Skip to content

Property value strategy: name the factory for binary properties #116

Description

@jorabin

Up to 3.1.1, the Jackson KDBX implementation holds attachment (binary property) content as the
Base64 text of the gzipped bytes, in KeePassFile.Binary, and decodes it on every
getBinaryProperty. This is the same whether or not the attachment is protected, and attachments
read from the KDBX 4 inner header are re-encoded that way. The protected flag itself was lost:
KDBX 4 attachments were always written as not protected, and KDBX 3.1 files with protected
attachments (Protected="True" in Meta/Binaries) could not be read.

From 3.1.2, attachment content is held as a PropertyValue: protected attachments use the
strategy's newProtected() factory (SealedStore by default), and unprotected attachments always
use BytesStore.

The strategy isn't used for unprotected attachments because newUnprotected() may return a
factory that holds strings (StringStore), whose of(byte[]) decodes the bytes as UTF-8 and so
can't hold arbitrary binary content. For the same reason, a custom newProtected() that holds
strings would corrupt protected attachments.

For 3.2.0, PropertyValue.Strategy should name the factories for binary properties explicitly,
e.g. default methods newProtectedBinary() and newUnprotectedBinary() (defaults SealedStore
and BytesStore), so that a strategy can choose how attachments are held in memory, and the
contract says these factories must hold arbitrary bytes unchanged. Update
PropertyValueProtection.md and BinaryProperties.md to match.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions