a ‚oep>ã@s¨dZddlZddlZddlZddlZddlmZddlmZddlmZddlm Z ddlm Z ddlm Z dd lm Z dd lm Z dd lmZdd lmZdd lmZddlmZddlmZddlmZddlmZddlmZddlmZddlmZddlmZddlmZddlm Z!ddl"m#Z#ddl"m Z ddl$m%Z%e &e'¡Z(dZ)ddgZ*Gdd„de#j+ej,ƒZ,Gdd „d ej-ƒZ.Gd!d"„d"ej-ƒZ/e0e0d#œd$d%„Z1dS)&zWebroot plugin.éN)ÚAny)ÚCallable)Ú DefaultDict)ÚDict)ÚIterable)ÚList)ÚOptional)ÚSequence)ÚSet)ÚType)ÚUnion)Ú challenges)Ú crypto_util)Úerrors)Ú interfaces)Úcli)ÚAnnotatedChallenge)Ú filesystem)Úos)Úops)Úutil)Úcommon)Ú safe_opena! Z@20c5ca1bd58fa8ad5f07a2f1be8b7cbb707c20fcb607a8fc8db9393952846a97Z@8d31383d3a079d2098a9d0c0921f4ab87e708b9868dc3f314d54094c2fe70336csTeZdZdZdZdZedœdd„Zee ddd œd d „ƒZ e e ed œd d„Z eeeejdœdd„Zeeddœ‡fdd„ Zddœdd„Ze e e ejdœdd„Zee ddœdd„Zee eeedœdd„Zee eeedœdd „Zd/eeeed"œd#d$„Zddœd%d&„Zee ed'œd(d)„Ze ejd*œd+d,„Z e e ddœd-d.„Z!‡Z"S)0Ú AuthenticatorzWebroot Authenticator.zñSaves the necessary validation files to a .well-known/acme-challenge/ directory within the nominated webroot path. A seperate HTTP server must be running and serving files from the webroot path. HTTP challenge only (wildcards not supported).zôAuthenticator plugin that performs http-01 challenge by saving necessary validation resources to appropriate paths on the file system. It expects that there is some other HTTP server configured to serve all files under specified web root ({0}).)ÚreturncCs|j | d¡¡S)NÚpath)Ú MORE_INFOÚformatÚconf©Úself©r!úBC:\Program Files\Certbot\pkgs\certbot\_internal\plugins\webroot.pyÚ more_infoFszAuthenticator.more_info).NN)ÚaddrcCs&|ddgtdd�|ditdd�dS)Nrz-wapublic_html / webroot path. This can be specified multiple times to handle different domains; each domain will have the webroot path that preceded it. For instance: `-w /var/www/example -d example.com -d www.example.com -w /var/www/thing -d thing.net -d m.thing.net` (default: Ask))ÚdefaultÚactionÚhelpÚmapa—JSON dictionary mapping domains to webroot paths; this implies -d for each entry. You may need to escape this from your shell. E.g.: --webroot-map '{"eg1.is,m.eg1.is":"/www/eg1/", "eg2.is":"/www/eg2"}' This option is merged with, but takes precedence over, -w / -d entries. At present, if you put webroot-map in a config file, it needs to be on a single line, like: webroot-map = {"example.com":"/var/www"}.)Ú_WebrootPathActionÚ_WebrootMapAction)Úclsr$r!r!r"Úadd_parser_argumentsIs  ÿÿz"Authenticator.add_parser_arguments)Úfailed_achallsrcCsdS)Nz÷The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.r!)r r-r!r!r"Ú auth_hint[szAuthenticator.auth_hint)ÚdomainrcCstjgS©N)r ÚHTTP01)r r/r!r!r"Úget_chall_prefaszAuthenticator.get_chall_pref©ÚargsÚkwargsrcs.tƒj|i|¤Ži|_t t¡|_g|_dSr0)ÚsuperÚ__init__Ú full_rootsÚ collectionsÚ defaultdictÚsetÚ performedÚ _created_dirs©r r4r5©Ú __class__r!r"r7es zAuthenticator.__init__cCsdSr0r!rr!r!r"ÚpreparelszAuthenticator.prepare)Úachallsrcs$ˆ |¡ˆ ¡‡fdd„|DƒS)Ncsg|]}ˆ |¡‘qSr!)Ú_perform_single)Ú.0Úachallrr!r"Ú tóz)Authenticator.perform..)Ú _set_webrootsÚ_create_challenge_dirs)r rBr!rr"Úperformos zAuthenticator.performc CsÄ| d¡rD| d¡d}t d|¡|D]}| d¡ |j|¡q(n|tt| d¡ ¡ƒƒ}|D]`}|j| d¡vr^| |j|¡}z|  |¡Wnt y Yn0|  d|¡|| d¡|j<q^dS)Nréÿÿÿÿz4Using the webroot path %s for all unmatched domains.r(r) rÚloggerÚinfoÚ setdefaultr/Úlistr;ÚvaluesÚ_prompt_for_webrootÚremoveÚ ValueErrorÚinsert)r rBÚ webroot_pathrEÚknown_webrootsZ new_webrootr!r!r"rHvs& ÿÿ  zAuthenticator._set_webroots)r/rVrcCsBd}|dur>|r0| ||¡}|dur<| |¡}q| |d¡}q|S)NT)Ú_prompt_with_webroot_listÚ_prompt_for_new_webroot)r r/rVÚwebrootr!r!r"rQŒs  z!Authenticator._prompt_for_webrootcCs\d| d¡}tjd |¡dg||dd�\}}|tjkrDt d¡‚|dkrPdS||d S) Nz--rzSelect the webroot for {0}:zEnter a new webrootT)Zcli_flagÚforce_interactiveúIEvery requested domain must have a webroot when using the webroot plugin.ré)Z option_nameÚ display_utilZmenurÚCANCELrÚ PluginError)r r/rVZ path_flagÚcodeÚindexr!r!r"rW›sý  ÿz'Authenticator._prompt_with_webroot_listF)r/Ú allowraisercCs>tjtd |¡dd�\}}|tjkr6|s,dSt d¡‚t|ƒS)NzInput the webroot for {0}:T)rZr[)rZvalidated_directoryÚ_validate_webrootrr]r^rr_)r r/rbr`rYr!r!r"rXªsý  ÿz%Authenticator._prompt_for_new_webrootc Csú| d¡}|st d¡‚| ¡D�]Ò\}}tj |tj tj j ¡¡|j |<t   d|j |¡t d¡�ôtt |j |¡dd…td�D]Â}tj |¡ršqˆzvt |d¡|j |¡ztj||dddd �Wn@ttf�y }z"t  d ¡t   d |¡WYd}~n d}~00Wqˆt�yH}zt d  ||¡¡‚WYd}~qˆd}~00qˆWdƒn1�sb0Ytjs tj |j |d ¡}tj |¡�r¨t  d|j |¡q t  d|j |¡t |ddd��}| !t"¡Wdƒq 1�sê0Yq dS)Nr(z�Missing parts of webroot configuration; please set either --webroot-path and --domains, or --webroot-map. Run with --help webroot for examples.z-Creating root challenges validation dir at %sérK)ÚkeyiíT)Z copy_userZ copy_groupz3Unable to change owner and uid of webroot directoryú Error was: %sz=Couldn't create root for {0} http-01 challenge responses: {1}ú web.configzPA web.config file has not been created in %s because another one already exists.zGCreating a web.config file in %s to allow IIS to serve challenge files.Úw餩ÚmodeÚchmod)#rrr_ÚitemsrrÚjoinÚnormcaser r1Z URI_ROOT_PATHr8rLÚdebugrÚ temp_umaskÚsortedrZ get_prefixesÚlenÚisdirÚmkdirr=ÚappendZcopy_ownership_and_apply_modeÚOSErrorÚAttributeErrorZwarningrÚ POSIX_MODEÚexistsrMrÚwriteÚ_WEB_CONFIG_CONTENT)r Zpath_mapÚnamerÚprefixÚ exceptionÚweb_config_pathZ web_configr!r!r"rI·sX ÿÿ ÿ $    ÿ  &ÿÿ<ÿÿz$Authenticator._create_challenge_dirs)Ú root_pathrErcCstj ||j d¡¡S)NÚtoken)rrrnZchallÚencode)r r�rEr!r!r"Ú_get_validation_pathîsz"Authenticator._get_validation_path)rErc Csª| ¡\}}|j|j}| ||¡}t d|¡t d¡�Lt|ddd��}|  |  ¡¡Wdƒn1sn0YWdƒn1sŒ0Y|j |  |¡|S)Nz#Attempting to save validation to %srdÚwbrirj) Zresponse_and_validationr8r/r„rLrprrqrr{rƒr<r$)r rEZresponseZ validationr�Úvalidation_pathZvalidation_filer!r!r"rCñs     JzAuthenticator._perform_singlec Cs0|D]¤}|j |jd¡}|dur| ||¡}t d|¡t |¡|j| |¡t j stj   |d¡}tj   |¡rt |¡}|tvrœt d|¡t |¡qt d|¡qg}|j�r|j ¡}zt |¡Wq®t�y} z0| d|¡t d|¡t d| ¡WYd} ~ q®d} ~ 00q®||_t d¡dS) Nz Removing %srgz4Cleaning web.config file generated by Certbot in %s.zQNot cleaning up the web.config file in %s because it is not generated by Certbot.rz3Challenge directory %s was not empty, didn't removerfzAll challenges cleaned up)r8Úgetr/r„rLrprrRr<rryrrnrzrÚ sha256sumÚ_WEB_CONFIG_SHA256SUMSrMr=ÚpopÚrmdirrwrT) r rBrEr�r†r€rˆZ not_removedrÚexcr!r!r"Úcleanups<     ÿ ÿ   $zAuthenticator.cleanup)F)#Ú__name__Ú __module__Ú __qualname__Ú__doc__Ú descriptionrÚstrr#Ú classmethodrr,rrr.rr r Z Challenger2rr7rAZChallengeResponserJrHrrQrWÚboolrXrIr„rCr�Ú __classcell__r!r!r?r"r8s* ÿ  7rc@s>eZdZdZdejejeee e dfe eddœdd„Z dS)r*z%Action class for parsing webroot_map.N)ÚparserÚ namespaceÚ webroot_mapÚ option_stringrcsV|dur dSt t|ƒ¡ ¡D]2\}‰tˆƒ‰|j ‡fdd„t ||¡Dƒ¡qdS)Nc3s|]}|ˆfVqdSr0r!)rDÚd©rUr!r"Ú ,sz-_WebrootMapAction.__call__..) ÚjsonÚloadsr“rmrcr™ÚupdaterZ add_domains)r r—r˜r™ršÚdomainsr!rœr"Ú__call__%s ÿz_WebrootMapAction.__call__)N) rŽr�r�r‘ÚargparseÚArgumentParserÚ Namespacer r“r rrr¢r!r!r!r"r*"s þ þr*csXeZdZdZeeddœ‡fdd„ Zd ejeje e e edfe e ddœdd„Z ‡ZS) r)z&Action class for parsing webroot_path.Nr3cstƒj|i|¤Žd|_dS)NF)r6r7Ú_domain_before_webrootr>r?r!r"r73sz_WebrootPathAction.__init__)r—r˜rUršrcCsl|dur dS|jrt d¡‚|jrH|jd}|jD]}|j ||¡q2n |jrTd|_|j tt |ƒƒ¡dS)NzPIf you specify multiple webroot paths, one of them must precede all domain flagsrKT) r¦rr_rUr¡r™rNrvrcr“)r r—r˜rUršZ prev_webrootr/r!r!r"r¢7sÿ  z_WebrootPathAction.__call__)N)rŽr�r�r‘rr7r£r¤r¥r r“r rr¢r–r!r!r?r"r)0sþ þr))rUrcCs&tj |¡st |d¡‚tj |¡S)z·Validates and returns the absolute path of webroot_path. :param str webroot_path: path to the webroot directory :returns: absolute path of webroot_path :rtype: str z% does not exist or is not a directory)rrrtrr_Úabspathrœr!r!r"rcMs rc)2r‘r£r9ržZloggingÚtypingrrrrrrrr r r r Zacmer ZcertbotrrrZcertbot._internalrZcertbot.achallengesrZcertbot.compatrrZcertbot.displayrrr]Zcertbot.pluginsrZ certbot.utilrZ getLoggerrŽrLr|r‰ZPluginrÚActionr*r)r“rcr!r!r!r"ÚsL                         þk