mirror of
https://github.com/openswarm-ai/openswarm.git
synced 2026-09-28 04:24:51 +02:00
* [eric] ci: gitleaks-ignore the known historical secrets so our branch stops failing on leaks it didnt add * [eric] workflows: restore scheduled-tasks on the workflow line (revert removal, keep windows fixes + 1.1.69) * [eric] workflows: re-apply uncommitted scheduling wip (schedule pill, calendar view, slice) * [eric] ops: gitignore dev-team local state files * [eric] ops: backlog item for download-tracking visibility * [eric] ci: allowlist the cdp-routes redaction-test token in gitleaks * [aidan] feat/scheduled-tasks: keep step labels in sync on edit and show chevron on every step * [aidan] fix: schedule time in chat * [aidan] ux/workflows: add workflow step removal (#91) * [aidan] feat/scheduled-tasks: remember workflow tool permissions across runs * [aidan] feat/task-scheduling: add hourly and minute (15-min minimum) schedule intervals (#93) * [aidan] feat/scheduled-tasks: calendar, rename, and edit workflows (#94) * [aidan] bug: fix schedule button * [aidan] fix/agent-errors: surface provider rate limits * [aidan] ux/cards: click-to-rename for chat and workflow titles Single-click a card's title to enter edit mode inline. Commit on Enter/blur, cancel on Escape. Rename persists via PATCH for workflows and sessions. * [aidan] feat/workflows: seed build prompt for zero-step workflows When a new workflow has no steps, seed the agent with a prompt asking the user to describe what the workflow should do, rather than starting blank. * [aidan] feat/workflows: add-to-schedule popover for unscheduled workflows Clicking the "+" on an unscheduled workflow row opens a popover with two options: - Keep this schedule: enables the workflow's existing cadence and moves it to Scheduled - Change schedule: opens the scheduling editor to pick a different time * [aidan] ux/workflows: wire add-to-schedule popover and simplify New button - Made the "+" icon on unscheduled workflow rows clickable, opening a popover to keep or change the schedule - Removed AddIcon from toolbar "New" button (now reads "New" instead of "+ New") * [aidan] fix/scheduled-tasks: open schedule calendar when Schedule pill clicked Fixed the Schedule pill click being swallowed by the toolbar's dismiss handler. Exempted the toolbar pills via data-toolbar-pills so their click handlers fire. * [aidan] ux/workflows: open New workflow in agent build chat instead of empty card When creating a new workflow from the hub, open it in edit_agent view (with the agent builder chat) instead of a preview card. The workflow is created on the backend first so the embedded session has a real ID. * [aidan] feat/workflow-edit: add draft testing save flow * [aidan] ux/chat: remove continue chat button * [aidan] ux/workflows: polish workflow card interactions * [aidan] fix/workflow-scheduling: save unscheduled workflows as drafts * aidan ui: schedule naming changes * [aidan] ui: tool calling desc/naming * [aidan] ui: calendar sidebar naming * [aidan] ui: fix stop viewing closing chat * [aidan] feat/workflows: auto-name workflows and polish the build flow (#95) * [aidan] feat/workflow-auto-naming: auto-generate workflow titles from steps Generate a title + description from a workflow's steps (one aux call, reused for step labels) whenever it is still auto_named, so a workflow built in the Edit Agent names itself on commit instead of staying "New workflow". A manual rename sets auto_named=False and is never overwritten. Stream the aux call (non-streaming drops content on some 9router lanes) and fall back to a step-derived title when the model is unavailable. * [aidan] feat/workflows: hide unsaved new workflows until first save A brand-new "+ New" workflow is created with unsaved=true and kept out of the hub's scheduled/unscheduled lists while the user is still building it in the Edit Agent. The first commit (Save) clears the flag and the workflow appears. Every other create path stays visible immediately. * [aidan] ux/workflows: remove redundant save workflow button The Edit Agent already has Discard/Save controls in its strip, so the header "Save