o
    ç÷¡g­,  ã                   @   sÒ   d Z ddlmZ ddlmZ ddlmZ ddlmZ G dd„ dƒZ	G d	d
„ d
e	ƒZ
G dd„ de	ƒZG dd„ de	ƒZG dd„ deƒZG dd„ deƒZedddgƒZG dd„ deƒZG dd„ deƒZG dd„ dƒZdS )z¿
Modern, adaptable authentication machinery.

Replaces certain parts of `.SSHClient`. For a concrete implementation, see the
``OpenSSHAuthStrategy`` class in `Fabric <https://fabfile.org>`_.
é    )Ú
namedtupleé   )ÚAgentKey)Ú
get_logger)ÚAuthenticationExceptionc                   @   s0   e Zd ZdZdd„ Zdd„ Zdd„ Zdd	„ Zd
S )Ú
AuthSourcezã
    Some SSH authentication source, such as a password, private key, or agent.

    See subclasses in this module for concrete implementations.

    All implementations must accept at least a ``username`` (``str``) kwarg.
    c                 C   ó
   || _ d S ©N©Úusername)Úselfr   © r   úA/usr/local/lib/python3.10/dist-packages/paramiko/auth_strategy.pyÚ__init__   ó   
zAuthSource.__init__c                 K   s0   dd„ |  ¡ D ƒ}d |¡}| jj› d|› d�S )Nc                 S   s   g | ]\}}|› d |›�‘qS )ú=r   )Ú.0ÚkÚvr   r   r   Ú
<listcomp>   s    z$AuthSource._repr.<locals>.<listcomp>z, ú(ú))ÚitemsÚjoinÚ	__class__Ú__name__)r   ÚkwargsÚpairsÚjoinedr   r   r   Ú_repr   s   
zAuthSource._reprc                 C   s   |   ¡ S r	   )r   ©r   r   r   r   Ú__repr__"   s   zAuthSource.__repr__c                 C   ó   t ‚)z)
        Perform authentication.
        ©ÚNotImplementedError©r   Ú	transportr   r   r   Úauthenticate%   s   zAuthSource.authenticateN)r   Ú
__module__Ú__qualname__Ú__doc__r   r   r!   r'   r   r   r   r   r      s    r   c                   @   ó   e Zd ZdZdd„ ZdS )ÚNoneAuthzS
    Auth type "none", ie https://www.rfc-editor.org/rfc/rfc4252#section-5.2 .
    c                 C   s   |  | j¡S r	   )Ú	auth_noner   r%   r   r   r   r'   1   s   zNoneAuth.authenticateN©r   r(   r)   r*   r'   r   r   r   r   r,   ,   s    r,   c                       s4   e Zd ZdZ‡ fdd„Z‡ fdd„Zdd„ Z‡  ZS )ÚPassworda  
    Password authentication.

    :param callable password_getter:
        A lazy callable that should return a `str` password value at
        authentication time, such as a `functools.partial` wrapping
        `getpass.getpass`, an API call to a secrets store, or similar.

        If you already know the password at instantiation time, you should
        simply use something like ``lambda: "my literal"`` (for a literal, but
        also, shame on you!) or ``lambda: variable_name`` (for something stored
        in a variable).
    c                    ó   t ƒ j|d� || _d S ©Nr
   )Úsuperr   Úpassword_getter)r   r   r3   ©r   r   r   r   D   s   
zPassword.__init__c                    s   t ƒ j| jd�S )N)Úuser)r2   r   r   r    r4   r   r   r!   H   s   zPassword.__repr__c                 C   s   |   ¡ }| | j|¡S r	   )r3   Úauth_passwordr   )r   r&   Úpasswordr   r   r   r'   M   s   zPassword.authenticate)r   r(   r)   r*   r   r!   r'   Ú__classcell__r   r   r4   r   r/   5   s
    r/   c                   @   r+   )Ú
PrivateKeya‹  
    Essentially a mixin for private keys.

    Knows how to auth, but leaves key material discovery/loading/decryption to
    subclasses.

    Subclasses **must** ensure that they've set ``self.pkey`` to a decrypted
    `.PKey` instance before calling ``super().authenticate``; typically
    either in their ``__init__``, or in an overridden ``authenticate`` prior to
    its `super` call.
    c                 C   s   |  | j| j¡S r	   )Úauth_publickeyr   Úpkeyr%   r   r   r   r'   e   s   zPrivateKey.authenticateNr.   r   r   r   r   r9   X   s    r9   c                       s,   e Zd ZdZ‡ fdd„Z‡ fdd„Z‡  ZS )ÚInMemoryPrivateKeyz1
    An in-memory, decrypted `.PKey` object.
    c                    r0   r1   )r2   r   r;   )r   r   r;   r4   r   r   r   n   s   
zInMemoryPrivateKey.__init__c                    s(   t ƒ j| jd�}t| jtƒr|d7 }|S )N)r;   z [agent])r2   r   r;   Ú
isinstancer   )r   Úrepr4   r   r   r!   s   s   zInMemoryPrivateKey.__repr__©r   r(   r)   r*   r   r!   r8   r   r   r4   r   r<   i   s    r<   c                       ó(   e Zd ZdZ‡ fdd„Zdd„ Z‡  ZS )ÚOnDiskPrivateKeya™  
    Some on-disk private key that needs opening and possibly decrypting.

    :param str source:
        String tracking where this key's path was specified; should be one of
        ``"ssh-config"``, ``"python-config"``, or ``"implicit-home"``.
    :param Path path:
        The filesystem path this key was loaded from.
    :param PKey pkey:
        The `PKey` object this auth source uses/represents.
    c                    s>   t ƒ j|d� || _d}||vrtd|›�ƒ‚|| _|| _d S )Nr
   )z
ssh-configzpython-configzimplicit-homez source argument must be one of: )r2   r   ÚsourceÚ
ValueErrorÚpathr;   )r   r   rB   rD   r;   Úallowedr4   r   r   r   ‰   s   
zOnDiskPrivateKey.__init__c                 C   s   | j | j| jt| jƒd�S )N)ÚkeyrB   rD   )r   r;   rB   ÚstrrD   r    r   r   r   r!   “   s   ÿzOnDiskPrivateKey.__repr__r?   r   r   r4   r   rA   |   s    
rA   ÚSourceResultrB   Úresultc                       r@   )Ú
AuthResultaÞ  
    Represents a partial or complete SSH authentication attempt.

    This class conceptually extends `AuthStrategy` by pairing the former's
    authentication **sources** with the **results** of trying to authenticate
    with them.

    `AuthResult` is a (subclass of) `list` of `namedtuple`, which are of the
    form ``namedtuple('SourceResult', 'source', 'result')`` (where the
    ``source`` member is an `AuthSource` and the ``result`` member is either a
    return value from the relevant `.Transport` method, or an exception
    object).

    .. note::
        Transport auth method results are always themselves a ``list`` of "next
        allowable authentication methods".

        In the simple case of "you just authenticated successfully", it's an
        empty list; if your auth was rejected but you're allowed to try again,
        it will be a list of string method names like ``pubkey`` or
        ``password``.

        The ``__str__`` of this class represents the empty-list scenario as the
        word ``success``, which should make reading the result of an
        authentication session more obvious to humans.

    Instances also have a `strategy` attribute referencing the `AuthStrategy`
    which was attempted.
    c                    s   || _ tƒ j|i |¤Ž d S r	   )Ústrategyr2   r   )r   rK   Úargsr   r4   r   r   r   Ç   s   zAuthResult.__init__c                 C   s   d  dd„ | D ƒ¡S )NÚ
c                 s   s&   � | ]}|j › d |jpd› �V  qdS )z -> ÚsuccessN)rB   rI   )r   Úxr   r   r   Ú	<genexpr>Ð   s   € 
ÿz%AuthResult.__str__.<locals>.<genexpr>)r   r    r   r   r   Ú__str__Ë   s   
ÿzAuthResult.__str__)r   r(   r)   r*   r   rQ   r8   r   r   r4   r   rJ   ¨   s    rJ   c                   @   s    e Zd ZdZdd„ Zdd„ ZdS )ÚAuthFailurea®  
    Basic exception wrapping an `AuthResult` indicating overall auth failure.

    Note that `AuthFailure` descends from `AuthenticationException` but is
    generally "higher level"; the latter is now only raised by individual
    `AuthSource` attempts and should typically only be seen by users when
    encapsulated in this class. It subclasses `AuthenticationException`
    primarily for backwards compatibility reasons.
    c                 C   r   r	   ©rI   )r   rI   r   r   r   r   á   r   zAuthFailure.__init__c                 C   s   dt | jƒ S )NrM   )rG   rI   r    r   r   r   rQ   ä   s   zAuthFailure.__str__N)r   r(   r)   r*   r   rQ   r   r   r   r   rR   Ö   s    
rR   c                   @   s(   e Zd ZdZdd„ Zdd„ Zdd„ ZdS )	ÚAuthStrategya   
    This class represents one or more attempts to auth with an SSH server.

    By default, subclasses must at least accept an ``ssh_config``
    (`.SSHConfig`) keyword argument, but may opt to accept more as needed for
    their particular strategy.
    c                 C   s   || _ ttƒ| _d S r	   )Ú
ssh_configr   r   Úlog)r   rU   r   r   r   r   ñ   s   zAuthStrategy.__init__c                 C   r"   )a[  
        Generator yielding `AuthSource` instances, in the order to try.

        This is the primary override point for subclasses: you figure out what
        sources you need, and ``yield`` them.

        Subclasses _of_ subclasses may find themselves wanting to do things
        like filtering or discarding around a call to `super`.
        r#   r    r   r   r   Úget_sourcesø   s   
zAuthStrategy.get_sourcesc                 C   s´   d}t | d�}|  ¡ D ]E}| j d|› �¡ z	| |¡}d}W n$ tyC } z|}|jj}| j d|› d|› �¡ W Y d}~nd}~ww | 	t
||ƒ¡ |rP nq|sXt|d�‚|S )	z»
        Handles attempting `AuthSource` instances yielded from `get_sources`.

        You *normally* won't need to override this, but it's an option for
        advanced users.
        F)rK   zTrying TzAuthentication via z failed with NrS   )rJ   rW   rV   Údebugr'   Ú	Exceptionr   r   ÚinfoÚappendrH   rR   )r   r&   Ú	succeededÚoverall_resultrB   rI   ÚeÚsource_classr   r   r   r'     s,   

ÿ€÷ÿ
zAuthStrategy.authenticateN)r   r(   r)   r*   r   rW   r'   r   r   r   r   rT   è   s
    rT   N)r*   Úcollectionsr   Úagentr   Úutilr   Ússh_exceptionr   r   r,   r/   r9   r<   rA   rH   ÚlistrJ   rR   rT   r   r   r   r   Ú<module>   s    	#!.