Accept planning baseline and UC-001 artifacts
Add the Use Case Diagram, Domain Model (use case and project), Dictionary, Operation Contract, Sequence Diagram, review records RC-001 to RC-015 and the Traceability Matrix. Split US-001 into one story per milestone, make GitHub optional (AGPL license applied when chosen), and accept BC-001, SA-001, PP-001, UCD-001, US-001, UC-001, SSD-001, DM-001, DM-002, OC-001, SD-001, DICT-001 and MIL-001 to MIL-003 after review. Refs: no issues synced yet (sync-project.sh dry run only) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -9,7 +9,8 @@
|
||||
## Version History
|
||||
| Date | Status | Author | Reviewer | Change | Commit |
|
||||
| --- | --- | --- | --- | --- | --- |
|
||||
| 2026-10-05 | Proposed | Jens Tirsvad Nielsen | S02 | Initial version | [424f14f] |
|
||||
| 2026-10-05 | Deprecated | Jens Tirsvad Nielsen | S02 | Initial version | [424f14f] |
|
||||
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Optional GitHub; choosing GitHub applies the AGPL license to the Gitea repository<br>Cited US-001.01<br>Target date accepted | pending |
|
||||
|
||||
---
|
||||
|
||||
@@ -30,6 +31,7 @@ Decide whether the secure base of `create-project.sh` is sound enough to build t
|
||||
| 3 | No token appears in stdout, stderr or a log in any test, including failure paths | None found | Any found |
|
||||
| 4 | Missing `git` or `curl` stops the script before any change | Stops with a clear message | Continues |
|
||||
| 5 | `.env` is ignored by git; both example files contain placeholders only | Verified | Real value present |
|
||||
| 6 | All acceptance criteria of US-001.01 in [US-001] are met | Verified | Any unmet |
|
||||
|
||||
## Dependencies
|
||||
|
||||
@@ -41,6 +43,7 @@ Decide whether the secure base of `create-project.sh` is sound enough to build t
|
||||
|
||||
| Business Case objective / KPI / user story | Reference |
|
||||
| --- | --- |
|
||||
| User story US-001.01 | [US-001] |
|
||||
| Objective 6 (no credential exposure, no overwrite) | [BC-001] |
|
||||
| Success criteria 1 and 6 | [BC-001] |
|
||||
|
||||
@@ -53,7 +56,7 @@ Decide whether the secure base of `create-project.sh` is sound enough to build t
|
||||
|
||||
## Target Date
|
||||
|
||||
2026-10-16 — proposed; the Business Case sets no deadline.
|
||||
2026-10-16 — the Business Case sets no deadline, so it does not constrain this date; accepted together with PP-001.
|
||||
|
||||
## Tasks
|
||||
|
||||
@@ -63,7 +66,7 @@ Decide whether the secure base of `create-project.sh` is sound enough to build t
|
||||
| 2 | Script skeleton with strict mode and safe helpers | `set -Eeuo pipefail`, an ERR/EXIT trap, `mktemp` with `umask 077` and cleanup on exit, small single-purpose functions, logging helpers that redact known secret values, and no `rm -rf`. Follow the framework `coding-conventions` Shell rules. | No | |
|
||||
| 3 | Safe parser for config.env and .env | Read `KEY=VALUE` lines without `source` or `eval`; accept only whitelisted keys, strip optional quotes, reject control characters, and validate that service URLs are well-formed `https` and that credentials are non-empty. Warn when `.env` is readable by other users. | No | |
|
||||
| 4 | Tool check and HTTP helper | Check `git` and `curl` (and optional `jq`, with a fallback parser for the few JSON fields needed) before any change. Wrap `curl` so tokens go through a private curl config file or stdin rather than the command line (visible in process lists), with `--fail-with-body` handling, timeouts, and error messages that carry the HTTP status but never the credential. | No | |
|
||||
| 5 | Interactive prompts and input validation | Prompt for repository name, description, visibility and the owner or organization separately for GitHub and Gitea, with defaults taken from configuration. Validate names against both hosts' allowed characters. `GITHUB_USER` is only the authenticating account and is never assumed to be the owner. | Yes | [UC-001] |
|
||||
| 5 | Interactive prompts and input validation | Prompt for repository name, description, visibility, whether to also create a GitHub repository (which also applies the AGPL license to the Gitea repository), and the owner or organization separately for Gitea and (if chosen) GitHub, with defaults taken from configuration. Validate names against both hosts' allowed characters. `GITHUB_USER` is only the authenticating account and is never assumed to be the owner. | Yes | [UC-001] |
|
||||
| 6 | .gitignore and test harness | Add `.env` and temporary files to `.gitignore`. Add a test harness with stubbed `curl` and `git` that covers parser rejection cases and the no-token-in-output check, run alongside `shellcheck`. | No | |
|
||||
|
||||
---
|
||||
|
||||
Reference in New Issue
Block a user