Close the cover-the-diff (L1, ADR-020) gaps the port opened:
- auth router: exercise the signUp/signOut procedure handlers through the
container-resolved caller (reformatted onto new lines by the port).
- core-dsr export: add an audit-doc case with array-valued changedFields /
piiCategories and an absent actorRoles, covering the optional-field
branches of the new audit-trail mapper.
- coverage:diff excludes: mirror the vitest coverage excludes for
core-trpc/src/providers/** and core-shared/src/trpc/context.ts so
changes to coverage-excluded framework glue don't fail the diff gate.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
Ports the upstream auth audit fixes onto the kept auth feature:
- revoke sessions server-side via an in-memory jti denylist (B5):
createSession embeds the session id as the JWT jti, invalidateSession
denylists it for the max token lifetime, validateSession rejects
denylisted and jti-less (fail-closed) tokens; constant-time signature
comparison (B4). Adds session-denylist.ts + test.
- cover signToken/verifyToken/validateSession crypto paths without a
running Payload by stubbing the payload module (B8).
- derive clientIp server-side from trusted proxy headers and drop it from
the public sign-in input schema; thread it as a server-only request
context argument so a client can no longer spoof its rate-limit bucket
(B2).
- declare the auth-injected email (and displayName) in the users
collection-level DSR pii map so Art. 15 export and Art. 17 soft delete
cover them (A5). Adapted to the clean-slate collection set.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK