Auf Entscheidung des Users vom 2026-09-09. Der Wunsch bleibt bestehen, hat aber
keine Dringlichkeit und wird nicht mehr als naechster Bau-Kandidat vorgelegt —
erst wieder aufgreifen, wenn der User ihn von sich aus nennt.
Damit ist derzeit kein naechster Schritt vorgemerkt: das Ledger ist leer, und
alle verbliebenen Punkte ruhen bewusst (Postfach-Test mangels Postfach,
Mandantentrennung solange Tessera intern laeuft, Lizenzpruefung bis alle Module
intern laufen, Branding ab jetzt).
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FYZcd3SSmo14QTqWx2KKzU
Die Browser-Abnahme hat drei uebersehene Stellen gefunden — "Aenderungen speichern",
"Oeffnen" und einen LDAP-Hinweis — und damit die Luecke im Waechter aufgedeckt, durch
die sie geschluepft sind: sein Verdachtsmuster war case-sensitiv. Beides mit 85d2d77
behoben.
In der SUMMARY festgehalten, wie geprueft wurde: eine unabhaengige Analyse aller
Tokens in de.json findet keine Ersatzschreibung mehr, der Schluesselsatz ist
unveraendert bei 787, und die Modulbeschreibung in der bestehenden Datenbank ist beim
API-Neustart per Seed-Upsert mitgewandert — ohne Migration, wie geplant.
Ausserdem vermerkt, dass eine erste Sichtpruefung per fetch aus der laufenden Seite
faelschlich Entwarnung gab. Dieselbe Methode hatte in dieser Sitzung schon einmal ein
falsches Ergebnis geliefert; die berichteten Zahlen stammen aus echten
Seitenaufrufen.
Backlog-Punkt zu den Umlauten nach completed verschoben.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01K5jtbGzC5Sf9npJ3JCjKhq
Beim Einbau des Logos im Browser aufgefallen und als Backlog-Punkte abgelegt, nicht
mitrepariert:
Mandanten-Branding — der Wunsch des Users, dass ein Administrator das Aussehen spaeter
selbst anpassen kann. Der Logo-Einbau hat dafuer schon vorgearbeitet: die Oberflaeche
zieht die Marke ausschliesslich aus einer zentralen Komponente, ein spaeterer Austausch
setzt an genau einer Stelle an. Was noch fehlt (Ablage, Mandantenfeld, Rueckfall,
Verwaltungsseite, Zusammenspiel mit hell/dunkel) steht im Punkt.
Umlaute — die deutschen Oberflaechentexte schreiben Umlaute in 29 Zeilen als
Buchstabenpaare aus: "fuer", "Loeschen", "Zurueck zum Dashboard", "Verfuegbar". Das
sieht jeder Nutzer auf jeder Seite. Mit Hinweis auf die Stolpersteine beim Ersetzen.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01K5jtbGzC5Sf9npJ3JCjKhq
- RssFeedListForm.test.tsx auf scope umgestellt: personal zeigt eigene Feeds
editierbar + plattformweite als schlichte, nicht bedienbare Liste darunter;
platform zeigt nur plattformweite Feeds, eigene Feeds tauchen dort gar
nicht auf; beide Faelle pruefen den scope-Parameter von createRssFeed
- settings-roles.test.tsx (neu): USER sieht Hinweis+Verweis statt
Bedienelemente, ADMIN/SUPER_ADMIN sehen Abrufintervall+RSS-Feeds, unbekannte
Rolle zeigt weder-noch, entfernte Abschnittsueberschriften kommen nirgends
mehr vor
- my-sources.test.tsx (neu): alle drei Abschnittsueberschriften vorhanden,
Verweis auf die Administrationsseite nur bei ADMIN/SUPER_ADMIN
- Erwartete Texte in allen drei Testdateien von Hand geschrieben, nicht aus
der gleichen next-intl-Zuordnung abgeleitet, die die Komponenten benutzen
- Backlog-Punkt 2026-08-11-tender-radar-einstellungen-mischen-rollen.md nach
todos/completed/ verschoben, mit Resolution-Abschnitt: beide Nutzer-
Entscheidungen (eigene Quellen je Nutzer, Trefferliste bleibt
plattform-global) und die Antwort auf offenen Punkt 4 (eigene
nutzerseitige Modulseite als Vorbild fuer kuenftige Module) dokumentiert
Verifikation: Web 205/205, API src/tenders 362/362, beide Typpruefungen
fehlerfrei.
