Check downloaded originals against their recorded content hash (closes #68)
check / check (push) Successful in 16s
check / check (push) Successful in 16s
downloadFile, shared by quak get, the content cache and backup, hashes the decrypted bytes (unkeyed BLAKE2b-512, standard base64) and stores nothing on a mismatch, failing with an error naming the file ID. A live photo ZIP is unpacked as it streams with fflate's Unzip, in small slices so memory stays bounded however far an entry expands, and its image and video hashed separately as <imageHash>:<videoHash>. decryptFile reads the older imageHash/videoHash fields for live photos. A file with no recorded hash is stored unchecked. Model: opus-5-5
This commit is contained in:
@@ -351,6 +351,46 @@ describe("model.decryptFile", () => {
|
||||
}
|
||||
});
|
||||
|
||||
it("reads the recorded content hash, joining an older live photo's two parts", () => {
|
||||
const masterKey = sodium.crypto_secretbox_keygen();
|
||||
const { collectionKey } = buildRawCollection(masterKey);
|
||||
const hashOf = (metadata: Record<string, unknown>) =>
|
||||
decryptFile(
|
||||
buildRawFile(collectionKey, {
|
||||
metadata: { title: "x", ...metadata },
|
||||
}),
|
||||
collectionKey,
|
||||
).metadata.hash;
|
||||
|
||||
expect(hashOf({ fileType: 0, hash: "H" })).toBe("H");
|
||||
expect(
|
||||
hashOf({ fileType: 2, hash: "H", imageHash: "I", videoHash: "V" }),
|
||||
).toBe("H");
|
||||
expect(hashOf({ fileType: 2, imageHash: "I", videoHash: "V" })).toBe(
|
||||
"I:V",
|
||||
);
|
||||
expect(hashOf({ fileType: 2, imageHash: "I" })).toBeUndefined();
|
||||
expect(
|
||||
hashOf({ fileType: 0, imageHash: "I", videoHash: "V" }),
|
||||
).toBeUndefined();
|
||||
expect(hashOf({ fileType: 0 })).toBeUndefined();
|
||||
expect(hashOf({ fileType: 0, hash: 42 })).toBeUndefined();
|
||||
expect(
|
||||
hashOf({ fileType: 2, imageHash: "I", videoHash: 7 }),
|
||||
).toBeUndefined();
|
||||
// An empty string counts as absent, not as a hash to match.
|
||||
expect(hashOf({ fileType: 0, hash: "" })).toBeUndefined();
|
||||
expect(
|
||||
hashOf({ fileType: 2, hash: "", imageHash: "I", videoHash: "V" }),
|
||||
).toBe("I:V");
|
||||
expect(
|
||||
hashOf({ fileType: 2, imageHash: "", videoHash: "V" }),
|
||||
).toBeUndefined();
|
||||
expect(
|
||||
hashOf({ fileType: 2, imageHash: "I", videoHash: "" }),
|
||||
).toBeUndefined();
|
||||
});
|
||||
|
||||
it("maps fileType numbers to FileType strings", () => {
|
||||
// Ente uses: 0=image, 1=video, 2=livePhoto
|
||||
const masterKey = sodium.crypto_secretbox_keygen();
|
||||
|
||||
Reference in New Issue
Block a user