Commit Graph
2 Commits
Author SHA1 Message Date
sneak dd2d256bc2 Test that an unparseable exp on /v1/image/ is refused with 400 (closes #72)
check / check (push) Failing after 1m57s
An exp that is not a whole number, or an empty exp=, is ignored today,
so a URL for a host that needs a signature gets 401 as if it had no exp.
This test asks for a 400 naming exp and the value instead; it fails
until the route refuses it. A URL without exp still gets 401.

Model: opus-5-5
2026-09-28 17:16:53 +00:00
clawbot db784bf561 Include quality and fit in the URL signature (closes #60)
check / check (push) Successful in 12s
The signed data is now
host:path:query:width:height:format:expiration:quality:fit. The route
turns a missing q into 85 and a missing fit into cover before checking
the signature, so those are the values signed for a URL without them;
imgcache fills both from the parsed request.

imgcache.Service.GenerateSignedURL now writes q and fit into the URL
next to sig and exp, first setting an unset quality or fit to 85 or
cover, so a generated URL verifies for the values it signed.

The known-answer vectors in golden_test.go, including one for quality
40 and fit contain, and the README signature section describe the new
format.

Model: opus-4-8 (implementation); opus-5-5 (rework)
2026-09-28 13:02:21 +02:00