ó
    ßÅŸg“2  ã                  óÌ   • S r SSKJr  S/rSSKJrJrJrJr  SSK	J
r
JrJr  SSKJrJrJrJrJrJrJr  SSKJr  S	S
KJr  S	SKJrJr  S	SKJr  \(       a  S	SKJr   " S S5      rg)z6Implementing support for MySQL Authentication Plugins.é    )ÚannotationsÚMySQLAuthenticator)ÚTYPE_CHECKINGÚAnyÚDictÚOptionalé   )ÚInterfaceErrorÚNotSupportedErrorÚget_exception)ÚAUTH_SWITCH_STATUSÚDEFAULT_CHARSET_IDÚDEFAULT_MAX_ALLOWED_PACKETÚ
ERR_STATUSÚEXCHANGE_FURTHER_STATUSÚ
MFA_STATUSÚ	OK_STATUS)ÚHandShakeTypeé   )Úlogger)ÚMySQLAuthPluginÚget_auth_plugin)ÚMySQLProtocol)ÚMySQLSocketc                  ó  • \ rS rSrSrSS jr\SS j5       r\SS j5       rSS jr	   S         SS jjr
      SS	 jr      SS
 jrSSSSS\SS\SSSSSS4                                   SS jjrSrg)r   é8   z$Implements the authentication phase.c                óX   • SU l         0 U l        0 U l        SU l        SU l        SU l        g)zConstructor.Ú FN)Ú	_usernameÚ
_passwordsÚ_plugin_configÚ_ssl_enabledÚ_auth_strategyÚ_auth_plugin_class©Úselfs    Úc/var/www/blue/EV-Temp_rev04/venv/lib/python3.13/site-packages/mysql/connector/aio/authentication.pyÚ__init__ÚMySQLAuthenticator.__init__;   s0   € à ˆŒØ*,ˆŒØ.0ˆÔØ"'ˆÔØ9=ˆÔØ15ˆÕó    c                ó   • U R                   $ )z&Signals whether or not SSL is enabled.)r"   r%   s    r'   Ússl_enabledÚMySQLAuthenticator.ssl_enabledD   s   € ð × Ñ Ð r*   c                ó   • U R                   $ )a®  Custom arguments that are being provided to the authentication plugin.

The parameters defined here will override the ones defined in the
auth plugin itself.

The plugin config is a read-only property - the plugin configuration
provided when invoking `authenticate()` is recorded and can be queried
by accessing this property.

Returns:
    dict: The latest plugin configuration provided when invoking
          `authenticate()`.
)r!   r%   s    r'   Úplugin_configÚ MySQLAuthenticator.plugin_configI   s   € ð ×"Ñ"Ð"r*   c                ó:   • U R                   R                  U5        g)z,Update the 'plugin_config' instance variableN)r!   Úupdate)r&   Úconfigs     r'   Úupdate_plugin_configÚ'MySQLAuthenticator.update_plugin_configZ   s   € à×Ñ×"Ñ" 6Õ*r*   Nc                óÞ   • Uc  U R                   nUc  U R                  n[        R                  " SU5        [	        XS9" UU R
                  R                  US5      U R                  S9U l        g)a\  Switch the authorization plugin.

Args:
    new_strategy_name: New authorization plugin name to switch to.
    strategy_class: New authorization plugin class to switch to
                    (has higher precedence than the authorization plugin name).
    username: Username to be used - if not defined, the username
              provided when `authentication()` was invoked is used.
    password_factor: Up to three levels of authentication (MFA) are allowed,
                     hence you can choose the password corresponding to the 1st,
                     2nd, or 3rd factor - 1st is the default.
NzSwitching to strategy %s)Úplugin_nameÚauth_plugin_classr   )r,   )	r   r$   r   Údebugr   r    Úgetr,   r#   )r&   Únew_strategy_nameÚstrategy_classÚusernameÚpassword_factors        r'   Ú_switch_auth_strategyÚ(MySQLAuthenticator._switch_auth_strategy^   sk   € ð& ÑØ—~‘~ˆHàÑ!Ø!×4Ñ4ˆNä�ŠÐ/Ð1BÔCÜ-Ø)ò
ð Ø�O‰O×Ñ °Ó4Ø×(Ñ(ñ
ˆÕr*   c              ƒ  óÞ  #   • SnUS   [         :X  Ga?  X0R                  ;  a  [        S5      e[        R                  " U5      u  pEU R                  XCS9  [        R                  " SX0R                  R                  5        U R                  R                  " X40 U R                  D6I Sh  v•N nUS   [        :X  aE  [        R                  " U5      nU R                  R                  " X40 U R                  D6I Sh  v•N nUS   [        :X  a  [        R                  " S5        U$ US   [         :X  a  [#        U5      eUS-  nUS   [         :X  a  GM?  [        R$                  " S	5        g N¿ No7f)
a´  Handle MFA (Multi-Factor Authentication) response.

Up to three levels of authentication (MFA) are allowed.

Args:
    sock: Pointer to the socket connection.
    pkt: MFA response.

Returns:
    ok_packet: If last server's response is an OK packet.
    None: If last server's response isn't an OK packet and no ERROR was raised.

Raises:
    InterfaceError: If got an invalid N factor.
    errors.ErrorTypes: If got an ERROR response.
r	   é   z5Failed Multi Factor Authentication (invalid N factor))r>   zMFA %i factor %sNzMFA completed succesfullyr   z"MFA terminated with a no ok packet)r   r    r
   r   Úparse_auth_next_factorr?   r   r9   r#   ÚnameÚauth_switch_responser!   r   Úparse_auth_more_dataÚauth_more_responser   r   r   Úwarning)r&   ÚsockÚpktÚn_factorr;   Ú	auth_datas         r'   Ú_mfa_n_factorÚ MySQLAuthenticator._mfa_n_factor€   sW  é € ð* ˆØ�!‰fœ
Ô"ØŸ™Ó.Ü$ØKóð ô ,9×+OÒ+OÐPSÓ+TÑ(ÐØ×&Ñ&Ð'8Ð&ÑSÜ�LŠLÐ+¨X×7JÑ7J×7OÑ7OÔPà×+Ñ+×@Ò@ØñØ#'×#6Ñ#6ñ÷ ˆCð �1‰vÔ0Ó0Ü)×>Ò>¸sÓC�	Ø ×/Ñ/×BÒBØñØ'+×':Ñ':ñ÷ �ð �1‰vœÓ"Ü—’Ð8Ô9Ø�
à�1‰vœÓ#Ü# CÓ(Ð(à˜‰MˆHð7 �!‰fœ
Ö"ô: 	�ŠÐ;Ô<Øñ)ñùs,   ‚B'E-Â)E)Â*AE-Ã;E+Ã<AE-ÅE-Å+E-c              ƒ  ó   #   • US   [         :X  a  [        U5      S:X  a  [        S5      eUS   [         :X  an  [        R                  " S5        [
        R                  " U5      u  p4U R                  U5        U R                  R                  " X40 U R                  D6I Sh  v•N nUS   [        :X  a[  [        R                  " S5        [
        R                  " U5      nU R                  R                  " X40 U R                  D6I Sh  v•N nUS   [        :X  a-  [        R                  " SU R                  R                  5        U$ US   [         :X  aZ  [        R                  " S5        [        R                  " S	U R                  R                  5        U R#                  X5      I Sh  v•N $ US   [$        :X  a  ['        U5      eg GN' NÁ N"7f)
a¬  Handle server's response.

Args:
    sock: Pointer to the socket connection.
    pkt: Server's response after completing the `HandShakeResponse`.

Returns:
    ok_packet: If last server's response is an OK packet.
    None: If last server's response isn't an OK packet and no ERROR was raised.

Raises:
    errors.ErrorTypes: If got an ERROR response.
    NotSupportedError: If got Authentication with old (insecure) passwords.
rB   é   z‡Authentication with old (insecure) passwords is not supported. For more information, lookup Password Hashing in the latest MySQL manualz+Server's response is an auth switch requestNzExchanging further packetsz%s completed succesfullyz$Starting multi-factor authenticationzMFA 1 factor %s)r   Úlenr   r   r9   r   Úparse_auth_switch_requestr?   r#   rE   r!   r   rF   rG   r   rD   r   rM   r   r   )r&   rI   rJ   r;   rL   s        r'   Ú_handle_server_responseÚ*MySQLAuthenticator._handle_server_response¶   s“  é € ð& ˆq‰6Ô'Ó'¬C°«H¸«MÜ#ð>óð ð ˆq‰6Ô'Ó'Ü�LŠLÐFÔGÜ+8×+RÒ+RÐSVÓ+WÑ(ÐØ×&Ñ&Ð'8Ô9Ø×+Ñ+×@Ò@ØñØ#'×#6Ñ#6ñ÷ ˆCð ˆq‰6Ô,Ó,Ü�LŠLÐ5Ô6Ü%×:Ò:¸3Ó?ˆIØ×+Ñ+×>Ò>ØñØ#'×#6Ñ#6ñ÷ ˆCð ˆq‰6”YÓÜ�LŠLÐ3°T×5HÑ5H×5MÑ5MÔNØˆJàˆq‰6”ZÓÜ�LŠLÐ?Ô@Ü�LŠLÐ*¨D×,?Ñ,?×,DÑ,DÔEØ×+Ñ+¨DÓ6×6Ð6àˆq‰6”ZÓÜ Ó$Ð$àò/ññ 7ùs8   ‚BGÂ GÂ!A'GÄG
Ä	B GÆ)GÆ*GÇ
GÇGr   r   Fc              ƒ  ó¸  #   • X0l         XEUS.U l        X l        XÐl        [        R
                  " UUUUUU	UUUUUU R                  U R                  S9u  nU l        U(       a  SSU4OSSU4nUR                  " U/UQ76 I Sh  v•N   [        UR                  U5      I Sh  v•N 5      nU R                  UU5      I Sh  v•N nUc  [        S5      SeU$  NQ N5 N7f)aÜ  Perform the authentication phase.

