o
    wvXj   ã                   @   s¶   d Z ddlZddlZddlmZmZ ddlmZ ddlm	Z
 ddlmZmZ dd„ ZG d	d
„ d
eƒZG dd„ dƒZG dd„ deƒZG dd„ deƒZG dd„ deƒZG dd„ deƒZdS )z+
Provides various authentication policies.
é    N)ÚauthenticateÚget_user_model)ÚCsrfViewMiddleware)Úgettext_lazy)ÚHTTP_HEADER_ENCODINGÚ
exceptionsc                 C   s&   | j  dd¡}t|tƒr| t¡}|S )z‰
    Return request's 'Authorization:' header, as a bytestring.

    Hide some test client ickyness where the header can be unicode.
    ÚHTTP_AUTHORIZATIONó    )ÚMETAÚgetÚ
isinstanceÚstrÚencoder   )ÚrequestÚauth© r   úZ/var/www/html/myproject/venv/lib/python3.10/site-packages/rest_framework/authentication.pyÚget_authorization_header   s   

r   c                   @   s   e Zd Zdd„ ZdS )Ú	CSRFCheckc                 C   s   |S ©Nr   )Úselfr   Úreasonr   r   r   Ú_reject   s   zCSRFCheck._rejectN)Ú__name__Ú
__module__Ú__qualname__r   r   r   r   r   r      s    r   c                   @   ó    e Zd ZdZdd„ Zdd„ ZdS )ÚBaseAuthenticationzF
    All authentication classes should extend BaseAuthentication.
    c                 C   s   t dƒ‚)zS
        Authenticate the request and return a two-tuple of (user, token).
        z#.authenticate() must be overridden.)ÚNotImplementedError©r   r   r   r   r   r   &   s   zBaseAuthentication.authenticatec                 C   s   dS )zç
        Return a string to be used as the value of the `WWW-Authenticate`
        header in a `401 Unauthenticated` response, or `None` if the
        authentication scheme should return `403 Permission Denied` responses.
        Nr   r   r   r   r   Úauthenticate_header,   s   z&BaseAuthentication.authenticate_headerN)r   r   r   Ú__doc__r   r    r   r   r   r   r   !   s    r   c                   @   s.   e Zd ZdZdZdd„ Zd
dd„Zdd	„ ZdS )ÚBasicAuthenticationz>
    HTTP Basic authentication against username/password.
    Úapic              
   C   sÈ   t |ƒ ¡ }|r|d  ¡ dkrdS t|ƒdkr!tdƒ}t |¡‚t|ƒdkr0tdƒ}t |¡‚zt |d ¡ 	t
¡ d¡}W n tttjfyS   td	ƒ}t |¡‚w |d |d }}|  |||¡S )
zœ
        Returns a `User` if a correct username and password have been supplied
        using HTTP Basic authentication.  Otherwise returns `None`.
        r   s   basicNé   z.Invalid basic header. No credentials provided.é   zCInvalid basic header. Credentials string should not contain spaces.ú:z?Invalid basic header. Credentials not correctly base64 encoded.)r   ÚsplitÚlowerÚlenÚ_r   ÚAuthenticationFailedÚbase64Ú	b64decodeÚdecoder   Ú	partitionÚ	TypeErrorÚUnicodeDecodeErrorÚbinasciiÚErrorÚauthenticate_credentials)r   r   r   ÚmsgÚ
auth_partsÚuseridÚpasswordr   r   r   r   ;   s"   


þz BasicAuthentication.authenticateNc                 C   sT   t ƒ j|d|i}tdd|i|¤Ž}|du rt tdƒ¡‚|js&t tdƒ¡‚|dfS )z
        Authenticate the userid and password against username and password
        with optional request for context.
        r8   r   NzInvalid username/password.úUser inactive or deleted.r   )r   ÚUSERNAME_FIELDr   r   r+   r*   Ú	is_active)r   r7   r8   r   ÚcredentialsÚuserr   r   r   r4   U   s   þz,BasicAuthentication.authenticate_credentialsc                 C   s
   d| j  S )NzBasic realm="%s")Úwww_authenticate_realmr   r   r   r   r    h   s   
z'BasicAuthentication.authenticate_headerr   )r   r   r   r!   r>   r   r4   r    r   r   r   r   r"   5   s    
r"   c                   @   r   )ÚSessionAuthenticationz<
    Use Django's session framework for authentication.
    c                 C   s.   t |jddƒ}|r|jsdS |  |¡ |dfS )z{
        Returns a `User` if the request session currently has a logged in user.
        Otherwise returns `None`.
        r=   N)ÚgetattrÚ_requestr;   Úenforce_csrf©r   r   r=   r   r   r   r   q   s
   

z"SessionAuthentication.authenticatec                 C   s6   t ƒ }| |¡ | |ddi ¡}|rt d| ¡‚dS )zK
        Enforce CSRF validation for session based authentication.
        Nr   zCSRF Failed: %s)r   Úprocess_requestÚprocess_viewr   ÚPermissionDenied)r   r   Úcheckr   r   r   r   rB   ƒ   s   
þz"SessionAuthentication.enforce_csrfN)r   r   r   r!   r   rB   r   r   r   r   r?   l   s    r?   c                   @   s:   e Zd ZdZdZdZdd„ Z	 dd„ Zdd	„ Zd
d„ Z	dS )ÚTokenAuthenticationa  
    Simple token based authentication.

    Clients should authenticate by passing the token key in the "Authorization"
    HTTP header, prepended with the string "Token ".  For example:

        Authorization: Token 401f7ac837da42b97f613d789819ff93537bee6a
    ÚTokenNc                 C   s    | j d ur| j S ddlm} |S )Nr   )rI   )ÚmodelÚrest_framework.authtoken.modelsrI   )r   rI   r   r   r   Ú	get_model�   s   
zTokenAuthentication.get_modelc                 C   s¦   t |ƒ ¡ }|r|d  ¡ | j ¡  ¡ krd S t|ƒdkr&tdƒ}t |¡‚t|ƒdkr5tdƒ}t |¡‚z|d  	¡ }W n t
yM   tdƒ}t |¡‚w |  |¡S )Nr   r$   z.Invalid token header. No credentials provided.r%   z=Invalid token header. Token string should not contain spaces.zIInvalid token header. Token string should not contain invalid characters.)r   r'   r(   Úkeywordr   r)   r*   r   r+   r.   ÚUnicodeErrorr4   )r   r   r   r5   Útokenr   r   r   r   ª   s    


þ
z TokenAuthentication.authenticatec                 C   s`   |   ¡ }z|j d¡j|d�}W n |jy   t tdƒ¡‚w |jj	s+t tdƒ¡‚|j|fS )Nr=   )ÚkeyzInvalid token.r9   )
rL   ÚobjectsÚselect_relatedr   ÚDoesNotExistr   r+   r*   r=   r;   )r   rP   rJ   rO   r   r   r   r4   ¿   s   ÿ
z,TokenAuthentication.authenticate_credentialsc                 C   s   | j S r   )rM   r   r   r   r   r    Ë   s   z'TokenAuthentication.authenticate_header)
r   r   r   r!   rM   rJ   rL   r   r4   r    r   r   r   r   rH   �   s    	rH   c                   @   s   e Zd ZdZdZdd„ ZdS )ÚRemoteUserAuthenticationa  
    REMOTE_USER authentication.

    To use this, set up your web server to perform authentication, which will
    set the REMOTE_USER environment variable. You will need to have
    'django.contrib.auth.backends.RemoteUserBackend in your
    AUTHENTICATION_BACKENDS setting
    ÚREMOTE_USERc                 C   s.   t |j | j¡d�}|r|jr|d fS d S d S )N)Úremote_user)r   r
   r   Úheaderr;   rC   r   r   r   r   Þ   s   
ÿz%RemoteUserAuthentication.authenticateN)r   r   r   r!   rW   r   r   r   r   r   rT   Ï   s    rT   )r!   r,   r2   Údjango.contrib.authr   r   Údjango.middleware.csrfr   Údjango.utils.translationr   r*   Úrest_frameworkr   r   r   r   r   r"   r?   rH   rT   r   r   r   r   Ú<module>   s    7$?