zemion 965244fc67 fix(ui): align contextual documentation with headings
Verified with the coordinated workspace changes by devkit full run
2026-09-08T225814-186389-0000-3e3ed7cd (all seven phases passed).
This shared UI pass does not mark the individual module reviews complete.
2026-09-09 02:04:16 +02:00
2026-07-10 21:57:28 +02:00

govoplan-search

Repository type: module (platform).

Permission-aware global and contextual search for GovOPlaN. Search is the first command in the titlebar action group. Clicking its icon, pressing F3, or pressing Ctrl/Cmd+K opens the same full query field and result overlay.

The titlebar command, result overlay, filters, and Search administration route announce stable help contexts. Pressing F1 while one of those controls is focused opens its Search documentation, with the current page retained as a fallback.

The route, overlay, state, accessibility, and consequence mapping is recorded in docs/INTERFACE_PATTERN_MIGRATION.md.

The module works with its built-in database index and no external search service. PostgreSQL uses native full-text search; SQLite provides a bounded development fallback. Other modules may:

  • register a live search provider in their module manifest
  • write authorized documents through the search.index_writer capability
  • announce context-sensitive WebUI search scopes through search.contexts

An optional OpenSearch adapter is a later provider, not a hard dependency. Source modules remain responsible for defining visibility and authorization.

Index lifecycle

Source modules register a versioned search_sources provider. A provider declares its resource types and index version, returns bounded resumable backfill pages, and batch-rechecks current authorization for sensitive resources. A source may additionally implement the event-source extension to translate committed platform events into SearchIndexChange records. The platform event worker queues those records idempotently and applies them to the derived index; Search never imports a source module or invents its ACL. Direct capability callers may still use search.index_writer.enqueue_change() when they already own a suitable transactional boundary.

The built-in backend exposes opaque cursor pagination and does not return pre-authorization totals. PostgreSQL uses full-text search and will add trigram indexes when pg_trgm is already installed; SQLite remains a bounded development fallback.

Tenant search administrators can use Administration > Search index or the equivalent /api/v1/search/admin/* endpoints to inspect source coverage, reconcile disabled modules, process queued changes, and start or continue bounded provider rebuilds. Quarantined changes and provider errors stay visible. Rows requiring a source authorization recheck are omitted when their provider is unavailable, stale, or fails to return an explicit allow decision.

Files, Campaign, Calendar, Mail, IDM, and Postbox provide native source adapters. Mail indexes only its bounded read-only cache, and Postbox never indexes ciphertext or key material. All six recheck current source-owned authorization when results are returned.

Data-subject requests

Search publishes privacy.dsar.search for derived index documents, queued changes, and minimized ACL projections. Exact Search or source-module references locate derived copies without exporting indexed text, URLs, metadata, token values, hashes, cursors, queued payloads, or errors. Account, identity, and membership matches describe access projections only and do not establish ownership of source content.

Derived documents and queued changes can be purged idempotently. ACL-only matches require review at the source authority. The authoritative module must be corrected or erased before a rebuild; otherwise its provider may republish the derived Search row.

S
Description
GovOPlaN search module for indexing, search APIs, cross-module discovery, result permissions, and search integration surfaces.
Readme AGPL-3.0
361 KiB
Languages
Python 73.5%
TypeScript 19.4%
JavaScript 4.7%
CSS 2.4%