| Dimension | Shared | Only in A | Only in B | Overlap |
|---|---|---|---|---|
| Sections | 0 | 1 | 1 | 0% |
| Commands | 0 | 0 | 0 | — |
| Section tags | 0 | 1 | 1 | 0% |
What each file covers
Sections
0 shared · 1 only in A · 1 only in B- − Supabase Policies Memory
- + Consent Rules
Commands
neither file has anySection tags
0 shared · 1 only in A · 1 only in B- − performance
- + do-not
Line diff
Aledon8/OpenLeukemia · supabase/policies/CLAUDE.md
@@ −1 @@
1# Supabase Policies Memory
2
3Apply this inside `supabase/policies/`.
4
5- RLS is a primary protection layer, not a later add-on.
6- Policies should make patient ownership and explicit consent enforceable.
7- Keep access paths narrow and auditable.
8- Treat document storage and normalized clinical data as separate access concerns.
9- Review policy changes as security-sensitive even when the SQL diff is small.
10
Aledon8/OpenLeukemia · .cursor/rules/consents.mdc
@@ +1 @@
1---
2description: Consent behavior rules across frontend and API
3globs:
4 - "frontend/src/features/consents/**/*"
5 - "ai-service/app/domains/consents/**/*"
6 - "ai-service/app/api/v1/consents.py"
7alwaysApply: false
8---
9
10# Consent Rules
11
12- Consent is never implied by registration, navigation, or another consent.
13- Keep each consent separate, explicit, auditable, and reversible.
14- Do not merge cloud storage, research participation, AI improvement, or community sharing into one choice.
15- Keep frontend consent identifiers aligned with API/domain consent types.
16- Add or update tests when consent types, labels, API responses, or service behavior change.
17
@@ −1 +1 @@
1−# Supabase Policies Memory
1+---
2+description: Consent behavior rules across frontend and API
3+globs:
4+ - "frontend/src/features/consents/**/*"
5+ - "ai-service/app/domains/consents/**/*"
6+ - "ai-service/app/api/v1/consents.py"
7+alwaysApply: false
8+---
29
3−Apply this inside `supabase/policies/`.
10+# Consent Rules
411
5−- RLS is a primary protection layer, not a later add-on.
6−- Policies should make patient ownership and explicit consent enforceable.
7−- Keep access paths narrow and auditable.
8−- Treat document storage and normalized clinical data as separate access concerns.
9−- Review policy changes as security-sensitive even when the SQL diff is small.
12+- Consent is never implied by registration, navigation, or another consent.
13+- Keep each consent separate, explicit, auditable, and reversible.
14+- Do not merge cloud storage, research participation, AI improvement, or community sharing into one choice.
15+- Keep frontend consent identifiers aligned with API/domain consent types.
16+- Add or update tests when consent types, labels, API responses, or service behavior change.
1017
