codekingpro/portable-devtools
114k
1import typing as t2 3if t.TYPE_CHECKING:4 from gssapi.raw.chan_bindings import ChannelBindings5 from gssapi.raw.creds import Creds6 from gssapi.raw.named_tuples import (7 AcceptSecContextResult,8 InitSecContextResult,9 InquireContextResult,10 )11 from gssapi.raw.names import Name12 from gssapi.raw.oids import OID13 from gssapi.raw.types import RequirementFlag14 15class SecurityContext:16 """17 A GSSAPI Security Context18 """19 20 def __new__(21 cls,22 cpy: t.Optional["SecurityContext"] = None,23 ) -> "SecurityContext": ...24 25 @property26 def _started(self) -> bool: ...27 28 29def init_sec_context(30 name: "Name",31 creds: t.Optional["Creds"] = None,32 context: t.Optional[SecurityContext] = None,33 mech: t.Optional["OID"] = None,34 flags: t.Optional[t.Union[35 int, "RequirementFlag",36 t.Iterable[int], t.Iterable["RequirementFlag"]37 ]] = None,38 lifetime: t.Optional[int] = None,39 channel_bindings: t.Optional["ChannelBindings"] = None,40 input_token: t.Optional[bytes] = None,41) -> "InitSecContextResult":42 """Initiate a GSSAPI security context.43 44 This method initiates a GSSAPI security context, targeting the given45 target name. To create a basic context, just provide the target name.46 Further calls used to update the context should pass in the output context47 of the last call, as well as the input token received from the acceptor.48 49 Warning:50 This changes the input context!51 52 Args:53 target_name (~gssapi.raw.names.Name): the target for the security54 context55 creds (Creds): the credentials to use to initiate the context,56 or None to use the default credentials57 context (~gssapi.raw.sec_contexts.SecurityContext): the security58 context to update, or None to create a new context59 mech (~gssapi.raw.types.MechType): the mechanism type for this security60 context, or None for the default mechanism type61 flags (list): the flags to request for the security context, or62 None to use the default set: mutual_authentication and63 out_of_sequence_detection. This may also be an64 :class:`IntEnumFlagSet`65 lifetime (int): the request lifetime of the security context in seconds66 (a value of 0 or None means indefinite)67 channel_bindings (ChannelBindings): The channel bindings (or None for68 no channel bindings)69 input_token (bytes): the token to use to update the security context,70 or None if you are creating a new context71 72 Returns:73 InitSecContextResult: the output security context, the actual mech74 type, the actual flags used, the output token to send to the acceptor,75 the actual lifetime of the context in seconds (or None if not supported76 or indefinite), and whether or not more calls are needed to finish the77 initiation.78 79 Raises:80 ~gssapi.exceptions.InvalidTokenError81 ~gssapi.exceptions.InvalidCredentialsError82 ~gssapi.exceptions.MissingCredentialsError83 ~gssapi.exceptions.ExpiredCredentialsError84 ~gssapi.exceptions.BadChannelBindingsError85 ~gssapi.exceptions.BadMICError86 ~gssapi.exceptions.ExpiredTokenError87 ~gssapi.exceptions.DuplicateTokenError88 ~gssapi.exceptions.MissingContextError89 ~gssapi.exceptions.BadNameTypeError90 ~gssapi.exceptions.BadNameError91 ~gssapi.exceptions.BadMechanismError92 """93 94 95def accept_sec_context(96 input_token: bytes,97 acceptor_creds: t.Optional["Creds"] = None,98 context: t.Optional[SecurityContext] = None,99 channel_bindings: t.Optional["ChannelBindings"] = None,100) -> "AcceptSecContextResult":101 """Accept a GSSAPI security context.102 103 This method accepts a GSSAPI security context using a token sent by the104 initiator, using the given credentials. It can either be used to accept a105 security context and create a new security context object, or to update an106 existing security context object.107 108 Warning:109 This changes the input context!110 111 Args:112 input_token (bytes): the token sent by the context initiator113 acceptor_creds (Creds): the credentials to be used to accept the114 context (or None to use the default credentials)115 context (~gssapi.raw.sec_contexts.SecurityContext): the security116 context to update (or None to create a new security context object)117 channel_bindings (ChannelBindings): The channel bindings (or None for118 no channel bindings)119 120 Returns:121 AcceptSecContextResult: the resulting security context, the initiator122 name, the mechanism being used, the output token, the flags in use,123 the lifetime of the context in seconds (or None for indefinite or not124 supported), the delegated credentials (valid only if the125 delegate_to_peer flag is set), and whether or not further token126 exchanges are needed to finalize the security context.127 128 Raises:129 ~gssapi.exceptions.InvalidTokenError130 ~gssapi.exceptions.InvalidCredentialsError131 ~gssapi.exceptions.MissingCredentialsError132 ~gssapi.exceptions.ExpiredCredentialsError133 ~gssapi.exceptions.BadChannelBindingsError134 ~gssapi.exceptions.MissingContextError135 ~gssapi.exceptions.BadMICError136 ~gssapi.exceptions.ExpiredTokenError137 ~gssapi.exceptions.DuplicateTokenError138 ~gssapi.exceptions.BadMechanismError139 """140 141 142def inquire_context(143 context: SecurityContext,144 initiator_name: bool = True,145 target_name: bool = True,146 lifetime: bool = True,147 mech: bool = True,148 flags: bool = True,149 locally_init: bool = True,150 complete: bool = True,151) -> "InquireContextResult":152 """Get information about a security context.153 154 This method obtains information about a security context, including155 the initiator and target names, as well as the TTL, mech,156 flags, and its current state (open vs closed).157 158 Note:159 the target name may be ``None`` if it would have been ``GSS_C_NO_NAME``160 161 Args:162 context (~gssapi.raw.sec_contexts.SecurityContext): the context in163 question164 165 Returns:166 InquireContextResult: the initiator name, the target name, the TTL167 (can be None for indefinite or not supported), the mech type, the168 flags, whether or not the context was locally initiated,169 and whether or not the context is currently fully established170 171 Raises:172 ~gssapi.exceptions.MissingContextError173 """174 175 176def context_time(177 context: SecurityContext,178) -> int:179 """Get the amount of time for which the given context will remain valid.180 181 This method determines the amount of time for which the given182 security context will remain valid. An expired context will183 give a result of 0.184 185 Args:186 context (~gssapi.raw.sec_contexts.SecurityContext): the security187 context in question188 189 Returns:190 int: the number of seconds for which the context will be valid191 192 Raises:193 ~gssapi.exceptions.ExpiredContextError194 ~gssapi.exceptions.MissingContextError195 """196 197 198def process_context_token(199 context: SecurityContext,200 token: bytes,201) -> None:202 """Process a token asynchronously.203 204 This method provides a way to process a token, even if the205 given security context is not expecting one. For example,206 if the initiator has the initSecContext return that the context207 is complete, but the acceptor is unable to accept the context,208 and wishes to send a token to the initiator, letting the209 initiator know of the error.210 211 Warning:212 This method has been essentially deprecated by :rfc:`2744`.213 214 Args:215 context (~gssapi.raw.sec_contexts.SecurityContext): the security216 context against which to process the token217 token (bytes): the token to process218 219 Raises:220 ~gssapi.exceptions.InvalidTokenError221 ~gssapi.exceptions.MissingContextError222 """223 224 225def import_sec_context(226 token: bytes,227) -> SecurityContext:228 """Import a context from another process.229 230 This method imports a security context established in another process231 by reading the specified token which was output by232 :func:`export_sec_context`.233 234 Raises:235 ~gssapi.exceptions.MissingContextError236 ~gssapi.exceptions.InvalidTokenError237 ~gssapi.exceptions.OperationUnavailableError238 ~gssapi.exceptions.UnauthorizedError239 """240 241 242def export_sec_context(243 context: SecurityContext,244) -> bytes:245 """Export a context for use in another process.246 247 This method exports a security context, deactivating in the current process248 and creating a token which can then be imported into another process249 with :func:`import_sec_context`.250 251 Warning: this modifies the input context252 253 Args:254 context (~gssapi.raw.sec_contexts.SecurityContext): the context to send255 to another process256 257 Returns:258 bytes: the output token to be imported259 260 Raises:261 ~gssapi.exceptions.ExpiredContextError262 ~gssapi.exceptions.MissingContextError263 ~gssapi.exceptions.OperationUnavailableError264 """265 266 267def delete_sec_context(268 context: SecurityContext,269 local_only: bool = True,270) -> bytes:271 """Delete a GSSAPI security context.272 273 This method deletes a GSSAPI security context,274 returning an output token to send to the other275 holder of the security context to notify them276 of the deletion.277 278 Note:279 This method generally should not be used. :class:`SecurityContext`280 objects will automatically be freed by Python.281 282 Args:283 context (~gssapi.raw.sec_contexts.SecurityContext): the security284 context in question285 local_only (bool): should we request local deletion (True), or also286 remote deletion (False), in which case a token is also returned287 288 Returns:289 bytes: the output token (if remote deletion is requested). Generally290 this is None, but bytes for compatibility.291 292 Raises:293 ~gssapi.exceptions.MissingContextError294 """295 