# noCV engineering task library

Content version 5

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.

## REXPORT — Deliver a personal data export with a narrow access boundary

A fictional learning workspace offers a member a portable copy of their own profile, notes and activity settings. Shared documents contain contributions from other people. The product export policy specifies included fields and shared-record handling; this is an engineering exercise, not a legal portability claim.

**Field:** Privacy engineering. **Suggested stack:** TypeScript, PostgreSQL, JSON, Object storage adapter.

**Engineer value:** Practice export scoping, consistency, streaming and expiring access without leaking other members’ data.

**Company value:** Create a reviewable export contract and cross-subject regression suite for an approved product policy.

**Delivery agreement:** Ten tickets from field inventory to delivery and cleanup. Artifacts contain only synthetic data, and all download links resolve through local provider doubles.

### Setup prerequisites

- Create synthetic members, private notes and shared-document contributions in a local database.

- Provide fake queue and object-storage adapters with controllable expiry and failure.

### Specify the export boundary

Define authorized subjects, included fields and shared-record rules.

#### REXPORT-101 — List exportable member fields before serializing database rows

**Task · Medium priority · Foundational**

noCV practice brief v5 · REXPORT-101 · Deliver a personal data export with a narrow access boundary

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Specify the export boundary. Depends on: No preceding ticket.

Difficulty: Foundational. Estimated focused work: 60 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Privacy engineering 80% · Backend 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A prototype exports complete ORM objects, including internal moderation flags and provider tokens.

Acceptance criteria

- Create an explicit allowlist for profile, private-note and settings fields.

- Exclude credentials, internal operational fields and unrelated-member data.

- Version the export schema and document omitted field categories.

Implementation constraints

- Build export DTOs independently of database model serialization.

Verification

- Export a synthetic row containing token-like and internal fields and verify they are absent.

- Add an unknown database column and confirm it does not enter the artifact automatically.

Deliverables

- Export field contract and allowlist tests

Rollout and recovery: Review the field contract before enabling generation; new fields require an explicit schema change.

Project prerequisites: Create synthetic members, private notes and shared-document contributions in a local database. Provide fake queue and object-storage adapters with controllable expiry and failure.

Engineer value: Practice export scoping, consistency, streaming and expiring access without leaking other members’ data.

Company value: Create a reviewable export contract and cross-subject regression suite for an approved product policy.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### REXPORT-102 — Define how shared document contributions appear in a personal export

**Task · Medium priority · Intermediate**

noCV practice brief v5 · REXPORT-102 · Deliver a personal data export with a narrow access boundary

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Specify the export boundary. Depends on: REXPORT-101.

Difficulty: Intermediate. Estimated focused work: 120 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Privacy engineering 100%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Exporting a whole shared document would include other members’ private comments and mentions.

Acceptance criteria

- Specify which subject-owned contributions and necessary context are included.

- Define redaction or omission for unrelated-member fields and private comments.

- Represent omitted shared content honestly rather than implying the export is a complete document history.

Implementation constraints

- Use a mixed-author fixture; access to a workspace does not by itself settle the product export policy.

Verification

- Export a document with two authors, private comments and a deleted contribution.

- Verify exported context does not reveal an unrelated private field or silently change the subject’s contribution text.

Deliverables

- Shared-record export policy and mixed-author fixtures

Rollout and recovery: Keep shared-content export disabled until its policy and regression examples are reviewed.

Project prerequisites: Create synthetic members, private notes and shared-document contributions in a local database. Provide fake queue and object-storage adapters with controllable expiry and failure.

Engineer value: Practice export scoping, consistency, streaming and expiring access without leaking other members’ data.

Company value: Create a reviewable export contract and cross-subject regression suite for an approved product policy.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### REXPORT-103 — Bind export creation to the current authorized subject

**Bug · High priority · Intermediate**

noCV practice brief v5 · REXPORT-103 · Deliver a personal data export with a narrow access boundary

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Specify the export boundary. Depends on: REXPORT-101, REXPORT-102.

