#!/usr/bin/env bash set -euo pipefail umask 077 SCRIPT_DIR="$(CDPATH= cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd -P)" # shellcheck source=lib.sh source "${SCRIPT_DIR}/lib.sh" require_command git if [[ "$#" -ne 2 ]]; then printf 'Verwendung: %s AUSGABEDATEI ABSOLUTER_ASSET_ROOT\n' "$0" >&2 exit 2 fi output="$1" asset_root="$2" output_parent="$(CDPATH= cd -- "$(dirname -- "${output}")" && pwd -P)" || { printf 'Das Ausgabeverzeichnis muss bereits existieren.\n' >&2 exit 1 } output="${output_parent}/$(basename -- "${output}")" project_root="$(git -C "${TOOL_ROOT}" rev-parse --show-toplevel)" project_root="$(CDPATH= cd -- "${project_root}" && pwd -P)" case "${output}" in "${project_root}"|"${project_root}"/*) printf 'Die Secret-Datei darf nicht im Repository liegen.\n' >&2 exit 1 ;; esac [[ "${asset_root}" == /* ]] || { printf 'Asset-Root muss absolut sein.\n' >&2 exit 1 } [[ ! -e "${output}" ]] || { printf 'Ausgabedatei existiert bereits; sie wird nicht überschrieben.\n' >&2 exit 1 } if command -v openssl >/dev/null 2>&1; then token="$(openssl rand -base64 48 | tr -d '\n')" else printf 'openssl wird zur sicheren Token-Erzeugung benötigt.\n' >&2 exit 1 fi printf 'PROJECTCAPTURE_BLOCKBENCH_TOKEN=%q\nPROJECTCAPTURE_ASSET_ROOT=%q\n' \ "${token}" "${asset_root}" > "${output}" chmod 0600 "${output}" printf 'Lokale Environment-Datei erstellt (Token wird nicht ausgegeben): %s\n' "${output}"