Files
atomic-design-poc/docs/project/refactor-backlog-setup
ehoandClaude Opus 5 176e5baef8 docs: BIO2 compliance pass + consolidated backlog (agents 07, 08)
Completes the pipeline's analysis phase. Agent 07 (BIO2/ISO 27002:2022,
control set stated as an assumption since none was supplied) produced 20
findings — 12 "defect now", 8 "production gate" — and agent 08 consolidated
all 47 findings across 00/02/04/06/07 into 33 tickets, 5 ADR-fixes and a
release checklist.

Two findings are live defects rather than refactoring candidates, both
verified directly:

- RB-01/BIO-004: GET /uploads/{documentId}/content takes only (string
  documentId) — no HttpContext, so no authorization is possible. It streams
  diploma and identity scans, protected by GUID unguessability alone, while
  DELETE on the same resource is owner-scoped.
- RB-02/BIO-008: Program.cs:674 concatenates the caller's BSN into the authz
  audit Resource column, which is persisted to SQLite and rendered by the
  admin audit page. Four doc comments claim that store holds no PII; the test
  cited as enforcing it asserts on column names, so a BSN inside a column
  called Resource is invisible to it.

07 also answered the handoff from 06: in a production behandelportal build no
X-Medewerker is sent, so StubIdentityProvider returns the seeded citizen. It
fails closed on backoffice capabilities but open on citizen-scoped ones,
including CanRevealBigNummer. Root cause is IIdentityProvider.Resolve
returning a non-nullable CallerIdentity — the interface cannot express "no
identity", so any provider must invent one.

08's gate was relaxed from all-seven to the four agents that ran; _status.md
records why 01/03/05 were skipped, and the backlog carries a "Coverage"
note naming what those skips leave unowned. It caught two errors in the
orchestrator's handoff: CQ-002 is not fixed (ApplicationsStore.cancel and
AdminCasesStore.delete still swallow errors -> RB-20), and CQ-004 shipped
with half its compliance criterion unmet (PUT /admin/flags/{key} writes no
audit row -> RB-07, which blocks signing ADR-C-009).

Both agents preserved a "verified clean — do not fix" list, so a later pass
does not re-spend effort on the controls that already hold.

Consolidation halted for human approval per its spec. No source file changed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-27 09:52:13 +02:00
..

Refactoring backlog — automated setup

What's in this package

refactor-backlog-setup/
  setup.sh                     ← run this once, from the root of the target repo
  agents/                      ← source prompts (edit these if you need to tweak
                                  scope/wording before running setup.sh)
    _persistence-protocol.md
    00-baseline.prompt.md
    01-readability.prompt.md
    02-testability.prompt.md
    03-ddd-hexagonal.prompt.md
    04-cqrs-light.prompt.md
    05-bdd.prompt.md
    06-adr-conformance.prompt.md
    07-bio2-compliance.prompt.md
    08-consolidation.prompt.md
    09-implementation.prompt.md  (template — one TICKET-ID per Phase 3 dispatch)

Usage

  1. Copy this refactor-backlog-setup/ folder into the root of the target repo (or reference it via a relative path).
  2. Edit anything in agents/ if scope/exclusions need repo-specific detail (e.g. exact module paths, ADR folder location) — the prompts currently use the defaults agreed in the design conversation.
  3. Run:
    bash refactor-backlog-setup/setup.sh
    
    This creates ./refactor-backlog/ with:
    • _status.md initialized, all agents not_started
    • 00-baseline.md through 07-bio2-compliance.md initialized with headers
    • 99-backlog.md empty, ready for Consolidation
    • implementation/ folder for Phase 3 notes
    • final-prompts/ — every agent prompt with the persistence protocol already merged in. These are the exact prompts to dispatch — no manual copy-paste needed.

Dispatch order

  1. Dispatch final-prompts/00-baseline.prompt.md (Opus). Wait for _status.md → baseline: complete.
  2. Dispatch the 7 Phase 1 prompts in parallel (Opus): 01 through 07. Each checks its own dependency in _status.md before starting.
  3. Once all 7 show complete, dispatch final-prompts/08-consolidation.prompt.md (Opus). It writes 99-backlog.md and halts for human approval — check the file for any ADR-fix or BIO2-flagged tickets before proceeding.
  4. For each approved ticket, copy final-prompts/09-implementation.prompt.md, fill in TICKET-ID:, dispatch (Sonnet). Run tickets in parallel within a CD batch, sequential across batches, per the Depends on column in 99-backlog.md.

Re-running / resuming

Safe to re-run setup.sh only on a fresh workspace — it does not check for an existing ./refactor-backlog/ and will overwrite _status.md and the phase output files. If a run is already in progress, don't re-run setup.sh; just re-dispatch the relevant final-prompts/*.prompt.md — each agent reads _status.md and its own output file first and resumes from where it left off.