check / check (push) Waiting to run
Every response carries X-Request-Id, the upstream fetch sends it, and the "upstream fetched", "image converted" and "image served" lines log it as request_id. pixa's own RequestID middleware keeps a request's own ID only when it is at most 64 letters, digits, '-', '_' or '.', and otherwise makes a random one with crypto/rand, so nothing a client chooses freely and nothing about the host reaches upstream. /v1/e/ now sets ETag, answers a matching If-None-Match with 304 and is routed for HEAD, through notModified, which both image handlers call. No Vary is added: go-chi/cors already sends Vary: Origin. Model: opus-5-5
28 行
768 B
Go
28 行
768 B
Go
package server
|
|
|
|
import (
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"testing"
|
|
)
|
|
|
|
// TestEncryptedImageRouteAnswersHEAD verifies that HEAD on the encrypted image
|
|
// route reaches its handler, as GET does, instead of being answered 405 Method
|
|
// Not Allowed. The handler refuses a token it cannot decrypt with 400, so that
|
|
// status shows the request got through.
|
|
func TestEncryptedImageRouteAnswersHEAD(t *testing.T) {
|
|
t.Parallel()
|
|
|
|
s := newTestServer(t)
|
|
|
|
rec := httptest.NewRecorder()
|
|
s.ServeHTTP(rec, httptest.NewRequestWithContext(
|
|
t.Context(), http.MethodHead, encryptedImagePath, nil))
|
|
t.Logf("status %d", rec.Code)
|
|
|
|
if rec.Code != http.StatusBadRequest {
|
|
t.Errorf("status = %d, want %d from the encrypted image handler",
|
|
rec.Code, http.StatusBadRequest)
|
|
}
|
|
}
|