Merge remote-tracking branch 'origin/main' into claude/encryption-ui-p3a

This commit is contained in:
Connor Yoh
2026-09-02 13:40:05 +01:00
855 changed files with 86791 additions and 13280 deletions
+19
View File
@@ -0,0 +1,19 @@
{
"$schema": "https://json.schemastore.org/claude-code-settings.json",
"hooks": {
"Stop": [
{
"hooks": [
{
"type": "command",
"command": "node",
"args": [
"${CLAUDE_PROJECT_DIR}/scripts/lint/comment-lint-hook.mjs"
],
"timeout": 60
}
]
}
]
}
}
-5
View File
@@ -8,11 +8,6 @@ updates:
- package-ecosystem: "gradle" # See documentation for possible values
directories:
- "/" # Location of package manifests
- "/app/common"
- "/app/core"
- "/app/proprietary"
- "/app/saas"
- "/buildSrc"
schedule:
interval: "weekly"
cooldown:
+1
View File
@@ -67,6 +67,7 @@ labels:
- 'frontend/**'
- 'frontend/.*'
- 'frontend/**/.*'
- '.taskfiles/frontend.yml'
- label: 'Tauri'
files:
+1
View File
@@ -20,6 +20,7 @@ Closes #(issue_number)
- [ ] I have read the [Stirling-PDF Developer Guide](https://github.com/Stirling-Tools/Stirling-PDF/blob/main/DeveloperGuide.md) (if applicable)
- [ ] I have read the [How to add new languages to Stirling-PDF](https://github.com/Stirling-Tools/Stirling-PDF/blob/main/devGuide/HowToAddNewLanguage.md) (if applicable)
- [ ] I have performed a self-review of my own code
- [ ] Every comment I added says something the code does not ([guide](https://github.com/Stirling-Tools/Stirling-PDF/blob/main/devGuide/CODE_COMMENTS.md))
- [ ] My changes generate no new warnings
### Documentation
+48 -2
View File
@@ -182,7 +182,7 @@ jobs:
fetch-depth: 0 # Fetch full history for commit hash detection
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
- name: Get version number
id: versionNumber
@@ -220,6 +220,42 @@ jobs:
echo "app_short=${APP_HASH:0:8}" >> $GITHUB_OUTPUT
fi
# The Stirling account previews connect to. Derived from the ref rather than stored as a URL
# so it cannot drift from the key: a mismatched pair is accepted by the browser and rejected
# by Supabase, surfacing much later as "session expired" on Usage rather than at sign-in.
# Secret only to match Saas-Dev-Deploy.yml, which owns the same value; a project ref is not
# itself sensitive, which is why SAAS_API_BASE_URL next to it is a plain variable.
- name: Resolve Stirling account config
id: saas
env:
PROJECT_REF: ${{ secrets.SAAS_DB_PROJECT_REF }}
API_BASE_OVERRIDE: ${{ vars.SAAS_API_BASE_URL }}
run: |
# Set, this is the one value both halves use: the browser's portal reads and the backend's
# register/entitlement calls have to land on the same SaaS, and nothing checks that they
# do. Unset, only the backend gets a base, from its own compiled-in default.
API_BASE="${API_BASE_OVERRIDE:-https://stirling.com/app}"
echo "backend_base=${API_BASE}" >> "$GITHUB_OUTPUT"
if [ -z "${PROJECT_REF}" ]; then
echo "Not configured for this environment: the preview will build without a Stirling"
echo "account, and the connect dialog will say so. To wire one up, set on the"
echo "pr-preview environment the secrets SAAS_DB_PROJECT_REF and"
echo "SAAS_SUPABASE_PUBLISHABLE_KEY, both from the same Supabase project."
echo "supabase_url=" >> "$GITHUB_OUTPUT"
echo "frontend_base=" >> "$GITHUB_OUTPUT"
else
# Only whether, not which: the ref is a secret here, so Actions masks it out of any
# line it appears in, derived URL included.
echo "Stirling account configured, at ${API_BASE}."
echo "supabase_url=https://${PROJECT_REF}.supabase.co" >> "$GITHUB_OUTPUT"
# Deliberately the override and not API_BASE: the backend's default is a subpath URL
# nobody has confirmed answers /api/v1, and prod CORS does not list preview hostnames,
# so portal reads stay off until someone sets a base they have checked. Empty leaves the
# committed .env default alone, which is the clean "not configured" state.
echo "frontend_base=${API_BASE_OVERRIDE}" >> "$GITHUB_OUTPUT"
fi
- name: Check if image exists
id: check-image
run: |
@@ -246,6 +282,9 @@ jobs:
build-args: |
VERSION_TAG=v2-alpha
BUILD_PORTAL=${{ env.BUILD_PORTAL }}
VITE_SUPABASE_URL=${{ steps.saas.outputs.supabase_url }}
VITE_SUPABASE_PUBLISHABLE_DEFAULT_KEY=${{ secrets.SAAS_SUPABASE_PUBLISHABLE_KEY }}
VITE_SAAS_API_URL=${{ steps.saas.outputs.frontend_base }}
platforms: linux/amd64
- name: Set up SSH
@@ -279,6 +318,13 @@ jobs:
environment:
DISABLE_ADDITIONAL_FEATURES: "false"
STIRLING_BILLING_ACCOUNT_LINK_ENABLED: "true"
STIRLING_BILLING_ACCOUNT_LINK_SAAS_BASE_URL: "${{ steps.saas.outputs.backend_base }}"
# Off so preview traffic never accrues against a real wallet or trips its cap. The
# 402 gate is separate and stays on, so gating is still testable here.
STIRLING_BILLING_ACCOUNT_LINK_METERING_ENABLED: "false"
# Stated rather than inferred from the request: the callback has to come back to the
# preview hostname, not to the container's own :8080 behind this proxy.
SYSTEM_FRONTENDURL: "https://${V2_PORT}.ssl.stirlingpdf.cloud"
SECURITY_ENABLELOGIN: "true"
SECURITY_INITIALLOGIN_USERNAME: "${TEST_LOGIN_USERNAME}"
SECURITY_INITIALLOGIN_PASSWORD: "${TEST_LOGIN_PASSWORD}"
@@ -353,7 +399,7 @@ jobs:
- name: Install Task for Storybook
if: steps.sb-changes.outputs.storybook == 'true'
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Build and deploy Storybook
id: storybook
@@ -206,7 +206,7 @@ jobs:
distribution: "temurin"
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Run Gradle Command
run: |
if [ "${{ needs.check-comment.outputs.disable_security }}" == "true" ]; then
@@ -222,7 +222,7 @@ jobs:
STIRLING_PDF_DESKTOP_UI: false
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
- name: Login to GitHub Container Registry
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
+246
View File
@@ -0,0 +1,246 @@
name: Auto SaaS Dev Deployment
on:
push:
branches:
- saas-prod
workflow_dispatch:
permissions:
contents: read
env:
FRONTEND_PORT: "901"
BACKEND_PORT: "902"
DEPLOY_DIR: /stirling/SAAS-DEV
jobs:
deploy-saas-dev:
runs-on: ubuntu-latest
environment: saas-dev
concurrency:
group: saas-dev-deploy
cancel-in-progress: true
permissions:
contents: read
packages: write
steps:
- name: Harden Runner
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
with:
egress-policy: audit
- name: Check SaaS configuration
id: config
env:
PROJECT_REF: ${{ secrets.SAAS_DB_PROJECT_REF }}
run: |
echo "supabase_url=https://${PROJECT_REF}.supabase.co" >> "$GITHUB_OUTPUT"
echo "meter_endpoint=https://${PROJECT_REF}.supabase.co/functions/v1/meter-payg-units" >> "$GITHUB_OUTPUT"
- name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
- name: Login to GitHub Container Registry
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ github.token }}
- name: Convert repository owner to lowercase
id: repoowner
run: echo "lowercase=$(echo ${{ github.repository_owner }} | awk '{print tolower($0)}')" >> $GITHUB_OUTPUT
- name: Get commit hash
id: commit-hash
run: echo "app_short=$(git rev-parse --short=8 HEAD)" >> $GITHUB_OUTPUT
- name: Build and push backend image
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with:
context: .
file: ./docker/backend/Dockerfile
push: true
cache-from: type=gha,scope=stirling-saas-backend
cache-to: type=gha,mode=max,scope=stirling-saas-backend
tags: |
ghcr.io/${{ steps.repoowner.outputs.lowercase }}/stirling-pdf-test:saas-backend-${{ steps.commit-hash.outputs.app_short }}
ghcr.io/${{ steps.repoowner.outputs.lowercase }}/stirling-pdf-test:saas-backend-latest
build-args: |
VERSION_TAG=v2-alpha
STIRLING_FLAVOR=saas
platforms: linux/amd64
- name: Build and push frontend image
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with:
context: .
file: ./docker/frontend/Dockerfile
push: true
cache-from: type=gha,scope=stirling-saas-frontend
cache-to: type=gha,mode=max,scope=stirling-saas-frontend
tags: |
ghcr.io/${{ steps.repoowner.outputs.lowercase }}/stirling-pdf-test:saas-frontend-${{ steps.commit-hash.outputs.app_short }}
ghcr.io/${{ steps.repoowner.outputs.lowercase }}/stirling-pdf-test:saas-frontend-latest
build-args: |
VERSION_TAG=v2-alpha
STIRLING_FLAVOR=saas
VITE_BUILD_MODE=development
VITE_SUPABASE_URL=${{ steps.config.outputs.supabase_url }}
VITE_SUPABASE_PUBLISHABLE_DEFAULT_KEY=${{ secrets.SAAS_SUPABASE_PUBLISHABLE_KEY }}
platforms: linux/amd64
- name: Build and push AI engine image
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with:
context: .
file: ./engine/Dockerfile
push: true
cache-from: type=gha,scope=stirling-saas-engine
cache-to: type=gha,mode=max,scope=stirling-saas-engine
tags: |
ghcr.io/${{ steps.repoowner.outputs.lowercase }}/stirling-pdf-test:saas-engine-${{ steps.commit-hash.outputs.app_short }}
ghcr.io/${{ steps.repoowner.outputs.lowercase }}/stirling-pdf-test:saas-engine-latest
platforms: linux/amd64
- name: Set up SSH
env:
SSH_KEY: ${{ secrets.NEW_VPS_SSH_KEY }}
run: |
mkdir -p ~/.ssh/
echo "$SSH_KEY" > ../private.key
sudo chmod 600 ../private.key
- name: Deploy to VPS
env:
IMAGE_BASE: ghcr.io/${{ steps.repoowner.outputs.lowercase }}/stirling-pdf-test
IMAGE_TAG: ${{ steps.commit-hash.outputs.app_short }}
GHCR_USER: ${{ github.actor }}
GHCR_TOKEN: ${{ github.token }}
VPS_USERNAME: ${{ secrets.NEW_VPS_USERNAME }}
VPS_HOST: ${{ secrets.NEW_VPS_HOST }}
SAAS_DB_URL: ${{ secrets.SAAS_DB_URL }}
SAAS_DB_USERNAME: ${{ secrets.SAAS_DB_USERNAME || 'postgres' }}
SAAS_DB_PASSWORD: ${{ secrets.SAAS_DB_PASSWORD }}
SAAS_DB_PROJECT_REF: ${{ secrets.SAAS_DB_PROJECT_REF }}
SUPABASE_EDGE_FUNCTION_SECRET: ${{ secrets.SUPABASE_EDGE_FUNCTION_SECRET }}
PAYG_METER_ENDPOINT: ${{ steps.config.outputs.meter_endpoint }}
STIRLING_KEYGEN_ENABLED: ${{ secrets.KEYGEN_ACCOUNT_ID != '' && secrets.KEYGEN_API_TOKEN != '' && secrets.KEYGEN_POLICY_ID != '' }}
KEYGEN_ACCOUNT_ID: ${{ secrets.KEYGEN_ACCOUNT_ID }}
KEYGEN_API_TOKEN: ${{ secrets.KEYGEN_API_TOKEN }}
KEYGEN_POLICY_ID: ${{ secrets.KEYGEN_POLICY_ID }}
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
VOYAGE_API_KEY: ${{ secrets.VOYAGE_API_KEY }}
run: |
set -euo pipefail
BASE_URL="http://${VPS_HOST}:${FRONTEND_PORT}"
yaml() {
printf "'%s'" "$(printf '%s' "$1" | sed -e "s/'/''/g" -e 's/\$/$$/g')"
}
ENGINE_SECRET="$(openssl rand -hex 32)"
AI_BACKEND_VARS="
SYSTEM_AIENGINE_ENABLED: \"true\"
SYSTEM_AIENGINE_URL: \"http://saas-engine:5001\"
APP_AI_SERVICEBASEURL: \"http://saas-engine:5001\"
STIRLING_ENGINE_SHARED_SECRET: $(yaml "$ENGINE_SECRET")"
AI_SERVICE="
saas-engine:
container_name: stirling-saas-dev-engine
image: ${IMAGE_BASE}:saas-engine-${IMAGE_TAG}
environment:
ANTHROPIC_API_KEY: $(yaml "$ANTHROPIC_API_KEY")
VOYAGE_API_KEY: $(yaml "$VOYAGE_API_KEY")
STIRLING_ENGINE_SHARED_SECRET: $(yaml "$ENGINE_SECRET")
restart: on-failure:5"
cat > docker-compose.yml << EOF
version: '3.3'
services:
saas-backend:
container_name: stirling-saas-dev-backend
image: ${IMAGE_BASE}:saas-backend-${IMAGE_TAG}
ports:
- "${BACKEND_PORT}:8080"
volumes:
- ${DEPLOY_DIR}/config:/configs:rw
- ${DEPLOY_DIR}/logs:/logs:rw
- ${DEPLOY_DIR}/storage:/storage:rw
environment:
SPRING_PROFILES_ACTIVE: "saas"
DISABLE_ADDITIONAL_FEATURES: "false"
SAAS_DB_URL: $(yaml "$SAAS_DB_URL")
SAAS_DB_USERNAME: $(yaml "$SAAS_DB_USERNAME")
SAAS_DB_PASSWORD: $(yaml "$SAAS_DB_PASSWORD")
SAAS_DB_PROJECT_REF: $(yaml "$SAAS_DB_PROJECT_REF")
SUPABASE_EDGE_FUNCTION_SECRET: $(yaml "$SUPABASE_EDGE_FUNCTION_SECRET")
PAYG_METER_ENDPOINT: $(yaml "$PAYG_METER_ENDPOINT")
STIRLING_KEYGEN_ENABLED: $(yaml "$STIRLING_KEYGEN_ENABLED")
KEYGEN_ACCOUNT_ID: $(yaml "$KEYGEN_ACCOUNT_ID")
KEYGEN_API_TOKEN: $(yaml "$KEYGEN_API_TOKEN")
KEYGEN_POLICY_ID: $(yaml "$KEYGEN_POLICY_ID")
SYSTEM_DEFAULTLOCALE: en-US
SYSTEM_MAXFILESIZE: "100"
METRICS_ENABLED: "true"
SYSTEM_GOOGLEVISIBILITY: "false"
SWAGGER_SERVER_URL: "${BASE_URL}"
baseUrl: "${BASE_URL}"${AI_BACKEND_VARS}
restart: on-failure:5
saas-frontend:
container_name: stirling-saas-dev-frontend
image: ${IMAGE_BASE}:saas-frontend-${IMAGE_TAG}
ports:
- "${FRONTEND_PORT}:80"
environment:
VITE_API_BASE_URL: "http://saas-backend:8080"
depends_on:
- saas-backend
restart: on-failure:5${AI_SERVICE}
EOF
SSH_OPTS=(-i ../private.key -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null)
scp "${SSH_OPTS[@]}" docker-compose.yml "${VPS_USERNAME}@${VPS_HOST}:/tmp/saas-dev-docker-compose.yml"
ssh "${SSH_OPTS[@]}" -T "${VPS_USERNAME}@${VPS_HOST}" << ENDSSH
set -e
mkdir -p ${DEPLOY_DIR}/{config,logs,storage}
mv /tmp/saas-dev-docker-compose.yml ${DEPLOY_DIR}/docker-compose.yml
chmod 600 ${DEPLOY_DIR}/docker-compose.yml
cd ${DEPLOY_DIR}
printf '%s' "${GHCR_TOKEN}" | docker login ghcr.io -u "${GHCR_USER}" --password-stdin
docker-compose down --remove-orphans 2>/dev/null || true
docker-compose pull
docker-compose up -d
docker logout ghcr.io >/dev/null 2>&1 || true
docker image prune -af --filter "until=336h" --filter "label!=keep=true" || true
ENDSSH
- name: Wait for the backend to answer
env:
VPS_HOST: ${{ secrets.NEW_VPS_HOST }}
run: |
URL="http://${VPS_HOST}:${BACKEND_PORT}/api/v1/info/status"
for i in $(seq 1 60); do
code=$(curl -s -o /dev/null -w '%{http_code}' --max-time 5 "$URL" || true)
if [ "$code" = "200" ]; then echo "Healthy after $((i * 10))s"; exit 0; fi
sleep 10
done
echo "::error::SaaS dev backend did not become healthy within 10 minutes"
exit 1
- name: Cleanup temporary files
if: always()
run: rm -f ../private.key docker-compose.yml
continue-on-error: true
+1 -2
View File
@@ -34,10 +34,9 @@ jobs:
cache-dependency-glob: |
engine/pyproject.toml
engine/uv.lock
cache-suffix: ai-engine
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Quality-check engine
id: engine-check
+1 -1
View File
@@ -52,7 +52,7 @@ jobs:
distribution: "temurin"
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Check Java formatting (Spotless)
# Runs once per matrix combination - pick the cheapest leg
# (core - no proprietary, no saas) so we don't wait for the
+1 -1
View File
@@ -95,7 +95,7 @@ jobs:
cache: "npm"
cache-dependency-path: frontend/package-lock.json
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Install Playwright (chromium only)
run: task e2e:install -- chromium
- name: Build frontend (needed for playwright's vite preview webServer)
+1 -2
View File
@@ -42,7 +42,6 @@ jobs:
cache-dependency-glob: |
engine/pyproject.toml
engine/uv.lock
cache-suffix: generated-models
- name: Restore cache Gradle User Home
if: inputs.use_shared_cache
@@ -76,7 +75,7 @@ jobs:
cache-dependency-path: frontend/package-lock.json
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Verify generated models are up to date
id: models-check
+1 -1
View File
@@ -38,7 +38,7 @@ jobs:
distribution: "temurin"
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Check licenses for compatibility
run: task backend:licenses:check
env:
+1 -1
View File
@@ -39,7 +39,7 @@ jobs:
distribution: "temurin"
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Generate OpenAPI documentation
run: task backend:swagger
env:
+1 -1
View File
@@ -57,7 +57,7 @@ jobs:
# runtime token isn't exposed) since the docker driver can't use it.
- name: Set up Docker Buildx
if: inputs.docker-base-changed != 'true'
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
# Expose ACTIONS_RUNTIME_TOKEN / ACTIONS_RESULTS_URL for docker buildx type=gha cache backend.
- name: Expose GitHub runtime for Buildx cache
+1 -1
View File
@@ -45,7 +45,7 @@ jobs:
cache: "npm"
cache-dependency-path: frontend/package-lock.json
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Install Playwright (chromium only)
run: task e2e:install -- chromium
- name: Build frontend (production bundle for vite preview)
+1 -1
View File
@@ -44,7 +44,7 @@ jobs:
cache: "npm"
cache-dependency-path: frontend/package-lock.json
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Build frontend (production bundle for vite preview)
env:
VITE_BUILD_FOR_PREVIEW: "1"
+1 -1
View File
@@ -36,7 +36,7 @@ jobs:
cache: "npm"
cache-dependency-path: frontend/package-lock.json
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: a11y gate (changed stories)
run: task frontend:storybook:a11y:changed -- origin/${{ github.base_ref || 'main' }}
- name: Upload scan reports
@@ -97,7 +97,7 @@ jobs:
run: npm ci --ignore-scripts --audit=false --fund=false
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Generate frontend license report (Push only)
if: github.event_name == 'push'
@@ -367,7 +367,7 @@ jobs:
distribution: "temurin"
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Check licenses and generate report
id: license-check
+1 -1
View File
@@ -27,7 +27,7 @@ jobs:
cache: "npm"
cache-dependency-path: frontend/package-lock.json
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Quality-check frontend
id: frontend-check
run: task frontend:check:all
+3 -3
View File
@@ -69,7 +69,7 @@ jobs:
distribution: "temurin"
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Get version number
id: versionNumber
run: |
@@ -169,7 +169,7 @@ jobs:
cache-dependency-path: frontend/package-lock.json
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Build JAR
run: ./gradlew build ${{ matrix.variant.build_frontend && '-PbuildWithFrontend=true' || '' }} -x spotlessApply -x spotlessCheck -x test -x sonarqube
@@ -268,7 +268,7 @@ jobs:
distribution: ${{ matrix.platform == 'windows-11-arm' && 'microsoft' || 'temurin' }}
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
# Build the universal JRE before desktop:prepare so the jlink:runtime
# task short-circuits on its `test -d runtime/jre` status check.
+3 -3
View File
@@ -38,7 +38,7 @@ jobs:
cache-dependency-path: frontend/package-lock.json
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Install all Playwright browsers
run: task e2e:install
@@ -89,7 +89,7 @@ jobs:
cache-dependency-path: frontend/package-lock.json
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: a11y gate (every story, ${{ matrix.theme }})
run: task frontend:storybook:a11y:${{ matrix.theme }}
@@ -162,7 +162,7 @@ jobs:
engine/uv.lock
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Start the fat image with login and storage enabled
run: docker compose -f docker/embedded/compose/test_cicd.yml up -d --build
+6 -2
View File
@@ -31,10 +31,14 @@ jobs:
cache-dependency-glob: |
engine/pyproject.toml
engine/uv.lock
cache-suffix: pre-commit
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Run pre-commit checks
run: task pre-commit
# The fixture corpus checks the comment rules themselves, so it runs here
# rather than on every local commit.
- name: Check the comment-lint fixture corpus
run: task pre-commit:comment-lint:selftest
+1 -1
View File
@@ -69,7 +69,7 @@ jobs:
- name: Set up Docker Buildx
id: buildx
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
- name: Set up QEMU
uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4.2.0
+2 -2
View File
@@ -85,10 +85,10 @@ jobs:
- name: Set up Docker Buildx
id: buildx
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Get version number
id: versionNumber
run: echo "versionNumber=$(./gradlew printVersion --quiet | tail -1)" >> $GITHUB_OUTPUT
+1 -1
View File
@@ -75,6 +75,6 @@ jobs:
# Upload the results to GitHub's code scanning dashboard.
- name: "Upload to code-scanning"
uses: github/codeql-action/upload-sarif@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7
uses: github/codeql-action/upload-sarif@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4.37.8
with:
sarif_file: results.sarif
+1 -1
View File
@@ -63,7 +63,7 @@ jobs:
SWAGGERHUB_USER: "Frooodle"
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Get version number
id: versionNumber
run: echo "versionNumber=$(./gradlew printVersion --quiet | tail -1)" >> $GITHUB_OUTPUT
+1 -2
View File
@@ -59,14 +59,13 @@ jobs:
cache-dependency-glob: |
engine/pyproject.toml
engine/uv.lock
cache-suffix: sync-files
- name: Install Python dependencies
run: |
uv sync --project engine --locked --group tools
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Sync translation TOML files
run: |
+1 -1
View File
@@ -212,7 +212,7 @@ jobs:
distribution: ${{ matrix.platform == 'windows-11-arm' && 'microsoft' || 'temurin' }}
- name: Setup Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Build universal macOS JRE
if: matrix.platform == 'macos-15'
+3 -3
View File
@@ -127,7 +127,7 @@ jobs:
distribution: "temurin"
- name: Install Task
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
- name: Build application
run: task backend:build
env:
@@ -142,7 +142,7 @@ jobs:
- name: Set up Docker Buildx
id: buildx
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
- name: Set base image and platform for this build
id: build-params
@@ -229,7 +229,7 @@ jobs:
- name: Set up Docker Buildx
id: buildx
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
- name: Build docker/unoserver/Dockerfile
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
+7 -2
View File
@@ -298,8 +298,13 @@ docs/type3/signatures/
**/application-dev-local.properties
# Claude
.claude/
# Claude. Contents are ignored so personal config stays local, with the two
# shared pieces re-included: settings.json (the comment-lint hook) and skills/.
# The directory itself cannot be ignored or git will not look inside it.
.claude/*
!.claude/settings.json
!.claude/skills/
.claude/settings.local.json
# Playwright MCP screenshots / traces
.playwright-mcp/
+62 -3
View File
@@ -40,12 +40,15 @@ tasks:
AIENGINE_ENABLED: '{{.AIENGINE_ENABLED | default "false"}}'
AIENGINE_TIMEOUTSECONDS: '{{.AIENGINE_TIMEOUTSECONDS | default "120"}}'
SECURITY_ENABLELOGIN: '{{.SECURITY_ENABLELOGIN | default ""}}'
# Set by dev:linked. Inline rather than in `env:` so an empty value emits nothing
# and cannot blank the committed default.
ACCOUNT_LINK_SAAS_BASE_URL: '{{.ACCOUNT_LINK_SAAS_BASE_URL | default ""}}'
env:
SERVER_PORT: '{{.PORT}}'
cmds:
- cmd: '{{if .AIENGINE_URL}}AIENGINE_URL={{.AIENGINE_URL}} AIENGINE_ENABLED={{.AIENGINE_ENABLED}} AIENGINE_TIMEOUTSECONDS={{.AIENGINE_TIMEOUTSECONDS}} {{end}}{{if .SECURITY_ENABLELOGIN}}SECURITY_ENABLELOGIN={{.SECURITY_ENABLELOGIN}} {{end}}cmd /c ".\gradlew.bat :stirling-pdf:bootRun"'
- cmd: '{{if .AIENGINE_URL}}AIENGINE_URL={{.AIENGINE_URL}} AIENGINE_ENABLED={{.AIENGINE_ENABLED}} AIENGINE_TIMEOUTSECONDS={{.AIENGINE_TIMEOUTSECONDS}} {{end}}{{if .SECURITY_ENABLELOGIN}}SECURITY_ENABLELOGIN={{.SECURITY_ENABLELOGIN}} {{end}}{{if .ACCOUNT_LINK_SAAS_BASE_URL}}STIRLING_BILLING_ACCOUNT_LINK_ENABLED=true STIRLING_BILLING_ACCOUNT_LINK_SAAS_BASE_URL={{.ACCOUNT_LINK_SAAS_BASE_URL}} {{end}}cmd /c ".\gradlew.bat :stirling-pdf:bootRun"'
platforms: [windows]
- cmd: '{{if .AIENGINE_URL}}AIENGINE_URL={{.AIENGINE_URL}} AIENGINE_ENABLED={{.AIENGINE_ENABLED}} AIENGINE_TIMEOUTSECONDS={{.AIENGINE_TIMEOUTSECONDS}} {{end}}{{if .SECURITY_ENABLELOGIN}}SECURITY_ENABLELOGIN={{.SECURITY_ENABLELOGIN}} {{end}}./gradlew :stirling-pdf:bootRun'
- cmd: '{{if .AIENGINE_URL}}AIENGINE_URL={{.AIENGINE_URL}} AIENGINE_ENABLED={{.AIENGINE_ENABLED}} AIENGINE_TIMEOUTSECONDS={{.AIENGINE_TIMEOUTSECONDS}} {{end}}{{if .SECURITY_ENABLELOGIN}}SECURITY_ENABLELOGIN={{.SECURITY_ENABLELOGIN}} {{end}}{{if .ACCOUNT_LINK_SAAS_BASE_URL}}STIRLING_BILLING_ACCOUNT_LINK_ENABLED=true STIRLING_BILLING_ACCOUNT_LINK_SAAS_BASE_URL={{.ACCOUNT_LINK_SAAS_BASE_URL}} {{end}}./gradlew :stirling-pdf:bootRun'
platforms: [linux, darwin]
dev:bundled:
@@ -84,6 +87,8 @@ tasks:
AIENGINE_URL: '{{.AIENGINE_URL}}'
AIENGINE_ENABLED: '{{.AIENGINE_ENABLED}}'
AIENGINE_TIMEOUTSECONDS: '{{.AIENGINE_TIMEOUTSECONDS}}'
APP_BASE_URL: '{{.APP_BASE_URL}}'
BASE_PATH: '{{.BASE_PATH}}'
staging:saas:
desc: "Start SaaS backend against the shared v3 staging project"
@@ -95,10 +100,47 @@ tasks:
AIENGINE_URL: '{{.AIENGINE_URL}}'
AIENGINE_ENABLED: '{{.AIENGINE_ENABLED}}'
AIENGINE_TIMEOUTSECONDS: '{{.AIENGINE_TIMEOUTSECONDS}}'
APP_BASE_URL: '{{.APP_BASE_URL}}'
BASE_PATH: '{{.BASE_PATH}}'
dev:linked:
desc: "Self-hosted backend linked to a locally running SaaS backend (see task linked:*)"
ignore_error: true
vars:
PORT: '{{.PORT | default "8080"}}'
SAAS_BASE_URL: '{{.SAAS_BASE_URL | default "http://localhost:8081"}}'
cmds:
- 'echo ">> self-hosted :{{.PORT}} linking to SaaS at {{.SAAS_BASE_URL}}"'
