Repository navigation
v1.19.0
Highlight: specs grouped into folders are visible. OpenSpec accepts a spec.md at any depth under openspec/specs/ — specs/contracts/pagination/spec.md is a valid capability — but spek only looked one level down, so a repository that groups its capabilities into folders showed nothing for them. Thanks to @flatrick (Patrik) (#61)
- Specs are found at any depth, in the main specs tree and in every change's delta specs, by OpenSpec's own rule: dot-entries are skipped, symlinked folders are not followed, and a linked
spec.mdcounts only if it points inside the specs tree. A spec's name is its full path, e.g.contracts/pagination - The Specs page is a folder tree with a filter, and the VS Code sidebar and IntelliJ tool window nest the same way. In VS Code, a spec that also has specs under it lists them before its own headings
- The graph labels a nested spec by its last segment, with the full path as its tooltip, and two specs with the same last segment open their own pages
- Security: a spec read can no longer reach outside the specs a scan lists. The web server built the file path straight from the spec or change name in the URL, so a name carrying
../(also as an encoded%2F) could read a file outside the repository. Every spec read, on every surface, now checks the name and serves only a spec the list would show - Behaviour change: a symlinked folder under
specs/is no longer listed, and neither is aspec.mdsymlink pointing outside it, matching what OpenSpec itself validates and archives - Internal:
@spekjs/core1.14.0 adds the@spekjs/core/spec-topicsubpath;@spekjs/ui1.4.0 requires it