File: connection.py

package info (click to toggle)
python-nbxmpp 6.3.0-1
  • links: PTS, VCS
  • area: main
  • in suites: forky, sid
  • size: 1,340 kB
  • sloc: python: 19,639; makefile: 4
file content (184 lines) | stat: -rw-r--r-- 5,310 bytes parent folder | download | duplicates (2)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
# Copyright (C) 2020 Philipp Hörist <philipp AT hoerist.com>
#
# This file is part of nbxmpp.
#
# SPDX-License-Identifier: GPL-3.0-or-later

from typing import Any

import logging

from gi.repository import Gio

from nbxmpp.const import ConnectionType
from nbxmpp.const import TCPState
from nbxmpp.structs import ServerAddress
from nbxmpp.util import LogAdapter
from nbxmpp.util import min_version
from nbxmpp.util import Observable

log = logging.getLogger("nbxmpp.connection")


class Connection(Observable):
    """
    Base Connection Class

    Signals:

        data-sent
        data-received
        bad-certificate
        connection-failed
        disconnected
    """

    def __init__(
        self,
        log_context: str | None,
        address: ServerAddress,
        accepted_certificates: list[Gio.TlsCertificate],
        ignore_tls_errors: bool,
        ignored_tls_errors: set[Gio.TlsCertificateFlags],
        client_cert: Any,
    ) -> None:

        self._log = LogAdapter(log, {"context": log_context})

        Observable.__init__(self, self._log)

        self._client_cert = client_cert
        self._address = address
        self._local_address: Gio.SocketAddress | None = None
        self._remote_address: str | None = None

        self._state = TCPState.DISCONNECTED
        self._tls_con: Gio.TlsConnection | None = None

        self._peer_certificate: Gio.TlsCertificate | None = None
        self._peer_certificate_errors: set[Gio.TlsCertificateFlags] | None = None
        self._accepted_certificates = accepted_certificates
        self._ignore_tls_errors = ignore_tls_errors
        self._ignored_tls_errors = ignored_tls_errors

    @property
    def tls_version(self) -> int | None:
        if self._tls_con is None:
            return None

        if not min_version("GLib", "2.69.0"):
            return None

        return self._tls_con.get_protocol_version()

    @property
    def ciphersuite(self) -> str | None:
        if self._tls_con is None:
            return None

        if not min_version("GLib", "2.69.0"):
            return None

        return self._tls_con.get_ciphersuite_name()

    def get_channel_binding_data(
        self, type_: Gio.TlsChannelBindingType
    ) -> bytes | None:
        assert self._tls_con is not None

        try:
            success, data = self._tls_con.get_channel_binding_data(type_)
        except Exception as error:
            self._log.warning("Unable to get channel binding data: %s", error)
            return None

        if not success:
            return None
        return data

    @property
    def local_address(self) -> Gio.SocketAddress | None:
        return self._local_address

    @property
    def remote_address(self) -> str | None:
        return self._remote_address

    @property
    def peer_certificate(
        self,
    ) -> tuple[Gio.TlsCertificate | None, set[Gio.TlsCertificateFlags] | None]:
        return (self._peer_certificate, self._peer_certificate_errors)

    @property
    def connection_type(self) -> ConnectionType:
        assert self._address is not None
        return self._address.type

    @property
    def state(self) -> TCPState:
        return self._state

    @state.setter
    def state(self, value: TCPState) -> None:
        self._log.info("Set Connection State: %s", value)
        self._state = value

    def _accept_certificate(self) -> bool:
        if not self._peer_certificate_errors:
            return True

        self._log.info(
            "Found TLS certificate errors: %s", self._peer_certificate_errors
        )

        if self._ignore_tls_errors:
            self._log.warning("Ignore all errors")
            return True

        if self._ignored_tls_errors:
            self._log.warning(
                "Ignore TLS certificate errors: %s", self._ignored_tls_errors
            )
            self._peer_certificate_errors -= self._ignored_tls_errors

        if Gio.TlsCertificateFlags.UNKNOWN_CA in self._peer_certificate_errors:
            for accepted_certificate in self._accepted_certificates:
                assert self._peer_certificate is not None
                if self._peer_certificate.is_same(accepted_certificate):
                    self._peer_certificate_errors.discard(
                        Gio.TlsCertificateFlags.UNKNOWN_CA
                    )
                    break

        return bool(not self._peer_certificate_errors)

    def disconnect(self) -> None:
        raise NotImplementedError

    def connect(self) -> None:
        raise NotImplementedError

    def send(self, stanza: Any, now: bool = False) -> None:
        raise NotImplementedError

    def _log_stanza(self, data: str, received: bool = True) -> None:
        direction = "RECEIVED" if received else "SENT"
        message = "::::: DATA %s ::::\n\n%s\n"
        self._log.info(message, direction, data)

    def start_tls_negotiation(self) -> None:
        raise NotImplementedError

    def shutdown_output(self) -> None:
        raise NotImplementedError

    def shutdown_input(self) -> None:
        raise NotImplementedError

    def destroy(self) -> None:
        self.remove_subscriptions()
        self._peer_certificate = None
        self._client_cert = None
        self._address = None
        self._tls_con = None