ó
    ßÅŸg­9  ã                  ó¾   • S r SSKJr  SSKJrJrJrJr  SSKJ	r	J
r
Jr  SSKJr  SSKJrJr  SSKJrJrJrJrJrJrJrJr  SS	KJr  \(       a  SS
KJr   " S S5      rg)z5Implementing support for MySQL Authentication Pluginsé    )Úannotations)ÚTYPE_CHECKINGÚAnyÚDictÚOptionalé   )ÚInterfaceErrorÚNotSupportedErrorÚget_exception)Úlogger)ÚMySQLAuthPluginÚget_auth_plugin)ÚAUTH_SWITCH_STATUSÚDEFAULT_CHARSET_IDÚDEFAULT_MAX_ALLOWED_PACKETÚ
ERR_STATUSÚEXCHANGE_FURTHER_STATUSÚ
MFA_STATUSÚ	OK_STATUSÚMySQLProtocol)ÚHandShakeType)ÚMySQLSocketc                  ó@  • \ rS rSrSrSS jr\SS j5       r\SS j5       rSS jr	\
S\4             SS jjr   S         SS
 jjr      SS jr      SS jrSSSSS	\
S\S	S	S	SS	S	4                                 SS jjrSrg	)ÚMySQLAuthenticatoré5   z$Implements the authentication phase.c                óX   • SU l         0 U l        0 U l        SU l        SU l        SU l        g)zConstructor.Ú FN)Ú	_usernameÚ
_passwordsÚ_plugin_configÚ_ssl_enabledÚ_auth_strategyÚ_auth_plugin_class©Úselfs    Ú_/var/www/blue/EV-Temp_rev04/venv/lib/python3.13/site-packages/mysql/connector/authentication.pyÚ__init__ÚMySQLAuthenticator.__init__8   s0   € à ˆŒØ*,ˆŒØ.0ˆÔØ"'ˆÔØ9=ˆÔØ15ˆÕó    c                ó   • U R                   $ )z&Signals whether or not SSL is enabled.)r!   r$   s    r&   Ússl_enabledÚMySQLAuthenticator.ssl_enabledA   s   € ð × Ñ Ð r)   c                ó   • U R                   $ )aº  Custom arguments that are being provided to the authentication plugin when called.

The parameters defined here will override the ones defined in the
auth plugin itself.

The plugin config is a read-only property - the plugin configuration
provided when invoking `authenticate()` is recorded and can be queried
by accessing this property.

Returns:
    dict: The latest plugin configuration provided when invoking
          `authenticate()`.
)r    r$   s    r&   Úplugin_configÚ MySQLAuthenticator.plugin_configF   s   € ð ×"Ñ"Ð"r)   c                ó:   • U R                   R                  U5        g)z,Update the 'plugin_config' instance variableN)r    Úupdate)r%   Úconfigs     r&   Úupdate_plugin_configÚ'MySQLAuthenticator.update_plugin_configW   s   € à×Ñ×"Ñ" 6Õ*r)   r   c                ó  • Uc  0 n[         R                  " UUUS9nUR                  U5        [        R                  " S5        UR                  UR                  S5      UR                  S5      UR                  S5      UR                  SS5      UR                  SS5      UR                  S	5      UR                  S
5      S9n[        R                  " S5        UR                  X‚5        [        R                  " S5        SU l        U$ )a{  Sets up an SSL communication channel.

Args:
    sock: Pointer to the socket connection.
    host: Server host name.
    ssl_options: SSL and TLS connection options (see
                 `network.MySQLSocket.build_ssl_context`).
    charset: Client charset (see [1]), only the lower 8-bits.
    client_flags: Integer representing client capabilities flags.
    max_allowed_packet: Maximum packet size.

Returns:
    ssl_request_payload: Payload used to carry out SSL authentication.

References:
    [1]: https://dev.mysql.com/doc/dev/mysql-server/latest/                page_protocol_basic_character_set.html#a_protocol_character_set
)ÚcharsetÚclient_flagsÚmax_allowed_packetzBuilding SSL contextÚcaÚcertÚkeyÚverify_certFÚverify_identityÚtls_versionsÚtls_ciphersuites)Ússl_caÚssl_certÚssl_keyÚssl_verify_certÚssl_verify_identityr>   Útls_cipher_suiteszSwitching to SSLzSSL has been enabledT)	r   Úmake_auth_sslÚsendr   ÚdebugÚbuild_ssl_contextÚgetÚswitch_to_sslr!   )	r%   ÚsockÚhostÚssl_optionsr6   r7   r8   Ússl_request_payloadÚssl_contexts	            r&   Ú	setup_sslÚMySQLAuthenticator.setup_ssl[   sî   € ð6 ÑØˆKô ,×9Ò9ØØ%Ø1ñ
Ðð
 	�	‰	Ð%Ô&ä�ŠÐ+Ô,Ø×,Ñ,Ø—?‘? 4Ó(Ø —_‘_ VÓ,Ø—O‘O EÓ*Ø'ŸO™O¨M¸5ÓAØ +§¡Ð0AÀ5Ó IØ$Ÿ™¨Ó8Ø)Ÿo™oÐ.@ÓAð -ð 
ˆô 	�ŠÐ'Ô(Ø×Ñ˜;Ô-ä�ŠÐ+Ô,Ø ˆÔà"Ð"r)   Nc                óÞ   • Uc  U R                   nUc  U R                  n[        R                  " SU5        [	        XS9" UU R
                  R                  US5      U R                  S9U l        g)a^  Switches the authorization plugin.

Args:
    new_strategy_name: New authorization plugin name to switch to.
    strategy_class: New authorization plugin class to switch to
                    (has higher precedence than the authorization plugin name).
    username: Username to be used - if not defined, the username
              provided when `authentication()` was invoked is used.
    password_factor: Up to three levels of authentication (MFA) are allowed,
                     hence you can choose the password corresponding to the 1st,
                     2nd, or 3rd factor - 1st is the default.
NzSwitching to strategy %s)Úplugin_nameÚauth_plugin_classr   )r+   )	r   r#   r   rH   r   r   rJ   r+   r"   )r%   Únew_strategy_nameÚstrategy_classÚusernameÚpassword_factors        r&   Ú_switch_auth_strategyÚ(MySQLAuthenticator._switch_auth_strategy”   sk   € ð& ÑØ—~‘~ˆHàÑ!Ø!×4Ñ4ˆNä�ŠÐ/Ð1BÔCÜ-Ø)ò
ð Ø�O‰O×Ñ °Ó4Ø×(Ñ(ñ
ˆÕr)   c                ó®  • SnUS   [         :X  Ga/  X0R                  ;  a  [        S5      e[        R                  " U5      u  pEU R                  XCS9  [        R                  " SX0R                  R                  5        U R                  R                  " X40 U R                  D6nUS   [        :X  a=  [        R                  " U5      nU R                  R                  " X40 U R                  D6nUS   [        :X  a  [        R                  " S5        U$ US   [         :X  a  [#        U5      eUS-  nUS   [         :X  a  GM/  [        R$                  " S5        g	)
aµ  Handles MFA (Multi-Factor Authentication) response.

Up to three levels of authentication (MFA) are allowed.

Args:
    sock: Pointer to the socket connection.
    pkt: MFA response.

Returns:
    ok_packet: If last server's response is an OK packet.
    None: If last server's response isn't an OK packet and no ERROR was raised.

Raises:
    InterfaceError: If got an invalid N factor.
    errors.ErrorTypes: If got an ERROR response.
é   é   z5Failed Multi Factor Authentication (invalid N factor))rY   zMFA %i factor %szMFA completed succesfullyr   z"MFA terminated with a no ok packetN)r   r   r	   r   Úparse_auth_next_factorrZ   r   rH   r"   ÚnameÚauth_switch_responser    r   Úparse_auth_more_dataÚauth_more_responser   r   r   Úwarning)r%   rL   ÚpktÚn_factorrV   Ú	auth_datas         r&   Ú_mfa_n_factorÚ MySQLAuthenticator._mfa_n_factor¶   s@  € ð* ˆØ�!‰fœ
Ô"ØŸ™Ó.Ü$ØKóð ô ,9×+OÒ+OÐPSÓ+TÑ(ÐØ×&Ñ&Ð'8Ð&ÑSÜ�LŠLÐ+¨X×7JÑ7J×7OÑ7OÔPà×%Ñ%×:Ò:ØñØ#'×#6Ñ#6ñˆCð �1‰vÔ0Ó0Ü)×>Ò>¸sÓC�	Ø×)Ñ)×<Ò<ØñØ'+×':Ñ':ñ�ð �1‰vœÓ"Ü—’Ð8Ô9Ø�
à�1‰vœÓ#Ü# CÓ(Ð(à˜‰MˆHð7 �!‰fœ
Ö"ô: 	�ŠÐ;Ô<Ør)   c                óZ  • US   [         :X  a  [        U5      S:X  a  [        S5      eUS   [         :X  af  [        R                  " S5        [
        R                  " U5      u  p4U R                  U5        U R                  R                  " X40 U R                  D6nUS   [        :X  aS  [        R                  " S5        [
        R                  " U5      nU R                  R                  " X40 U R                  D6nUS   [        :X  a-  [        R                  " SU R                  R                  5        U$ US   [         :X  aR  [        R                  " S5        [        R                  " SU R                  R                  5        U R#                  X5      $ US   [$        :X  a  ['        U5      eg	)
a­  Handles server's response.

Args:
    sock: Pointer to the socket connection.
    pkt: Server's response after completing the `HandShakeResponse`.

Returns:
    ok_packet: If last server's response is an OK packet.
    None: If last server's response isn't an OK packet and no ERROR was raised.

Raises:
    errors.ErrorTypes: If got an ERROR response.
    NotSupportedError: If got Authentication with old (insecure) passwords.
r^   é   z‡Authentication with old (insecure) passwords is not supported. For more information, lookup Password Hashing in the latest MySQL manualz+Server's response is an auth switch requestzExchanging further packetsz%s completed succesfullyz$Starting multi-factor authenticationzMFA 1 factor %sN)r   Úlenr
   r   rH   r   Úparse_auth_switch_requestrZ   r"   ra   r    r   rb   rc   r   r`   r   rh   r   r   )r%   rL   re   rV   rg   s        r&   Ú_handle_server_responseÚ*MySQLAuthenticator._handle_server_responseì   st  € ð& ˆq‰6Ô'Ó'¬C°«H¸«MÜ#ð>óð ð ˆq‰6Ô'Ó'Ü�LŠLÐFÔGÜ+8×+RÒ+RÐSVÓ+WÑ(ÐØ×&Ñ&Ð'8Ô9Ø×%Ñ%×:Ò:ØñØ#'×#6Ñ#6ñˆCð ˆq‰6Ô,Ó,Ü�LŠLÐ5Ô6Ü%×:Ò:¸3Ó?ˆIØ×%Ñ%×8Ò8ØñØ#'×#6Ñ#6ñˆCð ˆq‰6”YÓÜ�LŠLÐ3°T×5HÑ5H×5MÑ5MÔNØˆJàˆq‰6”ZÓÜ�LŠLÐ?Ô@Ü�LŠLÐ*¨D×,?Ñ,?×,DÑ,DÔEØ×%Ñ% dÓ0Ð0àˆq‰6”ZÓÜ Ó$Ð$àr)   r   Fc                óh  • X0l         XEUS.U l        XÀl        [        R                  " UUUUUU	U
UUUUU R
                  U R                  S9u  nU l        U(       a  SSU4OSSU4nUR                  " U/UQ76   [        UR                  U5      5      nU R                  UU5      nUc  [        S5      SeU$ )a   Performs the authentication phase.

During re-authentication you must set `is_change_user_request` to True.

Args:
    sock: Pointer to the socket connection.
    handshake: Initial handshake.
    username: Account's username.
    password1: Account's password factor 1.
    password2: Account's password factor 2.
    password3: Account's password factor 3.
    database: Initial database name for the connection.
    charset: Client charset (see [1]), only the lower 8-bits.
    client_flags: Integer representing client capabilities flags.
    max_allowed_packet: Maximum packet size.
    auth_plugin: Authorization plugin name.
    auth_plugin_class: Authorization plugin class (has higher precedence
                       than the authorization plugin name).
    conn_attrs: Connection attributes.
    is_change_user_request: Whether is a `change user request` operation or not.
    read_timeout: Timeout in seconds upto which the connector should wait for
                  the server to reply back before raising an ReadTimeoutError.
    write_timeout: Timeout in seconds upto which the connector should spend to
                   send data to the server before raising an WriteTimeoutError.
Returns:
    ok_packet: OK packet.

Raises:
    InterfaceError: If OK packet is NULL.
    ReadTimeoutError: If the time taken for the server to reply back exceeds
                      'read_timeout' (if set).
    WriteTimeoutError: If the time taken to send data packets to the server
                       exceeds 'write_timeout' (if set).

References:
    [1]: https://dev.mysql.com/doc/dev/mysql-server/latest/                page_protocol_basic_character_set.html#a_protocol_character_set
)r   r]   é   )Ú	handshakerX   ÚpasswordÚdatabaser6   r7   r8   Úauth_pluginrU   Ú
conn_attrsÚis_change_user_requestr+   r.   r   NzGot a NULL ok_pkt)r   r   r#   r   Ú	make_authr+   r.   r"   rG   ÚbytesÚrecvrn   r	   )r%   rL   rr   rX   Ú	password1Ú	password2Ú	password3rt   r6   r7   r8   ru   rU   rv   rw   Úread_timeoutÚwrite_timeoutÚresponse_payloadÚ	send_argsre   Úok_pkts                        r&   ÚauthenticateÚMySQLAuthenticator.authenticate#  sÝ   € ðt "ŒØ'¸)ÑDˆŒØ"3Ôô 1>×0GÒ0GØØØØØØ%Ø1Ø#Ø/Ø!Ø#9Ø×(Ñ(Ø×,Ñ,ñ1
Ñ-Ð˜$Ô-ö& &ð ��=Ñ!à˜˜mÐ,ð 	ð
 	�	Š	Ð"Ð/ YÓ/ô �D—I‘I˜lÓ+Ó,ˆà×-Ñ-¨d°CÓ8ˆØ‰>Ü Ð!4Ó5¸4Ð?àˆr)   )r#   r"   r   r    r!   r   )ÚreturnÚNone)r…   Úbool)r…   úDict[str, Any])r2   rˆ   r…   r†   )rL   r   rM   ÚstrrN   zOptional[Dict[str, Any]]r6   Úintr7   rŠ   r8   rŠ   r…   ry   )NNr   )
rV   r‰   rW   úOptional[str]rX   r‹   rY   rŠ   r…   r†   )rL   r   re   ry   r…   zOptional[bytes])"rL   r   rr   r   rX   r‰   r{   r‰   r|   r‰   r}   r‰   rt   r‹   r6   rŠ   r7   rŠ   r8   rŠ   ru   r‹   rU   r‹   rv   zOptional[Dict[str, str]]rw   r‡   r~   úOptional[int]r   rŒ   r…   ry   )Ú__name__Ú
__module__Ú__qualname__Ú__firstlineno__Ú__doc__r'   Úpropertyr+   r.   r3   r   r   rQ   rZ   rh   rn   rƒ   Ú__static_attributes__© r)   r&   r   r   5   s  † Ù.ô6ð ó!ó ð!ð ó#ó ð#ô +ð *ØØ"<ð7#àð7#ð ð7#ð .ð	7#ð
 ð7#ð ð7#ð  ð7#ð 
õ7#ðx )-Ø"&Ø ð 
àð 
ð &ð 
ð  ð	 
ð
 ð 
ð 
õ 
ðD4àð4ð ð4ð 
ô	4ðl5àð5ð ð5ð 
ô	5ðv ØØØØ"&Ø)ØØ"<Ø%)Ø+/Ø/3Ø',Ø&*Ø'+ð#^àð^ð !ð^ð ð	^ð
 ð^ð ð^ð ð^ð  ð^ð ð^ð ð^ð  ð^ð #ð^ð )ð^ð -ð^ð !%ð^ð  $ð!^ð" %ð#^ð$ 
÷%^ð ^r)   r   N)r‘   Ú
__future__r   Útypingr   r   r   r   Úerrorsr	   r
   r   r   Úpluginsr   r   Úprotocolr   r   r   r   r   r   r   r   Útypesr   Únetworkr   r   r”   r)   r&   Ú<module>rœ      sE   ðñ: <Ý "ç 5Ó 5ç DÑ DÝ ß 5÷	÷ 	ó 	õ !æÝ$÷Lò Lr)   