Skip to content

Allow SVG in canBrowserDisplayImage - #26

Merged
m-mohr merged 3 commits into
moregeo-it:mainfrom
yharby:svg-browser-image
Oct 11, 2026
Merged

m-mohr merged 3 commits into
moregeo-it:mainfrom
yharby:svg-browser-image

Conversation

@yharby

@yharby yharby commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

Adds image/svg+xml to browserImageTypes and treats untyped .svg hrefs as images when allowUndefined is set. Browsers render SVG in <img> with scripts and external loads blocked, so this is safe.

This lets STAC Browser show SVG icons (getIcons). Note that thumbnails, previews and asset images typed image/svg+xml will now also display.

Tests added in tests/link.test.js, npm run check passes.

@m-mohr

m-mohr commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

Generally fine, but we may consider the following as SVG seem to have a security problem with scripts potentially and render in a generic (non-size) image tag usually worse than a raster image:

stac-js

  • getThumbnails(): sort SVG after raster images, and prefer a raster alternate over an SVG asset (browsers don't sniff SVG, so a mislabeled SVG fails where a PNG still loads)

See also radiantearth/stac-browser#1021 (comment)

@yharby

yharby commented Sep 25, 2026

Copy link
Copy Markdown
Contributor Author

Done in 9f1ca1d. getThumbnails() now sorts SVG after raster images, and prefers a raster alternate over an SVG asset.

@m-mohr
m-mohr force-pushed the svg-browser-image branch from be75e57 to 0d74adc Compare October 11, 2026 16:38
@m-mohr
m-mohr merged commit 50932ff into moregeo-it:main Oct 11, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants