o
    ?8¾\E  ã                   @   s†   d dl Z d dlZzd dlmZ W n ey   dd„ ZY nw ejd  dk r(eZndd„ ZG dd„ deƒZ	dd
d„Z
dd„ Zdd„ ZdS )é    N)Ú
ip_addressc                 C   s   d S ©N© )Úaddressr   r   úL/var/www/html/env/lib/python3.10/site-packages/pymongo/ssl_match_hostname.pyÚ<lambda>   ó    r   é   c                 C   s   | S r   r   )Úvaluer   r   r   r      r   c                   @   s   e Zd ZdS )ÚCertificateErrorN)Ú__name__Ú
__module__Ú__qualname__r   r   r   r   r      s    r   é   c           
      C   sò   g }| sdS |   d¡}|d }|dd… }| d¡}||kr&tdt| ƒ ƒ‚|s0|  ¡ | ¡ kS |dkr:| d¡ n| d	¡sD| d	¡rM| t |¡¡ n| t |¡ 	d
d¡¡ |D ]
}| t |¡¡ q[t 
dd |¡ d tj¡}	|	 |¡S )zhMatching according to RFC 6125, section 6.4.3

    http://tools.ietf.org/html/rfc6125#section-6.4.3
    FÚ.r   r   NÚ*z,too many wildcards in certificate DNS name: z[^.]+zxn--z\*z[^.]*z\Az\.z\Z)ÚsplitÚcountr   ÚreprÚlowerÚappendÚ
startswithÚreÚescapeÚreplaceÚcompileÚjoinÚ
IGNORECASEÚmatch)
ÚdnÚhostnameÚmax_wildcardsÚpatsÚpartsÚleftmostÚ	remainderÚ	wildcardsÚfragÚpatr   r   r   Ú_dnsname_match   s,   


ÿ
r)   c                 C   s   t t| ƒ ¡ ƒ}||kS )zˆExact matching of IP addresses.

    RFC 6125 explicitly doesn't define an algorithm for this
    (section 1.7.2 - "Out of Scope").
    )r   Ú_unicodeÚrstrip)ÚipnameÚhost_ipÚipr   r   r   Ú_ipaddress_matchK   s   r/   c              	   C   sD  | st dƒ‚ztt|ƒƒ}W n t tfy   d}Y nw g }|  dd¡}|D ]/\}}|dkr@|du r:t||ƒr: dS | |¡ q&|dkrU|durPt||ƒrP dS | |¡ q&|sz|  dd¡D ]}|D ]\}}|dkrxt||ƒrs  dS | |¡ qbq^t|ƒd	krŽt	d
|d 
tt|ƒ¡f ƒ‚t|ƒd	kržt	d||d f ƒ‚t	dƒ‚)z÷Verify that *cert* (in decoded format as returned by
    SSLSocket.getpeercert()) matches the *hostname*.  RFC 2818 and RFC 6125
    rules are followed.

    CertificateError is raised on failure. On success, the function
    returns nothing.
    ztempty or no certificate, match_hostname needs a SSL socket or SSL context with either CERT_OPTIONAL or CERT_REQUIREDNÚsubjectAltNamer   ÚDNSz
IP AddressÚsubjectÚ
commonNamer   z&hostname %r doesn't match either of %sz, zhostname %r doesn't match %rr   z=no appropriate commonName or subjectAltName fields were found)Ú
ValueErrorr   r*   ÚUnicodeErrorÚgetr)   r   r/   Úlenr   r   Úmapr   )Úcertr    r-   ÚdnsnamesÚsanÚkeyr
   Úsubr   r   r   Úmatch_hostnameV   sJ   þ
€

€úþ
þr>   )r   )r   ÚsysÚ	ipaddressr   ÚImportErrorÚversion_infoÚunicoder*   r4   r   r)   r/   r>   r   r   r   r   Ú<module>   s   ÿ
3