Urgent.News

What's breaking now, across thousands of outlets.

Tech

Decoding iPhone HEIC images in the browser with WebAssembly (no server, no uploads)

Every "free HEIC converter" website I found had the same privacy model: upload your photos to my server, wait, download the result. Family photos. Screenshots. Whatever was in your camera roll. I didn't want my files on someone else's disk, and I doubted other people wanted theirs on mine either. So I spent a while teaching the browser to do it locally instead. This post is about how the decoding…

A web-based tool called SnappyKit allows users to convert HEIC images to JPG, PNG, WebP, or AVIF formats directly in their browser without any server-side processing or file uploads. This is achieved by leveraging the libheif library, which has been integrated into WebAssembly (WASM), enabling the decoding to happen locally within the user's browser.

The HEIF image format, which supports high-quality photography, is decoded using libheif-js/wasm-bundle, a WASM module that wraps the libheif library. The API for the decoder is kept minimal, consisting of a HeifImage interface for accessing image dimensions, displaying the image data, and freeing the memory allocated for the image.

To ensure a smooth user experience, the HEIC decoder is lazy-loaded only when needed, using a promise to load the WASM module and caching it to prevent race conditions when multiple conversions are performed simultaneously. All allocated memory for the decoded images must be explicitly freed using the free() function to avoid memory leaks.

The website employs a strict Content Security Policy (CSP) to enhance security. The WASM-related security requirement, wasm-unsafe-eval, is added per-route in the Next.js configuration to maintain a strict policy for the majority of the site. A similar approach is taken for the bundle's bundler quirks, ensuring that the CommonJS files within the WASM package are treated properly by webpack, preventing critical dependency errors.

The converter also includes safeguards to protect users' privacy and device security. It rejects any image exceeding 100 megapixels or 16000 pixels per side, limiting the pixel work to prevent potential performance issues. Additionally, decode failures result in a user-friendly message instead of exposing raw error information, maintaining the privacy of users' files.

The website also performs automated tests to ensure that no image uploads or external-origin requests are made during the conversion process, guaranteeing that users' photos remain on their devices at all times.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

I Tried to Teach a Computer "Apple" (It Thought It Was a Fruit, an iPhone, and a Vector)

Hello, DEV Community! 🙌 It’s my first time writing here. As I was studying how models handle text today, I ran into a funny realization: computers don't understand human words at all.

  • Computers understand language through numbers, not words
  • Word embedding represents words as points in a high-dimensional space
  • Mathematical operations on word vectors reveal semantic relationships

Curate Verifiable ActiveAdmin 4 Themes with Markdown and CI

When a Rails theme claims ActiveAdmin 4 support, the difficult part is often not finding a screenshot. It is checking whether the theme actually targets ActiveAdmin 4's Tailwind-based asset model…

  • Curated directory of ActiveAdmin 4 themes
  • Repository focuses on documentation and links
  • GitHub Actions ensures Markdown validity

Not the 90s?

Oh, yeah, those were the days? No, the 1990s weren’t better. We devs weren’t better, the users weren’t better, and, hell, payment wasn’t better.

  • Developers in the 90s faced tool and system shortcomings
  • Users appreciated improvements that enhanced experience
  • Current approach relies on prompting, potentially leading to suboptimal solutions

The Real Cost of Returning the Identity Value in EF Core

When you insert thousands of rows into SQL Server with Entity Framework Core, performance drops quickly. Most developers blame change tracking.

  • EF Core makes extra round-trip to database for identity values
  • SQL Server auto-increment primary key triggers this overhead
  • Large batches suffer significant performance slowdown

More from Wednesday 30 September →