§
    ¥”jÑ`  ã                   óÖ  — d dl Z d dlZd dlmZ d dlmZ d dlmZmZ d dl	m
Z d dl	mZ d dl	mZ d dlmZ d d	lmZmZ d d
lmZ d dlmZ d dlmZ d dlmZ d dlmZ d dlmZ d dl m!Z!m"Z" d dl#m$Z$ ddl%m&Z& ddl'm(Z(m)Z) ddl*m+Z+ g d¢Z,ddl-m.Z. ddl/m0Z0  ej1        e2¦  «        Z3e G d„ d¦  «        ¦   «         Z4d„ Z5 G d„ d¦  «        Z6	 d'd!e+d"e"fd#„Z7d d$d dd ej8        d$fd!e+d"e"d%e9fd&„Z:dS )(é    N)Ú	dataclass)Úfield)ÚIterableÚOptional)Úcrl)Úocsp)Úx509)ÚCertificate)ÚgenericÚmisc)Úpdf_name)ÚIncrementalPdfFileWriter)Úget_and_apply)Ú
PdfHandler)ÚBasePdfFileWriter)Úextract_tst_data_iter)ÚCertificateValidatorÚValidationContext)ÚValidationPathé   )Úextract_certificate_infoé   )ÚNoDSSFoundErrorÚValidationInfoReadingError)ÚEmbeddedPdfSignature)ÚVRIÚDocumentSecurityStoreÚasync_add_validation_infoÚcollect_validation_infoÚenumerate_ocsp_certsé   )ÚSerialisedCredential)ÚPdfFileReaderc                   ó–   — e Zd ZU dZ ee¬¦  «        Zeed<   	  ee¬¦  «        Zeed<   	  ee¬¦  «        Z	eed<   	 de
j        fd„ZdS )	r   aA  
    VRI dictionary as defined in PAdES / ISO 32000-2.
    These dictionaries collect data that may be relevant for the validation of
    a specific signature.

    .. note::
        The data are stored as PDF indirect objects, not asn1crypto values.
        In particular, values are tied to a specific PDF handler.
    )Údefault_factoryÚcertsÚocspsÚcrlsÚreturnc                 óx  — t          j        t          d¦  «        t          d¦  «        i¦  «        }| j        r)t          j        | j        ¦  «        |t          d¦  «        <   | j        r)t          j        | j        ¦  «        |t          d¦  «        <   t          j        | j        ¦  «        |t          d¦  «        <   |S )zT
        :return:
            A PDF dictionary representing this VRI entry.
        z/Typeú/VRIz/OCSPz/CRLz/Cert)r   ÚDictionaryObjectr   r'   ÚArrayObjectr(   r&   )ÚselfÚvris     új/var/www/finuniver-perm.ru/html/portfolio/venv/lib/python3.11/site-packages/pyhanko/sign/validation/dss.pyÚas_pdf_objectzVRI.as_pdf_objectB   s¡   € õ
 Ô&­°Ñ(9Ô(9½8ÀFÑ;KÔ;KÐ'LÑMÔMˆØŒ:ð 	EÝ%,Ô%8¸¼Ñ%DÔ%DˆC•˜Ñ!Ô!Ñ"ØŒ9ð 	CÝ$+Ô$7¸¼	Ñ$BÔ$BˆC•˜Ñ Ô Ñ!Ý!(Ô!4°T´ZÑ!@Ô!@ˆ�H�WÑÔÑØˆ
ó    N)Ú__name__Ú
__module__Ú__qualname__Ú__doc__Ú
data_fieldÚsetr&   Ú__annotations__r'   r(   r   r,   r1   © r2   r0   r   r   '   sª   € € € € € € ðð ð �¨CÐ0Ñ0Ô0€Eˆ3Ð0Ð0Ñ0ðð �¨CÐ0Ñ0Ô0€Eˆ3Ð0Ð0Ñ0ðð �
¨3Ð/Ñ/Ô/€Dˆ#Ð/Ð/Ñ/ðð˜wÔ7ð ð ð ð ð ð r2   r   c              #   ó    K  — | d         j         }|dk    r6| d         }|d         j         dk    r|d         j        }|d         E d{V —† dS dS dS )	zJ
    Essentially nabbed from _extract_ocsp_certs in ValidationContext
    Úresponse_statusÚ
successfulÚresponse_bytesÚresponse_typeÚbasic_ocsp_responseÚresponser&   N)ÚnativeÚparsed)Úocsp_responseÚstatusr>   rA   s       r0   r    r    P   s~   è è € ð
 Ð,Ô-Ô4€FØ�ÒÐØ&Ð'7Ô8ˆØ˜/Ô*Ô1Ð5JÒJÐJØ% jÔ1Ô8ˆHØ Ô(Ð(Ð(Ð(Ð(Ð(Ð(Ð(Ð(Ð(ð	 ÐàJÐJr2   c                   ól  — e Zd ZdZ	 	 	 	 	 ddee         fd„Zed„ ¦   «         Zd„ Z	d„ Z
d„ Zd	„ Zed
ej        fd„¦   «         Zddddœd„Zd„ Zd
eej                 fd„Zd
efd„Zeded
d fd„¦   «         Zedddddddœdeded
d fd„¦   «         Zeddddddddddœ	dededee         defd„¦   «         ZdS ) r   z,
    Representation of a DSS in Python.
    NÚwriterc                 óv  — |�|ni | _         |�|ni | _        |�|ng | _        |�|ng | _        || _        |�|nt          j        ¦   «         | _        i }| j        D ] }|                     ¦   «         j	        }	|||	<   Œ!|| _
        i }
| j        D ] }|                     ¦   «         j	        }||
|<   Œ!|
| _        d| _        d S )NF)Úvri_entriesr&   r'   r(   rG   r   r,   Úbacking_pdf_objectÚ
get_objectÚdataÚ_ocsps_seenÚ
_crls_seenÚ	_modified)r.   rG   r&   r'   r(   rI   rJ   Ú
ocsps_seenÚocsp_refÚ
ocsp_bytesÚ	crls_seenÚcrl_refÚ	crl_bytess                r0   Ú__init__zDocumentSecurityStore.__init__b   sú   € ð +6Ð*A˜;˜;ÀrˆÔØ#Ð/�U�U°RˆŒ
Ø#Ð/�U�U°RˆŒ
Ø Ð,�D�D°"ˆŒ	àˆŒð "Ð-ð ÐåÔ)Ñ+Ô+ð 	Ôð ˆ
Øœ
ð 	.ð 	.ˆHØ!×,Ò,Ñ.Ô.Ô3ˆJØ%-ˆJ�zÑ"Ð"Ø%ˆÔàˆ	Ø”yð 	+ð 	+ˆGØ×*Ò*Ñ,Ô,Ô1ˆIØ#*ˆI�iÑ Ð Ø#ˆŒØˆŒˆˆr2   c                 ó   — | j         S ©N)rO   ©r.   s    r0   ÚmodifiedzDocumentSecurityStore.modified„   s
   € àŒ~Ðr2   c                 óv   — | j         s/d| _         | j        �#| j                             | j        ¦  «         d S d S d S )NT)rO   rJ   rG   Úupdate_containerrY   s    r0   Ú_mark_modifiedz$DocumentSecurityStore._mark_modifiedˆ   sN   € ØŒ~ð 	FØ!ˆDŒNØÔ&Ð2Ø”×,Ò,¨TÔ-DÑEÔEÐEÐEÐEð	Fð 	Fà2Ð2r2   c              #   ó0  K  — |D ]�}|                      ¦   «         }	 ||         V — Œ"# t          $ rb | j                             t	          j        |¬¦  «        ¦  «        }|                      ¦   «          |||<   |                     |¦  «         |V — Y Œ�w xY wd S )N©Ústream_data)ÚdumpÚKeyErrorrG   Ú
add_objectr   ÚStreamObjectr]   Úappend)r.   ÚobjsÚseenÚdestÚobjÚ	obj_bytesÚrefs          r0   Ú_cms_objects_to_streamsz-DocumentSecurityStore._cms_objects_to_streamsŽ   sÃ   è è € Øð 	ð 	ˆCØŸš™
œ
ˆIð	Ø˜9”oÐ%Ð%Ð%Ð%øÝð ð ð Ø”k×,Ò,ÝÔ(°YÐ?Ñ?Ô?ñô �ð ×#Ò#Ñ%Ô%Ð%Ø"%��Y‘Ø—’˜CÑ Ô Ð Ø�	�	�	�	�	ðøøøð		ð 	s   œ
'§A)BÂBc                 ó<   ‡ ‡— ˆfd„}ˆ fd„ |¦   «         D ¦   «         S )Nc               3   ó@   •K  — ‰D ]} t          | ¦  «        E d {V —† Œd S rX   )r    )Úrespr'   s    €r0   Úextra_certszADocumentSecurityStore._embed_certs_from_ocsp.<locals>.extra_certs�   sC   øè è € Øð 6ð 6�Ý/°Ñ5Ô5Ð5Ð5Ð5Ð5Ð5Ð5Ð5Ð5ð6ð 6r2   c                 ó:   •— g | ]}‰                      |¦  «        ‘ŒS r:   ©Ú_embed_cert)Ú.0Úcert_r.   s     €r0   ú
<listcomp>z@DocumentSecurityStore._embed_certs_from_ocsp.<locals>.<listcomp>¡   s'   ø€ ÐCÐCÐC¨E�× Ò  Ñ'Ô'ÐCÐCÐCr2   r:   )r.   r'   rp   s   `` r0   Ú_embed_certs_from_ocspz,DocumentSecurityStore._embed_certs_from_ocspœ   s@   øø€ ð	6ð 	6ð 	6ð 	6ð 	6ð DÐCÐCÐC°[°[±]´]ÐCÑCÔCÐCr2   c                 ó<  — | j         €t          d¦  «        ‚	 | j        |j                 S # t          $ r Y nw xY w| j                              t          j        |                     ¦   «         ¬¦  «        ¦  «        }|  	                    ¦   «          || j        |j        <   |S )Nú"This DSS does not support updates.r_   )
rG   Ú	TypeErrorr&   Úissuer_serialrb   rc   r   rd   ra   r]   )r.   Úcertrk   s      r0   rs   z!DocumentSecurityStore._embed_cert£   s¨   € ØŒ;ÐÝÐ@ÑAÔAÐAð	Ø”:˜dÔ0Ô1Ð1øÝð 	ð 	ð 	ØˆDð	øøøð Œk×$Ò$ÝÔ ¨T¯YªY©[¬[Ð9Ñ9Ô9ñ
ô 
ˆð 	×ÒÑÔÐØ),ˆŒ
�4Ô%Ñ&Øˆ
s   ˜* ª
7¶7r)   c                 óº   — t          j        | ¦  «                             ¦   «                              ¦   «                              ¦   «         }t          d|z   ¦  «        S )a  
        Hash the contents of a signature object to get the corresponding VRI
        identifier.

        This is internal API.

        :param contents:
            Signature contents.
        :return:
            A name object to put into the DSS.
        ú/)ÚhashlibÚsha1ÚdigestÚhexÚupperr   )ÚcontentsÚidents     r0   Úsig_content_identifierz,DocumentSecurityStore.sig_content_identifier³   sI   € õ ”˜XÑ&Ô&×-Ò-Ñ/Ô/×3Ò3Ñ5Ô5×;Ò;Ñ=Ô=ˆÝ˜˜e™Ñ$Ô$Ð$r2   r:   ©r&   r'   r(   c                óª  ‡ — ‰ j         €t          d¦  «        ‚t          |¦  «        }t          |¦  «        }t          ¦   «         }t          ¦   «         }ˆ fd„|D ¦   «         }|r.t          ‰                      |‰ j        ‰ j        ¦  «        ¦  «        }|r.t          ‰                      |‰ j        ‰ j        ¦  «        ¦  «        }| 	                    t          ‰  
                    |¦  «        ¦  «        ¦  «         |�\t          |||¬¦  «        }‰ j                              |                     ¦   «         ¦  «        ‰ j        |<   ‰                      ¦   «          dS dS )a÷  
        Register validation information for a set of signing certificates
        associated with a particular signature.

        :param identifier:
            Identifier of the signature object (see `sig_content_identifier`).
            If ``None``, only embed the data into the DSS without associating
            it with any VRI.
        :param certs:
            Certificates to add.
        :param ocsps:
            OCSP responses to add.
        :param crls:
            CRLs to add.
        Nry   c                 ó:   •— h | ]}‰                      |¦  «        ’ŒS r:   rr   )rt   r|   r.   s     €r0   ú	<setcomp>z5DocumentSecurityStore.register_vri.<locals>.<setcomp>Ü   s'   ø€ Ð>Ð>Ð>°�T×%Ò% dÑ+Ô+Ð>Ð>Ð>r2   r‡   )rG   rz   Úlistr8   rl   rM   r'   rN   r(   Úupdaterw   r   rc   r1   rI   r]   )	r.   Ú
identifierr&   r'   r(   Ú	ocsp_refsÚcrl_refsÚ	cert_refsr/   s	   `        r0   Úregister_vriz"DocumentSecurityStore.register_vriÃ   s]  ø€ ð" Œ;ÐÝÐ@ÑAÔAÐAå�U‘”ˆÝ�D‰zŒzˆå‘E”Eˆ	Ý‘5”5ˆØ>Ð>Ð>Ð>¸Ð>Ñ>Ô>ˆ	Øð 	ÝØ×,Ò,Ø˜4Ô+¨T¬Zñô ñô ˆIð
 ð 	ÝØ×,Ò,¨T°4´?ÀDÄIÑNÔNñô ˆHð
 	×Ò�˜T×8Ò8¸Ñ?Ô?Ñ@Ô@ÑAÔAÐAð Ð!Ý˜I¨Y¸XÐFÑFÔFˆCØ+/¬;×+AÒ+AØ×!Ò!Ñ#Ô#ñ,ô ,ˆDÔ˜ZÑ(ð ×ÒÑ!Ô!Ð!Ð!Ð!ð "Ð!r2   c                 ó�  — | j         }t          j        t          | j                             ¦   «         ¦  «        ¦  «        |d<   | j        rt          j        | j        ¦  «        |d<   | j        r)t          j        | j        ¦  «        |t          d¦  «        <   | j
        r)t          j        | j
        ¦  «        |t          d¦  «        <   |S )zÌ
        Convert the :class:`.DocumentSecurityStore` object to a python
        dictionary. This method also handles DSS updates.

        :return:
            A PDF object representing this DSS.
        ú/Certsr+   ú/OCSPsú/CRLs)rJ   r   r-   r‹   r&   ÚvaluesrI   r,   r'   r   r(   )r.   Úpdf_dicts     r0   r1   z#DocumentSecurityStore.as_pdf_objectô   s´   € ð Ô*ˆÝ$Ô0µ°d´j×6GÒ6GÑ6IÔ6IÑ1JÔ1JÑKÔKˆ�ÑØÔð 	JÝ&Ô7¸Ô8HÑIÔIˆH�VÑàŒ:ð 	KÝ+2Ô+>¸t¼zÑ+JÔ+JˆH•X˜hÑ'Ô'Ñ(àŒ9ð 	IÝ*1Ô*=¸d¼iÑ*HÔ*HˆH•X˜gÑ&Ô&Ñ'àˆr2   c              #   ó¤   K  — | j                              ¦   «         D ]3}|                     ¦   «         }t          j        |j        ¦  «        }|V — Œ4dS )zª
        Return a generator that parses and yields all certificates in the DSS.

        :return:
            A generator yielding :class:`.Certificate` objects.
        N)r&   r–   rK   r
   ÚloadrL   )r.   Úcert_refÚcert_streamr|   s       r0   Ú
load_certsz DocumentSecurityStore.load_certs	  s^   è è € ð œ
×)Ò)Ñ+Ô+ð 	ð 	ˆHØ08×0CÒ0CÑ0EÔ0EˆKÝÔ# KÔ$4Ñ5Ô5ˆDØˆJˆJˆJˆJð	ð 	r2   c                 ó¬  — t          |¦  «        }|                     dg ¦  «        }t          |                      ¦   «         ¦  «        |z   }t          |                     dd¦  «        ¦  «        }| j        D ]O}|                     ¦   «         }t          j                             |j	        ¦  «        }| 
                    |¦  «         ŒP||d<   t          |                     dd¦  «        ¦  «        }| j        D ]O}	|	                     ¦   «         }
t          j                             |
j	        ¦  «        }| 
                    |¦  «         ŒP||d<   t          dd|i|¤ŽS )a  
        Construct a validation context from the data in this DSS.

        :param validation_context_kwargs:
            Extra kwargs to pass to the ``__init__`` function.
        :return:
            A validation context preloaded with information from this DSS.
        Úother_certsr'   r:   r(   )ÚdictÚpopr‹   rœ   r'   rK   Ú	asn1_ocspÚOCSPResponser™   rL   re   r(   Úasn1_crlÚCertificateListr   )r.   Úvalidation_context_kwargsrp   r&   r'   rQ   Úocsp_streamro   r(   rT   Ú
crl_streamr   s               r0   Úas_validation_contextz+DocumentSecurityStore.as_validation_context  sO  € õ %)Ð)BÑ$CÔ$CÐ!Ø/×3Ò3°MÀ2ÑFÔFˆÝ�T—_’_Ñ&Ô&Ñ'Ô'¨+Ñ5ˆåÐ.×2Ò2°7¸BÑ?Ô?Ñ@Ô@ˆØœ
ð 	ð 	ˆHØ08×0CÒ0CÑ0EÔ0EˆKÝÔ)×.Ò.¨{Ô/?Ñ@Ô@ˆDØ�LŠL˜ÑÔÐÐØ-2Ð! 'Ñ*åÐ-×1Ò1°&¸"Ñ=Ô=Ñ>Ô>ˆØ”yð 	ð 	ˆGØ/6×/AÒ/AÑ/CÔ/CˆJÝÔ*×/Ò/°
´Ñ@Ô@ˆCØ�KŠK˜ÑÔÐÐØ,0Ð! &Ñ)å ÐPÐP¨UÐPÐ6OÐPÐPÐPr2   Úhandlerc                 ój  — 	 |j         d         }n!# t          $ r}t          ¦   «         |‚d}~ww xY wi }t          |dt          g ¬¦  «        }|D ]9}|                     ¦   «         }t          j        |j        ¦  «        }|||j	        <   Œ:t          |dt          g ¬¦  «        }	g }
|	D ]O}|                     ¦   «         }t          j                             |j        ¦  «        }|
                     |¦  «         ŒPt          |dt          g ¬¦  «        }g }|D ]O}|                     ¦   «         }t          j                             |j        ¦  «        }|                     |¦  «         ŒP	 t          |d         ¦  «        }n# t          $ r d}Y nw xY wt!          |t"          ¦  «        r|}nd} | |||	|||¬¦  «        }|S )	a  
        Read a DSS record from a file and add the data to a validation context.

        :param handler:
            PDF handler from which to read the DSS.
        :return:
            A DocumentSecurityStore object describing the current state of the
            DSS.
        ú/DSSNr“   )Údefaultr”   r•   r+   )rG   r&   r'   rI   r(   rJ   )Úrootrb   r   r   r‹   rK   r
   r™   rL   r{   r¡   r¢   re   r£   r¤   rŸ   Ú
isinstancer   )Úclsr©   Údss_dictÚer�   Úcert_ref_listrš   r›   r|   rŽ   r'   rQ   r¦   ro   r�   r(   rT   r§   r   rI   rG   Údsss                         r0   Úread_dsszDocumentSecurityStore.read_dss5  s  € ð	+Ø”| FÔ+ˆHˆHøÝð 	+ð 	+ð 	+Ý!Ñ#Ô#¨Ð*øøøøð	+øøøð ˆ	Ý% h°½$ÈÐKÑKÔKˆØ%ð 	5ð 	5ˆHØ08×0CÒ0CÑ0EÔ0EˆKÝ +Ô 0°Ô1AÑ BÔ BˆDØ,4ˆI�dÔ(Ñ)Ð)å! (¨HµdÀBÐGÑGÔGˆ	ØˆØ!ð 	ð 	ˆHØ08×0CÒ0CÑ0EÔ0EˆKÝÔ)×.Ò.¨{Ô/?Ñ@Ô@ˆDØ�LŠL˜ÑÔÐÐå  ¨7µDÀ"ÐEÑEÔEˆØˆØð 	ð 	ˆGØ/6×/AÒ/AÑ/CÔ/CˆJÝÔ*×/Ò/°
´Ñ@Ô@ˆCØ�KŠK˜ÑÔÐÐð	Ý˜x¨Ô/Ñ0Ô0ˆKˆKøÝð 	ð 	ð 	ØˆKˆKˆKð	øøøõ �gÕ0Ñ1Ô1ð 	ØˆFˆFàˆFð
 ˆcØØØØ#ØØ'ð
ñ 
ô 
ˆð ˆ
s"   ‚ �
.š)©.Å E6 Å6FÆFT©r&   r'   r(   ÚpathsÚvalidation_contextÚembed_rootsÚpdf_outr¸   c                ó"  ‡‡‡‡‡‡— 	 |                       |¦  «        }	d}
n# t          $ r d}
 | |¬¦  «        }	Y nw xY w|�t                               |¦  «        }nd}dt          t
          j                 fˆˆˆfd„}ˆˆfd„}ˆˆfd„}|	                     | |¦   «          |¦   «          |¦   «         ¬	¦  «         |	                     ¦   «         }|
r@| 	                    |¦  «        }||j
        t          d
¦  «        <   |                     ¦   «          |	S )aD  
        Add or update a DSS, and optionally associate the new information with a
        VRI entry tied to a signature object.

        You can either specify the CMS objects to include directly, or
        pass them in as output from `pyhanko_certvalidator`.

        :param pdf_out:
            PDF writer to write to.
        :param sig_contents:
            Contents of the new signature (used to compute the VRI hash), as
            a hexadecimal string, including any padding.
            If ``None``, the information will not be added to any VRI
            dictionary.
        :param certs:
            Certificates to include in the VRI entry.
        :param ocsps:
            OCSP responses to include in the VRI entry.
        :param crls:
            CRLs to include in the VRI entry.
        :param paths:
            Validation paths that have been established, and need to be added
            to the DSS.
        :param validation_context:
            Validation context from which to draw OCSP responses and CRLs.
        :param embed_roots:
            .. versionadded:: 0.9.0

            Option that controls whether the root certificate of each validation
            path should be embedded into the DSS. The default is ``True``.

            .. note::
                Trust roots are configured by the validator, so embedding them
                typically does nothing in a typical validation process.
                Therefore they can be safely omitted in most cases.
                Nonetheless, embedding the roots can be useful for documentation
                purposes.

            .. warning::
                This only applies to paths, not the ``certs`` parameter.

