DELETE /admin/uploads/{documentId} was gated by a standalone
`X-Admin: true` header check (`IsAdmin`), outside the `Authz` module
entirely and outside the `CasesAdmin`/`StamdataAdmin`/`OrgAdmin`/
`FlagsAdmin` wrappers the four sibling admin surfaces use. It wrote no
AuthzAuditStore row, so a destructive cross-owner document delete never
appeared on /beheer/audit. A repo-wide grep confirmed the only sender of
X-Admin was the backend test itself — no frontend or e2e path depends on
it — so the gate was safe to delete outright.
Routed the endpoint through CasesAdmin (Authz.CanManageCases), the same
wrapper the other admin-cases endpoints use. RB-07 already moved
AuditAuthz onto every *Admin wrapper's allow path, so this gets the
missing audit row for free with no second AuditAuthz call. Deleted the
now-unused IsAdmin function and updated the two comments that referenced
the old X-Admin seam.
Updated EndpointTests.cs's Admin_delete_requires_admin_role to send
X-Role: admin instead of X-Admin: true, and added
AuthzAuditTests.An_admin_upload_delete_is_recorded, which asserts the
cases:manage/allow row count increases by exactly one (a plain
Contains would already be satisfied by this test class's other
cases:manage calls). Verified both tests fail red against the
pre-fix gate.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Refactoring backlog — automated setup
What's in this package
refactor-backlog-setup/
setup.sh ← run this once, from the root of the target repo
agents/ ← source prompts (edit these if you need to tweak
scope/wording before running setup.sh)
_persistence-protocol.md
00-baseline.prompt.md
01-readability.prompt.md
02-testability.prompt.md
03-ddd-hexagonal.prompt.md
04-cqrs-light.prompt.md
05-bdd.prompt.md
06-adr-conformance.prompt.md
07-bio2-compliance.prompt.md
08-consolidation.prompt.md
09-implementation.prompt.md (template — one TICKET-ID per Phase 3 dispatch)
Usage
- Copy this
refactor-backlog-setup/folder into the root of the target repo (or reference it via a relative path). - Edit anything in
agents/if scope/exclusions need repo-specific detail (e.g. exact module paths, ADR folder location) — the prompts currently use the defaults agreed in the design conversation. - Run:
This creates
bash refactor-backlog-setup/setup.sh./refactor-backlog/with:_status.mdinitialized, all agentsnot_started00-baseline.mdthrough07-bio2-compliance.mdinitialized with headers99-backlog.mdempty, ready for Consolidationimplementation/folder for Phase 3 notesfinal-prompts/— every agent prompt with the persistence protocol already merged in. These are the exact prompts to dispatch — no manual copy-paste needed.
Dispatch order
- Dispatch
final-prompts/00-baseline.prompt.md(Opus). Wait for_status.md→ baseline: complete. - Dispatch the 7 Phase 1 prompts in parallel (Opus):
01through07. Each checks its own dependency in_status.mdbefore starting. - Once all 7 show
complete, dispatchfinal-prompts/08-consolidation.prompt.md(Opus). It writes99-backlog.mdand halts for human approval — check the file for anyADR-fixor BIO2-flagged tickets before proceeding. - For each approved ticket, copy
final-prompts/09-implementation.prompt.md, fill inTICKET-ID:, dispatch (Sonnet). Run tickets in parallel within a CD batch, sequential across batches, per theDepends oncolumn in99-backlog.md.
Re-running / resuming
Safe to re-run setup.sh only on a fresh workspace — it does not check for an
existing ./refactor-backlog/ and will overwrite _status.md and the phase
output files. If a run is already in progress, don't re-run setup.sh; just
re-dispatch the relevant final-prompts/*.prompt.md — each agent reads
_status.md and its own output file first and resumes from where it left off.