MIL-005: ask for missing credentials and create the project's own .env #41

Open
Tirsvad wants to merge 1 commits from mil-005-credentials into main
Owner

Implements MIL-005 (plan accepted in PR 40, RC-020).

  • .env is optional. A credential it does not provide (file missing, key absent or empty) is asked without echo: the Gitea token at the start, the GitHub token and account name once GitHub is chosen
  • An invalid value is asked again and never shown; when input ends the run stops before any request to a host; asked tokens are registered for redaction at once
  • After the local project exists the script asks (default no) whether to create a .env in it. On a yes it holds only the keys the project needs (GITEA_TOKEN; plus GITHUB_PAT and GITHUB_USER with GitHub), is created private (mode 600) from the start, is excluded from git through .git/info/exclude (no tracked file changes), is never replaced without a second yes and is never written when git tracks it. The summary names the keys, never the values
  • New library files credentials.sh and envfile.sh; README, .env.example and the security decisions updated

Security note: this deliberately changes the earlier guarantee that a token is never persisted: a token may now be written to exactly one file, the new project's .env, after a yes (Business Case objective 6 and success criterion 1 were amended in the plan).

Tests: tests/test-credentials.sh; two older tests that expected a missing credential to be an error were changed on purpose; full suite 1025 checks, 0 failed; a mutation check (removing the git exclusion) was caught. The hidden typing itself is not tested because the tests pipe their input.

Closes #35
Closes #36
Closes #37
Closes #38
Closes #39

🤖 Generated with Claude Code

Implements MIL-005 (plan accepted in PR 40, RC-020). - `.env` is optional. A credential it does not provide (file missing, key absent or empty) is asked without echo: the Gitea token at the start, the GitHub token and account name once GitHub is chosen - An invalid value is asked again and never shown; when input ends the run stops before any request to a host; asked tokens are registered for redaction at once - After the local project exists the script asks (default no) whether to create a `.env` in it. On a yes it holds only the keys the project needs (`GITEA_TOKEN`; plus `GITHUB_PAT` and `GITHUB_USER` with GitHub), is created private (mode 600) from the start, is excluded from git through `.git/info/exclude` (no tracked file changes), is never replaced without a second yes and is never written when git tracks it. The summary names the keys, never the values - New library files `credentials.sh` and `envfile.sh`; README, `.env.example` and the security decisions updated **Security note:** this deliberately changes the earlier guarantee that a token is never persisted: a token may now be written to exactly one file, the new project's `.env`, after a yes (Business Case objective 6 and success criterion 1 were amended in the plan). **Tests:** `tests/test-credentials.sh`; two older tests that expected a missing credential to be an error were changed on purpose; full suite 1025 checks, 0 failed; a mutation check (removing the git exclusion) was caught. The hidden typing itself is not tested because the tests pipe their input. Closes #35 Closes #36 Closes #37 Closes #38 Closes #39 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Tirsvad added 1 commit 2026-10-06 07:44:42 +02:00
.env becomes optional. A credential it does not provide (an absent file, an
absent or empty key) is asked, without echo: GITEA_TOKEN at the start,
GITHUB_PAT and GITHUB_USER once GitHub is chosen. An invalid value is asked
again and never shown; when input ends the run stops before any request.
Asked tokens are registered for redaction at once.

After the local project exists the script asks (default no) whether to
create a .env in it. On a yes it holds only the needed keys, is created
private (mode 600) from the start, is excluded from git through
.git/info/exclude (no tracked file changes), is never replaced without a
second yes and is never written when git tracks it. The summary names the
keys, never the values.

New library files credentials.sh and envfile.sh; README, .env.example and
the security decisions updated; tests cover every case.

Task: MIL-005#1
Task: MIL-005#2
Task: MIL-005#3
Task: MIL-005#4
Task: MIL-005#5
Closes #35
Closes #36
Closes #37
Closes #38
Closes #39

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
You are not authorized to merge this pull request.
This pull request can be merged automatically.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin mil-005-credentials:mil-005-credentials
git checkout mil-005-credentials
Sign in to join this conversation.