Ports the upstream web-next compliance wiring onto the clean-slate
auth-shell app, adapted to the auth-only collection set (no workspaces
feature on this branch):
- add a per-request createWebNextTrpcContext (A11): derives clientIp (B2),
resolves the authenticated user from the session cookie via the auth
feature's denylist-aware validateSession plus a role snapshot (B7), and
threads the boot-time consent factory + DSR binding so the mounted
consent/dsr routers are live instead of dead stubs.
- bind the production/dev-seed consent + DSR compliance bindings in
bind-production and expose them via getComplianceBindings; kick off the
retention purge cycle (A3).
- enforce manifest rate limits on the production path: bind
InMemoryRateLimit seeded from the auth manifest's budgets (A4/B3) while
dev-seed keeps the no-op limiter. Adds a regression test driving sign-in
through the real production binder + app router.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
Ports the kept-file portions of the upstream infra audit-fix subset onto
the clean-slate template branch (auth-only shape; workspaces feature never
existed here, so its package.json edit is skipped):
- resolve the root playwright config in pnpm test:visual (S8)
- prune dead VERCEL_ENV from turbo.json globalEnv (S9)
- drop the duplicate chromium install in the storybook CI job (S10)
- wire scripts/**/*.test.mjs under a dedicated vitest runner
(vitest.scripts.config.mjs + pnpm test:scripts + CI validate step);
convert node:test imports to vitest keeping node:assert
- ignore *.tsbuildinfo repo-wide and untrack the committed build state
- align every @trpc/* range on ^11.18.0 so the workspace resolves to a
single version (peer-warning-free install)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK