HEX
Server: nginx/1.30.4
System: Linux d-twindigital-web-1.host-ed.eu 4.18.0-553.141.2.el8_10.x86_64 #1 SMP Wed Jul 8 10:28:18 EDT 2026 x86_64
User: u_twindigital_html (1009)
PHP: 8.3.30
Disabled: NONE
Upload Files
File: //lib/python3.6/site-packages/S3/__pycache__/ConnMan.cpython-36.pyc
3

@tJ[�+�@s�ddlmZddlZejdkr,ddlmZnddlmZddlZddlm	Z	ddl
mZyddlmZWn e
k
r�ddlmZYnXdd	lmZdd
lmZddlmZdejkr�Gd
d�de�ZnejZdgZGdd�de�ZGdd�de�ZdS)�)�absolute_importN��)�httplib)�	Semaphore)�debug)�urlparse)�Config)�ParameterError)�getBucketFromHostname�CertificateErrorc@seZdZdS)rN)�__name__�
__module__�__qualname__�rr�/usr/lib/python3.6/ConnMan.pyrs�ConnManc@s^eZdZdZdZedd��Zedd��Zedd��Zd	d
�Z	dd�Z
edd
d��Zdd�ZdS)�http_connectionNFcCsNt�}d}ytj|d�}Wntk
r.YnX|rJ|jrJd|_td�|S)N)�cafileFz+Disabling SSL certificate hostname checking)r	�sslZcreate_default_context�AttributeError�check_ssl_hostname�check_hostnamer)r�cfg�contextrrr�_ssl_verified_context*sz%http_connection._ssl_verified_contextcCs:td�d}ytj|tjd�}Wntk
r4YnX|S)Nz"Disabling SSL certificate checking)rZ	cert_reqs)rrZ_create_unverified_contextZ	CERT_NONEr)rrrrr�_ssl_unverified_context8sz'http_connection._ssl_unverified_contextcCsZtjrtjSt�}|j}|dkr$d}td|�|jr@tj|�}n
tj|�}|t_dt_|S)N�zUsing ca_certs_file %sT)	r�context_setrr	Z
ca_certs_filer�check_ssl_certificaterr)rrrrrr�_ssl_contextCs

zhttp_connection._ssl_contextcCs�td�|jdf�}|j�}tdtj�j}x�|D]�\}}|dkr2|j�}|jd�rh|jd�rh|jd�s||jd�r�|jd�r�dS||d	tj	j�d
�kr2|j|dtj	j�d
��r2dSq2WdS)
a�
        Wildcard matching for *.s3.amazonaws.com and similar per region.

        Per http://docs.aws.amazon.com/AmazonS3/latest/dev/BucketRestrictions.html:
        "We recommend that all bucket names comply with DNS naming conventions."

        Per http://docs.aws.amazon.com/AmazonS3/latest/dev/VirtualHosting.html:
        "When using virtual hosted-style buckets with SSL, the SSL
        wild card certificate only matches buckets that do not contain
        periods. To work around this, use HTTP or write your own
        certificate verification logic."

        Therefore, we need a custom validation routine that allows
        mybucket.example.com.s3.amazonaws.com to be considered a valid
        hostname for the *.s3.amazonaws.com wildcard cert, and for the
        region-specific *.s3-[region].amazonaws.com wildcard cert.

        We also forgive non-S3 wildcard certificates should the
        hostname match, to allow compatibility with other S3
        API-compatible storage providers.
        z6checking SSL subjectAltName as forgiving wildcard certZsubjectAltNamezhttps://ZDNSz*.s3z.amazonaws.comz.amazonaws.com.cnT�*)Zbucket�locationrF)
r�get�lowerrr	Zhost_bucket�hostname�
startswith�endswithZbucket_location)�self�certr%ZsanZcleaned_host_bucket_config�key�valuerrr�forgive_wildcard_certWs"
z%http_connection.forgive_wildcard_certcCs||jjj�}ytj||j�WnXtk
r2dStk
rDdStk
rv}z|j	||j�sf|�WYdd}~XnXdS)N)
�c�sockZgetpeercertr�match_hostnamer%r�
ValueErrorrr,)r(r)�errrr/szhttp_connection.match_hostnamecCs�yftj�}t|�\}}|r:d|kr:td�d}|rJd|_n|rF|j}nd}tj||||d�}td�WnZtk
r�ytj|||d�}td�Wn(tk
r�tj||�}td	�YnXYnX|S)
N�.zHBucket name contains "." character, disabling initial SSL hostname checkFT)rrz=httplib.HTTPSConnection() has both context and check_hostname)rz*httplib.HTTPSConnection() has only contextz@httplib.HTTPSConnection() has neither context nor check_hostname)rr rrrrZHTTPSConnection�	TypeError)r%�portrZbucket_name�successr�connrrr�_https_connection�s*z!http_connection._https_connectioncCs0||_||_d|_td|�}|j|_|j|_|jrZ|jdkrZ|jjd�|_td|j�nd|_|j	s�|r�t
j|j|j�|_td|j|j�n"t
j|j|j�|_td|j|j�nz|�r
t
j|j	|j�|_td|j	|j�|jr�|jp�d}|jj|j|�td	|j|�n"t
j|j	|j�|_td
|j	|j�dS)Nrzhttps://�/zendpoint path set to %sz#non-proxied HTTPSConnection(%s, %s)z"non-proxied HTTPConnection(%s, %s)zproxied HTTPSConnection(%s, %s)i�ztunnel to %s, %szproxied HTTPConnection(%s, %s))r�id�counterrr%r4�path�rstripr�
proxy_hostrr7r-rZHTTPConnection�
proxy_portZ
set_tunnel)r(r9r%rrZparsed_hostnamer4rrr�__init__�s0zhttp_connection.__init__)N)
r
rrrr�staticmethodrrr r,r/r7r?rrrrr&s($rc@s@eZdZejZejZe�ZiZdZ	e
ddd��Ze
dd��ZdS)ri NcCs
t�}|dkr|j}d}|jdkrJ|r8tjdkr8td��d|j|jf}nd|rTdpVd|f}tjj	�|tj
kr|gtj
|<ttj
|�r�tj
|j�}t
d|j|jf�tjj�|s�t
d|�t||||�}|jj�|jr�|jr�|jr�|j�|jd	7_|S)
Nriz6use_https=True can't be used with proxy on Python <2.7z
proxy://%s:%szhttp%s://%s�sz)ConnMan.get(): re-using connection: %s#%dz*ConnMan.get(): creating new connection: %sr)r	Z	use_httpsr=�sys�
hexversionr
r>r�
conn_pool_sem�acquire�	conn_pool�len�poprr9r:�releaserr-�connectrrrr/)r%rrr6Zconn_idrrrr#�s0





zConnMan.getcCs�|jjd�r"|jj�td�dS|jtjkrD|jj�td�dStjj	�tj
|jj|�tjj�td|j|jf�dS)Nzproxy://zFConnMan.put(): closing proxy connection (keep-alive not yet supported)z+ConnMan.put(): closing over-used connectionz2ConnMan.put(): connection put back to pool (%s#%d))
r9r&r-�closerr:r�conn_max_counterrDrErF�appendrI)r6rrr�puts



zConnMan.put)N)
r
rrrZ_CS_REQ_SENTZCONTINUErrDrFrLr@r#rNrrrrr�s)rr)Z
__future__rrB�version_infoZCustom_httplib3xrZCustom_httplib27r�	threadingr�loggingrr�ImportErrorZurllib.parser	Z
Exceptionsr
ZUtilsr�__dict__�	Exceptionr�__all__�objectrrrrrr�<module>	s*

;