fix: the provenance panel hotlinked the CDN for images already on disk (3965)
CI / lint (push) Successful in 8s
CI / extension-version (push) Successful in 9s
Build images / sign-extension (push) Successful in 9s
Build images / build-agent (push) Successful in 17s
CI / frontend-build (push) Successful in 35s
CI / backend-lint-and-test (push) Successful in 1m18s
Build images / build-web (push) Successful in 1m22s
Build images / smoke-web (push) Skipped
Build images / build-ml (push) Successful in 2m19s
Build images / promote (push) Skipped
CI / integration (push) Successful in 2m38s

Two surfaces render a post's HTML body. get_post did _localize_inline_images(sanitize_post_html(...)); provenance_service._post_dict called sanitize_post_html alone. So opening the Provenance panel fetched images from Patreon's CDN for files FC had already downloaded - the archive reaching out to the platform to display what it had archived, which is the thing 830 Phase 2 set out to stop. The same bodies also break when a CDN URL expires or a post is removed, while the identical local copy sits unused.

The fix is the shape, not the call. Those were two separately-callable halves and only the first looked mandatory, so a second caller was always going to do half of it. render_post_body in the new services/post_body.py is the whole pipeline in one call, and sanitizing-without-localizing is no longer a reachable operation. _localize_inline_images moves there verbatim; post_feed_service loses five imports that went with it.

_post_dict becomes async and takes the session. Both call sites are already inside async methods, so for_image's list comprehension awaits per entry - fine, because localization issues ZERO queries for a body with no inline <img>, which is most of them. Recorded that early exit in the module so the loop isn't "optimized" into a batch without a measurement.

Deliberately NOT fixed: provenance still names the same columns url/title/date where the feed says post_url/post_title/post_date, and its description_translated is full text where the feed truncates to DESCRIPTION_LIMIT. That is 3965's wider half - a breaking payload change for ProvenancePanel with no second reason to spend it today. Noted in _post_dict's docstring so the next reader knows it was seen and left.

Four regression tests on the provenance path, covering both entry points plus the two refusals the feed already pins: an uncaptured image stays hotlinked (a broken local path is worse than an intact remote one), and a filehash owned by another artist never leaks in. Reverting render_post_body to a bare sanitize fails the first two.

Recorded as snippet 3968.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SHQB1YukL3VyvMK8rcbmV9
This commit is contained in:
2026-09-12 19:57:00 -04:00
co-authored by Claude Opus 5
parent 2862fadcb1
commit 6f5ea5d1d3
4 changed files with 217 additions and 58 deletions
+20 -5
View File
@@ -18,17 +18,32 @@ from ..models import (
Source,
attachment_download_url,
)
from ..utils.html_sanitize import sanitize_post_html
from .post_body import render_post_body
def _post_dict(p: Post) -> dict:
async def _post_dict(session: AsyncSession, p: Post) -> dict:
"""One provenance entry's post.
NOTE: the key names here deliberately differ from
`PostFeedService._to_dict` (`url`/`title`/`date` vs
`post_url`/`post_title`/`post_date`, `attachment_count` vs `attachments`),
and `description_translated` is the FULL text here where the feed truncates
it to DESCRIPTION_LIMIT. That divergence is issue #3965's wider half and is
deliberately NOT addressed here — renaming is a breaking payload change for
ProvenancePanel with no second reason to spend it.
What IS fixed here is the body: this used to call `sanitize_post_html`
alone, so provenance bodies hotlinked the platform CDN for images already
on disk while the post detail view served local copies. `render_post_body`
is the whole pipeline, so the two surfaces cannot drift apart again.
"""
return {
"id": p.id,
"external_post_id": p.external_post_id,
"url": p.post_url,
"title": p.post_title,
"date": p.post_date.isoformat() if p.post_date else None,
"description_html": sanitize_post_html(p.description),
"description_html": await render_post_body(session, p.description, p.artist_id),
"attachment_count": p.attachment_count,
# Translation (#143): the English title/description shown by default when
# a translation exists; the UI toggles to the original. Source lang labels
@@ -131,7 +146,7 @@ class ProvenanceService:
"provenance_id": ip.id,
"captured_at": ip.captured_at.isoformat()
if ip.captured_at else None,
"post": _post_dict(post),
"post": await _post_dict(self.session, post),
"source": _source_dict(src) if src is not None else None,
"artist": _artist_dict(art),
}
@@ -154,7 +169,7 @@ class ProvenanceService:
return None
post, src, art = row
return {
"post": _post_dict(post),
"post": await _post_dict(self.session, post),
"source": _source_dict(src) if src is not None else None,
"artist": _artist_dict(art),
"attachments": await self._attachments_for_posts([post.id]),