Documentacion tecnica primera entrega JDLM - #233
Conversation
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughThis PR establishes RestoStock’s MVP documentation set: product definition, architecture, persistence and API contracts, governance, backlog traceability, user stories, technical tickets, AI prompt workflows, repository metadata, and project-specific README content. ChangesRestoStock MVP Documentation
Estimated code review effort: 4 (Complex) | ~45 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 13
Note
Due to the large number of review comments, Critical, Major severity comments were prioritized as inline comments.
🟡 Minor comments (8)
.gitignore-37-42 (1)
37-42: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick winFix the
.vscodeexception pattern.Ignoring
.vscode/at the directory level prevents the later!rules from re-including the selected files. If you want to keep tracked editor settings, ignore the contents instead.🔧 Proposed fix
-.vscode/ +.vscode/* !.vscode/settings.json !.vscode/tasks.json !.vscode/launch.json !.vscode/extensions.json🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.gitignore around lines 37 - 42, The `.vscode/` ignore rule blocks the later negation entries from re-including tracked editor files, so update the `.gitignore` patterns under the IDEs/Editors section to ignore the contents of `.vscode` instead of the directory itself. Keep the existing exception entries for `.vscode/settings.json`, `.vscode/tasks.json`, `.vscode/launch.json`, and `.vscode/extensions.json` so those files can still be tracked.docs/07_restostock_security_strategy.md-53-56 (1)
53-56: 🔒 Security & Privacy | 🟡 Minor | ⚡ Quick winUse hashing terminology here, not encryption.
bcrypt is a one-way hash, so calling this control “encryption at rest” is technically wrong and can lead to the wrong implementation model. Rename it to reflect PIN hashing/verification explicitly.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/07_restostock_security_strategy.md` around lines 53 - 56, The terminology in the “Conexiones Seguras y Cifrado” section is incorrect for PIN storage: bcrypt is a one-way hash, not encryption. Update the heading and surrounding text in this docs section to explicitly describe PIN hashing and verification, and replace “Encryption at Rest” language with “hashing” terminology while keeping the bcrypt guidance and salt-round requirements aligned with the existing security control.readme.md-63-90 (1)
63-90: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick winReplace the setup placeholders with runnable commands.
This section still ships
Sin definir aunblocks, so a new contributor cannot bootstrap the project from the README. Fill in the real commands or mark the section explicitly as pending.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@readme.md` around lines 63 - 90, The local setup section still contains placeholder text instead of actionable steps, so replace each “Sin definir aun” block with the actual bootstrap commands in the README’s setup list. Update the steps for cloning, installing monorepo dependencies, creating the `.env` file under `apps/backend/`, starting Docker Compose, running Prisma migrations/seed, and launching the development servers, using the same section structure so a contributor can follow it end to end. If any command is intentionally not ready, mark that specific step as pending rather than leaving placeholders.docs/10_restostock_api_specification.md-92-100 (1)
92-100: 🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick winClarify
remanente.unitsource.Remanentedoesn’t persist a unit; that value lives onInsumo.consumptionUnit(andStockMovement.unit). Either expose it as a derived field with an explicit source or align this payload with the other remanente responses.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/10_restostock_api_specification.md` around lines 92 - 100, The `remanente.unit` field in the API spec is ambiguous because `Remanente` does not persist a unit directly. Update the `remanente` example and surrounding description to either mark `unit` as a derived value sourced from `Insumo.consumptionUnit` or `StockMovement.unit`, or remove it to match the other `Remanente` payloads; use the `Remanente` and `Insumo.consumptionUnit` references to keep the spec consistent.docs/02_restostock_prd.md-100-106 (1)
100-106: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick winFix the truncated non-goal entry.
The last bullet is merged into the next heading, which breaks the markdown structure and leaves the "Integración de Hardware Físico" item incomplete.
♻️ Proposed fix
-* **Integración de Hardware Físico:** No se integra## 📋 5. Backlog de Historias de Usuario (INVEST) +* **Integración de Hardware Físico:** No se integra. + +## 📋 5. Backlog de Historias de Usuario (INVEST)🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/02_restostock_prd.md` around lines 100 - 106, The “Integración de Hardware Físico” non-goal is truncated and merged into the next heading, breaking the markdown structure. Edit the non-goals section in the PRD so the bullet is completed as its own item and the “Backlog de Historias de Usuario (INVEST)” heading starts on a new line after the list. Use the surrounding section titles and the “Multisede” bullet to locate the broken list entry.docs/01_idea_inicial.md-3-10 (1)
3-10: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick winNormalize the TOC fragments to match the generated anchors. The current links keep accented characters, so they won’t resolve against the heading IDs; update all six fragments to accent-free slugs like
#1-frontera-entre-problema-y-solucionand#2-vision-y-metricas-de-exito-kpis.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/01_idea_inicial.md` around lines 3 - 10, The table of contents links use accented fragments that do not match the generated heading anchors, so update the six TOC entries in the index to use the same accent-free slugs produced by the markdown headings. Edit the existing list items under the Índice section so each fragment matches its corresponding heading ID, using the same pattern as the headings for Frontera entre Problema y Solución, Visión y Métricas de Éxito (KPIs), Lenguaje Ubicuo, Flujo Principal, Fuera de Alcance, and Preguntas de Clarificación.Source: Linters/SAST tools
docs/02_restostock_prd.md-3-24 (1)
3-24: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick winFix the broken Backlog anchor
docs/02_restostock_prd.md:13,105—#5-backlog-de-historias-de-usuario-investhas no matching heading because## 📋 5. Backlog de Historias de Usuario (INVEST)is merged into the previous bullet. Split that heading onto its own line.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/02_restostock_prd.md` around lines 3 - 24, The Backlog table-of-contents link is broken because the section heading for the backlog is merged into the prior bullet list instead of being a standalone heading. Update the markdown around the Table of Contents so the “Backlog de Historias de Usuario (INVEST)” section has its own heading that matches the anchor used by the TOC link. Use the existing TOC entry and the “Backlog de Historias de Usuario (INVEST)” title as the locating symbols when fixing the structure.Source: Linters/SAST tools
docs/tickets/TK-008.md-21-23 (1)
21-23: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick winClarify the deadlock-ordering note. Keep
remanente.idordering only for lock acquisition / transaction sequencing; the actual consumption order must remain FEFO (calculated_expiration_dateascending) so the oldest remanente is depleted first.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/tickets/TK-008.md` around lines 21 - 23, Clarify the deadlock mitigation in the risk note: keep `remanente.id` ordering only for lock acquisition or transaction sequencing, and do not use it as the business consumption order. Update the wording around the deadlock section in `TK-008.md` so it clearly states that the actual depletion logic must remain FEFO, using `calculated_expiration_date` ascending, with `remanente.id` only serving to make Prisma transaction updates acquire locks in a consistent order.
🧹 Nitpick comments (1)
docs/tickets/TK-002.md (1)
15-17: 🔒 Security & Privacy | 🔵 Trivial | ⚡ Quick winKeep PIN hashing out of the domain model.
Pinshould validate format only; hashing and verification belong in application/infrastructure. As written, this reads like the domain object will ownbcrypt, which blurs the layer contract and weakens the architecture.Also applies to: 41-44
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/tickets/TK-002.md` around lines 15 - 17, The `Pin` value object is taking on hashing/verification responsibilities that should not live in the domain layer. Update the `User`/`Pin` domain model so it only validates PIN format and leaves `bcrypt`-style hashing and comparison to `AuthenticateByPinUseCase` or infrastructure helpers; keep `IUserRepository` and the API/auth flow aligned with that separation.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/02_restostock_prd.md`:
- Around line 48-52: El KPI de TRR está inconsistente entre los documentos y
debe unificarse en un solo valor. Revisa la definición de “Tasa de Rotación de
Remanentes (TRR)” en este PRD y alinéala con el valor correcto del documento de
framing, luego propaga ese mismo umbral en el backlog y en los tests
relacionados. Usa como referencias para localizar el cambio la sección
“Objetivos de Negocio y KPIs (Métricas de Éxito)” y las menciones de “TRR” en el
repositorio para asegurar que todos los artefactos queden consistentes.
In `@docs/05_restostock_components_description.md`:
- Around line 81-82: Update the MovementType union to include CONSUMPTION so it
matches the partial kitchen consumption workflow described in the design. Make
this change in the MovementType declaration alongside the existing EXTRACTION,
TRANSFER, and DISCARD values, and ensure any related sample API or persistence
contract references that rely on MovementType stay aligned with the new allowed
value.
- Around line 15-16: The `src/kitchen` description currently states a fixed 48h
TRR for remanentes, but it must match the `calculated_expiration_date` rule from
`docs/03_restostock_design.md`. Update this spec text to describe expiry as the
minimum of the original expiration date and `opened_at + open_shelf_life_days`,
or the original expiration date when shelf life is null, and keep the
`src/kitchen` module wording consistent with that rule.
- Around line 133-208: The HTTP controller and DTO handling around
StockController.handleExtraction/RecordExtractionInput are inconsistent with the
documented API shape because quantity is treated as a JavaScript number instead
of the serialized Decimal/string form. Update the transport boundary in
handleExtraction to accept the incoming quantity as a string, validate it there,
and convert it into a Decimal before calling RecordExtractionUseCase.execute so
the payload stays consistent end-to-end with RecordExtractionInput.quantity.
- Around line 78-80: The Domain sample still imports decimal.js instead of using
the dependency-free DecimalValue shared value object. Update the Domain
blueprint in docs/05_restostock_components_description.md to replace the Decimal
import/reference with DecimalValue so it matches the rule and stays aligned with
the folder structure guidance in docs/06_restostock_folder_structure.md. Use the
Domain sample section and any related value-object references to ensure the
example no longer depends on external decimal.js.
