2 Commits
Author SHA1 Message Date
sneak 881446739e Refuse a q outside 1-100 on /v1/image/ with 400 (closes #134)
check / check (push) Successful in 3m44s
A q that was not a number or was outside 1-100 was dropped and 85 used,
so q=500 was served and verified against a signature made for 85. It is
now a 400 naming q and the value, read with the generator's quality
check; only a q missing from the URL is 85.

The route also refuses with 400 a query string that cannot be decoded
(r.URL.Query() drops such a pair, so q=80% arrived as no q) and any
parameter given more than once, which was read from its first value only
(q=80&q=500 was served at 80).

Model: opus-5-5
2026-09-28 15:20:43 +00:00
sneak c74a8d4499 test: /v1/image/ answers an invalid q with 400 (closes #134)
Route tests: a q that is not a whole number from 1 to 100, an empty one
included, is a 400 naming q and the value; a parameter given more than
once is a 400 naming it; a query string that cannot be decoded is a 400
showing it. On next each is served, at 85 or at the first value given.

Model: opus-5-5
2026-09-28 15:20:43 +00:00
@@ -309,7 +309,6 @@ func TestHandleImage_InvalidQuery_Returns400(t *testing.T) {
{"q=0", `invalid q: must be from 1 to 100, got "0"`},
{"q=101", `invalid q: must be from 1 to 100, got "101"`},
{"q=", `invalid q: not a number, got ""`},
{"q=&q=500", `invalid q: given more than once`},
{"q=80&q=500", `invalid q: given more than once`},
{"q=80&q=", `invalid q: given more than once`},
{"fit=cover&fit=contain", `invalid fit: given more than once`},