Skip to content

fix: add DocMDP reference to catalog for certification signatures - #166

Closed
akkaraponph wants to merge 2 commits into
digitorus:mainfrom
akkaraponph:fix/catalog-docmdp-reference
Closed

akkaraponph wants to merge 2 commits into
digitorus:mainfrom
akkaraponph:fix/catalog-docmdp-reference

Conversation

@akkaraponph

Copy link
Copy Markdown
Contributor

Summary

Add the required document-catalog /Perms << /DocMDP N 0 R >> entry when creating a CertificationSignature.

This is a PDF structural interoperability fix for Adobe Acrobat certification recognition. Without the catalog pointer, Acrobat may treat a cryptographically valid certification signature as a normal approval signature and omit the “Certified by …” banner.

The implementation:

  • References the actual generated signature object.
  • Returns an error when the existing document catalog already contains /Perms, preserving the first-certification-signature requirement.
  • Leaves approval-signature behavior, public APIs, signing algorithms, certificate-chain handling, and visible signatures unchanged.
  • Adds regression coverage for certification and approval signatures.

This does not guarantee trust status; that still depends on the recipient’s trusted certificate chain and revocation validation.

Verification

  • gofmt -w sign/pdfcatalog.go sign/pdfcatalog_test.go sign/sign_test.go
  • go test ./... -count=1

@akkaraponph akkaraponph reopened this Sep 16, 2026
@codecov

codecov Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 83.33333% with 1 line in your changes missing coverage. Please review.
✅ Project coverage is 60.27%. Comparing base (8f1bd3d) to head (fc92c74).
⚠️ Report is 21 commits behind head on main.

Files with missing lines Patch % Lines
sign/pdfcatalog.go 83.33% 1 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main     #166      +/-   ##
==========================================
- Coverage   63.21%   60.27%   -2.95%     
==========================================
  Files          46       47       +1     
  Lines        3934     4194     +260     
==========================================
+ Hits         2487     2528      +41     
- Misses       1447     1666     +219     
Flag Coverage Δ
unittests 60.27% <83.33%> (-2.95%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Copy link
Copy Markdown
Member

@akkaraponph thanks — this is a real gap, and #165 found the same thing a day earlier. I've opened #169 which combines both, credited to you and @uinoushi.

The one change from your approach: an existing /Perms isn't rejected outright, since a Reader-enabled document carries /Perms << /UR3 … >> without ever having been certified. #169 merges /DocMDP into that dictionary and only refuses when /DocMDP is already present or the document already has a signed field.

Since your goal was Acrobat recognition, would you be able to test #169 with the documents you were checking against? What I'd like to confirm is that Acrobat now shows the "Certified by …" banner, and that the permission level you set (DocMDPPerm) is what Acrobat reports under the signature properties.

go get github.com/digitorus/pdfsign@agent/wizardly-shannon-mtm0lq

Generated by Claude Code

@vanbroup vanbroup closed this Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants