Encryption handlers and permissions. All modules are fwModules; the handlers' fw-crypto deps resolve from @awacloud/fw/crypto.

Module Returns Deps Description
pdfSecurity { typeEncryptDict, selectHandler, isEmbeddedFileStream, dispatchDecryptStream } pdfErrors Dispatch, §7.6.2.
pdfStandardV4 { tryPassword, decryptString, decryptStream, decryptEmbeddedFile, encryptEmbeddedFile, encryptString, encryptStream, buildOU, buildPerms, computeFileKey, computeU, computeO, objectKey, rc4, md5, padPassword, PASSWORD_PADDING } pdfErrors, aes, cbc, bitArray PDF 1.6 legacy — RC4-128 / AES-128-CBC.
pdfStandardV5 { tryPassword, decryptString, decryptStream, encryptString, encryptStream, buildUUE, buildOOE, buildPerms } pdfErrors, fw crypto, pdfAesGcm? Historical R=5 AES-256.
pdfStandardV6 { tryPassword, decryptString, decryptStream, encryptString, encryptStream, buildUUE, buildOOE, buildPerms } pdfErrors, fw crypto, pdfAesGcm? R=6 hardening, §7.6.4.
pdfPermissions { decodePermissions, verifyPermsField } pdfErrors, fw aes /P + /Perms MAC.
pdfAesGcm { encryptObjectGcm, decryptObjectGcm } pdfErrors, fw aes, gcm, bitArray AES-GCM (ISO TS 32003).

Decryption pattern

const sec  = runtime.resolve('pdfSecurity');
const enc  = sec.typeEncryptDict(trailer.encrypt);
const selection = sec.selectHandler(enc, {
    v5: runtime.resolve('pdfStandardV5'),
    v6: runtime.resolve('pdfStandardV6')
});
const { fileEncryptionKey } = selection.handler.tryPassword(enc, password, false);

See also

  • pdfTrailer — carrier of the /Encrypt dict.
  • Signature — orthogonal to the encryption handlers.