Commit Graph

10 Commits

Author SHA1 Message Date
3d52f2de85 test(generators): strip new compliance-core deps in optional-package e2e
The core-package audit/consent/dsr reconstruction e2e tests remove the
target package and strip its references so pnpm install succeeds in the
simulated post-removal tree. The ported compliance wiring adds new
references the strip lists missed — core-cms now depends on core-audit
(audit-logs collection + erasure hook), and web-next depends on
core-consent + core-dsr (tRPC compliance context) — so strip those too.
The generated snapshots are unchanged.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-13 06:23:14 +02:00
9b8c5f7416 docs(template): record the 2026-07-13 audit-fix sync in provenance
Note that the branch is now maintained (grown beyond the snapshot) and
enumerate the six ported clusters, including the auth-only reductions of
core-cms and web-next.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-13 06:15:09 +02:00
a80cf66026 test(coverage): cover the diff for ported auth + dsr changes
Close the cover-the-diff (L1, ADR-020) gaps the port opened:

- auth router: exercise the signUp/signOut procedure handlers through the
  container-resolved caller (reformatted onto new lines by the port).
- core-dsr export: add an audit-doc case with array-valued changedFields /
  piiCategories and an absent actorRoles, covering the optional-field
  branches of the new audit-trail mapper.
- coverage:diff excludes: mirror the vitest coverage excludes for
  core-trpc/src/providers/** and core-shared/src/trpc/context.ts so
  changes to coverage-excluded framework glue don't fail the diff gate.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-13 06:14:42 +02:00
932d7f381e feat(web-next): resolve session user + live compliance context and rate limits
Ports the upstream web-next compliance wiring onto the clean-slate
auth-shell app, adapted to the auth-only collection set (no workspaces
feature on this branch):

- add a per-request createWebNextTrpcContext (A11): derives clientIp (B2),
  resolves the authenticated user from the session cookie via the auth
  feature's denylist-aware validateSession plus a role snapshot (B7), and
  threads the boot-time consent factory + DSR binding so the mounted
  consent/dsr routers are live instead of dead stubs.
- bind the production/dev-seed consent + DSR compliance bindings in
  bind-production and expose them via getComplianceBindings; kick off the
  retention purge cycle (A3).
- enforce manifest rate limits on the production path: bind
  InMemoryRateLimit seeded from the auth manifest's budgets (A4/B3) while
  dev-seed keeps the no-op limiter. Adds a regression test driving sign-in
  through the real production binder + app router.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-13 06:14:02 +02:00
c2841cf352 refactor(core-trpc): make the tRPC context router-agnostic
Ports the type-safety/ergonomics half of the upstream cycle-break: core-trpc
no longer imports AppRouter from @repo/core-api (an illegal
core -> core-composition boundary edge). The runtime context and both
providers are now AnyTRPCRouter-generic; consumers inject their router type
via useTRPC<TRouter>().

The clean-slate tree is already cycle-free (no kept feature consumes
core-trpc), so this is purely the architecture/boundary improvement. The
per-feature app-slice types the upstream commit added for the demo features
are intentionally skipped: no kept feature consumes useTRPC yet.

Also covers the router-agnostic useTRPC delegation: the refactor turned
useTRPC into a wrapper function whose body was unexercised, dropping
client.ts below the coverage floor — client.test.ts stubs the context
factory and asserts the delegation, restoring client.ts to 100%.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-13 06:09:10 +02:00
361b28da99 fix(auth): port server-side session revocation and sign-in hardening
Ports the upstream auth audit fixes onto the kept auth feature:

- revoke sessions server-side via an in-memory jti denylist (B5):
  createSession embeds the session id as the JWT jti, invalidateSession
  denylists it for the max token lifetime, validateSession rejects
  denylisted and jti-less (fail-closed) tokens; constant-time signature
  comparison (B4). Adds session-denylist.ts + test.
- cover signToken/verifyToken/validateSession crypto paths without a
  running Payload by stubbing the payload module (B8).
- derive clientIp server-side from trusted proxy headers and drop it from
  the public sign-in input schema; thread it as a server-only request
  context argument so a client can no longer spoof its rate-limit bucket
  (B2).
- declare the auth-injected email (and displayName) in the users
  collection-level DSR pii map so Art. 15 export and Art. 17 soft delete
  cover them (A5). Adapted to the clean-slate collection set.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-13 06:08:22 +02:00
f2f24f7bfa fix(compliance): port DSR/consent/audit/retention audit fixes
Ports the upstream compliance-core audit fixes onto the kept core-dsr,
core-consent, core-audit, core-cms and core-shared packages:

- core-dsr: scope DSR operations to the caller's own subject (A11);
  include the subject's audit trail in exports; resolve the per-request
  binding from ctx instead of a throwing singleton proxy.
- core-consent: build the consent router from the shared superjson
  transformer (A10); merge per-category on persist instead of replacing;
  validate migrated categories against an allow-list.
- core-audit: keyed 128-bit pseudonyms + salted DSR certificate; add the
  audit-logs collection and the req-scoped GDPR audit-erasure afterDelete
  hook (A6).
- core-shared: grace-purge soft-deleted rows via a retention-purge task +
  tombstone field and boot registration (A2/A3); add the
  require-authenticated tRPC helper; derive clientIp + resolve the session
  user in createTrpcContext (B2/A11).
- core-cms: register audit-logs, wire the audit-erasure hook and
  retention-purge tasks; adapted to the clean-slate collection set
  (users only — no workspaces feature on this branch).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-13 06:07:25 +02:00
4e4cd5fa7c chore(tooling): port upstream infra/tooling audit fixes
Ports the kept-file portions of the upstream infra audit-fix subset onto
the clean-slate template branch (auth-only shape; workspaces feature never
existed here, so its package.json edit is skipped):

- resolve the root playwright config in pnpm test:visual (S8)
- prune dead VERCEL_ENV from turbo.json globalEnv (S9)
- drop the duplicate chromium install in the storybook CI job (S10)
- wire scripts/**/*.test.mjs under a dedicated vitest runner
  (vitest.scripts.config.mjs + pnpm test:scripts + CI validate step);
  convert node:test imports to vitest keeping node:assert
- ignore *.tsbuildinfo repo-wide and untrack the committed build state
- align every @trpc/* range on ^11.18.0 so the workspace resolves to a
  single version (peer-warning-free install)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-13 06:04:36 +02:00
dda9af93ad docs(template): note prettier normalization in provenance 2026-07-12 20:55:15 +02:00
f77e6ea881 chore(template): clean-slate template snapshot from bb4a0c7
Curated, product-agnostic snapshot of the post-story-04 tree: demo
content deleted, auth-only reference feature, web-next shell, all gates
green. Product-specific docs, ADRs 027-029, PRDs/epics/archive, editor
library traces, and product naming are curated out; generic template
repairs (coverage provider devDeps, root test:coverage script, live
lint fixes, root-only release-please) are kept. See TEMPLATE.md for
provenance, curation list, and usage.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-12 20:40:54 +02:00