Skip to content

✨[Feat] Sprint 15 Image Metadata Inspector & Cleaner - #29

Merged
maruson08 merged 6 commits into
v2from
feat/sprint-15-image-metadata
Aug 26, 2026
Merged

maruson08 merged 6 commits into
v2from
feat/sprint-15-image-metadata

Conversation

@maruson08

Copy link
Copy Markdown
Member

Summary

  • vendor the immutable secure-metadata v0.1.0 browser Release artifact from tag v0.1.0 / commit 352258ec413a838dfe8b9146370505f125b5ae10
  • pin secure-metadata-0.1.0.browser.js at SHA-256 8d0b8a1addf904760aa1f52378fb05eed6540520cb05fe2320d77011cba69c28 behind one same-origin adapter boundary
  • add a single-file JPEG, PNG, and WebP inspector with decoded-vs-opaque presentation and honest partial inspection semantics
  • implement authoritative Privacy Clean with ICC preservation, fail-closed post-clean verification, and normalized _clean output naming
  • add complete English, Korean, Japanese, Spanish, German, and French copy plus Image category navigation

Privacy and security

  • local-only processing; no upload, analytics, telemetry, CDN, npm runtime loading, GitHub runtime fetch, or automatic update check
  • no Canvas, pixel decoding, resizing, conversion, quality change, or re-encoding in this feature
  • unknown metadata is not guessed away; metadata-partial is successful but non-exhaustive
  • cleaned bytes are written only after verifyMetadata returns valid and every policy check passes

Validation

  • git diff --check
  • node tests/run-all.mjs
  • deterministic JPEG/PNG/WebP inspection, opaque WebP EXIF, removal, ICC preservation, deterministic output, verification, application-limit, naming/MIME, unsafe-sink, import-boundary, and network-path tests
  • vendor directory, package metadata, tag/commit provenance, and exact SHA-256 release gate
  • localhost route and referenced resource audit: all HTTP 200
  • in-app visual/manual browser QA was attempted twice but the browser host was blocked by the existing Windows ACL startup error; no tab was created

Closes #22
Closes #23
Closes #24
Closes #25
Closes #26
Closes #27
Closes #28

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant