+
    Dfj\                     (   R t ^ RIt^ RIHt ^ RIHt ^ RIHtHt ^ RI	H
t
HtHt ^ RIHt ^ RIHt ^ RIHt ^ R	IHt ^ R
IHt ^ RIHt ^ RIHt ^ RIHtHt ^ RIHt ^ RI H!t!H"t" ^ RI#H$t$ ^ RI%H&t&H't'H(t( ^ RI)H*t* ^ RI+H,t, ^ RI-H.t. R t/ ! R R4      t0 ! R R4      t1 ! R R]1]0]Pd                  4      t3 ! R R]1]Pd                  4      t4 ! R R]1]Pd                  4      t5]! ]Pl                  4        ! R  R!4      t7 ! R" R#]Pd                  4      t8R# )$z!
Tests for L{twisted.web._auth}.
N)implementer)verifyObject)errorportal)	ANONYMOUSAllowAnonymousAccess'InMemoryUsernamePasswordDatabaseDontUse)IUsernamePassword)IPv4Address)ConnectionDone)EventLoggingObserver)globalLogPublisher)Failure)unittest)basicdigest)BasicCredentialFactory)HTTPAuthSessionWrapperUnauthorizedResource)ICredentialFactory)	IResourceResourcegetChildForRequestNOT_DONE_YET)Data)DummyRequestc                 J    \         P                  ! V 4      P                  4       # N)base64	b64encodestrip)ss   &@/usr/lib/python3/dist-packages/twisted/web/test/test_httpauth.pyr    r    %   s    A$$&&    c                   R   a  ] tR t^)t o RtR tRR ltR tR tR t	R t
R	 tR
tV tR# )BasicAuthTestsMixinz
L{TestCase} mixin class which defines a number of tests for
L{basic.BasicCredentialFactory}.  Because this mixin defines C{setUp}, it
must be inherited before L{TestCase}.
c                    V P                  4       V n        R V n        RV n        RV n        \
        P                  ! V P                  4      V n        R# )s   foos   dreids   S3CuR1TyN)makeRequestrequestrealmusernamepasswordr   r   credentialFactoryselfs   &r#   setUpBasicAuthTestsMixin.setUp0   s>    '')
 #!&!=!=djj!Ir$   Nc                4    \        V P                  : R24      h)z
Create a request object to be passed to
L{basic.BasicCredentialFactory.decode} along with a response value.
Override this in a subclass.
z did not implement makeRequest)NotImplementedError	__class__)r/   methodclientAddresss   &&&r#   r(   BasicAuthTestsMixin.makeRequest7   s     "T^^$66T"UVVr$   c                X    V P                  \        \        V P                  4      4       R# )z=
L{BasicCredentialFactory} implements L{ICredentialFactory}.
N
assertTruer   r   r-   r.   s   &r#   test_interface"BasicAuthTestsMixin.test_interface?        	%79O9OPQr$   c                   \        RP                  V P                  RV P                  .4      4      pV P                  P                  WP                  4      pV P                  \        P                  ! V4      4       V P                  VP                  V P                  4      4       V P                  VP                  V P                  R,           4      4       R# )z
L{basic.BasicCredentialFactory.decode} turns a base64-encoded response
into a L{UsernamePassword} object with a password which reflects the
one which was encoded in the response.
r$      :s   wrongN)r    joinr+   r,   r-   decoder)   r:   r	   
providedBycheckPasswordassertFalser/   responsecredss   &  r#   test_usernamePassword)BasicAuthTestsMixin.test_usernamePasswordE   s     SXXt}}dDMM&JKL&&--hE)44U;<++DMM:;,,T]]X-EFGr$   c                f   \        RP                  V P                  RV P                  .4      4      pVP	                  R4      pV P
                  P                  WP                  4      pV P                  \        \        V4      4       V P                  VP                  V P                  4      4       R# )zb
L{basic.BasicCredentialFactory.decode} decodes a base64-encoded
response with incorrect padding.
r$   r?      =N)r    r@   r+   r,   r!   r-   rA   r)   r:   r   r	   rC   rE   s   &  r#   test_incorrectPadding)BasicAuthTestsMixin.test_incorrectPaddingR   s}    
 SXXt}}dDMM&JKL>>$'&&--hE%6>?++DMM:;r$   c                    RpV P                  \        P                  V P                  P                  VV P                  4       4       R# )zp
L{basic.BasicCredentialFactory.decode} raises L{LoginFailed} if passed
a response which is not base64-encoded.
   xN)assertRaisesr   LoginFailedr-   rA   r(   r/   rF   s   & r#   test_invalidEncoding(BasicAuthTestsMixin.test_invalidEncoding^   s>    
 ""))		
r$   c                    \        R4      pV P                  \        P                  V P                  P
                  VV P                  4       4       R# )z}
L{basic.BasicCredentialFactory.decode} raises L{LoginFailed} when
passed a response which is not valid base64-encoded text.
s   123abc+/N)r    rP   r   rQ   r-   rA   r(   rR   s   & r#   test_invalidCredentials+BasicAuthTestsMixin.test_invalidCredentialsk   sC    
 [)""))		
r$   )r-   r,   r*   r)   r+      GETN)__name__
__module____qualname____firstlineno____doc__r0   r(   r;   rH   rL   rS   rV   __static_attributes____classdictcell____classdict__s   @r#   r&   r&   )   s6     JWRH
<

 
r$   r&   c                   *   a  ] tR t^yt o RR ltRtV tR# )RequestMixinNc                V    Vf   \        RRR4      p\        R4      pWn        W#n        V# )zW
Create a L{DummyRequest} (change me to create a
L{twisted.web.http.Request} instead).
TCP	localhosti     /)r
   r   r5   client)r/   r5   r6   r)   s   &&& r#   r(   RequestMixin.makeRequestz   s1    
  '{DAMt$&r$    rX   )rZ   r[   r\   r]   r(   r_   r`   ra   s   @r#   rd   rd   y   s     
 
r$   rd   c                       ] tR t^tRtRtR# )BasicAuthTestszC
Basic authentication tests which use L{twisted.web.http.Request}.
rk   N)rZ   r[   r\   r]   r^   r_   rk   r$   r#   rm   rm      s    r$   rm   c                   B   a  ] tR t^t o RtR tR tR tR tR t	Rt
V tR# )	DigestAuthTestszD
Digest authentication tests which use L{twisted.web.http.Request}.
c                    RV n         RV n        \        P                  ! V P                  V P                   4      V n        V P                  4       V n        R# )z.
Create a DigestCredentialFactory for testing

   test realm   md5N)r*   	algorithmr   DigestCredentialFactoryr-   r(   r)   r.   s   &r#   r0   DigestAuthTests.setUp   sD     #
!'!?!?NNDJJ"
 '')r$   c                6  a aaaa RoRoR.o\        4       oVVVVV 3R lpS P                  S P                  P                  RV4       S P	                  S\        RS^Q4      4      pS P                  P                  SV4       S P                  S^ ,          4       R# )z
L{digest.DigestCredentialFactory.decode} calls the C{decode} method on
L{twisted.cred.digest.DigestCredentialFactory} with the HTTP method and
host of the request.
s   169.254.0.1rY   Fc                 ~   < SP                  SV 4       SP                  SV4       SP                  SV4       R S^ &   R# )TN)assertEqual)	_response_method_hostdonehostr5   rF   r/   s   &&&r#   check*DigestAuthTests.test_decode.<locals>.check   s<    Xy1VW-T5)DGr$   rA   rf   N)objectpatchr-   r   r(   r
   rA   r:   )r/   r~   reqr|   r}   r5   rF   s   f  @@@@r#   test_decodeDigestAuthTests.test_decode   s     w8	 	 	

4))00(EBv{5$'CD%%h4Q r$   c                X    V P                  \        \        V P                  4      4       R# )z>
L{DigestCredentialFactory} implements L{ICredentialFactory}.
Nr9   r.   s   &r#   r;   DigestAuthTests.test_interface   r=   r$   c                   V P                   P                  V P                  4      pV P                  VR,          R4       V P                  VR,          R4       V P                  VR,          R4       V P	                  RV4       V P	                  RV4       VP                  4        F  pV P                  R	V4       K  	  R
# )a8  
The challenge issued by L{DigestCredentialFactory.getChallenge} must
include C{'qop'}, C{'realm'}, C{'algorithm'}, C{'nonce'}, and
C{'opaque'} keys.  The values for the C{'realm'} and C{'algorithm'}
keys must match the values supplied to the factory's initializer.
None of the values may have newlines in them.
qop   authr*   rq   rs   rr   nonceopaque   
N)r-   getChallenger)   rx   assertInvaluesassertNotIn)r/   	challengevs   &  r#   test_getChallenge!DigestAuthTests.test_getChallenge   s     **77E	5)737+];;/8gy)h	*!!#AUA& $r$   c                >   V P                  RR4      pV P                  P                  V4      pV P                  VR,          R4       V P                  VR,          R4       V P                  VR,          R4       V P	                  R	V4       V P	                  R
V4       R# )z
L{DigestCredentialFactory.getChallenge} can issue a challenge even if
the L{Request} it is passed returns L{None} from C{getClientIP}.
rY   Nr   r   r*   rq   rs   rr   r   r   )r(   r-   r   rx   r   )r/   r)   r   s   &  r#    test_getChallengeWithoutClientIP0DigestAuthTests.test_getChallengeWithoutClientIP   s    
 ""640**77@	5)737+];;/8gy)h	*r$   )rs   r-   r*   r)   N)rZ   r[   r\   r]   r^   r0   r   r;   r   r   r_   r`   ra   s   @r#   ro   ro      s)     	*!,R'"+ +r$   ro   c                   H   a  ] tR t^t o RtR tR tR tR tR t	R t
RtV tR	# )
UnauthorizedResourceTestsz$
Tests for L{UnauthorizedResource}.
c                    \        . 4      pV P                  VP                  RR4      V4       V P                  VP                  RR4      V4       R# )z6
An L{UnauthorizedResource} is every child of itself.
fooNbar)r   assertIdenticalgetChildWithDefault)r/   resources   & r#   test_getChildWithDefault2UnauthorizedResourceTests.test_getChildWithDefault   sH     (+X99%FQX99%FQr$   c                    \        \        R4      .4      pVP                  V4       V P                  VP                  R4       V P                  VP
                  P                  R4      R.4       R# )z
Render L{UnauthorizedResource} for the given request object and verify
that the response code is I{Unauthorized} and that a I{WWW-Authenticate}
header is set in the response containing a challenge.
example.com     www-authenticates   basic realm="example.com"N)r   r   renderrx   responseCoderesponseHeadersgetRawHeaders)r/   r)   r   s   && r#   _unauthorizedRenderTest1UnauthorizedResourceTests._unauthorizedRenderTest   sb     ()?)N(OPx --s3##112EF)*	
r$   c                    V P                  4       pV P                  V4       V P                  RRP                  VP                  4      4       R# )z
L{UnauthorizedResource} renders with a 401 response code and a
I{WWW-Authenticate} header and puts a simple unauthorized message
into the response body.
s   Unauthorizedr$   Nr(   r   rx   r@   writtenr/   r)   s   & r#   test_render%UnauthorizedResourceTests.test_render   s=     ""$$$W-#((7??*CDr$   c                    V P                  RR7      pV P                  V4       V P                  RRP                  VP                  4      4       R# )z
The rendering behavior of L{UnauthorizedResource} for a I{HEAD} request
is like its handling of a I{GET} request, but no response body is
written.
s   HEAD)r5   r$   Nr   r   s   & r#   test_renderHEAD)UnauthorizedResourceTests.test_renderHEAD   sB     ""'"2$$W-chhw78r$   c                    \        \        R4      .4      pV P                  4       pVP                  V4       V P	                  VP
                  P                  R4      R.4       R# )z
The realm value included in the I{WWW-Authenticate} header set in
the response when L{UnauthorizedResounrce} is rendered has quotes
and backslashes escaped.
zexample\"foor   s   basic realm="example\\\"foo"N)r   r   r(   r   rx   r   r   )r/   r   r)   s   &  r#   test_renderQuotesRealm0UnauthorizedResourceTests.test_renderQuotesRealm  sZ     ()?)P(QR""$x ##112EF/0	
r$   c                   \        \        P                  ! RR4      .4      pV P                  4       pVP	                  V4       VP
                  P                  R4      ^ ,          pV P                  RV4       V P                  RV4       R# )z
The digest value included in the I{WWW-Authenticate} header
set in the response when L{UnauthorizedResource} is rendered
has quotes and backslashes escaped.
rr   s   example\"foor   s   realm="example\\\"foo"s   hm="md5N)r   r   rt   r(   r   r   r   r   )r/   r   r)   
authHeaders   &   r#   test_renderQuotesDigest1UnauthorizedResourceTests.test_renderQuotesDigest  sx     (++F4DEF
 ""$x ,,::;NOPQR
2J?j*-r$   rk   N)rZ   r[   r\   r]   r^   r   r   r   r   r   r   r_   r`   ra   s   @r#   r   r      s/     R
E9
. .r$   r   c                   6   a  ] tR tRt o RtR tR tR tRtV t	R# )Realmi(  a*  
A simple L{IRealm} implementation which gives out L{WebAvatar} for any
avatarId.

@type loggedIn: C{int}
@ivar loggedIn: The number of times C{requestAvatar} has been invoked for
    L{IResource}.

@type loggedOut: C{int}
@ivar loggedOut: The number of times the logout callback has been invoked.
c                .    ^ V n         ^ V n        Wn        R# )    N)	loggedOutloggedInavatarFactory)r/   r   s   &&r#   __init__Realm.__init__5  s    *r$   c                    \         V9   d<   V ;P                  ^,          un        \         V P                  V4      V P                  3# \	        4       h)   )r   r   r   logoutr3   )r/   avatarIdmind
interfacess   &&&*r#   requestAvatarRealm.requestAvatar:  s=    
"MMQMd00:DKKGG!##r$   c                8    V ;P                   ^,          un         R# )r   N)r   r.   s   &r#   r   Realm.logout@  s    !r$   )r   r   r   N)
rZ   r[   r\   r]   r^   r   r   r   r_   r`   ra   s   @r#   r   r   (  s     
+
$ r$   r   c                      a  ] tR tRt o Rt]tR tR tR t	R t
R tR tR	 tR
 tR tR tR tR tR tR tR tR tR tR tRtV tR# )HTTPAuthHeaderTestsiD  z&
Tests for L{HTTPAuthSessionWrapper}.
c                   RV n         RV n        RV n        RV n        RV n        \        4       V n        V P                  P                  V P                   V P                  4       \        V P                  R4      V n	        V P                  P                  V P                  \        V P                  R4      4       V P                   V P                  /V n        \        V P                  P                  4      V n        \        P                   ! V P                  V P                  .4      V n        . V n        \%        V P                  V P"                  4      V n        R# )zL
Create a realm, portal, and L{HTTPAuthSessionWrapper} to use in the tests.
s   foo bars   bar bazs&   contents of the avatar resource itselfs	   foo-childs'   contents of the foo child of the avatar
text/plainN)r+   r,   avatarContent	childNamechildContentr   checkeraddUserr   avatarputChildavatarsr   getr*   r   PortalcredentialFactoriesr   wrapperr.   s   &r#   r0   HTTPAuthHeaderTests.setUpK  s     #"F%F>@T]]DMM:4--|<T^^T$2C2C\-RSt{{34<<++,
mmDJJ?#% -dkk4;S;STr$   c                    \        V P                  R,           V P                  ,           4      pVP                  P	                  RRV,           4       \        V P                  V4      # )z
Add an I{basic authorization} header to the given request and then
dispatch it, starting from C{self.wrapper} and returning the resulting
L{IResource}.
