o
    uvXjo.  ã                   @   s¶   d dl Z d dlZd dlZd dlmZmZ d dlmZ d dlmZ d dl	m
Z
 d dlmZ d dlmZmZmZ d dlmZ ejej ZG d	d
„ d
eƒZG dd„ deƒZG dd„ dƒZdS )é    N)ÚdatetimeÚ	timedelta)Úsettings)ÚSuspiciousSession)ÚSuspiciousOperation)Útimezone)Úconstant_time_compareÚget_random_stringÚsalted_hmac)Úimport_stringc                   @   ó   e Zd ZdZdS )ÚCreateErrorz‡
    Used internally as a consistent exception type to catch from save (see the
    docstring for SessionBase.save() for details).
    N©Ú__name__Ú
__module__Ú__qualname__Ú__doc__© r   r   úb/var/www/html/myproject/venv/lib/python3.10/site-packages/django/contrib/sessions/backends/base.pyr      s    r   c                   @   r   )ÚUpdateErrorzF
    Occurs if Django tries to update a session that was deleted.
    Nr   r   r   r   r   r      s    r   c                   @   s‚  e Zd ZdZdZdZeƒ ZdTdd„Zdd„ Z	d	d
„ Z
dd„ Zdd„ ZdTdd„Zefdd„Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd „ Zd!d"„ Zd#d$„ Zd%d&„ Zd'd(„ Zd)d*„ Zd+d,„ Zd-d.„ Zd/d0„ Zd1d2„ Zd3d4„ Zd5d6„ Z d7d8„ Z!e"e ƒZ#e"e e!ƒZ$dUd:d;„Z%e"e%ƒZ&d<d=„ Z'd>d?„ Z(d@dA„ Z)dBdC„ Z*dDdE„ Z+dFdG„ Z,dHdI„ Z-dJdK„ Z.dUdLdM„Z/dTdNdO„Z0dPdQ„ Z1e2dRdS„ ƒZ3dS )VÚSessionBasez-
    Base class for all Session classes.
    Ú
testcookieÚworkedNc                 C   s"   || _ d| _d| _ttjƒ| _d S )NF)Ú_session_keyÚaccessedÚmodifiedr   r   ÚSESSION_SERIALIZERÚ
serializer©ÚselfÚsession_keyr   r   r   Ú__init__,   s   zSessionBase.__init__c                 C   ó
   || j v S ©N©Ú_session©r   Úkeyr   r   r   Ú__contains__2   ó   
zSessionBase.__contains__c                 C   s
   | j | S r#   r$   r&   r   r   r   Ú__getitem__5   r)   zSessionBase.__getitem__c                 C   s   || j |< d| _d S ©NT©r%   r   ©r   r'   Úvaluer   r   r   Ú__setitem__8   s   

zSessionBase.__setitem__c                 C   s   | j |= d| _d S r+   r,   r&   r   r   r   Ú__delitem__<   s   
zSessionBase.__delitem__c                 C   s   | j  ||¡S r#   )r%   Úget)r   r'   Údefaultr   r   r   r1   @   s   zSessionBase.getc                 C   s:   | j p|| jv | _ || ju rdn|f}| jj|g|¢R Ž S )Nr   )r   r%   Ú_SessionBase__not_givenÚpop)r   r'   r2   Úargsr   r   r   r4   C   s   zSessionBase.popc                 C   s(   || j v r
| j | S d| _|| j |< |S r+   r,   r-   r   r   r   Ú
setdefaultH   s
   


zSessionBase.setdefaultc                 C   s   | j | | j< d S r#   )ÚTEST_COOKIE_VALUEÚTEST_COOKIE_NAME©r   r   r   r   Úset_test_cookieP   s   zSessionBase.set_test_cookiec                 C   s   |   | j¡| jkS r#   )r1   r8   r7   r9   r   r   r   Útest_cookie_workedS   s   zSessionBase.test_cookie_workedc                 C   s   | | j = d S r#   )r8   r9   r   r   r   Údelete_test_cookieV   s   zSessionBase.delete_test_cookiec                 C   s   d| j j }t||ƒ ¡ S )Nzdjango.contrib.sessions)Ú	__class__r   r
   Ú	hexdigest)r   r.   Úkey_saltr   r   r   Ú_hashY   s   zSessionBase._hashc                 C   s4   |   ¡  |¡}|  |¡}t | ¡ d | ¡ d¡S )zGReturn the given session dictionary serialized and encoded as a string.ó   :Úascii)r   Údumpsr@   Úbase64Ú	b64encodeÚencodeÚdecode)r   Úsession_dictÚ
serializedÚhashr   r   r   rF   ]   s   
zSessionBase.encodec              
   C   s¤   t  | d¡¡}z | dd¡\}}|  |¡}t| ¡ |ƒs!tdƒ‚|  ¡  	|¡W S  t
yQ } zt|tƒrEt d|jj ¡}| t|ƒ¡ i W  Y d }~S d }~ww )NrB   rA   é   zSession data corruptedzdjango.security.%s)rD   Ú	b64decoderF   Úsplitr@   r   rG   r   r   ÚloadsÚ	ExceptionÚ
isinstancer   ÚloggingÚ	getLoggerr=   r   ÚwarningÚstr)r   Úsession_dataÚencoded_datarJ   rI   Úexpected_hashÚeÚloggerr   r   r   rG   c   s   

€úzSessionBase.decodec                 C   s   | j  |¡ d| _d S r+   )r%   Úupdater   )r   Údict_r   r   r   rZ   u   s   
zSessionBase.updatec                 C   r"   r#   r$   r&   r   r   r   Úhas_keyy   r)   zSessionBase.has_keyc                 C   ó
   | j  ¡ S r#   )r%   Úkeysr9   r   r   r   r^   |   r)   zSessionBase.keysc                 C   r]   r#   )r%   Úvaluesr9   r   r   r   r_      r)   zSessionBase.valuesc                 C   r]   r#   )r%   Úitemsr9   r   r   r   r`   ‚   r)   zSessionBase.itemsc                 C   s   i | _ d| _d| _d S r+   )Ú_session_cacher   r   r9   r   r   r   Úclear…   s   
zSessionBase.clearc                 C   s(   z	| j  o| j W S  ty   Y dS w )zBReturn True when there is no session_key and the session is empty.T)r   ra   ÚAttributeErrorr9   r   r   r   Úis_empty�   s
   ÿzSessionBase.is_emptyc                 C   s   	 t dtƒ}|  |¡s|S q)z)Return session key that isn't being used.Té    )r	   ÚVALID_KEY_CHARSÚexistsr   r   r   r   Ú_get_new_session_key”   s
   

ýz SessionBase._get_new_session_keyc                 C   s   | j d u r
|  ¡ | _ | j S r#   )r   rh   r9   r   r   r   Ú_get_or_create_session_key›   s   

z&SessionBase._get_or_create_session_keyc                 C   s   |ot |ƒdkS )z”
        Key must be truthy and at least 8 characters long. 8 characters is an
        arbitrary lower bound for some minimal key security.
        é   )Úlenr&   r   r   r   Ú_validate_session_key    s   z!SessionBase._validate_session_keyc                 C   s   | j S r#   )Ú_SessionBase__session_keyr9   r   r   r   Ú_get_session_key§   s   zSessionBase._get_session_keyc                 C   s   |   |¡r
|| _dS d| _dS )zV
        Validate session key on assignment. Invalid values will set to None.
        N)rl   rm   ©r   r.   r   r   r   Ú_set_session_keyª   s   


zSessionBase._set_session_keyFc                 C   sL   d| _ z| jW S  ty%   | jdu s|ri | _Y | jS |  ¡ | _Y | jS w )zž
        Lazily load session from storage (unless "no_load" is True, when only
        an empty dict is stored) and store it in the current instance.
        TN)r   ra   rc   r    Úload)r   Úno_loadr   r   r   Ú_get_session¶   s   ÿûzSessionBase._get_sessionc                 K   s‚   z|d }W n t y   t ¡ }Y nw z|d }W n t y(   |  d¡}Y nw |s.tjS t|tƒs5|S || }|jd |j	 S )zÕGet the number of seconds until the session expires.

        Optionally, this function accepts `modification` and `expiry` keyword
        arguments specifying the modification and expiry of the session.
        ÚmodificationÚexpiryÚ_session_expiryi€Q )
ÚKeyErrorr   Únowr1   r   ÚSESSION_COOKIE_AGErP   r   ÚdaysÚseconds)r   Úkwargsrt   ru   Údeltar   r   r   Úget_expiry_ageÇ   s    ÿÿ
zSessionBase.get_expiry_agec                 K   sx   z|d }W n t y   t ¡ }Y nw z|d }W n t y(   |  d¡}Y nw t|tƒr0|S |p4tj}|t|d� S )zÔGet session the expiry date (as a datetime object).

        Optionally, this function accepts `modification` and `expiry` keyword
        arguments specifying the modification and expiry of the session.
        rt   ru   rv   )r{   )	rw   r   rx   r1   rP   r   r   ry   r   )r   r|   rt   ru   r   r   r   Úget_expiry_dateà   s   ÿÿ

zSessionBase.get_expiry_datec                 C   sL   |du rz| d= W dS  t y   Y dS w t|tƒr t ¡ | }|| d< dS )a*  
        Set a custom expiration for the session. ``value`` can be an integer,
        a Python ``datetime`` or ``timedelta`` object or ``None``.

        If ``value`` is an integer, the session will expire after that many
        seconds of inactivity. If set to ``0`` then the session will expire on
        browser close.

        If ``value`` is a ``datetime`` or ``timedelta`` object, the session
        will expire at that specific future time.

        If ``value`` is ``None``, the session uses the global session expiry
        policy.
        Nrv   )rw   rP   r   r   rx   ro   r   r   r   Ú
set_expiryõ   s   þþ
zSessionBase.set_expiryc                 C   s"   |   d¡du r
tjS |   d¡dkS )a  
        Return ``True`` if the session is set to expire when the browser
        closes, and ``False`` if there's an expiry date. Use
        ``get_expiry_date()`` or ``get_expiry_age()`` to find the actual expiry
        date/age, if there is one.
        rv   Nr   )r1   r   ÚSESSION_EXPIRE_AT_BROWSER_CLOSEr9   r   r   r   Úget_expire_at_browser_close  s   z'SessionBase.get_expire_at_browser_closec                 C   s   |   ¡  |  ¡  d| _dS )zc
        Remove the current session data from the database and regenerate the
        key.
        N)rb   Údeleter   r9   r   r   r   Úflush  s   
zSessionBase.flushc                 C   s0   | j }| j}|  ¡  || _|r|  |¡ dS dS )zU
        Create a new session key, while retaining the current session data.
        N)r%   r    Úcreatera   rƒ   )r   Údatar'   r   r   r   Ú	cycle_key#  s   ÿzSessionBase.cycle_keyc                 C   ó   t dƒ‚)zF
        Return True if the given session_key already exists.
        z9subclasses of SessionBase must provide an exists() method©ÚNotImplementedErrorr   r   r   r   rg   0  ó   zSessionBase.existsc                 C   rˆ   )zÅ
        Create a new session instance. Guaranteed to create a new object with
        a unique key and will have saved the result once (with empty data)
        before the method returns.
        z8subclasses of SessionBase must provide a create() methodr‰   r9   r   r   r   r…   6  ó   zSessionBase.createc                 C   rˆ   )zä
        Save the session data. If 'must_create' is True, create a new session
        object (or raise CreateError). Otherwise, only update an existing
        object and don't create one (raise UpdateError if needed).
        z6subclasses of SessionBase must provide a save() methodr‰   )r   Úmust_creater   r   r   Úsave>  rŒ   zSessionBase.savec                 C   rˆ   )zx
        Delete the session data under this key. If the key is None, use the
        current session key value.
        z8subclasses of SessionBase must provide a delete() methodr‰   r   r   r   r   rƒ   F  s   zSessionBase.deletec                 C   rˆ   )z@
        Load the session data and return a dictionary.
        z6subclasses of SessionBase must provide a load() methodr‰   r9   r   r   r   rq   M  r‹   zSessionBase.loadc                 C   rˆ   )a  
        Remove expired sessions from the session store.

        If this operation isn't possible on a given backend, it should raise
        NotImplementedError. If it isn't necessary, because the backend has
        a built-in expiration mechanism, it should be a no-op.
        z.This backend does not support clear_expired().r‰   )Úclsr   r   r   Úclear_expiredS  s   	zSessionBase.clear_expiredr#   )F)4r   r   r   r   r8   r7   Úobjectr3   r!   r(   r*   r/   r0   r1   r4   r6   r:   r;   r<   r@   rF   rG   rZ   r\   r^   r_   r`   rb   rd   rh   ri   rl   rn   rp   Úpropertyr    r   rs   r%   r~   r   r€   r‚   r„   r‡   rg   r…   rŽ   rƒ   rq   Úclassmethodr�   r   r   r   r   r   #   s`    

	

	

r   )rD   rQ   Ústringr   r   Údjango.confr   Ú"django.contrib.sessions.exceptionsr   Údjango.core.exceptionsr   Údjango.utilsr   Údjango.utils.cryptor   r	   r
   Údjango.utils.module_loadingr   Úascii_lowercaseÚdigitsrf   rO   r   r   r   r   r   r   r   Ú<module>   s    