Local semgrep run found 25 findings (not the WP's remembered 27 — already-stale
by the time this ran): dependabot cooldown, npm min-release-age, every GitHub
Action pinned to a full commit SHA (dependabot's existing github-actions
ecosystem entry keeps these current), and 2 detect-non-literal-regexp findings
in e2e/create-ssp.mjs suppressed as false positives (non-attacker-controlled
input: a test's own captured version number, a local generator's CLI arg).
`semgrep scan` now runs with `--error`, a real blocking gate instead of
report-only.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- backend: dotnet format the WP-51 migration (2-space indent, no BOM)
to match .editorconfig — dotnet format --verify-no-changes was failing.
- storybook: stub FeatureFlagStore (WP-47) in shell/site-header stories
alongside AccessStore, fixing NG0201 no-provider errors; bump the
storybook-a11y container's memory cap 4g→6g (build-storybook +
compodoc measured ~5.8GB peak RSS, leaving too little headroom).
- backend: fix a startup-breaking bug in the new (WP-52) POST
/zgw/notificaties handler — it took ZgwOptions as a minimal-API
parameter, which isn't registered in DI, so ASP.NET's endpoint-table
build threw on every request once the route was registered (incl.
/swagger, which is why Playwright's webServer health check timed
out). Close over the existing `zgw` local instead.
- e2e: brief-v2.spec.ts's "Voorbeeld" button locator was ambiguous
once a second "Voorbeeld met testwaarden" button existed (Playwright
name matching is substring-based) — added `exact: true`. Also fixed
the sent-letter preview flow to match app-letter-composer's actual
behavior (single click → fetch, no in-page dialog, unlike
app-behandel-scherm's), and fixed a watermark assertion that checked
for the always-present `.preview-watermark` CSS class name instead
of the conditionally-rendered "VOORBEELD" marker text.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Closes phase 6 (Brief v2): a demo script mapping shipped scenarios to
URL+click paths (no Brief v2 PRD ever existed to translate one from —
written directly against the code instead), one e2e spec covering
compose→approve→send and admin republish→drafter-sees-it, and
Storybook state gaps (rejection diff, read-only viewer, org logo,
upload rejection) that prior WPs left uncovered. Flags passage-picker
as dead code, superseded by besluit-panel.
npm run e2e is not verified green in this sandbox — see WP-28's
Deviations section; the pre-existing, unmodified smoke.spec.ts fails
identically here, pointing at a sandbox rendering issue rather than a
regression.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>