The core-package audit/consent/dsr reconstruction e2e tests remove the
target package and strip its references so pnpm install succeeds in the
simulated post-removal tree. The ported compliance wiring adds new
references the strip lists missed — core-cms now depends on core-audit
(audit-logs collection + erasure hook), and web-next depends on
core-consent + core-dsr (tRPC compliance context) — so strip those too.
The generated snapshots are unchanged.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
Close the cover-the-diff (L1, ADR-020) gaps the port opened:
- auth router: exercise the signUp/signOut procedure handlers through the
container-resolved caller (reformatted onto new lines by the port).
- core-dsr export: add an audit-doc case with array-valued changedFields /
piiCategories and an absent actorRoles, covering the optional-field
branches of the new audit-trail mapper.
- coverage:diff excludes: mirror the vitest coverage excludes for
core-trpc/src/providers/** and core-shared/src/trpc/context.ts so
changes to coverage-excluded framework glue don't fail the diff gate.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
Ports the upstream web-next compliance wiring onto the clean-slate
auth-shell app, adapted to the auth-only collection set (no workspaces
feature on this branch):
- add a per-request createWebNextTrpcContext (A11): derives clientIp (B2),
resolves the authenticated user from the session cookie via the auth
feature's denylist-aware validateSession plus a role snapshot (B7), and
threads the boot-time consent factory + DSR binding so the mounted
consent/dsr routers are live instead of dead stubs.
- bind the production/dev-seed consent + DSR compliance bindings in
bind-production and expose them via getComplianceBindings; kick off the
retention purge cycle (A3).
- enforce manifest rate limits on the production path: bind
InMemoryRateLimit seeded from the auth manifest's budgets (A4/B3) while
dev-seed keeps the no-op limiter. Adds a regression test driving sign-in
through the real production binder + app router.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
Ports the type-safety/ergonomics half of the upstream cycle-break: core-trpc
no longer imports AppRouter from @repo/core-api (an illegal
core -> core-composition boundary edge). The runtime context and both
providers are now AnyTRPCRouter-generic; consumers inject their router type
via useTRPC<TRouter>().
The clean-slate tree is already cycle-free (no kept feature consumes
core-trpc), so this is purely the architecture/boundary improvement. The
per-feature app-slice types the upstream commit added for the demo features
are intentionally skipped: no kept feature consumes useTRPC yet.
Also covers the router-agnostic useTRPC delegation: the refactor turned
useTRPC into a wrapper function whose body was unexercised, dropping
client.ts below the coverage floor — client.test.ts stubs the context
factory and asserts the delegation, restoring client.ts to 100%.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
Ports the upstream auth audit fixes onto the kept auth feature:
- revoke sessions server-side via an in-memory jti denylist (B5):
createSession embeds the session id as the JWT jti, invalidateSession
denylists it for the max token lifetime, validateSession rejects
denylisted and jti-less (fail-closed) tokens; constant-time signature
comparison (B4). Adds session-denylist.ts + test.
- cover signToken/verifyToken/validateSession crypto paths without a
running Payload by stubbing the payload module (B8).
- derive clientIp server-side from trusted proxy headers and drop it from
the public sign-in input schema; thread it as a server-only request
context argument so a client can no longer spoof its rate-limit bucket
(B2).
- declare the auth-injected email (and displayName) in the users
collection-level DSR pii map so Art. 15 export and Art. 17 soft delete
cover them (A5). Adapted to the clean-slate collection set.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
Ports the upstream compliance-core audit fixes onto the kept core-dsr,
core-consent, core-audit, core-cms and core-shared packages:
- core-dsr: scope DSR operations to the caller's own subject (A11);
include the subject's audit trail in exports; resolve the per-request
binding from ctx instead of a throwing singleton proxy.
- core-consent: build the consent router from the shared superjson
transformer (A10); merge per-category on persist instead of replacing;
validate migrated categories against an allow-list.
- core-audit: keyed 128-bit pseudonyms + salted DSR certificate; add the
audit-logs collection and the req-scoped GDPR audit-erasure afterDelete
hook (A6).
- core-shared: grace-purge soft-deleted rows via a retention-purge task +
tombstone field and boot registration (A2/A3); add the
require-authenticated tRPC helper; derive clientIp + resolve the session
user in createTrpcContext (B2/A11).
- core-cms: register audit-logs, wire the audit-erasure hook and
retention-purge tasks; adapted to the clean-slate collection set
(users only — no workspaces feature on this branch).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
Ports the kept-file portions of the upstream infra audit-fix subset onto
the clean-slate template branch (auth-only shape; workspaces feature never
existed here, so its package.json edit is skipped):
- resolve the root playwright config in pnpm test:visual (S8)
- prune dead VERCEL_ENV from turbo.json globalEnv (S9)
- drop the duplicate chromium install in the storybook CI job (S10)
- wire scripts/**/*.test.mjs under a dedicated vitest runner
(vitest.scripts.config.mjs + pnpm test:scripts + CI validate step);
convert node:test imports to vitest keeping node:assert
- ignore *.tsbuildinfo repo-wide and untrack the committed build state
- align every @trpc/* range on ^11.18.0 so the workspace resolves to a
single version (peer-warning-free install)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK