|
|
|
@@ -175,20 +175,21 @@ path under `/v1/` answers 200, in maintenance mode too.
|
|
|
|
|
with the page naming a field that is not valid; 500 when the URL cannot be
|
|
|
|
|
made.
|
|
|
|
|
- `GET /logout` — end the login session. Needs: nothing. Answers: 303 to `/`.
|
|
|
|
|
- `GET` or `HEAD` `/v1/image/<host>/<path>/<size>.<format>` — an image, fetched,
|
|
|
|
|
resized and converted (below). Needs: a signature, unless the host is
|
|
|
|
|
allowlisted (see Source Hosts). Answers: 200; 304 when `If-None-Match` matches
|
|
|
|
|
the image's `ETag`; 400 for a URL or parameter that is not valid, or for the
|
|
|
|
|
format `auto` an `Accept` header that is not valid; 406 for the format `auto`
|
|
|
|
|
when `Accept` allows none of the formats it chooses from; 401 for a missing or
|
|
|
|
|
wrong signature, a missing `exp` or an `exp` in the past; 403 when the
|
|
|
|
|
request's `Referer` names a host in `referer_blocklist`, checked before the
|
|
|
|
|
signature, the cache and the upstream fetch; 403 when the upstream host, or a
|
|
|
|
|
host it redirects to, is `localhost`, ends in `.localhost` or `.local`, or has
|
|
|
|
|
an address in a blocked network (see `blocked_networks`); 502 when the
|
|
|
|
|
upstream answered with an error status, and for 5 minutes after that for the
|
|
|
|
|
same source URL; 503 when pixa is busy or in maintenance mode; 500 for any
|
|
|
|
|
other failure.
|
|
|
|
|
- `GET` or `HEAD` `/v1/image/<host>/<path>/<size>.<format>`, or
|
|
|
|
|
`/v1/image/<host>/<path>/<size>` with no format — an image, fetched, resized
|
|
|
|
|
and converted (below). Needs: a signature, unless the host is allowlisted (see
|
|
|
|
|
Source Hosts). Answers: 200; 304 when `If-None-Match` matches the image's
|
|
|
|
|
`ETag`; 400 for a URL or parameter that is not valid, or for the format `auto`
|
|
|
|
|
an `Accept` header that is not valid; 406 for the format `auto` when `Accept`
|
|
|
|
|
allows none of the formats it chooses from; 401 for a missing or wrong
|
|
|
|
|
signature, a missing `exp` or an `exp` in the past; 403 when the request's
|
|
|
|
|
`Referer` names a host in `referer_blocklist`, checked before the signature,
|
|
|
|
|
the cache and the upstream fetch; 403 when the upstream host, or a host it
|
|
|
|
|
redirects to, is `localhost`, ends in `.localhost` or `.local`, or has an
|
|
|
|
|
address in a blocked network (see `blocked_networks`); 502 when the upstream
|
|
|
|
|
answered with an error status, and for 5 minutes after that for the same
|
|
|
|
|
source URL; 503 when pixa is busy or in maintenance mode; 500 for any other
|
|
|
|
|
failure.
|
|
|
|
|
- `GET` or `HEAD` `/v1/e/<token>/<name>` — an image through an encrypted URL
|
|
|
|
|
(see Encrypted URLs). Needs: nothing but the URL. Answers: 200; 304 when
|
|
|
|
|
`If-None-Match` matches the image's `ETag`; 400 for a token that does not
|
|
|
|
|