Repository navigation
pyHanko 0.4.0 alpha
Pre-release
Pre-release
·
2357 commits
to master
since this release
The release has been uploaded to PyPI. Documentation is available on ReadTheDocs.
Note: The public API is not completely stable yet, so future releases may still include API changes. This is particularly likely for the validation code and the pdf_utils package; please refer to the documentation for further details.
Change log
New features and enhancements
Encryption
- Expose permission flags outside security handler
- Make file encryption key straightforward to grab
Signing
- Mildly refactor
PdfSignedDatafor non-signing uses - Make DSS API more flexible
- Allow direct input of cert/ocsp/CRL objects as opposed to only certvalidator output
- Allow input to not be associated with any concrete VRI.
- Greatly improved PKCS#11 support
- Added support for RSASSA-PSS and ECDSA.
- Added tests for RSA functionality using SoftHSMv2.
- Added a command to the CLI for generic PKCS#11.
- Note: Tests don't run in CI, and ECDSA is not included in the test suite yet (SoftHSMv2 doesn't seem to expose all the necessary mechanisms).
- Factor out
unsigned_attrsin signer, added adigest_algorithmparameter tosigned_attrs. - Allow signing with any
BasePdfFileWriter(in particular, this allows creating signatures in the initial revision of a PDF file) - Add
CMSAlgorithmProtectionattribute when possible- Note: Not added to PAdES signatures for the time being.
- Improved support for deep fields in the form hierarchy (arguably orthogonal to the standard, but it doesn't hurt to be flexible)
Validation
- Path handling improvements:
- Paths in the structure tree are also simplified.
- Paths can be resolved relative to objects in a file.
- Limited support for tagged PDF in the validator.
- Existing form fields can be filled in without tripping up the modification analysis module.
- Adding new form fields to the structure tree after signing is not allowed for the time being.
- Internal refactoring in CMS validation logic:
- Isolate cryptographic integrity validation from trust validation
- Rename
externally_invalidAPI parameter toencap_data_invalid - Validate
CMSAlgorithmProtectionwhen present.
- Improved support for deep fields in the form hierarchy (arguably orthogonal to the standard, but it doesn't hurt to be flexible).
- Added
Miscellaneous
- Export
copy_into_new_writer. - Transparently handle non-seekable output streams in the signer.
- Remove unused
__iadd__implementation from VRI class. - Clean up some corner cases in
container_refhandling. - Refactored
SignatureFormFieldinitialisation (internal API).
Bugs fixed
- Deal with some XRef processing edge cases.
- Make
signed_revisionon embedded signatures more robust. - Fix an issue where DocTimeStamp additions would trigger
/All-type field locks. - Fix some issues with
modification_levelhandling in validation status reports. - Fix a few logging calls.
- Fix some minor issues with signing API input validation logic.