PdfViewer¶
PDF embed/object viewer with SafeUrl source.
| Import | from hedron import PdfViewer |
| Distribution | hedron |
| Backend activity | No |
| Normal render mode | RenderMode.FRAGMENT |
Live demo¶
The preview is a local docs simulation (not a running Hedron server). Interactive demos show a “Simulated HTMX” trace when applicable.
Basic use¶
Compose under Page for full documents, or return from a fragment route for HTMX swaps.
How it works¶
Phase 0.15 surface. Prefer native HTML semantics and ordinary HTTP actions.
This component's core behavior is server-rendered HTML and does not require a browser runtime. The preview is ordinary semantic HTML, so keyboard, form, link, and disclosure behavior comes from the platform.
Constructor and parameters¶
PdfViewer(src: 'SafeUrl | str', *, title: 'str' = 'PDF document', allow_external: 'bool' = False, class_: 'str | None' = None, mark: 'str | None' = None, **kwargs: 'object') -> 'None'
| Parameter | Type | Meaning |
|---|---|---|
src |
SafeUrl | str |
Media or document URL (SafeUrl preferred for untrusted input). |
title |
str |
Accessible title (document, iframe, dialog, or media). Default: 'PDF document'. |
allow_external |
bool |
Allow non-same-origin / non-asset URLs when True. Default: False. |
class_ |
str | None |
Optional CSS class string (class in HTML). Default: None. |
mark |
str | None |
Optional stable test mark (data-hedron-mark). Default: None. |
Composition and backend behavior¶
Keep PdfViewer at the smallest semantic boundary. Fragment routes should return only
the replaced region and preserve stable target IDs across success, validation, empty,
loading, and error responses.
PdfViewer is primarily presentational; keep any mutation on an explicit action or component route.
Accessibility¶
Keyboard and screen-reader operable; no-JS fallback required where interactive.
Security¶
Escaping and SafeUrl / TrustedHtml are framework concerns; authorization and data
exposure remain application code. Redact secrets before rendering.
Common mistakes¶
- Do not treat client-only hints (geolocation, browser storage) as authorization.
- Do not copy docs-preview JavaScript into an application server.