TPDFlibSignDoc
Security and Signatures
Description
TPDFlibSignDoc provides direct access to the signature fields of a document without loading the complete PDF into memory
The class opens a file, a caller-owned stream, or an ANSI byte string, enumerates the AcroForm signature fields, and reads the raw values of an existing signature so a verifier can recompute the /ByteRange digest
It also performs the write side of incremental updates: Append starts a new revision, AddSignatureField registers a fresh field, and the SetSignatureValue family writes into the reserved space while keeping earlier revisions intact
The SigningWorkbench demo drives this class end to end, from field enumeration to ByteRange inspection and certificate extraction
Syntax
Delphi
TPDFlibSignDoc = Class
Public
Destructor Destroy; Override;
Function Open(Const FileName: WideString; Const Password: WideString; ReadWrite: Boolean): Boolean;
Function OpenStream(SourceStream: TStream; Const Password: WideString): Boolean;
Function OpenString(Const SourceData: AnsiString; Const Password: WideString): Boolean;
Procedure Append;
Function AppendToFile(Const FileName: WideString): Boolean;
Function AppendToStream(TargetStream: TStream): Boolean;
Procedure Close;
Function AddSignatureField(Const FieldName: WideString; PageNumber: Integer): Integer;
Function HasSignatureField(Const FieldName: WideString): Boolean;
Procedure GetSignatureFieldNames(Names: TStrings);
Function GetSignatureValueObjNum(Const FieldName: WideString): Integer;
Function GetSignatureValueByName(Const FieldName: WideString; ValueKey: Integer): AnsiString;
Function GetSignatureTextValueByName(Const FieldName: WideString; ValueKey: Integer): WideString;
Function GetSignatureDocMDPLevelByName(Const FieldName: WideString): Integer;
Function GetSignaturePermissionInfoByName(Const FieldName: WideString;
Out Report: TPDFlibSignaturePermissionReport): Boolean;
Function GetSignatureSeedValueEx(Const FieldName: WideString;
Out SeedValue: TPDFSignatureSeedValue): Boolean;
Function GetSignatureContentsHashHexByName(Const FieldName: WideString): AnsiString;
Function SetSignatureValue(Const FieldName: WideString; Const NewValue: AnsiString;
DocMDPLevel: Integer): Boolean;
Function SetSignatureFieldLock(Const FieldName: WideString;
Const Action: AnsiString; Const Fields: TArray): Boolean;
Procedure SetSignatureImage(Const FieldName: WideString; Const ImageData: AnsiString; ImageOptions: Integer);
Procedure SetSignatureAppearanceText(Const FieldName, Text: WideString; FontSize, FontRed, FontGreen, FontBlue: Double);
Procedure SetSignatureBounds(Const FieldName: WideString; Left, Top, Width, Height: Double);
Function GetDocumentBytes: TBytes;
Function GetDocumentSize: Int64;
Function ReadDocumentRange(Offset: Int64; Buffer: Pointer; Count: Integer): Integer;
Function GetDSSValidationMaterial(Const FieldName: WideString;
Out Certs, CRLs, OCSPs: TStructStrArray; Out UsedVRI: Boolean): Boolean;
Procedure SetSignatureFlags(NewFlags: Integer);
Procedure EnsurePAdESExtensions(ESICLevel: Integer);
Property IsOpen: Boolean Read FIsOpen;
Property SignatureFieldPosition: Int64 Read FSignatureFieldPosition;
Property SignatureFieldLength: Integer Read FSignatureFieldLength;
End; Methods
| Open, OpenStream, OpenString | Open a file, stream, or in-memory ANSI string, optionally for read-write access; Open accepts a password and a read-write flag |
|---|---|
| Append, AppendToFile, AppendToStream | Start a new incremental revision in place, or append the revision to a new file or stream |
| Close | Releases the underlying smart reader and document handles |
| AddSignatureField | Registers a new signature field on the given page and returns its object number, or 0 on failure |
| HasSignatureField | True when a signature field with the fully qualified name exists |
| GetSignatureFieldNames | Fills a TStrings with every signature field name in the AcroForm |
| GetSignatureValueObjNum | Object number of the signature value dictionary, or 0 when the field is unsigned |
| GetSignatureValueByName | Raw binary values selected by ValueKey: 0 = /Contents, 1 = /Cert, 2 = /Filter, 3 = /SubFilter, 11 to 14 = /ByteRange entries 0 to 3 as decimal strings |
| GetSignatureTextValueByName | Text values selected by ValueKey: 0 = /M, 1 = /Name, 2 = /Reason, 3 = /Location, 4 = /ContactInfo, 5 = /Type |
| GetSignatureDocMDPLevelByName | The DocMDP transform level (P value) of a certifying signature, 0 when absent |
| GetSignaturePermissionInfoByName | Parses the DocMDP and FieldMDP constraints of a signature into a report record |
| GetSignatureSeedValueEx | Reads the /SV seed-value dictionary that constrains what a signer may write into the field |
| GetSignatureContentsHashHexByName | Hex digest of the signed contents covered by the ByteRange |
| SetSignatureValue | Writes a finished signature into the reserved /Contents space and records the DocMDP level |
| SetSignatureFieldLock | Writes a field lock dictionary with an action and field-name list |
| SetSignatureImage, SetSignatureAppearanceText, SetSignatureBounds | Control the visible appearance: a drawn image, a text-only appearance stream built in v3.221.0, and explicit field bounds |
| GetDocumentBytes, GetDocumentSize, ReadDocumentRange | Raw access to the underlying bytes so the whole file or a ByteRange segment can be hashed externally |
| GetDSSValidationMaterial | Returns the DSS certificates, CRLs, and OCSP responses for a field and reports whether VRI evidence was used |
| SetSignatureFlags, EnsurePAdESExtensions | Adjust /SigFlags and add the ETSI PAdES extension schema |
Fields
| IsOpen | True between a successful open and Close |
|---|---|
| SignatureFieldPosition | File offset of the selected signature field contents |
| SignatureFieldLength | Byte length reserved for the selected signature contents |
Remarks
The whole file is materialised by GetDocumentBytes because the two ByteRange segments together cover essentially the entire file
For signing without touching this low-level surface, the facade exposes the equivalent pipeline through the documented SignProcess functions
See also
TPDFlibSignatureVerifier, TPDFlibPFXFile, TPDFlibSigner, NewSignProcessFromFile, GetSignProcessByteRange