mirror of
https://github.com/heygen-com/hyperframes.git
synced 2026-09-14 18:01:20 +08:00
9db1b9d314
Adds `hyperframes capture-video <project>` which downloads a single
video from the capture's video-manifest.json on demand. The capture
pipeline writes the manifest + preview PNGs but deliberately skips
the mp4s — a site with 12+ feature videos would balloon the capture
from ~5 MB to hundreds of MB. This command pulls one entry at a
time, addressed by --index N (matched against the manifest entry's
own `index` field, not array offset — the manifest can have gaps).
• SSRF-safe via `safeFetch` from capture/assetDownloader (rejects
private/metadata hosts, re-validates redirects).
• Content-type whitelist: `video/*` + a small set of common
`application/*` variants. Anything else (HTML error pages,
JSON, tracking pixels) aborts cleanly.
• 250 MB hard cap on Content-Length AND body size.
• Filename sanitization: percent-decoded then anything outside
[A-Za-z0-9._-] stripped.
• Race-free write: `flag: "wx"` atomic exclusive-create with
EEXIST handled as 'already downloaded' (no upstream existsSync
precheck — eliminates the TOCTOU pattern).
• Dual-layout aware: checks `<dir>/extracted/` (standalone
capture) and `<dir>/capture/extracted/` (W2H project layout).
• Suggested embed snippet includes `id="video-${entry.index}"`
so the output passes the producer's media discovery / lint.
Registered in cli.ts + help.ts.