BIO-012: roleInterceptor/subjectInterceptor are correctly registered only under isDevMode(), but three hand-written fetch adapters (reveal-bignummer, letter-preview, org-template's proefbrief) bypass HttpClient and set X-Role/X-Subject themselves with no guard. The readers underneath, role.ts and subject.ts, were ungated too: they read ?role=/?subject= and wrote it into sessionStorage on any navigation, in any build -- for ?subject= that value is a BSN, which is exactly what SessionStore's G1 comment promises never happens. Gate both layers: currentRole()/currentSubject() return their safe default immediately outside isDevMode() (no query-param read, no sessionStorage write), and the three adapters additionally wrap their headers in isDevMode() so a production request carries neither header at all, matching what an HttpClient request already does once the interceptors aren't registered. TE-002: reveal-bignummer's response-shape validation was a "Trust boundary" a spec could only reach by stubbing globalThis.fetch. Exported it as parseRevealed(body), matching the other 30 parse* boundaries in the repo. Same treatment for letter-preview's errorMessage and org-template's proefbrief error mapping (extracted from an inline try/catch into a named, exported function first, since it wasn't already separate). BIO-006(a): reveal-bignummer sent X-Step-Up: 'true' unconditionally, so the backend's step-up precondition constrained nothing. reveal() now takes a stepUp flag; BriefStore.revealBigNummer() -- reachable only after the UI's confirm() gesture -- is the one that supplies it, so the literal no longer lives in the transport adapter. BIO-006(b): documented in roles-and-access.md that drafter is also the backend's fallback identity (StubIdentityProvider's catch-all arm), not just the dev switcher's initial choice -- so the least-privilege consequence of it also being the only role that may reveal a BSN is visible. Doc correction, same diff: roles-and-access.md's "wired only under isDevMode()" claim was false for the three hand-written fetch paths; it now says where the gate lives (interceptor registration and the reader functions) so it doesn't go stale the same way again. CLAUDE.md's dev-only claims needed no correction -- they already noted these three calls bypass the interceptor. Every fix has a test confirmed red by temporarily reverting the source change and rerunning the suite before restoring it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Documentation
Docs are split by kind, and kept out of each other's way:
reference/— information. How the system works and why: architecture, decisions (ADRs), the FP/TEA/atomic learning guide, accessibility and UX reference. Stable knowledge, not tied to a sprint.project/— administration. Planning and tracking: the work-package backlog, product requirements (PRDs), and the (superseded) roadmap. This is the moving, process-facing material.
Teaching material that is best read next to the components lives in Storybook, not
here — see the Foundations section (src/docs/*.mdx), starting at Foundations →
Overview. The reference/ docs are the long-form source; the Foundations pages are the
condensed, cross-linked curriculum.
reference/ — information
| Doc | What it is |
|---|---|
| architecture/ARCHITECTURE.md | The architecture walkthrough: contexts/layers, state management, parse-don't-validate, the feature recipe, the .NET backend seam. |
| architecture/0001-bff-lite-decision-dtos.md | ADR — BFF-lite endpoints + decision DTOs (backend decides, FE renders). |
| architecture/0002-user-groups-and-bounded-contexts.md | ADR — user groups as actors; identity vs authorization. |
| architecture/0003-cibg-huisstijl.md | ADR — adopt CIBG Huisstijl (vendored Bootstrap 5.2) + the token bridge. |
| architecture/0004-stamdata-as-code.md | ADR — business-tunable reference data as typed, compile-time-validated config (not a production DB). |
| architecture/0005-openzaak-behind-bff.md | ADR — connect to OpenZaak (ZGW APIs) behind the BFF via a config-gated data-source seam; the FE never changes. |
| openzaak-integration.md | How the BFF sources cases from OpenZaak (the IZaakSource seam + ZGW client), and how to add the next slice. |
| stamdata.md | How stamdata (config-as-code reference data) is laid out, how to add a table with zero UI code, and why coupling stays low. |
| audit-log.md | How the data-minimised authz/PII-reveal audit trail is built, how to audit a new action, and the one-producer-hub coupling. |
| feature-flags.md | How runtime feature flags work (catalog-as-code + runtime state), how to add one, and the hand-wired gating coupling to watch. |
| scaffolding.md | How code generation & scaffolding work: plop generators (gen:value-object/gen:form-machine), the NSwag client (gen:api), showcase snippets, and the skill recipes. |
| roles-and-access.md | The roles/actors + capability model: who can do what, how to switch roles in dev, and what each unlocks. |
| architecture/dependencies.md | Bounded-context + atomic-layer boundaries: the allowed-import rules, how they're enforced (dep:check) and visualized (dep:graph). |
| architecture/dependency-graph.md | Generated mermaid graph of contexts × layers (regenerate with npm run dep:graph). |
| fp-tea-atomic-design.md | Long-form learning guide: FP + The Elm Architecture + atomic design. |
| wcag-checklist.md | Manual WCAG checks automation can't catch (tab order, focus traps, reflow). |
| ui-ux-audit.md | Early UI/UX audit against NL Design System (predates ADR-0003 — read in that light). |
project/ — administration
| Doc | What it is |
|---|---|
| backlog/README.md | The work-package backlog index (WP-01…WP-48) — the live tracker. |
| prd/0001-mijn-aanvragen-en-wizardstatus.md | PRD — "Mijn aanvragen": running wizards, application status, document preview. |
| prd/0002-attribute-based-access-control.md | PRD — attribute-based access control in the UI. |
| prd/0003-brief-v2-demo-script.md | Demo script — Brief v2 scenarios mapped to a URL + click path (WP-28). |
| SHOWCASE-ROADMAP.md | Superseded roadmap (absorbed into project/backlog/) — kept for history. |