Files
code-review-graph/skills/project-review/references/manual-review/permission.md
T
dev 307d2fd471 feat: add project-review workflow (whole-project / single-feature review)
Adds the project-review workflow for code review independent of the git
diff. The scope is parsed from the user instruction: 全面/整个项目 ->
whole-project (score every source file), otherwise feature + target
keyword (locate the code with semantic search + graph queries).

- scoring_tools.py: score_review_func gains all_files=True to score every
  source file in the graph via store.get_all_files()
- main.py: score_review_tool gains all_files param; registers the
  project_review MCP prompt (prompts 6->7)
- prompts.py: project_review_prompt(scope, target) with whole-project and
  feature branches (fixed a precedence bug that truncated the feature text)
- skills.py + skills/project-review/: new read-only project-review skill
  with shared checklists
- .opencode/command/code-review-graph-project-review.md: slash command
- tests: test_project_review.py (prompt rendering), TestProjectReviewPrompt,
  skill count assertions 5->6, all_files wiring checks
- docs: prompts (6->7) + project-review entries across COMMANDS, CLAUDE,
  README (+localized), INDEX, architecture, LLM-OPTIMIZED-REFERENCE,
  CHANGELOG
2026-08-06 13:56:54 +08:00

579 B

Permission Module — Manual Review Checklist

High-risk module: authorization changes require product/human confirmation.

  • Every endpoint/action enforces the intended permission — no default-allow
  • Role hierarchy / scoping (tenant, org, user) is consistent
  • Object-level permissions checked on read AND write
  • Deny-before-allow ordering is safe
  • Permission checks cannot be bypassed via IDs, query params, or bulk ops
  • New permission/role values handled by all consumers (enum completeness)
  • Sensitive actions audited with actor + target