B
    §0H[¿.  ã               @   sÂ   d dl Z d dlZd dlZd dlmZmZ d dlmZ d dlmZ d dl	m
Z
 d dlmZ d dlmZmZmZ d dlmZ d d	lmZ ejej ZG d
d„ deƒZG dd„ deƒZG dd„ dƒZdS )é    N)ÚdatetimeÚ	timedelta)Úsettings)ÚSuspiciousSession)ÚSuspiciousOperation)Útimezone)Úconstant_time_compareÚget_random_stringÚsalted_hmac)Úforce_bytes)Úimport_stringc               @   s   e Zd ZdZdS )ÚCreateErrorz‡
    Used internally as a consistent exception type to catch from save (see the
    docstring for SessionBase.save() for details).
    N)Ú__name__Ú
__module__Ú__qualname__Ú__doc__© r   r   úiC:\Users\HIRONO~1\AppData\Local\Temp\pip-install-6bm3nxem\django\django\contrib\sessions\backends\base.pyr      s   r   c               @   s   e Zd ZdZdS )ÚUpdateErrorzF
    Occurs if Django tries to update a session that was deleted.
    N)r   r   r   r   r   r   r   r   r      s   r   c               @   s‚  e Zd ZdZdZdZeƒ ZdTdd„Zdd„ Z	d	d
„ Z
dd„ Zdd„ ZdUdd„Zefdd„Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd „ Zd!d"„ Zd#d$„ Zd%d&„ Zd'd(„ Zd)d*„ Zd+d,„ Zd-d.„ Zd/d0„ Zd1d2„ Zd3d4„ Zd5d6„ Z d7d8„ Z!e"e ƒZ#e"e e!ƒZ$dVd:d;„Z%e"e%ƒZ&d<d=„ Z'd>d?„ Z(d@dA„ Z)dBdC„ Z*dDdE„ Z+dFdG„ Z,dHdI„ Z-dJdK„ Z.dWdLdM„Z/dXdNdO„Z0dPdQ„ Z1e2dRdS„ ƒZ3dS )YÚSessionBasez-
    Base class for all Session classes.
    Z
testcookieZworkedNc             C   s"   || _ d| _d| _ttjƒ| _d S )NF)Ú_session_keyÚaccessedÚmodifiedr   r   ZSESSION_SERIALIZERÚ
serializer)ÚselfÚsession_keyr   r   r   Ú__init__-   s    zSessionBase.__init__c             C   s
   || j kS )N)Ú_session)r   Úkeyr   r   r   Ú__contains__3   s    zSessionBase.__contains__c             C   s
   | j | S )N)r   )r   r   r   r   r   Ú__getitem__6   s    zSessionBase.__getitem__c             C   s   || j |< d| _d S )NT)r   r   )r   r   Úvaluer   r   r   Ú__setitem__9   s    
zSessionBase.__setitem__c             C   s   | j |= d| _d S )NT)r   r   )r   r   r   r   r   Ú__delitem__=   s    zSessionBase.__delitem__c             C   s   | j  ||¡S )N)r   Úget)r   r   Údefaultr   r   r   r$   A   s    zSessionBase.getc             C   s8   | j p|| jk| _ || jkr dn|f}| jj|f|žŽ S )Nr   )r   r   Ú_SessionBase__not_givenÚpop)r   r   r%   Úargsr   r   r   r'   D   s    zSessionBase.popc             C   s,   || j kr| j | S d| _|| j |< |S d S )NT)r   r   )r   r   r!   r   r   r   Ú
setdefaultI   s
    


zSessionBase.setdefaultc             C   s   | j | | j< d S )N)ÚTEST_COOKIE_VALUEÚTEST_COOKIE_NAME)r   r   r   r   Úset_test_cookieQ   s    zSessionBase.set_test_cookiec             C   s   |   | j¡| jkS )N)r$   r+   r*   )r   r   r   r   Útest_cookie_workedT   s    zSessionBase.test_cookie_workedc             C   s   | | j = d S )N)r+   )r   r   r   r   Údelete_test_cookieW   s    zSessionBase.delete_test_cookiec             C   s   d| j j }t||ƒ ¡ S )Nzdjango.contrib.sessions)Ú	__class__r   r
   Ú	hexdigest)r   r!   Zkey_saltr   r   r   Ú_hashZ   s    zSessionBase._hashc             C   s4   |   ¡  |¡}|  |¡}t | ¡ d | ¡ d¡S )zGReturn the given session dictionary serialized and encoded as a string.ó   :Úascii)r   Údumpsr1   Úbase64Ú	b64encodeÚencodeÚdecode)r   Zsession_dictÚ
serializedÚhashr   r   r   r7   ^   s    
zSessionBase.encodec          
   C   s¤   t  t|ƒ¡}yD| dd¡\}}|  |¡}t| ¡ |ƒsBtdƒ‚n|  ¡  	|¡S W nL t
k
rž } z.t|tƒrŽt d|jj ¡}| t|ƒ¡ i S d }~X Y nX d S )Nr2   é   zSession data corruptedzdjango.security.%s)r5   Ú	b64decoder   Úsplitr1   r   r8   r   r   ÚloadsÚ	ExceptionÚ
isinstancer   ÚloggingÚ	getLoggerr/   r   ÚwarningÚstr)r   Zsession_dataZencoded_datar:   r9   Zexpected_hashÚeÚloggerr   r   r   r8   d   s    


zSessionBase.decodec             C   s   | j  |¡ d| _d S )NT)r   Úupdater   )r   Zdict_r   r   r   rG   v   s    zSessionBase.updatec             C   s
   || j kS )N)r   )r   r   r   r   r   Úhas_keyz   s    zSessionBase.has_keyc             C   s
   | j  ¡ S )N)r   Úkeys)r   r   r   r   rI   }   s    zSessionBase.keysc             C   s
   | j  ¡ S )N)r   Úvalues)r   r   r   r   rJ   €   s    zSessionBase.valuesc             C   s
   | j  ¡ S )N)r   Úitems)r   r   r   r   rK   ƒ   s    zSessionBase.itemsc             C   s   i | _ d| _d| _d S )NT)Ú_session_cacher   r   )r   r   r   r   Úclear†   s    zSessionBase.clearc             C   s.   yt | jƒ o| j S  tk
r(   dS X dS )zBReturn True when there is no session_key and the session is empty.TN)Úboolr   rL   ÚAttributeError)r   r   r   r   Úis_emptyŽ   s    zSessionBase.is_emptyc             C   s    xt dtƒ}|  |¡sP qW |S )z)Return session key that isn't being used.é    )r	   ÚVALID_KEY_CHARSÚexists)r   r   r   r   r   Ú_get_new_session_key•   s
    

z SessionBase._get_new_session_keyc             C   s   | j d kr|  ¡ | _ | j S )N)r   rT   )r   r   r   r   Ú_get_or_create_session_key�   s    

z&SessionBase._get_or_create_session_keyc             C   s   |ot |ƒdkS )z”
        Key must be truthy and at least 8 characters long. 8 characters is an
        arbitrary lower bound for some minimal key security.
        é   )Úlen)r   r   r   r   r   Ú_validate_session_key¢   s    z!SessionBase._validate_session_keyc             C   s   | j S )N)Ú_SessionBase__session_key)r   r   r   r   Ú_get_session_key©   s    zSessionBase._get_session_keyc             C   s   |   |¡r|| _nd| _dS )zV
        Validate session key on assignment. Invalid values will set to None.
        N)rX   rY   )r   r!   r   r   r   Ú_set_session_key¬   s    
zSessionBase._set_session_keyFc             C   sH   d| _ y| jS  tk
r@   | jdks*|r2i | _n
|  ¡ | _Y nX | jS )zž
        Lazily load session from storage (unless "no_load" is True, when only
        an empty dict is stored) and store it in the current instance.
        TN)r   rL   rO   r   Úload)r   Zno_loadr   r   r   Ú_get_session¸   s    zSessionBase._get_sessionc             K   s†   y|d }W n t k
r(   t ¡ }Y nX y|d }W n t k
rT   |  d¡}Y nX |s`tjS t|tƒsn|S || }|jd |j	 S )zÕGet the number of seconds until the session expires.

        Optionally, this function accepts `modification` and `expiry` keyword
        arguments specifying the modification and expiry of the session.
        ÚmodificationÚexpiryÚ_session_expiryi€Q )
ÚKeyErrorr   Únowr$   r   ÚSESSION_COOKIE_AGEr@   r   ÚdaysÚseconds)r   Úkwargsr^   r_   Údeltar   r   r   Úget_expiry_ageÉ   s    
zSessionBase.get_expiry_agec             K   s|   y|d }W n t k
r(   t ¡ }Y nX y|d }W n t k
rT   |  d¡}Y nX t|tƒrd|S |sntj}|t|d� S )zÔGet session the expiry date (as a datetime object).

        Optionally, this function accepts `modification` and `expiry` keyword
        arguments specifying the modification and expiry of the session.
        r^   r_   r`   )re   )	ra   r   rb   r$   r@   r   r   rc   r   )r   rf   r^   r_   r   r   r   Úget_expiry_dateâ   s    
zSessionBase.get_expiry_datec             C   sN   |dkr,y
| d= W n t k
r&   Y nX dS t|tƒrBt ¡ | }|| d< dS )a*  
        Set a custom expiration for the session. ``value`` can be an integer,
        a Python ``datetime`` or ``timedelta`` object or ``None``.

        If ``value`` is an integer, the session will expire after that many
        seconds of inactivity. If set to ``0`` then the session will expire on
        browser close.

        If ``value`` is a ``datetime`` or ``timedelta`` object, the session
        will expire at that specific future time.

        If ``value`` is ``None``, the session uses the global session expiry
        policy.
        Nr`   )ra   r@   r   r   rb   )r   r!   r   r   r   Ú
set_expiryø   s    

zSessionBase.set_expiryc             C   s"   |   d¡dkrtjS |   d¡dkS )a  
        Return ``True`` if the session is set to expire when the browser
        closes, and ``False`` if there's an expiry date. Use
        ``get_expiry_date()`` or ``get_expiry_age()`` to find the actual expiry
        date/age, if there is one.
        r`   Nr   )r$   r   ZSESSION_EXPIRE_AT_BROWSER_CLOSE)r   r   r   r   Úget_expire_at_browser_close  s    z'SessionBase.get_expire_at_browser_closec             C   s   |   ¡  |  ¡  d| _dS )zc
        Remove the current session data from the database and regenerate the
        key.
        N)rM   Údeleter   )r   r   r   r   Úflush  s    zSessionBase.flushc             C   s,   | j }| j}|  ¡  || _|r(|  |¡ dS )zU
        Create a new session key, while retaining the current session data.
        N)r   r   ÚcreaterL   rl   )r   Údatar   r   r   r   Ú	cycle_key&  s    zSessionBase.cycle_keyc             C   s   t dƒ‚dS )zF
        Return True if the given session_key already exists.
        z9subclasses of SessionBase must provide an exists() methodN)ÚNotImplementedError)r   r   r   r   r   rS   3  s    zSessionBase.existsc             C   s   t dƒ‚dS )zÅ
        Create a new session instance. Guaranteed to create a new object with
        a unique key and will have saved the result once (with empty data)
        before the method returns.
        z8subclasses of SessionBase must provide a create() methodN)rq   )r   r   r   r   rn   9  s    zSessionBase.createc             C   s   t dƒ‚dS )zä
        Save the session data. If 'must_create' is True, create a new session
        object (or raise CreateError). Otherwise, only update an existing
        object and don't create one (raise UpdateError if needed).
        z6subclasses of SessionBase must provide a save() methodN)rq   )r   Zmust_creater   r   r   ÚsaveA  s    zSessionBase.savec             C   s   t dƒ‚dS )zx
        Delete the session data under this key. If the key is None, use the
        current session key value.
        z8subclasses of SessionBase must provide a delete() methodN)rq   )r   r   r   r   r   rl   I  s    zSessionBase.deletec             C   s   t dƒ‚dS )z@
        Load the session data and return a dictionary.
        z6subclasses of SessionBase must provide a load() methodN)rq   )r   r   r   r   r\   P  s    zSessionBase.loadc             C   s   t dƒ‚dS )a  
        Remove expired sessions from the session store.

        If this operation isn't possible on a given backend, it should raise
        NotImplementedError. If it isn't necessary, because the backend has
        a built-in expiration mechanism, it should be a no-op.
        z.This backend does not support clear_expired().N)rq   )Úclsr   r   r   Úclear_expiredV  s    	zSessionBase.clear_expired)N)N)F)F)N)4r   r   r   r   r+   r*   Úobjectr&   r   r   r    r"   r#   r$   r'   r)   r,   r-   r.   r1   r7   r8   rG   rH   rI   rJ   rK   rM   rP   rT   rU   rX   rZ   r[   Úpropertyr   r   r]   r   rh   ri   rj   rk   rm   rp   rS   rn   rr   rl   r\   Úclassmethodrt   r   r   r   r   r   $   s\   

	

	

r   )r5   rA   Ústringr   r   Zdjango.confr   Z"django.contrib.sessions.exceptionsr   Zdjango.core.exceptionsr   Zdjango.utilsr   Zdjango.utils.cryptor   r	   r
   Zdjango.utils.encodingr   Zdjango.utils.module_loadingr   Úascii_lowercaseÚdigitsrR   r?   r   r   r   r   r   r   r   Ú<module>   s   