In `@docs/08_restostock_testing_strategy.md`:
- Around line 107-109: The example fixtures for MOCK_INSUMO_ID and MOCK_USER_ID
use semantic strings that do not satisfy the UUIDv4 contract required by
insumoId and userId. Update the documented sample values in the testing strategy
example to valid UUIDv4 fixtures while keeping the same variable names, so the
example passes validation and still reads semantically.
- Around line 58-60: The testing strategy wording in “Mocks Mínimos (Favorecer
Fakes e In-Memory)” is too broad and incorrectly applies in-memory repositories
beyond unit tests. Update this section to scope fakes/in-memory repositories
only to unit tests, and clarify that integration tests should run against a real
isolated database so Prisma/PostgreSQL behavior, transactions, and schema
constraints are exercised. Keep the guidance aligned with the existing
“Directiva” and “Solución” wording in this section.
In `@docs/tickets/TK-005.md`:
- Line 17: The RecordConsumptionSchema for POST /api/kitchen/consumption
currently allows zero or negative quantities, which can corrupt inventory by
increasing stock. Update the Zod validation in RecordConsumptionSchema to
require a strictly positive amount, and make sure the integration tests for
cumulative partial consumptions cover rejecting zero and negative payloads while
keeping the existing consumption flow intact.
In `@docs/tickets/TK-007.md`:
- Around line 24-26: The request-layer outage handling should be changed from
React Error Boundaries to explicit async loading/error states, since rejected
fetches are not caught by boundaries. Update the guidance in the ticket to point
to the request flow and its error handling path, and mention the relevant
UI/data-fetching logic (instead of boundary-based recovery) so the app can show
a graceful disconnected state when the backend is unavailable.
In `@docs/user_stories/US-005.md`:
- Around line 20-25: Update the alternative flow in US-005 to also cover
double-discard rejection, not just nonexistent IDs. In the user story section
that describes the discard path, extend the scenario around the discard use case
so it explicitly states rejection when the remnant is already CONSUMED or
DISCARDED, and that no database update occurs in those states. Keep the wording
aligned with the existing scenario structure (“Given/When/Then/And”) so the
discard rules are unambiguous.
In `@docs/user_stories/US-007.md`:
- Around line 41-45: Update the INVEST criteria text in US-007 to remove the
“tolerante a saldos negativos” wording and describe that the backend should
never leave a remanente below zero. Keep the scenario consistent with the FEFO
flow by stating that any faltante is handled as a separate merma while the
affected remanente is reduced to zero; adjust the [N]egociable bullet
accordingly and keep the rest of the assessment unchanged.
In `@prompts.md`:
- Around line 394-398: The validation guidance incorrectly names DOMPurify as
the validator for emails, phone numbers, and PINs even though it only sanitizes
HTML. Update the section in prompts.md to point to a real runtime validation
approach such as Zod for params, query, and body, and restrict DOMPurify to
renderable HTML/XSS sanitization only; keep the wording aligned with the
existing Zero Trust validation strategy and the strict schema-based validation
guidance.
In `@readme.md`:
- Around line 345-405: The README summary is inconsistent with the content below
it: the intro claims 8 user stories, 9 tickets, and a full PR history, but this
section only includes US-001 to US-003, TK-001 to TK-003, and PR `#1`. Update the
summary in readme.md to match the actual documented scope, or add the missing
US/TK/PR entries so the counts and references align. Use the section headings
“Historias de Usuario”, “Tickets de Trabajo”, and “Pull Requests” as the anchors
when reconciling the content.
---
Minor comments:
In @.gitignore:
- Around line 37-42: The `.vscode/` ignore rule blocks the later negation
entries from re-including tracked editor files, so update the `.gitignore`
patterns under the IDEs/Editors section to ignore the contents of `.vscode`
instead of the directory itself. Keep the existing exception entries for
`.vscode/settings.json`, `.vscode/tasks.json`, `.vscode/launch.json`, and
`.vscode/extensions.json` so those files can still be tracked.
In `@docs/01_idea_inicial.md`:
- Around line 3-10: The table of contents links use accented fragments that do
not match the generated heading anchors, so update the six TOC entries in the
index to use the same accent-free slugs produced by the markdown headings. Edit
the existing list items under the Índice section so each fragment matches its
corresponding heading ID, using the same pattern as the headings for Frontera
entre Problema y Solución, Visión y Métricas de Éxito (KPIs), Lenguaje Ubicuo,
Flujo Principal, Fuera de Alcance, and Preguntas de Clarificación.
In `@docs/02_restostock_prd.md`:
- Around line 100-106: The “Integración de Hardware Físico” non-goal is
truncated and merged into the next heading, breaking the markdown structure.
Edit the non-goals section in the PRD so the bullet is completed as its own item
and the “Backlog de Historias de Usuario (INVEST)” heading starts on a new line
after the list. Use the surrounding section titles and the “Multisede” bullet to
locate the broken list entry.
- Around line 3-24: The Backlog table-of-contents link is broken because the
section heading for the backlog is merged into the prior bullet list instead of
being a standalone heading. Update the markdown around the Table of Contents so
the “Backlog de Historias de Usuario (INVEST)” section has its own heading that
matches the anchor used by the TOC link. Use the existing TOC entry and the
“Backlog de Historias de Usuario (INVEST)” title as the locating symbols when
fixing the structure.
In `@docs/07_restostock_security_strategy.md`:
- Around line 53-56: The terminology in the “Conexiones Seguras y Cifrado”
section is incorrect for PIN storage: bcrypt is a one-way hash, not encryption.
Update the heading and surrounding text in this docs section to explicitly
describe PIN hashing and verification, and replace “Encryption at Rest” language
with “hashing” terminology while keeping the bcrypt guidance and salt-round
requirements aligned with the existing security control.
In `@docs/10_restostock_api_specification.md`:
- Around line 92-100: The `remanente.unit` field in the API spec is ambiguous
because `Remanente` does not persist a unit directly. Update the `remanente`
example and surrounding description to either mark `unit` as a derived value
sourced from `Insumo.consumptionUnit` or `StockMovement.unit`, or remove it to
match the other `Remanente` payloads; use the `Remanente` and
`Insumo.consumptionUnit` references to keep the spec consistent.
In `@docs/tickets/TK-008.md`:
- Around line 21-23: Clarify the deadlock mitigation in the risk note: keep
`remanente.id` ordering only for lock acquisition or transaction sequencing, and
do not use it as the business consumption order. Update the wording around the
deadlock section in `TK-008.md` so it clearly states that the actual depletion
logic must remain FEFO, using `calculated_expiration_date` ascending, with
`remanente.id` only serving to make Prisma transaction updates acquire locks in
a consistent order.
In `@readme.md`:
- Around line 63-90: The local setup section still contains placeholder text
instead of actionable steps, so replace each “Sin definir aun” block with the
actual bootstrap commands in the README’s setup list. Update the steps for
cloning, installing monorepo dependencies, creating the `.env` file under
`apps/backend/`, starting Docker Compose, running Prisma migrations/seed, and
launching the development servers, using the same section structure so a
contributor can follow it end to end. If any command is intentionally not ready,
mark that specific step as pending rather than leaving placeholders.
---
Nitpick comments:
In `@docs/tickets/TK-002.md`:
- Around line 15-17: The `Pin` value object is taking on hashing/verification
responsibilities that should not live in the domain layer. Update the
`User`/`Pin` domain model so it only validates PIN format and leaves
`bcrypt`-style hashing and comparison to `AuthenticateByPinUseCase` or
infrastructure helpers; keep `IUserRepository` and the API/auth flow aligned
with that separation.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 44ce643d-2aa4-4400-aa11-378c001305ff
📒 Files selected for processing (36)
.gitignoreCHANGELOG.mddocs/00_nuevas_ideas_funcionalidades.mddocs/01_idea_inicial.mddocs/02_restostock_prd.mddocs/03_restostock_design.mddocs/04_restostock_architecture_diagram.mddocs/05_restostock_components_description.mddocs/06_restostock_folder_structure.mddocs/07_restostock_security_strategy.mddocs/08_restostock_testing_strategy.mddocs/09_restostock_database_schema.mddocs/10_restostock_api_specification.mddocs/audit_report.mddocs/backlog_map.mddocs/tickets/TK-001.mddocs/tickets/TK-002.mddocs/tickets/TK-003.mddocs/tickets/TK-004.mddocs/tickets/TK-005.mddocs/tickets/TK-006.mddocs/tickets/TK-007.mddocs/tickets/TK-008.mddocs/tickets/TK-009.mddocs/tickets/indice_tickets.mddocs/user_stories/US-001.mddocs/user_stories/US-002.mddocs/user_stories/US-003.mddocs/user_stories/US-004.mddocs/user_stories/US-005.mddocs/user_stories/US-006.mddocs/user_stories/US-007.mddocs/user_stories/US-008.mddocs/user_stories/indice_user_stories.mdprompts.mdreadme.md
There was a problem hiding this comment.
Actionable comments posted: 10
🧹 Nitpick comments (2)
.prompts/skills/SK-01_product_discovery.md (2)
24-25: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick winExige hipótesis falsables, no solo impactos “medibles”.
La plantilla permite generar hipótesis sin línea base, objetivo cuantificado ni ventana de observación. Añade esos elementos para que la validación pueda confirmar o rechazar la hipótesis.
Propuesta
-1. HIPÓTESIS DE VALIDACIÓN: Formula la hipótesis de negocio utilizando la estructura: "Creemos que si permitimos a [User Persona] realizar [acción de valor], lograremos [cambio de comportamiento / impacto medible]". +1. HIPÓTESIS DE VALIDACIÓN: Formula una hipótesis con acción, métrica, línea base, objetivo, población y ventana temporal: "Creemos que si permitimos a [User Persona] realizar [acción de valor], [métrica] aumentará/disminuirá de [línea base] a [objetivo] en [periodo]".🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.prompts/skills/SK-01_product_discovery.md around lines 24 - 25, Actualiza las secciones “HIPÓTESIS DE VALIDACIÓN” y cualquier instrucción asociada para exigir hipótesis falsables: incluye una línea base, un objetivo cuantificado y una ventana de observación, además de la acción, persona e impacto. Mantén la estructura identificable de “HIPÓTESIS DE VALIDACIÓN” y asegúrate de que la hipótesis permita confirmarse o rechazarse mediante esos criterios.
13-14: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick winHaz que la investigación de mercado sea verificable y acotada.
“Investiga brevemente” no define geografía, segmento, horizonte temporal ni formato de evidencias. El resultado puede ser genérico o estar desactualizado, y la decisión Buy vs. Build no será auditable.
Propuesta
-1. ANÁLISIS DEL MERCADO Y COMPETENCIA: Investiga brevemente qué soluciones (tanto open source como comerciales/SaaS) existen actualmente en el mercado para resolver este dolor. -2. DECISIÓN BUY VS. BUILD: Evalúa de forma estratégica si realmente tiene sentido construir esta solución desde cero o si es un "commodity" que se podría resolver utilizando integraciones existentes. Define cuál es el verdadero "core diferencial" que justifica el desarrollo propio. +1. ANÁLISIS DEL MERCADO Y COMPETENCIA: Investiga, para [GEOGRAFÍA], [SEGMENTO] y con información vigente a [FECHA], qué soluciones open source y comerciales/SaaS existen. Incluye fuentes, fecha de consulta y separa hechos de inferencias. +2. DECISIÓN BUY VS. BUILD: Compara las alternativas según coste, cobertura funcional, integración, riesgos y diferenciación. Justifica qué core diferencial requiere desarrollo propio.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.prompts/skills/SK-01_product_discovery.md around lines 13 - 14, Acota la investigación de mercado definiendo explícitamente geografía, segmento objetivo y horizonte temporal, y exige comparar un conjunto limitado de soluciones open source y comerciales/SaaS. En las secciones “ANÁLISIS DEL MERCADO Y COMPETENCIA” y “DECISIÓN BUY VS. BUILD”, solicita evidencias verificables para cada opción —como URL, documentación, precios o fecha de consulta— y un formato uniforme que incluya capacidades, limitaciones, costes y adecuación al problema, junto con criterios explícitos para justificar el core diferencial y la decisión final.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.prompts/skills/SK-02_prd_generation.md:
- Around line 38-42: Define deterministic offline-transaction rules in section
“3.2. Flujos Alternativos y Manejo de Errores”: specify client-generated
idempotency keys, durable local queueing, replay ordering, duplicate prevention,
retry behavior, conflict resolution, and handling of authentication/token or
entity-expiration changes while offline. Alternatively, remove the local/delayed
persistence requirement from the MVP; ensure the prompt no longer leaves offline
inventory-movement semantics ambiguous.
In @.prompts/skills/SK-03_architecture_design.md:
- Around line 3-6: The prompt inconsistently hard-codes “design.md” instead of
using the configured output path. Update the references in the
architecture-design instructions, including the document description near the
diff, to consistently use [RUTA_DE_SALIDA_DISEÑO] and align with the
orchestrator’s expected artifact path; remove any implication that a fixed
design.md filename should be created.
In @.prompts/skills/SK-07_cicd_pipeline.md:
- Around line 5-6: Expand the CI requirements in SK-07 to specify provisioning a
dedicated test database via a service container or equivalent, including
readiness health checks before tests run. Require applying schema migrations,
loading deterministic seed data, and cleaning up afterward, while keeping
connection details sourced from GitHub environment variables.
- Around line 3-6: Aclara en SK-07_cicd_pipeline.md que el workflow use
exclusivamente el evento pull_request hacia main y nunca pull_request_target,
sin exponer secrets del repositorio a jobs que ejecuten código del checkout.
Configura la base de datos de pruebas mediante credenciales desechables no
sensibles y variables de entorno del workflow, o un service container, evitando
secretos reales y verificando que TypeScript, linters y pruebas usen esa
configuración.
In @.prompts/skills/SK-08_security_strategy.md:
- Around line 18-19: Update the security strategy’s “Conexiones Seguras y
Cifrado” guidance to clearly separate irreversible hashing/KDF from reversible
encryption: require salted password hashing for PINs, hash tokens when only
comparison is needed, and reserve column encryption for tokens or other data
that must be recovered.
- Around line 12-14: Corrige la instrucción sobre DOMPurify: no lo presentes
como validador genérico de entradas ni para correos, PINs, números o payloads
HTTP. En el punto 2, exige esquemas estrictos en tiempo de ejecución, como Zod,
para validar por separado params, query y body antes de la capa de aplicación o
dominio; reserva DOMPurify exclusivamente para campos que acepten HTML o texto
enriquecido intencionalmente.
- Around line 1-3: Actualiza el prompt asociado a “Seguridad y Mitigación de
Vulnerabilidades” para exigir primero un inventario de funcionalidades de IA y
jurisdicciones relevantes, antes de clasificar el riesgo o asumir que aplica el
EU AI Act; si no existe un componente de IA calificable, debe declararse como no
aplicable y justificarse. Mantén el análisis GDPR vinculado al modelo real de
tratamiento de datos personales, incluyendo los apartados relacionados entre las
líneas 21-25.
In @.prompts/skills/SK-10_prisma_schema.md:
- Around line 3-12: Aclara en SK-10_prisma_schema.md que el resultado destinado
a [RUTA_DE_SALIDA_SCHEMA] debe ser un archivo ejecutable con sintaxis pura de
Prisma, sin encabezados, texto explicativo ni bloques Markdown; si también se
requiere documentación en prompts.md, define un artefacto separado para ella y
conserva allí la justificación de los índices.
In @.prompts/skills/SK-11_api_specification.md:
- Around line 15-20: Define a single deterministic serialization for Decimal
values in the API specification, preferably decimal strings, and remove the
“números/strings” alternative from the request payload guidance. Document the
required precision, scale, and validation pattern, and ensure all relevant
payload and response examples and endpoint contracts use that representation
consistently.
In @.prompts/skills/SK-14_pull_requests.md:
- Around line 7-23: Actualiza “Paso 1” y “Paso 2” para prohibir la invención de
historial, PRs, tickets o Quality Gates: exige evidencia verificable del
repositorio, GitHub y CI, marca como “No verificable” cualquier dato sin
respaldo y permite documentar menos de tres PRs cuando no existan. Elimina la
obligación de inferir hitos desde carpetas o backlog y conserva la plantilla
únicamente para PRs realmente identificadas, usando los símbolos “Paso 1” y
“Paso 2” como puntos de modificación.
---
Nitpick comments:
In @.prompts/skills/SK-01_product_discovery.md:
- Around line 24-25: Actualiza las secciones “HIPÓTESIS DE VALIDACIÓN” y
cualquier instrucción asociada para exigir hipótesis falsables: incluye una
línea base, un objetivo cuantificado y una ventana de observación, además de la
acción, persona e impacto. Mantén la estructura identificable de “HIPÓTESIS DE
VALIDACIÓN” y asegúrate de que la hipótesis permita confirmarse o rechazarse
mediante esos criterios.
- Around line 13-14: Acota la investigación de mercado definiendo explícitamente
geografía, segmento objetivo y horizonte temporal, y exige comparar un conjunto
limitado de soluciones open source y comerciales/SaaS. En las secciones
“ANÁLISIS DEL MERCADO Y COMPETENCIA” y “DECISIÓN BUY VS. BUILD”, solicita
evidencias verificables para cada opción —como URL, documentación, precios o
fecha de consulta— y un formato uniforme que incluya capacidades, limitaciones,
costes y adecuación al problema, junto con criterios explícitos para justificar
el core diferencial y la decisión final.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 5291a098-d06a-4234-849d-2555424fa13c
📒 Files selected for processing (17)
.prompts/README.md.prompts/nuevas_ideas_cascada.md.prompts/skills/SK-01_product_discovery.md.prompts/skills/SK-02_prd_generation.md.prompts/skills/SK-03_architecture_design.md.prompts/skills/SK-04_mermaid_diagram.md.prompts/skills/SK-05_hexagonal_layers.md.prompts/skills/SK-06_folder_structure.md.prompts/skills/SK-07_cicd_pipeline.md.prompts/skills/SK-08_security_strategy.md.prompts/skills/SK-09_testing_strategy.md.prompts/skills/SK-10_prisma_schema.md.prompts/skills/SK-11_api_specification.md.prompts/skills/SK-12_user_stories.md.prompts/skills/SK-13_backlog_tickets.md.prompts/skills/SK-14_pull_requests.mdprompts.md
💤 Files with no reviewable changes (1)
- .prompts/nuevas_ideas_cascada.md
✅ Files skipped from review due to trivial changes (5)
- .prompts/skills/SK-09_testing_strategy.md
- .prompts/README.md
- .prompts/skills/SK-12_user_stories.md
- .prompts/skills/SK-04_mermaid_diagram.md
- .prompts/skills/SK-13_backlog_tickets.md
🚧 Files skipped from review as they are similar to previous changes (1)
- prompts.md
…ith technical guidelines
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.prompts/skills/SK-14_pull_requests.md:
- Around line 15-16: Update the PR template instructions around the PR title and
branch-name fields to require the exact values from GitHub, preserving them
verbatim. Do not synthesize, rewrite, or normalize historical metadata to match
Conventional Commits or branch naming conventions; instead, mark any
non-conformance while retaining the original title and branch name.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 88383708-c86e-41b8-ae0b-50bc00ae9c63
📒 Files selected for processing (20)
.prompts/skills/SK-02_prd_generation.md.prompts/skills/SK-03_architecture_design.md.prompts/skills/SK-07_cicd_pipeline.md.prompts/skills/SK-08_security_strategy.md.prompts/skills/SK-10_prisma_schema.md.prompts/skills/SK-11_api_specification.md.prompts/skills/SK-14_pull_requests.mdCHANGELOG.mddocs/02_restostock_prd.mddocs/05_restostock_components_description.mddocs/10_restostock_api_specification.mddocs/tickets/TK-003.mddocs/tickets/TK-007.mddocs/tickets/TK-009.mddocs/tickets/indice_tickets.mddocs/user_stories/US-002.mddocs/user_stories/US-005.mddocs/user_stories/US-007.mddocs/user_stories/US-008.mdreadme.md
✅ Files skipped from review due to trivial changes (16)
- docs/user_stories/US-007.md
- docs/user_stories/US-002.md
- .prompts/skills/SK-07_cicd_pipeline.md
- .prompts/skills/SK-03_architecture_design.md
- .prompts/skills/SK-10_prisma_schema.md
- docs/user_stories/US-008.md
- docs/tickets/indice_tickets.md
- docs/05_restostock_components_description.md
- CHANGELOG.md
- .prompts/skills/SK-11_api_specification.md
- docs/tickets/TK-009.md
- docs/tickets/TK-003.md
- docs/10_restostock_api_specification.md
- docs/tickets/TK-007.md
- docs/user_stories/US-005.md
- docs/02_restostock_prd.md
🚧 Files skipped from review as they are similar to previous changes (3)
- .prompts/skills/SK-08_security_strategy.md
- .prompts/skills/SK-02_prd_generation.md
- readme.md
…cimal precision and SK-14 updates
There was a problem hiding this comment.
