feat(rules): user permanent rules — writing style, web building, web security (BDR-085)
Three rules/ files from the user's permanent-rules text: - writing-style.md (always-on): em-dash ban, no it's-not-X-it's-Y, no emoji, no decorative bold, no reflex triads, no hedging chains, slop vocabulary ban, sentence-length variety, deliverable self-check. Scope carve-outs keep caveman registries, code comments, skill templates intact. - web-building.md (path-scoped): design anti-default list + public-site done checklist (report missing items, never invent them). - web-security.md (path-scoped): browser-exposed keys, service-key/client split, RLS, server-side auth, IDOR, cookie flags, field minimization, rate limiting — extends §Security, no dup of the core. Project CLAUDE.md rules/ doctrine: 320-budget exception for standalone always-on user rule sets.
This commit is contained in:
@@ -0,0 +1,21 @@
|
||||
---
|
||||
paths: ["**/*.ts", "**/*.tsx", "**/*.js", "**/*.jsx", "**/*.vue", "**/*.svelte", "**/*.astro", "**/*.php", "**/*.py"]
|
||||
---
|
||||
|
||||
# Web app security — specifics
|
||||
|
||||
Extends the global Security section (input validation, parameterized
|
||||
queries, secrets in env vars, AuthN/AuthZ, fail closed). If a request
|
||||
breaks one of these rules, say so instead of doing it.
|
||||
|
||||
- No API key in code shipped to the browser. Env vars, server-side only.
|
||||
- The service/admin key never reaches the client: publishable key only.
|
||||
- Row Level Security enabled on every table (Supabase/Postgres and kin).
|
||||
- Authentication verified server-side, never only in the browser.
|
||||
- No IDOR: changing an id in a URL must never expose another user's
|
||||
data. Authorize object access on every request.
|
||||
- Passwords hashed (bcrypt/argon2). Session cookies httpOnly + secure
|
||||
+ sameSite.
|
||||
- API responses return only the fields the client needs.
|
||||
- Login rate limiting, upload restrictions (type/size), forced HTTPS,
|
||||
security headers.
|
||||
Reference in New Issue
Block a user