Refuse an empty fit on /v1/image/ with 400 (closes #139)
check / check (push) Successful in 13s
check / check (push) Successful in 13s
A fit in the URL with an empty value (fit=) was treated as missing, so it was served as cover and verified against a signature made for cover. It is now a 400 naming fit, the same rule the route applies to an empty q. It is checked before the existing fit-mode check, which takes an empty fit as missing; any other value still goes through that check unchanged. Only a fit missing from the URL is cover. Model: opus-5-5
This commit was merged in pull request #140.
This commit is contained in:
@@ -30,6 +30,12 @@ exhaustion
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-09-28 refuse an empty `fit` on `/v1/image/` (closes #139): a
|
||||
`fit` in the URL with an empty value (`fit=`) is a 400 naming `fit`,
|
||||
instead of being served as `cover` and verified against a signature
|
||||
made for `cover`; only a `fit` missing from the URL is still `cover`;
|
||||
any other value still goes through the existing fit-mode check;
|
||||
`README.md` says so where it documents `fit`.
|
||||
- 2026-09-28 refuse an invalid `q` on `/v1/image/` (closes #134): a `q`
|
||||
that is not a whole number from 1 to 100, an empty `q` included, is a
|
||||
400 naming `q` and the value, instead of being served at the default
|
||||
|
||||
Reference in New Issue
Block a user