Commit Graph

65 Commits

Author SHA1 Message Date
3b577635f8 feat(web-next): resolve session user + live compliance context and rate limits
Ports the upstream web-next compliance wiring onto our auth-shell app,
adapted to the Veect collection set (auth + workspaces, no demo features):

- add a per-request createWebNextTrpcContext (A11): derives clientIp (B2),
  resolves the authenticated user from the session cookie via the auth
  feature's denylist-aware validateSession plus a role snapshot (B7), and
  threads the boot-time consent factory + DSR binding so the mounted
  consent/dsr routers are live instead of dead stubs.
- bind the production/dev-seed consent + DSR compliance bindings in
  bind-production and expose them via getComplianceBindings; kick off the
  retention purge cycle (A3).
- enforce manifest rate limits on the production path: bind
  InMemoryRateLimit seeded from the auth manifest's budgets (A4/B3) while
  dev-seed keeps the no-op limiter. Adds a regression test driving sign-in
  through the real production binder + app router.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-13 00:02:21 +02:00
318a69e780 fix(compliance): port DSR/consent/audit/retention audit fixes
Ports the upstream compliance-core audit fixes onto the kept core-dsr,
core-consent, core-audit, core-cms and core-shared packages (pristine
template state here, so taken to the fixed end-state):

- core-dsr: scope DSR operations to the caller's own subject (A11);
  include the subject's audit trail in exports; resolve the per-request
  binding from ctx instead of a throwing singleton proxy.
- core-consent: build the consent router from the shared superjson
  transformer (A10); merge per-category on persist instead of replacing;
  validate migrated categories against an allow-list.
- core-audit: keyed 128-bit pseudonyms + salted DSR certificate; add the
  audit-logs collection and the req-scoped GDPR audit-erasure afterDelete
  hook (A6).
- core-shared: grace-purge soft-deleted rows via a retention-purge task +
  tombstone field and boot registration (A2/A3); add the
  require-authenticated tRPC helper; derive clientIp + resolve the session
  user in createTrpcContext (B2/A11).
- core-cms: register audit-logs, wire the audit-erasure hook and
  retention-purge tasks; adapted to our collection set (users, workspaces).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 23:54:14 +02:00
ac0bf80eca fix(auth): port server-side session revocation and sign-in hardening
Ports the upstream auth audit fixes onto the kept auth feature:

- revoke sessions server-side via an in-memory jti denylist (B5):
  createSession embeds the session id as the JWT jti, invalidateSession
  denylists it for the max token lifetime, validateSession rejects
  denylisted and jti-less (fail-closed) tokens; constant-time signature
  comparison (B4). Adds session-denylist.ts + test.
- cover signToken/verifyToken/validateSession crypto paths without a
  running Payload by stubbing the payload module (B8).
- derive clientIp server-side from trusted proxy headers and drop it from
  the public sign-in input schema; thread it as a server-only request
  context argument so a client can no longer spoof its rate-limit bucket
  (B2).
- declare the auth-injected email (and displayName) in the users
  collection-level DSR pii map so Art. 15 export and Art. 17 soft delete
  cover them (A5). Adapted to our collection set (no username field).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 23:53:43 +02:00
8b114351a8 chore(tooling): port upstream infra/tooling audit fixes
Reconciles the upstream audit-fix PR's infra changes onto the Veect
control-plane fork (kept-file portions only; deleted demo features
skipped):

- resolve the root playwright config in pnpm test:visual (S8)
- prune dead VERCEL_ENV from turbo.json globalEnv (S9)
- drop the duplicate chromium install in the storybook CI job (S10)
- wire scripts/**/*.test.mjs under a dedicated vitest runner
  (vitest.scripts.config.mjs + pnpm test:scripts + CI validate step);
  convert node:test imports to vitest keeping node:assert; fix the
  work-tree fixtures to mirror the docs/work/epics/ layout
- ignore *.tsbuildinfo repo-wide and untrack the committed build state
- align every @trpc/* range on ^11.18.0 so the workspace resolves to a
  single version (peer-warning-free install)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 23:40:07 +02:00
882c47b014 docs(work): close walking-skeleton story 04 (runner clone/install) 2026-07-12 22:55:17 +02:00
ec7bf948af feat(runner): install stage with progress events
Install stage: package-manager detection (lockfile beats the
packageManager field, npm default — vite-kitchen's shape), install run
inside the clone with staged status heartbeats, and every failure —
including install-before-clone — mapped to the named install-failed
cause with a bounded output tail. The spawned-runner suite now runs the
full clone → install pipeline on the daemon-served vite-kitchen (real
npm registry install) and greps the child's entire stdout+stderr plus
the clone's .git/config for the PAT and workspace token. Shared test
doubles extracted (exec.mock.ts, tests/runner-session.ts) to keep the
suites duplication-free.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 22:50:41 +02:00
750ab44379 feat(runner): clone stage with ephemeral credential helper
Clone stage per tech spec §6, verbatim mechanics: every git invocation
carries a BLANK credential.helper first (suppresses OS keychain
helpers) then the inline veect helper; the PAT reaches git via child
env only — never argv, URLs, logs, or .git/config. GIT_TERMINAL_PROMPT
and GIT_ASKPASS are pinned so a headless clone can never hang on a TTY
or ambient IDE askpass. Staged status events (start/heartbeat/final) +
ready on success; named failures: invalid-git-url, auth-failed,
clone-failed (daemon's 'repository not exported' maps to bad-URL, not
auth). Integration suite clones the daemon-served vite-kitchen and an
authenticated dumb-HTTP remote that asserts the exact Basic credential
git presented, plus leak assertions over logs/argv/.git.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 22:50:41 +02:00
b090e26701 feat(runner): WS protocol server with handshake
apps/runner scaffold (app-tier, walking-skeleton story 04): WS server
speaking @repo/core-runner-protocol. Every inbound/outbound frame is
envelope-wrapped and zod-parsed; hello/ready handshake gates on the
workspace-scoped token (constant-time compare, redacted token on
rejection replies); named error events for version/schema/auth
rejections. Config via env only (token never argv); port announced on
stdout for the story-06 provisioner. Runtime deps: ws (the standard
Node WS server; ADR-022 traces do not apply to app-tier) and zod.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 22:50:41 +02:00
11e5012572 docs(work): close walking-skeleton story 03 (workspaces feature) 2026-07-12 22:37:40 +02:00
eec402d49d feat(workspaces): status and list use cases
getWorkspaceStatus returns persisted { id, status } only (runner-driven
transitions arrive in story 07); listWorkspaces returns the
credential-free workspace array with a strict void input (optional on
the tRPC procedure so clients can call without args). Repository gains
listWorkspaces on interface, mock, and Payload impl; the contract suite
covers listing incl. the never-returns-credentials guarantee.
Controller span+capture wrapping is extracted into a shared
bindWorkspacesController helper used by both binders, trimming the
bind-production/bind-dev-seed clone family fallow was flagging.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 22:36:18 +02:00
c990e1b871 feat(workspaces): encrypted write-only credential storage
Workspaces Payload collection with the PAT as a write-only field:
access.read () => false strips it from every access-controlled read
path, and a field-level beforeChange hook encrypts on write with
AES-256-GCM (scrypt key from VEECT_SECRET, random per-value salt + IV,
v1 storage format) via node:crypto only. The real repository replaces
the phase-1 stub with payload create/findByID; toDomain never maps the
credential, and getDecryptedCredential(id) is the single server-side
decrypt path for the runner handoff (story 07). Contract suite now
covers create, write-only behaviour, and the decrypt path against both
the mock and the Payload impl (stub runs the real collection hooks).
Missing VEECT_SECRET fails production bind/boot with an actionable
message; dev-seed boots without it. Env declared in turbo.json
globalEnv + .env.example.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 22:36:18 +02:00
8219c1fabb feat(workspaces): connectWorkspace use case with audit
Manifest-first: connectWorkspace declared mutates:true with the
workspace-connected audit event, requiredCores gains audit. Workspace
entity gains gitUrl + persisted status enum (created/connecting/ready/
error). Input takes name + git URL + PAT; the output schema is the
credential-free workspace entity, so the PAT can never round-trip.
Audit emission asserted with RecordingAuditLog; binders wire the use
