Refuse an empty fit on /v1/image/ with 400 (closes #139) #140
+2
-1
@@ -132,7 +132,8 @@ Where:
|
|||||||
or `85` when the URL has no `q`; a request whose `q` is anything else is
|
or `85` when the URL has no `q`; a request whose `q` is anything else is
|
||||||
refused with 400
|
refused with 400
|
||||||
- `fit` — the URL's `fit` query parameter (cover, contain, fill, inside,
|
- `fit` — the URL's `fit` query parameter (cover, contain, fill, inside,
|
||||||
outside), or `cover` when the URL has no `fit`
|
outside), or `cover` when the URL has no `fit`; a request whose `fit` is
|
||||||
|
anything else, an empty `fit=` included, is refused with 400
|
||||||
|
|
||||||
**Example:** resize `https://cdn.example.com/photos/cat.jpg` to 800x600
|
**Example:** resize `https://cdn.example.com/photos/cat.jpg` to 800x600
|
||||||
WebP with expiration 1704067200, default quality and fit:
|
WebP with expiration 1704067200, default quality and fit:
|
||||||
|
|||||||
@@ -30,6 +30,12 @@ exhaustion
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
|
- 2026-09-28 refuse an empty `fit` on `/v1/image/` (closes #139): a
|
||||||
|
`fit` in the URL with an empty value (`fit=`) is a 400 naming `fit`,
|
||||||
|
instead of being served as `cover` and verified against a signature
|
||||||
|
made for `cover`; only a `fit` missing from the URL is still `cover`;
|
||||||
|
any other value still goes through the existing fit-mode check;
|
||||||
|
`README.md` says so where it documents `fit`.
|
||||||
- 2026-09-28 refuse an invalid `q` on `/v1/image/` (closes #134): a `q`
|
- 2026-09-28 refuse an invalid `q` on `/v1/image/` (closes #134): a `q`
|
||||||
that is not a whole number from 1 to 100, an empty `q` included, is a
|
that is not a whole number from 1 to 100, an empty `q` included, is a
|
||||||
400 naming `q` and the value, instead of being served at the default
|
400 naming `q` and the value, instead of being served at the default
|
||||||
|
|||||||
@@ -144,8 +144,14 @@ func (s *Handlers) parseImageRequest(
|
|||||||
return nil, false
|
return nil, false
|
||||||
}
|
}
|
||||||
|
|
||||||
if fit := query.Get("fit"); fit != "" {
|
// Only a fit missing from the URL is cover. A fit in the URL that is not a
|
||||||
req.FitMode = imgcache.FitMode(fit)
|
// fit mode is refused by the fit-mode check below; that check would take an
|
||||||
|
// empty fit as missing, so an empty one is refused here.
|
||||||
|
req.FitMode = imgcache.FitMode(query.Get("fit"))
|
||||||
|
if query.Has("fit") && req.FitMode == "" {
|
||||||
|
s.respondError(w, `invalid fit: not a fit mode, got ""`, http.StatusBadRequest)
|
||||||
|
|
||||||
|
return nil, false
|
||||||
}
|
}
|
||||||
|
|
||||||
// Default fit mode if not set
|
// Default fit mode if not set
|
||||||
|
|||||||
Odkázat v novém úkolu
Zablokovat Uživatele