Check downloaded originals against their recorded content hash (closes #68)
check / check (push) Successful in 58s
check / check (push) Successful in 58s
downloadFile, shared by quak get, the content cache and backup, hashes the decrypted bytes (unkeyed BLAKE2b-512, standard base64) and stores nothing on a mismatch, failing with an error naming the file ID. A live photo ZIP is unpacked as it streams with fflate's Unzip, in small slices so memory stays bounded however far an entry expands, and its image and video hashed separately as <imageHash>:<videoHash>. decryptFile reads the older imageHash/videoHash fields for live photos. A file with no recorded hash is stored unchecked. Model: opus-5-5
This commit was merged in pull request #98.
This commit is contained in:
+23
-1
@@ -34,6 +34,28 @@ const FILE_TYPE_MAP: Record<number, FileType> = {
|
||||
|
||||
const parseFileType = (n: number): FileType => FILE_TYPE_MAP[n] ?? "unknown";
|
||||
|
||||
// The hash the uploading client recorded for the original's bytes, read the
|
||||
// way the upstream client's `metadataHash` reads it: `hash` if present,
|
||||
// otherwise, for a live photo from an older client that wrote the two parts
|
||||
// separately, `<imageHash>:<videoHash>`. A field that is not a non-empty
|
||||
// string counts as absent, and a file with no hash at all is normal.
|
||||
const expectedHash = (json: Record<string, unknown>): string | undefined => {
|
||||
const text = (v: unknown): string | undefined =>
|
||||
typeof v === "string" && v !== "" ? v : undefined;
|
||||
const hash = text(json.hash);
|
||||
if (hash !== undefined) return hash;
|
||||
const imageHash = text(json.imageHash);
|
||||
const videoHash = text(json.videoHash);
|
||||
if (
|
||||
json.fileType === 2 &&
|
||||
imageHash !== undefined &&
|
||||
videoHash !== undefined
|
||||
) {
|
||||
return `${imageHash}:${videoHash}`;
|
||||
}
|
||||
return undefined;
|
||||
};
|
||||
|
||||
export const decryptCollection = (
|
||||
raw: RawCollection,
|
||||
keys: KeyMaterial,
|
||||
@@ -115,7 +137,7 @@ export const decryptFile = (
|
||||
modificationTime: metadataJSON.modificationTime ?? 0,
|
||||
latitude: metadataJSON.latitude,
|
||||
longitude: metadataJSON.longitude,
|
||||
hash: metadataJSON.hash,
|
||||
hash: expectedHash(metadataJSON),
|
||||
};
|
||||
|
||||
const magicMetadata = decryptMagicMetadata(raw.magicMetadata, key);
|
||||
|
||||
Reference in New Issue
Block a user