final version seems

This commit is contained in:
bchanot
2026-04-08 13:46:45 +02:00
parent f8811fab37
commit f55a2b3fdf
34 changed files with 4270 additions and 1743 deletions
+48 -17
View File
@@ -1,74 +1,105 @@
# <PROJECT NAME> — CLAUDE.md
# This file was generated by /init-project.
# It is the single source of truth for Claude in this repository.
# Global rules live in ~/.claude/CLAUDE.md — this file extends or
# overrides them for this specific project.
# Generated by /init-project. Single source of truth for Claude in this repo.
# Global rules: ~/.claude/CLAUDE.md — this file extends or overrides them.
---
## Project overview
<!-- FILL: 2–4 sentences. What does this project do and for whom. -->
<!-- What it does and for whom. 2-4 sentences. -->
<!-- Ex: REST API for managing food delivery orders. Exposes CRUD endpoints consumed by a React frontend. Single-tenant, deployed on a VPS via Docker Compose. -->
---
## Stack
<!-- FILL: language + version, framework, runtime, database, key services -->
<!-- language+version, framework, runtime, database, key services -->
<!-- Ex: Python 3.12 / FastAPI / PostgreSQL 16 / Redis 7 / Docker Compose -->
---
## Build commands
<!-- FILL: exact commands to build the project -->
<!-- Exact commands — native and Docker if applicable -->
<!-- Ex:
Native : uvicorn src.main:app --reload
Docker : docker compose up --build
Build : docker build -t myapp .
-->
---
## Test commands
<!-- FILL: exact commands to run tests -->
<!-- Ex: pytest src/tests/ -v --cov=src -->
---
## Lint / format commands
<!-- FILL: exact commands, or N/A -->
<!-- Ex: ruff check . && black --check . && mypy src/ -->
<!-- Or: N/A -->
---
## Folder structure
<!-- FILL: actual tree of the project -->
<!-- Actual tree — fill after scaffolding -->
<!-- Ex:
src/
main.py — app init, lifespan hooks
routes/ — one file per resource
models/ — SQLAlchemy models
schemas/ — Pydantic schemas
services/ — business logic
tests/
conftest.py
test_orders.py
-->
---
## Architecture
<!-- FILL: module responsibilities, data flow, key design decisions -->
<!-- Module responsibilities, data flow, key design decisions -->
<!-- Ex: Request → router → service (business logic) → repository (DB) → response.
Auth: JWT validated in a FastAPI dependency injected at router level. -->
---
## Project conventions
<!-- FILL: naming style, file organization, patterns specific to this project -->
<!-- Naming, file organization, patterns specific to this project -->
<!-- Ex: snake_case everywhere. Route files named after the resource (orders.py, users.py).
All DB access goes through repository classes, never direct in routes. -->
---
## Exceptions to global rules
<!-- FILL: explicit overrides of ~/.claude/CLAUDE.md, or write "none — global rules apply" -->
<!-- Explicit overrides of ~/.claude/CLAUDE.md, or: -->
<!-- none — global rules apply -->
---
## Key dependencies
<!-- FILL: library name — purpose, one line each -->
<!-- library — purpose, one line each -->
<!-- Ex:
fastapi — web framework
sqlalchemy — ORM
alembic — DB migrations
pydantic — validation/serialization
pytest — test framework
ruff — linter
-->
---
## Workflow expectations
<!-- FILL: how Claude should behave in this repo:
e.g. always run tests after modification, never modify unrelated files,
ask before large refactors, etc. -->
<!-- How Claude should behave in this repo -->
<!-- Ex: Always run pytest after any model/service change.
Never modify migration files — generate new ones with alembic revision.
