.env becomes optional. A credential it does not provide (an absent file, an absent or empty key) is asked, without echo: GITEA_TOKEN at the start, GITHUB_PAT and GITHUB_USER once GitHub is chosen. An invalid value is asked again and never shown; when input ends the run stops before any request. Asked tokens are registered for redaction at once. After the local project exists the script asks (default no) whether to create a .env in it. On a yes it holds only the needed keys, is created private (mode 600) from the start, is excluded from git through .git/info/exclude (no tracked file changes), is never replaced without a second yes and is never written when git tracks it. The summary names the keys, never the values. New library files credentials.sh and envfile.sh; README, .env.example and the security decisions updated; tests cover every case. Task: MIL-005#1 Task: MIL-005#2 Task: MIL-005#3 Task: MIL-005#4 Task: MIL-005#5 Closes #35 Closes #36 Closes #37 Closes #38 Closes #39 Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
30 lines
1.2 KiB
Bash
30 lines
1.2 KiB
Bash
# RepoFoundry credentials. Placeholders only: never put a real value in this
|
|
# file or commit one.
|
|
#
|
|
# Everything in this file is optional: a credential that is missing here is
|
|
# asked for when the script runs (the token is not echoed).
|
|
#
|
|
# Copy this file to .env, fill in the values and keep it private
|
|
# (chmod 600 .env on Linux and macOS). .env is ignored by git. The file is
|
|
# read as plain KEY=VALUE lines and never executed. Values may be wrapped in
|
|
# single or double quotes.
|
|
|
|
# GitHub personal access token. Needed only when you choose to create a
|
|
# GitHub repository. It creates the repository and is also the password of the
|
|
# Gitea push mirror, so it needs permission to create repositories for the
|
|
# chosen owner and to push to the new one. Prefer a fine-grained token.
|
|
GITHUB_PAT=
|
|
|
|
########################################
|
|
# Secrets for framework
|
|
########################################
|
|
|
|
# GitHub account the token belongs to. It identifies who authenticates; it is
|
|
# only a default suggestion for the owner prompt, because the repository can
|
|
# belong to an organization.
|
|
GITHUB_USER=
|
|
|
|
# Gitea access token. It needs permission to create repositories
|
|
# for the chosen owner and to manage the repository's push mirror.
|
|
GITEA_TOKEN=
|