[php-src] Issue #9318: ZipArchive password protection doesn't work if entryname is used in addFile()

From: Date: Fri, 12 Aug 2022 15:08:10 +0000
Subject: [php-src] Issue #9318: ZipArchive password protection doesn't work if entryname is used in addFile()
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-242203@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/9318 Author: zoltan-sule ### Description The following code: ```php <?php $zip = new ZipArchive(); if ($zip->open('/tmp/test1.zip', ZipArchive::CREATE) === TRUE) { $zip->setPassword('secret_'); $zip->addFile('/tmp/test.txt', 'test.txt'); $zip->setEncryptionName('/tmp/test.txt', ZipArchive::EM_AES_256); $zip->close(); } ``` Resulted in this output: _I am able to extract the content without the password._ But I expected this output instead: _that I need to use the password during the extraction._ **Working but not optimal** If I leave entryname empty in addFile() method then I need to type the password before I want to extract the content but then the tmp appears inside the zip file as a directory structure. ``` <?php $zip = new ZipArchive(); if ($zip->open('/tmp/test2.zip', ZipArchive::CREATE) === TRUE) { $zip->setPassword('secret_'); $zip->addFile('/tmp/test.txt'); $zip->setEncryptionName('/tmp/test.txt', ZipArchive::EM_AES_256); $zip->close(); } ``` ### PHP Version PHP 8.1.8 ### Operating System Ubuntu 20.04.4 LTS

« previous php.bugs (#242203) next »