# SVG vector subset for Web V1

SVG is treated as untrusted local input. The SVG adapter parses detached XML, rejects unknown elements and attributes, and passes only a checked tree to svg2pdf.js and jsPDF. It does not place source SVG in the live application DOM and has **no raster fallback**. An unsupported file fails the entire Convert/Merge operation with its filename.

Supported drawing elements: `<rect>`, `<circle>`, `<ellipse>`, `<line>`, `<polyline>`, `<polygon>`, `<path>`, and nested `<g>`. `<title>` and `<desc>` may contain plain text but do not become drawn PDF text. Supported path commands: M, L, H, V, C, S, Q, T, A, Z, including lowercase variants. Basic transforms (matrix, translate, scale, rotate, skewX, skewY), solid named colors from the explicit adapter list, `#RGB`, `#RRGGBB`, `none`, fill/stroke opacity, stroke width/caps/joins/dashes, and evenodd fill rules are allowed. Basic standalone `<text>` is also supported as PDF text, as specified below.

The root must provide both width and height, or a valid four-number viewBox. Width/height accept unitless pixels, px, pt, mm, cm, or in. Both dimensions must be positive and finite. A viewBox-only SVG uses its viewBox width and height in CSS pixels. If dimensions and viewBox coexist, content is centered and fitted with `xMidYMid meet`, without arbitrary stretching. CSS pixels map to 96 per inch; page points are 0.75 per pixel, proportionally scaled down for PDF page limits. The adapter enforces 1 MiB, 5,000 element, 64 nesting level, coordinate magnitude, and path token limits.

The adapter rejects scripts, event attributes, CSS/style, complex text (`tspan`, `textPath`), `<image>`, `<use>`, `<foreignObject>`, embedded HTML, DTD/entities, processing instructions, references, gradients, filters, masks, patterns, clipping, external URLs, data URLs, unsupported paint/color formats, invalid geometry, and unknown constructs. This deliberately strict subset avoids fetching external resources or executing content. It also avoids silently dropping unsupported content. SVG feature fidelity beyond the documented subset is not claimed.

## Basic text and font policy

`<text>` may appear directly in the root or a group, with no child elements. Content must be nonempty printable ASCII (U+0020–U+007E). XML entities such as `&amp;` are decoded; ordinary spaces, tabs and line breaks collapse to one space and edge whitespace is removed. This is one text run, not multiline layout. Unsupported characters fail clearly; convert other lettering to paths in the source.

Supported text attributes are single unitless numeric `x`/`y` (default 0, alphabetic baseline), positive `font-size` (default 16 CSS pixels, same absolute units as root dimensions), solid `fill`, `font-family`, `font-weight` (`normal`/`400`, `bold`/`700`), and `text-anchor` (`start`, `middle`, `end`). Existing paint and transform attributes remain available, including inherited group paint and transforms. Text-specific font attributes are allowed only on the text element; CSS, style attributes, coordinate lists, dx/dy, textLength, baseline overrides and letter spacing remain unsupported.

Font policy is fail closed: only the exact generic families `serif`, `sans-serif`, and `monospace` are accepted, mapped by the vendored library to PDF standard Times, Helvetica, and Courier, with normal/bold variants. Omitted family defaults explicitly to serif. Named/custom families, font lists, external/remote/embedded web fonts and `@font-face` are rejected; fonts are never fetched. The PDF uses its built-in standard fonts. Anchor offsets use the selected PDF standard font metrics inside the adapter. Generic fonts can differ from the source browser fonts, so exact typography fidelity is not claimed. Unavailable custom typography must be converted to paths by the source author; there is no automatic font substitution outside this contract or raster fallback.

Validation completes on a detached XML document before conversion. Only validated ASCII strings and allowlisted font parameters reach the library's temporary hidden text-measurement node, which the library removes after success. The source SVG tree is never inserted into the application DOM. External stylesheet loading is explicitly disabled in the converter.

Generated SVG PDFs are independently reopened, checked for page count, and tested for vector path/paint or PDF text operators with no `/Image` XObject on SVG pages. Visual inspection on representative real SVGs remains part of Chrome/Edge acceptance.
