+
    Gb]  c                   s*   ^ RI t ^ RIHt ^ RIHtHt ^ RIHtHt ^ RIHtH	t	 ^ RIH
t
Ht ^ RIHt ^ RIHt R	]! R
RRR4      R]! RRRR4      R]! RRRR4      R]! RRRR4      R]! RRRR4      R]! RRRR4      R]! RRRR4      R]! RRRR4      R]! RRRR4      R]! RRRR4      R]! R RRR4      R!]! R"RRR4      R#]! R$RRR4      /t . R)Ot  ! R% R&]4      t]P&                  t]P(                  t]P*                  t]P,                  t ! R' R(4      tR# )*i    N)common)JWExceptionJWKeyNotFound)JWSEHeaderParameterJWSEHeaderRegistry)base64url_decodebase64url_encode)json_decodejson_encode)JWA)JWKSetalgZ	AlgorithmFTenczEncryption AlgorithmzipzCompression AlgorithmZjkuzJWK Set URLZjwkzJSON Web KeykidzKey IDZx5uz	X.509 URLZx5czX.509 Certificate ChainZx5tz"X.509 Certificate SHA-1 Thumbprintzx5t#S256z$X.509 Certificate SHA-256 ThumbprintZtypZTypeZctyzContent TypecritZCriticalc                   s:   a a ] tR t^1t oRtRV 3R lltRtVtV ;t# )InvalidJWEDatazjInvalid JWE Object.

This exception is raised when the JWE Object is invalid and/or
improperly formatted.
c                s   < R pV'       d   TpMRpV'       d   VR\        V4      ,          ,          p\        \        V `  V4       R # )Nz!Unknown Data Verification Failurez {%s})ZstrZsuperr   __init__)selfZmessageZ	exceptionZmsg	__class__s   &&& 1/usr/lib/python3.14/site-packages/jwcrypto/jwe.pyr   ZInvalidJWEData.__init__8   s:    C5C7S^++Cnd,S1     )NN)	__name__
__module____qualname____firstlineno____doc__r   __static_attributes____classdictcell__Z__classcell__)r   __classdict__s   @@r   r   r   1   s     2 2r   r   c                   s  a  ] tR t^Jt o RtRR ltR tR t]R 4       t	]	P                  R 4       t	R tRR	 ltR
 tR tRR ltRR ltR tR tR tR tRR lt]R 4       t]R 4       t]R 4       tR tR tR tRtV tR# )JWEz?JSON Web Encryption object

This object represent a JWE token.
Nc	                s   RV n         / V n        RV n        \        \        4      V n        V'       d   V P
                  P                  V4       Ve4   \        V\        4      '       d   Wn        MVP                  R4      V n        RV n
        RV n        V'       d   W@P                  R&   V'       d<   \        V\        4      '       d   \        V4      pM\        V4       W P                  R&   V'       d<   \        V\        4      '       d   \        V4      pM\        V4       W0P                  R&   V'       d   WPn         V'       d   V P                  WgR7       R# V'       d   \!        R4      hR# )a  Creates a JWE token.

:param plaintext(bytes): An arbitrary plaintext to be encrypted.
:param protected: A JSON string with the protected header.
:param unprotected: A JSON string with the shared unprotected header.
:param aad(bytes): Arbitrary additional authenticated data
:param algs: An optional list of allowed algorithms
:param recipient: An optional, default recipient key
:param header: An optional header for the default recipient
:param header_registry: Optional additions to the header registry
Nutf-8aad	protectedunprotected)headerz-Header is allowed only with default recipient)_allowed_algsobjects	plaintextr   JWEHeaderRegistryheader_registryupdate
isinstancebytesencodecek
decryptlogdictr   r   add_recipient
ValueError)	r   r'   r"   r#   r!   algsZ	recipientr$   r)   s	   &&&&&&&&&r   r   ZJWE.__init__P   s    "12CD  ''8 )U++!*!*!1!1'!:"%LL)T**'	2	I&(1LL%+t,,)+6K(*5LL'!%y8LMM r   c                    V P                   ;'       g    \        pW9  d   \        R 4      h\        P                  ! V4      # zAlgorithm not allowed)r%   default_allowed_algsInvalidJWEOperationr	   Zkeymgmt_algr   ZnameZallowed   && r   _jwa_keymgmtZJWE._jwa_keymgmt   s7    $$<<(<%&=>>t$$r   c                r4   r5   )r%   r6   r7   r	   Zencryption_algr8   r9   r   _jwa_encZJWE._jwa_enc   s9    $$<<(<%&=>>!!$''r   c                sJ    V P                   '       d   V P                   # \        # )zjAllowed algorithms.

The list of allowed algorithms.
Can be changed by setting a list of algorithm names.
)r%   r6   r      &r   allowed_algsJWE.allowed_algs   s"     %%%''r   c                sT    \        V\        4      '       g   \        R 4      hWn        R# )zAllowed Algs must be a listN)r+   listZ	TypeErrorr%   )r   r3   s   &&r   r>   r?      s!    $%%9::!r   c                s    \        VP                  4       4       F  pW29   g   K  \        R V,          4      h	  VP                  V4       V# )zDuplicate header: "%s")r@   keysr   r*   )r   Zh1Zh2ks   &&& r   _merge_headersZJWE._merge_headers   s>    bggiAw$%=%ABB ! 			"	r   c                sJ   / pR V P                   9   d.   \        V P                   R ,          4      pV P                  W#4      pRV P                   9   d.   \        V P                   R,          4      pV P                  W$4      pV'       d   \        V4      pV P                  W%4      pV# )r"   r#   )r&   r   rC   )r   r$   jhphZuhZrh   &&    r   _get_jose_headerZJWE._get_jose_header   s    $,,&T\\+67B$$R,BDLL(T\\-89B$$R,BV$B$$R,B	r   c                s    VP                  R R4      pVf   \        R4      hV P                  V4      pVP                  RR4      pVf   \        R4      hV P                  V4      pW53# )r   NzMissing "alg" from headersr   zMissing "enc" from headers)getr   r:   r;   )r   rD   Zalgnamer   Zencnamer   rF   r   _get_alg_enc_from_headersZJWE._get_alg_enc_from_headers   si    &&%? !=>>(&&%? !=>>mmG$xr   c                s,   \        V P                  P                  R R4      4      pRV P                  9   d+   VR\        V P                  R,          4      ,           ,          pVP                  R4      pVP                  RR4      pVR8X  d%   \        P
                  ! V P                  4      ^R pMVf   V P                  pM\        R4      hVP                  V P                  WF4      w  rxp	WpP                  R	&   WP                  R
&   WP                  R&   R# )r"    r!   .r    r   NDEFUnknown compressioniv
ciphertexttagi)
r   r&   rH   r-   zlibcompressr'   r2   Zencryptr.   )
r   r   r   rD   r!   rR   datarN   rO   rP   s
   &&&&      r   _encryptZJWE._encrypt   s    t||//R@ADLL 3)$,,u*=>>>Cjj!66%&u==026D>>D233!kk$((C>T%/\"!Ur   c                s   V P                   f   \        R4      h\        V P                   \        4      '       g   \        R4      h\        V\        4      '       d   \        V4      pV P                  V4      pV P                  V4      w  rE/ pV'       d   W&R&   VP                  WP                  V P                  V4      pVR,          V n
        RV9   d   VR,          VR&   RV9   dB   \        VP                  RR4      4      pV P                  WR,          4      p	\        V	4      VR&   R	V P                  9  d   V P                  WEV4       R
V P                  9   d%   V P                  R
,          P!                  V4       R# RV P                  9   g   RV P                  9   d   . V P                  R
&   / p
RV P                  9   d   V P                  P#                  R4      V
R&   RV P                  9   d   V P                  P#                  R4      V
R&   V P                  R
,          P!                  V
4       V P                  R
,          P!                  V4       R# V P                  P%                  V4       R# )a  Encrypt the plaintext with the given key.

:param key: A JWK key or password of appropriate type for the 'alg'
 provided in the JOSE Headers.
:param header: A JSON string representing the per-recipient header.

:raises ValueError: if the plaintext is missing or not of type bytes.
:raises ValueError: if the compression type is unknown.
:raises InvalidJWAAlgorithm: if the 'alg' provided in the JOSE
 headers is missing or unknown, or otherwise not implemented.
NzMissing plaintextzPlaintext must be 'bytes'r$   r.   Zekencrypted_keyz{}rO   
recipients)r'   r2   r+   r,   r0   r   rG   rI   Zwrapwrap_key_sizer.   r   rH   rC   r&   rT   appendZpopr*   )r   keyr$   rD   r   r   recZwrappedhZnhZns   &&&        r   r1   ZJWE.add_recipient   s    >>!011$..%00899fd## (F""6*11"5"M((3 1 1488R@5>7?#*4=C wCGGHd34A$$Q(9:B'OCMt||+MM#B'4<<'LL&--c2,DLL0H)+DLL&A$,,.%)\\%5%5o%F/"4<<'"ll..x8(LL&--a0LL&--c2LL$r   c           
     s   RV P                   9  d   \        R4      hV'       Ed   R F%  pW P                   9   g   K  \        RV,          4      h	  RV P                   9  d   \        R4      h\        V P                   R,          4      pR F  pWC9  g   K  \        RV,          4      h	  R	V P                   9   dH   \        V P                   R	,          4      ^8w  d   \        R
4      hV P                   R	,          ^ ,          pMV P                   pRV9   d   \        VR,          4      p\        V P                   R,          4      pV P	                  Wc4      p\        V4      V P                   R&   V P                  4       pV P                  V4      w  rV P                  WV4       VR RP                  \        V P                   R,          4      \        VP                  RR4      4      \        V P                   R,          4      \        V P                   R,          4      \        V P                   R,          4      .4      # V P                   pR\        VR,          4      R\        VR,          4      R\        V P                   R,          4      /p
RV9   d   \        VR,          4      V
R&   RV9   d   \        VR,          4      V
R&   RV9   d   \        VR,          4      V
R&   R	V9   di   . V
R	&   VR	,           FU  p/ pRV9   d   \        VR,          4      VR&   RV9   d   \        VR,          4      VR&   V
R	,          P                  V4       KW  	  M8RV9   d   \        VR,          4      V
R&   RV9   d   \        VR,          4      V
R&   \        V
4      # )a  Serializes the object into a JWE token.

:param compact(boolean): if True generates the compact
 representation, otherwise generates a standard JSON format.

:raises InvalidJWEOperation: if the object cannot be serialized
 with the compact representation and `compact` is True.
:raises InvalidJWEOperation: if no recipients have been added
 to the object.

