Ë
    ¸2Úiº*  ã                   óÂ   — d dl mZ d dlmZ d dlmZmZ d dlmZm	Z	 d dl
mZ  e«       Zd dl
mZmZ d dlmZ  G d„ d	«      Z G d
„ d«      Z G d„ d«      Z G d„ d«      Zy)é    )ÚIterable)Úsettings)Úlogin_requiredÚREDIRECT_FIELD_NAME)ÚImproperlyConfiguredÚPermissionDenied)Úget_user_obj_perms_model)Úget_40x_or_NoneÚget_anonymous_user)Úget_objects_for_userc                   ó>   ‡ — e Zd ZdZeZej                  Zˆ fd„Z	ˆ xZ
S )ÚLoginRequiredMixinay  
    A login required mixin for use with class based views. This Class is a
    light wrapper around the `login_required` decorator and hence function
    parameters are just attributes defined on the class.

    Due to parent class order traversal this mixin must be added as the left
    most mixin of a view.

    The mixin has exactly the same flow as `login_required` decorator:

        If the user isn't logged in, redirect to ``settings.LOGIN_URL``, passing
        the current absolute path in the query string. Example:
        ``/accounts/login/?next=/polls/3/``.

        If the user is logged in, execute the view normally. The view code is
        free to assume the user is logged in.

    **Class Settings**

    ``LoginRequiredMixin.redirect_field_name``

        *Default*: ``'next'``

    ``LoginRequiredMixin.login_url``

        *Default*: ``settings.LOGIN_URL``

    c                 óv   •—   t        | j                  | j                  ¬«      t        ‰| �  «      |g|¢­i |¤ŽS )N)Úredirect_field_nameÚ	login_url)r   r   r   ÚsuperÚdispatch)ÚselfÚrequestÚargsÚkwargsÚ	__class__s       €úF/var/www/html/acx/venv/lib/python3.12/site-packages/guardian/mixins.pyr   zLoginRequiredMixin.dispatch,   sS   ø€ ð
ð 8Œ~°$×2JÑ2JØ(,¯©ô8ä‰GÑó
ð ð$ð ò$ð #ñ$ð 	$ó    )Ú__name__Ú
__module__Ú__qualname__Ú__doc__r   r   r   Ú	LOGIN_URLr   r   Ú__classcell__©r   s   @r   r   r      s%   ø„ ñð8 .ÐØ×"Ñ"€I÷$ð $r   r   c                   ór   ‡ — e Zd ZdZej
                  ZdZeZ	dZ
dZdZdZdZd	d„Zd„ Zd„ Zd	d„Zˆ fd„Zˆ xZS )
ÚPermissionRequiredMixinaÄ  
    A view mixin that verifies if the current logged in user has the specified
    permission by wrapping the ``request.user.has_perm(..)`` method.

    If a `get_object()` method is defined either manually or by including
    another mixin (for example ``SingleObjectMixin``) or ``self.object`` is
    defined then the permission will be tested against that specific instance,
    alternatively you can specify `get_permission_object()` method if ``self.object``
    or `get_object()` does not return the object against you want to test permission

    .. note:
       Testing of a permission against a specific object instance requires an
       authentication backend that supports. Please see ``django-guardian`` to
       add object level permissions to your project.

    The mixin does the following:

        If the user isn't logged in, redirect to settings.LOGIN_URL, passing
        the current absolute path in the query string. Example:
        /accounts/login/?next=/polls/3/.

        If the `raise_exception` is set to True than rather than redirect to
        login page a `PermissionDenied` (403) is raised.

        If the user is logged in, and passes the permission check than the view
        is executed normally.

    **Example Usage**::

        class SecureView(PermissionRequiredMixin, View):
            ...
            permission_required = 'auth.change_user'
            ...

    **Class Settings**

    ``PermissionRequiredMixin.permission_required``

        *Default*: ``None``, must be set to either a string or list of strings
        in format: *<app_label>.<permission_codename>*.

    ``PermissionRequiredMixin.login_url``

        *Default*: ``settings.LOGIN_URL``

    ``PermissionRequiredMixin.redirect_field_name``

        *Default*: ``'next'``

    ``PermissionRequiredMixin.return_403``

        *Default*: ``False``. Returns 403 error page instead of redirecting
        user.

    ``PermissionRequiredMixin.return_404``

        *Default*: ``False``. Returns 404 error page instead of redirecting
        user.

