o
    þÞhè  ã                   @   sP   d dl m Z  d dlmZ d dlmZmZ d dlmZmZ G dd„ dƒZ	e	ƒ Z
dS )é    )Údatetime)Úsettings)Úconstant_time_compareÚsalted_hmac)Úbase36_to_intÚint_to_base36c                   @   sŒ   e Zd ZdZdZdZdZdZdd„ Zdd„ Z	dd	„ Z
ee	e
ƒZd
d„ Zdd„ ZeeeƒZdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ ZdS )ÚPasswordResetTokenGeneratorza
    Strategy object used to generate and check tokens for the password
    reset mechanism.
    z6django.contrib.auth.tokens.PasswordResetTokenGeneratorNc                 C   s   | j pd| _ d S )NÚsha256)Ú	algorithm©Úself© r   úZ/var/www/html/premium_crap/venv/lib/python3.10/site-packages/django/contrib/auth/tokens.pyÚ__init__   s   z$PasswordResetTokenGenerator.__init__c                 C   s   | j ptjS ©N)Ú_secretr   Ú
SECRET_KEYr   r   r   r   Ú_get_secret   s   z'PasswordResetTokenGenerator._get_secretc                 C   ó
   || _ d S r   )r   )r   Úsecretr   r   r   Ú_set_secret   ó   
z'PasswordResetTokenGenerator._set_secretc                 C   s   | j d u rtjS | j S r   )Ú_secret_fallbacksr   ÚSECRET_KEY_FALLBACKSr   r   r   r   Ú_get_fallbacks   s   
z*PasswordResetTokenGenerator._get_fallbacksc                 C   r   r   )r   )r   Ú	fallbacksr   r   r   Ú_set_fallbacks#   r   z*PasswordResetTokenGenerator._set_fallbacksc                 C   s   |   ||  |  ¡ ¡| j¡S )zi
        Return a token that can be used once to do a password reset
        for the given user.
        )Ú_make_token_with_timestampÚ_num_secondsÚ_nowr   )r   Úuserr   r   r   Ú
make_token(   s
   ýz&PasswordResetTokenGenerator.make_tokenc                 C   s¦   |r|sdS z	|  d¡\}}W n
 ty   Y dS w zt|ƒ}W n
 ty*   Y dS w | jg| j¢D ]}t|  |||¡|ƒr@ nq2dS |  |  ¡ ¡| t	j
krQdS dS )zP
        Check that a password reset token is correct for a given user.
        Fú-T)ÚsplitÚ
ValueErrorr   r   Úsecret_fallbacksr   r   r   r   r   ÚPASSWORD_RESET_TIMEOUT)r   r    ÚtokenÚts_b36Ú_Útsr   r   r   r   Úcheck_token3   s.   ÿÿþüz'PasswordResetTokenGenerator.check_tokenc                 C   s>   t |ƒ}t| j|  ||¡|| jd� ¡ d d d… }d||f S )N)r   r
   é   z%s-%s)r   r   Úkey_saltÚ_make_hash_valuer
   Ú	hexdigest)r   r    Ú	timestampr   r(   Úhash_stringr   r   r   r   T   s   
üúz6PasswordResetTokenGenerator._make_token_with_timestampc                 C   sR   |j du rdn|j jddd�}| ¡ }t||dƒpd}|j› |j› |› |› |› �S )aÂ  
        Hash the user's primary key, email (if available), and some user state
        that's sure to change after a password reset to produce a token that is
        invalidated when it's used:
        1. The password field will change upon a password reset (even if the
           same password is chosen, due to password salting).
        2. The last_login field will usually be updated very shortly after
           a password reset.
        Failing those things, settings.PASSWORD_RESET_TIMEOUT eventually
        invalidates the token.

        Running this data through salted_hmac() prevents password cracking
        attempts using the reset token, provided the secret isn't compromised.
        NÚ r   )ÚmicrosecondÚtzinfo)Ú
last_loginÚreplaceÚget_email_field_nameÚgetattrÚpkÚpassword)r   r    r0   Úlogin_timestampÚemail_fieldÚemailr   r   r   r.   b   s   
ÿýz,PasswordResetTokenGenerator._make_hash_valuec                 C   s   t |tdddƒ  ¡ ƒS )NiÑ  é   )Úintr   Útotal_seconds)r   Údtr   r   r   r   |   s   z(PasswordResetTokenGenerator._num_secondsc                 C   s   t  ¡ S r   )r   Únowr   r   r   r   r      s   z PasswordResetTokenGenerator._now)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r-   r
   r   r   r   r   r   Úpropertyr   r   r   r%   r!   r+   r   r.   r   r   r   r   r   r   r      s&    

!r   N)r   Údjango.confr   Údjango.utils.cryptor   r   Údjango.utils.httpr   r   r   Údefault_token_generatorr   r   r   r   Ú<module>   s    
|