Skip to main content

Module asset

Module asset 

Source
Expand description

Plugin image assets (#156): a content plugin may ship images and reference them from routine steps, so a guided break can show what a stretch looks like rather than only describing it.

Assets travel inline in the manifest as base64, exactly like a detector’s module_base64 — so a plugin is still one signed file. The signature binds each asset by the sha256 declared alongside it (the data_base64 blob is excluded from the signing payload; see super::signature::signing_payload), and validate_asset independently checks the bytes hash to that declared value. A tampered blob therefore fails either the signature (if the hash was changed) or the hash check (if only the bytes were swapped).

Everything here is pure — no I/O — and the format/dimension sniffing reads only header fields (it never decodes pixels), so a hostile file cannot turn validation itself into a decompression bomb. The pixel-count cap then bounds what the overlay will later decode.

Structs§

ManifestAsset
One inline image declared in a manifest. data_base64 is excluded from the signing payload; the signature binds the image through sha256.

Enums§

AssetKind
What a validated asset turned out to be. Routine images reference an Image; sound cues reference an Audio. The kind lets the manifest check that each reference points at the right sort of asset.
AudioFormat
The audio formats a plugin may ship for break/routine cues. Detected by container magic bytes; the byte cap bounds their length.
ImageFormat
The image formats a plugin may ship. The raster formats each have a header we can read dimensions from without decoding pixels; Svg is vector XML, vetted structurally instead (see validate_svg).

Constants§

MAX_ASSETS
Most images a pack ever needs; bounds the manifest and the install dialog.
MAX_ASSET_BYTES
Per-asset decoded-byte cap. Generous for a UI illustration, small enough that 64 of them stay well under the 8 MiB manifest cap.
MAX_ASSET_ID_LEN 🔒
MAX_IMAGE_PIXELS
Decode-time pixel cap (width × height). The decompression-bomb guard: a tiny compressed file can claim enormous dimensions, so we reject on the declared header size before anything decodes it.
MAX_SOUND_BYTES
Tighter byte cap for audio cues. A cue is a short sound, not a track; the size bounds the playback length without parsing every container’s duration.

Functions§

has_event_handler 🔒
true if the text holds an inline on…=" event-handler attribute (a space or tab/newline, then on, then letters, then =). No benign SVG attribute begins with on, so the heuristic has no real false positives. Namespace declarations (xmlns) and href/src values are untouched. Coarse by design — see validate_svg for why that is sufficient in the <img> render context.
has_external_ref 🔒
true if a fetching attribute/function (href, src, CSS url(...), @import) points at a remote scheme (http, https, or protocol-relative //). Deliberately does not match xmlns="http://…" namespace URLs (they carry no href/src/url(), nor self-contained data: URIs. Coarse by design — see validate_svg for why that is sufficient in the <img> render context.
hex_lower 🔒
is_safe_asset_id 🔒
true if id is a safe single filename component: non-empty, within the length cap, and only [a-z0-9._-] (no path separators, no traversal).
sniff
Identify an image’s format and pixel dimensions from its header alone. Returns None for anything not in the allowlist or with a header too short or malformed to read. Never decodes pixel data.
sniff_audio
Identify an audio container from its magic bytes. WAV shares the RIFF header with WebP — the WAVE form type at 8..12 disambiguates.
sniff_webp 🔒
Dimensions from the three WebP chunk layouts (extended, lossless, lossy).
u16le 🔒
u24le 🔒
u32be 🔒
u32le 🔒
validate_asset
Decode and fully validate one declared asset, returning its decoded bytes and sniffed format on success. Checks, first-error-wins: a filename-safe id, a 64-char lowercase-hex sha256, valid base64, the decoded-byte cap, that the bytes hash to the declared sha256, an allowed format, and the pixel cap.
validate_svg 🔒
Recognise and structurally vet an SVG document.