ADR 0009: Clarify VM18 before designing signage
- Status: accepted clarification gate
- Date: 2026-08-21
Scope note, 2026-09-07
The backlog row this ADR came from used the word “kiosk” for two unrelated things. They are now separate, and this gate covers only one of them.
- Kiosk mode — a simplified, authenticated backoffice at
/kioskfor an ordinary operator — was defined and delivered as a core surface. It needs no product or legal gate: it is a narrowing of the existing backoffice under the existing ACL, with no unattended display, no paired device and no scheduled content. See Kiosk mode and the complete reference § 30. Nothing in it reopens this ADR. - VM18 / digital signage — unattended public display of scheduled content on physical screens — remains blocked by the gate below.
Read “kiosk-like” in the context below as signage, not as kiosk mode.
Context
The backlog asks for a customizable kiosk-like graphic system for “VM18/digital signage”. The repository contains no definition of VM18, target device, display contract, content policy, jurisdiction, or product owner. VM18 could mean age-restricted content, a hardware/device model, a format, or another business term. Those interpretations lead to materially different legal, security, accessibility, offline and interaction requirements.
Decision
Do not select a data model, module API, theme, device protocol, age gate, or
publication workflow until the clarification record in
doc/public/en/architecture/evaluations/signage.md is completed and approved.
If VM18 means age-restricted content, product/legal direction is mandatory before even a disposable implementation. An unattended display cannot be assumed to perform identity or age verification, and a cosmetic acknowledgement must not be represented as a compliant age gate.
Consequences
No Signage module, migration, route, template, device credential, analytics, tracking, or content classification is added in 0.26.0. The gate prevents a theme-specific kiosk hack and records the exact inputs needed for a bounded future architecture.
After approval, the implementation plan may evaluate an optional Signage module with channels, screens, versioned playlists/layouts, schedules and immutable signed display manifests, reusing Page, Widget, Media, Menu and Calendar only where semantics match. This is a candidate shape, not pre-approved scope.