File manager - Edit - /opt/saltstack/salt/lib/python3.10/site-packages/urllib3/util/__pycache__/ssl_match_hostname.cpython-310.pyc
Back
o ;jg � @ s� d Z ddlmZ ddlZddlZddlZddlmZmZ ejr%ddl m Z dZG dd � d e�Z d!d"dd�Zd#dd�Z d$d%dd �ZdS )&zHThe match_hostname() function from Python 3.5, essential when using SSL.� )�annotationsN)�IPv4Address�IPv6Address� )�_TYPE_PEER_CERT_RET_DICTz3.5.0.1c @ s e Zd ZdS )�CertificateErrorN)�__name__� __module__�__qualname__� r r �S/opt/saltstack/salt/lib/python3.10/site-packages/urllib3/util/ssl_match_hostname.pyr s r �dn� typing.Any�hostname�str� max_wildcards�int�return�typing.Match[str] | None | boolc C s� g }| sdS | � d�}|d }|dd� }|�d�}||kr&tdt| � ��|s2t| �� |�� k�S |dkr<|�d� n|�d �sF|�d �rO|�t� |�� n|�t� |�� d d�� |D ] }|�t� |�� q]t�dd �|� d tj �} | �|�S )zhMatching according to RFC 6125, section 6.4.3 http://tools.ietf.org/html/rfc6125#section-6.4.3 F�.r r N�*z,too many wildcards in certificate DNS name: z[^.]+zxn--z\*z[^.]*z\Az\.z\Z)�split�countr �repr�bool�lower�append� startswith�re�escape�replace�compile�join� IGNORECASE�match) r r r Zpats�partsZleftmost� remainder� wildcards�frag�patr r r �_dnsname_match s, � r* �ipname�host_ip�IPv4Address | IPv6Addressr c C s t �| �� �}t|j|jk�S )a� Exact matching of IP addresses. RFC 9110 section 4.3.5: "A reference identity of IP-ID contains the decoded bytes of the IP address. An IP version 4 address is 4 octets, and an IP version 6 address is 16 octets. [...] A reference identity of type IP-ID matches if the address is identical to an iPAddress value of the subjectAltName extension of the certificate." )� ipaddress� ip_address�rstripr �packed)r+ r, �ipr r r �_ipaddress_matchP s r3 F�cert�_TYPE_PEER_CERT_RET_DICT | None�hostname_checks_common_name�Nonec C sN | st d��zt�|�}W n t y d}Y nw g }| �dd�}|D ]/\}}|dkr=|du r7t||�r7 dS |�|� q#|dkrR|durMt||�rM dS |�|� q#|r}|du r}|s}| �dd�D ]}|D ]\}}|dkr{t||�rv dS |�|� qeqat|�d kr�td |d� t t|��f ��t|�d kr�td|�d |d ����td��)a) Verify that *cert* (in decoded format as returned by SSLSocket.getpeercert()) matches the *hostname*. RFC 2818 and RFC 6125 rules are followed, but IP addresses are not accepted for *hostname*. CertificateError is raised on failure. On success, the function returns nothing. ztempty or no certificate, match_hostname needs a SSL socket or SSL context with either CERT_OPTIONAL or CERT_REQUIREDN�subjectAltNamer �DNSz IP Address�subject� commonNamer z&hostname %r doesn't match either of %sz, z hostname z doesn't match r z/no appropriate subjectAltName fields were found)� ValueErrorr. r/ �getr* r r3 �lenr r"