howto/create-access-tokens.md walks through creating the Gitea access token
and the GitHub classic personal access token that RepoFoundry needs, with nine
illustrations in howto/img/, how to hand the tokens to the script, how to keep
them safe and what the script's token errors mean.
The README's Token permissions section now links to it.
- RC-031 is Accepted with a Go verdict and no open action items
- MIL-008 and the documents it changes are set to Accepted (previous rows
Deprecated): BC-001, US-001, UC-001, OC-001, SD-001, DCD-001, DCD-002,
DM-001, DM-002, MIL-003, PP-001 and TM-001
The version is raised to 0.3.1 and release v0.3.1 is tagged on Gitea from the
merge commit once the pull request is merged. MIL-008 gets task 4 and
criterion 7; RC-031 counts seven criteria.
create_local_project no longer adds a github remote, with or without GitHub:
a push to origin reaches GitHub through the push mirror. A github remote that
already exists, such as one made by an earlier version, is left as it is, and
a different origin is still refused.
- Remove github_remote_url, which nothing else used
- README describes the one remote and how to remove an old github remote
- Tests: origin is the only remote with and without GitHub, no GitHub address
in .git/config, and an existing github remote is kept
Task: MIL-008#1
Task: MIL-008#2
Task: MIL-008#3
A project created by the script had two remotes, origin (Gitea) and github.
Gitea already pushes to GitHub through the push mirror, so the second remote
is not needed and invites a push that goes around the mirror.
- MIL-008 and its review record RC-031
- Objective 4, US-001.03, UC-001 step 8, OC-001 P9, SD-001, DCD-001, DCD-002,
DM-001 and DM-002 describe one remote; MIL-003 criterion 1 and task 1 follow
- Project plan and traceability matrix list MIL-008 and RC-031
- Review records RC-022 to RC-030 are Accepted
- The documents they review are set to Accepted (previous rows Deprecated)
- RC-028 and RC-029: Go-with-conditions becomes Go; the two action items are closed
- OC-001, SD-001 and DCD-001 carry a note that the UC-002 documents supersede the startProjectCreation signature
- README: start from the folder where the project is created, make the script a global command, where config.env and .env are read from and the confirmation
- Tests: qc tests set up the temp directory and force a real failure; the default-files test runs from a folder without files of its own; the link test allows for path aliases; the work directory cleanup deletes links
Task: MIL-007#3
Task: MIL-007#4
Refs #49
Refs #51
- git submodule update --init --recursive after adding or reusing the framework
- Follow links to the script so SCRIPT_DIR and the checkout are the real ones
- config.env and .env: --config/--env, else ./ in the working folder, else the checkout's
- Name the files used; a file from the working folder needs a yes before any request
- MIL-007 accepted; test fixtures for the qc checklists; tests/test-launch.sh
Work in progress: the README section is not written yet, and four tests of
test-launch.sh fail and two shellcheck warnings remain; they are fixed next.
Task: MIL-007#1
Task: MIL-007#2
Refs #47
Refs #48
Refs #51
- PROJECT_LICENSE (a Gitea license key, or none) is read, checked and never asked
- Without it AGPL-3.0 applies only when GitHub is chosen and the project is public
- The license is applied on Gitea with or without GitHub, and checked against the server first
- Plan and summary name the license and where it came from
- MIL-006 accepted; README and config.env.example document the key
- Tests: new test-license.sh; existing tests use a public project where they expect AGPL-3.0
Task: MIL-006#1
Task: MIL-006#2
Task: MIL-006#3
Task: MIL-006#4
Refs #44
Refs #45
Refs #46
Refs #50
- --config and --env, else ./config.env and ./.env, else the checkout's
- Files named before any request; a file from the working folder needs a yes
- UC-002, US-002, MIL-007 criteria 9 and 10, models and contracts updated
- Review record RC-029
- MIL-006: the AGPL-3.0 default needs GitHub and a public project
- MIL-007: fetch the framework's own submodules (qc); start through a command link; README usage
- UC-002 with SSD, DM, OC, SD and DCD; US-001.07 and US-002
- Reconcile the project DM, DCD, dictionary, use case diagram and traceability matrix
- Review records RC-022 to RC-028
Add objective 10 to the Business Case, US-001.06 and the use case, SSD, OC,
SD, DM-001, DM-002, dictionary, DCD-001 and DCD-002 changes: a license set
in config.env (PROJECT_LICENSE, a Gitea license key or none) applies with or
without GitHub; when absent AGPL-3.0 applies only when GitHub is chosen. It
is never asked, and a license the server does not offer stops the run
before anything is created.
Add milestone MIL-006 (8 Go/No-Go criteria, 4 tasks) and its phase in the
Project Plan. All new rows are Proposed.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
.env becomes optional. A credential it does not provide (an absent file, an
absent or empty key) is asked, without echo: GITEA_TOKEN at the start,
GITHUB_PAT and GITHUB_USER once GitHub is chosen. An invalid value is asked
again and never shown; when input ends the run stops before any request.
Asked tokens are registered for redaction at once.
After the local project exists the script asks (default no) whether to
create a .env in it. On a yes it holds only the needed keys, is created
private (mode 600) from the start, is excluded from git through
.git/info/exclude (no tracked file changes), is never replaced without a
second yes and is never written when git tracks it. The summary names the
keys, never the values.
New library files credentials.sh and envfile.sh; README, .env.example and
the security decisions updated; tests cover every case.
Task: MIL-005#1
Task: MIL-005#2
Task: MIL-005#3
Task: MIL-005#4
Task: MIL-005#5
Closes#35Closes#36Closes#37Closes#38Closes#39
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Add objective 9 to the Business Case (and amend objective 6 and success
criterion 1: a token may be written only to the new project's .env after a
yes), US-001.05, UC-001 extensions 2b, 9c and 9d, with the SSD, OC, SD,
DM-001, DM-002 and dictionary in step. Add the classes CredentialCollector,
EnvFileWriter and EnvFile to DCD-001 and DCD-002, and both ends'
multiplicities to every association. Restore three lines of SD-001 damaged
by an earlier edit.
Add milestone MIL-005 (9 Go/No-Go criteria, 5 tasks) and its phase in the
Project Plan. Accept the planning set and the two DCDs; reviews recorded in
RC-020 and RC-021.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
- DCD-001 (UC-001): design classes refining DM-001, with class table,
method traceability to OC-001 and SD-001, patterns and dependency check,
and the mapping of each class to src/lib.
- DCD-002: the consolidated project-level model, created from DCD-001.
- SD-001: messages aligned with the DCD method signatures; cites DCD-001.
- Dictionary, registry and traceability matrix updated.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
The repeated run with a write:user token passes on both hosts, so
criterion 7 is now Pass; only the README review (criterion 6) remains.
Refs #20
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
The file holds the Maintainer's own addresses and project details, so it
stays out of the repository like .env.
Refs #31
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
- Say in the README and config.env.example that a value containing " #"
must be quoted, and pin both behaviours with a test.
- Say in the script header and the README that details set in config.env
are not asked.
- Record the review as RC-019 and link it in the traceability matrix.
Task: MIL-004#4
Task: MIL-004#5
Refs #30
Refs #31
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Eight optional keys (PROJECT_NAME, PROJECT_DESCRIPTION, PROJECT_VISIBILITY,
GITEA_OWNER, USE_GITHUB, GITHUB_OWNER, PROJECT_DIRECTORY, ENABLE_PLAN_GATE)
are read and checked with the validators the prompts use. A key that is
present counts as set (only the description may be empty); it is not asked
and the summary marks it "(from config.env)". An invalid value stops the
run before any request and names the key. USE_GITHUB=no skips the GitHub
owner and warns about a stray GITHUB_OWNER. The confirmations stay
interactive. Keys and an example are documented; tests cover every key.
Task: MIL-004#1
Task: MIL-004#2
Task: MIL-004#3
Task: MIL-004#4
Task: MIL-004#5
Closes#27Closes#28Closes#29Closes#30Closes#31
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>