Skip to main content

forme/
lib.rs

1//! # Forme
2//!
3//! A page-native PDF rendering engine.
4//!
5//! Most PDF renderers treat a document as an infinite vertical canvas and then
6//! slice it into pages after layout. This produces broken tables, orphaned
7//! headers, collapsed flex layouts on page boundaries, and years of GitHub
8//! issues begging for fixes.
9//!
10//! Forme does the opposite: **the page is the fundamental unit of layout.**
11//! Every layout decision—every flex calculation, every line break, every table
12//! row placement—is made with the page boundary as a hard constraint. Content
13//! doesn't get "sliced" after the fact. It flows *into* pages.
14//!
15//! ## Architecture
16//!
17//! ```text
18//! Input (JSON/API)
19//!       ↓
20//!   [model]    — Document tree: nodes, styles, content
21//!       ↓
22//!   [style]    — Resolve cascade, inheritance, defaults
23//!       ↓
24//!   [layout]   — Page-aware layout engine
25//!       ↓
26//!   [pdf]      — Serialize to PDF bytes
27//! ```
28
29pub mod barcode;
30pub mod chart;
31pub mod error;
32pub mod font;
33pub mod image_loader;
34pub mod layout;
35pub mod model;
36pub mod pdf;
37pub mod qrcode;
38pub mod style;
39pub mod svg;
40pub mod template;
41pub mod text;
42
43#[cfg(feature = "wasm")]
44pub mod wasm;
45
46#[cfg(feature = "wasm-raw")]
47pub mod wasm_raw;
48
49pub use error::FormeError;
50pub use layout::LayoutInfo;
51pub use model::{
52    CertificationConfig, ColumnDef, ColumnWidth, FontEntry, PatternType, RedactionPattern,
53    RedactionRegion, TextRun,
54};
55pub use model::{ChartDataPoint, ChartSeries, DotPlotGroup};
56pub use model::{Document, Metadata, Node, NodeKind, PageConfig, PageSize};
57pub use style::Style;
58
59use font::FontContext;
60use layout::LayoutEngine;
61use pdf::PdfWriter;
62
63/// Certify PDF bytes with an X.509 certificate.
64///
65/// Takes arbitrary PDF bytes and a certification configuration, and returns
66/// new PDF bytes with a valid digital signature. Uses incremental update
67/// to preserve the original PDF content.
68pub fn certify_pdf(
69    pdf_bytes: &[u8],
70    config: &model::CertificationConfig,
71) -> Result<Vec<u8>, FormeError> {
72    pdf::certify::certify_pdf(pdf_bytes, config)
73}
74
75/// Redact regions of a PDF by overlaying opaque rectangles.
76///
77/// Takes arbitrary PDF bytes and a list of redaction regions (page, x, y,
78/// width, height in top-origin coordinates). Returns new PDF bytes with
79/// the redaction rectangles drawn on top via incremental update.
80pub fn redact_pdf(
81    pdf_bytes: &[u8],
82    regions: &[model::RedactionRegion],
83) -> Result<Vec<u8>, FormeError> {
84    pdf::redaction::redact_pdf(pdf_bytes, regions)
85}
86
87/// Find text regions matching patterns in a PDF.
88///
89/// Searches PDF content streams for literal or regex patterns and returns
90/// redaction regions (in web top-origin coordinates) for each match.
91pub fn find_text_regions(
92    pdf_bytes: &[u8],
93    patterns: &[model::RedactionPattern],
94) -> Result<Vec<RedactionRegion>, FormeError> {
95    pdf::redaction::find_text_regions(pdf_bytes, patterns)
96}
97
98/// Redact text matching patterns from a PDF.
99///
100/// Convenience wrapper: finds text regions matching the patterns, then
101/// applies coordinate-based redaction to all matches.
102pub fn redact_text(
103    pdf_bytes: &[u8],
104    patterns: &[model::RedactionPattern],
105) -> Result<Vec<u8>, FormeError> {
106    pdf::redaction::redact_text(pdf_bytes, patterns)
107}
108
109/// Merge multiple PDFs into a single document.
110///
111/// Takes a slice of PDF byte slices and returns merged PDF bytes containing
112/// all pages in order. Requires at least 2 input PDFs.
113pub fn merge_pdfs(pdfs: &[&[u8]]) -> Result<Vec<u8>, FormeError> {
114    pdf::merge::merge_pdfs(pdfs)
115}
116
117/// Render a document to PDF bytes.
118///
119/// This is the primary entry point. Takes a document tree and returns
120/// the raw bytes of a valid PDF file. If the document has a `certification`
121/// configuration, the output PDF is digitally signed.
122pub fn render(document: &Document) -> Result<Vec<u8>, FormeError> {
123    render_with_warnings(document).map(|(pdf, _warnings)| pdf)
124}
125
126/// Lay out a document, running the page-number sentinel re-layout loop **only
127/// when the document actually places a `{{pageNumber}}`/`{{totalPages}}`
128/// sentinel**. Without one, the reserved sentinel width is never consumed, so a
129/// re-layout reproduces byte-identical pages — pure wasted work (measured as a
130/// 2x render cost above 100 pages, where the total-page digit count first
131/// crosses 2->3; see `benchmarks/`). The sentinel presence is detected at the
132/// exhaustive chokepoint — every sentinel glyph is measured in
133/// `FontContext::char_width`, from any source (HTML `counter()`, margin boxes,
134/// JSX literals). Returns the laid-out pages, the populated font context, and
135/// the number of full layout passes (1, or 2–3 when the width needed fixing).
136///
137/// SCOPING NOTE (investigated 2026-09, abandoned — see benchmarks/): re-laying
138/// out ONLY the running element on a digit-width change, instead of the whole
139/// document, looks like a clean ~2x win but is NOT scopable as written. The
140/// sentinel width is consumed during INJECTION — `inject_fixed_elements` lays
141/// out the footer/margin content — NOT during the flow pass; the flow-time
142/// `measure_node_height` height reservation doesn't touch it. And HTML `@page`
143/// margin boxes are mapped to Fixed nodes (see the `html` crate), so there is no
144/// purely out-of-flow page-number case. Consequently the guard signals (is there
145/// a sentinel? in flow or in a running element? does its height change?) don't
146/// exist yet after a flow-only pass, and a naive "reuse flow + re-inject" split
147/// silently SKIPS the digit-width correction entirely — a correctness regression
148/// that byte-identity caught. Any future attempt must derive those signals from
149/// injection or a document-model scan, not from the flow pass.
150fn layout_with_sentinel_passes(
151    document: &Document,
152) -> (
153    Vec<crate::layout::LayoutPage>,
154    FontContext,
155    u32,
156    Vec<String>,
157) {
158    let mut font_context = FontContext::new();
159    register_document_fonts(&mut font_context, &document.fonts);
160    let engine = LayoutEngine::new();
161    font_context.reset_page_sentinel();
162    let mut pages = engine.layout(document, &font_context);
163    let mut passes = 1u32;
164
165    if font_context.saw_page_sentinel() {
166        for _ in 0..2 {
167            let needed = digits_for_count(pages.len());
168            if needed == font_context.sentinel_digit_count() {
169                break;
170            }
171            font_context.set_sentinel_digit_count(needed);
172            pages = engine.layout(document, &font_context);
173            passes += 1;
174        }
175    }
176    let layout_warnings = engine.take_warnings();
177    (pages, font_context, passes, layout_warnings)
178}
179
180/// Number of full layout passes a document needs (1 for the common case; 2–3
181/// only when a page-number sentinel's reserved width must be corrected).
182/// Exposed as the regression guard for the sentinel re-layout optimization.
