• 0 Open
    9 Closed
    Updated 2026-07-05 00:33:54 +02:00
    No due date

    Empty but deployed: monorepo, CI/CD, Compose stack. Exit: a commit to main reaches dorfteich-test.101010.cloud automatically.

  • 0 Open
    11 Closed
    Updated 2026-07-05 05:43:09 +02:00
    No due date

    Register, verify e-mail, log in, reset password — in German and English.

  • 0 Open
    12 Closed
    Updated 2026-07-08 13:14:56 +02:00
    No due date

    Ponds and pages with a real TipTap editor, images, trash — single-user persistence via REST.

  • 0 Open
    10 Closed
    Updated 2026-07-09 09:05:23 +02:00
    No due date

    Live collaboration with cursors, offline editing, version history.

  • 0 Open
    8 Closed
    Updated 2026-07-09 13:46:54 +02:00
    No due date

    Labels, ordering, wikilinks/backlinks, full-text search.

  • 0 Open
    10 Closed
    Updated 2026-07-10 00:57:14 +02:00
    No due date

    Full role/grant model incl. public access and quota ladder.

  • 0 Open
    9 Closed
    Updated 2026-07-10 15:30:43 +02:00
    No due date

    Attachments, Word/OpenOffice import, Markdown/Word/PDF export.

  • 0 Open
    10 Closed
    Updated 2026-07-11 14:23:55 +02:00
    No due date

    Sandboxed plugin system with SDK and reference plugins.

  • 0 Open
    12 Closed
    Updated 2026-07-12 12:33:33 +02:00
    No due date

    Setup wizard, backups, monitoring, self-hosting guide — go-live of dorfteich.online.

  • 0 Open
    6 Closed
    Updated 2026-07-12 00:13:14 +02:00
    No due date

    Comments, watches, notifications.

  • 0 Open
    4 Closed
    Updated 2026-07-12 04:54:49 +02:00
    No due date

    UI-Feinschliff nach M8/M9: Platznutzung, Icon-Navigation, Presence.

  • 0 Open
    2 Closed
    Updated 2026-07-12 11:47:59 +02:00
    No due date

    Machine access to Dorfteich instances: personal access tokens, a public REST API, and a built-in MCP endpoint — each behind an instance-wide switch (default off) with per-pond opt-in.

  • 0 Open
    14 Closed
    Updated 2026-07-30 23:11:10 +02:00
    No due date

    Cheap changes with high assessor signal: token key separation, fail-closed CSRF, bounded sessions, restricted backup targets, and the data-hygiene jobs that are missing today (pond purge, orphan files, trash in the search index, audit retention). Includes the residue findings the Ist-Aufnahme added on top of the plan (conversion-job payloads, mail-outbox retention, page-link slugs). No dependencies — can start immediately.

  • 0 Open
    6 Closed
    Updated 2026-07-31 05:29:14 +02:00
    No due date

    The items pulled forward from the roadmap plus supply-chain evidence: attachment integrity hashes, a hard plugin off-switch, a stable SIEM event catalogue, SBOM in CI, image digest pinning, and a pinned Node version. Digest pinning (#203) should land before M28 (offline/airgap deployment) — the mirror procedure and the offline update path both build on immutable references.

  • 0 Open
    10 Closed
    Updated 2026-07-31 07:59:07 +02:00
    No due date

    classification as first-class page metadata (ADR 0022) and its pass-through into every output channel. Separating classification levels stays outside the application (one instance per level); this milestone delivers the marking. Prerequisite for M29 (read-access audit trail).

  • 0 Open
    4 Closed
    Updated 2026-07-31 13:47:17 +02:00
    No due date

    OIDC (Authorization Code + PKCE) against the existing UserIdentity.provider slot, proxy-header/mTLS as the alternative path, and a hard auth.local.enabled=false switch including every token flow. Delegates the authentication base function to the operator's platform (ADR 0019/0021).

  • 0 Open
    5 Closed
    Updated 2026-07-31 17:46:31 +02:00
    No due date

    A verified airgap path, not a plausible one: registry mirror procedure, network-free reproducible build, a documented isolated test run, and an offline update path including migrations. Depends on image digest pinning (#203) in M25 (hardening & supply chain).

  • 0 Open
    4 Closed
    Updated 2026-07-31 12:59:08 +02:00
    No due date

    Variant A of the plan: read events only for pages with classification = VS_NFD. Requires M26 (classification metadata). Deliberately narrow — clean purpose limitation, and it keeps Yjs sync from producing an event flood.

  • 0 Open
    6 Closed
    Updated 2026-07-31 10:57:46 +02:00
    No due date

    The §52 VSA delimitation statement, hardening guide, security documentation, operations manual, IT-Grundschutz mapping (APP.3.1, CON.11.1) and the residual-risk list. Runs in parallel and starts early — the delimitation statement does not depend on any implementation.

  • 0 Open
    1 Closed
    Updated 2026-07-31 22:04:48 +02:00
    No due date

    Deliberately deferred: plugin allowlist with hash pinning (#232). The hard off-switch (#200) in M25 already closes the 'code execution in the VS zone' risk for the offer stage.