Completes the pipeline's analysis phase. Agent 07 (BIO2/ISO 27002:2022,
control set stated as an assumption since none was supplied) produced 20
findings — 12 "defect now", 8 "production gate" — and agent 08 consolidated
all 47 findings across 00/02/04/06/07 into 33 tickets, 5 ADR-fixes and a
release checklist.
Two findings are live defects rather than refactoring candidates, both
verified directly:
- RB-01/BIO-004: GET /uploads/{documentId}/content takes only (string
documentId) — no HttpContext, so no authorization is possible. It streams
diploma and identity scans, protected by GUID unguessability alone, while
DELETE on the same resource is owner-scoped.
- RB-02/BIO-008: Program.cs:674 concatenates the caller's BSN into the authz
audit Resource column, which is persisted to SQLite and rendered by the
admin audit page. Four doc comments claim that store holds no PII; the test
cited as enforcing it asserts on column names, so a BSN inside a column
called Resource is invisible to it.
07 also answered the handoff from 06: in a production behandelportal build no
X-Medewerker is sent, so StubIdentityProvider returns the seeded citizen. It
fails closed on backoffice capabilities but open on citizen-scoped ones,
including CanRevealBigNummer. Root cause is IIdentityProvider.Resolve
returning a non-nullable CallerIdentity — the interface cannot express "no
identity", so any provider must invent one.
08's gate was relaxed from all-seven to the four agents that ran; _status.md
records why 01/03/05 were skipped, and the backlog carries a "Coverage"
note naming what those skips leave unowned. It caught two errors in the
orchestrator's handoff: CQ-002 is not fixed (ApplicationsStore.cancel and
AdminCasesStore.delete still swallow errors -> RB-20), and CQ-004 shipped
with half its compliance criterion unmet (PUT /admin/flags/{key} writes no
audit row -> RB-07, which blocks signing ADR-C-009).
Both agents preserved a "verified clean — do not fix" list, so a later pass
does not re-spend effort on the controls that already hold.
Consolidation halted for human approval per its spec. No source file changed.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Runs the multi-agent refactoring-backlog pipeline in docs/project/
refactor-backlog-setup/ up to and including three of the seven Phase 1
agents.
00-baseline.md establishes the metrics every later agent must cite, using
only tooling already in the repo (vitest lcov, coverlet cobertura, ESLint's
core `complexity` rule at threshold 0 for a full distribution, depcruise
--metrics). Duplication and C# complexity had no tooling, so
tools/baseline-scan.mjs adds a deterministic ~200-line text scan rather
than a new dependency; the approximations are labelled as such.
Headline: FE 75.1% line coverage but only over the 98 of 220 source files a
spec loads; BE 97.6% line / 79.6% branch; 0 layering violations; 7.1%
duplication; 25 of 2085 TS functions over CC 10.
Then 02-testability, 04-cqrs-light and 06-adr-conformance (27 findings).
01/03/05 were skipped deliberately — the baseline shows little for them to
find; 07 (BIO2) and 08 (consolidation) are still open.
Each agent corrected a baseline observation of mine, and in every case the
error was in something derived rather than measured:
- BL-007 counted ~13 adapter "mutations" from the `runSubmit` helper name;
5 of those call sites are reads. It also missed 3 real mutations that
reach the raw ApiClient and never return a Result.
- BL-002 diagnosed the 100%-duplicated auth folders as ADR-0002's
divergence prediction failing. It never had a chance to fail: §3's
`Principal` union was never built.
- BL-004 named libs/shared/domain and libs/beheer/contracts as coverage
gaps; both are pure type declarations where 0% is unimprovable.
All three corrections are recorded inline in 00-baseline.md §10, so agent
08 does not inherit the bad numbers.
.prettierignore excludes the agent prompt directories — reflowing their
markdown would edit the prompt text itself.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>