U
    ÔZjV  ã                   @   s€   d Z ddlZddlmZ ddlmZ ddlmZ ddlm	Z	 ddl
mZ ddlmZ dd	lmZ e e¡ZG d
d„ dejƒZdS )z2A class that performs HTTP-01 challenges for Nginxé    N)Ú
challenges)ÚList)Úerrors)Úos)Úcommon)Úobj)Únginxparserc                       sX   e Zd ZdZ‡ fdd„Zdd„ Zdd„ Zdd	„ Zd
d„ Zdd„ Z	dd„ Z
dd„ Z‡  ZS )ÚNginxHttp01aÞ  HTTP-01 authenticator for Nginx

    :ivar configurator: NginxConfigurator object
    :type configurator: :class:`~nginx.configurator.NginxConfigurator`

    :ivar list achalls: Annotated
        class:`~certbot.achallenges.KeyAuthorizationAnnotatedChallenge`
        challenges

    :param list indices: Meant to hold indices of challenges in a
        larger array. NginxHttp01 is capable of solving many challenges
        at once which causes an indexing issue within NginxConfigurator
        who must return all responses in order. Imagine
        NginxConfigurator maintaining state about where all of the
        challenges, possibly of different types, belong in the response
        array. This is an optional utility.

    c                    s(   t t| ƒ |¡ tj |jjd¡| _d S )Nzle_http_01_cert_challenge.conf)	Úsuperr	   Ú__init__r   ÚpathÚjoinÚconfigZ
config_dirÚchallenge_conf)ÚselfÚconfigurator©Ú	__class__© úX/var/www/html/TRUCKING_PROJECT/venv/lib/python3.8/site-packages/certbot_nginx/http_01.pyr   '   s
     ÿzNginxHttp01.__init__c                 C   s4   | j s
g S dd„ | j D ƒ}|  ¡  | j dd¡ |S )z‡Perform a challenge on Nginx.

        :returns: list of :class:`certbot.acme.challenges.HTTP01Response`
        :rtype: list

        c                 S   s   g | ]}|  |j¡‘qS r   )ÚresponseÚaccount_key©Ú.0Úxr   r   r   Ú
<listcomp>6   s     z'NginxHttp01.perform.<locals>.<listcomp>zHTTP ChallengeT)ÚachallsÚ_mod_configr   Úsave)r   Ú	responsesr   r   r   Úperform,   s    zNginxHttp01.performc              	      sX  d}dddˆ j g}ˆ jjj}ddddg}ˆ jjj| }|D ]”}|d dgkr:|d	 }d}d}	|D ]@}
|
d |d	 kr˜t|
d	 ƒt|d
 ƒk r”|||	< d}|	d	7 }	q`|s²| d|¡ ||krÆ| d|¡ d} qÐq:|sât d| ¡‚‡ fdd„ˆ j	D ƒ}dd„ |D ƒ}t
 |¡}t dt|ƒ¡ ˆ jj dˆ j ¡ tˆ j dƒ�}t
 ||¡ W 5 Q R X dS )a  Modifies Nginx config to include server_names_hash_bucket_size directive
           and server challenge blocks.

        :raises .MisconfigurationError:
            Unable to find a suitable HTTP block in which to include
            authenticator hosts.
        FÚ
Úincludeú Zserver_names_hash_bucket_sizeZ128r   Úhttpé   é   Tz;Certbot could not find a block to include challenges in %s.c                    s   g | ]}ˆ   |¡‘qS r   )Ú_make_or_mod_server_block)r   Úachall©r   r   r   r   d   s     z+NginxHttp01._mod_config.<locals>.<listcomp>c                 S   s   g | ]}|d k	r|‘qS )Nr   r   r   r   r   r   e   s      zGenerated server block:
%sÚwN)r   r   ÚparserZconfig_rootÚparsedÚintÚinsertr   ÚMisconfigurationErrorr   r   ZUnspacedListÚloggerÚdebugÚstrZreverterZregister_file_creationÚopenÚdump)r   ZincludedZinclude_directiveÚrootZbucket_directiveÚmainÚlineÚbodyZfound_bucketZposnZ
inner_liner   Znew_confr   r)   r   r   @   sL    

ÿÿ
 ÿzNginxHttp01._mod_configc                 C   s’   g }d| j jj }d | j jj¡}| j jj}| j  |¡\}}|rt|sL|d }tj |¡tj |¡g}t 	d||¡ ntj |¡g}t 	d|¡ |S )z”Finds addresses for a challenge block to listen on.
        :returns: list of :class:`certbot_nginx.obj.Addr` to apply
        :rtype: list
        z%sz[::]:{0}z ipv6only=onz5Using default addresses %s and %s for authentication.z,Using default address %s for authentication.)
r   r   Úhttp01_portÚformatZ	ipv6_infor   ZAddrÚ
fromstringr0   Úinfo)r   Ú	addressesZdefault_addrZ	ipv6_addrÚportZipv6Zipv6onlyr   r   r   Ú_default_listen_addresseso   s,    ÿ


ÿþÿz%NginxHttp01._default_listen_addressesc                 C   s    t jt j tjj|j d¡¡ S )NÚtoken)	r   Úsepr   r   r   ZHTTP01ZURI_ROOT_PATHZchallÚencode)r   r(   r   r   r   Ú_get_validation_pathŒ   s    z NginxHttp01._get_validation_pathc                 C   sX   |   ¡ }dd„ |D ƒ}tj | jjjd¡}| dd|jgdd|g|  	|¡g¡ dg|gS )a…  Creates a server block for a challenge.
        :param achall: Annotated HTTP-01 challenge
        :type achall:
            :class:`certbot.achallenges.KeyAuthorizationAnnotatedChallenge`
        :param list addrs: addresses of challenged domain
            :class:`list` of type :class:`~nginx.obj.Addr`
        :returns: server block for the challenge host
        :rtype: list
        c                 S   s   g | ]}d d|j dd�g‘qS )Úlistenr#   F)Úinclude_default)Z	to_string)r   Úaddrr   r   r   r   š   s     z2NginxHttp01._make_server_block.<locals>.<listcomp>Zhttp_01_nonexistentZserver_namer#   r5   Úserver)
r?   r   r   r   r   r   Zwork_dirÚextendÚdomainÚ_location_directive_for_achall)r   r(   ÚaddrsÚblockZdocument_rootr   r   r   Ú_make_server_block�   s    
 ÿþzNginxHttp01._make_server_blockc                 C   s@   |  |j¡}|  |¡}dddd|gdddgdddd|ggg}|S )NÚlocationr#   ú=Zdefault_typez
text/plainÚreturnZ200)Ú
validationr   rC   )r   r(   rQ   Zvalidation_pathÚlocation_directiver   r   r   rJ   §   s    
ÿÿz*NginxHttp01._location_directive_for_achallc                 C   s”   z"| j j|jd| j jj dd�}W n  tjk
rB   |  |¡ Y S X |d }|  |¡g}| j j	 
||¡ ddddddd	gg}| j j	j
||dd
� dS )zÒModifies a server block to respond to a challenge.

        :param achall: Annotated HTTP-01 challenge
        :type achall:
            :class:`certbot.achallenges.KeyAuthorizationAnnotatedChallenge`

        z%iT)Zcreate_if_no_matchr   Zrewriter#   z!^(/.well-known/acme-challenge/.*)z$1Úbreak)Zinsert_at_topN)r   Zchoose_redirect_vhostsrI   r   r9   r   r/   rM   rJ   r+   Zadd_server_directives)r   r(   ZvhostsZvhostrR   Zrewrite_directiver   r   r   r'   ±   s.    
 ÿ

ÿ   ÿ
 ÿz%NginxHttp01._make_or_mod_server_block)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r    r   r?   rC   rM   rJ   r'   Ú__classcell__r   r   r   r   r	      s   /
r	   )rW   ÚloggingZacmer   Zacme.magic_typingr   Zcertbotr   Zcertbot.compatr   Zcertbot.pluginsr   Zcertbot_nginxr   r   Ú	getLoggerrT   r0   ZChallengePerformerr	   r   r   r   r   Ú<module>   s   
