o
    þÞh².  ã                   @   sú   d dl Z d dlmZ d dlmZ d dlmZmZmZ d dl	m
Z
 d dlmZ d dlmZmZ d dlmZ d d	lmZ d d
lmZ d dlmZ d dlmZmZ d dlmZ dd„ Zdd„ ZG dd„ deƒZG dd„ deƒZ G dd„ dƒZ!G dd„ de!ƒZ"dS )é    N)Úpartial)Úurlsplit)ÚiscoroutinefunctionÚmarkcoroutinefunctionÚsync_to_async)Úsettings)Úauth)ÚREDIRECT_FIELD_NAMEÚload_backend)ÚRemoteUserBackend)Úredirect_to_login)ÚImproperlyConfigured)Úresolve_url)ÚMiddlewareMixinÚRemovedInDjango61Warning)ÚSimpleLazyObjectc                 C   s   t | dƒst | ¡| _| jS )NÚ_cached_user)Úhasattrr   Úget_userr   ©Úrequest© r   ú^/var/www/html/premium_crap/venv/lib/python3.10/site-packages/django/contrib/auth/middleware.pyr      s   
r   c                 Ã   s$   �t | dƒst | ¡I d H | _| jS )NÚ_acached_user)r   r   Ú	aget_userr   r   r   r   r   Úauser   s   €
r   c                   @   s   e Zd Zdd„ ZdS )ÚAuthenticationMiddlewarec                    s4   t ˆ dƒs	tdƒ‚t‡ fdd„ƒˆ _ttˆ ƒˆ _d S )NÚsessionzñThe Django authentication middleware requires session middleware to be installed. Edit your MIDDLEWARE setting to insert 'django.contrib.sessions.middleware.SessionMiddleware' before 'django.contrib.auth.middleware.AuthenticationMiddleware'.c                      s   t ˆ ƒS ©N)r   r   r   r   r   Ú<lambda>(   s    z:AuthenticationMiddleware.process_request.<locals>.<lambda>)r   r   r   Úuserr   r   ©Úselfr   r   r   r   Úprocess_request   s   
ÿz(AuthenticationMiddleware.process_requestN)Ú__name__Ú
__module__Ú__qualname__r#   r   r   r   r   r      s    r   c                   @   s4   e Zd ZdZeZdd„ Zdd„ Zdd„ Zdd	„ Z	d
S )ÚLoginRequiredMiddlewarez›
    Middleware that redirects all unauthenticated requests to a login page.

    Views using the login_not_required decorator will not be redirected.
    c                 C   s(   |j jrd S t|ddƒsd S |  ||¡S )NÚlogin_requiredT)r    Úis_authenticatedÚgetattrÚhandle_no_permission)r"   r   Ú	view_funcÚ	view_argsÚview_kwargsr   r   r   Úprocess_view5   s
   z$LoginRequiredMiddleware.process_viewc                 C   s&   t |dd ƒptj}|stdƒ‚t|ƒS )NÚ	login_urlz�No login URL to redirect to. Define settings.LOGIN_URL or provide a login_url via the 'django.contrib.auth.decorators.login_required' decorator.)r*   r   Ú	LOGIN_URLr   Ústr)r"   r,   r0   r   r   r   Úget_login_url>   s   ÿz%LoginRequiredMiddleware.get_login_urlc                 C   s   t |d| jƒS )NÚredirect_field_name)r*   r4   )r"   r,   r   r   r   Úget_redirect_field_nameH   s   z/LoginRequiredMiddleware.get_redirect_field_namec           	      C   sp   |  ¡ }t|  |¡ƒ}t|ƒd d… \}}t|ƒd d… \}}|r%||kr/|r+||kr/| ¡ }t|||  |¡ƒS )Né   )Úbuild_absolute_urir   r3   r   Úget_full_pathr   r5   )	r"   r   r,   ÚpathÚresolved_login_urlÚlogin_schemeÚlogin_netlocÚcurrent_schemeÚcurrent_netlocr   r   r   r+   K   s   ÿýz,LoginRequiredMiddleware.handle_no_permissionN)
r$   r%   r&   Ú__doc__r	   r4   r/   r3   r5   r+   r   r   r   r   r'   ,   s    	
r'   c                       sh   e Zd ZdZdZdZ‡ fdd„ZdZdZdd„ Z	dd	„ Z
d
d„ Zdd„ Zdd„ Zdd„ Zdd„ Z‡  ZS )ÚRemoteUserMiddlewarea  
    Middleware for utilizing web-server-provided authentication.

    If request.user is not authenticated, then this middleware attempts to
    authenticate the username from the ``REMOTE_USER`` key in ``request.META``,
    an environment variable commonly set by the webserver.

    If authentication is successful, the user is automatically logged in to
    persist the user in the session.

    The ``request.META`` key is configurable and defaults to ``REMOTE_USER``.
    Subclass this class and change the ``header`` attribute if you need to
    use a different key from ``request.META``, for example a HTTP request
    header.
    Tc                    s<   |d u rt dƒ‚|| _t|ƒ| _| jrt| ƒ tƒ  ¡  d S )Nzget_response must be provided.)Ú
ValueErrorÚget_responser   Úis_asyncr   ÚsuperÚ__init__)r"   rB   ©Ú	__class__r   r   rE   r   s   
zRemoteUserMiddleware.__init__ÚREMOTE_USERc                 C   s$   | j r|  |¡S |  |¡ |  |¡S r   )rC   Ú	__acall__r#   rB   r!   r   r   r   Ú__call__�   s   


zRemoteUserMiddleware.__call__c                 C   s¨   t |dƒs	tdƒ‚z|j| j }W n ty'   | jr$|jjr$|  |¡ Y d S w |jjr>|j 	¡ |  
||¡kr9d S |  |¡ tj||d�}|rR||_t ||¡ d S d S )Nr    úçThe Django remote user auth middleware requires the authentication middleware to be installed.  Edit your MIDDLEWARE setting to insert 'django.contrib.auth.middleware.AuthenticationMiddleware' before the RemoteUserMiddleware class.©Úremote_user)r   r   ÚMETAÚheaderÚKeyErrorÚforce_logout_if_no_headerr    r)   Ú_remove_invalid_userÚget_usernameÚclean_usernamer   ÚauthenticateÚlogin©r"   r   Úusernamer    r   r   r   r#   ‡   s(   
ÿ
ú

üz$RemoteUserMiddleware.process_requestc                 Ã   sv   �| j jtjur+| j jtju r+tjdtdd� t| jdd�|ƒI d H  |  |¡I d H S |  |¡I d H  |  |¡I d H S )NzƒSupport for subclasses of RemoteUserMiddleware that override process_request() without overriding aprocess_request() is deprecated.r6   )ÚcategoryÚ
stacklevelT)Úthread_sensitive)	rG   r#   r@   Úaprocess_requestÚwarningsÚwarnr   r   rB   r!   r   r   r   rI   ®   s   €ûzRemoteUserMiddleware.__acall__c                 Ã   sÜ   �t |dƒs
tdƒ‚z
|jd| j  }W n ty3   | jr0| ¡ I d H }|jr0|  |¡I d H  Y d S w | ¡ I d H }|jrR| 	¡ |  
||¡krJd S |  |¡I d H  tj||d�I d H }|rl||_t ||¡I d H  d S d S )Nr    rK   ÚHTTP_rL   )r   r   rN   rO   rP   rQ   r   r)   Ú_aremove_invalid_userrS   rT   r   Úaauthenticater    ÚaloginrW   r   r   r   r\   À   s0   €
ÿø	üz%RemoteUserMiddleware.aprocess_requestc                 C   s<   |j tj }t |¡}z| |¡}W |S  ty   Y |S w )zr
        Allow the backend to clean the username, if the backend defines a
        clean_username method.
        )r   r   ÚBACKEND_SESSION_KEYr
   rT   ÚAttributeError)r"   rX   r   Úbackend_strÚbackendr   r   r   rT   ê   s   
þþz#RemoteUserMiddleware.clean_usernamec                 C   sT   zt |j tjd¡ƒ}W n ty   t |¡ Y dS w t|tƒr(t |¡ dS dS ©z 
        Remove the current authenticated user in the request which is invalid
        but only if the user is authenticated via the RemoteUserBackend.
        Ú N)	r
   r   Úgetr   rc   ÚImportErrorÚlogoutÚ
isinstancer   ©r"   r   Ústored_backendr   r   r   rR   ÷   s   ÿþ
ÿz)RemoteUserMiddleware._remove_invalid_userc                 Ã   sh   �zt |j tjd¡I dH ƒ}W n ty"   t |¡I dH  Y dS w t|tƒr2t |¡I dH  dS dS rg   )	r
   r   Úagetr   rc   rj   Úalogoutrl   r   rm   r   r   r   r`     s   €ÿþ
ÿz*RemoteUserMiddleware._aremove_invalid_user)r$   r%   r&   r?   Úsync_capableÚasync_capablerE   rO   rQ   rJ   r#   rI   r\   rT   rR   r`   Ú__classcell__r   r   rF   r   r@   ^   s    '*r@   c                   @   s   e Zd ZdZdZdS )ÚPersistentRemoteUserMiddlewarea‹  
    Middleware for web-server provided authentication on logon pages.

    Like RemoteUserMiddleware but keeps the user authenticated even if
    the ``request.META`` key is not found in the request. Useful for
    setups when the external authentication is only expected to happen
    on some "logon" URL and the rest of the application wants to use
    Django's authentication mechanism.
    FN)r$   r%   r&   r?   rQ   r   r   r   r   rt     s    
rt   )#r]   Ú	functoolsr   Úurllib.parser   Úasgiref.syncr   r   r   Údjango.confr   Údjango.contribr   Údjango.contrib.authr	   r
   Údjango.contrib.auth.backendsr   Údjango.contrib.auth.viewsr   Údjango.core.exceptionsr   Údjango.shortcutsr   Údjango.utils.deprecationr   r   Údjango.utils.functionalr   r   r   r   r'   r@   rt   r   r   r   r   Ú<module>   s(    2 ;