Replace dashes with appropriate characters

This commit is contained in:
2026-09-13 09:05:21 +02:00
parent 7d0d303c2a
commit eb20c94c7b
6 changed files with 12 additions and 12 deletions
+1 -1
View File
@@ -10,7 +10,7 @@ import (
// tokenCookie remembers a caller's token so it does not have to be pasted for
// every upload.
//
// It is HttpOnly, so a script on this origin cannot read it back — which is the
// It is HttpOnly, so a script on this origin cannot read it back, which is the
// reason to prefer it over localStorage, where any injected script could
// exfiltrate the credential. The page never needs to see the value: the server
// resolves it and renders who the caller is.
+2 -2
View File
@@ -85,8 +85,8 @@ func (s *Server) refuse(w http.ResponseWriter, r *http.Request, m *store.Meta, f
// deleteCredentials collects every secret the request carries.
//
// Three can legitimately arrive at once — the object's delete token in the
// form, a token in the header, and a remembered token in the cookie — and any
// Three can legitimately arrive at once, the object's delete token in the
// form, a token in the header, and a remembered token in the cookie, and any
// one of them may be the sufficient one. They are all collected so that the
// first one present cannot shadow the others.
func (s *Server) deleteCredentials(w http.ResponseWriter, r *http.Request) []string {
+3 -3
View File
@@ -936,7 +936,7 @@ func (h *harness) formUploadWith(t *testing.T, cookie *http.Cookie, fields map[s
// --- content security policy ---------------------------------------------
// The page's own behaviour and its CSP have to agree, and nothing in a Go test
// or a curl invocation enforces CSP — only a browser does. This reads the
// or a curl invocation enforces CSP, only a browser does. This reads the
// script that is actually shipped, works out which fetch directives the page
// needs, and checks the policy grants them.
//
@@ -1284,8 +1284,8 @@ func TestAdminLinkIsShownOnlyToAdmins(t *testing.T) {
}
}
// Mixing the two request shapes — a multipart body with the headers the raw
// shape uses — must not silently discard the options. Being handed a UUID when
// Mixing the two request shapes, a multipart body with the headers the raw
// shape uses, must not silently discard the options. Being handed a UUID when
// you asked for a name is worse than being told no.
func TestMultipartHonoursTheHeaderForm(t *testing.T) {
h := newHarness(t, nil)
+1 -1
View File
@@ -96,7 +96,7 @@ func (s *Server) uploadMultipart(w http.ResponseWriter, r *http.Request, boundar
mr := multipart.NewReader(r.Body, boundary)
// Headers seed the request even here, so that a caller mixing the two
// shapes — curl -F with a Vanity header, say — is not silently given a
// shapes, curl -F with a Vanity header, say, is not silently given a
// UUID instead of the name they asked for. A non-empty form field of the
// same meaning overrides them.
req := uploadRequest{