Security Recommendations for SelectPdf Html To Pdf Converter | |
SelectPdf Html To Pdf Converter is a .NET library that offers the possibility to convert web pages to PDF. The conversion from HTML to PDF implies the rendering of the web page being converted. Because of the support to run complex HTML/CSS/Javascript, a number of things need to be taken into consideration when using SelectPdf, to make sure your application remains secure.
If you convert your own files to pdf and know exactly what they contain, you are fine. But if you take external files/code to convert to PDF from users you do not know, follow the following recommendations.
Control input
Check the content of the web page being converted. Look for code (especially javascript) that might harm your system. Sanitizing user input can be difficult and attackers can sometimes find a way around the protection.
Retrict access
If you only access the system from certain locations, restrict the access to it limiting the IP addresses allowed.
Disable javascript execution
If you do not need to execute javascript, disable it setting the following property:
Disable access to local files
If you do not need to access local server files during the conversion, disable access setting the following property:
Isolate conversions of pages you do not trust
By default the engine may run inside your application's process (ChromiumEngineHostMode). A page you do not trust can be converted in a separate engine process instead, so that a crash or a hang stays out of your application:
Do not share the HTTP cache between users
When the engine runs inside your application it keeps its HTTP cache from one conversion to the next by default (HttpCache), which makes repeated conversions faster. The cache is keyed by address, not by the user a conversion runs for, so a response one conversion fetched can be served to the next. If your application converts pages on behalf of different users whose content must stay separate, start every conversion with an empty cache - or keep only resources from other sites, which never includes the converted page's own responses: