Team Ai
Datasetpublic

codekingpro/portable-devtools

sourceHugging Faceupdated 5mo agoView on Hugging Face
1likes14kdownloads
_encryption.cpython-313.pyc645 linesDownload Raw Back to __pycache__
1�

2s�j���T�SSKrSSKrSSKrSSKJrJr SSKJrJrJ	r	J3r4 SSKJrJ
r
JrJrJrJrJrJrJrJr SSKJr SSKJrJrJrJrJrJrJrJ r J!r! "SS	5r"S5r#S\$S\$4S
jr%"SS5r&"SS5r'"SS\5r("SS\)\5r*"SS5r+"SS5r,g)�N)�Enum�IntEnum)�Any�Optional�Union�cast)6�CryptAES�	CryptBase�
CryptIdentity�CryptRC4�aes_cbc_decrypt�aes_cbc_encrypt�aes_ecb_decrypt�aes_ecb_encrypt�rc4_decrypt�rc4_encrypt�)�logger_warning)	�ArrayObject�ByteStringObject�DictionaryObject�7NameObject�NumberObject�	PdfObject�StreamObject�TextStringObject�create_string_objectc�^�\rSrSrS\S\S\SS4SjrS\S\4S	jrS8S.S\S\S\4S
jjr	Sr9g)�CryptFilter�<�	stm_crypt�	str_crypt�ef_crypt�returnNc�(�XlX lX0lg�N)r!r"r#)�selfr!r"r#s    �WD:\code\apps\devtools\python\user_packages\Python313\site-packages\pypdf/_encryption.py�__init__�CryptFilter.__init__=s��#��"�� �
��objc�F^�[U[5(a2TRRUR5n[U5nU$[U[105(a6TRRUR
55n[U5nU$[U[5(a[5nURU5 URTRRUR55 UR5HupETRU5X4'M UnU$[U[5(a:[5nUR5HupETRU5X4'M UnU$[U[5(a[U4SjU55nU$)Nc3�F># �UHnTRU5v� M g7fr&)�encrypt_object)�.0�xr's  �r(�	<genexpr>�-CryptFilter.encrypt_object.<locals>.<genexpr>[s����B�c��d�1�1�!�4�4�c�s�!)�11isinstancerr"�encrypt�original_bytesr�get_encoded_bytesr�update�set_datar!�_data�itemsr/rr)r'r,�data�obj2�key�values`     r(r/�CryptFilter.encrypt_objectGsW����c�+�,�,��>�>�)�)�#�*<�*<�=�D�"�4�(�C�$�12�#��-�
.�
.��>�>�)�)�#�*?�*?�*A�B�D�"�4�(�C��13���\�
*�
*��>�D��K�K����M�M�$�.�.�0�0����;�<�!�i�i�k�14�� �/�/��6��	�*��C��15���-�
.�
.�#�%�D�!�i�i�k�16�� �/�/��6��	�*��C��17���[�
)�
)��B�c�B�B�C��18r+T��strictrBc�|�[U[[45(a1URR	UR19US9n[
U5nU$[U[5(aUURR	URUS9Ul	UR5HupEURXRS9X'M U$[U[5(a,UR5HupEURXRS9X'M U$[U[5(a/[[U55HnURXUS9X'M U$�NrA)r4rrr"�decryptr6rrr!r:r;�decrypt_objectrr�range�len)r'r,rBr<r>r?�is       r(rF�CryptFilter.decrypt_object^s���c�,�.>�?�@�@��>�>�)�)�#�*<�*<�V�)�L�D�&�t�,�C��20���\�
*�
*����.�.�s�y�y��.�H�C�I�!�i�i�k�21���.�.�u�.�D���*��22�
��-�
.�
.�!�i�i�k�23���.�.�u�.�D���*�24�25���[�
)�
)��3�s�8�_���,�,�S�V�F�,�C���%��26r+)r#r!r")�__name__�27__module__�__qualname__�__firstlineno__r28r)rr/�boolrF�__static_attributes__�r+r(rr<sf��!��!��!��	!�2930�!��)��	��.@D��)����	��r+rs (�N^Nu�AdNV��..��h>�/��dSizr<r$c��U[-SS$)N� )�_PADDING)r<s r(�_paddingrUus���8�O�S�b�!�!r+c�$�\rSrSr\S\S\S\S\S\S\S\S	\4S31j5r\S\S\S\S	\4Sj5r	\S
\S\S\S	\4Sj5r32\S\S\S\S	\4Sj5r\S\S\S\S\S\S\S\S\S	\4Sj5r\S\S\S\S\S\S\S\S\S	\4Sj5r
Srg)�AlgV4�y�password�rev�key_size�o_entry�P�	id1_entry�metadata_encryptedr$c���[U5n[R"U5nURU5 UR[R33"SU55 URU5 US:�aU(dURS5 UR
5n	US-n34US:�a9[S5H*n[R"U	SU355R
5n	M, U	SU36$)u&37Algorithm 2: Computing an encryption key.38 39a) Pad or truncate the password string to exactly 32 bytes. If the40   password string is more than 32 bytes long,41   use only its first 32 bytes; if it is less than 32 bytes long, pad it42   by appending the required number of43   additional bytes from the beginning of the following padding string:44        < 28 BF 4E 5E 4E 75 8A 41 64 00 4E 56 FF FA 01 0845        2E 2E 00 B6 D0 68 3E 80 2F 0C A9 FE 64 53 69 7A >46   That is, if the password string is n bytes long, append47   the first 32 - n bytes of the padding string to the end48   of the password string. If the password string is empty49   (zero-length), meaning there is no user password,50   substitute the entire padding string in its place.51 52b) Initialize the MD5 hash function and pass the result of step (a)53   as input to this function.54c) Pass the value of the encryption dictionary’s O entry to the55   MD5 hash function. ("Algorithm 3: Computing56   the encryption dictionary’s O (owner password) value" shows how the57   O value is computed.)58d) Convert the integer value of the P entry to a 32-bit unsigned binary59   number and pass these bytes to the60   MD5 hash function, low-order byte first.61e) Pass the first element of the file’s file identifier array (the value62   of the ID entry in the document’s trailer63   dictionary; see Table 15) to the MD5 hash function.64f) (Security handlers of revision 4 or greater) If document metadata is65   not being encrypted, pass 4 bytes with66   the value 0xFFFFFFFF to the MD5 hash function.67g) Finish the hash.68h) (Security handlers of revision 3 or greater) Do the following69   50 times: Take the output from the previous70   MD5 hash and pass