Files
digital-psychology/.ai/security.md
T
jackyu66gitandCursor 2fb1dfee14 chore: seal Design Vision v1 and monorepo scaffold
Archive the differentiated YuXinGu product docs, AI engineering system,
design contract, and Go/Vue scaffold. Next execution prioritizes Cece-parity
over early innovation (see .ai/product/STRATEGY.md).

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-02 16:00:44 +08:00

636 B

Security — Golden Rules

AuthZ

  • Authenticate before mutating user data.
  • Authorize ownership: user A cannot read/write user B resources.

Input

  • Validate all external input at handler boundary.
  • Parameterized SQL only. Never string-concatenate SQL.

Secrets

  • No secrets in repo, frontend bundles, or logs.
  • Rotate via env / secret manager.

Privacy

  • Birthday / answers / reports are personal data.
  • Soft-delete and future account deletion path required in design.
  • Log request ids; avoid logging full PII payloads.

Content compliance

  • Reject generating 疗效 / 吉凶文案 in prompts and templates.