Ë
    üûàg¨  ã                   ód   — d dl mZ d dlmZ d dlmZ ddlmZ  G d„ d«      Zd„ Z	 G d	„ d
e«      Z
y)é    )Úurlparse)Úsettings)Úis_same_domainé   )ÚAsyncWebsocketConsumerc                   ó4   — e Zd ZdZd„ Zd„ Zd„ Zd„ Zd„ Zd„ Z	y)	ÚOriginValidatorze
    Validates that the incoming connection has an Origin header that
    is in an allowed list.
    c                 ó    — || _         || _        y ©N)ÚapplicationÚallowed_origins)Úselfr   r   s      úY/var/www/skyplay_api_hub/venv/lib/python3.12/site-packages/channels/security/websocket.pyÚ__init__zOriginValidator.__init__   s   € Ø&ˆÔØ.ˆÕó    c              ƒ   ó`  K  — |d   dk7  rt        d«      ‚d }|j                  dg «      D ]&  \  }}|dk(  sŒ	 t        |j                  d«      «      }Œ( | j                  |«      r| j                  |||«      ƒ d {  –—† S t        «       } ||||«      ƒ d {  –—† S # t        $ r Y Œ|w xY w7 Œ/7 Œ­w)NÚtypeÚ	websocketz<You cannot use OriginValidator on a non-WebSocket connectionÚheaderss   originÚlatin1)Ú
ValueErrorÚgetr   ÚdecodeÚUnicodeDecodeErrorÚvalid_originr   ÚWebsocketDenier)r   ÚscopeÚreceiveÚsendÚparsed_originÚheader_nameÚheader_valueÚdeniers           r   Ú__call__zOriginValidator.__call__   sÎ   è ø€ à�‰=˜KÒ'ÜØNóð ð ˆØ).¯©°9¸bÓ)Aò 	Ñ%ˆK˜Ø˜iÓ'ðä$,¨\×-@Ñ-@ÀÓ-JÓ$K‘Mð		ð ×Ñ˜]Ô+à×)Ñ)¨%°¸$Ó?×?Ð?ô %Ó&ˆFÙ  w°Ó5×5Ð5øô *ò Ùðúð
 @øð 6úsF   ‚3B.·BÁ)B.Á:B*Á;B.ÂB,ÂB.Â	B'Â$B.Â&B'Â'B.Â,B.c                 óF   — |€d| j                   vry| j                  |«      S )z¼
        Checks parsed origin is None.

        Pass control to the validate_origin function.

        Returns ``True`` if validation function was successful, ``False`` otherwise.
        Ú*F)r   Úvalidate_origin©r   r    s     r   r   zOriginValidator.valid_origin+   s+   € ð Ð  S°×0DÑ0DÑ%DØØ×#Ñ# MÓ2Ð2r   c                 óD   ‡ ‡— t        ˆˆ fd„‰ j                  D «       «      S )aÖ  
        Validate the given origin for this site.

        Check than the origin looks valid and matches the origin pattern in
        specified list ``allowed_origins``. Any pattern begins with a scheme.
        After the scheme there must be a domain. Any domain beginning with a
        period corresponds to the domain and all its subdomains (for example,
        ``http://.example.com``). After the domain there must be a port,
        but it can be omitted. ``*`` matches anything and anything
        else must match exactly.

        Note. This function assumes that the given origin has a schema, domain
        and port, but port is optional.

