o
    éT•jù:  ã                   @   sè   d Z dgZddlZddlZddlZe d¡Ze d¡ZG dd„ deƒZ	dd	„ Z
d
d„ Zdd„ ZG dd„ dƒZG dd„ dƒZG dd„ dƒZG dd„ dƒZG dd„ dƒZdd„ Zdd„ Zdd„ Zdd„ Zdd „ Zd!d"„ Zd#d$„ Zd%d&„ ZdS )'a&  
Middleware to check for obedience to the WSGI specification.

Some of the things this checks:

* Signature of the application and start_response (including that
  keyword arguments are not used).

* Environment checks:

  - Environment is a dictionary (and not a subclass).

  - That all the required keys are in the environment: REQUEST_METHOD,
    SERVER_NAME, SERVER_PORT, wsgi.version, wsgi.input, wsgi.errors,
    wsgi.multithread, wsgi.multiprocess, wsgi.run_once

  - That HTTP_CONTENT_TYPE and HTTP_CONTENT_LENGTH are not in the
    environment (these headers should appear as CONTENT_LENGTH and
    CONTENT_TYPE).

  - Warns if QUERY_STRING is missing, as the cgi module acts
    unpredictably in that case.

  - That CGI-style variables (that don't contain a .) have
    (non-unicode) string values

  - That wsgi.version is a tuple

  - That wsgi.url_scheme is 'http' or 'https' (@@: is this too
    restrictive?)

  - Warns if the REQUEST_METHOD is not known (@@: probably too
    restrictive).

  - That SCRIPT_NAME and PATH_INFO are empty or start with /

  - That at least one of SCRIPT_NAME or PATH_INFO are set.

  - That CONTENT_LENGTH is a positive integer.

  - That SCRIPT_NAME is not '/' (it should be '', and PATH_INFO should
    be '/').

  - That wsgi.input has the methods read, readline, readlines, and
    __iter__

  - That wsgi.errors has the methods flush, write, writelines

* The status is a string, contains a space, starts with an integer,
  and that integer is in range (> 100).

* That the headers is a list (not a subclass, not another kind of
  sequence).

* That the items of the headers are tuples of strings.

* That there is no 'status' header (that is used in CGI, but not in
  WSGI).

* That the headers don't contain newlines or colons, end in _ or -, or
  contain characters codes below 037.

* That Content-Type is given if there is content (CGI often has a
  default content type, but WSGI does not).

* That no Content-Type is given when there is no content (@@: is this
  too restrictive?)

* That the exc_info argument to start_response is a tuple or None.

* That all calls to the writer are with strings, and no other methods
  on the writer are accessed.

* That wsgi.input is used properly:

  - .read() is called with exactly one argument

  - That it returns a string

  - That readline, readlines, and __iter__ return strings

  - That .close() is not called

  - No other methods are provided

* That wsgi.errors is used properly:

  - .write() and .writelines() is called with a string

  - That .close() is not called, and no other methods are provided.

* The response iterator:

  - That it is not a string (it should be a list of a single string; a
    string will work, but perform horribly).

  - That .__next__() returns a string

  - That the iterator is not iterated over until start_response has
    been called (that can signal either a server or application
    error).

  - That .close() is called (doesn't raise exception, only prints to
    sys.stderr, because we only know it isn't called when the object
    is garbage collected).
Ú	validatoré    Nz^[a-zA-Z][a-zA-Z0-9\-_]*$z[\000-\037]c                   @   s   e Zd ZdZdS )ÚWSGIWarningz:
    Raised in response to WSGI-spec-related warnings
    N)Ú__name__Ú
__module__Ú__qualname__Ú__doc__© r   r   ú'/usr/lib/python3.10/wsgiref/validate.pyr   y   s    r   c                 G   s   | st |Ž ‚d S ©N)ÚAssertionError)ÚcondÚargsr   r   r	   Úassert_~   s   ÿr   c                 C   s$   t | ƒtu r| S td |t| ƒ¡ƒ‚)Nz!{0} must be of type str (got {1}))ÚtypeÚstrr   ÚformatÚrepr)ÚvalueÚtitler   r   r	   Úcheck_string_type‚   s
   ÿr   c                    s   ‡ fdd„}|S )a®  
    When applied between a WSGI server and a WSGI application, this
    middleware will check for WSGI compliance on a number of levels.
    This middleware does not modify the request or response in any
    way, but will raise an AssertionError if anything seems off
    (except for a failure to close the application iterator, which
    will be printed to stderr -- there's no way to raise an exception
    at that point).
    c                     s’   t t| ƒdkdƒ t | dƒ | \}‰ t|ƒ g ‰‡ ‡fdd„}t|d ƒ|d< t|d ƒ|d< ˆ||ƒ}t |d uo=|dkd	ƒ t|ƒ t|ˆƒS )
Né   zTwo arguments requiredúNo keyword arguments allowedc                     s’   t t| ƒdkpt| ƒdkd| f ƒ t | dƒ | d }| d }t| ƒdkr+| d }nd }t|ƒ t|ƒ t||ƒ t|ƒ ˆ d ¡ tˆ | Ž ƒS )Nr   é   zInvalid number of arguments: %sr   r   é   )r   ÚlenÚcheck_statusÚcheck_headersÚcheck_content_typeÚcheck_exc_infoÚappendÚWriteWrapper)r   ÚkwÚstatusÚheadersÚexc_info©Ústart_responseÚstart_response_startedr   r	   Ústart_response_wrapperŸ   s   ÿ


z;validator.<locals>.lint_app.<locals>.start_response_wrapperú
wsgi.inputúwsgi.errorsFz>The application must return an iterator, if only an empty list)r   r   Úcheck_environÚInputWrapperÚErrorWrapperÚcheck_iteratorÚIteratorWrapper)r   r!   Úenvironr(   Úiterator©Úapplicationr%   r	   Úlint_app”   s   
ÿ
zvalidator.<locals>.lint_appr   )r3   r4   r   r2   r	   r   ˆ   s   )c                   @   s<   e Zd Zdd„ Zdd„ Zdd„ Zdd„ Zd	d
„ Zdd„ ZdS )r,   c                 C   ó
   || _ d S r
   )Úinput)ÚselfÚ
wsgi_inputr   r   r	   Ú__init__Á   ó   
zInputWrapper.__init__c                 G   s0   t t|ƒdkƒ | jj|Ž }t t|ƒtu ƒ |S ©Nr   )r   r   r6   Úreadr   Úbytes©r7   r   Úvr   r   r	   r<   Ä   ó   zInputWrapper.readc                 G   s0   t t|ƒdkƒ | jj|Ž }t t|ƒtu ƒ |S r;   )r   r   r6   Úreadliner   r=   r>   r   r   r	   rA   Ê   r@   zInputWrapper.readlinec                 G   sJ   t t|ƒdkƒ | jj|Ž }t t|ƒtu ƒ |D ]
}t t|ƒtu ƒ q|S r;   )r   r   r6   Ú	readlinesr   Úlistr=   )r7   r   ÚlinesÚliner   r   r	   rB   Ð   s   zInputWrapper.readlinesc                 c   s   � 	 |   ¡ }|s
d S |V  qr
   )rA   )r7   rE   r   r   r	   Ú__iter__Ø   s   €üzInputWrapper.__iter__c                 C   ó   t ddƒ d S )Nr   z input.close() must not be called©r   ©r7   r   r   r	   Úcloseß   ó   zInputWrapper.closeN)	r   r   r   r9   r<   rA   rB   rF   rJ   r   r   r   r	   r,   ¿   s    r,   c                   @   ó4   e Zd Zdd„ Zdd„ Zdd„ Zdd„ Zd	d
„ ZdS )r-   c                 C   r5   r
   )Úerrors)r7   Úwsgi_errorsr   r   r	   r9   ä   r:   zErrorWrapper.__init__c                 C   s    t t|ƒtu ƒ | j |¡ d S r
   )r   r   r   rM   Úwrite©r7   Úsr   r   r	   rO   ç   s   zErrorWrapper.writec                 C   s   | j  ¡  d S r
   )rM   ÚflushrI   r   r   r	   rR   ë   rK   zErrorWrapper.flushc                 C   s   |D ]}|   |¡ qd S r
   )rO   )r7   ÚseqrE   r   r   r	   Ú
writelinesî   s   ÿzErrorWrapper.writelinesc                 C   rG   )Nr   z!errors.close() must not be calledrH   rI   r   r   r	   rJ   ò   rK   zErrorWrapper.closeN)r   r   r   r9   rO   rR   rT   rJ   r   r   r   r	   r-   â   s    r-   c                   @   ó   e Zd Zdd„ Zdd„ ZdS )r    c                 C   r5   r
   )Úwriter)r7   Úwsgi_writerr   r   r	   r9   ÷   r:   zWriteWrapper.__init__c                 C   s   t t|ƒtu ƒ |  |¡ d S r
   )r   r   r=   rV   rP   r   r   r	   Ú__call__ú   s   zWriteWrapper.__call__N)r   r   r   r9   rX   r   r   r   r	   r    õ   ó    r    c                   @   rU   )ÚPartialIteratorWrapperc                 C   r5   r
   ©r1   )r7   Úwsgi_iteratorr   r   r	   r9      r:   zPartialIteratorWrapper.__init__c                 C   s   t | jd ƒS r
   )r/   r1   rI   r   r   r	   rF     s   zPartialIteratorWrapper.__iter__N)r   r   r   r9   rF   r   r   r   r	   rZ   þ   rY   rZ   c                   @   rL   )r/   c                 C   s    || _ t|ƒ| _d| _|| _d S )NF)Úoriginal_iteratorÚiterr1   ÚclosedÚcheck_start_response)r7   r\   r`   r   r   r	   r9   	  s   

zIteratorWrapper.__init__c                 C   s   | S r
   r   rI   r   r   r	   rF     s   zIteratorWrapper.__iter__c                 C   sT   t | j dƒ t| jƒ}t|ƒturt dd|f ƒ | jd ur(t | jdƒ d | _|S )NzIterator read after closedFz$Iterator yielded non-bytestring (%r)zjThe application returns and we started iterating over its body, but start_response has not yet been called)r   r_   Únextr1   r   r=   r`   )r7   r?   r   r   r	   Ú__next__  s   ÿ

ÿzIteratorWrapper.__next__c                 C   s$   d| _ t| jdƒr| j ¡  d S d S )NTrJ   )r_   Úhasattrr]   rJ   rI   r   r   r	   rJ     s   ÿzIteratorWrapper.closec                 C   s"   | j s	tj d¡ t| j dƒ d S )Nz/Iterator garbage collected without being closed)r_   ÚsysÚstderrrO   r   rI   r   r   r	   Ú__del__#  s   ÿÿzIteratorWrapper.__del__N)r   r   r   r9   rF   rb   rJ   rf   r   r   r   r	   r/     s    r/   c                 C   sÖ  t t| ƒtu dt| ƒ| f ƒ dD ]}t || v d|f ƒ qdD ]}t || vd||dd … f ƒ q d| vr<t dt¡ |  ¡ D ]}d	|v rGq@t t| | ƒtu d
|t| | ƒ| | f ƒ q@t t| d ƒtu d| d f ƒ t | d dv d| d  ƒ t	| d ƒ t
| d ƒ | d dvr—t d| d  t¡ t |  d¡ p¤| d  d¡d| d  ƒ t |  d¡ p¸| d  d¡d| d  ƒ |  d¡rÓt t| d ƒdkd| d  ƒ |  d¡sßt d| v dƒ t |  d¡dkdƒ d S )Nz:Environment is not of the right type: %r (environment: %r))	ÚREQUEST_METHODÚSERVER_NAMEÚSERVER_PORTúwsgi.versionr)   r*   zwsgi.multithreadzwsgi.multiprocesszwsgi.run_oncez$Environment missing required key: %r)ÚHTTP_CONTENT_TYPEÚHTTP_CONTENT_LENGTHz8Environment should not have the key: %s (use %s instead)é   ÚQUERY_STRINGz’QUERY_STRING is not in the WSGI environment; the cgi module will use sys.argv when this variable is missing, so application errors are more likelyÚ.z9Environmental variable %s is not a string: %r (value: %r)rj   z#wsgi.version should be a tuple (%r)zwsgi.url_scheme)ÚhttpÚhttpszwsgi.url_scheme unknown: %rr)   r*   rg   )ÚGETÚHEADÚPOSTÚOPTIONSÚPATCHÚPUTÚDELETEÚTRACEzUnknown REQUEST_METHOD: %rÚSCRIPT_NAMEú/z$SCRIPT_NAME doesn't start with /: %rÚ	PATH_INFOz"PATH_INFO doesn't start with /: %rÚCONTENT_LENGTHr   zInvalid CONTENT_LENGTH: %rzgOne of SCRIPT_NAME or PATH_INFO are required (PATH_INFO should at least be '/' if SCRIPT_NAME is empty)zOSCRIPT_NAME cannot be '/'; it should instead be '', and PATH_INFO should be '/')r   r   ÚdictÚwarningsÚwarnr   Úkeysr   ÚtupleÚcheck_inputÚcheck_errorsÚgetÚ
startswithÚint)r0   Úkeyr   r   r	   r+   *  sx   
ÿÿÿÿÿüÿÿÿ
ÿ
þ
þ
þ

ÿ
ÿÿr+   c                 C   ó&   dD ]}t t| |ƒd| |f ƒ qd S )N)r<   rA   rB   rF   z-wsgi.input (%r) doesn't have the attribute %s©r   rc   )r8   Úattrr   r   r	   rƒ   k  ó   
ÿÿÿrƒ   c                 C   r‰   )N)rR   rO   rT   z.wsgi.errors (%r) doesn't have the attribute %srŠ   )rN   r‹   r   r   r	   r„   q  rŒ   r„   c                 C   sz   t | dƒ} |  d d¡d }tt|ƒdkd| ƒ t|ƒ}t|dkd| ƒ t| ƒdk s1| d d	kr;t d
|  t¡ d S d S )NÚStatusr   r   r   z)Status codes must be three characters: %réd   zStatus code is invalid: %ré   ú zjThe status string (%r) should be a three-digit integer followed by a single space and a status explanation)r   Úsplitr   r   r‡   r   r€   r   )r"   Ústatus_codeÚ
status_intr   r   r	   r   w  s   
ÿþýÿr   c                 C   s  t t| ƒtu d| t| ƒf ƒ | D ]n}t t|ƒtu d|t|ƒf ƒ t t|ƒdkƒ |\}}t|dƒ}t|dƒ}t | ¡ dkd| ƒ t d|voKd	|vd
| ƒ t t |¡d| ƒ t | 	d¡ of| 	d¡ d| ƒ t
 |¡rt dd|t
 |¡ d¡f ƒ qd S )Nz%Headers (%r) must be of type list: %rz1Individual headers (%r) must be of type tuple: %rr   úHeader namezHeader valuer"   zyThe Status header cannot be used; it conflicts with CGI script, and HTTP status is not given through headers (value: %r).Ú
ú:z,Header names may not contain ':' or '\n': %rzBad header name: %rú-Ú_z#Names may not end in '-' or '_': %rr   z#Bad header value: %r (bad char: %r))r   r   rC   r‚   r   r   ÚlowerÚ	header_reÚsearchÚendswithÚbad_header_value_reÚgroup)r#   ÚitemÚnamer   r   r   r	   r   …  sB   
ÿÿ
ÿÿ

þÿÿÿ
ÿ€îr   c                 C   s€   t | dƒ} t|  d d¡d ƒ}d}|D ]\}}t |dƒ}| ¡ dkr0||vr) d S tdd| ƒ q||vr>tdd| ƒ d S d S )	Nr�   r   r   )éÌ   i0  r”   zcontent-typezJContent-Type header found in a %s response, which must not return content.z,No Content-Type header found in headers (%s))r   r‡   r‘   r™   r   )r"   r#   ÚcodeÚNO_MESSAGE_BODYr    r   r   r   r	   r   ž  s   

ÿ€ÿr   c                 C   s*   t | d u p
t| ƒtu d| t| ƒf ƒ d S )Nz exc_info (%r) is not a tuple: %r)r   r   r‚   )r$   r   r   r	   r   ®  s   ÿr   c                 C   s   t t| ttfƒ dƒ d S )NzwYou should not return a string as your application iterator, instead return a single-item list containing a bytestring.)r   Ú
isinstancer   r=   r[   r   r   r	   r.   ³  s   ÿr.   )r   Ú__all__Úrerd   r   Úcompilerš   r�   ÚWarningr   r   r   r   r,   r-   r    rZ   r/   r+   rƒ   r„   r   r   r   r   r.   r   r   r   r	   Ú<module>   s0   j

7#		#A