Skip to main content

forme/
lib.rs

1//! # Forme
2//!
3//! A page-native PDF rendering engine.
4//!
5//! Most PDF renderers treat a document as an infinite vertical canvas and then
6//! slice it into pages after layout. This produces broken tables, orphaned
7//! headers, collapsed flex layouts on page boundaries, and years of GitHub
8//! issues begging for fixes.
9//!
10//! Forme does the opposite: **the page is the fundamental unit of layout.**
11//! Every layout decision—every flex calculation, every line break, every table
12//! row placement—is made with the page boundary as a hard constraint. Content
13//! doesn't get "sliced" after the fact. It flows *into* pages.
14//!
15//! ## Architecture
16//!
17//! ```text
18//! Input (JSON/API)
19//!       ↓
20//!   [model]    — Document tree: nodes, styles, content
21//!       ↓
22//!   [style]    — Resolve cascade, inheritance, defaults
23//!       ↓
24//!   [layout]   — Page-aware layout engine
25//!       ↓
26//!   [pdf]      — Serialize to PDF bytes
27//! ```
28
29pub mod barcode;
30pub mod chart;
31pub mod error;
32pub mod font;
33pub mod image_loader;
34pub mod layout;
35pub mod model;
36pub mod pdf;
37pub mod qrcode;
38pub mod style;
39pub mod svg;
40pub mod template;
41pub mod text;
42
43#[cfg(feature = "wasm")]
44pub mod wasm;
45
46#[cfg(feature = "wasm-raw")]
47pub mod wasm_raw;
48
49pub use error::FormeError;
50pub use layout::LayoutInfo;
51pub use model::{
52    CertificationConfig, ColumnDef, ColumnWidth, FontEntry, PatternType, RedactionPattern,
53    RedactionRegion, TextRun,
54};
55pub use model::{ChartDataPoint, ChartSeries, DotPlotGroup};
56pub use model::{Document, Metadata, Node, NodeKind, PageConfig, PageSize};
57pub use style::Style;
58
59use font::FontContext;
60use layout::LayoutEngine;
61use pdf::PdfWriter;
62
63/// Certify PDF bytes with an X.509 certificate.
64///
65/// Takes arbitrary PDF bytes and a certification configuration, and returns
66/// new PDF bytes with a valid digital signature. Uses incremental update
67/// to preserve the original PDF content.
68pub fn certify_pdf(
69    pdf_bytes: &[u8],
70    config: &model::CertificationConfig,
71) -> Result<Vec<u8>, FormeError> {
72    pdf::certify::certify_pdf(pdf_bytes, config)
73}
74
75/// Redact regions of a PDF by overlaying opaque rectangles.
76///
77/// Takes arbitrary PDF bytes and a list of redaction regions (page, x, y,
78/// width, height in top-origin coordinates). Returns new PDF bytes with
79/// the redaction rectangles drawn on top via incremental update.
80pub fn redact_pdf(
81    pdf_bytes: &[u8],
82    regions: &[model::RedactionRegion],
83) -> Result<Vec<u8>, FormeError> {
84    pdf::redaction::redact_pdf(pdf_bytes, regions)
85}
86
87/// Find text regions matching patterns in a PDF.
88///
89/// Searches PDF content streams for literal or regex patterns and returns
90/// redaction regions (in web top-origin coordinates) for each match.
91pub fn find_text_regions(
92    pdf_bytes: &[u8],
93    patterns: &[model::RedactionPattern],
94) -> Result<Vec<RedactionRegion>, FormeError> {
95    pdf::redaction::find_text_regions(pdf_bytes, patterns)
96}
97
98/// Redact text matching patterns from a PDF.
99///
100/// Convenience wrapper: finds text regions matching the patterns, then
101/// applies coordinate-based redaction to all matches.
102pub fn redact_text(
103    pdf_bytes: &[u8],
104    patterns: &[model::RedactionPattern],
105) -> Result<Vec<u8>, FormeError> {
106    pdf::redaction::redact_text(pdf_bytes, patterns)
107}
108
109/// Merge multiple PDFs into a single document.
110///
111/// Takes a slice of PDF byte slices and returns merged PDF bytes containing
112/// all pages in order. Requires at least 2 input PDFs.
113pub fn merge_pdfs(pdfs: &[&[u8]]) -> Result<Vec<u8>, FormeError> {
114    pdf::merge::merge_pdfs(pdfs)
115}
116
117/// Render a document to PDF bytes.
118///
119/// This is the primary entry point. Takes a document tree and returns
120/// the raw bytes of a valid PDF file. If the document has a `certification`
121/// configuration, the output PDF is digitally signed.
