Outcome
An accepted iMessage can include supported local image attachments, which Push forwards through the shared image pipeline to Codex, Pi, or Claude.
Dependencies
Constraints
- Read attachment metadata through the Messages database without reading image bytes during polling.
- Join attachments to their message while preserving one inbound message per Messages row.
- Read attachment bytes only inside the accepted worker.
- Canonicalize and verify each path under the Messages attachment directory before opening it.
- Reject missing files, directories, escaping symlinks, and unsupported types.
- Support JPEG, PNG, and WebP directly.
- Convert HEIC and HEIF to a private temporary JPEG using macOS system image tooling, then apply the shared size limit to the result.
- Preserve text decoding, reply-marker filtering, group rejection, cursors, and sender allowlists.
- Document the added Full Disk Access implications and local conversion behavior.
Acceptance criteria
Checks
cargo test --locked imessage
cargo test --locked gateway
cargo fmt --all --check
cargo clippy --locked --all-targets -- -D warnings
cargo build --locked
cargo test --locked
mkdocs build --strict
Manually send a JPEG screenshot and an iPhone HEIC photo through iMessage. Confirm both are understood and no converted files remain.
Out of scope
- iMessage image replies
- Videos, Live Photo video components, stickers, PDFs, and other documents
- Group chats
- Durable storage of image bytes
Outcome
An accepted iMessage can include supported local image attachments, which Push forwards through the shared image pipeline to Codex, Pi, or Claude.
Dependencies
Constraints
Acceptance criteria
Checks
Manually send a JPEG screenshot and an iPhone HEIC photo through iMessage. Confirm both are understood and no converted files remain.
Out of scope