Repository navigation
Every chat picture and video goes through the worker, and readers see a loader until it has (GRYT-1669) - #277
Merged
Conversation
… a loader until it has (GRYT-1669) Co-Authored-By: Claude Opus 5.5 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Sivert's call on GRYT-1669: all attachments through quarantine, quick and easy, with a loader in the client while the worker works.
What goes through the worker now
sniffMediareads the first 16 bytes, so a PNG sent asapplication/octet-streamis treated as a PNG. An HLS playlist named.mp4is not a video by its bytes, so it stays a plain file.chatvideo-v1(image-worker PR alongside). Without it they keep today's path: stored as sent, with a poster.attachment, asandboxCSP andnosniff, as before.The loader
processingwhile in quarantine, andrefusedonce the worker has given up. A refused file is never served, and the message says so rather than being pruned.settleChatAttachmentwaits for the worker's verdict, then sendschat:attachments { conversation_id, message_id, enriched_attachments }for every message carrying the file. It goes only to the people who can read that conversation, using the same recipients as an edit, so nothing about a private channel or DM goes anywhere else.POST /api/uploadsanswersprocessing.Tested live: server and worker in Docker, the web client from the client PR, real uploads through the composer. The loader showed at 0.25 s and cleared at 0.75 s. The 3 s video with sound came back as 640×360 AV1 + AAC, played in the client, and decoded audio. A fake HLS "video" showed "couldn't be processed". Unit tests:
sniffMedia, the mislabelled picture, chat video following the capability, and processing → refused. Full suite: 1968 pass, and the one runner hiccup (voiceRecovery.test.ts, a deserialize error) passes 14/14 on its own.What to look at:
listMessagesWithFileinsrc/db/sqlite/messages.tsreadsmessage_attachments. It's review-required, and a read only.chat:attachmentsyet, so a thread reply's loader clears on reopen.🤖 Generated with Claude Code