fn validate_svg(bytes: &[u8]) -> Option<Result<(), String>>Expand description
Recognise and structurally vet an SVG document.
None means the bytes are not an SVG at all, so validation falls through to
the audio sniffer / unsupported-format error. Some(Ok) is a safe SVG;
Some(Err(reason)) is an SVG carrying a dangerous construct.
The overlay renders assets with <img src=asset:…> under a CSP of
script-src 'self'; object-src 'none', so scripts, onload, and external
fetches inside an SVG never execute — these checks are defense-in-depth, plus
the one guard the <img> sandbox does not give: rejecting a DTD blocks XML
entity-expansion (“billion laughs”) and external-entity (XXE) attacks, which
happen at parse time. There is no pixel cap (vector); the decoded-byte cap
bounds the source, and with no entities it cannot expand.
The <script>/handler/external-ref checks below are coarse string/scanner
filters, not a general SVG sanitizer: a determined document can evade
them (whitespace around =, encoded characters, unquoted attributes). That
is harmless only because the render context is <img> + CSP, where the
evaded constructs are inert. Revisit them before rendering a plugin SVG any
other way (inline <svg>, <object>, a rasterizer, top-level navigation) —
in those contexts they would not be sufficient on their own.