| 1 |
Define project name and configuration files |
Keep the working name RepoFoundry in one constant so it is easy to change, and confirm on GitHub that the name is free (the exact name returned 404 on 2026-10-05; only RepoFoundryAI by another owner exists). Create config.env.example with GITHUB_API_URL=https://api.github.com, GITHUB_WEB_URL=https://github.com, GITEA_URL=https://git.tirsystem.com/ and a Gitea API base (GITEA_API_URL, default https://git.tirsystem.com/api/v1; the request listed GITEA_URL twice, the second is treated as the API URL). Create .env.example with empty GITHUB_PAT, GITHUB_USER, GITEA_TOKEN. |
No |
|
| 2 |
Script skeleton with strict mode and safe helpers |
set -Eeuo pipefail, an ERR/EXIT trap, mktemp with umask 077 and cleanup on exit, small single-purpose functions, logging helpers that redact known secret values, and no rm -rf. Follow the framework coding-conventions Shell rules. |
No |
|
| 3 |
Safe parser for config.env and .env |
Read KEY=VALUE lines without source or eval; accept only whitelisted keys, strip optional quotes, reject control characters, and validate that service URLs are well-formed https and that credentials are non-empty. Warn when .env is readable by other users. |
No |
|
| 4 |
Tool check and HTTP helper |
Check git and curl (and optional jq, with a fallback parser for the few JSON fields needed) before any change. Wrap curl so tokens go through a private curl config file or stdin rather than the command line (visible in process lists), with --fail-with-body handling, timeouts, and error messages that carry the HTTP status but never the credential. |
No |
|
| 5 |
Interactive prompts and input validation |
Prompt for repository name, description, visibility and the owner or organization separately for GitHub and Gitea, with defaults taken from configuration. Validate names against both hosts' allowed characters. GITHUB_USER is only the authenticating account and is never assumed to be the owner. |
Yes |
UC-001 |
| 6 |
.gitignore and test harness |
Add .env and temporary files to .gitignore. Add a test harness with stubbed curl and git that covers parser rejection cases and the no-token-in-output check, run alongside shellcheck. |
No |
|