Found by the review of #194 (#194 (comment)). The deleted scripts/manual-test.sh made a URL on the generator page with a one-second ttl, waited, and expected 410. No Go test covers that: the 410 tests in internal/handlers build an expired token directly, and the generator round-trip test sets no ttl.
Plan: one new test in internal/handlers, next to the generator round trip: POST /generate with a logged-in session and a short ttl makes a URL that /v1/e/ serves before the ttl passes and answers 410 after it. Use the clock seam the token code already has if there is one, so the test does not sleep for the ttl; if there is none, a ttl of one second and a wait just past it is acceptable. New test only.
Model: opus-5-5
Found by the review of https://git.eeqj.de/sneak/pixa/pulls/194 (https://git.eeqj.de/sneak/pixa/pulls/194#issuecomment-125099). The deleted `scripts/manual-test.sh` made a URL on the generator page with a one-second `ttl`, waited, and expected 410. No Go test covers that: the 410 tests in `internal/handlers` build an expired token directly, and the generator round-trip test sets no `ttl`.
Plan: one new test in `internal/handlers`, next to the generator round trip: `POST /generate` with a logged-in session and a short `ttl` makes a URL that `/v1/e/` serves before the `ttl` passes and answers 410 after it. Use the clock seam the token code already has if there is one, so the test does not sleep for the `ttl`; if there is none, a `ttl` of one second and a wait just past it is acceptable. New test only.
Model: opus-5-5
New test in #201: a URL made on the generator page with a ttl of one second is served by /v1/e/ at once and answers 410 two seconds later. There is no way for a test to set the clock, so it waits for real.
Model: opus-5-5
New test in https://git.eeqj.de/sneak/pixa/pulls/201: a URL made on the generator page with a `ttl` of one second is served by `/v1/e/` at once and answers 410 two seconds later. There is no way for a test to set the clock, so it waits for real.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found by the review of #194 (#194 (comment)). The deleted
scripts/manual-test.shmade a URL on the generator page with a one-secondttl, waited, and expected 410. No Go test covers that: the 410 tests ininternal/handlersbuild an expired token directly, and the generator round-trip test sets nottl.Plan: one new test in
internal/handlers, next to the generator round trip:POST /generatewith a logged-in session and a shortttlmakes a URL that/v1/e/serves before thettlpasses and answers 410 after it. Use the clock seam the token code already has if there is one, so the test does not sleep for thettl; if there is none, attlof one second and a wait just past it is acceptable. New test only.Model: opus-5-5
New test in #201: a URL made on the generator page with a
ttlof one second is served by/v1/e/at once and answers 410 two seconds later. There is no way for a test to set the clock, so it waits for real.Model: opus-5-5