JBrowser Source Docs

jbrowser.core.aeszip

Generated from the source code of JBrowser 1.5.4.

jbrowser/core/aeszip.py · 186 lines

Password-protected ZIP files with AES-256 encryption (the WinZip AES format, AE-2).

Used to export saved passwords: the CSV never touches the disk unencrypted. Python's zipfile module only knows the old "ZipCrypto" encryption, which is broken (a known-plaintext attack recovers the key), so this writes WinZip's AES format itself, on top of the cryptography package. 7-Zip, WinRAR, PeaZip, Keka, The Unarchiver and libarchive (Windows' tar.exe) open these files; Windows Explorer's built-in "Extract All" does not support AES encryption.

Format (APPNOTE.TXT section 7.2, and WinZip's "AES Encryption Information"): * compression method 99, with an extra field 0x9901 holding the vendor version (2 = AE-2), "AE", the key strength (3 = 256 bits) and the real compression method (8 = deflate); * the key is PBKDF2-HMAC-SHA1(password, 16-byte salt, 1000 iterations), 66 bytes long: the AES key, the HMAC key and a 2-byte password check; * the data is AES in counter mode with a 128-bit little-endian counter starting at 1, followed by the first 10 bytes of HMAC-SHA1 over the encrypted data. AE-2 stores no CRC (it could leak information).

ZipPasswordError#

class ZipPasswordError(ValueError)source

The password is wrong (or the file was changed).

Functions#

write_encrypted_zip#

write_encrypted_zip(path: str, files: dict[str, bytes], password: str) -> Nonesource

Write files (name → content) to path as an AES-256 encrypted, deflated ZIP.

read_zip#

read_zip(path: str, password: str='') -> dict[str, bytes]source

Read every file of a ZIP: plain, or AES encrypted (AE-1/AE-2, any key strength). Raises ZipPasswordError for a wrong password and ValueError for anything unsupported.