How to control external resources

GroupDocs.Signature does not load the external resources a document links to, unless you allow them. This article explains what external resources are, why they are skipped, and how to allow the ones you trust with the LoadOptions class.

Note
External resources are skipped by default starting with GroupDocs.Signature for .NET 26.9. Earlier versions loaded them.

What are external resources?

A document can refer to resources that are stored outside it instead of inside it:

FormatExternal resources
Word Processing documentslinked images, pictures inserted by an INCLUDEPICTURE field
Presentationslinked pictures
Spreadsheetspictures linked to a file or an address
SVG imagesimages, and style sheets imported with @import
Archiveswhatever the documents inside them refer to

Hyperlinks are not external resources: GroupDocs.Signature never follows them.

Security considerations

Loading an external resource means requesting the address written in the document. When the documents come from other people, that is a risk:

  • Server-side request forgery. A document can make your server request internal addresses, such as a cloud metadata endpoint or a service on localhost.
  • Credential leaks. A UNC path (\\host\share\image.png) can make Windows send the account’s NTLM credentials to another host.
  • Offline installations. On a machine without network access the requests fail or wait for a time-out.

That is why GroupDocs.Signature skips external resources by default. A skipped resource is not drawn in page previews or in documents saved as images, and image, barcode and QR-code search does not see it. Embedded images are not affected, and a signed Word document keeps its links.

Skip external resources (default)

Nothing to set:

using (Signature signature = new Signature("sample.docx"))
{
    // External resources of sample.docx are not loaded.
}

This is the same as setting the SkipExternalResources property explicitly:

LoadOptions loadOptions = new LoadOptions
{
    SkipExternalResources = true
};
using (Signature signature = new Signature("sample.docx", loadOptions))
{
}

Allow specific external resources

List the parts of the addresses you trust in the WhitelistedResources property. A resource is loaded when its address contains one of them, ignoring case. Empty entries are ignored. Prefer long fragments: cdn.example.com would also match https://attacker.test/?cdn.example.com.

LoadOptions loadOptions = new LoadOptions
{
    WhitelistedResources = new List<string>
    {
        "https://cdn.example.com/images/"
    }
};
using (Signature signature = new Signature("sample.docx", loadOptions))
{
    // Only images from https://cdn.example.com/images/ are loaded.
}

Load all external resources

Only for documents you trust:

LoadOptions loadOptions = new LoadOptions
{
    SkipExternalResources = false
};
using (Signature signature = new Signature("trusted.docx", loadOptions))
{
    // Every external resource is loaded.
}

Documents inside archives and SVG images

  • Archives: documents inside an archive follow the settings you pass for the archive.
  • SVG images: before it reads an SVG image, GroupDocs.Signature removes the references it will not load. An SVG image that is not well-formed XML cannot be checked, so it is rejected with GroupDocsSignatureException while external resources are skipped.

Upgrading from LoadExternalResources

Earlier versions had LoadOptions.LoadExternalResources, which loaded external resources by default and has the opposite meaning:

Earlier codeSame effect now
LoadExternalResources = falseSkipExternalResources = true, the default
LoadExternalResources = trueSkipExternalResources = false

LoadExternalResources still works, but it is obsolete: use SkipExternalResources in new code.

See Network access and data privacy for every situation in which GroupDocs.Signature uses the network.

More resources

GitHub Examples

You may easily run the code above and see the feature in action in our GitHub examples:

Free Online Apps

Along with the full-featured .NET library, we provide simple but powerful free online apps.

To sign PDF, Word, Excel, PowerPoint, and other documents you can use the online apps from the GroupDocs.Signature App Product Family.

Close
Loading

Analyzing your prompt, please hold on...

An error occurred while retrieving the results. Please refresh the page and try again.