TPDFlibSignDoc

Security and Signatures

Description

TPDFlibSignDoc provides direct access to the signature fields of a document without loading the complete PDF into memory

The class opens a file, a caller-owned stream, or an ANSI byte string, enumerates the AcroForm signature fields, and reads the raw values of an existing signature so a verifier can recompute the /ByteRange digest

It also performs the write side of incremental updates: Append starts a new revision, AddSignatureField registers a fresh field, and the SetSignatureValue family writes into the reserved space while keeping earlier revisions intact

The SigningWorkbench demo drives this class end to end, from field enumeration to ByteRange inspection and certificate extraction

Syntax

Delphi

TPDFlibSignDoc = Class
  Public
    Destructor Destroy; Override;
    Function Open(Const FileName: WideString; Const Password: WideString; ReadWrite: Boolean): Boolean;
    Function OpenStream(SourceStream: TStream; Const Password: WideString): Boolean;
    Function OpenString(Const SourceData: AnsiString; Const Password: WideString): Boolean;
    Procedure Append;
    Function AppendToFile(Const FileName: WideString): Boolean;
    Function AppendToStream(TargetStream: TStream): Boolean;
    Procedure Close;
    Function AddSignatureField(Const FieldName: WideString; PageNumber: Integer): Integer;
    Function HasSignatureField(Const FieldName: WideString): Boolean;
    Procedure GetSignatureFieldNames(Names: TStrings);
    Function GetSignatureValueObjNum(Const FieldName: WideString): Integer;
    Function GetSignatureValueByName(Const FieldName: WideString; ValueKey: Integer): AnsiString;
    Function GetSignatureTextValueByName(Const FieldName: WideString; ValueKey: Integer): WideString;
    Function GetSignatureDocMDPLevelByName(Const FieldName: WideString): Integer;
    Function GetSignaturePermissionInfoByName(Const FieldName: WideString;
      Out Report: TPDFlibSignaturePermissionReport): Boolean;
    Function GetSignatureSeedValueEx(Const FieldName: WideString;
      Out SeedValue: TPDFSignatureSeedValue): Boolean;
    Function GetSignatureContentsHashHexByName(Const FieldName: WideString): AnsiString;
    Function SetSignatureValue(Const FieldName: WideString; Const NewValue: AnsiString;
      DocMDPLevel: Integer): Boolean;
    Function SetSignatureFieldLock(Const FieldName: WideString;
      Const Action: AnsiString; Const Fields: TArray): Boolean;
    Procedure SetSignatureImage(Const FieldName: WideString; Const ImageData: AnsiString; ImageOptions: Integer);
    Procedure SetSignatureAppearanceText(Const FieldName, Text: WideString; FontSize, FontRed, FontGreen, FontBlue: Double);
    Procedure SetSignatureBounds(Const FieldName: WideString; Left, Top, Width, Height: Double);
    Function GetDocumentBytes: TBytes;
    Function GetDocumentSize: Int64;
    Function ReadDocumentRange(Offset: Int64; Buffer: Pointer; Count: Integer): Integer;
    Function GetDSSValidationMaterial(Const FieldName: WideString;
      Out Certs, CRLs, OCSPs: TStructStrArray; Out UsedVRI: Boolean): Boolean;
    Procedure SetSignatureFlags(NewFlags: Integer);
    Procedure EnsurePAdESExtensions(ESICLevel: Integer);
    Property IsOpen: Boolean Read FIsOpen;
    Property SignatureFieldPosition: Int64 Read FSignatureFieldPosition;
    Property SignatureFieldLength: Integer Read FSignatureFieldLength;
  End;

Methods

Open, OpenStream, OpenStringOpen a file, stream, or in-memory ANSI string, optionally for read-write access; Open accepts a password and a read-write flag
Append, AppendToFile, AppendToStreamStart a new incremental revision in place, or append the revision to a new file or stream
CloseReleases the underlying smart reader and document handles
AddSignatureFieldRegisters a new signature field on the given page and returns its object number, or 0 on failure
HasSignatureFieldTrue when a signature field with the fully qualified name exists
GetSignatureFieldNamesFills a TStrings with every signature field name in the AcroForm
GetSignatureValueObjNumObject number of the signature value dictionary, or 0 when the field is unsigned
GetSignatureValueByNameRaw binary values selected by ValueKey: 0 = /Contents, 1 = /Cert, 2 = /Filter, 3 = /SubFilter, 11 to 14 = /ByteRange entries 0 to 3 as decimal strings
GetSignatureTextValueByNameText values selected by ValueKey: 0 = /M, 1 = /Name, 2 = /Reason, 3 = /Location, 4 = /ContactInfo, 5 = /Type
GetSignatureDocMDPLevelByNameThe DocMDP transform level (P value) of a certifying signature, 0 when absent
GetSignaturePermissionInfoByNameParses the DocMDP and FieldMDP constraints of a signature into a report record
GetSignatureSeedValueExReads the /SV seed-value dictionary that constrains what a signer may write into the field
GetSignatureContentsHashHexByNameHex digest of the signed contents covered by the ByteRange
SetSignatureValueWrites a finished signature into the reserved /Contents space and records the DocMDP level
SetSignatureFieldLockWrites a field lock dictionary with an action and field-name list
SetSignatureImage, SetSignatureAppearanceText, SetSignatureBoundsControl the visible appearance: a drawn image, a text-only appearance stream built in v3.221.0, and explicit field bounds
GetDocumentBytes, GetDocumentSize, ReadDocumentRangeRaw access to the underlying bytes so the whole file or a ByteRange segment can be hashed externally
GetDSSValidationMaterialReturns the DSS certificates, CRLs, and OCSP responses for a field and reports whether VRI evidence was used
SetSignatureFlags, EnsurePAdESExtensionsAdjust /SigFlags and add the ETSI PAdES extension schema

Fields

IsOpenTrue between a successful open and Close
SignatureFieldPositionFile offset of the selected signature field contents
SignatureFieldLengthByte length reserved for the selected signature contents

Remarks

The whole file is materialised by GetDocumentBytes because the two ByteRange segments together cover essentially the entire file

For signing without touching this low-level surface, the facade exposes the equivalent pipeline through the documented SignProcess functions

See also

TPDFlibSignatureVerifier, TPDFlibPFXFile, TPDFlibSigner, NewSignProcessFromFile, GetSignProcessByteRange