Ë
    ÚŠ±ji%  ã                  óä   — d dl mZ d dlZd dlmZmZ d dlmZ d dlm	Z	m
Z
mZmZ ddlmZmZmZmZmZmZmZmZmZmZmZ erd dlmZ d d	lmZ  ej:                  e«      Z G d
„ d«      Z 	 	 	 	 dd„Z!y)é    )ÚannotationsN)ÚTYPE_CHECKINGÚAny)Úunquote)Ú	BlueprintÚFlaskÚResponseÚrequesté   )Ú
ACL_ORIGINÚCorsOptionsInputÚResourcePatternÚ_ComputedCorsOptionsÚget_cors_optionsÚget_regexp_patternÚmerge_optionsÚparse_resourcesÚserialize_optionsÚset_cors_headersÚtry_match_pattern)ÚCallable)ÚUnpackc                  ó"   — e Zd ZdZddd„Zdd„Zy)ÚCORSa  
    Initializes Cross Origin Resource sharing for the application. The
    arguments are identical to `cross_origin`, with the addition of a
    `resources` parameter. The resources parameter defines a series of regular
    expressions for resource paths to match and optionally, the associated
    options to be applied to the particular resource. These options are
    identical to the arguments to `cross_origin`.

    The settings for CORS are determined in the following order

    1. Resource level settings (e.g when passed as a dictionary)
    2. Keyword argument settings
    3. App level configuration settings (e.g. CORS_*)
    4. Default settings

    Note: as it is possible for multiple regular expressions to match a
    resource path, the regular expressions are first sorted by length,
    from longest to shortest, in order to attempt to match the most
    specific regular expression. This allows the definition of a
    number of specific resource options, with a wildcard fallback
    for all other resources.

    :param resources:
        The series of regular expression and (optionally) associated CORS
        options to be applied to the given resource path.

        If the argument is a dictionary, it's keys must be regular expressions,
        and the values must be a dictionary of kwargs, identical to the kwargs
        of this function.

        If the argument is a list, it is expected to be a list of regular
        expressions, for which the app-wide configured options are applied.

        If the argument is a string, it is expected to be a regular expression
        for which the app-wide configured options are applied.

        Default : Match all and apply app-level configuration

    :type resources: dict, iterable or string

    :param origins:
        The origin, or list of origins to allow requests from.
        The origin(s) may be regular expressions, case-sensitive strings,
        or else an asterisk.

        ..  note::

            origins must include the schema and the port (if not port 80),
            e.g.,
            `CORS(app, origins=["http://localhost:8000", "https://example.com"])`.

        Default : '*'
    :type origins: list, string or regex

    :param methods:
        The method or list of methods which the allowed origins are allowed to
        access for non-simple requests.

        Default : [GET, HEAD, POST, OPTIONS, PUT, PATCH, DELETE]
    :type methods: list or string

    :param expose_headers:
        The header or list which are safe to expose to the API of a CORS API
        specification.

        Default : None
    :type expose_headers: list or string

    :param allow_headers:
        The header or list of header field names which can be used when this
        resource is accessed by allowed origins. The header(s) may be regular
        expressions, case-sensitive strings, or else an asterisk.

        Default : '*', allow all headers
    :type allow_headers: list, string or regex

    :param supports_credentials:
        Allows users to make authenticated requests. If true, injects the
        `Access-Control-Allow-Credentials` header in responses. This allows
        cookies and credentials to be submitted across domains.

        :note: This option cannot be used in conjunction with a '*' origin

        Default : False
    :type supports_credentials: bool

    :param max_age:
        The maximum time for which this CORS request maybe cached. This value
        is set as the `Access-Control-Max-Age` header.

        Default : None
    :type max_age: timedelta, integer, string or None

    :param send_wildcard: If True, and the origins parameter is `*`, a wildcard
        `Access-Control-Allow-Origin` header is sent, rather than the
        request's `Origin` header.

        Default : False
    :type send_wildcard: bool

    :param vary_header:
        If True, the header Vary: Origin will be returned as per the W3
        implementation guidelines.

        Setting this header when the `Access-Control-Allow-Origin` is
        dynamically generated (e.g. when there is more than one allowed
        origin, and an Origin than '*' is returned) informs CDNs and other
        caches that the CORS headers are dynamic, and cannot be cached.

        If False, the Vary header will never be injected or altered.

        Default : True
    :type vary_header: bool

    :param allow_private_network:
        If True, the response header `Access-Control-Allow-Private-Network`
        will be set with the value 'true' whenever the request header
        `Access-Control-Request-Private-Network` has a value 'true'.

        If False, the response header `Access-Control-Allow-Private-Network`
        will be set with the value 'false' whenever the request header
        `Access-Control-Request-Private-Network` has a value of 'true'.

        If the request header `Access-Control-Request-Private-Network` is
        not present or has a value other than 'true', the response header
        `Access-Control-Allow-Private-Network` will not be set.

        Default : True
    :type allow_private_network: bool
    Nc                ó>   — || _         |� | j                  |fi |¤Ž y y ©N)Ú_optionsÚinit_app)ÚselfÚappÚkwargss      úY/var/www/io.vulcan-creative.com/venv/lib/python3.12/site-packages/flask_cors/extension.pyÚ__init__zCORS.__init__£   s&   € ØˆŒØˆ?ØˆD�M‰M˜#Ñ( Ó(ð ó    c                ó4  ‡‡— t        || j                  |«      }t        |«      }t        |j	                  dd«      «      }|D ��cg c]  \  }}|t        || j                  ||«      f‘Œ! }}}|D ��ci c]  \  }}t        |«      |“Œ }	}}t        j                  d|	«       t        |«      Š|j                  ‰«       |j                  rEt        |d«      r8|Šdˆˆfd„}
 |
‰j                  «      ‰_         |
‰j                  «      ‰_        y y y c c}}w c c}}w )NÚ	resourcesz/*z#Configuring CORS with resources: %sÚhandle_exceptionc                ó   •‡ — dˆˆˆ fd„}|S )Nc            	     ó>   •—  ‰‰j                   ‰| i |¤Ž«      «      S r   )Úmake_response)Úargsr!   Úapp_anyÚcors_after_requestÚfs     €€€r"   Úwrapped_functionzICORS.init_app.<locals>._after_request_decorator.<locals>.wrapped_functionÍ   s#   ø€ Ù-¨g×.CÑ.CÁAÀtÐDVÈvÑDVÓ.WÓXÐXr$   )r+   r   r!   r   Úreturnr	   © )r.   r/   r,   r-   s   ` €€r"   Ú_after_request_decoratorz/CORS.init_app.<locals>._after_request_decoratorÌ   s   ù€ ÷Yð (Ð'r$   )r.   zCallable[..., Any]r0   zCallable[..., Response])r   r   r   r   Úgetr   r   ÚLOGÚdebugÚmake_after_request_functionÚafter_requestÚintercept_exceptionsÚhasattrr'   Úhandle_user_exception)r   r    r!   ÚmergedÚoptionsr&   ÚpatternÚoptsÚresolved_resourcesÚresources_humanr2   r,   r-   s              @@r"   r   zCORS.init_app¨   s!  ù€ ô ˜s D§M¡M°6Ó:ˆÜ# FÓ+ˆô $ F§J¡J¨{¸EÓ$BÓCˆ	ð bk÷R
ÙN]ÈwÐX\ˆWÔ& s¨D¯M©M¸6À4ÓHÒIðR
Ðñ R
ð Ug×gÁÀ'È4Ô-¨gÓ6¸Ñ<ÐgˆÑgÜ�	‰	Ð7¸ÔIä8Ð9KÓLÐØ×ÑÐ,Ô-ð ×'Ò'¬G°CÐ9KÔ,LØˆGö(ñ (@À×@XÑ@XÓ'YˆGÔ$Ù,DÀW×EbÑEbÓ,cˆGÕ)ð -MÐ'ùó#R
ùó hs   Á$DÁ1Dr   )r    zFlask | Blueprint | Noner!   úUnpack[CorsOptionsInput]r0   ÚNone)r    zFlask | Blueprintr!   rA   r0   rB   )Ú__name__Ú
__module__Ú__qualname__Ú__doc__r#   r   r1   r$   r"   r   r      s   „ ñAôF)ô
+dr$   r   c                ó   ‡ — dˆ fd„}|S )Nc                ó”  •— | j                   �6| j                   j                  t        «      rt        j	                  d«       | S t        t        j                  «      }‰D ]Q  \  }}t        ||d¬«      sŒt        j	                  dt        j                  t        |«      |«       t        | |«        | S  t        j	                  d«       | S )Nz*CORS have been already evaluated, skippingT)ÚcaseSensitivez=Request to '%r' matches CORS resource '%s'. Using options: %szNo CORS rule matches)Úheadersr3   r   r4   r5   r   r
   Úpathr   r   r   )ÚrespÚnormalized_pathÚ	res_regexÚres_optionsr&   s       €r"   r-   z7make_after_request_function.<locals>.cors_after_requestÙ   s©   ø€ à�<‰<Ð#¨¯©×(8Ñ(8¼Ô(DÜ�I‰IÐBÔCØˆKÜ!¤'§,¡,Ó/ˆØ&/ò 	.Ñ"ˆI�{Ü  °)È4ÖPÜ—	‘	ØSÜ—L‘LÜ& yÓ1Øô	ô !  {Ô3Øð ˆð	.ô �I‰IÐ,Ô-Øˆr$   )rL   r	   r0   r	   r1   )r&   r-   s   ` r"   r6   r6   Ö   s   ø€ õð( Ðr$   )r&   z2list[tuple[ResourcePattern, _ComputedCorsOptions]]r0   zCallable[[Response], Response])"Ú
__future__r   ÚloggingÚtypingr   r   Úurllib.parser   Úflaskr   r   r	   r
   Úcorer   r   r   r   r   r   r   r   r   r   r   Úcollections.abcr   Útyping_extensionsr   Ú	getLoggerrC   r4   r   r6   r1   r$   r"   ú<module>rY      sl   ðÝ "ã ß %Ý  ç 5Ó 5÷÷ ÷ ñ ñ Ý(å(à€g×Ñ˜Ó!€÷tdñ tdðnØAðà#ôr$   