§
    ¥”j©0  ã                   óö   — d dl Z d dlmZ d dlmZmZmZmZmZ d dl	m
Z
mZ ddlmZ ddlmZmZmZ ddlmZmZ  ed	¬
¦  «         G d„ d¦  «        ¦   «         Zeej        e
j        f         Z G d„ d¦  «        ZdS )é    N)Ú	dataclass)Ú	FrozenSetÚIterableÚIteratorÚOptionalÚUnion)ÚcmsÚx509é   )Ú
AAControls)Ú	AuthorityÚAuthorityWithCertÚTrustAnchor)Úget_ac_extension_valueÚget_issuer_dnT)Úfrozenc                   ó2   — e Zd ZU eed<   	 eed<   	 eed<   dS )ÚQualifiedPolicyÚissuer_domain_policy_idÚuser_domain_policy_idÚ
qualifiersN)Ú__name__Ú
__module__Ú__qualname__ÚstrÚ__annotations__Ú	frozenset© ó    úi/var/www/finuniver-perm.ru/html/portfolio/venv/lib/python3.11/site-packages/pyhanko_certvalidator/path.pyr   r      sH   € € € € € € à Ð Ð Ñ ðð ÐÐÑðð ÐÐÑðð r   r   c                   ó.  — e Zd ZU dZdZeee                  ed<   dZ	de
deej                 dee         fd„Zede
fd	„¦   «         Zed
„ ¦   «         Zedee         fd„¦   «         Zdee         fd„Zdeej                 fd„Zedej        fd„¦   «         Zdee         fd„Zdefd„Zdej        defd„Zdej        fd„Zdefd„Zd"d„Zd„ Zdeee                  fd„Z de!j"        de#fd„Z$ed„ ¦   «         Z%d„ Z&d„ Z'de#de(ej                 fd„Z)d „ Z*d!„ Z+dS )#ÚValidationPathza
    Represents a path going towards an end-entity certificate or attribute
    certificate.
    NÚ_qualified_policiesÚtrust_anchorÚintermÚleafc                 óp   — |r|st          d¦  «        ‚t          |¦  «        | _        || _        || _        d S )Nz-Leafless paths cannot have intermediate certs)Ú
ValueErrorÚlistÚ_intermÚ_rootÚ_leaf)Úselfr$   r%   r&   s       r    Ú__init__zValidationPath.__init__0   sC   € ð ð 	N˜$ð 	NÝÐLÑMÔMÐMÝ˜F‘|”|ˆŒØ!ˆŒ
ØˆŒ
ˆ
ˆ
r   Úreturnc                 ó   — | j         S ©N)r+   ©r-   s    r    r$   zValidationPath.trust_anchor<   s
   € àŒzÐr   c                 óÊ   — | j         j        }t          |t          ¦  «        r|j        S | j        r| j        d         S t          | j        t          j        ¦  «        r| j        S dS )a  
        Returns the current beginning of the path - for a path to be complete,
        this certificate should be a trust root

        .. warning::
            This is a compatibility property, and will return the first non-root
            certificate if the trust root is not provisioned as a certificate.
            If you want the trust root itself (even when it doesn't have a
            certificate), use :attr:`trust_anchor`.

        :return:
            The first asn1crypto.x509.Certificate object in the path
        r   N)	r+   Ú	authorityÚ
isinstancer   Úcertificater*   r,   r
   ÚCertificate)r-   Úroots     r    ÚfirstzValidationPath.first@   si   € ð ŒzÔ#ˆÝ�dÕ-Ñ.Ô.ð 	ØÔ#Ð#ØŒ\ð 	Ø”< ”?Ð"Ý˜œ
¥DÔ$4Ñ5Ô5ð 	Ø”:Ðð	ð 	r   c                 ó€   — | j         �| j         S | j        s(| j        j        }t	          |t
          ¦  «        r|j        S dS )a<  
        Returns the current leaf certificate (AC or public-key).
        The trust root's certificate will be returned if there is one and
        there are no other certificates in the path.

        If the trust root is certificate-less and there are no certificates,
        the result will be ``None``.
        N)r,   r*   r$   r4   r5   r   r6   )r-   Úroot_authoritys     r    r&   zValidationPath.leafW   sJ   € ð Œ:Ð!Ø”:ÐØ”ð 	2Ø!Ô.Ô8ˆNÝ˜.Õ*;Ñ<Ô<ð 2Ø%Ô1Ð1àˆtr   c                 ó˜   — | j         }t          |t          j        ¦  «        r|j        j        S t          |t          j        ¦  «        rdS d S )Nz<Attribute certificate>)r&   r5   r
   r7   ÚsubjectÚhuman_friendlyr	   ÚAttributeCertificateV2©r-   r&   s     r    Údescribe_leafzValidationPath.describe_leafj   sI   € ØŒyˆÝ�d�DÔ,Ñ-Ô-ð 	Ø”<Ô.Ð.Ý˜�cÔ8Ñ9Ô9ð 	Ø,Ð,à�4r   c                 óL   — | j         }t          |t          j        ¦  «        r|S dS )z‘
        Returns the current leaf certificate if it is an X.509 public-key
        certificate, and ``None`` otherwise.
        :return:
        N)r&   r5   r
   r7   r@   s     r    Úget_ee_cert_safezValidationPath.get_ee_cert_safes   s*   € ð ŒyˆÝ�d�DÔ,Ñ-Ô-ð 	ØˆKà�4r   c                 ó@   — |                       ¦   «         }|r|S t          ‚)zá
        Returns the last certificate in the path if it is an X.509 public-key
        certificate, and throws an error otherwise.

        :return:
            The last asn1crypto.x509.Certificate object in the path
        )rC   ÚLookupError©r-   Úcerts     r    ÚlastzValidationPath.last€   s(   € ð ×$Ò$Ñ&Ô&ˆØð 	ØˆKåÐr   c              #   ó\   K  — | j         j        V — | j        D ]}t          |¦  «        V — ŒdS )zU
        Iterate over all authorities in the path, including the trust root.
        N)r+   r4   r*   r   rF   s     r    Úiter_authoritieszValidationPath.iter_authorities�   sK   è è € ð ŒjÔ"Ð"Ð"Ð"Ø”Lð 	*ð 	*ˆDÝ# DÑ)Ô)Ð)Ð)Ð)Ð)ð	*ð 	*r   rG   c                 ó4  — t          |¦  «        }t          |t          j        ¦  «        r|j        }n!t          |d¦  «        }|r|d         j        nd}|                      ¦   «         D ]#}|j        |k    r|j	        }|r	|r||k    rŒ|c S Œ$t          d¦  «        ‚)aK  
        Return the issuer of the cert specified, as defined by this path

        :param cert:
            A certificate to get the issuer of

        :raises:
            LookupError - when the issuer of the certificate could not be found

        :return:
            An asn1crypto.x509.Certificate object of the issuer
        Úauthority_key_identifierÚkey_identifierNú6Unable to find the issuer of the certificate specified)r   r5   r
   r7   rL   r   ÚnativerJ   ÚnameÚkey_idrE   )r-   rG   Úissuer_nameÚakiÚaki_extr4   Úkeyids          r    Úfind_issuing_authorityz%ValidationPath.find_issuing_authority—   sË   € õ $ DÑ)Ô)ˆÝ�d�DÔ,Ñ-Ô-ð 	HØÔ/ˆCˆCå,¨TÐ3MÑNÔNˆGØ6=ÐG�'Ð*Ô+Ô2Ð2À4ˆCà×.Ò.Ñ0Ô0ð 	!ð 	!ˆIØŒ~ Ò,Ð,Ø!Ô(�Øð ˜Sð  U¨c¢\ \ØØ Ð Ð Ð ð	 -õ ØDñ
ô 
ð 	
r   Únew_leafc                 ó€  — | j         j        }t          |t          ¦  «        r,|j        j        |j        k    rt          | j         g |¬¦  «        S | j        }d}t          |¦  «        D ]\  }}|j        |j        k    r|} nŒ|€t          d|j
        j        › �¦  «        ‚t          | j         |d|dz   …         |¬¦  «        S )aÆ  
        Remove all certificates in the path after the cert specified and return
        them in a new path.

        Internal API.

        :param cert:
            An asn1crypto.x509.Certificate object to find

        :param new_leaf:
            A new leaf certificate to append.

        :raises:
            LookupError - when the certificate could not be found

        :return:
            The current ValidationPath object, for chaining
        ©r%   r&   Nz6Unable to find the specified certificate in the path: r   )r+   r4   r5   r   r6   Úissuer_serialr"   r*   Ú	enumeraterE   r=   r>   )r-   rG   rW   r;   ÚcertsÚ
cert_indexÚindexÚentrys           r    Útruncate_to_and_appendz%ValidationPath.truncate_to_and_append·   sï   € ð( œÔ-ˆÝ�nÕ&7Ñ8Ô8ð 	LØÔ)Ô7¸4Ô;MÒMÐMÝ% d¤j¸À(ÐKÑKÔKÐKà”ˆØˆ
Ý% eÑ,Ô,ð 	ð 	‰LˆE�5ØÔ" dÔ&8Ò8Ð8Ø"�
Ø�ð 9ð ÐÝØfÈÌÔIdÐfÐfñô ð õ ØŒJ˜uÐ%5 z°A¡~Ð%5Ô6¸Xð
ñ 
ô 
ð 	
r   c                 óÂ  — d}| j         j                             |¦  «        r9|j        dk    rt	          | j        g d¬¦  «        S t	          | j        g |¬¦  «        S | j        }t          |¦  «        D ]<\  }}|j        |j	        k    r'|j
        r|j        r|j
        |j        k    r|} nŒ8|} nŒ=|€t          d¦  «        ‚t	          | j        |d|dz   …         |¬¦  «        S )aŸ  
        Remove all certificates in the path after the issuer of the cert
        specified, as defined by this path, and append a new one.

        Internal API.

        :param cert:
            A new leaf certificate to append.

        :raises:
            LookupError - when the issuer of the certificate could not be found

        :return:
            The current ValidationPath object, for chaining
        NÚmayberY   rN   r   )r&   )r$   r4   Úis_potential_issuer_ofÚself_signedr"   r+   r*   r[   r=   ÚissuerrM   rL   rE   )r-   rG   Úissuer_indexr\   r^   r_   s         r    Útruncate_to_issuer_and_appendz,ValidationPath.truncate_to_issuer_and_appendà   s&  € ð" ˆð ÔÔ&×=Ò=¸dÑCÔCð 	HàÔ 7Ò*Ð*õ & d¤j¸À$ÐGÑGÔGÐGå% d¤j¸À$ÐGÑGÔGÐGð ”ˆÝ% eÑ,Ô,ð 	ð 	‰LˆE�5ØŒ} ¤Ò+Ð+ØÔ'ð ¨DÔ,Ið ØÔ+¨tÔ/LÒLÐLØ',˜Ø˜ð Mð $)�LØ�Eð ,ð ÐÝØHñô ð õ ˜dœj¨%Ð0B°,ÀÑ2BÐ0BÔ*CÈ$ÐOÑOÔOÐOr   c                 ó�   — | j         d d …         }| j        r|                     | j        ¦  «         t          | j        ||¬¦  «        S )N©r$   r%   r&   )r*   r,   Úappendr"   r+   )r-   rG   Ú	new_certss      r    Úcopy_and_appendzValidationPath.copy_and_append  sQ   € Ø”L   ”Oˆ	ØŒ:ð 	)Ø×Ò˜TœZÑ(Ô(Ð(ÝØœ¨I¸Dð
ñ 
ô 
ð 	
r   c                 ó¦   — t          | j        ¦  «        dk    rt          ‚| j        dd…         | j        d         }}t          | j        ||¬¦  «        S )z‰
        Drop the leaf cert from this path and return a new path with the
        last intermediate certificate set as the leaf.
        r   Néÿÿÿÿri   )Úlenr*   Ú
IndexErrorr"   r+   )r-   Ú
new_intermrW   s      r    Úcopy_and_drop_leafz!ValidationPath.copy_and_drop_leaf  sZ   € õ ˆtŒ|ÑÔ Ò!Ð!ÝÐØ#œ|¨C¨R¨CÔ0°$´,¸rÔ2B�Hˆ
ÝØœ¨J¸Xð
ñ 
ô 
ð 	
r   c                 ó   — || _         d S r1   ©r#   )r-   Úpoliciess     r    Ú_set_qualified_policiesz&ValidationPath._set_qualified_policies%  s   € Ø#+ˆÔ Ð Ð r   c                 ó   — | j         S r1   rt   r2   s    r    Úqualified_policiesz!ValidationPath.qualified_policies(  s   € ØÔ'Ð'r   Úattr_idc                 óŒ   ‡— d„ | D ¦   «         }t          d„ |D ¦   «         ¦  «        }|sdS t          ˆfd„|D ¦   «         ¦  «        S )Nc                 ó6   — g | ]}t          j        |¦  «        ‘ŒS r   )r   Úread_extension_value)Ú.0rG   s     r    ú
<listcomp>z3ValidationPath.aa_attr_in_scope.<locals>.<listcomp>,  s0   € ð "
ð "
ð "
Ø6:�JÔ+¨DÑ1Ô1ð"
ð "
ð "
r   c              3   ó   K  — | ]}|d uV — Œ	d S r1   r   )r}   Úxs     r    ú	<genexpr>z2ValidationPath.aa_attr_in_scope.<locals>.<genexpr>/  s&   è è € ÐMÐM°˜q¨˜}ÐMÐMÐMÐMÐMÐMr   Tc              3   óF   •K  — | ]}|®|                      ‰¦  «        V — Œd S r1   )Úaccept)r}   Úctrlry   s     €r    r�   z2ValidationPath.aa_attr_in_scope.<locals>.<genexpr>9  sE   øè è € ð ð àð Ð#ð	 —’˜GÑ$Ô$ð $Ð#Ð#Ð#ðð r   )ÚanyÚall)r-   ry   Úaa_controls_extensionsÚaa_controls_useds    `  r    Úaa_attr_in_scopezValidationPath.aa_attr_in_scope+  s‰   ø€ ð"
ð "
Ø>Bð"
ñ "
ô "
Ðõ ÐMÐMÐ6LÐMÑMÔMÑMÔMÐØð 	Ø�4õ ð ð ð ð à2ðñ ô ñ ô ð r   c                 óB   — t          | j        ¦  «        | j        rdndz   S )Nr   r   )ro   r*   r,   r2   s    r    Úpkix_lenzValidationPath.pkix_lenA  s"   € å�4”<Ñ Ô ¨¬Ð$: A A¸Ñ;Ð;r   c                 ó   — d| j         z   S )Nr   )r‹   r2   s    r    Ú__len__zValidationPath.__len__E  s   € à�4”=Ñ Ð r   c                 óò   — | j         j        }|dk    r;t          | j        ¦  «        dz   }||k    r| j        �| j        S | j        |dz
           S t          |t          ¦  «        r|j        S t          d¦  «        ‚)Nr   r   zRoot has no certificate)	r+   r4   ro   r*   r,   r5   r   r6   rE   )r-   Úkeyr4   Úleaf_ixs       r    Ú__getitem__zValidationPath.__getitem__I  s   € à”JÔ(ˆ	Ø�Š7ˆ7Ý˜$œ,Ñ'Ô'¨!Ñ+ˆGØ�gŠ~ˆ~ $¤*Ð"8Ø”zÐ!Ø”<  a¡Ô(Ð(Ý˜	Õ#4Ñ5Ô5ð 	9àÔ(Ð(õ Ð7Ñ8Ô8Ð8r   Úinclude_rootc                 óÞ   — | j         j        }|rt          |t          ¦  «        r|j        fnd}| j        }t          |t          j        ¦  «        r|fnd}t          j	        || j
        |¦  «        S )zÆ
        Iterate over the certificates in the path.

        :param include_root:
            Include the root (if it is supplied as a certificate)
        :return:
            An iterator.
        r   )r+   r4   r5   r   r6   r,   r
   r7   Ú	itertoolsÚchainr*   )r-   r’   r8   Ú	from_rootr&   Ú	from_leafs         r    Ú
iter_certszValidationPath.iter_certsY  sz   € ð ŒzÔ#ˆð ðÝ *¨4Õ1BÑ CÔ CðˆTÔÐÐàð 	ð
 ŒzˆÝ)¨$µÔ0@ÑAÔAÐI�T�G�GÀrˆ	ÝŒ˜y¨$¬,¸	ÑBÔBÐBr   c                 ó.   — |                       d¬¦  «        S )NT)r’   )r˜   r2   s    r    Ú__iter__zValidationPath.__iter__l  s   € ð �Š¨DˆÑ1Ô1Ð1r   c                 ó�   — t          |t          ¦  «        sdS | j        |j        k    o| j        |j        k    o| j        |j        k    S )NF)r5   r"   r$   r*   r,   )r-   Úothers     r    Ú__eq__zValidationPath.__eq__q  sN   € Ý˜%¥Ñ0Ô0ð 	Ø�5àÔ Ô!3Ò3ð *Ø” ¤Ò-ð*à”
˜eœkÒ)ð	
r   )r/   r"   ),r   r   r   Ú__doc__r#   r   r   r   r   Ú_path_aa_controlsr   r   r
   r7   ÚLeafr.   Úpropertyr$   r9   r&   r   rA   rC   rH   r   rJ   rV   r`   rg   rl   rr   rv   rx   r	   ÚAttCertAttributeTypeÚboolr‰   r‹   r�   r‘   r   r˜   rš   r�   r   r   r    r"   r"   &   sï  € € € € € € ðð ð
 AEÐ˜ )¨OÔ"<Ô=ÐDÐDÑDàÐð
à!ð
ð ˜Ô)Ô*ð
ð �tŒnð	
ð 
ð 
ð 
ð ð˜kð ð ð ñ „Xðð ðð ñ „Xðð, ð�h˜t”nð ð ð ñ „Xðð$˜x¨œ}ð ð ð ð ð (¨4Ô+;Ô"<ð ð ð ð ð ð�dÔ&ð ð ð ñ „Xðð* (¨9Ô"5ð *ð *ð *ð *ð
¨4ð 
ð 
ð 
ð 
ð@&
¨4Ô+;ð &
Àtð &
ð &
ð &
ð &
ðR.P°$Ô2Bð .Pð .Pð .Pð .Pð`
 Dð 
ð 
ð 
ð 
ð
ð 
ð 
ð 
ð,ð ,ð ,ð( H¨Y°Ô-GÔ$Hð (ð (ð (ð (ð¨Ô(@ð ÀTð ð ð ð ð, ð<ð <ñ „Xð<ð!ð !ð !ð9ð 9ð 9ð C tð C°¸Ô9IÔ0Jð Cð Cð Cð Cð&2ð 2ð 2ð

ð 
ð 
ð 
ð 
r   r"   )r”   Údataclassesr   Útypingr   r   r   r   r   Ú
asn1cryptor	   r
   Ú
asn1_typesr   r4   r   r   r   Úutilr   r   r   r7   r?   r    r"   r   r   r    ú<module>r©      sX  ðà Ð Ð Ð Ø !Ð !Ð !Ð !Ð !Ð !Ø AÐ AÐ AÐ AÐ AÐ AÐ AÐ AÐ AÐ AÐ AÐ AÐ AÐ Aà  Ð  Ð  Ð  Ð  Ð  Ð  Ð  à "Ð "Ð "Ð "Ð "Ð "ðð ð ð ð ð ð ð ð ð ð
 8Ð 7Ð 7Ð 7Ð 7Ð 7Ð 7Ð 7ð €�$ÐÑÔðð ð ð ð ñ ô ñ Ôðð" ˆTÔ˜sÔ9Ð9Ô:€ðR
ð R
ð R
ð R
ð R
ñ R
ô R
ð R
ð R
ð R
r   