fix(client-handover): gate push behind explicit GO + report-only fallback

STEP 5 previously ran `git push origin "$CURRENT_BRANCH"` autonomously
after the fix loops (gitflow-conformity §2b, verified HIGH). Now:
- gitflow precondition: no develop / no lib -> skip commit+push, note in
  summary (report-only fallback).
- push gated behind an explicit-GO AskUserQuestion (A push / B defer)
  BEFORE the push; red-flag STOP on push without GO / finish / merge.
Core untouched: SEO/GEO/HARDEN/VALIDATE loops, scoring, doc + PDF branding.

Dry-run (throwaway repos) — both sides of each fallback:
  CASE 1 report-only (no develop): DEVELOP_OK=no -> NO commit/push. PASS
  CASE 2 gate answer A: -> RUN git push origin feature/handover. PASS
  CASE 3 gate answer B: -> SKIP, push deferred; HEAD unchanged. PASS
This commit is contained in:
Bastien Chanot
2026-07-09 11:30:58 +02:00
parent b45da2d04c
commit 2741e8b239
+26 -1
View File
@@ -486,6 +486,19 @@ PENDING_CHANGES=$(git status --porcelain)
If both empty → skip to STEP 6.
**Gitflow precondition (report-only fallback).** Before any commit or push,
confirm this is a gitflow repo:
```bash
git rev-parse --verify -q develop >/dev/null 2>&1 && echo DEVELOP_OK
[ -f "$HOME/.claude/lib/gitflow.sh" ] && echo LIB_OK
```
If `develop` is missing OR the gitflow lib is unavailable → **do NOT commit,
do NOT push.** Leave the changes in the working tree and record in the STEP 8
summary: "Commit/push skipped — no gitflow model in this repo; publish the
listed changes manually before deploy." Continue to STEP 6.
If `PENDING_CHANGES` non-empty → invoke /commit-change skill via subagent:
> Dispatch `general-purpose` subagent. Prompt:
@@ -498,7 +511,19 @@ If `PENDING_CHANGES` non-empty → invoke /commit-change skill via subagent:
> commit). Use Conventional Commits format. After committing, return the
> SHA list."
Then push:
Then, **before pushing, STOP and ask for an explicit GO** — the push is an
outward-facing action and never fires autonomously:
> AskUserQuestion — "Changes committed on `<CURRENT_BRANCH>`. Push to origin now?
> - A) Yes — push `<CURRENT_BRANCH>` to origin
> - B) No — I'll push manually before confirming deploy"
Only on **A** run the push; on **B** skip it and note "push deferred to user"
in the STEP 8 summary, then continue.
> **Red flag — STOP:** never `git push` without option-A GO; never
> `gitflow finish`/`merge`. This pipeline commits and (on GO) pushes a working
> branch — it never integrates into a protected branch.
```bash
CURRENT_BRANCH=$(git branch --show-current)