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (5)
readme.md (4)
276-276: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick winCorrect the documented endpoint count.
This section says there are 3 critical endpoints, but the README documents four sections:
/api/auth/pin,/api/stock/extraction,/api/kitchen/remanentes, and/api/reports/waste.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@readme.md` at line 276, Update the README statement describing the critical business endpoints to say there are 4 instead of 3, matching the documented sections for /api/auth/pin, /api/stock/extraction, /api/kitchen/remanentes, and /api/reports/waste.
181-181: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick winDescribe bcrypt as hashing, not encryption.
bcrypt produces one-way password/PIN hashes; it does not encrypt values for later decryption. Update this wording so the security documentation does not imply that credentials can be recovered.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@readme.md` at line 181, Update the “Cifrado de Datos” documentation entry to describe bcrypt as one-way hashing rather than encryption, while preserving the cost factor 10 and database storage details; make clear that passwords and PINs cannot be recovered by decryption.
65-90: 📐 Maintainability & Code Quality | 🟠 Major | ⚡ Quick winReplace the installation placeholders with real commands.
The README presents these blocks as executable setup instructions, but each contains
Sin definir aun.. Copying them produces shell/configuration errors and prevents local onboarding. Add the actual clone, install, environment, database, migration, and development commands, or clearly mark this section as pending instead of presenting placeholders as instructions.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@readme.md` around lines 65 - 90, Replace every “Sin definir aun.” placeholder in “Pasos para la puesta en marcha local” with the actual clone, dependency installation, environment configuration, Docker Compose, Prisma migration/seed, and development server commands; if any command is unavailable, clearly mark the corresponding setup step as pending rather than leaving executable-looking placeholder blocks.
127-127: 🔒 Security & Privacy | 🟡 Minor | ⚡ Quick winClarify the tablet auth contract
readme.md:127,143still mixes “PIN Auth Token” and “JWT/PIN”; the tablet should use the PIN only for/api/auth/pin, then send the returned Bearer JWT on subsequent requests.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@readme.md` at line 127, Update the README’s tablet authentication documentation and diagram labels to state that the tablet sends the PIN only to /api/auth/pin, then uses the returned Bearer JWT for all subsequent API requests; remove inconsistent “PIN Auth Token” and “JWT/PIN” wording while preserving the existing API flow description.prompts.md (1)
67-75: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick winClose the Prompt 3 code fence before the response section.
The fence opened at Line 67 remains open through the “Respuesta del Agente de IA” and architecture headings, so that content is rendered as code until the next fence at Line 85. Add the closing ````` immediately after the Prompt 3 instruction.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@prompts.md` around lines 67 - 75, Close the Markdown code fence immediately after the Prompt 3 instruction and before the “Respuesta del agente de IA” section, keeping the response and subsequent architecture headings rendered as normal Markdown.
🧹 Nitpick comments (1)
prompts.md (1)
248-251: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick winAvoid duplicate Markdown headings for response labels.
Respuesta del Agente de IAandNota de control humanoare repeated headings, triggering MD024 and creating ambiguous anchors. Use unique section-specific headings or bold labels instead.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@prompts.md` around lines 248 - 251, Update the response labels in the affected documentation section so “Respuesta del agente de IA” and “Nota de control humano” are not repeated Markdown headings; use unique section-specific headings or bold labels while preserving the existing content.Source: Linters/SAST tools
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In `@prompts.md`:
- Around line 67-75: Close the Markdown code fence immediately after the Prompt
3 instruction and before the “Respuesta del agente de IA” section, keeping the
response and subsequent architecture headings rendered as normal Markdown.
In `@readme.md`:
- Line 276: Update the README statement describing the critical business
endpoints to say there are 4 instead of 3, matching the documented sections for
/api/auth/pin, /api/stock/extraction, /api/kitchen/remanentes, and
/api/reports/waste.
- Line 181: Update the “Cifrado de Datos” documentation entry to describe bcrypt
as one-way hashing rather than encryption, while preserving the cost factor 10
and database storage details; make clear that passwords and PINs cannot be
recovered by decryption.
- Around line 65-90: Replace every “Sin definir aun.” placeholder in “Pasos para
la puesta en marcha local” with the actual clone, dependency installation,
environment configuration, Docker Compose, Prisma migration/seed, and
development server commands; if any command is unavailable, clearly mark the
corresponding setup step as pending rather than leaving executable-looking
placeholder blocks.
- Line 127: Update the README’s tablet authentication documentation and diagram
labels to state that the tablet sends the PIN only to /api/auth/pin, then uses
the returned Bearer JWT for all subsequent API requests; remove inconsistent
“PIN Auth Token” and “JWT/PIN” wording while preserving the existing API flow
description.
---
Nitpick comments:
In `@prompts.md`:
- Around line 248-251: Update the response labels in the affected documentation
section so “Respuesta del agente de IA” and “Nota de control humano” are not
repeated Markdown headings; use unique section-specific headings or bold labels
while preserving the existing content.
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: dbd30d3d-0a61-4582-8f66-11007fbaba47
📒 Files selected for processing (14)
.prompts/skills/SK-14_pull_requests.mdCHANGELOG.mddocs/02_restostock_prd.mddocs/03_restostock_design.mddocs/06_restostock_folder_structure.mddocs/10_restostock_api_specification.mddocs/audit_report.mddocs/backlog_map.mddocs/tickets/TK-010.mddocs/tickets/indice_tickets.mddocs/user_stories/US-009.mddocs/user_stories/indice_user_stories.mdprompts.mdreadme.md
✅ Files skipped from review due to trivial changes (10)
- docs/user_stories/indice_user_stories.md
- docs/user_stories/US-009.md
- .prompts/skills/SK-14_pull_requests.md
- docs/tickets/indice_tickets.md
- docs/audit_report.md
- docs/tickets/TK-010.md
- docs/06_restostock_folder_structure.md
- docs/backlog_map.md
- docs/03_restostock_design.md
- docs/02_restostock_prd.md
🚧 Files skipped from review as they are similar to previous changes (1)
- docs/10_restostock_api_specification.md
- Reorganiza archivos de docs/ y .prompts/skills/ en carpetas estructuradas - Actualiza referencias e índices en readme.md, CHANGELOG.md, prompts.md y guías - Añade nuevos documentos de gobernanza, trazabilidad y glosario
There was a problem hiding this comment.
Note
Due to the large number of review comments, Critical severity comments were prioritized as inline comments.
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (6)
.prompts/skills/specs/05_agile_planning/SK-14_pull_requests.md (1)
35-36: 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick winAllow fewer than three PR records consistently.
The prompt permits fewer than three verified PRs in Step 1, but later requires exactly three fichas. Change these instructions to require up to three verified PRs, documenting fewer when the repository provides insufficient evidence.
Also applies to: 42-42
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.prompts/skills/specs/05_agile_planning/SK-14_pull_requests.md around lines 35 - 36, Actualiza las instrucciones de los pasos 1 y 2 para solicitar hasta tres PRs verificadas, no exactamente tres, y permitir documentar menos cuando el repositorio no aporte evidencia suficiente. Mantén coherente la instrucción del paso 3 para que escriba las fichas disponibles, hasta un máximo de tres, preservando intacto el resto del documento.docs/05_agile_planning/tickets/TK-008.md (1)
15-17: 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick winAdd an insufficient-stock rollback acceptance case.
Require a
422response when any ingredient cannot be fully satisfied and assert that every remanent and movement remains unchanged. This is the concrete proof that the single$transactionprevents partial recipe consumption.Also applies to: 38-41
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/05_agile_planning/tickets/TK-008.md` around lines 15 - 17, Extend the TK-008 acceptance criteria for ConsumeRecipeUseCase to cover insufficient stock: when any ingredient cannot be fully satisfied, require a 422 response and verify that all remanents and stock movements retain their pre-consumption state, demonstrating atomic rollback through the single transaction.docs/05_agile_planning/tickets/TK-010.md (1)
20-24: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick winReplace the Prisma
groupBy+ relation join assumption.
groupBycannot return joined relation fields frominsumos, so this task should specify a two-step path or a raw SQL/view-based aggregation instead of framing a singlegroupByas the complete repository implementation.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/05_agile_planning/tickets/TK-010.md` around lines 20 - 24, Actualiza la especificación de PrismaReportRepository para no asumir que groupBy puede devolver campos relacionados de insumos. Describe una implementación en dos pasos que agregue StockMovement y luego consulte los nombres/marcas relacionados, o define explícitamente una agregación mediante SQL crudo o una vista.docs/01_product_definition/03_glosario_y_reglas_negocio.md (1)
35-39: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy liftMake offline inventory mutations idempotent end to end.
