The WP-41 GET /admin/audit trail now has an FE view: a beheer audit page (domain AuditEntry + adapter/parse + store) rendering the data-minimised trail as a read-only table, capability-gated on cases:manage. Added to ADMIN_LINKS (header nav + dashboard Beheer section) and to the role.interceptor ROLE_AWARE list so the admin-gated call carries X-Role. Closes WP-42's audit half. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2.7 KiB
WP-42 — Privacy & security showcase page
Status: done (optional Foundations MDX writeup left as a nice-to-have)
Audit view (added after WP-41)
/beheer/audit — an admin page (beheer/ui/audit.page.ts) reading the WP-41 GET /admin/audit
trail through a beheer adapter/store (domain AuditEntry + trust-boundary parse), rendered as a
read-only table (time/action/resource/decision/role/correlation-id), capability-gated on
cases:manage. Added to ADMIN_LINKS (so it shows in the header nav + dashboard "Beheer" section)
and to the role.interceptor ROLE_AWARE list (else it silently 403s). This closes the audit half.
Phase: 8 — platform/DX/showcase Priority: P2 Depends on: WP-40, WP-41
Outcome (mask/parse half — done, on user request ahead of WP-41)
Added a "6 · PII — maskeren & parsen" section to /concepts demonstrating the WP-40 pieces with
FP + atomic design, framed for AVG art. 9 / data-minimisation: a live <app-masked-value> atom
(masked-by-default BSN that reveals on click; note points to the real step-up + audited reveal in
behandel-scherm) and a live parseBsn elfproef parse mirroring the postcode demo. Both show the
real linked source via the WP-39 snippet mechanism (// #region showcase:parseBsn in bsn.ts,
showcase:mask in pii.ts, registered in gen-snippets.mjs → snippets.generated.ts, drift-gated).
No i18n (showcase is Dutch-only teaching text). No behaviour change outside the showcase.
Still pending (needs WP-41): the "log PII / no-PII audit trail" half — visualizing the persisted authz/reveal audit — plus an optional Foundations MDX writeup.
Why
Once the reusable privacy pieces exist (WP-40 masked-value atom + pure maskers, WP-41 persisted no-PII audit), showcase them as a teaching artifact: how to mask and log PII safely with FP (pure functional core) + atomic design (the masked-value atom), tied to the existing reveal + step-up + capability slice.
Decisions
- A Foundations MDX + a small
showcasedemo (showcase context may read every context). - Teach the principles explicitly: data-minimisation, PII out of logs, masked-by-default + audited reveal, server as authority — framed for a Dutch register (AVG art. 9, BIO).
- Reuse WP-39's linked-snippet mechanism so the shown code can't drift.
Files
- New
src/docs/privacy-security.mdx(Foundations). - New/extended
showcasedemo wiring<app-masked-value>, the pure maskers, and the reveal flow.
Acceptance criteria
- Page demonstrates mask + no-PII logging with live components and linked (non-drifting) code.
- Explains the register rationale (AVG/BIO/data-minimisation) concisely.
- Storybook a11y green;
npm run cigreen.