Refuse an empty fit on /v1/image/ with 400 (closes #139) #140

Merged
clawbot merged 2 commits from issue-139-empty-fit-400 into next 2026-09-28 18:07:12 +02:00
3 changed files with 16 additions and 3 deletions
Showing only changes of commit 02adb1b91d - Show all commits
+2 -1
View File
@@ -132,7 +132,8 @@ Where:
or `85` when the URL has no `q`; a request whose `q` is anything else is
refused with 400
- `fit` — the URL's `fit` query parameter (cover, contain, fill, inside,
outside), or `cover` when the URL has no `fit`
outside), or `cover` when the URL has no `fit`; a request whose `fit` is
anything else, an empty `fit=` included, is refused with 400
**Example:** resize `https://cdn.example.com/photos/cat.jpg` to 800x600
WebP with expiration 1704067200, default quality and fit:
+6
View File
@@ -30,6 +30,12 @@ exhaustion
# Completed Steps
- 2026-09-28 refuse an empty `fit` on `/v1/image/` (closes #139): a
`fit` in the URL with an empty value (`fit=`) is a 400 naming `fit`,
instead of being served as `cover` and verified against a signature
made for `cover`; only a `fit` missing from the URL is still `cover`;
any other value still goes through the existing fit-mode check;
`README.md` says so where it documents `fit`.
- 2026-09-28 refuse an invalid `q` on `/v1/image/` (closes #134): a `q`
that is not a whole number from 1 to 100, an empty `q` included, is a
400 naming `q` and the value, instead of being served at the default
+8 -2
View File
@@ -144,8 +144,14 @@ func (s *Handlers) parseImageRequest(
return nil, false
}
if fit := query.Get("fit"); fit != "" {
req.FitMode = imgcache.FitMode(fit)
// Only a fit missing from the URL is cover. A fit in the URL that is not a
// fit mode is refused by the fit-mode check below; that check would take an
// empty fit as missing, so an empty one is refused here.
req.FitMode = imgcache.FitMode(query.Get("fit"))
if query.Has("fit") && req.FitMode == "" {
s.respondError(w, `invalid fit: not a fit mode, got ""`, http.StatusBadRequest)
return nil, false
}
// Default fit mode if not set