Empty but deployed: monorepo, CI/CD, Compose stack. Exit: a commit to main reaches dorfteich-test.101010.cloud automatically.
Register, verify e-mail, log in, reset password — in German and English.
Ponds and pages with a real TipTap editor, images, trash — single-user persistence via REST.
Live collaboration with cursors, offline editing, version history.
Labels, ordering, wikilinks/backlinks, full-text search.
Full role/grant model incl. public access and quota ladder.
Attachments, Word/OpenOffice import, Markdown/Word/PDF export.
M7 — Plugins
Sandboxed plugin system with SDK and reference plugins.
Setup wizard, backups, monitoring, self-hosting guide — go-live of dorfteich.online.
Comments, watches, notifications.
M10 — UI polish
UI-Feinschliff nach M8/M9: Platznutzung, Icon-Navigation, Presence.
Machine access to Dorfteich instances: personal access tokens, a public REST API, and a built-in MCP endpoint — each behind an instance-wide switch (default off) with per-pond opt-in.
Cheap changes with high assessor signal: token key separation, fail-closed CSRF, bounded sessions, restricted backup targets, and the data-hygiene jobs that are missing today (pond purge, orphan files, trash in the search index, audit retention). Includes the residue findings the Ist-Aufnahme added on top of the plan (conversion-job payloads, mail-outbox retention, page-link slugs). No dependencies — can start immediately.
The items pulled forward from the roadmap plus supply-chain evidence: attachment integrity hashes, a hard plugin off-switch, a stable SIEM event catalogue, SBOM in CI, image digest pinning, and a pinned Node version. Digest pinning (#203) should land before M28 (offline/airgap deployment) — the mirror procedure and the offline update path both build on immutable references.
classification as first-class page metadata (ADR 0022) and its pass-through into every output channel. Separating classification levels stays outside the application (one instance per level); this milestone delivers the marking. Prerequisite for M29 (read-access audit trail).
OIDC (Authorization Code + PKCE) against the existing UserIdentity.provider slot, proxy-header/mTLS as the alternative path, and a hard auth.local.enabled=false switch including every token flow. Delegates the authentication base function to the operator's platform (ADR 0019/0021).
A verified airgap path, not a plausible one: registry mirror procedure, network-free reproducible build, a documented isolated test run, and an offline update path including migrations. Depends on image digest pinning (#203) in M25 (hardening & supply chain).
Variant A of the plan: read events only for pages with classification = VS_NFD. Requires M26 (classification metadata). Deliberately narrow — clean purpose limitation, and it keeps Yjs sync from producing an event flood.
The §52 VSA delimitation statement, hardening guide, security documentation, operations manual, IT-Grundschutz mapping (APP.3.1, CON.11.1) and the residual-risk list. Runs in parallel and starts early — the delimitation statement does not depend on any implementation.