Timestamp ordering and UUID serialization do not prevent duplicate application after retries. Define one client event/idempotency key, carry it through the API, and enforce uniqueness in persistence.
docs/01_product_definition/03_glosario_y_reglas_negocio.md#L35-L39: replace timestamp-only replay semantics with an idempotent event protocol.docs/04_persistence_and_api/10_restostock_api_specification.md#L360-L366: add the key to mutation contracts and document duplicate-response behavior.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/01_product_definition/03_glosario_y_reglas_negocio.md` around lines 35 - 39, Define a single client event/idempotency key for offline inventory mutations and replace timestamp-only replay semantics in docs/01_product_definition/03_glosario_y_reglas_negocio.md:35-39 with protocol wording that carries this key through retries. Update the mutation contracts in docs/04_persistence_and_api/10_restostock_api_specification.md:360-366 to accept and propagate the key, enforce its uniqueness in persistence, and document the response returned when a duplicate key is submitted.docs/01_product_definition/02_restostock_prd.md (1)
104-107: 🎯 Functional Correctness | 🟠 Major | 🏗️ Heavy liftResolve the recipe-consumption scope contradiction.
The non-goal excludes automatic recipe deductions, while US-007 requires them. Choose one MVP behavior and propagate it to the stories, tickets, API, and tests. Also restore the missing line break before the heading at Line 107 (
No se integra##).Suggested clarification
-* **Descuento automático de inventario por receta (BOM):** No se calcularán deducciones automáticas... +* **Descuento automático por facturación o comandas:** No se calcularán deducciones implícitas... + +## 📋 5. Backlog de Historias de Usuario (INVEST)Also applies to: 186-196
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/01_product_definition/02_restostock_prd.md` around lines 104 - 107, Resolve the contradiction between the recipe-consumption non-goal and US-007 by selecting one explicit MVP behavior, then align US-007, related backlog tickets, API contracts, and tests with that behavior. Update the product-definition scope text and remove any conflicting requirements. Restore the missing newline before the section heading so “No se integra” and “## 📋 5. Backlog…” are separate lines.docs/02_architecture_design/06_restostock_folder_structure.md (1)
141-152: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick winFix the directory-tree connectors around
reports.
kitchenis shown with└──, which makes it the final child, butreportsis then introduced as another sibling with├──. Makekitchena non-final├──entry andreportsthe final└──entry so the documented tree is structurally valid.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/02_architecture_design/06_restostock_folder_structure.md` around lines 141 - 152, Update the directory-tree connectors for the kitchen and reports entries: change kitchen from the final-child └── connector to the non-final ├── connector, and make reports use the final-child └── connector. Preserve all nested kitchen structure and labels.
🟠 Major comments (26)
.prompts/skills/specs/01_product_definition/SK-02_prd_generation.md-9-9 (1)
9-9: 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick winAlign prompt output paths with the canonical repository artifacts.
These skills currently declare filenames that differ from the files referenced by downstream documentation and prompts. Agents may generate parallel files that later steps cannot locate.
.prompts/skills/specs/01_product_definition/SK-02_prd_generation.md#L9-L9: usedocs/01_product_definition/02_restostock_prd.md; update the default path in Lines 95-97 as well..prompts/skills/specs/02_architecture_design/SK-03_architecture_design.md#L9-L9: usedocs/02_architecture_design/03_restostock_design.md..prompts/skills/specs/02_architecture_design/SK-04_mermaid_diagram.md#L9-L10: usedocs/02_architecture_design/04_restostock_architecture_diagram.md.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.prompts/skills/specs/01_product_definition/SK-02_prd_generation.md at line 9, Align the declared output paths with the canonical repository artifacts: in .prompts/skills/specs/01_product_definition/SK-02_prd_generation.md at lines 9 and 95-97, use docs/01_product_definition/02_restostock_prd.md; in .prompts/skills/specs/02_architecture_design/SK-03_architecture_design.md at line 9, use docs/02_architecture_design/03_restostock_design.md; and in .prompts/skills/specs/02_architecture_design/SK-04_mermaid_diagram.md at lines 9-10, use docs/02_architecture_design/04_restostock_architecture_diagram.md..prompts/skills/specs/05_agile_planning/SK-12_user_stories.md-6-9 (1)
6-9: 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick winCompleta el contrato de entradas y salidas del prompt.
El frontmatter declara únicamente
prd_doc, aunque el cuerpo exige también[RUTA_DEL_DISEÑO]. Además, solo declara la carpeta de historias como salida, pero el prompt exige generar también el índice en[RUTA_DE_SALIDA_INDICE_STORIES]. Añadedesign_docy el archivo de índice al contrato de ejecución.Also applies to: 16-18, 35-36
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.prompts/skills/specs/05_agile_planning/SK-12_user_stories.md around lines 6 - 9, Completa el contrato de entradas y salidas del prompt: añade design_doc junto a prd_doc en inputs y declara el archivo de índice correspondiente a RUTA_DE_SALIDA_INDICE_STORIES junto a la carpeta de historias en outputs. Mantén alineados el frontmatter y las rutas exigidas por el cuerpo del prompt..prompts/skills/specs/02_architecture_design/SK-05_hexagonal_layers.md-1-10 (1)
1-10: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick winUnifica las rutas de salida de los prompts con los artefactos del repositorio.
Todos estos prompts omiten el segmento
restostockde sus rutas, por lo que pueden generar archivos que no coincidan con los nombres esperados por el stack documental:
.prompts/skills/specs/02_architecture_design/SK-05_hexagonal_layers.md#L1-L10: usa05_restostock_components_description.md..prompts/skills/specs/02_architecture_design/SK-06_folder_structure.md#L1-L9: usa06_restostock_folder_structure.md..prompts/skills/specs/03_governance_and_quality/SK-08_security_strategy.md#L1-L10: usa07_restostock_security_strategy.md..prompts/skills/specs/03_governance_and_quality/SK-09_testing_strategy.md#L1-L9: usa08_restostock_testing_strategy.md..prompts/skills/specs/04_persistence_and_api/SK-10_prisma_schema.md#L1-L10: usa09_restostock_database_schema.md..prompts/skills/specs/04_persistence_and_api/SK-11_api_specification.md#L1-L10: usa10_restostock_api_specification.md.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.prompts/skills/specs/02_architecture_design/SK-05_hexagonal_layers.md around lines 1 - 10, Unifica las rutas de salida con los artefactos esperados del repositorio: en .prompts/skills/specs/02_architecture_design/SK-05_hexagonal_layers.md (líneas 1-10), usa 05_restostock_components_description.md; en .prompts/skills/specs/02_architecture_design/SK-06_folder_structure.md (líneas 1-9), usa 06_restostock_folder_structure.md; en .prompts/skills/specs/03_governance_and_quality/SK-08_security_strategy.md (líneas 1-10), usa 07_restostock_security_strategy.md; en .prompts/skills/specs/03_governance_and_quality/SK-09_testing_strategy.md (líneas 1-9), usa 08_restostock_testing_strategy.md; en .prompts/skills/specs/04_persistence_and_api/SK-10_prisma_schema.md (líneas 1-10), usa 09_restostock_database_schema.md; y en .prompts/skills/specs/04_persistence_and_api/SK-11_api_specification.md (líneas 1-10), usa 10_restostock_api_specification.md.docs/05_agile_planning/matriz_trazabilidad.md-14-14 (1)
14-14: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick winUse one canonical API route per requirement.
The same contracts currently expose different paths for consumption and recipe consumption.
docs/05_agile_planning/matriz_trazabilidad.md#L14-L14: align REQ-004 with the selected consumption route.docs/05_agile_planning/matriz_trazabilidad.md#L17-L17: use the canonical recipe route from the API specification.docs/05_agile_planning/user_stories/US-004.md#L43-L44: update the story and tests to the same route.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/05_agile_planning/matriz_trazabilidad.md` at line 14, Use one canonical API route for each consumption requirement across all referenced documentation: update REQ-004 in docs/05_agile_planning/matriz_trazabilidad.md at lines 14-14 to the selected consumption route, update the recipe requirement at lines 17-17 to the canonical recipe route from the API specification, and update docs/05_agile_planning/user_stories/US-004.md at lines 43-44 so the story and tests use the same route.docs/05_agile_planning/matriz_trazabilidad.md-12-19 (1)
12-19: 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick winUse canonical Prisma model names in the matrix.
At least
ActiveRemanentandItemdo not match the supplied schema names (RemanenteandInsumo). Reconcile every Prisma entry against the actual schema; otherwise Rule 2’s “exact model declaration” check cannot be trusted.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/05_agile_planning/matriz_trazabilidad.md` around lines 12 - 19, Reconcile every Prisma model listed in the traceability matrix with the canonical declarations in the supplied schema, replacing incorrect names such as ActiveRemanent and Item with their exact schema names Remanente and Insumo. Review all model entries in REQ-002 through REQ-009, preserving valid names and updating only mismatches so Rule 2 can verify exact model declarations.docs/05_agile_planning/matriz_trazabilidad.md-11-19 (1)
11-19: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick winReplace local filesystem links with repository-relative links.
The
file:///home/lacruzjd/...links only work on the author’s machine and will be broken in GitHub and other clones. Use relative repository links for the user stories, tickets, and skills.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/05_agile_planning/matriz_trazabilidad.md` around lines 11 - 19, Replace every file:///home/lacruzjd/... URL in the traceability matrix links with repository-relative paths for the referenced user stories, tickets, and skills. Preserve each link’s existing target file and display text, using paths relative to the matrix document.docs/05_agile_planning/matriz_trazabilidad.md-25-27 (1)
25-27: 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick winMake the coverage rule and TK-001 mapping consistent.
