U
    ]7                     @   s   d Z ddlZddlZddlZddlZddlZddlmZmZm	Z	m
Z
mZmZ G dd deZG dd de	jZG dd	 d	e	jZG d
d de	jZG dd deZedkree  dS )zJSON Web Signature.    N)b64errors	json_utiljwajwkutilc                   @   s,   e Zd ZdZdZedd Zedd ZdS )	MediaTypez MediaType field encoder/decoder.zapplication/c                 C   s(   d|kr$d|krt d| j| S |S )zDecoder./;zUnexpected semi-colon)r   DeserializationErrorPREFIXclsvalue r   ,/usr/lib/python3/dist-packages/josepy/jws.pydecode   s
    

zMediaType.decodec                 C   s.   d|kr*| | jst|t| jd S |S )zEncoder.r
   N)
startswithr   AssertionErrorlenr   r   r   r   encode   s    zMediaType.encodeN)__name__
__module____qualname____doc__r   classmethodr   r   r   r   r   r   r      s   
	r   c                   @   s  e Zd ZdZejdejjddZ	ejdddZ
ejdejjddZejdddZejd	ddZejd
dddZejdejddZejdejddZejdejejddZejdejejddZejddddZdd Zdd Zdd Zejdd Zejdd Zejdd ZdS )Headera6  JOSE Header.

    .. warning:: This class supports **only** Registered Header
        Parameter Names (as defined in section 4.1 of the
        protocol). If you need Public Header Parameter Names (4.2)
        or Private Header Parameter Names (4.3), you must subclass
        and override :meth:`from_json` and :meth:`to_partial_json`
        appropriately.

    .. warning:: This class does not support any extensions through
        the "crit" (Critical) Header Parameter (4.1.11) and as a
        conforming implementation, :meth:`from_json` treats its
        occurrence as an error. Please subclass if you seek for
        a different behaviour.

    :ivar x5tS256: "x5t#S256"
    :ivar str typ: MIME Media Type, inc. :const:`MediaType.PREFIX`.
    :ivar str cty: Content-Type, inc. :const:`MediaType.PREFIX`.

    algT)decoder	omitemptyjku)r   r   kidx5ux5cr   r   defaultx5tzx5t#S256typ)encoderr   r   ctycritc                    s   t  fddt jD S )z4Fields that would not be omitted in the JSON object.c                 3   s0   | ](\}}| t |s|t |fV  qd S N)Zomitgetattr).0nameZfieldselfr   r   	<genexpr>N   s   z%Header.not_omitted.<locals>.<genexpr>)dictsixZ	iteritems_fieldsr/   r   r/   r   not_omittedL   s    
zHeader.not_omittedc                 C   s^   t |t| s tdt||  }| }t||rFtd|| t| f |S )NzHeader cannot be added to: {0}z+Addition of overlapping headers not defined)
isinstancetype	TypeErrorformatr5   setintersectionupdate)r0   otherZnot_omitted_selfZnot_omitted_otherr   r   r   __add__R   s    
zHeader.__add__c                 C   s   | j dkrtd| j S )zFind key based on header.

        .. todo:: Supports only "jwk" header parameter lookup.

        :returns: (Public) key found in the header.
        :rtype: .JWK

        :raises josepy.errors.Error: if key could not be found

        NzNo key found)r   r   Errorr/   r   r   r   find_key`   s    

zHeader.find_keyc                 C   s   t dd S )Nz("crit" is not supported, please subclass)r   r   )Zunused_valuer   r   r   r*   o   s    zHeader.critc                 C   s   dd | D S )Nc                 S   s&   g | ]}t tjtjj|jqS r   )base64	b64encodeOpenSSLcryptoZdump_certificateFILETYPE_ASN1wrappedr-   Zcertr   r   r   
<listcomp>y   s
   
 zHeader.x5c.<locals>.<listcomp>r   r   r   r   r   r#   w   s    z
Header.x5cc              
   C   sJ   zt dd | D W S  tjjk
rD } zt|W 5 d }~X Y nX d S )Nc              	   s   s,   | ]$}t tjtjjt|V  qd S r+   )r   ZComparableX509rC   rD   Zload_certificaterE   rA   	b64decoderG   r   r   r   r1      s
   
zHeader.x5c.<locals>.<genexpr>)tuplerC   rD   r?   r   r   )r   errorr   r   r   r#   |   s    
N)r   r   r   r   r   Fieldr   JWASignature	from_jsonr   r    r   JWKr!   r"   r#   decode_b64joser&   Zx5tS256r   r   r   r'   r)   r*   r5   r>   r@   r   r(   r   r   r   r   r   &   sN         
 
 

r   c                       s   e Zd ZdZeZdZejddddZ	ejdde ej
dZejd	ejejd
Ze	jdd Z	e	jdd Z	 fddZedd Zedd ZdddZede fddZ fddZe fddZ  ZS )	Signaturea  JWS Signature.

    :ivar combined: Combined Header (protected and unprotected,
        :class:`Header`).
    :ivar unicode protected: JWS protected header (Jose Base-64 decoded).
    :ivar header: JWS Unprotected Header (:class:`Header`).
    :ivar str signature: The signature.

    )combined	protectedT r$   header)r   r%   r   	signature)r   r(   c                 C   s   t | dS Nutf-8)r   encode_b64joser   rI   r   r   r   rT      s    zSignature.protectedc                 C   s   t | dS rX   )r   rQ   r   rI   r   r   r   rT      s    c                    s8   d|kr|  |}tt| jf | | jjd k	s4td S )NrS   )_with_combinedsuperrR   __init__rS   r   r   )r0   kwargs	__class__r   r   r]      s    
zSignature.__init__c                 C   sZ   d|kst |d| jd j}|d| jd j}|rJ|| j| }n|}||d< |S )NrS   rV   rT   )r   getr4   r%   
header_cls
json_loads)r   r^   rV   rT   rS   r   r   r   r[      s    zSignature._with_combinedc                 C   s   t |dd t | S )NrY      .)r   rB   r   )r   rT   payloadr   r   r   _msg   s    zSignature._msgNc                 C   s8   |dkr| j  n|}| j jj|j| j| | j|dS )zEVerify.

        :param JWK key: Key used for verification.

        N)keysigmsg)rS   r@   r   verifyrg   rW   rf   rT   )r0   re   rg   r   r   r   rj      s     zSignature.verifyc                 K   s   t ||jst|}||d< |r,| |d< t|| jjsBt|| jjsTti }|D ]}	|	|kr\||	||	< q\|r| jf |	 }
nd}
| jf |}	|
|j| |
|}| |
|	|dS )z;Sign.

        :param JWK key: Key for signature.

        r   r   rU   )rT   rV   rW   )r6   ktyr   
public_keyr:   issubsetrb   r4   popZ
json_dumpssignrg   rf   )r   re   rg   r   Zinclude_jwkprotectr^   Zheader_paramsZprotected_paramsrV   rT   rW   r   r   r   ro      s"    zSignature.signc                    s$   t t|  }|d  s |d= |S )NrV   )r\   rR   fields_to_partial_jsonr5   )r0   fieldsr_   r   r   rq      s    z Signature.fields_to_partial_jsonc                    s8   t t| |}| |}d|d  kr4td|S )Nr   rS   zalg not present)r\   rR   fields_from_jsonr[   r5   r   r   )r   jobjrr   Zfields_with_combinedr_   r   r   rs      s
    

zSignature.fields_from_json)N)r   r   r   r   r   rb   	__slots__r   rM   rT   rO   rV   rQ   rZ   rW   r(   r   r]   r   r[   rf   rj   	frozensetro   rq   rs   __classcell__r   r   r_   r   rR      s@   	   




 rR   c                   @   sd   e Zd ZdZdZeZdddZedd Z	e
dd	 Zd
d Zedd ZdddZedd ZdS )JWSzgJSON Web Signature.

    :ivar str payload: JWS Payload.
    :ivar str signature: JWS Signatures.

    re   
signaturesNc                    s   t  fddjD S )Verify.c                 3   s   | ]}| j V  qd S r+   )rj   re   r-   rh   rg   r0   r   r   r1     s     zJWS.verify.<locals>.<genexpr>)allrz   )r0   rg   r   r}   r   rj     s    z
JWS.verifyc                 K   s    | || j jf d|i|fdS )Sign.re   ry   )signature_clsro   )r   re   r^   r   r   r   ro     s    zJWS.signc                 C   s   t | jdkst| jd S )zPGet a singleton signature.

        :rtype: :class:`JWS.signature_cls`

           r   )r   rz   r   r/   r   r   r   rW     s    zJWS.signaturec                 C   s\   t | jdkstd| jj ks&tt| jj	dd t| j
 d t| jj S )z7Compact serialization.

        :rtype: bytes

        r   r   rY   rd   )r   rz   r   rW   rV   r5   r   rB   rT   r   re   r/   r   r   r   
to_compact  s    
zJWS.to_compactc                 C   sh   z| d\}}}W n tk
r2   tdY nX | jt|dt|d}| t||fdS )zACompact deserialization.

        :param bytes compact:

        rd   zOCompact JWS serialization should comprise of exactly 3 dot-separated componentsrY   )rT   rW   ry   )split
ValueErrorr   r   r   r   rJ   r   )r   compactrT   re   rW   rh   r   r   r   from_compact)  s    
zJWS.from_compactTc                 C   sR   | j s
tt| j}|rBt| j dkrB| j d  }||d< |S || j dS d S )Nr   r   re   ry   )rz   r   r   rZ   re   r   to_partial_json)r0   Zflatre   Zretr   r   r   r   <  s    
zJWS.to_partial_jsonc                    sv   d|krd|krt dnVd|krF t|d j|fdS  t|d t fdd|d D dS d S )NrW   rz   zFlat mixed with non-flatre   ry   c                 3   s   | ]} j |V  qd S r+   )r   rO   r|   r   r   r   r1   S  s   z JWS.from_json.<locals>.<genexpr>)r   r   r   rQ   rn   r   rO   rK   )r   rt   r   r   r   rO   J  s    zJWS.from_json)N)T)r   r   r   r   ru   rR   r   rj   r   ro   propertyrW   r   r   r   rO   r   r   r   r   rx      s   


	

rx   c                   @   sZ   e Zd ZdZedd Zedd Zedd Zedd	 Zed
d Z	edddZ
dS )CLIzJWS CLI.c                 C   s   |j j|j }|j  |jdkr.g |_|jr@|jd t	j
tj  ||j t|jd}|jrt| d nt|  dS )r   Nr   )re   rg   r   rp   rY   )r   rk   loadrg   readcloserp   r   appendrx   ro   sysstdinr   r:   r3   print_r   r   Zjson_dumps_pretty)r   argsrg   rh   r   r   r   ro   Z  s    

zCLI.signc              
   C   s   |j rttj  }nJzttj }W n4 tj	k
rd } zt
| W Y dS d}~X Y nX |jdk	r|jdk	s~t|j|j  }|j  nd}tj|j |j|d S )r{   N)rg   )r   rx   r   r   r   r   r   rc   r   r?   r3   r   rg   rk   r   r   rl   r   stdoutwritere   rj   )r   r   rh   rL   rg   r   r   r   rj   l  s    

z
CLI.verifyc                 C   s   t j|S r+   )r   rN   rO   r   argr   r   r   	_alg_type  s    zCLI._alg_typec                 C   s   |t jjkst|S r+   )rR   rb   r4   r   r   r   r   r   _header_type  s    zCLI._header_typec                 C   s   |t jjkstt jj| S r+   )r   rP   ZTYPESr   r   r   r   r   	_kty_type  s    zCLI._kty_typeNc                 C   s   |dkrt jdd }t }|jddd | }|d}|j| jd |jdd	t	d
dd |jdd| j
tjd |jddd| jd |d}|j| jd |jdd	t	d
dd |jd| jdd ||}||S )z Parse arguments and sign/verify.Nr   z	--compact
store_true)actionro   )funcz-kz--keyrbT)r7   Zrequiredz-az--alg)r7   r%   z-pz	--protectr   )r   r7   rj   Fz--kty)r   argvargparseArgumentParseradd_argumentZadd_subparsersZ
add_parserZset_defaultsro   ZFileTyper   r   ZRS256r   rj   r   
parse_argsr   )r   r   parserZ
subparsersZparser_signZparser_verifyZparsedr   r   r   run  sP    
         
     
zCLI.run)N)r   r   r   r   r   ro   rj   r   r   r   r   r   r   r   r   r   W  s   




r   __main__)r   r   rA   r   rC   r3   Zjosepyr   r   r   r   r   r   objectr   ZJSONObjectWithFieldsr   rR   rx   r   r   exitr   r   r   r   r   <module>   s    `r_V