Files
atomic-design-poc/docs/project/backlog
ehoandClaude Opus 4.8 c404995980
CI / frontend (push) Failing after 31s
CI / storybook-a11y (push) Failing after 30s
CI / backend (push) Failing after 30s
CI / e2e (push) Failing after 30s
CI / semgrep (push) Failing after 30s
CI / api-client-drift (push) Failing after 30s
ci: replace CodeQL with Semgrep (Gitea-compatible SAST)
CodeQL is GitHub-only — its analyze step uploads SARIF to GitHub's code-scanning
API and assumes a GitHub Security tab; this CI runs on Gitea only, so the job could
never go green (it had been red since it was added). Replace it with Semgrep OSS, a
plain CLI SAST with no account/platform API, which runs fine on Gitea.

- Remove the codeql job (+ its security-events permission) and the schedule trigger
  (it existed only for codeql; semgrep runs on push + PR).
- Add a semgrep job: setup-python + `pip install semgrep` +
  `semgrep scan --config p/default --config p/csharp --metrics=off`. pip-on-runner
  (not container:) mirrors the other jobs' model; anonymous registry, telemetry off.
- Report-only for now (no --error → job stays green): a local dry-run found 27
  findings, mostly CI/config policy (unpinned actions, .npmrc), not app-code vulns.
  WP-30 tracks triaging them + flipping to --error (a blocking gate).

Verified locally: `semgrep scan` runs clean (exit 0 without --error, 306 rules /
450 files). CI behaviour confirmable only on the Gitea runner — watch the run.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-22 09:34:13 +02:00
..

Backlog — showcase hardening

Ordered work packages that take this POC from "good" to reference showcase: CIBG design-system fidelity, DDD/FP consistency, Storybook as curriculum, and WCAG compliance with automated gates. Source: the architecture/CIBG/a11y audit of 2026-07-02 (plan: "Showcase hardening").

This backlog supersedes docs/project/SHOWCASE-ROADMAP.md.

Session protocol

  • Switch to Opus first (/model opus) before tackling any WP.
  • One WP per session. Read CLAUDE.md, this README, the WP file, and the WP's "Read first" list — then execute. Do not start the next WP in the same session.
  • The Decisions block in each WP is pre-made — don't relitigate it.
  • A WP ends GREEN (below) with its acceptance criteria checked off and its Status updated to done (+ commit hash).
  • No WP leaves a lint rule/check disabled without an inline justification comment and a cross-reference to the WP that will remove it.

GREEN (global definition of done)

npm run lint && npm run check:tokens && npm test && npm run build && npm run build-storybook

From WP-01 onward, additionally:

npm run test-storybook:ci

Phases 0–5 were frontend-only; phase 6 (Brief v2) touches backend/ — for those WPs cd backend && dotnet test is part of GREEN, and any wire change ends with npm run gen:api leaving no drift.

From WP-19 onward, npm run e2e is part of CI (its own job) but NOT part of the local GREEN one-liner above — it needs the real backend + npm start already running (see WP-19's own file), so it's a separate manual/CI step, not chained into the others.

Order

Gates land before the work they cover; each lint rule lands in the same WP as the fixes for its existing violations, so every WP ends green.

WP Title Phase Status
WP-01 Axe-on-every-story CI gate 0 · gates done
WP-02 Harden check:tokens + fix what it catches 0 · gates done
WP-03 Boundaries I: contracts purity + ApiClient confinement 0 · gates done
WP-04 Boundaries II: ui ↛ infrastructure + showcase sanction 0 · gates done
WP-05 Parse-don't-validate closure + MDX 1 · FP/DDD done
WP-06 Generic async template contexts — kill $any() 1 · FP/DDD done
WP-07 Brief on the shared idioms + RemoteData MDX 1 · FP/DDD done
WP-08 One store idiom + machine naming + TEA MDX 1 · FP/DDD done
WP-09 Pure-logic closure: dates + missing command specs 1 · FP/DDD done
WP-10 CIBG button fidelity 2 · CIBG done
WP-11 CIBG markup fidelity: application-link + absent-class triage 2 · CIBG done
WP-12 CIBG Datablock for application data 2 · CIBG done
WP-13 CIBG-gap register + hygiene + MDX 2 · CIBG done
WP-14 Storybook taxonomy reorg + Layers MDX 3 · Storybook done
WP-15 Missing stories: shell + brief components 3 · Storybook done
WP-16 Component a11y: description wiring + alert role 4 · a11y done
WP-17 App-level a11y: route focus, template lint, WCAG checklist 4 · a11y done
WP-18 ABAC capability spine (Principal + capabilities, phase P1) 5 · productie-volwassenheid done
WP-19 Playwright e2e smoke 5 · productie-volwassenheid done
WP-20 Second locale proof 5 · productie-volwassenheid done
WP-21 Resilience seams (correlation-id, idempotency, retry) 5 · productie-volwassenheid done
WP-22 Durable persistence (optional tier) 5 · productie-volwassenheid done
WP-23 Org-template backend + admin role 6 · Brief v2 done
WP-24 Letter canvas (edit on the letter) 6 · Brief v2 done
WP-25 Server-rendered letter preview (HTML; PDF deferred) 6 · Brief v2 todo
WP-26 Admin org-template editor 6 · Brief v2 done
WP-27 Brief UX layer (undo/redo, standaardbrief, diff) 6 · Brief v2 todo
WP-28 Brief v2 demo polish (scenarios, e2e, docs) 6 · Brief v2 todo
WP-29 Stamdata beheer editor (low-code, PR-emitting) follow-on · ADR-0004 done
WP-30 CI performance follow-ups (node_modules cache, runner image, path filters) follow-on · CI/infra todo

Sequencing dependencies (stated in the WPs too): 01 before 10–15 (axe covers story churn); 03/04 before 05–09 (boundaries stop new violations during refactors); 06 before 07 (typed <app-async> before brief adopts it); 13 defines the gap-marker format that 11/12 reference — if 11/12 run first, they define it and 13 adopts it. 18–22 (phase 5, "productie-volwassenheid") are independent of each other and of phases 1–4 — pick any order; 18 is the recommended first pick (it's the headline gap: no authorization spine exists yet, and it closes the FE-computed-authz anti-pattern in brief.store.ts). 22 is explicitly lower priority — the current in-memory persistence is a documented, defensible POC choice, not a bug. Phase 6 (Brief v2, the "Brief opstellen v2" PRD) is strictly ordered 23 → 24 → 25 → 26 → 27 → 28: 24 needs 23's orgTemplate on the wire, 25 needs 24's letter.css contract, 26 needs 23's endpoints + 24's canvas, 27/28 polish on top.

WP template

# WP-NN — Title

Status: todo | in-progress | done (<commit>)
Phase: N — name

## Why

## Read first

## Decisions (pre-made, don't relitigate)

## Files

## Steps

## Acceptance criteria

## Verification

## Out of scope

## Risks