Refuse an empty fit on /v1/image/ with 400 (closes #139)
check / check (push) Successful in 2m32s
check / check (push) Successful in 2m32s
A fit in the URL with an empty value (fit=) was treated as missing, so it was served as cover and verified against a signature made for cover. It is now a 400 naming fit, the same rule the route applies to an empty q. It is checked before the existing fit-mode check, which takes an empty fit as missing; any other value still goes through that check unchanged. Only a fit missing from the URL is cover. Model: opus-5-5
This commit is contained in:
@@ -144,8 +144,14 @@ func (s *Handlers) parseImageRequest(
|
||||
return nil, false
|
||||
}
|
||||
|
||||
if fit := query.Get("fit"); fit != "" {
|
||||
req.FitMode = imgcache.FitMode(fit)
|
||||
// Only a fit missing from the URL is cover. A fit in the URL that is not a
|
||||
// fit mode is refused by the fit-mode check below; that check would take an
|
||||
// empty fit as missing, so an empty one is refused here.
|
||||
req.FitMode = imgcache.FitMode(query.Get("fit"))
|
||||
if query.Has("fit") && req.FitMode == "" {
|
||||
s.respondError(w, `invalid fit: not a fit mode, got ""`, http.StatusBadRequest)
|
||||
|
||||
return nil, false
|
||||
}
|
||||
|
||||
// Default fit mode if not set
|
||||
|
||||
Reference in New Issue
Block a user