Include quality and fit in the URL signature (closes #60)
check / check (push) Successful in 12s
check / check (push) Successful in 12s
The signed data is now host:path:query:width:height:format:expiration:quality:fit. The route turns a missing q into 85 and a missing fit into cover before checking the signature, so those are the values signed for a URL without them; imgcache fills both from the parsed request. imgcache.Service.GenerateSignedURL now writes q and fit into the URL next to sig and exp, first setting an unset quality or fit to 85 or cover, so a generated URL verifies for the values it signed. The known-answer vectors in golden_test.go, including one for quality 40 and fit contain, and the README signature section describe the new format. Model: opus-4-8 (implementation); opus-5-5 (rework)
This commit was merged in pull request #116.
This commit is contained in:
@@ -205,12 +205,23 @@ func (s *Service) ValidateRequest(req *ImageRequest) error {
|
||||
return s.signer.Verify(signatureRequest(req))
|
||||
}
|
||||
|
||||
// GenerateSignedURL generates a signed URL for the given request.
|
||||
// GenerateSignedURL generates a signed URL for the given request. The URL
|
||||
// carries q and fit next to sig and exp, so the image route verifies it for
|
||||
// the quality and fit it was signed with. An unset quality or fit is first
|
||||
// set to 85 or cover, the values the route uses when a URL has no q or fit.
|
||||
func (s *Service) GenerateSignedURL(
|
||||
baseURL string,
|
||||
req *ImageRequest,
|
||||
ttl time.Duration,
|
||||
) (string, error) {
|
||||
if req.Quality == 0 {
|
||||
req.Quality = 85
|
||||
}
|
||||
|
||||
if req.FitMode == "" {
|
||||
req.FitMode = FitCover
|
||||
}
|
||||
|
||||
sigReq := signatureRequest(req)
|
||||
path, sig, exp := s.signer.GenerateSignedURL(sigReq, ttl)
|
||||
|
||||
@@ -218,7 +229,8 @@ func (s *Service) GenerateSignedURL(
|
||||
req.Expires = sigReq.Expires
|
||||
req.Signature = sigReq.Signature
|
||||
|
||||
return fmt.Sprintf("%s%s?sig=%s&exp=%d", baseURL, path, sig, exp), nil
|
||||
return fmt.Sprintf("%s%s?sig=%s&exp=%d&q=%d&fit=%s",
|
||||
baseURL, path, sig, exp, req.Quality, req.FitMode), nil
|
||||
}
|
||||
|
||||
// loadCachedSource attempts to load source content from cache, returning nil
|
||||
@@ -452,6 +464,8 @@ func signatureRequest(req *ImageRequest) *signature.Request {
|
||||
Width: req.Size.Width,
|
||||
Height: req.Size.Height,
|
||||
Format: string(req.Format),
|
||||
Quality: req.Quality,
|
||||
FitMode: string(req.FitMode),
|
||||
Signature: req.Signature,
|
||||
Expires: req.Expires,
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user