Ë
    zñ�j­,  ã                   ó  — d Z ddlmZ ddlmZ ddlmZ ddlmZ  G d„ d«      Z	 G d	„ d
e	«      Z
 G d„ de	«      Z G d„ de	«      Z G d„ de«      Z G d„ de«      Z edddg«      Z G d„ de«      Z G d„ de«      Z G d„ d«      Zy)z¿
Modern, adaptable authentication machinery.

Replaces certain parts of `.SSHClient`. For a concrete implementation, see the
``OpenSSHAuthStrategy`` class in `Fabric <https://fabfile.org>`_.
é    )Ú
namedtupleé   )ÚAgentKey)Ú
get_logger)ÚAuthenticationExceptionc                   ó(   — e Zd ZdZd„ Zd„ Zd„ Zd„ Zy)Ú
AuthSourcezã
    Some SSH authentication source, such as a password, private key, or agent.

    See subclasses in this module for concrete implementations.

    All implementations must accept at least a ``username`` (``str``) kwarg.
    c                 ó   — || _         y ©N©Úusername)Úselfr   s     úW/var/www/api.ozpay.ru/ozpay/venv/lib/python3.12/site-packages/paramiko/auth_strategy.pyÚ__init__zAuthSource.__init__   s	   € Ø ˆ�ó    c                 ó¶   — |j                  «       D ��cg c]  \  }}|› d|›�‘Œ }}}dj                  |«      }| j                  j                  › d|› d�S c c}}w )Nú=z, ú(ú))ÚitemsÚjoinÚ	__class__Ú__name__)r   ÚkwargsÚkÚvÚpairsÚjoineds         r   Ú_reprzAuthSource._repr   s\   € ð +1¯,©,«.×9¡$ ! Q�A�3�a˜�u’Ð9ˆÑ9Ø—‘˜5Ó!ˆØ—.‘.×)Ñ)Ð*¨!¨F¨8°1Ð5Ð5ùó :s   ”Ac                 ó"   — | j                  «       S r   )r   ©r   s    r   Ú__repr__zAuthSource.__repr__"   s   € Ø�z‰z‹|Ðr   c                 ó   — t         ‚)z)
        Perform authentication.
        ©ÚNotImplementedError©r   Ú	transports     r   ÚauthenticatezAuthSource.authenticate%   s
   € ô "Ð!r   N)r   Ú
__module__Ú__qualname__Ú__doc__r   r   r"   r(   © r   r   r	   r	      s   „ ñò!ò6òó"r   r	   c                   ó   — e Zd ZdZd„ Zy)ÚNoneAuthzS
    Auth type "none", ie https://www.rfc-editor.org/rfc/rfc4252#section-5.2 .
    c                 ó8   — |j                  | j                  «      S r   )Ú	auth_noner   r&   s     r   r(   zNoneAuth.authenticate1   s   € Ø×"Ñ" 4§=¡=Ó1Ð1r   N©r   r)   r*   r+   r(   r,   r   r   r.   r.   ,   s   „ ñó2r   r.   c                   ó2   ‡ — e Zd ZdZˆ fd„Zˆ fd„Zd„ Zˆ xZS )ÚPassworda  
    Password authentication.

    :param callable password_getter:
        A lazy callable that should return a `str` password value at
        authentication time, such as a `functools.partial` wrapping
        `getpass.getpass`, an API call to a secrets store, or similar.

        If you already know the password at instantiation time, you should
        simply use something like ``lambda: "my literal"`` (for a literal, but
        also, shame on you!) or ``lambda: variable_name`` (for something stored
        in a variable).
    c                 ó4   •— t         ‰| �  |¬«       || _        y ©Nr   )Úsuperr   Úpassword_getter)r   r   r7   r   s      €r   r   zPassword.__init__D   s   ø€ Ü‰Ñ (ÐÔ+Ø.ˆÕr   c                 ó8   •— t         ‰| �  | j                  ¬«      S )N)Úuser)r6   r   r   )r   r   s    €r   r"   zPassword.__repr__H   s   ø€ ô ‰w‰} $§-¡-ˆ}Ó0Ð0r   c                 óZ   — | j                  «       }|j                  | j                  |«      S r   )r7   Úauth_passwordr   )r   r'   Úpasswords      r   r(   zPassword.authenticateM   s)   € ð ×'Ñ'Ó)ˆØ×&Ñ& t§}¡}°hÓ?Ð?r   )r   r)   r*   r+   r   r"   r(   Ú__classcell__©r   s   @r   r3   r3   5   s   ø„ ñô/ô1ö
@r   r3   c                   ó   — e Zd ZdZd„ Zy)Ú
PrivateKeya‹  
    Essentially a mixin for private keys.

    Knows how to auth, but leaves key material discovery/loading/decryption to
    subclasses.

    Subclasses **must** ensure that they've set ``self.pkey`` to a decrypted
    `.PKey` instance before calling ``super().authenticate``; typically
    either in their ``__init__``, or in an overridden ``authenticate`` prior to
    its `super` call.
    c                 óN   — |j                  | j                  | j                  «      S r   )Úauth_publickeyr   Úpkeyr&   s     r   r(   zPrivateKey.authenticatee   s   € Ø×'Ñ'¨¯©°t·y±yÓAÐAr   Nr1   r,   r   r   r@   r@   X   s   „ ñ
óBr   r@   c                   ó,   ‡ — e Zd ZdZˆ fd„Zˆ fd„Zˆ xZS )ÚInMemoryPrivateKeyz1
    An in-memory, decrypted `.PKey` object.
    c                 ó4   •— t         ‰| �  |¬«       || _        y r5   )r6   r   rC   )r   r   rC   r   s      €r   r   zInMemoryPrivateKey.__init__n   s   ø€ Ü‰Ñ (ÐÔ+àˆ�	r   c                 óz   •— t         ‰| �  | j                  ¬«      }t        | j                  t        «      r|dz  }|S )N)rC   z [agent])r6   r   rC   Ú
isinstancer   )r   Úrepr   s     €r   r"   zInMemoryPrivateKey.__repr__s   s6   ø€ ô ‰g‰m §¡ˆmÓ+ˆÜ�d—i‘i¤Ô*Ø�:ÑˆCØˆ
r   ©r   r)   r*   r+   r   r"   r=   r>   s   @r   rE   rE   i   s   ø„ ñô÷
ð r   rE   c                   ó(   ‡ — e Zd ZdZˆ fd„Zd„ Zˆ xZS )ÚOnDiskPrivateKeya™  
    Some on-disk private key that needs opening and possibly decrypting.

    :param str source:
        String tracking where this key's path was specified; should be one of
        ``"ssh-config"``, ``"python-config"``, or ``"implicit-home"``.
    :param Path path:
        The filesystem path this key was loaded from.
    :param PKey pkey:
        The `PKey` object this auth source uses/represents.
    c                 óx   •— t         ‰| �  |¬«       || _        d}||vrt        d|›�«      ‚|| _        || _        y )Nr   )z
ssh-configzpython-configzimplicit-homez source argument must be one of: )r6   r   ÚsourceÚ
ValueErrorÚpathrC   )r   r   rN   rP   rC   Úallowedr   s         €r   r   zOnDiskPrivateKey.__init__‰   sH   ø€ Ü‰Ñ (ÐÔ+ØˆŒØBˆØ˜Ñ ÜÐ?À¸{ÐKÓLÐLØˆŒ	àˆ�	r   c                 óx   — | j                  | j                  | j                  t        | j                  «      ¬«      S )N)ÚkeyrN   rP   )r   rC   rN   ÚstrrP   r!   s    r   r"   zOnDiskPrivateKey.__repr__“   s/   € Ø�z‰zØ—	‘	 $§+¡+´C¸¿	¹	³Nð ó 
ð 	
r   rJ   r>   s   @r   rL   rL   |   s   ø„ ñ
ôö
r   rL   ÚSourceResultrN   Úresultc                   ó(   ‡ — e Zd ZdZˆ fd„Zd„ Zˆ xZS )Ú
AuthResultaÞ  
    Represents a partial or complete SSH authentication attempt.

    This class conceptually extends `AuthStrategy` by pairing the former's
    authentication **sources** with the **results** of trying to authenticate
    with them.

    `AuthResult` is a (subclass of) `list` of `namedtuple`, which are of the
    form ``namedtuple('SourceResult', 'source', 'result')`` (where the
    ``source`` member is an `AuthSource` and the ``result`` member is either a
    return value from the relevant `.Transport` method, or an exception
    object).

    .. note::
        Transport auth method results are always themselves a ``list`` of "next
        allowable authentication methods".

        In the simple case of "you just authenticated successfully", it's an
        empty list; if your auth was rejected but you're allowed to try again,
        it will be a list of string method names like ``pubkey`` or
        ``password``.

        The ``__str__`` of this class represents the empty-list scenario as the
        word ``success``, which should make reading the result of an
        authentication session more obvious to humans.

    Instances also have a `strategy` attribute referencing the `AuthStrategy`
    which was attempted.
    c                 ó2   •— || _         t        ‰| �  |i |¤Ž y r   )Ústrategyr6   r   )r   rZ   Úargsr   r   s       €r   r   zAuthResult.__init__Ç   s   ø€ Ø ˆŒÜ‰Ñ˜$Ð) &Ó)r   c                 ó2   — dj                  d„ | D «       «      S )Nú
c              3   óZ   K  — | ]#  }|j                   › d |j                  xs d› �–— Œ% y­w)z -> ÚsuccessN)rN   rV   )Ú.0Úxs     r   ú	<genexpr>z%AuthResult.__str__.<locals>.<genexpr>Ð   s.   è ø€ ò 
Ø9:ˆq�x‰xˆj˜˜QŸX™XÒ2¨Ð3Ô4ñ
ùs   ‚)+)r   r!   s    r   Ú__str__zAuthResult.__str__Ë   s"   € ð
 �y‰yñ 
Ø>Bô
ó 
ð 	
r   )r   r)   r*   r+   r   rc   r=   r>   s   @r   rX   rX   ¨   s   ø„ ñô<*ö
r   rX   c                   ó   — e Zd ZdZd„ Zd„ Zy)ÚAuthFailurea®  
    Basic exception wrapping an `AuthResult` indicating overall auth failure.

    Note that `AuthFailure` descends from `AuthenticationException` but is
    generally "higher level"; the latter is now only raised by individual
    `AuthSource` attempts and should typically only be seen by users when
    encapsulated in this class. It subclasses `AuthenticationException`
    primarily for backwards compatibility reasons.
    c                 ó   — || _         y r   ©rV   )r   rV   s     r   r   zAuthFailure.__init__á   s	   € Øˆ�r   c                 ó2   — dt        | j                  «      z   S )Nr]   )rT   rV   r!   s    r   rc   zAuthFailure.__str__ä   s   € Ø”c˜$Ÿ+™+Ó&Ñ&Ð&r   N)r   r)   r*   r+   r   rc   r,   r   r   re   re   Ö   s   „ ñòó'r   re   c                   ó"   — e Zd ZdZd„ Zd„ Zd„ Zy)ÚAuthStrategya   
    This class represents one or more attempts to auth with an SSH server.

    By default, subclasses must at least accept an ``ssh_config``
    (`.SSHConfig`) keyword argument, but may opt to accept more as needed for
    their particular strategy.
    c                 ó:   — || _         t        t        «      | _        y r   )Ú
ssh_configr   r   Úlog)r   rl   s     r   r   zAuthStrategy.__init__ñ   s   € ð %ˆŒÜœhÓ'ˆ�r   c                 ó   — t         ‚)a[  
        Generator yielding `AuthSource` instances, in the order to try.

        This is the primary override point for subclasses: you figure out what
        sources you need, and ``yield`` them.

        Subclasses _of_ subclasses may find themselves wanting to do things
        like filtering or discarding around a call to `super`.
        r$   r!   s    r   Úget_sourceszAuthStrategy.get_sourcesø   s
   € ô "Ð!r   c                 ó¨  — d}t        | ¬«      }| j                  «       D ]S  }| j                  j                  d|› �«       	 |j	                  |«      }d}|j                  t        ||«      «       |sŒS n |st        |¬«      ‚|S # t
        $ rC}|}|j                  j                  }| j                  j                  d|› d|› �«       Y d}~Œxd}~ww xY w)	z»
        Handles attempting `AuthSource` instances yielded from `get_sources`.

        You *normally* won't need to override this, but it's an option for
        advanced users.
        F)rZ   zTrying TzAuthentication via z failed with Nrg   )rX   ro   rm   Údebugr(   Ú	Exceptionr   r   ÚinfoÚappendrU   re   )r   r'   Ú	succeededÚoverall_resultrN   rV   ÚeÚsource_classs           r   r(   zAuthStrategy.authenticate  sÞ   € ð ˆ	Ü#¨TÔ2ˆð ×&Ñ&Ó(ò 	ˆFØ�H‰H�N‰N˜W V HÐ-Ô.ðØ×,Ñ,¨YÓ7�Ø �	ð" ×!Ñ!¤,¨v°vÓ">Ô?ÚÙð/	ñ4 Ü ^Ô4Ð4àÐøô) ò Ø�ð  !Ÿ{™{×3Ñ3�Ø—‘—‘Ø)¨&¨°¸|¸nÐM÷ñ ûðús   ÁBÂ	CÂ9CÃCN)r   r)   r*   r+   r   ro   r(   r,   r   r   rj   rj   è   s   „ ñò(ò
"ó+r   rj   N)r+   Úcollectionsr   Úagentr   Úutilr   Ússh_exceptionr   r	   r.   r3   r@   rE   rL   rU   ÚlistrX   re   rj   r,   r   r   ú<module>r~      s�   ðñõ #å Ý Ý 2÷"ñ "ô:2ˆzô 2ô@ˆzô @ôFB�ô Bô"˜ô ô&
�zô 
ñB ˜.¨8°XÐ*>Ó?€ô*
�ô *
ô\'Ð)ô '÷$Gò Gr   