MIL-001 Foundation: config parsing, HTTP helper, prompts and tests #22

Merged
Tirsvad merged 1 commits from mil-001-foundation into main 2026-10-05 08:00:41 +02:00
Owner

First code phase of RepoFoundry (create-project.sh): the secure base that
later phases build on. It validates configuration and credentials, checks the
tools and asks for the project details. It makes no network call and no
change on disk yet.

Implements MIL-001 and US-001.01 (UC-001 steps 1 to 3).

What is in this PR

  • create-project.sh: safe parser for config.env and .env (never sourced;
    unknown keys, malformed lines, duplicates and credentials in config.env
    are rejected), tool check, interactive prompts with validation, redaction
    of secrets in all output, private temporary files cleaned up on exit
  • HTTP helper: the token goes into a private curl config file, never onto the
    command line; redirects are not followed; no token in any message
  • config.env.example and .env.example (placeholders only), .gitignore
    additions, .editorconfig, .shellcheckrc
  • tests/: plain-bash harness with a stub curl (no network, no real .env)

Go/No-Go criteria (MIL-001)

  1. shellcheck reports no errors: clean (shfmt and bash -n too)
  2. Files are never sourced; unknown keys and malformed lines are rejected: tested
  3. No token in any output, including failure paths: tested, and a deliberately
    planted leak was caught
  4. Missing git or curl stops before any change: tested
  5. .env is ignored by git; example files hold placeholders only: tested
  6. Acceptance criteria of US-001.01: met

tests/run-tests.sh: 201 checks, 0 failed.

Decisions to review

  • Needs bash 4.4 or later (the script says so and stops on older versions)
  • mktemp is a required tool next to git and curl
  • Without jq, json_get reads the first matching key anywhere in the file
  • The GitHub name check was done by hand; the automated check comes with the
    MIL-002 preflight
  • File-permission warning for .env is skipped on Windows

Notes for the reviewer

  • This branch is based on planning, so until the planning PR is merged the
    diff against main also shows the planning documents. The code is the last
    commit (102dd24).
  • No separate code review record (RC against QC-SH-001) yet; the milestone
    Go/No-Go review is still to do.

Closes #3
Closes #4
Closes #5
Closes #6
Closes #7
Closes #8

First code phase of RepoFoundry (`create-project.sh`): the secure base that later phases build on. It validates configuration and credentials, checks the tools and asks for the project details. It makes no network call and no change on disk yet. Implements MIL-001 and US-001.01 (UC-001 steps 1 to 3). ## What is in this PR - `create-project.sh`: safe parser for `config.env` and `.env` (never sourced; unknown keys, malformed lines, duplicates and credentials in `config.env` are rejected), tool check, interactive prompts with validation, redaction of secrets in all output, private temporary files cleaned up on exit - HTTP helper: the token goes into a private curl config file, never onto the command line; redirects are not followed; no token in any message - `config.env.example` and `.env.example` (placeholders only), `.gitignore` additions, `.editorconfig`, `.shellcheckrc` - `tests/`: plain-bash harness with a stub curl (no network, no real `.env`) ## Go/No-Go criteria (MIL-001) 1. `shellcheck` reports no errors: clean (`shfmt` and `bash -n` too) 2. Files are never sourced; unknown keys and malformed lines are rejected: tested 3. No token in any output, including failure paths: tested, and a deliberately planted leak was caught 4. Missing `git` or `curl` stops before any change: tested 5. `.env` is ignored by git; example files hold placeholders only: tested 6. Acceptance criteria of US-001.01: met `tests/run-tests.sh`: 201 checks, 0 failed. ## Decisions to review - Needs bash 4.4 or later (the script says so and stops on older versions) - `mktemp` is a required tool next to `git` and `curl` - Without `jq`, `json_get` reads the first matching key anywhere in the file - The GitHub name check was done by hand; the automated check comes with the MIL-002 preflight - File-permission warning for `.env` is skipped on Windows ## Notes for the reviewer - This branch is based on `planning`, so until the planning PR is merged the diff against `main` also shows the planning documents. The code is the last commit (`102dd24`). - No separate code review record (RC against QC-SH-001) yet; the milestone Go/No-Go review is still to do. Closes #3 Closes #4 Closes #5 Closes #6 Closes #7 Closes #8
Tirsvad added 1 commit 2026-10-05 08:00:33 +02:00
create-project.sh validates config.env and .env (parsed, never sourced),
checks the required tools, asks for the project details and prints a
summary. It makes no network call and no change on disk yet.

- config.env.example and .env.example hold placeholders only
- tokens go through a private curl config file, never the command line
- tests run in private directories with a stub curl; shellcheck and shfmt
  are part of tests/run-tests.sh

Task: MIL-001#1
Task: MIL-001#2
Task: MIL-001#3
Task: MIL-001#4
Task: MIL-001#5
Task: MIL-001#6
Closes #3
Closes #4
Closes #5
Closes #6
Closes #7
Closes #8

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Tirsvad merged commit 4b6e5b6c67 into main 2026-10-05 08:00:41 +02:00
Sign in to join this conversation.