lucianoandClaude Opus 4.7 f954be610b docs(adr): 0002 encryption at-rest plan for art. 9 GDPR data
Picks application-level field encryption via prisma-field-encryption
(AES-256-GCM, master key from KMS) as the primary defence, combined with
volume encryption on the production Postgres host as defence in depth.

Documents:
- which fields are sensitive now (Profile.weight*, Profile.targetDate) and
  which arrive in V1 (WeightEntry, FastEvent, ProgressPhoto)
- which fields stay in clear text and why (email/login, age/gender for
  aggregate analytics, height/activity for plan generation)
- alternatives rejected: pgcrypto (key in queries), volume-only (no app-level
  protection), client-side E2E (kills BMR/TDEE server-side calculation)
- consequences and the implementation roadmap for a follow-up PR

Status: proposed — must be implemented before opening V1 to public users.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-29 14:38:01 +02:00
2026-04-29 12:10:08 +02:00
2026-04-29 12:10:08 +02:00
2026-04-29 12:10:08 +02:00
2026-04-29 12:10:08 +02:00
2026-04-29 12:10:08 +02:00
2026-04-29 12:10:08 +02:00
2026-04-29 12:10:08 +02:00

KetoPath

Web app responsive multi-utente per la gestione personalizzata di chetogenica e digiuno intermittente.

Vedi CLAUDE.md per le convenzioni di progetto e docs/PRD_KetoPath.docx per il PRD completo.

Prerequisiti

  • Node.js >=20.11 (vedi .nvmrc)
  • pnpm >=9 (corepack enable && corepack prepare pnpm@latest --activate)

Getting started

pnpm install
pnpm typecheck
pnpm lint
pnpm format:check

Struttura del monorepo

apps/
  web/              # Next.js 14 frontend (da scaffoldare)
  api/              # Fastify backend (da scaffoldare)
packages/
  shared/           # Tipi e utility di dominio
  ui/               # Componenti UI riusabili
  db/               # Prisma client (da scaffoldare)
  tsconfig/         # tsconfig presets condivisi
  eslint-config/    # ESLint config condivisa
docs/
  PRD_KetoPath.docx

Script disponibili

  • pnpm dev — avvia tutte le app in parallelo
  • pnpm dev:web / pnpm dev:api — avvia singola app
  • pnpm build — build di produzione
  • pnpm lint / pnpm lint:fix — ESLint
  • pnpm format / pnpm format:check — Prettier
  • pnpm typecheck — tsc -b su tutto il monorepo
  • pnpm test — Vitest (unit test)
  • pnpm test:e2e — Playwright (E2E)
S
Description
No description provided
Readme
665 KiB
0 Stars 1 Watchers 0 Forks
Languages
TypeScript 97.3%
CSS 1.7%
JavaScript 1%