code-review

โดย contentstack

รายการตรวจสอบ pull-request สำหรับความปลอดภัย ข้อมูลประจำตัว Contentstack การทำความสะอาดข้อมูล และการกำหนดค่ารูปภาพ

npx skills add https://github.com/contentstack/kickstart-next-ssg --skill code-review

Code review – kickstart-next-ssg

When to use

  • Before approving or merging a pull request
  • Auditing changes that touch env vars, CMS integration, or user-facing HTML

Instructions

Secrets and configuration

  • No real .env values or delivery/preview tokens committed; use placeholders in docs only.
  • New NEXT_PUBLIC_* keys are exposed to the browser—avoid putting sensitive server-only secrets behind that prefix.

Contentstack

  • Token scopes and preview settings stay aligned with README.md (preview-capable delivery token, Live Preview environment).

Security and dependencies

HTML and XSS

  • Rich text and block copy use dangerouslySetInnerHTML only after isomorphic-dompurify in pages/index.tsx; preserve or improve sanitization when changing markup.

Images

  • New remote image domains must be reflected in next.config.mjs images.remotePatterns (or env-driven hostname) so next/image does not break at runtime.

Quality

  • Run npm run lint locally for substantive TS/React changes.

Skills เพิ่มเติมจาก contentstack

cms-assets
contentstack
ให้คำแนะนำนักพัฒนาเกี่ยวกับการจัดระเบียบ การส่งมอบ และการแปลง assets ใน Contentstack ครอบคลุมโครงสร้างโฟลเดอร์ การแปลงผ่าน Image Delivery API การเผยแพร่…
cms-branches-aliases
contentstack
แนะนำนักพัฒนาเกี่ยวกับการใช้ branches ของ Contentstack สำหรับการพัฒนาคอนเทนต์แบบแยกส่วน และ aliases สำหรับการ部署คอนเทนต์โดยไม่มีการหยุดให้บริการ ครอบคลุมกลยุทธ์การจัดการ branches และ…
cms-data-modeling-best-practices
contentstack
แนะนำนักพัฒนาในการออกแบบโมเดลเนื้อหาใน Contentstack โดยใช้โครงสร้างที่เรียบง่ายที่สุดและสามารถนำกลับมาใช้ใหม่ได้ สกิลนี้อธิบายว่าควรใช้ content types, references, global… เมื่อใด
cms-live-preview-visual-builder-support-assistant
contentstack
วินิจฉัยและแนะนำการติดตั้ง Contentstack Live Preview และ Visual Builder ตรวจสอบบริบทตัวอย่าง ระบุสัญญาที่ขาด และแนะนำ…
cms-releases
contentstack
แนะนำนักพัฒนาเกี่ยวกับการใช้ Contentstack Releases สำหรับการปรับใช้เนื้อหาแบบประสานงานและเป็นอะตอมมิก ครอบคลุมการสร้างรีลีส การจัดการไอเทม การปรับใช้แบบเป็นขั้นตอน…
cms-roles-permissions
contentstack
ให้คำแนะนำนักพัฒนาเกี่ยวกับการออกแบบบทบาท สิทธิ์ ทีม และการเข้าถึงโทเค็นใน Contentstack อธิบายบทบาทในตัว บทบาทที่กำหนดเอง การรวมสิทธิ์…
cms-taxonomy
contentstack
ให้คำแนะนำนักพัฒนาเกี่ยวกับการใช้ Contentstack Taxonomy สำหรับการจำแนกเนื้อหาที่มีโครงสร้างและเป็นลำดับชั้น รวมถึงการกรองฝั่งดีลิเวอรี ครอบคลุม taxonomy เทียบกับ tags,…
cms-tokens-authentication
contentstack
แนะนำนักพัฒนาในการเลือกวิธีการรับรองความถูกต้องและประเภทโทเค็นของ Contentstack ที่เหมาะสมสำหรับกรณีการใช้งาน frontend, backend, automation และแอปพลิเคชันของบุคคลที่สาม…