+
    ŽvjÑ  ã                   óŠ   a € R t0 t R t^ RIt^ RIt^ RIHt ^ RIHt ^ RIHt ]P                  ! R4      t
] ^ k  ! R R4      tR# )	zMUtility module providing security and routing guardrails for the Mailjet SDK.N)ÚAny)ÚFinal)Úurlparsez[\r\n]c                   óÐ   a € ] tR t^t o Rt]V 3R lR l4       t]V 3R lR l4       t]V 3R lR l4       t]RV 3R lR	 ll4       t	]V 3R
 lR l4       t
]V 3R lR l4       tRtV tR# )ÚSecurityGuardz*Centralized OWASP API security guardrails.c                ó*   <€ V ^8„  d   QhRS[ RS[ RR/# )é   Ú
class_nameÚnameÚreturnN©Ústr)ÚformatÚ__classdict__s   "€Úa/var/www/html/daimler-pipeline/venv/lib/python3.14/site-packages/mailjet_rest/utils/guardrails.pyÚ__annotate__ÚSecurityGuard.__annotate__   s"   ø€ ÷ *ñ *©cð *¹ð *Àñ *ó    c                ó„   € VP                  R4      '       d   RV  RV R2p\        V4      hVR8X  d   Rp\        V4      hR# )a  Prevent magic method traps and secret leakage.

Args:
    class_name (str): The name of the calling class.
    name (str): The name of the requested attribute.

Raises:
    AttributeError: If attempting to access private or intentionally removed attributes.
Ú_Ú'z' object has no attribute 'Úauthz9The 'auth' attribute was intentionally removed (CWE-316).N)Ú
startswithÚAttributeError)r	   r
   ÚmsgÚerr_msgs   &&  r   Úvalidate_attribute_accessÚ'SecurityGuard.validate_attribute_access   sO   € ð �?‰?˜3×ÒØ�j�\Ð!<¸T¸FÀ!ÐDˆCÜ  Ó%Ð%Ø�6Œ>ØQˆGÜ  Ó)Ð)ñ r   c                ó&   <€ V ^8„  d   QhRS[ RS[/# )r   Úvalr   )r   r   )r   r   s   "€r   r   r   #   s   ø€ ÷ 	>ñ 	>¡ð 	>©ñ 	>r   c                óX   € \        V 4      P                  RR4      P                  RR4      # )z˜Sanitize log values to prevent Log Forging (CWE-117).

Args:
    val (Any): The input value to sanitize.

Returns:
    str: The sanitized string value.
Ú
r   Ú)r   Úreplace)r   s   &r   Úsanitize_log_traceÚ SecurityGuard.sanitize_log_trace"   s(   € ô �3‹x×Ñ  cÓ*×2Ñ2°4¸Ó=Ð=r   c                ó:   <€ V ^8„  d   QhRS[ S[S[3,          RR/# )r   Úkwargsr   N)Údictr   r   )r   r   s   "€r   r   r   /   s#   ø€ ÷ :ñ :¡t©C±¨H¥~ð :¸$ñ :r   c                ó’  € V P                  R4      RJ d    Rp\        P                  ! V\        ^R7       V P                  R4      pV'       dz   \        ;QJ d*    R VP                  4        4       F  '       g   K   RM	  RM! R VP                  4        4       4      '       d"   Rp\        P                  ! V\        ^R7       R	# R	# R	# )
z•Evaluate request kwargs for security risks (MitM, Proxies).

Args:
    kwargs (dict[str, Any]): The dictionary of keyword arguments for the request.
ÚverifyFzPSecurity Warning: Disabling TLS verification exposes the client to MitM attacks.©Ú
stacklevelÚproxiesc              3   óV   "  € T F  p\        V4      P                  R 4      x € K!  	  R# 5i)zhttp://N)r   r   )Ú.0Úps   & r   Ú	<genexpr>Ú7SecurityGuard.check_request_security.<locals>.<genexpr>:   s$   é € ÐRÑAQ¸Aœ3˜q›6×,Ñ,¨Y×7Ð7ÓAQùs   ‚')Tz2Security Warning: Unencrypted HTTP proxy detected.N)ÚgetÚwarningsÚwarnÚUserWarningÚanyÚvalues)r'   r   r-   s   &  r   Úcheck_request_securityÚ$SecurityGuard.check_request_security.   s†   € ð �:‰:�hÓ 5Ó(ØdˆCÜ�MŠM˜#œ{°qÕ9à—*‘*˜YÓ'ˆß—s“sÑRÀÇÁÔAQÓR—s—s’sÑRÀÇÁÔAQÓR×RÒRØFˆCÜ�MŠM˜#œ{°q×9ñ S‰7r   c                ó*   <€ V ^8„  d   QhRS[ RS[ RR/# )r   Úapi_urlÚallowed_root_domainr   Nr   )r   r   s   "€r   r   r   ?   s#   ø€ ÷ ?ñ ?¡Sð ?¹sð ?ÐW[ñ ?r   c                óˆ  € \        V 4      pVP                  R8w  d   RVP                   R2p\        V4      hVP                  '       g   Rp\        V4      hVP                  P	                  4       pWQ8w  dL   VP                  RV 24      '       g0   RVP                   R2p\        P                  ! V\        ^R7       R	# R	# R	# )
a  Validate API URL for secure transport and Anti-SSRF (CWE-918).

Args:
    api_url (str): The base URL for the Mailjet API.
    allowed_root_domain (str): The permitted root domain to prevent SSRF.

Raises:
    ValueError: If the scheme is not HTTPS or the hostname is missing.
ÚhttpszASecure connection required: api_url scheme must be 'https', got 'z'.z"Invalid api_url: missing hostname.Ú.z:Security Warning: api_url points to a non-Mailjet domain (z).r+   N)	r   ÚschemeÚ
ValueErrorÚhostnameÚlowerÚendswithr4   r5   r6   )r<   r=   Úparsedr   r   rC   Úwarn_msgs   &&     r   Úvalidate_config_urlÚ!SecurityGuard.validate_config_url>   sµ   € ô ˜'Ó"ˆØ�=‰=˜GÔ#ØUÐV\×VcÑVcÐUdÐdfÐgˆCÜ˜S“/Ð!Ø��ˆØ:ˆGÜ˜WÓ%Ð%à—?‘?×(Ñ(Ó*ˆàÔ*°8×3DÑ3DÀqÐI\ÐH]ÐE^×3_Ò3_ØSÐTZ×TcÑTcÐSdÐdfÐgˆHÜ�MŠM˜(¤K¸A×>ñ 4`Ñ*r   c                ó0   <€ V ^8„  d   QhRS[ RS[ RS[ RR/# )r   ÚversionÚ
name_lowerÚresource_lowerr   Nr   )r   r   s   "€r   r   r   X   s0   ø€ ÷ Añ A¡Sð A±cð AÉ3ð AÐSWñ Ar   c                óä   € RpVR8X  d   V R9  d   RpM5V R8X  d   VR8X  d   RpM$V P                  R4      '       d   VR8X  d   R	V  R
2pV'       d    \        P                  ! V\        ^R7       R# R# )zùEmit warnings for ambiguous routing scenarios to improve Developer Experience.

Args:
    version (str): The current API version string.
    name_lower (str): The lowercase endpoint name.
    resource_lower (str): The lowercase resource identifier.
Ú ÚsendÚv3zIMailjet API Ambiguity: The Send API is only available on 'v3' and 'v3.1'.Úv1ÚtemplatezAMailjet API Ambiguity: Content API (v1) uses plural '/templates'.Ú	templatesz"Mailjet API Ambiguity: Email API (z) uses singular '/template'.r+   N>   rQ   úv3.1)r   r4   r5   ÚDeprecationWarning)rK   rL   rM   r   s   &&& r   Úvalidate_dx_routingÚ!SecurityGuard.validate_dx_routingW   sp   € ð ˆØ˜Ô G°>Ô$AØ]‰CØ˜Œ_ °:Ô!=ØU‰CØ×Ñ ×%Ò%¨.¸KÔ*GØ6°w°iÐ?[Ð\ˆCçÜ�MŠM˜#Ô1¸a×@ñ r   c                ó:   <€ V ^8„  d   QhRS[ S[S[3,          RR/# )r   Úcustom_headersr   N)r(   r   )r   r   s   "€r   r   r   l   s#   ø€ ÷ *ñ *©d±3¹°8­nð *Àñ *r   c                ó¢   € V P                  4        F:  w  r\        P                  \        V4      4      '       g   K+  RV R2p\	        V4      h	  R# )zÑPrevent HTTP Header Injection (CWE-113).

Args:
    custom_headers (dict[str, str]): The dictionary of custom headers to validate.

Raises:
    ValueError: If CRLF characters are detected in any header value.
z#CRLF Injection detected in header 'r   N)ÚitemsÚ_CRLF_REÚsearchr   rB   )rZ   ÚkeyÚvaluer   s   &   r   Úvalidate_crlf_headersÚ#SecurityGuard.validate_crlf_headersk   sE   € ð )×.Ñ.Ö0‰JˆCÜ�‰œs 5›z×*Ô*Ø?À¸uÀAÐF�Ü  Ó)Ð)ó 1r   © N)zmailjet.com)Ú__name__Ú
__module__Ú__qualname__Ú__firstlineno__Ú__doc__Ústaticmethodr   r$   r9   rH   rW   ra   Ú__static_attributes__Ú__classdictcell__)r   s   @r   r   r      s…   ø‡ € Ù4à÷*ó ð*ð" ÷	>ó ð	>ð ÷:ó ð:ð ÷?ñ ?ó ð?ð0 ÷Aó ðAð& ÷*ó ö*r   r   c                ó@   € V ^8„  d   Qh/ ^ \         9   d
   \        ;R&   # )r   r]   )Ú__conditional_annotations__r   )r   s   "r   r   r      s   € × SÑ S÷ (Ò 'Œ%Ñ 'ò Tr   )rm   rh   Úrer4   Útypingr   r   Úurllib.parser   Úcompiler]   r   r   )rm   s   @r   Ú<module>rr      s7   øðÞ Sã 	Û Ý Ý Ý !ð —*’*˜YÓ'€Ó '÷k*ó k*r   