o
    ˜¨ÊhT"  ã                   @   s*  d Z ddlZddlZddlZddlZddlZddlmZ ddlm	Z	m
Z
 ddlmZ ddlmZ ddlmZ edƒZd	ZG d
d„ deƒZG dd„ deƒZdd„ Zdd„ Zdd„ Zdd„ Zd*dd„Zdd„ Zd+dd„ZG dd„ dƒZdd ed!fd"d#„Zdd eddfd$d%„ZG d&d'„ d'ƒZ G d(d)„ d)e ƒZ!dS ),a_  
Functions for creating and restoring url-safe signed JSON objects.

The format used looks like this:

>>> signing.dumps("hello")
'ImhlbGxvIg:1QaUZC:YIye-ze3TTx7gtSv422nZA4sgmk'

There are two components here, separated by a ':'. The first component is a
URLsafe base64 encoded JSON of the object passed to dumps(). The second
component is a base64 encoded hmac/SHA-256 hash of "$first_component:$secret"

signing.loads(s) checks the signature and returns the deserialized object.
If the signature fails, a BadSignature exception is raised.

>>> signing.loads("ImhlbGxvIg:1QaUZC:YIye-ze3TTx7gtSv422nZA4sgmk")
'hello'
>>> signing.loads("ImhlbGxvIg:1QaUZC:YIye-ze3TTx7gtSv42-modified")
...
BadSignature: Signature "ImhlbGxvIg:1QaUZC:YIye-ze3TTx7gtSv42-modified" does not match

You can optionally compress the JSON prior to base64 encoding it to save
space, using the compress=True argument. This checks if compression actually
helps and only applies compression if the result is a shorter string:

>>> signing.dumps(list(range(1, 20)), compress=True)
'.eJwFwcERACAIwLCF-rCiILN47r-GyZVJsNgkxaFxoDgxcOHGxMKD_T7vhAml:1QaUaL:BA0thEZrp4FQVXIXuOvYJtLJSrQ'

The fact that the string is compressed is signalled by the prefixed '.' at the
start of the base64 JSON.

There are 65 url-safe characters: the 64 used by url-safe base64 and the ':'.
These functions make use of all of them.
é    N)Úsettings)Úconstant_time_compareÚsalted_hmac©Úforce_bytes)Úimport_string)Ú_lazy_re_compilez^[A-z0-9-_=]*$Ú>0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyzc                   @   ó   e Zd ZdZdS )ÚBadSignaturezSignature does not match.N©Ú__name__Ú
__module__Ú__qualname__Ú__doc__© r   r   úE/var/www/html/env/lib/python3.10/site-packages/django/core/signing.pyr   4   ó    r   c                   @   r
   )ÚSignatureExpiredz3Signature timestamp is older than required max_age.Nr   r   r   r   r   r   :   r   r   c                 C   sZ   | dkrdS | dk rdnd}t | ƒ} d}| dkr)t| dƒ\} }t| | }| dks|| S )Nr   Ú0ú-Ú é>   )ÚabsÚdivmodÚBASE62_ALPHABET)ÚsÚsignÚencodedÚ	remainderr   r   r   Ú
b62_encode@   s   þr    c                 C   sT   | dkrdS d}| d dkr| dd … } d}d}| D ]}|d t  |¡ }q|| S )Nr   r   é   r   éÿÿÿÿr   )r   Úindex)r   r   ÚdecodedÚdigitr   r   r   Ú
b62_decodeL   s   r&   c                 C   s   t  | ¡ d¡S )Nó   =)Úbase64Úurlsafe_b64encodeÚstrip)r   r   r   r   Ú
b64_encodeY   ó   r+   c                 C   s    dt | ƒ d  }t | | ¡S )Nr'   é   )Úlenr(   Úurlsafe_b64decode)r   Úpadr   r   r   Ú
b64_decode]   s   r1   Úsha1c                 C   s   t t| |||d� ¡ ƒ ¡ S )N©Ú	algorithm)r+   r   ÚdigestÚdecode)ÚsaltÚvalueÚkeyr4   r   r   r   Úbase64_hmacb   s
   ÿþr:   c                 C   s   dt | ƒ S )Ns   django.http.cookiesr   )r9   r   r   r   Ú_cookie_signer_keyh   s   r;   ú%django.core.signing.get_cookie_signerc                 C   s&   t tjƒ}|ttjƒtttjƒ| d�S )N)r9   Úfallback_keysr7   )r   r   ÚSIGNING_BACKENDr;   Ú
SECRET_KEYÚmapÚSECRET_KEY_FALLBACKS)r7   ÚSignerr   r   r   Úget_cookie_signerm   s   

ýrC   c                   @   s    e Zd ZdZdd„ Zdd„ ZdS )ÚJSONSerializerzW
    Simple wrapper around json to be used in signing.dumps and
    signing.loads.
    c                 C   s   t j|dd� d¡S )N)ú,ú:)Ú
separatorsúlatin-1)ÚjsonÚdumpsÚencode)ÚselfÚobjr   r   r   rJ   |   s   zJSONSerializer.dumpsc                 C   s   t  | d¡¡S )NrH   )rI   Úloadsr6   )rL   Údatar   r   r   rN      r,   zJSONSerializer.loadsN)r   r   r   r   rJ   rN   r   r   r   r   rD   v   s    rD   zdjango.core.signingFc                 C   s   t ||d�j| ||d�S )a½  
    Return URL-safe, hmac signed base64 compressed JSON string. If key is
    None, use settings.SECRET_KEY instead. The hmac algorithm is the default
    Signer algorithm.

    If compress is True (not the default), check if compressing using zlib can
    save some space. Prepend a '.' to signify compression. This is included
    in the signature, to protect against zip bombs.

    Salt can be used to namespace the hash, so that a signed string is
    only valid for a given namespace. Leaving this at the default
    value or re-using a salt value across different parts of your
    application without good cause is a security risk.

    The serializer is expected to return a bytestring.
    )r7   )Ú
serializerÚcompress)ÚTimestampSignerÚsign_object)rM   r9   r7   rP   rQ   r   r   r   rJ   ƒ   s   ÿrJ   c                 C   s   t |||d�j| ||d�S )z|
    Reverse of dumps(), raise BadSignature if signature fails.

    The serializer is expected to accept a bytestring.
    )r7   r=   )rP   Úmax_age)rR   Úunsign_object)r   r9   r7   rP   rT   r=   r   r   r   rN   ›   s
   ýrN   c                   @   sT   e Zd Z					ddd„Zddd„Zdd„ Zd	d
„ Zedfdd„Zefdd„Z	dS )rB   NrF   c                 C   sf   |pt j| _|d ur|nt j| _|| _t | j¡rtd| ƒ‚|p*d| j	j
| j	jf | _|p/d| _d S )NzJUnsafe Signer separator: %r (cannot be empty or consist of only A-z0-9-_=)z%s.%sÚsha256)r   r?   r9   rA   r=   ÚsepÚ_SEP_UNSAFEÚmatchÚ
ValueErrorÚ	__class__r   r   r7   r4   )rL   r9   rW   r7   r4   r=   r   r   r   Ú__init__°   s"   ÿýÿÿþzSigner.__init__c                 C   s"   |p| j }t| jd ||| jd�S )NÚsignerr3   )r9   r:   r7   r4   )rL   r8   r9   r   r   r   Ú	signatureÊ   s   
zSigner.signaturec                 C   s   d|| j |  |¡f S ©Nz%s%s%s)rW   r^   ©rL   r8   r   r   r   r   Î   s   zSigner.signc                 C   sd   | j |vrtd| j  ƒ‚| | j d¡\}}| jg| j¢D ]}t||  ||¡ƒr+|  S qtd| ƒ‚)NzNo "%s" found in valuer!   zSignature "%s" does not match)rW   r   Úrsplitr9   r=   r   r^   )rL   Úsigned_valuer8   Úsigr9   r   r   r   ÚunsignÑ   s   
ÿzSigner.unsignFc                 C   s\   |ƒ   |¡}d}|rt |¡}t|ƒt|ƒd k r|}d}t|ƒ ¡ }|r)d| }|  |¡S )ae  
        Return URL-safe, hmac signed base64 compressed JSON string.

        If compress is True (not the default), check if compressing using zlib
        can save some space. Prepend a '.' to signify compression. This is
        included in the signature, to protect against zip bombs.

        The serializer is expected to return a bytestring.
        Fr!   TÚ.)rJ   ÚzlibrQ   r.   r+   r6   r   )rL   rM   rP   rQ   rO   Úis_compressedÚ
compressedÚbase64dr   r   r   rS   Ú   s   


zSigner.sign_objectc                 K   sX   | j |fi |¤Ž ¡ }|d d… dk}|r|dd … }t|ƒ}|r&t |¡}|ƒ  |¡S )Nr!   ó   .)rd   rK   r1   rf   Ú
decompressrN   )rL   Ú
signed_objrP   Úkwargsri   rk   rO   r   r   r   rU   ó   s   
zSigner.unsign_object)NrF   NNN©N)
r   r   r   r\   r^   r   rd   rD   rS   rU   r   r   r   r   rB   ¯   s    
ú
	rB   c                       s2   e Zd Zdd„ Z‡ fdd„Zd‡ fdd„	Z‡  ZS )	rR   c                 C   s   t tt ¡ ƒƒS rn   )r    ÚintÚtime)rL   r   r   r   Ú	timestamp  r,   zTimestampSigner.timestampc                    s    d|| j |  ¡ f }tƒ  |¡S r_   )rW   rq   Úsuperr   r`   ©r[   r   r   r     s   zTimestampSigner.signNc                    sj   t ƒ  |¡}| | jd¡\}}t|ƒ}|dur3t|tjƒr!| ¡ }t	 	¡ | }||kr3t
d||f ƒ‚|S )zk
        Retrieve original value and check it wasn't signed more
        than max_age seconds ago.
        r!   NzSignature age %s > %s seconds)rr   rd   ra   rW   r&   Ú
isinstanceÚdatetimeÚ	timedeltaÚtotal_secondsrp   r   )rL   r8   rT   Úresultrq   Úagers   r   r   rd   	  s   zTimestampSigner.unsignrn   )r   r   r   rq   r   rd   Ú__classcell__r   r   rs   r   rR     s    rR   )r2   )r<   )"r   r(   ru   rI   rp   rf   Údjango.confr   Údjango.utils.cryptor   r   Údjango.utils.encodingr   Údjango.utils.module_loadingr   Údjango.utils.regex_helperr   rX   r   Ú	Exceptionr   r   r    r&   r+   r1   r:   r;   rC   rD   rJ   rN   rB   rR   r   r   r   r   Ú<module>   sB    #

	
ÿ
úR