case through wireUseCase with the __audited brand, and web-next
bindAll now binds core-audit (payload+stdout sinks in production,
stdout in dev-seed) so boot conformance passes in both modes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 22:36:18 +02:00
6216897680 feat(workspaces): scaffold feature
Scaffold the workspaces feature package via pnpm turbo gen feature
(single Workspace entity, getWorkspace use case) and hand-wire the
aggregators: bindAll dispatcher (web-next), core-api app router, and
workspace deps. Release-please registration reverted per the root-only
versioning policy (AGENTS.md, ADR-027 retrofit). Pinned @trpc/server
to the repo-wide 11.16.0 resolution so instanceof TRPCError checks
share one module instance.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 22:35:55 +02:00
97593593f2 docs(work): close walking-skeleton story 09 (editor package) 2026-07-12 22:24:37 +02:00
9495023aed feat(editor): board shell with iframe frame and selection overlay
React Flow board (pan/zoom + frame drag are pure editor-side transforms
— zero canvas-protocol traffic, <16ms budget) hosting one iframe frame
node on the adapter origin. The frame waits for runtime.ready
(queue-drain) behind an explicit 'Starting preview…' skeleton, then
requests a single Element via render-frame (core-runner-protocol
schema) plus geometry; agent-reported geometry stays frame-local and
click reports drive store selection. The selection ring renders as an
editor-side overlay from reported geometry — chrome never inside the
customer's document (ADR-028). Stories + jsdom component tests for
board/frame/overlay; Storybook stories glob extended to
packages/editor (verified via static build).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 22:18:24 +02:00
c2f56ac8c9 feat(editor): canvas-protocol client and store
The editor side of the ADR-028 canvas protocol: local .strict() zod
schemas (runtime.ready, geometry.report, click.target agent events;
render-frame reused from @repo/core-runner-protocol + geometry.request
editor commands; direction-specific envelopes) and a client that pins
targetOrigin in BOTH directions — outbound posts never use '*', inbound
drops wrong-origin, wrong-source, and schema-invalid events before any
handler runs. Shapes are deliberately small and reconcile with the
adapter's agent script in stories 05/10. Unit-tested against a scripted
agent double; zustand store holds registry + selection ONLY (DesignDoc
v1 arrives with the design-doc epic, ADR-029).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 22:07:08 +02:00
c42eca5b80 feat(editor): scaffold editor package
UI-only feature package for the ADR-029 editor rebuild: tsconfig
rootDir '.', vitest jsdom base with '@' alias and honest L0 baseline
thresholds, conformance ESLint active, React 19, @xyflow/react +
zustand wired against the pre-approved 2026-07-12 library traces.
Minimal feature.manifest.ts (empty useCases — no binders; declares
requiredCores runner-protocol + baseline coverage band) so the editor
participates in pnpm conformance without weakening any lint rule.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 22:00:34 +02:00
e9edad69b4 docs(work): close walking-skeleton story 02 (protocol package) 2026-07-12 21:47:47 +02:00
52f3b19dfe feat(core-runner-protocol): v0 message schemas with round-trip tests
Envelope pins protocolVersion "0" and carries the workspace-scoped
auth token; discriminated union on type covers hello/ready, clone,
install, scan, adapter-start, render-frame, status (stage + elapsed),
and error (named causes). All .strict() so the control plane, editor,
and runner cannot drift apart silently (ADR-027, PRD user story 7).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 21:47:34 +02:00
15dc6b9128 feat(core-runner-protocol): scaffold protocol package
Hand-scaffolded from the packages/core-events shape: the core-package
turbo generator only covers its eight pre-curated snapshot names
(analytics, audit, consent, dsr, events, realtime, trpc, ui) and
rejects 'runner-protocol' at the name prompt. Flagged in the package
AGENTS.md as a future generator snapshot candidate.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 21:47:34 +02:00
240075d95b docs(work): close walking-skeleton story 01 (fixture + git helpers) 2026-07-12 21:44:13 +02:00
2bd882e0b0 feat(core-testing): git-serving fixture helpers
serveFixtureRepo(fixtureDir) copies a fixture into a temp dir, commits
it as a fresh single-commit repo, bare-clones it, and serves it over
`git daemon --export-all` on an ephemeral localhost port (default) or
as a file:// URL (fallback for daemon-less environments). Returns
{ cloneUrl, bareRepoPath, protocol, stop } with idempotent teardown.
Tests exercise a real `git clone` of fixtures/vite-kitchen over both
protocols. New subpath export @repo/core-testing/git — node-only, so
deliberately not on the jsdom root barrel. No new runtime deps: node
built-ins + system git (present in git's exec-path on macOS and the
ubuntu CI image).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 21:40:52 +02:00
1ae4a2385c test(fixtures): add vite-kitchen fixture repo
Minimal Vite + React + TS + Tailwind app with a typed-props Button
component (the future react-docgen-typescript scan target), landed at
fixtures/ outside the pnpm workspace and turbo graph. Its dependencies
exist on paper only — the runner installs them after cloning (story 04);
no lockfile, never pnpm-installed here.

