+
    šh©j­,  ã                   ó  € R t ^ RIHt ^RIHt ^RIHt ^RIHt  ! R R4      t	 ! R R]	4      t
 ! R	 R
]	4      t ! R R]	4      t ! R R]4      t ! R R]4      t]! RRR.4      t ! R R]4      t ! R R]4      t ! R R4      tR# )z¿
Modern, adaptable authentication machinery.

Replaces certain parts of `.SSHClient`. For a concrete implementation, see the
``OpenSSHAuthStrategy`` class in `Fabric <https://fabfile.org>`_.
)Ú
namedtuple)ÚAgentKey)Ú
get_logger)ÚAuthenticationExceptionc                   ó<   a € ] tR t^t o RtR tR tR tR tRt	V t
R# )Ú
AuthSourcezÓ
Some SSH authentication source, such as a password, private key, or agent.

See subclasses in this module for concrete implementations.

All implementations must accept at least a ``username`` (``str``) kwarg.
c                ó   € Wn         R # ©N©Úusername)Úselfr   s   &&ÚQ/var/www/html/bestweb/venv/lib/python3.14/site-packages/paramiko/auth_strategy.pyÚ__init__ÚAuthSource.__init__   s   € Ø Žó    c                óº   € VP                  4        UUu. uF  w  r#V R V: 2NK  	  pppRP                  V4      pV P                  P                   RV R2# u uppi )Ú=z, Ú(Ú))ÚitemsÚjoinÚ	__class__Ú__name__)r   ÚkwargsÚkÚvÚpairsÚjoineds   &,    r   Ú_reprÚAuthSource._repr   s[   € ð +1¯,©,¬.Ô9©.¡$ !�A�3�a˜‘u“©.ˆÑ9Ø—‘˜5Ó!ˆØ—.‘.×)Ñ)Ð*¨!¨F¨8°1Ð5Ð5ùó :s   ”Ac                ó"   € V P                  4       # r	   )r   ©r   s   &r   Ú__repr__ÚAuthSource.__repr__"   s   € Ø�z‰z‹|Ðr   c                ó   € \         h)z
Perform authentication.
©ÚNotImplementedError©r   Ú	transports   &&r   ÚauthenticateÚAuthSource.authenticate%   s
   € ô "Ð!r   r
   N)r   Ú
__module__Ú__qualname__Ú__firstlineno__Ú__doc__r   r   r"   r)   Ú__static_attributes__Ú__classdictcell__©Ú__classdict__s   @r   r   r      s#   ø‡ € ñò!ò6ò÷"ð "r   r   c                   ó*   a € ] tR t^,t o RtR tRtV tR# )ÚNoneAuthzK
Auth type "none", ie https://www.rfc-editor.org/rfc/rfc4252#section-5.2 .
c                ó8   € VP                  V P                  4      # r	   )Ú	auth_noner   r'   s   &&r   r)   ÚNoneAuth.authenticate1   s   € Ø×"Ñ" 4§=¡=Ó1Ð1r   © N©r   r+   r,   r-   r.   r)   r/   r0   r1   s   @r   r4   r4   ,   s   ø‡ € ñ÷2ð 2r   r4   c                   óH   a a€ ] tR t^5t oRtV 3R ltV 3R ltR tRtVt	V ;t
# )ÚPasswordaó  
Password authentication.

:param callable password_getter:
    A lazy callable that should return a `str` password value at
    authentication time, such as a `functools.partial` wrapping
    `getpass.getpass`, an API call to a secrets store, or similar.

    If you already know the password at instantiation time, you should
    simply use something like ``lambda: "my literal"`` (for a literal, but
    also, shame on you!) or ``lambda: variable_name`` (for something stored
    in a variable).
c                ó4   <€ \         SV `  VR 7       W n        R# ©r
   N)Úsuperr   Úpassword_getter)r   r   r?   r   s   &&&€r   r   ÚPassword.__init__D   s   ø€ Ü‰Ñ (ÐÔ+Ø.Ör   c                ó8   <€ \         SV `  V P                  R 7      # ))Úuser)r>   r   r   )r   r   s   &€r   r"   ÚPassword.__repr__H   s   ø€ ô ‰w‰} $§-¡-ˆ}Ó0Ð0r   c                óZ   € V P                  4       pVP                  V P                  V4      # r	   )r?   Úauth_passwordr   )r   r(   Úpasswords   && r   r)   ÚPassword.authenticateM   s)   € ð ×'Ñ'Ó)ˆØ×&Ñ& t§}¡}°hÓ?Ð?r   )r?   )r   r+   r,   r-   r.   r   r"   r)   r/   r0   Ú__classcell__©r   r2   s   @@r   r;   r;   5   s    ù‡ € ñõ/õ1÷
@ò @r   r;   c                   ó*   a € ] tR t^Xt o RtR tRtV tR# )Ú
PrivateKeyak  
Essentially a mixin for private keys.

Knows how to auth, but leaves key material discovery/loading/decryption to
subclasses.

Subclasses **must** ensure that they've set ``self.pkey`` to a decrypted
`.PKey` instance before calling ``super().authenticate``; typically
either in their ``__init__``, or in an overridden ``authenticate`` prior to
its `super` call.
c                óN   € VP                  V P                  V P                  4      # r	   )Úauth_publickeyr   Úpkeyr'   s   &&r   r)   ÚPrivateKey.authenticatee   s   € Ø×'Ñ'¨¯©°t·y±yÓAÐAr   r8   Nr9   r1   s   @r   rK   rK   X   s   ø‡ € ñ
÷Bð Br   rK   c                   óB   a a€ ] tR t^it oRtV 3R ltV 3R ltRtVtV ;t	# )ÚInMemoryPrivateKeyz)
An in-memory, decrypted `.PKey` object.
c                ó4   <€ \         SV `  VR 7       W n        R# r=   )r>   r   rN   )r   r   rN   r   s   &&&€r   r   ÚInMemoryPrivateKey.__init__n   s   ø€ Ü‰Ñ (ÐÔ+àŽ	r   c                óŽ   <€ \         SV `  V P                  R 7      p\        V P                  \        4      '       d
   VR,          pV# )©rN   z [agent])r>   r   rN   Ú
isinstancer   )r   Úrepr   s   & €r   r"   ÚInMemoryPrivateKey.__repr__s   s9   ø€ ô ‰g‰m §¡ˆmÓ+ˆÜ�d—i‘i¤×*Ò*Ø�:ÕˆCØˆ
r   rU   ©
r   r+   r,   r-   r.   r   r"   r/   r0   rH   rI   s   @@r   rQ   rQ   i   s   ù‡ € ñõ÷
õ r   rQ   c                   ó<   a a€ ] tR t^|t oRtV 3R ltR tRtVtV ;t	# )ÚOnDiskPrivateKeyau  
Some on-disk private key that needs opening and possibly decrypting.

:param str source:
    String tracking where this key's path was specified; should be one of
    ``"ssh-config"``, ``"python-config"``, or ``"implicit-home"``.
:param Path path:
    The filesystem path this key was loaded from.
:param PKey pkey:
    The `PKey` object this auth source uses/represents.
c                óz   <€ \         SV `  VR 7       W n        RpW%9  d   \        RV: 24      hW0n        W@n        R# )r
   z source argument must be one of: N)z
ssh-configzpython-configzimplicit-home)r>   r   ÚsourceÚ
ValueErrorÚpathrN   )r   r   r]   r_   rN   Úallowedr   s   &&&&& €r   r   ÚOnDiskPrivateKey.__init__‰   s@   ø€ Ü‰Ñ (ÐÔ+ØŒØBˆØÔ ÜÐ?À¹{ÐKÓLÐLØŒ	àŽ	r   c                óx   € V P                  V P                  V P                  \        V P                  4      R 7      # ))Úkeyr]   r_   )r   rN   r]   Ústrr_   r!   s   &r   r"   ÚOnDiskPrivateKey.__repr__“   s/   € Ø�z‰zØ—	‘	 $§+¡+´C¸¿	¹	³Nð ó 
ð 	
r   )r_   rN   r]   rY   rI   s   @@r   r[   r[   |   s   ù‡ € ñ
õ÷
ò 
r   r[   ÚSourceResultr]   Úresultc                   ó<   a a€ ] tR t^¨t oRtV 3R ltR tRtVtV ;t	# )Ú
AuthResulta†  
Represents a partial or complete SSH authentication attempt.

This class conceptually extends `AuthStrategy` by pairing the former's
authentication **sources** with the **results** of trying to authenticate
with them.

`AuthResult` is a (subclass of) `list` of `namedtuple`, which are of the
form ``namedtuple('SourceResult', 'source', 'result')`` (where the
``source`` member is an `AuthSource` and the ``result`` member is either a
return value from the relevant `.Transport` method, or an exception
object).

.. note::
    Transport auth method results are always themselves a ``list`` of "next
    allowable authentication methods".

    In the simple case of "you just authenticated successfully", it's an
    empty list; if your auth was rejected but you're allowed to try again,
    it will be a list of string method names like ``pubkey`` or
    ``password``.

    The ``__str__`` of this class represents the empty-list scenario as the
    word ``success``, which should make reading the result of an
    authentication session more obvious to humans.

Instances also have a `strategy` attribute referencing the `AuthStrategy`
which was attempted.
c                ó4   <€ Wn         \        SV `  ! V/ VB  R # r	   )Ústrategyr>   r   )r   rk   Úargsr   r   s   &&*,€r   r   ÚAuthResult.__init__Ç   s   ø€ Ø ŒÜ‰Ò˜$Ð) &Ô)r   c                ó2   € R P                  R V  4       4      # )Ú
c              3   ój   "  € T F)  qP                    R VP                  ;'       g    R 2x € K+  	  R# 5i)z -> ÚsuccessN)r]   rg   )Ú.0Úxs   & r   Ú	<genexpr>Ú%AuthResult.__str__.<locals>.<genexpr>Ð   s-   é € ð 
Ù>B¸�x‰xˆj˜˜QŸX™X×2Ð2¨Ð3Õ4»dùs   ‚#3¦3)r   r!   s   &r   Ú__str__ÚAuthResult.__str__Ë   s"   € ð
 �y‰yñ 
Ù>Bó
ó 
ð 	
r   ©rk   )
r   r+   r,   r-   r.   r   rv   r/   r0   rH   rI   s   @@r   ri   ri   ¨   s   ù‡ € ñõ<*÷
ò 
r   ri   c                   ó0   a € ] tR t^Öt o RtR tR tRtV tR# )ÚAuthFailurea’  
Basic exception wrapping an `AuthResult` indicating overall auth failure.

Note that `AuthFailure` descends from `AuthenticationException` but is
generally "higher level"; the latter is now only raised by individual
`AuthSource` attempts and should typically only be seen by users when
encapsulated in this class. It subclasses `AuthenticationException`
primarily for backwards compatibility reasons.
c                ó   € Wn         R # r	   ©rg   )r   rg   s   &&r   r   ÚAuthFailure.__init__á   s   € ØŽr   c                ó:   € R \        V P                  4      ,           # )ro   )rd   rg   r!   s   &r   rv   ÚAuthFailure.__str__ä   s   € Ø”c˜$Ÿ+™+Ó&Õ&Ð&r   r|   N)	r   r+   r,   r-   r.   r   rv   r/   r0   r1   s   @r   rz   rz   Ö   s   ø‡ € ñò÷'ð 'r   rz   c                   ó6   a € ] tR t^èt o RtR tR tR tRtV t	R# )ÚAuthStrategyzì
This class represents one or more attempts to auth with an SSH server.

By default, subclasses must at least accept an ``ssh_config``
(`.SSHConfig`) keyword argument, but may opt to accept more as needed for
their particular strategy.
c                ó:   € Wn         \        \        4      V n        R # r	   )Ú
ssh_configr   r   Úlog)r   rƒ   s   &&r   r   ÚAuthStrategy.__init__ñ   s   € ð %ŒÜœhÓ'ˆŽr   c                ó   € \         h)a+  
Generator yielding `AuthSource` instances, in the order to try.

This is the primary override point for subclasses: you figure out what
sources you need, and ``yield`` them.

Subclasses _of_ subclasses may find themselves wanting to do things
like filtering or discarding around a call to `super`.
r%   r!   s   &r   Úget_sourcesÚAuthStrategy.get_sourcesø   s
   € ô "Ð!r   c                óÆ  € Rp\        V R7      pV P                  4        FY  pV P                  P                  RV 24        VP	                  V4      pRpVP                  \        WE4      4       V'       g   KY   M	  V'       g   \        VR7      hV#   \
         dD   pTpTP                  P                  pT P                  P                  RT RT 24        Rp?L‡Rp?ii ; i)	z›
Handles attempting `AuthSource` instances yielded from `get_sources`.

You *normally* won't need to override this, but it's an option for
advanced users.
Frx   zTrying TzAuthentication via z failed with Nr|   )ri   r‡   r„   Údebugr)   Ú	Exceptionr   r   ÚinfoÚappendrf   rz   )r   r(   Ú	succeededÚoverall_resultr]   rg   ÚeÚsource_classs   &&      r   r)   ÚAuthStrategy.authenticate  sÙ   € ð ˆ	Ü#¨TÔ2ˆð ×&Ñ&Ö(ˆFØ�H‰H�N‰N˜W V HÐ-Ô.ðØ×,Ñ,¨YÓ7�Ø �	ð" ×!Ñ!¤,¨vÓ">Ô?ß‰yÙñ/ )÷4 Ü ^Ô4Ð4àÐøô) ô Ø�ð  !Ÿ{™{×3Ñ3�Ø—‘—‘Ø)¨&¨°¸|¸nÐM÷ñ ûðús   ÁBÂC Â9CÃC )r„   rƒ   N)
r   r+   r,   r-   r.   r   r‡   r)   r/   r0   r1   s   @r   r�   r�   è   s   ø‡ € ñò(ò
"÷+ð +r   r�   N)r.   Úcollectionsr   Úagentr   Úutilr   Ússh_exceptionr   r   r4   r;   rK   rQ   r[   rf   Úlistri   rz   r�   r8   r   r   Ú<module>r˜      s�   ðñõ #å Ý Ý 2÷"ñ "ô:2ˆzô 2ô@ˆzô @ôFB�ô Bô"˜ô ô&
�zô 
ñB ˜.¨8°XÐ*>Ó?€ô*
�ô *
ô\'Ð)ô '÷$Gó Gr   