Squashed 'docs/standards/playbook/' changes from e504a68..b529012
b529012 ✅ test(tests): avoid hardcoded missing path 07583c8 🐛 fix(tests): make doc link check awk-portable 6244aa3 🔧 chore(ci): relax gitattributes check 31dd0c5 🐛 fix(scripts): require existing project root 15d4d63 🔧 chore(ci): install python3-pip 90c6313 🔧 chore(ci): run tests in a single job d84eff0 🔧 chore(ci): make actions base url configurable 395598d 🔧 chore(ci): fix yaml step names 4ae2733 ✨ feat(sync_standards): auto-detect existing languages e97fb00 ✨ feat(sync_standards): default gitattributes to append da0ef2b ✅ test: add automated tests and ci workflow 99bef30 🎨 style(markdown): format all markdown files with prettier 7e96bc8 ♻️ refactor(tsl): split function.md into 44 modular files 0d6b2a0 📝 docs(readme): add quick decision table and TL;DR for distribution methods 3b2188f 🎨 style(markdown): format markdown files with prettier 41fc43b 📝 docs(tsl): document {Unit.}Type source annotation 3dceaf7 📝 docs(tsl): clarify tsf-only top-level rules and type annotations 3a63829 📝 docs(skills): add create-plan skill f02a707 🐛 fix(scripts): escape markdown backticks in vendor_playbook 064aa92 🐛 fix(scripts): correct bat scripts 4881feb 🔧 chore(gitattributes): enforce crlf for bat files 1fa3e2a 🐛 fix(scripts): escape parentheses in sync_standards output 3958cad 📝 docs(vendor_playbook): mention ci templates 9d059cf ✨ feat(templates): add gitea ci example a52bb24 📝 docs(codex_skills): normalize markdown formatting cc8ad4c 📝 docs(skills): slim commit-message 2a98e15 🐛 fix(skills): quote YAML descriptions 8f78d22 🐛 fix(sync_standards): generate minimal AGENTS.md 5547665 ✨ feat(skills): add commit-message suggestion skill 3fe8bd7 🔧 chore(sync_standards): create AGENTS.md on sync 283d311 ✨ feat(playbook): add syntax book and codex skills tooling 5b97ed5 📝 docs(tsl): clarify syntax references 27e0700 ✨ feat(skills): add pdf/docx/pptx/xlsx wrapper workflows 5551363 ✨ feat(skills): add debugging and bulk refactor workflows 1d4f548 ✨ feat(skills): add built-in workflow skills c0895dd 📝 docs(skills): add anthropics document-skills integration cf9f80d 🔧 chore(playbook): add Claude Code skills guide and align python templates git-subtree-dir: docs/standards/playbook git-subtree-split: b529012c59c5d67c3073884d7b617763647417fd
This commit is contained in:
@@ -0,0 +1,58 @@
|
||||
---
|
||||
name: defense-in-depth
|
||||
description:
|
||||
"Defense in depth: add layered validation/guardrails across a data path (auth,
|
||||
validation, invariants, rate limits, idempotency). Triggers: defense in depth,
|
||||
guardrails, harden, 分层校验, 多道防线, 安全加固."
|
||||
---
|
||||
|
||||
# Defense in Depth(分层校验 / 多道防线)
|
||||
|
||||
## When to Use
|
||||
|
||||
- Auth/data path changes (permissions, roles, ownership checks)
|
||||
- Risky inputs (user input, external APIs, files, SQL, commands)
|
||||
- Operations that must be safe under retries/concurrency
|
||||
- Incidents where we fixed symptoms but not the root class of bugs
|
||||
|
||||
## Inputs(required)
|
||||
|
||||
- Data path: entrypoints → core logic → side effects (DB/files/network)
|
||||
- Threat model: what could go wrong? who can trigger it?
|
||||
- Constraints: latency budgets, backward compatibility, rollout plan
|
||||
- Verification: how to prove guardrails work (tests, logs, metrics)
|
||||
|
||||
## Procedure(default)
|
||||
|
||||
1. **Map the Path**
|
||||
- Identify trust boundaries and validation points
|
||||
- List invariants that must always hold
|
||||
|
||||
2. **Layer Guardrails**
|
||||
- AuthN/AuthZ checks at boundaries (least privilege)
|
||||
- Input validation + normalization (reject early)
|
||||
- Business invariants (defensive checks with clear errors)
|
||||
- Idempotency / dedup / retry-safety
|
||||
- Rate limits / resource bounds (timeouts, size limits)
|
||||
- Observability (structured logs, metrics, alerts)
|
||||
|
||||
3. **Failure Modes**
|
||||
- Define what happens on invalid input, partial failures, timeouts
|
||||
- Ensure errors are actionable and do not leak sensitive info
|
||||
|
||||
4. **Verify**
|
||||
- Add tests for each guardrail and key edge cases
|
||||
- Propose minimal manual verification steps if tests are missing
|
||||
|
||||
## Output Contract(stable)
|
||||
|
||||
- Path map: trust boundaries + invariants
|
||||
- Guardrails: what to add at each layer (with rationale)
|
||||
- Risks: what remains and why
|
||||
- Verification: exact tests/commands and expected signals
|
||||
|
||||
## Guardrails
|
||||
|
||||
- Avoid “one big check”; prefer multiple small, well-scoped checks
|
||||
- Prefer explicit errors over silent fallback
|
||||
- Security checks must not be bypassable via alternate code paths
|
||||
Reference in New Issue
Block a user