--- title: 校正:AI 整理的待办清单有虚构项,开工前先核实 type: experience permalink: main/projects/d5a7f581-c442-4554-87b9-ee723b8b0258/校正-ai-整理的待办清单有虚构项开工前先核实 stable_id: e53bcaef-4e7c-4bd7-b480-783f864c5a1f scope: project project_id: d5a7f581-c442-4554-87b9-ee723b8b0258 memory_type: experience status: active revision: 1 restored_from_commit: 6a6a895eafcca6052e81a14fca103a42635dd1c2 created_at: '2026-09-23T15:10:29.256494+00:00' updated_at: '2026-09-23T15:10:29.256554+00:00' tags: - backlog - curation - pitfall - audit --- 2026-08-28 核实了 curated/maintenance 与 curated/troubleshooting 里的具体技术待办,四条中三条不成立(整理模型推测产物,不要再花时间追):1) “core/config.py 缺 api_enabled 导致 forbidden”——假,实际 server/app/services/settings.py 已完整实现 SETTING_API_ENABLED(默认 True,可在系统设置配)。2) “scripts/create-module.mjs 存在 ___SNAKE___snapshot 拼写错误”——假,占位符是 `__SNAKE__`,`___SNAKE___snapshot` 渲染后为私有函数 `__snapshot`,是有意设计。3) “pytest.ini 指向空测试目录”——假,server/tests 下有 7 个 test_*.py(auth_rbac/containers/database/frontend/pypi/scripts/storage)。4) “scripts/pypi_mirror.py 硬编码凭证”——真,第 27 行 SERVER_PASSWORD 存明文服务器密码,应改为从环境变量或密码库读取。经验:curated 文档里的“待办/问题”只能当线索,涉及代码的一定先 grep 核实再动手;以 checkpoint 和人写 memory 为准。