{
  "policy": {
    "version": 5,
    "patterns": {
      "version": 1,
      "method": "CURATED_PRACTICE_TOPIC",
      "notice": "Pattern topics identify design choices to practice. Read the ticket's acceptance criteria and justify the simplest suitable approach. Tags are not capability or ownership evidence; an untagged ticket has no curated pattern topic assigned."
    },
    "fieldMix": {
      "version": 1,
      "method": "CURATED_ESTIMATE",
      "notice": "Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence."
    },
    "contentStatus": "PRACTICE_BRIEF",
    "assessmentStatus": "NOT_QUALIFIED",
    "evidenceUse": "NONE",
    "aiPolicy": "AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.",
    "notice": "Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.",
    "outcomeEvidence": "Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.",
    "ownershipEvidence": "Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence."
  },
  "patternTopics": [
    {
      "id": "factory-method",
      "label": "Factory Method",
      "group": "Creational"
    },
    {
      "id": "abstract-factory",
      "label": "Abstract Factory",
      "group": "Creational"
    },
    {
      "id": "builder",
      "label": "Builder",
      "group": "Creational"
    },
    {
      "id": "prototype",
      "label": "Prototype",
      "group": "Creational"
    },
    {
      "id": "singleton",
      "label": "Singleton",
      "group": "Creational"
    },
    {
      "id": "adapter",
      "label": "Adapter",
      "group": "Structural"
    },
    {
      "id": "bridge",
      "label": "Bridge",
      "group": "Structural"
    },
    {
      "id": "composite",
      "label": "Composite",
      "group": "Structural"
    },
    {
      "id": "decorator",
      "label": "Decorator",
      "group": "Structural"
    },
    {
      "id": "facade",
      "label": "Facade",
      "group": "Structural"
    },
    {
      "id": "flyweight",
      "label": "Flyweight",
      "group": "Structural"
    },
    {
      "id": "proxy",
      "label": "Proxy",
      "group": "Structural"
    },
    {
      "id": "chain-of-responsibility",
      "label": "Chain of Responsibility",
      "group": "Behavioral"
    },
    {
      "id": "command",
      "label": "Command",
      "group": "Behavioral"
    },
    {
      "id": "interpreter",
      "label": "Interpreter",
      "group": "Behavioral"
    },
    {
      "id": "iterator",
      "label": "Iterator",
      "group": "Behavioral"
    },
    {
      "id": "mediator",
      "label": "Mediator",
      "group": "Behavioral"
    },
    {
      "id": "memento",
      "label": "Memento",
      "group": "Behavioral"
    },
    {
      "id": "observer",
      "label": "Observer",
      "group": "Behavioral"
    },
    {
      "id": "state",
      "label": "State",
      "group": "Behavioral"
    },
    {
      "id": "strategy",
      "label": "Strategy",
      "group": "Behavioral"
    },
    {
      "id": "template-method",
      "label": "Template Method",
      "group": "Behavioral"
    },
    {
      "id": "visitor",
      "label": "Visitor",
      "group": "Behavioral"
    },
    {
      "id": "ports-and-adapters",
      "label": "Ports and Adapters",
      "group": "Architectural"
    },
    {
      "id": "cqrs",
      "label": "CQRS",
      "group": "Architectural"
    },
    {
      "id": "strangler-fig",
      "label": "Strangler Fig",
      "group": "Architectural"
    },
    {
      "id": "saga",
      "label": "Saga",
      "group": "Distributed and reliability"
    },
    {
      "id": "transactional-outbox",
      "label": "Transactional Outbox",
      "group": "Distributed and reliability"
    },
    {
      "id": "circuit-breaker",
      "label": "Circuit Breaker",
      "group": "Distributed and reliability"
    },
    {
      "id": "bulkhead",
      "label": "Bulkhead",
      "group": "Distributed and reliability"
    }
  ],
  "projects": [
    {
      "id": "e980f00e-89b2-45ce-882b-9f578b896ce6",
      "key": "AFETCH",
      "title": "Constrain a server-side document fetcher",
      "field": "Security",
      "summary": "Fetch approved remote documents while controlling redirects, size and authority.",
      "context": "A fictional knowledge service imports documents from customer-entered URLs. The importer follows redirects and trusts response metadata too broadly.",
      "stack": [
        "TypeScript",
        "HTTP client",
        "Object storage"
      ],
      "prerequisites": [
        "Build a local fetch adapter and controlled HTTP test servers.",
        "Use synthetic documents and deny network access outside the test allowlist."
      ],
      "developerValue": "Practice defensive URL handling and bounded untrusted-input processing.",
      "companyValue": "Review whether integrations can import content without expanding infrastructure access.",
      "delivery": "Ten scoped tickets across three phases. Build a synthetic local service or select a ticket after recreating its prerequisites; estimates exclude setup.",
      "phases": [
        {
          "id": "policy",
          "title": "Define fetch authority",
          "goal": "Constrain URLs, identity and network destinations."
        },
        {
          "id": "fetch",
          "title": "Bound remote work",
          "goal": "Apply limits through redirects and response streaming."
        },
        {
          "id": "review",
          "title": "Validate abuse resistance",
          "goal": "Reproduce failures and preserve safe diagnostics."
        }
      ],
      "tickets": [
        {
          "id": "60ac42f8-d233-435e-9c08-78c7540143c5",
          "key": "AFETCH-101",
          "title": "Accept only explicitly supported document URL schemes",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 75,
          "phaseId": "policy",
          "dependsOn": [],
          "scenario": "A customer enters a non-HTTP URI that the generic import library attempts to interpret as a local resource.",
          "acceptanceCriteria": [
            "Allow HTTPS under an explicit destination policy.",
            "Reject embedded credentials and unsupported schemes.",
            "Normalize once and retain a safe display URL."
          ],
          "implementationNotes": [
            "Use a standard URL parser; do not build one with string prefixes."
          ],
          "verification": [
            "Accept an approved synthetic HTTPS URL.",
            "Reject file, data and credential-bearing URLs before network calls."
          ],
          "deliverables": [
            "URL input policy and parser tests"
          ],
          "rollout": "Enforce validation before import dispatch; quarantine existing unsupported requests.",
          "skills": [
            "Input validation",
            "URL parsing"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 70
            },
            {
              "field": "API design",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "423bd472-d035-4524-adb2-b51d09ce8df9",
          "key": "AFETCH-102",
          "title": "Bind document import requests to tenant-owned destination policies",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "policy",
          "dependsOn": [
            "AFETCH-101"
          ],
          "scenario": "One tenant configures an approved host and another tenant unexpectedly inherits permission to fetch from it.",
          "acceptanceCriteria": [
            "Resolve allowlists within the requesting tenant.",
            "Require authorization before creating a fetch job.",
            "Reject unknown policy references without disclosing other tenants' hosts."
          ],
          "implementationNotes": [
            "Store policy version with the import request."
          ],
          "verification": [
            "Import through the tenant's approved synthetic host.",
            "Reuse another tenant's policy ID and verify zero fetch calls."
          ],
          "deliverables": [
            "Scoped destination-policy service"
          ],
          "rollout": "Deploy tenant resolution before enabling saved policies; disable import on ambiguous ownership.",
          "skills": [
            "Tenant isolation",
            "Authorization"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 80
            },
            {
              "field": "Backend",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "6f1072d8-34c1-49d1-8f4f-9ef8ea31257b",
          "key": "AFETCH-103",
          "title": "Reject private and special-use destination addresses before connection",
          "type": "BUG",
          "priority": "URGENT",
          "difficulty": "ADVANCED",
          "estimateMinutes": 240,
          "phaseId": "policy",
          "dependsOn": [
            "AFETCH-101",
            "AFETCH-102"
          ],
          "scenario": "A public-looking hostname resolves to an internal address during import and reaches a service unavailable to the user.",
          "acceptanceCriteria": [
            "Apply destination-address policy to every resolved connection target.",
            "Reject loopback, private and special-use addresses outside explicit local tests.",
            "Prevent resolver results from changing unchecked before connection."
          ],
          "implementationNotes": [
            "Use an injected resolver and connection adapter; tests never contact internal services."
          ],
          "verification": [
            "Resolve an allowed synthetic public address through the fixture adapter.",
            "Return loopback or changed resolution and verify no connection is opened."
          ],
          "deliverables": [
            "Resolver-to-connection policy and fixture tests"
          ],
          "rollout": "Run policy checks before enabling network fetches; deny unresolved or ambiguous destinations.",
          "skills": [
            "Network security",
            "SSRF prevention"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 60
            },
            {
              "field": "Networking",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "af0f9f62-bc46-494f-8a16-e52bb6a5d34b",
          "key": "AFETCH-104",
          "title": "Revalidate every document redirect before following it",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 210,
          "phaseId": "fetch",
          "dependsOn": [
            "AFETCH-103"
          ],
          "scenario": "An approved download host redirects to an unapproved internal URL after the first request passes validation.",
          "acceptanceCriteria": [
            "Limit redirect count and validate each target independently.",
            "Do not forward credentials across origins.",
            "Reject redirect loops with a stable reason code."
          ],
          "implementationNotes": [
            "Use local controlled redirect fixtures only."
          ],
          "verification": [
            "Follow one permitted same-policy redirect.",
            "Redirect toward an internal fixture address and assert it is blocked before connection."
          ],
          "deliverables": [
            "Redirect policy and credential-stripping regression"
          ],
          "rollout": "Enable bounded redirect handling; disable redirect support if a client bypasses target validation.",
          "skills": [
            "HTTP security",
            "Redirect handling"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 60
            },
            {
              "field": "Networking",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "de19cb62-71f3-4989-94bf-6aa17cf4b3bc",
          "key": "AFETCH-105",
          "title": "Enforce byte and time limits while streaming imported documents",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "fetch",
          "dependsOn": [
            "AFETCH-104"
          ],
          "scenario": "A response declares a small Content-Length but streams indefinitely, occupying a worker slot.",
          "acceptanceCriteria": [
            "Bound actual streamed bytes regardless of headers.",
            "Enforce connect, idle and overall deadlines.",
            "Cancel the upstream stream and remove incomplete staging objects on failure."
          ],
          "implementationNotes": [
            "Choose explicit local test budgets and an injectable clock."
          ],
          "verification": [
            "Import a document within the declared byte and deadline limits.",
            "Stream beyond the byte cap or stall and verify cancellation plus cleanup."
          ],
          "deliverables": [
            "Bounded stream adapter and timeout fixtures"
          ],
          "rollout": "Canary small imports; lower admitted limits while investigating failures.",
          "skills": [
            "Streaming",
            "Resource limits"
          ],
          "fieldMix": [
            {
              "field": "Performance engineering",
              "percentage": 40
            },
            {
              "field": "Security",
              "percentage": 30
            },
            {
              "field": "Networking",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "0f3dc497-c4e6-42e5-88cc-0c060e280291",
          "key": "AFETCH-106",
          "title": "Validate document type from bytes before publishing the import",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "fetch",
          "dependsOn": [
            "AFETCH-105"
          ],
          "scenario": "A remote server labels an executable-looking payload as text and the importer publishes it under a trusted document type.",
          "acceptanceCriteria": [
            "Allow a declared finite set of document formats.",
            "Check supported signatures and parser outcomes against claimed type.",
            "Keep mismatched or malformed content quarantined."
          ],
          "implementationNotes": [
            "Do not execute imported content or trust file extensions."
          ],
          "verification": [
            "Import valid synthetic text and supported document bytes.",
            "Mismatch content type and bytes and verify no published object."
          ],
          "deliverables": [
            "Format gate and mismatch cases"
          ],
          "rollout": "Gate new imports before publication; retain quarantined bytes under restricted retention.",
          "skills": [
            "Content validation",
            "Untrusted data"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 80
            },
            {
              "field": "Backend",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "374e1060-af8d-48b0-b02b-979245c94722",
          "key": "AFETCH-107",
          "title": "Make interrupted document fetch retries preserve one import identity",
          "type": "STORY",
          "priority": "MEDIUM",
          "difficulty": "EXPERT",
          "estimateMinutes": 300,
          "phaseId": "fetch",
          "dependsOn": [
            "AFETCH-105",
            "AFETCH-106"
          ],
          "scenario": "A response drops after storage completes; retry publishes a second document with a different identity.",
          "acceptanceCriteria": [
            "Use a stable import command identity and staged object generation.",
            "Publish at most one completed object per command.",
            "Changed URL or policy version under the same key conflicts."
          ],
          "implementationNotes": [
            "Persist publication and completion state atomically."
          ],
          "verification": [
            "Drop the response after publication and retry to the same import.",
            "Interrupt a stream and verify its incomplete generation cannot be published."