Workflow" button was a duplicate save path. Remove it and its pulse/edit-session-id wiring; the model/time subtitle stays. * [aidan] ux/workflows: animate title on auto-rename Wrap the workflow card title in the same Typewriter the chat card uses, so when the auto-generated name replaces the placeholder after Save it retypes letter-by-letter. Gated on a real (non-placeholder) title so it never animates on mount or for already-named workflows. * [aidan] ux/workflows: animate sidebar title on auto-rename Wrap the calendar hub's sidebar row title in the same Typewriter the workflow card uses, so a title that auto-renames retypes letter-by-letter in the sidebar too. Extract the placeholder/isRealTitle guard into the shared workflowVisuals so the card and sidebar stay in sync. * [aidan] fix/workflows: connect watch tether, keep watched chat open, wire draft run/history * [aidan] ui: grey out chat pill when not selected * [aidan] ui: fix running agent display * [aidan] feat/history-popover: add chat history and scheduled tasks run log tabs (#96) * [aidan] ux/schedule: toast when calendar view already open on expand * [aidan] ui: fix popover descs * [aidan] feat/workflow-runs: add pause, resume, and stop controls for live runs * [aidan] feat/schedule-calendar: add calendar occurrences endpoint and concrete timezones * [aidan] feat/workflows: require at least one step to save a workflow * [aidan] ux/edit-agent: hide Discard for an unsaved new workflow * [aidan] ux/edit-agent: move fix-prefix card below the step list * [aidan] feat/workflows: toast when an unattended scheduled run starts * [aidan] fix/dashboard-tethers: anchor workflow-sidecar tethers to measured card rects * [aidan] feat/workflows: validate steps before scheduling and keep chat tool memory * [aidan] feat/mcp-suggestions: dismissable integration banner with per-session cooldown * [aidan] feat/workflows: add scheduled-run "running now" toast with click-to-view (#97) * [aidan] ux/workflows: surface paused state on card, sidebar, and calendar; tidy run history * [aidan] feat/mcp-suggestions: suggest both Google and Microsoft when provider is ambiguous * [aidan] fix/agent-tokens: friendly out-of-tokens card across all agent surfaces * [aidan] feat/workflow-model: persist edit-agent model on save with switch notice and fresh drafts * [aidan] fix/workflow-chat: force stop on watched run mirrors workflow card stop * [aidan] fix/workflow-cards: keep watched run tethered on finish to avoid duplicate chat * [aidan] feat/schedule-calendar: mark current time with a now line in week view * [aidan] refactor/private-names: rename error and schedule classifiers from _ to p_ * [aidan] feat/scheduled-tasks: agent workflow scheduling and in-chat convert (#98) * [aidan] feat/workflow-suggest: nudge user to convert repeatable chat to workflow Add SuggestConvertToWorkflow MCP tool that agents call at the end of a task when they've completed something worth repeating (daily report, weekly check, recurring data pull). Frontend detects the tool call and glows the "Convert to workflow" button 3 times to draw the eye. When user clicks it, the suggested cadence (e.g. "every weekday at 9am") is stored in the draft and seeded into the scheduling agent's first prompt, so the agent can act on the suggestion rather than asking the user again. Tool is never auto-called — agents decide when a task is genuinely repeatable (not debugging, creative work, one-off lookup). Tool description emphasizes sparse, high-confidence use only (once per session max). Files changed: - backend/apps/agents/schedule_mcp_server.py: add SuggestConvertToWorkflow tool - frontend/src/shared/mcpToolMeta.ts: add label for new tool - frontend/src/app/pages/Dashboard/cards/AgentCard.tsx: detect suggestion in session messages, show+glow "Convert to workflow" button, pass cadence to draft - frontend/src/shared/state/workflowsSlice.ts: add suggested_cadence field to Workflow interface - frontend/src/app/pages/Workflows/SchedulingView.tsx: seed scheduling agent prompt with suggested cadence hint * [aidan] feat/agent-scheduling: route recurring asks through native workflows, deny claude cron skill * [aidan] feat/workflow-convert: in-chat convert popup and auto-open scheduled workflow card * [aidan] ux/calendar-page: schedule calendar restyle + popover fixes (#99) * [aidan] fix/dashboard-delete: remove workflows calendar panel on delete key * [aidan] ux/workflows-calendar: restyle hub, fix today highlight, add toolbar toggle * [aidan] ux/schedule-popover: compact density, fix sticky header bleed, add header spacing * [aidan] ux/schedule-calendar: hollow ring dot for past fires in month view * [aidan] ux/schedule-calendar: clickable +N more opens day's full run list * [aidan] feat/run-log-filters: add success and skipped pills to scheduled task history * [aidan] fix/convert-button: stop drag capture so convert-to-workflow click fires * [aidan] ux/calendar-card: match border color and radius to chat and workflow cards * [aidan] fix/minimap: render missed-runs card on the minimap * [aidan] ux/run-sparkline: simplify tooltip to plain run tally * [aidan] ux/run-history: collapse expanded run view to one clickable line * [aidan] ux/calendar-card: match corner radius to browser cards * [aidan] feat/workflows: launch-time scheduling UX and workflow-card polish (#101) * [aidan] feat/schedule-list: lazy-load list view via scroll sentinel * [aidan] feat/missed-runs: launch toast with per-workflow counts and pan-to-card * [aidan] fix/dashboard-tethers: keep watching line anchored on canvas zoom * [aidan] feat/scheduled-tasks: review missed runs at launch instead of auto-firing on_missed * [aidan] refactor/workflow-cards: use radius and status design tokens, polish card chrome * [aidan] ux/agent-card: keep convert-to-workflow visible during runs with mid-turn toast * [aidan] ux/mcp-bubble: drop redundant verb label when a workflow label is shown * [aidan] chore/backend: remove stale explanatory comments * [aidan] fix/workflows-hub: load workflows on hub mount so calendar fills at launch * [aidan] feat/workflows: generate title, description, step labels at convert time * [aidan] fix/tidy-layout: include workflows hub in tidy and fit-to-view * [aidan] feat/schedule-list: window long list via measured-height virtualizer * [aidan] ux/workflows-hub: remove time-saved badge from calendar header * [aidan] fix/types: add missing semantic-type labels and drop stray fade arg * [aidan] feat/schedule: pin monthly day-of-month and honor repeat-every intervals * [aidan] feat/schedule: inherit source-session tool surface for scheduled runs * [aidan] ux/calendar: restack hour-cell events as bars with overflow affordance * [aidan] feat/calendar: open the run card when clicking a scheduled occurrence * [aidan] ux/missed-runs: add per-group select-all toggle and rename skip action * [aidan] feat: new scheduled task design ported * [aidan] ui: sidebar reorder, repeat controls on schedule card * [aidan] ui: sidebar, scheduling time * [aidan] feat/schedule: pin monthly last-day-of-month * [aidan] feat/steps: per-step enable toggle * [aidan] feat/workflows: per-workflow color swatch * [aidan] feat/trash: soft-delete workflows with restore and purge * [aidan] feat/run-monitor: live run monitor card on the canvas * [aidan] feat/run-context: attach a run as removable chat context * [aidan] feat/compose: new-workflow landing page and auto-commit build flow * [aidan] ui/workflows: dark mode and design-system cohesion * [aidan] ui/calendar: overflow popover, condensed week view, scroll fix * [aidan] feat/home: ongoing runs, missed review, and accurate Coming-up counts * [aidan] fix/run-status: sync ongoing runs and heal stuck/interrupted runs * [aidan] ux/schedule: last-day-of-month UI, Run-at time typing, interval input * [aidan] ux/workflows: default window size and toolbar icon * [aidan] fix/schedule: measure ran_late from start and anchor recurrences to created_at * [aidan] feat/calendar: render fire times from backend, drop JS recurrence reimpl * [aidan] chore/dashboard: drop dead configure/missed-run cards, refetch on reconnect * [aidan] chore/agent-card: remove unreachable convert-to-workflow action * [aidan] fix/workflows: don't bump updated_at on a no-op draft commit so