5f553ece11704c91af77e2b304453b4d41d3e574
Allow document owners to invite external users (no Stirling-PDF account) to sign documents via a one-time share link. Backend: - GuestCertificateService: generates ephemeral PKCS12 keystores keyed by email, with rfc822Name SAN for industry-traceable digital signatures; uses emailProtection EKU, cryptographically random serial numbers, and HMAC-SHA256 derived passwords - SigningFinalizationService: handles GUEST_CERT case in buildKeystore() and getKeystorePassword() - WorkflowParticipantController: defaults certType to GUEST_CERT for unregistered participants, captures hashed-IP audit trail on submission, skips password encryption for GUEST_CERT paths - WorkflowSessionService: sends signing invitation email to guest participants on session creation; redacts email PII in logs - EmailService: adds sendSigningInvitationEmail() with HTML-escaped user-supplied values and javascript: URL guard to prevent XSS Frontend: - GuestSignPage: new token-gated route /sign/:token outside AppProviders; full page-state machine (loading/ready/expired/signed/declined/error) - GuestCertificateChooser: auto-generated cert vs upload P12 chooser - SelectParticipantsStep: refactored to support registered + external (email) participants via tabbed UI with validation - AddParticipantsFlow: same external email tab added for mid-session adds - CreateSessionFlow/SignPopout: thread new Participant[] shape through to split userIds and emails on submit - App.tsx: /sign/:token route with minimal GuestSigningProviders (no auth) - i18n: [guestSigning] keys added to en-GB/translation.toml Tests: - GuestCertificateServiceTest: keystore generation, SAN, deterministic passwords - WorkflowParticipantControllerTest: GUEST_CERT defaulting, audit trail, token guards, encrypt() not called for guest cert - EmailServiceTest: invitation email, HTML injection safety, JS URL guard - GuestSignPage.test.tsx: 9 vitest unit tests (all page states + submit) - SelectParticipantsStep.test.tsx: 15 vitest unit tests - GuestSigningE2E.spec.ts: 19 Playwright E2E tests (route-mocked, no backend) - playwright.config.ts: fix testDir to src/core/tests, use port 5174
feat(docker): update base images to Java 25, Spring 4, Jackson 3, Gradle 9 and optimize JVM options (Project Lilliput) (#5725)
ci: enhance GitHub Actions workflows with Gradle setup, caching improvements, and Docker image testing (#3956)
Stirling PDF - The Open-Source PDF Platform
Stirling PDF is a powerful, open-source PDF editing platform. Run it as a personal desktop app, in the browser, or deploy it on your own servers with a private API. Edit, sign, redact, convert, and automate PDFs without sending documents to external services.
Key Capabilities
- Everywhere you work - Desktop client, browser UI, and self-hosted server with a private API.
- 50+ PDF tools - Edit, merge, split, sign, redact, convert, OCR, compress, and more.
- Automation & workflows - No-code pipelines direct in UI with APIs to process millions of PDFs.
- Enterprise‑grade - SSO, auditing, and flexible on‑prem deployments.
- Developer platform - REST APIs available for nearly all tools to integrate into your existing systems.
- Global UI - Interface available in 40+ languages.
For a full feature list, see the docs: https://docs.stirlingpdf.com
Quick Start
docker run -p 8080:8080 docker.stirlingpdf.com/stirlingtools/stirling-pdf
Then open: http://localhost:8080
For full installation options (including desktop and Kubernetes), see our Documentation Guide.
Resources
Support
- Community Discord
- Bug Reports: Github issues
Contributing
We welcome contributions! Please see CONTRIBUTING.md for guidelines.
For development setup, see the Developer Guide.
For adding translations, see the Translation Guide.
License
Stirling PDF is open-core. See LICENSE for details.
Description
#1 PDF Application on GitHub that lets you edit PDFs on any device anywhere
https://stirling.com
dockerhacktoberfestjavapdfpdf-converterpdf-editorpdf-manipulationpdf-mergerpdf-ocrpdf-toolspdf-web-appspdfmergerself-hosted
Readme
MIT
694 MiB
Languages
Java
49.9%
TypeScript
39.9%
Python
4.3%
CSS
2.7%
Shell
0.9%
Other
2.2%

