§
    „ßj¯%  ã                  óð   — d dl mZ d dlmZ d dlZd dlZd dlZddl	m
Z
 ddl	mZ ddl	mZ ddl	mZ ddlmZ  G d	„ d
¦  «        Z G d„ de¦  «        Zddd„Z G d„ de¦  «        Zdd„Z G d„ d¦  «        ZdS )é    )ÚannotationsNé   )Ú_base64_alphabet)Úbase64_decode)Úbase64_encode©Ú
want_bytes)ÚBadSignaturec                  ó"   — e Zd ZdZdd„Zdd	„Zd
S )ÚSigningAlgorithmzgSubclasses must implement :meth:`get_signature` to provide
    signature generation functionality.
    ÚkeyÚbytesÚvalueÚreturnc                ó   — t          ¦   «         ‚)z2Returns the signature for the given key and value.)ÚNotImplementedError©Úselfr   r   s      úF/var/www/html/venv/lib/python3.11/site-packages/itsdangerous/signer.pyÚget_signaturezSigningAlgorithm.get_signature   s   € å!Ñ#Ô#Ð#ó    ÚsigÚboolc                óT   — t          j        ||                      ||¦  «        ¦  «        S )zMVerifies the given signature matches the expected
        signature.
        )ÚhmacÚcompare_digestr   )r   r   r   r   s       r   Úverify_signaturez!SigningAlgorithm.verify_signature   s'   € õ Ô" 3¨×(:Ò(:¸3ÀÑ(FÔ(FÑGÔGÐGr   N©r   r   r   r   r   r   )r   r   r   r   r   r   r   r   )Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r   © r   r   r   r      sL   € € € € € ðð ð$ð $ð $ð $ðHð Hð Hð Hð Hð Hr   r   c                  ó   — e Zd ZdZdd„ZdS )	ÚNoneAlgorithmz`Provides an algorithm that does not perform any signing and
    returns an empty signature.
    r   r   r   r   c                ó   — dS )Nr   r#   r   s      r   r   zNoneAlgorithm.get_signature$   s   € Øˆsr   Nr   )r   r    r!   r"   r   r#   r   r   r%   r%      s2   € € € € € ðð ðð ð ð ð ð r   r%   r   Ústringr   r   út.Anyc                ó*   — t          j        | ¦  «        S )zÈDon't access ``hashlib.sha1`` until runtime. FIPS builds may not include
    SHA-1, in which case the import and use as a default would fail before the
    developer can configure something else.
    )ÚhashlibÚsha1)r'   s    r   Ú
_lazy_sha1r,   (   s   € õ
 Œ<˜ÑÔÐr   c                  óF   — e Zd ZU dZ ee¦  «        Zded<   ddd„Zdd„Z	dS )ÚHMACAlgorithmz*Provides signature generation using HMACs.r(   Údefault_digest_methodNÚdigest_methodc                ó&   — |€| j         }|| _        d S ©N)r/   r0   )r   r0   s     r   Ú__init__zHMACAlgorithm.__init__8   s   € ØÐ Ø Ô6ˆMà$1ˆÔÐÐr   r   r   r   r   c                ób   — t          j        ||| j        ¬¦  «        }|                     ¦   «         S )N)ÚmsgÚ	digestmod)r   Únewr0   Údigest)r   r   r   Úmacs       r   r   zHMACAlgorithm.get_signature>   s)   € ÝŒh�s °Ô1CÐDÑDÔDˆØ�zŠz‰|Œ|Ðr   r2   )r0   r(   r   )
r   r    r!   r"   Ústaticmethodr,   r/   Ú__annotations__r3   r   r#   r   r   r.   r.   0   sg   € € € € € € Ø4Ð4ð
 $0 <°
Ñ#;Ô#;ÐÐ;Ð;Ð;Ñ;ð2ð 2ð 2ð 2ð 2ðð ð ð ð ð r   r.   Ú
secret_keyú7str | bytes | cabc.Iterable[str] | cabc.Iterable[bytes]úlist[bytes]c                ór   — t          | t          t          f¦  «        rt          | ¦  «        gS d„ | D ¦   «         S )Nc                ó,   — g | ]}t          |¦  «        ‘ŒS r#   r   )Ú.0Úss     r   ú
<listcomp>z#_make_keys_list.<locals>.<listcomp>I   s   € Ð.Ð.Ð.˜a�J�q‰MŒMÐ.Ð.Ð.r   )Ú
isinstanceÚstrr   r	   )r<   s    r   Ú_make_keys_listrF   C   s?   € õ �*�s¥E˜lÑ+Ô+ð (Ý˜:Ñ&Ô&Ð'Ð'à.Ð. :Ð.Ñ.Ô.Ð.r   c                  ó    — e Zd ZU dZ ee¦  «        Zded<   dZded<   	 	 	 	 	 d$d%d„Z	e
d&d„¦   «         Zd'd(d„Zd)d„Zd)d„Zd*d „Zd+d"„Zd,d#„Zd	S )-ÚSigneraÖ  A signer securely signs bytes, then unsigns them to verify that
    the value hasn't been changed.

    The secret key should be a random string of ``bytes`` and should not
    be saved to code or version control. Different salts should be used
    to distinguish signing in different contexts. See :doc:`/concepts`
    for information about the security of the secret key and salt.

    :param secret_key: The secret key to sign and verify with. Can be a
        list of keys, oldest to newest, to support key rotation.
    :param salt: Extra key to combine with ``secret_key`` to distinguish
        signatures in different contexts.
    :param sep: Separator between the signature and value.
    :param key_derivation: How to derive the signing key from the secret
        key and salt. Possible values are ``concat``, ``django-concat``,
        or ``hmac``. Defaults to :attr:`default_key_derivation`, which
        defaults to ``django-concat``.
    :param digest_method: Hash function to use when generating the HMAC
        signature. Defaults to :attr:`default_digest_method`, which
        defaults to :func:`hashlib.sha1`. Note that the security of the
        hash alone doesn't apply when used intermediately in HMAC.
    :param algorithm: A :class:`SigningAlgorithm` instance to use
        instead of building a default :class:`HMACAlgorithm` with the
        ``digest_method``.

    .. versionchanged:: 2.0
        Added support for key rotation by passing a list to
        ``secret_key``.

    .. versionchanged:: 0.18
        ``algorithm`` was added as an argument to the class constructor.

    .. versionchanged:: 0.14
        ``key_derivation`` and ``digest_method`` were added as arguments
        to the class constructor.
    r(   r/   údjango-concatrE   Údefault_key_derivationó   itsdangerous.Signeró   .Nr<   r=   Úsaltústr | bytes | NoneÚsepústr | bytesÚkey_derivationú
str | Noner0   út.Any | NoneÚ	algorithmúSigningAlgorithm | Nonec                ó@  — t          |¦  «        | _        t          |¦  «        | _        | j        t          v rt          d¦  «        ‚|�t          |¦  «        }nd}|| _        |€| j        }|| _        |€| j	        }|| _
        |€t          | j
        ¦  «        }|| _        d S )NzŠThe given separator cannot be used because it may be contained in the signature itself. ASCII letters, digits, and '-_=' must not be used.rK   )rF   Úsecret_keysr	   rO   r   Ú
ValueErrorrM   rJ   rQ   r/   r0   r.   rT   )r   r<   rM   rO   rQ   r0   rT   s          r   r3   zSigner.__init__�   s¶   € õ )8¸
Ñ(CÔ(CˆÔÝ$ S™/œ/ˆŒàŒ8Õ'Ð'Ð'Ýð7ñô ð ð ÐÝ˜dÑ#Ô#ˆDˆDà)ˆDàˆŒ	àÐ!Ø!Ô8ˆNà#1ˆÔàÐ Ø Ô6ˆMà$1ˆÔàÐÝ% dÔ&8Ñ9Ô9ˆIà+4ˆŒˆˆr   r   r   c                ó   — | j         d         S )z�The newest (last) entry in the :attr:`secret_keys` list. This
        is for compatibility from before key rotation support was added.
        éÿÿÿÿ)rW   )r   s    r   r<   zSigner.secret_key¯   s   € ð
 Ô Ô#Ð#r   c                ón  — |€| j         d         }nt          |¦  «        }| j        dk    rGt          j        t
          |                      | j        |z   ¦  «                             ¦   «         ¦  «        S | j        dk    rJt          j        t
          |                      | j        dz   |z   ¦  «                             ¦   «         ¦  «        S | j        dk    rIt          j
        || j        ¬¦  «        }|                     | j        ¦  «         |                     ¦   «         S | j        dk    r|S t          d	¦  «        ‚)
aü  This method is called to derive the key. The default key
        derivation choices can be overridden here. Key derivation is not
        intended to be used as a security method to make a complex key
        out of a short password. Instead you should use large random
        secret keys.

        :param secret_key: A specific secret key to derive from.
            Defaults to the last item in :attr:`secret_keys`.

        .. versionchanged:: 2.0
            Added the ``secret_key`` parameter.
        NrZ   ÚconcatrI   s   signerr   )r6   ÚnonezUnknown key derivation method)rW   r	   rQ   ÚtÚcastr   r0   rM   r8   r   r7   ÚupdateÚ	TypeError)r   r<   r9   s      r   Ú
derive_keyzSigner.derive_key¶   s   € ð ÐØÔ)¨"Ô-ˆJˆJå# JÑ/Ô/ˆJàÔ (Ò*Ð*Ý”6�% ×!3Ò!3°D´IÀ
Ñ4JÑ!KÔ!K×!RÒ!RÑ!TÔ!TÑUÔUÐUØÔ  OÒ3Ð3Ý”6Ý�t×)Ò)¨$¬)°iÑ*?À*Ñ*LÑMÔM×TÒTÑVÔVñô ð ð Ô  FÒ*Ð*Ý”(˜:°Ô1CÐDÑDÔDˆCØ�JŠJ�t”yÑ!Ô!Ð!Ø—:’:‘<”<ÐØÔ  FÒ*Ð*ØÐåÐ;Ñ<Ô<Ð<r   r   c                óœ   — t          |¦  «        }|                      ¦   «         }| j                             ||¦  «        }t	          |¦  «        S )z*Returns the signature for the given value.)r	   rb   rT   r   r   )r   r   r   r   s       r   r   zSigner.get_signature×   sC   € å˜5Ñ!Ô!ˆØ�oŠoÑÔˆØŒn×*Ò*¨3°Ñ6Ô6ˆÝ˜SÑ!Ô!Ð!r   c                ó`   — t          |¦  «        }|| j        z   |                      |¦  «        z   S )zSigns the given string.)r	   rO   r   )r   r   s     r   ÚsignzSigner.signÞ   s/   € å˜5Ñ!Ô!ˆØ�t”xÑ $×"4Ò"4°UÑ";Ô";Ñ;Ð;r   r   r   c                óþ   — 	 t          |¦  «        }n# t          $ r Y dS w xY wt          |¦  «        }t          | j        ¦  «        D ]6}|                      |¦  «        }| j                             |||¦  «        r dS Œ7dS )z+Verifies the signature for the given value.FT)r   Ú	Exceptionr	   ÚreversedrW   rb   rT   r   )r   r   r   r<   r   s        r   r   zSigner.verify_signatureã   s¡   € ð	Ý Ñ$Ô$ˆCˆCøÝð 	ð 	ð 	Ø�5�5ð	øøøõ ˜5Ñ!Ô!ˆå" 4Ô#3Ñ4Ô4ð 	ð 	ˆJØ—/’/ *Ñ-Ô-ˆCàŒ~×.Ò.¨s°E¸3Ñ?Ô?ð Ø�t�tðð ˆus   ‚ ’
 Ÿ Úsigned_valuec                óø   — t          |¦  «        }| j        |vrt          d| j        ›d�¦  «        ‚|                     | j        d¦  «        \  }}|                      ||¦  «        r|S t          d|›d�|¬¦  «        ‚)zUnsigns the given string.zNo z found in valuer   z
Signature z does not match)Úpayload)r	   rO   r
   Úrsplitr   )r   ri   r   r   s       r   ÚunsignzSigner.unsignô   s�   € å! ,Ñ/Ô/ˆàŒ8˜<Ð'Ð'ÝÐ@ T¤XÐ@Ð@Ð@ÑAÔAÐAà!×(Ò(¨¬°1Ñ5Ô5‰
ˆˆsà× Ò  ¨Ñ,Ô,ð 	ØˆLåÐ>¨Ð>Ð>Ð>ÈÐNÑNÔNÐNr   c                óT   — 	 |                       |¦  «         dS # t          $ r Y dS w xY w)znOnly validates the given signed value. Returns ``True`` if
        the signature exists and is valid.
        TF)rm   r
   )r   ri   s     r   ÚvalidatezSigner.validate  s@   € ð	Ø�KŠK˜Ñ%Ô%Ð%Ø�4øÝð 	ð 	ð 	Ø�5�5ð	øøøs   ‚ ™
'¦')rK   rL   NNN)r<   r=   rM   rN   rO   rP   rQ   rR   r0   rS   rT   rU   )r   r   r2   )r<   rN   r   r   )r   rP   r   r   )r   rP   r   rP   r   r   )ri   rP   r   r   )ri   rP   r   r   )r   r    r!   r"   r:   r,   r/   r;   rJ   r3   Úpropertyr<   rb   r   re   r   rm   ro   r#   r   r   rH   rH   L   s   € € € € € € ð#ð #ðV $0 <°
Ñ#;Ô#;ÐÐ;Ð;Ð;Ñ;ð #2ÐÐ1Ð1Ð1Ñ1ð
 $:ØØ%)Ø&*Ø-1ð,5ð ,5ð ,5ð ,5ð ,5ð\ ð$ð $ð $ñ „Xð$ð=ð =ð =ð =ð =ðB"ð "ð "ð "ð<ð <ð <ð <ð
ð ð ð ð"Oð Oð Oð Oðð ð ð ð ð r   rH   )r   )r'   r   r   r(   )r<   r=   r   r>   )Ú
__future__r   Úcollections.abcÚabcÚcabcr*   r   Útypingr^   Úencodingr   r   r   r	   Úexcr
   r   r%   r,   r.   rF   rH   r#   r   r   ú<module>rx      s�  ðØ "Ð "Ð "Ð "Ð "Ð "à Ð Ð Ð Ð Ð Ø €€€Ø €€€Ø Ð Ð Ð à &Ð &Ð &Ð &Ð &Ð &Ø #Ð #Ð #Ð #Ð #Ð #Ø #Ð #Ð #Ð #Ð #Ð #Ø  Ð  Ð  Ð  Ð  Ð  Ø Ð Ð Ð Ð Ð ðHð Hð Hð Hð Hñ Hô Hð Hð ð ð ð ð Ð$ñ ô ð ð ð  ð  ð  ð  ðð ð ð ð Ð$ñ ô ð ð&/ð /ð /ð /ð~ð ~ð ~ð ~ð ~ñ ~ô ~ð ~ð ~ð ~r   