How to Strip GPS EXIF Data Before Publishing Images in Node.js Express Apps
A developer guide outlines a secure image publishing pipeline for Node.js Express applications that strips GPS and EXIF metadata before any upload becomes publicly accessible. The approach uses Sharp for re-encoding uploads as fresh JPEG or WebP files, ensuring metadata is not carried over from the original. After re-encoding, the output bytes are parsed and verified using the exifr library, and the publish job is rejected if any GPS location fields are still detected. The original upload is kept access-controlled as evidence, while only the verified, metadata-free derivative is stored and published. The method also enforces an 8 MB request size limit and includes unit tests covering phone photos with GPS tags, orientation-tagged screenshots, and images with no EXIF data.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in