Skip to content

pyHanko 0.4.0 alpha

Pre-release
Pre-release

Choose a tag to compare

@MatthiasValvekens MatthiasValvekens released this 14 Feb 10:51
· 2357 commits to master since this release
0.4.0

The release has been uploaded to PyPI. Documentation is available on ReadTheDocs.

Note: The public API is not completely stable yet, so future releases may still include API changes. This is particularly likely for the validation code and the pdf_utils package; please refer to the documentation for further details.

Change log

New features and enhancements

Encryption

  • Expose permission flags outside security handler
  • Make file encryption key straightforward to grab

Signing

  • Mildly refactor PdfSignedData for non-signing uses
  • Make DSS API more flexible
    • Allow direct input of cert/ocsp/CRL objects as opposed to only certvalidator output
    • Allow input to not be associated with any concrete VRI.
  • Greatly improved PKCS#11 support
    • Added support for RSASSA-PSS and ECDSA.
    • Added tests for RSA functionality using SoftHSMv2.
    • Added a command to the CLI for generic PKCS#11.
    • Note: Tests don't run in CI, and ECDSA is not included in the test suite yet (SoftHSMv2 doesn't seem to expose all the necessary mechanisms).
  • Factor out unsigned_attrs in signer, added a digest_algorithm parameter to signed_attrs.
  • Allow signing with any BasePdfFileWriter (in particular, this allows creating signatures in the initial revision of a PDF file)
  • Add CMSAlgorithmProtection attribute when possible
    • Note: Not added to PAdES signatures for the time being.
  • Improved support for deep fields in the form hierarchy (arguably orthogonal to the standard, but it doesn't hurt to be flexible)

Validation

  • Path handling improvements:
    • Paths in the structure tree are also simplified.
    • Paths can be resolved relative to objects in a file.
  • Limited support for tagged PDF in the validator.
    • Existing form fields can be filled in without tripping up the modification analysis module.
    • Adding new form fields to the structure tree after signing is not allowed for the time being.
  • Internal refactoring in CMS validation logic:
    • Isolate cryptographic integrity validation from trust validation
    • Rename externally_invalid API parameter to encap_data_invalid
    • Validate CMSAlgorithmProtection when present.
  • Improved support for deep fields in the form hierarchy (arguably orthogonal to the standard, but it doesn't hurt to be flexible).
  • Added

Miscellaneous

  • Export copy_into_new_writer.
  • Transparently handle non-seekable output streams in the signer.
  • Remove unused __iadd__ implementation from VRI class.
  • Clean up some corner cases in container_ref handling.
  • Refactored SignatureFormField initialisation (internal API).

Bugs fixed

  • Deal with some XRef processing edge cases.
  • Make signed_revision on embedded signatures more robust.
  • Fix an issue where DocTimeStamp additions would trigger /All-type field locks.
  • Fix some issues with modification_level handling in validation status reports.
  • Fix a few logging calls.
  • Fix some minor issues with signing API input validation logic.