o
    "h;                     @  s  U d dl mZ d dlZd dlZd dlZd dlZd dlmZmZ d dl	m
Z
 d dlmZ d dlmZ d dlmZmZ dd	lmZmZmZmZmZ dd
lmZmZ ddlmZmZmZmZmZm Z  ej!dkrkd dlm"Z" nd dl#m"Z" ej!dkrd dlm$Z$m%Z% nd dl#m$Z$m%Z% ej!dkrd dlm&Z& nd dl#m&Z& edZ'e$dZ(e)e)e*e*f df Z+de,d< e)e+df Z-de,d< G dd deZ.e
ddG dd deZ/e
ddG dd dee/ Z0G d d! d!eZ1dS )"    )annotationsN)CallableMapping)	dataclass)wraps)
SSLContext)AnyTypeVar   )BrokenResourceErrorEndOfStreamaclose_forcefullyget_cancelled_exc_class	to_thread)TypedAttributeSettyped_attribute)AnyByteStreamAnyByteStreamConnectable
ByteStreamByteStreamConnectableListener	TaskGroup)   
   )	TypeAlias)r      )TypeVarTupleUnpack)r      )overrideT_RetvalPosArgsT.r   _PCTRTT_PCTRTTTc                   @  s   e Zd ZU dZe Zded< e Zded< e Zded< e Z	ded	< e Z
d
ed< e Zded< e Zded< e Zded< e Zded< e Zded< dS )TLSAttributez5Contains Transport Layer Security related attributes.
str | Nonealpn_protocolbyteschannel_binding_tls_uniqueztuple[str, str, int]cipherz*None | dict[str, str | _PCTRTTT | _PCTRTT]peer_certificatezbytes | Nonepeer_certificate_binaryboolserver_sidez!list[tuple[str, str, int]] | Noneshared_ciphersssl.SSLObject
ssl_objectstandard_compatiblestrtls_versionN)__name__
__module____qualname____doc__r   r&   __annotations__r(   r)   r*   r+   r-   r.   r0   r1   r3    r9   r9   D/var/www/html/venv/lib/python3.10/site-packages/anyio/streams/tls.pyr$   3   s   
 r$   F)eqc                   @  s   e Zd ZU dZded< ded< ded< ded	< ded
< edddddd2ddZd3ddZd4dd Zd5d"d#Z	d6d7d(d)Z
d8d+d,Zd5d-d.Zed9d0d1ZdS ):	TLSStreama  
    A stream wrapper that encrypts all sent data and decrypts received data.

    This class has no public initializer; use :meth:`wrap` instead.
    All extra attributes from :class:`~TLSAttribute` are supported.

    :var AnyByteStream transport_stream: the wrapped stream

    r   transport_streamr,   r1   r/   _ssl_objectzssl.MemoryBIO	_read_bio
_write_bioNT)r-   hostnamessl_contextr1   r-   bool | NonerA   r%   rB   ssl.SSLContext | Nonereturnc                  s   |du r| }|s'|rt jjnt jj}t |}tt dr'| jt j M  _t  }t  }t	|t j
u r@|j||||d}	nt|j||||dI dH }	| |||	||d}
|
|	jI dH  |
S )a  
        Wrap an existing stream with Transport Layer Security.

        This performs a TLS handshake with the peer.

        :param transport_stream: a bytes-transporting stream to wrap
        :param server_side: ``True`` if this is the server side of the connection,
            ``False`` if this is the client side (if omitted, will be set to ``False``
            if ``hostname`` has been provided, ``False`` otherwise). Used only to create
            a default context when an explicit context has not been provided.
        :param hostname: host name of the peer (if host name checking is desired)
        :param ssl_context: the SSLContext object to use (if not provided, a secure
            default will be created)
        :param standard_compatible: if ``False``, skip the closing handshake when
            closing the connection, and don't raise an exception if the peer does the
            same
        :raises ~ssl.SSLError: if the TLS handshake fails

        NOP_IGNORE_UNEXPECTED_EOF)r-   server_hostname)r=   r1   r>   r?   r@   )sslPurposeCLIENT_AUTHSERVER_AUTHcreate_default_contexthasattroptionsrF   	MemoryBIOtyper   wrap_bior   run_sync_call_sslobject_methoddo_handshake)clsr=   r-   rA   rB   r1   purposebio_inbio_outr0   wrapperr9   r9   r:   wrapa   s@   


	zTLSStream.wrapfunc&Callable[[Unpack[PosArgsT]], T_Retval]argsUnpack[PosArgsT]r    c                   s  	 z|| }W n t jyY   z| jjr!| j| j I d H  | j I d H }W n& ty8   | j	
  Y n tyP } z| j	
  | j
  t|d }~ww | j	| Y no t jyn   | j| j I d H  Y nZ t jy } z| j	
  | j
  t|d }~w t jy } z"| j	
  | j
  t|t js|jrd|jv r| jrt|td  d }~ww | jjr| j| j I d H  |S q)NTUNEXPECTED_EOF_WHILE_READING)rH   SSLWantReadErrorr@   pendingr=   sendreadreceiver   r?   	write_eofOSErrorr   writeSSLWantWriteErrorSSLSyscallErrorSSLError
isinstanceSSLEOFErrorstrerrorr1   )selfr[   r]   resultdataexcr9   r9   r:   rS      sV   






z TLSStream._call_sslobject_methodtuple[AnyByteStream, bytes]c                   s:   |  | jjI dH  | j  | j  | j| j fS )z
        Does the TLS closing handshake.

        :return: a tuple of (wrapped byte stream, bytes left in the read buffer)

        N)rS   r>   unwrapr?   re   r@   r=   rc   rn   r9   r9   r:   rs      s
   

zTLSStream.unwrapNonec                   sP   | j rz	|  I d H  W n ty   t| jI d H   w | j I d H  d S N)r1   rs   BaseExceptionr   r=   aclosert   r9   r9   r:   rx      s   zTLSStream.aclose   	max_bytesintr'   c                   s$   |  | jj|I d H }|st|S rv   )rS   r>   rc   r   )rn   rz   rp   r9   r9   r:   rd      s
   zTLSStream.receiveitemc                   s   |  | jj|I d H  d S rv   )rS   r>   rg   )rn   r|   r9   r9   r:   rb      s   zTLSStream.sendc                   sb   |  tj}td|}|r-t|dt|dpd}}||fdk r-td| td)NzTLSv(\d+)(?:\.(\d+))?   r
   r   )r}   r   z;send_eof() requires at least TLSv1.3; current session uses z7send_eof() has not yet been implemented for TLS streams)extrar$   r3   rematchr{   groupNotImplementedError)rn   r3   r   majorminorr9   r9   r:   send_eof   s   "zTLSStream.send_eofMapping[Any, Callable[[], Any]]c                   s   i  j jtj jjtj jjtj jjtj	 fddtj
 fddtj fddtj fddtj fddtj fddtj jji
S )Nc                         j dS )NFr>   getpeercertr9   rt   r9   r:   <lambda>  s    z,TLSStream.extra_attributes.<locals>.<lambda>c                     r   )NTr   r9   rt   r9   r:   r     s    c                     s    j jS rv   )r>   r-   r9   rt   r9   r:   r     s    c                     s    j jr	 j  S d S rv   )r>   r-   r.   r9   rt   r9   r:   r     s   c                         j S rv   r1   r9   rt   r9   r:   r         c                     r   rv   )r>   r9   rt   r9   r:   r     r   )r=   extra_attributesr$   r&   r>   selected_alpn_protocolr(   get_channel_bindingr)   r*   r+   r-   r.   r1   r0   r3   versionrt   r9   rt   r:   r     s   


zTLSStream.extra_attributes)r=   r   r-   rC   rA   r%   rB   rD   r1   r,   rE   r<   )r[   r\   r]   r^   rE   r    )rE   rr   rE   ru   )ry   )rz   r{   rE   r'   )r|   r'   rE   ru   rE   r   )r4   r5   r6   r7   r8   classmethodrZ   rS   rs   rx   rd   rb   r   propertyr   r9   r9   r9   r:   r<   O   s*   
 

F
.



r<   c                   @  sn   e Zd ZU dZded< ded< dZded< d	Zd
ed< ed ddZ	d!d"ddZ	d#ddZ
ed$ddZdS )%TLSListenera  
    A convenience listener that wraps another listener and auto-negotiates a TLS session
    on every accepted connection.

    If the TLS handshake times out or raises an exception,
    :meth:`handle_handshake_error` is called to do whatever post-mortem processing is
    deemed necessary.

    Supports only the :attr:`~TLSAttribute.standard_compatible` extra attribute.

    :param Listener listener: the listener to wrap
    :param ssl_context: the SSL context object
    :param standard_compatible: a flag passed through to :meth:`TLSStream.wrap`
    :param handshake_timeout: time limit for the TLS handshake
        (passed to :func:`~anyio.fail_after`)
    zListener[Any]listenerzssl.SSLContextrB   Tr,   r1      floathandshake_timeoutrq   rw   streamr   rE   ru   c                   sL   t |I dH  t| t sttjd| d t| tr#t| t r$ dS )a  
        Handle an exception raised during the TLS handshake.

        This method does 3 things:

        #. Forcefully closes the original stream
        #. Logs the exception (unless it was a cancellation exception) using the
           ``anyio.streams.tls`` logger
        #. Reraises the exception if it was a base exception or a cancellation exception

        :param exc: the exception
        :param stream: the original stream

        NzError during TLS handshake)exc_info)r   rk   r   logging	getLoggerr4   	exception	Exception)rq   r   r9   r9   r:   handle_handshake_error4  s   
z"TLSListener.handle_handshake_errorNhandlerCallable[[TLSStream], Any]
task_groupTaskGroup | Nonec                   s2   t  d fdd}j||I d H  d S )Nr   r   rE   ru   c              
     s   ddl m} z$|j tj| jjdI d H }W d    n1 s%w   Y  W n tyG } z|| I d H  W Y d }~d S d }~ww  |I d H  d S )Nr
   )
fail_after)rB   r1   )	 r   r   r<   rZ   rB   r1   rw   r   )r   r   wrapped_streamrq   r   rn   r9   r:   handler_wrapperY  s     z*TLSListener.serve.<locals>.handler_wrapper)r   r   rE   ru   )r   r   serve)rn   r   r   r   r9   r   r:   r   T  s   zTLSListener.servec                   s   | j  I d H  d S rv   )r   rx   rt   r9   r9   r:   rx   k  s   zTLSListener.acloser   c                   s   t j fddiS )Nc                     r   rv   r   r9   rt   r9   r:   r   q  r   z.TLSListener.extra_attributes.<locals>.<lambda>)r$   r1   rt   r9   rt   r:   r   n  s   zTLSListener.extra_attributes)rq   rw   r   r   rE   ru   rv   )r   r   r   r   rE   ru   r   r   )r4   r5   r6   r7   r8   r1   r   staticmethodr   r   rx   r   r   r9   r9   r9   r:   r     s   
 "
r   c                   @  s2   e Zd ZdZdddddddZedddZdS )TLSConnectablea  
    Wraps another connectable and does TLS negotiation after a successful connection.

    :param connectable: the connectable to wrap
    :param hostname: host name of the server (if host name checking is desired)
    :param ssl_context: the SSLContext object to use (if not provided, a secure default
        will be created)
    :param standard_compatible: if ``False``, skip the closing handshake when closing
        the connection, and don't raise an exception if the server does the same
    NTrA   rB   r1   connectabler   rA   r%   rB   rD   r1   r,   rE   ru   c                C  sN   || _ |pttjj| _t| jtjstdt	| jj
 || _|| _d S )Nz7ssl_context must be an instance of ssl.SSLContext, not )r   rH   rL   rI   rK   rB   rk   r   	TypeErrorrP   r4   rA   r1   )rn   r   rA   rB   r1   r9   r9   r:   __init__  s   

zTLSConnectable.__init__r<   c                   sR   | j  I d H }ztj|| j| j| jdI d H W S  ty(   t|I d H   w )Nr   )	r   connectr<   rZ   rA   rB   r1   rw   r   )rn   r   r9   r9   r:   r     s   zTLSConnectable.connect)
r   r   rA   r%   rB   rD   r1   r,   rE   ru   )rE   r<   )r4   r5   r6   r7   r   r   r   r9   r9   r9   r:   r   u  s    r   )2
__future__r   r   r   rH   syscollections.abcr   r   dataclassesr   	functoolsr   r   typingr   r	   r   r   r   r   r   r   _core._typedattrr   r   abcr   r   r   r   r   r   version_infor   typing_extensionsr   r   r   r    r!   tupler2   r"   r8   r#   r$   r<   r   r   r9   r9   r9   r:   <module>   sB     
	

 MX