--- id: 02-migrate-auth-binders epic: binder-wrap-helper title: Migrate auth feature binders to wireUseCase type: technical-story status: todo feature: auth depends-on: [01-wire-use-case-helper] blocks: [08-holistic-validation] --- ## Goal Replace the inline `withSpan + withCapture (+ optional withAudit)` blocks in `packages/auth/src/di/bind-production.ts` and `packages/auth/src/di/bind-dev-seed.ts` with `wireUseCase` calls for all three auth use cases (signIn, signUp, signOut). ## Why Auth's binder pair contributes one of the five top-ten `pnpm fallow` clone groups. The inline wrap blocks are ~30–79 lines of mechanical boilerplate that adds noise to every auth binder diff. ## Done when - `bind-production.ts` and `bind-dev-seed.ts` call `wireUseCase` for signIn, signUp, and signOut — no inline `withSpan(... withCapture(...))` pattern remains in either file. - Audit-bearing use cases (per manifest check) pass `auditLog` + audit schema to `wireUseCase`; non-audit use cases omit it. - `pnpm test --filter @repo/auth` green (binder tests + integration tests). - `pnpm typecheck --filter @repo/auth` green. - `assertFeatureConformance` does not throw at boot for auth (brands + manifest match). ## In scope - `packages/auth/src/di/bind-production.ts` — use-case binding blocks only. - `packages/auth/src/di/bind-dev-seed.ts` — use-case binding blocks only. - Repository and service bindings stay as-is (direct `.toConstantValue()` calls). - Controller bindings stay as-is (controllers are out of scope for this PRD). ## Out of scope - Controller bindings — deferred follow-up per PRD. - Changes to auth use-case implementations, schemas, or tests outside the binder. - Changes to `assertFeatureConformance` or the manifest. ## Tasks - [ ] Read `packages/auth/src/feature.manifest.ts` — identify which use cases declare `audits: [...]` (non-empty) vs `audits: []` - [ ] Read `packages/auth/src/di/bind-production.ts` — understand current inline wrap shape and which deps each use case receives - [ ] Read `packages/auth/src/di/bind-dev-seed.ts` — same for dev-seed mode - [ ] Update `packages/auth/src/di/bind-production.ts` — replace all three inline wrap blocks with `wireUseCase` calls; pass `auditLog` + schema for audit-bearing use cases - [ ] Update `packages/auth/src/di/bind-dev-seed.ts` — same - [ ] Run `pnpm test --filter @repo/auth` — verify all tests pass - [ ] Run `pnpm typecheck --filter @repo/auth` — verify no type regressions