feat : update i guess
CI / Verify (push) Failing after 1m4s
CI / Build immutable images and deploy (push) Skipped

This commit is contained in:
2026-10-03 15:47:47 +07:00 Unverified
parent f5cfe0a22e
commit 95c45841e7
15 changed files with 4297 additions and 174 deletions
+4
View File
@@ -9,6 +9,10 @@ describe("image decoding before publication", () => {
await expect(inspectImage(bytes, "image/jpeg")).rejects.toMatchObject({ status: 422 });
await expect(inspectImage(bytes.subarray(0, 40), "image/png")).rejects.toMatchObject({ status: 422 });
});
it.each(["jpeg", "webp"] as const)("accepts a decoded %s image", async (format) => {
const bytes = await sharp({ create: { width: 8, height: 12, channels: 3, background: "red" } })[format]().toBuffer();
await expect(inspectImage(bytes, `image/${format}`)).resolves.toEqual({ width: 8, height: 12 });
});
it("rejects a magic-byte-only fake", async () => {
await expect(inspectImage(Uint8Array.from([137, 80, 78, 71, 13, 10, 26, 10]), "image/png"))
.rejects.toMatchObject({ status: 422 });
+3 -6
View File
@@ -1,5 +1,3 @@
import sharp from "sharp";
import { HttpError } from "@/lib/security/http";
import { hasValidImageSignature, MAX_MEDIA_BYTES, type IMAGE_MIME_TYPES } from "./validation";
@@ -9,13 +7,12 @@ export async function inspectImage(bytes: Uint8Array, mimeType: (typeof IMAGE_MI
if (bytes.byteLength > MAX_MEDIA_BYTES) throw new HttpError(413, "image-too-large");
if (!hasValidImageSignature(bytes.subarray(0, 16), mimeType)) throw new HttpError(422, "invalid-image");
try {
const image = sharp(bytes, { limitInputPixels: MAX_IMAGE_PIXELS, failOn: "warning", animated: true });
const image = new Bun.Image(bytes, { maxPixels: MAX_IMAGE_PIXELS });
const metadata = await image.metadata();
const width = metadata.autoOrient.width || metadata.width;
const height = metadata.autoOrient.height || metadata.height;
const { width, height } = metadata;
if (!width || !height || width * height > MAX_IMAGE_PIXELS) throw new Error("invalid dimensions");
// Metadata alone accepts truncated images; decode pixels before publishing.
await image.stats();
await image.bytes();
return { width, height };
} catch {
throw new HttpError(422, "invalid-image");