o
    �¨ÊhJ  ã                   @   sh   d dl Z d dlZd dlmZmZ d dlmZmZ d dlm	Z	m
Z
mZ dd„ Zdd„ ZG d	d
„ d
eƒZdS )é    N)Úsha1Úsha256)ÚPY3Ústring_types)ÚizipÚurlparseÚparse_qsc                 C   s<   t | ƒt |ƒkr
dS d}t| |ƒD ]
\}}|||kM }q|S )zçCompare two strings while protecting against timing attacks

    :param str string1: the first string
    :param str string2: the second string

    :returns: True if the strings are equal, False if not
    :rtype: :obj:`bool`
    FT)Úlenr   )Ústring1Ústring2ÚresultÚc1Úc2© r   úJ/var/www/html/env/lib/python3.10/site-packages/twilio/request_validator.pyÚcompare
   s   	r   c                 C   s$   | j  d¡d }| j|d�}| ¡ S )z£Remove the port number from a URI

    :param uri: full URI that Twilio requested on your server

    :returns: full URI without a port number
    :rtype: str
    ú:r   )Únetloc)r   ÚsplitÚ_replaceÚgeturl)ÚuriÚ
new_netlocÚnew_urir   r   r   Úremove_port   s   r   c                   @   s4   e Zd Zdd„ Zefdd„Zefdd„Zdd„ Zd	S )
ÚRequestValidatorc                 C   s   |  d¡| _d S ©Núutf-8)ÚencodeÚtoken)Úselfr   r   r   r   Ú__init__*   s   zRequestValidator.__init__c           	      C   sl   |}t |ƒdkrt| ¡ ƒD ]
\}}||| 7 }qt | j| d¡t¡}t 	| 
¡ ¡}|r2| d¡}| ¡ S )a/  Compute the signature for a given request

        :param uri: full URI that Twilio requested on your server
        :param params: post vars that Twilio sent with the request
        :param utf: whether return should be bytestring or unicode (python3)

        :returns: The computed signature
        r   r   )r	   ÚsortedÚitemsÚhmacÚnewr   r   r   Úbase64Ú	b64encodeÚdigestÚdecodeÚstrip)	r    r   ÚparamsÚutfÚsÚkÚvÚmacÚcomputedr   r   r   Úcompute_signature-   s   	
z"RequestValidator.compute_signaturec                 C   s.   t  t| d¡ƒ ¡ ¡}|r| d¡}| ¡ S r   )r&   r'   r   r   r(   r)   r*   )r    Úbodyr,   r1   r   r   r   Úcompute_hashC   s   
zRequestValidator.compute_hashc                 C   s–   |du ri }t |ƒ}|jdkr|jrt|ƒ}d}d}t|jƒ}d|v r>t|tƒr>t|  	|¡|d d ƒ}t|  
|i ¡|ƒ}n	t|  
||¡|ƒ}|oJ|S )a]  Validate a request from Twilio

        :param uri: full URI that Twilio requested on your server
        :param params: dictionary of POST variables or string of POST body for JSON requests
        :param signature: expected signature in HTTP X-Twilio-Signature header

        :returns: True if the request passes validation, False if not
        NÚhttpsFTÚ
bodySHA256r   )r   ÚschemeÚportr   r   ÚqueryÚ
isinstancer   r   r4   r2   )r    r   r+   Ú	signatureÚ
parsed_uriÚvalid_signatureÚvalid_body_hashr9   r   r   r   ÚvalidateK   s   	
zRequestValidator.validateN)Ú__name__Ú
__module__Ú__qualname__r!   r   r2   r4   r?   r   r   r   r   r   (   s
    r   )r&   r$   Úhashlibr   r   Úsixr   r   Útwilio.compatr   r   r   r   r   Úobjectr   r   r   r   r   Ú<module>   s    