122pub fn render(document: &Document) -> Result<Vec<u8>, FormeError> {
123    render_with_warnings(document).map(|(pdf, _warnings)| pdf)
124}
125
126/// Lay out a document, running the page-number sentinel re-layout loop **only
127/// when the document actually places a `{{pageNumber}}`/`{{totalPages}}`
128/// sentinel**. Without one, the reserved sentinel width is never consumed, so a
129/// re-layout reproduces byte-identical pages — pure wasted work (measured as a
130/// 2x render cost above 100 pages, where the total-page digit count first
131/// crosses 2->3; see `benchmarks/`). The sentinel presence is detected at the
132/// exhaustive chokepoint — every sentinel glyph is measured in
133/// `FontContext::char_width`, from any source (HTML `counter()`, margin boxes,
134/// JSX literals). Returns the laid-out pages, the populated font context, and
135/// the number of full layout passes (1, or 2–3 when the width needed fixing).
136///
137/// SCOPING NOTE (investigated 2026-09, abandoned — see benchmarks/): re-laying
138/// out ONLY the running element on a digit-width change, instead of the whole
139/// document, looks like a clean ~2x win but is NOT scopable as written. The
140/// sentinel width is consumed during INJECTION — `inject_fixed_elements` lays
141/// out the footer/margin content — NOT during the flow pass; the flow-time
142/// `measure_node_height` height reservation doesn't touch it. And HTML `@page`
143/// margin boxes are mapped to Fixed nodes (see the `html` crate), so there is no
144/// purely out-of-flow page-number case. Consequently the guard signals (is there
145/// a sentinel? in flow or in a running element? does its height change?) don't
146/// exist yet after a flow-only pass, and a naive "reuse flow + re-inject" split
147/// silently SKIPS the digit-width correction entirely — a correctness regression
148/// that byte-identity caught. Any future attempt must derive those signals from
149/// injection or a document-model scan, not from the flow pass.
150fn layout_with_sentinel_passes(
151    document: &Document,
152) -> (Vec<crate::layout::LayoutPage>, FontContext, u32) {
153    let mut font_context = FontContext::new();
154    register_document_fonts(&mut font_context, &document.fonts);
155    let engine = LayoutEngine::new();
156    font_context.reset_page_sentinel();
157    let mut pages = engine.layout(document, &font_context);
158    let mut passes = 1u32;
159
160    if font_context.saw_page_sentinel() {
161        for _ in 0..2 {
162            let needed = digits_for_count(pages.len());
163            if needed == font_context.sentinel_digit_count() {
164                break;
165            }
166            font_context.set_sentinel_digit_count(needed);
167            pages = engine.layout(document, &font_context);
168            passes += 1;
169        }
170    }
171    (pages, font_context, passes)
172}
173
174/// Number of full layout passes a document needs (1 for the common case; 2–3
175/// only when a page-number sentinel's reserved width must be corrected).
176/// Exposed as the regression guard for the sentinel re-layout optimization.
177pub fn count_layout_passes(document: &Document) -> u32 {
178    layout_with_sentinel_passes(document).2
179}
180
181/// Render a document to PDF bytes plus any non-fatal warnings (e.g. pdfUa
182/// requested without an embeddable font registered). Same output as `render`;
183/// the warnings surface through the WASM bindings and the HTML wrapper.
184pub fn render_with_warnings(document: &Document) -> Result<(Vec<u8>, Vec<String>), FormeError> {
185    render_with_warnings_and_passes(document).map(|(pdf, warnings, _passes)| (pdf, warnings))
186}
187
188/// Like [`render_with_warnings`], but also returns the number of layout passes
189/// the render took — surfaced through the HTML wrapper for benchmark evidence.
190pub fn render_with_warnings_and_passes(
191    document: &Document,
192) -> Result<(Vec<u8>, Vec<String>, u32), FormeError> {
193    // Coarse phase profiling behind FORME_PROFILE (native only in practice —
194    // `env::var` is Err under wasm, so the timer is never constructed there and
195    // `Instant::now` is never called). Prints layout vs serialize to stderr.
196    let profile = std::env::var("FORME_PROFILE").is_ok();
197    let t_layout = if profile {
198        Some(std::time::Instant::now())
199    } else {
200        None
201    };
202    let (pages, font_context, passes) = layout_with_sentinel_passes(document);
203    let layout_ms = t_layout.map(|t| t.elapsed().as_secs_f64() * 1000.0);
204
205    let writer = PdfWriter::new();
206    let tagged = document.tagged
207        || document.pdf_ua
208        || matches!(document.pdfa, Some(model::PdfAConformance::A2a));
209    let t_ser = if profile {
210        Some(std::time::Instant::now())
211    } else {
212        None
213    };
214    let (pdf, warnings) = writer.write(
215        &pages,
216        &document.metadata,
217        &font_context,
218        tagged,
219        document.pdfa.as_ref(),
220        document.pdf_ua,
221        document.embedded_data.as_deref(),
222        document.flatten_forms,
223    )?;
224    let serialize_ms = t_ser.map(|t| t.elapsed().as_secs_f64() * 1000.0);
225    let pdf = if let Some(ref sig_config) = document.certification {
226        pdf::certify::certify_pdf(&pdf, sig_config)?
