1@README.md 2 3- **`#![forbid(unsafe_code)]` holds through pgrx's macros; keep it.** 4 Anything that needs `unsafe` goes in `postjevsql-pg` behind a safe API. 5- **`jev.endpoint` stays superuser-only: whoever sets it receives the API 6 key.** The same goes for `jev.api_key_file` (whose account pays), 7 `jev.dns_servers` (where names point) and `jev.price_per_mtok` (what spend 8 is reckoned from). 9- **The control file's version is `@CARGO_VERSION@`, filled from 10 `build/defs.bzl`.** Never write a version here. 11- **A SQL function's body only refuses** (`Failure::Unbatched`). The scan 12 answers every call it claims; never give a body real work, or a call the 13 scan missed would send one request per row. 14- **A new function is three edits that must agree:** its `#[pg_extern]`, its 15 entry in `JevScan::FUNCTIONS`, and a `REVOKE` line in 16 `revoke_from_public` (`tests/privileges.rs` fails on a function left 17 executable by PUBLIC). `TREE_FUNCTIONS` and `SHORTLIST_FUNCTIONS` are 18 indexes into `FUNCTIONS`, so inserting an entry before them shifts them.