feat : update i guess
This commit is contained in:
@@ -9,6 +9,10 @@ describe("image decoding before publication", () => {
|
||||
await expect(inspectImage(bytes, "image/jpeg")).rejects.toMatchObject({ status: 422 });
|
||||
await expect(inspectImage(bytes.subarray(0, 40), "image/png")).rejects.toMatchObject({ status: 422 });
|
||||
});
|
||||
it.each(["jpeg", "webp"] as const)("accepts a decoded %s image", async (format) => {
|
||||
const bytes = await sharp({ create: { width: 8, height: 12, channels: 3, background: "red" } })[format]().toBuffer();
|
||||
await expect(inspectImage(bytes, `image/${format}`)).resolves.toEqual({ width: 8, height: 12 });
|
||||
});
|
||||
it("rejects a magic-byte-only fake", async () => {
|
||||
await expect(inspectImage(Uint8Array.from([137, 80, 78, 71, 13, 10, 26, 10]), "image/png"))
|
||||
.rejects.toMatchObject({ status: 422 });
|
||||
|
||||
@@ -1,5 +1,3 @@
|
||||
import sharp from "sharp";
|
||||
|
||||
import { HttpError } from "@/lib/security/http";
|
||||
import { hasValidImageSignature, MAX_MEDIA_BYTES, type IMAGE_MIME_TYPES } from "./validation";
|
||||
|
||||
@@ -9,13 +7,12 @@ export async function inspectImage(bytes: Uint8Array, mimeType: (typeof IMAGE_MI
|
||||
if (bytes.byteLength > MAX_MEDIA_BYTES) throw new HttpError(413, "image-too-large");
|
||||
if (!hasValidImageSignature(bytes.subarray(0, 16), mimeType)) throw new HttpError(422, "invalid-image");
|
||||
try {
|
||||
const image = sharp(bytes, { limitInputPixels: MAX_IMAGE_PIXELS, failOn: "warning", animated: true });
|
||||
const image = new Bun.Image(bytes, { maxPixels: MAX_IMAGE_PIXELS });
|
||||
const metadata = await image.metadata();
|
||||
const width = metadata.autoOrient.width || metadata.width;
|
||||
const height = metadata.autoOrient.height || metadata.height;
|
||||
const { width, height } = metadata;
|
||||
if (!width || !height || width * height > MAX_IMAGE_PIXELS) throw new Error("invalid dimensions");
|
||||
// Metadata alone accepts truncated images; decode pixels before publishing.
|
||||
await image.stats();
|
||||
await image.bytes();
|
||||
return { width, height };
|
||||
} catch {
|
||||
throw new HttpError(422, "invalid-image");
|
||||
|
||||
Reference in New Issue
Block a user