§
    ÀiÛD  ã                   ó  — U d Z ddlZddlZddlZddlZddlZddlmZmZm	Z	m
Z
mZmZmZmZmZ ddlmZ ddlmZ ddlmZ ddlmZ dd	lmZmZ dd
lmZ  G d„ ded¬¦  «        Zej        ej        ej        ej        ej         ej         ej         ej         ej!        ej!        ej!        ej!        dœZ"ee#ee$gdf         f         e%d<    ej&        ej'        dk     rdnd¦  «        Z(dZ)e	eed         df                  e%d<    e* e+e" ,                    ¦   «         ¦  «        ¦  «        Z-e	ee#df                  e%d<    e.h d£¦  «        Z/e	e
e#                  e%d<   de#de#fd„Z0de#de#fd„Z1de#dee#e#f         fd „Z2 G d!„ d"¦  «        Z3dS )#av  
Digest authentication middleware for aiohttp client.

This middleware implements HTTP Digest Authentication according to RFC 7616,
providing a more secure alternative to Basic Authentication. It supports all
standard hash algorithms including MD5, SHA, SHA-256, SHA-512 and their session
variants, as well as both 'auth' and 'auth-int' quality of protection (qop) options.
é    N)	ÚCallableÚDictÚFinalÚ	FrozenSetÚListÚLiteralÚTupleÚ	TypedDictÚUnion)ÚURLé   )Úhdrs)ÚClientError)ÚClientHandlerType)ÚClientRequestÚClientResponse)ÚPayloadc                   óV   — e Zd ZU eed<   eed<   eed<   eed<   eed<   eed<   eed<   dS )	ÚDigestAuthChallengeÚrealmÚnonceÚqopÚ	algorithmÚopaqueÚdomainÚstaleN)Ú__name__Ú
__module__Ú__qualname__ÚstrÚ__annotations__© ó    új/home/mmwave/public_html/mmwave/venv/lib/python3.11/site-packages/aiohttp/client_middleware_digest_auth.pyr   r   $   sO   € € € € € € Ø€J€J�JØ€J€J�JØ	€H€H�HØ€N€N�NØ€K€K�KØ€K€K�KØ€J€J�J€J€Jr#   r   F)Útotal)ÚMD5zMD5-SESSÚSHAzSHA-SESSÚSHA256zSHA256-SESSzSHA-256zSHA-256-SESSÚSHA512zSHA512-SESSzSHA-512zSHA-512-SESSzhashlib._HashÚDigestFunctions)é   é   z:(?:^|\s|,\s*)(\w+)\s*=\s*(?:"((?:[^"\\]|\\.)*)"|([^\s,]+))z>(?:^|\s|,\s*)((?>\w+))\s*=\s*(?:"((?:[^"\\]|\\.)*)"|([^\s,]+)))r   r   r   r   r   r   r   .ÚCHALLENGE_FIELDSÚSUPPORTED_ALGORITHMS>   Úurir   r   Úcnoncer   ÚresponseÚusernameÚQUOTED_AUTH_FIELDSÚvalueÚreturnc                 ó.   — |                       dd¦  «        S )z,Escape double quotes for HTTP header values.ú"ú\"©Úreplace©r4   s    r$   Úescape_quotesr<   u   s   € à�=Š=˜˜eÑ$Ô$Ð$r#   c                 ó.   — |                       dd¦  «        S )z-Unescape double quotes in HTTP header values.r8   r7   r9   r;   s    r$   Úunescape_quotesr>   z   s   € à�=Š=˜ Ñ$Ô$Ð$r#   Úheaderc                 óP   ‡— ˆfd„t                                | ¦  «        D ¦   «         S )a�  
    Parse key-value pairs from WWW-Authenticate or similar HTTP headers.

    This function handles the complex format of WWW-Authenticate header values,
    supporting both quoted and unquoted values, proper handling of commas in
    quoted values, and whitespace variations per RFC 7616.