During re-authentication you must set `is_change_user_request` to True.

Args:
    sock: Pointer to the socket connection.
    handshake: Initial handshake.
    username: Account's username.
    password1: Account's password factor 1.
    password2: Account's password factor 2.
    password3: Account's password factor 3.
    database: Initial database name for the connection.
    charset: Client charset (see [1]), only the lower 8-bits.
    client_flags: Integer representing client capabilities flags.
    ssl_enabled: Boolean indicating whether SSL is enabled,
    max_allowed_packet: Maximum packet size.
    auth_plugin: Authorization plugin name.
    auth_plugin_class: Authorization plugin class (has higher precedence
                       than the authorization plugin name).
    conn_attrs: Connection attributes.
    is_change_user_request: Whether is a `change user request` operation or not.
    read_timeout: Timeout in seconds upto which the connector should wait for
                  the server to reply back before raising an ReadTimeoutError.
    write_timeout: Timeout in seconds upto which the connector should spend to
                   send data to the server before raising an WriteTimeoutError.

Returns:
    ok_packet: OK packet.

Raises:
    InterfaceError: If OK packet is NULL.
    ReadTimeoutError: If the time taken for the server to reply back exceeds
                      'read_timeout' (if set).
    WriteTimeoutError: If the time taken to send data packets to the server
                       exceeds 'write_timeout' (if set).

References:
    [1]: https://dev.mysql.com/doc/dev/mysql-server/latest/                page_protocol_basic_character_set.html#a_protocol_character_set
)r   r	   é   )Ú	handshaker=   ÚpasswordÚdatabaseÚcharsetÚclient_flagsÚmax_allowed_packetÚauth_pluginr8   Ú
conn_attrsÚis_change_user_requestr,   r/   r   NzGot a NULL ok_pkt)r   r    r"   r$   r   Ú	make_authr,   r/   r#   ÚwriteÚbytesÚreadrS   r
   )r&   rI   rW   r=   Ú	password1Ú	password2Ú	password3rY   rZ   r[   r,   r\   r]   r8   r^   r_   Úread_timeoutÚwrite_timeoutÚresponse_payloadÚ	send_argsrJ   Úok_pkts                         r'   ÚauthenticateÚMySQLAuthenticator.authenticateí   sÿ   é € ðz "ŒØ'¸)ÑDˆŒØ'ÔØ"3Ôô 1>×0GÒ0GØØØØØØ%Ø1Ø#Ø/Ø!Ø#9Ø×(Ñ(Ø×,Ñ,ñ1
Ñ-Ð˜$Ô-ö& &ð ��=Ñ!à˜˜mÐ,ð 	ð
 �jŠjÐ)Ð6¨IÒ6×6Ð6ô ˜$Ÿ)™) LÓ1×1Ó2ˆà×3Ñ3°D¸#Ó>×>ˆØ‰>Ü Ð!4Ó5¸4Ð?àˆñ 	7ñ 2á>ùs6   ‚B CÂCÂCÂ CÂ!CÂ>CÂ?CÃCÃC)r$   r#   r    r!   r"   r   )ÚreturnÚNone)rn   Úbool)rn   úDict[str, Any])r3   rq   rn   ro   )NNr   )
r;   Ústrr<   úOptional[str]r=   rs   r>   Úintrn   ro   )rI   r   rJ   rb   rn   zOptional[bytes])$rI   r   rW   r   r=   rr   rd   rr   re   rr   rf   rr   rY   rs   rZ   rt   r[   rt   r,   rp   r\   rt   r]   rs   r8   rs   r^   zOptional[Dict[str, str]]r_   rp   rg   úOptional[int]rh   ru   rn   rb   )Ú__name__Ú
__module__Ú__qualname__Ú__firstlineno__Ú__doc__r(   Úpropertyr,   r/   r4   r?   rM   rS   r   r   rl   Ú__static_attributes__© r*   r'   r   r   8   s»  † Ù.ô6ð ó!ó ð!ð ó#ó ð#ô +ð )-Ø"&Ø ð 
àð 
ð &ð 
ð  ð	 
ð
 ð 
ð 
õ 
ðD4àð4ð ð4ð 
ô	4ðl5àð5ð ð5ð 
ô	5ðv ØØØØ"&Ø)ØØ!Ø"<Ø%)Ø+/Ø/3Ø',Ø&*Ø'+ð%bàðbð !ðbð ð	bð
 ðbð ðbð ðbð  ðbð ðbð ðbð ðbð  ðbð #ðbð )ðbð -ðbð  !%ð!bð" $ð#bð$ %ð%bð& 
÷'bð br*   N)rz   Ú
__future__r   Ú__all__Útypingr   r   r   r   Úerrorsr
   r   r   Úprotocolr   r   r   r   r   r   r   Útypesr   r   Úpluginsr   r   r   Únetworkr   r   r}   r*   r'   Ú<module>r†      sP   ðñ: =å "àÐ
 €ç 5Ó 5ç EÑ E÷÷ ñ õ "Ý ß 5Ý #æÝ$÷Wò Wr*   