Summary
Duration configuration parsing discards time.ParseDuration errors and always stores the returned value. Invalid input therefore appears to succeed and becomes a zero duration.
Affected code
internal/config/settings.go:270 — ignores the parse error
Impact
A typo in timeout or consent-lifetime configuration is accepted but changes behavior to an immediate/zero timeout or another fallback path. The resulting behavior is difficult to diagnose because the setter reported success.
Suggested correction
Return the parsing error with the key and invalid value, and do not mutate configuration when validation fails. Apply any domain constraints (for example, positive timeouts) explicitly after parsing.
Acceptance criteria
- Invalid duration syntax returns an actionable error.
- Configuration remains unchanged after a failed update.
- Zero/negative durations are either deliberately supported and documented or rejected per setting.
- Table tests cover valid units, malformed values, zero, and negative values.
Summary
Duration configuration parsing discards
time.ParseDurationerrors and always stores the returned value. Invalid input therefore appears to succeed and becomes a zero duration.Affected code
internal/config/settings.go:270— ignores the parse errorImpact
A typo in timeout or consent-lifetime configuration is accepted but changes behavior to an immediate/zero timeout or another fallback path. The resulting behavior is difficult to diagnose because the setter reported success.
Suggested correction
Return the parsing error with the key and invalid value, and do not mutate configuration when validation fails. Apply any domain constraints (for example, positive timeouts) explicitly after parsing.
Acceptance criteria