/usr/local/lib/python3.6/site-packages/urllib3/contrib/__pycache__
NameSizeModeActions
appengine.cpython-36.pyc81070644editdlrm
ntlmpool.cpython-36.pyc35440644editdlrm
pyopenssl.cpython-36.pyc156800644editdlrm
securetransport.cpython-36.pyc214270644editdlrm
socks.cpython-36.pyc55190644editdlrm
_appengine_environ.cpython-36.pyc13580644editdlrm
__init__.cpython-36.pyc1490644editdlrm
Edit: /usr/local/lib/python3.6/site-packages/urllib3/contrib/__pycache__/securetransport.cpython-36.pyc (21427B)
3 Eg&@sdZddlmZddlZddlZddlZddlZddlZddl Z ddl Z ddl Z ddl Z ddl Z ddlmZddlmZddlmZdd lmZmZmZdd lmZmZmZmZmZmZydd l mZWn$e k rdZdd l!m"Z"YnXd dgZ#dZ$ej$Z%ej&j'Z(e j)Z*e j+Z,dZ-ej.ej/ej0ej1ej2ej3ej4ej5ej6ej7ej8ej9ej:ej;ejej?ej@ejAejBejCejDejEejFejGejHejIejJejKgZLejMejNejOfeejNejOfiZPeQe drejRejRfePe jS<eQe drejTejTfePe jU<eQe drejNejNfePe jV<eQe dr.ejWejWfePe jX<eQe drLejOejOfePe jY<dd ZZddZ[ddZ\ddZ]ej^e\Z_ej`e]ZaGdddebZcerd%ddZdn d&d!dZdedec_dGd"d#d#ebZedS)'a SecureTranport support for urllib3 via ctypes. This makes platform-native TLS available to urllib3 users on macOS without the use of a compiler. This is an important feature because the Python Package Index is moving to become a TLSv1.2-or-higher server, and the default OpenSSL that ships with macOS is not capable of doing TLSv1.2. The only way to resolve this is to give macOS users an alternative solution to the problem, and that solution is to use SecureTransport. We use ctypes here because this solution must not require a compiler. That's because pip is not allowed to require a compiler either. This is not intended to be a seriously long-term solution to this problem. The hope is that PEP 543 will eventually solve this issue for us, at which point we can retire this contrib module. But in the short term, we need to solve the impending tire fire that is Python on Mac without this kind of contrib module. So...here we are. To use this module, simply import and inject it:: import urllib3.contrib.securetransport urllib3.contrib.securetransport.inject_into_urllib3() Happy TLSing! This code is a bastardised version of the code found in Will Bond's oscrypto library. An enormous debt is owed to him for blazing this trail for us. For that reason, this code should be considered to be covered both by urllib3's license and by oscrypto's: .. code-block:: Copyright (c) 2015-2016 Will Bond Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. )absolute_importN)util)six)PROTOCOL_TLS_CLIENT)CoreFoundationSecurity SecurityConst)_assert_no_error_build_tls_unknown_ca_alert_cert_array_from_pem_create_cfstring_array_load_client_cert_chain_temporary_keychain) _fileobject)backport_makefileinject_into_urllib3extract_from_urllib3Ti@PROTOCOL_SSLv2PROTOCOL_SSLv3PROTOCOL_TLSv1PROTOCOL_TLSv1_1PROTOCOL_TLSv1_2cCs.tt_ttj_tt_ttj_dt_dtj_dS)zG Monkey-patch urllib3 with SecureTransport-backed SSL-support. TN)SecureTransportContextr SSLContextssl_HAS_SNIIS_SECURETRANSPORTrrI/usr/local/lib/python3.6/site-packages/urllib3/contrib/securetransport.pyrs cCs.tt_ttj_tt_ttj_dt_dtj_dS)z> Undo monkey-patching by :func:`inject_into_urllib3`. FN)orig_util_SSLContextrrrorig_util_HAS_SNIrrrrrr rs c Csxd}y8tj|}|dkr tjS|j}|d}|j}d}d}y|xv||kr|dksZ|dkrttj||sttjt j d||} t j | j ||} |j| | } || 7}| sB|stjSPqBWWnhtjk r"} zH| j }|dk o|t j kr||d<|t jks |t jkrtjSWYdd} ~ XnX||d<||kr bytes_readrErrr recv@s   zWrappedSocket.recvNc Cs|jr dS|dkrt|}tj|j|}tjd}|jtj|j ||tj |}WdQRX|t j kr|j dkrtjdn"|t jt jfkr|jnt||j S)Nrzrecv timed out)rKrVr,r- from_bufferc_size_trUr ZSSLReadrIrxr r4ryr&r<r0ZerrSSLClosedNoNotifyrSr )rQr>nbytesprocessed_bytesrYrrr r/Fs$       zWrappedSocket.recv_intocCs ||_dS)N)rO)rQr<rrr rPqszWrappedSocket.settimeoutcCs|jS)N)rO)rQrrr r'tszWrappedSocket.gettimeoutc Cshtjd}|j"tj|j|t|tj|}WdQRX|tj krZ|j dkrZt j dnt ||j S)Nrzsend timed out)r,rrUr ZSSLWriterIrVrxr r4ryr&r<r )rQrErrYrrr rDws  " zWrappedSocket.sendcCs8d}x.|t|kr2|j|||t}||7}qWdS)Nr)rVrDSSL_WRITE_BLOCKSIZE)rQrE total_sentrFrrr rbszWrappedSocket.sendallc Cs$|jtj|jWdQRXdS)N)rUr ZSSLCloserI)rQrrr shutdowns zWrappedSocket.shutdowncCs|jdkrd|_|jr(tj|jd|_|jr@tj|jd|_|jrvtj|jtj|jt j |j d|_|_ |j j S|jd8_dS)NrT)rJrKrIrr\rNrLr ZSecKeychainDeleteshutilrmtreerMr&rS)rQrrr rSs        zWrappedSocket.closeFc Cs|s tdtj}d}d}ztj|jtj|}t||sBdStj|}|sTdStj |d}|sht tj |}|szt t j |}t j|} tj| |}Wd|rt j||rt j|X|S)Nz2SecureTransport only supports dumping binary certsr) ValueErrorr rvrwrIr,rxr ZSecTrustGetCertificateCountZSecTrustGetCertificateAtIndexAssertionErrorZSecCertificateCopyDatarZCFDataGetLengthZCFDataGetBytePtrrBr\) rQ binary_formr{ZcertdataZ der_bytesrYZ cert_countZleafZ data_lengthr8rrr getpeercerts2       zWrappedSocket.getpeercertcCstj}tj|jtj|}t||jtj krt|\|_|_d|_d|_d|_d|_d|_d|_d|_ dS)NrF) _protocol_to_min_max _min_version _max_version_options_verify _trust_bundle _client_cert _client_key_client_key_passphrase_alpn_protocols)rQrrrr rRszSecureTransportContext.__init__cCsdS)z SecureTransport cannot have its hostname checking disabled. For more, see the comment on getpeercert() in this file. Tr)rQrrr check_hostname!sz%SecureTransportContext.check_hostnamecCsdS)z SecureTransport cannot have its hostname checking disabled. For more, see the comment on getpeercert() in this file. Nr)rQryrrr r)scCs|jS)N)r)rQrrr options1szSecureTransportContext.optionscCs ||_dS)N)r)rQryrrr r;scCs|jr tjStjS)N)rrh CERT_REQUIRED CERT_NONE)rQrrr verify_mode@sz"SecureTransportContext.verify_modecCs|tjkrdnd|_dS)NTF)rhrr)rQryrrr rDscCsdS)Nr)rQrrr set_default_verify_pathsHs z/SecureTransportContext.set_default_verify_pathscCs|jS)N)r)rQrrr load_default_certsTsz)SecureTransportContext.load_default_certscCs|tjjkrtddS)Nz5SecureTransport doesn't support custom cipher strings)rrDEFAULT_CIPHERSr)rQrXrrr set_ciphersWs z"SecureTransportContext.set_ciphersNc Cs:|dk rtd|dk r,t|WdQRX|p2||_dS)Nz1SecureTransport does not support cert directories)rrtr)rQcafilecapathcadatarrr load_verify_locations\s   z,SecureTransportContext.load_verify_locationscCs||_||_||_dS)N)rrZ_client_cert_passphrase)rQcertfilekeyfilepasswordrrr load_cert_chainhsz&SecureTransportContext.load_cert_chaincCs&ttdstddd|D|_dS)z Sets the ALPN protocols that will later be set on the context. Raises a NotImplementedError if ALPN is not supported. r[z2SecureTransport supports ALPN only in macOS 10.12+cSsg|]}tj|qSr)r ensure_binary).0prrr wsz=SecureTransportContext.set_alpn_protocols..N)hasattrr NotImplementedErrorr)rQr]rrr set_alpn_protocolsms z)SecureTransportContext.set_alpn_protocolsFTc CsP| s t|st|stt|}|j||j|j|j|j|j|j|j |j |S)N) rrHrrrrrrrrr)rQsock server_sidedo_handshake_on_connectsuppress_ragged_eofsrr:rrr wrap_socketys z"SecureTransportContext.wrap_socket)NNN)NN)FTTN)rrrrrRpropertyrsetterrrrrrrrrrrrrr rs$     r)r)rN)fr __future__rrr,r*os.pathrqrr&rhrc threadingweakrefrpackagesrZ util.ssl_rZ_securetransport.bindingsrr r Z_securetransport.low_levelr r r rrrr ImportErrorZpackages.backports.makefiler__all__rr"rrr!WeakValueDictionaryr#Lockr~rZ'TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384Z'TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256Z%TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384Z%TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256Z-TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256Z+TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256Z#TLS_DHE_RSA_WITH_AES_256_GCM_SHA384Z#TLS_DHE_RSA_WITH_AES_128_GCM_SHA256Z'TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384Z$TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHAZ'TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256Z$TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHAZ%TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384Z"TLS_ECDHE_RSA_WITH_AES_256_CBC_SHAZ%TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256Z"TLS_ECDHE_RSA_WITH_AES_128_CBC_SHAZ#TLS_DHE_RSA_WITH_AES_256_CBC_SHA256Z TLS_DHE_RSA_WITH_AES_256_CBC_SHAZ#TLS_DHE_RSA_WITH_AES_128_CBC_SHA256Z TLS_DHE_RSA_WITH_AES_128_CBC_SHAZTLS_AES_256_GCM_SHA384ZTLS_AES_128_GCM_SHA256ZTLS_RSA_WITH_AES_256_GCM_SHA384ZTLS_RSA_WITH_AES_128_GCM_SHA256ZTLS_AES_128_CCM_8_SHA256ZTLS_AES_128_CCM_SHA256ZTLS_RSA_WITH_AES_256_CBC_SHA256ZTLS_RSA_WITH_AES_128_CBC_SHA256ZTLS_RSA_WITH_AES_256_CBC_SHAZTLS_RSA_WITH_AES_128_CBC_SHArW PROTOCOL_TLSrrrrrrrrrrrrrrrArGZ SSLReadFuncr|Z SSLWriteFuncr}objectrHrrrrrr 5s            76  <