164 a credential that must be accepted is minted anyway 165 one accepted value must be accepted once per consumer 166 a requirement cannot be optional 167 code several modules share has no home 168 a setting reaches every file and every contribution
1.5 KiB
1.5 KiB
status, opened, located-in, fixed-by, amended-design
| status | opened | located-in | fixed-by | amended-design | ||||
|---|---|---|---|---|---|---|---|---|
| open | 2026-09-30 |
|
168 — A setting reaches every file and every contribution
What was observed
Settings merge key by key into every "merge": "json" file of a module and every contribution
it makes; a provider's settings are also laid over what it serves. Seen on ace:
- searxng's
endpointsand a routelabelland in searxng's ownsettings.yml; nodered'stimeZoneandmqttkeys land in mosquitto's grants file; keycloak'sissuerlands in itspostgres-databaseandroutecontributions. - every consumer's
plex-apibinding carries plex'sendpointsandexposesettings — and a provider setting namedportwould silently redirect every consumer. - a module cannot have two configurable files: searxng's sidecar config had to stop being mergeable so searxng's keys would not reach it.
Harmless today only because every receiver happens to ignore unknown keys.
What would be right
A setting is aimed: at a file (by resource id), at a contribution (by requirement), or at what the module serves — declared settable by the module (ADR 0046 already says settings drive "the fields the manifest marks") — and an unaimed key is refused like any unknown setting.