Plan MIL-005: ask for missing credentials and create the project .env
Add objective 9 to the Business Case (and amend objective 6 and success criterion 1: a token may be written only to the new project's .env after a yes), US-001.05, UC-001 extensions 2b, 9c and 9d, with the SSD, OC, SD, DM-001, DM-002 and dictionary in step. Add the classes CredentialCollector, EnvFileWriter and EnvFile to DCD-001 and DCD-002, and both ends' multiplicities to every association. Restore three lines of SD-001 damaged by an earlier edit. Add milestone MIL-005 (9 Go/No-Go criteria, 5 tasks) and its phase in the Project Plan. Accept the planning set and the two DCDs; reviews recorded in RC-020 and RC-021. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
+56
-33
@@ -9,7 +9,8 @@
|
||||
## Version History
|
||||
| Date | Status | Author | Reviewer | Change | Commit |
|
||||
| --- | --- | --- | --- | --- | --- |
|
||||
| 2026-10-06 | Proposed | Jens Tirsvad Nielsen | S02 | Initial version | [f4d611b] |
|
||||
| 2026-10-06 | Deprecated | Jens Tirsvad Nielsen | S02 | Initial version | [f4d611b] |
|
||||
| 2026-10-06 | Accepted | Jens Tirsvad Nielsen | S02 | Added CredentialCollector, EnvFileWriter and EnvFile; writeEnvFile parameter | pending |
|
||||
|
||||
---
|
||||
|
||||
@@ -35,11 +36,17 @@ enum Visibility {
|
||||
|
||||
class ProjectCreator <<controller>> {
|
||||
+startProjectCreation() : PromptSet
|
||||
+provideProjectDetails(name : String, description : String, visibility : Visibility, giteaOwner : Owner, githubOwner : Owner [0..1], directory : Path, enablePlanGate : Boolean) : Summary
|
||||
+provideProjectDetails(name : String, description : String, visibility : Visibility, giteaOwner : Owner, githubOwner : Owner [0..1], directory : Path, enablePlanGate : Boolean, writeEnvFile : Boolean) : Summary
|
||||
}
|
||||
class ConfigLoader {
|
||||
+load(configFile : Path, envFile : Path) : Configuration
|
||||
}
|
||||
class CredentialCollector {
|
||||
+collect(configuration : Configuration, kinds : String [1..3]) : Configuration
|
||||
}
|
||||
class EnvFileWriter {
|
||||
+write(project : LocalProject, configuration : Configuration, hasGithub : Boolean) : EnvFile [0..1]
|
||||
}
|
||||
class ToolChecker {
|
||||
+check(tools : String [1..*]) : ToolCheck
|
||||
}
|
||||
@@ -149,6 +156,10 @@ class HookSetup {
|
||||
-areHooksInstalled : Boolean
|
||||
-isPlanGateEnabled : Boolean
|
||||
}
|
||||
class EnvFile {
|
||||
-address : Path
|
||||
-keys : String [1..3]
|
||||
}
|
||||
class Template {
|
||||
-name : String
|
||||
-isCopied : Boolean
|
||||
@@ -162,6 +173,8 @@ class Summary {
|
||||
|
||||
ProjectCreator ..> ConfigLoader : creates
|
||||
ProjectCreator ..> ToolChecker : creates
|
||||
ProjectCreator ..> CredentialCollector : creates
|
||||
ProjectCreator ..> EnvFileWriter : creates [0..1]
|
||||
ProjectCreator ..> Preflight : creates
|
||||
ProjectCreator ..> GiteaClient : creates
|
||||
ProjectCreator ..> GitHubClient : creates [0..1]
|
||||
@@ -176,40 +189,42 @@ GitHost "1" --> "0..*" Owner : has
|
||||
GiteaClient ..> Configuration
|
||||
GitHubClient ..> Configuration
|
||||
|
||||
ProjectCreator --> "1" Run
|
||||
Run *-- "1" Configuration
|
||||
Run *-- "1" ToolCheck
|
||||
Run *-- "0..1" ProjectRequest
|
||||
Run --> "1" PromptSet : returns
|
||||
Configuration *-- "1..2" Credential
|
||||
ProjectCreator "0..*" --> "1" Run
|
||||
Run "1" *-- "1" Configuration
|
||||
Run "1" *-- "1" ToolCheck
|
||||
Run "1" *-- "0..1" ProjectRequest
|
||||
Run "1" --> "1" PromptSet : returns
|
||||
Configuration "1" *-- "1..3" Credential
|
||||
|
||||
ProjectRequest --> "1" Owner : giteaOwner
|
||||
ProjectRequest --> "0..1" Owner : githubOwner
|
||||
ProjectRequest *-- "0..1" PreflightResult
|
||||
ProjectRequest --> "0..1" GiteaRepository : stored in
|
||||
ProjectRequest --> "0..1" GitHubRepository : also stored in
|
||||
ProjectRequest --> "0..1" LocalProject : working copy
|
||||
Summary --> "1" ProjectRequest : reports on
|
||||
ProjectRequest "0..*" --> "1" Owner : giteaOwner
|
||||
ProjectRequest "0..*" --> "0..1" Owner : githubOwner
|
||||
ProjectRequest "1" *-- "0..1" PreflightResult
|
||||
ProjectRequest "1" --> "0..1" GiteaRepository : stored in
|
||||
ProjectRequest "1" --> "0..1" GitHubRepository : also stored in
|
||||
ProjectRequest "1" --> "0..1" LocalProject : working copy
|
||||
Summary "0..*" --> "1" ProjectRequest : reports on
|
||||
|
||||
Repository <|-- GiteaRepository
|
||||
Repository <|-- GitHubRepository
|
||||
Repository --> "1" Owner : owned by
|
||||
GiteaRepository *-- "0..1" LicenseFile
|
||||
PushMirror --> "1" GiteaRepository : source
|
||||
PushMirror --> "1" GitHubRepository : target
|
||||
PushMirror --> "1" Credential : authorised by
|
||||
Repository "0..*" --> "1" Owner : owned by
|
||||
GiteaRepository "1" *-- "0..1" LicenseFile
|
||||
PushMirror "0..*" --> "1" GiteaRepository : source
|
||||
PushMirror "0..*" --> "1" GitHubRepository : target
|
||||
PushMirror "0..*" --> "1" Credential : authorised by
|
||||
|
||||
LocalProject *-- "1..2" Remote
|
||||
Remote --> "1" Repository : points to
|
||||
LocalProject *-- "1" Submodule
|
||||
LocalProject *-- "1" HookSetup
|
||||
LocalProject *-- "0..*" Template
|
||||
InstallResult --> "1" Submodule
|
||||
InstallResult --> "1" HookSetup
|
||||
InstallResult --> "0..*" Template
|
||||
LocalProject "1" *-- "1..2" Remote
|
||||
Remote "0..*" --> "1" Repository : points to
|
||||
LocalProject "1" *-- "1" Submodule
|
||||
LocalProject "1" *-- "1" HookSetup
|
||||
LocalProject "1" *-- "0..*" Template
|
||||
LocalProject "1" *-- "0..1" EnvFile
|
||||
EnvFile "0..*" --> "1..3" Credential : copy of
|
||||
InstallResult "0..*" --> "1" Submodule
|
||||
InstallResult "0..*" --> "1" HookSetup
|
||||
InstallResult "0..*" --> "0..*" Template
|
||||
|
||||
ProjectRequest --> Visibility
|
||||
Repository --> Visibility
|
||||
ProjectRequest "0..*" --> "1" Visibility
|
||||
Repository "0..*" --> "1" Visibility
|
||||
@enduml
|
||||
```
|
||||
|
||||
@@ -219,6 +234,8 @@ Repository --> Visibility
|
||||
| --- | --- | --- | --- | --- |
|
||||
| `ProjectCreator` | none (controller for the system operations of [OC-001]) | Receives the two system operations, sequences the steps and stops on the first failure. | none | `startProjectCreation`, `provideProjectDetails` |
|
||||
| `ConfigLoader` | Configuration | Reads `config.env` and `.env` as plain text and validates every value, preset project details included. | none | `load` |
|
||||
| `CredentialCollector` | none (system concept) | Asks, without echo, for a credential that `.env` does not provide and validates it like one read from `.env`. | none | `collect` |
|
||||
| `EnvFileWriter` | Credentials File | Creates the project's own `.env` with the credentials the project needs: owner-only, excluded from git, never replaced without a yes. | none | `write` |
|
||||
| `ToolChecker` | none (system concept `ToolCheck`) | Detects the required and optional tools. | none | `check` |
|
||||
| `Preflight` | none (system concept `PreflightResult`) | Runs the read-only checks of both hosts before anything is created. | none | `check` |
|
||||
| `GitHost` | Git Host | The operations every host offers: check the token, check that an owner accepts new repositories, check that a name is free. | `name`, `webAddress`, `apiAddress` | `verifyToken`, `ownerAccepts`, `nameFree` |
|
||||
@@ -244,6 +261,7 @@ Repository --> Visibility
|
||||
| `Remote` | Remote | A named link to a repository (`origin`, `github`), without a credential. | `name`, `address` | none |
|
||||
| `Submodule` | Framework | The framework added to the local project. | `name`, `address` | none |
|
||||
| `HookSetup` | Framework Setup | Records the skills and hooks installed and the plan gate state. | `areSkillsInstalled`, `areHooksInstalled`, `isPlanGateEnabled` | none |
|
||||
| `EnvFile` | Credentials File | The `.env` of the project: a copy of the credentials it needs. | `address`, `keys` | none |
|
||||
| `Template` | Template | A framework file copied into the project. | `name`, `isCopied` | none |
|
||||
| `InstallResult` | none (carries the result of one operation) | Returns the submodule, the hook setup and the templates of `install`. | none | none |
|
||||
| `Summary` | Summary | The report returned to the Maintainer; it contains no credential. | `createdItems`, `skippedItems`, `nextSteps` | none |
|
||||
@@ -254,8 +272,10 @@ Repository --> Visibility
|
||||
| Method signature | Operation Contract / SD message |
|
||||
| --- | --- |
|
||||
| `ProjectCreator.startProjectCreation() : PromptSet` | [OC-001] `startProjectCreation`; [SD-001] `startProjectCreation()` |
|
||||
| `ProjectCreator.provideProjectDetails(name, description, visibility, giteaOwner, githubOwner, directory, enablePlanGate) : Summary` | [OC-001] `provideProjectDetails`; [SD-001] `provideProjectDetails(...)` |
|
||||
| `ProjectCreator.provideProjectDetails(name, description, visibility, giteaOwner, githubOwner, directory, enablePlanGate, writeEnvFile) : Summary` | [OC-001] `provideProjectDetails`; [SD-001] `provideProjectDetails(...)` |
|
||||
| `ConfigLoader.load(configFile, envFile) : Configuration` | [SD-001] `load(config.env, .env)`; [OC-001] `startProjectCreation` P2 |
|
||||
| `CredentialCollector.collect(configuration, kinds) : Configuration` | [SD-001] `collect(configuration, GITEA_TOKEN)` and `collect(configuration, GITHUB_PAT, GITHUB_USER)`; [OC-001] `startProjectCreation` P2 and the precondition of `provideProjectDetails` |
|
||||
| `EnvFileWriter.write(project, configuration, hasGithub) : EnvFile` | [SD-001] `write(localProject, configuration, githubOwner present)`; [OC-001] `provideProjectDetails` P14 |
|
||||
| `ToolChecker.check(tools) : ToolCheck` | [SD-001] `check(git, curl, jq)`; [OC-001] `startProjectCreation` P3 |
|
||||
| `Preflight.check(request) : PreflightResult` | [SD-001] `check(request)`; [OC-001] `provideProjectDetails` P2 |
|
||||
| `GiteaClient(configuration)` | [SD-001] `new(configuration)` to `GiteaClient` |
|
||||
@@ -278,14 +298,14 @@ Repository --> Visibility
|
||||
| --- | --- | --- |
|
||||
| Controller (GRASP) | `ProjectCreator` | One entry for the system operations; coordinates and does no HTTP, git or file work itself |
|
||||
| Facade (GoF) | `GitHost`, `GiteaClient`, `GitHubClient` | Each client hides one host's HTTP API and keeps the token inside; no other class sees a credential. `GitHost` holds the operations both share |
|
||||
| Pure Fabrication (GRASP) | `ConfigLoader`, `ToolChecker`, `Preflight`, `LocalProjectBuilder`, `FrameworkInstaller`, `SummaryReport` | No domain concept owns these responsibilities; small units keep cohesion high |
|
||||
| Pure Fabrication (GRASP) | `ConfigLoader`, `ToolChecker`, `CredentialCollector`, `EnvFileWriter`, `Preflight`, `LocalProjectBuilder`, `FrameworkInstaller`, `SummaryReport` | No domain concept owns these responsibilities; small units keep cohesion high |
|
||||
| Creator (GRASP) | `ConfigLoader` creates `Configuration`; `GiteaClient` creates `GiteaRepository` and `PushMirror` | The creating class holds the data needed to build the object |
|
||||
| Protection from variations (GRASP) | `GiteaClient`, `GitHubClient`, `ProjectRequest` | The optional GitHub path is decided by the controller; the clients do not know it |
|
||||
| Data Transfer Object (GoF-style) | `InstallResult` | Carries the three results of `install` in one return value |
|
||||
|
||||
## Dependency Check
|
||||
|
||||
No circular dependency. `ProjectCreator` depends on every helper class and no helper depends on it. `Preflight` depends on the two clients; the clients extend `GitHost` and depend only on `Configuration`. The data classes form a tree: `Run` holds `Configuration`, `ToolCheck` and `ProjectRequest`; `ProjectRequest` reaches the repositories and the `LocalProject`; `Summary` points at `ProjectRequest` and nothing points back at it. `Repository` is shared by `Remote` and `PushMirror` without a cycle.
|
||||
No circular dependency. `ProjectCreator` depends on every helper class and no helper depends on it. `Preflight` depends on the two clients; the clients extend `GitHost` and depend only on `Configuration`. The data classes form a tree: `Run` holds `Configuration`, `ToolCheck` and `ProjectRequest`; `ProjectRequest` reaches the repositories and the `LocalProject`; `Summary` points at `ProjectRequest` and nothing points back at it. `CredentialCollector` and `EnvFileWriter` depend only on `Configuration`, `Credential` and `LocalProject`; the only class that holds a secret after the run is `EnvFile`, and only as a copy written to the Maintainer's own disk. `Repository` is shared by `Remote` and `PushMirror` without a cycle.
|
||||
|
||||
SOLID check: no class has more than one reason to change (one host API, one kind of local work, one report); the clients can be replaced behind the same operations; the controller depends on the operations, not on how a host or git is called. `ProjectCreator` has two operations and no data, so it is not a god class.
|
||||
|
||||
@@ -296,6 +316,8 @@ SOLID check: no class has more than one reason to change (one host API, one kind
|
||||
| `ProjectCreator` | `create-project.sh` (`main`), `lib/apply.sh` |
|
||||
| `ConfigLoader` | `lib/config.sh` (`load_configuration`), `lib/validate.sh` |
|
||||
| `ToolChecker` | `lib/tools.sh` |
|
||||
| `CredentialCollector` | planned for [MIL-005]: `lib/credentials.sh`, with `lib/prompts.sh` |
|
||||
| `EnvFileWriter` | planned for [MIL-005]: `lib/envfile.sh` |
|
||||
| `Preflight` | `lib/preflight.sh` |
|
||||
| `GitHost`, `GiteaClient`, `GitHubClient` | `lib/api.sh`, `lib/http.sh`, `lib/json.sh`, `lib/repositories.sh`, `lib/mirror.sh`, `lib/hosts.sh` |
|
||||
| `LocalProjectBuilder` | `lib/localproject.sh`, `lib/git.sh` |
|
||||
@@ -311,6 +333,7 @@ SOLID check: no class has more than one reason to change (one host API, one kind
|
||||
[DM-002]: ../domain-model.md
|
||||
[OC-001]: ./oc.md
|
||||
[SD-001]: ./sd.md
|
||||
[MIL-005]: ../milestones/mil-005-credentials.md
|
||||
[DICT-001]: ../dictionary.md
|
||||
[DCD-002]: ../dcd.md
|
||||
[f4d611b]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/f4d611b77cc70b4686506d44bf8f439045d9e0d2
|
||||
|
||||
+10
-3
@@ -9,8 +9,8 @@
|
||||
## Version History
|
||||
| Date | Status | Author | Reviewer | Change | Commit |
|
||||
| --- | --- | --- | --- | --- | --- |
|
||||
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Initial version | [02875ae] |
|
||||
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Configuration may hold preset project details | [2a6bb8e] |
|
||||
| 2026-10-05 | Deprecated | Jens Tirsvad Nielsen | S02 | Configuration may hold preset project details | [2a6bb8e] |
|
||||
| 2026-10-06 | Accepted | Jens Tirsvad Nielsen | S02 | Added Credentials File (a Local Project may have one) | pending |
|
||||
|
||||
---
|
||||
|
||||
@@ -79,6 +79,9 @@ class "Framework Setup" as FrameworkSetup {
|
||||
class Template {
|
||||
name
|
||||
}
|
||||
class "Credentials File" as CredentialsFile {
|
||||
address
|
||||
}
|
||||
class Summary {
|
||||
created items
|
||||
skipped items
|
||||
@@ -108,6 +111,8 @@ LocalProject "1" --> "1" FrameworkSetup : has
|
||||
FrameworkSetup "0..*" --> "1" Framework : is installed from
|
||||
Framework "1" --> "1..*" Template : provides
|
||||
LocalProject "1" --> "0..*" Template : contains a copy of
|
||||
LocalProject "1" --> "0..1" CredentialsFile : has
|
||||
CredentialsFile "1" --> "1..2" AccessToken : holds a copy of
|
||||
Summary "1" --> "1" Project : reports on
|
||||
@enduml
|
||||
```
|
||||
@@ -132,6 +137,7 @@ Summary "1" --> "1" Project : reports on
|
||||
| Framework | The SQA-QC-Framework added to a Local Project | name, address | [UC-001] step 9 "framework submodule" |
|
||||
| Framework Setup | The skills and git hooks installed from the Framework, with the plan gate on or off | plan gate enabled | [UC-001] step 9 "skills and hooks", "plan gate" |
|
||||
| Template | A file the Framework provides to copy into a project (`AGENTS.md`, artifact registry) | name | [UC-001] step 9 "templates" |
|
||||
| Credentials File | The file in a Local Project that holds a copy of the Access Tokens (and the GitHub account name) the project needs; readable by its owner only and ignored by git | address | [UC-001] step 9 "credentials file" |
|
||||
| Summary | The report of what was created, skipped or failed and how to continue | created items, skipped items, next steps | [UC-001] step 10 "summary" |
|
||||
|
||||
## Association Table
|
||||
@@ -158,6 +164,8 @@ Summary "1" --> "1" Project : reports on
|
||||
| Framework Setup | is installed from | Framework | 0..* to 1 |
|
||||
| Framework | provides | Template | 1 to 1..* |
|
||||
| Local Project | contains a copy of | Template | 1 to 0..* |
|
||||
| Local Project | has | Credentials File | 1 to 0..1 |
|
||||
| Credentials File | holds a copy of | Access Token | 1 to 1..2 |
|
||||
| Summary | reports on | Project | 1 to 1 |
|
||||
|
||||
## Generalizations
|
||||
@@ -172,5 +180,4 @@ Summary "1" --> "1" Project : reports on
|
||||
[SSD-001]: ./ssd.md
|
||||
[DICT-001]: ../dictionary.md
|
||||
[DM-002]: ../domain-model.md
|
||||
[02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a
|
||||
[2a6bb8e]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/2a6bb8e8afadfe6ca4a621da30e44a372898ca62
|
||||
|
||||
+10
-7
@@ -9,8 +9,8 @@
|
||||
## Version History
|
||||
| Date | Status | Author | Reviewer | Change | Commit |
|
||||
| --- | --- | --- | --- | --- | --- |
|
||||
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Initial version | [02875ae] |
|
||||
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Project details may be defined by the Configuration | [2a6bb8e] |
|
||||
| 2026-10-05 | Deprecated | Jens Tirsvad Nielsen | S02 | Project details may be defined by the Configuration | [2a6bb8e] |
|
||||
| 2026-10-06 | Accepted | Jens Tirsvad Nielsen | S02 | Credentials asked when missing; EnvFile created in the local project (P14); writeEnvFile parameter | pending |
|
||||
|
||||
---
|
||||
|
||||
@@ -31,7 +31,7 @@ Concepts below use the IT terms of [DICT-001] for the PO concepts of [DM-001]. `
|
||||
**Postconditions**
|
||||
|
||||
- P1. A `Run` instance was created.
|
||||
- P2. A `Configuration` instance was created from `config.env` and `.env`, with every value validated (including the project details preset in `config.env`) and the credentials held only in memory.
|
||||
- P2. A `Configuration` instance was created from `config.env` and `.env`, with every value validated (including the project details preset in `config.env`). A `Credential` that `.env` did not provide was entered by the Maintainer without echo and validated; every `Credential` is held only in memory.
|
||||
- P3. A `ToolCheck` instance was created and associated with the `Run`, recording that `git` and `curl` are present and whether `jq` is present.
|
||||
- P4. The `Run` was associated with a `PromptSet` that is returned.
|
||||
|
||||
@@ -39,21 +39,23 @@ Concepts below use the IT terms of [DICT-001] for the PO concepts of [DM-001]. `
|
||||
|
||||
| Condition (failing precondition) | Outcome |
|
||||
| --- | --- |
|
||||
| `config.env` or `.env` is missing, or a value is missing or malformed (a preset project detail included) | The `Run` ends with an error naming the key, never its value; nothing was changed |
|
||||
| `config.env` is missing, or a value in `config.env` or `.env` is malformed (a preset project detail included) | The `Run` ends with an error naming the key, never its value; nothing was changed |
|
||||
| A `Credential` is missing and input ends before a valid one is entered | The `Run` ends with an error naming the key; nothing was changed |
|
||||
| `git` or `curl` is missing | The `Run` ends with an error naming the tool; nothing was changed |
|
||||
|
||||
## Contract: provideProjectDetails
|
||||
|
||||
| Item | Value |
|
||||
| --- | --- |
|
||||
| Operation | `provideProjectDetails(name: String, description: String, visibility: Visibility, giteaOwner: Owner, githubOwner: Owner [0..1], directory: Path, enablePlanGate: Boolean): Summary` |
|
||||
| Operation | `provideProjectDetails(name: String, description: String, visibility: Visibility, giteaOwner: Owner, githubOwner: Owner [0..1], directory: Path, enablePlanGate: Boolean, writeEnvFile: Boolean): Summary` |
|
||||
| Traces to | `provideProjectDetails` in [SSD-001] |
|
||||
| Concepts | ProjectRequest, PreflightResult, GiteaRepository, GitHubRepository, LicenseFile, PushMirror, LocalProject, Remote, Submodule, HookSetup, Summary |
|
||||
| Concepts | ProjectRequest, PreflightResult, GiteaRepository, GitHubRepository, LicenseFile, PushMirror, LocalProject, Remote, Submodule, HookSetup, EnvFile, Summary |
|
||||
|
||||
**Preconditions**
|
||||
|
||||
- A `Run` exists and its `Configuration` is valid (from `startProjectCreation`).
|
||||
- `githubOwner` is present exactly when the Maintainer chose GitHub.
|
||||
- When `githubOwner` is present, the GitHub `Credential`s are known: from `.env`, or entered by the Maintainer without echo and validated before the first request.
|
||||
- A detail that the `Configuration` defines is not asked: it is taken from the `Configuration`.
|
||||
|
||||
**Postconditions**
|
||||
@@ -71,6 +73,7 @@ Concepts below use the IT terms of [DICT-001] for the PO concepts of [DM-001]. `
|
||||
- P11. A `HookSetup` instance was associated with the `LocalProject`, recording that skills and git hooks were installed once and, if `enablePlanGate`, that the plan gate was enabled.
|
||||
- P12. `AGENTS.md` and `docs/artifact-registry.md` exist in the `LocalProject`, each either newly copied from the framework templates or left as it was because the Maintainer declined to replace it.
|
||||
- P13. A `Summary` instance was created listing every created item, every skipped item and the next step for anything that failed, and is returned. It contains no credential.
|
||||
- P14. If `writeEnvFile`, an `EnvFile` named `.env` was associated with the `LocalProject`, holding only the `Credential`s the project needs (the Gitea token, and the GitHub token and account name when `githubOwner` is present). It is readable by its owner only and excluded from git without a change to any tracked file, and no `Credential` is shown in any output. If `writeEnvFile` is false, no `EnvFile` was created. An existing `.env` is left as it was unless the Maintainer agreed to replace it.
|
||||
|
||||
**Exceptions**
|
||||
|
||||
@@ -81,6 +84,7 @@ Concepts below use the IT terms of [DICT-001] for the PO concepts of [DM-001]. `
|
||||
| `GiteaRepository` creation fails after a `GitHubRepository` was created (P5, P3 ordering) | The `Summary` lists the `GitHubRepository` as created, the `GiteaRepository` as failed and how to continue |
|
||||
| `PushMirror` creation fails (P6) | The `Summary` lists both repositories as created, the mirror as failed and how to continue; the local steps are not run |
|
||||
| `directory` exists, or a target file exists, and the Maintainer declines replacing it (P7, P12) | That item is skipped and listed in the `Summary` |
|
||||
| A `.env` already exists in the `LocalProject` and the Maintainer declines replacing it (P14) | That item is skipped and listed in the `Summary` |
|
||||
| A different `core.hooksPath` exists and the Maintainer declines replacing it (P11) | Hooks are not installed and this is listed in the `Summary` |
|
||||
| SSH to port 10022 fails and the `Submodule` cannot be added (P10) | The `Summary` lists the repositories as created, the submodule as failed, and the SSH prerequisite |
|
||||
|
||||
@@ -90,5 +94,4 @@ Concepts below use the IT terms of [DICT-001] for the PO concepts of [DM-001]. `
|
||||
[DM-001]: ./dm.md
|
||||
[DICT-001]: ../dictionary.md
|
||||
[SD-001]: ./sd.md
|
||||
[02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a
|
||||
[2a6bb8e]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/2a6bb8e8afadfe6ca4a621da30e44a372898ca62
|
||||
|
||||
+39
-11
@@ -9,8 +9,8 @@
|
||||
## Version History
|
||||
| Date | Status | Author | Reviewer | Change | Commit |
|
||||
| --- | --- | --- | --- | --- | --- |
|
||||
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Note: preset project details are read by ConfigLoader | [2a6bb8e] |
|
||||
| 2026-10-06 | Proposed | Jens Tirsvad Nielsen | S02 | Messages aligned with the method signatures of DCD-001<br>Cited DCD-001 | [f4d611b] |
|
||||
| 2026-10-06 | Deprecated | Jens Tirsvad Nielsen | S02 | Messages aligned with the method signatures of DCD-001<br>Cited DCD-001 | [f4d611b] |
|
||||
| 2026-10-06 | Accepted | Jens Tirsvad Nielsen | S02 | Added CredentialCollector and EnvFileWriter and their messages (P2, P14) | pending |
|
||||
|
||||
---
|
||||
|
||||
@@ -28,6 +28,7 @@ actor Maintainer
|
||||
participant ":ProjectCreator" as PC
|
||||
participant ":ConfigLoader" as CL
|
||||
participant ":ToolChecker" as TC
|
||||
participant ":CredentialCollector" as CC
|
||||
|
||||
Maintainer -> PC : startProjectCreation()
|
||||
activate PC
|
||||
@@ -36,6 +37,11 @@ PC -> CL : load(config.env, .env)
|
||||
activate CL
|
||||
CL --> PC : configuration
|
||||
deactivate CL
|
||||
create CC
|
||||
PC -> CC : collect(configuration, GITEA_TOKEN)
|
||||
activate CC
|
||||
CC --> PC : configuration
|
||||
deactivate CC
|
||||
create TC
|
||||
PC -> TC : check(git, curl, jq)
|
||||
activate TC
|
||||
@@ -44,6 +50,7 @@ deactivate TC
|
||||
PC --> Maintainer : promptSet
|
||||
deactivate PC
|
||||
destroy CL
|
||||
destroy CC
|
||||
destroy TC
|
||||
@enduml
|
||||
```
|
||||
@@ -53,7 +60,7 @@ destroy TC
|
||||
| Pattern (GRASP / GoF) | Applied to | Rationale |
|
||||
| --- | --- | --- |
|
||||
| Controller (GRASP) | `ProjectCreator` | Receives the system operations and coordinates, without doing the work itself |
|
||||
| Pure Fabrication (GRASP) | `ConfigLoader`, `ToolChecker` | No domain concept owns parsing or tool checks; separate small units keep cohesion high |
|
||||
| Pure Fabrication (GRASP) | `ConfigLoader`, `ToolChecker`, `CredentialCollector` | No domain concept owns parsing, tool checks or asking for a credential; separate small units keep cohesion high |
|
||||
| Creator (GRASP) | `ConfigLoader` creates `Configuration` | It holds the data needed to build and validate it |
|
||||
|
||||
### Postcondition Coverage
|
||||
@@ -61,13 +68,13 @@ destroy TC
|
||||
| Postcondition (from contract) | Satisfied by message |
|
||||
| --- | --- |
|
||||
| P1 Run created | `startProjectCreation` received by `ProjectCreator` |
|
||||
| P2 Configuration created and validated | `load(config.env, .env)` |
|
||||
| P2 Configuration created and validated; a missing credential entered, validated and held in memory | `load(config.env, .env)` and `collect(configuration, GITEA_TOKEN)` |
|
||||
| P3 ToolCheck created | `check(git, curl, jq)` |
|
||||
| P4 PromptSet returned | `promptSet` return to the Maintainer |
|
||||
|
||||
### Responsibility Check
|
||||
|
||||
`ProjectCreator` only sequences two calls; parsing and validation sit in `ConfigLoader`, tool detection in `ToolChecker`. No object receives every message. Project details preset in `config.env` are read and validated by `ConfigLoader` as part of `configuration`; the second sequence is unchanged, because `provideProjectDetails` receives the same arguments whether they were asked or preset.
