Firstly, sorry for my bad grammer. English is not my main language...
I'm developing a fully AJAXed wordpress theme that contains front end thread submission form in it and I wanted add animated GIF support.
And I wrote a code PHP code that uses imagick library:
// there is also another function that
checks image's exif, size, width, height, finfo and retuns true if all good.
// first imagick resize is basicly re-coding the image to kill shell/hack codes in the gif.
$imagick = new Imagick($image['tmp_name']);
$imagick = $imagick->coalesceImages();
foreach($imagick as $frame){
$frame->scaleImage($width, 0);
}
$imagick = $imagick->deconstructImages();
$imagick->writeImages($new_image_name, true);
$imagick->destroy();
// and this one for the thumbnail of the post.
$imagick = new Imagick($image['tmp_name']);
$imagick = $imagick->coalesceImages();
foreach($imagick as $frame){
$frame->scaleImage(wp_get_registered_image_subsizes()["left-frame-thumbnail"]["width"], 0);
}
$imagick = $imagick->deconstructImages();
$imagick->writeImages($new_image_name, true);
$imagick->destroy();
Code works like charm but I noticed this is a expensive code. I mean if user uploads a big gif file it will cause a CPU spike in my opinion.
And if rather I limit GIF sizes to like 2MB it doesn't matter because other problem is frame count. As we know that when we are resizing a GIF we are splitting all frames, resizing them and re-joining them together. There are a lot of gif around 300kb but contains 50+ frames in it. So frame count is also a problem for server's CPU.
Then I said; hey! let's resize gifs on client-side with Javascript! And I wrote a code that resize gif on client-side. And this really works very well.
I wrote a code on server side to get resized 2 gif file and saved them directly to server (also checking their exif,dimensions,finfo). All fine, server CPU is fine.
But! I noticed the number one rule: "never trust to data that came from client-side."
If I'm resizing it client side it's good. Resizing kills hack/shell codes in images. But what if users sends fake 2 two file that looks like its just resized and came from the form via console or something?
There is already a CSRF token in my ajax submission but I'm sure this is not enough.
Summary: What is the best way to handle with animated GIFs? What I'm doing wrong.