The rule currently requires every ticket to have a user story and REST endpoint, while TK-001 is intentionally documented as an infrastructure enabler without either.
docs/05_agile_planning/matriz_trazabilidad.md#L25-L27: exempt infrastructure enablers explicitly or require their mappings.docs/05_agile_planning/backlog_map.md#L28-L29: update the graph if TK-001 must receive a requirement/endpoint.docs/05_agile_planning/backlog_map.md#L100-L100: remove the undocumented N/A exception or define it in the coverage rules.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/05_agile_planning/matriz_trazabilidad.md` around lines 25 - 27, Make the coverage rule and TK-001 mapping consistent: in docs/05_agile_planning/matriz_trazabilidad.md lines 25-27, explicitly exempt infrastructure enablers or require TK-001 to have a valid user story and documented REST endpoint; in docs/05_agile_planning/backlog_map.md lines 28-29, update TK-001’s graph if mappings are required; and at line 100 remove the undocumented N/A exception or define it in the coverage rules.docs/05_agile_planning/tickets/TK-002.md-21-23 (1)
21-23: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick winMake PIN brute-force protection testable.
The proposed five-attempt/15-minute lockout is not included in the acceptance criteria or DoD. Define the counter scope, atomic persistence, reset-on-success behavior, lockout response, and requirement that no token is issued while locked.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/05_agile_planning/tickets/TK-002.md` around lines 21 - 23, The PIN brute-force mitigation in “Mitigación de Riesgos Técnicos” must define testable lockout behavior: specify the counter scope, persist failed-attempt updates atomically, reset the counter after successful authentication, return a defined response while locked, and ensure no token is issued during lockout. Add the five-attempt and 15-minute requirements to the ticket’s acceptance criteria or DoD.docs/05_agile_planning/tickets/TK-001.md-22-29 (1)
22-29: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick winMake database TLS enforcement explicit.
Validating that
DATABASE_URLexists does not guarantee an encrypted PostgreSQL connection. Require the URL/provider-specific TLS setting in the DoD, for examplesslmode=requireorDATABASE_OPTIONS=sslmode=require, and test that non-TLS configuration is rejected.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/05_agile_planning/tickets/TK-001.md` around lines 22 - 29, Actualiza el DoD de conectividad y validación de configuración para exigir explícitamente TLS en PostgreSQL mediante la configuración correspondiente de DATABASE_URL o DATABASE_OPTIONS, como sslmode=require. Añade el criterio de que las configuraciones sin TLS sean rechazadas durante la validación Zod y cubre este caso en las pruebas.docs/05_agile_planning/tickets/TK-003.md-21-23 (1)
21-23: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy liftRequire database-level concurrency control for stock state transitions.
Application/domain checks alone can allow duplicate debits or duplicate discard movements under concurrent requests. Use row locks, serializable transactions with retry, or atomic conditional updates, and create the audit movements within the same protected transaction.
docs/05_agile_planning/tickets/TK-003.md#L21-L23: do not treat a sequential transaction alone as sufficient for stock extraction.docs/05_agile_planning/tickets/TK-006.md#L21-L24: protect the active-to-discarded transition against concurrent double discard.docs/05_agile_planning/tickets/TK-009.md#L21-L23: select/lock affected IDs before bulk updates, or use a supported returning/locking strategy, so concurrent closures cannot duplicate discard records.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/05_agile_planning/tickets/TK-003.md` around lines 21 - 23, The ticket requirements must explicitly mandate database-level concurrency control for every stock state transition. In docs/05_agile_planning/tickets/TK-003.md lines 21-23, require row locking, serializable transactions with retry, or atomic conditional updates, and create audit movements within the same protected transaction; do not describe a sequential transaction alone as sufficient. Apply equivalent protection to the active-to-discarded transition in docs/05_agile_planning/tickets/TK-006.md lines 21-24, and in docs/05_agile_planning/tickets/TK-009.md lines 21-23 require selecting and locking affected IDs before bulk updates or another supported locking/returning strategy to prevent duplicate discard records.docs/04_persistence_and_api/09_restostock_database_schema.md-87-87 (1)
87-87: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy liftAlign
conversionFactorprecision with the documented invariant.
conversionFactorusesDecimal(10,2), while the glossary invariant and audit report specifyDecimal(12,4)for numeric physical quantities. Widen the field or explicitly exempt it consistently; otherwise unit conversion can introduce rounding errors.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/04_persistence_and_api/09_restostock_database_schema.md` at line 87, Update the conversionFactor field in the schema definition to use Decimal(12,4), aligning it with the documented precision invariant for numeric physical quantities. Preserve its existing conversion_factor mapping.docs/04_persistence_and_api/10_restostock_api_specification.md-74-99 (1)
74-99: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy liftDefer remanente creation until the unit is opened.
The product flow extracts a sealed purchase unit first, then creates a remanente on the first partial consumption in consumption units. This contract creates an active remanente immediately, keeps its quantity in
Horma, and starts accelerated expiration at extraction, conflicting with the documented conversion and shelf-life rules.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/04_persistence_and_api/10_restostock_api_specification.md` around lines 74 - 99, Update the POST /api/stock/extraction contract so extraction only records the sealed purchase-unit removal; defer remanente creation until the unit is opened during the first partial consumption. Remove the immediate ACTIVE remanente response, quantity in Horma, and extraction-time calculated expiration, and document the later remanente creation using consumption units and the applicable accelerated shelf-life rules.docs/04_persistence_and_api/09_restostock_database_schema.md-111-116 (1)
111-116: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy liftDo not cascade-delete inventory audit history.
Deleting an
Insumocurrently cascades intoStockMovement, despite that table being the immutable audit log. Use soft deletion viaisActiveand restrictive/archive semantics for catalog records; otherwise historical waste and movement reports can disappear.Also applies to: 135-145, 161-169, 192-198
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/04_persistence_and_api/09_restostock_database_schema.md` around lines 111 - 116, Update the Prisma relations and deletion behavior for inventory audit records, including the schema sections around the Insumo, StockMovement, and related catalog relations. Remove Cascade deletion from audit-history paths and use restrictive or archive semantics instead, preserving StockMovement and historical waste/movement reports when an Insumo is deleted; rely on the existing isActive soft-deletion approach for catalog records.docs/03_governance_and_quality/audit_report.md-51-56 (1)
51-56: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy liftAlign the audit finding with the actual negative-balance invariant.
This section says recipe consumption reduces stock to zero and records the shortage, but
docs/01_product_definition/03_glosario_y_reglas_negocio.mdand the API specification require rejecting over-consumption atomically with HTTP 422. Select one rule before claiming that all findings are resolved.Also applies to: 60-64
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/03_governance_and_quality/audit_report.md` around lines 51 - 56, Align the US-007 statement in the audit report with the authoritative negative-balance rule: over-consumption must be rejected atomically with HTTP 422 rather than clamped to zero and recorded as a shortage. Update the related finding text consistently and only claim resolution once it matches the glossary and API specification.docs/04_persistence_and_api/09_restostock_database_schema.md-147-163 (1)
147-163: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy liftModel discard movements with a valid destination contract.
StockMovementrequiresfromLocationandtoLocation, butLocationTypeonly contains operational storage locations, so aDISCARDmovement cannot represent a real waste destination. Add aWASTE/waste location, or make the destination nullable and enforce discard-specific destination constraints. Also makereasonnon-nullable, e.g. an enum type or Prisma-level constraint fortype == DISCARD.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/04_persistence_and_api/09_restostock_database_schema.md` around lines 147 - 163, Update the StockMovement model and its related LocationType definition so discard movements can represent a valid waste destination by adding a WASTE location, and make reason required for discard records through the existing schema’s strongest available constraint or validation. Preserve destination requirements for non-discard movements and ensure discard movements use the waste destination consistently.docs/02_architecture_design/03_restostock_design.md-393-410 (1)
393-410: 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick winDefine how discard movements populate mandatory locations.
stock_movements.from_locationandto_locationare required, but the discard request supplies onlyreason. Specify the source/destination derivation from the remanent, or make those fields conditionally nullable with an explicit invariant; otherwise the endpoint contract cannot produce a valid movement record.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/02_architecture_design/03_restostock_design.md` around lines 393 - 410, Update the POST /api/kitchen/remanentes/:id/discard contract to define how mandatory stock movement locations are populated: specify that from_location and to_location are derived from the remanent, or explicitly document their conditional nullability and invariant when recording a discard movement.docs/02_architecture_design/03_restostock_design.md-262-289 (1)
262-289: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick winAdd brute-force protection to public PIN authentication.
A public endpoint accepting a four-digit PIN needs rate limiting, retry throttling/lockout, and security audit events. Without these controls, the documented authentication boundary permits rapid credential guessing.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/02_architecture_design/03_restostock_design.md` around lines 262 - 289, Add brute-force protections to the documented POST /api/auth/pin flow: apply per-user and per-client rate limiting, progressively throttle or temporarily lock authentication after repeated invalid PIN attempts, and emit security audit events for failures and lockouts. Preserve successful authentication and the existing 401 error contract while ensuring the controls cannot be bypassed by rapid retries.docs/02_architecture_design/05_restostock_components_description.md-202-205 (1)
202-205: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick winMap domain errors safely instead of returning every error as HTTP 500.
Validation and insufficient-stock failures should become the documented 4xx responses. Returning
error.messagedirectly can expose internal details; use typed error mapping and a generic 500 response for unexpected failures.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/02_architecture_design/05_restostock_components_description.md` around lines 202 - 205, Update the extraction-recording error handler around the catch block to map known validation and insufficient-stock domain errors to their documented 4xx status responses. Avoid exposing error.message directly; return safe client-facing messages for typed domain errors and use a generic internal-server-error response for unexpected failures.docs/02_architecture_design/03_restostock_design.md-81-89 (1)
81-89: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy liftChoose one repository-root layout.
The architecture map places
src/at the repository root, while the folder specification places backend code underapps/backend/src/. This ambiguity will produce incorrect imports, commands, and deployment paths.
docs/02_architecture_design/03_restostock_design.md#L81-L89: update the slice map to use the chosen monorepo path.docs/02_architecture_design/06_restostock_folder_structure.md#L85-L95: keep the physical tree and all references aligned with that choice.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/02_architecture_design/03_restostock_design.md` around lines 81 - 89, Choose a single repository-root layout and align both documentation trees with it: update docs/02_architecture_design/03_restostock_design.md lines 81-89 to show the slice map under the chosen monorepo path, and update docs/02_architecture_design/06_restostock_folder_structure.md lines 85-95 so its physical tree and references use the same path. Ensure imports, commands, and deployment paths consistently follow that layout.docs/02_architecture_design/05_restostock_components_description.md-133-159 (1)
133-159: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy liftMake extraction a real stock transfer and honor
toLocation.
RecordExtractionInputomits the API’stoLocation, while the use case hardcodesKITCHEN_FRIDGE. More importantly, it only saves a movement and never atomically decrementswarehouse_stocks; repeated requests can create audit records without reducing available stock. Pass the destination through the use case and update stock plus movement in one transaction with an insufficient-stock check.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/02_architecture_design/05_restostock_components_description.md` around lines 133 - 159, Update RecordExtractionInput and RecordExtractionUseCase.execute to accept and propagate the API’s toLocation instead of hardcoding KITCHEN_FRIDGE. Make extraction atomically validate and decrement warehouse_stocks, then persist the StockMovement through the repository in the same transaction, rejecting insufficient stock and preventing audit records without the corresponding stock reduction.docs/03_governance_and_quality/07_restostock_security_strategy.md-66-72 (1)
66-72: 🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy liftAvoid claiming strict GDPR compliance from this control list alone.
Minimization and tokenization are useful controls, but this section does not establish lawful basis, retention/deletion, data-subject rights, processor contracts, breach handling, or access governance. Reword this as planned GDPR-aligned controls unless a legal/privacy assessment covers the remaining obligations.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/03_governance_and_quality/07_restostock_security_strategy.md` around lines 66 - 72, Reword the section headed “3.2. Cumplimiento de la Directiva GDPR” to describe planned GDPR-aligned privacy controls rather than strict GDPR compliance. Retain the existing minimization and LLM de-identification/tokenization controls, but avoid implying they alone satisfy GDPR; only claim full compliance if supported by a documented legal/privacy assessment covering the remaining obligations.docs/02_architecture_design/03_restostock_design.md-475-489 (1)
475-489: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy liftComplete the persistence blueprint for advertised MVP workflows.
The architecture promises recipe consumption and shift reconciliation, and the folder tree lists their entities and use cases, but the logical data model does not define their tables, relationships, constraints, or indexes.
docs/02_architecture_design/03_restostock_design.md#L475-L489: add the persistence contracts for recipes and reconciliation, or mark the workflows as future scope.docs/02_architecture_design/06_restostock_folder_structure.md#L119-L146: keep the folder structure synchronized with the final MVP scope.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/02_architecture_design/03_restostock_design.md` around lines 475 - 489, Complete the persistence blueprint in docs/02_architecture_design/03_restostock_design.md for the Recipe, RecipeIngredient, ConsumeRecipeUseCase, ShiftReconciliation, and ShiftReconciliationItem workflows, defining tables, relationships, constraints, and required indexes; alternatively mark these workflows as future scope. In docs/02_architecture_design/06_restostock_folder_structure.md, synchronize the listed entities and use cases with that final MVP decision, removing or retaining them consistently.docs/02_architecture_design/03_restostock_design.md-199-212 (1)
199-212: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy liftPrevent catalog deletion from destroying or invalidating audit history.
insumoscascades intoremanentes, whilestock_movements.insumo_idis mandatory and its delete behavior is unspecified. A physical ingredient deletion can therefore either erase remanents or fail because historical movements still reference the ingredient. Prefer soft deletion viais_active, or define consistentRESTRICT/archival semantics for every dependent record.Also applies to: 239-243
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/02_architecture_design/03_restostock_design.md` around lines 199 - 212, Update the stock_movements and related insumos/remanentes schema definitions to preserve audit history when a catalog ingredient is removed. Prefer adding an is_active soft-deletion field to insumos and ensuring dependent records remain intact; otherwise define consistent RESTRICT or archival delete behavior for insumos, remanentes, and stock_movements, including the mandatory stock_movements.insumo_id relationship.docs/02_architecture_design/05_restostock_components_description.md-186-195 (1)
186-195: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy liftStandardize the quantity representation end-to-end.
The API example serializes
quantityas a string, the security schema accepts a number, the controller expects a string and converts it toDecimalValue, and the tests pass numbers directly. Select one transport representation—preferably decimal strings—and explicitly convert toDecimalValueat the HTTP boundary.
docs/02_architecture_design/05_restostock_components_description.md#L186-L195: keep parsing and conversion at the controller boundary.docs/02_architecture_design/03_restostock_design.md#L296-L301: retain the chosen wire format in the API contract.docs/03_governance_and_quality/07_restostock_security_strategy.md#L22-L31: make the Zod schema validate the same wire format.docs/03_governance_and_quality/08_restostock_testing_strategy.md#L121-L140: construct the domain value object before invoking the use case.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/02_architecture_design/05_restostock_components_description.md` around lines 186 - 195, Standardize quantity as a decimal string across the full flow: in docs/02_architecture_design/05_restostock_components_description.md lines 186-195, keep validation and DecimalValue conversion at the controller boundary; in docs/02_architecture_design/03_restostock_design.md lines 296-301, retain the decimal-string wire format in the API contract; in docs/03_governance_and_quality/07_restostock_security_strategy.md lines 22-31, update the Zod schema to validate strings; and in docs/03_governance_and_quality/08_restostock_testing_strategy.md lines 121-140, convert test quantities to the domain value object before invoking the use case.docs/02_architecture_design/04_restostock_architecture_diagram.md-30-37 (1)
30-37: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy liftDocument the offline queue replay path.
The queue is shown storing events, but no edge sends queued transactions back to the API when connectivity returns. Add the synchronization/retry flow and define idempotency and conflict handling.
docs/02_architecture_design/04_restostock_architecture_diagram.md#L30-L37: add theOfflineQueue -> APIreplay path.docs/02_architecture_design/03_restostock_design.md#L60-L67: document replay, deduplication, and failure handling alongside the existing queue flow.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/02_architecture_design/04_restostock_architecture_diagram.md` around lines 30 - 37, Update docs/02_architecture_design/04_restostock_architecture_diagram.md lines 30-37 to add an OfflineQueue-to-API replay/synchronization edge, including retry behavior. Update docs/02_architecture_design/03_restostock_design.md lines 60-67 alongside the existing queue flow to document replay on reconnection, idempotent deduplication, and conflict/failure handling.docs/03_governance_and_quality/07_restostock_security_strategy.md-61-64 (1)
61-64: 🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy liftReframe the EU AI Act classification and date.
The AI Act is Regulation (EU) 2024/1689; avoiding the “Regulación Europea 2026” wording avoids implying this is a future/special 2026 regime. If RestoStock has no AI system now, state that the AI Act is out of scope for the current scope and classify any future AI feature based on its actual use case.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/03_governance_and_quality/07_restostock_security_strategy.md` around lines 61 - 64, Update section 3.1 to identify the EU AI Act as Regulation (EU) 2024/1689 and state that it is out of scope for RestoStock’s current non-AI functionality. Replace the fixed future “Limited Risk” classification with guidance to classify any future AI module according to its actual use case and applicable obligations.
🟡 Minor comments (9)
CHANGELOG.md-27-31 (1)
27-31: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick winUse a repository-relative link instead of a local filesystem URL.
file:///home/lacruzjd/...only works on the author’s machine, so the changelog link is broken for every repository reader and exposes a local path. Use the repository-relative path already used elsewhere in this file.Proposed fix
- * Actualización del instructivo de PRs en [.prompts/skills/specs/05_agile_planning/SK-14_pull_requests.md](file:///home/lacruzjd/entrgafinal/AI4Devs-finalproject/.prompts/skills/specs/05_agile_planning/SK-14_pull_requests.md) para exigir la retención íntegra de metadatos (título y rama) recuperados de GitHub, impidiendo normalizaciones artificiales y permitiendo identificar de forma no destructiva las no conformidades. + * Actualización del instructivo de PRs en [.prompts/skills/specs/05_agile_planning/SK-14_pull_requests.md](.prompts/skills/specs/05_agile_planning/SK-14_pull_requests.md) para exigir la retención íntegra de metadatos (título y rama) recuperados de GitHub, impidiendo normalizaciones artificiales y permitiendo identificar de forma no destructiva las no conformidades.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@CHANGELOG.md` around lines 27 - 31, Replace the local filesystem URL in the “Gobernanza de Historial de Integraciones” changelog entry with the repository-relative path to SK-14_pull_requests.md, matching the relative-link style already used elsewhere in CHANGELOG.md.prompts.md-57-57 (1)
57-57: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick winMake repeated response headings unique.
markdownlintreports MD024 because each section uses the same### Respuesta del Agente de IA:heading. Add the prompt/artifact name to each heading, or use non-heading formatting where unique anchors are unnecessary.Also applies to: 75-75, 167-167, 182-182, 198-198, 214-214, 231-231
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@prompts.md` at line 57, Update each repeated “Respuesta del Agente de IA” heading in prompts.md to include its corresponding prompt or artifact name, ensuring every heading is unique and satisfies markdownlint MD024; alternatively, convert these labels to non-heading formatting where unique anchors are unnecessary.Source: Linters/SAST tools
docs/README.md-12-36 (1)
12-36: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick winUse repository-relative documentation links.
The
file:///home/lacruzjd/...URLs are local-machine paths and will be broken for GitHub readers and other contributors. Replace them with relative links such as01_product_definition/01_idea_inicial.md.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/README.md` around lines 12 - 36, Update all documentation links in the README sections shown, replacing each file:///home/lacruzjd/... URL with a repository-relative path from the docs directory, such as 01_product_definition/01_idea_inicial.md. Preserve the existing link labels, descriptions, section structure, and directory links.docs/05_agile_planning/user_stories/US-003.md-30-31 (1)
30-31: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick winDefine all alert threshold boundaries.
The rules leave exactly 6 hours, exactly 24 hours, and expired remanents unspecified. Define inclusive boundaries and the expired state so the UI cannot classify the same remanent inconsistently.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/05_agile_planning/user_stories/US-003.md` around lines 30 - 31, Define explicit inclusive UX/UI thresholds for remanent cards: specify how exactly 6 hours and exactly 24 hours are classified, and add a distinct rule for expired remanents. Ensure the categories are mutually exclusive and collectively cover all remaining lifetimes.docs/01_product_definition/01_idea_inicial.md-3-9 (1)
3-9: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick winFix the table-of-contents anchors.
The six fragments contain accented characters and are reported as invalid by MD051. Use explicit ASCII anchors or normalized fragments so the links work reliably in rendered Markdown.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/01_product_definition/01_idea_inicial.md` around lines 3 - 9, Actualiza los seis enlaces del índice para usar anclas ASCII explícitas o fragmentos normalizados sin caracteres acentuados, manteniendo cada enlace apuntando a su sección correspondiente y resolviendo las advertencias MD051.Source: Linters/SAST tools
docs/02_architecture_design/03_restostock_design.md-8-19 (1)
8-19: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick winRepair the invalid table-of-contents fragments.
The generated anchors on these entries do not match the document headings, and markdownlint reports
MD051. Regenerate the fragments from the exact rendered heading IDs so navigation works.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/02_architecture_design/03_restostock_design.md` around lines 8 - 19, Update the table-of-contents links for sections 2, 2.1–2.4, 3, and 3.1–3.5 to use the exact anchors generated from their rendered headings, resolving all MD051 fragment errors while preserving the displayed link text and section order.Source: Linters/SAST tools
docs/03_governance_and_quality/07_restostock_security_strategy.md-53-55 (1)
53-55: 🔒 Security & Privacy | 🟡 Minor | ⚡ Quick winCall bcrypt output a hash, not encryption.
bcrypt provides one-way password hashing; it does not provide reversible encryption at rest. Rename this section/wording to avoid creating incorrect storage and key-management expectations.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/03_governance_and_quality/07_restostock_security_strategy.md` around lines 53 - 55, Update the “Cifrado a Nivel de Columna (Encryption at Rest)” wording to describe bcrypt as one-way hashing rather than encryption. Rename the section and its references to use hash terminology, while preserving the requirements for unique per-record salts and a minimum work factor of 10.docs/03_governance_and_quality/08_restostock_testing_strategy.md-65-72 (1)
65-72: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick winMake the canonical assertion example executable and contract-valid.
EXPIREDis not part of the documentedRemanenteStatusenum, andactionis undefined. Use a valid status such asDISCARDEDwhere appropriate and show a complete callable assertion.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/03_governance_and_quality/08_restostock_testing_strategy.md` around lines 65 - 72, Update the canonical assertion example in the testing strategy documentation to use a documented RemanenteStatus value such as DISCARDED instead of EXPIRED, and replace the undefined action reference with a complete callable assertion target that demonstrates toThrowError while preserving the intended error message.docs/02_architecture_design/03_restostock_design.md-136-139 (1)
136-139: 🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick winDo not call this model non-relational.
3NF, foreign keys, relational cardinalities, and
ON DELETEactions make this a relational database blueprint. Rename the section to “relational/database-agnostic” or remove the non-relational claim.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/02_architecture_design/03_restostock_design.md` around lines 136 - 139, Update the “Modelo de Datos Lógico/Físico Agnóstico” section heading and description to remove the claim that the blueprint is independent of relational and non-relational databases. Describe it as a relational or database-agnostic model consistent with its 3NF structure, foreign keys, cardinalities, and ON DELETE actions.
🧹 Nitpick comments (3)
docs/05_agile_planning/tickets/TK-007.md (1)
23-25: 🩺 Stability & Availability | 🔵 Trivial | ⚡ Quick winSpecify interval cleanup and the time invalidation mechanism.
useMemowill not recompute merely because time passes. Require a single mounted interval that updates a tick/dependency and is cleared on unmount; otherwise alerts can become stale or leak timers.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/05_agile_planning/tickets/TK-007.md` around lines 23 - 25, Actualiza la mitigación de alertas dinámicas para exigir un único setInterval mientras el componente esté montado, usando un tick/estado como dependencia que invalide el useMemo cada minuto; limpia el intervalo al desmontar mediante su función de cleanup para evitar alertas obsoletas y temporizadores filtrados.docs/05_agile_planning/tickets/TK-009.md (1)
21-23: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick winDefine the exact outcome for excessive variance.
“Alertar o requerir confirmación” leaves the API behavior ambiguous. Specify the threshold boundary, whether the reconciliation is rejected or held for approval, and the response/status when the 50% limit is exceeded.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/05_agile_planning/tickets/TK-009.md` around lines 21 - 23, Actualiza la sección “Validaciones de Varianza Críticas” para definir un comportamiento único ante varianzas excesivas: especifica si el límite del 50% es inclusivo, rechaza o deja pendiente de aprobación la reconciliación, y documenta la respuesta y el estado HTTP que debe devolver la API cuando se supera ese umbral.docs/05_agile_planning/tickets/TK-004.md (1)
21-23: 🚀 Performance & Scalability | 🔵 Trivial | ⚡ Quick winDo not equate
includewith one SQL query.Prisma relation loading may use separate batched queries depending on the configured strategy. If the requirement is specifically one query or a verified N+1 guarantee, define the chosen strategy and validate it with query logging/
EXPLAIN ANALYZErather than relying onincludealone.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/05_agile_planning/tickets/TK-004.md` around lines 21 - 23, Actualiza la mitigación de consultas N+1 en “Mitigación de Riesgos Técnicos” para no afirmar que `include: { insumo: true }` garantiza una sola consulta SQL. Define explícitamente la estrategia de carga de relaciones requerida y valida el comportamiento mediante logging de consultas y, si corresponde, `EXPLAIN ANALYZE`; conserva la verificación del índice `idx_remanente_fefo`.
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 761c989c-d8b6-41ac-9896-9de52f1e7005
📒 Files selected for processing (60)
.prompts/README.md.prompts/nuevas_ideas_cascada.md.prompts/skills/development/backend/.gitkeep.prompts/skills/development/devops_and_env/.gitkeep.prompts/skills/development/frontend/.gitkeep.prompts/skills/development/testing_and_qa/.gitkeep.prompts/skills/specs/01_product_definition/SK-01_product_discovery.md.prompts/skills/specs/01_product_definition/SK-02_prd_generation.md.prompts/skills/specs/02_architecture_design/SK-03_architecture_design.md.prompts/skills/specs/02_architecture_design/SK-04_mermaid_diagram.md.prompts/skills/specs/02_architecture_design/SK-05_hexagonal_layers.md.prompts/skills/specs/02_architecture_design/SK-06_folder_structure.md.prompts/skills/specs/03_governance_and_quality/SK-07_cicd_pipeline.md.prompts/skills/specs/03_governance_and_quality/SK-08_security_strategy.md.prompts/skills/specs/03_governance_and_quality/SK-09_testing_strategy.md.prompts/skills/specs/04_persistence_and_api/SK-10_prisma_schema.md.prompts/skills/specs/04_persistence_and_api/SK-11_api_specification.md.prompts/skills/specs/05_agile_planning/SK-12_user_stories.md.prompts/skills/specs/05_agile_planning/SK-13_backlog_tickets.md.prompts/skills/specs/05_agile_planning/SK-14_pull_requests.mdCHANGELOG.mddocs/01_product_definition/01_idea_inicial.mddocs/01_product_definition/02_restostock_prd.mddocs/01_product_definition/03_glosario_y_reglas_negocio.mddocs/02_architecture_design/03_restostock_design.mddocs/02_architecture_design/04_restostock_architecture_diagram.mddocs/02_architecture_design/05_restostock_components_description.mddocs/02_architecture_design/06_restostock_folder_structure.mddocs/03_governance_and_quality/07_restostock_security_strategy.mddocs/03_governance_and_quality/08_restostock_testing_strategy.mddocs/03_governance_and_quality/audit_report.mddocs/03_governance_and_quality/guia_redaccion_tecnica.mddocs/04_persistence_and_api/09_restostock_database_schema.mddocs/04_persistence_and_api/10_restostock_api_specification.mddocs/05_agile_planning/backlog_map.mddocs/05_agile_planning/matriz_trazabilidad.mddocs/05_agile_planning/tickets/TK-001.mddocs/05_agile_planning/tickets/TK-002.mddocs/05_agile_planning/tickets/TK-003.mddocs/05_agile_planning/tickets/TK-004.mddocs/05_agile_planning/tickets/TK-005.mddocs/05_agile_planning/tickets/TK-006.mddocs/05_agile_planning/tickets/TK-007.mddocs/05_agile_planning/tickets/TK-008.mddocs/05_agile_planning/tickets/TK-009.mddocs/05_agile_planning/tickets/TK-010.mddocs/05_agile_planning/tickets/indice_tickets.mddocs/05_agile_planning/user_stories/US-001.mddocs/05_agile_planning/user_stories/US-002.mddocs/05_agile_planning/user_stories/US-003.mddocs/05_agile_planning/user_stories/US-004.mddocs/05_agile_planning/user_stories/US-005.mddocs/05_agile_planning/user_stories/US-006.mddocs/05_agile_planning/user_stories/US-007.mddocs/05_agile_planning/user_stories/US-008.mddocs/05_agile_planning/user_stories/US-009.mddocs/05_agile_planning/user_stories/indice_user_stories.mddocs/README.mdprompts.mdreadme.md
🚧 Files skipped from review as they are similar to previous changes (3)
- .prompts/nuevas_ideas_cascada.md
- .prompts/README.md
- readme.md
Summary by CodeRabbit