Refuse a q outside 1-100 on /v1/image/ with 400 (closes #134)
check / check (push) Successful in 2m34s
check / check (push) Successful in 2m34s
The route ignored a q that was not a number or was outside 1-100 and used 85, so q=banana or q=500 was served as if q were absent and verified against a signature made for 85. It now reads q with the check the URL generator uses for its quality field (parseFormInt with minQuality and maxQuality, default encurl.DefaultQuality) and answers anything else with a 400 naming q and the value. That check takes an empty value as missing, so an empty q in the URL is refused before it. The query string is read with url.ParseQuery, since r.URL.Query() drops a pair it cannot decode, such as q=80%; one that cannot be decoded is a 400 showing it. Only a q missing from the URL is 85. README.md states the range. Model: opus-5-5
This commit is contained in:
@@ -125,8 +125,9 @@ Where:
|
||||
- `height` — requested height in pixels, `0` for original
|
||||
- `format` — output format (jpeg, png, webp, avif, gif, orig)
|
||||
- `expiration` — Unix timestamp when signature expires
|
||||
- `quality` — the URL's `q` query parameter (1-100), or `85` when the URL
|
||||
has no `q`
|
||||
- `quality` — the URL's `q` query parameter, a whole number from 1 to 100,
|
||||
or `85` when the URL has no `q`; a request whose `q` is anything else is
|
||||
refused with 400
|
||||
- `fit` — the URL's `fit` query parameter (cover, contain, fill, inside,
|
||||
outside), or `cover` when the URL has no `fit`
|
||||
|
||||
|
||||
Reference in New Issue
Block a user