Difficulty: Intermediate. Estimated focused work: 135 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 60% · Privacy engineering 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

The endpoint accepts any member ID and relies on the UI to submit the current user.

Acceptance criteria

- Resolve export scope from the authenticated subject and approved workspace access.

- Reject substituted IDs and revoked sessions before queueing work.

- Record a safe operation reference without embedding personal fields in job identifiers.

Implementation constraints

- Authorization also belongs at the data-access boundary used by background assembly.

Verification

- Create an export as the matching synthetic member.

- Attempt another member’s ID and a revoked membership, checking that no job or artifact is created.

Deliverables

- Scoped export command and cross-subject denial tests

Rollout and recovery: Deploy command and repository checks together before queue activation.

Project prerequisites: Create synthetic members, private notes and shared-document contributions in a local database. Provide fake queue and object-storage adapters with controllable expiry and failure.

Engineer value: Practice export scoping, consistency, streaming and expiring access without leaking other members’ data.

Company value: Create a reviewable export contract and cross-subject regression suite for an approved product policy.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

### Build a consistent artifact

Generate bounded exports with explicit version and failure behavior.

#### REXPORT-104 — Freeze the export selection without holding a long database transaction

**Story · Medium priority · Advanced**

noCV practice brief v5 · REXPORT-104 · Deliver a personal data export with a narrow access boundary

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Build a consistent artifact. Depends on: REXPORT-103.

Difficulty: Advanced. Estimated focused work: 210 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Database engineering 50% · Privacy engineering 30% · System design 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Notes added midway through an export appear inconsistently, and the worker holds a transaction open while uploading the archive.

Acceptance criteria

- Declare the export consistency boundary and record a cutoff or snapshot reference.

- Keep database selection consistent with that boundary while assembling outside an unbounded transaction.

- Expose generation time and the selection boundary in the manifest.

Implementation constraints

- Choose a method supported by the local schema; do not promise a global snapshot across unrelated stores without a protocol.

Verification

- Edit and add notes during a paused assembly and verify the documented inclusion rule.

- Slow artifact upload and verify no long-lived database transaction is retained solely for transfer.

Deliverables

- Selection protocol and concurrent-edit export tests

Rollout and recovery: Version the consistency contract; failed assembly may retry against the same frozen selection or start a clearly new operation.

Project prerequisites: Create synthetic members, private notes and shared-document contributions in a local database. Provide fake queue and object-storage adapters with controllable expiry and failure.

Engineer value: Practice export scoping, consistency, streaming and expiring access without leaking other members’ data.

Company value: Create a reviewable export contract and cross-subject regression suite for an approved product policy.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### REXPORT-105 — Stream large note exports with bounded intermediate storage

**Story · Medium priority · Advanced**

noCV practice brief v5 · REXPORT-105 · Deliver a personal data export with a narrow access boundary

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Build a consistent artifact. Depends on: REXPORT-101, REXPORT-104.

Difficulty: Advanced. Estimated focused work: 210 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Performance engineering 40% · Privacy engineering 30% · Storage systems 30%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A member with many notes causes the worker to build one large JSON string and exceed its resource budget.

Acceptance criteria

- Stream the chosen format with bounded buffering and valid escaping.

- Keep ordering and manifest counts deterministic for the frozen selection.

- Remove incomplete temporary artifacts on controlled failure while preserving retry metadata.

Implementation constraints

- Use a synthetic large-note fixture and declared memory/disk limits; do not require real user content.

Verification

- Export the same selection through small and large chunk sizes and compare parsed records and digest.

- Interrupt output after a multibyte value and verify no incomplete artifact becomes downloadable.

Deliverables

- Streaming exporter, resource report and interrupted-write regression

Rollout and recovery: Keep completed artifacts unpublished until final validation; retry writes to a new temporary object identity.

