Ë
    M/Åeš2  ã                   ó   — d Z ddlZddlZddlZddlmZ ddlmZ ddlmZ ddlm	Z	 ddlm
Z
 ddlmZ dd	lmZ dd
lmZ ddlmZ ddlZddlmZ ddlmZ ddlmZ ddlmZ ddlmZ 	 ddlmZ ddlmZ ddlmZ  ej>                  e «      Z! G d„ d«      Z"de#dee#ef   dee#ef   deee	e#ef   f   fd„Z$ G d„ dejJ                  «      Z& G d„ d«      Z' ee e'ejP                  e    «      «      ejP                  e <   y# e$ r	 dZdZdZY Œ’w xY w)z;Common code for DNS Authenticator Plugins built on Lexicon.é    N)Ú
ModuleType)ÚAny)Úcast)ÚDict)ÚList)ÚMapping)ÚOptional)ÚTuple)ÚUnion)Ú	HTTPError)ÚRequestException)Úconfiguration)Úerrors)Ú
dns_common)ÚClient)ÚConfigResolver)ÚProviderc                   ó´   — e Zd ZdZdd„Zdedededdfd„Zdedededdfd	„Zdeddfd
„Zde	dede
ej                     fd„Zdedede
ej                     fd„Zy)ÚLexiconClientzº
    Encapsulates all communication with a DNS provider via Lexicon.

    .. deprecated:: 2.7.0
       Please use certbot.plugins.dns_common_lexicon.LexiconDNSAuthenticator instead.
    ÚreturnNc                 ó   — |  y ©N© ©Úselfs    úD/usr/lib/python3/dist-packages/certbot/plugins/dns_common_lexicon.pyÚ__init__zLexiconClient.__init__0   s   € Úó    ÚdomainÚrecord_nameÚrecord_contentc                 óþ   — | j                  |«       	 | j                  j                  d||¬«       y# t        $ rA}t        j                  d|d¬«       t        j                  dj                  |«      «      ‚d}~ww xY w)a§  
        Add a TXT record using the supplied information.

        :param str domain: The domain to use to look up the managed zone.
        :param str record_name: The record name (typically beginning with '_acme-challenge.').
        :param str record_content: The record content (typically the challenge validation).
        :raises errors.PluginError: if an error occurs communicating with the DNS Provider API
        ÚTXT©ÚrtypeÚnameÚcontentú'Encountered error adding TXT record: %sT©Úexc_infoúError adding TXT record: {0}N)	Ú_find_domain_idÚproviderÚcreate_recordr   ÚloggerÚdebugr   ÚPluginErrorÚformat©r   r   r    r!   Úes        r   Úadd_txt_recordzLexiconClient.add_txt_record3   st   € ð 	×Ñ˜VÔ$ð	OØ�M‰M×'Ñ'¨e¸+È~Ð'Õ^øÜò 	OÜ�L‰LÐBÀAÐPTˆLÔUÜ×$Ñ$Ð%C×%JÑ%JÈ1Ó%MÓNÐNûð	Oús   “2 ²	A<»<A7Á7A<c                 ó2  — 	 | j                  |«       	 | j
                  j                  d||¬«       y# t        j                  $ r"}t        j	                  d|d¬«       Y d}~yd}~ww xY w# t        $ r"}t        j	                  d|d¬«       Y d}~yd}~ww xY w)a«  
        Delete a TXT record using the supplied information.

        :param str domain: The domain to use to look up the managed zone.
        :param str record_name: The record name (typically beginning with '_acme-challenge.').
        :param str record_content: The record content (typically the challenge validation).
