Skip to content

fix(media): strip data URI prefix from base64 media strings - #489

Open
jackiectl2 wants to merge 1 commit into
weaviate:mainfrom
jackiectl2:fix-data-uri-base64
Open

jackiectl2 wants to merge 1 commit into
weaviate:mainfrom
jackiectl2:fix-data-uri-base64

Conversation

@jackiectl2

Copy link
Copy Markdown

Fixes #250

What

toBase64FromMedia now accepts base64 data URIs such as data:image/jpeg;base64,<data> (e.g. the output of FileReader.readAsDataURL or canvas.toDataURL) and sends only the base64 payload to Weaviate, in both @weaviate/node and @weaviate/web. This applies everywhere media goes through toBase64FromMedia: nearImage/nearMedia in query, generate and aggregate, and generative images.

Why

  • web: strings starting with data: were returned unchanged, so the prefix was sent to the server and the request failed.
  • node: the string was passed to fs.stat first, so a short data URI failed with ENOENT; a long one hit ENAMETOOLONG, was then treated as a URL, and failed with Failed to download image from URL.

The v2 GraphQL nearMedia builder already strips this prefix; this does the same for the collections API. Non-base64 data: strings keep their current behaviour.

Testing

  • New unit tests: packages/test/node/base64/unit.test.ts (via the public @weaviate/node export) and packages/test/web/base64.test.ts. They fail without the change.
  • npm run lint, npm run format:check, npm run build (incl. check:web) and all unit tests in packages/test pass locally.
  • Integration tests were not run locally (no Weaviate instance).

toBase64FromMedia passed strings like `data:image/jpeg;base64,<data>` on
unchanged. The web client sent the prefix to Weaviate, which rejects it,
and the node client treated the string as a file path or URL, so it
failed with ENOENT or "Failed to download image from URL".

Detect a `data:<mime>;base64,` prefix and return only the base64 payload,
as the v2 GraphQL nearMedia builder already does.

Signed-off-by: Tianlang (Jackie) Chen <305351710+jackiectl2@users.noreply.github.com>

@orca-security-eu orca-security-eu Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Orca Security Scan Summary

Status Check Issues by priority
Passed Passed Infrastructure as Code high 0   medium 0   low 0   info 0 View in Orca
Passed Passed SAST high 0   medium 0   low 0   info 0 View in Orca
Passed Passed Secrets high 0   medium 0   low 0   info 0 View in Orca
Passed Passed Vulnerabilities high 0   medium 0   low 0   info 0 View in Orca

@weaviate-git-bot

Copy link
Copy Markdown

To avoid any confusion in the future about your contribution to Weaviate, we work with a Contributor License Agreement. If you agree, you can simply add a comment to this PR that you agree with the CLA so that we can merge.

beep boop - the Weaviate bot 👋🤖

PS:
Are you already a member of the Weaviate Forum?

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Enable client to slice base64 string

2 participants