
    wg\jc                        S SK r S SKJr  S SKJrJr  S SKJrJr  S SKJrJ	r	  S SKJ
r
Jr  S SKJr  S SKJr  S	rS
r\" SSSS5      \" SSSS5      \" SSSS5      \" SSSS5      \" SSSS5      \" SSSS5      \" SSSS5      \" SSSS5      \" SSSS5      \" SSSS5      \" SSSS5      \" SSSS5      \" SSSS5      S.r / SQr  " S S\5      r\R*                  r\R,                  r\R.                  r\R0                  r " S S5      rg)     N)common)JWExceptionJWKeyNotFound)JWSEHeaderParameterJWSEHeaderRegistry)base64url_decodebase64url_encode)json_decodejson_encode)JWA)JWKSeti   i  @	AlgorithmFTzEncryption AlgorithmzCompression AlgorithmzJWK Set URLzJSON Web KeyzKey IDz	X.509 URLzX.509 Certificate Chainz"X.509 Certificate SHA-1 Thumbprintz$X.509 Certificate SHA-256 ThumbprintTypezContent TypeCritical)algenczipjkujwkkidx5ux5cx5tzx5t#S256typctycrit)zRSA-OAEPzRSA-OAEP-256A128KWA192KWA256KWdirzECDH-ESzECDH-ES+A128KWzECDH-ES+A192KWzECDH-ES+A256KW	A128GCMKW	A192GCMKW	A256GCMKWzPBES2-HS256+A128KWzPBES2-HS384+A192KWzPBES2-HS512+A256KWzA128CBC-HS256zA192CBC-HS384zA256CBC-HS512A128GCMA192GCMA256GCMc                   0   ^  \ rS rSrSrSU 4S jjrSrU =r$ )InvalidJWEData5   zjInvalid JWE Object.

This exception is raised when the JWE Object is invalid and/or
improperly formatted.
c                 x   > S nU(       a  UnOSnU(       a  US[        U5      -  -  n[        [        U ]  U5        g )Nz!Unknown Data Verification Failurez {%s})strsuperr(   __init__)selfmessage	exceptionmsg	__class__s       G/home/edenadmin/noVNC/venv/lib/python3.13/site-packages/jwcrypto/jwe.pyr-   InvalidJWEData.__init__<   s:    C5C7S^++Cnd,S1     )NN)__name__
__module____qualname____firstlineno____doc__r-   __static_attributes____classcell__)r2   s   @r3   r(   r(   5   s    2 2r5   r(   c                      \ rS rSrSr   SS jrS rS r\S 5       r	\	R                  S 5       r	S	 rSS
 jrS rS rSS jrSS jrS rS r\4S jrSS jrSS jr\S 5       r\S 5       r\S 5       rS rS rS rSrg)JWEN   z?JSON Web Encryption object

This object represent a JWE token.
Nc
                    SU l         0 U l        SU l        [        [        5      U l        Xl        U(       a  U R
                  R                  U5        Ub2  [        U[        5      (       a  Xl        OUR                  S5      U l        SU l        SU l        U(       a  X@R                  S'   U(       a:  [        U[        5      (       a  [        U5      nO[        U5        X R                  S'   U(       a:  [        U[        5      (       a  [        U5      nO[        U5        X0R                  S'   U(       a  XPl         U(       a  U R!                  XgS9  gU(       a  [#        S5      eg)a>  Creates a JWE token.

:param plaintext(bytes): An arbitrary plaintext to be encrypted.
:param protected: A JSON string with the protected header.
:param unprotected: A JSON string with the shared unprotected header.
:param aad(bytes): Arbitrary additional authenticated data
:param algs: An optional list of allowed algorithms
:param recipient: An optional, default recipient key
:param header: An optional header for the default recipient
:param header_registry: Optional additions to the header registry
:param flattened: Use flattened serialization syntax (default True)
Nutf-8aad	protectedunprotected)headerz-Header is allowed only with default recipient)_allowed_algsobjects	plaintextr   JWEHeaderRegistryheader_registry	flattenedupdate
isinstancebytesencodecek
decryptlogdictr   r
   add_recipient
ValueError)
r.   rI   rD   rE   rC   algs	recipientrF   rK   rL   s
             r3   r-   JWE.__init__T   s    "12CD"  ''8 )U++!*!*!1!1'!:"%LL)T**'	2	I&(1LL%+t,,)+6K(*5LL'!%y8LMM r5   c                     U R                   =(       d    [        nX;  a  [        S5      e[        R                  " U5      $ NzAlgorithm not allowed)rG   default_allowed_algsInvalidJWEOperationr   keymgmt_algr.   namealloweds      r3   _jwa_keymgmtJWE._jwa_keymgmt   s4    $$<(<%&=>>t$$r5   c                     U R                   =(       d    [        nX;  a  [        S5      e[        R                  " U5      $ rZ   )rG   r[   r\   r   encryption_algr^   s      r3   _jwa_encJWE._jwa_enc   s6    $$<(<%&=>>!!$''r5   c                 H    U R                   (       a  U R                   $ [        $ )zjAllowed algorithms.

The list of allowed algorithms.
Can be changed by setting a list of algorithm names.
)rG   r[   r.   s    r3   allowed_algsJWE.allowed_algs   s     %%%''r5   c                 P    [        U[        5      (       d  [        S5      eXl        g )NzAllowed Algs must be a list)rN   list	TypeErrorrG   )r.   rV   s     r3   ri   rj      s!    $%%9::!r5   c                     [        UR                  5       5       H  nX2;   d  M
  [        SU-  5      e   UR                  U5        U$ )NzDuplicate header: "%s")rl   keysr(   rM   )r.   h1h2ks       r3   _merge_headersJWE._merge_headers   s>    bggiAw$%=%ABB ! 			"	r5   c                 4   0 nSU R                   ;   a)  [        U R                   S   5      nU R                  X#5      nSU R                   ;   a)  [        U R                   S   5      nU R                  X$5      nU(       a  [        U5      nU R                  X%5      nU$ )NrD   rE   )rH   r
   rs   )r.   rF   jhphuhrhs         r3   _get_jose_headerJWE._get_jose_header   s    $,,&T\\+67B$$R,BDLL(T\\-89B$$R,BV$B$$R,B	r5   c                     UR                  SS 5      nUc  [        S5      eU R                  U5      nUR                  SS 5      nUc  [        S5      eU R                  U5      nX54$ )Nr   zMissing "alg" from headersr   zMissing "enc" from headers)getr(   ra   re   )r.   rv   algnamer   encnamer   s         r3   _get_alg_enc_from_headersJWE._get_alg_enc_from_headers   si    &&%? !=>>(&&%? !=>>mmG$xr5   c                    [        U R                  R                  SS5      5      nSU R                  ;   a  US[        U R                  S   5      -   -  nUR                  S5      nUR                  SS 5      nUS:X  a$  [        R
                  " U R                  5      SS	 nOUc  U R                  nO[        S
5      eUR                  U R                  XF5      u  pxn	XpR                  S'   XR                  S'   XR                  S'   g )NrD    rC   .rB   r   DEF   Unknown compressioniv
ciphertexttag)
r	   rH   r}   rP   zlibcompressrI   rU   encryptrQ   )
r.   r   r   rv   rC   r   datar   r   r   s
             r3   _encryptJWE._encrypt   s    t||//R@ADLL 3)$,,u*=>>>Cjj!66%&u==026D>>D233!kk$((C>T%/\"!Ur5   c                    U R                   c  [        S5      e[        U R                   [        5      (       d  [        S5      e[        U[        5      (       a  [        U5      nU R                  U5      nU R                  U5      u  pE0 nU(       a  X&S'   UR                  XR                  U R                  U5      nUS   U l
        SU;   a  US   US'   SU;   a=  [        UR                  SS5      5      nU R                  XS   5      n	[        U	5      US'   S	U R                  ;  a  U R                  XEU5        S
U R                  ;   a  U R                  S
   R!                  U5        gU R"                  (       a  SU R                  ;   d  SU R                  ;   a  / U R                  S
'   0 n
SU R                  ;   a  U R                  R%                  S5      U
S'   SU R                  ;   a  U R                  R%                  S5      U
S'   U R                  S
   R!                  U
5        U R                  S
   R!                  U5        gU R                  R'                  U5        gU/U R                  S
'   g)a  Encrypt the plaintext with the given key.

:param key: A JWK key or password of appropriate type for the 'alg'
 provided in the JOSE Headers.
:param header: A JSON string representing the per-recipient header.

:raises ValueError: if the plaintext is missing or not of type bytes.
:raises ValueError: if the compression type is unknown.
:raises InvalidJWAAlgorithm: if the 'alg' provided in the JOSE
 headers is missing or unknown, or otherwise not implemented.
NzMissing plaintextzPlaintext must be 'bytes'rF   rQ   ekencrypted_keyz{}r   
recipients)rI   rU   rN   rO   rS   r   rz   r   wrapwrap_key_sizerQ   r
   r}   rs   rH   r   appendrL   poprM   )r.   keyrF   rv   r   r   recwrappedhnhns              r3   rT   JWE.add_recipient   s    >>!011$..%00899fd## (F""6*11"5"M((3 1 1488R@5>7?#*4=C wCGGHd34A$$Q(9:B'OCMt||+MM#B'4<<'LL&--c2^^$,,.(dll2J-/\*"dll2)-)9)9/)JAo&t||+"&,,"2"28"<AhK\*11!4\*11#6##C(*-DLL&r5   c           
      :   SU R                   ;  a  [        S5      eU(       Ga  S H   nX R                   ;   d  M  [        SU-  5      e   SU R                   ;  a  [        S5      e[        U R                   S   5      nS H  nXC;  d  M
  [        SU-  5      e   S	U R                   ;   a:  [        U R                   S	   5      S
:w  a  [        S5      eU R                   S	   S   nOU R                   nSU;   a  [        US   5      n[        U R                   S   5      nU R	                  Xc5      n[        U5      U R                   S'   U R                  5       nU R                  U5      u  pU R                  XU5        US	 SR                  [        U R                   S   5      [        UR                  SS5      5      [        U R                   S   5      [        U R                   S   5      [        U R                   S   5      /5      $ U R                   n[        US   5      [        US   5      [        U R                   S   5      S.n
SU;   a  [        US   5      U
S'   SU;   a  [        US   5      U
S'   SU;   a  [        US   5      U
S'   S	U;   aV  / U
S	'   US	    HG  n0 nSU;   a  [        US   5      US'   SU;   a  [        US   5      US'   U
S	   R                  U5        MI     O.SU;   a  [        US   5      U
S'   SU;   a  [        US   5      U
S'   [        U
5      $ )a  Serializes the object into a JWE token.

:param compact(boolean): if True generates the compact
 representation, otherwise generates a standard JSON format.

:raises InvalidJWEOperation: if the object cannot be serialized
 with the compact representation and `compact` is True.
:raises InvalidJWEOperation: if no recipients have been added
 to the object.

:return: A json formatted string or a compact representation string
:rtype: `str`
r   No available ciphertext)rC   rE   z9Can't use compact encoding when the '%s' parameter is setrD   z4Can't use compact encoding without protected headers)r   r   z@Can't use compact encoding, '%s' must be in the protected headerr      zInvalid number of recipientsr   rF   r   r   r   r   r   )r   r   r   rE   rC   )rH   r\   r
   lenrs   r   rz   r   r   joinr	   r}   r   )r.   compactinvalidrw   requiredr   r   nphrv   r   r   objes                r3   	serializeJWE.serialize  s0    t||+%&?@@/ll*-!#*+, , 0
 $,,.)JL L !k!:; ,H)1/19:; ; !-
 t||+t||L12a7-.LMMll<03ll3
  H. k!:;))!0,7,<[)**,99"=c+M88-dll;.GH-cggor.JK-dll4.@A-dll<.HI-dll5.AB	D E E ,,C!1#l2C!D)#d)4*4<<+>?AC c!#3C4D#EK #%0]1C%DM"|-c%j9E
s"$&L!|,CA&#-,S-AB /*3&1#h-&@(%,,Q/ - #c)(_)=> (s?$/H$>CMs##r5   c                     U HL  nX R                   ;  a  [        SU-  5      eU R                   U   R                  (       a  M@  [        SU-  5      e   g )NzUnknown critical header: "%s"z!Unsupported critical header: "%s")rK   r(   	supported)r.   r   rr   s      r3   _check_critJWE._check_critj  sZ    A,,,$%Dq%HII++A.888( *023*4 5 5 r5   c
                     UR                  X2R                  XE5      n
UR                  XXxU	5      nU R                  R	                  S5        Xl        U$ )NSuccess)unwrapr   decryptrR   r   rQ   )r.   r   r   r   enckeyrF   rC   r   r   r   rQ   r   s               r3   _unwrap_decryptJWE._unwrap_decrypts  sF    jj//@{{3RS9y)r5   c                 r   U R                  UR                  SS 5      5      nU R                  UR                  S0 5      5        U H?  nXPR                  ;   d  M  U R                  R	                  XP5      (       a  M6  [        S5      e   U R                  UR                  SS 5      5      nU R                  UR                  SS 5      5      n[        U R                  R                  SS5      5      nSU R                  ;   a  US	[        U R                  S   5      -   -  nUR                  S
5      n[        U[        5      (       a  Un	SU R                  ;   aN  UR                  U R                  S   5      n
U
(       d'  [        SR!                  U R                  S   5      5      eU
n	U	 Hm  n U R#                  XgUUR                  SS5      XHU R                  S   U R                  S   U R                  S   5	      nU R$                  R'                  S5          O   SU R$                  ;  a  [        S5      eONU R#                  XgUUR                  SS5      XHU R                  S   U R                  S   U R                  S   5	      nUR                  SS 5      nUS:X  a  [/        W5      [0        :  a  [        SS[0         S3-   5      e[2        R4                  " [2        R6                  * S9nUR9                  X5      U l        UR<                  (       d  UR>                  (       d  S U l        [        SSU S3-   5      eg Uc  WU l        g [A        S5      e! [(         a`  nUR                  SUR+                  5       5      nU R$                  R'                  SR!                  U[-        U5      5      5         S nAGM  S nAff = f)NrF   r   zFailed header checkr   r   rD   r   rC   r   rB   r   zKey ID {} not in key setr   r5   r   r   r   r   zKey [{}] failed: [{}]zNo working key found in key setr   r   z+Compressed data exceeds maximum allowedsizez ())wbitsz2Compressed data exceeds maximum allowedoutput sizer   )!rz   r}   r   rK   check_headerr(   ra   re   r	   rH   rP   rN   r   jose_headerget_keysr   formatr   rR   r   	Exception
thumbprintreprr   default_max_compressed_sizer   decompressobj	MAX_WBITS
decompressrI   unconsumed_taileofrU   )r.   r   ppemax_plaintextrv   hdrr   r   rC   ro   kid_keysrr   r   r   keyidr   dos                    r3   _decryptJWE._decrypt|  se   ""3778T#:; 	+,C***++88CC()>?? 
 ud 34mmBFF5$/0t||//R@ADLL 3)$,,u*=>>>Cjj!c6""D(((<<(8(8(?@'(B(I(I(,(8(8(?)A B B<//!030M02d9K04\0J04U0C	ED
 OO**95  /#$EFF 0 ''#(+(E(*d1C(,\(B(,U(;	=D 66%&u4y66$!"=!>a@AB B ##4>>/:B]]4?DN!!!%$"&(q$9:; ; *0
 !DN233= ! <EE%8EOO**+B+I+I+0$q',; < <<s   )A)M
N6AN11N6c                    SU l         US:X  a  [        nSU R                  ;  a  [        S5      e/ U l        SnSU R                  ;   a(  U R                  S    H  n U R                  XUS9  M     O U R                  XR                  US9  U R                   (       d3  U(       a  [        S
5      e[        S[        U R                  5      -   5      eg! [         aI  n[        U[        5      (       a  SnU R                  R                  S	[        U5      -  5         SnAM  SnAff = f! [         aH  n[        U[        5      (       a  SnU R                  R                  S	[        U5      -  5         SnANSnAff = f)a  Decrypt a JWE token.

:param key: The (:class:`jwcrypto.jwk.JWK`) decryption key.
:param key: A (:class:`jwcrypto.jwk.JWK`) decryption key,
 or a (:class:`jwcrypto.jwk.JWKSet`) that contains a key indexed
 by the 'kid' header or (deprecated) a string containing a password.
:param max_plaintext: Maximum plaintext size allowed, 0 means
 the library default applies. Application writers are recommended
 to set a limit here if they know what is the max plaintext size
 for their application.

:raises InvalidJWEOperation: if the key is not a JWK object.
:raises InvalidJWEData: if the ciphertext can't be decrypted or
 the object is otherwise malformed.
:raises JWKeyNotFound: if key is a JWKSet and the key is not found.
Nr   r   r   Fr   )r   TzFailed: [%s]zKey Not found in JWKSetz%No recipient matched the provided key)rI   default_max_plaintext_sizerH   r\   rR   r   r   rN   r   r   r   r(   )r.   r   r   
missingkeyr   r   s         r3   r   JWE.decrypt  sT   $ A6Mt||+%&?@@
4<<'||L1EMM#-MH 2Ac<<}M ~~#$=>>  "')-doo)>"? @ @  ! E!!]33%)
OO**>DG+CDDE  Aa//!%J&&~Q'?@@As0   C1D& 
D#>DD#&
E80>E33E8c                 x   0 U l         SU l        SU l        0 n  [        U5      n[	        US   5      US'   [	        US   5      US'   [	        US   5      US'   SU;   a"  [	        US   5      nUR                  S5      US'   SU;   a  [        US   5      US'   SU;   a  [	        US   5      US'   S	U;   aV  / US	'   US	    HG  n0 nS
U;   a  [	        US
   5      US
'   SU;   a  [        US   5      US'   US	   R                  U5        MI     O.S
U;   a  [	        US
   5      US
'   SU;   a  [        US   5      US'   X0l         U(       a  U R                  U5        gg! [         a  nUR                  S5      n[        U5      S:w  a  [        5       Ue[	        US   5      nUR                  S5      US'   [	        US   5      n	U	S:w  a  [	        US   5      US
'   [	        US   5      US'   [	        US   5      US'   [	        US   5      US'    SnANSnAff = f! [         a  n[        S[        U5      5      UeSnAff = f)ad  Deserialize a JWE token.

NOTE: Destroys any current status and tries to import the raw
JWE provided.

If a key is provided a decryption step will be attempted after
the object is successfully deserialized.

:param raw_jwe: a 'raw' JWE token (JSON Encoded or Compact
 notation) string.
:param key: A (:class:`jwcrypto.jwk.JWK`) decryption key,
 or a (:class:`jwcrypto.jwk.JWKSet`) that contains a key indexed
 by the 'kid' header or (deprecated) a string containing a password
 (optional).

:raises InvalidJWEData: if the raw object is an invalid JWE token.
:raises InvalidJWEOperation: if the decryption fails.
Nr   r   r   rD   rB   rE   rC   r   r   rF   r      r   r   r5   r         zInvalid format)rH   rI   rQ   r
   r   decoder   r   rU   splitr   r(   r   r   r   )
r.   raw_jwer   odjwepr   r   r   ekeys
             r3   deserializeJWE.deserialize  sj   ( .	C(5"7+*4:6$"243E"F,+DK8%$&(k):;A%&XXg%6AkN D('243F'GAm$D=/U<AeH4'&(AlO#L1*c1 0_1E F o.#s?*5c(m*DAhK,..q1  2 '$.,T/-BC /*4'&1$x.&A( L
 LL %  5}}S)t9>(*1$T!W-!"'!2+'Q03;)9$q')BAo&*473$"247";,+DG4%5  	C !147;B	CsI   C/E 	H 
.E 8H 
H"B%HH HH 
H9H44H9c                 R    U R                   (       d  [        S5      eU R                   $ )NzPlaintext not available)rI   r\   rh   s    r3   payloadJWE.payload?  s    ~~%&?@@~~r5   c                     U R                  U R                  R                  S5      5      n[        U5      S:X  a  [	        S5      eU$ )NrF   r   zJOSE Header not available)rz   rH   r}   r   r\   )r.   rv   s     r3   r   JWE.jose_headerE  s=    ""4<<#3#3H#=>r7a<%&ABB	r5   c                 6    U " 5       nUR                  U5        U$ )zCreates a JWE object from a serialized JWE token.

:param token: A string with the json or compat representation
 of the token.

:raises InvalidJWEData: if the raw object is an invalid JWE token.

:return: A JWE token
:rtype: JWE
)r   )clstokenr   s      r3   from_jose_tokenJWE.from_jose_tokenL  s     e
r5   c                 >   [        U[        5      (       d  g U R                  5       UR                  5       :H  $ ! [         aY    SU R                  0nUR                  U R                  5        SUR                  0nUR                  UR                  5        X#:H  s $ f = f)NFrI   )rN   r?   r   r   rI   rM   rH   )r.   otherdata1data2s       r3   __eq__
JWE.__eq__]  s    %%%	">>#u'888 	" $..1ELL& %//2ELL'>!	"s    9 A BBc                 d     U R                  5       $ ! [         a    U R                  5       s $ f = fN)r   r   __repr__rh   s    r3   __str__JWE.__str__i  s/    	#>>## 	#==?"	#s    //c                 l    SU R                  5        S3$ ! [         a    [        U R                  5      nU R                  R                  S5      nU R                  R                  S5      nU R                  R                  S5      nU R                  nSU S3SU S3-   S	U S3-   S
U SU S3-   s $ f = f)NzJWE.from_json_token("z")rD   rE   rC   zJWE(plaintext=z, z
protected=zunprotected=zaad=z, algs=r   )r   r   r   rI   rH   r}   rG   )r.   rI   rD   rE   rC   rV   s         r3   r   JWE.__repr__o  s    	.*4>>+;*<B?? 		.T^^,I((5I,,**=9K,,""5)C%%D#I;b1	{"-.!+b12 #gdV1-. .		.s    BB32B3)rG   rQ   rR   rL   rK   rH   rI   )	NNNNNNNNTr   )F)r   )r7   r8   r9   r:   r;   r-   ra   re   propertyri   setterrs   rz   r   r   rT   r   r   r   r   r   r   r   r   r   classmethodr   r   r   r   r<   r6   r5   r3   r?   r?   N   s    
 DH=A151Nf%( 
( 
( " "
	"&8/tV$p5 0J D4L/@bJX  
     
"#.r5   r?   )r   jwcryptor   jwcrypto.commonr   r   r   r   r   r	   r
   r   jwcrypto.jwar   jwcrypto.jwkr   r   r   rJ   r[   r(   InvalidCEKeyLengthInvalidJWEKeyLengthInvalidJWEKeyTyper\   r?   r6   r5   r3   <module>r     sT     6 C > 4   ) . 
 {E4>5udDI6tTJ}eUDA~ueTBxd;{E5$?8%MCU$d,#$J$)5$8vudD9~udDA
D$= " *
%  !2[ 2& .. 00 ,, 00 m. m.r5   