Expand description
Plugin image assets (#156): a content plugin may ship images and reference them from routine steps, so a guided break can show what a stretch looks like rather than only describing it.
Assets travel inline in the manifest as base64, exactly like a
detector’s module_base64 — so a plugin is still one signed file. The
signature binds each asset by the sha256 declared alongside it (the
data_base64 blob is excluded from the signing payload; see
super::signature::signing_payload), and validate_asset independently
checks the bytes hash to that declared value. A tampered blob therefore
fails either the signature (if the hash was changed) or the hash check (if
only the bytes were swapped).
Everything here is pure — no I/O — and the format/dimension sniffing reads only header fields (it never decodes pixels), so a hostile file cannot turn validation itself into a decompression bomb. The pixel-count cap then bounds what the overlay will later decode.
Structs§
- Manifest
Asset - One inline image declared in a manifest.
data_base64is excluded from the signing payload; the signature binds the image throughsha256.
Enums§
- Asset
Kind - What a validated asset turned out to be. Routine images reference an
Image; sound cues reference anAudio. The kind lets the manifest check that each reference points at the right sort of asset. - Audio
Format - The audio formats a plugin may ship for break/routine cues. Detected by container magic bytes; the byte cap bounds their length.
- Image
Format - The image formats a plugin may ship. The raster formats each have a header
we can read dimensions from without decoding pixels;
Svgis vector XML, vetted structurally instead (seevalidate_svg).
Constants§
- MAX_
ASSETS - Most images a pack ever needs; bounds the manifest and the install dialog.
- MAX_
ASSET_ BYTES - Per-asset decoded-byte cap. Generous for a UI illustration, small enough that 64 of them stay well under the 8 MiB manifest cap.
- MAX_
ASSET_ 🔒ID_ LEN - MAX_
IMAGE_ PIXELS - Decode-time pixel cap (width × height). The decompression-bomb guard: a tiny compressed file can claim enormous dimensions, so we reject on the declared header size before anything decodes it.
- MAX_
SOUND_ BYTES - Tighter byte cap for audio cues. A cue is a short sound, not a track; the size bounds the playback length without parsing every container’s duration.
Functions§
- has_
event_ 🔒handler trueif the text holds an inlineon…="event-handler attribute (a space or tab/newline, thenon, then letters, then=). No benign SVG attribute begins withon, so the heuristic has no real false positives. Namespace declarations (xmlns) and href/src values are untouched. Coarse by design — seevalidate_svgfor why that is sufficient in the<img>render context.- has_
external_ 🔒ref trueif a fetching attribute/function (href,src, CSSurl(...),@import) points at a remote scheme (http,https, or protocol-relative//). Deliberately does not matchxmlns="http://…"namespace URLs (they carry nohref/src/url(), nor self-containeddata:URIs. Coarse by design — seevalidate_svgfor why that is sufficient in the<img>render context.- hex_
lower 🔒 - is_
safe_ 🔒asset_ id trueifidis a safe single filename component: non-empty, within the length cap, and only[a-z0-9._-](no path separators, no traversal).- sniff
- Identify an image’s format and pixel dimensions from its header alone.
Returns
Nonefor anything not in the allowlist or with a header too short or malformed to read. Never decodes pixel data. - sniff_
audio - Identify an audio container from its magic bytes. WAV shares the
RIFFheader with WebP — theWAVEform type at 8..12 disambiguates. - sniff_
webp 🔒 - Dimensions from the three WebP chunk layouts (extended, lossless, lossy).
- u16le 🔒
- u24le 🔒
- u32be 🔒
- u32le 🔒
- validate_
asset - Decode and fully validate one declared asset, returning its decoded bytes and sniffed format on success. Checks, first-error-wins: a filename-safe id, a 64-char lowercase-hex sha256, valid base64, the decoded-byte cap, that the bytes hash to the declared sha256, an allowed format, and the pixel cap.
- validate_
svg 🔒 - Recognise and structurally vet an SVG document.