# The two backends run different STIRLING_FLAVOURs, which are different Gradle
# project graphs sharing one build/ tree. Waiting avoids overlapping builds; it
# does not make the sharing safe, so avoid rebuilding one while the other runs.
- cmd: |
n=0
while [ "$n" -lt 150 ]; do
if curl -s -m 2 "{{.SAAS_BASE_URL}}" >/dev/null 2>&1; then
echo ">> SaaS backend is up, starting self-hosted"
break
fi
n=$((n + 1))
{{if eq OS "windows"}}powershell -NoProfile -Command "Start-Sleep -Seconds 2"{{else}}sleep 2{{end}}
done
if [ "$n" -ge 150 ]; then
echo ">> SaaS backend never answered; starting anyway"
fi
- task: dev:proprietary
vars:
PORT: '{{.PORT}}'
ACCOUNT_LINK_SAAS_BASE_URL: '{{.SAAS_BASE_URL}}'
_run:saas:
internal: true
dotenv: ['app/.env.saas.local', 'app/.env.saas']
# The frontend files are here only for RUN_SUBPATH, which the authorize URL needs.
# Last, because dotenv is set-if-absent: app/* still decides everything else.
dotenv:
- 'app/.env.saas.local'
- 'app/.env.saas'
- 'frontend/editor/.env.saas.local'
- 'frontend/editor/.env.saas'
ignore_error: true
vars:
PORT: '{{.PORT | default "8080"}}'
@@ -111,12 +153,29 @@ tasks:
AIENGINE_URL: '{{.AIENGINE_URL | default ""}}'
AIENGINE_ENABLED: '{{.AIENGINE_ENABLED | default "false"}}'
AIENGINE_TIMEOUTSECONDS: '{{.AIENGINE_TIMEOUTSECONDS | default "120"}}'
# Empty is the same as unset: the property defaults to empty and is blank-checked.
APP_BASE_URL: '{{.APP_BASE_URL | default ""}}'
# Relocates configs/pipeline/logs, for a second backend in the same directory.
# Empty is the same as unset: the reader blank-checks it.
BASE_PATH: '{{.BASE_PATH | default ""}}'
env:
SERVER_PORT: '{{.PORT}}'
STIRLING_FLAVOR: saas
STIRLING_BASE_PATH: '{{.BASE_PATH}}'
AIENGINE_URL: '{{.AIENGINE_URL}}'
AIENGINE_ENABLED: '{{.AIENGINE_ENABLED}}'
AIENGINE_TIMEOUTSECONDS: '{{.AIENGINE_TIMEOUTSECONDS}}'
# Appends RUN_SUBPATH: the approval page is at <base>/link, so a subpath build
# serves it at <base>/app/link. An explicit value still wins.
SYSTEM_FRONTENDURL:
sh: |
if [ -n "${SYSTEM_FRONTENDURL:-}" ]; then
echo "${SYSTEM_FRONTENDURL}"
elif [ -n "{{.APP_BASE_URL}}" ] && [ -n "${RUN_SUBPATH:-}" ]; then
echo "{{.APP_BASE_URL}}/${RUN_SUBPATH}"
else
echo "{{.APP_BASE_URL}}"
fi
cmds:
# PROFILE_ARGS is empty when PROFILES=none, i.e. the bare `saas` profile
# against SAAS_DB_* (production).
+14 -4
View File
@@ -23,7 +23,7 @@ tasks:
- package-lock.json
- package.json
status:
- test -d node_modules
- npm ls --depth=0
env:
CI: '{{ .CI | default "false" }}'
@@ -121,17 +121,17 @@ tasks:
sh: |
case "${SAAS_ENV:-dev}" in
staging) ref="${SAAS_STAGING_PROJECT_REF:?set it in app/.env.saas.local}" ;;
*) ref="${SAAS_DEV_PROJECT_REF:?set it in app/.env.saas.local, or run task staging:saas}" ;;
*) ref="${SAAS_DEV_PROJECT_REF:?set it in app/.env.saas.local, or pass SAAS_ENV=staging}" ;;
esac
echo "https://${ref}.supabase.co"
VITE_SUPABASE_PUBLISHABLE_DEFAULT_KEY:
sh: |
case "${SAAS_ENV:-dev}" in
staging) echo "${SAAS_STAGING_PUBLISHABLE_KEY:?set it in app/.env.saas.local}" ;;
*) echo "${SAAS_DEV_PUBLISHABLE_KEY:?set it in app/.env.saas.local}" ;;
*) echo "${SAAS_DEV_PUBLISHABLE_KEY:?set it in app/.env.saas.local, or pass SAAS_ENV=staging}" ;;
esac
cmds:
- 'echo ">> frontend Supabase target: $VITE_SUPABASE_URL"'
- 'echo ">> frontend {{.SAAS_ENV}}: Supabase $VITE_SUPABASE_URL, backend $BACKEND_URL"'
- npx vite editor --mode saas --port {{.PORT}}{{if .OPEN}} --open{{end}}
dev:
@@ -173,6 +173,16 @@ tasks:
OPEN: '{{.OPEN}}'
SAAS_ENV: '{{.SAAS_ENV}}'
staging:saas:
desc: "Start frontend dev server against the shared v3 staging project"
cmds:
- task: dev:saas
vars:
SAAS_ENV: staging
PORT: '{{.PORT}}'
BACKEND_URL: '{{.BACKEND_URL}}'
OPEN: '{{.OPEN}}'
dev:desktop:
desc: "Start frontend dev server in desktop mode"
deps:
+82
View File
@@ -11,6 +11,7 @@ vars:
'.github/scripts/*.py'
'app/core/src/main/resources/static/python/*.py'
':(exclude)*split_photos.py'
':(exclude)scripts/lint/fixtures/*'
SPELL_FILES: >-
'*.html'
'*.css'
@@ -59,6 +60,7 @@ tasks:
- task: gitleaks
- task: whitespace
- task: toml-sort
- task: comment-lint
fix:
desc: "Auto-fix formatting, spelling, and secrets issues across the repo"
@@ -75,6 +77,7 @@ tasks:
vars: { FIX: '1' }
- task: codespell
- task: gitleaks
- task: comment-lint
install:
desc: "Install the pinned pre-commit Python tools"
@@ -130,6 +133,85 @@ tasks:
cmds:
- "{{.GITLEAKS_BIN}} git --pre-commit --redact --staged --verbose"
comment-lint:
desc: "Check comment quality on the lines this branch adds"
summary: |
Blocks a comment that restates the code below it, a section banner, or a
block of commented-out code. Everything else it reports is advisory.
Scoped to added lines, so touching an old file never surfaces the standing
backlog. The standard is devGuide/CODE_COMMENTS.md.
With no arguments it diffs the working tree against HEAD, which is what a
pre-commit run wants: the lines you are about to commit. On a CI pull request
it diffs against the target branch instead, via GITHUB_BASE_REF.
To ask what a whole branch adds instead, use the branch variant, which
needs no argument passing:
task comment-lint:branch
Full tree (report only): task pre-commit:comment-lint:all
Fixture corpus: task pre-commit:comment-lint:selftest
# Depends on the frontend install because the .ts/.tsx half of the rule set
# runs as an oxlint plugin. Without it the TS engine warns and skips, which
# would leave the frontend silently unchecked on CI.
deps: [":frontend:install"]
cmds:
- node scripts/lint/comment-lint.mjs {{.CLI_ARGS}}
comment-lint:branch:
desc: "Check comment quality on everything this branch adds over its base"
summary: |
Like `task comment-lint`, but scoped to the whole branch rather than to
uncommitted work, so it still reports after you commit.
Exists as its own task because passing `-- --since origin/main` through Task
is not portable: with the npm build of Task the launcher is a PowerShell
script, and PowerShell strips the `--` before Task sees it, leaving Task to
print its own usage.
Override the base with BASE=<ref>.
vars:
BASE: '{{.BASE | default "origin/main"}}'
deps: [":frontend:install"]
cmds:
- node scripts/lint/comment-lint.mjs --since {{.BASE}}
comment-lint:ci:
desc: "Comment gate as CI runs it: fixture corpus, then the diff"
summary: |
The corpus checks the rules themselves rather than the code under review, so
it belongs on CI and not on every local commit. Run this before changing a
rule, and let CI run it on every pull request.
deps: [":frontend:install"]
cmds:
- node scripts/lint/comment-lint.mjs --selftest
- node scripts/lint/comment-lint.mjs {{.CLI_ARGS}}
comment-lint:hook:
desc: "Comment gate for the editor hook: everything this turn changed"
summary: |
Same scope as `task comment-lint`, kept as its own name so the hook has a
stable entry point and the taskfile shows every way the linter is invoked.
Not in the frontend-install dependency chain on purpose: this runs at the end
of every turn, so it stays as short as it can be. If oxlint is missing the TS
half warns and skips.
cmds:
- node scripts/lint/comment-lint.mjs
comment-lint:all:
desc: "Report every comment finding in the tree (never fails)"
deps: [":frontend:install"]
cmds:
- node scripts/lint/comment-lint.mjs --all
comment-lint:selftest:
desc: "Check both comment-lint engines against the fixture corpus"
deps: [":frontend:install"]
cmds:
- node scripts/lint/comment-lint.mjs --selftest
gitleaks-bin:
internal: true
desc: "Ensure the pinned, checksum-verified gitleaks binary is cached in .task/bin"
+38 -1
View File
@@ -21,6 +21,43 @@ Task `desc:` fields should describe **what** the task does, not **how** it does
- `task docker:build` — build standard Docker image
- `task docker:up` — start Docker compose stack
## Comments
A comment must carry information the code cannot. If a reader could derive it from the code in front of them, delete it.
Comment the current state. Not what the code used to do, not what changed, not why it changed: git holds that. Where history explains the shape, state the reason instead, so "this used to reimplement the modal internals" becomes "thin wrapper over the shared Modal: duplicating its portal and focus trap is how dialogs drift apart". Future state goes in a TODO with an issue.
Write a comment when it does one of these four jobs:
- **Contract.** What a caller must know that the signature cannot say: preconditions, invariants, units, ownership and lifetime, thread-safety, error semantics, side effects. Document the contract of everything a caller outside the file can reach, and nothing else. Goes on the type/method/module as Javadoc, JSDoc, or a docstring.
- **Why.** The constraint the code satisfies, the bug it avoids, the alternative rejected and the reason.
- **Hazard.** "Must stay in sync with X", "order matters because Y", "do not remove, it prevents Z".
- **Map.** A short orientation at the top of a genuinely complex file: what it owns, and what it deliberately does not.
Never write:
- A comment that restates the next line. `// Handle drag start` above `handleDragStart` is noise.
- Section banners or position markers: `// --- Types ---`, `// Helpers`, `// =====`.
- Step narration in a function body (`// Step 1:`, `// Then we`). If the steps need labels they need names: extract functions. Numbering a genuinely numbered thing, like a wizard step, is fine.
- Commented-out code. Delete it.
- Doc tags that restate the signature. `@param blob - The blob` says nothing; omit the tag rather than pad it.
- Docs on self-explanatory members with no constraint to state.
Two tests before keeping a comment:
- **Delete it.** Is any information lost? If not, it stays deleted.
- **Could a name carry it instead?** A better identifier, an extracted function, or a named constant beats a comment. Prefer the code change.
A comment at the end of a line usually decodes that line, and that is worth keeping: `{0x25, 0x50} // "%PDF"`, `50L * 1024 * 1024 // 50 MB`. The rules that compare a comment against the code below it do not apply there, but a trailing TODO or a trailing bit of history is judged like any other.
A reference is supplementary, never load-bearing: the comment must survive deleting it. `// See #1234` is a dead end; `// saving first loses every annotation (#6865)` is not. Prefer a spec (`RFC 3161`) or CVE where one applies.
A TODO needs an issue, not an owner: `// TODO(#1234): re-enable the gate once account syncing lands`. If it is not worth an issue, it is not worth a TODO. A question is not a TODO.
A comment block over ~12 lines outside a file or type header usually means the code needs restructuring, or that the prose is product documentation and belongs in the docs repo.
`task comment-lint` checks the mechanical part of this on the lines you add, and runs inside `task pre-commit`. Reasoning, worked examples and the linter's own rules: @devGuide/CODE_COMMENTS.md
## Common Development Commands
### Build and Test
@@ -70,7 +107,7 @@ The project structure is defined in `engine/pyproject.toml`. Any new dependencie
- Avoid nested functions and nested classes unless the language construct requires them.
- Prefer composition to inheritance when combining concepts.
- Avoid speculative abstractions. Add a layer only when it removes real duplication or clarifies lifecycle.
- Add comments sparingly and only when they explain non-obvious intent.
- Comments follow the repo-wide rules in the "Comments" section above.
#### Python Typing and Models
- Deserialize into Pydantic models as early as possible.
+1
View File
@@ -42,6 +42,7 @@ Please make sure your Pull Request adheres to the following guidelines:
- Keep commits atomic. One commit should contain one change. If you want to make multiple changes, submit multiple Pull Requests.
- Commits should be clear, concise, and easy to understand.
- References to the Issue number in the Pull Request and/or Commit message.
- Every comment in the diff should say something the code does not. See [Code comments](devGuide/CODE_COMMENTS.md); `task comment-lint` checks the mechanical part.
## Translations
+100
View File
@@ -121,6 +121,92 @@ tasks:
cmds:
- task: dev:_all
# No engine: linking never calls it.
linked:staging:
desc: "SaaS on the shared v3 project + a self-hosted instance linked to it"
cmds:
- task: linked:_all
vars: { SAAS_ENV: staging }
linked:dev:
desc: "SaaS on the current PR's preview branch + a self-hosted instance linked to it"
cmds:
- task: linked:_all
vars: { SAAS_ENV: dev }
linked:_all:
internal: true
vars:
SAAS_ENV: '{{.SAAS_ENV | default "staging"}}'
PORTS:
sh: '{{if eq OS "windows"}}{{.FIND_FREE_PORT_PS}} 8081 5174 8080 5173{{else}}{{.FIND_FREE_PORT_SH}} 8081 5174 8080 5173{{end}}'
SAAS_BACKEND_PORT: '{{index (splitList "\n" .PORTS) 0}}'
SAAS_FRONTEND_PORT: '{{index (splitList "\n" .PORTS) 1}}'
APP_BACKEND_PORT: '{{index (splitList "\n" .PORTS) 2}}'
APP_FRONTEND_PORT: '{{index (splitList "\n" .PORTS) 3}}'
deps:
# APP_BASE_URL is the SaaS *frontend*: the approval page is served by vite, not
# by the API. BASE_PATH moves this backend's configs/pipeline aside so it does not
# race the self-hosted one, which keeps ./configs and its existing database.
- task: 'backend:{{.SAAS_ENV}}:saas'
vars:
PORT: '{{.SAAS_BACKEND_PORT}}'
APP_BASE_URL: 'http://localhost:{{.SAAS_FRONTEND_PORT}}'
BASE_PATH: 'tmp/linked-saas'
- task: frontend:dev:saas
vars:
PORT: '{{.SAAS_FRONTEND_PORT}}'
BACKEND_URL: 'http://localhost:{{.SAAS_BACKEND_PORT}}'
SAAS_ENV: '{{.SAAS_ENV}}'
- task: backend:dev:linked
vars:
PORT: '{{.APP_BACKEND_PORT}}'
SAAS_BASE_URL: 'http://localhost:{{.SAAS_BACKEND_PORT}}'
- task: frontend:dev:proprietary
vars:
PORT: '{{.APP_FRONTEND_PORT}}'
BACKEND_URL: 'http://localhost:{{.APP_BACKEND_PORT}}'
OPEN: "true"
- task: linked:_ready
vars:
SAAS_BACKEND_PORT: '{{.SAAS_BACKEND_PORT}}'
SAAS_FRONTEND_PORT: '{{.SAAS_FRONTEND_PORT}}'
APP_BACKEND_PORT: '{{.APP_BACKEND_PORT}}'
APP_FRONTEND_PORT: '{{.APP_FRONTEND_PORT}}'
# Waits for all four to answer, then prints where they landed.
linked:_ready:
internal: true
cmds:
- cmd: |
n=0
ok=0
while [ "$n" -lt 150 ]; do
ok=1
for u in "http://localhost:{{.SAAS_BACKEND_PORT}}" \
"http://localhost:{{.SAAS_FRONTEND_PORT}}" \
"http://localhost:{{.APP_BACKEND_PORT}}" \
"http://localhost:{{.APP_FRONTEND_PORT}}"; do
# Not -o /dev/null: Windows curl.exe treats it as a real path and exits 23.
curl -s -m 2 "$u" >/dev/null 2>&1 || ok=0
done
if [ "$ok" = 1 ]; then break; fi
n=$((n + 1))
# `sleep` is a binary, not a builtin, and Windows has none.
{{if eq OS "windows"}}powershell -NoProfile -Command "Start-Sleep -Seconds 2"{{else}}sleep 2{{end}}
done
echo ""
if [ "$ok" = 1 ]; then
echo ">> all four answering"
else
echo ">> still waiting on one or more after 5 minutes; addresses below anyway"
fi
echo ">> self-hosted UI http://localhost:{{.APP_FRONTEND_PORT}}/processor"
echo ">> self-hosted api http://localhost:{{.APP_BACKEND_PORT}}"
echo ">> saas UI http://localhost:{{.SAAS_FRONTEND_PORT}}"
echo ">> saas api http://localhost:{{.SAAS_BACKEND_PORT}}"
echo ""
dev:_all:
internal: true
vars:
@@ -180,6 +266,20 @@ tasks:
cmds:
- task: frontend:lint
- task: engine:lint
- task: comment-lint
comment-lint:
desc: "Check comment quality on the lines this branch adds"
aliases: [comments]
cmds:
- task: pre-commit:comment-lint
vars: { CLI_ARGS: '{{.CLI_ARGS}}' }
comment-lint:branch:
desc: "Check comment quality on everything this branch adds over its base"
cmds:
- task: pre-commit:comment-lint:branch
vars: { BASE: '{{.BASE}}' }
fix:
desc: "Auto-fix all components"
+32 -7
View File
@@ -3,6 +3,10 @@ bootRun {
enabled = false
}
dependencies {
// Security-hardening utilities (zip-slip, SSRF, filename sanitization, command injection).
// Declared as api here so core + proprietary (which depend on common) get it transitively,
// keeping it off modules that don't need it (e.g. saas).
api 'io.github.pixee:java-security-toolkit:1.2.3'
api "com.google.guava:guava:${guavaVersion}"
api 'org.springframework.boot:spring-boot-starter-webmvc'
api 'org.springframework.boot:spring-boot-starter-aspectj'
@@ -22,7 +26,10 @@ dependencies {
api "org.springdoc:springdoc-openapi-starter-webmvc-ui:3.0.3"
// Simple Java Mail for EML/MSG parsing (replaces direct Angus Mail usage)
api 'org.simplejavamail:simple-java-mail:9.3.2'
api 'org.simplejavamail:outlook-module:9.3.2' // MSG file support
// MSG file support; exclude commons-math3 (only HSSF/formula needs it, MSG parsing doesn't)
api('org.simplejavamail:outlook-module:9.3.2') {
exclude group: 'org.apache.commons', module: 'commons-math3'
}
api 'jakarta.mail:jakarta.mail-api:2.1.5'
runtimeOnly 'org.eclipse.angus:angus-mail:2.0.5'
@@ -36,12 +43,30 @@ dependencies {
api "com.stirling:jpdfium:${jpdfiumVersion}"
// -PjpdfiumPlatforms=all|none|<csv of linux-x64,linux-arm64,darwin-x64,darwin-arm64,windows-x64>
// 'none' skips natives entirely (windows-arm64 builds, until JPDFium ships that platform).
def jpdfiumPlatformsProp = (project.findProperty('jpdfiumPlatforms') ?: 'all').toString().trim()
def jpdfiumAllPlatforms = ['linux-x64', 'linux-arm64', 'darwin-x64', 'darwin-arm64', 'windows-x64']
// -PjpdfiumPlatforms=auto|all|none|<csv of linux-x64,linux-arm64,linux-musl-x64,linux-musl-arm64,darwin-x64,darwin-arm64,windows-x64> (windows-arm64 natives not published yet)
def jpdfiumPlatformsProp = (project.findProperty('jpdfiumPlatforms') ?: 'auto').toString().trim()
def jpdfiumAllPlatforms = ['linux-x64', 'linux-arm64', 'linux-musl-x64', 'linux-musl-arm64', 'darwin-x64', 'darwin-arm64', 'windows-x64']
def jpdfiumPlatforms
if (jpdfiumPlatformsProp == 'all') {
if (jpdfiumPlatformsProp == 'auto') {
def osName = System.getProperty('os.name').toLowerCase()
def osArch = System.getProperty('os.arch').toLowerCase()
def isArm64 = osArch.contains('aarch64') || osArch.contains('arm64')
if (osName.contains('linux')) {
jpdfiumPlatforms = isArm64 ? ['linux-arm64'] : ['linux-x64']
} else if (osName.contains('mac')) {
jpdfiumPlatforms = isArm64 ? ['darwin-arm64'] : ['darwin-x64']
} else if (osName.contains('win')) {
if (isArm64) {
logger.lifecycle("JPDFium natives are not available for windows-arm64; set -PjpdfiumPlatforms=none to skip bundling natives.")
jpdfiumPlatforms = []
} else {
jpdfiumPlatforms = ['windows-x64']
}
} else {
// Fallback: bundle all platforms when host can't be determined
jpdfiumPlatforms = jpdfiumAllPlatforms
}
} else if (jpdfiumPlatformsProp == 'all') {
jpdfiumPlatforms = jpdfiumAllPlatforms
} else if (jpdfiumPlatformsProp == 'none') {
jpdfiumPlatforms = []
@@ -51,7 +76,7 @@ dependencies {
def jpdfiumInvalid = jpdfiumPlatforms.findAll { !jpdfiumAllPlatforms.contains(it) }
if (jpdfiumInvalid) {
throw new GradleException("Unknown jpdfiumPlatforms value(s): ${jpdfiumInvalid.join(', ')}. " +
"Valid: ${jpdfiumAllPlatforms.join(', ')}, 'all' or 'none'.")
"Valid: ${jpdfiumAllPlatforms.join(', ')}, 'auto', 'all' or 'none'.")
}
logger.lifecycle("JPDFium native platforms: ${jpdfiumPlatforms ? jpdfiumPlatforms.join(', ') : 'none'}")
jpdfiumPlatforms.each { platform ->
@@ -48,7 +48,7 @@ public class EndpointConfiguration {
private final ApplicationProperties applicationProperties;
@Getter private Map<String, Boolean> endpointStatuses = new ConcurrentHashMap<>();
private Map<String, Set<String>> endpointGroups = new ConcurrentHashMap<>();
private Set<String> disabledGroups = new HashSet<>();
private Set<String> disabledGroups = ConcurrentHashMap.newKeySet();
private Map<String, DisableReason> endpointDisableReasons = new ConcurrentHashMap<>();
private Map<String, DisableReason> groupDisableReasons = new ConcurrentHashMap<>();
private Map<String, Set<String>> endpointAlternatives = new ConcurrentHashMap<>();
@@ -237,7 +237,7 @@ public class TabulaTableParser implements TableParser {
score -= 0.3f;
}
return Math.max(0f, Math.min(1f, score));
return Math.clamp(score, 0f, 1f);
}
private Bounds tableBounds(Table table) {
@@ -15,7 +15,8 @@ public class StringToMapPropertyEditor extends PropertyEditorSupport {
@Override
public void setAsText(String text) throws IllegalArgumentException {
try {
TypeReference<HashMap<String, String>> typeRef = new TypeReference<>() {};
TypeReference<HashMap<String, String>> typeRef =
new TypeReference<HashMap<String, String>>() {};
Map<String, String> map = objectMapper.readValue(text, typeRef);
setValue(map);
} catch (Exception e) {
@@ -113,6 +113,16 @@ class RequestUriUtilsTest {
assertTrue(RequestUriUtils.isFrontendRoute("", "/split-pdf"));
}
@Test
void testIsFrontendRoute_editorRouteOwnedByFrontend() {
// /editor (and its tool routes) is an SPA route: a direct-nav/refresh must
// serve index.html, not the auth filter's 302-to-/login. Regression test for
// the editor moving from / to /editor, whose refresh bounced processor users
// to the processor because the redirect dropped the return path.
assertTrue(RequestUriUtils.isFrontendRoute("", "/editor"));
assertTrue(RequestUriUtils.isFrontendRoute("/app", "/app/editor"));
}
@Test
void testIsFrontendRoute_filesRouteOwnedByFrontend() {
// /files and /files/<folder-uuid> are FileManagerView routes - they
+1
View File
@@ -106,6 +106,7 @@ SwaggerDoc.json
# Log file
*.log
*.log.gz
# BlueJ files
*.ctxt
+17 -2
View File
@@ -62,8 +62,16 @@ dependencies {
// CVE-2022-25647: Explicit gson to prevent unsafe deserialization (tabula would pull 2.8.7)
implementation "com.google.code.gson:gson:${gsonVersion}"
implementation 'org.apache.pdfbox:jbig2-imageio:3.0.5'
implementation 'com.opencsv:opencsv:5.12.0' // https://mvnrepository.com/artifact/com.opencsv/opencsv
implementation 'org.apache.poi:poi-ooxml:5.5.1'
// OpenCSV: Stirling-PDF only uses CSVWriter, not the opencsv-bean module.
// Exclude commons-beanutils + commons-collections.
implementation('com.opencsv:opencsv:5.12.0') {
exclude group: 'commons-beanutils', module: 'commons-beanutils'
exclude group: 'commons-collections', module: 'commons-collections'
}
// POI: only XSSF (modern Excel) is used, not HSSF/FormulaEvaluator which need commons-math3.
implementation('org.apache.poi:poi-ooxml:5.5.1') {
exclude group: 'org.apache.commons', module: 'commons-math3'
}
// Batik only bridge module needed (transitively pulls anim, gvt, util, css, dom, svg-dom)
// Replaces batik-all which included unused codec, svggen, transcoder, script modules
@@ -129,6 +137,10 @@ bootJar {
exclude 'META-INF/*.RSA'
exclude 'META-INF/*.EC'
// Exclude source maps from production JAR, dev-only debugging artifacts, not needed at runtime
exclude 'static/pdfjs-legacy/**/*.map'
exclude 'static/**/*.map'
manifest {
attributes(
'Implementation-Title': 'Stirling-PDF',
@@ -294,6 +306,9 @@ tasks.register('copyFrontendAssets', Copy) {
// Exclude files that conflict with backend static resources
exclude 'robots.txt' // Backend already has this
exclude 'favicon.ico' // Backend already has this
// Backend ships its own NotoSans-Regular.ttf here and it is git-tracked;
// letting the editor's copy win would dirty the source tree on every build.
exclude 'fonts/NotoSans-Regular.ttf'
}
into resourcesStaticDir
duplicatesStrategy = DuplicatesStrategy.INCLUDE // Let frontend overwrite when needed
@@ -237,7 +237,7 @@ public class EditTextController {
Matcher matcher = edit.pattern().matcher(joined);
List<MatchSpan> spans = new ArrayList<>();
StringBuffer interpolation = new StringBuffer();
StringBuilder interpolation = new StringBuilder();
int previousAppendPosition = 0;
while (matcher.find()) {
if (matcher.start() == matcher.end()) {
@@ -0,0 +1,598 @@
package stirling.software.SPDF.controller.api;
import java.io.IOException;
import java.util.ArrayList;
import java.util.Base64;
import java.util.List;
import org.apache.pdfbox.pdmodel.PDDocument;
import org.apache.pdfbox.pdmodel.PDPage;
import org.apache.pdfbox.pdmodel.PDResources;
import org.apache.pdfbox.pdmodel.font.PDFont;
import org.springframework.http.ResponseEntity;
import org.springframework.web.bind.annotation.PostMapping;
import org.springframework.web.bind.annotation.RequestBody;
import com.fasterxml.jackson.annotation.JsonInclude;
import io.swagger.v3.oas.annotations.Operation;
import lombok.Data;
import lombok.RequiredArgsConstructor;
import lombok.extern.slf4j.Slf4j;
import stirling.software.common.annotations.api.GeneralApi;
import stirling.software.common.service.CustomPDFDocumentFactory;
/**
* Charcode-encode helper for the v2 PDF text editor.
*
* <p>The frontend editor uses PDFium-WASM, which exposes {@code FPDFText_SetCharcodes} for writing
* new text using raw font charcodes (skipping PDFium's broken reverse Unicode→CID lookup for
* embedded subset fonts). What PDFium does NOT expose is the byte-encoding side of an existing font
* - given a PDFont and a Unicode string, what are the bytes the font's encoding produces? PDFBox
* does have that ({@link PDFont#encode}).
*
* <p>This endpoint accepts the source PDF + a "locator" describing where to find the font in
* question (page index + a sample char known to render in the target font, optionally narrowed by
* the font's /BaseFont name) + the Unicode text the frontend wants to encode. It returns the
* charcode sequence the frontend can pass to {@code FPDFText_SetCharcodes}.
*
* <p>If the locator can't find a matching text fragment, or if the font can't encode some chars,
* the response reports which chars are missing so the frontend can fall back to Helvetica per char.
*/
@Slf4j
@GeneralApi
@RequiredArgsConstructor
public class PdfTextEditorCharcodeController {
/** Reject JSON bodies whose base64 implies a decoded PDF larger than this. */
private static final int MAX_PDF_BYTES = 100 * 1024 * 1024;
/**
* Upper bound on {@code request.text} code units. Editor requests are word-sized; an unbounded
* text drove a per-code-point encode/exception loop (CPU burn) on crafted requests.
*/
private static final int MAX_TEXT_CHARS = 4096;
/** Nested form-XObject resource dictionaries visited per lookup (cycle/DoS guard). */
private static final int MAX_RESOURCE_DICTS = 32;
/** Bound on the reverse-map cache so a busy multi-document server can't grow it forever. */
private static final int REVERSE_MAP_CACHE_MAX = 32;
/** Access-ordered LRU bounded at {@link #REVERSE_MAP_CACHE_MAX} entries. */
private static final class BoundedReverseMapCache
extends java.util.LinkedHashMap<String, java.util.Map<String, Long>> {
private static final long serialVersionUID = 1L;
BoundedReverseMapCache() {
super(16, 0.75f, true);
}
@Override
protected boolean removeEldestEntry(
java.util.Map.Entry<String, java.util.Map<String, Long>> eldest) {
return size() > REVERSE_MAP_CACHE_MAX;
}
}
private static final java.util.Map<String, java.util.Map<String, Long>> REVERSE_MAP_CACHE =
java.util.Collections.synchronizedMap(new BoundedReverseMapCache());
private final CustomPDFDocumentFactory pdfDocumentFactory;
// NOTE: PDFBox's PDSimpleFont emits one "No Unicode mapping for .notdef" WARN per probed
// charcode when buildReverseUnicodeMap iterates 0..0xFFFF, which once flooded info.log to
// ~1.4 GB overnight. That logger is silenced DECLARATIVELY in logback.xml (a config entry ops
// can see and revert) rather than by mutating the global logger from a static block here -
// mutating it at class-load time hid the same warnings from every other tool in the JVM with
// no trace in configuration.
@Data
public static class EncodeCharcodesRequest {
/** Base64-encoded original PDF. The frontend already has the bytes loaded. */
private String pdfBase64;
/** 0-based page index containing the font sample. */
private int pageIndex;
/**
* A char known to exist on the page in the target font. Combined with {@code fontName}
* (when supplied) it locates the source PDFont via its ToUnicode CMap.
*/
private String locatorChar;
/**
* Optional /BaseFont name of the target font (as PDFium's FPDFFont_GetBaseFontName reports
* it). When a page has TWO fonts that both render {@code locatorChar}, this disambiguates
* which one to encode against - otherwise the first font found wins and a cross-font edit
* gets the wrong font's charcode. Null = keep the legacy first-match behaviour.
*/
private String fontName;
/**
* Optional SHA-256 (lowercase hex) of the target font's embedded program bytes (what
* PDFium's FPDFFont_GetFontData returns = the decoded FontFile/FontFile2/FontFile3 stream).
* This is the ONLY unambiguous font identity: PDFium strips the "ABCDEF+" subset tag from
* font names, so every subset of one family reports the same {@code fontName} and a
* name-based lookup can land on a SIBLING subset whose charcode space is different -
* returning valid-but-wrong charcodes that scramble the edited text. When present and a
* font on the page matches, it wins over name matching.
*/
private String fontSha256;
/** Unicode text the frontend wants to encode. */
private String text;
}
@Data
@JsonInclude(JsonInclude.Include.NON_NULL)
public static class EncodeCharcodesResponse {
/**
* Per-char charcode array (one entry per code point in {@code request.text}). When the
* font's encoding produces multi-byte sequences, each char gets the full unsigned int value
* of its bytes packed big-endian (so a 2-byte CID like 0x004D becomes 77).
*/
private List<Long> charcodes;
/** Chars from the request that the font couldn't encode. */
private List<String> missing;
/** Diagnostic note - included so the frontend HUD can show what happened. */
private String note;
/** Set when the request failed entirely (bad pdf bytes, no matching font, etc.). */
private String error;
}
@Operation(
summary = "Encode Unicode → font charcodes for the v2 PDF text editor",
description =
"""
Frontend-only helper: takes the source PDF, a locator pointing at an existing
char rendered in the target font, and a Unicode string. Returns the byte
sequence the target font produces for that Unicode, packed as one unsigned
int per char. The frontend then calls FPDFText_SetCharcodes with the
returned ints to inject new text that reuses the embedded font's actual
glyphs. Chars the font can't encode are listed in `missing` so the caller
can fall back per-char.
""")
@PostMapping(
value = "/pdf-text-editor/encode-charcodes",
consumes = "application/json",
produces = "application/json")
public ResponseEntity<EncodeCharcodesResponse> encodeCharcodes(
@RequestBody EncodeCharcodesRequest request) {
EncodeCharcodesResponse resp = new EncodeCharcodesResponse();
if (request == null
|| request.getPdfBase64() == null
|| request.getText() == null
|| request.getLocatorChar() == null) {
resp.setError("missing required fields");
return ResponseEntity.badRequest().body(resp);
}
// length/4*3 bounds the decoded size without decoding, so we reject early before
// allocating.
String b64 = request.getPdfBase64();
if ((long) b64.length() / 4 * 3 > MAX_PDF_BYTES) {
resp.setError("pdf too large");
return ResponseEntity.status(413).body(resp);
}
// Reported separately: a combined check names only one cause and misleads the caller.
if (request.getText().length() > MAX_TEXT_CHARS) {
resp.setError("text too long");
return ResponseEntity.badRequest().body(resp);
}
if (request.getLocatorChar().length() > 4) {
resp.setError("locatorChar too long");
return ResponseEntity.badRequest().body(resp);
}
byte[] pdfBytes;
try {
pdfBytes = Base64.getDecoder().decode(b64);
} catch (IllegalArgumentException e) {
resp.setError("pdfBase64 is not valid base64");
return ResponseEntity.badRequest().body(resp);
}
try (PDDocument doc = pdfDocumentFactory.load(pdfBytes, true)) {
if (request.getPageIndex() < 0 || request.getPageIndex() >= doc.getNumberOfPages()) {
resp.setError("pageIndex out of range");
return ResponseEntity.badRequest().body(resp);
}
PDPage page = doc.getPage(request.getPageIndex());
// Skip walking the page's content stream (it crashes on Type3 fonts with
// UnsupportedOperationException("Not implemented: Type3") before we can do anything
// useful). Instead enumerate the page's font resources and pick the one identified by
// the request's font-program hash (definitive), falling back to name matching.
// For Chrome/Skia-printed PDFs that emit one Type3 font per glyph, this lands on
// the exact font that renders the locator char.
ResourceFont located =
findFontByToUnicode(
page,
request.getLocatorChar(),
request.getFontName(),
request.getFontSha256(),
doc);
if (located == null) {
resp.setError(
"no font on page "
+ request.getPageIndex()
+ " renders locatorChar="
+ request.getLocatorChar()
+ (request.getFontName() != null
? " (fontName=" + request.getFontName() + ")"
: ""));
return ResponseEntity.ok(resp);
}
// Build a reverse Unicode→charcode map by walking the font's ToUnicode CMap.
// This is the ONLY path that works for Type3 fonts (PDFBox's font.encode() throws
// "Not implemented: Type3" on them), and it also acts as a more reliable fallback
// for subset fonts whose encode() rejects chars not in the original document.
//
// For Sample.pdf specifically, every embedded font is Type3 (Chrome/Skia output),
// but they all carry a ToUnicode CMap mapping CIDs back to Unicode. We iterate
// charcodes 0..0xFFFF, call font.toUnicode(cc) for each, and record the inverse
// mapping for the chars the user wants to write.
PDFont font = located.font();
java.util.Map<String, Long> reverseMap =
buildReverseUnicodeMap(pdfBytes, located, request.getPageIndex());
List<Long> charcodes = new ArrayList<>();
List<String> missing = new ArrayList<>();
String text = request.getText();
int i = 0;
while (i < text.length()) {
int cp = text.codePointAt(i);
String oneChar = new String(Character.toChars(cp));
i += Character.charCount(cp);
// Whitespace is NEVER charcode-reused. Subset Type1/LaTeX fonts
// usually have no real space glyph, yet font.encode(0x20) still
// returns code 0x20 without throwing - and SetCharcodes(0x20)
// then paints whatever glyph sits at that subset code (e.g. „
// quotedblbase in LMRoman). Report whitespace as missing so the
// frontend emits it as a positional gap instead.
if (Character.isWhitespace(cp)) {
missing.add(oneChar);
continue;
}
// 1st try: font.encode() - works for Type0/TrueType/Type1
Long packed = null;
try {
byte[] encoded = font.encode(oneChar);
long p = 0L;
for (byte b : encoded) p = (p << 8) | (b & 0xff);
packed = p;
} catch (IOException
| IllegalArgumentException
| UnsupportedOperationException encodeEx) {
// 2nd try: ToUnicode reverse lookup - works for Type3 + anything with a CMap
packed = reverseMap.get(oneChar);
}
if (packed != null) charcodes.add(packed);
else missing.add(oneChar);
}
resp.setCharcodes(charcodes);
if (!missing.isEmpty()) resp.setMissing(missing);
resp.setNote(
"font="
+ font.getName()
+ " encoded "
+ charcodes.size()
+ " of "
+ (charcodes.size() + missing.size())
+ " chars");
return ResponseEntity.ok(resp);
} catch (IOException e) {
log.warn("encodeCharcodes: failed to load PDF", e);
resp.setError("failed to load PDF");
return ResponseEntity.badRequest().body(resp);
} catch (RuntimeException e) {
log.warn("encodeCharcodes: unexpected error", e);
resp.setError("unexpected error");
return ResponseEntity.status(500).body(resp);
}
}
/**
* Locate the font the request targets. Identity sources, strongest first:
*
* <ol>
* <li><b>Program hash</b>: SHA-256 of the embedded font program bytes. Definitive - two
* different subsets NEVER share program bytes, and PDFium's FPDFFont_GetFontData returns
* exactly the decoded FontFile stream, so frontend and backend hash the same bytes.
* <li><b>Exact /BaseFont name</b> (subset tag included), then <b>tag-stripped name</b>. Name
* matches are only accepted when UNAMBIGUOUS: PDFium reports subset fonts WITHOUT their
* "ABCDEF+" tag, so a page with several subsets of one family ("AAAAAC+Garamond",
* "AAAAAG+Garamond", ...) has them ALL match the stripped name - and encoding against the
* wrong sibling returns valid-but-wrong charcodes that scramble the edited text ("RUSSELL
* W. MANGUM" rendered "US EEL W. MANGS M"). With 2+ candidates we return null so the
* frontend takes its safe fallback instead of a coin flip.
* </ol>
*
* <p>This avoids running PDFStreamEngine.processPage, which throws
* UnsupportedOperationException on Type3 font glyph rendering. The PDFont lookup itself is
* purely metadata-driven and works on all subtypes.
*/
private static ResourceFont findFontByToUnicode(
PDPage page, String wantChar, String fontName, String fontSha256, PDDocument doc) {
try {
List<ResourceFont> fonts = collectResourceTreeFonts(page.getResources());
// 1) Program-hash identity. When several dicts share one program (identical bytes
// re-embedded), any of them renders the same glyphs for the same codes; prefer the
// one whose ToUnicode covers the locator char so the reverse map is usable.
if (fontSha256 != null && !fontSha256.isEmpty()) {
List<ResourceFont> hashMatches = new ArrayList<>();
for (ResourceFont rf : fonts) {
String sha = fontProgramSha256(rf.font());
if (fontSha256.equalsIgnoreCase(sha)) hashMatches.add(rf);
}
for (ResourceFont rf : hashMatches) {
if (probesToUnicode(rf.font(), wantChar)) return rf;
}
if (!hashMatches.isEmpty()) return hashMatches.get(0);
// No program on this page hashes to what the frontend is editing (e.g. PDFium
// returned a substitute font's bytes for a non-embedded font). Fall through to
// name matching rather than failing outright.
}
// 2) Name identity - exact tag-included first, then tag-stripped - each accepted
// only when it selects a single font.
if (fontName != null && !fontName.isEmpty()) {
ResourceFont exact =
selectUnambiguous(
fonts, wantChar, f -> fontName.equals(f.getName()), "exact");
if (exact != null) return exact;
String wantStripped = stripSubsetTag(fontName);
ResourceFont stripped =
selectUnambiguous(
fonts,
wantChar,
f -> wantStripped.equals(stripSubsetTag(f.getName())),
"stripped");
if (stripped != null) return stripped;
// The frontend NAMED the font it is editing. Falling back to "any font that
// renders the char" would hand back a DIFFERENT font's charcodes, which the
// frontend then writes into the named font's text object - wrong glyph, and the
// backend strategy skips all frontend validation. Report the char missing
// instead so the caller takes its own fallback path.
return null;
}
// 3) Legacy locator-only behaviour: first font whose ToUnicode renders the char.
for (ResourceFont rf : fonts) {
if (probesToUnicode(rf.font(), wantChar)) return rf;
}
} catch (RuntimeException ignore) {
// Be defensive: any single bad font shouldn't sink the whole request.
}
return null;
}
/**
* Apply {@code nameFilter}, then decide: exactly one candidate whose ToUnicode covers {@code
* wantChar} wins; two+ probe-hits are AMBIGUOUS (null). With zero probe-hits, a single
* name-matching font is still returned (font.encode() may handle chars without a ToUnicode -
* common for Type0/Identity-H), but two+ name matches are again ambiguous.
*/
private static ResourceFont selectUnambiguous(
List<ResourceFont> fonts,
String wantChar,
java.util.function.Predicate<PDFont> nameFilter,
String modeLabel) {
List<ResourceFont> named = new ArrayList<>();
for (ResourceFont rf : fonts) {
try {
if (rf.font().getName() != null && nameFilter.test(rf.font())) named.add(rf);
} catch (RuntimeException ignore) {
}
}
if (named.isEmpty()) return null;
List<ResourceFont> probed = new ArrayList<>();
for (ResourceFont rf : named) {
if (probesToUnicode(rf.font(), wantChar)) probed.add(rf);
}
if (probed.size() == 1) return probed.get(0);
if (probed.size() > 1) {
log.debug(
"encodeCharcodes: {} name match ambiguous ({} fonts render locator '{}') -"
+ " refusing cross-subset guess",
modeLabel,
probed.size(),
wantChar);
return null;
}
return named.size() == 1 ? named.get(0) : null;
}
/** True when some charcode in the font's ToUnicode CMap maps to {@code wantChar}. */
private static boolean probesToUnicode(PDFont font, String wantChar) {
// Cheap inverse-CMap probe: iterate codes until we hit one whose toUnicode is wantChar.
// For Type3 with at most ~16 glyphs, this is microseconds. For full Type0 subsets
// it's a few-thousand-iteration scan.
int upper = font.isStandard14() ? 256 : 0x10000;
for (int cc = 0; cc < upper; cc++) {
String u;
try {
u = font.toUnicode(cc);
} catch (Exception ignore) {
continue;
}
if (u != null && u.equals(wantChar)) return true;
}
return false;
}
private record ResourceFont(PDFont font, String path) {}
private record PendingResources(PDResources resources, String path) {}
/**
* Breadth-first collection of every distinct font reachable from the page's resources AND every
* nested form XObject's resources (bounded by {@link #MAX_RESOURCE_DICTS}, cycle-safe, deduped
* by COS dictionary identity). The v2 reader surfaces form-XObject text as editable, so its
* fonts must be findable too.
*/
private static List<ResourceFont> collectResourceTreeFonts(PDResources resources) {
List<ResourceFont> out = new ArrayList<>();
java.util.ArrayDeque<PendingResources> queue = new java.util.ArrayDeque<>();
java.util.Set<org.apache.pdfbox.cos.COSDictionary> seenDicts =
java.util.Collections.newSetFromMap(new java.util.IdentityHashMap<>());
java.util.Set<org.apache.pdfbox.cos.COSDictionary> seenFonts =
java.util.Collections.newSetFromMap(new java.util.IdentityHashMap<>());
if (resources != null) queue.add(new PendingResources(resources, ""));
int visited = 0;
// Bound a crafted page declaring many fonts none of which match (CPU-DoS guard).
final int MAX_FONTS = 64;
while (!queue.isEmpty() && visited < MAX_RESOURCE_DICTS) {
PendingResources pending = queue.poll();
PDResources res = pending.resources();
if (!seenDicts.add(res.getCOSObject())) continue;
visited++;
for (org.apache.pdfbox.cos.COSName name : res.getFontNames()) {
if (out.size() >= MAX_FONTS) break;
PDFont font;
try {
font = res.getFont(name);
} catch (IOException | RuntimeException e) {
continue;
}
if (font == null || !seenFonts.add(font.getCOSObject())) continue;
out.add(new ResourceFont(font, pending.path() + "/" + name.getName()));
}
try {
for (org.apache.pdfbox.cos.COSName xn : res.getXObjectNames()) {
try {
org.apache.pdfbox.pdmodel.graphics.PDXObject xo = res.getXObject(xn);
if (xo
instanceof
org.apache.pdfbox.pdmodel.graphics.form.PDFormXObject form) {
PDResources fr = form.getResources();
if (fr != null) {
queue.add(
new PendingResources(
fr, pending.path() + "/" + xn.getName()));
}
}
} catch (IOException | RuntimeException ignore) {
}
}
} catch (RuntimeException ignore) {
}
}
return out;
}
/**
* SHA-256 (lowercase hex) of a font's embedded program bytes - the decoded
* FontFile/FontFile2/FontFile3 stream, which is byte-identical to what PDFium's
* FPDFFont_GetFontData hands the frontend. Null when the font embeds no program.
*/
private static String fontProgramSha256(PDFont font) {
try {
org.apache.pdfbox.pdmodel.font.PDFontDescriptor fd = font.getFontDescriptor();
if (fd == null && font instanceof org.apache.pdfbox.pdmodel.font.PDType0Font type0) {
fd = type0.getDescendantFont().getFontDescriptor();
}
if (fd == null) return null;
org.apache.pdfbox.pdmodel.common.PDStream stream = fd.getFontFile2();
if (stream == null) stream = fd.getFontFile3();
if (stream == null) stream = fd.getFontFile();
if (stream == null) return null;
return sha256Hex(stream.toByteArray());
} catch (IOException | RuntimeException e) {
return null;
}
}
/** Drop the 6-letter "ABCDEF+" subset prefix PDF puts on subset /BaseFont names. */
private static String stripSubsetTag(String fontName) {
if (fontName == null) return null;
if (fontName.length() > 7
&& fontName.charAt(6) == '+'
&& fontName.chars().limit(6).allMatch(c -> c >= 'A' && c <= 'Z')) {
return fontName.substring(7);
}
return fontName;
}
/**
* Build a Unicode→charcode map for a font by iterating every charcode in 0..0xFFFF and asking
* the font's ToUnicode CMap what Unicode it maps to. Charcodes that aren't in the CMap throw
* inside toUnicode (PDFBox returns null or throws depending on font subtype), and those are
* skipped silently.
*
* <p>This is the encoding inverse PDFBox doesn't expose directly. For Type3 fonts (where
* font.encode() throws "Not implemented"), this is the ONLY way to write text in the same font
* - we look up the user's char in the reverse map and pass that charcode to
* FPDFText_SetCharcodes on the frontend.
*
* <p>The 0..0xFFFF range is sufficient for Type0/CIDFontType2 fonts (CIDs are 16-bit). For
* single-byte fonts the loop short-circuits after 256. We don't go higher because no PDF font
* has a CID outside that range in practice; the per-font result is memoised in {@link
* #REVERSE_MAP_CACHE} so the 65 536-entry probe runs once per document+font, not per request.
*/
private static java.util.Map<String, Long> buildReverseUnicodeMap(
byte[] pdfBytes, ResourceFont located, int pageIndex) {
String key = sha256Hex(pdfBytes) + "|" + fontCacheIdentity(located, pageIndex);
// Compound get/put under the map's own monitor. The 0..0xFFFF probe runs OUTSIDE the
// lock so one slow build can't block every other request on the shared cache.
java.util.Map<String, Long> cached;
synchronized (REVERSE_MAP_CACHE) {
cached = REVERSE_MAP_CACHE.get(key);
}
if (cached != null) return cached;
java.util.Map<String, Long> built = computeReverseUnicodeMap(located.font());
synchronized (REVERSE_MAP_CACHE) {
java.util.Map<String, Long> raced = REVERSE_MAP_CACHE.putIfAbsent(key, built);
return raced != null ? raced : built;
}
}
private static String fontCacheIdentity(ResourceFont located, int pageIndex) {
org.apache.pdfbox.cos.COSObjectKey objectKey = null;
try {
objectKey = located.font().getCOSObject().getKey();
} catch (RuntimeException ignore) {
}
if (objectKey != null) {
return "obj|" + objectKey.getNumber() + "." + objectKey.getGeneration();
}
return "res|p" + pageIndex + located.path();
}
/** Lowercase hex SHA-256 of the PDF bytes; used as the reverse-map cache key. */
private static String sha256Hex(byte[] bytes) {
try {
byte[] digest = java.security.MessageDigest.getInstance("SHA-256").digest(bytes);
StringBuilder sb = new StringBuilder(digest.length * 2);
for (byte b : digest) {
sb.append(Character.forDigit((b >> 4) & 0xf, 16));
sb.append(Character.forDigit(b & 0xf, 16));
}
return sb.toString();
} catch (java.security.NoSuchAlgorithmException e) {
// SHA-256 is always present in a JRE; fall back to a length+hash key just in case so
// the cache still functions (correctness holds - collisions only cost a rebuild).
return bytes.length + ":" + java.util.Arrays.hashCode(bytes);
}
}
private static java.util.Map<String, Long> computeReverseUnicodeMap(PDFont font) {
java.util.Map<String, Long> out = new java.util.HashMap<>();
int upper = font.isStandard14() ? 256 : 0x10000;
for (int cc = 0; cc < upper; cc++) {
String u;
try {
u = font.toUnicode(cc);
} catch (Exception ignore) {
continue;
}
if (u == null || u.isEmpty()) continue;
// First charcode wins for a given Unicode (the canonical mapping).
out.putIfAbsent(u, (long) cc);
}
return out;
}
}
@@ -95,7 +95,8 @@ public class UIDataController {
try (InputStream is = resource.getInputStream()) {
Map<String, List<Dependency>> licenseData =
objectMapper.readValue(is, new TypeReference<>() {});
objectMapper.readValue(
is, new TypeReference<Map<String, List<Dependency>>>() {});
data.setDependencies(licenseData.get("dependencies"));
} catch (IOException e) {
log.error("Failed to load licenses data", e);
@@ -25,12 +25,15 @@ final class FormPayloadParser {
private static final String KEY_VALUE = "value";
private static final String KEY_DEFAULT_VALUE = "defaultValue";
private static final TypeReference<Map<String, Object>> MAP_TYPE = new TypeReference<>() {};
private static final TypeReference<Map<String, Object>> MAP_TYPE =
new TypeReference<Map<String, Object>>() {};
private static final TypeReference<List<FormUtils.ModifyFormFieldDefinition>>
MODIFY_FIELD_LIST_TYPE = new TypeReference<>() {};
MODIFY_FIELD_LIST_TYPE =
new TypeReference<List<FormUtils.ModifyFormFieldDefinition>>() {};
private static final TypeReference<List<FormUtils.NewFormFieldDefinition>> NEW_FIELD_LIST_TYPE =
new TypeReference<>() {};
private static final TypeReference<List<String>> STRING_LIST_TYPE = new TypeReference<>() {};
private static final TypeReference<List<String>> STRING_LIST_TYPE =
new TypeReference<List<String>>() {};
private FormPayloadParser() {}
@@ -96,7 +96,9 @@ public class AddCommentsController {
List<CommentSpecDto> dtos;
try {
dtos = objectMapper.readValue(commentsJson, new TypeReference<>() {});
dtos =
objectMapper.readValue(
commentsJson, new TypeReference<List<CommentSpecDto>>() {});
} catch (JacksonException e) {
throw new ResponseStatusException(
HttpStatus.BAD_REQUEST, "comments must be a JSON array of CommentSpec objects");
@@ -338,6 +338,19 @@ public class ConfigController {
// Premium/Enterprise settings
configData.put("premiumEnabled", applicationProperties.getPremium().isEnabled());
// Whether this instance can link a Stirling (SaaS) account at all. The account-link
// beans live in :proprietary and are @ConditionalOnProperty on this same key, so when
// it is off they are absent and /api/v1/account-link/* returns 404. The frontend cannot
// tell that 404 apart from "not linked yet", so it needs this told to it explicitly
// before it can prompt anyone to link. Read from the environment rather than
// AccountLinkProperties because :core must not depend on :proprietary.
configData.put(
"accountLinkAvailable",
applicationContext
.getEnvironment()
.getProperty(
"stirling.billing.account-link.enabled", Boolean.class, false));
// AI Engine settings
ApplicationProperties.AiEngine aiEngineConfig = applicationProperties.getAiEngine();
configData.put("aiEngineEnabled", aiEngineConfig.isEnabled());
@@ -114,6 +114,7 @@ public class OCRController {
List<String> selectedLanguages = request.getLanguages();
boolean sidecar = request.isSidecar();
Boolean deskew = request.isDeskew();
Boolean rotatePages = request.isRotatePages();
Boolean clean = request.isClean();
Boolean cleanFinal = request.isCleanFinal();
String ocrType = request.getOcrType();
@@ -154,6 +155,7 @@ public class OCRController {
selectedLanguages,
sidecar,
deskew,
rotatePages,
clean,
cleanFinal,
ocrType,
@@ -236,6 +238,7 @@ public class OCRController {
List<String> selectedLanguages,
Boolean sidecar,
Boolean deskew,
Boolean rotatePages,
Boolean clean,
Boolean cleanFinal,
String ocrType,
@@ -268,6 +271,10 @@ public class OCRController {
if (deskew != null && deskew) {
command.add("--deskew");
}
if (rotatePages != null && rotatePages) {
// Tesseract OSD-based automatic page orientation correction (90/180/270)
command.add("--rotate-pages");
}
if (clean != null && clean) {
command.add("--clean");
}
@@ -221,6 +221,10 @@ public class RedactController {
.normalizeFonts(false)
.fixToUnicode(false)
.glyphAware(true)
.ligatureAware(true)
.bidiAware(true)
.graphemeSafe(true)
.sanitizeStructure(false) // WIP/Experimental API
.redactMetadata(true)
.build();
@@ -110,6 +110,10 @@ class TextRedactionService {
.fixToUnicode(false)
.repairWidths(false)
.glyphAware(true)
.ligatureAware(true)
.bidiAware(true)
.graphemeSafe(true)
.sanitizeStructure(false)
.build();
try (PdfDocument checkDoc = PdfDocument.open(tempIn.toPath())) {
@@ -25,6 +25,11 @@ public class ProcessPdfWithOcrRequest extends PDFFile {
@Schema(description = "Deskew the input file if set to true")
private boolean deskew;
@Schema(
description =
"Auto-correct page orientation (90/180/270) using Tesseract OSD if set to true")
private boolean rotatePages;
@Schema(description = "Clean the input file if set to true")
private boolean clean;
@@ -4,7 +4,9 @@ import java.time.Instant;
import java.time.temporal.ChronoUnit;
import java.util.Map;
import java.util.concurrent.ConcurrentHashMap;
import java.util.concurrent.atomic.AtomicLong;
import org.springframework.scheduling.annotation.Scheduled;
import org.springframework.stereotype.Service;
import lombok.extern.slf4j.Slf4j;
@@ -21,7 +23,7 @@ public class WeeklyActiveUsersService {
private final Map<String, Instant> activeBrowsers = new ConcurrentHashMap<>();
// Track total unique browsers seen (overall)
private long totalUniqueBrowsers = 0;
private final AtomicLong totalUniqueBrowsers = new AtomicLong(0);
// Application start time
private final Instant startTime = Instant.now();
@@ -36,12 +38,12 @@ public class WeeklyActiveUsersService {
return;
}
boolean isNewBrowser = !activeBrowsers.containsKey(browserId);
activeBrowsers.put(browserId, Instant.now());
Instant now = Instant.now();
Instant previous = activeBrowsers.put(browserId, now);
if (isNewBrowser) {
totalUniqueBrowsers++;
log.debug("New browser recorded: {} (Total: {})", browserId, totalUniqueBrowsers);
if (previous == null) {
long total = totalUniqueBrowsers.incrementAndGet();
log.debug("New browser recorded: {} (Total: {})", browserId, total);
}
}
@@ -61,7 +63,7 @@ public class WeeklyActiveUsersService {
* @return Total unique browsers count
*/
public long getTotalUniqueBrowsers() {
return totalUniqueBrowsers;
return totalUniqueBrowsers.get();
}
/**
@@ -88,7 +90,8 @@ public class WeeklyActiveUsersService {
activeBrowsers.entrySet().removeIf(entry -> entry.getValue().isBefore(sevenDaysAgo));
}
/** Manual cleanup trigger (can be called by scheduled task if needed) */
/** Scheduled cleanup trigger running every hour */
@Scheduled(fixedRate = 3600000)
public void performCleanup() {
int sizeBefore = activeBrowsers.size();
cleanupOldEntries();
@@ -154,7 +154,8 @@ public class PdfJsonFontService {
return "otf";
}
if (signature == 0x74746366) {
return "cff";
log.debug("[FONT-DEBUG] TrueType Collection ('ttcf') font program is unsupported");
return null;
}
return null;
}
@@ -175,7 +176,8 @@ public class PdfJsonFontService {
return "otf";
}
if (signature == 0x74746366) {
return "cff";
log.debug("[FONT-DEBUG] TrueType Collection ('ttcf') FontFile2 is unsupported");
return null;
}
return null;
}
+46 -7
View File
@@ -15,24 +15,63 @@
<encoder>
<pattern>%d %p %c{1} [%thread] %m%n</pattern>
</encoder>
<rollingPolicy class="ch.qos.logback.core.rolling.TimeBasedRollingPolicy">
<fileNamePattern>${LOG_PATH}/auth-%d{yyyy-MM-dd}.log</fileNamePattern>
<maxHistory>1</maxHistory>
<!-- SizeAndTime, not Time alone: the size trigger is what stops a
runaway logger filling the disk (see GENERAL appender note).
Archives are gzipped, so 64 MB of them holds far more than a
day. Worst case on disk is one 100 MB live file plus the cap. -->
<rollingPolicy class="ch.qos.logback.core.rolling.SizeAndTimeBasedRollingPolicy">
<fileNamePattern>${LOG_PATH}/auth-%d{yyyy-MM-dd}.%i.log.gz</fileNamePattern>
<maxFileSize>100MB</maxFileSize>
<maxHistory>7</maxHistory>
<totalSizeCap>64MB</totalSizeCap>
</rollingPolicy>
</appender>
<!-- Rolling File Appender for General Logs -->
<!-- Rolling File Appender for General Logs
Why SizeAndTimeBased + totalSizeCap: a previous build of the v2 PDF
text editor's reverse-CMap probe loop triggered PDSimpleFont to emit
one "No Unicode mapping for .notdef" WARN per probed charcode per
font per request. With TimeBasedRollingPolicy alone there was no
size ceiling; info.log grew to 1.4 GB in a single day before the JVM
choked. The class-level silencer fixes the specific offender, but
this size cap is the defence-in-depth: any future logger that
floods unexpectedly will roll + auto-delete instead of starving
disk + Jetty threads. -->
<appender name="GENERAL" class="ch.qos.logback.core.rolling.RollingFileAppender">
<file>${LOG_PATH}/info.log</file>
<encoder>
<pattern>%d %p %c{1} [%thread] %m%n</pattern>
</encoder>
<rollingPolicy class="ch.qos.logback.core.rolling.TimeBasedRollingPolicy">
<fileNamePattern>${LOG_PATH}/info-%d{yyyy-MM-dd}.log</fileNamePattern>
<maxHistory>1</maxHistory>
<rollingPolicy class="ch.qos.logback.core.rolling.SizeAndTimeBasedRollingPolicy">
<fileNamePattern>${LOG_PATH}/info-%d{yyyy-MM-dd}.%i.log.gz</fileNamePattern>
<maxFileSize>100MB</maxFileSize>
<maxHistory>7</maxHistory>
<totalSizeCap>256MB</totalSizeCap>
</rollingPolicy>
</appender>
<!-- Suppress PDFBox PDSimpleFont's per-charcode .notdef WARN.
Required by the v2 PDF text editor's `buildReverseUnicodeMap`
which DELIBERATELY iterates every charcode in 0..0xFFFF to
discover the encoding-to-Unicode map of an embedded subset
font. For any subset font ~99% of those probes hit .notdef,
and the default WARN level for those misses turned info.log
into a 1.4 GB monster overnight.
This declarative logback entry is the SOLE mechanism: it is
visible to ops and revertable via configuration. An earlier
build also mutated this logger's level from a static block in
PdfTextEditorCharcodeController, which silenced the same
warnings JVM-wide with no trace in any config file - that
static block has been removed in favour of this entry. -->
<logger name="org.apache.pdfbox.pdmodel.font.PDSimpleFont"
level="ERROR" additivity="false">
<appender-ref ref="CONSOLE"/>
<appender-ref ref="GENERAL"/>
</logger>
<!-- Root Logger -->
<root level="INFO">
<appender-ref ref="CONSOLE"/>
@@ -186,7 +186,7 @@ system:
maxDPI: 500 # Maximum allowed DPI for PDF to image conversion
corsAllowedOrigins: [] # List of allowed origins for CORS (e.g. ['http://localhost:5173', 'https://app.example.com']). WARNING: leaving this empty falls back to allowing ALL origins (with credentials), it does NOT disable CORS. Set explicit origins to lock it down.
backendUrl: "" # Backend base URL for SAML/OAuth/API callbacks (e.g. 'http://localhost:8080' for dev, 'https://api.example.com' for production). REQUIRED for SSO authentication to work correctly. This is where your IdP will send SAML responses and OAuth callbacks. Leave empty to default to 'http://localhost:8080' in development.
frontendUrl: "" # Frontend URL for invite email links (e.g. 'https://app.example.com'). Optional - if not set, will use backendUrl. This is the URL users click in invite emails.
frontendUrl: "" # Base URL of the web app, as a browser reaches it (e.g. 'https://app.example.com', or 'https://example.com/app' if served under a base path). Optional - if not set, will use backendUrl. Used for any link handed to a browser: invite emails, share links, mobile QR codes, and the account-link handshake.
enableMobileScanner: true # Enable mobile phone QR code upload feature. Requires frontendUrl to be configured.
enableMobileSignature: true # Enable drawing signatures on a phone via QR code from the Sign tool. Requires frontendUrl to be configured.
mobileScannerSettings:
@@ -94,7 +94,7 @@
{
"moduleName": "com.fasterxml.jackson.core:jackson-core",
"moduleUrl": "https://github.com/FasterXML/jackson-core",
"moduleVersion": "2.22.1",
"moduleVersion": "2.22.2",
"moduleLicense": "The Apache Software License, Version 2.0",
"moduleLicenseUrl": "https://www.apache.org/licenses/LICENSE-2.0.txt"
},
@@ -108,7 +108,7 @@
{
"moduleName": "com.fasterxml.jackson.core:jackson-databind",
"moduleUrl": "https://github.com/FasterXML/jackson",
"moduleVersion": "2.22.1",
"moduleVersion": "2.22.2",
"moduleLicense": "The Apache Software License, Version 2.0",
"moduleLicenseUrl": "https://www.apache.org/licenses/LICENSE-2.0.txt"
},
@@ -143,7 +143,7 @@
{
"moduleName": "com.fasterxml.jackson:jackson-bom",
"moduleUrl": "https://github.com/FasterXML/jackson-bom",
"moduleVersion": "2.22.1",
"moduleVersion": "2.22.2",
"moduleLicense": "The Apache Software License, Version 2.0",
"moduleLicenseUrl": "http://www.apache.org/licenses/LICENSE-2.0.txt"
},
@@ -440,42 +440,14 @@
{
"moduleName": "com.stirling:jpdfium",
"moduleUrl": "https://github.com/Stirling-Tools/JPDFium",
"moduleVersion": "1.0.4",
"moduleLicense": "MIT License",
"moduleLicenseUrl": "https://opensource.org/licenses/MIT"
},
{
"moduleName": "com.stirling:jpdfium-natives-darwin-arm64",
"moduleUrl": "https://github.com/Stirling-Tools/JPDFium",
"moduleVersion": "1.0.4",
"moduleLicense": "MIT License",
"moduleLicenseUrl": "https://opensource.org/licenses/MIT"
},
{
"moduleName": "com.stirling:jpdfium-natives-darwin-x64",
"moduleUrl": "https://github.com/Stirling-Tools/JPDFium",
"moduleVersion": "1.0.4",
"moduleLicense": "MIT License",
"moduleLicenseUrl": "https://opensource.org/licenses/MIT"
},
{
"moduleName": "com.stirling:jpdfium-natives-linux-arm64",
"moduleUrl": "https://github.com/Stirling-Tools/JPDFium",
"moduleVersion": "1.0.4",
"moduleVersion": "1.1.3",
"moduleLicense": "MIT License",
"moduleLicenseUrl": "https://opensource.org/licenses/MIT"
},
{
"moduleName": "com.stirling:jpdfium-natives-linux-x64",
"moduleUrl": "https://github.com/Stirling-Tools/JPDFium",
"moduleVersion": "1.0.4",
"moduleLicense": "MIT License",
"moduleLicenseUrl": "https://opensource.org/licenses/MIT"
},
{
"moduleName": "com.stirling:jpdfium-natives-windows-x64",
"moduleUrl": "https://github.com/Stirling-Tools/JPDFium",
"moduleVersion": "1.0.4",
"moduleVersion": "1.1.3",
"moduleLicense": "MIT License",
"moduleLicenseUrl": "https://opensource.org/licenses/MIT"
},
@@ -521,36 +493,18 @@
"moduleLicense": "GNU General Public License, version 2 with the GNU Classpath Exception",
"moduleLicenseUrl": "https://www.gnu.org/software/classpath/license.html"
},
{
"moduleName": "com.twelvemonkeys.common:common-image",
"moduleVersion": "3.13.1",
"moduleLicense": "The BSD License",
"moduleLicenseUrl": "https://github.com/haraldk/TwelveMonkeys#license"
},
{
"moduleName": "com.twelvemonkeys.common:common-image",
"moduleVersion": "3.14.0",
"moduleLicense": "The BSD License",
"moduleLicenseUrl": "https://github.com/haraldk/TwelveMonkeys#license"
},
{
"moduleName": "com.twelvemonkeys.common:common-io",
"moduleVersion": "3.13.1",
"moduleLicense": "The BSD License",
"moduleLicenseUrl": "https://github.com/haraldk/TwelveMonkeys#license"
},
{
"moduleName": "com.twelvemonkeys.common:common-io",
"moduleVersion": "3.14.0",
"moduleLicense": "The BSD License",
"moduleLicenseUrl": "https://github.com/haraldk/TwelveMonkeys#license"
},
{
"moduleName": "com.twelvemonkeys.common:common-lang",
"moduleVersion": "3.13.1",
"moduleLicense": "The BSD License",
"moduleLicenseUrl": "https://github.com/haraldk/TwelveMonkeys#license"
},
{
"moduleName": "com.twelvemonkeys.common:common-lang",
"moduleVersion": "3.14.0",
@@ -569,12 +523,6 @@
"moduleLicense": "The BSD License",
"moduleLicenseUrl": "https://github.com/haraldk/TwelveMonkeys#license"
},
{
"moduleName": "com.twelvemonkeys.imageio:imageio-core",
"moduleVersion": "3.13.1",
"moduleLicense": "The BSD License",
"moduleLicenseUrl": "https://github.com/haraldk/TwelveMonkeys#license"
},
{
"moduleName": "com.twelvemonkeys.imageio:imageio-core",
"moduleVersion": "3.14.0",
@@ -587,12 +535,6 @@
"moduleLicense": "The BSD License",
"moduleLicenseUrl": "https://github.com/haraldk/TwelveMonkeys#license"
},
{
"moduleName": "com.twelvemonkeys.imageio:imageio-metadata",
"moduleVersion": "3.13.1",
"moduleLicense": "The BSD License",
"moduleLicenseUrl": "https://github.com/haraldk/TwelveMonkeys#license"
},
{
"moduleName": "com.twelvemonkeys.imageio:imageio-metadata",
"moduleVersion": "3.14.0",
@@ -605,24 +547,12 @@
"moduleLicense": "The BSD License",
"moduleLicenseUrl": "https://github.com/haraldk/TwelveMonkeys#license"
},
{
"moduleName": "com.twelvemonkeys.imageio:imageio-tiff",
"moduleVersion": "3.13.1",
"moduleLicense": "The BSD License",
"moduleLicenseUrl": "https://github.com/haraldk/TwelveMonkeys#license"
},
{
"moduleName": "com.twelvemonkeys.imageio:imageio-tiff",
"moduleVersion": "3.14.0",
"moduleLicense": "The BSD License",
"moduleLicenseUrl": "https://github.com/haraldk/TwelveMonkeys#license"
},
{
"moduleName": "com.twelvemonkeys.imageio:imageio-webp",
"moduleVersion": "3.13.1",
"moduleLicense": "The BSD License",
"moduleLicenseUrl": "https://github.com/haraldk/TwelveMonkeys#license"
},
{
"moduleName": "com.twelvemonkeys.imageio:imageio-webp",
"moduleVersion": "3.14.0",
@@ -769,13 +699,6 @@
"moduleLicense": "The Apache Software License, Version 2.0",
"moduleLicenseUrl": "http://www.apache.org/licenses/LICENSE-2.0.txt"
},
{
"moduleName": "commons-beanutils:commons-beanutils",
"moduleUrl": "https://commons.apache.org/proper/commons-beanutils",
"moduleVersion": "1.11.0",
"moduleLicense": "Apache-2.0",
"moduleLicenseUrl": "https://www.apache.org/licenses/LICENSE-2.0.txt"
},
{
"moduleName": "commons-cli:commons-cli",
"moduleUrl": "http://commons.apache.org/proper/commons-cli/",
@@ -790,13 +713,6 @@
"moduleLicense": "Apache-2.0",
"moduleLicenseUrl": "https://www.apache.org/licenses/LICENSE-2.0.txt"
},
{
"moduleName": "commons-collections:commons-collections",
"moduleUrl": "http://commons.apache.org/collections/",
"moduleVersion": "3.2.2",
"moduleLicense": "Apache License, Version 2.0",
"moduleLicenseUrl": "http://www.apache.org/licenses/LICENSE-2.0.txt"
},
{
"moduleName": "commons-io:commons-io",
"moduleUrl": "https://commons.apache.org/proper/commons-io/",
@@ -1360,13 +1276,6 @@
"moduleLicense": "Apache-2.0",
"moduleLicenseUrl": "https://www.apache.org/licenses/LICENSE-2.0.txt"
},
{
"moduleName": "org.apache.commons:commons-math3",
"moduleUrl": "http://commons.apache.org/proper/commons-math/",
"moduleVersion": "3.6.1",
"moduleLicense": "Apache License, Version 2.0",
"moduleLicenseUrl": "http://www.apache.org/licenses/LICENSE-2.0.txt"
},
{
"moduleName": "org.apache.commons:commons-text",
"moduleUrl": "https://commons.apache.org/proper/commons-text",
@@ -57,6 +57,8 @@ class ToolIODeclarationCoverageTest {
// documents.
"/api/v1/convert/pdf/text-editor",
"/api/v1/convert/text-editor/pdf",
// Charcode lookup for the v2 editor: returns glyph mappings, not a document.
"/api/v1/general/pdf-text-editor",
// Signing sessions, certificate checks and hardware token enumeration; the
// signing tool itself is /api/v1/security/cert-sign, which is declared.
"/api/v1/security/cert-sign/sessions",
@@ -0,0 +1,516 @@
package stirling.software.SPDF.controller.api;
import java.io.ByteArrayOutputStream;
import java.io.IOException;
import java.io.InputStream;
import java.nio.file.Files;
import java.nio.file.Path;
import java.nio.file.Paths;
import java.util.ArrayList;
import java.util.HashSet;
import java.util.List;
import java.util.Set;
import javax.imageio.ImageIO;
import org.apache.pdfbox.Loader;
import org.apache.pdfbox.cos.COSName;
import org.apache.pdfbox.pdmodel.PDDocument;
import org.apache.pdfbox.pdmodel.PDPage;
import org.apache.pdfbox.pdmodel.PDPageContentStream;
import org.apache.pdfbox.pdmodel.PDResources;
import org.apache.pdfbox.pdmodel.font.PDFont;
import org.apache.pdfbox.pdmodel.font.PDFontDescriptor;
import org.apache.pdfbox.pdmodel.font.PDType0Font;
import org.apache.pdfbox.pdmodel.font.PDType1Font;
import org.apache.pdfbox.pdmodel.font.PDType3Font;
import org.apache.pdfbox.pdmodel.font.Standard14Fonts;
import org.apache.pdfbox.rendering.PDFRenderer;
import org.junit.jupiter.api.Disabled;
import org.junit.jupiter.api.Test;
/**
* Probe: what can PDFBox actually do for font ENCODING on real-world PDFs. This is a diagnostic
* test (not a regression) - run with --tests PdfBoxFontEncodingProbeTest -i to see stdout.
*
* <p>Answers these questions:
*
* <ol>
* <li>Type0/CIDFontType2 subset: can we add a new glyph not in the original subset? (no, encode
* throws IllegalArgumentException).
* <li>Type1: same question.
* <li>TrueType: same question.
* <li>Can we load a fresh TTF via PDType0Font.load(doc, file) and write text with it? (yes,
* primary path).
* <li>Round-trip via getFontStream / re-embed - can it rehabilitate Type3? (no - Type3 has no
* FontFile* program at all).
* <li>What fonts ship with PDFBox / fontbox? (only LiberationSans-Regular.ttf + AFM for the 14
* standard fonts; CFF/Type1 binaries are NOT bundled - Standard14Fonts.getMappedFontName
* redirects unmappable ones to LiberationSans).
* </ol>
*/
@Disabled(
"Diagnostic probe: dumps PDFBox font encoding tables to stdout and asserts nothing. Kept for font debugging; run manually.")
public class PdfBoxFontEncodingProbeTest {
private static final Path PROJECT_ROOT =
Paths.get(System.getProperty("user.dir")).getParent().getParent();
private static final Path SAMPLE =
PROJECT_ROOT.resolve("frontend/editor/public/samples/Sample.pdf");
private static final Path[] EXTRA_FIXTURES = {
PROJECT_ROOT.resolve("frontend/editor/src/core/tests/test-fixtures/stirling-marketing.pdf"),
PROJECT_ROOT.resolve("frontend/editor/src/core/tests/test-fixtures/multi-page-sample.pdf"),
PROJECT_ROOT.resolve("frontend/editor/src/core/tests/test-fixtures/big-sample.pdf"),
PROJECT_ROOT.resolve("frontend/editor/src/core/tests/test-fixtures/paragraph-sample.pdf"),
PROJECT_ROOT.resolve("frontend/editor/src/core/tests/test-fixtures/user-sample.pdf"),
};
/**
* Rasterize the Q4b output (Sample.pdf with injected Liberation text) to confirm the new text
* actually renders on top of the existing Type3 content.
*/
@Test
public void probeRenderInjectedSample() throws IOException {
Path liberation =
PROJECT_ROOT.resolve(
"app/core/src/main/resources/static/fonts/LiberationSans-Regular.ttf");
byte[] pdfBytes = Files.readAllBytes(SAMPLE);
ByteArrayOutputStream out = new ByteArrayOutputStream();
try (PDDocument doc = Loader.loadPDF(pdfBytes)) {
PDPage page = doc.getPage(0);
PDType0Font ttf;
try (InputStream in = Files.newInputStream(liberation)) {
ttf = PDType0Font.load(doc, in, true);
}
try (PDPageContentStream cs =
new PDPageContentStream(
doc, page, PDPageContentStream.AppendMode.APPEND, true, true)) {
cs.beginText();
cs.setFont(ttf, 24);
cs.newLineAtOffset(50, 120);
cs.showText("INJECTED via PDType0Font.load - $@#&Z");
cs.endText();
}
doc.save(out);
}
// Rasterize page 0 to a PNG so we can eyeball it.
try (PDDocument check = Loader.loadPDF(out.toByteArray())) {
PDFRenderer renderer = new PDFRenderer(check);
java.awt.image.BufferedImage img = renderer.renderImageWithDPI(0, 100);
// Build dir, not the repo root: this render is a debugging aid and was
// twice committed by accident when it landed in the working tree.
Path png =
Paths.get(System.getProperty("user.dir"), "build", "probe-output")
.resolve("pdfbox-probe-q4b-rendered.png");
Files.createDirectories(png.getParent());
ImageIO.write(img, "PNG", png.toFile());
System.out.println(
"Rendered injected sample to "
+ png
+ " - "
+ img.getWidth()
+ "x"
+ img.getHeight());
}
}
/**
* Build a PDF in memory that uses a Type0/CIDFontType2 subset font (the kind Word / InDesign /
* LibreOffice produce), then probe whether encode() can add a glyph that wasn't in the original
* subset.
*/
@Test
public void probeType0CIDFontType2Subset() throws IOException {
System.out.println(
"\n##################################################################\n"
+ "Q1 probe: Type0/CIDFontType2 SUBSET can/cannot add new glyphs\n"
+ "##################################################################\n");
Path liberation =
PROJECT_ROOT.resolve(
"app/core/src/main/resources/static/fonts/LiberationSans-Regular.ttf");
// Build a PDF that contains only "abc" subsetted from LiberationSans.
ByteArrayOutputStream baos = new ByteArrayOutputStream();
try (PDDocument doc = new PDDocument()) {
PDPage page = new PDPage();
doc.addPage(page);
PDType0Font subset;
try (InputStream in = Files.newInputStream(liberation)) {
subset = PDType0Font.load(doc, in, true /* embedSubset */);
}
try (PDPageContentStream cs = new PDPageContentStream(doc, page)) {
cs.beginText();
cs.setFont(subset, 12);
cs.newLineAtOffset(100, 700);
cs.showText("abc");
cs.endText();
}
doc.save(baos);
}
// Reload the produced PDF and try to add a NEW glyph through the embedded subset font.
byte[] subsetPdf = baos.toByteArray();
try (PDDocument doc = Loader.loadPDF(subsetPdf)) {
PDResources res = doc.getPage(0).getResources();
for (COSName fn : res.getFontNames()) {
PDFont f = res.getFont(fn);
System.out.println(
" Subset font in saved PDF: "
+ f.getName()
+ " ("
+ f.getClass().getSimpleName()
+ ", subType="
+ f.getSubType()
+ ")");
for (String ch : new String[] {"a", "b", "c", "Z", "z", "0", "$", "@", "X", " "}) {
try {
byte[] enc = f.encode(ch);
StringBuilder hex = new StringBuilder();
for (byte b : enc) hex.append(String.format("%02X ", b & 0xff));
System.out.println(
" encode('" + ch + "') -> [" + hex.toString().trim() + "] OK");
} catch (UnsupportedOperationException uoe) {
System.out.println(" encode('" + ch + "') UNSUPPORTED");
} catch (IllegalArgumentException iae) {
System.out.println(
" encode('" + ch + "') MISSING - " + iae.getMessage());
} catch (IOException ioe) {
System.out.println(" encode('" + ch + "') IO ERR - " + ioe.getMessage());
}
}
}
}
}
@Test
public void probeExtraFixtures() throws IOException {
System.out.println(
"\n##################################################################\n"
+ "Extra fixture font-class probe\n"
+ "##################################################################\n");
for (Path fixture : EXTRA_FIXTURES) {
if (!Files.exists(fixture)) {
System.out.println("(missing) " + fixture);
continue;
}
System.out.println("\n=== " + fixture.getFileName() + " ===");
byte[] bytes = Files.readAllBytes(fixture);
try (PDDocument doc = Loader.loadPDF(bytes)) {
Set<COSName> seen = new HashSet<>();
for (int p = 0; p < doc.getNumberOfPages(); p++) {
PDPage page = doc.getPage(p);
PDResources res = page.getResources();
if (res == null) continue;
for (COSName name : res.getFontNames()) {
if (!seen.add(name)) continue;
try {
PDFont f = res.getFont(name);
if (f == null) continue;
String fontFile = "none";
PDFontDescriptor d = f.getFontDescriptor();
if (d != null) {
if (d.getFontFile() != null) fontFile = "FontFile";
else if (d.getFontFile2() != null) fontFile = "FontFile2";
else if (d.getFontFile3() != null) fontFile = "FontFile3";
}
String z = "?";
try {
f.encode("Z");
z = "OK";
} catch (UnsupportedOperationException ex) {
z = "UNSUPPORTED";
} catch (IllegalArgumentException ex) {
z = "MISSING";
} catch (IOException ex) {
z = "IO_ERR";
}
System.out.println(
" page "
+ p
+ " "
+ name.getName()
+ " -> "
+ f.getName()
+ " "
+ f.getClass().getSimpleName()
+ " ("
+ f.getSubType()
+ ", "
+ fontFile
+ ", embed="
+ f.isEmbedded()
+ ") encode('Z')="
+ z);
} catch (IOException e) {
System.out.println(
" page "
+ p
+ " "
+ name.getName()
+ " load failed: "
+ e.getMessage());
}
}
}
}
}
}
@Test
public void probeAllQuestions() throws IOException {
System.out.println(
"\n##################################################################\n"
+ "PDFBox font-encoding probe (Sample.pdf + bundled fallback fonts)\n"
+ "##################################################################\n");
// Discover every font in Sample.pdf so we have a real-world test set.
byte[] pdfBytes = Files.readAllBytes(SAMPLE);
try (PDDocument doc = Loader.loadPDF(pdfBytes)) {
List<PDFont> allFonts = new ArrayList<>();
Set<COSName> seen = new HashSet<>();
for (int p = 0; p < doc.getNumberOfPages(); p++) {
PDPage page = doc.getPage(p);
PDResources res = page.getResources();
if (res == null) continue;
for (COSName name : res.getFontNames()) {
if (!seen.add(name)) continue;
try {
PDFont f = res.getFont(name);
if (f != null) allFonts.add(f);
} catch (Exception e) {
System.out.println(
" (skipped " + name.getName() + " - " + e.getMessage() + ")");
}
}
}
System.out.println(
"Discovered " + allFonts.size() + " unique fonts across Sample.pdf:");
for (PDFont f : allFonts) {
System.out.println(
" - "
+ f.getName()
+ " ("
+ f.getClass().getSimpleName()
+ ", subType="
+ f.getSubType()
+ ", embedded="
+ f.isEmbedded()
+ ")");
}
// Q1/Q2/Q3
// Try encoding a char that is NEVER in Sample.pdf via each font.
// 'Z' is unlikely to be in the subset for most marketing pages.
// Try several candidates to surface what each font can/can't add.
String[] candidates = {"Z", "$", "@", "#", "Q", "&", "A", "0", "M"};
for (PDFont f : allFonts) {
System.out.println("\n=== Encode-probe for font: " + f.getName() + " ===");
for (String ch : candidates) {
try {
byte[] enc = f.encode(ch);
StringBuilder hex = new StringBuilder();
for (byte b : enc) hex.append(String.format("%02X ", b & 0xff));
System.out.println(
" encode('" + ch + "') -> [" + hex.toString().trim() + "] OK");
} catch (UnsupportedOperationException uoe) {
System.out.println(
" encode('" + ch + "') UNSUPPORTED: " + uoe.getMessage());
} catch (IllegalArgumentException iae) {
System.out.println(" encode('" + ch + "') MISSING: " + iae.getMessage());
} catch (IOException ioe) {
System.out.println(" encode('" + ch + "') IO ERR: " + ioe.getMessage());
}
}
}
// Q5
// For each font, see what's in the FontFile* stream - this is what we'd
// have to round-trip through to "rehabilitate" a Type3 font.
System.out.println("\n=== FontFile stream availability (Q5) ===");
for (PDFont f : allFonts) {
String kind = "none";
int size = 0;
PDFontDescriptor d = f.getFontDescriptor();
if (d != null) {
if (d.getFontFile() != null) {
kind = "FontFile (Type1)";
size = streamBytes(d.getFontFile().getCOSObject().createInputStream());
} else if (d.getFontFile2() != null) {
kind = "FontFile2 (TTF)";
size = streamBytes(d.getFontFile2().getCOSObject().createInputStream());
} else if (d.getFontFile3() != null) {
kind = "FontFile3 (CFF/OpenType)";
size = streamBytes(d.getFontFile3().getCOSObject().createInputStream());
}
}
System.out.println(
" "
+ f.getName()
+ " ("
+ f.getClass().getSimpleName()
+ "): "
+ kind
+ " ("
+ size
+ " bytes)");
if (f instanceof PDType3Font) {
System.out.println(
" -> Type3 has CharProc streams, NOT a FontFile binary."
