From 68cc75d0b0ba57097b88a27ee8fe1bc542bc374f Mon Sep 17 00:00:00 2001 From: Ajay Ghanwat Date: Wed, 19 Aug 2026 22:55:50 +0530 Subject: [PATCH] docs: fold the auth deprecations into the cleanup spec as a firm scope They are our own superseded options, not a stale dependency. The recommended form is already what the showcase example uses; the blast radius is three test files inside packages/auth, and the rpId/origin options are already ignored at runtime. Co-Authored-By: Claude Opus 5 --- ...-08-19-legacy-and-config-cleanup-design.md | 29 +++++++++++++------ 1 file changed, 20 insertions(+), 9 deletions(-) diff --git a/docs/superpowers/specs/2026-08-19-legacy-and-config-cleanup-design.md b/docs/superpowers/specs/2026-08-19-legacy-and-config-cleanup-design.md index d8bdbe35..a92795f7 100644 --- a/docs/superpowers/specs/2026-08-19-legacy-and-config-cleanup-design.md +++ b/docs/superpowers/specs/2026-08-19-legacy-and-config-cleanup-design.md @@ -87,17 +87,28 @@ import from them**, so deleting the files is not enough — those imports must b ## Deprecated auth options -`@wrnexus/auth` carries nine `@deprecated` markers in three groups: +`@wrnexus/auth` carries nine `@deprecated` markers. These are **our own superseded options**, not an +out-of-date dependency — there is no newer version to move to, only newer options we already added. +Removing them means deleting the old aliases and moving the few call sites that still use them. -- `onSignedIn` / `onSignedOut` aliases in `http/index.ts` and `plugin.ts`, superseded by - `createAuthEngine({ onSignedIn })` -- `onSuccessfulSignUp`'s misspelled alias in `types.ts` -- Four RP-ID and origin options in `engine.ts`, superseded by values bound to the issued challenge +| Group | Where | Replacement | Still used? | +| --------------------------------------------------------------------- | ---------------------------- | ------------------------------------------- | ----------------------------------------------------------- | +| `onSignedIn` / `onSignedOut` on HTTP route options and plugin options | `http/index.ts`, `plugin.ts` | the same names on `createAuthEngine({ … })` | only `packages/auth/test/http.test.ts` and `plugin.test.ts` | +| `onSuccessfullSignUp` (misspelled alias) | `types.ts` | `onSuccessfulSignUp` | nowhere — zero references | +| `rpId` / `origin` on passkey verification | `engine.ts` (4 sites) | values bound to the issued challenge | `packages/auth/test/engine.test.ts` | -These are a different package from the compiler and config surface, and they are removable -independently. They are included here because the instruction was to remove deprecated code, and -splitting them into their own pass would mean two migrations of the same apps. If the auth surface -should stay, drop this section — nothing else in the spec depends on it. +Two things this table settles: + +- **The recommended form is already in use.** `examples/auth-showcase/app/lib/auth.ts` passes + `onSignedIn` / `onSignedOut` to `createAuthEngine`, which is the _current_ API. The deprecated + members are the same names on different option objects, so the example needs no change. +- **Neither test app uses any of them.** Nothing in `D:\Company\wrnexuspps` references these + options. + +So the blast radius is three test files inside `packages/auth`, which are exercising the deprecated +paths and are updated or removed alongside them. The `rpId` / `origin` options are already ignored at +runtime — verification uses the values bound to the issued challenge — so removing them changes no +behaviour, only the shape of the call. ## Migration