/v1/image/ serves an invalid q as the default instead of answering 400 #134

Closed
opened 2026-09-28 14:35:02 +02:00 by clawbot · 2 comments
Collaborator

Found while reworking #126.

On the plain /v1/image/ route, a q that is not a number or is outside 1-100 is ignored and the default 85 is used, so q=banana or q=500 is served as if q were absent (and, since #60, verifies against a signature made for 85). pixa's rule is that a set but invalid value is an error, never a silent default. The same problem for exp is already #72 item 1; this issue is q only.

Definition of done

  • On /v1/image/, a q that is not a whole number from 1 to 100 is a 400 naming q and the value; an absent q still means 85.
  • Failing route tests first: non-numeric q, q=0, q=101, each a 400; absent q unchanged.
  • README.md states the accepted range where it documents q.

Model: opus-5-5

Found while reworking https://git.eeqj.de/sneak/pixa/pulls/126. On the plain `/v1/image/` route, a `q` that is not a number or is outside 1-100 is ignored and the default 85 is used, so `q=banana` or `q=500` is served as if `q` were absent (and, since https://git.eeqj.de/sneak/pixa/issues/60, verifies against a signature made for 85). pixa's rule is that a set but invalid value is an error, never a silent default. The same problem for `exp` is already https://git.eeqj.de/sneak/pixa/issues/72 item 1; this issue is `q` only. ## Definition of done - On `/v1/image/`, a `q` that is not a whole number from 1 to 100 is a 400 naming `q` and the value; an absent `q` still means 85. - Failing route tests first: non-numeric `q`, `q=0`, `q=101`, each a 400; absent `q` unchanged. - `README.md` states the accepted range where it documents `q`. Model: opus-5-5
clawbot added this to the 1.0.0 milestone 2026-09-28 14:35:02 +02:00
Author
Collaborator

Plan:

  • In parseImageRequest (internal/handlers/image.go), read q with the check the URL generator already applies to its quality field: parseFormInt with minQuality/maxQuality and default encurl.DefaultQuality (85). An absent q stays 85; any other value that is not a whole number from 1 to 100 is a 400 such as invalid q: must be from 1 to 100, got "500". The separate "default quality if not set" step goes away.
  • Tests first, in their own commit: route tests for q=banana, q=0 and q=101, each a 400 naming q and the value. An absent q is already covered by the existing test that checks a URL without q against a signature made for 85.
  • README.md: the quality line of the signature specification, the one place q is documented, gains the accepted range and the 400.
  • An empty q= counts as absent, as an empty fit= does and as an empty quality does in the generator.
  • exp (#72) is not touched.

Model: opus-5-5

Plan: - In `parseImageRequest` (`internal/handlers/image.go`), read `q` with the check the URL generator already applies to its quality field: `parseFormInt` with `minQuality`/`maxQuality` and default `encurl.DefaultQuality` (85). An absent `q` stays 85; any other value that is not a whole number from 1 to 100 is a 400 such as `invalid q: must be from 1 to 100, got "500"`. The separate "default quality if not set" step goes away. - Tests first, in their own commit: route tests for `q=banana`, `q=0` and `q=101`, each a 400 naming `q` and the value. An absent `q` is already covered by the existing test that checks a URL without `q` against a signature made for 85. - `README.md`: the `quality` line of the signature specification, the one place `q` is documented, gains the accepted range and the 400. - An empty `q=` counts as absent, as an empty `fit=` does and as an empty quality does in the generator. - `exp` (https://git.eeqj.de/sneak/pixa/issues/72) is not touched. Model: opus-5-5
Author
Collaborator

Built as planned above, with no deviations: #138

Model: opus-5-5

Built as planned above, with no deviations: https://git.eeqj.de/sneak/pixa/pulls/138 Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/pixa#134