70 lines
3.3 KiB
Markdown
70 lines
3.3 KiB
Markdown
# Quick Task 261009-dkv: Modul Dateien Etappe 2a: Teilen von Dateien und Ordnern ueber Nextcloud - Context
|
|
|
|
**Gathered:** 2026-10-09
|
|
**Status:** Ready for planning
|
|
|
|
<domain>
|
|
## Task Boundary
|
|
|
|
Module "Dateien" (slug `nextcloud-files`), Etappe 2a: sharing. Users share files and folders of their
|
|
own Nextcloud account from inside Tessera (Nextcloud OCS Files Sharing API, always under the caller's
|
|
own app password), see existing shares, change them and remove them. Builds on quick 261008-mzu
|
|
(Etappe 1: browse/upload/download/rename/move/delete). Search is NOT part of this task (later quick).
|
|
Module version bump + module changelog + user/admin docs are part of the task.
|
|
|
|
</domain>
|
|
|
|
<decisions>
|
|
## Implementation Decisions
|
|
|
|
### Share targets
|
|
- Both: share with colleagues (Nextcloud users AND groups, found via Nextcloud's sharee search) and
|
|
public links (to hand to customers etc.).
|
|
|
|
### Link protection
|
|
- Follow the Nextcloud server policy — do not invent Tessera-side rules. User believes the company
|
|
Nextcloud enforces a password for links but NOT an expiry date. Tessera must read the policy from
|
|
the Nextcloud capabilities (password enforced, expiry enforced/default days, etc.) and reflect it
|
|
in the form (required fields, defaults, maximums); Nextcloud's error messages on policy violations
|
|
must be shown understandably in German. Optional fields (expiry when not enforced) remain freely
|
|
settable.
|
|
|
|
### Permissions
|
|
- Simple choice: "Ansehen" (read only) or "Bearbeiten" (edit). For folders additionally
|
|
"Nur hochladen" (file drop / Briefkasten, mainly for public links). No per-bit checkboxes.
|
|
|
|
### Overview
|
|
- Both views: "Von mir geteilt" and "Mit mir geteilt" as separate views in the module, plus a share
|
|
indicator on every shared entry in the file list. Shares can be opened from both places to change
|
|
or remove them.
|
|
|
|
### Claude's Discretion
|
|
- Copy-link button, optional link label/note, notification behaviour (Nextcloud's own behaviour for
|
|
user/group shares is fine), how "Mit mir geteilt" items are opened/navigated, accepting/declining
|
|
pending incoming shares if the server requires it, UI layout of the share dialog (follow existing
|
|
dialog patterns of the module), error mapping, rate/size limits, test strategy.
|
|
|
|
</decisions>
|
|
|
|
<specifics>
|
|
## Specific Ideas
|
|
|
|
- Etappe 1 was prepared for this: DAV layer keeps a generic `davRequest`, auth client an `ocsRequest`,
|
|
entries keep Nextcloud permission letters (R = shareable), the row menu takes an action list.
|
|
- Respect all Etappe-1 safety rules (fixed path prefixes, no redirects, no cookies, call gate on 429,
|
|
401 handling / account marked expired, German error contract, RLS/tenant rules).
|
|
- Local test Nextcloud container `tessera-nc-test` (http://172.17.0.1:18080) exists for e2e tests;
|
|
its sharing policy can be set via occ to test "password enforced" behaviour.
|
|
|
|
</specifics>
|
|
|
|
<canonical_refs>
|
|
## Canonical References
|
|
|
|
- .planning/quick/261008-mzu-modul-nextcloud-dateien-eigenstaendiger-/261008-mzu-PLAN.md (Etappe 1 design decisions D-A..D-O)
|
|
- .planning/quick/261008-mzu-modul-nextcloud-dateien-eigenstaendiger-/261008-mzu-SUMMARY.md
|
|
- .planning/quick/261008-mzu-modul-nextcloud-dateien-eigenstaendiger-/261008-mzu-REVIEW.md
|
|
- Nextcloud OCS Share API docs (developer manual: client APIs / OCS share API, sharee API)
|
|
|
|
</canonical_refs>
|