Refuse a q outside 1-100 on /v1/image/ with 400 (closes #134)
check / check (push) Successful in 13s
check / check (push) Successful in 13s
A q that was not a number or was outside 1-100 was dropped and 85 used, so q=500 was served and verified against a signature made for 85. It is now a 400 naming q and the value, read with the generator's quality check; only a q missing from the URL is 85. The route also refuses with 400 a query string that cannot be decoded (r.URL.Query() drops such a pair, so q=80% arrived as no q) and any parameter given more than once, which was read from its first value only (q=80&q=500 was served at 80). Model: opus-5-5
This commit was merged in pull request #138.
This commit is contained in:
@@ -94,6 +94,9 @@ In-process caching of request-to-output mappings targets 1-5k r/s.
|
||||
|
||||
Images are only fetched from origins using TLS with valid certificates.
|
||||
|
||||
A request whose query string cannot be decoded, or gives any parameter more
|
||||
than once, is refused with 400.
|
||||
|
||||
- `<format>`: one of `orig`, `png`, `jpeg`, `webp`
|
||||
- `<size>`: `orig` or `<width>x<height>` (e.g. `800x600`)
|
||||
|
||||
@@ -125,8 +128,9 @@ Where:
|
||||
- `height` — requested height in pixels, `0` for original
|
||||
- `format` — output format (jpeg, png, webp, avif, gif, orig)
|
||||
- `expiration` — Unix timestamp when signature expires
|
||||
- `quality` — the URL's `q` query parameter (1-100), or `85` when the URL
|
||||
has no `q`
|
||||
- `quality` — the URL's `q` query parameter, a whole number from 1 to 100,
|
||||
or `85` when the URL has no `q`; a request whose `q` is anything else is
|
||||
refused with 400
|
||||
- `fit` — the URL's `fit` query parameter (cover, contain, fill, inside,
|
||||
outside), or `cover` when the URL has no `fit`
|
||||
|
||||
|
||||
Reference in New Issue
Block a user