the first n bytes of the output as input into a new71   MD5 hash, where n is the number of72   bytes of the encryption key as defined by the value of the encryption73   dictionary’s Length entry.74i) Set the encryption key to the first n bytes of the output from the75   final MD5 hash, where n shall always be 576   for security handlers of revision 2 but, for security handlers of77   revision 3 or greater, shall depend on the78   value of the encryption dictionary’s Length entry.79 80Args:81    password: The encryption secret as a bytes-string82    rev: The encryption revision (see PDF standard)83    key_size: The size of the key in bytes84    o_entry: The owner entry85    P: A set of flags specifying which operations shall be permitted86        when the document is opened with user access. If bit 2 is set to 1,87        all other bits are ignored and all operations are permitted.88        If bit 2 is set to 0, permission for operations are based on the89        values of the remaining flags defined in Table 24.90    id1_entry:91    metadata_encrypted: A boolean indicating if the metadata is encrypted.92 93Returns:94    The u_hash digest of length key_size95 96�<I���������2N)rU�hashlib�md5r8�struct�pack�digestrG)rYrZr[r\r]r^r_�a�u_hash�
u_hash_digest�length�_s            r(�compute_key�AlgV4.compute_keyzs���N
�X������Q����
�
�g���
�
�f�k�k�$��*�+��
�
�i� ��!�8�.��M�M�-�.��
�
��
��Q����!�8��2�Y�� '���M�'�6�,B� C� J� J� L�
���W�f�%�%r+�owner_passwordc���[U5n[R"U5R5nUS:�a6[	S5H'n[R"U5R5nM) USUS-$)u�97Algorithm 3: Computing the encryption dictionary’s O (owner password) value.98 99a) Pad or truncate the owner password string as described in step (a)100   of "Algorithm 2: Computing an encryption key".101   If there is no owner password, use the user password instead.102b) Initialize the MD5 hash function and pass the result of step (a) as103   input to this function.104c) (Security handlers of revision 3 or greater) Do the following 50 times:105   Take the output from the previous106   MD5 hash and pass it as input into a new MD5 hash.107d) Create an RC4 encryption key using the first n bytes of the output108   from the final MD5 hash, where n shall109   always be 5 for security handlers of revision 2 but, for security110   handlers of revision 3 or greater, shall111   depend on the value of the encryption dictionary’s Length entry.112e) Pad or truncate the user password string as described in step (a) of113   "Algorithm 2: Computing an encryption key".114f) Encrypt the result of step (e), using an RC4 encryption function with115   the encryption key obtained in step (d).116g) (Security handlers of revision 3 or greater) Do the following 19 times:117   Take the output from the previous118   invocation of the RC4 function and pass it as input to a new119   invocation of the function; use an encryption120   key generated by taking each byte of the encryption key obtained in121   step (d) and performing an XOR122   (exclusive or) operation between that byte and the single-byte value123   of the iteration counter (from 1 to 19).124h) Store the output from the final invocation of the RC4 function as125   the value of the O entry in the encryption dictionary.126 127Args:128    owner_password:129    rev: The encryption revision (see PDF standard)130    key_size: The size of the key in bytes131 132Returns:133    The RC4 key134 135rerfNrd)rUrgrhrkrG)rsrZr[rl�
o_hash_digestrps      r(�compute_O_value_key�AlgV4.compute_O_value_key�sd��T
�^�$�����A��-�-�/�
��!�8��2�Y�� '���M� :� A� A� C�
���_�x�1�}�-�-r+�rc4_key�
user_passwordc�^�[U5n[X5nUS:�a3[SS5H#m[U4SjU55n[XT5nM% U$)z�136See :func:`compute_O_value_key`.137 138Args:139    rc4_key:140    user_password:141    rev: The encryption revision (see PDF standard)142 143Returns:144    The RC4 encrypted145 146rer�c3�,># �UH	oT-v� M g7fr&rQ�r0r1rIs  �r(r2�(AlgV4.compute_O_value.<locals>.<genexpr>�����3�7�a��E�7���)rUrrG�bytes)rxryrZrl�rc4_encr>rIs      @r(�compute_O_value�AlgV4.compute_O_valuesQ���
�]�#���g�)���!�8��1�b�\���3�7�3�3��%�c�3��"��r+r>c�6^�US::a[U[5$[R"[5nUR	U5 [XR55n[
SS5H#m[U4SjU55n[XT5nM% [U5$)uy147Algorithm 4: Computing the encryption dictionary’s U (user password) value.148 149(Security handlers of revision 2)150 151a) Create an encryption key based on the user password string, as152   described in "Algorithm 2: Computing an encryption key".153b) Encrypt the 32-byte padding string shown in step (a) of154   "Algorithm 2: Computing an encryption key", using an RC4 encryption155   function with the encryption key from the preceding step.156c) Store the result of step (b) as the value of the U entry in the157   encryption dictionary.158 159Args:160    key:161    rev: The encryption revision (see PDF standard)162    id1_entry:163 164Returns:165    The value166 167�rr{c3�,># �UH	oT-v� M g7fr&rQr}s  �r(r2�(AlgV4.compute_U_value.<locals>.<genexpr>Ps����/�3�a��E�3�r�)	rrTrgrhr8rkrGr�rU)r>rZr^rmr�rxrIs      @r(�compute_U_value�AlgV4.compute_U_values����0�!�8��s�H�-�-�	�2���X�&���
�
�i� ��c�=�=�?�3���q�"��A��/�3�/�/�G�!�'�3�G���� � r+�u_entryc	��[RXX#XVU5n[RX�U5n	US:�a168U	SSn	USSnX�:waSnU$)ur169Algorithm 6: Authenticating the user password.170 171a) Perform all but the last step of "Algorithm 4: Computing the172   encryption dictionary’s U (user password) value (Security handlers of173   revision 2)" or "Algorithm 5: Computing the encryption dictionary’s U174   (user password) value (Security handlers of revision 3 or greater)"175   using the supplied password string.176b) If the result of step (a) is equal to the value of the encryption177   dictionary’s U entry (comparing on the first 16 bytes in the case of178   security handlers of revision 3 or greater), the password supplied is179   the correct user password. The key obtained in step (a) (that is, in180   the first step of "Algorithm 4: Computing the encryption181   dictionary’s U (user password) value182   (Security handlers of revision 2)" or183   "Algorithm 5: Computing the encryption dictionary’s U (user password)184   value (Security handlers of revision 3 or greater)") shall be used185   to decrypt the document.186 187Args:188    user_password: The user password as a bytes stream189    rev: The encryption revision (see PDF standard)190    key_size: The size of the key in bytes191    o_entry: The owner entry192    u_entry: The user entry193    P: A set of flags specifying which operations shall be permitted194        when the document is opened with user access. If bit 2 is set to 1,195        all other bits are ignored and all operations are permitted.196        If bit 2 is set to 0, permission for operations are based on the197        values of the remaining flags defined in Table 24.198    id1_entry:199    metadata_encrypted: A boolean indicating if the metadata is encrypted.200 201Returns:202    The key203 204reN�r+)rWrqr�)205ryrZr[r\r�r]r^r_r>�u_values206          r(�verify_user_password�AlgV4.verify_user_passwordTs`��`�����1�AS�207���'�'��)�<���!�8��c�r�l�G��c�r�l�G����C��208r+c209��^�[RXU5nUS::a[X�5n	O6Un	[SSS5H#m[	U4SjU55n210[X�5n	M% [RU	UUUUUUU5$)u.211Algorithm 7: Authenticating the owner password.212 213a) Compute an encryption key from the supplied password string, as214   described in steps (a) to (d) of215   "Algorithm 3: Computing the encryption dictionary’s O (owner password)216   value".217b) (Security handlers of revision 2 only) Decrypt the value of the218   encryption dictionary’s O entry, using an RC4219   encryption function with the encryption key computed in step (a).220   (Security handlers of revision 3 or greater) Do the following 20 times:221   Decrypt the value of the encryption dictionary’s O entry (first iteration)222   or the output from the previous iteration (all subsequent iterations),223   using an RC4 encryption function with a different encryption key at224   each iteration. The key shall be generated by taking the original key225   (obtained in step (a)) and performing an XOR (exclusive or) operation226   between each byte of the key and the single-byte value of the227   iteration counter (from 19 to 0).228c) The result of step (b) purports to be the user password.229   Authenticate this user password using230   "Algorithm 6: Authenticating the user password".231   If it is correct, the password supplied is the correct owner password.232 233Args:234    owner_password:235    rev: The encryption revision (see PDF standard)236    key_size: The size of the key in bytes237    o_entry: The owner entry238    u_entry: The user entry239    P: A set of flags specifying which operations shall be permitted240        when the document is opened with user access. If bit 2 is set to 1,241        all other bits are ignored and all operations are permitted.242        If bit 2 is set to 0, permission for operations are based on the243        values of the remaining flags defined in Table 24.244    id1_entry:245    metadata_encrypted: A boolean indicating if the metadata is encrypted.246 247Returns:248    bytes249 250r�������c3�,># �UH	oT-v� M g7fr&rQr}s  �r(r2�.AlgV4.verify_owner_password.<locals>.<genexpr>�rr�)rWrvrrGr�r�)rsrZr[r\r�r]r^r_rxryr>rIs           @r(�verify_owner_password�AlgV4.verify_owner_password�s����h�+�+�N��J���!�8�'��9�M�#�M��2�r�2�&���3�7�3�3�� +�C� ?�
�'��)�)������
���	251�		252r+rQN)rKrLrMrN�staticmethodr��intrOrqrvr�r�r�r�rPrQr+r(rWrWys����R&��R&�
�R&��R&��	R&�253�R&��
R&�!�R&�254�R&��R&�h�0.�E�0.��0.�s�0.�u�0.��0.�d����u��3��5����*�9!�U�9!��9!��9!�5�9!��9!�v�8��8�
�8��8��	8�255�8��
8��8�!�8�256�8��8�t�E257��E258�
�E259��E260��	E261�262�E263��
E264��E265�!�E266�267�E268��E269r+rWc�v�\rSrSr\S\S\S\S\S\S\4Sj5r\S\S\S\S	\S\4270S271j5r\S\S\S\S\S\4272S
j5r	\S\S\S\S\273S\2744275Sj5r\S\S\S\S\S\S\276S\\
\
44Sj5r\S\S\S\S\\\44Sj5r\S\S\S\S\S\\\44277Sj5r\S\S\S\278S\4Sj5rSrg)�AlgV5i��RrY�o_value�oe_valuer�r$c���USSn[RXUSSUSS5USS:wag[S[S555n[RXUSSUSS5n[	XeU5$)	ud279Algorithm 3.2a Computing an encryption key.280 281To understand the algorithm below, it is necessary to treat the O and U282strings in the Encrypt dictionary as made up of three sections.283The first 32 bytes are a hash value (explained below). The next 8 bytes284are called the Validation Salt. The final 8 bytes are called the Key Salt.285 2861. The password string is generated from Unicode input by processing the287   input string with the SASLprep (IETF RFC 4013) profile of288   stringprep (IETF RFC 3454), and then converting to a UTF-8289   representation.2902. Truncate the UTF-8 representation to 127 bytes if it is longer than291   127 bytes.2923. Test the password against the owner key by computing the SHA-256 hash293   of the UTF-8 password concatenated with the 8 bytes of owner294   Validation Salt, concatenated with the 48-byte U string. If the295   32-byte result matches the first 32 bytes of the O string, this is296   the owner password.297   Compute an intermediate owner key by computing the SHA-256 hash of298   the UTF-8 password concatenated with the 8 bytes of owner Key Salt,299   concatenated with the 48-byte U string. The 32-byte result is the300   key used to decrypt the 32-byte OE string using AES-256 in CBC mode301   with no padding and an initialization vector of zero.302   The 32-byte result is the file encryption key.3034. Test the password against the user key by computing the SHA-256 hash304   of the UTF-8 password concatenated with the 8 bytes of user305   Validation Salt. If the 32 byte result matches the first 32 bytes of306   the U string, this is the user password.307   Compute an intermediate user key by computing the SHA-256 hash of the308   UTF-8 password concatenated with the 8 bytes of user Key Salt.309   The 32-byte result is the key used to decrypt the 32-byte310   UE string using AES-256 in CBC mode with no padding and an311   initialization vector of zero. The 32-byte result is the file312   encryption key.3135. Decrypt the 16-byte Perms string using AES-256 in ECB mode with an314   initialization vector of zero and the file encryption key as the key.315   Verify that bytes 9-11 of the result are the characters ‘a’, ‘d’, ‘b’.316   Bytes 0-3 of the decrypted Perms entry, treated as a little-endian317   integer, are the user permissions.318   They should match the value in the P key.319 320Args:321    R: A number specifying which revision of the standard security322        handler shall be used to interpret this dictionary323    password: The owner password324    o_value: A 32-byte string, based on both the owner and user passwords,325        that shall be used in computing the encryption key and in326        determining whether a valid owner password was entered327    oe_value:328    u_value: A 32-byte string, based on the user password, that shall be329        used in determining whether to prompt the user for a password and,330        if so, whether a valid user or owner password was entered.331 332Returns:333    The key334 335N�rS�(�0r+c3�&# �UHnSv� M	 g7f�rNrQ�r0rps  r(r2�.AlgV5.verify_owner_password.<locals>.<genexpr>����(�i��1�i���r��r��calculate_hashr�rGr
)r�rYr�r�r��iv�tmp_keys       r(r��AlgV5.verify_owner_password�s���|�D�S�>��� � ��g�b��n�g�c�r�l�K��s��|�
��
�(�e�B�i�(�
(���&�&�q�G�B�r�N�G�C�R�L�Q���w�H�5�5r+�ue_valuec���USSn[RXUSSS5USS:wag[S[S555n[RXUSSS5n[	XTU5$)	a�336See :func:`verify_owner_password`.337 338Args:339    R: A number specifying which revision of the standard security340        handler shall be used to interpret this dictionary341    password: The user password342    u_value: A 32-byte string, based on the user password, that shall be343        used in determining whether to prompt the user for a password344        and, if so, whether a valid user or owner password was entered.345    ue_value:346 347Returns:348    bytes349 350Nr�rSr�r+c3�&# �UHnSv� M	 g7fr�rQr�s  r(r2�-AlgV5.verify_user_password.<locals>.<genexpr>8r�r�r�r�r�)r�rYr�r�r�r�s      r(r��AlgV5.verify_user_password!sp��(�D�S�>������W�R��^�S�A�W�S�b�\�Q��
�(�e�B�i�(�
(���&�&�q�G�B�r�N�C�H���w�H�5�5r+�salt�udatac��[R"X-U-5R5nUS:aU$SnUS-
nX-U-n[USSUSSUS-5n[R[R[R3514[
USS5S-nU"U5R5nUS:�a
USUS-352::aOM�USS$)	N�rrr�rS�@rer�)rg�sha256rkr�sha384�sha512�sum)	r�rYr�r��k�count�k1�e�hash_fns	         r(r��AlgV5.calculate_hash<s���
�N�N�8�?�U�2�3�:�:�<���q�5��H�����Q�J�E����%�B���#�2���"�R��"�r�'�:�A������������!�C�R�&�k�A�o�	�G�353��354�!�!�#�A���{�q��u���355�2�����"�v�
r+r>�perms�pr_c�|�U(aSOSn[R"SU5S-U-S-n[X5nXVSS:H$)a356See :func:`verify_owner_password` and :func:`compute_perms_value`.357 358Args:359    key: The owner password360    perms:361    p: A set of flags specifying which operations shall be permitted362        when the document is opened with user access.363        If bit 2 is set to 1, all other bits are ignored and all364        operations are permitted.365        If bit 2 is set to 0, permission for operations are based on366        the values of the remaining flags defined in Table 24.367    metadata_encrypted:368 369Returns:370    A boolean371 372�T�Frarc�adbN�)rirjr)r>r�r�r_�b8�p1�p2s       r(�verify_perms�AlgV5.verify_permsQsE��,(�T�T��
�[�[��q�
!�$7�
7�"�
<�v�
E��
�S�
(�����W�}�r+ryrsc��USSnUSSn[RXU5upg[RXX65up�[RX4U5n373UUUU	U374S.$)Nr�)�/U�/UE�/O�/OE�/Perms)r�r�r��compute_Perms_value)r�ryrsr>r�r_r�r�r�r�r�s           r(�generate_values�AlgV5.generate_valueslsr��&�d�s�+�
�'���-��!�1�1�!�C�H���!�1�1�!�S�R����)�)�#�2D�E�������375�	376r+c���[R"S5nUSSnUSSn[RXUS5U-U-n[RXUS5n[	S[S555n[
XxU5n	Xi4$)u�377Algorithm 3.8 Computing the encryption dictionary’s U (user password)378and UE (user encryption key) values.379 3801. Generate 16 random bytes of data using a strong random number generator.381   The first 8 bytes are the User Validation Salt. The second 8 bytes382   are the User Key Salt. Compute the 32-byte SHA-256 hash of the383   password concatenated with the User Validation Salt. The 48-byte384   string consisting of the 32-byte hash followed by the User385   Validation Salt followed by the User Key Salt is stored as the U key.3862. Compute the 32-byte SHA-256 hash of the password concatenated with387   the User Key Salt. Using this hash as the key, encrypt the file388   encryption key using AES-256 in CBC mode with no padding and an389   initialization vector of zero. The resulting 32-byte string is stored390   as the UE key.391 392Args:393    R:394    password:395    key:396 397Returns:398    A tuple (u-value, ue value)399 400r�Nrdr+c3�&# �UHnSv� M	 g7fr�rQr�s  r(r2�(AlgV5.compute_U_value.<locals>.<genexpr>�r�r���secrets�token_bytesr�r�r�rGr)401r�rYr>�random_bytes�val_salt�key_saltr�r�r�r�s402          r(r��AlgV5.compute_U_value�s���6�*�*�2�.�����#�����#���&�&�q�H�c�B�X�M�PX�X���&�&�q�H�c�B��
�(�e�B�i�(�
(��"�7��4��� � r+c��[R"S5nUSSnUSSn[RXXS5U-U-n[RXXcSS5n[	S[S555n	[
X�U5n403Xz4$)u	404Algorithm 3.9 Computing the encryption dictionary’s O (owner password)405and OE (owner encryption key) values.406 4071. Generate 16 random bytes of data using a strong random number408   generator. The first 8 bytes are the Owner Validation Salt. The409   second 8 bytes are the Owner Key Salt. Compute the 32-byte SHA-256410   hash of the password concatenated with the Owner Validation Salt and411   then concatenated with the 48-byte U string as generated in412   Algorithm 3.8. The 48-byte string consisting of the 32-byte hash413   followed by the Owner Validation Salt followed by the Owner Key Salt414   is stored as the O key.4152. Compute the 32-byte SHA-256 hash of the password concatenated with416   the Owner Key Salt and then concatenated with the 48-byte U string as417   generated in Algorithm 3.8. Using this hash as the key,418   encrypt the file encryption key using AES-256 in CBC mode with419   no padding and an initialization vector of zero.420   The resulting 32-byte string is stored as the OE key.421 422Args:423    R:424    password:425    key:426    u_value: A 32-byte string, based on the user password, that shall be427        used in determining whether to prompt the user for a password428        and, if so, whether a valid user or owner password was entered.429 430Returns:431    A tuple (O value, OE value)432 433r�Nrdr�c3�&# �UHnSv� M	 g7fr�rQr�s  r(r2�(AlgV5.compute_O_value.<locals>.<genexpr>�r�r�r�)r�rYr>r�r�r�r�r�r�r�r�s           r(r��AlgV5.compute_O_value�s���F�*�*�2�.�����#�����#��� � ��h�@�8�K�h�V�	��&�&�q�H�c�r�l�K��
�(�e�B�i�(�
(��"�7��4��� � r+c��U(aSOSn[R"S5n[R"SU5S-U-S-U-n[	X5$)u434Algorithm 3.10 Computing the encryption dictionary’s Perms435(permissions) value.436 4371. Extend the permissions (contents of the P integer) to 64 bits by438   setting the upper 32 bits to all 1’s.439   (This allows for future extension without changing the format.)4402. Record the 8 bytes of permission in the bytes 0-7 of the block,441   low order byte first.4423. Set byte 8 to the ASCII value ' T ' or ' F ' according to the443   EncryptMetadata Boolean.4444. Set bytes 9-11 to the ASCII characters ' a ', ' d ', ' b '.4455. Set bytes 12-15 to 4 bytes of random data, which will be ignored.4466. Encrypt the 16-byte block using AES-256 in ECB mode with an447   initialization vector of zero, using the file encryption key as the448   key. The result (16 bytes) is stored as the Perms string, and checked449   for validity when the file is opened.450 451Args:452    key:453    p: A set of flags specifying which operations shall be permitted454        when the document is opened with user access. If bit 2 is set to 1,455        all other bits are ignored and all operations are permitted.456        If bit 2 is set to 0, permission for operations are based on the457        values of the remaining flags defined in Table 24.458    metadata_encrypted: A boolean indicating if the metadata is encrypted.459 460Returns:461    The perms value462 463r�r�rbrarcr�)r�r�rirjr)r>r�r_r��rrr<s      r(r��AlgV5.compute_Perms_value�sN��B(�T�T��
�
 �
 ��
#���{�{�4��#�&9�9�B�>��G�"�L���s�)�)r+rQN)rKrLrMrNr�r�r�r�r�r�rOr��dictrr��tupler�r�r�rPrQr+r(r�r��s464���E6��E6��E6�*/�E6�;@�E6�KP�E6�	�E6��E6�N�6��6��6�*/�6�;@�6�	�6��6�4��#����e��E��e����(��
�� ��%(��>B��	
����4�465��466��467��468��	469�470�471�!�
472�473�c�3�h��474��475�*�"!�3�"!�%�"!�e�"!��e�U�l�@S�"!��"!�H�+!��+!��+!�&+�+!�6;�+!�	�u�e�|�	�+!��+!�Z�#*��#*�3�#*�D�#*�U�#*��#*r+r�c� �\rSrSrSrSrSrSrg)�PasswordTypei�rrr�rQN)rKrLrMrN�
NOT_DECRYPTED�
USER_PASSWORD�OWNER_PASSWORDrPrQr+r(r�r��s���M��M��Nr+r�c�(�\rSrSrSrSrSrSrSrSr	g)	�EncryptAlgorithmi)rr�r�)r�re�)rbrbr�)�r��)r�r�r�rQN)476rKrLrMrN�RC4_40�RC4_128�AES_128�477AES_256_R5�AES_256rPrQr+r(r�r�s��
�F��G��G��J��Gr+r�c�H�\rSrSr%\\S'\\S'\\S'\\S'\\S'Srg)	�EncryptionValuesi�O�U�OE�UE�PermsrQN)rKrLrMrNr��__annotations__rPrQr+r(r�r�s���H��H�
�I�
�I��Lr+r�c���\rSrSrSrS\S\S\S\S\S\S	\S478\	S\	S\	S
\479\SS4SjrS\4Sjr
S\S\S\S\4SjrSS.S\S\S\S\S\4480Sjjr\S\S\4Sj5rS\S\S\4Sjr\S\	S\S\S\S\4481S j5r\S!\\\	4S\4S"j5rS!\\\	4S\4S#jrS!\S\\\44S$jrS!\S\\\44S%jrS&\	S'\482\	S\4S(jrS&\S'\SS4S)jr\S*\S	\SS4S+j5r \S,\!S-\S	\SS4S.j5r"S/r#g)0�483Encryptionia�484Collects and manages parameters for PDF document encryption and decryption.485 486Args:487    V: A code specifying the algorithm to be used in encrypting and488       decrypting the document.489    R: The revision of the standard security handler.490    Length: The length of the encryption key in bits.491    P: A set of flags specifying which operations shall be permitted492       when the document is opened with user access493    entry: The encryption dictionary object.494    EncryptMetadata: Whether to encrypt metadata in the document.495    first_id_entry: The first 16 bytes of the file's original ID.496    StmF: The name of the crypt filter that shall be used by default497          when decrypting streams.498    StrF: The name of the crypt filter that shall be used when decrypting499          all strings in the document.500    EFF: The name of the crypt filter that shall be used when501         encrypting embedded file streams that do not have their own502         crypt filter specifier.503    values: Additional encryption parameters.504 505�Vr��Lengthr]�entry�EncryptMetadata�first_id_entry�StmF�StrF�EFF�valuesr$Nc���XlX lX0lUS-S-UlX`lXplX�lX�lX�lU=(d506 [5Ul507[RUl
