Ë
    5¾ªj“2  ã                  óÂ   — d Z ddlmZ dgZddlmZmZmZmZ ddl	m
Z
mZmZ ddlmZmZmZmZmZmZmZ ddlmZ d	d
lmZ d	dlmZmZ d	dlmZ erd	dlmZ  G d„ d«      Zy)z6Implementing support for MySQL Authentication Plugins.é    )ÚannotationsÚMySQLAuthenticator)ÚTYPE_CHECKINGÚAnyÚDictÚOptionalé   )ÚInterfaceErrorÚNotSupportedErrorÚget_exception)ÚAUTH_SWITCH_STATUSÚDEFAULT_CHARSET_IDÚDEFAULT_MAX_ALLOWED_PACKETÚ
ERR_STATUSÚEXCHANGE_FURTHER_STATUSÚ
MFA_STATUSÚ	OK_STATUS)ÚHandShakeTypeé   )Úlogger)ÚMySQLAuthPluginÚget_auth_plugin)ÚMySQLProtocol)ÚMySQLSocketc                  óü   — e Zd ZdZdd„Zedd„«       Zedd„«       Zdd„Z	 	 	 d	 	 	 	 	 	 	 	 	 dd„Z		 	 	 	 	 	 dd„Z
	 	 	 	 	 	 dd	„Zd
d
d
d
deddeddddddf	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 	 dd„Zy)r   z$Implements the authentication phase.c                óX   — d| _         i | _        i | _        d| _        d| _        d| _        y)zConstructor.Ú FN)Ú	_usernameÚ
_passwordsÚ_plugin_configÚ_ssl_enabledÚ_auth_strategyÚ_auth_plugin_class©Úselfs    úa/var/www/html/serviGia/entorno/lib/python3.12/site-packages/mysql/connector/aio/authentication.pyÚ__init__zMySQLAuthenticator.__init__;   s0   € à ˆŒØ*,ˆŒØ.0ˆÔØ"'ˆÔØ9=ˆÔØ15ˆÕó    c                ó   — | j                   S )z&Signals whether or not SSL is enabled.)r!   r$   s    r&   Ússl_enabledzMySQLAuthenticator.ssl_enabledD   s   € ð × Ñ Ð r(   c                ó   — | j                   S )aö  Custom arguments that are being provided to the authentication plugin.

        The parameters defined here will override the ones defined in the
        auth plugin itself.

        The plugin config is a read-only property - the plugin configuration
        provided when invoking `authenticate()` is recorded and can be queried
        by accessing this property.

        Returns:
            dict: The latest plugin configuration provided when invoking
                  `authenticate()`.
        )r    r$   s    r&   Úplugin_configz MySQLAuthenticator.plugin_configI   s   € ð ×"Ñ"Ð"r(   c                ó:   — | j                   j                  |«       y)z,Update the 'plugin_config' instance variableN)r    Úupdate)r%   Úconfigs     r&   Úupdate_plugin_configz'MySQLAuthenticator.update_plugin_configZ   s   € à×Ñ×"Ñ" 6Õ*r(   Nc                óæ   — |€| j                   }|€| j                  }t        j                  d|«        t	        ||¬«      || j
                  j                  |d«      | j                  ¬«      | _        y)a¬  Switch the authorization plugin.

        Args:
            new_strategy_name: New authorization plugin name to switch to.
            strategy_class: New authorization plugin class to switch to
                            (has higher precedence than the authorization plugin name).
            username: Username to be used - if not defined, the username
                      provided when `authentication()` was invoked is used.
            password_factor: Up to three levels of authentication (MFA) are allowed,
                             hence you can choose the password corresponding to the 1st,
                             2nd, or 3rd factor - 1st is the default.
        NzSwitching to strategy %s)Úplugin_nameÚauth_plugin_classr   )r*   )	r   r#   r   Údebugr   r   Úgetr*   r"   )r%   Únew_strategy_nameÚstrategy_classÚusernameÚpassword_factors        r&   Ú_switch_auth_strategyz(MySQLAuthenticator._switch_auth_strategy^   sq   € ð& ÐØ—~‘~ˆHàÐ!Ø!×4Ñ4ˆNä�‰Ð/Ð1BÔCð
œoØ)¸^ô
ð Ø�O‰O×Ñ °Ó4Ø×(Ñ(ô
ˆÕr(   c              ƒ  óÖ  K  — d}|d   t         k(  �r=|| j                  vrt        d«      ‚t        j                  |«      \  }}| j                  ||¬«       t        j                  d|| j                  j                  «        | j                  j                  ||fi | j                  ¤Žƒ d{  –—† }|d   t        k(  rEt        j                  |«      } | j                  j                  ||fi | j                  ¤Žƒ d{  –—† }|d   t        k(  rt        j                  d«       |S |d   t         k(  rt#        |«      ‚|dz  }|d   t         k(  r�Œ=t        j$                  d	«       y7 Œ¸7 Œi­w)
a  Handle MFA (Multi-Factor Authentication) response.

        Up to three levels of authentication (MFA) are allowed.

        Args:
            sock: Pointer to the socket connection.
            pkt: MFA response.

        Returns:
            ok_packet: If last server's response is an OK packet.
            None: If last server's response isn't an OK packet and no ERROR was raised.

        Raises:
            InterfaceError: If got an invalid N factor.
            errors.ErrorTypes: If got an ERROR response.
        r	   é   z5Failed Multi Factor Authentication (invalid N factor))r9   zMFA %i factor %sNzMFA completed succesfullyr   z"MFA terminated with a no ok packet)r   r   r
   r   Úparse_auth_next_factorr:   r   r4   r"   ÚnameÚauth_switch_responser    r   Úparse_auth_more_dataÚauth_more_responser   r   r   Úwarning)r%   ÚsockÚpktÚn_factorr6   Ú	auth_datas         r&   Ú_mfa_n_factorz MySQLAuthenticator._mfa_n_factor€   si  è ø€ ð* ˆØ�!‰fœ
Ó"Ø˜tŸ™Ñ.Ü$ØKóð ô ,9×+OÑ+OÐPSÓ+TÑ(Ð˜yØ×&Ñ&Ð'8È(Ð&ÔSÜ�L‰LÐ+¨X°t×7JÑ7J×7OÑ7OÔPà@˜×+Ñ+×@Ñ@Ø�iñØ#'×#6Ñ#6ñ÷ ˆCð �1‰vÔ0Ò0Ü)×>Ñ>¸sÓC�	ØB˜D×/Ñ/×BÑBØ˜)ñØ'+×':Ñ':ñ÷ �ð �1‰vœÒ"Ü—‘Ð8Ô9Ø�
à�1‰vœÒ#Ü# CÓ(Ð(à˜‰MˆHð7 �!‰fœ
Ô"ô: 	�‰Ð;Ô<Øð)øðús,   ‚B*E)Â,E%Â-AE)Ã=E'Ã>AE)ÅE)Å'E)c              ƒ  óŒ  K  — |d   t         k(  rt        |«      dk(  rt        d«      ‚|d   t         k(  rnt        j                  d«       t        j                  |«      \  }}| j                  |«        | j                  j                  ||fi | j                  ¤Žƒ d{  –—† }|d   t        k(  rZt        j                  d«       t        j                  |«      } | j                  j                  ||fi | j                  ¤Žƒ d{  –—† }|d   t        k(  r,t        j                  d| j                  j                  «       |S |d   t         k(  rYt        j                  d«       t        j                  d	| j                  j                  «       | j#                  ||«      ƒ d{  –—† S |d   t$        k(  rt'        |«      ‚y7 �Œ 7 Œ¼7 Œ!­w)
aü  Handle server's response.

        Args:
            sock: Pointer to the socket connection.
            pkt: Server's response after completing the `HandShakeResponse`.

        Returns:
            ok_packet: If last server's response is an OK packet.
            None: If last server's response isn't an OK packet and no ERROR was raised.

        Raises:
            errors.ErrorTypes: If got an ERROR response.
            NotSupportedError: If got Authentication with old (insecure) passwords.
        r<   é   z‡Authentication with old (insecure) passwords is not supported. For more information, lookup Password Hashing in the latest MySQL manualz+Server's response is an auth switch requestNzExchanging further packetsz%s completed succesfullyz$Starting multi-factor authenticationzMFA 1 factor %s)r   Úlenr   r   r4   r   Úparse_auth_switch_requestr:   r"   r?   r    r   r@   rA   r   r>   r   rG   r   r   )r%   rC   rD   r6   rF   s        r&   Ú_handle_server_responsez*MySQLAuthenticator._handle_server_response¶   s¢  è ø€ ð& ˆq‰6Ô'Ò'¬C°«H¸ªMÜ#ð>óð ð ˆq‰6Ô'Ò'Ü�L‰LÐFÔGÜ+8×+RÑ+RÐSVÓ+WÑ(Ð˜yØ×&Ñ&Ð'8Ô9Ø@˜×+Ñ+×@Ñ@Ø�iñØ#'×#6Ñ#6ñ÷ ˆCð ˆq‰6Ô,Ò,Ü�L‰LÐ5Ô6Ü%×:Ñ:¸3Ó?ˆIØ>˜×+Ñ+×>Ñ>Ø�iñØ#'×#6Ñ#6ñ÷ ˆCð ˆq‰6”YÒÜ�L‰LÐ3°T×5HÑ5H×5MÑ5MÔNØˆJàˆq‰6”ZÒÜ�L‰LÐ?Ô@Ü�L‰LÐ*¨D×,?Ñ,?×,DÑ,DÔEØ×+Ñ+¨D°#Ó6×6Ð6àˆq‰6”ZÒÜ Ó$Ð$àð/ùðøð 7ús8   ‚BGÂF=ÂA%GÄG ÄBGÆ GÆ!GÇ GÇGr   r   Fc              ƒ  ó¸  K  — || _         |||dœ| _        |
| _        || _        t	        j
                  ||||||	|||||| j                  | j                  ¬«      \  }| _        |rdd|fndd|f} |j                  |g|¢­Ž ƒ d{  –—†  t        |j                  |«      ƒ d{  –—† «      }| j                  ||«      ƒ d{  –—† }|€t        d«      d‚|S 7 ŒP7 Œ47 Œ­w)aä  Perform the authentication phase.

