Code reading on 28 September 2026 at fd992ea, not checked live. The endpoint is admin-only, so the impact is small.
What happens
POST /settings/overrides (OverridesController::setOverrides(), lib/Controller/OverridesController.php:138-162, #[AuthorizedAdminSetting]) has three faults.
- A write failure returns the exception text (
:149-151). CustomOverridesService::writeFile() puts the absolute file path in that text (lib/Service/CustomOverridesService.php:202-214).
- Unknown token names are dropped by
filterEditable() (CustomOverridesService.php:172-181). Values containing {, }, ; or comment markers are dropped by buildDeclarationLines() (:253-255). The endpoint still answers 200, with written set to the size of the input rather than what was written (OverridesController.php:162). The token editor spec asks for 400 on an excluded token (openspec/specs/token-editor-ui/spec.md:65-70).
- The audit entry records the raw input as
new (:153-160), so the log lists tokens that never reached the file.
Already specified
openspec/changes/authoring-token-value-types/ task 2.1 returns 400 for an unknown name or a wrong value, and a generic message on a write failure.
Live check
As an admin, POST /index.php/apps/thematiq/settings/overrides with one registry token and one unknown name, and confirm whether the answer is 200 with written: 2 and whether the audit entry lists both.
Found by the thematiq OpenSpec pass lane (read-only notes, 27 September 2026).
Code reading on 28 September 2026 at fd992ea, not checked live. The endpoint is admin-only, so the impact is small.
What happens
POST /settings/overrides(OverridesController::setOverrides(),lib/Controller/OverridesController.php:138-162,#[AuthorizedAdminSetting]) has three faults.:149-151).CustomOverridesService::writeFile()puts the absolute file path in that text (lib/Service/CustomOverridesService.php:202-214).filterEditable()(CustomOverridesService.php:172-181). Values containing{,},;or comment markers are dropped bybuildDeclarationLines()(:253-255). The endpoint still answers 200, withwrittenset to the size of the input rather than what was written (OverridesController.php:162). The token editor spec asks for 400 on an excluded token (openspec/specs/token-editor-ui/spec.md:65-70).new(:153-160), so the log lists tokens that never reached the file.Already specified
openspec/changes/authoring-token-value-types/task 2.1 returns 400 for an unknown name or a wrong value, and a generic message on a write failure.Live check
As an admin, POST
/index.php/apps/thematiq/settings/overrideswith one registry token and one unknown name, and confirm whether the answer is 200 withwritten: 2and whether the audit entry lists both.Found by the thematiq OpenSpec pass lane (read-only notes, 27 September 2026).