Uploads were written to the qr disk byte-for-byte. A bookshop cover arrived as a 9000x6600 print-resolution JPEG — 18MB — and was then served in full to every visitor of a public bio page. During a launch that one file accounted for roughly 1.6GB of 1.9GB of image traffic, and because these assets are proxied through the app rather than served statically, PHP streamed every byte of it and held a worker for the duration. Nothing the QR/bio pages display needs more than a couple of thousand pixels, so UploadedImageOptimizer caps the long edge at 2000px and re-encodes on the way in. The incident file becomes ~350KB. Configurable via qr.image.*. Deliberately conservative, because a broken upload is worse than a large one: - Format is preserved. A PNG stays a PNG so transparency survives; converting to JPEG would put black boxes behind logos. - GIF is excluded — GD would silently drop animation frames. - SVG and any file GD cannot read is stored untouched. - Small files are passed through rather than lossily re-encoded for no gain. - Output is discarded if it came out larger than the original. - Any failure logs and falls back to storing the original. Applied to the seven image paths only. Books (PDF/EPUB) and documents keep the plain store — the optimiser would have fallen through for them anyway, but routing non-images through something called an image optimiser invites the wrong change later. This is the source-level counterpart to the nginx cache: caching stops the bytes being regenerated, this stops them existing. Tests: 6 new, including the real 9000x6600 shape, PNG alpha survival, format preservation and non-image passthrough. Pre-existing suite failures unchanged at 8. Co-Authored-By: Claude <noreply@anthropic.com>
23 lines
1018 B
PHP
23 lines
1018 B
PHP
<?php
|
|
|
|
return [
|
|
'price_per_qr_ghs' => (float) env('QR_PRICE_PER_QR_GHS', 5.0),
|
|
'min_topup_ghs' => (float) env('QR_MIN_TOPUP_GHS', 5.0),
|
|
'max_pdf_bytes' => (int) env('QR_MAX_PDF_BYTES', 104857600), // 100 MB
|
|
|
|
/*
|
|
| Uploaded images are downscaled and re-encoded before storage. These assets
|
|
| are proxied through PHP to public bio pages, so an oversized original costs
|
|
| a worker and full bandwidth on every single view — a 9000x6600 18MB cover
|
|
| once accounted for ~1.6GB of 1.9GB of image traffic during a launch.
|
|
*/
|
|
'image' => [
|
|
'max_dimension' => (int) env('QR_IMAGE_MAX_DIMENSION', 2000),
|
|
'jpeg_quality' => (int) env('QR_IMAGE_JPEG_QUALITY', 82),
|
|
// Small files are stored untouched rather than lossily re-encoded.
|
|
'passthrough_bytes' => (int) env('QR_IMAGE_PASSTHROUGH_BYTES', 512000),
|
|
],
|
|
'short_code_length' => (int) env('QR_SHORT_CODE_LENGTH', 8),
|
|
'scan_unique_window_hours' => (int) env('QR_SCAN_UNIQUE_WINDOW_HOURS', 24),
|
|
];
|