Ë
    ¹ûàgè  ã                   ó^   — d dl m Z  d dlmZ d dlmZmZ d dlmZmZ  G d„ d«      Z	 e	«       Z
y)é    )Údatetime)Úsettings)Úconstant_time_compareÚsalted_hmac)Úbase36_to_intÚint_to_base36c                   ó†   — e Zd ZdZdZdZdZdZd„ Zd„ Z	d„ Z
 ee	e
«      Zd„ Zd„ Z eee«      Zd	„ Zd
„ Zd„ Zd„ Zd„ Zd„ Zy)ÚPasswordResetTokenGeneratorza
    Strategy object used to generate and check tokens for the password
    reset mechanism.
    z6django.contrib.auth.tokens.PasswordResetTokenGeneratorNc                 ó.   — | j                   xs d| _         y )NÚsha256)Ú	algorithm©Úselfs    úX/var/www/skyplay_api_hub/venv/lib/python3.12/site-packages/django/contrib/auth/tokens.pyÚ__init__z$PasswordResetTokenGenerator.__init__   s   € ØŸ™Ò3¨8ˆ�ó    c                 ó>   — | j                   xs t        j                  S ©N)Ú_secretr   Ú
SECRET_KEYr   s    r   Ú_get_secretz'PasswordResetTokenGenerator._get_secret   s   € Ø�|‰|Ò2œx×2Ñ2Ð2r   c                 ó   — || _         y r   )r   )r   Úsecrets     r   Ú_set_secretz'PasswordResetTokenGenerator._set_secret   s	   € Øˆ�r   c                 óR   — | j                   €t        j                  S | j                   S r   )Ú_secret_fallbacksr   ÚSECRET_KEY_FALLBACKSr   s    r   Ú_get_fallbacksz*PasswordResetTokenGenerator._get_fallbacks   s&   € Ø×!Ñ!Ð)Ü×0Ñ0Ð0Ø×%Ñ%Ð%r   c                 ó   — || _         y r   )r   )r   Ú	fallbackss     r   Ú_set_fallbacksz*PasswordResetTokenGenerator._set_fallbacks#   s
   € Ø!*ˆÕr   c                 óv   — | j                  || j                  | j                  «       «      | j                  «      S )zi
        Return a token that can be used once to do a password reset
        for the given user.
        )Ú_make_token_with_timestampÚ_num_secondsÚ_nowr   )r   Úusers     r   Ú
make_tokenz&PasswordResetTokenGenerator.make_token(   s5   € ð
 ×.Ñ.ØØ×Ñ˜dŸi™i›kÓ*Ø�K‰Kó
ð 	
r   c                 óp  — |r|sy	 |j                  d«      \  }}	 t        |«      }| j                  g| j                  ¢D ]!  }t        | j                  |||«      |«      sŒ! n y| j                  | j                  «       «      |z
  t        j                  kD  ryy# t        $ r Y yw xY w# t        $ r Y yw xY w)zP
        Check that a password reset token is correct for a given user.
        Fú-T)ÚsplitÚ
ValueErrorr   r   Úsecret_fallbacksr   r#   r$   r%   r   ÚPASSWORD_RESET_TIMEOUT)r   r&   ÚtokenÚts_b36Ú_Útsr   s          r   Úcheck_tokenz'PasswordResetTokenGenerator.check_token3   sÏ   € ñ ™Øð	ØŸ™ CÓ(‰IˆF�Að	Ü˜vÓ&ˆBð
 —{‘{Ð; T×%:Ñ%:Ð;ò 	ˆFÜ$Ø×/Ñ/°°b¸&ÓAØõñ ð	ð ð ×Ñ˜dŸi™i›kÓ*¨RÑ/´8×3RÑ3RÒRØàøô- ò 	Ùð	ûô
 ò 	Ùð	ús"   ‡B œB) Â	B&Â%B&Â)	B5Â4B5c                 ó´   — t        |«      }t        | j                  | j                  ||«      || j                  ¬«      j                  «       d d d…   }|›d|›�S )N)r   r   é   r)   )r   r   Úkey_saltÚ_make_hash_valuer   Ú	hexdigest)r   r&   Ú	timestampr   r/   Úhash_strings         r   r#   z6PasswordResetTokenGenerator._make_token_with_timestampT   s[   € ô ˜yÓ)ˆÜ!Ø�M‰MØ×!Ñ! $¨	Ó2ØØ—n‘nô	
÷
 ‰)‹+ÙˆaˆCñ
ˆò !¡+Ð.Ð.r   c                 óÚ   — |j                   €dn|j                   j                  dd¬«      }|j                  «       }t        ||d«      xs d}|j                  › |j
                  › |› |› |› �S )aÂ  
        Hash the user's primary key, email (if available), and some user state
        that's sure to change after a password reset to produce a token that is
        invalidated when it's used:
        1. The password field will change upon a password reset (even if the
           same password is chosen, due to password salting).
        2. The last_login field will usually be updated very shortly after
           a password reset.
        Failing those things, settings.PASSWORD_RESET_TIMEOUT eventually
        invalidates the token.

        Running this data through salted_hmac() prevents password cracking
        attempts using the reset token, provided the secret isn't compromised.
        NÚ r   )ÚmicrosecondÚtzinfo)Ú
last_loginÚreplaceÚget_email_field_nameÚgetattrÚpkÚpassword)r   r&   r8   Úlogin_timestampÚemail_fieldÚemails         r   r6   z,PasswordResetTokenGenerator._make_hash_valueb   sv   € ð& �‰Ð&ñ à—‘×(Ñ(°Q¸tÐ(ÓDð 	ð
 ×/Ñ/Ó1ˆÜ˜˜k¨2Ó.Ò4°"ˆØ—'‘'�˜4Ÿ=™=˜/¨/Ð):¸9¸+ÀeÀWÐMÐMr   c                 óP   — t        |t        ddd«      z
  j                  «       «      S )NiÑ  é   )Úintr   Útotal_seconds)r   Údts     r   r$   z(PasswordResetTokenGenerator._num_seconds|   s$   € Ü�Bœ $¨¨1Ó-Ñ-×<Ñ<Ó>Ó?Ð?r   c                 ó*   — t        j                  «       S r   )r   Únowr   s    r   r%   z PasswordResetTokenGenerator._now   s   € ä�|‰|‹~Ðr   )Ú__name__Ú
__module__Ú__qualname__Ú__doc__r5   r   r   r   r   r   r   Úpropertyr   r   r!   r,   r'   r2   r#   r6   r$   r%   © r   r   r
   r
      sv   „ ñð
 H€HØ€IØ€GØÐò4ò3òñ �k ;Ó/€Fò&ò
+ñ   °Ó?Ðò	
òòB/òNò4@ór   r
   N)r   Údjango.confr   Údjango.utils.cryptor   r   Údjango.utils.httpr   r   r
   Údefault_token_generatorrS   r   r   ú<module>rX      s)   ðÝ å  ß Bß :÷yñ yñx 6Ó7Ñ r   