TestKdbx4.cpp 26 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609
  1. /*
  2. * Copyright (C) 2018 KeePassXC Team <team@keepassxc.org>
  3. *
  4. * This program is free software: you can redistribute it and/or modify
  5. * it under the terms of the GNU General Public License as published by
  6. * the Free Software Foundation, either version 2 or (at your option)
  7. * version 3 of the License.
  8. *
  9. * This program is distributed in the hope that it will be useful,
  10. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  11. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  12. * GNU General Public License for more details.
  13. *
  14. * You should have received a copy of the GNU General Public License
  15. * along with this program. If not, see <http://www.gnu.org/licenses/>.
  16. */
  17. #include "TestKdbx4.h"
  18. #include "config-keepassx-tests.h"
  19. #include "core/Metadata.h"
  20. #include "format/KdbxXmlReader.h"
  21. #include "format/KdbxXmlWriter.h"
  22. #include "format/KeePass2.h"
  23. #include "format/KeePass2Reader.h"
  24. #include "format/KeePass2Writer.h"
  25. #include "keys/FileKey.h"
  26. #include "keys/PasswordKey.h"
  27. #include "mock/MockChallengeResponseKey.h"
  28. #include "mock/MockClock.h"
  29. #include <QTest>
  30. int main(int argc, char* argv[])
  31. {
  32. QCoreApplication app(argc, argv);
  33. QCoreApplication::setAttribute(Qt::AA_Use96Dpi, true);
  34. QTEST_SET_MAIN_SOURCE_PATH
  35. TestKdbx4Argon2 argon2Test;
  36. TestKdbx4AesKdf aesKdfTest;
  37. TestKdbx4Format kdbx4Test;
  38. return QTest::qExec(&argon2Test, argc, argv) || QTest::qExec(&aesKdfTest, argc, argv)
  39. || QTest::qExec(&kdbx4Test, argc, argv);
  40. }
  41. void TestKdbx4Argon2::initTestCaseImpl()
  42. {
  43. m_xmlDb->changeKdf(fastKdf(KeePass2::uuidToKdf(KeePass2::KDF_ARGON2D)));
  44. m_kdbxSourceDb->changeKdf(fastKdf(KeePass2::uuidToKdf(KeePass2::KDF_ARGON2D)));
  45. }
  46. QSharedPointer<Database>
  47. TestKdbx4Argon2::readXml(const QString& path, bool strictMode, bool& hasError, QString& errorString)
  48. {
  49. KdbxXmlReader reader(KeePass2::FILE_VERSION_4);
  50. reader.setStrictMode(strictMode);
  51. auto db = reader.readDatabase(path);
  52. hasError = reader.hasError();
  53. errorString = reader.errorString();
  54. return db;
  55. }
  56. QSharedPointer<Database> TestKdbx4Argon2::readXml(QBuffer* buf, bool strictMode, bool& hasError, QString& errorString)
  57. {
  58. KdbxXmlReader reader(KeePass2::FILE_VERSION_4);
  59. reader.setStrictMode(strictMode);
  60. auto db = reader.readDatabase(buf);
  61. hasError = reader.hasError();
  62. errorString = reader.errorString();
  63. return db;
  64. }
  65. void TestKdbx4Argon2::writeXml(QBuffer* buf, Database* db, bool& hasError, QString& errorString)
  66. {
  67. KdbxXmlWriter writer(KeePass2::FILE_VERSION_4, {});
  68. writer.writeDatabase(buf, db);
  69. hasError = writer.hasError();
  70. errorString = writer.errorString();
  71. }
  72. void TestKdbx4Argon2::readKdbx(QIODevice* device,
  73. QSharedPointer<const CompositeKey> key,
  74. QSharedPointer<Database> db,
  75. bool& hasError,
  76. QString& errorString)
  77. {
  78. KeePass2Reader reader;
  79. reader.readDatabase(device, key, db.data());
  80. hasError = reader.hasError();
  81. if (hasError) {
  82. errorString = reader.errorString();
  83. }
  84. QCOMPARE(reader.version(), KeePass2::FILE_VERSION_4);
  85. }
  86. void TestKdbx4Argon2::writeKdbx(QIODevice* device, Database* db, bool& hasError, QString& errorString)
  87. {
  88. if (db->kdf()->uuid() == KeePass2::KDF_AES_KDBX3) {
  89. db->changeKdf(fastKdf(KeePass2::uuidToKdf(KeePass2::KDF_ARGON2D)));
  90. }
  91. KeePass2Writer writer;
  92. hasError = writer.writeDatabase(device, db);
  93. hasError = writer.hasError();
  94. if (hasError) {
  95. errorString = writer.errorString();
  96. }
  97. QCOMPARE(writer.version(), KeePass2::FILE_VERSION_4);
  98. }
  99. void TestKdbx4AesKdf::initTestCaseImpl()
  100. {
  101. m_xmlDb->changeKdf(fastKdf(KeePass2::uuidToKdf(KeePass2::KDF_AES_KDBX4)));
  102. m_kdbxSourceDb->changeKdf(fastKdf(KeePass2::uuidToKdf(KeePass2::KDF_AES_KDBX4)));
  103. }
  104. Q_DECLARE_METATYPE(QUuid)
  105. void TestKdbx4Format::init()
  106. {
  107. MockClock::setup(new MockClock());
  108. }
  109. void TestKdbx4Format::cleanup()
  110. {
  111. MockClock::teardown();
  112. }
  113. void TestKdbx4Format::testFormat400()
  114. {
  115. QString filename = QString(KEEPASSX_TEST_DATA_DIR).append("/Format400.kdbx");
  116. auto key = QSharedPointer<CompositeKey>::create();
  117. key->addKey(QSharedPointer<PasswordKey>::create("t"));
  118. KeePass2Reader reader;
  119. auto db = QSharedPointer<Database>::create();
  120. reader.readDatabase(filename, key, db.data());
  121. QCOMPARE(reader.version(), KeePass2::FILE_VERSION_4);
  122. QVERIFY(db.data());
  123. QVERIFY(!reader.hasError());
  124. QCOMPARE(db->rootGroup()->name(), QString("Format400"));
  125. QCOMPARE(db->metadata()->name(), QString("Format400"));
  126. QCOMPARE(db->rootGroup()->entries().size(), 1);
  127. auto entry = db->rootGroup()->entries().at(0);
  128. QCOMPARE(entry->title(), QString("Format400"));
  129. QCOMPARE(entry->username(), QString("Format400"));
  130. QCOMPARE(entry->attributes()->keys().size(), 6);
  131. QCOMPARE(entry->attributes()->value("Format400"), QString("Format400"));
  132. QCOMPARE(entry->attachments()->keys().size(), 1);
  133. QCOMPARE(entry->attachments()->value("Format400"), QByteArray("Format400\n"));
  134. }
  135. void TestKdbx4Format::testFormat400Upgrade()
  136. {
  137. QFETCH(QUuid, kdfUuid);
  138. QFETCH(QUuid, cipherUuid);
  139. QFETCH(bool, addCustomData);
  140. QFETCH(quint32, expectedVersion);
  141. QScopedPointer<Database> sourceDb(new Database());
  142. sourceDb->changeKdf(fastKdf(sourceDb->kdf()));
  143. sourceDb->metadata()->setName("Wubba lubba dub dub");
  144. QCOMPARE(sourceDb->kdf()->uuid(), KeePass2::KDF_AES_KDBX3); // default is legacy AES-KDF
  145. auto key = QSharedPointer<CompositeKey>::create();
  146. key->addKey(QSharedPointer<PasswordKey>::create("I am in great pain, please help me!"));
  147. sourceDb->setKey(key, true, true);
  148. QBuffer buffer;
  149. buffer.open(QBuffer::ReadWrite);
  150. // upgrade to KDBX 4 by changing KDF and Cipher
  151. sourceDb->changeKdf(fastKdf(KeePass2::uuidToKdf(kdfUuid)));
  152. sourceDb->setCipher(cipherUuid);
  153. // CustomData in meta should not cause any version change
  154. sourceDb->metadata()->customData()->set("CustomPublicData", "Hey look, I turned myself into a pickle!");
  155. if (addCustomData) {
  156. // this, however, should
  157. sourceDb->rootGroup()->customData()->set("CustomGroupData",
  158. "I just killed my family! I don't care who they were!");
  159. }
  160. KeePass2Writer writer;
  161. writer.writeDatabase(&buffer, sourceDb.data());
  162. if (writer.hasError()) {
  163. QFAIL(qPrintable(QString("Error while writing database: %1").arg(writer.errorString())));
  164. }
  165. // read buffer back
  166. buffer.seek(0);
  167. KeePass2Reader reader;
  168. auto targetDb = QSharedPointer<Database>::create();
  169. reader.readDatabase(&buffer, key, targetDb.data());
  170. if (reader.hasError()) {
  171. QFAIL(qPrintable(QString("Error while reading database: %1").arg(reader.errorString())));
  172. }
  173. QVERIFY(targetDb->rootGroup());
  174. QCOMPARE(targetDb->metadata()->name(), sourceDb->metadata()->name());
  175. QCOMPARE(reader.version(), expectedVersion);
  176. QCOMPARE(targetDb->cipher(), cipherUuid);
  177. QCOMPARE(targetDb->metadata()->customData()->value("CustomPublicData"),
  178. sourceDb->metadata()->customData()->value("CustomPublicData"));
  179. QCOMPARE(targetDb->rootGroup()->customData()->value("CustomGroupData"),
  180. sourceDb->rootGroup()->customData()->value("CustomGroupData"));
  181. }
  182. // clang-format off
  183. void TestKdbx4Format::testFormat400Upgrade_data()
  184. {
  185. QTest::addColumn<QUuid>("kdfUuid");
  186. QTest::addColumn<QUuid>("cipherUuid");
  187. QTest::addColumn<bool>("addCustomData");
  188. QTest::addColumn<quint32>("expectedVersion");
  189. auto constexpr kdbx3 = KeePass2::FILE_VERSION_3_1;
  190. auto constexpr kdbx4 = KeePass2::FILE_VERSION_4;
  191. QTest::newRow("Argon2d + AES") << KeePass2::KDF_ARGON2D << KeePass2::CIPHER_AES256 << false << kdbx4;
  192. QTest::newRow("Argon2id + AES") << KeePass2::KDF_ARGON2ID << KeePass2::CIPHER_AES256 << false << kdbx4;
  193. QTest::newRow("AES-KDF + AES") << KeePass2::KDF_AES_KDBX4 << KeePass2::CIPHER_AES256 << false << kdbx4;
  194. QTest::newRow("AES-KDF (legacy) + AES") << KeePass2::KDF_AES_KDBX3 << KeePass2::CIPHER_AES256 << false << kdbx3;
  195. QTest::newRow("Argon2d + AES + CustomData") << KeePass2::KDF_ARGON2D << KeePass2::CIPHER_AES256 << true << kdbx4;
  196. QTest::newRow("Argon2id + AES + CustomData") << KeePass2::KDF_ARGON2ID << KeePass2::CIPHER_AES256 << true << kdbx4;
  197. QTest::newRow("AES-KDF + AES + CustomData") << KeePass2::KDF_AES_KDBX4 << KeePass2::CIPHER_AES256 << true << kdbx4;
  198. QTest::newRow("AES-KDF (legacy) + AES + CustomData") << KeePass2::KDF_AES_KDBX3 << KeePass2::CIPHER_AES256 << true << kdbx4;
  199. QTest::newRow("Argon2d + ChaCha20") << KeePass2::KDF_ARGON2D << KeePass2::CIPHER_CHACHA20 << false << kdbx4;
  200. QTest::newRow("Argon2id + ChaCha20") << KeePass2::KDF_ARGON2ID << KeePass2::CIPHER_CHACHA20 << false << kdbx4;
  201. QTest::newRow("AES-KDF + ChaCha20") << KeePass2::KDF_AES_KDBX4 << KeePass2::CIPHER_CHACHA20 << false << kdbx4;
  202. QTest::newRow("AES-KDF (legacy) + ChaCha20") << KeePass2::KDF_AES_KDBX3 << KeePass2::CIPHER_CHACHA20 << false << kdbx3;
  203. QTest::newRow("Argon2d + ChaCha20 + CustomData") << KeePass2::KDF_ARGON2D << KeePass2::CIPHER_CHACHA20 << true << kdbx4;
  204. QTest::newRow("Argon2id + ChaCha20 + CustomData") << KeePass2::KDF_ARGON2ID << KeePass2::CIPHER_CHACHA20 << true << kdbx4;
  205. QTest::newRow("AES-KDF + ChaCha20 + CustomData") << KeePass2::KDF_AES_KDBX4 << KeePass2::CIPHER_CHACHA20 << true << kdbx4;
  206. QTest::newRow("AES-KDF (legacy) + ChaCha20 + CustomData") << KeePass2::KDF_AES_KDBX3 << KeePass2::CIPHER_CHACHA20 << true << kdbx4;
  207. QTest::newRow("Argon2d + Twofish") << KeePass2::KDF_ARGON2D << KeePass2::CIPHER_TWOFISH << false << kdbx4;
  208. QTest::newRow("Argon2id + Twofish") << KeePass2::KDF_ARGON2ID << KeePass2::CIPHER_TWOFISH << false << kdbx4;
  209. QTest::newRow("AES-KDF + Twofish") << KeePass2::KDF_AES_KDBX4 << KeePass2::CIPHER_TWOFISH << false << kdbx4;
  210. QTest::newRow("AES-KDF (legacy) + Twofish") << KeePass2::KDF_AES_KDBX3 << KeePass2::CIPHER_TWOFISH << false << kdbx3;
  211. QTest::newRow("Argon2d + Twofish + CustomData") << KeePass2::KDF_ARGON2D << KeePass2::CIPHER_TWOFISH << true << kdbx4;
  212. QTest::newRow("Argon2id + Twofish + CustomData") << KeePass2::KDF_ARGON2ID << KeePass2::CIPHER_TWOFISH << true << kdbx4;
  213. QTest::newRow("AES-KDF + Twofish + CustomData") << KeePass2::KDF_AES_KDBX4 << KeePass2::CIPHER_TWOFISH << true << kdbx4;
  214. QTest::newRow("AES-KDF (legacy) + Twofish + CustomData") << KeePass2::KDF_AES_KDBX3 << KeePass2::CIPHER_TWOFISH << true << kdbx4;
  215. }
  216. // clang-format on
  217. void TestKdbx4Format::testFormat410Upgrade()
  218. {
  219. Database db;
  220. db.changeKdf(fastKdf(db.kdf()));
  221. QCOMPARE(db.kdf()->uuid(), KeePass2::KDF_AES_KDBX3);
  222. QCOMPARE(KeePass2Writer::kdbxVersionRequired(&db), KeePass2::FILE_VERSION_3_1);
  223. auto group1 = new Group();
  224. group1->setUuid(QUuid::createUuid());
  225. group1->setParent(db.rootGroup());
  226. auto group2 = new Group();
  227. group2->setUuid(QUuid::createUuid());
  228. group2->setParent(db.rootGroup());
  229. auto entry = new Entry();
  230. entry->setUuid(QUuid::createUuid());
  231. entry->setGroup(group1);
  232. // Groups with tags
  233. group1->setTags("tag");
  234. QCOMPARE(KeePass2Writer::kdbxVersionRequired(&db), KeePass2::FILE_VERSION_4_1);
  235. group1->setTags("");
  236. QCOMPARE(KeePass2Writer::kdbxVersionRequired(&db), KeePass2::FILE_VERSION_3_1);
  237. // PasswordQuality flag set
  238. entry->setExcludeFromReports(true);
  239. QCOMPARE(KeePass2Writer::kdbxVersionRequired(&db), KeePass2::FILE_VERSION_4_1);
  240. entry->setExcludeFromReports(false);
  241. QCOMPARE(KeePass2Writer::kdbxVersionRequired(&db), KeePass2::FILE_VERSION_3_1);
  242. // Previous parent group set on group
  243. group1->setPreviousParentGroup(group2);
  244. QCOMPARE(group1->previousParentGroup(), group2);
  245. QCOMPARE(KeePass2Writer::kdbxVersionRequired(&db), KeePass2::FILE_VERSION_4_1);
  246. group1->setPreviousParentGroup(nullptr);
  247. QCOMPARE(KeePass2Writer::kdbxVersionRequired(&db), KeePass2::FILE_VERSION_3_1);
  248. // Previous parent group set on entry
  249. entry->setPreviousParentGroup(group2);
  250. QCOMPARE(entry->previousParentGroup(), group2);
  251. QCOMPARE(KeePass2Writer::kdbxVersionRequired(&db), KeePass2::FILE_VERSION_4_1);
  252. entry->setPreviousParentGroup(nullptr);
  253. QCOMPARE(KeePass2Writer::kdbxVersionRequired(&db), KeePass2::FILE_VERSION_3_1);
  254. // Custom icons with name or modification date
  255. Metadata::CustomIconData customIcon;
  256. auto iconUuid = QUuid::createUuid();
  257. db.metadata()->addCustomIcon(iconUuid, customIcon);
  258. QCOMPARE(KeePass2Writer::kdbxVersionRequired(&db), KeePass2::FILE_VERSION_3_1);
  259. customIcon.name = "abc";
  260. db.metadata()->removeCustomIcon(iconUuid);
  261. db.metadata()->addCustomIcon(iconUuid, customIcon);
  262. QCOMPARE(KeePass2Writer::kdbxVersionRequired(&db), KeePass2::FILE_VERSION_4_1);
  263. customIcon.name.clear();
  264. customIcon.lastModified = Clock::currentDateTimeUtc();
  265. db.metadata()->removeCustomIcon(iconUuid);
  266. QCOMPARE(KeePass2Writer::kdbxVersionRequired(&db), KeePass2::FILE_VERSION_3_1);
  267. db.metadata()->addCustomIcon(iconUuid, customIcon);
  268. QCOMPARE(KeePass2Writer::kdbxVersionRequired(&db), KeePass2::FILE_VERSION_4_1);
  269. }
  270. void TestKdbx4Format::testUpgradeMasterKeyIntegrity()
  271. {
  272. QFETCH(QString, upgradeAction);
  273. QFETCH(quint32, expectedVersion);
  274. // prepare composite key
  275. auto passwordKey = QSharedPointer<PasswordKey>::create("turXpGMQiUE6CkPvWacydAKsnp4cxz");
  276. QByteArray fileKeyBytes("Ma6hHov98FbPeyAL22XhcgmpJk8xjQ");
  277. QBuffer fileKeyBuffer(&fileKeyBytes);
  278. fileKeyBuffer.open(QBuffer::ReadOnly);
  279. auto fileKey = QSharedPointer<FileKey>::create();
  280. fileKey->load(&fileKeyBuffer);
  281. auto crKey = QSharedPointer<MockChallengeResponseKey>::create(QByteArray("azdJnbVCFE76vV6t9RJ2DS6xvSS93k"));
  282. auto compositeKey = QSharedPointer<CompositeKey>::create();
  283. compositeKey->addKey(passwordKey);
  284. compositeKey->addKey(fileKey);
  285. compositeKey->addChallengeResponseKey(crKey);
  286. QScopedPointer<Database> db(new Database());
  287. db->changeKdf(fastKdf(db->kdf()));
  288. QCOMPARE(db->kdf()->uuid(), KeePass2::KDF_AES_KDBX3); // default is legacy AES-KDF
  289. db->setKey(compositeKey);
  290. // upgrade the database by a specific method
  291. if (upgradeAction == "none") {
  292. // do nothing
  293. } else if (upgradeAction == "meta-customdata") {
  294. db->metadata()->customData()->set("abc", "def");
  295. } else if (upgradeAction == "kdf-aes-kdbx3") {
  296. db->changeKdf(fastKdf(KeePass2::uuidToKdf(KeePass2::KDF_AES_KDBX3)));
  297. } else if (upgradeAction == "kdf-argon2") {
  298. db->changeKdf(fastKdf(KeePass2::uuidToKdf(KeePass2::KDF_ARGON2D)));
  299. } else if (upgradeAction == "kdf-aes-kdbx4") {
  300. db->changeKdf(fastKdf(KeePass2::uuidToKdf(KeePass2::KDF_AES_KDBX4)));
  301. } else if (upgradeAction == "public-customdata") {
  302. db->publicCustomData().insert("abc", "def");
  303. } else if (upgradeAction == "rootgroup-customdata") {
  304. db->rootGroup()->customData()->set("abc", "def");
  305. } else if (upgradeAction == "group-customdata") {
  306. auto group = new Group();
  307. group->setParent(db->rootGroup());
  308. group->setUuid(QUuid::createUuid());
  309. group->customData()->set("abc", "def");
  310. } else if (upgradeAction == "rootentry-customdata") {
  311. auto entry = new Entry();
  312. entry->setGroup(db->rootGroup());
  313. entry->setUuid(QUuid::createUuid());
  314. entry->customData()->set("abc", "def");
  315. } else if (upgradeAction == "entry-customdata") {
  316. auto group = new Group();
  317. group->setParent(db->rootGroup());
  318. group->setUuid(QUuid::createUuid());
  319. auto entry = new Entry();
  320. entry->setGroup(group);
  321. entry->setUuid(QUuid::createUuid());
  322. entry->customData()->set("abc", "def");
  323. } else {
  324. QFAIL(qPrintable(QString("Unknown action: %s").arg(upgradeAction)));
  325. }
  326. QBuffer buffer;
  327. buffer.open(QBuffer::ReadWrite);
  328. KeePass2Writer writer;
