JiRaska/open-bank-oss
62.9
Adequate · 8 October 2026
381.7k
lines of production code
Kotlin
with TypeScript
3
measurements over time
What this system is
This system is a comprehensive digital banking platform that manages core financial operations, including account lifecycle, payments, lending, and treasury. It enforces strict regulatory compliance through features such as AML, KYC, sanctions screening, and four-eyes approvals, while providing a robust operator console for monitoring and administrative tasks. The architecture integrates automated governance agents and AI capabilities to audit code and infrastructure, ensuring security and system health through continuous oversight and observability.
Features
AI agent governance: evals registry, agent charters, and card capability registry
The governance library now includes a structured AI agent governance framework. It introduces an evals registry (ADR-0148) with a README, baselines, and specific eval suites for agents like compliance-officer, control-liveness-sentinel, customer-copilot, and devops-agent, ensuring agent behavior is tested against injection and accuracy scenarios. It also adds agents-opa-data.yaml, which defines tool allow/deny policies for various agent roles (e.g., compliance-officer, ledger-domain-engineer, customer-copilot) to be consumed by OPA policies. Additionally, a new card-capabilities.yaml registry (ADR-0283 phase 2) documents card scheme capabilities (e.g., BIN lookup, tokenization) for Visa and Mastercard, including their availability and bindings. Finally, ai-rollout.yaml provides a narrative for the AI governance rollout (ADR-0031), and case-collaboration-opa-data.yaml defines case collaboration grants for agents.
openbank-libs · high confidence
AP2 mandate verification service introduces bank-side authorization evidence
The new openbank-ap2-service provides a bank-side verification endpoint (POST /ap2/verify) that validates Agent Payments Protocol (AP2) signed mandates as authorization evidence without moving funds. It performs a two-stage check—verifying the Ed25519/ES256 signature chain against a configured trust list and enforcing domain constraints (payee, amount cap, currency, expiry)—and returns a verdict with data-minimized evidence. The service is gated by the shared OPA policy decision point (failing closed if the PDP is unavailable) and exposes detailed Micrometer metrics for signature outcomes, constraint violations, and verification latency.
openbank-ap2-service · high confidence
API endpoints for managing delegation role presets
Added server-side API routes to support the creation, retrieval, update, and deletion of delegation role presets. The new endpoints proxy requests to the delegation service, enforcing authentication and validating preset IDs, which enables the admin UI to manage reusable role configurations.
openbank-admin-ui/src/app/api/delegation-role-presets · high confidence
Add CVE evidence fetching logic for inventory
The inventory module now includes a new \cveEvidence.ts\ file that defines the data structures and logic for fetching Common Vulnerabilities and Exposures (CVE) information. This implementation maps specific components (Quarkus, Kotlin) to their OSV coordinates and fetches vulnerability data from the \/api/sbom/cve\ endpoint, handling loading, verified, and unavailable states with a 10-second timeout.
openbank-admin-ui/src/lib/inventory · high confidence
Add Explorer brand guide component
A new ExplorerGuide component has been added to the admin UI's brand section, providing a styled aside element for educational or navigational content. It features a branded layout with a mascot image (defaulting to the 'lion', with support for 'lioness'), customizable title and body text, and an optional action area, available in both standard and compact modes.
openbank-admin-ui/src/components/brand · high confidence
Add SCA and Settlement operator approval review pages
The admin UI now includes dedicated review pages for SCA and Settlement operator approvals. Users with the 'operator-approvals:decide' permission can access these via the new /approvals/sca/\[id\] and /approvals/settlement/\[id\] routes, which render the OperatorApprovalWorkbench component to inspect and decide on specific requests. An API endpoint at /api/sca/approvals/\[id\] supports GET and PATCH operations to fetch and forward these decisions to the upstream operator service.
openbank-admin-ui/src/app/api/sca, openbank-admin-ui/src/app/approvals/sca, openbank-admin-ui/src/app/approvals/settlement · high confidence
Add SLSA build-provenance attestation and harden SBOM attestation verification
The deployment pipeline now generates and attaches a SLSA v0.2 build-provenance attestation to deploy images, proving which repository, commit, and CI workflow produced each image. This is complemented by a hardened SBOM attestation helper that strictly validates the CycloneDX document before signing, pins the use of cosign v2 for Kyverno compatibility, and verifies that the specific attestation envelope landed in the image rather than relying on older, potentially stale envelopes.
openbank-infra/scripts · high confidence
Add SWIFT message detail page
Introduces a new detail view for individual SWIFT messages, accessible via the /swift/\[id\] route. The page displays key message attributes including ID, type, reference, status, creation time, sender/receiver BICs, and amount, alongside a toggleable raw JSON payload. It handles loading, not-found, and unreachable states with appropriate feedback and includes a refresh action to re-fetch the latest verified snapshot from the SWIFT service.
openbank-admin-ui/src/app/swift/\[id\] · high confidence
Add Temporal Workflow Flow page
A new Temporal Workflow Flow page has been added to the admin UI, providing a visual representation of money-path saga workflows as animated step-chains. The page displays live aggregate metrics (scheduled, completed, failed, and timed-out workflows over the last hour) fetched from the Temporal status API, alongside reference diagrams that illustrate the code-defined workflow steps and compensation paths.
openbank-admin-ui/src/app/temporal/flow · high confidence
Add bilingual DORA metric labels for DevOps findings
A new shared constant providing Czech and English labels for DORA metrics (Deployment Frequency, Lead Time for Changes, Change Failure Rate, and Time to Restore) has been added to the DevOps library. This allows the DevOps page and the Remediation Review Dialog to display localized metric tags without creating circular dependencies between the modules.
openbank-admin-ui/src/lib/devops · high confidence
Add consents lookup page for operators
Introduces a new Consents page in the admin UI, allowing operators to look up consent evidence by party or grantee. Since the consent service does not expose a global list endpoint, this page implements a lookup interface with two lenses: searching by party (the default view) and by grantee (providing a global view of active marketing consents for the fixed grantee party-service:marketing-comms). The implementation includes logic to handle in-flight request race conditions when switching lenses, ensuring that stale results from previous lookups do not incorrectly display under the new context.
openbank-admin-ui/src/app/consents · high confidence
Add contextual operational insights panels
The admin UI now includes a new ContextualInsights component that embeds live Grafana panels directly into the interface. This feature provides operators with immediate visibility into key operational metrics—such as payment success rates, ledger error rates, and event backlog—without needing to navigate away to the Grafana dashboard. The component supports collapsible sections, automatic dark/light theme synchronization, and handles cross-origin authentication loading states with skeleton screens and timeout indicators.
openbank-admin-ui/src/components/insights · high confidence
Add dedicated payment detail page for SEPA and domestic payments
Introduces a new page at /payments/\[id\] that displays detailed information for individual SEPA and domestic payments. The page loads payment data via the backend API, handles loading and error states, and presents key details such as payment ID, status, amount, parties, and routing information. It supports refreshing the payment data and displays status badges with appropriate tones for RECEIVED and SENT\_TO\_CLEARING states.
openbank-admin-ui/src/app/payments/\[id\] · high confidence
Add notifications management page
The admin UI now includes a new NotificationsPage component that allows administrators to view, paginate, and refresh a list of system notifications. This page fetches data from the notification service API, handles various error states (such as unauthorized access or unreachable services) by displaying a graceful error panel, and supports pagination with a page size of 20 items. It also includes logic to handle race conditions during loading and ensures that sensitive data is cleared upon authentication failure.
openbank-admin-ui/src/components/notifications · high confidence
Add onboarding conversion analytics page
A new page at /onboarding/analytics provides historical funnel analysis for the onboarding process. It visualizes conversion rates, drop-off points, median dwell times, and signature success/failure reasons by querying the ClickHouse-backed /api/onboarding/funnel-analytics endpoint. Users can filter data by date range and refresh the view, with support for Czech and English localization.
openbank-admin-ui/src/app/onboarding/analytics · high confidence
Add operator page to query and view settlement status
Operators can now look up a settlement by its transfer reference ID to view its persisted state. The new settlements page provides a lookup form that validates the UUID and navigates to a detail view, which displays key details (payer/payee accounts, amount, currency, timestamps) and the current status (e.g., PENDING, BOOKED, REJECTED) via a dedicated status panel. The status panel includes a refresh button to re-query the backend and handles various error states (not found, unauthorized, unreachable) with user-friendly messages. This feature is read-only and does not initiate or retry transfers.
openbank-admin-ui/src/app/settlements, openbank-admin-ui/src/components/settlement, openbank-admin-ui/src/lib/settlement · high confidence
Add regulatory period management panel
A new RegulatoryPeriodPanel component has been added to the admin UI, enabling operators to manage immutable FINREP/COREP evidence. This feature allows a maker to create a draft for a completed month, while a separate operator can verify the evidence hash and freeze the period to create immutable regulatory proof. The panel includes controls for selecting the month, refreshing data, and handling the draft/verify/freeze workflow with appropriate role checks and status notifications.
openbank-admin-ui/src/components/closings · high confidence
Added CI fuzzing infrastructure for libs-domain parsers
Added ClusterFuzzLite configuration files (Dockerfile, build script, and project config) to enable continuous fuzzing of the libs-domain parsers. The setup uses a pinned OSS-Fuzz base image, installs JDK 25 to match the project's target, and delegates the actual build logic to the existing ossfuzz build script, ensuring consistency with the OSS-Fuzz proposal.
.clusterfuzzlite · high confidence
Added documentation diagrams for account lifecycle and AML freeze workflows
New Mermaid diagrams have been added to the openbank-account-service resources to visualize key business processes. These include the account lifecycle state machine (covering states like Pending Activation, Active, Dormant, Frozen, and Closed), the entity-relationship schema for accounts and related tables (authorizations, pockets, balances), and the sequence diagram for the AML/court-order freeze workflow, detailing the interaction between the Admin UI, Account Service, database, and event outbox.
openbank-account-service/src/main/resources/diagrams · high confidence
Admin UI API route for fetching published incentive offers
The admin interface now includes a new API endpoint at /api/incentives that retrieves published incentive offers from the backend incentive service. This route handles authentication via the user's access token, forwards the request to the incentive service on port 8156, and returns the list of offers along with a state indicator (ok, unauthorized, not\_deployed, or unreachable) to help the UI manage loading and error states effectively.
openbank-admin-ui/src/app/api/incentives · high confidence
Admin UI adds server-side tracing, telemetry relay, and governance snapshots
The admin console now captures server-side OpenTelemetry traces for inbound requests and outbound BFF calls, using a preloaded bootstrap script to ensure spans are exported and PII is scrubbed from query strings before transmission. A new same-origin telemetry relay endpoint allows browser-based RUM data to be forwarded to the in-cluster collector. Additionally, the UI now serves a read-only AI governance snapshot detailing control maturity and compliance status, exposes a list of Communication Studio personas, and relays product-catalog requests with the operator's OIDC bearer token to fix upstream authorization failures.
openbank-admin-ui · high confidence
Admin UI exposes FinOps tier classification report via API
The admin UI now provides an API endpoint at /api/finops/tier-classifier that serves the daily FinOps tier classification report generated by the ADR-0057 CronJob. This allows the admin interface to display per-service tier drift and recommendations as a read-only markdown view, with the API returning availability status and the report content once the daily job has produced output.
openbank-admin-ui/src/app/api/finops/tier-classifier · high confidence
Admin UI library: new catalog, test-intelligence, and messaging capabilities with license update and security hardening
The \openbank-admin-ui/src/lib\ area introduces several new capabilities and updates existing behavior. For product cataloging, new modules (\catalog-bundle-proposals\, \catalog-offer-composition\, \catalog-offer-intelligence\, \catalog-offer-selection\, \catalog-review-capability\, \catalog-schema-form\, \catalog-structural-diff\, \product-catalog-v2\) provide deterministic, privacy-safe bundle simulation, offer selection, schema-based form generation, and a v2 API client. For test intelligence, new modules (\test-intelligence-execution-evidence\, \test-intelligence-freshness\, \test-intelligence-state\, \test-intelligence-triage\) add evidence aggregation, staleness enforcement, state prioritization, and triage filtering. Operator messaging is enabled via \opsMessageApi\ in \api.ts\, supporting composed messages and four-eyes approval decisions. The library's license is updated from MPL-2.0 to Apache-2.0. Security is improved by encoding dynamic API path segments in \api.ts\ to prevent path traversal, and by adding a CodeQL suppression for a known Kubernetes API token access pattern in \discovery.ts\. Service discovery in \discovery.ts\ is expanded to include new namespaces like \documents\, \engagement\, \referral\, \kyb\, \communication\, and \context\.
openbank-admin-ui/src/lib · high confidence
Admin UI now exposes Pyrra SLO evidence via a new API route
A new API endpoint at /api/pyrra/summary has been added to the Admin UI, allowing the interface to retrieve operational evidence (availability and error budgets) for six key customer journey SLOs. Instead of adding a new service edge, this route queries the existing Prometheus instance for Pyrra's 30-day increase recording rules, returning structured data on transaction, ledger, SEPA instant, domestic payment, settlement, and fraud availability. This enables the Admin UI to display real-time SLO compliance data without bypassing Pyrra's identity gate.
openbank-admin-ui/src/app/api/pyrra · high confidence
Admin UI now exposes a referral programs API route
The admin interface now includes a new API endpoint at /api/referral-programs that fetches the published MGM programme catalogue from the referral service. This route handles authentication via the admin session, proxies requests to the backend service (defaulting to localhost:8155 or the Kubernetes service), and returns the list of programs along with a state indicator (ok, unauthorized, not\_deployed, or unreachable) to help the UI handle different service availability scenarios.
openbank-admin-ui/src/app/api/referral-programs · high confidence
Admin UI now supports viewing and uploading yield curve sets
The balance-sheet admin interface now includes dedicated pages for managing yield curve sets. Users with the 'balance-sheet:curves:upload' permission can upload curve sets via a guided form that enforces provenance tracking (preventing synthetic defaults and restricting uploads to risk/admin roles), while all users with 'balance-sheet:view' access can browse a list of existing sets and view detailed breakdowns of pillars, zero rates, and discount factors per index and currency.
openbank-admin-ui/src/app/balance-sheet/curve-sets · high confidence
Admin UI payment lists now support query parameters
The domestic and SEPA payment list endpoints in the admin UI now accept and forward query parameters from the browser to the backend services. Previously, these API routes performed static GET requests without any search or filter arguments; they now import a shared \paymentListQuery\ utility to construct the request URL based on \req.nextUrl.searchParams\. This change enables the frontend to pass filters, pagination, or sorting criteria to the underlying payment services, allowing users to refine the displayed payment evidence lists.
openbank-admin-ui/src/app/api/domestic-payments, openbank-admin-ui/src/app/api/sepa-payments · high confidence
AnaCredit service gains persistent credit exposure storage and IFRS 9 stage projection
The AnaCredit service now persists credit exposures in Postgres (replacing the previous in-memory store) and introduces a durable IFRS 9 stage projection for loans. This projection is updated via a new Kafka consumer for lending's loan.stage\_changed events, with idempotent writes to handle out-of-order or duplicate deliveries. Observability is enhanced with new metrics for exposure intake, return building, and loan stage event outcomes. The service also includes a Dockerfile for containerization and updated diagrams reflecting the new data model and reporting flow.
openbank-anacredit-service · high confidence
Analytics sink: improved event attribution, initial account seeding, and credit-lifecycle marts
The analytics sink now derives producing domain and service from Kafka topic metadata (headers and keys) rather than relying solely on message bodies, significantly reducing 'UNKNOWN' attribution for events like transactions and standing orders. To ensure historical data integrity, a new initial-load backfill seeds the warehouse with existing account ownership from the account registry, preventing invisible gaps in Customer 360 views. Additionally, the sink now exposes a credit profile REST endpoint and introduces ClickHouse views for credit-lifecycle marts (decisions, IFRS 9 staging, vintage) and settled transaction facts, enabling downstream lending and financial health analytics that were previously unavailable due to missing data or schema definitions.
openbank-analytics-sink · high confidence
Audit attribution and savings withdrawal approval event
Account domain events now include explicit \occurredAt\ timestamps and a \sourceService\ field (set to "account-service") to improve audit trail accuracy and source attribution for consumers like balance-service and statement-service. Additionally, a new \SavingsWithdrawalApproved\ event has been introduced to signal that a delegate's withdrawal proposal has been approved by the account owner, enabling the payments path to execute the fund transfer.
openbank-account-service/src/main/kotlin/com/openbank/account/domain/event · high confidence
Authz-policy-auditor agent introduces static OPA/Rego drift detection and LLM diagnosis
The openbank-authz-policy-auditor service now runs automated sweeps against the fleet's OPA/Rego authorization sources and agents.yaml charters to detect drift. It implements four static checks: identifying structurally unreachable principal-type rules, catching agent-ID prefix mismatches on the REST bridge, flagging charter tool-tier drift (typos in allow tokens or dead deny globs), and preventing REST bypasses of agent allow-lists. Findings are diagnosed via an LLM gateway (ADR-0148/ADR-0167) and, per security policy, are never auto-fixed; instead, the service refuses to fabricate proposal URLs and returns null when no GitHub ticket or PR is created, ensuring findings remain in a DIAGNOSED state until a human triages them. The agent runs as a Temporal workflow with idempotent scheduling and exposes its findings through a dedicated repository.
openbank-authz-policy-auditor · high confidence
Automatic creation of business current accounts during onboarding
Business parties (companies and sole traders) now automatically have a current account opened in a PENDING\_ACTIVATION state when they activate, provided they do not already have one. This new BusinessOnboardingAccount component ensures idempotency so that racing events or retries do not create duplicate accounts, streamlining the setup process for business customers.
openbank-account-service/src/main/kotlin/com/openbank/account/application/onboarding · high confidence
Balance service introduces four-eyes approval, transactional outbox, and value-date roll capabilities
The balance service now enforces a four-eyes approval gate for credit and debit actions, requiring an operator to explicitly approve or reject pending requests via a new REST endpoint. Event publishing has migrated from a direct emitter to a transactional outbox pattern, ensuring balance events are persisted atomically with their corresponding state changes. Additionally, a daily value-date roll scheduler now announces the maturity of future-dated credits, updating downstream systems so that funds become spendable on their effective date. These changes are supported by database migrations that repair historical double-counting errors, add idempotency constraints for holds, and optimize queries for value-date projections.
openbank-balance-service · high confidence
Billing service introduces fee assessment, outbox-based ledger posting, and annual fee summaries
The billing service now implements the core fee lifecycle: it assesses account fees against product-catalog rules (with fail-closed behavior when data is missing), persists assessments atomically with outbox rows for ledger posting, and supports fee reversals via a four-eyes approval flow. It also generates PAD Art. 5 annual fee summaries by aggregating posted fees per account and year. This location provides the application-layer use cases, domain models, and outbound ports (including the ledger posting adapter) that drive these capabilities.
openbank-billing-service · high confidence
Browser RUM telemetry and BFF tracing infrastructure
The admin UI now captures browser-based Real User Monitoring (RUM) data, including Core Web Vitals (CLS, INP, LCP) and screen views, using a dedicated OpenTelemetry WebTracerProvider with a distinct service name ('openbank-admin-ui-browser') to separate it from server-side BFF traces. This change introduces new modules (\rum.ts\, \rum-service-name.ts\) to handle browser telemetry export via an authenticated relay, while \tracing.ts\ ensures necessary OpenTelemetry packages are bundled for the Node.js BFF preload. Additionally, the license header in \glitchtip.ts\ was updated from MPL-2.0 to Apache-2.0.
openbank-admin-ui/src/lib/telemetry · high confidence
Business co-signing, screen feedback, and per-party rate limiting
The customer-edge now supports multi-signature business payments, allowing entities to hold and release payments against a signing policy enforced by delegation-service. It also introduces screen feedback submission with screenshot storage and telemetry, and enforces a configurable per-party request rate limit (default 100/min) using Valkey.
openbank-customer-edge · high confidence
Business onboarding read model and operator cockpit
The onboarding service now projects \openbank.kyb.events\ into a separate business onboarding read model, giving operators a dedicated cockpit to track legal-entity cases. This includes a new REST API (\/api/v1/onboarding/business\) to list cases, view individual case details, and see funnel-stage counts, alongside a new database table (\business\_onboarding\_records\) and a Kafka consumer (\kyb-events-in\) that handles out-of-order replays and GDPR erasure for natural persons involved in business cases.
openbank-onboarding-service · high confidence
Campaign authoring and monitoring now use a visual canvas and evidence-based dashboards
The campaign builder has shifted from a form-based interface to a visual, linear canvas (JourneyEditor) that lets marketers add, edit, and remove steps directly. This is supported by a JourneyRecipePicker that provides app-first templates (such as push, banner, and email-with-fallback) to quickly scaffold journeys. For monitoring, the interface now displays a CampaignPlanningBoard to show upcoming scheduled windows, a CampaignLaunchReadiness checklist to verify audience, content, and policy constraints before publishing, and a CampaignOutcomeBrief to show aggregate metrics like audience size, handed-off sends, and conversions. Additionally, a CampaignAttentionFunnel component provides verified in-app engagement data (impressions, clicks, and dismissals) to help marketers understand what users actually did, while a JourneyCanvas visualizes the campaign flow and drop-off reasons.
openbank-admin-ui/src/components/campaigns · high confidence
Campaign service introduces domain metrics and operator-facing analytics surfaces
The campaign-service now emits domain-level metrics (via CampaignMetricsPort) to expose silent failure modes such as dry-run sends, suppressed journeys, and enrolment stalls, enabling operators to distinguish between active campaigns and those contacting no one. Additionally, the service provides new read-model queries for Campaign Studio: a planning radar showing scheduled windows, engagement funnels for in-app surfaces, holdout and content experiment results with statistical confidence intervals, and a paginated send log that includes suppressed outcomes for full visibility.
openbank-campaign-service · high confidence
Card issuance now enforces real-time controls, secure vaulting, and delegation
Card issuance now actively enforces customer-set channel controls (contactless, online, ATM, abroad) and spending limits (daily, monthly, and per-category) at the point of authorization, rather than merely storing them. The service introduces a synthetic PAN vault to securely store card credentials using AES-256-GCM encryption, including a backfill job to populate this vault for pre-existing cards and a re-encryption job to migrate credentials to new keys. Additionally, the service now supports card delegation, allowing cardholders to grant specific permissions (view, manage limits) to other parties via an enforcement projection.
openbank-card-issuance-service · high confidence
Clearing page modernized with unified layout and enhanced data visibility
The Clearing & Settlement page now uses the unified OperatorLayout shell, replacing the previous custom sidebar and header. The interface displays gross debits instead of a single currency volume, supports multiple currencies, and shows 'In clearing' status alongside 'Pending'. It also preserves the last successful data snapshot when the service is unavailable, ensuring users retain visibility of clearing batches during outages.
openbank-admin-ui/src/app/clearing · high confidence
Clearing service posts net-settlement journals and enforces four-eyes approval
The clearing service now posts a balanced double-entry net-settlement journal to the ledger service for every settled batch, debiting the Customer Cash Clearing GL and crediting the Scheme Settlement GL in the batch currency, with idempotency enforced via a deterministic key to prevent double-settlement. It also exposes a REST endpoint for operators to view and decide on pending four-eyes approvals, gating settlement actions until a second operator authorizes them.
openbank-clearing-service · high confidence
Communication Studio persona overview and style editor added
The admin UI now includes a Communication Studio section with a persona list page showing prompt registry status and a persona detail page displaying the locked core prompt and editable style/playbook layers. A new style editor page allows makers to draft and submit style versions for review, while approvers can initiate publishing; it also includes a golden-set editor for managing test inputs.
openbank-admin-ui/src/app/communication · high confidence
Communication service introduces style, playbook, and golden-set management capabilities
The openbank-communication-service now provides the backend logic for managing communication personas, including the ability to draft, review, publish, and retire communication styles and playbooks (call scripts and approved answers) with mandatory four-eyes approval and deterministic content linting. It also introduces a golden-set domain model for storing test questions and expected properties, along with a pure, non-LLM scorer to validate composed answers against these criteria. This change establishes the core application services, domain models, and outbox event publishing for persona updates, while explicitly excluding the replay gate and UI components which are handled in other areas.
openbank-communication-service · high confidence
Control-liveness-sentinel service introduces scheduled autonomous health checks with LLM-driven diagnosis and remediation proposals
The openbank-control-liveness-sentinel service is now fully operational, enabling automated daily liveness checks that run on a schedule rather than only on manual trigger. The service implements four ADR-0160 control mechanisms: workflow heartbeat monitoring, event consumer liveness, lineage-vs-code verification, and reconciliation drift detection. When issues are detected, the service uses an LLM to diagnose root causes and can automatically propose fixes by creating GitHub pull requests or tracking tickets. The system is designed to be idempotent for scheduled runs, preventing duplicate executions, and includes proper Prometheus metric integration for observability.
openbank-control-liveness-sentinel · high confidence
Controlled P0/P1 banking context investigations and assignment administration
The admin UI now supports controlled investigations for complaints and incident impacts, requiring explicit case IDs and purposes to access context data. For complaints, a new UI component displays a relationship graph of the context neighborhood, including a payment timeline, while incident investigations show an aggregate business impact map without exposing individual customer identifiers. Access to these sensitive views is governed by a new time-bound assignment system: administrators can propose access for specific principals, cases, and purposes, which must be independently approved by another admin before becoming active, and can be revoked at any time.
openbank-admin-ui/src/app/api/context, openbank-admin-ui/src/components/context · high confidence
Copilot service re-licensed to AGPL-3.0-only and introduces credit AI levels with content-safety guardrails
The openbank-copilot-service is now licensed under the GNU Affero General Public License v3.0-only (open-core dual-licensing), replacing the previous MPL-2.0 terms. Functionally, the service now enforces a three-tier credit AI level system (L0 Explainer, L1 Advisor, L2 Agent) gated by specific customer consents, allowing the assistant to read credit profiles and assess affordability only when permitted. It also introduces a model-based content-safety guardrail (Llama Guard) that inspects both user inputs and assistant outputs, auditing and blocking unsafe content based on a configurable fail-closed policy. Additionally, the service implements hybrid help retrieval that fuses keyword and semantic (vector) search results, and ensures GDPR compliance by hard-deleting conversation history upon receiving PARTY\_ERASED events.
openbank-copilot-service · high confidence
Cost report API now includes daily spend trends
The FinOps costs API endpoint now returns a daily spend trend alongside the existing total cost and service breakdown. Consumers of this API will receive a new \daily\ array in the response, containing per-day totals (date and amount) when available, enabling them to visualize spending patterns over time rather than just aggregate figures.
openbank-admin-ui/src/app/api/finops/costs · high confidence
Customer-facing payment confirmation download and rejection notifications
Customers can now download a rendered HTML confirmation for settled domestic payments and receive explicit notifications when a payment is rejected by the scheme. The service introduces a new read-only confirmation flow that resolves the published document template and renders it on demand via the document service, and adds a customer notification port that maps internal rejection reasons (including sensitive AML/fraud flags) to safe, customer-facing messages.
openbank-domestic-payment · high confidence
Customer-facing styled statement download and closed-period restatement capability
Statement service now supports two new capabilities for customers and compliance: a customer-facing styled statement download endpoint that renders a Handlebars template via document-service on demand (without persisting the output), and a restatement path that allows correcting a previously closed statement period by issuing a new legal sequence that supersedes the old one. The restatement logic recomputes the period, enforces reconciliation, and emits a new \account.statement.period.restated.v1\ event with proper audit attribution (\sourceService\, \occurredAt\). To support these features, the database schema was extended with migrations to add a \claimed\_at\ column for atomic outbox row claiming, a \model\_snapshot\ column to freeze render inputs for byte-identical re-renders, a \supersedes\_sequence\ reference for the restatement chain, and a \synthetic\ flag for outbox taint tracking. Additionally, the outbox dispatcher now uses \FOR UPDATE SKIP LOCKED\ to prevent concurrent row claims during canary deployments, and a constraint ensures outbox \created\_at\ timestamps are plausible (post-2020).
openbank-statement-service · high confidence
Dark theme is now user-accessible and persistent
Operators can now actively switch the admin interface between light and dark modes, with the preference saved via local storage and cookies to persist across sessions. Previously, dark theme styles existed in the CSS but were never applied to the application state, making the feature unreachable for end users; this change introduces a React context and hook to manage the theme toggle and ensure the UI reflects the user's choice.
openbank-admin-ui/src/lib/theme · high confidence
Day-end UI: unified layout, regulatory period tab, and stale tie-out detection
The Day-end page now uses the shared OperatorLayout for consistent navigation, and adds a new 'Regulatory period' tab to the closing controls. The daily tie-out (EoD) panel now detects stale results (older than 25 hours) instead of showing 'no data', and displays the count of excluded currencies in the reconciliation report. The UI also includes a new PageHeader component and improved accessibility attributes for the tab navigation.
openbank-admin-ui/src/app/day-end · high confidence
Delegation service initial release (v0.17.0)
The openbank-delegation-service is introduced as a new component, establishing the foundational infrastructure and core delegation capabilities. This release includes the service's Dockerfile, governance manifest, and static analysis baselines, alongside the implementation of customer-to-party access grants, business payment signing with N-of-M approvals, managed account portfolios, and a customer recertification workflow. It also enforces organization grant authority, projects approval policies to accounts, and adds lifecycle approval evidence and spend reservation counting to ensure secure and auditable delegated financial operations.
openbank-delegation-service · high confidence
Disputes page modernized with unified layout and enhanced service status visibility
The Disputes page now uses the shared OperatorLayout for consistent navigation and styling, replacing the previous custom sidebar/header structure. The interface has been updated to use new UI components (PageHeader, StatCard, ServiceStatusBadge) and a centralized dispute data hook, which provides clearer visibility into the dispute service's state, including scale-to-zero idle states and snapshot retention during refreshes. Additionally, the page now integrates ContextAssignmentAdministration and ComplaintContextInvestigation components, and improves accessibility with proper ARIA labels and live regions for loading and status updates.
openbank-admin-ui/src/app/disputes · high confidence
Docs-truth-agent introduces ADR drift detection and fixes proposal reporting
The docs-truth-agent now runs a scheduled sweep that scans ADRs for drift against the codebase, detecting three specific issues: shipped artifacts that are missing, planned artifacts that have already been shipped, and enforcement status mismatches between ADR claims and governance rules. The agent uses an LLM to diagnose findings and attempts to propose fixes, but currently refuses to create GitHub proposals or tickets (returning null) because the write path is not yet wired, ensuring no fabricated URLs are reported.
openbank-docs-truth-agent · high confidence
Document service scaffolding and initial domain model
The document-service module is introduced with its foundational infrastructure and core domain contracts. This includes the Dockerfile (exposing port 8143), governance manifest, and build wrappers. The application layer defines the primary use-case interfaces for template management, document rendering, signature ceremonies, and onboarding, along with the outbound ports for persistence, PDF generation, and SCA verification. A new annual statement delivery capability is implemented to handle fee-summary events, and the initial domain models for documents and templates are established.
openbank-document-service · high confidence
Documented Temporal workflow steps for money-path sagas
The admin UI now displays the specific steps for key money-path workflows (domestic payments, SEPA payments, FX conversions, and closings) via a new shared data file. This curated list of saga steps, including compensation branches, is used by the Temporal overview and flow pages to provide users with clear, documented visibility into the lifecycle of these transactions rather than relying on scraped live history.
openbank-admin-ui/src/lib/temporal · high confidence
Domain library module split and new feature/money domain primitives
The \openbank-libs\ module has been split into domain and runtime parts, moving core domain types (such as \CzechAccountNumber\, \CasePriority\, and \Ids\) into the new \openbank-libs-domain\ module. This location introduces new domain primitives: an \OnlineFeatureStore\ interface for low-latency feature lookups and windowed event counting, a \VelocityWindow\ enum for tumbling time buckets, and a \RoundingPolicy\ registry that centralizes rounding rules (scale and mode) for money, interest, FX, and treasury calculations. Additionally, money validation is now typed via \InvalidMoneyException\ and \InvalidMoneyReason\, providing specific error codes for scale, currency, and positivity failures.
openbank-libs-domain/src/main/kotlin/com/openbank/libs/domain · high confidence
Enhanced account opening controls and new savings goal delegation capabilities
Account opening now validates against the product catalog to ensure the product exists and is active, and requires a terms version for term deposits. The service also supports idempotent account creation to prevent duplicate openings. A new savings goal delegation system allows delegates to propose withdrawals that require owner approval via SCA, with a dedicated guard enforcing grant validity. Authorization is expanded to support delegated access grants alongside legacy mandates, and owners can now view all parties with effective access to their accounts.
openbank-account-service/src/main/kotlin/com/openbank/account/application/usecase · high confidence
Enhanced account opening with product selection, party search, and idempotency
The new account creation page now fetches active products from the catalog to allow users to select a product, which automatically populates account type, currency, and terms. It includes a PartySearch component for selecting customers and ensures sanctions screening uses the selected party's legal name. The submission process now uses a stable idempotency key to prevent duplicate account creation on double-submits and handles specific contract errors gracefully.
openbank-admin-ui/src/app/accounts/new · high confidence
Expanded account management and delegation authorization capabilities
This change introduces several new capabilities to the account service's internal API. Users can now manage savings goals (setting, updating, and clearing them) and rename accounts with custom display labels. For term deposits, opening an account now supports recording specific terms versions and effective dates. Additionally, the service exposes a fleet-wide query to list active accounts for billing discovery, provides account owners with a view of all parties who can act on their account, and implements a detailed authorization check for delegated payments that returns specific audit evidence (grant ID, grantor) and outcome reasons (e.g., limit exceeded, no grant) rather than a simple boolean.
openbank-account-service/src/main/kotlin/com/openbank/account/application/port/in · high confidence
Expanded test intelligence type definitions and license update
The admin UI now supports a richer set of test evidence types, including new interfaces for performance evidence (with k6 threshold results), synthetic journey evidence, mutation testing details (including timed-out mutants), and contract verification provenance (tracking consumer/provider versions and unresolved reasons). A new \test-intelligence.ts\ file introduces types for infrastructure observations (collapsing Testcontainers lifecycle reprovisions) and diagnostic artifacts. Additionally, the license header in these type files has been updated from MPL-2.0 to Apache-2.0.
openbank-admin-ui/src/lib/types · high confidence
Expose live campaign launch guardrails via API
A new API endpoint at /api/campaigns/guardrails has been added to the admin UI, allowing the Studio interface to retrieve the current live platform guardrails for campaign launches. This endpoint authenticates the user and proxies the request to the campaign service, ensuring that the UI displays the actual enforced policies rather than local defaults, while handling authentication errors and service unreachability gracefully.
openbank-admin-ui/src/app/api/campaigns/guardrails · high confidence
Exposes build attestation endpoint for synthetic monitoring
The admin UI now includes a new public endpoint at /.well-known/openbank-build-attestation that returns the current build's Git SHA. This minimal, credential-free interface allows synthetic monitors to verify the running version of the admin UI without exposing operator APIs, configuration details, or deployment specifics.
openbank-admin-ui/src/app/.well-known · high confidence
FX service introduces four-eyes approval workflow and enhanced operational observability
The FX service now supports a four-eyes approval gate for FX conversions, exposing a new REST endpoint at \/api/v1/fx/approvals\ that allows operators to list and decide on pending approvals, backed by a new Redis-based approval store. To improve operational visibility, the service now exposes metrics to distinguish between real and synthetic fraud-scoring verdicts (indicating when the fraud service is degraded), and classifies ČNB rate ingestion outcomes into specific categories (e.g., HTTP error, unreachable, parse error) to aid in troubleshooting. Additionally, the database schema for the transactional outbox has been extended with columns for \claimed\_at\ (to support atomic row claiming), \synthetic\ (to track synthetic-origin events), and a constraint on \created\_at\ to prevent invalid epoch timestamps.
openbank-fx-service · high confidence
FinOps agent gains scheduled analysis, persistent anomaly memory, and LLM gateway integration
The openbank-finops-agent now runs a daily analysis sweep automatically (previously it only responded to manual triggers), ensuring cost anomalies are detected without operator intervention. To support this, the agent has replaced its in-memory anomaly storage with a durable PostgreSQL backend (including the \anomalies\ table and \PostgresAnomalyRepository\), so rejected or resolved anomalies are not re-proposed after a pod restart. Additionally, the agent now integrates with an LLM gateway via \LlmGatewayProducer\ for diagnosis and proposal generation, and includes a \FinOpsAnalysisScheduler\ with workflow liveness recording to monitor the scheduled job's health.
openbank-finops-agent · high confidence
Finance team can now void back-posted loans via a four-eyes UI
The admin UI now includes a dedicated page for voiding previously executed ledger back-fills, allowing finance staff to cancel a back-post by creating offsetting journal entries and marking the affected loans as voided. This feature mirrors the existing back-fill workflow by enforcing a four-eyes control: a user proposes the void, a different person must approve it, and the system records the specific identities of the proposer, approver, and executor to ensure auditability.
openbank-admin-ui/src/app/balance-sheet/ledger-backfill · high confidence
Flaky Test Hunter findings page and detail view
The IAOps section now includes a dedicated Flaky Test Hunter interface. The main page lists active findings across four check types (runBlocking unit drop, Pact local-verification blind spot, Pact provider collision, and test-count drift) and provides an operator-triggered weekly sweep with idempotent admission and retry-safe behavior. Clicking a finding opens a detail view that displays the full record, including severity, status, file path, measured values, timestamps, root cause, and any proposed fix diff with a link to the pull request.
openbank-admin-ui/src/app/iaops/flaky-test-hunter · high confidence
Four-eyes approval queue for SWIFT send actions
Operators can now view and decide on pending four-eyes approvals for SWIFT messages via a new \GET /api/v1/swift/approvals\ endpoint. Previously, a maker's \POST /api/v1/swift\ call was paused with a 202 and an approval ID, but there was no way for a checker to discover or act on that pending request other than out-of-band communication. This change introduces a dedicated approval inbox that lists pending approvals (oldest first, limited to 200) and allows a checker to approve or reject them via \PATCH /api/v1/swift/approvals/{id}\, ensuring the four-eyes ceremony completes reliably within the 24-hour Redis TTL.
openbank-swift-service · high confidence
Fraud review queue now visible in the admin console
The fraud analyst console now exposes the REVIEW queue, which previously was not accessible in the UI. This change adds a new page at /fraud that displays a table of payments flagged as REVIEW by the engine, including details such as amount, rail, account, score, rules, and timestamp. The page includes summary statistics for critical and elevated scores, supports manual refresh, and handles data unavailability by showing the last successful snapshot. This is a read-only view; resolution of these items remains in the four-eyes compliance flow.
openbank-admin-ui/src/app/fraud · high confidence
Fraud service adds marketing-suppression holds and shadow ML scoring
The fraud service now supports two new capabilities: a marketing-suppression hold signal and in-process shadow ML scoring. For holds, the service tracks repeated 'REVIEW' verdicts and, when a threshold is met, raises a time-limited hold on the owning party (emitted via a transactional outbox) to suppress marketing, without affecting live payment restrictions. For ML, an in-process ONNX Runtime adapter now evaluates a baseline logistic model in shadow mode—logging scores without influencing verdicts—and includes a model-card verification step and an in-image smoke test to ensure the native library loads correctly in the deployment environment.
openbank-fraud-service · high confidence
Granular do-not-contact suppressions and four-eyes approval workflow
The consent service now supports granular do-not-contact suppressions (ADR-0219 D3), allowing operators to block specific scopes or topics for a party without revoking their underlying consent. This includes a new Suppression domain model, repository, and REST endpoints for creating, listing, and revoking suppressions, backed by a new database table and idempotency constraints. Additionally, a four-eyes approval workflow (ADR-0155) has been introduced for consent grants and revocations, featuring a Redis-backed approval store and REST endpoints to list and decide on pending approvals, with a fix to ensure null request bodies return 400 instead of 500.
openbank-consent-service · high confidence
Human-in-the-loop approval endpoint for DevOps findings
A new API route at /api/devops/decide has been added to the admin UI, enabling human operators to approve or reject proposed remediations for DevOps findings. This endpoint acts as a proxy to the devops-agent, forwarding the operator's decision (approve or reject) along with the finding ID. It handles authentication via the existing auth provider and enforces input validation, ensuring that only valid IDs and actions are processed before forwarding the request to the backend service.
openbank-admin-ui/src/app/api/devops/decide · high confidence
IAOps page adopts OperatorLayout and introduces Agent Control Room UI
The IAOps page now uses the shared OperatorLayout instead of its own inline layout, ensuring consistent navigation and header behavior across operator surfaces. The page itself has been significantly expanded to include an Agent Control Room hero section with responsive CSS, dynamic imports for the AgentMeshExplainer and AgentInsightsPanel, and new data models for phase roadmaps, control maturity, and cost coverage. It also integrates contextual insights and maps FinOps anomalies to the shared AgentFinding view-model, while updating status badges and color tokens to use the new design system variables.
openbank-admin-ui/src/app/iaops · high confidence
Idempotent flaky test trigger endpoint for admin UI
The Admin UI now exposes a new API route at \/api/iaops/flaky-test-hunter/trigger\ that allows administrators to manually trigger a bounded flaky test check. This endpoint enforces idempotency by accepting a \requestedOn\ date parameter, ensuring that repeated requests for the same day do not spawn duplicate workflows. It communicates with the internal \flaky-test-hunter\ service using an idempotency key and returns a workflow ID upon successful admission (HTTP 202), while handling upstream timeouts, network errors, or unsupported backend versions with specific error codes to prevent accidental duplicate executions across UTC midnight boundaries.
openbank-admin-ui/src/app/api/iaops/flaky-test-hunter · high confidence
Immutable delegation audit timeline and reusable role presets
The delegation management library now includes an immutable audit timeline and a structured role preset system. The new \auditTimeline.ts\ module projects append-only audit evidence into a clear, comparable timeline, displaying lifecycle actions, actors, timestamps, and reasons while handling data normalization and truncation. Additionally, \rolePresets.ts\ introduces a catalog of reusable role presets with specific capabilities for accounts, cards, and savings, distinguishing between assignable delegate roles and reserved ownership roles to prevent recursive authority.
openbank-admin-ui/src/lib/delegations · high confidence
Improved feedback UI resilience, accessibility, and service status clarity
The feedback components now provide a more robust and accessible operator experience. A new SectionBoundary component isolates rendering errors to specific screen sections, preventing a single failure from crashing the entire page. The ServiceStatusBadge has been updated to distinguish between idle (scale-to-zero), checking, down, and up states, avoiding false alarms for services that are merely waking up. Additionally, the DataUnavailable component now uses appropriate ARIA live regions to announce data states to screen readers without interrupting workflow, and its default language has been corrected to English.
openbank-admin-ui/src/components/feedback · high confidence
Interest service now accrues daily and capitalizes monthly for both Savings and Current accounts
The interest service now performs actual daily interest accrual and monthly capitalization for both Savings and Current accounts, replacing the previous stub implementation. It discovers active accounts and their booked balances from the account service, synchronizes fixed interest rates from the product catalog, and posts capitalization journals to the ledger service with idempotency guarantees. Withholding tax is remitted to the tax authority via the transaction service, and the system degrades gracefully if upstream services are unavailable.
openbank-interest-service · high confidence
Introduce AI DevOps agent for SSDLC and DORA monitoring
The openbank-devops-agent is a new service that continuously monitors CI/CD pipeline health and deployment reliability using the Temporal workflow engine. It collects signals from Prometheus and the GitHub REST API to detect regressions across six key areas: CI pipeline health, DORA metric performance, runner capacity, deploy health, SSDLC hygiene, and incident recurrence. When a threshold is breached, the agent uses an LLM to diagnose the root cause and proposes a durable remediation—such as a code pull request, a runbook update, or a tracking ticket—which is then queued for human-in-the-loop (HITL) approval. The agent persists its findings in a PostgreSQL database and exposes its operational status and LLM spend metrics to Prometheus for observability.
openbank-devops-agent · high confidence
Introduce COREP C 01.00 Own Funds reporting and XBRL-CSV preflight safeguards
The finrep-service now generates the COREP C 01.00 (Own Funds) template by mapping ledger trial balance lines to EBA capital-structure accounts, explicitly flagging missing data as visible gaps rather than silent omissions. It also adds an XBRL-CSV preflight check that blocks rendering if the preview has unmapped EBA cells or if the trial balance does not balance, and introduces a robust balance-assurance mechanism that cross-checks the ledger's balance verdict against finrep's own per-currency double-entry recomputation to detect evidence defects.
openbank-finrep-service · high confidence
Introduce Customer 360 derived view with name-based search
A new Customer 360 page has been added to the admin UI, allowing operators to search for parties by name or email rather than UUID. This view aggregates derived data from the analytics silver layer (ClickHouse) to display event counts, recency, and lifecycle states across domains. The page integrates several panels including Adverse State, Lípa, Portfolio, Devices, and Documents, while explicitly noting that figures are non-authoritative and distinct from source services like CRM.
openbank-admin-ui/src/app/customer-360 · high confidence
Introduce Flaky Test Hunter agent for fleet-wide silent test failure detection
The new openbank-flaky-test-hunter service provides an automated agent that scans the entire fleet's Kotlin test sources and JUnit execution reports to detect silent test failures. It identifies four specific patterns: expression-body tests using coroutine builders (like runBlocking) without an explicit Unit return type (which JUnit5 silently drops), Pact provider verification tests gated on system properties that are skipped locally, multiple test classes declaring the same Pact provider name (causing verification collisions), and mismatches between declared and executed test counts. The agent runs as a Temporal workflow, uses an LLM to diagnose root causes and propose mechanical fixes (such as adding missing Unit types), and records all AI-attributed actions for auditability.
openbank-flaky-test-hunter · high confidence
Introduce Lístek loyalty ledger with earn, redeem, and expiry capabilities
The openbank-loyalty-service now implements the Lístek closed-loop loyalty system, allowing parties to earn 'leaves' for financial-health achievements (such as sustained savings or on-time repayments), redeem them for specific benefits (like fee waivers or interest bonuses), and track expiration. The service enforces a 5,000-leaf annual cap per party, uses an append-only ledger with FIFO consumption for burns, and ensures idempotency for both earning and redemption. It also provides a list of benefit grants and a provisioning summary for accounting, while explicitly avoiding monetary conversion to remain outside electronic money regulations.
openbank-loyalty-service · high confidence
Introduce Product Studio interface for catalog authoring and review
The Product Studio page is now available in the admin UI, providing a unified workspace for catalog authors to create and manage product specifications, offerings, and revisions. This interface supports guided form entry, JSON draft editing with schema validation, and structural diffing against live published baselines. It also includes features for proposing bundle components, managing offering relationships (such as bundles and add-ons), and previewing market-matched offers with AI-driven explanations. Private catalog reviews are integrated for authorized operators, allowing them to assess findings and approve changes before publication.
openbank-admin-ui/src/app/product-studio · high confidence
Introduce SWIFT message validation and lifecycle grouping
The SWIFT library now includes a strict message contract that validates incoming SWIFT data against defined schemas. Users can parse raw SWIFT messages into structured objects with guaranteed types for message types (e.g., MT103, MT202), statuses (e.g., PENDING, VALIDATED), and identifiers (UUIDv7, BIC codes). The library also provides utility functions to group messages by lifecycle stage (in\_flight, confirmed, exception) and map statuses to UI tones (success, danger, warning, info), ensuring consistent validation and display of SWIFT transaction evidence.
openbank-admin-ui/src/lib/swift · high confidence
Introduce Swarm Cases listing page
Added a new page at /iaops/cases that displays a list of 'swarm cases' (coordinated agent threads) with status-based filtering and pagination. The page fetches case summaries from the /api/iaops/cases endpoint, handles loading and error states (including unauthorized or unreachable service scenarios), and provides links to individual case detail views.
openbank-admin-ui/src/app/iaops/cases · high confidence
Introduce Test Intelligence API route for aggregating synthetic and RUM evidence
Added a new Next.js API route at \openbank-admin-ui/src/app/api/test-intelligence/route.ts\ that serves a consolidated Test Intelligence report. This endpoint aggregates live evidence from Prometheus (synthetic journey run history, freshness gauges) and Tempo (browser RUM trace correlations, mobile platform attribution, backend service correlations) to provide operators with a unified view of test coverage, performance, and system health.
openbank-admin-ui/src/app/api/test-intelligence · high confidence
Introduce Verification of Payee (VoP) service
The new openbank-vop-service implements the Verification of Payee control (ADR-0171, IPR Art. 5c) to validate payee names against IBANs. It resolves account-holder names for domestic IBANs via the account-service and party-service, and returns NO\_DATA for external IBANs where no EPC VoP scheme link exists. The service enforces a fail-open behavior for lookups (proceeding with NO\_DATA rather than blocking payments) and a fail-closed behavior for rate limiting. It includes a name-matching policy that supports exact matches, close matches (handling typos, initials, and legal-form suffixes), and no-match outcomes, while ensuring that matched names are only disclosed in close-match scenarios to prevent name enumeration. Verification evidence, including hashed IBANs and names, is persisted for fraud claims, and comprehensive metrics are emitted for verification outcomes, latency, and rate-limit decisions.
openbank-vop-service · high confidence
Introduce case-coordinator-agent module with Temporal swarm workflow and security hardening
The new openbank-case-coordinator-agent module (v0.8.1) deploys a Temporal-based CaseWorkflow that enables an agent swarm to join, contribute, and converge on a single human-in-the-loop proposal. This release hardens security by authorizing the asserted agent identity against the authenticated caller, keying open-rate quotas on the caller rather than the claimed identity, and sanitizing log output to prevent injection. It also adds a case thread read API for inspecting case history and evidence, and aligns the Dockerfile with the deploy recipe to ensure the container image is built correctly.
openbank-case-coordinator-agent · high confidence
Introduce context-service for compliance investigations
The new openbank-context-service provides a dedicated capability for investigating AML cases, complaints, incidents, and authorization scopes. It exposes REST endpoints (e.g., /api/v1/context/aml-cases) and consumes Kafka events to build a bounded, audited evidence graph. Access is strictly controlled via a maker-checker assignment workflow and a Policy Decision Point, with all reads and disclosures recorded for audit. The service is containerized via a Quarkus-based Dockerfile, governed by a compliance data-domain policy, and includes e2e performance gates to ensure investigation queries remain within latency and throughput targets.
openbank-context-service · high confidence
Introduce customer graph and context investigation data models
The admin UI now includes new TypeScript modules to parse and manage structured data for customer relationships and incident/complaint investigations. This adds support for a 'customer graph' that aggregates live facts about accounts, cards, notifications, lending applications, AML cases, devices, and documents, alongside a 'context neighborhood' model for tracking nodes and edges in complaint and incident investigations. It also introduces parsing for incident impact projections and a dedicated service URL helper for the context service, enabling the UI to consume and validate these specific data structures from the backend.
openbank-admin-ui/src/lib/context · high confidence
Introduce dedicated run duration metrics for workflow oversight
Added WorkflowRunMetrics to provide precise per-run duration tracking for the oversight sweep, replacing the previous trace-based latency buckets that saturated at 5 seconds and could not distinguish between healthy and degraded run times. This new metric exposes count, sum, and max values to allow accurate calculation of mean run duration, alongside a companion budget gauge to define degradation thresholds, ensuring that performance issues lasting longer than 5 seconds are now observable and alertable.
openbank-libs-domain/src/main/kotlin/com/openbank/libs/observability · high confidence
Introduce document template management interface
Adds a new Document Templates page to the admin UI, enabling operators to create, edit, and manage document templates with features like syntax highlighting, dynamic live previews, and status management (Draft, Published, Retired). The implementation includes a layout wrapper and a comprehensive page component that handles template lifecycle actions, integrates with the document service via a universal proxy, and ensures accessibility and focus safety in dialogs.
openbank-admin-ui/src/app/document-templates · high confidence
Introduce gamification engine and in-app engagement surfaces
The engagement service now supports in-app campaign surfaces (banners, carousels, stories) and a gamification engine. Users can now earn rewards by completing challenges (e.g., completing a budgeting course) within the rewards hub, with points awarded via an idempotent ledger. The service also introduces a rewards hub membership toggle, allowing users to opt in or out of the gamification feature. Additionally, the service exposes a read API for a party's active adverse states (such as arrears or fraud holds) to support targeted exclusions, and enforces stricter consent and contact-gate policies for all marketing-related interactions.
openbank-engagement-service · high confidence
Introduce governance-auditor agent for post-merge PR compliance checks
The new governance-auditor service (v0.6.2) implements ADR-0164 by running a Temporal workflow that audits merged pull requests against governance rules. It collects PR metadata via a read-only GitHub adapter, detects violations (such as missing threat models for money-path services, insufficient approvals, or unverified GPG signatures), and uses an LLM gateway to diagnose findings. While the LLM diagnosis is wired, the proposal creation path is currently stubbed to refuse and return null, ensuring no fabricated proposal URLs are returned to users.
openbank-governance-auditor · high confidence
Introduce openbank-incentive-service for governed promo-code offers and reservations
The openbank-incentive-service is a new Quarkus-based component (port 8156) that manages the lifecycle of incentive offers and promo-code reservations. It exposes an operator API for creating, submitting, and publishing offers with configurable stacking policies, and a customer-edge boundary API for reserving, committing, and releasing attributed promo-code reservations. The service persists data in a new PostgreSQL database (openbank\_incentive) via Flyway migrations and publishes governed lifecycle events to Kafka through an outbox pattern with resilient dispatch.
openbank-incentive-service · high confidence
Introduce referral service with qualification logic and outbox-based event publishing
The openbank-referral-service is introduced to manage the referral lifecycle, including program creation, invite issuance, and reward tracking. It implements ADR-0310 qualification logic that evaluates invites against account-opened facts at either event time or attribution time, ensuring idempotent reward assignment per referee per program. The service persists qualification events and rewards transactionally to a PostgreSQL outbox, which is then asynchronously dispatched to Kafka topics (Qualified, RewardRequested, RewardOutcome) via a resilient dispatcher with circuit breaking and retry policies. It also exposes metrics for outbox backlog and dead-letter counts, and provides a view for referrers to see their own invites and associated rewards.
openbank-referral-service · high confidence
Introduce segments catalogue with governed audience lifecycle and approval
The admin UI now includes a new Segments page that displays a code-defined catalogue of audiences (such as 'Active customers') with their current state (Draft, Pending Approval, Approved). Marketers can view audience details and request on-demand reach previews, which evaluate the audience against the data layer. The page also implements a governed lifecycle workflow, allowing authorized users to submit segments for approval and approve them, with a single-flight mechanism to prevent duplicate mutations during state transitions. The layout reuses the standard OperatorLayout component.
openbank-admin-ui/src/app/segments · high confidence
Introduce shared UI primitive layer and unified status vocabulary
The admin-ui now provides a centralized set of accessible UI primitives (Drawer, EmptyState, LoadMoreControl, LoadingState, PageHeader, StatCard, StatusBadge, and Tabs) and a single semantic status vocabulary. This replaces the previous pattern where individual pages hand-rolled their own tables, headings, and status colours, ensuring consistent styling, proper accessibility (focus management, ARIA roles), and a unified approach to displaying operational statuses across the interface.
openbank-admin-ui/src/components/ui · high confidence
Introduce standalone WeasyPrint PDF rendering sidecar
Adds a new, lightweight HTTP sidecar service (\openbank-document-renderer\) that converts HTML to PDF using WeasyPrint, serving as the default renderer for the platform's document templates. The service exposes a \POST /render\ endpoint (port 8200) and implements strict SSRF/LFI mitigations by restricting URL fetching to inline \data:\ URIs only, rejecting external network or file access. It is containerized with a multi-stage Dockerfile, hash-pinned dependencies, and a 10 MiB request body limit to ensure security and minimal resource usage.
openbank-document-renderer · high confidence
Introduce the open-bank risk-engine service
The open-bank risk-engine service is now available, providing a read-only balance-sheet snapshot capability that pulls the trial balance and sub-ledger data from the ledger service and the loan book from the lending service. It exposes use cases for computing Liquidity (LCR/NSFR), Interest Rate Risk in the Banking Book (IRRBB), Pillar 1 credit-risk capital, and ČNB minimum reserve requirements, all derived on request from tied-out snapshots and versioned curve sets.
openbank-risk-engine · high confidence
Introduce three-month FX trend visualization
The admin UI now includes a new FxTrendChart component that displays a three-month historical trend for currency pairs. Users can select a base currency from a dropdown to view a line chart showing the rate movement over the last three calendar months, along with key metrics such as start, latest, minimum, and maximum rates. The chart indicates the percentage change with directional icons and colors, and provides explanatory notes in both Czech and English to help users interpret the indicative CNB mid-rate data.
openbank-admin-ui/src/components/fx · high confidence
Introduces domain ports for LLM observability, safety, and reasoning
This change adds a set of pure-domain interfaces in the \openbank-libs-domain\ LLM package to standardize how the fleet interacts with LLM infrastructure and reports metrics. It introduces \LlmGatewayPort\ as the single egress choke point for chat calls, \ContentSafetyPort\ and \ContentSafetyMetricsPort\ to model-based safety guardrails (like Llama Guard) and their Prometheus reporting, \LlmCallMetricsPort\ for unified spend and reliability tracking, \EmbeddingPort\ for vector search, \TraceIdProvider\ to link gateway traces to service spans, and \ReasoningGraph\ to manage agent reasoning loops. These ports replace ad-hoc implementations, ensuring consistent observability, safety verdicts, and traceability across all LLM-consuming services.
openbank-libs-domain/src/main/kotlin/com/openbank/libs/llm · high confidence
Introducing the Testing Assurance Board
The System Tests page now features a new Assurance Board that consolidates test evidence into four navigable layers: CI evidence, Testcontainers runtime, Sandbox synthetics, and Client & RUM. This replaces the previous service-by-service test results table with a high-level view of deterministic gates, actual topology, scheduled falsification, and production signals, allowing operators to quickly assess assurance gaps across the system.
openbank-admin-ui/src/app/system/tests · high confidence
KYB service introduces business onboarding with registry verification and multi-signer agreements
The openbank-kyb-service (port 8157) is now available to handle legal-entity onboarding. It verifies companies against public registers (including a new UK Companies House adapter) and allows a human operator to confirm representation rules when the register text is ambiguous. The service supports a multi-signer workflow where the initiator and cosigners must sign a business agreement via the document-service's SCA ceremony before the entity party is activated.
openbank-kyb-service · high confidence
KYC page overhaul: unified layout, pagination, and evidence validation
The KYC section now uses the shared OperatorLayout shell instead of a custom sidebar/header, and the main page supports paginated case lists with a PartySearch component for filtering by specific parties. Data loading is now abort-safe to prevent overlapping requests, and incoming KYC data is validated against published contracts (parseKycCaseEvidence/parseKycCasePageEvidence) to ensure correct rendering of status and pagination metadata.
openbank-admin-ui/src/app/kyc · high confidence
KYC party lookup and agent identity resolution
The admin UI now includes a PartyLookup component that allows users to search for KYC customers by name, company, or UUID, with clear error messaging for service unavailability or failures. Additionally, a new API route at /api/governance/agent-identities exposes the agent registry from agents.yaml, enabling the UI to attribute proposals to specific charters and handle cases where the identity source is unavailable.
openbank-admin-ui/src/app/api/governance, openbank-admin-ui/src/components/kyc · high confidence
KYC service adds case expiration, PEP screening, adverse-media readiness, and orphaned-party detection
The KYC service now enforces a 30-day expiration for abandoned OPEN cases so parties can be re-KYC'd, and introduces a first-increment PEP screening check against the sanctions service's PEP\_GLOBAL list (routing outages to manual review rather than failing closed). It also exposes a four-valued adverse-media screening outcome—currently reporting SOURCE\_NOT\_CONFIGURED to make the lack of coverage observable—and adds an orphaned-party detector that reconciles the party register against KYC cases to surface parties with no case.
openbank-kyc-service · high confidence
Kill-switch status endpoint added to admin UI API
A new API route at /api/iaops/kill-switch has been introduced to expose the current state of the case-coordinator kill-switch. This endpoint authenticates the request and proxies the status from the case-coordinator service, returning whether the kill-switch is active and which scopes are currently restricted. It handles scenarios where the service is not deployed, unreachable, or returns an error, ensuring the admin UI can reliably display the kill-switch status.
openbank-admin-ui/src/app/api/iaops/kill-switch · high confidence
Ledger-service introduces accounting-day lifecycle, statutory period freeze, and booked-change replay capabilities
The ledger-service now owns the accounting-day lifecycle (OPEN → CUTOFF → TIED\_OUT → LOCKED) and enforces day-granular posting locks to prevent backdated entries from invalidating tie-outs. It also implements statutory period close (DRAFT → FROZEN) with hash-anchored, immutable trial-balance evidence and period-granular posting locks. Additionally, it provides an operator replay endpoint to re-emit historical AccountBookedChanged events for downstream projection catch-up without mutating ledger state.
openbank-ledger-service · high confidence
Lending service introduces credit-risk insights, compliance-pack governance, and loan termination workflows
The openbank-lending-service now exposes a read-only credit-risk insight interface that surfaces engine-evaluated applications, book-wide outcome summaries, and IFRS 9 provisioning views for the console. It adds a four-eyes activation workflow for jurisdictional compliance packs, ensuring that pack proposals are content-addressed, idempotent, and approved by a different principal before being compiled into the active registry. The service also implements a full termination and early-exit lifecycle, allowing settlement quotes, statutory withdrawals, delinquency/default marking, forbearance assessments, and bank-initiated termination with maker-checker segregation. Additionally, it wires a deterministic starter credit policy (eligibility, affordability, and pricing bands) and durable origination timers via Temporal, while fixing borrower disbursement crediting and ensuring audit attribution uses the correct source service.
openbank-lending-service · high confidence
Lípa loyalty console API endpoints for catalogues and party ledgers
New API routes have been added to the admin UI to support the Lípa loyalty console. The \/api/loyalty\ endpoint retrieves the global loyalty catalogue (benefits, earn sources, and provisioning details) from the loyalty service, while \/api/loyalty/party/\[partyId\]\ fetches the specific ledger and balance for a given party. Both endpoints enforce the \loyalty:view\ permission and are designed to provide transparent, symmetric data to operators, clearly distinguishing between service availability states (ok, not deployed, unreachable, unauthorized) to prevent misinterpretation of service health.
openbank-admin-ui/src/app/api/loyalty · high confidence
Modernized login page with brand storytelling and accessibility improvements
The login interface has been completely redesigned to feature a split-screen layout with a branded 'story' section showcasing OpenBank Explorer imagery and operational benefits, alongside a streamlined sign-in panel. This update introduces multi-language support (English and Czech) via a context-based copy system, enhances accessibility with skip-navigation links and reduced-motion preferences, and improves security signaling through a 'zero-trust' trust note and secure badge. The underlying license has also been updated from MPL-2.0 to Apache-2.0.
openbank-admin-ui/src/app/auth/login · high confidence
New API endpoint for retrieving DORA ICT incident data
A new backend-for-frontend (BFF) route has been added at /api/security/incidents to expose the durable DORA ICT incident register. This endpoint authenticates users, fetches paginated incident data from the security-scanner-service, and returns the verified list to the admin UI, enabling users to view and triage DORA-compliant security incidents directly within the application.
openbank-admin-ui/src/app/api/security/incidents · high confidence
New API endpoint to duplicate campaigns into reusable drafts
A new API route at \/api/campaigns/\[id\]/duplicate\ has been added, allowing users to create a new, maker-owned draft copy of an existing campaign. This dedicated endpoint proxies the request to the backend campaign service, ensuring that the duplication process is isolated from standard lifecycle actions and does not share state transitions or error semantics with the source campaign.
openbank-admin-ui/src/app/api/campaigns/\[id\]/duplicate · high confidence
New API endpoints for campaign cadences and triggers
Added new API routes in the admin UI to fetch the reviewed cadence catalogue and trigger definitions from the campaign service. These endpoints proxy requests to the backend, ensuring that the UI always uses the upstream contract for available events and scheduling options rather than relying on locally duplicated or hardcoded lists.
openbank-admin-ui/src/app/api/campaigns/cadences, openbank-admin-ui/src/app/api/campaigns/triggers · high confidence
New API endpoints for security KPIs and Prometheus metrics
The admin UI now exposes two new API routes under /api/security/kpis. The /metrics endpoint serves security KPIs (such as network policy coverage, dependency freshness, and credential status) in Prometheus text exposition format, enabling integration with Prometheus alerting and Grafana dashboards. The parent /api/security/kpis endpoint serves the raw CI-generated security KPI snapshot as JSON, providing a read-only view of the weekly security posture data baked into the image.
openbank-admin-ui/src/app/api/security/kpis · high confidence
New API endpoints for settlement status and operator approval decisions
The admin UI now exposes two new API routes to support settlement operations. The \/api/settlements/\[id\]\ endpoint allows clients to query the current status of a specific settlement by forwarding the request to the upstream settlement service. Additionally, the \/api/settlements/approvals/\[id\]\ endpoint enables operators to review and submit decisions (approve or reject) for settlement-related actions, handling both retrieval of the current decision state and submission of new decisions via PATCH requests.
openbank-admin-ui/src/app/api/settlements · high confidence
New API routes for audience management and actions
Added new Next.js API routes to handle audience operations within the admin UI. The \/api/audiences\ route now supports listing existing audiences and creating new ones by forwarding requests to the campaign service. Additionally, a new dynamic route at \/api/audiences/\[name\]/\[version\]/\[action\]\ enables specific actions—preview, submit, and approve—on audience segments, including detailed state handling for preview responses and error mapping for authentication or service availability issues.
openbank-admin-ui/src/app/api/audiences · high confidence
New API routes for case list and thread history
Added two new Next.js API routes in the admin UI to proxy requests to the case-coordinator-agent: a list endpoint that retrieves cases with status filtering and pagination, and a detail endpoint that fetches the full case thread history. Both routes enforce authentication via bearer tokens, handle service availability states (not deployed, unreachable, or empty), and return structured JSON responses to support the new swarm case list and thread view components.
openbank-admin-ui/src/app/api/iaops/cases · high confidence
New CI gate health status endpoint
A new API route at /api/devops/gate-health has been added to the admin UI, allowing users to view the current state of the CI gate estate. This endpoint reads a build-time snapshot file (gate-health.json) generated by the CI pipeline, exposing details such as gate modes, flakiness, and budget adherence without requiring live access to the GitHub API or holding any tokens at runtime.
openbank-admin-ui/src/app/api/devops/gate-health · high confidence
New Card Capabilities Matrix page in Admin UI
A new page at /cards/capabilities has been added to the Admin UI, displaying a matrix of card capabilities. This server-side page fetches the capability registry baked into the build and renders it via the CardCapabilityMatrix client component, ensuring bilingual support through the useLanguage hook while adhering to Content Security Policy requirements for nonce injection.
openbank-admin-ui/src/app/cards/capabilities · high confidence
New Card Disputes and Network Tokens management pages
The admin UI now includes dedicated pages for managing card-related lifecycle events. The Card Disputes page allows operators to view network-held dispute cases, displaying both bank and scheme statuses alongside response deadlines. The Network Tokens page enables management of token states (active, suspended, deleted) for specific cards, explicitly indicating whether the data comes from the live network or a local mirror to prevent stale-state errors. Both pages require a specific card ID to load data and enforce idempotency keys for state-changing actions.
openbank-admin-ui/src/app/cards/disputes, openbank-admin-ui/src/app/cards/tokens · high confidence
New Credit Risk & Decisioning Console for Risk Analysts
A new read-only console page has been added at /lending/risk, providing risk analysts with a comprehensive view of engine decisions, policy configurations, and portfolio health. The page displays decision outcomes (approve, refer, decline) with reason codes and rule hits, allows filtering by jurisdiction, and visualizes affordability thresholds, IFRS 9 stage mixes, and vintage performance. It also exposes policy tables and ECL coverage metrics, ensuring all data sources and limitations (such as DB-aggregated vs. loaded counts) are clearly labeled for auditability.
openbank-admin-ui/src/app/lending/risk · high confidence
New Customer 360 API endpoint for party-specific analytics
Added a new Next.js API route at \/api/customer-360/\[partyId\]\ that retrieves a consolidated view of a customer's activity by querying the \openbank\_analytics.silver\_party\_events\ ClickHouse view. The endpoint enforces \compliance:view\ permissions, validates the \partyId\ as a UUID to prevent injection, and returns structured data including domain summaries, associated account IDs, and consent details. It is designed to degrade gracefully by returning \available: false\ if the data source is unreachable, ensuring the UI displays a calm 'DataUnavailable' state rather than a raw error.
openbank-admin-ui/src/app/api/customer-360/\[partyId\] · high confidence
New Customer 360 Graph API endpoint
Added a new API route at \/api/customer-360/\[partyId\]/graph\ that aggregates customer data from multiple backend services (accounts, cards, notifications, lending, AML, devices, and documents) into a single response. The endpoint enforces a \compliance:view\ role, validates the party ID format, applies specific fetch timeouts and result limits per data source, and returns both the parsed data and metadata indicating which sources were unavailable or truncated.
openbank-admin-ui/src/app/api/customer-360/\[partyId\]/graph · high confidence
New Customer 360 party panels and name-based search
The party view now includes several new read-only panels that display live, authoritative data from backend services rather than the analytics silver layer: an Adverse State panel showing marketing exclusions (fraud hold, arrears, etc.) from engagement-service; a Customer Context Graph visualizing relationships across domains (accounts, cards, consents, etc.) with live filtering and flow animation; a Customer Portfolio panel summarizing accounts, loan applications, and AML cases; a Devices panel listing registered mobile devices and their last active times from notification-service; a Documents panel showing customer documents with download links from document-service; and a Lípa panel displaying the customer's loyalty balance and earnings from loyalty-service. Additionally, a shared PartySearch component allows operators to find customers by human-readable name (or paste a UUID) instead of requiring a party UUID, resolving the name to an ID via party-service before navigating to the relevant page.
openbank-admin-ui/src/components/party · high confidence
New DevOps Insights API endpoint for monitoring findings
A new API route at /api/devops/insights has been added to the admin UI, acting as a backend-for-frontend proxy to the devops-agent service. This endpoint retrieves active DevOps findings—including CI pipeline health, DORA metric regressions, runner capacity, deploy health, SSDLC hygiene, and incident recurrence—and returns them to the client. The implementation enforces authentication, applies a 10-second timeout to prevent hanging requests, and sanitizes any proposed remediation URLs to ensure they point to trusted repositories, while gracefully handling service unavailability by returning an empty list.
openbank-admin-ui/src/app/api/devops/insights · high confidence
New DevOps UI components for CI gate health and remediation review
The DevOps section now includes a Quality Gate Health Panel that displays a build-time snapshot of the CI quality-gate estate (including enforcement status, flakiness, and shard run times) fetched from /api/devops/gate-health, and a Remediation Review Dialog that requires explicit human confirmation before approving or rejecting automated remediation findings, replacing the previous single-click decision flow.
openbank-admin-ui/src/components/devops · high confidence
New EntityChip component for standardized entity navigation
A new EntityChip component has been added to the admin UI to replace bare UUIDs with clickable, icon-labeled chips for parties and accounts. This component resolves human-readable labels (legal names or account numbers) from the backend services, handles permission-based visibility (hiding links if the user lacks view rights), and provides a consistent, non-blocking navigation experience across entity details.
openbank-admin-ui/src/components/entities · high confidence
New FX trend calculation and visualization logic
Added a new module (\trend.ts\) that implements the logic for displaying a three-calendar-month FX rate trend. This includes normalizing raw CNB history data (deduplicating by date, handling inverted pairs, and calculating mid-rates), computing trend direction and summary statistics (min, max, change percent), and providing helpers to position chart points on a real-time axis for accurate visual representation.
openbank-admin-ui/src/lib/fx · high confidence
New GDPR-compliant privacy notice page for OpenBank Admin
A new privacy notice page has been added to the OpenBank Admin UI, accessible before sign-in, to clearly explain how operator data is handled. The page details the data journey (identity via Keycloak, session management via NextAuth, and audit trails), identifies the data controller, and outlines retention policies, user rights, and contact information for privacy and security inquiries. It supports English and Czech, includes accessibility features like skip links, and links to the standard security.txt file.
openbank-admin-ui/src/app/privacy · high confidence
New GitOps drift scanner API and license update
The admin UI now exposes a new API endpoint at /api/sbom/drift to display GitOps synchronization status for money-path services, reading from a daily snapshot and returning a 503 status if the scan has not yet run. Additionally, the license for the affected UI files has been updated from MPL-2.0 to Apache-2.0.
openbank-admin-ui/src/app/api/sbom · high confidence
New ICT incident register page for DORA compliance
A new Incidents page has been added to the OpenBank admin UI to display the ICT incident register, supporting DORA regulatory evidence requirements. The page provides a dashboard with summary statistics for total, active, high-severity (P1/P2), and unreported incidents, alongside a searchable and filterable table of incident details including severity, status, detection time, and regulatory reporting status. It includes localized timestamps, role-based access control via AuthGuard, and robust error handling for scenarios such as unauthorized access, missing deployment, or data validation failures.
openbank-admin-ui/src/app/security/incidents · high confidence
New Infrastructure Topology page for visualizing platform architecture
A new Infrastructure Topology page has been added to the admin UI, providing a visual map of the platform's architectural components and their relationships. This page displays real-time live status for key services (such as ArgoCD, Karpenter, PostgreSQL, and Kafka) alongside a hand-authored, verifiable diagram of the platform's wiring—including deployment chains, data flows, and observability pipelines. It serves as a companion to the code-derived service map, offering operators a clear, static view of how infrastructure pieces like ArgoCD, CNPG, and Istio interconnect.
openbank-admin-ui/src/app/infrastructure/topology · high confidence
New Member-Get-Member (MGM) program catalogue page
A new page has been added to the Admin UI at the referrals section, allowing administrators to view a catalogue of published MGM programs. The page displays program details such as name, version, reward amount, qualification event, and validity window, while enforcing that only published versions are shown and that campaigns cannot override the program's reward. Access is restricted to users with the 'campaign:view' permission.
openbank-admin-ui/src/app/campaigns/referrals · high confidence
New OBO MCP relay endpoint for operator console access
A new API route at /api/agent/obo-mcp has been added to the admin UI, enabling the backend to act as a relay for MCP JSON-RPC requests on behalf of signed-in operators. This feature implements an On-Behalf-Of (OBO) flow where the server exchanges the operator's token for an audience-restricted token targeting the MCP service, ensuring the exchanged token never leaves the server side. The endpoint is disabled by default and requires the OBO\_MCP\_ENABLED environment variable to be set to true, along with specific realm permissions and MCP service resolver flags. It includes server-side caching of exchanged tokens keyed by the operator's subject token hash, session creation and binding with the MCP service, and a 10-second timeout for upstream requests.
openbank-admin-ui/src/app/api/agent/obo-mcp · high confidence
New SBOM endpoint and synthetic taint propagation for canary testing
The runtime library now exposes a new management endpoint at /q/openbank/sbom that serves the service's CycloneDX Software Bill of Materials (bom.json) baked into the image, allowing operators to verify the exact dependencies of the running container. Additionally, a new synthetic taint system (ADR-0252) has been implemented to support canary testing: the SyntheticTaintRequestFilter validates incoming taint headers against a configurable list of trusted principals, propagating the taint state via MDC and OpenTelemetry baggage to downstream services via the SyntheticTaintClientFilter. This ensures that synthetic traffic is correctly identified and excluded from regulatory aggregates, while the SyntheticTaintExternalBoundary annotation allows explicit marking of external edges where taint propagation should stop.
openbank-libs-runtime/src/main/kotlin/com/openbank/libs/web · high confidence
New SDD console for fleet-wide mandate monitoring
A new read-only SDD console page has been added to the admin UI, providing a fleet-wide view of direct debit mandates sorted by recency. The page displays key details such as creditor and debtor information, scheme type, status, and activity dates, and includes a status filter to narrow the view (including B2B pending confirmation states). Operators can manually refresh the data, and the interface is localized for Czech and English users.
openbank-admin-ui/src/app/sdd · high confidence
New SDLC overview page with interactive quality gates and stage details
The OpenBank admin UI now includes a dedicated SDLC page that visualizes the seven-stage development lifecycle (Intent through Operate) and explains the CI quality gates. Users can view detailed descriptions for each stage, see specific actions required by Developers, DevOps, and Business roles, and explore a catalog of governance gates (blocking, scoped, runtime) with their associated checks and failure modes. The page provides deep links to related documentation such as ADRs, Test Intelligence, security evidence, and system inventory, helping teams understand and navigate the enforced SDLC controls and policy goals.
openbank-admin-ui/src/app/devops/sdlc · high confidence
New Security Excellence Hub consolidates ecosystem-wide security view
A new Security Excellence page has been added to the admin UI, providing a single, consolidated dashboard that aggregates read-only signals from various security pillars (such as posture scans, ICT incidents, fraud, AML, and sanctions) into one score and radar overview. The page implements specific degradation logic (per ADR-0056) to explicitly mark unavailable or unauthorized domains rather than showing false zeros, and includes drill-through links to detailed pages for each pillar.
openbank-admin-ui/src/app/security/excellence · high confidence
New Test Intelligence Agent API endpoint for admin UI
A new API route at \/api/test-intelligence/agents\ has been added to the admin UI, enabling the frontend to fetch and process test intelligence data via an agent. This endpoint aggregates findings from the 'flaky-test-hunter' service and enriches them with governance snapshots, evidence states, and component history (such as flaky/failing test counts and infrastructure status) from a local test intelligence report. It implements strict input validation and sanitization—restricting evidence kinds/states to a closed vocabulary, bounding text lengths, and validating URLs—to ensure safe, deterministic data is passed to the agent without exposing raw, untrusted report data.
openbank-admin-ui/src/app/api/test-intelligence/agents · high confidence
New Test Intelligence and AI Agent panels in the admin UI
The admin UI now includes a Test Intelligence Flow component that visualizes the seven-stage quality architecture (from change to accountability) and displays live evidence health signals, alongside a Test Agent Panel that shows AI-generated findings, governance evidence, and allows authorized users to trigger analysis. A LazyTestAgentPanel wrapper defers loading the agent panel until it approaches the viewport to improve performance.
openbank-admin-ui/src/components/testing · high confidence
New Treasury Limit Utilisation view
A new read-only page in the Treasury section displays credit-limit utilisation per counterparty and currency, showing the limit amount, utilised principal, available headroom, utilisation percentage, breach status, and the count of active senior overrides. The data is fetched server-side to ensure it matches the exact rules enforced at booking, and users can refresh the view manually.
openbank-admin-ui/src/app/treasury/limits · high confidence
New agent diagnostics, swarm collaboration, and insights panels
The Agent Control Room now includes several new visualization components to help operators understand and manage AI agents. The Agent Diagnostics panel displays an agent's operational envelope (data access, tools, guardrails, compute, and cadence) with a visual scan animation. The Agent Mesh Explainer and Agent Mesh Map components illustrate how specialist agents collaborate in a governed 'swarm' to handle cases, emphasizing human oversight. The Agent Insights Panel surfaces AI findings below page metrics, allowing operators to review and approve or reject agent proposals. Additionally, the Agent Outcomes panel tracks acceptance rates and review latency, while the Agent Identity component provides human-readable personas for each agent.
openbank-admin-ui/src/components/agent · high confidence
New audience draft composer with governed rules
The admin UI now includes a dedicated page for creating audience drafts, allowing users to define selection rules based on customer status (Active, Pending KYC, Suspended) and an optional minimum relationship age. The interface enforces strict input validation (lowercase alphanumeric names, non-negative integers for tenure) and implements single-flight request handling to prevent duplicate submissions. It also provides clear feedback on session expiration, role-based access denials, and name conflicts, guiding users through a draft-approval workflow.
openbank-admin-ui/src/app/segments/new · high confidence
New balance sheet workbench entry point
The admin UI now includes a dedicated balance sheet section. Accessing the /balance-sheet route automatically redirects users to the snapshots list, and the layout wraps the content in the standard operator workbench styling.
openbank-admin-ui/src/app/balance-sheet · high confidence
New balance-sheet analysis components for risk officers
The balance-sheet area now includes a suite of new UI components that present regulatory and risk data in a structured, user-friendly way. CategoryTable displays aggregated regulatory figures by category with expandable detail rows, while InstrumentsPanel shows snapshot instruments with human-readable labels, obligor names (where permitted), and credit-risk metrics like RWA. CurveUploadForm provides a guided interface for uploading yield-curve sets with validation and preview. IrrbbSummaryPanel presents interest-rate risk (IRRBB) results including delta EVE/NII by scenario and outlier test status. Supporting components include RunContext for run metadata and curve-set selection, ProvenanceBadge to distinguish synthetic from production data, RequestedByBadge to show who initiated a snapshot, and chart components for maturity ladders and repricing gaps. All components use the BFF API and respect user permissions for sensitive data.
openbank-admin-ui/src/components/balance-sheet · high confidence
New balance-sheet snapshot management page
The admin UI now includes a dedicated page for managing balance-sheet snapshots, allowing users with the appropriate roles to request or replay snapshots for a specific as-of date. The interface displays a list of recent runs, showing their status (tied out or untied), position counts, mismatch counts, provenance, and the user who requested each snapshot. It also provides an overview of tied-out versus mismatched snapshots and links to the next step for configuring curve sets for interest-rate risk scenarios.
openbank-admin-ui/src/app/balance-sheet/snapshots · high confidence
New build-time scripts for derived admin UI data and synthetic browser testing
The admin UI now includes a suite of new build-time scripts in the \scripts/\ directory that replace hand-maintained data with derived, source-of-truth artifacts and add a new synthetic browser test. \generate-card-capabilities.mjs\ bakes the Card Center capability matrix from the governance YAML registry, \generate-events.mjs\ derives the Kafka topic table from the AsyncAPI document and service configs, \generate-origination-graph.mjs\ extracts the loan-origination state machine from Kotlin source, and \generate-product-catalog-v2-types.mjs\ generates TypeScript types from the OpenAPI spec. \governance-schema.mjs\ centralizes the governance YAML validation rules using Zod. Additionally, \admin-login-synthetic.mjs\ introduces a credential-free browser synthetic that verifies the public Admin UI's SSO boundary, measures Web Vitals (FCP, CLS), and asserts build attestation and auth-gate redirects. \collect-gate-health.mjs\ and \collect-test-intelligence.mjs\ are new collectors that derive CI gate health and test intelligence snapshots from GitHub Actions API and staged artifacts, respectively.
openbank-admin-ui/scripts · high confidence
New campaign detail console with journey visualization and experiment tracking
The campaign detail page has been replaced with a comprehensive console that displays campaign metadata, a visual journey canvas, and detailed engagement metrics. Users can now view campaign outcomes through a funnel visualization rather than raw tables, track conversion data and holdout experiment results, and see party names instead of UUIDs in enrollment lists. The interface includes a send log with filtering capabilities, decision path tracking, and explicit handling of delivery statuses and suppression reasons, providing a complete view of campaign performance and lifecycle state.
openbank-admin-ui/src/app/campaigns/\[id\] · high confidence
New campaign operator console with lifecycle board and analytics
The campaigns section now features a dedicated operator console that replaces the previous raw inventory table with a visual lifecycle board (Draft, Awaiting approval, Running, Paused, Closed) to help marketers quickly identify active, stuck, or unfinished campaigns. The landing page aggregates delivery health metrics (sent, suppressed, failed) and trusted engagement analytics (impressions, clicks, dismissals) from backend services, while also displaying planning radar data. The interface is designed as read-only for general operators to preserve the four-eyes approval gate, with specific RBAC guards and BFF routing configured to expose these new aggregate endpoints and action states.
openbank-admin-ui/src/app/campaigns · high confidence
New card detail page for admin operators
A new route at /cards/\[id\] provides a comprehensive, linkable view of a single card's status, lifecycle, and operational controls. The page displays masked card details (never full PANs for PCI compliance), account and party references, and sibling cards, while allowing operators with appropriate RBAC permissions to view limits, controls, and execute card transitions (such as blocking or replacing) via a confirmation dialog. It includes robust error handling for service outages and degraded states.
openbank-admin-ui/src/app/cards/\[id\] · high confidence
New card management components for the admin UI
Added a suite of React components to the admin UI's card management area, including a capability matrix view, lifecycle state diagram, and operator controls for spending limits and channel toggles. The update also introduces a guided card issuance dialog, lifecycle transition buttons, and confirmation dialogs for irreversible actions like blocking or cancelling cards, along with shared status chips and operation feedback banners.
openbank-admin-ui/src/components/cards · high confidence
New card-processing service introduces the card money path and network token/dispute lifecycles
The openbank-card-processing-service is introduced to implement the card money path (authorisation, hold, clearing, and ledger posting) and the network token and dispute-case lifecycles, fulfilling ADR-0283. This service acts as the caller for card-issuance's authorisation decisions—previously uncalled—ensuring spend is measured, held, and posted to the ledger. It also provides the implementation for network token provisioning/status changes and dispute case opening/evidence submission, wiring the Visa and Mastercard BIN adapters and ensuring idempotency and transactional outbox consistency for these critical financial operations.
openbank-card-processing-service · high confidence
New communication style approval queue page
A new page has been added to the admin UI at /approvals/communication to support the four-eyes approval workflow for communication styles. Users with the communication:style:decide permission can now view a queue of pending style version publish requests, see who created each draft, and approve or reject them. The page enforces segregation of duties by preventing self-approval and provides feedback on the outcome of each decision.
