-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.coderabbit.yaml
More file actions
71 lines (71 loc) · 3.25 KB
/
Copy path.coderabbit.yaml
File metadata and controls
71 lines (71 loc) · 3.25 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
# NOTE: tone_instructions must stay <=250 chars — over-limit silently falls
# back to CodeRabbit defaults (hit in #89).
# yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json
language: en-US
early_access: false
tone_instructions: >-
Prioritize data integrity, runtime correctness, and PII on exfiltration surfaces (URLs, logs, payloads, responses). Same-device drafts are owner-approved — see path_instructions. Flag sync setState in effects, non-atomic writes, error logging.
reviews:
profile: chill
request_changes_workflow: false
high_level_summary: true
review_status: true
auto_review:
enabled: true
drafts: false
base_branches:
- dev
path_filters:
- '!pnpm-lock.yaml'
- '!messages/**'
- '!docs/**'
- '!.opencode/**'
path_instructions:
- path: app/api/**
instructions: >-
Verify every route enforces auth via getSession() and role checks before data access,
validates input with zod, and never logs request bodies, tokens, or PII.
- path: lib/auth/**
instructions: >-
Focus on JWT/session handling correctness (HS256, expiry), secret hygiene, and that no
token material is ever logged or exposed in responses.
- path: modules/orders/**
instructions: >-
Verify multi-table writes are atomic for the driver (neon-http has no
transactions — use db.batch), totals are computed server-side, and
inventory deduction never runs after a failed availability check.
- path: lib/inventory-management.ts
instructions: >-
Stock changes must be atomic conditional decrements, not
read-modify-write; movements recorded only after successful decrements.
- path: e2e/**
instructions: >-
Locators must be strict-mode safe (no ambiguous getByText regexes),
avoid asserting on toast wrapper duplication, and keep environment
assumptions explicit.
- path: test/**
instructions: >-
Mocks must mirror real driver constraints (e.g. neon-http batch/transaction
support) so green tests cannot mask runtime breakage.
- path: store/**
instructions: >-
Same-device localStorage drafts (cart items, checkout contact,
offline queue) are owner-approved. Do not flag PII at rest here;
verify shape-validation on rehydrate (corrupt → fallback),
manual rehydration gating for SSR pages, and that no draft data is
transmitted except inside the existing order submit payload.
- path: modules/core/hooks/use-offline-orders.ts
instructions: >-
Established precedent for the approved localStorage-draft pattern
(person details included). Judge store/** changes against it.
- path: proxy.ts
instructions: >-
Public catalog is by design (/, /products incl. /products/[id],
/order). Only flag newly exposed auth-gated surfaces
(/dashboard/*, /profile/*) or weakened role checks.
- path: lib/log-error.ts
instructions: >-
The BLOCKED_KEYS allowlist is intentional privacy-by-design; never
ask to log PII, bodies, tokens, or user agents. Debuggability comes
from correlation IDs (order/tracking/ingredient) and curated
messages — flag their absence instead.