Ignore surfaces follow the docs/product/reference precedent: fallow,
root ESLint, prettier, and the coverage:diff ALLOWED_GLOBS all skip
fixtures/**.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 21:36:21 +02:00
fe9b2c4151 docs(work): ship platform-retrofit PRD 2026-07-12 21:17:35 +02:00
8d1d1ebd0e docs(work): close story 08 and epic platform-retrofit (20/20 tasks) 2026-07-12 21:17:11 +02:00
46250c819f docs(agents): rewrite package map and conventions for Veect
AGENTS.md now describes the Veect control plane (ADR-027/028/029,
docs/product/ authority table, glossary Veect-domain vocabulary), with
the package map, boundary tags, and per-package conventions verified
against the filesystem (auth + 11 core + 3 tooling packages;
web-next/cms/storybook apps) and code examples drawn from the real auth
feature. Adds warning notes for known generator staleness — the
release-please per-feature registration that would collide with the
root-only v* tag policy, the pre-shipped trace overwrite hazard (zod
incident, restored in e4a3b65), the trpc template's removed
@trpc/react-query dep — and records the accepted warn-severity lint
backlog (~93 findings).

Per story amendments, the same slice prunes the dead "web-tanstack"
member from core-shared's app-tag unions (bind-otel-instrumentation.ts,
sentry/init-client.ts; tests retargeted to "web-next") and fixes the
stale app/feature tag lists in docs/architecture/overview.md. A warning
comment mirrors the release-please note at the generator call site; no
functional generator changes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 21:06:38 +02:00
d7534b9926 docs(claude): rewrite agent context for Veect
Project overview and Read First now describe the Veect control plane
(hosted design-to-code SaaS, ADR-027/028/029, docs/product/ as the
authoritative spec bundle, glossary Veect-domain vocabulary). The
versioning bullet reflects the root-only release-please policy, the
Quick Start conformance-rule miscount reads sixteen, and the Read First
qualifiers acknowledge events/realtime/audit cores are scaffolded.

