4 Commits
Author SHA1 Message Date
clawbot 9742842975 Document and test the one-year max-age cap (closes #63)
check / check (push) Successful in 2m43s
The README said max-age is the seconds left until the URL's expiry, but a
URL expiring more than a year away gets one year; it now says at most one
year. A new case for an encrypted URL with a two-year TTL expects
max-age=31536000.

Model: opus-5-5
2026-09-29 01:26:21 +00:00
clawbot 0a0142d1af Keep max-age within an expiring image URL's lifetime (closes #63)
Both image routes sent Cache-Control: public, max-age=31536000,
immutable, so a browser or proxy could keep serving an image for a year
after its signed or encrypted URL had expired. The header is now built
from the request's Expires: max-age is the whole seconds left until the
URL expires, never negative, or one year for a URL with no expiry.
ToImageRequest now carries an encrypted URL's expiry onto the request,
as the image route already does with exp. immutable stays: it only stops
revalidation while a copy is fresh, and freshness now ends at the
expiry. README.md documents the header.

Model: opus-5-5
2026-09-29 01:25:25 +00:00
clawbot ac95c33cdb Test that max-age never outlives an expiring image URL (closes #63)
Route tests for both image routes. An image served through a signed URL
expiring in 60 seconds, or an encrypted URL with a 60 second TTL, must
get a max-age of at most 60. A URL with no expiry keeps one year. An
allowlisted URL whose exp has already passed, which is served without
checking exp, must get 0. The expiring cases fail until the fix that
follows.

Model: opus-5-5
2026-09-29 01:25:25 +00:00
sneak 05678eaae5 next -> main (1.0.0 milestone) (#118)
check / check (push) Successful in 12s
Reviewed-on: #118
2026-09-29 03:01:06 +02:00
2 changed files with 8 additions and 5 deletions
+4 -3
View File
@@ -102,9 +102,10 @@ than once, is refused with 400.
An image is served with `Cache-Control: public, max-age=<seconds>, immutable`.
When the URL has an expiry (an `exp`, or the TTL of an encrypted URL),
`max-age` is the whole seconds left until then, so no browser or proxy cache
keeps the image after pixa would refuse the URL. A URL with no expiry gets one
year. `immutable` only stops a client revalidating while its copy is fresh.
`max-age` is the whole seconds left until then, at most one year, so no browser
or proxy cache keeps the image after pixa would refuse the URL. A URL with no
expiry gets one year. `immutable` only stops a client revalidating while its
copy is fresh.
The login form (`POST /`) is limited to 5 attempts per minute per client
address, counting an IPv6 client by its /64; an attempt over the limit is
@@ -158,8 +158,9 @@ func TestHandleImage_AllowlistedHost_MaxAge(t *testing.T) {
}
// TestHandleImageEnc_MaxAge verifies that an image served through an encrypted
// URL with a 60 second TTL may be cached for at most those 60 seconds, and that
// one made without a TTL, which never expires, may be cached for a year.
// URL with a 60 second TTL may be cached for at most those 60 seconds, that one
// with a two-year TTL may be cached for a year, and that one made without a
// TTL, which never expires, may be cached for a year.
func TestHandleImageEnc_MaxAge(t *testing.T) {
t.Parallel()
@@ -170,6 +171,7 @@ func TestHandleImageEnc_MaxAge(t *testing.T) {
wantAtMost int
}{
{"60 second TTL", time.Now().Add(time.Minute).Unix(), 50, 60},
{"two-year TTL", time.Now().Add(2 * 365 * 24 * time.Hour).Unix(), 31536000, 31536000},
{"no TTL", 0, 31536000, 31536000},
}