Adds the format auto for /v1/image/ URLs, encrypted URLs and the generator page, per the plan on #88.
Once the signature or token is checked, pixa chooses AVIF when Accept names image/avif, else WebP when it names image/webp, else JPEG when the most specific of image/jpeg, image/* and */* allows it, or when there is no Accept. q=0 refuses a format. A header allowing none of the three answers 406; one that does not parse, or has a q outside 0 to 1, answers 400. The signature and token cover the literal auto; the cache key and ETag use the chosen format, so the formats are cached apart. Answers from that point on, 304 and HEAD included, carry Vary: Accept next to the CORS Vary: Origin; fixed-format answers do not. README.md documents the order.
Each Accept entry is parsed with the standard library's mime.ParseMediaType: no Go library for this is both widely used and maintained, and the most used one ignores q=0.
Deviation from the plan: image/* and */* do not make AVIF or WebP acceptable; only naming them does, because browsers that cannot show them (Safari 14 and 15 for AVIF, older Safari and Firefox for WebP) send the wildcards too. Wildcards still allow and refuse JPEG.
Judgement call: a malformed Accept answers 400 rather than being ignored, per the repo rule against silent fallbacks.
Judgement call: q values above 0 do not reorder the three formats.
Judgement call: an encrypted auto URL ends in img.jpg, as orig does.
Model: opus-5-5
Adds the format `auto` for `/v1/image/` URLs, encrypted URLs and the generator page, per the plan on https://git.eeqj.de/sneak/pixa/issues/88.
Once the signature or token is checked, pixa chooses AVIF when `Accept` names `image/avif`, else WebP when it names `image/webp`, else JPEG when the most specific of `image/jpeg`, `image/*` and `*/*` allows it, or when there is no `Accept`. `q=0` refuses a format. A header allowing none of the three answers 406; one that does not parse, or has a `q` outside 0 to 1, answers 400. The signature and token cover the literal `auto`; the cache key and `ETag` use the chosen format, so the formats are cached apart. Answers from that point on, 304 and `HEAD` included, carry `Vary: Accept` next to the CORS `Vary: Origin`; fixed-format answers do not. `README.md` documents the order.
Each `Accept` entry is parsed with the standard library's `mime.ParseMediaType`: no Go library for this is both widely used and maintained, and the most used one ignores `q=0`.
- Deviation from the plan: `image/*` and `*/*` do not make AVIF or WebP acceptable; only naming them does, because browsers that cannot show them (Safari 14 and 15 for AVIF, older Safari and Firefox for WebP) send the wildcards too. Wildcards still allow and refuse JPEG.
- Judgement call: a malformed `Accept` answers 400 rather than being ignored, per the repo rule against silent fallbacks.
- Judgement call: `q` values above 0 do not reorder the three formats.
- Judgement call: an encrypted `auto` URL ends in `img.jpg`, as `orig` does.
Model: opus-5-5
Tests for #88, before the change:
the format chosen for each Accept header (AVIF-capable, WebP-only,
neither, wildcard only, absent, q=0 on AVIF, malformed), both image
routes serving an auto URL in the chosen format with Vary: Accept, also
on HEAD and 304, the signature covering auto rather than the chosen
format, each chosen format cached apart, and Vary: Accept next to the
CORS middleware's Vary: Origin. They do not compile yet: FormatAuto and
formatForAccept do not exist.
Model: opus-5-5
auto is a format in the /v1/image/ path, an encrypted URL's token and
the generator page. Once the signature or token is checked, pixa
chooses AVIF when Accept names image/avif, else WebP when it names
image/webp, else JPEG when the most specific of image/jpeg, image/* and
*/* allows it or Accept is absent. q=0 refuses a format; a header
allowing none of the three answers 406, one that does not parse 400.
The signature and token cover auto itself; the cache key and ETag use
the chosen format. Answers from then on carry Vary: Accept.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Adds the format
autofor/v1/image/URLs, encrypted URLs and the generator page, per the plan on #88.Once the signature or token is checked, pixa chooses AVIF when
Acceptnamesimage/avif, else WebP when it namesimage/webp, else JPEG when the most specific ofimage/jpeg,image/*and*/*allows it, or when there is noAccept.q=0refuses a format. A header allowing none of the three answers 406; one that does not parse, or has aqoutside 0 to 1, answers 400. The signature and token cover the literalauto; the cache key andETaguse the chosen format, so the formats are cached apart. Answers from that point on, 304 andHEADincluded, carryVary: Acceptnext to the CORSVary: Origin; fixed-format answers do not.README.mddocuments the order.Each
Acceptentry is parsed with the standard library'smime.ParseMediaType: no Go library for this is both widely used and maintained, and the most used one ignoresq=0.image/*and*/*do not make AVIF or WebP acceptable; only naming them does, because browsers that cannot show them (Safari 14 and 15 for AVIF, older Safari and Firefox for WebP) send the wildcards too. Wildcards still allow and refuse JPEG.Acceptanswers 400 rather than being ignored, per the repo rule against silent fallbacks.qvalues above 0 do not reorder the three formats.autoURL ends inimg.jpg, asorigdoes.Model: opus-5-5
PASS
9a5ef06c804b89d0972eec94fee69d7f94ea548e, rebased ontonextat01823d27dba433d4412b7446cff2d56e224bb01d.Model: opus-5-5