+ " getFontStream() returns null. Round-trip rehab is impossible:");
System.out.println(
" each glyph is a mini content stream, not a glyph outline in a"
+ " standard font format. We'd need to rasterize each CharProc to"
+ " glyph outlines + build a fresh TTF/CFF from scratch.");
}
}
}
// Q4: PDType0Font.load(doc, file) round-trip
System.out.println("\n=== Q4: load fresh TTF and write text to a fresh PDF ===");
Path liberation =
PROJECT_ROOT.resolve(
"app/core/src/main/resources/static/fonts/LiberationSans-Regular.ttf");
if (!Files.exists(liberation)) {
System.out.println(" Liberation TTF not found at " + liberation);
} else {
try (PDDocument out = new PDDocument()) {
PDPage page = new PDPage();
out.addPage(page);
PDType0Font ttf;
try (InputStream in = Files.newInputStream(liberation)) {
ttf = PDType0Font.load(out, in, true /* embedSubset */);
}
System.out.println(
" Loaded TTF -> "
+ ttf.getName()
+ " ("
+ ttf.getClass().getSimpleName()
+ ")");
String testText = "Hello world! 0123 Z $ @";
byte[] encoded = ttf.encode(testText);
System.out.println(
" Encoded "
+ testText.length()
+ " chars -> "
+ encoded.length
+ " bytes (Identity-H = 2 bytes/glyph)");
try (PDPageContentStream cs = new PDPageContentStream(out, page)) {
cs.beginText();
cs.setFont(ttf, 12);
cs.newLineAtOffset(100, 700);
cs.showText(testText);
cs.endText();
}
ByteArrayOutputStream baos = new ByteArrayOutputStream();
out.save(baos);
Path tmp = Files.createTempFile("pdfbox-probe-q4-", ".pdf");
Files.write(tmp, baos.toByteArray());
System.out.println(
" Wrote fresh-TTF PDF to "
+ tmp
+ " ("
+ baos.size()
+ " bytes) - opens cleanly.");
// Re-load to confirm the new font is embedded properly.
try (PDDocument check = Loader.loadPDF(baos.toByteArray())) {
PDResources res = check.getPage(0).getResources();
for (COSName fn : res.getFontNames()) {
PDFont f = res.getFont(fn);
System.out.println(
" embedded font: "
+ f.getName()
+ " ("
+ f.getClass().getSimpleName()
+ ", embedded="
+ f.isEmbedded()
+ ")");
}
}
}
}
// Q4b: load TTF into an EXISTING PDF (Sample.pdf) and append text
System.out.println(
"\n=== Q4b: load TTF into EXISTING Sample.pdf and write text on page 0 ===");
try (PDDocument doc = Loader.loadPDF(pdfBytes)) {
PDPage page = doc.getPage(0);
PDType0Font ttf;
try (InputStream in = Files.newInputStream(liberation)) {
ttf = PDType0Font.load(doc, in, true);
}
// append-mode content stream so we don't disturb existing graphics
try (PDPageContentStream cs =
new PDPageContentStream(
doc,
page,
PDPageContentStream.AppendMode.APPEND,
true /* compress */,
true /* resetContext */)) {
cs.beginText();
cs.setFont(ttf, 12);
cs.newLineAtOffset(50, 50);
cs.showText("Injected via PDType0Font.load - $@#&");
cs.endText();
}
ByteArrayOutputStream baos = new ByteArrayOutputStream();
doc.save(baos);
Path tmp = Files.createTempFile("pdfbox-probe-q4b-", ".pdf");
Files.write(tmp, baos.toByteArray());
System.out.println(
" Wrote injected-text PDF to " + tmp + " (" + baos.size() + " bytes).");
// Verify by re-reading: how many fonts now on page 0?
try (PDDocument check = Loader.loadPDF(baos.toByteArray())) {
PDResources res = check.getPage(0).getResources();
int count = 0;
for (COSName fn : res.getFontNames()) {
PDFont f = res.getFont(fn);
count++;
System.out.println(
" page-0 font: "
+ fn.getName()
+ " -> "
+ f.getName()
+ " ("
+ f.getClass().getSimpleName()
+ ")");
}
System.out.println(" Total fonts on page 0: " + count);
}
}
// Q6: what fonts ship in PDFBox / fontbox
System.out.println("\n=== Q6: bundled fonts (Standard14 redirect probe) ===");
for (Standard14Fonts.FontName fn : Standard14Fonts.FontName.values()) {
PDType1Font f = new PDType1Font(fn);
String mapped = "" + Standard14Fonts.getMappedFontName(fn.getName());
System.out.println(
" Standard14 "
+ fn.getName()
+ " -> mapped='"
+ mapped
+ "' name="
+ f.getName());
}
System.out.println(
" (PDFBox bundles ONLY LiberationSans-Regular.ttf as a binary; the AFMs cover"
+ " metrics for the 14 standard fonts but rendering Helvetica/Times/Courier"
+ " glyphs falls back to LiberationSans glyphs at runtime when no system font"
+ " is found.)");
}
private static int streamBytes(InputStream is) {
try (InputStream it = is) {
ByteArrayOutputStream baos = new ByteArrayOutputStream();
byte[] buf = new byte[4096];
int n;
while ((n = it.read(buf)) >= 0) baos.write(buf, 0, n);
return baos.size();
} catch (IOException e) {
return -1;
}
}
}
@@ -0,0 +1,755 @@
package stirling.software.SPDF.controller.api;
import static org.assertj.core.api.Assertions.assertThat;
import static org.mockito.Mockito.mock;
import java.io.ByteArrayOutputStream;
import java.io.InputStream;
import java.util.Base64;
import org.apache.pdfbox.pdmodel.PDDocument;
import org.apache.pdfbox.pdmodel.PDPage;
import org.apache.pdfbox.pdmodel.PDPageContentStream;
import org.apache.pdfbox.pdmodel.font.PDType1Font;
import org.apache.pdfbox.pdmodel.font.Standard14Fonts;
import org.junit.jupiter.api.Test;
import org.springframework.http.ResponseEntity;
import stirling.software.SPDF.controller.api.PdfTextEditorCharcodeController.EncodeCharcodesRequest;
import stirling.software.SPDF.controller.api.PdfTextEditorCharcodeController.EncodeCharcodesResponse;
import stirling.software.common.service.CustomPDFDocumentFactory;
import stirling.software.common.service.PdfMetadataService;
/**
* Regression coverage for the v2 text editor "spaces render as „" bug.
*
* <p>mushroom-life.pdf is a LaTeX document whose embedded LMRoman subset font has NO real space
* glyph, yet {@code font.encode(" ")} still returns charcode 0x20 without throwing. Reusing that
* code via {@code FPDFText_SetCharcodes} paints whatever glyph sits at subset code 0x20 - the
* quotedblbase „. The controller must therefore report whitespace as {@code missing} so the
* frontend emits it as a positional gap instead of a reused glyph.
*/
class PdfTextEditorCharcodeControllerTest {
private static PdfTextEditorCharcodeController controller() {
return new PdfTextEditorCharcodeController(
new CustomPDFDocumentFactory(mock(PdfMetadataService.class)));
}
private static String mushroomBase64() throws Exception {
try (InputStream in =
PdfTextEditorCharcodeControllerTest.class.getResourceAsStream(
"/pdftexteditor/mushroom-life.pdf")) {
assertThat(in).as("mushroom-life.pdf test resource").isNotNull();
return Base64.getEncoder().encodeToString(in.readAllBytes());
}
}
private static EncodeCharcodesRequest request(String text) throws Exception {
EncodeCharcodesRequest req = new EncodeCharcodesRequest();
req.setPdfBase64(mushroomBase64());
req.setPageIndex(0);
// findFontByToUnicode locates the font via the ToUnicode CMap - "M" exists on page 0.
req.setLocatorChar("M");
req.setText(text);
return req;
}
@Test
void spaceIsReportedMissingNeverEncoded() throws Exception {
PdfTextEditorCharcodeController controller = controller();
ResponseEntity<EncodeCharcodesResponse> resp = controller.encodeCharcodes(request(" "));
EncodeCharcodesResponse body = resp.getBody();
assertThat(body).isNotNull();
assertThat(body.getError()).isNull();
// The space must be reported missing, NOT handed back as a charcode
// (0x20) the frontend would reuse into the „ glyph.
assertThat(body.getMissing()).containsExactly(" ");
assertThat(body.getCharcodes()).isNullOrEmpty();
}
@Test
void realCharsEncodeWhileWhitespaceStaysAGap() throws Exception {
PdfTextEditorCharcodeController controller = controller();
// "M M" - both M's must encode to real charcodes; only the space is a gap.
ResponseEntity<EncodeCharcodesResponse> resp = controller.encodeCharcodes(request("M M"));
EncodeCharcodesResponse body = resp.getBody();
assertThat(body).isNotNull();
assertThat(body.getError()).isNull();
assertThat(body.getCharcodes()).as("both M glyphs encode").hasSize(2);
assertThat(body.getMissing()).containsExactly(" ");
}
@Test
void tabAndNewlineAreAlsoTreatedAsGaps() throws Exception {
PdfTextEditorCharcodeController controller = controller();
ResponseEntity<EncodeCharcodesResponse> resp = controller.encodeCharcodes(request("\t\n"));
EncodeCharcodesResponse body = resp.getBody();
assertThat(body).isNotNull();
assertThat(body.getMissing()).containsExactly("\t", "\n");
assertThat(body.getCharcodes()).isNullOrEmpty();
}
/**
* A page with two fonts that BOTH render 'A'. {@code fontName} must select which one to encode
* against - the cross-font fix. Without it the first font in resources order won wins and a
* cross-font edit got the wrong font's charcode.
*/
private static String twoFontBase64() throws Exception {
try (PDDocument doc = new PDDocument()) {
PDPage page = new PDPage();
doc.addPage(page);
PDType1Font helvetica = new PDType1Font(Standard14Fonts.FontName.HELVETICA);
PDType1Font times = new PDType1Font(Standard14Fonts.FontName.TIMES_ROMAN);
try (PDPageContentStream cs = new PDPageContentStream(doc, page)) {
cs.beginText();
cs.setFont(helvetica, 12);
cs.newLineAtOffset(72, 720);
cs.showText("A");
cs.endText();
cs.beginText();
cs.setFont(times, 12);
cs.newLineAtOffset(72, 700);
cs.showText("A");
cs.endText();
}
ByteArrayOutputStream bos = new ByteArrayOutputStream();
doc.save(bos);
return Base64.getEncoder().encodeToString(bos.toByteArray());
}
}
private static EncodeCharcodesRequest twoFontRequest(String fontName) throws Exception {
EncodeCharcodesRequest req = new EncodeCharcodesRequest();
req.setPdfBase64(twoFontBase64());
req.setPageIndex(0);
req.setLocatorChar("A");
req.setFontName(fontName);
req.setText("A");
return req;
}
@Test
void fontNameDisambiguatesBetweenTwoFontsRenderingTheSameChar() throws Exception {
PdfTextEditorCharcodeController controller = controller();
// Targeting Times-Roman must encode against Times-Roman, not whichever
// font happens to appear first in the page's font resources.
EncodeCharcodesResponse times =
controller.encodeCharcodes(twoFontRequest("Times-Roman")).getBody();
assertThat(times).isNotNull();
assertThat(times.getError()).isNull();
assertThat(times.getNote()).contains("Times-Roman");
assertThat(times.getCharcodes()).hasSize(1);
// Targeting Helvetica must encode against Helvetica.
EncodeCharcodesResponse helv =
controller.encodeCharcodes(twoFontRequest("Helvetica")).getBody();
assertThat(helv).isNotNull();
assertThat(helv.getError()).isNull();
assertThat(helv.getNote()).contains("Helvetica");
assertThat(helv.getCharcodes()).hasSize(1);
}
@Test
void unknownFontNameReportsNoFontInsteadOfWrongFont() throws Exception {
PdfTextEditorCharcodeController controller = controller();
// A name that matches no font on the page must NOT silently encode
// against a different font: the frontend writes the returned charcodes
// into the NAMED font's text object, so a first-match fallback would
// bake wrong glyphs. It must report failure so the caller falls back.
EncodeCharcodesResponse body =
controller.encodeCharcodes(twoFontRequest("DoesNotExist")).getBody();
assertThat(body).isNotNull();
assertThat(body.getError()).contains("no font");
assertThat(body.getCharcodes()).isNull();
}
@Test
void missingRequiredFieldsReturns400() {
EncodeCharcodesRequest req = new EncodeCharcodesRequest();
req.setPdfBase64("AAAA");
req.setLocatorChar("M");
// text is null
ResponseEntity<EncodeCharcodesResponse> resp = controller().encodeCharcodes(req);
assertThat(resp.getStatusCode().value()).isEqualTo(400);
assertThat(resp.getBody()).isNotNull();
assertThat(resp.getBody().getError()).isEqualTo("missing required fields");
}
@Test
void invalidBase64Returns400() {
EncodeCharcodesRequest req = new EncodeCharcodesRequest();
req.setPdfBase64("!!!notbase64!!!");
req.setLocatorChar("M");
req.setText("M");
ResponseEntity<EncodeCharcodesResponse> resp = controller().encodeCharcodes(req);
assertThat(resp.getStatusCode().value()).isEqualTo(400);
assertThat(resp.getBody()).isNotNull();
assertThat(resp.getBody().getError()).isEqualTo("pdfBase64 is not valid base64");
}
@Test
void pageIndexOutOfRangeReturns400() throws Exception {
EncodeCharcodesRequest req = request("M");
req.setPageIndex(999);
ResponseEntity<EncodeCharcodesResponse> resp = controller().encodeCharcodes(req);
assertThat(resp.getStatusCode().value()).isEqualTo(400);
assertThat(resp.getBody()).isNotNull();
assertThat(resp.getBody().getError()).isEqualTo("pageIndex out of range");
}
@Test
void nonPdfBytesReturnsGenericError() {
EncodeCharcodesRequest req = new EncodeCharcodesRequest();
req.setPdfBase64(Base64.getEncoder().encodeToString("not a pdf".getBytes()));
req.setLocatorChar("M");
req.setText("M");
// Must not throw, and must not leak the raw PDFBox parser message.
ResponseEntity<EncodeCharcodesResponse> resp = controller().encodeCharcodes(req);
assertThat(resp.getStatusCode().is4xxClientError()).isTrue();
assertThat(resp.getBody()).isNotNull();
assertThat(resp.getBody().getError()).isEqualTo("failed to load PDF");
}
@Test
void absentLocatorCharReturns200WithError() throws Exception {
// U+FFFF never appears in the document, so no font matches.
ResponseEntity<EncodeCharcodesResponse> resp =
controller().encodeCharcodes(requestWithLocator("￿"));
assertThat(resp.getStatusCode().value()).isEqualTo(200);
EncodeCharcodesResponse body = resp.getBody();
assertThat(body).isNotNull();
assertThat(body.getError()).isNotNull();
assertThat(body.getCharcodes()).isNull();
}
@Test
void oversizePdfRejected() {
EncodeCharcodesRequest req = new EncodeCharcodesRequest();
// A base64 string long enough that length/4*3 exceeds the 100MB cap, without
// ever allocating the decoded bytes (the guard runs before decode).
char[] huge = new char[140 * 1024 * 1024];
java.util.Arrays.fill(huge, 'A');
req.setPdfBase64(new String(huge));
req.setLocatorChar("M");
req.setText("M");
ResponseEntity<EncodeCharcodesResponse> resp = controller().encodeCharcodes(req);
assertThat(resp.getStatusCode().value()).isEqualTo(413);
assertThat(resp.getBody()).isNotNull();
assertThat(resp.getBody().getError()).isEqualTo("pdf too large");
}
private static EncodeCharcodesRequest requestWithLocator(String locator) throws Exception {
EncodeCharcodesRequest req = request("M");
req.setLocatorChar(locator);
return req;
}
/**
* Build a page whose resources declare {@code filler} fonts that do NOT render 'A' (Symbol /
* ZapfDingbats have non-Latin encodings) plus, optionally, a trailing Helvetica that does. The
* Standard14 probe upper bound is 256 so each scan is cheap.
*/
private static String manyFontsBase64(int filler, boolean trailingTarget) throws Exception {
try (PDDocument doc = new PDDocument()) {
PDPage page = new PDPage();
doc.addPage(page);
org.apache.pdfbox.pdmodel.PDResources resources =
new org.apache.pdfbox.pdmodel.PDResources();
for (int n = 0; n < filler; n++) {
Standard14Fonts.FontName fn =
(n % 2 == 0)
? Standard14Fonts.FontName.SYMBOL
: Standard14Fonts.FontName.ZAPF_DINGBATS;
resources.put(
org.apache.pdfbox.cos.COSName.getPDFName("Ff" + n), new PDType1Font(fn));
}
if (trailingTarget) {
resources.put(
org.apache.pdfbox.cos.COSName.getPDFName("Target"),
new PDType1Font(Standard14Fonts.FontName.HELVETICA));
}
page.setResources(resources);
ByteArrayOutputStream bos = new ByteArrayOutputStream();
doc.save(bos);
return Base64.getEncoder().encodeToString(bos.toByteArray());
}
}
private static EncodeCharcodesRequest manyFontsRequest(String base64) {
EncodeCharcodesRequest req = new EncodeCharcodesRequest();
req.setPdfBase64(base64);
req.setPageIndex(0);
req.setLocatorChar("A");
req.setText("A");
return req;
}
@Test
void targetFontFoundAmongManyFonts() throws Exception {
// 60 non-matching fonts then the Helvetica target, all within the 64-font cap.
ResponseEntity<EncodeCharcodesResponse> resp =
controller().encodeCharcodes(manyFontsRequest(manyFontsBase64(60, true)));
assertThat(resp.getStatusCode().value()).isEqualTo(200);
EncodeCharcodesResponse body = resp.getBody();
assertThat(body).isNotNull();
assertThat(body.getError()).isNull();
assertThat(body.getCharcodes()).hasSize(1);
}
@Test
void targetBeyondFontCapReturnsGracefulNoFont() throws Exception {
// 64 non-matching fonts then the target at position 65 - the scan cap stops
// before reaching it, so we get a graceful no-font error rather than a full scan.
ResponseEntity<EncodeCharcodesResponse> resp =
controller().encodeCharcodes(manyFontsRequest(manyFontsBase64(64, true)));
assertThat(resp.getStatusCode().value()).isEqualTo(200);
EncodeCharcodesResponse body = resp.getBody();
assertThat(body).isNotNull();
assertThat(body.getError()).isNotNull();
assertThat(body.getCharcodes()).isNull();
}
// Same-family sibling subsets. One document can embed several subsets of
// one family, each re-encoded by order of first glyph use, so a letter has
// a different charcode in each ("R" = 0x21 in one, 0x22 in its sibling).
// FPDFFont_GetBaseFontName strips the "ABCDEF+" tag, so a name-based
// lookup cannot tell them apart and borrows the wrong subset's codes.
//
// The doc below mirrors that with two TrueType subsets differing only by
// subset tag. PUA code points keep it deterministic: font.encode() cannot
// resolve them by glyph name, so the charcode can only come from the
// selected font's ToUnicode reverse map - proving WHICH font was picked.
private static final String PUA = "";
/** ToUnicode CMap mapping each supplied charcode to a BMP code point. */
private static byte[] toUnicodeCmap(int[][] codeToUnicode) {
StringBuilder sb =
new StringBuilder(
"""
/CIDInit /ProcSet findresource begin
12 dict begin
begincmap
/CIDSystemInfo << /Registry (Adobe) /Ordering (UCS) /Supplement 0 >> def
/CMapName /Adobe-Identity-UCS def
/CMapType 2 def
1 begincodespacerange
<00><FF>
endcodespacerange
""");
sb.append(codeToUnicode.length).append(" beginbfchar\n");
for (int[] pair : codeToUnicode) {
sb.append(String.format("<%02X><%04X>%n", pair[0], pair[1]));
}
sb.append(
"""
endbfchar
endcmap
CMapName currentdict /CMap defineresource pop
end
end
""");
return sb.toString().getBytes(java.nio.charset.StandardCharsets.US_ASCII);
}
private static org.apache.pdfbox.cos.COSDictionary subsetFontDict(
PDDocument doc, String baseName, byte[] fontProgram, byte[] toUnicode)
throws Exception {
org.apache.pdfbox.cos.COSDictionary font = new org.apache.pdfbox.cos.COSDictionary();
font.setItem(org.apache.pdfbox.cos.COSName.TYPE, org.apache.pdfbox.cos.COSName.FONT);
font.setItem(
org.apache.pdfbox.cos.COSName.SUBTYPE, org.apache.pdfbox.cos.COSName.TRUE_TYPE);
if (baseName != null) {
font.setName(org.apache.pdfbox.cos.COSName.BASE_FONT, baseName);
}
font.setInt(org.apache.pdfbox.cos.COSName.FIRST_CHAR, 0x21);
font.setInt(org.apache.pdfbox.cos.COSName.LAST_CHAR, 0x22);
org.apache.pdfbox.cos.COSArray widths = new org.apache.pdfbox.cos.COSArray();
widths.add(org.apache.pdfbox.cos.COSInteger.get(500));
widths.add(org.apache.pdfbox.cos.COSInteger.get(500));
font.setItem(org.apache.pdfbox.cos.COSName.WIDTHS, widths);
org.apache.pdfbox.cos.COSDictionary fd = new org.apache.pdfbox.cos.COSDictionary();
fd.setItem(org.apache.pdfbox.cos.COSName.TYPE, org.apache.pdfbox.cos.COSName.FONT_DESC);
if (baseName != null) {
fd.setName(org.apache.pdfbox.cos.COSName.FONT_NAME, baseName);
}
fd.setInt(org.apache.pdfbox.cos.COSName.FLAGS, 4);
fd.setItem(
org.apache.pdfbox.cos.COSName.FONT_BBOX,
new org.apache.pdfbox.pdmodel.common.PDRectangle(0, 0, 1000, 1000).getCOSArray());
fd.setInt(org.apache.pdfbox.cos.COSName.ITALIC_ANGLE, 0);
fd.setInt(org.apache.pdfbox.cos.COSName.ASCENT, 800);
fd.setInt(org.apache.pdfbox.cos.COSName.DESCENT, -200);
fd.setInt(org.apache.pdfbox.cos.COSName.CAP_HEIGHT, 700);
fd.setInt(org.apache.pdfbox.cos.COSName.STEM_V, 80);
if (fontProgram != null) {
org.apache.pdfbox.pdmodel.common.PDStream ff2 =
new org.apache.pdfbox.pdmodel.common.PDStream(
doc, new java.io.ByteArrayInputStream(fontProgram));
ff2.getCOSObject().setInt(org.apache.pdfbox.cos.COSName.LENGTH1, fontProgram.length);
fd.setItem(org.apache.pdfbox.cos.COSName.FONT_FILE2, ff2.getCOSObject());
}
font.setItem(org.apache.pdfbox.cos.COSName.FONT_DESC, fd);
org.apache.pdfbox.pdmodel.common.PDStream tu =
new org.apache.pdfbox.pdmodel.common.PDStream(
doc, new java.io.ByteArrayInputStream(toUnicode));
font.setItem(org.apache.pdfbox.cos.COSName.getPDFName("ToUnicode"), tu.getCOSObject());
return font;
}
// Distinct fake font programs - hashing distinguishes the subsets by these bytes.
private static final byte[] PROGRAM_A =
"fake-ttf-program-A".getBytes(java.nio.charset.StandardCharsets.US_ASCII);
private static final byte[] PROGRAM_B =
"fake-ttf-program-B".getBytes(java.nio.charset.StandardCharsets.US_ASCII);
/**
* Two sibling subsets of "FakeGaramond" whose ToUnicode maps give U+E000 DIFFERENT charcodes:
* 0x22 in subset A (AAAAAC+), 0x21 in subset B (AAAAAG+) - exactly the CV's shifted-code
* layout. {@code includeSecond=false} keeps only subset A for the unambiguous-fallback case.
*/
private static String siblingSubsetsBase64(boolean includeSecond) throws Exception {
try (PDDocument doc = new PDDocument()) {
PDPage page = new PDPage();
doc.addPage(page);
org.apache.pdfbox.cos.COSDictionary fonts = new org.apache.pdfbox.cos.COSDictionary();
fonts.setItem(
org.apache.pdfbox.cos.COSName.getPDFName("TTA"),
subsetFontDict(
doc,
"AAAAAC+FakeGaramond",
PROGRAM_A,
toUnicodeCmap(new int[][] {{0x21, 0xE001}, {0x22, 0xE000}})));
if (includeSecond) {
fonts.setItem(
org.apache.pdfbox.cos.COSName.getPDFName("TTB"),
subsetFontDict(
doc,
"AAAAAG+FakeGaramond",
PROGRAM_B,
toUnicodeCmap(new int[][] {{0x21, 0xE000}, {0x22, 0xE002}})));
}
org.apache.pdfbox.pdmodel.PDResources resources =
new org.apache.pdfbox.pdmodel.PDResources();
resources.getCOSObject().setItem(org.apache.pdfbox.cos.COSName.FONT, fonts);
page.setResources(resources);
ByteArrayOutputStream bos = new ByteArrayOutputStream();
doc.save(bos);
return Base64.getEncoder().encodeToString(bos.toByteArray());
}
}
private static String sha256Hex(byte[] bytes) throws Exception {
byte[] digest = java.security.MessageDigest.getInstance("SHA-256").digest(bytes);
StringBuilder sb = new StringBuilder();
for (byte b : digest) sb.append(String.format("%02x", b));
return sb.toString();
}
private static EncodeCharcodesRequest siblingRequest(
String base64, String fontName, String fontSha256) {
EncodeCharcodesRequest req = new EncodeCharcodesRequest();
req.setPdfBase64(base64);
req.setPageIndex(0);
req.setLocatorChar(PUA);
req.setFontName(fontName);
req.setFontSha256(fontSha256);
req.setText(PUA);
return req;
}
@Test
void fontProgramHashSelectsTheExactSubset() throws Exception {
String base64 = siblingSubsetsBase64(true);
PdfTextEditorCharcodeController controller = controller();
// Both requests carry the SAME tag-stripped name PDFium reports ("FakeGaramond"),
// so only the program hash can tell the subsets apart.
EncodeCharcodesResponse viaA =
controller
.encodeCharcodes(
siblingRequest(base64, "FakeGaramond", sha256Hex(PROGRAM_A)))
.getBody();
assertThat(viaA).isNotNull();
assertThat(viaA.getError()).isNull();
assertThat(viaA.getNote()).contains("AAAAAC+FakeGaramond");
assertThat(viaA.getCharcodes()).containsExactly(0x22L);
EncodeCharcodesResponse viaB =
controller
.encodeCharcodes(
siblingRequest(base64, "FakeGaramond", sha256Hex(PROGRAM_B)))
.getBody();
assertThat(viaB).isNotNull();
assertThat(viaB.getError()).isNull();
assertThat(viaB.getNote()).contains("AAAAAG+FakeGaramond");
assertThat(viaB.getCharcodes()).containsExactly(0x21L);
}
@Test
void ambiguousStrippedNameRefusesToGuessBetweenSiblingSubsets() throws Exception {
// No hash, and the tag-stripped name matches BOTH subsets which both render the
// locator char. Guessing here is what scrambled "RUSSELL W. MANGUM III" into
// "US EEL W. MANGS M III" - the sibling's codes hit different glyphs. The
// backend must refuse so the frontend takes its safe fallback.
EncodeCharcodesResponse body =
controller()
.encodeCharcodes(
siblingRequest(siblingSubsetsBase64(true), "FakeGaramond", null))
.getBody();
assertThat(body).isNotNull();
assertThat(body.getError()).contains("no font");
assertThat(body.getCharcodes()).isNull();
}
@Test
void exactTaggedNameStillSelectsItsSubset() throws Exception {
// A caller that DOES know the full tagged /BaseFont name keeps working.
EncodeCharcodesResponse body =
controller()
.encodeCharcodes(
siblingRequest(
siblingSubsetsBase64(true), "AAAAAG+FakeGaramond", null))
.getBody();
assertThat(body).isNotNull();
assertThat(body.getError()).isNull();
assertThat(body.getNote()).contains("AAAAAG+FakeGaramond");
assertThat(body.getCharcodes()).containsExactly(0x21L);
}
@Test
void strippedNameStillWorksWhenUnambiguous() throws Exception {
// With a SINGLE subset on the page, the tag-stripped name (what PDFium
// reports) must keep resolving - the ambiguity guard only bites when
// two+ siblings could answer.
EncodeCharcodesResponse body =
controller()
.encodeCharcodes(
siblingRequest(siblingSubsetsBase64(false), "FakeGaramond", null))
.getBody();
assertThat(body).isNotNull();
assertThat(body.getError()).isNull();
assertThat(body.getNote()).contains("AAAAAC+FakeGaramond");
assertThat(body.getCharcodes()).containsExactly(0x22L);
}
@Test
void staleHashFallsBackToNameMatching() throws Exception {
// A hash matching NO font on the page (e.g. PDFium handed back a substitute
// font's bytes) must not brick the request: name matching still runs, and an
// exact tagged name resolves.
EncodeCharcodesResponse body =
controller()
.encodeCharcodes(
siblingRequest(
siblingSubsetsBase64(true),
"AAAAAC+FakeGaramond",
"0000000000000000000000000000000000000000000000000000000000000000"))
.getBody();
assertThat(body).isNotNull();
assertThat(body.getError()).isNull();
assertThat(body.getNote()).contains("AAAAAC+FakeGaramond");
assertThat(body.getCharcodes()).containsExactly(0x22L);
}
private static final String PUA_E000 = "";
private static final String PUA_E002 = "";
private static final byte[] SHARED_PROGRAM =
"fake-ttf-program-shared".getBytes(java.nio.charset.StandardCharsets.US_ASCII);
private static String cacheIdentityPairBase64(String baseName, byte[] program)
throws Exception {
try (PDDocument doc = new PDDocument()) {
PDPage page = new PDPage();
doc.addPage(page);
org.apache.pdfbox.cos.COSDictionary fonts = new org.apache.pdfbox.cos.COSDictionary();
fonts.setItem(
org.apache.pdfbox.cos.COSName.getPDFName("C1"),
subsetFontDict(
doc,
baseName,
program,
toUnicodeCmap(new int[][] {{0x21, 0xE001}, {0x22, 0xE000}})));
fonts.setItem(
org.apache.pdfbox.cos.COSName.getPDFName("C2"),
subsetFontDict(
doc,
baseName,
program,
toUnicodeCmap(new int[][] {{0x21, 0xE002}, {0x22, 0xE003}})));
org.apache.pdfbox.pdmodel.PDResources resources =
new org.apache.pdfbox.pdmodel.PDResources();
resources.getCOSObject().setItem(org.apache.pdfbox.cos.COSName.FONT, fonts);
page.setResources(resources);
ByteArrayOutputStream bos = new ByteArrayOutputStream();
doc.save(bos);
return Base64.getEncoder().encodeToString(bos.toByteArray());
}
}
private static EncodeCharcodesRequest cacheIdentityRequest(
String base64, String locator, String fontName, String fontSha256) {
EncodeCharcodesRequest req = new EncodeCharcodesRequest();
req.setPdfBase64(base64);
req.setPageIndex(0);
req.setLocatorChar(locator);
req.setFontName(fontName);
req.setFontSha256(fontSha256);
req.setText(locator);
return req;
}
@Test
void unnamedFontsSharingOneProgramDoNotShareACachedMap() throws Exception {
String base64 = cacheIdentityPairBase64(null, SHARED_PROGRAM);
String sha = sha256Hex(SHARED_PROGRAM);
PdfTextEditorCharcodeController controller = controller();
EncodeCharcodesResponse first =
controller
.encodeCharcodes(cacheIdentityRequest(base64, PUA_E000, null, sha))
.getBody();
assertThat(first).isNotNull();
assertThat(first.getError()).isNull();
assertThat(first.getCharcodes()).containsExactly(0x22L);
EncodeCharcodesResponse second =
controller
.encodeCharcodes(cacheIdentityRequest(base64, PUA_E002, null, sha))
.getBody();
assertThat(second).isNotNull();
assertThat(second.getError()).isNull();
assertThat(second.getMissing()).isNullOrEmpty();
assertThat(second.getCharcodes())
.as("second font must not be served the first font's cached map")
.containsExactly(0x21L);
}
@Test
void fontsSharingOneNameDoNotShareACachedMap() throws Exception {
String base64 = cacheIdentityPairBase64("SharedName", null);
PdfTextEditorCharcodeController controller = controller();
EncodeCharcodesResponse first =
controller
.encodeCharcodes(cacheIdentityRequest(base64, PUA_E000, "SharedName", null))
.getBody();
assertThat(first).isNotNull();
assertThat(first.getError()).isNull();
assertThat(first.getCharcodes()).containsExactly(0x22L);
EncodeCharcodesResponse second =
controller
.encodeCharcodes(cacheIdentityRequest(base64, PUA_E002, "SharedName", null))
.getBody();
assertThat(second).isNotNull();
assertThat(second.getError()).isNull();
assertThat(second.getMissing()).isNullOrEmpty();
assertThat(second.getCharcodes())
.as("same-name fonts must not share one cached map")
.containsExactly(0x21L);
}
private static String formXObjectFontBase64() throws Exception {
try (PDDocument doc = new PDDocument()) {
PDPage page = new PDPage();
doc.addPage(page);
org.apache.pdfbox.pdmodel.graphics.form.PDFormXObject outer =
new org.apache.pdfbox.pdmodel.graphics.form.PDFormXObject(doc);
outer.setBBox(new org.apache.pdfbox.pdmodel.common.PDRectangle(0, 0, 200, 200));
org.apache.pdfbox.pdmodel.graphics.form.PDFormXObject inner =
new org.apache.pdfbox.pdmodel.graphics.form.PDFormXObject(doc);
inner.setBBox(new org.apache.pdfbox.pdmodel.common.PDRectangle(0, 0, 100, 100));
org.apache.pdfbox.pdmodel.PDResources innerResources =
new org.apache.pdfbox.pdmodel.PDResources();
innerResources.put(
org.apache.pdfbox.cos.COSName.getPDFName("F1"),
new PDType1Font(Standard14Fonts.FontName.HELVETICA));
inner.setResources(innerResources);
org.apache.pdfbox.pdmodel.PDResources outerResources =
new org.apache.pdfbox.pdmodel.PDResources();
outerResources.put(org.apache.pdfbox.cos.COSName.getPDFName("Fm1"), inner);
outer.setResources(outerResources);
org.apache.pdfbox.pdmodel.PDResources pageResources =
new org.apache.pdfbox.pdmodel.PDResources();
pageResources.put(org.apache.pdfbox.cos.COSName.getPDFName("Fm0"), outer);
page.setResources(pageResources);
ByteArrayOutputStream bos = new ByteArrayOutputStream();
doc.save(bos);
return Base64.getEncoder().encodeToString(bos.toByteArray());
}
}
private static String cyclicFormXObjectsBase64() throws Exception {
try (PDDocument doc = new PDDocument()) {
PDPage page = new PDPage();
doc.addPage(page);
org.apache.pdfbox.pdmodel.graphics.form.PDFormXObject formA =
new org.apache.pdfbox.pdmodel.graphics.form.PDFormXObject(doc);
formA.setBBox(new org.apache.pdfbox.pdmodel.common.PDRectangle(0, 0, 100, 100));
org.apache.pdfbox.pdmodel.graphics.form.PDFormXObject formB =
new org.apache.pdfbox.pdmodel.graphics.form.PDFormXObject(doc);
formB.setBBox(new org.apache.pdfbox.pdmodel.common.PDRectangle(0, 0, 100, 100));
org.apache.pdfbox.pdmodel.PDResources resA =
new org.apache.pdfbox.pdmodel.PDResources();
org.apache.pdfbox.pdmodel.PDResources resB =
new org.apache.pdfbox.pdmodel.PDResources();
resA.put(org.apache.pdfbox.cos.COSName.getPDFName("Self"), formA);
resA.put(org.apache.pdfbox.cos.COSName.getPDFName("Fb"), formB);
resB.put(org.apache.pdfbox.cos.COSName.getPDFName("Fa"), formA);
resB.put(
org.apache.pdfbox.cos.COSName.getPDFName("F1"),
new PDType1Font(Standard14Fonts.FontName.HELVETICA));
formA.setResources(resA);
formB.setResources(resB);
org.apache.pdfbox.pdmodel.PDResources pageResources =
new org.apache.pdfbox.pdmodel.PDResources();
pageResources.put(org.apache.pdfbox.cos.COSName.getPDFName("Fm0"), formA);
page.setResources(pageResources);
ByteArrayOutputStream bos = new ByteArrayOutputStream();
doc.save(bos);
return Base64.getEncoder().encodeToString(bos.toByteArray());
}
}
@Test
void fontReachableOnlyThroughAFormXObjectIsFound() throws Exception {
ResponseEntity<EncodeCharcodesResponse> resp =
controller().encodeCharcodes(manyFontsRequest(formXObjectFontBase64()));
assertThat(resp.getStatusCode().value()).isEqualTo(200);
EncodeCharcodesResponse body = resp.getBody();
assertThat(body).isNotNull();
assertThat(body.getError()).isNull();
assertThat(body.getNote()).contains("Helvetica");
assertThat(body.getCharcodes()).containsExactly((long) 'A');
}
@Test
@org.junit.jupiter.api.Timeout(60)
void cyclicFormXObjectResourcesTerminate() throws Exception {
ResponseEntity<EncodeCharcodesResponse> resp =
controller().encodeCharcodes(manyFontsRequest(cyclicFormXObjectsBase64()));
assertThat(resp.getStatusCode().value()).isEqualTo(200);
EncodeCharcodesResponse body = resp.getBody();
assertThat(body).isNotNull();
assertThat(body.getError()).isNull();
assertThat(body.getCharcodes()).containsExactly((long) 'A');
}
}
@@ -0,0 +1,340 @@
package stirling.software.SPDF.controller.api;
import java.io.ByteArrayInputStream;
import java.io.IOException;
import java.io.InputStream;
import java.nio.charset.StandardCharsets;
import java.nio.file.Files;
import java.nio.file.Path;
import java.nio.file.Paths;
import java.util.HashSet;
import java.util.Set;
import java.util.TreeSet;
import org.apache.pdfbox.Loader;
import org.apache.pdfbox.contentstream.PDFStreamEngine;
import org.apache.pdfbox.contentstream.operator.state.Concatenate;
import org.apache.pdfbox.contentstream.operator.state.Restore;
import org.apache.pdfbox.contentstream.operator.state.Save;
import org.apache.pdfbox.contentstream.operator.state.SetGraphicsStateParameters;
import org.apache.pdfbox.contentstream.operator.state.SetMatrix;
import org.apache.pdfbox.contentstream.operator.text.BeginText;
import org.apache.pdfbox.contentstream.operator.text.EndText;
import org.apache.pdfbox.contentstream.operator.text.SetFontAndSize;
import org.apache.pdfbox.contentstream.operator.text.SetTextHorizontalScaling;
import org.apache.pdfbox.contentstream.operator.text.SetTextLeading;
import org.apache.pdfbox.contentstream.operator.text.SetTextRenderingMode;
import org.apache.pdfbox.contentstream.operator.text.SetTextRise;
import org.apache.pdfbox.contentstream.operator.text.SetWordSpacing;
import org.apache.pdfbox.contentstream.operator.text.ShowText;
import org.apache.pdfbox.cos.COSBase;
import org.apache.pdfbox.cos.COSDictionary;
import org.apache.pdfbox.cos.COSName;
import org.apache.pdfbox.cos.COSStream;
import org.apache.pdfbox.pdmodel.PDDocument;
import org.apache.pdfbox.pdmodel.PDPage;
import org.apache.pdfbox.pdmodel.PDResources;
import org.apache.pdfbox.pdmodel.font.PDFont;
import org.apache.pdfbox.pdmodel.font.PDFontDescriptor;
import org.apache.pdfbox.pdmodel.font.PDType3CharProc;
import org.apache.pdfbox.pdmodel.font.PDType3Font;
import org.junit.jupiter.api.Disabled;
import org.junit.jupiter.api.Test;
/**
* Diagnostic test: enumerate every font referenced by Sample.pdf and dump its subtype, encoding,
* ToUnicode, and embedded font program info. For Type3 fonts also dump CharProcs glyph names and
* the content stream of one glyph (the 'M' if present).
*
* <p>Not a real regression test - run with --tests SamplePdfFontDumpTest -i to see the stdout
* output.
*/
@Disabled(
"Diagnostic probe: dumps Sample.pdf font internals to stdout and asserts nothing. Kept for font debugging; run manually.")
public class SamplePdfFontDumpTest {
private static final Path SAMPLE =
Paths.get(System.getProperty("user.dir"))
.getParent()
.getParent()
.resolve("frontend/editor/public/samples/Sample.pdf");
@Test
public void dumpFonts() throws IOException {
byte[] pdfBytes = Files.readAllBytes(SAMPLE);
try (PDDocument doc = Loader.loadPDF(pdfBytes)) {
int numPages = doc.getNumberOfPages();
System.out.println("Sample.pdf has " + numPages + " pages.");
Set<COSDictionary> seenFontDicts = new HashSet<>();
for (int p = 0; p < numPages; p++) {
PDPage page = doc.getPage(p);
System.out.println("\n=== Page " + p + " ===");
PDResources resources = page.getResources();
if (resources == null) {
System.out.println(" (no resources)");
continue;
}
for (COSName fontName : resources.getFontNames()) {
PDFont font;
try {
font = resources.getFont(fontName);
} catch (IOException e) {
System.out.println(
" Font "
+ fontName.getName()
+ ": failed to load - "
+ e.getMessage());
continue;
}
if (font == null) continue;
COSDictionary dict = font.getCOSObject();
if (!seenFontDicts.add(dict)) {
System.out.println(
" Font " + fontName.getName() + " -> already seen above");
continue;
}
dumpFont(fontName.getName(), font);
}
}
// Scan: for every text-show operation, record per-font (charcode, unicode) pairs.
System.out.println("\n=== All (font, charcode, unicode) seen on page ===");
for (int p = 0; p < numPages; p++) {
PDPage page = doc.getPage(p);
AllCharsScanner scanner = new AllCharsScanner();
scanner.processPage(page);
System.out.println("\nPage " + p + ":");
for (var entry : scanner.perFont.entrySet()) {
PDFont font = entry.getKey();
var seen = entry.getValue();
System.out.println(" Font " + font.getName() + " " + font.getSubType() + ":");
var sortedSeen = new java.util.TreeMap<Integer, String>(seen);
for (var s : sortedSeen.entrySet()) {
System.out.println(
" charcode 0x"
+ Integer.toHexString(s.getKey())
+ " ("
+ s.getKey()
+ ") -> '"
+ s.getValue()
+ "'");
}
}
}
// Confirm font.encode() works for Type3 fonts.
System.out.println("\n=== Can we encode existing chars in F27/F28? ===");
PDPage page0 = doc.getPage(0);
PDResources r0 = page0.getResources();
for (String fname : new String[] {"F27", "F28"}) {
PDFont f = r0.getFont(COSName.getPDFName(fname));
if (f == null) {
System.out.println(" " + fname + ": NOT FOUND on page 0");
continue;
}
System.out.println(" " + fname + ": " + f.getClass().getSimpleName());
for (String ch : new String[] {"M", "0", "1", "+", "Z", "a"}) {
try {
byte[] enc = f.encode(ch);
StringBuilder sb = new StringBuilder();
for (byte b : enc) sb.append(String.format("%02X ", b & 0xff));
System.out.println(
" encode('" + ch + "') -> [" + sb.toString().trim() + "]");
} catch (Exception e) {
System.out.println(
" encode('"
+ ch
+ "') FAILED: "
+ e.getClass().getSimpleName()
+ " "
+ e.getMessage());
}
}
}
// Dump page 0 content stream so we can see how "10M+" is composed.
System.out.println("\n=== Page 0 RAW content stream (first 4kb) ===");
try (InputStream is = doc.getPage(0).getContents()) {
byte[] bytes = is.readAllBytes();
System.out.println("Total content stream size: " + bytes.length + " bytes");
String asStr = new String(bytes, StandardCharsets.ISO_8859_1);
int idx = asStr.indexOf("F27");
if (idx >= 0) {
int start = Math.max(0, idx - 100);
int end = Math.min(asStr.length(), idx + 2500);
System.out.println("--- F27 context ---");
System.out.println(asStr.substring(start, end));
System.out.println("---");
}
int idx2 = asStr.indexOf("F28");
if (idx2 >= 0) {
int start = Math.max(0, idx2 - 200);
int end = Math.min(asStr.length(), idx2 + 600);
System.out.println("--- F28 context ---");
System.out.println(asStr.substring(start, end));
System.out.println("---");
}
}
// Dump a CharProc for each font's first non-zero glyph, with focus on any 'M' or "0".
System.out.println("\n=== Sample CharProc dumps for Type3 fonts ===");
Set<COSDictionary> printed = new HashSet<>();
for (int p = 0; p < numPages; p++) {
PDPage page = doc.getPage(p);
PDResources resources = page.getResources();
if (resources == null) continue;
for (COSName fn : resources.getFontNames()) {
PDFont font = resources.getFont(fn);
if (!(font instanceof PDType3Font)) continue;
if (!printed.add(font.getCOSObject())) continue;
PDType3Font t3 = (PDType3Font) font;
// Iterate charcodes 0..255 looking for any that map to 'M' or '0' or '+'.
for (int cc = 0; cc < 256; cc++) {
String u = null;
try {
u = t3.toUnicode(cc);
} catch (Exception e) {
/* */
}
if (u == null) continue;
if (u.equals("M") || u.equals("0") || u.equals("+") || u.equals("1")) {
System.out.println(
"Page "
+ p
+ " font '"
+ fn.getName()
+ "' charcode "
+ cc
+ " maps to '"
+ u
+ "':");
dumpType3Glyph(t3, cc);
}
}
}
}
}
}
private void dumpFont(String resourceName, PDFont font) {
COSDictionary dict = font.getCOSObject();
String subtype = dict.getNameAsString(COSName.SUBTYPE);
String baseFont = dict.getNameAsString(COSName.BASE_FONT);
boolean hasEncoding = dict.containsKey(COSName.ENCODING);
boolean hasToUnicode = dict.containsKey(COSName.TO_UNICODE);
PDFontDescriptor descriptor = font.getFontDescriptor();
boolean hasEmbedded = false;
String embeddedKind = "none";
if (descriptor != null) {
COSDictionary dDict = descriptor.getCOSObject();
if (dDict.containsKey(COSName.FONT_FILE)) {
hasEmbedded = true;
embeddedKind = "FontFile (Type1)";
} else if (dDict.containsKey(COSName.FONT_FILE2)) {
hasEmbedded = true;
embeddedKind = "FontFile2 (TrueType)";
} else if (dDict.containsKey(COSName.FONT_FILE3)) {
hasEmbedded = true;
COSBase ff3 = dDict.getDictionaryObject(COSName.FONT_FILE3);
if (ff3 instanceof COSStream) {
String ff3Subtype = ((COSStream) ff3).getNameAsString(COSName.SUBTYPE);
embeddedKind = "FontFile3 (" + ff3Subtype + ")";
} else {
embeddedKind = "FontFile3";
}
}
}
System.out.println(
" Font resource '"
+ resourceName
+ "': base='"
+ baseFont
+ "' subtype="
+ subtype
+ " hasEncoding="
+ hasEncoding
+ " hasToUnicode="
+ hasToUnicode
+ " embedded="
+ hasEmbedded
+ " ("
+ embeddedKind
+ ")");
if (font instanceof PDType3Font) {
PDType3Font t3 = (PDType3Font) font;
COSDictionary charProcs = t3.getCharProcs();
int count = charProcs == null ? 0 : charProcs.size();
System.out.println(" Type3 CharProcs count = " + count);
if (charProcs != null) {
TreeSet<String> names = new TreeSet<>();
for (COSName k : charProcs.keySet()) names.add(k.getName());
System.out.println(" glyph names: " + names);
}
}
}
private void dumpType3Glyph(PDType3Font font, int charcode) throws IOException {
String name = font.getEncoding() != null ? font.getEncoding().getName(charcode) : null;
System.out.println(" Type3 charcode " + charcode + " -> glyph name '" + name + "'");
PDType3CharProc proc = font.getCharProc(charcode);
if (proc == null) {
System.out.println(" (no CharProc for that charcode)");
return;
}
COSStream stream = proc.getCOSObject();
byte[] raw;
try (InputStream is = stream.createInputStream()) {
raw = is.readAllBytes();
}
System.out.println(" CharProc content stream (" + raw.length + " bytes):");
System.out.println("---");
System.out.println(new String(raw, StandardCharsets.ISO_8859_1));
System.out.println("---");
}
/** Records every (font, charcode -> unicode) tuple seen on a page. */
static final class AllCharsScanner extends PDFStreamEngine {
final java.util.LinkedHashMap<PDFont, java.util.Map<Integer, String>> perFont =
new java.util.LinkedHashMap<>();
AllCharsScanner() {
addOperator(new BeginText(this));
addOperator(new EndText(this));
addOperator(new SetFontAndSize(this));
addOperator(new SetTextHorizontalScaling(this));
addOperator(new SetTextLeading(this));
addOperator(new SetTextRenderingMode(this));
addOperator(new SetTextRise(this));
addOperator(new SetWordSpacing(this));
addOperator(new SetMatrix(this));
addOperator(new Save(this));
addOperator(new Restore(this));
addOperator(new Concatenate(this));
addOperator(new SetGraphicsStateParameters(this));
addOperator(new ShowText(this));
}
@Override
protected void showText(byte[] string) throws IOException {
PDFont font = getGraphicsState().getTextState().getFont();
if (font == null) return;
var seen = perFont.computeIfAbsent(font, k -> new java.util.LinkedHashMap<>());
ByteArrayInputStream in = new ByteArrayInputStream(string);
while (in.available() > 0) {
int code;
try {
code = font.readCode(in);
} catch (IOException e) {
break;
}
String u;
try {
u = font.toUnicode(code);
} catch (RuntimeException e) {
u = null;
}
seen.putIfAbsent(code, u);
}
}
}
}
@@ -485,9 +485,9 @@ class PdfJsonFontServiceMoreTest {
class DetectExtra {
@Test
@DisplayName("detectFontFlavor recognises ttcf as cff and otf via OTTO")
@DisplayName("detectFontFlavor rejects ttcf collections and recognises otf via OTTO")
void detectFlavorExtra() {
assertEquals("cff", service.detectFontFlavor(new byte[] {0x74, 0x74, 0x63, 0x66}));
assertNull(service.detectFontFlavor(new byte[] {0x74, 0x74, 0x63, 0x66}));
List<byte[]> otfVariants = List.of(new byte[] {0x4F, 0x54, 0x54, 0x4F});
for (byte[] otf : otfVariants) {
assertEquals("otf", service.detectFontFlavor(otf));
@@ -57,10 +57,9 @@ class PdfJsonFontServiceTest {
}
@Test
void detectFontFlavor_cffSignature_returnsCff() {
// 0x74746366 = "ttcf"
byte[] cff = {0x74, 0x74, 0x63, 0x66};
assertEquals("cff", service.detectFontFlavor(cff));
void detectFontFlavor_ttcSignature_returnsNull() {
byte[] ttc = {0x74, 0x74, 0x63, 0x66};
assertNull(service.detectFontFlavor(ttc));
}
@Test
@@ -94,9 +93,9 @@ class PdfJsonFontServiceTest {
}
@Test
void detectTrueTypeFormat_cffSignature_returnsCff() {
byte[] cff = {0x74, 0x74, 0x63, 0x66};
assertEquals("cff", service.detectTrueTypeFormat(cff));
void detectTrueTypeFormat_ttcSignature_returnsNull() {
byte[] ttc = {0x74, 0x74, 0x63, 0x66};
assertNull(service.detectTrueTypeFormat(ttc));
}
@Test
@@ -24,22 +24,6 @@ import tools.jackson.databind.node.ObjectNode;
/**
* Outbound calls from a self-hosted instance to its linked SaaS backend (combined-billing "Mode
* A").
*
* <p>Calls:
*
* <ul>
* <li>{@link #register} — relays the admin's short-lived Supabase JWT to {@code POST
* /api/v1/account-link/register}; the SaaS side mints + returns a device credential.
* <li>{@link #fetchEntitlement} — authenticates with the stored device credential against {@code
* GET /api/v1/instance/entitlement}; what the local gate consults.
* <li>{@link #reportUsage} — daily usage sync ({@code POST /api/v1/instance/sync}); reports
* cumulative units and returns the refreshed entitlement.
* <li>{@link #revokeSelf} — self-revokes the credential on local unlink ({@code POST
* /api/v1/instance/revoke-self}).
* </ul>
*
* <p>Uses {@code java.net.http.HttpClient} (the established self-hosted outbound pattern; see
* {@code AiEngineClient}); base URL + client are injectable so tests can stub SaaS.
*/
@Slf4j
@Service
@@ -72,13 +56,7 @@ public class AccountLinkClient {
this.httpClient = httpClient;
}
/** The device credential a successful {@link #register} returns. */
public record RegisterResult(String deviceId, String deviceSecret, Long teamId) {}
/**
* A non-2xx reply from the SaaS account-link API. Carries the upstream status so the caller can
* map auth failures (401/403) through rather than masking everything as a 502.
*/
/** A non-2xx reply from the SaaS account-link API. */
public static class UpstreamException extends IOException {
private final int status;
@@ -92,11 +70,7 @@ public class AccountLinkClient {
}
}
/**
* Authoritative deny (401/403) — the device credential is revoked or invalid. Unlike a
* transport/server failure (which returns {@code null} and fails open), the cache must BLOCK on
* this. Unchecked so it propagates through {@link #fetchEntitlement}'s transport try/catch.
*/
/** Authoritative deny (401/403) — the device credential is revoked or invalid. */
public static final class RevokedException extends RuntimeException {
private final int status;
@@ -110,46 +84,142 @@ public class AccountLinkClient {
}
}
/** What the SaaS side hands back when it records a connect handshake. */
public record ConnectRequestResult(
String requestId, int expiresInSeconds, String authorizeUrl) {}
public enum ConnectClaimOutcome {
/** Approved and collected; the credential fields are populated. */
GRANTED,
/** A re-authentication was approved. */
CONFIRMED,
/** No human decision yet. */
PENDING,
/** Declined, expired or already used. */
REJECTED,
/** SaaS unreachable or erroring. */
UNAVAILABLE
}
public record ConnectClaimResult(
ConnectClaimOutcome outcome, String deviceId, String deviceSecret, Long teamId) {
static ConnectClaimResult of(ConnectClaimOutcome outcome) {
return new ConnectClaimResult(outcome, null, null, null);
}
}
/** Opens a connect handshake. */
public ConnectRequestResult connectRequest(
String name, String callbackUrl, String nonce, String claimSecret) throws IOException {
return connectRequest(name, callbackUrl, nonce, claimSecret, null);
}
/**
* Relays the admin Supabase JWT to the SaaS register endpoint and returns the minted
* credential.
*
* @throws IOException on transport failure or a non-2xx response (caller surfaces to the
* admin).
* As {@link #connectRequest}, but presenting an existing device credential so the SaaS side
* treats this as a re-authentication and pins the handshake to the team we already belong to.
*/
public RegisterResult register(String supabaseJwt, String instanceName) throws IOException {
String body =
instanceName == null || instanceName.isBlank()
? "{}"
: "{\"name\":" + mapper.writeValueAsString(instanceName) + "}";
HttpRequest request =
public ConnectRequestResult connectRequest(
String name,
String callbackUrl,
String nonce,
String claimSecret,
DeviceCredential credential)
throws IOException {
ObjectNode root = mapper.createObjectNode();
if (name != null && !name.isBlank()) {
root.put("name", name);
}
root.put("callbackUrl", callbackUrl);
root.put("nonce", nonce);
root.put("claimSecret", claimSecret);
HttpRequest.Builder builder =
HttpRequest.newBuilder()
.uri(uri("/api/v1/account-link/register"))
.header("Authorization", "Bearer " + supabaseJwt)
.uri(uri("/api/v1/account-link/connect/request"))
.header("Content-Type", "application/json")
.header("Accept", "application/json")
.timeout(timeout())
.POST(HttpRequest.BodyPublishers.ofString(body))
.build();
.POST(HttpRequest.BodyPublishers.ofString(mapper.writeValueAsString(root)));
if (credential != null) {
builder.header(HEADER_DEVICE_ID, credential.getDeviceId())
.header(HEADER_DEVICE_SECRET, credential.getDeviceSecret());
}
HttpResponse<String> response = send(request);
HttpResponse<String> response = send(builder.build());
if (response.statusCode() / 100 != 2) {
throw new UpstreamException(response.statusCode(), response.body());
}
JsonNode root = mapper.readTree(response.body());
String deviceId = text(root, "deviceId");
String deviceSecret = text(root, "deviceSecret");
if (deviceId == null || deviceSecret == null) {
throw new IOException("SaaS register response missing deviceId/deviceSecret");
JsonNode body = mapper.readTree(response.body());
String requestId = text(body, "requestId");
if (requestId == null) {
throw new IOException("SaaS connect response missing requestId");
}
String authorizeUrl = text(body, "authorizeUrl");
if (authorizeUrl == null || !isAbsoluteHttpUrl(authorizeUrl)) {
throw new IOException("SaaS connect response carried no usable authorizeUrl");
}
return new ConnectRequestResult(requestId, body.path("expiresIn").asInt(0), authorizeUrl);
}
/**
* Collects the device credential for an approved handshake, proving possession of the claim
* secret.
*/
public ConnectClaimResult connectClaim(String requestId, String claimSecret) {
HttpResponse<String> response;
try {
ObjectNode root = mapper.createObjectNode();
root.put("requestId", requestId);
root.put("claimSecret", claimSecret);
HttpRequest request =
HttpRequest.newBuilder()
.uri(uri("/api/v1/account-link/connect/claim"))
.header("Content-Type", "application/json")
.header("Accept", "application/json")
.timeout(timeout())
.POST(
HttpRequest.BodyPublishers.ofString(
mapper.writeValueAsString(root)))
.build();
response = send(request);
} catch (Exception e) {
log.debug("Connect claim failed (transport): {}", e.getMessage());
return ConnectClaimResult.of(ConnectClaimOutcome.UNAVAILABLE);
}
int status = response.statusCode();
if (status == 202) {
return ConnectClaimResult.of(ConnectClaimOutcome.PENDING);
}
if (status >= 500 && status <= 599) {
return ConnectClaimResult.of(ConnectClaimOutcome.UNAVAILABLE);
}
if (status < 200 || status > 299) {
return ConnectClaimResult.of(ConnectClaimOutcome.REJECTED);
}
try {
JsonNode body = mapper.readTree(response.body());
Long teamId = body.hasNonNull("teamId") ? body.get("teamId").asLong() : null;
// A re-authentication says so explicitly and carries no credential, so an absent
// credential is only an error when we were expecting one.
if ("confirmed".equals(text(body, "status"))) {
return new ConnectClaimResult(ConnectClaimOutcome.CONFIRMED, null, null, teamId);
}
String deviceId = text(body, "deviceId");
String deviceSecret = text(body, "deviceSecret");
if (deviceId == null || deviceSecret == null) {
log.warn("Connect claim succeeded but the reply carried no credential");
return ConnectClaimResult.of(ConnectClaimOutcome.REJECTED);
}
return new ConnectClaimResult(
ConnectClaimOutcome.GRANTED, deviceId, deviceSecret, teamId);
} catch (RuntimeException e) {
log.debug("Connect claim parse failed: {}", e.getMessage());
return ConnectClaimResult.of(ConnectClaimOutcome.REJECTED);
}
Long teamId = root.hasNonNull("teamId") ? root.get("teamId").asLong() : null;
return new RegisterResult(deviceId, deviceSecret, teamId);
}
/**
* Revokes this instance's own credential on the SaaS side, authenticated by that credential.
