Compare commits

..
Author SHA1 Message Date
ephraimduncan 02166af7eb fix: remove the direct url fallback from the migrate script
The fallback uses POSIX shell syntax, but npm on Windows runs scripts in cmd.exe. docker/start.sh keeps the fallback for Docker, and the manual guide sets the two variables.
2026-09-28 10:39:50 +00:00
ephraimduncan a3fbd791de docs: remove the npx migration command that cannot find the schema
From the repository root, `npx prisma migrate deploy` stops with "Could
not find Prisma Schema". It also does not use the fallback for
`NEXT_PRIVATE_DIRECT_DATABASE_URL`. The `npm run prisma:migrate-deploy`
command above it does the same work and uses the fallback.
2026-09-28 10:23:30 +00:00
ephraimduncan 5874b8f8c4 fix: set the direct url for manual migrations
`npm run prisma:migrate-deploy` stopped with error P1012 when
`NEXT_PRIVATE_DIRECT_DATABASE_URL` was not set. If the direct URL is
empty, the script uses `NEXT_PRIVATE_DATABASE_URL`, the same as the
Docker start script.

The manual migration command in the upgrade guide does not use the start
script, and Prisma cannot find the schema at the default path in the
image. The command sets the two variables and gives the path to the
schema.
2026-09-28 10:17:35 +00:00
ephraimduncan c66270ad9d fix: use the database url when the direct url is not set
The Docker start script runs Prisma migrations. The Prisma schema reads
`NEXT_PRIVATE_DIRECT_DATABASE_URL`, and the migrations stopped with error
P1012 when the variable was not set.

If the variable is empty, the start script sets it to
`NEXT_PRIVATE_DATABASE_URL`. This agrees with the documentation and with
docker/production/compose.yml.
2026-09-28 09:38:46 +00:00
Lucas Smith a1d4bec143 fix: accept owner-password protected pdfs (#3396)
Strip encryption from PDFs that open with an empty user password via
libpdf's ignorePermissions, still rejecting user-password PDFs.

Upgrade @libpdf/core to 0.5.1, which also keeps overlapping and layered
text intact during text extraction.

Resolves #3303
2026-09-26 11:23:33 +10:00
10 changed files with 20 additions and 126 deletions
@@ -191,9 +191,6 @@ For manual deployments or troubleshooting:
```bash
# Apply pending migrations
npm run prisma:migrate-deploy
# Or using npx directly
npx prisma migrate deploy
```
<Callout type="info">
@@ -426,8 +426,9 @@ docker pull documenso/documenso:<version>
# Run migrations only
docker run --rm \
-e NEXT_PRIVATE_DATABASE_URL="postgresql://user:password@host:5432/documenso" \
-e NEXT_PRIVATE_DIRECT_DATABASE_URL="postgresql://user:password@host:5432/documenso" \
documenso/documenso:<version> \
npx prisma migrate deploy
npx prisma migrate deploy --schema ../../packages/prisma/schema.prisma
```
<Callout type="warn">
@@ -122,7 +122,7 @@ export const EnvelopeItemEditDialog = ({
toast({
title: t`Failed to read file`,
description: t`The file is not a valid PDF.`,
description: t`The file is not a valid PDF or is password protected.`,
variant: 'destructive',
});
}
@@ -1,5 +1,4 @@
import { useDebouncedValue } from '@documenso/lib/client-only/hooks/use-debounced-value';
import type { TLocalField } from '@documenso/lib/client-only/hooks/use-editor-fields';
import { useCurrentEnvelopeEditor } from '@documenso/lib/client-only/providers/envelope-editor-provider';
import { useCurrentEnvelopeRender } from '@documenso/lib/client-only/providers/envelope-render-provider';
import { PDF_VIEWER_ERROR_MESSAGES } from '@documenso/lib/constants/pdf-viewer-i18n';
@@ -26,7 +25,6 @@ import { cn } from '@documenso/ui/lib/utils';
import { Alert, AlertDescription, AlertTitle } from '@documenso/ui/primitives/alert';
import { Button } from '@documenso/ui/primitives/button';
import { Separator } from '@documenso/ui/primitives/separator';
import { useToast } from '@documenso/ui/primitives/use-toast';
import type { MessageDescriptor } from '@lingui/core';
import { msg } from '@lingui/core/macro';
import { useLingui } from '@lingui/react';
@@ -34,7 +32,6 @@ import { Trans } from '@lingui/react/macro';
import { DocumentStatus, FieldType, RecipientRole } from '@prisma/client';
import { AlertTriangleIcon, FileTextIcon, PencilIcon, SparklesIcon } from 'lucide-react';
import { useEffect, useMemo, useRef, useState } from 'react';
import { useHotkeys } from 'react-hotkeys-hook';
import { useRevalidator, useSearchParams } from 'react-router';
import { isDeepEqual } from 'remeda';
import { match } from 'ts-pattern';
@@ -87,7 +84,6 @@ export const EnvelopeEditorFieldsPage = () => {
const { currentEnvelopeItem, setCurrentEnvelopeItem } = useCurrentEnvelopeRender();
const { _ } = useLingui();
const { toast } = useToast();
const [isAiFieldDialogOpen, setIsAiFieldDialogOpen] = useState(false);
const [isAiEnableDialogOpen, setIsAiEnableDialogOpen] = useState(false);
@@ -100,34 +96,6 @@ export const EnvelopeEditorFieldsPage = () => {
const selectedField = useMemo(() => structuredClone(editorFields.selectedField), [editorFields.selectedField]);
const [copiedField, setCopiedField] = useState<TLocalField | null>(null);
useHotkeys(['ctrl+c', 'meta+c'], (event) => {
// Keep the native copy when the user has selected text.
if (!selectedField || window.getSelection()?.toString()) {
return;
}
event.preventDefault();
setCopiedField(selectedField);
toast({
title: _(msg`Copied field`),
description: _(msg`Copied field to clipboard`),
});
});
useHotkeys(['ctrl+v', 'meta+v'], (event) => {
if (!copiedField) {
return;
}
event.preventDefault();
// Paste the next copy offset from the last one, so repeated pastes do not stack.
setCopiedField(editorFields.duplicateField(copiedField));
});
/**
* Debounce the fields used for overlap detection so we don't recompute on every
* small drag/resize movement, which is expensive on large field counts and can
+1 -1
View File
@@ -92,7 +92,7 @@ export const getUploadErrorMessage = (code: string): ToastMessageDescriptor => {
.with(AppErrorCode.TOO_MANY_REQUESTS, () => FAIR_USE_LIMIT_EXCEEDED_ERROR_MESSAGE)
.with('INVALID_DOCUMENT_FILE', () => ({
title: msg`Error`,
description: msg`You cannot upload encrypted PDFs.`,
description: msg`The file is not a valid PDF or is password protected.`,
}))
.with(AppErrorCode.LIMIT_EXCEEDED, () => ({
title: msg`Error`,
+3
View File
@@ -24,6 +24,9 @@ printf "🏥 Health check: http://localhost:3000/api/health\n"
printf "📊 Certificate status: http://localhost:3000/api/certificate-status\n"
printf "👥 Community: https://github.com/documenso/documenso\n\n"
# The Prisma schema requires a direct URL. Without a connection pooler, it is the same as the database URL.
export NEXT_PRIVATE_DIRECT_DATABASE_URL="${NEXT_PRIVATE_DIRECT_DATABASE_URL:-$NEXT_PRIVATE_DATABASE_URL}"
printf "🗄️ Running database migrations...\n"
npx prisma migrate deploy --schema ../../packages/prisma/schema.prisma