|
||||
`ProjectCreator` only sequences three calls; parsing and validation sit in `ConfigLoader`, asking for a missing credential in `CredentialCollector`, tool detection in `ToolChecker`. No object receives every message. Project details preset in `config.env` are read and validated by `ConfigLoader` as part of `configuration`; the second sequence is unchanged, because `provideProjectDetails` receives the same arguments whether they were asked or preset.
|
||||
|
||||
## Sequence: provideProjectDetails
|
||||
|
||||
@@ -77,7 +84,7 @@ destroy TC
|
||||
|
||||
```plantuml
|
||||
@startuml
|
||||
'actor Maintainer
|
||||
actor Maintainer
|
||||
participant ":ProjectCreator" as PC
|
||||
participant ":Preflight" as PF
|
||||
participant ":GiteaClient" as GT
|
||||
@@ -85,8 +92,10 @@ participant ":GitHubClient" as GH
|
||||
participant ":LocalProjectBuilder" as LB
|
||||
participant ":FrameworkInstaller" as FI
|
||||
participant ":SummaryReport" as SR
|
||||
participant ":CredentialCollector" as CC
|
||||
participant ":EnvFileWriter" as EW
|
||||
|
||||
-> PC : provideProjectDetails(name, description, visibility, giteaOwner, githubOwner, directory, enablePlanGate)
|
||||
Maintainer -> PC : provideProjectDetails(name, description, visibility, giteaOwner, githubOwner, directory, enablePlanGate, writeEnvFile)
|
||||
activate PC
|
||||
create GT
|
||||
PC -> GT : new(configuration)
|
||||
@@ -94,6 +103,13 @@ opt githubOwner present
|
||||
create GH
|
||||
PC -> GH : new(configuration)
|
||||
end
|
||||
opt githubOwner present
|
||||
create CC
|
||||
PC -> CC : collect(configuration, GITHUB_PAT, GITHUB_USER)
|
||||
activate CC
|
||||
CC --> PC : configuration
|
||||
deactivate CC
|
||||
end
|
||||
create PF
|
||||
PC -> PF : check(request)
|
||||
activate PF
|
||||
@@ -137,18 +153,29 @@ deactivate LB
|
||||
create FI
|
||||
PC -> FI : install(localProject, enablePlanGate)
|
||||
activate FI
|
||||
FI --> PC : submodule, hookSetup, templates
|
||||
FI --> PC : installResult
|
||||
deactivate FI
|
||||
|
||||
opt writeEnvFile
|
||||
create EW
|
||||
PC -> EW : write(localProject, configuration, githubOwner present)
|
||||
activate EW
|
||||
EW --> PC : envFile
|
||||
deactivate EW
|
||||
end
|
||||
|
||||
create SR
|
||||
PC -> SR : compose(request)
|
||||
SR --> PC : summary
|
||||
PC --> Maintainer : summary
|
||||
deactivate PC
|
||||
destroy PF
|
||||
destroy GT
|
||||
destroy GH
|
||||
destroy LB
|
||||
destroy FI
|
||||
destroy CC
|
||||
destroy EW
|
||||
destroy SR
|
||||
@enduml
|
||||
```
|
||||
@@ -158,7 +185,7 @@ destroy SR
|
||||
| Pattern (GRASP / GoF) | Applied to | Rationale |
|
||||
| --- | --- | --- |
|
||||
| Controller (GRASP) | `ProjectCreator` | Single entry for the system operation; sequences the steps and stops on the first failure |
|
||||
| Pure Fabrication (GRASP) | `Preflight`, `LocalProjectBuilder`, `FrameworkInstaller`, `SummaryReport` | Each groups one responsibility that no domain concept owns |
|
||||
| Pure Fabrication (GRASP) | `Preflight`, `LocalProjectBuilder`, `FrameworkInstaller`, `SummaryReport`, `CredentialCollector`, `EnvFileWriter` | Each groups one responsibility that no domain concept owns |
|
||||
| Facade (GoF) | `GiteaClient`, `GitHubClient` | Hide each host's HTTP API and credential handling behind a small interface; tokens never leave them |
|
||||
| Protection from variations (GRASP) | Client classes | The `github`-optional and license variations are decided by the controller's `alt` and `opt`, not inside the clients |
|
||||
|
||||
@@ -170,6 +197,7 @@ destroy SR
|
||||
| P2 PreflightResult created | `check(request)` |
|
||||
| P3 GiteaRepository created | `createRepository(request, license)` |
|
||||
| P4 LicenseFile when GitHub chosen, otherwise empty | `createRepository(..., license=AGPL-3.0)` and the `alt` branch `license=none` |
|
||||
| P2 GitHub credentials known before the first request | `collect(configuration, GITHUB_PAT, GITHUB_USER)` inside `opt githubOwner present` |
|
||||
| P5 empty GitHubRepository when chosen | `createEmptyRepository(request)` |
|
||||
| P6 PushMirror and first sync | `addPushMirror(...)` and `requestSync(pushMirror)` |
|
||||
| P7 LocalProject created, history from Gitea when not empty | `build(directory, ...)` |
|
||||
@@ -179,14 +207,14 @@ destroy SR
|
||||
| P11 HookSetup, plan gate if chosen | `install(localProject, enablePlanGate)` |
|
||||
| P12 AGENTS.md and registry copied or kept | `install(...)` returning `templates` |
|
||||
| P13 Summary created and returned | `compose(request)` and the final return |
|
||||
| P14 EnvFile created with the needed credentials, owner-only, ignored by git, or none when declined | `write(localProject, configuration, githubOwner present)` inside `opt writeEnvFile` |
|
||||
|
||||
### Responsibility Check
|
||||
|
||||
`ProjectCreator` sequences and decides on the optional paths but performs no HTTP, git or file work. Host calls are in the two clients, local work in `LocalProjectBuilder` and `FrameworkInstaller`, reporting in `SummaryReport`, so cohesion stays high and no object receives all messages. Failure handling (exceptions in [OC-001]) is the controller's single stop-and-report rule and is not drawn.
|
||||
`ProjectCreator` sequences and decides on the optional paths but performs no HTTP, git or file work. Host calls are in the two clients, local work in `LocalProjectBuilder` and `FrameworkInstaller`, the credential prompts in `CredentialCollector`, the `.env` in `EnvFileWriter`, reporting in `SummaryReport`, so cohesion stays high and no object receives all messages. Failure handling (exceptions in [OC-001]) is the controller's single stop-and-report rule and is not drawn.
|
||||
|
||||
---
|
||||
|
||||
[OC-001]: ./oc.md
|
||||
[DCD-001]: ./dcd.md
|
||||
[2a6bb8e]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/2a6bb8e8afadfe6ca4a621da30e44a372898ca62
|
||||
[f4d611b]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/f4d611b77cc70b4686506d44bf8f439045d9e0d2
|
||||
|
||||
+6
-7
@@ -9,8 +9,8 @@
|
||||
## Version History
|
||||
| Date | Status | Author | Reviewer | Change | Commit |
|
||||
| --- | --- | --- | --- | --- | --- |
|
||||
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Optional GitHub; choosing GitHub applies the AGPL license to the Gitea repository<br>Cited OC-001 and DM-001 | [02875ae] |
|
||||
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Parameters may come from config.env; the message is unchanged | [2a6bb8e] |
|
||||
| 2026-10-05 | Deprecated | Jens Tirsvad Nielsen | S02 | Parameters may come from config.env; the message is unchanged | [2a6bb8e] |
|
||||
| 2026-10-06 | Accepted | Jens Tirsvad Nielsen | S02 | writeEnvFile parameter and the credentials that .env does not provide | pending |
|
||||
|
||||
---
|
||||
|
||||
@@ -26,7 +26,7 @@ actor Maintainer as A
|
||||
participant ":System" as S
|
||||
A -> S : startProjectCreation()
|
||||
S --> A : prompts for project details
|
||||
A -> S : provideProjectDetails(name, description, visibility, giteaOwner, githubOwner, directory, enablePlanGate)
|
||||
A -> S : provideProjectDetails(name, description, visibility, giteaOwner, githubOwner, directory, enablePlanGate, writeEnvFile)
|
||||
S --> A : checks passed
|
||||
S --> A : creation summary
|
||||
@enduml
|
||||
@@ -36,19 +36,18 @@ S --> A : creation summary
|
||||
|
||||
| Step | Message | Parameters | Return | Use case step |
|
||||
| --- | --- | --- | --- | --- |
|
||||
| 1 | startProjectCreation | none | prompts for project details (after configuration and tool checks) | 1, 2 |
|
||||
| 2 | provideProjectDetails | name, description, visibility, giteaOwner, githubOwner (optional; given means GitHub is chosen and the Gitea repository gets the AGPL license; omitted means no GitHub and no license), directory, enablePlanGate (each of these may come from `config.env` instead of the Maintainer; the message is unchanged) | checks passed, then a creation summary | 3 to 10 |
|
||||
| 1 | startProjectCreation | none | prompts for project details (after configuration and tool checks; a missing credential is asked first) | 1, 2 |
|
||||
| 2 | provideProjectDetails | name, description, visibility, giteaOwner, githubOwner (optional; given means GitHub is chosen and the Gitea repository gets the AGPL license; omitted means no GitHub and no license), directory, enablePlanGate (each of these may come from `config.env` instead of the Maintainer; the message is unchanged), writeEnvFile (whether to create the project's `.env`), and the credentials that `.env` does not provide (GitHub ones only when GitHub is chosen) | checks passed, then a creation summary | 3 to 10 |
|
||||
|
||||
Steps 4 to 9 are internal to the system, so one operation covers them. A consent question (step 8a, 9a, 9b) is a prompt from the system and is out of scope for this diagram; failure flows are out of scope here.
|
||||
|
||||
## Lifecycle Notes
|
||||
|
||||
The system is one script run. It starts with the first operation and ends after the summary; nothing persists between runs.
|
||||
The system is one script run. It starts with the first operation and ends after the summary; nothing persists between runs except the `.env` the Maintainer agreed to in the new project.
|
||||
|
||||
---
|
||||
|
||||
[UC-001]: ./uc.md
|
||||
[DM-001]: ./dm.md
|
||||
[OC-001]: ./oc.md
|
||||
[02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a
|
||||
[2a6bb8e]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/2a6bb8e8afadfe6ca4a621da30e44a372898ca62
|
||||
|
||||
+15
-7
@@ -9,8 +9,8 @@
|
||||
## Version History
|
||||
| Date | Status | Author | Reviewer | Change | Commit |
|
||||
| --- | --- | --- | --- | --- | --- |
|
||||
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Optional GitHub; choosing GitHub applies the AGPL license to the Gitea repository<br>Cited DM-001 and UCD-001 | [02875ae] |
|
||||
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Step 3: details set in config.env are not asked (extensions 3a, 3b) | [2a6bb8e] |
|
||||
| 2026-10-05 | Deprecated | Jens Tirsvad Nielsen | S02 | Step 3: details set in config.env are not asked (extensions 3a, 3b) | [2a6bb8e] |
|
||||
| 2026-10-06 | Accepted | Jens Tirsvad Nielsen | S02 | Credentials not in .env are asked (step 2, extension 2b); the project .env is created with consent (step 9, extensions 9c, 9d) | pending |
|
||||
|
||||
---
|
||||
|
||||
@@ -26,33 +26,36 @@
|
||||
- S02 — credentials are never exposed and nothing is overwritten silently
|
||||
- S03 — the published procedure is documented and reusable
|
||||
- **Preconditions:**
|
||||
- `config.env` and `.env` exist and are valid.
