+
     h<  c                  s   ^ RI Ht ^ RIt^ RIt^ RIt^ RIHt ^ RIHtH	t	H
t
 ^ RIHt ^ RIHtHtHtHt ^ RIHt ^ RIHt ^ R	IHt ^ R
IHtHtHt ^ RIHt ^RIHt ^RI H!t!H"t"H#t#H$t$ ^RI%H&t& ]PN                  ! ](4      t)R R lt* ! R R]PV                  4      t,] ! R R4      4       t- ! R R],4      t. ! R R].4      t/ ! R R4      t0R# )i    )annotationsN)	dataclass)IntEnumIntFlagunique)Event)AnyCallableClassVarMapping)default_backend)hashes)ec)Cipher
algorithmsmodes)HKDF)CoseKey)	bytes2inthmac_sha256	int2bytessha256)Ctap2c                    V ^8  d   QhRRRR/# )   pinstrreturnbytes Zformat   "4/usr/lib/python3.14/site-packages/fido2/ctap2/pin.py__annotate__r!   3   s     	 	# 	% 	    c                sR   \        V \        4      '       g   \        R \         24      h\        V 4      ^8  d   \        R4      hV P	                  4       P                  ^@R4      pVR\        V4      ^,
          ) ^,          ,          ,          p\        V4      ^8  d   \        R4      hV# )zPIN of wrong type, expecting zPIN must be >= 4 characterss    zPIN must be <= 255 bytes)Z
isinstancer   
ValueErrorlenencodeZljust)r   Z
pin_padded   & r    _pad_pinr'   3   s    c38>??
3x!|677##B.J%S_r12R788J
:344r"   c                  s    ] tR t^?t$ R]R&   ]P                  R R l4       t]P                  R R l4       t]P                  R R l4       t	]P                  R	 R
 l4       t
]P                  R R l4       tRtR# )PinProtocolzClassVar[int]VERSIONc               r   )r   peer_cose_keyr   r   ztuple[Mapping[int, Any], bytes]r   r   r   r    r!   PinProtocol.__annotate__C   s       5T r"   c                    R# )zeGenerates an encapsulation of the public key.
Returns the message to transmit and the shared secret.
Nr   )selfr*      &&r    encapsulateZPinProtocol.encapsulateB       r"   c               $    V ^8  d   QhRRRRRR/# )r   keyr   	plaintextr   r   r   r   r    r!   r+   I   s!      5 U u r"   c                r,   )zEncrypts dataNr   )r-   r2   r3      &&&r    encryptZPinProtocol.encryptH   r0   r"   c               r1   )r   r2   r   
ciphertextr   r   r   r   r    r!   r+   M   s!     & &5 &e & &r"   c                r,   )zDecrypts encrypted dataNr   )r-   r2   r6   r4   r    decryptZPinProtocol.decryptL   r0   r"   c               r1   )r   r2   r   messager   r   r   r   r    r!   r+   Q   s!     3 3 3 3% 3r"   c                r,   )z$Computes a MAC of the given message.Nr   r-   r2   r8   r4   r    authenticateZPinProtocol.authenticateP   r0   r"   c                    V ^8  d   QhRRRR/# )r   tokenr   r   r   r   r   r    r!   r+   U   s      E e r"   c                r,   )z^Validates that a token is well-formed.
Returns the token, or if invalid, raises a ValueError.
Nr   r-   r<   r.   r    validate_tokenZPinProtocol.validate_tokenT   r0   r"   r   N)__name__
__module____qualname____firstlineno____annotations__abcZabstractmethodr/   r5   r7   r:   r>   __static_attributes__r   r"   r    r(   r(   ?   s     
 	  	& & 	3 3 	 r"   r(   c                  s,    ] tR t^[t$ R]R&   R]R&   RtR# )_PinUvr(   protocolr   r<   r   N)r?   r@   rA   rB   rC   rE   r   r"   r    rF   rF   [   s    Lr"   rF   c                  sR    ] tR t^atRt^tRtR R ltR tR t	R t
R tR tR	 tR
tR# )PinProtocolV1zImplementation of the CTAP2 PIN/UV protocol v1.

:param ctap: An instance of a CTAP2 object.
:cvar VERSION: The version number of the PIV/UV protocol.
:cvar IV: An all-zero IV used for some cryptographic operations.
c               r;   )r   zr   r   r   r   r   r    r!   ZPinProtocolV1.__annotate__l   s      U u r"   c                	s    \        V4      # N)r   )r-   rI   r.   r    kdfZPinProtocolV1.kdfl   s    ayr"   c                	s6   \        4       p\        P                  ! \        P                  ! 4       V4      pVP	                  4       P                  4       p^^^RR^R\        VP                  ^ 4      R\        VP                  ^ 4      /p\        VR,          4      p\        VR,          4      p\        P                  ! Wg\        P                  ! 4       4      P	                  V4      pV P                  VP                  \        P                  ! 4       V4      4      p	WY3# )i   iiii)r
   r   Zgenerate_private_keyZ	SECP256R1Z
public_keyZpublic_numbersr   xyr   ZEllipticCurvePublicNumbersrK   ZexchangeZECDH)
r-   r*   beZskZpnkey_agreementrL   rM   pkshared_secrets
   &&        r    r/   ZPinProtocolV1.encapsulateo   s    $$R\\^R8]]_++-qs	"$$#	"$$#
 mB'(mB'(**1@KKBORWWY!;<++r"   c                	s    \        4       p\        \        P                  ! V4      \        P
                  ! \        P                  4      V4      # rJ   )r
   r   r   AESr   CBCrH   IV)r-   secretrN   s   && r    _get_cipher_v1ZPinProtocolV1._get_cipher_v1   s1    jnnV,eii8H8H.I2NNr"   c                	    V P                  V4      pVP                  4       pVP                  V4      VP                  4       ,           # rJ   )rV   	encryptorupdatefinalize)r-   r2   r3   cipherenc   &&&  r    r5   ZPinProtocolV1.encrypt   s:    $$S) zz)$s||~55r"   c                	rW   rJ   )rV   	decryptorrY   rZ   )r-   r2   r6   r[   decr]   r    r7   ZPinProtocolV1.decrypt   s:    $$S) zz*%66r"   c                	s&    \        W4      R ,          # )N   Nr   r9   r4   r    r:   ZPinProtocolV1.authenticate   s    3(--r"   c                	s<    \        V4      R9  d   \        R4      hV# )ra   z#PIN/UV token must be 16 or 32 bytes)ra       r$   r#   r=   r.   r    r>   ZPinProtocolV1.validate_token   s    u:X%BCCr"   r   Ns                   )r?   r@   rA   rB   __doc__r)   rT   rK   r/   rV   r5   r7   r:   r>   rE   r   r"   r    rH   rH   a   s7     G	B,$O6
7
.r"   rH   c                  sN    ] tR t^tRt^tRtRtRtR t	R t
R tR tR tR	 tR
tR# )PinProtocolV2zImplementation of the CTAP2 PIN/UV protocol v2.

:param ctap: An instance of a CTAP2 object.
:cvar VERSION: The version number of the PIV/UV protocol.
:cvar IV: An all-zero IV used for some cryptographic operations.
s   CTAP2 HMAC keys   CTAP2 AES keyc                	s^   \        4       p\        \        P                  ! 4       ^ \        P
                  \        P                  VR7      P                  V4      p\        \        P                  ! 4       ^ \        P
                  \        P                  VR7      P                  V4      pW4,           # )rc   )Z	algorithmZlengthZsaltinfoZbackend)	r
   r   r   ZSHA256rf   	HKDF_SALTHKDF_INFO_HMACZderiveHKDF_INFO_AES)r-   rI   rN   hmac_keyaes_keys   &&   r    rK   ZPinProtocolV2.kdf   s    mmo((--
 &) 	 mmo((,,
 &) 	 !!r"   c                	s    \        4       p\        \        P                  ! V4      \        P
                  ! V4      V4      # rJ   )r
   r   r   rR   r   rS   )r-   rU   ivrN      &&& r    _get_cipher_v2ZPinProtocolV2._get_cipher_v2   s*    jnnV,eiimR@@r"   c                	s    VR ,          p\         P                  ! ^4      pV P                  W44      pVP                  4       pWFP	                  V4      ,           VP                  4       ,           # )rc   NN)osZurandomro   rX   rY   rZ   )r-   r2   r3   rl   rm   r[   r\      &&&    r    r5   ZPinProtocolV2.encrypt   sS    c(ZZ^$$W1 JJy))CLLN::r"   c                	s    VR ,          pVR,          VR,          r$V P                  W44      pVP                  4       pVP                  V4      VP                  4       ,           # )rp   r`   :ra   NN)ro   r^   rY   rZ   )r-   r2   r6   rl   rm   r[   r_   rr   r    r7   ZPinProtocolV2.decrypt   sR    c(#C*S/J$$W1 zz*%66r"   c                	s*    VR ,          p\        W24      # ):Nrc   Nrb   )r-   r2   r8   rk   rn   r    r:   ZPinProtocolV2.authenticate   s    s88--r"   c                	s<    \        V4      ^ 8w  d   \        R4      hV# )rc   zPIN/UV token must be 32 bytesrd   r=   r.   r    r>   ZPinProtocolV2.validate_token   s    u:<==r"   r   Ns                                    )r?   r@   rA   rB   re   r)   rh   ri   rj   rK   ro   r5   r7   r:   r>   rE   r   r"   r    rf   rf      s<     GI&N$M"$A;7.r"   rf   c                  s   ] tR t^tRt]].t] ! R R]	4      4       t
] ! R R]	4      4       t] ! R R]4      4       t]R 4       t]R	 4       tRR R lltR tRR R lltRR R lltR R ltR R ltR R ltR R ltRtR
# )	ClientPina  Implementation of the CTAP2 Client PIN API.

:param ctap: An instance of a CTAP2 object.
:param protocol: An optional instance of a PinUvAuthProtocol object. If None is
    provided then the latest protocol supported by both library and Authenticator
    will be used.
c                  s6    ] tR t^t^t^t^t^t^t^t	^t
^	tRtR# )ClientPin.CMDr   N)r?   r@   rA   rB   GET_PIN_RETRIESGET_KEY_AGREEMENTSET_PIN
CHANGE_PINGET_TOKEN_USING_PIN_LEGACYGET_TOKEN_USING_UVGET_UV_RETRIESGET_TOKEN_USING_PINrE   r   r"   r    CMDrt      s.     
%)"!"r"   r}   c                  s*    ] tR t^t^t^t^t^t^tRt	R# )ClientPin.RESULTr   N)
r?   r@   rA   rB   KEY_AGREEMENTPIN_UV_TOKENPIN_RETRIESPOWER_CYCLE_STATE
UV_RETRIESrE   r   r"   r    RESULTr~      s     
r"   r   c                  s2    ] tR t^t^t^t^t^t^t^ t	^@t
RtR# )ClientPin.PERMISSIONr   N)r?   r@   rA   rB   ZMAKE_CREDENTIALZGET_ASSERTIONZCREDENTIAL_MGMTZ
BIO_ENROLLZLARGE_BLOB_WRITEZAUTHENTICATOR_CFGZPERSISTENT_CREDENTIAL_MGMTrE   r   r"   r    
PERMISSIONr      s(    
 %)"r"   r   c                s     RV P                   9   # )zChecks if ClientPin functionality is supported.

Note that the ClientPin function is still usable without support for client
PIN functionality, as UV token may still be supported.
Z	clientPin)optionsrg      &r    is_supportedZClientPin.is_supported   s     dll**r"   c                s<    V P                   P                  R4      RJ # )z&Checks if pinUvAuthToken is supported.ZpinUvAuthTokenT)r   getr   r   r    is_token_supportedZClientPin.is_token_supported  s     || 01T99r"   Nc               r   )r   ctapr   rG   zPinProtocol | Noner   r   r   r    r!   ClientPin.__annotate__
  s     
% 
%U 
%.@ 
%r"   c                	s    Wn         VfW   \        P                   F7  pVP                  VP                  P
                  9   g   K*  V! 4       V n         R # 	  \        R4      hW n        R # )Nz)No compatible PIN/UV protocols supported!)r   rs   	PROTOCOLSr)   rg   Zpin_uv_protocolsrG   r#   )r-   r   rG   Zprotorn   r    __init__ZClientPin.__init__
  sR    	",,==DII$>$>>16DM -
 !!LMM$Mr"   c                	s
   V P                   P                  V P                  P                  \        P
                  P                  4      pV\        P                  P                  ,          pV P                  P                  V4      # rJ   )
r   
client_pinrG   r)   rs   r}   rv   r   r   r/   )r-   resprP   s   &  r    _get_shared_secretZClientPin._get_shared_secret  s\    yy##MM!!9==#B#B
 )""001}}((,,r"   c               s(    V ^8  d   QhRRRRRRRR/# )	r   r   r   permissionsClientPin.PERMISSION | Nonepermissions_rpid
str | Noner   r   r   r   r   r    r!   r     s2     )
 )
)
 1)
 %	)

 
)
r"   c           	     s4   \         P                  V P                  P                  4      '       g   \	        R4      hV P                  4       w  rE\        VP                  4       4      R,          pV P                  P                  WV4      p\         P                  V P                  P                  4      '       d$   V'       d   \         P                  P                  pM\         P                  P                  pRpRpV P                  P                  V P                  P                  VVVVVR7      p	V	\         P                   P"                  ,          p
\$        P'                  RV 24       V P                  P)                  V P                  P+                  WZ4      4      # )a  Get a PIN/UV token from the authenticator using PIN.

:param pin: The PIN of the authenticator.
:param permissions: The permissions to associate with the token.
:param permissions_rpid: The permissions RPID to associate with the token.
:return: A PIN/UV token.
z,Authenticator does not support get_pin_tokenr`   N)rO   pin_hash_encr   r   zGot PIN token for permissions: )rs   r   r   rg   r#   r   r   r%   rG   r5   r   r}   r|   ry   r   r)   r   r   loggerdebugr>   r7   )r-   r   r   r   rO   rQ   pin_hashr   Zcmdr   pin_token_encs   &&&&       r    get_pin_tokenZClientPin.get_pin_token  s1    %%diinn55KLL'+'>'>'@$#**,',}},,]E''		77K--33C--::CK#yy##MM!!'%#- $ 
 Y--::;6{mDE}}++MM!!-?
 	
r"   c          
     s,    V ^8  d   QhRRRRRRRRR	R
/# )r   r   r   r   r   eventzEvent | Noneon_keepalivezCallable[[int], None] | Noner   r   r   r   r   r    r!   r   I  s<     %
 %
0%
 %%
 	%

 3%
 
%
r"   c           
     s   \         P                  V P                  P                  4      '       g   \	        R4      hV P                  4       w  rVV P                  P                  V P                  P                  \         P                  P                  VVVVVR7      pV\         P                  P                  ,          p\        P                  RV 24       V P                  P                  V P                  P!                  Wh4      4      # )a   Get a PIN/UV token from the authenticator using built-in UV.

:param permissions: The permissions to associate with the token.
:param permissions_rpid: The permissions RPID to associate with the token.
:param event: An optional threading.Event which can be used to cancel
    the invocation.
:param on_keepalive: An optional callback to handle keep-alive messages
    from the authenticator. The function is only called once for
    consecutive keep-alive messages with the same status.
:return: A PIN/UV token.
z+Authenticator does not support get_uv_token)rO   r   r   r   r   zGot UV token for permissions: )rs   r   r   rg   r#   r   r   rG   r)   r}   rz   r   r   r   r   r>   r7   )	r-   r   r   r   r   rO   rQ   r   r   s	   &&&&&    r    get_uv_tokenZClientPin.get_uv_tokenI  s    $ ++DIINN;;JKK'+'>'>'@$yy##MM!!MM,,'#-% $ 
 Y--::;5k]CD}}++MM!!-?
 	
r"   c                   V ^8  d   QhRR/# )r   r   ztuple[int, int | None]r   r   r   r    r!   r   p  s     
 
!7 
r"   c                s&   V P                   P                  V P                  P                  \        P
                  P                  4      pV\        P                  P                  ,          VP                  \        P                  P                  4      3# )zGet the number of PIN retries remaining.

