a
    ÛEb(   ã                   @   s   d Z ddlZddlZddlZddlZddlZddlmZ ddlm	Z	m
Z
 ddlmZ ddlmZ ddlmZ edƒZd	ZG d
d„ deƒZG dd„ deƒZdd„ Zdd„ Zdd„ Zdd„ Zd(dd„Zd)dd„ZG dd„ dƒZddedfd d!„Zddedfd"d#„ZG d$d%„ d%ƒZG d&d'„ d'eƒZ dS )*ae  
Functions for creating and restoring url-safe signed JSON objects.

The format used looks like this:

>>> signing.dumps("hello")
'ImhlbGxvIg:1QaUZC:YIye-ze3TTx7gtSv422nZA4sgmk'

There are two components here, separated by a ':'. The first component is a
URLsafe base64 encoded JSON of the object passed to dumps(). The second
component is a base64 encoded hmac/SHA1 hash of "$first_component:$secret"

signing.loads(s) checks the signature and returns the deserialized object.
If the signature fails, a BadSignature exception is raised.

>>> signing.loads("ImhlbGxvIg:1QaUZC:YIye-ze3TTx7gtSv422nZA4sgmk")
'hello'
>>> signing.loads("ImhlbGxvIg:1QaUZC:YIye-ze3TTx7gtSv422nZA4sgmk-modified")
...
BadSignature: Signature failed: ImhlbGxvIg:1QaUZC:YIye-ze3TTx7gtSv422nZA4sgmk-modified

You can optionally compress the JSON prior to base64 encoding it to save
space, using the compress=True argument. This checks if compression actually
helps and only applies compression if the result is a shorter string:

>>> signing.dumps(list(range(1, 20)), compress=True)
'.eJwFwcERACAIwLCF-rCiILN47r-GyZVJsNgkxaFxoDgxcOHGxMKD_T7vhAml:1QaUaL:BA0thEZrp4FQVXIXuOvYJtLJSrQ'

The fact that the string is compressed is signalled by the prefixed '.' at the
start of the base64 JSON.

There are 65 url-safe characters: the 64 used by url-safe base64 and the ':'.
These functions make use of all of them.
é    N)Úsettings)Úconstant_time_compareÚsalted_hmac)Úforce_bytes)Úimport_string)Ú_lazy_re_compilez^[A-z0-9-_=]*$Z>0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyzc                   @   s   e Zd ZdZdS )ÚBadSignaturezSignature does not match.N©Ú__name__Ú
__module__Ú__qualname__Ú__doc__© r   r   úS/home/ja/django-apps/lartica_env/lib/python3.9/site-packages/django/core/signing.pyr   4   s   r   c                   @   s   e Zd ZdZdS )ÚSignatureExpiredz3Signature timestamp is older than required max_age.Nr	   r   r   r   r   r   :   s   r   c                 C   sT   | dkrdS | dk rdnd}t | ƒ} d}| dkrLt| dƒ\} }t| | }q(|| S )Nr   Ú0ú-Ú é>   )ÚabsÚdivmodÚBASE62_ALPHABET)ÚsÚsignÚencodedÚ	remainderr   r   r   Ú
b62_encode@   s    r   c                 C   sT   | dkrdS d}| d dkr,| dd … } d}d}| D ]}|d t  |¡ }q4|| S )Nr   r   é   r   éÿÿÿÿr   )r   Úindex)r   r   ÚdecodedÚdigitr   r   r   Ú
b62_decodeL   s    r"   c                 C   s   t  | ¡ d¡S )Nó   =)Úbase64Úurlsafe_b64encodeÚstrip)r   r   r   r   Ú
b64_encodeY   s    r'   c                 C   s    dt | ƒ d  }t | | ¡S )Nr#   é   )Úlenr$   Úurlsafe_b64decode)r   Úpadr   r   r   Ú
b64_decode]   s    r,   Úsha1c                 C   s   t t| |||d� ¡ ƒ ¡ S )N©Ú	algorithm)r'   r   ÚdigestÚdecode)ÚsaltÚvalueÚkeyr/   r   r   r   Úbase64_hmacb   s    ÿr5   ú%django.core.signing.get_cookie_signerc                 C   s$   t tjƒ}ttjƒ}|d| | d�S )Ns   django.http.cookies©r2   )r   r   ZSIGNING_BACKENDr   Ú
SECRET_KEY)r2   ÚSignerr4   r   r   r   Úget_cookie_signerh   s    

r:   c                   @   s    e Zd ZdZdd„ Zdd„ ZdS )ÚJSONSerializerzW
    Simple wrapper around json to be used in signing.dumps and
    signing.loads.
    c                 C   s   t j|dd� d¡S )N)ú,ú:)Ú
separatorsúlatin-1)ÚjsonÚdumpsÚencode)ÚselfÚobjr   r   r   rA   t   s    zJSONSerializer.dumpsc                 C   s   t  | d¡¡S )Nr?   )r@   Úloadsr1   )rC   Údatar   r   r   rE   w   s    zJSONSerializer.loadsN)r
   r   r   r   rA   rE   r   r   r   r   r;   n   s   r;   zdjango.core.signingFc                 C   s   t ||d�j| ||d�S )a½  
    Return URL-safe, hmac signed base64 compressed JSON string. If key is
    None, use settings.SECRET_KEY instead. The hmac algorithm is the default
    Signer algorithm.

