Strip metadata from processed images (closes #82) #145

Merged
clawbot merged 2 commits from issue-82-strip-metadata into next 2026-09-29 02:18:26 +02:00
Collaborator

Closes #82.

  • encode sets govips' StripMetadata on every export, so no output carries EXIF (GPS, serial number, embedded thumbnail), XMP, IPTC or an ICC profile.
  • Process calls AutoRotate right after decoding, so the orientation tag can go and a requested size applies to the upright image. Before, a rotated photo asked for by width alone got its height from the sideways image.
  • ICC: convert to sRGB, then strip. Clients show an image with no profile as sRGB, so colours stay right without passing on the source's profile, which can name the device or software; colours outside sRGB are clipped.
  • orig format: stripped like every other output. pixa never serves the source bytes; orig already re-encodes in the source's format.
  • No config key: nothing needs metadata kept, and a switch would only turn the protection off.
  • README.md gains an "Image Metadata" section.

Not visible in the diff:

  • The conversion names libvips' built-in "srgb" profile, not govips' SRGBIEC6196621ICCProfilePath, which govips sets on first use but reads without a lock.
  • govips ignores StripMetadata for GIF; libvips writes no EXIF, XMP or ICC profile to GIF anyway, and the test covers GIF.

Fixtures in internal/imageprocessor/testdata/, made once with the vips command-line tool and exiftool:

  • gps-exif.jpg (1 KB): 16x16 grey; exiftool added GPS, camera and capture-time tags.
  • orientation-6.jpg (811 bytes): 16x8, red left, blue right; exiftool set orientation 6.
  • display-p3.jpg (1.3 KB): 8x8 of (234, 51, 35), sRGB red written in Display P3, saved with libvips' built-in Display P3 profile.

Model: opus-5-5

Closes https://git.eeqj.de/sneak/pixa/issues/82. - `encode` sets govips' `StripMetadata` on every export, so no output carries EXIF (GPS, serial number, embedded thumbnail), XMP, IPTC or an ICC profile. - `Process` calls `AutoRotate` right after decoding, so the orientation tag can go and a requested size applies to the upright image. Before, a rotated photo asked for by width alone got its height from the sideways image. - **ICC: convert to sRGB, then strip.** Clients show an image with no profile as sRGB, so colours stay right without passing on the source's profile, which can name the device or software; colours outside sRGB are clipped. - **`orig` format: stripped like every other output.** pixa never serves the source bytes; `orig` already re-encodes in the source's format. - No config key: nothing needs metadata kept, and a switch would only turn the protection off. - `README.md` gains an "Image Metadata" section. Not visible in the diff: - The conversion names libvips' built-in `"srgb"` profile, not govips' `SRGBIEC6196621ICCProfilePath`, which govips sets on first use but reads without a lock. - govips ignores `StripMetadata` for GIF; libvips writes no EXIF, XMP or ICC profile to GIF anyway, and the test covers GIF. Fixtures in `internal/imageprocessor/testdata/`, made once with the `vips` command-line tool and `exiftool`: - `gps-exif.jpg` (1 KB): 16x16 grey; exiftool added GPS, camera and capture-time tags. - `orientation-6.jpg` (811 bytes): 16x8, red left, blue right; exiftool set orientation 6. - `display-p3.jpg` (1.3 KB): 8x8 of (234, 51, 35), sRGB red written in Display P3, saved with libvips' built-in Display P3 profile. Model: opus-5-5
clawbot added the needs-review label 2026-09-29 02:02:36 +02:00
clawbot self-assigned this 2026-09-29 02:02:36 +02:00
clawbot added 2 commits 2026-09-29 02:02:37 +02:00
Failing tests first: GPS EXIF must not survive into any output format,
an image with EXIF orientation 6 must come out upright (also when only a
width is asked for), and a Display P3 image must come out as sRGB with
no ICC profile. Three JPEG fixtures of about 1 KB each are added under
internal/imageprocessor/testdata/.

Model: opus-5-5
Strip metadata from processed images (closes #82)
check / check (push) Successful in 2m59s
f5902f4241
Every output is exported with govips' StripMetadata, so it carries no
EXIF, XMP, IPTC or ICC profile, the orig format included: it is always
re-encoded, and pixa never serves the source bytes. The image is turned
upright with AutoRotate right after decoding, so dropping the
orientation tag does not leave it rotated, and a requested size applies
to the upright image. An image with an ICC profile is converted to sRGB
before export, since clients show an image with no profile as sRGB.
No setting turns this off. README.md documents it.

Model: opus-5-5
Author
Collaborator

PASS. Variants already in a deployment's disk cache from before this change keep their metadata until evicted; that is outside #82 and worth its own issue.

Model: opus-5-5

PASS. Variants already in a deployment's disk cache from before this change keep their metadata until evicted; that is outside https://git.eeqj.de/sneak/pixa/issues/82 and worth its own issue. Model: opus-5-5
clawbot merged commit be060a8305 into next 2026-09-29 02:18:26 +02:00
clawbot deleted branch issue-82-strip-metadata 2026-09-29 02:18:26 +02:00
clawbot removed the needs-review label 2026-09-29 02:18:26 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/pixa#145