-
Notifications
You must be signed in to change notification settings - Fork 40
Open
Open
Copy link
Description
Describe the bug
I got a long list with special characters that seem to break the format on the second page break.
To Reproduce
Create the following files:
main.sdoc:
[DOCUMENT]
TITLE: text in header
[TEXT]
STATEMENT: Main file
[REQUIREMENT]
UID: REQ-003
TITLE: text in header
STATEMENT: >>>
CRA Annex I:
* 'Annex I Part 1 (1)', 'Products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks.'
* 'Annex I Part 1 (2-a)', 'On the basis of the cybersecurity risk assessment referred to in Article 13(2) and where applicable, products with digital elements shall:\nbe made available on the market without known exploitable vulnerabilities'
* 'Annex I Part 1 (2-b)', 'On the basis of the cybersecurity risk assessment referred to in Article 13(2) and where applicable, products with digital elements shall:\nbe made available on the market with a secure by default configuration, unless otherwise agreed between manufacturer and business user in relation to a tailor-made product with digital elements, including the possibility to reset the product to its original state'
* 'Annex I Part 1 (2-c)', 'On the basis of the cybersecurity risk assessment referred to in Article 13(2) and where applicable, products with digital elements shall:\nensure that vulnerabilities can be addressed through security updates, including, where applicable, through automatic security updates that are installed within an appropriate timeframe enabled as a default setting, with a clear and easy-to-use opt-out mechanism, through the notification of available updates to users, and the option to temporarily postpone them'
* 'Annex I Part 1 (2-d)', 'On the basis of the cybersecurity risk assessment referred to in Article 13(2) and where applicable, products with digital elements shall:\nensure protection from unauthorised access by appropriate control mechanisms, including but not limited to authentication, identity or access management systems, and report on possible unauthorised access'
* 'Annex I Part 1 (2-e)', 'On the basis of the cybersecurity risk assessment referred to in Article 13(2) and where applicable, products with digital elements shall:\nprotect the confidentiality of stored, transmitted or otherwise processed data, personal or other, such as by encrypting relevant data at rest or in transit by state of the art mechanisms, and by using other technical means'
* 'Annex I Part 1 (2-f)', 'On the basis of the cybersecurity risk assessment referred to in Article 13(2) and where applicable, products with digital elements shall:\nprotect the integrity of stored, transmitted or otherwise processed data, personal or other, commands, programs and configuration against any manipulation or modification not authorised by the user, and report on corruptions'
* 'Annex I Part 1 (2-g)', 'On the basis of the cybersecurity risk assessment referred to in Article 13(2) and where applicable, products with digital elements shall:\nprocess only data, personal or other, that are adequate, relevant and limited to what is necessary in relation to the intended purpose of the product with digital elements (data minimisation)'
* 'Annex I Part 1 (2-h)', 'On the basis of the cybersecurity risk assessment referred to in Article 13(2) and where applicable, products with digital elements shall:\nprotect the availability of essential and basic functions, also after an incident, including through resilience and mitigation measures against denial-of-service attacks'
* 'Annex I Part 1 (2-i)', 'On the basis of the cybersecurity risk assessment referred to in Article 13(2) and where applicable, products with digital elements shall:\nminimise the negative impact by the products themselves or connected devices on the availability of services provided by other devices or networks'
* 'Annex I Part 1 (2-j)', 'On the basis of the cybersecurity risk assessment referred to in Article 13(2) and where applicable, products with digital elements shall:\nbe designed, developed and produced to limit attack surfaces, including external interfaces'
* 'Annex I Part 1 (2-k)', 'On the basis of the cybersecurity risk assessment referred to in Article 13(2) and where applicable, products with digital elements shall:\nbe designed, developed and produced to reduce the impact of an incident using appropriate exploitation mitigation mechanisms and techniques'
* 'Annex I Part 1 (2-l)', 'On the basis of the cybersecurity risk assessment referred to in Article 13(2) and where applicable, products with digital elements shall:\nprovide security related information by recording and monitoring relevant internal activity, including the access to or modification of data, services or functions, with an opt-out mechanism for the user'
* 'Annex I Part 1 (2-m)', 'On the basis of the cybersecurity risk assessment referred to in Article 13(2) and where applicable, products with digital elements shall:\nprovide the possibility for users to securely and easily remove on a permanent basis all data and settings and, where such data can be transferred to other products or systems, ensure that this is done in a secure manner'
* 'Annex I Part 2 (1)', 'Manufacturers of products with digital elements shall:\nidentify and document vulnerabilities and components contained in products with digital elements, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products'
* 'Annex I Part 2 (2)', 'Manufacturers of products with digital elements shall:\nin relation to the risks posed to products with digital elements, address and remediate vulnerabilities without delay, including by providing security updates\nwhere technically feasible, new security updates shall be provided separately from functionality updates'
* 'Annex I Part 2 (3)', 'Manufacturers of products with digital elements shall:\napply effective and regular tests and reviews of the security of the product with digital elements'
* 'Annex I Part 2 (4)', 'Manufacturers of products with digital elements shall:\nonce a security update has been made available, share and publicly disclose information about fixed vulnerabilities, including a description of the vulnerabilities, information allowing users to identify the product with digital elements affected, the impacts of the vulnerabilities, their severity and clear and accessible information helping users to remediate the vulnerabilities\nin duly justified cases, where manufacturers consider the security risks of publication to outweigh the security benefits, they may delay making public information regarding a fixed vulnerability until after users have been given the possibility to apply the relevant patch'
* 'Annex I Part 2 (5)', 'Manufacturers of products with digital elements shall:\nput in place and enforce a policy on coordinated vulnerability disclosure'
* 'Annex I Part 2 (6)', 'Manufacturers of products with digital elements shall:\ntake measures to facilitate the sharing of information about potential vulnerabilities in their product with digital elements as well as in third-party components contained in that product, including by providing a contact address for the reporting of the vulnerabilities discovered in the product with digital elements'
* 'Annex I Part 2 (7)', 'Manufacturers of products with digital elements shall:\nprovide for mechanisms to securely distribute updates for products with digital elements to ensure that vulnerabilities are fixed or mitigated in a timely manner and, where applicable for security updates, in an automatic manner'
* 'Annex I Part 2 (8)', 'Manufacturers of products with digital elements shall:\nensure that, where security updates are available to address identified security issues, they are disseminated without delay and, unless otherwise agreed between a manufacturer and a business user in relation to a tailor-made product with digital elements, free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken'
<<<
strictdoc_config.py:
from strictdoc.core.project_config import ProjectConfig
def create_config() -> ProjectConfig:
config = ProjectConfig(
project_title = "POC Bug",
project_features = [
"SEARCH",
"HTML2PDF",
],
server_host = "localhost",
server_port = 5000,
)
return config
using the current --pre strictdoc from #2503 with the current Dockerfile:
docker run --rm -v $(pwd):/data -e HOST_UID=$(id -u) -e HOST_GID=$(id -g) -p 5000:5000 -it strictdoc:latest /bin/bash -c 'cd /data && strictdoc export . --output-dir output --formats html2pdf'
Somehow I am unable to reproduce it with something else than the CRA Annex 1 entries. so I guess it has something to do with the long entries or with the characters within those lines
Expected behavior
No Listitem text within the header of the page.
Screenshots

Metadata
Metadata
Assignees
Labels
No labels