o
    ›¨Êh‰  ã                   @   s–   d dl Z d dlZd dlmZ d dlmZ d dlmZ d dlm	Z	 d dl
mZ ddlmZmZ dd	lmZmZmZ G d
d„ deƒZG dd„ deeƒZdS )é    N©ÚHttpResponse©Úconstant_time_compare)Úmethod_decorator)Úcsrf_exempt)ÚViewé   )ÚAnymailInsecureWebhookWarningÚAnymailWebhookValidationFailure)Úget_anymail_settingÚcollect_all_methodsÚget_request_basic_authc                       s0   e Zd ZdZdZdZ‡ fdd„Zdd„ Z‡  ZS )ÚAnymailBasicAuthMixinzAImplements webhook basic auth as mixin to AnymailBaseWebhookView.TNc                    sb   t dg |d�| _t| jtjƒr| jg| _| jr$t| jƒdk r$t dt	¡ t
t| ƒjdi |¤Ž d S )NÚwebhook_secret)ÚdefaultÚkwargsé   z¦Your Anymail webhooks are insecure and open to anyone on the web. You should set WEBHOOK_SECRET in your ANYMAIL settings. See 'Securing webhooks' in the Anymail docs.© )r   Ú
basic_authÚ
isinstanceÚsixÚstring_typesÚwarn_if_no_basic_authÚlenÚwarningsÚwarnr
   Úsuperr   Ú__init__©Úselfr   ©Ú	__class__r   úG/var/www/html/env/lib/python3.10/site-packages/anymail/webhooks/base.pyr      s   ÿ
üzAnymailBasicAuthMixin.__init__c                    s@   | j rt|ƒ‰ t‡ fdd„| j D ƒƒ}|std| j ƒ‚dS dS )zHIf configured for webhook basic auth, validate request has correct auth.c                 3   s   � | ]}t ˆ |ƒV  qd S ©Nr   )Ú.0Úallowed_auth©Úrequest_authr   r#   Ú	<genexpr>1   s   € ÿz9AnymailBasicAuthMixin.validate_request.<locals>.<genexpr>z3Missing or invalid basic auth in Anymail %s webhookN)r   r   Úanyr   Úesp_name)r    ÚrequestÚauth_okr   r'   r#   Úvalidate_request*   s   ÿÿ÷z&AnymailBasicAuthMixin.validate_request)	Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r   r   r.   Ú__classcell__r   r   r!   r#   r      s    r   c                       st   e Zd ZdZ‡ fdd„ZdZdd„ Zdd„ Zg d	¢Ze	e
ƒ‡ fd
d„ƒZdd„ Zdd„ Zdd„ Zedd„ ƒZ‡  ZS )ÚAnymailBaseWebhookViewzàBase view for processing ESP event webhooks

    ESP-specific implementations should subclass
    and implement parse_events. They may also
    want to implement validate_request
    if additional security is available.
    c                    s(   t t| ƒjdi |¤Ž t| jdƒ| _d S )Nr.   r   )r   r4   r   r   r"   Ú
validatorsr   r!   r   r#   r   D   s   zAnymailBaseWebhookView.__init__Nc                 C   s   dS )a‡  Check validity of webhook post, or raise AnymailWebhookValidationFailure.

        AnymailBaseWebhookView includes basic auth validation.
        Subclasses can implement (or provide via mixins) if the ESP supports
        additional validation (such as signature checking).

        *All* definitions of this method in the class chain (including mixins)
        will be called. There is no need to chain to the superclass.
        (See self.run_validators and collect_all_methods.)

        Security note: use django.utils.crypto.constant_time_compare for string
        comparisons, to avoid exposing your validation to a timing attack.
        Nr   ©r    r,   r   r   r#   r.   M   s   z'AnymailBaseWebhookView.validate_requestc                 C   s   t ƒ ‚)zzReturn a list of normalized AnymailWebhookEvent extracted from ESP post data.

        Subclasses must implement.
        )ÚNotImplementedErrorr6   r   r   r#   Úparse_events`   s   z#AnymailBaseWebhookView.parse_events)ÚpostÚheadÚoptionsc                    s   t t| ƒj|g|¢R i |¤ŽS r$   )r   r4   Údispatch©r    r,   Úargsr   r!   r   r#   r<   k   s   zAnymailBaseWebhookView.dispatchc                 O   s   t ƒ S r$   r   r=   r   r   r#   r:   o   s   zAnymailBaseWebhookView.headc                 O   s>   |   |¡ |  |¡}| j}|D ]}| jj| j||d� qtƒ S )N)ÚsenderÚeventr+   )Úrun_validatorsr8   r+   ÚsignalÚsendr"   r   )r    r,   r>   r   Úeventsr+   r@   r   r   r#   r9   s   s   

zAnymailBaseWebhookView.postc                 C   s   | j D ]}|| |ƒ qd S r$   )r5   )r    r,   Ú	validatorr   r   r#   rA   ƒ   s   
ÿz%AnymailBaseWebhookView.run_validatorsc                 C   s   t d| jj| jjf ƒ‚)zç
        Read-only name of the ESP for this webhook view.

        Subclasses must override with class attr. E.g.:
            esp_name = "Postmark"
            esp_name = "SendGrid"  # (use ESP's preferred capitalization)
        z&%s.%s must declare esp_name class attr)r7   r"   r0   r/   )r    r   r   r#   r+   ‡   s   	ÿzAnymailBaseWebhookView.esp_name)r/   r0   r1   r2   r   rB   r.   r8   Úhttp_method_namesr   r   r<   r:   r9   rA   Úpropertyr+   r3   r   r   r!   r#   r4   ;   s    	r4   )r   r   Údjango.httpr   Údjango.utils.cryptor   Údjango.utils.decoratorsr   Údjango.views.decorators.csrfr   Údjango.views.genericr   Ú
exceptionsr
   r   Úutilsr   r   r   Úobjectr   r4   r   r   r   r#   Ú<module>   s    -