        :return:
            a :class:`DocumentSecurityStore` object containing both the new
            and existing contents of the DSS (if any).
        FT)rG   Nr)   c               3   ó~   •K  — ‰pdE d {V —† ‰pdD ]*} t          | ¦  «        }‰st          |¦  «         |E d {V —† Œ+d S ©Nr:   )ÚiterÚnext)ÚpathÚ
path_partsr&   r¸   r¶   s     €€€r0   Ú_certsz:DocumentSecurityStore.supply_dss_in_writer.<locals>._certs»  s|   øè è € Ø�{ Ð"Ð"Ð"Ð"Ð"Ð"Ð"à˜ ð &ð &�Ý! $™ZœZ�
Ø"ð %å˜Ñ$Ô$Ð$Ø%Ð%Ð%Ð%Ð%Ð%Ð%Ð%Ð%ð&ð &r2   c               3   óB   •K  — ‰ pdE d {V —† ‰�‰j         E d {V —† d S d S r¼   )r'   )r'   r·   s   €€r0   Ú_ocspsz:DocumentSecurityStore.supply_dss_in_writer.<locals>._ocspsÅ  sR   øè è € Ø�{ Ð"Ð"Ð"Ð"Ð"Ð"Ð"Ø!Ð-Ø-Ô3Ð3Ð3Ð3Ð3Ð3Ð3Ð3Ð3Ð3ð .Ð-r2   c               3   óB   •K  — ‰ pdE d {V —† ‰�‰j         E d {V —† d S d S r¼   )r(   )r(   r·   s   €€r0   Ú_crlsz9DocumentSecurityStore.supply_dss_in_writer.<locals>._crlsÊ  sR   øè è € Ø�z˜rÐ!Ð!Ð!Ð!Ð!Ð!Ð!Ø!Ð-Ø-Ô2Ð2Ð2Ð2Ð2Ð2Ð2Ð2Ð2Ð2ð .Ð-r2   r‡   r«   )r´   r   r   r†   r   r	   r
   r‘   r1   rc   r­   r   Úupdate_root)r¯   r¹   Úsig_contentsr&   r'   r(   r¶   r·   r¸   r³   Úcreatedr�   rÁ   rÃ   rÅ   r°   Údss_refs      ``````        r0   Úsupply_dss_in_writerz*DocumentSecurityStore.supply_dss_in_writers  s�  øøøøøø€ ðt	&Ø—,’,˜wÑ'Ô'ˆCØˆGˆGøÝ)ð 	&ð 	&ð 	&ØˆGØ�#˜WÐ%Ñ%Ô%ˆCˆCˆCð	&øøøð Ð#Ý.×EÒEØñô ˆJˆJð ˆJð	&�¥Ô!1Ô2ð 	&ð 	&ð 	&ð 	&ð 	&ð 	&ð 	&ð 	&ð	4ð 	4ð 	4ð 	4ð 	4ð 	4ð
	3ð 	3ð 	3ð 	3ð 	3ð 	3ð
 	×ÒØ˜f˜f™hœh¨f¨f©h¬h¸U¸U¹W¼Wð 	ñ 	
ô 	
ð 	
ð ×$Ò$Ñ&Ô&ˆð ð 	"Ø×(Ò(¨Ñ2Ô2ˆGØ-4ˆGŒL� &Ñ)Ô)Ñ*Ø×ÒÑ!Ô!Ð!Øˆ
s   ˆ   ;º;F)	r&   r'   r(   r¶   r·   Úforce_writer¸   Úfile_credentialÚstrictrË   rÌ   rÍ   c       	   
      óæ   — t          ||¬¦  «        }|j        �|
�|j                             |
¦  «         |                      ||||||||	¬¦  «        }|s|j        r|                     ¦   «          dS dS )a¤  
        Wrapper around :meth:`supply_dss_in_writer`.

        The result is applied to the output stream as an incremental update.

        :param output_stream:
            Output stream to write to.
        :param sig_contents:
            Contents of the new signature (used to compute the VRI hash), as
            a hexadecimal string, including any padding.
            If ``None``, the information will not be added to any VRI
            dictionary.
        :param certs:
            Certificates to include in the VRI entry.
        :param ocsps:
            OCSP responses to include in the VRI entry.
        :param crls:
            CRLs to include in the VRI entry.
        :param paths:
            Validation paths that have been established, and need to be added
            to the DSS.
        :param force_write:
            Force a write even if the DSS doesn't have any new content.
        :param validation_context:
            Validation context from which to draw OCSP responses and CRLs.
        :param embed_roots:
            .. versionadded:: 0.9.0

            Option that controls whether the root certificate of each validation
            path should be embedded into the DSS. The default is ``True``.

            .. note::
                Trust roots are configured by the validator, so embedding them
                typically does nothing in a typical validation process.
                Therefore they can be safely omitted in most cases.
                Nonetheless, embedding the roots can be useful for documentation
                purposes.

            .. warning::
                This only applies to paths, not the ``certs`` parameter.
        :param file_credential:
            .. versionadded:: 0.13.0

            Serialised file credential, to update encrypted files.
        :param strict:
            If ``True``, enforce strict validation of the input stream.
            Default is ``True``.
        )rÍ   Nrµ   )r   Úsecurity_handlerÚauthenticaterÊ   rZ   Úwrite_in_place)r¯   Úoutput_streamrÇ   r&   r'   r(   r¶   r·   rË   r¸   rÌ   rÍ   r¹   r³   s                 r0   Úadd_dsszDocumentSecurityStore.add_dssÜ  s£   € õ@ +¨=ÀÐHÑHÔHˆØÔ#Ð/°OÐ4OØÔ$×1Ò1°/ÑBÔBÐBØ×&Ò&ØØØØØØØ1Ø#ð 'ñ 	
ô 	
ˆð ð 	%˜#œ,ð 	%Ø×"Ò"Ñ$Ô$Ð$Ð$Ð$ð	%ð 	%r2   )NNNNN) r3   r4   r5   r6   r   r   rV   ÚpropertyrZ   r]   rl   rw   rs   Ústaticmethodr   Ú
NameObjectr†   r‘   r1   r   r	   r
   rœ   r   r¨   Úclassmethodr   r´   ÚboolrÊ   r"   rÓ   r:   r2   r0   r   r   ]   sj  € € € € € ðð ð ØØØØð ð  àÐ*Ô+ð ð  ð  ð  ðD ðð ñ „XððFð Fð Fðð ð ðDð Dð Dðð ð ð  ð%¨GÔ,>ð %ð %ð %ñ „\ð%ð 13¸"À2ð /"ð /"ð /"ð /"ð /"ðbð ð ð*
˜H TÔ%5Ô6ð 
ð 
ð 
ð 
ðQà	ðQð Qð Qð Qð@ ð;˜zð ;Ð.Eð ;ð ;ð ;ñ „[ð;ðz ð ØØØØØ ðfð fð fà"ðfð ðfð 
!ðfð fð fñ „[ðfðP ð ØØØØØ!Ø Ø:>ØðM%ð M%ð M%ð ðM%ð ðM%ð "Ð"6Ô7ðM%ð ðM%ð M%ð M%ñ „[ðM%ð M%ð M%r2   r   FÚembedded_sigr·   c              ƒ   ó  ‡‡K  — ‰j         j        }|j        st                               d¦  «         g Šˆˆfd„} || j        ¦  «        ƒ d{V —† |s/dD ],}t          | j        |¬¦  «        D ]} ||¦  «        ƒ d{V —† ŒŒ-‰S )a  
    Query revocation info for a PDF signature using a validation context,
    and store the results in a validation context.

    This works by validating the signer's certificate against the provided
    validation context, which causes revocation info to be cached for
    later retrieval.

    .. warning::
        This function does *not* actually validate the signature, but merely
        checks the signer certificate's chain of trust.

    :param embedded_sig:
        Embedded PDF signature to operate on.
    :param validation_context:
        Validation context to use.
    :param skip_timestamp:
        If the signature has a time stamp token attached to it, also collect
        revocation information for the timestamp.
    :return:
        A list of validation paths.
    zfRevocation mode is set to soft-fail/tolerant mode; collected revocation information may be incomplete.c              “   óä   •K  — t          | ¦  «        }|j        }|j        }t          ||‰¬¦  «        }|                     t          ¦   «         ¬¦  «        ƒ d {V —†}‰                     |¦  «         d S )N)Úintermediate_certsr·   )Ú	key_usage)r   Úsigner_certrž   r   Úasync_validate_usager8   re   )Úsigned_dataÚ	cert_infor|   rž   Ú	validatorr¿   r¶   r·   s         €€r0   Ú_validate_signed_dataz6collect_validation_info.<locals>._validate_signed_dataT  s‡   øè è € Ý,¨[Ñ9Ô9ˆ	ØÔ$ˆØÔ+ˆå(ØØ*Ø1ð
ñ 
ô 
ˆ	ð
 ×3Ò3½c¹e¼eÐ3ÑDÔDÐDÐDÐDÐDÐDÐDˆØ�Š�TÑÔÐÐÐr2   N)FT)Úsigned)Úrevinfo_policyÚrevocation_checking_policyÚ	essentialÚloggerÚwarningrà   r   Úsigner_info)rÙ   r·   Úskip_timestampÚrevinfo_fetch_policyrã   rä   Útst_signed_datar¶   s    `     @r0   r   r   -  sþ   øøè è € ð: 	Ô)ÔDð ð  Ô)ð 
Ý�Šð8ñ	
ô 	
ð 	
ð
 €Eðð ð ð ð ð ð  Ð
 Ô 8Ñ
9Ô
9Ð9Ð9Ð9Ð9Ð9Ð9Ð9Øð =Ø#ð 	=ð 	=ˆFÝ#8ØÔ(°ð$ñ $ô $ð =ð =�ð ,Ð+¨OÑ<Ô<Ð<Ð<Ð<Ð<Ð<Ð<Ð<Ð<ð=ð €Lr2   Tr¸   c	              ƒ   ó   K  — | j         }	|r|	j        x}
}t          j        |¦  «         nt          j        |¦  «        }
t          | ||¬¦  «        ƒ d{V —†}|r-| j                             ¦   «                              d¦  «        }nd}t          j
        |	¦  «        }||_        t                               |||||¬¦  «        }|s|j        r-|r|                     ¦   «          nZ|                     |
¦  «         nD|sB|	j                             d¦  «         t          j        t'          |¦  «        |	j        |
¦  «         t          j        ||
¦  «        S )aY  
    .. versionadded: 0.9.0

    Add validation info (CRLs, OCSP responses, extra certificates) for a
    signature to the DSS of a document in an incremental update.
    This is a wrapper around :func:`collect_validation_info`.

    :param embedded_sig:
        The signature for which the revocation information needs to be
        collected.
    :param validation_context:
        The validation context to use.
    :param skip_timestamp:
        If ``True``, do not attempt to validate the timestamp attached to
        the signature, if one is present.
    :param add_vri_entry:
        Add a ``/VRI`` entry for this signature to the document security store.
        Default is ``True``.
    :param output:
        Write the output to the specified output stream.
        If ``None``, write to a new :class:`.BytesIO` object.
        Default is ``None``.
    :param in_place:
        Sign the original input stream in-place.
        This parameter overrides ``output``.
    :param chunk_size:
        Chunk size parameter to use when copying output to a new stream
        (irrelevant if ``in_place`` is ``True``).
    :param force_write:
        Force a new revision to be written, even if not necessary (i.e.
        when all data in the validation context is already present in the DSS).
    :param embed_roots:
        Option that controls whether the root certificate of each validation
        path should be embedded into the DSS. The default is ``True``.

        .. note::
            Trust roots are configured by the validator, so embedding them
            typically does nothing in a typical validation process.
            Therefore they can be safely omitted in most cases.
            Nonetheless, embedding the roots can be useful for documentation
            purposes.
    :return:
        The (file-like) output object to which the result was written.
    )rë   NÚascii)r·   r¶   r¸   r   )ÚreaderÚstreamr   Ú!assert_writable_and_random_accessÚprepare_rw_output_streamr   Úpkcs7_contentr‚   Úencoder   Úfrom_readerÚIO_CHUNK_SIZEr   rÊ   rZ   rÑ   ÚwriteÚseekÚchunked_writeÚ	bytearrayÚfinalise_output)rÙ   r·   rë   Úadd_vri_entryÚin_placeÚoutputrË   Ú
chunk_sizer¸   rð   Úworking_outputr¶   rÇ   r¹   Úresulting_dsss                  r0   r   r   k  s–  è è € ðp )Ô/€Fð ð 	?Ø"(¤-Ð/ˆ˜õ 	Ô.¨vÑ6Ô6Ð6Ð6åÔ6°vÑ>Ô>ˆå)ØÐ(¸ðñ ô ð ð ð ð ð ð €Eð ð Ø#Ô1×5Ò5Ñ7Ô7×>Ò>¸wÑGÔGˆˆàˆå&Ô2°6Ñ:Ô:€GØ&€GÔÝ)×>Ò>ØØØ-ØØð ?ñ ô €Mð ð 	Q�mÔ,ð 	QØð 	*Ø×"Ò"Ñ$Ô$Ð$Ð$à�MŠM˜.Ñ)Ô)Ð)Ð)Øð Qð 	Œ×Ò˜1ÑÔÐÝÔ�9 ZÑ0Ô0°&´-ÀÑPÔPÐPÝÔ ¨Ñ7Ô7Ð7r2   )F);r   ÚloggingÚdataclassesr   r   r7   Útypingr   r   Ú
asn1cryptor   r£   r   r¡   r	   Úasn1crypto.x509r
   Úpyhanko.pdf_utilsr   r   Úpyhanko.pdf_utils.genericr   Ú$pyhanko.pdf_utils.incremental_writerr   Úpyhanko.pdf_utils.miscr   Úpyhanko.pdf_utils.rw_commonr   Úpyhanko.pdf_utils.writerr   Ú#pyhanko.sign.validation.generic_cmsr   Úpyhanko_certvalidatorr   r   Úpyhanko_certvalidator.pathr   Úgeneralr   Úerrorsr   r   Úpdf_embeddedr   Ú__all__Úpdf_utils.cryptr"   Úpdf_utils.readerr#   Ú	getLoggerr3   rè   r   r    r   r   ÚDEFAULT_CHUNK_SIZErØ   r   r:   r2   r0   ú<module>r     sÓ  ðØ €€€Ø €€€Ø !Ð !Ð !Ð !Ð !Ð !Ø +Ð +Ð +Ð +Ð +Ð +Ø %Ð %Ð %Ð %Ð %Ð %Ð %Ð %à &Ð &Ð &Ð &Ð &Ð &Ø (Ð (Ð (Ð (Ð (Ð (Ø Ð Ð Ð Ð Ð Ø 'Ð 'Ð 'Ð 'Ð 'Ð 'Ø +Ð +Ð +Ð +Ð +Ð +Ð +Ð +Ø .Ð .Ð .Ð .Ð .Ð .Ø IÐ IÐ IÐ IÐ IÐ IØ 0Ð 0Ð 0Ð 0Ð 0Ð 0Ø 2Ð 2Ð 2Ð 2Ð 2Ð 2Ø 6Ð 6Ð 6Ð 6Ð 6Ð 6Ø EÐ EÐ EÐ EÐ EÐ EØ IÐ IÐ IÐ IÐ IÐ IÐ IÐ IØ 5Ð 5Ð 5Ð 5Ð 5Ð 5à .Ð .Ð .Ð .Ð .Ð .Ø ?Ð ?Ð ?Ð ?Ð ?Ð ?Ð ?Ð ?Ø .Ð .Ð .Ð .Ð .Ð .ðð ð €ð 4Ð 3Ð 3Ð 3Ð 3Ð 3Ø -Ð -Ð -Ð -Ð -Ð -à	ˆÔ	˜8Ñ	$Ô	$€ð ð%ð %ð %ð %ð %ñ %ô %ñ „ð%ðP
)ð 
)ð 
)ðM%ð M%ð M%ð M%ð M%ñ M%ô M%ð M%ðf ð;ð ;Ø&ð;à)ð;ð ;ð ;ð ;ðB ØØØØØÔ&Øðc8ð c8Ø&ðc8à)ðc8ð ðc8ð c8ð c8ð c8ð c8ð c8r2   