Strip metadata from processed images (closes #82)
check / check (push) Successful in 2m59s

Every output is exported with govips' StripMetadata, so it carries no
EXIF, XMP, IPTC or ICC profile, the orig format included: it is always
re-encoded, and pixa never serves the source bytes. The image is turned
upright with AutoRotate right after decoding, so dropping the
orientation tag does not leave it rotated, and a requested size applies
to the upright image. An image with an ICC profile is converted to sRGB
before export, since clients show an image with no profile as sRGB.
No setting turns this off. README.md documents it.

Model: opus-5-5
This commit is contained in:
2026-09-28 23:56:21 +00:00
parent b3e59e7855
commit f5902f4241
3 changed files with 43 additions and 1 deletions
+6 -1
View File
@@ -30,6 +30,12 @@ exhaustion
# Completed Steps
- 2026-09-28 strip metadata from processed images (closes #82): every output is
exported with govips' `StripMetadata`, so it carries no EXIF, XMP, IPTC or ICC
profile; the image is first turned upright with `AutoRotate` (before sizes are
worked out) and, when it has an ICC profile, converted to sRGB; the `orig`
format is re-encoded and stripped like any other, as pixa never serves the
source bytes; there is no setting to keep metadata; documented in `README.md`.
- 2026-09-28 rate limit the login form (closes #66): `POST /` is limited to 5
attempts per minute per client address, and an attempt over the limit is
refused with 429 and a `Retry-After` header; the address is the one
@@ -251,7 +257,6 @@ exhaustion
# Future Steps
- P1: strip EXIF and other metadata from processed images (privacy)
- P2: security
- referer blacklist
- per-IP rate limiting on the image routes