:return: A json formatted string or a compact representation string
:rtype: `str`
rO   No available ciphertextr!   r#   z9Can't use compact encoding when the '%s' parameter is setr"   z4Can't use compact encoding without protected headersz@Can't use compact encoding, '%s' must be in the protected headerrV   zInvalid number of recipientsr$   rK   rU   rJ   rN   rP   )r!   r#   )r   r   )r&   r7   r   lenrC   r   rG   rI   rT   Zjoinr   rH   rX   )r   ZcompactZinvalidrE   ZrequiredrZ   r[   ZnphrD   r   r   objes   &&           r   	serializeZJWE.serialize	  s>    t||+%&?@@7/ll*-!#*+, , 0
 $,,.)JL L !k!:; ,H)1/19:; ; !-
 t||+t||L12a7-.LMMll<03ll3
  H. k!:;))!0,7,<[)**,99"=c+M88-dll;.GH-cggor.JK-dll4.@A-dll<.HI-dll5.AB	D E E ,,C!1#l2C!D)#d)4*4<<+>?AC c!#3C4D#EK #%0]1C%DM"|-c%j9E
s"$&L!|,,CA&#-,S-AB /*3&1#h-&@(%,,Q/ - #c)(_)=> (s?$/H$>CMs##r   c                s    V FZ  pW P                   9  d   \        R V,          4      hV P                   V,          P                  '       d   KJ  \        RV,          4      h	  R# )zUnknown critical header: "%s"z!Unsupported critical header: "%s"N)r)   r   Z	supported)r   r   rB   r9   r   _check_critZJWE._check_crita  sZ    A,,,$%Dq%HII++A.888( *023*4 5 5 r   c
                s    VP                  W2P                  WE4      p
VP                  WWxV	4      pV P                  P	                  R 4       Wn        V# )Success)ZunwraprW   decryptr/   rX   r.   )r   r   r   rY   Zenckeyr$   r!   rN   rO   rP   r.   rS   s   &&&&&&&&&&  r   _unwrap_decryptZJWE._unwrap_decryptj  sF    jj//@{{3RS9y)r   c                s    V P                  VP                  R R4      4      pV P                  VP                  R/ 4      4       V FA  pW@P                  9   g   K  V P                  P	                  W@4      '       d   K8  \        R4      h	  V P                  VP                  RR4      4      pV P                  VP                  RR4      4      p\        V P                  P                  RR4      4      pRV P                  9   d+   VR	\        V P                  R,          4      ,           ,          pVP                  R
4      p\        V\        4      '       Ed   TpRV P                  9   dX   VP                  V P                  R,          4      p	V	'       g,   \        RP!                  V P                  R,          4      4      hT	pV Fy  p
 V P#                  WVV
VP                  RR4      W7V P                  R,          V P                  R,          V P                  R,          4	      pV P$                  P'                  R4        M	  RV P$                  9  d   \        R4      hMZV P#                  WVVVP                  RR4      W7V P                  R,          V P                  R,          V P                  R,          4	      pVP                  RR4      pVR8X  d.   \.        P0                  ! X\.        P2                  ) 4      V n        R# Vf
   XV n        R# \7        R4      h  \(         da   pT
P                  RT
P+                  4       4      pT P$                  P'                  RP!                  T\-        T4      4      4        Rp?EK  Rp?ii ; i)r$   Nr   zFailed header checkr   r   r"   rJ   r!   rK   r    r   zKey ID {} not in key setrU   r   rN   rO   rP   rb   zKey [{}] failed: [{}]zNo working key found in key setr   rL   rM   )rG   rH   ra   r)   Zcheck_headerr   r:   r;   r   r&   r-   r+   r
   jose_headerZget_keysr   Zformatrd   r/   rX   	ExceptionZ
thumbprintreprrQ   Z
decompressZ	MAX_WBITSr'   r2   )r   rY   ZpperD   Zhdrr   r   r!   rA   Zkid_keysrB   rS   r_   ZkeyidrR   s   &&&            r   _decryptZJWE._decrypts  s   ""3778T#:; 	+,C***++88CC()>?? 
 ud 34mmBFF5$/0t||//R@ADLL 3)$,,u*=>>>Cjj!c6""D(((<<(8(8(?@'(B(I(I(,(8(8(?)A B B<//!030M02d9K04\0J04U0C	ED
 OO**95  /#$EFF 0 ''#(+(E(*d1C(,\(B(,U(;	=D 66%&u!__TDNN?CDN!DN233) ! <EE%8EOO**+B+I+I+0$q',; < <<s   A5LM=AM88M=c                s   RV P                   9  d   \        R4      h. V n        RpRV P                   9   d.   V P                   R,           F  p V P                  W4       K  	  M V P                  WP                   4       V P                  '       g9   V'       d   \        R4      h\        R	\        V P                  4      ,           4      hR#   \         dO   p\        T\        4      '       d   RpT P                  P                  R\        T4      ,          4        Rp?K  Rp?ii ; i  \         dN   p\        T\        4      '       d   RpT P                  P                  R\        T4      ,          4        Rp?LRp?ii ; i)
a  Decrypt a JWE token.

