Ë
    5¾ªj­9  ã                  ó´   — d Z ddlmZ ddlmZmZmZmZ ddlm	Z	m
Z
mZ ddlmZ ddlmZmZ ddlmZmZmZmZmZmZmZmZ dd	lmZ erdd
lmZ  G d„ d«      Zy)z5Implementing support for MySQL Authentication Pluginsé    )Úannotations)ÚTYPE_CHECKINGÚAnyÚDictÚOptionalé   )ÚInterfaceErrorÚNotSupportedErrorÚget_exception)Úlogger)ÚMySQLAuthPluginÚget_auth_plugin)ÚAUTH_SWITCH_STATUSÚDEFAULT_CHARSET_IDÚDEFAULT_MAX_ALLOWED_PACKETÚ
ERR_STATUSÚEXCHANGE_FURTHER_STATUSÚ
MFA_STATUSÚ	OK_STATUSÚMySQLProtocol)ÚHandShakeType)ÚMySQLSocketc                  ó   — e Zd ZdZdd„Zedd„«       Zedd„«       Zdd„Ze	de
f	 	 	 	 	 	 	 	 	 	 	 	 	 dd„Z	 	 	 d	 	 	 	 	 	 	 	 	 dd	„Z	 	 	 	 	 	 dd
„Z	 	 	 	 	 	 dd„Zddddde	de
ddddddf	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 dd„Zy)ÚMySQLAuthenticatorz$Implements the authentication phase.c                óX   — d| _         i | _        i | _        d| _        d| _        d| _        y)zConstructor.Ú FN)Ú	_usernameÚ
_passwordsÚ_plugin_configÚ_ssl_enabledÚ_auth_strategyÚ_auth_plugin_class©Úselfs    ú]/var/www/html/serviGia/entorno/lib/python3.12/site-packages/mysql/connector/authentication.pyÚ__init__zMySQLAuthenticator.__init__8   s0   € à ˆŒØ*,ˆŒØ.0ˆÔØ"'ˆÔØ9=ˆÔØ15ˆÕó    c                ó   — | j                   S )z&Signals whether or not SSL is enabled.)r    r#   s    r%   Ússl_enabledzMySQLAuthenticator.ssl_enabledA   s   € ð × Ñ Ð r'   c                ó   — | j                   S )a  Custom arguments that are being provided to the authentication plugin when called.

        The parameters defined here will override the ones defined in the
        auth plugin itself.

        The plugin config is a read-only property - the plugin configuration
        provided when invoking `authenticate()` is recorded and can be queried
        by accessing this property.

        Returns:
            dict: The latest plugin configuration provided when invoking
                  `authenticate()`.
        )r   r#   s    r%   Úplugin_configz MySQLAuthenticator.plugin_configF   s   € ð ×"Ñ"Ð"r'   c                ó:   — | j                   j                  |«       y)z,Update the 'plugin_config' instance variableN)r   Úupdate)r$   Úconfigs     r%   Úupdate_plugin_configz'MySQLAuthenticator.update_plugin_configW   s   € à×Ñ×"Ñ" 6Õ*r'   r   c                ó  — |€i }t        j                  |||¬«      }|j                  |«       t        j                  d«       |j                  |j                  d«      |j                  d«      |j                  d«      |j                  dd«      |j                  dd«      |j                  d	«      |j                  d
«      ¬«      }t        j                  d«       |j                  ||«       t        j                  d«       d| _        |S )aã  Sets up an SSL communication channel.

        Args:
            sock: Pointer to the socket connection.
            host: Server host name.
            ssl_options: SSL and TLS connection options (see
                         `network.MySQLSocket.build_ssl_context`).
            charset: Client charset (see [1]), only the lower 8-bits.
            client_flags: Integer representing client capabilities flags.
            max_allowed_packet: Maximum packet size.

        Returns:
            ssl_request_payload: Payload used to carry out SSL authentication.

        References:
            [1]: https://dev.mysql.com/doc/dev/mysql-server/latest/                page_protocol_basic_character_set.html#a_protocol_character_set
        )ÚcharsetÚclient_flagsÚmax_allowed_packetzBuilding SSL contextÚcaÚcertÚkeyÚverify_certFÚverify_identityÚtls_versionsÚtls_ciphersuites)Ússl_caÚssl_certÚssl_keyÚssl_verify_certÚssl_verify_identityr9   Útls_cipher_suiteszSwitching to SSLzSSL has been enabledT)	r   Úmake_auth_sslÚsendr   ÚdebugÚbuild_ssl_contextÚgetÚswitch_to_sslr    )	r$   ÚsockÚhostÚssl_optionsr1   r2   r3   Ússl_request_payloadÚssl_contexts	            r%   Ú	setup_sslzMySQLAuthenticator.setup_ssl[   sð   € ð6 ÐØˆKô ,×9Ñ9ØØ%Ø1ô
Ðð
 	�	‰	Ð%Ô&ä�‰Ð+Ô,Ø×,Ñ,Ø—?‘? 4Ó(Ø —_‘_ VÓ,Ø—O‘O EÓ*Ø'ŸO™O¨M¸5ÓAØ +§¡Ð0AÀ5Ó IØ$Ÿ™¨Ó8Ø)Ÿo™oÐ.@ÓAð -ó 
ˆô 	�‰Ð'Ô(Ø×Ñ˜;¨Ô-ä�‰Ð+Ô,Ø ˆÔà"Ð"r'   Nc                óæ   — |€| j                   }|€| j                  }t        j                  d|«        t	        ||¬«      || j
                  j                  |d«      | j                  ¬«      | _        y)a®  Switches the authorization plugin.

        Args:
            new_strategy_name: New authorization plugin name to switch to.
            strategy_class: New authorization plugin class to switch to
                            (has higher precedence than the authorization plugin name).
            username: Username to be used - if not defined, the username
                      provided when `authentication()` was invoked is used.
            password_factor: Up to three levels of authentication (MFA) are allowed,
                             hence you can choose the password corresponding to the 1st,
                             2nd, or 3rd factor - 1st is the default.
        NzSwitching to strategy %s)Úplugin_nameÚauth_plugin_classr   )r)   )	r   r"   r   rC   r   r   rE   r)   r!   )r$   Únew_strategy_nameÚstrategy_classÚusernameÚpassword_factors        r%   Ú_switch_auth_strategyz(MySQLAuthenticator._switch_auth_strategy”   sq   € ð& ÐØ—~‘~ˆHàÐ!Ø!×4Ñ4ˆNä�‰Ð/Ð1BÔCð
œoØ)¸^ô
ð Ø�O‰O×Ñ °Ó4Ø×(Ñ(ô
ˆÕr'   c                ó¦  — d}|d   t         k(  �r-|| j                  vrt        d«      ‚t        j                  |«      \  }}| j                  ||¬«       t        j                  d|| j                  j                  «        | j                  j                  ||fi | j                  ¤Ž}|d   t        k(  r=t        j                  |«      } | j                  j                  ||fi | j                  ¤Ž}|d   t        k(  rt        j                  d«       |S |d   t         k(  rt#        |«      ‚|dz  }|d   t         k(  r�Œ-t        j$                  d«       y	)
a  Handles MFA (Multi-Factor Authentication) response.

        Up to three levels of authentication (MFA) are allowed.

        Args:
            sock: Pointer to the socket connection.
            pkt: MFA response.

        Returns:
            ok_packet: If last server's response is an OK packet.
            None: If last server's response isn't an OK packet and no ERROR was raised.

        Raises:
            InterfaceError: If got an invalid N factor.
            errors.ErrorTypes: If got an ERROR response.
        é   é   z5Failed Multi Factor Authentication (invalid N factor))rS   zMFA %i factor %szMFA completed succesfullyr   z"MFA terminated with a no ok packetN)r   r   r	   r   Úparse_auth_next_factorrT   r   rC   r!   ÚnameÚauth_switch_responser   r   Úparse_auth_more_dataÚauth_more_responser   r   r   Úwarning)r$   rG   ÚpktÚn_factorrP   Ú	auth_datas         r%   Ú_mfa_n_factorz MySQLAuthenticator._mfa_n_factor¶   sP  € ð* ˆØ�!‰fœ
Ó"Ø˜tŸ™Ñ.Ü$ØKóð ô ,9×+OÑ+OÐPSÓ+TÑ(Ð˜yØ×&Ñ&Ð'8È(Ð&ÔSÜ�L‰LÐ+¨X°t×7JÑ7J×7OÑ7OÔPà:�$×%Ñ%×:Ñ:Ø�iñØ#'×#6Ñ#6ñˆCð �1‰vÔ0Ò0Ü)×>Ñ>¸sÓC�	Ø<�d×)Ñ)×<Ñ<Ø˜)ñØ'+×':Ñ':ñ�ð �1‰vœÒ"Ü—‘Ð8Ô9Ø�
à�1‰vœÒ#Ü# CÓ(Ð(à˜‰MˆHð7 �!‰fœ
Ô"ô: 	�‰Ð;Ô<Ør'   c                óF  — |d   t         k(  rt        |«      dk(  rt        d«      ‚|d   t         k(  rft        j                  d«       t        j                  |«      \  }}| j                  |«        | j                  j                  ||fi | j                  ¤Ž}|d   t        k(  rRt        j                  d«       t        j                  |«      } | j                  j                  ||fi | j                  ¤Ž}|d   t        k(  r,t        j                  d| j                  j                  «       |S |d   t         k(  rQt        j                  d«       t        j                  d| j                  j                  «       | j#                  ||«      S |d   t$        k(  rt'        |«      ‚y	)
aý  Handles server's response.

        Args:
            sock: Pointer to the socket connection.
            pkt: Server's response after completing the `HandShakeResponse`.

        Returns:
            ok_packet: If last server's response is an OK packet.
            None: If last server's response isn't an OK packet and no ERROR was raised.

        Raises:
            errors.ErrorTypes: If got an ERROR response.
            NotSupportedError: If got Authentication with old (insecure) passwords.
        rW   é   z‡Authentication with old (insecure) passwords is not supported. For more information, lookup Password Hashing in the latest MySQL manualz+Server's response is an auth switch requestzExchanging further packetsz%s completed succesfullyz$Starting multi-factor authenticationzMFA 1 factor %sN)r   Úlenr
   r   rC   r   Úparse_auth_switch_requestrT   r!   rZ   r   r   r[   r\   r   rY   r   ra   r   r   )r$   rG   r^   rP   r`   s        r%   Ú_handle_server_responsez*MySQLAuthenticator._handle_server_responseì   s€  € ð& ˆq‰6Ô'Ò'¬C°«H¸ªMÜ#ð>óð ð ˆq‰6Ô'Ò'Ü�L‰LÐFÔGÜ+8×+RÑ+RÐSVÓ+WÑ(Ð˜yØ×&Ñ&Ð'8Ô9Ø:�$×%Ñ%×:Ñ:Ø�iñØ#'×#6Ñ#6ñˆCð ˆq‰6Ô,Ò,Ü�L‰LÐ5Ô6Ü%×:Ñ:¸3Ó?ˆIØ8�$×%Ñ%×8Ñ8Ø�iñØ#'×#6Ñ#6ñˆCð ˆq‰6”YÒÜ�L‰LÐ3°T×5HÑ5H×5MÑ5MÔNØˆJàˆq‰6”ZÒÜ�L‰LÐ?Ô@Ü�L‰LÐ*¨D×,?Ñ,?×,DÑ,DÔEØ×%Ñ% d¨CÓ0Ð0àˆq‰6”ZÒÜ Ó$Ð$àr'   r   Fc                óf  — || _         |||dœ| _        || _        t        j                  ||||||	|
||||| j
                  | j                  ¬«      \  }| _        |rdd|fndd|f} |j                  |g|¢­Ž  t        |j                  |«      «      }| j                  ||«      }|€t        d«      d‚|S )a   Performs the authentication phase.

        During re-authentication you must set `is_change_user_request` to True.

        Args:
            sock: Pointer to the socket connection.
            handshake: Initial handshake.
            username: Account's username.
            password1: Account's password factor 1.
            password2: Account's password factor 2.
            password3: Account's password factor 3.
            database: Initial database name for the connection.
            charset: Client charset (see [1]), only the lower 8-bits.
            client_flags: Integer representing client capabilities flags.
            max_allowed_packet: Maximum packet size.
            auth_plugin: Authorization plugin name.
            auth_plugin_class: Authorization plugin class (has higher precedence
                               than the authorization plugin name).
            conn_attrs: Connection attributes.
            is_change_user_request: Whether is a `change user request` operation or not.
            read_timeout: Timeout in seconds upto which the connector should wait for
                          the server to reply back before raising an ReadTimeoutError.
            write_timeout: Timeout in seconds upto which the connector should spend to
                           send data to the server before raising an WriteTimeoutError.
        Returns:
            ok_packet: OK packet.