* Best-effort: returns {@code false} if SaaS is unreachable or rejects, so the caller (local
* unlink) can still clear locally and log the orphan for follow-up. Idempotent on SaaS.
*/
public boolean revokeSelf(String deviceId, String deviceSecret) {
try {
@@ -174,17 +244,7 @@ public class AccountLinkClient {
}
}
/**
* Fetches the current entitlement using the stored device credential. Three outcomes:
*
* <ul>
* <li>2xx → the parsed snapshot.
* <li>401/403 → {@link RevokedException} (authoritative deny — revoked/invalid credential);
* the caller must BLOCK, not fail open.
* <li>transport failure, other non-2xx (e.g. 5xx), or a malformed body → {@code null}
* ("unknown" — the caller fails open).
* </ul>
*/
/** Fetches the current entitlement using the stored device credential. */
public InstanceEntitlement fetchEntitlement(String deviceId, String deviceSecret) {
HttpResponse<String> response;
try {
@@ -224,9 +284,6 @@ public class AccountLinkClient {
/**
* Reports the period's cumulative per-category units to {@code POST /api/v1/instance/sync} and
* returns the fresh entitlement in the same reply — one round-trip both reports and refreshes.
* SaaS bills the delta against its last-seen cumulative, so resending the same totals is
* idempotent. Same three outcomes as {@link #fetchEntitlement}; on {@code null} the caller must
* not advance its last-synced markers so the usage retries next sync.
*/
public InstanceEntitlement reportUsage(
String deviceId,
@@ -360,4 +417,19 @@ public class AccountLinkClient {
private static String text(JsonNode node, String field) {
return node.hasNonNull(field) ? node.get(field).asText() : null;
}
/** Absolute http(s) with a host. */
static boolean isAbsoluteHttpUrl(String candidate) {
try {
URI uri = URI.create(candidate.strip());
String scheme = uri.getScheme();
return uri.isAbsolute()
&& scheme != null
&& ("http".equalsIgnoreCase(scheme) || "https".equalsIgnoreCase(scheme))
&& uri.getHost() != null
&& !uri.getHost().isBlank();
} catch (IllegalArgumentException e) {
return false;
}
}
}
@@ -16,21 +16,11 @@ import org.springframework.web.bind.annotation.RestController;
import io.swagger.v3.oas.annotations.Hidden;
import jakarta.servlet.http.HttpServletRequest;
import lombok.extern.slf4j.Slf4j;
/**
* Same-origin account-link surface on the self-hosted instance (combined-billing "Mode A").
*
* <p>The portal (served from this same origin, admin authenticated by the existing self-hosted
* security chain) calls these. {@code POST /link} relays the admin's Supabase JWT to the SaaS
* backend, which mints + returns a device credential we store locally. {@code GET /status} backs
* the portal's link card; {@code GET /usage} exposes locally-accrued unsynced usage the portal adds
* to SaaS-synced spend; {@code POST /sync-now} forces an immediate usage sync (ops "reconcile now"
* / test aid).
*
* <p>Admin-only, {@code @Profile("!saas")}, gated behind {@code
* stirling.billing.account-link.enabled} — off → bean absent → 404.
*/
/** Same-origin account-link surface on the self-hosted instance (combined billing). */
@Slf4j
@Hidden
@RestController
@@ -41,51 +31,110 @@ import lombok.extern.slf4j.Slf4j;
public class AccountLinkController {
private final AccountLinkService service;
private final ConnectService connectService;
private final LocalUsageService localUsageService;
// Present only when metering is on (its own flag); absent → /sync-now reports 409.
private final ObjectProvider<UsageSyncService> syncServiceProvider;
public AccountLinkController(
AccountLinkService service,
ConnectService connectService,
LocalUsageService localUsageService,
ObjectProvider<UsageSyncService> syncServiceProvider) {
this.service = service;
this.connectService = connectService;
this.localUsageService = localUsageService;
this.syncServiceProvider = syncServiceProvider;
}
/** {@code supabaseJwt} is the admin's short-lived token the portal already holds. */
public record LinkRequest(String supabaseJwt, String name) {}
/** {@code callbackUrl} is the portal telling us where its own callback route lives. */
public record ConnectStartRequest(String name, String callbackUrl) {}
@PostMapping("/link")
public ResponseEntity<?> link(@RequestBody LinkRequest req) {
if (req == null || req.supabaseJwt() == null || req.supabaseJwt().isBlank()) {
return ResponseEntity.badRequest()
.body(java.util.Map.of("error", "supabaseJwt is required"));
}
/** {@code nonce} comes from the callback fragment the approval page redirected to. */
public record ConnectCompleteRequest(String nonce) {}
/**
* Opens a browser-mediated link handshake and returns the approval URL to send the admin to.
*/
@PostMapping("/connect/start")
public ResponseEntity<?> connectStart(
@RequestBody(required = false) ConnectStartRequest req, HttpServletRequest http) {
try {
return ResponseEntity.ok(service.link(req.supabaseJwt(), req.name()));
return ResponseEntity.ok(
connectService.start(req != null ? req.name() : null, callbackHint(req, http)));
} catch (AccountLinkClient.UpstreamException e) {
// Auth failures are the admin's token, not a gateway fault: surface 401/403 as-is so
// the portal can prompt a re-sign-in. Anything else upstream → 502. Don't echo the
// raw upstream body back to the browser.
HttpStatus status =
e.status() == HttpStatus.UNAUTHORIZED.value()
|| e.status() == HttpStatus.FORBIDDEN.value()
? HttpStatus.valueOf(e.status())
: HttpStatus.BAD_GATEWAY;
log.warn("Account-link register rejected upstream: HTTP {}", e.status());
return ResponseEntity.status(status).body(java.util.Map.of("error", "LINK_FAILED"));
} catch (IOException e) {
// Don't echo e.getMessage() to the browser: a DNS/connection/TLS failure can carry the
// configured SaaS host/IP. Log it server-side; return the same opaque body the
// UpstreamException branch does.
log.warn("Account-link failed (transport): {}", e.getMessage());
log.warn("Account-link connect rejected upstream: HTTP {}", e.status());
return ResponseEntity.status(HttpStatus.BAD_GATEWAY)
.body(java.util.Map.of("error", "LINK_FAILED"));
.body(java.util.Map.of("error", "CONNECT_FAILED"));
} catch (IOException e) {
// Same reasoning as /link: a transport message can carry the configured SaaS host.
log.warn("Account-link connect failed (transport): {}", e.getMessage());
return ResponseEntity.status(HttpStatus.BAD_GATEWAY)
.body(java.util.Map.of("error", "CONNECT_FAILED"));
}
}
/** Re-establishes the admin's SaaS session for a server that is already linked. */
@PostMapping("/connect/reauth")
public ResponseEntity<?> connectReauth(
@RequestBody(required = false) ConnectStartRequest req, HttpServletRequest http) {
try {
return ResponseEntity.ok(connectService.startReauth(callbackHint(req, http)));
} catch (AccountLinkClient.UpstreamException e) {
log.warn("Account-link reauth rejected upstream: HTTP {}", e.status());
return ResponseEntity.status(HttpStatus.BAD_GATEWAY)
.body(java.util.Map.of("error", "CONNECT_FAILED"));
} catch (IOException e) {
log.warn("Account-link reauth failed: {}", e.getMessage());
return ResponseEntity.status(HttpStatus.BAD_GATEWAY)
.body(java.util.Map.of("error", "CONNECT_FAILED"));
}
}
/** Called by the callback page with the nonce it found in the fragment. */
@PostMapping("/connect/complete")
public ResponseEntity<ConnectService.ConnectStatus> connectComplete(
@RequestBody(required = false) ConnectCompleteRequest req) {
return ResponseEntity.ok(connectService.complete(req != null ? req.nonce() : null));
}
/** Everything we know about where the admin's browser is, for the callback. */
private static ConnectService.CallbackHint callbackHint(
ConnectStartRequest req, HttpServletRequest http) {
return new ConnectService.CallbackHint(
req != null ? req.callbackUrl() : null, http.getHeader("Origin"), baseUrlOf(http));
}
/**
* This instance's base URL as the browser reached it, including any context path so a subpath
* deployment builds a callback that actually resolves.
*/
private static String baseUrlOf(HttpServletRequest request) {
String forwardedProto = firstHop(request.getHeader("X-Forwarded-Proto"));
String forwardedHost = firstHop(request.getHeader("X-Forwarded-Host"));
String scheme = forwardedProto != null ? forwardedProto : request.getScheme();
String hostPort;
if (forwardedHost != null) {
hostPort = forwardedHost;
} else {
int port = request.getServerPort();
boolean defaultPort =
("http".equals(scheme) && port == 80)
|| ("https".equals(scheme) && port == 443);
hostPort = defaultPort ? request.getServerName() : request.getServerName() + ":" + port;
}
String context = request.getContextPath() == null ? "" : request.getContextPath();
return scheme + "://" + hostPort + context;
}
private static String firstHop(String headerValue) {
if (headerValue == null || headerValue.isBlank()) {
return null;
}
String first = headerValue.split(",")[0].strip();
return first.isEmpty() ? null : first;
}
@GetMapping("/status")
public ResponseEntity<AccountLinkService.LinkStatus> status() {
return ResponseEntity.ok(service.status());
@@ -106,12 +155,7 @@ public class AccountLinkController {
return ResponseEntity.ok(localUsageService.currentPeriodUnsynced());
}
/**
* Forces an immediate usage sync to SaaS — the same work the daily scheduler does. An admin
* "reconcile now" action (and a test aid so you don't wait on the scheduler). Idempotent:
* re-reports the current cumulative, so a repeat trigger bills nothing. {@code 204} once run;
* {@code 409} when metering is off (the sync bean is absent).
*/
/** Forces an immediate usage sync to SaaS — the same work the daily scheduler does. */
@PostMapping("/sync-now")
public ResponseEntity<Void> syncNow() {
UsageSyncService sync = syncServiceProvider.getIfAvailable();
@@ -8,29 +8,17 @@ import org.springframework.stereotype.Component;
import lombok.Getter;
import lombok.Setter;
/**
* Self-hosted side of combined-billing "Mode A" (connected self-hosted).
*
* <p>Binds the {@code stirling.billing.account-link.*} keys. {@link #enabled} mirrors the same flag
* the gated beans test with {@code @ConditionalOnProperty}; it is kept here only so non-conditional
* code (e.g. the gate's flag-off short-circuit, exposed status) can read it. The whole feature is
* <b>off by default</b> and <b>dark</b> — when off nothing gates and the link endpoints 404.
*/
/** Self-hosted side of combined billing: this instance bills through a linked SaaS team. */
@Getter
@Setter
@Component
@ConfigurationProperties(prefix = "stirling.billing.account-link")
public class AccountLinkProperties {
/** Master switch. When {@code false} (default) the feature is fully inert. */
/** Master switch. */
private boolean enabled = false;
/**
* Base URL of the SaaS backend this instance links to (register + entitlement live there).
*
* <p>STUB: defaults to the public cloud host; an operator overrides it for staging. There is no
* existing SaaS-base-url property in the self-hosted profile, so this is introduced here.
*/
/** Base URL of the SaaS backend this instance links to (register + entitlement live there). */
private String saasBaseUrl = "https://stirling.com/app";
/** Cached entitlement is reused for this long before a refresh is attempted. */
@@ -39,20 +27,18 @@ public class AccountLinkProperties {
/** Connect/read timeout for the outbound SaaS calls. */
private int requestTimeoutSeconds = 10;
/** Phase 2 usage metering + daily sync. Keyed under {@code …account-link.metering.*}. */
/** Phase 2 usage metering + daily sync. */
private final Metering metering = new Metering();
/**
* Dedicated billing switch, <b>separate</b> from {@link #enabled} so the link plumbing can be
* enabled (e.g. to test linking) without ever turning on real usage metering, reporting, or cap
* enforcement. Both default off; metering requires the master flag too. This is the production
* safety key — flipping it on is what actually bills linked instances.
* Separate from {@link #enabled} so linking can be exercised without billing anything. Both
* default off, and metering needs the master flag as well.
*/
@Getter
@Setter
public static class Metering {
/** Turns on usage metering, the daily sync, and cap enforcement. Default off. */
/** Turns on usage metering, the daily sync, and cap enforcement. */
private boolean enabled = false;
/**
@@ -65,12 +51,7 @@ public class AccountLinkProperties {
*/
private int graceDays = 3;
/**
* Dedup window for identical input sets. A re-run of the same inputs within this window is
* treated as workflow chaining and not re-charged; the same inputs run again after it are
* billed afresh. Mirrors the cloud's {@code payg.lineage.workflow-window} so the same op
* costs the same on the instance and in the cloud.
*/
/** Dedup window for identical input sets. */
private Duration workflowWindow = Duration.ofMinutes(5);
}
}
@@ -1,6 +1,5 @@
package stirling.software.proprietary.accountlink;
import java.io.IOException;
import java.util.Optional;
import org.springframework.boot.autoconfigure.condition.ConditionalOnProperty;
@@ -9,13 +8,7 @@ import org.springframework.stereotype.Service;
import lombok.extern.slf4j.Slf4j;
/**
* Linking orchestrator (self-hosted side of combined-billing "Mode A").
*
* <p>{@link #link} is the same-origin action the portal triggers: it relays the admin's Supabase
* JWT to the SaaS register endpoint, then persists the returned device credential secure-at-rest.
* The credential — not the JWT — authenticates all later unattended entitlement calls.
*/
/** Linking orchestrator (self-hosted side of combined billing). */
@Slf4j
@Service
@Profile("!saas")
@@ -38,24 +31,9 @@ public class AccountLinkService {
/** Status of this instance's link, for the portal's "Account link" card. */
public record LinkStatus(boolean linked, String deviceId, Long teamId, String linkedAt) {}
/**
* Registers this instance with the SaaS team behind {@code supabaseJwt} and stores the
* credential.
*
* @throws IOException if the SaaS register call fails (surfaced to the admin as a link error).
*/
public LinkStatus link(String supabaseJwt, String instanceName) throws IOException {
AccountLinkClient.RegisterResult result = client.register(supabaseJwt, instanceName);
credentialStore.save(result.deviceId(), result.deviceSecret(), result.teamId());
entitlementCache.invalidate();
log.info("Account-link: instance linked to team {}", result.teamId());
return status();
}
/**
* Unlinks this instance — best-effort tells SaaS to revoke first (so the row gets {@code
* revoked_at} set), then clears locally regardless. If SaaS is unreachable the local clear
* still proceeds (admin's intent must win); the orphan row can be revoked from the portal.
* revoked_at} set), then clears locally regardless.
*/
public void unlink() {
credentialStore
@@ -12,7 +12,7 @@ import lombok.NoArgsConstructor;
import lombok.Setter;
/**
* Singleton row holding this instance's daily-sync bookkeeping (combined-billing "Mode A").
* Singleton row holding this instance's daily-sync bookkeeping (combined billing).
*
* <p>{@link #lastSyncSeq} is reserved (incremented + persisted) <em>before</em> each report so it
* is strictly monotonic across restarts and partial failures — SaaS dedups replays by comparing it,
@@ -2,5 +2,5 @@ package stirling.software.proprietary.accountlink;
import org.springframework.data.jpa.repository.JpaRepository;
/** Persistence for the singleton {@link AccountLinkSyncState} (combined-billing "Mode A"). */
/** Persistence for the singleton {@link AccountLinkSyncState} (combined billing). */
public interface AccountLinkSyncStateRepository extends JpaRepository<AccountLinkSyncState, Long> {}
@@ -0,0 +1,276 @@
package stirling.software.proprietary.accountlink;
import java.io.IOException;
import java.net.URI;
import java.net.URISyntaxException;
import java.nio.charset.StandardCharsets;
import java.security.MessageDigest;
import java.security.SecureRandom;
import java.time.Duration;
import java.time.LocalDateTime;
import java.util.Base64;
import java.util.Locale;
import java.util.Optional;
import org.springframework.boot.autoconfigure.condition.ConditionalOnProperty;
import org.springframework.context.annotation.Profile;
import org.springframework.stereotype.Service;
import org.springframework.transaction.annotation.Transactional;
import lombok.extern.slf4j.Slf4j;
import stirling.software.common.model.ApplicationProperties;
/** Browser-mediated account linking, instance side. */
@Slf4j
@Service
@Profile("!saas")
@ConditionalOnProperty(name = "stirling.billing.account-link.enabled", havingValue = "true")
public class ConnectService {
/** Frontend route that consumes the callback fragment. */
static final String CALLBACK_PATH = "/account-link/callback";
private static final int SECRET_BYTES = 32;
private final AccountLinkClient client;
private final ConnectStateRepository stateRepo;
private final DeviceCredentialStore credentialStore;
private final EntitlementCache entitlementCache;
private final ApplicationProperties applicationProperties;
private final SecureRandom random = new SecureRandom();
public ConnectService(
AccountLinkClient client,
ConnectStateRepository stateRepo,
DeviceCredentialStore credentialStore,
EntitlementCache entitlementCache,
ApplicationProperties applicationProperties) {
this.client = client;
this.stateRepo = stateRepo;
this.credentialStore = credentialStore;
this.entitlementCache = entitlementCache;
this.applicationProperties = applicationProperties;
}
public enum Phase {
/** Nothing in flight and not linked. */
NONE,
/** A handshake is open, waiting for a leader to approve it on the SaaS site. */
PENDING,
/** Linked. */
LINKED,
/** The handshake outlived its window; start a new one. */
EXPIRED,
/** Declined or already used; start a new one. */
REJECTED,
/** SaaS could not be reached; the handshake is still valid and can be retried. */
UNAVAILABLE
}
/** What the portal renders. */
public record ConnectStatus(
Phase phase, String authorizeUrl, Long secondsRemaining, Long teamId) {
static ConnectStatus of(Phase phase) {
return new ConnectStatus(phase, null, null, null);
}
}
/** Everything we know about where the admin's browser actually is, in decreasing authority. */
public record CallbackHint(
String requestedCallbackUrl, String browserOrigin, String derivedBaseUrl) {}
/** Opens a handshake and returns where to send the admin. */
@Transactional
public ConnectStatus start(String name, CallbackHint hint) throws IOException {
if (credentialStore.isLinked()) {
return status();
}
return open(name, hint, null);
}
/**
* Opens a handshake that only re-establishes the admin's browser session, for an instance that
* is already linked.
*/
@Transactional
public ConnectStatus startReauth(CallbackHint hint) throws IOException {
DeviceCredential credential =
credentialStore
.get()
.orElseThrow(
() ->
new IOException(
"This server is not linked, so there is no session"
+ " to re-establish"));
return open(credential.getDeviceId(), hint, credential);
}
private ConnectStatus open(String name, CallbackHint hint, DeviceCredential credential)
throws IOException {
String callbackUrl = resolveCallbackUrl(hint);
if (callbackUrl == null) {
throw new IOException(
"Cannot determine where to send the admin back to; set system.frontendUrl");
}
String nonce = randomSecret();
String claimSecret = randomSecret();
AccountLinkClient.ConnectRequestResult created =
client.connectRequest(name, callbackUrl, nonce, claimSecret, credential);
LocalDateTime now = LocalDateTime.now();
ConnectState state = new ConnectState();
state.setId(ConnectState.SINGLETON_ID);
state.setRequestId(created.requestId());
state.setNonce(nonce);
state.setClaimSecret(claimSecret);
state.setCallbackUrl(callbackUrl);
state.setAuthorizeUrl(created.authorizeUrl());
state.setCreatedAt(now);
state.setExpiresAt(
now.plusSeconds(created.expiresInSeconds() > 0 ? created.expiresInSeconds() : 900));
stateRepo.save(state);
log.info("Account-link connect: handshake {} opened", created.requestId());
return pendingStatus(state, now);
}
/** Finishes a handshake from the callback the approval page redirected to. */
@Transactional
public ConnectStatus complete(String nonce) {
Optional<ConnectState> found = stateRepo.findById(ConnectState.SINGLETON_ID);
if (found.isEmpty()) {
// Already finished (a double-submitted callback) or never started.
return status();
}
ConnectState state = found.get();
if (state.isExpired(LocalDateTime.now())) {
stateRepo.delete(state);
return ConnectStatus.of(Phase.EXPIRED);
}
if (nonce == null || !nonceMatches(nonce, state.getNonce())) {
log.warn(
"Account-link connect: callback for handshake {} had a bad nonce",
state.getRequestId());
return ConnectStatus.of(Phase.REJECTED);
}
AccountLinkClient.ConnectClaimResult claim =
client.connectClaim(state.getRequestId(), state.getClaimSecret());
return switch (claim.outcome()) {
case GRANTED -> {
credentialStore.save(claim.deviceId(), claim.deviceSecret(), claim.teamId());
entitlementCache.invalidate();
stateRepo.delete(state);
log.info("Account-link connect: linked to team {}", claim.teamId());
yield new ConnectStatus(Phase.LINKED, null, null, claim.teamId());
}
case CONFIRMED -> {
stateRepo.delete(state);
log.info(
"Account-link connect: session re-established for team {}", claim.teamId());
yield new ConnectStatus(Phase.LINKED, null, null, claim.teamId());
}
case PENDING ->
// The admin reached the callback before the approval committed. The row stays,
// so a retry finishes it.
ConnectStatus.of(Phase.PENDING);
case REJECTED -> {
stateRepo.delete(state);
yield ConnectStatus.of(Phase.REJECTED);
}
case UNAVAILABLE -> ConnectStatus.of(Phase.UNAVAILABLE);
};
}
@Transactional(readOnly = true)
public ConnectStatus status() {
Optional<DeviceCredential> credential = credentialStore.get();
if (credential.isPresent()) {
return new ConnectStatus(Phase.LINKED, null, null, credential.get().getTeamId());
}
Optional<ConnectState> state = stateRepo.findById(ConnectState.SINGLETON_ID);
if (state.isEmpty()) {
return ConnectStatus.of(Phase.NONE);
}
LocalDateTime now = LocalDateTime.now();
if (state.get().isExpired(now)) {
return ConnectStatus.of(Phase.EXPIRED);
}
return pendingStatus(state.get(), now);
}
private static ConnectStatus pendingStatus(ConnectState state, LocalDateTime now) {
long remaining = Duration.between(now, state.getExpiresAt()).toSeconds();
return new ConnectStatus(
Phase.PENDING, state.getAuthorizeUrl(), Math.max(remaining, 0), null);
}
/** Decides the callback, preferring knowledge over inference. */
String resolveCallbackUrl(CallbackHint hint) {
String configured = applicationProperties.getSystem().getFrontendUrl();
if (configured != null && !configured.isBlank()) {
return trimTrailingSlash(configured.strip()) + CALLBACK_PATH;
}
String browserOrigin = originOf(hint.browserOrigin());
if (browserOrigin != null) {
String requested = hint.requestedCallbackUrl();
if (requested != null && browserOrigin.equals(originOf(requested))) {
return requested.strip();
}
return browserOrigin + CALLBACK_PATH;
}
return hint.derivedBaseUrl() == null || hint.derivedBaseUrl().isBlank()
? null
: trimTrailingSlash(hint.derivedBaseUrl().strip()) + CALLBACK_PATH;
}
/** Scheme, host and port of an absolute http(s) URL; null if it is not one. */
private static String originOf(String candidate) {
if (candidate == null || candidate.isBlank()) {
return null;
}
URI uri;
try {
uri = new URI(candidate.strip());
} catch (URISyntaxException e) {
return null;
}
if (uri.getScheme() == null || uri.getHost() == null) {
return null;
}
String scheme = uri.getScheme().toLowerCase(Locale.ROOT);
if (!"http".equals(scheme) && !"https".equals(scheme)) {
return null;
}
int port = uri.getPort();
boolean defaultPort =
port == -1
|| ("http".equals(scheme) && port == 80)
|| ("https".equals(scheme) && port == 443);
return defaultPort
? scheme + "://" + uri.getHost()
: scheme + "://" + uri.getHost() + ":" + port;
}
private static String trimTrailingSlash(String value) {
return value.replaceAll("/+$", "");
}
private String randomSecret() {
byte[] buf = new byte[SECRET_BYTES];
random.nextBytes(buf);
return Base64.getUrlEncoder().withoutPadding().encodeToString(buf);
}
/** Constant-time so a caller cannot probe the nonce a character at a time. */
private static boolean nonceMatches(String candidate, String expected) {
if (expected == null) {
return false;
}
return MessageDigest.isEqual(
candidate.getBytes(StandardCharsets.UTF_8),
expected.getBytes(StandardCharsets.UTF_8));
}
}
@@ -0,0 +1,60 @@
package stirling.software.proprietary.accountlink;
import java.io.Serializable;
import java.time.LocalDateTime;
import jakarta.persistence.Column;
import jakarta.persistence.Entity;
import jakarta.persistence.Id;
import jakarta.persistence.Table;
import lombok.Getter;
import lombok.NoArgsConstructor;
import lombok.Setter;
/** The one in-flight "connect this server" handshake, instance side. */
@Entity
@Table(name = "account_link_connect_state")
@NoArgsConstructor
@Getter
@Setter
public class ConnectState implements Serializable {
private static final long serialVersionUID = 1L;
public static final Long SINGLETON_ID = 1L;
@Id
@Column(name = "id")
private Long id = SINGLETON_ID;
/** Opaque handle the SaaS side gave us; identifies the handshake on both sides. */
@Column(name = "request_id", nullable = false, length = 64)
private String requestId;
/** Correlator we minted. */
@Column(name = "nonce", nullable = false, length = 128)
private String nonce;
/** Secret we minted and sent to SaaS server to server. */
@Column(name = "claim_secret", nullable = false, length = 128)
private String claimSecret;
/** Where we asked the approval page to send the admin back to. */
@Column(name = "callback_url", nullable = false, length = 2048)
private String callbackUrl;
/** The approval URL handed to the browser, so a reload can offer it again. */
@Column(name = "authorize_url", nullable = false, length = 2048)
private String authorizeUrl;
@Column(name = "created_at", nullable = false)
private LocalDateTime createdAt;
@Column(name = "expires_at", nullable = false)
private LocalDateTime expiresAt;
public boolean isExpired(LocalDateTime now) {
return expiresAt != null && expiresAt.isBefore(now);
}
}
@@ -0,0 +1,6 @@
package stirling.software.proprietary.accountlink;
import org.springframework.data.jpa.repository.JpaRepository;
/** Data access for the singleton {@link ConnectState} row. */
public interface ConnectStateRepository extends JpaRepository<ConnectState, Long> {}
@@ -13,8 +13,8 @@ import lombok.NoArgsConstructor;
import lombok.Setter;
/**
* The device credential this self-hosted instance received when it linked a SaaS account
* (combined-billing "Mode A"). Singleton — one instance links to exactly one SaaS team.
* The device credential this self-hosted instance received when it linked a SaaS account (combined
* billing). Singleton — one instance links to exactly one SaaS team.
*
* <p>Unlike the SaaS side (which stores only a hash), the instance must keep the plaintext {@code
* deviceSecret} so it can present it on every unattended entitlement call. It lives in the local
@@ -8,7 +8,7 @@ import org.springframework.context.annotation.Profile;
import org.springframework.stereotype.Service;
/**
* Decides whether a request may proceed under combined-billing "Mode A" on a self-hosted instance.
* Decides whether a request may proceed under combined billing on a self-hosted instance.
*
* <p>Rules (in order):
*
@@ -39,8 +39,8 @@ import stirling.software.proprietary.policy.controller.PolicyRunRoutes;
import stirling.software.proprietary.security.model.ApiKeyAuthenticationToken;
/**
* Request-time gate + meter for combined-billing "Mode A". {@code preHandle} blocks billable (API /
* AI / automation) work when the instance is unlinked or over its limit; manual tools pass through.
* Request-time gate + meter for combined billing. {@code preHandle} blocks billable (API / AI /
* automation) work when the instance is unlinked or over its limit; manual tools pass through.
* {@code afterCompletion} meters a successful billable op into the per-period cumulative counter.
*
* <p>Blocking responds {@code 402} with a machine-readable body the FE maps to a "link to activate"
@@ -16,11 +16,11 @@ import lombok.NoArgsConstructor;
/**
* The last time the instance metered a given input set this period — the local equivalent of the
* cloud's lineage join (combined-billing "Mode A"). The meter dedups on a rolling <b>workflow
* window</b>: an identical input set re-submitted within the window (see {@link
* AccountLinkProperties.Metering}) is treated as workflow chaining and not re-charged, while the
* same inputs run again after the window are billed afresh — matching the cloud's 5-minute open-job
* window so the same operation costs the same on the instance and in the cloud.
* cloud's lineage join (combined billing). The meter dedups on a rolling <b>workflow window</b>: an
* identical input set re-submitted within the window (see {@link AccountLinkProperties.Metering})
* is treated as workflow chaining and not re-charged, while the same inputs run again after the
* window are billed afresh — matching the cloud's 5-minute open-job window so the same operation
* costs the same on the instance and in the cloud.
*
* <p>{@code lastMeteredAt} is refreshed on every sighting (the window slides, as recording a cloud
* artifact touches its job). One row per {@code (period, signature)}; the unique constraint also
@@ -5,7 +5,7 @@ import java.util.Optional;
import org.springframework.data.jpa.repository.JpaRepository;
/** Persistence for the per-period metered input-set signatures (combined-billing "Mode A"). */
/** Persistence for the per-period metered input-set signatures (combined billing). */
public interface MeteredInputSignatureRepository
extends JpaRepository<MeteredInputSignature, Long> {
@@ -17,10 +17,10 @@ import lombok.NoArgsConstructor;
import stirling.software.proprietary.billing.BillingCategory;
/**
* Durable per-(billing period, category) cumulative usage counter for combined-billing "Mode A".
* Each successful billable op increments its row; the daily sync reports the cumulative totals and
* SaaS bills the delta since the last sync. The cumulative model is idempotent (a resend bills
* nothing) and tamper-evident (a counter that drops is a signal). One row per {@code (period_start,
* Durable per-(billing period, category) cumulative usage counter for combined billing. Each
* successful billable op increments its row; the daily sync reports the cumulative totals and SaaS
* bills the delta since the last sync. The cumulative model is idempotent (a resend bills nothing)
* and tamper-evident (a counter that drops is a signal). One row per {@code (period_start,
* category)}, auto-created by Hibernate; only the flag-gated {@link UsageMeterService} writes it.
*/
@Entity
@@ -9,7 +9,7 @@ import org.springframework.data.jpa.repository.Query;
import org.springframework.data.repository.query.Param;
import org.springframework.transaction.annotation.Transactional;
/** Persistence for the per-period/per-category usage counters (combined-billing "Mode A"). */
/** Persistence for the per-period/per-category usage counters (combined billing). */
public interface UsageCounterRepository extends JpaRepository<UsageCounter, Long> {
/**
@@ -18,8 +18,8 @@ import lombok.extern.slf4j.Slf4j;
import stirling.software.proprietary.billing.BillingCategory;
/**
* Daily usage sender for combined-billing "Mode A". Reports each period's cumulative per-category
* usage to SaaS, which bills the delta against its own last-seen totals.
* Daily usage sender for combined billing. Reports each period's cumulative per-category usage to
* SaaS, which bills the delta against its own last-seen totals.
*
* <p>Resilience: the sync seq is persisted before the report so it never regresses across
* restarts/failures; a transport failure leaves the {@code lastSyncedUnits} markers untouched so
@@ -59,7 +59,7 @@ public enum AuditLevel {
*/
public static AuditLevel fromInt(int level) {
// Ensure level is within valid bounds
int boundedLevel = Math.min(Math.max(level, 0), 3);
int boundedLevel = Math.clamp(level, 0, 3);
for (AuditLevel auditLevel : values()) {
if (auditLevel.level == boundedLevel) {
@@ -11,9 +11,9 @@ import java.util.HexFormat;
/**
* SHA-256 content fingerprint shared by the SaaS charge path and the linked self-hosted instance's
* meter (combined-billing "Mode A"), so both derive an <em>identical</em> signature for the same
* bytes — the basis for lineage dedup. Pure, no Spring: fixed 64 KiB buffer (allocation independent
* of file size), hardware-accelerated by the JVM where available.
* meter (combined billing), so both derive an <em>identical</em> signature for the same bytes — the
* basis for lineage dedup. Pure, no Spring: fixed 64 KiB buffer (allocation independent of file
* size), hardware-accelerated by the JVM where available.
*
* <p>Lives in {@code :proprietary} (not {@code :common}) so it stays out of the community core
* build yet is reachable from {@code :saas} (which depends on {@code :proprietary}).
@@ -17,16 +17,16 @@ import org.springframework.data.redis.core.ScanOptions;
import org.springframework.data.redis.core.StringRedisTemplate;
import org.springframework.stereotype.Component;
import com.fasterxml.jackson.core.JsonProcessingException;
import com.fasterxml.jackson.core.type.TypeReference;
import com.fasterxml.jackson.databind.ObjectMapper;
import lombok.RequiredArgsConstructor;
import lombok.extern.slf4j.Slf4j;
import stirling.software.common.cluster.JobStore;
import stirling.software.common.cluster.JobStoreEntry;
import tools.jackson.core.JacksonException;
import tools.jackson.core.type.TypeReference;
import tools.jackson.databind.ObjectMapper;
/**
* Valkey-backed {@link JobStore}. Each job is one hash; a reverse index maps fileId to jobId.
*
@@ -44,8 +44,10 @@ public class ValkeyJobStore implements JobStore {
private static final String FILE_INDEX_PREFIX = "stirling:file2job:";
private static final ObjectMapper MAPPER = new ObjectMapper();
private static final TypeReference<List<String>> LIST_STRING = new TypeReference<>() {};
private static final TypeReference<Map<String, String>> MAP_STRING = new TypeReference<>() {};
private static final TypeReference<List<String>> LIST_STRING =
new TypeReference<List<String>>() {};
private static final TypeReference<Map<String, String>> MAP_STRING =
new TypeReference<Map<String, String>>() {};
private final StringRedisTemplate template;
@@ -265,7 +267,7 @@ public class ValkeyJobStore implements JobStore {
}
try {
return MAPPER.readValue(v.toString(), MAP_STRING);
} catch (JsonProcessingException e) {
} catch (JacksonException e) {
log.warn(
"JobStore {} field 'resultMeta' is not valid JSON '{}' - treating as empty",
key,
@@ -277,7 +279,7 @@ public class ValkeyJobStore implements JobStore {
private static String writeJson(Object value) {
try {
return MAPPER.writeValueAsString(value);
} catch (JsonProcessingException e) {
} catch (JacksonException e) {
throw new IllegalStateException("Failed to JSON-serialize JobStore field", e);
}
}
@@ -286,7 +288,7 @@ public class ValkeyJobStore implements JobStore {
try {
List<String> parsed = MAPPER.readValue(json, LIST_STRING);
return parsed == null ? new ArrayList<>() : parsed;
} catch (JsonProcessingException e) {
} catch (JacksonException e) {
log.warn(
"JobStore {} field 'fileIds' is not valid JSON '{}' - treating as empty",
key,
@@ -35,7 +35,7 @@ public class AuditConfigurationProperties {
// Ensure level is within valid bounds (0-3)
int configLevel = auditConfig.getLevel();
this.level = Math.min(Math.max(configLevel, 0), 3);
this.level = Math.clamp(configLevel, 0, 3);
// Retention days (0 means infinite)
this.retentionDays = auditConfig.getRetentionDays();
@@ -48,7 +48,7 @@ public class UsageRestController {
@RequestParam(value = "dataType", defaultValue = "all") String dataType,
@RequestParam(value = "days", defaultValue = "30") Integer days) {
int lookbackDays = Math.max(1, Math.min(days, 365));
int lookbackDays = Math.clamp(days, 1, 365);
// Get audit events filtered by type
List<PersistentAuditEvent> events = getEventsByDataType(dataType, lookbackDays);
@@ -18,6 +18,19 @@ public enum FailureActionId {
DISMISS(Execution.SERVER, "Dismiss"),
/**
* Open the failed operation in the client with its document, for the owner to run again
* themselves. Not a re-run: the settings are theirs to check first.
*/
OPEN_IN_TOOL(Execution.CLIENT, "Retry"),
/**
* Ask the owner for the password and unlock the document in their client. Re-running is implied
* rather than named: an id says what a caller must supply, and a {@link
* FailureActionSlot#RESOLUTION} runs the failed work again once it has it.
*/
DECRYPT(Execution.CLIENT, "Decrypt and retry"),
/** Open the document behind the incident, in whichever client can resolve its id. */
VIEW_FILE(Execution.CLIENT, "View file"),
@@ -0,0 +1,14 @@
package stirling.software.proprietary.failure;
/** Placement intent, not layout: the client promotes, knowing what it can actually run. */
public enum FailureActionSlot {
/** The action that resolves the failure. At most one per kind. */
RESOLUTION,
/** Offered alongside the resolution, for a caller the resolution is not aimed at. */
SECONDARY,
/** Available but folded away: correct, rarely what anyone wants to press next. */
OVERFLOW
}
@@ -1,8 +1,12 @@
package stirling.software.proprietary.failure;
import static stirling.software.proprietary.failure.FailureActionId.DECRYPT;
import static stirling.software.proprietary.failure.FailureActionId.DISMISS;
import static stirling.software.proprietary.failure.FailureActionId.OPEN_IN_TOOL;
import static stirling.software.proprietary.failure.FailureActionId.VIEW_FILE;
import static stirling.software.proprietary.failure.FailureActionId.VIEW_IN_PROCESSOR;
import static stirling.software.proprietary.failure.FailureActionSlot.OVERFLOW;
import static stirling.software.proprietary.failure.FailureActionSlot.SECONDARY;
import static stirling.software.proprietary.failure.FailureAudience.ANYONE_WHO_SEES;
import static stirling.software.proprietary.failure.FailureAudience.OWNER;
import static stirling.software.proprietary.failure.FailureAudience.TEAM_REVIEWER;
@@ -21,11 +25,8 @@ import lombok.AccessLevel;
import lombok.Getter;
/**
* The registry of failure kinds, described as data: a stable id, i18n keys and an English fallback
* like {@code ExceptionUtils.ErrorCode}, plus the facets a review surface needs.
*
* <p>A new kind ships as a registry entry plus copy. Each offer also says who it is for, since one
* incident is read both by whoever hit it and by whoever reviews after them.
* The registry of failure kinds as data: id, i18n keys, English fallback, plus the facets a review
* surface needs. A new kind ships as an entry plus copy; each offer says who it is for and where.
*/
@Getter
public enum FailureKind {
@@ -36,9 +37,12 @@ public enum FailureKind {
FailureScope.FILE,
errorCodes("E004"),
fallback("This document is password-protected, so the pipeline could not read it."),
offer(VIEW_FILE, OWNER),
offer(VIEW_IN_PROCESSOR, TEAM_REVIEWER),
offer(DISMISS, ANYONE_WHO_SEES)),
// The password is the fix; the owner's own document is the runner-up.
resolution(DECRYPT, OWNER),
global(VIEW_FILE, OWNER, SECONDARY),
global(VIEW_IN_PROCESSOR, TEAM_REVIEWER, OVERFLOW),
global(OPEN_IN_TOOL, OWNER, OVERFLOW),
global(DISMISS, ANYONE_WHO_SEES, OVERFLOW)),
UNKNOWN(
FailureStage.INTERNAL,
@@ -47,11 +51,11 @@ public enum FailureKind {
FailureScope.RUN,
noErrorCodes(),
fallback("This run failed for a reason Stirling does not yet recognise."),
// Same order as every other kind: declaration order is display order, so the document
// leads wherever it is offered rather than moving between failures.
offer(VIEW_FILE, OWNER),
offer(VIEW_IN_PROCESSOR, TEAM_REVIEWER),
offer(DISMISS, ANYONE_WHO_SEES));
// No known fix to declare, so a plain retry leads: these are often one-offs.
global(OPEN_IN_TOOL, OWNER, SECONDARY),
global(VIEW_FILE, OWNER, SECONDARY),
global(VIEW_IN_PROCESSOR, TEAM_REVIEWER, OVERFLOW),
global(DISMISS, ANYONE_WHO_SEES, OVERFLOW));
private static final String KEY_PREFIX = "portal.failures.kind.";
private static final String ACTION_KEY_PREFIX = "portal.failures.action.";
@@ -98,27 +102,37 @@ public enum FailureKind {
this.offers = List.of(offers);
}
/**
* One ordered list rather than ids plus parallel maps of audiences and labels, which could
* disagree with each other.
*
* @param labelKeySuffix key under {@code portal.failures.action.}, or null for the generic
* label
*/
private record Offer(FailureActionId id, FailureAudience audience, String labelKeySuffix) {}
/** One ordered list, not parallel maps of audiences, slots and labels that could disagree. */
private record Offer(
FailureActionId id,
FailureAudience audience,
FailureActionSlot slot,
String labelKeySuffix) {}
/** Declaration order is display order. */
private static Offer offer(FailureActionId id, FailureAudience audience) {
return new Offer(id, audience, null);
/** The action that fixes this kind. One per kind: needing two would make it two kinds. */
private static Offer resolution(FailureActionId id, FailureAudience audience) {
return new Offer(id, audience, FailureActionSlot.RESOLUTION, null);
}
/**
* As {@link #offer(FailureActionId, FailureAudience)}, but labelled by this kind's own wording
* where the shared one reads badly.
*/
private static Offer offer(
/** As {@link #resolution(FailureActionId, FailureAudience)}, with this kind's own wording. */
private static Offer resolution(
FailureActionId id, FailureAudience audience, String labelKeySuffix) {
return new Offer(id, audience, labelKeySuffix);
return new Offer(id, audience, FailureActionSlot.RESOLUTION, labelKeySuffix);
}
/** Not this kind's fix: an offer any kind can make, with the shared wording. */
private static Offer global(
FailureActionId id, FailureAudience audience, FailureActionSlot slot) {
return new Offer(id, audience, slot, null);
}
/** As above, with this kind's own wording where the shared one reads badly. */
private static Offer global(
FailureActionId id,
FailureAudience audience,
FailureActionSlot slot,
String labelKeySuffix) {
return new Offer(id, audience, slot, labelKeySuffix);
}
/**
@@ -157,21 +171,25 @@ public enum FailureKind {
return offers.stream().map(Offer::id).toList();
}
/**
* What this kind offers, in declaration order, each with its label resolved. What a review
* surface reads, so it never has to ask two separate questions about one offer.
*/
/** What this kind offers, in declaration order, each with label and placement resolved. */
public List<OfferedAction> getOfferedActions() {
return offers.stream()
.map(
offer ->
new OfferedAction(
offer.id(), labelKeyFor(offer.id()), offer.audience()))
offer.id(),
labelKeyFor(offer.id()),
offer.audience(),
offer.slot()))
.toList();
}
/** One action as a kind declares it: what to call it and who it is for. */
public record OfferedAction(FailureActionId id, String labelKey, FailureAudience audience) {}
/** One action as a kind declares it: what to call it, who it is for, where it wants to sit. */
public record OfferedAction(
FailureActionId id,
String labelKey,
FailureAudience audience,
FailureActionSlot slot) {}
/** Whether this kind offers {@code action}. The dispatch guard: see {@code FailureActionId}. */
public boolean declares(FailureActionId action) {
@@ -64,16 +64,17 @@ public interface FileRunEventRepository extends JpaRepository<FileRunEventEntity
int fold(@Param("id") String id, @Param("now") Instant now, @Param("detail") String detail);
/**
* Reopen a resolved incident whose failure has recurred. Guarded on the current status so only
* {@code RESOLVED} flips; a concurrent dismiss is never overwritten back to {@code NEW}.
* A recurrence reopens {@code RESOLVED} (the fix did not hold) and {@code FILE_REMOVED} (the
* document is back). Guarded, so a reviewer's {@code DISMISSED} is never overwritten.
*/
@Modifying(clearAutomatically = true)
@Transactional
@Query(
"update FileRunEventEntity e set"
+ " e.status = stirling.software.proprietary.failure.FileRunEventStatus.NEW,"
+ " e.statusActor = null, e.statusAt = null where e.id = :id and e.status ="
+ " stirling.software.proprietary.failure.FileRunEventStatus.RESOLVED")
+ " e.statusActor = null, e.statusAt = null where e.id = :id and e.status in"
+ " (stirling.software.proprietary.failure.FileRunEventStatus.RESOLVED,"
+ " stirling.software.proprietary.failure.FileRunEventStatus.FILE_REMOVED)")
int reopenIfResolved(@Param("id") String id);
/**
@@ -1,5 +1,9 @@
package stirling.software.proprietary.failure;
import java.nio.charset.StandardCharsets;
import java.security.MessageDigest;
import java.security.NoSuchAlgorithmException;
import java.util.HexFormat;
import java.util.List;
import java.util.Map;
@@ -171,6 +175,18 @@ public class FileRunEventService {
return action.execute(event, inputs == null ? Map.of() : inputs, currentActor());
}
/** Mark an incident resolved after a client's own retry worked. Idempotent. */
public FileRunEvent resolve(String eventId) {
FileRunEvent event = requireVisible(eventId);
// No terminal pre-check: the store's guarded UPDATE decides, rather than racing a read.
return store.applyStatusOnce(
event.id(),
event.teamId(),
FileRunEventStatus.RESOLVED,
currentActor(),
FileRunEventStatus.open());
}
/** "No such event" rather than a refusal, so trying does not confirm a colleague's exists. */
private FileRunEvent requireVisible(String eventId) {
ReadScope scope = readScope();
@@ -222,7 +238,8 @@ public class FileRunEventService {
boolean unattended,
boolean documentless) {
String reason = disabledReasonFor(offer.audience(), closed, unattended, documentless);
return new AvailableAction(offer.id(), offer.labelKey(), reason == null, reason);
return new AvailableAction(
offer.id(), offer.labelKey(), offer.slot(), reason == null, reason);
}
/** Closed wins over everything, then the owner-only reasons, most specific first. */
@@ -251,11 +268,38 @@ public class FileRunEventService {
};
}
/** Login disabled has no roles, so its one operator triages everything. */
private boolean reviewsTeam() {
/** Whether the caller triages the team's incidents, not only their own. Login disabled: all. */
public boolean reviewsTeam() {
return !enforced() || policyManagementAuthority.canEditPolicies();
}
/**
* An opaque, stable discriminator for the calling viewer, for a client scoping per-browser read
* state. Hashed rather than the username itself: a client only needs to tell one viewer from
* another, and the value ends up in that browser's own storage.
*
* <p>{@code "anonymous"} with login disabled, where the one operator is every viewer.
*/
public String viewerKey() {
String actor = currentActor();
return actor == null || actor.isBlank() ? "anonymous" : sha256Prefix(actor);
}
/** First 8 bytes of SHA-256 as hex: stable, one-way, and collision-safe enough to key on. */
private static String sha256Prefix(String value) {
try {
byte[] digest =
MessageDigest.getInstance("SHA-256")
.digest(value.getBytes(StandardCharsets.UTF_8));
return HexFormat.of().formatHex(digest, 0, 8);
} catch (NoSuchAlgorithmException e) {
// Every JVM ships SHA-256; a constant here would silently merge two viewers' read
// state, so the caller gets no key and the client falls back to showing everything.
log.warn("SHA-256 unavailable, so notifications cannot be scoped to a viewer", e);
return "";
}
}
private FailureActionId parseActionId(String actionId) {
for (FailureActionId candidate : FailureActionId.values()) {
if (candidate.name().equals(actionId)) {
@@ -326,6 +370,11 @@ public class FileRunEventService {
return applicationProperties.getSecurity().isEnableLogin();
}
/** One action offered to one caller, availability resolved. */
public record AvailableAction(
FailureActionId id, String labelKey, boolean enabled, String disabledReasonKey) {}
FailureActionId id,
String labelKey,
FailureActionSlot slot,
boolean enabled,
String disabledReasonKey) {}
}
@@ -3,10 +3,7 @@ package stirling.software.proprietary.failure;
import java.util.Arrays;
import java.util.List;
/**
* Disposition of one recorded failure. {@code RESOLVED} is declared but not set yet (it becomes
* system-set later); the rollup already defines what a repeat means for it, which is to reopen.
*/
/** Disposition of one recorded failure. {@code RESOLVED} is system-set; a repeat reopens it. */
public enum FileRunEventStatus {
NEW(false),
ACKNOWLEDGED(false),
@@ -14,9 +11,8 @@ public enum FileRunEventStatus {
RESOLVED(true),
/**
* The document this incident was about was deleted from its owner's editor, so there is nothing
* left to act on. Distinct from {@code DISMISSED}, which is a reviewer's decision, and from
* {@code RESOLVED}, which reopens on recurrence: this one cannot recur, the file is gone.
* The document was deleted, so there is nothing left to act on. A recurrence reopens it like
* {@code RESOLVED}: a fresh failure is proof the document is back.
*/
FILE_REMOVED(true);
@@ -61,14 +61,15 @@ public record FileRunEventView(
}
/**
* {@code defaultLabel} and {@code execution} let a client render and route an action it was
* never built with. Declaration order is display order.
* {@code defaultLabel} and {@code execution} let a client render an action it was never built
* with; {@code slot} is placement intent. See {@link FailureActionSlot}.
*/
public record ActionView(
String id,
String labelKey,
String defaultLabel,
FailureActionId.Execution execution,
FailureActionSlot slot,
boolean enabled,
String disabledReasonKey) {
@@ -78,6 +79,7 @@ public record FileRunEventView(
action.labelKey(),
action.id().getDefaultLabel(),
action.id().getExecution(),
action.slot(),
action.enabled(),
action.disabledReasonKey());
}
@@ -1,5 +1,6 @@
package stirling.software.proprietary.model;
import java.io.Serial;
import java.io.Serializable;
import jakarta.persistence.*;
@@ -19,7 +20,7 @@ import lombok.*;
@ToString
public class UserLicenseSettings implements Serializable {
private static final long serialVersionUID = 1L;
@Serial private static final long serialVersionUID = 1L;
public static final Long SINGLETON_ID = 1L;
@@ -2,10 +2,14 @@ package stirling.software.proprietary.notification;
import java.util.List;
import org.springframework.http.HttpStatus;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.PathVariable;
import org.springframework.web.bind.annotation.PostMapping;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RequestParam;
import org.springframework.web.bind.annotation.RestController;
import org.springframework.web.server.ResponseStatusException;
import io.swagger.v3.oas.annotations.Hidden;
import io.swagger.v3.oas.annotations.Operation;
@@ -13,9 +17,11 @@ import io.swagger.v3.oas.annotations.tags.Tag;
import lombok.RequiredArgsConstructor;
import stirling.software.proprietary.failure.FailureActionException;
/**
* Open to any authenticated user, unlike the failure endpoints it draws on: each source scopes its
* own rows. Read-only, because every action a notification offers runs on the client's own device.
* Open to any authenticated user: each source scopes its own rows. Every action runs on the
* client's own device, so the only write is it reporting a fix.
*/
@RestController
@RequestMapping("/api/v1/notifications")
@@ -40,9 +46,34 @@ public class NotificationController {
+ " to mark read here yet: the client tracks what it has shown.")
public NotificationsResponse list(@RequestParam(required = false) Integer limit) {
int capped = Math.min(limit == null ? DEFAULT_LIMIT : Math.max(1, limit), MAX_LIMIT);
return new NotificationsResponse(notifications.list(capped));
return new NotificationsResponse(
notifications.list(capped),
notifications.callerReviewsTeam(),
notifications.callerViewerKey());
}
@PostMapping("/{notificationId}/resolved")
@Operation(
summary = "Record that a client-side retry fixed what a notification was about",
description =
"Takes the prefixed notification id, not the producing row's id. Not an action:"
+ " nobody is offered a resolve button, and a recurrence brings the"
+ " notification back.")
public NotificationView resolved(@PathVariable String notificationId) {
try {
return notifications.resolve(notificationId);
} catch (IllegalArgumentException e) {
throw new ResponseStatusException(HttpStatus.BAD_REQUEST, e.getMessage(), e);
} catch (FailureActionException e) {
throw new ResponseStatusException(
FailureActionException.statusOf(e.getReason()), e.getMessage(), e);
}
}
/** Wrapped so paging or a total can be added without breaking clients. */
public record NotificationsResponse(List<NotificationView> notifications) {}
public record NotificationsResponse(
List<NotificationView> notifications,
boolean viewerReviewsTeam,
/** Opaque; the client scopes its own read state on it. Empty means "cannot scope". */
String viewerKey) {}
}
@@ -20,9 +20,47 @@ public class NotificationService {
private final FileRunEventService fileRunEvents;
/** Newest first, and only open failures: one already dealt with is not news. */
/**
* Newest first, and only open failures about a document: one already dealt with is not news,
* and a row naming no file has nothing the bell can offer beyond saying so.
*
* <p>Filtered on the named file rather than the kind's scope, because a RUN-scoped kind still
* names one when the editor reported it: a failed tool run belongs here. Applied after the
* limit, so a page can come back short while unattributed rows exist - the review surface is
* where those are meant to be read, and it lists them unfiltered.
*/
public List<NotificationView> list(int limit) {
return fileRunEvents.list(null, null, limit).stream().map(this::fromFailure).toList();
return fileRunEvents.list(null, null, limit).stream()
.filter(event -> event.fileId() != null && !event.fileId().isBlank())
.map(this::fromFailure)
.toList();
}
/** Whether the caller sees the whole team's incidents rather than only their own. */
public boolean callerReviewsTeam() {
return fileRunEvents.reviewsTeam();
}
/** Opaque and stable, so a shared browser can keep one viewer's read state off another's. */
public String callerViewerKey() {
return fileRunEvents.viewerKey();
}
/** Takes the prefixed id, so the bell cannot reach a failure endpoint even by accident. */
public NotificationView resolve(String notificationId) {
NotificationSource.QualifiedId qualified = qualify(notificationId);
return switch (qualified.source()) {
case FAILURE -> fromFailure(fileRunEvents.resolve(qualified.rowId()));
};
}
/** The source and row id behind a notification id, refusing anything that is not one. */
private static NotificationSource.QualifiedId qualify(String notificationId) {
return NotificationSource.parse(notificationId)
.orElseThrow(
() ->
new IllegalArgumentException(
"Not a notification id: " + notificationId));
}
/** Prefixes the row id on the way out, so it is never sent bare. */
@@ -1,6 +1,8 @@
package stirling.software.proprietary.notification;
import java.util.Arrays;
import java.util.Locale;
import java.util.Optional;
/**
* Which subsystem produced a notification. Every id is prefixed with it, so a client never holds
@@ -18,4 +20,24 @@ public enum NotificationSource {
public String qualify(String sourceRowId) {
return prefix() + sourceRowId;
}
/** Empty rather than throwing for an unprefixed or unknown id: both arrive from clients. */
public static Optional<QualifiedId> parse(String notificationId) {
if (notificationId == null) {
return Optional.empty();
}
int separator = notificationId.indexOf(SEPARATOR);
if (separator <= 0 || separator == notificationId.length() - 1) {
return Optional.empty();
}
String prefix = notificationId.substring(0, separator);
String rowId = notificationId.substring(separator + 1);
return Arrays.stream(values())
.filter(source -> source.name().equalsIgnoreCase(prefix))
.findFirst()
.map(source -> new QualifiedId(source, rowId));
}
/** A notification id split into the source that owns it and that source's own row id. */
public record QualifiedId(NotificationSource source, String rowId) {}
}
@@ -336,6 +336,15 @@ public class PolicyController {
* nothing to check.
*/
private void requireAccessibleOutput(Policy policy) {
// An editor policy hands its results back to the workspace the file came from. A stored
// destination would send the run to a folder or bucket instead, leaving the editor's copy
// untouched - and the editor's import would then have nothing to collect.
if (policy.editor().allowed() && !policy.outputIds().isEmpty()) {
throw new ResponseStatusException(
HttpStatus.BAD_REQUEST,
"An editor policy delivers back to the editor and can't also have a"
+ " destination");
}
for (String outputId : policy.outputIds()) {
Source destination =
sourceStore
@@ -393,7 +402,8 @@ public class PolicyController {
policy.steps(),
policy.output(),
policy.outputIds(),
teamId);
teamId,
policy.editor());
}
/** Output secrets never leave the server: reads return the redaction sentinel instead. */
@@ -0,0 +1,34 @@
package stirling.software.proprietary.policy.model;
/**
* How a policy participates in the editor: it fires in the browser as each file passes through,
* rather than being swept from a stored {@code Source} on a trigger.
*
* <p>An object rather than a bare flag so the moment it fires ({@code runOn}) travels with the
* decision, and so later editor-only settings have somewhere to live.
*
* @param allowed whether the editor may run this policy at all
* @param runOn which moment it fires on: {@code "upload"} or {@code "export"}
*/
public record EditorConfig(boolean allowed, String runOn) {
public static final String UPLOAD = "upload";
public static final String EXPORT = "export";
public EditorConfig {
runOn = EXPORT.equals(runOn) ? EXPORT : UPLOAD;
}
/** Not an editor policy: swept server-side, or run only on demand. */
public static EditorConfig disabled() {
return new EditorConfig(false, UPLOAD);
}
public static EditorConfig onUpload() {
return new EditorConfig(true, UPLOAD);
}
public static EditorConfig onExport() {
return new EditorConfig(true, EXPORT);
}
}

Some files were not shown because too many files have changed in this diff Show More