U
f @ s d Z ddlmZ ddlZddlZddlZddlmZmZ ejrJddl m
Z
dZG dd d eZ
dd
ddd
dddZddddddZddddddddZdS )zHThe match_hostname() function from Python 3.5, essential when using SSL. )annotationsN)IPv4AddressIPv6Address )_TYPE_PEER_CERT_RET_DICTz3.5.0.1c @ s e Zd ZdS )CertificateErrorN)__name__
__module____qualname__ r r P/opt/alt/python38/lib/python3.8/site-packages/urllib3/util/ssl_match_hostname.pyr s r z
typing.Anystrintztyping.Match[str] | None | bool)dnhostname
max_wildcardsreturnc
C s g }| sdS | d}|d }|dd }|d}||krLtdt| |sdt| | kS |dkrx|d n>|d s|d r|t | n|t |
d
d |D ]}|t | qtdd
| d tj
} | |S )zhMatching according to RFC 6125, section 6.4.3
http://tools.ietf.org/html/rfc6125#section-6.4.3
F.r r N*z,too many wildcards in certificate DNS name: z[^.]+zxn--z\*z[^.]*z\Az\.z\Z)splitcountr reprboollowerappend
startswithreescapereplacecompilejoin
IGNORECASEmatch)
r r r patspartsleftmost remainder wildcardsfragpatr r r _dnsname_match s,
r* zIPv4Address | IPv6Addressr )ipnamehost_ipr c C s t | }t|j|jkS )a Exact matching of IP addresses.
RFC 9110 section 4.3.5: "A reference identity of IP-ID contains the decoded
bytes of the IP address. An IP version 4 address is 4 octets, and an IP
version 6 address is 16 octets. [...] A reference identity of type IP-ID
matches if the address is identical to an iPAddress value of the
subjectAltName extension of the certificate."
) ipaddress
ip_addressrstripr packed)r+ r, ipr r r _ipaddress_matchP s r2 Fz_TYPE_PEER_CERT_RET_DICT | NoneNone)certr hostname_checks_common_namer c C s | st dz0d|kr0t|d|d }n
t|}W n t k
rT d}Y nX g }| dd}|D ]^\}}|dkr|dkrt||r dS || qj|dkrj|dk rt||r dS || qj|r&|dkr&|s&| ddD ]8}|D ].\}}|d krt||r dS || qqt|d
krRt d|d
tt|f n0t|d
krzt d
|d|d nt ddS )a) Verify that *cert* (in decoded format as returned by
SSLSocket.getpeercert()) matches the *hostname*. RFC 2818 and RFC 6125
rules are followed, but IP addresses are not accepted for *hostname*.
CertificateError is raised on failure. On success, the function
returns nothing.
ztempty or no certificate, match_hostname needs a SSL socket or SSL context with either CERT_OPTIONAL or CERT_REQUIRED%NsubjectAltNamer DNSz
IP Addresssubject
commonNamer z&hostname %r doesn't match either of %sz, z hostname z doesn't match r z/no appropriate subjectAltName fields were found)
ValueErrorr- r. rfindgetr* r r2 lenr r mapr ) r4 r r5 r, dnsnamessankeyvaluesubr r r match_hostname_ sJ
rE )r )F)__doc__
__future__r r- r typingr r
TYPE_CHECKINGssl_r __version__r; r r* r2 rE r r r r