  329. QVERIFY(writer.writeDatabase(&buffer, db.data()));
  330. // paranoid check that we cannot decrypt the database without a key
  331. buffer.seek(0);
  332. KeePass2Reader reader;
  333. auto db2 = QSharedPointer<Database>::create();
  334. reader.readDatabase(&buffer, QSharedPointer<CompositeKey>::create(), db2.data());
  335. QVERIFY(reader.hasError());
  336. // check that we can read back the database with the original composite key,
  337. // i.e., no components have been lost on the way
  338. buffer.seek(0);
  339. db2 = QSharedPointer<Database>::create();
  340. reader.readDatabase(&buffer, compositeKey, db2.data());
  341. if (reader.hasError()) {
  342. QFAIL(qPrintable(reader.errorString()));
  343. }
  344. QCOMPARE(reader.version(), expectedVersion);
  345. if (expectedVersion >= KeePass2::FILE_VERSION_4) {
  346. QVERIFY(db2->kdf()->uuid() != KeePass2::KDF_AES_KDBX3);
  347. }
  348. }
  349. void TestKdbx4Format::testUpgradeMasterKeyIntegrity_data()
  350. {
  351. QTest::addColumn<QString>("upgradeAction");
  352. QTest::addColumn<quint32>("expectedVersion");
  353. QTest::newRow("Upgrade: none") << QString("none") << KeePass2::FILE_VERSION_3_1;
  354. QTest::newRow("Upgrade: none (meta-customdata)") << QString("meta-customdata") << KeePass2::FILE_VERSION_3_1;
  355. QTest::newRow("Upgrade: none (explicit kdf-aes-kdbx3)") << QString("kdf-aes-kdbx3") << KeePass2::FILE_VERSION_3_1;
  356. QTest::newRow("Upgrade (explicit): kdf-argon2") << QString("kdf-argon2") << KeePass2::FILE_VERSION_4;
  357. QTest::newRow("Upgrade (explicit): kdf-aes-kdbx4") << QString("kdf-aes-kdbx4") << KeePass2::FILE_VERSION_4;
  358. QTest::newRow("Upgrade (implicit): public-customdata") << QString("public-customdata") << KeePass2::FILE_VERSION_4;
  359. QTest::newRow("Upgrade (implicit): rootgroup-customdata")
  360. << QString("rootgroup-customdata") << KeePass2::FILE_VERSION_4;
  361. QTest::newRow("Upgrade (implicit): group-customdata") << QString("group-customdata") << KeePass2::FILE_VERSION_4;
  362. QTest::newRow("Upgrade (implicit): rootentry-customdata")
  363. << QString("rootentry-customdata") << KeePass2::FILE_VERSION_4;
  364. QTest::newRow("Upgrade (implicit): entry-customdata") << QString("entry-customdata") << KeePass2::FILE_VERSION_4;
  365. }
  366. void TestKdbx4Format::testAttachmentIndexStability()
  367. {
  368. QScopedPointer<Database> db(new Database());
  369. db->changeKdf(fastKdf(KeePass2::uuidToKdf(KeePass2::KDF_ARGON2ID)));
  370. auto compositeKey = QSharedPointer<CompositeKey>::create();
  371. db->setKey(compositeKey);
  372. QVERIFY(!db->uuid().isNull());
  373. auto root = db->rootGroup();
  374. auto group1 = new Group();
  375. group1->setUuid(QUuid::createUuid());
  376. QVERIFY(!group1->uuid().isNull());
  377. group1->setParent(root);
  378. // Simulate KeeShare group, which uses its own attachment namespace
  379. auto group2 = new Group();
  380. group2->setUuid(QUuid::createUuid());
  381. QVERIFY(!group2->uuid().isNull());
  382. group2->setParent(group1);
  383. group2->customData()->set("KeeShare/Reference", "value doesn't matter");
  384. QVERIFY(group2->isShared());
  385. auto attachment1 = QByteArray("qwerty");
  386. auto attachment2 = QByteArray("asdf");
  387. auto attachment3 = QByteArray("zxcv");
  388. auto entry1 = new Entry();
  389. entry1->setUuid(QUuid::createUuid());
  390. QVERIFY(!entry1->uuid().isNull());
  391. auto uuid1 = entry1->uuid();
  392. entry1->attachments()->set("a", attachment1);
  393. QCOMPARE(entry1->attachments()->keys().size(), 1);
  394. QCOMPARE(entry1->attachments()->values().size(), 1);
  395. entry1->setGroup(root);
  396. auto entry2 = new Entry();
  397. entry2->setUuid(QUuid::createUuid());
  398. QVERIFY(!entry2->uuid().isNull());
  399. auto uuid2 = entry2->uuid();
  400. entry2->attachments()->set("a", attachment1);
  401. entry2->attachments()->set("b", attachment2);
  402. QCOMPARE(entry2->attachments()->keys().size(), 2);
  403. QCOMPARE(entry2->attachments()->values().size(), 2);
  404. entry2->setGroup(group1);
  405. auto entry3 = new Entry();
  406. entry3->setUuid(QUuid::createUuid());
  407. QVERIFY(!entry3->uuid().isNull());
  408. auto uuid3 = entry3->uuid();
  409. entry3->attachments()->set("a", attachment1);
  410. entry3->attachments()->set("b", attachment2);
  411. entry3->attachments()->set("x", attachment3);
  412. entry3->attachments()->set("y", attachment3);
  413. QCOMPARE(entry3->attachments()->keys().size(), 4);
  414. QCOMPARE(entry3->attachments()->values().size(), 3);
  415. entry3->setGroup(group2);
  416. QBuffer buffer;
  417. buffer.open(QBuffer::ReadWrite);
  418. KeePass2Writer writer;
  419. QVERIFY(writer.writeDatabase(&buffer, db.data()));
  420. QVERIFY(writer.version() >= KeePass2::FILE_VERSION_4);
  421. buffer.seek(0);
  422. KeePass2Reader reader;
  423. // Re-read database and check that all attachments are still correctly assigned
  424. auto db2 = QSharedPointer<Database>::create();
  425. reader.readDatabase(&buffer, QSharedPointer<CompositeKey>::create(), db2.data());
  426. QVERIFY(!reader.hasError());
  427. QVERIFY(!db->uuid().isNull());
  428. auto a1 = db2->rootGroup()->findEntryByUuid(uuid1)->attachments();
  429. QCOMPARE(a1->keys().size(), 1);
  430. QCOMPARE(a1->values().size(), 1);
  431. QCOMPARE(a1->value("a"), attachment1);
  432. auto a2 = db2->rootGroup()->findEntryByUuid(uuid2)->attachments();
  433. QCOMPARE(a2->keys().size(), 2);
  434. QCOMPARE(a2->values().size(), 2);
  435. QCOMPARE(a2->value("a"), attachment1);
  436. QCOMPARE(a2->value("b"), attachment2);
  437. auto sharedGroup = db2->rootGroup()->findEntryByUuid(uuid3)->group();
  438. QVERIFY(sharedGroup->isShared());
  439. auto a3 = db2->rootGroup()->findEntryByUuid(uuid3)->attachments();
  440. QCOMPARE(a3->keys().size(), 4);
  441. QCOMPARE(a3->values().size(), 3);
  442. QCOMPARE(a3->value("a"), attachment1);
  443. QCOMPARE(a3->value("b"), attachment2);
  444. QCOMPARE(a3->value("x"), attachment3);
  445. QCOMPARE(a3->value("y"), attachment3);
  446. }
  447. void TestKdbx4Format::testCustomData()
  448. {
  449. Database db;
  450. // test public custom data
  451. QVariantMap publicCustomData;
  452. publicCustomData.insert("CD1", 123);
  453. publicCustomData.insert("CD2", true);
  454. publicCustomData.insert("CD3", "abcäöü");
  455. db.setPublicCustomData(publicCustomData);
  456. publicCustomData.insert("CD4", QByteArray::fromHex("ababa123ff"));
  457. db.publicCustomData().insert("CD4", publicCustomData.value("CD4"));
  458. QCOMPARE(db.publicCustomData(), publicCustomData);
  459. const QString customDataKey1 = "CD1";
  460. const QString customDataKey2 = "CD2";
  461. const QString customData1 = "abcäöü";
  462. const QString customData2 = "Hello World";
  463. // test custom database data
  464. db.metadata()->customData()->set(customDataKey1, customData1);
  465. db.metadata()->customData()->set(customDataKey2, customData2);
  466. auto lastModified = db.metadata()->customData()->value(CustomData::LastModified);
  467. const int dataSize = customDataKey1.toUtf8().size() + customDataKey2.toUtf8().size() + customData1.toUtf8().size()
  468. + customData2.toUtf8().size() + lastModified.toUtf8().size()
  469. + CustomData::LastModified.toUtf8().size();
  470. QCOMPARE(db.metadata()->customData()->size(), 3);
  471. QCOMPARE(db.metadata()->customData()->dataSize(), dataSize);
  472. // test custom root group data
  473. Group* root = db.rootGroup();
  474. root->customData()->set(customDataKey1, customData1);
  475. root->customData()->set(customDataKey2, customData2);
  476. QCOMPARE(root->customData()->size(), 3);
  477. QCOMPARE(root->customData()->dataSize(), dataSize);
  478. // test copied custom group data
  479. auto* group = new Group();
  480. group->setParent(root);
  481. group->setUuid(QUuid::createUuid());
  482. group->customData()->copyDataFrom(root->customData());
  483. QCOMPARE(*group->customData(), *root->customData());
  484. // test copied custom entry data
  485. auto* entry = new Entry();
  486. entry->setGroup(group);
  487. entry->setUuid(QUuid::createUuid());
  488. entry->customData()->copyDataFrom(group->customData());
  489. QCOMPARE(*entry->customData(), *root->customData());
  490. // test custom data deletion
  491. entry->customData()->set("additional item", "foobar");
  492. QCOMPARE(entry->customData()->size(), 4);
  493. entry->customData()->remove("additional item");
  494. QCOMPARE(entry->customData()->size(), 3);
  495. QCOMPARE(entry->customData()->dataSize(), dataSize);
  496. // test custom data on cloned groups
  497. QScopedPointer<Group> clonedGroup(group->clone());
  498. QCOMPARE(*clonedGroup->customData(), *group->customData());
  499. // test custom data on cloned entries
  500. QScopedPointer<Entry> clonedEntry(entry->clone(Entry::CloneNoFlags));
  501. QCOMPARE(*clonedEntry->customData(), *entry->customData());
  502. QBuffer buffer;
  503. buffer.open(QBuffer::ReadWrite);
  504. KeePass2Writer writer;
  505. writer.writeDatabase(&buffer, &db);
  506. // read buffer back
  507. buffer.seek(0);
  508. KeePass2Reader reader;
  509. auto newDb = QSharedPointer<Database>::create();
  510. reader.readDatabase(&buffer, QSharedPointer<CompositeKey>::create(), newDb.data());
  511. // test all custom data are read back successfully from KDBX
  512. QCOMPARE(newDb->publicCustomData(), publicCustomData);
  513. QCOMPARE(newDb->metadata()->customData()->value(customDataKey1), customData1);
  514. QCOMPARE(newDb->metadata()->customData()->value(customDataKey2), customData2);
  515. QCOMPARE(newDb->rootGroup()->customData()->value(customDataKey1), customData1);
  516. QCOMPARE(newDb->rootGroup()->customData()->value(customDataKey2), customData2);
  517. auto* newGroup = newDb->rootGroup()->children()[0];
  518. QCOMPARE(newGroup->customData()->value(customDataKey1), customData1);
  519. QCOMPARE(newGroup->customData()->value(customDataKey2), customData2);
  520. auto* newEntry = newDb->rootGroup()->children()[0]->entries()[0];
  521. QCOMPARE(newEntry->customData()->value(customDataKey1), customData1);
  522. QCOMPARE(newEntry->customData()->value(customDataKey2), customData2);
  523. }