Files
agentic-dev/apps
Danijel Martinek 932d7f381e feat(web-next): resolve session user + live compliance context and rate limits
Ports the upstream web-next compliance wiring onto the clean-slate
auth-shell app, adapted to the auth-only collection set (no workspaces
feature on this branch):

- add a per-request createWebNextTrpcContext (A11): derives clientIp (B2),
  resolves the authenticated user from the session cookie via the auth
  feature's denylist-aware validateSession plus a role snapshot (B7), and
  threads the boot-time consent factory + DSR binding so the mounted
  consent/dsr routers are live instead of dead stubs.
- bind the production/dev-seed consent + DSR compliance bindings in
  bind-production and expose them via getComplianceBindings; kick off the
  retention purge cycle (A3).
- enforce manifest rate limits on the production path: bind
  InMemoryRateLimit seeded from the auth manifest's budgets (A4/B3) while
  dev-seed keeps the no-op limiter. Adds a regression test driving sign-in
  through the real production binder + app router.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
2026-07-13 06:14:02 +02:00
..