96 lines
4.6 KiB
Markdown
96 lines
4.6 KiB
Markdown
## 1) Prioritized debt list
|
|
|
|
1. Monolithic `actions/index.js` (over-coupled “god module”)
|
|
2. Inconsistent API error handling/response contracts across `pages/api/**`
|
|
3. Sensitive/verbose logging in app + API paths
|
|
4. Endpoint sprawl and duplicated proxy patterns (`pages/api/endpoint/*_api.js`)
|
|
5. i18n routing complexity in large rewrite maps
|
|
6. Sparse automated test coverage for high-risk flows
|
|
7. Legacy/stale commented patterns in critical files
|
|
|
|
## 2) Impact of each item
|
|
|
|
- **1) `actions/index.js` monolith**
|
|
- High blast radius for any change; weak modularity and hard ownership boundaries.
|
|
- Evidence: ~100+ exports mixing search, auth, account, file, PDF, notify, CRM concerns.
|
|
|
|
- **2) API contract inconsistency**
|
|
- Clients must handle errors inconsistently; reliability and observability suffer.
|
|
- Evidence: many handlers return raw `res.status(400).json(error)` while others shape custom outputs.
|
|
|
|
- **3) Verbose/sensitive logging**
|
|
- Privacy/security risk plus noisy telemetry.
|
|
- Evidence: 300+ `console.log` occurrences, including auth/email/upload-related contexts.
|
|
|
|
- **4) Endpoint duplication**
|
|
- Maintenance cost and drift risk (validation/auth/error semantics diverge over time).
|
|
- Evidence: repeated patterns across many `_api.js` proxy handlers.
|
|
|
|
- **5) i18n rewrite complexity**
|
|
- Higher risk of EN/CY divergence as routes evolve.
|
|
- Evidence: large manual rewrite map + separate i18n page namespace config.
|
|
|
|
- **6) Sparse tests**
|
|
- Release confidence depends heavily on manual checks; slower, riskier change cadence.
|
|
|
|
- **7) Stale patterns**
|
|
- Increased cognitive load and unclear source-of-truth behavior in some modules.
|
|
|
|
## 3) Recommended next cleanup targets
|
|
|
|
1. **Decompose `actions/index.js` by domain** (structure-only first, keep barrel exports).
|
|
2. **Add shared API handler utilities** for validation/error envelope; migrate top sensitive endpoints first.
|
|
3. **Implement logging redaction wrapper + policy** and remove direct logs in auth/email/file paths.
|
|
4. **Create high-risk smoke tests** (auth callback, search endpoint, upload negative-path, email failure-path).
|
|
5. **Extract proxy/integration helpers** (token/hash/header/retry) to reduce endpoint duplication.
|
|
6. **Add EN/CY parity CI checks** for route and locale key consistency.
|
|
|
|
## 4) Runtime note (updated)
|
|
|
|
- `server.js` and `server/server.js` exist in the repository but are **not the active production concern** for the current refactor stream.
|
|
- Current baseline runtime for this debt plan is the standard Next runtime path (`npm start`).
|
|
- Runtime canonicalization is therefore removed from the active prioritized debt list unless deployment evidence changes.
|
|
|
|
## 5) Progress snapshot against architecture/debt review (2026-03-25)
|
|
|
|
Cross-referenced with:
|
|
|
|
- `context/architecture.md` (status + execution sequence)
|
|
- `memory-bank/architect-review.md`
|
|
|
|
Status by debt item:
|
|
|
|
1. **Monolithic `actions/index.js`** -> **in progress**
|
|
- Significant modular extraction completed (shared clients and route helpers), but full domain split remains open.
|
|
2. **Inconsistent API contracts** -> **major progress**
|
|
- Broad endpoint hardening and contract normalization completed across many route clusters.
|
|
3. **Sensitive/verbose logging** -> **partial progress**
|
|
- Relay path improved; broader auth/email/file redaction standardization still pending.
|
|
4. **Endpoint sprawl/duplication** -> **major progress**
|
|
- Shared relay/request helpers reduced repeated route logic; long-tail cleanup remains.
|
|
5. **i18n rewrite complexity** -> **improving**
|
|
- Targeted EN/CY rewrite parity automation now exists; CI enforcement still pending.
|
|
6. **Sparse high-risk tests** -> **major progress**
|
|
- Focused automation now covers auth redirect safety, signed-delete/upload negative paths, and EN/CY parity checks.
|
|
7. **Legacy/stale patterns** -> **partial progress**
|
|
- Multiple cleanup slices completed; still an ongoing hygiene lane.
|
|
|
|
Immediate recommended next lane (aligned to architecture Sequence B):
|
|
|
|
- Consolidate signed-request patterns behind a focused helper.
|
|
- Apply broader logging hardening in auth/file/email/account-sensitive paths.
|
|
|
|
If you want, I can convert this into a sprint-ready debt register (ID, owner, effort, risk reduction, target milestone).
|
|
|
|
## 6) Additional architecture visibility debt (2026-06-19)
|
|
|
|
### Security Boundary Visibility
|
|
|
|
- Inconsistent visibility of endpoint ownership validation.
|
|
- Unknown consistency of authenticated endpoint protection.
|
|
- Incomplete inventory of public vs authenticated endpoints.
|
|
|
|
Recommended action:
|
|
|
|
- Perform Portal API Security & Access Boundary Assessment.
|