viewing a workflow doesn't reorder the sidebar * [aidan] feat/schedule: warn when scheduling a workflow that has no steps * [aidan] fix/selection-tool: never select the workflows app, and exit the tool on Escape without dropping selections * [aidan] ux/compose: diversify new-workflow starter prompts across personas * [aidan] ux/run-monitor: spawn the run card a bit farther right of the workflows app * [aidan] fix/schedule: harden run recovery and storage writes against crashes * [aidan] ux/compose: restyle new-workflow starters as a clean pill cluster with rich prompts * [aidan] fix/workflows: optimistically apply edits so the schedule banner updates instantly * [aidan] ui/workflows: three-tone surface depth so the window lifts off the canvas in both themes * [aidan] ui/workflows: close buttons turn red on hover, matching the chat card * [aidan] test/schedule: cover executor pipeline, storage durability, and recurrence gaps * [aidan] fix: remove package-lock json * [aidan] fix/workflows-compose: keep compose view until edit agent replies * [aidan] feat/workflows: auto-generate workflow + step titles with typewriter animation * [eric] deps: restore frontend/package-lock.json (PR #105 deletion broke npm ci) --------- Co-authored-by: Eric <ciregenz@berkeley.edu> Co-authored-by: cire <134991075+ciregenz@users.noreply.github.com>
587 lines
16 KiB
Python
587 lines
16 KiB
Python
from __future__ import annotations
|
|
|
|
import base64
|
|
import binascii
|
|
import ipaddress
|
|
import re
|
|
from collections.abc import Sequence
|
|
from typing import Callable, TypeVar, cast
|
|
|
|
from .exceptions import InvalidHeaderFormat, InvalidHeaderValue
|
|
from .typing import (
|
|
ConnectionOption,
|
|
ExtensionHeader,
|
|
ExtensionName,
|
|
ExtensionParameter,
|
|
Subprotocol,
|
|
UpgradeProtocol,
|
|
)
|
|
|
|
|
|
__all__ = [
|
|
"build_host",
|
|
"parse_connection",
|
|
"parse_upgrade",
|
|
"parse_extension",
|
|
"build_extension",
|
|
"parse_subprotocol",
|
|
"build_subprotocol",
|
|
"validate_subprotocols",
|
|
"build_www_authenticate_basic",
|
|
"parse_authorization_basic",
|
|
"build_authorization_basic",
|
|
]
|
|
|
|
|
|
T = TypeVar("T")
|
|
|
|
|
|
def build_host(
|
|
host: str,
|
|
port: int,
|
|
secure: bool,
|
|
*,
|
|
always_include_port: bool = False,
|
|
) -> str:
|
|
"""
|
|
Build a ``Host`` header.
|
|
|
|
"""
|
|
# https://datatracker.ietf.org/doc/html/rfc3986#section-3.2.2
|
|
# IPv6 addresses must be enclosed in brackets.
|
|
try:
|
|
address = ipaddress.ip_address(host)
|
|
except ValueError:
|
|
# host is a hostname
|
|
pass
|
|
else:
|
|
# host is an IP address
|
|
if address.version == 6:
|
|
host = f"[{host}]"
|
|
|
|
if always_include_port or port != (443 if secure else 80):
|
|
host = f"{host}:{port}"
|
|
|
|
return host
|
|
|
|
|
|
# To avoid a dependency on a parsing library, we implement manually the ABNF
|
|
# described in https://datatracker.ietf.org/doc/html/rfc6455#section-9.1 and
|
|
# https://datatracker.ietf.org/doc/html/rfc7230#appendix-B.
|
|
|
|
|
|
def peek_ahead(header: str, pos: int) -> str | None:
|
|
"""
|
|
Return the next character from ``header`` at the given position.
|
|
|
|
Return :obj:`None` at the end of ``header``.
|
|
|
|
We never need to peek more than one character ahead.
|
|
|
|
"""
|
|
return None if pos == len(header) else header[pos]
|
|
|
|
|
|
_OWS_re = re.compile(r"[\t ]*")
|
|
|
|
|
|
def parse_OWS(header: str, pos: int) -> int:
|
|
"""
|
|
Parse optional whitespace from ``header`` at the given position.
|
|
|
|
Return the new position.
|
|
|
|
The whitespace itself isn't returned because it isn't significant.
|
|
|
|
"""
|
|
# There's always a match, possibly empty, whose content doesn't matter.
|
|
match = _OWS_re.match(header, pos)
|
|
assert match is not None
|
|
return match.end()
|
|
|
|
|
|
_token_re = re.compile(r"[-!#$%&\'*+.^_`|~0-9a-zA-Z]+")
|
|
|
|
|
|
def parse_token(header: str, pos: int, header_name: str) -> tuple[str, int]:
|
|
"""
|
|
Parse a token from ``header`` at the given position.
|
|
|
|
Return the token value and the new position.
|
|
|
|
Raises:
|
|
InvalidHeaderFormat: On invalid inputs.
