Adds the project-review workflow for code review independent of the git diff. The scope is parsed from the user instruction: 全面/整个项目 -> whole-project (score every source file), otherwise feature + target keyword (locate the code with semantic search + graph queries). - scoring_tools.py: score_review_func gains all_files=True to score every source file in the graph via store.get_all_files() - main.py: score_review_tool gains all_files param; registers the project_review MCP prompt (prompts 6->7) - prompts.py: project_review_prompt(scope, target) with whole-project and feature branches (fixed a precedence bug that truncated the feature text) - skills.py + skills/project-review/: new read-only project-review skill with shared checklists - .opencode/command/code-review-graph-project-review.md: slash command - tests: test_project_review.py (prompt rendering), TestProjectReviewPrompt, skill count assertions 5->6, all_files wiring checks - docs: prompts (6->7) + project-review entries across COMMANDS, CLAUDE, README (+localized), INDEX, architecture, LLM-OPTIMIZED-REFERENCE, CHANGELOG
15 lines
702 B
Markdown
15 lines
702 B
Markdown
# Payment Module — Manual Review Checklist
|
|
|
|
High-risk module: payment changes require human confirmation for every
|
|
blocker/major fix.
|
|
|
|
- [ ] Callback idempotency: a duplicated webhook/callback does not double-charge
|
|
- [ ] Amounts stored as fixed-point (integers/cents), never floats
|
|
- [ ] Currency codes and precision handled correctly
|
|
- [ ] Provider signature / HMAC verification on callbacks
|
|
- [ ] Refund logic: correct reversal, no double-refund
|
|
- [ ] Failure path: payment timeout, declined, retry semantics
|
|
- [ ] Transaction boundary spans charge + order-state update
|
|
- [ ] Sensitive data (PAN, tokens) never logged or masked on output
|
|
- [ ] Ledger/journal entries are append-only and auditable
|