Fix the defects found by the live end-to-end run, add RC-017

- Close stdin for ssh, git, curl and the framework scripts, so a real ssh
  no longer swallows answers meant for later prompts.
- Count LICENSE and LICENSE + README.md (what Gitea creates) as content
  the script made, so a partly created repository can be reused.
- Document the observed token scopes (write:user for user-owned Gitea
  repositories) and the Gitea README.md in the README.
- Correct criterion 2 of MIL-002 (new Proposed version row).
- Record the run and the final security review as RC-017.
- Tests: stdin regression, initial_only reuse, other files count as
  content, example config needs its address edited.

Task: MIL-003#6
Task: MIL-002#1
Refs #20

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-10-05 21:41:47 +08:00
co-authored by Claude Sonnet 5.5
parent 0030334e5e
commit 613a288dea
13 changed files with 203 additions and 33 deletions
+12 -1
View File
@@ -158,10 +158,21 @@ test_example_files_hold_placeholders_only() {
fail ".env.example has a value for ${line%%=*}; it must be empty"
fi
done < <(grep -E '^[A-Z_]+=' "$REPO_ROOT/.env.example")
# The example holds a placeholder for the Gitea address, so it must be
# edited before use: as it is, it is refused with a clear message...
run_lib "" "parse_env_file \"$REPO_ROOT/config.env.example\" CONFIG_KEYS CONFIG
validate_config
echo parsed"
assert_contains "config.env.example is valid" "$OUT" "parsed"
assert_status "placeholder address is refused" 1 "$STATUS"
assert_contains "names the key" "$ERR" "GITEA_URL"
# ...and with a real address in its place the rest of the file is valid.
sed -e 's|^GITEA_URL=.*|GITEA_URL=https://git.example.test/|' \
-e 's|^GITEA_API_URL=.*|GITEA_API_URL=https://git.example.test/api/v1|' \
"$REPO_ROOT/config.env.example" >"$WORK/example.env"
run_lib "" "parse_env_file \"$WORK/example.env\" CONFIG_KEYS CONFIG
validate_config
echo parsed"
assert_contains "config.env.example is valid once the address is set" "$OUT" "parsed"
run_lib "" "parse_env_file \"$REPO_ROOT/.env.example\" CREDENTIAL_KEYS CREDENTIALS
echo parsed"
assert_contains ".env.example parses" "$OUT" "parsed"