Can LiteParse Parse Password-Protected PDF Files? Implementation Guide
Yes. LiteParse decrypts password-protected PDFs transparently when you supply the password through the LiteParseConfig structure. The password propagates through every API layer—from Rust CLI flags and language bindings down to the PDFium extraction engine—enabling normal text extraction and OCR on encrypted documents.
LiteParse, the multi-format document parser from the run-llama organization, treats encrypted PDFs exactly like standard documents once the correct password is provided. Instead of rejecting locked files, the parser accepts a password parameter in its configuration and passes it through every internal layer until it reaches the PDFium library, which handles the actual decryption. This guide examines the source code implementation to demonstrate how password protection works across all LiteParse interfaces.
Password Configuration Architecture
LiteParse centralizes password management in the LiteParseConfig struct, making the feature available consistently across all language bindings and interfaces.
The Core Configuration Structure
In crates/liteparse/src/config.rs (lines 24-26), the LiteParseConfig struct defines the password field as an optional string:
pub struct LiteParseConfig {
pub password: Option<String>,
// ... other fields
}
This structure is instantiated at the entry point of every public API, ensuring the password is available throughout the document lifecycle.
CLI and Language Binding Interfaces
All front-ends expose the password parameter to users:
- Rust CLI:
crates/liteparse/src/main.rs(lines 81-84) exposes a--passwordflag that maps directly to the configuration struct. - Node.js:
packages/node/src/lib.ts(lines 27-33) maps the JavaScriptpasswordconfiguration field to the native Rust struct. - Python:
packages/python/liteparse/parser.py(lines 76-94) accepts apasswordargument in theLiteParseconstructor. - WASM:
crates/liteparse-wasm/src/lib.rs(lines 49-53) mirrors the native configuration, including the password field for browser environments.
Internal Password Propagation to PDFium
Once provided, the password flows through three critical layers before reaching the PDF decryption engine.
Parser Implementation
The parse_input method in crates/liteparse/src/parser.rs (lines 84-87 and 101-103) retrieves the password from the config and passes it to the extraction stage:
// From parser.rs: the password is extracted and forwarded
let password = self.config.password.as_deref();
// ... later passed to document loading
PDF Loading and Decryption
In crates/liteparse/src/extract.rs (lines 5-14), the low-level PDFium wrapper receives the password via load_document or load_document_from_bytes:
// PDFium handles decryption internally when password is provided
let doc = library.load_document(path, password)?;
PDFium then decrypts the file internally using standard PDF encryption algorithms, returning a handle to the unlocked document for normal text extraction.
Conversion Handling for Office Documents
For non-PDF inputs, LiteParse converts files to PDF before extraction. In crates/liteparse/src/conversion.rs (lines 96-110 and 188-190), the conversion helpers forward the password so that password-protected Office documents (Word, Excel, PowerPoint) can be unlocked by LibreOffice before conversion to PDF.
Implementation Examples by Platform
The following examples demonstrate how to supply passwords across LiteParse's supported environments.
Rust CLI
Use the --password flag when parsing from the command line:
liteparse parse my-protected.pdf --password secret123
Node.js
Pass the password in the configuration object when instantiating the parser:
import { LiteParse } from "liteparse";
const parser = new LiteParse({
password: "secret123", // decrypts protected PDFs
ocrEnabled: false,
});
const result = await parser.parse("my-protected.pdf");
console.log(result.text);
Python
Supply the password as a constructor argument:
from liteparse import LiteParse
parser = LiteParse(password="secret123") # handles decryption
result = parser.parse("my-protected.pdf")
print(result.text)
Browser WASM
When using the WebAssembly build, include the password in the initialization options:
import { LiteParse } from "liteparse-wasm";
const parser = new LiteParse({ password: "secret123" });
const data = await fetch("protected.pdf").then(r => r.arrayBuffer());
const result = await parser.parse(data);
console.log(result.text);
Summary
- Unified Configuration: The
passwordfield inLiteParseConfig(config.rs) provides a single entry point for decryption across all platforms. - Full API Coverage: Rust CLI (
--passwordflag), Node.js, Python, and WASM bindings all support password-protected documents. - PDFium Integration: Passwords propagate to
extract.rs, where PDFium'sload_documenthandles the actual cryptographic unlocking. - Office Document Support: The conversion layer (
conversion.rs) forwards passwords to LibreOffice, enabling parsing of encrypted Word and Excel files after conversion. - Transparent Processing: Once decrypted, password-protected PDFs undergo identical text extraction and OCR workflows as unencrypted files.
Frequently Asked Questions
Does LiteParse support password-protected Microsoft Office documents?
Yes. When you parse a password-protected Word or Excel file, LiteParse forwards the password through the conversion layer in crates/liteparse/src/conversion.rs (lines 96-110). This allows LibreOffice to unlock the document before converting it to PDF for text extraction.
How does the password reach the PDF engine?
The password travels through a defined pipeline: it starts in LiteParseConfig (config.rs), is retrieved by parse_input (parser.rs lines 84-87), and is passed to PDFium's load_document function in extract.rs (lines 5-14), which performs the decryption internally.
Is the password stored persistently by LiteParse?
No. The password exists only as an Option<String> within the LiteParseConfig instance during the parsing session. It is not cached to disk or retained in memory after the LiteParse instance is dropped, and it is passed directly to the underlying PDFium library without intermediate logging.
What happens if I provide the wrong password for an encrypted PDF?
If the password is incorrect, PDFium's load_document call in extract.rs will fail to decrypt the document, and LiteParse will propagate this error back through the API. The parser returns a decryption error rather than attempting to process the encrypted binary content.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →