other
- Location
suspicious_person_detector.py:503- Finding
Biometric face snapshots are automatically uploaded to a public third-party image host
- Content
View full analysis
str: """Upload a local image to the sm.ms anonymous image host. Returns the public https URL on success, or '' on any failure. sm.ms accepts anonymous multipart uploads (no API key required); per-IP daily quota applies. Used by the Feishu push to obtain a clickable image URL because Feishu custom-bot cards cannot render external image URLs inline. """ if not local_path or not os.path.isfile(local_path): return "" try: with open(local_path, "rb") as f: files = {"smfile": (os.path.basename(local_path), f.read(), "image/jpeg")} resp = requests.post( "https://sm.ms/api/v2/upload", files=files, timeout=15, ) resp.raise_for_status() data = resp.json() if data.get("success") and data.get("data", {}).get("url"): return data["data"]["url"] if data.get("code") == "image_repeated" and data.get("images"): return data["images"] logger.warning(f"sm.ms upload non-success response: {data}") return "" except Exception as e: logger.error(f"Image host upload failed ({local_path}): {e}") return "" ``` ```python if face_local and app_id and app_secret: image_key = _feishu_upload_image(app_id, app_secret, face_local) # Fallback: public image host URL if not image_key and face_local: face_url = _upload_image_to_imghost(face_local) ``` ### Technical Analysis Face snapshots are sensitive biometric and surveillance data. When Feishu notification is enabled, the code first tries to upload the snapshot to Feishu. If application credentials are absent, incomplete, invalid, or the Feishu upload merely fail ...[truncated 2260 chars]- Remediation
View remediation