          ],
          "deliverables": [
            "Idempotent import completion and fault probe"
          ],
          "rollout": "Canary one synthetic tenant; stop completion and inspect staging generations on inconsistency.",
          "skills": [
            "Idempotency",
            "Storage lifecycle"
          ],
          "fieldMix": [
            {
              "field": "Storage systems",
              "percentage": 40
            },
            {
              "field": "Security",
              "percentage": 30
            },
            {
              "field": "Backend",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "447423b3-37c9-4bed-917f-0308ed217a92",
          "key": "AFETCH-108",
          "title": "Remove query secrets from document-fetch error messages",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 75,
          "phaseId": "review",
          "dependsOn": [
            "AFETCH-104",
            "AFETCH-107"
          ],
          "scenario": "A signed download URL appears in an operator error message after a timeout.",
          "acceptanceCriteria": [
            "Log safe origin, import ID and failure code only.",
            "Strip query, fragment and user information from diagnostics.",
            "Keep provider errors from bypassing the safe projection."
          ],
          "implementationNotes": [
            "Use fabricated signed URLs in tests."
          ],
          "verification": [
            "Trace a timeout by import ID.",
            "Inject secret-like query values into redirect and timeout errors and assert absence."
          ],
          "deliverables": [
            "Fetch diagnostic sanitizer"
          ],
          "rollout": "Deploy safe diagnostics before broad imports; restrict older error records.",
          "skills": [
            "Privacy",
            "Error handling"
          ],
          "fieldMix": [
            {
              "field": "Privacy engineering",
              "percentage": 50
            },
            {
              "field": "Security",
              "percentage": 50
            }
          ],
          "patterns": []
        },
        {
          "id": "fe221b0c-d1df-4296-8c62-8b765dff0088",
          "key": "AFETCH-109",
          "title": "Build a regression matrix for document-fetch trust-boundary failures",
          "type": "CHORE",
          "priority": "MEDIUM",
          "difficulty": "EXPERT",
          "estimateMinutes": 300,
          "phaseId": "review",
          "dependsOn": [
            "AFETCH-103",
            "AFETCH-104",
            "AFETCH-105",
            "AFETCH-106"
          ],
          "scenario": "The fetcher has individual guards, but a client upgrade could bypass a guard only when redirects, DNS and retries combine.",
          "acceptanceCriteria": [
            "Cover composed resolver, redirect, size and cancellation cases.",
            "Assert forbidden connection attempts and publication calls remain zero.",
            "Record expected failure codes without claiming universal attack coverage."
          ],
          "implementationNotes": [
            "All network behavior runs through local controlled adapters."
          ],
          "verification": [
            "Run an allowed redirected import through the complete pipeline.",
            "Combine redirect with resolution change and oversized body; stop at the earliest applicable guard."
          ],
          "deliverables": [
            "Adversarial fixture matrix and regression command"
          ],
          "rollout": "Require the matrix for client upgrades; pin the last passing client revision if failures appear.",
          "skills": [
            "Security testing",
            "Boundary analysis"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 50
            },
            {
              "field": "Quality engineering",
              "percentage": 30
            },
            {
              "field": "Networking",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "4569d06a-1dff-4180-8324-aac2396c56ea",
          "key": "AFETCH-110",
          "title": "Document the exception process for a newly requested document host",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 90,
          "phaseId": "review",
          "dependsOn": [
            "AFETCH-102",
            "AFETCH-109"
          ],
          "scenario": "Support wants to unblock a customer's host quickly without permanently disabling destination checks.",
          "acceptanceCriteria": [
            "Request a tenant-scoped host and purpose.",
            "Record policy version, reviewer and expiry for any exception.",
            "Retain all address, redirect and byte controls."
          ],
          "implementationNotes": [
            "Use a fictional host; no live allowlist modification is part of this ticket."
          ],
          "verification": [
            "Review a complete scoped exception example.",
            "Reject a wildcard destination request that bypasses address policy."
          ],
          "deliverables": [
            "Host exception template and worked review"
          ],
          "rollout": "Use the template for policy proposals; expire exceptions rather than widening global defaults.",
          "skills": [
            "Threat modeling",
            "Operational policy"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 80
            },
            {
              "field": "Site reliability",
              "percentage": 20
            }
          ],
          "patterns": []
        }
      ]
    }
  ]
}
