Keep max-age within an expiring image URL's lifetime (closes #63)
Both image routes sent Cache-Control: public, max-age=31536000, immutable, so a browser or proxy could keep serving an image for a year after its signed or encrypted URL had expired. The header is now built from the request's Expires: max-age is the whole seconds left until the URL expires, never negative, or one year for a URL with no expiry. ToImageRequest now carries an encrypted URL's expiry onto the request, as the image route already does with exp. immutable stays: it only stops revalidation while a copy is fresh, and freshness now ends at the expiry. README.md documents the header. Model: opus-5-5
This commit is contained in:
@@ -95,7 +95,8 @@ type ImageRequest struct {
|
||||
FitMode FitMode
|
||||
// Signature is the HMAC signature for non-allowlisted hosts
|
||||
Signature string
|
||||
// Expires is the signature expiration timestamp
|
||||
// Expires is when the URL expires: the exp of a signed URL, or the expiry
|
||||
// of an encrypted URL; the zero time if it has none
|
||||
Expires time.Time
|
||||
// AllowHTTP indicates whether HTTP (non-TLS) is allowed for this request
|
||||
AllowHTTP bool
|
||||
|
||||
Reference in New Issue
Block a user