U
    O¼|eh%  ã                   @   s>  d Z ddlZddlZddlZddlZddlZddlZddlmZ ddl	m
Z
mZ ddlmZ ddlmZ ddlmZ ddlmZ ed	ƒZd
ZG dd„ deƒZG dd„ deƒZdd„ Zdd„ Zdd„ Zdd„ Zd+dd„Zdd„ Zd,dd„ZG dd „ d ƒZ dd!e d"fd#d$„Z!dd!e ddfd%d&„Z"G d'd(„ d(ƒZ#G d)d*„ d*e#ƒZ$dS )-a_  
Functions for creating and restoring url-safe signed JSON objects.

The format used looks like this:

>>> signing.dumps("hello")
'ImhlbGxvIg:1QaUZC:YIye-ze3TTx7gtSv422nZA4sgmk'

There are two components here, separated by a ':'. The first component is a
URLsafe base64 encoded JSON of the object passed to dumps(). The second
component is a base64 encoded hmac/SHA-256 hash of "$first_component:$secret"

signing.loads(s) checks the signature and returns the deserialized object.
If the signature fails, a BadSignature exception is raised.

>>> signing.loads("ImhlbGxvIg:1QaUZC:YIye-ze3TTx7gtSv422nZA4sgmk")
'hello'
>>> signing.loads("ImhlbGxvIg:1QaUZC:YIye-ze3TTx7gtSv42-modified")
...
BadSignature: Signature "ImhlbGxvIg:1QaUZC:YIye-ze3TTx7gtSv42-modified" does not match

You can optionally compress the JSON prior to base64 encoding it to save
space, using the compress=True argument. This checks if compression actually
helps and only applies compression if the result is a shorter string:

>>> signing.dumps(list(range(1, 20)), compress=True)
'.eJwFwcERACAIwLCF-rCiILN47r-GyZVJsNgkxaFxoDgxcOHGxMKD_T7vhAml:1QaUaL:BA0thEZrp4FQVXIXuOvYJtLJSrQ'

The fact that the string is compressed is signalled by the prefixed '.' at the
start of the base64 JSON.

There are 65 url-safe characters: the 64 used by url-safe base64 and the ':'.
These functions make use of all of them.
é    N)Úsettings)Úconstant_time_compareÚsalted_hmac)ÚRemovedInDjango51Warning©Úforce_bytes)Úimport_string)Ú_lazy_re_compilez^[A-z0-9-_=]*$Z>0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyzc                   @   s   e Zd ZdZdS )ÚBadSignaturezSignature does not match.N©Ú__name__Ú
__module__Ú__qualname__Ú__doc__© r   r   úP/var/www/website-v5/atlas_env/lib/python3.8/site-packages/django/core/signing.pyr
   6   s   r
   c                   @   s   e Zd ZdZdS )ÚSignatureExpiredz3Signature timestamp is older than required max_age.Nr   r   r   r   r   r   <   s   r   c                 C   sT   | dkrdS | dk rdnd}t | ƒ} d}| dkrLt| dƒ\} }t| | }q(|| S )Nr   Ú0ú-Ú é>   )ÚabsÚdivmodÚBASE62_ALPHABET)ÚsÚsignÚencodedÚ	remainderr   r   r   Ú
b62_encodeB   s    r   c                 C   sT   | dkrdS d}| d dkr,| dd … } d}d}| D ]}|d t  |¡ }q4|| S )Nr   r   é   r   éÿÿÿÿr   )r   Úindex)r   r   ÚdecodedZdigitr   r   r   Ú
b62_decodeN   s    r#   c                 C   s   t  | ¡ d¡S )Nó   =)Úbase64Úurlsafe_b64encodeÚstrip)r   r   r   r   Ú
b64_encode[   s    r(   c                 C   s    dt | ƒ d  }t | | ¡S )Nr$   é   )Úlenr%   Úurlsafe_b64decode)r   Úpadr   r   r   Ú
b64_decode_   s    r-   Úsha1c                 C   s   t t| |||d� ¡ ƒ ¡ S )N©Ú	algorithm)r(   r   ÚdigestÚdecode)ÚsaltÚvalueÚkeyr0   r   r   r   Úbase64_hmacd   s    ÿr6   c                 C   s   dt | ƒ S )Ns   django.http.cookiesr   )r5   r   r   r   Ú_cookie_signer_keyj   s    r7   ú%django.core.signing.get_cookie_signerc                 C   s&   t tjƒ}|ttjƒtttjƒ| d�S )N)r5   Úfallback_keysr3   )r   r   ÚSIGNING_BACKENDr7   Ú
SECRET_KEYÚmapÚSECRET_KEY_FALLBACKS)r3   ÚSignerr   r   r   Úget_cookie_signero   s    

ýr?   c                   @   s    e Zd ZdZdd„ Zdd„ ZdS )ÚJSONSerializerzW
    Simple wrapper around json to be used in signing.dumps and
    signing.loads.
    c                 C   s   t j|dd� d¡S )N)ú,ú:)Z
separatorsúlatin-1)ÚjsonÚdumpsÚencode)ÚselfÚobjr   r   r   rE   ~   s    zJSONSerializer.dumpsc                 C   s   t  | d¡¡S )NrC   )rD   Úloadsr2   )rG   Údatar   r   r   rI   �   s    zJSONSerializer.loadsN)r   r   r   r   rE   rI   r   r   r   r   r@   x   s   r@   zdjango.core.signingFc                 C   s   t ||d�j| ||d�S )a½  
    Return URL-safe, hmac signed base64 compressed JSON string. If key is
    None, use settings.SECRET_KEY instead. The hmac algorithm is the default
    Signer algorithm.

    If compress is True (not the default), check if compressing using zlib can
    save some space. Prepend a '.' to signify compression. This is included
    in the signature, to protect against zip bombs.

    Salt can be used to namespace the hash, so that a signed string is
    only valid for a given namespace. Leaving this at the default
    value or re-using a salt value across different parts of your
    application without good cause is a security risk.

    The serializer is expected to return a bytestring.
    )r5   r3   )Ú
serializerÚcompress)ÚTimestampSignerÚsign_object)rH   r5   r3   rK   rL   r   r   r   rE   …   s
      ÿrE   c                 C   s   t |||d�j| ||d�S )z|
    Reverse of dumps(), raise BadSignature if signature fails.

    The serializer is expected to accept a bytestring.
    )r5   r3   r9   )rK   Úmax_age)rM   Úunsign_object)r   r5   r3   rK   rO   r9   r   r   r   rI   �   s      ÿûrI   c                   @   sV   e Zd Zddddddœdd„Zddd„Zdd	„ Zd
d„ Zedfdd„Zefdd„Z	dS )r>   NrB   )r5   Úsepr3   r0   r9   c          	      G   s¼   |pt j| _|d k	r|nt j| _|| _|p<d| jj| jjf | _	|pFd| _
|r tjd| jj› d�tdd� t|ddd	d
dgƒD ] \}}|s’|dkr~t| ||ƒ q~t | j¡r¸td| ƒ‚d S )Nz%s.%sZsha256z Passing positional arguments to z is deprecated.é   )Ú
stacklevelr5   rQ   r3   r0   r9   zJUnsafe Signer separator: %r (cannot be empty or consist of only A-z0-9-_=))r   r;   r5   r=   r9   rQ   Ú	__class__r   r   r3   r0   ÚwarningsÚwarnr   ÚzipÚsetattrÚ_SEP_UNSAFEÚmatchÚ
ValueError)	rG   r5   rQ   r3   r0   r9   ÚargsÚargÚattrr   r   r   Ú__init__¸   s:    	ÿýþ
ü ÿÿÿzSigner.__init__c                 C   s"   |p| j }t| jd ||| jd�S )NZsignerr/   )r5   r6   r3   r0   )rG   r4   r5   r   r   r   Ú	signatureà   s    
zSigner.signaturec                 C   s   d|| j |  |¡f S ©Nz%s%s%s)rQ   r`   ©rG   r4   r   r   r   r   ä   s    zSigner.signc                 C   sh   | j |krtd| j  ƒ‚| | j d¡\}}| jf| j•D ]}t||  ||¡ƒr8|  S q8td| ƒ‚d S )NzNo "%s" found in valuer   zSignature "%s" does not match)rQ   r
   Úrsplitr5   r9   r   r`   )rG   Zsigned_valuer4   Úsigr5   r   r   r   Úunsignç   s    

zSigner.unsignFc                 C   s\   |ƒ   |¡}d}|r:t |¡}t|ƒt|ƒd k r:|}d}t|ƒ ¡ }|rRd| }|  |¡S )ae  
        Return URL-safe, hmac signed base64 compressed JSON string.

        If compress is True (not the default), check if compressing using zlib
        can save some space. Prepend a '.' to signify compression. This is
        included in the signature, to protect against zip bombs.

        The serializer is expected to return a bytestring.
        Fr   TÚ.)rE   ÚzlibrL   r*   r(   r2   r   )rG   rH   rK   rL   rJ   Zis_compressedZ
compressedÚbase64dr   r   r   rN   ð   s    

zSigner.sign_objectc                 K   sT   | j |f|Ž ¡ }|d d… dk}|r2|dd … }t|ƒ}|rHt |¡}|ƒ  |¡S )Nr   ó   .)re   rF   r-   rg   Ú
decompressrI   )rG   Z
signed_objrK   Úkwargsrh   rj   rJ   r   r   r   rP   	  s    
zSigner.unsign_object)N)
r   r   r   r_   r`   r   re   r@   rN   rP   r   r   r   r   r>   ³   s   ù(
	r>   c                       s2   e Zd Zdd„ Z‡ fdd„Zd‡ fdd„	Z‡  ZS )	rM   c                 C   s   t tt ¡ ƒƒS )N)r   ÚintÚtime)rG   r   r   r   Ú	timestamp  s    zTimestampSigner.timestampc                    s    d|| j |  ¡ f }tƒ  |¡S ra   )rQ   rn   Úsuperr   rb   ©rT   r   r   r     s    zTimestampSigner.signNc                    sj   t ƒ  |¡}| | jd¡\}}t|ƒ}|dk	rft|tjƒrB| ¡ }t	 	¡ | }||krft
d||f ƒ‚|S )zk
        Retrieve original value and check it wasn't signed more
        than max_age seconds ago.
        r   NzSignature age %s > %s seconds)ro   re   rc   rQ   r#   Ú
isinstanceÚdatetimeÚ	timedeltaÚtotal_secondsrm   r   )rG   r4   rO   Úresultrn   Zagerp   r   r   re     s    zTimestampSigner.unsign)N)r   r   r   rn   r   re   Ú__classcell__r   r   rp   r   rM     s   rM   )r.   )r8   )%r   r%   rr   rD   rm   rU   rg   Údjango.confr   Zdjango.utils.cryptor   r   Údjango.utils.deprecationr   Údjango.utils.encodingr   Údjango.utils.module_loadingr   Údjango.utils.regex_helperr	   rY   r   Ú	Exceptionr
   r   r   r#   r(   r-   r6   r7   r?   r@   rE   rI   r>   rM   r   r   r   r   Ú<module>   sJ   #

	   ÿ
ú
d