Skip to content

[Bug]: PDF viewer: text layer not rendered (no text selection, toolbar broken) on non-secure (HTTP) pages since Firefox 156 – crypto.randomUUID is not a function #22107

Description

@vanjaljubojevic

Affected versions: Firefox 156, 157 (Windows). Last working: Firefox 155.
I tracked down the root cause; details below.

Steps to reproduce:

  1. Open any PDF served over plain HTTP from a non-localhost host (i.e. not a secure
    context), so it opens in the built-in PDF viewer.
  2. Try to select text in the PDF.

The PDF can be opened directly in a tab; it does not need to be embedded. Embedding
it in an <iframe> on an HTTP page behaves the same way.

Actual results:

  • Pages are drawn, but text cannot be selected or copied; links/annotations missing;
    toolbar functions do not work. The document behaves like an image.
  • Console: "renderView: TypeError: crypto.randomUUID is not a function"

Expected results:

  • Text layer is rendered and text can be selected, as in Firefox 155.

The same PDF works when served from localhost, or when the host is added to
dom.securecontext.allowlist, which confirms this depends on the secure context.

Root cause:

  • crypto.randomUUID() is [SecureContext]-only, so it is undefined in the viewer
    whenever the PDF is loaded over HTTP (opened directly or in an iframe).
  • In the MOZCENTRAL build, getUuid() calls crypto.randomUUID() without a fallback
    (the typeof check is only kept for the generic build; see pdf.js PR Simplify the getUuid helper function #19084).
  • Up to Firefox 155 getUuid() was only reached from editor/image code, so normal
    viewing was not affected.
  • pdf.js PR Expose the table structure attributes in the struct tree #21702 (commit 240bfee, "Expose the table structure attributes in the
    struct tree"), shipped in Firefox 156 (pdf.js 6.3.237), added to
    StructTreeLayerBuilder:
    #structElementIdPrefix = pdfjs_internal_struct_${getUuid()}_;
  • StructTreeLayerBuilder is constructed for every page in PDFPageView, right before
    the text layer is rendered:
    this.structTreeLayer ||= new StructTreeLayerBuilder(pdfPage, viewport.rawDims);
    const textLayerPromise = this.textLayer ? this.#renderTextLayer() : null;
  • The field initializer throws, the promise chain rejects, and the text and
    annotation layers are never created. The error is caught and logged in
    PDFRenderingQueue.renderView.

Possible fixes:

  • Restore the crypto.getRandomValues() fallback in getUuid() for the MOZCENTRAL
    build, or
  • use a non-crypto unique prefix in StructTreeLayerBuilder (e.g. a module-level
    counter), since the id only needs to be unique within the document.

Regression range: Firefox 155 (pdf.js 6.3.72) works, Firefox 156 (pdf.js 6.3.237)
is broken. Regressed by pdf.js PR #21702. This affects every PDF opened over plain
HTTP, so it may have broad impact. It looks like it belongs in Firefox :: PDF Viewer.

Bugzilla: https://bugzilla.mozilla.org/show_bug.cgi?id=2075182

Web browser and its version

Firefox 157.0 (also reproducible on 156; works on 155)

Operating system and its version

Windows 11 (10.0.26100). The bug is not OS-specific: it is caused by pdf.js code and depends only on the page being loaded over HTTP.

PDF.js version

Built-in Firefox PDF viewer (pdf.js 6.3.335 in Firefox 157, 6.3.237 in Firefox 156)

Is the bug present in the latest PDF.js version?

Yes

Is a browser extension

No

Steps to reproduce the problem

Steps to reproduce:

  1. Open any PDF served over plain HTTP from a non-localhost host (i.e. not a secure
    context), so it opens in the built-in PDF viewer.
  2. Try to select text in the PDF.

The PDF can be opened directly in a tab; it does not need to be embedded. Embedding
it in an <iframe> on an HTTP page behaves the same way.

What is the expected behavior?

  • Text layer is rendered and text can be selected, as in Firefox 155 (and with all menu buttons enabled).

What went wrong?

  • Pages are drawn, but text cannot be selected or copied; links/annotations missing;
    toolbar functions do not work. The document behaves like an image.
  • Console: "renderView: TypeError: crypto.randomUUID is not a function"

Link to a viewer

No response

Additional context

No response

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    Priority

    None yet

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions