Files
atomic-design-poc/docs/project/refactor-backlog-setup
ehoandClaude Opus 5 de349e702e test(auth): extract and spec the stored-session parse boundary (RB-10)
SessionStore.restore() — identical in both apps — read localStorage itself
and did the parse plus shape validation in the same module-private function,
invoked from a field initializer, so the storage read happened the instant
the singleton was constructed and no spec could feed it a raw string. The
logic it guards is a trust boundary, not incidental validation: the comment
above it names G1 (never persist the BSN) and G2 (validate the shape before
trusting it), and CLAUDE.md mandates a spec for boundary parse* adapters.
ssp/auth and bhp/auth were jointly the worst-covered frontend modules.

parseStoredSession(raw) moves into each app's auth/domain/session.ts, which
is pure TS and already had a spec, so no new scaffolding was needed;
restore() collapses to one line. Four cases: absent, non-JSON, wrong shape,
and — BIO-017's addition — a stored {"bsn":…,"naam":…} restoring with bsn
'', which makes the G1 guarantee executable rather than merely commented.
Verified red without the fix.

Landed twice, once per app, deliberately. TE-001 and BL-002 both say an
extract-to-shared here would contradict ADR-0002, which models the two
actors as different Principal variants and expects the two auth contexts to
diverge; RB-13 is what differentiates them.

Also specs redactProfile (BIO-017's second half) — a pure exported
PII-redaction function that had none.

behaviour-spec.mdx is regenerated, which also picks up the test names RB-07
added; that commit should have carried them and did not.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-27 14:08:06 +02:00
..

Refactoring backlog — automated setup

What's in this package

refactor-backlog-setup/
  setup.sh                     ← run this once, from the root of the target repo
  agents/                      ← source prompts (edit these if you need to tweak
                                  scope/wording before running setup.sh)
    _persistence-protocol.md
    00-baseline.prompt.md
    01-readability.prompt.md
    02-testability.prompt.md
    03-ddd-hexagonal.prompt.md
    04-cqrs-light.prompt.md
    05-bdd.prompt.md
    06-adr-conformance.prompt.md
    07-bio2-compliance.prompt.md
    08-consolidation.prompt.md
    09-implementation.prompt.md  (template — one TICKET-ID per Phase 3 dispatch)

Usage

  1. Copy this refactor-backlog-setup/ folder into the root of the target repo (or reference it via a relative path).
  2. Edit anything in agents/ if scope/exclusions need repo-specific detail (e.g. exact module paths, ADR folder location) — the prompts currently use the defaults agreed in the design conversation.
  3. Run:
    bash refactor-backlog-setup/setup.sh
    
    This creates ./refactor-backlog/ with:
    • _status.md initialized, all agents not_started
    • 00-baseline.md through 07-bio2-compliance.md initialized with headers
    • 99-backlog.md empty, ready for Consolidation
    • implementation/ folder for Phase 3 notes
    • final-prompts/ — every agent prompt with the persistence protocol already merged in. These are the exact prompts to dispatch — no manual copy-paste needed.

Dispatch order

  1. Dispatch final-prompts/00-baseline.prompt.md (Opus). Wait for _status.md → baseline: complete.
  2. Dispatch the 7 Phase 1 prompts in parallel (Opus): 01 through 07. Each checks its own dependency in _status.md before starting.
  3. Once all 7 show complete, dispatch final-prompts/08-consolidation.prompt.md (Opus). It writes 99-backlog.md and halts for human approval — check the file for any ADR-fix or BIO2-flagged tickets before proceeding.
  4. For each approved ticket, copy final-prompts/09-implementation.prompt.md, fill in TICKET-ID:, dispatch (Sonnet). Run tickets in parallel within a CD batch, sequential across batches, per the Depends on column in 99-backlog.md.

Re-running / resuming

Safe to re-run setup.sh only on a fresh workspace — it does not check for an existing ./refactor-backlog/ and will overwrite _status.md and the phase output files. If a run is already in progress, don't re-run setup.sh; just re-dispatch the relevant final-prompts/*.prompt.md — each agent reads _status.md and its own output file first and resumes from where it left off.