o
    �õ±j@3  ã                   @   s¾   d dl Z d dlZd dlZd dlmZmZmZ d dlmZm	Z	m
Z
 d dlmZmZmZ d dlmZmZmZ G dd„ dƒZd dlmZ d d	lmZ d d
lmZ d dlmZ d dlmZ g d¢ZdS )é    N)ÚurlparseÚparse_qsÚunquote)Ústr_oneÚint_oneÚbool_one)ÚasyauthSecretÚasyauthProtocolÚasyauthSubProtocol)ÚSubProtocolÚSubProtocolNativeÚSubProtocolSSPIc                   @   sÔ   e Zd Zdddejdeƒ fdedededededefdd	„Z	d!d
d„Z
edd„ ƒZedd„ ƒZdd„ Zedd„ ƒZedd„ ƒZedefdd„ƒZedefdd„ƒZedefdd„ƒZed"dededefdd „ƒZdS )#ÚUniCredentialNÚsecretÚusernameÚdomainÚstypeÚprotocolÚsubprotocolc           	      K   sð   || _ || _|| _|| _|| _|| _|| _|tjtj	fv r#tj
| _d S |tjkr7tj
| _t | j¡ ¡ | _d S |tjkratj
| _t | j¡| _t| jƒd dkrYt| jƒdkrYd S | j ¡ | _d S |tjkrvdd l}tj
| _| d¡| _d S d S )Né   r   é2   zEnter password: )r   r   r   r   r   r   Úmetadatar   ÚPASSÚPWÚPASSWORDÚPWB64Úbase64Ú	b64decodeÚdecodeÚPWHEXÚbytesÚfromhexÚlenÚPWPROMPTÚgetpass)	Úselfr   r   r   r   r   r   Úkwargsr$   © r'   ú–/root/aizidognhua/tmp/workspace/projects/ec89d86c-575f-41c9-af57-ac45cbdbf775/venv/lib/python3.10/site-packages/asyauth/common/credentials/__init__.pyÚ__init__
   s.   

 
ýzUniCredential.__init__c           	      K   sÐ  |d u r| j }|tjkr4| jjtjkr-ddlm} || j	| j
| j| jfd| ji|¤Ž ¡ S td| j ƒ‚|tjkrb| jjtjkr[ddlm} || j	| j
| j| jf| j|dœ|¤Ž ¡ S td| j ƒ‚|tjkr�| jjtjkr†ddlm} || jdd|i|¤Žg| jd	� ¡ S td| j ƒ‚|tjkr¸| jjtjkr±dd
lm} || jdd|i|¤Žg| jd	� ¡ S td| j ƒ‚|tjkrã| jjtjkrÜddlm} || jdd|i|¤Žg| jd	� ¡ S td| j ƒ‚t | ¡S )Nr   ©ÚNTLMCredentialr   zUnsupported subprotocol "%s"©ÚKerberosCredential)r   Útarget©ÚSPNEGOCredentialr.   )r   ©ÚSPNEGOEXCredential©ÚCREDSSPCredentialr'   )r   r	   ÚNTLMr   Útyper
   ÚNATIVEÚasyauth.common.credentials.ntlmr+   r   r   r   r   Úbuild_contextÚ	ExceptionÚKERBEROSÚ#asyauth.common.credentials.kerberosr-   ÚSPNEGOÚ!asyauth.common.credentials.spnegor0   ÚSPNEGOEXÚ#asyauth.common.credentials.spnegoexr2   ÚCREDSSPÚ"asyauth.common.credentials.credsspr4   ÚcopyÚdeepcopy)	r%   r   r.   r&   r+   r-   r0   r2   r4   r'   r'   r(   r9   '   sP   
(
üúùø

