Step 1Find the risky paths
Auth, money, data access, parsing, crypto and external input.
ATALAIAWhich code moves points or checks who you are?
DEV LEADredeem(), the ledger client and the partner callback parser.
ATALAIAThose always get a human review. The scanners take the rest.
Leaves the roomRisky paths: auth, redeem, ledger, parser
Step 2Read the diffs
Line by line, with the threat model next to the code.
ATALAIAIn redeem(), the balance check runs, then the write. Nothing in between.
DEVELOPERIt's fast, though. Can two requests really land together?
ATALAIAEasily, with a script. Two threads, one balance, two vouchers.
Leaves the roomPR #318: 214 lines read
Step 3Comment where devs work
Findings land as PR comments with a suggested fix.
ATALAIAThe fix is in the PR as a suggestion: one conditional debit.
DEVELOPERApplied. My test with two parallel redeems now fails one of them.
Leaves the room3 PR comments, 1 suggested fix
Step 4Teach the pattern
Checklists and pairing so the next review needs us less.
DEV LEADCan we turn this into a checklist for the senior devs?
ATALAIAEight checks for money paths. Next review you lead, and I watch.
Leaves the roomChecklist: 8 checks for money paths
- ATALAIA
- DEV LEAD
- DEVELOPER
- DEVELOPER 2
- DEVELOPER 3