Files
atomic-design-poc/docs/project/refactor-backlog-setup
ehoandClaude Opus 5 8b8b522052 fix(auth): make no-identity representable; stub dev-only (RB-09)
IIdentityProvider.Resolve returned a non-nullable CallerIdentity, so
the interface could not express "no identity" - StubIdentityProvider
was forced to invent one for any request carrying no credential at
all. Consequence: a production behandelportal build sends no
X-Medewerker header (medewerkerInterceptor is dev-only), so it used
to authenticate as the seeded citizen, role drafter - failing closed
on backoffice capabilities but open on every citizen-scoped endpoint,
including CanRevealBigNummer.

Resolve now returns CallerIdentity?. StubIdentityProvider keeps a
non-nullable return type (a valid narrower override) since it never
itself has "no identity" to report - it is registered only under
IsDevelopment() now. Production registers nothing and throws an
InvalidOperationException immediately during startup instead: there
is no real DigiD/employee-SSO provider in this POC yet, so a
misconfigured Production deploy must fail before serving a single
request, not resolve one per request. The identity-resolution
middleware turns a null resolution into a 401 rather than passing it
downstream.

Added StubIdentityProviderTests.Never_returns_null_even_with_no_headers_at_all
and ProductionIdentityProviderTests, which builds its own
WebApplicationFactory<Program> with UseEnvironment("Production") and
asserts startup throws. Verified both new tests fail red against the
pre-fix code.

RB-01's residual (GET /uploads/{id}/content reached via plain browser
navigation, no identity header) is confirmed unchanged in Development
and its Production consequence is written up in
implementation/rb-09.md for whoever lands the real identity provider -
no signed-URL/cookie scheme was designed here, per scope.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-27 14:06:49 +02:00
..

Refactoring backlog — automated setup

What's in this package

refactor-backlog-setup/
  setup.sh                     ← run this once, from the root of the target repo
  agents/                      ← source prompts (edit these if you need to tweak
                                  scope/wording before running setup.sh)
    _persistence-protocol.md
    00-baseline.prompt.md
    01-readability.prompt.md
    02-testability.prompt.md
    03-ddd-hexagonal.prompt.md
    04-cqrs-light.prompt.md
    05-bdd.prompt.md
    06-adr-conformance.prompt.md
    07-bio2-compliance.prompt.md
    08-consolidation.prompt.md
    09-implementation.prompt.md  (template — one TICKET-ID per Phase 3 dispatch)

Usage

  1. Copy this refactor-backlog-setup/ folder into the root of the target repo (or reference it via a relative path).
  2. Edit anything in agents/ if scope/exclusions need repo-specific detail (e.g. exact module paths, ADR folder location) — the prompts currently use the defaults agreed in the design conversation.
  3. Run:
    bash refactor-backlog-setup/setup.sh
    
    This creates ./refactor-backlog/ with:
    • _status.md initialized, all agents not_started
    • 00-baseline.md through 07-bio2-compliance.md initialized with headers
    • 99-backlog.md empty, ready for Consolidation
    • implementation/ folder for Phase 3 notes
    • final-prompts/ — every agent prompt with the persistence protocol already merged in. These are the exact prompts to dispatch — no manual copy-paste needed.

Dispatch order

  1. Dispatch final-prompts/00-baseline.prompt.md (Opus). Wait for _status.md → baseline: complete.
  2. Dispatch the 7 Phase 1 prompts in parallel (Opus): 01 through 07. Each checks its own dependency in _status.md before starting.
  3. Once all 7 show complete, dispatch final-prompts/08-consolidation.prompt.md (Opus). It writes 99-backlog.md and halts for human approval — check the file for any ADR-fix or BIO2-flagged tickets before proceeding.
  4. For each approved ticket, copy final-prompts/09-implementation.prompt.md, fill in TICKET-ID:, dispatch (Sonnet). Run tickets in parallel within a CD batch, sequential across batches, per the Depends on column in 99-backlog.md.

Re-running / resuming

Safe to re-run setup.sh only on a fresh workspace — it does not check for an existing ./refactor-backlog/ and will overwrite _status.md and the phase output files. If a run is already in progress, don't re-run setup.sh; just re-dispatch the relevant final-prompts/*.prompt.md — each agent reads _status.md and its own output file first and resumes from where it left off.