Ë
    á]jV  ã            
       óª  — d dl mZ d dlZd dlZd dlmZ d dlmZ d dlmZ  e	d«      Z
ddgdgdgd	œZ e	d
«      Zdj                   e ed d«       edd«       edd«      «      D � cg c]
  }  e| «      ‘Œ c} «      Z ej"                  dez   dz   ej$                  «      ZdZ G d„ de«      Z G d„ d«      Zd„ Z G d„ dej2                  «      Zyc c} w )é    )ÚchainN)Úunescape)Úhtml5lib_shim)Ú
parse_shim)ÚaÚabbrÚacronymÚbÚ
blockquoteÚcodeÚemÚiÚliÚolÚstrongÚulÚhrefÚtitle)r   r   r	   )ÚhttpÚhttpsÚmailtoÚ é	   é   é   é   é    ú[ú]ú?c                   ó   — e Zd Zy)ÚNoCssSanitizerWarningN)Ú__name__Ú
__module__Ú__qualname__© ó    úG/var/www/zogu/zoguvenv/lib/python3.12/site-packages/bleach/sanitizer.pyr"   r"   5   s   „ Ør'   r"   c                   ó,   — e Zd ZdZeeeddddfd„Zd„ Zy)ÚCleanera¨  Cleaner for cleaning HTML fragments of malicious content

    This cleaner is a security-focused function whose sole purpose is to remove
    malicious content from a string such that it can be displayed as content in
    a web page.

    To use::

        from bleach.sanitizer import Cleaner

        cleaner = Cleaner()

        for text in all_the_yucky_things:
            sanitized = cleaner.clean(text)

    .. Note::

       This cleaner is not designed to use to transform content to be used in
       non-web-page contexts.

    .. Warning::

       This cleaner is not thread-safe--the html parser has internal state.
       Create a separate cleaner per thread!


    FTNc                 óT  — || _         || _        || _        || _        || _        |xs g | _        || _        t        j                  | j                   | j                  dd¬«      | _	        t        j                  d«      | _        t        j                  dddddd¬«      | _        |€…g }t        |t        «      r|}nOt        |t         «      r?g }|j#                  «       D ]*  }	t        |	t        t$        f«      sŒ|j'                  |	«       Œ, d|v rt)        j*                  d	t,        ¬
«       yyy)a8  Initializes a Cleaner

        :arg set tags: set of allowed tags; defaults to
            ``bleach.sanitizer.ALLOWED_TAGS``

        :arg dict attributes: allowed attributes; can be a callable, list or dict;
            defaults to ``bleach.sanitizer.ALLOWED_ATTRIBUTES``

        :arg set protocols: set of allowed protocols for links; defaults
            to ``bleach.sanitizer.ALLOWED_PROTOCOLS``

        :arg bool strip: whether or not to strip disallowed elements

        :arg bool strip_comments: whether or not to strip HTML comments

        :arg list filters: list of html5lib Filter classes to pass streamed content through

            .. seealso:: http://html5lib.readthedocs.io/en/latest/movingparts.html#filters

            .. Warning::

               Using filters changes the output of ``bleach.Cleaner.clean``.
               Make sure the way the filters change the output are secure.

        :arg CSSSanitizer css_sanitizer: instance with a "sanitize_css" method for
            sanitizing style attribute values and style text; defaults to None

        F)ÚtagsÚstripÚconsume_entitiesÚnamespaceHTMLElementsÚetreeÚalwaysT)Úquote_attr_valuesÚomit_optional_tagsÚescape_lt_in_attrsÚresolve_entitiesÚsanitizeÚalphabetical_attributesNÚstylez7'style' attribute specified, but css_sanitizer not set.)Úcategory)r,   Ú
attributesÚ	protocolsr-   Ústrip_commentsÚfiltersÚcss_sanitizerr   ÚBleachHTMLParserÚparserÚgetTreeWalkerÚwalkerÚBleachHTMLSerializerÚ
serializerÚ
isinstanceÚlistÚdictÚvaluesÚtupleÚextendÚwarningsÚwarnr"   )
Úselfr,   r:   r;   r-   r<   r=   r>   Úattributes_valuesrH   s
             r(   Ú__init__zCleaner.__init__V   s'  € ðL ˆŒ	Ø$ˆŒØ"ˆŒØˆŒ
Ø,ˆÔØ’} "ˆŒØ*ˆÔä#×4Ñ4Ø—‘Ø—*‘*Ø"Ø"'ô	
ˆŒô $×1Ñ1°'Ó:ˆŒÜ'×<Ñ<Ø&Ø$Ø#ð #àà$)ô
ˆŒð Ð ð !#ÐÜ˜*¤dÔ+Ø$.Ñ!ä˜J¬Ô-Ø$&Ð!Ø(×/Ñ/Ó1ò 9�FÜ! &¬4´¨-Õ8Ø)×0Ñ0°Õ8ð9ð Ð+Ñ+Ü—‘ØMÜ2öð ,ð !r'   c           	      óÒ  — t        |t        «      s(d|j                  j                  ›d�dz   }t	        |«      ‚|sy| j
                  j                  |«      }t        | j                  |«      | j                  | j                  | j                  | j                  | j                  | j                  ¬«      }| j                  D ]  } ||¬«      }Œ | j                   j#                  |«      S )zÐCleans text and returns sanitized result as unicode

        :arg str text: text to be cleaned

        :returns: sanitized text as unicode

        :raises TypeError: if ``text`` is not a text type

        zargument cannot be of z type, zmust be of text typer   )ÚsourceÚallowed_tagsr:   Ústrip_disallowed_tagsÚstrip_html_commentsr>   Úallowed_protocols)rQ   )rE   ÚstrÚ	__class__r#   Ú	TypeErrorr@   ÚparseFragmentÚBleachSanitizerFilterrB   r,   r:   r-   r<   r>   r;   r=   rD   Úrender)rM   ÚtextÚmessageÚdomÚfilteredÚfilter_classs         r(   ÚcleanzCleaner.clean«   sÓ   € ô ˜$¤Ô$à(¨¯©×)@Ñ)@Ð(CÀ7ÐKØ(ñ)ð ô ˜GÓ$Ð$áØà�k‰k×'Ñ'¨Ó-ˆÜ(Ø—;‘;˜sÓ#ØŸ™Ø—‘Ø"&§*¡*Ø $× 3Ñ 3Ø×,Ñ,Ø"Ÿn™nô
ˆð !ŸL™Lò 	5ˆLÙ#¨8Ô4‰Hð	5ð �‰×%Ñ% hÓ/Ð/r'   )	r#   r$   r%   Ú__doc__ÚALLOWED_TAGSÚALLOWED_ATTRIBUTESÚALLOWED_PROTOCOLSrO   ra   r&   r'   r(   r*   r*   9   s*   „ ñð< Ø%Ø#ØØØØóSój#0r'   r*   c                 ó�   ‡ — t        ‰ «      r‰ S t        ‰ t        «      rˆ fd„}|S t        ‰ t        «      rˆ fd„}|S t	        d«      ‚)a0  Generates attribute filter function for the given attributes value

    The attributes value can take one of several shapes. This returns a filter
    function appropriate to the attributes value. One nice thing about this is
    that there's less if/then shenanigans in the ``allow_token`` method.

    c                 ó�   •— | ‰v r‰|    }t        |«      r
 || ||«      S ||v ryd‰v r‰d   }t        |«      r
 || ||«      S ||v S y)NTÚ*F)Úcallable)ÚtagÚattrÚvalueÚattr_valr:   s       €r(   Ú_attr_filterz.attribute_filter_factory.<locals>._attr_filterÞ   sl   ø€ Ø�jÑ Ø% c™?�Ü˜HÔ%Ù# C¨¨uÓ5Ð5à˜8Ñ#Øà�jÑ Ø% c™?�Ü˜HÔ%Ù# C¨¨uÓ5Ð5à˜xÐ'Ð'àr'   c                 ó   •— |‰v S ©Nr&   )rj   rk   rl   r:   s      €r(   rn   z.attribute_filter_factory.<locals>._attr_filterô   s   ø€ Ø˜:Ð%Ð%r'   z3attributes needs to be a callable, a list or a dict)ri   rE   rG   rF   Ú
ValueError)r:   rn   s   ` r(   Úattribute_filter_factoryrr   Ñ   sM   ø€ ô �
ÔØÐä�*œdÔ#ô	ð$ Ðä�*œdÔ#ô	&ð Ðä
ÐJÓ
KÐKr'   c            	       ó–   — e Zd ZdZeeeej                  ej                  ej                  dddf	d„Zd„ Zd„ Zd„ Zd	„ Zd
„ Zd„ Zd„ Zd„ Zy)rZ   zmhtml5lib Filter that sanitizes text

    This filter can be used anywhere html5lib filters can be used.

    FTNc                 óø   — t         j                  j                  | |«       t        |«      | _        t        |«      | _        t        |«      | _        || _        |	| _	        || _
        || _        |
| _        || _        y)a]  Creates a BleachSanitizerFilter instance

        :arg source: html5lib TreeWalker stream as an html5lib TreeWalker

        :arg set allowed_tags: set of allowed tags; defaults to
            ``bleach.sanitizer.ALLOWED_TAGS``

        :arg dict attributes: allowed attributes; can be a callable, list or dict;
            defaults to ``bleach.sanitizer.ALLOWED_ATTRIBUTES``

        :arg set allowed_protocols: set of allowed protocols for links; defaults
            to ``bleach.sanitizer.ALLOWED_PROTOCOLS``

        :arg attr_val_is_uri: set of attributes that have URI values

        :arg svg_attr_val_allows_ref: set of SVG attributes that can have
            references

        :arg svg_allow_local_href: set of SVG elements that can have local
            hrefs

        :arg bool strip_disallowed_tags: whether or not to strip disallowed
            tags

        :arg bool strip_html_comments: whether or not to strip HTML comments

        :arg CSSSanitizer css_sanitizer: instance with a "sanitize_css" method for
            sanitizing style attribute values and style text; defaults to None

        N)r   ÚFilterrO   Ú	frozensetrR   rU   rr   Úattr_filterrS   rT   Úattr_val_is_uriÚsvg_attr_val_allows_refr>   Úsvg_allow_local_href)rM   rQ   rR   r:   rU   rx   ry   rz   rS   rT   r>   s              r(   rO   zBleachSanitizerFilter.__init__  ss   € ô` 	×Ñ×%Ñ% d¨FÔ3ä% lÓ3ˆÔÜ!*Ð+<Ó!=ˆÔä3°JÓ?ˆÔØ%:ˆÔ"Ø#6ˆÔ à.ˆÔØ'>ˆÔ$Ø*ˆÔØ$8ˆÕ!r'   c              #   ó„   K  — |D ]5  }| j                  |«      }|sŒt        |t        «      r|E d {  –—†  Œ2|–— Œ7 y 7 Œ­wrp   )Úsanitize_tokenrE   rF   )rM   Útoken_iteratorÚtokenÚrets       r(   Úsanitize_streamz%BleachSanitizerFilter.sanitize_streamA  sF   è ø€ Ø#ò 		ˆEØ×%Ñ% eÓ,ˆCáØä˜#œtÔ$Ø—‘à“	ñ		ð ús   ‚/A ±>²A c              #   óP  K  — g }|D ]h  }|rF|d   dk(  r|j                  |«       Œdj                  |D �cg c]  }|d   ‘Œ	 c}«      ddœ}g }|–— n|d   dk(  r|j                  |«       Œe|–— Œj dj                  |D �cg c]  }|d   ‘Œ	 c}«      ddœ}|–— yc c}w c c}w ­w)z/Merge consecutive Characters tokens in a streamÚtypeÚ
Charactersr   Údata)r„   r‚   N)ÚappendÚjoin)rM   r}   Úcharacters_bufferr~   Ú
char_tokenÚ	new_tokens         r(   Úmerge_charactersz&BleachSanitizerFilter.merge_charactersM  sÓ   è ø€ àÐà#ò 	ˆEÙ Ø˜‘= LÒ0Ø%×,Ñ,¨UÔ3Øð
 !#§¡ØBSÖT°J˜Z¨Ó/ÒTó!ð !-ñ	!�Ið )+Ð%Ø#“Oà�v‘ ,Ò.Ø!×(Ñ(¨Ô/Øà‹Kð+	ð0 —G‘GÐBSÖT°J˜Z¨Ó/ÒTÓUØ ñ
ˆ	ð ‹ùò# Uùò Uùs   ‚3B&µB
ÁA B&ÂB!ÂB&c                 ó|   — | j                  | j                  t        j                  j	                  | «      «      «      S rp   )rŠ   r€   r   ru   Ú__iter__)rM   s    r(   rŒ   zBleachSanitizerFilter.__iter__n  s4   € Ø×$Ñ$Ø× Ñ ¤×!5Ñ!5×!>Ñ!>¸tÓ!DÓEó
ð 	
r'   c                 ó,  — |d   }|dv r@|d   | j                   v r| j                  |«      S | j                  ry| j                  |«      S |dk(  r/| j                  s"t        j                  |d   ddd	œ¬
«      |d<   |S y|dk(  r| j                  |«      S |S )aÕ  Sanitize a token either by HTML-encoding or dropping.

        Unlike sanitizer.Filter, allowed_attributes can be a dict of {'tag':
        ['attribute', 'pairs'], 'tag': callable}.

        Here callable is a function with two arguments of attribute name and
        value. It should return true of false.

        Also gives the option to strip tags instead of encoding.

        :arg dict token: token to sanitize

        :returns: token or list of tokens

        r‚   )ÚStartTagÚEndTagÚEmptyTagÚnameNÚCommentr„   z&quot;z&#x27;)ú"ú')Úentitiesrƒ   )rR   Úallow_tokenrS   Údisallowed_tokenrT   r   ÚescapeÚsanitize_characters)rM   r~   Ú
token_types      r(   r|   z$BleachSanitizerFilter.sanitize_tokens  sµ   € ð  ˜6‘]ˆ
ØÐ;Ñ;Ø�V‰} × 1Ñ 1Ñ1Ø×'Ñ'¨Ó.Ð.à×+Ò+Øð ×,Ñ,¨UÓ3Ð3à˜9Ò$Ø×+Ò+ä -× 4Ñ 4Ø˜&‘M°(ÀÑ,Jô!��f‘ð �àà˜<Ò'Ø×+Ñ+¨EÓ2Ð2ð ˆLr'   c                 óÞ  — |j                  dd«      }|s|S t        j                  t        |«      }||d<   d|vr|S g }t	        j
                  |«      D ]—  }|sŒ|j                  d«      rmt	        j                  |«      }|�V|dk(  r|j                  dddœ«       n|j                  d|d	œ«       |t        |«      d
z   d }|r|j                  d|dœ«       Œ„|j                  d|dœ«       Œ™ |S )a½  Handles Characters tokens

        Our overridden tokenizer doesn't do anything with entities. However,
        that means that the serializer will convert all ``&`` in Characters
        tokens to ``&amp;``.

        Since we don't want that, we extract entities here and convert them to
        Entity tokens so the serializer will let them be.

        :arg token: the Characters token to work on

        :returns: a list of tokens

        r„   r   ú&NÚamprƒ   )r‚   r„   ÚEntity)r‚   r‘   é   )
ÚgetÚINVISIBLE_CHARACTERS_REÚsubÚINVISIBLE_REPLACEMENT_CHARr   Únext_possible_entityÚ
startswithÚmatch_entityr…   Úlen)rM   r~   r„   Ú
new_tokensÚpartÚentityÚ	remainders          r(   r™   z)BleachSanitizerFilter.sanitize_charactersž  s  € ð �y‰y˜ Ó$ˆáØˆLä&×*Ñ*Ô+EÀtÓLˆØˆˆf‰ð �d‰?ØˆLàˆ
ô "×6Ñ6°tÓ<ò 	DˆDÙØà�‰˜sÔ#Ü&×3Ñ3°DÓ9�ØÐ%Ø ’ð #×)Ñ)°<ÈÑ*MÕNà"×)Ñ)°8ÀVÑ*LÔMð !%¤S¨£[°1¡_Ð%6Ð 7�IÙ Ø"×)Ñ)°<ÈÑ*SÔTØà×Ñ |¸TÑBÕCð5	Dð8 Ðr'   c                 ó   — t        j                  |«      }t        j                  dd|«      }t        j                  dd|«      }|j	                  «       }	 t        j                  |«      }|j                  r|j                  |v r|S y|j                  d«      r|S d|v r|j                  d«      d   |v r|S d|v sd	|v r|S y# t        $ r Y yw xY w)
zÄChecks a uri value to see if it's allowed

        :arg value: the uri value to sanitize
        :arg allowed_protocols: set of allowed protocols

        :returns: allowed value or None

        z[`\000-\040\177-\240\s]+r   z[^\x00-\x7f]Nú#ú:r   r   r   )r   Úconvert_entitiesÚrer¢   Úlowerr   Úurlparserq   Úschemer¥   Úsplit)rM   rl   rU   Únormalized_uriÚparseds        r(   Úsanitize_uri_valuez(BleachSanitizerFilter.sanitize_uri_valueÛ  sð   € ô '×7Ñ7¸Ó>ˆô Ÿ™Ð ;¸RÀÓPˆô
 Ÿ™ °°^ÓDˆð (×-Ñ-Ó/ˆð	ô  ×(Ñ(¨Ó8ˆFð
 �=Š=à�}‰}Ð 1Ñ1Ø�ð& ð ×(Ñ(¨Ô-Ø�ð �~Ñ%Ø"×(Ñ(¨Ó-¨aÑ0Ð4EÑEà�ð Ð*Ñ*¨gÐ9JÑ.JØ�àøô5 ò 	áð	ús   ÁC Ã	CÃCc                 ób  — d|v �r)i }|d   j                  «       D �]  \  }}|\  }}| j                  |d   ||«      sŒ#|| j                  v r!| j                  || j                  «      }|€ŒP|}|| j
                  v r5t        j                  ddt        |«      «      }|j                  «       }|sŒ“|}d|d   f| j                  v r0|dt        j                  d   dffv rt        j                  d	|«      rŒØ|d
k(  r*| j                  r| j                  j                  |«      }nd}|||<   �Œ ||d<   |S )z-Handles the case where we're allowing the tagr„   r‘   Nzurl\s*\(\s*[^#\s][^)]+?\)ú )Nr   Úxlinkr   z
^\s*[^#\s])Nr8   r   )Úitemsrw   rx   r·   rU   ry   r°   r¢   r   r-   rz   r   Ú
namespacesÚsearchr>   Úsanitize_css)	rM   r~   ÚattrsÚnamespaced_nameÚvalÚ	namespacer‘   Ú	new_valueÚnew_vals	            r(   r–   z!BleachSanitizerFilter.allow_token  sh  € à�UŠ?ð ˆEØ(-¨f©×(;Ñ(;Ó(=ó 5-Ñ$� Ø"1‘�	˜4ð ×'Ñ'¨¨f©°t¸SÔAØð # d×&:Ñ&:Ñ:Ø $× 7Ñ 7¸¸T×=SÑ=SÓ T�IØ Ð(Ø Ø#�Cð # d×&BÑ&BÑBÜ Ÿf™fÐ%AÀ3ÌÐQTËÓV�GØ%Ÿm™m›o�GÙ"Ø ð
 &˜ð ˜% ™-Ð(¨D×,EÑ,EÑEØ&Ø&Ü&×1Ñ1°'Ñ:¸FÐCð+ñ ô Ÿ9™9 ]°CÔ8Ø$ð # oÒ5Ø×)Ò)Ø"×0Ñ0×=Ñ=¸cÓB™ð !˜ð *-��oÓ&ðk5-ðn "ˆE�&‰Màˆr'   c                 óÊ  — |d   }|dk(  rd|d   › d�|d<   n¤|d   r“|dv sJ ‚g }|d   j                  «       D ]W  \  \  }}}|r|s||}}|�|t        j                  vr|}nt        j                  |   › d|› �}|j                  d	|› d
|› d�«       ŒY d|d   › dj	                  |«      › d�|d<   nd|d   › d�|d<   |j                  d«      r|d   d d › d�|d<   d|d<   |d= |S )Nr‚   r�   z</r‘   ú>r„   )rŽ   r�   r®   r¹   z="r“   ú<r   ÚselfClosingéÿÿÿÿz/>rƒ   )r»   r   Úprefixesr…   r†   r    )rM   r~   rš   r¿   Únsr‘   ÚvrÀ   s           r(   r—   z&BleachSanitizerFilter.disallowed_token[  sE  € Ø˜6‘]ˆ
Ø˜Ò!Ø   v¡ ¨qÐ1ˆE�&ŠMà�6Š]ØÐ!9Ñ9Ð9Ð9ØˆEØ!& v¡×!4Ñ!4Ó!6ò :‘‘
��T˜Añ ™dØ# R˜�Bð �: ¬=×+AÑ+AÑ!AØ&*‘Oä)6×)?Ñ)?ÀÑ)CÐ(DÀAÀdÀVÐ&L�Oð
 —‘˜q Ð 1°°A°3°aÐ8Õ9ð!:ð"    f¡˜¨r¯w©w°u«~Ð.>¸aÐ@ˆE�&ŠMð    f¡˜¨aÐ0ˆE�&‰Mà�9‰9�]Ô#Ø$ V™}¨S¨bÐ1Ð2°"Ð5ˆE�&‰Mà$ˆˆf‰à�&ˆMØˆr'   )r#   r$   r%   rb   rc   rd   re   r   rx   ry   rz   rO   r€   rŠ   rŒ   r|   r™   r·   r–   r—   r&   r'   r(   rZ   rZ   ü   sj   „ ñð "Ø%Ø+Ø%×5Ñ5Ø -× EÑ EØ*×?Ñ?Ø#Ø Øó<9ò|
òòB
ò
)òV;òz9òvCóJ$r'   rZ   )Ú	itertoolsr   r°   rK   Úxml.sax.saxutilsr   Úbleachr   r   rv   rc   rd   re   r†   ÚrangeÚchrÚINVISIBLE_CHARACTERSÚcompileÚUNICODEr¡   r£   ÚUserWarningr"   r*   rr   ÚSanitizerFilterrZ   )Úcs   0r(   ú<module>rØ      s÷   ðÝ Û 	Û å %å  Ý ñ ðó€ð( �'Ð	ØˆIØˆyñÐ ñ Ð9Ó:Ð ð —w‘wÙ™5  A›;©¨b°"«±u¸RÀ³}ÓEÖF��Sˆ…VÒFóÐ ð
 %˜"Ÿ*™* SÐ+?Ñ%?À#Ñ%EÀrÇzÁzÓRÐ ð !Ð ô	˜Kô 	÷U0ñ U0òp(LôVC˜M×9Ñ9õ Cùòe Gs   Á'C