§
    >Ä³g“2  ã                  óÊ   — d Z ddlmZ dgZddlmZmZmZmZ ddl	m
Z
mZmZ ddlmZmZmZmZmZmZmZ ddlmZ d	d
lmZ d	dlmZmZ d	dlmZ erd	dlmZ  G d„ d¦  «        ZdS )z6Implementing support for MySQL Authentication Plugins.é    )ÚannotationsÚMySQLAuthenticator)ÚTYPE_CHECKINGÚAnyÚDictÚOptionalé   )ÚInterfaceErrorÚNotSupportedErrorÚget_exception)ÚAUTH_SWITCH_STATUSÚDEFAULT_CHARSET_IDÚDEFAULT_MAX_ALLOWED_PACKETÚ
ERR_STATUSÚEXCHANGE_FURTHER_STATUSÚ
MFA_STATUSÚ	OK_STATUS)ÚHandShakeTypeé   )Úlogger)ÚMySQLAuthPluginÚget_auth_plugin)ÚMySQLProtocol)ÚMySQLSocketc                  óš   — e Zd ZdZd2d„Zed3d„¦   «         Zed4d„¦   «         Zd5d
„Z	 	 	 d6d7d„Z	d8d„Z
d8d„Zdddddeddeddddddfd9d1„ZdS ):r   z$Implements the authentication phase.ÚreturnÚNonec                óZ   — d| _         i | _        i | _        d| _        d| _        d| _        dS )zConstructor.Ú FN)Ú	_usernameÚ
_passwordsÚ_plugin_configÚ_ssl_enabledÚ_auth_strategyÚ_auth_plugin_class©Úselfs    ú`/var/www/html/mpstechhub/venv/lib/python3.11/site-packages/mysql/connector/aio/authentication.pyÚ__init__zMySQLAuthenticator.__init__;   s6   € à ˆŒØ*,ˆŒØ.0ˆÔØ"'ˆÔØ9=ˆÔØ15ˆÔÐÐó    Úboolc                ó   — | j         S )z&Signals whether or not SSL is enabled.)r#   r&   s    r(   Ússl_enabledzMySQLAuthenticator.ssl_enabledD   s   € ð Ô Ð r*   úDict[str, Any]c                ó   — | j         S )aö  Custom arguments that are being provided to the authentication plugin.

        The parameters defined here will override the ones defined in the
        auth plugin itself.

        The plugin config is a read-only property - the plugin configuration
        provided when invoking `authenticate()` is recorded and can be queried
        by accessing this property.

        Returns:
            dict: The latest plugin configuration provided when invoking
                  `authenticate()`.
        )r"   r&   s    r(   Úplugin_configz MySQLAuthenticator.plugin_configI   s   € ð Ô"Ð"r*   Úconfigc                ó:   — | j                              |¦  «         dS )z,Update the 'plugin_config' instance variableN)r"   Úupdate)r'   r1   s     r(   Úupdate_plugin_configz'MySQLAuthenticator.update_plugin_configZ   s   € àÔ×"Ò" 6Ñ*Ô*Ð*Ð*Ð*r*   Nr   Únew_strategy_nameÚstrÚstrategy_classúOptional[str]ÚusernameÚpassword_factorÚintc                óÔ   — |€| j         }|€| j        }t          j        d|¦  «          t	          ||¬¦  «        || j                             |d¦  «        | j        ¬¦  «        | _        dS )a¬  Switch the authorization plugin.

        Args:
            new_strategy_name: New authorization plugin name to switch to.
            strategy_class: New authorization plugin class to switch to
                            (has higher precedence than the authorization plugin name).
            username: Username to be used - if not defined, the username
                      provided when `authentication()` was invoked is used.
            password_factor: Up to three levels of authentication (MFA) are allowed,
                             hence you can choose the password corresponding to the 1st,
                             2nd, or 3rd factor - 1st is the default.
        NzSwitching to strategy %s)Úplugin_nameÚauth_plugin_classr   )r-   )	r    r%   r   Údebugr   r!   Úgetr-   r$   )r'   r5   r7   r9   r:   s        r(   Ú_switch_auth_strategyz(MySQLAuthenticator._switch_auth_strategy^   sˆ   € ð& ÐØ”~ˆHàÐ!Ø!Ô4ˆNåŒÐ/Ð1BÑCÔCÐCð
�oØ)¸^ð
ñ 
ô 
ð ØŒO×Ò °Ñ4Ô4ØÔ(ð
ñ 
ô 
ˆÔÐÐr*   Úsockr   ÚpktÚbytesúOptional[bytes]c              ƒ  ó¨  K  — d}|d         t           k    �r'|| j        vrt          d¦  «        ‚t          j        |¦  «        \  }}|                      ||¬¦  «         t          j        d|| j        j	        ¦  «          | j        j
        ||fi | j        ¤Žƒ d{V —†}|d         t          k    r3t          j        |¦  «        } | j        j        ||fi | j        ¤Žƒ d{V —†}|d         t          k    rt          j        d¦  «         |S |d         t           k    rt#          |¦  «        ‚|dz  }|d         t           k    �°'t          j        d	¦  «         dS )
a  Handle MFA (Multi-Factor Authentication) response.

        Up to three levels of authentication (MFA) are allowed.

        Args:
            sock: Pointer to the socket connection.
            pkt: MFA response.

        Returns:
            ok_packet: If last server's response is an OK packet.
            None: If last server's response isn't an OK packet and no ERROR was raised.

        Raises:
            InterfaceError: If got an invalid N factor.
            errors.ErrorTypes: If got an ERROR response.
        r	   é   z5Failed Multi Factor Authentication (invalid N factor))r:   zMFA %i factor %sNzMFA completed succesfullyr   z"MFA terminated with a no ok packet)r   r!   r
   r   Úparse_auth_next_factorrA   r   r?   r$   ÚnameÚauth_switch_responser"   r   Úparse_auth_more_dataÚauth_more_responser   r   r   Úwarning)r'   rB   rC   Ún_factorr5   Ú	auth_datas         r(   Ú_mfa_n_factorz MySQLAuthenticator._mfa_n_factor€   s¸  è è € ð* ˆØ�!Œf�
Ò"Ñ"Ø˜tœÐ.Ð.Ý$ØKñô ð õ ,9Ô+OÐPSÑ+TÔ+TÑ(Ð˜yØ×&Ò&Ð'8È(Ð&ÑSÔSÐSÝŒLÐ+¨X°tÔ7JÔ7OÑPÔPÐPà@˜Ô+Ô@Ø�iðð Ø#'Ô#6ðð ð ð ð ð ð ð ˆCð �1ŒvÕ0Ò0Ð0Ý)Ô>¸sÑCÔC�	ØB˜DÔ/ÔBØ˜)ðð Ø'+Ô':ðð ð ð ð ð ð ð �ð �1Œv�Ò"Ð"Ý”Ð8Ñ9Ô9Ð9Ø�
à�1Œv�Ò#Ð#Ý# CÑ(Ô(Ð(à˜‰MˆHð7 �!Œf�
Ò"Ñ"õ: 	ŒÐ;Ñ<Ô<Ð<Øˆtr*   c              ƒ  ód  K  — |d         t           k    r"t          |¦  «        dk    rt          d¦  «        ‚|d         t           k    r_t          j        d¦  «         t          j        |¦  «        \  }}|                      |¦  «          | j        j	        ||fi | j
        ¤Žƒ d{V —†}|d         t          k    rGt          j        d¦  «         t          j        |¦  «        } | j        j        ||fi | j
        ¤Žƒ d{V —†}|d         t          k    r!t          j        d| j        j        ¦  «         |S |d         t           k    rOt          j        d¦  «         t          j        d	| j        j        ¦  «         |                      ||¦  «        ƒ d{V —†S |d         t$          k    rt'          |¦  «        ‚dS )
aü  Handle server's response.

        Args:
            sock: Pointer to the socket connection.
            pkt: Server's response after completing the `HandShakeResponse`.

        Returns:
            ok_packet: If last server's response is an OK packet.
            None: If last server's response isn't an OK packet and no ERROR was raised.

        Raises:
            errors.ErrorTypes: If got an ERROR response.
            NotSupportedError: If got Authentication with old (insecure) passwords.
        rG   é   z‡Authentication with old (insecure) passwords is not supported. For more information, lookup Password Hashing in the latest MySQL manualz+Server's response is an auth switch requestNzExchanging further packetsz%s completed succesfullyz$Starting multi-factor authenticationzMFA 1 factor %s)r   Úlenr   r   r?   r   Úparse_auth_switch_requestrA   r$   rJ   r"   r   rK   rL   r   rI   r   rP   r   r   )r'   rB   rC   r5   rO   s        r(   Ú_handle_server_responsez*MySQLAuthenticator._handle_server_response¶   s  è è € ð& ˆqŒ6Õ'Ò'Ð'­C°©H¬H¸ªM¨MÝ#ð>ñô ð ð ˆqŒ6Õ'Ò'Ð'ÝŒLÐFÑGÔGÐGÝ+8Ô+RÐSVÑ+WÔ+WÑ(Ð˜yØ×&Ò&Ð'8Ñ9Ô9Ð9Ø@˜Ô+Ô@Ø�iðð Ø#'Ô#6ðð ð ð ð ð ð ð ˆCð ˆqŒ6Õ,Ò,Ð,ÝŒLÐ5Ñ6Ô6Ð6Ý%Ô:¸3Ñ?Ô?ˆIØ>˜Ô+Ô>Ø�iðð Ø#'Ô#6ðð ð ð ð ð ð ð ˆCð ˆqŒ6•YÒÐÝŒLÐ3°TÔ5HÔ5MÑNÔNÐNØˆJàˆqŒ6•ZÒÐÝŒLÐ?Ñ@Ô@Ð@ÝŒLÐ*¨DÔ,?Ô,DÑEÔEÐEØ×+Ò+¨D°#Ñ6Ô6Ð6Ð6Ð6Ð6Ð6Ð6Ð6àˆqŒ6•ZÒÐÝ Ñ$Ô$Ð$àˆtr*   r   r   FÚ	handshaker   Ú	password1Ú	password2Ú	password3ÚdatabaseÚcharsetÚclient_flagsr-   Úmax_allowed_packetÚauth_pluginr>   Ú
conn_attrsúOptional[Dict[str, str]]Úis_change_user_requestÚread_timeoutúOptional[int]Úwrite_timeoutc              ƒ  óœ  K  — || _         |||dœ| _        |
| _        || _        t	          j        ||||||	|||||| j        | j        ¬¦  «        \  }| _        |rdd|fndd|f} |j	        |g|¢R Ž ƒ d{V —† t          |                     |¦  «        ƒ d{V —†¦  «        }|                      ||¦  «        ƒ d{V —†}|€t          d¦  «        d‚|S )aä  Perform the authentication phase.

        During re-authentication you must set `is_change_user_request` to True.

        Args:
            sock: Pointer to the socket connection.
            handshake: Initial handshake.
            username: Account's username.
            password1: Account's password factor 1.
            password2: Account's password factor 2.
            password3: Account's password factor 3.
            database: Initial database name for the connection.
            charset: Client charset (see [1]), only the lower 8-bits.
            client_flags: Integer representing client capabilities flags.
            ssl_enabled: Boolean indicating whether SSL is enabled,
            max_allowed_packet: Maximum packet size.
            auth_plugin: Authorization plugin name.
            auth_plugin_class: Authorization plugin class (has higher precedence
                               than the authorization plugin name).
            conn_attrs: Connection attributes.
            is_change_user_request: Whether is a `change user request` operation or not.
            read_timeout: Timeout in seconds upto which the connector should wait for
                          the server to reply back before raising an ReadTimeoutError.
            write_timeout: Timeout in seconds upto which the connector should spend to
                           send data to the server before raising an WriteTimeoutError.

        Returns:
            ok_packet: OK packet.

        Raises:
            InterfaceError: If OK packet is NULL.
            ReadTimeoutError: If the time taken for the server to reply back exceeds
                              'read_timeout' (if set).
            WriteTimeoutError: If the time taken to send data packets to the server
                               exceeds 'write_timeout' (if set).

        References:
            [1]: https://dev.mysql.com/doc/dev/mysql-server/latest/                page_protocol_basic_character_set.html#a_protocol_character_set
        )r   r	   é   )rV   r9   ÚpasswordrZ   r[   r\   r]   r^   r>   r_   ra   r-   r0   r   NzGot a NULL ok_pkt)r    r!   r#   r%   r   Ú	make_authr-   r0   r$   ÚwriterD   ÚreadrU   r
   )r'   rB   rV   r9   rW   rX   rY   rZ   r[   r\   r-   r]   r^   r>   r_   ra   rb   rd   Úresponse_payloadÚ	send_argsrC   Úok_pkts                         r(   ÚauthenticatezMySQLAuthenticator.authenticateí   sC  è è € ðz "ˆŒØ'¨I¸)ÐDÐDˆŒØ'ˆÔØ"3ˆÔõ 1>Ô0GØØØØØØ%Ø1Ø#Ø/Ø!Ø#9ØÔ(ØÔ,ð1
ñ 1
ô 1
Ñ-Ð˜$Ô-ð& &ð-ˆQ��=Ð!Ð!à˜˜mÐ,ð 	ð
 ˆdŒjÐ)Ð6¨IÐ6Ð6Ð6Ð6Ð6Ð6Ð6Ð6Ð6Ð6õ ˜$Ÿ)š) LÑ1Ô1Ð1Ð1Ð1Ð1Ð1Ð1Ñ2Ô2ˆà×3Ò3°D¸#Ñ>Ô>Ð>Ð>Ð>Ð>Ð>Ð>ˆØˆ>Ý Ð!4Ñ5Ô5¸4Ð?àˆr*   )r   r   )r   r+   )r   r.   )r1   r.   r   r   )NNr   )
r5   r6   r7   r8   r9   r8   r:   r;   r   r   )rB   r   rC   rD   r   rE   )$rB   r   rV   r   r9   r6   rW   r6   rX   r6   rY   r6   rZ   r8   r[   r;   r\   r;   r-   r+   r]   r;   r^   r8   r>   r8   r_   r`   ra   r+   rb   rc   rd   rc   r   rD   )Ú__name__Ú
__module__Ú__qualname__Ú__doc__r)   Úpropertyr-   r0   r4   rA   rP   rU   r   r   rn   © r*   r(   r   r   8   s   € € € € € Ø.Ð.ð6ð 6ð 6ð 6ð ð!ð !ð !ñ „Xð!ð ð#ð #ð #ñ „Xð#ð +ð +ð +ð +ð )-Ø"&Ø ð 
ð  
ð  
ð  
ð  
ðD4ð 4ð 4ð 4ðl5ð 5ð 5ð 5ðv ØØØØ"&Ø)ØØ!Ø"<Ø%)Ø+/Ø/3Ø',Ø&*Ø'+ð%bð bð bð bð bð bð br*   N)rr   Ú
__future__r   Ú__all__Útypingr   r   r   r   Úerrorsr
   r   r   Úprotocolr   r   r   r   r   r   r   Útypesr   r   Úpluginsr   r   r   Únetworkr   r   rt   r*   r(   ú<module>r}      si  ðð: =Ð <à "Ð "Ð "Ð "Ð "Ð "àÐ
 €à 5Ð 5Ð 5Ð 5Ð 5Ð 5Ð 5Ð 5Ð 5Ð 5Ð 5Ð 5à EÐ EÐ EÐ EÐ EÐ EÐ EÐ EÐ EÐ Eðð ð ð ð ð ð ð ð ð ð ð ð ð ð ð ð ð ð "Ð !Ð !Ð !Ð !Ð !Ø Ð Ð Ð Ð Ð Ø 5Ð 5Ð 5Ð 5Ð 5Ð 5Ð 5Ð 5Ø #Ð #Ð #Ð #Ð #Ð #àð %Ø$Ð$Ð$Ð$Ð$Ð$ðWð Wð Wð Wð Wñ Wô Wð Wð Wð Wr*   