$
$
$
zUniCredential.build_contextc                   C   s   t tttttdœS )N)ÚtimeoutÚdnsÚdnscÚdcÚdccÚrealmc)r   r   r'   r'   r'   r(   Úget_url_paramsY   s   úzUniCredential.get_url_paramsc                  C   sò  ddl m}m} d }d }d }tj}tj}tƒ }t| ƒ}	|	 ¡ }
|
 	¡ D ]\}}t
|ƒtu r3t|ƒ|
|< q#|	jdi |
¤Ž}	|	j ¡  d¡}t|ƒdkrVzt|ƒ}W nn   Y ni|d  dd¡}zt|ƒ}W nZ   |d  d¡}t|ƒdkr¨zt|d ƒ}W n   t|d ƒ}t|d ƒ}Y n/t|d ƒ}d }|	jd ur¡t|	jƒ}t ||¡}nzt|d ƒ}tj}W n
   t|d ƒ}Y Y |	jd urà|	j d¡dkrÛ|	j d¡\}}|d	krÚd }nd }|	j}|	j}d }|tjkródd
lm} |}n|tjtjfv �rddl m!} |}i }|d u�r| "¡ }t# "¡ }t$ %t# "¡ d ¡}t$ %| &¡ d ¡}d}|	jd u�r^t|	jƒ}|D ]+}| 'd¡du �r>d}||v �rM|| || ƒ||< ||v �r\|| || ƒ||< �q2|tjtjfv �r€|||||fd|i|¤Ž}|tjk�r~tj|_(|S |tjk�rðd }|du �r�ddl)m*} |j|	j|	j+dd�}d }|d d u�r·||d d|j,||d |d d�}d }|d d u�rÑ||d d|j,||d |d d�}|d }|||||||d |d |d |d ||||d d�S t#||||||ƒS ) Nr   ©Ú	UniTargetÚUniProtoú+é   ú-Ú_ú\éÿÿÿÿÚ.r,   r*   FÚproxyTr   )ÚUniProxyTargetéX   )Úendpoint_portrH   rF   )ÚproxiesrF   Údc_iprI   rG   ÚetypeÚaltnameÚ	altdomainÚcertdataÚkeydatarJ   )	r.   r]   r^   r_   r`   Úetypesr   Úcross_targetÚcross_realmr'   )-Úasysocks.unicomm.common.targetrM   rN   r   ÚNONEr	   r   r   Ú_asdictÚitemsr6   Ústrr   Ú_replaceÚschemeÚupperÚsplitr"   Úreplacer
   Úqueryr   r   Úfrom_url_paramsr5   r   ÚfindÚpasswordr;   r<   r-   ÚSICILYr8   r+   rK   r   ÚdictÚfromkeysÚkeysÚ
startswithr   Úasysocks.unicomm.common.proxyrW   ÚhostnameÚ
CLIENT_TCP) Úconnection_urlrM   rN   r   r   r   r   r   r   Úurl_eÚurl_dictÚpropÚvalÚschemesÚ	auth_tagsÚsptrn   Úcredobjr-   r+   ÚextraparamsÚparamstemplateÚparamsÚextraÚproxy_presentÚkÚresrZ   rW   r.   rb   ra   r'   r'   r(   Úfrom_urld   sø   €


€
€




€üûú
""óúzUniCredential.from_urlc                 C   s^   dd l }d}| jD ]#}| j| }t||jƒr|}n	t||jƒr"|j}|d|t|ƒf 7 }q	|S )Nr   z==== UniCredential ====
z%s: %s
)ÚenumÚ__dict__Ú
isinstanceÚIntFlagÚEnumÚnamerh   )r%   r‹   Útrˆ   r~   r'   r'   r(   Ú__str__ï   s   

zUniCredential.__str__c                  C   sP   t  ¡ dkr
tdƒ‚ddlm}  ddlm} | ƒ }|d|d |d tjt	ƒ d	�S )
zJReturns an NTLM credential object matching the current user (Windows only)ÚWindowsú,This function only works on Windows systems!r   ©Úget_logon_infor*   Nr   r   )r   r   )
ÚplatformÚsystemr:   Úwinacl.functions.highlevelr–   r8   r+   r   re   r   )r–   r+   Úuserinfor'   r'   r(   Úget_sspi_ntlmý   s   ûzUniCredential.get_sspi_ntlmc                  C   s‚   t  ¡ dkr
tdƒ‚ddlm}  ddlm} ddlm}m	} | ƒ }||d d|j
|d |d	 d
�}|d|d |d	 tj|tƒ d�S )zMReturns a Kerberos credential object matching the current user (Windows only)r“   r”   r   r•   r,   rL   ÚlogonserverrX   Údnsdomainname)r[   r   Nr   )r   r.   r   )r—   r˜   r:   r™   r–   r<   r-   rd   rM   rN   ry   r   re   r   )r–   r-   rM   rN   rš   Údctargetr'   r'   r(   Úget_sspi_kerberos  s*   ûúzUniCredential.get_sspi_kerberosÚauthtypec                 C   sL   t  ¡ dkr
tdƒ‚|  ¡ dkrt ¡ }|S |  ¡ dkr"t ¡ }|S tdƒ‚)Nr“   r”   r5   r;   z0Only NTLM or KERBEROS auth types supported here!)r—   r˜   r:   rk   r   r›   rŸ   )r    r‚   r'   r'   r(   Úget_sspi&  s   üÿzUniCredential.get_sspic                 C   ó4   t  ¡ dkr
tdƒ‚ddlm} t | ¡}||gƒS )zKReturns a SPNEGO credential object matching the current user (Windows only)r“   r”   r   r/   )r—   r˜   r:   r>   r0   r   r¡   )r    r0   r‚   r'   r'   r(   Úget_sspi_spnego2  ó
   

zUniCredential.get_sspi_spnegoc                 C   r¢   )zLReturns a CREDSSP credential object matching the current user (Windows only)r“   r”   r   r3   )r—   r˜   r:   rB   r4   r   r¡   )r    r4   r‚   r'   r'   r(   r£   ;  r¤   Ú Ú
authprotosrƒ   c                 C   s   d}|| ||f S )z5Returns user help regarding the credential url formata�  
URL format:

	protocol+authproto-secrettype://[domain]\username:secret@[ip|hostname]:[port]/?param1=value1&param2=value2

protocol: The protocol to use (see below)
	%s
authproto (protocol dependent): 
	%s
username: The username to authenticate with
secret: The secret to authenticate with (depends on secrettype)
domain: The domain of the user
secrettype: The type of the secret (see below)
	password/pw/pass: A plaintext password
	pwb64: A base64 encoded password
	pwprompt: Password will be prompted for on STDIN
	pwhex: A hex encoded password
	nt: NT hash
	==== Kerberos only ====
	rc4: RC4 key (Kerberos only)
	aes: AES key (any size, Kerberos only)
	aes128: AES128 key (Kerberos only)
	aes256: AES256 key (Kerberos only)
	ccache: ccache file name (only local directory)
	ccachehex: A hex encoded ccache file
	ccacheb64: A base64 encoded ccache file
	keytab: keytab file name (only local directory)
	keytabhex: A hex encoded keytab file
	keytabb64: A base64 encoded keytab file
	pfx: pfx file name (only local directory)
	pfxhex: A hex encoded pfx file
	pfxb64: A base64 encoded pfx file
	pem: pem file name (only local directory)
	pemhex: A hex encoded pem file
	pemb64: A base64 encoded pem file
	certstore: Use Windows certificate store (Windows only, Kerberos only)
	kirbi: kirbi file name (only local directory)
	kirbihex: A hex encoded kirbi file
	kirbib64: A base64 encoded kirbi file
	==== SSH Only ====
	sshprivkey: ssh private key file name (only local directory)
	sshprivkeystr: ssh private key file data in string format
	sshprivkeyb64: A base64 encoded ssh private key file

Extra parameters are in the form of param=value. The following parameters are supported:
	altname: Alternative name for certificate authentication
	altdomain: Alternative domain for certificate authentication
	etype: Supported encryption type to use (Kerberos only)
	dc: The domain controller to use (Kerberos only)
	dns: Don't use this.
	%s
r'   )r   r¦   rƒ   Útemplater'   r'   r(   Úget_helpD  s   4zUniCredential.get_help)NN)r¥   r¥   r¥   )Ú__name__Ú
__module__Ú__qualname__r   re   r   rh   r	   r   r)   r9   ÚstaticmethodrK   rŠ   r’   r›   rŸ   r¡   r£   r¨   r'   r'   r'   r(   r   	   s*    4
2


 

r   r3   r,   r*   r/   r1   )r4   r-   r+   r0   r2   )r   r—   rC   Úurllib.parser   r   r   Úasyauth.utils.paramprocessorr   r   r   Úasyauth.common.constantsr   r	   r
   Úasyauth.common.subprotocolsr   r   r   r   rB   r4   r<   r-   r8   r+   r>   r0   r@   r2   Ú__all__r'   r'   r'   r(   Ú<module>   s       y