        Raises:
            InterfaceError: If OK packet is NULL.
            ReadTimeoutError: If the time taken for the server to reply back exceeds
                              'read_timeout' (if set).
            WriteTimeoutError: If the time taken to send data packets to the server
                               exceeds 'write_timeout' (if set).

        References:
            [1]: https://dev.mysql.com/doc/dev/mysql-server/latest/                page_protocol_basic_character_set.html#a_protocol_character_set
        )r   rV   é   )Ú	handshakerR   ÚpasswordÚdatabaser1   r2   r3   Úauth_pluginrO   Ú
conn_attrsÚis_change_user_requestr)   r+   r   NzGot a NULL ok_pkt)r   r   r"   r   Ú	make_authr)   r+   r!   rB   ÚbytesÚrecvrf   r	   )r$   rG   ri   rR   Ú	password1Ú	password2Ú	password3rk   r1   r2   r3   rl   rO   rm   rn   Úread_timeoutÚwrite_timeoutÚresponse_payloadÚ	send_argsr^   Úok_pkts                        r%   ÚauthenticatezMySQLAuthenticator.authenticate#  så   € ðt "ˆŒØ'¨I¸)ÑDˆŒØ"3ˆÔô 1>×0GÑ0GØØØØØØ%Ø1Ø#Ø/Ø!Ø#9Ø×(Ñ(Ø×,Ñ,ô1
Ñ-Ð˜$Ô-ñ& &ð ��=Ñ!à˜˜mÐ,ð 	ð
 	ˆ�	‰	Ð"Ð/ YÓ/ô �D—I‘I˜lÓ+Ó,ˆà×-Ñ-¨d°CÓ8ˆØˆ>Ü Ð!4Ó5¸4Ð?àˆr'   )ÚreturnÚNone)r{   Úbool)r{   úDict[str, Any])r.   r~   r{   r|   )rG   r   rH   ÚstrrI   zOptional[Dict[str, Any]]r1   Úintr2   r€   r3   r€   r{   rp   )NNr   )
rP   r   rQ   úOptional[str]rR   r�   rS   r€   r{   r|   )rG   r   r^   rp   r{   zOptional[bytes])"rG   r   ri   r   rR   r   rr   r   rs   r   rt   r   rk   r�   r1   r€   r2   r€   r3   r€   rl   r�   rO   r�   rm   zOptional[Dict[str, str]]rn   r}   ru   úOptional[int]rv   r‚   r{   rp   )Ú__name__Ú
__module__Ú__qualname__Ú__doc__r&   Úpropertyr)   r+   r/   r   r   rL   rT   ra   rf   rz   © r'   r%   r   r   5   sü  „ Ù.ó6ð ò!ó ð!ð ò#ó ð#ó +ð *ØØ"<ð7#àð7#ð ð7#ð .ð	7#ð
 ð7#ð ð7#ð  ð7#ð 
ó7#ðx )-Ø"&Ø ð 
àð 
ð &ð 
ð  ð	 
ð
 ð 
ð 
ó 
ðD4àð4ð ð4ð 
ó	4ðl5àð5ð ð5ð 
ó	5ðv ØØØØ"&Ø)ØØ"<Ø%)Ø+/Ø/3Ø',Ø&*Ø'+ð#^àð^ð !ð^ð ð	^ð
 ð^ð ð^ð ð^ð  ð^ð ð^ð ð^ð  ð^ð #ð^ð )ð^ð -ð^ð !%ð^ð  $ð!^ð" %ð#^ð$ 
ô%^r'   r   N)r†   Ú
__future__r   Útypingr   r   r   r   Úerrorsr	   r
   r   r   Úpluginsr   r   Úprotocolr   r   r   r   r   r   r   r   Útypesr   Únetworkr   r   rˆ   r'   r%   ú<module>r�      sE   ðñ: <Ý "ç 5Ó 5ç DÑ DÝ ß 5÷	÷ 	ó 	õ !áÝ$÷Lò Lr'   