Skip to content

Encrypt Buffer-sourced Recipe output in endPDF - #967

Merged
julianhille merged 2 commits into
developfrom
issue/446-recipe-buffer-encrypt
Oct 7, 2026
Merged

julianhille merged 2 commits into
developfrom
issue/446-recipe-buffer-encrypt

Conversation

@julianhille

Copy link
Copy Markdown
Owner

Summary

A Recipe created from a Buffer accepted encrypt(), but endPDF() skipped the re-encryption step, printed Feature: Encryption is not supported in Buffer Mode yet. and delivered an unencrypted PDF to the callback (or wrote one to the output path).

The low-level recrypt() binding already accepts a read stream and a write stream, so no C++ change is needed. _encrypt() now re-encrypts the collected output bytes through PDFRStreamForBuffer / PDFWStreamForBuffer and swaps the result in before the callback runs or the output path is written. The path-source branch is unchanged.

Parity

Wasm already re-encrypted the finished bytes in endPDF(), so native was the lagging end here. The Wasm encryption test gains the mirrored "modified source with a view password" case so both suites assert the same behavior. No DIFFERENCES.md change.

Changes

  • packages/native-core/lib/recipe/encrypt.js: Buffer branch in _encrypt(), JSDoc updated (encrypt() no longer documents Buffer sources as unencrypted).
  • packages/native-core/lib/Recipe.js: drop the Buffer-mode guard and its console message.
  • packages/native-with-source/tests/recipe/encryption.js: three new cases (Buffer source with view password incl. repeated endPDF(), Buffer source with output path and owner password, new Buffer PDF with encrypt()).
  • packages/wasm/tests/recipe/encryption.test.mjs: mirrored modified-source case.
  • packages/native/docs/recipe/encryption.md: Buffer example.
  • CHANGELOG.md: Fixed entry. Output correction with no API change, so not a breaking change.

Not in scope: the sibling insertPage Buffer-mode guard directly above still only logs; it deserves its own issue.

Verification

  • npm test: 871 passing
  • packages/wasm: node ./scripts/run-mocha.mjs tests/recipe/encryption.test.mjs: 3 passing on a fresh Wasm build
  • npm run test:codestyle, npm run native:test:types, npm run native-with-source:test:types, strict npm run docs:check: clean

Closes #446

A Recipe created from a Buffer accepted encrypt() but endPDF() skipped the
re-encryption step, logged "Encryption is not supported in Buffer Mode
yet." and handed the callback (or wrote to the output path) an unencrypted
PDF. The low-level recrypt() binding already accepts a read stream and a
write stream, so _encrypt() now re-encrypts the collected output bytes
through PDFRStreamForBuffer/PDFWStreamForBuffer and swaps the result in
before the callback runs or the output path is written. Wasm already
re-encrypted the finished bytes; its test suite gains the mirrored
modified-source case so both ends assert the same behavior.
@read-the-docs-community

read-the-docs-community Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Documentation build overview

📚 MuhammaraJS | 🛠️ Build #34959017 | 📁 Comparing c87b7f7 against latest (a68f79d)

  🔍 Preview build  

3 files changed
± api/type-declarations.html
± recipe/encryption.html
± recipe/reference.html

recrypt() takes the source password in `password`, but encrypt() filled
that key with the new owner password, so a PDF the constructor options had
already encrypted could not be re-encrypted and endPDF() threw. _encrypt()
now opens the output with the constructor password, skips an encrypt()
call without a password as Wasm does, and replaces the collected Buffer
bytes instead of holding the plaintext next to the encrypted copy. The
public .d.ts no longer says Buffer sources stay unencrypted, and the Wasm
tests share one recipeFixture() helper.
@julianhille
julianhille merged commit 4e8a005 into develop Oct 7, 2026
49 checks passed
@julianhille
julianhille deleted the issue/446-recipe-buffer-encrypt branch October 7, 2026 23:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

enable encryption in recipe for buffers

1 participant