Thanks for taking the time to improve Finimatic.
Read these first:
- README.md
- docs/GETTING_STARTED.md
- docs/ARCHITECTURE.md
- docs/DATA_MODEL.md
- docs/API_REFERENCE.md
- docs/TESTING.md
- docs/reference/ for historical specs and audits
Backend:
cd backend
python -m venv .venv
source .venv/bin/activate
python -m pip install --upgrade pip
pip install -r requirements.txt
cp sample.env.example .env
python -m pytest -qWindows PowerShell activation:
.\.venv\Scripts\Activate.ps1Frontend:
cd frontend
npm install
cp .env.example .env
npm run build- Do not commit secrets, database files, logs, build output, or
KEYS.md. - Do not add Gmail, Groq, or Gemini keys to frontend code or Vite env variables.
- Keep
VITE_API_URLas the only frontend environment variable. - Preserve the backend-owned send policy and confirmation harness.
- Do not make AI output authoritative for side effects.
- Keep assistant data bounded and redacted.
- Add or update tests for behavior changes.
- Keep documentation aligned with actual code paths.
cd backend
python -m pytest -qcd frontend
npm run build- The change is scoped and described clearly.
- Backend tests pass if backend code changed.
- Frontend build passes if frontend code changed.
- Documentation was updated when behavior changed.
- No raw keys, passwords, tokens, or database files were added.
- Email sends remain gated by policy and confirmation where applicable.
- UI changes include sanitized screenshots when they affect visible behavior.
Open a focused PR and explain:
- what data is read
- what data is written
- whether credentials are touched
- whether email can be sent
- what tests prove the behavior
Changes that weaken credential handling, audit redaction, send policy, or assistant confirmation should not be merged without careful review.