chore: seal Design Vision v1 and monorepo scaffold
Archive the differentiated YuXinGu product docs, AI engineering system, design contract, and Go/Vue scaffold. Next execution prioritizes Cece-parity over early innovation (see .ai/product/STRATEGY.md). Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -0,0 +1,26 @@
|
||||
# Security — Golden Rules
|
||||
|
||||
## AuthZ
|
||||
|
||||
- Authenticate before mutating user data.
|
||||
- Authorize ownership: user A cannot read/write user B resources.
|
||||
|
||||
## Input
|
||||
|
||||
- Validate all external input at handler boundary.
|
||||
- Parameterized SQL only. Never string-concatenate SQL.
|
||||
|
||||
## Secrets
|
||||
|
||||
- No secrets in repo, frontend bundles, or logs.
|
||||
- Rotate via env / secret manager.
|
||||
|
||||
## Privacy
|
||||
|
||||
- Birthday / answers / reports are personal data.
|
||||
- Soft-delete and future account deletion path required in design.
|
||||
- Log request ids; avoid logging full PII payloads.
|
||||
|
||||
## Content compliance
|
||||
|
||||
- Reject generating 疗效 / 吉凶文案 in prompts and templates.
|
||||
Reference in New Issue
Block a user