Project prerequisites: Create synthetic members, private notes and shared-document contributions in a local database. Provide fake queue and object-storage adapters with controllable expiry and failure.

Engineer value: Practice export scoping, consistency, streaming and expiring access without leaking other members’ data.

Company value: Create a reviewable export contract and cross-subject regression suite for an approved product policy.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### REXPORT-106 — Validate the export manifest before marking assembly complete

**Chore · Medium priority · Intermediate**

noCV practice brief v5 · REXPORT-106 · Deliver a personal data export with a narrow access boundary

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Build a consistent artifact. Depends on: REXPORT-102, REXPORT-105.

Difficulty: Intermediate. Estimated focused work: 150 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Storage systems 50% · Privacy engineering 30% · Data engineering 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

The archive download succeeds even when one source query failed and an entire section is missing.

Acceptance criteria

- Record schema version, section counts, selection boundary and artifact digest.

- Distinguish intentionally omitted sections from failed required sections.

- Mark ready only after required sections and digest validation succeed.

Implementation constraints

- A digest establishes artifact consistency, not completeness beyond the declared export contract.

Verification

- Fail the required private-note query and verify the export remains non-ready and non-downloadable, with the required-section failure reported explicitly.

- Corrupt a completed temporary artifact and verify publication is blocked.

Deliverables

- Manifest validator and incomplete-section fixtures

Rollout and recovery: Place manifest validation before the ready transition; keep failed artifacts inaccessible and eligible for cleanup.

Project prerequisites: Create synthetic members, private notes and shared-document contributions in a local database. Provide fake queue and object-storage adapters with controllable expiry and failure.

Engineer value: Practice export scoping, consistency, streaming and expiring access without leaking other members’ data.

Company value: Create a reviewable export contract and cross-subject regression suite for an approved product policy.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

### Deliver and expire access

Restrict retrieval and verify cleanup and disclosure behavior.

#### REXPORT-107 — Issue a short-lived download capability only after subject authorization

**Story · Medium priority · Advanced**

noCV practice brief v5 · REXPORT-107 · Deliver a personal data export with a narrow access boundary

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Deliver and expire access. Depends on: REXPORT-103, REXPORT-106.

Difficulty: Advanced. Estimated focused work: 210 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 60% · Privacy engineering 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A predictable artifact URL lets one member retrieve another member’s completed export.

Acceptance criteria

- Authorize every capability request against the current subject and export operation.

- Scope the capability to one object and a declared short lifetime.

- Keep capabilities out of generic logs, analytics and unrelated API responses.

Implementation constraints

- Use a local storage adapter implementing the capability contract; an opaque URL alone is not authorization.

Verification

- Request and use a valid capability for the matching export.

- Attempt another subject’s operation, an expired capability and an altered object reference; all must fail without bytes.

Deliverables

- Download capability endpoint and scope/expiry tests

Rollout and recovery: Enable downloads only after complete artifacts exist; disable capability issuance independently during an incident.

Project prerequisites: Create synthetic members, private notes and shared-document contributions in a local database. Provide fake queue and object-storage adapters with controllable expiry and failure.

Engineer value: Practice export scoping, consistency, streaming and expiring access without leaking other members’ data.

Company value: Create a reviewable export contract and cross-subject regression suite for an approved product policy.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### REXPORT-108 — Revoke export access when the subject loses the required session

**Bug · High priority · Expert**

noCV practice brief v5 · REXPORT-108 · Deliver a personal data export with a narrow access boundary

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Deliver and expire access. Depends on: REXPORT-103, REXPORT-107.

Difficulty: Expert. Estimated focused work: 300 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 40% · Privacy engineering 40% · System design 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A member signs out all sessions after an account concern, but a previously issued export link remains usable longer than the product policy allows.

Acceptance criteria

- Define the revocation guarantee and the limits of direct object-store capabilities.

- Choose a bounded retrieval design that meets the stated exercise policy and document its latency/availability tradeoff.

- Prevent new access after revocation and state how an already-started transfer is handled.

Implementation constraints

- Do not promise immediate revocation of an independently valid signed URL without a mechanism that can enforce it.

Verification

- Issue access, revoke the session and attempt a new download under the chosen design.

- Revoke during a paused transfer and verify the documented in-flight behavior and resource cleanup.

Deliverables

- Revocation design decision and enforced retrieval tests

Rollout and recovery: Roll out the chosen retrieval path under a new capability version; stop issuing the old form before claiming the new guarantee.

Project prerequisites: Create synthetic members, private notes and shared-document contributions in a local database. Provide fake queue and object-storage adapters with controllable expiry and failure.

Engineer value: Practice export scoping, consistency, streaming and expiring access without leaking other members’ data.

Company value: Create a reviewable export contract and cross-subject regression suite for an approved product policy.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### REXPORT-109 — Expire export artifacts and incomplete assembly objects separately

**Chore · Medium priority · Advanced**

noCV practice brief v5 · REXPORT-109 · Deliver a personal data export with a narrow access boundary

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Deliver and expire access. Depends on: REXPORT-105, REXPORT-106, REXPORT-107.

Difficulty: Advanced. Estimated focused work: 180 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Privacy engineering 50% · Storage systems 30% · Site reliability 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Completed exports expire after a day, but failed assembly objects remain indefinitely under a different prefix.

Acceptance criteria

- Define bounded lifetimes for ready, failed and abandoned temporary artifacts.

- Recheck active assembly ownership before removing a temporary object.

- Confirm object removal separately from expired download access.

Implementation constraints

- Use an injected clock and per-operation object registry; prefix age alone cannot distinguish an active write.

Verification

- Advance time through each lifecycle and verify correct removal eligibility.

- Race cleanup with an active assembly lease and verify either safe retention or the declared cancellation path.

Deliverables

- Artifact cleanup policy and lifecycle race tests

Rollout and recovery: Run a scoped preview before local cleanup; retain unresolved storage outcomes for reconciliation.

Project prerequisites: Create synthetic members, private notes and shared-document contributions in a local database. Provide fake queue and object-storage adapters with controllable expiry and failure.

Engineer value: Practice export scoping, consistency, streaming and expiring access without leaking other members’ data.

Company value: Create a reviewable export contract and cross-subject regression suite for an approved product policy.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### REXPORT-110 — Review the export for cross-member disclosure and delivery failures

**Task · Medium priority · Expert**

noCV practice brief v5 · REXPORT-110 · Deliver a personal data export with a narrow access boundary

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Deliver and expire access. Depends on: REXPORT-102, REXPORT-106, REXPORT-108, REXPORT-109.

Difficulty: Expert. Estimated focused work: 270 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Privacy engineering 50% · Quality engineering 30% · Security 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

The happy-path export looks correct, but nobody has reviewed shared records, access revocation and abandoned files together.

Acceptance criteria

- Run a fixture matrix covering two members, two organizations, shared contributions and private notes.

- Reconcile manifest counts and allowed fields with the declared policy and actual artifact.

- Report tested boundaries, omitted content and unresolved provider limitations without a blanket privacy certification.

Implementation constraints

- The exercise review is a reproducible engineering check; it does not create noCV evidence or legal assurance by itself.

Verification

- Attempt creation, polling and download across subject/organization boundaries.

- Exercise interrupted assembly, expiry and session revocation, then inventory remaining local artifacts.

Deliverables

- Export review report and reproducible disclosure/failure matrix

Rollout and recovery: Enable the complete local flow only when required cases pass; keep unsupported content categories explicitly out of the export contract.

Project prerequisites: Create synthetic members, private notes and shared-document contributions in a local database. Provide fake queue and object-storage adapters with controllable expiry and failure.

Engineer value: Practice export scoping, consistency, streaming and expiring access without leaking other members’ data.

Company value: Create a reviewable export contract and cross-subject regression suite for an approved product policy.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.
