Commit Graph
2 Commits
Author SHA1 Message Date
clawbot 20a46e96a2 Test ETag, 304 and HEAD on /v1/e/
An image served through an encrypted URL must carry an ETag, a request
whose If-None-Match is that ETag must get 304 with no body, HEAD must get
200 with the headers and no body, and the server must route HEAD on
/v1/e/ to its handler instead of answering 405.

Model: opus-5-5
2026-10-04 08:40:15 +00:00
clawbot f8d40b89a7 Validate dimensions and fit mode on encrypted URLs (closes #62)
check / check (push) Successful in 3m6s
The encrypted /v1/e/ route used the decrypted payload unchecked, so a
token could request an over-limit size or an unknown fit mode; the
generator turned unparseable numbers into 0.

imgcache.ValidateDimension alone holds the MaxDimension bound and is
used by the path parser, by the new ValidateImageRequest (which adds
ValidateFitMode) and by the generator. Both image routes call
ValidateImageRequest, so each answers 400. The generator answers 400
naming the field for a width or height that is not a number or fails
that check, a quality that is not a number from 1 to 100, a ttl that is
not a number from 0 to the largest the expiry calculation can hold, or
an unknown fit. Empty quality is 85; empty ttl never expires. The
form's size inputs stop at 8192.

Model: opus-4-8 (implementation); opus-5-5 (rework)
2026-09-28 15:24:32 +02:00