Skip to content

Commit 29875bc

Browse files
authored
Merge pull request #194 from ConductionNL/feature/openspec-implementation
feat: OpenSpec implementation
2 parents 81243ee + 9c686af commit 29875bc

95 files changed

Lines changed: 4166 additions & 1257 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

.claude/commands/test.md

Lines changed: 858 additions & 0 deletions
Large diffs are not rendered by default.

.claude/commands/update.md

Lines changed: 454 additions & 0 deletions
Large diffs are not rendered by default.

.claude/skills/test-architectuur-expert.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -48,6 +48,8 @@ Sarah's account is in the Default Organisation (expected for VNG roles). The org
4848
| Issue | Title | Test Step |
4949
|-------|-------|-----------|
5050
| #148 | (VNGR) GEMMA-architectuur opvraagbaar met API | Step 12 |
51+
| #412 | Niet alle AMEF views hebben documentatie | Step 15 |
52+
| #413 | Views testen vs softwarecatalogus scope | Step 19 |
5153

5254
## Acceptance Criteria Reference
5355

.claude/skills/test-bezoeker.md

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -47,6 +47,11 @@ This persona tests everything an **unauthenticated user** sees. The search page
4747
| #448 | Overzichtspagina's: vormgeving inconsistent | Verify dienst/koppeling detail pages match applicatie layout |
4848
| #453 | Zoeken: filters van slag met filter Type=Koppeling | Verify Type=Koppeling filter correctly scopes other facets |
4949
| #455 | Tabblad koppelingen en contactpersonen publiekelijk niet getoond | Verify Koppelingen and Contactpersonen tabs visible on public app detail pages |
50+
| #205 | Gedepubliceerde applicatie nog vindbaar | Verify depublished applications do NOT appear in public search |
51+
| #333 | UUID uit filters refcomp en standaarden | Verify reference component and standards filters show names, not UUIDs |
52+
| #398 | Zoeken: Filter met UUID's onder leveranciers | Verify leverancier filter shows readable names, not UUIDs |
53+
| #438 | Zoeken: verschillende vormgeving Diensten na filteren | Verify dienst card layout is consistent across filter combinations |
54+
| #440 | Zoeken: Organisatietype teveel aan opties | Verify Organisatietype filter shows only 4 options: gemeente, samenwerking, leverancier, community |
5055

5156
## Acceptance Criteria Reference
5257

.claude/skills/test-functioneel-beheerder.md

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -81,6 +81,22 @@ Peter's account (`peter.vandijk@test.nl`) is in the Default Organisation. **Impo
8181
| #187 | Tekstvoorstellen (remaining text changes) | Step 7 |
8282
| #449 | Handleiding facets configureren klopt niet | Step 21 |
8383
| #450 | Back-end: Icoon voor publiceren verwijderen | Step 6 |
84+
| #23 | Data migratie verificatie | Step 19 |
85+
| #65 | Collega's toegang geven (contactpersonen beheer) | Step 5 |
86+
| #182 | Algemene voorwaarden, Privacyverklaring, Disclaimer, FAQ | Step 21 |
87+
| #188 | Aanmeldproces | Step 3 |
88+
| #208 | NC Dashboard organisatie overzicht table issue | Step 23 |
89+
| #209 | Help knop gaat naar niet bestaande pagina | Step 23 |
90+
| #231 | AMEFF exports foutmelding bij import in Archi | Step 24 |
91+
| #255 | Dashboard welkomstekst | Step 23 |
92+
| #268 | Dashboard tekst aanpassen na inloggen | Step 23 |
93+
| #329 | Teksten SWC definitief (PowerPoint vergelijking) | Step 7 |
94+
| #336 | Views | Step 22 |
95+
| #338 | Dashboard en Inloggen | Step 23 |
96+
| #339 | Activeren gebruikers | Step 3 |
97+
| #411 | Vraag: Required eisen uitgezet voor dataimport | Step 19 |
98+
| #417 | Vraag: Andere email adressen voor contactpersonen | Step 5 |
99+
| #431 | Aanmeldproces: tussenvoegsel niet meer aanwezig | Step 3 |
84100

85101
## Acceptance Criteria Reference
86102

.claude/skills/test-gemeente.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -92,6 +92,10 @@ Maria's active organization is **Test Gemeente**. The internal Nextcloud org UUI
9292
| #346 | Zoeken: paginering werkt niet | Step 14 |
9393
| #347 | Zoeken: Dienstkaartje toont array | **MOVED → bezoeker** (public search page) |
9494
| #349 | Zoeken: UUID's onder standaarden filter | Step 14 |
95+
| #261 | Wizards: pas te testen na RBAC | Step 10 |
96+
| #311 | Altijd inlog-account en -organisatie tonen | Step 4 |
97+
| #331 | Koppeling relatie Applicatie | Step 11 |
98+
| #418 | Performance: applicaties dropdown traag bij dienst wizard | Step 10 |
9599

96100
## Acceptance Criteria Reference
97101

.claude/skills/test-leverancier.md

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -137,6 +137,23 @@ This agent tests the following steps from the test flow (`testen.md`):
137137
| #454 | Wizard koppelingen: Reeds bestaande koppelingen voor worden niet gevonden | Step 11 |
138138
| #456 | Consistentie in werking van wizards | Step 7 |
139139
| #457 | Koppeling: verwijderen geeft een 400-error | Step 11 |
140+
| #6 | Standaarden registreren bij pakket | Step 16 |
141+
| #73 | Meerdere contactpersonen registreren en koppelen | Step 5 |
142+
| #335 | Diensten Wizards | Step 9 |
143+
| #405 | Applicatie verwijderen die door dienst ondersteund wordt | Step 7 |
144+
| #415 | Spelling "Applicatie informatie" | Step 7 |
145+
| #430 | Beheertabel toont kolom Compliancy met applicatienamen | Step 7 |
146+
| #432 | Koppeling naamgeving niet consistent | Step 11 |
147+
| #433 | Import koppelingen lijkt niet goed te gaan | Step 11 |
148+
| #434 | Eerste account leverancier niet beschikbaar als contactpersoon | Step 5 |
149+
| #436 | Error bij ophalen applicatie overzicht | Step 7 |
150+
| #439 | Error na openen Applicatie-overzicht | Step 7 |
151+
| #441 | Mapping versies gaat niet goed bij geimporteerde applicaties | Step 7 |
152+
| #442 | Opgevoerd document wijzigt van naam naar bewijs_<getal> | Step 7 |
153+
| #419 | Standaarden en standaard-versie niet goed gekoppeld | Step 16 |
154+
| #420 | Gemeente-applicaties verschijnen niet in aanbod-endpoint | Step 12 |
155+
| #435 | Import: niet alle geimporteerde applicaties zichtbaar | Step 7 |
156+
| #437 | Geimporteerde leverancier: koppeling opslaan geeft foutmelding | Step 11 |
140157

141158
## Acceptance Criteria Reference
142159

.claude/skills/test-security-officer.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -78,6 +78,7 @@ The authoritative RBAC rules are in `softwarecatalog/lib/Settings/softwarecatalo
7878
| #315 | Hoge prioriteit: Zoekpagina toont deel gemeentelijk applicatielandschap | Step 14 |
7979
| #447 | Zoeken: concept leverancier zonder VNG triage direct vindbaar | Step 3 |
8080
| #455 | Tabblad koppelingen en contactpersonen publiekelijk niet getoond — RBAC? | Step 12 |
81+
| #414 | Mogen deelnemers gebruiksobjecten lezen | Step 12 |
8182

8283
## Testing Hints for Specific Issues
8384

README.md

Lines changed: 150 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -189,6 +189,69 @@ Full documentation is available at **[softwarecatalog.app](https://softwarecatal
189189
| [User Guide](docs/USER_GUIDE.md) | End-user and administrator guide |
190190
| [Configuration](docs/CONFIGURATION.md) | Setup instructions and troubleshooting |
191191

192+
## Testing
193+
194+
Software Catalogus is tested through three complementary layers that together provide comprehensive quality assurance.
195+
196+
### Code Quality (Conduction Quality Workflow)
197+
198+
Every commit runs through the [Conduction quality workflow](https://github.com/ConductionNL/softwarecatalog/actions) — a strict CI/CD pipeline that enforces:
199+
200+
- **PHP Lint** — syntax validation
201+
- **PHPCS** — coding standards (PEAR + PSR-12 + custom Conduction rules, including forbidden functions and named parameter enforcement)
202+
- **PHPMD** — mess detection (clean code, code size, design, naming, and unused code rules)
203+
- **Psalm** — static analysis (level 4, with unused code detection)
204+
- **PHPStan** — static analysis (level 5)
205+
- **PHPUnit** — unit and integration tests (strict mode: `failOnRisky`, output detection, execution order by dependency)
206+
- **ESLint** — JavaScript/Vue linting
207+
- **Stylelint** — CSS linting
208+
209+
All checks must pass before a release. Run locally with `composer check:strict` (full PHP pipeline) or `npm run lint` (frontend).
210+
211+
### API Tests (454 Assertions)
212+
213+
A dedicated Newman/Postman collection validates the entire API surface with **454 automated assertions** across 334 requests organized in 11 test folders:
214+
215+
| Folder | Coverage |
216+
|--------|----------|
217+
| Setup | Test data creation and environment validation |
218+
| Public API & Search | Faceted search, pagination, UUID resolution |
219+
| RBAC & Organization Scoping | Multi-tenant access control |
220+
| Object CRUD | Create, read, update, delete across all entity types |
221+
| Data Migration & Import | CSV/Magic Mapper imports |
222+
| ArchiMate & Views | GEMMA architecture elements and relations |
223+
| User Profile & Authentication | Login, password, session management |
224+
| Export & Reporting | CSV and Excel export |
225+
| Aanbod & Gebruik | Supply and usage registration |
226+
| Data Quality & Naming | Naming conventions and data consistency |
227+
| Glossary & Content | Glossary terms and CMS content |
228+
229+
Run with: `npx newman run tests/postman_collection.json -e tests/api/.env_00_-_Setup.json`
230+
231+
### Agentic Browser Tests (1,026 Acceptance Criteria)
232+
233+
AI-driven browser agents test the application from **7 real-world persona perspectives**, each with their own Nextcloud account, role-based permissions, and test scenarios. The agents use Playwright to interact with the live application exactly as a human would — navigating pages, filling forms, clicking buttons, and verifying results.
234+
235+
| Persona | Role | Focus |
236+
|---------|------|-------|
237+
| Leverancier | Software supplier | Wizard flows, application/dienst/koppeling management |
238+
| Gemeente | Municipal user | Search, filters, wizard text, data quality |
239+
| Security Officer | Security auditor | RBAC enforcement, data exposure, access control |
240+
| Functioneel Beheerder | Functional administrator | Configuration, backend management, exports |
241+
| Samenwerking | Collaboration partner | Cross-organization features, member delegation |
242+
| Bezoeker | Anonymous visitor | Public access, unauthenticated search, privacy |
243+
| Architectuur Expert | Enterprise architect | GEMMA API, ArchiMate views, OAS documentation |
244+
245+
Together these agents validate **1,026 acceptance criteria** across 137 GitHub issues, covering end-to-end user journeys, RBAC boundaries, wizard completions, and data integrity. Each persona receives a dedicated skill file (`.claude/skills/test-{persona}.md`) containing their assigned issues and test instructions. Results are stored in `test-results/` with per-persona reports.
246+
247+
Run with: `.claude/commands/test.md` (all tests) or individual persona skills.
248+
249+
### Issue Management & Acceptance Criteria
250+
251+
VNG did not begin filing issues for the Softwarecatalogus until October 2025, and when they did, the issues contained only descriptions — no structured acceptance criteria. Since our agentic test pipeline requires explicit, verifiable acceptance criteria to determine pass/fail outcomes, we set up a parallel system of **markdown shadow issues** in `test-results/api/issues/`. Each shadow issue mirrors a VNG GitHub issue but adds the structured acceptance criteria (AC1, AC2, …) that our API and browser agents need.
252+
253+
The master file `issues.md` tracks all 137 IGS (In Review/Scoped) issues with their **1,026 acceptance criteria**, each tagged by test type (`[API]`, `[UI]`, or `[HYBRID]`). Of these, **316 criteria** are covered by the automated Newman/Postman suite, while the remainder are validated by the persona-based browser agents. This approach maintains full traceability back to the original VNG issues while giving our test automation the concrete, testable assertions it requires.
254+
192255
## Standards & Compliance
193256

