/v1/image/ serves an empty fit= as cover instead of answering 400 #139

Closed
opened 2026-09-28 16:42:06 +02:00 by clawbot · 2 comments
Collaborator

Found in review of #138.

On /v1/image/, a fit present in the URL with an empty value (fit=) is treated as absent and served as cover, and it verifies against a signature made for cover. pixa's rule is that a present but invalid value is an error, never a silent default; #134 fixes the same gap for q.

Definition of done

  • On /v1/image/, fit= (present, empty) is a 400 naming fit; only a fit missing from the URL means cover.
  • Failing route test first; the existing fit-mode tests still pass.
  • README.md, where it documents fit, says so.

Model: opus-5-5

Found in review of https://git.eeqj.de/sneak/pixa/pulls/138. On `/v1/image/`, a `fit` present in the URL with an empty value (`fit=`) is treated as absent and served as `cover`, and it verifies against a signature made for `cover`. pixa's rule is that a present but invalid value is an error, never a silent default; https://git.eeqj.de/sneak/pixa/issues/134 fixes the same gap for `q`. ## Definition of done - On `/v1/image/`, `fit=` (present, empty) is a 400 naming `fit`; only a `fit` missing from the URL means `cover`. - Failing route test first; the existing fit-mode tests still pass. - `README.md`, where it documents `fit`, says so. Model: opus-5-5
clawbot added this to the 1.0.0 milestone 2026-09-28 16:42:06 +02:00
Author
Collaborator

Plan:

  • On /v1/image/, a fit that is in the URL but empty is refused with 400 invalid fit: not a fit mode, got "", checked the same way as the empty q from #134. It has to be checked before the existing fit-mode check, which takes an empty fit as missing.
  • Any other value still goes through that existing check, unchanged: an unknown fit is still a 400, and a fit missing from the URL is still cover and still verifies against a signature made for cover.
  • Failing route test first as its own commit (a fit= row in the route's invalid-query test), then the fix, the README.md line that documents fit, and TODO.md.

Model: opus-5-5

Plan: - On `/v1/image/`, a `fit` that is in the URL but empty is refused with 400 `invalid fit: not a fit mode, got ""`, checked the same way as the empty `q` from https://git.eeqj.de/sneak/pixa/issues/134. It has to be checked before the existing fit-mode check, which takes an empty fit as missing. - Any other value still goes through that existing check, unchanged: an unknown fit is still a 400, and a `fit` missing from the URL is still `cover` and still verifies against a signature made for `cover`. - Failing route test first as its own commit (a `fit=` row in the route's invalid-query test), then the fix, the `README.md` line that documents `fit`, and `TODO.md`. Model: opus-5-5
Author
Collaborator

Built in #140. One change from the plan: the failing test is a new test function, not a row in the existing invalid-query test, because the repo's rules do not allow changing existing tests without the owner's approval.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/pixa/pulls/140. One change from the plan: the failing test is a new test function, not a row in the existing invalid-query test, because the repo's rules do not allow changing existing tests without the owner's approval. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/pixa#139