New tests only, in internal/handlers, with the mock fetcher and no network, per the plan on #77.
/v1/e/: a valid token serves the image; an expired token answers 410; a token with one character changed, cut short, or made with another signing key answers 400, as README.md says for a token that does not decrypt. The server these run against would serve the photo for any token it accepted.
Login: GET / shows the login form; a wrong key shows it again with its error and sets no session cookie; the right key answers 303 to / with a session cookie whose Secure, HttpOnly and SameSite=Strict are checked one by one.
GET /logout answers 303 to / with an empty session cookie sent with Max-Age=0.
POST /generate with the form's token and cookie but no login session answers 303 to / and makes no URL.
Round trip: the URL the generator page shows is served by /v1/e/.
Not visible in the diff:
Everywhere these tests look, the code answers as README.md says; no difference is pinned.
In the round trip, /v1/e/ runs on separate handlers made with the same signing key, as the generator's test router has no image service.
The new file uses formatField and imgcache.FormatJPEG because a third literal "format" or "jpeg" in the package trips the linter's repeated-string check.
Judgement call: the right-key test also checks that GET / with the new cookie shows the generator page, so the cookie is shown to work, not only to carry its attributes.
Model: opus-5-5
New tests only, in `internal/handlers`, with the mock fetcher and no network, per the plan on https://git.eeqj.de/sneak/pixa/issues/77.
- `/v1/e/`: a valid token serves the image; an expired token answers 410; a token with one character changed, cut short, or made with another signing key answers 400, as `README.md` says for a token that does not decrypt. The server these run against would serve the photo for any token it accepted.
- Login: `GET /` shows the login form; a wrong key shows it again with its error and sets no session cookie; the right key answers 303 to `/` with a session cookie whose `Secure`, `HttpOnly` and `SameSite=Strict` are checked one by one.
- `GET /logout` answers 303 to `/` with an empty session cookie sent with `Max-Age=0`.
- `POST /generate` with the form's token and cookie but no login session answers 303 to `/` and makes no URL.
- Round trip: the URL the generator page shows is served by `/v1/e/`.
Not visible in the diff:
- Everywhere these tests look, the code answers as `README.md` says; no difference is pinned.
- In the round trip, `/v1/e/` runs on separate handlers made with the same signing key, as the generator's test router has no image service.
- The new file uses `formatField` and `imgcache.FormatJPEG` because a third literal `"format"` or `"jpeg"` in the package trips the linter's repeated-string check.
Judgement call: the right-key test also checks that `GET /` with the new cookie shows the generator page, so the cookie is shown to work, not only to carry its attributes.
Model: opus-5-5
New handler tests in internal/handlers, with no network: GET / shows the
login form without a session; a wrong key shows it again with an error and
sets no session cookie; the right key answers 303 with a session cookie
marked Secure, HttpOnly and SameSite=Strict, with which GET / shows the
generator page; GET /logout empties the cookie with Max-Age=0; POST
/generate without a session answers 303 to /; /v1/e/ serves a valid
token's image, answers 410 for an expired token and 400 for one changed,
cut short or made with another signing key; a URL made on the generator
page is served by /v1/e/. No code changes.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
New tests only, in
internal/handlers, with the mock fetcher and no network, per the plan on #77./v1/e/: a valid token serves the image; an expired token answers 410; a token with one character changed, cut short, or made with another signing key answers 400, asREADME.mdsays for a token that does not decrypt. The server these run against would serve the photo for any token it accepted.GET /shows the login form; a wrong key shows it again with its error and sets no session cookie; the right key answers 303 to/with a session cookie whoseSecure,HttpOnlyandSameSite=Strictare checked one by one.GET /logoutanswers 303 to/with an empty session cookie sent withMax-Age=0.POST /generatewith the form's token and cookie but no login session answers 303 to/and makes no URL./v1/e/.Not visible in the diff:
README.mdsays; no difference is pinned./v1/e/runs on separate handlers made with the same signing key, as the generator's test router has no image service.formatFieldandimgcache.FormatJPEGbecause a third literal"format"or"jpeg"in the package trips the linter's repeated-string check.Judgement call: the right-key test also checks that
GET /with the new cookie shows the generator page, so the cookie is shown to work, not only to carry its attributes.Model: opus-5-5
PASS: head
a96d15188821e51f349fe480c1ab50c6df7e4da1, rebased ontonextatf8c437b83f642596c211c76b4d25ef10d734ee7d.Model: opus-5-5
a96d151888to30ae998114