SkipExternalResources

LoadOptions.SkipExternalResources property

Gets or sets a flag that stops the document from loading external resources. The default value is true: external resources are not loaded, except those that match WhitelistedResources.

public bool SkipExternalResources { get; set; }

Remarks

A document can refer to resources stored outside it: linked images, pictures inserted by an INCLUDEPICTURE field, linked pictures in presentations and spreadsheets, and images and style sheets that an SVG image refers to. Loading such a resource makes the library request its address. On a server that processes untrusted documents, a document could use this to make the server send requests to internal addresses (server-side request forgery), and a UNC or file:// path could make Windows send the account’s NTLM credentials to another host. On an offline or air-gapped installation, the requests fail or wait for a time-out.

Resources that are skipped are not drawn in page previews or in documents saved as images, and image, barcode and QR-code search does not see them. Set this property to false only for trusted documents, and prefer allowing specific addresses with WhitelistedResources.

The setting applies to word processing documents, presentations, spreadsheets and SVG images, including documents inside archives. For SVG images, the references that are not allowed are removed from the image before it is read, and an SVG image that is not well-formed XML is rejected. The setting does not control certificate revocation checks, time-stamp servers or licensing.

This property replaces LoadExternalResources, which has the opposite meaning.

See Also