Every audio and video upload was probed and remuxed inside the request, whatever its length; ffmpeg would read any protocol and probe any format; `-map 0` kept the data tracks iPhones add, which mp4 refuses; nothing was ever transcoded, so HEVC or MPEG-4 Part 2 reached browsers that can't play them, and the advertised video_matrix_limit and frame rate limit were never applied; the output was read whole into memory, the video was saved before its poster could fail, and the poster's frame leaked in /tmp. FLAC uploads were served as 404. Now an upload sent to /api/v2/media is stored as sent in media-incoming (beside the media root, never served) and answered with 202 and no url, while a ProcessMedia job, one at a time, does the work; GET /api/v1/media/:id answers 206 until it is ready, or 422 with why, and media still processing can't be posted. v1 processes before answering. ffmpeg reads only that file (protocol whitelist, format forced from the probe) and drops data and subtitle tracks. A video browsers play as it is (H.264, VP8, VP9, AV1 within Media:MaxVideoPixels and MaxFrameRate) is remuxed, anything else transcoded to H.264 that fits, as Mastodon does; longer than Media:MaxSeconds is refused. Outputs move into place only once everything succeeded, every temporary file goes, durations are kept, FLAC is served as audio/flac, and the unit gets PrivateTmp. The instance API advertises the limits that are now applied. No pasture scenario uploads audio or video through PrivaPub, so the sweep could not see this. MastodonMediaTests: v2 answers 202 then the job makes it playable (and an unreadable file 422 once processed), media still processing can't be posted, MPEG-4 Part 2 becomes H.264, a video over the limit is made smaller, FLAC is served. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
103 lines
3.9 KiB
C#
103 lines
3.9 KiB
C#
using Microsoft.AspNetCore.Http;
|
|
using Microsoft.Extensions.Caching.Memory;
|
|
|
|
using MongoDB.Entities;
|
|
|
|
using NetVips;
|
|
|
|
using PrivaPub.Domain.Media;
|
|
using PrivaPub.Domain.Statuses;
|
|
using PrivaPub.Federation.Rendering;
|
|
using PrivaPub.Models.Media;
|
|
using PrivaPub.Tests.Support;
|
|
|
|
namespace PrivaPub.Tests.Domain
|
|
{
|
|
[Trait("Category", "Integration")]
|
|
public sealed class MediaFlowTests : IAsyncLifetime
|
|
{
|
|
Harness _harness;
|
|
|
|
public async ValueTask InitializeAsync()
|
|
{
|
|
Assert.SkipUnless(MongoFixture.Enabled, MongoFixture.Skip);
|
|
_harness = await Harness.Start();
|
|
}
|
|
|
|
public async ValueTask DisposeAsync()
|
|
{
|
|
if (_harness != default)
|
|
await _harness.DisposeAsync();
|
|
}
|
|
|
|
static byte[] Png(int width, int height)
|
|
{
|
|
using var image = (Image.Black(width, height, bands: 3) + new double[] { 10, 120, 200 }).Cast(Enums.BandFormat.Uchar);
|
|
return image.WriteToBuffer(".png");
|
|
}
|
|
|
|
static IFormFile Upload(byte[] bytes, string contentType) =>
|
|
new FormFile(new MemoryStream(bytes), 0, bytes.Length, "file", "picture") { Headers = new HeaderDictionary(), ContentType = contentType };
|
|
|
|
[Fact]
|
|
public async Task An_upload_is_attached_once_and_federated_with_its_alt_text()
|
|
{
|
|
var token = TestContext.Current.CancellationToken;
|
|
var (_, alice) = await _harness.Persona("alice");
|
|
var (_, mallory) = await _harness.Persona("mallory");
|
|
|
|
var upload = await _harness.Media.Upload(alice, Upload(Png(300, 200), "image/png"), "a blue square", "0.25,-0.5", false, token);
|
|
Assert.True(upload.Ok);
|
|
Assert.True(File.Exists(Path.Combine(_harness.Media.Root, upload.Attachment.FilePath)));
|
|
|
|
var stolen = await _harness.Statuses.Publish(mallory, new StatusDraft { Text = "mine", MediaIds = new[] { upload.Attachment.ID } }, token);
|
|
Assert.False(stolen.Ok);
|
|
|
|
var posted = await _harness.Statuses.Publish(alice, new StatusDraft { Text = "look", MediaIds = new[] { upload.Attachment.ID } }, token);
|
|
Assert.True(posted.Ok);
|
|
Assert.Equal(posted.Post.ID, (await DB.Default.Find<MediaAttachment>().OneAsync(upload.Attachment.ID, token)).PostId);
|
|
|
|
var note = ActivityPubRenderer.Note(posted.Post, alice, default, default);
|
|
var attachment = note["attachment"]![0]!;
|
|
Assert.Equal("a blue square", attachment["name"]!.GetValue<string>());
|
|
Assert.Equal(300, attachment["width"]!.GetValue<int>());
|
|
Assert.Equal(-0.5f, attachment["focalPoint"]![1]!.GetValue<float>());
|
|
Assert.StartsWith("https://privapub.test/media/files/", attachment["url"]!.GetValue<string>());
|
|
|
|
var reused = await _harness.Statuses.Publish(alice, new StatusDraft { Text = "again", MediaIds = new[] { upload.Attachment.ID } }, token);
|
|
Assert.False(reused.Ok);
|
|
}
|
|
|
|
[Fact]
|
|
public async Task Unsupported_files_are_refused()
|
|
{
|
|
var (_, alice) = await _harness.Persona("alice");
|
|
|
|
var outcome = await _harness.Media.Upload(alice, Upload(System.Text.Encoding.UTF8.GetBytes("<svg/>"), "image/svg+xml"), default, default, false, TestContext.Current.CancellationToken);
|
|
|
|
Assert.False(outcome.Ok);
|
|
Assert.Equal(422, outcome.Status);
|
|
}
|
|
|
|
[Fact]
|
|
public async Task The_proxy_serves_signed_remote_media_and_nothing_else()
|
|
{
|
|
var token = TestContext.Current.CancellationToken;
|
|
var path = $"/files/{Guid.NewGuid():N}.png";
|
|
_harness.Peer.ServeFile(path, Png(10, 10), "image/png");
|
|
var proxy = new MediaProxy(_harness.Local, Peer.Http(), _harness.Media, new StaticOptions<MediaOptions>(new MediaOptions()));
|
|
|
|
var wrapped = proxy.Wrap(_harness.Peer.A + path);
|
|
var parts = new Uri(wrapped).AbsolutePath.Split('/');
|
|
var (file, contentType) = await proxy.Fetch(parts[3], parts[4], token);
|
|
var (tampered, _) = await proxy.Fetch(parts[3].Replace(parts[3][0], parts[3][0] == 'A' ? 'B' : 'A'), parts[4], token);
|
|
|
|
Assert.StartsWith("https://privapub.test/media/proxy/", wrapped);
|
|
Assert.Equal("image/png", contentType);
|
|
Assert.True(File.Exists(file));
|
|
Assert.StartsWith(_harness.Media.ProxyRoot, file);
|
|
Assert.Null(tampered);
|
|
}
|
|
}
|
|
}
|