From the 2026-06-27 audit branch (fix/audit-2026-06-27-critical-medium), whose
work was ~80% absorbed into main via the batch branches. This ports the pieces
that were NOT in main:
- compression.rs: cap image decode with image::Limits (12000x12000, 256 MiB
max_alloc) via ImageReader instead of image::open(). The upload body-size cap
bounds the file on disk but not the *decoded* dimensions, so a small
decompression-bomb image could OOM the box during decode/resize. Surgical port
of the audit's decode guard only (not its image/video semaphore split).
- docs/SECURITY-BACKLOG.md: the audit's triaged backlog, reconciled against main
(each item tagged done / open / contingent-on-signed-media). Records the still-
open items: host moderation UI gap, owner-delete SSE broadcast, quota
mount-detection (starts_with) + low-disk guard.
- docs/DECISION-media-auth.md: writes up the one real architectural divergence —
main serves media unauthenticated (ServeDir + UUID-capability) while the audit
built a signed/TTL'd gateway. Lays out the tradeoff (leaked URL = permanent vs
~24h access; banned-user access) and a recommendation, for a human decision.
Verified: cargo build clean.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>