194257
- **Data standard:** GEMMA Softwarecatalogus (VNG)
@@ -198,11 +261,94 @@ Full documentation is available at **[softwarecatalog.app](https://softwarecatal
198261
- **Audit trail:** Full change history on all objects
199262
- **Localization:** English and Dutch
200263

201-
## Related Apps
264+
## Required Repositories
265+
266+
The Softwarecatalogus is not a standalone application — it runs as a Nextcloud app backed by several other apps, with a separate React-based public frontend.
267+
268+
| Repository | Role | Required |
269+
|-----------|------|----------|
270+
| [OpenRegister](https://github.com/ConductionNL/openregister) | Data storage layer — all objects (applications, modules, organizations, contacts) are stored as JSON objects in OpenRegister. Also provides the Docker environment (`docker-compose.yml`). | Yes |
271+
| [OpenCatalogi](https://github.com/ConductionNL/opencatalogi) | Publication and catalog management — handles public search, faceted filtering, and federated publishing of catalog data. | Yes |
272+
| [NL Design](https://github.com/ConductionNL/nldesign) | Design token theming — applies Dutch government (NL Design System) styling via CSS custom properties. | Yes |
273+
| [Tilburg WOO UI](https://github.com/ConductionNL/tilburg-woo-ui) | **Separate public frontend** — a React/Preact SPA that serves as the citizen-facing interface at `localhost:3000`. Provides public search, detail pages, and registration forms (product, usage, integration, organization). This is **not** a Nextcloud app but a standalone web application that communicates with Nextcloud via the OpenRegister and OpenCatalogi APIs. | Yes |
274+
| [MyDash](https://github.com/ConductionNL/mydash) | Dashboard widgets for the Nextcloud dashboard page. | Recommended |
275+
276+
## Installation
277+
278+
### 1. Start the Docker environment
279+
280+
The Docker environment is managed from the OpenRegister repository:
281+
282+
```bash
283+
cd openregister
284+
docker compose up -d # Core: PostgreSQL + Nextcloud + n8n
285+
docker compose --profile ui up -d # Adds the Tilburg WOO UI frontend
286+
```
287+
288+
This starts:
289+
- **Nextcloud** at `http://localhost:8080` (admin:admin)
290+
- **Tilburg WOO UI** at `http://localhost:3000` (public frontend)
291+
- **PostgreSQL 16** with pgvector and pg_trgm extensions
292+
- **n8n** for workflow automation
293+
294+
### 2. Install Nextcloud apps (order matters)
295+
296+
Apps must be enabled in this order because of dependency chains:
297+
298+
```bash
299+
# 1. OpenRegister — foundation, must be first
300+
docker exec -u www-data nextcloud php occ app:enable openregister
301+
302+
# 2. OpenCatalogi — depends on OpenRegister for publication data
303+
docker exec -u www-data nextcloud php occ app:enable opencatalogi
304+
305+
# 3. NL Design — theming (no hard dependencies, but should be early)
306+
docker exec -u www-data nextcloud php occ app:enable nldesign
307+
308+
# 4. Software Catalogus — depends on OpenRegister and OpenCatalogi
309+
docker exec -u www-data nextcloud php occ app:enable softwarecatalog
310+
311+
# 5. MyDash — optional, for dashboard widgets
312+
docker exec -u www-data nextcloud php occ app:enable mydash
313+
```
314+
315+
### 3. Import data
316+
317+
The Softwarecatalogus requires register schemas and seed data to function. Import the configurations via the OpenRegister Magic Mapper:
318+
319+
```bash
320+
# Import the softwarecatalogus register configuration
321+
# This creates the voorzieningen register with all required schemas
322+
# (module, dienst, organisatie, contactpersoon, contract, etc.)
323+
curl -X POST "http://localhost:8080/index.php/apps/openregister/api/configurations?force=true" \
324+
-u admin:admin \
325+
-H "Content-Type: application/json" \
326+
-d @softwarecatalog/configurations/softwarecatalogus_register.json
327+
```
328+
329+
For a complete test environment with users, organizations, and sample data:
330+
331+
```bash
332+
bash softwarecatalog/test-setup.sh
333+
```
334+
335+
This creates 7 test users across 4 organizations (leverancier, gemeente, samenwerking, admin), seeds contact persons and sample applications, and verifies RBAC scoping.
336+
337+
### 4. Build frontends
338+
339+
```bash
340+
# Nextcloud app frontend (Vue 2)
341+
cd softwarecatalog && npm install && npm run build
342+
343+
# Public frontend (React) — only needed if not using Docker
344+
cd tilburg-woo-ui && yarn install && yarn build
345+
```
346+
347+
## Support
348+
349+
For support, contact us at [support@conduction.nl](mailto:support@conduction.nl).
202350

203-
- **[OpenRegister](https://github.com/ConductionNL/openregister)** — Object storage layer (required dependency)
204-
- **[OpenCatalogi](https://github.com/ConductionNL/opencatalogi)** — Publication and catalog management
205-
- **[NL Design](https://github.com/ConductionNL/nldesign)** — Design token theming for Dutch government standards
351+
For a Service Level Agreement (SLA), contact [sales@conduction.nl](mailto:sales@conduction.nl).
206352

207353
## License
208354

appinfo/info.xml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,8 @@
2121
**Requires:** [OpenRegister](https://apps.nextcloud.com/apps/openregister) (install from the [Nextcloud App Store](https://apps.nextcloud.com/apps/openregister)).
2222
2323
Free and open source under the EUPL license.
24+
25+
**Support:** For support, contact support@conduction.nl. For a Service Level Agreement (SLA), contact sales@conduction.nl.
2426
]]></description>
2527
<description lang="nl"><![CDATA[Software Catalogus brengt gestructureerd softwareportfoliobeheer naar Nextcloud. Houd al je applicaties, modules en koppelingen bij — en deel ze via een gefedereerd open data netwerk.
2628
@@ -37,6 +39,8 @@ Free and open source under the EUPL license.
3739
**Vereist:** [OpenRegister](https://apps.nextcloud.com/apps/openregister) (installeer via de [Nextcloud App Store](https://apps.nextcloud.com/apps/openregister)).
3840
3941
Vrij en open source onder de EUPL-licentie.
42+
43+
**Ondersteuning:** Voor ondersteuning, neem contact op via support@conduction.nl. Voor een Service Level Agreement (SLA), neem contact op via sales@conduction.nl.
4044
]]></description>
4145
<version>0.1.140</version>
4246
<licence>agpl</licence>

0 commit comments

Comments
 (0)