Anthony Stirling 7111f0d2df refactor: improve security and code quality with Pattern instances
Replace regex string literals with compiled Pattern instances for better
performance and readability.

Security improvements:
- MobileScannerService: Add input validation patterns
  - Filename sanitization pattern
  - Session ID validation pattern
  - File extension validation pattern
  - Prevents path traversal and injection attacks

- SvgSanitizer: Enhanced SVG sanitization

Code quality improvements:
- Convert regex string literals to Pattern.compile() across codebase
- Better performance (patterns compiled once vs per-use)
- More explicit intent in code
- Easier to maintain and test

Changed files:
- Controllers: MergeController, ConvertPdfJsonController, StampController,
  PipelineDirectoryProcessor, ReactRoutingController, UIDataTessdataController
- Services: PdfJsonConversionService, PdfJsonFallbackFontService,
  SharedSignatureService, TotpService, SignatureService
- Core: SPDFApplication
- Tests updated accordingly

Related: #5680 (if already merged, this consolidates remaining changes)
2026-02-16 10:44:21 +00:00
2026-02-06 13:45:32 +00:00
2025-12-21 10:40:32 +00:00
2025-12-02 17:15:29 +00:00
2025-09-04 14:08:28 +01:00
2026-02-06 18:06:01 +00:00

Stirling PDF logo

Stirling PDF - The Open-Source PDF Platform

Stirling PDF is a powerful, open-source PDF editing platform. Run it as a personal desktop app, in the browser, or deploy it on your own servers with a private API. Edit, sign, redact, convert, and automate PDFs without sending documents to external services.

Docker Pulls Discord OpenSSF Scorecard GitHub Repo stars

Stirling PDF - Dashboard

Key Capabilities

  • Everywhere you work - Desktop client, browser UI, and self-hosted server with a private API.
  • 50+ PDF tools - Edit, merge, split, sign, redact, convert, OCR, compress, and more.
  • Automation & workflows - No-code pipelines direct in UI with APIs to process millions of PDFs.
  • Enterprise‑grade - SSO, auditing, and flexible on‑prem deployments.
  • Developer platform - REST APIs available for nearly all tools to integrate into your existing systems.
  • Global UI - Interface available in 40+ languages.

For a full feature list, see the docs: https://docs.stirlingpdf.com

Quick Start

docker run -p 8080:8080 docker.stirlingpdf.com/stirlingtools/stirling-pdf

Then open: http://localhost:8080

For full installation options (including desktop and Kubernetes), see our Documentation Guide.

Resources

Support

Contributing

We welcome contributions! Please see CONTRIBUTING.md for guidelines.

For development setup, see the Developer Guide.

For adding translations, see the Translation Guide.

License

Stirling PDF is open-core. See LICENSE for details.

Languages
Java 49.9%
TypeScript 39.9%
Python 4.3%
CSS 2.7%
Shell 0.9%
Other 2.2%