+
     h4"  c                  s   ^ RI Ht ^ RIt^ RIHt ^ RIHtHt ^ RIH	t	 ^ RI
HtHtHt ^ RIHt ^ RIHt ^ R	IHt ^ R
IHtHtHt ^RIHtHt  ! R R]4      t ! R R]4      t ! R R]4      t ! R R]4      t ! R R]4      t ] ! R R]4      4       t!] ! R R4      4       t"R t#]#R R l4       t$ ! R R]PJ                  4      t& ! R R ]&4      t' ! R! R"]&4      t(R# t)R$ t* ! R% R&]PJ                  4      t+R# )'i    )annotationsN)	dataclass)IntEnumuniquewraps)AnyMappingSequence)x509)InvalidSignature)default_backend)ecpaddingrsa)AttestationObjectAuthenticatorDatac                  s    ] tR t^,tRtRtR# )InvalidAttestationz.Base exception for attestation-related errors. N__name__
__module____qualname____firstlineno____doc____static_attributes__r       ;/usr/lib/python3.14/site-packages/fido2/attestation/base.pyr   r   ,   s    8r   r   c                  s    ] tR t^0tRtRtR# )InvalidDataz"Attestation contains invalid data.r   Nr   r   r   r   r   r   0   s    ,r   r   c                  s    ] tR t^4tRtRtR# )r
   z7The signature of the attestation could not be verified.r   Nr   r   r   r   r
   r
   4   s    Ar   r
   c                  s    ] tR t^8tRtRtR# )UntrustedAttestationz)The CA of the attestation is not trusted.r   Nr   r   r   r   r   r   8   s    3r   r   c                  s0   a  ] tR t^<tRtRV 3R lltRtV ;t# )UnsupportedTypez(The attestation format is not supported.c                	sZ   < \         ST `  V'       d   R V R2MR4       Wn        W n        R# )zAttestation format "z" is not supportedz)This attestation format is not supported!N)super__init__	auth_datafmt)selfr!   r"   	__class__s   &&&r   r    ZUnsupportedType.__init__?   s1     #3%'9:<	

 #r   )r!   r"   N)r   r   r   r   r   r    r   __classcell__)r$   s   @r   r   r   <   s    2 r   r   c                  s.    ] tR t^ItRt^t^t^t^t^ t	Rt
R# )AttestationTypezSupported attestation types.r   N)r   r   r   r   r   ZBASICZSELFZATT_CAZANON_CANONEr   r   r   r   r'   r'   I   s    &EDFGDr   r'   c                  s0    ] tR t^Tt$ RtR]R&   R]R&   RtR# )AttestationResultz'The result of verifying an attestation.r'   Zattestation_typelist[bytes]
trust_pathr   N)r   r   r   r   r   Z__annotations__r   r   r   r   r)   r)   T   s    1%%r   r)   c                s0   a  \        S 4      V 3R l4       pV# )zDUtility decoractor to wrap common exceptions related to InvalidData.c                 sh   <  S! V / VB #   \         \        \        3 d   p\        T4      hR p?ii ; ir%   )
ValueErrorZKeyErrorZ
IndexErrorr   )argsZkwargsefs   *, r   innerZcatch_builtins.<locals>.inner_   s9    	!d%f%%Hj1 	!a. 	!s    1,1r   )r/   r0   s   f r   catch_builtinsr1   \   s"     1X! ! Lr   c                    V ^8  d   QhRRRR/# )   chainr*   returnNoner   Zformat   "r   __annotate__r9   j   s     % %[ %T %r   c                s   V  Uu. uF"  p\         P                  ! V\        4       4      NK$  	  ppVP                  ^ 4      pV'       d   TpVP                  ^ 4      pVP	                  4       p \        V\        P                  4      '       dH   VP                  VP                  VP                  \        P                  ! 4       VP                  4       K  \        V\        P                  4      '       dH   VP                  VP                  VP                  \        P                   ! VP                  4      4       K  \#        R4      hR# u upi   \$         d    \'        4       hi ; i)zVerifies a chain of certificates.

Checks that the first item in the chain is signed by the next, and so on.
The first item is the leaf, the last is the root.
zUnsupported signature key typeN)r	   Zload_der_x509_certificater   ZpopZ
public_keyZ
isinstancer   ZRSAPublicKeyverifyZ	signatureZtbs_certificate_bytesr   ZPKCS1v15Zsignature_hash_algorithmr   ZEllipticCurvePublicKeyZECDSAr,   _InvalidSignaturer
   )r4   ZderZcertscertZchildZpubs   &     r   verify_x509_chainr=   i   s    PUUuT++C1BCuEU99Q<D
yy|oo	%#s//00

OO//$$&22	 C!:!:;;

OO//HHU;;< !!ABB+  V0 ! 	%"$$	%s   (E,A%E A%E :E E"c                  sZ    ] tR t^tRt]P                  R R l4       t]R R l4       t	Rt
R# )Attestationz7Implements verification of a specific attestation type.c               s(    V ^8  d   QhRRRRRRRR/# )	r3   	statementzMapping[str, Any]r!   r   client_data_hashbytesr5   r)   r   r7   r8   r   r9   Attestation.__annotate__   s2     	 	$	 %	  		
 
	r   c                s    R# )zNVerifies attestation statement.

:return: An AttestationResult if successful.
Nr   r#   r?   r!   r@      &&&&r   r:   ZAttestation.verify   s    r   c               r2   )r3   r"   Zstrr5   ztype[Attestation]r   r7   r8   r   r9   rB      s     
+ 
+c 
+/ 
+r   c                s   a  \         P                  4        F  p\        VRR4      S 8X  g   K  Vu # 	   ! V 3R lR\        4      pV# )z6Get an Attestation subclass type for the given format.FORMATNc                  s,   <a  ] tR t^tV V3R ltRtV ;t# )9Attestation.for_type.<locals>.TypedUnsupportedAttestationc                	s&   < \         SV `  S4       R # r%   )r   r    )r#   r$   r"   s   &r   r    ZBAttestation.for_type.<locals>.TypedUnsupportedAttestation.__init__   s     %r   r   )r   r   r   r   r    r   r&   )r$   r"   s   @r   TypedUnsupportedAttestationrF      s    & &r   rG   )r>   __subclasses__getattrUnsupportedAttestation)r"   clsrG   s   f  r   for_typeZAttestation.for_type   sC     --/CsHd+s2
 0	&*@ 	& +*r   r   N)r   r   r   r   r   abcabstractmethodr:   ZstaticmethodrL   r   r   r   r   r>   r>      s1    A	 	 
+ 
+r   r>   c                  s&    ] tR t^tRR ltR tRtR# )rJ   Nc                	s    Wn         R # r%   r"   )r#   r"      &&r   r    ZUnsupportedAttestation.__init__   s    r   c                	s,    \        W P                  4      hr%   )r   r"   rC   rD   r   r:   ZUnsupportedAttestation.verify   s    i22r   rO   r%   )r   r   r   r   r    r:   r   r   r   r   rJ   rJ      s    3r   rJ   c                  s     ] tR t^tRtR tRtR# )NoneAttestationnonec                	sZ    V/ 8w  d   \        R 4      h\        \        P                  . 4      # )z*None Attestation requires empty statement.)r   r)   r'   r(   rC   rD   r   r:   ZNoneAttestation.verify   s(    ?JKK !5!5r::r   r   N)r   r   r   r   rE   r:   r   r   r   r   rQ   rQ      s    F;r   rQ   c                sX   V P                   \        P                  P                  8w  d   \	        R 4      h V P
                  P                  \        P                  4      pVP                  P                  '       d   \	        R4      hR#   \        P                   d    \	        R4      hi ; i)z+Attestation certificate must use version 3!z+Attestation certificate must have CA=false!z4Attestation certificate must have Basic Constraints!N)Zversionr	   ZVersionZv3r   Z
extensionsZget_extension_for_classZBasicConstraintsZvaluecaZExtensionNotFound)r<   Zbcs   & r   _validate_cert_commonrT      s    ||t||&GHHR__44T5J5JK88;;;KLL !! RPQQRs   AB ;B !B)c                 s    \         P                  4        U u. uF  p \        V R R4      R8w  g   K  V ! 4       NK   	  up # u up i )rE   rR   )r>   rH   rI   )rK   s    r   _default_attestationsrU      sG     --//C3&)V3 	/  s   >>c                  sf    ] tR t^tRtRR R llt]P                  R R l4       tR R lt	R	 t
R
tR# )AttestationVerifierzBase class for verifying attestation.

