Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
17 commits
Select commit Hold shift + click to select a range
45ee319
feat: Add OpenRegister dependency check and enforce scoped CSS
rubenvdlinde Mar 18, 2026
4205cba
feat: Add support contact info to app description and README
rubenvdlinde Mar 18, 2026
fe8df12
feat: Standardize settings with CnVersionInfoCard, fix section icon
rubenvdlinde Mar 18, 2026
db97fca
fix: Add @nextcloud/dialogs webpack alias to fix local dev build
rubenvdlinde Mar 18, 2026
f6284dd
fix: Import t/n translation functions in settings entry point
rubenvdlinde Mar 18, 2026
b84b65f
fix: Pass app version from IAppManager instead of deprecated OCP\App
rubenvdlinde Mar 18, 2026
4aa98a4
feat: Add i18n support — fix imports, correct app IDs, Composition AP…
rubenvdlinde Mar 18, 2026
b8010ce
chore: Update test results and add l10n bundles
rubenvdlinde Mar 18, 2026
28d6358
fix: Resolve Psalm errors in softwarecatalog
rubenvdlinde Mar 18, 2026
1f80726
docs: Add testing, dependencies, and installation sections to README
rubenvdlinde Mar 19, 2026
af81e0f
fix: Resolve all PHPCS errors — auto-fix formatting + manual fixes fo…
rubenvdlinde Mar 19, 2026
e96ff29
style: Apply PHPCS auto-formatting
rubenvdlinde Mar 19, 2026
c37eff3
style: Apply PHPCS auto-formatting
rubenvdlinde Mar 19, 2026
d186ba4
style: Apply PHPCS auto-formatting
rubenvdlinde Mar 19, 2026
63ddc87
fix: Resolve all PHPStan errors — fix named param mismatches, undefin…
rubenvdlinde Mar 19, 2026
defea1b
Merge remote-tracking branch 'origin/development' into feature/opensp…
rubenvdlinde Mar 19, 2026
9c686af
fix: Resolve PHPCS and Psalm errors after merge with development
rubenvdlinde Mar 19, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
858 changes: 858 additions & 0 deletions .claude/commands/test.md

Large diffs are not rendered by default.

454 changes: 454 additions & 0 deletions .claude/commands/update.md

Large diffs are not rendered by default.

2 changes: 2 additions & 0 deletions .claude/skills/test-architectuur-expert.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,8 @@ Sarah's account is in the Default Organisation (expected for VNG roles). The org
| Issue | Title | Test Step |
|-------|-------|-----------|
| #148 | (VNGR) GEMMA-architectuur opvraagbaar met API | Step 12 |
| #412 | Niet alle AMEF views hebben documentatie | Step 15 |
| #413 | Views testen vs softwarecatalogus scope | Step 19 |

## Acceptance Criteria Reference

Expand Down
5 changes: 5 additions & 0 deletions .claude/skills/test-bezoeker.md
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,11 @@ This persona tests everything an **unauthenticated user** sees. The search page
| #448 | Overzichtspagina's: vormgeving inconsistent | Verify dienst/koppeling detail pages match applicatie layout |
| #453 | Zoeken: filters van slag met filter Type=Koppeling | Verify Type=Koppeling filter correctly scopes other facets |
| #455 | Tabblad koppelingen en contactpersonen publiekelijk niet getoond | Verify Koppelingen and Contactpersonen tabs visible on public app detail pages |
| #205 | Gedepubliceerde applicatie nog vindbaar | Verify depublished applications do NOT appear in public search |
| #333 | UUID uit filters refcomp en standaarden | Verify reference component and standards filters show names, not UUIDs |
| #398 | Zoeken: Filter met UUID's onder leveranciers | Verify leverancier filter shows readable names, not UUIDs |
| #438 | Zoeken: verschillende vormgeving Diensten na filteren | Verify dienst card layout is consistent across filter combinations |
| #440 | Zoeken: Organisatietype teveel aan opties | Verify Organisatietype filter shows only 4 options: gemeente, samenwerking, leverancier, community |

## Acceptance Criteria Reference

Expand Down
16 changes: 16 additions & 0 deletions .claude/skills/test-functioneel-beheerder.md
Original file line number Diff line number Diff line change
Expand Up @@ -81,6 +81,22 @@ Peter's account (`peter.vandijk@test.nl`) is in the Default Organisation. **Impo
| #187 | Tekstvoorstellen (remaining text changes) | Step 7 |
| #449 | Handleiding facets configureren klopt niet | Step 21 |
| #450 | Back-end: Icoon voor publiceren verwijderen | Step 6 |
| #23 | Data migratie verificatie | Step 19 |
| #65 | Collega's toegang geven (contactpersonen beheer) | Step 5 |
| #182 | Algemene voorwaarden, Privacyverklaring, Disclaimer, FAQ | Step 21 |
| #188 | Aanmeldproces | Step 3 |
| #208 | NC Dashboard organisatie overzicht table issue | Step 23 |
| #209 | Help knop gaat naar niet bestaande pagina | Step 23 |
| #231 | AMEFF exports foutmelding bij import in Archi | Step 24 |
| #255 | Dashboard welkomstekst | Step 23 |
| #268 | Dashboard tekst aanpassen na inloggen | Step 23 |
| #329 | Teksten SWC definitief (PowerPoint vergelijking) | Step 7 |
| #336 | Views | Step 22 |
| #338 | Dashboard en Inloggen | Step 23 |
| #339 | Activeren gebruikers | Step 3 |
| #411 | Vraag: Required eisen uitgezet voor dataimport | Step 19 |
| #417 | Vraag: Andere email adressen voor contactpersonen | Step 5 |
| #431 | Aanmeldproces: tussenvoegsel niet meer aanwezig | Step 3 |

## Acceptance Criteria Reference

Expand Down
4 changes: 4 additions & 0 deletions .claude/skills/test-gemeente.md
Original file line number Diff line number Diff line change
Expand Up @@ -92,6 +92,10 @@ Maria's active organization is **Test Gemeente**. The internal Nextcloud org UUI
| #346 | Zoeken: paginering werkt niet | Step 14 |
| #347 | Zoeken: Dienstkaartje toont array | **MOVED → bezoeker** (public search page) |
| #349 | Zoeken: UUID's onder standaarden filter | Step 14 |
| #261 | Wizards: pas te testen na RBAC | Step 10 |
| #311 | Altijd inlog-account en -organisatie tonen | Step 4 |
| #331 | Koppeling relatie Applicatie | Step 11 |
| #418 | Performance: applicaties dropdown traag bij dienst wizard | Step 10 |

## Acceptance Criteria Reference

Expand Down
17 changes: 17 additions & 0 deletions .claude/skills/test-leverancier.md
Original file line number Diff line number Diff line change
Expand Up @@ -137,6 +137,23 @@ This agent tests the following steps from the test flow (`testen.md`):
| #454 | Wizard koppelingen: Reeds bestaande koppelingen voor worden niet gevonden | Step 11 |
| #456 | Consistentie in werking van wizards | Step 7 |
| #457 | Koppeling: verwijderen geeft een 400-error | Step 11 |
| #6 | Standaarden registreren bij pakket | Step 16 |
| #73 | Meerdere contactpersonen registreren en koppelen | Step 5 |
| #335 | Diensten Wizards | Step 9 |
| #405 | Applicatie verwijderen die door dienst ondersteund wordt | Step 7 |
| #415 | Spelling "Applicatie informatie" | Step 7 |
| #430 | Beheertabel toont kolom Compliancy met applicatienamen | Step 7 |
| #432 | Koppeling naamgeving niet consistent | Step 11 |
| #433 | Import koppelingen lijkt niet goed te gaan | Step 11 |
| #434 | Eerste account leverancier niet beschikbaar als contactpersoon | Step 5 |
| #436 | Error bij ophalen applicatie overzicht | Step 7 |
| #439 | Error na openen Applicatie-overzicht | Step 7 |
| #441 | Mapping versies gaat niet goed bij geimporteerde applicaties | Step 7 |
| #442 | Opgevoerd document wijzigt van naam naar bewijs_<getal> | Step 7 |
| #419 | Standaarden en standaard-versie niet goed gekoppeld | Step 16 |
| #420 | Gemeente-applicaties verschijnen niet in aanbod-endpoint | Step 12 |
| #435 | Import: niet alle geimporteerde applicaties zichtbaar | Step 7 |
| #437 | Geimporteerde leverancier: koppeling opslaan geeft foutmelding | Step 11 |

## Acceptance Criteria Reference

Expand Down
1 change: 1 addition & 0 deletions .claude/skills/test-security-officer.md
Original file line number Diff line number Diff line change
Expand Up @@ -78,6 +78,7 @@ The authoritative RBAC rules are in `softwarecatalog/lib/Settings/softwarecatalo
| #315 | Hoge prioriteit: Zoekpagina toont deel gemeentelijk applicatielandschap | Step 14 |
| #447 | Zoeken: concept leverancier zonder VNG triage direct vindbaar | Step 3 |
| #455 | Tabblad koppelingen en contactpersonen publiekelijk niet getoond — RBAC? | Step 12 |
| #414 | Mogen deelnemers gebruiksobjecten lezen | Step 12 |

## Testing Hints for Specific Issues

Expand Down
154 changes: 150 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -189,6 +189,69 @@ Full documentation is available at **[softwarecatalog.app](https://softwarecatal
| [User Guide](docs/USER_GUIDE.md) | End-user and administrator guide |
| [Configuration](docs/CONFIGURATION.md) | Setup instructions and troubleshooting |

## Testing

Software Catalogus is tested through three complementary layers that together provide comprehensive quality assurance.

### Code Quality (Conduction Quality Workflow)

Every commit runs through the [Conduction quality workflow](https://github.com/ConductionNL/softwarecatalog/actions) — a strict CI/CD pipeline that enforces:

- **PHP Lint** — syntax validation
- **PHPCS** — coding standards (PEAR + PSR-12 + custom Conduction rules, including forbidden functions and named parameter enforcement)
- **PHPMD** — mess detection (clean code, code size, design, naming, and unused code rules)
- **Psalm** — static analysis (level 4, with unused code detection)
- **PHPStan** — static analysis (level 5)
- **PHPUnit** — unit and integration tests (strict mode: `failOnRisky`, output detection, execution order by dependency)
- **ESLint** — JavaScript/Vue linting
- **Stylelint** — CSS linting

All checks must pass before a release. Run locally with `composer check:strict` (full PHP pipeline) or `npm run lint` (frontend).

### API Tests (454 Assertions)

A dedicated Newman/Postman collection validates the entire API surface with **454 automated assertions** across 334 requests organized in 11 test folders:

| Folder | Coverage |
|--------|----------|
| Setup | Test data creation and environment validation |
| Public API & Search | Faceted search, pagination, UUID resolution |
| RBAC & Organization Scoping | Multi-tenant access control |
| Object CRUD | Create, read, update, delete across all entity types |
| Data Migration & Import | CSV/Magic Mapper imports |
| ArchiMate & Views | GEMMA architecture elements and relations |
| User Profile & Authentication | Login, password, session management |
| Export & Reporting | CSV and Excel export |
| Aanbod & Gebruik | Supply and usage registration |
| Data Quality & Naming | Naming conventions and data consistency |
| Glossary & Content | Glossary terms and CMS content |

Run with: `npx newman run tests/postman_collection.json -e tests/api/.env_00_-_Setup.json`

### Agentic Browser Tests (1,026 Acceptance Criteria)

AI-driven browser agents test the application from **7 real-world persona perspectives**, each with their own Nextcloud account, role-based permissions, and test scenarios. The agents use Playwright to interact with the live application exactly as a human would — navigating pages, filling forms, clicking buttons, and verifying results.

| Persona | Role | Focus |
|---------|------|-------|
| Leverancier | Software supplier | Wizard flows, application/dienst/koppeling management |
| Gemeente | Municipal user | Search, filters, wizard text, data quality |
| Security Officer | Security auditor | RBAC enforcement, data exposure, access control |
| Functioneel Beheerder | Functional administrator | Configuration, backend management, exports |
| Samenwerking | Collaboration partner | Cross-organization features, member delegation |
| Bezoeker | Anonymous visitor | Public access, unauthenticated search, privacy |
| Architectuur Expert | Enterprise architect | GEMMA API, ArchiMate views, OAS documentation |

Together these agents validate **1,026 acceptance criteria** across 137 GitHub issues, covering end-to-end user journeys, RBAC boundaries, wizard completions, and data integrity. Each persona receives a dedicated skill file (`.claude/skills/test-{persona}.md`) containing their assigned issues and test instructions. Results are stored in `test-results/` with per-persona reports.

Run with: `.claude/commands/test.md` (all tests) or individual persona skills.

### Issue Management & Acceptance Criteria

VNG did not begin filing issues for the Softwarecatalogus until October 2025, and when they did, the issues contained only descriptions — no structured acceptance criteria. Since our agentic test pipeline requires explicit, verifiable acceptance criteria to determine pass/fail outcomes, we set up a parallel system of **markdown shadow issues** in `test-results/api/issues/`. Each shadow issue mirrors a VNG GitHub issue but adds the structured acceptance criteria (AC1, AC2, …) that our API and browser agents need.

The master file `issues.md` tracks all 137 IGS (In Review/Scoped) issues with their **1,026 acceptance criteria**, each tagged by test type (`[API]`, `[UI]`, or `[HYBRID]`). Of these, **316 criteria** are covered by the automated Newman/Postman suite, while the remainder are validated by the persona-based browser agents. This approach maintains full traceability back to the original VNG issues while giving our test automation the concrete, testable assertions it requires.

## Standards & Compliance

- **Data standard:** GEMMA Softwarecatalogus (VNG)
Expand All @@ -198,11 +261,94 @@ Full documentation is available at **[softwarecatalog.app](https://softwarecatal
- **Audit trail:** Full change history on all objects
- **Localization:** English and Dutch

## Related Apps
## Required Repositories

The Softwarecatalogus is not a standalone application — it runs as a Nextcloud app backed by several other apps, with a separate React-based public frontend.

| Repository | Role | Required |
|-----------|------|----------|
| [OpenRegister](https://github.com/ConductionNL/openregister) | Data storage layer — all objects (applications, modules, organizations, contacts) are stored as JSON objects in OpenRegister. Also provides the Docker environment (`docker-compose.yml`). | Yes |
| [OpenCatalogi](https://github.com/ConductionNL/opencatalogi) | Publication and catalog management — handles public search, faceted filtering, and federated publishing of catalog data. | Yes |
| [NL Design](https://github.com/ConductionNL/nldesign) | Design token theming — applies Dutch government (NL Design System) styling via CSS custom properties. | Yes |
| [Tilburg WOO UI](https://github.com/ConductionNL/tilburg-woo-ui) | **Separate public frontend** — a React/Preact SPA that serves as the citizen-facing interface at `localhost:3000`. Provides public search, detail pages, and registration forms (product, usage, integration, organization). This is **not** a Nextcloud app but a standalone web application that communicates with Nextcloud via the OpenRegister and OpenCatalogi APIs. | Yes |
| [MyDash](https://github.com/ConductionNL/mydash) | Dashboard widgets for the Nextcloud dashboard page. | Recommended |

## Installation

### 1. Start the Docker environment

The Docker environment is managed from the OpenRegister repository:

```bash
cd openregister
docker compose up -d # Core: PostgreSQL + Nextcloud + n8n
docker compose --profile ui up -d # Adds the Tilburg WOO UI frontend
```

This starts:
- **Nextcloud** at `http://localhost:8080` (admin:admin)
- **Tilburg WOO UI** at `http://localhost:3000` (public frontend)
- **PostgreSQL 16** with pgvector and pg_trgm extensions
- **n8n** for workflow automation

### 2. Install Nextcloud apps (order matters)

Apps must be enabled in this order because of dependency chains:

```bash
# 1. OpenRegister — foundation, must be first
docker exec -u www-data nextcloud php occ app:enable openregister

# 2. OpenCatalogi — depends on OpenRegister for publication data
docker exec -u www-data nextcloud php occ app:enable opencatalogi

# 3. NL Design — theming (no hard dependencies, but should be early)
docker exec -u www-data nextcloud php occ app:enable nldesign

# 4. Software Catalogus — depends on OpenRegister and OpenCatalogi
docker exec -u www-data nextcloud php occ app:enable softwarecatalog

# 5. MyDash — optional, for dashboard widgets
docker exec -u www-data nextcloud php occ app:enable mydash
```

### 3. Import data

The Softwarecatalogus requires register schemas and seed data to function. Import the configurations via the OpenRegister Magic Mapper:

```bash
# Import the softwarecatalogus register configuration
# This creates the voorzieningen register with all required schemas
# (module, dienst, organisatie, contactpersoon, contract, etc.)
curl -X POST "http://localhost:8080/index.php/apps/openregister/api/configurations?force=true" \
-u admin:admin \
-H "Content-Type: application/json" \
-d @softwarecatalog/configurations/softwarecatalogus_register.json
```

For a complete test environment with users, organizations, and sample data:

```bash
bash softwarecatalog/test-setup.sh
```

This creates 7 test users across 4 organizations (leverancier, gemeente, samenwerking, admin), seeds contact persons and sample applications, and verifies RBAC scoping.

### 4. Build frontends

```bash
# Nextcloud app frontend (Vue 2)
cd softwarecatalog && npm install && npm run build

# Public frontend (React) — only needed if not using Docker
cd tilburg-woo-ui && yarn install && yarn build
```

## Support

For support, contact us at [support@conduction.nl](mailto:support@conduction.nl).

- **[OpenRegister](https://github.com/ConductionNL/openregister)** — Object storage layer (required dependency)
- **[OpenCatalogi](https://github.com/ConductionNL/opencatalogi)** — Publication and catalog management
- **[NL Design](https://github.com/ConductionNL/nldesign)** — Design token theming for Dutch government standards
For a Service Level Agreement (SLA), contact [sales@conduction.nl](mailto:sales@conduction.nl).

## License

Expand Down
4 changes: 4 additions & 0 deletions appinfo/info.xml
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,8 @@
**Requires:** [OpenRegister](https://apps.nextcloud.com/apps/openregister) (install from the [Nextcloud App Store](https://apps.nextcloud.com/apps/openregister)).

Free and open source under the EUPL license.

**Support:** For support, contact support@conduction.nl. For a Service Level Agreement (SLA), contact sales@conduction.nl.
]]></description>
<description lang="nl"><![CDATA[Software Catalogus brengt gestructureerd softwareportfoliobeheer naar Nextcloud. Houd al je applicaties, modules en koppelingen bij — en deel ze via een gefedereerd open data netwerk.

Expand All @@ -37,6 +39,8 @@ Free and open source under the EUPL license.
**Vereist:** [OpenRegister](https://apps.nextcloud.com/apps/openregister) (installeer via de [Nextcloud App Store](https://apps.nextcloud.com/apps/openregister)).

Vrij en open source onder de EUPL-licentie.

**Ondersteuning:** Voor ondersteuning, neem contact op via support@conduction.nl. Voor een Service Level Agreement (SLA), neem contact op via sales@conduction.nl.
]]></description>
<version>0.1.140</version>
<licence>agpl</licence>
Expand Down
1 change: 1 addition & 0 deletions eslint.config.js
Original file line number Diff line number Diff line change
Expand Up @@ -53,6 +53,7 @@ module.exports = defineConfig([
rules: {
'jsdoc/require-jsdoc': 'off',
'vue/first-attribute-linebreak': 'off',
'vue/enforce-style-attribute': ['error', { allow: ['scoped'] }],
'@typescript-eslint/no-explicit-any': 'off',
'n/no-missing-import': 'off',
'import/no-unresolved': ['error', { ignore: ['^@conduction/nextcloud-vue'] }],
Expand Down
Loading
Loading