Ports the upstream compliance-core audit fixes onto the kept core-dsr,
core-consent, core-audit, core-cms and core-shared packages (pristine
template state here, so taken to the fixed end-state):
- core-dsr: scope DSR operations to the caller's own subject (A11);
include the subject's audit trail in exports; resolve the per-request
binding from ctx instead of a throwing singleton proxy.
- core-consent: build the consent router from the shared superjson
transformer (A10); merge per-category on persist instead of replacing;
validate migrated categories against an allow-list.
- core-audit: keyed 128-bit pseudonyms + salted DSR certificate; add the
audit-logs collection and the req-scoped GDPR audit-erasure afterDelete
hook (A6).
- core-shared: grace-purge soft-deleted rows via a retention-purge task +
tombstone field and boot registration (A2/A3); add the
require-authenticated tRPC helper; derive clientIp + resolve the session
user in createTrpcContext (B2/A11).
- core-cms: register audit-logs, wire the audit-erasure hook and
retention-purge tasks; adapted to our collection set (users, workspaces).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
AGENTS.md now describes the Veect control plane (ADR-027/028/029,
docs/product/ authority table, glossary Veect-domain vocabulary), with
the package map, boundary tags, and per-package conventions verified
against the filesystem (auth + 11 core + 3 tooling packages;
web-next/cms/storybook apps) and code examples drawn from the real auth
feature. Adds warning notes for known generator staleness — the
release-please per-feature registration that would collide with the
root-only v* tag policy, the pre-shipped trace overwrite hazard (zod
incident, restored in e4a3b65), the trpc template's removed
@trpc/react-query dep — and records the accepted warn-severity lint
backlog (~93 findings).
Per story amendments, the same slice prunes the dead "web-tanstack"
member from core-shared's app-tag unions (bind-otel-instrumentation.ts,
sentry/init-client.ts; tests retargeted to "web-next") and fixes the
stale app/feature tag lists in docs/architecture/overview.md. A warning
comment mirrors the release-please note at the generator call site; no
functional generator changes.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK