Skip to main content

Encode an identifier into an image's pixels; verify a JSON record against any copy

Project description

Mememage

Encode an identifier into an image's pixels; verify a JSON record against any copy.

Mememage writes a 2-pixel-tall bar into the bottom rows of an image. The bar holds two values:

  • identifier — a short string that points to a JSON record, stored separately (a server, a CDN, IPFS, a file).
  • content hash — a SHA-256 over the record. verify recomputes it and compares against the bar.

The bar survives JPEG, resaves, screenshots, and re-uploads, so the identifier reads back from any copy. encode reads any image Pillow can open and writes a lossless PNG; decode and verify work on any format the bar survives. Record fields are arbitrary — captions, credits, generation parameters, links.

pip install mememage                 # encode / decode / verify — Pillow included
# pip install "mememage[encrypt]"    # adds AES-256 field encryption

Quickstart

Three functions, all pure image operations:

import mememage

# encode — write the bar into the image, build the record from your fields
result = mememage.encode("photo.png", {"title": "Morning fog", "by": "catmemes"})
result.identifier            # 'mememage-3dc5f03a747bb38e' (derived from the fields)
result.save("photo.json")    # the record — store or serve it separately

# decode — read the bar back out of the pixels (the inverse of encode)
bar = mememage.decode("photo.jpg")      # any format the bar survived: PNG, JPEG, a screenshot
bar.identifier, bar.content_hash

# verify — does a record match an image? (recomputed hash == the bar's)
mememage.verify("photo.jpg", result.record)        # True if the record is intact

You resolve the record from its identifier — look it up wherever you keep it, then verify:

bar    = mememage.decode("photo.jpg")    # identifier + content hash from the pixels
record = my_store[bar.identifier]        # your storage: a dict, a file, a DB, a URL
mememage.verify("photo.jpg", record)     # True if the record matches the image
  • encode accepts any image — a path, bytes, a PIL Image, or a numpy array (HEIC needs the [heic] extra) — and returns the barred image as Record.image. Given a destination — a path (in place, or a .png sibling for non-PNG), out=<path.png>, or out=<stream> (e.g. BytesIO) — it writes the file. Output is always PNG: the bar is lossless, and a lossy re-encode would corrupt it. An in-memory input with no destination never touches disk.
  • decode / verify accept the same in-memory forms — a path, bytes, a file-like, a PIL Image, or a numpy array. No disk round-trip.
  • No network I/Odecode returns the identifier; you resolve the record. Core is pure pixel + hash operations.

Encrypt private fields

  • Mark fields private to encrypt them (AES-256-GCM via PBKDF2) under a password.
  • The record still verifies without the password — the hash covers the ciphertext.
  • unlock returns the decrypted fields. The password is not stored; only the ciphertext is kept in the record.
result = mememage.encode("photo.png", {"title": "Public", "gps": "45.5,-122.6"},
                         password="hunter2", private=["gps"])
mememage.verify("photo.png", result.record)              # matches — no password
mememage.unlock(result, "hunter2")["gps"]                # '45.5,-122.6'

Command line

mememage encode photo.png --field title="Morning fog" -o photo.json   # write the record
mememage decode photo.jpg --record photo.json                         # VERIFIED (exit 0) / ALTERED (exit 1)
mememage decode photo.jpg                                             # read the identifier only (no record)

Without -o, the record is written next to the image as <identifier>.json. decode exits 0 on a match.

License

MIT.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

mememage-0.1.1.tar.gz (48.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

mememage-0.1.1-py3-none-any.whl (35.9 kB view details)

Uploaded Python 3

File details

Details for the file mememage-0.1.1.tar.gz.

File metadata

  • Download URL: mememage-0.1.1.tar.gz
  • Upload date:
  • Size: 48.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for mememage-0.1.1.tar.gz
Algorithm Hash digest
SHA256 9d83dc840e74ad12e5dc32bef7009be67dc54a3b75900ef1f860ce4876d3b979
MD5 2f4edbe4e4d32baa456b1b7c27ed42c2
BLAKE2b-256 405ce6aec3337e1f1ab356041b4edacf3deb7c983dd190536acc647a4329254b

See more details on using hashes here.

Provenance

The following attestation bundles were made for mememage-0.1.1.tar.gz:

Publisher: publish.yml on sememtac/mememage

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file mememage-0.1.1-py3-none-any.whl.

File metadata

  • Download URL: mememage-0.1.1-py3-none-any.whl
  • Upload date:
  • Size: 35.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for mememage-0.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 b19f71d1b659b3cb0bec0ad79e6663e8a583020e464e2d1aa4d543e6a095937a
MD5 83dc3b40e1e4382529a036c08b4368e8
BLAKE2b-256 0dff228cf4e65e642dae59fae3fcccd3ac128bb8704676dca4f4b4ab3be6304f

See more details on using hashes here.

Provenance

The following attestation bundles were made for mememage-0.1.1-py3-none-any.whl:

Publisher: publish.yml on sememtac/mememage

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page