#!/bin/sh
set -eu
git init --bare /tmp/remote.git >/dev/null
cp /opt/gitleaks/hooks/gitleaks-pre-receive /tmp/remote.git/hooks/pre-receive
git init -b main /tmp/source >/dev/null
cd /tmp/source
git config user.name 'Offline test'
git config user.email test@localhost.localdomain
git remote add origin /tmp/remote.git
echo 'Clean offline fixture' > README.md
git add .
git commit -m clean >/dev/null
git push origin main
echo 'PASS: clean push with no network'
printf 'github_token = "ghp_%s"\n' '7zX9aB2cD4eF6gH8jK0mN3pQ5rS1tU9vW2yZ' > fixture.txt
git add .
git commit -m 'synthetic secret' >/dev/null
if git push origin main > /tmp/rejected.log 2>&1; then
    echo 'FAIL: secret accepted' >&2
    exit 1
fi
cat /tmp/rejected.log
grep -q 'Push rejected: Gitleaks' /tmp/rejected.log
echo 'PASS: secret rejected with no network'