:param key: The (:class:`jwcrypto.jwk.JWK`) decryption key.
:param key: A (:class:`jwcrypto.jwk.JWK`) decryption key,
 or a (:class:`jwcrypto.jwk.JWKSet`) that contains a key indexed
 by the 'kid' header or (deprecated) a string containing a password.

:raises InvalidJWEOperation: if the key is not a JWK object.
:raises InvalidJWEData: if the ciphertext can't be decrypted or
 the object is otherwise malformed.
:raises JWKeyNotFound: if key is a JWKSet and the key is not found.
rO   r\   FrV   TzFailed: [%s]NzKey Not found in JWKSetz%No recipient matched the provided key)r&   r7   r/   rh   rf   r+   r   rX   rg   r'   r   )r   rY   Z
missingkeyrZ   r_   s   &&   r   rc   ZJWE.decrypt  s=    t||+%&?@@
4<<'||L11EMM#+ 2Ac<<0 ~~~#$=>>  "')-doo)>"? @ @  ! E!!]33%)
OO**>DG+CDDE  Aa//!%J&&~Q'?@@As2   C%D( D%AD  D%(F 3AE;;F c                s&   / V n         RV n        RV n        / p  \        V4      p\	        VR,          4      VR&   \	        VR,          4      VR&   \	        VR,          4      VR&   RV9   d'   \	        VR,          4      pVP                  R4      VR&   RV9   d   \        VR,          4      VR&   RV9   d   \	        VR,          4      VR&   R	V9   di   . VR	&   VR	,           FU  p/ pR
V9   d   \	        VR
,          4      VR
&   RV9   d   \        VR,          4      VR&   VR	,          P                  V4       KW  	  M8R
V9   d   \	        VR
,          4      VR
&   RV9   d   \        VR,          4      VR&   W0n         T'       d   T P                  T4       R# R#   \         d   pTP                  R4      p\        T4      ^8w  d   \        4       Th\	        T^ ,          4      pTP                  R4      TR&   \	        T^,          4      p	T	R8w  d   \	        T^,          4      TR
&   \	        T^,          4      TR&   \	        T^,          4      TR&   \	        T^,          4      TR&    Rp?LRp?ii ; i  \         d   p\        R\        T4      4      ThRp?ii ; i)ad  Deserialize a JWE token.

NOTE: Destroys any current status and tries to import the raw
JWE provided.

If a key is provided a decryption step will be attempted after
the object is successfully deserialized.

:param raw_jwe: a 'raw' JWE token (JSON Encoded or Compact
 notation) string.
:param key: A (:class:`jwcrypto.jwk.JWK`) decryption key,
 or a (:class:`jwcrypto.jwk.JWKSet`) that contains a key indexed
 by the 'kid' header or (deprecated) a string containing a password
 (optional).

:raises InvalidJWEData: if the raw object is an invalid JWE token.
:raises InvalidJWEOperation: if the decryption fails.
NrN   rO   rP   r"   r    r#   r!   rV   rU   r$   rK   r   zInvalid format)r&   r'   r.   r   r   Zdecoder   rX   r2   Zsplitr]   r   rf   rg   rc   )
r   Zraw_jwerY   ZoZdjweZprZ   r_   ZcZekeys
   &&&       r   deserializeZJWE.deserialize  sm   ( .	C(2"7+*4:6$"243E"F,+DK8%$&(k):;A%&XXg%6AkN D('243F'GAm$D=/U<AeH4'&(AlO#L11*c1 0_1E F o.#s?*5c(m*DAhK,..q1  2 '$.,T/-BC /*4'&1$x.&A( L
 LL %  2MM#&q6Q;(*1$QqT*!"'!2+'!-3;)9!A$)?Ao&*1Q40$"21Q4"8,+AaD1%2  	C !147;B	CsI   DF 7I* 88F 0I* I'B?I"I* "I''I* *J5JJc                sT    V P                   '       g   \        R 4      hV P                   # )zPlaintext not available)r'   r7   r<   r=   r   payloadZJWE.payload$  s!    ~~~%&?@@~~r   c                s    V P                  V P                  P                  R 4      4      p\        V4      ^ 8X  d   \	        R4      hV# )r$   zJOSE Header not available)rG   r&   rH   r]   r7   )r   rD   s   & r   re   ZJWE.jose_header*  s=    ""4<<#3#3H#=>r7a<%&ABB	r   c                s6    V ! 4       pVP                  V4       V# )zCreates a JWE object from a serialized JWE token.

