o
    c<                     @   s   d Z ddlZddlZddlZddlmZmZmZmZm	Z	m
Z
mZmZmZ ddlmZ ddlZddlmZmZmZmZ ddlmZ ddlmZ G dd	 d	ZG d
d dejZG dd dejZG dd dejZG dd dZedkr{ee   dS dS )zJSON Web Signature.    N)	AnyDict	FrozenSetListMappingOptionalTupleTypecast)crypto)b64errors	json_utiljwa)jwk)utilc                   @   sB   e Zd ZdZdZ	 ededefddZededefddZd	S )
	MediaTypez MediaType field encoder/decoder.zapplication/valuereturnc                 C   s(   d|vrd|v rt d| j| S |S )zDecoder./;zUnexpected semi-colon)r   DeserializationErrorPREFIXclsr    r   7/opt/certbot/lib/python3.10/site-packages/josepy/jws.pydecode   s
   

zMediaType.decodec                 C   s.   d|vr| | jsJ |t| jd S |S )zEncoder.r   N)
startswithr   lenr   r   r   r   encode)   s   zMediaType.encodeN)	__name__
__module____qualname____doc__r   classmethodstrr   r    r   r   r   r   r      s    	r   c                   @   s  e Zd ZU dZejdejjddZ	e
ej ed< ejdddZe
e ed< ejdejjddZe
ej ed< ejdddZe
e ed< ejd	ddZe
e ed	< ejd
dddZeejdf ed
< ejdejddZe
e ed< ejdejddZe
e ed< ejdejejddZe
e ed< ejdejejddZe
e ed< ejddddZ ee!df ed< e"eej#f ed< de"eej#f fddZ$de!dd fddZ%de&jfddZ'e j(de!de!fdd Z ej)d!d" Zej(d#d" Zd$S )%Headera6  JOSE Header.

    .. warning:: This class supports **only** Registered Header
        Parameter Names (as defined in section 4.1 of the
        protocol). If you need Public Header Parameter Names (4.2)
        or Private Header Parameter Names (4.3), you must subclass
        and override :meth:`from_json` and :meth:`to_partial_json`
        appropriately.

    .. warning:: This class does not support any extensions through
        the "crit" (Critical) Header Parameter (4.1.11) and as a
        conforming implementation, :meth:`from_json` treats its
        occurrence as an error. Please subclass if you seek for
        a different behaviour.

    :ivar x5tS256: "x5t#S256"
    :ivar str typ: MIME Media Type, inc. :const:`MediaType.PREFIX`.
    :ivar str cty: Content-Type, inc. :const:`MediaType.PREFIX`.

    algT)decoder	omitemptyjku)r*   r   kidx5ux5cr   r*   default.x5tzx5t#S256x5tS256typ)encoderr)   r*   ctycrit_fieldsr   c                    s    fdd j  D S )z4Fields that would not be omitted in the JSON object.c                    s,   i | ]\}}| t |s|t |qS r   )omitgetattr).0namefieldselfr   r   
<dictcomp>]   s    z&Header.not_omitted.<locals>.<dictcomp>)r7   itemsr=   r   r=   r   not_omitted[   s   
zHeader.not_omittedotherc                 C   sb   t |t| stdt||  }| }t||r#td|| t| di |S )NzHeader cannot be added to: {0}z+Addition of overlapping headers not definedr   )
isinstancetype	TypeErrorformatrA   setintersectionupdate)r>   rB   not_omitted_selfnot_omitted_otherr   r   r   __add__a   s   
zHeader.__add__c                 C   s   | j du r
td| j S )zFind key based on header.

        .. todo:: Supports only "jwk" header parameter lookup.

        :returns: (Public) key found in the header.
        :rtype: .JWK

        :raises josepy.errors.Error: if key could not be found

        NzNo key found)r   r   Errorr=   r   r   r   find_keyo   s   

zHeader.find_keyunused_valuec                 C   s
   t d)Nz("crit" is not supported, please subclass)r   r   )rO   r   r   r   r6   ~   s   zHeader.critc                 C   s   dd | D S )Nc                 S   s"   g | ]}t ttj|jqS r   )base64	b64encoder   dump_certificateFILETYPE_ASN1wrappedr:   certr   r   r   
<listcomp>   s
    
zHeader.x5c.<locals>.<listcomp>r   r   r   r   r   r.      s   z
Header.x5cc              
   C   s:   z
t dd | D W S  tjy } zt|d }~ww )Nc              	   s   s*    | ]}t ttjt|V  qd S N)r   ComparableX509r   load_certificaterS   rP   	b64decoderU   r   r   r   	<genexpr>   s    zHeader.x5c.<locals>.<genexpr>)tupler   rM   r   r   )r   errorr   r   r   r.      s   

N)*r!   r"   r#   r$   r   r<   r   JWASignature	from_jsonr(   r   __annotations__r+   bytesjwk_modJWKr   r,   r&   r-   r.   r   r   rZ   decode_b64joser1   r2   r   r    r   r3   r5   r6   r   r   FieldrA   rL   josepyrN   r)   r4   r   r   r   r   r'   3   sF   
 

"

 
r'   c                       s  e Zd ZU dZeZeed< dZej	ddddZ
eed< ej	dde ejd	Zeed< ej	d
ejejdZeed
< e
jdedefddZ
e
jdedefddZ
deddf fddZededeeef fddZedededefddZd'dedeej defddZede fdedejdej dede!dedd fd d!Z"deeef f fd"d#Z#ed$e$eef deeef f fd%d&Z%  Z&S )(	Signaturea  JWS Signature.

