o
    c2                     @   sp  d Z ddlZddlZddlmZ ddlmZ ddl	Z	ddl
Z
ddlZddlZddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ dd	lmZ dd
lmZ ddlmZ ddlmZ ddlmZ ddlmZ e	eZG dd dejZ G dd dZ!G dd dZ"G dd de e!Z#G dd dej$Z$G dd de$e!Z%G dd de"Z&G dd dej'Z(dS )z1Support for standalone client challenge solvers.     N)Any)cast)List)Mapping)Optional)Set)Tuple)Type)crypto)SSL)
challenges)crypto_utilc                       sf   e Zd ZdZdededdf fddZddd	Zd
ejde	e
ejejf  fddZdddZ  ZS )	TLSServerzGeneric TLS Server.argskwargsreturnNc                    sh   | dd| _| jrtj| _ntj| _| di | _| dtj| _	| dd| _
t j|i | d S )Nipv6Fcertsmethodallow_reuse_addressT)popr   socketAF_INET6address_familyAF_INETr   r   _DEFAULT_SSL_METHODr   r   super__init__selfr   r   	__class__ </opt/certbot/lib/python3.10/site-packages/acme/standalone.pyr      s   
zTLSServer.__init__c              	   C   s.   t tjtj| j| jt| dd | jd| _d S )N_alpn_selection)cert_selectionalpn_selectionr   )r   r   r   	SSLSocket_cert_selectiongetattrr   r   r"   r"   r#   
_wrap_sock*   s
   

zTLSServer._wrap_sock
connectionc                 C   s   |  }|r| j|dS dS )z.Callback selecting certificate for connection.N)get_servernamer   getr   r,   server_namer"   r"   r#   r(   0   s   zTLSServer._cert_selectionc                 C   s   |    tj| S N)r+   socketserver	TCPServerserver_bindr*   r"   r"   r#   r4   8   s   zTLSServer.server_bindr   N)__name__
__module____qualname____doc__r   r   r+   r   
Connectionr   r   r
   PKeyX509r(   r4   __classcell__r"   r"   r    r#   r      s    

r   c                   @   s   e Zd ZdZdZdZdS )ACMEServerMixinz"ACME server common settings mixin.z'ACME client standalone challenge solverTN)r6   r7   r8   r9   server_versionr   r"   r"   r"   r#   r>   =   s    r>   c                
   @   sj   e Zd ZdZdeej deee	f de
de
ddf
dd	Zdd
dZdeeee	f  fddZdddZdS )BaseDualNetworkedServersa  Base class for a pair of IPv6 and IPv4 servers that tries to do everything
       it's asked for both servers, but where failures in one server don't
       affect the other.

       If two servers are instantiated, they will serve on the same port.
       ServerClassserver_addressremaining_argsr   r   Nc                 O   s,  |d }g | _ g | _d }dD ]y}z0||d< |d f|f |dd   }|f| }	||	i |}
td|d |d |r<dnd W n9 tjyy } z,|}| jr_td	|d |d |r[dnd ntd
|d |d |rldnd W Y d }~qd }~ww | j|
 |
j d }q| js|r|tdd S )N   )TFr   r      z$Successfully bound to %s:%s using %sIPv6IPv4zCertbot wasn't able to bind to %s:%s using %s, this is often expected due to the dual stack nature of IPv6 socket implementations.z Failed to bind to %s:%s using %szCould not bind to IPv4 or IPv6.)threadsserversloggerdebugr   errorappendgetsockname)r   rA   rB   rC   r   portlast_socket_err
ip_versionnew_addressnew_argsserverer"   r"   r#   r   L   sF   	


z!BaseDualNetworkedServers.__init__c                 C   s2   | j D ]}tj|jd}|  | j| qdS )z*Wraps socketserver.TCPServer.serve_forever)targetN)rI   	threadingThreadserve_foreverstartrH   rM   r   rT   threadr"   r"   r#   rY   ~   s   
z&BaseDualNetworkedServers.serve_foreverc                 C   s   dd | j D S )z/Wraps socketserver.TCPServer.socket.getsocknamec                 S   s   g | ]}|j  qS r"   )r   rN   ).0rT   r"   r"   r#   
<listcomp>   s    z9BaseDualNetworkedServers.getsocknames.<locals>.<listcomp>)rI   r*   r"   r"   r#   getsocknames   s   z%BaseDualNetworkedServers.getsocknamesc                 C   s:   | j D ]
}|  |  q| jD ]}|  qg | _dS )zpWraps socketserver.TCPServer.shutdown, socketserver.TCPServer.server_close, and
           threading.Thread.joinN)rI   shutdownserver_closerH   joinr[   r"   r"   r#   shutdown_and_server_close   s   




z2BaseDualNetworkedServers.shutdown_and_server_closer5   )r6   r7   r8   r9   r	   r2   r3   r   strintr   r   rY   r   r_   rc   r"   r"   r"   r#   r@   D   s    

2r@   c                   @   s   e Zd ZdZdZ	ddeeef deee	j
e	jf  deeee	j
e	jf f dedd	f
d
dZdejdeee	j
e	jf  fddZdejdee defddZd	S )TLSALPN01ServerzTLSALPN01 Server.s
   acme-tls/1FrB   r   challenge_certsr   r   Nc                 C   s    t j| |tj||d || _d S )N)r   r   )r   r   r2   BaseRequestHandlerrg   )r   rB   r   rg   r   r"   r"   r#   r      s
   

zTLSALPN01Server.__init__r,   c                 C   s&   |  }|rtd| | j| S d S )Nz)Serving challenge cert for server name %s)r-   rJ   rK   rg   r/   r"   r"   r#   r(      s
   	
zTLSALPN01Server._cert_selection_connectionalpn_protosc                 C   sB   t |dkr|d | jkrtd| j | jS tdt| dS )z!Callback to select alpn protocol.rD   r   zAgreed on %s ALPNz#Cannot agree on ALPN proto. Got: %s    )lenACME_TLS_1_PROTOCOLrJ   rK   rd   )r   ri   rj   r"   r"   r#   r$      s
   zTLSALPN01Server._alpn_selection)F)r6   r7   r8   r9   rm   r   rd   re   r   r
   r;   r<   r   bytesboolr   r   r:   r   r(   r$   r"   r"   r"   r#   rf      s"    
 rf   c                       .   e Zd ZdZdededdf fddZ  ZS )
HTTPServerzGeneric HTTP Server.r   r   r   Nc                    s<   | dd| _| jrtj| _ntj| _t j|i | d S )Nr   F)r   r   r   r   r   r   r   r   r   r    r"   r#   r      s
   
zHTTPServer.__init__r6   r7   r8   r9   r   r   r=   r"   r"   r    r#   rq      s    "rq   c                       sH   e Zd ZdZ	ddeeef deej	 de
dedd	f
 fd
dZ  ZS )HTTP01ServerzHTTP01 Server.F   rB   	resourcesr   timeoutr   Nc                    s    t  j|tj||d|d d S )Nsimple_http_resourcesrv   )r   )r   r   HTTP01RequestHandlerpartial_init)r   rB   ru   r   rv   r    r"   r#   r      s   
zHTTP01Server.__init__)Frt   )r6   r7   r8   r9   r   rd   re   r   r   HTTP01ro   r   r=   r"   r"   r    r#   rs      s    rs   c                       rp   )HTTP01DualNetworkedServersz`HTTP01Server Wrapper. Tries everything for both. Failures for one don't
       affect the other.r   r   r   Nc                    s   t  jtg|R i | d S r1   )r   r   rs   r   r    r"   r#   r      s   z#HTTP01DualNetworkedServers.__init__rr   r"   r"   r    r#   r|      s    "r|   c                       s   e Zd ZdZeddZdededdf fdd	Ze	de
fd
dZdededdfddZdddZdddZdddZdddZdddZedeej de
ddfddZ  ZS )ry   zHTTP01 challenge handler.

    Adheres to the stdlib's `socketserver.BaseRequestHandler` interface.

    :ivar set simple_http_resources: A set of `HTTP01Resource`
        objects. TODO: better name?

    HTTP01Resourcezchall response validationr   r   r   Nc                    s8   | dt | _| dd| _t j|i | |  d S )Nrx   rv   rt   )r   setrx   _timeoutr   r   r   r    r"   r#   r      s   zHTTP01RequestHandler.__init__c                 C   s   | j S )z
        The default timeout this server should apply to requests.
        :return: timeout to apply
        :rtype: int
        )r   r*   r"   r"   r#   rv      s   zHTTP01RequestHandler.timeoutformatc                 G   s   t d| jd ||  dS )zLog arbitrary message.z	%s - - %sr   N)rJ   rK   client_address)r   r   r   r"   r"   r#   log_message   s   z HTTP01RequestHandler.log_messagec                 C   s   |  d tj|  dS )zHandle request.zIncoming requestN)r   BaseHTTPServerBaseHTTPRequestHandlerhandler*   r"   r"   r#   r     s   
zHTTP01RequestHandler.handlec                 C   sB   | j dkr|   d S | j dtjj r|   d S |   d S )N/)pathhandle_index
startswithr   r{   URI_ROOT_PATHhandle_simple_http_resource
handle_404r*   r"   r"   r#   do_GET  s
   
zHTTP01RequestHandler.do_GETc                 C   s6   |  d | dd |   | j| jj  dS )zHandle index page.   zContent-Type	text/htmlN)send_responsesend_headerend_headerswfilewriterT   r?   encoder*   r"   r"   r#   r     s   
z!HTTP01RequestHandler.handle_indexc                 C   s4   | j tjdd | dd |   | jd dS )zHandler 404 Not Found errors.z	Not Found)messagezContent-typer   s   404N)r   http_client	NOT_FOUNDr   r   r   r   r*   r"   r"   r#   r     s   zHTTP01RequestHandler.handle_404c                 C   sv   | j D ])}|jj| jkr,| d|jd | tj |   | j	
|j   dS q| d | d| j dS )z$Handle HTTP01 provisioned resources.zServing HTTP01 with token %rtokenNzNo resources to servez0%s does not correspond to any resource. ignoring)rx   challr   r   r   r   r   OKr   r   r   
validation)r   resourcer"   r"   r#   r     s   


z0HTTP01RequestHandler.handle_simple_http_resourcerx   rv   z'functools.partial[HTTP01RequestHandler]c                 C   s   t j| ||dS )zPartially initialize this handler.

        This is useful because `socketserver.BaseServer` takes
        uninitialized handler and initializes it with the current
        request.

        rw   )	functoolspartial)clsrx   rv   r"   r"   r#   rz   -  s   
z!HTTP01RequestHandler.partial_initr5   )r6   r7   r8   r9   collections
namedtupler}   r   r   propertyre   rv   rd   r   r   r   r   r   r   classmethodr   r   r{   rz   r=   r"   r"   r    r#   ry      s(    




ry   ))r9   r   r   http.clientclientr   http.serverrT   r   loggingr   r2   rW   typingr   r   r   r   r   r   r   r	   OpenSSLr
   r   acmer   r   	getLoggerr6   rJ   r3   r   r>   r@   rf   rq   rs   r|   r   ry   r"   r"   r"   r#   <module>   s<    
!Q+
