Merged PR 2408: updated context for current state at 19062026
updated context for current state at 19062026 Related work items: #23754
This commit is contained in:
@@ -1,5 +1,33 @@
|
||||
# Architecture Reference
|
||||
|
||||
## Architecture Programme Status
|
||||
|
||||
### Discovery Status
|
||||
|
||||
Complete
|
||||
|
||||
### Current Phase
|
||||
|
||||
Adoption Planning
|
||||
|
||||
### Current Proven Business Decision Models
|
||||
|
||||
- Appeal Type Policy
|
||||
- Representation Entry Policy
|
||||
- Representation Type Availability
|
||||
|
||||
### Next Recommended Architecture Stream
|
||||
|
||||
Portal API Security & Access Boundary Assessment
|
||||
|
||||
### Objectives
|
||||
|
||||
- endpoint inventory
|
||||
- authenticated/public classification
|
||||
- ownership validation review
|
||||
- access-control consistency review
|
||||
- security boundary assessment
|
||||
|
||||
## Runtime Topology
|
||||
|
||||
1. Next.js runtime serves UI routes and API routes (legacy custom server files are present but not active).
|
||||
|
||||
@@ -10,6 +10,8 @@ The PEDW architectural discovery programme is considered complete for practical
|
||||
|
||||
No strong undiscovered business-policy candidates remain.
|
||||
|
||||
No major undiscovered architectural business-policy candidates remain in the current portal scope.
|
||||
|
||||
Future architectural work should focus on:
|
||||
|
||||
- documentation consolidation
|
||||
@@ -20,6 +22,8 @@ Future architectural work should focus on:
|
||||
|
||||
rather than broad architectural discovery.
|
||||
|
||||
Future architecture work should therefore be treated as adoption-planning and assurance work, not as reopening the discovery programme.
|
||||
|
||||
---
|
||||
|
||||
## Final Architectural Classification
|
||||
@@ -879,6 +883,21 @@ Primary focus:
|
||||
|
||||
---
|
||||
|
||||
## Recommended Next Architecture Stream
|
||||
|
||||
Portal API Security & Access Boundary Assessment
|
||||
|
||||
Suggested investigation areas:
|
||||
|
||||
- endpoint inventory
|
||||
- ownership enforcement review
|
||||
- authenticated/public endpoint classification
|
||||
- access-control consistency assessment
|
||||
|
||||
This is intended as the highest-value next architecture stream after discovery close-out and should be treated as a focused security/access-boundary review rather than as a new business-policy discovery track.
|
||||
|
||||
---
|
||||
|
||||
### Recommended Next Verification Slice
|
||||
|
||||
**Appeal Type Availability Filtering Verification**
|
||||
|
||||
Reference in New Issue
Block a user