Files
atomic-design-poc/docs/project/refactor-backlog-setup
ehoandClaude Opus 5 a2e935d1d8 fix(uploads): authorize the document-content and status endpoints (RB-01)
GET /uploads/{documentId}/content took only (string documentId) — no
HttpContext, so no authorization was possible. It streams diploma and
identity scans, protected by GUID unguessability alone, while DELETE on the
same resource has always been owner-scoped. GET /uploads/status had the same
shape and confirmed whether any client-chosen localId exists, plus its
documentId.

Both now take HttpContext. Content is readable by the owning
ZorgverlenerCaller or a caller passing Authz.CanBeoordelen — matched on the
caller kind rather than branched on a boolean, because ctx.Zorgverlener()
throws for a MedewerkerCaller and the behandelportal's beoordeling screen is
a legitimate reader. Status is scoped to ctx.Zorgverlener().Bsn via a new
owner parameter on DocumentStore.ByLocalIds (one call site).

404, not 403, on both: a foreign document id must not be distinguishable
from one that never existed, and a foreign localId reads back as "unknown".

Residual, recorded in the implementation note: both callers reach the URL as
a plain browser navigation (<a href> / previewUrl), which carries no identity
header and no interceptor, so StubIdentityProvider resolves it to the seeded
citizen. That is BIO-002 and belongs to RB-09; the links keep working today
only because one citizen owns every document in the POC.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-27 10:48:04 +02:00
..

Refactoring backlog — automated setup

What's in this package

refactor-backlog-setup/
  setup.sh                     ← run this once, from the root of the target repo
  agents/                      ← source prompts (edit these if you need to tweak
                                  scope/wording before running setup.sh)
    _persistence-protocol.md
    00-baseline.prompt.md
    01-readability.prompt.md
    02-testability.prompt.md
    03-ddd-hexagonal.prompt.md
    04-cqrs-light.prompt.md
    05-bdd.prompt.md
    06-adr-conformance.prompt.md
    07-bio2-compliance.prompt.md
    08-consolidation.prompt.md
    09-implementation.prompt.md  (template — one TICKET-ID per Phase 3 dispatch)

Usage

  1. Copy this refactor-backlog-setup/ folder into the root of the target repo (or reference it via a relative path).
  2. Edit anything in agents/ if scope/exclusions need repo-specific detail (e.g. exact module paths, ADR folder location) — the prompts currently use the defaults agreed in the design conversation.
  3. Run:
    bash refactor-backlog-setup/setup.sh
    
    This creates ./refactor-backlog/ with:
    • _status.md initialized, all agents not_started
    • 00-baseline.md through 07-bio2-compliance.md initialized with headers
    • 99-backlog.md empty, ready for Consolidation
    • implementation/ folder for Phase 3 notes
    • final-prompts/ — every agent prompt with the persistence protocol already merged in. These are the exact prompts to dispatch — no manual copy-paste needed.

Dispatch order

  1. Dispatch final-prompts/00-baseline.prompt.md (Opus). Wait for _status.md → baseline: complete.
  2. Dispatch the 7 Phase 1 prompts in parallel (Opus): 01 through 07. Each checks its own dependency in _status.md before starting.
  3. Once all 7 show complete, dispatch final-prompts/08-consolidation.prompt.md (Opus). It writes 99-backlog.md and halts for human approval — check the file for any ADR-fix or BIO2-flagged tickets before proceeding.
  4. For each approved ticket, copy final-prompts/09-implementation.prompt.md, fill in TICKET-ID:, dispatch (Sonnet). Run tickets in parallel within a CD batch, sequential across batches, per the Depends on column in 99-backlog.md.

Re-running / resuming

Safe to re-run setup.sh only on a fresh workspace — it does not check for an existing ./refactor-backlog/ and will overwrite _status.md and the phase output files. If a run is already in progress, don't re-run setup.sh; just re-dispatch the relevant final-prompts/*.prompt.md — each agent reads _status.md and its own output file first and resumes from where it left off.