+
    …¿jE	  ã                   óˆ   € ^ RI t ^ RIHtHt RtRt ! R R]4      tR R ltR R	 lt	R
 R lt
R R ltR R ltRR R lltR# )é    N)ÚFernetÚInvalidTokenÚBESTWEB_SECRET_KEYc                   ó   € ] tR t^tRtRtR# )ÚSecretDecryptionErrorzDRaised when a stored secret cannot be decrypted with the active key.© N)Ú__name__Ú
__module__Ú__qualname__Ú__firstlineno__Ú__doc__Ú__static_attributes__r   ó    Ú)/var/www/html/bestweb/app/core/secrets.pyr   r      s   † ÝNr   r   c                ó$   € V ^8„  d   QhR\         /# ©é   Úreturn)r   )Úformats   "r   Ú__annotate__r      s   € ÷  ñ  ”ñ  r   c                  óœ   € \         P                  ! \        4      p V '       g   \        \         R 24      h\	        V P                  4       4      # )z belum diset)ÚosÚgetenvÚ	_KEY_NAMEÚRuntimeErrorr   Úencode)Úkeys    r   Ú_fernetr      s6   € Ü
�)Š)”IÓ
€CßÜœi˜[¨Ð5Ó6Ð6Ü�#—*‘*“,ÓÐr   c                ó$   € V ^8„  d   QhR\         /# r   )Úlist)r   s   "r   r   r      s   € ÷ ñ œ4ñ r   c                 óæ   € . p \          FL  p\        P                  ! V4      pV'       g   K#   V P                  \	        VP                  4       4      4       KN  	  V #   \        \        3 d     Kf  i ; i)a   Keys historically used to encrypt device credentials.

Credentials were written with DEVICE_CREDENTIAL_KEY while the code only ever
read BESTWEB_SECRET_KEY, so they failed to decrypt and were silently sent to
devices as ciphertext. These are still tried on read so existing rows recover.
)Ú_LEGACY_KEY_NAMESr   r   Úappendr   r   Ú
ValueErrorÚ	TypeError)ÚfernetsÚnamer   s      r   Ú_fallback_fernetsr(      sb   € ð €Gß!ˆÜ�iŠi˜‹oˆßÙð	Ø�N‰Nœ6 #§*¡*£,Ó/Ö0ñ "ð €Nøô œIÐ&ô 	Úð	ús   ­(AÁA0Á/A0c                ó0   € V ^8„  d   QhR\         R\         /# ©r   Úvaluer   ©Ústr)r   s   "r   r   r   &   s   € ÷ 6ñ 6œ#ð 6¤#ñ 6r   c                 ól   € \        4       P                  V P                  4       4      P                  4       # ©N)r   Úencryptr   Údecode©r+   s   &r   Úencrypt_secretr3   &   s$   € Ü‹9×Ñ˜UŸ\™\›^Ó,×3Ñ3Ó5Ð5r   c                ó0   € V ^8„  d   QhR\         R\         /# r*   r,   )r   s   "r   r   r   *   s   € ÷ Eñ Eœð E¤ñ Er   c                ó  € . p\        4       .\        4       O F1  p VP                  V P                  4       4      P	                  4       u # 	  \        R4      h  \
        \        3 d   pTP                  T4        Rp?Kh  Rp?ii ; i)z5Decrypt with the active key, then any historical key.Nz*no configured key could decrypt this value)r   r(   Údecryptr   r1   r   r$   r#   )r+   ÚerrorsÚfernetÚexcs   &   r   Ú_decrypt_anyr:   *   sv   € à€FÜ“9Ð3Ô0Ó2Ó3ˆð	Ø—>‘> %§,¡,£.Ó1×8Ñ8Ó:Ò:ñ 4ô
 ÐCÓ
DÐDøô œjÐ)ô 	Ø�M‰M˜#×Òûð	ús   œ,AÁBÁ)B Â Bc                ó0   € V ^8„  d   QhR\         R\         /# r*   r,   )r   s   "r   r   r   5   s   € ÷ ñ œ#ð ¤#ñ r   c                 óL   €  \        V 4      #   \        \        3 d    T u # i ; ir/   )r:   r   r$   r2   s   &r   Údecrypt_secretr=   5   s+   € ðÜ˜EÓ"Ð"øÜœ*Ð%ô àŠðús   ‚
 �#¢#c                ó<   € V ^8„  d   QhR\         R\         R\         /# )r   r+   Úlabelr   r,   )r   s   "r   r   r   =   s!   € ÷ ñ ¤ð ¬Sð Äñ r   c                ój   €  \        V 4      #   \        \        3 d   p\        T R24      ThRp?ii ; i)zøDecrypt a secret and fail loudly instead of silently returning ciphertext.

Device credentials must use this: sending an undecryptable ciphertext to a
network device produces a misleading "invalid user name or password" and
hides the real problem.
ze tersimpan dengan kunci enkripsi yang berbeda. Password tidak dapat dipulihkan dan harus diset ulang.N)r:   r   r$   r   )r+   r?   r9   s   && r   Údecrypt_secret_strictrA   =   sJ   € ðÜ˜EÓ"Ð"øÜœ*Ð%ô Ü#Øˆgð Eð Eó
ð ð	ûðús   ‚
 �2ž-­2)ÚDEVICE_CREDENTIAL_KEY)Úsecret)r   Úcryptography.fernetr   r   r   r"   r   r   r   r(   r3   r:   r=   rA   r   r   r   Ú<module>rE      sH   ðÛ 	ß 4à €	Ø.Ð ôO˜Lô Oõ õõ&6õEõ÷ñ r   