183pub fn count_layout_passes(document: &Document) -> u32 {
184    layout_with_sentinel_passes(document).2
185}
186
187/// Render a document to PDF bytes plus any non-fatal warnings (e.g. pdfUa
188/// requested without an embeddable font registered). Same output as `render`;
189/// the warnings surface through the WASM bindings and the HTML wrapper.
190pub fn render_with_warnings(document: &Document) -> Result<(Vec<u8>, Vec<String>), FormeError> {
191    render_with_warnings_and_passes(document).map(|(pdf, warnings, _passes)| (pdf, warnings))
192}
193
194/// Like [`render_with_warnings`], but also returns the number of layout passes
195/// the render took — surfaced through the HTML wrapper for benchmark evidence.
196pub fn render_with_warnings_and_passes(
197    document: &Document,
198) -> Result<(Vec<u8>, Vec<String>, u32), FormeError> {
199    // Coarse phase profiling behind FORME_PROFILE (native only in practice —
200    // `env::var` is Err under wasm, so the timer is never constructed there and
201    // `Instant::now` is never called). Prints layout vs serialize to stderr.
202    let profile = std::env::var("FORME_PROFILE").is_ok();
203    let t_layout = if profile {
204        Some(std::time::Instant::now())
205    } else {
206        None
207    };
208    let (pages, font_context, passes, layout_warnings) = layout_with_sentinel_passes(document);
209    let layout_ms = t_layout.map(|t| t.elapsed().as_secs_f64() * 1000.0);
210
211    let writer = PdfWriter::new();
212    let tagged = document.tagged
213        || document.pdf_ua
214        || matches!(
215            document.pdfa,
216            Some(model::PdfAConformance::A2a) | Some(model::PdfAConformance::A3a)
217        );
218    let t_ser = if profile {
219        Some(std::time::Instant::now())
220    } else {
221        None
222    };
223    let (pdf, warnings) = writer.write(
224        &pages,
225        &document.metadata,
226        &font_context,
227        tagged,
228        document.pdfa.as_ref(),
229        document.pdf_ua,
230        document.embedded_data.as_deref(),
231        &document.attachments,
232        document.zugferd.as_ref(),
233        document.flatten_forms,
234    )?;
235    let warnings = {
236        let mut all = layout_warnings;
237        all.extend(warnings);
238        all
239    };
240    let serialize_ms = t_ser.map(|t| t.elapsed().as_secs_f64() * 1000.0);
241    let pdf = if let Some(ref sig_config) = document.certification {
242        pdf::certify::certify_pdf(&pdf, sig_config)?
243    } else {
244        pdf
245    };
246    if let (Some(l), Some(s)) = (layout_ms, serialize_ms) {
247        eprintln!(
248            "FORME_PROFILE pages={} passes={passes} layout_ms={l:.1} serialize_ms={s:.1}",
249            pages.len()
250        );
251    }
252    Ok((pdf, warnings, passes))
253}
254
255/// Render a document to PDF bytes along with layout metadata.
256///
257/// Same as `render()` but also returns `LayoutInfo` describing the
258/// position and dimensions of every element on every page.
259/// If the document has a `certification` configuration, the output PDF
260/// is digitally signed.
261pub fn render_with_layout(
262    document: &Document,
263) -> Result<(Vec<u8>, LayoutInfo, Vec<String>), FormeError> {
264    let (pages, font_context, _passes, layout_warnings) = layout_with_sentinel_passes(document);
265    let layout_info = LayoutInfo::from_pages(&pages);
266    let writer = PdfWriter::new();
267    let tagged = document.tagged
268        || document.pdf_ua
269        || matches!(
270            document.pdfa,
271            Some(model::PdfAConformance::A2a) | Some(model::PdfAConformance::A3a)
272        );
273    let (pdf, warnings) = writer.write(
274        &pages,
275        &document.metadata,
276        &font_context,
277        tagged,
278        document.pdfa.as_ref(),
279        document.pdf_ua,
280        document.embedded_data.as_deref(),
281        &document.attachments,
282        document.zugferd.as_ref(),
283        document.flatten_forms,
284    )?;
285    let pdf = if let Some(ref sig_config) = document.certification {
286        pdf::certify::certify_pdf(&pdf, sig_config)?
287    } else {
288        pdf
289    };
290    let warnings = {
291        let mut all = layout_warnings;
292        all.extend(warnings);
293        all
294    };
295    Ok((pdf, layout_info, warnings))
296}
297
298/// Return the number of digits needed to display `n` as a decimal string.
299fn digits_for_count(n: usize) -> u32 {
300    if n < 10 {
301        1
302    } else if n < 100 {
303        2
304    } else if n < 1000 {
305        3
306    } else {
307        4
308    }
309}
310
311/// Register custom fonts from the document's `fonts` array.
312fn register_document_fonts(font_context: &mut FontContext, fonts: &[FontEntry]) {
313    use base64::Engine as _;
314    let b64 = base64::engine::general_purpose::STANDARD;
315
316    for entry in fonts {
317        let bytes = if let Some(comma_pos) = entry.src.find(',') {
318            // data URI: "data:font/ttf;base64,AAAA..."
319            b64.decode(&entry.src[comma_pos + 1..]).ok()
320        } else {
321            // raw base64 string
322            b64.decode(&entry.src).ok()
323        };
324
325        if let Some(data) = bytes {
326            font_context
327                .registry_mut()
328                .register(&entry.family, entry.weight, entry.italic, data);
329        }
330    }
331}
332
333/// Render a document described as JSON to PDF bytes.
334pub fn render_json(json: &str) -> Result<Vec<u8>, FormeError> {
335    let document: Document = serde_json::from_str(json)?;
336    render(&document)
337}
338
339/// Render a document described as JSON to PDF bytes along with layout metadata.
340pub fn render_json_with_layout(
341    json: &str,
342) -> Result<(Vec<u8>, LayoutInfo, Vec<String>), FormeError> {
343    let document: Document = serde_json::from_str(json)?;
344    render_with_layout(&document)
345}
346
347/// Render a template with data to PDF bytes.
348///
349/// Takes a template JSON tree (with `$ref`, `$each`, `$if`, operators) and
350/// a data JSON object. Evaluates all expressions, then renders the resulting
351/// document to PDF.
352pub fn render_template(template_json: &str, data_json: &str) -> Result<Vec<u8>, FormeError> {
353    let template: serde_json::Value = serde_json::from_str(template_json)?;
354    let data: serde_json::Value = serde_json::from_str(data_json)?;
355    let resolved = template::evaluate_template(&template, &data)?;
356    let document: Document = serde_json::from_value(resolved)?;
357    render(&document)
358}
359
360/// Render a template with data to PDF bytes along with layout metadata.
361pub fn render_template_with_layout(
362    template_json: &str,
363    data_json: &str,
364) -> Result<(Vec<u8>, LayoutInfo), FormeError> {
365    let template: serde_json::Value = serde_json::from_str(template_json)?;
366    let data: serde_json::Value = serde_json::from_str(data_json)?;
367    let resolved = template::evaluate_template(&template, &data)?;
368    let document: Document = serde_json::from_value(resolved)?;
369    render_with_layout(&document).map(|(pdf, layout, _warnings)| (pdf, layout))
370}
371
372#[cfg(test)]
373mod tests {
374    use super::*;
375
376    #[test]
377    fn test_digits_for_count() {
378        assert_eq!(digits_for_count(0), 1);
379        assert_eq!(digits_for_count(1), 1);
380        assert_eq!(digits_for_count(9), 1);
381        assert_eq!(digits_for_count(10), 2);
382        assert_eq!(digits_for_count(99), 2);
383        assert_eq!(digits_for_count(100), 3);
384        assert_eq!(digits_for_count(999), 3);
385        assert_eq!(digits_for_count(1000), 4);
386    }
387}