+
     h4"  c                  s   ^ RI Ht ^ RIt^ RIHt ^ RIHtHt ^ RIH	t	 ^ RI
HtHtHt ^ RIHt ^ RIHt ^ R	IHt ^ R
IHtHtHt ^RIHtHt  ! R R]4      t ! R R]4      t ! R R]4      t ! R R]4      t ! R R]4      t ] ! R R]4      4       t!] ! R R4      4       t"R t#]#R R l4       t$ ! R R]PJ                  4      t& ! R R ]&4      t' ! R! R"]&4      t(R# t)R$ t* ! R% R&]PJ                  4      t+R# )'i    )annotationsN)	dataclass)IntEnumuniquewraps)AnyMappingSequence)x509)InvalidSignature)default_backend)ecpaddingrsa)AttestationObjectAuthenticatorDatac                  s    ] tR t^,tRtRtR# )InvalidAttestationz.Base exception for attestation-related errors. N__name__
__module____qualname____firstlineno____doc____static_attributes__r       ;/usr/lib/python3.14/site-packages/fido2/attestation/base.pyr   r   ,   s    8r   r   c                  s    ] tR t^0tRtRtR# )InvalidDataz"Attestation contains invalid data.r   Nr   r   r   r   r   r   0   s    ,r   r   c                  s    ] tR t^4tRtRtR# )r
   z7The signature of the attestation could not be verified.r   Nr   r   r   r   r
   r
   4   s    Ar   r
   c                  s    ] tR t^8tRtRtR# )UntrustedAttestationz)The CA of the attestation is not trusted.r   Nr   r   r   r   r   r   8   s    3r   r   c                  s0   a  ] tR t^<tRtRV 3R lltRtV ;t# )UnsupportedTypez(The attestation format is not supported.c                	sZ   < \         ST `  V'       d   R V R2MR4       Wn        W n        R# )zAttestation format "z" is not supportedz)This attestation format is not supported!N)super__init__	auth_datafmt)selfr!   r"   	__class__s   &&&r   r    ZUnsupportedType.__init__?   s1     #3%'9:<	

 #r   )r!   r"   N)r   r   r   r   r   r    r   __classcell__)r$   s   @r   r   r   <   s    2 r   r   c                  s.    ] tR t^ItRt^t^t^t^t^ t	Rt
R# )AttestationTypezSupported attestation types.r   N)r   r   r   r   r   ZBASICZSELFZATT_CAZANON_CANONEr   r   r   r   r'   r'   I   s    &EDFGDr   r'   c                  s0    ] tR t^Tt$ RtR]R&   R]R&   RtR# )AttestationResultz'The result of verifying an attestation.r'   Zattestation_typelist[bytes]
trust_pathr   N)r   r   r   r   r   Z__annotations__r   r   r   r   r)   r)   T   s    1%%r   r)   c                s0   a  \        S 4      V 3R l4       pV# )zDUtility decoractor to wrap common exceptions related to InvalidData.c                 sh   <  S! V / VB #   \         \        \        3 d   p\        T4      hR p?ii ; ir%   )
ValueErrorZKeyErrorZ
IndexErrorr   )argsZkwargsefs   *, r   innerZcatch_builtins.<locals>.inner_   s9    	!d%f%%Hj1 	!a. 	!s    1,1r   )r/   r0   s   f r   catch_builtinsr1   \   s"     1X! ! Lr   c                    V ^8  d   QhRRRR/# )   chainr*   returnNoner   Zformat   "r   __annotate__r9   j   s     % %[ %T %r   c                s   V  Uu. uF"  p\         P                  ! V\        4       4      NK$  	  ppVP                  ^ 4      pV'       Ed   TpVP                  ^ 4      pVP	                  4       p \        V\        P                  4      '       dX   VP                  f   Q hVP                  VP                  VP                  \        P                  ! 4       VP                  4       K  \        V\        P                  4      '       dY   VP                  f   Q hVP                  VP                  VP                  \        P                   ! VP                  4      4       EK  \#        R4      hR# u upi   \$         d    \'        4       hi ; i)zVerifies a chain of certificates.

Checks that the first item in the chain is signed by the next, and so on.
The first item is the leaf, the last is the root.
NzUnsupported signature key type)r	   Zload_der_x509_certificater   ZpopZ
public_keyZ
isinstancer   ZRSAPublicKeyZsignature_hash_algorithmverifyZ	signatureZtbs_certificate_bytesr   ZPKCS1v15r   ZEllipticCurvePublicKeyZECDSAr,   _InvalidSignaturer
   )r4   ZderZcertscertZchildZpubs   &     r   verify_x509_chainr=   i   s=    PUUuT++C1BCuEU99Q<D
%yy|oo	%#s//0055AAA

OO//$$&22	 C!:!:;;55AAA

OO//HHU;;< !!ABB+  V0 ! 	%"$$	%s   (E)-A5E. $A5E. E. .Fc                  sZ    ] tR t^tRt]P                  R R l4       t]R R l4       t	Rt
R# )Attestationz7Implements verification of a specific attestation type.c               s(    V ^8  d   QhRRRRRRRR/# )	r3   	statementzMapping[str, Any]r!   r   client_data_hashbytesr5   r)   r   r7   r8   r   r9   Attestation.__annotate__   s2     	 	$	 %	  		
 
	r   c                s    R# )zNVerifies attestation statement.

:return: An AttestationResult if successful.
Nr   r#   r?   r!   r@      &&&&r   r:   ZAttestation.verify   s    r   c               r2   )r3   r"   Zstrr5   ztype[Attestation]r   r7   r8   r   r9   rB      s     
+ 
+c 
+/ 
+r   c                s   a  \         P                  4        F  p\        VRR4      S 8X  g   K  Vu # 	   ! V 3R lR\        4      pV# )z6Get an Attestation subclass type for the given format.FORMATNc                  s,   <a  ] tR t^tV V3R ltRtV ;t# )9Attestation.for_type.<locals>.TypedUnsupportedAttestationc                	s&   < \         SV `  S4       R # r%   )r   r    )r#   r$   r"   s   &r   r    ZBAttestation.for_type.<locals>.TypedUnsupportedAttestation.__init__   s     %r   r   )r   r   r   r   r    r   r&   )r$   r"   s   @r   TypedUnsupportedAttestationrF      s    & &r   rG   )r>   __subclasses__getattrUnsupportedAttestation)r"   clsrG   s   f  r   for_typeZAttestation.for_type   sC     --/CsHd+s2
 0	&*@ 	& +*r   r   N)r   r   r   r   r   abcabstractmethodr:   ZstaticmethodrL   r   r   r   r   r>   r>      s1    A	 	 
+ 
+r   r>   c                  s&    ] tR t^tRR ltR tRtR# )rJ   Nc                	s    Wn         R # r%   r"   )r#   r"      &&r   r    ZUnsupportedAttestation.__init__   s    r   c                	s,    \        W P                  4      hr%   )r   r"   rC   rD   r   r:   ZUnsupportedAttestation.verify   s    i22r   rO   r%   )r   r   r   r   r    r:   r   r   r   r   rJ   rJ      s    3r   rJ   c                  s     ] tR t^tRtR tRtR# )NoneAttestationnonec                	sZ    V/ 8w  d   \        R 4      h\        \        P                  . 4      # )z*None Attestation requires empty statement.)r   r)   r'   r(   rC   rD   r   r:   ZNoneAttestation.verify   s(    ?JKK !5!5r::r   r   N)r   r   r   r   rE   r:   r   r   r   r   rQ   rQ      s    F;r   rQ   c                sX   V P                   \        P                  P                  8w  d   \	        R 4      h V P
                  P                  \        P                  4      pVP                  P                  '       d   \	        R4      hR#   \        P                   d    \	        R4      hi ; i)z+Attestation certificate must use version 3!z+Attestation certificate must have CA=false!z4Attestation certificate must have Basic Constraints!N)Zversionr	   ZVersionZv3r   Z
extensionsZget_extension_for_classZBasicConstraintsZvaluecaZExtensionNotFound)r<   Zbcs   & r   _validate_cert_commonrT      s    ||t||&GHHR__44T5J5JK88;;;KLL !! RPQQRs   AB ;B !B)c                 s    \         P                  4        U u. uF  p \        V R R4      R8w  g   K  V ! 4       NK   	  up # u up i )rE   rR   )r>   rH   rI   )rK   s    r   _default_attestationsrU      sG     --//C3&)V3 	/  s   >>c                  sf    ] tR t^tRtRR R llt]P                  R R l4       tR R lt	R	 t
R
tR# )AttestationVerifierzBase class for verifying attestation.