SUlSUlg)NlT)rr�rr]rr^rr	r508r�rr�r��_password_type�_key�_are_permissions_valid)r'rr�rr]rrrrr	r509rs            r(r)�Encryption.__init__,sj�� �������k�/�[�0���.��'���	��	���(.�(D�2B�2D���*�8�8���%)��	�,0��#r+c�<�UR[R:g$r&)r
r�r�)r's r(�is_decrypted�Encryption.is_decryptedKs���"�"�l�&@�&@�@�@r+r,�idnum�510generationc�v�URU5(dU$URX#5nURU5$r&)�_is_encryption_object�_make_crypt_filterr/)r'r,rr�cfs     r(r/�Encryption.encrypt_objectNs9���)�)�#�.�.��J�
�
$�
$�U�
7��� � ��%�%r+TrArBc�r�URU5(dU$URX#5nURXS9$rD)rrrF)r'r,rrrBrs      r(rF�Encryption.decrypt_objectVs<���)�)�#�.�.��J�
�
$�
$�U�
7��� � �� �4�4r+c�L�[U[[[[[51145$r&)r4rrrrr)r,s r(r� Encryption._is_encryption_object^s&���� � ��� �
�	512�		513r+c���[R"SU5SSn[R"SU5SSnUR(deURnURS::a�URS:XaSOURS-nUSUU-U-n[514R"U5nUR5S[US-S	5n	URS5155 UR5S[US-S	5n516OSn	Sn517UnURURX�U5nURURX�U5n
URURX�U5n[X�U5$)u\	518Algorithm 1: Encryption of data using the RC4 or AES algorithms.519 520a) Obtain the object number and generation number from the object521   identifier of the string or stream to be encrypted522   (see 7.3.10, "Indirect Objects"). If the string is a direct object,523   use the identifier of the indirect object containing it.524b) For all strings and streams without crypt filter specifier; treating525   the object number and generation number as binary integers, extend526   the original n-byte encryption key to n + 5 bytes by appending the527   low-order 3 bytes of the object number and the low-order 2 bytes of528   the generation number in that order, low-order byte first.529   (n is 5 unless the value of V in the encryption dictionary is greater530   than 1, in which case n is the value of Length divided by 8.)531   If using the AES algorithm, extend the encryption key an additional532   4 bytes by adding the value “sAlT”, which corresponds to the533   hexadecimal values 0x73, 0x41, 0x6C, 0x54. (This addition is done for534   backward compatibility and is not intended to provide additional535   security.)536c) Initialize the MD5 hash function and pass the result of step (b) as537   input to this function.538d) Use the first (n + 5) bytes, up to a maximum of 16, of the output539   from the MD5 hash as the key for the RC4 or AES symmetric key540   algorithms, along with the string or stream data to be encrypted.541   If using the AES algorithm, the Cipher Block Chaining (CBC) mode,542   which requires an initialization vector, is used. The block size543   parameter is set to 16 bytes, and the initialization vector is a544   16-byte random number that is stored as the first 16 bytes of the545   encrypted stream or string.546 547Algorithm 3.1a: Encryption of data using the AES-256 algorithm.548 549Note: Algorithm 3.1a does not use MD5 key derivation, so AES-256550encrypted files can be read on FIPS-enabled systems where MD5 is blocked.551 5521. Use the 32-byte file encryption key for the AES-256 symmetric key553   algorithm, along with the string or stream data to be encrypted.554   Use the AES algorithm in Cipher Block Chaining (CBC) mode, which555   requires an initialization vector. The block size parameter is set to556   16 bytes, and the initialization vector is a 16-byte random number557   that is stored as the first 16 bytes of the encrypted stream or string.558   The output is the encrypted data to be stored in the PDF file.559z<iNrer�rbrr�rdr�ssAlTr+)rirjrrrrgrhrk�minr8�560_get_cryptrr	r561r)r'rr�pack1�pack2r>�n�key_data�key_hashrx�562aes128_key�563aes256_keyr!r"r#s               r(r�Encryption._make_crypt_filterks;��X���D�%�(��!�,�����D�*�-�b�q�1���y�y��y��i�i���6�6�Q�;��V�V�q�[��d�k�k�Q�&6�A��2�A�w����.�H��{�{�8�,�H��o�o�'�(8�#�a�!�e�R�.�9�G�
�O�O�G�$�!���*�+;�S��Q���^�<�J��G��J��564��O�O�D�I�I�w�J�O�	��O�O�D�I�I�w�J�O�	��?�?�4�8�8�W�*�M���9��:�:r+�methodrxr'r(c�|�US:Xa[U5$US:Xa[U5$US:Xa565[5$[U5$)N�/AESV2�/AESV3�	/Identity)r	rr)r*rxr'r(s    r(r!�Encryption._get_crypt�sE���X���J�'�'��X���J�'�'��[� � �?�"��� � r+rYc��[U[5(aURS5nU$UnU$![a URS5nU$f=f)Nzlatin-1zutf-8)r4�str�encode�	Exception)rY�pwds  r(�_encode_password�Encryption._encode_password�s[���h��$�$�
/��o�o�i�0��566�567��C��568��	�
/��o�o�g�.���569�	
/�s�.�A
�A
c���URU5nURS::aURU5OURU5up4U[R570:waX@lX0lU$)Nrb)r5r�	verify_v4�	verify_v5r�r�r
r)r'rYr4r>�rcs     r(�verify�Encryption.verify�sU���#�#�H�-��)-���1��$�.�.��%�$�.�.��:M���
��+�+�+�"$���I��	r+c571�b�[RUURURURR572URRURURUR5nU(aU[R4$[RUURURURR573URRURURUR5nU(aU[R4$S[R4$)Nr+)rWr�r�rrr�r�r]r^rr�r�r�r�r�)r'rYr>s   r(r8�Encryption.verify_v4�s����)�)���F�F��K�K��K�K�M�M��K�K�M�M��F�F��N�N�� � �	574�����3�3�3�3��(�(���F�F��K�K��K�K�M�M��K�K�M�M��F�F��N�N�� � �	575�����2�2�2�2��L�.�.�.�.r+c��[RURXRRURR576URR5n[RnU(dY[RURXRRURR5n[RnU(dS[R4$[RX RRURUR 5UlUR"(d[%S[&5 X#4$)Nr+zignore '/Perms' verify failed)r�r�r�rr�r�r�r�r�r�r�r�r�r�r�r]rrrrK)r'rYr>r:s    r(r9�Encryption.verify_v5�s����)�)��F�F�H�k�k�m�m�T�[�[�^�^�T�[�[�]�]�577���
(�
(����,�,�����+�+�-�-�������C��+�+�B����2�2�2�2�',�&8�&8��k�k�>O�>O�QU�QW�QW�Y]�Ym�Ym�&n��#��*�*��:�H�E��w�r+ryrsc���URU5nU(aURU5OSnUcUnURS::aURX45 O�[R"UR578S-5Ul[RURX4URURUR5nUSURl
USURlUSURlUSURlUSURl[%5n['UR5U[)S5'['UR5U[)S	5'['UR5795U[)S5805'['UR5U[)S5'[)S5U[)S
5'[+URR5U[)S5'[+URR5U[)S5'URS:�a�[%5n[)S5U[)S5'[)UR,5U[)S5'['UR581S-5U[)S5825'[%5nXx[)S5'X�[)S5'[)S5U[)S5'[)S5U[)S5'URS:�a�[+URR5U[)S5'[+URR 5U[)S5'[+URR"5U[)S5'U$)Nrbrdr�r�r�r�r��/V�/R�/Length�/P�	/Standard�/Filterz/DocOpenz583/AuthEvent�/CFMz/StdCF�/CF�/StmF�/StrFr�)r5r�compute_values_v4r�r�rrr�r�r�r]rrr�r�r�r�r�rrrrr)	r'ryrs�user_pwd�	owner_pwdr�dict_obj�std_cfrs	         r(�write_entry�Encryption.write_entrys����(�(��7��=K�D�)�)�.�9�QU�	��� �I��6�6�Q�;��"�"�8�7��+�+�D�K�K�1�,<�=�D�I��*�*�����T�Y�Y�����@T�@T��F�#�4�L�D�K�K�M�"�4�L�D�K�K�M�#�E�]�D�K�K�N�#�E�]�D�K�K�N� &�x� 0�D�K�K��#�%��%1�$�&�&�%9���D�!�"�%1�$�&�&�%9���D�!�"�*6�t�{�{�*C���I�&�'�%1�$�&�&�%9���D�!�"�*4�[�*A���I�&�'�&6�d�k�k�m�m�%D���D�!�"�%5�d�k�k�m�m�%D���D�!�"��6�6�Q�;�%�'�F�/9�*�/E�F�:�l�+�,�)3�D�I�I�)>�F�:�f�%�&�,8�����9I�,J�F�:�i�(�)�!�#�B�'-�z�(�#�$�*,�Z��&�'�,6�x�,@�H�Z��(�)�,6�x�,@�H�Z��(�)��6�6�Q�;�*:�4�;�;�>�>�*J�H�Z��&�'�*:�4�;�;�>�>�*J�H�Z��&�'�-=�d�k�k�>O�>O�-P�H�Z��)�*��r+c	���[RX RUR5n[R	X1UR5n[RUURURUURURUR5n[RXPRUR5nXPl584X@RlX`Rl
gr&)rWrvr�rr�rqr]r^rr�rrr�r�)r'ryrsrxr�r>r�s       r(rL�Encryption.compute_values_v49s����+�+�N�F�F�D�K�K�P���'�'�����G�������F�F��K�K���F�F��N�N�� � �585���'�'��V�V�T�^�^�D���	����
����
r+�encryption_entryc��URS5S:wa[S5eSU;a[S5eSnSnSnURSS5nUS	;a[S586US35eUS:�a�US
nURSS5nURSS5nURSU5nUS:waXbSnUS:waXcSnUS:waXdSnSnX';a[SUS35eX7;a[SUS35eXG;a[SUS35e[[US5n[[US5n	URSS5n587US:Xa?US:Xa9[[WUS5n[[URSS55S-n588URS5nUbUR589OS n[
5n
[[US!5RU
l	[[US"5RU
l590URS#[55RU
lURS$[55RU
lURS%[55RU
l
[UUU591U	UUU
UUUUS&9$)'NrGrFz1only Standard PDF encryption handler is availablez592/SubFilterz/SubFilter NOT supported�/V2rBr)rr�rerbr�z
Encryption V=z NOT supportedrbrIrJr.rKz/EFFrH)r.rWr,r-zStmF Method z NOT supported!zStrF Method zEFF Method rCrErDr�r,r�rdz/EncryptMetadataTr�r�r�r�r��rr�rr]rrrr	rr593r)�get�NotImplementedErrorrr�rr?r�rr6r�r�r�r�r�r)rUr�594stm_filter�595str_filter�	ef_filter�alg_ver�filters�allowed_methods�alg_rev�596perm_flags�key_bits�cf_dict�encrypt_metadatars              r(�read�Encryption.readLs������	�*�k�9�%�C��
��+�+�%�&@�A�A��597��598��	�"�&�&�t�Q�/���/�)�%�
�g�Y�n�&M�N�N��a�<�&�u�-�G�)�-�-�g�{�C�J�)�-�-�g�{�C�J�(�,�,�V�Z�@�I��[�(�$�0��8�599��[�(�$�0��8�600��K�'�#�.�v�6�	�F�O��0�)�L���O�*T�U�U��0�)�L���O�*T�U�U��/�)�K�	�{�/�*R�S�S��s�,�T�2�3���#�/��5�6�601�#�'�'�	�2�6���a�<�J�(�2��+�W�5E�g�5N�-O�P�G��C����Y��!;�<�q�@�H�+�/�/�0B�C��&6�&B��"�"��	�"�#���(�*:�4�*@�A�P�P����(�*:�4�*@�A�P�P���$�(�(��0@�0B�C�R�R��	�$�(�(��0@�0B�C�R�R��	�'�+�+�H�6F�6H�I�X�X��������,�)�����"�602�	603r+�alg�permissionsc���Uup4nSupgnU[R:XaSupgnO)U[R[R4;aSupgn[	UUUUSUSUUU[5S9$)N)rWrWrW)r,r,r,)r-r-r-TrX)r�r�r�r�rr)	rhrirr^rarcr[r\r]s	         r(�make�Encryption.make�s���&)�"��(�,?�)�604�	��"�*�*�*�0L�-�J�I�
�%�0�0�2B�2J�2J�K�
K�0L�-�J�I������ �)�����"�$�605�	606r+)
r607rrr]r�rr	rrrr
r^r)$rKrLrMrN�__doc__r�rrOr�r1rr�r)rrr/rFr�rrrr608r!rr5r�r;r�r8r9rQrLrfr�rkrPrQr+r(rrs����01��1��1��	1�609�1� �
1��1��1��1��1��1��)�*�1�610�1�>A�d�A�&�)�&�C�&�S�&�Y�&�]a�5�)�5�C�5�S�5�UY�5�en�5��611612�9�613614��615616��617618�G;��G;��G;��G;�R�619!��620!�#�621!�16�622!�DI�623!�	�624!��625!���5����#4�������u�U�C�Z�0��\��/�%�/�E�%��2E�,F�/�8�%��E�%��2E�,F��*2� �2�2:�3�-�2�	�2�h �u� �e� �PT� �&�B626�/�B627��B628�<�B629��B630�H�631�
�632�,/�633�AF�634�	�635��636r+r)-rgr�ri�enumrr�typingrrrr�pypdf._crypt_providersr	r637rrr
rrrrr�_utilsr�genericrrrrrrrrrrrTr�rUrWr�r�r�r�r�rrQr+r(�<module>rss���6��
��-�-����#�638�639�640�0�0�hH�	�"�5�"�U�"�\641�\642�~643a*�a*�H	�7���u�d����W644�W645r+
codekingpro/portable-devtools · Team Ai