    :ivar combined: Combined Header (protected and unprotected,
        :class:`Header`).
    :ivar unicode protected: JWS protected header (Jose Base-64 decoded).
    :ivar header: JWS Unprotected Header (:class:`Header`).
    :ivar str signature: The signature.

    combined)rj   	protectedT r/   header)r*   r0   r)   	signature)r)   r4   r   r   c                 C   s   t | dS Nutf-8)r   encode_b64joser    rX   r   r   r   rk      s   zSignature.protectedc                 C   s   t | dS ro   )r   rf   r   rX   r   r   r   rk      s   kwargsNc                    s8   d|vr	|  |}t jdi | | jjd usJ d S )Nrj   r   )_with_combinedsuper__init__rj   r(   )r>   rr   	__class__r   r   ru      s   
zSignature.__init__c                 C   sZ   d|vsJ | d| jd j}| d| jd j}|r%|| j| }n|}||d< |S )Nrj   rm   rk   )getr7   r0   
header_cls
json_loads)r   rr   rm   rk   rj   r   r   r   rs      s   zSignature._with_combinedpayloadc                 C   s   t |dd t | S )Nrp      .)r   rQ   r    )r   rk   r{   r   r   r   _msg   s   zSignature._msgkeyc                 C   sJ   |du r	| j  n|}| j jstd| j jj|j| j| | j	|dS )zvVerify.

        :param bytes payload: Payload to verify.
        :param JWK key: Key used for verification.

        Nz Not signature algorithm defined.)r~   sigmsg)
rj   rN   r(   rh   rM   verifyr~   rn   r}   rk   )r>   r{   r~   
actual_keyr   r   r   r      s   
zSignature.verifyr(   include_jwkprotectc                 K   s   t ||jsJ |}||d< |r| |d< t|| jjs!J || jjs*J i }|D ]}	|	|v r;||	||	< q.|rI| jdi | }
nd}
| jdi |}	|	|j
| |
|}| |
|	|dS )aD  Sign.

        :param bytes payload: Payload to sign.
        :param JWK key: Key for signature.
        :param JWASignature alg: Signature algorithm to use to sign.
        :param bool include_jwk: If True, insert the JWK inside the signature headers.
        :param FrozenSet protect: List of headers to protect.

        r(   r   rl   )rk   rm   rn   Nr   )rC   kty
public_keyrG   issubsetry   r7   pop
json_dumpssignr~   r}   )r   r{   r~   r(   r   r   rr   header_paramsprotected_paramsrm   rk   rn   r   r   r   r      s$   zSignature.signc                    s    t   }|d  s|d= |S )Nrm   )rt   fields_to_partial_jsonrA   )r>   fieldsrv   r   r   r      s   
z Signature.fields_to_partial_jsonjobjc                    s4   t  |}| |}d|d  vrtd|S )Nr(   rj   zalg not present)rt   fields_from_jsonrs   rA   r   r   )r   r   r   fields_with_combinedrv   r   r   r     s
   

zSignature.fields_from_jsonrY   )'r!   r"   r#   r$   r'   ry   rb   	__slots__r   r<   rk   r&   ra   rm   rf   rq   rn   rc   r4   r)   r   ru   r%   r   rs   r}   r   rh   re   boolr   	frozensetr`   r   r   r   r   r   __classcell__r   r   rv   r   ri      sL   
 	$0ri   c                   @   s   e Zd ZU dZdZeed< ee ed< eZ	dde
ej defdd	Zeded
edd fddZedefddZdefddZededd fddZddedeeef fddZedeeef dd fddZdS )JWSzgJSON Web Signature.

    :ivar str payload: JWS Payload.
    :ivar str signature: JWS Signatures.

    r{   
signaturesr{   r   Nr~   r   c                    s   t  fddjD S )Verify.c                 3   s    | ]
}| j V  qd S rY   )r   r{   r:   r   r~   r>   r   r   r]     s    zJWS.verify.<locals>.<genexpr>)allr   )r>   r~   r   r   r   r     s   z
JWS.verifyrr   c                 K   s    | || j jdd|i|fdS )Sign.r{   r   Nr   )signature_clsr   )r   r{   rr   r   r   r   r     s   zJWS.signc                 C   s   t | jdks	J | jd S )zPGet a singleton signature.

        :rtype: :class:`JWS.signature_cls`

           r   )r   r   r=   r   r   r   rn   %  s   
zJWS.signaturec                 C   s\   t | jdks	J d| jj vsJ t| jjdd t| j	 d t| jj S )z7Compact serialization.

        :rtype: bytes

        r   r(   rp   r|   )
r   r   rn   rm   rA   r   rQ   rk   r    r{   r=   r   r   r   
to_compact/  s   
zJWS.to_compactcompactc                 C   sb   z
| d\}}}W n ty   tdw | jt|dt|d}| t||fdS )zACompact deserialization.

        :param bytes compact:

        r|   zOCompact JWS serialization should comprise of exactly 3 dot-separated componentsrp   )rk   rn   r   )split
ValueErrorr   r   r   r   r\   r   )r   r   rk   r{   rn   r   r   r   r   from_compactA  s   zJWS.from_compactTflatc                 C   sN   | j sJ t| j}|r!t| j dkr!| j d  }||d< |S || j dS )Nr   r   r{   r   )r   r   rq   r{   r   to_partial_json)r>   r   r{   retr   r   r   r   T  s   
zJWS.to_partial_jsonr   c                    s   d|v rd|v rt dd|v r*dd | D } t|d  j|fdS  t|d t fdd	|d D dS )
Nrn   r   zFlat mixed with non-flatc                 S   s   i | ]\}}|d kr||qS )r{   r   )r:   r~   r   r   r   r   r?   g  s    z!JWS.from_json.<locals>.<dictcomp>r{   r   c                 3   s    | ]	} j |V  qd S rY   )r   ra   r   r   r   r   r]   l  s    z JWS.from_json.<locals>.<genexpr>)r   r   r@   r   rf   r   ra   r^   )r   r   filteredr   r   r   ra   b  s   
zJWS.from_jsonrY   )T)r!   r"   r#   r$   r   rc   rb   r   ri   r   r   rh   re   r   r   r%   r   r   propertyrn   r   r   r   r&   r   r   ra   r   r   r   r   r     s"   
 	 r   c                   @   s   e Zd ZdZedejddfddZedejdefddZ	ed	e
dejfd
dZed	e
de
fddZed	e
deej fddZeddee dee fddZdS )CLIzJWS CLI.argsr   Nc                 C   s   |j j|j }|j  |jdu rg |_|jr |jd t	j
tj  ||j t|jd}|jr@t| d dS t|  dS )r   Nr(   )r{   r~   r(   r   rp   )r(   r   loadr~   readcloser   r   appendr   r   sysstdinr    rG   printr   r   json_dumps_pretty)r   r   r~   r   r   r   r   r   s  s   

zCLI.signc              
   C   s   |j rttj  }n&zttttj }W n t	j
y3 } zt| W Y d}~dS d}~ww |jdurQ|jdus@J |j|j  }|j  nd}tj|j  |j|d S )r   NF)r~   )r   r   r   r   r   r   r    r
   rz   r   rM   r   r~   r   r   r   r   stdoutwriter{   r   r   )r   r   r   r_   r~   r   r   r   r     s    
z
CLI.verifyargc                 C   s   t j|S rY   )r   r`   ra   r   r   r   r   r   	_alg_type  s   zCLI._alg_typec                 C   s   |t jjv sJ |S rY   )ri   ry   r7   r   r   r   r   _header_type  s   zCLI._header_typec                 C   s   |t jjv sJ t jj| S rY   )rd   re   TYPESr   r   r   r   	_kty_type  s   zCLI._kty_typec                 C   s   |du rt jdd }t }|jddd | }|d}|j| jd |jdd	t	d
dd |jdd| j
tjd |jddd| jd |d}|j| jd |jdd	t	d
dd |jd| jdd ||}||S )z Parse arguments and sign/verify.Nr   z	--compact
store_true)actionr   )funcz-kz--keyrbT)rD   requiredz-az--alg)rD   r0   z-pz	--protectr   )r   rD   r   Fz--kty)r   argvargparseArgumentParseradd_argumentadd_subparsers
add_parserset_defaultsr   FileTyper   r   RS256r   r   r   
parse_argsr   )r   r   parser
subparsersparser_signparser_verifyparsedr   r   r   run  s4   




zCLI.runrY   )r!   r"   r#   r$   r%   r   	Namespacer   r   r   r   r   r`   r   r   r	   rd   re   r   r   r&   r   r   r   r   r   r   r   p  s    "r   __main__)!r$   r   rP   r   typingr   r   r   r   r   r   r   r	   r
   OpenSSLr   rh   r   r   r   r   r   rd   r   r   JSONObjectWithFieldsr'   ri   r   r   r!   exitr   r   r   r   r   <module>   s$    ,azbV