Override the ca_lookup method to provide a trusted root certificate used
to verify the trust path from the attestation.
Nc               s    V ^8  d   QhRR/# )r3   attestation_typeszSequence[Attestation] | Noner   r7   r8   r   r9    AttestationVerifier.__annotate__   s     O O*F Or   c                	s8    T;'       g    \        4       V n        R # r%   )rU   _attestation_types)r#   rW   rP   r   r    ZAttestationVerifier.__init__   s    "3"N"N7L7Nr   c               $    V ^8  d   QhRRRRRR/# )r3   attestation_resultr)   r!   r   r5   zbytes | Noner   r7   r8   r   r9   rX      s$     $ $"3$@Q$	$r   c                s    \        4       h)zLookup a CA certificate to be used to verify a trust path.

:param attestation_result: The result of the attestation
:param auth_data: The AuthenticatorData from the registration
)ZNotImplementedError)r#   r[   r!   s   &&&r   	ca_lookupZAttestationVerifier.ca_lookup   s     "##r   c               rZ   )r3   attestation_objectr   r@   rA   r5   r6   r   r7   r8   r   r9   rX      s$     * *"3*GL*	*r   c                s   \        VP                  4      pV P                   F#  p\        VRR4      VP                  8X  g   K!  Tp M	  VP	                  VP
                  VP                  V4      pV P                  WQP                  4      pV'       g   \        R4      h \        VP                  V.,           4       R#   \         d   p\        T4      hRp?ii ; i)zVerify attestation.

:param attestation_object: dict containing attestation data.
:param client_data_hash: SHA256 hash of the ClientData bytes.
rE   NzNo root found for Authenticator)rJ   r"   rY   rI   r:   Zatt_stmtr!   r\   r   r=   r+   r
   )r#   r]   r@   Zatt_verifierZatZresultrS   r.   s   &&&     r   verify_attestationZ&AttestationVerifier.verify_attestation   s     %;;M;Q;Q$R))Br8T*.@.D.DD! * $$''((
 ^^F$@$@A&'HII	*f//2$67 	*&q))	*s   B> >C	CCc                s&    V P                   ! V!   R# )z?Allows passing an instance to Fido2Server as verify_attestationN)r^   )r#   r-   s   &*r   __call__ZAttestationVerifier.__call__  s    &r   )rY   r%   )r   r   r   r   r   r    rM   rN   r\   r^   r_   r   r   r   r   rV   rV      s2    O 	$ $*B'r   rV   ),Z
__future__r    rM   Zdataclassesr   Zenumr   r   Z	functoolsr   Ztypingr   r   r   Zcryptographyr	   Zcryptography.exceptionsr
   r;   Zcryptography.hazmat.backendsr   Z)cryptography.hazmat.primitives.asymmetricr   r   r   Zwebauthnr   r   Z	Exceptionr   r   r   r   r'   r)   r1   r=   ZABCr>   rJ   rQ   rT   rU   rV   r   r   r   <module>r`      s  8 # 
 !    ) )  I 8 F F ;9 9-$ -B) B4- 4
( 
 g     
 % %D+#'' +:3[ 3;k ;	R8'#'' 8'r   