Skip to content

fix(mobile): enforce image size gate via file measurement before base64 read (#229) - #715

Merged
rynfar merged 1 commit into
pylonfrom
fix/issue-229-image-file-share-size-gate
Sep 21, 2026
Merged

rynfar merged 1 commit into
pylonfrom
fix/issue-229-image-file-share-size-gate

Conversation

@rynfar

@rynfar rynfar commented Sep 21, 2026 •

Copy link
Copy Markdown
Collaborator

Closes #229

Summary of Fix

  • Early measurement before base64 read: In buildIncomingShareDraft (apps/mobile/src/features/sharing/incoming-share-model.ts), image URIs are measured with input.fileReader.readSize(uri) before calling readBase64(uri). If the file is oversized (>10 MB) or empty (<=0 bytes), it is rejected with an early warning and temporary owned files are cleaned up, avoiding converting multi-hundred-megabyte files into memory-hogging base64 strings and causing OOM crashes.
  • Ignore spoofed / unmeasured metadata: If the sender provides an untrusted size (e.g. Android OpenableColumns.SIZE) that underreports the real size, the disk measurement takes precedence.
  • Mixed share payload resolution: In apps/mobile/src/features/sharing/IncomingShareProvider.tsx, removed the arbitrary condition blocking resolvedPayloadsForFiles() when generic file payloads (file, audio, video) are present alongside images. Mixed shares now correctly resolve image metadata.
  • Unit tests: Added tests in incoming-share-model.test.ts verifying that oversized images are rejected before base64 conversion both when no resolved payloads exist and when resolved contentSize is inaccurate.

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

…64 read (#229)

- Measure image file size with fileReader.readSize before reading into base64
- Reject oversized images prior to materializing base64 payload into memory
- Allow image resolution when generic file payloads are present in mixed shares
- Add unit tests verifying size limit rejection without resolved payloads and with spoofed contentSize
- Closes #229
@vercel

vercel Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
pylon-marketing Ignored Ignored Preview Sep 21, 2026 9:25pm UTC

@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:M labels Sep 21, 2026
@rynfar
rynfar merged commit 44259f3 into pylon Sep 21, 2026
19 checks passed
@rynfar
rynfar deleted the fix/issue-229-image-file-share-size-gate branch September 21, 2026 21:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

mobile: mixed image+file share skips the image size gate before base64

1 participant