用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/lukemcqueen/hermes-cortex --skill role-gating-and-public-moderation命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
正在显示 SKILL.md
| name | role-gating-and-public-moderation |
| description | Role gating, PII tiers, and UGC moderation patterns. |
| version | 1.0.0 |
| category | software-development |
| platforms | ["linux","macos"] |
Patterns for a multi-role product with an anonymous/public surface plus
privileged surfaces (admin/editor) and user-submitted public content
(directory/listings/reviews). Distilled from the Example church-directory +
prayer-warrior build; see references/fastapi-example.md for the concrete
FastAPI implementation.
{register} endpoint must force role = seeker and ignore any
client-supplied role. Drop the role field from the request schema entirely
so a malicious payload is silently dropped by the validator.register({role:"admin"}) →
login → /auth/me returns role == seeker, and that account is 403 on
every privileged surface.role still seeker — NO privileged
access until an owner approves.warrior_status pending | approved). The role is
promoted only on approval (role → warrior, status → approved).ensure_user(session, email, pw, role, force_role=True) +
commit), then login normally. The same helper powers the seed script.forbidden not in entry for email/status/flags).status = pending, hidden from the
public. Only status == approved appears publicly.pending → approved | rejected | needs_info. Owner review
endpoint sets status + review notes + an optional harm/abuse flag.rejected + flagged. Flagged
entries are NEVER public, even if later approved by mistake.approved/public; only anonymous submissions enter the review queue.help_url so submitters are offered help, not just rejection.When adding a second dependency function next to an existing one (e.g. add
get_current_admin below get_current_evangelist), a replace-style patch can
accidentally consume the first function's trailing return user, so it falls
through and returns None — turning every gated endpoint into a 500. After any
such edit, confirm the ORIGINAL function still ends in return user (or run
the suite; the data-domain tests will catch it as 500s while auth tests pass).
Run the full API test suite (auth + RBAC + moderation) and assert: