feat(rules): user permanent rules — writing style, web building, web security (BDR-085)

Three rules/ files from the user's permanent-rules text:
- writing-style.md (always-on): em-dash ban, no it's-not-X-it's-Y, no
  emoji, no decorative bold, no reflex triads, no hedging chains, slop
  vocabulary ban, sentence-length variety, deliverable self-check.
  Scope carve-outs keep caveman registries, code comments, skill
  templates intact.
- web-building.md (path-scoped): design anti-default list + public-site
  done checklist (report missing items, never invent them).
- web-security.md (path-scoped): browser-exposed keys, service-key/client
  split, RLS, server-side auth, IDOR, cookie flags, field minimization,
  rate limiting — extends §Security, no dup of the core.
Project CLAUDE.md rules/ doctrine: 320-budget exception for standalone
always-on user rule sets.
This commit is contained in:
Bastien Chanot
2026-08-25 19:48:02 +02:00
parent dbc7d7aa70
commit 12e5324065
5 changed files with 90 additions and 1 deletions
+7
View File
@@ -7,6 +7,13 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
## [Unreleased] ## [Unreleased]
### Added ### Added
- **User permanent rules (BDR-085)** — three new rules/ files from the
user's rule text: `writing-style.md` (always-on: em-dash ban, no slop
vocabulary, no hedging chains, deliverable self-check),
`web-building.md` (path-scoped: design anti-defaults + public-site done
checklist), `web-security.md` (path-scoped: RLS, service-key/client
split, IDOR, cookie flags, rate limiting — extends §Security, no dup).
Project CLAUDE.md rules/ doctrine gains the 320-budget exception.
- **/tour multi-project parallel fan-out (BDR-084)** — two or more - **/tour multi-project parallel fan-out (BDR-084)** — two or more
project paths now dispatch one runner per repo in a single message project paths now dispatch one runner per repo in a single message
(independent working trees, nothing collides) instead of processing (independent working trees, nothing collides) instead of processing
+3 -1
View File
@@ -17,7 +17,9 @@ A rule WITH `paths:` YAML frontmatter (glob list) loads lazily — only when
Claude reads a file matching a glob; a rule WITHOUT it loads at session Claude reads a file matching a glob; a rule WITHOUT it loads at session
start, same cost as the global memory. Extract from CLAUDE.global.md only start, same cost as the global memory. Extract from CLAUDE.global.md only
what can be path-scoped (the token win) or what is generated; always-on what can be path-scoped (the token win) or what is generated; always-on
doctrine stays in CLAUDE.global.md. `paths:` globs match against the doctrine stays in CLAUDE.global.md. Exception: a standalone user-authored
rule set that would bust the 320-line density budget may live here WITHOUT
`paths:` (always-on load) — writing-style.md (BDR-085). `paths:` globs match against the
CURRENT project's tree — a broad glob (e.g. `rules/**`) can fire in foreign CURRENT project's tree — a broad glob (e.g. `rules/**`) can fire in foreign
projects; keep rule bodies tiny. projects; keep rule bodies tiny.
Docs: https://code.claude.com/docs/en/memory.md#path-specific-rules Docs: https://code.claude.com/docs/en/memory.md#path-specific-rules
+30
View File
@@ -0,0 +1,30 @@
---
paths: ["**/*.html", "**/*.astro", "**/*.css", "**/*.scss", "**/*.tsx", "**/*.jsx", "**/*.vue", "**/*.svelte"]
---
# Web building — no default reflexes + done checklist
## Avoid unless the user asks for them
- Purple gradient, purple/black, neon, washed-out pastels, rainbow.
- Drop shadow on everything; the same border-radius on every element.
- Bento grid, dot grid, glowing background orbs, decorative color strip.
- Sparkle icons, animated arrows, emojis as icons, decorative fake
terminal window.
- Hover animation on every element; scroll-reveal animations everywhere.
- Three aligned feature cards, three pricing tiers, checkmark bullets.
- Vague hero title ("unleash your potential"): state what the product does.
- Fake testimonials, fake visitor or client counters, invented numbers.
Never, in any context.
- Inter, Geist or Space Grotesk as the default font: propose an
alternative and justify it. Existing brand identities keep their fonts.
## Before declaring a public site done
Check: custom 404 · call to action in the first viewport · per-page
title + description · share/OG image · favicons · robots.txt · sitemap ·
alt text on images · layout tested at 375 px · loading states · form
error messages · confirmation page · real legal mentions · cookie banner
with a working refuse option · audience measurement · contact address ·
compressed images.
Report the missing items to the user instead of inventing them. Internal
tools and dashboards: only the relevant items apply. Deep audits stay
with /seo, /harden, /web-validate.
+21
View File
@@ -0,0 +1,21 @@
---
paths: ["**/*.ts", "**/*.tsx", "**/*.js", "**/*.jsx", "**/*.vue", "**/*.svelte", "**/*.astro", "**/*.php", "**/*.py"]
---
# Web app security — specifics
Extends the global Security section (input validation, parameterized
queries, secrets in env vars, AuthN/AuthZ, fail closed). If a request
breaks one of these rules, say so instead of doing it.
- No API key in code shipped to the browser. Env vars, server-side only.
- The service/admin key never reaches the client: publishable key only.
- Row Level Security enabled on every table (Supabase/Postgres and kin).
- Authentication verified server-side, never only in the browser.
- No IDOR: changing an id in a URL must never expose another user's
data. Authorize object access on every request.
- Passwords hashed (bcrypt/argon2). Session cookies httpOnly + secure
+ sameSite.
- API responses return only the fields the client needs.
- Login rate limiting, upload restrictions (type/size), forced HTTPS,
security headers.
+29
View File
@@ -0,0 +1,29 @@
# Writing style — user-facing prose
Scope: prose written FOR the user: answers, docs, reports, deliverables,
site copy. Does NOT override memory registries (caveman format), code
comments (code style rules), or structured skill/report templates.
Banned:
- Em-dash. Use a comma, a colon, or a period.
- The "it's not X, it's Y" / "ce n'est pas X, c'est Y" frame.
- Emojis, unless explicitly requested.
- Decorative bold. Bold marks a key term, not one word per sentence.
- Rule-of-three enumerations by reflex. Two often suffice, four sometimes.
- Hedging chains ("il est possible que", "could potentially", "in some
cases"). Assert, or say you don't know.
- Restating the user's question before answering it.
- Slop vocabulary, buzzword sense: delve, explorons, plongeons, "il
convient de noter" / "it's worth noting", figurative paysage/landscape,
robuste/robust, transformer/transform. Technical senses stay allowed
(robustness as a review lens, a math transform).
Do:
- Vary sentence and paragraph length. A short sentence after a long one.
- Write like speech. A sentence you cannot say aloud in one breath gets
cut in two.
- A paragraph over a bullet list when prose carries it.
Self-check before handing over a deliverable (text, site, feature):
reread against these rules (plus the web rules for a site) and tell the
user what you corrected to comply, or that nothing needed correcting.