ó
    Ð]jg  ã                  óÊ   • S r SSKJr  SSKrSSKrSSKrSSKJrJr  \R                  (       a  SSK	J
r
  Sr " S S	\5      r S       SS
 jjrSS jr S       SS jjrg)zHThe match_hostname() function from Python 3.5, essential when using SSL.é    )ÚannotationsN)ÚIPv4AddressÚIPv6Addressé   )Ú_TYPE_PEER_CERT_RET_DICTz3.5.0.1c                  ó   • \ rS rSrSrg)ÚCertificateErroré   © N)Ú__name__Ú
__module__Ú__qualname__Ú__firstlineno__Ú__static_attributes__r   ó    Ú\/home/mande/repo/quber/.venv/lib/python3.13/site-packages/urllib3/util/ssl_match_hostname.pyr	   r	      s   † Úr   r	   c                ó8  • / nU (       d  gU R                  S5      nUS   nUSS nUR                  S5      nXr:”  a  [        S[        U 5      -   5      eU(       d*  [	        U R                  5       UR                  5       :H  5      $ US:X  a  UR                  S5        O‡UR                  S	5      (       d  UR                  S	5      (       a&  UR                  [        R                  " U5      5        O5UR                  [        R                  " U5      R                  S
S5      5        U H(  nUR                  [        R                  " U5      5        M*     [        R                  " SSR                  U5      -   S-   [        R                  5      n	U	R                  U5      $ )z`Matching according to RFC 6125, section 6.4.3

http://tools.ietf.org/html/rfc6125#section-6.4.3
FÚ.r   r   NÚ*z,too many wildcards in certificate DNS name: z[^.]+zxn--z\*z[^.]*z\Az\.z\Z)ÚsplitÚcountr	   ÚreprÚboolÚlowerÚappendÚ
startswithÚreÚescapeÚreplaceÚcompileÚjoinÚ
IGNORECASEÚmatch)
ÚdnÚhostnameÚmax_wildcardsÚpatsÚpartsÚleftmostÚ	remainderÚ	wildcardsÚfragÚpats
             r   Ú_dnsname_matchr.      sN  € ð €DÞØð �H‰H�T‹N€EØ�Q‰x€HØ�a�b�	€Ià—‘˜sÓ#€IØÓ ô
 Ø:¼TÀ"»XÑEó
ð 	
ö
 Ü�B—H‘H“J (§.¡.Ó"2Ñ2Ó3Ð3ð
 �3ƒð 	�‰�GÕØ	×	Ñ	˜V×	$Ñ	$¨×(;Ñ(;¸F×(CÑ(Cð
 	�‰”B—I’I˜hÓ'Õ(ð 	�‰”B—I’I˜hÓ'×/Ñ/°°wÓ?Ô@ó ˆØ�‰”B—I’I˜d“OÖ$ñ ô �*Š*�U˜UŸZ™Z¨Ó-Ñ-°Ñ5´r·}±}Ó
E€CØ�9‰9�XÓÐr   c                óŽ   • [         R                  " U R                  5       5      n[        UR                  UR                  :H  5      $ )am  Exact matching of IP addresses.

RFC 9110 section 4.3.5: "A reference identity of IP-ID contains the decoded
bytes of the IP address. An IP version 4 address is 4 octets, and an IP
version 6 address is 16 octets. [...] A reference identity of type IP-ID
matches if the address is identical to an iPAddress value of the
subjectAltName extension of the certificate."
)Ú	ipaddressÚ
ip_addressÚrstripr   Úpacked)ÚipnameÚhost_ipÚips      r   Ú_ipaddress_matchr7   P   s2   € ô 
×	Ò	˜fŸm™m›oÓ	.€BÜ�—	‘	˜WŸ^™^Ñ+Ó,Ð,r   c                ó  • U (       d  [        S5      e [        R                  " U5      n/ nU R                  SS5      nU Ha  u  pgUS:X  a(  Uc  [	        Xq5      (       a    gUR                  U5        M3  US:X  d  M;  Ub  [        Xs5      (       a    gUR                  U5        Mc     U(       aZ  UcW  U(       dP  U R                  SS5       H:  nU H1  u  pgUS:X  d  M  [	        Xq5      (       a      gUR                  U5        M3     M<     [        U5      S	:”  a0  [        S
U< SSR                  [        [        U5      5      < 35      e[        U5      S	:X  a  [        S
U< SUS   < 35      e[        S5      e! [          a    Sn GNZf = f)a  Verify that *cert* (in decoded format as returned by
SSLSocket.getpeercert()) matches the *hostname*.  RFC 2818 and RFC 6125
rules are followed, but IP addresses are not accepted for *hostname*.

CertificateError is raised on failure. On success, the function
returns nothing.
ztempty or no certificate, match_hostname needs a SSL socket or SSL context with either CERT_OPTIONAL or CERT_REQUIREDNÚsubjectAltNamer   ÚDNSz
IP AddressÚsubjectÚ
commonNamer   z	hostname z doesn't match either of z, z doesn't match r   z/no appropriate subjectAltName fields were found)Ú
ValueErrorr0   r1   Úgetr.   r   r7   Úlenr	   r!   Úmapr   )	Úcertr%   Úhostname_checks_common_namer5   ÚdnsnamesÚsanÚkeyÚvalueÚsubs	            r   Úmatch_hostnamerH   _   su  € ö Üð-ó
ð 	
ðÜ×&Ò& xÓ0ˆð €HØ'+§x¡xÐ0@À"Ó'E€Có ‰
ˆØ�%‹<Ø‰¤>°%×#BÑ#BÙØ�O‰O˜EÖ"Ø�LÕ ØÑ"Ô'7¸×'GÑ'GÙØ�O‰O˜EÖ"ñ ö # w¡¾xØ—8‘8˜I rÖ*ˆCÛ!‘
�Ø˜,Õ&Ü% e×6Ñ6ÚØ—O‘OØöó	 "ñ +ô ˆ8ƒ}�qÓÝã,4°d·i±iÄÄDÈ(Ó@SÕ6TðVó
ð 	
ô 
ˆX‹˜!Ó	Ü ¨8©,°oÀhÈqÁkÁ_ÐUÓVÐVäÐPÓQÐQøôK ó à‹ðús   ”E5 Å5FÆF)r   )r$   z
typing.Anyr%   Ústrr&   ÚintÚreturnztyping.Match[str] | None | bool)r4   rI   r5   zIPv4Address | IPv6AddressrK   r   )F)rA   z_TYPE_PEER_CERT_RET_DICT | Noner%   rI   rB   r   rK   ÚNone)Ú__doc__Ú
__future__r   r0   r   Útypingr   r   ÚTYPE_CHECKINGÚssl_r   Ú__version__r=   r	   r.   r7   rH   r   r   r   Ú<module>rS      s™   ðÙ Nõ #ã Û 	Û ß .à	××Ý.à€ô	�zô 	ð
 9:ð5Øð5Ø!ð5Ø25ð5à$õ5ôp-ð$ ).ð:RØ
)ð:Ràð:Rð "&ð:Rð 
ö	:Rr   