    ``PermissionRequiredMixin.raise_exception``

        *Default*: ``False``

        `permission_required` - the permission to check of form "<app_label>.<permission codename>"
                                i.e. 'polls.can_vote' for a permission on a model in the polls application.

    ``PermissionRequiredMixin.accept_global_perms``

        *Default*: ``False``,  If accept_global_perms would be set to True, then
         mixing would first check for global perms, if none found, then it will
         proceed to check object level permissions.

    ``PermissionRequiredMixin.permission_object``
         *Default*: ``(not set)``, object against which test the permission; if not set fallback
         to ``self.get_permission_object()`` which return ``self.get_object()``
         or ``self.object`` by default.

    ``PermissionRequiredMixin.any_perm``

        *Default*: ``False``. if True, any of permission in sequence is accepted.

    NFc                 óø   — t        | j                  t        «      r| j                  g}|S t        | j                  t        «      r| j                  D �cg c]  }|‘Œ }}|S t	        d| j                  z  «      ‚c c}w ©a  
        Returns list of permissions in format *<app_label>.<codename>* that
        should be checked against *request.user* and *object*. By default, it
        returns list from ``permission_required`` attribute.

        :param request: Original request.
        zŽ'PermissionRequiredMixin' requires 'permission_required' attribute to be set to '<app_label>.<permission codename>' but is set to '%s' instead©Ú
isinstanceÚpermission_requiredÚstrr   r   ©r   r   ÚpermsÚps       r   Úget_required_permissionsz0PermissionRequiredMixin.get_required_permissions�   óˆ   € ô �d×.Ñ.´Ô4Ø×-Ñ-Ð.ˆEð ˆô ˜×0Ñ0´(Ô;Ø $× 8Ñ 8Ö9˜1’QÐ9ˆEÐ9ð ˆô	 'ð (hð *.×)AÑ)Añ(Bó Cð Cùò :ó   Á	A7c                 óŒ   — t        | d«      r| j                  S t        | d«      xr | j                  «       xs t        | dd «      S )NÚpermission_objectÚ
get_objectÚobject)Úhasattrr1   r2   Úgetattr)r   s    r   Úget_permission_objectz-PermissionRequiredMixin.get_permission_object£   sE   € Ü�4Ð,Ô-Ø×)Ñ)Ð)Ü˜˜lÓ+ÒA°·±Ó0Aò .Ü˜˜h¨Ó-ð	/r   c                 ó@  — | j                  «       }t        || j                  |«      || j                  | j                  | j
                  | j                  | j                  | j                  ¬«	      }|r| j                  |||¬«       |r| j                  r
t        «       ‚|S )z 
        Checks if *request.user* has all permissions returned by
        *get_required_permissions* method.

        :param request: Original request.
        )r+   Úobjr   r   Ú
return_403Ú
return_404Úaccept_global_permsÚany_perm)r8   )r6   r
   r-   r   r   r9   r:   r;   r<   Úon_permission_check_failÚraise_exceptionr   )r   r   r8   Ú	forbiddens       r   Úcheck_permissionsz)PermissionRequiredMixin.check_permissions©   s”   € ð ×(Ñ(Ó*ˆä# GØ*.×*GÑ*GØ(/ó+1à(+Ø.2¯n©nØ8<×8PÑ8PØ/3¯©Ø/3¯©Ø8<×8PÑ8PØ-1¯]©]ô
&ˆ	ñ Ø×)Ñ)¨'°9À#Ð)ÔFÙ˜×-Ò-Ü"Ó$Ð$ØÐr   c                  ó   — y)a…  
        Method called upon permission check fail. By default it does nothing and
        should be overridden, if needed.