    If compress is True (not the default), check if compressing using zlib can
    save some space. Prepend a '.' to signify compression. This is included
    in the signature, to protect against zip bombs.

    Salt can be used to namespace the hash, so that a signed string is
    only valid for a given namespace. Leaving this at the default
    value or re-using a salt value across different parts of your
    application without good cause is a security risk.

    The serializer is expected to return a bytestring.
    r7   )Ú
serializerÚcompress)ÚTimestampSignerÚsign_object)rD   r4   r2   rG   rH   r   r   r   rA   {   s    ÿrA   c                 C   s   t ||d�j| ||d�S )z|
    Reverse of dumps(), raise BadSignature if signature fails.

    The serializer is expected to accept a bytestring.
    r7   )rG   Úmax_age)rI   Úunsign_object)r   r4   r2   rG   rK   r   r   r   rE   “   s    ÿrE   c                   @   sH   e Zd Zddd„Zdd„ Zdd„ Zd	d
„ Zedfdd„Zefdd„Z	dS )r9   Nr=   c                 C   sR   |pt j| _|| _t | j¡r*td| ƒ‚|p@d| jj| jj	f | _
|pJd| _d S )NzJUnsafe Signer separator: %r (cannot be empty or consist of only A-z0-9-_=)z%s.%sÚsha256)r   r8   r4   ÚsepÚ_SEP_UNSAFEÚmatchÚ
ValueErrorÚ	__class__r   r
   r2   r/   )rC   r4   rN   r2   r/   r   r   r   Ú__init__¡   s    ÿÿþzSigner.__init__c                 C   s   t | jd || j| jd�S )NZsignerr.   )r5   r2   r4   r/   ©rC   r3   r   r   r   Ú	signature¯   s    ÿzSigner.signaturec                 C   s   d|| j |  |¡f S ©Nz%s%s%s)rN   rU   rT   r   r   r   r   ´   s    zSigner.signc                 C   sN   | j |vrtd| j  ƒ‚| | j d¡\}}t||  |¡ƒr>|S td| ƒ‚d S )NzNo "%s" found in valuer   zSignature "%s" does not match)rN   r   Úrsplitr   rU   )rC   Zsigned_valuer3   Úsigr   r   r   Úunsign·   s    
zSigner.unsignFc                 C   s\   |ƒ   |¡}d}|r:t |¡}t|ƒt|ƒd k r:|}d}t|ƒ ¡ }|rRd| }|  |¡S )ae  
        Return URL-safe, hmac signed base64 compressed JSON string.

        If compress is True (not the default), check if compressing using zlib
        can save some space. Prepend a '.' to signify compression. This is
        included in the signature, to protect against zip bombs.

        The serializer is expected to return a bytestring.
        Fr   TÚ.)rA   ÚzlibrH   r)   r'   r1   r   )rC   rD   rG   rH   rF   Zis_compressedÚ
compressedÚbase64dr   r   r   rJ   ¿   s    

zSigner.sign_objectc                 K   sX   | j |fi |¤Ž ¡ }|d d… dk}|r6|dd … }t|ƒ}|rLt |¡}|ƒ  |¡S )Nr   ó   .)rY   rB   r,   r[   Ú
decompressrE   )rC   Z
signed_objrG   Úkwargsr]   r_   rF   r   r   r   rL   Ø   s    
zSigner.unsign_object)Nr=   NN)
r
   r   r   rS   rU   r   rY   r;   rJ   rL   r   r   r   r   r9       s   
r9   c                       s2   e Zd Zdd„ Z‡ fdd„Zd‡ fdd„	Z‡  ZS )	rI   c                 C   s   t tt ¡ ƒƒS )N)r   ÚintÚtime)rC   r   r   r   Ú	timestampç   s    zTimestampSigner.timestampc                    s    d|| j |  ¡ f }tƒ  |¡S rV   )rN   rc   Úsuperr   rT   ©rR   r   r   r   ê   s    zTimestampSigner.signNc                    sj   t ƒ  |¡}| | jd¡\}}t|ƒ}|durft|tjƒrB| ¡ }t	 	¡ | }||krft
d||f ƒ‚|S )zk
        Retrieve original value and check it wasn't signed more
        than max_age seconds ago.
        r   NzSignature age %s > %s seconds)rd   rY   rW   rN   r"   Ú
isinstanceÚdatetimeÚ	timedeltaÚtotal_secondsrb   r   )rC   r3   rK   Úresultrc   Zagere   r   r   rY   î   s    zTimestampSigner.unsign)N)r
   r   r   rc   r   rY   Ú__classcell__r   r   re   r   rI   æ   s   rI   )r-   )r6   )!r   r$   rg   r@   rb   r[   Zdjango.confr   Zdjango.utils.cryptor   r   Zdjango.utils.encodingr   Zdjango.utils.module_loadingr   Zdjango.utils.regex_helperr   rO   r   Ú	Exceptionr   r   r   r"   r'   r,   r5   r:   r;   rA   rE   r9   rI   r   r   r   r   Ú<module>   s6   #

ÿ
ÿ
F