Skip to content

fix: strip EXIF metadata when withMetadata is false without explicit adjustments (#18629) - #18630

Open
PINYOPATTANAWASANPORN wants to merge 1 commit into
payloadcms:mainfrom
PINYOPATTANAWASANPORN:fix/uploads-strip-exif-metadata-18629
Open

PINYOPATTANAWASANPORN wants to merge 1 commit into
payloadcms:mainfrom
PINYOPATTANAWASANPORN:fix/uploads-strip-exif-metadata-18629

Conversation

@PINYOPATTANAWASANPORN

Copy link
Copy Markdown
Contributor

Summary of Changes

  • In packages/transformer-sharp/src/transformFile.ts, updated the early bypass condition in ransformMain so that when withMetadata: false is configured on the upload collection, images without dimensions adjustments (
    esizeOptions, ormatOptions, rimOptions, constructorOptions) are still passed through Sharp's transformation pipeline (
    otate() + optionallyAppendMetadata()) rather than early-returning { status: 'continue' } with raw unaltered buffers.
  • Added a unit test in packages/transformer-sharp/src/transformFile.spec.ts asserting that ransformMain processes the image and strips EXIF metadata when withMetadata: false is configured without explicit adjustments.

Root Cause / Technical Context

Fixes #18629.
When an upload collection specifies withMetadata: false without resizing or format conversions, ransformMain in packages/transformer-sharp/src/transformFile.ts previously bypassed Sharp completely via:
ypescript if (!fileIsAnimatedType && !fileHasAdjustments) { return { status: 'continue' } }
This caused the unmodified uploaded buffer to be written directly to storage, preserving raw EXIF metadata (GPS geographic coordinates, camera device info, timestamps). Checking withMetadata !== false ensures that collections configured to strip metadata correctly invoke Sharp to produce sanitized file buffers.

Verification & Testing

  • Added unit test: should strip EXIF metadata when withMetadata is false without image adjustments in ransformFile.spec.ts.
  • Validated that crop, ocalPoint, and collections with withMetadata === true or custom callbacks retain expected metadata behavior.
  • Minimal surgical diff (1-line code change + unit test).

Impact & Compatibility

  • Breaking changes: None.
  • Fully backward-compatible with existing transformers and upload collections.

@PINYOPATTANAWASANPORN PINYOPATTANAWASANPORN changed the title fix(transformer-sharp): strip EXIF metadata when withMetadata is false without explicit adjustments (#18629) fix: strip EXIF metadata when withMetadata is false without explicit adjustments (#18629) Oct 9, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug(uploads): raw uploaded images bypass transformer pipeline preserving sensitive EXIF GPS location metadata (CWE-200)

1 participant