o
    ç÷¡g I  ã                   @   s~  U d dl Z d dlmZ d dlmZ d dlmZmZ d dlm	Z	 e
ejƒZdZd Zd Zd Zd Zd Zd Zd Zd Zd Zd Zd Zd Zd Zd Zer‹e e de ¡ ¡¡dd… Ze ¡ Ze  ¡ Ze !¡ Ze "¡ Ze #¡ Ze $¡ Ze %¡ Ze &¡ Ze '¡ Ze (¡ Ze )¡ Ze *¡ Ze +¡ Ze ,¡ Ze -¡ Z.e/e0d< e 1¡ Z2e/e0d< e 3¡ Z4e/e0d	< e 5¡ Z6e/e0d
< e 7¡ Z8e/e0d< e 9¡ Z:e/e0d< e ;¡ Z<e/e0d< e =¡ Z>e/e0d< e ?¡ Z@e/e0d< e e de A¡ ¡¡dd… ZBeCe0d< e D¡ ZEe/e0d< e F¡ ZGe/e0d< e H¡ ZIe/e0d< e J¡ ZKe/e0d< e L¡ ZMe/e0d< e N¡ ZOe/e0d< e P¡ ZQe/e0d< e R¡ ZSe/e0d< e T¡ ZUe/e0d< e V¡ ZWe/e0d< e e de X¡ ¡¡dd… ZYeCe0d< e Z¡ Z[e/e0d< e \¡ Z]e/e0d< e ^¡ Z_e/e0d< e `¡ Zae/e0d< e b¡ Zce/e0d < e d¡ Zee/e0d!< e f¡ Zge/e0d"< e h¡ Zie/e0d#< e j¡ Zke/e0d$< e l¡ Zme/e0d%< eZneZoeZpeZqeZreZsd&Ztd'Zud(Zvd)Zwewfd*e/d+e/d,e/d-e/d.df
d/d0„Zxd1e/d2e/d.ee/e/e/f fd3d4„Zyd5ewfd6eCd7eCd*e/d+e/d,e/d8e/d-e/d.eCfd9d:„Zzeneofd6eCd1e/d2e/d.eCfd;d<„Z{d=eCd6eCd.e
fd>d?„Z|d1e/d2e/d@e/d.dfdAdB„Z}dCe/d6eCd7eCd1e/d2e/d@e/d.eCfdDdE„Z~d6eCd1e/d2e/d@e/d.eCf
dFdG„Zd=eCd6eCd.e
fdHdI„Z€e€Z�dS )Jé    N)ÚTuple)ÚffiÚlib)Úensureó    úchar *Úcrypto_pwhash_ALG_ARGON2I13Úcrypto_pwhash_ALG_ARGON2ID13Úcrypto_pwhash_ALG_DEFAULTÚcrypto_pwhash_SALTBYTESÚcrypto_pwhash_STRBYTESÚcrypto_pwhash_PASSWD_MINÚcrypto_pwhash_PASSWD_MAXÚcrypto_pwhash_BYTES_MINÚcrypto_pwhash_BYTES_MAXÚcrypto_pwhash_argon2i_STRPREFIXÚ"crypto_pwhash_argon2i_MEMLIMIT_MINÚ"crypto_pwhash_argon2i_MEMLIMIT_MAXÚ"crypto_pwhash_argon2i_OPSLIMIT_MINÚ"crypto_pwhash_argon2i_OPSLIMIT_MAXÚ*crypto_pwhash_argon2i_OPSLIMIT_INTERACTIVEÚ*crypto_pwhash_argon2i_MEMLIMIT_INTERACTIVEÚ'crypto_pwhash_argon2i_OPSLIMIT_MODERATEÚ'crypto_pwhash_argon2i_MEMLIMIT_MODERATEÚ(crypto_pwhash_argon2i_OPSLIMIT_SENSITIVEÚ(crypto_pwhash_argon2i_MEMLIMIT_SENSITIVEÚ crypto_pwhash_argon2id_STRPREFIXÚ#crypto_pwhash_argon2id_MEMLIMIT_MINÚ#crypto_pwhash_argon2id_MEMLIMIT_MAXÚ#crypto_pwhash_argon2id_OPSLIMIT_MINÚ#crypto_pwhash_argon2id_OPSLIMIT_MAXÚ+crypto_pwhash_argon2id_OPSLIMIT_INTERACTIVEÚ+crypto_pwhash_argon2id_MEMLIMIT_INTERACTIVEÚ(crypto_pwhash_argon2id_OPSLIMIT_MODERATEÚ(crypto_pwhash_argon2id_MEMLIMIT_MODERATEÚ)crypto_pwhash_argon2id_OPSLIMIT_SENSITIVEÚ)crypto_pwhash_argon2id_MEMLIMIT_SENSITIVEéÿÿÿ?é?   l   ÿÿÿÿ i   ÚnÚrÚpÚmaxmemÚreturnc                 C   s  t |dkdtjd� t |dkdtjd� t | | d @ dkdtjd� t | dkdtjd� t |t| kd t¡tjd� t | dd	| > k tjd� |d
 | }td
 }t | d || ktjd� d| | d  d }t |t| ktjd� t |tj| ktjd� t || |kdtjd� d S )Nr   zInvalid block size©ÚraisingzInvalid parallelization factoré   z Cost factor must be a power of 2zCost factor must be at least 2zp*r is greater than {}é   é€   é   é    é   z7Memory limit would be exceeded with the choosen n, r, p)r   ÚexcÚ
ValueErrorÚSCRYPT_PR_MAXÚformatÚ
UINT64_MAXÚsysÚmaxsize)r)   r*   r+   r,   ÚBlenÚiÚVlen© r@   úF/usr/local/lib/python3.10/dist-packages/nacl/bindings/crypto_pwhash.pyÚ_check_memory_occupation¿   s2   ý
ý

ýrB   ÚopslimitÚmemlimitc                 C   s°   | dk rd} d}| |d k r)d}| d|  }t ddƒD ]}d| |d kr' nqn*||d  }t ddƒD ]}d| |d kr@ nq4| d d|  }|d	krOd	}|| }|||fS )
z/Python implementation of libsodium's pickparamsi €  é   r4   r0   r5   r(   r3   r2   r'   )Úrange)rC   rD   r*   r+   ÚmaxnÚn_log2Úmaxrpr@   r@   rA   Ú nacl_bindings_pick_scrypt_paramsé   s*   ÿ€ÿ
rJ   é@   ÚpasswdÚsaltÚdklenc           	      C   sÖ   t tdtjd� t t|tƒtd� t t|tƒtd� t t|tƒtd� t t| tƒtd� t t|tƒtd� t||||ƒ t	 
d|¡}t | t| ƒ|t|ƒ|||||¡	}t |dkdtjd� t	 t	 d|¡|¡dd… S )aš  
    Derive a cryptographic key using the ``passwd`` and ``salt``
    given as input.

    The work factor can be tuned by by picking different
    values for the parameters

    :param bytes passwd:
    :param bytes salt:
    :param bytes salt: *must* be *exactly* :py:const:`.SALTBYTES` long
    :param int dklen:
    :param int opslimit:
    :param int n:
    :param int r: block size,
    :param int p: the parallelism factor
    :param int maxmem: the maximum available memory available for scrypt's
                       operations
    :rtype: bytes
    :raises nacl.exceptions.UnavailableError: If called when using a
        minimal build of libsodium.
    úNot available in minimal buildr.   z	uint8_t[]r   ú$Unexpected failure in key derivationr   N)r   Ú&has_crypto_pwhash_scryptsalsa208sha256r6   ÚUnavailableErrorÚ
isinstanceÚintÚ	TypeErrorÚbytesrB   r   Únewr   Ú%crypto_pwhash_scryptsalsa208sha256_llÚlenÚRuntimeErrorÚbufferÚcast)	rL   rM   r)   r*   r+   rN   r,   ÚbufÚretr@   r@   rA   rX   	  s*   ýÿýrX   c                 C   sP   t tdtjd� t dt¡}t || t	| ƒ||¡}t |dkdtj
d� t |¡S )a„  
    Derive a cryptographic key using the ``passwd`` and ``salt``
    given as input, returning a string representation which includes
    the salt and the tuning parameters.

    The returned string can be directly stored as a password hash.

    See :py:func:`.crypto_pwhash_scryptsalsa208sha256` for a short
    discussion about ``opslimit`` and ``memlimit`` values.

    :param bytes passwd:
    :param int opslimit:
    :param int memlimit:
    :return: serialized key hash, including salt and tuning parameters
    :rtype: bytes
    :raises nacl.exceptions.UnavailableError: If called when using a
        minimal build of libsodium.
    rO   r.   úchar[]r   z&Unexpected failure in password hashing)r   rQ   r6   rR   r   rW   ÚSCRYPT_STRBYTESr   Ú&crypto_pwhash_scryptsalsa208sha256_strrY   rZ   Ústring)rL   rC   rD   r]   r^   r@   r@   rA   ra   E  s   ýÿý
ra   Úpasswd_hashc                 C   sV   t tdtjd� t t| ƒtd kdtjd� t | |t|ƒ¡}t |dkdtj	d� dS )a9  
    Verifies the ``passwd`` against the ``passwd_hash`` that was generated.
    Returns True or False depending on the success

    :param passwd_hash: bytes
    :param passwd: bytes
    :rtype: boolean
    :raises nacl.exceptions.UnavailableError: If called when using a
        minimal build of libsodium.
    rO   r.   r0   zInvalid password hashr   úWrong passwordT)
r   rQ   r6   rR   rY   r`   r7   r   Ú-crypto_pwhash_scryptsalsa208sha256_str_verifyÚInvalidkeyError©rc   rL   r^   r@   r@   rA   re   q  s   ýý
ÿre   Úalgc                 C   sâ   |t kr6|tk rt d t¡¡‚|tkrt d t¡¡‚| tk r(t d t¡¡‚| tkr4t d t¡¡‚d S |tkrl|t	k rFt d t	¡¡‚|t
krRt d t
¡¡‚| tk r^t d t¡¡‚| tkrjt d t¡¡‚d S t d¡‚)Nz"memlimit must be at least {} bytesz!memlimit must be at most {} byteszopslimit must be at least {}zopslimit must be at most {}zUnsupported algorithm)r   r   r6   r7   r9   r   r   r   r	   r   r   r   r    rU   )rC   rD   rh   r@   r@   rA   Ú_check_argon2_limits_alg’  sj   ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ
ri   Úoutlenc              
   C   s  t t| tƒtjd� t t|tƒtjd� t t|tƒtjd� t t|tƒtjd� t t|tƒtjd� t|ƒtkr@t d 	t¡¡‚| t
k rLt d 	t
¡¡‚| tkrXt d 	t¡¡‚t|||ƒ t d| ¡}t || |t|ƒ||||¡}t |dkdtjd� t || ¡dd… S )	a  
    Derive a raw cryptographic key using the ``passwd`` and the ``salt``
    given as input to the ``alg`` algorithm.

