mirror of
https://github.com/MadsLorentzen/ai-job-search.git
synced 2026-09-17 08:36:25 +00:00
The quick start walked a new user into gh repo fork - forks of public repos are always public - and two steps later had /setup write personal data into tracked files, with the only complete warning in SETUP.md section 8, a section about pulling updates that a first-time user has no reason to open during onboarding. A real user hit exactly this (#345). The warning now sits adjacent to both fork commands (README step 1, SETUP.md section 2, both pointing at section 8's private-remote recipe), and /setup checks the origin's visibility BEFORE writing anything: a public-fork origin gets a confirm-first warning instead of a note after every file is on disk. A private origin, no origin, or a non-git directory continues silently. Reported by @basilevs with a complete reproduction and fix analysis; this implements his fixes (1) and (4). Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
ab5d23bad4
commit
34b8b3f91f
@@ -10,7 +10,26 @@ There are three paths into setup. Step 0 picks the right one; all three converge
|
||||
|
||||
If `$ARGUMENTS` contains `--section <name>`, skip directly to that section in Path C for an update-only flow. Do not run the path-selection prompt below.
|
||||
|
||||
Otherwise, before greeting the user, scan the `documents/` folder. Use Glob with `documents/**/*` and count files per subfolder (`cv/`, `linkedin/`, `diplomas/`, `references/`, `applications/`).
|
||||
Otherwise, first check where this working copy would publish to — **before anything is
|
||||
written, not after** (the Step 4 privacy note fires only once every file is already on
|
||||
disk, which is too late to inform the decision). Run `git remote get-url origin`; if the
|
||||
command fails (no remote, or not a git checkout), skip this check silently. If there is
|
||||
a GitHub `origin`, check it with `gh repo view <owner/repo> --json visibility,isFork`
|
||||
when `gh` is available. If the origin is a **public fork** of the template — or its
|
||||
visibility cannot be determined — warn now and wait:
|
||||
|
||||
> **Heads-up before we start:** your `origin` points at `<owner/repo>`, which is a
|
||||
> public GitHub fork. This setup writes your personal data (name, contact details,
|
||||
> employment history, salary expectations) into **tracked** files, and anything you
|
||||
> commit *and push* to that fork is visible to anyone. Two safe options: keep your
|
||||
> profile commits local and never push them, or push to a **private** repository
|
||||
> instead — SETUP.md section 8 has the two-minute private-remote recipe. Want to
|
||||
> continue with the setup?
|
||||
|
||||
Wait for the user's confirmation before showing the path prompt. A private origin, no
|
||||
origin, or a non-fork remote needs no warning — continue silently.
|
||||
|
||||
Then, before greeting the user, scan the `documents/` folder. Use Glob with `documents/**/*` and count files per subfolder (`cv/`, `linkedin/`, `diplomas/`, `references/`, `applications/`).
|
||||
|
||||
Then welcome the user with a single message that lists three paths. The wording changes based on what was found.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user