code-review

作者: contentstack

在审查Management Python SDK的PR时使用——公共API、_APIClient、OAuth、测试、安全。

npx skills add https://github.com/contentstack/contentstack-management-python --skill code-review

Code review – Contentstack Management Python

When to use

  • Reviewing a PR, self-review before submit, or automated review prompts.

Instructions

Work through the checklist below. Optionally tag findings: Blocker, Major, Minor.

Public API

  • Exported Client, Region, stack and resource helpers match README and contentstack_management.__all__ / __init__.py.
  • Docstrings on Client and changed public methods when behavior or parameters change.

Compatibility

  • Avoid breaking Client constructor or stack method chains without a semver strategy; document migration for breaking changes.

HTTP / auth

  • Changes to _APIClient or OAuth paths: verify retries, headers, and interceptor behavior with unit tests; no regressions for authtoken / management_token headers.

Testing

  • Unit coverage for new logic; API updates when live CMA request/response behavior changes; mock when contract-style tests are appropriate.
  • pytest tests/unit/ passes.

Security

  • No hardcoded tokens; no logging secrets in new code.

Severity (optional)

LevelExamples
BlockerBreaking public API without approval; security issue; no tests for new logic where tests are practical
MajorInconsistent HTTP/auth behavior; README examples that do not match code
MinorStyle; minor docs