🚨 Severity: MEDIUM
💡 Vulnerability: Missing input validation on file upload allowed non-image files to be stored in settings.
🎯 Impact: Storing non-image data (potentially malicious payloads) in settings storage, which could be used for further exploitation or DoS.
🔧 Fix:
- Added strict file type validation (`image/*`) in `handleFileUpload`.
- Updated `optimizeImage` to return `null` if image loading fails, ensuring invalid data is not stored.
- Added user alerts for invalid file types or processing failures.
✅ Verification:
- Added `src/__tests__/image-security.test.ts` to verify `optimizeImage` fails securely.
- Verified with `pnpm test`.