Ports the upstream web-next compliance wiring onto the clean-slate
auth-shell app, adapted to the auth-only collection set (no workspaces
feature on this branch):
- add a per-request createWebNextTrpcContext (A11): derives clientIp (B2),
resolves the authenticated user from the session cookie via the auth
feature's denylist-aware validateSession plus a role snapshot (B7), and
threads the boot-time consent factory + DSR binding so the mounted
consent/dsr routers are live instead of dead stubs.
- bind the production/dev-seed consent + DSR compliance bindings in
bind-production and expose them via getComplianceBindings; kick off the
retention purge cycle (A3).
- enforce manifest rate limits on the production path: bind
InMemoryRateLimit seeded from the auth manifest's budgets (A4/B3) while
dev-seed keeps the no-op limiter. Adds a regression test driving sign-in
through the real production binder + app router.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK