Brand logos
Serve supplied brand artwork without fetching price data.
GET /static/image/brand/{filename}
Successful responses use Content-Type: image/svg+xml, Cache-Control: public, max-age=86400, an ETag, public CORS and X-Content-Type-Options: nosniff. A restrictive content security policy prevents SVG scripts and external resource loads.
HEAD returns image headers without a body. Conditional requests can return 304. Unknown paths return 404; they do not query FuelWatch or Google. Existing static images support GET/HEAD and reject other methods, including OPTIONS. Normal image embedding uses simple CORS and does not require a preflight.
Generic artwork
Unknown brands (0), Ampol (2), BOC (4), Independent (15), OTR (42) and OMG Caltex (48) currently use generic.svg because a matching dedicated SVG was not supplied. The fallback does not change the brand's code or name.
Logo URLs are stable but artwork may change. Do not cache indefinitely. Display the brand's name as accessible alternative text when the image conveys that name; use an empty alt attribute when adjacent text already supplies it.