MIL-001 review fixes: stop tokens leaking under bash -x, move script to src/, RC-016 #24

Merged
Tirsvad merged 6 commits from mil-001-foundation into main 2026-10-05 08:23:32 +02:00
Owner

Follow-up to the merged MIL-001 PR: findings from the code review (RC-016,
against QC-SH-001) and the move of the script to src/.

Why this matters

The merged version prints the access tokens in the trace when the script is
run with bash -x (47 occurrences in a test run). This PR switches tracing
off with a warning and adds a test that fails if the guard is removed.

What is in this PR

  • Security: set -x is disabled while the script runs; no secret reaches a trace
  • Parser: a byte order mark on the first line of a config file is ignored
  • json_get: strips the carriage return jq adds on Windows, and returns the
    first matching key (not the last) when jq is not installed
  • Naming: boolean keys renamed to has_github and is_plan_gate_enabled
  • Header: cites the task it implements (MIL-001, US-001.01, UC-001), lists
    every external tool the script calls, documents that tracing is off
  • Location: create-project.sh moves to src/create-project.sh, so the plan
    gate (Task: MIL-NNN#N trailer) now applies to it. config.env and .env
    still default to the project root (the parent of src/); --config and
    --env override
  • Review record RC-016 and the Traceability Matrix entry

Checks

  • tests/run-tests.sh: 214 checks, 0 failed; shellcheck and shfmt clean
  • Mutation checks: a planted token leak and the removed tracing guard are both
    caught by the tests
  • Run against a real .env from the project root and from another directory:
    no token in any output, no temporary files left

Follow-ups (non-blocking, from RC-016, owner S02, due 2026-10-30)

  • Run the tests on Linux and macOS (bash 4.4 or later); the .env permission
    warning is skipped on Windows
  • Check by hand that Ctrl-C removes the temporary directory (SIGTERM is tested)
  • Check the real repository name rules of GitHub and Gitea in the MIL-002 preflight

Notes for the reviewer

  • Three accepted documents still show shellcheck create-project.sh without
    the src/ path: docs/business-case.md (success criterion 6),
    docs/milestones/mil-001-foundation.md (Go/No-Go criterion 1) and RC-016.
    Left unchanged here, since correcting them needs new Version History rows.
  • The history has a rename commit followed by a content commit (the first
    rename commit was pushed without its edits and fixed one commit later).

No issue closed: issues #3 to #8 were closed by the merged PR 22.

🤖 Generated with Claude Code

Follow-up to the merged MIL-001 PR: findings from the code review (RC-016, against QC-SH-001) and the move of the script to `src/`. ## Why this matters The merged version prints the access tokens in the trace when the script is run with `bash -x` (47 occurrences in a test run). This PR switches tracing off with a warning and adds a test that fails if the guard is removed. ## What is in this PR - Security: `set -x` is disabled while the script runs; no secret reaches a trace - Parser: a byte order mark on the first line of a config file is ignored - `json_get`: strips the carriage return `jq` adds on Windows, and returns the first matching key (not the last) when `jq` is not installed - Naming: boolean keys renamed to `has_github` and `is_plan_gate_enabled` - Header: cites the task it implements (MIL-001, US-001.01, UC-001), lists every external tool the script calls, documents that tracing is off - Location: `create-project.sh` moves to `src/create-project.sh`, so the plan gate (`Task: MIL-NNN#N` trailer) now applies to it. `config.env` and `.env` still default to the project root (the parent of `src/`); `--config` and `--env` override - Review record RC-016 and the Traceability Matrix entry ## Checks - `tests/run-tests.sh`: 214 checks, 0 failed; `shellcheck` and `shfmt` clean - Mutation checks: a planted token leak and the removed tracing guard are both caught by the tests - Run against a real `.env` from the project root and from another directory: no token in any output, no temporary files left ## Follow-ups (non-blocking, from RC-016, owner S02, due 2026-10-30) - Run the tests on Linux and macOS (bash 4.4 or later); the `.env` permission warning is skipped on Windows - Check by hand that Ctrl-C removes the temporary directory (SIGTERM is tested) - Check the real repository name rules of GitHub and Gitea in the MIL-002 preflight ## Notes for the reviewer - Three accepted documents still show `shellcheck create-project.sh` without the `src/` path: `docs/business-case.md` (success criterion 6), `docs/milestones/mil-001-foundation.md` (Go/No-Go criterion 1) and RC-016. Left unchanged here, since correcting them needs new Version History rows. - The history has a rename commit followed by a content commit (the first rename commit was pushed without its edits and fixed one commit later). No issue closed: issues #3 to #8 were closed by the merged PR 22. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Tirsvad added 6 commits 2026-10-05 08:22:54 +02:00
Switch off set -x (it printed tokens), accept a byte order mark, strip the
carriage return jq adds on Windows, return the first key without jq, rename
the boolean keys, and cite the task in the header. Add regression tests and
review record RC-016.

Task: MIL-001#2
Task: MIL-001#3
Task: MIL-001#4
Task: MIL-001#6

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Code belongs in src/, where the plan gate applies. config.env and .env
still default to the project root (the parent of src/). Add tests for the
location and the defaults.

Task: MIL-001#2

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Follow-up to the move: config.env and .env default to the project root
(the parent of src/), the header says so, and the tests use the new path.
Add tests for the location and the defaults.

Task: MIL-001#2

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Tirsvad merged commit 903c948d85 into main 2026-10-05 08:23:32 +02:00
Sign in to join this conversation.