227    } else {
228        pdf
229    };
230    if let (Some(l), Some(s)) = (layout_ms, serialize_ms) {
231        eprintln!(
232            "FORME_PROFILE pages={} passes={passes} layout_ms={l:.1} serialize_ms={s:.1}",
233            pages.len()
234        );
235    }
236    Ok((pdf, warnings, passes))
237}
238
239/// Render a document to PDF bytes along with layout metadata.
240///
241/// Same as `render()` but also returns `LayoutInfo` describing the
242/// position and dimensions of every element on every page.
243/// If the document has a `certification` configuration, the output PDF
244/// is digitally signed.
245pub fn render_with_layout(
246    document: &Document,
247) -> Result<(Vec<u8>, LayoutInfo, Vec<String>), FormeError> {
248    let (pages, font_context, _passes) = layout_with_sentinel_passes(document);
249    let layout_info = LayoutInfo::from_pages(&pages);
250    let writer = PdfWriter::new();
251    let tagged = document.tagged
252        || document.pdf_ua
253        || matches!(document.pdfa, Some(model::PdfAConformance::A2a));
254    let (pdf, warnings) = writer.write(
255        &pages,
256        &document.metadata,
257        &font_context,
258        tagged,
259        document.pdfa.as_ref(),
260        document.pdf_ua,
261        document.embedded_data.as_deref(),
262        document.flatten_forms,
263    )?;
264    let pdf = if let Some(ref sig_config) = document.certification {
265        pdf::certify::certify_pdf(&pdf, sig_config)?
266    } else {
267        pdf
268    };
269    Ok((pdf, layout_info, warnings))
270}
271
272/// Return the number of digits needed to display `n` as a decimal string.
273fn digits_for_count(n: usize) -> u32 {
274    if n < 10 {
275        1
276    } else if n < 100 {
277        2
278    } else if n < 1000 {
279        3
280    } else {
281        4
282    }
283}
284
285/// Register custom fonts from the document's `fonts` array.
286fn register_document_fonts(font_context: &mut FontContext, fonts: &[FontEntry]) {
287    use base64::Engine as _;
288    let b64 = base64::engine::general_purpose::STANDARD;
289
290    for entry in fonts {
291        let bytes = if let Some(comma_pos) = entry.src.find(',') {
292            // data URI: "data:font/ttf;base64,AAAA..."
293            b64.decode(&entry.src[comma_pos + 1..]).ok()
294        } else {
295            // raw base64 string
296            b64.decode(&entry.src).ok()
297        };
298
299        if let Some(data) = bytes {
300            font_context
301                .registry_mut()
302                .register(&entry.family, entry.weight, entry.italic, data);
303        }
304    }
305}
306
307/// Render a document described as JSON to PDF bytes.
308pub fn render_json(json: &str) -> Result<Vec<u8>, FormeError> {
309    let document: Document = serde_json::from_str(json)?;
310    render(&document)
311}
312
313/// Render a document described as JSON to PDF bytes along with layout metadata.
314pub fn render_json_with_layout(
315    json: &str,
316) -> Result<(Vec<u8>, LayoutInfo, Vec<String>), FormeError> {
317    let document: Document = serde_json::from_str(json)?;
318    render_with_layout(&document)
319}
320
321/// Render a template with data to PDF bytes.
322///
323/// Takes a template JSON tree (with `$ref`, `$each`, `$if`, operators) and
324/// a data JSON object. Evaluates all expressions, then renders the resulting
325/// document to PDF.
326pub fn render_template(template_json: &str, data_json: &str) -> Result<Vec<u8>, FormeError> {
327    let template: serde_json::Value = serde_json::from_str(template_json)?;
328    let data: serde_json::Value = serde_json::from_str(data_json)?;
329    let resolved = template::evaluate_template(&template, &data)?;
330    let document: Document = serde_json::from_value(resolved)?;
331    render(&document)
332}
333
334/// Render a template with data to PDF bytes along with layout metadata.
335pub fn render_template_with_layout(
336    template_json: &str,
337    data_json: &str,
338) -> Result<(Vec<u8>, LayoutInfo), FormeError> {
339    let template: serde_json::Value = serde_json::from_str(template_json)?;
340    let data: serde_json::Value = serde_json::from_str(data_json)?;
341    let resolved = template::evaluate_template(&template, &data)?;
342    let document: Document = serde_json::from_value(resolved)?;
343    render_with_layout(&document).map(|(pdf, layout, _warnings)| (pdf, layout))
344}
345
346#[cfg(test)]
347mod tests {
348    use super::*;
349
350    #[test]
351    fn test_digits_for_count() {
352        assert_eq!(digits_for_count(0), 1);
353        assert_eq!(digits_for_count(1), 1);
354        assert_eq!(digits_for_count(9), 1);
355        assert_eq!(digits_for_count(10), 2);
356        assert_eq!(digits_for_count(99), 2);
357        assert_eq!(digits_for_count(100), 3);
358        assert_eq!(digits_for_count(999), 3);
359        assert_eq!(digits_for_count(1000), 4);
360    }
361}