|
||||
- `config.env` exists and is valid. `.env` may be missing or hold only some credentials; a credential it does not provide is asked.
|
||||
- `config.env` may preset any of the project details of step 3.
|
||||
- `git` and `curl` are installed.
|
||||
- The Maintainer has a Gitea token, a GitHub PAT (only when GitHub is chosen) and SSH access to Gitea on port 10022.
|
||||
- The Maintainer has a Gitea token, a GitHub PAT and a GitHub account name (only when GitHub is chosen) and SSH access to Gitea on port 10022.
|
||||
- **Postconditions (success guarantee):**
|
||||
- A repository exists on Gitea under the chosen owner. It is empty, or, when the Maintainer chose GitHub, it holds the AGPL license file.
|
||||
- When the Maintainer chose to create a GitHub repository, an empty repository exists on GitHub under the chosen owner, the Gitea repository is a push mirror to it, and the AGPL license file reaches GitHub through the mirror.
|
||||
- A local project directory exists with credential-free remotes `origin` (Gitea) and, when GitHub was chosen, `github`, the `framework` submodule, installed skills and hooks, and the copied templates.
|
||||
- When the Maintainer agreed, the local project has a `.env` that holds only the credentials the project needs, is readable by its owner only and is ignored by git.
|
||||
- The Maintainer has a summary of what was created.
|
||||
|
||||
### Main Success Scenario
|
||||
|
||||
1. The Maintainer starts the project creation.
|
||||
2. The system loads and validates the configuration and credentials and checks that the required tools exist.
|
||||
2. The system loads and validates the configuration and credentials and checks that the required tools exist. A credential that `.env` does not provide is asked, without echo; the GitHub credentials are asked once GitHub is chosen.
|
||||
3. The Maintainer provides the repository name, description, visibility, the Gitea owner, whether to also create a GitHub repository (and if so its owner), the local directory, and whether to enable the plan gate. A detail that is set in `config.env` is not asked.
|
||||
4. The system checks that the tokens needed for the chosen hosts work, that the owners accept new repositories, that the name is free on those hosts, and whether SSH to Gitea works.
|
||||
5. Optional: if the Maintainer chose GitHub, the system creates the empty GitHub repository.
|
||||
6. The system creates the Gitea repository. If the Maintainer chose GitHub, the repository is created with the AGPL license file and so is not empty; otherwise it is empty and has no license.
|
||||
7. Optional: if GitHub was chosen, the system configures the Gitea repository as a push mirror to GitHub and verifies it. A license file in the Gitea repository is pushed to GitHub by the mirror.
|
||||
8. The system creates the local project with the `origin` remote and, if GitHub was chosen, the `github` remote.
|
||||
9. The system adds the framework submodule, installs its skills and hooks (and the plan gate if chosen) and copies the templates.
|
||||
9. The system adds the framework submodule, installs its skills and hooks (and the plan gate if chosen) and copies the templates. If the Maintainer agrees, it also creates the project's own `.env` with the credentials the project needs.
|
||||
10. The system reports a summary of what was created.
|
||||
|
||||
### Extensions (Alternative / Exception Flows)
|
||||
|
||||
- 2a. A required tool is missing, or a configuration value is missing or malformed:
|
||||
1. The system stops before any change and names the problem without showing a credential.
|
||||
- 2b. A credential is not provided in `.env`:
|
||||
1. The system asks for it without showing what is typed. An invalid value is refused and asked again; when input ends the system stops before any change and names the key.
|
||||
- 3a. A project detail is set in `config.env`:
|
||||
1. The system uses it and does not ask for it; the summary says it came from the configuration.
|
||||
- 3b. A configured project detail is invalid:
|
||||
@@ -69,12 +72,18 @@
|
||||
1. The system asks the Maintainer before replacing it; on no, it skips that item and reports it.
|
||||
- 9b. A different git hooks setup is already configured in the project:
|
||||
1. The system asks before replacing it.
|
||||
- 9c. The Maintainer declines creating the project's `.env`:
|
||||
1. The system creates none and says so in the summary.
|
||||
- 9d. A `.env` already exists in the project:
|
||||
1. The system asks before replacing it; on no, it keeps it and reports it.
|
||||
|
||||
### Special Requirements / Business Rules
|
||||
|
||||
| Step | Rule |
|
||||
| --- | --- |
|
||||
| 2, 4 | A token never appears in output, logs, command lines, remote URLs or temporary files left behind |
|
||||
| 2 | A credential that is asked is read without echo, validated like one read from `.env`, and held in memory for the run |
|
||||
| 9 | The project's `.env` is the only place a token is written. It is created only after a yes (default no), holds only the keys the project needs (`GITEA_TOKEN`; `GITHUB_PAT` and `GITHUB_USER` when GitHub was chosen), is readable by its owner only, is excluded from git without changing a tracked file, and is never replaced without a yes |
|
||||
| 3 | The GitHub owner and the Gitea owner are chosen separately; `GITHUB_USER` is only the authenticating account |
|
||||
| 3 | A project detail set in `config.env` (the key is present, even if empty where an empty value is allowed) is not asked; only the confirmations stay interactive |
|
||||
| 3, 5, 7 | GitHub is optional; without it no GitHub repository, mirror or `github` remote is created and the GitHub credentials are not required |
|
||||
@@ -93,5 +102,4 @@
|
||||
[US-001]: ../user-stories.md
|
||||
[SA-001]: ../stakeholder-analysis.md
|
||||
[DM-001]: ./dm.md
|
||||
[02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a
|
||||
[2a6bb8e]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/2a6bb8e8afadfe6ca4a621da30e44a372898ca62
|
||||
|
||||
Reference in New Issue
Block a user