Stack roadmap158 open issues across the stack, by themeThe board on GitHub ↗
Now10 · what's being worked on now
Next18 · lined up after that
RepositoryIssueKindEffort
build & packaging5
🦡 vermilingua #49 Detect resource name conflicts during component flattening bug S
🦡 vermilingua #50 Non-clean rebuilds leave deleted/renamed resources in the .woa bug S
🦡 vermilingua #51 Write a file to the WOA containing some info about the build feature S
🦡 vermilingua #53 Rename deploy.monitorHost to deploy.monitorUrl cleanup S
🦡 vermilingua #54 Context-dependent build products — skip flags for archives/split, and a configuration review feature M
docs4
🌿 parsley #15 Write syntax documentation docs M
🤖 modulo #11 Configuration reference: every parameter, exactly what it does, with examples docs M
🦡 vermilingua #55 Document build.properties, and reconsider it as a single home for unrelated concerns docs M
🔌 wo-adaptor-jetty #5 Clean up and document configuration parameters and the public API docs S
KVC2
🚀 ng-objects #20 Ensure KVC skips over inaccessible members and goes on to the accessible one cleanup S
🚀 ng-objects #36 Add support for maps in KVC feature S
HTTP & requests2
🚀 ng-objects #66 NGRequest: parse the body lazily (raw body + on-demand form values), not eagerly at the adaptor security M
🤸‍♀️ wonder-slim #168 Resources: a dedicated marker for the stamp in resource URLs cleanup S
templates & diagnostics2
🌿 parsley #7 Show a list of errors within the page at the top of the page feature S
🌿 parsley #17 Include template name in exception messages feature S
front-end trust & admin1
🤖 modulo #8 Per-Site security response headers (HSTS, and friends) security S
convergence & architecture1
🤸‍♀️ wonder-slim #42 Rework ERXKVCReflectionHack before the JDK removes Unsafe.putObject cleanup M
deployment stack1
⚙️️ wonder-slim-deployment #12 Replace FileBrowser EVIL_HACK with proper XML encoding declaration bug S
Waiting on a decision17 · can't move until a call is made
RepositoryIssueKindEffort
build & packaging3
🦡 vermilingua #41 Make build.properties redundant decision M
🦡 vermilingua #52 launch.origin: assert that the app runs from a packaged bundle, let the framework decide the deployment mode decision M
🔌 wo-adaptor-jetty #3 Pick a package name instead of com.webobjects decision S
front-end trust & admin3
🔌 wo-adaptor-jetty #4 Honor WOHost for socket binding, drop the host FIXMEs decision S
🤸‍♀️ wonder-slim #39 ERXMonitorServer: bind address, transport and port, decided with the deployment stack decision S
🤸‍♀️ wonder-slim #54 ERControl: clear up and document access controls decision M
deployment stack3
⚙️️ wonder-slim-deployment #31 Remove the unknown-applications tracking mechanism decision S
⚙️️ wonder-slim-deployment #51 Name the source of truth: JavaMonitor's co-located wotaskd is the authority decision M
⚙️️ wonder-slim-deployment #53 Deployment: builds directory and rollout strategies (upload ≠ activate) decision L
sessions & state2
🚀 ng-objects #58 Decide on CSRF protection strategy decision M
🤸‍♀️ wonder-slim #90 Direct action and route requests restore the session they carry, even when nothing uses it decision M
routing & URLs2
🤖 modulo #15 Route to an application by path prefix within a site, as well as by hostname decision M
⚙️️ wonder-slim-deployment #24 First-class domain configuration on MApplication, surfaced through wotaskd to modulo decision M
logging & config1
🚀 ng-objects #72 Logging configuration shared with wonder-slim: ng-logging and ng-logging-logback decision M
KVC1
🌿 parsley #18 Keypath resolution and Optional: rethink null-safety vs Optional unwrapping decision M
Ajax1
🤸‍♀️ wonder-slim #36 Delete the classic Ajax module (superseded by AjaxSlim) decision L
observability1
⚙️️ wonder-slim-deployment #56 Application type identification: instance self-description, wotaskd-mediated decision M
The notebook113 · ideas and design notes, kept on file
RepositoryIssueKindEffort
deployment stack27
🚀 ng-objects #55 Proper wotaskd integration: complete WOMPRequestHandler and align with the WO admin protocol feature M
🤖 modulo #5 Per-Site error pages (replacing Jetty defaults) feature M
🤖 modulo #6 Unify plain and front-end startup into a single handler pipeline cleanup M
🤖 modulo #13 A site's identity and storage shouldn't hang off its first hostname design note M
🔌 wo-adaptor-jetty #7 One Jetty server for the adaptors and modulo; adaptors become handlers design note L
⚙️️ wonder-slim-deployment #2 Replace SpawnOfWotaskd.sh wrapper with ProcessBuilder cleanup S
⚙️️ wonder-slim-deployment #8 Pull non-model concerns (HTTP, error reporting, runtime control) out of model classes cleanup M
⚙️️ wonder-slim-deployment #9 Test calculateNextScheduledShutdown for day-of-week / off-by-one bugs after java.time migration cleanup S
⚙️️ wonder-slim-deployment #10 Implement actual force-quit (current button is misleadingly named) feature M
⚙️️ wonder-slim-deployment #11 Spawn WOApps directly from wotaskd (replace launch script) feature M
⚙️️ wonder-slim-deployment #14 Content-addressed artifact store for deployments (rsync-equivalent over web services) design note L
⚙️️ wonder-slim-deployment #17 Replace 30s passive wait on wotaskd startup with active liveness probe bug S
⚙️️ wonder-slim-deployment #18 Replace 'archive on sleep() if dirty' pattern with explicit transactional persistence design note M
⚙️️ wonder-slim-deployment #20 Remove MulticastListener and the UDP discovery/version-probe paths cleanup S
⚙️️ wonder-slim-deployment #23 Extract instance-lifecycle operations from ApplicationsPage; delete AdminApplicationsPage bridge cleanup M
⚙️️ wonder-slim-deployment #25 Store deployment configuration in a git repository (audit trail, atomicity, replication, rollback) design note L
⚙️️ wonder-slim-deployment #27 Sweep: replace String/int constant fields with enums (osType, schedulingType, scheduler, instance state, …) cleanup S
⚙️️ wonder-slim-deployment #28 Separate isRunning_W into a state-machine tick and a pure predicate cleanup M
⚙️️ wonder-slim-deployment #34 Define and enforce authority across JavaMonitor / wotaskd / instances design note L
⚙️️ wonder-slim-deployment #38 Bundled distribution: ship wotaskd + JavaMonitor + modulo as a single platform package design note L
⚙️️ wonder-slim-deployment #39 Pluggable provisioner abstraction: add hosts via Hetzner, Linode, Docker, Kubernetes, bare-metal SSH design note L
⚙️️ wonder-slim-deployment #44 Replace wotaskd's HTTP layer with a more targeted server abstraction design note L
⚙️️ wonder-slim-deployment #46 Eliminate DNS as a runtime dependency in the platform's address-handling code cleanup M
⚙️️ wonder-slim-deployment #47 Allow expansion from single-host (localhost) deployment without manual instance reconfiguration feature M
⚙️️ wonder-slim-deployment #48 Multi-config support in JavaMonitor: manage multiple separate deployments from one operator surface design note L
⚙️️ wonder-slim-deployment #50 Take wotaskd off the shared mutable M-class model and onto the DTO tree directly cleanup L
⚙️️ wonder-slim-deployment #52 Collapse MHost.osType and the per-platform path fields on MApplication cleanup M
templates & diagnostics15
🚀 ng-objects #27 Add component binding synchronization design note M
🚀 ng-objects #28 Template validation feature M
🚀 ng-objects #33 Component actions design note M
🚀 ng-objects #60 Compile templates to Java classes design note L
🚀 ng-objects #61 Enrich exceptions thrown during rendering with positional context feature M
🚀 ng-objects #63 Tag-alias resolution is global at runtime — a framework's templates should resolve tags in their own context, not the application's design note M
🚀 ng-objects #64 Parser: record a SourceRange per binding (not just per element) feature S
🌿 parsley #12 Rewrite declaration parser cleanup M
🌿 parsley #13 Custom error pages (for display of stuff like template parser errors) feature M
🌿 parsley #16 Support namespaced element types in WOD files feature S
🌿 parsley #20 Exception disposition registry (inline vs full-page + per-type templates) design note M
🌿 parsley #23 Switch components bypass tag-alias resolution (runtime dynamicElementWithName) bug S
🦡 vermilingua #42 Build-time validation of WebObjects templates design note L
🤸‍♀️ wonder-slim #46 Production exception policy (designed alongside ng-objects) design note M
🤸‍♀️ wonder-slim #95 ERXStyleSheet: render as a plain <link> tag, where it's written cleanup S
element API10
🧩 apiext-format #4 Value sets — allowed values for a binding (literal enums and dynamic sources) design note L
🧩 apiext-format #7 Component reusability (can it be used as a tag?) design note S
🧩 apiext-format #8 Element/component use scope (access control / visibility) design note M
🧩 apiext-format #10 Declare the primary HTML element an element renders as design note M
🧩 apiext-format #11 Root <wo class> uses the simple class name (Obj-C relic) — reconcile with FQN class references cleanup M
🧩 apiext-format #20 Structured replacement pointer on <deprecated> (use="...") design note S
🧩 apiext-format #21 Severity on <deprecated> (let a deprecation escalate to an error) design note S
🧩 apiext-format #24 Enclosing-context requirement (element must sit inside a form) design note S
🧩 apiext-format #25 Prefix-family bindings (declare a family of bindings by prefix, e.g. ?key query params) design note M
🧩 apiext-format #26 Generated-from-source authoring mode (annotations + javadoc → .apiext); the file stays canonical design note L
routing & URLs9
🚀 ng-objects #16 allow hierarchical route tables feature M
🚀 ng-objects #17 Add support for route parameters feature M
🚀 ng-objects #18 Standardize behaviour for trailing slashes in routes bug S
🚀 ng-objects #19 Allow adding comments/docs on routes docs S
🔌 wo-adaptor-jetty #8 Forward 404 responses to the next handler by configuration, replacing the unhandled-response marker design note M
🤸‍♀️ wonder-slim #51 Base path: serve an application beneath a public path of its own feature M
🤸‍♀️ wonder-slim #59 Routing: host-based routes (one application, several hostnames) feature M
🤸‍♀️ wonder-slim #167 Routing: more outcomes for a route handler (NOT_FOUND, PASS_ON) design note M
⚙️️ wonder-slim-deployment #37 Group filtering on woconfig (let each web server see only the apps it should serve) feature S
IDE9
🚀 ng-objects #62 Headless rendering CLI and snapshot-test pattern feature M
🚀 ng-objects #65 Headless action driving: render a page, list its actions, invoke one (dev endpoint) feature M
🚀 ng-objects #69 Development mode: read resources from src/main/resources on disk, not the classpath output folder feature M
🌿 parsley #26 Heat map: make static template text locatable (click text → its exact spot in the template) feature M
🌿 parsley #27 Heat map: delete the legacy comment-marker machinery cleanup S
🌿 parsley #29 Agent-readable render profile: the heat map's data as JSON (per-binding timings + attributed queries) feature L
💋 parslips #2 Make syntax color defaults theme-aware (light vs. dark mode) feature M
💋 parslips #8 Reuse Eclipse/WTP's JS/CSS support for inline <script>/<style> blocks in templates design note L
💋 parslips #9 Element visibility: hide non-reusable and out-of-scope elements from completion and the Element Reference feature M
logging & config7
🚀 ng-objects #1 NGProperties should keep track of where properties originate from feature S
🤸‍♀️ wonder-slim #143 Configuration: rework how properties are loaded and read (bringing NGProperties' model along) design note L
🤸‍♀️ wonder-slim #152 Logging patterns: what reload4j's layout writes that logback and the console logger can't design note M
🤸‍♀️ wonder-slim #153 Share the logging configuration with ng-objects feature M
🤸‍♀️ wonder-slim #160 Deployment modes and configuration sets design note L
⚙️️ wonder-slim-deployment #42 Multi-environment support: per-app overlays for managing dev/staging/production from one SiteConfig design note L
⚙️️ wonder-slim-deployment #57 JavaMonitor: remove log4j, with the Live log fed by a backend-neutral log listener cleanup M
convergence & architecture7
🚀 ng-objects #4 NGApplication should not be a global design note L
🚀 ng-objects #44 Threaded component rendering design note L
🚀 ng-objects #45 Create an OpenRewrite recipe for WO->NG design note L
🚀 ng-objects #73 Investigate: applications exposing their domain as MCP tools design note L
🤸‍♀️ wonder-slim #35 Run without ERFoundation and ERWebObjects cleanup L
🤸‍♀️ wonder-slim #47 Own implementations of the WO dynamic elements, shared with ng-objects design note L
🤸‍♀️ wonder-slim #129 Investigate: one source for the formatting locale and WebObjects' languages() design note M
HTTP & requests7
