314f6cf7f8
- README: purpose, hand-typeable fetch usage, naming + placeholder conventions - CONTRIBUTING: public-repo sanitization rule (procedures only, no particulars) - _template.ps1: iex-safe script convention (Read-Host, no param, admin check) - od-smb-cred.md: Open Dental SMB stored-credential fix - cg-disable.ps1: standalone Credential Guard disable + reboot Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
1.8 KiB
1.8 KiB
Contributing (note-to-self)
Solo-maintained. This file exists to keep future-me honest.
The rule
Procedures only. No particulars.
This repo is public-read. Anything that identifies a client or would let a reader act against a client environment goes to the private tier — no exceptions.
Never commit:
- Client / business names, site identifiers
- Hostnames, IPs, subnets, SSIDs, MAC addresses
- Usernames, account names, email addresses
- Passwords, keys, tokens, connection strings, license keys
- Screenshots, exports, logs, or config dumps containing any of the above
Instead use placeholders: <CLIENT>, <SERVER>, <SHARE>, <SHARE_USER>,
<USER>, <PASSWORD>. Filled-in versions live in the private tier
(private repo or Bitwarden secure note).
Where things go
| Content | Home |
|---|---|
| Generic procedure with placeholders | This repo |
| Anything needing a credential | Private tier |
| Client-specific config / values | Private tier |
| Any identifying detail | Private tier |
If a step can't be written without a real particular, it doesn't belong here — split the particular out to the private tier and reference it as a placeholder.
Before every commit
- Re-read the diff. Would a stranger learn who the client is, or how to reach their systems? If yes, stop.
- No real hostnames/IPs/users/passwords — placeholders only.
- No screenshots or pasted output with real data.
- Scripts prompt for client-specifics at run time; they don't hard-code them.
Scripts
Follow _template.ps1:
- Prompt for placeholders with
Read-Host— no editing before running, noparam()(can't pass args throughirm | iex). - Safe to run via
irm <url> | iexfrom our own server. - Confirm before anything destructive or that reboots.
- Check for admin explicitly (
#Requiresis not enforced underiex).