mozilla/pdf.js · error · Error
doc.external is read-only
Error message
doc.external is read-only
What it means
PDF.js's scripting sandbox (src/scripting_api) implements the Acrobat JavaScript `doc` object inside a QuickJS sandbox. Per the Acrobat API specification this property is read-only, so the class defines a getter that returns the current value and a setter that unconditionally throws `Error("doc.<prop> is read-only")`. The throw aborts the currently executing sandboxed script event and is reported back to the host. `external` reports whether the script runs outside Acrobat; pdf.js returns the `DOC_EXTERNAL` constant (false) and forbids writes.
Source
Thrown at src/scripting_api/doc.js:362
}
get dynamicXFAForm() {
return false;
}
set dynamicXFAForm(_) {
throw new Error("doc.dynamicXFAForm is read-only");
}
get external() {
// According to the specification this should be `true` in non-Acrobat
// applications, however we ignore that to avoid bothering users with
// an `alert`-dialog on document load (see issue 15509).
return DOC_EXTERNAL;
}
set external(_) {
throw new Error("doc.external is read-only");
}
get filesize() {
return this._filesize;
}
set filesize(_) {
throw new Error("doc.filesize is read-only");
}
get hidden() {
return false;
}
set hidden(_) {
throw new Error("doc.hidden is read-only");
}
View on GitHub (pinned to 5903d58d58)
Solutions
- Remove the assignment to `doc.external`; read it through the getter instead.
- There is no supported override; the value reflects the host environment constant.
- If you cannot edit the PDF's embedded script, wrap the statement in try/catch so the rest of the form logic still runs.
Example fix
// before doc.external = true; // after // external is read-only — drop the assignment; read via doc.external
Defensive patterns
Strategy: validation
Validate before calling
// Known read-only doc properties (PDF.js scripting_api/doc.js)
const READONLY_DOC_PROPS = new Set([
'author','bookmarkRoot','creator','dataObjects','docID',
'documentFileName','dynamicXFAForm','external','filesize','hidden',
'hostContainer','icons','info','innerAppWindowRect','innerDocWindowRect',
'isModal','keywords','modDate'
]);
if (READONLY_DOC_PROPS.has('external')) {
// skip the write; external is read-only in pdf.js
console.warn('doc.external is read-only in pdf.js');
} else {
doc.external = value;
} Type guard
// Known read-only doc properties (PDF.js scripting_api/doc.js)
const READONLY_DOC_PROPS = new Set([
'author','bookmarkRoot','creator','dataObjects','docID',
'documentFileName','dynamicXFAForm','external','filesize','hidden',
'hostContainer','icons','info','innerAppWindowRect','innerDocWindowRect',
'isModal','keywords','modDate'
]);
const isReadOnlyDocProp = (name) => READONLY_DOC_PROPS.has(name);
// usage: if (!isReadOnlyDocProp('keywords')) doc.keywords = v; Try / catch
try {
doc.external = value;
} catch (e) {
// pdf.js throws Error('doc.external is read-only')
if (/is read-only/.test(e.message)) { /* swallow, expected */ }
else { throw e; }
} Prevention
- Treat every property listed in the Acrobat JS reference as read-only unless pdf.js provides a setter that stores the value.
- Before assigning, check `isReadOnlyDocProp('external')` or grep the setter in src/scripting_api/doc.js for a `throw`.
- When porting scripts from Acrobat, run them against the pdf.js sandbox in the dev server first to surface writes early.
- Prefer reading metadata through the Info dictionary at PDF authoring time rather than mutating it from a script.
When it happens
Trigger: A sandboxed PDF form/script executes an assignment to the property, e.g. `doc.external = value;` or `doc.external++`. Because the setter always throws (there is no condition), any write attempt triggers it.
Common situations: Scripts ported from desktop Acrobat where external was toggled; forms that try to stamp runtime state into document metadata on save/open; and PDFs generated by tools that emit non-spec-compliant JavaScript.
Related errors
- doc.info.${prop} is read-only
- doc.author is read-only
- doc.bookmarkRoot is read-only
- doc.creator is read-only
- doc.dataObjects is read-only
AI-assisted analysis of mozilla/pdf.js@5903d58d58 (2026-08-13).
Data as JSON: /api/errors/1f321b24d895b046.
Report an issue: GitHub.