Files
code-review-graph/skills/project-review/references/manual-review/payment.md
T
dev 307d2fd471 feat: add project-review workflow (whole-project / single-feature review)
Adds the project-review workflow for code review independent of the git
diff. The scope is parsed from the user instruction: 全面/整个项目 ->
whole-project (score every source file), otherwise feature + target
keyword (locate the code with semantic search + graph queries).

- scoring_tools.py: score_review_func gains all_files=True to score every
  source file in the graph via store.get_all_files()
- main.py: score_review_tool gains all_files param; registers the
  project_review MCP prompt (prompts 6->7)
- prompts.py: project_review_prompt(scope, target) with whole-project and
  feature branches (fixed a precedence bug that truncated the feature text)
- skills.py + skills/project-review/: new read-only project-review skill
  with shared checklists
- .opencode/command/code-review-graph-project-review.md: slash command
- tests: test_project_review.py (prompt rendering), TestProjectReviewPrompt,
  skill count assertions 5->6, all_files wiring checks
- docs: prompts (6->7) + project-review entries across COMMANDS, CLAUDE,
  README (+localized), INDEX, architecture, LLM-OPTIMIZED-REFERENCE,
  CHANGELOG
2026-08-06 13:56:54 +08:00

702 B

Payment Module — Manual Review Checklist

High-risk module: payment changes require human confirmation for every blocker/major fix.

  • Callback idempotency: a duplicated webhook/callback does not double-charge
  • Amounts stored as fixed-point (integers/cents), never floats
  • Currency codes and precision handled correctly
  • Provider signature / HMAC verification on callbacks
  • Refund logic: correct reversal, no double-refund
  • Failure path: payment timeout, declined, retry semantics
  • Transaction boundary spans charge + order-state update
  • Sensitive data (PAN, tokens) never logged or masked on output
  • Ledger/journal entries are append-only and auditable