diff --git a/internal/server/cookie.go b/internal/server/cookie.go index 5eaa212..f6c2faa 100644 --- a/internal/server/cookie.go +++ b/internal/server/cookie.go @@ -10,7 +10,7 @@ import ( // tokenCookie remembers a caller's token so it does not have to be pasted for // every upload. // -// It is HttpOnly, so a script on this origin cannot read it back — which is the +// It is HttpOnly, so a script on this origin cannot read it back, which is the // reason to prefer it over localStorage, where any injected script could // exfiltrate the credential. The page never needs to see the value: the server // resolves it and renders who the caller is. diff --git a/internal/server/delete.go b/internal/server/delete.go index 5d9344f..5f97763 100644 --- a/internal/server/delete.go +++ b/internal/server/delete.go @@ -85,8 +85,8 @@ func (s *Server) refuse(w http.ResponseWriter, r *http.Request, m *store.Meta, f // deleteCredentials collects every secret the request carries. // -// Three can legitimately arrive at once — the object's delete token in the -// form, a token in the header, and a remembered token in the cookie — and any +// Three can legitimately arrive at once, the object's delete token in the +// form, a token in the header, and a remembered token in the cookie, and any // one of them may be the sufficient one. They are all collected so that the // first one present cannot shadow the others. func (s *Server) deleteCredentials(w http.ResponseWriter, r *http.Request) []string { diff --git a/internal/server/server_test.go b/internal/server/server_test.go index eca81ce..db5427c 100644 --- a/internal/server/server_test.go +++ b/internal/server/server_test.go @@ -936,7 +936,7 @@ func (h *harness) formUploadWith(t *testing.T, cookie *http.Cookie, fields map[s // --- content security policy --------------------------------------------- // The page's own behaviour and its CSP have to agree, and nothing in a Go test -// or a curl invocation enforces CSP — only a browser does. This reads the +// or a curl invocation enforces CSP, only a browser does. This reads the // script that is actually shipped, works out which fetch directives the page // needs, and checks the policy grants them. // @@ -1284,8 +1284,8 @@ func TestAdminLinkIsShownOnlyToAdmins(t *testing.T) { } } -// Mixing the two request shapes — a multipart body with the headers the raw -// shape uses — must not silently discard the options. Being handed a UUID when +// Mixing the two request shapes, a multipart body with the headers the raw +// shape uses, must not silently discard the options. Being handed a UUID when // you asked for a name is worse than being told no. func TestMultipartHonoursTheHeaderForm(t *testing.T) { h := newHarness(t, nil) diff --git a/internal/server/upload.go b/internal/server/upload.go index 137dee9..2b996ff 100644 --- a/internal/server/upload.go +++ b/internal/server/upload.go @@ -96,7 +96,7 @@ func (s *Server) uploadMultipart(w http.ResponseWriter, r *http.Request, boundar mr := multipart.NewReader(r.Body, boundary) // Headers seed the request even here, so that a caller mixing the two - // shapes — curl -F with a Vanity header, say — is not silently given a + // shapes, curl -F with a Vanity header, say, is not silently given a // UUID instead of the name they asked for. A non-empty form field of the // same meaning overrides them. req := uploadRequest{ diff --git a/web/static/app.js b/web/static/app.js index 7e93e4f..ff3ad36 100644 --- a/web/static/app.js +++ b/web/static/app.js @@ -67,7 +67,7 @@ // --- drag and drop ------------------------------------------------------ function describeSelection() { var f = fileInput.files[0]; - dropHint.textContent = f ? f.name + ' — ' + formatSize(f.size) + dropHint.textContent = f ? f.name + ' - ' + formatSize(f.size) : 'Choose a file, or drop one here.'; } @@ -109,7 +109,7 @@ progress.hidden = false; // FormData follows DOM order, so the token, expiry and vanity fields all - // precede the file part — which is exactly what the server requires. + // precede the file part, which is exactly what the server requires. var data = new FormData(form); var started = Date.now(); @@ -125,8 +125,8 @@ var rate = elapsed > 0 ? ev.loaded / elapsed : 0; var eta = rate > 0 ? (ev.total - ev.loaded) / rate : 0; progressText.textContent = - (pct * 100).toFixed(0) + '% — ' + formatSize(ev.loaded) + ' of ' + - formatSize(ev.total) + ' — ' + formatSize(rate) + '/s' + + (pct * 100).toFixed(0) + '% - ' + formatSize(ev.loaded) + ' of ' + + formatSize(ev.total) + ' - ' + formatSize(rate) + '/s' + (eta > 1 ? ', ' + formatTime(eta) + ' left' : ''); }; diff --git a/web/templates/index.html b/web/templates/index.html index 14189f3..ddc065f 100644 --- a/web/templates/index.html +++ b/web/templates/index.html @@ -1,6 +1,6 @@ {{define "content"}} {{if .Stale}} -

Your login is no longer valid — that token has been removed. You have been logged out.

+

Your login is no longer valid, that token has been removed. You have been logged out.

{{end}}