| Dimension | Shared | Only in A | Only in B | Overlap |
|---|---|---|---|---|
| Sections | 0 | 1 | 1 | 0% |
| Commands | 0 | 0 | 0 | — |
| Section tags | 0 | 1 | 1 | 0% |
What each file covers
Sections
0 shared · 1 only in A · 1 only in B- − Supabase Policies Memory
- + Consent Instructions
Commands
neither file has anySection tags
0 shared · 1 only in A · 1 only in B- − performance
- + agent-behaviour
Line diff
Aledon8/OpenLeukemia · supabase/policies/CLAUDE.md
@@ −1 @@
1# Supabase Policies Memory
2
3Apply this inside `supabase/policies/`.
4
5- RLS is a primary protection layer, not a later add-on.
6- Policies should make patient ownership and explicit consent enforceable.
7- Keep access paths narrow and auditable.
8- Treat document storage and normalized clinical data as separate access concerns.
9- Review policy changes as security-sensitive even when the SQL diff is small.
10
Aledon8/OpenLeukemia · .github/instructions/consents.instructions.md
@@ +1 @@
1---
2applyTo: "frontend/src/features/consents/**/*,ai-service/app/domains/consents/**/*,ai-service/app/api/v1/consents.py"
3---
4
5# Consent Instructions
6
7- Consent is never implied by registration, navigation, or another consent.
8- Keep each consent separate, explicit, auditable, and reversible.
9- Do not merge cloud storage, research participation, AI improvement, or community sharing into one choice.
10- Keep frontend consent identifiers aligned with API/domain consent types.
11- Add or update tests when consent types, labels, API responses, or service behavior change.
12
@@ −1 +1 @@
1−# Supabase Policies Memory
1+---
2+applyTo: "frontend/src/features/consents/**/*,ai-service/app/domains/consents/**/*,ai-service/app/api/v1/consents.py"
3+---
24
3−Apply this inside `supabase/policies/`.
5+# Consent Instructions
46
5−- RLS is a primary protection layer, not a later add-on.
6−- Policies should make patient ownership and explicit consent enforceable.
7−- Keep access paths narrow and auditable.
8−- Treat document storage and normalized clinical data as separate access concerns.
9−- Review policy changes as security-sensitive even when the SQL diff is small.
7+- Consent is never implied by registration, navigation, or another consent.
8+- Keep each consent separate, explicit, auditable, and reversible.
9+- Do not merge cloud storage, research participation, AI improvement, or community sharing into one choice.
10+- Keep frontend consent identifiers aligned with API/domain consent types.
11+- Add or update tests when consent types, labels, API responses, or service behavior change.
1012
