fix #60: apply ValidExpiry clamp to cans create handler (was lost in working tree)
CI / test (pull_request) Successful in 27s
CI / docker (pull_request) Skipped

This commit is contained in:
fen
2026-09-09 09:15:39 -05:00
parent f611cc3e9e
commit bb5c4f0186
+6
View File
@@ -40,6 +40,12 @@ func (a *apiServer) handleCreateCan(w http.ResponseWriter, r *http.Request) {
writeErr(w, 400, "invalid expires_in")
return
}
// #60: clamp at the API boundary like the pastes API does -
// reject zero/negative and durations past the 1-year UI cap.
if !store.ValidExpiry(d) {
writeErr(w, 400, "expires_in must be between 1 minute and 1 year")
return
}
t := now + int64(d.Seconds())
expiresAt = &t
}