Close the cover-the-diff (L1, ADR-020) gaps the port opened:
- auth router: exercise the signUp/signOut procedure handlers through the
container-resolved caller (b66759a reformatted them onto new lines).
- core-dsr export: add an audit-doc case with array-valued changedFields /
piiCategories and an absent actorRoles, covering the optional-field
branches of the new audit-trail mapper (9f90f05).
- coverage:diff excludes: mirror the vitest coverage excludes for
core-trpc/src/providers/** and core-shared/src/trpc/context.ts so
changes to coverage-excluded framework glue don't fail the diff gate.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
Ports the upstream auth audit fixes onto the kept auth feature:
- revoke sessions server-side via an in-memory jti denylist (B5):
createSession embeds the session id as the JWT jti, invalidateSession
denylists it for the max token lifetime, validateSession rejects
denylisted and jti-less (fail-closed) tokens; constant-time signature
comparison (B4). Adds session-denylist.ts + test.
- cover signToken/verifyToken/validateSession crypto paths without a
running Payload by stubbing the payload module (B8).
- derive clientIp server-side from trusted proxy headers and drop it from
the public sign-in input schema; thread it as a server-only request
context argument so a client can no longer spoof its rate-limit bucket
(B2).
- declare the auth-injected email (and displayName) in the users
collection-level DSR pii map so Art. 15 export and Art. 17 soft delete
cover them (A5). Adapted to our collection set (no username field).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
Veect retrofit (ADR-027): fifth and final slice of the demo-content
removal. Deletes packages/navigation whole and prunes every composition
edge in one commit: core-api router mount + dep + router test, core-cms
header-global composition + dep + regenerated Payload types (globals
now empty), web-next bindAll (prod + dev-seed) + tests + Tailwind
source + transpilePackages + dep, cms/core-cms payload config test
assertions, home e2e nav assertion, tsconfig paths, fallow
ignoreDependencies entry, anchor-guard FEATURES list, generator e2e
strip lists + reference-feature comments (navigation -> auth, incl.
feature templates + scaffolding guide), lockfile prune, and
feature-list doc trims (CLAUDE.md, AGENTS.md, glossary, app/feature
AGENTS.md). Compliance YAML regeneration produced no churn (navigation
declared no PII).
Cycle break: navigation's UI hooks were the last edge closing the
committed core-trpc -> core-api -> navigation -> core-trpc package
cycle. With it gone, the lint turbo task graph builds for the first
time and every package's ESLint executes; the epic's lint waiver
expires here. Latent findings: 3 errors, all mechanical, fixed
in-slice - require() import in turbo/generators/config.ts
(no-require-imports), literal type assertion in auth's
authentication.service.ts (prefer-as-const), and next-env.d.ts
triple-slash in apps/cms (rule scoped off for that generated file,
mirroring web-next's existing override). 99 warn-severity findings
remain across 5 packages (pii-declaration-must-be-complete on test
fixtures, turbo/no-undeclared-env-vars on test env keys) - all
warn-by-design, non-gating.
core-trpc keeps a consumer (apps/web-next providers) and stays per
ADR-027. Its unused @trpc/react-query dependency, surfaced by the
post-deletion fallow audit, is removed rather than ignore-listed -
core-trpc's hooks use @trpc/tanstack-react-query. Remaining fallow
warn (auth validateSession "unused member") is a false positive: the
method implements IAuthenticationService and is exercised in
container.test.ts; auth stays untouched as the regression canary.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK