모든 엔티티에 대한 검토 댓글: 게스트/사용자, 답글, 1–5 평점, 차단, GDPR 삭제, 안전한 HTML
코드파일 9개컨텍스트약 552토큰검사 통과
설치
$
genpm add @core/comments포함 내용
- src/lib/comments/에 소스 코드, 파일 9개. (23kB)
- src/lib/comments/AGENTS.md에 AI 규칙, 그리고 IDE 규칙 파일.
- .env.example에 추가되는 환경 변수: COMMENTS_NOTIFY_TO.
- @core/antispam, @core/auth, @core/contracts, @core/db, @core/email, @core/jobs을(를) 자동으로 해결합니다.
README
이 패키지에는 README가 없습니다.
약 552토큰→ src/lib/comments/AGENTS.md→ .cursor/rules/genpm-core-comments.mdc
이것이 AI가 src/lib/comments에서 작업할 때 읽는 내용 그대로입니다. 그 외에는 컨텍스트에 아무것도 추가되지 않습니다.
@core/comments — rules for AI agents
Purpose
Comments on anything (entityType + entityId: posts, products, pages): guests (name + email, stored only as a hash)
or signed-in users, one level of replies, optional 1–5 rating (reused by @core/reviews), moderation queue with email
alerts, bans, GDPR erasure and safe HTML rendering. Anti-spam via @core/antispam. Tables: comments, comment_bans.
Map
index.ts— public API:postComment,listComments,moderate,ban,eraseComments,ratingSummary,commentHtml,commentsAdminResource.comments.ts— logic and thecomments.notifyjob.admin.ts— moderation queue.schema.ts— tables.adapters/hono.ts—commentRoutes({ currentUser }).adapters/next.ts—commentRoute({ currentUser })→{ GET, POST }.
Integration
- Env: optional
COMMENTS_NOTIFY_TO(moderators, comma-separated) andEMAIL_FROM. Migrations as insrc/lib/db/AGENTS.md; the @core/jobs cron must run. - Mount the endpoints at
/api/comments/:type/:idwithcurrentUserfrom @core/auth (getUser/getUserFromCookieHeader). - The form posts
body(andname,emailfor guests,parentIdfor replies) plus the @core/antispam fields (honeypotProps,_ts). Show "your comment awaits moderation" when the response status ispending. - Render the list from
GETorlistComments(type, id); render each body withcommentHtml(body)(escaped; the only HTML allowed). - Add
commentsAdminResourcetosrc/genpm/admin.ts(permissionscomments:read,comments:moderate). - Verify: a guest comment is pending until approved in the admin, then it is listed.
Conventions
- Default moderation is
guests: guests and users without an approved comment wait for approval. Usenoneonly on trusted, private sites. - Erase on request with
eraseComments({ email })or({ userId }); delete user comments when the account is deleted. - Show ratings only from
ratingSummary(approved comments).
Don't
- Don't store or show guest emails; don't render comment bodies as Markdown/HTML.
- Don't auto-approve guests to "increase engagement".
- Don't expose
pending,spamordeletedcomments in public endpoints.
# @core/comments — rules for AI agents
## Purpose
Comments on anything (`entityType` + `entityId`: posts, products, pages): guests (name + email, stored only as a hash)
or signed-in users, one level of replies, optional 1–5 rating (reused by @core/reviews), moderation queue with email
alerts, bans, GDPR erasure and safe HTML rendering. Anti-spam via @core/antispam. Tables: `comments`, `comment_bans`.
## Map
- `index.ts` — public API: `postComment`, `listComments`, `moderate`, `ban`, `eraseComments`, `ratingSummary`, `commentHtml`, `commentsAdminResource`.
- `comments.ts` — logic and the `comments.notify` job. `admin.ts` — moderation queue. `schema.ts` — tables.
- `adapters/hono.ts` — `commentRoutes({ currentUser })`. `adapters/next.ts` — `commentRoute({ currentUser })` → `{ GET, POST }`.
## Integration
1. Env: optional `COMMENTS_NOTIFY_TO` (moderators, comma-separated) and `EMAIL_FROM`. Migrations as in `src/lib/db/AGENTS.md`; the @core/jobs cron must run.
2. Mount the endpoints at `/api/comments/:type/:id` with `currentUser` from @core/auth (`getUser`/`getUserFromCookieHeader`).
3. The form posts `body` (and `name`, `email` for guests, `parentId` for replies) plus the @core/antispam fields (`honeypotProps`, `_ts`).
Show "your comment awaits moderation" when the response status is `pending`.
4. Render the list from `GET` or `listComments(type, id)`; render each body with `commentHtml(body)` (escaped; the only HTML allowed).
5. Add `commentsAdminResource` to `src/genpm/admin.ts` (permissions `comments:read`, `comments:moderate`).
6. Verify: a guest comment is pending until approved in the admin, then it is listed.
## Conventions
- Default moderation is `guests`: guests and users without an approved comment wait for approval. Use `none` only on trusted, private sites.
- Erase on request with `eraseComments({ email })` or `({ userId })`; delete user comments when the account is deleted.
- Show ratings only from `ratingSummary` (approved comments).
## Don't
- Don't store or show guest emails; don't render comment bodies as Markdown/HTML.
- Don't auto-approve guests to "increase engagement".
- Don't expose `pending`, `spam` or `deleted` comments in public endpoints.
.genpmignore 적용 후 주입될 정확한 트리입니다. 고정 대상:
// Adaptador Next.js: `app/api/comments/[type]/[id]/route.ts` →
// export const { GET, POST } = commentRoute({ currentUser: async () => getUser(await cookies()) });
import type { Moderation } from '../index.ts';
import { type CurrentUser, handleList, handlePost } from './http.ts';
type Ctx = { params: Promise<{ type: string; id: string }> };
export function commentRoute(opts: { currentUser: CurrentUser; moderation?: Moderation }) {
return {
GET: async (req: Request, ctx: Ctx) => {
const { type, id } = await ctx.params;
return handleList(req, type, id);
},
POST: async (req: Request, ctx: Ctx) => {
const { type, id } = await ctx.params;
return handlePost(req, type, id, opts);
},
};
}
이 패키지는 MCP 서버를 선언하지 않습니다.
| 버전 | 커밋 | 게시일 | 검사 |
|---|---|---|---|
| 1.0.1 | abfbbe8 | 4시간 전 | 검사 통과 |
- genpm
- @core/antispam ^1.0.0@core/auth ^1.1.0@core/contracts ^1.0.0@core/db ^1.0.0@core/email ^1.0.1@core/jobs ^1.0.0
- npm
- zod ^4.0.0
- 제안됨
- GenPM은 npm 명령을 제안하고, 동의한 경우에만 실행합니다.
- 사용하는 패키지 (2)
- @core/kit-blog ^1.0.0@core/reviews ^1.0.0
- 검사
- 검사 통과 · 문제 0건
- 커밋
- v1.0.1 → abfbbe8ddb3706a9640b94d9dea43a45e70da1a9 · 가져온 뒤 검증됨
- 스크립트
- 없음. GenPM은 패키지 코드를 절대 실행하지 않습니다.
- 라이선스
- MIT
- 품질
- 100/100
- 인정된 라이선스충족
- AGENTS.md에 목적 설명충족
- AGENTS.md에 통합 단계충족
- AGENTS.md에 규칙 또는 금지 사항충족
- 테스트 포함충족
- 보안 검사 통과충족
- 최근 6개월 내 게시충족
- 인증된 게시자충족
- 요약과 키워드충족
- 신고
- 문제가 있나요?