Settings given as files: the _FILE form of every setting #87

Open
opened 2026-10-06 20:40:53 +02:00 by clawbot · 1 comment
Collaborator

"Configuration surface" in SPEC.md: every setting may instead be given as a file holding the value, named by the setting's name with _FILE added, such as SWWAF_ADMIN_TOKEN_FILE and SWWAF_METRICS_TOKEN_FILE, for secrets and long lists. "Deployment" says how an operator keeps a token file out of the app's reach. The tokens of #27 need it. One PR to next.

  • For every setting X, X_FILE names a file read once at start; its contents are the value, with one trailing newline removed (so echo and editors work), and are checked exactly as X would be.
  • X and X_FILE both set, or a file that cannot be read, stops the start with a message naming the variable.
  • A token given as a file is masked in the logged configuration like one given directly; the log names the file.
  • SWWAF_LOG_REMOTE_TLS_CA_FILE, whose value is already a file, is not given a _FILE form of its own (SWWAF_LOG_REMOTE_TLS_CA_FILE_FILE); if #84 has not landed when this is built, whichever lands second sees to it.
  • README.md says so, with the token file example from "Deployment".

Definition of done: tests show a setting read from a file, the trailing newline removed and no more, both forms set stopping the start, an unreadable file stopping the start, and a token from a file masked in the log; each test failing with its rule broken; make check green; one PR to next, passed by a reviewer who did not write it.

Model: opus-5-5

"Configuration surface" in `SPEC.md`: every setting may instead be given as a file holding the value, named by the setting's name with `_FILE` added, such as `SWWAF_ADMIN_TOKEN_FILE` and `SWWAF_METRICS_TOKEN_FILE`, for secrets and long lists. "Deployment" says how an operator keeps a token file out of the app's reach. The tokens of https://git.eeqj.de/sneak/smallwebwaf/issues/27 need it. One PR to `next`. - For every setting `X`, `X_FILE` names a file read once at start; its contents are the value, with one trailing newline removed (so `echo` and editors work), and are checked exactly as `X` would be. - `X` and `X_FILE` both set, or a file that cannot be read, stops the start with a message naming the variable. - A token given as a file is masked in the logged configuration like one given directly; the log names the file. - `SWWAF_LOG_REMOTE_TLS_CA_FILE`, whose value is already a file, is not given a `_FILE` form of its own (`SWWAF_LOG_REMOTE_TLS_CA_FILE_FILE`); if https://git.eeqj.de/sneak/smallwebwaf/pulls/84 has not landed when this is built, whichever lands second sees to it. - `README.md` says so, with the token file example from "Deployment". Definition of done: tests show a setting read from a file, the trailing newline removed and no more, both forms set stopping the start, an unreadable file stopping the start, and a token from a file masked in the log; each test failing with its rule broken; `make check` green; one PR to `next`, passed by a reviewer who did not write it. Model: opus-5-5
clawbot self-assigned this 2026-10-06 20:40:53 +02:00
Author
Collaborator

Built in #89.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/smallwebwaf/pulls/89. Model: opus-5-5
Sign in to join this conversation.