    Examples of supported formats:
      - key1="value1", key2=value2
      - key1 = "value1" , key2="value, with, commas"
      - key1=value1,key2="value2"
      - realm="example.com", nonce="12345", qop="auth"

    Args:
        header: The header value string to parse

    Returns:
        Dictionary mapping parameter names to their values
    c                 ól   •— i | ]0\  }}}|                      ¦   «         xŠ¯‰|rt          |¦  «        n|“Œ1S r"   )Ústripr>   )Ú.0ÚkeyÚ
quoted_valÚunquoted_valÚstripped_keys       €r$   ú
<dictcomp>z&parse_header_pairs.<locals>.<dictcomp>“   sV   ø€ ð ð ð á)ˆC�˜\ØŸIšI™KœKÐ'ˆLðØ°ZÐQ•o jÑ1Ô1Ð1À\ðð ð r#   )Ú_HEADER_PAIRS_PATTERNÚfindall)r?   rG   s    @r$   Úparse_header_pairsrK      s<   ø€ ð(ð ð ð å-B×-JÒ-JÈ6Ñ-RÔ-Rðñ ô ð r#   c            	       ó–   — e Zd ZdZ	 ddedededdfd„Zd	ed
edee	e
d         f         defd„Zd
edefd„Zdedefd„Zdededefd„ZdS )ÚDigestAuthMiddlewarea  
    HTTP digest authentication middleware for aiohttp client.

    This middleware intercepts 401 Unauthorized responses containing a Digest
    authentication challenge, calculates the appropriate digest credentials,
    and automatically retries the request with the proper Authorization header.

    Features:
    - Handles all aspects of Digest authentication handshake automatically
    - Supports all standard hash algorithms:
      - MD5, MD5-SESS
      - SHA, SHA-SESS
      - SHA256, SHA256-SESS, SHA-256, SHA-256-SESS
      - SHA512, SHA512-SESS, SHA-512, SHA-512-SESS
    - Supports 'auth' and 'auth-int' quality of protection modes
    - Properly handles quoted strings and parameter parsing
    - Includes replay attack protection with client nonce count tracking
    - Supports preemptive authentication per RFC 7616 Section 3.6

    Standards compliance:
    - RFC 7616: HTTP Digest Access Authentication (primary reference)
    - RFC 2617: HTTP Authentication (deprecated by RFC 7616)
    - RFC 1945: Section 11.1 (username restrictions)

    Implementation notes:
    The core digest calculation is inspired by the implementation in
    https://github.com/requests/requests/blob/v2.18.4/requests/auth.py
    with added support for modern digest auth features and error handling.
    TÚloginÚpasswordÚ
preemptiver5   Nc                 ó,  — |€t          d¦  «        ‚|€t          d¦  «        ‚d|v rt          d¦  «        ‚|| _        |                     d¦  «        | _        |                     d¦  «        | _        d| _        d| _        i | _        || _        g | _	        d S )Nz"None is not allowed as login valuez%None is not allowed as password valueú:z8A ":" is not allowed in username (RFC 1945#section-11.1)úutf-8r#   r   )
Ú
ValueErrorÚ
_login_strÚencodeÚ_login_bytesÚ_password_bytesÚ_last_nonce_bytesÚ_nonce_countÚ
_challengeÚ_preemptiveÚ_protection_space)ÚselfrN   rO   rP   s       r$   Ú__init__zDigestAuthMiddleware.__init__¹   s¡   € ð ˆ=ÝÐAÑBÔBÐBàÐÝÐDÑEÔEÐEà�%ˆ<ˆ<ÝÐWÑXÔXÐXà&+ˆŒØ*/¯,ª,°wÑ*?Ô*?ˆÔØ-5¯_ª_¸WÑ-EÔ-EˆÔà!$ˆÔØˆÔØ/1ˆŒØ!+ˆÔà,.ˆÔÐÐr#   ÚmethodÚurlÚbodyr#   c           
   ƒ   óÞ	  ‡"‡#K  — | j         }d|vrt          d¦  «        ‚d|vrt          d¦  «        ‚|d         }|d         }|st          d¦  «        ‚|                     dd¦  «        }|                     dd	¦  «        }|                     ¦   «         }	|                     d
d¦  «        }
|                     d¦  «        }|                     d¦  «        }t          |¦  «        j        }d}d}|reddh                     d„ |                     d¦  «        D ¦   «         ¦  «        }|st          d|› �¦  «        ‚d|v rdnd}|                     d¦  «        }|	t          vr-t          d|	› dd 
                    t          ¦  «        › �¦  «        ‚t          |	         Š#dt          dt          fˆ#fd„Š"dt          dt          dt          fˆ"fd„}d 
                    | j        || j        f¦  «        }|                     ¦   «         › d|› �                     ¦   «         }|dk    rTt          |t           ¦  «        r|                     ¦   «         ƒ d{V —†}n|} ‰"|¦  «        }d 
                    ||f¦  «        } ‰"|¦  «        } ‰"|¦  «        }|| j        k    r| xj        dz  c_        nd| _        || _        | j        d›}|                     d¦  «        }t)          j        d 
                    t-          | j        ¦  «                             d¦  «        |t/          j        ¦   «                              d¦  «        t3          j        d ¦  «        g¦  «        ¦  «                             ¦   «         dd!…         }|                     d¦  «        }|	                     ¦   «                              d"¦  «        r! ‰"d 
                    |||f¦  «        ¦  «        }|r'd 
                    |||||f¦  «        } |||¦  «        }n! ||d 
                    ||f¦  «        ¦  «        }t;          | j        ¦  «        t;          |¦  «        t;          |¦  «        ||                     ¦   «         |d#œ}|
rt;          |
¦  «        |d
<   |r||d<   ||d$<   ||d%<   g }|                      ¦   «         D ]D\  } }!| tB          v r| "                    | › d&|!› d'�¦  «         Œ*| "                    | › d(|!› �¦  «         ŒEd)d 
                    |¦  «        › �S )*aÕ  
        Build digest authorization header for the current challenge.

        Args:
            method: The HTTP method (GET, POST, etc.)
            url: The request URL
            body: The request body (used for qop=auth-int)

        Returns:
            A fully formatted Digest authorization header string

        Raises:
            ClientError: If the challenge is missing required parameters or
                         contains unsupported values

        r   z:Malformed Digest auth challenge: Missing 'realm' parameterr   z:Malformed Digest auth challenge: Missing 'nonce' parameterzBSecurity issue: Digest auth challenge contains empty 'nonce' valuer   Ú r   r&   r   rS   r#   Úauthzauth-intc                 ó^   — h | ]*}|                      ¦   «         ¯|                      ¦   «         ’Œ+S r"   )rB   )rC   Úqs     r$   ú	<setcomp>z/DigestAuthMiddleware._encode.<locals>.<setcomp>  s-   € ÐDÐDÐD˜q¸!¿'º'¹)¼)ÐD�—’‘”ÐDÐDÐDr#   Ú,zEDigest auth error: Unsupported Quality of Protection (qop) value(s): z/Digest auth error: Unsupported hash algorithm: z. Supported algorithms: z, Úxr5   c                 ób   •—  ‰| ¦  «                              ¦   «                              ¦   «         S )z<RFC 7616 Section 3: Hash function H(data) = hex(hash(data)).)Ú	hexdigestrV   )rj   Úhash_fns    €r$   ÚHz'DigestAuthMiddleware._encode.<locals>.H  s)   ø€ à�7˜1‘:”:×'Ò'Ñ)Ô)×0Ò0Ñ2Ô2Ð2r#   ÚsÚdc                 óD   •—  ‰d                      | |f¦  «        ¦  «        S )zDRFC 7616 Section 3: KD(secret, data) = H(concat(secret, ":", data)).ó   :)Újoin)ro   rp   rn   s     €r$   ÚKDz(DigestAuthMiddleware._encode.<locals>.KD   s#   ø€ à�1�T—Y’Y  1˜vÑ&Ô&Ñ'Ô'Ð'r#   rr   rR   Nr   Ú08xé   é   z-SESS)r2   r   r   r/   r1   r   Úncr0   z="r7   Ú=zDigest )#r[   r   ÚgetÚupperrV   r   Úpath_qsÚintersectionÚsplitr*   rs   r.   ÚbytesrW   rX   Ú
isinstancer   Úas_bytesrY   rZ   ÚhashlibÚsha1r    ÚtimeÚctimeÚosÚurandomrl   Úendswithr<   rU   ÚdecodeÚitemsr3   Úappend)$r^   r`   ra   rb   Ú	challenger   r   Úqop_rawÚalgorithm_originalr   r   Únonce_bytesÚrealm_bytesÚpathr   Ú	qop_bytesÚ
valid_qopsrt   ÚA1ÚA2Úentity_bytesÚentity_hashÚHA1ÚHA2ÚncvalueÚncvalue_bytesr0   Úcnonce_bytesÚnoncebitÚresponse_digestÚheader_fieldsÚpairsÚfieldr4   rn   rm   s$                                     @@r$   Ú_encodezDigestAuthMiddleware._encodeÓ   sÏ  øøè è € ð& ”Oˆ	Ø˜)Ð#Ð#ÝØLñô ð ð ˜)Ð#Ð#ÝØLñô ð ð
 ˜'Ô"ˆØ˜'Ô"ˆð ð 	ÝØTñô ð ð —-’-  rÑ*Ô*ˆà&Ÿ]š]¨;¸Ñ>Ô>ÐØ&×,Ò,Ñ.Ô.ˆ	Ø—’˜x¨Ñ,Ô,ˆð —l’l 7Ñ+Ô+ˆØ—l’l 7Ñ+Ô+ˆÝ�3‰xŒxÔˆð ˆØˆ	Øð 
	,Ø  *Ð-×:Ò:ØDÐD G§M¢M°#Ñ$6Ô$6ÐDÑDÔDñô ˆJð ð Ý!ØeÐ\cÐeÐeñô ð ð !+¨jÐ 8Ð 8�*�*¸fˆCØŸ
š
 7Ñ+Ô+ˆIà�OÐ+Ð+ÝðKÀ)ð Kð KØ)-¯ªÕ3GÑ)HÔ)HðKð Kñô ð õ )¨Ô3ˆð	3•ð 	3�5ð 	3ð 	3ð 	3ð 	3ð 	3ð 	3ð	(•%ð 	(�Eð 	(¥eð 	(ð 	(ð 	(ð 	(ð 	(ð 	(ð
 �YŠY˜Ô)¨;¸Ô8LÐMÑNÔNˆØ—’‘”Ð'Ð' Ð'Ð'×.Ò.Ñ0Ô0ˆØ�*ÒÐÝ˜$¥Ñ(Ô(ð $Ø%)§]¢]¡_¤_Ð4Ð4Ð4Ð4Ð4Ð4��à#�Ø˜!˜L™/œ/ˆKØ—’˜B Ð,Ñ-Ô-ˆBàˆa�‰eŒeˆØˆa�‰eŒeˆð ˜$Ô0Ò0Ð0ØÐÔ Ñ"ÐÔÐà !ˆDÔà!,ˆÔØÔ&Ð,Ð,ˆØŸš wÑ/Ô/ˆõ ”Ø�HŠHå˜Ô)Ñ*Ô*×1Ò1°'Ñ:Ô:ØÝ”J‘L”L×'Ò'¨Ñ0Ô0Ý”J˜q‘M”Mð	ñô ñ	
ô 	
÷ Š)‰+Œ+�c�r�cô	ˆð —}’} WÑ-Ô-ˆð �?Š?ÑÔ×%Ò% gÑ.Ô.ð 	AØ�!�D—I’I˜s K°Ð>Ñ?Ô?Ñ@Ô@ˆCð ð 	EØ—y’yØ˜m¨\¸9ÀcÐJñô ˆHð !˜b  hÑ/Ô/ˆOˆOà ˜b  d§i¢i°¸cÐ0BÑ&CÔ&CÑDÔDˆOõ & d¤oÑ6Ô6Ý" 5Ñ)Ô)Ý" 5Ñ)Ô)ØØ'×.Ò.Ñ0Ô0Ø+ð
ð 
ˆð ð 	<Ý&3°FÑ&;Ô&;ˆM˜(Ñ#ð ð 	-Ø#&ˆM˜%Ñ Ø")ˆM˜$ÑØ&,ˆM˜(Ñ#ð ˆØ)×/Ò/Ñ1Ô1ð 	1ð 	1‰LˆE�5ØÕ*Ð*Ð*Ø—’ Ð1Ð1¨Ð1Ð1Ð1Ñ2Ô2Ð2Ð2à—’ Ð/Ð/¨Ð/Ð/Ñ0Ô0Ð0Ð0à+˜Ÿš 5Ñ)Ô)Ð+Ð+Ð+r#   c                 óú   — t          |¦  «        }| j        D ]c}|                     |¦  «        sŒt          |¦  «        t          |¦  «        k    s|d         dk    r dS |t          |¦  «                 dk    r dS ŒddS )zô
        Check if the given URL is within the current protection space.

        According to RFC 7616, a URI is in the protection space if any URI
        in the protection space is a prefix of it (after both have been made absolute).
        éÿÿÿÿú/TF)r    r]   Ú
startswithÚlen)r^   ra   Úrequest_strÚ	space_strs       r$   Ú_in_protection_spacez)DigestAuthMiddleware._in_protection_spacev  s�   € õ ˜#‘h”hˆØÔ/ð 		ð 		ˆIà×)Ò)¨)Ñ4Ô4ð Øå�;ÑÔ¥3 y¡>¤>Ò1Ð1°Y¸r´]ÀcÒ5IÐ5IØ�t�tà�3˜y™>œ>Ô*¨cÒ1Ð1Ø�t�tð 2àˆur#   r1   c           
      ó   — |j         dk    rdS |j                             dd¦  «        }|sdS |                     d¦  «        \  }}}|sdS |                     ¦   «         dk    rdS |sdS t          |¦  «        x}sdS i | _        t          D ]#}|                     |¦  «        x}r
|| j        |<   Œ$|j         	                    ¦   «         }	| j                             d¦  «        x}
rÅg | _
        |
                     ¦   «         D ]¨}|                     d¦  «        }|                     d	¦  «        rH| j
                             t          |	                     t#          |¦  «        ¦  «        ¦  «        ¦  «         Œt| j
                             t          t#          |¦  «        ¦  «        ¦  «         Œ©nt          |	¦  «        g| _
        t%          | j        ¦  «        S )
zŠ
        Takes the given response and tries digest-auth, if needed.

        Returns true if the original request must be resent.
        i‘  Fzwww-authenticaterd   Ú Údigestr   r7   r¥   )ÚstatusÚheadersrz   Ú	partitionÚlowerrK   r[   r-   ra   Úoriginr]   r~   rB   r¦   r‹   r    rs   r   Úbool)r^   r1   Úauth_headerr`   Úsepr¯   Úheader_pairsr¡   r4   r²   r   r/   s               r$   Ú_authenticatez"DigestAuthMiddleware._authenticateŠ  sá  € ð Œ?˜cÒ!Ð!Ø�5àÔ&×*Ò*Ð+=¸rÑBÔBˆØð 	Ø�5à*×4Ò4°SÑ9Ô9Ñˆ��WØð 	à�5à�<Š<‰>Œ>˜XÒ%Ð%à�5àð 	à�5õ !3°7Ñ ;Ô ;Ð;�ð 	à�5ð ˆŒÝ%ð 	/ð 	/ˆEØ$×(Ò(¨Ñ/Ô/Ð/ˆuð /Ø).�” Ñ&øð ”×$Ò$Ñ&Ô&ˆà”_×(Ò(¨Ñ2Ô2Ð2ˆ6ð 	3à%'ˆDÔ"Ø—|’|‘~”~ð Að A�à—i’i ‘n”n�Ø—>’> #Ñ&Ô&ð AàÔ*×1Ò1µ#°f·k²kÅ#ÀcÁ(Ä(Ñ6KÔ6KÑ2LÔ2LÑMÔMÐMÐMð Ô*×1Ò1µ#µc¸#±h´h±-´-Ñ@Ô@Ð@Ð@ðAõ '*¨&¡k¤k ]ˆDÔ"õ �D”OÑ$Ô$Ð$r#   ÚrequestÚhandlerc              ƒ   ób  K  — d}t          d¦  «        D ]–}|dk    s(| j        r_| j        rX|                      |j        ¦  «        r>|                      |j        |j        |j        ¦  «        ƒ d{V —†|j        t          j
        <    ||¦  «        ƒ d{V —†}|                      |¦  «        s nŒ—|€J ‚|S )zRun the digest auth middleware.Né   r   )Úranger\   r[   rª   ra   r¢   r`   rb   r¯   r   ÚAUTHORIZATIONr·   )r^   r¸   r¹   r1   Úretry_counts        r$   Ú__call__zDigestAuthMiddleware.__call__Å  sÿ   è è € ð ˆÝ  ™8œ8ð 	ð 	ˆKð ˜QŠˆØÔ ð à”Oð ð ×-Ò-¨g¬kÑ:Ô:ð ð
 =A¿LºLØ”N G¤K°´ñ=ô =ð 7ð 7ð 7ð 7ð 7ð 7�”¥Ô 2Ñ3ð
 %˜W WÑ-Ô-Ð-Ð-Ð-Ð-Ð-Ð-ˆHð ×%Ò% hÑ/Ô/ð Ø�ðð Ð#Ð#Ð#Øˆr#   )T)r   r   r   Ú__doc__r    r³   r_   r   r   r   r   r¢   rª   r   r·   r   r   r¿   r"   r#   r$   rM   rM   š   s  € € € € € ðð ðD  ð	/ð /àð/ð ð/ð ð	/ð
 
ð/ð /ð /ð /ð4a,Øða,Ø #ða,Ø+0°¸'À#¼,Ð1FÔ+Gða,à	ða,ð a,ð a,ð a,ðF¨ð °ð ð ð ð ð(9% nð 9%¸ð 9%ð 9%ð 9%ð 9%ðvØ$ðØ/@ðà	ðð ð ð ð ð r#   rM   )4rÀ   r‚   r†   ÚreÚsysr„   Útypingr   r   r   r   r   r   r	   r
   r   Úyarlr   rd   r   Úclient_exceptionsr   Úclient_middlewaresr   Úclient_reqrepr   r   Úpayloadr   r   Úmd5rƒ   Úsha256Úsha512r*   r    r   r!   ÚcompileÚversion_inforI   r-   ÚtupleÚsortedÚkeysr.   Ú	frozensetr3   r<   r>   rK   rM   r"   r#   r$   ú<module>rÒ      sQ  ððð ð ð €€€Ø 	€	€	€	Ø 	€	€	€	Ø 
€
€
€
Ø €€€ð
ð 
ð 
ð 
ð 
ð 
ð 
ð 
ð 
ð 
ð 
ð 
ð 
ð 
ð 
ð 
ð 
ð 
ð 
ð 
ð 
ð 
ð Ð Ð Ð Ð Ð à Ð Ð Ð Ð Ð Ø *Ð *Ð *Ð *Ð *Ð *Ø 1Ð 1Ð 1Ð 1Ð 1Ð 1Ø 8Ð 8Ð 8Ð 8Ð 8Ð 8Ð 8Ð 8Ø Ð Ð Ð Ð Ð ðð ð ð ð ˜)¨5ð ñ ô ð ð Œ;Ø”ØŒ<Ø”ØŒnØ”>ØŒ~Ø”NØŒnØ”>ØŒ~Ø”NðBð B€��c˜8 U G¨_Ð$<Ô=Ð=Ô>ð ð ñ ð" #˜œ
à
Ô˜'Ò!Ð!ð BÐAà	Jñô Ð ð<ð	 �%Ø	ØÐQÔRÐTWÐWôôð ð ñ ð  05¨u°V°V¸O×<PÒ<PÑ<RÔ<RÑ5SÔ5SÑ/TÔ/TÐ �e˜E # s (œOÔ,Ð TÐ TÑ Tð -6¨IØIÐIÐIñ-ô -Ð �E˜) Cœ.Ô)ð ð ñ ð
%˜ð % ð %ð %ð %ð %ð
%˜3ð % 3ð %ð %ð %ð %ð
˜sð  t¨C°¨H¤~ð ð ð ð ð6Fð Fð Fð Fð Fñ Fô Fð Fð Fð Fr#   