Tour Photo Attachment Metadata Sanitizer

  1. Read README.md, SECURITY.md, INTEGRATION.md, and COMPATIBILITY.md.
  2. Run npm test and npm run example with Node.js 18 or newer.
  3. Map authorized host attachment facts into the input. Never treat caller metadata as proof of the image bytes.
  4. Review the retained allowlist and keep original filenames disabled unless the disclosure is intentional.
  5. Use a separate reviewed image pipeline to inspect, decode, strip binary metadata, re-encode, scan, and store the actual file.
  6. Stage with representative renter and staff fixtures, then use Floot Update/Publish and verify the exact production download, integration, access rules, and rollback.

This package performs no file, EXIF, upload, delete, authorization, or privacy-certification operation.