[Privacy] Complete DSAR provider coverage across data-owning modules #47
Closed
opened 2026-08-07 14:51:08 +02:00 by zemion
·
13 comments
No Branch/Tag Specified
Labels
Clear labels
area/api
area/auth
area/db
area/devex
area/docs
area/governance
area/marketing
area/migrations
area/module-system
area/rbac
area/release
area/security
area/tenancy
area/webui
audit/complexity
audit/duplication
audit/false-positive
audit/needs-design
audit/quick-fix
audit/structural
codex/needs-human
codex/ready
module/access
module/addresses
module/admin
module/appointments
module/approvals
module/audit
module/calendar
module/campaign
module/cases
module/committee
module/connectors
module/core
module/dashboard
module/dataflow
module/datasources
module/decisions
module/dist-lists
module/dms
module/docs
module/encryption
module/erp
module/evaluation
module/files
module/fit-connect
module/forms
module/forms-runtime
module/helpdesk
module/identity
module/identity-trust
module/idm
module/ledger
module/mail
module/mandates
module/notifications
module/ops
module/organizations
module/parties
module/payments
module/permits
module/policy
module/poll
module/portal
module/postbox
module/projects
module/quick-access
module/records
module/reporting
module/risk-compliance
module/scheduling
module/search
module/services
module/tasks
module/templates
module/tenancy
module/tickets
module/views
module/voting
module/wiki
module/workflow
module/workflow-engine
module/xoev
module/xrechnung
module/xta-osci
source/backlog-import
source/security-audit
source/todo-scan
HTTP API contracts, routers, schemas, or API smoke behavior.
Authentication, sessions, access bootstrap, or login behavior.
Database sessions, models, transactions, or persistence primitives.
Local developer workflow, scripts, tests, tooling, or release helpers.
Durable documentation and project guidance.
Governance policy, audit, privacy, retention, or compliance behavior.
Public website, product messaging, publication copy, or legal page content.
Alembic migrations, schema bootstrap, or persistence evolution.
Module discovery, manifests, capabilities, routing, or optional integrations.
Permissions, roles, delegation, or authorization policy.
Versioning, release locks, tags, packaging, or dependency pins.
Security posture, static analysis, supply-chain hardening, or vulnerability remediation.
Tenant boundaries, provisioning, or tenant-scoped data behavior.
Shared WebUI shell, frontend components, routing, or frontend tests.
Complexity finding from Radon, Xenon, or equivalent maintainability scans.
Duplicated-code finding from jscpd or equivalent similarity scans.
Audit finding reviewed as a narrow false positive or acceptable risk.
Audit finding that needs an architectural or product decision before implementation.
Audit finding that appears narrow and directly fixable.
Audit finding that needs design, refactoring, or behavior review.
Needs an explicit human decision before Codex should implement.
Suitable for Codex to pick up with the existing issue context.
GovOPlaN access, identity, authentication, RBAC, and administration behavior.
GovOPlaN Addresses module behavior or integration.
GovOPlaN Admin module behavior or integration.
GovOPlaN Appointments module behavior or integration.
GovOPlaN Approvals module behavior or integration.
GovOPlaN Audit module behavior or integration.
GovOPlaN Calendar module behavior or integration.
GovOPlaN campaign module behavior or integration.
GovOPlaN Cases module behavior or integration.
GovOPlaN Committee module behavior or integration.
GovOPlaN Connectors module behavior or integration.
GovOPlaN core runner, shared primitives, shell, or extension points.
GovOPlaN Dashboard module behavior or integration.
GovOPlaN Dataflow module behavior or integration.
GovOPlaN governed datasource contracts, catalogs, and integrations.
GovOPlaN formal Decisions module behavior or integration.
GovOPlaN Distribution Lists module behavior or integration.
GovOPlaN Dms module behavior or integration.
GovOPlaN Docs module behavior or integration.
GovOPlaN Encryption key custody, cryptographic policy, and E2EE integration.
GovOPlaN Erp module behavior or integration.
GovOPlaN Evaluation module behavior or integration.
GovOPlaN files module behavior or integration.
GovOPlaN Fit Connect module behavior or integration.
GovOPlaN Forms module behavior or integration.
GovOPlaN Forms Runtime module behavior or integration.
GovOPlaN Helpdesk module behavior or integration.
GovOPlaN Identity module behavior or integration.
GovOPlaN Identity Trust module behavior or integration.
GovOPlaN Idm module behavior or integration.
GovOPlaN Ledger module behavior or integration.
GovOPlaN mail module behavior or integration.
GovOPlaN Mandates, jurisdiction, responsibility, and authority behavior or integration.
GovOPlaN Notifications module behavior or integration.
GovOPlaN Ops module behavior or integration.
GovOPlaN Organizations module behavior or integration.
GovOPlaN procedure Parties, representation, and delivery-authority behavior or integration.
GovOPlaN Payments module behavior or integration.
GovOPlaN Permits module behavior or integration.
GovOPlaN Policy module behavior or integration.
GovOPlaN Poll module behavior or integration.
GovOPlaN Portal module behavior or integration.
GovOPlaN Postbox module behavior or integration.
GovOPlaN Projects module behavior or integration.
GovOPlaN configurable task-local Quick Access behavior and integrations.
GovOPlaN Records and eAkte lifecycle behavior or integration.
GovOPlaN Reporting module behavior or integration.
GovOPlaN Risk Compliance module behavior or integration.
GovOPlaN Scheduling module behavior or integration.
GovOPlaN Search module behavior or integration.
GovOPlaN versioned institutional Services behavior or integration.
GovOPlaN Tasks module behavior or integration.
GovOPlaN Templates module behavior or integration.
GovOPlaN Tenancy module behavior or integration.
GovOPlaN Tickets module behavior or integration.
GovOPlaN governed task views, interface projections, and workflow view integration.
GovOPlaN Voting module behavior or integration.
GovOPlaN Wiki module behavior or integration.
GovOPlaN Workflow module behavior or integration.
GovOPlaN Workflow Engine runtime, persistence, or integration.
GovOPlaN Xoev module behavior or integration.
GovOPlaN Xrechnung module behavior or integration.
GovOPlaN Xta Osci module behavior or integration.
priority
p0
Immediate stop-the-line priority.
priority
p1
High priority for the next focused work window.
priority
p2
Normal planned priority.
priority
p3
Low priority or opportunistic cleanup.
Imported from markdown backlog, roadmap, plan, or TODO files.
Created from a structured security or code-quality audit report.
Imported from inline TODO/FIXME/HACK markers by the Gitea TODO importer.
status
blocked
Cannot progress without a decision, dependency, credential, or external change.
status
in-progress
Currently being worked.
status
needs-info
Needs clarifying input before implementation can proceed safely.
status
ready
Ready for implementation.
status
triage
Needs review, ownership, priority, or acceptance criteria.
type
bug
A reproducible defect, regression, or incorrect behavior.
type
debt
Cleanup, refactoring, risk reduction, or deferred engineering work.
type
docs
Documentation, process, or developer workflow work.
type
feature
New user-visible behavior or platform capability.
type
task
Implementation, maintenance, migration, or operational work.
type
user-story
End-to-end user journey or real-world process story used to steer product slices.
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: GovOPlaN/govoplan#47
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Context
Core #59 now owns a durable, provider-neutral data-subject request workflow with selector corroboration, coverage reporting, immutable authorization evidence, review/export/erasure states, optimistic concurrency, typed erasure confirmation, audit events, and an Access reference provider. Active modules without a provider are reported explicitly rather than silently omitted.
This umbrella tracks adoption by every remaining data-owning module.
Provider Contract
Each provider must:
Rollout
Related: GovOPlaN/govoplan-core#59.
Files DSAR coverage is complete via GovOPlaN/govoplan-files#44 and
govoplan-files@ce4eaef. The provider covers Files/file-version/evidence metadata without exporting raw bytes or credential material, classifies retained and manual-review records, and automates only revalidated idempotent share revocation and mutable subject-reference detachment. The umbrella rollout checkbox has been updated. Full workspace focused verification passed.Campaign provider coverage is complete via govoplan-campaign#94 and pushed as govoplan-campaign@73cfad2. The provider covers isolated recipient/version/job/delivery/report/artifact metadata, preserves immutable evidence, executes only revalidated reversible personal preferences and access changes, and passed the complete workspace focused gate.
Calendar and Scheduling coverage is complete and pushed.
GovOPlaN/govoplan-calendar@a2a9e8e; module issue #24 closed; full suite151 passed, 5 subtests passed.GovOPlaN/govoplan-scheduling@0fd2972; module issue #9 closed; full suite94 passed.tools/checks/check-focused.sh: passed, including backend/migrations, dependency and shared UI contracts, 59 WebUI permutations and bundle budgets, 7 Playwright conformance tests, and trailing module UI checks.The umbrella rollout item
Calendar and scheduling datais now checked.Mail DSAR coverage is complete:
GovOPlaN/govoplan-mail@34bd5be; module issue #22 is closed. Full Mail suite:141 passed, 22 subtests passed; manifest registry: 68/68. The sharedMail and Postbox datacheckbox remains open until Postbox coverage is complete.Mail and Postbox rollout is complete.
GovOPlaN/govoplan-mail@34bd5be; package/manifest version alignment:2fe56fc.GovOPlaN/govoplan-postbox@e5da713; child issue #28 closed.The umbrella rollout checkbox has been updated. The next dependency-safe cluster is IDM, Organizations, Addresses, and Parties.
