Repository navigation
Avatars, banners and chat images through the worker's quarantine (GRYT-1664) - #272
Merged
Merged
Conversation
… (GRYT-1664) When the image worker reports quarantine-v1 on /health, an avatar, a banner or a chat image is stored under quarantine/ as sent, with an image job, and the server never decodes it: the worker writes it out again inside its jail and moves the row. Any read of a file still in quarantine waits up to 15 seconds for that, then answers 503 media_not_ready with no-store, so the bytes as sent are never served. A worker that doesn't say quarantine-v1, including none at all and the desktop-embedded one, keeps today's path. Videos, group and webhook pictures and emoji are unchanged for now. Redoes the reverted 8d7f9bd, gated on the worker. Co-Authored-By: Claude Opus 5.5 <[email protected]>
…ntined Co-Authored-By: Claude Opus 5.5 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The server half of the upload plan in GRYT-1664. It goes with Gryt-chat/image-worker#40, and does nothing until that worker is deployed.
What it does
workerCapabilities.tsasks the image worker's/healthevery minute (IMAGE_WORKER_URL). Only when the answer listsquarantine-v1does the server use quarantine. No worker, an old worker, an unreachable worker, or the desktop-embedded worker (which has no jail) all mean today's path, unchanged.quarantine/avatars|banners|uploads/with an image job, and the server doesn't decode it. Before, it ran sharp (avatars and banners) orvalidateImage(chat) on the stranger's file itself. The worker writes it out again in its jail and moves the row (image-worker#40).GET /api/uploads/files/:idnever serves a quarantine key. A read waits up to 15 seconds for the worker's copy, which normally takes a second or two, so clients need no change. If it never comes, the answer is503 media_not_readywithno-store.Redoes the reverted 8d7f9bd (#268), gated on the worker this time, so a release can't leave uploads stranded.
What to look at
storeUploadedFileskipsvalidateImagefor a quarantined chat image. The worker refuses anything that doesn't decode, and the row has no width or height until it does.src/routes,src/services,src/index.ts).Tests: 1965 pass, 3 of them new. They cover a banner landing in quarantine with its job, a read that waits for the worker's copy, a read that gives up with 503, and the old path with a worker that doesn't claim quarantine.
🤖 Generated with Claude Code