Skip to content

fix(reliability): validate Blob runtime input before property access #316

Description

@seonghobae

Current canonical ownership

Draft PR #160 / branch fix/blob-size-preflight-20260811 is the sole active Inkspan writer for this blobToDataUri() runtime-category boundary. Do not treat exact head/check snapshots in this issue as lifecycle authority; refetch PR #160, protected main, formal reviews/threads, live governance, and every applicable exact-head workflow immediately before any action. Active-PR source/tests and the PR body are higher-authority than this planning issue; protected main remains shipped truth until integration.

Acceptance contract

blobToDataUri() must prove the genuine platform Blob internal slot before using metadata or payload capabilities. Runtime non-Blob values fail through the stable Inkspan converter boundary before caller-controlled Blob-like size, type, or arrayBuffer members can become authority. Genuine Blob/File size and MIME metadata come from intrinsic platform getters; byte reads use the platform Blob capability rather than an instance override; the pre-read byte ceiling remains authoritative. Platform fallbacks, MIME precedence, browser/Node behavior, and standalone no-service operation remain intact.

The canonical #160 regression corpus must machine-check hostile Blob-like values, genuine Blob values with shadowed metadata/payload accessors, platform fallbacks, MIME precedence, and pre-read resource rejection. No network, persistence, authorization, tenancy, credentials, model/provider, deployment, migration, retention, or durable-audit authority moves into Inkspan.

Evidence rule

Predecessor workflow/review results are historical only. Pending, queued, skipped, cancelled, absent, stale, predecessor, status-only, or model-only evidence is non-passing. Exact-current-head technical success does not substitute for qualifying independent approval or then-live governance.

Integration boundary

Keep this issue open until #160 integrates under then-live governance. Keep #160 Draft/unmerged while #118 owns the frozen protected v0.6.0 publication/provenance boundary and exact-current-head gates plus qualifying independent approval remain incomplete. Do not create a competing converter writer, transfer predecessor evidence, self-approve, weaken gates, force-push/destructively rebase, move protected main, or fabricate release identity.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: apiAPI, protocol, event, or external contractarea: authAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: securitySecurity boundary, hardening, or vulnerability preventionpriority: mediumNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behavior

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions