Files
pedwfrontend/memory-bank/debt-list.md
T
Robert Bond 0150e243ed Merged PR 2408: updated context for current state at 19062026
updated context for current state at 19062026

Related work items: #23754
2026-06-19 12:39:40 +00:00

96 lines
4.6 KiB
Markdown

## 1) Prioritized debt list
1. Monolithic `actions/index.js` (over-coupled “god module”)
2. Inconsistent API error handling/response contracts across `pages/api/**`
3. Sensitive/verbose logging in app + API paths
4. Endpoint sprawl and duplicated proxy patterns (`pages/api/endpoint/*_api.js`)
5. i18n routing complexity in large rewrite maps
6. Sparse automated test coverage for high-risk flows
7. Legacy/stale commented patterns in critical files
## 2) Impact of each item
- **1) `actions/index.js` monolith**
- High blast radius for any change; weak modularity and hard ownership boundaries.
- Evidence: ~100+ exports mixing search, auth, account, file, PDF, notify, CRM concerns.
- **2) API contract inconsistency**
- Clients must handle errors inconsistently; reliability and observability suffer.
- Evidence: many handlers return raw `res.status(400).json(error)` while others shape custom outputs.
- **3) Verbose/sensitive logging**
- Privacy/security risk plus noisy telemetry.
- Evidence: 300+ `console.log` occurrences, including auth/email/upload-related contexts.
- **4) Endpoint duplication**
- Maintenance cost and drift risk (validation/auth/error semantics diverge over time).
- Evidence: repeated patterns across many `_api.js` proxy handlers.
- **5) i18n rewrite complexity**
- Higher risk of EN/CY divergence as routes evolve.
- Evidence: large manual rewrite map + separate i18n page namespace config.
- **6) Sparse tests**
- Release confidence depends heavily on manual checks; slower, riskier change cadence.
- **7) Stale patterns**
- Increased cognitive load and unclear source-of-truth behavior in some modules.
## 3) Recommended next cleanup targets
1. **Decompose `actions/index.js` by domain** (structure-only first, keep barrel exports).
2. **Add shared API handler utilities** for validation/error envelope; migrate top sensitive endpoints first.
3. **Implement logging redaction wrapper + policy** and remove direct logs in auth/email/file paths.
4. **Create high-risk smoke tests** (auth callback, search endpoint, upload negative-path, email failure-path).
5. **Extract proxy/integration helpers** (token/hash/header/retry) to reduce endpoint duplication.
6. **Add EN/CY parity CI checks** for route and locale key consistency.
## 4) Runtime note (updated)
- `server.js` and `server/server.js` exist in the repository but are **not the active production concern** for the current refactor stream.
- Current baseline runtime for this debt plan is the standard Next runtime path (`npm start`).
- Runtime canonicalization is therefore removed from the active prioritized debt list unless deployment evidence changes.
## 5) Progress snapshot against architecture/debt review (2026-03-25)
Cross-referenced with:
- `context/architecture.md` (status + execution sequence)
- `memory-bank/architect-review.md`
Status by debt item:
1. **Monolithic `actions/index.js`** -> **in progress**
- Significant modular extraction completed (shared clients and route helpers), but full domain split remains open.
2. **Inconsistent API contracts** -> **major progress**
- Broad endpoint hardening and contract normalization completed across many route clusters.
3. **Sensitive/verbose logging** -> **partial progress**
- Relay path improved; broader auth/email/file redaction standardization still pending.
4. **Endpoint sprawl/duplication** -> **major progress**
- Shared relay/request helpers reduced repeated route logic; long-tail cleanup remains.
5. **i18n rewrite complexity** -> **improving**
- Targeted EN/CY rewrite parity automation now exists; CI enforcement still pending.
6. **Sparse high-risk tests** -> **major progress**
- Focused automation now covers auth redirect safety, signed-delete/upload negative paths, and EN/CY parity checks.
7. **Legacy/stale patterns** -> **partial progress**
- Multiple cleanup slices completed; still an ongoing hygiene lane.
Immediate recommended next lane (aligned to architecture Sequence B):
- Consolidate signed-request patterns behind a focused helper.
- Apply broader logging hardening in auth/file/email/account-sensitive paths.
If you want, I can convert this into a sprint-ready debt register (ID, owner, effort, risk reduction, target milestone).
## 6) Additional architecture visibility debt (2026-06-19)
### Security Boundary Visibility
- Inconsistent visibility of endpoint ownership validation.
- Unknown consistency of authenticated endpoint protection.
- Incomplete inventory of public vs authenticated endpoints.
Recommended action:
- Perform Portal API Security & Access Boundary Assessment.