        :param request: Original request
        :param response: 403 response returned by *check_permissions* method.
        :param obj: Object that was fetched from the view (using ``get_object``
          method or ``object`` attribute, in that order).
        N© )r   r   Úresponser8   s       r   r=   z0PermissionRequiredMixin.on_permission_check_failÃ   s   � r   c                 ó~   •— || _         || _        || _        | j                  |«      }|r|S t	        ‰| �  |g|¢­i |¤ŽS ©N)r   r   r   r@   r   r   )r   r   r   r   rC   r   s        €r   r   z PermissionRequiredMixin.dispatchÎ   sJ   ø€ ØˆŒØˆŒ	ØˆŒØ×)Ñ)¨'Ó2ˆÙØˆOÜ‰wÑ Ð9¨$Ò9°&Ñ9Ð9r   rE   )r   r   r   r   r   r   r   r(   r   r   r9   r:   r>   r;   r<   r-   r6   r@   r=   r   r    r!   s   @r   r#   r#   3   s[   ø„ ñQðf ×"Ñ"€IØÐØ-ÐØ€JØ€JØ€OØÐØ€Hóò&/òó4	÷:ð :r   r#   c                   ó(   — e Zd Zed„ «       Zd„ Zd„ Zy)ÚGuardianUserMixinc                  ó   — t        «       S rE   )r   rB   r   r   Úget_anonymouszGuardianUserMixin.get_anonymousÚ   s   € ä!Ó#Ð#r   c                 óD   — t         j                  j                  || |«      S rE   )ÚUserObjectPermissionÚobjectsÚassign_perm©r   Úpermr8   s      r   Úadd_obj_permzGuardianUserMixin.add_obj_permÞ   ó   € Ü#×+Ñ+×7Ñ7¸¸dÀCÓHÐHr   c                 óD   — t         j                  j                  || |«      S rE   )rK   rL   Úremove_permrN   s      r   Údel_obj_permzGuardianUserMixin.del_obj_permá   rQ   r   N)r   r   r   ÚstaticmethodrI   rP   rT   rB   r   r   rG   rG   Ø   s    „ àñ$ó ð$òIóIr   rG   c                   ó8   ‡ — e Zd ZdZdZi Zdd„Zd„ Zˆ fd„Zˆ xZ	S )ÚPermissionListMixinag  
    A view mixin that filter object in queryset for the current logged by required permission.

    **Example Usage**::

        class SecureView(PermissionListMixin, ListView):
            ...
            permission_required = 'articles.view_article'
            ...

    or::

        class SecureView(PermissionListMixin, ListView):
            ...
            permission_required = 'auth.change_user'
            get_objects_for_user_extra_kwargs = {'use_groups': False}
            ...

    **Class Settings**

    ``PermissionListMixin.permission_required``

        *Default*: ``None``, must be set to either a string or list of strings
        in format: *<app_label>.<permission_codename>*.

    ``PermissionListMixin.get_objects_for_user_extra_kwargs``

        *Default*: ``{}``,  A extra params to pass for ```guardian.shortcuts.get_objects_for_user```

    Nc                 óø   — t        | j                  t        «      r| j                  g}|S t        | j                  t        «      r| j                  D �cg c]  }|‘Œ }}|S t	        d| j                  z  «      ‚c c}w r%   r&   r*   s       r   r-   z,PermissionListMixin.get_required_permissions  r.   r/   c                 óŽ   — t        d| j                  j                  | j                  | j                  «      |dœ| j                  ¤ŽS )z‡
        Returns dict of kwargs that should be pass to ```get_objects_for_user```.

        :param request: Queryset to filter
        )Úuserr+   ÚklassrB   )Údictr   rZ   r-   Ú!get_objects_for_user_extra_kwargs)r   Úquerysets     r   Úget_get_objects_for_user_kwargsz3PermissionListMixin.get_get_objects_for_user_kwargs  sG   € ô ð >˜Ÿ™×*Ñ*Ø×7Ñ7¸¿¹ÓEØ"ñ>ð ×<Ñ<ñ>ð 	>r   c                 óV   •— t        ‰| �  |i |¤Ž}t        di | j                  |«      ¤ŽS )NrB   )r   Úget_querysetr   r_   )r   r   r   Úqsr   s       €r   ra   z PermissionListMixin.get_queryset%  s0   ø€ Ü‰WÑ! 4Ð2¨6Ñ2ˆÜ#ÑO d×&JÑ&JÈ2Ó&NÑOÐOr   rE   )
r   r   r   r   r(   r]   r-   r_   ra   r    r!   s   @r   rW   rW   å   s,   ø„ ñð< ÐØ(*Ð%óò&	>÷Pð Pr   rW   N)Úcollections.abcr   Údjango.confr   Údjango.contrib.auth.decoratorsr   r   Údjango.core.exceptionsr   r   Úguardian.utilsr	   rK   r
   r   Úguardian.shortcutsr   r   r#   rG   rW   rB   r   r   ú<module>ri      sU   ðÝ $å  ß Nß IÝ 3Ù/Ó1Ð ß >Ý 3÷$$ñ $$÷Nb:ñ b:÷J
Iñ 
I÷BPò BPr   