Files
atomic-design-poc/docs
ehoandClaude Opus 5 176e5baef8 docs: BIO2 compliance pass + consolidated backlog (agents 07, 08)
Completes the pipeline's analysis phase. Agent 07 (BIO2/ISO 27002:2022,
control set stated as an assumption since none was supplied) produced 20
findings — 12 "defect now", 8 "production gate" — and agent 08 consolidated
all 47 findings across 00/02/04/06/07 into 33 tickets, 5 ADR-fixes and a
release checklist.

Two findings are live defects rather than refactoring candidates, both
verified directly:

- RB-01/BIO-004: GET /uploads/{documentId}/content takes only (string
  documentId) — no HttpContext, so no authorization is possible. It streams
  diploma and identity scans, protected by GUID unguessability alone, while
  DELETE on the same resource is owner-scoped.
- RB-02/BIO-008: Program.cs:674 concatenates the caller's BSN into the authz
  audit Resource column, which is persisted to SQLite and rendered by the
  admin audit page. Four doc comments claim that store holds no PII; the test
  cited as enforcing it asserts on column names, so a BSN inside a column
  called Resource is invisible to it.

07 also answered the handoff from 06: in a production behandelportal build no
X-Medewerker is sent, so StubIdentityProvider returns the seeded citizen. It
fails closed on backoffice capabilities but open on citizen-scoped ones,
including CanRevealBigNummer. Root cause is IIdentityProvider.Resolve
returning a non-nullable CallerIdentity — the interface cannot express "no
identity", so any provider must invent one.

08's gate was relaxed from all-seven to the four agents that ran; _status.md
records why 01/03/05 were skipped, and the backlog carries a "Coverage"
note naming what those skips leave unowned. It caught two errors in the
orchestrator's handoff: CQ-002 is not fixed (ApplicationsStore.cancel and
AdminCasesStore.delete still swallow errors -> RB-20), and CQ-004 shipped
with half its compliance criterion unmet (PUT /admin/flags/{key} writes no
audit row -> RB-07, which blocks signing ADR-C-009).

Both agents preserved a "verified clean — do not fix" list, so a later pass
does not re-spend effort on the controls that already hold.

Consolidation halted for human approval per its spec. No source file changed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-27 09:52:13 +02:00
..

Documentation

Docs are split by kind, and kept out of each other's way:

  • reference/ — information. How the system works and why: architecture, decisions (ADRs), the FP/TEA/atomic learning guide, accessibility and UX reference. Stable knowledge, not tied to a sprint.
  • project/ — administration. Planning and tracking: the work-package backlog, product requirements (PRDs), and the (superseded) roadmap. This is the moving, process-facing material.

Teaching material that is best read next to the components lives in Storybook, not here — see the Foundations section (libs/shared/docs/*.mdx, run npm run storybook). The reference/ docs are the long-form source; the Foundations pages are the condensed, cross-linked curriculum.

Starting out? Foundations → Learning Path (libs/shared/docs/learning-path.mdx) is a paced, hands-on three-day route through the codebase; Foundations → Overview (overview.mdx) is the map of every idea, cross-linked.

reference/ — information

Doc What it is
architecture/ARCHITECTURE.md The architecture walkthrough: contexts/layers, state management, parse-don't-validate, the feature recipe, the .NET backend seam.
architecture/0001-bff-lite-decision-dtos.md ADR — BFF-lite endpoints + decision DTOs (backend decides, FE renders).
architecture/0002-user-groups-and-bounded-contexts.md ADR — user groups as actors; identity vs authorization.
architecture/0003-cibg-huisstijl.md ADR — adopt CIBG Huisstijl (vendored Bootstrap 5.2) + the token bridge.
architecture/0004-stamdata-as-code.md ADR — business-tunable reference data as typed, compile-time-validated config (not a production DB).
architecture/0005-openzaak-behind-bff.md ADR — connect to OpenZaak (ZGW APIs) behind the BFF via a config-gated data-source seam; the FE never changes.
architecture/0006-test-data-builders.md ADR — build test data through the production door: type-state builders, reducer replay, and which fixture idiom fits which test.
openzaak-integration.md How the BFF sources cases from OpenZaak (the IZaakSource seam + ZGW client), and how to add the next slice.
../backend/openzaak/README.md Docker harness for running OpenZaak locally: bring-up, integration test, notifications, teardown.
stamdata.md How stamdata (config-as-code reference data) is laid out, how to add a table with zero UI code, and why coupling stays low.
audit-log.md How the data-minimised authz/PII-reveal audit trail is built, how to audit a new action, and the one-producer-hub coupling.
feature-flags.md How runtime feature flags work (catalog-as-code + runtime state), how to add one, and the hand-wired gating coupling to watch.
scaffolding.md How code generation & scaffolding work: plop generators (gen:value-object/gen:form-machine), the NSwag client (gen:api), showcase snippets, and the skill recipes.
roles-and-access.md The roles/actors + capability model: who can do what, how to switch roles in dev, and what each unlocks.
architecture/dependencies.md Bounded-context + atomic-layer boundaries: the allowed-import rules, how they're enforced (dep:check) and visualized (dep:graph).
architecture/dependency-graph.md Generated mermaid graph of contexts × layers (regenerate with npm run dep:graph).
fp-tea-atomic-design.md Long-form learning guide: FP + The Elm Architecture + atomic design.
wcag-checklist.md Manual WCAG checks automation can't catch (tab order, focus traps, reflow).
ui-ux-audit.md Early UI/UX audit against NL Design System (predates ADR-0003 — read in that light).

project/ — administration

Doc What it is
backlog/README.md The work-package backlog index — the live tracker, with the session protocol.
prd/0001-mijn-aanvragen-en-wizardstatus.md PRD — "Mijn aanvragen": running wizards, application status, document preview.
prd/0002-attribute-based-access-control.md PRD — attribute-based access control in the UI.
prd/0003-brief-v2-demo-script.md Demo script — Brief v2 scenarios mapped to a URL + click path (WP-28).
SHOWCASE-ROADMAP.md Superseded roadmap (absorbed into project/backlog/) — kept for history.