o
    uvXjï  ã                   @   sP   d dl mZ d dlmZ d dlmZmZ d dlmZm	Z	 G dd„ dƒZ
e
ƒ ZdS )é    )Údate)Úsettings)Úconstant_time_compareÚsalted_hmac)Úbase36_to_intÚint_to_base36c                   @   sJ   e Zd ZdZdZejZdd„ Zdd„ Z	dd„ Z
d	d
„ Zdd„ Zdd„ ZdS )ÚPasswordResetTokenGeneratorza
    Strategy object used to generate and check tokens for the password
    reset mechanism.
    z6django.contrib.auth.tokens.PasswordResetTokenGeneratorc                 C   s   |   ||  |  ¡ ¡¡S )zi
        Return a token that can be used once to do a password reset
        for the given user.
        )Ú_make_token_with_timestampÚ	_num_daysÚ_today)ÚselfÚuser© r   úW/var/www/html/myproject/venv/lib/python3.10/site-packages/django/contrib/auth/tokens.pyÚ
make_token   s   z&PasswordResetTokenGenerator.make_tokenc                 C   sŒ   |r|sdS z	|  d¡\}}W n
 ty   Y dS w zt|ƒ}W n
 ty*   Y dS w t|  ||¡|ƒs6dS |  |  ¡ ¡| tjkrDdS dS )zP
        Check that a password reset token is correct for a given user.
        Fú-T)	ÚsplitÚ
ValueErrorr   r   r	   r
   r   r   ÚPASSWORD_RESET_TIMEOUT_DAYS)r   r   ÚtokenÚts_b36Ú_Útsr   r   r   Úcheck_token   s"   ÿÿz'PasswordResetTokenGenerator.check_tokenc                 C   s<   t |ƒ}t| j|  ||¡| jd� ¡ d d d… }d||f S )N)Úsecreté   z%s-%s)r   r   Úkey_saltÚ_make_hash_valuer   Ú	hexdigest)r   r   Ú	timestampr   Úhash_stringr   r   r   r	   6   s   
ýüz6PasswordResetTokenGenerator._make_token_with_timestampc                 C   s>   |j du rdn|j jddd�}t|jƒ|j t|ƒ t|ƒ S )a­  
        Hash the user's primary key and some user state that's sure to change
        after a password reset to produce a token that invalidated when it's
        used:
        1. The password field will change upon a password reset (even if the
           same password is chosen, due to password salting).
        2. The last_login field will usually be updated very shortly after
           a password reset.
        Failing those things, settings.PASSWORD_RESET_TIMEOUT_DAYS eventually
        invalidates the token.

        Running this data through salted_hmac() prevents password cracking
        attempts using the reset token, provided the secret isn't compromised.
        NÚ r   )ÚmicrosecondÚtzinfo)Ú
last_loginÚreplaceÚstrÚpkÚpassword)r   r   r   Úlogin_timestampr   r   r   r   A   s    z,PasswordResetTokenGenerator._make_hash_valuec                 C   s   |t dddƒ jS )NiÑ  é   )r   Údays)r   Údtr   r   r   r
   U   s   z%PasswordResetTokenGenerator._num_daysc                 C   s   t  ¡ S )N)r   Útoday)r   r   r   r   r   X   s   z"PasswordResetTokenGenerator._todayN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r   Ú
SECRET_KEYr   r   r   r	   r   r
   r   r   r   r   r   r      s    r   N)Údatetimer   Údjango.confr   Údjango.utils.cryptor   r   Údjango.utils.httpr   r   r   Údefault_token_generatorr   r   r   r   Ú<module>   s    
U