        :raises errors.PluginError: if an error occurs communicating with the DNS Provider  API
        ú7Encountered error finding domain_id during deletion: %sTr)   Nr#   r$   ú)Encountered error deleting TXT record: %s)r,   r   r1   r/   r0   r-   Údelete_recordr   r3   s        r   Údel_txt_recordzLexiconClient.del_txt_recordD   s“   € ð	Ø× Ñ  Ô(ð	XØ�M‰M×'Ñ'¨e¸+È~Ð'Õ^øô ×!Ñ!ò 	Ü�L‰LÐRÐTUØ"&ð ô (äûð	ûô  ò 	XÜ�L‰LÐDÀaÐRVˆL×WÑWûð	Xús,   ‚3 ”A+ ³A(ÁA#Á#A(Á+	BÁ4BÂBc                 óä  — t        j                  |«      }|D ]_  }	 t        | j                  d«      r|| j                  j                  d<   n|| j                  _        | j                  j                  «         y t        j                  dj                  ||«      «      ‚# t        $ r }| j                  ||«      }|r|‚Y d}~Œ«d}~wt        $ r }| j                  ||«      }|r|‚Y d}~ŒÒd}~ww xY w)zÆ
        Find the domain_id for a given domain.

        :param str domain: The domain for which to find the domain_id.
        :raises errors.PluginError: if the domain_id cannot be found.
        Úoptionsr   NúAUnable to determine zone identifier for {0} using zone names: {1})r   Úbase_domain_name_guessesÚhasattrr-   r<   r   Úauthenticater   Ú_handle_http_errorÚ	ExceptionÚ_handle_general_errorr   r1   r2   ©r   r   Údomain_name_guessesÚdomain_namer4   Úresult1Úresult2s          r   r,   zLexiconClient._find_domain_idY   sì   € ô )×AÑAÀ&ÓIÐà.ò 	"ˆKð"Ü˜4Ÿ=™=¨)Ô4à6A�D—M‘M×)Ñ)¨(Ò3ð ,7�D—M‘MÔ(à—‘×*Ñ*Ô,áð	"ô. × Ñ Ð!dß"(¡&¨Ð1DÓ"EóGð 	Gøô ò "Ø×1Ñ1°!°[ÓA�áØ!�Mô ûäò "Ø×4Ñ4°Q¸ÓD�áØ!�Mô ûð"ús$   œABÂ	C/Â(CÃC/ÃC*Ã*C/r4   rF   c                 óL   — t        j                  dj                  ||«      «      S ©Nz/Error determining zone identifier for {0}: {1}.©r   r1   r2   ©r   r4   rF   s      r   rA   z LexiconClient._handle_http_error}   ó$   € Ü×!Ñ!Ð"Sß#)¡6¨+°qÓ#9ó;ð 	;r   c                 ó‚   — t        |«      j                  d«      s%t        j                  dj	                  ||«      «      S y ©NzNo domain foundz9Unexpected error determining zone identifier for {0}: {1}©ÚstrÚ
startswithr   r1   r2   rL   s      r   rC   z#LexiconClient._handle_general_error�   ó:   € Ü�1‹v× Ñ Ð!2Ô3Ü×%Ñ%Ð&aß'-¡v¨k¸1Ó'=ó?ð ?àr   ©r   N)Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   rQ   r5   r:   r,   r   r	   r   r1   rA   rB   rC   r   r   r   r   r   (   s¼   „ ñó ðO Sð O°sð OÈCð OÐTXó Oð"X Sð X°sð XÈCð XÐTXó Xð*"G cð "G¨dó "GðH; Ið ;¸Cð ;ÀHÈV×M_ÑM_ÑD`ó ;ð yð ¸sð ÀxÐPV×PbÑPbÑGcô r   r   Úlexicon_provider_nameÚlexicon_optionsÚprovider_optionsr   c                 óÜ   — d| i}|j                  |«       t        €|j                  |«       |S i }|j                  |«       ||| <   t        «       j                  |«      j                  «       S )aá  
    Convenient function to build a Lexicon 2.x/3.x config object.

    :param str lexicon_provider_name: the name of the lexicon provider to use
    :param dict lexicon_options: options specific to lexicon
    :param dict provider_options: options specific to provider
    :return: configuration to apply to the provider
    :rtype: ConfigurationResolver or dict

    .. deprecated:: 2.7.0
       Please use certbot.plugins.dns_common_lexicon.LexiconDNSAuthenticator instead.
    Úprovider_name)Úupdater   Ú	with_dictÚwith_env)rY   rZ   r[   Úconfig_dictÚprovider_configs        r   Úbuild_lexicon_configrc   ˆ   sv   € ð $3Ð4IÐ"J€KØ×Ñ�Ô'ÜÐà×ÑÐ+Ô,ØÐð +-ˆØ×ÑÐ/Ô0Ø-<ˆÐ)Ñ*ÜÓ×)Ñ)¨+Ó6×?Ñ?ÓAÐAr   c                   óV  ‡ — e Zd ZdZdej
                  defˆ fd„Zee	j                  defd„«       «       Zedefd„«       Zded	ed
eddfd„Zdedefd„Zdd„Zdedededdfd„Zdedededdfd„Zdedefd„Zdededeej0                     fd„Zdededeej0                     fd„Zˆ xZS )ÚLexiconDNSAuthenticatorzr
    Base class for a DNS authenticator that uses Lexicon client
    as backend to execute DNS record updates
    Úconfigr&   c                 ó8   •— t         ‰| �  ||«       g | _        |  y r   )Úsuperr   Ú_provider_options)r   rf   r&   Ú	__class__s      €r   r   z LexiconDNSAuthenticator.__init__«   s   ø€ Ü‰Ñ˜ Ô&Ø=?ˆÔÚr   r   c                  ó   — y)z9
        The name of the Lexicon provider to use
        Nr   r   s    r   Ú_provider_namez&LexiconDNSAuthenticator._provider_name°   s   � r   c                  ó   — y)zX
        Time to live to apply to the DNS records created by this Authenticator
        é<   r   r   s    r   Ú_ttlzLexiconDNSAuthenticator._ttl·   s   € ð
 r   Úcreds_var_nameÚcreds_var_labelÚlexicon_provider_option_nameNc                 ó@   — | j                   j                  |||f«       y r   )ri   Úappend)r   rp   rq   rr   s       r   Ú_add_provider_optionz,LexiconDNSAuthenticator._add_provider_option¾   s"   € à×Ñ×%Ñ%Ø˜_Ð.JÐKõ	Mr   r   c                 óV  — t        | d«      s| j                  «        d|d|d| j                  d| j                  | j                  | j                  D �ci c]$  }|d   | j
                  j                  |d   «      “Œ& c}i}t        «       j                  |«      j                  «       S c c}w )NÚ_credentialsr   Ú	delegatedr]   Úttlé   r   )
r?   Ú_setup_credentialsrl   ro   ri   rw   Úconfr   r_   r`   )r   r   ÚitemÚdict_configs       r   Ú_build_lexicon_configz-LexiconDNSAuthenticator._build_lexicon_configÃ   s«   € Ü�t˜^Ô,Ø×#Ñ#Ô%ð �fð ˜Ø˜T×0Ñ0Ø�4—9‘9Ø×ÑØ.2×.DÑ.Dö"FØ&*ð #' q¡'¨4×+<Ñ+<×+AÑ+AÀ$ÀqÁ'Ó+JÑ"Jò "Fð

ˆô Ó×)Ñ)¨+Ó6×?Ñ?ÓAÐAùò"Fs   Á)B&c           
      óš   — | j                  dd| j                  › d�| j                  D �ci c]  }|d   |d   “Œ c}¬«      | _        y c c}w )NÚcredentialszCredentials INI file for z DNS authenticatorr   é   )ÚkeyÚlabelÚrequired_variables)Ú_configure_credentialsrl   ri   rw   )r   r}   s     r   r{   z*LexiconDNSAuthenticator._setup_credentialsÔ   sX   € Ø ×7Ñ7ØØ-¨d×.AÑ.AÐ-BÐBTÐUØ=A×=SÑ=SÖT°T  Q¡¨¨a©Ñ 0ÒTð 8ó 
ˆÕùò  Us   ªAÚvalidation_nameÚ
validationc                 óH  — | j                  |«      }	 t        | j                  |«      «      5 }|j                  d||¬«       d d d «       y # 1 sw Y   y xY w# t        $ rA}t
        j                  d|d¬«       t        j                  dj                  |«      «      ‚d }~ww xY w)Nr#   r$   r(   Tr)   r+   )
Ú_resolve_domainr   r   r.   r   r/   r0   r   r1   r2   )r   r   r‡   rˆ   Úresolved_domainÚ
operationsr4   s          r   Ú_performz LexiconDNSAuthenticator._performÛ   sž   € Ø×.Ñ.¨vÓ6ˆð	OÜ˜×2Ñ2°?ÓCÓDð `È
Ø×(Ñ(¨u¸?ÐT^Ð(Ô_÷`÷ `ñ `ûäò 	OÜ�L‰LÐBÀAÐPTˆLÔUÜ×$Ñ$Ð%C×%JÑ%JÈ1Ó%MÓNÐNûð	Oús4   “A ­AÁA ÁAÁA ÁA Á	B!Á <BÂB!c                 ó|  — 	 | j                  |«      }	 t        | j                  |«      «      5 }|j                  d||¬«       d d d «       y # t        j                  $ r"}t        j	                  d|d¬«       Y d }~y d }~ww xY w# 1 sw Y   y xY w# t        $ r"}t        j	                  d|d¬«       Y d }~y d }~ww xY w)Nr7   Tr)   r#   r$   r8   )	rŠ   r   r1   r/   r0   r   r   r9   r   )r   r   r‡   rˆ   r‹   r4   rŒ   s          r   Ú_cleanupz LexiconDNSAuthenticator._cleanupå   sÄ   € ð	Ø"×2Ñ2°6Ó:ˆOð	XÜ˜×2Ñ2°?ÓCÓDð `È
Ø×(Ñ(¨u¸?ÐT^Ð(Ô_÷`ð `øô ×!Ñ!ò 	Ü�L‰LÐRÐTUØ"&ð ô (äûð	ú÷`ð `ûäò 	XÜ�L‰LÐDÀaÐRVˆL×WÑWûð	XúsK   ‚A ”B ®BÁB ÁBÁA<Á<BÂBÂ	B ÂB Â	B;ÂB6Â6B;c                 ó”  — t        j                  |«      }|D ]*  }	 t        | j                  |«      «      5  |cd d d «       c S  t        j                  dj                  ||«      «      ‚# 1 sw Y   nxY wŒ_# t        $ r }| j                  ||«      }|r|‚Y d }~Œƒd }~wt        $ r }| j                  ||«      }|r|‚Y d }~Œªd }~ww xY w)Nr=   )r   r>   r   r   r   rA   rB   rC   r   r1   r2   rD   s          r   rŠ   z'LexiconDNSAuthenticator._resolve_domainó   sÜ   € Ü(×AÑAÀ&ÓIÐà.ò 	"ˆKð"ô ˜D×6Ñ6°{ÓCÓDñ 'Ø&÷'ó 'ð		"ô" × Ñ Ð!dß"(¡&¨Ð1DÓ"EóGð 	G÷'ð 'úð 'øäò "Ø×1Ñ1°!°[ÓA�áØ!�Mô ûäò "Ø×4Ñ4°Q¸ÓD�áØ!�Mô ûð"ús9   œA7¶A*¸	A7Á*A3	Á/A7Á7	CÂ BÂCÂ'CÃCr4   rF   c                 óL   — t        j                  dj                  ||«      «      S rJ   rK   rL   s      r   rA   z*LexiconDNSAuthenticator._handle_http_error
  rM   r   c                 ó‚   — t        |«      j                  d«      s%t        j                  dj	                  ||«      «      S y rO   rP   rL   s      r   rC   z-LexiconDNSAuthenticator._handle_general_error  rS   r   rT   )rU   rV   rW   rX   r   ÚNamespaceConfigrQ   r   ÚpropertyÚabcÚabstractmethodrl   Úintro   ru   r   r   r{   r�   r�   rŠ   r   r	   r   r1   rA   rB   rC   Ú__classcell__)rj   s   @r   re   re   ¥   sU  ø„ ñð
?˜}×<Ñ<ð ?ÀCõ ?ð
 Ø×Ñð ò ó ó ðð
 ð�cò ó ððM°3ð MÈð MØ;>ðMØCGóMð
B¨Cð B°Nó Bó"
ðO˜sð O°Sð OÀcð OÈdó OðX˜sð X°Sð XÀcð XÈdó XðG cð G¨có Gð.; Ið ;¸Cð ;ÀHÈV×M_ÑM_ÑD`ó ;ð yð ¸sð ÀxÐPV×PbÑPbÑGc÷ r   re   c                   ób   — e Zd ZdZdefd„Zdedefd„Zdededdfd	„Z	dedefd
„Z
dee   fd„Zy)Ú_DeprecationModulez”
    Internal class delegating to a module, and displaying warnings when attributes
    related to deprecated attributes in the current module.
    Úmodulec                 ó"   — || j                   d<   y ©NÚ_module)Ú__dict__)r   r›   s     r   r   z_DeprecationModule.__init__  s   € Ø#)ˆ�‰�iÒ r   Úattrr   c                 ó‚   — |dv r&t        j                  |› dt        › d�t        d¬«       t	        | j
                  |«      S )N)r   rc   z attribute in z/ module is deprecated and will be removed soon.rz   )Ú
stacklevel)ÚwarningsÚwarnrU   ÚDeprecationWarningÚgetattrrž   ©r   r    s     r   Ú__getattr__z_DeprecationModule.__getattr__   sC   € ØÐ<Ñ<Ü�M‰M˜T˜F .´°
ð ;6ð 6ä,¸õ<ô �t—|‘| TÓ*Ð*r   ÚvalueNc                 ó2   — t        | j                  ||«       y r   )Úsetattrrž   )r   r    r©   s      r   Ú__setattr__z_DeprecationModule.__setattr__'  s   € Ü�—‘˜d EÕ*r   c                 ó0   — t        | j                  |«       y r   )Údelattrrž   r§   s     r   Ú__delattr__z_DeprecationModule.__delattr__*  s   € Ü�—‘˜dÕ#r   c                 ó4   — dgt        | j                  «      z   S r�   )Údirrž   r   s    r   Ú__dir__z_DeprecationModule.__dir__-  s   € Øˆ{œS §¡Ó.Ñ.Ð.r   )rU   rV   rW   rX   r   r   rQ   r   r¨   r¬   r¯   r   r²   r   r   r   rš   rš     sc   „ ñð*˜zó *ð+ ð +¨ó +ð+ ð +¨Cð +°Dó +ð$ ð $¨ó $ð/˜˜c™ô /r   rš   ))rX   r•   ÚloggingÚsysÚtypesr   Útypingr   r   r   r   r   r	   r
   r   r£   Úrequests.exceptionsr   r   Úcertbotr   r   Úcertbot.pluginsr   Úlexicon.clientr   Úlexicon.configr   Úlexicon.interfacesr   ÚImportErrorÚ	getLoggerrU   r/   r   rQ   rc   ÚDNSAuthenticatorre   rš   Úmodulesr   r   r   ú<module>rÁ      s#  ðÙ AÛ 
Û Û 
Ý Ý Ý Ý Ý Ý Ý Ý Ý Û å )Ý 0å !Ý Ý &ðÝ%Ý-Ý+ð 
ˆ×	Ñ	˜8Ó	$€÷]ñ ]ð@B°ð BØ*1°#°s°(Ñ*;ðBØOVÐWZÐ\_ÐW_ÑO`ðBà# N°D¸¸c¸±NÐ$BÑCóBô:m˜j×9Ñ9ô m÷f/ñ /ñ4 ˜ZÑ);¸C¿K¹KÈÑ<QÓ)RÓS€‡�ˆHÒ øðe ò Ø€FØ€NØ‚Hðús   Á(C? Ã?DÄD