← all helpWHAT IT IS
Image galleries inside throway, under https://skale.dev/throway/pics, for event
photos: anyone can create a gallery and becomes its admin via a
per-gallery secret token. Visitors upload freely, everyone views.
CREATE (like dirs: create-or-get for dir-style names)
POST https://skale.dev/throway/pics?create=1&name=hochzeit-2026
-> JSON: id, url (public), admin_url, token (shown exactly once!)
A name like "hochzeit-2026" ([a-z0-9-], 5-32 chars) becomes the
gallery's key: https://skale.dev/throway/pics/g/hochzeit-2026 (create-or-get,
idempotent). Re-creating an existing named gallery returns it WITHOUT
the token. Any other name is a display name on a fresh hex id.
The gallery admin link is https://skale.dev/throway/pics/g/<gid>/<token>. With it
you can hide, unhide, delete and reorder images. Galleries are unlisted
by default; &listed=1 puts them in the public index at GET /pics.
UPLOAD (public, no auth)
POST https://skale.dev/throway/pics/g/<gid>?name=photo.jpg (raw bytes)
POST https://skale.dev/throway/pics/g/<gid> (multipart, batch)
POST https://skale.dev/throway/pics/g/<gid>?url=<image-url> (server-side import —
drag a picture from another site onto the dropzone, e.g. straight
from a Google Photos tab; public hosts, images only, max 30 MB)
Images at or under 2048px are stored byte-identical (JPEG
metadata stripped losslessly, pixels untouched). Only larger images
are downscaled to 2048px WebP q90, stepped down
only while the result exceeds ~1 MB (alpha preserved; GIFs pass
through). Fixed lifetime: 90
days per image — an upload also slides the gallery's lifetime. Own
pool: 20 GB shared across galleries. Full pool REJECTS uploads
(507) — existing images are never evicted.
VIEW
GET https://skale.dev/throway/pics index (listed galleries)
GET https://skale.dev/throway/pics/g/<gid> one gallery
GET https://skale.dev/throway/pics/g/<gid>?embed=1 minimal view for <iframe> embedding
GET https://skale.dev/throway/pics/i/<id> one image (?thumb=1 for preview)
LIKES & COMMENTS (guestbook, no login; since 1.38.0)
POST https://skale.dev/throway/pics/i/<pid>?like=1 toggle image like
-> {id, likes, liked}; one like per visitor (pseudonymous
fingerprint from IP+UA, keyed by the gallery's secret token —
same visitor, same button: toggles off)
POST https://skale.dev/throway/pics/g/<gid>?comment=1 add a comment
body: urlencoded form or JSON {name, text} — name <= 40 chars
(optional, defaults to "Gast"), text <= 500 chars;
20 s cooldown per visitor, max 500 per gallery
POST https://skale.dev/throway/pics/g/<gid>?clike=<cid> toggle comment like
GET https://skale.dev/throway/pics/g/<gid>?likes=1 cheap counters for
polling: {likes: {pid: n}, cl: {cid: n}, comments: m}
GET https://skale.dev/throway/pics/g/<gid>?sort=likes images ranked by likes
(ties keep the curated order; ?embed=1 keeps it). In browsers
liked images FLIP-climb live and a 30 s poll keeps counts fresh.
Comments render newest first; the gallery admin (or the superadmin
token) deletes them (admin action cdel). Nothing personal is persisted
with a comment — no IP, no fingerprint.
ADMIN (per-gallery token or the server superadmin token, as path segment)
GET https://skale.dev/throway/pics/g/<gid>/<secret> admin page
GET https://skale.dev/throway/pics/g/<gid>/<secret>/json listing incl. hidden
POST https://skale.dev/throway/pics/g/<gid>/<secret> form: id, action=hide|unhide|delete|up|down
Hidden images: 404 for everyone but the admin. Deleted images: gone
for good (bytes + meta).agent hint — this page is machine-readable
curl -A curl https://skale.dev/throway/help/pics # this topic as plain text