:return: A tuple of the number of PIN attempts remaining until the
authenticator is locked, and the power cycle state, if available.
)r   r   rG   r)   rs   r}   ru   r   r   r   r   r-   r   r&   r    get_pin_retriesZClientPin.get_pin_retriesp  si     yy##MM!!9==#@#@
 !!--.HHY%%778
 	
r"   c               r   )r   r   Zintr   r   r   r    r!   r   ~  s     1 1 1r"   c                s    V P                   P                  V P                  P                  \        P
                  P                  4      pV\        P                  P                  ,          # )zGet the number of UV retries remaining.

:return: A tuple of the number of UV attempts remaining until the
authenticator is locked, and the power cycle state, if available.
)	r   r   rG   r)   rs   r}   r{   r   r   r   r&   r    get_uv_retriesZClientPin.get_uv_retries~  sE     yy##DMM$9$99==;W;WXI$$//00r"   c               r   )r   r   r   r   Noner   r   r   r    r!   r     s     ( (3 (4 (r"   c                s   \         P                  V P                  P                  4      '       g   \	        R4      hV P                  4       w  r#V P                  P                  V\        V4      4      pV P                  P                  W44      pV P                  P                  V P                  P                  \         P                  P                  VVVR7       \        P                  R4       R# )zSet the PIN of the autenticator.

This only works when no PIN is set. To change the PIN when set, use
change_pin.

:param pin: A PIN to set.
(Authenticator does not support ClientPin)rO   new_pin_encpin_uv_paramzPIN has been setN)rs   r   r   rg   r#   r   rG   r5   r'   r:   r   r)   r}   rw   r   )r-   r   rO   rQ   Zpin_encr   s   &&    r    set_pinZClientPin.set_pin  s     %%diinn55GHH'+'>'>'@$--''x}E}}11-I		MM!!MM!!'% 	 	
 	&'r"   c               s$    V ^8  d   QhRRRRRR/# )r   old_pinr   new_pinr   r   r   r   r   r    r!   r     s!     , ,# , , ,r"   c           	     sf   \         P                  V P                  P                  4      '       g   \	        R4      hV P                  4       w  r4\        VP                  4       4      R,          pV P                  P                  WE4      pV P                  P                  V\        V4      4      pV P                  P                  WGV,           4      pV P                  P                  V P                  P                  \         P                  P                  VVVVR7       \         P                  R4       R# )zChange the PIN of the authenticator.

This only works when a PIN is already set. If no PIN is set, use
set_pin.

:param old_pin: The currently set PIN.
:param new_pin: The new PIN to set.
r   r`   )rO   r   r   r   zPIN has been changedN)rs   r   r   rg   r#   r   r   r%   rG   r5   r'   r:   r   r)   r}   rx   r   )	r-   r   r   rO   rQ   r   r   r   r   s	   &&&      r    
change_pinZClientPin.change_pin  s     %%diinn55GHH'+'>'>'@$'..*+C0}},,]Emm++M8G;LM}}115
 			MM!!MM$$'%#% 	 	
 	*+r"   )r   rG   rJ   )NN)NNNN)r?   r@   rA   rB   re   rf   rH   r   r   r   r}   r   r   r   Zstaticmethodr   r   r   r   r   r   r   r   r   r   rE   r   r"   r    rs   rs      s     .I#g # #    *W * * + + : :
%-)
V%
N
1(0, ,r"   rs   )1Z
__future__r    rD   Zloggingrq   Zdataclassesr   Zenumr   r   r   Z	threadingr   Ztypingr   r   r   r	   Zcryptography.hazmat.backendsr
   Zcryptography.hazmat.primitivesr   Z)cryptography.hazmat.primitives.asymmetricr   Z&cryptography.hazmat.primitives.ciphersr   r   r   Z'cryptography.hazmat.primitives.kdf.hkdfr   Zcoser   Zutilsr   r   r   r   Zbaser   Z	getLoggerr?   r   r'   ZABCr(   rF   rH   rf   rs   r   r"   r    <module>r      s   8 # 
  	 ! ) )  3 3 8 1 8 L L 8  = = 			8	$	#'' 8   
4K 4n9M 9xg, g,r"   