Repository navigation
Encrypt Buffer-sourced Recipe output in endPDF - #967
Merged
Merged
Conversation
A Recipe created from a Buffer accepted encrypt() but endPDF() skipped the re-encryption step, logged "Encryption is not supported in Buffer Mode yet." and handed the callback (or wrote to the output path) an unencrypted PDF. The low-level recrypt() binding already accepts a read stream and a write stream, so _encrypt() now re-encrypts the collected output bytes through PDFRStreamForBuffer/PDFWStreamForBuffer and swaps the result in before the callback runs or the output path is written. Wasm already re-encrypted the finished bytes; its test suite gains the mirrored modified-source case so both ends assert the same behavior.
Documentation build overview
|
recrypt() takes the source password in `password`, but encrypt() filled that key with the new owner password, so a PDF the constructor options had already encrypted could not be re-encrypted and endPDF() threw. _encrypt() now opens the output with the constructor password, skips an encrypt() call without a password as Wasm does, and replaces the collected Buffer bytes instead of holding the plaintext next to the encrypted copy. The public .d.ts no longer says Buffer sources stay unencrypted, and the Wasm tests share one recipeFixture() helper.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A
Recipecreated from aBufferacceptedencrypt(), butendPDF()skipped the re-encryption step, printedFeature: Encryption is not supported in Buffer Mode yet.and delivered an unencrypted PDF to the callback (or wrote one to the output path).The low-level
recrypt()binding already accepts a read stream and a write stream, so no C++ change is needed._encrypt()now re-encrypts the collected output bytes throughPDFRStreamForBuffer/PDFWStreamForBufferand swaps the result in before the callback runs or the output path is written. The path-source branch is unchanged.Parity
Wasm already re-encrypted the finished bytes in
endPDF(), so native was the lagging end here. The Wasm encryption test gains the mirrored "modified source with a view password" case so both suites assert the same behavior. NoDIFFERENCES.mdchange.Changes
packages/native-core/lib/recipe/encrypt.js: Buffer branch in_encrypt(), JSDoc updated (encrypt()no longer documents Buffer sources as unencrypted).packages/native-core/lib/Recipe.js: drop the Buffer-mode guard and its console message.packages/native-with-source/tests/recipe/encryption.js: three new cases (Buffer source with view password incl. repeatedendPDF(), Buffer source with output path and owner password, new Buffer PDF withencrypt()).packages/wasm/tests/recipe/encryption.test.mjs: mirrored modified-source case.packages/native/docs/recipe/encryption.md: Buffer example.CHANGELOG.md: Fixed entry. Output correction with no API change, so not a breaking change.Not in scope: the sibling
insertPageBuffer-mode guard directly above still only logs; it deserves its own issue.Verification
npm test: 871 passingpackages/wasm:node ./scripts/run-mocha.mjs tests/recipe/encryption.test.mjs: 3 passing on a fresh Wasm buildnpm run test:codestyle,npm run native:test:types,npm run native-with-source:test:types, strictnpm run docs:check: cleanCloses #446