Forms, Containers, and Integration Surfaces

HotPDF provides transactional form editing and bounded integration APIs for applications that need deterministic PDF processing without arbitrary script execution

Transactional forms and FDF

THPDFFormEditSession tracks dirty fields, regenerates appearances, and supports undo, redo, commit, and rollback

THPDFFormEventKind and THPDFFormEventBinding select the event source, while THPDFConstrainedFormActionKind and THPDFConstrainedFormAction describe the permitted mutation

THPDFFormEventResult reports dispatch outcomes and THPDFFormEditHistoryEntry exposes reversible edit history

Focus, pointer, key, and commit events dispatch only caller-bound set, toggle, clear, undo, or redo actions

FDF interchange covers field values, annotations, and status data through streams while retaining the existing lightweight field-only APIs

XFA flattening

Barcode and specialized UI widgets use read-only text fallbacks, while signatures and choice lists retain native AcroForm mappings

Flowed subforms honor content-area and page-area breaks, keep groups, overflow leader and trailer targets, and repeated page-area pagination

Attachments and portfolios

Embedded files can be extracted directly to a caller stream under a byte limit while MD5, declared size, dates, MIME type, and associated-file relationship are validated

Portfolio editing supports details, tile, hidden, and custom views, ordered sort keys, nested folders, navigator metadata, and schema or item metadata removal

THPDFPortfolioSortKeyArray carries stable multi-key ordering for portfolio navigation

Bounded integration

Each JSON operation can limit memory, elapsed time, object count, decompression ratio, and output size with structured budget-exceeded results

The versioned flat C callback ABI writes random-access source bytes directly into parser buffers, streams output through retryable partial writes, and exposes cancellation, progress, diagnostics, fixed status codes, and validated opaque handles

Corpus minimization removes object spans and byte ranges only while a stable failure signature remains reproducible, continuously keeps the smallest case across runs through process-safe locking and atomic replacement, and publishes stable SHA-256-addressed metadata

Deterministic differential probes compare parse, render, text, and save domains across repeated engine runs, with save fingerprints using reproducible serialization rather than time-derived document identifiers

THPDFRegressionDomain identifies each surface, while the versioned JSON report preserves signatures, instability, isolated errors, engine names, and the input SHA-256 in stable order

Primary APIs