From 12e53240652b944a7c84b3e65c0fcfd4ff134891 Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Tue, 25 Aug 2026 19:48:02 +0200 Subject: [PATCH] =?UTF-8?q?feat(rules):=20user=20permanent=20rules=20?= =?UTF-8?q?=E2=80=94=20writing=20style,=20web=20building,=20web=20security?= =?UTF-8?q?=20(BDR-085)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Three rules/ files from the user's permanent-rules text: - writing-style.md (always-on): em-dash ban, no it's-not-X-it's-Y, no emoji, no decorative bold, no reflex triads, no hedging chains, slop vocabulary ban, sentence-length variety, deliverable self-check. Scope carve-outs keep caveman registries, code comments, skill templates intact. - web-building.md (path-scoped): design anti-default list + public-site done checklist (report missing items, never invent them). - web-security.md (path-scoped): browser-exposed keys, service-key/client split, RLS, server-side auth, IDOR, cookie flags, field minimization, rate limiting — extends §Security, no dup of the core. Project CLAUDE.md rules/ doctrine: 320-budget exception for standalone always-on user rule sets. --- CHANGELOG.md | 7 +++++++ CLAUDE.md | 4 +++- rules/web-building.md | 30 ++++++++++++++++++++++++++++++ rules/web-security.md | 21 +++++++++++++++++++++ rules/writing-style.md | 29 +++++++++++++++++++++++++++++ 5 files changed, 90 insertions(+), 1 deletion(-) create mode 100644 rules/web-building.md create mode 100644 rules/web-security.md create mode 100644 rules/writing-style.md diff --git a/CHANGELOG.md b/CHANGELOG.md index 6f27f95..568e868 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,13 @@ Format follows [Keep a Changelog](https://keepachangelog.com/). ## [Unreleased] ### Added +- **User permanent rules (BDR-085)** — three new rules/ files from the + user's rule text: `writing-style.md` (always-on: em-dash ban, no slop + vocabulary, no hedging chains, deliverable self-check), + `web-building.md` (path-scoped: design anti-defaults + public-site done + checklist), `web-security.md` (path-scoped: RLS, service-key/client + split, IDOR, cookie flags, rate limiting — extends §Security, no dup). + Project CLAUDE.md rules/ doctrine gains the 320-budget exception. - **/tour multi-project parallel fan-out (BDR-084)** — two or more project paths now dispatch one runner per repo in a single message (independent working trees, nothing collides) instead of processing diff --git a/CLAUDE.md b/CLAUDE.md index a7b5941..94091bb 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -17,7 +17,9 @@ A rule WITH `paths:` YAML frontmatter (glob list) loads lazily — only when Claude reads a file matching a glob; a rule WITHOUT it loads at session start, same cost as the global memory. Extract from CLAUDE.global.md only what can be path-scoped (the token win) or what is generated; always-on -doctrine stays in CLAUDE.global.md. `paths:` globs match against the +doctrine stays in CLAUDE.global.md. Exception: a standalone user-authored +rule set that would bust the 320-line density budget may live here WITHOUT +`paths:` (always-on load) — writing-style.md (BDR-085). `paths:` globs match against the CURRENT project's tree — a broad glob (e.g. `rules/**`) can fire in foreign projects; keep rule bodies tiny. Docs: https://code.claude.com/docs/en/memory.md#path-specific-rules diff --git a/rules/web-building.md b/rules/web-building.md new file mode 100644 index 0000000..c60a473 --- /dev/null +++ b/rules/web-building.md @@ -0,0 +1,30 @@ +--- +paths: ["**/*.html", "**/*.astro", "**/*.css", "**/*.scss", "**/*.tsx", "**/*.jsx", "**/*.vue", "**/*.svelte"] +--- + +# Web building — no default reflexes + done checklist + +## Avoid unless the user asks for them +- Purple gradient, purple/black, neon, washed-out pastels, rainbow. +- Drop shadow on everything; the same border-radius on every element. +- Bento grid, dot grid, glowing background orbs, decorative color strip. +- Sparkle icons, animated arrows, emojis as icons, decorative fake + terminal window. +- Hover animation on every element; scroll-reveal animations everywhere. +- Three aligned feature cards, three pricing tiers, checkmark bullets. +- Vague hero title ("unleash your potential"): state what the product does. +- Fake testimonials, fake visitor or client counters, invented numbers. + Never, in any context. +- Inter, Geist or Space Grotesk as the default font: propose an + alternative and justify it. Existing brand identities keep their fonts. + +## Before declaring a public site done +Check: custom 404 · call to action in the first viewport · per-page +title + description · share/OG image · favicons · robots.txt · sitemap · +alt text on images · layout tested at 375 px · loading states · form +error messages · confirmation page · real legal mentions · cookie banner +with a working refuse option · audience measurement · contact address · +compressed images. +Report the missing items to the user instead of inventing them. Internal +tools and dashboards: only the relevant items apply. Deep audits stay +with /seo, /harden, /web-validate. diff --git a/rules/web-security.md b/rules/web-security.md new file mode 100644 index 0000000..abbf7a2 --- /dev/null +++ b/rules/web-security.md @@ -0,0 +1,21 @@ +--- +paths: ["**/*.ts", "**/*.tsx", "**/*.js", "**/*.jsx", "**/*.vue", "**/*.svelte", "**/*.astro", "**/*.php", "**/*.py"] +--- + +# Web app security — specifics + +Extends the global Security section (input validation, parameterized +queries, secrets in env vars, AuthN/AuthZ, fail closed). If a request +breaks one of these rules, say so instead of doing it. + +- No API key in code shipped to the browser. Env vars, server-side only. +- The service/admin key never reaches the client: publishable key only. +- Row Level Security enabled on every table (Supabase/Postgres and kin). +- Authentication verified server-side, never only in the browser. +- No IDOR: changing an id in a URL must never expose another user's + data. Authorize object access on every request. +- Passwords hashed (bcrypt/argon2). Session cookies httpOnly + secure + + sameSite. +- API responses return only the fields the client needs. +- Login rate limiting, upload restrictions (type/size), forced HTTPS, + security headers. diff --git a/rules/writing-style.md b/rules/writing-style.md new file mode 100644 index 0000000..1f8a48b --- /dev/null +++ b/rules/writing-style.md @@ -0,0 +1,29 @@ +# Writing style — user-facing prose + +Scope: prose written FOR the user: answers, docs, reports, deliverables, +site copy. Does NOT override memory registries (caveman format), code +comments (code style rules), or structured skill/report templates. + +Banned: +- Em-dash. Use a comma, a colon, or a period. +- The "it's not X, it's Y" / "ce n'est pas X, c'est Y" frame. +- Emojis, unless explicitly requested. +- Decorative bold. Bold marks a key term, not one word per sentence. +- Rule-of-three enumerations by reflex. Two often suffice, four sometimes. +- Hedging chains ("il est possible que", "could potentially", "in some + cases"). Assert, or say you don't know. +- Restating the user's question before answering it. +- Slop vocabulary, buzzword sense: delve, explorons, plongeons, "il + convient de noter" / "it's worth noting", figurative paysage/landscape, + robuste/robust, transformer/transform. Technical senses stay allowed + (robustness as a review lens, a math transform). + +Do: +- Vary sentence and paragraph length. A short sentence after a long one. +- Write like speech. A sentence you cannot say aloud in one breath gets + cut in two. +- A paragraph over a bullet list when prose carries it. + +Self-check before handing over a deliverable (text, site, feature): +reread against these rules (plus the web rules for a site) and tell the +user what you corrected to comply, or that nothing needed correcting.