diff --git a/pkg/modules/libreoffice/api/protection.go b/pkg/modules/libreoffice/api/protection.go index 9ada1596..d9c550cc 100644 --- a/pkg/modules/libreoffice/api/protection.go +++ b/pkg/modules/libreoffice/api/protection.go @@ -35,12 +35,13 @@ var ( zipMagic = []byte{0x50, 0x4b, 0x03, 0x04} // An unencrypted OOXML document is always a ZIP package, so any of these - // extensions over a compound file means the payload is encrypted. Legacy - // binary formats (.doc, .xls, .ppt) are compound files either way and are - // deliberately absent. + // extensions over a compound file means the payload is encrypted. A .xlsb + // workbook stores binary parts inside that same ZIP package, so it belongs + // here too. Legacy binary formats (.doc, .xls, .ppt) are compound files + // either way and are deliberately absent. ooxmlExtensions = map[string]struct{}{ ".docx": {}, ".docm": {}, ".dotx": {}, ".dotm": {}, - ".xlsx": {}, ".xlsm": {}, ".xltx": {}, ".xltm": {}, + ".xlsx": {}, ".xlsm": {}, ".xltx": {}, ".xltm": {}, ".xlsb": {}, ".pptx": {}, ".pptm": {}, ".potx": {}, ".potm": {}, ".ppsx": {}, ".ppsm": {}, } diff --git a/pkg/modules/libreoffice/api/protection_test.go b/pkg/modules/libreoffice/api/protection_test.go index 88fa88df..d71f24ce 100644 --- a/pkg/modules/libreoffice/api/protection_test.go +++ b/pkg/modules/libreoffice/api/protection_test.go @@ -76,6 +76,11 @@ func TestDetectPasswordProtection(t *testing.T) { path: ole2("encrypted.xlsx"), want: PasswordProtectionRequired, }, + { + name: "encrypted binary workbook", + path: ole2("encrypted.xlsb"), + want: PasswordProtectionRequired, + }, { name: "legacy binary document is inconclusive", path: ole2("legacy.doc"),