Skip to content

Saving token overrides answers 200 while dropping tokens, and leaks a path #694

Description

@rubenvdlinde

Code reading on 28 September 2026 at fd992ea, not checked live. The endpoint is admin-only, so the impact is small.

What happens

POST /settings/overrides (OverridesController::setOverrides(), lib/Controller/OverridesController.php:138-162, #[AuthorizedAdminSetting]) has three faults.

  • A write failure returns the exception text (:149-151). CustomOverridesService::writeFile() puts the absolute file path in that text (lib/Service/CustomOverridesService.php:202-214).
  • Unknown token names are dropped by filterEditable() (CustomOverridesService.php:172-181). Values containing {, }, ; or comment markers are dropped by buildDeclarationLines() (:253-255). The endpoint still answers 200, with written set to the size of the input rather than what was written (OverridesController.php:162). The token editor spec asks for 400 on an excluded token (openspec/specs/token-editor-ui/spec.md:65-70).
  • The audit entry records the raw input as new (:153-160), so the log lists tokens that never reached the file.

Already specified

openspec/changes/authoring-token-value-types/ task 2.1 returns 400 for an unknown name or a wrong value, and a generic message on a write failure.

Live check

As an admin, POST /index.php/apps/thematiq/settings/overrides with one registry token and one unknown name, and confirm whether the answer is 200 with written: 2 and whether the audit entry lists both.

Found by the thematiq OpenSpec pass lane (read-only notes, 27 September 2026).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingtriageAwaiting triage

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions