a ‚oe29ã@sddZddlZddlZddlZddlZddlZddlZddlmZddlm Z ddlm Z ddlm Z ddlm Z ddlm Z dd lmZdd lmZddlZddlZddlZdd lmZdd lmZdd lmZddlmZddlmZddlmZddlmZddl m!Z!ddl"m#Z#ddl"m$Z$e %e&¡Z'Gdd„dƒZ(Gdd„dej)ƒZ*Gdd„dej)ƒZ+dS)z!Creates ACME accounts for server.éN)ÚAny)ÚCallable)Úcast)ÚDict)ÚList)ÚMapping)ÚOptional)Ú serialization)Úfields)Úmessages)ÚClientV2)Ú configuration)Úerrors)Ú interfaces)Úutil)Ú constants)Ú filesystem)Úosc@speZdZdZGdd„dejƒZdejej e dddœdd„Z e e dœd d „ƒZe dœd d „Zeed œdd„ZdS)ÚAccountzáACME protocol registration. :ivar .RegistrationResource regr: Registration Resource :ivar .JWK key: Authorized Account Key :ivar .Meta: Account metadata :ivar str id: Globally unique account identifier. c@sNeZdZUdZe d¡Zejed<e   d¡Z e ed<e j ddd�Z e ed<dS)z Account.MetaaÍAccount metadata :ivar datetime.datetime creation_dt: Creation date and time (UTC). :ivar str creation_host: FQDN of host, where account has been created. :ivar str register_to_eff: If not None, Certbot will register the provided email during the account registration. .. note:: ``creation_dt`` and ``creation_host`` are useful in cross-machine migration scenarios. Ú creation_dtÚ creation_hostÚregister_to_effT)Z omitemptyN)Ú__name__Ú __module__Ú __qualname__Ú__doc__Ú acme_fieldsZrfc3339rÚdatetimeÚ__annotations__ÚjoseZfieldrÚstrr©r!r!ú:C:\Program Files\Certbot\pkgs\certbot\_internal\account.pyÚMeta-s  r#N)ÚregrÚkeyÚmetaÚreturnc Cs¶||_||_|dur<|jtjjtjd�jdd�t  ¡dd�n||_ z t   ¡}Wn4t y‚t jd ittttfddiƒ¤Ž}Yn0| |jj ¡jtjjtjjd�¡| ¡|_dS) N)Ztzr)Z microsecond)rrrÚmd5ZusedforsecurityF)ÚencodingÚformat)r()r%r$r#rZnowÚpytzZUTCÚreplaceÚsocketZgetfqdnr&Úhashlibr(Ú ValueErrorÚnewrrr rÚupdateZ public_keyZ public_bytesr ZEncodingZPEMZ PublicFormatZSubjectPublicKeyInfoZ hexdigestÚid)Úselfr$r%r&Zhasherr!r!r"Ú__init__=s&üüü  (þzAccount.__init__©r'cCs&d t |jj¡|jj|jdd…¡S)z3Short account identification string, useful for UI.z {1}@{0} ({2})Né)r*Ú pyrfc3339Zgenerater&rrr2©r3r!r!r"Úslug\s ÿÿz Account.slugcCsd |jj|j|j|j¡S)Nz<{0}({1}, {2}, {3})>)r*Ú __class__rr$r2r&r8r!r!r"Ú__repr__bsÿzAccount.__repr__)Úotherr'cCs0t||jƒo.|j|jko.|j|jko.|j|jkS©N)Ú isinstancer:r%r$r&)r3r<r!r!r"Ú__eq__fs  ÿ ÿ þzAccount.__eq__)N)rrrrrZJSONObjectWithFieldsr#r ÚRegistrationResourceÚJWKrr4Úpropertyr r9r;rÚboolr?r!r!r!r"r#s ÿ ÿ rc@sbeZdZdZdeeeefddœdd„Ze edœdd„Z ee dd œd d „Z eed œd d„Z dS)ÚAccountMemoryStoragezIn-memory account storage.N)Úinitial_accountsr'cCs|dur |ni|_dSr=)Úaccounts)r3rEr!r!r"r4oszAccountMemoryStorage.__init__r5cCst|j ¡ƒSr=)ÚlistrFÚvaluesr8r!r!r"Úfind_allrszAccountMemoryStorage.find_all©ÚaccountÚclientr'cCs*|j|jvrt d|j¡||j|j<dS)NzOverwriting account: %s)r2rFÚloggerÚdebug)r3rKrLr!r!r"Úsaveus zAccountMemoryStorage.save©Ú account_idr'cCs.z |j|WSty(t |¡‚Yn0dSr=)rFÚKeyErrorrÚAccountNotFound©r3rQr!r!r"Úloadzs  zAccountMemoryStorage.load)N)rrrrrrr rr4rrIr rOrUr!r!r!r"rDls rDc@s´eZdZdZejddœdd„Zeedœdd„Zeeed œd d „Z e eed œd d„ƒZ e eed œdd„ƒZ e eed œdd„ƒZ eeedœdd„Zeedœdd„Zeeeddœdd„Zeeddœdd„Zeeed œdd „Zeedœd!d"„Zeedd#œd$d%„Zedd&œd'd(„Zedd&œd)d*„Zeddœd+d,„Zeedd œd-d.„Zeddœd/d0„Zeeegefed1œd2d3„Zeed&œd4d5„Zeedd6œd7d8„Z eedd6œd9d:„Z!eedd6œd;d<„Z"dS)=ÚAccountFileStoragezjAccounts file storage. :ivar certbot.configuration.NamespaceConfig config: Client configuration N)Úconfigr'cCs||_t |jd|jj¡dS©NiÀ)rWrÚmake_or_verify_dirÚ accounts_dirÚstrict_permissions)r3rWr!r!r"r4‡szAccountFileStorage.__init__rPcCs| ||jj¡Sr=)Ú!_account_dir_path_for_server_pathrWÚ server_pathrTr!r!r"Ú_account_dir_path‹sz$AccountFileStorage._account_dir_path)rQr]r'cCs|j |¡}tj ||¡Sr=)rWÚaccounts_dir_for_server_pathrÚpathÚjoin)r3rQr]rZr!r!r"r\Žs z4AccountFileStorage._account_dir_path_for_server_path)Úaccount_dir_pathr'cCstj |d¡S)Nz regr.json©rr`ra©Úclsrbr!r!r"Ú _regr_path’szAccountFileStorage._regr_pathcCstj |d¡S)Nzprivate_key.jsonrcrdr!r!r"Ú _key_path–szAccountFileStorage._key_pathcCstj |d¡S)Nz meta.jsonrcrdr!r!r"Ú_metadata_pathšsz!AccountFileStorage._metadata_path)r]r'c CsÐ|j |¡}zt |¡}Wnty0gYS0g}|D]>}z| | ||¡¡Wq:tjyvt j ddd�Yq:0q:|sÌ|t j vrÌt j |}|  |¡}|rÈz| ||¡WntyÆgYS0|}|S)NzAccount loading problemT)Úexc_info)rWr_rÚlistdirÚOSErrorÚappendÚ_load_for_server_pathrÚAccountStorageErrorrMrNrÚLE_REUSE_SERVERSÚ_find_all_for_server_pathÚ_symlink_to_accounts_dir)r3r]rZZ candidatesrFrQÚprev_server_pathZ prev_accountsr!r!r"rpžs*       z,AccountFileStorage._find_all_for_server_pathr5cCs| |jj¡Sr=)rprWr]r8r!r!r"rI¹szAccountFileStorage.find_all)rrr]rQr'cCs(| ||¡}| ||¡}t ||¡dSr=)r\rÚsymlink)r3rrr]rQÚprev_account_dirZnew_account_dirr!r!r"Ú_symlink_to_account_dir¼s  z*AccountFileStorage._symlink_to_account_dir)rrr]r'cCsJ|j |¡}tj |¡r$t |¡n t |¡|j |¡}t ||¡dSr=)rWr_rr`ÚislinkÚunlinkÚrmdirrs)r3rrr]rZrtr!r!r"rqÂs      z+AccountFileStorage._symlink_to_accounts_dirc Cs~| ||¡}tj |¡s€|tjvrntj|}| ||¡}|j |¡}t  |¡r^|  |||¡n |  ||¡|St   d|›d�¡‚zÀt| |¡ƒ� }tj | ¡¡}Wdƒn1s¶0Yt| |¡ƒ� } tj |  ¡¡} Wdƒn1sô0Yt| |¡ƒ� } tj |  ¡¡} Wdƒn1�s40YWn0t�yp} zt  | ¡‚WYd} ~ n d} ~ 00t|| | ƒS)Nú Account at ú does not exist)r\rr`ÚisdirrrormrWr_rjrurqrrSÚopenrfr r@Z json_loadsÚreadrgrrArhrr#ÚIOErrorrn)r3rQr]rbrrZprev_loaded_accountrZÚ regr_filer$Úkey_filer%Ú metadata_filer&Úerrorr!r!r"rmËs*        ..4 z(AccountFileStorage._load_for_server_pathcCs| ||jj¡Sr=)rmrWr]rTr!r!r"rUçszAccountFileStorage.loadrJc Csfz2| |¡}| ||¡| ||¡| ||¡Wn.ty`}zt |¡‚WYd}~n d}~00dS)z˜Create a new account. :param Account account: account to create :param ClientV2 client: ACME client associated to the account N)Ú_prepareÚ_createÚ _update_metaÚ _update_regrr~rrn)r3rKrLÚdir_pathr‚r!r!r"rOês   zAccountFileStorage.save)rKr'c CsNz| |¡}| ||¡Wn.tyH}zt |¡‚WYd}~n d}~00dS)z^Update the registration resource. :param Account account: account to update N)rƒr†r~rrn©r3rKr‡r‚r!r!r"Ú update_regrùs  zAccountFileStorage.update_regrc CsNz| |¡}| ||¡Wn.tyH}zt |¡‚WYd}~n d}~00dS)zVUpdate the meta resource. :param Account account: account to update N)rƒr…r~rrnrˆr!r!r"Ú update_metas  zAccountFileStorage.update_metacCsX| |¡}tj |¡s(t d|›d�¡‚| ||jj¡t  |jj ¡sT|  |jj¡dS)znDelete registration info from disk :param account_id: id of account which should be deleted ryrzN) r^rr`r{rrSÚ#_delete_account_dir_for_server_pathrWr]rjrZÚ$_delete_accounts_dir_for_server_path)r3rQrbr!r!r"Údeletes   zAccountFileStorage.deletecCs(t |j|¡}| ||¡}t |¡dSr=)Ú functoolsÚpartialr\Ú!_delete_links_and_find_target_dirÚshutilÚrmtree)r3rQr]Ú link_funcÚnonsymlinked_dirr!r!r"r‹!s z6AccountFileStorage._delete_account_dir_for_server_pathcCs"|jj}| ||¡}t |¡dSr=)rWr_r�rrx)r3r]r“r”r!r!r"rŒ&s z7AccountFileStorage._delete_accounts_dir_for_server_path)r]r“r'c Csž||ƒ}i}tj ¡D]\}}|||<qd}|rtd}||vr,||}||ƒ} tj | ¡r,t | ¡|kr,d}|}| }q,tj |¡ršt |¡} t |¡| }qt|S)a/Delete symlinks and return the nonsymlinked directory path. :param str server_path: file path based on server :param callable link_func: callable that returns possible links given a server_path :returns: the final, non-symlinked target :rtype: str TF) rroÚitemsrr`rvrÚreadlinkrw) r3r]r“r‡Zreused_serversÚkÚvZpossible_next_linkZnext_server_pathZ next_dir_pathÚtargetr!r!r"r�+s&     z4AccountFileStorage._delete_links_and_find_target_dircCs"| |j¡}t |d|jj¡|SrX)r^r2rrYrWr[)r3rKrbr!r!r"rƒSs zAccountFileStorage._prepare)rKr‡r'cCsJtj| |¡ddd�� }| |j ¡¡Wdƒn1s<0YdS)NÚwé)Úchmod)rZ safe_openrgÚwriter%Ú json_dumps)r3rKr‡r€r!r!r"r„XszAccountFileStorage._createcCsTt| |¡dƒ�0}tji|jjd�}| | ¡¡Wdƒn1sF0YdS)Nrš)ÚbodyÚuri)r|rfr r@r$r r�rž)r3rKr‡rr$r!r!r"r†\s þzAccountFileStorage._update_regrcCsDt| |¡dƒ� }| |j ¡¡Wdƒn1s60YdS)Nrš)r|rhr�r&rž)r3rKr‡r�r!r!r"r…cszAccountFileStorage._update_meta)#rrrrr ZNamespaceConfigr4r r^r\Ú classmethodrfrgrhrrrprIrurqrmrUr rOr‰rŠr�r‹rŒrr�rƒr„r†r…r!r!r!r"rV�s>ÿ    ÿ (rV),rrrŽr.Zloggingr‘r-ÚtypingrrrrrrrZcryptography.hazmat.primitivesr Zjosepyrr7r+Zacmer rr Z acme.clientr Zcertbotr rrrZcertbot._internalrZcertbot.compatrrZ getLoggerrrMrZAccountStoragerDrVr!r!r!r"Ús>                   I