Ask before touching the auth dependency or JWT logic. -->
+16 -90
View File
@@ -1,69 +1,4 @@
# Claude Code — Settings Reference
## Where each file goes
```
~/.claude/
├── settings.json ← home-settings.json (renamed) — global, NEVER commit
│
mon-projet/
└── .claude/
├── settings.json ← settings.json — project rules, commit to git
└── settings.local.json← settings.local.json — personal, gitignored
```
Add to your project `.gitignore`:
```
.claude/settings.local.json
```
---
## Precedence (highest → lowest)
```
managed-settings.json system-wide, cannot be overridden
└── CLI flags --allowedTools, --disallowedTools (session only)
└── settings.local.json personal local
└── settings.json project (team)
└── ~/.claude/settings.json global user
```
**DENY always wins over ALLOW, regardless of level.**
---
## What goes where
| Rule type | File |
|---|---|
| Deny secrets, SSH, rm -rf, sudo | `~/.claude/settings.json` |
| Deny git push --force, curl\|bash | `~/.claude/settings.json` |
| Ask git push, docker run, deploy | `~/.claude/settings.json` |
| Ask package managers (brew, apt) | `~/.claude/settings.json` |
| Allow git read-only, ls, cat, grep | `~/.claude/settings.json` |
| Allow npm/cargo/make/pytest... | `.claude/settings.json` (project) |
| Ask psql, mysql, redis-cli | `.claude/settings.json` (project) |
| Allow specific WebFetch domains | `.claude/settings.local.json` |
| Personal additionalDirectories | `.claude/settings.local.json` |
---
## defaultMode values
| Value | Behavior | When to use |
|---|---|---|
| `default` | Prompts on first use of each tool | Normal development |
| `acceptEdits` | Auto-accepts file edits, prompts for Bash | Trusting sessions |
| `plan` | Read-only — Claude plans, cannot execute | Code review, audit |
| `bypassPermissions` | Skips all prompts — **dangerous** | CI/CD only, sandboxed env |
Disable bypass permanently (set in `~/.claude/settings.json`):
```json
{ "permissions": { "disableBypassPermissionsMode": "disable" } }
```
---
# Claude Code — Settings Rule Syntax
## Rule syntax
@@ -83,14 +18,10 @@ Disable bypass permanently (set in `~/.claude/settings.json`):
"Write(**/*.key)" // deny writing any .key file
```
### WebFetch
### WebFetch / WebSearch
```json
"WebFetch(domain:docs.rs)" // specific domain only
"WebFetch" // all web fetches (no sub-pattern)
```
### WebSearch
```json
"WebFetch" // all web fetches
"WebSearch" // no sub-patterns supported
```
@@ -99,32 +30,27 @@ Disable bypass permanently (set in `~/.claude/settings.json`):
"Agent(explorer)"
"Skill(deploy *)"
"mcp__github__*" // all tools from github MCP server
"mcp__playwright__navigate"
```
---
## defaultMode values
| Value | Behavior | When to use |
|---|---|---|
| `default` | Prompts on first use of each tool | Normal development |
| `acceptEdits` | Auto-accepts file edits, prompts for Bash | Trusting sessions |
| `plan` | Read-only — Claude plans, cannot execute | Code review, audit |
| `bypassPermissions` | Skips all prompts — **dangerous** | CI/CD only, sandboxed env |
## Security notes
- `Read(**/.env)` only blocks the Read tool.
`Bash(cat .env)` bypasses it unless you also deny that Bash command.
→ Use `.claudeignore` for hard file exclusion.
- `disableBypassPermissionsMode: "disable"` prevents switching to
bypass mode mid-session — set it in `~/.claude/settings.json`.
- Prefer `ask` over `allow` for anything touching external systems
(git push, deploy, database commands, package install).
- `deny` rules in `~/.claude/settings.json` cannot be overridden
by project-level `allow` rules — deny always wins globally.
---
- `Read(**/.env)` only blocks the Read tool. `Bash(cat .env)` bypasses it unless separately denied.
→ Use `.claudeignore` for hard file exclusion regardless of tool.
- `disableBypassPermissionsMode: "disable"` prevents switching to bypass mode mid-session.
- Prefer `ask` over `allow` for anything touching external systems.
- `deny` in `~/.claude/settings.json` cannot be overridden by project-level `allow` — deny always wins.
## managed-settings.json (enterprise)
Cannot be overridden by any user or project setting.
| OS | Path |
|---|---|
| Windows | `C:\ProgramData\ClaudeCode\managed-settings.json` |
+5 -4
View File
@@ -1,5 +1,4 @@
{
"_readme": "Project-level settings — commit this file. Extends ~/.claude/settings.json. Only put project-specific rules here.",
"permissions": {
@@ -53,19 +52,21 @@
"Bash(docker ps*)",
"Bash(docker images*)",
"Bash(docker logs *)",
"Bash(docker stop *)",
"Bash(docker rm *)",
"Bash(node *)",
"Bash(ts-node *)",
"Bash(tsx *)",
"Bash(npx *)",
"Bash(norminette*)"
],
"ask": [
"Bash(npx *)",
"Bash(docker stop *)",
"Bash(docker rm *)",
"Bash(make deploy*)",
"Bash(npm run deploy*)",
"Bash(cargo publish*)",
-1
View File
@@ -1,5 +1,4 @@
{
"_readme": "Personal local overrides — DO NOT commit. Add .claude/settings.local.json to .gitignore. Highest priority after CLI flags.",
"permissions": {