MIL-001 review fixes: stop tokens leaking under bash -x, move script to src/, RC-016 #24

Merged
Tirsvad merged 6 commits from mil-001-foundation into main 2026-10-05 08:23:32 +02:00
3 changed files with 33 additions and 5 deletions
Showing only changes of commit 9413ec3e4c - Show all commits
+8 -4
View File
@@ -14,8 +14,8 @@
# create-project.sh --help | --version # create-project.sh --help | --version
# #
# Options # Options
# --config FILE service addresses (default: config.env next to the script) # --config FILE service addresses (default: config.env in the project root)
# --env FILE credentials (default: .env next to the script) # --env FILE credentials (default: .env in the project root)
# -h, --help show this help # -h, --help show this help
# --version show the version # --version show the version
# #
@@ -73,9 +73,13 @@ esac
SCRIPT_DIR="$(cd "$script_path_dir" && pwd)" SCRIPT_DIR="$(cd "$script_path_dir" && pwd)"
readonly SCRIPT_DIR readonly SCRIPT_DIR
unset script_path_dir unset script_path_dir
# The script lives in src/; the configuration files live one level up, in
# the project root, next to config.env.example and .env.example.
PROJECT_ROOT="$(cd "$SCRIPT_DIR/.." && pwd)"
readonly PROJECT_ROOT
CONFIG_FILE="$SCRIPT_DIR/config.env" CONFIG_FILE="$PROJECT_ROOT/config.env"
ENV_FILE="$SCRIPT_DIR/.env" ENV_FILE="$PROJECT_ROOT/.env"
TMP_DIR="" TMP_DIR=""
HAS_JQ=0 HAS_JQ=0
HTTP_STATUS=0 HTTP_STATUS=0
+1 -1
View File
@@ -11,7 +11,7 @@
# shellcheck disable=SC2016,SC2034 # stub and snippet text is literal on purpose; OUT, ERR and STATUS are read by the test files # shellcheck disable=SC2016,SC2034 # stub and snippet text is literal on purpose; OUT, ERR and STATUS are read by the test files
REPO_ROOT="$(cd "${BASH_SOURCE[0]%/*}/.." && pwd)" REPO_ROOT="$(cd "${BASH_SOURCE[0]%/*}/.." && pwd)"
readonly REPO_ROOT readonly REPO_ROOT
readonly SCRIPT="$REPO_ROOT/create-project.sh" readonly SCRIPT="$REPO_ROOT/src/create-project.sh"
# Distinctive fake credentials; the tests search all output for them. # Distinctive fake credentials; the tests search all output for them.
readonly FAKE_GITEA_TOKEN="giteaFAKEtoken1234567890" readonly FAKE_GITEA_TOKEN="giteaFAKEtoken1234567890"
+24
View File
@@ -174,3 +174,27 @@ test_termination_removes_temp_files() {
exec 7>&- exec 7>&-
assert_eq "temp directory removed after SIGTERM" "" "$(find "$WORK/tmp" -mindepth 1)" assert_eq "temp directory removed after SIGTERM" "" "$(find "$WORK/tmp" -mindepth 1)"
} }
test_script_lives_in_src() {
assert_file_exists "script in src/" "$REPO_ROOT/src/create-project.sh"
assert_file_missing "no copy in the project root" "$REPO_ROOT/create-project.sh"
}
test_default_files_are_in_the_project_root() {
# A project copy: script in src/, config.env and .env one level up.
write_fixtures
mkdir -p "$WORK/project/src"
cp "$SCRIPT" "$WORK/project/src/create-project.sh"
cp "$WORK/config.env" "$WORK/project/config.env"
cp "$WORK/.env" "$WORK/project/.env"
STATUS=0
PATH="$WORK/bin:$PATH" TMPDIR="$WORK/tmp" "$BASH" "$WORK/project/src/create-project.sh" \
<<<"$ANSWERS_GITHUB" >"$WORK/out.txt" 2>"$WORK/err.txt" || STATUS=$?
assert_status "run with the default files" 0 "$STATUS"
assert_contains "found config.env in the project root" "$(cat "$WORK/out.txt")" "https://git.example.test/TirSystem/my-app"
# Run from another directory: the defaults follow the script, not the cwd.
STATUS=0
(cd "$WORK" && PATH="$WORK/bin:$PATH" TMPDIR="$WORK/tmp" "$BASH" "$WORK/project/src/create-project.sh" \
<<<"$ANSWERS_GITEA_ONLY" >"$WORK/out.txt" 2>"$WORK/err.txt") || STATUS=$?
assert_status "run from another directory" 0 "$STATUS"
}