Ports the upstream compliance-core audit fixes onto the kept core-dsr,
core-consent, core-audit, core-cms and core-shared packages (pristine
template state here, so taken to the fixed end-state):
- core-dsr: scope DSR operations to the caller's own subject (A11);
include the subject's audit trail in exports; resolve the per-request
binding from ctx instead of a throwing singleton proxy.
- core-consent: build the consent router from the shared superjson
transformer (A10); merge per-category on persist instead of replacing;
validate migrated categories against an allow-list.
- core-audit: keyed 128-bit pseudonyms + salted DSR certificate; add the
audit-logs collection and the req-scoped GDPR audit-erasure afterDelete
hook (A6).
- core-shared: grace-purge soft-deleted rows via a retention-purge task +
tombstone field and boot registration (A2/A3); add the
require-authenticated tRPC helper; derive clientIp + resolve the session
user in createTrpcContext (B2/A11).
- core-cms: register audit-logs, wire the audit-erasure hook and
retention-purge tasks; adapted to our collection set (users, workspaces).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
Reconciles the upstream audit-fix PR's infra changes onto the Veect
control-plane fork (kept-file portions only; deleted demo features
skipped):
- resolve the root playwright config in pnpm test:visual (S8)
- prune dead VERCEL_ENV from turbo.json globalEnv (S9)
- drop the duplicate chromium install in the storybook CI job (S10)
- wire scripts/**/*.test.mjs under a dedicated vitest runner
(vitest.scripts.config.mjs + pnpm test:scripts + CI validate step);
convert node:test imports to vitest keeping node:assert; fix the
work-tree fixtures to mirror the docs/work/epics/ layout
- ignore *.tsbuildinfo repo-wide and untrack the committed build state
- align every @trpc/* range on ^11.18.0 so the workspace resolves to a
single version (peer-warning-free install)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
AGENTS.md now describes the Veect control plane (ADR-027/028/029,
docs/product/ authority table, glossary Veect-domain vocabulary), with
the package map, boundary tags, and per-package conventions verified
against the filesystem (auth + 11 core + 3 tooling packages;
web-next/cms/storybook apps) and code examples drawn from the real auth
feature. Adds warning notes for known generator staleness — the
release-please per-feature registration that would collide with the
root-only v* tag policy, the pre-shipped trace overwrite hazard (zod
incident, restored in e4a3b65), the trpc template's removed
@trpc/react-query dep — and records the accepted warn-severity lint
backlog (~93 findings).
Per story amendments, the same slice prunes the dead "web-tanstack"
member from core-shared's app-tag unions (bind-otel-instrumentation.ts,
sentry/init-client.ts; tests retargeted to "web-next") and fixes the
stale app/feature tag lists in docs/architecture/overview.md. A warning
comment mirrors the release-please note at the generator call site; no
functional generator changes.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK