
    Dj3                       U d Z ddlmZ ddlZddlmZ ej                            ej                            e	          d          Z
 ee
d          5 Z e            Zded<    e            Zded	<    e            Zded
<   eD ]Ze                    d                                          Zere                    d          rAe                    d          re                    edd                    te                    d          re                    edd                    e                    e           	 ddd           n# 1 swxY w Y    eed eD             z  d eD             z            ZddZddZdS )a6  
These functions validate RP_ID and APP_ID according to simplified TLD+1 rules,
using a bundled copy of the public suffix list fetched from:

  https://publicsuffix.org/list/public_suffix_list.dat

Advanced APP_ID values pointing to JSON files containing valid facets are not
supported by this implementation.
    )annotationsN)urlparsezpublic_suffix_list.datrbzset[str]_suffix_set_wildcard_set_exception_setutf8z//!   *.   c                    h | ]}d | S )r    ).0ws     E/home/thesage/.hermes/venv/lib/python3.11/site-packages/fido2/rpid.py	<setcomp>r   =   s    333888333    c                    h | ]}d | S )r
   r   )r   es     r   r   r   =   s    6W6W6W1w1ww6W6W6Wr   domainstrreturnboolc                    | t           v rdS | t          v rdS |                     dd          }t          |          dk    r|d         t          v rdS dS )zvCheck if a domain is a public suffix per the PSL algorithm.

    https://github.com/publicsuffix/list/wiki/Format
    FT.r   r   )r   r   splitlenr   )r   partss     r   _is_public_suffixr    A   s^    
 utLLa  E
5zzQ58}44t5r   rp_idoriginc                   | sdS t          |          }|j        }|j        dk    r1|j        |fdk    r$|j        dk    r|r|                    d          sdS || k    rdS |r)|                    d| z             rt	          |           sdS dS )zChecks if a Webauthn RP ID is usable for a given origin.

    :param rp_id: The RP ID to validate.
    :param origin: The origin of the request.
    :return: True if the RP ID is usable by the origin, False if not.
    Fhttps)http	localhostr%   z
.localhostTr   )r   hostnameschemeendswithr    )r!   r"   urlhosts       r   verify_rp_idr,   P   s      u
6

C<D
 	
gZ"777v%%$%4==3N3N%uu}}t cEk** 3DU3K3K t5r   )r   r   r   r   )r!   r   r"   r   r   r   )__doc__
__future__r   osurllib.parser   pathjoindirname__file__	tld_fnameopenfsetr   __annotations__r   r   _linedecodestrip_entry
startswithaddsortedsuffixesr    r,   r   r   r   <module>rB      sP  8   # " " " " " 				 ! ! ! ! ! !GLL224LMM		T)T $aCEEK!!!!!ceeM####"suuN$$$$ 	$ 	$f%%++-- 	**400 	S!! 	$vabbz****t$$ 	$fQRRj))))OOF####	$	$ $ $ $ $ $ $ $ $ $ $ $ $ $ $  633]33336W6W6W6W6WW 
        s   C-EEE