Ë
    aQbjµ*  ã                   ó*  — d Z ddlmZmZmZmZ ddlmZmZ ddl	m	Z	 ddlm
Z
 erddlmZ 	 dd	lmZ dd
lmZmZ ddlmZ ddlmZ 	 ddlmZ dZdZ G d„ de«      Z G d„ de
«      Z y# e$ rZ ej2                  d«      e‚dZ[ww xY w# e$ r dZY ŒBw xY w)zWebAuthn Authentication Plugin.é    )ÚTYPE_CHECKINGÚAnyÚCallableÚOptionalé   )ÚerrorsÚutils)Úloggeré   )ÚMySQLAuthPlugin)ÚMySQLSocket)Ú
dump_bytes)ÚFido2ClientÚUserInteraction)ÚCtapHidDevice)Ú!PublicKeyCredentialRequestOptionszxModule fido2 is required for WebAuthn authentication mechanism but was not found. Unable to authenticate with the serverN)ÚCtapPcscDeviceTFÚMySQLWebAuthnAuthPluginc                   ó,   — e Zd ZdZddee   fd„Zdd„Zy)ÚClientInteractionz(Provides user interaction to the Client.NÚcallbackc                 ó    — || _         d| _        y )NzTPlease insert FIDO device and perform gesture action for authentication to complete.)r   Úmsg)Úselfr   s     úi/var/www/html/venv/lib/python3.12/site-packages/mysql/connector/plugins/authentication_webauthn_client.pyÚ__init__zClientInteraction.__init__B   s   € Ø ˆŒðð 	�ó    c                 ó~   — | j                   €t        | j                  «       y| j                  | j                  «       y)z=Prompt message for the user interaction with the FIDO device.N)r   Úprintr   ©r   s    r   Ú	prompt_upzClientInteraction.prompt_upI   s'   € à�=‰=Ð Ü�$—(‘(�Oà�M‰M˜$Ÿ(™(Õ#r   ©N)ÚreturnN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r   r   r!   © r   r   r   r   ?   s   „ Ù2ñ
 ¨(Ñ!3ó 
ô$r   r   c                   óà   — e Zd ZU dZdZee   ed<   dZee	   ed<   ddg dœZ
eed<   edefd„«       Zedefd	„«       Z	 dd
ee   defd„Zdededee   fd„Zdddededefd„Zdddededefd„Zy)r   z<Class implementing the MySQL WebAuthn authentication plugin.NÚclientr   )ÚrpIdÚ	challengeÚallowCredentialsÚoptionsr#   c                  ó   — y)zPlugin official name.Úauthentication_webauthn_clientr(   r    s    r   ÚnamezMySQLWebAuthnAuthPlugin.nameX   s   € ð 0r   c                  ó   — y)z'Signals whether or not SSL is required.Fr(   r    s    r   Úrequires_sslz$MySQLWebAuthnAuthPlugin.requires_ssl]   s   € ð r   Úcredential_idc                 ó  — | j                   €t        j                  d«      ‚|�|ddœg| j                  d<   | j                   j	                  t        j                  | j                  «      «      }t        |j                  «       «      }d}t        j                  d«      }|t        j                  |«      z  }t        |«      D ]Œ  }|j                  |«      }t        |j                  «      }|j                  }	|t        j                  t        |«      «      z  }||z  }|t        j                  t        |	«      «      z  }||	z  }|j                   }ŒŽ |t        j                  t        |«      «      z  }||z  }t#        j$                  d|«       |S )zôGet assertion from authenticator and return the response.

        Args:
            credential_id (Optional[bytearray]): The credential ID.

        Returns:
            bytearray: The response packet with the data from the assertion.
        zNo WebAuthn client foundz
public-key)ÚidÚtyper-   r   r   z&WebAuthn - payload response packet: %s)r*   r   ÚInterfaceErrorr.   Úget_assertionr   Ú	from_dictÚlenÚget_assertionsr	   Úlc_intÚrangeÚget_responseÚcbor_dump_bytesÚauthenticator_dataÚ	signatureÚclient_datar
   Údebug)
r   r4   Ú	assertionÚnumber_of_assertionsÚclient_data_jsonÚpacketÚiÚassertion_responserA   rB   s
             r   Úget_assertion_responsez.MySQLWebAuthnAuthPlugin.get_assertion_responseb   s�  € ð �;‰;ÐÜ×'Ñ'Ð(BÓCÐCàÐ$ð
 (Ø(ñð0ˆD�L‰LÐ+Ñ,ð —K‘K×-Ñ-Ü-×7Ñ7¸¿¹ÓEó
ˆ	ô  # 9×#;Ñ#;Ó#=Ó>ÐØÐô —‘˜a“ˆØ”%—,‘,Ð3Ó4Ñ4ˆô Ð+Ó,ò 	>ˆAØ!*×!7Ñ!7¸Ó!:Ðô "1Ð1C×1VÑ1VÓ!WÐð +×4Ñ4ˆIà”e—l‘l¤3Ð'9Ó#:Ó;Ñ;ˆFØÐ(Ñ(ˆFØ”e—l‘l¤3 y£>Ó2Ñ2ˆFØ�iÑˆFð  2×=Ñ=Ñð	>ð" 	”%—,‘,œsÐ#3Ó4Ó5Ñ5ˆØÐ"Ñ"ˆä�‰Ð=¸vÔFØˆr   Ú	auth_dataÚkwargsc                 óÈ  — 	 t        j                  |d«      \  }}t        j                  |«      \  }}|| j                  d<   |j	                  «       | j                  d<   t        j                  d|«       t        j                  d| j                  d   «       t        j                  d| j                  d   «       t        t        j                  «       d«      }|�t        j                  d	«       n$t        rt        t        j                  «       d«      }|€t        j                  d
«      ‚t        |d| j                  d   › �t!        | j"                  «      ¬«      | _        | j$                  j&                  j                  j)                  d«      st        j                  d«       yt        j                  d«       y# t        $ r}t        j                  d«      |‚d}~ww xY w)aE  Find authenticator device and check if supports resident keys.

        It also creates a Fido2Client using the relying party ID from the server.

        Raises:
            InterfaceError: When the FIDO device is not found.

        Returns:
            bytes: 2 if the authenticator supports resident keys else 1.
        r   r,   r+   zWebAuthn - capability: %dzWebAuthn - challenge: %szWebAuthn - relying party id: %sz2Unable to parse MySQL WebAuthn authentication dataNzWebAuthn - Use USB HID channelzNo FIDO device foundzhttps://)Úuser_interactionÚrkz6WebAuthn - Authenticator doesn't support resident keysó   1z<WebAuthn - Authenticator with support for resident key foundó   2)r	   Úread_intÚread_lc_string_listr.   Údecoder
   rD   Ú
ValueErrorr   r8   Únextr   Úlist_devicesÚCTAP_PCSC_DEVICE_AVAILABLEr   r   r   r   r*   ÚinfoÚget)	r   rL   rM   ÚpacketsÚ
capabilityr,   Úrp_idÚerrÚdevices	            r   Úauth_responsez%MySQLWebAuthnAuthPlugin.auth_response¨   s‡  € ð	Ü"'§.¡.°¸AÓ">ÑˆG�ZÜ$×8Ñ8¸ÓAÑˆI�uØ(1ˆD�L‰L˜Ñ%Ø#(§<¡<£>ˆD�L‰L˜Ñ Ü�L‰LÐ4°jÔAÜ�L‰LÐ3°T·\±\À+Ñ5NÔOÜ�L‰LÐ:¸D¿L¹LÈÑ<PÔQô ”m×0Ñ0Ó2°DÓ9ˆØÐÜ�L‰LÐ9Õ:Ý'Üœ.×5Ñ5Ó7¸Ó>ˆFàˆ>Ü×'Ñ'Ð(>Ó?Ð?ô "ØØ�t—|‘| FÑ+Ð,Ð-Ü.¨t¯}©}Ó=ô
ˆŒð �{‰{×Ñ×'Ñ'×+Ñ+¨DÔ1Ü�L‰LÐQÔRØä�‰ÐSÔTØøô7 ò 	Ü×'Ñ'ØDóàðûð	ús   ‚B9F= Æ=	G!ÇGÇG!Úsockr   c                 ó  — t        j                  |«      \  }}| j                  |«      }t        j                  d|t        |«      «       |j                  |«       t        |j                  «       «      }t        j                  d|«       |S )aE  Handles server's `auth more data` response.

        Args:
            sock: Pointer to the socket connection.
            auth_data: Authentication method data (from a packet representing
                       an `auth more data` response).
            kwargs: Custom configuration to be passed to the auth plugin
                    when invoked. The parameters defined here will override the ones
                    defined in the auth plugin itself.

        Returns:
            packet: Last server's response after back-and-forth
                    communication.
        úWebAuthn - request: %s size: %sú%WebAuthn - server response packet: %s)	r	   Úread_lc_stringrK   r
   rD   r;   ÚsendÚbytesÚrecv)r   rb   rL   rM   Ú_r4   ÚresponseÚpkts           r   Úauth_more_responsez*MySQLWebAuthnAuthPlugin.auth_more_responseØ   sn   € ô" !×/Ñ/°	Ó:Ñˆˆ=à×.Ñ.¨}Ó=ˆä�‰Ð6¸Ä#ÀhÃ-ÔPØ�	‰	�(Ôä�D—I‘I“KÓ ˆÜ�‰Ð<¸cÔBàˆ
r   c                 ón  — |j                  d«      xs |j                  d«      }t        |t        «      rt        j                  |«      n|| _        | j                  |«      }d}|dk(  r[t        j                  d«       |j                  t        j                  t        |«      «      «       t        |j                  «       «      S | j                  |«      }t        j                  d|t        |«      «       |j                  |«       t        |j                  «       «      }t        j                  d|«       |S )aS  Handles server's `auth switch request` response.

        Args:
            sock: Pointer to the socket connection.
            auth_data: Plugin provided data (extracted from a packet
                       representing an `auth switch request` response).
            kwargs: Custom configuration to be passed to the auth plugin
                    when invoked. The parameters defined here will override the ones
                    defined in the auth plugin itself.

        Returns:
            packet: Last server's response after back-and-forth
                    communication.
        Úwebauthn_callbackÚfido_callbackNrQ   z WebAuthn - request credential_idrd   re   )r[   Ú
isinstanceÚstrr	   Úimport_objectr   ra   r
   rD   rg   r=   Úintrh   ri   rK   r;   )r   rb   rL   rM   Úwebauth_callbackrk   r4   rl   s           r   Úauth_switch_responsez,MySQLWebAuthnAuthPlugin.auth_switch_responseõ   sü   € ð" "Ÿ:™:Ð&9Ó:ò 
¸f¿j¹jØó?
Ðô
 Ð*¬CÔ0ô ×ÑÐ 0Ô1à!ð 	Œð ×%Ñ% iÓ0ˆØˆà�tÒä�L‰LÐ;Ô<Ø�I‰I”e—l‘l¤3 x£=Ó1Ô2ô ˜Ÿ™›Ó%Ð%à×.Ñ.¨}Ó=ˆä�‰Ð6¸Ä#ÀhÃ-ÔPØ�	‰	�(Ôä�D—I‘I“KÓ ˆÜ�‰Ð<¸cÔBàˆ
r   r"   )r$   r%   r&   r'   r*   r   r   Ú__annotations__r   r   r.   ÚdictÚpropertyrr   r1   Úboolr3   Ú	bytearrayrh   rK   r   ra   rm   rv   r(   r   r   r   r   Q   sô   … ÙFà$(€FˆH�[Ñ!Ó(Ø#'€Hˆh�xÑ Ó'Ø!°È"ÑM€GˆTÓMàð0�cò 0ó ð0ð ð˜dò ó ðð
 48ñDØ% iÑ0ðDà	óDðL. uð .¸ð .ÀÈÁó .ð`Ø!ðØ.3ðØ?Bðà	óð:-Ø!ð-Ø.3ð-Ø?Bð-à	ô-r   )!r'   Útypingr   r   r   r   Ú r   r	   r
   r   Únetworkr   Ú
fido2.cborr   r@   Úfido2.clientr   r   Ú	fido2.hidr   Úfido2.webauthnr   ÚImportErrorÚ
import_errÚProgrammingErrorÚ
fido2.pcscr   rY   ÚModuleNotFoundErrorÚAUTHENTICATION_PLUGIN_CLASSr   r   r(   r   r   ú<module>r‰      sª   ðñ: &÷ :Ó 9ç Ý Ý áÝ%ð	Ý8ß9Ý'Ý@ð'Ý)à!%Ðð
 8Ð ô$˜ô $ô$Q˜oõ QøðG ò Ø
!ˆ&×
!Ñ
!ð	<óð ðûðûð ò 'Ø!&Òð'ús)   ¬A( ÁB Á(BÁ-B Â BÂBÂB