Ë
    R>{i´  ã                  ó¶   — d Z ddlmZ ddlZddlZddlZddlmZmZ ej                  rddl	m
Z
 dZ G d„ d	e«      Z	 d	 	 	 	 	 	 	 dd
„Zdd„Z	 d	 	 	 	 	 	 	 dd„Zy)zHThe match_hostname() function from Python 3.5, essential when using SSL.é    )ÚannotationsN)ÚIPv4AddressÚIPv6Addressé   )Ú_TYPE_PEER_CERT_RET_DICTz3.5.0.1c                  ó   — e Zd Zy)ÚCertificateErrorN)Ú__name__Ú
__module__Ú__qualname__© ó    ú]/var/www/skyplay_api_hub/venv/lib/python3.12/site-packages/urllib3/util/ssl_match_hostname.pyr	   r	      s   „ Ør   r	   c                ó  — g }| sy| j                  d«      }|d   }|dd }|j                  d«      }||kD  rt        dt        | «      z   «      ‚|s*t	        | j                  «       |j                  «       k(  «      S |dk(  r|j                  d«       n{|j                  d	«      s|j                  d	«      r%|j                  t        j                  |«      «       n4|j                  t        j                  |«      j                  d
d«      «       |D ]&  }|j                  t        j                  |«      «       Œ( t        j                  ddj                  |«      z   dz   t        j                  «      }	|	j                  |«      S )zhMatching according to RFC 6125, section 6.4.3

    http://tools.ietf.org/html/rfc6125#section-6.4.3
    Fú.r   r   NÚ*z,too many wildcards in certificate DNS name: z[^.]+zxn--z\*z[^.]*z\Az\.z\Z)ÚsplitÚcountr	   ÚreprÚboolÚlowerÚappendÚ
startswithÚreÚescapeÚreplaceÚcompileÚjoinÚ
IGNORECASEÚmatch)
ÚdnÚhostnameÚmax_wildcardsÚpatsÚpartsÚleftmostÚ	remainderÚ	wildcardsÚfragÚpats
             r   Ú_dnsname_matchr+      sO  € ð €DÙØð �H‰H�T‹N€EØ�Q‰x€HØ�a�b�	€Ià—‘˜sÓ#€IØ�=Ò ô
 Ø:¼TÀ"»XÑEó
ð 	
ñ
 Ü�B—H‘H“J (§.¡.Ó"2Ñ2Ó3Ð3ð
 �3‚ð 	�‰�GÕØ	×	Ñ	˜VÔ	$¨×(;Ñ(;¸FÔ(Cð
 	�‰”B—I‘I˜hÓ'Õ(ð 	�‰”B—I‘I˜hÓ'×/Ñ/°°wÓ?Ô@ð ò %ˆØ�‰”B—I‘I˜d“OÕ$ð%ô �*‰*�U˜UŸZ™Z¨Ó-Ñ-°Ñ5´r·}±}Ó
E€CØ�9‰9�XÓÐr   c                óŒ   — t        j                  | j                  «       «      }t        |j                  |j                  k(  «      S )a…  Exact matching of IP addresses.

    RFC 9110 section 4.3.5: "A reference identity of IP-ID contains the decoded
    bytes of the IP address. An IP version 4 address is 4 octets, and an IP
    version 6 address is 16 octets. [...] A reference identity of type IP-ID
    matches if the address is identical to an iPAddress value of the
    subjectAltName extension of the certificate."
    )Ú	ipaddressÚ
ip_addressÚrstripr   Úpacked)ÚipnameÚhost_ipÚips      r   Ú_ipaddress_matchr4   P   s2   € ô 
×	Ñ	˜fŸm™m›oÓ	.€BÜ�—	‘	˜WŸ^™^Ñ+Ó,Ð,r   c                ó  — | st        d«      ‚	 d|v r(t        j                  |d|j                  d«       «      }nt        j                  |«      }g }| j	                  dd«      }|D ]S  \  }}|dk(  r"|€t        ||«      r y|j                  |«       Œ-|dk(  sŒ3|�t        ||«      r y|j                  |«       ŒU |rK|€I|sG| j	                  dd«      D ]2  }|D ]+  \  }}|d	k(  sŒt        ||«      r  y|j                  |«       Œ- Œ4 t        |«      d
kD  r.t        d|›ddj                  t        t        |«      «      ›�«      ‚t        |«      d
k(  rt        d|›d|d   ›�«      ‚t        d«      ‚# t         $ r d}Y �Œ0w xY w)a)  Verify that *cert* (in decoded format as returned by
    SSLSocket.getpeercert()) matches the *hostname*.  RFC 2818 and RFC 6125
    rules are followed, but IP addresses are not accepted for *hostname*.

    CertificateError is raised on failure. On success, the function
    returns nothing.
    ztempty or no certificate, match_hostname needs a SSL socket or SSL context with either CERT_OPTIONAL or CERT_REQUIREDú%NÚsubjectAltNamer   ÚDNSz
IP AddressÚsubjectÚ
commonNamer   z	hostname z doesn't match either of z, z doesn't match r   z/no appropriate subjectAltName fields were found)Ú
ValueErrorr-   r.   ÚrfindÚgetr+   r   r4   Úlenr	   r   Úmapr   )	Úcertr"   Úhostname_checks_common_namer2   ÚdnsnamesÚsanÚkeyÚvalueÚsubs	            r   Úmatch_hostnamerG   _   s¬  € ñ Üð-ó
ð 	
ð
ð �(‰?Ü×*Ñ*¨8Ð4I°h·n±nÀSÓ6IÐ+JÓK‰Gä×*Ñ*¨8Ó4ˆGð
 €HØ'+§x¡xÐ0@À"Ó'E€Cð ò #‰
ˆˆUØ�%Š<Øˆ¤>°%¸Ô#BÙØ�O‰O˜EÕ"Ø�LÓ ØÐ"Ô'7¸¸wÔ'GÙØ�O‰O˜EÕ"ð#ñ # w ¹xØ—8‘8˜I rÓ*ò 	+ˆCØ!ò +‘
��UØ˜,Ó&Ü% e¨XÔ6ÚØ—O‘O EÕ*ñ	+ð	+ô ˆ8ƒ}�qÒÝâ,4°d·i±iÄÄDÈ(Ó@SÔ6TðVó
ð 	
ô 
ˆX‹˜!Ò	Ü ¨8¨,°oÀhÈqÁkÀ_ÐUÓVÐVäÐPÓQÐQøôG ò à‹ðús   �AE2 Å2FÆ F)r   )r!   z
typing.Anyr"   Ústrr#   ÚintÚreturnztyping.Match[str] | None | bool)r1   rH   r2   zIPv4Address | IPv6AddressrJ   r   )F)r@   z_TYPE_PEER_CERT_RET_DICT | Noner"   rH   rA   r   rJ   ÚNone)Ú__doc__Ú
__future__r   r-   r   Útypingr   r   ÚTYPE_CHECKINGÚssl_r   Ú__version__r;   r	   r+   r4   rG   r   r   r   ú<module>rR      sž   ðÙ Nõ #ã Û 	Û ß .à	×ÒÝ.à€ô	�zô 	ð
 9:ð5Øð5Ø!ð5Ø25ð5à$ó5óp-ð$ ).ð@RØ
)ð@Ràð@Rð "&ð@Rð 
ô	@Rr   