Add CSV and ZIP fitment interoperability #14

Merged
alan merged 1 commit from feature/fitment-csv-zip-v0.1.10 into main 2026-09-09 10:30:01 +00:00
Owner

Summary

Adds CSV/ZIP interoperability for fitment packs while retaining canonical JSON as the authoritative content representation.

The ZIP bundle is a reversible spreadsheet-oriented projection of the canonical fitment-pack model. JSON → ZIP → JSON preserves semantic content and canonical SHA-256 identity.

Highlights

  • Add CSV bundle import/export support.
  • Add ZIP bundle import/export support without extracting archive contents to disk.
  • Preserve reusable equipment identifiers through equipment_identifiers.csv.
  • Preserve optional-note presence semantics explicitly.
  • Preserve canonical JSON/hash identity across CSV/ZIP round trips.
  • Add reversible spreadsheet-formula escaping for formula-sensitive values.
  • Add strict ZIP path, compression, comment, encryption, symlink, size, and row-count validation.
  • Add source and privacy-minimized community ZIP exports.
  • Add bundle validate, preview, import, and export API paths.
  • Require existing fitment authorization semantics for read/import operations.
  • Extend project validation and adversarial self-tests for the CSV/ZIP contract.
  • Extend Nextcloud 34 integration smoke coverage for ZIP round trips, duplicate imports, malicious traversal archives, privacy-minimized exports, and authorization behavior.

Security and Bounds

The runtime rejects:

  • ZIP files over 8 MiB compressed
  • more than 32 MiB expanded data
  • more than 250,000 aggregate CSV rows
  • missing, duplicate, unknown, or nested archive members
  • traversal paths
  • encrypted entries
  • symlinks
  • ZIP comments or entry comments
  • unsupported compression methods
  • malformed UTF-8/BOM handling
  • incorrect CSV headers
  • unsupported CSV dialect metadata

Formula-sensitive values are escaped reversibly rather than destructively sanitized.

Qualification

Candidate tree:

5dc018315451885d927c118209b676a4d1edad8c

Qualification completed successfully with:

  • fitment-pack validation
  • project metadata/authority validation
  • project validator self-tests
  • profile validation
  • ESLint
  • Stylelint
  • Vue/TypeScript typecheck
  • production npm audit: 0 vulnerabilities
  • production build
  • PHP 8.2 qualification in immutable CI image
  • PHP 8.5 qualification in immutable CI image
  • PHPUnit: 87 tests, 478 assertions
  • Composer validation
  • Composer security audit
  • Nextcloud 34 SQLite smoke test
  • Nextcloud 34 PostgreSQL smoke test
  • generated frontend asset reproduction
  • git diff --check

Scope

This completes the currently planned JSON + CSV/ZIP fitment interoperability foundation for v0.1.10.

## Summary Adds CSV/ZIP interoperability for fitment packs while retaining canonical JSON as the authoritative content representation. The ZIP bundle is a reversible spreadsheet-oriented projection of the canonical fitment-pack model. JSON → ZIP → JSON preserves semantic content and canonical SHA-256 identity. ## Highlights * Add CSV bundle import/export support. * Add ZIP bundle import/export support without extracting archive contents to disk. * Preserve reusable equipment identifiers through `equipment_identifiers.csv`. * Preserve optional-note presence semantics explicitly. * Preserve canonical JSON/hash identity across CSV/ZIP round trips. * Add reversible spreadsheet-formula escaping for formula-sensitive values. * Add strict ZIP path, compression, comment, encryption, symlink, size, and row-count validation. * Add source and privacy-minimized community ZIP exports. * Add bundle validate, preview, import, and export API paths. * Require existing fitment authorization semantics for read/import operations. * Extend project validation and adversarial self-tests for the CSV/ZIP contract. * Extend Nextcloud 34 integration smoke coverage for ZIP round trips, duplicate imports, malicious traversal archives, privacy-minimized exports, and authorization behavior. ## Security and Bounds The runtime rejects: * ZIP files over 8 MiB compressed * more than 32 MiB expanded data * more than 250,000 aggregate CSV rows * missing, duplicate, unknown, or nested archive members * traversal paths * encrypted entries * symlinks * ZIP comments or entry comments * unsupported compression methods * malformed UTF-8/BOM handling * incorrect CSV headers * unsupported CSV dialect metadata Formula-sensitive values are escaped reversibly rather than destructively sanitized. ## Qualification Candidate tree: `5dc018315451885d927c118209b676a4d1edad8c` Qualification completed successfully with: * fitment-pack validation * project metadata/authority validation * project validator self-tests * profile validation * ESLint * Stylelint * Vue/TypeScript typecheck * production npm audit: 0 vulnerabilities * production build * PHP 8.2 qualification in immutable CI image * PHP 8.5 qualification in immutable CI image * PHPUnit: 87 tests, 478 assertions * Composer validation * Composer security audit * Nextcloud 34 SQLite smoke test * Nextcloud 34 PostgreSQL smoke test * generated frontend asset reproduction * `git diff --check` ## Scope This completes the currently planned JSON + CSV/ZIP fitment interoperability foundation for v0.1.10.
Add CSV and ZIP fitment interoperability
All checks were successful
CI / PHP 8.5 (pull_request) Successful in 8s
CI / PHP 8.2 (pull_request) Successful in 8s
CI / Frontend and generated assets (pull_request) Successful in 25s
CI / Nextcloud 34 / sqlite (pull_request) Successful in 3m14s
CI / Nextcloud 34 / pgsql (pull_request) Successful in 3m35s
CI / Unsigned install candidate (pull_request) Successful in 4s
6a8eb23b1a
alan merged commit 3595c198d1 into main 2026-09-09 10:30:01 +00:00
alan deleted branch feature/fitment-csv-zip-v0.1.10 2026-09-09 10:30:01 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
alan/maintenance_tracker_for_nextcloud!14
No description provided.