FR-114.<批>-<序> <做什麼一句話>(SUMMARY #<號>,<嚴重度>) 例:FR-114.1-3 專案成員與任務指派寫入時先反查填進來的東西是不是這個專案的(SUMMARY #41/#109/#110,中) requirement 欄一律 FR-114。
本卡屬 FR-114 資安修正(母卡 CM-2019),第 <N> 批「<批名>」卡 <批-序>,修 SUMMARY #<號>(出自 <Mxx-n>)。<嚴重度>。修法規格來自內化卡 <CM-xxxx>,計畫在 docs/features/FR-114-2609-security-fix-dispatch/batches/plan-b<N>.md「卡 <批-序>」段。
/Users/chouraymond/Projects/Billows/Audit-Manager/compliance-manager-be/.claude/worktrees/wt-fix-security(branch fix/security-b1)改,不要碰主 checkout(掃描線正在讀它)。跑服務用 PORT=8001。/Users/chouraymond/Projects/Jedicogy/module/jedi-python-package/.claude/worktrees/jedi-wt-fix-security/<套件目錄>(branch fix/security-b1)改,只動自己那支套件的子目錄、只 git add 該子目錄下的檔。pyproject.toml 把該套件的 pin 改成 jedi-xxx = { path = "/Users/chouraymond/Projects/Jedicogy/module/jedi-python-package/.claude/worktrees/jedi-wt-fix-security/jedi-xxx", develop = true },poetry update jedi-xxx。這個 path 改動不 commit(git add 時跳過 pyproject.toml)。/Users/chouraymond/Projects/Billows/Audit-Manager/compliance-manager-fe/.claude/worktrees/wt-fix-security(branch fix/security-b1;不存在就 git worktree add .claude/worktrees/wt-fix-security -b fix/security-b1 開)。程式 commit 之後、Notion 回寫之前,順手改報告狀態(在 BE 工作區改,跟程式同一個 branch 另一個 commit):
docs/security-report/M<NN>-<模組>.md:本卡那幾條在「問題一覽」表的狀態欄改成「✅ 已修(FR-114.<批-序>)」,「怎麼修」欄最後加一句實際修法(一句,白話)。只動狀態欄與那一句,不重寫段落。docs/security-report/SUMMARY.md:問題總表對應 # 的狀態欄改「✅ 已修」,批欄改「—」。python scripts/deliverables/render_index.py docs/security-report/ --site-root docs/security-report/,把產出的 html 一起 git add。common/authz/(BE)或套件既有的 assert_*/guard port,不另立 helper;新增 error code 照 GRC_<HTTP><序號>。PYTHONPATH=<套件工作區路徑>——BE 的 pyproject 對套件是 pin,不帶 PYTHONPATH 驗的是 site-packages 的舊版、改動沒被測到還全綠(CM-2023 踩到)。git add <檔名>,禁用 -am;pyproject.toml 的 path 改動不 add。commit message 寫清楚做了什麼/為什麼/驗證了什麼/踩了什麼坑,結尾 Co-Authored-By: Claude <model> <noreply@anthropic.com>。