pypi xhtml2pdf 0.2.22
CSS positioning, server-mode security limits, and 18 issues fixed

4 hours ago

CSS positioning. position: relative, absolute and fixed now work, with top/right/bottom/left and z-index. An absolute box is placed from its positioned ancestor, so you can put text over an image. A fixed box repeats on every page, and a negative z-index paints under the flow. These properties used to be ignored (#449, #566, #638).

Safer rendering of untrusted HTML. ResourceAccessPolicy.server() turns on a full set of limits in one call:

  • max_local_bytes and max_image_pixels, checked before an image is decoded
  • budgets for the whole render: resources, total bytes, fetch and render time, document size and nesting depth, with the new RenderLimitError
  • refusal of untrusted PDF backgrounds
  • a private temporary directory for each render
    Every limit is off by default, so existing code behaves the same. The security guide now has a checklist for deploying on a server.

Page breaks. page-break-before/after/inside: avoid and the CSS 3 break-* properties are supported (#27).

Bug fixes

  • color: transparent and hex colours with alpha (#rgba, #rrggbbaa) (#811)
  • Tables: an empty <tr> no longer aborts the document (#323); <thead>/<tbody>/<tfoot> backgrounds are painted (#806); a rowspan stops at the end of its group (#470)
  • A grey PNG with alpha no longer comes out as a black box (#349)
  • rem is relative to the root font size (#726)
  • <pdf:pagenumber/> alone in its block now prints (#670)
  • <a href="#x"> links to any id="x" (#615); an image inside a link is clickable (#491)
  • @page margins combined with a content @frame (#303, #765)
  • -pdf-keep-in-frame-mode is read from the <td> (#220)
  • Right-to-left list markers are drawn on the right (#663)
  • Windows drive-letter paths are no longer taken for URLs (#447)
  • xhtml2pdf - - writes a valid PDF to stdout (#464); the debug log no longer dumps the source document (#92)
  • Signing inputs outside the document's directory work again, and an input that can't be read is reported by name; signature trust roots are loaded from their own files
  • Importing xhtml2pdf no longer changes how ReportLab's own ParaFrag.clone behaves in your process

⚠️ Requirements

ReportLab 4.4.9 is now the minimum (it was 4.0.4). The <pdf:toc> support has needed 4.4.9 since 0.2.19, so any document with a <pdf:toc> already failed on older versions. CI now also tests this minimum version.

Full notes: https://xhtml2pdf.readthedocs.io/en/latest/release-notes.html

Full Changelog: v0.2.21...v0.2.22

Don't miss a new xhtml2pdf release

NewReleases is sending notifications on new releases.