o
    Öž\.  ã                   @   sÊ  d Z ddlmZmZmZ ddlZddlZddlZddlm	Z	m
Z
 ddlmZmZmZmZmZmZ zddlZW n eyA   dZY nw ejdd�G d	d
„ d
eƒƒZdd„ Zdd„ Zdd„ Zdd„ Zejddd�G dd„ deƒƒZejdd�G dd„ deƒƒZejddd�G dd„ deƒƒZejddd�G dd„ deƒƒZejddd�G dd„ deƒƒZejdd�G dd „ d eƒƒZ ejddd�G d!d"„ d"eƒƒZ!ejddd�G d#d$„ d$eƒƒZ"d%d&„ Z#d'd(„ Z$e	d)d*ƒZ%dS )+z
Common verification code.
é    )Úabsolute_importÚdivisionÚprint_functionNé   )Ú	maketransÚ	text_type)ÚCertificateErrorÚDNSMismatchÚIPAddressMismatchÚSRVMismatchÚURIMismatchÚVerificationErrorT)Úslotsc                   @   s    e Zd ZdZe ¡ Ze ¡ ZdS )ÚServiceMatchz<
    A match of a service id and a certificate pattern.
    N)Ú__name__Ú
__module__Ú__qualname__Ú__doc__ÚattrÚibÚ
service_idÚcert_pattern© r   r   ú:/usr/lib/python3/dist-packages/service_identity/_common.pyr      s    r   c                 C   sŒ   g }t | |ƒt | |ƒ }dd„ |D ƒ}|D ]}||vr$| |j|d�¡ q|D ]}||vr<t| |jƒr<| |j|d�¡ q'|rDt|d�‚|S )zä
    Verify whether *cert_patterns* are valid for *obligatory_ids* and
    *optional_ids*.

    *obligatory_ids* must be both present and match.  *optional_ids* must match
    if a pattern of the respective type is present.
    c                 S   s   g | ]}|j ‘qS r   )r   )Ú.0Úmatchr   r   r   Ú
<listcomp>4   s    z+verify_service_identity.<locals>.<listcomp>)Úmismatched_id)Úerrors)Ú_find_matchesÚappendÚerror_on_mismatchÚ_contains_instance_ofÚpattern_classr   )Úcert_patternsÚobligatory_idsÚoptional_idsr   ÚmatchesÚmatched_idsÚir   r   r   Úverify_service_identity'   s$   
ÿ€
ÿ€
r*   c                 C   s8   g }|D ]}| D ]}|  |¡r| t||d�¡ qq|S )a  
    Search for matching certificate patterns and service_ids.

    :param cert_ids: List certificate IDs like DNSPattern.
    :type cert_ids: `list`

    :param service_ids: List of service IDs like DNS_ID.
    :type service_ids: `list`

    :rtype: `list` of `ServiceMatch`
    )r   r   )Úverifyr    r   )r$   Úservice_idsr'   ÚsidÚcidr   r   r   r   I   s   
€þr   c                 C   s   | D ]
}t ||ƒr dS qdS )zB
    :type seq: iterable
    :type cl: type

    :rtype: bool
    TF)Ú
isinstance)ÚseqÚclÚer   r   r   r"   ]   s
   
ÿr"   c                 C   s~   t | tƒrz|  d¡} W n
 ty   Y dS w zt| ƒ W dS  ty'   Y nw zt |  dd¡¡ W dS  ty>   Y dS w )zð
    Check whether *pattern* could be/match an IP address.

    :param pattern: A pattern for a host name.
    :type pattern: `bytes` or `unicode`

    :return: `True` if *pattern* could be an IP address, else `False`.
    :rtype: bool
    ÚasciiFTÚ*Ú1)	r/   ÚbytesÚdecodeÚUnicodeErrorÚintÚ
ValueErrorÚ	ipaddressÚ
ip_addressÚreplace©Úpatternr   r   r   Ú_is_ip_addressj   s$   

