Refuse a q outside 1-100 on /v1/image/ with 400 (closes #134)
check / check (push) Successful in 3m10s

The route ignored a q that was not a number or was outside 1-100 and
used 85, so q=banana or q=500 was served as if q were absent and
verified against a signature made for 85.

It now reads q with the check the URL generator uses for its quality
field (parseFormInt with minQuality and maxQuality, default
encurl.DefaultQuality) and answers anything else with a 400 naming q
and the value. An absent or empty q is still 85. README.md states the
range.

Model: opus-5-5
This commit is contained in:
2026-09-28 14:00:02 +00:00
parent 8da2d18545
commit 14bde63d0d
4 changed files with 27 additions and 18 deletions
+6
View File
@@ -30,6 +30,12 @@ exhaustion
# Completed Steps
- 2026-09-28 refuse an invalid `q` on `/v1/image/` (closes #134): a `q`
that is not a whole number from 1 to 100 is a 400 naming `q` and the
value, instead of being served at the default 85; the route reads `q`
with the generator's quality check (`parseFormInt` with `minQuality`
and `maxQuality`); an absent or empty `q` is still 85; `README.md`
states the range.
- 2026-09-28 start on a fresh upaas volume (closes #129): the image
starts as root only to give `/var/lib/pixa` to `pixad` when `pixad`
does not own it (`deploy/docker-entrypoint.sh`), then runs the server