Fix case-insensitive ZIP entry matching in ZipFileZipEntrySource under Turkish Locale#1136
Merged
pjfanning merged 6 commits intoJun 12, 2026
Conversation
Member
|
forbidden apis used |
Contributor
|
I have updated the code and pushed the changes to address the Forbidden APIs check failure |
Remove unnecessary conversion of normalizedPath to lowercase.
Member
|
@kali834x there were some issues that I committed fixes for. Could you review them? |
Contributor
|
I reviewed the changes and ran TestZipSecureFile locally: |
Member
|
merged - thanks |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
ZipFileZipEntrySource.getEntry()performs case-insensitive matching of ZIP entry names. However, its implementation is inconsistent withZipInputStreamZipEntrySource, which normalizes names usingtoLowerCase(Locale.ROOT)before lookup.Since OPC ZIP entry names are standardized and should be compared using locale-independent ASCII semantics, both implementations should use the same normalization strategy to ensure consistent behavior across entry source types.
This PR aligns
ZipFileZipEntrySourcewithZipInputStreamZipEntrySourceby normalizing names usingtoLowerCase(Locale.ROOT). A unit test is added to verify consistent case-insensitive lookups and to guard against locale-related regressions, including under the Turkish locale.