docs(work): decompose binder-wrap-helper PRD into epic + 8 stories

Output from `pnpm work decompose 2026-05-13-binder-wrap-helper
--execute` — sandcastle ran the decomposer agent with subscription
auth (after the macOS keychain workaround + Dockerfile fix from
prior commits). The agent wrote files but hit `Max iterations: 1`
before committing, so this commit carries its output unchanged.

Epic: docs/work/binder-wrap-helper/
  - _epic.md links to PRD 2026-05-13-binder-wrap-helper
  - features: [core-shared, auth, blog, media, marketing-pages,
    navigation, tooling]

Stories (8 total, with dependency edges):
  01-wire-use-case-helper           prereq (blocks 02..07)
    Goal: helper at core-shared/conformance/wire-use-case.ts +
    tests covering brand stacking, span/capture/audit composition,
    idempotent bind. depends-on: [], blocks 02..07.
  02-migrate-auth-binders           depends-on [01]
  03-migrate-blog-binders           depends-on [01]
  04-migrate-media-binders          depends-on [01]
  05-migrate-marketing-pages-       depends-on [01]
    binders
  06-migrate-navigation-binders     depends-on [01]
  07-update-feature-generator       depends-on [01]
  08-holistic-validation            depends-on [02..07], blocks: []
    Final gate suite + fallow dupes check to verify the 5 binder-
    pair clone groups have disappeared.

After 01 lands, stories 02..07 are parallelisable; 08 collects them.

Pre-commit hook regenerates _state.json + re-stages it so `pnpm
work next` immediately surfaces the new ready story.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-05-13 18:10:31 +02:00
parent 9d4b801909
commit 6f18075593
10 changed files with 598 additions and 3 deletions

View File

@@ -0,0 +1,49 @@
---
id: 02-migrate-auth-binders
epic: binder-wrap-helper
title: Migrate auth feature binders to wireUseCase
type: technical-story
status: todo
feature: auth
depends-on: [01-wire-use-case-helper]
blocks: [08-holistic-validation]
---
## Goal
Replace the inline `withSpan + withCapture (+ optional withAudit)` blocks in `packages/auth/src/di/bind-production.ts` and `packages/auth/src/di/bind-dev-seed.ts` with `wireUseCase` calls for all three auth use cases (signIn, signUp, signOut).
## Why
Auth's binder pair contributes one of the five top-ten `pnpm fallow` clone groups. The inline wrap blocks are ~3079 lines of mechanical boilerplate that adds noise to every auth binder diff.
## Done when
- `bind-production.ts` and `bind-dev-seed.ts` call `wireUseCase` for signIn, signUp, and signOut — no inline `withSpan(... withCapture(...))` pattern remains in either file.
- Audit-bearing use cases (per manifest check) pass `auditLog` + audit schema to `wireUseCase`; non-audit use cases omit it.
- `pnpm test --filter @repo/auth` green (binder tests + integration tests).
- `pnpm typecheck --filter @repo/auth` green.
- `assertFeatureConformance` does not throw at boot for auth (brands + manifest match).
## In scope
- `packages/auth/src/di/bind-production.ts` — use-case binding blocks only.
- `packages/auth/src/di/bind-dev-seed.ts` — use-case binding blocks only.
- Repository and service bindings stay as-is (direct `.toConstantValue()` calls).
- Controller bindings stay as-is (controllers are out of scope for this PRD).
## Out of scope
- Controller bindings — deferred follow-up per PRD.
- Changes to auth use-case implementations, schemas, or tests outside the binder.
- Changes to `assertFeatureConformance` or the manifest.
## Tasks
- [ ] Read `packages/auth/src/feature.manifest.ts` — identify which use cases declare `audits: [...]` (non-empty) vs `audits: []`
- [ ] Read `packages/auth/src/di/bind-production.ts` — understand current inline wrap shape and which deps each use case receives
- [ ] Read `packages/auth/src/di/bind-dev-seed.ts` — same for dev-seed mode
- [ ] Update `packages/auth/src/di/bind-production.ts` — replace all three inline wrap blocks with `wireUseCase` calls; pass `auditLog` + schema for audit-bearing use cases
- [ ] Update `packages/auth/src/di/bind-dev-seed.ts` — same
- [ ] Run `pnpm test --filter @repo/auth` — verify all tests pass
- [ ] Run `pnpm typecheck --filter @repo/auth` — verify no type regressions