+
     h`=  c                  s|   ^ RI Ht ^ RIt^ RIt^ RIHtHtHtHt ^ RI	H
t ^ RIHt ^RIHt ^RIHt ^RIHtHt ^R	IHtHtHtHtHtHtHtHtHtHtH t H!t!H"t"H#t#H$t$H%t%H&t&H't'H(t(H)t) ]PT                  ! ]+4      t,]]]-.R3,          t.]]/.]03,          t1R
 R lt2R R lt3RR R llt4R R lt5R R lt6 ! R R4      t7R# )i    )annotationsN)AnyCallableMappingSequence)InvalidSignature)constant_time)CoseKeyverify_rp_id)websafe_decodewebsafe_encode)AttestationConveyancePreferenceAttestationObjectAttestedCredentialDataAuthenticationResponseAuthenticatorAttachmentAuthenticatorDataAuthenticatorSelectionCriteriaCollectedClientDataCredentialCreationOptionsCredentialRequestOptions"PublicKeyCredentialCreationOptionsPublicKeyCredentialDescriptorPublicKeyCredentialParameters!PublicKeyCredentialRequestOptionsPublicKeyCredentialRpEntityPublicKeyCredentialTypePublicKeyCredentialUserEntityRegistrationResponseResidentKeyRequirementUserVerificationRequirementc                    V ^8  d   QhRRRR/# )   rp_idstrreturnVerifyOrigin Zformat   "1/usr/lib/python3.14/site-packages/fido2/server.py__annotate__r*   F   s     , , , ,    c                s   a  V 3R  l# )c                s   < \        SV 4      # Nr   )Zor"   s   &r)   Z<lambda>Z'_verify_origin_for_rp.<locals>.<lambda>G   s    \%+r+   r&   )r"   s   fr)   _verify_origin_for_rpr-   F   s	    ++r+   c               r    )r!   	challengebytes | Noner$   bytesr&   r'   r(   r)   r*   r*   J   s      < E r+   c                s    V f   \         P                  ! ^ 4      p V # \        V \        4      '       g   \	        R4      h\        V 4      ^8  d   \        R4      hV # )Nz)Custom challenge must be of type 'bytes'.z&Custom challenge length must be >= 16.)osZurandom
isinstancer0   Z	TypeErrorZlen
ValueError)r.   s   &r)   _validata_challenger4   J   sV    JJrN	 	 )U++GHHy>BEFFr+   c               r    )r!   
credentialr   r$   r   r&   r'   r(   r)   r*   r*   U   s      &"r+   c                sN    \        \        P                  V P                  VR7      # )a~  Converts an AttestedCredentialData to a PublicKeyCredentialDescriptor.

:param credential: AttestedCredentialData containing the credential ID to use.
:param transports: Optional list of AuthenticatorTransport strings to add to the
    descriptor.
:return: A descriptor of the credential, for use with register_begin or
    authenticate_begin.
:rtype: PublicKeyCredentialDescriptor
)typeid
transports)r   r   
PUBLIC_KEYcredential_id)r5   r8      &&r)   to_descriptorr<   U   s&     )$//## r+   c               r    )r!   credsGSequence[AttestedCredentialData | PublicKeyCredentialDescriptor] | Noner$   z.Sequence[PublicKeyCredentialDescriptor] | Noner&   r'   r(   r)   r*   r*   h   s      R3r+   c                s    V f   R # V  Uu. uF:  p\        V\        4      '       d   \        V4      M\        P                  ! V4      NK<  	  up# u upi r,   )r2   r   r<   r   	from_dict)r=   Zc   & r)   _wrap_credentialsrA   h   s_     }  A !344 !.88;<   s   A Ac               $    V ^8  d   QhRRRRRR/# )r!   attestation_objectr   client_data_hashr0   r$   ZNoner&   r'   r(   r)   r*   r*   w   s$      )=B	r+   c                s    R# )zIgnore attestation.Nr&   )rC   rD   r;   r)   _ignore_attestationrE   w   s    r+   c                  sx    ] tR t^}tRtRR R lltRR R lltR R ltRR	 R
 lltR R lt	]
R R l4       tRtR# )Fido2Servera   FIDO2 server.

:param rp: Relying party data as `PublicKeyCredentialRpEntity` instance.
:param attestation: (optional) Requirement on authenticator attestation.
:param verify_origin: (optional) Alternative function to validate an origin.
:param verify_attestation: (optional) function to validate attestation, which is
    invoked with attestation_object and client_data_hash. It should return nothing
    and raise an exception on failure. By default, attestation is ignored.
    Attestation is also ignored if `attestation` is set to `none`.
Nc               (    V ^8  d   QhRRRRRRRR/# )	r!   rpr   attestationz&AttestationConveyancePreference | Noneverify_originzVerifyOrigin | Noneverify_attestationzVerifyAttestation | Noner&   r'   r(   r)   r*   Fido2Server.__annotate__   s8     C C'C <C +	C
 5Cr+   c                	s   \         P                  ! V4      V n        T;'       g     \        V P                  P                  4      V n        R V n        \        V4      V n        \        P                  ! 4        Uu. uF  p\        \        P                  VR7      NK   	  upV n        T;'       g    \        V n        \"        P%                  RV P                   24       R # u upi )N)r6   algz Fido2Server initialized for RP: )r   r?   rH   r-   r7   _verifytimeoutr   rI   r   Zsupported_algorithmsr   r   r9   allowed_algorithmsrE   _verify_attestationloggerdebug)selfrH   rI   rJ   rK   rM   s   &&&&& r)   __init__ZFido2Server.__init__   s     .77;$II(=dggjj(I:;G
 335	#
 6 *,77S 6	#
 $6#L#L9L 7yAB#
s   8$Cc               s4    V ^8  d   QhRRRRRRRRR	R
RRRR/# )r!   userr   credentialsr>   resident_key_requirementzResidentKeyRequirement | Noneuser_verification"UserVerificationRequirement | Noneauthenticator_attachmentzAuthenticatorAttachment | Noner.   r/   r$   z%tuple[CredentialCreationOptions, Any]r&   r'   r(   r)   r*   rL      s\     B
 B
+B
 T	B
 #@B
 >B
 #AB
  B
 
/B
r+   c                s   V P                   '       g   \        R4      h\        V4      p\        V4      pV P	                  Wd4      p	\
        P                  RRP                  R T;'       g    .  4       4      ,           4       \        \        V P                  \        P                  ! V4      TV P                   V P                  T\        VVV34      '       d   \        VVVR7      MRV P                   VR7	      R7      V	3# )	a  Return a PublicKeyCredentialCreationOptions registration object and
the internal state dictionary that needs to be passed as is to the
corresponding `register_complete` call.

:param user: The dict containing the user data.
:param credentials: The list of previously registered credentials, these can be
    of type AttestedCredentialData, or PublicKeyCredentialDescriptor.
:param resident_key_requirement: The desired RESIDENT_KEY_REQUIREMENT level.
:param user_verification: The desired USER_VERIFICATION level.
:param authenticator_attachment: The desired AUTHENTICATOR_ATTACHMENT
    or None to not provide a preference (and get both types).
:param challenge: A custom challenge to sign and verify or None to use
    OS-specific random bytes.
:return: Registration data, internal state.z!Server has no allowed algorithms.z1Starting new registration, existing credentials: , c              3  T   "   T F  qP                   P                  4       x  K   	  R # 5ir,   r7   hexZ.0Zdr@   r)   	<genexpr>Z-Fido2Server.register_begin.<locals>.<genexpr>   s     >,=q

,=   &()r[   Zresident_keyrY   N)	rH   rV   r.   Zpub_key_cred_paramsrO   Zexclude_credentialsZauthenticator_selectionrI   
extensions
public_key)rP   r3   r4   rA   _make_internal_staterR   rS   joinr   r   rH   r   r?   rO   Zanyr   rI   )
rT   rV   rW   rX   rY   r[   r.   rc   descriptorsstates
   &&&&&&&&  r)   register_beginZFido2Server.register_begin   s    4 &&&@AA'	2	'4)))G?ii>K,=,=2,=>>?	
 &=ww6@@F'(,(?(? LL(3  8 8 1  75M)A.? " $ 0 0)/6 9
 	
r+   c               r    )r!   responsez(RegistrationResponse | Mapping[str, Any]r$   r   r&   r'   r(   r)   r*   rL      s      4 4 ;4 
	4r+   c                s   \         P                  ! V4      pVP                  P                  pVP                  P                  pVP
                  \        P                  P                  8w  d   \        R4      hV P                  VP                  4      '       g   \        R4      h\        P                  ! \        VR,          4      VP                  4      '       g   \        R4      h\        P                  ! V P                   P"                  ;'       g    RVP$                  P&                  4      '       g   \        R4      hVP$                  P)                  4       '       g   \        R4      hVR,          \*        P,                  8X  d,   VP$                  P/                  4       '       g   \        R	4      hV P0                  R
\2        P4                  39  d>   \6        P9                  RVP:                   24       V P=                  WTP>                  4       VP$                  p\6        PA                  RVPB                  PD                  PG                  4       ,           4       V# )zVerify the correctness of the registration data received from
the client.

:param state: The state data returned by the corresponding
    `register_begin`.
:param response: The registration response from the client.
:return: The authenticator data
&Incorrect type in CollectedClientData.&Invalid origin in CollectedClientData.r.   Wrong challenge in response.r+   Wrong RP ID hash in response.User Present flag not set.rY   z;User verification required, but User Verified flag not set.NzVerifying attestation of type zNew credential registered: )$r   r?   rk   client_datarC   r6   r   TYPEZCREATEr3   rN   originr   bytes_eqr
   r.   rH   id_hash	auth_data
rp_id_hashis_user_presentr   REQUIREDis_user_verifiedrI   r   ZNONErR   rS   ZfmtrQ   hashinfoZcredential_datar:   r_   )rT   ri   rk   Zregistrationrq   rC   rv   s   &&&    r)   register_completeZFido2Server.register_complete   s    ,55h?"++77)22EE277>>>EFF||K..//EFF%%5-.0E0E
 
 ;<<%%GGOO""s$6$@$@$K$K
 
 <==!++;;==9:: %&*E*N*NN&00AACCM  D*I*N*N#OOLL9:L:P:P9QRS$$%79I9IJ '00	)''5599;<	
 r+   c               rG   )	r!   rW   r>   rY   rZ   r.   r/   r$   z$tuple[CredentialRequestOptions, Any]r&   r'   r(   r)   r*   rL     s5     *
 *
 T*

 >*
  *
 
.*
r+   c                s^   \        V4      p\        V4      pV P                  W24      pVf   \        P	                  R4       M2\        P	                  RRP                  R V 4       4      ,           4       \        \        VV P                  V P                  P                  VVVR7      R7      V3# )a  Return a PublicKeyCredentialRequestOptions assertion object and the internal
state dictionary that needs to be passed as is to the corresponding
`authenticate_complete` call.

:param credentials: The list of previously registered credentials, these can be
    of type AttestedCredentialData, or PublicKeyCredentialDescriptor.
:param user_verification: The desired USER_VERIFICATION level.
:param challenge: A custom challenge to sign and verify or None to use
    OS-specific random bytes.
:return: Assertion data, internal state.z/Starting new authentication without credentialsz.Starting new authentication, for credentials: r\   c              3  r]   r,   r^   r`   r@   r)   ra   Z1Fido2Server.authenticate_begin.<locals>.<genexpr>3  s     <1DDHHJJrb   )r.   rO   r"   Zallow_credentialsrY   rc   rd   )r4   rA   rf   rR   rS   rg   r   r   rO   rH   r7   )rT   rW   rY   r.   rc   rh   ri   s   &&&&&  r)   authenticate_beginZFido2Server.authenticate_begin  s    & (	2	'4)))GLLJKLL@))<<<= %<' LL''**&1&7)	 
 	
r+   c               rB   )r!   rW   z Sequence[AttestedCredentialData]rk   z*AuthenticationResponse | Mapping[str, Any]r$   r   r&   r'   r(   r)   r*   rL   D  s*     23 23 623 =	23
 
 23r+   c                sj   \         P                  ! V4      pVP                  pVP                  P                  pVP                  P
                  pVP                  P                  pVP                  \        P                  P                  8w  d   \        R4      hV P                  VP                  4      '       g   \        R4      h\        VR,          4      VP                  8w  d   \        R4      h\         P"                  ! V P$                  P&                  ;'       g    RVP(                  4      '       g   \        R4      hVP+                  4       '       g   \        R4      hVR,          \,        P.                  8X  d"   VP1                  4       '       g   \        R	4      hV Fk  p	V	P2                  V8X  g   K   V	P4                  P7                  WvP8                  ,           V4       \<        P?                  RTPA                  4        24       T	u # 	  \        R4      h  \:         d    \        R
4      hi ; i)a  Verify the correctness of the assertion data received from
the client.

:param state: The state data returned by the corresponding
    `register_begin`.
:param credentials: The list of previously registered credentials.
:param credential_id: The credential id from the client response.
:param client_data: The client data.
:param auth_data: The authenticator data.
:param signature: The signature provided by the client.rl   rm   r.   rn   r+   ro   rp   rY   z;User verification required, but user verified flag not set.zInvalid signature.zCredential authenticated: zUnknown credential ID.)!r   r?   Zraw_idrk   rq   Zauthenticator_data	signaturer6   r   rr   ZGETr3   rN   rs   r
   r.   r   rt   rH   ru   rw   rx   r   ry   rz   r:   re   Zverifyr{   _InvalidSignaturerR   r|   r_   )
rT   ri   rW   rk   Zauthenticationr:   rq   rv   r   Zcreds
   &&&&      r)   authenticate_completeZ!Fido2Server.authenticate_completeD  s   " 099(C&--$--99"++>>	"++55	277;;;EFF||K..//EFF%,-1F1FF;<<%%dggoo&<&<i>R>RSS<==((**9:: %&*E*N*NN..00M   D!!]2;OO**97G7G+GS 89J9J9L8MNO   122	 ) ;$%9::;s   8,HH2c               r    )r!   r.   r0   rY   rZ   r&   r'   r(   r)   r*   rL   y  s     
 

-O
r+   c                	s     R \        V 4      RV/# r.   rY   )r   r   r;   r)   rf   Z Fido2Server._make_internal_statex  s    
 	2!2
 	
r+   )rN   rQ   rP   rI   rH   rO   )NNN)NNNNNN)NNNN)__name__Z
__module__Z__qualname__Z__firstlineno__Z__doc__rU   rj   r}   r~   r   Zstaticmethodrf   Z__static_attributes__r&   r+   r)   rF   rF   }   s:    	C*B
H4l*
X23h 
 
r+   rF   r,   )8Z
__future__r    Zloggingr1   Ztypingr   r   r   r   Zcryptography.exceptionsr   r   Zcryptography.hazmat.primitivesr   Zcoser   Zrpidr	   Zutilsr
   r   Zwebauthnr   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   Z	getLoggerr   rR   r0   ZVerifyAttestationr#   Zboolr%   r-   r4   r<   rA   rE   rF   r&   r+   r)   <module>r      s   8 #  	 3 3 I 8   1     . 
		8	$ /7=> t$,&B
 B
r+   