Curated, product-agnostic snapshot of the post-story-04 tree: demo content deleted, auth-only reference feature, web-next shell, all gates green. Product-specific docs, ADRs 027-029, PRDs/epics/archive, editor library traces, and product naming are curated out; generic template repairs (coverage provider devDeps, root test:coverage script, live lint fixes, root-only release-please) are kept. See TEMPLATE.md for provenance, curation list, and usage. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016j8z4VHjedXDTjEDNg7qHK
1.5 KiB
1.5 KiB
@repo/core-dsr
Optional core package providing GDPR Data Subject Rights (DSR) interfaces and implementations. Scaffold via pnpm turbo gen core-package dsr.
Structure
src/
data-export.interface.ts # IDataExport — exportSubjectData
data-delete.interface.ts # IDataDelete — deleteSubjectData
data-rectify.interface.ts # IDataRectify — updateSubjectField
processing-restriction.interface.ts # IProcessingRestriction — setRestriction, isRestricted
dsr-types.ts # UserDataBundle, DeletionCertificate, DSR value types
contexts/
user-data.jsonld # schema.org JSON-LD @context
index.ts # Barrel export
Design
Four interfaces map directly to GDPR Articles 15–18 + 20:
IDataExport(Art. 15/20) — export a subject's data asUserDataBundleIDataDelete(Art. 17) — soft-delete or cascade-hard-delete subject data; returnsDeletionCertificateIDataRectify(Art. 16) — update a specific field for a subjectIProcessingRestriction(Art. 18) — toggle and read the processing restriction flag
Implementations walk custom.pii-tagged fields and custom.subject-linked collections. Row semantics:
kind: "self" | "owner"→ directly owned by the subject (export full; delete hard or soft)kind: "reference"→ references the subject from another entity (export redacted; redact link on delete)
See docs/architecture/agent-first-workflow-and-conformance.md for the DI conventions.