Also retargets .claude/hooks/prompt-context.sh's Releases pointer from
the retired hybrid per-package scheme to the root-only policy and prunes
its deleted-feature tag examples (story 02 follow-up flag).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 21:06:23 +02:00
e1a267d559 docs(work): close story 09 (template/clean-slate branch created) 2026-07-12 20:55:40 +02:00
f85b848266 docs(work): close story 05 (optional cores fc13424 + e50306c) 2026-07-12 20:36:42 +02:00
e4a3b659a3 fix(docs): restore zod trace enrichment lost to stale generator template
The core-package generator's pre-shipped zod trace force-overwrote the
curated trace, dropping lastRevalidated/is-sub-processor/processes-pii/
socketRisk fields and the deciders record. Restores the rich version
with the consumer list updated for the post-retrofit package map.
Reviewer-required follow-up from story 05.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 20:36:29 +02:00
e50306cbf6 feat(core-realtime): scaffold realtime optional core
Generator-emitted scaffold (pnpm turbo gen core-package realtime) plus
the story-00-precedent coverage repairs (coverage provider devDep,
symbols.ts exclude + tested allowlist mirror) and three minimal tests
covering generator-emitted realtime code the template suite misses.
Squash of 31d85e0 + review-fix cf11b38.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 20:35:09 +02:00
fc13424e9d feat(core-events): scaffold events optional core
Scaffolded via pnpm turbo gen core-package events (generator-first,
ADR-022 pre-shipped zod trace landed in docs/library-decisions/).
Generator wired transpilePackages + E1/J eslint rule block. Two
story-00-precedent additions so the coverage gates pass: the
@vitest/coverage-v8 devDep (L0 sweep) and the honest symbols.ts
exclude (mirroring core-shared/vitest.config.ts) plus its missing
ALLOWED_GLOBS mirror in scripts/coverage/diff.mjs (L1 gate). No
consumers wired — compile-green floor for the walking-skeleton
PRD (ADR-027).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 20:35:09 +02:00
f215720449 docs(work): close story 04 (web-next shell f7b869b + bb4a0c7) 2026-07-12 20:27:50 +02:00
bb4a0c7219 test(web-next): boot smoke asserts auth-only bindAll
Dev-seed boot smoke for the retrofit floor: runs the REAL auth dev-seed
binder (so assertFeatureConformance executes like pnpm dev), resolves
every auth manifest use case + controller from the container, signs in a
seeded user server-side, and asserts the dispatcher wires exactly one
feature's binders — proving no dangling DI symbols from the deleted demo
features.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 20:23:27 +02:00
f7b869bf67 feat(web-next): minimal authenticated shell home
Shell home for the platform-retrofit floor: a sign-in form (dev-seed
credentials) and a signed-in placeholder with sign-out. Both flows run
through the composed tRPC appRouter via server actions that own the
session cookie on the app side; the auth feature is untouched. Adds the
auth sign-in Playwright spec as the surviving e2e baseline and drops the
last demo-template metadata.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 20:20:37 +02:00
e1aa934153 docs(work): close story 03 — all demo content deleted, lint live 2026-07-12 19:35:49 +02:00
48bf4da4cd refactor(navigation)!: delete navigation demo feature
Veect retrofit (ADR-027): fifth and final slice of the demo-content
removal. Deletes packages/navigation whole and prunes every composition
edge in one commit: core-api router mount + dep + router test, core-cms
header-global composition + dep + regenerated Payload types (globals
now empty), web-next bindAll (prod + dev-seed) + tests + Tailwind
source + transpilePackages + dep, cms/core-cms payload config test
assertions, home e2e nav assertion, tsconfig paths, fallow
ignoreDependencies entry, anchor-guard FEATURES list, generator e2e
strip lists + reference-feature comments (navigation -> auth, incl.
feature templates + scaffolding guide), lockfile prune, and
feature-list doc trims (CLAUDE.md, AGENTS.md, glossary, app/feature
AGENTS.md). Compliance YAML regeneration produced no churn (navigation
declared no PII).

Cycle break: navigation's UI hooks were the last edge closing the
committed core-trpc -> core-api -> navigation -> core-trpc package
cycle. With it gone, the lint turbo task graph builds for the first
time and every package's ESLint executes; the epic's lint waiver
expires here. Latent findings: 3 errors, all mechanical, fixed
in-slice - require() import in turbo/generators/config.ts
(no-require-imports), literal type assertion in auth's
authentication.service.ts (prefer-as-const), and next-env.d.ts
triple-slash in apps/cms (rule scoped off for that generated file,
mirroring web-next's existing override). 99 warn-severity findings
remain across 5 packages (pii-declaration-must-be-complete on test
fixtures, turbo/no-undeclared-env-vars on test env keys) - all
warn-by-design, non-gating.