openbank-admin-ui/src/app/approvals/communication · high confidence
New compliance pack activation console
A new four-eyes activation console has been added to the admin UI for managing jurisdictional credit compliance packs. This page allows operators to view active packs and pending proposals, submit new pack configurations via JSON, and approve or reject proposals through a dedicated review dialog. The interface enforces maker-checker separation by relying on the backend service to reject attempts where a single principal tries to both propose and decide, ensuring that pack activation requires distinct principals for each step.
openbank-admin-ui/src/app/lending/compliance-packs · high confidence
New credit-risk decisioning console and policy evidence tables
The lending risk section now includes a dedicated console for reviewing credit-risk decisions and policy evidence. This adds a PolicyTables component that displays decision rules (exclusion, eligibility, affordability, pricing) with human-readable conditions and hit counts from loaded decisions, alongside a suite of charts (OutcomeTrend, ReasonPareto, AffordabilityScatter, StageMixPie, BucketBars) that visualize approval/refer/decline trends, top adverse-action reasons, DSTI/DTI affordability distributions with policy threshold lines, portfolio stage mix, and delinquency buckets. The feature is supported by new TypeScript models and Zod validation schemas for decisions, outcomes, portfolio, and policy data, plus a shared color palette for consistent chart theming.
openbank-admin-ui/src/components/lending/risk · high confidence
New delegation approval detail view with immutable evidence timeline
A new read-only detail page has been added for individual delegation lifecycle approvals (suspend, reinstate, revoke). It displays the immutable evidence trail—including who proposed the action, when it was proposed, who made the independent decision, and when it was executed—along with a clear status badge and a timeline view. This screen does not allow submitting decisions or changing the delegation; it serves purely as an audit record, with a note that delivery to product projections should be verified in the delegation audit timeline.
openbank-admin-ui/src/app/approvals/delegation · high confidence
New delegation detail page with audit timeline and status display
A new single-grant detail page has been added for the delegation console, allowing users to view granted rights, ceilings, and a status timeline. The page displays key grant metadata including status, grantor/grantee parties, resource type, capabilities, approval policy, transaction/daily/monthly caps, and validity dates, with timestamps localized to the user's language. It also includes a read-only audit timeline component and a coverage probe for resource access eligibility checks. Bank-side actions (suspend, reinstate, revoke) are explicitly marked as unavailable with an explanation that these operations are currently handled by the fraud pipeline rather than the operator console.
openbank-admin-ui/src/app/delegations/\[id\] · high confidence
New delegation management console with audit, education, and access verification
The delegations area now features a comprehensive read-only console for operators. It includes a DelegationAuditTimeline that displays an immutable, timestamped history of delegation lifecycle events (offered, activated, revoked, etc.) with source attribution and live-status comparison. A DelegationEducation component provides segment-specific guidance (sole trader, SME, corporate) explaining the delegation model and current capabilities. Operators can use the CoverageProbe to check if a grantee has effective access to a specific resource and capability, and the EffectiveAccess view aggregates a customer's owned and delegated resources with attention flags for expiring or uncapped grants. The GrantTable and GrantView present grants with clear role matching, capability labels, and conditions, while the RoleCatalog allows browsing and managing reusable role presets.
openbank-admin-ui/src/components/delegations · high confidence
New domain primitives and shared definitions for audit, approvals, and accounting
The openbank-libs-domain module now includes several new domain components: a TopicProducers table that maps Kafka topics to their producing services to ensure correct audit attribution; a four-eyes approval store interface with status tracking and request binding; an AuditChain system providing hash-linked audit envelopes for integrity verification; DecisionRecord types for automated decision classification; and an AccountingClock with DayCount conventions for precise interest accrual calculations. Additionally, a detekt-baseline.xml file was added to suppress known code quality warnings in the domain module.
openbank-libs-domain · high confidence
New entity resolution API endpoint for unified search
A new API route at /api/entities/resolve has been added to serve as a facade for entity resolution, enabling the command palette to deep-link directly to parties and accounts. This endpoint accepts a search query and fans out requests to the party service (for legal names) and the account service (for IBANs), merging the results into a unified list of typed entity references with associated navigation routes.
openbank-admin-ui/src/app/api/entities · high confidence
New governed reporting API endpoints for the admin UI
Added two new API routes under /api/reporting to expose a governed query registry and a warehouse data surface. The /api/reporting route returns public metadata (titles, descriptions, parameter schemas, and column definitions) for all available reports, allowing the UI to render a selector and parameter form without exposing SQL logic to the browser. The /api/reporting/\[queryId\] route executes validated, server-side SQL against the ClickHouse warehouse, enforcing specific permissions per report entry and returning typed results with a row cap (1,000 rows) and graceful degradation (available: false) if the data source is unreachable. This change introduces the backend interface for the reporting feature but does not include the frontend UI components.
openbank-admin-ui/src/app/api/reporting · high confidence
New lending compliance and origination state libraries
This change introduces the core lending library components into the \openbank-libs-lending\ module. It adds a strict, fail-closed compliance pack parser that validates jurisdiction-specific rules (such as mandatory steps, disclosures, and eligibility checks) against a closed schema, ensuring no origination occurs under unreadable or invalid rule sets. A runtime registry manages these compiled packs, enforcing four-eyes approval workflows and immutable version history to guarantee consistent compliance enforcement across service replicas. Additionally, it defines the canonical loan-origination state machine (from Draft to Disbursed/Terminal) and moves the existing Delinquency logic into this new module, standardizing the license to Apache 2.0.
openbank-libs-lending/src/main/kotlin/com/openbank/libs/lending · high confidence
New lending console visualizes loan application lifecycle and pipeline
The lending console has been replaced with a credit-desk view that displays the ADR-0211 origination lifecycle as a vertical audit trail (OriginationFlow) and aggregates applications by stage in a pipeline view (OriginationPipeline). Operators can now see exactly where each application is in the process, how long items have waited in each stage, and which stages are stuck, with age-based color coding and clear indicators for terminal states. The pipeline explicitly discloses server-side data caps to prevent misinterpretation of counts, and supports both Czech and English labels.
openbank-admin-ui/src/components/lending · high confidence
New lending domain library with credit policy, pricing, and compliance models
The openbank-libs-lending module now provides the core domain models and calculation engines for the lending product. This includes a deterministic credit policy evaluator that processes applications against versioned exclusion, eligibility, affordability, and pricing tables to produce auditable approve/refer/decline decisions. It introduces a centralized APRC solver for regulatory-compliant annual percentage rate calculations, a financial health view that assesses customer reserve, cashflow, obligations, and habits, and a credit quote calculator that generates indicative pricing. The library also defines binding settlement and early-repayment quote logic, a compiled compliance pack for jurisdiction-specific legal duties, and a unified credit journey projection that maps origination states to customer-facing steps for unsecured, secured, and revolving products.
openbank-libs-lending · high confidence
New lending utility modules for integrity, four-eyes, and currency handling
This change introduces three new TypeScript modules in the lending library to support specific UI requirements. The \evidenceIntegrity\ module parses backend attestation data to determine if an audit trail is tampered or truncated and maps hash statuses to visual badges (altered, unverifiable, or verified). The \fourEyes\ module implements logic to identify if the current user is the proposer of a loan application, which is necessary to enforce the four-eyes approval workflow. The \money\ module provides utilities to normalize currency codes from different payload shapes and format monetary amounts with the correct currency symbol and locale.
openbank-admin-ui/src/lib/lending · high confidence
New loan application lifecycle view with evidence integrity and localized values
A new page at \/lending/applications/\[id\]\ displays the specific path a loan application has taken through the ADR-0211 lifecycle, rather than just a static status. This view includes the ADR-0214 evidence trail for each step, showing an integrity verdict to ensure auditability, and handles permission errors (403) gracefully so that lack of access does not appear as missing history. The interface localizes all values and labels, renders currency codes correctly, and clarifies the refresh state. It explicitly avoids exposing credit decision or disbursement buttons, directing users to the approval inbox instead, and ensures that only on-book loans are counted as active.
openbank-admin-ui/src/app/lending/applications · high confidence
New merchant catalogue maintenance screen for operators
A new admin interface has been added to allow operators to maintain the merchant enrichment catalogue. This screen displays a paginated list of known merchants and prioritizes an 'unmatched worklist' at the top, ranked by transaction volume, so operators can quickly identify and add missing merchants. Operators can edit merchant details (name, category, location), upload or remove logos, and delete entries, with all changes persisted via the backend API.
openbank-admin-ui/src/app/merchants · high confidence
New observability metrics and resilience patterns for LLM calls, guardrails, and inter-service retries
This update introduces new observability and resilience capabilities in the \openbank-libs-runtime\ library. For LLM interactions, it adds \LlmCallMetrics\ to track call volume, token consumption (separating prompt and completion), and latency, alongside \ContentSafetyMetrics\ to monitor guardrail classification verdicts and availability states. For inter-service communication, it introduces ADR-0321 resilience profiles (\MoneySync\, \Read\, \ExternalScheme\, \Batch\) with standardized timeout, retry, and circuit-breaker configurations. It also adds keyed-only retry logic via \KeyedCall\ and \KeyedCallFilter\ to safely retry idempotent requests while aborting non-idempotent ones, and improves fault visibility by surfacing original transport failures before they are masked by circuit breakers. Additionally, a fleet-standard percentile helper (\Percentiles\) is provided to standardize metric histogram publishing.
openbank-libs-runtime/src/main/kotlin/com/openbank/libs/observability · high confidence
New onboarding analytics dashboard and secure document preview
The admin UI now includes a new OnboardingAnalyticsCharts component that visualizes funnel conversion, daily signature success rates, and KYC verification method distribution for operators. Additionally, a new sandboxedPreview utility in the documents library generates an HTML shell with strict Content Security Policy and sandboxed iframes to safely preview document content without exposing it as a top-level document.
openbank-admin-ui/src/components/onboarding, openbank-admin-ui/src/lib/documents · high confidence
New onboarding funnel analytics API endpoint
Added a new API route at /api/onboarding/funnel-analytics that aggregates onboarding funnel data from ClickHouse for the admin board. This endpoint exposes step-level metrics (viewed, completed, drop-off, median dwell time), final signature outcomes over time, top signature failure reasons, and KYC method splits, allowing the admin UI to display comprehensive onboarding analytics.
openbank-admin-ui/src/app/api/onboarding · high confidence
New operational evidence dashboard for reliability monitoring
The admin UI now includes a new 'Operational Evidence' component that provides a consolidated view of system reliability. It displays three key metrics: the lowest remaining error budget from Pyrra (SLOs), the status of Temporal workflows (failures/completions in the last hour), and the slowest trace duration from Tempo. Each metric is presented with a status indicator (Healthy, Watch, Action, or No signal) and links to the respective detailed tools, allowing operators to quickly assess customer journey reliability.
openbank-admin-ui/src/components/observability · high confidence
New operator approval review interface with identity verification
The admin UI now includes a dedicated workbench for reviewing SCA and settlement operator approvals, allowing authorized operators to approve or reject requests after verifying the maker, purpose, and target. A new AgentIdentityBadge component displays the charter-backed identity of the request proposer, distinguishing between verified, unresolved, and unverifiable states to ensure audit context is visible during review.
openbank-admin-ui/src/components/approvals · high confidence
New per-agent detail page with charter, diagnostics, and outcome metrics
A new dynamic route at /iaops/agents/\[agentId\] provides a dedicated detail view for individual IAOps agents. This page renders the agent's persona and role, displays their charter (including tools, data access, and case capabilities) via a custom narrative parser, and visualizes agent diagnostics such as mesh maps and body analysis. It also presents outcome metrics with their denominators and lists pending proposals, allowing users to drill down into specific agent configurations and health status.
openbank-admin-ui/src/app/iaops/agents · high confidence
New per-agent drill-down page with diagnostics and proposal history
The admin UI now includes a dedicated detail page for individual agents, accessible via the new \/iaops/agents/\[agentId\]\ API route. This page aggregates three data sources: the agent's enforced charter from \agents.yaml\, its narrative documentation, and its Human-in-the-Loop (HITL) proposal history fetched from the agent service. It also exposes agent-specific diagnostics and mesh information derived from the governance registry. The endpoint degrades gracefully if the agent service is unreachable, ensuring the charter and narrative still render, and returns a 404 only for unknown agent IDs.
openbank-admin-ui/src/app/api/iaops/agents · high confidence
New performance test plans for money-path reads, writes, and security abuse
The performance testing scope has expanded with three new k6 scenarios: a read-only baseline for the money-path services (ledger journals and transaction lists) to establish latency trends against advertised SLOs; a local-only write benchmark that exercises the full concurrent posting path (account creation, funding, and transfers) to measure throughput and contention behavior; and a security abuse lane that probes the rejection path for invalid tokens, NUL-byte injection, and enumeration sweeps to ensure security boundaries fail safely. These are governed by a new \perf/scenarios.yaml\ configuration that defines their execution modes, safety boundaries, and blockers, alongside a detailed report of the first write-benchmark run which uncovered several local infrastructure defects.
perf · high confidence
New read-only delegation console for viewing party grants and effective access
A new read-only interface has been added to the admin UI under the delegations section, allowing operators to search for parties and view their granted and received delegation details along with computed effective access. The page uses a shared entity-resolution API to find parties and displays results as entity chips that deep-link to the standard party pages. It fetches grant data and effective access information via dedicated backend endpoints, handling loading states, timeouts, and error conditions gracefully. The console is intentionally read-only, as mutations like suspend, reinstate, or revoke are not supported from this view. It also displays projection health status for consumers, providing visibility into the state of delegation-related data pipelines.
openbank-admin-ui/src/app/delegations · high confidence
New reporting and analytics page with governed query registry
The admin UI now includes a dedicated /reporting page that consolidates two read-paths into the ClickHouse warehouse: authoritative reports served through a governed query registry (validated parameters, per-entry permissions, no raw SQL from the browser) and exploratory analytics via an embedded Grafana business-warehouse dashboard in kiosk mode. The page fetches a report catalogue, allows operators to select a report and set period parameters, runs the query against /api/reporting/\[queryId\], and displays tabular results with optional trend charts. It also handles authorization failures, missing data, and invalid parameter ranges with clear feedback.
openbank-admin-ui/src/app/reporting · high confidence
New reporting components for trend analysis and warehouse dashboard
Added two new React components to the reporting section: ReportTrend, which visualizes daily additive counts (such as settled transactions, failures, and event volumes) as bar charts with period-aware aggregation, and WarehouseDashboard, which embeds a Grafana dashboard for data exploration. The dashboard component handles period-based filtering, theme synchronization, and dynamic height adjustment while maintaining security by keeping the iframe source on the authenticated internal tools ingress.
openbank-admin-ui/src/components/reporting · high confidence
New risk analysis pages for balance-sheet snapshots
The balance-sheet snapshot detail view now includes dedicated sub-pages for five key risk metrics: Capital (Pillar 1 credit risk), IRRBB (interest-rate risk in the banking book), Liquidity (LCR and NSFR), Minimum reserve requirements, and Liquidity survival horizon forecasts. Each page fetches and displays specific regulatory data from the risk engine, providing users with detailed breakdowns, parameter sets, and provenance for each calculation directly within the snapshot context.
openbank-admin-ui/src/app/balance-sheet/snapshots/\[id\] · high confidence
New runtime libraries for audit, authorization, contact policy, and LLM integration
The openbank-libs-runtime module now includes several new capabilities: an opt-in hash-linked outbox audit event publisher for tamper-evident audit trails, a four-eyes approval binding system that fingerprints request arguments to link approvals to specific actions, a contact policy gate enforcing send caps, quiet hours, and suppression lists, and LLM integration adapters for Llama Guard content safety and OpenAI-compatible embeddings. Additionally, a Redis-backed online feature store and canonical JSON serialization for Money/CurrencyCode are provided, alongside a detekt baseline for code quality suppression.
openbank-libs-runtime · high confidence
New screen feedback board for operator surfaces
The admin UI now includes a dedicated screen feedback page that aggregates qualitative signals from operator interfaces. This view displays a chart of the most problematic screens, a table of recent user reports (including comments and environment context), and a breakdown of error rates by platform, OS, theme, and locale to help distinguish rendering regressions from product issues. The interface is localized for Czech and English and includes a manual refresh action.
openbank-admin-ui/src/app/feedback · high confidence
New screen-feedback API endpoint for admin board
Added a new API route at /api/feedback/screen-feedback that powers the admin 'Zpětná vazba k obrazovkám' board. This endpoint queries ClickHouse gold marts to return screen-level bug/idea/confusing metrics, the 50 most recent feedback reports (including comments and screenshot keys), and rendering context (OS/theme/locale). It enforces admin/operator/compliance roles, handles ClickHouse unavailability gracefully by returning an empty payload, and adheres to privacy guidelines by excluding party IDs and only exposing screenshot keys rather than images.
openbank-admin-ui/src/app/api/feedback · high confidence
New security primitives: honeytoken detection, OpenBao Transit field protection, and egress allowlisting
This update introduces several new security capabilities in the runtime library. HoneytokenFilter detects and counts probes against configured non-existent paths, emitting metrics and logs. OpenBaoTransitFieldProtector enables field-level encryption and decryption via OpenBao Transit, including token caching and rewrap support. SafeHttpClient provides an egress-allowlisted HTTP client to prevent SSRF by validating DNS resolution and enforcing TLS policies. SecurityTelemetry centralizes authorization decision metrics and span attributes for observability. Additionally, BearerTokenClientHeadersFactory now validates and propagates correlation IDs using accepted inbound ID shapes.
openbank-libs-runtime/src/main/kotlin/com/openbank/libs/security · high confidence
New server-side API routes for campaign console data aggregation
The admin UI now includes new Next.js API routes (\route.ts\) under \openbank-admin-ui/src/app/api/campaigns/\ to serve campaign detail data from the backend. These routes aggregate campaign metadata, enrolments, send logs (with pagination), journey funnels, engagement metrics, incentives, and experiment states into a single response for the campaign detail view, while a separate route handles paginated send-log filtering. A third route exposes the reviewed cross-channel catalogue of templates. All routes enforce authentication, proxy requests to the \campaign-service\ via the BFF, and handle error states (unauthorized, not deployed, unreachable) gracefully to ensure the console degrades safely when services are unavailable.
openbank-admin-ui/src/app/api/campaigns/\[id\] · high confidence
New static analysis rules enforce contact policy wiring and gamification module boundaries
The \openbank-libs-detekt-rules\ library now includes two new structural checks to enforce architectural and compliance invariants. The \MarketingCallSiteWiringRule\ ensures that any function annotated with \@MarketingCallSite\ has a \ContactPolicyGate\ injected and actively calls its \check\ method, preventing marketing touchpoints from bypassing policy gates. The \GamificationModuleBoundaryRule\ prevents lending and credit-decisioning modules from importing gamification domain state, ensuring these sensitive areas remain structurally separate to avoid conduct risks. Both rules are registered via the standard \RuleSetProvider\ service loader mechanism.
openbank-libs-detekt-rules · high confidence
New swarm case detail page with thread, timeline, and topology views
A new page at /iaops/cases/\[caseId\] displays detailed information for a specific swarm case, including its status, class, disposition target, budget, and contested rate. The page provides three distinct views for the case history: a thread view showing individual events (such as contributions, proposals, and signals), a timeline view, and a topology view, allowing operators to inspect the case's runtime evidence and decision history.
openbank-admin-ui/src/app/iaops/cases/\[caseId\] · high confidence
New unified object storage library for document management
A new storage abstraction has been introduced to standardize how binary artifacts (documents, PDFs, evidence) are stored and retrieved across services. The \ObjectStorePort\ interface defines the contract, with two concrete implementations provided in the runtime library: \S3ObjectStore\ for production use (leveraging AWS S3 with AES-256 server-side encryption and pre-signed URL support) and \PostgresBlobStore\ for development and low-volume scenarios (storing data in a \BYTEA\ table). Services can select the backend via the \openbank.objectstore.backend\ configuration property, defaulting to Postgres if unset.
openbank-libs-domain/src/main/kotlin/com/openbank/libs/storage, openbank-libs-runtime/src/main/kotlin/com/openbank/libs/storage · high confidence
New §38d withholding tax filing service for statutory reporting
This change introduces the openbank-tax-reporting-service, a new component that owns the §38d withholding tax filing process (ADR-0180). The service consumes \interest.withholding.remitted.v1\ events via Kafka to aggregate monthly withholding totals, manages the filing lifecycle (Open, Assembled, Filed) with strict idempotency and four-eyes separation of duties, and exposes a REST API for operators to view filings, check overdue status, and record submission references. While the service is currently marked as NOT DEPLOYED and lacks the EPO XML renderer (throwing an exception if called), it provides the system of record for what was filed and allows operators to manually key totals into the EPO portal and record the reference.
openbank-tax-reporting-service · high confidence
Nostro reconciliation page with statement upload and break listing
The Nostro reconciliation page now allows users with the treasury:nostro:upload permission to upload correspondent camt.053 statements and view the reconciliation results against the ledger. The interface also displays open breaks for the account, including details such as side, booking date, amount, reference, first seen date, and age in business days, with alerts triggered based on configurable age and amount thresholds.
openbank-admin-ui/src/app/treasury/nostro · high confidence
OSS-Fuzz integration for domain parsers
Added infrastructure to continuously fuzz the \Pacs008Reader\ and \RodneCislo\ parsers via OSS-Fuzz (Jazzer). This includes build scripts, Docker configuration, and seed corpus files to detect issues like XXE, stack overflows, and OOM errors in inbound XML and identity parsing.
fuzz · high confidence
Observability dashboard adds Edge Error Rate and improves metric accuracy
The observability page now displays a new 'Edge Error Rate' tile showing the customer-facing nginx 5xx ratio over a 1-hour window, complementing the existing 'Service Error Rate' which also uses a 1-hour window to avoid noisy 5-minute spikes. All error-rate metrics now use a consistent 1-hour aggregation window for better stability. Unknown or null metric values are rendered neutrally (muted text) instead of potentially misleading colors. The layout has been unified to use the shared OperatorLayout, and refresh timestamps are now localized to the user's language setting.
openbank-admin-ui/src/app/observability · high confidence
Onboarding AML screening and reconciliation for business parties
The AML service now screens business parties (COMPANY, SOLE\_TRADER) during onboarding by opening an AML case when they are created, using the same idempotent code path as individual customers. To fix a defect where parties approved for KYC but created before this logic existed were stuck indefinitely, a new scheduled reconciler automatically opens the missing onboarding cases for these parties. The reconciler is disabled by default and must be explicitly enabled via configuration.
openbank-aml-service · high confidence
Operator card management: issue flow, lifecycle controls, and capability matrix
The admin UI now provides a full operator card management experience. A guided issue flow derives the product and currency from the selected party and account, enforcing entitlement rules (quota, network, product status) and spending-limit invariants before submission. Operators can manage card lifecycles (activate, suspend, resume, block, cancel) and edit per-card limits and channel controls (contactless, online, ATM, abroad), with the UI mirroring the service's state machine to prevent illegal transitions. A new capability matrix screen displays supported networks and features, loading a baked registry from a JSON file. Client-side validation and error classification ensure operators see clear, bilingual explanations for failures such as quota exhaustion or forbidden actions.
openbank-admin-ui/src/lib/cards · high confidence
Operator-initiated customer messaging and notification observability
Operators can now send targeted emails to customers via the \opsmessage.compose\ endpoint, using pre-approved templates (\GENERIC\_NOTICE\, \SUPPORT\_FOLLOWUP\) with mandatory four-eyes approval. To prevent data leakage, all user-supplied variables in notification bodies are now HTML-escaped, and sensitive templates (like OTP codes) are redacted in storage. Additionally, the service now exposes detailed metrics for both email and push channels, distinguishing between successful sends, mocked environments, and failures, while a nightly job automatically retires push device tokens that have been inactive for 90 days.
openbank-notification-service · high confidence
Parties list pagination and unified layout
The Parties page now uses server-side pagination with cursor-based navigation, replacing the previous flat list approach to handle large datasets more efficiently. The layout has been unified to use the shared OperatorLayout component, ensuring consistent navigation and header presentation across the admin interface. Additionally, the party creation workflow is now guarded by an authorization check, preventing unauthorized users from accessing the creation form.
openbank-admin-ui/src/app/parties · high confidence
Party detail page overhaul with messaging, KYC verification, and improved error handling
The party detail page has been significantly refactored to unify status presentation, clarify actions, and localize banking record dates. It now supports viewing a party's message history and composing/approving operator-initiated messages for users with the appropriate permissions. KYC evidence is verified across operator views to ensure data integrity, and the UI now distinguishes unavailable related accounts. The page also prevents overlapping refreshes and uses a unified header and tab structure for better navigation.
openbank-admin-ui/src/app/parties/\[id\] · high confidence
Party service introduces AML profile declaration, marketing consent projection, and GDPR export capabilities
The party service now supports personal AML profile declarations, allowing customers to declare tax residency, occupation, and PEP status to trigger enhanced due diligence routing. It also projects marketing consent from the consent-service, keeping the party's consent status in sync with revocations or expirations. Additionally, the service exposes GDPR Art. 15 (subject-access) and Art. 20 (data portability) export endpoints, aggregating party PII, KYC, and card data for data subjects.
openbank-party-service · high confidence
Payments page refactored with unified layout, pagination, and Verification of Payee integration
The Payments page now uses the shared OperatorLayout for consistent workspace styling and replaces the previous hardcoded layout. Payment lists are paginated (50 items per page) with proper offset handling and error states, replacing the previous flat fetch. The Verification of Payee (VoP) feature is now fully integrated, calling the real backend API instead of using mock data, and includes improved UI states and accessibility labels. The layout file was also updated to reflect the project's license change from MPL-2.0 to Apache-2.0.
openbank-admin-ui/src/app/payments · high confidence
Product Catalog now supports GraalVM native builds and is deployable via Helm
The product-catalog service now includes a dedicated Dockerfile.native for building a GraalVM native binary, enabling faster startup times (200-330ms) and a reduced memory footprint, alongside a new Helm chart for streamlined Kubernetes deployment. The chart manages the stateless catalog service, configuring it for OIDC authentication, PostgreSQL persistence, and optional industry packs (banking, insurance). Additionally, the service introduces a configuration-driven fee waiver rule engine that evaluates fee conditions against account contexts, and enforces durable, canonical UUIDs for product identity to ensure stable references across the platform.
openbank-product-catalog · high confidence
Product catalog UI modernized with unified layout, accessibility, and localization
The product catalog interface has been refactored to use a shared OperatorLayout, replacing the previous custom sidebar and header structure. The product detail view now uses a standardized accessible Drawer component instead of a fixed-position panel, and all user-facing text has been localized via the i18n system. API calls now route through the BFF proxy to handle scale-to-zero states gracefully, and the UI enforces role-based permissions for editing actions while improving accessibility with proper ARIA labels and keyboard-safe focus management.
openbank-admin-ui/src/app/product-catalog · high confidence
Read-only backoffice delegation console API endpoints
The admin UI now exposes a set of read-only backend-for-frontend (BFF) routes under /api/delegations to support a new backoffice delegation console. These endpoints allow operators to view delegation details, inspect immutable audit timelines and lifecycle approval evidence, check effective access for specific parties, and monitor Kafka consumer-group lag for delegation event projections. All routes enforce strict role-based access (delegations:view and audit:view), validate UUIDs, and proxy requests to the delegation-service, account-service, card-issuance-service, and Kafka UI without exposing raw upstream payloads or allowing mutations.
openbank-admin-ui/src/app/api/delegations · high confidence
Redesigned operator dashboard with unified layout and parallel health reads
The dashboard now uses a shared OperatorLayout shell instead of a custom inline layout, applying a consistent visual theme and navigation structure. The page itself has been restyled with a new CSS module, featuring a modernized header, workspace links, and health overview sections. Under the hood, governance and health data are fetched in parallel to improve load times, and the component now correctly handles localization for Czech/English timestamps and preserves evidence state during refreshes.
openbank-admin-ui/src/app/dashboard · high confidence
Regulatory reporting page now displays live data previews and template metadata
The regulatory reporting interface has been updated to fetch and display actual regulatory template data (FINREP and COREP) rather than showing static placeholder fields. Users can now see specific cell values, currency formatting, and balance verdicts directly in the preview, along with metadata indicating whether the data source is a frozen ledger or a live working preview. The layout has also been consolidated to use the shared OperatorLayout component, and the license header has been updated from MPL-2.0 to Apache-2.0.
openbank-admin-ui/src/app/regulatory · high confidence
Release Steward agent introduces automated release-invariant checks and LLM-driven diagnosis
The release-steward service now runs a scheduled workflow that proactively scans the monorepo for release and version-axis drifts, including manifest/config lockstep mismatches, admin-ui version sync issues, explicit application version overrides, and OpenAPI version collisions or regressions across open pull requests. Detected findings are diagnosed using an LLM gateway integrated via the prompt registry, and while the agent currently refuses to open GitHub proposals or tickets (returning null rather than fabricating URLs), it correctly tracks findings through a DIAGNOSED state until human triage or future wiring is added.
openbank-release-steward · high confidence
SBOM viewer adds GitOps drift detection and fixes localization
The SBOM viewer now fetches and displays a 'drift' status badge when a service's running container image does not match its GitOps declaration, helping users identify configuration mismatches. Additionally, the component's user-facing text is now properly localized via the language context, and the license header has been updated from MPL-2.0 to Apache-2.0.
openbank-admin-ui/src/components/sbom · high confidence
SCA service introduces dynamic linking for approvals, documents, and cards, plus idempotency and cleanup tooling
The SCA service now supports dynamic linking for three new challenge purposes: APPROVAL (binding a device signature to a specific approval request and payload hash), DOCUMENT\_SIGNING (binding to a document hash and ceremony), and CARD\_MANAGEMENT (binding to a specific card and action like LIMIT\_INCREASE). This is enabled by new database columns in sca\_challenges and sca\_outbox (including claimed\_at for atomic outbox claiming and synthetic taint tracking) and a new PartyRegisterClient to look up party types. To prevent replay attacks, initiating a challenge now checks for idempotency and mints a fresh one if the previous attempt was already consumed, expired, or decided. Additionally, a new Python script (purge\_entity\_bound\_devices.py) allows operators to inventory and purge legacy device credentials enrolled to non-natural persons, and a k6 read-baseline test ensures performance for device and challenge lookups.
openbank-sca-service · high confidence
SDD service books debtor debits and exposes backoffice mandate queue
The SDD service now books the debtor-side debit for an authorised SEPA Direct Debit collection by consuming the \sdd.collection.authorised.v1\ Kafka event and posting to the transaction-service's \POST /api/v1/transactions\ endpoint using a dedicated M2M identity. A new REST endpoint, \GET /api/v1/sdd/mandates/recent\, provides a backoffice queue of recent mandates. The outbox infrastructure is hardened with atomic row claiming (\FOR UPDATE SKIP LOCKED\), synthetic taint tracking, and a guard against epoch-stamped rows.
openbank-sdd-service · high confidence
SEPA payment confirmation download and four-eyes approval inbox
Customers can now download a rendered HTML payment confirmation for completed SEPA payments via a new synchronous endpoint that fetches the template from document-service and merges payment details (amount, IBANs, status) without persisting a document record. Additionally, a new approval inbox endpoint allows operators to view and decide on pending four-eyes approvals for SEPA payments, resolving the previous issue where such requests were invisible to the checker. The service also introduces metrics to distinguish between real and synthetic fraud scoring verdicts, improving observability when the fraud service is degraded.
openbank-sepa-payment · high confidence
Sanctions management UI adopts unified operator layout and adds approval workflows
The sanctions management interface now uses the shared OperatorLayout component instead of its own sidebar/header, ensuring a consistent look and feel across operator workspaces. The sanctions page has been significantly enhanced to support operator workflows, including the ability to review and approve sanctions hits via a new approval decision dialog and a pending-approvals queue. The UI also introduces single-flight mutation handling to prevent duplicate requests, improves accessibility with proper ARIA labels and IDs for list toggles and cron editors, and fixes language localization by correctly applying Czech/English strings based on the active locale. Additionally, the codebase license has been updated from MPL-2.0 to Apache-2.0.
openbank-admin-ui/src/app/sanctions · high confidence
Sanctions service introduces four-eyes approval queue and deferred list refresh
Operators now have a dedicated queue to view and decide on pending four-eyes approvals for sanctions actions (such as clearing a screening hit), ensuring that a second operator can review and authorize decisions that were previously paused. Additionally, the service now supports a v2 refresh-all endpoint that returns immediately with a 202 Accepted status, deferring the actual list imports to a background scheduler to avoid proxy timeouts during large feed updates.
openbank-sanctions-service · high confidence
Service documentation page gains filtering and search; business onboarding console added
The Services documentation overview page now supports filtering and searching for services by name, ID, or group, and displays a dynamically derived count of microservices in the fleet rather than a hardcoded number. A new Business Onboarding console has been added, allowing operators to review and confirm how a company is represented (including signature counts and roles) with conflict detection for register changes. The Services page layout has been unified with the OperatorLayout component.
openbank-admin-ui/src/app/services · high confidence
Settlement service gains observability, compensation, and authorization capabilities
The settlement service now emits domain metrics (origination, saga steps, terminal outcomes, cycle duration) and stranded-settlement gauges to detect stalled workflows, implements proper compensation logic to reverse debits/credits and detect ledger posting status, and enforces OPA-based authorization on its endpoints.
openbank-settlement-service · high confidence
Simulation harness gains DST invariant coverage for billing, interest, and statement-close money paths
The openbank-simulation module now exercises end-to-end money-path invariants for billing fees, interest accruals, and statement closes. New scenario classes (FeeBillingScenario, InterestAccrualScenario, StatementCloseScenario) drive the real domain models (AssessedFee, InterestAccrual, ReconciliationPolicy) and post real ledger journals, while new bookkeeping models (BillingFeeLedger, InterestAccrualBook, StatementCloseBook) record both the domain-computed and ledger-posted sides. This enables MoneyPathInvariants to assert conservation and integrity laws (e.g., assessed vs posted fees match, gross/net/tax splits balance, statement periods persist only on successful reconciliation) instead of holding vacuously. A calibration replay harness (LendingEclCalibrationScenario) also allows IFRS 9 parameter changes to be reviewed against their quantified ECL impact before shipping.
openbank-simulation · high confidence
Standing orders now execute on SEPA and internal rails
Standing orders that were previously stuck in an ACTIVE state now actually execute. The service now includes a daily scheduler that dispatches due orders via Kafka, and a consumer that routes them to the correct payment rail: SEPA credit transfers for external payees, and same-day internal transfers for own-account moves. This change also adds the necessary database columns to store debtor details required by the SEPA rail, and introduces robust outbox handling with atomic row claiming and liveness monitoring to ensure reliable delivery.
openbank-standing-order-service · high confidence
System Health page adds operational insights and fixes accessibility and license
The System Health page now includes an OperationalEvidence component and a ContextualInsights dashboard to display customer impact and payment journey availability. The page header was refactored to use a shared PageHeader component, and timestamp formatting was updated to respect the user's language locale (Czech or English). Accessibility was improved by adding ARIA labels and roles to the refresh button and icons. Additionally, the code license was updated from MPL-2.0 to Apache-2.0, and a bug in the ServiceCard was fixed to display the database name instead of the schema name, with a fallback for stateless services.
openbank-admin-ui/src/app/system/health · high confidence
Temporal-based payment orchestration and merchant enrichment capabilities
This release introduces a durable Temporal workflow for payment execution, replacing the legacy saga pattern to ensure reliable cover holds, ledger postings, and compensation. It also adds merchant enrichment features, including a catalogue for operator-managed merchant data, logo ingestion with SSRF protections, and descriptor normalization to resolve merchant identities and locations.
openbank-transaction-service · high confidence
Transactions page redesign with pagination, validation, and unified layout
The Transactions page now uses a unified operator layout shell instead of a custom sidebar/header structure. Search results are paginated (50 per page) with a lookahead request to accurately display navigation controls. Input validation prevents searches with invalid date or amount ranges, and the obsolete 'channel' filter has been removed. The UI now displays transaction types and statuses using localized labels and neutral styling, and includes contextual operational insights and empty states for better operator guidance.
openbank-admin-ui/src/app/transactions · high confidence
Treasury approval inbox and counterparty limits pages added
The admin UI now includes two new treasury pages: an approval inbox for users with the treasury:deal:approve permission, which displays pending deals and allows approving or rejecting them (with a mandatory reason for rejections and a four-eyes check that hides the approve button for self-submitted deals), and a counterparty limits page for users with the treasury:view permission, which shows credit limits, exposure, and headroom per counterparty and currency with a visual utilisation meter.
openbank-admin-ui/src/app/treasury/approvals, openbank-admin-ui/src/app/treasury/counterparties · high confidence
Treasury daily position view for placed, borrowed, and ČNB holdings
The admin UI now includes a Treasury daily position page that displays per-currency data on what the desk has placed with banks, borrowed from them, and holds at the ČNB deposit facility as of a chosen day, along with the net of the three. Users can select an 'as of' date (with quick shortcuts) to view either actual positions (settled deals only, outstanding that day) or projected positions (concluded deals based on contracted value and maturity dates). The view shows placed, borrowed, ČNB holdings, net position, and deal count per currency, with a status badge indicating whether the data is actual or projected.
openbank-admin-ui/src/app/treasury/positions · high confidence
Treasury deal management: new deal creation and detail view
The admin UI now includes pages for creating and viewing treasury deals. The new deal page allows dealers to create a draft for various products (including FX spot and ČNB lombard borrowings), with client-side validation and a mandatory two-person approval workflow before posting. The deal detail page displays full deal information, lifecycle status, and ledger journals, while enforcing role-based actions and four-eyes approval rules.
openbank-admin-ui/src/app/treasury/deals/\[id\] · high confidence
Treasury deals blotter page added
A new Treasury deals page has been added to the admin UI, providing a filterable blotter view of money-market and deposit facility deals. Users can view deal details including product, counterparty, currency, principal, rate, value/maturity dates, FX side, and lifecycle state. The page supports filtering by deal state, displays a count of deals in the current selection, and includes navigation tiles to the new deal creation form, the four-eyes approval inbox (for users with approval permissions), and limit utilisation. It enforces role-based access, requiring 'treasury:view' to access and 'treasury:deal:create' to see the new deal link.
openbank-admin-ui/src/app/treasury/deals · high confidence
Treasury section: deal booking, approval, and reconciliation UI
The treasury section of the admin UI is now available, providing a complete workflow for managing interbank and central bank operations. Users can book FX spot deals and ČNB lombard borrowings, with client-side validation for FX pairs and value dates. The interface enforces a four-eyes approval process, hiding the approve action from the deal's creator and requiring a separate approver. It also displays counterparty limit utilisation and allows senior approvers to override breached limits. Additionally, the UI supports nostro reconciliation by uploading CAMT.053 statements and viewing break reports, while clearly distinguishing simulated (synthetic) counterparties from real banks.
openbank-admin-ui/src/components/treasury · high confidence
Treasury service initial release with money-market, FX, and reconciliation capabilities
The treasury service is now available (v0.12.0), introducing core money-market deal management with four-eyes booking, daily interest accrual, and integration with the ČNB lombard facility. Users can now book and settle FX spot deals, view counterparty limit utilisation, and enforce product limits at both submission and approval stages. The service also provides nostro account reconciliation against camt.053 and MT940 statements, with automated break detection and alerting. Additionally, a simulated market feature allows counterparties to quote off the risk engine's curve set, and the admin UI has been updated to display treasury deal details in a dealer-friendly format.
openbank-treasury-service · high confidence
Unified approval inbox now aggregates pending decisions from multiple domains
The admin UI now provides a single, federated view for pending maker-checker approvals across previously siloed services. This new API route at \/approvals/pending\ consolidates pending items from lending, sanctions, transactions, domestic payments, clearing, FX, ledger, SWIFT, SEPA payments, SEPA instant, notifications, party, account, consent, balance, billing, and delegation services into one canonical list. Users can now discover and manage four-eyes approvals that were previously invisible or required out-of-band tracking, with the interface displaying the source domain, action type, and maker for each item.
openbank-admin-ui/src/app/api/approvals · high confidence
Unified approval inbox with domain triage and single-flight decision controls
The approvals page now consolidates agent proposals and federated domain maker-checker queues into a single view, allowing operators to filter, sort, and search by domain. Decision actions are protected by a single-flight mechanism to prevent duplicate mutations when approving or rejecting the same proposal. The interface also displays agent identity badges resolved from the governance registry and uses CSS variables for state colors to ensure proper contrast in dark mode.
openbank-admin-ui/src/app/approvals · high confidence
Unified approval inbox with domain-specific routing and operator approval support
The admin UI now features a unified approval inbox that aggregates items across multiple domains (such as lending, sanctions, SCA, and settlement) and provides triage capabilities including filtering, sorting, and search. The system distinguishes between general domain approvals and specific operator approvals for SCA and settlement workflows, enforcing maker-checker separation and preserving the actor kind (e.g., human vs. AI agent) for auditability. For supported domains, the inbox provides direct links to the relevant domain-specific workbenches (e.g., sanctions, notifications, delegation, SCA, settlement), while operator approvals for SCA and settlement are handled via dedicated upstream services with strict validation of approval targets and decision payloads.
openbank-admin-ui/src/lib/approvals · high confidence
Wealth service introduces declared off-platform holdings
The new openbank-wealth-service allows customers to declare and manage off-platform assets and liabilities (such as real estate, vehicles, or external securities) via a REST API at /api/v1/holdings. Users can declare a holding, update its valuation, view its history, and withdraw it from their portfolio. The service persists these records in PostgreSQL and publishes domain events (e.g., holding declared, revalued, withdrawn) to Kafka via an outbox pattern, ensuring that state changes and event emissions are committed atomically.
openbank-wealth-service · high confidence
Removals
Removal of attic directory and one-off migration scripts
The attic directory, which previously held placeholder service definitions and historical one-off JavaScript migration scripts (such as those for updating API documentation, service maps, and BPMN diagrams), has been removed. These scripts were ad-hoc tools used to patch static content in the admin UI and are no longer needed, cleaning up the repository structure.
attic · high confidence
Removal of generic Saga state machine library
The generic \SagaStateMachine\ class and its associated \SagaTransitionPolicy\ and \SagaTransitionResult\ types have been removed from the \openbank-libs\ domain package. This deletion eliminates the shared, parameterized state-machine implementation for sagas, indicating that saga transition logic is being inlined or handled differently within specific saga implementations rather than relying on this common library component.
openbank-libs/src/main/kotlin/com/openbank/libs/domain · high confidence
Removal of unused Temporal library components
The \openbank-libs/src/main/kotlin/com/openbank/libs/temporal\ module has been cleaned up by removing four dead code files: \DeterministicRandom.kt\ (a seeded random source for testing), \OpaActivityInterceptor.kt\ (an OPA-based activity gate), \OpenBankSaga.kt\ (a saga compensation container), and \TemporalWorkerConfig.kt\ (the CDI bean that bootstrapped the Temporal worker). These components are no longer part of the active codebase, reducing the library's footprint and removing unused configuration and runtime behavior.
openbank-libs/src/main/kotlin/com/openbank/libs/temporal · high confidence
Security
Admin UI authentication and role-based access control overhaul
The admin UI's authentication and authorization logic has been significantly updated to enforce stricter security and align with backend role definitions. The license has been changed from MPL-2.0 to Apache-2.0. A new \requireApiPermission\ function enforces BFF route-level permission checks, preventing unauthorized direct API access. The role matrix in \roles.ts\ has been expanded to include new roles (SUPERVISOR, KYC split roles, CATALOG scopes, COMMS\_EDITOR/APPROVER) and updated permissions for payments, lending, sanctions, and notifications, ensuring UI navigation matches backend RBAC capabilities. Token refresh logic in \authOptions.ts\ now handles single-use refresh tokens to prevent session stampedes and rotation loss. Security is enhanced with \requireSecurePublicUrl\ enforcing HTTPS in production and \sameOriginPath\ preventing open redirect vulnerabilities in post-authentication callbacks. New persona-based workspace links are derived from user roles to streamline navigation.
openbank-admin-ui/src/lib/auth · high confidence
Admin UI security hardening and license update
The admin UI middleware has been renamed to proxy.ts and refactored to replace hardcoded role-based route guards with a centralized permission projection, ensuring navigation, deep links, and initial responses remain consistent. Security posture is improved by tightening Content Security Policy directives (removing Google Fonts and unsafe-inline styles), closing a latent public-surface guard gap by using a shared predicate for public routes, and explicitly allowing Grafana OAuth frames. The middleware now excludes specific API paths for Prometheus metrics and nginx auth gates while gating all other routes. Additionally, the repository license has been updated from MPL-2.0 to Apache-2.0, and OpenTelemetry SDK preloading is added to ensure BFF traces are captured in the standalone build.
openbank-admin-ui/src · high confidence
Centralized secure XML parsing to prevent XXE attacks
A new \SecureXml\ utility has been introduced in the domain library to provide hardened, centralized XML parsing. This component configures all JAXP factories (DOM, SAX, StAX, Schema, and Transformer) to strictly disable DOCTYPE declarations, external entities, DTD loading, and XInclude, effectively mitigating XML External Entity (XXE) vulnerabilities. Users must now use this specific entry point for XML operations to ensure compliance with the security hardening policy.
openbank-libs-domain/src/main/kotlin/com/openbank/libs/xml · high confidence
Enhanced agent security and error handling
The admin UI now implements per-run PKI agent SVIDs (short-lived client certificates) minted from OpenBao to replace the forgeable X-Agent-Id header, ensuring cryptographic identity for agent calls. Additionally, a new failure classification system distinguishes between specific agent states such as unauthorized access, unreachable services, and deployment errors, providing clearer feedback when agent requests fail.
openbank-admin-ui/src/lib/agent · high confidence
Gradle wrapper distribution integrity verification enabled
The Gradle wrapper configuration for the openbank-account-service now includes a SHA-256 checksum for the Gradle distribution archive. This ensures that the downloaded Gradle binary is verified against the expected hash before execution, protecting against supply-chain tampering or corrupted downloads during builds.
openbank-account-service/gradle · high confidence
ISO 20022 library hardens XML parsing and adds interbank settlement date support
The ISO 20022 library in \openbank-libs-iso20022\ now uses the fleet-wide \SecureXml\ builder for all XML parsing, validation, and serialization, replacing local \DocumentBuilderFactory\ and \TransformerFactory\ configurations to consistently prevent XXE attacks. This change also introduces the \IntrBkSttlmDt\ (interbank settlement date) field to \pacs.008\ credit transfers and adds vendored XSD schemas for \camt.056\ (payment cancellation) and \pacs.002\ (payment status reports). Additionally, readers for \pacs.008\ and \pacs.004\ now wrap malformed input errors in typed exceptions to ensure clean error handling.
openbank-libs-iso20022, openbank-libs-iso20022/src/main/kotlin/com/openbank/libs/iso20022 · high confidence
Behavioural changes
1740 commits (31 fixes) modifying (repo-wide)
A change to existing behaviour in (repo-wide) — 1740 commits (31 fixs), 29 files.
(repo-wide) · low confidence · unverified
AML monitoring page adopts unified operator layout and service status handling
The AML monitoring interface now uses the shared OperatorLayout component instead of its own custom sidebar and header, ensuring visual consistency with other operator workspaces. The page also replaces the manual health-check logic with a standardized ServiceStatusBadge that accurately reflects scale-to-zero states (idle/waking) for the AML service, and updates the case data model to search by customer reference, party ID, and alert code while validating case evidence more strictly.
openbank-admin-ui/src/app/aml · high confidence
Account model expanded with delegation, savings goals, and GDPR compliance fields
The account domain model now supports granular delegated access and savings goals while ensuring GDPR compliance. Users can now set savings goals with a target amount and date, and view or rename their accounts with a custom nickname. The model introduces a propose-only withdrawal flow for delegates, requiring owner approval via Strong Customer Authentication (SCA) before funds are released. Additionally, the system now tracks the specific terms version and URL under which term deposits were opened for regulatory transparency, and properly nullifies the legal name and savings goal upon GDPR erasure requests.
openbank-account-service/src/main/kotlin/com/openbank/account/domain/model · high confidence
Account opening, authorization, and delegation persistence improvements
The account service now ensures atomic account opening by persisting the account, its primary currency pocket, and an idempotency key in a single transaction, preventing partial states and duplicate opens. Account updates now use version-guarded optimistic locking to detect and reject concurrent modifications. Account authorizations are persisted correctly using merge operations to support re-saving, and delegation mandates are enforced via lifecycle projections that reject stale updates. Additionally, the outbox dispatcher uses an atomic SQL claim with SKIP LOCKED to prevent row contention, and audit timestamps are consistently stamped from an injected Clock.
openbank-account-service/src/main/kotlin/com/openbank/account/infrastructure/persistence/repository · high confidence
Account persistence layer: new delegation, savings, and idempotency entities; GDPR, naming, and timestamp fixes
The account-service persistence layer now stores delegation grants (DelegationProjectionEntity), party mandates (PartyMandateProjectionEntity), and savings withdrawal proposals (WithdrawalProposalEntity) to support delegated access and propose-only withdrawal flows. AccountEntity gains fields for legal\_name (nulled on GDPR Art. 17 erasure), savings goal metadata (goal\_name, goal\_target\_minor\_units, goal\_target\_date), a customer-chosen nickname, and terms\_version/terms\_url/terms\_effective\_from to record the terms version and document snapshot at opening. Timestamps for created\_at and updated\_at now default to Instant.now() instead of Instant.EPOCH, and the @PreUpdate hook that forced EPOCH on updates is removed. A new AccountIdempotencyEntity ensures atomic, version-guarded account opening. The AccountOutboxEntity adds a claimed\_at column for atomic FOR UPDATE SKIP LOCKED outbox claims. License headers across these files are updated from MPL-2.0 to Apache-2.0.
openbank-account-service/src/main/kotlin/com/openbank/account/infrastructure/persistence/entity · high confidence
Account service REST layer: new delegation, approval, and savings features plus license and error-handling updates
This change introduces several new capabilities and fixes in the account service's REST layer. It adds endpoints for a four-eyes approval workflow (listing and deciding pending approvals), a propose-only savings-goal withdrawal flow (proposing, listing, deciding, and canceling withdrawals), and machine-readable delegation checks for both payments and savings goals. It also adds a fleet-wide endpoint to list active accounts for billing discovery, allows account owners to view effective access, enables renaming accounts, and records terms versions for term deposits. Additionally, it fixes several behavioral issues: required parameters now return 400 instead of 500, screening outcomes return 422/503 without leaking match details, unknown authorization revocations return 404, and concurrent modifications return 409. The license for these files is updated from MPL-2.0 to Apache-2.0, and role checks are updated to use ROLE\_API instead of ROLE\_SERVICE.
openbank-account-service/src/main/kotlin/com/openbank/account/infrastructure/rest · high confidence
Account service client infrastructure: authentication, resilience, and balance logic updates
This update refactors the account service's external client layer to improve security, reliability, and data accuracy. Several clients (Balance, Sanctions, Transaction) now register the SyntheticTaintClientFilter for better boundary enforcement, and the Transaction client switches to a dedicated M2M identity (openbank-account) instead of the shared openbank-services client. A new ProductCatalogAdapter implements a fail-open strategy for product lookups to prevent blocking account openings, while a new PartyDirectoryClient enables paginated retrieval of active parties. The BalanceServiceClient now correctly uses the effectiveAvailableAmount field to prevent spending credits before their value date. Additionally, the ScaChallengeClient gains resilience via circuit breaking and retry logic, and the TransactionServiceClient now supports optional source accounts for payments.
openbank-account-service/src/main/kotlin/com/openbank/account/infrastructure/client · high confidence
Accounts page layout and search behavior overhaul
The accounts page layout now delegates to the unified OperatorLayout component, replacing the previous custom sidebar and header structure. Search functionality has been significantly improved to prevent stale results by using abort controllers for cancellation, and the page now supports cursor-based pagination with a 'Load More' control to handle large result sets without overwhelming the DOM. The UI also integrates a PartySearch component for selecting parties and adds specific locale-aware number formatting for Czech language users.
openbank-admin-ui/src/app/accounts · high confidence
Add strict validation for ledger journal data
A new \ledgerJournalContract.ts\ module has been introduced to enforce strict validation of ledger journal data. This change adds runtime checks for journal entries and pages, ensuring that fields such as status, amounts, dates, and currency codes conform to expected formats and constraints before they are processed, thereby improving data integrity and error handling for ledger-related operations.
openbank-admin-ui/src/lib/ledger · high confidence
Admin UI API proxy: expanded service registry and enhanced audit/security headers
The admin UI's API proxy now supports a significantly expanded set of backend services, including lending, campaign, SDD, fraud, document, engagement, regulatory (finrep), VOP, communication, and KYB services, alongside a renamed security-scanner entry and a special routing rule for the product-catalog standalone sidecar. To support new console features and improve auditability, the proxy now forwards the 'x-approval-id' header for four-eyes approval workflows and derives the 'x-operator-id' header from the authenticated session rather than trusting client input, ensuring accurate audit trails for operator actions. Additionally, ETag headers are now preserved in responses to support caching semantics.
openbank-admin-ui/src/app/api/svc · high confidence
Admin UI API routes switch to shared upstream client and tighten error handling
The admin UI's API routes for the agent chat and product catalog now delegate HTTP calls to a shared \productCatalogUpstream\ helper (imported from \@/lib/productCatalog/upstream\), replacing the previous inline \fetch\ logic that relied on the \PRODUCT\_CATALOG\_URL\ environment variable and custom proxy functions. This centralization standardizes how requests to the product catalog are constructed and sent. Additionally, the agent chat route's error handling has been tightened: it now explicitly checks \res.ok\ before parsing JSON to return early on non-2xx responses, and both the chat and product catalog routes no longer expose raw exception messages to the client, instead returning a generic \agent\_unreachable\ error string in catch blocks.
openbank-admin-ui/src/app/api/agent/chat, openbank-admin-ui/src/app/api/product-catalog · high confidence
Admin UI API services relicense to Apache-2.0 and update SBOM sourcing
The API service routes in the admin UI have been relicensed from MPL-2.0 to Apache-2.0. Additionally, the SBOM endpoint now attempts to fetch live SBOM data from running services via the \/q/openbank/sbom\ endpoint, falling back to the previously baked-in bundle if the live source is unavailable. The governance service route has been updated to use \databaseName\ instead of \schemaName\ and now reports an \available\ status to indicate whether the governance data file is present.
openbank-admin-ui/src/app/api/services · high confidence
Admin UI now exposes AI review unavailability status
The admin UI's API agent for catalog reviews now explicitly handles and surfaces when the underlying AI model is unavailable. Instead of returning a generic upstream error, the route detects specific 503 responses from the agent service (indicating the model is offline or missing) and returns a clear 'model unavailable' error to the operator. This allows the UI to distinguish between a temporary infrastructure failure and an intentional state where the AI review capability is not ready, improving the operator's ability to understand why a review might not be generated.
openbank-admin-ui/src/app/api/agent/catalog-reviews · high confidence
Admin UI: self-hosted fonts, route-transition loading, and improved accessibility
The admin UI now uses a local system font stack instead of fetching fonts from Google Fonts, removing a build-time network dependency and improving reliability in restricted environments. Navigation between pages now displays a consistent skeleton loading state to prevent layout shifts during route transitions. Additionally, error screens and global error boundaries have been updated with proper ARIA roles and labels, and the color palette has been adjusted to ensure all text meets WCAG AA contrast requirements.
openbank-admin-ui/src/app · high confidence
Agent API route adds per-run PKI identity and simplifies error handling
The MCP agent API route now mints a per-run PKI agent SVID (Signed Verification Document) via the BFF to provide verifiable identity for agent calls, falling back to the existing X-Agent-Id header if the certificate service is unavailable. Additionally, the route's error handling has been simplified to return a generic 'agent\_unreachable' message instead of exposing specific exception details, and the response status code for unreachable agents is now explicitly set to 502.
openbank-admin-ui/src/app/api/agent/mcp · high confidence
Agent proposals now display human vs. bot indicators
The operator cockpit now distinguishes between human and automated proposals in the HITL approval queue. The admin UI's API route fetches the agent charter registry to classify authors: proposals from known agents are marked with a 'bot' icon, while others are marked as 'user'. This enrichment allows the UI to provide clearer provenance for pending actions, falling back to upstream data if the registry is unavailable.
openbank-admin-ui/src/app/api/agent/proposals · high confidence
Agent service adopts AGPL-3.0-only license
The openbank-agent-service is now licensed under the GNU Affero General Public License v3.0 only, replacing the previous MPL-2.0 license used by the rest of the platform. This change introduces a dual-licensing model where the service remains open-core under AGPL-3.0-only, with a commercial license available from the maintainers as an alternative.
openbank-agent-service · high confidence
Audit event logging now includes explicit timestamps
The audit event publisher has been updated to explicitly log the event's timestamp within the audit log line. Previously, the log entry relied on the system time at the moment of publishing, which could be inaccurate if the event was delayed or replayed through a durable publisher. By including the \event.timestamp\ in the log output, the system ensures that the recorded time reflects when the operation actually occurred, supporting accurate reconstruction of audit trails in compliance with DORA Article 17 requirements. Additionally, the license header for this file was updated from MPL-2.0 to Apache-2.0.
openbank-libs-runtime/src/main/kotlin/com/openbank/libs/audit · high confidence
Audit log page uses unified layout and clarifies evidence window limits
The Audit Log page now uses the shared OperatorLayout for consistent navigation and styling. The interface has been updated to clarify that the audit service returns a limited window of the most recent verifiable events (up to AUDIT\_EVIDENCE\_WINDOW), explicitly distinguishing between a full result set and a truncated one. Additionally, the page now includes a 'Source' column in the audit table and provides provenance details for the displayed snapshot.
openbank-admin-ui/src/app/audit · high confidence
Audit service introduces tamper-evident external anchors, session-log retention, and fixes event attribution and chain integrity
The audit service now publishes signed external anchors (KMS-backed or HMAC) over the audit hash chain head, making the log verifiable against wholesale database rewrites, and exposes chain-integrity status via new Prometheus gauges so breaks are no longer silent. It adds a separate, mutable session-log table with a configurable 90-day retention scheduler (disabled by default) to keep operational PII separate from the immutable 10-year regulatory trail. Event attribution is corrected by reading Kafka headers and topics at ingest, eliminating the previous UNKNOWN/unknown defaults, and party-merge history is resolved at read time via a new index so queries return complete results. Additionally, timestamp hashing is fixed to match database precision to prevent permanent chain-breaks, and a dedicated consumer for agent audit provenance ensures reliable, deduplicated persistence.
openbank-audit-service · high confidence
Blocks regulatory exports when data is incomplete, unbalanced, or provisional
The regulatory reporting surface now prevents operators from downloading CSV/JSON files unless the underlying data is verified and complete. A new export-readiness gate blocks exports in several specific scenarios: when templates have not loaded, when the data source is unavailable, when no closed (immutable) reporting periods exist, when templates contain data gaps, or when the financial data is unbalanced (including cases where the ledger and reporting service disagree on balance). It also blocks exports generated from live, mutable trial balances (provisional data) to ensure only frozen, auditable evidence is exported.
openbank-admin-ui/src/lib/regulatory · high confidence
Build system overhaul: vulnerability pinning, reproducible builds, and isolated pact tests
The build-logic module has been significantly restructured to improve security posture, build reliability, and test isolation. A new \openbank.dependency-vulnerability-pins\ convention plugin now centrally enforces patched versions for critical transitive dependencies (including Netty, Jackson, PostgreSQL, BouncyCastle, and HttpClient5) across all services, preventing untested or vulnerable versions from resolving. The build process now generates byte-reproducible JAR archives by default, enabling reliable supply-chain verification. Additionally, Pact provider-verification tests are now executed via a dedicated \providerPactTest\ task, decoupling them from the main test suite to prevent cache-key collisions and ensure accurate contract verification. Kover coverage measurement has been refined to exclude Testcontainers infrastructure and now strictly measures coverage against each service's own sources, removing noise from shared libraries.
build-logic · high confidence
Business account catch-up scheduler and savings proposal expiry fix
The account service now includes a new scheduled job, BusinessAccountCatchUp, which proactively opens business current accounts and activates pending accounts for parties that became active before this logic was deployed, ensuring onboarding completes regardless of deployment timing. Additionally, the SavingsProposalExpiryScheduler has been corrected to properly handle the Vert.x context by using a suspend function, fixing a previous issue where the scheduler silently failed to execute due to missing reactive context.
openbank-account-service/src/main/kotlin/com/openbank/account/infrastructure/scheduler · high confidence
Campaign authoring now uses a visual canvas instead of a form
The new campaign creation interface has shifted from a traditional form-based entry (which required specifying engine-level details like templates and delays) to a visual, step-by-step canvas. This change allows marketers to assemble and edit campaign journeys node-by-node, providing immediate visibility of the flow. The canvas supports up to five linear steps, integrates with journey recipes, and enforces specific guardrails such as single-flight saving and a four-eyes gate for activation, ensuring the authoring experience aligns with domain constraints rather than raw engine vocabulary.
openbank-admin-ui/src/app/campaigns/new · high confidence
Campaign console API routes for lifecycle actions and engagement analytics
The admin UI now exposes server-side API routes to manage campaign lifecycle transitions (submit, activate, pause, resume, close, enrol) and to display read-only engagement analytics. The new \actions/route.ts\ enforces a strict allowlist of actions and derives the approver identity from the authenticated session to prevent the maker/checker hole, while the \route.ts\ file adds a GET endpoint that aggregates campaign summaries and fetches ClickHouse-based engagement metrics (impressions, clicks, dismissals). These changes ensure that state transitions are validated server-side and that analytics data is available to the console without exposing raw service endpoints to the client.
openbank-admin-ui/src/app/api/campaigns · high confidence
Campaign list now uses a lifecycle board visualization
The campaign list view has been replaced with a new StageBoard component that visualizes the campaign lifecycle as a series of connected stages. This board displays the count of items in each stage, sized by volume, and uses color coding (green, amber, red) to indicate how long the oldest item has waited in that stage, helping users quickly identify bottlenecks. Terminal stages are excluded from age-based coloring to avoid confusion with completed work. The visualization includes optional motion animations for flow between stages, which can be paused, and supports bilingual labels (Czech/English).
openbank-admin-ui/src/components/flow · high confidence
Card management UI overhaul with RBAC, pagination, and scale-to-zero support
The Card Center page has been significantly redesigned to support large portfolios through client-side pagination (25 items per page) and unified operator layout integration. Access is now governed by Role-Based Access Control (RBAC), with specific actions like issuing cards gated behind 'cards:issue' permissions. The interface also handles service availability more gracefully by detecting and displaying 'scale-to-zero' (idle/waking) states for the card issuance backend, replacing the previous static health check. Additionally, the layout component was migrated to use the unified OperatorLayout shell.
openbank-admin-ui/src/app/cards · high confidence
Catalog API interfaces updated for Apache 2.0 license and new data-flow topology fields
The catalog API interfaces in the admin UI have been updated to reflect the platform's license change from MPL-2.0 to Apache 2.0, visible in the SPDX headers of all route files. Additionally, the governance service interface has been refactored to rename 'schemaName' to 'databaseName' and 'schemaLineage' to 'databaseLineage', while introducing a new 'databaseNameEvidence' field to track derivation status. The service graph interface now supports optional 'infraNodes', 'externalNodes', 'infraEdges', and 'externalEdges' to represent additive data-flow tiers for infrastructure and external dependencies, ensuring backward compatibility with older snapshots.
openbank-admin-ui/src/app/api/catalog · high confidence
Clarifies logic for determining if payments settle internally
The domain layer now explicitly distinguishes between payments that stay within the bank and those that leave, preventing incorrect value-date rolling for internal transfers. A new \SettlementScope\ object determines if a booking settles immediately based on whether it credits an internal account or uses specific internal rails (INTERNAL, FEE, INTEREST), rather than relying on potentially unreliable rail strings. This change addresses issues where own-account transfers and in-house payments were incorrectly subject to clearing calendar rules, which previously caused silent refusals and incorrect availability calculations.
openbank-libs-iso20022/src/main/kotlin/com/openbank/libs/domain · high confidence
Clearing Simulator: Pact verification, auth role update, and license migration
The clearing simulator now includes provider-side Pact verification tests (both folder-based and broker-connected) to ensure contract compliance with consumers like the Swift service. The REST API authentication roles have been updated from ROLE\_SERVICE to ROLE\_API to align with platform standards, and the service license has been migrated from MPL-2.0 to Apache-2.0. Additionally, the Dockerfile has been simplified to a runtime-only recipe with a pinned base image digest, and the service now uses synthetic taint filtering for outbound REST calls.
openbank-clearing-simulator · high confidence
Compile-time enforcement for marketing contact call sites
A new \MarketingCallSite\ annotation has been introduced to mark functions that initiate marketing communications, such as campaign steps or engagement events. This annotation enables a compile-time check (ADR-0219 D4) that ensures these call sites are properly wired with a \ContactPolicyGate\ and explicitly perform policy checks, preventing unauthorized marketing dispatches at build time rather than relying on developer convention.
openbank-libs-domain/src/main/kotlin/com/openbank/libs/contact · high confidence
Configurable AWS Config recording with new IAM role output
The audit-baseline module now exposes a new \config\_recording\_enabled\ variable (defaulting to true) that allows users to stop the AWS Config recorder while keeping all underlying resources provisioned, which eliminates ConfigurationItem costs in non-production environments like sandbox. Additionally, the module now exports the \config\_role\_arn\ output, providing direct access to the IAM role ARN used by the configuration recorder.
openbank-infra/aws/modules/audit-baseline · high confidence
DNS module updates: AWS provider upgrade, SPF configuration for Zoho Mail, and KMS rotation fix
The DNS infrastructure module upgrades the AWS Terraform provider from version 5.80 to 6.53. It corrects the SPF record for the primary domain to authorize Zoho Mail servers (using \\~all\ and including the Zoho verification token) instead of rejecting all email, ensuring the \[e-mail redacted]\ inbox remains functional, and adds a strict \-all\ SPF record for the \admin\ subdomain. Additionally, it explicitly disables automatic key rotation on the DNSSEC KMS key, acknowledging that AWS KMS does not support automatic rotation for asymmetric keys used in DNSSEC.
openbank-infra/aws/modules/dns · high confidence
Database schema updates for GDPR, savings goals, and delegation
The account service database schema has been extended to support several new capabilities and compliance requirements. A new \legal\_name\ column on the \accounts\ table enables GDPR Art. 17 erasure by allowing the nullification of PII. Savings goal functionality is introduced via \goal\_name\, \goal\_target\_minor\_units\, and \goal\_target\_date\ columns, alongside a new \savings\_withdrawal\_proposals\ table to manage propose-only withdrawal flows with expiry windows. Delegation features are expanded with \account\_delegation\_projection\ tables to enforce grant policies, including resource typing for savings goals and approval policies (SOLO vs. N\_OF\_M), as well as a new \account\_party\_mandate\_projection\ table for SCA-derived human actors. Additionally, idempotency for account opening is enforced via a new \account\_idempotency\ table, term deposits now record the specific terms version used at opening, and the outbox table gains columns for atomic row claiming and synthetic taint tracking to improve reliability.
openbank-account-service/src/main/resources/db · high confidence
DevOps dashboard now surfaces AI agent findings and unifies layout
The DevOps page has been redesigned to display AI-generated security and compliance findings (via the new AgentInsightsPanel) alongside existing DORA metrics, replacing the previous test coverage bars. The layout now uses a shared OperatorLayout component for consistency, and the UI supports human-in-the-loop approve/reject decisions for these findings. Additionally, hardcoded color values have been replaced with CSS variables to support theming, and the project license has been updated from MPL-2.0 to Apache-2.0.
openbank-admin-ui/src/app/devops · high confidence
Display readable party names instead of truncated UUIDs on campaign screens
The campaign console now resolves party IDs to their legal or trading names by querying the party-service, replacing the previously displayed truncated UUIDs with human-readable identifiers. This change improves usability by making it easier to identify customers on marketing screens, while ensuring robustness through deduplication of requests, a cap on concurrent lookups, and a fallback to the original ID if a name cannot be resolved.
openbank-admin-ui/src/lib/campaigns · high confidence
Dispute service introduces tamper-evident evidence chains and stricter outbox reliability
The dispute service now enforces tamper-evident integrity on dispute evidence by appending SHA-256 hashes to every evidence item, ensuring that any in-place edit, deletion, or re-ordering of stored evidence is detected during verification. To support this, the database schema was extended with sequence, prev\_hash, and record\_hash columns on the evidence table, and a new remediation outcome type was added to disputes. Concurrent outbox reliability was improved by implementing atomic row claiming with SKIP LOCKED and adding a claimed\_at column to prevent duplicate publishing during rolling deployments, while a synthetic taint column preserves origin metadata across asynchronous dispatch. Additionally, a strict monotonic aggregate revision column was added to complaints to ensure consistent ordering for downstream consumers, and a guard constraint was applied to the outbox's created\_at column to prevent epoch-stamped rows from disrupting dispatch ordering.
openbank-dispute-service · high confidence
Durable DORA ICT incident register with transactional outbox
The security scanner now persists DORA ICT incident records to a database instead of an in-memory map, ensuring incidents survive pod restarts and are consistent across replicas. It introduces a transactional outbox pattern for these events, replacing a previously unused security outbox, and adds role-based access control to the incident and scanner REST endpoints.
openbank-security-scanner · high confidence
EKS cluster hardening: audit logging, node reliability, and scheduler stability
This update improves the reliability and observability of the EKS control plane and nodes. Cluster API audit logging is re-enabled to restore visibility into API access for security and compliance, while the bootstrap node group is now tied to the control-plane version to prevent drift and has auto-repair enabled to replace stuck nodes. The EBS CSI driver reserves attachment slots to prevent scheduler overcommitment on Nitro instances, and the new EKS node monitoring agent is installed to surface deeper node health conditions. Additionally, the VPC CNI's node agent now logs network policy events for observation, and the Terraform AWS provider is upgraded to v6.
openbank-infra/aws/modules/eks · high confidence
Enhanced security and cost optimization for the static site infrastructure
The static site module now enforces TLS-only access to the underlying S3 bucket via a new DenyInsecureTransport policy, ensuring defense-in-depth even if CloudFront redirection fails. The Content Security Policy has been updated to explicitly allowlist hCaptcha and Web3Forms origins, enabling the TestFlight beta signup form while maintaining strict isolation for other scripts. Additionally, S3 lifecycle rules have been adjusted to transition non-current object versions to the cheaper STANDARD\_IA storage class after 30 days before expiring them at 60 days, and the underlying AWS Terraform provider has been upgraded from version 5.80 to 6.53.
openbank-infra/aws/modules/static-site · high confidence
Expanded account lifecycle notifications and GDPR compliance support
The account service now explicitly notifies customers when their account is opened, closed, or frozen, ensuring they are informed of status changes that affect their ability to transact. Additionally, the system now supports GDPR Article 17 requirements by allowing the nullification of legal names for accounts owned by erased parties, and introduces idempotent account opening to prevent duplicate accounts during concurrent requests.
openbank-account-service/src/main/kotlin/com/openbank/account/application/port/out · high confidence
Feature flag CDI interceptor bindings moved to runtime module
The \FeatureFlag\ annotation and its associated \FeatureFlagInterceptor\ have been relocated from the \openbank-libs\ module to the new \openbank-libs-runtime\ module. This change aligns with the project's architectural split between domain logic and runtime framework dependencies, ensuring that CDI-specific interceptor bindings reside in the runtime layer. For users, the package name remains unchanged, so no import adjustments are required, but the underlying module structure has shifted to better separate framework concerns from pure domain code.
openbank-libs-runtime/src/main/kotlin/com/openbank/libs/flags · high confidence
Fee schedule validation and waiver rule description logic
The admin UI now includes a new contract layer for fee schedules that validates incoming API responses and formats waiver rules for display. This change adds strict validation for fee schedule items (ensuring required fields like ID, code, name, and valid numeric amounts) and enforces consistency between waiver eligibility flags and their associated rules. It also introduces a helper to generate human-readable descriptions of waiver conditions (e.g., 'balance \> 1000 USD'), enabling clearer communication of fee waiver eligibility criteria to administrators.
openbank-admin-ui/src/lib/fees · high confidence
Fees page adopts unified operator layout and clarifies waiver eligibility
The Fees page now uses the shared OperatorLayout component, aligning its navigation and header with the rest of the admin UI. The interface has been updated to highlight automated waiver rules, replacing the previous 'Fee Categories' stat with a count of fees that have evaluable waiver conditions, and the operations table now displays the specific waiver rule instead of frequency. Additionally, the page clarifies its data state by showing a message when the last loaded fee schedule may be stale, and improves accessibility with proper ARIA labels on interactive elements.
openbank-admin-ui/src/app/fees · high confidence
FinOps AI costs API adds data coverage metadata and parallelizes queries
The FinOps AI costs API now returns a \coverage\ object detailing Prometheus data availability (retention, time windows) and clarifies budget state by returning \null\ for \totalCostLast30dUsd\, \selfHostedPct\, and \tokensLast7d\ when specific metrics are unavailable, rather than defaulting to zero. Additionally, the API parallelizes Prometheus queries for multiple agents to improve performance and enforces a 5-second timeout on Prometheus fetches to prevent hanging requests.
openbank-admin-ui/src/app/api/finops/ai-costs · high confidence
FinOps anomalies endpoint now requires authentication and enforces timeouts
The FinOps anomalies API route now enforces access control by requiring the 'system:view' permission before returning data, blocking unauthenticated requests. Additionally, the underlying call to Alertmanager now includes a 5-second timeout, explicit cache control to prevent stale data, and standard JSON headers to ensure reliable and secure retrieval of anomaly information.
openbank-admin-ui/src/app/api/finops/anomalies · high confidence
FinOps page adopts unified operator layout and introduces daily spend trends
The FinOps page now uses the shared OperatorLayout shell, replacing the previous custom sidebar and header structure to align with the platform's unified operator surfaces. Additionally, the page now displays a daily spend trend chart for the last seven days, providing granular cost visibility that was previously only available in the AWS console. The interface also incorporates theme-aware colors for status indicators and integrates the AgentInsightsPanel to surface AI-agent findings directly below the metrics.
openbank-admin-ui/src/app/finops · high confidence
Flaky Test Hunter API endpoints and legacy trigger retirement
The admin UI now includes dedicated backend-for-frontend (BFF) routes to fetch flaky test findings and individual finding details from the flaky-test-hunter service, enabling the findings list and detail views. The legacy trigger endpoint has been retired and now returns a 410 Gone response, directing users to the governed IAOps trigger route instead.
openbank-admin-ui/src/app/api/flaky-test-hunter · high confidence
Governance API refactored to use modular data loaders and updated license
The governance API route has been refactored to replace inline file parsing and hardcoded ADR status lists with modular library functions (loadAgentCharters, loadAiGovernanceSnapshot), simplifying the route logic and centralizing data loading. Additionally, the file's license header has been updated from MPL-2.0 to Apache-2.0.
openbank-admin-ui/src/app/api/iaops/governance · high confidence
Governed reporting registry with strict parameter validation
The Admin UI reporting module now uses a governed query registry where reports are defined by declarative schemas (identifying parameters, columns, permissions, and SQL) rather than ad-hoc queries. This introduces strict validation for all report parameters (dates, months, numbers, enums) at the client boundary to prevent injection and ensure data integrity, and adds a client-side contract to validate report results against their expected schema before display.
openbank-admin-ui/src/lib/reporting · high confidence
Gradle wrapper upgraded to version 9.7.1 with checksum validation
The Gradle wrapper has been updated from version 9.6.0 to 9.7.1. To ensure integrity, a SHA-256 checksum (distributionSha256Sum) is now specified for the distribution URL, and distribution validation is explicitly enabled. This change ensures that builds use the correct, unmodified Gradle binary.
gradle/wrapper · high confidence
Idempotency keys now scoped per service and caller with canonical request fingerprinting
Idempotency keys are now scoped by service and caller principal, preventing a request from one service or user from incorrectly replaying in another. The system uses a canonical JSON fingerprint of the request body (sorted keys, normalized numbers, dropped nulls) to ensure identical requests generate identical hashes regardless of serialization quirks. A shared default Redis-backed store replaces per-service configuration, while a deployment transition guard ensures safe migration from legacy unscoped keys. Oversized responses are no longer stored for replay, returning a 409 on retry instead.
openbank-libs-runtime/src/main/kotlin/com/openbank/libs/idempotency · high confidence
Identity-aware access gate for internal admin tools
Internal tools (Grafana, Alertmanager, Pyrra) are now protected by a new identity-aware edge gate that validates user sessions and permissions before allowing access. This change ensures that only users with the appropriate 'system:view' permission can reach these tools, and specifically denies the public demo account access to Alertmanager to prevent accidental alert silencing, while restricting it to read-only views for Grafana and Pyrra.
openbank-admin-ui/src/app/api/gate · high confidence
Improved reliability of party event processing and new delegation enforcement projection
The account service now distinguishes between unprocessable 'poison pill' events and transient projection failures, ensuring that well-formed events failing due to temporary outages are retried and dead-lettered rather than silently dropped, which previously caused permanent data loss for new customers. Additionally, a new \DelegationEventConsumer\ has been introduced to maintain a local enforcement projection of delegation grants (specifically for ACCOUNT and SAVINGS\_GOAL resources), allowing the account service to independently verify and enforce access permissions based on delegation lifecycle events.
openbank-account-service/src/main/kotlin/com/openbank/account/infrastructure/kafka · high confidence
Improved service discovery, fetch resilience, and server-side routing in the admin UI
The admin UI now handles backend outages and cold-starts more gracefully: the new useServiceResource hook automatically retries requests when a service is scaling up from zero, preventing operators from seeing transient "not responding" errors. A new rowHandoff service allows list-to-detail navigation to reuse existing data without redundant network calls. Server-side routes can now correctly fetch relative URLs via a new serverSvcUrl helper, fixing issues where healthy services appeared down. Additionally, the service registry has been updated to include several new services (KYB, VoP, Documents, Lending, SDD, Copilot, Fraud, Analytics Sink, AnaCredit, Case Coordinator, Communication) and fixes the Kubernetes name mapping for the Security Scanner to ensure accurate discovery.
openbank-admin-ui/src/lib/services · high confidence
Infrastructure page adopts unified operator layout and adds platform control plane components
The Infrastructure page now uses the shared OperatorLayout for consistent navigation and styling, replacing the previous custom sidebar/header structure. The license header has been updated from MPL-2.0 to Apache-2.0. New platform control plane and orchestration components—Temporal, KEDA, ArgoCD, Kyverno, cert-manager, and Karpenter—have been added to the infrastructure status view. The page also integrates contextual operational insights, uses a standardized status badge component, and respects the user's locale for date formatting.
openbank-admin-ui/src/app/infrastructure · high confidence
Infrastructure status panel now distinguishes unavailable services from outages
The infrastructure status view in the admin UI now correctly reports services that are not part of the current deployment topology as 'UNKNOWN' instead of 'DOWN'. This change introduces a new probing module that separates cluster-specific and local development service definitions, using TCP and HTTP checks to verify reachability. Services like Temporal, KEDA, and ArgoCD, which are Kubernetes-only, will now show a neutral state in local environments rather than triggering false outage alerts, while other services like Postgres, Kafka, and Keycloak continue to be monitored for actual availability.
openbank-admin-ui/src/lib/infra · high confidence
Introduce structured fleet health evidence parsing and summarization
The operator dashboard now includes dedicated logic to parse and validate governance fleet data and service health metrics from the backend. New utility modules define strict contracts for fleet groups (core, payments, compliance, identity, open-banking, platform) and health entries, ensuring that service names, timestamps, and status indicators (UP/DOWN/UNKNOWN) are validated before display. Additionally, a summarization function aggregates individual health check samples into a high-level fleet state (healthy, degraded, or unavailable) based on deployment and latency data, providing a clearer, evidence-based view of system reliability without inferring unmeasured metrics like uptime or error rates.
openbank-admin-ui/src/lib/dashboard · high confidence
Lending console restructured as a credit desk with staged portfolio view
The lending console has been redesigned from a flat table dump into a stage-oriented credit desk, prioritizing actionable insights over raw data. The interface now centers on the origination queue and active loan portfolio, using stages as the primary navigation object rather than individual rows. Key behavioral improvements include honest handling of capped server limits (preventing misleading totals), clear distinction between loading states and confirmed zeros, and localized display of monetary values. The layout now utilizes a unified operator shell, and status badges are rendered with accessible color tones.
openbank-admin-ui/src/app/lending · high confidence
Library modularization and default Clock bean provision
The openbank-libs module has been split into domain and runtime components, moving API definitions like SearchRequest to the new domain module and updating their license headers to Apache 2.0. Additionally, a default Clock producer has been added to the runtime module to ensure that services lacking a custom Clock implementation can compile successfully by providing a fallback bean that respects existing service-specific overrides.
openbank-libs-domain/src/main/kotlin/com/openbank/libs/api, openbank-libs-runtime/src/main/kotlin/com/openbank/libs/time · high confidence
License change to Apache-2.0 and new account status notifications
The license for the files in this package has been updated from MPL-2.0 to Apache-2.0. Additionally, the Kafka notification publisher now sends messages to inform customers when their account is opened, closed, or frozen, in addition to the existing transaction completion notifications.
openbank-account-service/src/main/kotlin/com/openbank/account/infrastructure/messaging · high confidence
License header script now respects multi-license structure and CI mirrors platform images to ECR
The add-license-headers.sh script has been updated to support the repository's multi-license model (ADR-0136); instead of stamping MPL-2.0 on all files, it now reads the AGPL-3.0-only module list from governance/rules.yaml and applies the correct Apache-2.0 or AGPL-3.0 headers based on the file's path, while explicitly skipping .sql files to prevent Flyway checksum mismatches. Additionally, the mirror-ci-base-images.sh script now mirrors platform-specific images (alloy, grafana, falco, falcoctl) to ECR Public in addition to Kafka, ensuring that in-cluster DaemonSets and CI runners can pull these images without hitting Docker Hub rate limits or relying on anonymous pull-through caches.
scripts · high confidence
License migration to Apache-2.0 and deployment guidance update
The OpenBank Developer Portal has officially migrated its licensing from MPL-2.0 to Apache-2.0, a change reflected in the OpenAPI specification, the main site footer, and the security policy reference. Additionally, the portal now includes a link to a reference deployment guide in the main index, providing users with topology, sizing, and cost information for self-hosted evaluations. The underlying Docker image has also been updated to nginx-unprivileged 1.31-alpine, pinned to a specific digest for security compliance.
openbank-developer-portal · high confidence
License relicensed to Apache-2.0 and TERM\_DEPOSIT account type added
The openbank-admin-ui types module has been relicensed from MPL-2.0 to Apache-2.0, updating the license headers in index.ts and next-auth.d.ts. Additionally, the AccountType definition in index.ts now includes 'TERM\_DEPOSIT' as a valid value, enabling the system to recognize and handle term deposit accounts.
openbank-admin-ui/src/types · high confidence
Loyalty evidence validation and Lípa console educational content
The admin UI now validates loyalty data structures before use, ensuring that catalogue and party responses conform to expected schemas (e.g., valid states, non-negative counts, correct types) to prevent runtime errors from malformed API data. Additionally, the Lípa console now includes structured, bilingual educational content explaining the program's core principles (such as non-transferability and no cash-out), its system integrations, and its lifecycle, helping operators understand the rules and boundaries of the loyalty system.
openbank-admin-ui/src/lib/loyalty · high confidence
MCP service introduces stateful agent sessions, PII masking, and untrusted data handling
The openbank-mcp-service has been updated to enforce stricter security and compliance controls for AI agent interactions. Agent sessions are now stateful, storing lifecycle data and performing live Out-of-Band (OBO) validation, with a 13-month retention policy for audit trails. To protect customer privacy, the service now applies mandatory PII masking to all tool results, redacting natural-person identifiers and masking IBANs to their last four digits while preserving non-PII data like amounts and timestamps. Additionally, all tool results are now wrapped in untrusted data markers to prevent prompt injection attacks, ensuring that bank data is clearly distinguished from instructions. The service also implements server-side validation for payment proposal arguments and policy-filtered tool discovery, ensuring agents only see tools they are authorized to use.
openbank-mcp-service · high confidence
Modernized and clarified authentication error and access-denied pages
The OpenBank Admin UI now features a redesigned, accessible, and localized experience for authentication errors and forbidden access. The error page (openbank-admin-ui/src/app/auth/error) provides specific, user-friendly explanations for configuration issues, access denials, and expired verification links, replacing generic messages with clear guidance and a secure retry mechanism. The forbidden page (openbank-admin-ui/src/app/auth/forbidden) clarifies that access boundaries are security controls rather than system failures, showing the requested destination path and offering a direct return to the dashboard. Both pages support English and Czech, use consistent modern styling, and improve accessibility with proper ARIA labels and focus management.
openbank-admin-ui/src/app/auth/error · high confidence
Modernized sanctions approval and list-change dialogs
The sanctions management interface now uses new, modernized dialog components for key actions. The SanctionsApprovalDecisionDialog provides a clearer confirmation flow for approving or rejecting another operator's sanctions decision, including specific warnings about the maker's ability to retry. The SanctionsListChangeDialog offers a more detailed view when pausing or resuming automatic updates for a sanctions list, explicitly stating that the change is immediate, bypasses the four-eyes approval queue, and does not affect API screenings outside this console. Both dialogs improve clarity on the consequences of user actions and handle busy states and errors more robustly.
openbank-admin-ui/src/components/sanctions · high confidence
New Redis-backed approval store and shared endpoint support
The approval library now uses a new Redis-based persistence layer (RedisApprovalStore) that organizes records under service-specific namespaces to prevent cross-service collisions, enforces atomic state transitions via Lua scripts, and supports migration from the previous pipe-delimited string format. Additionally, a shared ApprovalEndpointSupport class provides the common logic for maker-checker endpoints, ensuring that checker identity is derived securely from the security context and that null request bodies are rejected before identity resolution.
openbank-libs-runtime/src/main/kotlin/com/openbank/libs/approval · high confidence
New build-info endpoint and optimized hex digest rendering
The shared libraries now expose a static \BuildInfo\ object that aggregates tech-stack details (Kotlin, Quarkus, JVM, OS, and build metadata) into a stable map for the \/api/v1/info\ endpoint, enabling the admin UI to surface stack inventory. Additionally, hex digest rendering has been refactored to use \java.util.HexFormat\, which produces byte-identical lowercase hex strings while significantly reducing allocation overhead compared to the previous \String.format\ approach.
openbank-libs-domain/src/main/kotlin/com/openbank/libs/util · high confidence
New governance data loaders and behavioral updates in the admin UI
The admin UI now includes new server-side loaders for AI agent charters, diagnostics, identity resolution, outcome metrics, and case decision briefs, enabling detailed per-agent visibility and evidence-based governance reporting. The compliance control tower now demotes controls from 'enforced' to 'planned' when live signals disprove their status, ensuring the UI reflects actual enforcement rather than static claims. Additionally, the platform license has been updated from MPL-2.0 to Apache-2.0 across the governance module.
openbank-admin-ui/src/lib/governance · high confidence
Notifications page now uses shared layout and content components
The notifications page layout has been simplified to use the shared OperatorLayout component, ensuring consistent navigation and header styling across the admin interface. The page content is now rendered via the NotificationsContent component, which handles the display of notification data, and access is protected by the AuthGuard component requiring the 'notifications:view' permission.
openbank-admin-ui/src/app/notifications · high confidence
Observability stack page adopts unified theme and component library
The Observability Stack page in the admin UI now uses a consistent design system. Hardcoded color values for pillar cards and the architecture diagram have been replaced with semantic CSS variables (accent, info, success, warning, danger), and the custom header markup has been swapped for the shared PageHeader component. Additionally, the page's license header was updated from MPL-2.0 to Apache-2.0.
openbank-admin-ui/src/app/observability/stack · high confidence
PID service outbox schema hardened with concurrency, taint, and data-integrity guards
The PID service database schema is extended with three new Flyway migrations to improve the reliability of the asynchronous outbox. A \claimed\_at\ column is added to support atomic row claiming via \FOR UPDATE SKIP LOCKED\, preventing duplicate dispatch when multiple service instances run concurrently. A \synthetic\ boolean column is added to preserve the origin taint of synthetic events across the dispatch pipeline. Finally, a check constraint is added to ensure \created\_at\ timestamps are plausible (on or after 2020-01-01), preventing epoch-stamped rows from disrupting the dispatcher's ordering.
openbank-pid-service · high confidence
PSD2 service replaces stub consent validation with real upstream client
The PSD2 service now calls the real consent-service REST API to validate consents, closing a security gap where the previous stub always returned true. This change introduces a typed REST client for the consent-service, backed by a real adapter that maps the provider's actual validation verdict, while keeping create/revoke operations on the stub as a follow-up. The update is supported by new database migrations for outbox tracking and synthetic taint, the removal of the unused outbox table, and comprehensive contract and unit tests for the new client and authorization flows.
openbank-psd2-service · high confidence
Platform relicensed from MPL-2.0 to Apache-2.0
The OpenBank platform has changed its software license from the Mozilla Public License 2.0 to the Apache License 2.0. This update is reflected in the license headers of the shared \openbank-libs\ library (including components like exception mappers, authorization interceptors, and ID generators) and across the \openbank-admin-ui\ application source files, ensuring consistent legal terms for all contributors and downstream users.