    :param outlen: the length of the derived key
    :type outlen: int
    :param passwd: The input password
    :type passwd: bytes
    :param salt:
    :type salt: bytes
    :param opslimit: computational cost
    :type opslimit: int
    :param memlimit: memory cost
    :type memlimit: int
    :param alg: algorithm identifier
    :type alg: int
    :return: derived key
    :rtype: bytes
    r.   z"salt must be exactly {} bytes longz*derived key must be at least {} bytes longz)derived key must be at most {} bytes longzunsigned char[]r   rP   N)r   rS   rT   r6   rU   rV   rY   r   r7   r9   r   r   ri   r   rW   r   Úcrypto_pwhashrZ   r[   )rj   rL   rM   rC   rD   rh   Úoutbufr^   r@   r@   rA   Úcrypto_pwhash_algË  sD   ÿÿÿÿÿÿÿýrm   c                 C   s„   t t|tƒtd� t t|tƒtd� t t| tƒtd� t|||ƒ t dd¡}t 	|| t
| ƒ|||¡}t |dkdtjd� t |¡S )a  
    Derive a cryptographic key using the ``passwd`` given as input
    and a random salt, returning a string representation which
    includes the salt, the tuning parameters and the used algorithm.

    :param passwd: The input password
    :type passwd: bytes
    :param opslimit: computational cost
    :type opslimit: int
    :param memlimit: memory cost
    :type memlimit: int
    :param alg: The algorithm to use
    :type alg: int
    :return: serialized derived key and parameters
    :rtype: bytes
    r.   r_   r2   r   rP   )r   rS   rT   rU   rV   ri   r   rW   r   Úcrypto_pwhash_str_algrY   r6   rZ   rb   )rL   rC   rD   rh   rl   r^   r@   r@   rA   rn     s   ÿý
rn   c                 C   sf   t t| tƒtd� t t|tƒtd� t t| ƒdkdtjd� t | |t|ƒ¡}t |dkdtj	d� dS )a4  
    Verifies the ``passwd`` against a given password hash.

    Returns True on success, raises InvalidkeyError on failure
    :param passwd_hash: saved password hash
    :type passwd_hash: bytes
    :param passwd: password to be checked
    :type passwd: bytes
    :return: success
    :rtype: boolean
    r.   é   z#Hash must be at most 127 bytes longr   rd   T)
r   rS   rV   rU   rY   r6   r7   r   Úcrypto_pwhash_str_verifyrf   rg   r@   r@   rA   rp   =  s   
ýrp   )‚r;   Útypingr   Únacl.exceptionsÚ
exceptionsr6   Únacl._sodiumr   r   r   ÚboolÚ-PYNACL_HAS_CRYPTO_PWHASH_SCRYPTSALSA208SHA256rQ   Ú,crypto_pwhash_scryptsalsa208sha256_STRPREFIXÚ,crypto_pwhash_scryptsalsa208sha256_SALTBYTESÚ+crypto_pwhash_scryptsalsa208sha256_STRBYTESÚ-crypto_pwhash_scryptsalsa208sha256_PASSWD_MINÚ-crypto_pwhash_scryptsalsa208sha256_PASSWD_MAXÚ,crypto_pwhash_scryptsalsa208sha256_BYTES_MINÚ,crypto_pwhash_scryptsalsa208sha256_BYTES_MAXÚ/crypto_pwhash_scryptsalsa208sha256_MEMLIMIT_MINÚ/crypto_pwhash_scryptsalsa208sha256_MEMLIMIT_MAXÚ/crypto_pwhash_scryptsalsa208sha256_OPSLIMIT_MINÚ/crypto_pwhash_scryptsalsa208sha256_OPSLIMIT_MAXÚ7crypto_pwhash_scryptsalsa208sha256_OPSLIMIT_INTERACTIVEÚ7crypto_pwhash_scryptsalsa208sha256_MEMLIMIT_INTERACTIVEÚ5crypto_pwhash_scryptsalsa208sha256_OPSLIMIT_SENSITIVEÚ5crypto_pwhash_scryptsalsa208sha256_MEMLIMIT_SENSITIVErb   r\   Ú,crypto_pwhash_scryptsalsa208sha256_strprefixÚ,crypto_pwhash_scryptsalsa208sha256_saltbytesÚ+crypto_pwhash_scryptsalsa208sha256_strbytesÚ-crypto_pwhash_scryptsalsa208sha256_passwd_minÚ-crypto_pwhash_scryptsalsa208sha256_passwd_maxÚ,crypto_pwhash_scryptsalsa208sha256_bytes_minÚ,crypto_pwhash_scryptsalsa208sha256_bytes_maxÚ/crypto_pwhash_scryptsalsa208sha256_memlimit_minÚ/crypto_pwhash_scryptsalsa208sha256_memlimit_maxÚ/crypto_pwhash_scryptsalsa208sha256_opslimit_minÚ/crypto_pwhash_scryptsalsa208sha256_opslimit_maxÚ7crypto_pwhash_scryptsalsa208sha256_opslimit_interactiveÚ7crypto_pwhash_scryptsalsa208sha256_memlimit_interactiveÚ5crypto_pwhash_scryptsalsa208sha256_opslimit_sensitiveÚ5crypto_pwhash_scryptsalsa208sha256_memlimit_sensitiveÚcrypto_pwhash_alg_argon2i13r   rT   Ú__annotations__Úcrypto_pwhash_alg_argon2id13r	   Úcrypto_pwhash_alg_defaultr
   Úcrypto_pwhash_saltbytesr   Úcrypto_pwhash_strbytesr   Úcrypto_pwhash_passwd_minr   Úcrypto_pwhash_passwd_maxr   Úcrypto_pwhash_bytes_minr   Úcrypto_pwhash_bytes_maxr   Úcrypto_pwhash_argon2i_strprefixr   rV   Ú"crypto_pwhash_argon2i_memlimit_minr   Ú"crypto_pwhash_argon2i_memlimit_maxr   Ú"crypto_pwhash_argon2i_opslimit_minr   Ú"crypto_pwhash_argon2i_opslimit_maxr   Ú*crypto_pwhash_argon2i_opslimit_interactiver   Ú*crypto_pwhash_argon2i_memlimit_interactiver   Ú'crypto_pwhash_argon2i_opslimit_moderater   Ú'crypto_pwhash_argon2i_memlimit_moderater   Ú(crypto_pwhash_argon2i_opslimit_sensitiver   Ú(crypto_pwhash_argon2i_memlimit_sensitiver   Ú crypto_pwhash_argon2id_strprefixr   Ú#crypto_pwhash_argon2id_memlimit_minr   Ú#crypto_pwhash_argon2id_memlimit_maxr   Ú#crypto_pwhash_argon2id_opslimit_minr   Ú#crypto_pwhash_argon2id_opslimit_maxr    Ú+crypto_pwhash_argon2id_opslimit_interactiver!   Ú+crypto_pwhash_argon2id_memlimit_interactiver"   Ú(crypto_pwhash_argon2id_opslimit_moderater#   Ú(crypto_pwhash_argon2id_memlimit_moderater$   Ú)crypto_pwhash_argon2id_opslimit_sensitiver%   Ú)crypto_pwhash_argon2id_memlimit_sensitiver&   ÚSCRYPT_OPSLIMIT_INTERACTIVEÚSCRYPT_MEMLIMIT_INTERACTIVEÚSCRYPT_OPSLIMIT_SENSITIVEÚSCRYPT_MEMLIMIT_SENSITIVEÚSCRYPT_SALTBYTESr`   r8   ÚLOG2_UINT64_MAXr:   ÚSCRYPT_MAX_MEMrB   rJ   rX   ra   re   ri   rm   rn   rp   Ú crypto_pwhash_argon2i_str_verifyr@   r@   r@   rA   Ú<module>   s®  
ÿÿþÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿþ
ÿ
ÿ
ÿ
ÿ
ÿ
ÿ
ÿ
ÿ
ÿ
ÿÿþ
ÿ
ÿ
ÿ
ÿ
ÿ
ÿ
ÿ
ÿ
ÿ
ÿÿÿÿÿÿÿÿÿÿ
þ*ÿÿ
þ&ùÿþýüûúù
ø>ýÿþý
ü,ÿÿ
þ!9ÿþýüûú
ùGÿþýü
û+