Keep max-age within an expiring image URL's lifetime (closes #63) #146

Merged
clawbot merged 3 commits from issue-63-cache-max-age into next 2026-09-29 03:51:58 +02:00
2 changed files with 8 additions and 5 deletions
Showing only changes of commit 9742842975 - Show all commits
+4 -3
View File
@@ -102,9 +102,10 @@ than once, is refused with 400.
An image is served with `Cache-Control: public, max-age=<seconds>, immutable`.
When the URL has an expiry (an `exp`, or the TTL of an encrypted URL),
`max-age` is the whole seconds left until then, so no browser or proxy cache
keeps the image after pixa would refuse the URL. A URL with no expiry gets one
year. `immutable` only stops a client revalidating while its copy is fresh.
`max-age` is the whole seconds left until then, at most one year, so no browser
or proxy cache keeps the image after pixa would refuse the URL. A URL with no
expiry gets one year. `immutable` only stops a client revalidating while its
copy is fresh.
The login form (`POST /`) is limited to 5 attempts per minute per client
address, counting an IPv6 client by its /64; an attempt over the limit is
@@ -158,8 +158,9 @@ func TestHandleImage_AllowlistedHost_MaxAge(t *testing.T) {
}
// TestHandleImageEnc_MaxAge verifies that an image served through an encrypted
// URL with a 60 second TTL may be cached for at most those 60 seconds, and that
// one made without a TTL, which never expires, may be cached for a year.
// URL with a 60 second TTL may be cached for at most those 60 seconds, that one
// with a two-year TTL may be cached for a year, and that one made without a
// TTL, which never expires, may be cached for a year.
func TestHandleImageEnc_MaxAge(t *testing.T) {
t.Parallel()
@@ -170,6 +171,7 @@ func TestHandleImageEnc_MaxAge(t *testing.T) {
wantAtMost int
}{
{"60 second TTL", time.Now().Add(time.Minute).Unix(), 50, 60},
{"two-year TTL", time.Now().Add(2 * 365 * 24 * time.Hour).Unix(), 31536000, 31536000},
{"no TTL", 0, 31536000, 31536000},
}