Implements MIL-005 (plan accepted in PR 40, RC-020).
.env is optional. A credential it does not provide (file missing, key absent or empty) is asked without echo: the Gitea token at the start, the GitHub token and account name once GitHub is chosen
An invalid value is asked again and never shown; when input ends the run stops before any request to a host; asked tokens are registered for redaction at once
After the local project exists the script asks (default no) whether to create a .env in it. On a yes it holds only the keys the project needs (GITEA_TOKEN; plus GITHUB_PAT and GITHUB_USER with GitHub), is created private (mode 600) from the start, is excluded from git through .git/info/exclude (no tracked file changes), is never replaced without a second yes and is never written when git tracks it. The summary names the keys, never the values
New library files credentials.sh and envfile.sh; README, .env.example and the security decisions updated
Security note: this deliberately changes the earlier guarantee that a token is never persisted: a token may now be written to exactly one file, the new project's .env, after a yes (Business Case objective 6 and success criterion 1 were amended in the plan).
Tests:tests/test-credentials.sh; two older tests that expected a missing credential to be an error were changed on purpose; full suite 1025 checks, 0 failed; a mutation check (removing the git exclusion) was caught. The hidden typing itself is not tested because the tests pipe their input.
Implements MIL-005 (plan accepted in PR 40, RC-020).
- `.env` is optional. A credential it does not provide (file missing, key absent or empty) is asked without echo: the Gitea token at the start, the GitHub token and account name once GitHub is chosen
- An invalid value is asked again and never shown; when input ends the run stops before any request to a host; asked tokens are registered for redaction at once
- After the local project exists the script asks (default no) whether to create a `.env` in it. On a yes it holds only the keys the project needs (`GITEA_TOKEN`; plus `GITHUB_PAT` and `GITHUB_USER` with GitHub), is created private (mode 600) from the start, is excluded from git through `.git/info/exclude` (no tracked file changes), is never replaced without a second yes and is never written when git tracks it. The summary names the keys, never the values
- New library files `credentials.sh` and `envfile.sh`; README, `.env.example` and the security decisions updated
**Security note:** this deliberately changes the earlier guarantee that a token is never persisted: a token may now be written to exactly one file, the new project's `.env`, after a yes (Business Case objective 6 and success criterion 1 were amended in the plan).
**Tests:** `tests/test-credentials.sh`; two older tests that expected a missing credential to be an error were changed on purpose; full suite 1025 checks, 0 failed; a mutation check (removing the git exclusion) was caught. The hidden typing itself is not tested because the tests pipe their input.
Closes #35
Closes #36
Closes #37
Closes #38
Closes #39
🤖 Generated with [Claude Code](https://claude.com/claude-code)
.env becomes optional. A credential it does not provide (an absent file, an
absent or empty key) is asked, without echo: GITEA_TOKEN at the start,
GITHUB_PAT and GITHUB_USER once GitHub is chosen. An invalid value is asked
again and never shown; when input ends the run stops before any request.
Asked tokens are registered for redaction at once.
After the local project exists the script asks (default no) whether to
create a .env in it. On a yes it holds only the needed keys, is created
private (mode 600) from the start, is excluded from git through
.git/info/exclude (no tracked file changes), is never replaced without a
second yes and is never written when git tracks it. The summary names the
keys, never the values.
New library files credentials.sh and envfile.sh; README, .env.example and
the security decisions updated; tests cover every case.
Task: MIL-005#1
Task: MIL-005#2
Task: MIL-005#3
Task: MIL-005#4
Task: MIL-005#5
Closes#35Closes#36Closes#37Closes#38Closes#39
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
You are not authorized to merge this pull request.
This pull request can be merged automatically.
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements MIL-005 (plan accepted in PR 40, RC-020).
.envis optional. A credential it does not provide (file missing, key absent or empty) is asked without echo: the Gitea token at the start, the GitHub token and account name once GitHub is chosen.envin it. On a yes it holds only the keys the project needs (GITEA_TOKEN; plusGITHUB_PATandGITHUB_USERwith GitHub), is created private (mode 600) from the start, is excluded from git through.git/info/exclude(no tracked file changes), is never replaced without a second yes and is never written when git tracks it. The summary names the keys, never the valuescredentials.shandenvfile.sh; README,.env.exampleand the security decisions updatedSecurity note: this deliberately changes the earlier guarantee that a token is never persisted: a token may now be written to exactly one file, the new project's
.env, after a yes (Business Case objective 6 and success criterion 1 were amended in the plan).Tests:
tests/test-credentials.sh; two older tests that expected a missing credential to be an error were changed on purpose; full suite 1025 checks, 0 failed; a mutation check (removing the git exclusion) was caught. The hidden typing itself is not tested because the tests pipe their input.Closes #35
Closes #36
Closes #37
Closes #38
Closes #39
🤖 Generated with Claude Code
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.