Override the ca_lookup method to provide a trusted root certificate used
to verify the trust path from the attestation.
Nc               s    V ^8  d   QhRR/# )r3   attestation_typeszSequence[Attestation] | Noner   r7   r8   r   r9    AttestationVerifier.__annotate__   s     O O*F Or   c                	s8    T;'       g    \        4       V n        R # r%   )rU   _attestation_types)r#   rW   rP   r   r    ZAttestationVerifier.__init__   s    "3"N"N7L7Nr   c               $    V ^8  d   QhRRRRRR/# )r3   attestation_resultr)   r!   r   r5   zbytes | Noner   r7   r8   r   r9   rX      s$     $ $"3$@Q$	$r   c                s    \        4       h)zLookup a CA certificate to be used to verify a trust path.

:param attestation_result: The result of the attestation
:param auth_data: The AuthenticatorData from the registration
)ZNotImplementedError)r#   r[   r!   s   &&&r   	ca_lookupZAttestationVerifier.ca_lookup   s     "##r   c               rZ   )r3   attestation_objectr   r@   rA   r5   r6   r   r7   r8   r   r9   rX      s$     * *"3*GL*	*r   c                s   \        VP                  4      pV P                   F#  p\        VRR4      VP                  8X  g   K!  Tp M	  VP	                  VP
                  VP                  V4      pV P                  WQP                  4      pV'       g   \        R4      h \        VP                  V.,           4       R#   \         d   p\        T4      hRp?ii ; i)zVerify attestation.

:param attestation_object: dict containing attestation data.
:param client_data_hash: SHA256 hash of the ClientData bytes.
rE   NzNo root found for Authenticator)rJ   r"   rY   rI   r:   Zatt_stmtr!   r\   r   r=   r+   r
   )r#   r]   r@   Zatt_verifierZatZresultrS   r.   s   &&&     r   verify_attestationZ&AttestationVerifier.verify_attestation   s     %;;M;Q;Q$R))Br8T*.@.D.DD! * $$''((
 ^^F$@$@A&'HII	*f//2$67 	*&q))	*s   B> >C	CCc                s&    V P                   ! V!   R# )z?Allows passing an instance to Fido2Server as verify_attestationN)r^   )r#   r-   s   &*r   __call__ZAttestationVerifier.__call__  s    &r   )rY   r%   )r   r   r   r   r   r    rM   rN   r\   r^   r_   r   r   r   r   rV   rV      s2    O 	$ $*B'r   rV   ),Z
__future__r    rM   Zdataclassesr   Zenumr   r   Z	functoolsr   Ztypingr   r   r   Zcryptographyr	   Zcryptography.exceptionsr
   r;   Zcryptography.hazmat.backendsr   Z)cryptography.hazmat.primitives.asymmetricr   r   r   Zwebauthnr   r   Z	Exceptionr   r   r   r   r'   r)   r1   r=   ZABCr>   rJ   rQ   rT   rU   rV   r   r   r   <module>r`      s  8 # 
 !    ) )  I 8 F F ;9 9-$ -B) B4- 4
( 
 g     
 % %D+#'' +:3[ 3;k ;	R8'#'' 8'r   