{"record":{"id":"ebb9db41fc78a10e","repo":"mozilla/pdf.js","slug":"doc-docid-is-read-only","errorCode":null,"errorMessage":"doc.docID is read-only","messagePattern":"doc\\.docID is read-only","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"src/scripting_api/doc.js","lineNumber":335,"sourceCode":"\n  set dirty(dirty) {\n    this._dirty = dirty;\n  }\n\n  get disclosed() {\n    return this._disclosed;\n  }\n\n  set disclosed(disclosed) {\n    this._disclosed = disclosed;\n  }\n\n  get docID() {\n    return this._docID;\n  }\n\n  set docID(_) {\n    throw new Error(\"doc.docID is read-only\");\n  }\n\n  get documentFileName() {\n    return this._documentFileName;\n  }\n\n  set documentFileName(_) {\n    throw new Error(\"doc.documentFileName is read-only\");\n  }\n\n  get dynamicXFAForm() {\n    return false;\n  }\n\n  set dynamicXFAForm(_) {\n    throw new Error(\"doc.dynamicXFAForm is read-only\");\n  }\n","sourceCodeStart":317,"sourceCodeEnd":353,"githubUrl":"https://github.com/mozilla/pdf.js/blob/5903d58d58e4dd9ce6ffa3834aea8480f06b4ada/src/scripting_api/doc.js#L317-L353","documentation":"PDF.js's scripting sandbox (src/scripting_api) implements the Acrobat JavaScript `doc` object inside a QuickJS sandbox. Per the Acrobat API specification this property is read-only, so the class defines a getter that returns the current value and a setter that unconditionally throws `Error(\"doc.<prop> is read-only\")`. The throw aborts the currently executing sandboxed script event and is reported back to the host. `docID` is the permanent document identifier array (seeded from `data.docID`, default `[\"\", \"\"]`); immutable per spec.","triggerScenarios":"A sandboxed PDF form/script executes an assignment to the property, e.g. `doc.docID = value;` or `doc.docID++`. Because the setter always throws (there is no condition), any write attempt triggers it.","commonSituations":"Scripts ported from desktop Acrobat where docID could be reset; forms that try to stamp runtime state into document metadata on save/open; and PDFs generated by tools that emit non-spec-compliant JavaScript.","solutions":["Remove the assignment to `doc.docID`; read it through the getter instead.","The docID is fixed when the PDF is created/signed; regenerate the PDF to change it.","If you cannot edit the PDF's embedded script, wrap the statement in try/catch so the rest of the form logic still runs."],"exampleFix":"// before\ndoc.docID = [\"id1\",\"id2\"];\n// after\n// docID is read-only — drop the assignment; read via doc.docID","handlingStrategy":"validation","validationCode":"// Known read-only doc properties (PDF.js scripting_api/doc.js)\nconst READONLY_DOC_PROPS = new Set([\n  'author','bookmarkRoot','creator','dataObjects','docID',\n  'documentFileName','dynamicXFAForm','external','filesize','hidden',\n  'hostContainer','icons','info','innerAppWindowRect','innerDocWindowRect',\n  'isModal','keywords','modDate'\n]);\nif (READONLY_DOC_PROPS.has('docID')) {\n  // skip the write; docID is read-only in pdf.js\n  console.warn('doc.docID is read-only in pdf.js');\n} else {\n  doc.docID = value;\n}","typeGuard":"// Known read-only doc properties (PDF.js scripting_api/doc.js)\nconst READONLY_DOC_PROPS = new Set([\n  'author','bookmarkRoot','creator','dataObjects','docID',\n  'documentFileName','dynamicXFAForm','external','filesize','hidden',\n  'hostContainer','icons','info','innerAppWindowRect','innerDocWindowRect',\n  'isModal','keywords','modDate'\n]);\nconst isReadOnlyDocProp = (name) => READONLY_DOC_PROPS.has(name);\n// usage: if (!isReadOnlyDocProp('keywords')) doc.keywords = v;","tryCatchPattern":"try {\n  doc.docID = value;\n} catch (e) {\n  // pdf.js throws Error('doc.docID is read-only')\n  if (/is read-only/.test(e.message)) { /* swallow, expected */ }\n  else { throw e; }\n}","preventionTips":["Treat every property listed in the Acrobat JS reference as read-only unless pdf.js provides a setter that stores the value.","Before assigning, check `isReadOnlyDocProp('docID')` or grep the setter in src/scripting_api/doc.js for a `throw`.","When porting scripts from Acrobat, run them against the pdf.js sandbox in the dev server first to surface writes early.","Prefer reading metadata through the Info dictionary at PDF authoring time rather than mutating it from a script."],"tags":["scripting","acrobat-api","read-only"],"backgroundTag":null,"analyzedSha":"5903d58d58e4dd9ce6ffa3834aea8480f06b4ada","analyzedAt":"2026-08-13T02:28:27.364Z","schemaVersion":2},"datasetVersion":"2026-08-13T04:17:16.726Z"}