o
    uvXj5  ã                   @   s*  d Z ddlZddlZddlZddlmZ ddlmZ ddlm	Z	m
Z
 ddlmZ ddlmZ ddlmZmZ dd	lmZ dd
lmZ ddlmZ e d¡ZdZdZdZdZdZdZdZ de  Z!ej"ej# Z$dZ%dd„ Z&dd„ Z'dd„ Z(dd„ Z)dd„ Z*d d!„ Z+d"d#„ Z,d$d%„ Z-d&d'„ Z.G d(d)„ d)eƒZ/dS )*z’
Cross Site Request Forgery Middleware.

This module provides a middleware that implements protection
against request forgeries from other sites.
é    N)Úurlparse)Úsettings)ÚDisallowedHostÚImproperlyConfigured)Úget_callable)Úpatch_vary_headers)Úconstant_time_compareÚget_random_string)ÚMiddlewareMixin)Úis_same_domain)Úlog_responsezdjango.security.csrfz%Referer checking failed - no Referer.z@Referer checking failed - %s does not match any trusted origins.zCSRF cookie not set.z CSRF token missing or incorrect.z/Referer checking failed - Referer is malformed.zCReferer checking failed - Referer is insecure while host is secure.é    é   Ú
_csrftokenc                   C   s
   t tjƒS )z/Return the view to be used for CSRF rejections.)r   r   ÚCSRF_FAILURE_VIEW© r   r   úS/var/www/html/myproject/venv/lib/python3.10/site-packages/django/middleware/csrf.pyÚ_get_failure_view$   s   
r   c                   C   s   t ttd�S )N)Úallowed_chars)r	   ÚCSRF_SECRET_LENGTHÚCSRF_ALLOWED_CHARSr   r   r   r   Ú_get_new_csrf_string)   s   r   c                    sP   t ƒ }t‰ t‡ fdd„| D ƒ‡ fdd„|D ƒƒ}d ‡ fdd„|D ƒ¡}|| S )z’
    Given a secret (assumed to be a string of CSRF_ALLOWED_CHARS), generate a
    token by adding a salt and using it to encrypt the secret.
    c                 3   ó   � | ]}ˆ   |¡V  qd S ©N©Úindex©Ú.0Úx©Úcharsr   r   Ú	<genexpr>4   ó   € z&_salt_cipher_secret.<locals>.<genexpr>Ú c                 3   s(   � | ]\}}ˆ || t ˆ ƒ  V  qd S r   )Úlen©r   r   Úyr   r   r   r!   5   s   €& )r   r   ÚzipÚjoin)ÚsecretÚsaltÚpairsÚcipherr   r   r   Ú_salt_cipher_secret-   s
   &r-   c                    s^   | dt … }| t d… } t‰ t‡ fdd„| D ƒ‡ fdd„|D ƒƒ}d ‡ fdd„|D ƒ¡}|S )zÑ
    Given a token (assumed to be a string of CSRF_ALLOWED_CHARS, of length
    CSRF_TOKEN_LENGTH, and that its first half is a salt), use it to decrypt
    the second half to produce the original secret.
    Nc                 3   r   r   r   r   r   r   r   r!   B   r"   z'_unsalt_cipher_token.<locals>.<genexpr>r#   c                 3   s    � | ]\}}ˆ ||  V  qd S r   r   r%   r   r   r   r!   C   s   € )r   r   r'   r(   )Útokenr*   r+   r)   r   r   r   Ú_unsalt_cipher_token9   s   &r/   c                   C   s
   t tƒ ƒS r   )r-   r   r   r   r   r   Ú_get_new_csrf_tokenG   s   
r0   c                 C   s@   d| j vrtƒ }t|ƒ| j d< nt| j d ƒ}d| j d< t|ƒS )aº  
    Return the CSRF token required for a POST form. The token is an
    alphanumeric value. A new token is created if one is not already set.

    A side effect of calling this function is to make the csrf_protect
    decorator and the CsrfViewMiddleware add a CSRF cookie and a 'Vary: Cookie'
    header to the outgoing response.  For this reason, you may need to use this
    function lazily, as is done by the csrf context processor.
    ÚCSRF_COOKIETÚCSRF_COOKIE_USED)ÚMETAr   r-   r/   )ÚrequestÚcsrf_secretr   r   r   Ú	get_tokenK   s   


r6   c                 C   s   | j  dtƒ dœ¡ d| _dS )zi
    Change the CSRF token in use for a request - should be done on login
    for security purposes.
    T)r2   r1   N)r3   Úupdater0   Úcsrf_cookie_needs_reset)r4   r   r   r   Úrotate_token^   s
   þ
r9   c                 C   s<   t  d| ¡r	tƒ S t| ƒtkr| S t| ƒtkrt| ƒS tƒ S )Nz[^a-zA-Z0-9])ÚreÚsearchr0   r$   ÚCSRF_TOKEN_LENGTHr   r-   )r.   r   r   r   Ú_sanitize_tokenj   s   r=   c                 C   s   t t| ƒt|ƒƒS r   )r   r/   )Úrequest_csrf_tokenÚ
csrf_tokenr   r   r   Ú_compare_salted_tokens{   s   þr@   c                   @   sH   e Zd ZdZdd„ Zdd„ Zdd„ Zdd	„ Zd
d„ Zdd„ Z	dd„ Z
dS )ÚCsrfViewMiddlewarezê
    Require a present and correct csrfmiddlewaretoken for POST requests that
    have a CSRF cookie, and set an outgoing CSRF cookie.

    This middleware should be used in conjunction with the {% csrf_token %}
    template tag.
    c                 C   s
   d|_ d S )NT)Úcsrf_processing_done)Úselfr4   r   r   r   Ú_acceptŽ   s   zCsrfViewMiddleware._acceptc                 C   s(   t ƒ ||d�}td||j||td� |S )N)ÚreasonzForbidden (%s): %s)Úresponser4   Úlogger)r   r   ÚpathrG   )rC   r4   rE   rF   r   r   r   Ú_reject•   s   üzCsrfViewMiddleware._rejectc                 C   s‚   t jr!z|j t¡W S  ty    tdt jd u rd ƒ‚d ƒ‚w z|jt j	 }W n
 t
y3   Y d S w t|ƒ}||kr?d|_|S )Nz†CSRF_USE_SESSIONS is enabled, but request.session is not set. SessionMiddleware must appear before CsrfViewMiddleware in MIDDLEWARE%s.Ú_CLASSESr#   T)r   ÚCSRF_USE_SESSIONSÚsessionÚgetÚCSRF_SESSION_KEYÚAttributeErrorr   Ú
MIDDLEWAREÚCOOKIESÚCSRF_COOKIE_NAMEÚKeyErrorr=   r8   )rC   r4   Úcookie_tokenr?   r   r   r   Ú
_get_tokenŸ   s,   þÿþÿÿÿzCsrfViewMiddleware._get_tokenc              
   C   sp   t jr|j t¡|jd kr|jd |jt< d S d S |jt j|jd t jt j	t j
t jt jt jd� t|dƒ d S )Nr1   )Úmax_ageÚdomainrH   ÚsecureÚhttponlyÚsamesite)ÚCookie)r   rK   rL   rM   rN   r3   Ú
set_cookierR   ÚCSRF_COOKIE_AGEÚCSRF_COOKIE_DOMAINÚCSRF_COOKIE_PATHÚCSRF_COOKIE_SECUREÚCSRF_COOKIE_HTTPONLYÚCSRF_COOKIE_SAMESITEr   ©rC   r4   rF   r   r   r   Ú
_set_token¶   s   ÿøzCsrfViewMiddleware._set_tokenc                 C   s$   |   |¡}|d ur||jd< d S d S )Nr1   )rU   r3   )rC   r4   r?   r   r   r   Úprocess_requestÈ   s   
þz"CsrfViewMiddleware.process_requestc                    sØ  t |ddƒrd S t |ddƒrd S |jdvrçt |ddƒr |  |¡S | ¡ r¢|j d¡‰ ˆ d u r4|  |t¡S tˆ ƒ‰ dˆ j	ˆ j
fv rF|  |t¡S ˆ j	dkrQ|  |t¡S tjrWtjntj}|d urm| ¡ }|d	vrld
||f }nz| ¡ }W n	 ty|   Y nw ttjƒ}|d ur‹| |¡ t‡ fdd„|D ƒƒs¢tˆ  ¡  }|  ||¡S |j d¡}	|	d u r²|  |t¡S d}
|jdkrÌz	|j dd¡}
W n	 tyË   Y nw |
dkrØ|j tjd¡}
t|
ƒ}
t|
|	ƒsç|  |t ¡S |  |¡S )NrB   FÚcsrf_exempt)ÚGETÚHEADÚOPTIONSÚTRACEÚ_dont_enforce_csrf_checksÚHTTP_REFERERr#   Úhttps)Ú443Ú80z%s:%sc                 3   s   � | ]	}t ˆ j|ƒV  qd S r   )r   Únetloc)r   Úhost©Úrefererr   r   r!     s   € z2CsrfViewMiddleware.process_view.<locals>.<genexpr>r1   ÚPOSTÚcsrfmiddlewaretoken)!ÚgetattrÚmethodrD   Ú	is_securer3   rM   rI   ÚREASON_NO_REFERERr   Úschemerp   ÚREASON_MALFORMED_REFERERÚREASON_INSECURE_REFERERr   rK   ÚSESSION_COOKIE_DOMAINr^   Úget_portÚget_hostr   ÚlistÚCSRF_TRUSTED_ORIGINSÚappendÚanyÚREASON_BAD_REFERERÚgeturlÚREASON_NO_CSRF_COOKIErt   ÚIOErrorÚCSRF_HEADER_NAMEr=   r@   ÚREASON_BAD_TOKEN)rC   r4   ÚcallbackÚcallback_argsÚcallback_kwargsÚgood_refererÚserver_portÚ
good_hostsrE   r?   r>   r   rr   r   Úprocess_viewÎ   sh   


ÿý€ÿ


ú

zCsrfViewMiddleware.process_viewc                 C   sD   t |ddƒst |ddƒr|S |j dd¡s|S |  ||¡ d|_|S )Nr8   FÚcsrf_cookie_setr2   T)rv   r3   rM   rd   r‘   rc   r   r   r   Úprocess_response;  s   z#CsrfViewMiddleware.process_responseN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__rD   rI   rU   rd   re   r�   r’   r   r   r   r   rA   „   s    	
mrA   )0r–   Úloggingr:   ÚstringÚurllib.parser   Údjango.confr   Údjango.core.exceptionsr   r   Údjango.urlsr   Údjango.utils.cacher   Údjango.utils.cryptor   r	   Údjango.utils.deprecationr
   Údjango.utils.httpr   Údjango.utils.logr   Ú	getLoggerrG   ry   r„   r†   r‰   r{   r|   r   r<   Úascii_lettersÚdigitsr   rN   r   r   r-   r/   r0   r6   r9   r=   r@   rA   r   r   r   r   Ú<module>   sD    
	