+4 -4
View File
@@ -15,7 +15,7 @@
"dependencies": {
"@ai-sdk/google-vertex": "5.0.48",
"@documenso/prisma": "*",
"@libpdf/core": "^0.4.2",
"@libpdf/core": "^0.5.1",
"@lingui/conf": "^5.6.0",
"@lingui/core": "^5.6.0",
"@marsidev/react-turnstile": "^1.5.0",
@@ -4480,9 +4480,9 @@
"license": "MIT"
},
"node_modules/@libpdf/core": {
"version": "0.4.2",
"resolved": "https://registry.npmjs.org/@libpdf/core/-/core-0.4.2.tgz",
"integrity": "sha512-lbkIqLDZCCxjLpiC+8/Xvaru/ME7iVVoihl9tLqbp/CDUWZNF0q3u7s2tBJB9wRW/SzUWID6YPFvBWws770hrQ==",
"version": "0.5.1",
"resolved": "https://registry.npmjs.org/@libpdf/core/-/core-0.5.1.tgz",
"integrity": "sha512-q+y4AEk9ngqyC1pdX/hNScnfh0ROr4vSiqX4C9CmuBzhtuVukbfTesXCaGvHZ3pksi8AJYDPGQ/0HzSeHZfi3A==",
"license": "MIT",
"dependencies": {
"@noble/ciphers": "^2.2.0",
+1 -1
View File
@@ -106,7 +106,7 @@
"dependencies": {
"@ai-sdk/google-vertex": "5.0.48",
"@documenso/prisma": "*",
"@libpdf/core": "^0.4.2",
"@libpdf/core": "^0.5.1",
"@lingui/conf": "^5.6.0",
"@lingui/core": "^5.6.0",
"@prisma/extension-read-replicas": "^0.4.1",
@@ -633,65 +633,6 @@ const assertDuplicateDeleteFieldPersistedInDatabase = async ({
expect(envelope.fields[0].type).toBe(FieldType.SIGNATURE);
};
// --- Copy and paste fields flow ---
type TCopyPasteFlowResult = {
externalId: string;
};
const runCopyPasteFieldFlow = async (surface: TEnvelopeEditorSurface): Promise<TCopyPasteFlowResult> => {
const externalId = `e2e-copy-paste-${nanoid()}`;
const root = surface.root;
await updateExternalId(surface, externalId);
await setupRecipientsForFieldPlacement(surface);
await clickEnvelopeEditorStep(root, 'addFields');
await expect(root.locator('.konva-container canvas').first()).toBeVisible();
await placeFieldOnPdf(root, 'Signature', { x: 150, y: 150 });
await selectFieldOnCanvas(root, { x: 150, y: 150 });
await root.keyboard.press('ControlOrMeta+c');
await root.keyboard.press('ControlOrMeta+v');
await root.keyboard.press('ControlOrMeta+v');
await expect.poll(async () => getKonvaElementCountForPage(root, 1, '.field-group')).toBe(3);
// Navigate away and back to persist changes.
await clickEnvelopeEditorStep(root, 'upload');
await clickEnvelopeEditorStep(root, 'addFields');
await expect.poll(async () => getKonvaElementCountForPage(root, 1, '.field-group')).toBe(3);
return { externalId };
};
const assertCopyPasteFieldPersistedInDatabase = async ({
surface,
externalId,
}: {
surface: TEnvelopeEditorSurface;
externalId: string;
}) => {
const envelope = await prisma.envelope.findFirstOrThrow({
where: {
externalId,
userId: surface.userId,
teamId: surface.teamId,
type: surface.envelopeType,
},
orderBy: { createdAt: 'desc' },
include: { fields: true },
});
expect(envelope.fields).toHaveLength(3);
expect(envelope.fields.every((field) => field.type === FieldType.SIGNATURE)).toBe(true);
// Each paste is offset from the previous one, so no two fields share a position.
const positions = new Set(envelope.fields.map((field) => `${field.positionX}:${field.positionY}`));
expect(positions.size).toBe(3);
};
// --- Change field type flow ---
type TChangeFieldTypeFlowResult = {
@@ -961,16 +902,6 @@ test.describe('document editor', () => {
});
});
test('copy and paste fields with keyboard shortcuts', async ({ page }) => {
const surface = await openDocumentEnvelopeEditor(page);
const result = await runCopyPasteFieldFlow(surface);
await assertCopyPasteFieldPersistedInDatabase({
surface,
...result,
});
});
test('place and configure all 10 field types', async ({ page }) => {
const surface = await openDocumentEnvelopeEditor(page);
const result = await runAllFieldTypesFlow(surface);
@@ -1033,16 +964,6 @@ test.describe('template editor', () => {
});
});
test('copy and paste fields with keyboard shortcuts', async ({ page }) => {
const surface = await openTemplateEnvelopeEditor(page);
const result = await runCopyPasteFieldFlow(surface);
await assertCopyPasteFieldPersistedInDatabase({
surface,
...result,
});
});
test('place and configure all 10 field types', async ({ page }) => {
const surface = await openTemplateEnvelopeEditor(page);
const result = await runAllFieldTypesFlow(surface);
@@ -9,14 +9,18 @@ export const normalizePdf = async (pdf: Buffer, options: { flattenForm?: boolean
console.error(`PDF normalization error: ${e.message}`);
throw new AppError('INVALID_DOCUMENT_FILE', {
message: 'The document is not a valid PDF',
message: 'The document is not a valid PDF or is password protected',
});
});
if (pdfDoc.isEncrypted) {
throw new AppError('INVALID_DOCUMENT_FILE', {
message: 'The document is encrypted',
});
if (!pdfDoc.isAuthenticated) {
throw new AppError('INVALID_DOCUMENT_FILE', {
message: 'The document is password protected',
});
}
pdfDoc.removeProtection({ ignorePermissions: true });
}
pdfDoc.flattenLayers();