilities to the spec or change beh…
rubenvdlinde Oct 7, 2026
044cce7
docs(openspec): add nine capability rows that main specs deliver but …
rubenvdlinde Oct 7, 2026
55d814b
Merge pull request #2570 from ConductionNL/spec/capability-specs-and-…
rubenvdlinde Oct 7, 2026
23e0b9b
docs(openspec): competitor cells on spec-round rows read unknown, not…
rubenvdlinde Oct 7, 2026
254619d
Merge pull request #2572 from ConductionNL/spec/unknown-not-unchecked
rubenvdlinde Oct 7, 2026
b4dbdd3
docs(openspec): re-rate the five rows whose linked change was archived
rubenvdlinde Oct 7, 2026
45a865f
docs(openspec): specify third-party connector authorship after the fact
rubenvdlinde Oct 7, 2026
5e903e5
Merge pull request #2575 from ConductionNL/spec/rerate-and-own-specs
rubenvdlinde Oct 7, 2026
b3c7aa9
feat(digital-post): store digital post as a service account, redact t…
rubenvdlinde Oct 7, 2026
8358de9
docs(openspec): archive ten webhook and retour changes moved onto the…
rubenvdlinde Oct 7, 2026
8667ef1
docs(openspec): archive eight access, opt-out, directory and setup ch…
rubenvdlinde Oct 7, 2026
7f56811
Merge pull request #2577 from ConductionNL/spec/archive-pass
rubenvdlinde Oct 7, 2026
92aaec2
docs(openspec): a Berichtenbox client built on the interface Logius p…
rubenvdlinde Oct 7, 2026
ad8a2af
feat(berichtenbox): a live MijnOverheid Berichtenbox client, on the i…
rubenvdlinde Oct 7, 2026
c7131eb
docs(openspec): specify portal-idp-broker-config after decision 94
rubenvdlinde Oct 8, 2026
e77728f
Merge pull request #2601 from ConductionNL/spec/idp-broker-config
rubenvdlinde Oct 8, 2026
aed98ed
fix(dso): retire the verzoek-to-case handoff, the case system makes t…
rubenvdlinde Oct 8, 2026
dc9d817
docs(openspec): integriq halves of portaliq's open forms changes
rubenvdlinde Oct 8, 2026
b0f9d27
Merge pull request #2613 from ConductionNL/spec/open-forms-cross
rubenvdlinde Oct 8, 2026
e370a53
Merge remote-tracking branch 'origin/development' into feat/gate23-or…
rubenvdlinde Oct 8, 2026
d8439fe
Merge development into fix/woo589-beta-gates
rubenvdlinde Oct 8, 2026
61991c1
fix(l10n): translate the 12 Berichtenbox result strings that landed a…
WilcoLouwerse Oct 8, 2026
56c247f
fix(quality): make the two Berichtenbox tests pass in CI and run the …
WilcoLouwerse Oct 8, 2026
27c13cc
Merge pull request #2616 from ConductionNL/fix/woo589-beta-review
WilcoLouwerse Oct 8, 2026
a829c69
Merge pull request #2553 from ConductionNL/fix/woo589-beta-gates
WilcoLouwerse Oct 8, 2026
539970e
Merge pull request #2544 from ConductionNL/feat/gate23-or-authorization
WilcoLouwerse Oct 8, 2026
3271987
docs(woo): the build queue and the decisions the Woo specs cite, in t…
rubenvdlinde Oct 8, 2026
1985e53
fix(auth): refuse weak HMAC consumer secrets and warn when OpenRegist…
WilcoLouwerse Oct 8, 2026
1ead925
chore(parity): one feature list, every capability under one feature
rubenvdlinde Oct 8, 2026
3b01a46
Merge pull request #2620 from ConductionNL/spec/feature-normalisation
rubenvdlinde Oct 8, 2026
b2a0008
fix(quality): suppress phpmd StaticAccess on the entry-points setup c…
WilcoLouwerse Oct 8, 2026
0dbb6af
Merge pull request #2618 from ConductionNL/fix/woo589-jwt-regression
WilcoLouwerse Oct 8, 2026
e6ecb53
fix(auth): read a numeric iss with OpenRegister's string cast so the …
WilcoLouwerse Oct 8, 2026
8d58b1c
chore(parity): every spec under a feature, every capability on a screen
rubenvdlinde Oct 8, 2026
0470a16
chore(parity): reasons for four specs with no screen by nature
rubenvdlinde Oct 8, 2026
905b994
Merge pull request #2624 from ConductionNL/spec/specs-and-screens
rubenvdlinde Oct 8, 2026
541b86d
fix(auth): refuse a non-scalar iss in the weak-secret guard instead o…
WilcoLouwerse Oct 8, 2026
0b509ec
Merge pull request #2622 from ConductionNL/fix/woo589-numeric-iss
WilcoLouwerse Oct 8, 2026
b0a0962
style(setup-check): wrap the StaticAccess suppression so the line fit…
WilcoLouwerse Oct 8, 2026
1f1d1b2
Merge pull request #2627 from ConductionNL/fix/woo589-phpcs-line-length
WilcoLouwerse Oct 8, 2026
dbf95d5
fix(e2e): 23 of the 31 E2E reds on development, and three code bugs t…
rubenvdlinde Oct 9, 2026
af3136d
merge feat/cti-contact-moment (kcc-cti-adapter Task 3, unlanded) into…
rubenvdlinde Oct 9, 2026
63b6d10
feat(approvals): decide an Integriq approval in the shared task inbox
rubenvdlinde Oct 9, 2026
aeefb2a
feat(observability): send execution traces to an OpenTelemetry collector
rubenvdlinde Oct 9, 2026
8b49b42
fix(observability): literal translations for the mirror text and the …
rubenvdlinde Oct 9, 2026
0fe69e3
chore(demo): three call_event demo objects (ADR-111 rule 1) for the m…
rubenvdlinde Oct 9, 2026
d9c62df
Merge pull request #2631 from ConductionNL/build/openspecs-1
rubenvdlinde Oct 9, 2026
8132104
fix(approvals): resolve an approval only from its own mirror task
WilcoLouwerse Oct 9, 2026
c19fd31
fix(approvals): expire a record whose mirror ended without a decision
WilcoLouwerse Oct 9, 2026
efb0558
fix(observability): never let an inbound traceparent choose the trace…
WilcoLouwerse Oct 9, 2026
ab8672e
fix(observability): keep BSNs and URL credentials out of the exported…
WilcoLouwerse Oct 9, 2026
fa09f56
fix(observability): pause trace export during a collector outage
WilcoLouwerse Oct 9, 2026
e140a3c
refactor(observability,approvals): keep the review fixes within the p…
WilcoLouwerse Oct 9, 2026
73e44a7
Merge pull request #2635 from ConductionNL/fix/woo589-review-2631
WilcoLouwerse Oct 9, 2026
2e9c221
fix(review): #2154 f7 — a retry that is not yet due is put back as an…
rjzondervan Oct 9, 2026
4212edf
fix(review): #2154 f8 — the identifier mask lets a formatted BSN, an …
rjzondervan Oct 9, 2026
ec06475
fix(review): #2154 f10 — while the breaker is open, traces are discar…
rjzondervan Oct 9, 2026
dc1e7d8
fix(review): #2154 f9 — an outcome like `Rejected` closes the mirror …
rjzondervan Oct 9, 2026
992f266
fix(review): #2154 f8 — pre-push: mask a BSN with any separator or en…
rjzondervan Oct 9, 2026
58ae385
fix(review): #2154 f10 — pre-push: count skipped traces in the distri…
rjzondervan Oct 9, 2026
1374f45
fix(review): #2154 f10 — pre-push: name the skip count for what it is
rjzondervan Oct 9, 2026
be41140
Merge pull request #2638 from ConductionNL/review/pr-2154-fixes-r6
WilcoLouwerse Oct 9, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
4 changes: 4 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
Expand Up @@ -20,3 +20,7 @@ bin/console text eol=lf
LICENSE export-ignore
README.md export-ignore
update-deps.sh export-ignore

# The Logius Berichtenbox contract is vendored byte for byte (see lib/Adapters/Berichtenbox/Logius/SOURCE.md).
lib/Adapters/Berichtenbox/Logius/** -text
tests/fixtures/berichtenbox/logius/** -text
30 changes: 30 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,37 @@
# Changelog

## [Unreleased]
### Security
- A JWT consumer whose HMAC secret is shorter than the algorithm's hash output
(32 bytes for HS256, 48 for HS384, 64 for HS512; RFC 7518 §3.2) is refused
again. The web-token verifier this app used before the OpenRegister
delegation refused those secrets; OpenRegister's `hash_hmac()` did not, so
for that class of consumer any caller could mint a token. The bridge refuses
such an issuer before OpenRegister sees the token, and OpenRegister refuses
it too from the release that carries the same check.

### Changed
- Integriq's inbound authentication (endpoints, SCIM, Notificaties callbacks,
EUDI, LTI) is delegated to OpenRegister and needs OpenRegister 2.1.35 or
newer (the release with the public credential checks, OR#4361). On an older
OpenRegister every credentialed inbound call is refused with 401; a new
setup check in the administration overview says so before the first caller
does. Install or update OpenRegister first.

### Added
- An install guide for the ZGW consumer sets (`docs/features/zgw-sets.md`), and
the installer's refusals in Dutch and English. A schema bound to a ZGW store
holds the store's own shape: the sets no longer name a translator.
- Governed agent actions. A Hermiq agent can now run a synchronization, test a
Comment thread
remko48 marked this conversation as resolved.
synchronization or a source, list dead letters, and replay or discard them.
It can never create, edit or delete configuration. Run, replay and discard
each take two calls: the agent stages a batch, a person approves it in Hermiq,
and Integriq runs it only on Hermiq's signed verdict for that exact batch.
One approval runs one batch once. `listDeadLetters` returns no payloads, and
replay and discard take ids only. Two new rows in the action authorization
matrix, `sync-dead-letter.replay` and `sync-dead-letter.discard`, are seeded
for `admin` only. Every agent call writes one `agent_action` record.
See docs/features/ai-agent-tools.md. (hermiq-ai-tooling)
- `eolProduct` and `eolCycle` are now `eol_product` and `eol_cycle`. They were
the only two camelCase slugs among the fifty-five this app declares, which
made their object URLs the only ones an operator could not guess from the
Expand Down
597 changes: 597 additions & 0 deletions LANE-LOG.md

Large diffs are not rendered by default.

60 changes: 59 additions & 1 deletion appinfo/info.xml
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@
- 📋 Pas bedrijfsregels toe op endpoint-verkeer en houd een audit trail per object bij

]]></description>
<version>0.4.8-unstable.20260919141023</version>
<version>0.4.10-unstable.20261009090000</version>
<licence>EUPL-1.2</licence>
<author mail="info@conduction.nl" homepage="https://www.conduction.nl/">Conduction</author>
<namespace>Integriq</namespace>
Expand Down Expand Up @@ -113,6 +113,8 @@
one, so the page built to answer "is my sync still going?"
would answer it wrongly. -->
<job>OCA\Integriq\BackgroundJob\StaleRunSweepJob</job>
<!-- opt-out-before-send: the opt-out decision log is kept seven years. -->
<job>OCA\Integriq\BackgroundJob\OptOutLogRetentionJob</job>
<job>OCA\Integriq\BackgroundJob\EventRetryJob</job>
<job>OCA\Integriq\BackgroundJob\LtiKeyRetirementJob</job>
<job>OCA\Integriq\BackgroundJob\BankfeedSyncJob</job>
Expand All @@ -121,6 +123,10 @@
<job>OCA\Integriq\BackgroundJob\KissPullJob</job>
<job>OCA\Integriq\BackgroundJob\ApprovalTimeoutSweepJob</job>
<job>OCA\Integriq\BackgroundJob\IwmoIjwRetryJob</job>
<job>OCA\Integriq\BackgroundJob\RodRetryJob</job>
<job>OCA\Integriq\BackgroundJob\VerzuimloketRetryJob</job>
<job>OCA\Integriq\BackgroundJob\MailboxPollJob</job>
<job>OCA\Integriq\BackgroundJob\OsoRetryJob</job>
<job>OCA\Integriq\BackgroundJob\StufZknRetryJob</job>
<!-- document-generation-vendor-adapter: every five minutes, ask the
vendor again about a render it has not settled. This is what keeps
Expand All @@ -136,6 +142,12 @@
version moved, probes at most 25 linked sources, oldest first,
then resolves every connection row without an outbound call. -->
<job>OCA\Integriq\BackgroundJob\ConnectionHealthJob</job>
<!-- observability-connection-run-summary: every five minutes. Counts
failed calls, failed runs and invalid objects against the
thresholds on sources and synchronizations, opens a
connection_alert above one and clears it once the count falls
back. Sources and synchronizations without thresholds are skipped. -->
<job>OCA\Integriq\BackgroundJob\ConnectionThresholdJob</job>
<!-- registry-subscription-connector: every fifteen minutes. Asks each
registry binding what changed about the identities it follows and
posts that to OpenRegister. Nothing about the changed record is
Expand All @@ -147,6 +159,7 @@
arrived to the document intake inbox. -->
<job>OCA\Integriq\BackgroundJob\DigitalPostStatusJob</job>
<job>OCA\Integriq\BackgroundJob\DigitalPostInboundJob</job>
<job>OCA\Integriq\BackgroundJob\UwlrEduVRetryJob</job>
</background-jobs>

<!-- ⚠️ CHILD ORDER IS FIXED BY THE APP STORE SCHEMA, and it is NOT the order
Expand Down Expand Up @@ -249,6 +262,10 @@
install has no stored jobs and it is a no-op there. -->
<step>OCA\Integriq\Repair\MigrateStoredJobClasses</step>
<step>OCA\Integriq\Repair\InitializeActions</step>
<!-- D33: broadens exchange.read only on an instance that still has the
untouched ["admin"] default. AFTER InitializeActions, so a fresh install
is seeded first and this step then has nothing to do. Never throws. -->
<step>OCA\Integriq\Repair\BroadenExchangeReadDefault</step>
<step>OCA\Integriq\Repair\MigrateLegacyStorage</step>
<step>OCA\Integriq\Repair\FlagSourceSecretsWriteOnly</step>
<!-- ocon#151 phase C / ADR-064: RUNS the inline-secret migration (mint,
Expand Down Expand Up @@ -332,6 +349,32 @@
idempotent, so nothing broke, but the second registration's
stated reason was false and the placement above is the
deliberate one (integriq#1983 review 5278999788). -->
<!-- identity-broker-browser-login: the disabled portaliq consumer,
so enabling it is one occ command. Never overwrites an entry. -->
<step>OCA\Integriq\Repair\SeedIdpBrokerConsumers</step>
<!-- dso-intake-through-an-integriq-connection: the dso_pki_* app config
becomes the one dso-stam consumer, with an empty account. Runs after
the register import, so the consumer schema exists. Idempotent. -->
<step>OCA\Integriq\Repair\MigrateDsoStamConnection</step>
<!-- openformulieren-intake-through-an-integriq-connection: the webhook
trust of the open-formulieren source becomes the one
open-formulieren consumer, with an empty account. Idempotent. -->
<step>OCA\Integriq\Repair\MigrateOpenFormulierenConnection</step>
<!-- public-webhooks-on-the-consumer-model: the webhook trust of the
peppol, sms, rod, oso, uwlr-eduv, verzuimloket, iwmo-ijw, stuf-zkn
and intake-channel sources becomes one consumer per webhook, with
an empty account. Idempotent; the sources are left as they are. -->
<step>OCA\Integriq\Repair\MigrateWebhookConnections</step>
<!-- bsn-intake-records-access-rules: the intake and handler groups the
dso_verzoek and openformulieren_submission authorization blocks
name, and each connection's account in its intake group. Runs
after the two connection migrations. Idempotent. -->
<step>OCA\Integriq\Repair\ProvisionIntakeGroups</step>
<!-- opt-outs-in-an-app-table-and-routing-rules-read-as-config: copies
the recipient_opt_out objects into integriq_opt_outs, which the
migration Version2Date20261005100000 created. Post-migration only:
a first install has nothing to copy. Idempotent. -->
<step>OCA\Integriq\Repair\MigrateOptOutsToTable</step>
Comment thread
rjzondervan marked this conversation as resolved.
</post-migration>
<!-- ocon#1180. A FIRST install runs neither `postSchemaChange` nor the
`post-migration` steps above: `Installer::installAppLastSteps()` passes
Expand Down Expand Up @@ -428,6 +471,10 @@
steps. -->
<step>OCA\Integriq\Repair\MigrateStoredJobClasses</step>
<step>OCA\Integriq\Repair\InitializeActions</step>
<!-- D33: broadens exchange.read only on an instance that still has the
untouched ["admin"] default. AFTER InitializeActions, so a fresh install
is seeded first and this step then has nothing to do. Never throws. -->
<step>OCA\Integriq\Repair\BroadenExchangeReadDefault</step>
<step>OCA\Integriq\Repair\MigrateLegacyStorage</step>
<step>OCA\Integriq\Repair\MaterializeCatalogItems</step>
<!-- connection-registry D5: every enabled app's
Expand All @@ -443,6 +490,12 @@
exists. Whether a brand-new instance should ship without those
fields is a product decision, tracked separately, not one this
fix should take by side effect. -->
<!-- identity-broker-browser-login: the disabled portaliq consumer,
so enabling it is one occ command. Never overwrites an entry. -->
<step>OCA\Integriq\Repair\SeedIdpBrokerConsumers</step>
<!-- bsn-intake-records-access-rules: a fresh instance gets the four
intake and handler groups too. -->
<step>OCA\Integriq\Repair\ProvisionIntakeGroups</step>
</install>
</repair-steps>

Expand Down Expand Up @@ -482,6 +535,10 @@
surfaced, never silently removed, so this is human-invoked and dry-run by
default. -->
<command>OCA\Integriq\Command\DedupeContracts</command>
<!-- stop-cloudevent-recursion section 5: deletes the CloudEvents generated from
other CloudEvents (source /objects/com.nextcloud.openregister.object.*) and the
event messages whose event is gone. Dry run unless the apply option is given. -->
<command>OCA\Integriq\Command\PurgeEventRecursion</command>
<!-- flow-native-synchronization task 3.3: renders one job as a generated
trigger schedule flow document, or names the features no flow node can
express. Same contract as the synchronization renderer above: the
Expand All @@ -500,6 +557,7 @@
(XML comments must not contain a double hyphen, so the flags are
not written with their leading dashes here.) -->
<command>OCA\Integriq\Command\FlowStepsToGraph</command>
<command>OCA\Integriq\Command\IdpConsumerCommand</command>
</commands>

<settings>
Expand Down
Loading
Loading