Ë
    ¦#ijç  ã                   ób   — d dl Z d dlmZ d dlmZmZ  G d„ de«      Z G d„ de«      Zd„ Zd
d	„Z	y)é    N)ÚStrEnum)ÚSimpleLazyObjectÚemptyc                   ó<   — e Zd ZdZdZdZdZdZdZdZ	dZ
d	Zd
ZdZdZy)ÚCSPaÿ  
    Content Security Policy constants for directive values and special tokens.

    These constants represent:
    1. Standard quoted string values from the CSP spec (e.g., 'self',
       'unsafe-inline')
    2. Special placeholder tokens (NONCE) that get replaced by the middleware

    Using this enum instead of raw strings provides better type checking,
    autocompletion, and protection against common mistakes like:

    - Typos (e.g., 'noone' instead of 'none')
    - Missing quotes (e.g., ["self"] instead of ["'self'"])
    - Inconsistent quote styles (e.g., ["'self'", ""unsafe-inline""])

    Example usage in Django settings:

        SECURE_CSP = {
            "default-src": [CSP.NONE],
            "script-src": [CSP.SELF, CSP.NONCE],
        }

    zContent-Security-Policyz#Content-Security-Policy-Report-Onlyz'none'z'report-sample'z'self'z'strict-dynamic'z'unsafe-eval'z'unsafe-hashes'z'unsafe-inline'z'wasm-unsafe-eval'z<CSP_NONCE_SENTINEL>N)Ú__name__Ú
__module__Ú__qualname__Ú__doc__ÚHEADER_ENFORCEÚHEADER_REPORT_ONLYÚNONEÚREPORT_SAMPLEÚSELFÚSTRICT_DYNAMICÚUNSAFE_EVALÚUNSAFE_HASHESÚUNSAFE_INLINEÚWASM_UNSAFE_EVALÚNONCE© ó    úJ/var/www/html/office/venv/lib/python3.12/site-packages/django/utils/csp.pyr   r      sF   „ ñð2 /€NØ>Ðð €DØ%€MØ€DØ'€NØ!€KØ%€MØ%€MØ+Ðð
 #�Er   r   c                   ó(   ‡ — e Zd ZdZˆ fd„Zd„ Zˆ xZS )Ú	LazyNoncea{  
    Lazily generates a cryptographically secure nonce string, for use in CSP
    headers.

    The nonce is only generated when first accessed (e.g., via string
    interpolation or inside a template).

    The nonce will evaluate as `True` if it has been generated, and `False` if
    it has not. This is useful for third-party Django libraries that want to
    support CSP without requiring it.

    Example Django template usage with context processors enabled:

        <script{% if csp_nonce %} nonce="{{ csp_nonce }}"...{% endif %}>

    The `{% if %}` block will only render if the nonce has been evaluated
    elsewhere.

    c                 ó,   •— t         ‰| �  t        «       y ©N)ÚsuperÚ__init__Úgenerate_nonce)ÚselfÚ	__class__s    €r   r   zLazyNonce.__init__I   s   ø€ Ü‰ÑœÕ(r   c                 ó&   — | j                   t        uS r   )Ú_wrappedr   )r!   s    r   Ú__bool__zLazyNonce.__bool__L   s   € Ø�}‰}¤EÐ)Ð)r   )r   r	   r
   r   r   r%   Ú__classcell__)r"   s   @r   r   r   4   s   ø„ ñô()ö*r   r   c                  ó,   — t        j                  d«      S )Né   )ÚsecretsÚtoken_urlsafer   r   r   r    r    P   s   € Ü× Ñ  Ó$Ð$r   c                 ó(  — g }| j                  «       D ]ã  \  }}|dv rŒ|du rd}n®t        |t        «      rt        |«      }nt        |t        t
        z  «      s|g}t        j                  |v x}r+|r)|D �cg c]  }|t        j                  k(  rd|› d�n|‘Œ }}n%|r#|D �cg c]  }|t        j                  k7  sŒ|‘Œ }}|sŒ¯dj                  |«      }|j                  |› d|› �j                  «       «       Œå dj                  |«      S c c}w c c}w )N)NFTÚ z'nonce-ú'ú z; )ÚitemsÚ
isinstanceÚsetÚsortedÚlistÚtupler   r   ÚjoinÚappendÚrstrip)ÚconfigÚnonceÚpolicyÚ	directiveÚvaluesÚrendered_valueÚhas_sentinelÚvs           r   Úbuild_policyr@   T   s  € Ø€Fà#Ÿ\™\›^ò @Ñˆ	�6Ø�]Ñ"Øà�T‰>Ø‰Nä˜&¤#Ô&ô   ›‘Ü ¬¬u©Ô5Ø ˜�ô !$§	¡	¨VÐ 3Ð3�Ð3¹ØOUÖVÈ!°´S·Y±Y²˜G E 7¨!Ñ,ÀAÑEÐV�ÑVÙØ%+Ö> ¨q´C·I±I«~š!Ð>�Ð>áØà ŸX™X fÓ-ˆNà�‰˜˜ 1 ^Ð$4Ð5×<Ñ<Ó>Õ?ð5@ð8 �9‰9�VÓÐùò Wùâ>s   Á5"D
Â DÂ9Dr   )
r)   Úenumr   Údjango.utils.functionalr   r   r   r   r    r@   r   r   r   ú<module>rC      s2   ðÛ Ý ç ;ô*#ˆ'ô *#ôZ*Ð ô *ò8%ôr   