feat(showcase): PII section — mask + elfproef parse (WP-42, mask/parse half)
CI / storybook-a11y (push) Successful in 5m3s
CI / frontend (push) Successful in 1m53s
CI / backend (push) Successful in 1m26s
CI / e2e (push) Successful in 2m46s
CI / semgrep (push) Successful in 59s
CI / api-client-drift (push) Successful in 2m7s

Add a "PII — maskeren & parsen" section to /concepts demonstrating the WP-40 pieces
with FP + atomic design, framed for AVG art. 9 / data-minimisation: a live
<app-masked-value> atom (masked BSN that reveals on click; real reveal is step-up +
audited in behandel-scherm) and a live parseBsn elfproef parse. Both show the real
linked source via the WP-39 snippet mechanism (new showcase regions in bsn.ts + pii.ts,
registered in gen-snippets.mjs). Delivers WP-42's showcase demo; the persisted-audit
half stays pending WP-41.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
eho
2026-07-23 15:43:53 +02:00
co-authored by Claude Opus 4.8
parent 62cb34b60f
commit 8c54ede6eb
7 changed files with 144 additions and 50 deletions
@@ -1,10 +1,23 @@
# WP-42 — Privacy & security showcase page
Status: todo
Status: partial — mask/parse showcase done; audit half pending WP-41
Phase: 8 — platform/DX/showcase
Priority: P2
Depends on: WP-40, WP-41
## Outcome (mask/parse half — done, on user request ahead of WP-41)
Added a "6 · PII — maskeren & parsen" section to `/concepts` demonstrating the WP-40 pieces with
FP + atomic design, framed for AVG art. 9 / data-minimisation: a live `<app-masked-value>` atom
(masked-by-default BSN that reveals on click; note points to the real step-up + audited reveal in
behandel-scherm) and a live `parseBsn` elfproef parse mirroring the postcode demo. Both show the
real linked source via the WP-39 snippet mechanism (`// #region showcase:parseBsn` in bsn.ts,
`showcase:mask` in pii.ts, registered in `gen-snippets.mjs``snippets.generated.ts`, drift-gated).
No i18n (showcase is Dutch-only teaching text). No behaviour change outside the showcase.
**Still pending (needs WP-41):** the "log PII / no-PII audit trail" half — visualizing the
persisted authz/reveal audit — plus an optional Foundations MDX writeup.
## Why
Once the reusable privacy pieces exist (WP-40 masked-value atom + pure maskers, WP-41 persisted