Refuse an unparseable exp with 400; log swallowed cache errors (closes #72)
check / check (push) Successful in 3m6s

An exp that was not a whole number, or empty, was ignored, so a URL for
a host that needs a signature got 401 as if it had no exp. It is now a
400 naming exp and the value; only an exp missing from the URL is
unchanged.

A failed variant .meta write, source metadata JSON write, Stats count
query, stats counter update, negative cache write or expired negative
cache delete was discarded without a trace. Each is now logged at warn
with the path or key and the error, and stays non-fatal. VariantStorage
takes the cache's logger for this. The metadata JSON write moved out of
StoreSource into writeMetadataSidecar to keep StoreSource within the
function length limit.

Model: opus-5-5
This commit is contained in:
2026-09-28 17:24:13 +00:00
parent dd2d256bc2
commit 0ec806fb67
6 changed files with 112 additions and 34 deletions
+3 -1
View File
@@ -127,7 +127,9 @@ Where:
- `width` — requested width in pixels, `0` for original
- `height` — requested height in pixels, `0` for original
- `format` — output format (jpeg, png, webp, avif, gif, orig)
- `expiration` — Unix timestamp when signature expires
- `expiration` — the URL's `exp` query parameter, the Unix timestamp when
the signature expires; a request whose `exp` is not a whole number, an
empty `exp=` included, is refused with 400
- `quality` — the URL's `q` query parameter, a whole number from 1 to 100,
or `85` when the URL has no `q`; a request whose `q` is anything else is
refused with 400