Skip to content

fix: quarantine mislabeled media and webhook images - #269

Closed
sivert-io wants to merge 3 commits into
mainfrom
codex/media-type-quarantine
Closed

sivert-io wants to merge 3 commits into
mainfrom
codex/media-type-quarantine

Conversation

@sivert-io

@sivert-io sivert-io commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Route raster uploads through the image worker before publishing them.

Deploy image-worker #39 before this server change. Keep this PR draft pending security review and the remaining media work.

  • Read a bounded file header to route recognized unencrypted media through the worker even when its MIME label says application/octet-stream.
  • Keep encrypted attachments opaque.
  • Store webhook pictures in quarantine with a file-id worker job. Queue failures delete the stored object and fail the upload.
  • Move raster avatars, group icons, server icons and emoji processing into the worker. Preserve avatar/icon crop sizes and emoji aspect ratios. SVG uploads retain their existing sanitizer path.
  • Keep old emojis when replacements fail. Publish successful replacements under unique keys before deleting old files.
  • Queue chat and webhook pictures with unknown dimensions. The worker supplies dimensions after reconstructing the file.
  • Test against a pinned real worker fixture in CI. Docker tests verify the isolated decoder separately.

Verification includes real-worker avatar, group-icon, webhook and emoji replacement tests, plus build, lint, comment-length, examples and self-hosted configuration checks. Lint has five existing warnings and no errors.

Remote preview metadata now reads bounded PNG/JPEG/GIF/WebP headers without a native decoder. These are layout hints, not validation. Unsupported header formats return unknown dimensions; images still load. Oversized network chunks cannot exceed the retained 450 KB buffer limit.

No changes under src/db, src/auth, src/middleware or src/storage. This PR does not provide full video reconstruction or desktop raster isolation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant