From 997c392d8ae96c4fe36d9955a11ec13fb982fdb6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Nikola=20Perovi=C4=87?= <46610174+Fooftilly@users.noreply.github.com> Date: Fri, 25 Sep 2026 22:22:00 +0200 Subject: [PATCH 1/2] chore: configure Greptile reviews --- .greptile/config.json | 57 +++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 57 insertions(+) create mode 100644 .greptile/config.json diff --git a/.greptile/config.json b/.greptile/config.json new file mode 100644 index 00000000..7ada7ee5 --- /dev/null +++ b/.greptile/config.json @@ -0,0 +1,57 @@ +{ + "strictness": 2, + "commentTypes": ["logic", "syntax", "style"], + "effort": "base", + "ignorePatterns": "frontend/vendor/**\ndocs/screenshots/**\ndata/**\ndata_testing/**\nartifacts/**\n**/*.zip\n**/*.woff2\n**/*.wasm", + "instructions": "Prioritize concrete correctness bugs, regressions, security defects, data-integrity failures, broken architecture invariants, unsafe persistence/filesystem behavior, concurrency or state-lifecycle bugs, and missing regression coverage. Do not comment on generic formatting, naming, stylistic preference, speculative refactors, or optional cleanup unless it violates an explicit PRKS repository rule. When a finding is based on a repository rule, identify the governing document or invariant. Distinguish currently implemented behavior from staged, proposed, or in-transition architecture; do not require future functionality merely because a design document describes it. Prefer actionable findings with a concrete failure mode over best-practice advice.", + "rules": [ + { + "id": "privacy-safe-logging", + "rule": "Backend changes must preserve PRKS privacy-safe logging. Flag code that can log user or library content, request bodies or query strings, titles, notes, annotations, names, filenames or absolute paths, user URLs, headers, raw browser messages or stacks, qpdf stderr, or unsanitized exception text.", + "scope": ["backend/**"], + "severity": "high" + }, + { + "id": "database-migration-safety", + "rule": "Database and schema changes must keep fresh-database schema and migrations coherent, preserve transactional and version-order guarantees, safely upgrade supported older databases, and reject unsupported newer schemas where applicable. Flag concrete parity, atomicity, ordering, or compatibility regressions.", + "scope": ["backend/db_*.py", "backend/**/*.sql"], + "severity": "high" + }, + { + "id": "managed-file-lifecycle", + "rule": "Changes that create, replace, retarget, restore, or delete managed files must preserve path containment, ownership/reference checks, crash-safe durability boundaries, cleanup recovery, and canonical-versus-derived state invariants. Flag races, orphan/leak paths, stale derived state, or deletion of still-referenced bytes.", + "scope": ["backend/**"], + "severity": "high" + }, + { + "id": "test-storage-isolation", + "rule": "Tests and test helpers must never operate on production data/ or a live PRKS_STORAGE tree. Flag any path, environment, fixture, or fallback that could reach production storage during tests.", + "scope": ["tests/**", "run_tests.py"], + "severity": "high" + }, + { + "id": "ui-design-contract", + "rule": "User-visible frontend changes must conform to DESIGN.md. Flag concrete conflicts with the documented component, selection, focus, accessibility, density, navigation, workspace, or interaction model; do not invent generic design preferences beyond that contract.", + "scope": ["frontend/**"], + "severity": "medium" + }, + { + "id": "workspace-context-ownership", + "rule": "Workspace, split-view, tab, route, editor, PDF, and contextual-panel changes must preserve TabContext ownership and documented workspace lifecycle semantics. Flag cross-context state leaks, unintended remounts, duplicate tabs, invalid Secondary-tree mutation, lost leave guards, or focus/URL changes that contradict the scoped frontend rules.", + "scope": ["frontend/js/**"], + "severity": "high" + }, + { + "id": "e2e-quality", + "rule": "E2E changes must preserve isolation and deterministic synchronization. Flag arbitrary sleeps, fixed ports, shared mutable state, weakened or vacuous assertions, hidden retries, production-storage access, and browser-level tests where the same regression can be covered adequately by a substantially faster unit, API, Node, or static test.", + "scope": ["tests/e2e/**"], + "severity": "medium" + }, + { + "id": "workflow-safety", + "rule": "GitHub Actions changes must preserve least-privilege permissions, safe handling of untrusted pull-request input, pinned actions where required by repository policy, correct cache/artifact boundaries, and truthful failure propagation. Flag workflows that can accidentally report success after a failed required step.", + "scope": [".github/workflows/**"], + "severity": "high" + } + ] +} From 6a7810c7c81f6a853f7a66f439669f9cb160028f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Nikola=20Perovi=C4=87?= <46610174+Fooftilly@users.noreply.github.com> Date: Fri, 25 Sep 2026 22:22:11 +0200 Subject: [PATCH 2/2] chore: add Greptile context files --- .greptile/files.json | 51 ++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 51 insertions(+) create mode 100644 .greptile/files.json diff --git a/.greptile/files.json b/.greptile/files.json new file mode 100644 index 00000000..aca738f3 --- /dev/null +++ b/.greptile/files.json @@ -0,0 +1,51 @@ +{ + "files": [ + { + "path": "AGENTS.md", + "description": "Repository-wide PRKS engineering, safety, testing, storage, and issue-tracking rules." + }, + { + "path": "SECURITY.md", + "description": "PRKS security boundaries, deployment assumptions, sensitive-data constraints, and vulnerability scope." + }, + { + "path": "backend/AGENTS.md", + "description": "Backend persistence, privacy-safe logging, filesystem, backup/restore, database, indexing, durability, and cross-domain invariants.", + "scope": ["backend/**"] + }, + { + "path": "frontend/AGENTS.md", + "description": "Frontend runtime, workspace, TabContext, navigation, offline/PWA, interaction, and cross-boundary behavior invariants.", + "scope": ["frontend/**"] + }, + { + "path": "DESIGN.md", + "description": "Authoritative PRKS visual and interaction design contract for user-visible frontend changes.", + "scope": ["frontend/**"] + }, + { + "path": "tests/AGENTS.md", + "description": "Test-layer routing, storage safety, and rules for loading the production-domain invariants exercised by a test.", + "scope": ["tests/**"] + }, + { + "path": "tests/e2e/AGENTS.md", + "description": "Browser E2E isolation, synchronization, tiering, performance, and debugging policy.", + "scope": ["tests/e2e/**"] + }, + { + "path": "docs/work-identity-model.md", + "description": "Approved-in-direction Work/Manifestation/Asset architecture design. Treat it as staged architecture: use it only when reviewing implementation that touches this model, and do not assume every proposed slice is already implemented.", + "scope": [ + "backend/db_*.py", + "backend/**/*work*.py", + "backend/**/*manifestation*.py", + "backend/**/*asset*.py", + "frontend/**/*work*.js", + "tests/**/*work*.py", + "tests/**/*manifestation*.py", + "tests/**/*asset*.py" + ] + } + ] +}