#!/usr/bin/env bash
#
# Credentials in the tracked tree, and in the bundle users receive.
#
# `scripts/secrets.sh` runs on the staged diff from the pre-commit hook, which
# is the cheap moment. This is the whole-tree version, run as part of verify so
# that something looks at what is ALREADY committed rather than only at what is
# arriving.
#
# The distinction earned itself here: the Zoho WebToLead tokens sat in four
# commits of a then-public repository for a month, and a staged-diff scan
# installed afterwards would never have mentioned them.
#
# It also scans dist/, which 10-build has just produced. A key can reach the
# bundle from an environment variable inlined at build time without ever being
# committed, and the tracked scan cannot see that. SECURITY_CHECKLIST.md listed
# this as a manual release check for months; nothing ran it.
#
# Exit 0 clean, 1 findings, 2 the scanner could not run.
set -uo pipefail
cd "$(git rev-parse --show-toplevel)" || exit 1

[ -f scripts/secrets.sh ] || { echo "secrets: scripts/secrets.sh is missing, so nothing was scanned." >&2; exit 2; }

status=0
bash scripts/secrets.sh --tracked || status=$?

if [ ! -d dist ]; then
  echo "secrets: dist/ is missing, so the built output was not scanned. Run 10-build first." >&2
  exit 2
fi

bash scripts/secrets.sh --built dist/ || { rc=$?; [ "$rc" -gt "$status" ] && status=$rc; }

exit "$status"
