Completes the pipeline's analysis phase. Agent 07 (BIO2/ISO 27002:2022,
control set stated as an assumption since none was supplied) produced 20
findings — 12 "defect now", 8 "production gate" — and agent 08 consolidated
all 47 findings across 00/02/04/06/07 into 33 tickets, 5 ADR-fixes and a
release checklist.
Two findings are live defects rather than refactoring candidates, both
verified directly:
- RB-01/BIO-004: GET /uploads/{documentId}/content takes only (string
documentId) — no HttpContext, so no authorization is possible. It streams
diploma and identity scans, protected by GUID unguessability alone, while
DELETE on the same resource is owner-scoped.
- RB-02/BIO-008: Program.cs:674 concatenates the caller's BSN into the authz
audit Resource column, which is persisted to SQLite and rendered by the
admin audit page. Four doc comments claim that store holds no PII; the test
cited as enforcing it asserts on column names, so a BSN inside a column
called Resource is invisible to it.
07 also answered the handoff from 06: in a production behandelportal build no
X-Medewerker is sent, so StubIdentityProvider returns the seeded citizen. It
fails closed on backoffice capabilities but open on citizen-scoped ones,
including CanRevealBigNummer. Root cause is IIdentityProvider.Resolve
returning a non-nullable CallerIdentity — the interface cannot express "no
identity", so any provider must invent one.
08's gate was relaxed from all-seven to the four agents that ran; _status.md
records why 01/03/05 were skipped, and the backlog carries a "Coverage"
note naming what those skips leave unowned. It caught two errors in the
orchestrator's handoff: CQ-002 is not fixed (ApplicationsStore.cancel and
AdminCasesStore.delete still swallow errors -> RB-20), and CQ-004 shipped
with half its compliance criterion unmet (PUT /admin/flags/{key} writes no
audit row -> RB-07, which blocks signing ADR-C-009).
Both agents preserved a "verified clean — do not fix" list, so a later pass
does not re-spend effort on the controls that already hold.
Consolidation halted for human approval per its spec. No source file changed.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Refactoring backlog — automated setup
What's in this package
refactor-backlog-setup/
setup.sh ← run this once, from the root of the target repo
agents/ ← source prompts (edit these if you need to tweak
scope/wording before running setup.sh)
_persistence-protocol.md
00-baseline.prompt.md
01-readability.prompt.md
02-testability.prompt.md
03-ddd-hexagonal.prompt.md
04-cqrs-light.prompt.md
05-bdd.prompt.md
06-adr-conformance.prompt.md
07-bio2-compliance.prompt.md
08-consolidation.prompt.md
09-implementation.prompt.md (template — one TICKET-ID per Phase 3 dispatch)
Usage
- Copy this
refactor-backlog-setup/folder into the root of the target repo (or reference it via a relative path). - Edit anything in
agents/if scope/exclusions need repo-specific detail (e.g. exact module paths, ADR folder location) — the prompts currently use the defaults agreed in the design conversation. - Run:
This creates
bash refactor-backlog-setup/setup.sh./refactor-backlog/with:_status.mdinitialized, all agentsnot_started00-baseline.mdthrough07-bio2-compliance.mdinitialized with headers99-backlog.mdempty, ready for Consolidationimplementation/folder for Phase 3 notesfinal-prompts/— every agent prompt with the persistence protocol already merged in. These are the exact prompts to dispatch — no manual copy-paste needed.
Dispatch order
- Dispatch
final-prompts/00-baseline.prompt.md(Opus). Wait for_status.md→ baseline: complete. - Dispatch the 7 Phase 1 prompts in parallel (Opus):
01through07. Each checks its own dependency in_status.mdbefore starting. - Once all 7 show
complete, dispatchfinal-prompts/08-consolidation.prompt.md(Opus). It writes99-backlog.mdand halts for human approval — check the file for anyADR-fixor BIO2-flagged tickets before proceeding. - For each approved ticket, copy
final-prompts/09-implementation.prompt.md, fill inTICKET-ID:, dispatch (Sonnet). Run tickets in parallel within a CD batch, sequential across batches, per theDepends oncolumn in99-backlog.md.
Re-running / resuming
Safe to re-run setup.sh only on a fresh workspace — it does not check for an
existing ./refactor-backlog/ and will overwrite _status.md and the phase
output files. If a run is already in progress, don't re-run setup.sh; just
re-dispatch the relevant final-prompts/*.prompt.md — each agent reads
_status.md and its own output file first and resumes from where it left off.