Refuse an unparseable exp with 400; log swallowed cache errors (closes #72)
check / check (push) Successful in 3m6s
check / check (push) Successful in 3m6s
An exp that was not a whole number, or empty, was ignored, so a URL for a host that needs a signature got 401 as if it had no exp. It is now a 400 naming exp and the value; only an exp missing from the URL is unchanged. A failed variant .meta write, source metadata JSON write, Stats count query, stats counter update, negative cache write or expired negative cache delete was discarded without a trace. Each is now logged at warn with the path or key and the error, and stays non-fatal. VariantStorage takes the cache's logger for this. The metadata JSON write moved out of StoreSource into writeMetadataSidecar to keep StoreSource within the function length limit. Model: opus-5-5
This commit is contained in:
@@ -116,11 +116,11 @@ func (s *Handlers) parseImageRequest(
|
||||
|
||||
req.Signature = query.Get("sig")
|
||||
|
||||
if expStr := query.Get("exp"); expStr != "" {
|
||||
exp, parseErr := strconv.ParseInt(expStr, 10, 64)
|
||||
if parseErr == nil {
|
||||
req.Expires = time.Unix(exp, 0)
|
||||
}
|
||||
req.Expires, err = parseExpires(query)
|
||||
if err != nil {
|
||||
s.respondError(w, err.Error(), http.StatusBadRequest)
|
||||
|
||||
return nil, false
|
||||
}
|
||||
|
||||
// Parse optional quality and fit params. Only a q missing from the URL is
|
||||
@@ -174,6 +174,26 @@ func (s *Handlers) parseImageRequest(
|
||||
return req, true
|
||||
}
|
||||
|
||||
// parseExpires reads the exp query parameter, a Unix time in seconds. An exp
|
||||
// missing from the URL gives the zero time, which the signature check takes
|
||||
// as no expiration. An exp in the URL that is not a whole number, an empty
|
||||
// one included, is an error naming exp and the value.
|
||||
func parseExpires(query url.Values) (time.Time, error) {
|
||||
if !query.Has("exp") {
|
||||
return time.Time{}, nil
|
||||
}
|
||||
|
||||
expStr := query.Get("exp")
|
||||
|
||||
exp, err := strconv.ParseInt(expStr, 10, 64)
|
||||
if err != nil {
|
||||
return time.Time{}, fmt.Errorf("%w exp: not a number, got %q",
|
||||
errInvalidFormField, expStr)
|
||||
}
|
||||
|
||||
return time.Unix(exp, 0), nil
|
||||
}
|
||||
|
||||
// respondImageError maps image retrieval errors to HTTP responses.
|
||||
func (s *Handlers) respondImageError(
|
||||
w http.ResponseWriter, req *imgcache.ImageRequest, err error,
|
||||
|
||||
Reference in New Issue
Block a user