Addresses DSAR coverage is complete:
GovOPlaN/govoplan-addresses@8740fb3; child issue GovOPlaN/govoplan-addresses#24 is closed. The full focused workspace gate passed. The IDM / Organizations / Addresses / Parties rollout item remains open while the other three providers are implemented.Completed the IDM / Organizations / Addresses / Parties rollout cluster:
govoplan-organizations@aa4ed0b,govoplan-idm@65ff14a,govoplan-addresses@8740fb3, andgovoplan-parties@9a9c4ca. Each provider is exact-tenant, bounded, minimized, fail-closed on selector conflicts, and publishes governed non-automatic dispositions. The complete focused workspace gate passes, including all 59 WebUI permutations and 7 browser conformance checks. Child issues Organizations #8, IDM #13, Addresses #24, and Parties #1 are closed.Completed the Cases / Records / Forms Runtime / Portal / service-interactions rollout cluster.
eab2f4b(privacy.dsar.cases)2ea7afa(privacy.dsar.forms_runtime)6f671f6(reviewed no-persistence/no-provider boundary)38f203a(privacy.dsar.records)a7998a5(privacy.dsar.services; catalogue attribution, with runtime effects owned by Cases, Forms Runtime, or Workflow Engine)All module suites, the manifest registry, dependency/boundary checks, 59 WebUI permutations, bundle budgets, seven Playwright conformance tests, and module-specific UI checks passed through
tools/checks/check-focused.sh.Completed the derived-data and orchestration wave:
016136f(#5)eb6742a(#9)f03497b(#8)6767905(#21)ceb61b5(#2)All five providers are tenant-scoped, bounded, fail closed on conflicting selectors, minimize exported records, provide governed erasure plans, and document the user/admin consequences. The full workspace focused gate passed, including backend suites, manifest and boundary checks, every WebUI module permutation and bundle budget, and all 7 Playwright UI-conformance tests.
Verified and completed the next governed DSAR provider wave:
f8305f1(privacy.dsar.dashboard)eaca788(privacy.dsar.quick_access)266f5da(privacy.dsar.views)975d90b(privacy.dsar.notifications)869891f(privacy.dsar.audit)88bd0e6(privacy.dsar.tasks)e08bc8b(privacy.dsar.payments)All seven commits are pushed and their owning issues are closed. The final cross-module gate passed in the combined workspace: static contracts/manifests and dependency boundaries, all backend suites, 59 WebUI module permutations with bundle budgets, and 7/7 Playwright conformance tests.
The next high-value provider candidates are Identity + Identity Trust; Approvals + Decisions; Voting + Poll + Committee; Risk Compliance; and Connectors + Encryption. The smaller configuration/definition stores (Templates, Forms, Admin, Policy, Mandates, Projects, and Distribution Lists) should follow or receive an explicit reviewed no-provider rationale. The umbrella remains open until that inventory and the zero-unexplained-gap integration matrix are complete.
Completed the governed DSAR adoption wave:
b5017ac8d1ca495d3eeb0e6ea0d67e03fe602ec542049ea80All seven providers include explicit subject matching and narrowing, bounded/minimized exports, sensitive-data exclusions, lifecycle classifications, automated tests, and manifest-driven user/administrator documentation. Remote main heads were verified after push.
Workspace verification passed with
tools/checks/check-focused.sh, including manifest and dependency-boundary checks, backend suites, 59 WebUI module permutations, seven Playwright conformance tests, and module-specific frontend checks.The remaining schema-owning inventory is: Risk Compliance, Encryption, Connectors, Distribution Lists, Projects, Templates, Admin, Forms, Mandates, and Policy. A sensible next wave is Risk Compliance plus Connectors/Encryption, followed by the configuration and definition stores.
Completed the remaining schema-owning module rollout in ten pushed and verified slices: risk-compliance#9, connectors#17, encryption#6, dist-lists#9, projects#3, templates#6, admin#10, forms#6, mandates#1, and policy#13. Each issue records its commit and focused tests; the 68-manifest registry and full focused workspace gate pass. The umbrella remains open only for an explicit cross-module coverage matrix/check that explains every active module without a provider.
Completed and verified.
govoplan@26a6681adds a strict workspace DSAR conformance gate, a reviewed exemption registry, and a generated 68-module evidence matrix. It also runs the gate from focused checks and the release-tag path.govoplan-access@fa0c85edocuments the existing Access DSAR capability, eliminating the final provider-documentation gap.tools/checks/check-focused.shpassed end to end: backend/composition suites, manifest and DSAR gates, 59 WebUI module permutations, full-product bundle budgets, seven Playwright conformance tests, and downstream module checks.The generated matrix is
docs/evidence/snapshots/DSAR_PROVIDER_COVERAGE.generated.md; future drift now fails CI/release validation.