pub const MAX_PIXELS: u64 = _; // 67_108_864u64Expand description
Refuse anything above ~64 megapixels.
Not a performance tuning knob — a decoded 64MP image is a quarter of a gigabyte of RGBA, and the dimensions come from a file header that a document can reference without the user having looked at it. Checking before allocating turns “the editor died opening a note” into “that image shows its alt text”.