        Returns ``True`` for a valid host, ``False`` otherwise.
        c              3   óP   •K  — | ]  }|d k(  xs ‰j                  ‰|«      –— Œ y­w)r&   N)Úmatch_allowed_origin)Ú.0Úpatternr    r   s     €€r   ú	<genexpr>z2OriginValidator.validate_origin.<locals>.<genexpr>I   s2   øè ø€ ò 
àð �s‰NÒO˜d×7Ñ7¸ÀwÓOÓOñ
ùs   ƒ#&)Úanyr   r(   s   ``r   r'   zOriginValidator.validate_origin8   s%   ù€ ô" ô 
à×/Ñ/ô
ó 
ð 	
r   c                 ó”  — |€yt        |j                  «       «      }|j                  €y|j                  s2t        d|z   «      j                  xs |}t	        |j                  |«      S | j                  |«      }| j                  |«      }|j                  |j                  k(  r&||k(  r!t	        |j                  |j                  «      ryy)aü  
        Returns ``True`` if the origin is either an exact match or a match
        to the wildcard pattern. Compares scheme, domain, port of origin and pattern.

        Any pattern can be begins with a scheme. After the scheme must be a domain,
        or just domain without scheme.
        Any domain beginning with a period corresponds to the domain and all
        its subdomains (for example, ``.example.com`` ``example.com``
        and any subdomain). Also with scheme (for example, ``http://.example.com``
        ``http://exapmple.com``). After the domain there must be a port,
        but it can be omitted.

        Note. This function assumes that the given origin is either None, a
        schema-domain-port string, or just a domain string
        Fz//T)r   ÚlowerÚhostnameÚschemer   Úget_origin_port)r   r    r-   Úparsed_patternÚpattern_hostnameÚorigin_portÚpattern_ports          r   r+   z$OriginValidator.match_allowed_originN   s¿   € ð  Ð Øô " '§-¡-£/Ó2ˆØ×!Ñ!Ð)ØØ×$Ò$Ü'¨¨w©Ó7×@Ñ@ÒKÀGÐÜ! -×"8Ñ"8Ð:JÓKÐKà×*Ñ*¨=Ó9ˆà×+Ñ+¨NÓ;ˆð ×!Ñ! ]×%9Ñ%9Ò9Ø˜|Ò+Ü˜}×5Ñ5°~×7NÑ7NÔOàØr   c                 ó°   — |j                   �|j                   S |j                  dk(  s|j                  dk(  ry|j                  dk(  s|j                  dk(  ryy)zq
        Returns the origin.port or port for this schema by default.
        Otherwise, it returns None.
        NÚhttpÚwséP   ÚhttpsÚwssi»  )Úportr3   )r   Úorigins     r   r4   zOriginValidator.get_origin_portu   sO   € ð
 �;‰;Ð"à—;‘;Ðà�=‰=˜FÒ" f§m¡m°tÒ&;àØ�]‰]˜gÒ%¨¯©¸%Ò)?ààr   N)
Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r$   r   r'   r+   r4   © r   r   r	   r	   	   s&   „ ñò
/ò6ò03ò
ò,%óNr   r	   c                 óf   — t         j                  }t         j                  r|sg d¢}t        | |«      S )zi
    Factory function which returns an OriginValidator configured to use
    settings.ALLOWED_HOSTS.
    )Ú	localhostz	127.0.0.1z[::1])r   ÚALLOWED_HOSTSÚDEBUGr	   )r   Úallowed_hostss     r   ÚAllowedHostsOriginValidatorrK   ˆ   s*   € ô
 ×*Ñ*€MÜ‡~‚~™mÚ;ˆÜ˜;¨Ó6Ð6r   c                   ó   — e Zd ZdZd„ Zy)r   z=
    Simple application which denies all requests to it.
    c              ƒ   ó@   K  — | j                  «       ƒ d {  –—†  y 7 Œ­wr   )Úclose)r   s    r   ÚconnectzWebsocketDenier.connect˜   s   è ø€ Ø�j‰j‹l×Òús   ‚–—N)rA   rB   rC   rD   rO   rE   r   r   r   r   “   s   „ ñór   r   N)Úurllib.parser   Údjango.confr   Údjango.http.requestr   Úgeneric.websocketr   r	   rK   r   rE   r   r   ú<module>rT      s0   ðÝ !å  Ý .å 6÷|ñ |ò~7ôÐ,õ r   