/opt/tessera keeps its directory (compose derives the project name from it,
and a rename would have orphaned tessera_pgdata) and now tracks main.
COMPOSE_FILE pins it to the production file so the checkout does not switch
the server onto the dev defaults.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
NEXT_PUBLIC_API_URL is read by the browser, not by the web container, so
http://api:3001 could never work outside Docker. The test server had been
corrected by hand long ago; the fix never came back here, so the file we
would ship to a customer was the broken one.
Also adopts the server's TESSERA_FORCE_CHANGE default of true, so a fresh
install requires the initial admin password to be changed.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The note predated 7bda56d and f574884, so two of its three points were
already shipped when it was picked up. Records what each commit actually
closed, and that the .env deny rules block the two committed template
files that hold no secrets.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The page carries platform config, tenant config and one per-user setting. The
per-user one -- the digest interval, which is what an ordinary user actually
comes for -- sits last, below three blocks they may not change.
Checked before writing it up: this is not a permission hole. The admin
endpoints are @Roles-guarded server side, so a normal user cannot change
anything; the page simply has no role check of its own, so they see controls
that fail on save.
The second half is a product question deliberately left open, because it is
not specific to this module: DKV-Fleet has the same shape, and every future
module with a personal setting will ask it again.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
/opt/tessera is not a working copy -- the compose file there is maintained by
hand, and the deploy path only pulls images. Two consequences showed up on the
same day: the renamed encryption key never reached the container although it
was in the server .env, and the "refuse to start without a key" guard does not
apply on alpha at all, because it only exists in the repository file.
The item deliberately stops short of proposing a fix to apply: it first asks
why the file is hand-maintained, since it may carry host-specific settings the
repository lacks, and moving to a checkout blindly would break the running
system.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Fallout from encrypting the LDAP bind password: the base compose file still
carries a hardcoded fallback key, so an install that never sets the variable
starts anyway and encrypts everything with a value that is in the repository.
The prod compose already requires it, which is the behaviour the base file
should have too.
Whether the example env files explain the key could not be checked in that
session, so the item says to look first rather than asserting it is missing.
Also notes, as an optional follow-up, why the variable is called
CALENDAR_ENCRYPTION_KEY and what a rename would have to handle.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Notes what was deliberately left out: extracting and renaming the crypto
service out of calendar/ touches five modules and belongs in its own change,
so the existing provider is reused as-is and the naming smell is recorded in
LdapModule instead.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Records the user's choice between the two candidate link targets (the notice
page on oeffentlichevergabe.de, not the awarding portal's own page), what was
checked before touching the adapter, and the trap in verifying it: the target
is a single-page app that answers 200 with an identical shell for any id, so
only rendered content proves the link works.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Neither is a Phase 16 defect; both surfaced while testing it and would
otherwise have been lost with the session.
1. Module activation has no licence check — a tenant admin can activate any
catalogue module for their own tenant. The grants matrix is NOT the hole: it
only distributes what is already active. Carries open product questions
(who issues licences, what expiry does), so it is written up as a draft, not
a decision.
2. The LDAP bind password is stored in clear text although an AES-256-GCM
service already exists and is used for calendar, DKV and tender inbox
credentials. Hashing is not an option here — the password must be replayable
to bind against the directory — so encryption at rest is the fix. No open
questions, just work.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>