ÿÿýÿr@   F)Úinitr   c                   @   s*   e Zd ZdZe ¡ Ze d¡Z	dd„ Z
dS )Ú
DNSPatternz7
    A DNS pattern as extracted from certificates.
    ó   ^[a-z0-9\-_.]+$c                 C   sh   t |tƒs	tdƒ‚| ¡ }|dkst|ƒsd|v r td |¡ƒ‚| t¡| _	d| j	v r2t
| j	ƒ dS dS )ú(
        :type pattern: `bytes`
        z'The DNS pattern must be a bytes string.ó    ó    zInvalid DNS pattern {0!r}.ó   *N)r/   r6   Ú	TypeErrorÚstripr@   r   ÚformatÚ	translateÚ_TRANS_TO_LOWERr?   Ú_validate_pattern©Úselfr?   r   r   r   Ú__init__’   s   
ÿ
ÿzDNSPattern.__init__N)r   r   r   r   r   r   r?   ÚreÚcompileÚ_RE_LEGAL_CHARSrP   r   r   r   r   rB   ˆ   s
    
rB   c                   @   s$   e Zd ZdZe ¡ Zedd„ ƒZdS )ÚIPAddressPatternz?
    An IP address pattern as extracted from certificates.
    c                 C   s0   z	| t  |¡d�W S  ty   td |¡ƒ‚w )Nr>   z Invalid IP address pattern {!r}.)r;   r<   r:   r   rJ   )ÚclsÚbsr   r   r   Ú
from_bytes­   s   ÿÿzIPAddressPattern.from_bytesN)	r   r   r   r   r   r   r?   ÚclassmethodrW   r   r   r   r   rT   ¥   s
    rT   c                   @   ó(   e Zd ZdZe ¡ Ze ¡ Zdd„ ZdS )Ú
URIPatternz8
    An URI pattern as extracted from certificates.
    c                 C   sd   t |tƒs	tdƒ‚| ¡  t¡}d|vsd|v st|ƒr#td |¡ƒ‚| 	d¡\| _
}t|ƒ| _dS )rD   z'The URI pattern must be a bytes string.ó   :rG   zInvalid URI pattern {0!r}.N)r/   r6   rH   rI   rK   rL   r@   r   rJ   ÚsplitÚprotocol_patternrB   Údns_pattern)rO   r?   Úhostnamer   r   r   rP   À   s   
ÿzURIPattern.__init__N)	r   r   r   r   r   r   r]   r^   rP   r   r   r   r   rZ   ·   ó
    rZ   c                   @   rY   )Ú
SRVPatternz8
    An SRV pattern as extracted from certificates.
    c                 C   s~   t |tƒs	tdƒ‚| ¡  t¡}|d dks"d|vs"d|v s"t|ƒr)td |¡ƒ‚| 	dd¡\}}|dd… | _
t|ƒ| _dS )	rD   z'The SRV pattern must be a bytes string.r   é_   ó   .rG   zInvalid SRV pattern {0!r}.r   N)r/   r6   rH   rI   rK   rL   r@   r   rJ   r\   Úname_patternrB   r^   )rO   r?   Únamer_   r   r   r   rP   Ú   s   
ÿÿzSRVPattern.__init__N)	r   r   r   r   r   r   rd   r^   rP   r   r   r   r   ra   Ñ   r`   ra   c                   @   s:   e Zd ZdZe ¡ Ze d¡Z	e
ZeZdd„ Zdd„ ZdS )ÚDNS_IDz)
    A DNS service ID, aka hostname.
    rC   c                 C   s�   t |tƒs	tdƒ‚| ¡ }|dkst|ƒrtdƒ‚tdd„ |D ƒƒr.tr*t |¡}n	t	dƒ‚| d¡}| 
t¡| _| j | j¡du rFtdƒ‚dS )	z+
        :type hostname: `unicode`
        z DNS-ID must be a unicode string.Ú zInvalid DNS-ID.c                 s   s   � | ]	}t |ƒd kV  qdS )é   N)Úord)r   Úcr   r   r   Ú	<genexpr>	  s   € z"DNS_ID.__init__.<locals>.<genexpr>z+idna library is required for non-ASCII IDs.r3   N)r/   r   rH   rI   r@   r:   ÚanyÚidnaÚencodeÚImportErrorrK   rL   r_   rS   r   )rO   r_   Úascii_idr   r   r   rP   þ   s    
ÿ
ÿzDNS_ID.__init__c                 C   s   t || jƒrt|j| jƒS dS )zC
        https://tools.ietf.org/search/rfc6125#section-6.4
        F)r/   r#   Ú_hostname_matchesr?   r_   rN   r   r   r   r+     s   zDNS_ID.verifyN)r   r   r   r   r   r   r_   rQ   rR   rS   rB   r#   r	   r!   rP   r+   r   r   r   r   rf   ñ   s    
rf   c                   @   s.   e Zd ZdZejejd�Ze	Z
eZdd„ ZdS )ÚIPAddress_IDz#
    An IP address service ID.
    )Ú	converterc                 C   s   | j |jkS )zC
        https://tools.ietf.org/search/rfc2818#section-3.1
        )Úipr?   rN   r   r   r   r+   ,  s   zIPAddress_ID.verifyN)r   r   r   r   r   r   r;   r<   rt   rT   r#   r
   r!   r+   r   r   r   r   rr   !  s    rr   c                   @   ó8   e Zd ZdZe ¡ Ze ¡ ZeZ	e
Zdd„ Zdd„ ZdS )ÚURI_IDz
    An URI service ID.
    c                 C   sf   t |tƒs	tdƒ‚| ¡ }d|vst|ƒrtdƒ‚| d¡\}}| d¡ t	¡| _
t| d¡ƒ| _dS )z&
        :type uri: `unicode`
        z URI-ID must be a unicode string.ú:zInvalid URI-ID.r3   ú/N)r/   r   rH   rI   r@   r:   r\   rn   rK   rL   Úprotocolrf   Údns_id)rO   ÚuriÚprotr_   r   r   r   rP   ?  s   
zURI_ID.__init__c                 C   s*   t || jƒr|j| jko| j |j¡S dS )zE
        https://tools.ietf.org/search/rfc6125#section-6.5.2
        F)r/   r#   r]   ry   rz   r+   r^   rN   r   r   r   r+   O  s
   þzURI_ID.verifyN)r   r   r   r   r   r   ry   rz   rZ   r#   r   r!   rP   r+   r   r   r   r   rv   3  ó    rv   c                   @   ru   )ÚSRV_IDz
    An SRV service ID.
    c                 C   sv   t |tƒs	tdƒ‚| ¡ }d|vst|ƒs|d dkrtdƒ‚| dd¡\}}|dd…  d¡ t	¡| _
t|ƒ| _dS )	z&
        :type srv: `unicode`
        z SRV-ID must be a unicode string.Ú.r   Ú_zInvalid SRV-ID.r   Nr3   )r/   r   rH   rI   r@   r:   r\   rn   rK   rL   re   rf   rz   )rO   Úsrvre   r_   r   r   r   rP   h  s   
zSRV_ID.__init__c                 C   s*   t || jƒr| j|jko| j |j¡S dS )zE
        https://tools.ietf.org/search/rfc6125#section-6.5.1
        F)r/   r#   re   rd   rz   r+   r^   rN   r   r   r   r+   x  s
   ÿzSRV_ID.verifyN)r   r   r   r   r   r   re   rz   ra   r#   r   r!   rP   r+   r   r   r   r   r~   \  r}   r~   c                 C   sZ   d| v r)|   dd¡\}}|  dd¡\}}||krdS | d¡r!dS |dkp(||kS | |kS )z«
    :type cert_pattern: `bytes`
    :type actual_hostname: `bytes`

    :return: `True` if *cert_pattern* matches *actual_hostname*, else `False`.
    :rtype: `bool`
    rG   rc   r   Fs   xn--)r\   Ú
startswith)r   Úactual_hostnameÚ	cert_headÚ	cert_tailÚactual_headÚactual_tailr   r   r   rq   „  s   
rq   c                 C   s‚   |   d¡}|dkrtd | ¡ƒ‚|  d¡}t|ƒdk r"td | ¡ƒ‚d|d vr/td | ¡ƒ‚td	d
„ |D ƒƒr?td | ¡ƒ‚dS )z˜
    Check whether the usage of wildcards within *cert_pattern* conforms with
    our expectations.

    :type hostname: `bytes`

    :return: None
    rG   r   z7Certificate's DNS-ID {0!r} contains too many wildcards.rc   é   zJCertificate's DNS-ID {0!r} has too few host components for wildcard usage.r   zECertificate's DNS-ID {0!r} has a wildcard outside the left-most part.c                 s   s   � | ]}t |ƒ V  qd S )N)Úlen)r   Úpr   r   r   rk   ¶  s   € z$_validate_pattern.<locals>.<genexpr>z0Certificate's DNS-ID {0!r} contains empty parts.N)Úcountr   rJ   r\   r‰   rl   )r   ÚcntÚpartsr   r   r   rM   š  s2   
	ÿÿ
þþÿÿÿrM   s   ABCDEFGHIJKLMNOPQRSTUVWXYZs   abcdefghijklmnopqrstuvwxyz)&r   Ú
__future__r   r   r   r;   rQ   r   Ú_compatr   r   Ú
exceptionsr   r	   r
   r   r   r   rm   ro   ÚsÚobjectr   r*   r   r"   r@   rB   rT   rZ   ra   rf   rr   rv   r~   rq   rM   rL   r   r   r   r   Ú<module>   sN     
ÿ
	"

/('%ÿ