diff --git a/.github/claude/review-guide.md b/.github/claude/review-guide.md index abfe295..89af2a3 100644 --- a/.github/claude/review-guide.md +++ b/.github/claude/review-guide.md @@ -8,11 +8,14 @@ controller→service→DB-class convention, naming rules, and request flow. Judg This service handles **per-user data, auth, and money** (Apple/Google/RevenueCat subscriptions), so security and authorization bugs are the highest-priority findings. -**Main branch is `main`.** Diff against `origin/main`. +**Main branch is `main`.** The harness hands you the pull request's unified diff as a file. The checkout is the +PR head only (`fetch-depth: 1`): there is no `origin/main` ref and no `gh` access inside the review, and +`git log` / `git blame` see only the head commit. ## How to review -1. Get the diff: `gh pr diff `. The branch is checked out in the working directory. +1. Read the unified diff the harness wrote for you; its path is in the task prompt. The PR branch is already + checked out in the working directory. 2. **Do not review the diff in isolation.** For each non-trivial change, open the surrounding code and its **callers** with `Read`/`Grep`/`Glob` before judging. Diff-only opinions are not acceptable. For a new/changed route, always open the router to confirm which middlewares (`auth`,