:param token: A string with the json or compat representation
 of the token.

:raises InvalidJWEData: if the raw object is an invalid JWE token.

:return: A JWE token
:rtype: JWE
)ri   )ZclsZtokenr^   r9   r   from_jose_tokenZJWE.from_jose_token1  s     e
r   c                sD   \        V\        4      '       g   R #  V P                  4       VP                  4       8H  #   \         dZ    RT P                  /pTP                  T P                  4       RTP                  /pTP                  TP                  4       Y#8H  u # i ; i)Fr'   )r+   r   r`   rf   r'   r*   r&   )r   ZotherZaZbs   &&  r   __eq__Z
JWE.__eq__B  s    %%%	>>#u'888 	dnn-AHHT\\"eoo.AHHU]]#6M	s    ; A!BBc                sf     V P                  4       #   \         d    T P                  4       u # i ; iN)r`   rf   __repr__r<   r=   r   __str__ZJWE.__str__N  s/    	#>>## 	#==?"	#s    00c                s    R V P                  4        R2#   \         d    \        T P                  4      pT P                  P                  R4      pT P                  P                  R4      pT P                  P                  R4      pT P                  pRT R2RT R2,           RT R2,           R	T R
T R2,           u # i ; i)zJWE.from_json_token("z")r"   r#   r!   zJWE(plaintext=z, z
protected=zunprotected=zaad=z, algs=Z))r`   rf   rg   r'   r&   rH   r%   )r   r'   r"   r#   r!   r3   s   &     r   rn   ZJWE.__repr__T  s    	.*4>>+;*<B?? 		.T^^,I((5I,,**=9K,,""5)C%%D#I;b1	{"-.!+b12 #gdV1-. .		.s    B'C ?C )r%   r.   r/   r)   r&   r'   )NNNNNNNNrm   )F)r   r   r   r   r   r   r:   r;   Zpropertyr>   ZsetterrC   rG   rI   rT   r1   r`   ra   rd   rh   rc   ri   rj   re   Zclassmethodrk   rl   ro   rn   r   r   )r   s   @r   r   r   J   s     
/Nb%( 
( 
( " "
	"&5%nV$p5:4x'@RJX  
     
#. .r   r   )zRSA-OAEPzRSA-OAEP-256ZA128KWZA192KWZA256KWZdirzECDH-ESzECDH-ES+A128KWzECDH-ES+A192KWzECDH-ES+A256KWZ	A128GCMKWZ	A192GCMKWZ	A256GCMKWzPBES2-HS256+A128KWzPBES2-HS384+A192KWzPBES2-HS512+A256KWzA128CBC-HS256zA192CBC-HS384zA256CBC-HS512ZA128GCMZA192GCMZA256GCM)rQ   Zjwcryptor    Zjwcrypto.commonr   r   r   r   r   r   r   r   Zjwcrypto.jwar	   Zjwcrypto.jwkr
   r(   r6   r   ZInvalidCEKeyLengthZInvalidJWEKeyLengthZInvalidJWEKeyTyper7   r   r   r   r   <module>rp      sm     6 C > 4   
{E4>	5udDI	6tTJ	}eUDA	~ueTB	xd;	{E5$?	8%M	CU$d,#$J$)5$8	vudD9	~udDA

D$= " *
%  !2[ 2& .. 00 ,, 00 V. V.r   