Architecture Decision Record Log
Purpose
This file tracks architecture decisions that affect implementation across modules.
Use ADR entries to avoid implicit decisions and reduce design drift.
Status Values
- Proposed
- Accepted
- Superseded
- Deprecated
ADR Format
Each entry should include:
- ID:
ADR-XXXX - Title
- Status
- Date
- Context
- Decision
- Consequences
- Alternatives Considered
- References to PRD, SRS, SDD, and requirement IDs
Template
md
## ADR-XXXX: <Title>
- Status: Proposed | Accepted | Superseded | Deprecated
- Date: YYYY-MM-DD
### Context — ADR-0001
<problem statement and constraints>
### Decision — ADR-0001
<what was chosen>
### Consequences — ADR-0001
<tradeoffs and expected impact>
### Alternatives Considered — ADR-0001
<option 1, option 2, option 3>
### References — ADR-0001
- ../../product/prd.md
- ../srs.md
- ../sdd.md
- Requirement IDs: FR-..., NFR-..., SR-..., SCR-...Working Rules
- A new architecture-impacting PR should include an ADR update when needed.
- Mark old ADRs as superseded instead of deleting history.
- Keep ADR decisions implementation-ready and testable.
- Link ADR decisions to ../../RTM.csv when requirements or coverage are affected.
Accepted ADRs
| ID | Title | Status | Date |
|---|---|---|---|
| ADR-0014 | Open Core architecture — plugin-based modules | Accepted | 2026-07-03 |
| ADR-0015 | Code Quality Tooling — ESLint + Prettier | Superseded | 2026-06-20 |
| ADR-0016 | RBAC Scope System — Permissões com Escopo por Entidade | Proposed | 2026-06-26 |
| ADR-0021 | EntityRepository — Persistence Abstraction for Worker Services | Accepted | 2026-07-04 |
| ADR-0022 | Multi-Role User Support — roles[], user_roles, and AuthPrincipal | Accepted | 2026-07-05 |
| ADR-0023 | Server-Authoritative Model — Command Handler Único + Events como Auditoria | Proposed | 2026-07-07 |
| ADR-0024-unified-error-handling.md | Unified Error Handling — Centralized ErrorCode Registry | Accepted | 2026-07-11 |
| ADR-0025-onboarding-subdomain.md | Onboarding Subdomain — Two Vite Configs vs Separate Project | Accepted | 2026-07-13 |
| ADR-0026-deterministic-daily-codes.md | Deterministic Daily Codes for Offline Check-in/Check-out | Accepted | 2026-07-16 |
| ADR-0027-read-mutation-hooks.md | Two-Hook Read/Mutation Pattern for UI Data Access | Accepted | 2026-07-23 |
| ADR-0028-persistence-pattern-boundaries.md | Persistence Pattern Boundaries — Three Legitimate Strategies | Accepted | 2026-07-23 |
| ADR-0029-amend-adr-0023.md | ADR-0023 Amendment — CommandContext, Proxy Governance, and Enforcement | Proposed | 2026-07-25 |
| ADR-0030-dexie-reversion.md | Dexie Reversion — 8 Key Design Decisions (issue #510) | Accepted | 2026-07-25 |
| ADR-0031-two-pass-pbkdf2.md | Two-Pass PBKDF2 for Free-Tier Password Security | Proposed | 2026-07-28 |
| ADR-0032-durable-objects-fan-out.md | Durable Objects for Real-Time Event Fan-Out | Accepted | 2026-07-29 |
| ADR-0033-mcp-surface.md | MCP Surface — Agent Integration via Model Context Protocol | Proposed | 2026-07-31 |
| ADR-0034-class-session-relationship.md | Class–Session Relationship in Check-in/Capacity Queries | Accepted | 2026-08-05 |
| ADR-0035-translation-policy.md | Unified Translation Policy — App MT+Review; the docs track (manual + pins) is superseded by ADR-0046 | Accepted | 2026-08-09 |
| ADR-0036-authorized-pickup-list.md | Authorized Pickup List — Closed Guardian List Data Model (issue #589) | Accepted | 2026-08-09 |
| ADR-0037-simplify-for-solo-llm.md | Simplify Quality Infrastructure for Solo Dev + LLM | Accepted | 2026-08-10 |
| ADR-0038-termux-environment.md | Termux Environment — Native Subset + CI-Only Gates, No proot | Accepted | 2026-08-09 |
| ADR-0039-online-only-default.md | Online-Only Default Mode — Decoupling the Offline Stack (wayfinder map #667) | Accepted | 2026-08-18 |
| ADR-0040-derived-visitor-status.md | Derived Visitor Status — is_visitor from familyMembershipStatus (issue #151) | Accepted | 2026-08-31 |
| ADR-0041-nucleus-role-join-table.md | Child Nucleus Role in Module Join Table — nucleus_members, not core students (issue #151) | Accepted | 2026-08-31 |
| ADR-0042-pickup-authorization-levels.md | Pickup Authorization Levels — N1 (enrollment) / N2 (phone OTP) / N3 (temporary, parent-present) (issue #758) | Accepted | 2026-09-09 |
| ADR-0043-feed-definition-seam.md | One Definition Per Feed — the fan-out seam #604/#609 left open (amends ADR-0032) | Accepted | 2026-09-09 |
| ADR-0044-portable-core-boundary.md | Portable Core — Cloudflare as deployment platform, not programming model (amends ADR-0028, ADR-0039 §1) | Accepted | 2026-09-11 |
| ADR-0045-civil-calendar-day-boundary.md | Civil Calendar Day Boundary — shared day is the church's zone, age is the viewer's (the evening check-in defect; amended: mirror → packages/dates) | Accepted | 2026-09-13 |
| ADR-0046-pt-br-only-docs-portal.md | pt-BR-Only Docs Portal — remove the docs/en mirror and its tooling; serve a translation notice at /en/ | Accepted | 2026-09-14 |
Archived ADRs
ADRs older than 6 months whose decisions are fully consolidated (implemented, no active controversy) live in archive/. They remain part of the decision history — superseded by later ADRs where applicable — but are no longer read as active guidance.
| ID | Title | Status | Date |
|---|---|---|---|
| ADR-0001 | Local Data Engine and Migration Strategy | Superseded | 2026-04-10 |
| ADR-0002 | Sync Transport, Ordering, and Idempotency | Accepted | 2026-04-10 |
| ADR-0003 | Auth Adapter and Session Token Model | Accepted | 2026-04-10 |
| ADR-0004 | Client-side encryption approach for sensitive local data | Accepted | 2026-04-11 |
| ADR-0005 | Deterministic conflict ordering details | Accepted | 2026-04-11 |
| ADR-0006 | Service-worker cache invalidation strategy | Accepted | 2026-04-11 |
| ADR-0007 | Keycloak token validation boundary | Accepted | 2026-04-11 |
| ADR-0008 | Backend schema and idempotency ledger baseline | Superseded | 2026-04-11 |
| ADR-0009 | Debian + Docker Compose deployment baseline | Accepted | 2026-04-11 |
| ADR-0010 | Backup and restore policy | Superseded | 2026-04-11 |
| ADR-0011 | Phase 2 user-management backend alignment | Accepted | 2026-04-11 |
| ADR-0012 | Photo/media policy | Accepted | 2026-04-11 |
| ADR-0013 | Pagination strategy | Accepted | 2026-04-11 |