a ‚oeÌ6ã@sTdZddlZddlZddlmZddlmZddlmZddlmZddlm Z ddlm Z dd lm Z ddl Z dd l mZdd lmZdd lmZdd lmZddlmZddlmZddlmZddlmZddlmZddlmZe e¡ZGdd„dej ej!ej"d�Z#Gdd„dƒZ$e%ddœdd„Z&e%ddœdd„Z'e%ee%dœdd „Z(dS)!z*Common code for DNS Authenticator Plugins.éN)Úsleep)ÚCallable)ÚIterable)ÚList)ÚMapping)ÚOptional)ÚType)Ú challenges)Ú achallenges)Ú configuration)Úerrors)Ú interfaces)Ú filesystem)Úos)Úops)Úutil)Úcommoncs°eZdZdZejeddœ‡fdd„ Zed2e de ddœd d „ƒZ e e jed œd d „Zeeeejdœdd„Zddœdd„Zedœdd„Ze e je ejdœdd„Ze e jddœdd„Zejddœdd„ƒZejeeeddœdd„ƒZejeeeddœd d!„ƒZeedd"œd#d$„Zd3eee e egdfdd%œd&d'„Z!d4eee e"eefe e d(gdfd(d)œd*d+„Z#e$eed,œd-d.„ƒZ%e$d5ee e egdfed/œd0d1„ƒZ&‡Z'S)6ÚDNSAuthenticatorz!Base class for DNS AuthenticatorsN)ÚconfigÚnameÚreturncstƒ ||¡d|_dS)NF)ÚsuperÚ__init__Ú_attempt_cleanup)Úselfrr©Ú __class__©ú;C:\Program Files\Certbot\pkgs\certbot\plugins\dns_common.pyrszDNSAuthenticator.__init__é ).N)ÚaddÚdefault_propagation_secondsrcCs|d|tdd�dS)Núpropagation-secondszjThe number of seconds to wait for DNS to propagate before asking the ACME server to verify the DNS record.)ÚdefaultÚtypeÚhelp)Úint)Úclsr r!rrrÚadd_parser_arguments$s ýz%DNSAuthenticator.add_parser_arguments)Úfailed_achallsrcCs(| d¡}dj|j||dkr dndd�S)z,See certbot.plugins.common.Plugin.auth_hint.r"zßThe Certificate Authority failed to verify the DNS TXT records created by --{name}. Ensure the above domains are hosted by this DNS provider, or try increasing --{name}-propagation-seconds (currently {secs} second{suffix}).éÚsÚ)rZsecsÚsuffix)ÚconfÚformatr)rr)ZdelayrrrÚ auth_hint-s  ýÿzDNSAuthenticator.auth_hint)Ú unused_domainrcCstjgS©N)r ZDNS01)rr1rrrÚget_chall_pref7szDNSAuthenticator.get_chall_pref)rcCsdSr2r©rrrrÚprepare:szDNSAuthenticator.preparecCs tƒ‚dSr2©ÚNotImplementedErrorr4rrrÚ more_info=szDNSAuthenticator.more_info)ÚachallsrcCs~| ¡d|_g}|D]@}|j}| |¡}| |j¡}| |||¡| | |j¡¡qt   d|  d¡¡t |  d¡ƒ|S)NTz/Waiting %d seconds for DNS changes to propagater") Ú_setup_credentialsrÚdomainÚvalidation_domain_nameÚ validationÚ account_keyÚ_performÚappendÚresponseÚ display_utilÚnotifyr.r)rr9Z responsesÚachallr;r<r=rrrÚperform@s  ÿzDNSAuthenticator.performcCs>|jr:|D].}|j}| |¡}| |j¡}| |||¡q dSr2)rr;r<r=r>Ú_cleanup)rr9rDr;r<r=rrrÚcleanupXs   zDNSAuthenticator.cleanupcCs tƒ‚dS)z@ Establish credentials, prompting if necessary. Nr6r4rrrr:asz#DNSAuthenticator._setup_credentials)r;Úvalidation_namer=rcCs tƒ‚dS)aX Performs a dns-01 challenge by creating a DNS TXT record. :param str domain: The domain being validated. :param str validation_domain_name: The validation record domain name. :param str validation: The validation record content. :raises errors.PluginError: If the challenge cannot be performed Nr6©rr;rHr=rrrr?hs zDNSAuthenticator._performcCs tƒ‚dS)aX Deletes the DNS TXT record which would have been created by `_perform_achall`. Fails gracefully if no such record exists. :param str domain: The domain being validated. :param str validation_domain_name: The validation record domain name. :param str validation: The validation record content. Nr6rIrrrrFus zDNSAuthenticator._cleanup)ÚkeyÚlabelrcCs0| |¡}|s,| |¡}t|j| |¡|ƒdS)a Ensure that a configuration value is available. If necessary, prompts the user and stores the result. :param str key: The configuration key. :param str label: The user-friendly label for this piece of information. N)r.Ú_prompt_for_dataÚsetattrrÚdest)rrJrKÚconfigured_valueÚ new_valuerrrÚ _configureƒs  zDNSAuthenticator._configure)rJrKÚ validatorrcCsB| |¡}|s>| ||¡}t|j| |¡tj tj |¡¡ƒdS)a  Ensure that a configuration value is available for a path. If necessary, prompts the user and stores the result. :param str key: The configuration key. :param str label: The user-friendly label for this piece of information. N) r.Ú_prompt_for_filerMrrNrÚpathÚabspathÚ expanduser)rrJrKrRrOrPrrrÚ_configure_file“s  z DNSAuthenticator._configure_fileÚCredentialsConfiguration)rJrKÚrequired_variablesrRrcsVtddœ‡‡‡fdd„ }ˆ |||¡tˆ |¡ˆjƒ}ˆrF| ˆ¡ˆrRˆ|ƒ|S)að As `_configure_file`, but for a credential configuration file. If necessary, prompts the user and stores the result. Always stores absolute paths to avoid issues during renewal. :param str key: The configuration key. :param str label: The user-friendly label for this piece of information. :param dict required_variables: Map of variable which must be present to error to display. :param callable validator: A method which will be called to validate the `CredentialsConfiguration` resulting from the supplied input after it has been validated to contain the `required_variables`. Should throw a `~certbot.errors.PluginError` to indicate any issue. N©Úfilenamercs*t|ˆjƒ}ˆr| ˆ¡ˆr&ˆ|ƒdSr2)rXrNÚrequire)r[Zapplied_configuration©rYrrRrrÚ __validator¸s   z.__validator)ÚstrrWrXr.rNr\)rrJrKrYrRÚ_DNSAuthenticator__validatorZcredentials_configurationrr]rÚ_configure_credentials¤s  z'DNSAuthenticator._configure_credentials)rKrcsPtddœ‡fdd„ }tj|d ˆ¡dd�\}}|tjkr<|St d ˆ¡¡‚dS) zá Prompt the user for a piece of information. :param str label: The user-friendly label for this piece of information. :returns: The user's response (guaranteed non-empty). :rtype: str N)Úircs|st d ˆ¡¡‚dS)NzPlease enter your {0}.)r Ú PluginErrorr/)rb©rKrrr^Ösz6DNSAuthenticator._prompt_for_data..__validatorzInput your {0}T©Zforce_interactiveú{0} required to proceed.)r_rZvalidated_inputr/rBÚOKr rc)rKr`ÚcoderArrdrrLÌs ý  z!DNSAuthenticator._prompt_for_data)rKrRrcsRtddœ‡‡fdd„ }tj|d ˆ¡dd�\}}|tjkr>|St d ˆ¡¡‚dS) aà Prompt the user for a path. :param str label: The user-friendly label for the file. :param callable validator: A method which will be called to validate the supplied input after it has been validated to be a non-empty path to an existing file. Should throw a `~certbot.errors.PluginError` to indicate any issue. :returns: The user's response (guaranteed to exist). :rtype: str NrZcs8|st d ˆ¡¡‚tj |¡}t|ƒˆr4ˆ|ƒdS)Nz&Please enter a valid path to your {0}.)r rcr/rrTrVÚ validate_file©r[©rKrRrrr^ðs  z6DNSAuthenticator._prompt_for_file..__validatorzInput the path to your {0}Trerf)r_rZvalidated_directoryr/rBrgr rc)rKrRr`rhrArrkrrSãs  ý  z!DNSAuthenticator._prompt_for_file)r)N)NN)N)(Ú__name__Ú __module__Ú __qualname__Ú__doc__r ZNamespaceConfigr_rÚ classmethodrr&r(rr ZAnnotatedChallenger0rrr Z Challenger3r5r8ZChallengeResponserErGÚabcÚabstractmethodr:r?rFrQrrWrraÚ staticmethodrLrSÚ __classcell__rrrrrsRÿÿ ÿ  ÿ ÿ ÿÿ þý (r)Ú metaclassc@s„eZdZdZdd„feeegefddœdd„Zeeefddœd d „Zee ed œd d „Z ee d œdd„Z ee ed œdd„Z dS)rXz>Represents a user-supplied filed which stores API credentials.cCs|Sr2r)ÚxrrrÚóz!CredentialsConfiguration.N)r[Úmapperrc Csnt|ƒzt |¡|_WnJtjyb}z0tjd||dd�t d  ||¡¡‚WYd}~n d}~00||_ dS)zö :param str filename: A path to the configuration file. :param callable mapper: A transformation to apply to configuration key names :raises errors.PluginError: If the file does not exist or is not a valid format. z0Error parsing credentials configuration '%s': %sT)Úexc_infoz0Error parsing credentials configuration '{}': {}N) Úvalidate_file_permissionsÚ configobjZ ConfigObjÚconfobjZConfigObjErrorÚloggerÚdebugr rcr/ry)rr[ryÚerrrrs"üþÿz!CredentialsConfiguration.__init__)rYrc Cs’g}|D]R}| |¡s4| d | |¡||¡¡q| |¡s| d | |¡||¡¡q|rŽt d t|ƒdkrxdnd|jj d  |¡¡¡‚dS) zôEnsures that the supplied set of variables are all present in the file. :param dict required_variables: Map of variable which must be present to error to display. :raises errors.PluginError: If one or more are missing. z)Property "{0}" not found (should be {1}).z'Property "{0}" not set (should be {1}).z9Missing {0} in credentials configuration file {1}: * {2}r*ÚpropertyZ propertiesz * N) Ú_hasr@r/ryÚ_getr rcÚlenr}r[Újoin)rrYÚmessagesÚvarrrrr\"s$ ÿ ÿýÿz CredentialsConfiguration.require)r‡rcCs | |¡S)zØFind a configuration value for variable `var`, as transformed by `mapper`. :param str var: The variable to get. :returns: The value of the variable, if it exists. :rtype: str or None )rƒ©rr‡rrrr.;szCredentialsConfiguration.confcCs| |¡|jvSr2)ryr}rˆrrrr‚EszCredentialsConfiguration._hascCs|j | |¡¡Sr2)r}ÚgetryrˆrrrrƒHszCredentialsConfiguration._get)rlrmrnror_rrrr\rr.Úboolr‚rƒrrrrrXs $ rXrZcCs<tj |¡st d |¡¡‚tj |¡r8t d |¡¡‚dS)z&Ensure that the specified file exists.zFile not found: {0}zPath is a directory: {0}N)rrTÚexistsr rcr/ÚisdirrjrrrriLs  ricCs"t|ƒt |¡rt d|¡dS)zHEnsure that the specified file exists and warn about unsafe permissions.z8Unsafe permissions on credentials configuration file: %sN)rirZhas_world_permissionsr~Zwarningrjrrrr{Vs r{)r;rcs&| d¡‰‡fdd„tdtˆƒƒDƒS)aÂReturn a list of progressively less-specific domain names. One of these will probably be the domain name known to the DNS provider. :Example: >>> base_domain_name_guesses('foo.bar.baz.example.com') ['foo.bar.baz.example.com', 'bar.baz.example.com', 'baz.example.com', 'example.com', 'com'] :param str domain: The domain for which to return guesses. :returns: The a list of less specific domain names. :rtype: list Ú.csg|]}d ˆ|d…¡‘qS)r�N)r…)Ú.0rb©Z fragmentsrrÚ orxz,base_domain_name_guesses..r)ÚsplitÚranger„)r;rr�rÚbase_domain_name_guesses_s r“))rorqZloggingÚtimerÚtypingrrrrrrr|Zacmer Zcertbotr r r r Zcertbot.compatrrZcertbot.displayrrrBZcertbot.pluginsrZ getLoggerrlr~ZPluginZ AuthenticatorÚABCMetarrXr_rir{r“rrrrÚs6                  jG