Document and test the one-year max-age cap (closes #63)
check / check (push) Successful in 2m43s
check / check (push) Successful in 2m43s
The README said max-age is the seconds left until the URL's expiry, but a URL expiring more than a year away gets one year; it now says at most one year. A new case for an encrypted URL with a two-year TTL expects max-age=31536000. Model: opus-5-5
This commit is contained in:
@@ -102,9 +102,10 @@ than once, is refused with 400.
|
||||
|
||||
An image is served with `Cache-Control: public, max-age=<seconds>, immutable`.
|
||||
When the URL has an expiry (an `exp`, or the TTL of an encrypted URL),
|
||||
`max-age` is the whole seconds left until then, so no browser or proxy cache
|
||||
keeps the image after pixa would refuse the URL. A URL with no expiry gets one
|
||||
year. `immutable` only stops a client revalidating while its copy is fresh.
|
||||
`max-age` is the whole seconds left until then, at most one year, so no browser
|
||||
or proxy cache keeps the image after pixa would refuse the URL. A URL with no
|
||||
expiry gets one year. `immutable` only stops a client revalidating while its
|
||||
copy is fresh.
|
||||
|
||||
The login form (`POST /`) is limited to 5 attempts per minute per client
|
||||
address, counting an IPv6 client by its /64; an attempt over the limit is
|
||||
|
||||
Reference in New Issue
Block a user