Ports the upstream compliance-core audit fixes onto the kept core-dsr,
core-consent, core-audit, core-cms and core-shared packages:
- core-dsr: scope DSR operations to the caller's own subject (A11);
include the subject's audit trail in exports; resolve the per-request
binding from ctx instead of a throwing singleton proxy.
- core-consent: build the consent router from the shared superjson
transformer (A10); merge per-category on persist instead of replacing;
validate migrated categories against an allow-list.
- core-audit: keyed 128-bit pseudonyms + salted DSR certificate; add the
audit-logs collection and the req-scoped GDPR audit-erasure afterDelete
hook (A6).
- core-shared: grace-purge soft-deleted rows via a retention-purge task +
tombstone field and boot registration (A2/A3); add the
require-authenticated tRPC helper; derive clientIp + resolve the session
user in createTrpcContext (B2/A11).
- core-cms: register audit-logs, wire the audit-erasure hook and
retention-purge tasks; adapted to the clean-slate collection set
(users only — no workspaces feature on this branch).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK