fix(overrides): refuse a save that would drop tokens, and keep the file path out of errors - #701
Merged
Conversation
…le path out of errors A save with an unknown token name or a value the writer strips answered 200 with written set to the input size, and the audit entry listed tokens that never reached the file. It now answers 400 naming those tokens and writes nothing. A write failure answers a generic message instead of the exception text, which carried the absolute file path. Fixes #694
Contributor
Quality Report — ConductionNL/thematiq @
|
| Check | PHP | Vue | Security | License | Tests |
|---|---|---|---|---|---|
| lint | ✅ | ||||
| phpcs | ✅ | ||||
| phpmd | ✅ | ||||
| psalm | ✅ | ||||
| phpstan | ✅ | ||||
| phpmetrics | ✅ | ||||
| eslint | ✅ | ||||
| stylelint | ✅ | ||||
| build | ✅ | ||||
| check-manifest | ✅ | ||||
| test-l10n | ✅ | ||||
| format | ✅ | ||||
| composer | ✅ | ✅ 107/107 | |||
| npm | ✅ | ✅ 2/2 | |||
| app:check-code | ⏭️ | ||||
| info.xml | ✅ | ||||
| REUSE | ✅ | ||||
| lockfile sync | ✅ | ||||
| PHPUnit | ✅ | ||||
| Newman | ✅ | ||||
| Playwright | ⏭️ deferred: E2E runs locally and on the promotion path only. This pull request targets development, so the suite is asked once per promotion into beta and main rather than once per push per open pull request. Run it on any branch from the Actions tab, or locally with npx playwright test. |
||||
| Hydra gates | ✅ |
Quality workflow — 2026-09-28 15:12 UTC
Download the full PDF report from the workflow artifacts.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Saving token overrides answered 200 while dropping tokens, and a write failure returned the absolute file path.
The defect
POST /settings/overridespassed the input toCustomOverridesService::write(), which silently dropped unknown token names and values containing{,},;or comment markers. The answer was still 200 withwrittenset to the size of the input, and the audit entry recorded the raw input asnew. A write failure returned the exception text, which names the file path.The test that was red
tests/Unit/Controller/OverridesControllerValidationTest.phpdrives the controller with the realCustomOverridesServicewriting into a temporary app directory. On development,testUnknownTokenIs400andtestWrongValueIs400got 200,testNonStringValueIs400hit a type error, andtestWriteFailureHidesPathfailed.testValidSaveReportsAndAuditsWhatWasWrittenguards the happy path.The fix
CustomOverridesService::findRejected()lists every tokenwrite()would not persist, with the reason: not in the registry, not a string, or a value that would break out of the:rootblock. The writer and the check share oneisUnsafeValue().setOverrides()refuses the whole save with 400 when anything is rejected, naming the tokens inerrorandrejected, and writes nothing. Sowrittenand the audit entry now describe what reached the file.The editor already shows
data.errorwhenstatusis notok, so the admin now sees which tokens were refused. One side effect to know about: a stale token left incustom-overrides.cssfrom an older registry now makes a save through the token set switcher (which merges the stored overrides) answer 400 naming that token, where it used to be dropped without a word.The typed value checks from
authoring-token-value-typestask 2.1 (a wrong colour or length) are not part of this change; this closes the silent drop and the path leak.Verified
composer check:strict: exit 0 (itstest:allskips in a bare clone, so PHPUnit ran separately).lib/privateon the autoloader: 855 tests, 11 errors and 7 failures, the same 18 names as on development 551954e (missing Symfony and server classes outside a Nextcloud tree).npm run lint,format,test:l10n,check:l10n-js,check:manifest,test:unit: all exit 0.--scope-to-diff: exit 0.Fixes #694