Skip to content

fix(pdf): honor crypt filter defaults and password byte limits - #1183

Merged
andiwand merged 2 commits into
mainfrom
review/pdf-authentication
Oct 6, 2026
Merged

andiwand merged 2 commits into
mainfrom
review/pdf-authentication

Conversation

@andiwand

@andiwand andiwand commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

🤖 Generated with Claude Code

Valid PDFs with named unencrypted crypt filters were rejected because CFM None and its omitted default were not recognized. Accept both according to ISO 32000-1 Table 25. Revision-6 AES-256 authentication also now truncates UTF-8 password bytes to 127 before validation and key recovery, as Algorithm 2.A requires.

Validation: PdfEncryption.* passes all 11 tests. A frozen qpdf 12.3.2 vector verifies user and owner passwords, ignored suffixes, shorter-password rejection, and decrypted content without requiring qpdf at test runtime. Named filter tests cover both explicit and omitted CFM. The earlier integrated stack passed 607 targeted C++ tests and 17 script tests.

Unicode SASLprep password normalization remains a separate compatibility limitation; this patch addresses the byte limit only.

@andiwand
andiwand marked this pull request as ready for review October 6, 2026 20:34
@andiwand
andiwand force-pushed the review/modern-statistical-formulas branch from 3f97f8e to a2e7d7e Compare October 6, 2026 20:40
Base automatically changed from review/modern-statistical-formulas to main October 6, 2026 20:42
andiwand and others added 2 commits October 6, 2026 22:42
V 5 always used AESV3 and ignored /StmF, /StrF and /CF, so the named
None filter and Identity did not apply to AES-256 files. V 5 now
resolves the filters as V 4 does. If an entry is absent, V 5 keeps
AESV3, because AES-256 writers that omit the filters still encrypt
everything.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MxyTMutqSUJRGfxA8CyzMc
@andiwand
andiwand force-pushed the review/pdf-authentication branch from 66525d3 to bf67e9c Compare October 6, 2026 20:46
@andiwand
andiwand merged commit 31e5ee9 into main Oct 6, 2026
2 of 23 checks passed
@andiwand
andiwand deleted the review/pdf-authentication branch October 6, 2026 20:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant