Ë
    0]jÐ"  ã                   ó¶   — d dl Z d dlmZmZ d dlmZ d dlmZ d dlm	Z	 d dl
mZ d dlmZ d dlmZmZmZmZmZ  G d	„ d
e«      Z G d„ d«      Z G d„ dee«      Zy)é    N)ÚABCÚabstractmethod)ÚOptional)Úwarn)Úreverse)ÚNoReverseMatch)Úsettings)Úget_failure_limitÚ is_client_ip_address_blacklistedÚ is_client_ip_address_whitelistedÚis_client_method_whitelistedÚis_user_attempt_whitelistedc                   ój   — e Zd ZdZed	defd„«       Zed„ «       Zed„ «       Zed	de	e   de
fd„«       Zy)
ÚAbstractAxesHandlerz3
    Contract that all handlers need to follow
    NÚcredentialsc                 ó   — t        d«      ‚)zm
        Handles the Django ``django.contrib.auth.signals.user_login_failed`` authentication signal.
        z'user_login_failed should be implemented©ÚNotImplementedError©ÚselfÚsenderr   ÚrequestÚkwargss        úI/var/www/zogu/zoguvenv/lib/python3.12/site-packages/axes/handlers/base.pyÚuser_login_failedz%AbstractAxesHandler.user_login_failed   s   € ô
 "Ð"KÓLÐLó    c                 ó   — t        d«      ‚)zj
        Handles the Django ``django.contrib.auth.signals.user_logged_in`` authentication signal.
        z$user_logged_in should be implementedr   ©r   r   r   Úuserr   s        r   Úuser_logged_inz"AbstractAxesHandler.user_logged_in   s   € ô
 "Ð"HÓIÐIr   c                 ó   — t        d«      ‚)zk
        Handles the Django ``django.contrib.auth.signals.user_logged_out`` authentication signal.
        z%user_logged_out should be implementedr   r   s        r   Úuser_logged_outz#AbstractAxesHandler.user_logged_out&   s   € ô
 "Ð"IÓJÐJr   Úreturnc                 ó   — t        d«      ‚)a  
        Checks the number of failures associated to the given request and credentials.

        This is a virtual method that needs an implementation in the handler subclass
        if the ``settings.AXES_LOCK_OUT_AT_FAILURE`` flag is set to ``True``.
        z"get_failures should be implementedr   ©r   r   r   s      r   Úget_failuresz AbstractAxesHandler.get_failures-   s   € ô "Ð"FÓGÐGr   ©N)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   Údictr   r    r"   r   Úintr&   © r   r   r   r      s{   „ ñð ñM°Tò Mó ðMð ñJó ðJð ñKó ðKð ñH°¸$±ð HÈ3ò Hó ñHr   r   c            	       ó   — e Zd ZdZddee   defd„Zddee   defd„Zddee   defd„Z	ddee   defd„Z
dee   fd	„Zdefd
„Zdefd„Zddddœdee   dee   dedefd„Zddœdee   defd„Zddœdee   defd„Zddœdedee   defd„Zy)ÚAxesBaseHandlera‚  
    Handler API definition for implementations that are used by the ``AxesProxyHandler``.

    If you wish to specialize your own handler class, override the necessary methods
    and configure the class for use by setting ``settings.AXES_HANDLER = 'module.path.to.YourClass'``.
    Make sure that new the handler is compliant with AbstractAxesHandler and make sure it extends from this mixin.
    Refer to `AxesHandler` for an example.

    The default implementation that is actually used by Axes is ``axes.handlers.database.AxesDatabaseHandler``.

    .. note:: This is a virtual class and **can not be used without specialization**.
    Nr   r#   c                 óº   — t         j                  r| j                  |«      sy| j                  ||«      ry| j	                  ||«      ry| j                  ||«      ryy)aF  
        Checks if the user is allowed to access or use given functionality such as a login view or authentication.

        This method is abstract and other backends can specialize it as needed, but the default implementation
        checks if the user has attempted to authenticate into the site too many times through the
        Django authentication backends and returns ``False`` if user exceeds the configured Axes thresholds.

        This checker can implement arbitrary checks such as IP whitelisting or blacklisting,
        request frequency checking, failed attempt monitoring or similar functions.

        Please refer to the ``axes.handlers.database.AxesDatabaseHandler`` for the default implementation
        and inspiration on some common checks and access restrictions before writing your own implementation.
        TF)r	   ÚAXES_ONLY_ADMIN_SITEÚis_admin_requestÚis_blacklistedÚis_whitelistedÚ	is_lockedr%   s      r   Ú
is_allowedzAxesBaseHandler.is_allowedF   sW   € ô ×(Ò(°×1FÑ1FÀwÔ1OØà×Ñ˜w¨Ô4Øà×Ñ˜w¨Ô4Øà�>‰>˜' ;Ô/Øàr   c                 ó   — t        |«      ryy)zY
        Checks if the request or given credentials are blacklisted from access.
        TF)r   r%   s      r   r4   zAxesBaseHandler.is_blacklistedc   s   € ô
 ,¨GÔ4Øàr   c                 óN   — t        ||«      ryt        |«      ryt        |«      ryy)zX
        Checks if the request or given credentials are whitelisted for access.
        TF)r   r   r   r%   s      r   r5   zAxesBaseHandler.is_whitelistedm   s*   € ô
 ' w°Ô<Øä+¨GÔ4Øä'¨Ô0Øàr   c                 ób   — t         j                  r| j                  ||«      t        ||«      k\  S y)zH
        Checks if the request or given credentials are locked.
        F)r	   ÚAXES_LOCK_OUT_AT_FAILUREr&   r
   r%   s      r   r6   zAxesBaseHandler.is_locked}   s9   € ô
 ×,Ò,à×$Ñ$Ø˜óä" 7¨KÓ8ñ9ð 9ð r   c                 ó8   — 	 t        d«      S # t        $ r Y yw xY w)zE
        Returns admin url if exists, otherwise returns None
        úadmin:indexN)r   r   )r   s    r   Úget_admin_urlzAxesBaseHandler.get_admin_urlŠ   s$   € ð	Ü˜=Ó)Ð)øÜò 	Ùð	ús   ‚
 �	˜c                 ó’   — t        |d«      r;| j                  «       }|duxr% t        j                  d|› �|j                  «      duS y)z>
        Checks that request located under admin site
        ÚpathNú^F)Úhasattrr>   ÚreÚmatchr@   ©r   r   Ú	admin_urls      r   r3   z AxesBaseHandler.is_admin_request“   sQ   € ô �7˜FÔ#Ø×*Ñ*Ó,ˆIà Ð%ò HÜ—H‘H˜q  ˜_¨g¯l©lÓ;À4ÐGðð
 r   c                 óÚ   — t        dt        «       t        j                  r<t	        |d«      r0	 t        d«      }t        j                  d|› �|j                  «       S y# t        $ r Y yw xY w)zq
        Checks if the request is NOT for admin site
        if `settings.AXES_ONLY_ADMIN_SITE` is True.
        z³This method is deprecated and will be removed in future versions. If you looking for method that checks if `request.path` located under admin site, use `is_admin_request` instead.r@   r=   TrA   F)
r   ÚDeprecationWarningr	   r2   rB   r   r   rC   rD   r@   rE   s      r   Úis_admin_sitezAxesBaseHandler.is_admin_site    sp   € ô
 	ð>ô ô	
ô ×(Ò(¬W°W¸fÔ-EðÜ# MÓ2�	ô —x‘x ! I ; °·±Ó>Ð>Ð>àøô	 "ò Ùðús   ®A Á	A*Á)A*F)Ú
ip_addressÚusernameÚip_or_usernamerJ   rK   rL   c                 ó   — y)aZ  
        Resets access attempts that match the given IP address or username.

        This method makes more sense for the DB backend, but as it is used by the ProxyHandler
        (via inherent), it needs to be defined here, so we get compliant with all proxy methods.

        Please overwrite it on each specialized handler as needed.
        r   r.   )r   rJ   rK   rL   s       r   Úreset_attemptszAxesBaseHandler.reset_attempts¶   s   € ð r   )Úage_daysrO   c                 ó   — y)aS  
        Resets access logs that are older than given number of days.

        This method makes more sense for the DB backend, but as it is used by the ProxyHandler
        (via inherent), it needs to be defined here, so we get compliant with all proxy methods.

        Please overwrite it on each specialized handler as needed.
        r   r.   ©r   rO   s     r   Ú
reset_logszAxesBaseHandler.reset_logsÇ   ó   € ð r   c                 ó   — y)a[  
        Resets access failure logs that are older than given number of days.

        This method makes more sense for the DB backend, but as it is used by the ProxyHandler
        (via inherent), it needs to be defined here, so we get compliant with all proxy methods.

        Please overwrite it on each specialized handler as needed.
        r   r.   rQ   s     r   Úreset_failure_logsz"AxesBaseHandler.reset_failure_logsÒ   rS   r   )ÚlimitrV   c                 ó   — y)ay  Remove access failure logs that are over
        AXES_ACCESS_FAILURE_LOG_PER_USER_LIMIT for user username.

        This method makes more sense for the DB backend, but as it is used by the ProxyHandler
        (via inherent), it needs to be defined here, so we get compliant with all proxy methods.

        Please overwrite it on each specialized handler as needed.

        r   r.   )r   rK   rV   s      r   Ú remove_out_of_limit_failure_logsz0AxesBaseHandler.remove_out_of_limit_failure_logsÝ   s   € ð r   r'   )r(   r)   r*   r+   r   r,   Úboolr7   r4   r5   r6   Ústrr>   r3   rI   r-   rN   rR   rU   rX   r.   r   r   r0   r0   8   s*  „ ññ¨x¸©~ð Èó ñ:°8¸D±>ð ÈTó ñ°8¸D±>ð ÈTó ñ ¨h°t©nð Èó ð˜x¨™}ó ð¨4ó ð¨ó ð2 %)Ø"&Ø$òð ˜S‘Mðð ˜3‘-ð	ð
 ðð 
óð" 7;ò 	 h¨s¡mð 	¸só 	ð ?Cò 	¨h°s©mð 	Àsó 	ð 8<òØðØ'/°¡}ðà	ôr   r0   c                   óB   — e Zd ZdZd	defd„Zd„ Zd„ Zd	dee   de	fd„Z
y)
ÚAxesHandlerzI
    Signal bare handler implementation without any storage backend.
    Nr   c                  ó   — y r'   r.   r   s        r   r   zAxesHandler.user_login_failedñ   ó   € Ør   c                  ó   — y r'   r.   r   s        r   r    zAxesHandler.user_logged_inô   r^   r   c                  ó   — y r'   r.   r   s        r   r"   zAxesHandler.user_logged_out÷   r^   r   r#   c                  ó   — y)Nr   r.   r%   s      r   r&   zAxesHandler.get_failuresú   s   € Ør   r'   )r(   r)   r*   r+   r,   r   r    r"   r   r-   r&   r.   r   r   r\   r\   ì   s4   „ ññ°Tó òòñ°¸$±ð È3ô r   r\   )rC   Úabcr   r   Útypingr   Úwarningsr   Údjango.urlsr   Údjango.urls.exceptionsr   Ú	axes.confr	   Úaxes.helpersr
   r   r   r   r   r   r0   r\   r.   r   r   ú<module>ri      sO   ðÛ 	ß #Ý Ý å Ý 1å ÷õ ô"H˜#ô "H÷Jqñ qôhÐ% õ r   