core-trpc keeps a consumer (apps/web-next providers) and stays per
ADR-027. Its unused @trpc/react-query dependency, surfaced by the
post-deletion fallow audit, is removed rather than ignore-listed -
core-trpc's hooks use @trpc/tanstack-react-query. Remaining fallow
warn (auth validateSession "unused member") is a false positive: the
method implements IAuthenticationService and is exercised in
container.test.ts; auth stays untouched as the regression canary.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 19:34:54 +02:00
61e1f0792d docs(work): close story 07 (editor library traces f8a4b70 + 3a1b088) 2026-07-12 19:13:30 +02:00
3a1b0886c5 docs(library-decisions): trace zustand v5 for the editor store
Pre-approve the ADR-022 library trace for the editor's client-state
store (ADR-029: store on DesignDoc v1, React 19). Evaluates v5
specifically — the founder prototype used v4. Trace only — the package
is not installed by this commit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 19:12:44 +02:00
f8a4b70752 docs(library-decisions): trace @xyflow/react for the editor board
Pre-approve the ADR-022 library trace for the React Flow board substrate
(ADR-028/029) so walking-skeleton implementers of packages/editor do not
stall on the library-policy pre-commit hook. Trace only — the package is
not installed by this commit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 19:12:44 +02:00
4843953ecc docs(work): close story 06 (template work archived as 2b39ae8) 2026-07-12 17:33:05 +02:00
2b39ae8c0a docs(work): archive shipped template epics and PRDs
Move the 8 shipped template epics and their 9 PRDs (incl.
coverage-architecture) to docs/work/archive/{epics,prds}/ so dispatch
context and prioritization only see live Veect work. The state builder
already walks docs/work/epics/ + docs/work/prds/ only; the one work-CLI
script that matched archive paths (bump-updated-timestamps.mjs, staged
docs/work/**/*.md) now excludes docs/work/archive/ so archived content
stays byte-identical.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 17:32:20 +02:00
2126fda6f8 docs(work): tick story 03 slice 4 (marketing-pages deleted as 9ee9418) 2026-07-12 17:23:39 +02:00
9ee941863d refactor(marketing-pages)!: delete marketing-pages demo feature
Veect retrofit (ADR-027): fourth slice of the demo-content removal.
Deletes packages/marketing-pages whole and prunes every composition
edge in one commit: core-api router mount + dep, core-cms
collection/global composition + dep + regenerated Payload types,
web-next bindAll (prod + dev-seed) + tests + about page + Tailwind
source + transpilePackages + dep, cms/core-cms payload config test
assertions, marketing-page e2e spec, tsconfig paths, fallow ignore
entry, anchor-guard + generator e2e feature lists, compliance
data-map + retention-policy regeneration, lockfile prune, and
feature-list doc entries (CLAUDE.md, AGENTS.md, glossary, app/feature
AGENTS.md).

Event teardown: marketing-pages was the sole consumer of
auth.user.signed-up (welcome-email handler + job). The handler, its
Payload tasks, and the bus subscription all lived inside the package's
own binders, so they die with it — no other package wires the
subscription. Auth's manifest `publishes` stays untouched: a publisher
with zero consumers is legal (pnpm conformance only fails on orphan
consumers, verified green). The app-level sign-up-welcome-email test
asserted the marketing-pages mailer stays empty without a bus; it is
deleted with the feature, and the now-unused test-only bind-state
helpers in web-next bind-production.ts go with it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 17:23:08 +02:00
7dd3e7ceac docs(work): add story 09 template-snapshot (founder request) 2026-07-12 17:21:30 +02:00
c0f7a20bfd docs(work): tick story 03 slice 3 (media deleted as 80beacf) 2026-07-12 16:32:06 +02:00
80beacfe88 refactor(media)!: delete media demo feature
Veect retrofit (ADR-027): third slice of the demo-content removal.
Deletes packages/media whole and prunes every composition edge in one
commit: core-api router mount + dep, core-cms collection composition +
dep + regenerated Payload types, web-next bindAll (prod + dev-seed) +
tests + Tailwind source + transpilePackages + dep, cms/core-cms/web-next
payload config test assertions, tsconfig paths, anchor-guard + generator
e2e feature lists, compliance data-map + retention-policy regeneration,
lockfile prune, and feature-list doc entries (CLAUDE.md, AGENTS.md,
glossary, app/feature AGENTS.md).

Media was the uploads feature: the marketing-pages pages.hero.image and
navigation header.logo upload fields (relationTo: "media") are removed
from those collections in this slice — Payload config sanitization
rejects a relationship to a missing collection. Both features' domain
entities keep their optional imageId/logoId fields; their repositories
already tolerate the fields being absent. Both features are deleted in
later slices.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 16:26:42 +02:00
483c7b2c8e docs(work): tick story 03 slice 2 (blog deleted as ea24c85) 2026-07-12 16:04:25 +02:00
ea24c85424 refactor(blog)!: delete blog demo feature
Veect retrofit (ADR-027): the template's demo content is being removed
to make room for the Veect package map. This slice deletes
packages/blog whole and prunes every composition edge in one commit:
core-api router mount, core-cms collections + regenerated Payload
types, web-next bindAll entry / home page / blog route / Tailwind
sources, blog e2e spec, tsconfig paths, fallow ignore entry,
anchor-guard + generator e2e feature lists, compliance artifacts,
and feature-list doc entries (CLAUDE.md, AGENTS.md, glossary).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 15:56:22 +02:00
bb12cc2432 docs(work): tick story 03 slice 1 (web-tanstack deleted as 986f8b2) 2026-07-12 15:32:09 +02:00