U
    ÓZj…6  ã                   @   s  d Z ddlZddlZddlZddlZddlZddlZddlZddl	Z	ddl
Z
ddlZddlZddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlmZ dd	lmZ dd
lmZ e e¡ZG dd„ deƒZdd„ Z G dd„ dej!ƒZ"G dd„ dej#ƒZ$G dd„ dej!ƒZ%dS )z!Creates ACME accounts for server.é    N)Úserialization)Úfields)Úmessages)Ú	constants)Úerrors)Ú
interfaces)Úutil)Úosc                   @   sH   e Zd ZdZG dd„ dejƒZddd„Zedd„ ƒZ	d	d
„ Z
dd„ ZdS )ÚAccountzáACME protocol registration.

    :ivar .RegistrationResource regr: Registration Resource
    :ivar .JWK key: Authorized Account Key
    :ivar .Meta: Account metadata
    :ivar str id: Globally unique account identifier.

    c                   @   s$   e Zd ZdZe d¡Ze d¡Z	dS )zAccount.Metaa+  Account metadata

        :ivar datetime.datetime creation_dt: Creation date and time (UTC).
        :ivar str creation_host: FQDN of host, where account has been created.

        .. note:: ``creation_dt`` and ``creation_host`` are useful in
            cross-machine migration scenarios.

        Úcreation_dtÚcreation_hostN)
Ú__name__Ú
__module__Ú__qualname__Ú__doc__Úacme_fieldsZRFC3339Fieldr   ÚjoseÚFieldr   © r   r   úR/var/www/html/TRUCKING_PROJECT/venv/lib/python3.8/site-packages/certbot/account.pyÚMeta&   s   	
r   Nc                 C   sn   || _ || _|d kr:| jtjjtjd�jdd�t 	¡ d�n|| _
t | j j  ¡ jtjjtjjd�¡ ¡ | _d S )N)Útzr   )Úmicrosecond)r   r   )ÚencodingÚformat)ÚkeyÚregrr   ÚdatetimeÚnowÚpytzÚUTCÚreplaceÚsocketÚgetfqdnÚmetaÚhashlibÚmd5Z
public_keyZpublic_bytesr   ZEncodingZPEMZPublicFormatZSubjectPublicKeyInfoÚ	hexdigestÚid)Úselfr   r   r$   r   r   r   Ú__init__3   s&    üÿÿüüþÿzAccount.__init__c                 C   s&   d  t | jj¡| jj| jdd… ¡S )z3Short account identification string, useful for UI.z{1}@{0} ({2})Né   )r   Ú	pyrfc3339Úgenerater$   r   r   r(   ©r)   r   r   r   ÚslugG   s    ÿ ÿzAccount.slugc                 C   s   d  | jj| j| j| j¡S )Nz<{0}({1}, {2}, {3})>)r   Ú	__class__r   r   r(   r$   r.   r   r   r   Ú__repr__M   s       ÿzAccount.__repr__c                 C   s0   t || jƒo.| j|jko.| j|jko.| j|jkS ©N)Ú
isinstancer0   r   r   r$   )r)   Úotherr   r   r   Ú__eq__Q   s    
ÿ
ÿ
þzAccount.__eq__)N)r   r   r   r   r   ZJSONObjectWithFieldsr   r*   Úpropertyr/   r1   r5   r   r   r   r   r
      s   	

r
   c                 C   s4   t j tj¡}|dkrdS | d | j¡|j¡ dS )z.Informs the user about their new ACME account.Na   Your account credentials have been saved in your Certbot configuration directory at {0}. You should make a secure backup of this folder now. This configuration directory will also contain certificates and private keys obtained by Certbot so making regular backups of this folder is ideal.)	ÚzopeÚ	componentZqueryUtilityr   Z	IReporterZadd_messager   Z
config_dirZMEDIUM_PRIORITY)ÚconfigÚreporterr   r   r   Úreport_new_accountW   s    ûùr;   c                   @   s2   e Zd ZdZddd„Zdd„ Zdd„ Zd	d
„ ZdS )ÚAccountMemoryStoragezIn-memory account storage.Nc                 C   s   |d k	r|ni | _ d S r2   )Úaccounts)r)   Zinitial_accountsr   r   r   r*   i   s    zAccountMemoryStorage.__init__c                 C   s   t t | j¡ƒS r2   )ÚlistÚsixÚ
itervaluesr=   r.   r   r   r   Úfind_alll   s    zAccountMemoryStorage.find_allc                 C   s*   |j | jkrt d|j ¡ || j|j < d S )NzOverwriting account: %s)r(   r=   ÚloggerÚdebug©r)   ÚaccountÚclientr   r   r   Úsaveo   s    zAccountMemoryStorage.savec                 C   s0   z| j | W S  tk
r*   t |¡‚Y nX d S r2   )r=   ÚKeyErrorr   ÚAccountNotFound©r)   Ú
account_idr   r   r   Úloadt   s    zAccountMemoryStorage.load)N)r   r   r   r   r*   rA   rG   rL   r   r   r   r   r<   f   s
   
r<   c                   @   s   e Zd ZdZe d¡ZdS )Ú$RegistrationResourceWithNewAuthzrURIaf  A backwards-compatible RegistrationResource with a new-authz URI.

       Hack: Certbot versions pre-0.11.1 expect to load
       new_authzr_uri as part of the account. Because people
       sometimes switch between old and new versions, we will
       continue to write out this field for some time so older
       clients don't crash in that scenario.
    Únew_authzr_uriN)r   r   r   r   r   r   rN   r   r   r   r   rM   z   s   rM   c                   @   s´   e Zd ZdZdd„ Zdd„ Zdd„ Zedd	„ ƒZed
d„ ƒZ	edd„ ƒZ
dd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zd d!„ Zd"d#„ Zd$d%„ Zd&d'„ Zd(S ))ÚAccountFileStoragezMAccounts file storage.

    :ivar .IConfig config: Client configuration

    c                 C   s   || _ t |jd| j j¡ d S )NéÀ  )r9   r   Úmake_or_verify_dirÚaccounts_dirÚstrict_permissions)r)   r9   r   r   r   r*   ‹   s    zAccountFileStorage.__init__c                 C   s   |   || jj¡S r2   )Ú!_account_dir_path_for_server_pathr9   Úserver_pathrJ   r   r   r   Ú_account_dir_path�   s    z$AccountFileStorage._account_dir_pathc                 C   s   | j  |¡}tj ||¡S r2   )r9   Úaccounts_dir_for_server_pathr	   ÚpathÚjoin)r)   rK   rU   rR   r   r   r   rT   ’   s    z4AccountFileStorage._account_dir_path_for_server_pathc                 C   s   t j |d¡S )Nz	regr.json©r	   rX   rY   ©ÚclsÚaccount_dir_pathr   r   r   Ú
_regr_path–   s    zAccountFileStorage._regr_pathc                 C   s   t j |d¡S )Nzprivate_key.jsonrZ   r[   r   r   r   Ú	_key_pathš   s    zAccountFileStorage._key_pathc                 C   s   t j |d¡S )Nz	meta.jsonrZ   r[   r   r   r   Ú_metadata_pathž   s    z!AccountFileStorage._metadata_pathc              	   C   sÖ   | j  |¡}zt |¡}W n tk
r2   g  Y S X g }|D ]@}z| |  ||¡¡ W q< tjk
rz   t	j
ddd� Y q<X q<|sÒ|tjkrÒtj| }|  |¡}|rÎz|  ||¡ W n tk
rÌ   g  Y S X |}|S )NzAccount loading problemT)Úexc_info)r9   rW   r	   ÚlistdirÚOSErrorÚappendÚ_load_for_server_pathr   ÚAccountStorageErrorrB   rC   r   ÚLE_REUSE_SERVERSÚ_find_all_for_server_pathÚ_symlink_to_accounts_dir)r)   rU   rR   Ú
candidatesr=   rK   Úprev_server_pathZprev_accountsr   r   r   rh   ¢   s*    



z,AccountFileStorage._find_all_for_server_pathc                 C   s   |   | jj¡S r2   )rh   r9   rU   r.   r   r   r   rA   ½   s    zAccountFileStorage.find_allc                 C   s(   |   ||¡}|   ||¡}t ||¡ d S r2   )rT   r	   Úsymlink)r)   rk   rU   rK   Úprev_account_dirZnew_account_dirr   r   r   Ú_symlink_to_account_dirÀ   s    z*AccountFileStorage._symlink_to_account_dirc                 C   sJ   | j  |¡}tj |¡r$t |¡ n
t |¡ | j  |¡}t ||¡ d S r2   )r9   rW   r	   rX   ÚislinkÚunlinkÚrmdirrl   )r)   rk   rU   rR   rm   r   r   r   ri   Å   s    
z+AccountFileStorage._symlink_to_accounts_dirc              
   C   s:  |   ||¡}tj |¡s||tjkrntj| }|  ||¡}| j |¡}t 	|¡r^|  
|||¡ n|  ||¡ |S t d| ¡‚z‚t|  |¡ƒ�}tj | ¡ ¡}W 5 Q R X t|  |¡ƒ�}	tj |	 ¡ ¡}
W 5 Q R X t|  |¡ƒ�}tj | ¡ ¡}W 5 Q R X W n. tk
�r, } zt |¡‚W 5 d }~X Y nX t||
|ƒS )NúAccount at %s does not exist)rT   r	   rX   Úisdirr   rg   re   r9   rW   rb   rn   ri   r   rI   Úopenr^   r   ÚRegistrationResourceZ
json_loadsÚreadr_   r   ZJWKr`   r
   r   ÚIOErrorrf   )r)   rK   rU   r]   rk   Zprev_loaded_accountrR   Ú	regr_filer   Úkey_filer   Úmetadata_filer$   Úerrorr   r   r   re   Î   s.    


ÿz(AccountFileStorage._load_for_server_pathc                 C   s   |   || jj¡S r2   )re   r9   rU   rJ   r   r   r   rL   ì   s    zAccountFileStorage.loadc                 C   s   | j ||dd� d S )NF©Ú	regr_only©Ú_saverD   r   r   r   rG   ï   s    zAccountFileStorage.savec                 C   s   | j ||dd� dS )zmSave the registration resource.

        :param Account account: account whose regr should be saved

        Tr|   Nr~   )r)   rE   Úacmer   r   r   Ú	save_regrò   s    zAccountFileStorage.save_regrc                 C   sT   |   |¡}tj |¡s$t d| ¡‚|  || jj¡ t 	| jj
¡sP|  | jj¡ dS )znDelete registration info from disk

        :param account_id: id of account which should be deleted

        rr   N)rV   r	   rX   rs   r   rI   Ú#_delete_account_dir_for_server_pathr9   rU   rb   rR   Ú$_delete_accounts_dir_for_server_path)r)   rK   r]   r   r   r   Údeleteú   s    
ÿzAccountFileStorage.deletec                 C   s(   t  | j|¡}|  ||¡}t |¡ d S r2   )Ú	functoolsÚpartialrT   Ú!_delete_links_and_find_target_dirÚshutilÚrmtree)r)   rK   rU   Ú	link_funcÚnonsymlinked_dirr   r   r   r‚     s    z6AccountFileStorage._delete_account_dir_for_server_pathc                 C   s"   | j j}|  ||¡}t |¡ d S r2   )r9   rW   r‡   r	   rq   )r)   rU   rŠ   r‹   r   r   r   rƒ     s    z7AccountFileStorage._delete_accounts_dir_for_server_pathc           
      C   sœ   ||ƒ}i }t jD ]}||t j| < qd}|rrd}||kr*|| }||ƒ}tj |¡r*t |¡|kr*d}|}|}q*tj |¡r˜t |¡}	t |¡ |	}qr|S )a/  Delete symlinks and return the nonsymlinked directory path.

        :param str server_path: file path based on server
        :param callable link_func: callable that returns possible links
            given a server_path

        :returns: the final, non-symlinked target
        :rtype: str

        TF)r   rg   r	   rX   ro   Úreadlinkrp   )
r)   rU   rŠ   Zdir_pathZreused_serversÚkZpossible_next_linkZnext_server_pathZnext_dir_pathÚtargetr   r   r   r‡     s&    


z4AccountFileStorage._delete_links_and_find_target_dirc           
   
   C   s  |   |j¡}t |d| jj¡ zÈt|  |¡dƒ�L}|j}t	|j
dƒrZt|j
ji |jd�}ntji |jd�}| | ¡ ¡ W 5 Q R X |sätj|  |¡ddd��}| |j ¡ ¡ W 5 Q R X t|  |¡dƒ�}| |j ¡ ¡ W 5 Q R X W n. tk
�r }	 zt |	¡‚W 5 d }	~	X Y nX d S )NrP   Úwz	new-authz)rN   ÚbodyÚuri)r�   r‘   é   )Úchmod)rV   r(   r   rQ   r9   rS   rt   r^   r   ÚhasattrÚ	directoryrM   Z	new_authzr‘   r   ru   ÚwriteZ
json_dumpsZ	safe_openr_   r   r`   r$   rw   r   rf   )
r)   rE   r€   r}   r]   rx   r   ry   rz   r{   r   r   r   r   <  s@    ýþ ÿÿÿzAccountFileStorage._saveN)r   r   r   r   r*   rV   rT   Úclassmethodr^   r_   r`   rh   rA   rn   ri   re   rL   rG   r�   r„   r‚   rƒ   r‡   r   r   r   r   r   rO   …   s.   


	'rO   )&r   r   r…   r%   Úloggingrˆ   r"   Zjosepyr   r,   r   r?   Zzope.componentr7   Zcryptography.hazmat.primitivesr   r€   r   r   r   Zcertbotr   r   r   r   Zcertbot.compatr	   Ú	getLoggerr   rB   Úobjectr
   r;   ZAccountStorager<   ru   rM   rO   r   r   r   r   Ú<module>   s2   
;