Home β€Ί Playgrounds β€Ί Secure extraction

Secure extraction

extractZip() treats every archive as hostile until proven otherwise. Run the two crafted archives below β€” a zip-slip and a header-inconsistent one β€” and watch each refusal come back as a typed err.code. Then drop your own to see what passes.

…or drop your own archive
extractZip runs with its defaults on β€” it never touches a filesystem