Files
claude/rules/web-security.md
Bastien Chanot 12e5324065 feat(rules): user permanent rules — writing style, web building, web security (BDR-085)
Three rules/ files from the user's permanent-rules text:
- writing-style.md (always-on): em-dash ban, no it's-not-X-it's-Y, no
  emoji, no decorative bold, no reflex triads, no hedging chains, slop
  vocabulary ban, sentence-length variety, deliverable self-check.
  Scope carve-outs keep caveman registries, code comments, skill
  templates intact.
- web-building.md (path-scoped): design anti-default list + public-site
  done checklist (report missing items, never invent them).
- web-security.md (path-scoped): browser-exposed keys, service-key/client
  split, RLS, server-side auth, IDOR, cookie flags, field minimization,
  rate limiting — extends §Security, no dup of the core.
Project CLAUDE.md rules/ doctrine: 320-budget exception for standalone
always-on user rule sets.
2026-08-25 19:48:02 +02:00

989 B

paths
paths
**/*.ts
**/*.tsx
**/*.js
**/*.jsx
**/*.vue
**/*.svelte
**/*.astro
**/*.php
**/*.py

Web app security — specifics

Extends the global Security section (input validation, parameterized queries, secrets in env vars, AuthN/AuthZ, fail closed). If a request breaks one of these rules, say so instead of doing it.

  • No API key in code shipped to the browser. Env vars, server-side only.
  • The service/admin key never reaches the client: publishable key only.
  • Row Level Security enabled on every table (Supabase/Postgres and kin).
  • Authentication verified server-side, never only in the browser.
  • No IDOR: changing an id in a URL must never expose another user's data. Authorize object access on every request.
  • Passwords hashed (bcrypt/argon2). Session cookies httpOnly + secure
    • sameSite.
  • API responses return only the fields the client needs.
  • Login rate limiting, upload restrictions (type/size), forced HTTPS, security headers.