Replace dashes with appropriate characters
This commit is contained in:
@@ -10,7 +10,7 @@ import (
|
|||||||
// tokenCookie remembers a caller's token so it does not have to be pasted for
|
// tokenCookie remembers a caller's token so it does not have to be pasted for
|
||||||
// every upload.
|
// every upload.
|
||||||
//
|
//
|
||||||
// It is HttpOnly, so a script on this origin cannot read it back — which is the
|
// It is HttpOnly, so a script on this origin cannot read it back, which is the
|
||||||
// reason to prefer it over localStorage, where any injected script could
|
// reason to prefer it over localStorage, where any injected script could
|
||||||
// exfiltrate the credential. The page never needs to see the value: the server
|
// exfiltrate the credential. The page never needs to see the value: the server
|
||||||
// resolves it and renders who the caller is.
|
// resolves it and renders who the caller is.
|
||||||
|
|||||||
@@ -85,8 +85,8 @@ func (s *Server) refuse(w http.ResponseWriter, r *http.Request, m *store.Meta, f
|
|||||||
|
|
||||||
// deleteCredentials collects every secret the request carries.
|
// deleteCredentials collects every secret the request carries.
|
||||||
//
|
//
|
||||||
// Three can legitimately arrive at once — the object's delete token in the
|
// Three can legitimately arrive at once, the object's delete token in the
|
||||||
// form, a token in the header, and a remembered token in the cookie — and any
|
// form, a token in the header, and a remembered token in the cookie, and any
|
||||||
// one of them may be the sufficient one. They are all collected so that the
|
// one of them may be the sufficient one. They are all collected so that the
|
||||||
// first one present cannot shadow the others.
|
// first one present cannot shadow the others.
|
||||||
func (s *Server) deleteCredentials(w http.ResponseWriter, r *http.Request) []string {
|
func (s *Server) deleteCredentials(w http.ResponseWriter, r *http.Request) []string {
|
||||||
|
|||||||
@@ -936,7 +936,7 @@ func (h *harness) formUploadWith(t *testing.T, cookie *http.Cookie, fields map[s
|
|||||||
// --- content security policy ---------------------------------------------
|
// --- content security policy ---------------------------------------------
|
||||||
|
|
||||||
// The page's own behaviour and its CSP have to agree, and nothing in a Go test
|
// The page's own behaviour and its CSP have to agree, and nothing in a Go test
|
||||||
// or a curl invocation enforces CSP — only a browser does. This reads the
|
// or a curl invocation enforces CSP, only a browser does. This reads the
|
||||||
// script that is actually shipped, works out which fetch directives the page
|
// script that is actually shipped, works out which fetch directives the page
|
||||||
// needs, and checks the policy grants them.
|
// needs, and checks the policy grants them.
|
||||||
//
|
//
|
||||||
@@ -1284,8 +1284,8 @@ func TestAdminLinkIsShownOnlyToAdmins(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Mixing the two request shapes — a multipart body with the headers the raw
|
// Mixing the two request shapes, a multipart body with the headers the raw
|
||||||
// shape uses — must not silently discard the options. Being handed a UUID when
|
// shape uses, must not silently discard the options. Being handed a UUID when
|
||||||
// you asked for a name is worse than being told no.
|
// you asked for a name is worse than being told no.
|
||||||
func TestMultipartHonoursTheHeaderForm(t *testing.T) {
|
func TestMultipartHonoursTheHeaderForm(t *testing.T) {
|
||||||
h := newHarness(t, nil)
|
h := newHarness(t, nil)
|
||||||
|
|||||||
@@ -96,7 +96,7 @@ func (s *Server) uploadMultipart(w http.ResponseWriter, r *http.Request, boundar
|
|||||||
mr := multipart.NewReader(r.Body, boundary)
|
mr := multipart.NewReader(r.Body, boundary)
|
||||||
|
|
||||||
// Headers seed the request even here, so that a caller mixing the two
|
// Headers seed the request even here, so that a caller mixing the two
|
||||||
// shapes — curl -F with a Vanity header, say — is not silently given a
|
// shapes, curl -F with a Vanity header, say, is not silently given a
|
||||||
// UUID instead of the name they asked for. A non-empty form field of the
|
// UUID instead of the name they asked for. A non-empty form field of the
|
||||||
// same meaning overrides them.
|
// same meaning overrides them.
|
||||||
req := uploadRequest{
|
req := uploadRequest{
|
||||||
|
|||||||
+4
-4
@@ -67,7 +67,7 @@
|
|||||||
// --- drag and drop ------------------------------------------------------
|
// --- drag and drop ------------------------------------------------------
|
||||||
function describeSelection() {
|
function describeSelection() {
|
||||||
var f = fileInput.files[0];
|
var f = fileInput.files[0];
|
||||||
dropHint.textContent = f ? f.name + ' — ' + formatSize(f.size)
|
dropHint.textContent = f ? f.name + ' - ' + formatSize(f.size)
|
||||||
: 'Choose a file, or drop one here.';
|
: 'Choose a file, or drop one here.';
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -109,7 +109,7 @@
|
|||||||
progress.hidden = false;
|
progress.hidden = false;
|
||||||
|
|
||||||
// FormData follows DOM order, so the token, expiry and vanity fields all
|
// FormData follows DOM order, so the token, expiry and vanity fields all
|
||||||
// precede the file part — which is exactly what the server requires.
|
// precede the file part, which is exactly what the server requires.
|
||||||
var data = new FormData(form);
|
var data = new FormData(form);
|
||||||
var started = Date.now();
|
var started = Date.now();
|
||||||
|
|
||||||
@@ -125,8 +125,8 @@
|
|||||||
var rate = elapsed > 0 ? ev.loaded / elapsed : 0;
|
var rate = elapsed > 0 ? ev.loaded / elapsed : 0;
|
||||||
var eta = rate > 0 ? (ev.total - ev.loaded) / rate : 0;
|
var eta = rate > 0 ? (ev.total - ev.loaded) / rate : 0;
|
||||||
progressText.textContent =
|
progressText.textContent =
|
||||||
(pct * 100).toFixed(0) + '% — ' + formatSize(ev.loaded) + ' of ' +
|
(pct * 100).toFixed(0) + '% - ' + formatSize(ev.loaded) + ' of ' +
|
||||||
formatSize(ev.total) + ' — ' + formatSize(rate) + '/s' +
|
formatSize(ev.total) + ' - ' + formatSize(rate) + '/s' +
|
||||||
(eta > 1 ? ', ' + formatTime(eta) + ' left' : '');
|
(eta > 1 ? ', ' + formatTime(eta) + ' left' : '');
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
{{define "content"}}
|
{{define "content"}}
|
||||||
{{if .Stale}}
|
{{if .Stale}}
|
||||||
<p class="notice">Your login is no longer valid — that token has been removed. You have been logged out.</p>
|
<p class="notice">Your login is no longer valid, that token has been removed. You have been logged out.</p>
|
||||||
{{end}}
|
{{end}}
|
||||||
|
|
||||||
<form id="upload" class="card" method="post" action="{{.Base}}api/upload"
|
<form id="upload" class="card" method="post" action="{{.Base}}api/upload"
|
||||||
|
|||||||
Reference in New Issue
Block a user