Example E045 : encryption and permissions

User and owner passwords, and the permission flags that control what a viewer will allow.

User and owner passwords, and the permission flags that control what a viewer will allow.

PDF

E045_encryption_and_permissions.pdf

Source Code

<?php

declare(strict_types=1);

/**
 * E045_encryption_and_permissions.php
 *
 * @since       2026-04-27
 * @category    Library
 * @package     Pdf
 * @author      Nicola Asuni <info@tecnick.com>
 * @copyright   2002-2026 Nicola Asuni - Tecnick.com LTD
 * @license     https://www.gnu.org/copyleft/lesser.html GNU-LGPL v3 (see LICENSE)
 * @link        https://github.com/tecnickcom/tc-lib-pdf
 *
 * This file is part of tc-lib-pdf software library.
 */

// NOTE: local file reads (images, fonts, attachments) are restricted to an allowlist of
// trusted paths that covers this package tree, so run the examples in place. To read assets
// from other locations, list them in the 'allowedPaths' entry of the fileOptions constructor
// parameter (see E047_remote_resources_security.php).

// NOTE: run make fonts in the project root to generate the dependencies and example fonts.

// autoloader when using Composer
require __DIR__ . '/../vendor/autoload.php';

// define fonts directory
\define('K_PATH_FONTS', \realpath(__DIR__ . '/../vendor/tecnickcom/tc-lib-pdf-font/target/fonts'));

// autoloader when using RPM or DEB package installation
//require ('/usr/share/php/Com/Tecnick/Pdf/autoload.php');

$fileId = \md5('E045_encryption_and_permissions');
$encrypt = new \Com\Tecnick\Pdf\Encrypt\Encrypt(
    enabled: true,
    file_id: $fileId,
    mode: 2,
    permissions: ['modify', 'copy', 'annot-forms', 'assemble'],
    user_pass: 'demo-user',
    owner_pass: 'demo-owner',
);

// main TCPDF object
$pdf = new \Com\Tecnick\Pdf\Tcpdf(
    unit: \Com\Tecnick\Pdf\Page\Unit::Millimeter,
    isunicode: true,
    subsetfont: false,
    compress: true,
    mode: \Com\Tecnick\Pdf\PdfConformance::None,
    objEncrypt: $encrypt,
);

// ----------

$pdf->setCreator('tc-lib-pdf');
$pdf->setAuthor('Nicola Asuni');
$pdf->setSubject('tc-lib-pdf example: 045');
$pdf->setTitle('Encryption and Permissions');
$pdf->setKeywords('TCPDF tc-lib-pdf encryption permissions user password owner password rights');
$pdf->setPDFFilename('E045_encryption_and_permissions.pdf');

$pdf->setViewerPreferences(['DisplayDocTitle' => true]);

$pdf->enableDefaultPageContent();

// ----------
// Insert fonts

$bfont = $pdf->font->insert($pdf->pon, 'helvetica', '', 10);

$page01 = $pdf->addPage();
$pdf->page->addContent($bfont['out']);

$html = <<<HTML
    <h1>Encryption and Permissions</h1>
    <p>This document demonstrates PDF encryption and permission controls using tc-lib-pdf.
    The file is protected with a user password (<em>demo-user</em>) and an owner password (<em>demo-owner</em>).
    Encryption restricts unauthorized access while the owner password grants full control.
    The allowed permissions for this document are: <strong>modify</strong>, <strong>copy</strong>,
    <strong>annot-forms</strong>, and <strong>assemble</strong>.
    All other operations, such as printing, are denied.</p>
    HTML;

$pdf->addHTMLCell(html: $html, posx: 20, posy: 10, width: 180);

// ----------

// get PDF document as raw string
$rawpdf = $pdf->getOutPDFString();

// Various output modes:

//$pdf->savePDF(\dirname(__DIR__).'/target', $rawpdf);
$pdf->renderPDF(rawpdf: $rawpdf);

//$pdf->downloadPDF($rawpdf);
//echo $pdf->getMIMEAttachmentPDF($rawpdf);