a ‚oe™ã @spUdZddlZddlmZddlmZddlmZddlmZddlmZddlmZdd lm Z dd l m Z dd l m Z dd l mZgd ¢Ze jeeeefddfdœdd„Ze jedœdd„Ze je e jedœdd„Ze e jeee e je jddœdd„Zedddœdd„ZGdd„deejd�Zd d!d"ejd#d$d%gd#d&ed'd(d)d*œ gZeeeefed+<dS),z(New interface style Certbot enhancementséN)ÚAny)ÚCallable)ÚDict)Ú Generator)ÚIterable)ÚList)ÚOptional)Ú configuration)Ú interfaces)Ú constants)Zredirectzensure-http-headerz ocsp-stapling)ÚconfigÚreturnccs"tD]}t||dƒr|VqdS)z› Generator to yield the enabled new style enhancements. :param config: Configuration. :type config: certbot.configuration.NamespaceConfig Úcli_destN)Ú_INDEXÚgetattr)r Úenh©rú=C:\Program Files\Certbot\pkgs\certbot\plugins\enhancements.pyÚenabled_enhancementssrcCs tt|ƒƒS)zÉ Checks if one or more of the requested enhancements are those of the new enhancement interfaces. :param config: Configuration. :type config: certbot.configuration.NamespaceConfig )Úanyr)r rrrÚ are_requested(sr)r Ú installerr cCs&t|ƒD]}t||dƒsdSqdS)ai Checks that all of the requested enhancements are supported by the installer. :param config: Configuration. :type config: certbot.configuration.NamespaceConfig :param installer: Installer object :type installer: interfaces.Installer :returns: If all the requested enhancements are supported by the installer :rtype: bool ÚclassFT)rÚ isinstance)r rrrrrÚ are_supported3s r)ÚlineageÚdomainsrr r cCs*|r&t|ƒD]}t||dƒ||ƒq dS)a´ Run enable method for each requested enhancement that is supported. :param lineage: Certificate lineage object :type lineage: certbot.interfaces.RenewableCert :param domains: List of domains in certificate to enhance :type domains: str :param installer: Installer object :type installer: interfaces.Installer :param config: Configuration. :type config: certbot.configuration.NamespaceConfig Úenable_functionN)rr)rrrr rrrrÚenableHs r).N)Úaddr c Cs:tD]0}||d|d|d|d|d|dd�qdS) z« Populates the command line flags for certbot._internal.cli.HelpfulParser :param add: Add function of certbot._internal.cli.HelpfulParser :type add: func Ú cli_groupsÚcli_flagÚ cli_actionrÚcli_flag_defaultÚcli_help)ÚactionÚdestÚdefaultÚhelpN)r)rrrrrÚ populate_cli_s  þr)c@sneZdZdZejejeeddœdd„ƒZ ejejeeddœdd„ƒZ eje eje e eeddœd d „ƒZdS) ÚAutoHSTSEnhancementa; Enhancement interface that installer plugins can implement in order to provide functionality that configures the software to have a 'Strict-Transport-Security' with initially low max-age value that will increase over time. The plugins implementing new style enhancements are responsible of handling the saving of configuration checkpoints as well as calling possible restarts of managed software themselves. For update_autohsts method, the installer may have to call prepare() to finalize the plugin initialization. Methods: enable_autohsts is called when the header is initially installed using a low max-age value. update_autohsts is called every time when Certbot is run using 'renew' verb. The max-age value should be increased over time using this method. deploy_autohsts is called for every lineage that has had its certificate renewed. A long HSTS max-age value should be set here, as we should be confident that the user is able to automatically renew their certificates. N)rÚargsÚkwargsr cOsdS)aæ Gets called for each lineage every time Certbot is run with 'renew' verb. Implementation of this method should increase the max-age value. :param lineage: Certificate lineage object :type lineage: certbot.interfaces.RenewableCert .. note:: prepare() method inherited from `interfaces.Plugin` might need to be called manually within implementation of this interface method to finalize the plugin initialization. Nr©Úselfrr+r,rrrÚupdate_autohsts†sz#AutoHSTSEnhancement.update_autohstscOsdS)a Gets called for a lineage when its certificate is successfully renewed. Long max-age value should be set in implementation of this method. :param lineage: Certificate lineage object :type lineage: certbot.interfaces.RenewableCert Nrr-rrrÚdeploy_autohsts”sz#AutoHSTSEnhancement.deploy_autohsts)rrr+r,r cOsdS)a™ Enables the AutoHSTS enhancement, installing Strict-Transport-Security header with a low initial value to be increased over the subsequent runs of Certbot renew. :param lineage: Certificate lineage object :type lineage: certbot.interfaces.RenewableCert :param domains: List of domains in certificate to enhance :type domains: `list` of `str` Nr)r.rrr+r,rrrÚenable_autohstsžsz#AutoHSTSEnhancement.enable_autohsts)Ú__name__Ú __module__Ú __qualname__Ú__doc__ÚabcÚabstractmethodr Ú RenewableCertrr/r0rrÚstrr1rrrrr*ls  ÿr*)Ú metaclassZAutoHSTSzUGradually increasing max-age value for HTTP Strict Transport Security security headerz --auto-hstsZ auto_hstsZsecurityZenhanceÚ store_truer/r0r1) Únamer$r!r#r rr"rZupdater_functionZdeployer_functionrr) r5r6ÚtypingrrrrrrrZcertbotr r Zcertbot._internalr Z ENHANCEMENTSZNamespaceConfigr9rÚboolrZ Installerrr8rr)ÚobjectÚABCMetar*Z CLI_DEFAULTSrÚ__annotations__rrrrÚsJ           ÿ   ÿ þ  Gôÿ