forked from bchanot/claude
feat(rules): user permanent rules — writing style, web building, web security (BDR-085)
Three rules/ files from the user's permanent-rules text: - writing-style.md (always-on): em-dash ban, no it's-not-X-it's-Y, no emoji, no decorative bold, no reflex triads, no hedging chains, slop vocabulary ban, sentence-length variety, deliverable self-check. Scope carve-outs keep caveman registries, code comments, skill templates intact. - web-building.md (path-scoped): design anti-default list + public-site done checklist (report missing items, never invent them). - web-security.md (path-scoped): browser-exposed keys, service-key/client split, RLS, server-side auth, IDOR, cookie flags, field minimization, rate limiting — extends §Security, no dup of the core. Project CLAUDE.md rules/ doctrine: 320-budget exception for standalone always-on user rule sets.
This commit is contained in:
@@ -7,6 +7,13 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
|
||||
## [Unreleased]
|
||||
|
||||
### Added
|
||||
- **User permanent rules (BDR-085)** — three new rules/ files from the
|
||||
user's rule text: `writing-style.md` (always-on: em-dash ban, no slop
|
||||
vocabulary, no hedging chains, deliverable self-check),
|
||||
`web-building.md` (path-scoped: design anti-defaults + public-site done
|
||||
checklist), `web-security.md` (path-scoped: RLS, service-key/client
|
||||
split, IDOR, cookie flags, rate limiting — extends §Security, no dup).
|
||||
Project CLAUDE.md rules/ doctrine gains the 320-budget exception.
|
||||
- **/tour multi-project parallel fan-out (BDR-084)** — two or more
|
||||
project paths now dispatch one runner per repo in a single message
|
||||
(independent working trees, nothing collides) instead of processing
|
||||
|
||||
@@ -17,7 +17,9 @@ A rule WITH `paths:` YAML frontmatter (glob list) loads lazily — only when
|
||||
Claude reads a file matching a glob; a rule WITHOUT it loads at session
|
||||
start, same cost as the global memory. Extract from CLAUDE.global.md only
|
||||
what can be path-scoped (the token win) or what is generated; always-on
|
||||
doctrine stays in CLAUDE.global.md. `paths:` globs match against the
|
||||
doctrine stays in CLAUDE.global.md. Exception: a standalone user-authored
|
||||
rule set that would bust the 320-line density budget may live here WITHOUT
|
||||
`paths:` (always-on load) — writing-style.md (BDR-085). `paths:` globs match against the
|
||||
CURRENT project's tree — a broad glob (e.g. `rules/**`) can fire in foreign
|
||||
projects; keep rule bodies tiny.
|
||||
Docs: https://code.claude.com/docs/en/memory.md#path-specific-rules
|
||||
|
||||
@@ -0,0 +1,30 @@
|
||||
---
|
||||
paths: ["**/*.html", "**/*.astro", "**/*.css", "**/*.scss", "**/*.tsx", "**/*.jsx", "**/*.vue", "**/*.svelte"]
|
||||
---
|
||||
|
||||
# Web building — no default reflexes + done checklist
|
||||
|
||||
## Avoid unless the user asks for them
|
||||
- Purple gradient, purple/black, neon, washed-out pastels, rainbow.
|
||||
- Drop shadow on everything; the same border-radius on every element.
|
||||
- Bento grid, dot grid, glowing background orbs, decorative color strip.
|
||||
- Sparkle icons, animated arrows, emojis as icons, decorative fake
|
||||
terminal window.
|
||||
- Hover animation on every element; scroll-reveal animations everywhere.
|
||||
- Three aligned feature cards, three pricing tiers, checkmark bullets.
|
||||
- Vague hero title ("unleash your potential"): state what the product does.
|
||||
- Fake testimonials, fake visitor or client counters, invented numbers.
|
||||
Never, in any context.
|
||||
- Inter, Geist or Space Grotesk as the default font: propose an
|
||||
alternative and justify it. Existing brand identities keep their fonts.
|
||||
|
||||
## Before declaring a public site done
|
||||
Check: custom 404 · call to action in the first viewport · per-page
|
||||
title + description · share/OG image · favicons · robots.txt · sitemap ·
|
||||
alt text on images · layout tested at 375 px · loading states · form
|
||||
error messages · confirmation page · real legal mentions · cookie banner
|
||||
with a working refuse option · audience measurement · contact address ·
|
||||
compressed images.
|
||||
Report the missing items to the user instead of inventing them. Internal
|
||||
tools and dashboards: only the relevant items apply. Deep audits stay
|
||||
with /seo, /harden, /web-validate.
|
||||
@@ -0,0 +1,21 @@
|
||||
---
|
||||
paths: ["**/*.ts", "**/*.tsx", "**/*.js", "**/*.jsx", "**/*.vue", "**/*.svelte", "**/*.astro", "**/*.php", "**/*.py"]
|
||||
---
|
||||
|
||||
# Web app security — specifics
|
||||
|
||||
Extends the global Security section (input validation, parameterized
|
||||
queries, secrets in env vars, AuthN/AuthZ, fail closed). If a request
|
||||
breaks one of these rules, say so instead of doing it.
|
||||
|
||||
- No API key in code shipped to the browser. Env vars, server-side only.
|
||||
- The service/admin key never reaches the client: publishable key only.
|
||||
- Row Level Security enabled on every table (Supabase/Postgres and kin).
|
||||
- Authentication verified server-side, never only in the browser.
|
||||
- No IDOR: changing an id in a URL must never expose another user's
|
||||
data. Authorize object access on every request.
|
||||
- Passwords hashed (bcrypt/argon2). Session cookies httpOnly + secure
|
||||
+ sameSite.
|
||||
- API responses return only the fields the client needs.
|
||||
- Login rate limiting, upload restrictions (type/size), forced HTTPS,
|
||||
security headers.
|
||||
@@ -0,0 +1,29 @@
|
||||
# Writing style — user-facing prose
|
||||
|
||||
Scope: prose written FOR the user: answers, docs, reports, deliverables,
|
||||
site copy. Does NOT override memory registries (caveman format), code
|
||||
comments (code style rules), or structured skill/report templates.
|
||||
|
||||
Banned:
|
||||
- Em-dash. Use a comma, a colon, or a period.
|
||||
- The "it's not X, it's Y" / "ce n'est pas X, c'est Y" frame.
|
||||
- Emojis, unless explicitly requested.
|
||||
- Decorative bold. Bold marks a key term, not one word per sentence.
|
||||
- Rule-of-three enumerations by reflex. Two often suffice, four sometimes.
|
||||
- Hedging chains ("il est possible que", "could potentially", "in some
|
||||
cases"). Assert, or say you don't know.
|
||||
- Restating the user's question before answering it.
|
||||
- Slop vocabulary, buzzword sense: delve, explorons, plongeons, "il
|
||||
convient de noter" / "it's worth noting", figurative paysage/landscape,
|
||||
robuste/robust, transformer/transform. Technical senses stay allowed
|
||||
(robustness as a review lens, a math transform).
|
||||
|
||||
Do:
|
||||
- Vary sentence and paragraph length. A short sentence after a long one.
|
||||
- Write like speech. A sentence you cannot say aloud in one breath gets
|
||||
cut in two.
|
||||
- A paragraph over a bullet list when prose carries it.
|
||||
|
||||
Self-check before handing over a deliverable (text, site, feature):
|
||||
reread against these rules (plus the web rules for a site) and tell the
|
||||
user what you corrected to comply, or that nothing needed correcting.
|
||||
Reference in New Issue
Block a user