Tour Photo Attachment Metadata Sanitizer
- Read README.md, SECURITY.md, INTEGRATION.md, and COMPATIBILITY.md.
- Run
npm testandnpm run examplewith Node.js 18 or newer. - Map authorized host attachment facts into the input. Never treat caller metadata as proof of the image bytes.
- Review the retained allowlist and keep original filenames disabled unless the disclosure is intentional.
- Use a separate reviewed image pipeline to inspect, decode, strip binary metadata, re-encode, scan, and store the actual file.
- Stage with representative renter and staff fixtures, then use Floot Update/Publish and verify the exact production download, integration, access rules, and rollback.
This package performs no file, EXIF, upload, delete, authorization, or privacy-certification operation.