mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-05 23:19:43 +02:00
feat(web): mobile image upload to active session via paste dialog (#101)
- Extend the keyboard accessory paste dialog with an image picker (camera / photo library) plus best-effort image paste, routing selected files through the existing _uploadAndInsertImages pipeline - Re-encode images to standard JPEG/PNG in the browser before upload, so mislabeled gallery images (e.g. MIUI WebP claiming image/jpeg) pass the server magic-byte check; PNG keeps transparency, GIF passes through untouched, decode failures fall back to the original file - Log the real byte header on the paste-image magic-mismatch branch to pin down any remaining format mismatches without a guessing loop - Ignore the runtime .claude-images/ upload directory Co-authored-by: Teigen <teigen@TeigendeMac-mini.local>
This commit is contained in:
@@ -1674,6 +1674,14 @@ export function registerSessionRoutes(
|
||||
// Sniff actual bytes — filename and Content-Type are both attacker-supplied.
|
||||
// Polyglot HTML/PNG would otherwise pass and serve back with image/png MIME.
|
||||
if (!imageMagicMatchesExt(imageBytes, ext)) {
|
||||
// Diagnostic: on some Android galleries (e.g. MIUI) a WebP/HEIF is
|
||||
// mislabeled as image/jpeg, so the declared ext passes the allowlist but
|
||||
// the magic bytes do not. Log the real header so format mismatches can be
|
||||
// pinned down without a reproduce-and-guess loop. The client now
|
||||
// re-encodes images to JPEG/PNG before upload, so this should be rare.
|
||||
console.warn(
|
||||
`[paste-image] magic mismatch: filename=${JSON.stringify(part.filename)} mime=${JSON.stringify(part.mimetype)} declaredExt=${ext} magic=${imageBytes.subarray(0, 12).toString('hex')}`
|
||||
);
|
||||
reply.code(415);
|
||||
return createErrorResponse(ApiErrorCode.INVALID_INPUT, `Image bytes do not match declared type ${ext}`);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user