a ‚oeªJã@sòdZddlZddlZddlZddlZddlmZddlmZddlmZddlm Z ddl m Z ddl Z ddl mZdd l mZdd lmZdd lmZdd lmZe e¡ZGd d„dejƒZGdd„dƒZeddœdd„Zeedœdd„ZdS)z$Certbot user-supplied configuration.éN)ÚAny)ÚDict)ÚList)ÚOptional)Úparse)Úerrors)Úutil)Ú constants)Úmisc)Úosc@s8eZdZdZe ¡Ze ¡Ze ¡Ze ¡Z e ¡Z dS)ÚArgumentSourcez;Enum for describing where a configuration argument was set.N) Ú__name__Ú __module__Ú __qualname__Ú__doc__ÚenumÚautoZ COMMAND_LINEZ CONFIG_FILEÚDEFAULTZENV_VARÚRUNTIME©rrú6C:\Program Files\Certbot\pkgs\certbot\configuration.pyr sr c@sœeZdZdZejddœdd„Zeee fddœdd„Z ee d œd d „Z eee fd œd d„Zeddœdd„Zeeeee fd œdd„ƒZee dœdd„Zee ddœdd„Zeed œdd„ƒZejeddœdd„ƒZeeed œdd„ƒZejeddœd d„ƒZeed œd!d"„ƒZejedd#œd$d"„ƒZeed œd%d&„ƒZejedd'œd(d&„ƒZeed œd)d*„ƒZejedd+œd,d*„ƒZee d œd-d.„ƒZeed œd/d0„ƒZeed œd1d2„ƒZeed œd3d4„ƒZeed œd5d6„ƒZ eed œd7d8„ƒZ!eed œd9d:„ƒZ"eed œd;d<„ƒZ#eed œd=d>„ƒZ$ee d œd?d@„ƒZ%eed œdAdB„ƒZ&eed œdCdD„ƒZ'eed œdEdF„ƒZ(ee)ed œdGdH„ƒZ*ee d œdIdJ„ƒZ+ee d œdKdL„ƒZ,ee d œdMdN„ƒZ-eeed œdOdP„ƒZ.eed œdQdR„ƒZ/eedSœdTdU„Z0eed œdVdW„ƒZ1eed œdXdY„ƒZ2eed œdZd[„ƒZ3eed œd\d]„ƒZ4eed œd^d_„ƒZ5eed œd`da„ƒZ6eed œdbdc„ƒZ7eed œddde„ƒZ8ee d œdfdg„ƒZ9e ddhœdidj„Z:dS)kÚNamespaceConfiga4Configuration wrapper around :class:`argparse.Namespace`. Please note that the following attributes are dynamically resolved using :attr:`~certbot.configuration.NamespaceConfig.work_dir` and relative paths defined in :py:mod:`certbot._internal.constants`: - `accounts_dir` - `csr_dir` - `in_progress_dir` - `key_dir` - `temp_checkpoint_dir` And the following paths are dynamically resolved using :attr:`~certbot.configuration.NamespaceConfig.config_dir` and relative paths defined in :py:mod:`certbot._internal.constants`: - `default_archive_dir` - `live_dir` - `renewal_configs_dir` :ivar namespace: Namespace typically produced by :meth:`argparse.ArgumentParser.parse_args`. :type namespace: :class:`argparse.Namespace` N)Ú namespaceÚreturncCsv|t |d|¡t |dd¡t |di¡tj |jj¡|j_tj |jj¡|j_tj |jj¡|j_t |ƒdS)NrÚ_argument_sourcesÚ_previously_accessed_mutables) ÚobjectÚ __setattr__r ÚpathÚabspathrÚ config_dirÚwork_dirZlogs_dirÚ_check_config_sanity)ÚselfrrrrÚ__init__AszNamespaceConfig.__init__)Úargument_sourcesrcCst |d|¡dS)al Associate the NamespaceConfig with a dictionary describing where each of its arguments came from, e.g. `{ 'email': ArgumentSource.CONFIG_FILE }`. This is necessary for making runtime evaluations on whether an argument was specified by the user or not (see `set_by_user`). For an example of how to build such a dictionary, see `certbot._internal.cli.helpful.HelpfulArgumentParser._build_sources_dict` :ivar argument_sources: dictionary of argument names to their :class:`ArgumentSource` :type argument_sources: :class:`Dict[str, ArgumentSource]` rN)rr)r#r%rrrÚset_argument_sourcesOsz$NamespaceConfig.set_argument_sources)Úvarrc Csæddlm}ddlm}ddlm}|jdur6tdƒ‚||vrBdS|dvrx| |¡\}}|d krh|duS|d krx|duS||jvrª|j|tj krªt   d |t ||ƒ¡d S|  |g¡D]*}| |¡r¶t   d ||  |g¡¡d Sq¶dS) ad Return True if a particular config variable has been set by the user (via CLI or config file) including if the user explicitly set it to the default, or if it was dynamically set at runtime. Returns False if the variable was assigned a default value. Raises an exception if `argument_sources` is not set. r)ÚDEPRECATED_OPTIONS)Ú VAR_MODIFIERS)Ú selectionNzoNamespaceConfig.set_by_user called without an ArgumentSources dict. See NamespaceConfig.set_argument_sources().F)Ú authenticatorÚ installerr+r,zVar %s=%s (set by user).T)Z#certbot._internal.cli.cli_constantsr(r)Zcertbot._internal.pluginsr*r%Ú RuntimeErrorZcli_plugin_requestsr rÚloggerÚdebugÚgetattrÚgetÚ set_by_user)r#r'r(r)r*ZauthÚinstÚmodifierrrrr2as2    ÿ  ÿzNamespaceConfig.set_by_user)rcCs t|jƒS)zQ Returns a dictionary mapping all argument names to their values )Úvarsr©r#rrrÚto_dict‹szNamespaceConfig.to_dict)ÚnamercCs,|jdur(tj|j|<||jvr(|j|=dS)a) If an argument_sources dict was set, overwrites an argument's source to be ArgumentSource.RUNTIME. Used when certbot sets an argument's values at runtime. This also clears the modified value from _previously_accessed_mutables since it is no longer needed. N)rr rr)r#r8rrrÚ_mark_runtime_override‘s   z&NamespaceConfig._mark_runtime_overridecCs<|j ¡ ¡D]&\}}t|j|ƒ}||kr| |¡q|jS)zPReturns _argument_sources after handling any changes to accessed mutable values.)rÚcopyÚitemsr0rr9r)r#r8Z prev_valueZ current_valuerrrr%�s   z NamespaceConfig.argument_sourcescCsV|j}t|j|ƒ}|durR||vs0||tjkrR||jvrRt|ƒsRt |¡|j|<|S©N) r%r0rr rrÚ _is_immutabler:Údeepcopy)r#r8Z arg_sourcesÚvaluerrrÚ __getattr__±s zNamespaceConfig.__getattr__)r8r?rcCs| |¡t|j||ƒdSr<)r9Úsetattrr)r#r8r?rrrrÀs zNamespaceConfig.__setattr__cCs|jjS)zACME Directory Resource URI.)rÚserverr6rrrrBÄszNamespaceConfig.server)Úserver_rcCs| d¡||j_dS)NrB)r9rrB)r#rCrrrrBÉs cCs|jjS)z¥Email used for registration and recovery contact. Use comma to register multiple emails, ex: u1@example.com,u2@example.com. (default: Ask). )rÚemailr6rrrrDÎszNamespaceConfig.email)ÚmailrcCs| d¡||j_dS)NrD)r9rrD)r#rErrrrD×s cCs|jjS)zSize of the RSA key.)rÚ rsa_key_sizer6rrrrFÜszNamespaceConfig.rsa_key_size)ÚksizercCs| d¡||j_dS)zSet the rsa_key_size propertyrFN)r9rrF)r#rGrrrrFás cCs|jjS)z`The SECG elliptic curve name to use. Please see RFC 8446 for supported values. )rÚelliptic_curver6rrrrHçszNamespaceConfig.elliptic_curve)ÚecurvercCs| d¡||j_dS)zSet the elliptic_curve propertyrHN)r9rrH)r#rIrrrrHïs cCs|jjS)zhType of generated private key. Only *ONE* per invocation can be provided at this time. )rÚkey_typer6rrrrJõszNamespaceConfig.key_type)ÚktypercCs| d¡||j_dS)zSet the key_type propertyrJN)r9rrJ)r#rKrrrrJýs cCs|jjS)zŸAdds the OCSP Must-Staple extension to the certificate. Autoconfigures OCSP Stapling for supported setups (Apache version >= 2.3.3 ). )rÚ must_stapler6rrrrLszNamespaceConfig.must_staplecCs|jjS)zConfiguration directory.)rr r6rrrr szNamespaceConfig.config_dircCs|jjS)zWorking directory.)rr!r6rrrr!szNamespaceConfig.work_dircCs | |j¡S)z2Directory where all account information is stored.)Úaccounts_dir_for_server_pathÚ server_pathr6rrrÚ accounts_dirszNamespaceConfig.accounts_dircCstj |jjtj¡S)z Configuration backups directory.)r rÚjoinrr!r Z BACKUP_DIRr6rrrÚ backup_dirszNamespaceConfig.backup_dircCs t dt¡tj |jjtj ¡S)zBDirectory where new Certificate Signing Requests (CSRs) are saved.z[NamespaceConfig.csr_dir is deprecated and will be removed in an upcoming release of Certbot) ÚwarningsÚwarnÚDeprecationWarningr rrPrr r ZCSR_DIRr6rrrÚcsr_dir sÿzNamespaceConfig.csr_dircCstj |jjtj¡S)z:Directory used before a permanent checkpoint is finalized.)r rrPrr!r ZIN_PROGRESS_DIRr6rrrÚin_progress_dir'szNamespaceConfig.in_progress_dircCs t dt¡tj |jjtj ¡S)z Keys storage.z[NamespaceConfig.key_dir is deprecated and will be removed in an upcoming release of Certbot) rRrSrTr rrPrr r ZKEY_DIRr6rrrÚkey_dir,sÿzNamespaceConfig.key_dircCstj |jjtj¡S)zTemporary checkpoint directory.)r rrPrr!r ZTEMP_CHECKPOINT_DIRr6rrrÚtemp_checkpoint_dir3s ÿz#NamespaceConfig.temp_checkpoint_dircCs|jjS)zÂDisable verification of the ACME server's certificate. The root certificates trusted by Certbot can be overriden by setting the REQUESTS_CA_BUNDLE environment variable. )rÚ no_verify_sslr6rrrrY9szNamespaceConfig.no_verify_sslcCs|jjS)z¯Port used in the http-01 challenge. This only affects the port Certbot listens on. A conforming ACME server will still attempt to connect on port 80. )rÚ http01_portr6rrrrZBszNamespaceConfig.http01_portcCs|jjS)z;The address the server listens to during http-01 challenge.)rÚhttp01_addressr6rrrr[KszNamespaceConfig.http01_addresscCs|jjS)z…Port used to serve HTTPS. This affects which port Nginx will listen on after a LE certificate is installed. )rÚ https_portr6rrrr\PszNamespaceConfig.https_portcCs|jjS)zuList of user specified preferred challenges. Sorted with the most preferred challenge listed first. )rÚ pref_challsr6rrrr]YszNamespaceConfig.pref_challscCs|jjS)a‰Allow only a subset of names to be authorized to perform validations. When performing domain validation, do not consider it a failure if authorizations can not be obtained for a strict subset of the requested domains. This may be useful for allowing renewals for multiple domains to succeed even if some domains no longer point at this system. )rÚallow_subset_of_namesr6rrrr^as z%NamespaceConfig.allow_subset_of_namescCs|jjS)zºEnable strict permissions checks. Require that all configuration files are owned by the current user; only needed if your config is somewhere unsafe like /tmp/. )rÚstrict_permissionsr6rrrr_msz"NamespaceConfig.strict_permissionscCs|jjS)z Disable renewal updates. If updates provided by installer enhancements when Certbot is being run with "renew" verb should be disabled. )rÚdisable_renew_updatesr6rrrr`vsz%NamespaceConfig.disable_renew_updatescCs|jjS)zþSet the preferred certificate chain. If the CA offers multiple certificate chains, prefer the chain whose topmost certificate was issued from this Subject Common Name. If no match, the default offered chain will be used. )rÚpreferred_chainr6rrrraszNamespaceConfig.preferred_chaincCs&t |jj¡}|j|j dtjj¡S)zFile path based on ``server``.ú/) rÚurlparserrBÚnetlocrÚreplacer Úsep)r#ÚparsedrrrrN‰szNamespaceConfig.server_path)rNrcCs t |¡}tj |jjtj|¡S)z/Path to accounts directory based on server_path) r Z.underscores_for_unsupported_characters_in_pathr rrPrr r Z ACCOUNTS_DIR)r#rNrrrrM�s  ÿz,NamespaceConfig.accounts_dir_for_server_pathcCstj |jjtj¡Sr<)r rrPrr r Z ARCHIVE_DIRr6rrrÚdefault_archive_dir•sz#NamespaceConfig.default_archive_dircCstj |jjtj¡Sr<)r rrPrr r ZLIVE_DIRr6rrrÚlive_dir™szNamespaceConfig.live_dircCstj |jjtj¡Sr<)r rrPrr r ZRENEWAL_CONFIGS_DIRr6rrrÚrenewal_configs_dir�s ÿz#NamespaceConfig.renewal_configs_dircCstj |jjtj¡S)z>Path to directory with hooks to run with the renew subcommand.)r rrPrr r ZRENEWAL_HOOKS_DIRr6rrrÚrenewal_hooks_dir¢s ÿz!NamespaceConfig.renewal_hooks_dircCstj |jtj¡S)z8Path to the pre-hook directory for the renew subcommand.)r rrPrkr ZRENEWAL_PRE_HOOKS_DIRr6rrrÚrenewal_pre_hooks_dir¨s ÿz%NamespaceConfig.renewal_pre_hooks_dircCstj |jtj¡S)z;Path to the deploy-hook directory for the renew subcommand.)r rrPrkr ZRENEWAL_DEPLOY_HOOKS_DIRr6rrrÚrenewal_deploy_hooks_dir®s ÿz(NamespaceConfig.renewal_deploy_hooks_dircCstj |jtj¡S)z9Path to the post-hook directory for the renew subcommand.)r rrPrkr ZRENEWAL_POST_HOOKS_DIRr6rrrÚrenewal_post_hooks_dir´s ÿz&NamespaceConfig.renewal_post_hooks_dircCs|jjS)zuThis option specifies how long (in seconds) Certbot will wait for the server to issue a certificate. )rÚissuance_timeoutr6rrrroºsz NamespaceConfig.issuance_timeoutcCs|jjS)z�This option specifies whether Certbot should generate a new private key when replacing a certificate, even if reuse_key is set. )rÚnew_keyr6rrrrpÁszNamespaceConfig.new_key)Ú_memorcCsHt |j¡}t|ƒ|ƒ}t |dt |j¡¡t |dt |j¡¡|S)Nrr)r:r>rÚtyperrr%r)r#rqZnew_nsZ new_configrrrÚ __deepcopy__Ês   ÿzNamespaceConfig.__deepcopy__);r rrrÚargparseÚ Namespacer$rÚstrr r&Úboolr2rr7r9Úpropertyrr%r@rrBÚsetterrDÚintrFrHrJrLr r!rOrQrUrVrWrXrYrZr[r\rr]r^r_r`rarNrMrhrirjrkrlrmrnrorprsrrrrr&s°*   r)ÚconfigrcCsF|j|jkrt d |j¡¡‚|jjdurB|jjD]}t |¡q2dS)zåValidate command line options and display error message if requirements are not met. :param config: NamespaceConfig instance holding user configuration :type args: :class:`certbot.configuration.NamespaceConfig` z;Trying to run http-01 and https-port on the same port ({0})N) rZr\rZConfigurationErrorÚformatrZdomainsrZenforce_domain_sanity)r{Údomainrrrr"Õs ÿÿ  r")r?rcCsLt|tƒrtdd„|DƒƒSttttttt fD]}t||ƒr.dSq.|duS)zIs value of an immutable type?css|]}t|ƒVqdSr<)r=)Ú.0ZsubvaluerrrÚ îóz _is_immutable..TN) Ú isinstanceÚtupleÚallrzÚfloatÚcomplexrvÚbytesrwÚ frozenset)r?Zimmutable_typerrrr=ês   r=)rrtr:rZloggingÚtypingrrrrZurllibrrRZcertbotrrZcertbot._internalr Zcertbot.compatr r Z getLoggerr r.ÚEnumr rr"rwr=rrrrÚs.           2