        During re-authentication you must set `is_change_user_request` to True.

        Args:
            sock: Pointer to the socket connection.
            handshake: Initial handshake.
            username: Account's username.
            password1: Account's password factor 1.
            password2: Account's password factor 2.
            password3: Account's password factor 3.
            database: Initial database name for the connection.
            charset: Client charset (see [1]), only the lower 8-bits.
            client_flags: Integer representing client capabilities flags.
            ssl_enabled: Boolean indicating whether SSL is enabled,
            max_allowed_packet: Maximum packet size.
            auth_plugin: Authorization plugin name.
            auth_plugin_class: Authorization plugin class (has higher precedence
                               than the authorization plugin name).
            conn_attrs: Connection attributes.
            is_change_user_request: Whether is a `change user request` operation or not.
            read_timeout: Timeout in seconds upto which the connector should wait for
                          the server to reply back before raising an ReadTimeoutError.
            write_timeout: Timeout in seconds upto which the connector should spend to
                           send data to the server before raising an WriteTimeoutError.

        Returns:
            ok_packet: OK packet.

        Raises:
            InterfaceError: If OK packet is NULL.
            ReadTimeoutError: If the time taken for the server to reply back exceeds
                              'read_timeout' (if set).
            WriteTimeoutError: If the time taken to send data packets to the server
                               exceeds 'write_timeout' (if set).

        References:
            [1]: https://dev.mysql.com/doc/dev/mysql-server/latest/                page_protocol_basic_character_set.html#a_protocol_character_set
        )r   r	   é   )Ú	handshaker8   ÚpasswordÚdatabaseÚcharsetÚclient_flagsÚmax_allowed_packetÚauth_pluginr3   Ú
conn_attrsÚis_change_user_requestr*   r,   r   NzGot a NULL ok_pkt)r   r   r!   r#   r   Ú	make_authr*   r,   r"   ÚwriteÚbytesÚreadrL   r
   )r%   rC   rO   r8   Ú	password1Ú	password2Ú	password3rQ   rR   rS   r*   rT   rU   r3   rV   rW   Úread_timeoutÚwrite_timeoutÚresponse_payloadÚ	send_argsrD   Úok_pkts                         r&   ÚauthenticatezMySQLAuthenticator.authenticateí   s  è ø€ ðz "ˆŒØ'¨I¸)ÑDˆŒØ'ˆÔØ"3ˆÔô 1>×0GÑ0GØØØØØØ%Ø1Ø#Ø/Ø!Ø#9Ø×(Ñ(Ø×,Ñ,ô1
Ñ-Ð˜$Ô-ñ& &ð ��=Ñ!à˜˜mÐ,ð 	ð
 ˆd�j‰jÐ)Ð6¨IÒ6×6Ð6ô ˜$Ÿ)™) LÓ1×1Ó2ˆà×3Ñ3°D¸#Ó>×>ˆØˆ>Ü Ð!4Ó5¸4Ð?àˆð 	7øð 2øà>ús6   ‚BCÂCÂCÂ!CÂ"CÂ?CÃ CÃCÃC)ÚreturnÚNone)re   Úbool)re   úDict[str, Any])r/   rh   re   rf   )NNr   )
r6   Ústrr7   úOptional[str]r8   rj   r9   Úintre   rf   )rC   r   rD   rZ   re   zOptional[bytes])$rC   r   rO   r   r8   ri   r\   ri   r]   ri   r^   ri   rQ   rj   rR   rk   rS   rk   r*   rg   rT   rk   rU   rj   r3   rj   rV   zOptional[Dict[str, str]]rW   rg   r_   úOptional[int]r`   rl   re   rZ   )Ú__name__Ú
__module__Ú__qualname__Ú__doc__r'   Úpropertyr*   r,   r0   r:   rG   rL   r   r   rd   © r(   r&   r   r   8   sµ  „ Ù.ó6ð ò!ó ð!ð ò#ó ð#ó +ð )-Ø"&Ø ð 
àð 
ð &ð 
ð  ð	 
ð
 ð 
ð 
ó 
ðD4àð4ð ð4ð 
ó	4ðl5àð5ð ð5ð 
ó	5ðv ØØØØ"&Ø)ØØ!Ø"<Ø%)Ø+/Ø/3Ø',Ø&*Ø'+ð%bàðbð !ðbð ð	bð
 ðbð ðbð ðbð  ðbð ðbð ðbð ðbð  ðbð #ðbð )ðbð -ðbð  !%ð!bð" $ð#bð$ %ð%bð& 
ô'br(   N)rp   Ú
__future__r   Ú__all__Útypingr   r   r   r   Úerrorsr
   r   r   Úprotocolr   r   r   r   r   r   r   Útypesr   r   Úpluginsr   r   r   Únetworkr   r   rr   r(   r&   ú<module>r{      sP   ðñ: =å "àÐ
 €ç 5Ó 5ç EÑ E÷÷ ñ õ "Ý ß 5Ý #áÝ$÷Wò Wr(   