Skip to content

feat: GET URL-based rendering (signed, for dynamic OG images) #95

Description

@ajianaz

Demand source: Robolly (GET render.jpg?title=...&photo=...) and Bannerbear Simple/Signed URLs — primary use case: blog engines / platforms fetch the OG image via a plain URL, no client library, no POST.

Proposed design:

  1. Endpoint GET /r/:template.jpg?d=<base64url(JSON)>&sig=<hmac>.
  2. sig = HMAC-SHA256(d, COSY_API_KEY) — prevents abuse (bandwidth becomes our cost). Unsigned mode remains dev-only.
  3. Support png/webp responses via extension.
  4. Cache-Control: public, max-age=3600 (OG image re-crawl).

Acceptance:

  • A blog engine can set <meta property="og:image" content="https://cosy.host/r/og-image.jpg?d=...&sig=...">.
  • Invalid signature = 403. Oversized query (>8KB) = 413.

Effort: M. Priority #4.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions