o
    Šåg  ã                   @   sh   d Z ddlZddlZddlmZ ddlmZ ddlmZ ddlmZ dd	l	m
Z
 d
ZG dd„ de
ƒZdS )aŠ  
A provided CSRF implementation which puts CSRF data in a session.

This can be used fairly comfortably with many `request.session` type
objects, including the Werkzeug/Flask session store, Django sessions, and
potentially other similar objects which use a dict-like API for storing
session keys.

The basic concept is a randomly generated value is stored in the user's
session, and an hmac-sha1 of it (along with an optional expiration time,
for extra security) is used as the value of the csrf_token. If this token
validates with the hmac of the random value + expiration time, and the
expiration time is not passed, the CSRF validation will pass.
é    N)Údatetime)Ú	timedelta)Úsha1é   )ÚValidationErroré   )ÚCSRF)ÚSessionCSRFc                       sP   e Zd ZdZ‡ fdd„Zdd„ Zdd„ Zdd	„ Zed
d„ ƒZ	edd„ ƒZ
‡  ZS )r	   z%Y%m%d%H%M%Sc                    s   |j | _tƒ  |¡S )N)ÚmetaÚ	form_metaÚsuperÚ
setup_form)ÚselfÚform©Ú	__class__© úP/var/www/html/flaskapp/venv/lib/python3.10/site-packages/wtforms/csrf/session.pyr      s   zSessionCSRF.setup_formc                 C   s²   | j }|jd u rtdƒ‚|jd u rtdƒ‚| j}d|vr'tt d¡ƒ 	¡ |d< | j
r>|  ¡ | j
  | j¡}d |d |¡}nd}|d }tj|j| d¡td�}|› d	| 	¡ › �S )
Nz<must set `csrf_secret` on class Meta for SessionCSRF to workz2Must provide a session-like object as csrf contextÚcsrfé@   z{}{}Ú Úutf8©Ú	digestmodú##)r   Úcsrf_secretÚ	ExceptionÚcsrf_contextÚ	TypeErrorÚsessionr   ÚosÚurandomÚ	hexdigestÚ
time_limitÚnowÚstrftimeÚTIME_FORMATÚformatÚhmacÚnewÚencode)r   Úcsrf_token_fieldr
   r   ÚexpiresÚ
csrf_buildÚ	hmac_csrfr   r   r   Úgenerate_csrf_token#   s&   
ÿ
ÿzSessionCSRF.generate_csrf_tokenc           	      C   sª   | j }|jrd|jvrt| d¡ƒ‚|j dd¡\}}| jd |  d¡}tj|j	|t
d�}| ¡ |kr;t| d¡ƒ‚| jrQ|  ¡  | j¡}||krSt| d¡ƒ‚d S d S )	Nr   zCSRF token missing.r   r   r   r   zCSRF failed.zCSRF token expired.)r   Údatar   ÚgettextÚsplitr   r*   r(   r)   r   r   r"   r#   r$   r%   r&   )	r   r   Úfieldr
   r,   r.   Ú	check_valÚhmac_compareÚnow_formattedr   r   r   Úvalidate_csrf_token=   s   ýzSessionCSRF.validate_csrf_tokenc                 C   s   t  ¡ S )zP
        Get the current time. Used for test mocking/overriding mainly.
        )r   r$   ©r   r   r   r   r$   O   s   zSessionCSRF.nowc                 C   s   t | jdtdd�ƒS )NÚcsrf_time_limité   )Úminutes)Úgetattrr   r   r8   r   r   r   r#   U   s   zSessionCSRF.time_limitc                 C   s   t | jjd| jjƒS )Nr   )r<   r   r   r8   r   r   r   r   Y   s   ÿzSessionCSRF.session)Ú__name__Ú
__module__Ú__qualname__r&   r   r/   r7   r$   Úpropertyr#   r   Ú__classcell__r   r   r   r   r	      s    
r	   )Ú__doc__r(   r    r   r   Úhashlibr   Ú
validatorsr   Úcorer   Ú__all__r	   r   r   r   r   Ú<module>   s    