Refuse an empty fit on /v1/image/ with 400 (closes #139)
check / check (push) Successful in 2m32s
check / check (push) Successful in 2m32s
A fit in the URL with an empty value (fit=) was treated as missing, so it was served as cover and verified against a signature made for cover. It is now a 400 naming fit, the same rule the route applies to an empty q. It is checked before the existing fit-mode check, which takes an empty fit as missing; any other value still goes through that check unchanged. Only a fit missing from the URL is cover. Model: opus-5-5
This commit is contained in:
@@ -132,7 +132,8 @@ Where:
|
||||
or `85` when the URL has no `q`; a request whose `q` is anything else is
|
||||
refused with 400
|
||||
- `fit` — the URL's `fit` query parameter (cover, contain, fill, inside,
|
||||
outside), or `cover` when the URL has no `fit`
|
||||
outside), or `cover` when the URL has no `fit`; a request whose `fit` is
|
||||
anything else, an empty `fit=` included, is refused with 400
|
||||
|
||||
**Example:** resize `https://cdn.example.com/photos/cat.jpg` to 800x600
|
||||
WebP with expiration 1704067200, default quality and fit:
|
||||
|
||||
Reference in New Issue
Block a user