+
    Dfj!                         R t ^ RIHt ^ RIHt ^ RIHt ^ RIHt ^ RI	H
t
 ^ RIHt ^ RIHtHt ]! ]4       ! R R	4      4       t]! ]4       ! R
 R4      4       tR# )a  
A guard implementation which supports HTTP header-based authentication
schemes.

If no I{Authorization} header is supplied, an anonymous login will be
attempted by using a L{Anonymous} credentials object.  If such a header is
supplied and does not contain allowed credentials, or if anonymous login is
denied, a 401 will be sent in the response along with I{WWW-Authenticate}
headers for each of the allowed authentication schemes.
)implementer)error)	Anonymous)Logger)proxyForInterface)util)	IResource_UnsafeErrorPagec                   @   a  ] tR t^t o RtRtR tR tR tR t	Rt
V tR# )	UnauthorizedResourcez.
Simple IResource to escape Resource dispatch
Tc                    Wn         R # N_credentialFactories)self	factoriess   &&;/usr/lib/python3/dist-packages/twisted/web/_auth/wrapper.py__init__UnauthorizedResource.__init__#   s    $-!    c                  aa R oVV3R lpR oVP                  R4       V P                   FA  pVP                  V4      pVP                  P	                  RV! VP
                  V4      4       KC  	  VP                  R8X  d   R# R# )	z-
Send www-authenticate headers to the client
c                 T    \        V \        4      '       d   V P                  R 4      # T # )ascii)
isinstancestrencodess   &r   ensureBytes0UnauthorizedResource.render.<locals>.ensureBytes+   s"    (21c(:(:188G$AAr   c                    < . pVP                  4        F:  w  r4S! V4      pS! V4      pVP                  VR ,           S! V4      ,           4       K<  	  RP                  V RP                  V4      .4      # )   =    s   , )itemsappendjoin)scheme	challengelstkvr   quoteStrings   &&   r   generateWWWAuthenticate<UnauthorizedResource.render.<locals>.generateWWWAuthenticate.   sd    C!)NN

1t8k!n45 * 99fejjo677r   c                 b    R V P                  RR4      P                  R R4      ,           R ,           # )   "   \s   \\s   \")replacer   s   &r   r+   0UnauthorizedResource.render.<locals>.quoteString6   s*    !))E62::4HH4OOr   i  s   www-authenticates   HEADr   s   Unauthorized)setResponseCoder   getChallengeresponseHeadersaddRawHeaderr&   method)r   requestr,   factr'   r   r+   s   &&   @@r   renderUnauthorizedResource.render&   s}    
	B	8	P 	$--D))'2I##00#%<T[[)%T .
 >>W$r   c                    V # )z
Disable resource dispatch
 r   pathr8   s   &&&r   getChildWithDefault(UnauthorizedResource.getChildWithDefaultC   s	     r   c                    \        4       hr   NotImplementedErrorr   r?   childs   &&&r   putChildUnauthorizedResource.putChildI       !##r   r   N)__name__
__module____qualname____firstlineno____doc__isLeafr   r:   r@   rG   __static_attributes____classdictcell____classdict__s   @r   r   r      s*      F.:$ $r   r   c                   l   a  ] tR t^Nt o RtRt]! 4       tR tR t	R t
R tR tR tR	 tR
 tR tRtV tR# )HTTPAuthSessionWrapperaE  
Wrap a portal, enforcing supported header-based authentication schemes.

@ivar _portal: The L{Portal} which will be used to retrieve L{IResource}
    avatars.

@ivar _credentialFactories: A list of L{ICredentialFactory} providers which
    will be used to decode I{Authorization} headers into L{ICredentials}
    providers.
Fc                    Wn         W n        R# )a#  
Initialize a session wrapper

@type portal: C{Portal}
@param portal: The portal that will authenticate the remote client

@type credentialFactories: C{Iterable}
@param credentialFactories: The portal that will authenticate the
    remote client based on one submitted C{ICredentialFactory}
N)_portalr   )r   portalcredentialFactoriess   &&&r   r   HTTPAuthSessionWrapper.__init__^   s     $7!r   c                   VP                  R4      pV'       g.   \        P                  ! V P                  \	        4       4      4      # V P                  V4      w  r4Vf   \        V P                  4      #  VP                  WA4      p\        P                  ! V P                  V4      4      #   \        P                   d    \        T P                  4      u # \         d,    T P                  P                  R4       \        RRR4      u # i ; i)z
Get the L{IResource} which the given request is authorized to receive.
If the proper authorization headers are present, the resource will be
requested from the portal.  If not, an anonymous login attempt will be
made.
s   authorizationz+Unexpected failure from credentials factory  Internal Error )	getHeaderr   DeferredResource_loginr   _selectParseHeaderr   r   decoder   LoginFailedBaseException_logfailurer	   )r   r8   
authheaderfactory
respStringcredentialss   &&    r   _authorizedResource*HTTPAuthSessionWrapper._authorizedResourcel   s     &&'78
((Y[)ABB"55jA?'(A(ABB	C!..=K (([)ABB    	C'(A(ABB 	?IIKL#C)92>>	?s   4B* **DD)D
Dc                B    V P                  V4      P                  V4      # )z
Find the L{IResource} avatar suitable for the given request, if
possible, and render it.  Otherwise, perhaps render an error page
requiring authorization or describing an internal server failure.
)rl   r:   )r   r8   s   &&r   r:   HTTPAuthSessionWrapper.render   s      ''077@@r   c                    VP                   P                  ^ VP                  P                  4       4       V P	                  V4      # )a,  
Inspect the Authorization HTTP header, and return a deferred which,
when fired after successful authentication, will return an authorized
C{Avatar}. On authentication failure, an C{UnauthorizedResource} will
be returned, essentially halting further dispatch on the wrapped
resource and all children
)postpathinsertprepathpoprl   r>   s   &&&r   r@   *HTTPAuthSessionWrapper.getChildWithDefault   s8     	7??#6#6#89''00r   c                    V P                   P                  VR\        4      pVP                  V P                  V P
                  4       V# )z
Get the L{IResource} avatar for the given credentials.

@return: A L{Deferred} which will be called back with an L{IResource}
    avatar or which will errback if authentication fails.
N)rW   loginr   addCallbacks_loginSucceeded_loginFailed)r   rk   ds   && r   ra   HTTPAuthSessionWrapper._login   s;     LL{D)<	t++T->->?r   c                Z   aa Vw  r#o ! VV3R lR\        \        R4      4      oS! V4      # )z
Handle login success by wrapping the resulting L{IResource} avatar
so that the C{logout} callback will be invoked when rendering is
complete.
c                   F   <a a ] tR t^t oRtV3R ltV V3R ltRtVtV ;t	# )?HTTPAuthSessionWrapper._loginSucceeded.<locals>.ResourceWrapperaZ  
Wrap an L{IResource} so that whenever it or a child of it
completes rendering, the cred logout hook will be invoked.

An assumption is made here that exactly one L{IResource} from
among C{avatar} and all of its children will be rendered.  If
more than one is rendered, C{logout} will be invoked multiple
times and probably earlier than desired.
c                F   < S! V P                   P                  W4      4      # )z
Pass through the lookup to the wrapped resource, wrapping
the result in L{ResourceWrapper} to ensure C{logout} is
called when rendering of the child is complete.
)resourcer@   )r   namer8   ResourceWrappers   &&&r   r@   SHTTPAuthSessionWrapper._loginSucceeded.<locals>.ResourceWrapper.getChildWithDefault   s     't}}'H'H'WXXr   c                h   < VP                  4       P                  V3R l4       \        SV `  V4      # )z|
Hook into response generation so that when rendering has
finished completely (with or without error), C{logout} is
called.
c                    < S! 4       # r   r=   )ignlogouts   &r   <lambda>XHTTPAuthSessionWrapper._loginSucceeded.<locals>.ResourceWrapper.render.<locals>.<lambda>   s    68r   )notifyFinishaddBothsuperr:   )r   r8   	__class__r   s   &&r   r:   FHTTPAuthSessionWrapper._loginSucceeded.<locals>.ResourceWrapper.render   s,     $$&../CDw~g..r   r=   )
rJ   rK   rL   rM   rN   r@   r:   rP   rQ   __classcell__)r   rS   r   r   s   @@r   r   r      s     Y/ /r   r   r   )r   r   )r   args	interfaceavatarr   r   s   &&  @@r   ry   &HTTPAuthSessionWrapper._loginSucceeded   s5     %)!	6	/ 	//	:F 	/8 v&&r   c                    VP                  \        P                  \        P                  4      '       d   \	        V P
                  4      # V P                  P                  RVR7       \        RRR4      # )z
Handle login failure by presenting either another challenge (for
expected authentication/authorization-related failures) or a server
error page (for anything else).
zGHTTPAuthSessionWrapper.getChildWithDefault encountered unexpected error)rg   r\   r]   r^   )	checkr   Unauthorizedrd   r   r   rf   rg   r	   )r   results   &&r   rz   #HTTPAuthSessionWrapper._loginFailed   sc     <<**E,=,=>>'(A(ABBII#  
 $C)92>>r   c                    VP                  R4      pV^ ,          P                  4       pV P                   F0  pVP                  V8X  g   K  VRP	                  VR,          4      3u # 	  R# )a&  
Choose an C{ICredentialFactory} from C{_credentialFactories}
suitable to use to decode the given I{Authenticate} header.

@return: A two-tuple of a factory and the remaining portion of the
    header value to be decoded or a two-tuple of L{None} if no
    factory can decode the header value.
r"   :   NN)NN)splitlowerr   r&   r%   )r   headerelementsr&   r9   s   &&   r   rb   )HTTPAuthSessionWrapper._selectParseHeader   s`     <<%!""$--D{{f$dii566 . r   c                    \        4       hr   rC   rE   s   &&&r   rG   HTTPAuthSessionWrapper.putChild   rI   r   )r   rW   N)rJ   rK   rL   rM   rN   rO   r   rf   r   rl   r:   r@   ra   ry   rz   rb   rG   rP   rQ   rR   s   @r   rU   rU   N   sM     	 F8D8C0A1	$'L?  $ $r   rU   N)rN   zope.interfacer   twisted.credr   twisted.cred.credentialsr   twisted.loggerr   twisted.python.componentsr   twisted.webr   twisted.web.resourcer   r	   r   rU   r=   r   r   <module>r      sa   
	 '  . ! 7  < Y/$ /$ /$d Y]$ ]$ ]$r   