§
    >Ä³gµ*  ã                   ó8  — d Z ddlmZmZmZmZ ddlmZmZ ddl	m	Z	 ddlm
Z
 erddlmZ 	 dd	lmZ dd
lmZmZ ddlmZ ddlmZ n# e$ rZ ej        d¦  «        e‚dZ[ww xY w	 ddlmZ dZn# e$ r dZY nw xY wdZ G d„ de¦  «        Z G d„ de
¦  «        Z dS )zWebAuthn Authentication Plugin.é    )ÚTYPE_CHECKINGÚAnyÚCallableÚOptionalé   )ÚerrorsÚutils)Úloggeré   )ÚMySQLAuthPlugin)ÚMySQLSocket)Ú
dump_bytes)ÚFido2ClientÚUserInteraction)ÚCtapHidDevice)Ú!PublicKeyCredentialRequestOptionszxModule fido2 is required for WebAuthn authentication mechanism but was not found. Unable to authenticate with the serverN)ÚCtapPcscDeviceTFÚMySQLWebAuthnAuthPluginc                   ó4   — e Zd ZdZddee         fd„Zdd„ZdS )	ÚClientInteractionz(Provides user interaction to the Client.NÚcallbackc                 ó"   — || _         d| _        d S )NzTPlease insert FIDO device and perform gesture action for authentication to complete.)r   Úmsg)Úselfr   s     út/var/www/html/mpstechhub/venv/lib/python3.11/site-packages/mysql/connector/plugins/authentication_webauthn_client.pyÚ__init__zClientInteraction.__init__B   s   € Ø ˆŒðð 	Œˆˆó    Úreturnc                 ót   — | j         €t          | j        ¦  «         dS |                       | j        ¦  «         dS )z=Prompt message for the user interaction with the FIDO device.N)r   Úprintr   ©r   s    r   Ú	prompt_upzClientInteraction.prompt_upI   s5   € àŒ=Ð Ý�$”(‰OŒOˆOˆOˆOà�MŠM˜$œ(Ñ#Ô#Ð#Ð#Ð#r   ©N)r   N)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r   r   r"   © r   r   r   r   ?   sS   € € € € € Ø2Ð2ð
ð 
 ¨(Ô!3ð 
ð 
ð 
ð 
ð$ð $ð $ð $ð $ð $r   r   c                   ó  — e Zd ZU dZdZee         ed<   dZee	         ed<   ddg dœZ
eed<   edefd„¦   «         Zedefd	„¦   «         Z	 dd
ee         defd„Zdededee         fd„Zdddededefd„Zdddededefd„ZdS )r   z<Class implementing the MySQL WebAuthn authentication plugin.NÚclientr   )ÚrpIdÚ	challengeÚallowCredentialsÚoptionsr   c                 ó   — dS )zPlugin official name.Úauthentication_webauthn_clientr(   r!   s    r   ÚnamezMySQLWebAuthnAuthPlugin.nameX   s
   € ð 0Ð/r   c                 ó   — dS )z'Signals whether or not SSL is required.Fr(   r!   s    r   Úrequires_sslz$MySQLWebAuthnAuthPlugin.requires_ssl]   s	   € ð ˆur   Úcredential_idc                 ó  — | j         €t          j        d¦  «        ‚|�|ddœg| j        d<   | j                              t          j        | j        ¦  «        ¦  «        }t          |                     ¦   «         ¦  «        }d}t          j
        d¦  «        }|t          j
        |¦  «        z  }t          |¦  «        D ]‹}|                     |¦  «        }t          |j        ¦  «        }|j        }	|t          j
        t          |¦  «        ¦  «        z  }||z  }|t          j
        t          |	¦  «        ¦  «        z  }||	z  }|j        }ŒŒ|t          j
        t          |¦  «        ¦  «        z  }||z  }t#          j        d|¦  «         |S )	zôGet assertion from authenticator and return the response.

        Args:
            credential_id (Optional[bytearray]): The credential ID.

        Returns:
            bytearray: The response packet with the data from the assertion.
        NzNo WebAuthn client foundz
public-key)ÚidÚtyper-   r   r   z&WebAuthn - payload response packet: %s)r*   r   ÚInterfaceErrorr.   Úget_assertionr   Ú	from_dictÚlenÚget_assertionsr	   Úlc_intÚrangeÚget_responseÚcbor_dump_bytesÚauthenticator_dataÚ	signatureÚclient_datar
   Údebug)
r   r4   Ú	assertionÚnumber_of_assertionsÚclient_data_jsonÚpacketÚiÚassertion_responserA   rB   s
             r   Úget_assertion_responsez.MySQLWebAuthnAuthPlugin.get_assertion_responseb   sš  € ð Œ;ÐÝÔ'Ð(BÑCÔCÐCàÐ$ð
 (Ø(ðð ð0ˆDŒLÐ+Ñ,ð ”K×-Ò-Ý-Ô7¸¼ÑEÔEñ
ô 
ˆ	õ  # 9×#;Ò#;Ñ#=Ô#=Ñ>Ô>ÐØÐõ ”˜a‘”ˆØ•%”,Ð3Ñ4Ô4Ñ4ˆõ Ð+Ñ,Ô,ð 	>ð 	>ˆAØ!*×!7Ò!7¸Ñ!:Ô!:Ðõ "1Ð1CÔ1VÑ!WÔ!WÐð +Ô4ˆIà•e”l¥3Ð'9Ñ#:Ô#:Ñ;Ô;Ñ;ˆFØÐ(Ñ(ˆFØ•e”l¥3 y¡>¤>Ñ2Ô2Ñ2ˆFØ�iÑˆFð  2Ô=ÐÐà•%”,�sÐ#3Ñ4Ô4Ñ5Ô5Ñ5ˆØÐ"Ñ"ˆåŒÐ=¸vÑFÔFÐFØˆr   Ú	auth_dataÚkwargsc                 ó¢  — 	 t          j        |d¦  «        \  }}t          j        |¦  «        \  }}|| j        d<   |                     ¦   «         | j        d<   t          j        d|¦  «         t          j        d| j        d         ¦  «         t          j        d| j        d         ¦  «         n'# t          $ r}t          j	        d¦  «        |‚d}~ww xY wt          t          j        ¦   «         d¦  «        }|�t          j        d	¦  «         n(t          r!t          t          j        ¦   «         d¦  «        }|€t          j	        d
¦  «        ‚t          |d| j        d         › �t!          | j        ¦  «        ¬¦  «        | _        | j        j        j                             d¦  «        st          j        d¦  «         dS t          j        d¦  «         dS )aE  Find authenticator device and check if supports resident keys.

        It also creates a Fido2Client using the relying party ID from the server.

        Raises:
            InterfaceError: When the FIDO device is not found.

        Returns:
            bytes: 2 if the authenticator supports resident keys else 1.
        r   r,   r+   zWebAuthn - capability: %dzWebAuthn - challenge: %szWebAuthn - relying party id: %sz2Unable to parse MySQL WebAuthn authentication dataNzWebAuthn - Use USB HID channelzNo FIDO device foundzhttps://)Úuser_interactionÚrkz6WebAuthn - Authenticator doesn't support resident keysó   1z<WebAuthn - Authenticator with support for resident key foundó   2)r	   Úread_intÚread_lc_string_listr.   Údecoder
   rD   Ú
ValueErrorr   r8   Únextr   Úlist_devicesÚCTAP_PCSC_DEVICE_AVAILABLEr   r   r   r   r*   ÚinfoÚget)	r   rL   rM   ÚpacketsÚ
capabilityr,   Úrp_idÚerrÚdevices	            r   Úauth_responsez%MySQLWebAuthnAuthPlugin.auth_response¨   sÇ  € ð	Ý"'¤.°¸AÑ">Ô">ÑˆG�ZÝ$Ô8¸ÑAÔAÑˆI�uØ(1ˆDŒL˜Ñ%Ø#(§<¢<¡>¤>ˆDŒL˜Ñ ÝŒLÐ4°jÑAÔAÐAÝŒLÐ3°T´\À+Ô5NÑOÔOÐOÝŒLÐ:¸D¼LÈÔ<PÑQÔQÐQÐQøÝð 	ð 	ð 	ÝÔ'ØDñô àðøøøøð	øøøõ •mÔ0Ñ2Ô2°DÑ9Ô9ˆØÐÝŒLÐ9Ñ:Ô:Ð:Ð:Ý'ð 	?Ý�.Ô5Ñ7Ô7¸Ñ>Ô>ˆFàˆ>ÝÔ'Ð(>Ñ?Ô?Ð?õ "ØØ-�t”| FÔ+Ð-Ð-Ý.¨t¬}Ñ=Ô=ð
ñ 
ô 
ˆŒð Œ{ÔÔ'×+Ò+¨DÑ1Ô1ð 	ÝŒLÐQÑRÔRÐRØ�4åŒÐSÑTÔTÐTØˆts   ‚B*B- Â-
CÂ7CÃCÚsockr   c                 ó:  — t          j        |¦  «        \  }}|                      |¦  «        }t          j        d|t          |¦  «        ¦  «         |                     |¦  «         t          |                     ¦   «         ¦  «        }t          j        d|¦  «         |S )aE  Handles server's `auth more data` response.

        Args:
            sock: Pointer to the socket connection.
            auth_data: Authentication method data (from a packet representing
                       an `auth more data` response).
            kwargs: Custom configuration to be passed to the auth plugin
                    when invoked. The parameters defined here will override the ones
                    defined in the auth plugin itself.