🚀 ng-objects #38 Implement "cookie deletion" API in NGResponse feature S
🚀 ng-objects #39 Implement a generic resource cache for caching resources/webserver-resources and components design note M
🤖 modulo #16 Spool request bodies without a Content-Length, and replay them on failover feature M
🔌 wo-adaptor-jetty #6 Spool request bodies that arrive without Content-Length feature M
🔌 wo-adaptor-jetty #16 WebSocket support: smaller items left over from #13 cleanup M
🤸‍♀️ wonder-slim #140 Resources: a way for applications to control client caching feature S
🤸‍♀️ wonder-slim #141 Resources: processing on the way out (stamped url() in stylesheets, templating) design note M
sessions & state6
🚀 ng-objects #26 Add support for stateless components design note M
🚀 ng-objects #47 Redesign NGSwitchComponent as dynamic component references — keyed, not path-faked design note M
🚀 ng-objects #49 Session resurrection: framework support for rebuilding sessions across restarts design note M
🚀 ng-objects #54 Embed session-bound URL token in stateful URLs (with cookie still required) design note M
🚀 ng-objects #67 Page cache survival across restarts — wait for Java marshalling, and even then treat it as expanded resurrection design note L
🤸‍♀️ wonder-slim #131 Post/Redirect/Get for component actions (opt-in) design note M
front-end trust & admin6
🤸‍♀️ wonder-slim #53 ERControl: clean up the layout and decide which sections to keep cleanup M
⚙️️ wonder-slim-deployment #15 Replace shared-password auth with bearer tokens (role-based, JavaMonitor as issuer) security L
⚙️️ wonder-slim-deployment #35 Deployment toolchain should be safe to run over the public internet (no VPN required) security L
⚙️️ wonder-slim-deployment #40 Standalone management plane: separate admin port and protocol, app-framework-agnostic design note L
⚙️️ wonder-slim-deployment #45 First-class access policy for admin functionality (address allow-lists, restrictions, future auth) security M
⚙️️ wonder-slim-deployment #55 Multi-user support: registered users, per-user generated tokens security L
KVC3
🚀 ng-objects #3 KVC performance considerations cleanup M
🚀 ng-objects #25 Allow setting a replacement default implementation in NGKeyValueCoding design note S
🚀 ng-objects #29 Report accessibility errors in KVC feature S
build & packaging3
🦡 vermilingua #36 Support bundling JDKs in the application bundle feature M
🦡 vermilingua #48 Docker/container creation on build? design note M
⚙️️ wonder-slim-deployment #1 Set up GitHub Actions feature M
observability3
🤸‍♀️ wonder-slim #55 Instrumentation: modernize ERXStats, ERXStatisticsStore and WOEvent into one facility design note L
⚙️️ wonder-slim-deployment #22 Per-app request metrics in modulo (replacing the misleading 'transactions' WOStats counter) feature M
⚙️️ wonder-slim-deployment #33 Bidirectional metrics exchange between modulo and instances (architectural framing) design note L
Ajax1
🤸‍♀️ wonder-slim #132 AjaxSlim: stateless Ajax updates through direct actions or routes design note L
How the board works

Every open issue in every stack repository, in both the undur and ngobjects organizations, is on one GitHub project. Issues stay where they were filed; the board is the view across them.

Status is the column. Now is what's being worked on, Next what's lined up after it, Waiting on a decision what can't move until a call is made, and The notebook holds ideas and design notes kept on file. Issues are a design notebook as much as a bug tracker, so most of the board is the notebook, and that's by design.

Theme is the grouping, because a piece of work usually touches two or three repositories: client-address trust spans modulo and wonder-slim, routing spans wonder-slim and ng-objects, launch spans vermilingua and the deployment stack.

Kind says what an issue is: a bug, a security item, a feature, a decision, a design note, a cleanup, or docs. Effort is a rough size, S, M or L.

Pairs of issues that must ship together, and the chains where one issue blocks another, are recorded on the issues themselves on GitHub.

To get something on the board, file an issue in the repository it belongs to; it's picked up from there. Items the triage found done or superseded are reviewed before being closed and don't appear here.