|
|
|
|
"""
|
|
match = _token_re.match(header, pos)
|
|
if match is None:
|
|
raise InvalidHeaderFormat(header_name, "expected token", header, pos)
|
|
return match.group(), match.end()
|
|
|
|
|
|
_quoted_string_re = re.compile(
|
|
r'"(?:[\x09\x20-\x21\x23-\x5b\x5d-\x7e]|\\[\x09\x20-\x7e\x80-\xff])*"'
|
|
)
|
|
|
|
|
|
_unquote_re = re.compile(r"\\([\x09\x20-\x7e\x80-\xff])")
|
|
|
|
|
|
def parse_quoted_string(header: str, pos: int, header_name: str) -> tuple[str, int]:
|
|
"""
|
|
Parse a quoted string from ``header`` at the given position.
|
|
|
|
Return the unquoted value and the new position.
|
|
|
|
Raises:
|
|
InvalidHeaderFormat: On invalid inputs.
|
|
|
|
"""
|
|
match = _quoted_string_re.match(header, pos)
|
|
if match is None:
|
|
raise InvalidHeaderFormat(header_name, "expected quoted string", header, pos)
|
|
return _unquote_re.sub(r"\1", match.group()[1:-1]), match.end()
|
|
|
|
|
|
_quotable_re = re.compile(r"[\x09\x20-\x7e\x80-\xff]*")
|
|
|
|
|
|
_quote_re = re.compile(r"([\x22\x5c])")
|
|
|
|
|
|
def build_quoted_string(value: str) -> str:
|
|
"""
|
|
Format ``value`` as a quoted string.
|
|
|
|
This is the reverse of :func:`parse_quoted_string`.
|
|
|
|
"""
|
|
match = _quotable_re.fullmatch(value)
|
|
if match is None:
|
|
raise ValueError("invalid characters for quoted-string encoding")
|
|
return '"' + _quote_re.sub(r"\\\1", value) + '"'
|
|
|
|
|
|
def parse_list(
|
|
parse_item: Callable[[str, int, str], tuple[T, int]],
|
|
header: str,
|
|
pos: int,
|
|
header_name: str,
|
|
) -> list[T]:
|
|
"""
|
|
Parse a comma-separated list from ``header`` at the given position.
|
|
|
|
This is appropriate for parsing values with the following grammar:
|
|
|
|
1#item
|
|
|
|
``parse_item`` parses one item.
|
|
|
|
``header`` is assumed not to start or end with whitespace.
|
|
|
|
(This function is designed for parsing an entire header value and
|
|
:func:`~websockets.http.read_headers` strips whitespace from values.)
|
|
|
|
Return a list of items.
|
|
|
|
Raises:
|
|
InvalidHeaderFormat: On invalid inputs.
|
|
|
|
"""
|
|
# Per https://datatracker.ietf.org/doc/html/rfc7230#section-7, "a recipient
|
|
# MUST parse and ignore a reasonable number of empty list elements";
|
|
# hence while loops that remove extra delimiters.
|
|
|
|
# Remove extra delimiters before the first item.
|
|
while peek_ahead(header, pos) == ",":
|
|
pos = parse_OWS(header, pos + 1)
|
|
|
|
items = []
|
|
while True:
|
|
# Loop invariant: a item starts at pos in header.
|
|
item, pos = parse_item(header, pos, header_name)
|
|
items.append(item)
|
|
pos = parse_OWS(header, pos)
|
|
|
|
# We may have reached the end of the header.
|
|
if pos == len(header):
|
|
break
|
|
|
|
# There must be a delimiter after each element except the last one.
|
|
if peek_ahead(header, pos) == ",":
|
|
pos = parse_OWS(header, pos + 1)
|
|
else:
|
|
raise InvalidHeaderFormat(header_name, "expected comma", header, pos)
|
|
|
|
# Remove extra delimiters before the next item.
|
|
while peek_ahead(header, pos) == ",":
|
|
pos = parse_OWS(header, pos + 1)
|
|
|
|
# We may have reached the end of the header.
|
|
if pos == len(header):
|
|
break
|
|
|
|
# Since we only advance in the header by one character with peek_ahead()
|
|
# or with the end position of a regex match, we can't overshoot the end.
|
|
assert pos == len(header)
|
|
|
|
return items
|
|
|
|
|
|
def parse_connection_option(
|
|
header: str, pos: int, header_name: str
|
|
) -> tuple[ConnectionOption, int]:
|
|
"""
|
|
Parse a Connection option from ``header`` at the given position.
|
|
|
|
Return the protocol value and the new position.
|
|
|
|
Raises:
|
|
InvalidHeaderFormat: On invalid inputs.
|
|
|
|
"""
|
|
item, pos = parse_token(header, pos, header_name)
|
|
return cast(ConnectionOption, item), pos
|
|
|
|
|
|
def parse_connection(header: str) -> list[ConnectionOption]:
|
|
"""
|
|
Parse a ``Connection`` header.
|
|
|
|
Return a list of HTTP connection options.
|
|
|
|
Args
|
|
header: value of the ``Connection`` header.
|
|
|
|
Raises:
|
|
InvalidHeaderFormat: On invalid inputs.
|
|
|
|
"""
|
|
return parse_list(parse_connection_option, header, 0, "Connection")
|
|
|
|
|
|
_protocol_re = re.compile(
|
|
r"[-!#$%&\'*+.^_`|~0-9a-zA-Z]+(?:/[-!#$%&\'*+.^_`|~0-9a-zA-Z]+)?"
|
|
)
|
|
|
|
|
|
def parse_upgrade_protocol(
|
|
header: str, pos: int, header_name: str
|
|
) -> tuple[UpgradeProtocol, int]:
|
|
"""
|
|
Parse an Upgrade protocol from ``header`` at the given position.
|
|
|
|
Return the protocol value and the new position.
|
|
|
|
Raises:
|
|
InvalidHeaderFormat: On invalid inputs.
|
|
|
|
"""
|
|
match = _protocol_re.match(header, pos)
|
|
if match is None:
|
|
raise InvalidHeaderFormat(header_name, "expected protocol", header, pos)
|
|
return cast(UpgradeProtocol, match.group()), match.end()
|
|
|
|
|
|
def parse_upgrade(header: str) -> list[UpgradeProtocol]:
|
|
"""
|
|
Parse an ``Upgrade`` header.
|
|
|
|
Return a list of HTTP protocols.
|
|
|
|
Args:
|
|
header: Value of the ``Upgrade`` header.
|
|
|
|
Raises:
|
|
InvalidHeaderFormat: On invalid inputs.
|
|
|
|
"""
|
|
return parse_list(parse_upgrade_protocol, header, 0, "Upgrade")
|
|
|
|
|
|
def parse_extension_item_param(
|
|
header: str, pos: int, header_name: str
|
|
) -> tuple[ExtensionParameter, int]:
|
|
"""
|
|
Parse a single extension parameter from ``header`` at the given position.
|
|
|
|
Return a ``(name, value)`` pair and the new position.
|
|
|
|
Raises:
|
|
InvalidHeaderFormat: On invalid inputs.
|
|
|
|
"""
|
|
# Extract parameter name.
|
|
name, pos = parse_token(header, pos, header_name)
|
|
pos = parse_OWS(header, pos)
|
|
# Extract parameter value, if there is one.
|
|
value: str | None = None
|
|
if peek_ahead(header, pos) == "=":
|
|
pos = parse_OWS(header, pos + 1)
|
|
if peek_ahead(header, pos) == '"':
|
|
pos_before = pos # for proper error reporting below
|
|
value, pos = parse_quoted_string(header, pos, header_name)
|
|
# https://datatracker.ietf.org/doc/html/rfc6455#section-9.1 says:
|
|
# the value after quoted-string unescaping MUST conform to
|
|
# the 'token' ABNF.
|
|
if _token_re.fullmatch(value) is None:
|
|
raise InvalidHeaderFormat(
|
|
header_name, "invalid quoted header content", header, pos_before
|
|
)
|
|
else:
|
|
value, pos = parse_token(header, pos, header_name)
|
|
pos = parse_OWS(header, pos)
|
|
|
|
return (name, value), pos
|
|
|
|
|
|
def parse_extension_item(
|
|
header: str, pos: int, header_name: str
|
|
) -> tuple[ExtensionHeader, int]:
|
|
"""
|
|
Parse an extension definition from ``header`` at the given position.
|
|
|
|
Return an ``(extension name, parameters)`` pair, where ``parameters`` is a
|
|
list of ``(name, value)`` pairs, and the new position.
|
|
|
|
Raises:
|
|
InvalidHeaderFormat: On invalid inputs.
