#!/bin/sh
# Pre-commit gate: refuse gitignored secret env files, then run the harness
# checks. Wired by `make harness-setup` via `git config core.hooksPath .githooks`.
set -e

env_candidates="$(git diff --cached --name-only --diff-filter=ACM | grep -E '(^|/)\.env($|\.)' || true)"
for f in $env_candidates; do
  if git check-ignore -q "$f"; then
    echo "pre-commit: refusing to commit gitignored secret env file: $f" >&2
    echo "  Secrets stay out of the repository; never force-add them." >&2
    exit 1
  fi
done

# Best-effort local secret scan; CI runs the enforcing gitleaks gate.
if command -v gitleaks >/dev/null 2>&1; then
  gitleaks protect --staged --redact --no-banner
fi

make harness-check
