Refuse an unparseable exp with 400; log swallowed cache errors (closes #72)
check / check (push) Successful in 3m6s

An exp that was not a whole number, or empty, was ignored, so a URL for
a host that needs a signature got 401 as if it had no exp. It is now a
400 naming exp and the value; only an exp missing from the URL is
unchanged.

A failed variant .meta write, source metadata JSON write, Stats count
query, stats counter update, negative cache write or expired negative
cache delete was discarded without a trace. Each is now logged at warn
with the path or key and the error, and stays non-fatal. VariantStorage
takes the cache's logger for this. The metadata JSON write moved out of
StoreSource into writeMetadataSidecar to keep StoreSource within the
function length limit.

Model: opus-5-5
This commit is contained in:
2026-09-28 17:24:13 +00:00
parent dd2d256bc2
commit 0ec806fb67
6 changed files with 112 additions and 34 deletions
+9
View File
@@ -30,6 +30,15 @@ exhaustion
# Completed Steps
- 2026-09-28 refuse an unparseable `exp` on `/v1/image/` and log swallowed
cache errors (closes #72): an `exp` in the URL that is not a whole
number, an empty `exp=` included, is a 400 naming `exp` and the value,
instead of being ignored and answered with 401 as if the URL had no
`exp`; only an `exp` missing from the URL is unchanged; `README.md` says
so where it documents `exp`. A failed variant `.meta` write, source
metadata JSON write, `Stats` count query, stats counter update, negative
cache write or expired negative cache delete is now logged at `warn`
with the path or key and the error, and stays non-fatal.
- 2026-09-28 refuse an empty `fit` on `/v1/image/` (closes #139): a
`fit` in the URL with an empty value (`fit=`) is a 400 naming `fit`,
instead of being served as `cover` and verified against a signature