r?      authorization   Basic )r    r+   r,   requestHeadersaddRawHeaderr   r   )r/   r)   authorizations   && r#   _authorizedBasicLogin)HTTPAuthHeaderTests._authorizedBasicLogin^  sM     "$--$"6"FG++,<i->WX!$,,88r$   c                   a a S P                  S P                  .4      o\        S P                  S4      pSP	                  4       pVV 3R lpVP                  V4       SP                  V4       V# )z
Resource traversal which encounters an L{HTTPAuthSessionWrapper}
results in an L{UnauthorizedResource} instance when the request does
not have the required I{Authorization} headers.
c                 @   < SP                  SP                  R 4       R# r   Nrx   r   resultr)   r/   s   &r#   
cbFinished@HTTPAuthHeaderTests.test_getChildWithDefault.<locals>.cbFinishedr      W1137r$   )r(   r   r   r   notifyFinishaddCallbackr   r/   childdr   r)   s   f   @r#   r   ,HTTPAuthHeaderTests.test_getChildWithDefaulth  s^     ""DNN#34"4<<9  "	8 	
j!ur$   c                `  a a S P                   P                  \        R4      4       S P                  S P                  .4      oSP
                  P                  RV4       \        S P                  S4      pSP                  4       pVV 3R lpVP                  V4       SP                  V4       V# )a   
Create a request with the given value as the value of an
I{Authorization} header and perform resource traversal with it,
starting at C{self.wrapper}.  Assert that the result is a 401 response
code.  Return a L{Deferred} which fires when this is all done.
r   r   c                 @   < SP                  SP                  R 4       R# r   r   r   s   &r#   r   AHTTPAuthHeaderTests._invalidAuthorizationTest.<locals>.cbFinished  r   r$   )r   appendr   r(   r   r   r   r   r   r   r   r   )r/   rF   r   r   r   r)   s   f&   @r#   _invalidAuthorizationTest-HTTPAuthHeaderTests._invalidAuthorizationTesty  s     	  ''(>}(MN""DNN#34++,<hG"4<<9  "	8 	
j!ur$   c                D    V P                  R\        R4      ,           4      # )z
Resource traversal which enouncters an L{HTTPAuthSessionWrapper}
results in an L{UnauthorizedResource} when the request has an
I{Authorization} header with a user which does not exist.
r   s   foo:bar)r   r    r.   s   &r#   (test_getChildWithDefaultUnauthorizedUser<HTTPAuthHeaderTests.test_getChildWithDefaultUnauthorizedUser  s     --i)J:O.OPPr$   c                f    V P                  R\        V P                  R,           4      ,           4      # )z
Resource traversal which enouncters an L{HTTPAuthSessionWrapper}
results in an L{UnauthorizedResource} when the request has an
I{Authorization} header with a user which exists and the wrong
password.
r   s   :bar)r   r    r+   r.   s   &r#   ,test_getChildWithDefaultUnauthorizedPassword@HTTPAuthHeaderTests.test_getChildWithDefaultUnauthorizedPassword  s-     --	$--'"9::
 	
r$   c                $    V P                  R4      # )z
Resource traversal which enouncters an L{HTTPAuthSessionWrapper}
results in an L{UnauthorizedResource} when the request has an
I{Authorization} header with an unrecognized scheme.
s   Quux foo bar baz)r   r.   s   &r#   *test_getChildWithDefaultUnrecognizedScheme>HTTPAuthHeaderTests.test_getChildWithDefaultUnrecognizedScheme  s     --.ABBr$   c                  a a S P                   P                  \        R4      4       S P                  S P                  .4      oS P                  S4      pSP                  4       pVV 3R lpVP                  V4       SP                  V4       V# )z
Resource traversal which encounters an L{HTTPAuthSessionWrapper}
results in an L{IResource} which renders the L{IResource} avatar
retrieved from the portal when the request has a valid I{Authorization}
header.
r   c                 V   < SP                  SP                  SP                  .4       R # r   )rx   r   r   ignoredr)   r/   s   &r#   r   JHTTPAuthHeaderTests.test_getChildWithDefaultAuthorized.<locals>.cbFinished  s     W__t/@/@.ABr$   )	r   r   r   r(   r   r   r   r   r   r   s   f   @r#   "test_getChildWithDefaultAuthorized6HTTPAuthHeaderTests.test_getChildWithDefaultAuthorized  sy     	  ''(>}(MN""DNN#34**73  "	C 	
j!ur$   c                  a a S P                   P                  \        R4      4       S P                  . 4      oS P	                  S4      pSP                  4       pVV 3R lpVP                  V4       SP                  V4       V# )z
Resource traversal which terminates at an L{HTTPAuthSessionWrapper}
and includes correct authentication headers results in the
L{IResource} avatar (not one of its children) retrieved from the
portal being rendered.
r   c                 V   < SP                  SP                  SP                  .4       R # r   )rx   r   r   r  s   &r#   r   =HTTPAuthHeaderTests.test_renderAuthorized.<locals>.cbFinished  s     W__t/A/A.BCr$   )r   r   r   r(   r   r   r   r   r   s   f   @r#   test_renderAuthorized)HTTPAuthHeaderTests.test_renderAuthorized  sr     	  ''(>}(MN""2&**73  "	D 	
j!ur$   c                `  a aa \        \        4       ! R R4      4       pV! 4       oS P                  P                  S4       S P	                  S P
                  .4      o\        S P                  S4      pSP                  4       pVVV 3R lpVP                  V4       SP                  V4       V# )z
When L{HTTPAuthSessionWrapper} finds an L{ICredentialFactory} to issue
a challenge, it calls the C{getChallenge} method with the request as an
argument.
c                   0   a  ] tR tRt o RtR tR tRtV tR# )UHTTPAuthHeaderTests.test_getChallengeCalledWithRequest.<locals>.DumbCredentialFactoryi  s   dumbc                    . V n         R # r   requestsr.   s   &r#   r   ^HTTPAuthHeaderTests.test_getChallengeCalledWithRequest.<locals>.DumbCredentialFactory.__init__  s	     "r$   c                <    V P                   P                  V4       / # r   )r  r   r   s   &&r#   r   bHTTPAuthHeaderTests.test_getChallengeCalledWithRequest.<locals>.DumbCredentialFactory.getChallenge  s    $$W-	r$   r  N)	rZ   r[   r\   r]   schemer   r   r_   r`   ra   s   @r#   DumbCredentialFactoryr    s     F# r$   r  c                 B   < SP                  SP                  S.4       R # r   )rx   r  )r	  factoryr)   r/   s   &r#   r   JHTTPAuthHeaderTests.test_getChallengeCalledWithRequest.<locals>.cbFinished  s    W--y9r$   )r   r   r   r   r(   r   r   r   r   r   r   )r/   r  r   r   r   r  r)   s   f    @@r#   "test_getChallengeCalledWithRequest6HTTPAuthHeaderTests.test_getChallengeCalledWithRequest  s     
'	(	 	 
)	 ()  ''0""DNN#34"4<<9  "	: 	
j!ur$   c                   V P                   P                  \        R4      4        ! R R\        4      pV P                  P                  V P                  V! 4       4       V P                  V P                  .4      pV P                  V4      pVP                  V4       V P                  V P                  P                  ^ 4       V# )z
Issue a request for an authentication-protected resource using valid
credentials and then return the C{DummyRequest} instance which was
used.

This is a helper for tests about the behavior of the logout
callback.
r   c                   &   a  ] tR tRt o R tRtV tR# )7HTTPAuthHeaderTests._logoutTest.<locals>.SlowerResourcei  c                    \         # r   r   r   s   &&r#   r   >HTTPAuthHeaderTests._logoutTest.<locals>.SlowerResource.render  s    ##r$   rk   N)rZ   r[   r\   r]   r   r_   r`   ra   s   @r#   SlowerResourcer$    s     $ $r$   r'  )r   r   r   r   r   r   r   r(   r   r   rx   r*   r   )r/   r'  r)   r   s   &   r#   _logoutTestHTTPAuthHeaderTests._logoutTest  s     	  ''(>}(MN	$X 	$ 	T^^^-=>""DNN#34**73u--q1r$   c                    V P                  4       pVP                  4        V P                  V P                  P                  ^4       R# )zH
The realm's logout callback is invoked after the resource is rendered.
N)r(  finishrx   r*   r   r   s   & r#   test_logoutHTTPAuthHeaderTests.test_logout  s6     ""$--q1r$   c                    V P                  4       pVP                  \        \        R4      4      4       V P	                  V P
                  P                  ^4       R# )z
The realm's logout callback is also invoked if there is an error
generating the response (for example, if the client disconnects
early).
zSimulated disconnectN)r(  processingFailedr   r   rx   r*   r   r   s   & r#   test_logoutOnError&HTTPAuthHeaderTests.test_logoutOnError  sE     ""$  8N)O!PQ--q1r$   c                   V P                   P                  \        R4      4       V P                  V P                  .4      pVP
                  P                  RR4       \        V P                  V4      pV P                  V\        4       R# )z
Resource traversal which enouncters an L{HTTPAuthSessionWrapper}
results in an L{UnauthorizedResource} when the request has a I{Basic
Authorization} header which cannot be decoded using base64.
r   r   s   Basic decode should failN)r   r   r   r(   r   r   r   r   r   assertIsInstancer   )r/   r)   r   s   &  r#   test_decodeRaises%HTTPAuthHeaderTests.test_decodeRaises  sr     	  ''(>}(MN""DNN#34++9	
 #4<<9e%9:r$   c                   RpV P                  V P                  P                  V4      R4       \        R4      pV P                  P                  V4       V P                  V P                  P                  V4      VR34       R# )z
L{HTTPAuthSessionWrapper._selectParseHeader} returns a two-tuple giving
the L{ICredentialFactory} to use to parse the header and a string
containing the portion of the header which remains to be parsed.
s   Basic abcdef123456Nr   s   abcdef123456)NN)rx   r   _selectParseHeaderr   r   r   )r/   basicAuthorizationr  s   &  r#   test_selectParseResponse,HTTPAuthHeaderTests.test_selectParseResponse$  sv     3LL++,>?	
 )7  ''0LL++,>?o&	
r$   c                  a \         P                  ! V \        4      p ! R R\        4      o ! V3R lR4      pV P                  P                  V! 4       4       V P                  V P                  .4      pVP                  P                  RR4       \        V P                  V4      pVP                  V4       V P                  VP                  R4       V P                  ^\!        V4      4       V P#                  V^ ,          R,          P$                  S4       V P                  \!        V P'                  S4      4      ^4       R	# )
z
Any unexpected exception raised by the credential factory's C{decode}
method results in a 500 response code and causes the exception to be
logged.
c                       ] tR tRtRtR# )KHTTPAuthHeaderTests.test_unexpectedDecodeError.<locals>.UnexpectedExceptioni=  rk   NrZ   r[   r\   r]   r_   rk   r$   r#   UnexpectedExceptionr=  =      r$   r?  c                   8   <a  ] tR tRt o RtR tV3R ltRtV tR# )BHTTPAuthHeaderTests.test_unexpectedDecodeError.<locals>.BadFactoryi@  s   badc                    / # r   rk   )r/   ri   s   &&r#   r   OHTTPAuthHeaderTests.test_unexpectedDecodeError.<locals>.BadFactory.getChallengeC  s    	r$   c                   < S! 4       hr   rk   )r/   rF   r)   r?  s   &&&r#   rA   IHTTPAuthHeaderTests.test_unexpectedDecodeError.<locals>.BadFactory.decodeF      )++r$   rk   N)	rZ   r[   r\   r]   r  r   rA   r_   r`   rb   r?  s   @r#   
BadFactoryrB  @  s     F, ,r$   rI  r   s   Bad abc  log_failureN)r   createWithCleanupr   	Exceptionr   r   r(   r   r   r   r   r   r   rx   r   assertEqualslenr3  valueflushLoggedErrors)r/   logObserverrI  r)   r   r?  s   &    @r#   test_unexpectedDecodeError.HTTPAuthHeaderTests.test_unexpectedDecodeError5  s     +<<TCUV	) 		, 	, 	  ''
5""DNN#34++,<jI"4<<9u--s3!S-.k!n];AACVWT334GHI1Mr$   c                  a \         P                  ! V \        4      p ! R R\        4      o ! V3R lR4      pV P                  P                  V! 4       4       V P                  P                  \        R4      4       V P                  V P                  .4      pV P                  V4      pVP                  V4       V P                  VP                  R4       V P                  ^\!        V4      4       V P#                  V^ ,          R,          P$                  S4       V P                  \!        V P'                  S4      4      ^4       R# )	zq
Any unexpected failure from L{Portal.login} results in a 500 response
code and causes the failure to be logged.
c                       ] tR tRtRtR# )JHTTPAuthHeaderTests.test_unexpectedLoginError.<locals>.UnexpectedExceptioniZ  rk   Nr>  rk   r$   r#   r?  rW  Z  r@  r$   r?  c                   4   <a  ] tR tRt o ]3tV3R ltRtV tR# )DHTTPAuthHeaderTests.test_unexpectedLoginError.<locals>.BrokenCheckeri]  c                   < S! 4       hr   rk   )r/   credentialsr?  s   &&r#   requestAvatarIdTHTTPAuthHeaderTests.test_unexpectedLoginError.<locals>.BrokenChecker.requestAvatarId`  rG  r$   rk   N)	rZ   r[   r\   r]   r	   credentialInterfacesr\  r_   r`   rH  s   @r#   BrokenCheckerrY  ]  s     $5#7 , ,r$   r_  r   rJ  rK  N)r   rL  r   rM  r   registerCheckerr   r   r   r(   r   r   r   rx   r   rN  rO  r3  rP  rQ  )r/   rR  r_  r)   r   r?  s   &    @r#   test_unexpectedLoginError-HTTPAuthHeaderTests.test_unexpectedLoginErrorS  s    
 +<<TCUV	) 		, 	, 	##MO4  ''(>}(MN""DNN#34**73u--s3!S-.k!n];AACVWT334GHI1Mr$   c                "  a aa Ro\        4       S P                  \        &   S P                  \        ,          P                  S P                  \        SR4      4       S P                  P                  \        4       4       S P                  P                  \        R4      4       S P                  S P                  .4      o\        S P                  S4      pSP                  4       pVV V3R lpVP!                  V4       SP#                  V4       V# )zT
Anonymous requests are allowed if a L{Portal} has an anonymous checker
registered.
s*   contents of the unprotected child resourcer   r   c                 B   < SP                  SP                  S.4       R # r   )rx   r   )r	  r)   r/   unprotectedContentss   &r#   r   <HTTPAuthHeaderTests.test_anonymousAccess.<locals>.cbFinished  s    W__/B.CDr$   )r   r   r   r   r   r   r   r`  r   r   r   r   r(   r   r   r   r   r   )r/   r   r   r   r)   re  s   f   @@r#   test_anonymousAccess(HTTPAuthHeaderTests.test_anonymousAccessm  s    
 L"**YY((NND!4lC	
 	##$8$:;  ''(>}(MN""DNN#34"4<<9  "	E 	
j!ur$   )r   r   r   r   r   r   r   r,   r   r*   r+   r   N)rZ   r[   r\   r]   r^   r   r(   r0   r   r   r   r   r  r  r  r  r   r(  r,  r0  r4  r9  rS  ra  rg  r_   r`   ra   s   @r#   r   r   D  su      KU&9"(Q	
C&(>,22;
"N<N4 r$   r   )9r^   r   zope.interfacer   zope.interface.verifyr   twisted.credr   r   twisted.cred.checkersr   r   r   twisted.cred.credentialsr	   twisted.internet.addressr
   twisted.internet.errorr   twisted.internet.testingr   twisted.loggerr   twisted.python.failurer   twisted.trialr   twisted.web._authr   r   twisted.web._auth.basicr   twisted.web._auth.wrapperr   r   twisted.web.iwebr   twisted.web.resourcer   r   r   twisted.web.serverr   twisted.web.staticr   twisted.web.test.test_webr   r    r&   rd   TestCaserm   ro   r   IRealmr   r   rk   r$   r#   <module>r~     s   
  & . & 
 7 0 1 9 - * " + : R / H H + # 2'M
 M
` \#68I8I H+lH$5$5 H+VJ.h.?.? J.Z FMM  8@(++ @r$   