fix(compliance): port DSR/consent/audit/retention audit fixes

Ports the upstream compliance-core audit fixes onto the kept core-dsr,
core-consent, core-audit, core-cms and core-shared packages:

- core-dsr: scope DSR operations to the caller's own subject (A11);
  include the subject's audit trail in exports; resolve the per-request
  binding from ctx instead of a throwing singleton proxy.
- core-consent: build the consent router from the shared superjson
  transformer (A10); merge per-category on persist instead of replacing;
  validate migrated categories against an allow-list.
- core-audit: keyed 128-bit pseudonyms + salted DSR certificate; add the
  audit-logs collection and the req-scoped GDPR audit-erasure afterDelete
  hook (A6).
- core-shared: grace-purge soft-deleted rows via a retention-purge task +
  tombstone field and boot registration (A2/A3); add the
  require-authenticated tRPC helper; derive clientIp + resolve the session
  user in createTrpcContext (B2/A11).
- core-cms: register audit-logs, wire the audit-erasure hook and
  retention-purge tasks; adapted to the clean-slate collection set
  (users only — no workspaces feature on this branch).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
This commit is contained in:
2026-07-13 06:07:25 +02:00
parent 4e4cd5fa7c
commit f2f24f7bfa
42 changed files with 2065 additions and 129 deletions

12
pnpm-lock.yaml generated
View File

@@ -448,6 +448,12 @@ importers:
"@repo/auth":
specifier: workspace:*
version: link:../auth
"@repo/core-audit":
specifier: workspace:*
version: link:../core-audit
"@repo/core-shared":
specifier: workspace:*
version: link:../core-shared
payload:
specifier: ^3.14.0
version: 3.81.0(graphql@16.13.2)(typescript@5.9.3)
@@ -495,6 +501,9 @@ importers:
"@testing-library/react":
specifier: ^16.0.0
version: 16.3.2(@testing-library/dom@10.4.1)(@types/react-dom@19.2.3(@types/react@19.2.14))(@types/react@19.2.14)(react-dom@19.2.4(react@19.2.4))(react@19.2.4)
"@trpc/client":
specifier: ^11.18.0
version: 11.18.0(@trpc/server@11.18.0(typescript@5.9.3))(typescript@5.9.3)
"@types/react":
specifier: ^19.0.0
version: 19.2.14
@@ -510,6 +519,9 @@ importers:
react:
specifier: ^19.0.0
version: 19.2.4
superjson:
specifier: ^2.2.1
version: 2.2.6
typescript:
specifier: ^5.8.0
version: 5.9.3