fix(compliance): port DSR/consent/audit/retention audit fixes

Ports the upstream compliance-core audit fixes onto the kept core-dsr,
core-consent, core-audit, core-cms and core-shared packages (pristine
template state here, so taken to the fixed end-state):

- core-dsr: scope DSR operations to the caller's own subject (A11);
  include the subject's audit trail in exports; resolve the per-request
  binding from ctx instead of a throwing singleton proxy.
- core-consent: build the consent router from the shared superjson
  transformer (A10); merge per-category on persist instead of replacing;
  validate migrated categories against an allow-list.
- core-audit: keyed 128-bit pseudonyms + salted DSR certificate; add the
  audit-logs collection and the req-scoped GDPR audit-erasure afterDelete
  hook (A6).
- core-shared: grace-purge soft-deleted rows via a retention-purge task +
  tombstone field and boot registration (A2/A3); add the
  require-authenticated tRPC helper; derive clientIp + resolve the session
  user in createTrpcContext (B2/A11).
- core-cms: register audit-logs, wire the audit-erasure hook and
  retention-purge tasks; adapted to our collection set (users, workspaces).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
This commit is contained in:
2026-07-12 23:54:14 +02:00
parent ac0bf80eca
commit 318a69e780
42 changed files with 2102 additions and 138 deletions

12
pnpm-lock.yaml generated
View File

@@ -497,6 +497,12 @@ importers:
"@repo/auth":
specifier: workspace:*
version: link:../auth
"@repo/core-audit":
specifier: workspace:*
version: link:../core-audit
"@repo/core-shared":
specifier: workspace:*
version: link:../core-shared
"@repo/workspaces":
specifier: workspace:*
version: link:../workspaces
@@ -547,6 +553,9 @@ importers:
"@testing-library/react":
specifier: ^16.0.0
version: 16.3.2(@testing-library/dom@10.4.1)(@types/react-dom@19.2.3(@types/react@19.2.14))(@types/react@19.2.14)(react-dom@19.2.4(react@19.2.4))(react@19.2.4)
"@trpc/client":
specifier: ^11.18.0
version: 11.18.0(@trpc/server@11.18.0(typescript@5.9.3))(typescript@5.9.3)
"@types/react":
specifier: ^19.0.0
version: 19.2.14
@@ -562,6 +571,9 @@ importers:
react:
specifier: ^19.0.0
version: 19.2.4
superjson:
specifier: ^2.2.1
version: 2.2.6
typescript:
specifier: ^5.8.0
version: 5.9.3