Web Forms guided setup

Configure a bounded static review, pause deliberately, and resume from checked state.

TraceMap ships a terminal wizard over shared persisted wizard state. It is not a GUI, desktop setup screen, browser wizard, or automatic customer onboarding service.

Public claim level: shipped for the bounded terminal workflow on main. Checked-in synthetic examples remain demo. TraceMap does not launch the website or execute SQL.

1. Choose the input

Pick one website context; do not imply whole-solution onboarding.

Website folder

Choose a folder with the expected Web Forms structure. If the folder contains C# or VB projects, select the intended project explicitly.

Solution

Choose a solution, then make an explicit selection of one matching website root and its project when project-backed, or its projectless Web Site entry when applicable. Ambiguity is a stop condition; the wizard does not register or scan every project automatically.

C# or VB project

Select one explicit .csproj or .vbproj. Project-defined references and tasks can still involve dependencies, but the selected website target remains explicit.

Projectless Web Site

Choose projectless mode when no project file owns the site. Static syntax and structural evidence remain available; publication is a separate Windows operator step.

2. Bound the forms

Choose all discovered forms or a deliberate subset.

AllUses the bounded discovered form inventory. “All” does not establish complete application or historical compiler-input coverage.
SelectedCreates the bounded forms.txt editing surface. It is the normal human-edited file; generated JSON is not.
PausedThe terminal exits with code 2 so the operator can edit the list. This is a saved pause, not success or failure.
Continue--continue resumes from saved configuration after revalidating the selection and inputs. A blank, missing, or comments-only file is regenerated as a template and pauses again with code 2; it is not a failure and empty never means all. An edited selection that escapes the root, duplicates a form, or collides by case fails closed.
Private stateSaved configuration may contain paths and copied binaries. It stays private operator state and is not public evidence or proof that setup succeeded.

3. Cross execution boundaries deliberately

Project builds and projectless publication have different authority.

Project-backed build consent

Before the operator types build, the terminal shows the trusted absolute tool path, version-probe arguments, build arguments, and working directory. The executable version itself is probed only after consent as part of the authorized build step.

MSBuild tasks may execute code, restore dependencies, and change build folders or source-controlled content. Declining consent executes no build.

Windows-required legacy projects

Classic, non-SDK, and .NET Framework C# or VB targets that resolve to Windows MSBuild are Windows-only. On another host, WINDOWS_BUILD_REQUIRED is a stop condition—not reduced cross-platform build support.

Projectless ASP.NET compilation

Compilation remains an external Windows operator step. Typing ready declares that publication was prepared; it is not authenticated compiler provenance and does not prove publication succeeded or came from the declared source.

4. Resume, add, or repair

Choose the operation that matches the state change.

--continueRevalidates the retained configuration, inputs, hashes, inventory, and staged copies before resuming the current project.
--add-projectAdds another website explicitly. It is not automatic solution-wide registration.
--repair-projectAfter preview and confirmation, resets one selected project's setup cursor while preserving other projects and the historical state described by the workflow contract.
Repair limitRepair does not fix customer code, install missing tools, recover source, restore lost provenance, or repair corrupt root configuration. Use manual correction or a new configuration root where required.

5. Read static evidence

Completion means retained static reports verified—not runtime behavior observed.

Evidence vocabulary

Review rule IDs, emitted evidence tiers, coverage labels, repository and commit identity, extractor versions, spans, limitations, and explicit gaps. A weaker hop remains weaker.

Evidence model · Gap register

Coverage posture

Partial, reduced, unresolved, unsupported, paused, declined, failed, external-step, and completed-report states remain distinct. A failed build is not clean evidence.

Reduced coverage · Static versus runtime

Stop conditions and owner handoff

Do not convert a blocked prerequisite into a softer success label.

Operator stops

Stop for declined consent, changed inputs, an invalid edited forms.txt, ambiguous targets, missing tools, or WINDOWS_BUILD_REQUIRED. A blank or missing selection file is instead a template-regeneration pause. The operator decides whether to correct the input, obtain the required host/tool, or abandon the attempt.

Build or repository owner stops

Stop for failed external publication, corrupt root state, unavailable source, or unverifiable provenance. A build or repository owner must supply authorized evidence or choose a new bounded root.

Review owner stops

Stop for partial analysis, explicit gaps, or retained reports that cannot be verified. The review owner decides whether the remaining coverage is usable; TraceMap does not grant release approval.

What this shipped workflow does not prove

It does not prove runtime page execution, event firing, branch feasibility, database or SQL execution, service reachability, production usage, deployment state, publication success, selected implementation, customer compatibility, migration parity, release approval, safety, complete coverage, automatic source acquisition, cross-service tracing, or authenticated build provenance.

Public pages do not contain customer screenshots, private source or markup, raw SQL, configuration values, credentials, connection material, local paths, private identities, raw fact streams, SQLite, analyzer output, copied binaries, or private validation details. TraceMap does not use LLM calls, embeddings, vector databases, or prompt-based classification for this evidence.