Adds the unified-review integration that fuses CRG graph context with the ai-code-review scoring methodology and gstack-review fix-first workflow: - scoring.py: objective Layer-2 metrics (sql_risk, exception_coverage, redundancy_rate, high_risk_density, vulnerability_risk) with good/warn/fail grades, plus dedupe_findings (fingerprint merge, multi-source confidence boost, PR quality score) and report data builder - tools/scoring_tools.py + main.py: three new MCP tools (score_review_tool, dedupe_findings_tool, generate_report_tool) - assets/report-template.html: self-contained HTML report template - skills.py + skills/unified-review/: new read-only unified-review skill with language/manual-review/specialist checklists - docs and CHANGELOG updated; tests added (test_scoring, test_report, test_unified_review) and test_skills updated for 5 skills
702 B
702 B
Payment Module — Manual Review Checklist
High-risk module: payment changes require human confirmation for every blocker/major fix.
- Callback idempotency: a duplicated webhook/callback does not double-charge
- Amounts stored as fixed-point (integers/cents), never floats
- Currency codes and precision handled correctly
- Provider signature / HMAC verification on callbacks
- Refund logic: correct reversal, no double-refund
- Failure path: payment timeout, declined, retry semantics
- Transaction boundary spans charge + order-state update
- Sensitive data (PAN, tokens) never logged or masked on output
- Ledger/journal entries are append-only and auditable