You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[Bug]: PDF viewer: text layer not rendered (no text selection, toolbar broken) on non-secure (HTTP) pages since Firefox 156 – crypto.randomUUID is not a function #22107
Affected versions: Firefox 156, 157 (Windows). Last working: Firefox 155.
I tracked down the root cause; details below.
Steps to reproduce:
Open any PDF served over plain HTTP from a non-localhost host (i.e. not a secure
context), so it opens in the built-in PDF viewer.
Try to select text in the PDF.
The PDF can be opened directly in a tab; it does not need to be embedded. Embedding
it in an <iframe> on an HTTP page behaves the same way.
Actual results:
Pages are drawn, but text cannot be selected or copied; links/annotations missing;
toolbar functions do not work. The document behaves like an image.
Console: "renderView: TypeError: crypto.randomUUID is not a function"
Expected results:
Text layer is rendered and text can be selected, as in Firefox 155.
The same PDF works when served from localhost, or when the host is added to
dom.securecontext.allowlist, which confirms this depends on the secure context.
Root cause:
crypto.randomUUID() is [SecureContext]-only, so it is undefined in the viewer
whenever the PDF is loaded over HTTP (opened directly or in an iframe).
In the MOZCENTRAL build, getUuid() calls crypto.randomUUID() without a fallback
(the typeof check is only kept for the generic build; see pdf.js PR Simplify the getUuid helper function #19084).
Up to Firefox 155 getUuid() was only reached from editor/image code, so normal
viewing was not affected.
pdf.js PR Expose the table structure attributes in the struct tree #21702 (commit 240bfee, "Expose the table structure attributes in the
struct tree"), shipped in Firefox 156 (pdf.js 6.3.237), added to
StructTreeLayerBuilder:
#structElementIdPrefix = pdfjs_internal_struct_${getUuid()}_;
StructTreeLayerBuilder is constructed for every page in PDFPageView, right before
the text layer is rendered:
this.structTreeLayer ||= new StructTreeLayerBuilder(pdfPage, viewport.rawDims);
const textLayerPromise = this.textLayer ? this.#renderTextLayer() : null;
The field initializer throws, the promise chain rejects, and the text and
annotation layers are never created. The error is caught and logged in
PDFRenderingQueue.renderView.
Possible fixes:
Restore the crypto.getRandomValues() fallback in getUuid() for the MOZCENTRAL
build, or
use a non-crypto unique prefix in StructTreeLayerBuilder (e.g. a module-level
counter), since the id only needs to be unique within the document.
Regression range: Firefox 155 (pdf.js 6.3.72) works, Firefox 156 (pdf.js 6.3.237)
is broken. Regressed by pdf.js PR #21702. This affects every PDF opened over plain
HTTP, so it may have broad impact. It looks like it belongs in Firefox :: PDF Viewer.
Affected versions: Firefox 156, 157 (Windows). Last working: Firefox 155.
I tracked down the root cause; details below.
Steps to reproduce:
context), so it opens in the built-in PDF viewer.
The PDF can be opened directly in a tab; it does not need to be embedded. Embedding
it in an <iframe> on an HTTP page behaves the same way.
Actual results:
toolbar functions do not work. The document behaves like an image.
Expected results:
The same PDF works when served from localhost, or when the host is added to
dom.securecontext.allowlist, which confirms this depends on the secure context.
Root cause:
whenever the PDF is loaded over HTTP (opened directly or in an iframe).
(the typeof check is only kept for the generic build; see pdf.js PR Simplify the
getUuidhelper function #19084).viewing was not affected.
struct tree"), shipped in Firefox 156 (pdf.js 6.3.237), added to
StructTreeLayerBuilder:
#structElementIdPrefix =
pdfjs_internal_struct_${getUuid()}_;the text layer is rendered:
this.structTreeLayer ||= new StructTreeLayerBuilder(pdfPage, viewport.rawDims);
const textLayerPromise = this.textLayer ? this.#renderTextLayer() : null;
annotation layers are never created. The error is caught and logged in
PDFRenderingQueue.renderView.
Possible fixes:
build, or
counter), since the id only needs to be unique within the document.
Regression range: Firefox 155 (pdf.js 6.3.72) works, Firefox 156 (pdf.js 6.3.237)
is broken. Regressed by pdf.js PR #21702. This affects every PDF opened over plain
HTTP, so it may have broad impact. It looks like it belongs in Firefox :: PDF Viewer.
Bugzilla: https://bugzilla.mozilla.org/show_bug.cgi?id=2075182
Web browser and its version
Firefox 157.0 (also reproducible on 156; works on 155)
Operating system and its version
Windows 11 (10.0.26100). The bug is not OS-specific: it is caused by pdf.js code and depends only on the page being loaded over HTTP.
PDF.js version
Built-in Firefox PDF viewer (pdf.js 6.3.335 in Firefox 157, 6.3.237 in Firefox 156)
Is the bug present in the latest PDF.js version?
Yes
Is a browser extension
No
Steps to reproduce the problem
Steps to reproduce:
context), so it opens in the built-in PDF viewer.
The PDF can be opened directly in a tab; it does not need to be embedded. Embedding
it in an <iframe> on an HTTP page behaves the same way.
What is the expected behavior?
What went wrong?
toolbar functions do not work. The document behaves like an image.
Link to a viewer
No response
Additional context
No response