On /v1/image/, a fit in the URL with an empty value (fit=) was treated as missing: it was served as cover and verified against a signature made for cover. It is now a 400, invalid fit: not a fit mode, got "". This is the rule #134 applied to q: only a parameter missing from the URL gets the default. A missing fit is still cover. README.md now says so where it documents fit.
Worth knowing when reading the diff:
The empty check sits in the route because the existing fit-mode check (imgcache.ValidateFitMode) accepts an empty mode on purpose. The generator and encrypted URLs rely on empty meaning cover. Any non-empty value still goes through that check, unchanged.
parseImageRequest is now at exactly the 80-line lint limit. To stay under it, fit is read straight into req.FitMode instead of a separate variable. The next line added to this function will need it split.
Disclosures:
Judgement call: an unknown fit (e.g. fit=bogus) still answers with the existing invalid image request: invalid fit mode. Changing that text is outside this issue, so the two refusals word it differently.
Judgement call: the failing test is a new test function, not a row in the existing invalid-query table. The repo's rules do not allow changing existing tests without the owner's approval.
Commits: the failing test first, then the fix.
Model: opus-5-5
Closes https://git.eeqj.de/sneak/pixa/issues/139.
On `/v1/image/`, a `fit` in the URL with an empty value (`fit=`) was treated as missing: it was served as `cover` and verified against a signature made for `cover`. It is now a 400, `invalid fit: not a fit mode, got ""`. This is the rule https://git.eeqj.de/sneak/pixa/issues/134 applied to `q`: only a parameter missing from the URL gets the default. A missing `fit` is still `cover`. `README.md` now says so where it documents `fit`.
Worth knowing when reading the diff:
- The empty check sits in the route because the existing fit-mode check (`imgcache.ValidateFitMode`) accepts an empty mode on purpose. The generator and encrypted URLs rely on empty meaning `cover`. Any non-empty value still goes through that check, unchanged.
- `parseImageRequest` is now at exactly the 80-line lint limit. To stay under it, `fit` is read straight into `req.FitMode` instead of a separate variable. The next line added to this function will need it split.
Disclosures:
- Judgement call: an unknown `fit` (e.g. `fit=bogus`) still answers with the existing `invalid image request: invalid fit mode`. Changing that text is outside this issue, so the two refusals word it differently.
- Judgement call: the failing test is a new test function, not a row in the existing invalid-query table. The repo's rules do not allow changing existing tests without the owner's approval.
- Commits: the failing test first, then the fix.
Model: opus-5-5
A fit in the URL with an empty value is served as cover today and
verifies against a signature made for cover. This test asks for a 400
naming fit instead; it fails until the route refuses it.
Model: opus-5-5
A fit in the URL with an empty value (fit=) was treated as missing, so
it was served as cover and verified against a signature made for cover.
It is now a 400 naming fit, the same rule the route applies to an empty
q. It is checked before the existing fit-mode check, which takes an
empty fit as missing; any other value still goes through that check
unchanged. Only a fit missing from the URL is cover.
Model: opus-5-5
PASS: an empty fit= on /v1/image/ is now refused with 400 naming fit, while a missing fit still means cover, as #139 asks.
Model: opus-5-5
PASS: an empty `fit=` on `/v1/image/` is now refused with 400 naming `fit`, while a missing `fit` still means `cover`, as https://git.eeqj.de/sneak/pixa/issues/139 asks.
Model: opus-5-5
clawbot
merged commit f149813c7e into next2026-09-28 18:07:12 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Closes #139.
On
/v1/image/, afitin the URL with an empty value (fit=) was treated as missing: it was served ascoverand verified against a signature made forcover. It is now a 400,invalid fit: not a fit mode, got "". This is the rule #134 applied toq: only a parameter missing from the URL gets the default. A missingfitis stillcover.README.mdnow says so where it documentsfit.Worth knowing when reading the diff:
imgcache.ValidateFitMode) accepts an empty mode on purpose. The generator and encrypted URLs rely on empty meaningcover. Any non-empty value still goes through that check, unchanged.parseImageRequestis now at exactly the 80-line lint limit. To stay under it,fitis read straight intoreq.FitModeinstead of a separate variable. The next line added to this function will need it split.Disclosures:
fit(e.g.fit=bogus) still answers with the existinginvalid image request: invalid fit mode. Changing that text is outside this issue, so the two refusals word it differently.Model: opus-5-5
PASS: an empty
fit=on/v1/image/is now refused with 400 namingfit, while a missingfitstill meanscover, as #139 asks.Model: opus-5-5