First code phase of RepoFoundry (create-project.sh): the secure base that
later phases build on. It validates configuration and credentials, checks the
tools and asks for the project details. It makes no network call and no
change on disk yet.
Implements MIL-001 and US-001.01 (UC-001 steps 1 to 3).
What is in this PR
create-project.sh: safe parser for config.env and .env (never sourced;
unknown keys, malformed lines, duplicates and credentials in config.env
are rejected), tool check, interactive prompts with validation, redaction
of secrets in all output, private temporary files cleaned up on exit
HTTP helper: the token goes into a private curl config file, never onto the
command line; redirects are not followed; no token in any message
config.env.example and .env.example (placeholders only), .gitignore
additions, .editorconfig, .shellcheckrc
tests/: plain-bash harness with a stub curl (no network, no real .env)
Go/No-Go criteria (MIL-001)
shellcheck reports no errors: clean (shfmt and bash -n too)
Files are never sourced; unknown keys and malformed lines are rejected: tested
No token in any output, including failure paths: tested, and a deliberately
planted leak was caught
Missing git or curl stops before any change: tested
.env is ignored by git; example files hold placeholders only: tested
Acceptance criteria of US-001.01: met
tests/run-tests.sh: 201 checks, 0 failed.
Decisions to review
Needs bash 4.4 or later (the script says so and stops on older versions)
mktemp is a required tool next to git and curl
Without jq, json_get reads the first matching key anywhere in the file
The GitHub name check was done by hand; the automated check comes with the
MIL-002 preflight
File-permission warning for .env is skipped on Windows
Notes for the reviewer
This branch is based on planning, so until the planning PR is merged the
diff against main also shows the planning documents. The code is the last
commit (102dd24).
No separate code review record (RC against QC-SH-001) yet; the milestone
Go/No-Go review is still to do.
First code phase of RepoFoundry (`create-project.sh`): the secure base that
later phases build on. It validates configuration and credentials, checks the
tools and asks for the project details. It makes no network call and no
change on disk yet.
Implements MIL-001 and US-001.01 (UC-001 steps 1 to 3).
## What is in this PR
- `create-project.sh`: safe parser for `config.env` and `.env` (never sourced;
unknown keys, malformed lines, duplicates and credentials in `config.env`
are rejected), tool check, interactive prompts with validation, redaction
of secrets in all output, private temporary files cleaned up on exit
- HTTP helper: the token goes into a private curl config file, never onto the
command line; redirects are not followed; no token in any message
- `config.env.example` and `.env.example` (placeholders only), `.gitignore`
additions, `.editorconfig`, `.shellcheckrc`
- `tests/`: plain-bash harness with a stub curl (no network, no real `.env`)
## Go/No-Go criteria (MIL-001)
1. `shellcheck` reports no errors: clean (`shfmt` and `bash -n` too)
2. Files are never sourced; unknown keys and malformed lines are rejected: tested
3. No token in any output, including failure paths: tested, and a deliberately
planted leak was caught
4. Missing `git` or `curl` stops before any change: tested
5. `.env` is ignored by git; example files hold placeholders only: tested
6. Acceptance criteria of US-001.01: met
`tests/run-tests.sh`: 201 checks, 0 failed.
## Decisions to review
- Needs bash 4.4 or later (the script says so and stops on older versions)
- `mktemp` is a required tool next to `git` and `curl`
- Without `jq`, `json_get` reads the first matching key anywhere in the file
- The GitHub name check was done by hand; the automated check comes with the
MIL-002 preflight
- File-permission warning for `.env` is skipped on Windows
## Notes for the reviewer
- This branch is based on `planning`, so until the planning PR is merged the
diff against `main` also shows the planning documents. The code is the last
commit (`102dd24`).
- No separate code review record (RC against QC-SH-001) yet; the milestone
Go/No-Go review is still to do.
Closes #3
Closes #4
Closes #5
Closes #6
Closes #7
Closes #8
create-project.sh validates config.env and .env (parsed, never sourced),
checks the required tools, asks for the project details and prints a
summary. It makes no network call and no change on disk yet.
- config.env.example and .env.example hold placeholders only
- tokens go through a private curl config file, never the command line
- tests run in private directories with a stub curl; shellcheck and shfmt
are part of tests/run-tests.sh
Task: MIL-001#1
Task: MIL-001#2
Task: MIL-001#3
Task: MIL-001#4
Task: MIL-001#5
Task: MIL-001#6
Closes#3Closes#4Closes#5Closes#6Closes#7Closes#8
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Tirsvad
merged commit 4b6e5b6c67 into main2026-10-05 08:00:41 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
First code phase of RepoFoundry (
create-project.sh): the secure base thatlater phases build on. It validates configuration and credentials, checks the
tools and asks for the project details. It makes no network call and no
change on disk yet.
Implements MIL-001 and US-001.01 (UC-001 steps 1 to 3).
What is in this PR
create-project.sh: safe parser forconfig.envand.env(never sourced;unknown keys, malformed lines, duplicates and credentials in
config.envare rejected), tool check, interactive prompts with validation, redaction
of secrets in all output, private temporary files cleaned up on exit
command line; redirects are not followed; no token in any message
config.env.exampleand.env.example(placeholders only),.gitignoreadditions,
.editorconfig,.shellcheckrctests/: plain-bash harness with a stub curl (no network, no real.env)Go/No-Go criteria (MIL-001)
shellcheckreports no errors: clean (shfmtandbash -ntoo)planted leak was caught
gitorcurlstops before any change: tested.envis ignored by git; example files hold placeholders only: testedtests/run-tests.sh: 201 checks, 0 failed.Decisions to review
mktempis a required tool next togitandcurljq,json_getreads the first matching key anywhere in the fileMIL-002 preflight
.envis skipped on WindowsNotes for the reviewer
planning, so until the planning PR is merged thediff against
mainalso shows the planning documents. The code is the lastcommit (
102dd24).Go/No-Go review is still to do.
Closes #3
Closes #4
Closes #5
Closes #6
Closes #7
Closes #8