|
|
|
|
"""
|
|
# Extract extension name.
|
|
name, pos = parse_token(header, pos, header_name)
|
|
pos = parse_OWS(header, pos)
|
|
# Extract all parameters.
|
|
parameters = []
|
|
while peek_ahead(header, pos) == ";":
|
|
pos = parse_OWS(header, pos + 1)
|
|
parameter, pos = parse_extension_item_param(header, pos, header_name)
|
|
parameters.append(parameter)
|
|
return (cast(ExtensionName, name), parameters), pos
|
|
|
|
|
|
def parse_extension(header: str) -> list[ExtensionHeader]:
|
|
"""
|
|
Parse a ``Sec-WebSocket-Extensions`` header.
|
|
|
|
Return a list of WebSocket extensions and their parameters in this format::
|
|
|
|
[
|
|
(
|
|
'extension name',
|
|
[
|
|
('parameter name', 'parameter value'),
|
|
....
|
|
]
|
|
),
|
|
...
|
|
]
|
|
|
|
Parameter values are :obj:`None` when no value is provided.
|
|
|
|
Raises:
|
|
InvalidHeaderFormat: On invalid inputs.
|
|
|
|
"""
|
|
return parse_list(parse_extension_item, header, 0, "Sec-WebSocket-Extensions")
|
|
|
|
|
|
parse_extension_list = parse_extension # alias for backwards compatibility
|
|
|
|
|
|
def build_extension_item(
|
|
name: ExtensionName, parameters: Sequence[ExtensionParameter]
|
|
) -> str:
|
|
"""
|
|
Build an extension definition.
|
|
|
|
This is the reverse of :func:`parse_extension_item`.
|
|
|
|
"""
|
|
return "; ".join(
|
|
[cast(str, name)]
|
|
+ [
|
|
# Quoted strings aren't necessary because values are always tokens.
|
|
name if value is None else f"{name}={value}"
|
|
for name, value in parameters
|
|
]
|
|
)
|
|
|
|
|
|
def build_extension(extensions: Sequence[ExtensionHeader]) -> str:
|
|
"""
|
|
Build a ``Sec-WebSocket-Extensions`` header.
|
|
|
|
This is the reverse of :func:`parse_extension`.
|
|
|
|
"""
|
|
return ", ".join(
|
|
build_extension_item(name, parameters) for name, parameters in extensions
|
|
)
|
|
|
|
|
|
build_extension_list = build_extension # alias for backwards compatibility
|
|
|
|
|
|
def parse_subprotocol_item(
|
|
header: str, pos: int, header_name: str
|
|
) -> tuple[Subprotocol, int]:
|
|
"""
|
|
Parse a subprotocol from ``header`` at the given position.
|
|
|
|
Return the subprotocol value and the new position.
|
|
|
|
Raises:
|
|
InvalidHeaderFormat: On invalid inputs.
|
|
|
|
"""
|
|
item, pos = parse_token(header, pos, header_name)
|
|
return cast(Subprotocol, item), pos
|
|
|
|
|
|
def parse_subprotocol(header: str) -> list[Subprotocol]:
|
|
"""
|
|
Parse a ``Sec-WebSocket-Protocol`` header.
|
|
|
|
Return a list of WebSocket subprotocols.
|
|
|
|
Raises:
|
|
InvalidHeaderFormat: On invalid inputs.
|
|
|
|
"""
|
|
return parse_list(parse_subprotocol_item, header, 0, "Sec-WebSocket-Protocol")
|
|
|
|
|
|
parse_subprotocol_list = parse_subprotocol # alias for backwards compatibility
|
|
|
|
|
|
def build_subprotocol(subprotocols: Sequence[Subprotocol]) -> str:
|
|
"""
|
|
Build a ``Sec-WebSocket-Protocol`` header.
|
|
|
|
This is the reverse of :func:`parse_subprotocol`.
|
|
|
|
"""
|
|
return ", ".join(subprotocols)
|
|
|
|
|
|
build_subprotocol_list = build_subprotocol # alias for backwards compatibility
|
|
|
|
|
|
def validate_subprotocols(subprotocols: Sequence[Subprotocol]) -> None:
|
|
"""
|
|
Validate that ``subprotocols`` is suitable for :func:`build_subprotocol`.
|
|
|
|
"""
|
|
if not isinstance(subprotocols, Sequence):
|
|
raise TypeError("subprotocols must be a list")
|
|
if isinstance(subprotocols, str):
|
|
raise TypeError("subprotocols must be a list, not a str")
|
|
for subprotocol in subprotocols:
|
|
if not _token_re.fullmatch(subprotocol):
|
|
raise ValueError(f"invalid subprotocol: {subprotocol}")
|
|
|
|
|
|
def build_www_authenticate_basic(realm: str) -> str:
|
|
"""
|
|
Build a ``WWW-Authenticate`` header for HTTP Basic Auth.
|
|
|
|
Args:
|
|
realm: Identifier of the protection space.
|
|
|
|
"""
|
|
# https://datatracker.ietf.org/doc/html/rfc7617#section-2
|
|
realm = build_quoted_string(realm)
|
|
charset = build_quoted_string("UTF-8")
|
|
return f"Basic realm={realm}, charset={charset}"
|
|
|
|
|
|
_token68_re = re.compile(r"[A-Za-z0-9-._~+/]+=*")
|
|
|
|
|
|
def parse_token68(header: str, pos: int, header_name: str) -> tuple[str, int]:
|
|
"""
|
|
Parse a token68 from ``header`` at the given position.
|
|
|
|
Return the token value and the new position.
|
|
|
|
Raises:
|
|
InvalidHeaderFormat: On invalid inputs.
|
|
|
|
"""
|
|
match = _token68_re.match(header, pos)
|
|
if match is None:
|
|
raise InvalidHeaderFormat(header_name, "expected token68", header, pos)
|
|
return match.group(), match.end()
|
|
|
|
|
|
def parse_end(header: str, pos: int, header_name: str) -> None:
|
|
"""
|
|
Check that parsing reached the end of header.
|
|
|
|
"""
|
|
if pos < len(header):
|
|
raise InvalidHeaderFormat(header_name, "trailing data", header, pos)
|
|
|
|
|
|
def parse_authorization_basic(header: str) -> tuple[str, str]:
|
|
"""
|
|
Parse an ``Authorization`` header for HTTP Basic Auth.
|
|
|
|
Return a ``(username, password)`` tuple.
|
|
|
|
Args:
|
|
header: Value of the ``Authorization`` header.
|
|
|
|
Raises:
|
|
InvalidHeaderFormat: On invalid inputs.
|
|
InvalidHeaderValue: On unsupported inputs.
|
|
|
|
"""
|
|
# https://datatracker.ietf.org/doc/html/rfc7235#section-2.1
|
|
# https://datatracker.ietf.org/doc/html/rfc7617#section-2
|
|
scheme, pos = parse_token(header, 0, "Authorization")
|
|
if scheme.lower() != "basic":
|
|
raise InvalidHeaderValue(
|
|
"Authorization",
|
|
f"unsupported scheme: {scheme}",
|
|
)
|
|
if peek_ahead(header, pos) != " ":
|
|
raise InvalidHeaderFormat(
|
|
"Authorization", "expected space after scheme", header, pos
|
|
)
|
|
pos += 1
|
|
basic_credentials, pos = parse_token68(header, pos, "Authorization")
|
|
parse_end(header, pos, "Authorization")
|
|
|
|
try:
|
|
user_pass = base64.b64decode(basic_credentials.encode()).decode()
|
|
except binascii.Error:
|
|
raise InvalidHeaderValue(
|
|
"Authorization",
|
|
"expected base64-encoded credentials",
|
|
) from None
|
|
try:
|
|
username, password = user_pass.split(":", 1)
|
|
except ValueError:
|
|
raise InvalidHeaderValue(
|
|
"Authorization",
|
|
"expected username:password credentials",
|
|
) from None
|
|
|
|
return username, password
|
|
|
|
|
|
def build_authorization_basic(username: str, password: str) -> str:
|
|
"""
|
|
Build an ``Authorization`` header for HTTP Basic Auth.
|
|
|
|
This is the reverse of :func:`parse_authorization_basic`.
|
|
|
|
"""
|
|
# https://datatracker.ietf.org/doc/html/rfc7617#section-2
|
|
assert ":" not in username
|
|
user_pass = f"{username}:{password}"
|
|
basic_credentials = base64.b64encode(user_pass.encode()).decode()
|
|
return "Basic " + basic_credentials
|