a 97aJnã@söddlZddlZddlZddlZddlZddlZddlmZmZddl m Z m Z ddl m Z ddl mZddl mZddlmZmZGdd „d eƒZGd d „d eƒZd d „Zddd„ZGdd„deƒZdd„Zddd„Zdd„Zddd„Zdd„ZdS) éN)ÚsixÚ OrderedDict)Úcreate_request_objectÚprepare_request_dict)ÚUnknownSignatureVersionError)ÚUnknownClientMethodError)Ú UnsupportedSignatureVersionError)Ú fix_s3_hostÚdatetime2timestampc@speZdZdZdd„Zedd„ƒZedd„ƒZedd „ƒZdd d „Z ddd„Z dd„Z ddd„Z e Z ddd„Zd S)Ú RequestSignera0 An object to sign requests before they go out over the wire using one of the authentication mechanisms defined in ``auth.py``. This class fires two events scoped to a service and operation name: * choose-signer: Allows overriding the auth signer name. * before-sign: Allows mutating the request before signing. Together these events allow for customization of the request signing pipeline, including overrides, request path manipulation, and disabling signing per operation. :type service_id: botocore.model.ServiceId :param service_id: The service id for the service, e.g. ``S3`` :type region_name: string :param region_name: Name of the service region, e.g. ``us-east-1`` :type signing_name: string :param signing_name: Service signing name. This is usually the same as the service name, but can differ. E.g. ``emr`` vs. ``elasticmapreduce``. :type signature_version: string :param signature_version: Signature name like ``v4``. :type credentials: :py:class:`~botocore.credentials.Credentials` :param credentials: User credentials with which to sign requests. :type event_emitter: :py:class:`~botocore.hooks.BaseEventHooks` :param event_emitter: Extension mechanism to fire events. cCs.||_||_||_||_||_t |¡|_dS©N)Ú _region_nameÚ _signing_nameÚ_signature_versionÚ _credentialsÚ _service_idÚweakrefÚproxyÚ_event_emitter)ÚselfZ service_idÚ region_nameÚ signing_nameÚsignature_versionÚ credentialsZ event_emitter©rúk/private/var/folders/s6/9n5zrl012gv99k63s4q6ccsd4s6mqz/T/pip-target-f5cq3f2q/lib/python/botocore/signers.pyÚ__init__>s zRequestSigner.__init__cCs|jSr )r ©rrrrrIszRequestSigner.region_namecCs|jSr )rrrrrrMszRequestSigner.signature_versioncCs|jSr )rrrrrrQszRequestSigner.signing_nameNcKs | ||¡Sr )Úsign)rÚoperation_nameÚrequestÚkwargsrrrÚhandlerUszRequestSigner.handlerÚstandardc Cs"|}|dur|j}|dur |j}| |||j¡}|jjd |j ¡|¡|||j|||d�|t j k�r|||dœ} |dur‚|| d<|j  di¡} |sª|   d¡rª| d| d<|   d ¡rÀ| d | d <z|j fi| ¤Ž} Wn>t �y} z$|d krút|d �‚n| ‚WYd} ~ n d} ~ 00|  |¡dS) a<Sign a request before it goes out over the wire. :type operation_name: string :param operation_name: The name of the current operation, e.g. ``ListBuckets``. :type request: AWSRequest :param request: The request object to be sent over the wire. :type region_name: str :param region_name: The region to sign the request for. :type signing_type: str :param signing_type: The type of signing to perform. This can be one of three possible values: * 'standard' - This should be used for most requests. * 'presign-url' - This should be used when pre-signing a request. * 'presign-post' - This should be used when pre-signing an S3 post. :type expires_in: int :param expires_in: The number of seconds the presigned url is valid for. This parameter is only valid for signing type 'presign-url'. :type signing_name: str :param signing_name: The name to use for the service when signing. Nzbefore-sign.{0}.{1})r rrrÚrequest_signerr)rrrÚexpiresZsigningÚregionrrr#©r)r rÚ_choose_signerÚcontextrÚemitÚformatrÚ hyphenizeÚbotocoreÚUNSIGNEDÚgetÚget_auth_instancerrZadd_auth) rrr rÚ signing_typeÚ expires_inrZexplicit_region_namerr!Zsigning_contextÚauthÚerrrr\sLÿ ÿú ý   ÿzRequestSigner.signc Cs�dddœ}| |d¡}|j}|tjur8| |¡s8||7}|jjd |j  ¡|¡|j |j ||d�\}}|durŒ|}|tjurŒ| |¡sŒ||7}|S)ai Allow setting the signature version via the choose-signer event. A value of `botocore.UNSIGNED` means no signing will be performed. :param operation_name: The operation to sign. :param signing_type: The type of signing that the signer is to be used for. :return: The signature version to sign with. z -presign-postz-query)ú presign-postú presign-urlÚzchoose-signer.{0}.{1})rrrr)N) r/rr-r.ÚendswithrZemit_until_responser+rr,rr ) rrr1r)Zsigning_type_suffix_mapÚsuffixrr"Úresponserrrr(¤s. þ  ÿ ÿü  ÿzRequestSigner._choose_signercKsŠ|dur|j}tjj |¡}|dur.t|d�‚d}|jdurF|j ¡}||d<|jrx|j durhtj   ¡‚||d<||d<|fi|¤Ž}|S)a© Get an auth instance which can be used to sign a request using the given signature version. :type signing_name: string :param signing_name: Service signing name. This is usually the same as the service name, but can differ. E.g. ``emr`` vs. ``elasticmapreduce``. :type region_name: string :param region_name: Name of the service region, e.g. ``us-east-1`` :type signature_version: string :param signature_version: Signature name like ``v4``. :rtype: :py:class:`~botocore.auth.BaseSigner` :return: Auth instance to sign a request. Nr'rrZ service_name) rr-r3ZAUTH_TYPE_MAPSr/rrZget_frozen_credentialsZREQUIRES_REGIONr Ú exceptionsZ NoRegionError)rrrrr!ÚclsZfrozen_credentialsr3rrrr0És$ÿ    zRequestSigner.get_auth_instanceécCs*t|ƒ}| |||d||¡| ¡|jS)aÍGenerates a presigned url :type request_dict: dict :param request_dict: The prepared request dictionary returned by ``botocore.awsrequest.prepare_request_dict()`` :type operation_name: str :param operation_name: The operation being signed. :type expires_in: int :param expires_in: The number of seconds the presigned url is valid for. By default it expires in an hour (3600 seconds) :type region_name: string :param region_name: The region name to sign the presigned url. :type signing_name: str :param signing_name: The name to use for the service when signing. :returns: The presigned url r6)rrÚprepareÚurl)rÚ request_dictrr2rrr rrrÚgenerate_presigned_url÷s  ÿz$RequestSigner.generate_presigned_url)NN)Nr#NN)N)r=NN)Ú__name__Ú __module__Ú __qualname__Ú__doc__rÚpropertyrrrr"rr(r0Zget_authrArrrrr s&!     ÿ H&ÿ ,þr c@s<eZdZdZdd„Zd dd„Zdd„Zdd d „Zd d „ZdS)ÚCloudFrontSigneraàA signer to create a signed CloudFront URL. First you create a cloudfront signer based on a normalized RSA signer:: import rsa def rsa_signer(message): private_key = open('private_key.pem', 'r').read() return rsa.sign( message, rsa.PrivateKey.load_pkcs1(private_key.encode('utf8')), 'SHA-1') # CloudFront requires SHA-1 hash cf_signer = CloudFrontSigner(key_id, rsa_signer) To sign with a canned policy:: signed_url = cf_signer.generate_signed_url( url, date_less_than=datetime(2015, 12, 1)) To sign with a custom policy:: signed_url = cf_signer.generate_signed_url(url, policy=my_policy) cCs||_||_dS)a–Create a CloudFrontSigner. :type key_id: str :param key_id: The CloudFront Key Pair ID :type rsa_signer: callable :param rsa_signer: An RSA signer. Its only input parameter will be the message to be signed, and its output will be the signed content as a binary string. The hash algorithm needed by CloudFront is SHA-1. N)Úkey_idÚ rsa_signer)rrHrIrrrr/s zCloudFrontSigner.__init__NcCsÂ|dur|dus |dur,|dur,d}t|ƒ‚|dur@| ||¡}t|tjƒrV| d¡}|durrdtt|ƒƒg}nd| |¡  d¡g}|  |¡}|  d| |¡  d¡d|j g¡|  ||¡S)a¤Creates a signed CloudFront URL based on given parameters. :type url: str :param url: The URL of the protected object :type date_less_than: datetime :param date_less_than: The URL will expire after that date and time :type policy: str :param policy: The custom policy, possibly built by self.build_policy() :rtype: str :return: The signed URL. Nz=Need to provide either date_less_than or policy, but not bothÚutf8z Expires=%sz Policy=%sz Signature=%szKey-Pair-Id=%s)Ú ValueErrorÚ build_policyÚ isinstancerÚ text_typeÚencodeÚintr Ú_url_b64encodeÚdecoderIÚextendrHÚ _build_url)rr?Údate_less_thanÚpolicyr4ÚparamsÚ signaturerrrrA>s(ÿÿ    þz'CloudFrontSigner.generate_presigned_urlcCs"d|vr dnd}||d |¡S)Nú?ú&)Újoin)rÚbase_urlZ extra_paramsÚ separatorrrrrTaszCloudFrontSigner._build_urlc Cs„tt|ƒƒ}tdd|iiƒ}|rþ ÿÿ ÿþrAcKs t|d<dS)Nr‰)r‰rtrrrÚadd_generate_presigned_post[sr–cCsà|}|}|}|} |} |dur"i}n| ¡}| dur6g} t|jƒ} |j} |jj d¡} |  d|i| ¡}t||jj dt |ƒdœd�|   d|i¡|  d¡r¸|   d d |dt dƒ …g¡n|   d |i¡||d <| j||| | d �S) a× Builds the url and the form fields used for a presigned s3 post :type Bucket: string :param Bucket: The name of the bucket to presign the post to. Note that bucket related conditions should not be included in the ``conditions`` parameter. :type Key: string :param Key: Key name, optionally add ${filename} to the end to attach the submitted filename. Note that key related conditions and fields are filled out for you and should not be included in the ``Fields`` or ``Conditions`` parameter. :type Fields: dict :param Fields: A dictionary of prefilled form fields to build on top of. Elements that may be included are acl, Cache-Control, Content-Type, Content-Disposition, Content-Encoding, Expires, success_action_redirect, redirect, success_action_status, and x-amz-meta-. Note that if a particular element is included in the fields dictionary it will not be automatically added to the conditions list. You must specify a condition for the element as well. :type Conditions: list :param Conditions: A list of conditions to include in the policy. Each element can be either a list or a structure. For example: [ {"acl": "public-read"}, ["content-length-range", 2, 5], ["starts-with", "$success_action_redirect", ""] ] Conditions that are included may pertain to acl, content-length-range, Cache-Control, Content-Type, Content-Disposition, Content-Encoding, Expires, success_action_redirect, redirect, success_action_status, and/or x-amz-meta-. Note that if you include a condition, you must specify the a valid value in the fields dictionary as well. A value will not be added automatically to the fields dictionary based on the conditions. :type ExpiresIn: int :param ExpiresIn: The number of seconds the presigned post is valid for. :rtype: dict :returns: A dictionary with two elements: ``url`` and ``fields``. Url is the url to post to. Fields is a dictionary filled with the form fields and respective values to use when submitting the post. For example: {'url': 'https://mybucket.s3.amazonaws.com 'fields': {'acl': 'public-read', 'key': 'mykey', 'signature': 'mysignature', 'policy': 'mybase64 encoded policy'} } NZ CreateBucketÚBucketTr‹r�Úbucketz ${filename}z starts-withz$keyÚkey)r@rƒr‚r2)Úcopyr€r|r�r{r‘r’r“rrrŽrˆr8r}r‰)rr—ZKeyZFieldsZ Conditionsr”r˜r™rƒr‚r2Zpost_presignerr•r’r@rrrr‰_sB@ ÿÿþþ   þr‰cCsR|jjdkrdS|jjj}|rN| dd¡r.dS| d¡dkrN|jjjdkrNdSdS)NZawsFZuse_dualstack_endpointZus_east_1_regional_endpointZregionalz us-east-1T)r{Ú partitionÚconfigZs3r/r)ÚclientZ s3_configrrrrŽÔs    ÿrŽ)N)Nr=N)NNr=)r„rrdror-Z botocore.authZbotocore.compatrrZbotocore.awsrequestrrZbotocore.exceptionsrrrZbotocore.utilsr r Úobjectr rGrursr€rŠrAr–r‰rŽrrrrÚ s4   |~ 3Lÿ ?ÿ u