Architecture and code map
LibreSign is a Nextcloud application. This page is the canonical starting point for understanding where responsibilities live before changing code.
Use the application repository as the source of truth for current class names, APIs and implementation details:
Repository map
The main application areas are:
lib/PHP backend code. Controllers expose HTTP/OCS behavior, services contain application logic and orchestration, database classes persist application state, and handlers contain specialized signing/certificate behavior.
src/Vue and TypeScript frontend code.
tests/php/Unit/Isolated PHP unit tests.
tests/php/Api/andtests/php/Integration/PHPUnit tests that exercise a bootstrapped Nextcloud runtime.
tests/integration/Behat behavior/integration scenarios and their support code.
src/tests/Frontend unit tests.
playwright/Browser/end-to-end test support where present in the current application repository.
appinfo/Nextcloud application metadata and route/configuration declarations.
3rdparty/Scoped third-party dependencies. Follow the instructions in that directory before changing it.
Responsibility boundaries
Backend enforcement
Permissions, validation, policy resolution and other security-sensitive business rules must be enforced by the backend. Frontend checks may improve the user experience, but they are not an authorization boundary.
Generated and vendored content
Do not edit generated translations, generated API/type output or vendored dependencies as if they were normal source files. Change their source contract and regenerate them using the workflow documented by the application repository.
Signing and document integrity
Changes affecting document signing, PDF validation, certificates, cryptographic policy, authorization or persisted audit state require focused regression and negative tests at the affected trust boundary.
Nextcloud integration
Prefer public Nextcloud OCP APIs and the repository’s existing integration patterns. Before introducing a workaround for an upstream change, verify the supported Nextcloud version and current upstream contract.
Where to go next
Development environment for setting up a development runtime.
Testing for testing and validation.
Development workflow for the normal issue-to-pull-request workflow.
API Documentation for the public API.
Release process for release operations.