        Returns:
            packet: Last server's response after back-and-forth
                    communication.
        úWebAuthn - request: %s size: %sú%WebAuthn - server response packet: %s)	r	   Úread_lc_stringrK   r
   rD   r;   ÚsendÚbytesÚrecv)r   rb   rL   rM   Ú_r4   ÚresponseÚpkts           r   Úauth_more_responsez*MySQLWebAuthnAuthPlugin.auth_more_responseØ   s†   € õ" !Ô/°	Ñ:Ô:Ñˆˆ=à×.Ò.¨}Ñ=Ô=ˆåŒÐ6¸Å#ÀhÁ-Ä-ÑPÔPÐPØ�	Š	�(ÑÔÐå�D—I’I‘K”KÑ Ô ˆÝŒÐ<¸cÑBÔBÐBàˆ
r   c                 óÌ  — |                      d¦  «        p|                      d¦  «        }t          |t          ¦  «        rt          j        |¦  «        n|| _        |                      |¦  «        }d}|dk    rit          j        d¦  «         | 	                    t          j
        t          |¦  «        ¦  «        ¦  «         t          |                     ¦   «         ¦  «        S |                      |¦  «        }t          j        d|t          |¦  «        ¦  «         | 	                    |¦  «         t          |                     ¦   «         ¦  «        }t          j        d|¦  «         |S )aS  Handles server's `auth switch request` response.

        Args:
            sock: Pointer to the socket connection.
            auth_data: Plugin provided data (extracted from a packet
                       representing an `auth switch request` response).
            kwargs: Custom configuration to be passed to the auth plugin
                    when invoked. The parameters defined here will override the ones
                    defined in the auth plugin itself.

        Returns:
            packet: Last server's response after back-and-forth
                    communication.
        Úwebauthn_callbackÚfido_callbackNrQ   z WebAuthn - request credential_idrd   re   )r[   Ú
isinstanceÚstrr	   Úimport_objectr   ra   r
   rD   rg   r=   Úintrh   ri   rK   r;   )r   rb   rL   rM   Úwebauth_callbackrk   r4   rl   s           r   Úauth_switch_responsez,MySQLWebAuthnAuthPlugin.auth_switch_responseõ   s<  € ð" "Ÿ:š:Ð&9Ñ:Ô:ð 
¸f¿jºjØñ?
ô ?
Ðõ
 Ð*­CÑ0Ô0ð"�EÔÐ 0Ñ1Ô1Ð1à!ð 	Œð ×%Ò% iÑ0Ô0ˆØˆà�tÒÐåŒLÐ;Ñ<Ô<Ð<Ø�IŠI•e”l¥3 x¡=¤=Ñ1Ô1Ñ2Ô2Ð2õ ˜Ÿš™œÑ%Ô%Ð%à×.Ò.¨}Ñ=Ô=ˆåŒÐ6¸Å#ÀhÁ-Ä-ÑPÔPÐPØ�	Š	�(ÑÔÐå�D—I’I‘K”KÑ Ô ˆÝŒÐ<¸cÑBÔBÐBàˆ
r   r#   )r$   r%   r&   r'   r*   r   r   Ú__annotations__r   r   r.   ÚdictÚpropertyrr   r1   Úboolr3   Ú	bytearrayrh   rK   r   ra   rm   rv   r(   r   r   r   r   Q   s}  € € € € € € ØFÐFà$(€FˆH�[Ô!Ð(Ð(Ñ(Ø#'€Hˆh�xÔ Ð'Ð'Ñ'Ø!°È"ÐMÐM€GˆTÐMÐMÑMàð0�cð 0ð 0ð 0ñ „Xð0ð ð˜dð ð ð ñ „Xðð
 48ðDð DØ% iÔ0ðDà	ðDð Dð Dð DðL. uð .¸ð .ÀÈÄð .ð .ð .ð .ð`Ø!ðØ.3ðØ?Bðà	ðð ð ð ð:-Ø!ð-Ø.3ð-Ø?Bð-à	ð-ð -ð -ð -ð -ð -r   )!r'   Útypingr   r   r   r   Ú r   r	   r
   r   Únetworkr   Ú
fido2.cborr   r@   Úfido2.clientr   r   Ú	fido2.hidr   Úfido2.webauthnr   ÚImportErrorÚ
import_errÚProgrammingErrorÚ
fido2.pcscr   rY   ÚModuleNotFoundErrorÚAUTHENTICATION_PLUGIN_CLASSr   r   r(   r   r   ú<module>r‰      sÖ  ðð: &Ð %ð :Ð 9Ð 9Ð 9Ð 9Ð 9Ð 9Ð 9Ð 9Ð 9Ð 9Ð 9à Ð Ð Ð Ð Ð Ð Ð Ø Ð Ð Ð Ð Ð Ø Ð Ð Ð Ð Ð àð &Ø%Ð%Ð%Ð%Ð%Ð%ð	Ø8Ð8Ð8Ð8Ð8Ð8Ø9Ð9Ð9Ð9Ð9Ð9Ð9Ð9Ø'Ð'Ð'Ð'Ð'Ð'Ø@Ð@Ð@Ð@Ð@Ð@Ð@øØð ð ð Ø
!ˆ&Ô
!ð	<ñô ð ðøøøøðøøøð'Ø)Ð)Ð)Ð)Ð)Ð)à!%ÐÐøØð 'ð 'ð 'Ø!&ÐÐÐð'øøøð 8Ð ð$ð $ð $ð $ð $˜ñ $ô $ð $ð$Qð Qð Qð Qð Q˜oñ Qô Qð Qð Qð Qs)   ¬A ÁA"ÁAÁA"Á&A/ Á/A9Á8A9