Shell home for the platform-retrofit floor: a sign-in form (dev-seed
credentials) and a signed-in placeholder with sign-out. Both flows run
through the composed tRPC appRouter via server actions that own the
session cookie on the app side; the auth feature is untouched. Adds the
auth sign-in Playwright spec as the surviving e2e baseline and drops the
last demo-template metadata.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
Veect retrofit (ADR-027): fifth and final slice of the demo-content
removal. Deletes packages/navigation whole and prunes every composition
edge in one commit: core-api router mount + dep + router test, core-cms
header-global composition + dep + regenerated Payload types (globals
now empty), web-next bindAll (prod + dev-seed) + tests + Tailwind
source + transpilePackages + dep, cms/core-cms payload config test
assertions, home e2e nav assertion, tsconfig paths, fallow
ignoreDependencies entry, anchor-guard FEATURES list, generator e2e
strip lists + reference-feature comments (navigation -> auth, incl.
feature templates + scaffolding guide), lockfile prune, and
feature-list doc trims (CLAUDE.md, AGENTS.md, glossary, app/feature
AGENTS.md). Compliance YAML regeneration produced no churn (navigation
declared no PII).
Cycle break: navigation's UI hooks were the last edge closing the
committed core-trpc -> core-api -> navigation -> core-trpc package
cycle. With it gone, the lint turbo task graph builds for the first
time and every package's ESLint executes; the epic's lint waiver
expires here. Latent findings: 3 errors, all mechanical, fixed
in-slice - require() import in turbo/generators/config.ts
(no-require-imports), literal type assertion in auth's
authentication.service.ts (prefer-as-const), and next-env.d.ts
triple-slash in apps/cms (rule scoped off for that generated file,
mirroring web-next's existing override). 99 warn-severity findings
remain across 5 packages (pii-declaration-must-be-complete on test
fixtures, turbo/no-undeclared-env-vars on test env keys) - all
warn-by-design, non-gating.
core-trpc keeps a consumer (apps/web-next providers) and stays per
ADR-027. Its unused @trpc/react-query dependency, surfaced by the
post-deletion fallow audit, is removed rather than ignore-listed -
core-trpc's hooks use @trpc/tanstack-react-query. Remaining fallow
warn (auth validateSession "unused member") is a false positive: the
method implements IAuthenticationService and is exercised in
container.test.ts; auth stays untouched as the regression canary.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
Veect retrofit (ADR-027): fourth slice of the demo-content removal.
Deletes packages/marketing-pages whole and prunes every composition
edge in one commit: core-api router mount + dep, core-cms
collection/global composition + dep + regenerated Payload types,
web-next bindAll (prod + dev-seed) + tests + about page + Tailwind
source + transpilePackages + dep, cms/core-cms payload config test
assertions, marketing-page e2e spec, tsconfig paths, fallow ignore
entry, anchor-guard + generator e2e feature lists, compliance
data-map + retention-policy regeneration, lockfile prune, and
feature-list doc entries (CLAUDE.md, AGENTS.md, glossary, app/feature
AGENTS.md).
Event teardown: marketing-pages was the sole consumer of
auth.user.signed-up (welcome-email handler + job). The handler, its
Payload tasks, and the bus subscription all lived inside the package's
own binders, so they die with it — no other package wires the
subscription. Auth's manifest `publishes` stays untouched: a publisher
with zero consumers is legal (pnpm conformance only fails on orphan
consumers, verified green). The app-level sign-up-welcome-email test
asserted the marketing-pages mailer stays empty without a bus; it is
deleted with the feature, and the now-unused test-only bind-state
helpers in web-next bind-production.ts go with it.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
Veect retrofit (ADR-027): third slice of the demo-content removal.
Deletes packages/media whole and prunes every composition edge in one
commit: core-api router mount + dep, core-cms collection composition +
dep + regenerated Payload types, web-next bindAll (prod + dev-seed) +
tests + Tailwind source + transpilePackages + dep, cms/core-cms/web-next
payload config test assertions, tsconfig paths, anchor-guard + generator
e2e feature lists, compliance data-map + retention-policy regeneration,
lockfile prune, and feature-list doc entries (CLAUDE.md, AGENTS.md,
glossary, app/feature AGENTS.md).
Media was the uploads feature: the marketing-pages pages.hero.image and
navigation header.logo upload fields (relationTo: "media") are removed
from those collections in this slice — Payload config sanitization
rejects a relationship to a missing collection. Both features' domain
entities keep their optional imageId/logoId fields; their repositories
already tolerate the fields being absent. Both features are deleted in
later slices.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
Veect retrofit (ADR-027): the template's demo content is being removed
to make room for the Veect package map. This slice deletes
packages/blog whole and prunes every composition edge in one commit:
core-api router mount, core-cms collections + regenerated Payload
types, web-next bindAll entry / home page / blog route / Tailwind
sources, blog e2e spec, tsconfig paths, fallow ignore entry,
anchor-guard + generator e2e feature lists, compliance artifacts,
and feature-list doc entries (CLAUDE.md, AGENTS.md, glossary).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
Veect retrofit (ADR-027): the product is a hosted SaaS built on
web-next; apps/web-tanstack existed only as template demo surface for
the TanStack Start framework path. This slice removes the app and all
wiring that referenced it:
- turbo.json globalEnv: WEB_TANSTACK_SENTRY_DSN,
VITE_WEB_TANSTACK_SENTRY_DSN, VITE_GIT_COMMIT_SHA,
SENTRY_PROJECT_WEB_TANSTACK
- .env.example: the same four DSN/release vars
- generator e2e fixtures that stripped deps from the app's package.json
- coverage diff comment + test fixtures referencing apps/web-tanstack
- app-list entries in README, CLAUDE.md (port table, Sentry projects),
AGENTS.md (tags, binder list, per-app docs), docs/glossary.md (App)
- pnpm-lock.yaml importer + orphaned transitive deps
Framework-support code in core packages stays: core-trpc's TanStack
provider, core-shared security/tanstack middleware, and the Sentry
react/node init adapters are generic TanStack support, not app wiring.
Prose in guides/ADRs/library traces is story 08 scope.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
The template baseline shipped 9 packages without @vitest/coverage-v8
and documented an L0 invocation turbo cannot parse — the full coverage
sweep had never run. Adds the provider (pinned to the feature-package
spec), a root test:coverage script, corrects every live doc/prompt/CI
occurrence, and calibrates coverage excludes for the 4 packages whose
latent threshold failures the outage masked (framework glue only —
zero threshold numbers changed). L0 sweep now passes 21/21.
Squash of a284baa + 5c6af95 (worktree-agent-a013c67cea83b2636),
implemented and reviewed via the dispatch loop under the epic's
baseline waiver (lint pending story 03).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK