Refuse an empty fit on /v1/image/ with 400 (closes #139)
check / check (push) Successful in 13s

A fit in the URL with an empty value (fit=) was treated as missing, so
it was served as cover and verified against a signature made for cover.
It is now a 400 naming fit, the same rule the route applies to an empty
q. It is checked before the existing fit-mode check, which takes an
empty fit as missing; any other value still goes through that check
unchanged. Only a fit missing from the URL is cover.

Model: opus-5-5
This commit was merged in pull request #140.
This commit is contained in:
2026-09-28 18:07:11 +02:00
parent 45869572ff
commit f149813c7e
4 changed files with 54 additions and 3 deletions
+8 -2
View File
@@ -144,8 +144,14 @@ func (s *Handlers) parseImageRequest(
return nil, false
}
if fit := query.Get("fit"); fit != "" {
req.FitMode = imgcache.FitMode(fit)
// Only a fit missing from the URL is cover. A fit in the URL that is not a
// fit mode is refused by the fit-mode check below; that check would take an
// empty fit as missing, so an empty one is refused here.
req.FitMode = imgcache.FitMode(query.Get("fit"))
if query.Has("fit") && req.FitMode == "" {
s.respondError(w, `invalid fit: not a fit mode, got ""`, http.StatusBadRequest)
return nil, false
}
// Default fit mode if not set