î
½1kdï  ã               @   sc  d  d l  Z  d  d l Z d  d l Z d  d l Z d  d l Z d  d l m Z m Z d  d l m Z y d  d l	 Z	 Wn e
 k
 rŒ d Z	 Yn Xd d d d d g Z d	 j ƒ  j ƒ  Z e Z Z xp d
 d d g f d d d g f f D]J \ Z Z x; e D]3 Z y e d e e f ƒ Wqö e
 k
 r(Yqö Xqö Wqã We	 d k	 oLe e e f k Z y d  d l	 m Z m Z WnW e
 k
 rÂy$ d  d l m Z d  d l m Z Wn e
 k
 r½d Z d Z Yn XYn Xe sâGd d „  d e ƒ Z n  e sd d d „ Z d d „  Z n  Gd d „  d e ƒ Z Gd d „  d e ƒ Z d d d „ Z d a d d  „  Z  d! d „  Z! d S)"é    N)ÚResolutionErrorÚExtractionError)Úurllib2ÚVerifyingHTTPSHandlerÚfind_ca_bundleÚis_availableÚ
cert_pathsÚ
opener_forzÄ
/etc/pki/tls/certs/ca-bundle.crt
/etc/ssl/certs/ca-certificates.crt
/usr/share/ssl/certs/ca-bundle.crt
/usr/local/share/certs/ca-root.crt
/etc/ssl/cert.pem
/System/Library/OpenSSL/certs/cert.pem
ÚHTTPSHandlerr   zurllib.requestÚHTTPSConnectionÚhttplibzhttp.clientzfrom %s import %s)ÚCertificateErrorÚmatch_hostname)r   )r   c               @   s   e  Z d  Z d S)r   N)Ú__name__Ú
__module__Ú__qualname__© r   r   úL/var/www/pythonscrapper/code/venv/build/setuptools/setuptools/ssl_support.pyr   8   s   r   é   c       
      C   sX  g  } |  s d S|  j  d ƒ } | d } | d d … } | j d ƒ } | | k rm t d t |  ƒ ƒ ‚ n  | s‰ |  j ƒ  | j ƒ  k S| d k r¥ | j d ƒ nY | j d	 ƒ sÃ | j d	 ƒ rÜ | j t j | ƒ ƒ n" | j t j | ƒ j	 d
 d ƒ ƒ x$ | D] } | j t j | ƒ ƒ qWt j
 d d j | ƒ d t j ƒ }	 |	 j | ƒ S)zpMatching according to RFC 6125, section 6.4.3

        http://tools.ietf.org/html/rfc6125#section-6.4.3
        FÚ.r   r   NÚ*z,too many wildcards in certificate DNS name: z[^.]+zxn--z\*z[^.]*z\Az\.z\Z)ÚsplitÚcountr   ÚreprÚlowerÚappendÚ
startswithÚreÚescapeÚreplaceÚcompileÚjoinÚ
IGNORECASEÚmatch)
ÚdnÚhostnameÚmax_wildcardsÚpatsÚpartsÚleftmostÚ	remainderÚ	wildcardsÚfragÚpatr   r   r   Ú_dnsname_match<   s*    
"&r.   c             C   s[  |  s t  d ƒ ‚ n  g  } |  j d f  ƒ } xC | D]; \ } } | d k r4 t | | ƒ r_ d S| j | ƒ q4 q4 W| sß xc |  j d f  ƒ D]L } xC | D]; \ } } | d k r™ t | | ƒ rÄ d S| j | ƒ q™ q™ WqŒ Wn  t | ƒ d k rt d | d	 j t t | ƒ ƒ f ƒ ‚ n; t | ƒ d k rKt d
 | | d f ƒ ‚ n t d ƒ ‚ d S)a=  Verify that *cert* (in decoded format as returned by
        SSLSocket.getpeercert()) matches the *hostname*.  RFC 2818 and RFC 6125
        rules are followed, but IP addresses are not accepted for *hostname*.

        CertificateError is raised on failure. On success, the function
        returns nothing.
        zempty or no certificateÚsubjectAltNameÚDNSNÚsubjectÚ
commonNamer   z&hostname %r doesn't match either of %sz, zhostname %r doesn't match %rr   z=no appropriate commonName or subjectAltName fields were found)	Ú
ValueErrorÚgetr.   r   Úlenr   r!   Úmapr   )Úcertr%   ÚdnsnamesÚsanÚkeyÚvalueÚsubr   r   r   r   p   s.    %r   c               @   s.   e  Z d  Z d Z d d „  Z d d „  Z d S)r   z=Simple verifying handler: no auth, subclasses, timeouts, etc.c             C   s   | |  _  t j |  ƒ d  S)N)Ú	ca_bundler
   Ú__init__)Úselfr=   r   r   r   r>   œ   s    	zVerifyingHTTPSHandler.__init__c                s   ˆ  j  ‡  f d d †  | ƒ S)Nc                s   t  |  ˆ  j | � S)N)ÚVerifyingHTTPSConnr=   )ÚhostÚkw)r?   r   r   Ú<lambda>¢   s    z2VerifyingHTTPSHandler.https_open.<locals>.<lambda>)Údo_open)r?   Úreqr   )r?   r   Ú
https_open    s    z VerifyingHTTPSHandler.https_openN)r   r   r   Ú__doc__r>   rF   r   r   r   r   r   ™   s   c               @   s.   e  Z d  Z d Z d d „  Z d d „  Z d S)r@   z@Simple verifying connection: no auth, subclasses, timeouts, etc.c             K   s    t  j |  | | � | |  _ d  S)N)r   r>   r=   )r?   rA   r=   rB   r   r   r   r>   ¨   s    zVerifyingHTTPSConn.__init__c             C   sÞ   t  j |  j |  j f t |  d d  ƒ ƒ } t |  d ƒ ra t |  d d  ƒ ra | |  _ |  j ƒ  n  t j	 | d t j
 d |  j ƒ|  _ y t |  j j ƒ  |  j ƒ Wn5 t k
 rÙ |  j j t  j ƒ |  j j ƒ  ‚  Yn Xd  S)NÚsource_addressÚ_tunnelÚ_tunnel_hostÚ	cert_reqsÚca_certs)ÚsocketÚcreate_connectionrA   ÚportÚgetattrÚhasattrÚsockrI   ÚsslÚwrap_socketÚCERT_REQUIREDr=   r   Úgetpeercertr   ÚshutdownÚ	SHUT_RDWRÚclose)r?   rR   r   r   r   Úconnect¬   s    $!	zVerifyingHTTPSConn.connectN)r   r   r   rG   r>   rZ   r   r   r   r   r@   ¦   s   r@   c             C   s   t  j t |  p t ƒ  ƒ ƒ j S)z@Get a urlopen() replacement that uses ca_bundle for verification)r   Úbuild_openerr   r   Úopen)r=   r   r   r   r	   À   s    c                 sx   t  d  k	 r t  j Sy d d l m ‰  Wn t k
 r? d  SYn XG‡  f d d †  d ˆ  ƒ }  |  d d d g ƒ a  t  j S)Nr   )ÚCertFilec                   s(   e  Z d  Z f  f  ‡  f d d † Z d S)z$get_win_certfile.<locals>.MyCertFilec                sL   ˆ  j  |  ƒ x | D] } |  j | ƒ q W|  j | ƒ t j |  j ƒ d  S)N)r>   ZaddstoreZaddcertsÚatexitÚregisterrY   )r?   ÚstoresÚcertsÚstore)r]   r   r   r>   Ô   s
    z-get_win_certfile.<locals>.MyCertFile.__init__N)r   r   r   r>   r   )r]   r   r   Ú
MyCertFileÓ   s   rc   r`   ÚCAÚROOT)Ú	_wincertsÚnameZwincertstorer]   ÚImportError)rc   r   )r]   r   Úget_win_certfileÉ   s    	ri   c              C   sw   t  j d k r t ƒ  Sx$ t D] }  t  j j |  ƒ r |  Sq Wy t j d d ƒ SWn t t	 t
 f k
 rr d SYn Xd S)z*Return an existing CA bundle path, or NoneÚntZcertifiz
cacert.pemN)Úosrg   ri   r   ÚpathÚisfileÚpkg_resourcesÚresource_filenamerh   r   r   )Z	cert_pathr   r   r   r   ß   s    )"rk   rM   r^   r   rn   r   r   Zsetuptools.compatr   rS   rh   Ú__all__Ústripr   r   Úobjectr
   r   ÚwhatÚwhereÚmoduleÚexecr   r   r   Zbackports.ssl_match_hostnamer3   r.   r   r@   r	   rf   ri   r   r   r   r   r   Ú<module>   sV   	

4)