(repo-wide) · high confidence
Production readiness scoring and CI governance improvements
The production readiness collector now derives the money-path service list from the authoritative rules.yaml instead of a hardcoded set, ensuring all services are scored with the correct strictness. It also fixes scoring logic to detect hexagonal ports by package name rather than filename, validates contract tests by checking for actual pact library imports or specific test class names instead of scanning comments, and scores only source-level database migrations to ignore Gradle copy artifacts. Additionally, the CI pipeline now enforces that every committed pact is replayed by a provider test before merge, prevents build-time-resolved CDI bean selections from being overridden by runtime environment variables, and prefers the newest performance evidence when selecting GitHub Actions artifacts.
python · high confidence
Redesigned loyalty workspace with new UI and evidence validation
The loyalty admin interface has been redesigned to provide a unified workspace for the Lípa programme, featuring a new layout, comprehensive CSS styling, and a multi-tab page (overview, catalogues, party, principles, finance, AI). This update introduces a new layout component wrapping the workspace in the OperatorLayout and adds specific styling for metrics, action cards, and responsive design. Additionally, the customer lookup functionality now includes validation for loyalty evidence, ensuring that party data is parsed and validated against a defined contract before display, improving data reliability for marketing and support teams.
openbank-admin-ui/src/app/loyalty · high confidence
Removal of central DomainMetrics observability facade
The central \DomainMetrics\ class, which previously provided a unified facade for tracking domain events such as payments, accounts, parties, KYC, SCA, and ledger postings, has been removed from the observability library. This change eliminates the shared instrumentation layer that services used to record metrics like submission counts, processing durations, and screening attempts without exposing raw Micrometer APIs directly.
openbank-libs/src/main/kotlin/com/openbank/libs/observability · high confidence
Removal of default timestamp in ApprovalPorts
The \findPendingActive\ method in the Four-Eyes approval ports no longer provides a default value for the \asOf\ parameter. Users must now explicitly pass a timestamp when querying for pending active approvals, rather than relying on the previous default behavior.
openbank-libs-domain/src/main/kotlin/com/openbank/libs/foureyes · high confidence
Removal of redundant ClockProducer
The custom ClockProducer in the account service infrastructure has been removed because its functionality is already provided by the DefaultClockProducer. This simplifies the codebase by eliminating duplicate logic for producing the system UTC clock.
openbank-account-service/src/main/kotlin/com/openbank/account/infrastructure · high confidence
Revert removal of broken ledger compensation in settlement
The previous fix that removed the ledger compensation logic (which could never run) has been reverted. This restores the original code path for settlement compensation, acknowledging that the prior removal was incorrect despite the logic being non-functional.
openbank-infra · high confidence
Risk and liquidity data is now grouped by regulatory category with human-readable labels
The admin UI now aggregates risk-engine output into logical regulatory categories (such as LCR/NSFR liquidity buckets and capital exposure classes) instead of displaying raw, per-loan lines. This change introduces new libraries for formatting money and percentages, grouping liquidity and exposure lines by their factor keys and IFRS 9 stages, and rendering bilingual (Czech/English) labels for these categories, stages, and regulatory citations. Users will see summarized totals for each category with clear, plain-language descriptions and proper pluralization, making the data easier to audit and reason about without losing the ability to drill down into the underlying items.
openbank-admin-ui/src/lib/format, openbank-admin-ui/src/lib/risk · high confidence
Runner infrastructure hardening and AWS provider upgrade
The GitHub Actions runner module now uses the AWS provider v6.53 and enforces stricter security and reproducibility standards. The runner instance is configured to explicitly assign a public IP address while disabling automatic public IP assignment on the subnet, a change justified by the absence of a NAT gateway to reduce costs. Additionally, the user-data script now installs Python dependencies with strict hash verification to prevent supply-chain tampering, and the Trivy scanner installation is pinned to a specific version (v0.63.0) with a SHA-256 checksum check to ensure integrity.
openbank-infra/aws/modules/runner · high confidence
SEPA Instant: four-eyes approval queue, fraud-scoring observability, and audit attribution
Operators can now view and decide on pending four-eyes approvals for SCT Inst payments via a new REST endpoint, resolving the previous issue where parked decisions were invisible to the checker. The service also distinguishes synthetic fraud verdicts (generated when the fraud service is unreachable) from real ones via new metrics, ensuring operational visibility into scoring degradation. Additionally, published events now include a sourceService field for accurate audit attribution, and the unused sct\_inst\_outbox database table has been removed.
openbank-sepa-instant · high confidence
SWIFT messaging page adopts unified operator layout and service resource patterns
The SWIFT messaging page now uses the shared OperatorLayout component for its shell, replacing the previous custom sidebar/header structure, and switches to the unified service resource hook for data fetching. This brings scale-to-zero awareness (idle/waking states) and retained snapshot display to the UI, while also updating the license header to Apache-2.0. The page's status metrics have been realigned to the new SWIFT lifecycle groups (in flight, confirmed, exceptions), and the layout now enforces a payment-rails:view permission.
openbank-admin-ui/src/app/swift · high confidence
Sanctions BFF routes now use shared upstream helper and support approval workflows
The sanctions API routes in the admin UI now delegate to a shared \forwardToSanctionsService\ helper, ensuring consistent authorization headers and error handling across checks, lists, and screening endpoints. This change fixes previous issues where manual list refreshes and updates failed due to missing authentication. Additionally, new routes have been added to support the sanctions approval workflow: a GET endpoint for the checker's pending-approvals queue, a PATCH endpoint for the checker to decide on approvals, and a POST endpoint for manual review of screening hits, enabling operators to dispose of sanctions hits through the UI.
openbank-admin-ui/src/app/api/sanctions · high confidence
Segment catalogue and preview API endpoints added
The admin UI now exposes two new API routes to support the shift to code-defined segments: a read-only segment catalogue endpoint that lists available segments, and a preview endpoint that allows marketers to evaluate a specific segment version against current data. These endpoints proxy requests to the campaign service, handling authentication and providing distinct state indicators (such as 'unauthorized', 'unknown\_segment', or 'unreachable') to ensure that service errors are not misinterpreted as empty results.
openbank-admin-ui/src/app/api/segments · high confidence
Settings page now uses unified layout and shows real session data instead of mock profiles
The Settings page layout has been consolidated to use the shared OperatorLayout component, replacing the previous custom sidebar and header structure. The profile view no longer displays hardcoded mock user details (such as 'Admin User' with static fields); instead, it leverages the real session profile via Next-Auth. Additionally, several settings tabs (Notifications, Security, API Keys) now explicitly indicate that their features are not yet supported by a backend contract, removing previous fake toggles and simulated save actions to prevent misleading user interactions.
openbank-admin-ui/src/app/settings · high confidence
Shared topology engine extracted for consistent visualization
The topology visualization components have been refactored to extract shared logic into a reusable engine, ensuring consistent rendering across service map, infrastructure topology, and data lineage pages. This change introduces shared geometry primitives for drawing curved, box-trimmed edges and mixing colors, a parameterized band layout system for wrapping items into centered rows, and reusable SVG definitions for node shadows and arrow markers. Additionally, a new flow animation component with a React hook respects the OS-level 'reduce motion' preference to disable animations for accessibility, while ensuring hydration consistency between server and client renders.
openbank-admin-ui/src/components/topology · high confidence
Stabilizes NAT instance reliability and reduces VPC endpoint costs
The network module now prevents accidental NAT instance recreation by pinning the AMI ID via a new variable, ensuring that infrastructure changes only occur when explicitly reviewed. It also increases the NAT instance size from t4g.nano to t4g.small to resolve capacity issues in specific availability zones and disables automatic public IP assignment on public subnets to align with security best practices. Additionally, the module removes four low-traffic VPC interface endpoints (including STS) to lower monthly costs, as their traffic volume is negligible compared to their fixed standing charges.
openbank-infra/aws/modules/network · high confidence
Standardized Temporal client configuration and fixed Kotlin data class serialization
The fleet-wide Temporal client configuration has been consolidated into a single \TemporalConfig\ interface, replacing multiple per-service copies with explicit defaults for server URL, namespace, and task queue, while introducing a \metricsEnabled\ flag to preserve existing behavioral differences. Additionally, the \TemporalClientProducer\ now registers Jackson's Kotlin module, allowing workflows to correctly serialize and deserialize Kotlin data classes without requiring no-argument constructors, which previously caused workflow task failures.
openbank-libs-temporal/src/main/kotlin/com/openbank/libs/temporal · high confidence
Strengthened security and error handling in the RCA API route
The RCA API endpoint now enforces server-side authentication and role-based authorization (system:view) for all requests, closing the previous reliance on client-side guards. Additionally, error responses no longer expose internal upstream details or stack traces to the client, returning generic error messages instead to prevent information leakage.
openbank-admin-ui/src/app/api/iaops/rca · high confidence
Technical Accounts page removed and layout unified
The dedicated Technical Accounts page has been removed, eliminating the hardcoded seed data and static table that previously displayed technical account balances and types. Additionally, the layout for this section now delegates to the shared OperatorLayout component, replacing the previous custom sidebar and header structure.
openbank-admin-ui/src/app/technical-accounts · high confidence
Temporal admin UI adopts operator layout and clarifies implementation status
The Temporal admin page now uses the shared OperatorLayout component for its shell, replacing the previous custom sidebar and header structure. The page content has been updated to reflect the current state of the system: the 'Shared Library' phase is marked as partially complete (client and config are shipped, but Saga DSL and OPA interceptor are not), and the PSD2 compliance section clarifies that the activity-level policy gate is planned but not yet deployed. Additionally, hardcoded color values in the UI components have been replaced with CSS variables to align with the new theme system.
openbank-admin-ui/src/app/temporal · high confidence
Test results API now dynamically lists observed services instead of a hardcoded list
The test results API endpoint no longer relies on a static, hardcoded list of known services. Instead, it dynamically derives the list of services from the actual test results present in the database, ensuring that all observed services are included in the response even if they were not previously defined in the application code. This change also updates the file's license header from MPL-2.0 to Apache-2.0.
openbank-admin-ui/src/app/api/test-results · high confidence
Treasury section landing page redirects to deal blotter
Navigating to the main Treasury section now automatically redirects users to the deal blotter view (/treasury/deals). A new layout component wraps the section content within the standard operator layout, ensuring consistent styling and navigation for all Treasury sub-pages.
openbank-admin-ui/src/app/treasury · high confidence
Unified operator layout for SEPA Instant and System pages
The SEPA Instant and System sections of the admin UI now share a common layout shell via the new OperatorLayout component, replacing the previous custom Sidebar and Header implementations. This change standardizes the visual structure and navigation experience across these operator surfaces, ensuring consistent styling and layout behavior.
openbank-admin-ui/src/app/sepa-instant, openbank-admin-ui/src/app/system · high confidence
Unified operator shell with mobile navigation, command palette, and dark theme
The admin UI now uses a single, shared layout shell (AppShell) for all authenticated operator routes, replacing the previous pattern where domain pages duplicated layout code. This change introduces a mobile-responsive navigation drawer with robust focus trapping, a global ⌘K command palette for quick navigation, and a toggleable dark theme. The layout also integrates a skip-link for accessibility, real-time session management via SessionProvider, and Core Web Vitals telemetry through RumScreenTracker, ensuring consistent visual hierarchy and behavior across the platform.
openbank-admin-ui/src/components/layout · high confidence
Updated Strimzi operator version and license headers
The FinOps lifecycle API route now reports the in-cluster Apache Kafka operator as Strimzi 1.2.0 (upgraded from 1.0.0). Additionally, the file's license headers have been updated from MPL-2.0 to Apache-2.0.
openbank-admin-ui/src/app/api/finops/lifecycle · high confidence
Updated Tempo backend port configuration
The BFF proxy for Grafana Tempo has been updated to target port 3200 instead of 3100 for both container and local development environments. This change ensures the Trace Explorer correctly routes search and single-trace fetch requests to the Tempo query API, preventing 502 errors when the service is reachable on the new port.
openbank-admin-ui/src/app/api/tempo · high confidence
Fixes
Add AML case data validation and parsing logic
Introduces a new contract module for Anti-Money Laundering (AML) cases that defines strict TypeScript types and validation rules for case data. This includes enumerations for statuses, risk levels, and screening types, along with a parser function that validates incoming raw data against these schemas, ensuring that fields like IDs, references, and timestamps are correctly formatted and present before the data is used in the application.
openbank-admin-ui/src/lib/aml · high confidence
Add PID record validation and parsing logic
The admin UI now includes a new module (pidRecordContract.ts) that defines the structure for PID record evidence and provides a parser to validate incoming PID list responses. This parser ensures that the response is an array of valid objects with required fields like ID, person ID, and verification status, throwing errors for malformed data to prevent invalid records from being processed.
openbank-admin-ui/src/lib/pid · high confidence
Add clearing batch data validation and formatting utilities
The clearing module now includes a new contract file that defines strict TypeScript types and validation logic for clearing batch data. This introduces a parser that validates incoming batch records against specific enums for statuses (e.g., PENDING, SETTLED), payment rails (e.g., SEPA\_SCT, SWIFT), and settlement types, ensuring data integrity before processing. It also provides a utility to format monetary values using the user's locale, falling back to a standard numeric format if currency formatting fails, which improves the reliability of financial displays in the admin UI.
openbank-admin-ui/src/lib/clearing · high confidence
Add client-side validation for consent evidence data
The admin UI now validates incoming consent evidence records against a strict schema before processing them. This new \consentContract.ts\ module enforces that identifiers are valid UUIDs, statuses and grantee types match allowed enums, timestamps are valid dates with logical ordering, and scopes are non-empty arrays of recognized values. Invalid records are silently excluded from the parsed list while tracking the count of exclusions, ensuring that only well-formed consent data is presented to the user.
openbank-admin-ui/src/lib/consents · high confidence
Add currency-safe interest accrual parsing and validation
The admin UI now includes a dedicated module for parsing and validating interest accrual data, ensuring that currency codes are normalized to uppercase and that all input fields (such as dates, amounts, and enum statuses) are strictly validated before use. This prevents potential display or calculation errors caused by malformed or inconsistent backend responses by enforcing type safety and format checks at the ingestion layer.
openbank-admin-ui/src/lib/interest · high confidence
Add robust party data contracts and server-side search resolution
The admin UI now enforces strict validation on party-related API responses through new TypeScript contracts in \createdParty.ts\, \partyListContract.ts\, and \portfolioContract.ts\, ensuring that pagination, portfolio counts, and creation results are correctly parsed and verified. Additionally, \resolveParty.ts\ introduces a server-side lookup mechanism for KYC parties, replacing unreliable client-side filtering with direct queries to the party-service, while correctly handling feature-flagged search endpoints and distinguishing between 'no results' and 'search unavailable' states.
openbank-admin-ui/src/lib/party · high confidence
Add standing order data contract and validation logic
The standing-orders library now includes a dedicated contract module that defines the TypeScript types and validation rules for standing order data. This change introduces strict parsing for standing order responses, ensuring that fields like status, frequency, payment type, currency, and dates are validated against allowed values and formats before being used in the application. It also provides utility functions to format monetary amounts and local dates for display, improving data consistency and user experience when viewing standing orders.
openbank-admin-ui/src/lib/standing-orders · high confidence
Add strict validation for KYC evidence and party data contracts
The admin UI now enforces strict validation when processing KYC case and party evidence data. New contract files in the parties library define allowed sets for statuses, risk levels, check types, and party attributes, ensuring that only well-formed, expected data structures are accepted. This prevents invalid or malformed evidence from being processed, improving data integrity across operator views.
openbank-admin-ui/src/lib/parties · high confidence
Add strict validation for SDD mandate data structures
The SDD library now includes a new \sddMandateContract.ts\ module that enforces strict validation rules for SDD mandate data. This change introduces comprehensive parsing logic that validates mandate fields against specific formats, including UUIDs for IDs, IBAN checksums for debtor accounts, and RFC3339 timestamps. It also enforces business logic constraints, such as ensuring B2B mandates are correctly confirmed and preventing invalid status transitions, thereby improving data integrity when processing SEPA Direct Debit mandates.
openbank-admin-ui/src/lib/sdd · high confidence
Add strict validation for merchant catalogue API responses
Introduces a new contract module (\merchantCatalogueContract.ts\) that validates and parses merchant catalogue data from the backend. This change ensures that the UI correctly handles optional fields (such as \geoPrecision\, \category\, and \updatedAt\) by treating absent or null values as valid, preventing parser errors that could previously be mistaken for service outages. It also enforces strict type checking for required fields like \descriptorKey\ and \cleanName\, as well as validation for numeric coordinates and dates, improving reliability when displaying the full merchant catalogue.
openbank-admin-ui/src/lib/merchants · high confidence
Add strict validation for onboarding evidence and funnel analytics data
The onboarding module now includes robust client-side validation for onboarding evidence records and funnel analytics data. New parsers in \evidence.ts\ and \funnelAnalyticsContract.ts\ enforce strict type checking, ensuring that onboarding stages, KYC statuses, UUIDs, and timestamps match expected formats, and that funnel analytics steps, sign outcomes, and failure reasons are structurally valid. This prevents malformed or inconsistent data from being processed in the admin UI, improving data integrity for onboarding workflows and analytics reporting.
openbank-admin-ui/src/lib/onboarding · high confidence
Add strict validation for transaction search results
A new contract file introduces rigorous validation for transaction search data, ensuring that API responses are truthful and structurally correct. The implementation enforces strict type checking for transaction types and statuses, validates UUID formats for account IDs, and verifies RFC3339 timestamps. It also applies business logic checks, such as ensuring amounts are positive, currency codes are valid three-letter codes, and that transaction lifecycle states (like completed status) align with the presence of a completion timestamp. This prevents invalid or malformed data from reaching the UI layer.
openbank-admin-ui/src/lib/transactions · high confidence
Add validation for Customer 360 evidence data
A new validation function \parseCustomer360Evidence\ has been added to the Customer 360 library to enforce data integrity at the browser boundary. This function verifies that incoming evidence payloads match the expected structure, including checking for valid timestamps, non-negative counts, and correct types for domains, account IDs, and consents, ensuring that only well-formed data is processed by the UI.
openbank-admin-ui/src/lib/customer360 · high confidence
Add validation for fraud review evidence data
The admin UI now validates incoming fraud review evidence data before processing. A new contract module enforces strict type checking, ensuring that fields like scoreId, amount, currency, and verdict meet specific format and value requirements (e.g., valid UUIDs, positive numbers, ISO currency codes). This prevents invalid or malformed data from entering the fraud review workflow.
openbank-admin-ui/src/lib/fraud · high confidence
Audit evidence window limit and provenance validation
The audit UI now explicitly enforces a 500-entry limit for evidence retrieval, matching the backend's maximum return size, and rejects responses exceeding this window to prevent misleading counts. It also validates the provenance of audit entries, ensuring that time sources and service sources are recognized values, and verifies that returned entries belong to the requested aggregate.
openbank-admin-ui/src/lib/audit · high confidence
Centralized role constants, removal of inert masking annotation, and framework-free logging
This change introduces a canonical \Roles\ object with \const val\ constants for all platform roles (including new KYC maker-checker roles \ROLE\_KYC\_OPENER\ and \ROLE\_KYC\_REVIEWER\, and the M2M \ROLE\_API\), ensuring \@RolesAllowed\ annotations use verified realm role names instead of raw strings. It removes the inert \@MaskSensitive\ annotation, which previously claimed to trigger serialization filtering that was never implemented, thereby preventing silent PII disclosure. Additionally, \ServiceTokenProvider\ is updated to use JDK \System.Logger\ instead of JBoss Logging to keep the domain module framework-free, and the security module is moved into the new \openbank-libs-domain\ package with its license header standardized to Apache 2.0.
openbank-libs-domain/src/main/kotlin/com/openbank/libs/security · high confidence
Clarify serverless tier disclosure and update license
The ServerlessLegend component now includes an accessible explainer section (with proper aria-controls and id attributes) to clarify how services are assigned to tiers, specifically noting that new services default to the lowest tier their trigger allows and that always-on is opt-in. Additionally, the ServerlessTierBadge component has been updated to use CSS variables for colors, improving theme consistency, and the repository license has been changed from MPL-2.0 to Apache-2.0.
openbank-admin-ui/src/components/finops · high confidence
FX page adopts unified operator layout and fixes localization
The FX admin page now uses the shared OperatorLayout component, aligning its navigation and header with the rest of the operator workspace. Localization strings for day labels and time-to-next-run are now properly separated into Czech and English variants to prevent language toggle leakage. The page also displays the actual status of the fx-service (including scale-to-zero idle states) and removes the fabricated client-side history rows, relying instead on the dedicated FxTrendChart for trend data.
openbank-admin-ui/src/app/fx · high confidence
FX service integration: history endpoint, scale-to-zero awareness, and operator auth relay
The FX API area now includes a new history endpoint that fetches a three-month ČNB reference-mid trend for currency pairs, replacing the previous client-side snapshots with a real, deduplicated time series. The existing rates endpoint has been hardened to relay the operator's bearer token to the fx-service (fixing silent 401 failures), and it now detects the service's scale-to-zero state via service discovery to display a calm 'idle' status instead of a misleading 'down' error. Additionally, the refresh endpoint now enforces role-based access control, requiring the 'payments:view' permission.
openbank-admin-ui/src/app/api/fx · high confidence
FinOps allocation page: localized numbers, theme unification, and accessibility fixes
The FinOps cost allocation page now formats monetary amounts according to the user's locale (e.g., Czech vs. British English) instead of using a fixed format. The visual theme has been unified by replacing hardcoded hex color codes with semantic CSS variables (e.g., var(--success), var(--accent)), and the page header has been standardized using the shared PageHeader component. Additionally, accessibility has been improved by adding ARIA roles and labels to the loading state and refresh button, and the initial data load is now deferred to the next tick to prevent synchronous rendering issues.
openbank-admin-ui/src/app/finops/allocation · high confidence
Finops API routes now report query failures instead of masking them as empty data
The Finops resources and right-sizing API endpoints now distinguish between a genuinely empty fleet and a failure to read metrics from Prometheus. Previously, if Prometheus returned an error or timed out, the routes returned an empty services list, misleading users into thinking the fleet had no services. The changes introduce an \error\ field listing the specific failed queries and a \degraded\ boolean flag, ensuring the UI can accurately display data gaps rather than silent empty states.
openbank-admin-ui/src/app/api/finops/resources, openbank-admin-ui/src/app/api/finops/right-sizing · high confidence
Fix dispute portfolio data validation and API response handling
The dispute portfolio contract is now strictly validated to ensure data integrity. The new \disputePortfolio.ts\ library enforces that dispute records contain required fields with correct types (e.g., valid ISO dates, finite non-negative amounts, 3-letter currency codes) and that statuses are from the defined set. The API route (\route.ts\) now parses and validates the upstream dispute-service response, throwing specific errors for invalid payloads or status mismatches, and deduplicates disputes by ID to prevent inflated totals when concurrent status reads observe transitions. This ensures the admin UI only displays verified, consistent dispute data.
openbank-admin-ui/src/app/api/disputes, openbank-admin-ui/src/lib/disputes · high confidence
Fix outbox service tagging and add dead-letter monitoring
The outbox dispatch loop now correctly identifies the service name in metrics by stripping Quarkus Arc-generated subclass suffixes (e.g., \\_Subclass\) from the class name, preventing broken metric labels. A new gauge is introduced to monitor the count of terminal dead-lettered outbox rows, ensuring operators can detect services that are silently failing to process events. Additionally, the outbox entity model now includes a \synthetic\ flag to support durable hand-off scenarios.
openbank-libs-runtime/src/main/kotlin/com/openbank/libs/persistence · high confidence
Fix sanctions list errors by relaying operator authentication to the backend
Sanctions list pages no longer display 'Session expired' or 'Invalid JSON' errors when loading data. A new server-side helper (\upstream.ts\) ensures that all requests to the sanctions backend include the operator's bearer token, fixing the 401 Unauthorized responses that previously occurred because the token was omitted from the fetch calls.
openbank-admin-ui/src/lib/sanctions · high confidence
Fix stale state in command palette keyboard navigation
The ⌘K command palette no longer reads stale result lists or invalid selection indices during keyboard navigation. A previous race condition allowed key presses to occur before React had committed the latest render, causing ArrowDown to deselect all rows and Enter to navigate nowhere. The fix mirrors live state into refs via a layout effect and clamps navigation indices to ensure the UI and event handlers always reflect the current state.
openbank-admin-ui/src/components/search · high confidence
Fixes AuthorizeInterceptor deadlock and adds authorization telemetry
The AuthorizeInterceptor in the authz runtime module now prevents deadlocks on reactive endpoints by replacing blocking thread parking with proper coroutine suspension handling, ensuring four-eyes approval checks do not exhaust Vert.x event loops. Additionally, the interceptor now records every authorization decision via SecurityTelemetry, enabling accurate monitoring of the AUTHZ\_ENFORCE rollout, and supports dotted-path resource extraction in the @Authorize annotation for more flexible policy scoping.
openbank-libs-runtime/src/main/kotlin/com/openbank/libs/authz · high confidence
Fixes security scanner status reporting by relaying operator authentication
The security scanner API route now correctly relays the operator's bearer token when fetching reports, resolving previous 401 errors that incorrectly reported the scanner as unavailable. The route also introduces a new 'unauthorized' status reason to distinguish between scanner connectivity issues and authentication failures, ensuring users see accurate health states for the security scanning service.
openbank-admin-ui/src/app/api/security · high confidence
Focus trapping for modal dialogs
Added a new \trapDialogFocus\ utility in the accessibility library to keep keyboard navigation contained within modal dialogs. This ensures that when users press Tab or Shift+Tab, focus cycles only between visible, focusable elements inside the dialog rather than moving to elements outside, improving keyboard accessibility for modal interactions.
openbank-admin-ui/src/lib/a11y · high confidence
Identity case decision workflow and layout modernization
The identity-cases module now uses a unified OperatorLayout shell instead of a custom inline layout, standardizing the admin interface structure. The decision-making process for identity verification cases has been hardened with a single-flight mechanism to prevent duplicate mutations when an operator submits a vote or reopens a case. Additionally, the decision action is now presented via a dedicated review dialog, allowing operators to confirm their intent before submission. Visual styling has been updated to use semantic tone classes (e.g., danger, success) instead of hardcoded colors, and accessibility has been improved with proper ARIA labels on form controls.
openbank-admin-ui/src/app/identity-cases · high confidence
Improved Temporal status API reliability and metric accuracy
The Temporal status API now distinguishes between missing metrics and query failures, preventing Prometheus outages from incorrectly reporting that Temporal is not deployed. It also updates metric queries to use the correct Temporal server metric names (e.g., \temporal\_restarts\ instead of \temporal\_server\_start\_count\) and adds a new \workflowTypes\ metric to the response.
openbank-admin-ui/src/app/api/temporal · high confidence
Improved accessibility, localization, and upgrade feedback in the LifecycleStrip component
The LifecycleStrip component now uses semantic CSS variables for badge colors to ensure AA 4.5:1 contrast ratios on all backgrounds, including dark mode. Date formatting respects the user's locale via a new dateLocale prop. The upgrade action button now provides accessible feedback with aria-busy and aria-live regions, and displays clearer status messages (e.g., 'Drafting…', 'Try again') instead of generic icons or text.
openbank-admin-ui/src/components/infra · high confidence
Improved account detail page reliability, security, and accessibility
The account detail page now validates incoming data against a strict contract to prevent rendering unverifiable account information, and uses a sequence guard to prevent race conditions during loading. Lifecycle actions (freeze, unfreeze, close) are now guarded by specific permissions (accounts:freeze, accounts:close) and require a mandatory audit reason instead of using a browser prompt. The UI has been refactored to use a shared PageHeader component, and accessibility is improved with ARIA attributes on loading states and action buttons.
openbank-admin-ui/src/app/accounts/\[id\] · high confidence
Improved authentication resilience and localization in the admin UI
The admin UI now handles expired or invalid refresh tokens more gracefully by automatically re-authenticating users instead of displaying static 'Access denied' or 'Session expired' panels. A new ReauthOnExpiry component detects terminal session errors and triggers a fresh Keycloak sign-in, allowing the console to self-heal when an operator returns to an idle tab. Additionally, hardcoded Czech strings in the AuthGuard component have been replaced with localized translations, ensuring that messages like 'Verifying identity…' and 'Access denied' respect the user's language preference.
openbank-admin-ui/src/components/auth · high confidence
Improved event reliability and synthetic taint propagation in Kafka consumers
The messaging runtime now includes two new components to enhance system resilience and observability. First, EventRetry provides a bounded retry mechanism for event handlers that prevents transient failures (such as database unavailability) from being silently acknowledged; instead, it retries up to three times and rethrows on final failure, ensuring the platform can detect and handle the error rather than leaving data in an inconsistent state. Second, SyntheticTaintKafkaRail ensures that the 'synthetic' flag (used to distinguish test traffic from real customer data) is correctly propagated from Kafka message headers into both MDC logging context and OpenTelemetry baggage, allowing downstream services and observability tools to accurately identify synthetic events during Kafka-based processing.
openbank-libs-runtime/src/main/kotlin/com/openbank/libs/messaging · high confidence
Improved inventory data handling and UI consistency
The Tech Inventory page now uses a unified PageHeader component for consistent layout and breadcrumb navigation. Data fetching has been refactored to use a new evidence-based API, allowing the UI to gracefully display the last verified inventory when a refresh fails, rather than showing an empty state. Additionally, date formatting now respects the user's selected language locale, and accessibility improvements include proper ARIA labels and hidden attributes for icons.
openbank-admin-ui/src/app/system/inventory · high confidence
Improved reliability and safety for new party creation
The New Party page now prevents duplicate submissions via a client-side single-flight lock and ensures idempotency by reusing the same key on retries, while also validating the server response to confirm the party was actually created. The form layout has been updated to use a responsive CSS grid, and the page header is now rendered via a shared component with proper access control.
openbank-admin-ui/src/app/parties/new · high confidence
Improved trace error handling and UI modernization
The Trace Explorer page now distinguishes between empty results, server errors, and unreachable Tempo backends, preventing operators from mistaking a 502 error for an empty trace. It also replaces the custom page header with a standardized PageHeader component and adds an ExplorerGuide to help users interpret trace waterfalls.
openbank-admin-ui/src/app/observability/traces · high confidence
Interest console: unified layout, dedicated permission, and resilient data handling
The Interest console now uses the shared OperatorLayout for consistent navigation and requires the specific 'interest:view' permission instead of the generic 'payments:view'. The page implements a robust data-fetching strategy that preserves the last successful snapshot when the interest-service is unavailable or returns an error, displaying a warning banner with the timestamp of the last valid load. It also correctly handles multi-currency scenarios by preventing invalid summation of accrued amounts across different currencies and provides clear access-denied messaging for unauthorized roles.
openbank-admin-ui/src/app/interest · high confidence
Introduce strict security data contracts and validation helpers
The admin UI now enforces rigorous validation for security-related data through new TypeScript contracts and parsing utilities. Content Security Policy generation is refined to restrict 'unsafe-eval' to development mode only, improving runtime security posture. Incident management data (ICT and general incidents) is validated against strict schemas, including support for UUIDv7 identifiers and precise status/severity tracking. Security KPIs (network policies, credentials, fuzzing, threat models, MTTR) are parsed with cross-field consistency checks to prevent contradictory metrics. Security scan results are validated to ensure unreachable services do not incorrectly lower the platform score, and all external URLs (such as pull requests) are strictly validated to prevent injection risks.
openbank-admin-ui/src/lib/security · high confidence
Introduce strict validation contracts for account details, opening, and party selection
This change adds three new TypeScript modules in the accounts library to enforce data integrity and security for account operations. \detailContract.ts\ validates account detail and balance payloads against strict type and format rules, ensuring only well-formed data reaches the UI. \openingContract.ts\ introduces a robust contract for parsing product catalogs and verifying account opening responses, including validation of UUIDs, currency codes, timestamps, and HTTPS terms URLs, while explicitly checking that the opened account matches the operator's request to prevent mismatched redirects. \partySelection.ts\ provides a helper to align sanctions screening data with the selected party, ensuring legal or trading names are correctly trimmed and populated.
openbank-admin-ui/src/lib/accounts · high confidence
Introduce strict validation for payment evidence and list data
The admin UI now enforces strict parsing and validation for payment-related data to prevent display of incomplete or malformed information. New modules in the payments library validate payment detail evidence (including UUID format, currency codes, and rail-specific fields like IBANs for SEPA or account numbers for domestic transfers), verify payment list items against a defined contract, and parse VOP (Verification of Payment) evidence with specific rules for verdicts and matched names. Additionally, a query helper now explicitly whitelists allowed filter parameters (status, debtorAccountId, limit, offset) when constructing payment list queries, ensuring only supported filters are forwarded.
openbank-admin-ui/src/lib/payments · high confidence
Kafka topic data now sourced from generated snapshot instead of hardcoded array
The Admin UI now retrieves Kafka topic information from a generated \events.json\ snapshot rather than a manually maintained TypeScript array. This change ensures the displayed topic list (including names, publishers, and consumers) accurately reflects the AsyncAPI documentation and service configurations, resolving previous discrepancies where many topic names were incorrect. The data is served via a new API route that reads the pre-built snapshot at build time, ensuring consistency and reducing maintenance drift.
openbank-admin-ui/src/app/api/events · high confidence
Karpenter IAM policy fixes and AWS provider upgrade
The Karpenter controller's IAM policy is updated to resolve permission errors that were preventing instance status health checks and garbage collection of instance profiles. Specifically, the policy now includes \ec2:DescribeCapacityReservations\, \ec2:DescribeInstanceStatus\, and \ec2:DescribePlacementGroups\ to support regional read actions, and adds \iam:ListInstanceProfiles\ to allow the garbage collection controller to function without 403 errors. Additionally, the underlying Terraform AWS provider is upgraded from version 5.80 to 6.53.
openbank-infra/aws/modules/karpenter-iam · high confidence
Ledger page refactored with pagination, accessibility, and operational insights
The General Ledger page now supports paginated journal entry loading (20 entries per page) with a 'Load more' mechanism that preserves previously fetched data even if subsequent requests fail. The layout has been unified with the operator shell, and the page includes contextual operational insights for users with system view permissions. Date inputs are now properly labeled for accessibility, and the entire view is protected by an AuthGuard requiring 'accounts:view' permission.
openbank-admin-ui/src/app/ledger · high confidence
License update and code formatting in idempotency configuration
The idempotency configuration file has been updated to reflect the platform's license change from MPL-2.0 to Apache-2.0. Additionally, minor formatting adjustments were applied to the idempotency store bean definition to resolve linting violations.
openbank-account-service/src/main/kotlin/com/openbank/account/infrastructure/idempotency · high confidence
Modernize agent page UI and improve error handling
The System Agent page now uses a dedicated PageHeader component for a cleaner layout and applies consistent accent-text color variables for better visual hierarchy. Error handling has been refined to distinguish between specific failure states (such as unreachable services or authentication issues) rather than showing generic errors, and a 'Try again' button is now provided in the DataUnavailable state to allow users to retry failed operations. Additionally, the page is protected by an AuthGuard requiring the 'agent:view' permission, and the license header has been updated to Apache-2.0.
openbank-admin-ui/src/app/system/agent · high confidence
Onboarding UI layout consolidation and funnel data accuracy fixes
The onboarding section now uses the unified OperatorLayout shell instead of a custom local layout, ensuring consistent navigation and styling across the admin interface. Additionally, the onboarding funnel KPIs no longer display fabricated zeros while data is loading or if the request fails; the counts remain null until a valid response is received, preventing misleading empty-state visuals. The page also imports shared parsing utilities for funnel counts and records, and adds a TrendingUp icon to the header.
openbank-admin-ui/src/app/onboarding · high confidence
Outbox dispatcher refactoring and license update
The AccountOutboxDispatcher now accepts DomainMetrics via constructor injection instead of relying on the parent class's default metrics, ensuring consistent observability. Additionally, the license header in this package has been updated from MPL-2.0 to Apache-2.0.
openbank-account-service/src/main/kotlin/com/openbank/account/infrastructure/outbox · high confidence
Outbox persistence domain refactored and hardened with atomic claims and correct timestamps
The outbox persistence logic has been moved into the \openbank-libs-domain\ module and significantly improved to ensure reliability in multi-pod deployments. Timestamps for outbox events now default to the current time instead of the 1970 epoch, preventing starvation of real traffic by stale records. The system introduces atomic row claiming via \FOR UPDATE SKIP LOCKED\ to safely handle concurrent dispatchers during rolling updates, and implements an exponential backoff strategy for failed messages to reduce unnecessary retry load. Additionally, synthetic event taint is now persisted and propagated to Kafka headers for proper tracking.
openbank-libs-domain/src/main/kotlin/com/openbank/libs/persistence · high confidence
PID page layout, status handling, and sync reliability improvements
The PID management page now uses the unified OperatorLayout shell and Apache-2.0 license headers. Status badges for PID records use a dedicated tone mapping (EXPIRED as warning, REVOKED as danger) distinct from generic consent defaults. The record list fetch includes race-condition protection via load generation counters to prevent stale state updates, and clarifies that a 404 response indicates an unavailable capability rather than an empty list. The quick-create flow now supports BankID sync with a pending payload checkpoint to ensure idempotent party creation, and validates required fields only when not resuming a checkpoint.
openbank-admin-ui/src/app/pid · high confidence
Prevents duplicate mutation submissions via single-flight and idempotency keys
The admin UI now includes a new \singleFlight\ module that prevents mutations from firing twice. It uses a synchronous lock to block re-entry during the same event loop (fixing race conditions where UI state updates are too slow) and generates stable idempotency keys based on payload content to ensure that network retries do not create duplicate operations on the server.
openbank-admin-ui/src/lib/mutations · high confidence
Prod-readiness API now reports 'NOT-DEPLOYED' status and updates license
The production readiness check API in the admin UI now includes a 'NOT-DEPLOYED' state in its gate response, allowing the system to explicitly distinguish between undeployed components and other readiness failures. Additionally, the file's license header has been updated from MPL-2.0 to Apache-2.0 to reflect the platform's relicensing.
openbank-admin-ui/src/app/api/prod-readiness · high confidence
Production readiness page preserves report on failure and distinguishes undeployed services
The Production Readiness page now handles API failures gracefully by preserving the last successfully loaded report and displaying a warning with a retry option, rather than clearing the data. It also introduces a distinct 'Not deployed' status for services that are not yet in production, separating them from 'NO-GO' (not ready) services. Additionally, the page's visual styling has been updated to use the new shared UI component library and themeable tone system.
openbank-admin-ui/src/app/system/readiness · high confidence
Refactor infrastructure status probes into shared library and update license
The infrastructure status API routes in the admin UI have been refactored to move probe definitions and logic into a shared library (\@/lib/infra/probes\), resolving Webpack bundling issues that previously prevented client source maps from being emitted. This change also updates the file headers from the MPL-2.0 to the Apache-2.0 license, reflecting the platform's broader relicensing. Additionally, a minor type correction in the lifecycle route ensures the \versionSource\ variable is correctly scoped when determining the source of a component's version.
openbank-admin-ui/src/app/api/infra · high confidence
Repair broken gateway documentation diagrams and clarify SLO targets
This change fixes the openbank-api-gateway documentation by repairing seven Mermaid diagrams that previously failed to parse, specifically adding or correcting the gateway routing flow, logical configuration model, and request lifecycle diagrams to accurately reflect the Kong OSS 3.7.1 passthrough behavior. Additionally, the operations documentation for both English and Czech locales has been updated to explicitly state that the listed Service Level Objectives (SLOs) are design targets for production-shaped deployments and are not guaranteed or measured in the single-node sandbox environment.
openbank-api-gateway · high confidence
Security page adopts operator layout and fixes false-positive reporting for unreachable services
The Security page now uses the unified OperatorLayout component, replacing the previous custom sidebar/header structure. The page logic has been refactored to use a shared security summary library, which corrects a false-positive issue where unreachable services were incorrectly dragging down the platform score and grade; the headline metrics now reflect only reachable services, while unreachable ones are surfaced separately as a coverage gap. Additionally, the data-fetching mechanism was hardened with request cancellation and abort controllers to prevent stale state updates, and date formatting now correctly respects the user's selected language.
openbank-admin-ui/src/app/security · high confidence
Service Configuration page: improved accessibility, localization, and error resilience
The Service Configuration page now handles API failures gracefully by catching fetch errors to prevent unhandled promise rejections and preserving the last known-good state. Refresh timestamps are localized using the user's selected language locale. The UI has been modernized by replacing the inline header with a shared PageHeader component and migrating all hardcoded color values to semantic CSS variables (e.g., success, warning, danger, accent) for consistent theming. Accessibility is improved with proper ARIA attributes (expanded, controls, busy, hidden) and semantic roles on interactive elements.
openbank-admin-ui/src/app/system/config · high confidence
Standardized error responses and corrected HTTP status codes across the API
This change introduces fleet-wide exception mappers and input guards in the runtime library to ensure consistent, client-friendly error handling. Authentication failures (401) now return the standard JSON error envelope instead of plain text. Several error conditions that previously returned 500 Internal Server Error are now correctly mapped to 4xx client errors: invalid dates (400), missing or null request bodies (400), and database persistence or decoding failures (400). Additionally, a new guard rejects JSON strings containing NUL characters with a 400 error, preventing database storage failures. The system also correctly maps Policy Decision Point outages to 503 Service Unavailable and ensures error timestamps reflect the actual time of the error rather than the Unix epoch.
openbank-libs-runtime/src/main/kotlin/com/openbank/libs/api · high confidence
Standing orders page adopts unified layout and handles scale-to-zero gracefully
The standing orders interface now uses the shared OperatorLayout for consistent navigation and styling. The page handles the standing-order-service being scaled to zero by routing requests through the BFF proxy and displaying a calm 'idle, waking…' status instead of an error. The summary cards now include 'Paused', 'Needs attention', and 'Completed' statuses, and the search filters remittance info and creditor IBANs. The page also announces loading states for accessibility.
openbank-admin-ui/src/app/standing-orders · high confidence
Strict validation for closing cockpit evidence
The closing cockpit now enforces strict validation on evidence data, ensuring that reconciliation reports, close runs, and failure records conform to expected schemas (e.g., valid UUIDs, ISO dates, and currency codes) before being processed. This prevents malformed or unexpected data from causing issues in the UI, improving reliability when viewing closing status and reconciliation details.
openbank-admin-ui/src/lib/closings · high confidence
Synchronize document language with server-side rendering
The admin UI now ensures that the HTML document's language attribute matches the user's selected language (English or Czech) immediately, preventing a mismatch between the visible text and the document metadata during hydration. This change introduces a new language configuration module and updates the language provider to prioritize server-side cookie preferences, migrating legacy localStorage settings and triggering server content refreshes to keep server-rendered documentation pages in sync with the client's language choice.
openbank-admin-ui/src/lib/i18n · high confidence
TPP registry outbox now emits lifecycle events and reads are no longer broken
The TPP registry now correctly writes TPP\_REGISTERED and TPP\_BLACKLISTED events to the outbox when a provider is registered or blacklisted, enabling downstream consumers to receive these lifecycle updates. Additionally, the service fixes a bug where reading registered TPPs failed due to a mismatch between the database's BIGSERIAL primary key and the domain's UUID requirement, ensuring the eIDAS licence gate can now authorize requests for existing providers.
openbank-tpp-registry-service · high confidence
Validate Tempo trace evidence data
The observability module now validates incoming Tempo trace data before processing it. A new file, tempo-evidence.ts, introduces strict parsing logic for trace summaries and flat spans, ensuring that fields like trace IDs, service names, and timestamps conform to expected formats and constraints. This prevents malformed or unexpected data from causing issues downstream in the UI.
openbank-admin-ui/src/lib/observability · high confidence
Validate audience preview data integrity
The admin UI now strictly validates audience preview responses before processing them. A new utility function checks that the data is a valid record with an expected state (ok, unauthorized, unknown\_segment, or unreachable), verifies the audience name and version match expectations, and ensures the size is a non-negative integer and the timestamp is valid. This prevents malformed or mismatched data from causing errors downstream.
openbank-admin-ui/src/lib/audiences · high confidence
Test coverage
Added JMH benchmarks and allocation baselines for shared libraries; Added and migrated unit tests for domain and runtime libraries; Added contract and accessibility tests for the account detail and lifecycle pages; Added contract binding tests for the generated product-catalog client; Added contract tests and test doubles for the ApprovalStore library; Added domain tests for IBAN validation, accounting calendar, and feature logic; Added k6 read-baseline performance tests for account service; Added test coverage for lending decision, amortization, APRC, and compliance logic; Added tests for ISO 20022 payment builders, readers, and XML validation; Added tests for JVM warmup readiness gate and resource type analysis; Added tests for LLM content safety and metrics provider logic; Added tests for LLM gateway client, content safety, trace correlation, and embedding adapters; Added tests for PolicyDecisionPoint contract and DenyAllPolicyDecisionPoint behavior; Added tests for RequestFingerprint idempotency logic; Added tests for SyntheticTaint validation logic; Added tests for Temporal client laziness and Kotlin data class serialization; Added tests for XML external entity protection; Added tests for audit chain integrity, event construction, and decision record invariants; Added tests for audit event and flag exposure timestamp recency; Added tests for audit event publishing and hash-linked outbox integrity; Added tests for authorization interceptor, feature flags, and policy decision points; Added tests for contact arbitration and policy gate logic; Added tests for domain ID converters and Money JSON serialization; Added tests for event retry logic and Kafka synthetic taint propagation; Added tests for fleet-wide API error handling and input validation guards; Added tests for gamification boundary and marketing wiring detekt rules; Added tests for idempotency request fingerprinting and Redis store behavior; Added tests for observability primitives in libs-runtime; Added tests for security domain components; Added tests for security primitives in the runtime library; Added tests for testing-library utilities and conformance kits; Added tests to validate the analytics topic-to-producer mapping; Added unit tests for AbstractOutboxDispatcher; Added unit tests for BuildInfo fallbacks and hex rendering utilities; Added unit tests for account service lifecycle and authorization logic; Added unit tests for approval contract and observability metrics; Added unit tests for persistence domain logic; Added unit tests for the ReasoningGraph execution engine; Added unit tests for web filters and resources in openbank-libs-runtime; Expanded end-to-end test coverage for Admin UI workflows; New shared test utilities and conformance kits in openbank-libs-testing; Removed Temporal smoke tests for bootstrap components; Removed test suite for openbank-libs; Removed tests for the saga state machine; Removed unit tests for AuthorizeInterceptor; Stabilized E2E authentication and shell readiness helpers.
Dependencies
Add OSS-Fuzz harness and agent-review dependency scaffolding
This change introduces build scaffolding for two new areas: an OSS-Fuzz integration module (fuzz/ossfuzz) that bundles the libs-domain classes with the Jazzer fuzzer API for security fuzzing, and a pinned npm dependency for the agent-review workflow (agent-review-claude-cli) to ensure reproducible installs of the Claude Code CLI. It also adds a Gradle init script to enable targeted mutation testing on the authz module and defines the initial build configurations for several new services (AP2, authz-policy-auditor, billing, campaign) including their Quarkus dependencies, persistence layers, and coverage floors.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 68 → 63 (-5.3)
- Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.
Lenses
- Code Health 77 → 72 (-4.7)
- Architecture 81 → 78 (-2.5)
- Maturity 89 → 91 (+2.3)
- Readiness 67 → 57 (-10.2)
- Security 68 → 62 (-5.4)
- Domain Modelling 77 (new)
- Accessibility 65 → 71 (+6.0)
- Performance 70 (new)
Resolved (62)
- Context and trade-offs are absent (only a summary + amendment list appears) (docs/adr/0077-observability-three-pillar-strategy.md)
- Coverage not measured — JavaScript/TypeScript suite
- Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
- Documentation: hard to navigate (openbank-infra/web/landing/README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no installation or build instructions (openbank-infra/aws/README.md)
- Documentation: no usage examples (README.md)
- Documentation: no usage examples (openbank-infra/aws/README.md)
- High CVE: [GHSA redacted] (gradle/verification-metadata.xml)
- High vulnerability: [GHSA redacted] (gradle/verification-metadata.xml)
- High vulnerability: [GHSA redacted] (gradle/verification-metadata.xml)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Low IaC: AWS-0089 (openbank-infra/aws/modules/static-site/main.tf)
- …and 42 more
New (3033)
- (anonymous) (cognitive 17) (openbank-infra/web/landing/main.js)
- ADR lacks an enforcement field (docs/adr/0001-record-architecture-decisions.md)
- ADR lacks an enforcement field (docs/adr/0002-hexagonal-architecture-per-service.md)
- ADR lacks an enforcement field (docs/adr/0003-transactional-outbox-for-kafka.md)
- ADR lacks an enforcement field (docs/adr/0004-saga-for-multi-service-workflows.md)
- ADR lacks an enforcement field (docs/adr/0005-openapi-design-first.md)
- ADR lacks an enforcement field (docs/adr/0006-asyncapi-for-kafka-topics.md)
- ADR lacks an enforcement field (docs/adr/0007-vault-for-secrets-management.md)
- ADR lacks an enforcement field (docs/adr/0008-opentelemetry-for-observability.md)
- ADR lacks an enforcement field (docs/adr/0009-postgres-per-service.md)
- ADR lacks an enforcement field (docs/adr/0010-kubernetes-argocd-gitops.md)
- ADR lacks an enforcement field (docs/adr/0011-testing-pyramid.md)
- ADR lacks an enforcement field (docs/adr/0012-mpl-license-and-dco.md)
- ADR lacks an enforcement field (docs/adr/0013-shared-outbox-in-openbank-libs.md)
- ADR lacks an enforcement field (docs/adr/0014-openbank-libs-centralization-roadmap.md)
- ADR lacks an enforcement field (docs/adr/0016-virtual-threads-not-adopted-yet.md)
- ADR lacks an enforcement field (docs/adr/0017-secrets-via-vault.md)
- ADR lacks an enforcement field (docs/adr/0018-opa-for-fine-grained-authz.md)
- ADR lacks an enforcement field (docs/adr/0019-docs-as-service.md)
- ADR lacks an enforcement field (docs/adr/0020-code-coverage-kover-regression-floor.md)
- …and 3013 more
Changes since last survey
- 300 commits — 254 feature/other, 46 fixes
By area
- openbank-infra/gitops — 109 commits
- (root) — 29 commits
- .github/scripts — 22 commits
- .github/workflows — 8 commits
- docs/adr — 7 commits
- openbank-admin-ui/src — 7 commits
- openbank-card-processing-service/src — 7 commits
- (repo) — 6 commits
- openbank-infra/web — 6 commits
- openbank-libs-runtime/src — 6 commits
- openbank-risk-engine/src — 6 commits
- .github/gates — 5 commits
- openbank-treasury-service/src — 5 commits
- openbank-clearing-service/src — 4 commits
- openbank-customer-edge/src — 4 commits
- openbank-infra/aws — 4 commits
- openbank-infra/docker — 4 commits
- openbank-admin-ui/app-status.json — 3 commits
- openbank-admin-ui/package-lock.json — 3 commits
- openbank-audit-service/src — 3 commits
Notable commits
- fix: fix(admin-ui): restore approval source routing and notification Redis (#12082)
- fix: fix(approval): preserve verified maker actor kind (#12159)
- fix: fix(audit): durable ingestion, serialized chain appends, complete checkpoint verification (#10041 slice 8b) (#11897)
- fix: fix(card-processing): apply each clearing once per key (#11990)
- fix: fix(card-processing): never mint a simulated token reference with a digit run (#12109)
- fix: fix(card-processing): require idempotency keys on token status and dispute refresh (#12031)
- fix: fix(card-processing): send fraud-service its real scoring contract, and pin both money-path pacts (#12073)
- fix: fix(ci): cover admission in service aggregate test (#12164)
- fix: fix(ci): rotate the reconcile cap so gate-blocked strands cannot starve the rest (#11834)
- fix: fix(clearing): clear each rail's own items and fit every cycle id (#12035)
- fix: fix(clearing): net and settle each currency in its own batch (#12003)
- fix: fix(context): delay commitment relays past boot and stop timing out backups (#12019)
- fix: fix(context): take the build-facts commit from an explicit input (#12099)
- fix: fix(docs): keep every runnable service documentation current (#11989)
- fix: fix(domestic-payment): build kernel Money at the inbound boundary (#12060)
- fix: fix(domestic-payment): report an unrecognised fraud verdict as UNKNOWN, not ALLOW (#11614)
- fix: fix(infra): admit large nodes in the stateful pool now that DB requests cover usage (#11830)
- fix: fix(infra): give Langfuse 3.225 web and worker enough Node heap (#12063)
- fix: fix(infra): honor disabled Config recording in self-heal (#11743)
- fix: fix(infra): make cloud-finops retries real and ship reaper logs (#12023)
- …and 280 more
Architecture
- 0 containers · 76 bounded contexts · 144 dependency edges (baseline)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
JiRaska/open-bank-oss was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 8 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 34d475f8d3b495ea5dc70ab0daebb715834de3d2 — the exact code this score is about.
- Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-bbd7b4f07d52.